Trojan/Virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tifald, Nov 23, 2009.

  1. Tifald

    Tifald Private E-2

    Hey

    I was on vacation and I think my brother downloaded some virus while I was away.. The internet has been slow and I was getting pop up messages from my firewall like. Catchme.sys etc.

    Attached are the logs.
     

    Attached Files:

  2. Tifald

    Tifald Private E-2

    My internet is really slow...

    I have some processes I never noticed before.. also start- run - msconfig doesn't work.

    csrss.exe
    smss.exe
    lsass.exe
    CTxfispi.exe

    Plus some exe files in Windows folder... which were created today.. But modified august 2000. Thats what it says in their properties..

    They are called..

    sed.exe
    SWREG.exe
    SWSC.exe
    SWXCACLS.exe
    zip.exe
    grep.exe

    Temporarily storing them in my recycling bin, until you can tell me what to do with them??

    I dont know but to me it seems like Mbam, Superantispyware.. and combofix dont work... =/
     
  3. Tifald

    Tifald Private E-2

    Okay Msconfig.exe.vir?

    Its a VIR file?

    Its now located in C:/Qoobox

    It got quarantined..

    Do I have some sasser virus? Or Virut infection?!!!!!!

    Now my comodo antivirus is telling me about.. Application.Wind32.Nircmd~@16774100

    C:\System Volume Information\_restore....\A0013333.exe...

    Sigh it seems like Comodo is the only program that notices anything..

    And again.. A0013358.exe...
    And again... A0013360.exe
    A0013366.pif
    A0014410.exe
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please return the files to where they belong. You should not be removing anything unless we direct you to do it!!!

    Please read this:
    Don't Bump! It Only Hurts You!!!

    You are missing system files!

    Now go to start / run / and type:
    sfc /scannow
    Have your xp cd handy and run it twice.

    What is this on your desktop:
    C:\Documents and Settings\Administrator\Desktop\7hk48t4y.exe ???

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.exe
    
    FCopy::
    C:\MGtools\temp\ctfmon.exemg | c:\windows\System32\ctfmon.exe
    C:\MGtools\temp\eventlog.dllmg | c:\windows\System32\eventlog.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MailBlocker]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. Tifald

    Tifald Private E-2

    Hey

    I am running a different version of Windows on this computer, its only 600mb, and it installs without explorer or windows media player. It also boots with under 20 processes after a fresh install. It takes up way less ram and is faster.. that might be why you think im missing system files??

    I have a real Windows XP Professional SP3 since 2008, but after having 60 processes and slowing down my computer I opted for this... I consider it to be like linux's different versions of the same OS. I dont think its bad since I own a legal copy.

    I just thought I should explain this so there is no confusion. However Ill do what you said with with the CD that pertains to this OS.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hummm.....then the only thing that you had posted about was in your system restore files. Is that all that you are having reported?
     
  7. Tifald

    Tifald Private E-2

    Well what happened was, I had all sorts of problems, so I tried to solve it myself. I downloaded MBAM, Superantispware, COMBO fix and MG tools. I ran all of them and they all found and corrected some viruses/trojans..

    I ran them again and I posted the new logs on here. Which I guess looked largely clean? However I keep feeling something is wrong, and COMODO antivirus keeps finding PsKILL.exe some type of trojan.. and i removed it twice now. I even downloaded dr. webs cureit and it found 3 trojans?

    I've run a new scan with A NEWLY Updated, Super Anti Spyware, and it found ZERO. Newly updated MBAM also finds nothing.

    ALSO Combo fix wants me to install system restore, "In order to run properly" and I don't want to do that..

    Attached is the OLD mbam log.

    And just as Im writing this Comodo antivurs detected, Trojware.Win32.Hacktool.Prockill and quarantined it.
     

    Attached Files:

  8. Tifald

    Tifald Private E-2

    So basically im just worried there is still something on my computer. Im worried MBAM AND Superantispyware cant detect it. Im especially worried because without windows XP I dont think COMBO fix ran properly. And also because I keep getting messages from my comodo antivirus, which I NEVER got before..
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off, ComboFix is asking you to install the Recovery Console, not system restore. The Recovery console allows you to be able to fix your system without having to use your xp disc. So there is no reason to not allow it to do that.

    "Comodo antivurs detected, Trojware.Win32.Hacktool.Prockill" that tells me nothing. I would need to know the exact path of the file it is reporting. It may be reporting PocketKill Box which is a legit program.

    You did not attach the logs that I requested. Please do that now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds