This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Agressiv trojan malware virus.. firewall disabled, una

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently had to completly re-install xp. For about a week I have installing all my old programs, running updates for windows XP and set up my pc for auto updates and even run the updater anytime i installed something new. Of course the first things I loaded were my virus protector Kaspersky and Firewall sygate….

Today I was updating Windows Media Player and a suggested update was offered when I tried to load a song… it appears to have been a virus or trojan. Kaspersky seemed to have caught it but not before serious damage occurred.

I am unable to access the web, my firewall is completely down. After being unable to re-install my firewall and after accessing the web for fixes I quickly realized I was going to loose access to explorer so I managed to download adware and comodo firewall. When I installed both of them neither one would launch. By this time I could no longer access the web with IE or googles Chrome. Chrome seemed to hang in a bit longer than IE as IE went down pretty fast.

You can see the the programs load in the task manager but something is ending them. I tried a system restore and it only had todays date in bold I couldn't go back any further and the time was just moments ago so no use to me. I created a restore point about 5 days ago… dont know what happened to it as its gone. it also appears explorer is deleting programs out of my task manager. The warning from kaspersky indicates IE is trying to embed other programs. I usually have about 30 items and I am down to 15. I have set the IE priority to low while kaspersky runs… as IE was running at 50%….. I think my registry is slowing being destroyed/deleted. I'm going to attempt to unistall IE and re-install…. I dont know how I will be able to restore the registry.

In the registry sygate, adware and comodo are no where to be found. like they have been deleted. I have scanned with kaspersky but nothing further has been found. Kaspersky still continues to give a pop up "Invader riskware running process IE.exec". See below for kaspersky scan and also posted hijack log…


Please advise…….

Thanks ahead of time!!!!
siberadam :pullhair:


from kaspersky

detected: riskware Invader Running process: C:\Documents and Settings\SiberAdam\My Documents\Downloads\windows_media_update.exe
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
detected: riskware Invader Running process: C:\WINDOWS\explorer.exe
detected: riskware Invader Running process: C:\Program Files\Internet Explorer\iexplore.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\winlogon.exe
deleted: Trojan program Trojan-Downloader.Win32.Clopack.a File: C:\DOCUME~1\SIBERA~1\LOCALS~1\Temp\2.tmp


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:51 PM, on 7/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1292428093-1500820517-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1246643880264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1246755479296
O20 - AppInit_DLLs: C:\WINDOWS\System32\dot3svc32.dll
O20 - Winlogon Notify: 286f18bb638 - C:\WINDOWS\System32\dot3svc32.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

–
End of file - 3560 bytes
Hi siberadam,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you for the response but eventually after this post my ststem would no longer boot regularly or in safe mode. It would restart and stall at a black screen and just sit there. I cant believe how quickly it took down my system. I dont know what I could have done differently to have prevented it. If you have any suggestions I would appreciate it. I have maintained my system for about 9 years with little problems. Of course I have made various upgrades and always update my system. I have felt very secure using Kaspersky Viruse and Sygate Firewall and as these were both operational at the time and dont know what more protection I could have had. My system crashed a few weeks ago due to some bad advice I didnt bother to research. So I had lost everhting then except for some files I had backedup on another drive. Still I lost way more than I would have liked. Something I dont understand is how my "System Restore" keeps getting deleted or is removed. How can either back this up or move it to another disk were I can access it at a later date if the original is distroyed and then how would I get my system to locate and recognize it? I have downloaded TFC in case I experience somehting like this again. What is its actual function? I will do some research and figure it out. My second hard drive is only 40G and is nearly full. Short of backingup my entire main hard drive I dont know what other precautions I should take. Any advice would be appreciated. I guess I could always run out and by a 500G hard drive and use it for backing up the main drive…. thanks for your time… siberadam :blush:
siberadam,

TFC stands for Temporary File Cleaner. I had you run that just to remove the dross prior to scanning with Malwarebytes'. Mostly to make the scan go faster but also malware sometime hides out in temporary file.

Some malware shuts off system restore.

Did you run Malwarbytes'
As stated previously I had to reformat my hardrive and completely reinstall XP. I would think that should have elimated any viruses/trojans…etc/ However to be on the safe side I ran several scans with the following: Lavasoft Adware Malwarebytes Spybot Kaspersky (installed virus protector) Sygate (firewall) Nothing was found. Are there any solutions to protecting "system restore" or another failsafe to protect the integraty of XP so that a complete re-install can be avoided? Siberadam
siberadam,

The only thing I know to do to keep system restore getting shut down is… don't shut it off yourself, and don't get infected with something that shuts it off. I realize that that isn't very helpful information. I'm sorry about that but that's the best I can do. I suggest you post over in the windows forums for advice and "tips and tricks" from the Tech Team.

Meanwhile, Log looks good :D


You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI