I have to reboot my computer (Windows Vista Home Premium) at least 2 times a day. Because after a wile working on it I get messages like: program X stopt working. I can't reboot through the start menu. I have to do it manually. After rebouting I get message from Avast that it blocked "Win32: Trojan-gen" and no further action is needed. Panda Cloud says it removed one virus. This is the matter every time I reboot. After rebooting I use System Mechanic Pro and Advanced System Care. But nothing helps and I cannot find "Win32 Trojan-gen". Three month ago I had simular problems and I reinstalled Vista but I was busy for weeks to get all the way it used to be. Can someone help me?
My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hello NoodleTech,
Thanks for your reply. I hope you can figure out the problem. One hour ago I got a email message from Prevx that my system was infected. The program said it removed a thread. Maybeβ¦
I will wait for your instructions.
Regards, Joost Pieter
βββββββββββββββββ Please include the contents of the following in your next reply:
DDS.txt Attach.txt.
NEXT
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scanβ¦click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<β ROOKIT" entries
Dear NoodleTech
Thanks for your quick replay. Your instructions were very clear to follow. Thank you for that.
Attached the files you requested.
Regards, Joost Pieter
Dear NoodleTech
I hope the "Gmer" file will be attached to my reply this time because in the first reply I was told the file was too large.
I had to cut the file in two because it was larger than 250k
So also see reply no. 3
Regards, Joost Pieter
Please read through the instructions to familiarize yourself with what to expect when the tool runs.
It is vitally important that combofix is renamed before it has even started to download
Please download ComboFix from Link 1 or Link 2 to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to "Always ask me where to Save the files".
During the download, before you save it to your desktop, rename Combofix to jgh.exe
It is important you rename Combofix during the download, but not after.
Please do not rename Combofix to other names, but only to the one indicated.
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Click onthis linkto see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hello Noodle tech
I tink the trojan problems are solved! After the actions you advised me to do, I do not get messages from Avast or Panda anymore. Offcourse I only can be sure after a couple of days. But so far, so good. I want to thank you very much. In a few days I will reply with my findings over the last days. Is it wise to keep the jgh program installed or shall I uninstall it?
Many thanks Joost Pieter
Hello NoodleTech,
Attached the two logs. One is in Dutch (I am Dutch, living in Indonesia), but it speaks for itself: No threads found.
But the other one found some threads.
I will wait for instructions.
Regards, Joost Pieter
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As⦠Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save β¦
Dear NoodleTech
I executed your latest instructions. During the scan a strange popup appeared ( see att) first I clicked "try again" but northing happened, after clicking :"continue" the popup disappeared and the scan went on.
Log attached also. Can you recommend a realtime malware protector and is it possible to run multiple anti malware program's or is this useless.
Thanks again for your great help sofar. Joost Pieter
Don't worry about the error message. ComboFix did what it was supposed to do.
You currently have 4 realtime antimalware programs running. This is not recommended because the programs can conflict with each other and also slow down system performance.
I suggest you uninstall Avast, Panda Cloud Antivirus, and IObit Security 360. Leave only Microsoft Security Essentials installed. It is a superb antimalware program and it does not hog system resources.
Besides that, it looks like your computer is clean!
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer More Secure
Click Start > Run
Type Inetcpl.cpl and click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected and Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.
3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.
4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Dear NoodleTech
No, I have no further questions. My latest questions were answered on the site you recommanded. Thanks for all your help. I am much obliged. A attachment as token of my appriciation. Joost Pieter