Computer Hope

Software => Computer viruses and spyware => Topic started by: swisstropics on January 02, 2013, 06:50:12 AM

Title: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on January 02, 2013, 06:50:12 AM
Hello,
I recently got a trojan in my internet explorer.  I was able to remove the trojan (using McAfee antivirus - 3 viruses found and removed) but now the majority of my .exe files won't work.

Any help in trying to get my PC back to work is greatly appreciated!

thank you  :)
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: Allan on January 02, 2013, 07:06:38 AM
Please follow the instructions in the following link and post your logs:
http://www.computerhope.com/forum/index.php/topic,46313.0.html
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on January 02, 2013, 08:00:46 AM
Hi,
I've tried to download CCleaner Slim, the download i think was successfull but when it came to run the program I got a pop-up window saying "unable to run CCSETUP326_SLIM.EXE"  :(
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: SuperDave on January 02, 2013, 11:45:07 AM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
Save Rkill to your desktop.

There are 7 different versions. If one of them won't run then download and try to run the other one.
 
Vista and Win7 users need to right click Rkill and choose Run as Administrator
 

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.exe (http://download.bleepingcomputer.com/grinler/rkill.exe)
* Rkill.com (http://download.bleepingcomputer.com/grinler/rkill.com)
* Rkill.scr (http://download.bleepingcomputer.com/grinler/rkill.scr)
* WiNlOgOn.exe (http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe)
* uSeRiNiT.exe (http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe)
* iExplore.exe (http://download.bleepingcomputer.com/grinler/iExplore.exe)
* eXplorer.exe (http://download.bleepingcomputer.com/grinler/eXplorer.exe)
Once you've gotten one of them to run then try to immediately run the following.
*********************************************************
Please download AdwCleaner  (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner)by Xplode onto your Desktop.
********************************************************
Malwarebytes' Anti-Malware (MBAM)

If you already have Malwarebytes be sure to check for updates before scanning!

Download Malwarebytes Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) and save it to your desktop. Alternate download link (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe)

•Double-click mbam-setup.exe and follow the prompts to install the program.

•Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If you encounter any problems while downloading the updates, manually download them from here (http://www.malwarebytes.org/mbam/database/mbam-rules.exe) and just double-click on mbam-rules.exe to install.

•If an update is found, it will download and install the latest version.
•Once the program has loaded, select Perform Quick Scan, then click Scan.

•When the scan is complete, click OK, then Show Results to view the results.

•Be sure that everything is checked, and click Remove Selected.

•When completed, a log will open in Notepad. Save it to a convenient location like the Desktop.

•The log is also automatically saved and can be viewed later by clicking the Logs tab in MBAM.

Copy and Paste the contents of the report in your reply.

•Exit MBAM.
.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

***************************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1 (http://screen317.spywareinfoforum.org/SecurityCheck.exe)
Link 2 (http://screen317.changelog.fr/SecurityCheck.exe)

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

Also, please post the other logs.
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on January 02, 2013, 01:16:38 PM
Hi Dave,
first of all thank you for taking the time to help me out!  :)

I've tried the links you've sent, first one failied, second one (Rkill.com) worked. As soon as Rkill was downloaded, I ran AdwCleaner and I'm sending you the result file as attachment........ I hope you'll get it.

Awaiting for next instructions.......

[year+ old attachment deleted by admin]
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on January 02, 2013, 02:18:05 PM
hello again Dave..... here's Malwarebytes log.........

[year+ old attachment deleted by admin]
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on January 02, 2013, 02:20:22 PM
........ and here is Securitycheck log.

After Security check finished scanning, I was asked to restart my PC and I did so. Once I got back into Windows, I've tried to run Explorer and it worked!!!  :)

....... does this mean that my PC is fine now??

[year+ old attachment deleted by admin]
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: SuperDave on January 02, 2013, 06:56:30 PM
Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

****************************************
Remove the Adware:
********************************************
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version (http://www.java.com/en/download/installed.jsp)

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment (http://www.majorgeeks.com/Sun_Java_Runtime_Environment_d4648.html).

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa (http://raproducts.org/click/click.php?id=1) and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) (http://java.sun.com/javase/6/docs/technotes/guides/jweb/otherFeatures/jqs.html) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
****************************************************
Quote
does this mean that my PC is fine now??
Well, we did get rid of a pile of crap. Let's see what left hanging around.

Download Combofix from any of the links below, and save it to your DESKTOP

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)

To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here  (http://www.pchelpforum.com/anti-virus/110194-how-disable-your-security-applications-4.html) for a tutorial regarding how to do so if you are unsure.
(http://i424.photobucket.com/albums/pp322/digistar/NSIS_disclaimer_ENG.png)

Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:

(http://i424.photobucket.com/albums/pp322/digistar/NSIS_extraction.png)

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.

(http://i424.photobucket.com/albums/pp322/digistar/RcAuto1.gif)

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

(http://i424.photobucket.com/albums/pp322/digistar/whatnext.png)

Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
Title: Re: Trojan removed but now the majority of my .exe files don't open the application
Post by: swisstropics on February 05, 2013, 02:16:19 AM
Lonnie, these informations are very usefull....... I've followed all the suggested steps and got rid of all the Trojans on my PC   :D

Thank you again ComputerHope Team!  :)