Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan removed but now the majority of my .exe files don't open the application  (Read 6829 times)

0 Members and 1 Guest are viewing this topic.

swisstropics

    Topic Starter


    Greenhorn

    • Experience: Familiar
    • OS: Windows XP
    Hello,
    I recently got a trojan in my internet explorer.  I was able to remove the trojan (using McAfee antivirus - 3 viruses found and removed) but now the majority of my .exe files won't work.

    Any help in trying to get my PC back to work is greatly appreciated!

    thank you  :)

    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    swisstropics

      Topic Starter


      Greenhorn

      • Experience: Familiar
      • OS: Windows XP
      Hi,
      I've tried to download CCleaner Slim, the download i think was successfull but when it came to run the program I got a pop-up window saying "unable to run CCSETUP326_SLIM.EXE"  :(

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
      *************************************************************************
      Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
      Save Rkill to your desktop.

      There are 7 different versions. If one of them won't run then download and try to run the other one.
       
      Vista and Win7 users need to right click Rkill and choose Run as Administrator
       

      You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

      * Rkill.exe
      * Rkill.com
      * Rkill.scr
      * WiNlOgOn.exe
      * uSeRiNiT.exe
      * iExplore.exe
      * eXplorer.exe
      Once you've gotten one of them to run then try to immediately run the following.
      *********************************************************
      Please download AdwCleaner by Xplode onto your Desktop.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Search.
      • A logfile will automatically open after the scan has finished.
      • Please post the content of that logfile in your reply.
      • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.
      ********************************************************
      Malwarebytes' Anti-Malware (MBAM)

      If you already have Malwarebytes be sure to check for updates before scanning!


      Download Malwarebytes Anti-Malware and save it to your desktop. Alternate download link

      •Double-click mbam-setup.exe and follow the prompts to install the program.

      •Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

      If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.

      •If an update is found, it will download and install the latest version.
      •Once the program has loaded, select Perform Quick Scan, then click Scan.

      •When the scan is complete, click OK, then Show Results to view the results.

      •Be sure that everything is checked, and click Remove Selected.

      •When completed, a log will open in Notepad. Save it to a convenient location like the Desktop.

      •The log is also automatically saved and can be viewed later by clicking the Logs tab in MBAM.

      Copy and Paste the contents of the report in your reply.

      •Exit MBAM.
      .
      Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

      ***************************************************
      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

      Also, please post the other logs.
      Windows 8 and Windows 10 dual boot with two SSD's

      swisstropics

        Topic Starter


        Greenhorn

        • Experience: Familiar
        • OS: Windows XP
        Hi Dave,
        first of all thank you for taking the time to help me out!  :)

        I've tried the links you've sent, first one failied, second one (Rkill.com) worked. As soon as Rkill was downloaded, I ran AdwCleaner and I'm sending you the result file as attachment........ I hope you'll get it.

        Awaiting for next instructions.......

        [year+ old attachment deleted by admin]

        swisstropics

          Topic Starter


          Greenhorn

          • Experience: Familiar
          • OS: Windows XP
          hello again Dave..... here's Malwarebytes log.........

          [year+ old attachment deleted by admin]

          swisstropics

            Topic Starter


            Greenhorn

            • Experience: Familiar
            • OS: Windows XP
            ........ and here is Securitycheck log.

            After Security check finished scanning, I was asked to restart my PC and I did so. Once I got back into Windows, I've tried to run Explorer and it worked!!!  :)

            ....... does this mean that my PC is fine now??

            [year+ old attachment deleted by admin]

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

            ****************************************
            Remove the Adware:
            • Please close all open programs and internet browsers.
            • Double click on adwcleaner.exe to run the tool.
            • Click on Delete.
            • Confirm each time with OK
            • Your computer will be rebooted automatically. A text file will open after the restart.
            • Please post the content of that logfile in your reply.
            • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
            ********************************************
            Update Your Java (JRE)

            Old versions of Java have vulnerabilities that malware can use to infect your system.


            First Verify your Java Version

            If there are any other version(s) installed then update now.

            Get the new version (if needed)

            If your version is out of date install the newest version of the Sun Java Runtime Environment.

            Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

            Be sure to close ALL open web browsers before starting the installation.

            Remove any old versions

            1. Download JavaRa and unzip the file to your Desktop.
            2. Open JavaRA.exe and choose Remove Older Versions
            3. Once complete exit JavaRA.

            Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
            ****************************************************
            Quote
            does this mean that my PC is fine now??
            Well, we did get rid of a pile of crap. Let's see what left hanging around.

            Download Combofix from any of the links below, and save it to your DESKTOP

            Link 1
            Link 2
            Link 3

            To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
            • Close any open windows and double click ComboFix.exe to run it.

              You will see the following image:


            Click I Agree to start the program.

            ComboFix will then extract the necessary files and you will see this:



            As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

            It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

            If you did not have it installed, you will see the prompt below. Choose YES.



            Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

            **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



            Click on Yes, to continue scanning for malware.

            When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

            Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

            Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
            Windows 8 and Windows 10 dual boot with two SSD's

            swisstropics

              Topic Starter


              Greenhorn

              • Experience: Familiar
              • OS: Windows XP
              Lonnie, these informations are very usefull....... I've followed all the suggested steps and got rid of all the Trojans on my PC   :D

              Thank you again ComputerHope Team!  :)