Computer freezes upon startup

Hi,

Im just wondering if you can help me out as my computer looks to have been infected with a trojan horse. Im a computer novice so bare with me. It all started yesterday when my computer picked up a threat on my avast anti virus. A picture of a fake antivirus software came on the screen and i clicked off it as quickly as I could.

But after that i would receive alert messages from avast antivirus literally every 5 minutes
telling me the trojan had been sent to the virus chest. I was concerned and started reading up on the problem.

After being suggested to use malwarebytes software. I downloaded it and ran the scan. The scan picked up alot of infected files, so i removed them and was told to reboot the system. after the system restarted I noticed that once my desktop had came up the computer froze. I can use the computer in safe mode but as soon as i access my normal desktop is freezes every tiem it starts up.

Any help would be gratefully appreciated! :smiley:

I believe the name of one of the trojan horses is: win32:downloader-PKU[trj]

Follow the “logs” guide above your post and attach the requested logs here

Ok thanks,

this might take a little time as im actually posting this from a different computer.

hi,

when i run OTL. ive copied the text into the custom scan box and ticked the scan all users box. But when i click run scan. it freezes and doesnt respond?

Continue with malwarebytes and aswMBR

Prior to that please run RogueKiller first… If need be rename the programme to winlogon

Hi guys,

Thanks for helping me out. Here is the log for the Malwarebytes software. Ive also attached both aswMBR and Rogue Killer logs. Im unsure if the aswMBR scan actually fully completed. Because it froze on one scanning section for a long time, hence the late reply. If it a problem, let me know what yous think.

------------- Malwarebytes -----------------

Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.09.06

Windows 7 Service Pack 1 x86 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Alan :: ALAN-PC [administrator]

Protection: Disabled

09/08/2012 14:54:25
mbam-log-2012-08-09 (14-54-25).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 199088
Time elapsed: 6 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\Windows\Installer{2d11f950-1632-4f03-32e4-d30c56eb420b}\U\00000004.@ (Rootkit.Zaccess) → Quarantined and deleted successfully.
C:\Windows\Installer{2d11f950-1632-4f03-32e4-d30c56eb420b}\U\00000008.@ (Trojan.Dropper.BCMiner) → Quarantined and deleted successfully.
C:\Windows\Installer{2d11f950-1632-4f03-32e4-d30c56eb420b}\U\000000cb.@ (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{2d11f950-1632-4f03-32e4-d30c56eb420b}\U\80000000.@ (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{2d11f950-1632-4f03-32e4-d30c56eb420b}\U\80000032.@ (Rootkit.0Access) → Quarantined and deleted successfully.

(end)

Are you able to run OTL now ? If not download and try this version

Download OTL to your Desktop

in reply to essexboy’s post. Yeah I tried the OLT link you sent me. Still the same. I copy and paste the informtation to put into the custom scan box, tick the ‘all user’ box. Then when I run scan, it jus freezes. I think every other software worked other than that.

OK I will jump a step

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Hi guys,

I had recieved the log back from the from combo fix, but I pressed the close button on the log. The big problem is the log txt file doesnt seemed to have saved as a seperate document like the other software logs, unless i have to access the comboFix.exe file again? on the computer front the promising news is that the desktop seems to be working in normal mode again as i can access the internet and type this post and there doesnt seem to be any freezes at this point. I can’t thank yous enough!

However obviously I don’t want to get complacent, so is there anything I should be doing after this process to ensure that the virus is completley gone?. Or is there any advice you could give me to stop things like this happening in the future? Finally should I keep the walware protection (OTL, RK, aswMBR etc) on my desktop as a precaution?

Thanks so much for your help!

Could you now retry OTL please and also look at C:\combofix.txt for the log

Hi again,

All of the files have been attached. Ater the combo fix scan, the OTL program began to work again thankfully. is there anything else that needs to be done?

Thanks

How is the computer running ?

run farbar service scanner

https://dl.dropbox.com/u/73555776/FSS.GIF

Tick “All” options.
Press “Scan”.
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

The computer looks like its running fine. Once the FFS is run completes its scan, should i restart my computer to check if the computer freezes from start up again??

heres the log for the FFS.exe

Post the log first and then reboot

Just restarted the computer. Its boote up nice and quickly and no freezes to be seen. Excellent news! Like I stated in a previous post. Will i need to use anything else? should i keep the malware programs as a precaution and is there any other advice you could give to prevent these things from happening again? Also is the Avast free antivirus a good tool to have, or should i be looking at other protection softwares? Its just been a nightmare the last 2 days lol :smiley:

Two registry items to fix

Right click the links below and select “Save Target as…” to your desktop
https://dl.dropbox.com/u/73555776/mpssvc7.reg
https://dl.dropbox.com/u/73555776/bits.reg
Right click the reg files in turn and select merge
Reboot and give me a final report on the computers behaviour

sorry mate do you mean highlight and merge them both at the same time, or right click and merge them seperatley?