Link to home
Create AccountLog in
Avatar of Stephen
StephenFlag for United States of America

asked on

Trojan Horse Pakes - Virus Removal Programs won't open - XP Home

Hey everyone. I'm working on a client's computer, and to start with the welcome screen would not load to allow a login. It would boot to a black screen with a mouse cursor that could move, but no keystrokes or mouse clicks were accepted. I booted with "Last known good configuration" and to my surprise it actually let me to the login screen. Since then, I've done a couple virus scans with UltimateBootCD4Win and found several culprits and removed them.

The problem I'm now facing is that I cannot launch many programs. I'm trying to run some more scans like ComboFix, MalwareBytes AntiMalware, and SuperAntiSpyware. I had no problem installing MalwareBytes, but SuperAntiSpyware fails with an error when trying to install. I have ComboFix on my flash drive and I'm unable to open it either.

When clicking on certain shortcuts and executables such as ComboFix, MWB, SmitFraud, and others either fail to load throwing up an error, or the hourglass appears for maybe 1-2 seconds (and the process shows itself during this time in Task Manager) and then goes away and nothing happens.

Before posting this question I did some more scans with AVG and found several entries for a virus known as Trojan Horse Pakes.ckf. AVG Deleted them all in safemode, but I still cannot open the same executables. I read someone's post in another forum with the same virus blocking the exact same apps. I also tried TrendMicro's housecall, but the site will not load. I'm about to give up and reinstall windows, but I'd rather not have to do that. I've tried everything in safe mode and normal mode that I can think of. Has anyone successfully removed this virus yet?

As far as I can tell, HiJackThis looks clean as well.
ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
Avatar of Stephen

ASKER

Thanks for your reply. I can't believe out of all the things I tried, I didn't think to simply change the filenames to confuse it. It was a smart little virus. Anyway, I was able to get MBAM to work, but it only showed up some false positives. Afterwards I got ComboFix to run and it immediately found the rootkit and asked me to reboot before completing the scan. It deleted the following files:

C:\smp.bat
c:\windows\regedit.com
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\UACyxirfwbw.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tmp.reg
c:\windows\system32\UACbbdqxrmh.log
c:\windows\system32\UACbcfmloke.dll
c:\windows\system32\UACewyuevdb.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACsjrscdjk.db
c:\windows\system32\UACuwmraprq.dll
c:\windows\system32\UACviymbcmd.dll
c:\windows\system32\UACvpypehqx.dll
c:\windows\system32\UACwexubfeg.dll
c:\windows\system32\UACxptkmneo.log
c:\windows\system32\UACxtapqxje.dat
c:\windows\system32\UACylkixlyw.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\Autorun.inf

All the UAC files are from the trojan rootkit I mentioned. I'm not entirely sure how this virus works and I was unable to find much information about it online. It blocked a lot of installations though. Thanks again for the suggestion. As far as I can tell the problem is solved. I will play around with it a little bit longer and come back tomorrow to accept your answer.
Can you also attach the Combofix log so we can check to make sure it's clean, often times we also use its script function to delete bad files that aren't removed in its previous runs.
Avatar of Stephen

ASKER

Here's the log. Can you tell me how that works or how you would use the script? I'd love to know how ComboFix is actually written. It's a great program. I just never know what it's actually going to get rid of because it doesn't say what it's searching for.

An automatic virus scan is running clean so far this morning so I think the computer is ready to go finally. They'll get charged a pretty penny for that one.
ComboFix---Trojan-Horse-Pakes.txt
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Avatar of Stephen

ASKER

Thanks a lot for the help. I was unaware of the uninstall feature. I've never used that part. Thanks for the sites as well. I will definitely take a look at those. Everything seems to be running smoothly again.
Avatar of Stephen

ASKER

Thanks!
If you like, also check out these links below:
1.  TonyKlein's article "So how did I get infected in the first place?"
http://www.spywareinfoforum.com/index.php?showtopic=60955

2.  miekiemoes' "How to prevent Malware"
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

3.  Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/tutorial82.html
Thanks!