Stephen
asked on
Trojan Horse Pakes - Virus Removal Programs won't open - XP Home
Hey everyone. I'm working on a client's computer, and to start with the welcome screen would not load to allow a login. It would boot to a black screen with a mouse cursor that could move, but no keystrokes or mouse clicks were accepted. I booted with "Last known good configuration" and to my surprise it actually let me to the login screen. Since then, I've done a couple virus scans with UltimateBootCD4Win and found several culprits and removed them.
The problem I'm now facing is that I cannot launch many programs. I'm trying to run some more scans like ComboFix, MalwareBytes AntiMalware, and SuperAntiSpyware. I had no problem installing MalwareBytes, but SuperAntiSpyware fails with an error when trying to install. I have ComboFix on my flash drive and I'm unable to open it either.
When clicking on certain shortcuts and executables such as ComboFix, MWB, SmitFraud, and others either fail to load throwing up an error, or the hourglass appears for maybe 1-2 seconds (and the process shows itself during this time in Task Manager) and then goes away and nothing happens.
Before posting this question I did some more scans with AVG and found several entries for a virus known as Trojan Horse Pakes.ckf. AVG Deleted them all in safemode, but I still cannot open the same executables. I read someone's post in another forum with the same virus blocking the exact same apps. I also tried TrendMicro's housecall, but the site will not load. I'm about to give up and reinstall windows, but I'd rather not have to do that. I've tried everything in safe mode and normal mode that I can think of. Has anyone successfully removed this virus yet?
As far as I can tell, HiJackThis looks clean as well.
The problem I'm now facing is that I cannot launch many programs. I'm trying to run some more scans like ComboFix, MalwareBytes AntiMalware, and SuperAntiSpyware. I had no problem installing MalwareBytes, but SuperAntiSpyware fails with an error when trying to install. I have ComboFix on my flash drive and I'm unable to open it either.
When clicking on certain shortcuts and executables such as ComboFix, MWB, SmitFraud, and others either fail to load throwing up an error, or the hourglass appears for maybe 1-2 seconds (and the process shows itself during this time in Task Manager) and then goes away and nothing happens.
Before posting this question I did some more scans with AVG and found several entries for a virus known as Trojan Horse Pakes.ckf. AVG Deleted them all in safemode, but I still cannot open the same executables. I read someone's post in another forum with the same virus blocking the exact same apps. I also tried TrendMicro's housecall, but the site will not load. I'm about to give up and reinstall windows, but I'd rather not have to do that. I've tried everything in safe mode and normal mode that I can think of. Has anyone successfully removed this virus yet?
As far as I can tell, HiJackThis looks clean as well.
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Can you also attach the Combofix log so we can check to make sure it's clean, often times we also use its script function to delete bad files that aren't removed in its previous runs.
ASKER
Here's the log. Can you tell me how that works or how you would use the script? I'd love to know how ComboFix is actually written. It's a great program. I just never know what it's actually going to get rid of because it doesn't say what it's searching for.
An automatic virus scan is running clean so far this morning so I think the computer is ready to go finally. They'll get charged a pretty penny for that one.
ComboFix---Trojan-Horse-Pakes.txt
An automatic virus scan is running clean so far this morning so I think the computer is ready to go finally. They'll get charged a pretty penny for that one.
ComboFix---Trojan-Horse-Pakes.txt
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
Thanks a lot for the help. I was unaware of the uninstall feature. I've never used that part. Thanks for the sites as well. I will definitely take a look at those. Everything seems to be running smoothly again.
ASKER
Thanks!
If you like, also check out these links below:
1. TonyKlein's article "So how did I get infected in the first place?"
http://www.spywareinfoforu m.com/inde x.php?show topic=6095 5
2. miekiemoes' "How to prevent Malware"
http://users.telenet.be/bl uepatchy/m iekiemoes/ prevention .html
3. Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcompute r.com/tuto rials/tuto rial82.htm l
Thanks!
1. TonyKlein's article "So how did I get infected in the first place?"
http://www.spywareinfoforu
2. miekiemoes' "How to prevent Malware"
http://users.telenet.be/bl
3. Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcompute
Thanks!
ASKER
C:\smp.bat
c:\windows\regedit.com
c:\windows\system32\AutoRu
c:\windows\system32\driver
c:\windows\system32\driver
c:\windows\system32\Packet
c:\windows\system32\pthrea
c:\windows\system32\tmp.re
c:\windows\system32\UACbbd
c:\windows\system32\UACbcf
c:\windows\system32\UACewy
c:\windows\system32\uacini
c:\windows\system32\UACsjr
c:\windows\system32\UACuwm
c:\windows\system32\UACviy
c:\windows\system32\UACvpy
c:\windows\system32\UACwex
c:\windows\system32\UACxpt
c:\windows\system32\UACxta
c:\windows\system32\UACylk
c:\windows\system32\WanPac
c:\windows\system32\wpcap.
D:\Autorun.inf
All the UAC files are from the trojan rootkit I mentioned. I'm not entirely sure how this virus works and I was unable to find much information about it online. It blocked a lot of installations though. Thanks again for the suggestion. As far as I can tell the problem is solved. I will play around with it a little bit longer and come back tomorrow to accept your answer.