Avatar of Stephen
Stephen
Flag for United States of America asked on

Trojan Horse Pakes - Virus Removal Programs won't open - XP Home

Hey everyone. I'm working on a client's computer, and to start with the welcome screen would not load to allow a login. It would boot to a black screen with a mouse cursor that could move, but no keystrokes or mouse clicks were accepted. I booted with "Last known good configuration" and to my surprise it actually let me to the login screen. Since then, I've done a couple virus scans with UltimateBootCD4Win and found several culprits and removed them.

The problem I'm now facing is that I cannot launch many programs. I'm trying to run some more scans like ComboFix, MalwareBytes AntiMalware, and SuperAntiSpyware. I had no problem installing MalwareBytes, but SuperAntiSpyware fails with an error when trying to install. I have ComboFix on my flash drive and I'm unable to open it either.

When clicking on certain shortcuts and executables such as ComboFix, MWB, SmitFraud, and others either fail to load throwing up an error, or the hourglass appears for maybe 1-2 seconds (and the process shows itself during this time in Task Manager) and then goes away and nothing happens.

Before posting this question I did some more scans with AVG and found several entries for a virus known as Trojan Horse Pakes.ckf. AVG Deleted them all in safemode, but I still cannot open the same executables. I read someone's post in another forum with the same virus blocking the exact same apps. I also tried TrendMicro's housecall, but the site will not load. I'm about to give up and reinstall windows, but I'd rather not have to do that. I've tried everything in safe mode and normal mode that I can think of. Has anyone successfully removed this virus yet?

As far as I can tell, HiJackThis looks clean as well.
Anti-Virus AppsAnti-Spyware

Avatar of undefined
Last Comment
rpggamergirl

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
rpggamergirl

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Stephen

ASKER
Thanks for your reply. I can't believe out of all the things I tried, I didn't think to simply change the filenames to confuse it. It was a smart little virus. Anyway, I was able to get MBAM to work, but it only showed up some false positives. Afterwards I got ComboFix to run and it immediately found the rootkit and asked me to reboot before completing the scan. It deleted the following files:

C:\smp.bat
c:\windows\regedit.com
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\UACyxirfwbw.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tmp.reg
c:\windows\system32\UACbbdqxrmh.log
c:\windows\system32\UACbcfmloke.dll
c:\windows\system32\UACewyuevdb.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACsjrscdjk.db
c:\windows\system32\UACuwmraprq.dll
c:\windows\system32\UACviymbcmd.dll
c:\windows\system32\UACvpypehqx.dll
c:\windows\system32\UACwexubfeg.dll
c:\windows\system32\UACxptkmneo.log
c:\windows\system32\UACxtapqxje.dat
c:\windows\system32\UACylkixlyw.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\Autorun.inf

All the UAC files are from the trojan rootkit I mentioned. I'm not entirely sure how this virus works and I was unable to find much information about it online. It blocked a lot of installations though. Thanks again for the suggestion. As far as I can tell the problem is solved. I will play around with it a little bit longer and come back tomorrow to accept your answer.
rpggamergirl

Can you also attach the Combofix log so we can check to make sure it's clean, often times we also use its script function to delete bad files that aren't removed in its previous runs.
Stephen

ASKER
Here's the log. Can you tell me how that works or how you would use the script? I'd love to know how ComboFix is actually written. It's a great program. I just never know what it's actually going to get rid of because it doesn't say what it's searching for.

An automatic virus scan is running clean so far this morning so I think the computer is ready to go finally. They'll get charged a pretty penny for that one.
ComboFix---Trojan-Horse-Pakes.txt
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
SOLUTION
Member_2_921743

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
rpggamergirl

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Stephen

ASKER
Thanks a lot for the help. I was unaware of the uninstall feature. I've never used that part. Thanks for the sites as well. I will definitely take a look at those. Everything seems to be running smoothly again.
Stephen

ASKER
Thanks!
rpggamergirl

If you like, also check out these links below:
1.  TonyKlein's article "So how did I get infected in the first place?"
http://www.spywareinfoforum.com/index.php?showtopic=60955

2.  miekiemoes' "How to prevent Malware"
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

3.  Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/tutorial82.html
Thanks!
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.