Author Topic: Please help, got stuck with a Trojan and a rootkit  (Read 28342 times)

0 Members and 1 Guest are viewing this topic.

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #15 on: June 26, 2013, 04:10:50 PM »
Can anyone help me?
It's been 20 hours, yet nobody suggests any sort of solution.
Is it unrepairable? Will I be hanged this way forever?
I've no means of contact with Essexboy, and all I could reach is that he's been offline all the time.
I wonder if any administrator could reach for him...could anybody respond...?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #16 on: June 26, 2013, 04:13:04 PM »
As Craig said, please be patient.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #17 on: June 26, 2013, 04:17:32 PM »
Alright, I'll try to be. Thanks for responding anyway.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #18 on: June 26, 2013, 04:22:18 PM »
NP. It shouldn't take too long.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #19 on: June 26, 2013, 04:38:34 PM »
Hi reboot the computer using the power button

Then run a fresh OTL scan so that I can see what remains

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #20 on: June 26, 2013, 04:49:48 PM »
Rubbing my eyes :)
Have you come to save me at last... :D

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #21 on: June 26, 2013, 04:51:19 PM »
Shall I run a " scan " or a " quick scan " ?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #22 on: June 26, 2013, 04:55:37 PM »
Sorry about that I had to do some actual work today :)

Press run scan and that should reveal anything that combofix missed

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #23 on: June 26, 2013, 05:14:29 PM »
It's ok. I'm glad you came back anyway.
I'm running it at the moment, meanwhile I want to let you learn about a few things:
1- I checked " all users", " LOP", "Purity" for this scan i'm running now, just as the very first one  I'd run.
2- I saw the black screen of the recovery console on reboot this time.
3- There seems to be a folder called Qoobox in my C:/ drive now, shall I look for any logs there?
4- There's also a copy of " my computer" called "combofix" in C:/ drive
5- This time after the reboot a message came from the tray saying that I was insecure and I had my firewalls turned off, is it dangerous?
 
I know it's a lot of things, but just wanted to make sure it's ok.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #24 on: June 26, 2013, 05:18:34 PM »
Once done we will hide the recovery console until you need it (hopefully never)

Qoobox is where combfix quarantines the bad boys

We will check the firewall next, is it just the windows one ?

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #25 on: June 26, 2013, 05:30:12 PM »
yes, I think it's the windows firewall, shall I have any others?

Here I attached the log from the OTL scan of today and you'll find also the one after the running the fix yesterday together with that of the quick scan before running combofix.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #26 on: June 26, 2013, 05:35:44 PM »
Looks good, can you confirm that the avast alerts have ceased ?

Lets now look at the firewall

Download and run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #27 on: June 26, 2013, 05:40:54 PM »
Yes, they've ceased since the very first scan run by OTL yesterday, even along going online no alerts or pop-ups since then. ( previously I couldn't get online without those alerts poping every couple of minutes that I disconnected the cable most of the time)


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #28 on: June 26, 2013, 05:42:15 PM »
Good so it is now repair time :)

Jackiee

  • Guest
Re: Please help, got stuck with a Trojan and a rootkit
« Reply #29 on: June 26, 2013, 06:00:09 PM »
Glad to hear it's good.  :D But for you, it wouldn't have been so.  :)
here's farbar's log...

I want to tell you that I've been having some difficulty since yesterday, after runing the OTL fix, making me unable to download anything, even a few megabytes, without being stopped at the 95% point exactly and getting a message in a window saying that whatsoever I was downloading couldn't be downloaded because the operation timed out.
Yesterday I tried downloading Combofix about 6 or 7 times and getting to the same cut end. In the last time I went clicking continously on the download window at the 95% point and then it completed and I got the file at last.

Today, the same exact story happened with Farbar and was resolved in the same way.
I'm sorry for such a long story, but I want to know if it's something to do with the either the infection or the fix.