unable to remove trojan , my pc is now super slow... cant run elemental, or impulse.

Beginning disinfection:
C:\WINDOWS\system32\ttux.qqo
[DETECTION] Is the TR/Inject.CM Trojan
[NOTE] The registration entry <HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell> was removed successfully.
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK library.
[NOTE] An ARK library instance is already running.
[NOTE] The file is scheduled for deleting after reboot.
The repair notes were written to the file 'C:\avrescue\rescue.avp'.

 

 

anyone dealt with this?  experienced suggestions? appreciate it

151,442 views 109 replies
Reply #1 Top

Removing trojans is a tricky business because you have to find the right scanning software for your pc infection.  There is also the larger problem of rootkits which are very difficult to solve and cause re-infection until they are removed also.  That said, have you tried MalwareByte's Anti-Malware?  It's pretty good.

If you can't eliminate the problem with trying some other scanners then you need to go to a rescue site like Bleeping Computers and follow their instructions to the letter.  They helped me (in just a few days) with a rootkit problem that persisted for weeks before they eradicated it fully.

Reply #2 Top

Honestly, if your PC is that badly infected, then the best course of action would be a clean install of Windows. 

Reply #3 Top

Honestly, if your PC is that badly infected, then the best course of action would be a clean install of Windows.
End of quote

Absolutely.  Boot from CK and nuke the HD down to bedrock first -- delete & rebuild the partition(s).  After the clean install, update your security software and get windows updates, etc, etc.  Every security pgm I have ever seen needed tweaks to make it more strict / paranoid than default.  I also tweak lots of browser & windows settings  -- disable some services (requires some research), and normally disable flash & javascript. You'll often need JS for legit sites (like this one), but keep it off for unknown sites.  If you aren't a video nut, you can probably keep flash off for months at a time - I've had it on only once in the last 2 years.  Most people don't need Java -- uninstall it and/or keep it disabled in your browser's add-on screen.  Replace Adobe Reader (I use Foxit reader instead).  Set the pdf reader not to use javascript or flash, not to open on demand, etc.  Set your PC not to auto-run anything from CDs or thumb-drives (requires registry tweaks or TweakUi).  If you are on XP and log on as administrator, consider running browser & email client DropMyRights (works with Firefox & Thunderbird; not with IE; flaky with Chrome).  Get some kind of add-filtering software -- the bad guys have lots of money to buy adds that will exploit whatever new flaw they know of, even on legitimate add-supported sites.

If you have backups, restore ONLY data files, not programs.  And do all your system hardening before you restore anything. 

Reply #4 Top

Lord Cobol, i would be lost trying to do what you say.  What is a CK, to boot from?  Nuke HD to bedrock?  You mean reformat HD?  I'm afraid to reinstall windows,etc.  I am just not that tech savy...

Use XP, and Opera for browsing the web - and i do watch videos some, as i have no tv or cable.   Might there be more specific advice at the bleeping site?

 

I'm able to get opera to work and post here.  Just cant get GalCiv, Ewom, or  impulse to work anymore.

Reply #5 Top

I would try Malewarebytes. See if that solves the issue and removes the infection.

Lord Cobol I don't do anything but run AVG and haven't had an infection in years. It boils down to your behaviors on the net and what you click on or download.

Reply #6 Top

"I'm afraid to reinstall windows,etc.  I am just not that tech savy..."

Make a list of important data [emails, photos, docs] that you absolutely NEED to keep....then go see someone who is tech-savvy ....and have them salvage data...and reformat/re-install windows.

If you have the time/opportunity to watch....do so.....it'll perhaps help you next time....;)

Reply #7 Top

 

 

  • HIJACKTHIS - you post the log to the analyzer just to see what it says but don't do anything/try to fix. Go to one of the HIJACK THIS forums for help

You can always make a small human sacrifice and see if Yrag shows up. ;)

 

Reply #8 Top

What anti-virus app is installed?

Reply #9 Top

Elana, did you try going to Bleeping Computers web site?  Did you click on the 2 links shown on the web page for Bleeping Computers?

Here is their Welcome page.  Basically, register with them, do some reading there and then post a help request in the right forum.  A very tech savy person will then assist you in removing your pc virus.  They were excellent and helped me remove a rootkit from an infected pc without having to reformat my HD or re-install windows.  They will also help you learn how not to get viruses too.

Reply #10 Top

Oh and Bleeping Computer is a HIJACKTHIS approved web site.

Reply #11 Top

I don't do anything but run AVG and haven't had an infection in years
End of quote
   I haven't either, myself, but I am responsible for all the PCS at the company, and some of those users......

What is a CK, to boot from?
End of quote
    Sorry, I meant "CD", as in boot from your windows install CD.

Reply #12 Top

Chances are fair you have additional infections that you don't know about.  Will it even permit you to do system restore?

Reply #13 Top

Ues, malwarebyres, and now just finished scan with avira.  Avira found 4 trojans, virus and quarantined them, then i deleted them.

Can now do galciv.  But impulse only go as far as the download updates (very small dialogue window) centered on desktop.  Then nothing.

 

MS word 2002, can't open any docs, and new docs, once saved, cannot be opened.  Dialog box says they are infected, or my anti-virus software is not update, (it is), or, anti-virsu software is uncompatabe with 'the application."  (MS Word).  When i try, the only way out of the dialogue boxes, is to repl doc with template... so deleting all my articles, docs. etc won't take care of it.

 

yes, did sys restore already.

Reply #14 Top

Everything I have read on that specific virus says you're gonna have to remove it manually, from files and registry. Unless you want to put out the money for a good Trojan remover, you're best bet is probably gonna be wiping your drive and reinstalling windows. I'm not sure if this bug attaches itself to the RAM or not.

Reply #15 Top

just ran cw shredder, twice, and it found nothing.

Reply #16 Top

This program finds and removes all the crap on my clients systems.

http://www.surfright.nl/en - Hitman pro - Download 32 or 64 depending on what you have.

Boot up in safemode with networking and scan. Remove whatever it finds.

Hope this helps!

Reply #17 Top

Start/ Run: type msconfig. Un-check ttux.qqo. Re-boot.
  

Reply #18 Top

Reading through this, I tend to agree with Island Dog. Sounds like you need a reinstall, Check majorgeeks.com for Trojan Removers and go through them If you are trying to save data but there is a good chance that it has embedded itself in something you may want to save. If you have a clean backup before you noticed this issue that may help. Nasty little things though, they can be timed to go off after setting dormant for months. try all the advice you see here before a reinstall if your data is critical, or you have things you don't want to lose. About to do the same thing my self, my stuff is just not running like it should be!

Reply #19 Top

i did the hijack thingy.  downloaded it.  installed it.  ran it.  ran it.  copied log.  posted log (paste) into analyzer field.  hit "parse"  went to window. said cant open file.

Reply #20 Top

downloaded stinger from mcvee.  won't let me install it.  says 'is in use by another program.'  i get this alot lately, and closing opera (browser) has always let me install program.  this time, even closing the browser did not let me install the stinger from macavv.

Reply #21 Top

Do what yrag said...he is the resident guru and wouldn't steer you wrong.

Reply #22 Top

and if i reinsrtall windows, how do i get galciv2, ewom back?  i don't have them on cds... I have to reinstall MS office, and I HATE MS and their codes... ( have the numbers, but the 'ohs and zeros look the same to me.)   going to geeksite

Reply #23 Top

I tried to do what yrag said.  but I cannot find the 'ttux.qqo ' after i run msconfig.  its not in any of the flile tabs, or boxes -so i cannot 'uncheck' it.

Reply #24 Top

Last time i had a nasty trojan infection in my computer i tried this program from bleepingcomputer.com, it was called fix, and it removed the infection that all the other scanners and antiviruses i tried didnt. And i didnt have to do a reinstall.

Reply #25 Top

i downloaded hitman pro.  tried to install it.  siad file was in use by another program.  I closed browswer (usually fixes this message).

then it said 'program is not a valid 32 bit program  (it is!).