Computing.Net > Forums > Security and Virus > Win32:CTX, Need Help Plz

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Win32:CTX, Need Help Plz

Reply to Message Icon

Name: stabgotham
Date: July 27, 2007 at 22:07:52 Pacific
OS: WinXP
CPU/Ram: 3700+/2Gig
Product: Home Built
Comment:

Having a tough time with the following virus:

Win32:CTX

AVG found nothing, so I dl'd Avast! which located the b---tard. All spyware cleaners came back empty (S&D, Ad-Aware 2007, AVG Anti-Spy). a-Squared Anti-Malware came back clean.

I have system restore turned off. I've googled every entry in my HiJackThis log, but this thing keeps coming back. Right now I have been placing the file in my Avast! vault, but I'm not sure what else to do at this point.

Lian-Li PC61
ASUS A8N-SLI Deluxe
AMD Athlon 3700+ San Diego @ 2.6 gHz stock cooling
eVGA 7800GT
2GB G.SKILL DDR400
WD Carviar 300gb SATA 3.0gb/s
Samsung 17" 740N Monitor
Dr. Peppe



Sponsored Link
Ads by Google

Response Number 1
Name: btk1w1
Date: July 27, 2007 at 23:20:46 Pacific
Reply:

First kill these processes

Right click your taskbar, click task manager, click the processes tab, look for, highlight and click the "end process" button for each of these files (if they are running):

ctx.exe
eclabm13.exe
fineprint.exe

Next click on start > search > all files and folders on hard drive and delete the files listed above.

If you have trouble try it in safe mode.

Post back how you went.


0

Response Number 2
Name: stabgotham
Date: July 28, 2007 at 09:39:01 Pacific
Reply:

Done. None of the processes or files were located.

Lian-Li PC61
ASUS A8N-SLI Deluxe
AMD Athlon 3700+ San Diego @ 2.6 gHz stock cooling
eVGA 7800GT
2GB G.SKILL DDR400
WD Carviar 300gb SATA 3.0gb/s
Samsung 17" 740N Monitor
Dr. Peppe


0

Response Number 3
Name: btk1w1
Date: July 28, 2007 at 21:14:25 Pacific
Reply:

If it is in the vault and keeps reappearing I suspect it has written itself to your restore folder. Did you try Avast boot-time scan?

What I would recommend doing first is disabling the system restore utility again.

Open avast from your desktop.

When the scanner screen shows click on the menu button on the top left (it looks like an eject button)and "schedule a boot-time scan". Quarantine everything it finds during boot scan. When complete boot up normally and turn on system restore and run another hjt scan.


0

Response Number 4
Name: stabgotham
Date: July 28, 2007 at 21:23:24 Pacific
Reply:

Done. Found another instance of the Win32:CTX. Put it in the chest. Re-ran everything. Seems to be clear.

What do I do with the files in my chest?

Lian-Li PC61
ASUS A8N-SLI Deluxe
AMD Athlon 3700+ San Diego @ 2.6 gHz stock cooling
eVGA 7800GT
2GB G.SKILL DDR400
WD Carviar 300gb SATA 3.0gb/s
Samsung 17" 740N Monitor
Dr. Peppe


0

Response Number 5
Name: btk1w1
Date: July 28, 2007 at 23:01:44 Pacific
Reply:

Leave these files in your chest for now.

Can you navigate to your c:\windows\system or c:\windows\system32 folder and see if you have a folder in there named ActiveScan.

If you have this then it is most likely avast has detected a false positive which means that it could actually be a safe file.

This file is downloaded when Panda active scan is run and is detected because it is a virus defenition which has not been encrypted.

If this file doesn't exist on your pc it is most likely malware and if your pc is running fine go ahead and remove it from the chest. You have the restore point from after a clean scan when you turned system restore back on.

I would also uninstall panda active scan from my add / remove programs in the control if it is installed and delete the ActiveScan folder. There are alot of other free online scanners you can use instead.

Can you to post back after you have done this so we can run a cleaning program and do a couple of other scans to be sure malware isn't lurking.



0

Related Posts

See More



Response Number 6
Name: stabgotham
Date: July 29, 2007 at 12:42:20 Pacific
Reply:

I had previously removed Activescan from my PC prior to all this. There is no "activescan" folder in the system32 folder, so I believe this was a true positive.

I have deleted the files from my chest as well.

Lian-Li PC61
ASUS A8N-SLI Deluxe
AMD Athlon 3700+ San Diego @ 2.6 gHz stock cooling
eVGA 7800GT
2GB G.SKILL DDR400
WD Carviar 300gb SATA 3.0gb/s
Samsung 17" 740N Monitor
Dr. Peppe


0

Response Number 7
Name: stabgotham
Date: July 29, 2007 at 13:53:00 Pacific
Reply:

Just ran another boot-time scan and this time it picked up Win32:Zlob-ZZ. Man, this is frustrating.

Lian-Li PC61
ASUS A8N-SLI Deluxe
AMD Athlon 3700+ San Diego @ 2.6 gHz stock cooling
eVGA 7800GT
2GB G.SKILL DDR400
WD Carviar 300gb SATA 3.0gb/s
Samsung 17" 740N Monitor
Dr. Peppe


0

Response Number 8
Name: btk1w1
Date: July 29, 2007 at 22:06:34 Pacific
Reply:

Trendmicro have a removal solution but before we proceed with it can you open your registry editor.

Click "start" > "run" and type in regedit.

Click on the + symbol next to each of these folders in the left panel.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\explorer\run

In the right panel do you have the entry:

wininet.dll = "regperf.exe" ?

If you do we will continue with the remedy.


0

Sponsored Link
Ads by Google
Reply to Message Icon

i have a virus please hel... no control panel/start me...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Win32:CTX, Need Help Plz

Comp blacks out..need help plz www.computing.net/answers/security/comp-blacks-outneed-help-plz/3392.html

Need help with virus www.computing.net/answers/security/need-help-with-virus/1461.html

resycled\ntldr.com need help plz www.computing.net/answers/security/resycledntldrcom-need-help-plz/24380.html