Thread: ctfmona.exe
View Single Post
Join Date: Jan 2008
Posts: 2
Reputation: KMPDX is an unknown quantity at this point 
Solved Threads: 0
KMPDX KMPDX is offline Offline
Newbie Poster

Re: ctfmona.exe

 
0
  #5
Feb 1st, 2008
Dude, I'm not much help with the Hijackthis log, but it looks like ctfmona.exe is still in your system32 file. I got rid of that by doing the following:
1 . Run>msconfig>startup>uncheck ctfmona.exe (not ctfmon.exe this is a legitamate service NOTE: "ctfmona.exe" , see the "a" at the end?
2. Read Crunchie's instructions in this same thread and make sure you have combofix downloaded ( I saw you do, but just saying anyway in case someone else reads this )
3. Boot to safe mode (It would not delete from normal mode)(f8 on before windows boots and choose boot to safe mode, I chose w/o networking)
4. When Safe Mode starts Run>System32>Show hiddenfiles This is how I located the illegitamate little sucker. From my System32 File I chose View>Details then I clicked on Date Modified until it showed the most recent first. This should put ctfmona.exe pretty near the top if not right at the top. DELETE with pride!
5 At this point I ran combofix and after it ran it created the log which showed me the exact registry location of the last bit of that trojan jerk. I opened the registry run>regedit and followed the path.and deleted the entry which took it out of the startup services. That did it! Read what crunchie wrote it's super useful. Hope that helps!