Cannot Run Applications - Avira Detects Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fjccommish, Jan 25, 2011.

  1. fjccommish

    fjccommish Private E-2

    This problem began Monday evening when the computer was booted. Applications will not run, give an error message:

    "The application failed to initialize properly (oxc0000022). Click OK to terminate the application,

    Avira pops up a malware warning:

    "Virus or unwanted program TR/Patched.JS was found in file c:\windows\sysWOW64\ws2_32.dll"

    Avira then performs a scan and claims to quarantine the offending file.

    When Avira isn't running programs run without problem.

    I ran the process described in the read me. Could not run combofix or rootrepeal because the system runs on Win XP 64-bit. The logs are attached.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you downloaded the current version of ComboFix, it does run on 64 bit systems.

    What malware issues are you having? I am not seeing any malware in your logs.
     
  3. fjccommish

    fjccommish Private E-2

    These are the instructions provided (linked) in the read and run first thread:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    "At this time ComboFix can only run on the following Windows versions:

    Windows XP (32-bit only)"

    When combofix is downloaded following the instructions in read and run first, then run, it returns an error "Error - Win32 Only. Incompatible OS. Combofix only works for workstations with Windows 2000 and XP."

    Is there a different version besides the one mentioned in the read and run first thread?

    The issue is that when avira is running no applications run. They return the error:

    "The application failed to initialize properly (oxc0000022). Click OK to terminate the application,

    Avira pops up a malware warning:

    "Virus or unwanted program TR/Patched.JS was found in file c:\windows\sysWOW64\ws2_32.dll"

    Avira then performs a scan and claims to quarantine the offending file.

    I cannot run any programs on the system. Nothing will run - Firefox, MSN Messenger, audio programs, games, video viewers - nothing. The system is useless because no applications run.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but not on Windows 2003 which this user is running. ;)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have Win XP. You have Win 2003.
     
  6. fjccommish

    fjccommish Private E-2

    "Yes but not on Windows 2003 which this user is running."

    No, the operating system is Windows XP Professional, 64-Bit.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry. I just looked at your HijackThis log and it reported >> Platform: Windows 2003 SP2 (WinNT 5.02.3790)


    Your sysinfo.txt log does report >> OS Name Microsoft(R) Windows(R) XP Professional x64 Edition

    Is the ws2_32.dll file coming up in new scans as still being infected? If yes, do you have your XP Pro x64 boot disk and you may need to boot to the Recovery Console to replace it with a clean copy.
     
  8. fjccommish

    fjccommish Private E-2

    That's odd. Maybe XP 64 s based on Win 2003?

    I don't think I have a boot disk. Is there a place to download a clean boot disk to perform this operation?

    The only program reporting issues with ws2_32.dll is avira. When programs try to run there is the error, avira pops up the warning, then scans and cleans the file.

    Nothing else finds it. If avira isn't running there are no problems.

    I've removed avira and installed Comodo, which detects no problems.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please get this: ws2_32.dll into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    Also...

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\sysWOW64\ws2_32.dll
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
     
  10. fjccommish

    fjccommish Private E-2

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your XP Pro x64 boot disk? The file is infected and needs replacing.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Already asked and answered in messages 7 & 8. ;)
     
  13. fjccommish

    fjccommish Private E-2

    Is there a location to download a clean version of that file?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You need your XP Pro x64 boot disk. Another possibility may be that updating to Service Pack 3 could update it.
     
  15. fjccommish

    fjccommish Private E-2

    I found the Win XP Pro 64 CD. Not sure how to replace the file from there because when in windows, browsing that CD shows ws2_32.dl_.

    What are the steps for creating a boot CD (if by that you didn't mean boot using the Win XP 64 Pro CD) and then replacing the corrupted file?
     
  16. fjccommish

    fjccommish Private E-2

    Booted to safe mode with command prompt.

    Extracted ws2_32.dl_ to the c:\windows\sysWOW64\ws2_32.dll.

    Whereas before if Avira was running applications wouldn't run, now even with Avira not running applications won't run.

    "The application has failed to start because ws2_32.dll was not found."

    Yet it's there, and it was taken from the Win XP 64 Pro installation CD.
     
  17. fjccommish

    fjccommish Private E-2

    Seems to be fixed after running sfc /scannow.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are happy to hear you have it fixed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. fjccommish

    fjccommish Private E-2

    No more WS2_32.dll errors, but the browsers still crash (Firefox, IE, Opera) upon visiting certain sites such as this one.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds more like an issue with the browsers themselves or add-ons. Close all Firefox, Opera, and Internet Explorer sessions. Also exit any other unnecessary applications. Then right click on your IE icon and select Start Without Add-ons

    Does that work any differently?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds