Combofix Hangs entire PC/Can't access Bleepingcomputer site

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tassadaru, Jan 13, 2013.

  1. Tassadaru

    Tassadaru Private E-2

    Greetings to all!

    I have fought with an so-called infection which keeps me from doing what I want on my PC.

    It all started today morning with World of Warcraft failing to run. Every time I tried to start the game, the game would crash with an access violation error.

    After researching the error online, it seemed that I was infected with malware. Tried downloading combofix from bleepingcomputer, to no avail. I couldn't access the site (worked fine from my phone though, so it was something on my PC that was blocking the site)

    After downloading from an alternate, I tried to run Combofix, which I used in the past with excellent results on several computers - to no avail. The damn thing wouldn't run to 100% if I put wheels on it. Every damn time, in Normal or Safe mode, it ran 'till the software showed "Scan times may easily double on heavily infected machines", then it would stall.

    And in stalling, I mean: no hard disk activity, no CPU activity, Windows desktop, taskbar, everything non-responsive, the "three-finger-salute" wouldn't work at all. All that could be done is "cold reset".

    So I installed SAS and MBAM, scanned with them, nothing really popped up, but problem was still there. ComboFix won't run, bleepingcomputer was inaccessible.

    I tried some of the alternate scans, and came across GMER. After running gmer, it detected some FPService stuff if I remember correctly (can't find the damn log), and popped up a notification that some Rootkit system modification has been found. All dandy, I stopped the red-highlighted service and deleted it, and as I did, *POOF*, blue screen by some randomly named .SYS file, let's call it asghduangya.SYS. It really was random, I can't remember it even if you killed me. And no, there's no damn .DMP file so I could see it.

    Anyway, after recovering from the BSOD, I ran a GMER scan again, and nothing was found resembling a rootkit. "Good", I said. Not really. Bleepingcomputer was still inaccessible, Combofix would still lock up my entire system.

    Let me explain how this lockup occurs as best I can: I run Combofix, it starts by trying to create a restore point. Since I don't use Restore, it stalls there for 15'ish seconds, then moves on to Scanning and that the scan could double on heavily infected machines. After that, (i left my AIMP playing), first, the network goes POOF, then AUDIO driver dies (and player freezes), then everything becomes unclickable, and CtrlAltDel doesn't work anymore. Hard drive stalls from activity and that's it. I have to give it the button salute.

    Now, I scanned my sistem as of writing this with OTL (and in Safe mode today morning as well) and MGtools so I shall label the scans accordingly by Morning and Night. Please note that Morning logs have been generated in Safe Mode, while Night logs (the most recent ones) were done now, last, during a Normal boot. Also, attached is a MBRcheck log from today morning.

    Please let me know what I can do to restore my computer to it's former glory (lol), and Windows functionality to it's default parameters so I can access bleepingcomputer and combofix would run. Also, don't know if it's related or not, but my Windows Update keeps installing the some same 2-3 updates over and over and over again, indefinately. I have disabled it for the time being.

    I would really appreciate your help, and would very much love to resolve this issue without having to reinstall my OS. I know it's Windows 7 32 bit and I have 4 gigs of ram, and so on and so forth, but there's lots of stuff installed and for now, I do not wish to reinstall my OS, until I get new hardware in the coming months.

    Thank you once again for your attention and time, and for your replies, and will look forward to hearing from you in the forseeable future to maybe solve these issues and kill the stuff that's making my computer go berserk.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Tassadaru

    Tassadaru Private E-2

    Here are the scan logs. Sorry for skipping them.

    There are 2 mbam logs, one from this morning, and one from tonight.

    Again, thank you so much for assisting me.
     

    Attached Files:

  4. Tassadaru

    Tassadaru Private E-2

    Sorry for the late reply, seems like SAS did a lil' midnight scan and found something.

    Code:
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com
    
    Generated 01/14/2013 at 02:49 AM
    
    Application Version : 5.6.1014
    
    Core Rules Database Version : 9865
    Trace Rules Database Version: 7677
    
    Scan type       : Complete Scan
    Total Scan Time : 00:47:54
    
    Operating System Information
    Windows 7 Ultimate 32-bit, Service Pack 1 (Build 6.01.7601)
    UAC On - Limited User
    
    Memory items scanned      : 788
    Memory threats detected   : 0
    Registry items scanned    : 47276
    Registry threats detected : 8
    File items scanned        : 70870
    File threats detected     : 3
    
    Adware.Tracking Cookie
    	C:\USERS\TASSADAR\AppData\Roaming\Microsoft\Windows\Cookies\IC3ZO9PR.txt [ Cookie:tassadar@yashi.com/servlet/ajrotator/track/pt1193884 ]
    	C:\USERS\TASSADAR\Cookies\IC3ZO9PR.txt [ Cookie:tassadar@yashi.com/servlet/ajrotator/track/pt1193884 ]
    
    Trojan.Agent/Gen-Nullo[Short]
    	HKLM\System\ControlSet001\Services\WINFPDRV
    	C:\WINDOWS\SYSTEM32\WINFPDRV.SYS
    	HKLM\System\ControlSet001\Enum\Root\LEGACY_WINFPDRV
    	HKLM\System\ControlSet003\Services\WINFPDRV
    	HKLM\System\ControlSet003\Enum\Root\LEGACY_WINFPDRV
    	HKLM\System\ControlSet004\Services\WINFPDRV
    	HKLM\System\ControlSet004\Enum\Root\LEGACY_WINFPDRV
    	HKLM\System\CurrentControlSet\Services\WINFPDRV
    	HKLM\System\CurrentControlSet\Enum\Root\LEGACY_WINFPDRV
    
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You really should not have utorrent running at start up. It opens your system to everyone.

    Re-run RogueKiller and click on the DNS tab and have it fix your DNS>

    Tell me what issues you may still be having, if any.
     
  6. Tassadaru

    Tassadaru Private E-2

    I used my custom nameservers from the router settings/ISP given ones via pppoe. --- That is fixed.

    My problem is I cannot access bleepingcomputer.com still :|
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, your logs are clean. Have you tried different browsers? Is that the only web site you can't access?
     
  8. Tassadaru

    Tassadaru Private E-2

    Greetings.

    Yes, I have tried different browsers and reinstalling browsers and running browsers without addons. That's the only site I tried and didn't work on my PC and works on my phone.

    Also, Combofix still hangs the entire PC after it starts scanning, as described in the original long message.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what to tell you. Combo fails on a number of systems. We can try one other thing:

    eSet Online Scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds