Post virus headache

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by redclanger, May 27, 2009.

  1. redclanger

    redclanger Private E-2

    Stoopid me got a virus yesterday. I scanned the file with McAfee before opening it - it found nothing but it infected my PC once I opened it. McAfee dealth with (at least some of) the threats as they appeared but my problems are not over. I did a deep scan which found more viruses and trojans and dealt with those. I then had problems starting Explorer as 'Data Execution Prevention' kept closing it. When I did get it, McAfee was reporting problems with files I know are clean - one was on a CD-ROM so could not have been infected. I turned off McAfee so at least my PC is usable but after a further reboot, I enter my password and then wait for ages before I get the message - 'The instruction at 0x0070068f referenced memory at 0070068f. The memory could not be 'written' press OK to stop the program and cancel to debug.' When I press OK, the computer does not do anything - it seems to stop booting but does not do anything else either - although I would not say it has hung.

    Another symptom is that when running in safe mode with network (as I am now) I cannot access the Windows Update site or McAfee's site.

    PS - McAfee in my opinion is rubbish and it is only on here because it is my work PC and came with it.

    I am running Windows XP SP3

    Please advise.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. redclanger

    redclanger Private E-2

    Thanks for the welcome.

    I have now followed the instructions and attach the logs.

    I am now able to boot the computer but I am still getting the same 0x0070068f error message on start up. I was unable run to combofix which deleted itself when I tried (I am running 32 bit). I also tried to install Microsoft.NET Framework 1.1 (although I think it is already installed) following the relevant error message but the set up 'ended prematurely'.

    One new curiousity is that Windows is reporting that it cannot find antivirus software - McAfee is still running and on-access scan is reenabled.

    Thanks
     

    Attached Files:

    Last edited by a moderator: May 27, 2009
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
    Last edited by a moderator: May 27, 2009
  5. redclanger

    redclanger Private E-2

    Nope - made no difference whatsoever - sorry. Attached is the log.

    One thing though - with this and the old version, I could not get it to check for updates. It seemed to think it was not connected to the internet. I have even expressly permitted it in the Windows Firewall - all this laptop has!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)


    1.
    Please go to Add/Remove programs and uninstall the following old version of java software:

    • Java(TM) 6 Update 6
    • Java(TM) 6 Update 7
    • Java(TM) 6 Update 11


    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.


    3. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Run Ccleaner!

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP
    • C:\Documents and Settings\stac076\Local Settings\TEMP
    • C:\TEMP

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. redclanger

    redclanger Private E-2

    Problem 1

    I have turned off all the protection that I can but McAfee's 'Disable On-Access Scan' is greyed out and I cannot access the McAfee website from this computer - I can from my partners but I do not have the codes to access anything on the website.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this and let me know how you get on.

    • Go to the console
    • Hit the properties for Access Protection
    • Look at the bottom of the window for a check box that says "Prevent McAfee Services from being stopped". Clear the checkbox

    Then continue on with my previous instructions :)
     
  9. redclanger

    redclanger Private E-2

    The Registry Key to delete line did not execute. I have attached the log. I shall not follow the remaining steps at this stage.

    Thank you very much for your help so far.
     

    Attached Files:

  10. redclanger

    redclanger Private E-2

    Sorry - just seen this - no such option in properties unfortunately!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    just continue on now with everything else, and get me the C:\Mglogs.zip :)
     
  12. redclanger

    redclanger Private E-2

    Right done - although did do the Java and the reboot the wrong way round now I have reread the instructions to make sure I did not miss anything out so I hope that was not too crucial!

    I got the following error running GetLogs.bat:
    "Process.dll.exe - Application Error
    The application failed to initialize properly (oxc000007b)..."
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please download a fresh copy of combofix from the following link COMBOFIX make sure that the combofix.exe has been downloaded to your desktop!

    2. Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. Now let's see if the below will work for us with ComboFix, (if it does NOT and you still cannot get it to run, move on to my Avenger instructions towards the end of the post.)

    Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\2.tmp
    C:\WINDOWS\system32\4.tmp
    C:\WINDOWS\system32\5.tmp
    C:\WINDOWS\system32\bekbn.dll
    C:\WINDOWS\system32\fkas
    C:\WINDOWS\system32\inform.dat
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10C0B0C0-FC01-473b-8EBB-4376353F96E4}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    4. Now run Ccleaner!

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    ............................................................................


    Avenger instructions should Combofix fail us again.




    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now follow steps, 4 5 and 6

    Attach the log from running either combofix, avenger, and also the new Mglogs.zip.
     
    Last edited by a moderator: May 29, 2009
  14. redclanger

    redclanger Private E-2

    Hi Kestrel

    Thanks for your continued help.

    An update, as of this morning, I can only bootup in Safe Mode (currently in safe mode with networking) When I try to boot up normally, I can a sequence of those write errors and explorer does not load so I get a blank desktop - no icons, no bottom bar. When I try to enter task manager, I get the same (or similar0 error messages. As an aside, Windows keeps trying to reinstall one of the corrupted software packages (the 2Simple stuff - I am a primary school teacher).

    In response to your post above.

    Combofix still will not work.

    Avenger still did not like the hkey instruction. I have attached to avenger log and the mglogs.zip.

    You are a very patient person! Thank you.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please before we continue with the below I would like for you to copy the fix and then physically pull out your cable and disconnect from the internet...


    1. Please disable all anti-virus and anti-spyware before we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2. Now we need to kill off some bad services, so I would like for you to do the below:

    Open notepad and copy and paste the following text in the quote box into the window:

    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    3.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Let's run a reg patch:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    5. Now Run Ccleaner on both cleaner and registry options. Back up when prompted before fixing issues.

    6. Now empty what temp files windows allows you to in the below bold folders:

    • C:\WINDOWS\Temp
    • C:\Documents and Settings\stac076\Local Settings\TEMP

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  16. redclanger

    redclanger Private E-2

    Thanks for that lot - the procedures seemed to run smoother - the only error message received was during GetLogs when I got a ProcessDll.exe Application Error - 'failed to initialize properly 0xc0000076'.

    On restart, I still got instruction errors relating to 0x0086068f and 0x0094557f and application errors relating to rundll32.exe, dwwin.exe and explorer all referencing 0xc0000005 and I am still running only in safe mode with networking. One development is though that the wireless network is stuck at acquiring network address - I have tried a right click repair and it is stuck at renewing ip address.

    I have attached the various log files - I may have attached to many trying to make sure I attach the right ones. (edit - bacup.zip is reported as being too large to attach)

    Thanks
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    2.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    3. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\stac076\Local Settings\Temp

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  18. redclanger

    redclanger Private E-2

    *&^&*(*%£!!!!!

    Attached are logs. After I ran avenger, the computer crashed on restart a couple of times - even when starting in safe mode with networking. It booted into safe mode only and I restarted it again so that avenger did a full run through - it has restarted into full windows - but with the same errors as before. It is still failing to connect fully to the network and is still getting stuck on acquiring network address.

    Due to lack of network connections, I typed up the avenger instructions - there was an error during the hkey instruction - contained in the log. I am pretty sure that I typed them up correctly, everything was double checked before is was executed.

    In your opinion, is there any light at the end of this particular tunnel or will New Win32 just keep outfoxing us and every turn leading ultimately to a reformat and reinstall?

    Thanks again
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The light at the end of the tunnel has gone out. :(

    Your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     
  20. redclanger

    redclanger Private E-2

    Will do - thanks for all your efforts guys.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry we couldn't do more. This is a nasty virus and as yet there is no known solution other than a reformat. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds