Problem with malware removal process

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trogladyte, May 18, 2010.

  1. trogladyte

    trogladyte Private E-2

    Hello, and thanks for taking the time to help.

    I satarted off in the drivers forum, as my wife's laptop's wireless has died, and the helper there thought there may have been a malware problem.

    I've been running through the process - Superantispyware found a couple of things, and Malwarebytes also found a few. I got as far as running Combofix, but whe Combofix restarted the machine it hung on the login screen. I left it for half an hour but it wasn't doing anything so I turned it off - no other keys were having any effect. When it restarted Combofix continued and produced a log.

    When I then went to run rootrepeal, i got an error: "illegal operation attempted on registry key that has been marked for deletion". Norton Internet Security also gets this error if a scan is attempted and also says "Norton Internet Security has encountered an internal scanning error. 0x8000405.

    Attempting to run MG Tools also produces this error.

    I'd be really grateful for your advice.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the logs that you have. SAS, MBAM, ComboFix.
     
  3. trogladyte

    trogladyte Private E-2

    Hi Tim

    I'm struggling to do that at the moment, as I can't open IE. I'm using my PC to post this. I was just going to try running SFC/Scannow from a safe mode command prompt. What do you think?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can transfer then to another computer and then attach them. As for running sfc /scannow ( note the space), it may or may not help.

    I would rather see the logs you have.
     
  5. trogladyte

    trogladyte Private E-2

    OK I seem to have functionality on the laptop again.

    Here are the logs.

    Well here's combofix anyway. Hang on will try again with the others.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in that Combo log. Can you now run MGTools?
     
  7. trogladyte

    trogladyte Private E-2

    Here are the other logs.

    I will try MG tools.

    I have also lost wired internet connectivity. Diagnostics say that the Realtek ethernet adapter has driver or hardware issues. It was running before the combofix crash.
     

    Attached Files:

  8. trogladyte

    trogladyte Private E-2

    Here's the MG tools log.

    Was thinking about deleting the ethernet card in device manager and lettingit find it and reinstall - would you agree?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can open SAS / go to preferences / repairs and scroll down to the fix for you network. See if that helps. In the meantime, I would like to see the C:\MGlogs.zip when you are ready.

    EDIT: Yes, you can try deleting the drive and then rebooting.
     
  10. trogladyte

    trogladyte Private E-2

    I've got a lot of exclammation marks on the network adaptors - it says "Windows cannot start this device because its configuration information (in the registry) is incomplete or damaged (code 19).
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. What malware issues are you having?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to reinstall those drivers. I am not seeing anything in your logs that may have damaged them.
     
  13. trogladyte

    trogladyte Private E-2

    Device manager won't let me uninstall them.
     
  14. trogladyte

    trogladyte Private E-2

    This was my original post in the drivers forum, which explains the original problem. The helper there thought it might be a malware problem:

    My wife's Compaq Preasarion A900 laptop running Vista will not connect to wireless. I think this may be an issue with NDISUIO.SYS.

    Yesterday we were getting an error on bootup: "- LogonUI.exe Bad Image: WTSAPI32.dll is either not designed to run on Windows or it contains an error" Few programs would run, and there was no networking. Safe mode was much the same. I ran SFC/scannow from a command prompt, and that reported that it had fixed some but not all system files.

    On reboot everything was back to normal except wireless. The wireless light is on, but Windows cannot find any wireless networks. Running the diagnostic reveals Windows wireless support is not on. But attempting to turn it on says Windows cannot fix the problem.

    The CBS log reveals the file that cannot be restored to be NDISUIO.SYS. It says that the file in store is also corrupted. This looks like a prime candidate for my problem, as I think its part of the zero configuration wireless support.

    Is it possible to restore this file from a remote location? If its available I could d/l to my desktop, and transfer to the laptop on a pen drive or something.

    Any help or advice would be appreciated - the wife is...slightly stressed.
     
  15. trogladyte

    trogladyte Private E-2

    Is it worth me trying to go back to s system restore point?
     
  16. trogladyte

    trogladyte Private E-2

    System restore won't complete succesfully...:cry:(
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  18. trogladyte

    trogladyte Private E-2

    Thanks Tim

    I'll try that. I at least have wired internet back. I had to delete the actual hardware adapter and Vista reinstalled it. I still have exclamation marks, but the laptop now connects when wired to router.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Best to go to the manufacturers web site and download your drivers from there.
     
  20. trogladyte

    trogladyte Private E-2

    Tim

    Having looked more closely, I think I have already done the registry fix for the wireless zero configuration service when I was being helped in the Drivers forum.

    Is the laptop now free of malware as far as you can see?

    Will you continue to help me to try to restore the wireless connection, or should I go back and pick up where I left off in the Drivers forum?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could continue this in the drivers forum. If it works hard wired, then one other option is to see if you can use a USB Wifi device to connect wirelessly. Esp. if you have deleted it already and that didnt fix it when you next booted up.
    Yes, I did not see any malware in your logs.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  22. trogladyte

    trogladyte Private E-2

    Thanks for your help Tim. I really appreciate it.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I just noticed that Combo erroneously removed two of your driver files. Let's put them back and then see if your wireless begins to work.
    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    DeQuarantine::
    C:\Qoobox\Quarantine\c:\windows\system32\drivers\snetcfg.exe.vir
    C:\Qoobox\Quarantine\c:\windows\system32\ndisapi.dll.vir
    C:\Qoobox\Quarantine\C\Windows\System32\drivers\Ndisrd.sys.vir
    Quit::
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Tell me if your wireless is working now.
     
    Last edited: May 23, 2010
  25. trogladyte

    trogladyte Private E-2

    Well I did that, Tim. But the process wasn't quite what I expected. Combofix ran through its full scanning routine, and then rebooted the machine. On reboot Windows Update kicked in, and tried and installed some updates, and then rebooted the machine again. On restart Windows update said it was configuring updates, but failed, and reversed the changes and then restarted again. Combofix kicked in after the final restart and produced a log.

    Windows now seems desperate to configure updates on boot up, but gives up after 25% on stage 1 of 3.

    It's a mercy that I'm such a patient man.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You hadn't removed Combo yet? In that case, attach the latest Combo log. And re-run MGtools to get a new log of that also.
     
  27. trogladyte

    trogladyte Private E-2

    Update

    miracle of miracles, Windoze update has successfully configured its updates.

    Still no wireless.

    Do you want to see the Combo log?
     
  28. trogladyte

    trogladyte Private E-2

    Yes, I'd removed Combo. But I reinstalled it.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you still have the quarantine folder? I would like to see that.
     
  30. trogladyte

    trogladyte Private E-2

    Where would that be and what's it's name?
     
  31. trogladyte

    trogladyte Private E-2

    Here's the combo log
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nah, too late. The quarantine file would be here if it still existed:
    C:\Qoobox\Quarantine\


    I think you will need to continue to try to replace your wireless drivers. Best to go to the manufacturers website and download them from there.
     
  33. trogladyte

    trogladyte Private E-2

    Ive got that directory. It contains an empty folder called C, a folder called registry backups and two files called "catchme" but they are all dated 23/5.

    I think I replaced the drivers anyway, as I deleted the cards when I lost wired connectivity and forced a reinstall. Driver updae says they are the latest, but I'll see what Halo thinks in the drivers forum.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that is the most recent quarantine folder from this latest run, not the one that shows the wrong drivers being removed. I will watch the drivers forum to see if you get running again.
     
  35. trogladyte

    trogladyte Private E-2

    Hi Tim

    I haven't had a reply to my thread in the Drivers forum for a while. Could it be that Halo thinks you are dealing with it? Should I bump it or wait?
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have passed this along to Halo. Hang in there. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds