services.exe 1073741482 error

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Medowolf, Sep 21, 2009.

  1. Medowolf

    Medowolf Private E-2

    Hey guys,
    I have a problem that I've seen others have. Each time I started up I get the message:

    The system is shutting down.
    Please save all work in progress and log off.Any unsaved changes will be lost.
    This shut down was initiated by NT\AUTHORIYSYSTEM Time before shut down(then a countdown starts at 1:00)
    Message The system process 'C:\WINDOWS\SYSTEM32\services.exe' terminated unexpectedly with status code -1073741482.The system will now shut down.)

    I've followed your READ AND RUN ME FIRST and so far only CCleaner was the only one that ran in safe-mode. I couldn't even log in Normal mode. MAM installed but shutdown after 2 seconds. It wouldn't even startup afterwards, just got the message:

    Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.

    So I went on so ComboFix.
    When it started its scan it said:

    Could not find C:\Combo-fix\Update-CF.cmd

    Scan then starts. It then backs up the registry and pops up saying I don't have "Microsoft Recovery Console" installed do I want to download it. I select no since there is no internet connection.

    It then continues the scan. After a few seconds it pops up saying ComboFix has detected rootkit activity and has to restart windows, displaying the following files:

    C:\windows\system32\drivers\UACyqbarmpfqh.sys
    C:\windows\system32\UACrnmqwiyuyf.dll
    C:\windows\system32\UACetkixnssae.dat

    When windows restarts the primary problem is gone. I could load into normal mode. As I do, ComboFix continues onces my desktop has loaded. It goes through the same process as before and ends the same way.

    I tried my wi-fi to see if it would download the recovery console yet it tells me:

    Cannot find RC-CF.cmd

    Now my Laptop is stuck in a loop. Once I start it up ComboFix just restarts displaying the same 3 files.

    Need some help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You made no mention of running MGtools which is the last scan in the READ & RUN ME. You need to run this and attach the log. Also if ComboFix made a log, attach it.

    Also run the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.


    Also run the below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r
     
  3. Medowolf

    Medowolf Private E-2

    Hey thanks for getting back to me.

    I finally got ComboFix to run through and obtain a log. It asked for the recovery console which wasn't installed. I had to download let ComboFix install it, which spat out another log. I included both plus a third which I will explain in a bit.

    Ran MGtools next and got the log.

    Ran Root Repeal and obtained the log from that.

    I tried the online SAS online scan. It started alright but I soon got bombarded by more viruses as the previous problem (services.exe error) had shut down my antivirus.
    That is the reason for the third ComboFix log. No other programs wouldn't run. Kept getting the message that the application was infected. ComboFix was the only one that started.
    Before running Combofix the scan had found a couple of things.

    Adware.Vundo/Variant-Broad
    Adware.Vundo/Variant-QHeader
    Trojan.Vundo-Variant/NextGen

    I didn't have time to check what they were since my computer was saying everything was infected.

    I reran the SAS I downloaded and found 2 infections. Both from the same file.

    Adware.Vundo/Variant-EC
    C:\Windows\System32\ZIDOYOWI.DLL

    I also noticed a strange file hiding in my system32 folder. It seems to be loading everytime I boot up.

    sotepoye

    There was also another file there that has been there since this whole mess started.

    nzfiu3h78di.dll

    Each time I restart I get the message
    Cannot load ZIDOYOWI.DLL specified module could not be found

    The other problem that I have is that i cannot open My Computer from the start menu. The only way I can access my files is by going through the My Music shortcut.

    Thanks for your time.
     

    Attached Files:

  4. Medowolf

    Medowolf Private E-2

    Here the rest of my logs.
    Thanks again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {0a40542f-b374-41f6-adb3-225e69934169} - nuwilofo.dll (file missing)
    O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
    O4 - HKLM\..\Run: [gofoduven] Rundll32.exe "c:\windows\system32\manuhavi.dll",a
    O21 - SSODL: suyutarig - {387dbfcd-3cca-45ef-a59c-7e41dc896711} - c:\windows\system32\manuhavi.dll
    O22 - SharedTaskScheduler: kupuhivus - {387dbfcd-3cca-45ef-a59c-7e41dc896711} - c:\windows\system32\manuhavi.dll
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common
    Files\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2009
    \vsserv.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Medowolf

    Medowolf Private E-2

    Sorry I took awhile to get back to you. My internet was down for a few days.
    I ran MGTools and didn't see the lines that you told me to select. None of them were.
    Might be because I reinstalled my Antivirus.
    I took a log from MGTools so you can see what I mean.
    I'll wait until you check this log out before I do anything else.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you now reinstalled BitDefender which you previously had uninstalled but not completely. Thus we cannot continue with the previous fix since you changed your system and the previous fix I gave would break BitDefender. Remember our instructions in the READ & RUN ME did say that once you begin, that you must not do anything other than what we ask you to do.

    You will noe need to run MGtools again and attach a new log before we can continue.
     
  8. Medowolf

    Medowolf Private E-2

    Sorry about the antivirus thing. I just needed the protection when i'm away from home.
    Here's the new log.

    Thanks again.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Begin by uninstalling the below left overs from Symantec:
    LiveReg (Symantec Corporation)
    LiveUpdate 1.80 (Symantec Corporation)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {b891f0f9-b225-41e1-9362-e9613b648fd1} - luhuwuji.dll (file missing)
    O4 - HKLM\..\Run: [vuyojupota] Rundll32.exe "zidoyowi.dll",s

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\SuperPawn\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Medowolf

    Medowolf Private E-2

    Hey, thanks for the help.

    Ran the scans you told me to. Everything seems to be okay now. The only thing I noticed when ComboFix was done, was that "beep.sys" was still missing.

    Here are the logs you asked for.

    Another thing I forgot to mention was that when I ran Combofix for the very first time, it said that a few of my system files were corrupted. It asked for a system disk, yet I didn't have one. I just went ahead and continued and didn't see which files they were. Is there any way to find out which files they might be?

    Thanks again for all the help.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we still need to fix this which the below should do.


    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Medowolf

    Medowolf Private E-2

    Hey chaslang thanks for all the help.
    Everything is running fine. I see no other problems.
    Here are the logs you wanted.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds