search engine redirects, windows update 80072efe failure code

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kasperzak, Jun 10, 2010.

  1. kasperzak

    kasperzak Private E-2

    For about the past week I've been getting search engine redirects, and cannot update windows (80072efe error code)...malewarebytes deleted the Trojan.Hiloti, Trojan.Dropper, and Trojan.Agent.U viruses a few days ago but has been unable to detect anything since. I've done everything in the READ & RUN ME FIRST_malware removal guide (except for combofix & rootrepeal) --- I ran mgtools in safe mode and as you can see in one of the attached files, it failed to scan properly :(

    I tried posting in another forum, but this malware is blocking my abilty to post somehow. Hopefully I'll be able to post here.

    Any ideas on what my next step should be? Is combofix realy safe to run?

    p.s. I did remove the threats found in the superantispyware log.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why did you skip them? They are not optional steps to run.


    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    Why are you running in safe mode? Are you unable to boot in normal mode? You should only running in safe mode if absolutely nothing else works.

    Did you disable UAC? And did you reboot after disabling it? Please try the below now.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. kasperzak

    kasperzak Private E-2

    Sorry sir, I shall comply with your instructions...I'll have to do this tomorrow night or the weekend..

    btw, UAC is and has been disabled for a long time on my laptop.

    Thanks for your assistance.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just attach the requested logs whenever you finish and then be sure to tell me how things are working afterwards.
     
  5. kasperzak

    kasperzak Private E-2

    I just attempted to run combofix.exe

    I got this message:

    The following files were trying to attach to combofix. They shall be disabled.
    C:/windows/system32/eNetHook.dll

    Ok, I proceeded

    Then I got:

    Windows command processor has stopped working

    details

    Problem signature:
    Problem Event Name: APPCRASH
    Application Name: CF25478.cfxxe
    Application Version: 6.0.6001.18000
    Application Timestamp: 47918bde
    Fault Module Name: ntdll.dll
    Fault Module Version: 6.0.6002.18005
    Fault Module Timestamp: 49e03821
    Exception Code: c00000fd
    Exception Offset: 0004a4df
    OS Version: 6.0.6002.2.2.0.768.3
    Locale ID: 1033
    Additional Information 1: fd00
    Additional Information 2: ea6f5fe8924aaa756324d57f87834160
    Additional Information 3: fd00
    Additional Information 4: ea6f5fe8924aaa756324d57f87834160

    How shall I proceed?

    p.s. By the way, I backed up my entire hard disk on a portable hd before proceeding, so I'm safe in that regard :)
     
    Last edited: Jun 12, 2010
  6. kasperzak

    kasperzak Private E-2

    update:

    In disabling my avg9 antivirus, I followed the procedures properly, but I still find avg9emc and avg9wd still running in task manager services. I can manually stop avg9emc from running, but when I try to stop avg9wd, it says "The operation could not be completed the requested control is not valid for this service"

    Should I ignore the message or is there something more I can do?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. kasperzak

    kasperzak Private E-2

    I followed intructions to disable avg, and had turned off defender & firewall.
    Ran combofix, got the same message again

    Windows command processor has stopped working

    Problem signature:
    Problem Event Name: APPCRASH
    Application Name: CF18526.cfxxe
    Application Version: 6.0.6001.18000
    Application Timestamp: 47918bde
    Fault Module Name: ntdll.dll
    Fault Module Version: 6.0.6002.18005
    Fault Module Timestamp: 49e03821
    Exception Code: c00000fd
    Exception Offset: 0004a4d2
    OS Version: 6.0.6002.2.2.0.768.3
    Locale ID: 1033
    Additional Information 1: fd00
    Additional Information 2: ea6f5fe8924aaa756324d57f87834160
    Additional Information 3: fd00
    Additional Information 4: ea6f5fe8924aaa756324d57f87834160

    I don't know what to do now...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just continue with the rest of my instructions in message # 2.
     
  10. kasperzak

    kasperzak Private E-2

    Lol I'm sorry I'm such an idiot, I had downloaded the TDSSKiller.zip on late thursday, must have forgot to run it yesterday...

    Well I noticed my error just a while ago :-o

    So I ran it, the command window reported:

    TDSS rootkit removing tool, Kaspersky Lab, 2010
    version 2.3.2.0 May 31 2010 10:39:48

    Scanning Services ...

    Scanning Drivers ...
    File "C:\Windows\system32\DRIVERS\smb.sys" infected by TDSS rootkit ... will be
    cured on next reboot

    Completed

    Results:
    Registry objects infected / cured / cured on reboot: 0 / 0 / 0
    File objects infected / cured / cured on reboot: 1 / 0 / 1

    To finalize removal of infection and avoid loosing of data program will
    reboot your PC now.
    Close all programs and choose Y to restart or N to continue


    I rebooted, connected, and no more redirects, plus I was able to update windows :clap

    Thanks so much chas, and my remaining hair thanks you too!

    I've attached the log file in case you want to see it.

    I hope I'm done, I'll check back in later.

    Thanks again!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You should attach the requested log from MGtools (see the end of msg # 2).
     
  12. kasperzak

    kasperzak Private E-2

    MGlogs.zip is attached
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It did not run properly. Did you let it finish running? Did you see any error messages? Did you shutdown protection software first? Did you run as administrator. Try running GetLogs.bat again.
     
  14. kasperzak

    kasperzak Private E-2

    I tried again. I turned off windows defender & firewall, disabled AVG, ran getlogs.bat as administrator. Got the same error message I got yesterday:

    16 bit MS-DOS Subsystem
    C:\Windows\system32\cmd.exe\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. VDD. Virtual Device Driver format in the registry is invalid. Choose 'Close' to terminate the application.

    I read that this could happen in Windows 2000 or XP, but I have Vista Home Premium:confused
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like you are having problems with Windows itself that may not be due to malware.

    Also, please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1

    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :reg
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  16. kasperzak

    kasperzak Private E-2

    systemlook.txt attached
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Are you having any problems on your PC at all other than potentially running MGtools?
     
  18. kasperzak

    kasperzak Private E-2

    Okay, mglogs.zip is attached.

    I would say my computer is more sluggish lately, sometimes ie has non-reponding errors, yesterday when I closed browser windows, it would take several seconds before they would actually close. This online session seems ok...so far...
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is likely due to the fact that you have an inadequate amount of memory to run Vista and your free hard disk space is getting to low. You logs show
    Code:
    Total Physical Memory 765 MB 
    Available Physical Memory 97.8 MB 
     
     
    Drive C: 
    Description Local Fixed Disk 
    Compressed No 
    File System NTFS 
    Size 69.78 GB (74,924,072,960 bytes) 
    Free Space 8.75 GB (9,400,438,784 bytes) 
    
    We recommend at least 2 GB of memory for Vista and you have less than half that amount and having only approximately 98 MB free is simply not acceptable.


    You need to uninstall Spybot - Search & Destroy 1.5.2.20 which is old and outdated.


    Delete the below files:
    C:\Users\Roy\AppData\Local\Sqonaliko.bin
    C:\Users\Roy\AppData\Local\Xfaduje.dat
    C:\yvikit.vlr


    Also to cleanup some additional disk space, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.


    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. kasperzak

    kasperzak Private E-2

    Followed intructions in your 2 previous posts, UAC is now enabled (I disabled it shortly after getting my laptop almost 3 years ago, guess I'd been lucky up till now)

    Restore point toggled, new restore point created.

    I cannot however uninstall combofix, the combofix file is on my desktop, when I run
    "%userprofile%\Desktop\combofix" /uninstall

    I get the message:
    windows cannot find 'C:/Users/Roy/Desktop/combofix' make sure you typed the name correctly and try again.

    by the way, Combofix is not listed in control panel>programs & features

    As I recall, I never got combofix to run properly...
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According the the MGlogs.zip file you attached, ComboFix.exe is not on your Desktop.

    It does not install as a Windows installed program. Neither does MGtools. ;)

    Then you would not need to run the uninstall for it. But your logs showed that you did run ComboFix to some extent because there was a C:\QooBox folder created by ComboFix when it saved backups. If you ran MGclean.bat, it will cleanup combofix files anyway.
     
    Last edited: Jun 16, 2010
  23. kasperzak

    kasperzak Private E-2

    Chas, just wanted to let you know that things have been running smoothly (well as smoothly as possible with insufficient ram) I've cleared some hd space, and getting used to working with UAC to keep safer.

    One odd side effect of this purging was my CDBank Catalogue program, it had about 100 DVDs catalogued, but only 3 remained after this. I should have saved an archive:-o

    Unfortunately, Acer bundled Vista Home Premium with my 1mb laptop, even though it was not appropriate for that amount of memory...I used a usb stick with ready boost, but I knew it was a poor substitute. You'd think these companies would be more responsible in their choice of the OS they install...rolleyes

    Well, thanks so much for saving my butt, I've never had such problems in 11 years on the internet, I'll try to stay out of trouble :-D
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You mean 1 GB. ;) Was enough for original Vista with no other software but will not suffice for updated Vista and other software. However you really did not have 1 GB for use by Windows. You appear to have an built-in video graphics card that is stealing 256 MB of memory from this 1 GB because the cheap graphics card did not have its own memory.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds