A nasty infection or corruption?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lostdata, May 15, 2011.

  1. lostdata

    lostdata Private E-2

    Hi, I have been having a lot of problems (please see: http://forums.majorgeeks.com/showthread.php?p=1623579), I’ll repost the problems here if necessary but I would like to ask a question first. I’ve tried the read and run me section first and combofix won’t load, I get a message (windows 7) that combofix isn’t commonly used and I’m blocked for my “protection”, SUPERAntiSpyware and Malwarebytes Anti-Malware downloaded apparently fine. Should I proceed without combofix or is there a way to download it. Thanks
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try renaming combofix.exe to mandarin.com and try running it again. If you still have a problem try safe mode. Still no joy then yes, skip the step.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Has UAC been disabled as instructed? A reboot is required after disabling. And has your protection software also been disabled.
     
  4. lostdata

    lostdata Private E-2

    This problem started about 4 days ago, I installed the following updates KB2529073, KB890880, KB2534366 automatically when I closed down my PC. The next day I noticed I couldn’t play WMV video files but other media seemed unaffected, so I installed the next windows update hoping it would fix the problem (KB2533552), but it didn’t. I started downloading the latest definitions for Norton internet security 2011 as I thought a scan would reveal any problems. When Norton tried to install the updates it reported that I had no protection and started downloading 97MB to fix the problem.
    Next I tried system restore, but I couldn’t restore past the critical updates. I tried SFC /scannow to see if a file had become corrupted and they had, some were fixed but others weren’t (see attachment sfc.txt). After SFC I tried playing WMV files and they played fine but explorer froze and reported that Symantec framework (at least that’s what I can remember) had stopped working. Upon restart, explorer worked but the video files wouldn’t play.
    I decided to find out if malware was to blame and downloaded the tools from majorgeeks. Downloading was managed by a pop-up on the base of explorer that looks like its part of Norton (but I'm not sure), it warned that combofix and MGTools were potentially dangerous but at the same time the Norton Insight pop-up said they were fine. I had to re-download combofix during the cleaning procedure as the first download said I couldn’t access the C:\ folder on execution, I also had to re-download MGTools mid-process as I couldn’t download into the root directory the first time. Please note I’m not sure if combofix was 100% successful, as I think I failed to fully shut off Norton during stages 1-5.
    During the cleaning process I also got some messages that may be useful(
    Before the cleaning process I tried to create a restore point and got the following message “C:\Windows\system32\srrstr.dll is either not designed to run on windows or contains an error”
    After I used Malwarebytes and tried to save the log, this message was displayed “notepad bad image C:\Windows\system32\NetworkExplorer.dll is either not designed to run on windows or it contains an error”
    And after I ran comobofix I was promted to make explorer by default browser.)
     

    Attached Files:

    • sfc.txt
      File size:
      6.8 KB
      Views:
      8
  5. lostdata

    lostdata Private E-2

    I’ve attached to log files to this post. I didn't run RootRepeal as my copy of windows 7 is 64 bit.

    Also during the MGtools execution, a hijackthis window opened and I clicked the accept button. Was I supposed to do this? I've just noticed that was mentioned under the instructions for all other windows users, not under the windows 7 MGTools instructions.
     

    Attached Files:

  6. lostdata

    lostdata Private E-2

    Hi, I’ve just noticed some strange files, I don’t know if they’re important but I’ll add the details in case they help with diagnosing the problem. The desktop has 2 copies of desktop.ini files and they have identical names which I thought was impossible, I had hidden files visible before this process and I’ve never noticed them before.

    One copy contains “ [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183 ”

    While the other contains “ [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
    [LocalizedFileNames]
    Norton Internet Security.lnk=@C:\PROGRA~2\NORTON~2\Branding\muis.dll,-102”

    There are also desktop.ini files in other directories, including the video library which contains two copies
    One contains “[.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21791
    InfoTip=@%SystemRoot%\system32\shell32.dll,-12690
    IconResource=%SystemRoot%\system32\imageres.dll,-189
    IconFile=%SystemRoot%\system32\shell32.dll
    IconIndex=-238”

    While the other contains “[.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21804
    InfoTip=@%SystemRoot%\system32\shell32.dll,-12690
    IconResource=%SystemRoot%\system32\imageres.dll,-3”
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry about the hidden files you are seeing on the desktop. It's because hidden files and folders are set to show.

    What are these files? If you do not know then delete them.

    • C:\{05488AF1-A09F-44B8-943E-D352FED4C1F1}
    • C:\{35599788-BE13-4879-8332-4A58069954A2}
    • C:\{437A1571-49B5-4BD9-8B5E-AF58D8EF4D48}
    • C:\{61636E7C-6C8B-4099-8D81-CA147BB983B5}
    • C:\{70BF80DA-C3CD-4682-B545-2AE3E4C8D8FA}
    • C:\{8157905F-A270-48DF-97A5-B55628173362}
    • C:\{8443E9A8-5CEB-476E-B2DA-DEB9FD04FC8D}
    • C:\{87EA941E-0464-41C0-BB7C-C932E662C1CE}
    • C:\{8CD54830-FCB8-4338-82CC-1C077DD606A3}
    • C:\{E61CF5A3-090A-48D8-86C9-87CF41F4B392}
    • C:\{ED048C48-744E-4020-AF27-C5DBF4ED5CA0}
    • C:\{F004D56A-3C7F-4086-A116-DC050007EA18}

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\users\Mike\AppData\Local\BIT7C42.tmp
    c:\users\Mike\AppData\Local\BIT7204.tmp
    Folder::
    C:\Users\Mike\AppData\Local\{43E05502-CFB8-43CE-8D05-8E22A38662B2}
    C:\Users\Mike\AppData\Local\{58353D20-A6DF-4827-8DFF-AD9B2233AE8B}
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. lostdata

    lostdata Private E-2

    Thanks for your help Kestrel13, I completed your combofix instructions and it seemed to go to plan, although foolishly I did open up the Norton Window to double check I closed it all down when I know you shouldn’t open any windows during its process. I closed off the UAC again before using combofix, was that correct?

    My machine blue screened yesterday for the first time, it produced something called a mini memory dump (or something like that) and a xhtml fie. Was this likely to have been caused by malware? I don’t know if it was the right thing to do, but I tried playing video files after the first READ & RUN ME procedures and today after combofix, and it still doesn’t play WMV files.

    One last thing I missed out updating Java from the read and run me instructions as I couldn't find any old copy to delete, was that OK?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not forget this part:
     
  10. lostdata

    lostdata Private E-2

    Sorry about that I missed it, the Zip is included with this post. I also accidently went online with my UAC off, I don’t know if that’s relevant. BTW during MGTools execution, windows reported a problem with “Stelwerx whoamI” or something like that, it either said it had stopped running or was unavailable. Also, the Malwarebytes antimalware software icon has been replaced by a generic one on the desktop, it happened after the read me run me procedure, so I reinstalled but it happened again. I turned Norton back on and the UAC after MGTools and rebooted, when I tried to use the video player it still won’t play WMV files.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete the below bold folders using windows explorer.

    C:\Users\Mike\AppData\Local\{43E05502-CFB8-43CE-8D05-8E22A38662B2}
    C:\Users\Mike\AppData\Local\{58353D20-A6DF-4827-8DFF-AD9B2233AE8B}

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running for you?
     
  12. lostdata

    lostdata Private E-2

    I carried out your instructions but there hasn't been any change for the video player, it's still refusing to play wmv files. As for stability, I haven't really been using my PC (using an old one) as its NIS subscription ran out yesterday. Are system files still missing or corrupt as in the sfc.txt file I uploaded earlier?
    The two filenames you listed were empty files and I deleted them. I had to download TDSSKiller and copy it to the problem PCs desktop because of the NIS problem. When ran TDSSKiller it found nothing, I also ran Getlogs.bat and I've attached the Zip file.

    I was going to remove Norton and install a new copy with another subscription, as it wasn't fully working before the subscription ran out. The green ticks stopped showing up in Google for safe sites and occasionally I get a message from explorer that an add on isn't working (I'm guessing it's for Norton). Should I remove Norton and start again or should I wait for further cleaning?

    Do you think I still have malware elements that need to be rooted out? The last time I had a malware problem on another PC about a year ago, I noticed during clean up that registry entries were removed by SAS/Malwarebytes. But none were removed this time as far as I can tell, is that a bad sign or just run-of-the-mill?
    Thanks
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is something to further discuss in the software forum.

    No, I think you have software problems if anything.
    It just finds what it finds. If it does not find anything that is good not bad. I dug deeper with other tools too.

    Not seeing anything else to do now here in the malware forum so I am going to give final steps. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. lostdata

    lostdata Private E-2

    Ok Many thanks for your help, I start that software post. What I was asking in a roundabout way was do you think it was malware that caused these corrupt files, or are there no signs of that, and was it in part or whole a hardware problem, like a memory problem causing the corruption. I have made a quick couple of memory passes but have found no problem, I don't want to make a more long winded scan unless a memory problem is likely.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not know what caused them to becorrupted.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds