Malware problem?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hoquista, Jun 17, 2008.

  1. Hoquista

    Hoquista Private E-2

    My sincerest apologies for posting this here (I assumed this is the place as I'm a noob). I am having a problem when I restart my computer. I get problems with the 'Generic host process for Win32 services' and it also give me:

    svchost.exe - Application Error
    The instruction at "0x009d96bc" referenced memory at "0x00000000." The
    memory could not be "written."

    I ran all the malware stuff :
    SUPERAntiSpyware
    Spybot
    Malwarebytes Anti-Malware
    ComboFix
    MGTools

    SUPER did not find anything so there isn't anything to attach. I have uploaded the files for anti-malware, combofix, and MGtools. Is there anything wrong and anthing that needs to be fixed?

    Thanks in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on your logs, it does not appear that your problem is due to malware. Let's do a couple things and run once more scan and go from there.

    First please disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    Then you can uninstall SUPERAntispyware since we are finished with it and it did not find anything.

    Is the below proxy server something you configured?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.uminho.pt:3128


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O16 - DPF: {FD163A9A-A3D8-4F7D-8224-32F81AC29EDA} (VPlayer Control) -
    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now delete the below files:
    C:\WINDOWS\system32\SET28.tmp
    C:\WINDOWS\system32\SET21.tmp
    C:\WINDOWS\system32\SET1F.tmp

    Now run Ccleaner!

    Now click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. If this finds any problems that it can not easily fix from files on your hard disk, it will ask for your Windows CD so have it ready.

    Now run this: Running GMER to detect rootkits

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • the GMER log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Hoquista

    Hoquista Private E-2

    First, thanks for the reply and the help so far.

    The proxy server is something I configured.

    Also, I did receive a success message about adding the above
    to the registry.

    I then goto this point.


    The computer then asks me for the Windows XP Professional Service Pack 2 CD but unfortunately, I don't have that Windows CD. The only thing I received from the manufacturer (ASUS) about Windows was the 'Windows Recovery CD' 1 and CD2 and the sfc does not accept that. Is there anything I can do? I stopped at that point because I didn't know whether I should continue to the next steps without completing this one.

    Also, my McAfee Security Center is showing a RemAdm-ProcLaunch!171. Do you know what that is? Thanks again!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Purchase one or borrow one from someone so that you can complete the scan. Those are the only options.


    Where is it detecting this? What file name and what path? It is possible that it is just psexec.exe from SysInternals which is now part of Microsoft. See: http://vil.nai.com/vil/content/v_129978.htm
     
  5. Hoquista

    Hoquista Private E-2

    I tried borrowing it from someone without success because it's essentially saying that it's not the correct CD.

    Is this what I need?
    http://support.microsoft.com/kb/310994

    I think it's from Combofix.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need a Windows XP SP2 CD for your type of Windows XP (like Media, Home, or PRO)

    No! Those are floppy disks to reinstall Windows when you do not have a CD drive


    Yes ComboFix uses psexec!
     
  7. Hoquista

    Hoquista Private E-2

    Thanks for the replies and being patient with me. How about this one?

    http://www.microsoft.com/downloads/...BE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en

    I just find it interesting that I already have the SP2 upgrade but I have to go out and purchase it instead of just downloading the file and burning it to a CD?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the installation for SP2. It is not a CD that sfc can access to repair or replace bad or corrupted files.

    You did not get a bootable CD with your PC and that is where you problems began. Blame the people you purchase your PC from.

    You could try going to Microsoft Update and installing the current Service Pack for Windows XP which is SP3. This may take care of any missing or corrupted files as long as they are part of the update. You can also download SP3 and install it yourself if you wish. You can get it at Major Geeks: Microsoft Windows XP Service Pack 3

    At anyrate, as I said earlier, your problems are not due to malware. This would be a topic better suited for the Software Forum.
     
  9. Hoquista

    Hoquista Private E-2

    Ok. Thanks. I am just trying to get it fixed using the sfc. I have downloaded the original *.exe file (~ 250 MB) of the SP2. Would I be able to burn that to a CD and have it work?

    I agree. I've had problems with ASUS in the past with my laptop and this fact of the whole windows restore CDs rather than the whole XP is annoying to say the least.

    Windows update did download the SP3 (~ 100 MBs?) and it installed correctly but the sfc /scannow is still asking for the SP2 CD. I downloaded the whole version (~ 550 MB) but I am not sure how to install it because the file is an *iso.

    What does the sfc /scannow and the rests of the steps do? Is it absolutely critical that I complete this?

    Thanks for your help and sorry for all the questions.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! A I said in my last message. This is not a Windows CD. It is the installation file for SP2 and it will not give you what you need which is a Windows XP SP2 bootable CD.


    Well doing this could revert certain file back to SP2 revision levels. Did it indicate which files it is looking to repair.

    The whole version of what? SP3? If that is what you meant, this is again only an installation program for SP3 it will not give you a Windows XP SP3 (or SP2) bootable CD.

    You should read this: http://support.microsoft.com/kb/310747

    As I said earlier your problems were not due to malwar. You have problems within the Windows Operating System. And that is what we are trying to fix. If you are not having any noticeable problems anymore, then don't worry about it, but I'm sure something is not correct if you are being asked for a CD when sfc is run. And I would expect it to now ask for an SP3 CD not an SP2 CD. Had you rebooted your PC after upgrading to SP3?
     
  11. Hoquista

    Hoquista Private E-2

    Ok... Thanks!

    It just said that 'Files are required for Windows to run properly must be copied to the DLL cache' and in the same window it said please insert the SP2 CD.

    The link you sent me to gives a ~ 550 MB version of SP3. I went to windows update directly and updated via that but I also downloaded the 550 MB version too but didn't install the 550 MB version.

    No, I didn't reboot. After I rebooted, it is now asking me to 'please insert the Windows XP Professional CD-ROM into the CD-ROM drive' with the same problem ('Files are required for Windows to run properly must be copied to the DLL cache'). I do not have those CDs - I only have the 'Recovery' CDs that was provided by ASUS. I have XP Pro CDs that were installed on another computer and unfortunately thay didn't work either.

    I still have the same problem after I reboot that I had under my first post (Generic Host processes, svchost.exe, and referenced memory).
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you continue this discussion in the Software Forum. These problems are not topics for the Malware Forum.
     
  13. Hoquista

    Hoquista Private E-2

    Thanks chaslang for your patience and your help! I will try there.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds