Security Tool BSOD

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChicagoCoin, Oct 27, 2009.

  1. ChicagoCoin

    ChicagoCoin Private E-2

    My problems started last Saturday when Security Tool was installed on this machine, ESET caught some of the malicious stuff but I did get infected, I used the SuperAntispyware online scan and Malwarebytes to remove the infection and finally got my desktop back but I can no longer boot up normally, only in safe mode.

    The error code of the BSOD is Stop: 0x000000C4, the rest of the code seems to change occasionally. I couldn't get on the internet until yesterday on this machine.
    From the Read and Run Me First thread:
    Downloaded the Sun Java update but I can't install it in safe mode, I have 6 Update 7.

    Other info, sorry, I updated my nvidia drivers, ran memtest and my memory passed. Have run eset in safemode a couple of times, there are items in my quarantine folder from 10/25 (about the time I got infected) but I can't restore or view them in safemode.

    Attaching log files, the Sas log is empty, I stupidly ran the online scan first and again stupidly uninstalled SuperAntiSpyware on my machine because I thought it had something to do with me not being able to connect to the web in safemode with networking. I can't install the program in safemode but did another online scan and it found nothing. Finally was able to run ComboFix, it kept rebooting due to rootkit detected.
     

    Attached Files:

  2. ChicagoCoin

    ChicagoCoin Private E-2

    Also attaching MGlogs.zip and I read some other threads about the Security Tool problem with suggestions to run exeHelper and AVPfind, these logs are also attached in case they are useful.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to put your PC into Normal Startup mode with MSconfig as requested in step 4 of the READ & RUN ME.


    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.
    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Delete the below files:
    C:\WINDOWS\ishvbf3v42.tmp
    C:\WINDOWS\system32\92CBCF


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.



    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks very much!
    I tried but it won't save that option after a reboot, everything is check marked except for 7 startup items at the bottom of the list, kindly let me know if they need to be listed.
    I didn't find these files.

    The computer still needs to be started in safemode, the requested logs are attached and thanks again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you working your problems in another forum? Who asked you to download Rkill?

    I strongly advise you to cleanup your very cluttered Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3A247B0C-A65A-41E6-997C-5276F3729A6E} - C:\Program Files\Common Files\mesof83122.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [DAEMON Tools-1033] SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    O4 - HKLM\..\Run: [DAEMON Tools] SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 8.0\avp.exe"
    O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
    O4 - HKCU\..\Run: [Shield] SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\Owner\LOCALS~1\Temp\c.exe
    O4 - HKCU\..\Run: [NordBull] C:\DOCUME~1\Owner\LOCALS~1\Temp\d.exe
    O4 - HKCU\..\Run: [MoneyAgent] SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [Google Desktop Search] SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. ChicagoCoin

    ChicagoCoin Private E-2

    Sorry chaslang, I read about RKill from bleepingcomputers.com but am not receiving support from the forums. I cleaned up the desktop and here are some of the problems encountered with your instructions, everything else ran ok.
    Error Message (in Safe Mode): The Windows Installer could not be accessed, This can occur if rou are running Widows in safe mode, or if the Widows Installer is not correctly Installed.
    Error Message (Directory Services restore mode): One or more customizations are not permitted by software restriction policy.

    Error Message: The system administrator has set policies to prevent this installation.

    The logs requested are attached, sorry about the problems, the computer still only runs in safe modes.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not make sense since your last MGlogs.zip file shows you ran in Normal Boot mode. And if you can run in Normal Boot mode you should be using that to complete instructions and to uninstall Java. So please clarify.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks again chaslang for the help, after performing the procedures in your latest post, the computer still hasn't started in normal mode since 10/25. I've usually been booting in Directory Services Restore Mode (windows domain controllers only) and am wondering if this is why it appears it's in normal mode. I'm able to use my usual screen resolution in this mode and previously enabled some Services in Control Panel/Administrative Tools/Services back when I couldn't connect to the web and in an attempt to get some programs to install (SuperAntiSpyware, etc.) and to work properly.

    I did run the latest procedures in Safe Mode with networking and this is part of the error message when trying to boot normally:
    A device driver attempting to corrupt the system has been caught, the faulty driver currently on the kernal stack must be replaced with a working version.
    Technical Info:
    Stop: 0x000000C4 (0x0000003c, 0x00000000, 0x873EB0F0, 0x00000000)

    Another note, I receive warnings in ComboFix that ESET antivirus is running (even in safemode with networking) and can't figure out how to disable it in Task Manager or anywhere else.

    Attaching latest logs that were requested.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most likely.

    May be problems with Windows itself. You may have some registry and or system file corruption, and you may have to work this out in the Software Forum or try a System Restore to a point in time before the problem began. However, I do have a couple more things for you to do first.

    Sometimes the best thing to do is just uninstall these protection programs since they frequently get in the way of cleanup and may even be broken due to the malware you had. It was rather obvious that it did not protect you nor help you find and remove the malware anyway. So before doing the below, I suggest that you uninstall ESET first.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. Pay attention to which CD is is asking for as it may ask for an original Windows XP CD or it may ask for the SP3 CD. You have to give it the correct CD if it asks for it. If you don't have one and it is asking for one, then this is the first problem you need to fix since you need the CDs to repair and missing or corrupted system files.


    Now download the current version of combofix.exe to your Desktop overwriting the previous copy.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. ChicagoCoin

    ChicagoCoin Private E-2

    When my problems began, I attempted to use 2 different restore points and they both failed, all of the restore points vanished shortly after that.
    ESET has now been uninstalled.
    I'm unable to run sfc, when i try Start,Run, sfc /scannow a blue window flashes for a second (unable to read it) and nothing seems to happen, I also tried COMMAND, sfc /scannow and receive the following error message:
    Windows File Protection could not initiate a scan of protected system files.

    The specific error code is 0x000006ba [The RPC server is unavailable.
    ].
    I tried to troubleshoot this problem via google but had no luck with these instructions from microsoft, the No Liability Accepted Certificate was already there, also read somewhere that sfc won't run in safe mode but don't know if thats true.

    Thanks again, computer still won't start normally, requested logs are attached.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    This could indicate problems with the Remote Procedure Call (RPC) service. You should check to make sure it is Started and set to Automatic. You can do this by clicking Start, Run and entering services.msc and clicking OK. Scroll down to the above service and double click on it and verify the settings.

    For continued support on your remaining problems, it would be best to continue in the Software Forum because your problems appear to be related to Windows at this point and not malware.
     
  12. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks, The RPC is set on Automatic and has been starting, I'll open up a new thread in the Software Forum and reference this thread.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just realized that the last ComboFix run did not really fix the atapi.sys file like it first implied and you still have an infection there and possibly an MBR infection. So before jumping into the Software Forum, let's see if we can get these fixed.

    We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 17, 2009
  14. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks for the information, I ran fixmbr and completed the other procedures, the logs requested are attached.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay neither the MBR infection nor the atapi.sys file infection got fixed. Did you run fixmbr before running ComboFix? Let's try again but FIRST, download and save the current version of combofix.exefor us to use but do not run it yet.

    Then boot to the Recovery Console and run the fixmbr command again. Let me know if you get any messages.

    Then run the same CFScript.txt fix with ComboFix as last time.
     
  16. ChicagoCoin

    ChicagoCoin Private E-2

    Yikes, I did run fixmbr before ComboFix and receive this Caution whenever it's run:
    This computer appears to have a non-standard or invalid master boot record
    I type "Y" at the prompt and receive this message:
    The new master boot record has successfully been written..

    Here are the new logs in case they will help.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix is still indicating a potential infection. Let's try using ComboFix again after downloading the new version and also this time we will not give it a command to replace the atapi.sys file. We will simply just run ComboFix.

    • Download the current version ( combofix.exe ) and save it to your Desktop.
    • Then shutdown your protection software
    • Then double click on the ComboFix.exe icon to run it.
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the new C:\combofix.txt log.


    Also tell me how your PC is running?
     
  18. ChicagoCoin

    ChicagoCoin Private E-2

    The ComboFix.txt file is attached, it sometimes takes a few reboots to finish due to a CD emulation Warning (first time I've seen that) and also the dectection of rootkit activity.

    Thanks again, the computer seems to run fine except for the bsod when attempting to start it up normally, the error message is very close the the one referenced earlier, only this part changes: 0x873EB0F0

    A device driver attempting to corrupt the system has been caught, the faulty driver currently on the kernal stack must be replaced with a working version.
    Technical Info:
    Stop: 0x000000C4 (0x0000003c, 0x00000000, 0x873EB0F0, 0x00000000)
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like it fixed the atapi.sys problem this time, but just to be safe, it may be a good idea to download the current version of ComboFix and run it one more time to make sure it does not find the same problem again.

    Does it tell you what file? Is there more to the message. atapi.sys is a device driver. It may be necessary to debug this further in the Software Forum or to use the below to further diagnose this:

    http://adrynalyne.spaces.live.com/blog/cns!AB9DE24BE9AF1B9F!199.entry
     
  20. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks for the link, I had previously downloaded the Microsoft debugging tools but am unable to install it in safemode, I receive this error message:
    "The system administrator has set policies to prevent this installation"

    The bsod doesn't mention a file name, I've attached the new ComboFix log.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your ComboFix log is now clean.

    Try running the below procedures and then retry.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Now run the below.

    Resetting Registry and File Permissions


    Restoring SeDebugPrivilege - ignore references to F-Secure Blacklight and Look2Me. The main point is to download and run SeDebug-Restore


    Reboot after doing the last step above.
     
  22. ChicagoCoin

    ChicagoCoin Private E-2

    Glad to hear that the log is clean, i had some problems with the other instructions, I can't run sfc /scannow, the same info applies from my earlier post here #10.

    I'm unable to install this, receive error message:
    "The system administrator has set policies to prevent this installation"
    Here's additional information that appears in my Event Viewer in case it helps:

    Event Type: Error
    Event Source: MsiInstaller
    Event Category: None
    Event ID: 1008
    Date: 11/30/2009
    Time: 6:53:51 PM
    User: COMPAQ\Owner
    Computer: COMPAQ
    Description:
    The installation of C:\Documents and Settings\Owner\Desktop\subinacl.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

    I ran the Reset.cmd and don't know if it worked or not, it didn't take a long time, a screen flashed but I was unable to read it.
    I ran SeDebug-Restore.exe and this is the message I receive, not sure if this in normal:
    '\cscript.exe' is not recognized as an internal or external command,
    operable program or batch file.

    Please reboot your machine

    Press any key to exit
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is starting to sound like you may have too much damage to your Operating System or to your user account to fix all the problems. I suggest two things to try.

    1. Try creating a new user account with admin privies and see what you can run using it.
    2. Or try boot in safe boot mode and truly login using the real Administrator user account and see what you can run.
    Also rerun the below on your problem user account:

    Please download ( yes download again to be sure you have the current version) and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! Also tell me what happened when using a new user account and when using the Administrator account in safe boot mode.
     
  24. ChicagoCoin

    ChicagoCoin Private E-2

    Ok, I created a new admin. user account and attempted to run or remove the programs mentioned earlier in this thread (java uninstall and install, sfc /scannow I suspect that this is not working, Microsoft debugging tools and subinacl.msi) and receive the same error messages. I also attempted this with the real Administrator account in safe boot mode with no luck. I attempted this before and after running the procedures that were mentioned in your post.

    I'm still receiving the bsod when attempting to boot normally, the bsod appears about 1 second after the select user screen appears, I clicked on the new admin. user account as fast as I could but still got the bsod.

    These procedures were completed in the proper order and the logs are attached, in case they will help.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are running out of things to try. There may just be too much damage to your OS to fix and you may have to reinstall. Let's try one more set of steps.

    Now uninstall ZoneAlarm.

    Now download and save the current version of combofix.exeto your Desktop.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  26. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks again for the information and assistance, ZoneAlarm has been uninstalled and I then ran the procedures.

    This was the first time that I didn't receive the rootkit activity warning when running ComboFix.

    I don't see a difference in the computer, still receive the bsod and can't install/uninstall the programs mentioned earlier. Attached the requested logs as requested.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but the atapi.sys infection does show up.

    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.
     
  28. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks again, attached is the TDSSKiller.txt file.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the current version of combofix.exe to your Desktop overwriting the previous copy.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. ChicagoCoin

    ChicagoCoin Private E-2

    Sorry about the delay chaslang, I got mixed up and thought I'd already run the new procedures.

    The new logs are attached, I had some problems getting ComboFix to run (rootkit and cd emulation reboots) but I was finally successful, didn't notice any changes with the computer, still have the bsod and program installation problems.

    FYI, after ComboFix ran and rebooted I received an error message about not finding a ComboFix.sys file.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just a few more things to try as we are quickly running out of ideas.

    Download the current version of combofix.exe to your Desktop overwriting the previous copy. Yes it was updated again just like MGtools as you will see below.




    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )




    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!



    If you still cannot boot in normal boot mode, try each of the below:
    • Run MSconfig and select Diagnostic Startup mode. Click Apply and OK. Then reboot.
    • Does it bootup with this mode? (Call this Mode 1) This is very limited and you will have no network connectivity. You will need to boot back to your normal method later to answer questions here.
    • Now in MSconfig again, select Selective Startup and uncheck the 4 boxes below. It should look like the below (double click to expand the image)
    mscfg1.jpg
    • Then click Apply and OK. Then reboot. Does it bootup with this mode? (Cal this Mode 2) This is very limited and you will have no network connectivity. You will need to boot back to your normal method later to answer questions here.
    • If it does boot okay in Mode 2, run MSconfig again and one at a time (with a reboot after each one) try enabling each of the 4 items disabled in Mode 2 to see if you can find which one cause a problem with startup.
     
    Last edited: Dec 23, 2009
  32. ChicagoCoin

    ChicagoCoin Private E-2

    OK, I ran ComboFix and MGtools and nothing changed with my bsod but I tried to connect to the internet and couldn't before trying the Diagnostic and Selective startups.
    I finally discovered that it was due to a ESET firewall entry that was enabled in my Network Connections/Local Area Connection properties, so I removed it and net access was back.
    :eek

    I then attempted to start up in Mode 1 and Mode 2 and nothing changed with the bsod so the problems persist, attaching logs requested.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmm!!! ComboFix is showing that your atapi.sys driver is infected again. Let's rerun a few things.

    First rerun TDSSkiller exactly like I had you run it a few messages back and attach this new full log.

    Now see if you can uninstall Java(TM) 6 Update 7 Let me know if it uninstalls.

    I also suggest that you uninstall the extremely outdated and ineffective Ad-Aware SE Professional
     
  34. ChicagoCoin

    ChicagoCoin Private E-2

    Yikes, I don't know what changed but I can't get TDSSKiller to produce a log this time, I tried (both in safe mode and safe mode Directory Services restore mode) under 2 different User Accounts:
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v
    Then I tried moving TDSSKiller into it's own folder in the C directory and ran (referenced at the TDSS link):
    "C:\tdsskiller\TDSSKiller.exe" -l report.txt -v
    and it still didn't produce a log. The message on the completion screen was the same each time:
    TDSS rootkit removing tool, Kaspersky Lab 2009
    version 2.1.1 Dec 20 2009 02:40:02
    Start log failed

    Scanning Registry ...
    UnhookRegistry: Cannot get access to KLMD, error 2

    Scanning Kernel memory ...

    Completed

    Results:
    Infected objects in memory: 0
    Cured objects in memory: 0
    Infected objects on disk: 0
    Objects on disk cured on reboot: 0
    Objects on disk deleted on reboot: 0
    Registry nodes deleted on reboot: 0

    Press any key to continue . . .
    Nothing has changed, I still can't uninstall:
    Error Message (in Safe Mode): The Windows Installer could not be accessed, This can occur if rou are running Widows in safe mode, or if the Widows Installer is not correctly Installed.
    Error Message (Directory Services restore mode): One or more customizations are not permitted by software restriction policy.
    Thanks for the information, uninstalled!
     
  35. ChicagoCoin

    ChicagoCoin Private E-2

    Sorry about the reply (couldn't edit my post) but I forgot to mention that I had downloaded the latest version of TDSSKiller from the link in case it had been updated, so maybe that was the difference?
     
  36. ChicagoCoin

    ChicagoCoin Private E-2

    Keep missing the 10 minute time limit for post editing, sorry.
    The TDSS log is now attached, I guess you no longer need to use a command line for the program and it produces a log by default in the C directory.
    :)
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is a bug in the new version that has broken the ability to give a log file name. It was clean anyway.

    Last thing to try is below and if this does not resolve any remaining problems, I suggest that you backup necessary files and then reinstall.


    First run this:Prevx 3.0



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  38. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks for the information, I performed the procedures and didn't notice any changes with the computer, still have the bsod and program installation problems, requested logs are attached.
     

    Attached Files:

  39. ChicagoCoin

    ChicagoCoin Private E-2

    I got the computer to start up normally for the first time in over 2 months!
    ;)
    Don't know if I should have done this but I used the information from Microsoft about the Driver Verifier:
    http://support.microsoft.com/kb/325672
    Turning off the Deadlock Detection didn't work but I tried this and no more bsod:
    I'm now receiving a Windows popup "The system has recovered from a serious error"
    Error Signature:
    BCCode : c4 BCP1 : 0000003C BCP2 : 00000000 BCP3 : 873EB0F0
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 768_1
    The following files will be included in this report:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\WERef40.dir00\Mini103109-04.dmp
    C:\DOCUME~1\Owner\LOCALS~1\Temp\WERef40.dir00\sysdata.xml

    The great news is that I was able to uninstall java and install the latest version and also installed the Microsoft debugger so perhaps I can use the link you provided earlier to read the dump file.

    I finally was able to run it, it ran in the background and eventually closed, didn't see any messages.

    Wondering if I should run SeDebug as directed earlier?

    Successfully installed SuperAntiSpyware and it didn't find anything.

    The computer so far seems to be running fine except for "The system has recovered from a serious error" popup.
    :major
     
  40. ChicagoCoin

    ChicagoCoin Private E-2

    An update, I was able to run the Microsoft debugger and have attached the file in case it will help.
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still not having malware problems. That driver may be a left over from Sygate Firewall. Try the below.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u wpsdrvnt.sys

    then click OK. If a dialog box confirming this action appears, click OK.

    Reboot and then see if you can delete the below file:
    C:\WINDOWS\system32\drivers\wpsdrvnt.sys

    Then I suggest if you still are having any problems that you post in the Software Forum since our work in this forum has been finished for awhile.


    Since you are not having malware problems, it is time to do our final steps. I am not going to have you toggle system restore at this time, just in case you still need to try and use system restore.
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  42. ChicagoCoin

    ChicagoCoin Private E-2

    Thanks very much for all of the help, my computer is now running fine!
    :)

    This command didn't work for me, it mentioned that the specified module couldn't be found.

    I didn't remember ever installing SyGate Firewall and discovered it's a part of Norton now so I ran a Norton Removal Tool and am not having anymore problems!

    Thanks again for everything!
    :major
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds