Antivirus Pro Malware and other errors

Discussion in 'Malware Help (A Specialist Will Reply)' started by DBean, Oct 24, 2009.

  1. DBean

    DBean Private E-2

    http://forums.majorgeeks.com/showthread.php?t=201587

    That was my original post on the problem. I have since gone through and done the steps listed in the Read & Run Me First thread that I could do, which was everything through the end of Step 3.

    However, I am unable to start Step 4 because my computer will not let me boot up in normal mode. The only option that will work currently is the Directory Services Restore Mode.

    I still have that status code -1073741482 error that pops up and keeps me from getting past the opening screen if I try to boot normally, and I still get that same blue screen of death error if I try to go with any of the safe mode choices. I do know that I was in the Task Manager and looking at the Processes when that whole status code error problem started if that helps any (This was a few hours before my original post).

    I did not want to go on any further since the next step clearly states to be back in normal mode before continuing, and I obviously can't be there at the moment. I'm not sure what my next move should be, so hopefully you all can help out some more.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you actually able to get to a running Windows system. If so, complete the READ & RUN ME as best as possible.

    If you cannot boot to a Windows desktop in any mode at all then there is not much we can do for you accept give you the below recommendations.

    First try the below to restore an older restore point. This requires your Windows boot CD.

    How to recover from a corrupted registry that prevents Windows XP from starting



    If the above does not work or you don't have your CD, you will have to try doing the below and will require the help of a friend with a working PC and where you can do any of these.
     
  3. DBean

    DBean Private E-2

    I was able to get back into my computer's normal mode this morning, and I finished the rest of the Read & Run Me First steps as indicated. I'm not getting hijacked when I go online anymore, and I also don't have that status code -1073741482 error upon starting up either. I'm still experiencing some other problems however. Here they are:

    1) The System Restore option does not work, saying something about a group policy and contacting your administrator. Other programs also say that I don't have access to them even though I should.

    2) Malwarebytes had an odd error when I tried to use it to correct the problem. Literally, it gave me a vbAccelerator SGrid II Control Runtime Error "0" as well as an "Automation Error "440". I have the program on a CD, but even trying to uninstall/reinstall didn't work. This was after I had a similar problem with Spy Sweeper, and it says that it's damaged and needs to be reinstalled now.

    3) I still get the Stop: 0x0000007B error if I try to boot in safe mode. Again, I do now have access to normal mode and Directory Services Restore Mode still works.

    4) Two new problems popped up upon restart after I was finished. The errors said:

    "assert in LSP original == reinterpret_cast<PROC>(instance -> org_startup_)
    assertion failed
    capture\lsp\nolsp\wsp.patches.cpp:202"

    "Windows cannot find C:\Documents"

    5) The 16-bit MS-DOS Subsystem error still remains

    I don't think malware is my issue anymore, but I'd like confirmation on that. If that's the case, where do I go from here with these other issues?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you attach the requested logs from the cleaning procedure, there is no sense in us addressing anything else. We need to see the logs to determine if you are really clean and what malware you had to begin with before deciding if we need to continue in this forum or send you to the Software Forum.
     
  5. DBean

    DBean Private E-2

    I tried to go back and get the logs from when I ran Spy Sweeper last, but I was locked out of that as well. All the problems are still there as well including the status code issue that I thought was fixed. I tried redoing the Read & Run Me thing from the beginning to make sure I hadn't screwed up somewhere. Looks like I did, but I can't do these steps:

    "Step 4: Enable viewing of hidden files, system files and file extensions"

    There is no Folder Options choice in the Tools menu, yet there is one on the computer I'm using right now. They're both the same model, so it looks like I'm locked out of that, too.

    Since I still have the issue of being unable to run any spy sweeping program no matter which one I install (after uninstalling the previous one), I have no way of getting any logs made let alone sent to you. Sorry for the whole runaround, but now what do I do?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions in the READ & RUN ME clearly stated the below:
    Thus you need to keep on going. You have not even gotten to the real cleaning steps yet.

    If you cannot run any of 5 tools used for scanning in the READ & RUN ME, then try the below instructions but again try all of the instructions.


    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  7. DBean

    DBean Private E-2

    I see where I messed up now. Here are the files from the four programs I was able to run. Once again, Malwarebytes encountered two problems that completely locked me out from running it:

    -vb Accelerator SGrid II Control Run-time error '0'
    -440 Automation error

    Other than that, I was able to get through that step. I'm not going to touch the System Restore step until I know it's safe to move on. Have at it, and thanks for putting up with my inexperience on this.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you started the cleanup process, you were not supposed to be doing anything except what we request. I can see you installed software from Agnitum Outpost Firewall on 10/26 also you install DNA on 11/08 and this is an extremely bad idea since using programs like it are most likely the root cause of your infection.

    Uninstall SUPERAntiSpyware right now so we can fix some issues related to it. I will tell you when to reinstall it.

    ComboFix needs to be on your Desktop not here: F:\ComboFix.exe If you don't do this properly, you will not be able to follow our other instructions. So download the current version of combofix.exe to your Desktop now.

    You have left overs from Symantec! Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)



    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Uninstall the below old versions of software:
    Java(TM) 6 Update 16

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - MRI_DISABLED - (no file)
    O4 - HKLM\..\Run: [UserFaultCheck] "C:\WINDOWS\system32\dumprep" 0 -u
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: MRI_DISABLED

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now reinstall SUPERAntiSpyware.

    Now try running Malwarebytes again.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the log from Win32kDiag
    • C:\ComboFix.txt
    • the log from Malwarebytes if it ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. DBean

    DBean Private E-2

    The status code and 16-bit MS-DOS Subsystem errors stopped showing up after my previous post. The blue screen of death Stop error if I tried to boot up in Safe Mode is also gone, meaning I can access Safe Mode outside of the Directory Services mode again. I don't know if it was fixed by the previous post or with the latest stuff you had me do, but it's working properly.

    The bad news is that Malwarebytes still gets the same two runtime errors of 0 and 440, so no go with that still. I'm also a little worried with how small the Win32kDiag.txt file was. I copy/pasted the bolded, including the -f -r part.

    The Outpost Firewall thing was my fault for trying to fix not having a software firewall on my computer to begin with, and I know for a fact that my friend downloaded Firefox on to this thing yesterday behind my back although the latter is not installed.

    Also, DNA was not downloaded (intentionally) on this computer. That program has been on this computer for awhile now as far as I know, much longer than the 11/8 date you said. I don't know what it is, and that's why I'm afraid to touch the thing. Should I do anything with these three programs?

    I'll make sure to keep everyone away from this thing until the next step. Goodness knows I messed up this computer enough as it is. I don't need anybody else doing it again for me!

    Edit: And before I forget, the Folder Options tab is once again available to me although it was already set to show me hidden files and folders.
     

    Attached Files:

    Last edited: Nov 11, 2009
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but yes it was by someone. This is not something that downloads and installs like malware. It is intentionally installed. We just don't recommend using torrent/p2p downloaders since they invariably lead to many infections. Thus you should just uninstall BitTorrent DNA and any other similar programs if installed. Check all user accounts to see if installed in any of them. If not found, you can use HJT to remove the startup and fix a Webroot left over:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Unknown owner - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (file missing)

    After clicking Fix, exit HJT.

    Then after your next reboot, delete the below two folders:
    c:\program files\DNA
    c:\documents and settings\Bean\Application Data\DNA


    You have a possible MBR infection. We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.


    Uninstall Malwarebytes, reboot. Then redownload the installer and reinstall. See if you can run it now.

    Also run a scan with SUPERAntiSpyware and attach the log if it runs.
     
    Last edited: Nov 11, 2009
  11. DBean

    DBean Private E-2

    Malwarebytes gets the same two errors. I caught another error message when I was rebooting after uninstalling Malwarebytes right before that. It said something about PCARmDrv.exe. I only had a couple of seconds to write it down, and I'm not sure what that means either.

    Other than the usual Malwarebytes error, I was able to run everything else without a hitch.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. DBean

    DBean Private E-2

    There was nothing called TDSSserv.sys or anything close to it when I checked in the Non-Plug and Play Drivers section, and that was with the hidden devices showing. There was a device named "catchme" that had a yellow exclamation mark on it when I checked that area again after running Combofix.

    When I tried the other fix mentioned in that thread via command prompt, the computer says that it can't locate "regsvr32" on my computer. When I ran a search for it, there were four different results:

    regsvr32.exe was in two folders C:\i386 and C:\Windows\SoftwareDistribution. Both were 12KB files. There were also two files in the C:\Windows\Prefetch area. Those files are 16KB and 30KB respectively. I left everything alone after the search. I hope I'm not giving any useless information, but I didn't want to leave anything out.

    Either way, Malwarebytes once again still has those same two errors that keep me from fixing this problem. As I said, I did do the Combofix step, so here's the log from that.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to copy one of these into your C:\Windows\System32 folder so that you can run the regsvr32 command to attempt the fix of Malwarebytes. This is a necessary system file. And since yours is missing, it is possible that other system file could be missing. You need to run the below System File Check (SFC) command.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Did you run fixmbr from the Recovery Console as requested in msg # 10 and was ComboFix run afterwards per msg # 12 using the new version of ComboFix?
     
  15. DBean

    DBean Private E-2

    Yes to both. The Combofix that was run after Message #12 replaced the old version you had me using the previous time on the Desktop.

    I copied regsvr32.exe into the System32 folder as instructed and then ran the System File Checker after that. It had me ask for the disc which I still have, and I was able to uninstall and reinstall Malwarebytes successfully! No more runtime errors. I'm not going to run the program though until told so because you might have me run the other steps, too.

    Either way, it feels awesome to finally be making some progress here.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you can run Malwarebytes now. Make sure you first select Update to get the current database installed. Then run a scan and attach the log.


    Now download ( to your Desktop ) and run the new ( yes another new version ) current version of combofix.exe and attach a new log.


    Tell what problems you are still having if any?
     
  17. DBean

    DBean Private E-2

    Updated and ran Malwarebytes without a hitch, and then I let Combofix do its thing. I seem to be doing all right for the most part. Malwarebytes didn't find any problems, so there was no action taken by me. I did have to split the Combofix.txt file up though since it turned out to be too large.

    I have one issue that I'm not sure on, and that's seeing this scrolling flash ad called Voicefive. It only shows up on one sub-board of a message board I frequently visit which makes me think it's just a normal ad, but let's make sure since it looks like I'm nearly finished.

    Other than that, everything's looking good!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes then it is probably just part of that website.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. DBean

    DBean Private E-2

    Mission accomplished! Thanks for all your help!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds