ComboFix aftershock - no Internet

Discussion in 'Malware Help (A Specialist Will Reply)' started by programmer04, Feb 2, 2010.

  1. programmer04

    programmer04 Private First Class

    My laptop was experiencing issues with slow speed and pop-ups. I began following the READ AND RUN ME FIRST post. When it came time to use ComboFix the program said there was an updated version, so I updated.

    Everything occured as the instructions said it should. After the computer restarted and the log was created, I noticed that I didn't have internet connection. I also wasn't able to open certain things like text files (one of which was the instructions I copied and pasted). After rebooting again, everything worked except the internet connection. I clicked on diagnose and it told me there was an issue with the drivers.

    In Device Manager it showed several problems with network adapters. When I open the Properties for each device with issues there is a message: "Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)".

    I have downloaded the drivers for my laptop, which include Nvidia, Atheros and Broadcom, but I would like someone to take a look before I uninstall the old and install the new.

    I have not finished the READ AND RUN ME FIRST, so I will only attach the first three logs for now. I've also included a snapshot of my Device Manager.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download and save MGtools.exe at the point requested? If so, please run it and attach the C:\MGlogs.zip which will give us a little more info that we need.


    ComboFix deleted the below files:
    c:\windows\system32\drivers\ndisrd.sys
    c:\windows\system32\drivers\snetcfg.exe
    c:\windows\system32\ndisapi.dll

    All of which have been associated with malware.
    http://www.bleepingcomputer.com/startups/ndisrd.sys-25024.html
    http://www.prevx.com/filenames/116418579896185226-X1/SNETCFG.EXE.html
    http://www.greatis.com/appdata/d/SysDir/n/ndisapi.dll.htm

    So it would be interesting to get copies of these files to see if they were really valid. The copies will be in your C:\QooBox folder which is where ComboFix quarantines everything. You should see the below folder:
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers

    and in this folder you should see the below files
    ndisrd.sys.vir
    snetcfg.exe.vir
    ndisapi.dll.vir

    which is just the original files renamed to have a .vir extension. Put them into a ZIP file and attach them here. Also copy them back to your C:\Windows\system32\drivers folder and then rename them to remove the .vir extension that was added.

    We also need to restore 2 driver registry entries related to the files that was removed. The below 2 drivers were removed:
    -------\Service_Ndisrd
    -------\Service_NdisrdMP


    I need the MGlogs.zip file from MGtools to help me determine how you can restore these entries.
     
  3. programmer04

    programmer04 Private First Class

    I did everything you requested. There were only two of the three files mentioned in the "C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers" folder. "ndisapi.dll.vir" was not there.

    Also, I almost forgot to mention this, but my wife (it's her laptop) allowed "coupon bar" to be installed. I have tried a few times to get rid of it. It shows up in the programs list but it won't let me uninstall it. Can you help me get rid of it?

    Here are the 2 zip files:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. It is in the below folder:

    C:\Qoobox\Quarantine\C\WINDOWS\system32


    Did you restore the other the files to their proper locations and without the extra .vir extension?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like false detections based on those two files you Zipped. Please also put the below 3 files into a ZIP file and attach it.

    Code:
    "C:\Qoobox\Quarantine\Registry_backups\"
    servic~1.dat  Feb  2 2010        3114  "Service_Ndisrd.reg.dat"
    servic~2.dat  Feb  2 2010        1324  "Service_NdisrdMP.reg.dat"
    
    "C:\Qoobox\Quarantine\C\Windows\System32\"
    ndisap~1.vir  May 14 2009       61440  "ndisapi.dll.vir"
     
  6. programmer04

    programmer04 Private First Class

    Yes, I restored both files plus the third just a moment ago. Here's the zip folder with all three files:
     

    Attached Files:

  7. programmer04

    programmer04 Private First Class

    The other two files from the Registry_backups folder:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work so don't continue with the below.

    If the above registry patch was successful and you are sure you restore the 3 files and removed the .vir extension, then reboot your PC and see how things are working afterwards.
     
  9. programmer04

    programmer04 Private First Class

    I double checked to make sure the three files were in the C:\Windows\system32\drivers folder and without the .vir extension. I got the success message from the fixme.reg file.

    After restarting, the internet still did not come up. I checked the Device Manager and the same devices still had issues. Now the properties messages read:

    "Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39)"

    and

    "This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)"
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only things left to try are a system restore to before the point of running the cleaning process and if that does not work, you may need to reinstall the drivers. It may be necessary to first delete the devices from Device Manager and then reboot. During the reboot the notification of new hardware should be seen and during this time you can reinstall the drivers.
     
  11. programmer04

    programmer04 Private First Class

    I reinstalled the drivers without doing a system restore and I now have an internet connection. One of the devices is still showing an issue, so I'll try to uninstall and reinstall that one, but for now I'm just glad I could get the connection. Thanks for the help.

    I was still wondering about the "CouponBar" that shows up in the programs list. It won't uninstall, but I also can't find any instance of it on my computer. My wife purposely installed it to be a part of the toolbars in Internet Exolorer, yet when I right click in the toolbar area it is not one of the options. Should I not worry about it? Did you notice it in any of the logs?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It was previously deleted by the cleaning procedure. See the log from SUPERAntiSpyware which is why it cannot really be uninstalled. It has been forcefully deleted. The below should remove the entry you see.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds