malware removal: vbalgrid glitch

Discussion in 'Malware Help (A Specialist Will Reply)' started by bird63, Apr 22, 2010.

  1. bird63

    bird63 Private E-2

    Hello, I'm infected (XPpro, SP3):
    desktop theme changed,
    quicklaunch closed,
    Google gadgets disabled,
    unable to run most programs,
    "Event Monitor user Notification Tool has encountered
    a problem and needs to close...";
    believe it started with fake McAfee Internet
    Security app
    and I am part way through READ & RUN ME FIRST guide, section 'Windows XP Cleaning Procedure'.

    SuperAntiSpyware was the last successful step and it detected nothing. Malwarebyte's Anti-Malware will not install or run from desktop or USB stick, in normal or safe mode. The following messagebox pops up:
    "failed to load control vbalGrid from vbalsgrid6.ocx. vbalsgrid6.ocx ay be outdated..."

    Per related threads: did not find TDSSserv.sys in Device Manager; ran MGTools and attached log ZIP.

    Holding here so as not to skip any more steps. Please advise.

    Thanks! --John
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You also have been hit by McAfee. If this was caused by McAfee, the fix is HERE.

    OR:

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\MGtools\temp\svchost.exemg | c:\windows\System32\svchost.exe 
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Tell me how things are working now.
     
  3. bird63

    bird63 Private E-2

    Thanks for the swift reply.

    I did not experience the false positive mentioned in the first link and windows has been able to start (though that's about all it does) so I started with your second recommendation.

    However, I am unable to drag'n'drop anything anywhere so I can't plug CFscript.txt into ComboFix.exe.

    My command window does open so I've been using that to copy files from an unaffected computer, etc. via USB stick.

    Is there a command line way that I can feed CFscript.txt to ComboFix.exe?

    Trying your first recommendation - the bleepingcomputer (so true) topic 311599 link - I arrived at a blue screen with "A problem has been detected..." and "STOP: 0x0000007B..." on two consecutive reboots so I am holding here for further advice.

    Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to use the command line to copy the file if you have downloaded XPsp3bu.exe.

    That puts a new copy of svchost into your MGTools folder. The command would be the same, basically:

    copy C:\MGtools\temp\svchost.exemg c:\windows\System32\svchost.exe
     
  5. bird63

    bird63 Private E-2

    Thanks TimW.

    The 'manual' copy in Safe Mode worked fine. I had downloaded and double-clicked XPspbu3.exe previously, per your direction.

    On reboot, Google sidebar was full of lots of unrecognized gadgets but, otherwise, my familiar desktop was back. Then it auto-rebooted before I had a chance to resume with AntiMalware and returned to the virus-y look & behavior.

    Redoing the svchost copy, rebooting and starting AntiMalware as quickly as possible, it was able to scan about 3700 items before the auto-shutdown. Here's the message:

    "Windows must now restart becasue the DCOM Server Process Launcher service terminated unexpectedly"

    and it counted down from 60 seconds and shut down right through AntiMalware.

    Is there a different tack I can take? Thanks!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you completely disabled McAfee??

    "since I could not copy and paste, I ended up deleting the DAT folder as suggested and putting my svchost file into a compressed file so I could just extract it into the right folder, since I couldn't copy and paste, and it fixed it."

    From a different user with similar issues.
     
    Last edited: Apr 22, 2010
  7. bird63

    bird63 Private E-2

    Unable to disable McAfee: it allows me to open the anti-virus config window, for example, but says it's OFF; when I return to the main screen it is ON again.

    Unable to use Add/Remove Programs to remove McAfee. Clicking there elicits no response.

    BTW, my McAfee Internet Security screen looks different: green bar across it and the start bar icon is a red shield, not a gray square with a red 'M' in it.

    Was able to update & run Anti-Malware by issuing 'Start : Run : shutdown -a' every time (twice) the DCOM error started its countdown. Now it seems to have given up and I am sitting on my normal desktop with limited abilities: no drag & drop, etc.

    Anti-Malware db version 4023 Quick Scan found nothing.

    Currently running a full Anti-Malware scan. OK?

    Where is the DAT folder mentioned by the other user? I do not see one under McAfee.

    May I have the link to that thread?

    How can I disable/remove McAfee?

    svchost.exe has disappeared from c:\windows\System32 again without any other evidence of change. Shall I just keep copying it into there from MGTools for the time being?

    Thanks! Your swift and expert attention is GREATLY appreciated.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. bird63

    bird63 Private E-2

    The McAfee fix made a difference - was finally able to disable it and continue with READ & RUN ME FIRST for XP SP3.
    Network access: OK
    Drag'n'drop: OK
    Google gadgets: remained whacky - removed (small price to pay)
    Have not yet tested much else.

    Ran ComboFix, Anti-Malware, RootRepeal and MGTools - logs attached. How does it look? THANKS!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see the HelpAssistant account is enabled. Please disable it.

    Did you set up the use of a proxy server:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

    Finally, are you having any other issues?
     
  12. bird63

    bird63 Private E-2

    Thanks. Disabled HelpAssistant using the computer management window.

    Is that sufficient or should I also follow the HelpAsst_mebroot_fix.exe procedure that you describe in topic 214780?

    To my knowledge, I did not set up the use of a proxy server but that HKCU key is indeed present in the registry. Does that need to go?

    Do you want a fresh MGTools log?

    No apparent problems at the moment. Was there something specific I likely did that caused this McAfee problem? Any specific way to avoid it in the future?

    Pending further instructions from you, I am heading for topic 44525 "How to Protect yourself from malware!" Thanks again.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, that should be sufficient.
    Let's remove it by running C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.
    No, you are good to go. :)
    It was not you, but a bad DAT file from McAfee.

    And you are most welcome. Safe surfing.
     
  14. bird63

    bird63 Private E-2

    HKCU...Proxy server HJT'd; that was easy.

    ouch.

    yea, wearing a helmet and goggles from now on.

    You folks do good work.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't forget the wet suit!!! LOL. Again, you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds