The Procedure entry point CredEnumerateA could not be found?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by unofornaio, Apr 29, 2011.

  1. unofornaio

    unofornaio Private E-2

    HI All,

    This is my first official post,

    I recently downloaded a the operating program for usenet. I know I know :-o I should have never done it but did so at the suggestion of a friend those sites scare me but he was convincing and well, I have never done that before and I think I may have been taught a lesson.

    I deleted the program within a couple of min cause honestly it scared me to use those sites. At any rate now at random I get a error box from windows 2000pro. I know I know its old but it works for me. anyway in the upper banner of the box in the left corner there is a file name listed that is ALWAYS a .exe file but its name changes every single time the box comes up. Right now there is one and in the upper left corner is z00ruTt.exe - Entry point not Found. Below this in the larger portion of the box centered above the OK button it reads "The procedure entry point CredEnumerateA could not be found in the dynamic link library advapi.32.dll

    This box shows up at random. If I do not click ok it will keep coming up, not as separate boxes but the same one.They look like the same box but actually each one has its own .exe file. so I click ok on the box and in its exact location the next one and next one till they stop. Its usally one at a time but if Im away from comp they build up and have been many when I get back. Again its not many boxes but ONE box that well for get it I dont know how to explain it.:confused

    When this comes up at random the .exe file is always different but the rest of the box remains the same.

    Im posting in here because the fact that it is coming up every couple of min and the .exe file is always different and that when I do a file search search on this comp they do not show up concerns me. Its as if its randomly looking for something.

    In addition to this and I don't know if they are related or not but started the same day. I get at start up or restart a pop up box that says of course now I cant remember exactly but it says something about eziriz .net reactor. I apologize for not remembering and I need to restart for it to come back so for now I will leave it as that and post EXACTLY what it says later.

    In the back of my mind I think that the Usenet program was not for my operating system. Im NOT going back there to look. but just thought I might mention this.

    Im posting this now BEFORE I go through the READ AND RUN ME procedures just to give those who may help an idea of what my current issue is.

    I will wait for direction from u experts as to what to do next. Im proceeding with caution because I was just getting ready to back up this hard drive with EVERYTHING on it, I have been putting it off. But now Im worried I will back up a bunch of problems. Thats another issue though.

    Thank you for any help and please if this is not in the right forum I apologize and will not be offended if someone moves it to a better location.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need the logs from the READ & RUN ME so that we can properly diagnose your PC.
     
  3. unofornaio

    unofornaio Private E-2

    Hi Again,

    Thank you to chaslang for responding.

    Well I followed the directions to the letter and ran everything. However

    combofix would not run because of a request to uninstall CA antivirus. I TRIED TRIED TRIED to get CA uninstalled but it did not work. Apparently this is a common problem with there software. I tried many of there own suggestions with not luck.

    ROOTREPEAL also ran a bit then because of error messages stopped. They said cannot read from address and each one was different. I noticed that each one created a "crash Report" that Im sure I can attach if that is necessary.

    So it appears that the programs that did run found quite a lot of crap. The issues I wrote about below are no longer happening. Does that mean Im safe? I dont know.

    I know you guys are busy here so I hesitate to submit all my info for review if Im not having any immediate problems. This is why I posted a summary of my problem before I ran the procedure I really didn't want to waste anyone's time on an issue that could be easily solved. I mean dont get me wrong I really would appreciate a review and diagnosis but if its not a pressing issue than that's ok. Someone just let me know.

    Also I would love to run those 2 programs but dont know how to get rid of the CA and how to overcome the "cannot read" errors.

    So if someone feels like reviewing my info let me know and if anyone could direct me on getting the 2 others to run that would be great.

    Hey I am already thankful for all the stuff I ran from here. In addition the sticky's were AMAZINGLY through and were easy to follow. Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to find out, you need to attach the logs. Without seeing the logs, we cannot tell you anymore than what you already know.
     
  5. unofornaio

    unofornaio Private E-2

    Ok here are the logs.

    I could not attach the MBAM log because of the message below:

    "mbam-log-2011-04-29 (20-35-39).txt:
    Your file of 469.6 KB bytes exceeds the forum's limit of 375.0 KB for this file type."

    Thanks for helping
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have never ever seen an MBAM log this large. You must have a heck of a lot of malware for the log to be that large. Put it into a ZIP file and attach the ZIP file.

    How much more stuff like below have you been doing? Perhaps this is why your log is so large.
    You need to uninstall all of these and you need to delete all of these cracks/keygens. See the below:
    Warning about Porn, Keygens, Cracks, and other Illegal Software
     
  7. unofornaio

    unofornaio Private E-2

    Thanks again,

    I believe the file is so large because of the error message I was getting that is the title of this thread. As I looked at the file it appears that each time the message would come up it created a new .exe file. This is what the large log is comprised of.

    I have attached the zip file and hope it works. I have not created a zip file in years.

    Sorry for the delay I have been had some electrical problems at the house.

    I might add that at start up I get a registry to small pop up. I read somewhere here not to make any changes to anything until u guys review all the logs. If this pop up is not related to anything in my logs could some one please advise me as to what I should do about it?

    Also I want to really clean up this hard drive and was going to start that process then I came here for help with the Malware issue. I want to do this right and clean up everything that I do not need or use. I dont want to create any more problems so I would appreciate very much some direction on that process. If this is not the forum or even the site to seek this direction just let me know.

    Again thanks for all your help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is not the expected location for FireFox to be running from. Did you install Firefox in a non-standard way?

    C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla Firefox\firefox.exe

    Another question. Did you setup the below ProxyOverrides for some reason?

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*.worldwinner.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;*photosite.com;*.dir.untd.com;*.prod.untd.com;m.2mdn.net;<local>;*.local

    Since you say you cannot get CA to uninstall, this could mean it is broken. And we are likely going to need to use ComboFix. Thus to that end I want you to install and run the below tool to see if you can get CA Antivirus uninstalled using it.

    Revo Uninstaller


    Now uninstall the below:
    Ad-Aware SE Personal << way out of date and useless.
    Uniblue ProcessQuickLink 2 << not recommended and not helpful
    Uniblue Registry Booster << not recommended and not helpful
    Uniblue RegistryBooster 2 << not recommended and not helpful
    Uniblue SpeedUpMyPC 3 << not recommended and not helpful


    Now I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - (no file)
    O4 - HKCU\..\Run: [0x017] 0x017
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1143dbac8a53a35b1822/netzip/RdxIE601.cab
    O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://diy.view22.com/view22/diyapp/View22RTE.cab

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Malwarebytes and select the Quarantine tab. Then click the Delete All button to empty the quarantine.

    Now Update Malwarebytes to current database and then run a new scan and fix anything that is found. Attach this new log. If it tells you to reboot after fixing items, reboot before continuing with the below.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. unofornaio

    unofornaio Private E-2

    WOW..

    I cant believe how much info you went over. Look I cant say it enough thank you very much.

    To answer your questions:

    Firefox install: Not that I know of, I just downloaded it and installed it.

    Proxy Overrides: Absolutely not I don't even know what those are. I mean I think they are related to internet connection but that's all.

    I will get to work following your instructions.

    Thanks again.
     
  10. unofornaio

    unofornaio Private E-2

    Hi Again,

    Ok Everything seems to have worked fine. I followed the instructions as u laid them out.

    At last reboot (before writing this) I did still get the registry too small pop up but I can live with that if its not the sign of something more ominous going on in the background. :confused

    That uninstaller was incredible. I cant imagine how many left over files are in here from just using the standard windows uninstaller.. Did that also take out all of those files from previously removed programs? or just from the ones that I recently did?

    I did delete quite a bunch of other stuff that I did not use anymore so it was great. Also I was wondering if the "packages" that updates or "hot fixes" come in can be deleted after they have been installed? There are dozens of them on here..

    Anyway the registry pop up is still there but its the only thing I can "see" that is an issue.

    I will wait for further instructions

    Thank you again
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware issue. It is just an issue with Windows 2000 and your registry size. Try the below.

    To increase the maximum registry size
    • click on Start -> Control Panel -> System -> Advanced -> Performance Options -> Change
    • Increase the maximum registry size and click Ok.
    Yes but not a topic for this forum. And it you delete them, you will not be able to uninstall them if ever necessary, but you probably will never need to uninstall them anyway.

    Your logs are still showing all the files I asked you to delete with Avenger and also manually delete afterwards if they still existed. Did you run things in the wrong order?

    Check the C:\Documents and Settings\Administrator\Local Settings\Temp folder. Do you still see all the files I said to delete?
     
  12. unofornaio

    unofornaio Private E-2

    Hmm,

    I have attached a screen shot of the temp folder and none of those are in there. I cut off part of the edges and bottom of the screen shot to try and reduce size but it did not reduce it so I just put it in a zip file. Those in there now are Im assuming are from more clean up I did yesterday.

    I did NOT run any of the programs you suggested since sending you the logs. The clean up I did was just putting things in the trash.

    I went in the exact order they were listed in your post. Starting from the top to the bottom.

    I also peaked in the tasks folder and the files u listed are no longer there.

    I have been careful to follow instructions. There are some other programs I wanted to get rid of but thought I better wait till I here back from you so I waited.

    Since I totally deleted CA from my system I have no similar program. Can u recommend some programs I should have running to protect my internet connection and these types of issues.? I realize I will probably not be able to install them till we are done here but just thought I should ask now.

    Also Im switching to ATT u-verse internet (should be here today) Im wondering if I should wait until we are done here? no big deal I haven't even cancelled my other service yet.

    Thanks again for your continued help.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just so I can double check a more current set of logs, do the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip

    Will be covered in my final instructions when I'm sure you are clean.
     
  14. unofornaio

    unofornaio Private E-2

    Here it is..
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds