Possible Malware: Several Symtoms: Can't Upgrade Windows, BSOD on reboot/Combofix

Discussion in 'Malware Help (A Specialist Will Reply)' started by boatdrinks, Apr 23, 2011.

  1. boatdrinks

    boatdrinks Private E-2

    Thanks for your help. I've been stumped for several days following several guides to figure out what I have and I'm at the limit of my own knowledge and skill.

    A few days ago I installed an old game, Sid Meier's Pirates!, securom when prompted, and upgraded firefox. Since and during my pd efforts I've noticed the following symptoms

    A persistent BSOD when issuing a shutdown or restart with the code 0X0000008E

    I cannot connect to Windows Upgrades via the Windows Upgrade utility in the control panel nor can I get to the MS update url via either firefox or IE. I've checked proxy, host files etc and I don't see anything unusual and have no other connectivity issues.

    SVCHOST.EXE starts to consume >50% of the CPU, which I initially attributed to possibly the upgrade connectivity so I've temporarily disabled checking for updates which seems to have settled this process.

    A host process for windows services has stopped working and was closed popup.

    Another extra tab generated by Firefox which redirects to a random URL. This has been solved by running one of the recommended malware utilities.

    I receive a BSOD for COMBOFIX. Just at the point after launching when the progress bar almost reaches full I received the following BSOD;

    "An attempt was made to write to read only memory"
    "0X000000BE ..."
    "starport.sys"

    I've tried this several times and I've also seen "IRQL_NOT_LESS_OR_EQUAL" BSODs.

    Combofix in safemode also returns a BSOD but less descript.

    None of the BSODs seem to generate a .dmp where I can locate even though I've set it both for kernel dumps and the smaller option, which I forget.

    I've attached the requested files and followed the steps mentioned in your Malware removal guide. Please let me know what else I can do.
     
  2. boatdrinks

    boatdrinks Private E-2

    attachments
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. boatdrinks

    boatdrinks Private E-2

    I should let you know that while waiting for a response to my initial post I reran a scan which found those two and supposedly removed them. I did not want to bump my post with that info.

    Regardless I've followed your instructions and have not noticed an improvement. I still receive BSODs after reboot and cannot connect to update microsoft sites. I'll attach the requested logs below.

    A pieces of info you might find helpful. Before following the instructions in this forum I did run a scan which found and supposedly removed agent.r_xj. I did not see it show up again in the scans mentioned in this forum but I felt you should know in case some files have been altered in such a manner by this virus to cause my symptoms.

    I am now in your hands and will not run a scan without your request.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point, I mostly have questions for you.

    What is this:
    C:\Users\Administrator\Desktop\Virus Removal Tool

    Why are all of these in this folder:
    Code:
    C:\Windows\System32\drivers\etc\anime.txt"
    battle~1.txt  Mar 26 2010        1187  "battlefieldkey.txt"
    delete~1.txt  Apr  9 2010         641  "deletesoldier.txt"
    faq.txt       Jan  1 2011        2063  "faq.txt"
    greyjoy.txt   Jan  1 2011          52  "greyjoy.txt"
    hgame.txt     Apr 16 2010        3988  "hgame.txt"
    knives.txt    Mar 12 2010        2916  "knives.txt"
    lannis~1.txt  Jan  1 2011          40  "lannister.txt"
    mhmmm.txt     Jan 30 2011        2575  "mhmmm.txt"
    password.txt  May 12 2010          37  "password.txt"
    rift.txt      Jan 24 2011        3569  "rift.txt"
    veritas.txt   Jun 19 2010        8583  "veritas.txt"
    villan~1.txt  Dec 30 2010         159  "villannames.txt
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now you will probably need to post in the software forum for your BSOD issues as well as the windows update issues, but you can try this:

    There are so many possible causes of problems with Windows Update that it would probably be best to send you to the Software Forum. However, there are a few things we can try first.

    1. Make sure time and date and TimeZone are correct
    2. See if it works in safe boot mode
    3. Reset HOSTS file

    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    4. flush DNS server

    Right-click on the Command Prompt icon and select
    "Run as administrator". Then type in: ipconfig/flushdns
    and press the Enter key on your keyboard.

    5. add Microsoft URLs to the Trusted Zone (see below)
    6. shutdown firewall and retry
    7. shutdown AntiVirus and try

    MS URLs

    http://*.update.microsoft.com


    http://download.windowsupdate.com


    http://genuine.microsoft.com


    http://go.microsoft.com


    http://support.microsoft.com


    http://update.microsoft.com


    https://*.update.microsoft.com <--Notice the https designation.

    the first thing to always check for Windows Update problems! make sure that Automatic Updates is not turned off. It needs to be on and the service status needs to be Started and the Service type needs to be Automatic.
     
  6. boatdrinks

    boatdrinks Private E-2

    The .txt files are all files of my own creation. As to why they are in that directory? Probably because it was the default of notepad at one time. They are random thoughts, shopping lists or misc garbage.

    I executed appHelpinterval fix as requested. I can attach a log if you wish?

    1. Time Zone is accurate
    2. I'm using a USB wireless adapter with Netgear software. It doesn't play nice with Safemode and I wasn't able to test this in safe mode.
    3. I had no host file.

    I followed your instructions for dling and creating a host file.

    I flushed DNS.

    I shutdown windows firewall, no av was running.

    I added the urls to IE, Internet Security, Trusted Zones. I believe this is what you expected?

    So far no change to the BSODs or Windows Update.

    I also restored my router defaults just in case and so far no change in windows update or url access to the upgrade windows urls. If you feel I'm clear of Malware/Viruses now I think I'll either post in your software forum or try to burn a recovery disk..

    To be honest I'm starting to see alot of strange behavior out of my OS. On top of what I've already mentioned I've noticed that after a few minutes I even get errors trying to access my windows firewall controls.

    Thanks again for your help!!
     
  7. boatdrinks

    boatdrinks Private E-2

    If it matters with a second machine on this network I was able to reach update.microsoft.com using both the url and ip. Even an IP that i was able to get off a nslookup on the machine that cannot reach access the website by the very same ip. It's as if I'm being blocked by firewall or some protocol.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post in the software forum to try to figure out your BSOD's. Since I can't find any malware that is causing this, we should do the final cleanup:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  9. boatdrinks

    boatdrinks Private E-2

    Tim, I went to software for my BSODs and they recommended the following;

    "There are 3 suspect files loaded in your dump files:

    84275511.sys 0x00520000 0x4abccca4 9/25/2009 14:59:00
    8427551.sys 0x00050000 0x4acf8ec7 10/9/2009 20:28:07
    84275512.sys 0x0000d000 0x4ae02bb3 10/22/2009 10:53:55

    These appear to be hidden from Explorer as there's no path to locate the files.

    I think it's back to your Malware thread and ask for assistance in locating these files and removing them from your system."


    The original dump files and this suggest was in

    http://forums.majorgeeks.com/showthread.php?p=1619338&posted=1#post1619338
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      84275511.sys
      8427551.sys
      84275512.sys
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  11. boatdrinks

    boatdrinks Private E-2

    Here are the results..

    ystemLook 04.09.10 by jpshortstuff
    Log created at 00:05 on 03/05/2011 by Administrator
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "84275511.sys"
    C:\Users\Administrator\Desktop\Virus Removal Tool\setup_9.0.0.722_23.04.2011_08-56\drivers\1\84275511.sys --a---- 128016 bytes [07:09 23/04/2011] [21:59 25/09/2009] 7DD41B7AC1FBB1DBF20BB1F4E4FBE58C
    C:\Windows\System32\drivers\84275511.sys --a---- 128016 bytes [07:09 23/04/2011] [21:59 25/09/2009] 7DD41B7AC1FBB1DBF20BB1F4E4FBE58C

    Searching for "8427551.sys"
    C:\Users\Administrator\Desktop\Virus Removal Tool\setup_9.0.0.722_23.04.2011_08-56\drivers\8427551.sys --a---- 311312 bytes [07:09 23/04/2011] [03:31 10/10/2009] 64D93EC1218765498C40619427A85A91
    C:\Windows\System32\drivers\8427551.sys --a---- 311312 bytes [07:09 23/04/2011] [03:31 10/10/2009] 64D93EC1218765498C40619427A85A91

    Searching for "84275512.sys"
    C:\Users\Administrator\Desktop\Virus Removal Tool\setup_9.0.0.722_23.04.2011_08-56\drivers\2\84275512.sys --a---- 37392 bytes [07:09 23/04/2011] [17:54 22/10/2009] A305FAD3719C5DB0C13D1C2BFD08A04D
    C:\Windows\System32\drivers\84275512.sys --a---- 37392 bytes [07:09 23/04/2011] [17:54 22/10/2009] A305FAD3719C5DB0C13D1C2BFD08A04D

    -= EOF =-
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I suggested in a private forum to Tim, these are just .SYS files from running Kaspersky's Virus Removal Tool at some point in the past. They are not problems.
     
  13. boatdrinks

    boatdrinks Private E-2

    Yeah. I'm just trying to clear my pc one issue at a time. The BSOD seems the easiest to troubleshoot. I believe these files were mentioned by your software support as something in the dump that needed tending to. Do you have any suggestions on what next?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it isn't a problem when in safe mode, then I would go into msconfig and stop all startup items. Boot into normal mode and see if the issue persists. If it doesn't, add the start up items one at a time until you find the cause.
     
  15. boatdrinks

    boatdrinks Private E-2

    Tim, I disabled all items from startup in msconfig, rebooted and I still received the BSOD on shutdown. I also tested Windows update and it still fails. It did solve an application error I had after a Civilization 4 install so I do appreciate that.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me take one more look at your system, download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new MGLOgs.zip
     
  17. boatdrinks

    boatdrinks Private E-2

    I received alot of WMI errors on this run and checked services and found that the service is start pending. I'll upload the MGLOGS.zip anyway and attempt to get this service back up.

    Later, I tried to restart and received an error "could not start in a timely fashion" I'll reenable my services in startup and reboot and try again.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  19. boatdrinks

    boatdrinks Private E-2

    After reboot I reran the mgtools with wmi running and I'll attach it below.

    I've cleared the two temp locations.

    I can connect to both urls you provided and I do get the download popup although I canceled. Do you recommend proceeding with the SP1 download and install?
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, as that may fix some of your issues. But according to your latest log, those temp files are all still there.
     
  21. boatdrinks

    boatdrinks Private E-2

    Downloading sp1 then. Yeah the temp files were removed after I ran mgtools.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's hope the download is successful and some of your issues are fixed. ;)
     
  23. boatdrinks

    boatdrinks Private E-2

    I installed SP1 and then went ahead and installed SP2. I still got bluescreens on reboot throughout the install process although it appears the service packs installed successfully. After completion I rebooted again and still received a BSOD that referenced my power supply which I can provide if necessary. I still can't connect to update microsoft sites through ie, firefox or the windows update. I turned on ms firewall logging and never saw it get dropped or accepted by my firewall when I tried accessing the update site via IP in IE.

    By the way, a bit earlier I tried to run combofix in safemode and windows and I still get a bsod at about 90% completion of the first progress bar.

    I still get the occasional unexpected firefox tab popup to a url like "brain quiz" or some spam nonsense.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have a new form of MBR infection.

    Please run this >> TDSSkiller - How to run And then attach the log from TDSSKiller. Your previous logs were all incomplete. Make sure you run this properly. If it can only get to 80% completion, it is very likely that you do have this new infection.
     
  25. boatdrinks

    boatdrinks Private E-2

    Well good news fellas. Tdsskiller found something this time. The strange thing about this is I thought I successfully ran tdsskiller several times trying to fix this because I've read several posts on this forum where this specific malware had symptoms very similar to mine and tdsskiller usually fixed it. Anyway, this time it found it and after reboot I was able to connect to update.microsoft.com urls. I'm also able to reboot without BSOD. I think I'm clean guys. Anything else you want me to try running or cleaning?
     

    Attached Files:

    Last edited: May 4, 2011
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You had an older copy and it was not running successfully as you can see by your very small logs on the previous runs. The new version fixed was able to run and fix the malware.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds