Regular Disconnects

Discussion in 'Malware Help (A Specialist Will Reply)' started by Klienfelt, May 3, 2011.

  1. Klienfelt

    Klienfelt Private E-2

    Until a couple of days ago everything seemed to work fine and it seems that I may have picked up something that is causing me to constantly make the internet unavailable. I have tested the internet on another pc and it has no problems.

    I have done all the scans and SAS and MBAM found nothing.
    I got an error message when trying to run Rootscan that "Invalid PE Image Found". However the scan still completed.
    I also got an error when trying to run MGTools that "Application has generated an exception that could be handled, Process ID = 0xc5c (3164), Thread ID = 0xc0 (192). I have .Net installed already.


    I have attached the Combofix, Rootscan, MGtools logs if anyone could help me out it would be appreciated. If you need the clean logs of Mbam and SAS I can upload them next post.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Running from: d:\downloads\ccffix.exe <--- Needs to be run from the desktop. Please move it there now before moving on.

    I still want to see their logs please.

    You have alot of missing files being reported by Combofix so I would like for you to run the below.

    Running SFC Scannow


    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      srsvc.dll*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\bltofzsb.qlf
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. Klienfelt

    Klienfelt Private E-2

    Ok well I'm stuck at the first hurdle, cannot run Msconfig from the run prompt. Says windows cannot find the file.

    Just to let you know, before installing XP on the machine I slimmed it down with Nlite so as to fit it all on a 4gig SD drive so some of the files were left out of the install.

    Since my first post I noticed last night that the volume icon had disappeared from the taskbar and I had no volume. I checked in Device Manager and found loads of audio and video codecs had been installed. I tried to remove some of the audio codecs and got the message that I didn't have permission to remove the drivers! I rebooted in safe mode and managed to remove the audio drivers one by one, however the video drivers are still there and haven't been explicitly installed by me.
     
  4. Klienfelt

    Klienfelt Private E-2

    Have now managed to download Msconfig.exe and restarted in Normal Mode.
    I have been unable so far to run SFC Scannow as I have a SP2 XP disk and it requires me to have the SP3 disk. Is it going to work if I download this file and copy it onto a disk?

    http://www.microsoft.com/downloads/...ce-b5fb-4488-8c50-fe22559d164e&displaylang=en

    Anyhow this is going to take some time as I don't have any blank cd's atm so I have done all the other scans and attached the logs.
     

    Attached Files:

  5. Klienfelt

    Klienfelt Private E-2

    Mbam and SAS logs.
     

    Attached Files:

    • Mbam.txt
      File size:
      912 bytes
      Views:
      3
    • SAS.txt
      File size:
      465 bytes
      Views:
      3
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      Volsnap.sys*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    This is something you are going to have to sort out in the software forum.
     
  7. Klienfelt

    Klienfelt Private E-2

    I have attached the log as requested and will post in the software forums regarding the sp3 issue.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm. Combofix is reporting infected files and I do not believe it in this case. I would like for you to post in the software forum like we said regarding the SP3 and then return here and I will have you run Combofix again and see what is what.
     
  9. Klienfelt

    Klienfelt Private E-2

    Yay! I made the new disk and slipstreamed SP3 onto it and I have run the Scannow command without errors, so I will await further instructions.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right good, so now run Combofix again and lets' see what it reports. :)
     
  11. Klienfelt

    Klienfelt Private E-2

    Ok so the new Cfix log is attached I ran it the normal way by just clicking on it, wasn't sure if I was suppose to run it again the way you described in your first post again?

    Unfortunately, I am still having disconnection issues.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.
    • c:\windows\system32\Drivers\Volsnap.sys
    • c:\windows\system32\srsvc.dll
     
  13. Klienfelt

    Klienfelt Private E-2

    hmmm, neither files are present on the computer, the closest file that I have is srvsvc.dll
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea, I am just not trusting what Combofix is reporting. I do not think you have malware problems and I suggest that you post in the software forum about your disconnecting issues.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Klienfelt

    Klienfelt Private E-2

    Ok well thanks alot for your time and assistance, so I was clean at the start?
    Is it worth me reporting these false positives to Combofix, if so how?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We removed a small piece of malware but I was not seeing anything else, no.
    No, not worth reporting the FP's, it happens sometimes. For instance files it reported as infected does not even exist. So we know straight away that what it is reporting is wrong.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the volsnap.sys file and the srsvc.dll files are missing then that is a problem because they are necessary files. Thus you would need to restore these from somewhere on the harddisk, from the Windows XP SP3 CD or from System Restore. However they are not missing. ComboFix told you that.

    ComboFix told you that volsnap.sys is infected and this should not be ignored. It could be due to a TDL infection and the file could be hidden due to this.
    ComboFix also told you the srsvc.dll file was infected and it could be hidden for the same reason and that cannot be ignored either. You really need to verify that the files are truly not missing. It they are missing, they need to be restore ( along with the below ). And if they really are there and are hidden, a rootkit like infection could be hiding them. It would be a good idea to check for them from the Recovery Console.

    The same goes for the other files it said were missing.
    Code:
    c:\windows\system32\proquota.exe . . . is missing!!
    c:\windows\System32\drivers\beep.sys ... is missing !!
    c:\windows\System32\es.dll ... is missing !!
    c:\windows\System32\srsvc.dll ... is missing !!
    c:\windows\System32\wscntfy.exe ... is missing !!
    c:\windows\System32\regsvc.dll ... is missing !!
    c:\windows\System32\schedsvc.dll ... is missing !!
    c:\windows\System32\ssdpsrv.dll ... is missing !!
    c:\windows\System32\termsrv.dll ... is missing !!
     
    Last edited: May 6, 2011
  18. Klienfelt

    Klienfelt Private E-2

    Well I'm really not sure where to go from here. I'm not sure how I check if these files are present or not.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh I just noticed Kestrel13! already asked you to run this. If you ran it before and it did not ask for your CD, then there is no sense in running it again.

    If is possible that you have have removed all those file yourself from your installation what you used nlite. I don't know for sure since I don't use it. At anyrate, Combofix is likely declaring those two files to be infected when in reality they are just missing. This is a problem that ComboFix has with some files. But the other files that it stated are missing are really missing. So either you need to put them back using SFC and if that does not work, you will need to copy them from your Win XP SP3 CD.
     
  21. Klienfelt

    Klienfelt Private E-2

    Well now I really am confused, shall I ignore the volsnap.sys and srsvc.dll combofix reports of infection or not?
    I already ran the scannow command and it did ask me for the disk which I had made specially for that and it ran ok.

    I have run combofix in the past on this machine and it has never reported that volsnap.sys is either missing or infected. It has however, reported that srsvc.dll is missing and infected in the same report.

    What i would like to do is copy the volsnap.sys and srsvc.dll files onto the hard drive and run combofix again. What do you think?
    Do all the files belong in C:\WINDOWS\system32 ?

    And what is the best method for copying them onto my pc?
     
  22. Klienfelt

    Klienfelt Private E-2

    Ok so I have managed to extract volsnap.sys and srsvc.dll and have run a new combofix scan.

    Volsnap.sys was located at windows\system32\drivers and that's why I couldn't see it, I was directed to windows/system32 to look for it.

    Well it was there and it was infected and now it has been replaced. So I think the scan looks alot better now, do you think I'm clean now?
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Now replace the below missing files too
    Code:
    c:\windows\system32\proquota.exe . . . is missing!!
    c:\windows\System32\drivers\beep.sys ... is missing !!
    c:\windows\System32\es.dll ... is missing !!
    c:\windows\System32\wscntfy.exe ... is missing !!
    c:\windows\System32\regsvc.dll ... is missing !!
    c:\windows\System32\schedsvc.dll ... is missing !!
    c:\windows\System32\ssdpsrv.dll ... is missing !!
    c:\windows\System32\termsrv.dll ... is missing !!
    No! Kestre13! told you to look in the drivers folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds