Anti-virus 360 and system reboot

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bad Panda, Feb 19, 2009.

  1. Bad Panda

    Bad Panda Private E-2

    We have a Vista system that was infected with Virusscan 360; the system reboots repeatedly. When I go to "Last Known Good" configuration it enables me to login and work. When I reboot the computer it goes into a reboot loop. I have ran all the utilities. The logs are attached. Thanks in advance!
     

    Attached Files:

  2. Bad Panda

    Bad Panda Private E-2

    Here is the malwarebytes log.
    Oh, one more piece of information. The reboot also occurs in safe mode. The very last thing to show loading in the drivers is a thing called adawares.sys or something like that. It goes by pretty quickly and I can't read the thing; but I don't believe that should be in my drivers for safe mode.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Bad Panda.

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is your 12 thread in less than a year. 10 of these threads are in the Malware Removal Forum. These appear to be all different PCs. Who do these PCs belong to and why are you fixing them?
     
  5. Bad Panda

    Bad Panda Private E-2

    I have a small computer consulting business and work on computers for friends. We also donate our time to a small school, and this is one of theirs. I found out last year some time that you don't deal with computers when it is for profit; so we don't contact you if it is a paying customer. Do you need additional information from me regarding this?
    Regards,
    Bad Panda

    P.S. Also, when I have worked on computers for my friends and used you, one of your techs asked me to have them contact you directly and work with you. So, that is what is happening now and why we haven't contacted you in a while.
     
    Last edited: Feb 24, 2009
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Bad Panda

    :) Ok --- let's get started, then.


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Re: Vista Cleaning Procedure ---> Step 2: Disabling User Account Control

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Run Ccleaner

    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    dr.m
     
  7. Bad Panda

    Bad Panda Private E-2

    System continues to reboot. I'm going to have to switch over to last known configuration again. The problem has not been resolved. :cry
     
  8. Bad Panda

    Bad Panda Private E-2

    Dang this is frustrating. I'd love to get my hands on the people that write these things.
    Anyway, here are the log files you requested. Have a good evening!
    Panda
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs show that you DID NOT follow my instructions.
    Repeat all of my instructions starting at Step 2: in my last reply.{ post#6 }

    dr.m
     
  10. Bad Panda

    Bad Panda Private E-2

    I did disable the anti-virus program. The program was running on the initial start of ComboFix. It reported that the agent was running, I disabled it and continued. It gave me the message again that the AV was running and that it was my own risk, but the program WAS NOT running.
    Was there anything in the logs that you saw that could account for the system rebooting? I am going to redo your instructions as you requested, but I'm concerned about hitting the "Last Known Good" option as often as I am having to do. I'm worried that I am putting something back into the system that you might think has been removed.
    Panda
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    Try this:
    Before using ComboFix, open Task Manager > Processes Tab to END the following processes:

    • [*]MSASCui.exe
      [*]UfSeAgnt.exe
      [*]SfCtlCom.exe
      [*]TMBMSRV.exe
      [*]TmPfw.exe
      [*]TmProxy.exe

    Repeat all of my instructions in post#6 starting at Step 2:...re-booting after running Step 3:


    Your logs show that your protection interfered with the fix...that is the purpose of the CFscript.txt -- to get some malware successfully removed.
     
    Last edited: Mar 3, 2009
  12. Bad Panda

    Bad Panda Private E-2

    okay doctor, I'm having a bit of a problem. Most of the processes that you are telling me to end are being reported to me as services. I can not end the services for some reason.
    Would you suggest for the time being I uninstall Trend Micro? Or is there another way that Vista will allow me to stop these services?
    Thanks for the help. By the way, you posted that last post at Midnight??? Are you just a caffeine junky or are you somewhere in the UK?
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :p
    Heh.. It appears --- that I need more coffee! My mistake...

    Disable a Service in Vista
    1. Open the Start Menu
    2. In the "Start Search" area, type services and press Enter
    3. If prompted, click on Continue in the UAC prompt, or provide the administrator
      password to approve.
    4. Scroll down the list of services till you see the service you want to disable:
      MSASCui.exe
      UfSeAgnt.exe
      SfCtlCom.exe
      TMBMSRV.exe
      TmPfw.exe
      TmProxy.exe
    5. Right-click on the service name and from the drop down menu, select Properties/b].
      • Click on the Stop button and wait a second for it to stop.
      • Next to Startup type, click on the drop down menu and select Disable.
      • Click on the Apply button.
        NOTE: If the service will not stop and gives a error, then you will need to restart the computer to stop it after you set it to Disabled and clicked on OK.
      [*]Close the Services window.


    NOW - Repeat all of my instructions in post#6 starting at Step 2:...re-booting after running Step 3:

    ** Try running ComboFix in Safe Mode the above doesn't work. Our last resort will be uninstalling Trend Micro temporarily.

    dr.m
     
  14. Bad Panda

    Bad Panda Private E-2

    Hey Dr. Wanted to update you on what has been happening.
    First, I was not able to disable the services that you needed. I was only able to find the following:
    ufseagnt.exe4
    tmbmsrv.exe
    tmpfw.exe
    tmproxy.exe
    Since I couldn't stop the services I had to disable them and reboot. Windows wouldn't come up again, so a last known good change had to be made...this reversed the changes I made to the services. I tried this 3 times before giving in and uninstalling the AV program. Restarted again, and the problem still exists. Now, this rebooting occurs even in safe mode. I noticed that the last of the drivers listed as being loaded into safe mode is the following:
    \windows\system32\Drivers\adwarealert.sys
    This is not a usual driver that I remember seeing. Also, notice that the "drivers" section was capitolized; different than the previous drivers that were all lower-case. I'm thinking this may be some spyware or something; but I can't get to it. Does this trigger anything in your memory? I'm working on it still but not making any headway. Any possible direction would be appreciated.
    Panda
    P.S. Oh, and the networking died. I did a netsh reset interface IP, but don't yet know if it corrected the problem....especially since I have to do another Last Known Good Configuration change.
     
  15. Bad Panda

    Bad Panda Private E-2

    I just uninstalled adwarealert as I found on another thread. I somehow missed it in add/remove programs. The PC appears to have booted normally, but TCP/IP still seems to be trashed. Any thoughts?
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello

    AdwareAlert shows in your MBAM log:
    Let's clean up after it and see if we can now get some more logs. Note: If ComboFix won't run in Normal Mode --- try booting into Safe Mode.

    Using ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Run Ccleaner

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!
     
  17. Bad Panda

    Bad Panda Private E-2

    Here are the logs you requested. Combofix seemed to work fine, with the exception that it states it is outdated. Since it can't get to the internet it says that it is outdated.
    Thanks!
     

    Attached Files:

  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    We're almost done with the malware removal.

    Please describe exactly what the problem is.
    • Is the connection hardwired or wireless?
    • Is a proxy being used? If so -- is it properly set?
    • If a proxy is not being used --- make sure the connection is set to not use one.

    Using ComboFix
    If ComboFix won't run in Normal Mode --- try booting into Safe Mode.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Run Ccleaner

    Please attach the C:\combofix.txt log and your answers to the questions I asked.

    Thanks!
    dr.m
     
  19. Bad Panda

    Bad Panda Private E-2

    Here is the log you requested. There were no issues running Combofix, and the system has not again had the issue with a problem rebooting.
    As for the interface problem, here is what I can tell you starting with your questions first:
    Is the connection hardwired or wireless? A: hardwired
    Is a proxy being used? If so -- is it properly set? A: no proxy is in use.
    If a proxy is not being used --- make sure the connection is set to not use one. A: No proxy is configured on the interface.

    My observations on the network connection are the following:
    The network interface hardware shows up in the Network Connections section. The NIC has the appropriate services attached with the exception of something from Trend Micro (a driver) which I have since removed. The NIC shows up that it is working in hardware, I get a link light, and all appears well in the world.
    However, when I go into CMD and do an IPCONFIG, that interface is not listed. In the network connections in Vista, it is listed as the only interface. However, in IPCONFIG 2 interfraces are listed as "disconnected" starting with Interface #6. It's odd. I'm assuming that the 2 listed are IP4 and IP6, but I can't figure out why they are disconnected.
     

    Attached Files:

    • log.txt
      File size:
      11.9 KB
      Views:
      4
  20. Bad Panda

    Bad Panda Private E-2

    Hey Doctor! You still with me? Or has Holmes finally won out?;)
     
  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    At what - checkers? .... not even that! :p

    * Just a comment: Using "Last Known Good Configuration" will put back things that were already fixed, so let's not use it while we're working on the pc.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 3:
    Run Ccleaner

    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds