Can't run antivirus software on W2K3

Discussion in 'Malware Help (A Specialist Will Reply)' started by lucci001, Jul 29, 2010.

  1. lucci001

    lucci001 Private E-2

    Hi,

    This is my first time posting anything to these types of forums so please forgive me if I leave out the obvious. I have a couple Windows 2003 server that appear to be infected by a virus or malware, etc. I was able to install Malwarebytes and run that. It removed a few things on both infected servers but I am still unable to install or successfully run any antivirus software. Even some online scan sites it won't let me even open. Any thoughts?

    Thank you.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We will have to work on one machine at a time. And have two seperate threads, one for each.

    Attach the log from MBAM

    Also make sure you have followed all of the below:

    Windows 2000 & 2003 Cleaning Procedure
     
  3. lucci001

    lucci001 Private E-2

    Here is the MBAM logs from "server1". I am going through the instructions in teh cleaning procedure you provided now. I will let you know when it's done. So far the Super Anti Spyware is picking some stuff up so maybe just going through those tasks will help.
     

    Attached Files:

    Last edited by a moderator: Jul 31, 2010
  4. lucci001

    lucci001 Private E-2

    Here are the results when I ran through the steps for the Windows 2003 cleanin procedure provided.

    Ran the Super Antispyware twice. Cleaned up files both times. Twice it cleaned registry entries that prevented me from opening task manager and regedit. This became a problem later when I tried to run MGTools. I attached the logs from these two runs.

    Tried to run Combofix but it said it would only work on Windows 2000 or XP. I am running Windows 2003 R2 sp2.

    Tried running RootRepeal but it crashed right away with the following log.
    ROOTREPEAL CRASH REPORT
    -------------------------
    Windows Version: Windows Server 2003 R2 SP2
    Exception Code: 0xc0000094
    Exception Address: 0x004eca19

    I then tried to run MGtools and got tons of error messages saying it couldn't update the registry. I tried running regedit and it said I wasn't authorized. I tried to open task manager and that was disabled again too. That had never happened until I started running Super Antispyware those first couple times. Anyway, I am attaching the zipped up logs from MGtools anyway.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's start by downloading a tool we will need.

    Pocket Killbox

    Save it to its own folder somewhere that you will be able to locate it later.

    Open up task manager and end the process of the following processes if seen running:

    • winhymr.exe
    • w72c0f.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winhymr.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\w72c0f.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\tmpykwdar
    C:\Documents and Settings\Administrator\Local Settings\nsq12.tmp
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot look for all of the above files we had Pocket Killbox attempt to delete. If you still see them, delete them yourself.

    Use windows explorer to find and delete the below folder:

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running.
     
  6. lucci001

    lucci001 Private E-2

    I noticed that when I ran Malwarebytes that some of the detection types on some of the infections it picked up were Win32.Sality. I found a SalityKiller tool on Kasperspy's web site which I had to download and email to myself so I could actually get it on the infected server since I couldn't even get to antivirus websites from the infected server. Once I ran this it cleaned up probably over 100 infected files. After it finished I was able to access antivirus web sites and download and install updated antivirus software. I'm running a full scan with the now installed McAfee Enterprise. So far no detections. Looks like this solved most of my issues thus far. I'll donig the same on the other infected server. If it doesn't do the trick I'll open another thread to try and resolve it.

    Thanks for all the insight, however. I learned a lot from this experience.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Very well then, if you are sure you're definately in the clear. However I shall leave this thread open in case yourequire further assistance. :)
     
  8. lucci001

    lucci001 Private E-2

    Okay, server 1 seems to be running well for the last couple days since I got it cleaned up. However, I have not had the same luck with server 2. My registry update and task managers keep getting disabled. I downloaded some freeware that will let me enable them on the fly, but sometimes seconds later it gets disabled again. When I am able to install an anti virus it shorty stops working afterwards. Do you want me to start a new thread on this? If not, what do you want me to run and post?

    Thank you.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Do begin a new thread, because posting another set of logs here combined with all my old instructions for computer #1 would be confusing for us both. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds