Code 80072EFE and other issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by lh1162, Jul 16, 2010.

  1. lh1162

    lh1162 Private E-2

    First time post, I hope I followed the instructions adequately!

    I was fooled by a pop-up window that I thought originated from my anti-virus software a few days ago. It turned out to be a Trojan. This virus caused the main windows screen to go all black after 30-60 seconds of loading. On subsequent reboots it also caused different windows toolbars to disappear.

    I thought I had solved the problem by following the procedures in your "Read and Run me First" section, but I still have issues. I now receive the following error message when trying to update Windows:

    Code 80072EFE Windows Update encountered an unknown error.

    Running Windows Vista Professional.

    The screen also goes very fuzzy on the login page for Windows, in color but kind of like an old black and white TV set. This goes away after a second or two.

    This computer is critical to the operation of our business. I would appreciate any help you could provide. I am now attaching logs.
     

    Attached Files:

  2. lh1162

    lh1162 Private E-2

    Here is the MG tools log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 20
    • Java(TM) 6 Update 7
    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    hiijfuuu
    File::
    c:\windows\System32\drivers\tydp.sys
    c:\users\Perats\AppData\Local\Ysuhikomejesux.dat
    c:\users\Perats\AppData\Local\Ntaviwoniqivux.bin
    Folder::
    c:\users\Perats\AppData\Local\wnwkubkwe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running now?
     
  5. lh1162

    lh1162 Private E-2

    OK, done. I followed the processes, and I attached the log to this post as instructed.
     

    Attached Files:

  6. lh1162

    lh1162 Private E-2

    Also, I still cannot access windows update. I know there are updates I have not installed, but the icon that usually prompts me to do updates in the bottom right corner of the screen is not appearing any longer.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good to me now. Hmm..

    I see windows updates running in your running processes shown in the HJT log.

    Tell me exactly what happens again when you go to control panel > and windows updates? Do you receive the same error code?


    Try manually visiting the windows update site using internet explorer. Or...
    (Start > Windows Update or open IE, click Tools, Windows Update)
    or...

    Now go to Start > Run > type in

    Click OK or press Enter

    You can attach that log to a post in the software forum. There's nothing more I can do for you here as all the malware has been removed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. lh1162

    lh1162 Private E-2

    Sorry it has taken me so long to follow-up...

    I ended up having to pay Dell for support. Since we were under some time pressures, it was a real need.

    The main hint that I was still infected was that I could not access Windows Update at all, though another Vista computer in our office could.

    After hours of getting help from Dell, running the same tools we had run in this forum and finding nothing, I was close to giving up. Finally they ran SpyBot in Safe Mode. This uncovered over 14000 infections!!! Several more hours of running scans got the computer clean.

    Thanks for your help, I just wanted to let everyone know what finally solved the issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds