Malware – DWGR12S – 2010.08.20

Discussion in 'Malware Help (A Specialist Will Reply)' started by manilka835, Aug 20, 2010.

  1. manilka835

    manilka835 Specialist

    Dr. K.D.J.H. Manilka Jayawardena,
    Medical Officer,
    National Tuberculosis Reference Laboratory (Central Laboratory of NPTCCD),
    Chest Hospital Premises,
    Welisara.
    Sri Lanka.
    Friday, 20th August 2010.​

    Dear MajorGeeks Forum,

    Malware – DWGR12S – 2010.08.20​


    None of your scanners were installed in this computer before, and since last week, this Computer’s Startup became very slow.

    The following message also appears on Startup.

    Failed to connect to a Windows service
    Windows could not connect to the System events Notification Service service. This problem prevents limited users from logging on to the system. As an administrative user, you can review file system Event Log for details about why the service didn’t respond.

    • Also Installation of StartupCPL failed

    • No Internet Connection is indicated and cannot Update SAS or any other scanner but on clicking the icon there is connectivity.

    • Unable to run Disk Defragmenter or Install Disk Keeper Lite stating Administrative privileges are not available even though this is the Administrator account

    I have run READ & RUN ME FIRST- Malware Removal Guide to make sure there are no Malware. The relevant logs are attached.
    The RootRepeal did not run as it suddenly closes in the middle of the scan on Normal Startup Mode and Safe Mode.

    Please advice on further action.


    Thanking you.​

    Yours Sincerely,
    Manilka​
    :confused
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is this a business machine? If so I will work with you as long as you consider the following risks:

    This entry here reveals why you have no internet access:


    This is way you have no internet access. Let's try going to the repais tab in SUPERantispyware,use the Repair broken Network Connection (WinSock LSP Chain) option. Let me know how that goes.

    Off-topic, I have visited the beautiful tear-drop island of Sri Lanka twice. What an amazing country you live in.

    Did that fix your internet connection?
     
  3. manilka835

    manilka835 Specialist

    Dear Kestrel13!
    Malware Fighter – Major Dilemma,

    Malware – DWGR12S – 2010.08.20

    The above computer is used for laboratory work. We have made backups in case there is loss of laboratory information or client information. Therefore you are free to do anything as we are trying to salvage the computer without formatting it. This Computer’s Startup is still very slow. The following message also still appears on Startup.

    Failed to connect to a Windows service
    “Windows could not connect to the System events Notification Service service. This problem prevents limited users from logging on to the system. As an administrative user, you can review file system Event Log for details about why the service didn’t respond.”

    • Also Installation of StartupCPL failed

    • No Internet Connection is indicated and cannot Update SAS or any other scanner but on clicking the icon there is connectivity. Using the repairs tab in SUPERantispyware, use the Repair broken Network Connection (WinSock LSP Chain) option also failed to establish the Internet connection. On running the wireless Internet, it indicates the message “Network Connection Prompt: Connection terminated”.

    • Unable to run Disk Defragmenter or Install Disk Keeper Lite stating Administrative privileges are not available even though this is the Administrator account

    A message appears that The COMODO Antivirus is turned off even though the programme indicates it is functioning normally and up-to-date even though its last update on 10th August 2010.

    The RootRepeal did not run as it suddenly closes in the middle of the scan on Normal Startup Mode and Safe Mode.

    When trying to update SuperAntiSpyware it indicates it is up-to-date even though its main screen does not indicate any update since installation.

    I have run READ & RUN ME FIRST- Malware Removal Guide to make sure there are no Malware. The relevant logs were attached previously. I wonder whether all these problems are due to Malware.

    Please advice on further action.

    By the way, Sri Lanka is a nice country to live in especially after getting rid of the terrorist. The only problem is its people do not know to live with what they get and the politicians want and get what they should not have.


    Thanking you.​

    Yours Sincerely,
    Manilka​
     
    Last edited by a moderator: Aug 28, 2010
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Visit the networking forum or the software Forum to resolve this issue, as it is not related to malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds