Malware or Not?

Discussion in 'Malware Help (A Specialist Will Reply)' started by upagumtree, Apr 20, 2009.

  1. upagumtree

    upagumtree Private E-2

    I suspect malware of some sort but cannot identify it. Strange things keep happening to this PC. e.g. Windows will often not shut down properly - screen says "Windows is shutting down" but nothing happens and user has to power off. On restarting, there may be a keyboard/Interface error - press F1 to resume and/or failure of the cursor to respond to mouse movements. After several restarts, I eventually get a functional mouse and then Windows security center will report that Kaspersky Internet security is turned off - may be just the antivirus turned off or just the firewall or both. At the moment windows security centre says that Kaspersky is turned on and the Kaspersky icon is present in the icon tray but it will not open if I right click on the icon. Have had the blue screen of death several times. At present IE7 will not connect to anywhere, but Firefox is perfectly happy.
    OS is Windows XP. Logfiles attached as requested. Please help, it's driving me nuts.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    It does not look like all your problems are do to malware.

    Do you have any idea what the below fairly new file is for?
    2009-04-11 19:04 . 2009-04-11 19:04 737 ----a-w c:\windows\system32\%LocalXml%

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 7

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\john\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. upagumtree

    upagumtree Private E-2

    Thank you for your reply.
    I have uninstalled SUPERAntiSpyware and installed the new version. Clicking the 'check for updates' button does not download any updates. I have tried several times but to no effect. The update button had stopped working on the previous version as well, I think on the 16th.of April.
    The update button on Malwarebytes will not download any updates either, after several attempts. It used not to be a problem until a week ago. I have attached logs for the two programs anyway.
    I do not know what the file c:\windows\system32\%LocalXml% is for, but I will attach it for you. It can be viewed with notepad and has changed contents today.
    I've started to clean up the desktop.
    Windows Messenger has been removed.
    Java(TM)6 Update 11 and Update 7 have been uninstalled.
    Combofix has been run with CFscript.txt as requested. Combofix took several hours to run and said it was going to restart Windows. The "Windows is shutting down" screen appeared and stayed on screen for another two hours. I assumed this to be another instance of Windows failing to shut down properly and powered off at this point. On restarting the PC, Combofix produced it's report.
    I've downloaded an .exe file for Sun Java from your link and run the file, but it doesn't seem to have actually done anything!
    Temp files removed and Ccleaner run as requested.
    c:\MGtools\GetLogs.bat has been run. C:\ComboFix.txt and C:\MGlogs.zip are attached.
    IE7 will still not connect to anywhere, but Firefox is functioning normally. Mouse has not been a problem for a while. Kaspersky Internet Security is still not happy. Twice It's given a warning message, "Attention. Black list of keys is missing or corrupted. Please run the update to continue operation." Also another Kaspersky screen "Uploading collected memory filedumps and traces to Kaspersky lab servers. Previous application launch failed." The Kaspersky update proceeds as it should and operation appears normal after that. I'll await your reply with interest.
     

    Attached Files:

  4. upagumtree

    upagumtree Private E-2

    Attached is the file c:windows\system32\%LocalXml% given the .txt extension to allow it to be attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. Appears to just be a test file for your antivirus program.

    Your logs are all clean. Even the initial logs did not show any real problems.

    You will have to check that your settings for IE are correct. For example, do you use a Proxy Server to connect to the internet? If not, then you need to change your browser settings so that it is not trying to use a proxy. If you do use a Proxy, then you need to make sure the proper values are entered.

    Also check to make sure you are not blocking IE (iexplore.exe) with your firewall.

    Since you are having problems with Kaspersky anyway, I suggest that you uninstall it and then reboot. After reboot, see if IE works. Then try reinstalling Kaspersky to see if your problems with it go away. If not, you should talk with them about the problems you are having with their program.
     
  6. upagumtree

    upagumtree Private E-2

    It's good to hear that my logs are all clean. The problem with the mouse pointer not responding to movements seems to have been due to an intermittent connection problem. I noticed that if the cable flexed at a certain angle where it enters the mouse casing, then the light on the mouse would go on and off. The mouse has now been replaced with a new one and seems fine. The F1 keyboard errors on bootup has also gone away.
    Settings for IE seem fine, but IE will still not connect to any site. The Kaspersky firewall has the same settings applied to IE as to Firefox which is working.
    Firefox will connect to www.kaspersky.co.uk home page, but hangs if I click on links from there to user forums or technical help. I am reluctant to uninstall Kaspersky Internet security. It was purchased and downloaded on line from Kaspersky and I do not have a disk to reinstall it from. I would hate to end up with no protection at all. The blue screen of death has appeared twice more while the PC was idle. At the top of the blue screen it has "IRQ_NOT_LESS_OR_EQUAL" At the bottom of the screen it has the codes 0x0000000A (0x00000000, 0x00000002, 0x00000000, 0x804FD5F3) or
    0x0000000A (0x00000004, 0x00000002, 0x00000001, 0x804DBE9B) on the last two occasions.
    I've tried again to install the current version of Sun Java from your link and also tried downloading it from Java.com Your site saves an .exe file of circa 15 MB to my hard disk while that from java.com is only circa 550kB. Neither of them appear to actually install anything. I am asked if I want to run the file, to which I answer Run. Then ....nothing happens. The .exe file is listed as a running process in the Task Manager but nothing is installed.
    I fear that if I uninstall Kaspersky and then attempt to download it and install it again, it will either not download or not install.
    Any suggestions as to where to go from here?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that IE is not being blocked by your firewall? Temporarily shutdown your firewall and see if IE connects.

    If it is still showing up as being disabled at various times, you may not have any choice as your problems do not appear to be malware related.

    These kinds of errors are most frequently related to Windows or other software application errors. You should check your event log to see what application is crashing. See this: http://support.microsoft.com/kb/308427


    The 15Mb version would be the correct file. The actual size in bytes should be 16,283,032 bytes. What you got from Sun may just be a file that downloads the installer.


    Let's just error on the safe side and do a check for rootkits. Run the below and attach the logs:

    Running GMER to detect rootkits

    Trend Micro RootkitBuster
     
  8. upagumtree

    upagumtree Private E-2

    Internet Explorer will not connect to any site even if the firewall is temporarily disabled.
    I have contacted Kaspersky and uninstalled and then downloaded Kaspersky Internet Security again. Problems continue. In fact, after installing Kaspersky again, Firefox would not connect to any site. On checking the LAN settings in Settings>Network connections the IP address had disappeared. I did a system restore to a point before uninstalling Kaspersky and the IP address reappeared and Firefox worked again, but IE7 still won't work.
    Please find attached a GMER log. I also downloaded TrendMicro RootkitBuster from your link. Unlike GMER, your link goes straight to a download page without any instructions on how to use it. The .exe file for RootkitBuster produces a window when it is run which says, "Windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item."
    The start of these problems seems to coincide with a Windows automatic update which took place on 17th. April. This included an IE7 update KB963027 and Windows updates KB952004, KB960803, KB961373, KB923561, KB959426,KB956572. This may just be a coincidence. I do remember last year, when I was using the Zonealarm firewall, a background Windows update interfered with Zonealarm and prevented any internet connection. But then lots of people were affected and it was mentioned on the BBC news. By the time I heard that, I'd spent 2 days checking my PC, router and cables
     

    Attached Files:

    Last edited: May 2, 2009
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GMER log is also clean.

    Since your problems do not appear to be malware related, I suggest that you posted the exact details of your current status. Like which browsers work and which do not. Also whether Kaspersky is still giving you problems.

    Before going to the Software Forum, I suggest that you run one more procedure just to see if it changes anything. Run this: Resetting Registry and File Permissions
     
  10. upagumtree

    upagumtree Private E-2

    I ran the "Resetting Registry and File Permissions," as requested. This ran with no problems, but things were unchanged. i.e. IE7 and BT Yahoo browsers would not connect to any site and the update buttons on Malwarebytes and Superantispyware would not download any updates. Firefox and Google Chrome were operational. Kaspersky Internet Security was fully operational after the reboot following "Resetting Registry and File Permissions." The blue screen of death occurred again for no apparent reason. On rebooting again after this, Kaspersky once again was fully operational.
    I had noticed from the Application logs in the system event viewer that error messages involving avp.exe (Kaspersky) were often preceeded by errors involving khost.exe or KService.exe. So I uninstalled 4oD, the application that allows you to download TV programmes from channel 4 TV in the UK. This produced a window saying "4oD Installer Information: Error 1905.Module
    C:\WINDOWS\system 32\macromed\Flash\Flash9d.ocx failed to unregister. KRESULT - 2147220472. Contact your support personnel." Despite this, it then said that the application had been successfully uninstalled.
    After this, IE7 and the BT Yahoo browser were back in working order, the update buttons on Malwarebytes and Superantispyware were functioning. Also, I was able to install Sun Java 6 Update 13 which had refused to install on several previous occasions. It may be premature to say that all my problems are solved, but it certainly looks to be a step in the right direction.
    I was able to direct IE7 to the Microsoft updates page. It is suggesting that I download IE8. I thought that might be a step too far at the moment, so I will see if IE7 stays stable for a while.
    I can only assume that the Microsoft updates on 17th.April disagreed in some way with the 4oD application which has been on this PC for at least a year. So, thank you very much for all your help and advice. You've led me into corners of the PC that I never knew existed.
    Just one nagging problem. I attempted to uninstall the BBC iPlayer download manager as I think it uses the same Kontiki system as 4oD. This produced an error window saying, "Installer information: A network error occurred while attempting to read from the file: C:\WINDOWS\Installer\bbciplayer_client_live.msi" It said the application had not been removed. Now if I click on the Change/Remove button for this programme in Add/Delete programs in the control panel, I am guided into the Install procedure rather than being given an uninstall option and the program size is given as only 0.01M. It looks as though it is not fully uninstalled. How should I resolve this?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this 4oD/Kontiki junk is something we have frequently suggested removing. Many people just remove it on sight like it is malware. It is not malware but it is not desirable.

    Your welcome.


    Please post all non-malware related questions in the appropriate forum. This should be posted in the Software Forum.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds