Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STICKY

Discussion in 'Malware Help (A Specialist Will Reply)' started by mv0001, Dec 30, 2006.

  1. mv0001

    mv0001 Private E-2

    Hi Everyone,

    I found this site through a Google search, it seems like an amazing resource and a great community. Even though I still haven't fully resolved my laptop issues, I feel like I am learning useful things by following your posts.

    My post is a bit long, but I tried to cover everything that seems relevant.

    Below is a description of what I think might have caused the issues, description of the issues, what I’ve done so far, and the text logs are attached. Any kind of help or suggestions would be really appreciated.


    POSSIBLE CAUSES?:
    One or two weeks ago I installed uTorrent and went a little crazy with downloads (MP3’s, TV Series, Programs – specifically Nero). Windows and Internet Explorer as well as Firefox were updated with the latest patches, Windows firewall was turned on, I was using a wireless router, Windows Defender was running and updated, and AVG Free Edition was also running and updated. The first time I downloaded Nero, errors occurred each time when trying to unzip the file. I think this might have been the bogus file? I downloaded another Nero installation file (shareware…of course) and it installed and worked fine. Next time I used my computer, two issues came up.


    ISSUES:
    1. Pop-ups when using IE, no pop-ups with Firefox.

    2. Windows stop error blue screen started appearing forcing a restart. I have no idea if the two issues are related, but both started around the same time. When I ran all the scans in safe mode the blue screen did not come up. In normal boot mode it occurs two or three times a days. As far as I can tell there is no pattern such as it occurring during higher RAM usage or more processing. Searching for the error code online, all I was able to find a posting on a different discussion board that iTunes and Nero compete for the same driver or resource and can’t be installed at the same system. There weren't any replies or suggestions on how to resolve the issue besides uninstalling both programs and picking one to reinstall. I figured it would be a good idea to get rid of all the Malware first and then deal with the blue screen stop error if it’s still there. I’ve also attached the error logs in case they are useful. If it’s not Malware related or not something covered on this forum maybe someone can still point me in the right direction.


    WHAT I’VE DONE SO FAR:
    - Ran AVG (normal boot mode), it did not find anything.
    - Ran Windows Defender (normal boot mode), did not find anything.
    - Ran Lavasoft Adaware a couple of times (normal boot mode), it found some objects but froze while scanning restore points and the program had to be shut down.

    - Followed all steps in the READ & RUN ME FIRST Sticky. The logs and brief comments are below
     
  2. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Ran CounterSpy in Safe Mode logged in as Administrator. It found WhenU.SaveNow Adware and deleted it.

    Ran Bitdefender and Panda ActiveScan in Safe Mode with Networking Support via IE. Don't think Bitfender found anything. Panda found 4 objects.
     

    Attached Files:

    Last edited: Dec 30, 2006
  3. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Ran GetRunKey, ShowNew, and HijackThis in normal boot mode



    Thanks in advance.
     

    Attached Files:

  4. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Quick Update:

    AVG just ran in the background. I can't export the test results but it did the following:

    - Deleted a restore file from C:\System Volume Information\ that was marked as infected with Trojan horse Generic2.NFY

    - Changed kernel32.dll and shell32.dll from C:\windos\system32\
     
  5. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Blue Screen Stop Error
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Welcome to Majorgeeks!

    I'm not seeing anything that stands out; however I do have some questions about some items!

    What are the below for?
    Code:
    "C:\WINDOWS\"
    ngutil.exe    Aug  3 2006        8258  "ngutil.exe"
    ngevent.dll   Aug  3 2006       29246  "ngevent.dll"
    ngmsgs.dll    Aug  3 2006       74300  "ngmsgs.dll"
    ngmsi.dll     Aug  3 2006       89666  "ngmsi.dll"
    ngwinx.dll    Aug  3 2006      125500  "ngwinx.dll"
    
    Could they be part of that Aventail VPN software?

    What are the below for?
    You can however delete the below files if they still exist:
    C:\Program Files\DAEMON Tools\SetupDTSB.exe
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\whenu_ff.jar
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll
     
  7. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Thanks for replying.

    The files in C:\Windows\ seem to be part of Aventail. When I click on properties on each file it lists aventail. Except for ngmsi.dll and ngutil.exe there is nothing listed under properties.

    O4 - HKCU\..\Run: [Countdown countdown.ini] "C:\Documents and Settings\Mirabel\My Documents\Downloads\countdown\countdown.exe"
    --- Part of a desktop countdown timer

    O4 - HKCU\..\Run: [scrbleh]
    C:\DOCUME~1\Mirabel\APPLIC~1\CLOCKP~1\Casttrans.ex
    e
    --- No idea what this is. Deleted the entire folder.

    O8 - Extra context menu item: -> TimelyWeb - C:\PROGRA~1\EldoS\TIMELY~1\IEPopupExtension.html
    --- Seems to be part of Timelyweb, installed the program some time ago.

    O9 - Extra button: TimelyWeb - {23315657-D3F3-4894-918E-F705AADED27D} - C:\PROGRA~1\EldoS\TIMELY~1\IEToolbarExtension.html (HKCU)
    --- Seems to be part of Timelyweb, installed the program some time ago.


    C:\Program Files\DAEMON Tools\SetupDTSB.exe
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\whenu_ff.jar
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll

    --- Deleted all these files


    Popups are still there. Please let me know if you have any other suggestions or what other tests I should run.

    Thanks.
     
  8. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    I also ran spy sweeper, since I only have the trial version it did not let me disinfect but the log is attached. It looks like it found a couple of Trojans. Maybe the log will help.

    Please let me know what you think.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Run FireFox and click Tools and select Extensions. Do you see anything about WhenU in the list shown? If so, select it and then click the Uninstall button. Did it uninstall successfully?

    Now check to see if the below folder exists and if it does then delete it.
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}


    Now download install and run this AVG Anti-Rootkit If AVG detects the c:\windows\system32:lzx32.sys file, have it attempt to fix/delete it. Tell me the results. If it says it found and deleted it, reboot and then scan again to make sure it is still gone.


    Now download the attached ServiceFilter.zip file and extract ALL the files in it into its own folder (I suggest using C:\ServiceFilter to make things easy).
    • now double click ServiceFilter.vbs to run it.
    • If you have a script blocking program (like an antivirus program) you will get a warning asking if you want to allow ServiceFilter.vbs to run, some will say "malicious script warning" or something to that effect. There is nothing malicious about this script, you can click to allow it to execute.
    • When the script finishes a wordpad doc should open with the unknown services listed in it. If the script could not access wordpad then you will see a message box telling you so, in that case you need to open POST_THIS.TXT by double clicking it.
    • Attach this POST_THIS.TXT file to your next message.
    • The script also creates a folder called OnlyOnRequest. DO NOT post the contents of the files in this folder unless requested.
    MAKE SURE YOU DO ALL OF THE ABOVE STEPS BEFORE DOING THE BELOW!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Spy Sweeper and attach a new log.

    Are you still getting popups?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Make sure you click refresh and re-read message # 9. I was editing it while you logged in!
     
  11. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Thanks for replying and your help so far.

    I deleted WhenU from firefox extensions and there was no C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}

    Ran AVG Anti-Rootkit and did the in depth scan, didn't find anything.

    Couldn't get ServiceFiler to run. When I click on ServiceFilter.vbs it tells me the version and then there is a Windows Script Error (Line: 157, Char.:7, Error: This key is already associated with an element of this colleciton, Code: 800A1C9, Microsoft VBScript Runtime error). Unzipped again same error. Disabled internet, all AV and spyware software but still the same error. And tried running it in Safe Mode logged in as Administrator but still the same error.

    Wasn't sure if you still wanted me to do the registry fix, so I did not do it just to be safe.


    Other things I did in the meantime:

    Googled "trojan-backdoor-rustock" from the spy sweeper log. Found info that it may cause the blue screen windows stop error. Downloaded and ran McAfee Stinger 2.6.

    Ran a bunch of different programs I found in hopes it might remove something. None of them really removed anything but cookies. One of these programs called "trojan hunter" does a fast scan when my computer boots up and I get the following error messages. Can't access following files: C:\WINDOWS\System32\Drivers\dtscsi.sys,
    C:\WINDOWS\System32\Drivers\sptd.sys and can't find C:\WINDOWS\system32\drivers\tifm21.sys. I hope some of this might be useful and did not screw anything up.

    There are no pop ups (I don't know if this is due to all the anti-spyware stuff running) and there are no more blue screen errors. But spysweeper still shows "trojan-backdoor-us15info". Latests log is attached.

    Thanks again.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Seems like something may have removed the rootkit file (rustock).

    Sorry about that. I fixed a couple of duplicate entries. Download the attach new version and use it instead. Then complete the steps in my previous message with the registry patch on thru to the end.


    Those other files you mentioned are valid:
    C:\WINDOWS\System32\Drivers\dtscsi.sys <--- Daemon tools software
    C:\WINDOWS\System32\Drivers\sptd.sys <--- Daemon tools software
    C:\WINDOWS\system32\drivers\tifm21.sys < Texas Instruments Flash Media Driver
     

    Attached Files:

  13. mv0001

    mv0001 Private E-2

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    Thanks again for your reply.

    Service Filter worked fine. The log is attached. I also did registry fix as instructed.

    Everything seems to running good with no pop ups. My only concern left is the "trojan-backdoor-us15info" that Spy Sweeper still finds. The latest Spy Sweeper log is also attached.

    Please let me know what you think.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware + Windows Stop Error -- Not Sure if related. Followed READ & RUN ME STIC

    That's what we have been working on since message # 9 where I gave you the fixME.reg patch and it is also why I was having you run ServiceFilter.

    Apparently the malware must have changed ownership properties of the registry key to make it difficult for you to remove. Let's use a different approach and let's hope SpySweeper is reporting correct info and that that is the only registry key that remains form it.


    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following key and take ownership of it (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\system\controlset001\enum\root\legacy_msasvc

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the Save as type is set to all files; Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if the above registry key still exists after running the above steps.

    Now I want you to use Registar Lite again to navigate to the below key by pasting it into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run SpySweeper again and attach a new log!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds