Network disabled, antivirus gone

Discussion in 'Malware Help (A Specialist Will Reply)' started by Griss, Aug 29, 2010.

  1. Griss

    Griss Private E-2

    Hi guys,
    My neighbour asked me to try fix his laptop(XPpro) and I'm having problems. He got infected from a downloaded file. All network adapters in device manager show yellow exclamations and error code 39. Antivirus has disappeared from sys tray and Add/Remove Programs. Cannot open Task Manager. Cannot install antivirus software (recieve error messages). Managed to install Spybot in safe mode and removed infections found, including security centre and hosts hijackers.
    I have tried using a restore point, without much success, and ran SFC. Have also tried reinstalling device drivers but no joy. I have followed the READ & RUN ME FIRST sticky and attach all logs.
    Any assistance would be greatly appreciated
     

    Attached Files:

  2. Griss

    Griss Private E-2

    And here is the MGlogs.zip file. I have gotten Avast AV to install, but i can't get the resident shields running. Also, task manager now opens and security centre seems to be back, but still no network access. The cleaning steps have had some success though.
    Hope you can help with the rest.
    Thanks
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=%s
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Griss

    Griss Private E-2

    Hi chaslang and thanks for the speedy response.
    Tried doing as you said. Ran analyse.exe no problem, but when i ran combofix with the CFscript, windows shut down and i now get a blue screen on startup with stop error 0x7E. Have booted to Safe Mode and am restoring to last restore point, which was earlier today, when i installed Avast (Just after doing READ & RUN sticky steps).
    Any suggestions?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach the new followup MGlogs.zip file after running GetLogs.bat as requested. This way I can see what may or may not changed. Do not rerun ComboFix unless I ask you to do so.
     
  6. Griss

    Griss Private E-2

    OK, reran analyse.exe after restore. Here's the new MGlogs. Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download and save this XPsp3bu.exe to your C:\ root folder ( or to your Desktop if you have a problem saving to the root). You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need. This will not fix anything and neither will the below. These are necessary steps so that I can prepare the next fix.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  8. Griss

    Griss Private E-2

    Ok, here's the new log file. Sorry for the delay. Time zones!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    If the above does not work, it may be necessary to use the Recovery Console to fix this problem. Do you have your Windows XP bootable CD?
     
  10. Griss

    Griss Private E-2

    Hi chaslang,
    I ran The Avenger and bsod 0x7E is back at restart. I tried safe mode restore again, but still getting bsod and restore fails.
    I don't have actual disc that came with laptop, as it had vista on it when he bought it, and he brought it to a repair shop and got them to install xp on it instead. I have copy of xp here but will need to find his product key. Also have UBCD, Hirens, miniPE if any help.
     
  11. Griss

    Griss Private E-2

    Update
    I got windows to boot by removing ndis.sys from drivers folder in safe mode.
    Ran CCleaner and MGlogs. Here are logs.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but that defeats the purpose of my last fix which was restoring your ndis.sys file. Now you have no ability for your network to work. You need the ndis.sys file. You have some other problem that is causing the crash.

    You need to restore the ndis.sys file. You can get a copy from the WinXP CD or you can rerun XPsp3bu.exe which will recreate the C:\MGtools\temp\ndis.sysmg file which is just a renamed copy of the ndis.sys file for WinXP SP3.
     
  13. Griss

    Griss Private E-2

    O.K. Had just moved ndis.sys to desktop. Have replaced it in the drivers folder now.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so now run the below.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Then reboot your PC and see if it boots up okay or if you get a BSOD. If you get a BSOD, write down the exact word for word error message and give it to us. Do not change what it says, give us the exact info.
     
  15. Griss

    Griss Private E-2

    Hi chaslang,
    I can't run SFC in safe mode. Just get a flash of a cmd window. Opened cmd and tried to run sfc /scannow there, but got this error message:
    "Windows File Protection could not initiate a scan of protected system files.
    The specific error code is 0x000006ba [The RPC server is unavailable.]."
    I checked services and RPC is started, but RPC locator is not, and wont start in safe mode.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you in safe mode?
     
  17. Griss

    Griss Private E-2

    Because when ndis.sys is placed in drivers folder, laptop crashes and won't boot into normal mode. BSOD reads:
    "A problem has been detected and Windows has been shut down to prevent damage to your computer.
    If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:
    Check to be sure you have adequate disk space. If a driver is identified in the Stop message, disable the driver or check with the manufacturer for driver updates. Try changing video adapters.
    Check with your hardware vendor for any BIOS updates. Disable BIOS memory options such as caching or shadowing. If you need to use safe mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode.
    Technical information:
    ***STOP: 0x0000007E (0xC0000005,0x805A8290,0xBA50F690,0xBA50F38C)"
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then temporarily move the driver out of the system32\drivers folder and back to your Desktop. Then boot in normal mode. While in normal boot mode see if you can run the sfc command. If not, then you have problems with Windows itself that need to be repaired and will likley have to work in the Software Forum on that.
     
  19. Griss

    Griss Private E-2

    Hi chaslang,
    Did as you said and still had problems. Laptop owner was getting impatient so he agreed to clean install of XP. Thanks a million for all the effort in trying to fix the issues. It is very much appreciated.
    All the best,
    Griss
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome
    Probably just as well since it was looking like Windows was broken anyway.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds