New Major Geeks user requiring urgent help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peteinhull, Feb 24, 2009.

  1. Peteinhull

    Peteinhull Private E-2

    Hi guys.

    Came accross this forum when I experienced major problems with Malware/Viruses. Carried out all but the last step in the Windows XP Cleaning procedure but now I'm having major difficulty. (This is a seperate computer).

    I had a lot of malware, so my Anti-Virus software obviously wasn't working.

    I went through Super Anti-Spyware, SpyBot, Malware reomver but then when I rebooted I got ablue screen of death with the following:

    PAGE_FAULT_IN_NONPAGED_AREA

    blah, blah, blah...

    *** STOP: 0x00000050 (OxFFFFFFFE, 0x00000000, 0x8A9F8ECA, 0x00000000)

    Can anybody PLEASE help me!!!

    Pete.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is that the full error message? We need any other info given in the message (i.e., I need to know the blah, blah, blah). This may be more of an issue to work in the Software Forum since your PC is unbootable.

    Did you attempt booting in safe mode?

    Also have you tried Last Known Good Configuration?

    You may be facing a repair install or a total reinstall. Do you have your Windows XP bootable CD?
     
  3. Peteinhull

    Peteinhull Private E-2

    Chaslang,

    Thanks for your prompt response. Yes it was as much as I had, the "blah, blah, blah" bit was just to save me typing the full generic blue death screen info.

    I have had to complete a full re-install, however, I now have another problem. I mentioned that I was working off another computer, well this now also has a virus, probably caused by my checking files on an external back-up drive used to back up the original laptop prior to the crash, even though I virus checked this drive with AVG prior to using it on the second PC.

    I will now complete all necessary checks listed in the "READ & RUN ME FIRST" section of this forum and post the necessary logs.

    Thanks again for your prompt response. Any advice you could give regarding my external hard drive would be appreciated.

    Pete.
     
    Last edited: Feb 25, 2009
  4. Peteinhull

    Peteinhull Private E-2

    Chaslang,

    I have now completed all steps as listed in the READ & RUN ME FIRST and Windows XP Cleaning Procedure and have attached my logs accordingly.

    Some issues to report during the cleaning procedure:

    Issue 1 During the Spybot scan, the following message was displayed:

    (to the effect of:) Not all infections have been removed as some are currently in use. These maybe removed after a restart. Can Spybot start after restart? Yes/No

    I entered Yes, the system rebooted and Spybot recommenced before Explorer started. During the scan, the system crashed and a blue death screen was displayed with the following message:

    A problem has been detected and Windows has been shutdown to prevent damage to your computer.

    If this is the first time you've seen this stop error screen, restart your computer. If this screen apprears again follow these steps:

    Check to be sure you have adequate disk space. If a driver is identified in the Stop message, disable the driver or check with the manufacturer for driver updates. Try changing vidoe adapter.

    Check with your hardware vendor for any BIOS updates. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, Press F8 to select Advanced Startup Options, and then select Safe Mode.

    Technical Information:

    *** STOP: 0x0000008E (0xC0000005, 0xF760F889, 0xA925DC2C, 0x00000000)

    *** Lbd.sys - Address F760F889 base at F760D000, Datestamp 49805dde


    Issue 2 During the Cobofix scan, the following message was displayed:

    Combofix has detected the presence of rootkill activity and needs to reboot the machine. Kindly note down on paper, the name of each file. We may need it later:

    C:\WINDOWS\system32\twex.exe

    - End of issues -

    Thanks for your continuing assistance.

    Pete.
     

    Attached Files:

  5. Peteinhull

    Peteinhull Private E-2

    Attached are Spybot report and MGLogs(zipped)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but my point was that we need ALL the blah blah blah info if you expect to get proper help. Remember that for the future.

    Are these logs for the second PC? If so, in the future, please remember that for each PC a different thread is required.

    Also note we do not ask for Spybot logs as we rarely need them. So you don't need to post them unless we specifically ask for them.

    Please see the first important notes and instructions in the READ & RUN ME. You MUST NOT have multiple antivirus programs installed. You need to uninstall either McAfee or AVG8 immediately before doing anything else.

    IMPORTANT NOTE: Some if not many, of your Windows system files are infected. And many other non-Windows files could also be infected. Even if we attempt to fix these problems (which may not be easy to do unless you have an original Windows XP SP3 bootable CD), your system may be unreliable and untrustworthy. You may need to reinstall this system too and you probably need to discard all the backups you were referring to since they may well be infected.


    Files that I know are infected:
    • C:\WINDOWS\system32\ctfmon.exe << and all other copies are infected too
    • C:\WINDOWS\explorer.exe << and all other copies are infected too
    • C:\WINDOWS\system32\userinit.exe << and all other copies are infected too
    • All backup copies of lsass.exe are infected.
    • All backup copies of services.exe are infected.
    • All backup copies of spoolsv.exe are infected.
    • All backup copies of svchost.exe are infected.
    If you wish to attempt to clean your PC anyway, continue with the below.


    First check to see if the below file is really missing as your logs imply. This is a valid Windows file and should not be missing.
    C:\WINDOWS\system32\sessmgr.exe


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Feb 28, 2009
  7. Peteinhull

    Peteinhull Private E-2

    Chaslang,

    Right, I went through all steps, with the exception of the removal of Windows Messanger. My friend wanted to retain this program, however, if it is a problem, I will remove it.

    Also, I tried to remove Macphee, using Control Panel>Add or Remove Programs, but it would not uninstall, any advice would be appreciated. I manually closed Macphee down after each reboot.

    I checked to see if C;\WINDOWS\systems32\sessmgr.exe was missing from the system and it was. I therefore copied accross this file from another computer, so this file is now present.

    Viewpoint Media Player removed. Sorry I must have missed this during the inital cleaning procedure.

    Ran C:\MGtools\analyse.exe and selected F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe, and fixed it.

    Ran Combofix after copying and pasteing the necessary script and I attach C:\ComboFix.txt as requested.

    Lastes version of Java installed.

    CCleaner ran, and thenI also ran the registry cleaner as well. (Should I have done this?)

    Now, this is where the problems started.

    When it rebooted and all the programs loaded, AVG displayed a virus in C:\WINDOWS\system32\charmap.exe The virus was listed as Win32/Heur.

    Spybot crashed at this point.

    I then closed down all anti-spyware and anti-virus software and before I could do anything alse the computer rebooted it's self. This became a constant loop, of restarting the rebooting then restarting etc.

    I had to boot in Safe Mode. I then tried to carry out the last of your instructions by going to C:\MGtools\GetLogs.bat, the process started but during the process, the computer crashed and displayed a blue death screen with the following on it:

    A problem has been detected and Windows has been shut down to prevent damage
    to your computer.

    PAGE_FAULT_IN_NONPAGED_AREA

    If this is the first time you've see this stop error screen,
    restart your computer. If this screen appreas again, follow
    these steps:

    Check to make sure any new hardware or software is properly installed.
    If this is a new installation, ask your hardware or software manufacturer
    for any windows updates you might need.

    If problems continue, disable or remove any newly installed hardware
    or software. Disable BIOS memory options such as caching or shadowing.
    If you need to use safe mode to remove or disable components, restart
    your computer, press F8 to select Advanced Startup Options, and then
    select safe mode.

    Technical Information:

    *** STOP: 0X00000050 (0XFFFFFFFE, 0X00000000, 0X86368ECA, 0X00000000)


    Beginning dump of physical memory
    Pysicla memory dump complete.
    Contact your system administrator or technical support group for further
    assistance.


    I restarted the computer again in Safemode and reinstalled the registry back up previoisly created in the registry clean up side of Spybot, and rebooted.

    This time the computer was stared in Normal mode and did not reboot it's self again.

    However, I have lost all Wireless capabilities.

    I tried to recomplete the C:\MGTools\GetLogs.bat procedure but each time it crashed and displayed the same blue death screen as detailed above.

    I checked the modified date of the MGlogs.zip and it has been modified during the procedure but I don't think it will be a complete log, although I have attached this log.

    Computer is displaying several infections picked up during the daily AVG Scan

    Over to you Sir! Thanks for your help thus far.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why? This is not something used anymore. Microsoft has even removed it from later releases of Windows. Make sure he is not confusing it with MSN Messenger or Windows Live Messenger which are not the same thing as Windows Messenger.

    Try running the below twice with a reboot inbetween the 1st and 2nd run:

    McAfee Consumer Product Removal Tool

    Make sure you run the above now!!!

    This file is a valid Window file. Perhaps you should scan it at the below online site to make sure it is not infected.

    http://www.virustotal.com/

    I did not ask you to run Spybot?

    Not related to what we were doing. Perhaps the restore changed something.

    Your MGlogs.zip file is not a valid file. Delete the one on the computer now. See if you can run C:\MGtools\GetRunKey.bat by double clicking on it. Just tell me what happens. If it runs, a notepad window should open with the runkeys.txt log in it.

    At this point, I expect that you may have to reinstall this system from scratch due to the infected Windows operating system files cause problems and there are no replacements available on the PC.
     
  9. Peteinhull

    Peteinhull Private E-2

    :)Chaslang,

    Just a quick note to thank you for your help and patience!

    I have had to do a complete reinstall, which although I didn't want to, has proved to be the only viable alternative.

    I appreciate all you guys for giving up your valuble time free of charge.

    Once again, thanks.

    Pete. :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    This was the best idea anyway since as I mentioned in msg # 6, many system files were infected and there were no clean replacements for some of them.

    You should work thru the below now:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds