Printer, and other, problems - malware related?

Discussion in 'Malware Help (A Specialist Will Reply)' started by DaveRM, Oct 11, 2012.

  1. DaveRM

    DaveRM Private First Class

    I started a thread elsewhere ( http://forums.majorgeeks.com/showthread.php?t=267375 ) - and was asked to get malware-checkout first. (That thread gives details of my problems.)

    I attach the logs asked for (FAQ's said max 4 attachments, but Upload dialog has space for 5 - hope this is OK)

    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [TASK][SUSP PATH] {C4EBEE94-6F02-40FF-ACCA-AAA13E49B5F0} : C:\Windows\System32\pcalua.exe -a C:\Users\Dave\AppData\Local\Google\Chrome\Application\17.0.963.56\Installer\setup.exe -c --uninstall --multi-install --chrome -> FOUND
      [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
      [HJ SMENU] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
      [HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
      [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$eaae87091227326dea8942cc24d73242\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-253632551-778818975-530532782-1000\$eaae87091227326dea8942cc24d73242\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$eaae87091227326dea8942cc24d73242\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-253632551-778818975-530532782-1000\$eaae87091227326dea8942cc24d73242\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach[/URL])
    Do not reboot your computer yet.

    Rescan with HitmanPro.
    Choose to Delete everything except this:
    C:\Users\Dave\Desktop\Useful progs\FotoMorphSetup.exe
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Now re-scan with both RogueKiller and Hitmanpro and attach both of those logs as well.
     
  3. DaveRM

    DaveRM Private First Class

    Thanks for quick reply - but I don't seem able to get started

    I attach a 'Problem steps Recorder' zip which shows what I did.
     

    Attached Files:

    Last edited: Oct 11, 2012
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just tell me what issues you had.
     
  5. DaveRM

    DaveRM Private First Class

    The first thing I noticed was my wife couldn't print. Her computer is in a small LAN with mine (which has the printer USB-attached) and son's (wireless connection).

    She saw my printer, but nothing arrived on my machine - nothing pending in Print Spooler.

    'Printer sharing' was OFF in Network & Sharing Center. Try to put it on, 'The specified service does not exist as an installed service'. I have uninstalled and reinstalled the printer - works fine for me, no change for her.

    Same effect on all other Sharing and Discovery items except 'Password protected sharing' - which I could, and did, turn on.

    I started a thread ( http://forums.majorgeeks.com/showthread.php?t=267375 ) - where 'lbmest' suggested maybe a malware underlying problem - get that side cleared first - hence this thread.

    Hope that helps.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I was asking was what problems you had trying to run the fix I gave you.
     
  7. DaveRM

    DaveRM Private First Class

    1) I right click on RogueKiller - click on Run as Admin
    2) Asks if I want to run- click on ''Run'
    3) RK opens, doing a Prescan, apparently. Says 'Please hit the scan button.' Nothing in the body of the report.
    4) Hit 'Scan' - Green progress bar - display as in the attachment - none of the detections you mention appear.

    Incidentally, the RogueKiller window seems stuck on one size - I can't drag the margins, to see more detail.

    The report this time is very different from the first time I ran RK - a couple of days ago now. That report did have the detections you referred to.

    Hope this helps. I think I followed your instructions properly.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach that new log.
     
  9. DaveRM

    DaveRM Private First Class

    I've re-run RK - as follows :-

    Open RK - Run as Admin

    RK opens, scanning - with 'Processes' tab selected

    When finished, says' Prescan finished - please hit the scan button'

    Hit 'Scan'

    Moves automatically to Registry button. Lists as per screengrab attached to my previous post.
    Says 'Scan finished Please look at the different tabs and delete items with the buttons'

    Also opens a Firefox page - about [Rootkit]ZeroAccess(Max++)

    -------------

    I don't see any detections in the 'active' window that correspons to your message 'Now click the *Registry tab and locate these detections' - they are there in the text-file log but not under the 'Registry' tab.

    Log as created again today attached to this posting.

    Sorry to be a pain, I do want to get to the bottom of this. Thanks for helping.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you trying to tell me that you can't remove these items:
    Code:
    ¤¤¤ Registry Entries : 15 ¤¤¤
    [TASK][PREVRUN] {BA1D74F8-524B-48A1-AC6F-DF54FDF7F31A} : C:\Windows\System32\pcalua.exe -a "C:\PROGRA~2\Free Hide Folder\UNWISE.EXE" -c C:\PROGRA~2\Free Hide Folder\INSTALL.LOG -> FOUND
    [TASK][PREVRUN] {C4EBEE94-6F02-40FF-ACCA-AAA13E49B5F0} : C:\Windows\System32\pcalua.exe -a C:\Users\Dave\AppData\Local\Google\Chrome\Application\17.0.963.56\Installer\setup.exe -c --uninstall --multi-install --chrome -> FOUND
    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJPOL] HKLM\[...]\Wow6432Node\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
    [HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    ¤¤¤ Particular Files / Folders: ¤¤¤
    [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$eaae87091227326dea8942cc24d73242\U --> FOUND
    [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-253632551-778818975-530532782-1000\$eaae87091227326dea8942cc24d73242\U --> FOUND
    [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$eaae87091227326dea8942cc24d73242\L --> FOUND
    [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-253632551-778818975-530532782-1000\$eaae87091227326dea8942cc24d73242\L --> FOUND
     
  11. DaveRM

    DaveRM Private First Class

    Yes - on grounds of uncertainty. I think I'm beginning to see what you want - there are 15 items on the RK Registry window - and you want me to checkmark some for deletion, leaving other. Sosrry it took a while for me to realise this.

    My problem now is - after the first two items listed, the next 6 all look identical to me they just list as

    HJPOL HKCU SOFTWARE\Microsoft\Win... Disabl... 0

    The next 2, similarly, are indistinguishable. The remainder show some slight variations.

    I am perhaps being a) very obtuse, and b) overcautious, but until I am confident I know exactly which ones to delete, I am loath to delete any.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just delete it all. Then attach the resultant log and then re-run RogueKiller and attach that log as well.
     
  13. DaveRM

    DaveRM Private First Class

    Thanks for coming back.

    Attached files as requested
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This virus usually screws with some of your services, so please now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. DaveRM

    DaveRM Private First Class

    MGlogs attached.

    Superficially, all seems unchanged. The computer seems to be running as before. Maybe Firefox is a tad faster loading. 'Printer sharing' in Network and sharing center still won't switch on. (I guess this is why my wife's printing doesn't appear on my machine.)

    Any other differences I notice, I'll report.

    I can't check if my wife will be able to send documents to my printer (which was the problem I was originally trying to fix) - she's away, I won't be able to get access to her computer till tomorrow evening, at the earliest.

    As a matter of interest, do you know which virus we are dealing with, please?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attached is bfe.zip
    Inside is:
    Extract bfe.reg to your desktop.
    Double-click bfe.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on.
    You can run these commands from the command prompt.
    • net start bfe
    • sc qc bfe

    If after doing the above the BFE service is still not running:

    Run regedit:
    1. Browse to the location for the BFE service in the registry (HKLM\System\CurrentControlSet\Services\BFE\Parameters\Policy), right click and select permissions. (note: HKLM is short for HKEY_LOCAL_MACHINE_
    2. In the “Permissions for Policy” window, click advanced | Add.
    3. Once the “Select Users, Computers or Group” box appears, change the “From this location:” to point to the local machine name.
    4. After changing the search location, enter “NT Service\BFE” in the “Enter the object name to select” box and click “Check names” – this will allow you to add the BFE account.
    5. Give the following privileges to the BFE account:
    Query Value
    Set Value
    Create Subkey
    Enumerate Subkeys
    Notify
    Read Control
    After adding the BFE account to the registry key, please try to start the Base Filtering Engine service.

    Go to Start / run / type in:
    services.msc

    scroll down as see if it is running. If not, set it to auto.
     
  17. DaveRM

    DaveRM Private First Class

    I've got bfe.reg on my desktop.

    I double-clicked on it - get a 'Publisher could not be verified' message - click 'Run'

    'Windows cannot open this file' message on bfe.reg.

    Given choice - 'Use web to find correct program. or 'Select a program from installed programs'.

    What should I do now?

    --------------

    Some changes to computer behaviour noted on restart this morning.

    1) A warning that Windows had blocked some programs - with a 'msconfig - Startup' dialog display.

    2) UAC is now on - I had it 'Off' before.

    3) An email from a newspaper containing a link to current articles on their website asks for Username & PW - never used to. Just click on 'X' 8 times - goes away, and links to their page on Firefox. However, this, too, demands username & pw - and then goes to 'Access denied'. Neither the email, nor web page, ever did this before.

    I checked a few other emails & web pages - they seem normal - so mebbe the newspaper has got a problem.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me jump in for a post or two while waiting for TimW to get back to you.
    Yes it was already back on in the last MGlogs.zip you posted. Turn it back off now and please leave it off.



    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  19. DaveRM

    DaveRM Private First Class

    Thanks for responding. I was beginning to get a bit worried.

    All steps run, I think correctly, with 2 provisos.

    1) I didn't notice the thing about disabling antivirus,when running Windows Repair, until I had started running it. Avg didn't seem to object - so I hope that is all OK.

    2) After I set MGtools running, I was suddenly in doubt whether I had 'Run as Administrator' - or just started it. So, I let it run, then re-ran it, checking UAC and Admin thing. The second log is attached as MGlogs - the first, (in case it makes any difference) is Glogs.

    Thanks again.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like that fixed the BFE service and the Windows Firewall. Are you having any other problems?
     
  21. DaveRM

    DaveRM Private First Class

    Confirm Firewall working - thanks

    I dunno if BFE is working - no idea how I would tell!

    Other problems :- I still can't get 'Printer Sharing' - which was what I originally noticed.

    In 'Network & Sharing Center' - if I try to set on

    Network Discovery
    File Sharing
    Printer Sharing

    There is no longer any error message - but it stays 'Off' - no matter what. I've tried 'Apply' repeatedly.

    If I try to turn on 'Public Folder Sharing' I get an error message 'Incorrect Function'

    As for 'Media Sharing' - is on - but I'm not greatly bothered about this one.

    'Password Protected Sharing' is on.

    As for anything else, there's nothing I've noticed as yet, but I've hardly done anything on the computer.

    It's the Printer Sharing I'm most concerned about - my wife needs to be able to send print jobs up to my computer - the printer is attached to my machine, it's not a 'network' printer. We're making do with email/attachment working, for the moment.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your remaining issues should be addressed in the software forum. They are not malware related.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds