Problem from malware - corrupted? svchost.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Brightstar, Aug 11, 2011.

  1. Brightstar

    Brightstar Private E-2

    Hi there. I've had this problem on my wife's laptop for a while and I've worked on it a bit and then shelved it for a while but have recently gotten back to it.

    The laptop seems to have been infected and then as far as I have been able to determine a possible windows update corrupted files.

    When the computer is started the following error pops up preventing windows XP from loading up. Basically no access is granted and currently the computer files and programs can only be accessed in SAFE mode.

    The following information is displayed in the window basically:

    There is an error in svchost.exe, the instruction 0x7c833425, the reference memory at 0x0020f5a4 not placed into memory because of I/O error status of 0xc00009a.

    The 2 options are to cancel, etc. don't provide any further access and all that can be done is to select an option from the dropbox -- restart being the only viable option.

    In reviewing the protocols here I've run what I could. (See attached logs).

    I've attempted to run ComboFix several time however I was never able to make it past the "scanning" stage. (Eventually the clock would stop - I left it running many hours several times after clock stopped in case processes were running that interfered with the clock, but no go.)

    The scans came up clean, but from earlier scans that I did:

    In evaluating the problem it appears I may need to reverse windows update files and have the re-downloaded, however since I can only access SAFE mode I am unable to do this. Any help would be appreciated.

    Thanks.
     

    Attached Files:

    Last edited by a moderator: Aug 11, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I understand you ran into difficulties with Combofix however, you did not mention MGTools. I at least need to see the logs from running that, please. (C:\MGlogs.zip)
     
  3. Brightstar

    Brightstar Private E-2

    You are correct. I apologize. See attachment.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. Brightstar

    Brightstar Private E-2

    Scans run - see attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware. Are you able to do this scan in safe mode with networking?


    Run this and attach the results.

    Using ESET's Online Scanner
     
  7. Brightstar

    Brightstar Private E-2

    You can see a few things were picked up (not including MGtools).

    I think my problem was/is two-fold: an infection and an svchost.exe error, which may or may not be related. Most of the infection has been removed, and the svchost.exe error is similar to the following:

    http://www.pchell.com/support/svchosterror.shtml

    however, since I am unable to boot up windows normally, I cannot use the described fix (since I can't run windows update in safe mode with networking).

    My initial hope was that an infection that may have been involved in the problem would help restore the svchost.exe error, but I'm beginning to suspect that once the system is clean I may have to employ a separate fix for the svchost.exe issue.
     

    Attached Files:

    Last edited: Aug 12, 2011
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you're right. It's become a non malware problem now. You can go ahead and post in the software forum if you like. :) Best of luck.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. Brightstar

    Brightstar Private E-2

    Thanks for your help.

    I was able to restart my computer and windows booted up normally - finally! I am having a problem with Windows Update but I'll post a message in the Software forum for that.

    Thanks again for helping bring this part of the problem to a close. It had been frustrating me for a long time.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds