Svchost errors, grey taskbar, no internet.

Discussion in 'Malware Help (A Specialist Will Reply)' started by EvilNinja, Apr 1, 2011.

  1. EvilNinja

    EvilNinja Private E-2

    Hi, could someone take a look at my logs, my computer has effectively died overnight, been trying to sort it out for 5 days now.

    Main problem is that svchost.exe errors at login attempting to read/write address 001a624b, the system takes 15 minutes to boot, the taskbar has gone from blue to grey (win classic), svchost keeps popping up at 99% cpu and my internet has gone haywire, it did connect and transfer something to somewhere but not to my router, but has since stopped working completely.

    Everything ran except for combofix, this produced a blue loading bar and then went off, it did create a temp (numbered) folder in c:
    I ran the superantispyware with scan >4mb on the last run.

    Drives E: and F: are partitions on a 10 year old harddrive, recently plugged in, most things on that were supposed to have been removed by AVG, the system restore DLL look worrying and the C:\AMIGA\CTP\TOOLS\BGLXML.EXE is the most recent added piece of software.
    Don't know what is being reported correctly, can/have remove(d) everything reported.

    Attached logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It does not look like you are having malware problems. Many of the old files/programs that you have are just falsely being detected as problems since they are unknown. I assume you meant the Amiga stufff is something you know about.


    You may just be having problems with windows itself, however let's run a couple more scans just to be safe.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now run this Using ESET's Online Scanner and attach the log from ESET.
     
  3. EvilNinja

    EvilNinja Private E-2

    Awesome - I LOVE YOU :drool

    After reboot, system now boots in it's usual 15 seconds, and have been able to apply the xp theme again (wasn't listed before).

    Haven't got my internet back on yet to try the online scan, is it now safe to do this? or is there something else I need to do before I mess things up again?

    Full log attached as well.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent.

    Skip the ESET scan and see if you can run ComboFix and attach that log.
     
  5. EvilNinja

    EvilNinja Private E-2

    Ok, managed to run the ESET online scan and combofix, attached logs.

    Everything seems ok now. except for my internal USB Hub, but that's my fault.
    Going to run the malwarebytes again overnight see if anything else gets picked up, will let you know if the system is clean tomorrow.

    Anything I need to do except uninstall combofix?
    Can you recommend a better free scanner that's beter than AVG?
    (if AVG missed these then it can't be very good)

    Thank you for spending the time to help me, it is very much appreciated, I will come back and buy a mug when I can afford one.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We need to restore the hwinterface.sys file and registry entries that ComboFix deleted as these are for your parallel port. I need a new MGtools log before we can do this, so please do the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  7. EvilNinja

    EvilNinja Private E-2

    Ok, logs attached, have got the win xp pro installation disk if that helps.

    Did notice that when I was trying to repair this by myself that killing jqs made the PC run without problems, it was that that was making the svchost keep going to 99%.
    Also remember that firefox ran a java applet from a site just before my system went down, it was quite an ordinary site which is why I remembered it as I don't expect normal sites to run java applets.
    Have stopped firefox from running java now, going to stop jqs running at startup when everything is ok.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay some info that is normally saved into the MGlogs.zip file is not getting put there for some reason. So I will need you to provided me with some info. Please get copies of the below two files and put them into a ZIP file and attach this ZIP file to your next message.


    C:\Qoobox\Quarantine\Registry_backups\Legacy_hwinterface.reg.dat
    C:\Qoobox\Quarantine\Registry_backups\Service_hwinterface.reg.dat
     
  9. EvilNinja

    EvilNinja Private E-2

    Ah, sorry, my fault, posted the wrong zip.
    Attached the correct zip with those files already in it.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So what was it that you were attaching? Were you creating your own file instead of attach what was requested?????


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. You may get a message indicating that not all of the items could be added to the registry.



    Now we need to use ComboFix to DeQuarantine a file that it should not have removed.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named C:\DeQuarantine_log.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\DeQuarantine_log.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. EvilNinja

    EvilNinja Private E-2

    Yep, posted the logs I had saved from mgtools directory, sorry, my desktop if full of logs and zips of logs.

    Second part of the regfix didn't work, no key in registry for [HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_hwinterface]
    The error was :- 'error accessing the registry'

    Didn't run the ComboFix yet, don't know enough about the registry to know if it would have been a problem.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions told you not to look in the MGtools folder. ;) C:\MGlogs.zip is automatically made and that is the log to attach.

    Yes that is what I was hinting at.

    Just continue.
     
  13. EvilNinja

    EvilNinja Private E-2

    Sorry for delay, real life issues.
    Uninstalled avg, dropped the CFscript onto combofix, it ran and deleted the combofix.exe icon on the desktop all by itself.

    The C:\DeQuarantine_log.txt does not exist.
    I checked the system32/drivers folder and hwinterface.sys isn't there.
    I also checked the C:\Qoobox\Quarantine folder, the hwinterface.sys.vir isn't there either.
    Ran TDSkiller, no hwinterface.sys.

    Only thing i've got is a catchme log in the C:\Qoobox\Quarantine folder with time and date ---- 2011-04-18 - 00:55:11 ------

    Guess i've gone and royally messed things up then.
    Any way to re-add the drivers through add hardware?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file ComboFix removed is in the below folder and was renamed to have .vir extension appended:

    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\hwinterface.sys.vir


    You can simply copy this file back to the C:\WINDOWS\system32\drivers folder and just remove the appended .vir extension after copying it.
     
  15. EvilNinja

    EvilNinja Private E-2

    No hwinterface.sys anywhere on c drive, with or without the .vir extension.
    Told you I messed it up :)
    System works fine except for firefox crashing on some java pages because I disabled java.
    So, i'm just going to not fix the parallel port until I need to use it, then i'll install Inpout32.dll.

    Thanks for all the help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not sure how it disappeared! But maybe when you tried to run the DeQuarantine, it sounded like ComboFix uninstalled itself because you say ComboFix.exe disappeared.


    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
     
  17. EvilNinja

    EvilNinja Private E-2

    Logs attached.

    BTW, i got a pagefile.sys that is 1.5Gb in size, wasn't there before I ran one of the programs, that file ok to delete?
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    Yes it was there before. It is part of Windows and required. You cannot delete it. You may have never noticed it because you had system files hidden in the past.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds