Unknown Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by thulen, Nov 6, 2010.

  1. thulen

    thulen Private E-2

    Anyone,

    I really enjoy the level of competencies in this forum. I work in industry but more on the network side. I have a computer that was given to me that is having some issues. I believe it was/still is infected after certain scans that were ran.

    This machine is running Windows Vista x86 SP2. I would have loved to run SDFix but it apparently won't run on Vista.

    Therefore, I read these 2 forums:

    http://forums.majorgeeks.com/showthread.php?t=35407
    http://forums.majorgeeks.com/showthread.php?t=139681

    When I run certain programs on this machine I get some errors shown in errors.bmp.

    SAS: I see the log in the program but when I click "View Log" nothing happens.

    MBAM: Log Attached

    Combofix: Log attached...errors.bmp is when I run Combofix...blue screen 50% of the time (but it still runs)

    RootRepeal: Error is in thread (only 4 attachments)

    MGTools: attached


    RoorRepeal Error
    ----------------------------------

    ROOTREPEAL CRASH REPORT
    -------------------------
    Windows Version: Windows Vista SP2
    Exception Code: 0xc0000005
    Exception Address: 0x004cbe53
    Attempt to write to address: 0x00000000

    Any help is greatly appreciated.

    Thank you,

    T
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    One of the two antivirus you have installed must be uninstalled!!

    • avast! Free Antivirus
    • Microsoft Security Essentials

    WinPcap 3.1 <-- Uninstall this only if you did not deliberately install it yourself.
    Java(TM) 6 Update 21 <--- Uninstall outdated java.

    Please open up Malware Bytes, locate the update tab > let it update > re-scan > fix anything it finds > and attach the log it made.

    SAS's log is here: C:\Users\home\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs attach the log(s) showing what it removed.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\Vvavaa.exe
    c:\windows\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. thulen

    thulen Private E-2

    I have a little problem with some of the errors such as the one in the first post errors.bmp with MBAM update. I was able to get a full scan off with Combofix. Both of those logs are posted along with SAS' log.
     

    Attached Files:

  4. thulen

    thulen Private E-2

    I'm sorry, forgot MGTools
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, now tell me what malware problems remain, if any?
     
  6. thulen

    thulen Private E-2

    I am still getting errors when trying to uninstall programs. This is the same error I get when I try and run Combofix. The error is attached.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What programs? Java?

    Try using Your Uninstaller
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me the contents of this folder:

    c:\users\home\{41660bea-6fff-463e-a68c-502ee9da283a}

    Delete this folder:

    c:\users\Guest\AppData\Local\temp(157)
     
  9. thulen

    thulen Private E-2

    c:\users\home\{41660bea-6fff-463e-a68c-502ee9da283a}

    741U.cat
    741U.inf
    getinst32.dll
    micdrv.dll

    c:\users\Guest\AppData\Local\temp(157)

    nothing

    I am trying to uninstall Neat Works from The Neat Company. I believe whatever this infection was hijacked programs. When I try to run, install, and/or uninstall certain programs I get the errors indicated in the .bmp.

    Those programs include:

    MBAM update
    Combofix
    Neat Works

    I did try Your Uninstaller and when I try it just starts the program's uninstall program accomplishing nothing but the same error.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this, as I said:

    c:\users\Guest\AppData\Local\temp(157)

    I am not convinced that the problems you are having now are malware related, so what I would suggest is that you post in the software forum regarding it.

    Run this just to see if it picks up on anything:

    Running Kaspersky Online Scanner
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds