Vista 32-bit: Probable Malware, possible registry shenanigans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Foxfax, Jun 21, 2012.

  1. Foxfax

    Foxfax Private E-2

    I am currently unable to update anything. I caught a rather evil virus about a month ago that Avast managed to catch and nuke but since then, my computer has been slowly getting worse, so I think the beggar survived. :(

    Currently nothing will accept updates, usually because they think I'm not connected to the internet. I can't connect to microsoft.com on IE either. Firefox connects fine, but won't update. World of Tanks won't update even when I manually download the client patch. No new French Tank Destroyers for me :cry

    Nothing updates, unless that thing is a Steam game. Steam itself won't update, but the games can. :confused

    Windows Update gets error 8024402C, which I've followed steps on how to fix to no avail.
    I followed the instructions for MG tools and attached the file.
    I followed the instructions for MBAM, but it couldn't update with the error PROGRAM_ERROR_UPDATING (0, 0, DNS error) and the scan didn't create a log in the program.

    HitmanPro could not connect to the internet and did no scanning. Log attached.

    When I try to run MGTools, a popup appears repeatedly:
    "16-bit MS-DOS Subsystem
    C:\Windows\system32\cmd.exe
    SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers.
    Virtual Device Driver format in the registry is invalid. Choose 'Close' to terminate the application."
    However, there's no Vista workaround in the thread. Trying the Windows XP workaround didn't work as there's no VirtualDeviceDrivers in my HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control registry.

    Clicking 'Close' lets the program continue, but the following message appears in the Command window: "The process cannot access the file because it is being used by another process."

    MGTools then hung up on the processdll.exe part of its scans. Log attached.

    Help is rather required for this poor noob, methinks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well as you say MGTools did not quite run correctly, so let's get a deeper look.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    ----------------------------------------------------------------

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. Foxfax

    Foxfax Private E-2

    Thanks for the help!
    I'm currently DLing the tools, will append once everything runs.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK! I'll be here to review the logs as soon as you have them.
     
  5. Foxfax

    Foxfax Private E-2

    Finally! Sorry, computer began hanging, then I had to DM DnD 3.5 until 4.20am, when the players finally decided that the dungeon wasn't clearable in one session. rolleyes

    Files attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    [2011/05/15 13:13:13 | 000,000,152 | ---- | C] () -- C:\ProgramData\~41017080r
    [2011/05/15 13:13:13 | 000,000,136 | ---- | C] () -- C:\ProgramData\~41017080
    [2010/06/21 17:58:41 | 000,000,691 | ---- | C] () -- C:\Users\Alan Fox\AppData\Roaming\GetValue.vbs
    [2010/06/21 17:58:41 | 000,000,035 | ---- | C] () -- C:\Users\Alan Fox\AppData\Roaming\SetValue.bat
    [2010/04/20 00:01:57 | 000,013,196 | -HS- | C] () -- C:\Users\Alan Fox\AppData\Local\x3Cg6jfw84
    [2010/04/20 00:01:57 | 000,013,196 | -HS- | C] () -- C:\ProgramData\x3Cg6jfw84
    
    :files
    C:\Users\ALANFO~1\AppData\Local\Temp\oflpydin.sys
      
    :Services
    oflpydin
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.



    Now run OTL again the way you did before in post # 2 and attach the log.

    How are things running?
     
  7. Foxfax

    Foxfax Private E-2

    Updating is still disabled, Steam still has Error:- 137 and won't update.

    Avast can update automatically, but not manually. It always fails on the first attempt (Unable to connect to server), then tells me I'm up-to-date.
     
  8. Foxfax

    Foxfax Private E-2

    Huh? My last reply, didn't. I think.

    Here's the logs.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm afraid I am not seeing any malware now, are you still unable to connect to certain websites?
     
  10. Foxfax

    Foxfax Private E-2

    Unfortunately, yes.

    Still not able to update anything.
     
  11. Foxfax

    Foxfax Private E-2

    Currently trying a clean boot to see if that'll help me spot the problem.
     
  12. Foxfax

    Foxfax Private E-2

    Problem occurs even clean-booted. *sigh*
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try posting about it in the software forum. Sorry I cannot assist you further but I do not believe it to be malware related.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. Foxfax

    Foxfax Private E-2

    In that case, I'll do as you advise, see if someone there can sort it, because I'm stumped. Thank you very much for your help until now! ;)
     
  15. Foxfax

    Foxfax Private E-2

    Just a second. Sorry to continually bug you, but I ran RootRepeal on a whim in Safe Mode and found some Chinese character drivers I have never seen in my life.

    Could this be my problem? Log attached.

    EDIT: I'm also finding a "PQSERVICE" drive on my System Properties for some reason.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Relates to a hidden partition for recovering your computer. Leave it alone. As for what Rootrepeal is picking up on, we will have to dig a little deeper and I may have to ask a colleague.



    Scan With RKUnHooker

    • Please Download Rootkit Unhooker Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • * This can take a while. Please be patient *.
    • Save the report somewhere where you can find it. Click Close.
    • Copy the entire contents of this log in you're next reply.
    • This log can be lengthy you may have to post it in separate replies.
    • Note: You may get the following warning - it is ok - just ignore it:
    • "Rootkit Unhooker has detected a parasite inside itself!
      [*] It is recommended to remove parasite, okay?"
     
  17. Foxfax

    Foxfax Private E-2

    Comes up with an error box.

    "Error

    Error Loading Driver, NTSTATUS code: C0000001"
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We would like for you to run TDSSKIller.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.


    Also I would like for you to run HitManPro in EWS mode (Refer to instructions) and attach the log from doing so.

    As for your internet connection we may have to uninstall and reinstall your network card driver from Device Manager.
     
  19. Foxfax

    Foxfax Private E-2

    Logs attached, hopefully telling you what you require.

    The forum won't let me upload my Hitman logs as they're apparently already uploaded. :confused
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not attach the TDSSKiller log.
     
  21. Foxfax

    Foxfax Private E-2

    Sorry about that, currently operating on less-than-optimum amounts of sleep. :-o

    Here you are.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are not seeing any malware. Did you try this as suggested?

     
  23. Foxfax

    Foxfax Private E-2

    Yes, just came back from doing this when I remembered something I did before: winsockfix.

    I might have fixed this. Hopefully. Fingers crossed. I manually winsock fixed using the command line, which seem (fingers very, very firmly crossed) to have let me fix my updating problem.

    Seems like it might have been corrupted during the virus attack. Maybe. I have little proper coding experience, so I have no real idea. But that seems to me to be likely, so I'll stick with that until better minds come up with the real answer.

    Currently updating windows update, which I need to be able to update. rolleyes

    I'll update you if this has actually worked. Or if it hasn't. Hopefully the former.
     
  24. Foxfax

    Foxfax Private E-2

    That seems to have done it. :celebrate :highfive

    If you think that my computer is (for now) malware free, I'll follow your "What to do last" tips below.

    Thank you very much for your help.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi FoxFax. :) Glad you're all sorted now. Yes, go back to post # 13 and follow final steps. safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds