Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

A Difficult Infection to Remove - Request Help [Solved]


  • This topic is locked This topic is locked

#31
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
There is a new version of combofix which I would like you to run from normal mode in your normal login. It is imperitive that it is run from there

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

Advertisements


#32
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I tried to run ComboFix in NORMAL mode and it would just not execute giving an error saying Windows was not able to find the path/drive (etc. .. to that effect) and also that I may not have access. When I tried to open paintbrush to PrintScreen the error message, it would not open PaintBrush and gave me an error about access rights (or was it about a missing rundll32.exe .. which will get clearer as you read along this post)

When I tried to run any other exec in NORMAL mode I got the same message. Next, I tried to go to Control Panel and try "Add Remove Programs" or some of the other options. Like earlier I got a message about the missing rundll32.exe file under Windows/System32.

Next, I tried to find rundll32.exe but could not find it manually either.

I have a twin laptop of the one that is having problems. Both re-formatted at the same time with the same OS options etc. I manually copied the rundll32.exe file from the other one to the one that we are trying to repair. After that all those errors were gone. I had feeling that IE8 may be causing some error and so deleted it from the system using Add/remove Progams which is working now.

I again re-booted in NORMAL mode and tried to run COMBOFIX. This time it ran beautifully except that initially it gave an error in the blue log screen that it throws up saying : "CScript Error : Loadfing your settings failed. Access Denied."

However otherwise it ran its course and then automatically re-booted the system. When the system came back, I looked in C:/ for the ComboFix.txt file. I was again surprised to find that like one of the earlier times which I have detailed in an earlier post, the ComboFix.txt file was not found. However there was a ComboFix entry listed as "File" but showing with an icon of an application. When I tried to open it nothing happened.

I ran a search in Windows for "ComboFix" on the C: drive and the results went into a loop and kept throwing the same 2-3 listings which included the shortcut file for ComboFix, the application itself and the same "Folder" which showed under C:\. If I did not abort it, on last count it had been throwing the same results at least 6-7 times and kept adding the same entries repeatedly.

So, while I ran ComboFix in NORMAL mode, I am not able to post a log. I remember this has happened earlier and then it had later got fixed after some of the steps you mentioned in the earlier post and then I had posted a screen-grab of the cleaned systems C:\.

Thanks for patiently reading and continuing to help to unravel this strange chain of events.
  • 0

#33
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No problem, trying to solve kysteries like this help to hone my skills

OK I will redo the AVZ scan and steps to see if we can get you back to being stable. I have some new instructions I hope you like them as one of the students made it for me :)

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: Posted Image
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Analysis" check box.
    Posted Image
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Analysis" check box.
    Posted Image
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post

  • 0

#34
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Files attached.

Thanks to your student for clear instructions which are very helpful.

Now with IE un-installed, I am really working fine using Mozilla. Only notice-able issues are that :

(1) I am not able to download any files (even the AVZ file had to be downloaded on a second PC and copied through a USB stick). When I tried AVZ, I got the error message

"This download has been blocked by your Security Zone Policy - kaspersky-lab.com".

Looking through some help, it looked to be related to Security Settings on the OS/Browser but some of the advised steps did not work.




(2) I am still not able to install any anti-virus solution. After all this I un-installed Avira and tried to install AVG (Grisoft) again (for records it was before running AVZ), but I got an error in the last step mentioning :

Local Machine Installation Failed
Installation: Error : Action failed for Registry key HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows: creating registry key Error0x80070005



Thanks

PS: I just realized that I did not run the update before using AVZ. Apologies!!! I will run it again now after running and update and post the logs. I will let these logs attached here continue, but I will get back shortly with new logs after running the update step. I hope it does not impact the system

Attached Files


  • 0

#35
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Please read my previous post - I forgot to do the update on AVZ before running the two scripts advised and so did the same this time and am attaching the two logs asked.

Other two issues that I noticed and listed in my previous post are still relevant.

Thanks

Attached Files


  • 0

#36
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
HI the first thing I would like you to do is uninstall Prevx as that is using a lot of processes and may well be blocking downloads. Having done that

AVZ FIX

  • Double click on AVZ.exe
  • Click File > Custom scripts
  • Copy & paste the contents of the following codebox in the box in the program (start with begin and end with end )
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     BC_DeleteFile('E:\RECYCLER\autorun.exe');
     DeleteFile('E:\RECYCLER\autorun.exe');
    BC_ImportDeletedList;
    ExecuteRepair(2);
    ExecuteRepair(14);
    ExecuteRepair(15);
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
  • Note: When you run the script, your PC will be restarted
  • Click Run
  • Restart your PC if it doesn't do it automatically.

ON COMPLETION

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Analysis" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach the zip file to your next post

THEN

Please download Dr.Web CureIt . Save it to your desktop:
  • Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in the pop-up window to allow the scan.
  • This will scan the files currently running in memory and if something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, select Complete scan.
  • Click the green arrow Posted Image at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click File and choose Save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report may need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Please post the Dr.Web.txt report in your next reply
  • Close Dr.Web Cureit.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.

NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on the X in the upper right corner.
  • 0

#37
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I have uninstalled Prevx.

I am attaching the AVZ log file asked after running the script as instructed. The laptop had re-started on its own at the end of the first process.

I was again not able to download the Dr.Web .exe on the laptop of interest and had to download it on another laptop and then transfer it through a USB stick.

Dr. Web utility executed and finally showed in the status bar that no infection was found but it did not throw any .csv report. Under File->Save Report List, the option "Save Report List" was greyed out and so there is no report to upload for it. However I am attaching the screenshot of the Dr. Web utility after it executed and you can see that it says no virus found.

Current "issues" continue to be the inability to download any files as I still get the error

"This download has been blocked by your Security Zone Policy"


and the inability to install AVG (and I think any other anti virus solution). I still get the same error:

Local Machine Installation Failed
Installation: Error : Action failed for Registry key HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows: creating registry key Error0x80070005


Thanks

Thanks

Attached Thumbnails

  • DrWebScreenAug7th.GIF

Attached Files


Edited by Michelle1123, 07 August 2009 - 08:01 AM.

  • 0

#38
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Lets try to reset the permissions first

Download Dialafix to your desktop. Unzip all the files. Then run dialafix :

Once it is running do the following:
Run the Tools button at the bottom ( the hammer ) .. scroll down to and highlight Repair Permissions and then click the Go button... be patient while it resets the permissions back to the factory defaults.


Then retry the installation of AVG
  • 0

#39
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Just as I was about to write a note saying things look much better since the last weekend when I started seeking help, something has struck and it is now worse than it ever was!

Here is the sequence of events:

I donwloaded Dialafix and ran it as you advised. It took much shorter time than I anticipated and finished the permission task. I re-booted and attempted to install AVG again. It again failed though I got some other error this time.

I then wanted to check if the issue was with AVG or any anti-virus software. So, I tried to install Avira this time. It worked! It got installed and after a re-boot it looked to be all set. It came up beautifully on boot and if I remember right, it even did a system scan once.

Now since the download has not been happening due to the "Security Zone" error message, I have been using a USB stick back and forth from another laptop to transfer files. I have been trying to be very careful and have kept scanning this USB stick with MAMB, AVG and Dr. Web.

However when I put the USB stick the next time on the laptop of interest which now had Avira running, it threw up some dialog boxes about a Trojan threat and I chose the default option which was DENY ACCESS. ( I recollect that the USB stick was plugged but am not absolutely sure if the error was with the system after a re-boot coinciding with the USB being plugged) It threw couple of other options which came very fast and were probably related to it. The next thing I knew --- the screen went blank with the blue background colour ( not the death-screen blue). I waited for a while but nothing changed. I hard re-booted with the power switch and again it started with the Windows screen and the welcome screen after which the blank blue screen remained. I tried re-booting in SAFE mode : after the user login choice, the screen goes black and blank except for "SAFE MODE" on the four corners of the screen and the OS/hardware details on the top as it always comes.

I tried to re-boot several times in NORMAL or SAFE mode but there was no difference.

Once after a couple of hours in NORMAL mode the same error message was thrown though this time the USB stick was not plugged in. I took a quick picture of the message on my camera phone before it disappeared but that picture did not come very clear.

Later tinkering around I found that I could get into the command prompt mode while booting using F8 though I could still not get into SAFE mode. Navigating directories, I launched Dr Web from the command prompt, and it ran well and returned without an detection on Express Scan. Next I launched Avira from the same mode and found find the references to the following which co-incide with the recollections I had of the last detection when it last booted in NORMAL mode.


It mentioned the following:

- TR/Crypt.CFI.Gen Trojan (source visicon.exe)
- TR/CryptXPACK.Gen Trojan (source pj11icon.exe)
- TR/CryptXPACK Gen Trojan (source misc.exe)


It also had references to four instances of containing " HEUR/Malware suspicious code of which three were in C:\WINDOWS\Explorer.EXE and one in GSimReaderApp.exe which is probably an application I have loaded long time back to take backup of SIMs.


I am attaching a picture of one of the last AVIRA messages I got when it booted last in NORMAL mode to show how it looked. I message relates to some Trojan and I can see that it refers to something probably in C:\Windows\Installer\....something.

So, that's where it is. The laptop is now not even booting though I was able to install Avira. The hope : I have command prompt access!



Update : I have launched AVIRA scan and it is still running with over 1375 detections though a few hundred were from one of the old AVZ4 folders from the quarantine or some similar location. Will update the results once the scan is over.

Attached Thumbnails

  • Image021.jpg

Edited by Michelle1123, 08 August 2009 - 06:59 AM.

  • 0

#40
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Sounds to me as though Avira has deleted something it should not have

As you can start with the command prompt ? lets do a restore

- type cd \ then enter
- then cd "system volume information"\_resto~1 then enter
- type dir then enter

when you hit Enter> it will list all the restore points folders
like rp1,rp2........ we have to see the last restore point to copy
the file from a recent backup. if the restore points have more than
one page then you have keep on hitting the Enter> key to view the
last restore point folder. You will have to choose the second to the
last option, if it has more than 2 RP's.

- type cd rp* {where * is the second to the last restore point no. } (Note :
Example : cd rp8, if rp8 is the second to the last restore point,
where last restore point no.=9 )

- then type cd snaphot

Now the command Prompt will look like this c:\system~1\_resto~1\rp9\snapshot>

- type: copy _registry_machine_system c:\windows\system32\config\system
press enter
- type: copy _registry_machine_softwarec:\windows\system32\config\software
press enter
- then type exit

Then try a reboot
  • 0

Advertisements


#41
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Good to know that all is not lost :-)

So, before I read your post, Avira ran its course, found 1800 odd issues and was able to auto-heal it. It however still did not help to boot normally.

Now to the restore attempt:

I was able to do the following:

- type cd \ then enter
- then cd "system volume information"\_resto~1 then enter
- type dir then enter


Now at this point I do not see lines of restore points but just one. I see five entries in all when I type the last dir. Four are files and one directory. These are:

drivetable.txt
fifo.log
RP13 <<< which is listed as a directory>>>
_driver.cfg
_fileslst.cfg



On doing cd RP13, I find 3 directories and two files. The directories include one called snapshot and the two files are RestorePointSize and rp.log

My question before proceeding : can I still go ahead with the steps of getting into the snapshot folder given that this is the only RP folder I see?

Thanks

Edited by Michelle1123, 08 August 2009 - 08:08 AM.

  • 0

#42
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
As that is the only one then we will give it a whirl

So it should be like this

Now the command Prompt will look like this c:\system~1\_resto~1\rp13\snapshot>

- type: copy _registry_machine_system c:\windows\system32\config\system
press enter
- type: copy _registry_machine_softwarec:\windows\system32\config\software
press enter
- then type exit
Then try a reboot
  • 0

#43
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
On typing the "copy_registry_..." command under snapshot directory, it returned the following ERROR message:


'copy _registry_machine_system' is not recognized as an internal or external command, operable program or batch file.
  • 0

#44
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Do you have a windows cd ? If so we will try a repair

Does windows give any sort of error dialogue when you try to boot i.e. does it reference a missing file or something ?
  • 0

#45
Michelle1123

Michelle1123

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Unfortunately these are old laptops and I do not have the CDs with me here.

It does not give any error message when it fails to boot. Just goes blank with the blue background that comes when logging in.

Anything we can do with the Microsoft Recovery Console that CombiFix installed last time?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP