TechSpot

[Active] Virus removal disables Windows from starting up

Inactive
By Pink
Aug 8, 2010
Topic Status:
Not open for further replies.
  1. Hi,
    recently i`ve been having some malware/virus problems.
    i run Malwarebytes anti malware program, and it finds various stuff.
    when i choose to erase it, it says that i need to reboot, which i do. but on the startup, windows won't boot. it gives me a bsod (which i can't read because it's really fast) and keep booting over and over (will boot in safe mode though, and when i run mbam from safe mode, it won't find nything) so i did like 3 repair installations over the previous week.

    here's my hijackthis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:17:46 PM, on 8/8/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\PixArt\PAC7302\Monitor.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\MagicTune Premium\GammaTray.exe
    C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\TEMP\Ksq.exe
    C:\WINDOWS\TEMP\Ksp.exe
    E:\Programs\Native Instruments\Traktor DJ Studio 3\Traktor\Traktor.exe
    E:\DO NOT ERASE!!! stuff after format\hijackthis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {99545358-1336-43DF-91D3-58E27EDCE65C} - c:\windows\system32\eltxhug.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [ZE18MW23GY] C:\WINDOWS\TEMP\Ksq.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: GammaTray.lnk = C:\Program Files\MagicTune Premium\GammaTray.exe
    O4 - Global Startup: NCProTray.lnk = C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

    --
    End of file - 5254 bytes


    and that's it, i hope you guys can help me!!!

    Thanks!
  2. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    BTW, mbam log:

    Malwarebytes' Anti-Malware 1.43
    Database version: 3458
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    8/8/2010 6:33:53 PM
    mbam-log-2010-08-08 (18-33-50).txt

    Scan type: Quick Scan
    Objects scanned: 156695
    Time elapsed: 6 minute(s), 14 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.


    P.S
    my computer works fine. games run smoothly, programs too, everything runs ok. but i'm afraid that this virus or whatever is gonna corrupt my hd.
  3. Broni

    Broni Malware Annihilator Posts: 46,787   +254

  4. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    Hi uhhh,
    i can't complete all of those steps because it will erase the malware and disable windows from starting up... so i can't really do any cleanup..
  5. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    Leave MBAM alone and give me other logs.
    Those are just scanners. They don't make any changes (DDS, GMER).
  6. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    So i`m attaching the GMER log, but whenever i open DDS, it opens it in notepad..

    Attached Files:

  7. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    Ok so now internet is running really slow, and mbam and avg antivirus are really slow while scanning too.
    i`ve managed to erase all of the threats found by mbam and AVG (i had to install it as it's the only antivirus i had!) and windows started up cool. but now the avg resident shield is giving me warnings every 15 seconds about a eltxhug.dll being a trojan horse agent2.AXSU (i can find it on hijackthis, but i think that this is the file that if it's removed, will prevent windows from booting)

    So, can you guys help?
    Thanks
  8. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    As our instructions say, do not perform ANY other steps, than asked for.
    Thanks :)

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.

    =======================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
  9. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    Ok so i ran both programs.
    MBRCheck saved a log, but combofix did a scan and removal, so guess what happened... i had to do a repair installation again, and it didn't save a log.
    but it looks like combofix removed the rootkits i had, so i think it's gonna be cool now.

    Thanks
  10. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    Nothing will be cool, until we finish all cleaning steps.
    It may look cool, but i assure you, it's not.

    Please, post required logs.
    If something unexpected happens, do NOT try any fixes by yourself, but let me know.
  11. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    ok cool so here's what happened.
    i ran combofix again because last time it didn't save any logs. and MBRCheck too.
    so i'm attaching the MBR, and Combofix logs!

    Thanks a lot! (and yeah, my pc is working slower than usual...)

    Attached Files:

     
  12. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    MBRCheck looks good, but we have some nasties in Combofix.
    Before we go there, I want you to run one more scan.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
  13. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    Ok, done TDSSkiller scan, but it found nothing and was really fast!
    attaching the log

    Attached Files:

  14. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    OK. I have a reason to believe, we're dealing here with not legit Windows copy.
    I can see this:
    - c:\windows\system32\antiwpa.dll
    antiwpa.dll is an illegal software crack used to bypass copy protection for Windows

    Comments?

    It's my bed time, so I'll check on you tomorrow.
  15. Pink

    Pink TS Enthusiast Topic Starter Posts: 127

    Hmm i had my windows installed by a computer tech, so i really dont know.
    but my pc was fine for a long time, and if that's a crack to bypass windows copy protection, it must've been on my pc for ages, so i don't think that's the culprit.
    is that the only suspicious file?
  16. Broni

    Broni Malware Annihilator Posts: 46,787   +254

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\ygxyoc.dll
    
    Driver::
    fspmum
    hbxlwzft
    ziuqqmq
    
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hqtipoor]
    [-HKEY_LOCAL_MACHINE\System\ControlSet005\Services\fspmum]
    [-HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hbxlwzft]
    [HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ziuqqmq]
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.