This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack WindowsUpdate

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Happy New Year!!! We downloaded Personal Antivirus. We downloaded and ran Malwarebytes which removed all except the 'hijackwindowsupdate in the registry data. The symptom is that information is flooding out of the computer as soon as it connects to the internet. Our service provider has a system which disconnects users if it detects 'suspicious' activity. The virus disallows the computer to disable the wireless or LAN connection. I have uninstalled the WLAN. I have gone into the registry files and tried to delete the infected files but they will not allow me to delete them. I have run ATF cleaner but still have the problem. I have been downloading these programs on another computer (the infected computer cannot use the internet or our service will interupted) and using a memory stick to transfer them to the infected computer. If you need to look at logs I will copy them to the stick and send them from the uninfected computer. Thanks for any help you can give me.
Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



This is the file Gmer.txt. Thank you for the help.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-01 14:07:39
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\fglyafog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwCreateEvent [0xEDC74595]
SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwCreateKey [0xEDC72585]
SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwOpenKey [0xEDC72645]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8c607f38.sys

AttachedDevice \FileSystem\Ntfs \Ntfs TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)

Device \Driver\Tcpip \Device\Ip 8c607f38.sys
Device \Driver\Tcpip \Device\Tcp 8c607f38.sys
Device \Driver\Tcpip \Device\Udp 8c607f38.sys
Device \Driver\Tcpip \Device\RawIp 8c607f38.sys
Device \Driver\Tcpip \Device\IPMULTICAST 8c607f38.sys

AttachedDevice \FileSystem\Fastfat \Fat TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\System32\drivers\8c607f38.sys (*** hidden *** ) [SYSTEM] 8c607f38 <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@ImagePath \SystemRoot\System32\drivers\8c607f38.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@kadfmmqr 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@F96ZK6nPB YmF0dXJhbWViZWwuY29t
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@ImagePath \SystemRoot\System32\drivers\8c607f38.sys
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@Start 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@kadfmmqr 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@F96ZK6nPB YmF0dXJhbWViZWwuY29t

—- EOF - GMER 1.0.15 —-

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
I was not able to install Windows Recovery Console as I do not have an internet connection on the infected computer. I was able to fins a way to download the recovery to a memory stick and transfer it from this computer to the infected computer.

Attachments:

Hi,

Do you have your internet connection restored now?

If not > try the following:

if your network icon appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair.

[external image: Posted Image]

If you have no task bar icon do this:

  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • click on the Repair menu option.

[external image: Posted Image]

Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.

If it is still not working, try the following:

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.


NEXT



Please do the following:

Go to Start > Run > type

services.msc

Into the run box > OK

The Services window will open.

scroll down the services names till you locate the following service:

Cryptographic Services


to the left you will see the options to
Stop the service or
Restart the service

(if it is not running the option to start the service will be there)

choose to restart the service (or start if it is not running)

Make sure it is set to start automatically.

Next scroll down to the following service:

Windows Management Instrumentation

to the left you will see the options to
stop the service
pause the service or
Restart the service

(if it is not actually running - start the service will be there)

choose to restart the service. (a couple of other services may be restarted as well - say Yes)
(or choose - start, if it is not running)
make sure it is set to Automatic.

Close the services window.

NEXT

Please run ComboFix once more, make sure all your security programs are totally disabled.

If ComboFix requests to update and install the Recovery Console - ALLOW it.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi, attached is the scan run by malwarebytes. I can hook up to the internet, but the virus causes excessive activity and our service provider automaticaaly suspends service. The virus will not allow me to disable the WLAN so I uninstalled it. I can plug in the LAN, but the activity immediately becomes excessive and the virus will not let me disable it. I have to unplug the DSL line to stop it.
The log says the two registry files have been removed successfully, but when I run MBAM again they keep showing up (in red). I will hook up to the internet to test, but the two files have just been detected again when I run MBAM.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI