Showing posts with label Vista. Show all posts
Showing posts with label Vista. Show all posts

2014-09-14

Malware or Broken Windows Vista Install? Symptoms and Chronology

Case Study a Possible Virus / Windows Vista Failure

I have been retained to remove a Windows virus. Here are some notes to assist others.

A Windows Vista computer with all patches applied regularly exhibits these symptoms while booted fully:

  • Browser connections time out 
  • Nothing can be installed as the shell has been taken over (.EXE launches produce an error message) 
  • AVI 2004 had been disabled but was re-enabled and is "working" 
  • The network is working: local and WAN pings succeed
  • Email traffic is normal 
What's been tried so far: 
  • Restore failed. This could be a Windows issue particular to this machine, or possibly one caused by the malware. Detailed logs were not examined as the problem predated the infection.
  • Booting into Safe mode allowed for AVG 2014 to be re-enabled, both while in Safe Mode and upon return to normal mode 
  • Malwarebytes found no errors in Safe Mode, but did hang after scanning about 28,000 objects 
  • Hitmanpro ran to completion with Malwarebytes disabled and did not find any errors.
  • The shell open registry keys were checked, and they are OK (recall that EXE's can be run in safe mode)
The symptoms are evident during full Windows mode, not safe mode. 

Strategy

I used some of the tactics used by William Rowland (Jan 2013), though the Safe mode block reported there is not one of the symptoms for this attack.

Result 

None of the safe mode tools proposed by W.R. turned up anything definitive. There were additional suggested tests that might have been fruitful, but as mentioned, running on "unsafe" mode was not possible -- especially Windows repair solutions -- none of which could be run in the operable safe mode.

A time-consuming Windows reinstallation was the only alternative.

2009-07-11

Vista: Best Startup Technique for S/W Needing Admin Rights

An audio driver and ftp server are two applications that are in my Vista Ultimate startup group. Both require admin authorization to start up. Nothing serious, but a nuisance, as they appear as "blocked" programs and must be manually launched.

Microsoft's Help suggests using Windows Defender to block the startup applications from running. This probably works fine, but didn't sit well, essentially "leave it broken."

Several solutions are possible. The one settled on, described in a forum post, utilizes the task scheduler to launch these applications instead of the startup folder. The task scheduler allows for setting the "run as admin" feature ahead of time. (The Vista task scheduler has a well-thought out UI and may be useful for you for other purposes).

But one of the tasks stubbornly refused to be removed from Startup. Unclear why, but by using the Sysinternals Autoruns utility, which has other benefits as well, the audio driver item could be cleared from the startup registry --without a tedious browse of the registry. (If you're on XP, try Mike Lin's utility).

2008-08-10

MS05-051 "broke" Vista: HRESULT was 8007043c eventsystemobj.cpp

I pride myself on keeping my most critical Vista box well patched and happy (from a Microsoft point of view). I plan to use Vista for many years -- I even bought the "retail" version.

Imagine my surprise when I noticed that it was no longer accepting peer to peer network connections. "Hmm, I guess I'll try rebooting," I frowned. But Mr. Ultimate Vista refused to start up. It displayed the Vista logo, then, without any message or notice, rebooted itself again. This would have gone on indefinitely if I had not intervened.

I booted into safe mode, (luckily that worked!) looked at the System log (not a minor accomplishment, since some of the other log flavors were not viewable due to "could not connect" errors). The error that got my attention was "The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043c from line 45 of d:\rtm\com\complus\src\events\tier1\eventsystemobj.cpp." And a probably related message, "System log:The following boot-start or system-start driver(s) failed to load: ACPIaswSPspldrWanarpv6." Deeper frown.

I looked at the Reliability Monitor, and it showed nothing unusual for the past couple of months.

A TechNet forum post suggested a closer look at the Microsoft KB entry that is the title of this post. In short, the problem is with permissions policies -- apparently some critical Windows applications were locked out from the Registration directory.

This is an understandable "bug." What is less understandable is how this problem escaped the automated test tool sniffers one imagines that Microsoft has at its disposal. After all, the easiest problem for a test script to detect is a boot failure.

Before the era of web- or email-enabled newsgroup / forum posts, my system could have been down for days as I sorted this out.

One other thing: the Microsoft warrantee for Vista is 90 days after it's activated.

2007-02-15

Windows App Install Permissions in Corporate Settings

I worked for more than a decade as a consultant in Fortune 100 settings. I remember well the difficulties one faces when installing even an innocuous application in Windows when you don't have admin (root) access. Martin McKay weighs in on the User Access Control in Vista, which, it seems, is not helping matters. I chime in with a reply on the CW blog page.