Can't boot in Normal Boot Mode

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bucks, Apr 11, 2009.

  1. Bucks

    Bucks Private E-2

    Hi

    I guess I got a virus
    I can't boot in Normal Boot Mode.
    But I can boot in Safe Boot Mode

    My OS is Windows Vista

    Steps I have yet done. I ran:
    - AVG
    - MAlwarebytes Anti-MALware
    - SupAntiSpywre
    - I uninstal Java but I couldn't re-instal the one I had downloded.
    Windows don't let install in Safe Mode.
    - Deactivated User Account Control.
    - Ran MGTools

    I tried to atach MGLogs.zip but the buton "MAnage Attachement" don't work

    Any help would be very much apreciated.

    Best regards
    Bucks
     
  2. Bucks

    Bucks Private E-2

    Attached Files:

    Last edited by a moderator: Apr 14, 2009
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have attached it to your last post for you.

    You need to attach the logs from SUPERAntiSpyware, Malwarebytes and ComboFix. Try another browser if still having problems. Also try refreshing your page to see if the Manage Attachments button appears.

    Based only on the MGlogs file, you may not be having malware problems.

    Did you create the below file?
    Code:
    "C:\Windows\"
    wintmp2.exe   18 Dec 2008      402857  "wintmp2.exe"
     
    Last edited: Apr 14, 2009
  4. Bucks

    Bucks Private E-2

    Hi
    Thank you for helping me

    After my last contact I ran some antivirus and go back to a restore point.
    I found two malwares:
    - Trojan.Dropper /sys-NV
    - Rootkit.Agent/Gen-Reestock

    I didn't create "wintmp2.exe".
    I tested it in the site "Virus Total" and many antivirus said that it was a malware.

    Now I can boot from Normal Mode but I verify that the button "Manage Attachements" still don't work.

    Today hadn't time to run the programs.
    Tomorrow I will try again

    Best regards
     
  5. Bucks

    Bucks Private E-2

    Hi chaslang

    Thank you for your help

    I ran SurperAntiSpyware but it didn't create a log. So I got an image of the results.
    I ran Malwarebytes and it found 2 trojans and a rootkit.
    Yesterday I ran ComboFix, but today I couldn't run it again. It just freezes.
    It says that I have Avira Antivir active but there is longtime that I have it no more.
    I couldn't find any file with 'Avira' in its name.

    Now I can't see the files on my pendrive :(

    I tried to atach the reports and the images but I couldn't, so I put them in a folder, that I call "Reports" I compact it and put it in RapidShare.
    Please, get here the report files:

    http://rapidshare.com/files/222594570/Reports.rar.html

    Thanks a lot.
    Best regards
    Bucks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disable any popup blockers that you may have enabled and try again. Otherwise copy the files to another PC and then attach them.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it did. It always creates a log by default. It is in the below folder which I can see in your other logs. Here is a list of all of your logs from SUPERAntiSpyware.
    Code:
    C:\Users\JBC_2\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    su3ed5~1.log  18 Apr 2009         836  "SUPERAntiSpyware Scan Log - 04-18-2009 - 19-20-11.log"
    supera~1.log  10 Feb 2009        1338  "SUPERAntiSpyware Scan Log - 02-10-2009 - 19-32-59.log"
    supera~2.log  15 Feb 2009        1107  "SUPERAntiSpyware Scan Log - 02-15-2009 - 15-51-14.log"
    supera~3.log  12 Apr 2009        1832  "SUPERAntiSpyware Scan Log - 04-12-2009 - 21-14-27.log"
    supera~4.log  17 Apr 2009         795  "SUPERAntiSpyware Scan Log - 04-17-2009 - 22-37-13.log"                                                                              
    You do not have the current version of Malwarebytes installed. You are way out of date. Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.


    What do you mean by this? Do you mean you cannot access it at all? Does it show up on your drive list in My Computer?



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMPC:\Users\JBC_2\AppData\Local\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • don't forget the new Malwarebytes log
    • also attach the SUPERAntiSpyware log that you never attached.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 27, 2009
  8. Bucks

    Bucks Private E-2

    Hi chaslang

    Thank you for spending your time to help me.
    I apreciate

    When I clicked in the icon "I:", (the one of the pen drive) I got the message "Aplicação não encontrada" that means, I think, "Program not found".
    See the image in attach PenDrive.png.
    Hopefully now is OK again. :)

    Now I got the new version of Malwarebytes and ran It again. I didnt knew where was its log. Now I put it in attach.

    I couldn't run Avenger. It says:

    "Error: Invalid Script. A valid script must begin with a command directive.
    Aborting execution."

    See image: Avenger.jpg

    I ran also GetLogs.bat and the file MGlogs.zip goes also in attach.

    I put all the files (logs and images) in a rar file named : Reports - 21Abr.rar

    Thank you

    Best regards

    ______________________________________________________________
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything to your last message. You need to make sure you attach the logs.

    I fixed and error in my instructions. Try the Avenger procedure again.

    Please DO NOT do this. Attach the logs in the for we request and that is exactly how they are created. We do not want RAR files and we do not want you making your own ZIP files either.
     
  10. Bucks

    Bucks Private E-2

    Hi

    I downloaded again Avenger and ran it

    I got a problem after the restart.
    I received a message telling me that a non authorized alteration had been made to Windows.
    Error detail : 0XC004D301

    I have been obliged to give again my Product Key.

    Once this problem solved I tried Avenger again.
    This time I got the same Invalid Script message, as in the past.

    Sorry about the '.rar' file. This time I am doing as you told me.

    Please find attached:
    avenger.txt
    mbam-lo-2009-04-21 (23-28-08).txt
    MGlogs.zip

    Thanks a lot
    Best regards
     

    Attached Files:

    Last edited: Apr 26, 2009
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my last message I said a fix an error in the script. You did not need to download Avenger again, you just needed to use the corrected fix which I edited. The snapshot you attached shows that you use the old fix and not the new one. The first line of the Avenger fix now says

    Drivers to delete:

    instead of

    Drivers to remove:

    You need to rerun this Avenger fix and attach the new c:\avenger.txt log. Also you will need to supply a new log from MGtools by running GetLogs.bat again.
     
  12. Bucks

    Bucks Private E-2

    Hi

    I ran again Avenger with your last script.
    I got the same problem as the last time I ran it (for the first time).

    After reboot it says that an unauthorized alteration had been made to Windows.
    I had to use the "Recovery Disk" and put again my Product Key.
    It didn't make a log.

    This is the message in Portuguese:
    ____________________

    Activação do Windows

    Foi feita uma alteração não autorizada ao Windows.
    Vai deixar de receber modificações, incluindo as referentes à sua licença ou activação.
    Utilize a hiperligação abaxo para determinar como corrigir o sistema.

    Mais informações online
    Detalhes

    Erro: 0xc004D301
    Descrição
    O processador de segurança relatou que o arquivo de dados fidedignos estava adulterado.
    ________________

    The automatic translation:

    Windows Activation

    An alteration not authorized to the Windows was made.
    Will no longer receive modifications, including those relating to your license or activation.
    Use the link below to determine how to fix the system.

    More information online
    Details
    Error: 0xc004D301
    Description
    The security processor reported that the archive of trustworth data was adulterated.
    _________________________________

    Hope this may help

    Thank you
    Best regards
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the new C:\MGlogs.zip file so I can check to see if Avenger was able to remove anything.


    How are things working now?
     
  14. Bucks

    Bucks Private E-2

    Hi

    Thank you for your help

    I ran GetLogs.bat, but I couldn't, again, use the button "Manage Attachements" to attach MGlogs.zip.

    So I put the file in RapidShare:
    http://rapidshare.de/files/46942241/MGlogs.zip.html

    Sorry for the inconvenient.
    Everything else seems to be working normaly

    Best regards
    Bucks
     

    Attached Files:

    Last edited by a moderator: May 2, 2009
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is incomplete and not useful. Please delete the current C:\MGlogs.zip file and then run the GetLogs.bat program again and make sure that you allow it to finish running. When it finishes, attach the new log. Please do not use rapidshare. If the Manage Attachments button does not work, just refresh your browser or use a different browser.
     
  16. Bucks

    Bucks Private E-2

    Hi
    Thank you

    Sorry about the log.
    I have no idea what went wrong

    Please find attached MGlogs.zip

    Hope this time is OK

    Best regards
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is still of no use to use. You must DOWNLOAD and save the MGtools.exe file to your C:\ folder as stated in the instructions. What little that shows in your logs reveals that you are trying to run it from the C:\Windows\System32 folder which is not where it belongs and this will not work properly. You need to follow the instructions properly and attach a new log. When you download it properly, you should have a C:\MGtools.exe file which is what you need to run.
     
  18. Bucks

    Bucks Private E-2

    Hi

    Thank you chaslang

    Please find in attach the file.

    Kind regards
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    P2P_Torrent Toolbar <-- This is a security risk

    Make sure you shutdown AVG and Ad-Aware's Ad-Watch before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files & folders we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. Bucks

    Bucks Private E-2

    Hi chaslang

    Thannks a lot for your suport.

    Please find in attach:
    avenger.txt
    MGlogs.zip

    Best regards
    Bucks
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to tell me how things are working.

    Your logs are clean but delete the below folder.
    Code:
    "C:\Users\JBC_2\AppData\Roaming\"
    #32E2~1       29 Apr 2009              ".#"

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. Bucks

    Bucks Private E-2

    Hi chaslang

    Thanks a lot for your very useful help.

    Aparently things now seem to run well

    I couldn't find the file:

    Code:
    "C:\Users\JBC_2\AppData\Roaming\"#32E2~1       29 Apr 2009              ".#"
    But I found a folder ".#"
    It was empty and I clean It

    Best regards
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was a folder not a file and .# is the one I was referring to. That is what is called the long folder name whereas the #32E2~1 name is called the 8.3 DOS short name (yes the short name in this case is longer ;) ).

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds