Malware trouble cant login to safe mode without a bluescree after 5 seconds

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SomeCrazyStuff, Sep 7, 2008.

  1. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok i am working on a laptop for a friend of mine. he has gotten somekind of malware on it.. i had once before removed some stuff from it.. and told him it wasn't completely clean and what to do about it.. but it would seem he has been back on the internet unprotected since then..

    at the moment when i log into regular mode i get a bluescreen listing a 0x000000f7 stop error.. but it gives no details.. also the bluescreen never takes longer than 30 seconds to occur so no way to do any trouble shooting there..

    when i try to log into safe mode the screen barely changes at all before i get the same bluescreen as before..

    the computer is a stock hp pavilion dv1000.. i do not know the exact specs of the computer other than it is running XP home SP2.. the guy im working on it for isnt at all technically savvy so it probably has just whatever was standard at the time he bought it...

    any help would be greatly appreciated..

    thankx in adv. ;)
     
  2. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    update: ok found some articles elsewhere online (thx google) and ive decided my friends laptop is victum to a buffer overrun attack... however im not having any luck discovering the driver thats over-running its buffer... any ideas as to a way to figure this out?

    thx for any help or suggestions or thoughts
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Moving to the Software Forum.
     
  4. studiot

    studiot MajorGeek

    One method of checking drivers is to boot to a command prompt, either using F8 options or with the repair console on the CD.

    Then add the following switches to boot.ini

    /bootlog (records driver loading action in c:\ntbtlog.txt)

    and/or

    /sos (forces xp to display drivers as loaded and halt at problem one.)
     
  5. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok at the moment i am kinda just playing with dofferent things.. i found the minidump fule along with the boot log and neither seem tohelp.. im about to try to get the MS debugging tools as per http://forums.majorgeeks.com/showthread.php?t=35246 and see what i find from that... will post more info later

    thx for all suggestions/.. please let me know of anymore

    edit: i did notice that when i login as safemode with command prompt the computer doesnt bluescreen.. ima do this and launch the explorer from there to get to the internet... (hopefully)*crosses fingers*
     
  6. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    iight just another update for anyone whos reading.. i have ben playing on it online for about an hour now with no bluescreens.. i am trying to run an eset online scan to see if it will clean anything up or maybe give me a malware name to do further research on...

    if anyone has any further ideas let me know.. i will try anything i can... never know what will help..;)
     
  7. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    yet another update..

    sorry for the numerous posts.. just dont want someone to waste the time on something i have already tried...

    just finished a malewarebytes scan and it gave me 76 infections including trojan.vundo.h, trojan.vundo, trojan.zlob, trojan.bho, trojan.agent, trojan.avkiller, adware.bho, malware.trace, trojan.extension.exploit, rogue.link, and trojan.dnschanger..

    now lets see what it can clean up...

    will post after if things still seem fishy...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since this points towards having malware ( your original message did not) then you should do the below and attach the requested logs. I will move this back to the Malware Forum to continue working on this. DO NOT RUN Malwarebytes again when you get to that part. Just attach the log that you should already have from running it.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  9. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    will do. but i just ran it again after rebooting and disabling system restore.. i found 10 more infections including search.hijack, malware.trace, trojan.vundo, trojan.zlob, and hijack.startmenu..

    also i should mention bfore i go through all the read and run first stuff that when i did the eset online scan it mentioned 7 trojans.. win32/privacyset.a(x2), win32/rootkit.agent.nex, win32/small.ndr, win32/small.ndr, win32/bho.nbm, win32/bho.ncv(x2), and win32/small.ndr

    however the eset online scan didnt offer any fixes for them nor could i find manual fixes in their threat encyclopedia... but o well..

    now to do the read and run first stuff.. i was lookin at it earlier and it seemd a VERY good guide to cleaning computers.. i could use it at work too.. xD maybe someone could make those programs into a boot disk of somekind? or work them into the ultimate boot cd and set it as a new distribution of it? just ideas though..

    will post later with the logs.. thx again for the previous help and ideas and future thx for any more help provided... :cool
     
    Last edited by a moderator: Sep 9, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then attach both logs from MBAM later but do not run it anymore and only run scans once.

    You should not have disabled system restore. That should only be done after malware is removed. Reenable it now. If something goes wrong during cleaning and you have no restore points, you will be reinstalling. Even an infected restore point is better than none at all. ;)
     
  11. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    sorry just reading your post.. yea i knew better than to disable it already.. suppose sleeplessness is starting to kick in.. still working on running scans... working on spybot right now.. i have the log for superantispyware... ill find the logs for malewarebytes after spybot is finished.. still have combofix and mgtools left to go... not too bad

    by the way.. do you work for majorgeeks.com or is it more a side job? was just curios cuz i really want to get more into the security side of things with computers and thought if this is your job you might have some suggestions to get started or different classes/certs to go for...

    lol
    will post all the logs at once.. in 2 different posts of course since theres a 3 attatchment limit(or so i read)

    edit: spybot has just under 100,000 files left to go through

    edit: ok mbam only listed one of the two logs? anychance it would have deleted one of the logs.. or maybe not even created one? it would appear the first log was deleted/. i know i didnt do it(purposely) unless it got caught in one of the clean up features of superantispy... thats the only other thing i can think of right now...
     
    Last edited: Sep 9, 2008
  12. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    iight here comes the logs.... gonna have to switch to the computer in question... (im lucky enough to have a couple of computer to play on while i waited.. xD)
     

    Attached Files:

  13. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    and heres the second mbam log.. stil dont know where the first went to...

    let me know what else you need...

    ima go to bed for tonight.. will pick this up tomorroow proly round noon(got classes til then)..

    thx again for all the help

    edit: also.. if you dont mind.. i would like to know what all you are looking for inthe logs.. i have a couple other computer that i would like to do thid for and would love to be able to do this for at work too.. would probably helpout with many of our problems up there... im part time as the pc/computer room tech for a trucking company and im sure you can imagine us having ppl calling all the time with this and that problem.. but if i knew what i was lookinjg for in the logs i could possibly help out on here and just whereever else it was needed(fixing friend's laptops.. >.>)

    forgot to defrag earlier.. going to install and run diskkeeper sometime tomorrow as well
     

    Attached Files:

    Last edited: Sep 9, 2008
  14. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok i dont mean to rush anyone but i would like to go ahead and get the defrag running and get MS updates going as well.. i noticed that the laptop had a couple of updates to get.. most likely including SP3...

    and while im on that topic has there been any complaints about sp3? i have talked to several people saying they are just going to wait and see how it goes with others before they put it on their machines...

    but anyways.. if someone could help out with those logs i would greatly appreciate it...

    as always thx in advance.. i cant ever get enough help.. xP
     
  15. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    well thx for helping.. i gave the laptop back to my friend today as it seemed to be running fine.. he put avg on it.. at least now he has SOMETHING there to help out...

    would still appreciate someone to look at the logs and tell me what they think.. iwould really like to know what to look for in the logs as well so i can trouble shoot computers on my own..

    but as far as this issue goes i suppose the thread can be closed...

    again thx everyone for the help.. will be posting in here again..
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we do not work for MGs and this is not a job. It is volunteer support.

    First learn as much as you can about the Windows Operating Systems (all of them). Then if you are looking for training in malware removal, join one of the below:

    http://www.spywareinfoforum.com/index.php?showtopic=34

    http://forums.whatthetech.com/What_the_Tech_Classroom_t80368.html

    http://www.geekstogo.com/forum/Would-like-to-learn-to-fight-malware-t4817.html


    No it did not delete any logs. What user account did you run the scan under. Based on your MGlogs.zip file, you did not run SUPERAntiSpyware or Malwarebytes while logged into the Michael Wilson user account which is where you ran ComboFix and MGtools. I say this because no logs for either program show in that user account. Either that or they never finished running. Perhaps you used one of the Administrator.FELLASPC accounts.


    Also note, you should read this: Don't Bump! It Only Hurts You!!! additional posting is causing you additional delays in getting answers. Message # 14 had already cost you at least a half a day and when you posted message # 15 it cost about another day on top of that.
     
    Last edited: Sep 11, 2008
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a topic for the Software Forum. ;)

    Well since you gave the PC back it is too late but here are the remaining things that needed to be done. Some for infections that remain and some just general performance todo's.

    First if you have installed AVG did you make sure that ALL of Norton was uninstalled before installing AVG. Norton rarely uninstalls properly.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper) -
    O16 - DPF: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class) -
    O16 - DPF: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class) -
    O24 - Desktop Component 0: Warning homepage - C:\WINDOWS\warnhp.html

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    awesome.. ill see if i can get the laptop for a lil while another day.. maybe this weekend before he has had too much time to do damage.. ill do as suggested...

    i know the sp3 quote should go on the software forum.. just figured to hit it while i was here..

    also this is a bit more personal but i would still like to know better what to look for in the log files.. like when you look at them what are the general flags that somethings amiss.. obviously something like the uninstalling all of norton and java updates and that stand out as i have seen several places where you have told people to do that.. but where do you see that it needs the certain options in HJT? or the registry changes? is that just from experience or was there something specific in the logs that caused you to suggest those things?

    again sorry i know this isnt really the place for those questions.. and i would have just sent them to you in a pm or something.. but i suppose i havent gotten enough posts in to be allowed to pm... and i havent found the appropriate forum to ask such things either..

    i REALLY appreciate the help.. ima start using those cleaner tools on computers at work and whereever that need to be tighty-ed up... yea i didnt know how to spelled tighty-ed.. lol

    again thx.. looking forward to future help.. who knows maybe after anther problem or two i might be able to help someone else.. xD
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is really a mostly a matter on knowing what belongs and what does not belong. As stated in message # 16, you have to have significant knowledge of the Windows Operating System and 3rd party software to best know what is valid and what is not. Sometimes it is rather easy to pickup randomly named out of place files and registry entries and othertimes it is not. It depends on the malware.

    The HJT changes were the least signficicant in this case. Only the 024 line was related to malware. The rest was simply things not needed. This is again all a matter or experience. Logs from ComboFix, HJT and the MGtools logs are not necessarily showing you things that are bad. They are given you information related to places where malware may or may not be hiding and it is up to the experienced person to determine what is good and what is bad. And then once you have find something that is malware, you need to decide on what is the best way to fix it.

    There was another line in the HJT log that I did not have you fix with HJT. I chose to fix it with ComboFix which is more reliable in this case because the problem was a service. The line was this:

    O23 - Service: NQBCZYQAN - Unknown owner - C:\DOCUME~1\ADMINI~1.002\LOCALS~1\Temp\NQBCZYQAN.exe (file missing)
     
  20. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    wow i didnt even see post #16.. my bad.. ok thx for the info there.. ill try to watch my posts..

    really appreciate the links to find out more about malware and training and stuff.. cant ever get enough reading material.. just hope as i read i will have instances to apply it on... and continue to get plenty to work on.. so i dont forget things....

    are those links specific to the scans we ran or are they more tuned to malware in general?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those links are malware training sites. They are not links to reading material. You have to enroll in the "school" and undergo training/testing and so on. It is not a short procedure. It is very detailed.
     
  22. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    oh my fault... i hadnt been to them yet.. well ill stop posting in here since the problem is fixed and we are starting to get a bit off topic..

    thanks again for all your help and for the links.. im about to go look around on them and might try to get started with some things.. who knows..
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You still need to get this PC cleaned up the rest of the way.
     
  24. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    i know.. i have to get my friend to let me have the laptop back.. until then i cant do much... sorry if you are waiting for confirmation logs or anything... i will do my best to get the laptop monday afternoon.. but.. no promises..
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem. You don't need to post again until you have been able to run the procedure and get the logs.
     
  26. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    iight heres the logs

    note: combofix stalled and after about an hour of waiting i closed it.. it was in the creating log stage so i hope it didnt mes anything up..

    the log i attatched for combofix.. im not sure that thats the current one.. if needed i will run combofix again and repost that log.. let me know..

    appreciate the help..:cool
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ComboFix log is incomplete. It is possible that AVG8 and or Norton is the reason as it falsely detects ComboFix and some files used by it as problems. You don't need to rerun ComboFix though.

    It appears that you did not Run this Disable/Remove Windows Messenger

    Also I still see both AVG8 and Norton Antivirus programs installed and running. As stated before, you need to uninstall one of these. If you decided that you wish to uninstall Norton then please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  28. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    yes.. im an idiot.. i forgot to note that i couldnt run the windows messenger remover because of no internet connection.. i wasnt in a place where i could get internet.. i had the instruction printed out for the txt files and what all else to run..

    i will run that asap..

    the norton this i wasnt aware that norton was still on it.. it didnt show in the add remover programs nor anywhere else that i remember seeing.. maybe it still has traces that are doing what they can to run.. i know how annoying norton can be to remove without that removal tool..

    ^^ that must be why you mentioned norton before... sorry i didnt pick up on the hint..

    also should i run combo fix again?

    thx alot
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Just follow the instructions given.
     
  30. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok was just making sure as the previous run didnt finish completely..

    i will try to run the norton remover and windows messenger remover as soon as i can..however i dont know when thatll be... unless you think something will evolve from what i have on the computer atm then i guess we can consider this topic closed...

    i know i have said this several times.. but i really appreciate all of your help.. and the links to learn more i know will prove useful.. i have enrolled in GeekU and am about to start the practice logs there... would you ming sharing some of your canned speeches with me to use as templates in creating my own? also what program do you use for your canned speeches? i downloaded Keynote and am working on figuring it out.. i made sure to bookmark all of the pages referencing HJT tutorials and such to look back on.. lol

    but anyways.. i wont keep rambling here... thanks again...:cool
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really need to learn from the school you have enrolled in and follow their styles and formats. Once you are out on your own, you will then adapt to the forum styles of where you provide tech support. Each forum may have unique styles. We for example do not want inline logs (they clutter up the search engines with alot of useless info and they clutter up the threads they are posted in and also slow down page loading in the forums) and we refuse to perform malware removal based on HijackThis logs alone like many forums do since they do not provide adequate information on the malware status of a PC. On many sites, HijackThis logs are the first thing requested. Here they are never requested since they are embedded into our own tools and automatically obtained. Whereas many forums are just analyzing and fixing what they see in HijackThis logs, we perform comprehensive malware removal and also cleanup other unnecessary junk and often provide performance improvement tips along the way.

    Nothing is required except the forum editor and notepad to make copies to save to text files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds