msconfig set to normal startup mode and now bsod on log in

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fuse01, Oct 12, 2011.

  1. fuse01

    fuse01 Private E-2

    i accidentally downloaded and installed program that was malware/virus. ive tried using comodo and malware bytes to try and remove it but with no joy. I found a few recommendation for this site so proceeded to go through the steps in the read me first thread in the malware removal section but after completing the "set msconfig to normal startup mode" every time i try to log into windows i get BSOD, what shall i do next?
     
  2. fuse01

    fuse01 Private E-2

    k i restarted in safemode and changed it back to selective start up. I looked through my start up items and noticed an item remaining from previous AV software for a location which no longer exists. and with that disabled my pc starts up fine.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having malware issues?
     
  4. fuse01

    fuse01 Private E-2

    comodo's defence+ has told me about suspicious exe files that have been created in my windows/temp folder which also attempted to launch , java has been used to try and launch suspicious exe's, (so @ that point i uninstalled java and deleted the java folder from program files i since then have reinstalled following one of you guides) every now and again when i click on a link i get redirected and my computer has significantly slow down to a point where i cant play games that i had no problems running only a couple of days ago. So im guessing that i have but i could only guess. there was also this .exe called zwinky that was flagged by comodo also. ill add the locations and files names below in case that helps.

    C:\Windows\TEMP\nmtokv\setup.exe
    C:\Windows\TEMP\unylvf\setup.exe
    C:\Windows\TEMP\ytyovu\setup.exe
    C:\Windows\TEMP\jnsfvv\setup.exe
    C:\Windows\TEMP\sddywh\setup.exe
    all above = trojan.win32.trojan.agent.gen@268865383

    C:\Windows\TEMP\rcuvsw\setup.exe
    trojan.win32.trojan.agent.gen@1

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EBYRD0DO\Zwinky[1].exe
    UnclassifiedMalware@251283264 (so I guess thats that question answered for us :)

    C:\Windows\TEMP\vcjptc\setup.exe
    Heur.Suspicious@286177749

    also whilst doing an online search b4 this post using house call i got these flagged up (by comodo not housecall which said i had no problems using a quick scan)

    C:\Users\fuse01\AppData\Local\Temp\HouseCall\VS78GV8K.00A
    UnclassifiedMalware@16057002

    C:\Users\fuse01\AppData\Local\Temp\HouseCall\VS78GV8K.01B
    Trojan.win32.kryptic.~NT@105835263

    hope that helps

    oh i had best add that i am now following the instructions from the "Vista and Win 7 Malware Removal/Cleaning Procedure" so ill let you know if im still having any problems after completion

    p.s thnx for the speedy reply
     
    Last edited: Oct 12, 2011
  5. fuse01

    fuse01 Private E-2

    i also forgot to mention that I downloaded goorefix to try to fix my redirection problem but when i try to run it cmd opens then it just closes with the following error message

    Problem Event Name: APPCRASH
    Application Name: GooredFix.exe
    Application Version: 2.0.0.687
    Application Timestamp: 4c2f02ff
    Fault Module Name: msvcrt.dll
    Fault Module Version: 7.0.7600.16385
    Fault Module Timestamp: 4a5bda6f
    Exception Code: c0000005
    Exception Offset: 0001d33d
    OS Version: 6.1.7601.2.1.0.256.1
    Locale ID: 2057
    Additional Information 1: 0a9e
    Additional Information 2: 0a9e372d3b4ad19135b953a78882e789
    Additional Information 3: 0a9e
    Additional Information 4: 0a9e372d3b4ad19135b953a78882e789
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. fuse01

    fuse01 Private E-2

    ive read through and followed the read and run me first guide but am still having problems although im not sure whether comodo might have interfered with mg tools and combo fix for instance even with all comodo features disabled combofix warned me that denfence+ and AV real time scanners where still active (i tried ending any comodo processes i could see also but that didnt help) also i cant get RootRepeal to run with out the following crash/error:ROOTREPEAL CRASH REPORT
    -------------------------
    Windows Version: Windows Vista SP1
    Exception Code: 0xc0000005
    Exception Address: 0x00429d13
    Attempt to write to address: 0x01878000

    aswell as having problems with running goorefix. I tried renaming them both but this had no effect, I have attached reports from malwarebytes, superantispyware, combo fix and MG
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any of those files or folders in your log, but let's see if they are found with a removal script.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Windows\TEMP\nmtokv\setup.exe
    C:\Windows\TEMP\unylvf\setup.exe
    C:\Windows\TEMP\ytyovu\setup.exe
    C:\Windows\TEMP\jnsfvv\setup.exe
    C:\Windows\TEMP\sddywh\setup.exe
    C:\Windows\TEMP\rcuvsw\setup.exe 
    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EBYRD0DO\Zwinky[1].exe
    C:\Windows\TEMP\vcjptc\setup.exe
    
    Folder::
    C:\Windows\TEMP\nmtokv
    C:\Windows\TEMP\unylvf
    C:\Windows\TEMP\ytyovu
    C:\Windows\TEMP\jnsfvv
    C:\Windows\TEMP\sddywh
    C:\Windows\TEMP\rcuvsw
    C:\Windows\TEMP\vcjptc
    
    FCopy::
    C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe | c:\windows\system32\userinit.exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now please do the following:
    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds