Stuck in safe mode and can't resolve security host names.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 4boys, Nov 11, 2008.

  1. 4boys

    4boys Private E-2

    Hi and thanks for looking at this.
    I have a winXP system running latest updates and SP3. When I got the system it was infected with various Mals..
    don't have all but here are some;
    Virantix
    Fraud.XPAntivirus
    Delf.Spool.CN
    Agent,AAC2
    Troj/FakeAV-CE [Sophos]

    Symptoms- System would of course produce offers to purchase XP Anti virus software. The system would redirect any browser searches to Mals own site using wording culled from search to make you think you were getting the software searched for. I could not download a new version of Spybot because of the redirect. Could not update old version because something has hosed the hosts table. Could not run Spybot because something would not let it or AdAware run. I was able to change the name of the executable in spybot to get it to run. I use a USB key to bring AdAware and spybot to the system with updates I got spybot to install and it cleaned a few things but wanted a reboot, since then I have not been able to boot to normal mode (I think the items added to the boot sequence to remove the infected files are keeping the system from booting) I manually deleted the files it thought were infected(those are still listed in the hijack this log). Ad Aware will not install due to Error "Sys admin has set policies to prevent this install" and I cant run the suggested gpedit.msc to fix the problem. System has AVG 7.5 but it's out of date and redirect of host does not allow updates.

    So I removed the HD from the system and connected it to another and ran norton AV 2008 and It finished the cleaning process but I can't get the drive to boot to normal mode and the hosts table is still jacked. Oh and I did check the hosts file and it is clean, the only listing is for "127.0.0.1 localhost". So can you tell me how this host resolution can be so jacked up?? I can connect to all the beguine web sites but as soon as I try to go to a security site like Majorgeeks.com and support.microsoft.com I get a failure to connect. No, it's not just in the browsers, I can't even ping these sites and I can't update the installed security software basically the domain name is not being resolved and is pointed back to 127.0.0.1 Local host. I can get to the security sites by putting the IP address directly in to address bar but links on the page won't work because they use the domain name.

    Ran CCleaner
    could not run SuperAnti Spyware because I'm stuck in safe mode
    Ran Spybot
    Ran Malwarebytes Anti-Malware but it wants to reboot to finish cleaning (only works in normal mode)
    Combofix appeared to do nothing (sat in the task manager for a few minutes)
    Ran MGtools log included.

    Any more ideas would be appreciated.

    I think that is about it, here are the logs I was able to run.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach any logs. :(
     
  3. 4boys

    4boys Private E-2

    I guess I didn't click something when attaching, lets Try this... I see I didn't click the "upload" button....
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...time to go to work.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  5. 4boys

    4boys Private E-2

    Tim W.
    Thanks for getting back to me on this. OK as for how it worked. Well I was good all the way to the Java runtime 6. I get this error after double clicking on the downloaded file "The Sys admin has set Policies to prevent this install".

    The system still only boots to safe mode and there are no issues in Device Manager. The domain resolution problem is still there. Once again I can surf to most sites but can't connect to any security related sites. I can get to Microsoft.com, intel.com and support.intel.com but not support.microsoft.com or Majorgeeks.com, I can connect with the IP addresses. I get the same results with ping at the command prompt. So this does not appear to be a browser issue. It feels like to me that something has messed with the Network software so that the system is looking at a Hosts file that is not named Hosts and is not searchable through explorer.

    I attached the logs, please note that the MGtools log is w/o the java install.

    Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you running through a router? If so, try resetting to factory settings.

    Please try running ComboFix again...once done then Download Blacklight Beta.

    * Download blbeta.exe and save it to the Desktop.
    * Once saved... double click blbeta.exe to install the program.
    * Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
    * If it displays any items...don't do anything with them yet. Just hit exit (close)
    * It will drop a log on Desktop that starts with fsbl....big number

    Please post contents of the BlackLight log.
     
  7. 4boys

    4boys Private E-2

    Tim,
    I'm a bit slow to reply, the video card on the system I connect to majorgeeks with failed. Old card, but not unexpected it's the second of two ATI cards that I bought to fail.

    Anyway, back to the system that had the problems I can't solve. I understand what you're thinking regarding the router, but it's a real simple one and any restrictions would affect all connected systems not just the one. Also these same resolution problems existed when I picked up the system, different router/different ISP. Besides, I can tell that the failed pings and DNS requests are not getting out of the box. If I were a tech support guy and someone had the problems I'm having with host name resolution I would think the fix is easy. Wipe the Hosts file and go home. But that's not the case, the hosts is clean. As far as I can tell the resolution is happening on the system.... unless it is some how spoofing me and sending all DNS requests to some bogus home brew DNS with all the security related sites stripped out. IPconfig shows that all unresolved reqeusts are being thrown at the default gateway (routers local IP address).

    FYI (I download all the fix files to a non affected system and throw them across the network, then bring the log files back and send then in my posts)

    ComboFix did nothing again, showed up in task manager for about 10 min then closed on it's own.

    Blacklight did not run in safe mode.

    Thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me exactly what happens if you boot to normal mode.

    I would like you to go to start / run / type "msconfig" without quotes and open the boot.ini tab....either get me a screen shot of it or copy and paste it into your next reply.
     
    Last edited: Nov 18, 2008
  9. 4boys

    4boys Private E-2

    Tim
    Thanks for getting back to me. During boot the system posts fine and I can get into the BIOS, everything seems fine there. Also system seems to find all the peripherals as in a normal boot. Next comes the windows loading screen, the one with the chasing blue cubes. That screen stays on for 7 passes of the blue cubes then the screen blinks and it goes back to the Dell bios screen and wants to boot to safe mode.

    Here is the Boot.ini
    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin
    C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

    I remember we use to fix some really funky network problems by reinstalling winsock in older versions of windows. Do you think there is anything in winsock or in the network stack that could produce these type of network problems?

    Thanks
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And none of the boxes are checked?

    If none are checked, then click the box to check all boot paths.

    Tell me what happens.
     
  11. 4boys

    4boys Private E-2

    none were checked: Clicking check all boot paths reports;

    This line in the boot.ini file does not refer to a valid operating system:

    "C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons"

    would you like to remove it from the boot.ini

    I have not even tried the console but I installed it as part of the trouble shooting prior to posing in the form.....
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the general tab in msconfig is set to normal startup....

    Then lets remove it "C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons".....click Start > Control Panel > System > Advanced Tab > Settings (under Startup and Recovery) > Edit. Now remove that portion of the path ...Now save the boot.ini file, close it and exit out of the system settings.

    Can you boot to normal mode now?
     
  13. 4boys

    4boys Private E-2

    Removed the boot to console option from the .ini file, system booted the same. Feels almost like a video driver issue but the system uses integrated video and there is nothing noted as wrong in Device Manager.

    The reason I say it feels like a video driver issue is because the systems seems to be loading all neccesary operating system files then fails at the end, just as you would expect a resolution change and the login screen to appear.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After removing the console path..did you go back to msconfig and check the path again? Did it give you an error?
     
  15. 4boys

    4boys Private E-2

    I had MSConfig check the boot path and it reports that all lines in the boot.ini appear OK.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to C:\Boot.ini...open it and get a copy of the file either by copy and paste or by making a back up and renaming it to boot.txt so it can be attached.
     
  17. 4boys

    4boys Private E-2

    That's pretty much what I did before. It's easier to copy from the text file than to copy anything from msconfig. But here is the INI file renamed to .txt

    Thanks again....
     

    Attached Files:

    • boot.txt
      File size:
      212 bytes
      Views:
      1
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be necessary to send you to the Software Forum to debug this, but let's try something.

    Run MSconfig and select Diagnostic Startup. Then click Apply, OK. And reboot your PC. See if it will come up in normal boot mode. If it does, you will not be able to do very much in this mode. No internet access either. Then you can try using Selective Startup with Msconfig and eliminate the loading of various items to see if you can located anything that may be preventing normal startup. It is a trial and error process of elimination.
     
  19. 4boys

    4boys Private E-2

    Changed boot to Diagnostic Startup but system would not come up in normal mode. Seems that something critical got removed or corrupted when I cleaned out the malware. I have always felt that XP could be fixed when there are problems, but it seems that a reinstall may be in order here. I would really love to know what has caused the network issue, that's got me concerned about the future of malware, if it can happen to this system it will happen to others.

    Let me know what you think.... Thanks for helping!!!
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only suggestion we have at this point is to do this:

    Go to run / type "sfc /scannow" without quotes and note the space...have your xp cd handy. Run it twice,

    If this does not work then possibly a repair install is in order. I would suggest that you post in the software forum to continue with this problem.

    We need to clean up the scan leftovers before to go:

     
  21. 4boys

    4boys Private E-2

    TimW,
    Thanks for working with me on this. It became a bit of a challenge for me to try to resolve, I hope not to run into something like this again. Still would like to know what happened to the network DNS resolution. The SFC Scan File Checker did not work. Most likely because I'm in safe mode got the error.
    "Windows File Protection could not initate a scan of protected system files."

    I'll got through the clean up and then do a reinstall of windows on this box. Should have it up in just a few hours....

    thanks again.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome...sorry we could not resolve this for you. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds