Vista machine keeps rebooting after malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by crm1975, Apr 2, 2011.

  1. crm1975

    crm1975 Private E-2

    I am fixing a PC for a friend who had a bunch of viruses on his machine. Some of these viruses were AV8 Rogue Anti Virus and Whitesmoke. I followed the malware removal guide and ran CCCleaner, SAS, MB Bytes, Combo Fix, and MG tools. I have also tried the "Repair" option(F8 on startup) and that just asks for a user/password screen and wont let me by. I also tried Last know good Config and that keeps rebooting as well.

    The log for Combofix said it found a rootkit (Bootkit TDL4) I beleive. Now when I reboot the machine into normal mode, it displays the log in for a few seconds and the reboots. It keeps doing this unless I boot into Safemode.

    I can boot into "Safe mode w/Networking" and everything seems to be fine, but obviuosly I would like to boot into normal mode. Also, when it does boot into Safe mode it always pops up the "System properties" window and Help for Safe mode.

    I am attaching the latest log files from SAS. MBBytes, Combofix and MGtools as well.

    Any help would be appreciated. Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Files::
    C:\Windows\TEMP\wwwodmrvf\snfmrhflajb.exe
    C:\Windows\TEMP\ckf4ud.exe
    
    DirLook::
    C:\Windows\System32\6.0.6002.18005
    
    Registry::
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MqmPab"=-
    "jaryxnfl"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall

    Now see if you can boot into normal mode and run the scans.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. crm1975

    crm1975 Private E-2

    I did what you said but it seems that when I drag the CFscript onto Combofix, it launches right away and then runs up to about step 41 and then reboots the machine. No finish log pops up or gets written. It then allows me to log in normally but then reboots after 5 seconds and I am back where I started. Each time it reboots, those 3 lines of registry entrys that get removed by HJT get added back in as well.

    I tried it twice now, each time re-running the Analyse.EXE and selecting those 3 lines for removal. Each time after I reboot, the CFScript.TXT file no longer exists and I need to re-create it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [combofix] "C:\ComboFix\CF5956.cfxxe" /c "C:\ComboFix\C.bat"
    O4 - HKLM\..\RunOnce: [combofix] "C:\ComboFix\CF5956.cfxxe" /c "C:\ComboFix\C.bat"
    O4 - HKUS\S-1-5-18\..\Run: [MqmPab] C:\Windows\TEMP\ckf4ud.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [jaryxnfl] C:\Windows\TEMP\wwwodmrvf\snfmrhflajb.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MqmPab] C:\Windows\TEMP\ckf4ud.exe (User 'Default user')

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. crm1975

    crm1975 Private E-2

    Ok, I tried running the Avenger. The machine reboots but Avenger doesn't seem to run. It comes up back to the log in screen and when I log in, the same thing happens, it reboots itself every 5 seconds like it was at the beginning.

    After the reboot, I ran the Analyse again and all 5 of the lines fixed by HJY are back. I fixed them again and tried setting up the Avenger again and it tells me that it is already queued for execution on Next reboot. I restarted the machine and also shut it down and it looks like the Avenger didn't run either time.

    Thanks
     
  6. crm1975

    crm1975 Private E-2

    The computer is still not running the Avenger on startup. I know enough to do some stuff manually if you need me to. I realize you guys are busy so just checking to see if you needed anything else from me, just let me know. Otherwise I will be patiently wait for your response. Thanks again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay please attach the follow up MGlogs.zip file anyway so we can see your current status.
     
  8. crm1975

    crm1975 Private E-2

    Here is the latest MGLOGS.Zip files
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of these lines I asked you to fix are in the last MGlog.zip file you attached.

    So what problems are you actually still having. Is it still not possible to boot in normal mode and run an MGtools scan?

    Why did you run ComboFix again on April 4th? We did not ask you to do this.
     
  10. crm1975

    crm1975 Private E-2

    After the machine rebooted I had run the HJT and fixed those 5 records again, so when the GETLOGS.BAT ran they were probably fixed by the Analyse.exe pgm. I attached the MGLOGS.ZIP again after a restart so the 5 lines show back up in my registry now.

    As for running Combofix again, I was trying to uninstall it and accidentally double clicked it and once it started running I didn't want to stop it.

    i will leave the machine alone from now on until I hear from you. sorry.

    Thanks
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The HijackThis log in your MGlogs.zip file was not updated for some reason. Can you boot up in normal boot mode and run a new scan with C:\MGtools\GetLogs.bat and attach the C:\MGlogs.zip fle obtained in normal boot mode?


    Also please run the below and attach the log from GMER:

    GMER - running with a random name
     
  12. crm1975

    crm1975 Private E-2

    I can't boot into normal mode because it reboots on me right away. I can only log in in Safe mode so I choose the Safe mode w/Networking. I ran the Analyse.exe program and just saved the log without fixing anything.

    I also downloaded the GMER program and ran that. So I attched both logs again. Thanks
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [combofix] "C:\ComboFix\CF5956.cfxxe" /c "C:\ComboFix\C.bat"
    O4 - HKLM\..\RunOnce: [combofix] "C:\ComboFix\CF5956.cfxxe" /c "C:\ComboFix\C.bat"
    O4 - HKUS\S-1-5-18\..\Run: [MqmPab] C:\Windows\TEMP\ckf4ud.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [jaryxnfl] C:\Windows\TEMP\wwwodmrvf\snfmrhflajb.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MqmPab] C:\Windows\TEMP\ckf4ud.exe (User 'Default user')

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\TEMP\ckf4ud.exe
    C:\Windows\TEMP\wwwodmrvf\snfmrhflajb.exe
    C:\Windows\TEMP\ckf4ud.exe
    C:\Windows\TEMP\wwwodmrvf
    C:\ComboFix
    C:\Windows\System32\lsseagf.txt
     
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "combofix"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "combofix"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MqmPab"=-
    "jaryxnfl"=-
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. crm1975

    crm1975 Private E-2

    Here are the logs. The OTM asked to reboot so I let and when it logged in in normal mode, it rebooted again right away. So I logged in in Safe mode and got the logs to attach.

    Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not making any sense at all. The log from OTM is stating that the items are not being found but the current logs you attach are showing the same old stuff which just does not agree nor make sense. Are you performing a System Restore or is your system automatically reconfiguring itself back to a previous setting after you run my fixes? That is what it looks like the only answer would be as to why things keep reappearing.
     
  16. crm1975

    crm1975 Private E-2

    When the OTM ran, it asked me to Reboot, I let it and it booted into normal mode. After 5 seconds it rebooted itself again so I hit F8 to go into Safe mode w/Networking. As soon as that happend, I ran the Scan only on the Analyse.exe and those 5 lines were back. I didn't fix anything, I just wanted to see if they came back. Then I sent you the logs on the forum.

    I can only think that the OTM deleted the records but when the machine reboots, somehow it is getting added back in somehow.

    I have not run anything else.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. OTM said they do not exist. The below is what OTM stated.
    Please run MSconfig and look in the Startup tab for each of the items we have been trying to remove with analyse.exe. Disable any that you find. Once you have disabled them. Immediately run C:\MGtools\GetLogs.bat and then attach the new C:\MGlogs.zip file.

    Then reboot your PC and see if it will run in Normal Boot Mode.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note that it appears that you have your Virtual Memory settings too low as I see the below file being created which normally should not be created:
    Code:
    "C:\Windows\System32\"
    temppf.sys    Apr 10 2011   268435456  "temppf.sys"
    
    You should fix this as stated in the below:

    http://support.microsoft.com/?kbid=257758
     
  19. crm1975

    crm1975 Private E-2

    I found Combofix.exe in the Startup. I unchecked it and re-ran the MGLOGS. I will fix the memory issue and reboot in a minute
     

    Attached Files:

  20. crm1975

    crm1975 Private E-2

    I rebooted the machine into normal mode and it is still doing the same thing, rebooting after 5 seconds..

    Was I suppose to run the Analyse.exe and fix those 5 lines again now that I unchecked Combofix.exe in the "startup" before exiting? At this time I have rebooted and had to go into Safe mode and Combofix.Exe is checked again.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you do not see the other ones listed below
     
  22. crm1975

    crm1975 Private E-2

    O4 - HKLM\..\RunOnce: [combofix] "C:\ComboFix\CF5956.cfxxe" /c "C:\ComboFix\C.bat"

    That is the only one I found. The Combofix.exe was not in there, neither were the other 3.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then do the below:

    Uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
    Now if you have not fix the Virtual Memory, do that now and then reboot. See if normal mode works.

    Get a new MGlogs.zip file and attach it ( from whatever mode you can run in ).
     
  24. crm1975

    crm1975 Private E-2

    I had unistalled Combo fix back on 4/6/11, after I accidentally ran it. I had just typed combofix /u when i did it originally and I don't think I ran it as admin. I know I didn't have the userprofile option in there.

    Now when I try to run the command you gave, that folder no longer exists
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save combofix.exe to your Desktop. Then run the uninstall with my instructions.
     
  26. crm1975

    crm1975 Private E-2

    Ok, Combofix deleted fine. I followed the link for the virtual size but there wasn't anything for Vista so I set the values on the bad machine equal to the values I have on MY working machine, but that is XP.

    Those settings are Custom Size, 1152MB Initial Size and Max 2304MB
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not bet setting them. You should allow Windows to control them for best performance.
     
  28. crm1975

    crm1975 Private E-2

    when I go in there it gives me an error saying

    "windows created a temporary paging file on your computer because of a problem that occurred with your paging file configuration when you started your computer. the total paging file size for all disk drives may be somewhat larger than the size you specified"

    It said this before too, but I had just clicked by it. Every time I reboot it does still popup the System properties window too.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please uninstall Avira and then do the below.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\Morton\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
    C:\Users\Morton\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine
    C:\Users\Morton\Desktop\CFScrip2t.txt
    C:\cleanup.bat
    C:\ComboFix.txt
    C:\mbam-log-2010-09-02 (06-17-25).txt
    C:\rkill.log
    C:\TDSSKiller.2.4.21.0_01.04.2011_21.33.05_log.txt
     
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "HP Software Update"=-
    "combofix"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seem you are having lingering Windows problems not malware problems. Items in your registry that we are removing just keep reappearing because Windows just keeps putting them back due to problems within Windows.

    You may need to try doing a System Restore to a point before your problems began. Next step may be to reinstall. But you can try the instructions in message # 29 first.
     
  31. crm1975

    crm1975 Private E-2

    I am doing your suggestions in post 29 but do you think upgrading to Windows 7 would most likely fix it since it seems to be a Windows error and not Malware anymore?

    My friend was thinking of upgrading soon but wanted to make sure there wasn't any malware/viruses on the machine.
     
  32. crm1975

    crm1975 Private E-2

    Here are the logs after doing step 29.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually I would suggest a clean install of Windows 7! Not an upgrade from Vista if that is possible. I full install disk may be more expensive though but at least he would then have a disk to perform any possibly future repairs that may become necessary due to malware infections or just do to problems within Windows itself.


    The logs still show the items were not removed even though OTM thinks they were. It looks to me like the registry is just locked ( permissions issues of some type within Windows ). And this may even be the cause of the inability to boot into normal mode and run properly. I think that the choice of either repairing Vista, reinstalling Vista, or starting from scratch with Windows 7 are the best next steps. Obvsiously to repair Vista, you would need the boot CD. But you could do a quick reimage from the Factory Recovery Partition on drive D just to quickly get Vista up and running again. Make sure that all necessary backups are performed first since restoring to a factory image does mean the PC will be back to the same state it was when it came out of the box.;)
     
  34. crm1975

    crm1975 Private E-2

    Ok, he actually did get the full Windows 7 disk instead of just the install disk. If I just copy the profile out of C:\users\ to an external hard drive most of his stuff will be saved correct? then I can install Windows 7 over the top of Vista and then copy the profile back, correct?

    Thanks for all your help, I know this was a pain.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Absolutely not.

    You need to backup everything that he needs from anywhere he as saved it. I cannot tell you where that may be but it does not have to be in the C:\users folder. And you would not be able to backup everything in that folder anyway since windows would stop you from copying certain system files. And no you should not install "on top of Vista". You should format the drive and reinstall from scratch. And NO!!!! You cannot copy the C:\Users folder back. You would totally break the Windows 7 installation if you tried that. You need to reinstall all programs that are wanted from scratch. What you can copy back from the backups are things like personal documents, pictures, videos, and other personal files.
     
  36. crm1975

    crm1975 Private E-2

    All right, thanks again for all your time and effort.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds