Malware logs me out of Windows in 10 minutes

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by afarrelltx, Sep 23, 2015.

  1. afarrelltx

    afarrelltx Private E-2

    I am trying to remove malware for a BSOD 777 error but some malware pops up a warning that windows will log me out in 10 minutes. I am unable to complete the Malware Bytes scan before the laptop shuts down. Please advise how I can stop the auto shut down.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to run the instructions in safe mode?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also unplug your Ethernet cable to disconnect from the internet while running scans. If you are using wireless then disable the wireless interface to remain disconnected while running scans.
     
  4. afarrelltx

    afarrelltx Private E-2

    OK, thanks for the reply. I am not sure which instructions Kestrel13 was referring to. I will disable the Wifi and try again.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. afarrelltx

    afarrelltx Private E-2

    Disconnecting the Wifi worked. It made it through the Malware Byte scan and found 1252 threats. I will proceed with the process.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent :)
     
  8. afarrelltx

    afarrelltx Private E-2

    I have completed scans and laptop is running fine except it cannot connect to the proxy server I use. I think Malware Bytes disabled it. I am not sure how to reset it.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, afarrelltx

    You need to attach the logs for Kestrel13! to be able to help you.
     
  10. afarrelltx

    afarrelltx Private E-2

    I finished scans but the problem is as bad or worse. I will attach logs.
    Thanks for your help.
    AF
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I see you ARE deliberately set up to use a proxy ;) I don't think Malware Bytes broke it, I still see signs of it in the logs.

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-4090598029-1852220028-499445824-1005\Software\Microsoft\Windows\CurrentVersion\Run | DV : C:\ProgramData\DataFile\DV.exe [-] -> Found
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-4090598029-1852220028-499445824-1005\Software\Microsoft\Windows\CurrentVersion\Run | DV : C:\ProgramData\DataFile\DV.exe [-] -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aWNCiENXrL ("C:\ProgramData\AVpfeh\aWNCiENXrL.exe") -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UdvdPork ("C:\ProgramData\1441845648\s9.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windowsmanagementservice ("C:\Users\Administrator Andy\AppData\Local\Temp\20150910\ct.exe" /svc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aWNCiENXrL ("C:\ProgramData\AVpfeh\aWNCiENXrL.exe") -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UdvdPork ("C:\ProgramData\1441845648\s9.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\windowsmanagementservice ("C:\Users\Administrator Andy\AppData\Local\Temp\20150910\ct.exe" /svc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aWNCiENXrL ("C:\ProgramData\AVpfeh\aWNCiENXrL.exe") -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\UdvdPork ("C:\ProgramData\1441845648\s9.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\windowsmanagementservice ("C:\Users\Administrator Andy\AppData\Local\Temp\20150910\ct.exe" /svc) -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for ALL of the entries on the Tasks tab please.....

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Re run Malware Bytes, have it fix anything it finds. Attach log if it does.
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  13. afarrelltx

    afarrelltx Private E-2

    I have completed the process but still get the virus warnings and windows is going to log me off. I have attached the logs. I am also still unable to get my proxy set up. Thanks Kestrel13 for your patience and help.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;)

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  15. afarrelltx

    afarrelltx Private E-2

    OK, I ran the FarBar scan and logs are attached.
    Regards,
    AF
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller please and attach log.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
     

    Attached Files:

  18. afarrelltx

    afarrelltx Private E-2

    I ran the tools as instructed and have attached the logs.

    Thanks,
    AF
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running?
     
  20. afarrelltx

    afarrelltx Private E-2

    Things seemed to be running better, but in the last session getting online, I got the BSOD and the warning about being logged off in 10 minutes. Did you see anything in the logs? Thanks again for you patience and persistence with issue.
    AF
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is it an actual BSOD or is it a pop up that is done in BSOD style?


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Also re run Malware Bytes and have it fix anything it finds
     
  22. afarrelltx

    afarrelltx Private E-2

    It is a pop up window BSOD code 777 with the scam phone # to call the Indian guy in San Fransisco who can help with rescuing my laptop for a fee. He told me of two options and said he could send my diagnostics to the help sites. I can press ALT F4 to close the pop-up window. The small warning window pops up to let me know windows will be shutting down in 10 minutes at --:-- am/pm. If I stay on that long, windows shuts down. I can start up again with the same results unless I shut off the Wifi. This all started when I tried to download free map updates for my TomTom gps. Hope this is helpful. I will run ADWcleaner and MB when I get home.
    Thanks,
    AF
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this a fake warning which is not really a BSOD. It may be necessary to reset your browsers ( all installed browsers ) to defaults in order to remove an unwanted browser extension that can be causing this. Kestrel13! can help you with this. You should back up all settings, bookmarks/favorites first.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  25. afarrelltx

    afarrelltx Private E-2

    OK, thanks. I reset the browsers, ran ADW and MB and have attached the logs.
    AF
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And how are things running now?
     
  27. afarrelltx

    afarrelltx Private E-2

    I am now having difficulty getting on the internet due to the proxy server settings. In one of the profiles I get limited access on IE. Chrome and Palemoon cannot connect and I shut off the proxy setting, but still no luck. Thank you for any insight you can provide.
    AF
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But Windows is not logging out in 10 minutes anymore?
     
  29. afarrelltx

    afarrelltx Private E-2

    Correct, and I don't get the pop-up BSOD scam. I tried to shut off the proxy but it did not help.
    Thanks,
    AF
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I suggest you post in the software forum about that. :)

    Ready for final steps?
     
  31. afarrelltx

    afarrelltx Private E-2

    I am not sure. I am concerned that some steps I did to delete the proxy may have caused more problems and since I cannot connect to the internet, I am not sure the malware or Trojan is gone. The system worked OK with the Wifi off. How can I verify if the malware is gone? I turned on the windows security and it warned me it had to clean off something. Let me know what I should do.
    Thanks,
    AF
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go through all the steps in the Read and Run Me First again and I will check all of the logs.
     
  33. afarrelltx

    afarrelltx Private E-2

    OK, I have tried to run the tools from the Read & Run Me First and the Win 7 cleaning procedure. I am unable to run Malwarebytes due to some missing file. I tried to download and re-install it but without success due to a missing file. I am able to get on the internet via IE only, Palemoon and Chrome cannot connect due to the proxy server which I have tried to turn off in both browsers. While online I have not seen the scam BSOD or Win shut down in 10. What do you recommend I do next? Thanks again for your patience and persistence. AF
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I thought you were deliberately set up to use a proxy??
     
  35. afarrelltx

    afarrelltx Private E-2

    Yes, I have been running some accountability software, X3Watch, but I uninstalled it and have tried to run without it until I get this malware issue resolved. Windows keeps trying to install it but I cancel the install. I hope this helps. AF
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the Read and Run me first again with it installed if necessary.
     
  37. afarrelltx

    afarrelltx Private E-2

    I tried reinstalling x3Watch but still cannot get on internet except with admin account and IE.
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And why is it that you are unable to run the below again?
    • Malware Bytes
    • Hitman Pro
    • RogueKiller
    • MGTools
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The user account that scans have been getting run on/posted for was

    USERNAME=Administrator Andy

    If you have other user accounts that have problems, you need to run scans on those user accounts so we can see how they are configured. So exactly which user account has problems?? Is it the only restricted user account that I see that begins with the name Andy?
     
  40. afarrelltx

    afarrelltx Private E-2

    Kestrel13! I can run Hitman, RogueKiller and MGTools but MalwareBytes is gone and I cannot reinstall it. When I run the setup application I get an error window that says " Setup, Runtime error (at 85:137) could not call proc." So, I have not been able to run MB for a while.

    Chas, On the admin account I can use internet only with IE. Palemoon and Chrome will not connect due to the proxy server. On the account that starts with Andy, I cannot connect to internet at all. I have run scans on both accounts. Please advise as to what I can do next, since I cannot use MB at this point. Thanks for your patience and persistence. I have not seen the BSOD nor windows logging me out, so I feel like we are making progress.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Palemoon and Chrome ( backup and favorites/bookmarks and settings first ). Then make sure you delete all folders related to them in all locations ( like in user folders, program files....etc ). Make sure you have deleted all folders for both browsers before continuing or what we are trying to do will not work. For example, delete all
    the below and there could be others ( I don't remember how/where Palemoon installs )

    C:\Users\Administrator Andy\AppData\Local\Google\Chrome
    C:\Users\Andyfarrell\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome
    C:\Users\Administrator Andy\AppData\Roaming\Mozilla
    C:\Program Files (x86)\Mozilla Firefox

    Then reboot and then reinstall just Chrome and see if it works.

    Scans have to be run while logged into only this account. To get proper operation you will have to temporarily give this account admin permissions. Logs for this account need to be attached.

    Don't worry about Malwarebytes right now at all.
     
    Last edited: Oct 15, 2015
  42. afarrelltx

    afarrelltx Private E-2

    Thanks Chas,
    I deleted Palemoon and Chrome but could not reinstall Chrome. I got and error message during the install that a firewall was not allowing the install. Please advise. Thanks, AF
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First question:
    • Is Palemoon working now?
    Second question:
    • Can you tell me the exact word for word error message you receive while trying to install Chrome?
    And then please disable your Windows firewall temporarily and see if you can get Chrome to install.
     
  44. afarrelltx

    afarrelltx Private E-2

    Chas,
    Thanks. Palemoon is working.
    When I try to run the Chrome setup, it says it is connecting to the internet but then gives me an error message that it cannot connect to the internet, shut off firewall or whitelist chrome setup exe file. I did both but get the same error.

    AF
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure this is an issue we can help you with as it does not seem to be related to malware. But let's check a couple more things.

    First uninstall Chrome again if any part of it is still installed. Also check again to make sure the below folders are deleted.

    C:\Users\Administrator Andy\AppData\Local\Google\Chrome
    C:\Users\Andyfarrell\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome


    Now run a new scan with FRST and attach a new log.

    Also run the below.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  46. afarrelltx

    afarrelltx Private E-2

    Thanks Chas,
    Palemoon is working normally. I cannot install Chrome, during setup it says it cannot connect to the internet, even thought I am connected and running Palemoon.
    Also, while windows boots up I have been getting an error message from Skype, so I uninstalled it and tried to reinstall it but got the same error message and it is: "Cannot Load the DLL(DNSAPI.dll)!"
    I have attached the FRST and OTL logs.

    AF
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are a few more left overs to cleanup and I also noticed one other important fact and that is that you are missing an necessary Windows file which can be causing some problems. We need to look for a replacement on your PC. A newer version of MGtools exists that looks for a replacement file that we can use in a subsequent fix.

    So please download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista, Win7, or Win8, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below logs:
    • C:\MGlogs.zip

    After I get this new log, I will create your next fix.
     
  48. afarrelltx

    afarrelltx Private E-2

    Chas,
    Thanks again for your patience. I ran MGTools and have a attached the MG logs. Please advise on next steps.

    AF
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
     
  50. afarrelltx

    afarrelltx Private E-2

    Thanks Chas,
    It seems like we are getting close to being back on track. I ran the scans and have attached the logs.

    Andy
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds