MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 01-16-09, 16:27
Aroma Aroma is offline
Private E-2
 
Join Date: Jan 2009
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Question Can't boot in normal mode - Malware removal Safe Mode?

I'm new to this forum and not a very sophisticated user, but help would be appreciated. I am running Windows XP (Build 2600.xpsp_sp2_gdr.080814-1233: Service Pack2). My computer froze and I had to hold power button to shut down. Shortly before I froze a window popped open to tell me that windows security firewall had been changed to off. I switched it back to on, but then the computer froze up a few minutes later. When I try to boot in normal mode I can log-in, but about 3 seconds after I see my desktop the screen goes black and I need to hold the power button down to turn off. I am only able to boot in safe mode. I have run spybot and adaware in safe mode and they find 'Virtumonde'. Spybot also finds 'MicrosoftWindowsSecurityCenter_disabled'. I correct/fix these problems in the software, but when I reboot nothing has changed and when I run them again (in safe mode) they find the exact same problems.

I tried following the directions on 'Read and Run me First', but don't get far because I can only boot in safe mode... I can't use the program uninstall that is part of the control panel to get rid of the Java updates of which I have a few - this seems to be because I am in safe mode. Also, it sounds like steps 2 and 3 also require to be booted in normal mode. Is it possible to complete 'read and run me first' in safe mode?

Any advice on how to proceed from here would be appreciated. thank you.
Reply With Quote
Sponsored links
  #2  
Old 01-16-09, 18:44
Aroma Aroma is offline
Private E-2
 
Join Date: Jan 2009
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

I decided to finish running the scans that were suggested in Safe Mode with the exception of Super AntiSpyware which I could not install in safe mode. After completing, I was able to boot in normal mode and so far it is working. I have attached the logs for you to look at and let me know if there are any other fixes I should undertake. Thanks for a great site!
Attached Files
File Type: zip MGlogs.zip (56.3 KB, 3 views)
File Type: txt ComboFix.txt (11.8 KB, 5 views)
File Type: txt mbam-log-2009-01-16 (13-55-32).txt (3.9 KB, 5 views)
Reply With Quote
  #3  
Old 01-17-09, 22:03
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,435
Thanks: 62
Thanked 7,679 Times in 4,142 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

Welcome to Major Geeks!

Quote:
Originally Posted by Aroma View Post
I decided to finish running the scans that were suggested in Safe Mode with the exception of Super AntiSpyware which I could not install in safe mode. After completing, I was able to boot in normal mode and so far it is working. I have attached the logs for you to look at and let me know if there are any other fixes I should undertake.
Yes now that you can boot in normal mode, you need to install SUPERAntiSpyware and run it as requested. Then attach the log from it.

Also do the below.

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


Uninstall the below old versions of software:
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Spybot - Search & Destroy 1.4


Now we need to use ComboFix
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::

Driver::
dimvbiow
File::
C:\WINDOWS\system32\kkbbyu.dll
c:\windows\system32\drivers\rymrxbsj.sys
c:\windows\Tasks\ctsvflra.job

DirLooK::
C:\BEES40e

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Now run Ccleaner!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


Then attach the below logs:
  • the SUPERAntiSpyware log
  • C:\ComboFix.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter

Last edited by chaslang; 01-17-09 at 22:11..
Reply With Quote
  #4  
Old 01-20-09, 14:21
Aroma Aroma is offline
Private E-2
 
Join Date: Jan 2009
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

I have completed the steps you outlined and attached the logs. Please note that the only difference is that before I got your response I had already removed Java updates and Spybot 1.4 and installed recommended current version of JAVA, so I did not repeat this step. System seems to be working fine after a few hours on it. Let me know if there is anything else I should follow up on. Thank you!
Attached Files
File Type: txt SASlog.txt (989 Bytes, 1 views)
File Type: txt ComboFix.txt (33.8 KB, 2 views)
File Type: zip MGlogs.zip (55.0 KB, 1 views)
Reply With Quote
  #5  
Old 01-22-09, 09:15
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,435
Thanks: 62
Thanked 7,679 Times in 4,142 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

You're welcome.

According to your new logs, a couple of things did not get completely fixed. Let's try the below procedure.


Now we need to use ComboFix again.
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::
Driver::
rymrxbsj
dimvbiow

File::
c:\windows\system32\drivers\rymrxbsj.sys
c:\windows\dimvbiow

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


Now run Ccleaner!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:
  • C:\ComboFix.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Sponsored links
  #6  
Old 01-27-09, 13:29
Aroma Aroma is offline
Private E-2
 
Join Date: Jan 2009
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

See attached logs. System seems to be working normally. Again, thanks for your help.
Attached Files
File Type: zip MGlogs.zip (55.0 KB, 2 views)
File Type: txt ComboFix.txt (13.0 KB, 3 views)
Reply With Quote
  #7  
Old 01-29-09, 00:25
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,435
Thanks: 62
Thanked 7,679 Times in 4,142 Posts
Default Re: Can't boot in normal mode - Malware removal Safe Mode?

You're logs are clean.


If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /u
      • Notes: The space between the combofix" and the /u, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    • Delete the C:\combofix folder from combofix (if it exists)
  3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  5. Go to add/remove programs and uninstall HijackThis.
  6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
  7. If you are running Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  8. After doing the above, you should work thru the below link:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't boot into normal mode, only safe mode. Infected kathinpdx Malware Removal 1 12-05-08 00:48
cannot boot XP in safe mode or normal m3i0x3 Software 1 04-09-08 22:56
malware can't be found in safe mode and the system shuts off in normal mode barononeefdip Malware Removal 5 08-25-07 12:19
can not boot to safe mode or normal mode help!! mattinsocal8911 Malware Removal 11 09-18-06 02:10
Can't Boot - Normal or Safe Mode netzach Malware Removal 1 10-22-05 15:56


All times are GMT -5. The time now is 03:12.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger