lsass.exe error with "Restarting in 60 seconds" message

Discussion in 'Malware Help (A Specialist Will Reply)' started by SWario, Oct 24, 2009.

  1. SWario

    SWario Sergeant

    Cousin's laptop got ganked again due to friends installing crap on it (Registry Defender Platinum v5 was present when I started, though MBAM probably removed it). When attempting to boot into Normal Mode, a memory error appears at the XP Welcome Screen followed by an error message stating that lsass.exe has had an error and that Windows will restart in 60 seconds. Safe Mode works, so all the scans have been done from there.

    SUPERAntiSpyware could not be run because it cannot be installed from Safe Mode. Could not uninstall and update Java because the Windows Installer Service could not be accessed in Safe Mode.

    MBAM ran fine.

    ComboFix produced a warning message:
    Avast was not running at the time since I was in Safe Mode, so I'm not sure why that warning was shown. I opened avast anyway to check its settings, and the Resident Protection was set to Disabled. There didn't seem to be a way to back out of ComboFix at that point anyhow, since the only button was "OK", so I clicked "OK". It produced another warning message with no way to exit the program reminding me that the real time scanner was still active, so I uninstalled avast, which prompted a restart, so I restarted. Perhaps you could send a note to the author(s) regarding this?

    Then, I ran ComboFix. It prompted me to install the Recovery Console, to which I said "Yes" though I had the computer disconnected from the Internet (it's in Safe Mode). As per the instructions, "if it fails, let it continue", I let it continue scanning. ComboFix restarted the computer, and I selected Safe mode again. ComboFix completed, and I then followed the "Manually installing the Windows Recovery Console section" instructions, which entailed running ComboFix again, so I did. I saved both ComboFix logs separately.

    RootRepeal ran fine.

    I ran MGTools. While on the step "Getting System Information" a notice appeared stating:
    I clicked "Don't Send". An Application Error for msinfo32.exe appeared regarding a memory instruction unable to be read.

    Finished running scans, now attaching logs.
     

    Attached Files:

  2. SWario

    SWario Sergeant

    And MGLogs.zip. Awaiting further instructions.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By now, you should know better than doing the below:
    C:\_Tools\MG stuff\MGtools.exe

    MGtools.exe belongs in the root folder of the Windows boot drive. Delete the above file.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 13

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. SWario

    SWario Sergeant

    Whoops! Old habits, I suppose. I usually keep all the installers together, and I mistakenly lumped MGTools in there. Deleted.

    Still booting into Safe Mode because I didn't want anything unnecessarily regenerating itself by attempting to boot normally until you had cleared it.

    While running MGTools, the "Getting System Information" step may have failed:
    I clicked "Don't Send". An Application Error for msinfo32.exe appeared regarding a memory instruction unable to be read. I clicked "OK".

    Requested logs are attached. If you'd like me to boot back into Normal Mode for any steps, please let me know.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong approach. We cannot clean your system properly if you continue to do this. You must only boot in safe mode when we ask you to do so. Boot in normal mode and get new logs.
     
  6. SWario

    SWario Sergeant

    Given that I couldn't boot into Normal Mode without a forced restart occuring, I was booting in Safe Mode per the instructions in the Readme. I acknowledge that you're more knowledgeable than I am in Malware Removal (you wrote the guide used here). I figured you'd let me know when to boot back into Normal Mode. As it turns out, you did, and that time is now!

    Back in Normal Mode (IT WORKS!) now to rerun your instructions properly, and things are sluggish to the point of almost unusable, but at least now it lets me in to Normal Mode at all.

    Uninstalled Java 6u13. Reran CFscript.txt on ComboFix. Installed Java 6u16. Reran Ccleaner. Reran C:\MGTools\GetLogs.bat.

    STILL got this error while running GetLogs:
    Clicked "Don't Send". Got the memory/application error for msinfo32.exe. Clicked "OK".

    New logs from Normal Mode are attached. Things are definitely improving. I can boot into Normal Mode without getting the forced restart, and the system is more responsive.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That explains why the log is missing from MGlogs.zip. This is a problem with your Windows installation not malware. You will have to address this in the Software Forum. Perhaps you some underlying Windows issues which are also causing you headaches.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. SWario

    SWario Sergeant

    It's very likely. This machine was a mess when I got it. I can run msinfo32 from Start>Run, but it just comes up as a blank white window. I'll check in with the Software Forum once we're done here.

    Hurray!

    I never did install SAS, due to previously only being able to run in Safe Mode at first. Is that a problem?

    Successfully uninstalled ComboFix. Deleted unneeded installers for tools/updates. I just realized that I hadn't explicitly mentioned: this computer is running Windows XP Professional SP3. Successfully uninstalled HijackThis.

    I did this, though the command prompt window that popped up said something like "Cannot find file specified" before closing the Explorer window I had launched it from and itself. Is that normal?

    According to the instructions in the Readme for "House Cleaning", it is recommended to run CCleaner on all user accounts. There is a Guest account enabled on this computer accessible in Normal Boot Mode. I logged into it to run CCleaner, and some RUNDLL warnings popped up:
    There were also identical warnings for duwohase.dll and kagokane.dll. Is something still running that's looking for these DLLs? I'll wait until hearing back from you until flushing the restore points because:
    Err, after looking up that quote, I realized that you were pointing me to "Step 4: Toggle System Restore" in the Windows XP Cleaning Procedure page, not "Step 3: House Cleaning" in the Readme. No wonder I was confused. My mistake. I hope it's not a problem that I reran CCleaner.

    I'm working on collecting the necessary software outlined in How to Protect yourself from malware! (from a different computer, of course). I think I'll try out the new Comodo Internet Security suite since it seems to have improved. However, I'll wait until we're sure there aren't additional things I need to do before installing the new software.

    Unreleated to this case: the version of Comodo Personal Firewall linked from the "Protect Yourself" page is outdated. I don't think that Comodo offers separate installers for their antivirus/firewall software anymore, but I do believe that their Comodo Internet Security installer offers individual installations of antivirus, firewall, or both.

    Sorry for the long post.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem but you could try it now.

    As long as requested logs are attached, we already know what a PC is running. ;) Without logs we would have to be told.

    Don't know what you mean about an Explorer window being closed. MGclean does not close the Windows Explorer window. It opens up a command prompt window while it is doing its work and then closes the command prompt window. Did the clean up work? Do you still see the MGtools folder and files inside of it? If so, MGclean.bat did not work.

    Actually the final instructions procedure needed to be updated and that was recently done. Last time a major update was made to the READ & RUN ME, step numbers were changed and the old step 3 is now step 6.

    Yes that is an old version of only the firewall which can still be used and works just fine. And it is a significantly smaller download. CIS includes alot of other baggage that some people have trouble bypassing when installing. When the old link for just the firewall is no longer offered at MGs, we will remove that from the procedure. Even this older firewall is much better than the Windows firewall and still provides great protection as does 3 year old version of ZoneAlarm.;) While it is a good idea to update, it is not as critical with a firewall as it is with an AV or AS program. So as long as the firewall was competent to begin with you are in pretty good shape.
     
  10. SWario

    SWario Sergeant

    Installed and ran SAS. It found and quarantined one thing. I've attached the log in case you feel it's important.

    The MGTools folder is gone. Still, it appeared to close the Explorer window that I had open to select the MGclean.bat file. I don't know if MGclean.bat inadvertently caused this, if something else did, or if I accidentally hit the X when moving the mouse (touchpad).

    Ah, makes sense.

    What is the word on those RUNDLL errors on the Limited Account?
    Would removing the Limited Account remove whatever tried to call those DLLs? Or would it be better to determine and remove what caused Windows to look for those DLLs?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It means you have startup entries (O4 lines seen in a HijackThis log) that you need to remove. The files are gone which is why they cannot load but the registry entries are still there.

    You only need to remove the dead startup entries.
     
  12. SWario

    SWario Sergeant

    Alright! I noticed that "View Hidden Files and Folders" was disabled on the Limited Account, so I enabled it. Would MGClean do that?

    I ran CCleaner on the Limited Account, and then I ran its Registry Cleaner. It found the dead startup entries in the registry, so I told it to "fix" (remove) them, and those alerts don't appear anymore.

    For completeness sake, I tried to rerun the Readme on the Limited Account. I ran SAS and MBAM. I'm attaching those logs in case you feel the need to review them, though it seems that everything that was detected was removed successfully (please correct me if I'm wrong, I'm trying to get a sense for how to read these logs).

    ComboFix, RootRepeal, and MGTools would not run, probably because it is a Limited Account. MGTools had lots of "Access is denied" lines in its application window and produced "16-bit MS-DOS Subsystem" errors about:
    Again, presumably because it was run on a Limited Account.

    Things seem much better now. Since you said before that the system was clean and it was time to set up protection for it. I'm going to do the remainder of the software uninstalls/installs on it that it needs and send it back to my cousin.

    Thanks again! I might have more PCs coming in this weekend though. >.<

    If I have comments or questions regarding the Readme process itself (the written instructions or tools) not in relation to a specific computer, should I post them here, in a separate thread, or in a PM?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes both uninstalling ComboFix and running MGclean reset these settings back to Windows default since they also change them to view all when first run.

    Correct.

    You will need to start a thread in the Malware Forum for your questions. We don't answer any technical questions in PMs and in most cases will just delete them as stated in the stickies.
     
  14. SWario

    SWario Sergeant

    Hmm. This machine still exhibits extreme slowness during the first five minutes or so after logging in. Was there anything in the logs to suggest why this might be happening? No processes appear to be spiking in CPU usage, and the memory usage is less than 300MB.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in msg # 7 stated the below
    This is still true and you need to address your issues with Windows. You are not having malware problems anymore. We removed your malware. Your OS has remaining problems. One of the most common reasons for msinfo32 not showing any info is that the Windows Management Instrumentation service (WMI service) is not running and this could mean other serices are not running too.

    You need to work in the Software Forum.
     
  16. SWario

    SWario Sergeant

    Alright then, I'll hop over to the Software Forum and see if they can take a look at what services on this computer are or aren't running and what should be done about those and the msinfo32 issue.
     
  17. SWario

    SWario Sergeant

    Thanks again!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds