Can't even make it through RUN ME FIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by lweigler, Sep 30, 2010.

  1. lweigler

    lweigler Private E-2

    Hi Major Geeks!

    I need you guys to come to the rescue again as you always do! Tim helped me recently on a machine and it was a quick and successful experience. Thank you very much!

    This time I'm working on my church's computer. I'm really struggling to with this one. I'm trying to make it through the read me and run me first thread but I cannot even get through that one. The computer won't let me. I can't do a normal startup b/c everything has the computer so bogged down that I can't do anything!!! I try running the tools to clean it and either the browser prohibits me from going to the appropriate website to get the tools or like SuperAntiSpyware, I got it downloaded and installed, but I go to run the scan and after it starts the computer shuts the program down. I need help please.

    I'm usually easy to deal with doing all the prereqs etc... but this time I am not getting very far with them. Where should I start?? Thanks guys!!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try using safe mode when needed instead of normal mode to get the scans run and we'll see what gives. Let me know how it's going.
     
  3. lweigler

    lweigler Private E-2

    Kestrel, thanks for the help. I'm currently at work so I'll have to wait till I get home to try this again. I will tell you that I was trying to run superantispyware from Safe mode and it was still getting closed right after I started it. I'll do everything that I can. Like I said, I cannot dl malwarebytes bc the browser won't let me even go to alot of sites, that being one of them.

    I'll try this again as soon as I get home. Thanks again. Everyone on here is always so patient and helpful!
     
  4. lweigler

    lweigler Private E-2

    Okay... I'm in safe mode. I have downloaded tools/apps and their updates via another pc and moved them over with my thumb drive.

    The problem is that everytime I got to run any of them, the scan starts and then the is shut down shortly after :( (even in safe mode). I have yet to successfully complete any of the first processes of cleaning. Please help.
    Thanks in advance.
     
  5. lweigler

    lweigler Private E-2

    Alright.. I pretty much can't run anything. I've tried everything but the second I try to run it just shuts down. The only thing I've been able to do is MGtools. I hope this can start us somewhere.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then:
    Now run the C:\MGtools.exe file by double clicking on it. (Agree to the Trend Micro Hijack this license this time round) Then attach the new C:\MGlogs.zip file that will be created by running this.


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  7. lweigler

    lweigler Private E-2

    Alright,
    I was able to do everything but the SAS scan. I downloaded it and when I began the scan it only ran for about 20 seconds. It found Trojan.Downloader-Heltrans or something like that. Right after it finds that the whole app just closes. I tried running it a few times with the same result. :(
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now rename combofix.exe to 123.com. If you are not able to run it in normal mode then please try safe mode again. Attach the C:\combofix.txt into your next reply if successful.
     
  9. lweigler

    lweigler Private E-2

    Okay... here's what happened when I attempted to run combofix. Something crazy is going on. This has happened for the 3rd time now. The computer is now in a viscious cycle of rebooting.

    I tried running combofix and the loading bar for combofix came up... but then after it showed loaded nothing happened. So, after giving it a chance to run I decided to reboot into safe mode. This time when I rebooted it was in the viscious reboot cycle. It loads up to the point where the windows login screen would come up then it reboots. If I disable the autorestart on system failure, I get the blue screen with this message.

    c000021a fatal system error - windows logon process system process terminated unexpectedly with a status of 0xc0000022

    Like I said, this has happened 2 other times in the last couple of days.... after researching the only way I could seem to get it to stop doing this and actually boot up (it won't even boot in safemode), I would have to put in the original windows disk and do a windows repair(reinstalling the operating system). I don't want to reformat this computer.

    Hopefully this information helps you... please advise with our next step. In the meantime I have just shut the computer off as it would just keep rebooting. Thanks!!!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think you will be better off asking about this in the software forum, and then once you are back up and running again you can return here.
     
  11. lweigler

    lweigler Private E-2

    Thanks... I have moved to the Software forum... when we're going again.. I'll post back. I apprecite your help!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries. :) Best of luck getting your problems sorted out.
     
  13. lweigler

    lweigler Private E-2

    Time for an update!

    Okay, I've since been in the software forum and they've sent me back this way. By the way, thank you for your patience. Hopefully you haven't used it all b/c you'll probably still need some with this one. I've about broken this computer a couple of times by now, haha. But yet I STILL haven't given up.

    It seems that the only way I've been able to recover from the reboot cycle is repair the OS. Thats kind of annoying b/c it takes 1/2 hr every time.

    I have made progress. At first I couldn't get anything running. I still can't run SuperAntiSpyware. Not even in SafeMode. It starts scanning and something closes it shortly after with no notification. I've now managed to get a couple things to actually scan the computer. I've attached mbam logs. Mbam thinks we're clean. I've also succesfully ran the eSet Online scan. It cleaned a few items as well. I can run MGTools but I'm not confident that its running correctly.

    I feel like I'm making progress and but then i'll reboot and I'll be back in the reboot cyce. However, everytime that I recover from that, I seem to get a little bit further. I hope I can provide SOMETHING that helps! Oh yeah, something else I've noticed... not sure if this has anything to do with it.. but it seems when I run combofix and then it reboots, it goes into the reboot cycle. I THINK that combofix finishes running though.

    I'll post what I have an be anxiously awaiting your guidance/opinion. Thank you very much.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach this log:

    C:\ComboFix.txt
     
  15. lweigler

    lweigler Private E-2

    Sorry about that... here it is. I just reran it.
     

    Attached Files:

  16. lweigler

    lweigler Private E-2

    Alright... I think I'm clean. Here are the logs.
     

    Attached Files:

  17. lweigler

    lweigler Private E-2

    And the RootRepeal.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There was no need to run Rootrepeal, combofix and MBAm again. Please only run things as I request.

    c:\windows\myClean.bat <--- Use windows explorer to find and delete that file.

    Navigate to C:\MGTools\analyse.exe and double click it to run (right click and run as admin if using vista or win7) Do a system scan onmly and save a log file to attach for my reviewal.

    What actual malware problems are you having now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds