"You are about to be logged off" virus help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by hunters, Aug 29, 2012.

  1. hunters

    hunters Private E-2

    Hi there, Upon bootup, I'm getting a windows that states "You are about to be logged off...." and then it does just that. I have run malwarebytes and it removed a bunch of garbage. I have installed Security Essentials and it can't get through a scan because of the constant reboots. Can anyone help please? Thanks for any help. Vista btw.
     
  2. thisisu

    thisisu Malware Consultant

  3. hunters

    hunters Private E-2

    Ok, a little update. I had just did a system restore to a few days ago before I ran those scans. I wasn't getting the "logged out" message yet. As soon as I installed Microsoft Security Essentials and ran a scan, it triggered the "infection" and it started giving me the window and shutting me down. I'm a little concerned that I wont be able to do many fixes as I don't have much time while "in there" before getting the message. And yes, it happens in safe mode as well.
     
  4. thisisu

    thisisu Malware Consultant

    In that case, we must work from a recovery environment.

    http://img827.imageshack.us/img827/1263/frst.gif Please download Farbar Recovery Scan Tool and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. hunters

    hunters Private E-2

    Attached, thanks!!
     

    Attached Files:

  6. hunters

    hunters Private E-2

    And btw, I'm still not getting that message as I have no virus protection scanning to "prompt or reference" it to trigger it. I hope that made some kind of sense. Computer is acting normal right now except of the aforementioned services not running and no virus protection. Thanks again.
     
  7. thisisu

    thisisu Malware Consultant

    Yeah you confused me here, because earlier you said that even while you were in Safe Mode, that MSE was prompting a reboot within a minute before you could do anything. Now you're saying it's running fine :confused

    In any case, we need a bit more information:

    http://img827.imageshack.us/img827/1263/frst.gif Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  8. hunters

    hunters Private E-2

    I'm sorry, that was confusing. After system restore and BEFORE adding virus protection and running a scan, I don't get the message. As soon as I install MSE and it scans, it musty"activate" something or reference the infection causing the message right after boot up. Does that clear anything up?
     
  9. thisisu

    thisisu Malware Consultant

    Yes, thanks for clearing that up. But go ahead and finish the directs using FRST and Search. This way we can fix everything in pretty much one "fix". ;)
     
  10. hunters

    hunters Private E-2

    here you go, thanks.
     

    Attached Files:

  11. thisisu

    thisisu Malware Consultant

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  12. hunters

    hunters Private E-2

    Ok, it is attached. Btw, I've been able to boot up normally just fine. Just haven't installed any protection yet in fear it will prompt that message loop again.
     

    Attached Files:

  13. thisisu

    thisisu Malware Consultant

  14. hunters

    hunters Private E-2

    I still haven't installed any virus or spyware protection because the initial scan is what prompted the error before. You think it's ok to install MSE and scan?
     
  15. hunters

    hunters Private E-2

    Well, I can tell you that something is still wrong with the services. I can't use Windows Update or turn on the security center or get into the firewall.
     
  16. hunters

    hunters Private E-2

    Another update, I've installed MSE, and it gives me an error when trying to download definitions. Can't get an internet connection. However I'm able to go online just fine using browsers. Doing an initial scan now...
     
  17. thisisu

    thisisu Malware Consultant

    Yes this type of malware has the ability to delete certain services by Microsoft. I can get a better idea of what exactly needs to be replaced once you go through the Read and Run Me First.
     
  18. hunters

    hunters Private E-2

    Thanks again for all of your help btw!!

    I should say that MSE is installed and scanned but still can't download new definitions. Attached should be all you requested.
     

    Attached Files:

  19. thisisu

    thisisu Malware Consultant

    Upload this file: C:\Users\gemariah\AppData\Local\Broderbund Software\ApplicationHistory\hdpnqw.dll to VirusTotal. Let me know the results (link me the page).

    Reviewing the rest of your logs now.
     
  20. thisisu

    thisisu Malware Consultant

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 29
    • Uniblue DriverScanner 2009

    __

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Reset Registry Permissions
      • Repair Windows Firewall
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press Scan.
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  21. hunters

    hunters Private E-2

    That folder is empty, no files in it.
     
  22. thisisu

    thisisu Malware Consultant

    RogueKiller may have already quarantined it, we'll find out later. Go ahead and continue with the instructions in the next post.
     
  23. hunters

    hunters Private E-2

    here you go
     

    Attached Files:

    • FSS.txt
      File size:
      3.4 KB
      Views:
      1
  24. thisisu

    thisisu Malware Consultant

    • Download each of the 3 files below onto the desktop of the computer with the issues:
    • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
    • Let me know if you received a successful message for all three files.
      • If all were successful, reboot your computer and rescan with Farbar Service Scanner. Attach its latest log.
      • If they weren't successful, let me know but rescan with Farbar Service Scanner too.
     
  25. hunters

    hunters Private E-2

    Here is the latest
     

    Attached Files:

    • FSS.txt
      File size:
      2.5 KB
      Views:
      3
  26. thisisu

    thisisu Malware Consultant

    You should be able to use Windows Update now. MSE should update too.

    I will create another fix for you to clean up the malware remnants (soon hopefully).
     
  27. hunters

    hunters Private E-2

    I am most impressed thisisu. I'm always in awe of folks like you who can diagnose and provide fixes based on messages and logs in a forum like this. Yes, MSE updates, all of the services that weren't working before are working and I'm updating 41 windows updates. NICE JOB AND THANK YOU! So there are still some remnants?
     
  28. thisisu

    thisisu Malware Consultant

    Thank you. It has taken a lot of practice.

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Coupon Printer for Windows

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:services [/COLOR]
    0200191266462858mcinstcleanup
    Symantec Core LC
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Users\gemariah\AppData\Local\Broderbund Software\ApplicationHistory\hdpnqw.dll
    C:\Users\gemariah\AppData\Roaming\lakerda1967.sys
    C:\Windows\Installer\{45239cb0-9390-a374-4c6e-af723abc5214} /d
    C:\Users\gemariah\AppData\Roaming\ousapc.dll
    C:\Users\gemariah\AppData\Roaming\SpeedyPC Software /d
    C:\Users\gemariah\AppData\Roaming\DriverCure /d
    dir /s C:\ProgramData\F4D561B4002E5E9455EDC395570F1C8B /c
    C:\ProgramData\F4D561B4002E5E9455EDC395570F1C8B /d
    C:\ProgramData\Driver Whiz /d
    C:\ProgramData\Driver Whiz(4) /d
    C:\WINDOWS\Tasks\SpeedyPC*.job /d
    C:\ProgramData\PC Drivers HeadQuarters /d
    C:\ProgramData\SpeedyPC Software /d
    C:\Users\gemariah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum /d
    [COLOR="DarkRed"]:reg[/COLOR]
    [-HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}]
    [-HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AE6CB148-7769-449C-B5D3-E8C3446CC209}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "startup"=dword:00000000
    [COLOR="DarkRed"]:commands[/COLOR]
    [clearallrestorepoints]
    [emptyjava]
    [emptyflash]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)
     
  29. hunters

    hunters Private E-2

    here it is
     

    Attached Files:

  30. hunters

    hunters Private E-2

    Also, is it ok to install Spybot and immunize and run a scan and remove what it finds? Thanks again
     
  31. thisisu

    thisisu Malware Consultant

    Yes, but do that after you have completed the below set of cleanup instructions:

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  32. hunters

    hunters Private E-2

    Thanks again Thisisu. You were a huge help!
     
  33. thisisu

    thisisu Malware Consultant

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds