Stuck in Safe Mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by marvinbarcelona, Jan 17, 2007.

  1. marvinbarcelona

    marvinbarcelona Private E-2

    A couple of days ago I re-started by PC and got this Blue Screen of Death;

    Bad Pool Caller

    Stop: 0x000000c2 (0x00000007, 0x00000cd4,0x15FFF87D, 0xB024B713)

    m_hook.sys - Address B024B713

    base at B02413000, date stamp 45a4e3d8

    This happen a couple of times, and each time the pc went into Windows normally, it lasted five minutes and then went into the above again.

    Since then, I've only been able to work in Safe Mode with networking.

    I've run all the tests for viruses, worms etc listed in some of the threads on this site, and everything is coming up clean.

    I'm on Windows XP Media with SP2

    Any help would be appreciated. Of course, if there's anymore information you require, please let me know, but be aware, I really do have limited knowledge on pretty much anything to do with pc's (I acknowledge there is a thing called 'the registry', but don't what it does or where it is.....thats how basic I am).
     
  2. theefool

    theefool Geekified

  3. Wavetar

    Wavetar Sergeant

    At first I was leaning towards a driver or hardware issue, as BSOD stop codes generally point to that, but if you search google for "m_hook.sys", all information leads to a virus/trojan/rootkit infection.

    You should try scanning with a specialized rootkit detector software, such as you can find here on Majorgeeks:

    http://www.majorgeeks.com/RootKit_Hook_Analyzer_d5021.html

    http://www.majorgeeks.com/Rootkit_Revealer_d4652.html

    Also, I've had great success with superantispyware for getting rid of tough malware that others have problems with:

    http://www.majorgeeks.com/SUPERAntiSpyware_d5116.html
     
  4. theefool

    theefool Geekified

    Odd, I thought I stated that this pointed to malware. ;)

    But, good posts. I'd rather let the malware geeks handle this one thought. :)
     
  5. marvinbarcelona

    marvinbarcelona Private E-2

    Thanks guys.

    I did follow the Malware Removal guide, but came up with nothing. I'll do them again and post the logs. (as recommended etc)

    The software recommended in this thread won't load while I'm in Safe Mode.

    I'll post back when I've gone through the Malware Removal Guide again.

    Thanks once again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Yes, when you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis


    Anything that you cannot do in safe mode, just use Normal Boot mode.

    Also please run this Sophos Anti-Rootkit and then attach a log from it too!
     
  7. marvinbarcelona

    marvinbarcelona Private E-2

    I've tried to find the answer, but I have to ask: what is normal boot mode and how do I get there? I'm already in Safe mode.

    Again, sorry to be thick.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is rather simple! Just don't boot in safe mode. That is normal boot mode.

    In additional per the READ & RUN ME, make sure you are also not using MSconfig to disable any startups. This is called Normal Startup. Don't confuse it with Normal Boot mode. You could be in normal boot mode but not be in normal startup. See Step 0 of the READ ME where this is explained.

    Your infections is part of a Trojan.Rootserv
     
  9. marvinbarcelona

    marvinbarcelona Private E-2

    I don't think I was making myself clear (sorry), but when I say that I'm stuck in Safe Mode, I mean I cannot get into anything else but Safe Mode.

    I start up the pc, it gets to the "Windows XP" screen, tries to load, screen goes blank and it begins again, only this time it goes to the screen that offers me a choice of boot modes. If I again choose normal boot mode it tries to load, screen goes blank etc.

    The other modes work, including the ones that involve the command line (correct?).

    So, unless there is something that I've missed (and I went through the Read and Run Me sticky very carefully), some of the programs listed here advise that they only work in normal mode and not Safe mode.

    I hope this clears some things up. As I said, I really am an innocent when it comes to pc's and their workings.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that explains it better!

    Which scans from the Read & Run Me are you able to run?
    • did you run CCleaner?
    • did you run Spybot?
    • did you run CounterSpy or AVG Antispyware? If so can you attach the log or are you saying absolutely nothing was found?
    • did you run BitDefender? If so can you attach the log or are you saying absolutely nothing was found?
    • did you run PandaActiveScan? If so can you attach the log or are you saying absolutely nothing was found?
    • since you cannot boot in Normal Mode, it is okay to run GetRunKey, ShowNew, and HijackThis from safe mode. So do this and attach the 3 logs to your next message.
    • also please download and try to run the below procedure and attach the log from it:
     
  11. marvinbarcelona

    marvinbarcelona Private E-2

    Heres the reports that i have. Unfortunately Panda Scan doesn't like me and won't run.

    All the scans are showing normal amount spyware crap that you usually get, but nothing out of the ordinary. I've run everything recommended, well everything that would run.

    There is something called MySearch Assistant that won't budge from my PC, but I've checked and it appears relatively harmless.

    Guys, I really need to get this PC out of Safe Mode and back into normal. Your help is much appreciated.
     

    Attached Files:

  12. marvinbarcelona

    marvinbarcelona Private E-2

    Oh, and I've got this from somewhere to.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please give me the info I requested:

    1) The log from GetRunKey
    2) The log from ShowNew
    3) the log from Sophos AntiRootkit

    You have a rootkit problem! Normal scans are not going to show anything.

    You did not even install and rename HijackThis properly per the directions in the READ ME. Please follow those instructions so that we can help you.

    After you get HijackThis installed and renamed per step 7 of the READ ME, continue on to the below.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to VXYCQNVAC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteVXYCQNVAC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - (no file)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Simon\Local Settings\Temp\
    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  14. marvinbarcelona

    marvinbarcelona Private E-2

    Here's the logs. I've followed your instructions to the letter. There are a couple of issues;

    1. I still cannot re-boot into normal mode. The issues outlined previously still exists

    2. Sophos AntiRootkit will not run as I get a message stating that it will not run in Safe Mode.

    I hope this helps, I really do....otherwise the pc goes out the window!

    Thanks for your help and patience.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the below tool will run:

    AVG Anti-Rootkit

    Attach a log!

    Uninstall the below malware:
    MyWay Search Assistant
    PC MightyMax v9
    Viewpoint Media Player

    You have another malware service to stop, disable and delete.!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to LW
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteLW into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Now attach the below new logs:
    • AVG Anti-rootkit log
    • ShowNew
    • HJT
     
  16. marvinbarcelona

    marvinbarcelona Private E-2

    Very quick note;

    1. I've deleted LW as recommended
    2. AVG Anti-Rootkit won't run. It keeps telling me to re-start my pc first. I do this and the same message appears.
    3. MyWay Search Assistant won't delete, it says it can't in Safe Mode - the others I've removed.

    I'll post HJT and Shownew when I get home from work.

    Thanks for your help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this: Restoring SeDebugPrivilege then try again. If it still does not work, try the below!

    Download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.


    Don't forget the HJT and Shownew logs.
     
  18. marvinbarcelona

    marvinbarcelona Private E-2

    I downloaded and ran SeDebug, and it advised I had been "granting SeDebug privilege to Administrators" and then advises me to reboot. I do and I can still only get into Safe mode.

    I also tried Backlight Beta, but that told me it wouldn't run while I was in Safe Mode.

    I've attached the new reports from Shownew and HJT as requested.

    How long can I keep this pc in Safe Mode?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but did you retry AVG Anti-Rootkit after doing this.

    For ever, but is that what you really meant to ask? Obviously you don't want to remain in safe mode. It's strange that you can only boot in Safe Mode. Normally this trojan does the opposite. It usually delete a registry key that is needed in order to allow you to boot in safe mode. They do that to make it more difficult to fix the problem.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy the quoted bold print below and paste it in the box that opens from Avenger:
    Now click the 'Done' button.
    Click on the traffic light icon and OK the prompt.
    You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it.
    A log file from Avenger will be produced at C:\avenger.txt, please post that log here in your next reply.


    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  20. marvinbarcelona

    marvinbarcelona Private E-2

    1. AVG Anti-Rootkit still won't run. It just keeps advising to reboot.

    2. I asked about running in Safe Mode because I was concerned it might cause problems running it for prolonged periods.

    3. Did the fixMe and The Avenger.

    4. Everything is still the same: the same start-up process, the same refusal to boot into normal mode.

    5. The programs you asked me to remove are still there and won't budge.

    6. I did manage to get Sophos to run. Well sort of: It wouldn't run "Process Scan", and gave the following message - "Could not initialize kernal driver mem.sweep.sys. Can not run in Safe Mode."

    The other two scans completed (Reg Scan and Disk Scan), but advised nothing found. The program didn't offer the chance to save any logs.

    Question: Am I missing something that won't let me boot in normal mode? Is there some program or part of one that's missing?



    Here's the new logs.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What programs?


    I need the log from Avenger!


    Some additional new malware showed up. Let's see if we can fix it.
    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [ahymerno] C:\ypftcjev.bat
    O4 - HKLM\..\Run: [nvaerhov] C:\wwhydtjj.bat

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\wwhydtjj.bat
    C:\ypftcjev.bat
    C:\zip.exe
    C:\WINDOWS\system32\drivers\fnxfdkjf.sys
    C:\WINDOWS\system32\drivers\spbuxqfl.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!


    Do you have other user accounts on this PC?
    • If so, can you boot in normal mode on the other user accounts.
    • If not, create a new user account. Now see if you can boot in normal mode on this new account.
     
    Last edited: Jan 28, 2007
  22. marvinbarcelona

    marvinbarcelona Private E-2

    Chaslang, thanks for all your help on this issue. I know I can be alittle annoying at times (on account of I generally don't know what the hell I'm doing). I've had to re-install Windows as I really needed my PC working proporly.

    However, I have gone over this site and downloaded some of the recommended software that will hopefully keep my PC safe in future. I've also printed off some of the guides you have here on the site (mainly to remind me not to be an idiot with PC security).

    Again, thanks very much. We may not have solved my problem, but I have learnt an awful lot from going through it, an awful lot from yourself and other folks here.

    Thanks again.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds