Computer only starts in safe-mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by GoldFishKilla, Oct 1, 2005.

  1. GoldFishKilla

    GoldFishKilla Private E-2

    I clicked on the AIM instant message that downlaods the virus then sends out the links to everyone on the buddy list. After getting it i managed to run spy-bot, adware, and symantec antivirus. I dont remmember if i did it in safe mode or in the regular mode. But my problem now is that I've run the programs in safe-mode and they dont show anything on my computer, but when i turn on my computer it starts normally goes to the windows xp page then flashes a blue page for about a second then restarts. Then it goes to the page where i can select: Safe-mode, Safe-mode with network, Safe-mode with command prompt, restart with last known good configuration. So i was hoping that you guys could help me figure out how i can get it so that it will start up normally again, thanks a lot for the help.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. GoldFishKilla

    GoldFishKilla Private E-2

    I ran all of the scans, when I ran the online BitDefender scan it came up with TrojanDownloader.CZR and deleted it, and it found Win32.worm.Oscarbot.B and deleted it. CWShredder found VX2.look2me it removed it, and CWS.ms.config and removed it. The other scans didn’t find anything. And here is the hijackthis log.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Make sure you have done the following:
    How to view hidden, system files & folders!
    Searching for Hidden Files on WinXP

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    REBOOT to Safe Mode

    Open Windows Explorer and navigate to C:\WINDOWS\System32 and DELETE windir32.exe.

    REBOOT to Normal Mode. Run HijackThis and Post a fresh log as an attachment.
     
  5. GoldFishKilla

    GoldFishKilla Private E-2

    When i do this step

    In HJT Choose Open the Misc Tools Section choose Process Manager

    I see:

    C:\WINDOWS\system32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsas.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\program Files\Internet Explorer\iexplore.exe
    C:\Spyware Tools\hijackthis\HijackThis.exe

    I don't see windir32.exe

    should i just proceed with the other steps?
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If it's not there then just proceed with the rest of the steps.
     
  7. GoldFishKilla

    GoldFishKilla Private E-2

    I went through the last step and fixed everything you told me to. Then restarted in safe-mode and searched for the file in the C:\WINDOWS\System32 folder but i couldnt find it, i ran a search for it and found this :WINDIR32.EXE.17f8AEA6.pf in C:\Windows\Preftech
    After that i tried to restart in normal mode and it still failed.
    And heres the newest hijackthis log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below in your log:

    O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe

    Did you have HJT fix that line and did you find c:\windows\system32\windir32.exe and delete it?

    You should also do the below:
    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so. We will reboot later.
     
  9. GoldFishKilla

    GoldFishKilla Private E-2

    Alright i took care of: O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe

    I still cant find windir32.exe in the folder c:\windows\system32

    I disabled CWShredder and deleted it with hijack this. And did not reboot.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay try rebooting now! See if normal boot mode will work.

    Either way, attach a new HJT log.
     
  11. GoldFishKilla

    GoldFishKilla Private E-2

    It didnt reboot normally but heres the new log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! Load the below file into notepad and copy and paste it into your next message.

    c:\boot.ini
     
  13. GoldFishKilla

    GoldFishKilla Private E-2

    Aorry about this, but what do you mean by "load the bellow file"?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what notepad is and how to run it?

    If so, just run it and click File, Open and then browse to c:\boot.ini and select it.
     
  15. GoldFishKilla

    GoldFishKilla Private E-2

    Here it is, I think, and I must say I'm very impressed with how your taking care of several people simultaneously.

    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I stepped out for a bit (snack time).

    That looks okay. Are there any error messages at all? Do you get to the point where you see the user accounts screen?

    Do you have your bootable WinXP CD?
     
  17. GoldFishKilla

    GoldFishKilla Private E-2

    When the computer boots up it gets to the XP Screen with the black background and the green dots that move across the screen uner the XP symbol, before it reaches the accounts, and then it flashes a blue page with white writing on it real fast and then restarts at the motherboards screen. I don’t have my bootable WinXP CD, I'm at college and ill have to go home to get it.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it is not a WinXP SP2 disk it will not be of much use anymore since you are on SP2. Is it WinXP SP2?

    You may need to do a Windows repair or at a mininum a registry repair. Your problem does not seem to be malware. It may be better to work this problem in the Software Forum. You may need to run something like in the below:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  19. GoldFishKilla

    GoldFishKilla Private E-2

    Its from about a year and a half ago, so I dont think that its a WinXPSP2 CD. I'll take a look at that thread and make a posting in the software section with a link to this thread. Thanks a lot for the help in getting all the help up till now I really appreciate it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If Shadow_Puter_Dude was around tonight, he would have walked you thru all this too. If you post in the Software Forum, he may even pick up where this left off. But check out that link from Microsoft it may become necessary to do that. Make sure you read the Summary and Warnings in that link too.
     
    Last edited: Oct 8, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds