Help with Win XP Cleaning

Discussion in 'Malware Help (A Specialist Will Reply)' started by mannshands, May 22, 2009.

  1. mannshands

    mannshands Private First Class

    Hi,
    Big problem using cleaning method. Running XP pro on HP Pavillion dv5000, 1000mb RAM.
    Laptop was working but crashing every 2 hours or when doing 2 things at once, like surfing while dl'ing a movie. Followed all instructions exactly. BTW this required stopping all startup progs and removing powerup and win passwords to allow proper reboots as required. Might want to add this ti the instructions.
    I got thru SAS, MBAM and CF. Took alot of renaming files to get MBAM installed. Saved all logs. Then tried MG Tools. Got error-Process Dll.exe. Installed NET. Ran MG. Computer crashed quickly. Now I can't reboot. Tried everything but keep going to chkdsk/restart loop. Tried all modes:last good config, safe, ect, but just goes back to chkdsk/reboot loop. Tried to use my CD with miniXP to break in and retrieve logs but can't get into BIOS setup anymore to change boot order and banging on space bar at boot only brings up the ISOLINUX title of the miniXP CD, but none of the progs on the cd.
    Got to recovery console but it asked for a password. I never use the console so have no password for it. Tried the passwords I had eliminated from BIOS and WIN, as well as blank password. Nope. After 3 tries it shut down.
    So what do i do now? I can't even get the bootable cd with reformat tools to start so I can't wipe the HDD and start fresh. That was my last resort.
    Thanks for any help
    mannshands
     
  2. mannshands

    mannshands Private First Class

    Re: Help with Win XP Cleaning, more info

    Luckily i kept a few notes.
    SAS found 1 bug:trojan horse generic 13 ARXS in recycler
    MB found 7 trojan.DNS changers and 1 Spyware.Passwords and 1 Rogue Installer, all in win temp or sys 32 files.
    Hope that helps. Cheers.
    mannshands
    ps: gonna try a live linux cd to see if i can get logs out that way
     
  3. mannshands

    mannshands Private First Class

    Re: Help with Win XP Cleaning. Saga cont.

    OK. Got an old Mandrake Live cd to boot but cannot find a way into my HDD.
    Then I managed to get Hiren's bood disc of utilities to boot up. But miniXP produced this error
    \HBCD\XP.CA_ Cannot load, error 7
    The other tools don't load proper and may produce a msg:NOT READY-C:\hbcd\UHARCD.EXE. If you are familiar with this collection of tools, is there any that will help retrieve logs or get XP to boot up if I do manage to open them?
    Last ditch effort will be tonight when I can get to my Linux Live CD collection and see if Ubuntu or LinuxMint, etc will run.
    Sorry for the multiple posts. Just adding info as I get it to help solve this issue.
    THX
    mannshands
     
    Last edited: May 22, 2009
  4. mannshands

    mannshands Private First Class

    Can't get LinuxLive cds to access the HDD!
    Did manage to get into the BIOS. HDD tests passed and all passwords Blank. I cannot use the recovery console that I had to dl as part of the install of the cleaner progs(CF or MGTools I think). Evidently I didn't have a recovery console previously installed. It requests an "admin password". I have no passwords set in either BIOS or XP users.
    Also: CombiFix removed 2 files mid-scan and prompted me to write their names down
    "in case you need them later".
    C:\windows\system32\drivers\gxvxcxvkowftacxovbrspmnsvfaxvnmevpieo.sys
    C:\windows\system32\gxvxcberxriknvxbfhwseninjttminutfqrje.dll
    Are these critical? Can I dl/reinstall them from somewhere?
    Patiently awaiting your response...Again sorry for multiple posts, but you do request all pertinent info,
    Cheers
    mannshands
     
  5. mannshands

    mannshands Private First Class

    Found the recovery password. Opened recovery console. I get to command line C:
    Now how do I do the recovery?
    THX
    mannshands
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most frequently, problems like this are hardware related. Possibly heat or a hard disk or memory problem.

    Don't need to since this is not necessary.

    You needed to attach them as requested however I see from the below that your system crashed before you got to doing this.

    MGtools does not really remove anything of significance. It just removes a few minor malware files if found and resets a few registry keys to normal defaults to work around potential issues where malware has disabled things like Task Manger, RegEdit...etc. Everything else that it does is just information collecting. Thus it is unlikely that running MGtools caused any kind of crash.

    It is possibly that if you do have malware, that it finally just got to a point where things hit the breaking point. There are quite a few new forms of malware that are infecting necessary Windows system files and eventually these infections can cause quite unpredictable problems.

    This again sounds like a hard disk issue as mentioned above.

    Again sounds like a hardware issue if you cannot access the BIOS.

    The password it is looking for is the password for the Administrator user account. Note this is the account actually named Administrator, not an account that just has administrator priviledges. You need to know this password since it is your PC. If you put one in (which is dangerous since malware could change it to anything it wants) then it should be blank. If you cannot figure out what the password is, you will need to use another PC to create the disk mentioned in the below and reset the password to blank. Only reset it to blank with this tool. Trying to set it to something other than blank frequently fails.

    http://home.eunet.no/~pnordahl/ntpasswd/


    However, I'm not sure what good getting to the Recovery Console is going to do since you are not getting error messages about missing operating system files. As stated above, sounds more like a possible disk crash of some kind.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are malware files not system files. Removing these was necessary. The act of removing these has never cause a crash like you are mentioning where chkdsk constantly runs.

    Have you tried running chkdsk /r from the Recovery Console?

    See the below for more info on the Recovery Console

    http://support.microsoft.com/kb/314058
     
  8. mannshands

    mannshands Private First Class

    Re: Got the logs off HDD!

    Hi.
    Running in Safe mode resulted in a freeze up at mup.sys; got a proceedure from AITechSolutions.net. that repaired the reg. Now XP (and BIOS)opens normally. So back to the beginning again. Uninstalled MG and CombiFix since they started popping up msgs frequently while I was simply surfing. I still get an error msg that CF cannot find a certain file and has to quit, again while surfing, not doing maintenence work. How to stop it?
    Here are the logs I now have access to. Have to include 5 logs so Will use another post for 5th.
    Also, I suspect the malware is in sys restore. 6 weeks ago I got a bug that wiped all but my latest restore point. I used AVG/SAS/MBAM/Avira/Conflicker tools to sort that out and thought it was gone.
    As far as hardware, can you suggest a test for that? I have Hirens Tools cd. I pass the Phoenix HDD self test, both modes. Advanced Sys Care RAM monitor rarely shows less than 50% free RAM. How do I test RAM?
    Thanks for the help,
    mannshands
     

    Attached Files:

  9. mannshands

    mannshands Private First Class

    Re: another log

    Here is MGTools log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Got the logs off HDD!

    It did not finish running properly so we will need to manually cleanup after it.

    Questiions like this should be posted in the Hardware Forum but you can check out the software available for downloading in the below links:

    http://www.majorgeeks.com/downloads7.html

    http://www.majorgeeks.com/downloads26.html

    Why do you have all of those port open in your firewall for Akamai NetSession Interface. Did you install something related to this? IS it part of this program? C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe See: http://www.akamai.com/html/misc/akamai_client/netsession_interface_faq.html

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\Common Files\BinarySense\hlAPP.dll" (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 28, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds