Login screen failure

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lagrima, Nov 11, 2009.

  1. Lagrima

    Lagrima Private E-2

    Hi all.

    Since afternoon today, my desktop computer with Windows XP won't start normally. I get to the login screen, but after typing my password, it just hangs (it doesn't even bother to check whether the password is right). I suspect it must be malware.

    It starts fine in Safe Mode, and when I use Diagnostic Startup with msconfig, but neither of those gives me network connection. As far as I can see, there are no files lost.

    When looking in Event Viewer, there were a few suspect errors earlier today, just when I started it.

    I ran CCleaner, and removed/fixed everything it wanted to.

    I ran Malwarebytes, and it actually found a three things, which I removed:

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Minimal\SVCWINSPOOL (Backdoor.IRCBot) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Network\SVCWINSPOOL (Backdoor.IRCBot) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\msvcrt2.dll (Trojan.Donbot) -> Quarantined and deleted successfully.

    These things were deleted from the quarantine, and according to Malwarebytes, my computer is clean.

    SuperAntiSpyware says "The system admininstrator has set policies to prevent this installation".

    gmer.exe (which has helped me before) says "gmer.exe has encountered a problem and needs to close." But for some reason, I can't get gmer.exe to run on this laptop either. I suppose there must have been some Windows update that prevents it from running.

    What more can I try?
     
  2. Lagrima

    Lagrima Private E-2

    And here are the suspected records in Event Viewer. They haven't occurred since. They occured after starting the computer today. Around lunch I turned it off, and after that the problem occured. There error occurred four times with the message

    The X service failed to start due to the following error:
    The system cannot find the file specified.

    where X is one of

    adfs
    mzho
    cmplrkyx
    fezp

    I suppose these strings are auto-generated, so it's hard to tell what malware this is.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  4. Lagrima

    Lagrima Private E-2

    Thank you! :)

    First, I'm a bit concerned that I can't start in normal mode, so everything I do below, I do in Safe Mode. Maybe the malware can't be found if I'm in Safe Mode? What do you think?

    Logs attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are more than 350 database versions out of date with Malwarebytes. Please run it and first select Update and get the new database installed. Then run a new scan and attach the log.

    Your logs are clean so I'm not sure that you are having malware problems. But I do suggest that you delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Gustaf\Local Settings\Temp


    Also see if you can run ComboFix as given in this procedure: http://forums.majorgeeks.com/showthread.php?t=139313
     
  6. Lagrima

    Lagrima Private E-2

    Thank you, Chaslang.

    My problems where all solved by making a Windows XP repair from the CD. I never thought the programs links would still work, but the only things I needed to update was Windows itself.

    I had wanted to update Malwarebytes, but since I had to do everything in Safe Mode, I had no Internet connection. I downloaded the latest version from the Internet and transferred it to the sick computer on a USB stick, but apparently that one wasn't updated either.

    I'm still annoyed I couldn't find out what it was. The symptoms were

    * Freeze after typing password on login screen
    * Paste function disabled in Explorer
    * Slow performance in Safe Mode

    I googled paste disabled and found it's used by malware sometimes. That is really EVIL, because it prevents you from backing up important files (unless you're smart enough to use Send To instead :p).
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds