Major issue with constant logon/logoff

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimbo720, Feb 24, 2009.

  1. jimbo720

    jimbo720 Private E-2

    I am having an issue with my desktop PC. I will try to make this post quick. I am running win xp home sp 2. Every time I log on it says, loading personal settings and it logs right off. So I tried running the recovery console and to get the userinit.exe file from the windows disc to no avail. I’ve also tried starting in safe mode, the last good configuration, and repairing the windows installation. I booted to the cd and tried repairing windows and nothing so far has been able to defeat this constant logon/logoff issue. I am looking for options as I am sure there’s something else I could do. I am pretty sure I have some malware and to think I was using Norton 360 v2 and it didn’t prevent any of this makes me sick. I have about 100 GB of data on my computer that is irreplaceable. Pictures of the kids, etc. What am I missing? Your help is greatly appreciated. Thanks, Jim.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jimbo720

    jimbo720 Private E-2

    Tim I just had a thought. I wonder if this will work. If I used my other pc and took the hard drive out of the infected PC and made it slave and ran the various anti-malware software programs to rid it of the corrupt files. Is there anything you could think of that would prevent that from working?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....that could be a very good solution, if the system files are not damaged ....try to get me as many of the requested logs as you can.
     
  5. jimbo720

    jimbo720 Private E-2

    Thanks. I was able to utilize my other PC and ran most the malware apps. I had an issue with MGtools as it didn't produce a zip file. I guess that's because the infected hard drive isn't running windows to identify the issues. I attached the other logs. Thanks in advance for your help.
     

    Attached Files:

  6. jimbo720

    jimbo720 Private E-2

    I checked my for the mglog.zip one more time and the zip file is attached.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much left in your logs. We can fix a few things, but then you need to put it back and try booting again.

    Did you have MGTools on the C:\ drive of this hard drive? It did not produce a log.

    You can use windows explorer to find and delete:
    c:\windows\system32\SET1D.tmp
    c:\windows\system32\SETE.tmp
    c:\windows\system32\SETC.tmp
    c:\windows\system32\SET17.tmp
    c:\windows\system32\SET1F.tmp
    c:\windows\system32\SET1B.tmp
    c:\windows\system32\SETF.tmp
    c:\windows\system32\SET24.tmp
    c:\windows\system32\SET16.tmp
    c:\windows\system32\SET15.tmp

    But none of that is the cause of your problems.

    Let me know what happens when you try to boot it up.
     
  8. jimbo720

    jimbo720 Private E-2

    I tried rebooting again but the looping issues are still occurring. At this point, I am going to move the essential files from the slave to an external drive I have and then reimage the hard drive. I appreciate your help. Thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ComboFix and MGtools scans need to be run after booting Windows on the infected drive otherwise they are of no use. SUPERAntiSpyware and Malwarebytes can be told to scan the slave drive which can be useful but it is still not as useful as when they are run after booting the infected version of Windows.

    If you have not reimaged yet, first look on the slave drive in the C:\Windows\System32 folder and see if the userinit.exe file exists and if it does, what is the exact file size in bytes and what is the date and time of creation. If it does not exist, try putting a copy there from your other PC.
     
  10. jimbo720

    jimbo720 Private E-2

    So I took your advice before reimaging and I didn't reimage at this point. The userinit.exe wasn't present on the slave so I copied it from the master. I put the infected hard drive back in the other pc and it booted up. It took a little while but after about 4 mins, the desktop screen appeared.

    An error message appeared which said there was an error loading c:\windows\system32\caitauuo.dll, that specific module could not be found.

    I was able to run the malware apps and I have attached the logs. I appreciate all your help. Thanks.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well....that is certainly better.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    c:\windows\System32\drivers\ccdecodee.sys
    C:\WINDOWS\UmFzaGVk

    Nowre-run Combo and then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and the combo log.
     
  12. jimbo720

    jimbo720 Private E-2

    Thanks again. I followed the instructions as closely as possible. I attached the logs. I couldn't disable norton 360 from running. I tried shutting down the processes in the task manager but they kept reappearing.

    -I completed the first notepad task
    -I completed the HJT task
    -I completed the regedit task as well. With regards to the regedit task, I did receive a message stating c:/document ....fixME.reg has been successfully entered into the registry.
    -I completed the deletion of the two files
    -I ran combo fix
    -When running GetLogs.bat, I got an error message stating "The application failed to initialize properly (0x0000135). Click OK to terminate application.

    Thanks again for helping through this. Is there anything else I need to complete.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'd ask you to download new versions of Combo and MGTools........but your logs are clean.:)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  14. jimbo720

    jimbo720 Private E-2

    So I downloaded a new combofix and mgtools. I attached the logs for analysis. There is a scanner running in the background stating it detected some suspicious hosts were trying to connect to the internet. The services were bs-serving-sys.com; spe.atmdt.com; edge.quantserve.com; and speed.pointroll.com. Have you ever heard of these services and are they disguises for malware? I checked online but the information I discovered was sketchy at best. Thanks for your help.
     

    Attached Files:

  15. jimbo720

    jimbo720 Private E-2

    I also noticed the copy/paste doesn't work using the mouse, I have to use the keyboard and it doesn't function constantly and my screen is going to a blank white screen. I press ctl + alt + del to bring it out and that works. Thanks again.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  17. jimbo720

    jimbo720 Private E-2

    The scanner that is running in the background is a-squared. I got it for free with a one year subscription. I have a firewall installed but I have to reset the rules. Thanks for all your help. I am on to protecting my PC from malware. Thanks for everything. This was an interesting and fruitful experience.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know...and you are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds