Major Problem - Now can't Log on!

Discussion in 'Malware Help (A Specialist Will Reply)' started by AndyM, Dec 9, 2007.

  1. AndyM

    AndyM Private E-2

    Hope you can help me!

    Last weekend, I followed your instructions from "Read & Run Me First" through to "Windows XP Cleaning Procedure" but ran out of time to contact you.

    Today, I went to startup my computer and initially got a blue screen Windows XP - CHKDSK screen. Windows corrected a problem in my file system and my normal Windows "Log On Box" appeared. I hit <enter> and it proceeded to "Loading your personal settings"-> "Logging Off" -> "Saving your personal settings" -> back to the "Log On Box". I then chose the shutdown option and restarted the computer interrupting with the F8 key to get to the SAFE MODE setting. When I hit OK at the "LOG On Box" the start, log off, save cycle repeated itself.

    Fortunately, I brought my laptop home from work and am able to communicate with you!

    What can I do now?

    Thanks,
    AndyM
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you saying that since you ran the READ & RUN ME a week ago, you have never boot this PC again until today? Meaning you did not use it at since running the READ ME? Nothing in the READ ME should cause an issue like this, what you are reporting is something that indicates, a possible loss of the c:\windows\system32\userinit.exe file or the registry key setting for it. Another choice is possible registry corruption. At this point, you are really in the wrong forum. This is now an issue for the Software Forum.

    Which service pack (SP) level were you running on this PC and do you have the Windows XP bootable CD for this SP? If not, what do you have? Just System Recovery CDs?

    You may be looking at a reinstall unless you have your Windows XP CD so you can get to the Recover Console to try a few things. Again this would be in the Software Forum.

    Sometimes a procedure like below is necessary to recover from possible registry corruption:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  3. AndyM

    AndyM Private E-2

    Thanks for your response and I can understand why you want this issue in the Software forum.

    I did not mean to insinuate that your instructions caused me any problems. They did not. I did reboot after running the protocols, and found that the malware was still resident in my machine.

    The mistake I probably made was in not toggling my Restore function back on after I was done. It was the next time that I attempted to boot up that I encountered the looping startup/shutdown.

    Yesterday, I did remember to try my Windows XP CD and was successful in re-establishing access and some semblance of normalcy but it was too late for me to try running the protocols again. I will try them this evening when I get home.

    I also reviewed your recommendation for the removal of Smitfraud which is what appears to be the most problematical of the spyware that has gotten into my machine. I will probably try this iif another cleaning doesn't do the trick.

    If not, I'll be sending you another email with Logs attached.

    Thanks for being here for us!
    AndyM
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only because of what you had described as an inability to truly boot up and log in. What you described is a problem that indicates an issue with Windows itself? If you cannot boot and get logged in, there is not much we can do for you related to malware removal. What we would have been working on would be trying to help resolved your boot problems which is something that can more easily be performed in the Software Forum. Thus that is why I was saying it belongs in the Software Forum.

    What did you do to get past your problem?

    If you can boot up and login, then you can run the READ & RUN ME and attach all of the required logs. We will then be able to access your malware status.
     
    Last edited: Dec 11, 2007
  5. AndyM

    AndyM Private E-2

    Thanks!

    Managed to get back on last night and I re-ran the "Read & Run Me First" protocols. However, I still have the Black desktop background with the red message "Warning! Spyware threat has been detected on your PC"...etc., etc. I'm sure there is more in the background, too!

    I am attaching the three Logs for your review.

    Hope you can help!

    AndyM
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to start by running AVG Antispyware again and this time don't ignore what it is finding. Have it Quarantine all the problems it finds. There is no sense in running the scans if you are not going to fix what they find.

    Is your copy of Spyware Doctor a paid version or a free trial? If free trial, uninstall it now as it is not of any real use.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
    O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
    O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
    O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06a81954e1a6fc20e815/netzip/RdxIE2.cab
    O21 - SSODL: E404Helper - {a4213046-8b85-4ab6-b685-51a4c4a7f75d} - e404d.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. AndyM

    AndyM Private E-2

    Thanks, Tim -

    I got back on this evening and completed your instructions. I have attached the two new logs that you requested.

    My computer is running much better now, however, I am still getting the Black Desktop Bacground with the red lettered "Warning! Spyware threat has been detected on your PC.", ... etc.

    Please let me know if there is more you can suggest or if I did anything wrong?

    AndyM

    View attachment MGlogs.zip

    View attachment Avenger.txt
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who's Tim? ;)


    Your Desktop may be locked. Try the below.


    Fixing Locked Desktop
    • Right click on your Desktop and select Properties.
    • Then click the Desktop tab
    • then click the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
      • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK.
    • Click Apply. And click OK.


    Any change?
     
  9. AndyM

    AndyM Private E-2

    Thanks, again -

    My desktop was not locked. After I sent my logs to you last evening, I realized that windows saves my settings each time it shuts down, so I re-established my original desktop just before I shutdown last night and voila! When I botted up today, my original desktop was there! :)

    I'm assuming that the last logs showed that I am spyware-free?

    AndyM
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your logs were clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds