Major problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rebuked, Feb 21, 2014.

  1. Rebuked

    Rebuked Private E-2

    I'll do my best to describe all of my problems and attach the appropriate logs in the right order and type. I have 5.
    My problem began about 6 to 8 months ago. The computer would not boot up. The Windows screen would run but, then the login screen would never show up. The screen would just stay blank. So we would have to shut the computer down manually and start over again. We found that unplugging the keyboard helped initially. Whether or not that had anything to do with the problem? I havent a clue. Lately, even the screen that displays options to use safe mode doesnt display. We sometimes have to reboot manually up to 20 times until we can log on.
    So here are my logs.

    Thank you in advance :wave
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. :)

    Are you purposely set up to use a proxy?
     
  3. Rebuked

    Rebuked Private E-2

    Dont know anything about it.
     
  4. Rebuked

    Rebuked Private E-2

    Thank you for answering my post, I greatly appreciate it. We have been using this provider for awhile. It was set up 6 years ago or so. I havent made any recent changes to the internet connection/ server etc. I wouldnt know how.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=192.168.1.1:80 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman and have it delete everything it finds.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix exit HJT.


    Delete these folders:

    • C:\Documents and Settings\Brooks Repair\Local Settings\Application Data\MarketBrowser Data
    • C:\Documents and Settings\Brooks Repair\Application Data\MyTurboPC.com
    • C:\Documents and Settings\Brooks Repair\Application Data\SparkTrust
    • C:\Documents and Settings\All Users\Application Data\MyTurboPC.com
    • C:\Documents and Settings\All Users\Application Data\SparkTrust


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. Rebuked

    Rebuked Private E-2

    Good Morning Kestrel,
    Again, Thank you for looking at problems and trying to diagnose some solutions.

    Would you like the defogger on or off?
    I am having problems with Internet connections (very slow or nonexistent in normal mode) also this morning, hopefully it will last until I get through the steps.
    Things are freezing up on me.
    I will make a copy of your instructions on Word so I have them just in case.
    Hopefully this will post.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. You can try running the steps in safe mode with networking if normal mode is proving to be too problematic.
     
  8. Rebuked

    Rebuked Private E-2

    Yes, running in safe mode with networking this may take a few days to post. :tas:tas:tas:tas:tas
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'll be here floating around. :)
     
  10. Rebuked

    Rebuked Private E-2

    ran RK
    deleted the proxy server.
    got RK report
    rebooted
    ran Hitman deleted finds
    ran MGtools deleted 06's
    deleted folders in documents and settings
    ran junkware tools for text.
    ran MG tools for MGlogs.zip

    quite the experience.
    many problems encountered in safe mode.
    main problem seems to be Internet Explorer.
    for some strange reason IE is extreamly slow.
    Chrome is normal.
    I think I picked up some other problems along the way using IE.
    see what you think
    :duck
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach the requested logs and I will let you know. ;) Thanks.
     
  12. Rebuked

    Rebuked Private E-2

    So sorry for the delay here.
    I tried to post them but was having other difficulties. Calving time is starting up here in the north woods and weve had some other problems, pulling a few cattle up out of the creek.
    Anyways, would have posted them this morning but now comp is make very strange sound.
    Power supply was just replaced and sounds like it isn't working right. only chance to communicate is from here at work.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh I hope everything works out. When and if you get chance, do post back and keep me updated. :)
     
  14. Rebuked

    Rebuked Private E-2

    I made it back. loose connection. cattle are alive.
    Also,
    I have no administrator privileges? In safe mode with networking administrator privileges so I tryed to reset. ie. Start- accessories-run as- command prompt- right click-the following user:- Administrator (no password)
    C:\WINDOWS\system32\cmd.exe
    This service cannot be started in Safe Mode
    Any way to bypass this as I can not get into regular boot up?
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode as previously requested. Thanks. If you have issues doing this you must tell me.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Documents and Settings\All Users\AIa00676
    C:\WINDOWS\system32\drivers\hikkmjsq.sys
    C:\WINDOWS\system32\drivers\iooqhgkt.sys
    C:\WINDOWS\system32\drivers\ipltsiel.sys
    C:\WINDOWS\system32\drivers\jnavwvvv.sys
    C:\WINDOWS\system32\drivers\ovedzmjp.sys
    C:\WINDOWS\system32\drivers\pmooefuk.sys
    C:\WINDOWS\system32\drivers\qdiofirx.sys
    C:\WINDOWS\system32\drivers\rqtnrqxu.sys
    C:\WINDOWS\system32\drivers\rxnnnevn.sys
    C:\WINDOWS\system32\drivers\toruqamg.sys
    C:\WINDOWS\system32\drivers\ujidhmpd.sys
    C:\WINDOWS\system32\drivers\xhlhvekq.sys
    C:\WINDOWS\system32\drivers\xnxphvqu.sys
    C:\WINDOWS\system32\drivers\zxrvrngc.sys
    
    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "AlcxMonitor"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  16. Rebuked

    Rebuked Private E-2

    Thank you for your assistance with my computer.
    I had no problem downloading and following all of the instructions. But, I assumed the OldTimer would have the text available in the program on reboot to copy and paste. Unfortunately, I can not find access or locate it anywhere. da on my part. I know you need it and had important info. I apologize because it may cause a diagnostic breach.:(
    I do have the MGlogs. zip however.
    Computer did not boot up in normal mode. So, I am using Safe Mode with networking.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This has NOTHING to do with me asking you to use MSCONFIG and putting this machine back into normal start up mode. Don't confuse the two.

    The logs look good, (But then I need to see them from normal mode!) :) what malware issues are you still having at this point in time?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds