System hangs on both boot and shutdown

Discussion in 'Malware Help (A Specialist Will Reply)' started by netzach, Jul 30, 2006.

  1. netzach

    netzach Private E-2

    Windows XP Pro, Service Pack Two. Symptoms:

    1) Boot process gets as far as displaying the wallpaper, but not to the point where it shows desktop icons or taskbar.

    2) Task Manager can be launched from that point, minimizing it puts it into the lower left-hand corner of the screen and shows just the blue part at the top of the screen.

    3) Anything that uses Windows Explorer ends up showing the "flashlight" icon swinging back and forth but gets no further.

    4) Anything that uses a .msi to install (Windows Defender, for example) hangs at the "Preparing to Install" note. See #3. If you hit cancel at that point it displays "Cancelling." but gets no further.

    5) There are three SVCHOST.EXE entries in the Processes list. If I kill the one that shows 4,096K memory usage, (occasionally 4,196K) the icons pop, the very bottom of the taskbar appears at the top of the screen and everything appears fine - for a couple of minutes. Then the system informs informs me it must shut down due to the failure of a RPC. It tries to shutdown, but hangs there, too.

    6) Booting in Safe Mode yields roughly the same results.

    7) Running Spybot S&D from a CD (couldn't install it directly, see #4) informs me that I have some variant of Zlob - doesn't say which one. It can't fully fix the system - three items unresolved - asks if I want to run on restart. That never happens, as it hangs shutting down, and whatever mechanism it uses to run S&D on restart never happens.

    8) I suspect that any changes to the Registry never get actually written to disk. See #7.

    9) Running "tasklist" from a command prompt also hangs.

    Any ideas? Short of a Wipe and reload, that is?


    bestRegards, Guy.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you boot up/shutdown okay from Safe Mode?

    Zlob is part of the SmitFraud family of infections. See if you can run the below which does not reqire any programs to be installed but you must download and run some tools.

    SpywareQuake & SpyFalcon Removal Procedure

    Attach the Smitfiles.txt log afterwards.

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  3. netzach

    netzach Private E-2

    Hiya, chaslang! Thanks for taking the time to respond!

    ___chaslang___
    Can you boot up/shutdown okay from Safe Mode?
    ---------------
    Kinda, sorta. I can get there, but have no taskbar. Not sure how to get to "Add/Remove Programs" in Control Panel without a Start button.


    ___chaslang___
    Zlob is part of the SmitFraud family of infections. See if you can
    run the below which does not reqire any programs to be installed
    but you must download and run some tools.
    ----------------
    Didn't know that! Great. This might be more tricky than I originally thought. :mad:

    Will the tools work without the Add/Remove Programs step in the instructions?


    bestRegards, Guy.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried running explorer.exe from Task Manager? Click File, New Task (Run..) and enter explorer.exe and click OK! See if that works and brings up a Desktop.


    You don't need to do anything wirh Add/Remove Programs to run the SpywareQuake procedure or the other two steps.
     
  5. netzach

    netzach Private E-2

    Doesn't bring up a desktop - but gives me a second "EXPLORER.EXE" entry in the Processes list. Neither one seems to be doing anything.

    I was just trying to be thorough. The Removal procedure says to make sure we have followed the "view system files and hidden folders" procedure - which requires a working explorer.exe to my way of thinking. Sixth bullet-point has us going to Add/Remove programs. I looked through the list of DLLs and EXEs using attrib from the CLI - "attrib" will list 'em even if they're system or hidden files - but none were present.

    Out of curiosity - is there any way to get to the control panel from the CLI (of File->Run->New Task in the Task Manager)???


    bestRegards, Guy.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you are correct! I forgot about that part. Just ignore it for now and continue. I really need to see the smitfiles.txt log and the two other logs I requested. We are not going to get very far until you get those logs posted.



    Out of curiosity - is there any way to get to the control panel from the CLI (of File->Run->New Task in the Task Manager)???[/quote] Yes! Just have it run APPWIZ.CPL and if that is not found try the full path C:\windows\system32\APPWIZ.CPL
     
  7. netzach

    netzach Private E-2

    One additional piece of information - just found this out from the gentleman who owns the computer - this problem started two days after he updated his Macaffee subscription. Do not know if this is relevant.


    bestRegards, Guy
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it!

    I still need the logs requested in message # 2 or I cannot help you any further!
     
  9. netzach

    netzach Private E-2

    Finally got the logs - but it was costly! No floppy, no USB support for thumbdrives, etc, no writeable optical media, no internet connection, no shares on the LAN.

    So I yanked the drive and took it to another client that uses SATA drives. Figured disk to disk copy would work. It did, but now /that/ computer is infected!

    bestRegards, Guy.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But were the procedures run and the logs created when the drive was in your PC? And then afterwards you just used the other PC to get the log files to upload?

    If you ran the procedures on the other (new PC), it is of no use in diagnosing your PCs problems.

    You still have SpyFalcon problems! Did you run this SpywareQuake & SpyFalcon Removal Procedure completely and did you run it before the other two logs were obtained.


    You can start a new thread to work on the new PC if it is infected. Make sure you indicate in the new thread that this is a second PC. Run the READ ME on this new PC.
     
  11. netzach

    netzach Private E-2

    Exactly. I ran it on the infected PC - exactly as it was written up in the procedure (except for the "show all files" and "add/remove programs" bits - we already discussed that) Then took that hard disk, with the three logs, over to the other system for copyting.

    Yes. My guess is that because the system's hanging on SHUTDOWN - the only way to reboot is kill the power - the registry changes aren't being written permanently to disk - so on reboot they're still there just like before, no matter that the SpywareQuake & SpyFalcon Removal Procedure removed the registrry entries.

    No need - There was a recent Ghost image of the other system. They're following proper backup procedures at the client company where I took the infected disk. Took me a good chunk of the night, I just wiped the disk and reloaded the saved Ghost image. It's already back to normal.


    bestRegards, Guy.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They are written as soon as you apply the registry patch.

    Let's do the below (I assume you have the harddisk back in the original PC)


    Make sure viewing of hidden files is enabled (per theREAD & RUN ME).

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Reboot into safe mode and delete the below files (if found):
    C:\windows\system32\appmagr.dll
    C:\WINDOWS\iun3402.exe

    Now reboot into normal mode and get new logs from GetRunKey and ShowNew and attach them here. I serioulsy doubt this infection from Smitfraud is the cause of your system hanging. Smitfraud is a problem but the symptoms you are mentioning are more likely related to problems within your OS (corrupted or missing files).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds