User Profile Cannot be Loaded & Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by buzz0340, Aug 9, 2014.

  1. buzz0340

    buzz0340 Private E-2

    Good morning.

    I am currently having issues with my Lenovo Y550 with Windows 7 (64bit). The main problem is the User Profile Cannot be Loaded. I have to operate everything through safemode with networking.

    I ran through your instruction list the best I could and below are my notes:

    CCleaner : Run and items cleaned.

    Roguekiller : Log attached. Appears to have flagged "zeroaccess".

    Malwarebytes: Multiple errors occur during install and cannot be run.

    TDSSkiller : Program ran but no threats found.

    I have logged onto another user account but the blue screen pops up and restarts the computer. If I remember correct it had error "0x00000051".

    Please let me know what else I need to do and appreciate any help!

    Thank you, Brian
     

    Attached Files:

  2. buzz0340

    buzz0340 Private E-2

    I forgot to attach the Hitman log file. Please see attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have remnants of a zero access infection. Did MGTools run?? We need to see logs from that too please, if it did. :) Thanks.
     
  4. buzz0340

    buzz0340 Private E-2

    MGTools was able to complete. Attached is the .zip file generated. Please let me know if you need anything else. Thank you!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [ZeroAccess] (X64) HKEY_CLASSES_ROOT\CLSID\{5839fca9-774d-42a1-acda-d6a79037f57f}\InprocServer32 | : C:\$Recycle.Bin\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\n. -> FOUND
    • [ZeroAccess] (X64) HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5839fca9-774d-42a1-acda-d6a79037f57f}\InprocServer32 | : C:\$Recycle.Bin\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\n. -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\$RECYCLE.BIN\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\L
    C:\$RECYCLE.BIN\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\U
    C:\$RECYCLE.BIN\S-1-5-21-4034101843-3159816184-889204002-1003\$d338b8401a8ffb3e1897b22cbc496529\L
    C:\$RECYCLE.BIN\S-1-5-21-4034101843-3159816184-889204002-1003\$d338b8401a8ffb3e1897b22cbc496529\U
    C:\ProgramData\blekko toolbars
    C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
    
    :reg
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS]
    [-HKU\S-1-5-21-4034101843-3159816184-889204002-1003\Software\AppDataLow\Software\AskToolbar]
    [-HKU\S-1-5-21-4034101843-3159816184-889204002-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AF74BA19-3382-4FB0-994B-D6B5F8CDB222}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Re run RogueKiller (just a scan) and attach new log.
    • Re run Hitman Pro and attach log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. buzz0340

    buzz0340 Private E-2

    Good morning again,

    I followed all of your directions the best I could:

    Roguekiller: Completed deletion. Attached scan labeled [2] ReRun

    OTM : Completed. Attached log.

    Junkware Removal Tool : I could not run this program. It would open up a blank command prompt and do nothing. No text. It would sit like this for 20 minutes.

    RogueKiller: Completed. Attached scan as [3].

    Hitman Pro: Could not run. Window prompts saying it is not a valid win32 application.

    MG_Tools: Completed and log attached as [2].

    Observations: All of your instructions were run via safemode because the user account would not work. After completion of your instructions, I tried again to open the user account and had issues. First the log in screens are very slow. It takes ~15 seconds for the password prompt to pop up after clicking on the user name. Once windows loads, the desktop background pops up but then the blue screen shuts down the computer and goes to "Windows Error Recovery".

    Please let me know what else I need to do.

    Thank you, Brian
     

    Attached Files:

  7. buzz0340

    buzz0340 Private E-2

    Update. I redownloaded hitman and was able to get it to run. attached is the latest scan log.

    Thank you, Brian
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Empty your recycle bin and then re run Hitman and attach log.
     
  9. buzz0340

    buzz0340 Private E-2

    I cleared the recycle bin and ran Hitman. The log is attached.

    Thank you, Brian
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, there are some leftovers from a zero access infection, I can't delete them with Hitman because your trial has already expired. :(

    I could not delete them with OTM, so let's try this.

    Trojan.Zeroaccess Removal Tool

    Once you have run it, rerun Hitman yet again and attach log.
     
  11. buzz0340

    buzz0340 Private E-2

    I completed the zeroaccess removal tool and ran hitman. The log is attached. The main user account still does not load.

    Thank you, Brian
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download Combofix to your desktop. Please refer to these instructions prior to running.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\$RECYCLE.BIN\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\L
    C:\$RECYCLE.BIN\S-1-5-18\$d338b8401a8ffb3e1897b22cbc496529\U
    C:\$RECYCLE.BIN\S-1-5-21-4034101843-3159816184-889204002-1003\$d338b8401a8ffb3e1897b22cbc496529\L
    C:\$RECYCLE.BIN\S-1-5-21-4034101843-3159816184-889204002-1003\$d338b8401a8ffb3e1897b22cbc496529\U
    C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
    
    Registry::
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now please re run Hitman again and attach log.
     
  13. buzz0340

    buzz0340 Private E-2

    Combofix ran but I didnt save/couldnt find the log. i can run again if needed. I ran hitman again and attached the most recent log.

    Please let me know what else I can do.

    Thank you, Brian
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, the zero access remnants are gone. Any other remaining issues concerning your user profile can be addressed in the software forum. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. buzz0340

    buzz0340 Private E-2

    Good morning again,

    Thank you very much for your support to date. I am still having issues with loading the user profiles. It seems that everything works fine when operating in safe mode but shuts down in the main user account. The windows blue screen will pop up and shut down the computer soon after log in. Any suggestions on identifying its source?

    Thank you, Brian
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said:

    ;) Best of luck
     
  17. buzz0340

    buzz0340 Private E-2

    I take it you think its a hardware problem. Thank you.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think I told you twice that it is software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds