Vista Boot Loop After Vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by BatchSpurs, Sep 30, 2008.

  1. BatchSpurs

    BatchSpurs Private E-2

    Hi, I will try to keep this as brief as possible and want to say any help will be PHENOMENALLY appreciated!

    For the last three days I have, successfully to a degree, been removing what appeared to be a variance of the Vundo/Virtumundo trojan from my computer.

    Programs used include;
    VundoFix
    Virtumundobegone
    Symantecs vundo removal tool (I forget the name, sorry)
    AVG
    SpybotSearchAndDestroy
    Combofix
    SuperAntiSpyware
    Malwarebytes Anti-Malware
    MGTools
    DrWeb CureIt
    I have used more programs no doubt but those are the ones i can remember (again sorry)

    Now whenever I try a normal startup I get the ACER screen (F2,F8 access screen), the usual Vista loading screens and the welcome screen all as usual. However the welcome screen stays on for 10 secs, which is usually only on for a brief 2 secs, and then the whole system restarts with no sign of my desktop. This process continues over and over.

    I can however get on to my desktop and user account "as normal" with no sign of the previous virus by using F8 and "Last known good configuration".

    I have tried System Repair (from F8 at startup), no success. I have no System Restore points, a symptom of the virus I guess, as I guess this would solve whatever the problem is.

    The problem is, with the fashion of now not giving out Op System discs with new computers, I have no way of reinstalling Vista and so a complete wipe of the system is not a feasible option, though I am beginning to think it is the ONLY option (other than keep using F8/Last known good configuration that is).

    I wonder if the problem is that the virus has altered my Boot process or something, sorry to be so vague but I am at best an amateur techy and at my wit's end!

    Again any help or suggestions will be gratefully received and attempted

    Thankyou, David

    P.S. sorry for original post with no logs
     

    Attached Files:

  2. BatchSpurs

    BatchSpurs Private E-2

    A quick update,

    After having logged in frequently via "LKGC" over the past few days I can quite safely say every trace of the virus has gone apart from this annoying change to either my boot process or winlogon.exe.

    Comp is running as good as normal apart from the annoying boot loop :confused
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your current issues do not appear to be due to malware. I'm not sure exactly what you did on your own outside of our READ & RUN ME instructions but nothing seen in your logs is cause for your current problems. You do need to attach your ComboFix log as we requested.




    I do see a major issue or two though.
    1. You did not pay attention to the warning not to use multiple antivirus programs. You have AVG8 and Norton Internet Security installed and one of these must be uninstall immediately.
    2. You did not disable Spybot's Teatimer as requested in the READ & RUN ME. You need to do this now. See this: How to disable Spybot's TeaTimer
    3. Is Spyware Doctor 6 a paid copy? If not, uninstall it. If it is a paid copy you probably should not keep it anyway since AVG8 includes an antispyware program and I believe Norton Internet Security also has their own.
    4. You need to uninstall the below old versin of Sun Java
      • J2SE Runtime Environment 5.0 Update 3
      • Java(TM) 6 Update 4
    5. You need to delete the below folder:
      • C:\Program Files\Enigma Software Group
     
    Last edited: Oct 3, 2008
  4. BatchSpurs

    BatchSpurs Private E-2

    Hi, thankyou for your time and attention.


    I'm not sure it is as a result of the prescence of a malware file itself, rather that the malware has edited an existing windows file necessary for logging onor booting or getting from "welcome" to desktop. I feel it may be an updated Vundo as the file i downloaded to contract the virus is now little over a week old; a Vundo with a twist possibly, editing the winlogon as i mentioned before?

    ComboFix log attached, max of 3 attachments did not permit it originally

    1, I know I did not strictly follow MG protocol but this is due to the fact that I stumbled across your site when I had ridded myself of maybe 80% of the virus. Believe me when I say that Norton is now long gone as it is this crappy program I hold responsible for me getting the virus; had it been working properly I would not be in this situation!

    2, Again SpyBotS&D was installed well before I came across this site so that would be the reason. Out of interest what is this "teatimer" feature and why is it a no-no?

    3, Spyware Doctor 6 being uninstalled as we speak, I believe it was recommended as a foolproof way to get rid of Vundo.. clearly not!

    4&5, Again, on it as we speak

    I'm not completely ruling out the fact that I may have inadvertantly done something to aggrivate the situation and maybe even cause my own problem, however I was very careful when eradicating the virus and it seems quite suspect that once it had gone this problem arose.


    Again, Thankyou
    David
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should post questions on this in the Software Forum. Also make sure you did not unchecked the check box to show the Welcome Center.

    Very unlikely since we would already be seeing dozens of the same problem. It only takes a few hours from the onset of new versions of Vundo to hit the streets before we are seeing many posts with the new forms showing.


    Yes that is why the instructions in the READ & RUN ME tell you to use a second message. You still did not attach it.

    Are you 100% sure it is ALL gone. It rarely uninstalls properly. I suggest you do the following.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    After doing the above, you should run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    I want to make sure all of Norton, and other programs, were removed.

    Teatimer is a realtime antispyware blocking feature. It has been problematic and resource hungry in the past and it drives many people crazy with too many popup questions. In addition, it gets in the way of malware removal.

    Definitely not!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds