windows keeps rebooting

Discussion in 'Malware Help (A Specialist Will Reply)' started by zx2max, Jun 26, 2009.

  1. zx2max

    zx2max Private E-2

    Windows boots up temporarily then reboots. It doesn't allow me to do anything. It's appears to be loading things then flashes a blue "screen of death" then reboots. this is a constant cycle. The blue screen flashes so fast I can't even read it. I managed to get Malwarebytes to install in safemode. it scanned and found about 30 infected files and fixed/removed them but windows still won't work. I am unable to get superantispyware to install because I can only get compuer to boot in safemode. i also ran ccleaner from a flash drive but still no luck.Any help would be greatly appreciated since I am trying to avoid reinstalling windows. Thanks.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    can you run Combofix and MGTools in safemode? Attach logs if you are successful. Also attach the log from running Malware Bytes.
     
  3. zx2max

    zx2max Private E-2

    Thanks for your assistance Kestrel13!. I ran combofix and MGools. I have attached the logs. I can't find the log from Malwarebytes but if needed I can rerun that program o get you a log. Since running the combofix and MGtools it looks like computer is working now but could you still look at the logs to make sure there isn't anything still infected that might have been overlooked.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your mglogs.zip is incomplete.

    This means something went wrong with the running of MGTools.exe.
    Did you recieve any errors whilst running it? See the below for possible error messages:

    Using MGtools
    • Did you let it run to completion?
    • Did you agree to the hijackthis license?

    Please run it again ensuring you do all of the above. Attach the new mglogs.zip into your next post :) Then we can start to work a fix for you.
     
  5. zx2max

    zx2max Private E-2

    I didn't get any errors but I think it was user error. I think I ran i from my desktop and not the C:\. I have attached the updated MGtools log. Thanks again.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not to worry, but we are still missing a Hijack this log and a couple others that are meant to be included in the zipped file. :( Did you agree to the hijack this license agreement?

    Thanks
    Kes
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also ensure that MCAfee isn't to blame and could be interfering with the complete running of MGTools
     
  8. zx2max

    zx2max Private E-2

    It could be mcafee. i wasn't sure how to disable it. i went to the advanced settings on turned off everything under computer and files as well as network and internet. then rerean mgtools but i didn't get the hijackthis license agreement. Am I doing something wrong with disabling Mcafee?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) save the log and attach it here.

    Thanks
    Kestrel13!
     
  10. zx2max

    zx2max Private E-2

    I attached HijackThis log. Thanks.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    afraid you didn't :(
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    More than likely I will be sending you to the Software Forum where you should disable auto rebooting so you can see the error messages. However, the first thing you need to do is uninstall both McAfee Security Center and Norton Security Center which they should never have installed at the same time. It is best to uninstall both now.

    Next let's run the McAfee and Norton removal tools:

    1. Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    2. Please download the McAfee Consumer Product Removal Tool

    Run this > Reboot your machine > and Run it again to get rid of remnants of McAfee.

    3. Also please can you get me these recent logs from running MBAM?
    4. Delete the below using Windows Explorer:

    c:\documents and settings\All Users\Application Data\11635784 <--- folder
    c:\documents and settings\All Users\Application Data\91645776 <--- folder

    C:\d45.bat <--- file
    c:\documents and settings\All Users\SPL6E.tmp <--- file
     
  13. zx2max

    zx2max Private E-2

    I used those tools to remove Norton and Mcafee. As well as deleted the files. Attached are the logs you requested (I really attached them this time) I really appreciate everything you are doing for me.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to run MBAM again and first update it and then run a new scan and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks
    Kes
     
  15. zx2max

    zx2max Private E-2

    Logs are attached.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to Add/Remove programs and uninstall the following old versions of Java:

    • J2SE Runtime Environment 5.0 Update 5
    • Java(TM) 6 Update 2

    2. Now I would like for you to run scannow, to do so, please refer to the below:

    Running SFC Scannow

    3. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    4. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    5. Next I would like for you to download a new copy of MGTools.

    Go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    6. Run the new MGTools.exe and attach the C:\mglogs.zip file that it generates.

    7. Attach it in your next reply.

    Thanks :)

    Kes
     
  17. zx2max

    zx2max Private E-2

    I followed your instructions. Attached is the new MGtools log. Thanks.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    whilst I go thru the rest of your logs please do the following: :)

    reboot your machine (if you haven't already done so since my last instructions) and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6
     
  19. zx2max

    zx2max Private E-2

    rebooted and got the latest and greatest Java.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    almost done! You didn't remove windows messenger though.

    Please follow my post #16 step # 3 to do this.

    Thanks
    Kes:)
     
  21. zx2max

    zx2max Private E-2

    Sorry I'm usually much better at following instructions. I've been a little out of it lately-fighting Lyme disease. I'll remove it later this afternoon when I get off work. Probably around 5pm EST. Do you need me to rerun MGtools or anything after I remove it?
     
  22. zx2max

    zx2max Private E-2

    I uninstalled Windows Messenger using that program from your link.
     
  23. zx2max

    zx2max Private E-2

    Hey Kestrel13! I had to give the laptop back to its owner today so hopefully it's all good. It seemed to be running fine. I really appreciate all your help.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hope you are okay! Get well soon zx2max :)
    you're very welcome!

    Tell them safe surfing! :wave
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds