XP Pro reboots at start, No Safe Mode w/ network, No Spyware Removal exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimmyPC, Oct 30, 2010.

  1. jimmyPC

    jimmyPC Private E-2

    I have read through the forum for the past two nights with no successful solution. I have already attempted the try general MALWARE removal sticky.


    I can only boot into regular safe mode. I cannot run ANY spyware removal or fix programs (MAB, Adaware, SuperSpyware, ComboFix, Spybot etc.). I cannot run the Avenger Tool because the PC will not boot normally. I have used another tool to scan for rootkits and found none, I have also cleaned the registry and I was eventually able to run smitfraudfix with no success.

    The blue screen error states:
    0xc0000005 -- which I believe is a registry error

    I have a HJT log attached. Thank you very much in advance, this is my company PC and crucial to my job.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not mention running MGtools. Did you try it? If you can run HijackThis then you can likely run MGtools. Also what exactly happens when you try to run Malwarebytes, SUPERAntiSpyware, and ComboFix?

    The only thing showing in your HijackThis log is a possible DNS infection and it would not cause the problems you are having with booting in normal mode or not having options for safe mode with networking...etc. Regsistry cleaning however has been known to cause many problems which is a major reason we don't recommend it.
     
  3. jimmyPC

    jimmyPC Private E-2

    chaslang:

    Thank you for replying, I have attached the MGlogs.zip.
    I would think also that I have a registry problem but I found it strange that the only programs I could not run from SafeMode were the common malware removal set.

    It may be a problem with my network connections as if I attempt to use SafeMode with networking, i get the same result of a reboot.

    thank you again for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer the below question I asked in my last message
     
  5. jimmyPC

    jimmyPC Private E-2

    They simply do nothing - I get the hour glass momentarily then nothing happens. Spybot will show in the 'processes' tab of tak manager for a brief second then disappear. The others do not even make it that far...Thank you for following up.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try the below.

    First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 15
    Java 2 Runtime Environment, SE v1.4.2_12
    Java(TM) 6 Update 15
    Java(TM) 6 Update 6

    What is the below folder for? It looks very suspicious
    Code:
    "C:\WINDOWS\"
    PRAGMA~1 May 5 2010 "PRAGMApxxyymspvq"
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: TBSB07215 - {FA2C50B7-C0D1-446C-9031-9B9FB16599A8} - (no file)
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\RunOnce: [Cleanup] C:\cleanup.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-21-3007948245-2664892597-1091355084-500\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.164.121,93.188.160.201
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0D491816-B155-4B48-955F-12EB71EEE6C3}: NameServer = 93.188.164.121,93.188.160.201

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. jimmyPC

    jimmyPC Private E-2

    - I uninstalled spybot all together because I cannot open it to change the settings.

    - I am not able to uninstall any of the JAVA components because I receive the following error: "The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installed is not correctly installed. Conotact your support personnel for assistance." Not sure if this is a legit error but I am in SafeMode.

    - I have deleted the C:\Windows\PRAGMA~ folder

    - I ran analyse.exe and 'fixed' all of the lines listed

    - I made the fixme.reg file and I DID receive a success message.

    - I ran avenger and I believe it deleted the listed files but upon reboot the system will still only boot into safe mode, the avenger.txt did not automatically pop up to review but I did find it in the C:

    - I ran CCleaner

    - Attached are the logs.

    Thank you again. Also, I have experienced a DrWatson Post Mortem Debugger error when trying to view properties of log files. This will lock the system up requiring a hard reboot...Not sure if this is indicitive of anything.

    I would be fine with restoring the system to an earlier date but when I try to use 'System Restore' I get an error stating that it has been turned off by group policy...this may be something done by my company but as the administrator I thought I would be able to circumvent that.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not looking like malware. I suggest that you try running the below and if it does not help, you may could try the Software Forum, but it is looking like you may be reinstalling or possible a repair may help ( both topics for the Software Forum ).


    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds