Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Blue Screen after log on WIN32:Patched-ck  (Read 7066 times)

0 Members and 1 Guest are viewing this topic.

Northender

    Topic Starter


    Rookie

    Blue Screen after log on WIN32:Patched-ck
    « on: September 17, 2008, 11:24:17 AM »
    I have been handed a badly infected laptop (my son’s girlfriends)

    I ran spybot sd and removed a load of stuff.

    Then ran a standalone kaspersky checker and found

    win32:patched-CK [trj]
    win32.virtumonde
    I managed to get rid of these eventually with vundofix
    And Drweb cure it
    The following files were initially infected
    C:\windows\explorer.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\services.exe
    C:\windows\system32\svchost.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\gebcc.dll
    C:\windows\system32\sysrest.sys

    I can boot the laptop in safe mode but in normal mode after encountering the log on screen and entering a password I am met with a completely blue screen and the mouse pointer which I can move around.The machine stays in this state.
    The machine is running Windows XP SP2

    I would really appreciate any help you can give me.

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\Explorer.EXE

    This is the Hijack this log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:11:20, on 17/09/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Safe mode with network support

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)

    --
    End of file - 3110 bytes

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Blue Screen after log on WIN32:Patched-ck
    « Reply #1 on: September 17, 2008, 11:50:03 AM »

    Northender

      Topic Starter


      Rookie

      Re: Blue Screen after log on WIN32:Patched-ck
      « Reply #2 on: September 18, 2008, 09:57:53 AM »
      Hi many thanks for your help
      I downloaded both programs you requested.
      Unfortunately when i tried installing superantispyware I got the message
      "The system administrator has set policies to prevent this installation"
      The name I logged on under has administrator rights tho.
      Also just out of interest I tried creating a new account and this loaded the background screen with no icons or tool bars and nothing else.
      I ran MBAM and this found a lot of stuff that i fixed.

      Here are the logs you requested.

      I have attached the logs you requested

      Thanks again



      [recovering disk space -- attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Blue Screen after log on WIN32:Patched-ck
      « Reply #3 on: September 18, 2008, 03:45:52 PM »
      Download SDFix by AndyManchesta and save it to your desktop.

      When using this tool, you must use the Administrator's account or an account with Administrative rights

      • Double click SDFix.exe and it will extract the files to %systemdrive%
      • (this is the drive that contains the Windows Directory, typically C:\SDFix).
      • DO NOT use it just yet.
      Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

      Open the SDFix folder and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
      • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log (from normal boot mode).

      Northender

        Topic Starter


        Rookie

        Re: Blue Screen after log on WIN32:Patched-ck
        « Reply #4 on: September 19, 2008, 12:25:51 AM »
        Hi did what you requested but still get the blue screen after attempting normal startup. I Can only start the computer in safemode and run SDFIX in safe mode.

        Here are the logs I got after starting the machine in safe mode

        Many thanks




        [recovering disk space -- attachment deleted by admin]

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Blue Screen after log on WIN32:Patched-ck
        « Reply #5 on: September 19, 2008, 11:18:16 AM »
        SDFix doesn't look like it finished it's run. Was there any problems running it?

        Northender

          Topic Starter


          Rookie

          Re: Blue Screen after log on WIN32:Patched-ck
          « Reply #6 on: September 20, 2008, 05:06:08 AM »
          Hi

          SDFIX Ran perfectly apart from running again when the machine reboots.
          I rebooted normally and stiill get the blue screen but no clear up from SDFIX.
          I Rebooted in safe mode and no clear up from SDFIX after this reboot either.
          Yet both times SDFIX had run 100%.
          I did get a message on the screen while SDFIX was running which read
          FINDSTR:Cannot read filelist from TESTPatched3.txt.
           Thanks for your help

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Blue Screen after log on WIN32:Patched-ck
          « Reply #7 on: September 20, 2008, 10:35:44 AM »
          Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

          Link #1
          Link #2

          **Note:  It is important that it is saved directly to your Desktop

          Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

          Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
           
          Double click combofix.exe & follow the prompts.
          When finished ComboFix will produce a log for you.
          Post the ComboFix log and a new HijackThis log in your next reply.

          Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

          Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

          Northender

            Topic Starter


            Rookie

            Re: Blue Screen after log on WIN32:Patched-ck
            « Reply #8 on: September 21, 2008, 03:28:18 AM »
            Hi
            Downloaded and ran Combofix.
            Combofix ran perfectly and here are the new logs you requested.
            Thanks for your help


            [Saving space - attachment deleted by admin]

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Blue Screen after log on WIN32:Patched-ck
            « Reply #9 on: September 21, 2008, 10:59:29 AM »
            Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

            Delete these files/folders, as follows:

            1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
            It must be Notepad, not Wordpad.
            2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

            Code: [Select]
            KillAll::

            File::
            C:\WINDOWS\system32\winlogon.exe.kav
            C:\WINDOWS\system32\services.exe.kav
            C:\WINDOWS\system32\lsass.exe.kav
            C:\WINDOWS\system32\drivers\41475545.sys

            Registry::
            [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

            [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

            [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

            [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

            3. Go to the Notepad window and click Edit > Paste
            4. Then click File > Save
            5. Name the file CFScript.txt - Save the file to your Desktop
            6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



            ComboFix will begin to execute, just follow the prompts.
            After reboot (in case it asks to reboot), it will produce a log for you.
            Post that log (Combofix.txt) in your next reply.

            Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

            ----------

            Download DrWeb CureIt & save it to your desktop.

            Scan with DrWeb-CureIt as follows:
            • Double-click on drweb-cureit.exe and then click Start.
            • An Express Scan of your PC notice will appear.
            • Under Start the Express Scan Now Click OK to start.
              • This is a short scan that will scan the files currently running in memory.
              • If or when something is found, click the Yes button when it asks you if you want to cure it.
            • Once the short scan has finished, Click Options > Change settings
            • Choose the Scan tab and UNcheck Heuristic analysis and click OK
            • Back at the main window, select the Complete scan button.
            • Then click the Green Arrow Start Scanning button on the right and the scan will start.
              • Click Yes to all if it asks if you want to cure/move any file(s).
            • When the scan is done.
            • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
            • Save the DrWeb.csv report to your Desktop.
            • Exit Dr.Web Cureit.
            • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
            [/COLOR]
            • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
            • Copy and paste that log in the next reply
            .
            ----------

            Any changes?

            Northender

              Topic Starter


              Rookie

              Re: Blue Screen after log on WIN32:Patched-ck
              « Reply #10 on: September 22, 2008, 11:28:03 AM »
              Hi
              Thanks again for your help
              Followed your instructions but still encountering the blue screen and mouse pointer.
              I have attached the logs you requested.

              [Saving space - attachment deleted by admin]

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Blue Screen after log on WIN32:Patched-ck
              « Reply #11 on: September 22, 2008, 11:34:37 AM »
              I don't think the bluescreens are malware related. You might make a post in the Windows forum so someone can help troubleshoot it.

              Download OTCleanIt.exe and save it to your Desktop.
              • Double-click OTCleanIt.exe.
              • Click the CleanUp! button.
              • Select Yes when the "Begin cleanup Process?" prompt appears.
              • If you are prompted to Reboot during the cleanup, select Yes.
              • The tool will delete itself once it finishes, if not delete it yourself.

              Northender

                Topic Starter


                Rookie

                Re: Blue Screen after log on WIN32:Patched-ck
                « Reply #12 on: September 23, 2008, 11:45:17 AM »
                Ok I'll try that forum.
                Thank you very much for your patience and help.

                Northender

                  Topic Starter


                  Rookie

                  Re: Blue Screen after log on WIN32:Patched-ck
                  « Reply #13 on: September 24, 2008, 12:29:11 PM »
                  Evilfantasy
                  I am not sure how but after reading another email on this site I decided to
                  uninstall Avast and couldnt believe it when the blue screen was there but thankfully so were my icons.
                  so pleased to get the laptop working again
                  Thanks for this brilliant sites help