Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 18-04-2008, 09:24 AM   #1 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Virus infected in PC and safe mode booting not working


Recently my PC was infected with a worm giving a fake warning that "you are using pirated illegal copy of windows".
I searched the net and found that it is a worm named "W32.Launcer" which infects removable drives and closes the windows when the title contains "player","winamp" etc. so I am unable to open any media players.

I ran a full scan.my antivirus detected the trogen and deleted the files.but still the warning appears.So I tried to run AdAware anti spyware,but it closes as soon as it opened.I confirmed that the trojan still remains.

My normal boot worked fine and I decided to run antivirus from safe mode, but after selecting the safe mode from boot option, it hangs with black screen with "safe mode" showing in all corners of the screen and nothing happens after that[the safe mode worked fine before running the scan]

Then I booted in normal mode and did a mistake. In msconfig i selected the option "/SafeMode" in boot.ini.Now whenever i boot it goes to the safe mode and nothing showing up.

How can I set back to normal mode? how can i edit the boot.ini to deselect the option?
how can i boot again with safe mode to delete the trojan?

I even tried last known good configuration but of no use.

My PC Config is Win XP with SP3 Release candidate,2 GB Ram,Bitdefender total security 2008, adaware 2007
__________________
Guhan
guhanath is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-04-2008, 11:03 PM   #2 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi,
I used the live cd of ubuntu and was able to view the windows drive with boot.ini.however i am unable to edit and save the boot.ini as it is read only. is there any other way that i can replace the old boot.ini with the new one or is it possible to change the permission of the file from live cd itself?

or is it possible to edit the boot.ini file from recovery console itself?
__________________
Guhan
guhanath is offline  
Old 19-04-2008, 10:15 AM   #3 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Now i modified the boot.ini from live cd and saved it to usb drive.then using the xp recovery console i changed the attribute of boot.ini to remove the read only attribute and copied the new boot.ini to my windows root.
Now i am able to boot into normal mode but still safe mode not working.
Now the priority moves to removing the trojan.I couldnt delete the trojan from normal mode.how can i remove it then?Is it possible to run any spyware from cd media? what are the ways i can diagnose the safe mode and how can i recover it.
In the normal mode i cannot open any antispyware or install new antispyware because whenever any window opens the trojan closes the window.
I found 2 process in task manager winhelp.exe and wowexec.exe which i could not kill at all.
I know that I am half way through little additional help will be needy.
__________________
Guhan
guhanath is offline  
Old 19-04-2008, 10:21 AM   #4 (permalink)
Human Spambot
 
Join Date: Jan 2007
Location: Lat 28.38°N , Longt 77.13°E
Posts: 2,431
Default Re: Virus infected in PC and safe mode booting not working

Quote:
Originally Posted by guhanath View Post
I couldnt delete the trojan from normal mode.how can i remove it then?

I found 2 process in task manager winhelp.exe and wowexec.exe which i could not kill at all.
I know that I am half way through little additional help will be needy.
Try using UNLOCKER if you can install it to remove the infected files. It can be used to kill such objects as well.
ThinkFree is offline  
Old 20-04-2008, 08:55 AM   #5 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi All,
Thanks for your extended support. I have installed the OEM version of Windows XP updated to SP3RC, BitdefenderTotal Security 2008(with all updates), Adaware 2007.

I could not run Adaware at all(it opens and closes immedietly, the trojan is not allowing it to open,even i could not access its folder, it immedietely closes it, even i could not install spybot,the window closes)

I ran a runscanner utility, a startup analyzer and process manager which tells me the rootkits and missing files. I found that lot of sys files were missing like pcidump.sys,changer.sys.Do they all required to get into safe mode?. so i tried to run sfs to get the missing windows files but no success( i used my friends xp cd,product key differs and windows gives error that cd product is different) how can i go about it?

It is really annoying that i could not recover the safe mode(is there any way to find what is happening in safe mode when it shows black screen?)

Runscanner identified winhelp as rootkit(at1.job) but the file was missing and startup has this running process.this might be the reason i am not able to kill the process.

There is no file named Aut3.tmp or Aut4.tmp
Regarding running the AVGrootkit i wll chk and let u know.
__________________
Guhan
guhanath is offline  
Old 20-04-2008, 04:37 PM   #6 (permalink)
Right Off the Assembly Line
 
Join Date: Apr 2008
Posts: 40
Default Re: Virus infected in PC and safe mode booting not working

Try RootKit unhooker.

http://www.woodmann.com/collaborativ....7.300.509.zip

File size: 160 kb only

Shows SSDT, shadow SSDT, process viewer, hooks etc...

I normally use this tools to for finding hiden files + any rootkit which might have hooked kernel api itself via .sys i.e. at the time of booting where it hooks NtQueryDirectoryInformation & hides itself we can easily see that.

Excellent tool worth trying.

Janki
janki2008 is offline  
Old 21-04-2008, 09:34 AM   #7 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi All,
I am able to remove the W32.Launcer worm which gave the warning "you are using illegal version of windows". Thanks for
your answers which did that with various rootkits.
Now i have narrowed down to 2 problems.
1. Safe mode still not booting up
2. A spyware is still present which closes any spyware application.(ie:whenever i open any antispyware it closes
immedietly.Even it is not allowing to install any antispywares like Spybot/AVG Antispyware. Even trying to access the
antisyware installation folder closes/even when web page contains any soln for spyware it closes that).Does anyonw know what malware it is?

Regarding the first problem,i found tht some malware will delete the registry key for safeboot.is that true?can anyone suggest what will be the default value?

If i am able to restore safe boot, then i think i can run antispyware from safe mode and remove it.Suggest a soln.
Also if i want to run SFC using my friends XP cd,how can i go about it?
__________________
Guhan
guhanath is offline  
Old 23-04-2008, 05:10 PM   #8 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi All,

Please try to help me in this.Does anyone have idea on how to use UBCD4Win to recover/repair windows
__________________
Guhan
guhanath is offline  
Old 23-04-2008, 06:46 PM   #9 (permalink)
Legen-wait for it-dary!
 
dheeraj_kumar's Avatar
 
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
Default Re: Virus infected in PC and safe mode booting not working

I sincerely advice you to backup all program settings, and your documents, and do a fresh install of xp. I have found via experience, that some virii and malware, and most rootkits leave some trace of themselves when you remove them, and they slow down your PC to a living hell. You are trying since 18/4 to 23/4 (today) why not spend 30 mins to reinstall xp?
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
dheeraj_kumar is offline  
Old 24-04-2008, 05:48 PM   #10 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi Dheeraj,

I dont want to reinstall XP as I have so many programs installed on my machine and i know that once my safe mode is ready i can run the spyware and remove the malware else i will try UBCD4Win to repair it. give suggestions
__________________
Guhan
guhanath is offline  
Old 24-04-2008, 06:18 PM   #11 (permalink)
Wise Old Crow
 
blueshift's Avatar
 
Join Date: Apr 2005
Location: Inside the Pixel
Posts: 1,227
Default Re: Virus infected in PC and safe mode booting not working

@guhanath,
could you edit the boot.ini file?

This is what I found you must be looking for.
Restoring Safe Mode with a .REG file

Do you have access to Taskmanager, MSConfig, Regeditor, Command windows?
__________________
http://twitter.com/blueshift155
blueshift is offline  
Old 25-04-2008, 09:39 AM   #12 (permalink)
Apprentice
 
Join Date: Jan 2005
Posts: 76
Default Re: Virus infected in PC and safe mode booting not working

Hi,
I will try this option and let you know. yes, I can access all except these actions.
1. Cannot get into safe mode
2. No Antispyware programs running/cannot install new.
3. explorer closes automatically when i go into installation folder of antispyware.
4.if any windows contains "spyware""adaware" etc.. it closes.

apart from this everything looks normal
__________________
Guhan
guhanath is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
No Safe Mode Swappy Software Q&A 2 24-08-2006 09:21 AM
Nasty virus hit......can only work in safe mode, need urgent help ranjan2001 Software Q&A 18 03-08-2006 08:08 PM
Difference Between FF Ordinary Mode & FF Safe Mode rajas700 QnA (read only) 9 27-08-2005 02:38 PM
Why ain't this Safe Mode Working (XP) rahulstein Software Q&A 7 23-08-2005 07:03 PM
XP SP2: SAFE MODE... ShekharPalash QnA (read only) 8 25-09-2004 11:02 PM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 03:17 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2