Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Computers
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
 
Old 03-06-2013, 08:26 AM
 
713 posts, read 3,438,748 times
Reputation: 550

Advertisements

Today when I went to start my computer, it would restart right after the start up logo. I am able to get online and run it in safe mode but am puzzled by what is causing the problem. Only idea is my temp folder. For the past week Norton has been hitting me with alerts of temp files acting weird and being removed from my temp folder that seem to just reappear after a while. Deleting the temp folder has fallen on some resistance since it says a file is open somewhere else. Properties shows there are 12 folders, yet there are none visible even when I turn hidden files on. Last note is when I had windows run a scan on all programs that start up, one of them was from the temp folder. Do not know if that is the cause of this problem since I dont even get to the windows loading page before the restart happens. Happens right after those orbs make the windows logo, then black screen fallowed by restart

Also says superfetch is not running yet that might be do to being in safe mode.
Reply With Quote Quick reply to this message

 
Old 03-06-2013, 10:46 AM
 
28,803 posts, read 47,705,555 times
Reputation: 37905
Try running Ccleaner.

Here's a post I made about using it in another forum on CD:

//www.city-data.com/forum/20778157-post21.html

What Anti-Virus are you using? Have you run Malwarebytes?
Reply With Quote Quick reply to this message
 
Old 03-06-2013, 10:48 AM
 
Location: SCW, AZ
8,323 posts, read 13,453,824 times
Reputation: 7995
you will have bare minimum amount of services running in Safe Mode, that is normal.
Were you able to get to the user login screen at all or it reboots even before that?
If you can get to the user login screen and it craps out afterward, the local user profile is corrupt.
If it happens beforehand, it is the filesystem. If you haven't made any changes to your system, installed/uninstalled any programs or drivers, my guess you got hit by a pesky malware.

How Windows savvy are you? Would you be able to boot to a removable media like DVD/Flash drive and scan the system? I personally recommend and use UBCD for any kind of diagnostic work where you cannot even boot the operating system in normal mode. I like using a bootable media to scan for system and malware issues because the operating system is inactive so if there is a malware infection, even if there is a hidden partition created by a powerful Trojan, you will be able to eradicate the issue that way.

You could however, boot in Safe Mode w/ Networking to see if you get a network connection, then download couple of solid standalone malware/virus scanners. Downloading a normal application like Malwarebytes and trying to install it in Safe Mode would probably not work. So, I would probably start buy deleting temp file folders using a standalone tools like ATF-Cleaner and try running something like McAfee's Stinger which is a standalone app that doesn't require installation and checks for boat load of infections and quite effective.

Anyhow, just throwing some ideas to get you rolling.

Good luck.
Reply With Quote Quick reply to this message
 
Old 03-06-2013, 10:57 PM
 
713 posts, read 3,438,748 times
Reputation: 550
Thanks I will start going down the list to see what might work. Must be a system infection since it happens before the windows login page. Right after window loads and you gain control of your mouse and keyboard, instead of showing the typical blue windows page, it just stays black for around 30 seconds before restarting.

My anti-virus is Norton.
Reply With Quote Quick reply to this message
 
Old 03-06-2013, 11:35 PM
 
713 posts, read 3,438,748 times
Reputation: 550
Summery: Was infected by ZeroAccess Trojan. Stinger removed almost all the files, enough for me to get into the system but not enough to stop it from trying to reinstall itself. Ran Norton's fix for the problem and can now get in with any problem yet I am still getting reports of files trying to run on my system.

May of found the cause, waited a minute and nothing. Opened firefox and got hit with reports of trojan's. Firefox could be infected and is linking me to malware

Note* Might not be firefox after all. It would seem that the moment I open either Internet Explore or Firefox I start to get hit by trojan's. All from ZeroAccess, which is located in file services.exe in System32 it would seem.

Last edited by rgomez912; 03-06-2013 at 11:58 PM..
Reply With Quote Quick reply to this message
 
Old 03-07-2013, 12:31 AM
 
Location: SCW, AZ
8,323 posts, read 13,453,824 times
Reputation: 7995
Quote:
Originally Posted by rgomez912 View Post
Summery: Was infected by ZeroAccess Trojan. Stinger removed almost all the files, enough for me to get into the system but not enough to stop it from trying to reinstall itself. Ran Norton's fix for the problem and can now get in with any problem yet I am still getting reports of files trying to run on my system.

May of found the cause, waited a minute and nothing. Opened firefox and got hit with reports of trojan's. Firefox could be infected and is linking me to malware

Note* Might not be firefox after all. It would seem that the moment I open either Internet Explore or Firefox I start to get hit by trojan's. All from ZeroAccess, which is located in file services.exe in System32 it would seem.
In short, your system is infected, internet browser is just a vessel or probably a trigger mechanism for the Trojan to activate itself since it seemingly hooked itself to core system process/services. Sounds like a Rootkit type.

If it is really that pesky, my advice, salvage your files (documents, pictures, bookmarks/favorites, etc.) and the do a fresh install of Windows. As a novice user, it is not worth taking a chance on a compromised system.

~TL
Reply With Quote Quick reply to this message
 
Old 03-07-2013, 12:37 AM
 
713 posts, read 3,438,748 times
Reputation: 550
I already ordered a new hard drive and a copy of windows 8 since I was planning on doing that anyway this virus just quickened that decision.
Reply With Quote Quick reply to this message
 
Old 03-07-2013, 02:26 AM
 
713 posts, read 3,438,748 times
Reputation: 550
For fun I decided to look at my Norton history to see when it might of started.

Quote:
2/25/13 * first instance of virus*

9:14PM - f311.tmp detected by SONAR

2/26/13

1:18AM - 91c5.tmp detected by SONAR

2/27/13

1:39AM - a81f.tmp detected by SONAR
1:49AM - fa93.tmp detected by SONAR
6:22AM - Unauthorized access blocked(Open File)
6:22AM - Unauthorized access blocked(Open File)

2/28/13

1:05AM - 684e.tmp detected by SONAR
1:25AM - Unauthorized access blocked(Set Registry Security Key)

3/1/13

3:18AM - Unauthorized access Blocked(Set Registry Security Key)
4:04AM - C720.tmp detected by SONAR
3:26PM - Unauthorized access Blocked(Set Registry Security Key)
11:48PM - 1ed8.tmp detected by SONAR
11:58PM - 67f9.tmp detected by SONAR

3/2/13

1:21AM - Unauthorized Access Blocked(Access Process Data)
1:21AM - Unauthorized Access Blocked(Access Process Data)
1:22AM - Unauthorized Access Blocked(Access Process Data)
1:22AM - Unauthorized Access Blocked(Access Process Data)
1:23AM - Unauthorized Access Blocked(Access Process Data)
3:33AM - Unauthorized Access Blocked(Set Registry Security Key)
10:11AM - f49b.tmp detected by SONAR
10:20AM - 4442.tmp detected by SONAR
3:40PM - Unauthorized Access Blocked(Set Registry Security Key)

3/3/13

4:04AM - 4f1f.tmp detected by SONAR
3:54PM - Unauthorized Access Blocked(Set Registry Security Key)
5:58PM - 7c4.tmp detected by SONAR

3/4/13

12:38AM - 951d.tmp detected by SONAR
4:04AM - Unauthorized access blocked(Set Registry Security Key)
10:00AM - 3444.tmp detected by SONAR
4:09PM - Unauthorized access blocked(Set Registry Security Key)
6:02PM - 73fc.tmp detected by SONAR

3/5/13

1:15AM - 924e.tmp detected by SONAR
1:24AM - da19.tmp detected by SONAR
4:16AM - Unauthorized access blocked(Set Registry Security Key)
11:27AM - 2f75.tmp detected by SONAR
4:23PM - Unauthorized access blocked(Set Registry Security Key)
7:08PM - IP Address has disappeared from adapter Teredo Tunneling Psuedo-Interface...
7:08PM - IP Address has disappeared from adapter Teredo Tunneling Psuedo-Interface...
7:08PM - Protecting your connection to newly detected network....
7:08PM - Protecting your connection to newly detected network....
8:38PM - An instance of AAB7.tmp is preparing to access the internet.

****************Start of major infection?**********************
8:38PM - You allowed AAB7 to access your network resources.
************************************************** ******

8:38PM - IP Address has disappeared from adapter Teredo Tunneling Psuedo-Interface...
8:38PM - IP Address has disappeared from adapter Teredo Tunneling Psuedo-Interface...

3/6/13

12:49AM - An instance of 6d60.tmp is preparing to access the internet
1:39AM - No user is logged in.
8:24AM - Firewall has been enabled
8:24AM - Protecting your network on newly detected network....
8:24AM - Protecting your network on newly detected network....
8:24AM - Protecting your network on newly detected network....
8:24AM - Protecting your network on newly detected network.....
8:24AM - IP has disappeared from adapter....
8:24AM - Protecting your network on newly detected network......
8:24AM - An instance of Norton360/ccsvchst.exe is preparing to access the internet
8:28AM - Firewall setting "AlertThreadEnabled" changed
8:28AM - User logged in.
8:28AM - Connected to a shared network(******)
8:28AM - Connected to a protected network(******)

*Around this time I tried to get on but could not and made this thread*

3/7/13

12:16AM - Firewall has been enabled
12:16AM - Protecting your network on newly detected network....
12:16AM - Protecting your network on newly detected network....
12:17AM - Protecting your network on newly detected network....
12:17AM - Protecting your network on newly detected network.....
12:18AM - IP has disappeared from adapter....
12:18AM - Protecting your network on newly detected network......
12:21AM - An instance of Norton360/ccsvchst.exe is preparing to access the internet
12:22AM - Firewall setting "AlertThreadEnabled" changed
12:22AM - User logged in.
12:22AM - Connected to a shared network(******)
12:22AM - Connected to a protected network(******)

*Let the attacks begin...*

12:23AM - 80000032@(Trojan.Gen.2) detected
12:26AM - 00000004@(Trojan.Zeroaccess.B) detected
12:26AM - 80000032@(Trojan.Gen.2) detected
12:26AM - 00000004@(Trojan.Zeroaccess.B) detected
12:26AM - Unauthorized access blocked(Access Process Data)
12:27AM - 80000000@(Trojen.Gen.2) detected
12:30AM - 000000cb@(Trojen.Zeroaccess.C) detected
12:30AM - 000000cb@(Trojen.Zeroaccess.C) detected
12:33AM - services.exe(Trojan.Zeroaccess!inf4) detected
12:34AM - 00000004@(Trojan.Zeroaccess.b) detected
12:34AM - 80000032@(Trojan.Gen.2) detected
**********So on so on***********
12:58AM - desktop.ini(Trojan.Zeroaccess) detected <-WINDOWS/ASSEMBLY file infection
***********Same stuff over and over*****
Reply With Quote Quick reply to this message
 
Old 03-07-2013, 06:03 AM
 
Location: Not.here
2,827 posts, read 4,342,582 times
Reputation: 2377
I would download TDSSKiller and run it to remove the Zeroaccess trojan. It's a quick download and the scan is quick also.

Kaspersky TDSSKiller - Download

If that didn't work, I would pull the plug (restore your pc to factory settings with a CD or from the hard drive partition) like TurcoLoco suggested. I think you can waste more time searching for viruses when the computer can be made clean (like when you first bought it on day one) in less time.... especially if you do transactions on your pc that you don't want someone stealing passwords, etc.

Last edited by nezlie; 03-07-2013 at 06:23 AM..
Reply With Quote Quick reply to this message
 
Old 03-11-2013, 06:09 AM
 
223 posts, read 732,538 times
Reputation: 257
Quote:
Originally Posted by nezlie View Post
I would download TDSSKiller and run it to remove the Zeroaccess trojan. It's a quick download and the scan is quick also.

Kaspersky TDSSKiller - Download

If that didn't work, I would pull the plug (restore your pc to factory settings with a CD or from the hard drive partition) like TurcoLoco suggested. I think you can waste more time searching for viruses when the computer can be made clean (like when you first bought it on day one) in less time.... especially if you do transactions on your pc that you don't want someone stealing passwords, etc.
I've used TDSSKiller recently and was amazed how well it worked. Awesome tool!
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Computers

All times are GMT -6. The time now is 06:04 AM.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top