[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1565
  • Last Modified:

Virus Restarting Windows Before it can be Scanned

Hi Experts,
I have a PC that has a virus that keeps rebooting the PC.
Windows 7 Pro

You are about to be logged off.
Windows has encountered a critical problem and will restart automatically in one minute. Please save your work now.

I've tried safe mode and safe mode with command line and both shut down.  

Then it downs the PC.  Have about 2 minutes to do anything before it goes down.
I killed some of the processes with Hijack this.

Security Essentials keeps popping up but the system goes down before it can remove them.
Virus: Win32/Sirefef.R

A USB drive does not get recognized soon enough but a CD will.
I've burned a CD & dragged several programs over to try but none of them have enough time to finish.
Combofix  Made it through creating a restore point and started to scan
Rootkit Buster

I can run hijack this and have attached log.
1 Solution
Ess KayEntrapenuerCommented:
restart in safe mode with no networking

Taskmanager - close all processes

and superantispyware

also, if it doent go through the shutdown process, perhaps it is just overheating quickly.
You can try running one of the rogue process stoppers during that interval before shut down. If that doesn't work, you may have to resort to a "Boot CD".

Rogue process stoppers described here:
http://www.experts-exchange.com/A_4922.html Rogue-Killer-What-a-great-name
and here:
http://www.experts-exchange.com/A_5124.html Stop-the-Bleeding-First-Aid-for-Malware

Boot CD's that may work:

@esskayb2d -
In the original question, the asker says that "Safe Mode" doesn't work.
Sudeep SharmaTechnical DesignerCommented:
The advise above from Younghv would work for you.

I suggested the same steps to one of the user and that worked for him, see below links as a proof


Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Iradat SiddiquiCommented:
please use malwarebytes MBAM and after starting the system ,go to the command prompt and keep the command prompt open and type shutdown -a  and when you see any shutdown is initiated run run the shutdown -a command in your command prompt so your system shutdown can be aborted and in the meantime keep on running the MBAM.
sgt_bestAuthor Commented:
I had a linux boot CD that the PC stayed up on so I know it is not hardware shutting it down.  Also, the research I've read on this virus is consistent with the 1 minute warning although the time varies. Sometimes you don't get a desktop, only the warning but most times I have about 2 minutes.  Safe mode with or without networking & command prompt are the same.
Rogue Killer doesn't finish.  Is there a particular # in Rouge Killer to use?

Will superantispyware or Stopzilla be any different as far as how quick they identify and stop the rouge process?

I thought the boot CD is probably the least video game like of my choices.

I downloaded the windows defender offline and made a CD in another PC. It scanned and found the same two viruses and it chose to remove one and disinfect the other but on reboot it came back.  Since it started with a quick scan, I am now repeating with a full scan to root out any Easter eggs...
sgt_bestAuthor Commented:
Full scan with Windows Defender Offline found more instances of the same viruses and I chose to remove rather than disinfect.  Worked.  Virus is gone but can't turn on windows firewall.
Windows Firewall cannot change some of your settings.   Error code 0x80070424.
Back to the knowledge base.

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now