All Scans Crash PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by blackandwhitefeathers, Apr 16, 2013.

  1. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Hi guys, thanks for reading this; I need some help.

    My laptop crashes during any scan that checks all files, but these run OK in safe mode. Nothing is found. There is no BSOD it just shuts itself down.

    Things that I know crash it:
    ESET nod32 antivirus
    defraggler
    mbam
    super antispyware

    I can't find the MBAM log file but I can guarantee nothing was found. I will rescan to be sure (because safe mode) after posting.

    The weird thing is that my grandmother's PC started doing the exact same thing around the same time.

    PS - I know I have COMODO and ESET installed but comodo AV is disabled. This crashing was also occurring before I updated.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello, blackandwhitefeathers :)

    Is there a chance your laptop is overheating? Check the fan underneath it, is it spinning as it should? Does it feel abnormally hot to the touch?

    Your logs are clean but we can run a few more checks if you'd like. The PC never shuts down while in Safe Mode? How long are you able to stay in Safe Mode without it shutting down?

    Also, did you intentionally put the below file onto your desktop?

    Code:
    C:\Users\Mark\Desktop\comctl32.dll
     
  3. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Thanks for the reply. I'll have to look into the heat issue I hadn't really thought of that. The DLL file is there from an old virus we had that corrupted the original we just left a copy on the desktop I guess. Anyway the machine can stay on indefinitely in safe mode it only crashes in normal mode.

    What additional Scans would you recommend?
     
  4. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    So I installed speed fan and monitored it and posted the computer up on a cooling pad and it still shut itself off during scanning and during reboot it also gives a message saying insert boot media And won't boot until I press in the power button and restart. Temps didn't get over 45C.

    Sorry for my lack of punctuation I'm relying on Siri for this
     
  5. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Quick update I'm running prime 95 to check for heat issues on the cooling pad if that lasts for a couple hours I'm going to put it back on the desktop and try it there.
     
  6. thisisu

    thisisu Malware Consultant

    We are mostly removing some unneeded startups here. Nothing actually malware related. Will run some additional scans if the problems you are experiencing persist.

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:

    • DriverTuner 3.1.0.0
    • Spybot - Search & Destroy

    __

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:
    • O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
    • O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __


    [​IMG] Fix items using OTL by OldTimer

    Download OTL.exe using the above link.
    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    [COLOR="DarkRed"]:services [/COLOR]
    SDScannerService
    SDUpdateService
    SDWSCService
    Amsp
    TiMiniService
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Program Files\Trend Micro
    C:\Windows\tasks\Google*.job /d
    [COLOR="DarkRed"]:reg[/COLOR]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"=-
    "FileHippo.com"=-
    "Skype"=-
    "Spybot-S&D Cleaning"=-
    "SUPERAntiSpyware"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "ASUSPRP"=-
    "ATKMEDIA"=-
    "ATKOSD2"=-
    "HControlUser"=-
    "Nuance PDF Reader-reminder"=-
    "SonicMasterTray"=-
    "UpdateLBPShortCut"=-
    "UpdateP2GoShortCut"=-
    "Wireless Console 3"=-
    "SDTray"=-
    "APSDaemon"=-
    "CarboniteSetupLite"=-
    "MaxMenuMgr"=-
    "gbrspcontrol"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
    "{22C7F6C6-8D67-4534-92B5-529A0EC09405}"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CA1377B-DC1D-4A52-9585-6E06050FAC53}]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "ASUSPRP"=-
    "ATKMEDIA"=-
    "ATKOSD2"=-
    "HControlUser"=-
    "Nuance PDF Reader-reminder"=-
    "SonicMasterTray"=-
    "UpdateLBPShortCut"=-
    "UpdateP2GoShortCut"=-
    "Wireless Console 3"=-
    "SDTray"=-
    "APSDaemon"=-
    "CarboniteSetupLite"=-
    "MaxMenuMgr"=-
    "gbrspcontrol"=-
    [HKEY_USERS\S-1-5-21-24970489-308164036-572334443-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "Google Update"=-
    "FileHippo.com"=-
    "Skype"=-
    "Spybot-S&D Cleaning"=-
    "SUPERAntiSpyware"=-
    [COLOR="DarkRed"]:commands[/COLOR]
    [createrestorepoint]
    [emptytemp]
    
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)
     
    Last edited: Apr 18, 2013
  7. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Alright, here's the OTL log.

    Gonna try MBAM and see if I crash.
     

    Attached Files:

  8. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Yeah, it still crashes.

    I saw one BSOD briefly during a scan but it was too quick for me to read it.

    The second time it crashed the scan actually completed but the PC started shutting itself down but seemed unable to close MBAM. Nothing else was responding so I pressed the scan button and noted that the program could not access the C or D drive; they didn't show up in the list of drives available for scanning. When I closed MBAM it restarted and I was greeted by the screen in the attached image (i also pressed a key, which is why it is repeated). I had to hard reset here to get back into Windows.

    FWIW, the Prime95 test went just fine - 74-76C maintained over several hours with no problems.
     

    Attached Files:

  9. thisisu

    thisisu Malware Consultant

    That's very high actually.

    74 - 76 C = 165.2 - 168.8 F

    Heading home from work.. will post more later after reviewing your log.
     
  10. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    Hi,

    I don't want to be rude but it has been a while and I'm still having this issue.. the laptop is cool during the scan but it rapidly shuts itself off towards the end / immediately after.

    It isn't instant like cutting the power but behaves almost like a typical shutdown however unbidden.

    When it is convenient for you - and I mean that - could I have some guidance?

    Thank you very much!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about the delay. thisisu is not regularly posting here anymore.

    Based on your logs, I do not believe you are having malware problems. This is a hardware issue of some type. You would be better off posting in the Hardware Forum.
     
  12. blackandwhitefeathers

    blackandwhitefeathers Private E-2

    All right - I've posted over there. Thank you to both of you for your help!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome from both of us. ;) Hope you get it fixed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds