help system locks up !!!! dr watson are you out there

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by billybudd, Apr 20, 2009.

  1. billybudd

    billybudd Private E-2

    system info:
    HPdv6000
    1.61ghx 1.43gb ram
    windows xp sp3
    AMDturion64x2
    Mcafee anti-virus


    this problem seemed to come about after I downloaded all of the windows updates that it had alerted me that it was ready for. After restart the system will not work, after windows loads Dr watson says that there is a post mortem error and them nothing will work. I click anthing get nothing. If I open process manager and shut down dr watson I can click on anything I want and get it to start to open but after about thirty seconds it will not respond again. the icons will refresh ever 2 min or so if I let the system just sit. what ever I have on the system will not allow Mc af ee to work properly as well. before this started to happen I notice that in the process manager that there would always be multiple iexplore.exe open even if I was not on the internet, ending them would only bring them back. I have run all of the malware programs that are asked of me and the logs are included. Please help as I am sending you this message from the safety of safe mode and need this computer to go to school. I hope that I have included what is needed if not let know if there is anything else that I can do to make the this an easier process.
    thank you in advance as I know that someone here will know what to do

    PS in looking at my Hijackthis log I see a program that might be at fault.
    it is in 04 HKLM\..\run, (nwiz) nwiz.exe\install
    ??? this looks like it does not belong, what do you think????
     
  2. billybudd

    billybudd Private E-2

    forgot the logs here they are
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this and see how things run:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\ovefilyje.dat
    C:\WINDOWS\duluqyl.inf  
    C:\WINDOWS\afese.dat
    C:\WINDOWS\cukuce.inf
    C:\WINDOWS\jepo.sys
    C:\WINDOWS\ojataw.dat
    C:\WINDOWS\rybe._dl
    C:\WINDOWS\uwac.bat
    C:\WINDOWS\wakaxih.dl    
    C:\WINDOWS\xapikoxyqy.bat
    C:\WINDOWS\xifonusyx.dll
    C:\WINDOWS\xuxin.lib
    C:\WINDOWS\ysozokojy.reg
    C:\WINDOWS\system32\32giasand.dat
    C:\WINDOWS\system32\betlinje.dat
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp\
    C:\Documents and Settings\xp\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. billybudd

    billybudd Private E-2

    thank you for the response Tim

    I booted in to safe mode when combofix restarted as the first time when it booted to normal mode the log never poped up. I think because of all the things that I have that start when the computer is turned on
    here are the logs that you asked for
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please make sure msconfig is set to normal startup.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * [color=darkred)Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.[/color]
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Files::
    c:\program files\Common Files\eqisusa.lib
    c:\program files\Common Files\ygol.dll
    c:\documents and settings\All Users\Application Data\exelukeciw.bat
    c:\documents and settings\xp\Application Data\ticobo.scr
    c:\documents and settings\xp\Local Settings\Application Data\yxejazyxyv.scr
    c:\documents and settings\xp\Application Data\ivutyfy.bat
    c:\documents and settings\xp\Local Settings\Application Data\xivogoz.reg
    c:\documents and settings\xp\Local Settings\Application Data\ezakydyrux.vbs
    C:\WINDOWS\bovefilyje.dat
    C:\WINDOWS\icukuce.inf
    C:\WINDOWS\ocylitona.scr
    C:\WINDOWS\temp\mcmsc_HdnYVg0q3rFnZwe
    C:\Documents and Settings\xp\Local Settings\Application Data\ezakydyrux.vbs
    C:\Documents and Settings\xp\Local Settings\Application Data\opuvew.db
    C:\Documents and Settings\xp\Local Settings\Application Data\poguv.dl
    C:\Documents and Settings\xp\Local Settings\Application Data\voxa._sy
    C:\Documents and Settings\xp\Local Settings\Application Data\xivogoz.reg
    C:\Documents and Settings\xp\Local Settings\Application Data\ynumovavo.dl
    C:\Documents and Settings\xp\Local Settings\Application Data\yxejazyxyv.scr
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat[/b] file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. billybudd

    billybudd Private E-2

    ok
    I ran everyting like you told me and there is no change in the problems that I was having

    in normal mode
    Icons still refresh every 1-1 1/2 min
    clicking on any icons does nothing
    if I go in to process manager and end dr watson
    I have a about 15-20 seconds where I can open a program then
    everything reverts back to inoperable

    am I doing something wrong??????

    here are the logs

    and thanks for the help tim I konw that you can figure this out
    :major
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you follow the instructions I gave you to do the Combo fix? The log you attached showed it did not remove anything in the fix.

    If you did exactly as I instructed, then we can try using Avenger:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat[/b] file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * Avenger
    * C:\MGlogs.zip
     
  8. billybudd

    billybudd Private E-2

    (before I posted the last set of logs) the first time that I ran combo fix when I inputed the script that you gave me combo fix had to update and then it got closed down so I recopied the script And ran it a second time.

    after running avenger

    I am still having the same issues

    here are the logs I hope that they are telling you what you need

    thak you tim
    here are the logs
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to try running both Combo and MGTools in normal mode>

    Find and delete:
    C:\WINDOWS\mfebcdata --> you can do that in safe mode, but then reboot into normal mode and try to run Combo as well as the MGtools\GetLogs.bat.
     
  10. billybudd

    billybudd Private E-2

    deleted C:\WINDOWS\mfebcdata
    I still had to end dr watson in the process manager before I could do anything
    Ran combofix in normal mode (log attached)


    could not get enough time before lock up to get to mgtools\getlogs.bat in the mgtools folder
    so after trying in vain for about 15 min I put a shortcut to mgtools\getlogs.bat on the desktop I hope that this will get you the info that you need
    at any rate I have attached the MGlogs.zip to this post

    thanks again for helping me and investing your time in doing this for all of us computer novices I know that you can help and debug this thing
     
  11. billybudd

    billybudd Private E-2

    got a little over zelous with the post button and forgot the logs

    :-o:-o:-o
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's use windows explorer to find and delete:
    C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B7.TMP
    C:\Program Files\Common Files\ejifyp.sys

    Now I want you to do this:

    Using BitDefender Online Scan.
     
  13. billybudd

    billybudd Private E-2

    tim

    Can the scan be done in safe mode or must it be done in normal mode ??

    I deleted the files that you asked to be done.
    A courious thing in the windows file there are 138 files with names like ($NtUninstallKB896422$) thet all start with $NtUninstall and end with that same dollar string ($) they all have this name under Folders:spuninst. some are blue colored font Some black font. Are these created by one of the programs that you have had me download? should I be worried about these???
    I am waiting for you answer as to how to go forward with the scan
    thank you
     
  14. billybudd

    billybudd Private E-2

    ok I did the scan in normal mode

    I have attached the logs

    It seems to have found a virus callled gen:trojan.huer in various forms
    it deleted all of them except 1 gen:trojan.heur.254ab4a4a which is atached to a dll file. Don't know if it is a needed file so I will wait for instructions

    i hope that we are colse to getting this solved I am in dire need of this computer as I am trying to go to school online and am getting behind.

    thank you
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ($NtUninstallKB896422$)--> these are all windows update files.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Are you able to continue running in normal mode?
     
  16. billybudd

    billybudd Private E-2

    it seems to be better now no Dr watson debugger error :celebrate:celebrate
    I am running in normal mode.
    are the logs clean?:hyper:hyper


    I have attached the logs that you asked for
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean, but you still need to clean out these folders:
    C:\Documents and Settings\xp\Local Settings\Temp\
    C:\WINDOWS\temp\

    Run CCleaner and then delete anything left over ( you will not be able to delete items from todays date).

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds