Can't run scans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RayDunne, Oct 27, 2007.

  1. RayDunne

    RayDunne Corporal

    Hi there, I'm trying to clean a PC and am having difficulties. I have been using this site to clean and maintain my PCs for some time now and since the first couple of times, I have been able to correct all the problems that I've had up until now. The PC is running WinXP. It is my sisters PC and she's not sure if things are up to date as far as Windows is concerned. I am on a different PC now and cannot check at this time, but I can post back later with that info. I know that she is running Avast AV, but unsure of firewall. When I turn it on, it ends up at a black screen that says "virus present, continue;Y or N". When I hit Y, Windows will boot most of the time. I can use the PC for a few minutes, but as soon as I try to run SpybotSD, it immediately shuts down. Same for AV and online scans. It is a fairly new PC and it is clean inside so I don't think it is overheating as it only shuts down when I try to run any scans. I went into safe mode and got Ccleaner to run on all accounts, but no Spybot. This started as soon as I installed it and tried to run the program. It seems to have installed as it is on the PC, but it will not run so it has not been updated. The PC was shutting down previously when I was trying to run Avast AV scan, and it also will not run the online scans. I am going to go back on it to get more info about the state of the PC, but I wanted to post this to get the process started and to see if anyone has any idea of what is going on here. I read through a few back posts to see if there was a thread on this, but could not find the exact problems.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest you try our new beta procedure given below

    Read & RUN ME FIRST Before Asking for Support

    Run as much as you can. If you can run things in normal boot mode then please do so. If you cannot run them in normal boot mode, then run them in safe boot mode. If you cannot run certain steps, just tell me when you return but continue on to the next step.
     
  3. RayDunne

    RayDunne Corporal

    Hi chas, and thanks again. I started the procedure you linked and while attempting to run combofix, the PC shutdown and now I can't get it to turn back on for long enough to do anything. I'm starting to suspect bad memory or some other hardware problem? I will let it sit for a few hours while I go to work and try again later. I had the same problem last night, it would start up and work OK for a bit, but once it shuts down a couple of times, it won't start again for awhile. It works OK for normal stuff such as browsing or using explorer, but it dies when I try to run any kind of scan. I will post back later with any results I can get, if any at all. Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you get it to come on again even if in safe mode, then skip right to the part with MGtools.exe and only use this tool to get the MGlogs.zip file that is mentioned. Attach this log if you get it.
     
  5. RayDunne

    RayDunne Corporal

    I can get it to run in safe mode, here's the file from MGTools. I'm not sure if it is right because I couldn't see the "I Accept" button on the HJT window, but I hit Tab and enter on the keyboard and there is a log file in there, so I hope it will help.
     

    Attached Files:

    Last edited: Oct 27, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs don't show any malware that would be causing the kind of problems you are describing. It may be worth a try using System Restore to go back to a point in time before the problems began. You may even want to uninstall Avast to see if it is causing some kind of problem for you.

    Also did your sister install the below?

    O4 - HKLM\..\Run: [trioService] "C:\PROGRA~1\Freeze.com\Halloween\\trioService.exe "


    You should also uninstall the below but if you uninstall them before using a restore point, they will still show up after doing the restore.
    Java(TM) 6 Update 2
    My Web Search (Cursor Mania)
    Sunbelt CounterSpy
     
    Last edited: Oct 28, 2007
  7. RayDunne

    RayDunne Corporal

    OK, thanks, I'll try your recommendations and follow your advise. I just have an issue uninstalling the My Web Search (Cursor Mania). I already tried to, it was one of the first things I tried to do when going through the sticky the first time as it is on the list there. When I try to uninstall, I get an error message;
    RUNDLL - Error loading C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll
    Also she has told me that she recently had the motherboard replaced because they told her that it was causing these problems. She has had them for some time and the place where she bought it tried to fix it by replacing the MB. My guess would be that they stuck the same memory board on the new MB and I am curious as to whether that could be the cause? Should I post in the hardware forum? Thanks for your help again chas. It is much appreciated.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then do this.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then check for the C:\Program Files\My We Search folder (or similar) and delete if found.

    Okay then if she has had these issues for a long time a System Restore may not do any good. Yes you should try posting in the Hardware Forum but you may want to run some memory test tools first to see if they find anything. Also if there are multiple memory devices, you could try uninstalling all but one and rotating thru each one to see if system behavior changes when different RAM modules are used.
     
  9. RayDunne

    RayDunne Corporal

    OK, here's where I'm at. I have followed all recommendations up to this point. I un-installed Avast to see if it was that, but it was not.

    This was something that she installed, it can go if you think it will help.

    I un-installed the Java update 2 and Counterspy, and I followed your directions to get rid of the My Web Search (Cursor Mania) entry.

    There are 4 DIMM slots on the MB and 2 memory modules. I took them both out and then tried each of them in each slot 1 by 1 and it still shuts down upon trying to run any kind of scan. It also shuts down during start-up, but only during POST, not once WinXP starts. When I get Windows to start, the PC works fine for browsing and working with small files and also with multiple applications open. It only crashes when I try to run any kind of scan, but chkdisk has run OK upon a restart when it crashed earlier. I haven't tried to move a large file within the PC yet.

    This is where I am at this point; When I hit the power button, it goes to a screen with 2 options; F10 for Boot Menu and F2 for BIOS Settings. If I don't hit either of those, it goes to another screen with a message that says "F11 to start recovery" with a 3 second timer. If I hit F11, it immediately shuts down. Also on this screen, a message that says "Boot Sector Write!! Virus: Contunue? Y or N_". If I wait until this message appears, or do nothing at all, it shuts down. The only way I can get it to start Windows is to hit the Y button while the 3 second timer for the "F11 to start recovery" message is on the screen. Then Windows works fine as long as I don't try to run any scans.

    The last abnormality (he he) is a small window that pops up during software loading that says "Critical Softwrap... - Softwrap file error 1" with an OK button.

    I'm completely stumped, I just wanted to make this last post in here to see if you had any other ideas before I try to start another thread somewhere else.

    Thanks again for all your help.
    Ray
     
    Last edited: Oct 28, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ahhhh!! I misundestood what you had said earlier. This message you are mentioning normally come from the BIOS have antivirus protection turned on to protect the bootsector. And this can cause problems for anything that legally requires writing to the boot sector like partitioning, formatting, and installing. You should go into the BIOS and disable this protection. It may say something like: Anti-Virus-Protection
     
  11. RayDunne

    RayDunne Corporal

    I disabled it and it didn't help. I think this one is beyond me, save for hardware replacement. Thanks again for your help. Keep up the good work:dood
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean that after disabling this feature of the BIOS that you still get that same message? If yes, double check to make sure the setting was actually saved.
     
  13. RayDunne

    RayDunne Corporal

    No, the message that says "Boot Sector Write!! - Virus : Continue..." does not appear, but the PC is still crashing.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's different and this is more than likely not a malware issue. Exactly when does it crash? Can you run in safe mode?
     
  15. RayDunne

    RayDunne Corporal

    It will start in safe mode, but the behavior is the same.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to run a quick test for rootkits just to be on the safe side. Run the below and attach the requested log.

    Running GMER to detect rootkits


    If the above turns up nothing, I suggest you post this in the Software (maybe Hardware) Forum.
     
  17. RayDunne

    RayDunne Corporal

    It just crashes.
     
    Last edited: Nov 1, 2007
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you get any error messages? If so exactly what do they say?

    Try running GMER in safe mode and also have your internet connection unplugged.

    What happens if you try to run sfc /scannow from a command prompt?
     
  19. RayDunne

    RayDunne Corporal

    No error messages, just immediately shuts off, same as when I try to run ANY type of scan.

    I did run it in safe mode, cable unplugged...

    I didn't try that last bit, "sfc /scannow", but I have given up and gave her PC back. She is going to try to take it to where she got the MB replaced and have them try to do something with it as I have a good feeling that it is a hardware related issue.

    Thank you for all the help chas, keep up the good work, we would all be lost without the precious time of people like yourself and others in here. This is a great site.
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Chaslang is on vacation this week so I am replying to his threads.

    I have only briefly read thru this thread, based on what I've read it does sound to me as it's not malware related and in fact hardware related.

    Hopefully she can get it to the right person who can fix it up for her.

    Good Luck!:major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds