Random reboots while playing.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DeathtoSpyware, Nov 25, 2005.

  1. DeathtoSpyware

    DeathtoSpyware Private E-2

    Hi Im having wierd reboots when I play games, I know im having spyware since my dad wanted to play with the comp.. and screwed up somewhere :(

    Please help me out I have a log with HJT and windows error showing 2 files or something. I runned Panda, Right now Ad-Aware with only 1 or 2 cookies, I ran Ewido killing 2 things but they come back again. I only have 1 anti-virus.
     

    Attached Files:

  2. DeathtoSpyware

    DeathtoSpyware Private E-2

    The windows error.


    Sorry for spam
     

    Attached Files:

  3. DeathtoSpyware

    DeathtoSpyware Private E-2

    Cant delete my post..
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  5. DeathtoSpyware

    DeathtoSpyware Private E-2

    Done all the instructions to hand.

    I stil lhave a random reboot what can I do?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please just finish my previous instructions.
     
  7. DeathtoSpyware

    DeathtoSpyware Private E-2

    Looks like I dont have spyware anymore, since I know how to get RID of it.

    Problem is you dont understand what I got. Its definetely a virus.
    The instructions you are giving me are for "omg a toolbar just appeared in my desktop, what I do? omg" I got a virus. I need some help please, enough with my sarcasm =/

    I had this file in my task manager bwgo0001ebf1.exe <-- changes names randomly. I have it on C://documents and settings/owner/localsettings/temp/

    And when my pc reboots I get the error, that I posted above as an attachment.


    Can you do a check on that file? I did norton, ad-aware, spysweeper, TrojanHunter, none seem to find anything. (just in case you'd asked)

    I will post a HJT log in safe mode in a moment. ( im probably just an idiot and the "dumb" procedures you asked me to do are for something else.. but since I see you tell everyone the same thing I got mad)
     
  8. DeathtoSpyware

    DeathtoSpyware Private E-2

    Safe mode was a typo, I did this on Normal mode.

    I terminated all unnecesary programs, no internet while doing the Scan.

    btw I swear I cant get rid of that logitech thing sry for the big list :rolleyes:

    and the program... remember that name now its bwgo0001c975.exe


    Norton doesnt detect it neither do the spyware programs..
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedures are for all forms of malware (virus, trojan, spyware, adware, popups, hijacks, etc). They are not just for one thing. They are required steps for all users having malware problems. HijackThis logs do not always show everything that could be on a PC. Running all the steps can help to root out other problems that may or may not show in a log.

    Note: As indicated in the READ & RUN ME, HJT logs must be posted from normal boot mode not safe mode.
     
    Last edited: Nov 26, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you skipped running MS Antispyware. Is there a reason why? I see you did run SpySweeper though which is a good removal tool.

    Did you already fix the below line which was in your first log?
    O4 - HKCU\..\Run: [Logitech Desktop Messenger] C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\NewVersion\setup-8876480.exe
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\DOCUME~1\Owner\LOCALS~1\Temp\bwgo0001c975.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - Startup: PowerReg Scheduler.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O18 - Protocol: bw+0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {7F66ABE2-BB24-4917-A009-4CE694774A1D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Documents and Settings\Owner\Local Settings\Temp\bwgo0001c975.exe <--- look for and delete all forms of bwg*.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. DeathtoSpyware

    DeathtoSpyware Private E-2

    Here. Its wierd that it was logictech since I DO have a webcam x_x


    I'll let you know if I get any reboots. Thanks so much for handling my arrogance =)


    Cheers.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really! We see this all the time. Logitech has a problem in this Desktop Messenger crap and hey have never fixed it. It is best to never use it.

    Your log is clean now. Are you problems all gone now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds