system restore is back, but other things not

Discussion in 'Malware Help (A Specialist Will Reply)' started by momcrossett, Feb 28, 2008.

  1. momcrossett

    momcrossett Private E-2

    Hi,
    We noticed our first problems with our computer (using Windows XP) when my husband was using ebay and he couldn't open some of the pages because of something called yieldmanager. The volume control button keeps disappearing from the taskbar and when I go into volume contol none of the buttons are able to be clicked. The email wasn't working before I did some of the scans, but it is back, for now. The homepage kept getting changed from google.com to microsoft.com. It appears okay now. I also couldn't use the search function, it showed up as a half white and half blue page with a brown dog on it. It appears to be okay for now. I couldn't use the printer. It appears to be okay for now. I would try to open up system restore, but it only opened as a white box. Now it shows up. I would open up User Accounts in Control Panel and it would be a white box. Now it is back. I don't know what has happened to make the good changes, but I'm also afraid that it can just as quickly go back the other way.
    Here is what I have done:
    I removed programs that I no longer use.
    I used CCleaner and removed items and fixed the registry.
    I downloaded and installed ComboFix and had it do a log for me.
    I downloaded and installed MGtools.exe and had it do a log for me.
    I downloaded and installed Superantispyware and had it do a log for me.
    I only have ZoneAlarm as the only thing in my taskbar.
    I used Diskeeper Lite and defragged my computer.
    I removed any malware using Add/Remove.
    I uninstalled Sun Java and downloaded the most recent Sun Java.
    I set MSConfig to normal startup.
    I emptied the recycle bin.
    I enabled viewing of hidden files.
    Please let me know if I had done what I needed to do to get my computer back working like it should. It has been terribly slow. When I would enter my password on my account and open my account, it would take about 3 minutes to do that. I tried to really pay attention to what I needed to do from information recieved from Major Geeks.
    I'm so thankful that you all are here and albe to help. It sure means alot to someone like me who tries to "first do no harm" to my computer.
    Thank you for any help that you can offer.
    Ruth Ann Crossett
     
    Last edited: Feb 29, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks Ruth Ann!

    Is this the order you did things in or did you do them how we requested in the READ ME. The order is very important
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your ComboFix log shows a load of files on your PC that are for Vista. What was installed by someone on 2-24/2008? I see GoBit Games and Cat's Eye Games installed on that date.

    I don't see any malware problems but I have a couple things for you do below. These will not fix any problems with System Restore. Is that your only remaining problem?

    I see Ewido AntiSpyware running but I don't see it in your installed programs list. Is it still in Add/Remove programs? Ewido has been discontinued since it was purchased by Grisoft and has now become AVG Antispyware.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. momcrossett

    momcrossett Private E-2

    Dear chaslang,
    I did as you asked in your last post.
    I did the fix that you asked me to do in HJT.
    I copied the bold text and saved it to fixme.reg and then I ran the MGtools and attached the file. Almost at the end of the scan an exception appeared and it said:
    Process DLL.exe- Common Language Runtime Debugging Services.
    Application has generated an exception that could not be handled.
    Process id= Oxb28 (2856), Thread id=Oxa6O (2656).
    Click OK to terminate the application.
    Click CANCEL to debug the application.
    I clicked Cancel.
    Then the following box appeared:
    Process DLL.exe- No debugger found.
    Registered JIT debugger is not available. An attempt to launch a JIT debugger with the following command resulted in an error code of 0X2 (2). Please check computer settings.
    cordbg.exe !a OxcdO
    Click on retry to have the process wait while attaching a debugger manually.
    Click on Cancel to abort the JIT debug request.
    I clicked Cancel.
    I am still having trouble with the volume control shortcut disappearing from the taskbar every time the computer is turned off or accounts changed. When I go into the Control Panel and check the volume icon, I'm not able to click on anything. So, we don't have sound.
    Can I safely run SUPERantispyware, Adware 2007 and Spybot Search and Destroy with Zone Alarm Internet Security Suite 2007?
    You had asked before what order I did some of the computer clean up because you said that it mattered. Here is the order that I remember to the best of my ability:
    I did the computer maintenance first.
    I checked Add/Remove for any game or utility or toolbar I wasn't using and I removed it.
    I cleaned the hard drive and removed invalid registry issues using CCleaner.
    I defragged the hard drive using Diskeeper Lite
    I rechecked Add/Remove for the list of Malware on Major Geeks-none were shown.
    I uninstalled all old Sun Java versions and update it.
    I used msconfig to set startup mode to normal instead of selective.
    I couldn't find any quarantine files to remove.
    I emptied the recycle bin.
    Since I had already downloaded CCleaner, I just ran it again but I hate to say that I just now saw that I needed to log into the other accounts on my computer.
    I enabled viewing of hidden, system files and file extensions.
    Followed the Windows XP Cleaning Procedure:
    Downloaded SUPERAntispyware
    Downloaded Spybot-Search and Destroy
    Downloaded combofix.exe
    Downloaded MGtools.exe
    Installed SUPERAntispyware, ran it and got the log.
    Installed Spybot-S&D and ran it.
    Ran Combofix and got the log.
    Ran MGtools and got the log.
    Does my computer look any better to you? Is there any way to get the Windows Vista files off the computer. You asked what was installed on 2-24-08 because you saw GoBit Games and Cat's Eye Games. I'm sure that came from me because I had gone to Big Fish Games and was trying a 1 hour tryout of a game called Lucky's Rainbow. I certainly didn't want those two things installed and I also didn't know that they had been installed. Is there any way to get rid of them too?
    Thank you so much for your expertise. It means so much to be able to ask someone for help and be able to trust what information that they give.
    Ruth Ann Crossett
     

    Attached Files:

  5. momcrossett

    momcrossett Private E-2

    I'm probably not doing this the right way, but I have gone onto 4 other accounts on my computer and I'm not able to use the search function on any of them or the system restore. They show up as white boxes. I'm also not able to download CCleaner to clean those other accounts in each account.
    Don't know what is going on here.
    Thanks for any information you can give me.
    Ruth Ann Crossett
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you edit your earlier posts and delete the logs? Now I cannot refer to your previous log for ComboFix or others to see what may have changed.

    Don't worry about this message. We don't need the output from processdll.exe anyway. You appear to have a variety of problems on your PC that all seem to be related to issues within your Windows OS.

    As I said in my previous message, you do not have malware problems. Your problems are related to issues within Windows itself.

    You did not address my question about Ewido.

    You can uninstall anything you do not want to use.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below and let me know if this helps.

    Click Start > Run and enter the below bold print commands (you can copy and paste them) into the run box. Do this one at a time. And after pasting in each click OK.

    regsvr32 jscript

    regsvr32 vbscript

    regsvr32 /i mshtml


    Note there is a space after the regsvr32 and after the /i

    After entering each of these, have any of your problems been resolved? I have to emphasize again that we are not fixing anything related to malware.
     
  8. momcrossett

    momcrossett Private E-2

    Chaslang,
    I copied and pasted each of the items you asked me to and after the last one I got this message box:
    mshtml was loaded, but the DllRegisterServer entry point was not found.
    mshtml does not appear to be a .DLL or .OCX file.
    It hasn't made a difference in the sound properties coming back, also I'm the only account out of the 6 accounts on our family computer that has the ability to use the search function. Everyone else just has the half blue and half white box that shows up.
    It does appear that our computer is working alittle faster. Thanks to you!
    Since you say that it is not a malware problem, but a OS problem, were you saying that you wanted me to start posting to the Software forum? I'm not sure I want to leave your expertise, but I will if you want me to.
    You asked why I edited my earlier posts and deleted the logs because you couldn't refer to my previous log for ComboFix or see anything else that has changed....I didn't even know that had happened. I'm really sorry.
    You also asked about Ewido AntiSpyware. I don't see it in my Add/Remove. We used to use some free AVG stuff awhile ago, but this was news to me that it is running on our computer. I didn't know and I also don't want it running.
    I really do appreciate all that you have been doing to help me. I also apologize for some of the things that I have ignorantly done that have made your job much harder.
    Ruth Ann Crossett
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Search your PC for mshtml.dll and tell me where you find it. There should be quite a few copies around from various updates from Microsoft. Also tell me the file size and date in bytes. You can get this info by right clicking on the file and selecting Properties.

    Let's see if we can get the last file restored first and rerun the command and then we will see.


    You also asked about Ewido AntiSpyware. I don't see it in my Add/Remove. We used to use some free AVG stuff awhile ago, but this was news to me that it is running on our computer. I didn't know and I also don't want it running.[/quote]Let's see if we can remove it.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ewido anti-spyware 4.0 guard
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Now reboot your PC and after reboot, delete the below folder.
    C:\Program Files\ewido anti-spyware 4.0

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
    Last edited: Mar 4, 2008
  10. momcrossett

    momcrossett Private E-2

    Chaslang,
    Please find attached the Word document that shows all the information about mshtml.dll files on my computer. Let me know if what I sent was what you needed.
    I also did as you asked about the Ewido anti-spyware. Good to have that gone!
    I rebooted and here is the MGlogs log.
    Thank you again for the time and brains that you have been spending in my behalf. I really appreciate it!
    Ruth Ann Crossett
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It seems that you do have the mshtml.dll file in the correct location.

    Let's do what we did in message # 32 again but without the /i option.

    Click Start > Run and enter the below bold print commands (you can copy and paste them) into the run box. Do this one at a time. And after pasting in each click OK.

    regsvr32 jscript

    regsvr32 vbscript

    regsvr32 mshtml


    Note there is a space after the regsvr32

    Did that help?
     
  12. momcrossett

    momcrossett Private E-2

    Chaslang,
    I did as you asked to copy and paste each one at a time and nothing seems to have changed. After the last one, I got a message box with RegSvr32 as the title and it said," mshtml was loaded, but the DllRegisterServer entry point was not found. mshtml does not appear to be a .DLL or .OCX file. " I think that was the same message I got last time after I ran the last one.
    I went around to the different members of my family last night and asked them if they were able to use the computer like they used to or if they were experiencing anything out of the ordinary.
    About a month ago, our Internet Explorer icon disappeared off of everyone's desktop.
    No one, except for me, has the ability to use the Search function.
    We are able to open the Sound icon in Control Panel, but aren't able to click on anything. Our volume shortcut disappeared from the taskbar.
    Our clock has just changed itself to a military 24 hour clock and it won't let me change it back.
    Sometimes when Internet Explorer is opened and you go to a page to look at something, then at the bottom, one after another pages will begin to open by themselves, sometimes up to 30 or 40. There might have been more, but we never let it go that long.
    Since I have absolutely no idea how these things have changed, I certainly have no idea how to change them back...but I am willing to work on it. Thanks again for your help!
    Ruth Ann Crossett
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still sounds like much of this may not be due to malware but let's try a few things.

    First let's try to fix your clock.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    Did that work?

    Now click Start, Run, and enter sfc /scannow into the run box and click OK. Note that there is a space after sfc. This will run System File Checker to look for missing and corrupt files. If it finds problems it will attempt to fix them. This could result in it asking for your Windows XP SP2 CD so be ready to put it into your CD drive. Reboot after running this. After reboot see if any symptoms have changed.

    Did sfc run? Did it ask for your CD?
     
  14. momcrossett

    momcrossett Private E-2

    Chaslang,
    I have been out of town and have just now read your latest thread. I think the clock is now fixed...thank you! No one changed it, it just changed itself...how does that happen?
    I also ran the sfc /scannow. It didn't ask me for my Windows XP SP2 CD and I'm glad, as I don't have one. I did reboot and nothing seems to have changed.
    My account and time spent on internet explorer seems to be better than everyone else's account on my computer. They still don't have the ability to search for files.
    As of this afternoon (the sound was was fine this morning), I don't have the ability to open the sound icon in control panel and it has disappeared from the taskbar. I also noticed that instead of what is normally listed in the boxes (SoundMAX Digital Audio) it now says Modem #7 line. This occurred without anyone using the computer.
    My husband now says that his Windows Media Player 11.0 won't open. He did uninstall it and reinstalled it and it didn't help.
    Everyone is complaining how slow the computer is and they are starting (and rather heatedly) to say that we ought to reinstall Windows XP on our computer. Isn't that done as a last defense? I didn't think it was the solution for a slow running computer that has lost some of it's functions.
    I will continue to work on the computers problems as long as you need me to.
    Thanks again for your help so far.
    Ruth Ann Crossett
     
    Last edited: Mar 11, 2008
  15. momcrossett

    momcrossett Private E-2

    Chaslang,
    I turned the computer off this afternoon and when it started, it started the CHKDSK on it's own when it came back on. It said it was checking the file system on C: The type of the file system is NTFS. The volume is dirty.
    Does this mean anything important?
    Ruth Ann Crossett
     
  16. momcrossett

    momcrossett Private E-2

    Chaslang,
    For awhile our volume control button was on and staying in the taskbar where I wanted it to be. Now whenever I want sound on the computer I have to go to Add/Remove and remove "Conexant D850 56K V.9x DFVc Modem". Then I go to Add Hardware and the Add Hardware Wizard comes on and lists all the new hardware (sound) that I'm adding. It lists two things:
    "Conexant D850 56K V.9x DFVc Modem" and "Modem Audio Device". Then the sound is back on the computer and in the control panel I can access the sound icon and make changes. Once I turn the computer off, the sound goes away until the next day when I have to do that process all over again or else use the computer without sound. Is this in any way related to the other problems that I'm having?
    Thanks! Ruth Ann Crossett
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If ComboFix does not run 100% correctly this can happen since it changes the clock to 24 hr mode and is supposed to change it back when it finishes.

    Perhaps you need to be working on the other accounts however this would really be an issue for the Software Forum.

    Again these are issues for the Software Forum or possibly Hardware as relates to sound.

    A reinstall may be your best bet if no reasons for the problems are found in the Software Forum.

    Do any processes appear to be hogging CPU time (look in Task Manager)?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More reason to look into a reinstall. You could be having hard disk problems. Does this happen on each reboot now? If yes, you can try the below.

    Click Start, Run and type in cmd and click OK. This will open a Command Prompt window.
    Type in chkntfs C: and then hit the enter key.
    This will tell you if the dirty bit is set ("C: is dirty")

    If not dirty, you will see something like the below:
    If it is dirty, type in chkntfs /x C: at the command prompt and this should prevent chkdsk from scanning drive C: at startup.

    You can read more about Dirty Volumes in the below link:

    http://technet2.microsoft.com/windowsserver/en/library/577908b1-db9b-401e-ba41-988b16b453001033.mspx?mfr=true
     
  19. momcrossett

    momcrossett Private E-2

    Chaslang,
    I did as you asked and was told that C: was not dirty.
    I also looked at the Task Manager and it looks like the System Idle Process is the only one that is hogging CPU. It is usually above 80.
    I don't know if that is what you needed.
    Do you want me to move along to the Software forum?
    You have been very helpful and have spent alot of time doing it. Thank you!
    Ruth Ann Crossett
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Idle Process is not a process. It is a measure of the time your CPU is doing nothing which should normally be at about 98 to 99 unless you are running some kind of active process or scan. So what is using the other 20% is the issue.

    Probably very soon. Just answer the above question.
     
  21. momcrossett

    momcrossett Private E-2

    Chaslang,
    It looks like:
    Scanning Process is #1
    MsMpEng.exe is #2
    vsmon.exe is #3
    MSASCui.exe is #4

    Of course there is some fluctuation but for the most part that appears to be what is using the most CPU.
    Ruth Ann Crossett
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is Scanning Process? You had no such process listed in your last MGlogs.zip file. The # 2 and # 4 processes are from Windows Defender which is not very good in the Windows XP version anyway so I would uninstall it and use something better as listed in our How to protect yourself sticky thread. The # 3 process is ZoneAlarm which can be resource greedy on some PCs. Especially the newer versions of ZoneAlarm. You could look into one of the other free firewalls mentions in the same How to protect yourself sticky.


    Did you install an antivirus program yet? Your previous logs should you did not have one installed.
     
  23. momcrossett

    momcrossett Private E-2

    Chaslang,
    I have no idea what Scanning Process is. I don't open Task Manager on a regular basis and of course I have no idea what is supposed to be there and what isn't.
    I used Add/Remove and removed Windows Defender.
    Are you saying that ZoneAlarm Internet Security Suite 2007 is resource greedy? Of course this is one of those things that my husband recently bought for our computer. It has an anti-virus program in it, so that is what we use. It also has it's own firewall.
    I also don't know what a sticky thread is or how to get to "How to protect yourself" sticky thread. Please let me know how to get to it.
    Thanks!
    Ruth Ann Crossett
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you something else to run that we can get 1000 times more and better information from than Task Manager which is rather archaic. I'll give you this info later. But since you now siad you have ZoneAlarm ISS, I would bet it is a process related to it.

    I did not realize you install the Security Suite. I was thinking you just had the firewall. The answer is yes. ALL Security Suites are pigs.

    The READ & RUN ME is a sticky! ;) When you come to the Malware Forum ( http://forums.majorgeeks.com/forumdisplay.php?f=35 ) every page that you are on in the forum will show the below (click the image to enlarge) at the top of the list of threads
    stickies.jpg
    Notice they say Sticky: and also notice to the right side they show what looks like a red pin to use in hanging up notes. ;) Sticky = Pinned Some people/forums say sticky and some say pinned. They are put in the forums because they are important facts that need to be read. Notice the How to Protect yourself sticky and also the READ ME.

    Now back to your process list.


    Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on Scanning Process (or whatever it is named).
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
     
  25. momcrossett

    momcrossett Private E-2

    Chaslang,
    I downloaded Process Explorer and I'm attaching the process list as you asked. I forgot to tell you that we are also getting the following message on a regular basis:
    Generic Host Process for Win32 Services has encountered a problem
    Does that mean anything?
    Thank you for explaining about sticky notes. I printed off the 7 pages of how to protect yourself from malware and will sit down and read it. It is a great service that you are doing....I hope you know that.
    Thanks again!
    Ruth Ann Crossett
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just more signs of issues within your Windows Operating System and more for the Software Forum.

    That process was for ZoneAlarm:
    Code:
    ScanningProcess.exe 1860  C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    Your System Idle Process was at 98.46% in that log which is pretty good. Thus at this point I suggest you prepare a list of all remaining issues and post them in the Software Forum.
     
  27. momcrossett

    momcrossett Private E-2

    Chaslang,
    Thanks so much again for all your help. I will now move along to the Software Forum knowing that I don't have Malware on my computer.
    Ruth Ann Crossett
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds