Computer Crashes To Restart

Discussion in 'Malware Help (A Specialist Will Reply)' started by thedon01, Aug 16, 2011.

  1. thedon01

    thedon01 Corporal

    I made a thread about this issue im having, http://forums.majorgeeks.com/showthread.php?t=241570, but i havent heard a response back so i figured to ask in the malware section.

    I'm not sold on it being a malware issue just yet and wanted a second opinion before i go through all the steps of the "read & run me". My problem is at times my computer seems like it's doing too much and restarts itself. I've noticed that it happens at times when i have multiple websites up, music playing, etc. i'm not sure what the problem is because i believe i have adequate memory and proper protection, but here's some basic info of what i have and what the most recent problem consisted of.

    MY PC
    Intel Pentium 4
    3.0GHZ
    Windows Home XP service pack 3
    2 GB Ram
    32 Bit
    I have installed a new CPU (exactly the same as the original)with after market fan roughly 3-4 years ago.
    I have a newer power supply (corsair) purchased last December (2010)
    There arent any bulging capacitors and the PC has been sprayed clean and have plenty of air flow.

    Problem
    PC crashes to restart

    Error report sent to MS

    The following files will be included in this error report
    C:\DOCUME`1\Owner\LOCALS`1\Temp\WER41ae.dir00\Min.081611-01.dmp
    C:\DOCUME`1\Owner\LOCALS`1\Temp\WER41ae.dir00\sysdata.xml

    Error signature
    BCCode:100000d1
    BCP1: QA08000D
    BCP2: 00000002
    BCP3: 00000001
    BCP4: B18491DD
    OSVer: 5_1_2600
    SP: 3_0
    Product: 768_1

    Windows Error Reporting from Microsoft
    http://wer.microsoft.com/responses/....3.0?SGD=5b126b2c-46a5-405d-beff-e644e96e6b49

    This problem has happened only after i had a "system broken file extension" (SBFE) from a virus a few months ago. i removed the problem but, the SBFE continually pops up when i scan with superantispyware. I'm not sure if this is important, but feel that its valid in the situation at hand. Please let me know if i should proceed with the "read & run me".

    Thank you
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see 8 responses all in all. :confused So not sure what you mean there.

    For me to verify if this may be a malware issue you will need to go through the R&R, yes. :)
     
  3. thedon01

    thedon01 Corporal

    someone just responded today and i will follow up with the R&R
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    People responded before today. Attach the logs once you are ready.
     
  5. thedon01

    thedon01 Corporal

    i have reports for Superantispyware, Malwarebytes, and combofix ready to upload. i'm having problems with Root Repeal freezing when i try to start the program. Antispyware/Antivirus/Firewall have all been disabled, but it still freezes. I wanted to see if i should continue with MGtools even though root repeal doesnt work. please let me know
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, do continue on.
     
  7. thedon01

    thedon01 Corporal

    i only have three scans to report. Like i said before Root Repeal freezes, and MGtools loads for a brief second and the command prompt box closes. I've disabled all virus, spyware, and firewall protection. i use Superantispyware, Avast, and Comodo. The scans i have are attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, but more than likely a log could have been created. Check for a C:\MGlogs.zip file please and attach it if you locate it.

    Otherwise, if it really did not produce a log you will have to do this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  9. thedon01

    thedon01 Corporal

    i didn't have any problems running like you said, however i did have individual note pad logs pop up after some scans. i saved them incase something didnt work properly, but i am uploading the mgtools.zip with this post. let me know if you need the individual note pad logs.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.


    Java(TM) 6 Update 22 <--- uninstall this outdated software.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Owner\Local Settings\Application Data\q2f17716jns3bn8e5584
    C:\Documents and Settings\All Users\Application Data\q2f17716jns3bn8e5584
    C:\Documents and Settings\Owner\Templates\q2f17716jns3bn8e5584
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!


    Do you use an Xbox?
     
  11. thedon01

    thedon01 Corporal

    alright i'll go through all those steps and post everything by tomorrow morning. Yes i play Xbox. When do i actually run Combofix?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem.

    Combofix will run when you follow my instructions to run the script I gave you.
     
  13. thedon01

    thedon01 Corporal

    alright ill do it now
     
  14. thedon01

    thedon01 Corporal

    i can't remove the old java. Everytime i use add/remove or ccleaner it freezes and i have to manually restart. It's happened twice thus far. What should i do?
     
  15. thedon01

    thedon01 Corporal

    1. i was able to remove old java and update to new java.

    2. i followed all the instructions

    when running combofix a popup window came up claiming 2 parasites found.

    C:\Program Files\Logitech\ITouch\iTchitk.dll
    C:\Program Files\Common Files\Logitech\Scrolling\LG MsgHk.dll

    When and how do i remove all the programs you asked me to dl?

    Logs attached below except for MGLogs.zip. There's an error stating i already posted it in this thread.
     

    Attached Files:

  16. thedon01

    thedon01 Corporal

    i unzipped the mgtools on my desktop and attached the files
     

    Attached Files:

  17. thedon01

    thedon01 Corporal

    last one
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Double click C:\MGTools.exe (right click and run as admin if using win7 or vista) and run it again, THEN attach the new C:\MGlogs.zip please.
     
  19. thedon01

    thedon01 Corporal

    like i said this is what happens when i try to attach it:

    MGlogs.zip:
    You have already attached this file in thread : Computer Crashes To Restart
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you must be trying to attach an older one. Did you run MGTools again as requested and still have trouble attaching the NEW C:\MGlogs.zip? :confused
     
  21. thedon01

    thedon01 Corporal

    i double clicked the icon on the desktop and it loaded for a brief second like before. you gave me specific directions before to go to Start > Run > cmd > and run the 5 scans individually. Do you want me to do this again?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It does not appear that you followed my instructions to run the Combofix script. I still see the files I wanted dead showing in the latest newfiles.log that you attached for me. Nor did you uninstall outdated Java and install new... Or... you are just attaching old logs.

    So... let's get a fresh look on things.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Documents and Settings\Owner\Local Settings\Application Data\q2f17716jns3bn8e5584
    C:\Documents and Settings\All Users\Application Data\q2f17716jns3bn8e5584
    C:\Documents and Settings\Owner\Templates\q2f17716jns3bn8e5584
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      q2f17716jns3bn8e5584
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  23. thedon01

    thedon01 Corporal

    i dont want to argue, but i can attach a text file showing all the programs loaded on my pc, including the Java update you told me to install. i explained that i was having trouble uninstalling the Java you requested, but successfully removed it none-the-less.

    i created the txt file for combo fix like you requested. Dragged it onto the combofix.exe dekstop file and the program ran itself. i saved the txt file that was created and attached it. i can repeat the process again if you'd like.

    MGtools will not run a scan, the cmd window pops up for a second and disappears, so you suggested i use a start >run > cmd approach, which i did not do one the 2nd request to run mgtools. i can also do this again if you'd like.

    but until i know differently i will continue with your last direction
     
  24. thedon01

    thedon01 Corporal

    attached below
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you are trying to attach the same old log!!! You first need to either rerun MGtools.exe or the C:\MGtools\GetLogs.bat file that Kestrel13! asked you to run. Then a new log would be created.

    If you cannot get it to run properly, then delete the current MGlogs.zip file and rerun the individual programs Kestrel13! asked you to run in msg # 8. This should at least update those few logs and then you can attach the new MGlogs.zip
     
  26. thedon01

    thedon01 Corporal

    newest mglogs.zip
     

    Attached Files:

  27. thedon01

    thedon01 Corporal

    is there anything else i need to do?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not looking like malware is the reason for your crashes, but let's run a couple more checks first.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller

    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Also click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. Let me know what happens when you run this.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot this. Also delete the below two files:


    C:\Documents and Settings\Owner\Local Settings\Application Data\q2f17716jns3bn8e5584
    C:\Documents and Settings\Owner\Templates\q2f17716jns3bn8e5584
     
  30. thedon01

    thedon01 Corporal

    ok i will run the scans tonight as you requested and post the results first thing in the morning
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay!

    Also let me know if you were able to successfully delete those two files
     
  32. thedon01

    thedon01 Corporal

    files deleted and scans attached below.
     

    Attached Files:

  33. thedon01

    thedon01 Corporal

    when doing the sfc scannow i keep getting a "windows file protection" box appear saying "files that are required for windos to run properly must be copied to the DLL Cache" and gives me three options: Retry/Info/Cancel.

    I've inserted my windows xp home edition disc as requested but continualy get this pop up. it doesnt end.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a question. Is the disk that you are putting into your CD drive the same service pack level as you are running? If yes, then check the below links. If it is not the same service pack as you are running, you need the same service pack level CD.


    See if the below links provide any help:

    http://support.microsoft.com/kb/909059

    http://support.microsoft.com/kb/291594
     
  35. thedon01

    thedon01 Corporal

    i would assume that it isnt. the disc i have is version 1.5. it was the original disc that came with the computer. seeing how the pc is older the disc would have to be as well.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is not a service pack version so it may just be some manufacturer disk version. Since you do not have the required CD and you PC seems to have a variety of Windows related problems. I suggest that you go back to the Software Forum and get help on uninstalling SP3. Then redownload it and reinstall it which may help to get all the missing/corrupted files fixed.
     
  37. thedon01

    thedon01 Corporal

    ok i will do, thank you for your help! How do i go about removing all the programs that you guys directed me to use?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the below.

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  39. thedon01

    thedon01 Corporal

    could you help me understand why it takes a long time to shut down and load up? Roughly 5 minutes to shut down, and approx 10-12 minutes to start up. My ATI Radeon side bar that loads on the desktop takes 5 minutes to close. Are these indications of malware or possibly a low amount of ram or anything else?
     
  40. thedon01

    thedon01 Corporal

    today i can't load internet explorer and different programs are freezing left and right. i'm not sure what's going on now, but i had to log on with another computer. please help
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may be due to Windows operating system issues which is why I suggested a reinstall of SP3. However, let me ask you something about what I saw in your MBRcheck log which I had first just thought was simply an unregonized master boot record. The below is from your MBRcheck log
    Code:
          Size  Device Name          MBR Status
      --------------------------------------------
        149 GB  [URL="file://\\.\PhysicalDrive0"]\\.\PhysicalDrive0[/URL]   Windows XP MBR code detected
                SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
        930 GB  [URL="file://\\.\PhysicalDrive2"]\\.\PhysicalDrive2[/URL]   RE: Windows XP MBR code detected
                SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
        465 GB  [URL="file://\\.\PhysicalDrive1"]\\.\PhysicalDrive1[/URL]   RE: Western Digital MBR code detected
                SHA1: CCCF1B32EE08ECFB66B30883CFF6110F69219FEA
    [B][COLOR=purple]    465 GB  [/COLOR][/B][URL="file://\\.\PhysicalDrive3"][B][COLOR=purple]\\.\PhysicalDrive3[/COLOR][/B][/URL][B][COLOR=purple]   RE: Unknown MBR code[/COLOR][/B]
                SHA1: D90653CCC05EE39D4D44E1F67C33297D65F3ED4F
    What is the drive that I highlighted in purple? Is it the same as physical drive 1 which is an Western Digital drive? Are these removable drives? What is physical drive 3 for and does it contain a Windows operating system ( OS ) is is it used to boot a different OS.
     
  42. thedon01

    thedon01 Corporal

    the 3 larger drives are external hard drives and no none of them contain an OS. Windows XP runs off of the 149GB internal hard drive.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Pysically uplug/disconnect all three external drives then reboot. Run another MBRcheck scan and attach the log. Also tell me how things work without these drives connected.


    Remember you do have Windows OS issues to fix.
     
  44. thedon01

    thedon01 Corporal

    sorry for the delay in response. i reformatted the pc to start fresh. i've reinstalled everything piece by piece, but i do have a concern. i ran a scan with Malwarebytes and Avast and it can back clean. i then ran a scan with superantispyware and it came back with "System.BrokenFileAssociation HKCR\.exe". Is that a false positive? I thought that malwarebytes ran a more in depth scan than other spyware removers?

    Are there any Virus/Spyware programs you recommend? Is there any major difference between the free programs that you've had me download in the past vs store bought?
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is just a false detection. This is a normal setting.

    Not necessarily. It looks for what it has been programmed to look for just like other tools. If they were all the same, you would need only one. They are not all the same and some find things others do not. Hence why we use multiple tools.

    In the link I gave you on How to protect yourself from malware!

    There is no perfect solution or perfect scanner. And if we were to test and rate programs today. The ratings would likely be differnent tomorrow due to updates to the programs and due to changes in malware ( thousands of new infections occur each week ). The main difference between tools you pay for and the free tools is that you will also get support ( to some extent ) and you will get some more features. For example, if you purchase Malwarebytes or SUPERAntiSpyware, you will get realtime protection which you don't get in the free versions.

    You can use as many "SCAN ONLY" tools as you want but you must not use duplicate full blown antivirus or antispyware or firewalls.
     
  46. thedon01

    thedon01 Corporal

    i am going to reinstall the comodo firewall today, but how about antivirus? i'm going to check that link, but just wanted your personal opinion.
     
  47. thedon01

    thedon01 Corporal

    ive had another crash. So im almost 100% certain it can't be malware/virus related seeing how i reformatted. Could it be hardware related and if so how do i go about figuring out what is wrong?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never did what I requested in message # 43 so that we could truly verify if the problem is related to the external drives....especially the one with the unknown MBR.

    Formatting a hard disk does not necessarily fix ALL malware problems. For a couple examples, it would not fix infected MBRs and it would not fix an infected BIOS ( BIOS infections are rare, but they do occur ). Also formatting one drives does not fix problems that may be arising due to other drives or any form of removabel media ( even a camera, a phone, a USB flash drive, etc ).
     
  49. thedon01

    thedon01 Corporal

    alright i do the scan mentioned in #43 and post the results
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First unplug ALL of the external drives. Then run the scan and post the results. Then keep the external drives unplugged and test how your PC operates without them plugged in.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds