Computer Crashes To Restart

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thedon01, Aug 16, 2011.

  1. thedon01

    thedon01 Corporal

    you got it
     
  2. thedon01

    thedon01 Corporal

    i apologize for the delay, i had a death in the family. i'll post the scan results by the weekend.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem. Sorry for your loss.
    And also describe how things work when there have been no external drives plugged in.
     
  4. thedon01

    thedon01 Corporal

    thank you very much, here is the report you asked me to scan. i did as you said. Here is what i've done since the last time we spoke.

    1. Ran the Malwarebytes scan like you asked

    2. Purchased new Ram (4) 1GB sticks. I removed the previous ram and installed the new ram. A total of 4 gb, but only 3.08 show up in system info. All the Ram are made by the same manufacture and are identical in brand, size, and model.

    What causes only 3.08gb to show instead of the full 4gb? i do have a 32bit system with an older video card (RADEON 9250 which is a 256MB video card). I'm assuming the video card memory plays a role in why my pc isnt showing the full 4gb, but i would assume not the entire 1 gig that's missing.

    So far there havent been any crashes with or without the external hard drives plugged in.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You needed to rerun MBRcheck.

    See this >> http://en.wikipedia.org/wiki/3_GB_barrier
     
  6. thedon01

    thedon01 Corporal

    my apologies, i will run that scan tonight.

    Also, im trying to remove Java 2 Runtime Environment SE v1.4.2 because i have the most recent Java, but i can't remove it.

    i keep getting

    "the feature your are trying to use is on a network resource that is unavailable"

    How do i fix this? i have tried using Start > Control Panel > Add/remove programs & CCleaner, but have the same problem.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. thedon01

    thedon01 Corporal

    installed revo uninstaller and tried to uninstall the old java, but i received the windows installer pop up that says:

    "the path 'C:\Documents and Settings\Owner\Local Settings\Application Data\{7148FOA6-6813-11D6-A77B-00B0D0142000}\Java 2 Runtime Environment, SE v1.4.2msi' cannot be found. Verify that you have access to this location and try again, or try to find the installation package 'Java 2 Runtime Evironment, SE v1.4.2.msi' in a folder from which you can install the product Java 2 Runtime Environment, SE v1.4.2."

    i clicked ok and canceled the search for Java 2 Runtime Environment SE v1.4.2 and Revo went into leftover registry items and there are 12 items in bold with options to delete them. What should i proceed with?
     
    Last edited: Oct 10, 2011
  9. thedon01

    thedon01 Corporal

    the text document has all the programs CClenar shows as able to uninstall. You will see the Java program im talking about.

    i've also noticed that in

    Start > Run > Msconfig > Startup > there are 3 items that don't have a name or a command, just a location. This seemed odd to me and wanted to know if i should do anything.

    I would like to perform all scans once the external hard drives are disconnected, so please let me know if you need me to use any other scans before that.
     
  10. thedon01

    thedon01 Corporal

    attached
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just delete them.


    You need to run MBRcheck and attach the new log that I requested. This is the most important thing you need to do.
     
  12. thedon01

    thedon01 Corporal

    here is the MBR check you asked for. i disconnected the external hard drives as you requested and ran the scan.

    2 more things:

    1. Revo Uninstaller, just to clarify, even though it's unable to uninstall the old java program you want me to remove all "bold" items listed? Will this make my registry unstable?

    2. Internet Explorer tends to run slow and freeze at times. I've even noticed frequent "tab recovered" problems. I've read that this can be associated with certain add ons. So i have tried to run IE 8 without addon's and still come across the lagging and tab recovered issues. MS has a "fix it" program to use when issues like this arise. Should i proceed to use the program?
    http://support.microsoft.com/mats/ie_freezes_or_crashes/en-us
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. You are just having it remove left over dead entries from Java.

    This brings us back around to what I stated earlier. You are not having malware problems. Your issues are all with Windows itself. And you could not run a proper sfc /scannow repair because you don't have a CD. It may or may not have helped.

    You need to work in the Software Forum for further help. There has been no significant malware removed here. The only potential issue is still with that one removable drive that had an unknown MBR. If you still have problems even when it is disconnected, then it is not your problem either.

    You can try the FixIt program if you wish but I have never really seen it do anything useful thus far. That does not mean it never helps. It just means where I have run it, it has never helped. However this is a topic for the Software Forum too. ;)
     
  14. thedon01

    thedon01 Corporal

    since i reformatted i do have an original Windows XP home edition disk. Should i proceed with a sfc/scannow or move over to the software forum?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It needs to be a Win XP SP3 disk to work properly. You can run this scan, but you still need to continue in the Software Forum as you are not having malware problems.
     
  16. thedon01

    thedon01 Corporal

    alright, thank you for all your help
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  18. thedon01

    thedon01 Corporal

    i've had 0 issues with my pc magically shutting down since the last time we talked, but i have noticed issues with web surfing.

    when clicking on web pages the page i've chosen jumps to what appears to be an advertisement web page. the intended search is always on the up and up, but you can watch the address bar change multiple times to an advertisement page. im assuming that's connected to a virus or spyware of some sort. would malwarebytes/superantispyware/avast/and spydoctor detect such issues or would i have to complete the original steps from before?

    In regards to the external drive that was in question i've found

    trojan.Agent/Gen-Autorun[Swisyn]
    P:\SYSTEM VOLUME INFORMATION\_RESTORE{xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxx}\RP151\A0023876.EXE
    P:\SYSTEM VOLUME INFORMATION\_RESTORE{xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxx}\RP151\A0023877.EXE

    the files in question on the external P drive included what appeared to be a 32 digit serial number following the word "RESTORE".

    Also how would i go about learning how to understand the programs you've had me use so that i don't have to continue coming back and wasting your time?
     
    Last edited: Oct 26, 2011
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may just be that you are seeing normal advertisements from the webpages getting loaded. If you are no being redirected, that is if you are not winding up on the wrong site after things load, then it is most likely just the pages/websites that you are loading.

    They would not necessarily find this even if it is malware. It all depends on what it is. If you really suspect malware, you will have to start over again and attach new logs in a NEW thread.

    You have to disable System Restore to remove restore points on the drive while it is plugged in to remove these.

    If you want to learn how to use specialty tools like ComboFix, MGtools, and similar you will have to go through special training which takes a long time.....especially if you are not already an expert on the Windows Operating System. You should never be using specialty tools like this on your own. You could turn your PC into a paper weight. See the below:

    Becoming A Malware Forum Helper
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also one more question. Is the P: drive you mentioned the external drive that had the Unknown MBR that I asked you to unplug to see if your problem went away after unplugging?
     
  21. thedon01

    thedon01 Corporal

    1. I'm definitely going to look into that link you sent me, im very interested.

    2. I believe it's a redirect infection illustrated in the thread i just found last night, http://forums.majorgeeks.com/showthread.php?t=230267. the pages are defintely "redirecting" to others that have nothing to do with the original link. it usually takes 3 or 4 processes (click on Original link > redirected to another page > click back > try original link again) before i can get to the original link i wanted.

    I have 2 PC's on my home network. The one that has the problem, which is the one im posting from and another (my mothers). I've also noticed a random "access violation" error on my mothers. i scanned that computer and found some infections that i successfully removed. This along with being redirected on the problematic PC we're discussing leads me to think there's definitely an infection. if need be i would rather be safe and runs the proper scans than proceed with a possible infection. Should i proceed with the directions from the 'redirect thread' or 'malware removal guide', or both?

    3. Should i try disabling system restore points and do some standard Avast/SAS/Malwarebytes scans before i make a new thread?

    4. I'm almost certain the P:drive is the one with the bad MBR. The only problem i have is determining which 465gb drive is which in the MBR scan because i have 2 externals that both 465gb. is there a way other than process of elimination to determine which is which? I'd prefer to not to start fresh (reformat) with either drive as they store a lot of vital information.
     
  22. thedon01

    thedon01 Corporal

    Here is a common example of what happens. I'm on the site www.freecovers.net looking for a game cover; Fifa 12. I'm signed in and click on the link to display the cover and im redirected to www[dot]hellolocals[dot]com and or www[dot]cheapstuff[dot]com, comparestores[dot]net. i click "back" and go back to try again. It takes 2 two times before i finally get what im looking for.
     
    Last edited by a moderator: Oct 27, 2011
  23. thedon01

    thedon01 Corporal

    So far i followed your thread on fixing google redirection/hijacking problems and still have the same problems. I've gotten to Step 5 where it says to do an MBR check.

    i did the scan and it came back with the same problem we had before (found non-standard or infected MBR). So to identity which drive has the problem i disconnected the P drive, the drive i told you yesterday had errors on it and ran the MBR check again. It came back with the same "found non-standard or infected MBR" so i know the MBR problem is not on the P drive (as it was disconnected during the scan). The drive that has the MBR problem is drive Q.

    i don't know what that means or how to proceed with fixing that external hard drive (drive Q).
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach this last log from MBRcheck while only this Q drive is plugged in.

    Then backup all the data on this drive just to be safe. While most of the time, repairing MBRs works without an issue, it does have the potential to make a drive unbootable.
     
  25. thedon01

    thedon01 Corporal

    will do, and should i continue with the malware removal/cleaning procedures due to the redirect issue?

    I've already gone through the thread about the redirect issue and have moved onto running the malware removal guide. Im currently on step 2/5 doing the malwarebytes anti-malware scan.

    i can have it done by tomorrow if need be, just let me know
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not right now. First let's see if we can repair the MBR.

    Did you backup all important files from this external Q drive ( to your hard disk or to your other removable drive ) as requested? You need to be safe.

    Do you have your Windows Boot CD now incase it is needed?
     
  27. thedon01

    thedon01 Corporal

    i ran the scan with the Q drive disconnected. the results are attached below.

    Currently backing up the files i intend to keep.

    Yes i have the windows boot CD that i used to recently reformat my pc, but i think you addressed the issue that it doesnt have the same service pack.

    I noticed that even with the drive disconnected im still getting the same redirect problems.
     

    Attached Files:

  28. thedon01

    thedon01 Corporal

    the files i intend to keep are quite large in total size so it may take a couple hours tonight, but they are backing up as we speak.

    Since i already began the malware removal guide a 2nd time (as requested from the redirect virus thread) is it safe to continue with hidden files and folders viewable and normal startup mode selected or should i undo these?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not what was wanted. We wanted the log with only the Q drive plugged in.

    Stop all other malware removal activities and just get important files backed up.

    Then give me the proper requested MBRcheck log.


    The issue about not having the proper service pack CD only pertains to being able to run sfc /scannow which I was having you do because you have corrupted or missing system files. This is not a malware issue. You still need to fix your Windows OS to avoid potential crashes like you were complaining about. However if you formatted and reinstall already, your corrupted file issues should be gone. All you needed to do was get all of your updates since your CD is old.
     
  30. thedon01

    thedon01 Corporal

    i forgot to ask something. i had problems running the MBR scan the first time we talked because i didnt have the proper windows CD to boot from and i ended up reformatting my pc. i don't want to go down that path again if i absolutely don't have to. So if i'm receiving a non-standard or infected MBR on this external drive (Q) can i wipe that drive clean and start fresh? i know i said i wanted to refrain from doing so, but if need be i will gladly start fresh on that drive if it solves the problem. i just don't know how to do so.

    I'm not sure if my understanding is correct, but a non standard or infected MBR on drive Q means theres a problem with windows or just the drive in question?
     
  31. thedon01

    thedon01 Corporal

    my apologies, the correct scan is attached now. there are 3 external drives (M/P/Q). i disconnected M & P and kept Q plugged in.
     

    Attached Files:

  32. thedon01

    thedon01 Corporal

    everything is backed up and ready to go
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now do the below with it configured still the same way.

    We will first attempt to fix the MBR with MBRcheck. Sometimes it works and sometimes it does not.

    • Run MBRCheck.exe
    • Wait until you see the following lines:
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
      • Options:
        [1] Dump the MBR of a physical disk to file.
        [2] Restore the MBR of a physical disk with a standard boot code.
        [3] Exit.
        Enter your choice:
    • Please push the 'Y' key and then press Enter
    • When the program asks you to Enter your choice: enter 2 to Rstore the MBR and press the Enter key
    • Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
      • Enter 3 and press the Enter key.
    • The program will show Available MBR codes as below
    • You need to select your version of Windows frrom the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    • The program will prompt for confirmation. Type 'YES' and hit Enter.
    • Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    • You will see all the text in the window get highlighted.
    • Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    • Paste that text into Notepad, save it to your desktop as MBRfix.txt
    • Restart your PC.
    • Attach the MBRfix.txt file to your next message.
    • Also rerun MBRcheck just like you have previously done in the past and now attach this log too.
     
    Last edited: Oct 28, 2011
  34. thedon01

    thedon01 Corporal

    when you asked to rerun MBRcheck just like i have previously done in the past are you referring to running MBR with all externals connected or just drive Q?
     
  35. thedon01

    thedon01 Corporal

    i just ran the MBR scan with only the Q external drive connected. M&P drives were disconnected. Both logs are attached below.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that did not work and now the drive shows as PhysicalDrive1 rather than 3.

    You will have to boot from your Windows XP CD and get into the Recovery Console. From the Recovery Console you will have to run the fixmbr \device\harddisk1 command. Note that there is a space after the fixmbr and note the direction of the \

    See this link http://support.microsoft.com/kb/307654 but skip the installing section and refer to the How to use the Recovery Console section.

    Once you run the fixmbr command, reboot your PC normally and then run MBRcheck again and attach a new log so we can verify if the MBR was fixed.
     
  37. thedon01

    thedon01 Corporal

    i noticed the switch from 3 to 1 as well. when running the recovery console im not prompted with the same steps from that link. the difference is the disc i reformatted with was the Gateway Windows XP Gome Edition operating system version1.5 disc. It's the disc that came with my Pc many years ago. i want to check with you about the specifics before i choose any options.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated earlier, there is no such version of Windows. This is just a version number that Gateway put on the disk. It has nothing to do with Windows. As long as it is a Windows XP boot disk, you should be able to boot to the Recovery Console. If it not a Windows XP boot disc, then you will not be able to use it to get to the Recovery Console.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your disk does not allow you to get into the Recovery Console, you can make a Recovery Console only disk. It cannot be use to reinstall Windows or to fix missing files though.


    If you do not have your Windows XP CD, you can create one with the Recovery Console.
    • Download the ISO file from the below link:
    • Then burn this file to a CD as a disk image file. Do not just copy/burn the file to the CD as a data disk. This will not make a bootable CD.
    • Then see if you can boot from this CD and get into the Recovery Console. See the second section in the below link where it says How to use the Recovery Console
    • If you can get to the command prompt of the Recovery Console, type the below command
      • fixmbr \device\harddisk1
    • and then hit enter. Note that there is a space after the fixmbr and note the direction of the \
    • After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.
    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.

    Note if you are unsure how to burn an image file see the below link which has some additional details:
     
    Last edited: Oct 29, 2011
  40. thedon01

    thedon01 Corporal

    I'm going to just burn the image you suggested as it seems the easier route, the only problem is the link you gave me opens to a blank page. Address = about:blank. is there another link to try?
     
  41. thedon01

    thedon01 Corporal

    i got the link to work, burned an image, loaded correctly. i tried to run fixmbr \device\harddisk1 and the outcome was 'the old master boot record cannot be read'. i typed exit and rebooted and removed cd.
     
  42. thedon01

    thedon01 Corporal

    i removed all data from the drive so if you want to completely erase the damn thing im fine with it. i don't know if that helps in anyway but i wanted you to know.
     
  43. thedon01

    thedon01 Corporal

    i see that your from northern nj i hope the storm didnt knock your power out, hope you're ok.
     
  44. thisisu

    thisisu Malware Consultant

    Hi, thedon01
    As you guessed, chaslang is currently experiencing some power issues. I will try to help you while he is away.

    The Q: drive may have some corruption on it. I have not seen this error message first hand but from what I've read on this error message that is what most people are suggesting. I have asked chaslang as well as he may know more about this.

    You were able to get the data off it without any problems, right?

    Also, I think chaslang asked you this earlier but I wasn't sure if you ever provided an answer. If you leave the Q: external drive unplugged from the PC; do you still experience the random PC crashes/reboots?

    Can you try the below with only the Q: external drive attached!!!

    http://img833.imageshack.us/img833/7035/aswmbricon.gif Please download aswMBR by Avast! to your desktop.
    • Double-click aswMBR.exe to run it (Vista and Win7 right-click and select Run as Administrator)
    • Select No when asked Would you like to download latest Avast! virus definitions?
    • Click the [Scan] button.
      Note: This scan should only take a few seconds to complete.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach items to your post)
     
  45. thedon01

    thedon01 Corporal

    thank you for responding, i figured something was up with chas, hope he's ok.

    yes i copied the files i intended to save off the Q drive, so if you need to reformat in anyway it won't bother me.

    i havent had crash issues since reformatting, whether the Q drive is connected or disconnected, but i am experiencing serious redirect issues. when trying to go to web pages i will get redirected to fake sites. it may take 3-5 tries before i can get the page i want. very frustrating.

    i downloaded the program you suggested and will do the scan and post the results. thank you
     
  46. thedon01

    thedon01 Corporal

    i did the scan with only the Q drive attached and powered on, except for obiously the C: drive (internal). results attached below.
     

    Attached Files:

  47. thisisu

    thisisu Malware Consultant

    It looks like aswMBR only scanned the 160GB internal drive. That's ok.

    If you have all the data backed up from Q: external that you wanted. It will be easiest just to format the Q: drive only. From My Computer, you can find the Western Digital 500gb external hard drive (should be Q: ) and right-mouse click it >> Format...

    See if your problems persist. Also run these afterwards:

    http://img685.imageshack.us/img685/3557/tdsskiller.gif Now we need to run TDSSKiller by Kaspersky
    Follow the instructions here and attach your log when you are finished. (How to attach items to your post)


    Please download MBRCheck by GeeksToGo to your desktop.
    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (Vista and Win7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (How to attach items to your post)
     
  48. thedon01

    thedon01 Corporal

    successfully reformatted drive Q, and ran both scans as requested. Still came back with a bad MBR, but not having a redirect issues as of right now. that could change however as it would take more time for me to verify. logs attached below.
     

    Attached Files:

  49. thisisu

    thisisu Malware Consultant

    Ok, let me know when you get a chance to verify it a bit more.

    Unknown does not necessarily mean infected.
     
  50. thedon01

    thedon01 Corporal

    ok ill get back to you tomorrow on it, thank you
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds