trouble with Vista desktop PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by mudbucket, Jan 24, 2012.

  1. mudbucket

    mudbucket Private E-2

    I have a desktop PC running Vista SP2, that is used by up to 6 family members. Recent problems include: trouble printing wirelessly. Network sharing/issues with W7 laptop. Windows Security Center was disabled. Firewall was on, but Defender was off and not accessible. Avira AntiVir program could not be used properly. System restore was off - there were no restore points. Trouble with internet access, browsers and some other applications would not run. Slow startup/shutdown. Sometimes pulling the plug was the only way to shutdown.

    I have followed the Read and Run Me First steps. I could not update Java in Safe Mode. I have followed the Vista malware removal threads and I have attached the logs. (Thanks chaslang!) Because of the problems, I did everything in Safe Mode. Although Superantispyware removed 76 files, I did not get a log. With Malwarebytes I got an internal error: "failed to expand shell folder userappdata." Not completed. Rolling back changes. I did get through the Combofix scan successfully, despite a warning about the AntiVir program running, but I can't disable the AV!! - I attached the log. The Root Repeal was not responding. I turned the Windows firewall off (oops) and tried again - not responding. I ran MGtools and attached the log.

    When I restarted the PC it was very slow. I logged on as user:administrator there was no desktop, nothing - just a beautiful blue screen! Using Ctrl-Alt-Del and restarting in Safe Mode w/networking got me back to this point. Please let me know what you think. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need you to run the procedure in normal boot mode unless that is impossible. While better than nothing, logs from safe mode do not give us the information we need.

    Also each user account may need to be cleaned if there are really infections present. You need to start with one user account and ALL scans/logs for that user account need to be provided. If other accounts are infected, they would have to be changed to be admin type accounts while cleaning and then changed back to restricted user accounts once deemed clean.

    I see from your safe mode logs, that the Burtis account was used so that is what we will start with. Can you get me at least a log from MGtools run in normal boot mode?
     
  3. mudbucket

    mudbucket Private E-2

    Yes. I attached the log from Normal boot mode, Burtis (Admin).
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thus far I'm not seeing any malware issues. I do see that you seem to have issues with your Windows Environment Variable settings. You are missing at least one normal setting named AppData and this could cause many issues. This is not a malware problem but more of Windows problem.

    Let's see if we can collect some additional info and possibly fix this setting.

    Please download Env.bat and save it to your Desktop. Then right click on the Env.bat and select Run As Administrator. This will run very fast and will add a log to C:\MGlogs.zip. Attach the updated MGlogs.zip file.


    Also do you have any idea what the below is doing as part of your environment variables.
    asl.log=Destination=file;OnFirstLog=command,environment
     
  5. mudbucket

    mudbucket Private E-2

    I ran Env.bat and attached the log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was correct about your AppData environment variable not being set properly. Lets try to fix it.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC and after reboot, to the below.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the TDSSkiller log
    • the MBRcheck log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 26, 2012
  7. mudbucket

    mudbucket Private E-2

    The registry fix got a successful message. However, after reboot i could not open a browser, and the system was very unstable. I downloaded TDSSkiller in Safe Mode, rebooted in Normal Mode and attempted to run from desktop as Admin. The program just hung and a restart did not help. I cannot generate a log.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please continue on to MBRcheck and MGtools.

    You did not answer my earlier question about the below
     
  9. mudbucket

    mudbucket Private E-2

    Time heals. The system became more stable and I was able to log on as Admin and run the scans. I attached the logs. I am fairly certain I ran them all as Administrator.

    As to the earlier question, I totally missed that. :-o
    Answer: I have no clue as to what that is doing as part of my environment variables.
    What's an environment variable?​
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a system setting that can be either a permanent type setting or a temporary setting which stores information about the environment your programs are running in. It is called a variable because they can be modified. Your AppData environment variable had been change to an incorrect value and thus was causing problems for many programs since it was not set to point to where it should point.


    Your MBRcheck log shows the below
    Code:
          Size  Device Name          MBR Status
      --------------------------------------------
        335 GB  [URL="file://\\.\PhysicalDrive0"]\\.\PhysicalDrive0[/URL]   Unknown MBR code
                SHA1: CEFD837A02A1F4445A136688B10013AE4399C2CF
    While an unknown MBR does not necessarily mean it is infected, in many cases it is. And since you are having problems, it may be a good idea to fix yours.

    Before we do this, I have to ask two questions:
    1. Do you have important data backed up?
    2. Do you have your Vista Boot DVD which we will need to use to boot to the System Recovery Environment to repair your MBR?
    Let's also cleanup a few misc non-malware items which may help with your performance issues ( like slow start up ).



    Uninstall the below software:
    Conduit Engine
    Java(TM) 6 Update 24

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
     
  11. mudbucket

    mudbucket Private E-2

    1. I have not backed up any data recently.
    2. I have 3 Windows Vista OS recovery discs on DVD+R
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should back up important data now.

    Those discs are not what you need. They are not bootable Vista discs. Let's see if you can do the below to enter System Recovery Options.



    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • If you can do all of the above to get to the Command Prompt then just type exit in the command prompt to boot back into normal Windows and let me know you were able to do this or not.
    NOTE: You need to follow the rest of my instructions in my previous message anyway before we can proceed to the next stage of fixing your MBR.
     
  13. mudbucket

    mudbucket Private E-2

    I cannot use the Backup utility without getting an error message about a file that can't be found. The system is unstable and limited at this time - I'll keep trying.

    I was able to enter System Recovery Options and get to the command prompt. (x:windows\system32> )

    I don't think I own a bootable Vista disc. My hard drive is partitioned with a FACTORY_IMAGE (D: ) that includes a boot file, and recovery stuff.

    I do not have the files backed up yet, and I think the system will need to be more stable for me to carry out those instructions successfully. I'll keep trying.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to use a Backup program. You can just copy the files/folders you want to copy. You need to copy them someplace not on your PC, like to a CD or DVD or to an external disk drive. If you were trying to use a backup utility to copy them to another copy on the same hard disk then that serves no purpose for why we are backing them up.

    No you need to follow the instructions I gave already. My request for you to backup your files is for what we need to do next.
     
  15. mudbucket

    mudbucket Private E-2

    OK I get that I need to back up files and then follow your previous instructions. I was trying to use the Windows Backup tool to write to DVD.

    My User folder has 160 GB that I want to backup, so I will have to come up with something more than 6 DVDs and a 16GB USB flash drive.

    Once I have my important files backed up I will continue with your instructions in post #10.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Consider purchasing an external USB drive so that you can always use it for backups. A 500GB drive is fairly cheap. And sales on 1 TB ( terabyte ) drives are happening all the time.
     
  17. mudbucket

    mudbucket Private E-2

    I will do that. Thanks!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just post back once you have completed those previous instructions.
     
  19. mudbucket

    mudbucket Private E-2

    I backed up important files. I removed Conduit but I could not uninstall Java (TM) 6 update 24. I could not get the ComboFix to run per the instructions, so I do not have a log. I have the ComboFix app on the desktop and I dragged the .txt file onto it, but it does not start or give me any prompts.
    The system is very slow and not very responsive. I have to use task manager to end tasks, and then restart and/or power down to continue.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OKay follow the same instructions as in message # 12 to boot back into the System Recovery Environment to get to the command prompt. Then in the command prompt window, enter the below commands ( note the space after bootrec ). The second one will reboot the PC. Allow it to boot back to normal Windows
    • bootrec /fixmbr
    • exit
    Once back in Windows...

    Re-run another scan with MBRCheck and attach its latest log.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • the new MBRcheck log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. mudbucket

    mudbucket Private E-2

    I got to the DOS prompt and ran the /fixmbr operation successfully.

    In normal windows the MBRCheck won't run, after 5 min. of waiting a click of the mouse gives me an error message: "The application is not responding" and I have to "End Process".

    I downloaded the MGtools app to the C: drive and tried to run as Admin, (UAC is still off). Same result - It does not run, not responding.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting in safe mode and running both programs.
     
  23. mudbucket

    mudbucket Private E-2

    Again, the computer was idle and with a little time the system seemed to become more stable.

    I noticed that AntiVir Guard was actively picking up on some Malware, and a few windows popped up: Windows backup utility, Lexmark printer, Firefox update, and Adobe update.

    I ran MBRCheck and MGtools and attached the logs. I am in Normal mode and can access the internet so that's an improvement!
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MBR is fixed.
    Then I would suggest that you are not having malware problems. You are likely having issues related to all the software you are loading/running at startup.

    Like what exactly and where. Your logs are clean. The only things we did thus far was fix an unknown MBR which may be the reason why you can access the internet now.

    The MGlogs.zip file you attached is not a new log. The files in it are from 1/27 and yesterday was 2/5 so it would appear that you did not get C:\MGtools\GetLogs.bat to run properly to create a new log. Try running it again and make sure it finishes running. Let me know if there are any problems running. Wait for your startup instabilities to cease before trying to run it.
     
    Last edited: Feb 6, 2012
  25. mudbucket

    mudbucket Private E-2

    Thanks for the MBR fix!

    I attached the latest AVscan logs that I was referring to.

    I ran MGtools and it was slow, but completed successfully. I attached the log.

    I still cannot start the Windows Security Service, Defender is off, it appears that System Restore is functioning.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing of any real concern in there.

    I assume you meant Window Security Center? You have the services for WSC and Defender stopped and disabled. Try starting them and setting the proper

    Please click Start, Run and type services.msc into the Run box and click OK. This will open up the Services form. Scroll down to the Security Center service and double click on it. If the Service status: shows Stopped or Disabled, click the Start button. Does it Start? Make sure that the Startup type is set to Automatic (Delayed Start).

    Now locate the Windows Defender service and Start it and set the Startup type to Automatic, Did this Start?

    Now close the above services forms and reboot your PC. After reboot, get a new log from MGtools and attach it here along with your answers to what happened while trying to start all the above services. Also see if they are still running ( Started ) after the reboot.
     
    Last edited: Mar 5, 2012
  27. mudbucket

    mudbucket Private E-2

    I opened the Security Center service and got the following notification:
    WSC_1.jpg
    Clicked OK. In the properties box the service was Disabled, changed to Automatic (Delayed Start), clicked Apply and got the same notification. Clicked OK and clicked Start.

    The service status in the properties box was Started, but after 20 sec. it changed to Stopped. When I clicked Start again I got the following:
    WSC_2.jpg
    In the services list the Security Center was Disabled.

    I opened the WinDefend service which was Disabled, I changed to Automatic, clicked Apply and then Start. I got the following:
    WDef_1.jpg
    Clicked OK, and tried Start again. I got the following:
    WDef_2.jpg
    Windows Defender did not start. It was listed as Disabled.

    After reboot these services were still Disabled. After each of 4 attempts at rebooting, I could not run MGtools, or open a browser, and Avira AV was not enabled. I am currently in Safe Mode w/networking to post this. I will attempt to run MGtools in Safe Mode and if successful, I will follow up with the log.
     
  28. mudbucket

    mudbucket Private E-2

    The log from MGtools run in Safe Mode is attached.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the below file and save it to your Desktop

    fixservice.reg

    Then right click on it and select Merge and allow it to be added to your registry.
    Then reboot your PC.

    After reboot, check the status of the Security Center and Windows Defender services.


    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the FSS.txt log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. mudbucket

    mudbucket Private E-2

    The system is too unstable to merge the fixservice file with the registry. It hangs and I have to End Process. I tried in normal mode a few times, and again in safe mode where I got this message:
    FS_1.jpg

    The system was too unstable to run the FSS scan in normal mode, so I ran it in safe mode anyway and attached the log.

    I ran the Getlogs.bat file and attached the logs zip file.

    I am still in Safe mode, so I need to restart and see if there is any improvement.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This means part of it worked and part of it did not which is quite normal due to some LEGACY registry keys that were in the simple patch.

    At this point to see what I need to see, logs from normal boot mode are necessary.

    What I gave you would not fix the problems you are having with stability. It was only a quick attempt at trying to kick start the Security Center and Defender services.

    As stated earlier, your problems are really not due to malware. Even the unknown MBR may not have been a real infection. It seems your problems are deep rooted in Windows itself or with hardware or driver software. Or potentially other software you are loading at startup. We could try disabling a variety of startup processes and services to see if it helps. In some cases it may be better to uninstall the software completely. However in the end, you may be looking at a reinstall to fix things.

    One other observation from the last MGlogs.zip obtain in normal bootmode is an excessive number of open TCP/IP connections to your PC. I see more than 8 times the number I normally see on a Vista PC. This could slow you down a lot since. You may be allowing lots of people to connect to your PC due to uTorrent or other similar programs allowing connections to your PC. Possibly some of this is also due to excessive gaming.

    Would you still like to try a few fixes or would you rather bite the bullet and reinstall?
     
    Last edited: Feb 12, 2012
  32. mudbucket

    mudbucket Private E-2

    Reviewing this thread brought up a few questions and a few things unmentioned. Have we determined that that all user accounts are uninfected? Was the AppData environment variable issue corrected properly?

    I hadn't mentioned it but I have a browser redirect problem that I was working on that hasn't been resolved.

    Also, when the system was more stable Avira AntiVir needed to be updated. I uninstalled the old version and did not successfully complete the update installation, so I am without an anti-virus program.

    With regard to your last post, I haven't been able to get any logs from normal boot mode yet. THe system has remained unstable for the last 4-5 days. I would prefer to disable or uninstall things to see if it improves, as before, so I can get logs in Normal mode.

    Regarding the excessive number of open TCP/IP connections, what can I do to reduce this? The PC is used for on-line gaming, is there something that we can do to ensure we are not causing a slow PC?

    I will reinstall the OS if necessary, but I would like to try a few things first (startup programs, uninstall programs etc.) or whatever you may suggest. I am hopeful that we can fix it without needing to reinstall. The system seemed to become more stable after rebooting, with time. That no longer seems to be the case. The MBR repair seemed somewhat effective because we did see some improvement, but that was short lived. I would like to try some other repairs/fixes before biting that bullet.

    For a reinstall, I have 3 Windows Vista OS recovery discs. Is this all i would need?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we have not but it does not matter for the single account the we have been check logs for. They are clean.... unless something new has actually been picked up since last running full scans. However running scans in safe boot mode, could miss things.

    Yes.

    To where and how often? Is this occurring in safe boot mode on your user accout? Also which browser are you using when redirected?

    Then I suggest uninstalling it completely since it is still running and possibly corrupted. Uninstall it right now!!!

    Okay, we will try a couple things.

    My experience is that online gaming always contributes to slow downs. Especially things like Steam which loads services/process everytime you startup.

    Possibly! I don't know what they are. Did you make them, or did they come with the PC?

    Uninstall the below:
    æTorrent
    Spybot - Search & Destroy
    SUPERAntiSpyware
    TeamViewer 6
    uTorrentBar Toolbar

    Delete the below files:
    C:\ProgramData\qjaxlkio.dss
    C:\Users\Burtis\AppData\Local\temp\6nb1wJRF.exe.part
    C:\Users\Burtis\AppData\Local\temp\fb8YmeEs.exe.part
    C:\Users\Burtis\AppData\Local\temp\LbVuSzui.exe.part

    Delete the below folders:
    C:\Users\Burtis\AppData\Local\temp\svba6.tmp
    C:\Users\Burtis\AppData\Local\temp\svpop.tmp

    Now while in Safe Mode, run MSconfig and choose Selective Startup. Then goto the Services tab and first check the Hide all Microsoft Service box at the bottom. Then disable all remaining services you see. Then select the Startup tab and locate each of the below. Names may appear differently.

    [hpsysdrv] c:\hp\support\hpsysdrv.exe
    [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
    [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    [WinampAgent] "C:\Users\Nicky #2\Downloads\Winamp\winampa.exe"
    [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    [lxdwmon.exe] "C:\Program Files\Lexmark 7600 Series\lxdwmon.exe"
    [EzPrint] "C:\Program Files\Lexmark 7600 Series\ezprint.exe"
    [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    [Skytel] Skytel.exe
    [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup
    [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
    [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    [DirectPlayerCore] "C:\Users\Eve\Desktop\NBC Direct\DirectPlayerCore.exe"

    Then uncheck them so that they do not startup. Then click Apply and OK. Then reboot and see if you can run in Normal Boot Mode.

    Also no matter whether it has to be safe mode or normal boot mode works, do the below

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
    Last edited: Feb 12, 2012
  34. mudbucket

    mudbucket Private E-2

    Thanks for the quick response! I uninstalled the listed software, deleted the files and folders, and disabled the recommended services and startup programs. One folder: C:\Users\Burtis\AppData\Local\temp\svpop.tmp was not found, but it may have been deleted when I deleted C:\Users\Burtis\AppData\Local\temp\svba6.tmp.

    I could not run in Normal mode, so I am in Safe mode and I attached the MGtools log.

    Regarding the browser redirect, it would occur in Chrome, and I think that IE and FF had the same issue. When using Google to find a website, if you clicked on a link it would redirect you to a seemingly random website. I noticed if you hit the back button and clicked the same Google link again it would send you to a different site, and after repeating this 3-4 times the link would eventually take you to the correct site. I have not noticed this in Safe mode although I haven't been surfing the web much in this mode. It has been an issue for months, and I did notice that it was still occurring in Normal mode about a week ago when this PC was more stable.

    With regard to the AV software, I have nothing installed. The problem was with installing the update, which I was unsuccessful in completing.

    I made the Vista recovery discs as recommended in this thread: http://forums.majorgeeks.com/showthread.php?t=180835
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run MSconfig again and on the General tab choose the Selective startup radio button. Then in the check boxes below this, uncheck both the Load system services and Load startup items

    Then click Apply and OK and allow your PC to boot normally ( do not choose safe boot ).

    You will not be able to do very much in this mode. We just want to see if it starts up and runs this way without having the extremely slow down issues you have mentioned.

    You will have reboot back to safe mode to use it like you have been using it so you can report to me what happened above.
     
  36. mudbucket

    mudbucket Private E-2

    Under Selective Startup I could uncheck the boxes, but upon clicking "Apply" a screened checkmark would appear in the checkbox for "Load system services." Only the checkbox for "Load startup items" remained unchecked (no matter what I tried). Sooo, I clicked OK and let the PC boot normally.

    It was slow to boot up, but responded quickly once loaded.

    I tried a few things: Control Panel opened. Security Center was off - I could not turn it on. Windows Defender was off - I turned it on(!) and it was able to run a quick scan. System Restore was "not functioning correctly." I tried System Protection - unexpected error, Volume Shadow Copy service not working. I could open Task Manager, OpenOffice Writer, some games (Solitaire), and CCleaner and these programs would function. Could not load Disk Defragmenter from System Tools (just checking - not attempting a defrag now!). Also, FF and IE would load, but no internet access. All of these actions performed quickly, normally.

    I noticed something a little strange - in Normal mode some of the desktop icons have an added-on "Windows shield" on the lower right side.:confused

    When I rebooted in Safe mode I did not have internet, so I ran MSconfig, changed back to Normal startup, and rebooted in Safe mode. Some other programs started that I haven't seen automatically open in Safe mode: LogMeInHamachi and Windows media player.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see an MGlogs.zip obtain from the semi-normal boot mode you were able to get into. Based on what you are saying, your problems are not malware but some software/driver you are loading and I may have to send you to the Software Forum for you to figure out which one or ones. We are way to busy here with malware to work on Windows/software issues.
     
  38. mudbucket

    mudbucket Private E-2

    I feel your pain.
    Thank you for the good news/bad news. I will post an MGlogs.zip soon.
     
  39. mudbucket

    mudbucket Private E-2

    I booted in "semi-normal" mode after running MSconfig and using the Selective Startup as described below. Then I ran MGtools from C:\ as Admin. I attached the MGlogs.zip.
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And it runs okay like this correct?

    If the answer is yes, then what you need to do ( and this will be tedious ) is to stay in this type mode but use the Services tab to slowly start enabling a couple services at a time ( you MUST keep track of what you are doing --- like what is enabled and what is disabled each time ) to see if you can zero in on which item or items when enabled cause the problems that you are having. Just use the Service tab right now and ignore the Startup tab. Obviously you have to reboot after each time you enable a couple services to see the effect. It will not change anything until you reboot.
     
  41. mudbucket

    mudbucket Private E-2

    Yes.

    I followed your recommended procedure and found that the problems are tied to the Print Spooler service. In Selective startup with all but the Print Spooler service checked, the system responds well.

    I can access the internet in this mode, so I downloaded and installed the current version of Avira Free Antivirus (the download was slow +/-400 kB/sec.).
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it would seem that this agrees with what I had stated at the beginning of this thread and that is you don't seem to be having malware problems. Seems you have Windows problems or software/driver conflict issues. You can try uninstalling any other junk you had insatlled ( like all those toolbars and browser helper objects or any other addons to your browser.

    I could look at a new set of logs from MGtools but I don't think I'm going to be able see anything more than what I have been saying about this not being a malware issue.

    Perhaps you should bite the bullet and just do a clean reinstall if you are not happy with the way the system is performing.
     
  43. mudbucket

    mudbucket Private E-2

    Glad to hear it's not malware. I will remove the toolbar, junk etc. I also have that browser redirect issue I need to fix.
    Since there appears to be problems associated with the Print Spooler service I would like to try to fix this.

    Not ready to bite the bullet for a reinstall yet.

    Before i reinstall, could you point me in the right direction in the Software Forum? I'd like to try to correct the issues with the following: Windows Security Center is off, and cant be turned on. WIndows Defender is off and can't be turned on. Windows Firewall is not using the recommended settings. I will need the Print Spooler service working properly, and I'd like to get the wireless printing operational again.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah well this is new info. So let's dig into this. Which browser are you redirected with? Is it only with Firefox ? Does it also happen if Firefox is shutdown and you use Internet Explorer?

    Do you currently have internet access on this PC with how you have it configured? Your last MGlogs.zip showed no internet capability because your DHCP service was still disabled. Also many other services were disabled at the time of that last log. Since you zeroed in on the print spooler problem, please attach a new MGlogs.zip that shows the real current running condition so that I can better tell what if anything is still going on.
     
    Last edited: Feb 25, 2012
  45. mudbucket

    mudbucket Private E-2

    It has been Chrome, FF and IE. I had one redirect using FF today after a Google search and clicking on one of the search results:
    FF_1.jpg
    Later today I used the FF and IE browsers for multiple searches on different user accounts without any issues, so it is not a constant problem.

    I can access the internet running in this mode: Selective Startup with the print spooler service unchecked.
    Although I checked the box for the Avira AV program, it clears itself and so it is also not running in this mode.
    I ran MGTools while in this mode - log is attached.
     

    Attached Files:

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good. Then let's see if you can complete the below which will require having a USB flashdrive. Note, you have an x32 system.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  47. mudbucket

    mudbucket Private E-2

    I downloaded the Farbar recovery scan tool to flash drive, and ran the scan from the command prompt.
    The log is attached.
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  49. mudbucket

    mudbucket Private E-2

    I ran FRST with fixlist.txt on the flashdrive. The log is attached.

    I could not run the Getlogs.bat file after rebooting in Windows Normal mode as requested. (not responding)

    I restarted using MSConfig-Selective startup with the print spooler disabled. I ran THe Getlogs.bat file in this mode. The MGlogs.zip is attached.
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run MSconfig and select the Startup tab. Renable all the startup process you have disable. Do not change the status of the Print Spooler service that you have disable due to the problems it causes. Then click Apply and reboot your PC. See if it runs okay now too. If not, trouble should the startup processes the same way you did with the services to see which ones may be problems.

    After the above reboot, continue on with the below instructions.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista or Win7 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      netsvcs
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      lsass.exe
      nsiproxy.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      tdx.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemdrive%\*.*
      %systemdrive%\MGtools\*.*
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.sys /90
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %windir%\assembly\GAC\*.ini
      %windir%\assembly\GAC_MSIL\*.ini
      %windir%\assembly\gac_32\*.ini
      %windir%\assembly\gac_64\*.ini
      %windir%\assembly\temp\*.ini
      %windir%\assembly\tmp\u /s
      %allusersprofile%\application data\*.exe
      hklm\system\currentcontrolset\services\dhcp
      hklm\system\currentcontrolset\services\afd
      hklm\system\currentcontrolset\services\tdx
      hklm\system\currentcontrolset\services\tcpip
      hklm\system\currentcontrolset\services\nsiproxy
      hklm\software\microsoft\windows\currentversion\run
      hklm\software\microsoft\windows\currentversion\runonce
      
    • Now click the Run Scan button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the OTL.txt and Extra.txt logs
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds