Crashing and viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackfoger1, Mar 20, 2007.

  1. blackfoger1

    blackfoger1 Private E-2

    My computer keeps crashing whenever i run a program that takes alot of computer power/usuage any sweeper or remove program crashes before it finishes. I cant even run PC tools antivirus. After that everytime i boot up a get a voice over my speaker saying system failure beepbeep (hard to understand) test. The time it takes to crash is anywhere 5 minutes to an hour while playing a game. Keeping the computer off for awile lets me get more time before the next crash. Each time i run my virus scanner it detects 5 viruses yet i cant remove them because i crash each time what should I do, just reformat and call it a day?? Please give me the instructions in slow steps im not that computer savy.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Problems like you are describing are typically related to issues other than malware. However the only way we can rule out malware completely is for you to run thru the below procedure as best as possible. Just remember that the more you complete and the more info in the form of logs that you provide, the greater the chance that we can help you.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. blackfoger1

    blackfoger1 Private E-2

    the only log i have is hackthis because the other crash when i try and i cant even reformat because it crashes.
     

    Attached Files:

    Last edited by a moderator: Mar 25, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you did not even make an attempt to follow the directions in the READ ME. You did not even rename HijackThis as requested, and you did not attach the log. Also you are using MSconfig to control startups which we also requested that you not do in the READ ME. Also if you can run HijackThis, you can more than likely can run GetRunKey and ShowNew. They require no installation and are just simple scripts.

    Without logs we cannot help you remove all your malware problems. HijackThis logs by themselves are totally inadequate. Try doing the below!
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Continnue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Note: some items mentioned below may have already been fixed by running ComboFix so if you do not see them, just ignore and continue.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    F2 - REG:system.ini: UserInit=userinit.exe,jggacpm.exe
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O4 - HKLM\..\Run: [win.exeouter.exeg] C:\WINDOWS\system32\win.exeouter.exeg
    O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\system32\loadadv64
    O4 - HKLM\..\Run: [2chkdsk] "rundll32.exe" "C:\WINDOWS\system32\hkljpsjf.dll",setvm
    O4 - HKLM\..\Run: [ula0U] "C:\WINDOWS\system32\slk8x2peu.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [BBBBC1BEBEBEBDB] 4A4A504D4D4D4.exe
    O4 - HKLM\..\Run: [4F8P39W] ec187em.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [Snbbn] C:\WINDOWS\system32\??rss.exe
    O4 - HKCU\..\Run: [Cdkjcnhb] C:\Program Files\?racle\?srss.exe
    O15 - Trusted Zone: *.napster.com
    O15 - Trusted Zone: http://locator.cdn.imageservr.com (HKLM)
    O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
    O20 - AppInit_DLLs: wowexec.dll


    NOTE: HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.


    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\windows\system32\jggacpm.exe
    C:\WINDOWS\system32\win.exeouter.exeg
    C:\WINDOWS\system32\loadadv64
    C:\WINDOWS\system32\hkljpsjf.dll
    C:\WINDOWS\system32\slk8x2peu.exe
    c:\windows\system32\4A4A504D4D4D4.exe
    c:\windows\system32\ec187em.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. c:\ComboFix.txt
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  5. blackfoger1

    blackfoger1 Private E-2

    Inline ComboFix and GetRunKey logs removed.
     
    Last edited by a moderator: Mar 27, 2007
  6. blackfoger1

    blackfoger1 Private E-2

    Inline duplicate GetRunKey log removed. Also inline HJT log removed
     
    Last edited by a moderator: Mar 27, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow instructions and attach logs! Do not post them inline! Posting them inline clutters up the thread and it even ruins the formatting of tools like GetRunKey, ShowNew and ComboFix and makes the logs too hard to read and requires too much time on our part. Since your logs were not posted properly per forum guidelines and because they are too hard to read this way, they were deleted. Please attach the four requested logs. Also you did not indicate how things are working now.

    Why is your HijackThis log so much smaller than the first time? Have you been fixing things with HijackThis on your own? If so, you removed things that you probably need.

    Also you posted the log for GetRunKey twice and never posted the ShowNew log.
     
  8. blackfoger1

    blackfoger1 Private E-2

    my comp is running faster in broswer but still having crashes and i fixed the hijack once by accident and couldnt add the newfiles.txt its too big
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain what you mean in greater detail. I have no idea what you mean. What hijack did you fix and what to you mean by accident?

    If what you meant to say is that you used HijackThis and just randomly fixed a whole bunch of things that it showed, well that was not a good idea. HijackThis does not report malware. It is not a malware scanner. Whatever you fixed with HijackThis you should restore from the backups that HijackThis makes. If you did not have HJT installed properly before fixing things or if you deleted the backups, you may have to reinstall your OS or at least all the applications that you may require to run properly at startup.

    Please download the current version of ShowNew which was just updated and use it to get a new log. Attach the new log.

    Also you need to attach a current HijackThis log.
     
  10. blackfoger1

    blackfoger1 Private E-2

    when i first went through the read me I accidently fixed everything before i saw the message below it. Now my computer can't connect to servers I.E. ventrilo or any online game where is the new version of ShowNew because I have checked the forums can't see it here is my newest Hijack this log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do what I said and restore everything from the HijackThis backups under the Misc Tools. You should have done this before attaching a new log.

     
  12. blackfoger1

    blackfoger1 Private E-2

    I just used the Newest version and it still can't seem to fit its the same amount of Mb's and I am posting my restored hijack this log with everything restored. Thank you for putting up with my annoying screw ups first time doing this is not my field. One item in Hijack this doesnt want to restore I have tried a couple times.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should only be about 30 to 50 Kbytes in size. This would be typical. It should not be Megabytes. Are you sure you are using version 0.33? Look at the top view lines of the newfiles.txt log. Does it look like the below
    Code:
    ******************************************************************************
    *             ShowNew.Bat - (c) 07/01/2006 By Chaslang                       *
    *                                                                            *
    *  03/26/2007 Version 0.33 beta                                              *
    *                - Fixed AllUsers to not be recursive - logs too big!        *
    ******************************************************************************

    Are things working a little better now that you restored everything?

    What is the item that you cannot restore?
     
  14. blackfoger1

    blackfoger1 Private E-2

    Overall things are the same can't see any changes the file i cant seem to restore is F2-Reg:system.ini: UserInit=userinit.exe,jggacpm.exe
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is restored and you don't need it anyway!

    Now I want you to redo ALL of the steps that I gave you in message number 4. Don't do anything except what I ask you to do. Don't run any other scanners or tools....etc. Only do exactly what is requested. Restoring things from HijackThis to correct that fact that you removed things you needed, also restore the malware so we need to start over again. Some items may no longer exist, just continue through all steps anyway.

    By the way it looks like you delete Internet Explorer along the way. I say this because HijackThis cannot determine the version number. Does IE still run on your PC?
     
  16. blackfoger1

    blackfoger1 Private E-2

    I think about 9 months back i might have deleted it for firefox why is it nesscary? and will you be on in about 20 minutes cause i want to fix this dang machine soon .
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I'm not sure about that since your first HJT log posted in message # 3 found the version for IE. And yes you do need it. It is an integral part of the Windows OS and if deleted or disabled you will have problems accessing many websites that require IE. Especially Microsoft websites!! You will not be able to download and install all of your required patches from Microsoft for all of their software (including Windows) without IE.

    Does the below file exist?
    C:\Program Files\Internet Explorer\iexplore.exe

    I'm not sure how much longer I will be around. I'm been up for 20 hrs straight right now. Post your logs when you complete the steps and we shall see.
     
  18. blackfoger1

    blackfoger1 Private E-2

    ok did the steps in order but when i did HJT i didnt get the note "HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue." and when i rebooted i got a new message Incd isn't registered or found something to that nature and im half done with my logs now
     

    Attached Files:

  19. blackfoger1

    blackfoger1 Private E-2

    heres the other 2
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still use InCD? You may have corrupted your installation.

    Get Started with the below while I look at the rest of your logs!

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  21. blackfoger1

    blackfoger1 Private E-2

    I saw the message again on Reboot It said Incd is not installed properly please reinstall and i just restored the files
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean by restored???? From where?

    You never answered my question about C:\Program Files\Internet Explorer\iexplore.exe

    Uninstall the below software:
    Mozilla Firefox (1.5.0.11) <--- this is out of date. I give a link to the new version below!
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Then install the current version of FireFox from: Mozilla Firefox

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: (no name) - 3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [LorFRVa3T] ixsnap.exe
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCfox000

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me if you get a success message about adding the above to the registry. This is important!


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\Downloaded Program Files\btiein.dll]
    C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx
    C:\WINDOWS\system32\ixsnap.exe
    C:\WINDOWS\sdfje.exe
    C:\WINDOWS\system32\bkipbvvr.dll
    C:\WINDOWS\system32\bmhlghbe.dll
    C:\WINDOWS\system32\ftqwhdci.dll
    C:\WINDOWS\system32\giclnfmn.dll
    C:\WINDOWS\system32\orfbqggt.dll
    C:\WINDOWS\system32\shovvwho.dll
    C:\WINDOWS\system32\uppmkxct.dll
    C:\WINDOWS\system32\wcuwlwtj.dll
    C:\WINDOWS\system32\fjspjlkh.tmp
    C:\WINDOWS\system32\cqjrnoko.ini
    C:\WINDOWS\system32\fjspjlkh.ini
    C:\WINDOWS\system32\fjspjlkh.ini2
    C:\WINDOWS\system32\gvpylfeh.ini
    C:\WINDOWS\system32\lvqoacyq.ini
    C:\WINDOWS\system32\sxlgopdf.ini
    C:\Documents and Settings\james larsen\Local Settings\Temp\bt0311.bat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, I'm done for the night. I'll be back sometime later tomorrow......that is later today.
     
  24. blackfoger1

    blackfoger1 Private E-2

    here is the logs and my comp still can't seem to connect to server which just seemed to happen over night all of the sudden and my start up is slower
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to answer all questions. This is the about the third time I'm asking this.

    I have no idea what you are referring too. What server? Are you getting a message telling you something? What is the message and in what application is it occurring?


    What's your reference point? Your malware appears to be gone. Any remaining problems may be due to things you have done to your PC.


    Did you forget to uninstall Viewpoint Media Player or is it not appearing in Add/Remove programs?

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Have HJT fix the below line:
    R3 - URLSearchHook: (no name) - 3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)

    Attach a new HJT log after doing the above.
     
  26. blackfoger1

    blackfoger1 Private E-2

    I cant connect to servers in general like ventrilo or teamspeak or any games for that matter I'm getting no messages about it other then i can't connect and R3 - URLSearchHook: (no name) - 3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) will not fix everytime i use Hijack this and I said C:\Program Files\Internet Explorer\iexplore.exe is not there i only have 3 folders in the I.E. program folder and yes I forgot to uninstall the Viewpoint media player
     
  27. blackfoger1

    blackfoger1 Private E-2

    nevermind the server issue is not a concern that is my fault trying to connect so don't worry and here is my HJT log hopefully i am done
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see where you said that.

    You need to get iexplore.exe back into that folder. You may be able to find a backup copy of it on your PC someplace. Do a search for it.


    Why are you running two antivirus programs? I see AVG7 and PC Tools Antivirus in your HJT log. See step 3 of the READ ME. Perhaps you may have uninstalled PC Tools Antivirus but it did not uninstall properly. If that is the case, then have HJT fix the below line:

    O4 - HKCU\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN

    Other than the R3 line which your said will not go away you are clean. It is only a minor issue. It could also be an effect of iexplore.exe being missing.
     
  29. blackfoger1

    blackfoger1 Private E-2

    im still crashing and i downloaded IE and i accidently downloaded AVG again i didn't know i had 1 already.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you mean your have crashes of your OS, you will have to post the exact complete error message in a thread in the Software Forum. We have removed your malware so there is nothing else to fix unless you can show me where you are having malware problems.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds