computer always freezing

Discussion in 'Malware Help (A Specialist Will Reply)' started by ucdawg12, Jul 5, 2009.

  1. ucdawg12

    ucdawg12 Private E-2

    so last night, for no reason i can think of, my pc started to freeze up every time i'd try to use it. it would get to the desktop and wait between 2-40 minutes before freezing up. it has done the same thing in safe mode with networking but not in the plain safe mode. i have gone through all the tests and scans and stuff now and would really appreciate some help. not much was found. i couldn't get a good report from RootRepeal because my PC would freeze before it would finish. I would see that it found 12 hidden files and that one was like windows\temp\hlktmp and then a few in my local settings that were all the same large random letter directory, something like \eqedfvcbsyhgs_dfswhn\, there were 4 of those, then a hiberfl.sys one in my C:\, which made up 6 of the 12 it found but by the time it found the last 6, the list display part had frozen with the rest of my computer though the scanner did not (the buttons did) i tried running this scan in safe mode but it found nothing. i think its malware though because it doesnt freeze in safe mode.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome to the forums. We are currently reviewing your logs and will get back to you with a set of instructions as soon as we can.

    Thanks for your patience during this time.
    Kes
     
  3. ucdawg12

    ucdawg12 Private E-2

    i know it's against the rules to bump and i have been debating doing this the whole day but i wouldn't be doing this if i didn't think that this thread had been forgotten as i have seen a lot of threads made a few days after this one receiving attention. i am not trying to be obnoxious but i don't know how long to wait.

    i had gotten some updates after my first post but i didn't want to bump it then and get in trouble but i might as well include them in this bump. i have now gotten rootrepeal logs. i hadn't touched this pc all week, but yesterday i did a few more scans with newer definitions and SAS picked up something called PEV.exe, and the Malwarebytes one picked up 2 registry keys that had disabled security functions. These were things they both missed during the scan a week ago. If you want these logs I can post them too.

    Also I have noticed this computer only freezes when it's connected to the internet. It will run fine if there's no cable connected, but with a connection it does freeze.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hadn't forgotton you.. I had been away for the weekend :)

    Please download the below:

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.

    1. FYI:

    Ad-Aware is not as effective as SUPERAntiSpyware and Malwarebytes that we had you install. So we suggest that you uninstall Ad-Aware (unless you purchased it) to avoid wasting any system resources on it.


    2. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    C:\WINDOWS\system32\99D888
    C:\WINDOWS\system32\butenufu
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3.Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix and GMER

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. ucdawg12

    ucdawg12 Private E-2

    thank you so much i appreciate this. my windows\temp folder was pretty empty, but there were 2 files from older dates that i could not delete, i have lost the names because my computer froze again when in process of typing this out but they were from 7/5 and 7/11 and had $$ in their names and extensions and when i tried to delete them they said they were being used, and my unlocker said services.exe was using them. i kept getting a bunch of errors from the MGtools command prompt that I ignored, I'm not sure if that was malware or not.

    edit:sorry forgot to upload logs
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. We need to do the below:

    1... Please ensure all your protection software IE: anti-virus and anti spyware is disabled/shut down before we continue on...

    2... Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    3... Run the new MGTools.exe and attach the log it generates into your next reply.

    4...Download Dr.Web CureIt and save it to your desktop.
    • Doubleclick the cureit-beta.exe file and allow to run
    • If it prompts you about getting any updates, get the update and then rerun the cureit-beta.exe installation.
    • When it finishes you will have a green window with a Start and and Update selection. Click Start
    • the Express Scan of your PC window will come up. Click OK to scan main memory to detect infected process in memory.
    • If anything is found in memory, click the yes button when it asks you if you want to cure it. This is only a short scan.
    • You may see a popup window to Buy or get a discount on the program. Just click the X at the top right to close this popup. The scan will continue.
    • Once the short scan is completed, click the Custom Scan radio button. Then Select each of your hard disk drives (that is if you have more than one). A red dot shows which drives have been chosen.
    • Click the green arrow at the right under the Dr.Web logo, and the scan will start.
    • Click 'Yes to all' if it finds any problems and asks if you want to cure or move the file.
    • When the scan has finished, look if you can click next icon next to the files found:
      http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif
    • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
      http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif
    • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
    • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Reboot your computer!! This is necessary because there could be files in use that will be moved or deleted during reboot.
    • After reboot, rename the DrWeb.csv file to DrWeb.txt so that it can be uploaded here and then attach the log from Dr.Web to your next reply

    Thanks
    Kestrel13!
     
  7. ucdawg12

    ucdawg12 Private E-2

    thanks again, Dr Web found a few new things but my PC is still freezing. MGTools took forever this time, with a bunch of errors and then a huge list of items that it couldn't either read or access because something else was already accessing it
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.

    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log

    Now use windows explorer to look for and if present delete:
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$$yt7.$$
    C:\WINDOWS\Temp\$67we.$

    Clean out all that you can from that folder.

    Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Now run the new MGTools.exe and attach the C:\mglogs.zip that it generates into your next reply.

    Thanks
    Kes
     
  9. ucdawg12

    ucdawg12 Private E-2

    here you go. i did all three MBR's (1 regular, 2 then through the run box and 3 then regular again) and they all came out the same but i'll upload them all anyway.

    er actually, the forum won't let me upload them because they are the same as the one that's already been uploaded
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please reboot with the XP CD and get into the recovery console....once there, type fixmbr and then hit enter.

    Next...

    2. Now reboot your machine.

    3. Go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    4. Run the new MGTools.exe and attach the C:\MGlogs.zip that it generates into your next reply.

    5. Also watch out for any error messages other than those mentioned in the Using MGtools link and let me know about those if you receieve any.

    Thanks
    Kes13!
     
  11. ucdawg12

    ucdawg12 Private E-2

    i can't get to the windows recovery console mode because i get a blue screen error every time i try to boot it up that way. but, the way i installed the recovery console, i did it from my i386 folder on my pc because i don't have an xp disc but it gave me an error that "Setup cannot continue because the version of Windows on your computer is newer than the version on the CD." but it did actually continue and it was installed and i had no errors from there but maybe thats why this is crashing?

    edit: oh i forgot to mention earlier that i couldn't delete these files:
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$$yt7.$$
    C:\WINDOWS\Temp\$67we.$
    because it said they're being used by another person or program
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    Could you please follow the instructions in the ComboFix procedure for downloading and installing the Recovery Console properly and if that works, to retry booting to the RC and running fixmbr.

    If you cannot do the above, you need to borrow a CD from someone so they can do this.

    Thanks
    Kes
     
  13. ucdawg12

    ucdawg12 Private E-2

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please follow what is in the ComboFix procedure we gave in the READ & RUN ME for running ComboFix. It explains how to install the RC which also refers to the above link and tells you exactly what to use.

    Thanks
    Kes
     
  15. ucdawg12

    ucdawg12 Private E-2

    i already did that and i'm still getting blue screens trying to enter the RC. I've found that i can make an XP cd from my /i386/ folder, so i'm going to grab a blank cd while I'm out today and hopefully this gets me into the RC successfully
     
  16. ucdawg12

    ucdawg12 Private E-2

    wow this is maddening. so, my came with XP preinstalled, and didn't have a disk, but it came with the installation software in the i386 folder and i learned i could make a xp cd from that. but i wasn't able to create an XP cd from my i386 folder because it was too big to fit on a cd, it's 1.2gb, so i made a dvd instead. but my bios will not let me boot from my dvd drive, only my cd drive. and i continue to get blue screens in spite of installing RC the ComboFix way and doing that CHKDSK /F thing. I am at a complete loss here as it seems like whatever this problem is it is always one step ahead of me
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You cannot make a bootable copy of Windows by just copying the files in the i386 folder onto a CD/DVD. You need to follow special procedures to make a CD bootable and to get the Windows XP SP level desired on it. To get a Win XP SP3 bootable CD, you already need a Win XP SP2 bootable CD. The below procedure explains how to slipstream a Win XP SP3 CD

    http://www.winsupersite.com/showcase/xpsp3_slipstream.asp
     
  18. ucdawg12

    ucdawg12 Private E-2

    i know. i didn't just copy the files onto a dvd, i went through a procedure with a boot image and all. and it didn't matter cause my bios doesnt let me boot from a dvd. anyway, like i said i don't have the cd. i sent an email to my dad to see if he has one lying around that he can send to me and he's still looking. but if he does find one, wouldn't that work fine to boot off of and get into the RC? would i actually need to even do the slipstream stuff?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to read this:

    Yes you can use your father's CD to just get to the Recovery Console, but if you father's Windows XP CD is not an SP3 CD and it is not for the same version of XP, you should not use it for anything else (like running sfc)

    You may be better off now to work this out in the Software Forum if you need any help in slipstreaming or burning a CD...etc. We can only help you with malware and already stated you need to get to the Recovery Console to run fixmbr. Until you have a Windows XP CD, we cannot help you anymore unless you want to try using Radix as I hinted at earlier to fix your MBR.

    Best of luck and sorry we can't be of more assistance in this forum. :)

    Kes and the team
     
  20. ucdawg12

    ucdawg12 Private E-2

    hm so do you mean that if I used an XP cd that isn't for my specific edition, i shouldn't do fixmbr? also i found a guide to making a bootable cd out of i386 http://www.howtohaven.com/system/createwindowssetupdisk.shtml but it was too big for a cd

    what is radix? im not sure where you hinted at it but if i havent already tried it i definitely would if it could help
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use Radix to try and fix your MBR

    Radix Rootkit Detection Tool

    • Right click on your Desktop and select New and fhen Folder to create a new folder on your Desktop. Name the folder Radix.
    • Download Radix from usec.at. Scroll down to the bottom of the page and click the Download Radix icon. Save it to your Desktop in the new Radix folder just created.
    • Unzip the archive into this Radix folder you created.
    • Run the program by double-clicking the radixgui.exe.
    • Click Yes to accept the license agreement.

    • Click on the MBR tab
    • Hit the "Check" button at the bottom left of the screen
    • Once it has run a check look towards bottom right of screen and choose to "save log"
    • Attach this log into your next reply.
     
  22. ucdawg12

    ucdawg12 Private E-2

    i had run radix normally, via the instructions in the thread about it just before i saw your reply and it found quite a few things outside the MBR. I ran that scan too just now. I had to zip the second log (the normal Radix one) because it was too big to be uploaded as a txt file
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    Please double open up Radix > hit MBR tab > click check > once finished > hit fix > and save log which you will need to attach here into your next reply. Let me know of any problems you encounter throughout doing this.

    Thanks
    Kes13!
     
  24. ucdawg12

    ucdawg12 Private E-2

    what do you mean by double open radix? i opened two up but i don't know if thats what you mean. did what you said, it gave me the same message as last time and said

    "MBR seems to be OK.(However it's not a standard Windows MBR that I know)
    "

    And "Fix" was greyed out so I couldn't click it. The forum won't let me upload the log since its the same as the last one I uploaded, "radixmbr.log" in my previous post
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You must make a backup of all your important data and personal files now! Copy them to cd. Do not copy any exe files or programs.

    When you open Radix, do you have a restore button?
     
  26. ucdawg12

    ucdawg12 Private E-2

    my dad did just find an xp cd and is planning on sending it to me. do i still need it? i do have a restore button on radix, but only after i do a check on the MBR. so i guess it sounds like a virus? any idea what it is? im backing up data as we speak
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have your data files backed up, then re-run Radix...then clicking the Restore button will bring up a form showing the win2kxp.mbr and winvista.mbr files that Radix already has saved copies of. Of course choose the proper file and let it run.

    Then attach the resultant log.
     
  28. ucdawg12

    ucdawg12 Private E-2

    im about halfway through backing stuff up, but a question, cause this would make it much easier, is radix going to affect any other harddrive but my c:\? i have a d:\ hard drive that would be much easier to use to backup rather than burning all these dvds
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All it will fix is your MBR...which is only on the C drive......back up to the d. :)
     
  30. ucdawg12

    ucdawg12 Private E-2

    cool, all went well, no problems. the log contains when i restored the mbr and also when i checked the MBR right after that
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  32. ucdawg12

    ucdawg12 Private E-2

    here it is
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One more time....Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Temp\$$$dq3e       
    C:\WINDOWS\Temp\$$yt7.$$     
    C:\WINDOWS\Temp\$67we.$       
    C:\WINDOWS\Temp\hlktmp       
    C:\WINDOWS\Temp\MCE00000
    C:\WINDOWS\Temp\MCE00001      
    C:\WINDOWS\Temp\MCE00002      
    C:\WINDOWS\Temp\xsw2
    C:\Documents and Settings\ucdawg12\Local Settings\temp\afl.log      
    C:\Documents and Settings\ucdawg12\Local Settings\temp\alm.log       
    C:\Documents and Settings\ucdawg12\Local Settings\temp\amt.log
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  34. ucdawg12

    ucdawg12 Private E-2

    wow, combofix with that script definitely got rid of something because this time mgtools ran without a single hitch. usually i get a bunch of error pop ups and then a huge string of lines saying that it cant access certain files cause they're in use but none of that at all this time.
     

    Attached Files:

  35. ucdawg12

    ucdawg12 Private E-2

    ugh sorry i realized i didnt get all the files you put in that quote box so i went back and redid combofix and got them this time. i ran mgtools again and i did get a few errors this time and it took much longer than the last one. not sure what the difference was. maybe because i had forgotten to turn mcafee back on before i did mgtools this time
     

    Attached Files:

  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This isn't good......let's try using Avenger.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  37. ucdawg12

    ucdawg12 Private E-2

    looks like avenger deleted them but they came right back. i also checked my MBR again cause I was suspicious it's still involved and Radix is back to saying it's ok but its an MBR its not familiar with after I had fixed it earlier. edit: i tried to upload that radix log but an identical one has already been uploaded in this thread
     

    Attached Files:

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The fact that these temp files will not delete means you still have an MBR infection.

    The instructions for fixing the MBR for a Dell are here (It involves burning a Dell Utility to a CD and booting from it). Making the CD can be done from another machine.

    http://support.ap.dell.com/support/t...=my&l=en&s=gen
     
  39. ucdawg12

    ucdawg12 Private E-2

    okay, i've made the cd and used it to repair the mbr. those files are still there and radix is still showing that its not familiar with my MBR
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If that did not work....then I suggest that you reformat that drive and do a clean install. :(
     
  41. ucdawg12

    ucdawg12 Private E-2

    ah okay. that's too bad. thanks for your help. is there a guide on this site as to how i should go about reformatting and what i'll need to do it and the clean install?

    edit: will reformatting fix an mbr? i'm reading an article that says it won't help http://www.cyberwalker.com/article/474
     
    Last edited: Aug 9, 2009
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can post in the software forum....but it is just a matter of setting your cd to be the first boot device in the bios, booting to the xp cd and then following the prompts....you will want to only format the c drive if you have more than one partition and then install on that partition.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds