Computer Crashing

Discussion in 'Malware Help (A Specialist Will Reply)' started by PStand, Jun 25, 2005.

  1. PStand

    PStand Private E-2

    My computer keeps crashing after being on it for a bit. When I try to system restore it crashes right at the end and so it can't restore anything. I've run Ad-Aware and defragmented it and it made the computer faster but didn't do anything about the crashing. Please help me. I wasn't sure where to post this so sorry if it's in the wrong place.

    Here's the hijackthis file in case you need it.

    Edit by bjgarrick: Unrequested, Inline HJT log removed!
     
    Last edited by a moderator: Jun 25, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    PStand,

    You have some major problems/infections on your machine. The first thing you need to do is uninstall one of your antivirus programs as running 2 will cause conflicts on your computer. Pick ONE and uninstall the others!

    After you complete the above, procede with the below steps:

    Download the following two files, create a folder on your desktop, call it TSC. Save these 2 files there!

    Sysclean Package

    Pattern.zip

    Once you have these downloaded into the folder you just created, REBOOT INTO SAFE MODE!

    Once in Safe Mode, double click the file sysclean.com

    When the system cleaner loads, click SCAN to start the scanner.


    Once scan is complete, reboot back into Normal Mode and attach a fresh HJT log.
     
  3. PStand

    PStand Private E-2

    Inline log attached!

    The scan didn't find a viruses, although it could not scan some files. I don't know if they were corrupt or something.
     

    Attached Files:

    Last edited by a moderator: Jun 26, 2005
  4. PStand

    PStand Private E-2

    One of the problems I have is that the computer can't restart at all, not just when I'm trying to do a system restore.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach all logs as attachments to your post instead of posting them inline!

    Now please procede with the below online scans:

    TrendMicro Online Scan
    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan
    Panda Online Scan

    After you complete the above online scans reboot and post a fresh HJT log as an attachment to your post.
     
  6. PStand

    PStand Private E-2

    I cannot do the TrendMicro scan because I don't have netscape installed. Is there anyway to get around having to get netscape?
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its not required you have Netscape installed, run it with IE. If you cant get it to run still just skip that scan and procede.
     
  8. PStand

    PStand Private E-2

    I could not run Bitdefender or RavAntivirus. The rest found only a few low risk spyware, and my computer still can't reboot. Here's the HJT log anyway.
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O4 - HKLM\..\Run: [Windows Services Hosts] svhosts.exe
    O4 - HKLM\..\RunServices: [Windows Services Hosts] svhosts.exe
    O4 - HKCU\..\Run: [Windows Services Hosts] svhosts.exe
    O4 - HKCU\..\RunServices: [Windows Services Hosts] svhosts.exe

    O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
    O16 - DPF: {85AF9A98-3423-45E4-8BAD-85645F16AC31} (P3 Bugs VoD Loader Class) - http://player.bugs.co.kr/install/mv/p3bvset.cab
    O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/mv/XTools.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following if they should remain:

    svhosts.exe <-- Search for this file and delete when found!

    (Do not confuse the above file with the legit file svchost.exe in the System32 folder.)

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  10. PStand

    PStand Private E-2

    Computer still not restarting....
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log looks clean to me, lets try one more thing.

    Download RegSupreme Pro 1.1

    Install this program, after you install you will be prompted to "defrag" you registry for best performance. You can go ahead and click YES, should take but a minute or so.

    After this completes at the top, click the REGISTRY CLEANER tab. Then click on "Aggressive" and let it scan. Afterwards you will see the total of invalid entries found. Once its complete, select ALL entries and select FIX. The program will then fix the ones that are fixable, the ones that are not will be removed. Type in a backup filename and save to an easy location just in case.

    Let me know the results! After you do this reboot and see if your running any better.
     
  12. PStand

    PStand Private E-2

    Computer still doesn't restart, and RegSupremePro found more errors when I ran it a second time... doesn't seem so reliable....
     
  13. PStand

    PStand Private E-2

    I repeatedly ran RegSupreme Pro and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help kept showing up. Maybe that has to do with the problem?
     
  14. PStand

    PStand Private E-2

    No, fixed that, it's not the problem.
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If your not having any further Malware problems then I would recommend posting this problem in the Software Forum.

    Let me know!
     
  16. PStand

    PStand Private E-2

    I will, and thanks for your help. The computer is definitely faster :D
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds