Computer Flat Lines! Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by gcpamking, Feb 21, 2006.

  1. gcpamking

    gcpamking Private E-2

    I posted a thread 2 days ago, which was added to a previous thread I had about malware!!

    I have hot had any response and I am in big trouble. My computer cannot restart! something has happened since the malware attack and the only way I can not get into the computer is to select the F2 button at setup and then use the F11 boot and choose

    "most recent settings that worked" option and I will finally get a screen and icons, however the computer then goes through a process of recognizing 'new hardware' i.e., hard drive, printer, ports, usb mass storage and so on. I cannot get it to regcognize my Palm to sinc it nor do a lot of other functions work.

    What do I do? My original malware problem was handled through Dem3nt3d, but he nor any other "geek" is jumpin in to help and boy do I need it!
    Should I crash my computer or what?

    Please someone respond!

    gcpamking
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt that your problems are malware related but when you keep starting new threads, what you are going to be met with is the below that you now need to run since it is more than a month since your previous problems.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .

    You need to provide a more clear statement of your problems too. You said you cannot restart. Do you mean restart from when it is running? Or do you mean after you have powered down your PC it will not boot up unless you use the Last known good configuration? Does this happen every time?

    In your other message that was moved to your previous thread, you said you lost a program. What does that mean and what program are you referring too? If you have done a system restore, anything added to the PC after the restore date will no longer work and must be reinstalled. None of this is malware related.
     
  3. gcpamking

    gcpamking Private E-2

    Thanks for the info and I appologize for not doing everything right. I assumed it was related to the malware problem only because the computer had not been used since that time.

    I will follow your directions and get back to you with the results and explanations.

    Thanks again,
    gcpamking
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem!

    Can you answer any of the questions I asked right now?
     
  5. gcpamking

    gcpamking Private E-2

    Sorry, I had to work so I wasn't able to get back to you right away. Re your questions.....what I meant when I said I could not restart was actually, I could not reboot when it was running or when I powered down. I could only get back if I chose the 'most recent settings that worked' and yes it happens every time.

    Re the 'lost' program, I was referring to a program called Homegage which was installed on the computer and it was not there when we came back from vacation (30 days)! This was before I tried to restore or anything else. All the information which was in Microsoft Outlook (contacts) also was no longer there.

    I am now going to do what you asked me to do and will respond after I have completed everything.

    Thanks,
    gcpamking
     
  6. gcpamking

    gcpamking Private E-2

    WOW....I am sending this to you from my laptop because the cursor on my desktop (the one with all the above problems) is going crazy!! I can get to your website or any other site but as soon as I try to scroll down or use the pointer to open something my screen the scroll bar goes up and down by itself and I can't control it at all?? It's like it has a mind of its' own! Needless to say I cannot download any of the tools you want me to and I am totally freaked!!

    gcpamking
     
    Last edited by a moderator: Feb 22, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use an external mouse (not built in)? If so, try either changing it or not using it at all if you do not have another.

    Does it happen if you do not have a connection to the internet available? Unplug the cable or disable the wireless card if wireless.

    Does it behave this way in safe mode if you can get into safe mode?
     
  8. gcpamking

    gcpamking Private E-2

    I did everything you asked!!

    Here's my new thread chasland,

    Ok, so after having some malware problems, then coming back to some weird problems, i.e., freezing up, scrolling issues etc, I did everything you asked: I checked out the preliminary house cleaning and found nothing, I disabled restore and enabled the viewing of hidden files, I downloaded CCleaner, Ad-Adware SE, SpyBot - Search & Destroy, Microsoft Windows Malicious Software Removal Tool, CounterSpy (could not download Microsoft Windows Defender 1051 (Beta 2) because it said I did not have Windows SP2???? so I downloaded the counterspy!), Hijack This!.......now it appears I have control over my mouse and the scrolling and I can once again reboot successfully, however, everytime I print, my cursor freezes and I have to reboot in order to regain control?????

    Can you determine anything from the downloaded logs???? I am at my wits end and don't know what else you can do to help me but I'm open for any suggestions!!! You guys are great and I appreciate your assistance...should I crash my system or slit my throat????

    Thanks,
    gcpamking
     

    Attached Files:

  9. gcpamking

    gcpamking Private E-2

    Re: I did everything you asked!!

    To chaslang,

    I thought I would try to determine what might be a problem, so I uninstalled my mouse and then reinstalled and I also uninstalled my printer (since I felt this was involved!) and voila!!!!! Everything seems to be working and I no longer have the cursor freezing up?

    Sure do appreciate everything you did....thanks so much and I can only hope this lasts. One last question, please advise how many of the spyware programs I need to retain and how many and which ones can I delete?

    gcpamking
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I did everything you asked!!

    You should have stayed in your original thread. I moved you back.

    Please post the log for Bitdefender by following the steps in the READ & RUN ME step 6 exactly as written. You had a bunch of problems there we need to check on but you only posted the log summary which is of no use to us. It gives no info on where the problems are found and if they were fixed. If you follow the directions it will produce an HTML file that will be uploadable here with a .txt extension.

    Is this Club Dice Casino something you knowingly installed? We normally remove all these casino type programs?

    Did you but CounterSpy? If not, uninstall it?

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O15 - Trusted Zone: *.instanetforms.com
    O15 - Trusted Zone: *.transactiondesk.com
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (file missing)
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM32\key.~
    C:\WINDOWS\uniq
    C:\WINDOWS\system32\sachostc.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. gcpamking

    gcpamking Private E-2

    Sorry, for some reason I had interpreted your instructions to mean I was supposed to start a new thread after completing everything....duh!!

    Anyway, I ran Bitdefender again (per the Read & Run Me step 6) and while it was scanning a message kept coming on "do you want to quit this scan" and of course I kept responding NO.....so, when it was done the screen does not come up the way you mentioned, instead I get a 'scan completed' and it asks if I want the results sent in to their site? I think I am attaching the right log you are requesting as bdscan1.txt but I also went to the next screen and hit the 'view report' and that is attached as bdscan2.txt. I sure hope one of these is what you are looking for?

    As far as Club Dice Casino, yes, I did intentionally install it and it's been on my computer for 5 years, however, I went to add/remove and clicked on remove and will do whatever else you want me to do.

    I uninstalled CounterSpy (As I mentioned, I only downloaded this because I am unable to install Microsoft Windows Defender and thought I was supposed to do CounterSpy if I couldn't get Defender installed?)

    Yes, I made sure that viewing of hidden files was enabled (per the tutorial) I had done that before also.

    I am going to run Hijack This now, so I will be leaving this site temporarily and finishing up on your instructions. Yu have me selecting two lines that are in my *trusted zone which I do recognize as they are used with my multiple listing service (I am a Realtor), however, I will follow your instructions and worry about reinstalling them later. I will then forward you a copy of the log .

    Also, I am glad you have continued to stay in touch as my cursor is still freezing up when I print anything and I have to reboot!! Could this be a hardware problem?

    Talk to you soon
    gcpamking
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything!

    Since you still have MS Antispyware, you do not need CounterSpy which is only a trial anyway.

    Normally there is little reason for things to be in the Trusted Zone. If you find it necessary later to get proper access to those sites, you can add them back. I surf more than most and have nothing in my TZ and have not found I needed it.

    Not sure! What kind of mouse (wired, wireless, USB, PS2).
     
  13. gcpamking

    gcpamking Private E-2

    OK, so I'm brain dead!!! Here's the posts and also, I had already disabled Restore and rebooted before you responded last night because I thought everything was ok!!! Another goof???

    I have a Microsoft Wireless Optical Mouse and a Wireless Comfort Keyboard.

    Anyway, here's the logs..................
     

    Attached Files:

  14. gcpamking

    gcpamking Private E-2

    Forgot to mention, I went to add/remove programs for Club Dice Casino and hit remove, however, after viewing Explorer I see it's still in the file! I went to Club Dice Uninstall and of course it can't find the right files, so how should I go about deleting all of it? Should I delete it from Explorer?

    I know you must be tired of answering all my questions, but I don't know what else to do!

    Thanks,
    gcpamking
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix the below lines:

    O9 - Extra button: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe
    O9 - Extra 'Tools' menuitem: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    You can delete the C:\Casino folder to if it exists.

    How are things working?
     
  16. gcpamking

    gcpamking Private E-2

    I removed Club Dice Casino per your instructions. Everything is running pretty good until I print something and immediately my mouse freezes up? This problem has not been solved.

    I am attaching a new Hijack this log.

    Did you find anything else in the Bitdefender log I sent?

    gcpamking
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. The problem with printing and your mouse is more than like not related to malware. I'm not sure what it is. You could try uninstalling and then reinstalling your printer drivers and maybe even your mouse itself. This problem would be better discussed in either the Hardware or Software Forums.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds