Computer frozen, can move mouse

Discussion in 'Malware Help (A Specialist Will Reply)' started by DeaTh-ShiNoBi, Apr 9, 2010.

  1. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    Overview:
    Hello, just yesterday, 4/8/10, I was watching Fullmetal Alchemist on animecrazy.net. I started a new episode, and the video was loading very very slowly. I tried several different links including myspace video, Rutube, and two different Megavideo links. All of the links were loading slowly, so I decided that I would just let one of the videos buffer (I picked Rutube), while I played Starcraft II beta.

    I ran Starcraft II beta and went to get something to eat. By the time I came back about 5 minutes later, Starcraft II was still loading, which was very strange because it usually loads in seconds. Actually, it had not even started loading yet. The bar was still at 0%. I tried opening task manager but my computer froze. I tried Start --> restart, but my computer would not open start. I could still move my mouse, but clicking things did not do anything.

    I hard restarted my computer by holding the power button and turning it back on and booted it into Normal Mode. Upon booting, it still had the same problems. I could move my mouse, but clicking things had no effect. Interestingly enough, I could mouse over Start and it would say "Click here to begin.", but clicking it had no effect. I hard restarted my computer again into Normal Mode, but it had the same problem. Next time, I tried hard restarting my computer into Safe Mode with command prompt, and it worked.

    After that, I tried restarting and booting into Safe Mode with Networking, which also worked. Any steps that I took to attempt to resolve the problem were done in Safe Mode because Normal mode would not boot without being frozen. Oh, I should also mention that I have not downloaded anything in the past couple of days.

    First steps:
    Before I went to majorgeeks.com, I tried running an older version of Malwarebytes' that I had on my computer. I ran a quick scan, but it did not find anything. I then realized that I forgot to update it, so I successfully updated it and ran a quick scan again, but it also found nothing. I ran a full scan after that, and it found 1 infection, which I successfully deleted. I have included the logs to these scans in this post as well, in case they are helpful.

    The problem was not fixed even after deleting the infection that Malwarebytes' found, so I tried a system restore, which also did not help. Unfortunately, I lacked the foresight to create a system restore point before I used system restore, but I don't think it really interfered with anything anyway.

    READ AND RUN ME FIRST:
    I followed the steps on READ AND RUN ME FIRST and the Windows XP Cleaning process. I downloaded all of the programs that it told me to and ran them in order.

    I attempted to reinstall SUPERAntiSpyware, but it would not let me run the uninstaller in Safe Mode. However, I was still able to run and successfully update the version that I already had. I ran the complete scan and it found nothing. The log is included.

    Malwarebytes' Anti-Malware successfully ran in Safe Mode when I used it before, but it did not run after I did the system restore. It came up with an error that said something like "Code 714". My guess is that it was trying to load the updated version of Malwarebytes', which I did not have at the time of the system restore point, two days ago. I tried to uninstall the program, but it still brought up "Code 714". I tried simply reinstalling it, which also brought up "Code 714", but it seems to have ignored its own error, as it finished installing after that and prompted me to restart my computer. I said "yes", and booted into Safe Mode again. This time I was able to run Malwarebytes' successfully, with no error message. I updated whatever it asked me to update and then ran the quick scan, which found nothing. The log is included.

    I attempted to run combofix.exe in Safe Mode, with no programs running in the background. It somehow found that Comodo Anti-Virus was still running, and asked me to close it. I wasn't sure how to close it because Comodo itself was not even running, so I looked it up online but found nothing that helped me. I just uninstalled Comodo to fix the problem, and it prompted me to restart my computer, which I did. That seems to have messed up combofix, though, as when I tried to run it again in Safe Mode, it skipped the steps involving the disclaimer and asking if I have "Windows Recovery Console" installed. It also skipped creating a system restore point. It brought up a blue command prompt window that said "'NIRCMDC' is not a recognizable system command." I waited several minutes for something to happen, which nothing did. I looked on the guide and it did not mention anything about "NIRCMDC", and I also used my other computer to do a Google search, which did not help me. I closed the combofix window and restarted my computer, and moved on.

    RootRepeal froze my computer the first time I tried to run it, even in Safe Mode. I hard restarted my computer into Safe Mode again and tried to run it. I decided to do other things while the scan was running, and came back about 45 minutes later. Somehow my computer restarted into Normal Mode, which still had the freezing problem, so I was forced to hard restart back into safe mode. I am unsure of whether the scan successfully completed or not, but RootRepeal seems to have not saved the log. I moved on.

    I ran MGtools successfully in Safe Mode, and got the MGlogs.zip from it.

    The logs will be posted in replies to this thread.
     
  2. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    The logs attached in this post are:
    Pre-READ ME mbam scans:
    mbam quick scan, old version
    mbam quick scan, updated version
    mbam full scan, updated version

    READ ME scans:
    SAS log
    (others in next post)
     

    Attached Files:

  3. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    The logs in this post are:

    mbam quick scan, following READ ME proceedure
    MGlogs.zip
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are no real problems showing in these safe boot mode logs. You are going to have to get logs from ComboFix and MGtools in normal boot mode. You need to first also run Defogger as requested in step 6 of the READ & RUN ME since you are using Daemon Tools. I did not see it on your Desktop as specified.

    Delete the C:\ComboFix folder and then download a new copy of ComboFix.exe to your Desktop.

    Run ComboFix and ignore any messages from ComboFix about an antivirus or other protection software running and just continue. Try unplugging your cable to the internet this time in normal boot mode. Also uninstall the P2P/torrent downloaders you have installed (uTorrent, Soulseek...etc) to avoid having them open up hundreds to thousands of connections into your PC. Also don't allow Steam to load at startup to avoid wasting all of your system resources on it being loaded.

    Also delete the below files:
    C:\Documents and Settings\user\Local Settings\Temp\Age_Of_Empires_III_(3)_Crack.5383077.TPB.torrent
    C:\Documents and Settings\user\Local Settings\Temp\bdfcl8h1.bmp
    C:\Documents and Settings\user\Local Settings\Temp\fla3CE.tmp
    C:\Documents and Settings\user\Local Settings\Temp\i4jdel0.exe
    C:\Documents and Settings\user\Local Settings\Temp\MgwiSI_Y.exe.part
    C:\Documents and Settings\user\Local Settings\Temp\SkypeSetup.exe
    C:\Documents and Settings\user\Local Settings\Temp\utt12F.tmp
    C:\Documents and Settings\user\Local Settings\Temp\utt12F.tmp.exe
    C:\Documents and Settings\user\Local Settings\Temp\vb4z8pzd.bmp
     
  5. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    Ah I did forget to use defogger again. I forgot about it completely. I did use it before I attempted the system restore, and it reversed the process. I forgot to do it again.

    I'll delete the files that you told me to. I don't think steam runs on start-up, or if it does, it's misbehaving because I don't want it to...

    Oh and I'll uninstall the P2P programs too. Thanks for the advice. I'll run combofix again and get a log for that. Are you suspecting that deleting the programs/files you told me to will allow me to boot into normal mode? It was freezing before, so I'm not sure if I'll be able to run combofix/MGtools in normal mode.
     
  6. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    I deleted the programs and files that you told me to, and I made sure that Steam does not load upon start-up, and I ran defogger again. I'm going to attempt to boot into normal mode again, now.
     
  7. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    I tried booting into normal mode again after deleting the programs and files, but it still froze. I forgot to unplug my internet cable though, so I'll do that and try again. Would running combofix in safe mode be worthless?
     
  8. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    No good, I can't boot into normal mode without an immediate freeze. I might as well run combofix in safe mode because that's the best that I can do. I'll post the log for that in a bit.

    At any rate, I've got to bail for now so I'll post the combofix log tomorrow. Hopefully I can get this fixed, thanks for the help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When exactly does the freeze occur? Is it before or after you enter your login?

    You can try this just so we can look, but I'm currently leaning more towards non-malware problems.

    Try creating a new user account by logging in in safe mode. Then reboot and see if the new account can be accessed in normal boot mode.
     
  10. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    The freezing occurred after startup. It would load my desktop properly and I could click things for about 2 seconds. After that, it would freeze completely. I actually gave up since I'm quite convinced as well that it wasn't a malware issue, and I just wiped my hard drive and reinstalled windows completely. Of course, I no longer had the freezing problem after that.

    Interestingly enough, in the process of reinstalling some of my old programs, I found what may have been the source of my problem. I reinstalled SmartDefrag and set up the preferences to how I liked them, which included "Run at startup." For some reason, the next time I restarted my computer, I noticed that SmartDefrag actually wasn't running, even though I told it to autostart. I opened it up and checked the preferences. Everything was how I set it before, except autostart was inexplicably unchecked. I checked it again and restarted my computer, this time SmartDefrag loaded.

    Needless to say, SmartDefrag was the only thing that loaded. My computer was frozen again, in the same exact way that it was frozen before. I hard restarted again and it happened again... Naturally I figured it was SmartDefrag so I booted into Safe Mode and uninstalled SmartDefrag, and after that I was successfully able to boot into normal mode without freezing.

    This implies that SmartDefrag is the program that was causing the freezing issue, but I find it quite strange that SmartDefrag recently began doing this to me because I had been running it on startup for at least 6 months now, and I had absolutely no problems. I really hope that I can somehow get SmartDefrag to work again without freezing my computer because I love the program.
     
  11. DeaTh-ShiNoBi

    DeaTh-ShiNoBi Private E-2

    I'm wondering if it's a conflict with one of my other programs, but that's hard to believe because I hadn't installed anything new in a while since before the freezing began, and now that I've wiped my hard drive, there's barely anything even on my computer.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to see you found the cause of your problem and that my assertion that it was not malware was correct. ;)

    You should post in the Software Forum if you wish to discuss potential issues with SmartDefrag. My personal opinion is that I would not run it. I don't believe in active on the fly defragging. I think it is a bad idea.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds