Computer shutting down

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vanillaheroine, Sep 25, 2012.

  1. Vanillaheroine

    Vanillaheroine Private E-2

    Hi! I have several problems with my computer and I hope somebody can help me. My computer started shutting down unexpectedly after almost 2 hours and I did not think it was a virus problem but I ran a scan with SUPER Anti Spyware and found out that C:\Windows\System32\services.exe was infected with trojan. Also one time I got a popup that my computer will shut down in 60 seconds. The problem was not solved so I reinstalled Windows but while doing so it was still shutting down after 20 minutes and I also got an error I did not get before.
    Long story short my computer still shuts down after 20 minutes and everytime I open it is checking system files on D. I also get popups from Malwarebytes Anti malware *successfully blocked acces to a potentially malicis website* and yesterday I got a popup regarding pevfind.exe

    PS I could not scan with MGtools because my computer shut down

    Thanks in advance
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing a lot of issues with malware. Please try to do this:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. Vanillaheroine

    Vanillaheroine Private E-2

    yeah, I find that strange but last week when I perfomed scans I found somethings for example with HitmanPro
    C:\Documents and Settings\deea\Application Data\cidialog32\lib\cidialog32.dll
    Size . . . . . . . : 128,512 bytes
    Age . . . . . . . : 24.7 days (2012-08-22 08:53:33)
    Entropy . . . . . : 8.0
    SHA-256 . . . . . : 05596201BC9AADE4C1FACB441867D105C93A378803FD9B90BD2C70BC7A0164CA
    Fuzzy . . . . . . : 22.0
    Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
    The Entry Point of this file lies in a resource section. This is an indication of malware infection.
    The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.
    Authors name is missing in version info. This is not common to most programs.
    Version control is missing. This file is probably created by an individual. This is not typical for most programs.
    Program contains PE structure anomalies. This is not typical for most programs.

    and I also ran a complete scan with Malwarebytes and had detected Files Detected: 3
    D:\System Volume Information\_restore{0B735B54-E1C6-4442-89EA-5319D83308AF}\RP6\A0000757.exe (PUP.RiskWareTool.CK) -> Quarantined and deleted successfully.
    D:\System Volume Information\_restore{2DB7AF5E-97F7-4E2E-9603-C0313D88F38A}\RP4\A0000220.exe (PUP.RiskWareTool.CK) -> Quarantined and deleted successfully.
    D:\System Volume Information\_restore{373697F2-F106-4BAD-913E-A1F1B133058C}\RP6\A0000256.exe (PUP.RiskWareTool.CK) -> Quarantined and deleted successfully.
    And also 3 times when I opened my computer besides the checking files on system D it also checked files on C and deleted some things.

    Anyway here are the OTL logs.
     

    Attached Files:

    Last edited: Sep 26, 2012
  4. Vanillaheroine

    Vanillaheroine Private E-2

    here are the OTL logs
     

    Attached Files:

  5. Vanillaheroine

    Vanillaheroine Private E-2

    I am very sorry for the double post but the first one didn't appear after a while and I thought it was deleted by a moderator. I just got a popup from Super Anti Spyware that Cprogramfiles\internetexplorer\iexplore.exe is infected with trojan and told me to run a scan. What should I do?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let SuperAntispyware run the scan.
     
  7. Vanillaheroine

    Vanillaheroine Private E-2

    Right now I am scanning with SuperAntiSpyware and I got a popup from AVG, it blocked several threats. They are attached below. Should I remove them?
    And when the SuperAntiSpyware scan is complete do i remove the threats, if they are any, or just attach a log?
     

    Attached Files:

    • avg.txt
      File size:
      7.8 KB
      Views:
      2
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All of what you are finding in AVG are in your restore points. They won't go away until you toggle system restore.

    Fix what Super finds and attach that log was well.
     
  9. Vanillaheroine

    Vanillaheroine Private E-2

    here is the SuperAntiSpyware log,mainly cookies.

    Thanks so much for your help, I really appreciate it!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing significant there. I suggest you post in the software forum for additional assistance with the computer shutting down. I am not finding any malware in your logs that could be responsible for that.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  11. Vanillaheroine

    Vanillaheroine Private E-2

    Thanks, will do so. Really appreciate your help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Hope you find the answer. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds