I'm having Serious Computer Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by adamato, Feb 8, 2006.

  1. adamato

    adamato Private E-2

    Help, I’m in some serious trouble. I currently own a Dell Dimension 8400 computer running Windows XP Home edition. I’ve been battling spyware & viruses for about a week now. It all started with the pest trap spyware virus and it went downhill from there. :eek:
    I can’t operate most of the functions of the computer right now. My internet access doesn’t work, I can’t start up Control panel, System Restore, Internet explorer, Webroot AntiSpyware for MSN and Norton Anti-Virus among other things. Not only that, my computer seems to “restart” every three (3) seconds, in Normal & Safe Modes. It refreshes the screen as if it’s starting up for the first time every three (3) seconds. The only way I can run an application is if its an icon on my desktop. Clicking on Start-Run locks up the system & I end up rebooting. Running Task Manager and clicking on “New Task” has limited success. Even this will lock up the machine. :mad:

    I printed out CHASLANG’s “Read & run me first before asking for support” directions and downloaded all of the necessary software. I couldn’t run CCleaner at all. I ended up running the following programs in this exact order:
    SpyBot-Search & Destroy (Locked up during removal process)
    Microsoft AntiSpyware
    SpyBot-Search & Destroy
    Ad-Aware SE

    For all of the programs, I couldn’t run the update features on my computer because of no Internet access. I haven’t run HijackThis just yet, hoping to perform that task this evening.

    Microsoft AntiSpyware kicked out a Trojan virus, couldn’t get which type of virus it was. SpyBot kicked out three Spywares the first time out and the two HKEY’s, which disabled my AntiVirus & Spyware programs at startup. The second time I ran SpyBot, the HKEY’s were removed.

    Here are the specs on my computer:
    Windows XP Home w/SP2
    40 MG hard drive
    1GB RAM
    Pentium 4, 3GHz

    If I need to list more info, let me know… :confused:

    I do no online banking or buying with my computer, so there’s no credit card info on my machine.

    I have all of the documentation and disks from Dell when I bought the computer about 18 months ago. Please help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So I guess you cannot do step 6 then since you have no internet access. Is that correct?

    Please make sure you follow step 7 for using HijackThs properly. Also it would be good if you could some how complete the steps in the below before doing HJT:

    Running Spy Sweeper
     
  3. adamato

    adamato Private E-2

    Correct. No Internet access at home. I had to do everything from work. I had WebRoot SpySweeper for MSN, but that stopped working also. I'll try to download Spy Sweeper & try again. Let you know tomorrow...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes make sure you download SpySweeper from the link given. It would be nice if you could get the updates but since you cannot get online (at least not yet) don't worry about them after install. Just run the scan and let it fix what it finds. Save and attach the log too.
     
  5. adamato

    adamato Private E-2

    Here we go. I failed to mention I disconnected my Internet cable after I realized I wasn't going to get onto the Internet at all. The computer still cycles as if restarting every three (3) seconds. Having to manually restart numerous times, I received two Not Responding messages for the following programs: "DVD Launcher" and "Dummy Mixer Callback Window".

    I installed & ran Spy Sweeper and was able to delete the spyware program named "PNPNetwork" and two quarantined programs by the same name.

    I installed & ran HijackThis (finally) and produced the following log file. I am however having trouble uploading the attachment to the posting. The software is not giving me a reason as to why. What should I do? :confused:
     
  6. adamato

    adamato Private E-2

    Finally got to upload my HijackThis file. This time it worked. :)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked you to attach the SpySweeper log.

    Also your HJT log is from safe mode and it appears to have been edited or filtered. We require logs to be from normal boot mode and totally unedited or filtered.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log does not show any major malware problems but you can do the below.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    After clicking Fix, exit HJT.:

    Let's dig deeper!


    Please follow the below steps...
    1. Please download and unzip Rootkit Revealer to your desktop.
    2. Please leave the defaults set as they are to:
      • Hide NTFS Metadata Files: this option is on by default
      • Scan Registry: this option is on by default.
    3. Launch rootkit revealer on the system and press the Scan button.
    4. RootkitRevealer scans the system reporting its actions in a status area at the bottom of its window and noting discrepancies in the output list. It may take a long time please disconnect from the internet and leave the PC to be scanned until it is finished.
    5. The log can be very large please edit out the items in the following folders in the log : C:\System Volume Information, if in the log, before attaching it.
    6. Please attach the the log here in this thread to your next post
     
  9. adamato

    adamato Private E-2

    Hey Chaslang. Thanks for the help so far. I've seen a little improvement so far. Attached is the log from the Spysweeper that I ran the night prior.

    I ran RootKitRevealer in Normal mode last night with mixed results. I was able to install & run the program, but I couldn't produce a scan log from the program. I ran the program twice and it locked up on me both times. What I have in the log is simply the output data the program produced. The program kicked out one (1) folder, the rest I believe are files. I hope the data is useful. I just couldn't kick out a scan log from the program.

    Please let me know if I should try RootKitRevealer again.

    When I started up last night, Microsoft AntiSpyware indicated that a change was attempted in revising my Start page from "dell.myway.com" to "about:blank" and denied it.

    By the way, I tried running Spysweeper in normal mode and the computer kept locking up and I end up having to reboot. The only way I could get the program to run was in safe mode.
     

    Attached Files:

    Last edited by a moderator: Feb 10, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message # 7 I said:

    Please attach a new HJT from normal boot mode.
     
  11. adamato

    adamato Private E-2

    First off, here is my HJT log as run in normal mode.

    I ran the Read me first procedure this weekend in order to see if all of the programs will run this time. I still have no internet access at home, so none of the programs were updated.

    (Safe Mode)
    CCleaner: Still won't run
    Microsoft Malicious: Ran, nothing came up.
    Ad-Aware SE: Freezes while scanning browser cache during "Started tracking cookie scan" (Attached log)
    Spybot: Locked up twice, couldn't obtain log. Registry keys which disabled Norton Internet security & Norton Anti-Virus re-appeared.
    CW Shredder: Couldn't run
    Kill2ME: Ran in normal mode. Stated "Look 2 Me" virus was detected.

    Downloaded BitDefender & Panda Titanium from websites since I couldn't do the online scan.
    (Normal mode)
    BitDefender: Wouldn't load properly
    Panda Titanium: Required me to uninstall Norton before installation. Couldn't load Panda.

    I'm going to run Webroot SpySweeper tonight in normal mode. So far, I can only get it to operate in Safe Mode.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read step 3 of the READ ME again. You must not use multiple antivirus applications. Choose between Panda, BitDefender and Symantec and then uninstall the others. You will see all three of them running in your HJT log. You must not do anything on your own. Please follow our directions and only our directions. If you are working this problem somewhere else, then make up your mind where you want to work the problem and stay there.


    After uninstalling ALL but one antivirus program, attach a new HJT log from normal boot mode.

    You have multiple bad Services running that we need to remove but the above must be done first. The bad services are:
    O23 - Service: BDCGN - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\BDCGN.exe
    O23 - Service: KOHWCBWYH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\KOHWCBWYH.exe
    O23 - Service: KPFFTKF - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\KPFFTKF.exe
    O23 - Service: YIKJIEVI - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\YIKJIEVI.exe
     
  13. adamato

    adamato Private E-2

    BitDefender & Panda have been uninstalled on my computer.

    I tried running Spy Sweeper for about three hours last night. I couldn't get the program to run in Normal mode. It seems that every time the program is about to appear on screen, it stopped itself and closed out. I get as far as the white background and title bar only, then it closes out. I could only get the program to run in Safe mode and even then, I couldn't generate a report log.

    I did run my computer in safe mode with command prompt and delete all of my cookies and Temporary Internet Files.

    Before shutting down last night, I ran HijackThis last night and produced the following log last night.

    I will HijackThis fix the SysInternals lines tonight and anything else that comes up today...

    BTW, this is the only website I'm taking advice from. I think the website is excellent.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will have to remove some things manually now because they did not uninstall properly. See Panda in your services too. Also Bitdefender still has some items running.

    I did run my computer in safe mode with command prompt and delete all of my cookies and Temporary Internet Files.

    Services are not always fixable that way. FIrst they must be stopped and disabled. Then you need to delete the service. This requires special steps.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below item is what I was referring to from BitDefender:
    O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe"
     
  16. adamato

    adamato Private E-2

    I opened up Add/Remove Programs and Bit Defender is not listed there, same goes for Panda. The Bit Defender icon on my screen is gone and the folder on my "C" drive is deleted. I missed this sub folder.

    Just let me know what to do. Between the constant "rebooting" and the locking up, I'm getting tired of sitting in front of my computer for hours at night....
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Panda Process Protection Service (or if not found look for the short name: PavPrSrv) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for the below service names:
    BDCGN
    KOHWCBWYH
    KPFFTKF
    YIKJIEVI

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Panda Process Protection Service

    If that does not work try entering the short name: PavPrSrv

    Now repeat the above HijackThis steps for the below service names:
    BDCGN
    KOHWCBWYH
    KPFFTKF
    YIKJIEVI

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\Tony\LOCALS~1\Temp\symlcsv1.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe"
    The below 023 line should be gone already but if you still see them, fix them.
    O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
    O23 - Service: BDCGN - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\BDCGN.exe
    O23 - Service: KOHWCBWYH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\KOHWCBWYH.exe
    O23 - Service: KPFFTKF - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Tony\LOCALS~1\Temp\KPFFTKF.exe
    O23 - Service: YIKJIEVI - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\YIKJIEVI.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Common Files\Panda Software <-- the whole folder if found
    C:\PROGRA~1\Softwin\BITDEF~1 <-- the whole folder if found
    C:\Documents and Settings\Tony\Local Settings\Temp\symlcsv1.exe <-- in fact delete all files allowed in this Temp folder which should remove some of the below.
    C:\Documents and Settings\Tony\Local Settings\Temp\BDCGN.exe
    C:\Documents and Settings\Tony\Local Settings\Temp\KOHWCBWYH.exe
    C:\Documents and Settings\Tony\Local Settings\Temp\KPFFTKF.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\YIKJIEVI.exe <-- in fact delete all files allowed in this Temp folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  18. adamato

    adamato Private E-2

    I've been having trouble using the "Start" button in normal mode. Every time I position the cursor on the taskbar, the cursor turns into an hourglass. The machine usually locks up on me when I do clock on the start button.

    Is it possible that I can perform the services.msc step in safe mode sucessfully?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe! But another way to get to services is from My Computer. If you have it on your Desktop, just right click on it and select Manage. In the next windows that comes up select the Services and Applications line to expand it. Then in the right column double click Services.

    If you do not have My Computer on your Desktop or the Manage selection does not appear, press CTRL-SHIFT-ESC to bring up Windows Task Manager. Then click File, and select New Task (Run...) and enter services.msc.
     
    Last edited: Feb 15, 2006
  20. adamato

    adamato Private E-2

    I think I'm SCREWED !!

    I tried this last night in both Normal and Safe modes and nothing happened. The program just didn't run. So, I tried this...

    This actually worked, right up until the part where I double click on Services. It was here where the program closed out. This happened both in Normal and Safe Modes.

    I was able to get onto some of the other directories in the Computer Management screen, especially in the Event Viewer sub-directory.

    Just to recep, I can't open Internet Explorer, Windows Explorer, Norton Anti-Virus, Spy Sweeper (Normal Mode only), no Internet access, and I lock up every time I click on start-run-browse. The only way I can get text into the run window is when I type it into some other text program like notepad.

    I hope you have other ideas to try out.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try something a little different. Read carefully as we will not use services.msc

    If you do not have My Computer on your Desktop or the Manage selection does not appear, press CTRL-SHIFT-ESC to bring up Windows Task Manager. Then click File, and select New Task (Run...) and enter cmd and click OK. This should open a command prompt window. Close the Task Manager window to get it out of your way.

    Now in the command prompt window enter the below lines each followed by the enter key. Make sure you enter them correctly. The purple text is just additional comments from me. Note: Important that you observe that the command prompt window has a prompt . This just means it is reading to except a command to execute. The command prompt is always showing the current folder (also called path) that you are in. When you first open the window, you will be at C:\Documents and Settings\username> prompt. Where username is whatever user account name you are logged in with. I assume it will be Tony. Start entering the below commands now.

    sc stop BDCGN
    sc delete BDCGN

    sc stop KOHWCBWYH
    sc delete KOHWCBWYH

    sc stop KPFFTKF
    sc delete KPFFTKF

    sc stop YIKJIEVI
    sc delete YIKJIEVI

    sc stop PavPrSrv
    sc delete PavPrSrv

    Make sure you use the quotes in the below.

    cd "C:\Documents and Settings\Tony\Local Settings\Temp"

    Make sure the command line prompt has change to C:\Documents and Settings\Tony\Local Settings\Temp> Do not do the below commands unless the prompt shows you are in the above Temp folder.

    attrib -r -h -s *.exe <--- There is a space between the del and the *
    del *.exe

    cd "C:\Documents and Settings\Administrator\Local Settings\Temp"

    Make sure the command line prompt has change to C:\Documents and Settings\Administrator\Local Settings\Temp> Do not do the below commands unless the prompt shows you are in the above Temp folder.

    attrib -r -h -s *.exe <--- There is a space between the del and the *
    del *.exe


    exit <-- this will close the command prompt window. Only do this after writing down any error message you may have gotten.


    Okay now tell me what happen with the above. If it all worked okay. Get a new HJT log and make sure the O23 line are gone.


    Then complete the rest of message # 17 from the below line down to the end (not some items should already be gone if the above worked).

    Make sure viewing of hidden files is enabled (per the tutorial).
     
  22. adamato

    adamato Private E-2

    OK, here we go...

    I started up the machine and opened up the Command Prompt. I was at the proper directory as you stated, nice work. I typed in the commands

    "sc stop..."
    "sc delete..."

    for all five (5) items listed in response #21 of this thread. Each time, the machine told me that the executable file wasn't running. I deleted all of the files.

    I connected to C:\Documents and Settings\Tony\Local Settings\Temp directory listed and ran the "attrib -r -h -s *.exe" command with no problem.
    However, when I performed the same function in the C:\Documents and Settings\Administrator\Local Settings\Temp directory, I received a "File not found" message. Typing in exit locked up my computer, so I had to reboot.

    I ran thru the entire process again and on the second pass, I was able to delete all executable files within the C:\Documents and Settings\Administrator\Local Settings\Temp directory.

    I opened up HijackThis and checked the O23 line. The Panda line was missing. Attached is the log for that process titled Hijackthislog1.log.

    Opening the "Open the Misc Tools" section, I was able to kill "C:\Docume~1\Tony\Locals~1\Temp\symlcsv1.exe". I took a few tries, but I was able to kill it. Scanning HJT, I was able to fix the R0 and O4 lines. All of the other o23 lines weren't there.

    Exited HJT and rebooted into Safe Mode. I couldn't open Windows Explorer, so I had to run the Command window and perform the following steps from there. The following directories were not found:

    C:\Program Files\Common files\Panda Software
    C:\Progra~1\Softwin\Bitdef~1

    I deleted all of the following files:
    symlcsv1.exe
    BDCGN.exe
    KOHWCBWYH.EXE
    KPFFTKF.EXE
    YIKJIEVI.EXE

    There was a TON of crap in these Temp directories. In fact, there were 2958 files totaling 665 MB of info and 168 Directories. Most of the stuff was .txt, .dmp, and tmp files. Those deleted easily. There were about 160 directories all labeled "WER****.dir00" which I tried to delete, but kept reappearing when I reran a directory inquiry. So I dumped as much as I could and kept going.

    I opened up the C:\Windows\Prefetch directory and cleared that out.

    I uninstalled and then re-installed CCleaner and this time it works. The only problem now is when I click the button to run the cleaner, something shuts the program down. This happened about 5 or 6 times.

    Resetting the Web Settings was tough. I was able to clear out the files and cookies. But when I went to change my home page to Major Geeks.com, the machine wouldn't stand for that and it locked up on me. So, I'm stuck with dell.com or msn.com for now. While rebooting, Task Manager spit out an "End Program" message for RUNDLL32.exe that I had never received before.

    One more thing, with Task Manager open and the Processes tab selected, whenever the screen "cycles" or "refreshes" (the background image stays but the task bar and all my icons disappear and then reappear), I notice that a file named "DWWIN.EXE" appears and then disappears.

    I rebooted into Normal Mode and ran HJT. Attached is the log titled "HijackThislog2.log"

    My machine runs a little quicker now, but I still can't open Windows Explorer, Internet Explorer, Norton AntiVirus, Spy Sweeper (Normal Mode only) and the screen still cycles on & off.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We have removed all those bad services now. Your remaining issues may be more related to corruption of problems with your Windows installation. When you try to run Windows Explorer, Internet Explorer...etc, what exactly happens.

    First please uninstall Spy Sweeper, reboot, and now try to Reset Web Settings.
    Does it work this time?

    Now try opening a command prompt window and enter the below command (this may ask you for your Windows CD if it finds missing or corrupted files it need to replace):

    sfc /scannow

    Tell me what the results of the above are.
     
  24. adamato

    adamato Private E-2

    When I try to open Windows Explorer and Internet Explorer, either by double clicking on the icon or by typing the command line into Task Manager, basically the hourglass icon flickers on (for 1-2 seconds) and then disappears.

    I just noticed on the second HJT log that the follwing line reappeared:

    C:\Documents and Settings\Tony\Local Settings\Temp\symlcsv1.exe

    I'm going to repeat the process in deleting this line before I start on the other stuff.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download GetRunKey125b.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey125b.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.
     
  26. adamato

    adamato Private E-2

    I worked on my computer this weekend and made some progress. In addressing the Reset Web Settings, I uninstalled Spy Sweeper and received an error message as follows "Access Violation at address 7C80AC9B. Read of address 80040119". Despite the error message, SpySweeper disappeared from by Add/Remove screen. Rebooting and Resetting Web Settings finally worked.

    I ran "sfc /scannow" and the computer checked the entire computer. However, at the end of the run the computer locks up and I receive no error messages or report. It simply stops responding. I performed this step four (4) times with the same results every time.

    I ran GetRunKey125 this weekend and produced a text file attached below.

    There were a few things I noticed this weekend. When my computer locks up, DRWTSN32.EXE is what's locking it up. While the computer screen cycles as if it's rebooting every time, explorer.exe, dwwin.exe appear & disappear from the Task Manager. DRWTSN.exe appears sporadically and then disappears without locking up the machine. When I run an executable file, DRWTSC32.exe shows up and stays on, in some cases more that one DRWTSN32.exe program is running at the same time. When I delete the program, most of the time the program I'm trying to run continues to operate. Rebooting isn't required. I did find that every time the screen cycles, a directory is created in my "Ducuments and settings\tony\local settings\temp" directory which consists of a ".tmp", *.dmp* and "DRWTSN32.EXE.dtmp file is created. I didn't note the size of the files created, but over time this creates quite a large volume of data in this directory.

    I ran CCleaner and found what was causing the program to close down. Thru the process of elimination, something in the "Temporary Internet Files" section of the program causes the machine to shut down. I was able to clean out everything else from within the checked boxes except this one. When I ran this one solo, the program shut down every time. There are about 1527 files in this section which I haven't been able to purge.

    I manually tried to go into my "C:\documents and settings\tony\local settings\temp" directory and manually delete everything located within the directory. One program I couldn't dump was "~DF6209.tmp" I kept getting a message stating "The process cannot access the file because it is being used by another process." The file is 32.7 kb.

    In looking thru my notes from when I first started having problems, I remember not being able to start Windows because of windows not finding my "wininet.dll" file. I found the file on my hard drive ( i think in the I386 directory) and copied it to my Windows\system 32 folder. That got the machine running again.

    Even though I can't open my Internet Explorer program, I found that I now can get updates thru some of my programs like Ad-Aware SE.

    I hope this info turns out to be useful in figuring out what's got my computer going crazy. I also attached the latest HijackThis log. It was the last thing I did yesterday.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC does not show anymore signs of malware but you should have HJT fix the below (seems like SpySweeper finished its uninstall):

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    It appears that C:\DOCUME~1\Tony\LOCALS~1\Temp\symlcsv1.exe is part of Symantec's stupidity! No one is exactly sure what it is used for but it appears to be spawned by them.

    DRWTSN32.exe , DRWTSN32.EXE, and DRWTSC32.exe are all part of Dr Watson a diagnostic program Windows automatically runs when crashes are occurring. This is not malware. You more than likely have some file corruption somewhere.

    Did your PC come with Win XP SP2 installed on it to start or did you upgrade at some point? If you upgraded, the wininet.dll file you copied from the i386 folder is not the correct version for your OS. You should look for one in a ServicePack Update folder. Just search your PC for wininet.dll and let me know what you find.

    Your problems that remain are not malware related and may be better served being discussed in the Software Forum. If it were me, I would start by uninstall ALL of the Symantec software and see how things work afterwards.

    By the way, files like "~DF6209.tmp" are created by your OS each time it starts. The ones with the current date are always in use and cannot be removed. Not sure why Ccleaner is crashing on them. It normally just skips over files that cannot be removed.
     
  28. adamato

    adamato Private E-2

    I used HijackThis to delete all of the recommended line items shown in posting #27.

    I obtained a copy of wininet.dll from www.dll-files.com and copied it to my I386 & windows\system32 sub-directories. I've so far noticed no difference. Should the DLL file be installed somehow or is its presence in the directories enough?

    I'm having difficulty uninstalling the Symantec products at this time. I did unplug the cable modem from the machine before uninstalling the products. LiveUpdate seems to be giving me some problems. It doesn't want to uninstall for some reason. NAV deleted with minimal effort and I'm saving Internet Security for last. So far, no change in the way the computer behaves. I just keep thinking there's a virus in the machine that's making my life miserable.

    Do you have any other suggestions I can try?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Symantec may need an Internet Connection to complete the install. I'm not sure about that but sometimes certain software does.

    You could also check the below to see if it will help:

    Removing your Norton program using SymNRT
     
  30. adamato

    adamato Private E-2

    I have a copy of my Dr Watson error log, one of many produced by my machine. I was wondering if this will help in figuring out what's wrong with my computer. If not, should I post this in the Software section? The log actually as the same Application Exception occuring 51 times. I just copied the first report and posted it here. The original log is actually over 5 MB.

    I'm also attaching the manifest document tht was found with the error log.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a topic for this forum. You can try the Software Forum to see if they can help with that.
     
  32. adamato

    adamato Private E-2

    And then, there was light....

    I finally got the machine up and running. YAHOO !!!

    I took your advice and went to the Software section for info. I searched for more info on Dr Watson and came across a posting which suggested that a possible fix for Dr Watson was to change the setting for

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Classic View State

    from 0 to 1.

    Well, I tried that and no luck. Since I couldn't get onto Windows Explorer and I am unable to see my hidden files, I decided that I would change the setting on a folder in the Explorer directory

    "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStart Panel"

    from 0 to 1, thinking that when I use the command prompt, I will be able to see the hidden files. Well, when I rebooted, the computer operated normally. I re-installed NAV2006 and ran the program. It found a Trojan virus, Trojan.DesktopHijack.B in two (2) places . Attached is the quarantined log.

    I'm going to run the Read Me before asking for support procedure.

    I will post all of the logs, along with a HijackThis log tomorrow night.

    For now, I'm one F'in happy camper !!
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A couple of those files are related to the Smitfraud family of problems. You should run thru the below and attach the smitfiles.txt log when finished. You will not find many (or even most) of the stuff shown in the sample HJT log but just continue thru the steps.

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal
     
  34. adamato

    adamato Private E-2

    OK, I ran thru the Read me bebefore posting procedure and I ran into some minor issues. Attached are my logs produced from this process. Hijackthis log is coming next.

    I haven't yet disabled my system restore points. I don't think I'm clean enough to do so. Please inform.
     

    Attached Files:

  35. adamato

    adamato Private E-2

    Here's the HijackThis log.

    By the way, I have multiple user logon's on my machine. Should I repeat the entire Read me before posting procedure for everybody's logon?
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run what I requested in message # 33? Please attach the smitfiles.txt log from that procedure. You don't need to run Panda again as shown in that procedure. Just follow the other steps and attach the smitfiles.txt log.

    You other logs are basically clean other than a SmitFraud related file and that is the reason I'm asking you to run this procedure.

    Also it would be a good idea to empty your orton AntiVirus Quarantine folder. There should be an option within the program to do this.
     
    Last edited: Feb 22, 2006
  37. adamato

    adamato Private E-2

    Here are my latest logs as requested. I ran the SmitRem first, then the Run me first before asking. One program found one element and it was deleted. Everything looks good though. I'll let you be the judge of that though.
     

    Attached Files:

  38. adamato

    adamato Private E-2

    Here are the last two (2) logs...
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks clean now! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  40. adamato

    adamato Private E-2

    Thank you very much for all your help. I'm telling you, I found this website purely by accident, but I'm glad I used it! :)
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and recommend us to your friends!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds