Need to check |causes: Malware| off the list

Discussion in 'Malware Help (A Specialist Will Reply)' started by na_astrith, Mar 10, 2009.

  1. na_astrith

    na_astrith Private E-2

    Some background about this PC: The Borring part -

    Nearly two years ago my brother-in-law commissioned Tigerdirect.com to build him a gaming computer. After he received it and started having errors (I would not like to go into them as I didn’t really touch the system) he called Tigerdirect.com and they sent out a technician, who after two separate visits (back to back days), replaced the motherboard, power supply and memory on the first visit and the graphics cards on the second.

    After the PC still had problems and at the tech’s suggestion, we sent it back to Tigerdirect.com who tested it, stating that everything was fine according to their tests, and sent it back.

    Again similar problems, this is really where I got involved, were occurring and after a short hiatus with dealing with this PC we brought it to BESTBUY and the GEEK squad. Geek squad held the PC for a few days called and said it was ok and ready for pick up.

    The reason I really got involved at this point was because my brother-in-law gave it to me after he had received another PC (Dell with similar specs).

    Took it home and couldn’t even boot to the OS. Farthest we could get was into the BIOS. We took it back to GEEK squad and they held it for about a week and a half, refunded the money charged and stated that it was bad memory on the graphics cards.

    So back to Tigerdirect.com, after my brother-in-law spoke to a VP, the PC went. The paperwork that returned with the PC stated that the motherboard, graphics cards, memory, cpu, cables and power supply were all replaced.
    Set the PC up after about a week after receiving it, boots to Windows. At this time I didn’t notice anything out of the ordinary.
    Loaded SpyDoctor and AVG
    USB plugged in my external
    Found the World of Warcraft exe file – WoW is in its own folder
    Played WoW (with addons-UI/mods) for about 3-4 hours with absolutely no problems

    Now the problem:

    Since that initial day I’ve begun to notice a lot of (non-responsive) errors, as well as other symptoms of my PC not behaving properly.
    After desktop is showing on XP (after the windows logo loading screen) sometimes it will take a few minutes for the pointer hourglass to switch to an arrow. But only sometimes as other times it loads and I can click on any program-Start button-IE7, anything available and it will begin loading right up. Other times though I will wait an additional minute or two when XP loads to desktop and if I open a program or click start I get nothing but the hourglass.

    Well you get my drift.
    Sometimes things open straight away (even well after XP desktop loads) and sometimes they hang with a non-responsive error.

    Yes I usually wait about a minute or two after I see the desktop load to begin clicking anything :-D

    My biggest issue though is that I can load World of Warcraft (disabling all of the addons-UI/mods) and it will go straight through, play fine and I haven’t noticed any “buggy” effects.

    Since I’m not one for a “pure” version of WoWs UI I don’t stay online long when logged in this way = bad observation?

    When loading addons for some reason I will experience the same kind of problems, as if WoW gets non-responsive. I could go into additional details about the WoW issues but I won’t here as this post is long enough.

    I’ve monitored GPU-Z/CPU-Z and watched the load on both gcards and cpu to drop to 0/1% while loading programs that become non-responsive if that helps any.

    Ok, all done with the READ & RUN ME FIRST prompts
    Headed to post and see what comes around.

    I also want it known that I’ve posted on both the ATI and World of Warcraft forums and it’s been the common response to reinstall XP. Which I might have done except I currently have no generic OEM install disks (and I’d like to not resort to torrents) in which to do it. There’s no C:/i386 folder on the PC and while the laptop has it is from a Dell XP install so I’m doubtful about recreating an install disk with my resources.

    My last forum exchange came off of the Windows XP forums and it came up that Malware was a possible problem, and that is why I’m here, to fix it or to check malware off the list.

    I’ll admit that my troubleshooting skills suck at the moment but I’ve looked through the processes running on task manager and I’ve not been able to notice any processes out of the ordinary so I’m at a loss. And now that I’ve loaded the programs recommended for trouble shooting there are a few more entries that I’ll need to look up.
    Jqs.exe
    And more than double svchost.exe processes as before... this normal after intalling the programs needed for the attchaments?
     
  2. na_astrith

    na_astrith Private E-2

    [edit] to add attachments
     

    Attached Files:

  3. na_astrith

    na_astrith Private E-2

    [edit] last log file
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. I can review your logs for malware but please remember that if this turns out to be a software problem which is does indeed sound like, then you will have to resolve your issues HERE

    Your MGlogs.zip are incomplete. Please refer to Using MGtools and check the information under the heading: Notes: Possible Error Messages Then try to rerun MGTools.exe and attach the MGlogs.zip.

    Thanks
    Kes
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    While I am waiting on your logs--

    Spyware Doctor ... is your copy of spyware doctor a free trial or is it paid for? If it is just a trial then please uninstall it.

    Please use Windows Explorer to find and delete the below:

    • C:\LOG8.tmp
    • C:\LOG5.tmp
    • C:\LOG6.tmp
    • C:\LOG4.tmp
    • C:\LOG3.tmp
     
  6. na_astrith

    na_astrith Private E-2

    Ty.

    I will certainly uninstal my trial version of SpyDoctor.
    And my apologies on the MGlog, it was late when I was finished writing the post and complteing the logs. :-o

    Yea I think it's a software problem (bad Win update or something) but I needed to make sure that Malware wasn't a factor. Go go cheaklists lol.

    I'll post the updated MGlog after deleting the trial version and the LOG files you posted.

    Thank you!
     
  7. na_astrith

    na_astrith Private E-2

    Heres the MGlog
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks, I'll get to looking them over later on this evening and get back to you asap

    kes
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please navigate to the following directories

    • C:\TempEI4
    • C:\c80e42f857d2887e5b

    Let me know what's inside of them.

    Also empty the contents of this temp folder:
    • C:\Documents and Settings\Owner\Local Settings\temp

    I'm not seeing any malware in your logs so I would indeed advise you to post up in the software forum.

    Best of luck with it :)
    Kes

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    Oh and in answer to your prior question when you first posted:

    Filename: jqs.exe
    Java Quick Starter
     
    Last edited: Mar 12, 2009
  10. na_astrith

    na_astrith Private E-2

    From C:\TempE14
     

    Attached Files:

  11. na_astrith

    na_astrith Private E-2

    Cont. C:\TempEI4 - sry typed in a one on the last reply

    Also two .tmp files

    5.tmp
    20.tmp

    both are 116KB
     

    Attached Files:

    Last edited: Mar 13, 2009
  12. na_astrith

    na_astrith Private E-2

    C:\c80e42f857d2887e5b

    has two folders

    AMD
    i386

    AMD folder contains 7 files:
    filterpipelineprintproc.dll
    msxpsdrv.cat
    msxpsdrv.inf
    msxpsinc.gpd
    msxpsinc.ppd
    mxdwdrv.dll
    xpssvcs.dll

    i386 contains 7 files with the same names as in the AMD folder
     
  13. na_astrith

    na_astrith Private E-2

    ;) thanks!
     
  14. na_astrith

    na_astrith Private E-2

    C:\c80e42f857d2887e5b

    I thought I posted this one...
    I'll wait a lil while incase of a dbl post
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's all good. Safe surfing :wave
     
  16. na_astrith

    na_astrith Private E-2

    Many thanks! Your assistance was mucho apreciado (my spanish sucks btw) !

    Now over to the software forum :-D
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    usted es muy agradable, yo espera que usted consigue sus ediciones resueltas.

    Good luck in software :-D
     
  18. na_astrith

    na_astrith Private E-2

    Hey I'm sorry to have to bump this but I wanted to share ;)

    So far none of the non-responsive problems have occured today.
    Whatever those scans did, I believe they set things right, even if they didn't remove anything.
    Currently testing programs and installing a game to test as well.
    Thanks again!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not at all considered a bump either ;)
    Thanks for letting me know. I'm very pleased to hear you're runnin' smoother now!

    kind regards
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds