PC crashing and crawling.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Surfers Do Charlie, Apr 3, 2006.

  1. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Hi guys

    You're going to have to be fairly gentle with me here, because I still have geek learner plates on...

    My ME pc has been running slow for a couple of years now, but since I went broadband a month or so ago it's all gone pear-shaped. My biggest problem is that my pc just jams most times I try to start it up, and then crashes fairly frequently. I've run through steps 0-6 on your READ & RUN ME FIRST (took about 4 days) and I'm attaching my Bitdefender and HJT logs.

    Any help you can give would be much appreciated !!


    Cheers

    EDIT: I've attached the bd scan but I'm not too sure how to post the HJT log so I'll post this and please let me know what else yo need.
     

    Attached Files:

  2. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    OK did more reading, and I guess the HJT file just needs to be included as an attachment rather than just as text in the body of the thread, so here goes...

    I forgot to say what the results of the other scans were - when I ran Spybot in Safe Mode it came up with over 1000 things to fix. I'd been using Spybot and all the others in steps 0-6 before, and the others only came up with half a dozen each, and Panda didn't find anything.

    (Possibly a dumb question: my C drive is over 99% full, mainly with music files - would clearing some of these out help any, or should I just get rid of the nasties first ?)

    Cheers guys
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Looks like you obtained your HJT log before running Bitdefender. HJT should be the last step otherwise things that show in it may have already been removed. Also you must attach the PandaActiveScan log as requested in step 6. Also you should attach your CounterSpy log as requested in step 5.

    Also since you appear to have an HSA (aka About:Blank) hijacker, run the below and attach the log to:

    about:Buster......No installation required! Just unzip it to a folder. Click Update and download any updates before scanning. Also run it twice with a reboot in between. Save the logs and attach later.

    If you receive an error message about a missing MSCOMCTL.OCX file when you run about:Buster, download the file in the link below and run it. It will give you the necessary file. There is also a help file that come with about:Buster that explains some common errors and how to fix.

    http://www.javacoolsoftware.net/downloads/missingfilesetup.exe
     
  4. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Good to be here !

    I thought I had run the HJT after Bitdefender - I ran BD last night (took about an hour and a half) and added the HJT log this morning, but I'd installed the HJT a couple of days ago and run it then, so maybe I'd just posted the original log without actually re-running HJT.

    CounterSpy: One infected cookie found, text log added. I've asked CS to delete this cookie now. (Had to run this one in Normal Mode)

    Ran PandaActiveScan again (in Normal Mode) and still nothing found, but it didn't seem to give me the option of a log (because nothing was found ?)

    I ran the about:Buster program (in Safe Mode) which pulled out a few things which it fixed, but then my pc froze before I could take a log file. I rebooted (again in safe mode) and got the all-clear - log file attached.

    I've just run HJT again in Normal mode (after an hour of trying to get the machine to switch on...) and I'm attaching the log for that.

    Thanks for all your patience !!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have both AVG and Antivir installed? Both show in your HJT log. If both are still installed, uninstall one of them.

    You must disable Spybot's Teatimer as requested in the READ & RUN ME.
    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked. Now quit Spybot!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\RunServices: [IEPT32.EXE] C:\WINDOWS\SYSTEM\IEPT32.EXE /s
    O4 - HKLM\..\RunServices: [IPWR.EXE] C:\WINDOWS\SYSTEM\IPWR.EXE /s
    O4 - HKLM\..\RunServices: [SYSXA.EXE] C:\WINDOWS\SYSXA.EXE
    O4 - HKLM\..\RunServices: [SDKOX32.EXE] C:\WINDOWS\SDKOX32.EXE
    O4 - HKLM\..\RunServices: [WINLQ.EXE] C:\WINDOWS\WINLQ.EXE
    O4 - HKLM\..\RunServices: [MSPS.EXE] C:\WINDOWS\MSPS.EXE
    O4 - HKLM\..\RunServices: [NETUY32.EXE] C:\WINDOWS\SYSTEM\NETUY32.EXE /s
    O15 - Trusted Zone: *.mozilla.org
    O19 - User stylesheet: (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM\IEPT32.EXE
    C:\WINDOWS\SYSTEM\IPWR.EXE
    C:\WINDOWS\SYSXA.EXE
    C:\WINDOWS\SDKOX32.EXE
    C:\WINDOWS\WINLQ.EXE
    C:\WINDOWS\MSPS.EXE
    C:\WINDOWS\SYSTEM\NETUY32.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Thanks for that

    I followed all your steps last night without too much problem, but now when I try to boot up in Normal mode to run and post my final HJT log, my pc just freezes before it fully loads all programs.

    It has been taking longer and longer to start up over the last 6 months, as I've added all (but only) the malware prevention programs that you recommend. It seems to be the firewall that's causing the main problem. Is there anything I can do to get the machine to start up, and do you have any advice on why it's struggling so much ?

    As I said in an earlier thread, my C drive is absolutely jammed with music files - would this be slowing things down ? Could I remove some programs from the Startup menu ? Anything I do at the moment will have to be in Safe Mode because it's the only way I can startup at the moment - I spent 4 hours trying to start the machine last night....

    Thanks again for your help.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you answer each of the below questions:
    1. How much free hard disk space do you have?
    2. How much RAM do you have?
    3. Did you uninstall one of the antivirus programs yet?
    4. Did you disable Teatimer yet?
    5. What firewall are you referring too? You did not have one before!
    6. You have both CounterSpy and Spyware Doctor installed. Are either of these the paid subscription version? Or are they both the free trial versions?
    The files in your log were remnants of an HSA infection and there could be literally hundreads more of them hiding on your system. We may need to save a log of the files in a couple of your folders and have you upload them here. These file can get quite large and will need to be put into a ZIP. So let me ask right now before giving any procedures, do you know how to use WinZip or similar to put files into a compressed ZIP?

    Post a HijackThis log from safe boot mode?
     
  8. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Thanks for that - okay here goes...

    I had to remove my firewall (Outpost) in order to get my machine to start. I should have explained in my last post that my last post was from work. I booted in Safe Mode when I got in, removed the firewall and it starts okay now. Hopefully I can get my machine clear of bugs and then reinstall.

    I'm attaching a HJT log done just now in Normal Mode.

    Answers to questions in order of easiness:

    3. Yep - removed AntiVir, now just got AVG running.
    4. I think that I've disabled TeaTimer - I followed your instructions.
    5. I'd followed one of your other threads and installed Outpost, but it seemed to be blocking my startup. I'll ask your advice on configuring it better when I install it next time.
    6. Both Counterspy and Spyware Doctor are free versions - I haven't subsribed or paid for any anti-spyware stuff yet, although I'm happy to if needs be.
    1. Okay, now it gets a bit harder - you mean my C drive right ? Where all the programs and files are kept ? It has a capacity of 18.6GB and all but 338MB is used up. Is that bad ?
    2. Now you're talking a different language to me. I know vaguely what RAM is for (processes and stuff ?) but no idea how to check...

    You've probably guessed the answer to the last one - I don't know to zip files up, but I can follow straightforward instructions.

    Sorry you're having to go back to basics here, but I'm keen to learn and I really do appreciate the time you're taking.

    Cheers

    p.s. I couldn't find any of those R and O .exe's using Windows Explorer after I'd used HJT, but a couple of them did have .dll versions - but I'm not sure what they were so I left them.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Since they are only the free versions they are of no long term use to you. Uninstall both of them.

    Yes! That is very bad and is not enough free disk space for your system to run properly. You need to backup to CD a lot of your music files and delete them from your hard disk (or you need to buy a larger hard disk). Are you implying you have multiple hard disks? If so, how much free space is on the other?

    Don't worry about this write now. We could easily get the info but your problem is the hard disk space.

    Give me the names of the DLL files you are referring to. Also give the file size and date.
     
  10. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Well, I've followed your instructions to the letter, and my machine is jumping around like Barry Bonds has given it a pick-me up !!

    Took a record 4 minutes to start up just now, after a previous best of 18 mins.

    Anyway, to run through your post:

    I've removed Counterspy and Spyware Doctor.

    I've binned a whole load of old music files, so my (only) hard drive now has a capacity of 18.6GB and 9.05GB of that is now free. Now I just got to hope my mp3 player, which has twice the memory of my pc, doesn't crash.

    The dll files in question are (with the date of creation):

    C:\WINDOWS\SYSTEM\IPWR.EXE 12th March 2005
    C:\WINDOWS\SYSXA.EXE 13th March 2005
    C:\WINDOWS\SYSTEM\NETUY32.EXE 29th March 2006 (not a typo...)

    All are zero bytes in size.

    The machine's starting up fine now, so I should I re-install the Outpost firewall, and if so, do you have any advice on configuration ?


    I'm starting to enjoy my pc again !!

    Thanks as ever - just let me know what next.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should backup files to CDs or to a DVD. No harddisk (in your PC or MP3 player) is immune to a crash.

    Those are EXE files not DLL files. Either way delete them.


    I personally do not use Outpost firewall but as with most firewalls you just have to allow or deny various programs access to the internet. Normally it is pretty obvious what the programs are as they popup when you run things on your PC. If you do not recognize something, then deny it access until you determine what the process is for.
     
  12. Surfers Do Charlie

    Surfers Do Charlie Private E-2

    Sorry, my mistake, I copied those file names from your original post without chaging the extensions from exe to dll. They should read:

    C:\WINDOWS\SYSTEM\IPWR.DLL
    C:\WINDOWS\SYSXA.DLL
    C:\WINDOWS\SYSTEM\NETUY32.DLL

    I'll ditch them now.

    The music's all on CD anyway, so no worries there.

    What firewall do you recommend I use (I'd prefer a free one obviously, but I'll pay if it's wisest) ?

    Now I'm just running:

    SpyBot
    Ad-Aware
    Trojan Hunter
    cwshredder
    AVG anti-virus
    and CCleaner every so often.

    Anything else I need on top of the firewall ?

    Do you reckon I'm clear as far as malware is concerned now - you want me to post a HJT log ?

    Thanks
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything you need is covered in the below final steps and the link given. You do need a real time antispyware program with blocking capability.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds