Please Help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by beck_bail, Jan 15, 2008.

  1. beck_bail

    beck_bail Private E-2

    A couple of days ago I first noticed a problem because my Mouse would not work and my CPU is tacked at 100%. I eventually figured out my mouse is not working because all of my USB ports are not working. When I first boot they seem OK (my infra red is on on the mouse), but then they go out while the starting windows screen is up. Then I found my firewall (sygate personal firewall) was off, and I can not re-start it! I am unable to boot my PC using either my Windows CS or a UBCD4WIN, they get to the starting windows screen, and then hang. It does boot from my hard drive, but takes much longer than it should, with a blank screen for about a minute between the windows splash screen and the log on screen.

    I've done the READ & RUN ME FIRST. I have a problem with the AVG part, it works but is not producing reports, so I've attached a screen shot of my settings instead, did I set something wrong? If so I can run again and attach the report.

    OH, and a note to the spybot folks if they see this. If its going to be used as a diagnostic tool, it should be usable without a mouse. I could not update it without a mouse. Fortunately I was able to find a USB to mouse port adapter.

    Thanks in advance for any help.

    - Bill
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I have no problem getting Spybot to scan without using the mouse. All the hotkeys are shown with underlines just like most applications. Alt-F followed by Alt-C gets a scan going.

    What I first started reading your message, I immediately assumed that this was more than likely not a malware issue. And your logs do not show any malware to make me change this immediate assessment.

    What are you using the below files for?
    Code:
    2007-12-22 12:14 . 2007-12-22 12:14 123 --a------ C:\WINDOWS\tmpcpyis.bat
    2007-12-22 12:14 . 2007-12-22 12:14 122 --a------ C:\WINDOWS\tmpdelis.bat
    2007-12-22 12:14 . 2007-12-22 12:14 26 --a------ C:\WINDOWS\winstart.bat

    I will however give you a few things to do.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Kazaa Lite K++ v2.4.1 <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
    O3 - Toolbar: (no name) - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    And if you don't use a remote control with your DVD player, also fix the below:
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Bill\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  3. beck_bail

    beck_bail Private E-2

    Hi Chaslang

    OK, I followed all the steps, unfortunately it doesn't show much improvement. Any ideas where I go next (hardware?, software?)?

    One thing I found, I used Process Explorer to view the system process thats using up the CPU, and its running dozens (maybe a hundred) entries called

    \Device\Tcp

    Not sure if that helps at all.

    Oh, and my bad on the spybot keyboard usage.

    Thanks for all your help!

    - Bill
     

    Attached Files:

  4. beck_bail

    beck_bail Private E-2

    Well, I've got good news bad news, I found the problem but I don't like it.

    Looking further with Process Explorer I found the CPU was busy trying to setup the USB ports. I went into my BIOS and disabled the USB ports, and now my processer is running at around 2%, but I have no USB ports.

    I'm going to ask around in the hardware forum about this, if you have any more advice for me I'd love to hear it.

    Thanks,
    - Bill
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hardware.

    What process? Or do you literally mean the process that is labeled System?
     
  6. beck_bail

    beck_bail Private E-2

    Yup, its the process labeled System.

    I dug into it a little further and found that the CPU time was with the System tying to setup the USB ports.

    I was able to play with some of the settings in my BIOS, I disabled USB EHCI (not sure what that is), and now everything seems OK. My USB ports are working with my mouse and printer, and the CPU is running normal.

    Any ideas what EHCI is?

    Thanks again for you help.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds