problem with my pc

Discussion in 'Malware Help (A Specialist Will Reply)' started by amishstifler, Mar 12, 2005.

  1. amishstifler

    amishstifler Private E-2

    i am recently having a problem with my pc i am running windows xp
    i guy i know sent me here to look for a debugger because he has had the same problem in the past
    but the problem i am having is, everything thing works like games interenet things like that but when i try to open like my computer or a folder my pc freezes and it doesnt do anything i can move my mouse but thats about it
    ctrl alt delete works as well
    then after a little bit an error pops up and says something like debugger has failed or something
    here is an image i got but i dont know if you can read it if not let me know and i will get a larger image host http://img.photobucket.com/albums/v317/mohaasteve/64432d5c.bmp
    maybe if you do a zoom in
    please help me

    thanks
     
  2. Adrynalyne

    Adrynalyne Guest

    I've met a lot of resistance in the past when I have said this, but its been true each time. You are inected with some nasty spyware.

    http://forums.majorgeeks.com/showthread.php?t=35407

    Please go through this and see what you find. I'll leave this here for now, instead of moving it to the spyware forum, just in case.

    Dr. Watson is trying to capture the debugging information when Windows Explorer crashes, and then crashes itself.

    Note: it doesn't happen in Safe Mode.
     
  3. Adrynalyne

    Adrynalyne Guest

  4. amishstifler

    amishstifler Private E-2

    ok thanks and sorry for posting in wrong thread
     
  5. Adrynalyne

    Adrynalyne Guest

    You didn't. But if its a spyware issue, they can better serve you.

    The jury is still out ;)
     
  6. amishstifler

    amishstifler Private E-2

    ok i ran spyware and adware they both didnt do anything
    i ran adware se
    spybot search and destroy
    click and fix
    they all didnt do anything

    is there any debuggers that you guys would recommend for windows xp
    my buddy said he had this same problem and he just ran a debugger and it fixed it all
     
  7. Adrynalyne

    Adrynalyne Guest

    Your buddy is confused. Debuggers (in this context) read errors and program dumps. They themselves don't fix a thing.

    http://majorgeeks.com/download.php?det=3019

    You didn't run all the tools in that article I originally posted, either.

    Help us, help you. Please try the above program and if it has no success, finish the original article I posted. Ok?

    :)
     
  8. amishstifler

    amishstifler Private E-2

    i am just saying what he use is was some debugger i dont know was the program you wanted me to use cwshredder ?
    i tried and it didnt look like it did anything it just gave me a bunch of info do you want me to post that here or......?
     
  9. Adrynalyne

    Adrynalyne Guest

    You click FIx. Did it say it found no problems?

    I understand what you are telling me about your friend, however, he is wrong.

    What are you going to debug?

    I can tell you right now what happens.

    Windows Explorer crashes.
    Dr. Watson tries to get the debug info from the error.
    It crashes.
    Your computer becomes unresponsive at that point.

    Ask your friend exactly what program he is talking about.
     
  10. Adrynalyne

    Adrynalyne Guest

    In fact, you can go to start, run and type drwtsn32.

    In the options, enable visual notification, and then you will see that Windows Explorer is crashign the next time it happens.
     
  11. amishstifler

    amishstifler Private E-2

    lol he ran it it was called debugger he dont rememver the exact name but he said look for debugger something on here lol
    thats why i came here
    i dont want to get into a little fight on here no problem ok forget it

    but all the programs i ran didnt do anything
    they found things and fixed it but didnt do anything

    is there any way i can get pcbugdoctor free does any one know a code i can get ?
    i will try the drwtsn32 in run

    thanks for staying with me and helping me though
     
  12. amishstifler

    amishstifler Private E-2

  13. Adrynalyne

    Adrynalyne Guest

    It doesn't matter. Dr. Watson is tryign to log it, and crashing. So the dump never gets created. I'm gonna move this thread over to the spyware forum and see if they can help you check your system out.

    We'll get to the bottom of this.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As Adryn requested earlier, please run ALL steps and in the order listed in the following sticky:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Report what is found and fixed or not fixed.

    If you still have a problem after doing all of those steps, follow the steps below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
    Last edited: Mar 12, 2005
  15. amishstifler

    amishstifler Private E-2

    ok will do sorry for not going through everything and reading everyingthing for asking so many question
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see my message below? Please follow those steps!
     
  17. amishstifler

    amishstifler Private E-2

    no i was posting right when you did i quess and i tried to open the hjhack and all it did was the same error
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean by
    what are you opening. And I asked did you run ALL the steps from the READ ME FIRST.
     
  19. amishstifler

    amishstifler Private E-2

    ok now whats wrong with my computer it is not spware it is not adware and i ran search and destroy and it has not problems from that program and i ran click and fixed it and i got rid of all the problems
    but them i ran pcbugdoctor and it said it had over 1000 problems and to fix it i have to buy the program and i do not want to buy it if i am only going to use it once if any one has a code to get into it and use with out buying it that would be awsome but other than that you gave me a hijack this and i downloaded it and i tried to unzip it but the system freezes again i can not open control panel, my computer, search, and other files and folders i can go into run and start things from there but thats about it
    ive ran trojan it didnt find anything i ran virus it didnt find anything
    all it is, is like a little glitch in something not running right
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you want our help? Then please follow our directions and stop doing stuff on your own. You are not helping us to help you this way.

    PCBugdoctor is not useful! It points out loads of trivial stuff that does not need fixing and it will not fix unless you buy it.
     
  21. amishstifler

    amishstifler Private E-2

    i am following your guys steps and i cant open half the stuff you are telling me to open so how am i suppose to do this
     
  22. amishstifler

    amishstifler Private E-2

    ok i got the hijack to open i ran it all through my internet
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PCBug Doctor is not on our list and you have given no feedback on doing any of the steps.

    Have you disabled system restore?
    Have you download the applications requested?
    Have you installed and updated them (or do you have a problem doing this)?
    Have you tried the online scanners?

    Have you booted in safe mode and run all the requested application?

    Do you have HJT version 1.99.1 and is it installed where requested?
    Try running HJT in safe mode and getting a log. If that runs, post it here.
     
  24. amishstifler

    amishstifler Private E-2

    system restore was never running ive tried eerything scan including online scans
    i have updated everything that would let me

    i updated my last post and uploaded the doc
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What does "I ran it all through my internet" mean?

    You have HJT installed in the wrong location and you did not exit your browsers before running it. So why did you say it would not run before?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you run thru ALL the steps in the READ ME FIRST, you would not be having this problem. Step 2 of Getting Prepared asks you to stop and disable the below service that you have running due to an HSA hijacker.

    O23 - Service: Remote Procedure Call (RPC) Helper (? 6QÔõ'ª´ÆÐ8) - Unknown owner - C:\WINDOWS\system32\iptl32.exe

    Why didn't you perform that step?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below two items are not useful and should be uninstalled:
    Spyware Begone - rogue/supspect spyware removal tool
    Spyware Doctor - this is the free version and will not fix anything. Thus not useful!

    You should also uninstall anything from Eacceleration as it is spyware. The below came from them:
    O4 - HKLM\..\Run: [eanth_system_patcher] C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe /Startup


    If you have stopped and disabled the Remote Procedure Call (RPC) Helper service per the READ ME, continue with below. Make sure you only stop and disable this exact named service and nothing else.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\iptl32.exe
    C:\WINDOWS\d3dh.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {50964B31-818E-39AB-1536-69D7A172E713} - C:\WINDOWS\system32\atlcj.dll
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
    O4 - HKLM\..\Run: [ws5T35Q] uxtrslvr.exe
    O4 - HKLM\..\Run: [eanth_system_patcher] C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe /Startup
    O4 - HKLM\..\Run: [d3dh.exe] C:\WINDOWS\d3dh.exe
    O4 - HKLM\..\Run: [10D.tmp] C:\DOCUME~1\STIFFL~1\LOCALS~1\Temp\10D.tmp.exe 0 10001
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: http://members.freewebs.com
    O15 - Trusted Zone: http://members10.freewebs.com
    O15 - Trusted Zone: http://members11.freewebs.com
    O15 - Trusted Zone: http://members12.freewebs.com
    O15 - Trusted Zone: http://members13.freewebs.com
    O15 - Trusted Zone: http://members14.freewebs.com
    O15 - Trusted Zone: http://members15.freewebs.com
    O15 - Trusted Zone: http://members16.freewebs.com
    O15 - Trusted Zone: http://members18.freewebs.com
    O15 - Trusted Zone: http://members3.freewebs.com
    O15 - Trusted Zone: http://members5.freewebs.com
    O15 - Trusted Zone: http://members9.freewebs.com
    O15 - Trusted Zone: http://www.freewebs.com
    O15 - Trusted Zone: http://gamingchat.iscool.net
    O15 - Trusted Zone: http://*.liquidgeneration.com
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: http://www.stiflersmohaa.tk
    O15 - Trusted Zone: *.awmdabest.com (HKLM)
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O23 - Service: Remote Procedure Call (RPC) Helper (? 6QÔõ'ª´ÆÐ8) - Unknown owner - C:\WINDOWS\system32\iptl32.exe


    After clicking Fix, exit HJT.
    Some of the O15 lines above will more than likely come back. We will address them in the next round.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\atlcj.dll
    C:\WINDOWS\system32\iptl32.exe
    C:\WINDOWS\d3dh.exe
    C:\WINDOWS\system32\uxtrslvr.exe
    C:\freescan <--- the whole folder
    C:\Program Files\ACCELE~1 <--- delete this whole folder. You will have to figure out the full name as this is the shortened name.
    C:\Documents and Settings\STIFFL~1\Local Settings\Temp\10D.tmp.exe <--- delete all files and sub-folders in this Temp folder (some will be denied - just skip them and continue)
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now run Ccleaner from the READ ME FIRST

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds