Some help for a PC newb

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheBlackClap, Jan 25, 2006.

  1. TheBlackClap

    TheBlackClap Private First Class

    Good day everyone.

    First off I would like to say, I do appreciate the resources and tools you offer here on this site, they are easily read for someone like me. I do like that!

    Ok here is the deal. I started to notice my Computer freezing up late last week. Roughly around that time I had installed some 'old' 512mb memory that a friend had given me. Also, I had installed two new programs. Photoshope CS2 and Fable. Anyways, about 1-2 days after all of these items were installed my computer would just freeze. Then when I tryed to open CS2 I was told that a .dll file was not in my system file. I then went online and found the .dll file and reinstalled. CS2 then worked, however filters were missing out of the options. About 30 mintues later, my Norton Antivirus said the auto detect options were turned off and not working. I checked the program but it said it was on autodetect.

    Since then I had used many of your resources here and it seems to have cleaned up my computer. However about 45 mintues later I could not get onto the Windows main desktop, it would just freeze. I then removed the old 512 memory my friend gave me, and I was able to get on. However, that doesn't seem to explain random files and or functions not working.

    Any help with how to approach and or look for a virus would be appreciated. I have taken as many of the steps you posted in this forum to action. All items I have taken into action seemed to work. But my new PC has never froze.

    Thank you in advance for your help.

    respectfully,
    TheBlackClap
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Not sure if you have a malware issue or not. Let's be sure by doing the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. TheBlackClap

    TheBlackClap Private First Class

    Hello Chaslang, I will redo this area. I checked over this last week when I ran into the problem. Once I follow all instructions I will post again. Thanks)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Be sure to attach the requested logs (see steps 6 & 7) if still having problems. Make sure you follow step 7 and the link given in it to get HijackThis installed correctly.
     
  5. TheBlackClap

    TheBlackClap Private First Class

    Bitdefender says it will take a little over 2 hours to run the scan, is this normal?
     
  6. TheBlackClap

    TheBlackClap Private First Class

    now it says almost 2 hr 45 mins
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It can take a very long time. A few things have an effect on the speed:

    - the number of drives in the PC being scanned
    - the number of files on the drives
    - the speed of your internet connection
    - the number of files that are actually found to be infected
     
  8. TheBlackClap

    TheBlackClap Private First Class

    Okay thanks for letting me know that this can be normal for certain situations. Thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One other thing that I did not mention will impact the time it takes.

    If you continue doing other things on the PC like surfing (coming here to post or reading threads) or running other processes. This will all increase the time it takes to run.

    Panda will quite awhile too when you run it next.
     
  10. TheBlackClap

    TheBlackClap Private First Class

    Ok All the required scans were conducted 2 items were found using ad-aware, I cleaned those items and everything was good.

    I then ran the Bitdefender/Panda/Hijack and have the logs attached in this message. Again, thank you for your help.
     
    Last edited: Oct 10, 2006
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read step 3 of the READ & RUN ME again. You have both AntiVir and Symantec installed. Pick one and uninstall the other.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. TheBlackClap

    TheBlackClap Private First Class


    Yes sir I did install that last week. A friend referred it to me. Could this be a problem program?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be! It may have come bundled with malware. But even if it was not, P2P applications are one of the largest spreaders of malware. Some malware removal programs will detect SafeShare and remove it automatically.

    When did you problems being? Was it around the time this was installed? (you did say "Computer freezing up late last week")

    Did you uininstall one of the antivirus programs yet?
     
  15. TheBlackClap

    TheBlackClap Private First Class


    Well the freezing started roughly after I dloaded some filters for my Photoshop CS2 program.

    I have not uninstalled any anitvirus programs yet.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which may also be ruffly around the time of installed Photshop CS2. Did you download this using SafeShare? If so, perhaps this is the root of your problems.

    Uninstall one now!
     
  17. TheBlackClap

    TheBlackClap Private First Class


    anyone of the programs I dload earlier as stated in the 7 step rule? Sorry, I just want to make sure :)
     
  18. TheBlackClap

    TheBlackClap Private First Class


    No I did not use safe share to install CS2. The only thing I attempting installing was the zipped filters.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of the antivirus programs I'm referring to were part of the READ & RUN ME.
     
  20. TheBlackClap

    TheBlackClap Private First Class


    I am sorry Chaslang, I am a bit confused on what I should uninstall. I am sorry it is my incoherence that is causing this confusion. haha
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you miss message # 11?
     
  22. TheBlackClap

    TheBlackClap Private First Class

    oh there we go, sorry. Yes I had missed that. I will uninstall antivir right now. Thanks :)
     
  23. TheBlackClap

    TheBlackClap Private First Class

    Okay uninstalled
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You really only show minor issue in your HJT log. None of which would be causes of your problems with your PC freezing.

    Is it still happening? When does it freeze? What are you running when it freezes (want to see if it is related to any program in particular)?

    I'll be offline for an hour or so now!
     
  25. TheBlackClap

    TheBlackClap Private First Class


    Well, it hasn't happened ever since I took out that memory that guy gave me. But I went all day yesterday without it happening. I would think if it was the memory that it would happen all the time, no it random stages. But no, it hasnt happened since I took that out.

    It froze at totally random times. Froze twice times in CS2, many times running defrag, many times starting up the system, while running norton antivirus update and adaware update. All together it has frozen maybe 10 times. Sometimes all in a row, sometimes nothign for a day. But as I said earlier, it hasnt frozen since I took out he memory; and I am not suprised since it didnt freeze yesterday that it won't freeze again.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Adding memory can do this if it is bad or if it is not up to spec with what your PC requires.

    I would suggest leaving the memory out or at a minimum verifying they are the correct type and speed for your PC and running a memory test on them too. None of this; however, is a topic for this forum.
     
  27. TheBlackClap

    TheBlackClap Private First Class


    I am actually going to leave the memory out Chaslang. Since you reviewed my logs and saw nothing that can cause the actions I have described. I will head over to the hardware forums to seek further info on this matter.

    So Chaslang, is this problem closed in your book? :)
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alrighty then! Good luck!
     
  29. TheBlackClap

    TheBlackClap Private First Class


    Okay thanks again Chas!
     
  30. TheBlackClap

    TheBlackClap Private First Class

    Hey Chaslang,
    All of a sudden my Symantec firewall and antivirus were disabled and it said I didnt have the right authority to configure. I unplugged from the internet and had to reinstall. This seems odd to me; this is the kind of stuff I was telling you about where stuff will just turn off or become deleted. You can't tell me this doesnt sound like a virus or someone access my PC through a back door.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be from malware but your previous logs did not reveal anything.

    Do you actually know when it was turned off? Could it have been off for awhile and you are just noticing now?
     
  32. TheBlackClap

    TheBlackClap Private First Class


    I turned on my computer about 1 hour ago and noticed nothing in teh lowerright hand corner of my screen, I always see the globe and golden shield. I right clicked that area and it had those two applications as always show. But, they were showing. So I went into program files and started from there and in my firewall it had everyone as disabled or off. When I double clicked to change I got the not authorized block.

    I dont even know how to check my symantec antivirus to see if it is on. I assume it is.

    I was on lastnight with you and it was working. This is very strange.
     
  33. TheBlackClap

    TheBlackClap Private First Class

    nevermind I see how to see if it is activated (antivirus that is)
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So what is your are your current problems? Is there only an issue with getting your Symantec firewall enabled?

    By the way is your WinXP SP2 firewall disabled? It should be if you are using a 3rd party firewall.
     
  35. TheBlackClap

    TheBlackClap Private First Class


    Chaslang,
    I dont have any performance problems like we worked out yesterday. I guess I am a little blown away as this is the second time my firewall/antivirus has been disabled with me doing nothing.

    Yes the standard WinXP firewall that came with the PC is disabled and symantec has full control.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you need to consider dumping Symantec (all of it) and getting something better.

    Is your Symantec firewall enabled now?
     
  37. TheBlackClap

    TheBlackClap Private First Class


    yes sir, I repaired it and now it is fine. So the logs you looked at earlier would have shown you if someone is hacking into my PC?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes but sometimes not! There are many new stealth programs (some called rootkits) that hide themselves from normal scans. Part of the reason we run the READ ME and keep telling people to do that before HJT is because in reality HJT does not show that much and it does not indicate bad from good. It just shows a the contents of a few registry locations and shows running processes. And even using it to fix a particular line (which just removes a registry key) is not a comprehensive as the cleanup performed by the scanning tools.

    There are a bunch more tools that we can run if you desire to dig in deeper.
     
  39. TheBlackClap

    TheBlackClap Private First Class

    That sounds good to me Chaslang, I would rather be careful and check all avenues than get screwed.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the steps in the below and attach the logs:
    Also download Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of log.

    You can also run the below tools if desired:

    avast! Virus Cleaner Tool No installation required! Ready to run as is
    McAfee AVERT Stinger..... No installation required! Ready to run as is.
     
  41. TheBlackClap

    TheBlackClap Private First Class

    Cool thanks chas, I will post what I have :)
     
    Last edited by a moderator: Jan 27, 2006
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay when finished, just attach the three logs and also tell me the results of the Avast and Stinger scans.
     
  43. TheBlackClap

    TheBlackClap Private First Class

    Okay, will do Chaslang, thanks!
     
  44. TheBlackClap

    TheBlackClap Private First Class

    OK Chaslang. I couldn't get a log for the Mcafee stinger, nothing was on it though. Here are all the logs plus HJT.
     
  45. TheBlackClap

    TheBlackClap Private First Class

    sorry here it is. One more attachment in next post
     
    Last edited: Oct 10, 2006
  46. TheBlackClap

    TheBlackClap Private First Class

    last log
     
    Last edited: Oct 10, 2006
  47. TheBlackClap

    TheBlackClap Private First Class

    My PC just froze in the middle of viewing the internet. ctrl alt del, didnt work so I had to do a hard shutdown. Not good. I really hope you can see something from these logs Chaslang
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs show no indications of any real malware issues. Just the same minor items in your HJT log I mentioned early which have nothing to do with your problems. Have HJT fix the below lines so at least we have them out of the way:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

    I suggest you pursue this further in the Software Forum. You may have a hardware or software conflict. Somethings I would try are:
    - check if you ever have crashes in safe mode
    - possibly disable certain software from loading (maybe even uninstall it) to see if this helps. I would start with uninstalling Symantec.
    - running a memory tester. This directory has a bunch of them: http://www.majorgeeks.com/downloads26.html this one may be a good start: Memtest86+

    - I would also recommend looking at your Event log for additional information that may be given on the crashes. You may have to enable event logging! The guys in the Software Forum can help with this.

    You should put a link in your thread in the Software Forum to this one so they can reference it to see what we have done.
     
    Last edited: Jan 27, 2006
  49. TheBlackClap

    TheBlackClap Private First Class

    Thanks Chaslang, I will refer as you stated. Thanks for you help and assistance. Have a good one dude.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds