Still Having Stability Issues After Run Me / Read Me First

Discussion in 'Malware Help (A Specialist Will Reply)' started by boyblunder, Jul 14, 2009.

  1. boyblunder

    boyblunder Private E-2

    I've been having some major stability issues on my Windows XP system and I thought I'd check with you guys before I bring down the hammer and reinstall the OS.

    The basic issue is this. When I'm running a program, any program, it invariably locks up after about five minutes of use, becomes unusable, and then the entire system locks up.

    The symptoms of the crash are as follows
    • If the piece of software that locks up is a media player, it repeats a couple microsecond loop of audio over and over.
    • If you select an option within a menu (File, Edit, etc...) the selected item will still show as highlighted on the screen after the rest of the menu disappears.
    • Eventually the menu bar at the bottom of the screen (the one with Start and the clock in it) will no longer show tabs for individual programs, just the icons remain without accompanying text.
    • For about a minute after the first piece of software crashes you can still select other running programs if they have a visable window.
    • For about a minute after the first piece of software crashes you can still select icons on the desktop but are unable to execute new programs or open files.
    • Hitting Ctrl+Alt+Del will cause the the Task Manager icon to appear in the system tray down by the clock but will not cause the dialog box to show up.

    After these things happen its usually only a matter of minutes until the entire system becomes unresponsive and the only recourse is to reboot the system from the physical power switch.

    My first reaction after this happened was to download the latest updated definition files for my antivirus and antimalware software and scan the system. This yielded no hits. I then thought it might be an issue with either the hard disk or the RAM so i ran some diagnostics but those came back clean as well. Finally I went through the steps in the read me / run me first post and have attached the logs from that on this post. I don't know if it's a bug, but I thought I'd have you guys take a look and get an expert opinion. Thank you much for your assistance in advance.
     

    Attached Files:

  2. boyblunder

    boyblunder Private E-2

    And the final log file
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello and welcome.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. This takes time so please bear with me and thankyou for your patience.

    Kestrel13!
     
  4. boyblunder

    boyblunder Private E-2

    thanks much for the assistance!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's do this:

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.

    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log

    Now...



    1. Please go to Add or Remove Programs and uninstall the following software as requested in the R&R:

    • Viewpoint Media Player

    2. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3. FYI: Ad-Aware is not as effective as SUPERAntiSpyware and Malwarebytes that we had you install. So we suggest that you uninstall Ad-Aware (unless you purchased it) to avoid wasting any system resources on it.

    4. Tidy up this desktop:

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation.

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    jnv4_mib
    Inemon_nrau
    
    File::
    c:\docume~1\Chris\LOCALS~1\Temp\jnv4_mib.sys
    c:\program files\ivkzydn.txt
    c:\windows\warnhp.html
    c:\windows\system32\attrib.exe 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    7. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    8. Run the new MGTools.exe and attach the C:\mglogs.zip into your next reply.

    9. Also attach the log from running ComboFix.

    10. Let me know how things are running now!!

    Thanks
    Kestrel13!
     
  6. boyblunder

    boyblunder Private E-2

    Before I start in, there are two unexpected changes I've noticed on my system since I went through the Run Me First steps. First, the little speaker icon for the volume control that used to show up down by the clock is no longer there. Is there a recommended way to get that back? Second, one of the driver options in my audio software is no longer showing up, I can't recall the exact name for the life of me but it had something to do with MME / DirectX. It used to be the default one on my system and ran audio through the onboard sound card. There is still an option showing up for the onboard sound card (with the hardware name), I'm just not sure if the MME one was in any way necessary.

    Ok, summary of my actions is as follows.

    MBR run the first time, it's log is mbr-001.log and is attached below.
    MBR run with from the command line specified, it's log is mbr-002.log and is attached below.

    1. Viewpoint Media Player has been removed.
    2. Windows Messenger has been removed with the suggested tool.
    3. AdAware has ben uninstalled (hasn't done me any good recently anyway).
    4. Desktop has been tidied up. Unnecessary application shortcuts and non-link files have been removed.
    5. Anti-virus and firewall software disabled. Hijack this run, specified lines selected and fixed. Computer started to lock up after scan. The desktop background didn't re-draw itself where hijack this had been after exiting, all the desktop then disappeared, desktop program icons didn't work. Rebooted the machine and per instructions re-activated firewall and anti-virus software.
    6. Re-downloaded Combofix (I had deleted it after the run first, didn't want to have something that potent hanging out on my desktop asking to be accidentally clicked). Copied the specified information into the text file, named it accordingly and used it to execute combofix. Combofix asked me to disable my antivirus software so I did, turned off the firewall as well for good measure. Didn't touch anything until the log popped up.
    7. Downloaded the new version of MGTools, ran it, log file attached below.

    I've re-activated the anti-virus and the firewall, I'll play around with the system for a while and let you know how we're doing.

    Thanks much again for all your time and help.
     

    Attached Files:

    Last edited by a moderator: Jul 21, 2009
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please reboot with the XP CD and get into the recovery console....once there, type fixmbr and then hit enter.

    Next...

    2. We need to restore a file, so to do this let's do the below:

    Now we need to use ComboFix to restore a file.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\WINDOWS\system32\attrib.exe.vir
    
    Quit::
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    4. Also attach the log from ComboFix

    Thanks
    Kestrel13!
     
    Last edited: Jul 21, 2009
  8. boyblunder

    boyblunder Private E-2

    Done.

    Only hiccup I ran into is that the log file generated by combofix was called dequarantine.txt instead of combofix.txt.
     

    Attached Files:

    Last edited by a moderator: Jul 21, 2009
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    yes I'm sorry :) That was my fault.

    Could you please refrain from quoting such large segments of my text to you as it makes it harder to keep track of what's going on. I shall review your logs and get back to you ASAP :)

    Thanks
    Kes13!
     
  10. boyblunder

    boyblunder Private E-2

    right on, sorry about the jumbo quotes.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay a question: Did you actually run fixmbr from the Recovery Console? I suspect you did not... Those files will not be removable until that is done. In most cases, they will already be gone after the normal bootup following the running of fixmbr. So do let me know!

    Thanks
    Kes13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds