There's my sign! But I need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by azsteve, Sep 7, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Anything is possible but I don't know why the reboots would only occur on certain sites and especially if it happens using different browsers. Keep track of which sites it happens on and exactly when on those sites it happens. If it happens in IE, see if it happens the same way and same place with FireFox.


    Let's do a little more hunting! Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  2. azsteve

    azsteve Private E-2

    I downloaded the WinPFind zip file but when I launch the program a window pops up saing "File not found." The program does launch but when I choose SCAN I get the following error in another pop up window "access violation at address 0044DE27 in module 'winpfind.exe' read of 00000004"
     
  3. azsteve

    azsteve Private E-2

    should I attempt to update my modem's driver?
     
  4. azsteve

    azsteve Private E-2

    okay, i figured it out and I'll post it when it's finished
     
  5. azsteve

    azsteve Private E-2

    here's my winpfind log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Although I still see a few files ending with .com extensions in your system32 folder, I do not think they have anything to do with the rebooting. How did you get all of these .exe files renamed (or copied) to .com files?

    Quite often random reboots can be related to a faulty power supply but that does not make sense here since you say it only happens when you access certain websites. I'm not sure what is causing this. If it always happens everytime you access certain sites, you could try exiting all other running programs including your antivirus and firewall and access the sites and see if it still shuts down. If it does not, you may be able to zero in on some kind of conflict with a piece of software.
     
  7. azsteve

    azsteve Private E-2

    I'm really not sure how I got all these .com files. Could a virus have done this? What could have caused this?

    I do everything within my power to make sure this computer is in tip-top shape, but when others are on here I can't supervise the whole time. It's usually my girlfriends sister who gets on here and she swears shes not downloading anything. I can't know for sure.

    I've been telling my girlfriend and her sister to monitor when the system reboots. So I'll keep an eye on this. It didn't happen all day today but the connection does go down. I have to unplug the modem, wait for a couple minutes and plug it back in. Should I update my driver?

    This may have been coincidental but all these problems seemed to start after we added this new epson r1800 printer and software.

    Should I delete any of the files from the winpfind. If so, which ones? Should I rename some files? Convert from com to exe?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Create a user account on the PC that your girlfriend's sister can user. Do not give that account admin priviledges. Change the password for your account so she does not have access to admin priviledges. This way she can surf but she cannot install anything and has restricted priviledges.

    Look in your c:\windows\system32 folder for the below .COM files and let me know the size of the files. Also look to see if there are .EXE equivalents for each.

    C:\WINDOWS\system32\netstat.com
    C:\WINDOWS\system32\ping.com
    C:\WINDOWS\system32\taskkill.com
    C:\WINDOWS\system32\tasklist.com
    C:\WINDOWS\system32\tracert.com

    You are saying you modem disconnects now. Is that what you meant before when you said reboot. Reboot means your computer goes thru a reboot (a restart).
     
  9. azsteve

    azsteve Private E-2

    Thanks for that advice. I will do this.

    C:\WINDOWS\system32\netstat.com - have .com and .exe
    C:\WINDOWS\system32\ping.com - have .com and .exe
    C:\WINDOWS\system32\taskkill.com - have .com ONLY
    C:\WINDOWS\system32\tasklist.com - have .com ONLY
    C:\WINDOWS\system32\tracert.com - have .com and .exe
    the .com files were created in 09/01/2005 and the .exe files were created on 01/14/2005 and were modified on 03/31/2003. How is that so? Created after they were modified? All the .com files are 2 bytes but the size on disk is 4, 096 bytes (4kb).

    My computer does randomly reboot. In addition to that, I do lose my internet connection and I just unplug the modem, wait two minutes and then plug it back in.
     
    Last edited by a moderator: Sep 25, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me the size in bytes for each of the .EXE files that you found from the list we are looking for.

    Also look for the below folders to see if they are found on your PC:

    c:\windows\i386
    c:\windows\driver cache\i386
    c:\i386
     
  11. azsteve

    azsteve Private E-2

    C:\WINDOWS\system32\netstat.exe (size-30,720 bytes, size on disk- 32,768)
    C:\WINDOWS\system32\ping.exe (size and size on disk-16,384
    C:\WINDOWS\system32\taskkill.exe (don't have .exe file)
    C:\WINDOWS\system32\tasklist.exe (don't have.exe file)
    C:\WINDOWS\system32\tracert.exe (size-10,752, size on disk-12,288)


    c:\windows\i386 (I have this file and the size is: 444,045,149 bytes and the size on disk is: 458,313,728) 6020 files and 48 folders

    c:\windows\driver cache\i386 (I have this file and the size is: 98,527,375 bytes and the size on disk is: 98,611,200) 48 files

    c:\i386 (don NOT have this file)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay delete the below files:
    netstat.com
    ping.com
    taskkill.com
    tasklist.com
    tracert.com

    Look in c:\windows\i386 for taskkill.exe and tasklist.exe
    It's possible that they are compressed and named taskkill.ex_ and tasklist.ex_
    Let me know what you find.
     
  13. azsteve

    azsteve Private E-2

    Below files have been deleted.

    netstat.com
    ping.com
    taskkill.com
    tasklist.com
    tracert.com

    I did not find taskkill.exe or tasklist.exe in c:\windows\i386. I didn't find anything with taskkill or tasklist. It went from taskbarp.ch_ to taskman.ex_
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your WinXP CD? If so, you should be able to copy/extract the taskkill.ex_ and tasklist.exe_ files from the i386 folder on your CD.
     
  15. azsteve

    azsteve Private E-2

    Just so I'm clear; I should find my cd and extract taskkill.ex_ and tasklist.exe_ to c:\windows\i386 or c:\i386 (since I don't have this file should I create it)? So from my cd to my hard drive?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Basically, yes you need those files. You need to expand the files from their compressed form on the CD and put them in your system32 folder. You would need to do this from a command prompt window. Let's assume your CD drive is drive D for the below example. Here is what you would enter at the command prompt:

    expand D:\i386\taskkill.ex_ c:\windows\system32\taskkill.exe

    expand D:\i386\tasklist.ex_ c:\windows\system32\tasklist.exe
     
  17. azsteve

    azsteve Private E-2

    I'm not able to locate my winxp cd. Can I find these files online somewhere? All I can find is an old win98 cd and book.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not legally!

    If your copy of Windows XP is valid and licensed to you, you should try getting your Windows Updates. It may help some of your problems. It is step 1 in the below link (you need to follow all of these steps anyway):

    How to Protect yourself from malware!
     
  19. azsteve

    azsteve Private E-2

    I'll keep looking for my cd. The only update windows has for me is the Windows XP Service Pack 2. I've downloaded this before and didn't like its features so I removed it. Should I install this again and disable the firewall? Is this a vital update?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is a vital security update! And yes you need to disable its firewall and just use your ZoneAlarm firewall.
     
  21. azsteve

    azsteve Private E-2

    Okay, I did the windows SP2 update. I also looked around for my copy of winxp that was supposed to come with this computer but all I can find is the restore cd. I emailed the tech support staff from the makers of my machine and they told me that a copy of the operating system was on the restore cd.

    I looked on the restore cd's and could not find the two missing files.

    What other options do I have?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A restore CD is not in the same format as a normal WinXP installation CD. So the files are probably hidden either in some kind of archive on the CD. If the restore CD had and i386 folder, look in it a see what you can find. I assume you are implying that installing WinXP SP2 did not install these two files?
     
  23. azsteve

    azsteve Private E-2

    Remind me not to buy an emachine ever again. But looking at Microsoft’s website, it seems like this problem (computer not being packed with operating system cd) is commonplace.

    I did search the restore cd's and came up empty handed. I wasn't able to open a couple of the zipped .cab files. I get the following error:

    Winzip cannot open (file name) because it is not in the standard Microsoft CAB format (as defined in mid-1998) The "signature bytes" required by Microsoft CAB specifications are missing.

    Yes, your assumption about the files not being installed with the SP2 is correct.
     
  24. azsteve

    azsteve Private E-2

    Good thinking! What are you talking about (wink-wink)?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Message removed! Are you having any other problems now?
     
  26. azsteve

    azsteve Private E-2

    As of now...NO! But I will need your help installing these files. Do I just reboot in safe mode or can I do this from RUN, cmd?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since they are missing already and they are process that are not normally running, you should be able to just copy them right into the system32 folder in normal boot mode.

    You can use Windows Explorer to copy them from whatever media you will be getting them from.
     
  28. azsteve

    azsteve Private E-2

    My problem still persists. I thought the problem was gone, but no, I can't catch a break.

    I have taskkill.exe and tasklist.exe and placed them in c:\windows\system32

    I also added user accounts but after doing so I keep getting error messages when I log on. I get the 'system has recovered from a serious error, don't send report or send report.' Everytime I check send report I get a different message; reltec, graphics update, bios.
     
  29. azsteve

    azsteve Private E-2

    One other note: this problem of the computer rebooting is happening at sites other than myspace.com. It happened to me today at earth.us. But without fail it always happens on myspace. It happened to my girlfriend last night while she was working on her website.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try looking at you Event Viewer log for errors under the Application and System section. This may give you an idea of what is going on.

    To see the Event Viewer, click Start, Run and enter eventvwr.msc and click OK.

    We may be hitting a point where you need to discuss these problems in the Software Forum. It no longer appears to be malware related but rather system software or hardware and driver related.
     
  31. azsteve

    azsteve Private E-2

    I looked at the event viewer and under the System tab I got an error message: "The event log file is corrupt." Under Application there are various error messages: crypt32, application error, application hang, vss, event system, and some others, too many to list. The list is pretty long and I think I counted 140-150 error messages.

    Might we be on to something? Please say yes. Put an end to this misery.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe and maybe not. There can normally be many things in the event log. You need to zero in on anything exactly related to your reboot time. But I think you know need to pursue this in the Software forum. You should checkout the event log ASAP after one of the unexpected reboots.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds