Unsure if malware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by PinkStars, Oct 6, 2008.

  1. PinkStars

    PinkStars Private E-2

    Hi. I'm having many issues with my desktop. The most recent issue is with aol. Whenever I tried loading or running aol, it ran very slow. Then over time aol would no longer open, stating that the program was corrupt. I proceeded to remove the program and tryed to re-install it. Each time I attempted to re-intall, a message appearing saying the downloader was corrupt. I've been trying to just use Microsoft Internet Explorer, but it also runs very slow. As of today, when I turned on the computer, I got a message saying a drive was not found?!...but then the computer proceed to load windows. The blue screen of death also pops up more frequently when the computer is in use. So..I'm not quite sure if this is all due to malware (which I scanned for and found none of), or if it's a hardware issue. Any help would be greatly appreciated!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi PinkStars


    To rule out malware, we would need you to run the below guide and attach the requested logs for one of our malware experts to review. As you mentioned this maybe a coincidence and not malware related but best to rule malware out first then we can direct your thread to the appropriate forum area.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.



    Also if you are getting a BSOD alot then please post the full error message in full.
     
  3. PinkStars

    PinkStars Private E-2

    Ok, so I downloaded all the setups for the various programs for malware removal. Every time I went to install each program, I got an error message saying one of the files was corrupted. I also tried to download Java, but I got an error saying "unpacking RT failed". I'm really thinking this isn't a malware problem..but I don't really know what it is, and therefore I don't know in which forum to post. If it is a malware problem, I can't install and of the software. Any ideas??
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you read this part:
     
  5. PinkStars

    PinkStars Private E-2

    Ok, so I was able to run CCleaner, SuperAntispyware, Malwarebytes' Anti-malware, and MGTools. I downloaded the other programs (Combofix and Spybots) onto my laptop, then copied them to this desktop, but the programs still will not run?! I keep receiving corrupted file error messages for Combofix. Spybots opens, but when I try to update, the error message states the external update program is corrupted. It won't let me check for problems because it tells me I need to update in order to do so. The programs run fine on my laptop. I have attached the logs of the programs I was able to run. Do you think this is a malware problem? If not, what forum should I post in?? Thanks!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing much in your logs....but we can do this:

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\32788R22FWJFW

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Tell me how things are running.
     
  7. PinkStars

    PinkStars Private E-2

    I followed all the steps, but I could not install Java Runtime 6. When I attempted to, a message popped up saying that " the cabinet file C:\DocumentsandSettings\Owner\ApplicationData\Sun\Java\..\Data1.cab has an invalid digital signature. The cabinet file may be corrupt". Also, before running the installation, it told me that I did not have an OS which supported the platform...but I have Windows SP2 installed :confused

    I have attached the MGtools log. I also got another error message when trying to run this program. The message said that processdll.ese application failed to initialize properly..
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you not running any Anti-virus software?

    I see that SP2 is in your add/remove list, however, your logs indicate it is only:
    OS Name Microsoft Windows XP Home Edition
    Version 5.1.2600 Service Pack 1

    As to slowness....you only have 512 in memory and only @192 left over. That could be the cause of slowness.
     
  9. PinkStars

    PinkStars Private E-2

    No there is no anti-virus software installed. I tried to run windows updates to install SP2, but it failed. I tried to directly download it from the Microsoft website, but when I went to install it I got an error message saying extraction failed, file is corrupt. Can I download it to another computer, then burn it and install from a cd?

    Also, why is there only 192 left over? As I can see, there is not much installed on the computer to begin with..what is taking up so much memory?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note to Tim,

    All versions of software from the READ & RUN ME are way out of date. SAS, MBAM, & MGtools are all incorrect versions.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are leaving yourself wide open for infections without an active anti-virus program installed. You may download any of the freeware AV's from HERE

    Did you try deleting the SP2 from the add/remove list? Did you get an error message?

    Yes, you can download to a different computer and transfer via cd or thumb drive.....

    I would recommend that you first install the AV program and run it! Make sure it doesn't report any malware. Then, if clean, install SP3!

    You may also benefit from this:
    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks Chas......


    @PinkStars ....please remove those items ( SAS, MBAM and MGtools) and download and run the updated versions from the current Read and Run First instructions. Make sure that after installing SAS & MBAM you update them again to the current database/detections since the installation only includes the current program version.
     
    Last edited by a moderator: Oct 20, 2008
  13. PinkStars

    PinkStars Private E-2

    I attempted to run AVG from a cd and a thumb drive, but neither worked. I actually can not run anything from the thumb drive because the computer will not install whatever is necessary to recognize the drive. I tried to install the software from the burned cd, but got the same error message as before. I also tried to run the program directly from the cd, but it gave me another error message.

    I can not uninstall SP2 because that also gives me an error message. Everything I have attempted to install or uninstall does not work. Every program I have tried to install gives me the same corruption error message. I re-formatted the computer's hard drive a few weeks ago. Could this be part of the problem? I will try and see if I can download and run the updated versions of those progams.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have either missing or corrupt system files.

    Try going to start / run / type "sfc /scannow" without qoutes and have your xp cd handy. Run it twice.
     
  15. PinkStars

    PinkStars Private E-2

    I just tried to run the scan...the window pops up as if it's about to start scanning, then just disappears. I tried restarted the computer a few times, but no luck. Do I need to reformat the drive again? This would be the third time reformatting...it never seems to solve the problem, but I really don't know what else to do...I'm ready to throw the computer out the window!!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have done clean installs with a total reformat and still have issues afterwards? This sounds like a hardware issue.....possibly faulty ram. Your inability to get clean downloads or to install programs would be indicative of that. :(

    Perhaps you should post in the software or hardware section. :(
     
  17. PinkStars

    PinkStars Private E-2

    Ok, I was thinking it may be a hardware problem too, but I wanted to make sure it wasn't malware causing the problem first. I will try posting in the hardware section. Thanks for all your help! I really appreciate it. :)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds