Weird issue with my computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by silas, Feb 27, 2009.

  1. silas

    silas MajorGeek

    I don't know if this belongs here or not. But here's what happen. I do nothing cept play an online game, read forums, and browse. I don't download anything (that I know of). Anyways this program came back to my computer that (I got rid of by deleting and uninstalling it) Its windows xp 2009 virus thing. I asked if this was a true legit program that downloaded and IS trying to help me. But no one said yes or no. I think its just spyware or something. It keeps popping up going nuts saying keylogger, virus, trojans, this and that all on my computer(its being attacked right now). Anyways So what happen I was browsing the internet. The program popped up and I closed it. It repeats it over and over.. I then go to restart my computer(because its being slow as heck) And I leave it off for some minutes, then I turn off the power strip to the wall (where dsl modem is hooked up to-plus the computer) I heard this can help slowness/reset start over. Anyways I turn it on and It loads up dsl.. Anyways I turn on the computer. It comes on fine.. then 20 seconds later.. BOOM shuts off computer and takes me to a blue screen with alot of info on it. Ill get to info in sec... anyways I it talked about some error and if it happen for the 1st time then just restart and it may work.. So I do that and still loads up and 20 seconds later goes to blue screen.. So finally I try many ways of getting into my computer(I tried safemode, other uses, my user, I tried booting into it different ways. And non of them would work.. it get stuck or just do nothing. So I had to litterally restart the computer like 15 times in 30 minutes tring to get into the computer. Anyways I was finally able to get into an OLD SAVED spot.. anyways I get in.. slow but iam in.. Anyways I automatically.. do a virus scan while pc going nuts with the program windows xp 2009 virus thingy.. keeps popping up each time I close it.. anyways I run the avg 8 and I got pics to show you want it found and what it did. If I remember you guys told me that healing is better.. then if not able to-then delete it. I dont know why I would heal a virus Id rather get rid of it but maybe someone can tell me that too? Anyways I got 1 thing that wasnt heal/deleted and I think its the main one. So I come to you with this question that Ill ask at the end. Next I did spybot n Distroy found 3 things of malware. I got picture of that too.. and I was able to fix them. Anyways what Iam is in AVG why would I heal a virus instead of deleting? And can I be fine just deleting the virus instead of healing? Can it come back if I just delete it some how or another? Another thing is.. if I got virus/trojan/w.e and I uninstall AVG and get rid of it.... do virus and stuff go back to computer or they go with the program? Same as Spybot n distroy.

    Next here a bigger pain for you guys. I wrote down most of what was on that blue screen when I couldnt get onto the computer.. Bare me with me and tell me what it is, what it means, what I do to fix, why it come up maybe its virus... ALSO tell me how to get rid of that thing on AVG that wouldnt delete/heal. Also I was thinking of using another program Because people just talking about avg not reading everything. And Iam tired of my pc getting junk on it:) Anyways Heres what I wrote down..And its not in perticular order.

    When I was finally able to get onto the computer ... after getting passed blue wall it said"c:/documents and settings/mine/application data/macramedia/common/9f54e0141.dll

    Next thing I wrote down- It said pretty much this was shut down so my computer wasnt damage. It said DRIVER_IRQL_NOT_LESS_OF_EQUAL
    big caps at top.

    Then it said you have an error of a newly added program/software.. well I thought I ****ed it up because the shut down and restart on the power cord and the dsl didn't connect with IP or w/e but I think im wrong now.. anyways it said if this is the 1st time getting this then restart the computer and it may be fixed. If this keeps happening then uninstall/take out what I added.. I never added anything.. Anyways it said disable BIOS memory options such as cashies and shadowing.. but i didn't mess with that. Said call tech at bottom with**stop: oxooooo01coxe1a21ooo,oxoooooo2,oxoooooo,oxaadf9cf6

    And below that in big words.. Beginning dump of memory physical memory dump complete. :confused

    LoL So anyways any suggestion and answers is welcome and needed tell me what is up with that and tell me all my questions if you can find them in this long annoying post thanks for helping.

    Okay I also forgot.. I got some cookies to look at I dont know what they are.. and they said they could be dangerous.. I also did ccleaner.. Another thing is i had more then max on pictures.. So ill try to smash em together with paint.

    So my questions are I think these.

    Whats that blue screen, why it come up, why my computer get mess up over it, how I got it maybe, and If I need to fix/or was it part of virus?

    If I have virus on AVG AND spybot n D and there in the vault or healed or deleted. When I delete the programs and uninstalled them.. will those come back? Or will they go with the program?

    Is it better to heal a virus then delete ? Why? And what does heal, put in vault, delete do?

    Also theres 1 item on AVG (which I think is the main virus) It didn't do anything So how Should I get rid of it?

    What are those viruses?

    What and why are those cookies warned to be bad?

    What and is windows xp 2009 program that keep coming back legit or is it bad that I keep getting from some site? I already deleted it before and uninstalled it?

    Also if it is legit why Does it go nuts on all these kinds of attacks Iam getting .. when avg and spybot got non of them?

    Will my computer be okay or what shall I do.. I was thinking of going to different virus, spyware.. something people say they use just as much.. but its better..? Or stick with this stuff.
     

    Attached Files:

    • 11.jpg
      11.jpg
      File size:
      111.9 KB
      Views:
      7
    • 22.jpg
      22.jpg
      File size:
      110.5 KB
      Views:
      5
    • 33.jpg
      33.jpg
      File size:
      98.9 KB
      Views:
      5
  2. silas

    silas MajorGeek

    Alright after I done all this and typed it here. I go to finally restart the computer. I restart it.. Loads SUPER slow.. like 5 minutes atleast... anyways I go to open firefox. This box comes up (which is in the picture) and I click dont okay. then it pops up next box(in picture) saying microsoft closing me down due to danger or w/e And then firefox would close.. anyways then I wait and firefox opened twice.. ? Weird.. but So far I havn't done anything.. and Iam just sitting on the forum for an answer.. Because if I restart I may get another issue:cry
     

    Attached Files:

  3. silas

    silas MajorGeek

    Question on startup section

    Iam looking at this site. http://www.sysinfo.org/startuplist.php?filter=jusched

    And Iam looking through it to search for what in my startup is good/or bad and if I need it or not to(because my computer is horrible slow now from me having previous issues which is in another thread I just made. My question is I got a thing called jushed and on that page.. it says its bad with an X which means(most likely its bad and a virus) and the way I looked is on my tab it says something about sub java.. and has an exe at the end.. so on that chart the .exe and something about sunjava-it says its a trojan and so I should get rid of it? How I do that? AVG and spybot didnt find it...
     
  4. silas

    silas MajorGeek

    Re: Question on startup section

    I also found that I got a file on startup named sysguard.exe.. its in c:program files/sysguard.exe but when I looked it up.. nothing.. but all the other sys.. something its all trojan/virus... bad? How i get rid of it?

    Another thing I cant find is..9f54e0141 rundll32.exe says location is microsoft application.
     
  5. silas

    silas MajorGeek

    Re: Question on startup section

    I unchecked the avg startup and restarted the computer. The computer popped up a window saying"I have used a system config. and the system is IN currently a dianostic or selective mode" causing this msg to show. So in order to go back and stop it.. i need to change it back.. So my question is.. what is dianostic and selective mode? Is that why it slow?
     
  6. silas

    silas MajorGeek

    Question about Microsoft site

    I was checking out microsoft website and their programs they offer and try. I got issues but I am not getting it with avg and spybot.. do you think I could try downloading worm program off microsoft and the other programs and try them?

    Also a question on zone alarm I downloaded.. how come it keeps popping up the window every so often saying this is tring to get through.. when all iam doing is browsing this site . I would assume it just ask permission to on each site once.
     
  7. silas

    silas MajorGeek

    Browsing some malware

    And I seen a file if it was called"zblob or w/e it is part of smithfraud or whatever.. and I need to do special things to it? I remember on scanning with avg that the zblog was last thing it scan and took forever scanning. http://forums.majorgeeks.com/showthread.php?t=74265 and why does it say post this on thread before step 2? You guys check if its bad?
     

    Attached Files:

  8. silas

    silas MajorGeek

    Re: Browsing some malware

    Heres the second report.. after I did it.. and also when i went back into normal mode.. my auto updates are gone and turned security off.. and it took my background on computer away to something gay color:( But did this work and get rid of anything on my computer?
     

    Attached Files:

  9. silas

    silas MajorGeek

    Okay I found on microsoft.. that the code I got on blue screen at the start of this mess means (that my driver tried to go into an area it wasn't suppose too) says to fix is is to use my windows debugger.. to try to find it and disable it or replace it. Does that mean that my driver is f'ed up? Iam just really confused with error on computer part, error from virus, errors from all my programs I tried got rid of alot of stuff... I just dont know.. I got until tuesday to mess with it. If anyone can think of a answer and do step by step.. ill be more then happy.Does anyone know where I can get a debugger for windows xp. I typed it into the search engine on microsoft.. and it came up with like 5 pages atleast.. :/ I really dunno what iam doing with it even it i downloaded right one.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The answer is almost always the same and it is what you should have done before doing whatever you have been doing and befor posting here. Here is the answer:

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  11. silas

    silas MajorGeek

    See the thing is I can run all programs (that I know of), I've downloaded many virus/spyware remove programs to clean it up, and even had a registry cleaner try. I'am tring all this because my computer some how is really slow, and loading things can take a while. I don't think its the internet.. Because some sites like this is lagless, but if I go to open firefox or anything else, or watch a movie its slow. So the thing is (I don't know if i messed my computer up to make it slow by removing stuff) I got that error and havn't got it sense I cleaned the computer, but once I cleaned computer it wasn't able to get rid of one virus.. and also it started being really slow at this time (getting rid of bad stuff). And I search thing's and find that they are named as bad files.. and there related to trojans, but theres alot on here if its true. Anyways Iam tring to figure out how to get and what I can do to get help of find what is slowing it down.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Neither do we.

    If you want help, follow the instructions and attach all of the requested logs. Otherwise I suggest that you post in the Software Forum since slow computers are quite frequently due to what you are running and your PC specs. Also they could just as easily be due to Windows problems.
     
  13. silas

    silas MajorGeek

    Alright I got a question. Heres my update on things.

    In the past I ran all sorts of programs- avg8, spybot, other spyware and anti virus programs, and a registry cleaner.

    It then got rid of stuff (and on few thing's it said it couldn't delete them) anyways I think Iam infected and maybe something on the inside is mess up.. if its not a virus,trojan, or etc. ANYWAYS I 1 time got hit with when starting the computer and it went to blue screen saying error microsoft is here because its dumping memory and it said a code that I later found out was about driver off a site. Anyways I finally got into the computer and I ran programs and so far I havn't hit it again. Now my computer is extremely slow, pauses, freezes up for time just going to sites, etc..

    Next I did all the read and run things few weeks ago. Now Iam here tring this suggestion on what Chaslang said. And I downloaded and ran all those programs - superanitispyware, spybot n destroy, MalewareBytesAnitware, combofix, and finally MGTools.

    Anyways I think I got the logs for all but I dont truly understand the MGTool one? Can I just attack the zip file of it or do I have to click things and make them turn into log and add all together or what. I read the site, and iam confused..

    Everything seem to work fine. Everything found atleast something cept spybot that didn't find any.

    Iam going to post attachments when I find out how to get the MGtool here to add to thread.

    Also what will these logs show/what are they capable of showing? Do they show my IP or any important info that I shouldn't put there? Can my logs show what can be causing my computer slowness?
     
  14. silas

    silas MajorGeek

    Iam really sorry for bumping. But I am "hopefully adding all the log files of those programs I did". Should be combofix, malwarebytesanti, spybot-didnt find anything, MGtools, and superantispyware. If you need more tell me what and how?
     

    Attached Files:

  15. silas

    silas MajorGeek

    Here's more of the things sorry for reposting.
     

    Attached Files:

  16. silas

    silas MajorGeek

    Finally are these the ones you need from MGtools? And if you need more from the file MGtools tell me which ones exactly.. and if you dont need any of these that I have posted tell me and Ill get rid of them. Just tell me if I got all of the right ones or not..:(
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach only the logs requested in the READ & RUN ME instructions. We do not need a Spybot log (and you did not attach a Spybot log even though you named it like one) and we do not want you posting individual logs from the MGtools folder. The log from MGtools.exe is the C:\MGlogs.zip file and you need to attach this before we can continue. Nor should you be renaming log files.
     
  18. silas

    silas MajorGeek

    Hm maybe someone can now tell me why after Ive done this.. I restarted the computer and the computer now says something about "finding diskette" and I cant go into safemode or anything. I have to get it reformated and also Iam on friends pc atm. So why did this go wrong? I followed each step perfect.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Quite possibly it is just due to the infection you had. For the last month we have been getting more and more PCs that are so seriously infected that they are requiring reinstalls. Many many operating system files are getting infected and all replacement copies on the PCs are also getting infected thus making it basically impossible to fix unless the end user (you) have a Windows bootable CD that is the same service pack revision level. And even then the PCs can be unreliable and untrustworthy.

    Since you never attached the required MGlogs.zip file I could not check to see if various system files were corrupted. And within the last 2 weeks the infections have gotten smarter and are now corrupting the system files but keeping there file dates and sizes the same which makes it undetectable unless your antivirus program is smart enough to find the changes. And from what we are seeing, the antivirus programs have a major deficiency since they are not protecting from this infection. Nor are they detecting it.
     
  20. silas

    silas MajorGeek

    Alright thanks maybe you can go to software or where else iam starting new thread plz and thanks.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but I'm too busy in this forum to have the time to work non-malware issues. Unless your PC is bootable, there is not much we can do for you in this forum. Once you can boot up and login, we can help you here, but we need ALL of the logs requested in the cleaning procedures.
     
  22. silas

    silas MajorGeek

    I deleted the logs I had Because I thought they were no useful and this thread was dropped. Anyways I did all that stuff and after I scanned the pc with those programs.. I restarted it and it messed up bad enough to where I had to have a guy reformate it/fix it to where it will load up. Alot of stuff is gone and not on it.. but then again some files are still here.. but I was deleting them. And Iam affraid if I run those again.. it mess up and Ill have to reformate/fix again.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no idea what you are talking about. If you formatted your system the only thing that will be there is what you reinstalled.

    If you formatted your system, you don't need to run the cleaning procedure because your system should not be infected. That is unless you are reinstalling from infected backups.
     
  24. silas

    silas MajorGeek

    I had a guy come over after all these problems, I ran those programs - I and posted logs, I didn't delete unless told too. I restarted and couldn't log in. It said press f2 and f12 I believe.. And each time I tried, it would go to blue screen with info of the computer on it.. Like maintaines, drivers, etc.. and When id restart it do the same. Anyways I couldn't go into anything else ONLY that. So I "supposly had a guy come over and reformat". I let the guy do his thing.. and after wards it was cleaned desktop with just recycling bin and internet explorer on it. So I was messing around the files in c:/whatever, and seen many files still there that Was there before this so called (reformat) Many files were there but the main icon wasn't for many of them. I think it was a poop job reformat if that is even what he did.. I'am sure he said he did (I don't think he fixed it and left it) Anyways I deleted the logs and folders and downloaded fire fox, java,and adobe flash player so far to just surf the net. I don't know what he did and I'm sure I'm not safe.. But I did do avg 8 and spy bot after wards and nothing cept cookies.. AND I'm affraid to redo those scans.. because it will maybe mess it up and Ill definantly get my arse beat by my gf for messing with her pc .
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If any original files and/or folders were still around, he did not do a format. He may have performed a repair install or a rebuild. Doing this leaves original files and folders in place. It also leaves many infections you may have had in place too which means a PC still needs to be cleaned if a repair install is performed.

    As I said above, you may still have infections since the PC was not actually formatted.

    The scans do not mess up PCs. The infections that PCs may have can cause problems when the scans are run and the infections are cleaned. Even running AVG could potentially cause problems if the removed a file necessary for the OS to work.

    You can try running just MBAM and MGtools and attaching those two logs. This will give us a little information anyway. Just running these is not comprehensive, but it does tell us quite a lot.
     
  26. silas

    silas MajorGeek

    Whats MBAM? Got a link?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's an abbreviation for Malwarebytes Anti-Malware. The link is in the READ & RUN ME. Similarly we commonly say SAS for SUPERAntiSpyware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds