WiredWX Hobby Weather ToolsLog in

 


descriptionPc won't shut down & keeps freezing EmptyPc won''t shut down & keeps freezing

more_horiz
Hi my other pc is in repairs & i'm currently using my daughters (or trying to!). Its running on xp & won't shut down. She had no internet access on it so i doubt its avirus or malware. it also freezes quite often. Got this msg on start up not sure if its relavent???? Let me think

Windows cannot find...C:\WINDOWS\config\csrss.exe

Thanks.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
:oops: sorry forgot to add the log!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:06:32, on 20/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Lexmark 4300 Series\lxcemon.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\Documents and Settings\Orinne\Local Settings\Temporary Internet Files\Content.IE5\POU3CY5A\setup_246_509_[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ie/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {F3847163-16EB-4D60-897F-6416BB863EC7} - C:\WINDOWS\system32\atmli.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [InstallProgram] C:\Documents and Settings\Orinne\Local Settings\Temporary Internet Files\Content.IE5\POU3CY5A\setup_246_509_[1].exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E6B1AFF-EB28-4B81-917A-B290AB519D2B}: NameServer = Edited out for privacy
O17 - HKLM\System\CS8\Services\Tcpip\..\{0E6B1AFF-EB28-4B81-917A-B290AB519D2B}: NameServer = Edited out for privacy
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5029 bytes

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
Hello.
The log shows a malware infection, so sometime whenever, it has or had internet connection, either that or someone used an infected USB stick/transported infected files onto the machine.

I've just run a check on a DNS setting, I need to know if you/your ISP is Irish, or located in Ireland.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {F3847163-16EB-4D60-897F-6416BB863EC7} - C:\WINDOWS\system32\atmli.dll
    O4 - HKCU\..\Run: [InstallProgram] C:\Documents and Settings\Orinne\Local Settings\Temporary Internet Files\Content.IE5\POU3CY5A\setup_246_509_[1].exe


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
yes my ISP provider is in Ireland. You helped me last week on my main PC which had malware issues & we do use a usb often to transfer files from my to this pc. I didn't realise you could transfer malware :oops: I do now!

Gonna follow above instructions now, thanks

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
Hello.
I have edited your log post for privacy because the IP I ran a trace on goes back to exact details, real name/address of what is likely you, or your ISP.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
Hello again! here is the log after the mbam

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 2

20/05/2009 21:02:34
mbam-log-2009-05-20 (21-02-34).txt

Scan type: Quick Scan
Objects scanned: 60753
Time elapsed: 8 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\SecuriSoft SARL (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\Adobe PhotoShop CS3 Extended Keygen + Activation.exe (Trojan.Horst) -> Quarantined and deleted successfully.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
Hello.
Two things here.

First, pleace update the MBAM database, you have an extremely old database running there.

Second, MBAM has found a crack/keygen, remove anymore that maybe lying around, otherwise I will refuse to help you.

"C:\WINDOWS\Adobe PhotoShop CS3 Extended Keygen + Activation.exe (Trojan.Horst) -> Quarantined and deleted successfully."

After an updated scan with MBAM, run this next tool.

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
"Second, MBAM has found a crack/keygen, remove anymore that maybe lying around, otherwise I will refuse to help you."

What is a crack/keygen? doesn't sound good! did search & it yielded nothing. I bought this Pc 2nd hand had most stuff preinstalled do you think i should do a clean install? have the xp disk that came with it.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
A crack/keygen is something hackers use to bypass programs that have to be bought to use fully, like AV's, photoshop, etc. This kind of activity is illegal, so if this machine is second hand, I would probably format it too, god knows what else maybe lurking.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
format, thats wiping the drive right? so a clean install & choose option to reformat? Have all pics & music documents etc.. backed up now.
thanks for the advice, i'll do that without further ado.

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
Okay. Smile...

descriptionPc won't shut down & keeps freezing EmptyRe: Pc won't shut down & keeps freezing

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum