Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Operating Systems » Windows XP/2000
Register for a Free Account

Windows XP/2000 - Computer Freeze After Start Up - Malware? posted in the Operating Systems forums; Hello everyone, I have a problem with my Compaq nx9030 (Windows XP SP3) laptop. Basically, today, after about 40 minutes of work it froze up. I tried to restart the ...


Reply
Scan your PC for Errors
Old 04-11-2009   #1
Bronze Member
 
Join Date: Apr 2009
Posts: 19
PC Experience: Experienced
Default Computer Freeze After Start Up - Malware?

Hello everyone,

I have a problem with my Compaq nx9030 (Windows XP SP3) laptop. Basically, today, after about 40 minutes of work it froze up. I tried to restart the system but it always freezes up after 30 seconds or so. I've gone through the whole system restore procedure, to no avail. My system works in safe mode with network connectivity, which is what I am using at the moment. Basically, it appears to be the same problem another user, DevilFish, seems to have experienced and so I assumed some kind of malware is behind it. I performed all the necessary scans and I am posting the logs here. Any help whatsoever would be appreciated, as I am in the midst of a dissertation, so yeah... hehe, not great timing for a computer crash. Thanks a lot and I wish everyone a pleasant day.


---


Malwarebytes log:

Malwarebytes' Anti-Malware 1.36
Database version: 1966
Windows 5.1.2600 Service Pack 3

2009-04-11 15:04:04
mbam-log-2009-04-11 (15-04-04).txt

Scan type: Full Scan (C:\|)
Objects scanned: 209771
Time elapsed: 59 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


---


HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:16:11, on 2009-04-11
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\***edited***\Desktop\HiJackThis\HijackThi s.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1103356243828
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett Packard Company - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 7712 bytes
Cipher_pipe is offline   Reply With Quote
Advertisement - Register to Remove
Old 04-11-2009   #2
Senior Security Analyst
 
Pancake's Avatar
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 6,866
PC Experience: Elite PC Guru
Default Re: Computer Freeze After Start Up - Malware?

From what you are saying and from looking at your log this does not appear to be a malware problem so I will move you to Windows XP/2000 forum.
__________________
  • An Australian Member of
  • and
My real name is Eddy
Pancake is online now   Reply With Quote
Old 04-12-2009   #3
Bronze Member
 
Join Date: Apr 2009
Posts: 19
PC Experience: Experienced
Default Re: Computer Freeze After Start Up - Malware?

Right, an update. It's still not working. Basically, what happens, regardless of whether I log in or not, the computer freezes up within 30-45 seconds of displaying the log in screen. It's not a complete freeze; I can still move my mouse around and when I click on icons, they do get highlighted about 2 minutes after I click on them. I cannot run any programs, however. Also, for whatever reason, I cannot connect with Firefox anymore, so I'm using Opera now, which seems to be working... so far.

As for how the problem arose, I was doing some random browsing yesterday morning before I decided to continue working on my dissertation. After having done so, I opened the Word document with my work and My Computer. At that point, the whole freeze up started. I couldn't restart the system and I couldn't get Task Manager to work, so I had to do a cold restart. And then the problems began, as described above.

I'll appreciate any help offered, I'd just really want to get back to working on that paper...
Cipher_pipe is offline   Reply With Quote
Old 04-12-2009   #4
Bronze Member
 
Join Date: Apr 2009
Posts: 19
PC Experience: Experienced
Default Re: Computer Freeze After Start Up - Malware?

Anyone? Anything? Please?
Cipher_pipe is offline   Reply With Quote
Old 04-12-2009   #5
Stoooooopid Girl.
 
Jelly Bean's Avatar
 
Join Date: Feb 2008
Location: Swansea
Posts: 12,727
PC Experience: None.
Default Re: Computer Freeze After Start Up - Malware?

Lets check a few things,I am not sure of the issue at the moment.

In XP click on your start button and then open the run box.

In the run box type cmd and hit ok.

A command prompt window will open.

In Vista click on your start button/choose all programs/then choose accessories/in the list you will see command prompt.

You need to run command prompt in elivated Admin in Vista so right click on command prompt and choose run as Admin.

A command prompt window will open.

For both XP/Vista:

Copy and paste in the command prompt window chkdsk /r and hit the enter key on your keyboard.

If you get a message saying:

Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N).

Type Y, and then press enter on your keyboard then restart your computer and let chkdsk run.

Please post results of chkdsk.

Ok lets check lets see if we can rule out/in a RAM/Memory issue.

DownloadMemtest86 and follow the instructions on "How To".

Note: If you do not have a floppy drive you can use a CD/USB stick,scroll down the attached links and you will notice the diffrent downloads.

Let us rule out or rule in a heating issue.

Firstly power off your computer and remove from the power outlet.

Carefully give the internal case a good clean,especialy the fans.This may take a little time if it is very dusty in there.

Then download and run SpeedFan,could you then post me a screenshot or list the tempratures for me please.

Download one of these software programs,they are both very good and I use them.

CCleaner.

Revo Uninstaller.

Please read the instructions before usage.

Please note Revo Uninstaller doesnt work with a 64 bit operating system.

In XP click on start then open the run box.

Type in the run box cmd and hit the ok button.

Copy and paste in scf /scannow and put in the XP install disk and hit enter on your keyboard.

Let sfc /scannow run.

Please post results.

Note: sfc /scannow is sfc "space" /scannow.


In Vista click start/All Programs/Accessories/Right click on command prompt and choose run as Admin.

Copy and paste in the command prompt window sfc /scannow and hit enter on your keyboard.Let sfc /scannow now run.

Please post results.

Note: sfc /scannow is sfc "space" /scannow.

Perform in safe mode if you have to.
__________________
Rwy'n ceisio fy ngorau.
Jelly Bean is offline   Reply With Quote
Old 04-13-2009   #6
Bronze Member
 
Join Date: Apr 2009
Posts: 19
PC Experience: Experienced
Default Re: Computer Freeze After Start Up - Malware?

Hi Jelly Bean, thanks for the reply. I ran chkdsk, everything was clean. I tried to clean the computer as best as I could, alas, it's a laptop, so I couldn't get everywhere. Speedfan gave me the following readings: HD0 - 42C, ACPI Temp1 - 60C (which is rather high, I can imagine). I'll run CCleaner next and post the results.
Cipher_pipe is offline   Reply With Quote
Old 04-13-2009   #7
Bronze Member
 
Join Date: Apr 2009
Posts: 19
PC Experience: Experienced
Default Re: Computer Freeze After Start Up - Malware?

I ran CCleaner, deleted everything I didn't need, fixed all issues, however, still the same freezing problem on start up. I'm running Memtest at the moment and will post the results.
Cipher_pipe is offline   Reply With Quote

Reply


Bookmarks

Tags
computer, Fixed:, freeze, malware, start, [Fixed]
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Fixed: computer freeze csgreene [Fixed] Hijackthis! Logs 10 10-14-2008 12:34 AM
Answered: Computer freeze George001 Windows XP/2000 5 08-27-2008 09:09 PM
[Resolved]XP will not start after freeze up doggerdan Windows XP/2000 12 05-25-2007 06:08 AM
[Fixed] start up freeze xznfgzx Windows XP/2000 9 01-25-2007 09:12 PM
My Computer freeze with some CD-RW joker123 Windows XP/2000 5 09-07-2005 04:51 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 03:45 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2