system
January 6, 2011, 4:33pm
1
HELP!!! I cant get rid of the memory error 0X7C923845 and Win32 Error and my computer keeps freezing up! I spend half of my day shutting it down and restarting it and now I feel like I am very unproductive throughout my day.
Can someone…anyone help???
Pondus
January 6, 2011, 4:41pm
2
Follow this guide form our expert malware remover Essexboy and post the log`s here (do not post in the guide )
http://forum.avast.com/index.php?topic=53253.0
To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt. and Malwarebytes scan log)
Essexboy is usually in here from 8:00pm to 11:59pm UK time
system
January 6, 2011, 4:43pm
3
You may also consider Kaspersky’s or Dr web’s rescue disk as helping tools.
Take care
Regards,
Tenko
system
January 6, 2011, 5:07pm
4
I have tried just about everything possible including Kapersky. I will try the recommendation by Essex Boy next and post the logs, etc. Hopfully that will work
system
January 6, 2011, 5:56pm
5
Here is my Malware log:
Malwarebytes’ Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5471
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/6/2011 9:43:56 AM
mbam-log-2011-01-06 (09-43-56).txt
Scan type: Quick scan
Objects scanned: 183355
Time elapsed: 43 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
system
January 6, 2011, 5:58pm
6
make a full system scan rather.
Regards,
Tenko
Pondus
January 6, 2011, 7:52pm
7
From Malwarebytes forum
The quick scan will find any malware that's active on the system that MBAM is capable of detecting. The only real usefulness of the full scan is detecting the occasional trace that get's missed by the quick scan, and even that's pretty rare. According to one of the developers the quick scan catches 99.9% of the malware that MBAM will detect.
http://forums.malwarebytes.org/index.php?showtopic=10405&pid=50995&mode=threaded&show=&st=#entry50995
system
January 6, 2011, 11:17pm
9
Ok, I ran the full scan and this is my log:
Malwarebytes’ Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5471
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/6/2011 3:14:27 PM
mbam-log-2011-01-06 (15-14-27).txt
Scan type: Full scan (C:|)
Objects scanned: 283645
Time elapsed: 3 hour(s), 40 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Any other ideas???
Pondus
January 6, 2011, 11:24pm
11
Any other ideas??
yes...follow the suggestion in my first post
post the OTL log`s here and let Essexboy have a look
system
January 6, 2011, 11:34pm
12
I have tried just about everything I can find online. I am hoping you can help!
I have attached the OTL Log. I have tried Hitman also
Thank you!
Pondus
January 6, 2011, 11:40pm
13
Essexboy is notified, check back tomorrow
You are showing drivers from AVG and Norton running on your system - this is not helping with the stability
Download AppRemover and run it.
Click Next >>
http://www.hdrcgb.org.uk/g2g/appremover1.jpg
Ensure “Remove Security Application ” is collected and click Next >>
http://www.hdrcgb.org.uk/g2g/appremover2.jpg
AppRemover will scan all the security applications on your PC
http://www.hdrcgb.org.uk/g2g/appremover3.jpg
Select Any AVG and Norton/Symantec entries from the applications offered and click Next >> twice.
http://www.hdrcgb.org.uk/g2g/appremover4.jpg
Follow any further on-screen instructions. If asked to reboot,please do so.
.
ONCE DONE
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
PRC - [2010/09/21 19:17:47 | 000,380,928 | ---- | M] () -- C:\Documents and Settings\tara.SPECSEALS\Local Settings\Temp\cosc.exe
PRC - [2010/09/21 19:17:47 | 000,302,592 | ---- | M] (Signature Systems, Inc.) -- C:\Documents and Settings\tara.SPECSEALS\Local Settings\Temp\CFileSrv.exe
PRC - [2010/09/21 19:17:47 | 000,155,648 | ---- | M] () -- C:\Documents and Settings\tara.SPECSEALS\Local Settings\Temp\CFAM.EXE
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value foundO3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-602162358-1202660629-839522115-1116\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-602162358-1202660629-839522115-1116\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-602162358-1202660629-839522115-1116\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
[2010/12/11 02:43:03 | 000,014,739 | ---- | M] () -- C:\WINDOWS\System32\12543.js
:Files
ipconfig /flushdns /c
:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
system
January 7, 2011, 10:49pm
15
I was not able to find AVG in the list to remove. I have completed all steps requested and attached the otl file.
Thank you for your help, what is the next step?
Pondus
January 7, 2011, 10:52pm
16
you can find AVG remover here #02 http://uninstallers.blogspot.com/ there is a 32bit and 64bit
Once you have completed these steps can you let me know if there is an improvement
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\SYSTEM32\NavLogon.dll ()
[2011/01/03 07:41:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2011/01/03 07:41:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/12/30 09:11:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/12/15 07:42:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/07 10:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
:Files
ipconfig /flushdns /c
:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disck check
system
January 10, 2011, 9:04pm
18
Ok, I did the steps you recommended… so far I have had errors such as Managed Mapi Catastrophic failure on my outlook and when I go to the internet I can not click on the links because they take me to another web site. I have to type in the website in the tool bar. I did not have to to this before.
I have been running this after your steps for about an hour and had to shut my computer down twice for freezing up already. The Reference Memory error has not shown up yet.
system
January 10, 2011, 9:05pm
19
I forgot to attach my latest OTL report
OK now I will go in with the big boy
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[*]Double click on ComboFix.exe & follow the prompts.
[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.
http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
http://img.photobucket.com/albums/v706/ried7/whatnext.png
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.