Unsolved
This post is more than 5 years old
15 Posts
0
19385
December 2nd, 2009 11:00
CPU maxed out in a normal boot, Can't boot in Safe Mode. Malware suspected
I'm new to this community and a bit of a novice with a computer, so please bear with me.
I have a Dell Dimensions E520 running XP Media Center Edition 2002 SP3. The computer has been getting extremely slow and suspect some Malware. The computer will boot in normal mode, but then appears to hang up. I looked at Task Manager (which took forever to open) and saw the CPU was maxed out by 2 processes (CLI.exe and dsca.exe at about 50% each ). If I end those 2 tasks, it will allow me to move around abit. When I go to the Dell website and try to download updated drivers, the task manager shows dfsvc.exe at 50% and won't download anything or let me open it. If a second dell window opens, I get a second dfsvc.exe at 50% and get hung up again. I ran Spy Bot which identified 6 trojans which I deleted, but didn't seem to help. If I try to boot the computer in Safe mode I get the Blue Screen with the following:
Stop: 0x0000007E (0xC0000005, 0x80537009, 0xF789E508, 0XF789E204). If I restart and allow it to boot in normal mode, I go back to the CPU being maxed out as noted above. Since I ran SpyBot and with the CLI.exex and dsca.exe ended, I've been getting occasional misdirection on my internet explorer 7 and get a 400 Bad Request on ther task manager and an Error with a Goggle page showing, sometimes it appears I'll get these randomly, but believe this is caused by some bcakground attempts (i.e. auto updates) that are getting redirected.
I've looked thru the forum threads and didn't find anything quite what I have, although some threads from Bugbatter looked similiar to what I'm fighting. Any thoughts on how I might proceed?
Thanks


Daniel3026
5 Posts
0
December 4th, 2009 10:00
Normal 0 21 MicrosoftInternetExplorer4Hi,West7948
I've been having the same blue screen, and all 5 codes are exactly the same. My PC boots fine when I boot it normally. But if I try to boot it on safe mode (or any other way than a normal startup of windows for that matter) I have a system crash at startup with the blue screen showing the same codes than you have.But it doesn't end there. From that point on, there's no way that the PC will boot at all... I tried every options windows gives me at boot time, even the ones hiding behind F8. To get around this, first of, I used another HD, and put a fresh install of XP, then I copied the boot.ini file from the fresh version of XP and pasted it in the other HD, witch was then a slave and had E:\ as a letter. Then I reboot on my original HD and it worked. I've been trying all kinds of things for the past 4 days.. tried all kinds of scans, Avira antivir, Bit Defender online scan, Spybot S&D, Registry cleaner, Eset NOD 32 online scan, Malware bytes' anti-malware... and they all came back with nothing...But it's obvious that I have something cuz both my IE and Firefox keeps redirecting me to other sites, often 2 to 3 redirects by one single click. So, tried every scans I could think of, nothign came out of that.. Can't boot in safe mode to make the scanning more efficient (and believe me, I tried to get it to boot safe mode. I don't know much about Hijack this, and how it works. The program itself is pretty simple, but I'm no geek and trying to make sense out of the results is pretty much an impossible task for me. I can do a couple of things with my PC, and I always managed to get to the bottom of things on my own. But maybe this time, I could use some help. Sorry if I broke any rules in regards to this forum/thread. It's my first time writing a post in ANY forum anywhere on the web. I'm waiting for sugestions. Thanks in advance =D
Bugbatter
4 Apprentice
•
20.5K Posts
0
December 4th, 2009 17:00
Welcome. Thank you for using Dell Community Forums.
Logs are read on the Malware Removal Forum.
Please Read This Before Posting For Malware Removal Help
Irktou
64 Posts
0
December 4th, 2009 18:00
dsca.exe and I believe is part of that dell support center
1234h
1 Rookie
•
86 Posts
0
December 4th, 2009 18:00
And one last bit of advice I wish to offer, and this is to everyone (not just those that have posted in this thread) in the Event Viewer > System Log you can find some very, very useful information. That should be a place to visit very early in your troubelshooting procedure.
1234h
1 Rookie
•
86 Posts
0
December 4th, 2009 18:00
Okey-dokey, , you have me a bit confused on a few things and you could help anyone who wants to help you by letting us know what you found out the CLI.exe and the dsca.exe are. What are those two? I mean, somebody might have that information fresh in there mind for some reason, but most likely they will do a book lookup or a Net search to find out. You can help a lot by letting whomever know right away to save that whomever some time. That seems fair enough, doesn't it?
Now, about this downloading of drivers -- that's what's got me confused. Why would you want to donwload any drivers before you have figured out what caused your original problem? I don't get that. Of course, I'm not the sharpest tool in the shed and maybe I'm missing something. But I'm wondering.
Oh yes, those error codes -- again, what did your research show those errors codes signify?
I'll pause here and wait for your responses to the questions I've asked and then we can move on. Seem okay to do that?
1234h
1 Rookie
•
86 Posts
0
December 4th, 2009 18:00
Okey-dokey, , you must have had a duplicate post in this thread that was deleted. I was looking for your second post and it's not in the Malware section. So you might be waiting for some response here.
The redirects might very well be a sign of malware of some kind, but the fact that you have done so many scans and found nothing might want to let us pause a moment and first consider other possibilities.
The first thing I'd be interested to know is what those error messages mean, but in your case, unlike who was able to get to the Dell website, you may not be able to do any Net searches for the error code information.
Maybe will give us the answer, but if not (and I'll wait for a bit) then I'll do it for you, unless someone already has the information and posts it here. In the meantime, if you are able to wait, maybe you shouldn't be so quick to post over in the Malware section.
Does that sound like a reasonable plan to get this troubleshhoting started?
1234h
1 Rookie
•
86 Posts
0
December 4th, 2009 18:00
Okay, it's all well and good that somebody has indicated where to go to troubleshoot a malware problem and included information about what needs to be posted over there, but no other advice related to what's been posted here is ... -- I don't know -- uncomfortable feeling, in my not so smart opinion.
I think that it should have first been pointed out that poster number 2 in this thread probably is facing a different problem than poster number 1. One has to be careful about this idea that if some trouble indications look the same the cause is the same. That can lead a person to go down the wrong road to finding an answer to what the problem is. From first readings, I think poster number 2 has a different problem than poster number 1 (sorry, I'm not yet using proper IDs). I just wanted to get this posted before I go back and study the two posts in more detail before, especially, poster number 1 took that problem over to the malware forum.
Daniel3026
5 Posts
0
December 5th, 2009 16:00
I've just found out that my Antivir Guard has detected something else a few days ago.... nov 30th to be exact. Here it is :
Virus or unwanted program 'HTML/Infected.WebPage.Gen [virus]'
detected in file 'C:\Documents and Settings\Daniel\Local Settings\Application Data\Mozilla\Firefox\Profiles\cbjayvgj.default\Cache\_CACHE_002_.
I'll try and look this up to see what I can learn from this.
Daniel
Daniel3026
5 Posts
0
December 5th, 2009 16:00
Hey 1234h,
First of, Thank you for taking the time to look this up with me.
I have just came across three malware detection from my Antivir Guard. Those have been detected today whilst I was surfing the net with Firefox.
Virus or unwanted program 'HTML/Infected.WebPage.Gen [virus]'
detected in file 'C:\Documents and Settings\Daniel\Local Settings\Temp\plugtmp-27\plugin-.
Virus or unwanted program 'HTML/Infected.WebPage.Gen [virus]'
detected in file 'C:\Documents and Settings\Daniel\Local Settings\Temp\plugtmp-27\plugin-.
Virus or unwanted program 'HTML/Infected.WebPage.Gen [virus]'
detected in file 'C:\Documents and Settings\Daniel\Local Settings\Temp\plugtmp-27\plugin-.
I also have another detection about an hour earlier than the 3 mentioned above. Here it is :
Virus or unwanted program 'JS/Gord.A.1 [virus]'
detected in file 'C:\Documents and Settings\Daniel\Local Settings\Application Data\{EAB301F1-286B-4EB1-93D0-298902F9EAEE}\chrome\content\overlay.xul.
Those all happened today, and all threats have been deleted by Antivir.
I'll wait for your feedback on this.
I should also add that a few days ago, I noticed that I couldn't access my ATI Control Center. I looked into it further and the process tab, I had 2 processes hanging. CLi.exe and MOM.exe. I looked it over the internet and they are files from the ATI bundle. I uninstalled all of ATI's components for the time being, just to get this out of the way.
I'll reinstall once I've found out what is hacking my IE and Firefox
Maybe there's a way to boot on safe mode that I'm not aware of. If so, I would love to know about it. I could run the scans from there and maybe get lucky and be able to get rid of whatever is doing this.
Thanks for the help, it's much appreciated
Daniel
P.S. Should I post here or somewhere else?? I read something on the beginnig of the thread and I couldn't make sense out of it.
Someone will have to tell me if I'm doing something wrong :S
1234h
1 Rookie
•
86 Posts
0
December 5th, 2009 17:00
I must admit, you have my curiousity up. "Infected.WebPage.Gen" sounds so, general -- as in ambiguous. Can't say as I've ever seen one of those before. That one I feel an urge to check myself -- the what-in-the-world bug has bitten me.
As for Safe Mode, I think your system should be like most and that means a tapping on the F8 key right after you hit the power switch should provide you with the options page, as in what Sfae Mode you want to get into. You might want to check that out while I'm poking around looking for the other info.
In fact, I just went into my chuckle mode -- what a name for a virus "Infected.WebPage".
Oh yes, speaking of systems, did you post what your OS is. Another nice feature of this forum is we can't read all the posts in a thread while we are composing a message. Dell likes to test the limits of our patience on this forum. Must be a test of our psyche. Some kind of study.
Back in a moment.
1234h
1 Rookie
•
86 Posts
0
December 5th, 2009 17:00
Okey-dokey, I got it. Some lazy website owners or user admin types aren't keeping their web pages clean. Still, a strange name.
Looks like a thorough removal, or check to see if it was caught quickly enough, means a look in your registry. No surprise there.
Might want to look at this page >> http://www.spywareremove.com/removeHTMLInfectedWebPageGen.html
Do you feel comfortable poking around in your registry? Guess I shouldn't use the word "poking" as it sounds so unprofessional.
And you may have a problem doing a backup now. If you're infected, the infected files will end up in the backup. But you should have restore points from before November 30th.
Anyway, first things first; how do you feel about going into your registry? It's really not that hard of a thing, if you're careful. Plenty of tutorials out there to study and explain every little detail.
Oh yes, I haven't checked what those error messages were all about, yet. Was sort of wondering if the OP would be back.
1234h
1 Rookie
•
86 Posts
0
December 5th, 2009 18:00
I found this in my files, if you can't get in with the F8 key.
Using the System Configuration Utility
When you are finished with troubleshooting in Safe mode, open MSCONFIG again, on the BOOT.INI tab, uncheck "/SAFEBOOT" and click OK to restart your computer
But it might be a good idea to get a handle on those error messages, first. What do you think?
1234h
1 Rookie
•
86 Posts
0
December 5th, 2009 18:00
I think we can keep the troubleshooting in this thread for now.
I also saw you are using XP. Would that be Home or Pro? May not matter so much, but good to have everything on the table while working a problem.
I also saw you did try the F8 key trick. Sorry, i'd forgotten the details of your first post. I was all focused on that neat title for a virus. Let me find something about other methods.
Bugbatter
4 Apprentice
•
20.5K Posts
0
December 5th, 2009 20:00
1234h, the site that you sent Daniel to, gives me a huge red Warning on WOT, so I could not go there. http://www.mywot.com/en/scorecard/spywareremove.com
"Poking around in the registry" is not advised unless you make a backup and know what you are doing.
If Antivir removed the problem, then all is well.
Regarding Infected.WebPage.Gen" please refer to this:
A common attack against the web infrastructure can be the infection of harmless web pages. Some malware changes every HTML file stored on the disc and adds a link (very often an IFrame) to a site hosting malicious code. Other attacks can aim for the web servers and try to insert forwarding to the pages hosted there. The owner of these pages is advised to take them offline. Fix the hole (either on his own PC or on the server), check the pages for infections, clean them and go online again. Infected Web Pages often contain additional Iframe, Object or Script Tags. The Script Tags often contain encrypted Code.
http://www.avira.com/en/threats/section/fulldetails/id_vir/3684/html_infected.webpage.gen.html
"everything on the table" means running diagnostics that show what is running and what may be hidden on a system, rather than guessing. This is not the forum where this is done. I posted two links above describing how this type of malware removal is handled.
I appreciate your wanting to help, but in the best interest of DCF members, it is worthwhile to have one of the trained analysts handle malware removal.
Daniel3026
5 Posts
0
December 5th, 2009 21:00
Hum.... ok...
I see now that I have to be more specific. So, I'll start over, and go over things quickly.
I use Win XP, all updates are up to date. Both my browsers are still redirecting me to god knows where, at least twice in one singlle click. So this means that Antivir does remove it completely. As for the possibles ways to boot in safe mode, I know about all of witch have been sugested, but my OS crashes if I dare try to boot in safe mode. And on top of that, I can't go back to normal boot afterwards. my system crashes everytime. I tried every single option that there is to get it to boot up again, but it just fails to bboot back. Now, to get around this, I placed another HD in my PC, installed a fresh copy of Win XP, and tried a few things here and there, to finally end up copying the boot.in file from my drive C: (fresh XP) over my other boot.ini file in my drive E: (original XP). I hope this bit is clear. But then again, may be irrelevant to the real issue.
Anyhow, I proceeded to try and boot up from my HD that wouldn't up to that point, and in the option, I chose "boot normally", and it worked. So now, I have my PC up and running again.
Now, since I know the usual procedures of trying to boot in safe mode, I was asking myself if there was other ways to try and force your PC to boot in safe mode... some kind of trick I wasn't aware of.
Also, the webpages that I have been reffered to, I already visit. I tried the removal of the infected keys in the registry, but none of those existed in my registry. Looked it up twice to make sure of that.
So now, Where do I go from here???
Booting in safe mode would be the best thing for me. I could then try the scans and with a little luck, I might be able to locate and delete that son of a gun :P
Awaiting for ideas, cuz I believe I ran out of those.
One particular detail that should be taken note of : The both of my browsers, I can use. But when I google something up, and I don't have the link in whole for me to copy/paste in the adress bar, I can't access that webpage. I mean I can't go thru with the top link, cuz then I get redirected anywhere and there's no way to trick it into going to the original webpage.
I now have control (freedom of choice) of the redirections in Firefox. I tried just now to find where it is in the options of Firefox, but I couldn't locate it.
I think that sums it up pretty good.
If there is still some infos you guys need, just ask
I want to thank everyone that is helping me out with this. It's much appreciated.
Daniel