Unsolved

This post is more than 5 years old

8 Posts

19676

June 3rd, 2005 16:00

I'm becoming desperate... please help me!

(Posted this to the hijackthis forum, but was suggested to post it here, since the problem appears not to be virus related.)
 Dear community.
 
Just received my brand new M70 precision laptop last week, but I haven't been able to use it yet because of problems that appear to be due to malicious software.

The symptoms are similar to that of the blaster worm.  When booting into Windows XP, I get an arrow message saying "the instruction at '0x000cfe50' referenced memory at '0x000cfe50'.  The memory could not be "written".  Okay to terminate program.  Cancel to debug."

Closing the window allows me to boot fully into XP, but then I get the infamous shut down in 60 seconds message:" the system is shutting down.  Please save all work in progress and log off.  This request was initiated by NT Authority\system.  Message: Windows must restart because the RPC service terminated unexpectedly."  And then it counts down from 60 seconds, after which it reboots.

I've also seen other errors like for generic host process for Win32 services, and a svchost.exe error.

I tried to format the hard disk and start all over, but the problem reappeared after one day.  I'm using panda fully up-to-date antivirus software.  I have tried removal tool for the blaster worm and a few other worms but to no avail.  Also, when does XP are fully updated with service pack two etc. To me, no suspicious processes are running.  Please find my hijackthis log below.

Cheers,Sune

Logfile of HijackThis v1.99.1
Scan saved at 5:19:57 PM, on 6/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\PaSSrv.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\Firewall\PavFires.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\PavFnSvr.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\pavprot.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\pavsrv51.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\Prevsrv.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\PsImSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\AVENGINE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\APVXDWIN.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\SRVLOAD.EXE
C:\Program Files\Panda Software\Panda Platinum Internet Security\WebProxy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Panda Software\Panda Platinum Internet Security\Upgrader.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\SUNEJE~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Platinum Internet Security\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Platinum Internet Security\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.ini"
O4 - HKLM\..\RunServices: [PANDA ANTISPAM SERVER SERVICE] "C:\Program Files\Panda Software\Panda Platinum Internet Security\PasSrv.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dragon NaturallySpeaking.lnk = C:\Program Files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: PAVWAIT.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Antispam Server Service (PASSRV) - Unknown owner - C:\Program Files\Panda Software\Panda Platinum Internet Security\PaSSrv.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Platinum Internet Security\Firewall\PavFires.exe
O23 - Service: Panda PAVFNSVR (PAVFNSVR) - Panda Software - C:\Program Files\Panda Software\Panda Platinum Internet Security\PavFnSvr.exe
O23 - Service: Panda PAVPROT (PAVPROT) - Panda Software - C:\Program Files\Panda Software\Panda Platinum Internet Security\pavprot.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Platinum Internet Security\pavsrv51.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Platinum Internet Security\Prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Platinum Internet Security\PsImSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Message Edited by sunejdk on 06-04-2005 05:43 AM

2 Intern

 • 

7.9K Posts

June 3rd, 2005 17:00

just as an afterthought, you might try running dell diagnostics on the ram and the harddrive

2 Intern

 • 

7.9K Posts

June 3rd, 2005 18:00

Message Edited by NemesisDB on 06-03-2005 03:03 PM

8 Posts

June 3rd, 2005 18:00

All right, I'll do that and be back later.
Thanks

8 Posts

June 3rd, 2005 18:00

(I meant of course "not virus related").

The title of the window with the "the memory could not be 'written'" is svchost.exe error. The system is also behaving strangely in many other ways. I get many error messages regarding many seemingly unrelated things. Lately, when running the blaster removal tool from Symantec, I got the Windows blue screen (kernel_data_inpage_error). I did it again after rebooting, and everything was fine, and no worm was found. Cheers,Sune.

2 Intern

 • 

7.9K Posts

June 3rd, 2005 18:00

yeah ...  run the full ram tests (all of them, several times) and run the full hard drive tests (along with a surface test if you can afford the wait)

8 Posts

June 3rd, 2005 18:00

Thanks for the advice.  I did that already, I ran the Dell diagnostic express tool, but perhaps it's worth running the full version?

 

Sune

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

June 4th, 2005 00:00

If you're still within first 21 days from the order date, just call Dell and say you want it replaced under the 'satisfaction guaranteed' warranty. You have to make the request within 21 days or they won't do it. Be polite but be insistent. It shouldn't cost you anything extra. Dell pays shipping for the replacement system and for return of this one.

Ron

1.4K Posts

June 4th, 2005 03:00

There's a possibility that you've been hit with a rootkit. It is undetectable by any AV program. It apparently uses svchost.exe to run it's thing. You can read more at these links:
 
 
 
Unfortunately the rootkitrevealer mentioned above and below has been pulled (no reason given).
 

8 Posts

June 4th, 2005 13:00

I ran all the diagnostics checks from Dell, and all tests passed.  Furthermore, I downloaded the rootkitrevealer utility, but it didn't find anything suspicious.  Finally, I checked the MD5 checksum of svchost.exe, and it was legitimate.
So objectively it seems like everything is fine with my computer, although it isn't.
The only thing remarkable is that for the first time ever, when I rebooted Windows after running the whole range of tests, I haven't seen any error messages... no reboot warning, no svchost error, and win seems to be behaving altogether normally.  For the first time ever, and even my windows button is working!
 
However, I'm sure this is a one-time miracle, so unless you hear otherwise, you may assume that I'm still battling with the problem and will be grateful for any advice.  If this 21 days buyers satisfaction also works in Denmark, then I will consider to ask for a new computer.  The not so reassuring fact is, however, that two of the people at work had very similar problems with their similar laptops. However, they solved their problems by reinstalling and restoring respectively. Which did not work for me. Sune

8 Posts

June 5th, 2005 06:00

yep, still a problem!
No Events found!

Top