Hi guys, am running xp pro and having problems with pc going into sleep mode when i open microsoft office outlook, sometimes it will open but as soon as i try and open a folder it shuts down and the only thing i see is a small window saying attention pc going into sleep mode and then it reboots itself.
Any ideas on where i should look or what to try would be great.

thanks ... ...

Is it a pc or a laptop. If it is a pc then turn off sleep mode in Control Panel - Power Options.

It may be caused by some type of infection. What protective software do you have and what does it say when you do a full scan?

hi and thanks for the reply. it is a desk top - scan came back with 0 problems, turned off sleep mode and tried to open outlook and it still shut down. Am running symantic

Right, Symantec / Norton software is absolutely rubbish at protecting a pc.
Download, update, and do a full scan with Mbam - http://www.malwarebytes.org/mbam.php then post it's results in this thread and we will see how infected your pc is.

Your pc will probably need further work, running Mbam is just the first stage.

hi Rik, how right you are... still doing scan but straight away found 9infections, will post final outcome when done.
Hopefully this will lead to fixing the problem.
Thanks for your help.

No problem. But please pleas please wait until you are given the all clear by myself or someone else before thinking your pc is %100 clean. Many people see an improvement after just an Mbam scan and think their system is clean when in fact further work is needed.

Hi, finished scan and had 64 infections which were removed. they were all adwear from something called Zango and the other was My web search. rebooted and opened email and it still came up with the window which has red across the top and ATTENTIION entering sleep mode then reboots itself. I had already backed up entire pc onto an external hard drive so i can format if i need to. PC belongs to a friend and it has 3 partitions one of them contains a program called Acronis which seems to be a system recovery but when i accessed it through F11 none of the functions worked and said no hard disk drivers found. It also has an error coming up saying windows installer not installed correctly.
am thinking formatting is the best road, what do you recommend.

I need to see the log that Mbam produced.

Malwarebytes' Anti-Malware 1.38
Database version: 2297
Windows 5.1.2600 Service Pack 3

10/07/2009 8:08:11 AM
mbam-log-2009-07-10 (08-08-11).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 180679
Time elapsed: 1 hour(s), 5 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 31
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 23
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\coresrv.lfgax (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.lfgax.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\Zango@Zango.com (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.3.79.0 (Adware.Zango) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\All Users\Application Data\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
c:\documents and settings\User\Application Data\Zango (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\IESkins (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0 (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOI (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOI\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\static\1 (Adware.Zango) -> Quarantined and deleted successfully.

Files Infected:
c:\program files\internet explorer\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\my documents\Blakes\LimewireSetup.exe (Adware.Zango) -> Quarantined and deleted successfully.
d:\my documents\Blakes\LimewireSetup2.exe (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSAEULA.mht (Adware.Zango) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

hey matilda21
i don’t know much about Mbam but we use Norton at work after all other antivirus has failed to produce. I am now a Norton fan, however if you treat it well it works fine.
If you are up to reformatting your pc and have the ALL the cd’s that you might need that is definitely the way to go. No machine that hosted a hacker is EVER 100% save again. You go on and format and re-install ( one should do that in any way every 1 – 2 years for maximum reliability)
After the re-install you can use a fire-wall program like online armor, (remember to disconnect windows firewall) a program called spyware Blaster and also a program called spyware terminator and if you use it in combination with spybot search and destroy and a antivirus like Norton you should be fine fine fine!
I never have any problems and use above programs (they are all free except for Norton)
Hope it helps
barry

I have seen the logs from hundreds of infected pc's and I can tell you that Norton is complete rubbish.
The worst infected were those with no protection. A very close second goes to those with Norton on it.

I wouldn't recommend Norton to my worst enemy.

matilda21, it does indeed look like Mbam has been very successful but as a precaution, I would like you to download HJT from here - http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html and post a log from it for me to check over.

Thanks Rick and Barry for your help, am not sure what happened but pc suddenly crashed and i couldn't even get into safe mode. I formatted and did clean install of windows and its working great. I am however not sure what is the best protection to use as some think norton or symantec are great and others think they are no good.I read reviews and alot think Bit defender is ok, there are so many out there do any of them really do all they claim to do.

Norton is absolute rubbish, don't waste your money on it.
There is plenty of free software out there that will do a far far better job of protecting your pc with absolutely zero cost.

Phishing filter - http://www.mywot.com/ It's free and very good.
Antivirus - http://www.avast.com/eng/download-avast-home.html Avast is very good and is free.
Aintispyware - http://www.malwarebytes.org/mbam.php Probably the best antimalware software there is at the moment and free.
Firewall - http://www.techsupportalert.com/best-free-firewall.htm There is plenty of information about free firewalls here.


The only reason that people say Norton is good is because they will believe all the hype of the adverts rather than evidence of it's uselessness.

Thanks for that information Rick will go ahead and download those programs.
thanks again for all you help.

No problem at all. At least someone on here appreciates my advice.

Dear Matilda and Rik
Rik it is not that I did not appreciate you advice, I am one of those people who look at any and all advice and make up my own mind, for years I didn’t like Norton ONLY because it made my machine slow , lately I find that it is not the case! I have never seen any Norton add in my life , I did not even know that they make adds. At work I have used AVG on all our workstations and bit defender on our servers, we got an 2 old viruses one called voiterai and the other one I cant remember its name , because AVG could not pick up the virus it infected about 50 of our pc’s unfortunately bit defender from day one gave us trouble with the installation and registration on our servers (it could be me that might have been to stupid to install it) eventually our main server got infected and bit defender (it is licensed, paid for) did not help me, i then proceeded to buy Norton as well because one of my colleagues at work had a old copy of Norton on his machine and it could detect and clean the 2 viruses(witch by this time infected 10000's of files) a 3 x license for Norton was about R450 ($60) so we bought 10 boxes ( 30 licenses) for a start , just to see.
Norton removed all the viruses, and could also scan other computers for viruses and removed them as well (it just took a little more man hours)
I do however feel that one should give each person a chance to discover for themselves what works and what they like, if not everyone would have been driving a Ford, and that is luckily not the case. I am quoting again from my previous mail as to what I have found to be of great help software wise on my home pc, to help prevent viruses (I have never had one in 25 years) maybe I am just lucky

After the re-install you can use a fire-wall program like online armor, (remember to disconnect windows firewall) a program called spyware Blaster and also a program called spyware terminator and if you use it in combination with spybot search and destroy and a antivirus like Norton you should be fine fine fine!

Hope it helps
Humbly replied
barry

Hi Barry and Rik, am not sure I should be having any more input here but I do feel the need to say that all advise given on this site is appreciated. Most people who are looking for help are probably like me and have very limited knowledge to the workings of computers and turn to Daniweb in the hope their problems can be fixed, the more unput from different people the better as it helps learners like me understand just that little bit more with each post.

Thanks guys ... PC is working beautifully now and well protected.
Matilda21... ...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.