Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Wow not sure where to start, computer keeps shutting down and restarting  (Read 6135 times)

0 Members and 1 Guest are viewing this topic.

MelindaW

    Topic Starter


    Greenhorn

    Okay so back in January my daughter was using computer on Myspace and after clicking on a bands page and viewing pics the computer started making a ding dong ding dong noise and then the page ( IE) closed and my screen went blue and then the pop up started with the fake ( I have seen and cleaned it up before) virus infections asking me to download the anti virus software to remove such detections. I did not do it but as I have learned previously it does not matter if I download it or not. I immediately used Windows Defender and it would let me scan for a while and then when the threats popped up in the scan my computer would shut down ( normal mode). So I restarted in safe mode and the end result was the same ( shut down and restart on its own). So I went to Microsoft for some help. I removed WD and used the Microsoft Security essentials and the same thing happened when I tried several times to scan the pc in both normal and safe mode. I got frustrated after days of not being able to fix it on my own that I decided to a system recovery not restore. I had backed up all my files before doing so only to find out that I did not have a backup disk for windows because it came preloaded on my pc. So when I was in DOS ( black screen with all the files only a techie would understand) I saw some "partition" errors. Found a website for that and think I fixed that part.

    Yet the computer still kept shutting down and restarting. I moved so all my stuff was in storage and I just now got all of pc stuff back out and decided to try and fix it. I have landed here. So I removed all of my antispyware/malware and virus software off my computer I thought and read your "read first thread about removing viruses" I downloaded the Avast and started the scan. The scan quit ( at least not shut down yet) and gave me and error
    "some files could not be scanned" and when it quit I got a talking message from Microsoft security essentials ( I thought I had removed) saying that the scan has finshed and this was the result of that.

    Trojan:Win32/Fakeinit
    Trojan:Win32/Malat
    Program:Win32/PowerRegScheduler
    It says all 3 have been removed but also says my computer might be at risk because I have not scanned my computer in a while.  ???

    So I am not sure what to do next?

    Compaq Presario
    Intel Celeron CPU 2.53GHz 376 MB of RAM
    Microsoft Windows XP Home Edition SP3

    « Last Edit: April 26, 2010, 11:46:46 PM by MelindaW »

    MelindaW

      Topic Starter


      Greenhorn

      Not trying to bump my topic I am following the steps in this topic http://www.computerhope.com/forum/index.php/topic,46313.0.html and repoting my logs for more information about my issue. I had no option to modify the post. So I had to reply

      SAS Log file
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/27/2010 at 07:46 PM

      Application Version : 4.35.1002

      Core Rules Database Version : 4858
      Trace Rules Database Version: 2670

      Scan type       : Complete Scan
      Total Scan Time : 01:47:47

      Memory items scanned      : 401
      Memory threats detected   : 0
      Registry items scanned    : 4277
      Registry threats detected : 0
      File items scanned        : 94151
      File threats detected     : 9

      Adware.IEPlugin
         C:\WINDOWS\lu.dat

      Adware.Tracking Cookie
         C:\Documents and Settings\Guest\Cookies\[email protected][1].txt
         C:\Documents and Settings\Guest\Cookies\guest@atdmt[1].txt
         C:\Documents and Settings\Guest\Cookies\guest@doubleclick[2].txt
         C:\Documents and Settings\Guest\Cookies\guest@fastclick[1].txt
         C:\Documents and Settings\Guest\Cookies\guest@interclick[2].txt
         C:\Documents and Settings\Guest\Cookies\[email protected][1].txt
         C:\Documents and Settings\Guest\Cookies\guest@overture[1].txt

      Rogue.Agent/Gen-Nullo[DLL]
         C:\WINDOWS\ARONZ.DLL


      Malware Log
      Malwarebytes' Anti-Malware 1.45
      www.malwarebytes.org

      Database version: 4043

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18702

      4/27/2010 9:43:26 PM
      mbam-log-2010-04-27 (21-43-26).txt

      Scan type: Quick scan
      Objects scanned: 139583
      Time elapsed: 13 minute(s), 30 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 1
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\Program Files\Common\_helper.sig (Malware.Trace) -> Quarantined and deleted successfully.

      « Last Edit: April 27, 2010, 07:41:02 PM by MelindaW »

      MelindaW

        Topic Starter


        Greenhorn

        HJT Log File

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 10:27:25 PM, on 4/27/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\windows\system\hpsysdrv.exe
        C:\WINDOWS\System32\hkcmd.exe
        C:\WINDOWS\System32\igfxtray.exe
        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\LSI SoftModem\agrsmsvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://zoomtown.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264286990578
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264293486015
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

        --
        End of file - 5547 bytes

        truenorth



          Guru

          Thanked: 253
          Melinda W, You have done an excellent job of detailing the preliminaries that led to your problem and also seem to have followed the actions of presenting the required logs. This particular forum is serviced by a very limited number of qualified experts and only they give advice here. So hopefully your patience will be soon rewarded and one will be along to assist you. truenorth

          MelindaW

            Topic Starter


            Greenhorn

            Thank you for your response. I am actually starting to think this is NOT a virus thing going on with my PC, I think I am missing some files for windows or something. When I did the recovery not restore I had to install some files from microsoft's website and I am thinking maybe I am still missing some files. I will sit back and wait.

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
              Hello  and welcome to
            Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

            1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
            2. The fixes are specific to your problem and should only be used for this issue on this machine.
            3. If you don't know or understand something, please don't hesitate to ask.
            4. Please DO NOT run any other tools or scans while I am helping you.
            5. It is important that you reply to this thread. Do not start a new topic.
            6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
            7. Absence of symptoms does not mean that everything is clear.

            If you suspect that something is incorrect with the files on your computer you can try this, if you have the OS disk.

            If so, place it in your CD ROM drive and follow the instructions below:
            •Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
            *Let this run undisturbed until the window with the blue  progress bar goes away
            SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.
            =====================================
            Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

            Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

            Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

            Exit out of MessengerDisable then delete the two files that were put on the desktop.

            =====================================
            Open HijackThis and select Do a system scan only

            Place a check mark next to the following entries: (if there)

            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


            Important: Close all open windows except for HijackThis and then click Fix checked.

            Once completed, exit HijackThis.
            ========================================
            Please download ComboFix from BleepingComputer.com

            Alternate link: GeeksToGo.com

            Rename ComboFix.exe to commy.exe before you save it to your Desktop
            Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
            Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
            As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
            Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

            Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


            Click on Yes, to continue scanning for malware.
            When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

            If you have problems with ComboFix usage, see How to use ComboFix

            Windows 8 and Windows 10 dual boot with two SSD's