PC Rebooting Randomly Please Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Blaine, Dec 12, 2004.

  1. Blaine

    Blaine Private E-2

    Hi, I run windows XP and my computer has been restarting randomly. I've run spybot, adaware, XCleaner, AVG, and looked at my running processes (got confused by them) and searched them on google and used almost every virus specific removal tool I can find. None of them are comming up with anything to remove at this point. I finally re-installed zonelabs firewall on my pc. This seems to have blocked the reboot problem for the time being. However I am getting many high risk rated blocks from zonelabs firewall.

    I'll be happy to post any logs that you would like me to post or additional details, I am trying to keep this first post brief due to not knowing what logs or details that I should post for this problem. I'll be grateful for any help that you pro's can give me.

    Thanks Very Much,

    Blaine
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A word of wisdom...never run without a firewall!

    You should attempt to follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If still having a problem after the above, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  3. Blaine

    Blaine Private E-2

    Having problems with the do an online scan at Symantec Security Check step. When I do the check for problems link my web browser closes. I"ll continue with the other steps but have tried this one 4 times or so. Going to have to skip it and go on to the other ones.

    Also I'm getting Virus Detected C:\Docume~1\blaine\LOCALS~1\Tem\V5403Db02952
    Trojan horse Downloader.Dyfica.AC

    With my AVG Resident Shield and it's telling me that no action is available when I try to remove to vault or delete the file while I'm doing the Trends Micro Check. Not sure what to do about this or if AVG is just detecting the scan being done.


    Thanks,

    Blaine
     
  4. Blaine

    Blaine Private E-2

    Ok, I've done all the steps besides the last two optional steps listed. I've done each step twice now except for Having problems with the do an online scan at Symantec Security Check step. When I do the check for problems link my web browser closes. I"ll continue with the other steps but have tried this one 4 times or so. Going to have to skip it and go on to the other ones.

    Also I'm getting Virus Detected C:\Docume~1\blaine\LOCALS~1\Tem\V5403Db02952

    Trojan horse Downloader.Dyfica.AC

    With my AVG Resident Shield and it's telling me that no action is available when I try to remove to vault or delete the file while I'm doing the Trends Micro Check. Not sure what to do about this or if AVG is just detecting the scan being done.

    My zonelabs firewall is also still preventing an intrusion from what looks to me like an IP Address. I've had 53 high risk rated access attempts. However my pc so far (about 25mins) is no longer randomly rebooting.

    Any further advise or help would be great, I'm not sure if this is spyware, adware or a virus or a hacker or what. I'm also unsure what to do about it. I can post a HiJack This logfile if you would like but wont do so until instructed to.

    Thanks Very Much!!!!

    Blaine *Screaming into the monitor for help from smarter people*
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in message # 2, if still having problems post your HJT log.
    At least the random reboots have stopped.
     
  6. Blaine

    Blaine Private E-2

    Sorry, wasn't sure if you wanted me to post Highjack this yet. Don't mean to frustrate you. Posting it now as an attachment. I've used both sites on the tutorial and removed all the items Analyzie This, and the other one said to remove.

    I've had one random reboot since I last posted. ZoneAlarm keeps giving me things like real player and Generic Host Process for Win32 Services, and a spooler app, trying to act as servers. I'm denying them currently except for the ones that pop up when I start my pc because my internet explorer wont fuction if I don't allow them. Any suggestions?

    Also here is a msg from zonelabs that I continue to get "The firewall has blocked internet access to your computer [NetBIOS SESSION] from 192.168.1.101 [TCP Port 4831] [TCP Flags:S]." Quotation marks added by me. How dangerous is this and what can I do about it? or is it part of my overall problem here do you think?

    Anyhow here is the Highjack This Log file. Thank you so so much for taking the time to help me with these issues, I really do appreciate it.


    Sincere Thanks

    Blaine
     

    Attached Files:

    Last edited: Dec 13, 2004
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember what I said about no browsers running when using HJT. You had this:
    C:\Program Files\Internet Explorer\iexplore.exe

    Also, C:\WINDOWS\notepad.exe should not be running.

    You have two virus applications running, AV Personal & AVG7. You must not do this. Only run one. Pick one and uninstall the other.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see anything bad in your log.

    If you do not want RealPlayer to have access to the internet then deny it and tell ZoneAlarm to always use that setting. Better yet, uninstall RealPlayer. I see no use for it and it is a big waste of system resources.

    For svchost.exe (what you called Generic Host Process) you can just allow Access as Trusted and Internet. It does not need to be a server. This is a Windows Process. Again tell ZoneAlarm to alway use those settings. The same goes for spoolsv.exe (Spooler Subsystem App).

    Basically when you first setup any firewall and when you first run any process/app, you need to tell the firewall what to do with the app.

    The IP address you gave (192.168.1.101 ) is more than likely your own address or another item on your network.
     
  9. LUCKY48

    LUCKY48 Private E-2

    I Figured That I'd Try Posting Here Because We Have Two Computers That Are Rebooting. One Boots Into Windows But Restarts Randomly Throughout The Day. The Other Constantly Reboots At Startup And Gets Quite Annoying. Both Computers Can Be Booted Into Safe Mode But Virus Scans And Spyware Scans Turn Up Absolutely Nothing.

    They Started Doing This Yesterday And When I Left Today, I Am Still Stumped.

    Help!!!!
     
  10. Blaine

    Blaine Private E-2

    Try all the steps that they've had me do Lucky ie. the basic ones in the sticky threads, "before you post read this". I finished up now and the reboot problem seems just about fixed. It seems to have fixed the problem for the most part. I'm sure Chaslang or someone will have your pcs working again fairly soon



    Blaine
     
  11. LUCKY48

    LUCKY48 Private E-2

    Blaine:
    Out of curiousity, is your computer a Gateway? So far, this problem has only caused gateway computers, except for 1, to shutdown randomly.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Lucky48,

    As Blaine said, run all the steps of the READ ME FIRST. If your problem persist, you should really begin your own thread for them.
     
  13. LUCKY48

    LUCKY48 Private E-2

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds