My Gateway laptop keeps shutting itself off

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nancyHEIDE, Oct 19, 2006.

  1. nancyHEIDE

    nancyHEIDE Private E-2

    My computer (everything) completely turns off on its own. This always occurs when I am running a virus scan and sometimes it occurs when I have left my desk for a while. I have the laptop plugged in and there are no power issues that would cause it to turn off. I have a home network with two other home computers and a router. We connect to high-speed internet using the router. I run Windows XP Pro 2002 SP2, Intel Pentium 4HT, 3400 MHz, 1022 MB Total Physical Memory (52% used), 5022 MB Virtual Memory (18% used). (I am getting these numbers from AIDA32.)

    I normally do virus scans (McAfee purchased version and safety.live.com online weekly on my computer, less often on the other networked computers. They are acting up too, though not as predictably.

    I also have been getting a couple of errors while trying to shut down or restart: dwwin.exe - DLL initialization failed. Application failed to initialize because the windows station is shutting down. (This happens even though I haven't tried to open anything) and Adobe AcroRd32.exe - Application Error. The instruction "0x5ad71531" referenced memory at "0x00000014". The memory could not be "read".

    These problems began around October 14 AM.

    I have attached the logs of all the files I could.

    NOTES: Spybot wouldn't load in SafeMode - done in Normal Mode & found two registry items.
    Computer turned off while running Microsoft Windows Defender in both Safe and Normal Modes. (No log available)
    Computer turned off while running CounterSpy in SafeMode - ran in Normal Mode and detected Comet Systems Adware and isearch.Desktop.Search (log attached)
    Computer turned off while running Bitdefender in both Safe and Normal Modes (No log available)
    Panda ActiveScan would not run in either mode... I got an "Error on page" message... Lines: 103 & 73, Char: 2, Error: Object doesn't support this property or method"
    When I searched the C: drive for runkeys.txt, it wasn't there. I ran the getrunkey.bat file again to make sure I did it, but the file still isn't there.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You MUST the directions as given in the links for GetRunKey and ShowNew. You are not following them for either program. The log you attached for ShowNew is incomplete. You MUST extract ALL files from the ZIP file and you MUST run the .bat files from a Windows Explorer session. If you run them from inside the ZIP file, they will not work properly.

    I will warn you right now that I doubt your problems are malware.

    You should not say that you do not have power problems unless you have physically opened up your laptop and measured all the voltages at appropriate points and then also check the voltages with an oscilloscope to make sure there are no noise spikes on the DC supplies. I'm not saying this is your problem, I just saying you cannot make that statement you made without having done this.

    You problems could even be due to overheating.

    Other comments which have nothing to do with your PC shutting down:
    • you should not have both Windows Defender and CounterSpy running. It will cause conflicts and wastes lots of system resource which will slow your PC down.
    • if your McAfee software also contains an antispyware feature your will want to uninstall both CounterSpy and Windows Defender. (Yes I know they were requested - but only one was requested - in the READ ME, but that is a generic cleaning process which makes no assumptions about what protection anyone may or may not already have).
    When was McAfee installed? And when did you uninstall Symantec (which by the way was not uninstalled properly).
     
  3. nancyHEIDE

    nancyHEIDE Private E-2

    OK, I uninstalled both CounterSpy and Windows Defender because McAfee does have antispyware software.

    Here's the logs from runkeys.txt and newfiles.txt .

    I did not test the power inside my computer, I made that comment based on our power supply. Be gentle, I'm new at this!

    As to McAfee's installation, it was in November 2005. Same with Symantec's uninstall. Is there a link to the proper way to uninstall this? If you know about it, I obviously didn't uninstall it properly.

    Thanks for any help you can give me with this.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not your fault! It is Symantec's fault! Uninstalling their software can be as difficult as removing malware. We see it ALL the time. I'll give you some steps to use to try and remove it further down.

    As I said earlier, your problems with your PC shutting down are not malware. Below are some things you need to do anyway.

    First if CounterSpy is a free trial version, uninstall it and keep Windows Defender.
    If CounterSpy is a paid version, keep it and uninstall Windows Defender.

    Now let's try to cleanup the stuff remaining from Symantec.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Now repeat the above for the following service: LiveUpdate
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above for the following service: LiveUpdate
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    After clicking Fix, exit HJT.
    Now reboot in normal mode
    Now attach a new HJT log and tell me how the above steps went.
    For your shutdown issues (which I assume still happen), you should try posting in the Hardware Forum (maybe the Software Forum). Your Event Logs (that someone should ask for) may include information on why it is shutting down.
     
    Last edited: Oct 23, 2006
  5. nancyHEIDE

    nancyHEIDE Private E-2

    Thanks so much for your help!

    I will reinstall Windows Defender as Counterspy was a trial version.

    Then I will try to fix my shutdown issue!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You HJT log is clean and the Symantec stuff is gone.

    Good luck with your Shutdown issue.
     
  7. nancyHEIDE

    nancyHEIDE Private E-2

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the update! That is one of the most common problems with random shutdowns.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds