Cannot Shutdown..

Discussion in 'Software' started by Radiofool, Jun 12, 2004.

  1. Radiofool

    Radiofool Private First Class

    Recently infected by the WIN32:Rbot-G Trojan, but Avast got rid of it.. The only problem i have now is that when XP tries to shutdown, nothing happens. Whether i shutdown from Start button, or from task manager, nothing happens. It just sits and looks at me. No idea if its connected to the Trojan, but any ideas?
     
  2. alanc

    alanc MajorGeek

    Any error message when you try to shutdown?

    Does system lock up when you try to shutdown?

    Will XP shutdown if you run shutdown -f ?
     
  3. Radiofool

    Radiofool Private First Class

    shutdown.exe -f doesn't work. There are no error messages, it doesn't hang.. When i hold the power button down, it does shut down, thats the only way i seem to be able to do it. After i switch it back on again, there are no error messages.
     
  4. alanc

    alanc MajorGeek

    Can you shutdown from Safe Mode?
     
  5. Radiofool

    Radiofool Private First Class

    Yes. Strangely, i can also shutdown from the welcome screen. As soon as i log in (as system admin) it won't work. This has nothing to do with a Win32:Rbot-G trojan i recently had but was removed by Avast does it?
     
  6. alanc

    alanc MajorGeek

    It might, there could be a leftover process running.

    Since the problem doesn't happen in Safe Mode I think the thing to do is use msconfig to perform clean-boot troubleshooting and narrow it down to a process or service, as described here:

    "How to perform a clean boot in Windows XP"
    http://support.microsoft.com/default.aspx?kbid=310353
     
  7. Radiofool

    Radiofool Private First Class

    Okay. I've done this. The problem is with 'Load Startup Items'

    In the Startup section of msconfig, there are very dodgy looking .exe files with scrambled-looking filenames like wupfyny.exe and wuawx.exe. This is sasser/blaster isn't it? I didn;t notice these before. Why didn't Avast pick these up? I'll re run it. Thanks for your help so far!
     
  8. Radiofool

    Radiofool Private First Class

    Okay. I ran housecall by trendmicro, and it found Worm Rbot.WU, Troj PopSpy.A and Worm Francette.L

    How did i get those? I'm gonna restart and see if they're there again.

    Thanks!
     
  9. Radiofool

    Radiofool Private First Class

    Okay. Those .exe files wupfyny.exe and wuawx.exe are still running in Startup. I searched for the files, and deleted them, but everytime i restart, they're back in Startup, but i can't find them when i search. I disabled them from Startup, but how do i get rid of them? Help!
     
  10. Radiofool

    Radiofool Private First Class

    Right. Everything seems to be okay. Those two files are gone, they still appear in the startup on msconfig, but they're disabled, and i guess harmless.

    Everything seems to be running okay, so i'll guess i'll leave it. Thanks everyone!
     
  11. da chicken

    da chicken MajorGeek

    If you still want to delete them, you can try Autoruns. That's a fairly extensive viewer for what's run on startup, and it gives you the opportunity to delete as well as disable.
     
  12. Radiofool

    Radiofool Private First Class

    hmm. they don't show up. maybe they are gone after all. Thanks.
     
  13. alanc

    alanc MajorGeek

    It's probably a good idea to run Adaware and Spybot, there might be spyware nasties on your machine.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds