Computer restarting in normal mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by cordovainc, Oct 16, 2006.

  1. cordovainc

    cordovainc Private E-2

    Hi guys, followed the "Read and Run Me" thread as best as I could (my problems will follow).

    What is happening is that when I am in normal mode my computer will sometimes get a system shutdown message (NT AUTHORITY/SYSTEM services.exe status code: 203) and sometimes just restart with no message in the middle of testing it.

    I also get a windows help window with an open file dialog box when I startup sometime.

    Everything scans clean, Panda scans with no viruses but 44 spyware but because of the resolution of my computer (it restarted while upgrading nvidia video driver) I was unable to see the buttons to save logs as it was a fixed window. I will be glad to repost is you can tell me a way around this. Also bitdefender wouldnt run, no error code just "Unable to run online scan". And last Windows Defender was run without updates cause it wouldnt update them. I got ox800706ba "the RPC Server is unavailable".

    I know there is little to work with but hopefully what I provide will spark something I can try to at least get the machine to the point where I can provide you great people with all the info you need.

    Thanks again, please let me know what I can do to help you help me further!
    Larry


    =cpu pentium 4, 512 MB DDR PC5400, Windows xp=
     

    Attached Files:

  2. cordovainc

    cordovainc Private E-2

    I am sorry to bump this, I cannot find the edit button :(

    Anyway I forgot to mention I think it is a malware problem cause I did find over 1200 instances in Adaware and Spybot (prior to coming here and doing the recommended steps) but they not run error free.

    Is this a characteristic of the Blaster Worm? I cannot find any info on the exact error message but I seem to remember in 2003 fixing machines with shutdown messages using the blaster worm removal tool.
     
  3. cordovainc

    cordovainc Private E-2

    Problem fixed. Wasn't Blaster I just had to copy default registry values.

    Incase somone searches and finds this:

    Boot using windows cd and enter System Recovery Console
    1. Rename c:\%windows%\system32\config\security to security.old
    2. Rename c:\%windows%\system32\config\system to system.old
    3. Copy c:\%windows%\repair\security to c:\%windows%\system32\config
    4. Copy c:\%windows%\repair\system to c:\%windows%\system32\config

    Reboot then all should be well.

    To clarify initial problem. Computer would display system shutdown messages then if no message it would reboot on Windows/Microsoft updates.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have malware and other problems on this PC.

    The below files should all be deleted:
    C:\WINDOWS\srvagbjanm.exe
    C:\WINDOWS\srvmmjegne.exe
    C:\WINDOWS\srvszgwrop.exe
    C:\WINDOWS\srvxwhepmt.exe
    C:\WINDOWS\system32\ieserv.exe
    C:\WINDOWS\system32\3332.dll
    C:\WINDOWS\system32\silc_dll.dll
    C:\WINDOWS\system32\inistone.ini

    You need to update your Sun Java version since your are 6 versions out of date.

    You also need to uninstall the below as requested in step 0 of the READ ME.
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    You are also begging for malware problems! You have no antivirus, no antispyware (at least not that is running properly), and no true firewall installed. You need to read and follow the below:

    How to Protect yourself from malware!
     
  5. cordovainc

    cordovainc Private E-2

    Hey, thanks for trying to help even though I said I "took care" of the problem. It's reall nice to see and is the reason why I read these forums a lot.

    The files have been deleted, where did you see those files listed and do they fall under a catagory or type of spyware/virus?

    And I apologize for the Viewpoint thing. Makes me look like an idiot when I dont do something on step 0 :( I went over the steps several times cause I know its annoying when someone doesnt do the steps then posts, then I put myself in the catagory by not doing it as well. In my defense I scanned add/remove programs but since Viewpoint is a normal listing (almost every computer) it didnt stand out to me. Next time I will read the listing on this site first then look through add/remove programs instead of looking at my list, then looking at the listing provided in step 0 and looking for entries I do not know.

    Thanks again, and I am sorry again!

    Larry
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes all of the above! And the were shown in your logs of course!

    And you have others too. One is a registry key and a possible folder with PurityScan:

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "PSHope"="\"C:\\Program Files\\PSHope\\PSHope.exe\""


    And another is a second folder related to PurityScan:

    C:\Program Files\PSCloner
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds