Desktop Endless Rebooting

Discussion in 'Malware Help (A Specialist Will Reply)' started by ailicis01, Dec 31, 2005.

  1. ailicis01

    ailicis01 Private E-2

    Satisfied with your incredible help on my laptop, I'm looking for assistance with my daughter's desktop. It is an HP/Compaq operating Windows XP. The computer continuously reboots, only when it detects an internet connection.

    I have ran all programs as instructed in READ ME FIRST except for Bitdefender and Panda. To download all the malware cleaning programs it took almost two days of constant downloading before the computer would shutdown and reboot. One by one, but I did it! The messages that come up are as follows. As soon as the computer starts & the desktop appears the following error is shown: " Error Signature: SzAppName:lsass.exe szAppVer:5.1.2600.1106 szModName:unkown SzModVer:0.0.0.0. offset:00000000"

    Then if I plug in the LAN cable (normal or safe mode) to download additional programs for cleaning or access the web (even if an explorer window is NOT opened), the following window opens with a 60 second timer countdown:
    "SYSTEM SHUTDOWN X"
    The system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY SYSTEM. Time before shutdown:00:00:60
    Message:

    THe system process 'C:\windows\system32\lsass.exe' terminated unexpectedly with status code - 1073741819. The system will now shut down and restart.


    I have a HJT log availabel, let me know if I should post it. Sorry for the long message.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Go ahead and post the HijackThis log.
     
  3. ailicis01

    ailicis01 Private E-2

    Here's the HJT log:
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    Download and Run
    - CWShredder ......No installation required! Just unzip it to a folder.

    REBOOT

    Post a fresh HijackThis log.
     
  5. ailicis01

    ailicis01 Private E-2

    Followed the instructions. CWShredder found nothing, here is the new log:
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, those lines didn't come back.

    REBOOT to Safe Mode.

    Open Windows Explorer, navigate to and delete the following:
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    REBOOT
    to Normal Mode.
    Follow the directions for Running Ewido Security Suite.

    Run CCleaner before doing the below.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.

    Post both the Ewido log and the WinPFind log.
     
  7. ailicis01

    ailicis01 Private E-2

    same problem
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    REBOOT to Safe Mode; open Windows Explorer and delete the following files:
    Next scan with HijackThis and fix teh following:
    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  9. ailicis01

    ailicis01 Private E-2

    same problems still
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  11. ailicis01

    ailicis01 Private E-2

    I cannot connect to the internet with enough time to download the update because the virus is continually rebooting. Is there a way to save the update to cd or flash drive from another computer and then transfer? If so please advise.
     
  12. ailicis01

    ailicis01 Private E-2

    I used a flash drive on another computer and downloaded service pack 2 onto the problem pc. I no longer have the continual reboot. However the LSA Shell error message did come up once on a reboot. Here are my logs, I'm sure they need some cleaning......
     

    Attached Files:

  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    REBOOT to Safe Mode.

    Open Windows Explorer; navigate to and delete the following:
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    REBOOT
    to Normal Mode.

    Try running Panda ActiveScan and post the log along with a fresh HijackThis log.
     
  14. ailicis01

    ailicis01 Private E-2

    I cannot run PANDA even after numerous reboots and uninstalls??? Here is an updated HJT. COuld you also advise on the explorer settings in the log. Some don't look familiar. Thanks
     

    Attached Files:

  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download, install and run BlackLight by F-Secure.

    Post the log once finished.

    Your HijackThis log doesn't so the infecton amymore.
     
  16. ailicis01

    ailicis01 Private E-2

    Ran Blacklight and it found nothing. I wasn't sure if you wanted a log from Blacklight or HJT. Blacklight didn't offer a log so I posted another HJT log. Could you please let me know what the " http://qus10.hpwis.com" lines are in the HJT log and if I should get rid of it?
     

    Attached Files:

  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    Other than that your logs are clean.

    You are most likely experiencing problems with the OS itself, and you would get better assistance with thatover in the software forum.
     
  18. ailicis01

    ailicis01 Private E-2

    rescanned and fixed above. Here's a new HJT. Should I create a restore point now?
     

    Attached Files:

  19. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Yes, disable system restore then enable system restore. You don't have to reboot.
     
  20. ailicis01

    ailicis01 Private E-2

    Thanks for all the help, MajorGeeks Rules!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds