Restarting Automatically

Discussion in 'Malware Help (A Specialist Will Reply)' started by kevon18, Dec 16, 2006.

  1. kevon18

    kevon18 Private E-2

    i have a problem!!! when i am openning the hijackthis folder, my pc restarts automatically! and even when i ran msconfig and regedit! i dont know why!! and sometimes when i download something like windows media player 11, my pc automatically restarts! i dont know whats going on! i need your help! tnx and more power!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Problems like you are describing could be due to malware or they could be due to hardware problems.
    1. Does your PC remain running if you just power up and logon and don't do anything?
    2. What if you don't run HJT, msconfig, regedit, or WMP? Do all other programs work without causing your PC to restart? Like can you run IE and surf for awhile without problems?
    3. Can you access the HJT folder and run msconfig, regedit and WMP without problems in safe mode?
    4. Why are you running regedit?
    If this is really malware, you will need to help us by running as much of the below as is possible. The more you run, the more likely we will be able to help you and the faster we will be able to do it.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. kevon18

    kevon18 Private E-2

    before i will continue the tutorial, i will answer first the 4 items

    1. yes
    2. yes
    3. no, it automatically restarts even in safe mode
    4. i want to explore this one

    in WMP, its pretty normal, im using WMP10 and i want to upgrade it to WMP11 but when i download it, my pc restarts.
    and also when i download the Audacity, it restarts also...
    "not all files that im downloading causes restarting of my pc"
    (i think that the culprit selects his victims)

    oh by the way! im on step 4 where i downloaded the getRunKey! ive extracted it , openned with WindowsExplorer but when i ran the getrunkey.bat, my pc also restarts... :rolleyes:
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running GetRunKey and ShowNew in safe mode if necessary.

    I also want you to try running the below.

    Please download GMER
    1. Save the GMER.zip file to your desktop
    2. Now uzip it to your desktop to reveal a GMER.exe file
    3. Double click the GMER.exe file
    4. Click the Rootkit tab and then click the Scan button.
    5. IMPORTANT: Do NOT use the computer while the scan is in progress.
    6. Please, do not select the "Show all" checkbox during the scan.
    7. When it finishes, click the Copy button. This will copy the results to your clipboard.
    8. Paste the clipboard into a notepad file and save it to a log (like gmer.log).
    9. Attach your log to your next reply.
    If you don't know how to open notepad, click Start, Run, and enter notepad and click OK. To paste the info you copied into notepad, just hit CTRL-V. Then save the log.
     
  5. kevon18

    kevon18 Private E-2

    Even in safe mode, my pc restarts when i run the getrunkey!! is this really a malware? heres the log file of gmer
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you may have a Gromozon Rootkit infection. You appear to have a least one sign of it in your log, so let's go under the assumption that you have it and run a fix for it. This can be quite nasty and difficult to remove. Let's give the below tool a run and hope that it can fix the problems.

    Gromozon Rootkit Removal Tool


    Attach the log from this! If it does say anything about find and removing the infection, see if you can now run other programs.
     
  7. kevon18

    kevon18 Private E-2

    my pc also restarts when i start downloading it...:rolleyes:
    whats the problem? aww...:confused:
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then download it on another PC and copy to this PC somehow. Or try downloading in safe mode.
    The rootkit is the problem. You will need to get tools onto this PC for us to be able to help you. So figure out a way to get them copied on to the infected PC.

    Another tool that could be useful is ADSspy.

    • Please download ADS Spy, save to your desktop.
    • Once you have downloaded this utility, extract the contents and double click "ADSSpy.exe" to run the utility.
    • Once the utility has loaded, make sure the first 2 boxes are checked.
    • Now click Scan the system for alternate data streams
    • After the scan has finish look for any lines that have the below on them
      • C:\WINDOWS\system32:ciaa.dll
    • Select ONLY THOSE LINES and nothing else! And then have ADSspy remove them (there may only be one instance).
    Then reboot your PC into safe mode. Make sure you have enabled viewing of hidden & system files per step 2 of the READ ME. Look for C:\WINDOWS\system32\ciaa.dll and if found, delete it.

    Attach a new log from GMER
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds