Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Pending] Random restart

[Fixed] Hijackthis! Logs - [Pending] Random restart posted in the Security & Safety forums; My computer just randomly restarts. and I do mean randomly, there is no common thing happening at the time....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-11-2005
PraiseJah's Avatar
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default [Pending] Random restart

My computer just randomly restarts. and I do mean randomly, there is no common thing happening at the time.


  #2  
Old 09-11-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,642
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Random restart

:-) Hey PraiseJah,

Welcome back. sorry about the circumstances tho.

Have you done any tests to determine if your PC is overheating? Give this one a try, and post back the temp that it lists for your motherboard?
Motherboard Monitor

Have you run all of the standard tests to make sure you aren't reinfected with a virus?

Please paste your HJT log here so one of us can see if there is anything in there causing the problem.

TTFN

T


  #3  
Old 09-11-2005
PraiseJah's Avatar
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default Re: Random restart

The temp is 32F. . .? I think lol

Attached Files
File Type: txt Log.txt (24.3 KB, 0 views)


  #4  
Old 09-11-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Random restart


Im not really surprised that youre pc reboots... but lets see what we can do:


Before using Hijack This Can you please do this for me:


Show hidden files and folders:


For 98/2000/ME:

1.double-click the My Computer icon
2.Click on the View menu, click Folder Options
3.Advanced Settings box, under the "Hidden files" folder, click Show all files.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.



Then disable system restore to prevent re-infection.
(if you have/use it.)
(you can turn it back on when youre pc is clean).


How to disable system restore:


WinME.

Click Start > Settings > Control Panel.
Double-click the System icon.
If the System icon is not visible, click View all Control Panel options to display it.
On the Performance tab, click File System.
On the Troubleshooting tab check Disable System Restore.
Click OK. Click Yes, when you are prompted to restart Windows.



Do a virus scan here. Or select one here.
Also run Stinger - Trojan Remover.
If you get report of files that can?t be cleaned/deleted please write down the filenames and locations and post that in your reply.

Then please do this since it?s better to use automated tools to get rid of the bad stuff use these programs first before doing the final cleaning with HJT.


Spybot: Search And Destroy:


1.Download the new version (1.4) of 'Spybot: Search And Destroy'.

2. Install it according to the instructions in 'How To Setup Spybot SD'.

3. Next, 'Search for Updates' as the definitions are not likely to be up-to-date.

4. Close ALL windows except Spybot SD.

5. Click the "Check for Problems" button.

6. Click 'Fix Selected Problems' and fix only the RED items.



Ad-Aware SE by Lavasoft:

1. Download 'Ad-Aware SE'.

2. Install according to the instructions in? "How To Setup Ad-Aware SE"

3. Next, 'Check for Updates' by clicking on the 'world globe' second from the right at the top of your Ad-Aware SE window.

4. Install the updates.

5. Close ALL windows except Ad-Aware SE.

6. Click on 'Start' and choose 'full scan' for a full scan.

7. Quarantine anything that it finds and SAVE the log file.





Please download Ccleaner here.



See if these are in "add and remove programs" and if they are then un-install them:



THE WEATHER CHANNEL <(optional , leave it if you want to keep it)
LOGITECH\DESKTOP MESSENGER
EliteToolBar
EliteSideBar
VBOUNCER
VirtualBouncer
AQUATICA WATERWORLDS
DESKAD SERVICE
XLMPDMPZ
EBATES_MOEMONEYMAKER
seaa
HELLO
H&ello


Then fix these with hijackthis if still present:


(except if you want to keep the "THE WEATHER CHANNEL" software then dont fix those.)


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {F6B07D5F-F283-9B29-B06A-EEE52EBD07A0} - C:\WINDOWS\SYSTEM\YNOEYM.DLL (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\VZBB.DLL
O2 - BHO: (no name) - {D2CB6414-F0A8-D10D-DFCB-F3DA1FCF68C7} - C:\WINDOWS\SYSTEM\BNOXPU.DLL
O2 - BHO: (no name) - {7B63831C-17A9-625C-8F9E-46D1EF63C6C0} - C:\WINDOWS\SYSTEM\MRDIM.DLL
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\VZBB.DLL
O4 - HKLM\..\Run: [c70e91fe5dc0] C:\WINDOWS\SYSTEM\DBMSSPXN.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRAM FILES\AQUATICA WATERWORLDS\AQ3HELPER.EXE /partner AQ3
O4 - HKLM\..\Run: [DeskAd Service] C:\PROGRAM FILES\DESKAD SERVICE\DESKADSERV.EXE
O4 - HKLM\..\Run: [xhrmy] C:\WINDOWS\Xhrmy.exe
O4 - HKLM\..\Run: [4MZT6FA4AT2NPD] C:\WINDOWS\SYSTEM\NuzK63G.exe
O4 - HKLM\..\Run: [FARMMEXT] C:\WINDOWS\FARMMEXT.exe
O4 - HKLM\..\Run: [zyrqwc] C:\WINDOWS\SYSTEM\zyrqwc.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\SYSTEM\OUSMJD.exe
O4 - HKLM\..\Run: [saie] c:\windows\system\saie.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\SYSTEM\CRAGEF.exe
O4 - HKLM\..\Run: [XLMPDMPZ] \Progra~1\XLMPDMPZ\XLMPDMPZ.exe
O4 - HKLM\..\Run: [KOGOL] C:\WINDOWS\SYSTEM\KDIGCHHS\KOGOL.EXE
O4 - HKLM\..\Run: [cwhtfc] C:\WINDOWS\SYSTEM\cwhtfc.exe
O4 - HKLM\..\Run: [App32dll] C:\WINDOWS\SYSTEM\MSNAVC32.EXE lee0105
O4 - HKLM\..\Run: [awal] C:\WINDOWS\SYSTEM\rgyiat\awal.exe
O4 - HKLM\..\Run: [ouvv] C:\WINDOWS\SYSTEM\qkxgr\ouvv.exe
O4 - HKLM\..\Run: [antiware] C:\WINDOWS\SYSTEM\ELITEPPA32.EXE
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qugyyw.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [TOLJVEEI] C:\WINDOWS\SYSTEM\TOXGKLJP\TOLJVEEI.EXE
O4 - HKCU\..\Run: [Ycurxdyg] C:\WINDOWS\SYSTEM\bmw.exe
O4 - HKCU\..\Run: [BLAXPI] C:\WINDOWS\SYSTEM\BLAXPI.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRAM FILES\THE WEATHER CHANNEL\THE WEATHER CHANNEL.EXE
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - HKCU\..\Run: [Etaa] C:\Program Files\seaa\ccam.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZNxdm396XXUS
O8 - Extra context menu item: Ebates - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.ht m
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\PROGRAM FILES\HELLO\PICASACAPTURE.DLL
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\PROGRAM FILES\HELLO\PICASACAPTURE.DLL
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.ht m (file missing) (HKCU)
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/Wi...nerInstall.cab

all 018 logitech entry's

O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINDOWS\SYSTEM\LMF32V.DLL

And then delete the files/folders in bold (if still present), after that run Ccleaner.


Now reboot and post a new hjt log please.







I see that you dont have a AV and firewall , to prevent infections like this you should have them , have a look in the download section for some free versions.

Also update windows to make sure youre patched and protected.




And do you still use/want the start/search pages and software from:

verizon.net
and
shawneelink




__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 10:22 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top