TechSpot

Computer just shuts down with no warning

By Jimborang
Oct 20, 2006
  1. I believe I may have another trojan at work. Attached is the HijackThis log. Any help with this mess will be appreciated. Ran a virus scan and all seems well with that. Would love some advice on as soon as possible. Thanks so much



    Jimborang
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Go and read the Trojan Pakes and other nasties preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.


    Regards Howard :wave: :wave:


    This thread is for the use of Jimborang only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. Jimborang

    Jimborang TS Rookie Topic Starter

    Thanks Howard

    Have done everything you have asked in the instructional email. Here is the new HijackThis log and Spyware log for your review. Took over nine hours to do all of the downloads etc. Long night!!!! I will post the logs in two different post because they are too long.

    Thanks

    Jimborang
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Please post your HJT and AVG Antispyware logs as attachments. See HERE.

    Regards Howard :)

    This thread is for the use of Jimborang only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. Jimborang

    Jimborang TS Rookie Topic Starter

    I hope this file attached okay Thanks for your help.

    Jimborang

    here is the second report you requested Howard. Thanks Jimborang
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Run HJT with no other programmes open. Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R3 - URLSearchHook: (no name) - {403FD7D8-6260-51CD-44F7-1DD4C9CFAFEC} - (no file)

    O2 - BHO: (no name) - {403FD7D8-6260-51CD-44F7-1DD4C9CFAFEC} - (no file)

    O2 - BHO: (no name) - {51EC5381-B76A-F8E1-3403-993C6428E0B1} - (no file)

    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    O20 - AppInit_DLLs: ?i??

    Click on the fix checked button.

    Close HJT.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    DinerDashSetup-dm[1].exe

    Close task manager.

    Locate and delete the following bold files and/or directories(if there).

    C:\Downloads\DinerDashSetup-dm[1].exe

    Reboot into normal mode, check to make sure the above file has been deleted.

    Turn system restore back on and rehide your protected OS files.

    Post a fresh HJT log and let me know if you`re still having any problems.

    Regards Howard :)

    This thread is for the use of Jimborang only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. Jimborang

    Jimborang TS Rookie Topic Starter

    Great job Howard

    Here is the latest Hijack this log. Looks like everything else is running fine. Do you recommend reloading Norton or keep the NOD that you recommended to clean my computer. Also, The HJT log seems to have a lot of extraneous files listed that are not necessary to run my computer efficiently. Can anything else be removed without harming the running of the machine. Still seems a little slow to me. Thanks for your help. At least it has stopped rebooting automatically for now.

    Jimborang
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    You`re running more than one antivirus programme. This is not recommended and will slow your system down and can cause conflicts. Uninstall one of them.

    I don`t recommend you install Norton as it`s the biggest resource hogging crap and will slow your system down even more.

    You have a lot of Cold fusion entries running on start up. Do you need them to run on startup? If not you should disable them via services.

    To speed up your pc, do the following. Uninstall anything you don`t want or use. Stop anything you don`t want to run on startup via msconfig`s startup tab.

    Go and read this thread HERE.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of Jimborang only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...