# Restarted on its own

Discussion in 'Virus & Other Malware Removal' started by s1cko, Jul 15, 2006.

Not open for further replies.

Joined:
Jul 12, 2006
Messages:
38
Hi, my computer has just restarted on its own my friend was doing one of those video professor things that i purchased and it just restarted. See I just had my computer reformatted a couple days ago and dont have that much protection yet. Can someone help me to see whats wrong? Also i have this program called wintasks and it didnt find anything out of the ordinary.

2. ### valisModerator

Joined:
Sep 24, 2004
Messages:
76,132
start > run > eventvwr.msc and look under the application and system areas on the left to see what occurred roughly at the time it crashed. Paste the data back here please.

v

Joined:
Jul 12, 2006
Messages:
38
The only 2 things that happened around that time is Information McLogevent and Information Security Center they both happened at the same time. Also after it restarted something came up and said Windows has encountered an error or something.

4. ### valisModerator

Joined:
Sep 24, 2004
Messages:
76,132
'windows encountered an error or something' is not enough data to make a diagnosis with, unless you want the diagnosis to be 'well, don't do whatever caused it again, and it won't happen'.

WHAT did the McLogevent say, and WHAT did the ISC say, verbatim? Chances are you are not hijacked, but we will get there in due time. It was most likely a hiccough in the system, as can happen sometimes, but regardless:

start > run > sysdm.cpl > advanced tab > start up and recovery settings button (bottom) > untick the 'auto restart' feature. Now when it crashed, the blue screen will stay up long enough for you to read it. Next time it happens, write down everything it says on there. For now, if you want, you can post a hijack this log and we can take a look at it, but if you recently reformatted, can't say that anything will be in there. As below:

· Save HJTsetup.exe to your desktop.
· Doubleclick on the HJTsetup.exe icon on your desktop.
· By default it will install to C:\Program Files\Hijack This.
· Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
· Put a check by Create a desktop icon then click Next again.
· Continue to follow the rest of the prompts from there.
· At the final dialogue box click Finish and it will launch Hijack This.
· Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
· Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
· DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Joined:
Jul 12, 2006
Messages:
38
Here is what it said:

Logfile of HijackThis v1.99.1
Scan saved at 8:01:49 PM, on 7/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

6. ### valisModerator

Joined:
Sep 24, 2004
Messages:
76,132
everything *looks* fine to me, but I am not qualified to tell you yes or no anyhow, so it's a moot point. I see you've got mcaffee up and running and sp2 up and running, which is really all I wanted the hjt log for. With those two you have your firewall and your antivirus, so you are pretty safe that way. Personally, I would wait for it to happen again, and this time pay very close attention to what it says. Also, did you have any more info from the event log?

v

As Seen On