PC Keeps Rebooting at Startup
#1
Posted 20 June 2009 - 07:32 PM
Malwarebytes' Anti-Malware 1.38
Database version: 2317
Windows 5.1.2600 Service Pack 3
6/20/2009 7:19:38 PM
mbam-log-2009-06-20 (19-19-38).txt
Scan type: Quick Scan
Objects scanned: 183613
Time elapsed: 25 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
#2
Posted 20 June 2009 - 07:50 PM
C:\WINDOWS\system32\drivers\mbam.sys
C:\WINDOWS\system32\drivers\mbamswissarmy.sys
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref (Windows 2000/XP)
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref (Windows Vista)
please take a look and reply back, thank you...
EDIT: It would help if I know what you are using for AV & a Firewall please

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#3
Posted 20 June 2009 - 07:59 PM
Thank you very much for responding so quickly. To be very blunt - I don't know. In fact I do not even know where to check or look to confirm your questions. I am a total amateur or newbie when it comes to computer troubleshooting. Can you direct me?
Steve
#4
Posted 20 June 2009 - 08:03 PM
And I believe you have XP? correct me if I'm wrong?

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#5
Posted 20 June 2009 - 08:12 PM
#6
Posted 20 June 2009 - 08:14 PM

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#7
Posted 20 June 2009 - 08:19 PM
#8
Posted 20 June 2009 - 08:24 PM

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#9
Posted 20 June 2009 - 08:28 PM
#10
Posted 20 June 2009 - 08:30 PM
victimized, on Jun 20 2009, 06:28 PM, said:
Look over the thread from the top, please.. remember no. # 3 he's new. After he replies back
let me know what ideas you have please

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#11
Posted 20 June 2009 - 08:31 PM
Additional info: after MBAM discovered the infections, I rebooted the pc and it worked just fine for about three or four hours. Then it suddenly rebooted by itself and has not worked correctly since.
I'm in safe mode now and it is the only way for me to communicate with you.
And yes, I totally agree....one pc at a time.
#12
Posted 20 June 2009 - 08:35 PM

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#13
Posted 20 June 2009 - 08:39 PM
Malwarebytes' Anti-Malware 1.38
Database version: 2310
Windows 5.1.2600 Service Pack 3
6/20/2009 6:46:45 AM
mbam-log-2009-06-20 (06-46-45).txt
Scan type: Quick Scan
Objects scanned: 180861
Time elapsed: 24 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 7
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\AVR09.exe (Adware.AdvancedVirusRemover) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\critical_warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.
#14
Posted 20 June 2009 - 08:52 PM

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#15
Posted 20 June 2009 - 08:57 PM
#16
Posted 20 June 2009 - 09:07 PM
#17
Posted 20 June 2009 - 09:10 PM
I made it through! Here is what I did. I closed out of everything and then went through the process of shutting down pc. Instead of restarting, I shut completely down, waited for 30 seconds and then pressed button to start the computer again. I booted up fine with no problems. My desktop showed up and everything looked fine. I clicked on the MS IE button on the bar at bottom of screen and after a few seconds I got a typical error message from MS Windows saying 'The system has recovered from a serious error. A log of this error has been created.' Then it basically goves me the option to tell Microsoft about the problem so I can send an error report to them. The buttons say 'Send Error Report' or 'Don't Send'.
#18
Posted 20 June 2009 - 09:12 PM
#19
Posted 20 June 2009 - 09:14 PM
another mystery?
EDIT: are you in windows ?

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
#20
Posted 20 June 2009 - 09:16 PM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users











