Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

System Keeps Rebooting itslef


  • Please log in to reply

#1
markmoloney

markmoloney

    New Member

  • Member
  • Pip
  • 6 posts
Hi all, bit of a novice here so excuse me in advance. My problem is as follows. Never had a problem with my PC until now. It is an AMD 2800 with a Hercules 64mb graphics card, ADSL , two disc drives the C has 4gb and the D has 20 GB.
Recently and nearly always now I am having the same problem. I am playing Novalogics Delta Force 2 in multiplayer mode and have been for years over the net but recently my PC keeps rebooting itself after a minute or so into the game.
I have carried out all the addware, spybot, hijack this and virus checkers and nothing has been spotted.
The game itself is loaded on my D drive which has about 14GB of free space. My C has onyl about 365mb of free space left. When the system tries to reboot itself 4 out of 5 times it only gets to the end of the memory test on boot up and then tries to boot itself over and over again. Incidentally I have 528 MB of ram. I do not have this problem with any other application I use. Any ideas. Thanks in advance.
  • 0

Advertisements


#2
Hemal

Hemal

    Founding Fart

  • Technician
  • 1,470 posts
welcome mark

lets take a look at whats running on your computer by using a free diagnostics tool called HiJack This, which can be found in my signiture, please download the program, close all open windows and programs, run the program, save your log and post it back up here
then we can go from there <_<

DO NOT delete or modify any of the things that apper on the HiJack This log unless told to
  • 0

#3
markmoloney

markmoloney

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thanks again for the help Sox. Here is the latest hijack this logfile.


ogfile of HijackThis v1.97.7
Scan saved at 22:32:25, on 03/06/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Documents and Settings\mm\Desktop\hijack\HijackThis.exe

O2 - BHO: (no name) - {8C8DFD57-48F1-CA9B-36B8-CFE6FC5A4B87} - C:\PROGRA~1\Refnew\TrayOpen.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: LogoInfo - {FD4F351C-3875-D45C-3371-99A95180753D} - C:\PROGRA~1\Refnew\TrayOpen.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Ball 1] C:\PROGRA~1\Title Send Dumb\InternetPlus.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKCU\..\Run: [Spyware-Cop] "D:\spyware\Spyware-Cop.exe" /s
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macrom...tor/cabs/sw.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.../20/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab
  • 0

#4
markmoloney

markmoloney

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Ok it just happened again. I include the event log just after it happened.

04/06/2004 19:56:40 TrueVector Service Error None 5007 N/A MM-5YA3CAH0N7JK "TrueVector engine: File ""C:\WINNT\Internet Logs\MM-5YA3CAH0N7JK.ldb"" was corrupt and has been copied to ""C:\WINNT\Internet Logs\xDB33.tmp"". File ""C:\WINNT\Internet Logs\MM-5YA3CAH0N7JK.ldb"" was corrupt and has been deleted. "
04/06/2004 19:56:39 TrueVector Service Error None 5007 N/A MM-5YA3CAH0N7JK "TrueVector engine: File ""C:\WINNT\Internet Logs\IAMDB.RDB"" was corrupt, restoring from backup ""C:\WINNT\Internet Logs\BACKUP.RDB"". "
04/06/2004 19:56:39 TrueVector Service Error None 5007 N/A MM-5YA3CAH0N7JK "TrueVector engine: File ""C:\WINNT\Internet Logs\IAMDB.RDB"" was corrupt and has been copied to ""C:\WINNT\Internet Logs\xDB32.tmp"". File ""C:\WINNT\Internet Logs\IAMDB.RDB"" was corrupt and has been deleted. "
04/06/2004 19:56:32 McLogEvent Information None 5000 NT AUTHORITY\SYSTEM MM-5YA3CAH0N7JK VirusScan Enterprise McShield service started - scanning for 91110 viruses.
Engine version : 4.3.20
.DAT version : 4364

EXTRA.DAT name : None
Number of virus signatures in EXTRA.DAT : None
Names of viruses that EXTRA.DAT can detect : None
04/06/2004 19:56:30 McAfeeFramework Information None 0 N/A MM-5YA3CAH0N7JK The description for Event ID ( 0 ) in Source ( McAfeeFramework ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: Service started.
  • 0

#5
admin

admin

    Founder Geek

  • Administrator
  • 24,501 posts
This looks like some randomonly named malware:
O4 - HKLM\..\Run: [Ball 1] C:\PROGRA~1\Title Send Dumb\InternetPlus.exe

Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items, then click fix checked.
O4 - HKLM\..\Run: [Ball 1] C:\PROGRA~1\Title Send Dumb\InternetPlus.exe

Reboot in safe mode (by tapping F8 at startup and select safe mode from the menu).
Be sure you're able to view hidden files, and remove the following files in bold (if found):
C:\PROGRAM FILES\Title Send Dumb\ <- this folder

Reboot your PC.

If you would please, rescan with HijackThis and post a fresh log, and let us know how your system's working. <_<

If that doesn't work, you should try repairing Internet Explorer:
http://www.geekstogo...p?showtopic=251
  • 0

#6
markmoloney

markmoloney

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thanks admin, I did the scan and removed the item. Rebooted in safe mode and followed your instructions but there was no files or folder of that name. Attached is the latest log.


Logfile of HijackThis v1.97.7
Scan saved at 21:09:54, on 04/06/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Documents and Settings\mm\Desktop\hijack\HijackThis.exe

O2 - BHO: (no name) - {8C8DFD57-48F1-CA9B-36B8-CFE6FC5A4B87} - C:\PROGRA~1\Refnew\TrayOpen.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: LogoInfo - {FD4F351C-3875-D45C-3371-99A95180753D} - C:\PROGRA~1\Refnew\TrayOpen.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKCU\..\Run: [Spyware-Cop] "D:\spyware\Spyware-Cop.exe" /s
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macrom...tor/cabs/sw.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.../20/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab
  • 0

#7
admin

admin

    Founder Geek

  • Administrator
  • 24,501 posts
Well it's gone <_<

If you continue having reboot problems, try the Internet Explorer repair, linked above.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP