1.

Solve : random windows restart?

Answer»

hi, i've just had windows restart randomly, and recived a message saying windows has recoverd from a serious error.
i sent the error report and it took me to this page: http://wer.microsoft.com/responses/Response.aspx/79/en-us/5.1.2600.2.00010300.2.0?SGD=402e73a9-0997-4d8d-9cc0-468a8e2a0c2d
which was no help at all... and this has never happend before :-?

all i was doing at the time was listning to music on my hardrive from windows media player, shutting down MSN, inserting a CD for a computer game (which i've done before many times without this happaning). and then all of a sudden windows shuts down.

i'm using WinXP home SP2, norton 2006 AV/firewall, all kept up to date

thanks in advance for any replies
i'm completely clueless on why this happend and how i can stop it from happaning again!heres a hijackthis log...ok GET AVG anti-spyware

spybot

Ccleaner
and update them

run all of the scans (including issues scan on Ccleaner and back up when ASKED) in safe mode with system restore off

unlovedwarriorHi Ted2 ... In addition to the above you MUST update java. Your Java is well out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it SAYS "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
When all is done please post a fresh HJT log

AND...

an update on how your compter is operating now.

There is at least one more HJT running process I don't like (and will be recommending its removal) and there may be other files that need deleting.

However, there's nothing in the log that indicates why you should have suffered a random restart. That issue may be down to hardware/software issues. Perhaps overheating too.

Let's deal with the obvious malware first though.


OJQuote
ok get avg anti-spyware

spybot

Ccleaner
and update them

run all of the scans (including issues scan on Ccleaner and back up when asked) in safe mode with system restore off

unlovedwarrior

done and done

thanks OJ, i wasen't aware of my Java being out of date, or it being a problem really. it's up to date now... i've had no more restarts so far...

whats next? i'd like to get rid of any malware possible..

oh, and i'm worried about the computer over heating too... it's a pre built computer, and i've had it for around 3 years. so i'm guessing it must be getting abit rusty by now :-/

i took some tempreture readings from Everest... while in game my CPU is around 61C
and while idle the temp is around 49C
i'm not sure if this is a good or bad thing.. but i am looking to upgrade at some point...sadly things have just got worse for me, i'm now unable to shut down windows!
i've had this problem which i've been ignoring for some time, but it just got worse..

ccApp.exe fails to shut down, normaly i wait a minute and it shuts down..
but now it just doesn't shut down at all! arfter waiting 30mins i go start/turn off again.. and nothing! i tried opening/closing norton,alt+ctrl+del - shut down does nothing either.
now the only way is to force my comp to shutdown
it only seems to do this sometimes, i've not worked out what triggers it yet.

i've had this smaller problem too where norton security 2006 crashes sometimes when i open it (normaly i just alt ctrl del it, load it up again and it's fine)... maybe it's all related, and norton is cuasing all the problems, i'm not sure. but it has worked fine for me in the past...


EDIT: lol! sorry, just noticed how full of questions this thead is! i'll ignore the norton crashes for now.. i'm more intrested in getting rid of this malware you spotted OJ.. i'm not sure how to read a HJT logDLoad the tool below...

Norton Removal Tool


1) Use Add Remove Programs first and un-install Norton...
2) From Windows Explorer search for any folders named Norton and Symantec and delete them...
3) DLoad and install ERUNT and have it make a backup of your registry...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next instance of Norton. Continue til you have reached the end of the registry...
5) Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6) Now run the Norton Removal tool you DLoaded...
7) Empty the recycle bin...
Go to My Computer and right clik the C: drive and select Properties and run disk cleanup...
9) Re-boot and run disk defrag....

There you're done !

See how easy Symantec makes it for you to dump their product ? ?

patio. 8-)Do you have a real Windows CD to reinstall with? It's been two days now and that is more than enough time to have installed, updated and reloaded your programs.

Of course this will not solve hardware issues, but a good format and reinstall solves all Windows problems.....for a while. Quote
thanks OJ, i wasen't aware of my Java being out of date, or it being a problem really. it's up to date now... i've had no more restarts so far...

whats next? i'd like to get rid of any malware possible..
Please post a fresh HJT log. We'll see where we go from there.


OJPatio, i'll keep note of that for later on thanks.. but i'll stay with norton until subscription runs out. arfter all, it is still doing it's job... just seems abit buggy is all :-/

and the reformat, i'm leaving that for a last resort... although it's defently time i made backups!! i'll by some blank CD's tomorow hopefully...

much appriceated
TedNo problem. I hope that subscription isn't too long...Hi

Please print this out as you will need to close all open windows for part of this fix.

The log is clean apart from the one program I alluded to earlier, ALCMTR.EXE.

This is related to Realtek AC97 Audio - Event Monitor. It's "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers. Undesirable.

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for it (IF it still exists) .........

C:\WINDOWS\ALCMTR.EXE


Open HijackThis and click on 'Do a System Scan Only'. Check the following entry (IF it still exists).....

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Please remember to close all other windows, including browsers before clicking Fix checked.


Go to the following file (in BOLD) and delete it .......

C:\WINDOWS\ALCMTR.EXE


Empty your recycle bin.


Reboot your system in Normal Mode.

Perform an online scan with Internet Explorer here .....

http://www.pandasoftware.com/products/activescan.htm

Click on the "Free To Use ActiveScan" located on the top right hand corner [list=1]
  • Click Check Now and a "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  • Enter your e-mail address, country, and state & click Scan Now * The download of the 8 MB Panda's ActiveX control will take place *
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
    • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    • Click on See report then click Save report[/color]
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
    * Turn off the real time scanner of any existing antivirus program while performing the online scan

    Paste the Panda Scan report here together with a new HiJackThis log.


    PLEASE ALSO LET US KNOW HOW YOUR COMPUTER IS OPERATING GENERALLY. ANY LINGERING ISSUES?


    OJ
generaly my computer is ok, performance is roughly what it should be i think...

alcmtr.exe - i'd rather keep this process

i remember using the free panda scan last year.. still gives the same result as it did before,
1 hack tool and 128 spyware detectedOn the Activescan report ...

This file: C:\HP\bin\KillIt.exe looks like something HP put there to delete bad stuff.

See this also ....
http://www.pcreview.co.uk/forums/thread-108839.php

If you do not use it you may delete it but, if HP put it there as part of a malware removal process, it may stop working.

You can upload/scan it online if you wish here:

http://virusscan.jotti.org/

http://www.kaspersky.com/scanforvirus

http://www.virustotal.com/flash/index_en.html

Or you can ask HP tech support about them: http://h10025.www1.hp.com/ewfrf/wc/siteHome

Once you make your decision you can delete it if you wish.

************

The others are cookies that Spybot and/or Ccleaner should get rid of. Load/update Programs from here ...

Spybot > http://www.spybot.info/

Ccleaner > http://www.spybot.info/
>>>NOTE >>> when downloading/installing Ccleaner make sure you UNtick the optional Yahoo TRoolbar download.

Scan your system with both and let them clean out cookies.

************

Empty your recycle bin.

************

Final thoughts.....

If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.

If you do suffer an infection again you should run first Spybot & Ccleaner to clean out your system.

Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.



OJ


Discussion

No Comment Found