eak500
Topic Starter
Hi Guys
My com keeps restarting and shows error" the system process 'C:\WINDOWS\system32\services.exe terminated unexpectedly with status code - 1073741819. The system will now shutdown and restart".
then i downloaded "Malwarebytes" to scan and it found 2 Trojans which are "Hijack.WindowUpdate". Malwarebyte can delete it and my restart symptom disappear. So, i guess those Trojans are the cause.However, after Malwarebytes deleted and quarantined, it come back every time i restart.
Basically, it is very much the same as these 2 links.
http://forums.whatthetech.com/Malwarebytes….html&st=15
http://forums.whatthetech.com/Hijack_Windo…on_t107128.html
please help!!!!…. i have been searching and trying to fix it for whole day and finally i find the hope here. Thanks in advance.
here is my log from Malwarebytpe.
Malwarebytes' Anti-Malware 1.41
Database version: 2861
Windows 5.1.2600 Service Pack 2
9/27/2009 12:23:34 AM
mbam-log-2009-09-27 (00-23-34).txt
Scan type: Quick Scan
Objects scanned: 134449
Time elapsed: 5 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
My com keeps restarting and shows error" the system process 'C:\WINDOWS\system32\services.exe terminated unexpectedly with status code - 1073741819. The system will now shutdown and restart".
then i downloaded "Malwarebytes" to scan and it found 2 Trojans which are "Hijack.WindowUpdate". Malwarebyte can delete it and my restart symptom disappear. So, i guess those Trojans are the cause.However, after Malwarebytes deleted and quarantined, it come back every time i restart.
Basically, it is very much the same as these 2 links.
http://forums.whatthetech.com/Malwarebytes….html&st=15
http://forums.whatthetech.com/Hijack_Windo…on_t107128.html
please help!!!!…. i have been searching and trying to fix it for whole day and finally i find the hope here. Thanks in advance.
here is my log from Malwarebytpe.
Malwarebytes' Anti-Malware 1.41
Database version: 2861
Windows 5.1.2600 Service Pack 2
9/27/2009 12:23:34 AM
mbam-log-2009-09-27 (00-23-34).txt
Scan type: Quick Scan
Objects scanned: 134449
Time elapsed: 5 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)