This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Forced shutdown and unable to manual update

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been having a plague of issues with my computer, every time I try to get to the bottom of these problems I manage only to get a headache. But I figure I shall start at the top of the list and fix a few problems at a time if possible. I've tried cnet but they've not been able to help me with any of these issues.

I don't know the source of this issues, it might be a nasty piece of software or not, wasn't sure where to post it. But I wanted to post my hijack this log so i figured here.

When I go to - http://windowsupdate.microsoft.com/ I get a blank page, not done with errors, but just done. If I have my security on high then i get you need to change your settings page.

I have tried all the suggestions listed here
http://support.microsoft.com/?kbid=193701
To no avail. (one of these suggestions lead my to my second problem)

Second problem.

I have a number processes listed as running. And like usual its hard to tell which processes belong to which program. As far as I know in XP pro, only two of those processes are critical, the rest should be able to be shut down and yet windows still run. But apparently shutting down one or more of these processes causes a pop up that shuts down your computer in 60 seconds.


I got a number of processes all called svchost.exe running. What triggered it was shutting down one of those svchosts (not any one of them, the first 4 or 5 or so shut down fine without triggering it) I think several programs will trigger it if forced down. The svchost file that triggers takes up by far the most memory of the svchost list. (about 18k)

This system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM

Time before shutdown: (starts out at 60 seconds and counts down)

Message
Windows must now restart because the Remote Procedure Call (RCP) service terminated unexpectedly.



I have run ad aware, spybot, avg antivirus and micropros online scans. None of the stuff they found and deleted fixed either issue.

Small piece of info. If I type in the command shutdown -a during the forced shutdown it is canceled.

Logfile of HijackThis v1.99.1
Scan saved at 5:00:47 AM, on 6/5/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\System\AVG7\avgamsvr.exe
E:\System\AVG7\avgupsvc.exe
E:\WINDOWS\system32\ZONELABS\vsmon.exe
E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
E:\System\ZoneAlarm\zlclient.exe
E:\System\AVG7\avgcc.exe
E:\WINDOWS\System32\wuauclt.exe
E:\System\MYIE2\Maxthon.exe
E:\PROGRA~1\WINZIP\winzip32.exe
E:\HijackThis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (E:\Documents and Settings\me\Application Data\Mozilla\Profiles\default\0wxxl3dy.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (E:\Documents and Settings\me\Application Data\Mozilla\Profiles\default\0wxxl3dy.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - (no file)
O2 - BHO: Watch for Browser Events - {42A7CE31-CEE7-4CCE-A060-A44A7E52E062} - E:\System\KEYBOA~1\kie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\System\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Zone Labs Client] E:\System\ZoneAlarm\zlclient.exe
O8 - Extra context menu item: &ieSpell Options - res://E:\System\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://E:\System\ieSpell\iespell.dll/SPELLCHECK.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - E:\System\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - E:\System\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - E:\System\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - E:\System\ieSpell\iespell.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O15 - Trusted Zone: http://V4.Windowsupdate.microsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {6EE39BFC-2FB6-4B69-9D05-CFC10E4F5B3E} (MavenBootInstallerAXControl Class) - http://client.maven.net/client/mavenBootInstaller.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\System\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\System\AVG7\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - E:\WINDOWS\system32\ZONELABS\vsmon.exe



Please, I'm desperate to fix these problems that plague my computer. :( Thank you.
Hi Hobbes! I'm 'KotaGuy. Welcome to TomCoyote!

If you still require assistance, could you please post a new HijackThis log. It has been a few days since you've posted and something might have changed since then.

Before you do, I'd like you to do some scans. Please do scans at Panda ActiveScan and TrendMicro HouseCall. Let them fix anything they find. Reboot between each scan.

If you don't have it, download and install Ad-Aware. Ipdate both Ad-Aware and Spybot. Visit this page for proper configuration. Run and scan with both, letting them fix whatever they find. Remember to reboot between each scan.

Download and install SP1a from here.

Once you have that done, post a new HijackThis log please.

Thanks!
No need to reboot if they don't find anything right?


I have run ad aware, spybot, avg antivirus and micropros online scans. None of the stuff they found and deleted fixed either issue.


I have updated and rescanned with these. They found nothing new but a few ad tracking cookies

Panda won't work for me.

As far as SP1. I believe I already installed that. You want me to reinstall that before posting a log? You don't want me to install SP2?
No… you don't have SP1 installed. And though SP2 is out, just get SP1 for now. Once you've got your system straightened out you can get SP2. Please reboot between each scan. Did you configure Ad-Aware and Spybot as suggested on the page I gave you a link to? If not, please do and run the scans. Post a new HijackThis log when done.
I reconfigured adaware like suggested and am doing a second scan now. SP1a won't install for me. Doesn't like my key ID. My XP pro copy isn't exactly legit. I'm not going to pay some hefty ~$200-$300+ MS tax on my computer (I believe thats how much they were charging retail for XP when I built my system) . I can't afford such things and its not fair considering how much less they charge corps, especially those who promise only to use MS's OS and such. Plus their near monoply on software products, its hard to find programs written for anything other then MS windows, especially games which are my addiction. dayam monopolies. :rant: I had forgotten this(that I had to find alternative ways to update instead of sp). I had updated XP pro as best as I could via different sources including the windowsupdate page (it use to work fine for me) And some other security webpages that I'm sure you would recognize them if I posted but I can't recall at the moment. Would you guys still be willing to help me? Please? :( Would be very much appreciated :D Whats in service pack 1a thats so needed for recognizing spyware programs in a hijackthis log anyways?
Logfile of HijackThis v1.99.1
Scan saved at 4:31:20 PM, on 6/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\System\AVG7\avgamsvr.exe
E:\System\AVG7\avgupsvc.exe
E:\WINDOWS\system32\ZONELABS\vsmon.exe
E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
E:\Program Files\QuickTime\qttask.exe
E:\System\ZoneAlarm\zlclient.exe
E:\System\AVG7\avgemc.exe
E:\System\AVG7\avgcc.exe
E:\Program Files\ATI Technologies\ATI.ACE\cli.exe
E:\System\MYIE2\Maxthon.exe
E:\HijackThis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (E:\Documents and Settings\me\Application Data\Mozilla\Profiles\default\0wxxl3dy.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (E:\Documents and Settings\me\Application Data\Mozilla\Profiles\default\0wxxl3dy.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - (no file)
O2 - BHO: Watch for Browser Events - {42A7CE31-CEE7-4CCE-A060-A44A7E52E062} - E:\System\KEYBOA~1\kie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\System\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Zone Labs Client] E:\System\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_EMC] E:\System\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\System\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATICCC] "E:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O8 - Extra context menu item: &ieSpell Options - res://E:\System\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://E:\System\ieSpell\iespell.dll/SPELLCHECK.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - E:\System\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - E:\System\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - E:\System\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - E:\System\ieSpell\iespell.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O15 - Trusted Zone: http://V4.Windowsupdate.microsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {6EE39BFC-2FB6-4B69-9D05-CFC10E4F5B3E} (MavenBootInstallerAXControl Class) - http://client.maven.net/client/mavenBootInstaller.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\System\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\System\AVG7\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - E:\WINDOWS\system32\ZONELABS\vsmon.exe
"As you have so admitted that you are running stolen merchandise, you have an option to pay for it and make it good, uninstall and go to a free version of Linux, or just deal with all the insecurities and problems you now have, TC does not support the use of illegal software" Tom Coyote Wilson


I really do advise you get a legit copy of Windows installed, you will be extremely vulnerable to a ton of exploits until you do. The reason installing the SP's are so important is that they close a lot of the security issues in XP.

Couple entries you can fix:

O2 - BHO: (no name) - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - (no file)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -


Nothing Malware related in your log though.

Because of that, coupled with the fact that you are admittedly using a pirated copy of XP, this is where my help must end. Sorry.
I am closing this topic as it has been resolved.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI