This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer auto restarts

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good day,

My PC auto restarts when I try to launch a program. This happened right after I have switched-on my PC. The first occurance was after I clicked on the Trend Micro PCC 2005 icon in the system tray at bottom right of window. After it auto-restarted, it restarted automatically when I clicked on the Ad-Aware icon on my desktop.

Please advise. Thank you.

My HJT log as is follows:

Logfile of HijackThis v1.99.1
Scan saved at 8:00:52 PM, on 11-Jun-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\MSOffice\Office\Msoffice.exe
C:\Program Files\WinZip\Wzqkpick.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114165901675
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk Dwf Viewer Control) - http://www.autodesk.com/global/dwfviewer/i…ViewerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
Hello wgan,

Welcome to Tom Coyote, I am so sorry that we haven't gotten to you. If you still need assistance, please do this.

DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix,
* just go to MY COMPUTER > YOUR C:\ DRIVE and create a new folder and name it HIJACKTHIS .
* Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
* Now open the new folder you just created and right click within that folder and select PASTE .
* Now HJT should reside in C:\HIJACKTHIS\HIJACKTHIS.EXE

Your system may have changed since you posted last, please post a new HJT log and I will look it over for you.
Good day ken545,

Yes, I do still need help.

Though the original problem of my PC auto-restart has not recurred, my system seems to be a little slower than previously, especially during booting-up stage.

I have scanned my PC with Ad-Aware, Spybot and Microsoft's beta version anti-spyware. So far all scans did not detect any spywares or suspicious programs.

In my attempt to improve my system's speed and boot-up, I have uninstalled SpyGuard and SpyBlaster. Resulting speed improvement has been minimal.

Kindly review my log and advise.

As in accordance to your instruction, I have saved the HijackThis into its own folder in C drive - C:\HijackThis\HijackThis

My new log is as follows:

Logfile of HijackThis v1.99.0
Scan saved at 3:38:18 PM, on 22-Jun-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\MSOffice\Office\Msoffice.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThis\HijackThis\HijackThis.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114165901675
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk Dwf Viewer Control) - http://www.autodesk.com/global/dwfviewer/i…ViewerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194
O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

Many thanks,
wgan
wgan,

Run HJT Scan Only and put a checkmark in the following entry, close all open windows and your web browser and click on FIX CHECKED.

* R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm

Spyware Blaster and Spyware Guard and two great programs that you should have left on your system. I urge you to reinstall them. I have never had experiences as to where they slowed your system down.

I would like you to run a couple of Free Online Virus sccanners. Run them both and have them enable to fix what they find. If they find anything and can't fix it, please post those results to this thread.

http://housecall.trendmicro.com/
http://www.pandasoftware.com/products/acti…n_principal.htm

You can also download and run the evaluation copy of TROJAN HUNTER
http://www.trojanhunter.com/

When your done with all the above, run HJT and post a new log please.
Good day ken545,

Thank you for your help.

I have done according to your instructions.

One item on first HJT log has been fixed.

+++

Result of Scan by Panda ActiveScan

Detected: Virus name: Restart

Location: C:\WINDOWS\SYSTEM\Tools\Restart.exe

Status: "No disinfected" - Panda ActiveScan cannot remove.

Link to Virus Encyclopedia: http://www.pandasoftware.com/virus_info/en…eteccion=122168

No action taken yet.

+++

Result of Scan by Trend Micro HouseCall

Detected: Spyware name: SPYW_FPTLBAR.100

Link to information on spyware:

http://www.trendmicro.com/vinfo/grayware/v…wareDetails.asp?

GNAME=SPYW%5FFPTLBAR%2E100

Action taken: removed with Trend Micro HouseCall

+++

Scan with Trojan Hunter

Nothing detected.

+++

Current HJT log:

Logfile of HijackThis v1.99.0
Scan saved at 7:35:59 AM, on 23-Jun-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\MSOffice\Office\Msoffice.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114165901675
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk Dwf Viewer Control) - http://www.autodesk.com/global/dwfviewer/i…ViewerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194
O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

Many thanks.
wgan
wgan,

I need to ask you a couple of questions.

Are you famliar with this program? I can't find to much info about it.
C:\Program Files\ANI\ANIWZCS2 Service

Are you familiar with this site?
Value Club. Challenger.com

Is this your ISP?
Asia Pacific Network

Lets run this free online scan from BitDefender
http://www.bitdefender.com/scan/licence.php


I would like you to enable windows to show all files and folders and restart your computer into SAFEMODE. Here are the instructions.

SHOW HIDDEN FILES AND FOLDERS

* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean


To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD

Now look for and delete this file in bold if found.

C:\WINDOWS\SYSTEM\Tools\Restart.exe

Now while still in Safemode…lets clean out all your temp files.



This process will clean out your TEMP FILES and your TEMPORARY INTERNET FILES. Please do both steps:

Step 1 - DELETE TEMP FILES

* This procedure should be run from SAFEMODE for better results.

* click on START/ RUN and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. You should do this for each user on your system. Please delete all
files that are found there. If you get an error when deleting a file, skip that file and delete all the others.

* Do this same process for %windir%\temp.

NOW RE-BOOT NORMALLY

Step 2 - DELETE TEMPORARY INTERNET FILES

* Now I want you to open up INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB, (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
When it is done, your Temporary Internet Files will now be deleted.


Now download and run CCleaner It is a safe program to use but I have to warn you that it will also delete your cookies, so when you run the program, before you scan, go to Options> Cookies and your cookies will load in the left window, just move the ones you want to keep to the right window.
http://www.ccleaner.com/

When your done, post a new log please.
Good day ken545,

Thanks again for your help.

Firstly, on your questions:

1) Are you famliar with this program? I can't find to much info about it.
C:\Program Files\ANI\ANIWZCS2 Service

wgan: The two programs, ANIWZCS2 and ANIO, found in the ANI folder are programs from Alpha Networks Inc., a Taiwanese company that develops and manufactures networking products. These two programs are used in the D-Link Wireless Broadband USB adaptor that I am using. What is curious is that these two programs are also found in the D-Link folder - C:\Program Files\D-Link\AirPlus G (AirPlus G is the model of the product I am using). Why would it have a separate folder created in the Programs directory for two programs that are already installed in the D-Link folder?


2) Are you familiar with this site? - Value Club. Challenger.com

wgan: Yes, I am familiar with this site, and have recently accessed it.


3) Is this your ISP? - Asia Pacific Network

wgan: No. My ISP is SingNet. Did you find anything from my HJT log that might suggest that my ISP is Asia Pacific Network? In fact, I have never heard of this ISP!

+++

I have followed the rest of your instruction:

1) entered Safe Mode and deleted this file - C:\WINDOWS\SYSTEM\Tools\Restart.exe.

2) from the Start/RUN function, cleared the Temp folders (%temp% and %windir%\temp) from the two admin accounts I have in my system that is listed under Safe Mode. Other user accounts of my system is not listed under Safe Mode, and therefore not able for me to access to delete the temp files using your suggested method. Tried searching for the Local\Temp folders in each of the users accounts, but cannot find such a folder.

3) Re-booted system after clearing the Temp folders.

4) Deleted IE temp files in accordance to your instruction.

5) Ran CCleaner and cleared all files that was listed after analysis under the Windows tab.

6) Ran online scan by Bit Defender after all the above the done. I was not able to do it prior to the actions above because the Bit Defender website was not accessible earlier.

+++

My current HJT log is as follows:

Logfile of HijackThis v1.99.0
Scan saved at 11:59:19 PM, on 23-Jun-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\MSOffice\Office\Msoffice.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\HijackThis\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114165901675
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk Dwf Viewer Control) - http://www.autodesk.com/global/dwfviewer/i…ViewerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194
O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

Many thanks.
wgan
Hello Again wgan, :D I am looking over your log and will be back early this evening. I just need to find info on this line. Don't do anything with it. You may want to call your ISP and ask them if they get there IP Addresses from them. It is pointing to the Asia Pacific Network which seems to be a company that assignes addresses. But lets make sure it is ok before we do anything. O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194 Outside of this, your log looks pretty clean. Are you still having that problem with it restarting?? Most times when that happens, it could be a power supply going bad.
Hello ken545, Thanks again for your help on my problem. I will check with my ISP about Asia Pacific Network and the two IP addresses. From that item - HKLM\System\CCS\Services\Tcpip\..\{3CF22887-B58B-4749-B3FD-C26B3C44776B}: NameServer = 192.168.10.220,203.127.219.194 - are you able to tell the function of this particular file? Is it a program? If so, is it possible to tell, roughly, what its supposed function? My PC is working fine now. Thank you for following on this matter. No further recurrence of that automatic restarting problem since I reported it here. Seems unlikely a power supply issue here. My PC is located in a residential area where power supply is stable, and I have not encountered such problems in Singapore before, even in an industrial area where heavy machineries are used. Also, my PC power unit is new, just about 12 months old, and it has not displayed any problems apart from that auto restart problem. The auto restart problem occurred, at that time of the problem, only when I clicked to launch a program. The booting of personal settings from the Windows XP main screen is also somewhat a little faster now, even with SpywareGuard and SpywareBlaster re-installed. I have disabled all automatic updates of programs though. There is one problem, though, that I forgot to mention earlier. Last month, on two occassions, different days though, when I clicked to shut down my computer, a dialog box popped-up to ask me if I really wanted to shut down the computer as another 'user' is still logged on! Nobody else used the computer. When I clicked on to continue the shut down, the computer seemed to go through the usual shutting down process. However, after my terminal, a 17" CRT, shut down, I noticed the CPU was still running as the processing lights was still flickering. I waited a while until I felt it was much too long from the norm for the computer to shut down that I had to press the power button to shut it down. Apart from that two occassions, this problem did not recur. Thanks again. Cheers wgan
wgan, I haven't forgotten about you, I just want more info on that line. I don't want to turn you loose until I am sure it is ok. Ken
Hi Ken, I have checked with my ISP, SingNet, they have not heard of Asia Pacific Network. My attempt to connect to those two IP addresses were not successful. I tried several times. But, each time ended with operation time out. However, I tried search on Asia Pacific Network. The website listed with that name is that of a news organisation based in New Zealand and Fiji. For all the international news, business, and financial websites that I connect to, I do not see or recall these websites having any link to a Asia Pacific Network. If anything, a third party cookie would be the most that could be found in my system. In any case, I have my browser privacy settings block all third party cookies. So, this, indeed, is a rather suspicious item. cheers wgan
wgan,

Outside of that entry, your system is clean. Lets do this, just leave that entry alone and use your computer for a few days and see if anything out of the ordinary comes up.

I would diffenitlly contact your ISP and inquire about it. I would be interested in there reply.


There is one problem, though, that I forgot to mention earlier. Last month, on two occassions, different days though, when I clicked to shut down my computer, a dialog box popped-up to ask me if I really wanted to shut down the computer as another 'user' is still logged on! Nobody else used the computer. When I clicked on to continue the shut down, the computer seemed to go through the usual shutting down process. However, after my terminal, a 17" CRT, shut down, I noticed the CPU was still running as the processing lights was still flickering. I waited a while until I felt it was much too long from the norm for the computer to shut down that I had to press the power button to shut it down.


Computers are a strange device, sometimes you will hit a day and have problems you never had before and the next day there gone. Just keep and eye on it and let me know if it keeps on happening. I can direct you to some excellent windows tech support sites that specializes in that sort of thing.

Why don't you post back in a few days and let me know how your doing.
Hi Ken, I will act on your suggestion and revert in a few days time. Have a jolly good weekend and catch up with you next week. Many thanks again. Kind regards, wgan
wgan,

Glad I could help. Here are some programs and tips for cleaning your system and keeping it clean in the futrue. Some of these you may have allready so just ignore the ones you have.

Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.
clean out your TEMP FILES

* This procedure should be run from SAFEMODE for better results.

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD


Now, while in SAFEMODE,

* click on START/ RUN , and type %temp% and press the ok button.

This will open up the temp directory that your machine uses. GO TO EDIT/ SELECT ALL and delete all the contents of that folder.
* Do this for each user of your computer.
* Do this same process for %windir%\temp.

NOW RE-BOOT NORMALLY

DELETE TEMPORARY INTERNET FILES

* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB, (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.


Now we need to TURN OFF and then TURN BACK ON SYSTEM RESTORE.

This will remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent
any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points
which are likely to be infected)



Turn off System Restore.

* On the Desktop, right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore.
* Click Apply, and then click OK.



Reboot your System


Turn ON System Restore.

* On the Desktop, right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* UN-Check Turn off System Restore.
* Click Apply, and then click OK.

* Now while in System Restore, create a new Restore Point.

* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.
* If you want to use a free program, try this one –> http://free.grisoft.com/doc/1

* Run SPYBOT SEARCH AND DESTROY/ CHECK FOR UPDATES/ IMMUNIZE and run a full system scan on a regular basis.

* Run AD-AWARE SE PERSONAL/ CHECK FOR UPDATES and run a FULL SYSTEM SCAN on a regular basis.

* Download and run SPYWARE BLASTER,
http://www.javacoolsoftware.com/
* Check for updates and enable all protection. This program will just sit in the background and help keep all the bad guys out.


* Download and install WINPATROL
http://www.winpatrol.com/download.html
* This program will warn you when any changes are being made to your system and give you the option to deny the change.


* IE-SPYAD is a one time install, it will put 1000s of bad sites in your IE Restricted Zone.
http://www.pcworld.com/downloads/file_down…23332&fileidx;=1



* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER/ GO TO PROPERTIES/ AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.


* Consider surfing the net with the FireFox Browser You can download via my signature.It has more features and is a lot
more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you
use this for awhile, you will want to make it your default.


* There companion THUNDERBIRD MAIL program was highly favored in PCWorld Magazine,, this to has a good spam filter
and is more secure than Outlook Express.

http://www.mozilla.org/products/thunderbird/

I will keep this thread open for you for a few days, I would like to hear from you as to the status of your system.

Ken :D
Hi there Ken, Thank you for your advice. I have acted according to your instructions: 1) Deleted all files in Temp folders using Start/Run: %temp% and %windir%\temp. Under this instruction to clear Temp folders, you instructed to do this process for all users. However, under Safe Mode in my PC, only the default Administrator account (in Safe Mode only) and the Computer Admin account (created by me to administer accounts under normal Windows environment) is accessible. Please advise how I am able to clear the Temp folders in each of the other user accounts? There is my own user account and another, that of my wife's. 2) I have turned-off System Restore, re-booted my PC, then re-started System Restore, and finally created a new Restore Point. 3) I use Trend Micro PC-cillin Internet Security 2005, and I scan my PC almost every alternate day. 4) I have ran SPYBOT SEARCH AND DESTROY/ CHECKed FOR UPDATES/ and IMMUNIZEd. 5) I have ran a full system scan by AD-AWARE SE PERSONAL/ and CHECKed FOR UPDATES. I run both Spybot and Ad-Aware almost every other day. 6) SpywareBlaster was downloaded previously, together with SpywareGuard. 7) I have installed WinPatrol. 8) I have downloaded IE-SPYAD. 9) I have set Windows Update to "DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM". 10) I am currently using Mozilla Firefox as my default browser. +++ Finally, on your last instruction, I shall report status of my PC to you in a few days time. Once again, many thanks. :thumbup: Kind regards, wgan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI