Specialty Forums
Security and Virus
General Hardware
CPUs/Overclocking
Networking
Digital Photo/Video
Office Software
PC Gaming
Console Gaming
Programming
Database
Web Development
Digital Home

General Forums
Windows XP
Windows Vista
Windows 95/98
Windows Me
Windows NT
Windows 2000
Win Server 2008
Win Server 2003
Windows 3.1
Linux
PDAs
BeOS
Novell Netware
OpenVMS
Solaris
Disk Op. System
Unix
Mac
OS/2

Drivers
Driver Scan
Driver Forum

Software
Automatic Updates

BIOS Updates

My Computing.Net

Solution Center

Free IT eBook

Howtos

Site Search

Message Find

RSS Feeds

Install Guides

Data Recovery

About

Home
Reply to Message Icon Go to Main Page Icon

Subject: Is this a virus? instant shut off.

Original Message
Name: kylem4711
Date: October 28, 2007 at 23:59:02 Pacific
Subject: Is this a virus? instant shut off.
OS: xp
CPU/Ram: ?
Model/Manufacturer: ?
Comment:
My computer shuts off at random times.

no warning, it just turns off.

I believe this started happening after i installed a torrent of 1 click dvd, the thing is, i have installed the same program on my laptop and it works fine.

I have installed XP again, but have had no success.

I have also run some anti-virus programs, but they have not detected anything.

is this a hardware problem, or a virus?



Report Offensive Message For Removal

Response Number 1
Name: XpUser4Real
Date: October 29, 2007 at 09:44:24 Pacific
Subject: Is this a virus? instant shut off.
Reply: (edit)
first of all, if you have trouble listing your specs for your PC click on the red link and there is help for you. The specs come in handy when trying to find a solution.

>>I have installed XP again, but have had no success<<
1-Was that a fresh install or a repair installation?
2-Turn off automatically restart and then post the EXACT error message.

personally it sounds like an over-heating problem.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


Report Offensive Follow Up For Removal

Response Number 2
Name: kylem4711
Date: October 29, 2007 at 17:58:57 Pacific
Subject: Is this a virus? instant shut off.
Reply: (edit)
i got the information you requested.

the computer has,

AMD Athlon(tm) 64 x2 dual core processor 6000+ 3.01 ghz, 2gb of RAM.


also, i dont think its over-heating because there is a little lcd screen which indicated that it is at about 32 C for the CPU and 30 for hdd.


also, i am waiting for it to shut off so that i can read you the exact message.

thanks for the help

ohh, also i am running XP professional SP2


Report Offensive Follow Up For Removal

Response Number 3
Name: kylem4711
Date: October 29, 2007 at 19:51:23 Pacific
Subject: Is this a virus? instant shut off.
Reply: (edit)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:48 PM, on 10/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3405 bytes


ComboFix 07-10-29.1 - kyle 2007-10-29 19:43:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1600 [GMT -7:00]
Running from: C:\Documents and Settings\kyle\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\DriverPacks\D\D\M\3\2\2.exe
C:\WINDOWS\system32\nvrssk.dll
C:\WINDOWS\system32\nvrssl.dll

.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-30 )))))))))))))))))))))))))))))))
.

2007-10-29 19:43 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-29 19:41 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-29 19:40 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-10-29 19:40 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-10-29 19:40 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-10-27 20:04 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-24 16:37 100,736 --a------ C:\WINDOWS\system32\drivers\nvatabus.sys
2007-10-24 16:36 28,672 --a------ C:\WINDOWS\system32\setupold.exe
2007-10-24 16:36 23,040 --a------ C:\WINDOWS\system32\setup.exe
2007-10-24 16:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\setup.exe
2007-10-24 16:36 3,038 --a------ C:\WINDOWS\system32\presetup.cmd
2007-09-02 19:32 1,580,544 --a------ C:\WINDOWS\system32\sfcfiles.dll
2007-09-02 19:15 984,576 --a------ C:\WINDOWS\system32\syssetup.dll
2007-09-02 19:15 360,704 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-09-02 19:05 1,852,928 --a--c--- C:\WINDOWS\system32\dllcache\acgenral.dll
2007-09-02 19:05 450,048 --a--c--- C:\WINDOWS\system32\dllcache\aclayers.dll
2007-09-02 19:05 245,248 --a--c--- C:\WINDOWS\system32\dllcache\acspecfc.dll
2007-09-02 19:05 141,312 --a--c--- C:\WINDOWS\system32\dllcache\aclua.dll
2007-09-02 19:05 116,224 --a--c--- C:\WINDOWS\system32\dllcache\acxtrnal.dll
2007-09-02 19:05 100,352 --a--c--- C:\WINDOWS\system32\dllcache\6to4svc.dll
2007-09-02 19:05 100,352 --a------ C:\WINDOWS\system32\6to4svc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-30 02:39 --------- d-----w C:\Documents and Settings\kyle\Application Data\AVG7
2007-10-30 02:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-10-28 02:54 10,601 ----a-w C:\hwids.dat
2007-10-28 02:52 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-28 02:49 --------- d-----w C:\Program Files\PeerGuardian2
2007-10-28 02:49 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-28 02:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-28 02:48 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-10-28 02:48 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-10-28 02:48 --------- d-----w C:\Program Files\Yahoo!
2007-10-28 02:48 --------- d-----w C:\Program Files\Lavasoft
2007-10-28 02:48 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-10-28 02:48 --------- d-----w C:\Program Files\Foxit
2007-10-28 02:48 --------- d-----w C:\Program Files\CCleaner
2007-10-28 02:48 --------- d-----w C:\Program Files\7-Zip
2007-10-28 02:48 --------- d-----w C:\Documents and Settings\Default User\Application Data\AVG7
2007-10-28 02:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-28 02:46 --------- d-----w C:\Program Files\SpywareBlaster
2007-09-27 05:00 4,617,728 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-09-19 16:14 16,844,800 ----a-w C:\WINDOWS\RTHDCPL.EXE
2007-09-03 02:32 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2007-09-03 02:32 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys
2007-09-03 02:32 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2007-09-03 02:32 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2007-09-03 02:32 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
2007-09-03 02:32 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
2007-09-03 02:32 476,160 ----a-w C:\WINDOWS\system32\wzcsvc.dll
2007-09-03 02:32 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
2007-09-03 02:32 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
2007-09-03 02:32 42,496 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2007-09-03 02:32 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
2007-09-03 02:32 37,376 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
2007-09-03 02:32 36,992 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2007-09-03 02:32 36,480 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2007-09-03 02:32 35,456 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2007-09-03 02:32 35,328 ----a-w C:\WINDOWS\system32\pid.dll
2007-09-03 02:32 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2007-09-03 02:32 25,472 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2007-09-03 02:32 23,040 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2007-09-03 02:32 20,992 ----a-w C:\WINDOWS\system32\hid.dll
2007-09-03 02:32 2,017,280 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2007-09-03 02:32 17,408 ----a-w C:\WINDOWS\system32\msyuv.dll
2007-09-03 02:32 16,000 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys
2007-09-03 02:32 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys
2007-09-03 02:32 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
2007-09-03 02:32 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2007-09-03 02:32 12,416 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2007-09-03 02:29 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2007-09-03 02:29 8,192 ----a-w C:\WINDOWS\system32\tsbyuv.dll
2007-09-03 02:29 8,192 ----a-w C:\WINDOWS\system32\streamci.dll
2007-09-03 02:29 77,891 ----a-w C:\WINDOWS\system32\usrmlnka.exe
2007-09-03 02:29 77,890 ----a-w C:\WINDOWS\system32\usrdpa.dll
2007-09-03 02:29 77,883 ----a-w C:\WINDOWS\system32\usrrtosa.dll
2007-09-03 02:29 72,192 ----a-w C:\WINDOWS\system32\sprio800.dll
2007-09-03 02:29 70,656 ----a-w C:\WINDOWS\system32\sprio600.dll
2007-09-03 02:29 69,700 ----a-w C:\WINDOWS\system32\usrshuta.exe
2007-09-03 02:29 69,699 ----a-w C:\WINDOWS\system32\usrcoina.dll
2007-09-03 02:29 69,632 ----a-w C:\WINDOWS\system32\spnike.dll
2007-09-03 02:29 61,508 ----a-w C:\WINDOWS\system32\usrprbda.exe
2007-09-03 02:29 61,500 ----a-w C:\WINDOWS\system32\usrcntra.dll
2007-09-03 02:29 58,112 ----a-w C:\WINDOWS\system32\drivers\vdmindvd.sys
2007-09-03 02:29 55,296 ----a-w C:\WINDOWS\system32\dvdplay.exe
2007-09-03 02:29 53,305 ----a-w C:\WINDOWS\system32\usrlbva.dll
2007-09-03 02:29 51,712 ----a-w C:\WINDOWS\system32\drivers\tosdvd.sys
2007-09-03 02:29 49,211 ----a-w C:\WINDOWS\system32\usrvpa.dll
2007-09-03 02:29 49,211 ----a-w C:\WINDOWS\system32\usrsdpia.dll
2007-09-03 02:29 49,209 ----a-w C:\WINDOWS\system32\usrv80a.dll
2007-09-03 02:29 45,116 ----a-w C:\WINDOWS\system32\usrvoica.dll
2007-09-03 02:29 41,019 ----a-w C:\WINDOWS\system32\usrsvpia.dll
2007-09-03 02:29 323,641 ----a-w C:\WINDOWS\system32\usrdtea.dll
2007-09-03 02:29 3,200 ----a-w C:\WINDOWS\system32\wowfax.dll
2007-09-03 02:29 262,528 ----a-w C:\WINDOWS\system32\drivers\cinemst2.sys
2007-09-03 02:29 23,936 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys
2007-09-03 02:29 23,808 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys
2007-09-03 02:29 21,376 ----a-w C:\WINDOWS\system32\drivers\tsbvcap.sys
2007-09-03 02:29 18,688 ----a-w C:\WINDOWS\system32\drivers\cdaudio.sys
2007-09-03 02:29 157,696 ----a-w C:\WINDOWS\system32\paqsp.dll
2007-09-03 02:29 147,968 ----a-w C:\WINDOWS\system32\mdwmdmsp.dll
2007-09-03 02:29 13,824 ----a-w C:\WINDOWS\system32\wowfaxui.dll
2007-09-03 02:29 12,160 ----a-w C:\WINDOWS\system32\drivers\mouhid.sys
2007-09-03 02:29 12,160 ----a-w C:\WINDOWS\system32\drivers\fsvga.sys
2007-09-03 02:29 12,032 ----a-w C:\WINDOWS\system32\drivers\riodrv.sys
2007-09-03 02:29 12,032 ----a-w C:\WINDOWS\system32\drivers\rio8drv.sys
2007-09-03 02:29 12,032 ----a-w C:\WINDOWS\system32\drivers\nikedrv.sys
2007-09-03 02:29 11,776 ----a-w C:\WINDOWS\system32\drivers\cpqdap01.sys
2007-09-03 02:29 102,457 ----a-w C:\WINDOWS\system32\usrv42a.dll
2007-09-03 02:14 84,480 ----a-w C:\WINDOWS\system32\pintool.exe
2007-09-03 02:14 82,432 ----a-w C:\WINDOWS\system32\msxml4r.dll
2007-09-03 02:14 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2007-09-03 02:14 69,120 ----a-w C:\WINDOWS\system32\wlanapi.dll
2007-09-03 02:14 62,336 ----a-w C:\WINDOWS\system32\drivers\rspndr.sys
2007-09-03 02:14 531,568 ----a-w C:\WINDOWS\system32\RmActivate_isv.exe
2007-09-03 02:14 523,376 ----a-w C:\WINDOWS\system32\RmActivate.exe
2007-09-03 02:14 519,280 ----a-w C:\WINDOWS\system32\SecProc_isv.dll
2007-09-03 02:14 518,768 ----a-w C:\WINDOWS\system32\SecProc.dll
2007-09-03 02:14 36,352 ----a-w C:\WINDOWS\system32\tsgqec.dll
2007-09-03 02:14 358,000 ----a-w C:\WINDOWS\system32\RmActivate_ssp.exe
2007-09-03 02:14 354,416 ----a-w C:\WINDOWS\system32\RmActivate_ssp_isv.exe
2007-09-03 02:14 35,840 ----a-w C:\WINDOWS\system32\qfecheck.exe
2007-09-03 02:14 323,696 ----a-w C:\WINDOWS\system32\msdrm.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-07-13 00:34]
"nwiz"="nwiz.exe" [2007-07-13 00:34 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-07-13 00:34]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 09:14 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2007-08-03 04:22 C:\WINDOWS\SkyTel.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-29 19:41]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nltide_3"=rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"=1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"=1 (0x1)


.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-29 19:45:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-29 19:46:02 - machine was rebooted
.
--- E O F ---



Report Offensive Follow Up For Removal

Response Number 4
Name: kylem4711
Date: October 29, 2007 at 20:06:00 Pacific
Subject: Is this a virus? instant shut off.
Reply: (edit)
1. it was a fresh install
2. when i turned it back on, there was no error message, it just started up like normal.... :/

Report Offensive Follow Up For Removal



Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Is this a virus?  instant shut off.

Comments:

 
  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 


Data Recovery Software



Version Tracker Pro
Keep your software current and secure, effortlessly

Click Here for a Free Scan

Driver Agent
Automatically find the latest drivers for your computer.
Click Here for a Free Scan



The information on Computing.Net is the opinions of its users. Such opinions may not be accurate and they are to be used at your own risk. Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE

All content ©1996-2007 Computing.Net, LLC