2000 Server Keeps Rebooting Every 45 Minutes

  1. #1
    edward935k3 is offline Newbie

    2000 Server Keeps Rebooting Every 45 Minutes

    RAN PANDA AND NORTON MULTIPLE TIMES. PANDA STILL SHOWS PSYME.GEN AND I CAN'T GET RID OF IT. AFTER APPROX 45 MINUTES, 2000 SERVER DISPLAYS A MESSAGE THAT NT SECURITY WILL SHUT DOWN.

    Logfile of HijackThis v1.99.1
    Scan saved at 2:52:50 PM, on 8/25/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\CatRoot\svchost.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINNT\system32\dhcpse.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\llssrv.exe
    C:\Program Files\LogMeIn\RaMaint.exe
    C:\Program Files\LogMeIn\LogMeIn.exe
    C:\WINNT\System32\tcpsvcs.exe
    C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINNT\system32\tlntsvr.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\Dfssvc.exe
    C:\WINNT\System32\inetsrv\inetinfo.exe
    C:\WINNT\System32\msdtc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\hkcmd.exe
    C:\WINNT\system32\igfxpers.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\LogMeIn\LogMeInSystray.exe
    C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackTh is.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Instatcom, Inc\SchedulePro\schedulePro.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINNT\system32\igfxsrvc.exe
    C:\WINNT\System32\mdm.exe
    C:\Program Files\LogMeIn\LogMeIn.exe

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [igfxtray] C:\WINNT\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINNT\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINNT\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1127765530046
    O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857E} (CWebLaunchCtl Object) - https://control.everdream.com/cf1liv...weblaunch2.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/actives.../asproinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3F4E2C73-0AB5-43E0-9124-15BA7DBA2371}: NameServer = 10.123.254.215,10.123.254.77
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AA0A3CC5-5446-4EC1-ACB0-B629FEDED99B}: NameServer = 198.6.1.125,198.6.1.150
    O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: (dhcpse) - Unknown owner - C:\WINNT\system32\dhcpse.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: WinGrd AVP System (WinGrd) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSInfo\kernel.exe (file missing)


  2. #2
    bergman is offline Newbie
    maybe try downloading AVG free and quarantining the file or see if it can fix it? otherwise if you know the file location, try running in safe mode and manually deleting the file. Try to keep in mind though that a system restore to a point earlier to the day you did it many times brings viruses back if its in the registry. so be sure to us regedit to make sure its not in the registry

+ Reply to Thread