I need help!
My PC Keeps restarting, and the only way I can do anything is in safe mode with networking.
When I try to start it normally, it keeps giving me a restart prompt with a countdown that lasts about 30 seconds.
Then it restarts and does the whole thing all over again.
I had to run HJT in safemode since I can't get the PC to start normally, but here's the log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:21:34 PM, on 11/15/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Running processes:
C:\WINNT\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - c:\winnt\system32\lodctr.dll
O2 - BHO: (no name) - {46600D6A-7867-4C1B-8B35-DBBC7DD2AABF} - C:\Program Files\WindowsUpdate\mezoheq83122.dll
O2 - BHO: (no name) - {5DC2F8EB-4E52-4B47-BADA-2B40CAB4EEA6} - C:\Program Files\WindowsUpdate\mezoheq4444.dll
O2 - BHO: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbHostIE.dll
O2 - BHO: {e6b6070d-a38d-a45b-53e4-66dd0931a057} - {750a1390-dd66-4e35-b54a-d83ad0706b6e} - C:\WINNT\system32\ocflloqm.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINNT\system32\fzssfuyz.dll
O2 - BHO: C:\WINNT\system32\jkd845jg.dll - {B5AC49A2-94F3-42BD-F434-2604812C897D} - C:\WINNT\system32\jkd845jg.dll
O2 - BHO: (no name) - {B5ECE52D-B89C-4E34-B4BD-6FAF3D3D2BD5} - C:\DOCUME~1\MDS07\LOCALS~1\Temp\jkkkk.dll
O2 - BHO: (no name) - {bcfa78d8-f7a8-4f38-a68f-bbc51243b5b8} - C:\WINNT\system32\amjcmvk.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\E404 Helper\e404.v5.dll
O2 - BHO: 0 - {FCEFB565-7CA7-4E89-E9A3-E01DC2C21FD5} - C:\Program Files\Accessories\qulaburuh455.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbHostIE.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [lcfep] "C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe" -x
O4 - HKLM\..\Run: [runner1] C:\WINNT\mrofinu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9
B1894E754BE546321EF81683BADC7E4F67D83F516CAC59B6
O4 - HKLM\..\Run: [avp] C:\WINNT\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [Printer] C:\WINNT\system32\printer.exe
O4 - HKLM\..\Run: [ms] C:\DOCUME~1\MDS07\LOCALS~1\Temp\8828\gm.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\DOCUME~1\MDS07\LOCALS~1\Temp\__c00A1964.dat",realset
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\DOCUME~1\MDS07\LOCALS~1\Temp\jkkkk.dll,c
O4 - HKCU\..\Run: [Spoolsv] C:\WINNT\system32\spoolvs.exe
O4 - HKCU\..\Run: [Taoe] "C:\PROGRA~1\MCROSO~1.NET\tracert.exe" -vt yazb
O4 - HKCU\..\Run: [userinit] C:\Documents and Settings\MDS07\Application Data\ntos.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [__c00DDD1B] rundll32.exe "C:\DOCUME~1\MDS07\LOCALS~1\Temp\__c00DDD1B.dat",B
O4 - HKCU\..\Run: [A00F52BC60.exe] C:\DOCUME~1\MDS07\LOCALS~1\Temp\_A00F52BC60.exe
O4 - HKCU\..\Run: [NI.UGA6P_0001_N122M2210] "C:\DOCUME~1\MDS07\LOCALS~1\Temp\gitobxmn.exe"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: findfast.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: autorun.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: Yahoo! Spades - http://download2.games.yahoo.com/games/clients/y/st3_x.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1180820018181
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins...ckerutility.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mds.mdsinc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mds.mdsinc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mds.mdsinc.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = mds.mdsinc.com
O21 - SSODL: DCOM Server 25319 - {2C1CD3D7-86AC-4068-93BC-A02304B25319} - C:\WINNT\system32\eiumfji.dll
O22 - SharedTaskScheduler: DCOM Server 25319 - {2C1CD3D7-86AC-4068-93BC-A02304B25319} - C:\WINNT\system32\eiumfji.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Aelita DMW Migration Agent (Vmover.exe) - Aelita Software Corporation - C:\WINNT\System32\Vmover.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Accessories\rterteproleg.html
--
End of file - 6664 bytes
How much of a mess is this!?
