Forum Home
Press F1
 
Thread ID: 82400 2007-08-26 04:11:00 Auto-restart Problem alvintwj (12725) Press F1
Post ID Timestamp Content User
584745 2007-08-26 04:11:00 My PC keeps on auto restarting itself. About 3 times per hours.
Didn't know what is the problem.

Always that BSOD pops up and show the name of this file: sysnic.sys

And hijackthis logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:42 AM, on 8/26/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
c:\windows\system32\msvcrtd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\crss5.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Steam\Steam.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: 0 - {F900399C-5DCF-4F8A-A4B7-9EC07BFEC303} - C:\Program Files\Windows Media Player\qugava.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [meceryko] C:\Program Files\MSN Gaming Zone\meceryko22011.exe
O4 - HKLM\..\Run: [subdhsu] netqunxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SvcManager] crss5.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [subdhsu] netqunxx.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

--
End of file - 3066 bytes

What should I do?
alvintwj (12725)
584746 2007-08-26 04:41:00 Start with this:

O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc . dll

It's a black hat . . . and you've got an old version of IE . . yours is v6 and they are up to v7 by now I think . . . .

I've had personal problems with this one:

O4 - HKLM\ . . \Run: [meceryko] C:\Program Files\MSN Gaming Zone\meceryko22011 . exe

Kill this one . . it's broken:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

I am suspicious of this . . it could also be a trojan too:

O4 - HKLM\ . . \Run: [SvcManager] crss5 . exe
SurferJoe46 (51)
584747 2007-08-26 04:47:00 Go to this site for more information on your HijackThis log.

http://www.hijackthis.de/

Paste your log in there and it will analyse it for you. Good luck :)
gellehar (12720)
584748 2007-08-26 05:03:00 Thanks guys. alvintwj (12725)
584749 2007-08-26 05:09:00 Yup tick these entries tick fix checked, close browser/s.

I would turn system restore off.

c:\windows\system32\crss5.exe - delete this file in safe mode.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [meceryko] C:\Program Files\MSN Gaming Zone\meceryko22011.exe

O4 - HKLM\..\Run: [subdhsu] netqunxx.exe - delete this file in safe mode

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [SvcManager] crss5.exe

O4 - HKCU\..\Run: [subdhsu] netqunxx.exe

O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll - delete this file in safe mode as well.

O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe - delete this file in safe mode.

I would also get trojan remover in my sig, if u can. Install update it then click on scan.

And select all options under the utilities menu.
Speedy Gonzales (78)
584750 2007-08-26 05:09:00 Always that BSOD pops up and show the name of this file: sysnic.syssisnic.sys is a SiS PCI Fast Ethernet Adapter Driver. Have you recently reinstalled your motherboard drivers, or even restored/repaired the operating system? Jen (38)
1