Link to home
Start Free TrialLog in
Avatar of sbornstein2
sbornstein2

asked on

Need Help!. Shutdown.exe under System32 keeps shutting down PC

Hello all.  Ok I had to delete this stupid program on my PC that was causing my PC to shutdown.  I think it was a virus.  So I cleaned up a bunch of things and deleted what I found to tbe the registry keys etc.  Last night what I did was after deleting things I restored the shutdown.exe in my System32 directory.  What was happening today was everytime the PC would load up Windows even in safe mode it was turning my PC off everytime.  So what I did was went into Command Prompt Safe Mode and deleted the Shutdown.exe again.  What I need to find is what the heck is calling that Shutdown.exe even when I am going to safe mode.  Right now it is completly deleted off my PC I should have just renamed it.  Does the Shutdown.exe suppose to be in the System32 directory?  Any idea where I can find what on Windows Startup is calling that?  Thanks all
Avatar of Rob Williams
Rob Williams
Flag of Canada image

Yes Shutdown.exe is usually in the system32 directory.
Are you sure this is the application that is shutting down the computer. The Sasser worm will generate a message to do with LSASS and that the machine will shutdown in X seconds. If this is the case see the following link for details and a removal tool. Also when complete install all Windows updates to eliminate future problems.
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html
Avatar of sbornstein2
sbornstein2

ASKER

no you are correct it is not.  I just had it happen again so its not the Shutdown.exe.  Next time I restared. Also what I did yesterday was run regclean tool.  What I just had to do again was go to safe mode and ran the undo reg clean file I had.  Went in regular again and got in again.  Not sure if that is going to fix it or next time again I have to first go in to Safe Mode with Command Prompt then in again.  Any idea what I can look for? , I dont think its that worm.  Is there some file I can look at that shows the steps it runs on windowsstartup?
Make sure it is not the worm. There are numerous versions of it and it is a VERY common problem. Wouldn't hurt to run the tool.

As for inspecting services at boot time, normally you might use MSConfig, but it is not installed on Windows 2000.
However, you can use the XP version (as per http://www.jsifaq.com/subI/tip4200/rh4221.htm ) With that you could disable as many services or applications as possible from starting at boot. See if the problem disappears, and if so start re-enabling until you find the culprit.
Im running that now.  Any idea where I can get that shutdown.exe now because I deleted it from the command prompt.  
Also starting to back up all my files to CD while at least I am getting on at this time.
Any idea what cvpd.exe is?
I actually have the msconfig I installed something a while ago so I remembered I could get that up from this PC.  So I see something called cvpd.exe that I deleted from system32.  I think its also one of the virus exes that was actually recreating another exe each time if one did not exist that it found.
sasser worm not found so thats good.
Just did the shutdown again and it went to screen It is safe to turn off your computer again.  Then first time to command prompt it came up so I thought I was totally screwed.  Then this time for some reason it took and got past the starting windows and I am on again.  
ASKER CERTIFIED SOLUTION
Avatar of Rob Williams
Rob Williams
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks sbornstein2 ,
--Rob