Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows 7 unexpected shutdowns


  • This topic is locked This topic is locked
7 replies to this topic

#1 tinyfighters

tinyfighters

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:02:30 AM

Posted 04 March 2010 - 07:13 PM

Ok when I start windows normally and open up google chrome I get a BSOD. Then in safe mode I try to post a topic in bleepingcomputer.com forum and midway I get BSOD again. I think it is caused by a rootkit or something.
When I go to task manager (normal mode) most of the processes are hidden and there are some processes with no user name and/or description.

Image name ccsvchost.exe
User Name
Description Symantec... (forgot rest)

Image name csrss.exe
User Name
Description

Image name winlogon.exe
User Name
Description


Last time I got some malware on my computer and removed it I think it left behind a rootkit.
Malwarebytes' Anti-Malware Quarantine: (Haha malware)
Backdoor.Bot
Generic.Bot.H
Backdoor.Bot
Generic.Bot.H
Backdoor.Trace
Backdoor.Bot
Backdoor.Bot
Trojan.Agent
Trojan.Agent

Now time for the BSOD info:
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7600.2.0.0.256.1
Locale ID: 1033

Additional information about the problem:
BCCode: f4
BCP1: 00000003
BCP2: 84F99780
BCP3: 84F998EC
BCP4: 822337B0
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1

Files that help describe the problem:
C:\Windows\Minidump\030410-21375-01.dmp
C:\Users\Administrator\AppData\Local\temp\WER-46953-0.sysdata.xml

Also my sound is screwed up there is no sound.
:thumbsup:

Edit: Removed unnecessary poll from this topic. ~ Animal

Edited by Animal, 04 March 2010 - 10:26 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,221 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:30 AM

Posted 04 March 2010 - 09:27 PM

Hello there are a few issues here ...
First >> is I am mving this to the Am I Infected forum from W7.

Second >> about the Bots and backdoors found.
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.



Third>> your signture needs to be adjusted. Please read the BleepingComputer.com Message Board Rules. and fix it ,else it will be removed, thanks.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 tinyfighters

tinyfighters
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:02:30 AM

Posted 04 March 2010 - 09:56 PM

I never heard of backdoor trojans doing this weird stuff like stealing information so I'll just reinstall Windows and change my passwords in case that criminal guy steals my password.
:thumbsup:

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,221 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:30 AM

Posted 05 March 2010 - 11:14 AM

Rootkits, backdoor Trojans, Botnets, and IRC Bots are very dangerous because they compromise system integrity by making changes that allow your computer to be used by the attacker for malicious purposes.


NOTE: your signature still needs to be reduced to 5 lines,you are at 8.

Signatures are limited to 5 lines or 2000 characters; whichever comes first. If your signature is larger than the allotted size given or deemed unacceptable, you will be requested to adjust your signature. Failure to comply will result in the removal of your signature.


Edited by boopme, 05 March 2010 - 11:14 AM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 tinyfighters

tinyfighters
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:02:30 AM

Posted 05 March 2010 - 04:36 PM

I'm reinstalling windows and what do I do after I change my passwords?
:thumbsup:

Hours later: I finish reinstalling windows but the same processes are still there (except for the Symantec one) does this mean I'm still infected with the Backdoor thing?

Edited by tinyfighters, 05 March 2010 - 05:55 PM.


#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,221 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:30 AM

Posted 05 March 2010 - 09:21 PM

hello, Is your symantec fully updated?
The next two may be legitimate,depending on their path. But if you reformatted and instaled Windows 7 malware should be gone,except perhaps an mbr rootkit.

I would suggest then you post a DDS log.


You will need to Download and Run DDS which will create a Pseudo HJT Report as part of its log..
If for some reason you cannot perform a step, move on to the next.
Please follow this guide. go and do steps 6 thru 8 ,, Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help . Then go here Virus, Trojan, Spyware, and Malware Removal Logs ,click New Topic,give it a relevant Title and post that complete log.

Let me know if it went OK.

thanks for fixing the signature :thumbsup:

Edited by boopme, 05 March 2010 - 09:22 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 tinyfighters

tinyfighters
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:02:30 AM

Posted 05 March 2010 - 09:46 PM

Ok I made the logs and stuff I'm going to post a new topic.
:thumbsup:

Few minutes later: Posted topic come see click here

Edited by tinyfighters, 05 March 2010 - 09:54 PM.


#8 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,949 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:02:30 AM

Posted 05 March 2010 - 10:16 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/t/300638/rootkit-infection-dds-log-here/ you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users