after being on for 10-15 min comp shuts down and restarts

T

Trudy Sunday

While being on line for 15-20 min or so, i get a red and
grey box in the middle of my screen stating due to
windowxp error, comp will shut down and restart. I
believe the code it reads is psc or spc not quite sure
which one, but am tired of of it shutting down on me. Am
a student right now, and need the access to internet for
major midterm papers and essays. could someone please let
me know what i should do.
 
K

Karl Levinson [x y] mvp

Trudy Sunday said:
While being on line for 15-20 min or so, i get a red and
grey box in the middle of my screen stating due to
windowxp error, comp will shut down and restart. I
believe the code it reads is psc or spc not quite sure
which one, but am tired of of it shutting down on me. Am
a student right now, and need the access to internet for
major midterm papers and essays. could someone please let
me know what i should do.


Try this, it might apply to you:


I've seen a number of people ask this question today, so I hope this is
helpful to someone:

FYI, the presence of the files Dcomx.exe or the other files mentioned below
along with a "Remote Procedure Call" or TFTP popup message on your system
and/or system lockups or reboots are signs you may have been hacked by a
tool such as Autorooter. [TFTP.EXE is a normal file that comes with many
versions of Windows, but it should usually not be running on most systems.]

To fix this, you need a firewall [even a free one such as www.sygate.com or
www.kerio.com], to install all the latest Microsoft service packs and
patches from www.windowsupdate.com, check your firewall logs to see who has
hacked you, and install and run an antivirus with the latest updates that
detects this thing [ www.grisoft.com is free antivirus], or submit sample
files to your antivirus vendor if it does not detect this thing. I do
believe there may be new variants of Autorooter that possibly have not yet
been fully discovered. Unlike an automated event like a worm, this event
may indicate that someone personally ran a tool against you and may have
done things to your computer.

There are a number of posts mentioning a quick "registry fix" to close "port
135." This does very little to secure your computer, as it only closes one
of the 130,000 ports on your computer. Get a firewall first, even a free
one.

Also, note that the presence of new files such as TFTPxxxx or DCOMX.EXE etc.
means that just installing the latest Microsoft patches, editing the
registry, etc. may no longer be sufficient. Installing the Microsoft patch,
editing the registry, closing ports, disabling services, etc. do absolutely
nothing to block the back door that has probably now been installed, so that
your computer can still be compromised using other ports.

You can find out if you are infected with Autorooter or something new that
hasn't been discovered by going to one of the scanner sites below. If
nothing is detected, that's pretty interesting, let us and your antivirus
company know:

http://housecall.antivirus.com [my preference] OR
http://security2.norton.com


Once your computer has been hacked, these are some things I might recommend
doing are here:

http://securityadmin.info/faq.htm#hacked
http://securityadmin.info/faq.htm#re-secure
http://securityadmin.info/faq.htm#harden

This Trojan has been given several different names by various anti-virus
companies:

RPC Worm (F-Secure)
Downloader-DM (McAfee)
Autorooter (Panda)
Worm.Win32.Autorooter (AVP)
Backdoor.IRC.Cirebot (Symantec)

References:

http://www.europe.f-secure.com/v-descs/rpc.shtml
http://vil.nai.com/vil/content/v_100524.htm
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.cirebot
..html
http://news.com.com/2100-1009-5059263.html
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp
http://www.microsoft.com/security/security_bulletins/MS03-026.asp
http://support.microsoft.com/?kbid=823980


Here are some signs of infection, though these do not necessarily match all
the variants that might be out there:

"Signs of infection:
- the existence of one or more of the following files:
rpc.exe
rpctest.exe
tftpd.exe
dcomx.exe
lolx.exe
worm.exe

Signs that a network is being attacked:
- traffic on port 445 to sequential IP addresses.
Signs that an attack has succeeded (allowing a remote shell and downloading
of the backdoor):
- port 57005 open;
- an ftp [tftp] connection on port 69."

I hope this helps. Let us know if you find anything interesting. Thanks to
Susan Bradley for pointing this information out.
 
R

Ron Martell

Trudy Sunday said:
While being on line for 15-20 min or so, i get a red and
grey box in the middle of my screen stating due to
windowxp error, comp will shut down and restart. I
believe the code it reads is psc or spc not quite sure
which one, but am tired of of it shutting down on me. Am
a student right now, and need the access to internet for
major midterm papers and essays. could someone please let
me know what i should do.

After your computer has restarted, right-click on "My Computer" and
select Manage

Expand the Event Viewer category and browse though each of the 3
subcategories for a red-flagged error message whose date and time
coresponds to the restart.

Double click on an error record to see the details of that error.

Post the error information back here if you need further advice or
assistance.

Good luck


Ron Martell Duncan B.C. Canada
--
Microsoft MVP
On-Line Help Computer Service
http://onlinehelp.bc.ca

"The reason computer chips are so small is computers don't eat much."
 
J

Jamie

I now have this issue...... same as described with a message reading
Remote Procedure Call service terminated...
I operate windows XP Home edition..
The problem now is that my computer trys to reboot, gets to the
loading page, hits the power saving page and kciks back to reboot....
ANY suggestions would be GREAT!
 
Joined
Jul 3, 2005
Messages
1
Reaction score
0
My system reboots all the time

0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 65 78 70 6c 6f 72 explor
0018: 65 72 2e 65 78 65 20 36 er.exe 6
0020: 2e 30 2e 32 39 30 30 2e .0.2900.
0028: 32 31 38 30 20 69 6e 20 2180 in
0030: 68 75 6e 67 61 70 70 20 hungapp
0038: 30 2e 30 2e 30 2e 30 20 0.0.0.0
0040: 61 74 20 6f 66 66 73 65 at offse
0048: 74 20 30 30 30 30 30 30 t 000000
0050: 30 30 00


the above is one of the error logs I tried two different ram sticks and fans seem to be working and have checked for virus and spyware's. The system reboots and seems to do it mainly if I'm playing online internet game.

Any help would help. Windows XP 512 ram

here is another error right after the other one:

41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 64 72 77 ure drw
0018: 74 73 6e 33 32 2e 65 78 tsn32.ex
0020: 65 20 35 2e 31 2e 32 36 e 5.1.26
0028: 30 30 2e 30 20 69 6e 20 00.0 in
0030: 64 62 67 68 65 6c 70 2e dbghelp.
0038: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0040: 32 36 30 30 2e 32 31 38 2600.218
0048: 30 20 61 74 20 6f 66 66 0 at off
0050: 73 65 74 20 30 30 30 31 set 0001
0058: 32 39 35 64 295d



and a system error below

0000: 53 79 73 74 65 6d 20 45 System E
0008: 72 72 6f 72 20 20 45 72 rror Er
0010: 72 6f 72 20 63 6f 64 65 ror code
0018: 20 31 30 30 30 30 30 30 1000000
0020: 61 20 20 50 61 72 61 6d a Param
0028: 65 74 65 72 73 20 66 66 eters ff
0030: 66 65 38 30 38 30 2c 20 fe8080,
0038: 30 30 30 30 30 30 30 32 00000002
0040: 2c 20 30 30 30 30 30 30 , 000000
0048: 30 31 2c 20 38 30 36 65 01, 806e
0050: 65 32 64 63 e2dc
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top