View Full Version : Random reboot of computer.
Aatraiu
23-08-2003, 03:17 PM
no idea what the hell is cusing this problem, probably related to my massive lag spikes, but as it stands i have used vet and norton and still come up with no viruses.
any help would be excellent
Bully
23-08-2003, 09:51 PM
UPDATED INFO -- Examining RPC/DCOM Compromised Computers
Many of the Windows computers that were missing the MS03-026 RPC/DCOM security patch may have been compromised. Symptoms might include random reboot, RPC failure, unusual sluggish performance and delayed bootup/shutdown.
There are a variety of Trojan programs that may have been installed on the compromised computer. A compromised computer should be removed from the network, inspected and restored. After backing up data, a full disk format and restore of the operating system is recommended. Some of the more common reported Trojan programs found on computers missing the MS03-026 patch include, but are not limited to:
Backdoor.IRC.Flood.F – Installation of a Trojan program for remote control of the compromised host. Reference information is here. See suggested Web site for a list of files often placed into local C:\Winnt\Inf folder.
BackDoor-AUI – Installation of a Trojan program for remote control of the compromised computer. Reference information is here. A compromise could be indicated by the presence of file “DIRECTX.EXE” in the local folder C:\WINNT\SYSTEM32. The Trojan could attempt to connect to an external IRC address via port 6667.
BackDoor.Hale – Installation of a Trojan program for remote control of the compromised computer, FTP services and other system utilities. Reference information is here. A compromise could be indicated by the presence of a folder “C:\winnt\system32\qossrv”. See suggested Web site for a list of files often placed into this folder.
Backdoor.WinShell.50 – Installation of a Trojan program permitting unauthorized access to the compromised computer. Reference information is here. A compromise is indicated by the presence of a new service with the characteristics of:
"Display Name"="CSRS Windows NT"
"Service Name"="CSRSWIN"
"Description"="CSRS Windows NT"
Backdoor.irc.cirebot.html - Installation of a Trojan program permitting unauthorized access to the compromised computer. Reference information is here. A compromised system is indicated by the presence of C:\Rpc.exe, C:\Rpctest.exe, or C:\Lolx.exe.
Aatraiu
24-08-2003, 05:37 PM
What would you do in my situation?
Bully
24-08-2003, 09:36 PM
There is realy only one thing you should do and format C
Palisade
24-08-2003, 10:10 PM
bl :(
Aatraiu
24-08-2003, 10:19 PM
nooooooooooooooooooooooooooooooooooooo :cry:
I think i wanna be sure before i go to drastic lengths. Is there any way i can be sure?
Bully
25-08-2003, 10:11 AM
It would be much quiker to delete and start again then chase the worms and virus's around your comp
Powered by vBulletin™ Version 4.0.6 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.