Computing.Net > Forums > Security and Virus > Am I crazy or hacked/virus/mystery?

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Am I crazy or hacked/virus/mystery?

Reply to Message Icon

Original Message
Name: Tarra
Date: February 12, 2003 at 09:45:57 Pacific
Subject: Am I crazy or hacked/virus/mystery?
OS: win xp Home 2000+
CPU/Ram: 480 MB- used to be 512??
Comment:

A while back, the PC began freezing and suddenly shutting down. I ran virus scans and at that time, they would show as a clean pc. (also getting ntdll.dll and rundll32.dll errors) Everything I do is saving as an html. If I work on a notepad text document, it creates a copy in a temp folder as an internet shortcut. If I just read something, it still saves into temp as html.

As the problem has been so bad lately, I decided to restore with my emachine restore cd. (did nothing to help)

I then ran more virus scans, but this time, they would shut down or shut down the PC before completion. I again ran restore and even did the load default bios.

That is not the strange problem. The strange problem is that each time I ran restore, the hard drive would seem to get smaller and smaller and now my ram(512 to 480 mb??) is showing less amounts. I used to have 80 gig, now with a newly restored pc and nothing more then windows and the programs emachine restore disk has I have 72ish gigs.

Now for the other weird things! I am on an adsl router (linksys)Originally the 4 computers hooked into the router and were not sharing ANYTHING (not networked). Now, we are suddenly on a shared connection and must use some networking workgroup to connect.

I also notice that if I am running something such as virus scan it shows me using 100% cpu in taskmgr. I can not close some services, if I do, I get an error saying NT AUTHORITY \SYSTEM- RPC service terminated.

When I do control alt delete, and look at processes on taskmgr I see the following items that I can not shut down, it says "Critical System Processes" Csrss.exe, winlogon.exe,smss.exe, svchost.exe and a few other ones.

When I go into services via control panel, some programs which I should be able to close will not allow me too. Either they switch back on or else they do not have a "click-able" button/drop down. A few that I remember are "telephony", "network location awareness", and "Protector Plus Service (UnRegistered)", and "TCP/IP Netbios Helper".

I am sorry this is such a long post, but I am really needing some answers. Again, we were not and did not set up a network, but somehow we now on one and we can not change it or else we lose connection to internet or pc's shutdown.

Also, the winlogon.exe that runs in "high priority", has 107,000+ page faults and 72,756,437 I/O write bytes..do not know why I am adding this in, but it seems very high numbers and caught my eye. again, it will shut my pc off if I close this winlogon.exe saying it is critical to system and nt authority/system is closing windows, rpc service terminated.

Thank you for any help or ideas you may have.


Report Offensive Message For Removal


Response Number 1
Name: hylian_lynk
Date: February 12, 2003 at 11:58:51 Pacific
Reply: (edit)

Possible ..
1)Trojan or Virus on pc ... some viruses cause your pc to report incorrect pc info.
2) Bad drivers ... xp can go really screwy if it doesn't like your drivers.
3) BIOS can cause memory errors
4) Windows Corruption ... ntdll is a boot file .... if drivers unload from your memory like this NT AUTHORITY \SYSTEM- RPC service terminated. Then your pc will not function properly ... NT authority will restart your pc.
Other than that ... system restore does a lot more at screwing up your pc, rtaher than helping it ..i would use that as last resort. Chances are after using it, you having missing windows files ... it did that to me a while back after the SP1 screwed up my laptop. You may want to try a clean install of XP to save headaches as last resort


Report Offensive Follow Up For Removal

Response Number 2
Name: Random
Date: February 12, 2003 at 12:42:09 Pacific
Reply: (edit)

I really have little input here except that one thing caught my eye:
RunDLL32.dll is not a Windows file.
RunDLL32.exe IS.

Check out W32.Netspree.Worm -- it creates the .dll file.

If it's actually RunDLL32.exe, ignore my post completely.


Report Offensive Follow Up For Removal

Response Number 3
Name: danny ramsey
Date: February 12, 2003 at 21:18:44 Pacific
Reply: (edit)

WOW lot of info beyond me however resend your book report to iwilsker@ih2000.net if anybody can give you a clue he can and will.you can find a lot of tips on his web site www.mycomputershow.com


Report Offensive Follow Up For Removal

Response Number 4
Name: Tux
Date: February 15, 2003 at 08:35:17 Pacific
Reply: (edit)

Ok, here's how you fix it:
1)Wipe your hard disk.
2)Fresh install a REAL operating system.


Report Offensive Follow Up For Removal

Response Number 5
Name: MAD
Date: February 21, 2003 at 16:32:24 Pacific
Reply: (edit)

Have you checked for hardware fualts ?

Try new stick of ram and see if it reports the rigth size .......

Doggy ram would mess up your restore ,

Just a thought!


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software