This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer keeps restarting

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer keeps restarting. It give a message that RPC has been activated and then shuts down in 60 sec. I looked it up on the web and found that the computer is infected by a worm I cannot go on the compter much less use the internet (I am at the library doing this). I tried getting the RPC not to take any actions by going to Services/ Recovery tab but the recovery tab is not there. It does not show in the safe mode either. Do you have any advise on how to fix this, and how to get rid of the worm? I have to check back later for your response as my time is running out. Thanks for any help.
Hello and :welcome:

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


You will need to right click and choose "Run as Administrator" to run the tools we will use.


Important: Disconnect the infected pc from any network as it may infect the other computers connected to it.

Does it also shut down your pc when you're in safe mode? Also, do you have your Windows installer cd with you? We might be needing it.

Let's do some scans, try this in normal mode, if it still shuts down then try it in safe mode.

Go to a known clean pc then do the following as we may be transfering files from the infected pc to another, take note to insert your USB flash drive (if any) that you are going to use:

Download Flash_Disinfector.exe by sUBs from HERE and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

–Next–

Download the following (DDS & GMER) from the clean pc then burn it to a cd/dvd or copy it into your flash drive then have it run on the infected pc:

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on to insert the attachment into your post
Please post both DDS logs in your next reply.

–Next–

[external image: Posted Image]
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply:
1. DDS logs.
2. GMER log.
Since I cannot work in the regular mode of my computer, will all of this work in the SAFE MODE? The computer does not shut down when operating in the SAFE MODE. I will down load the two programs and save them on a USB drive.
I down loaded and copied the DDS.scr and GWEN programs to a UBS flash drive, but I am not able to put them on the infected computer. The regular mode does not allow me to because it keeps shutting down. The safe mode, which works, is not allowing me to put the programs on the comput either. Can I run these programs directly from the flash drive?
Hi, What does it say when you try to copy and paste the tools to your desktop? You've said that there is about 60 sec before your pc restarts in normal mode. Let's try to use that window. Plug your USB device to the infected machine then start your pc. Once there, try to copy and paste the tools to your desktop then restart your pc in safe mode. Next, run the tools in safe mode. If that won't work then try running it in your flash drive.
Hi Inzanity,

I tried copying the two programs to the infected computer during the one minute window, but it does not work. And, the DDS program ran in safe mode, but really quick, like seconds, and did not produce a report. I did not try GMER.

The message that I get when I open in regular operating mode is as follow:

SYSTEN SHUT DOWN
This system is shutting down. Please save all work in progress and log off. Any on saved changes will be lost. This shutdown was initiated by NT Authority/system.

Message: Window must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly.


I tried to stop the RPC from taking any action by doing the following: Right click on MY Computer – select Manager – double click on Services and Applications –select Services — scroll down to first RPC in the Standard tab and right click on on it —- select Properties.

When I select properties nothing happens. It is as if that part of the program is not there. So I am not able to stop the RPC from taking action.
Hi,

This one's really putting up a fight. Let's do this:

Start you computer in normal mode.

Click on Start -> Run then copy paste the text below into the run box then press the Enter key or click OK. Do not copy the word CODE

shutdown -a


That will help prevent your pc from restarting.

After you're finished with the above, try running DDS and GMER again please. Thanks.
Hi, I did as you requested and "shutdown -a" did cause the shut down to be delayed, but not stopped. I had enough time to try using the DDS and GMER but I could not copy them to the C DRIVE. I still cannot go on the internet so I can't down load them. I tried running them from the USB flash drive and they ran, but none of them produced a report. This is tough. I am wondering if the computer is shot!
Hi,

What does it say when you try to copy it in the infected pc? It should be copied into your desktop.

Let's try this:

Restart your pc in Normal Mode.

–Next–

Please do the following:
  • Click on Start then Run.
  • Copy and paste the following command (except the word "Quote:") into the run box and click OK.

    shutdown -a


–Next–
  • Click on Start then Run.
  • Copy and paste the following command (except the word "Quote:") into the run box and click OK.

    regedit /e "%USERPROFILE%\Desktop\RegLook.txt" "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"

  • A text file named RegLook.txt will be created on your desktop.
–Next–

Download the following tool from a clean pc then copy it to your flash drive:

Download OTL.

Restart your pc in Safe Mode then
  • Copy and paste OTL.exe to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
–Next–

Try running GMER in safe mode please.

To post in your next reply:
1. RegLook.txt
2. OTL logs.
3. GMER log.
In answer to your question about what message i get when I try to copy: I do not get any messages.

Since I cannot copy anything to the computer i had to type in the second QUOTE. I got an error message, which states:
Cannot export USERPROFILE%Desktop\RegLook.txt. Error opening the file. There maybe a disk or file system error.
Because of this I could go any further with the process.
Hi, I tried copying OTL.exe on to my computer, in safe mode, but it did not work. I also tried running it from the flash drive, but that did not work either. I got this message D:\OTL.exe is not a valid Win32 application. Well I got a tad fed upwith the silly old computer (it is old, from 2002) and reinstalled the XP program, and is now able to run most programs from the normal mode without it being shut down. I am also able to get on the internet, but so far that is limited. I cannot access other website from the address prompt, but I can get to them by doing a search in Bing. I think that there are viruses on the computer. I think, too, that I have broken the rule thread rules. If the thread is still valid, what can I do now to check for and fix what ever virus in on my computer? Thanks.
Hi, It's ok if you've re-installed but did you do a reformat then re-install or just repair install? Run an OTL and GMER scan with your pc please. Thanks.
Hi,

I did not reformat the disk, I did a repair. The computer is running OK now. McAfee scan showed that there is an Adware-Gain on the computer which it can only partially get rid of. Also when I boot up, Windows Installer is trying to install. I stop it by pressing ctrl+alt+delete. Microsoft then wants to send the error message that Windows Installer was stop while installing OCR AWare [32-bit].

I tried running the OTL program but it did not work. I tried it in safe mode and got same error message as stated in my last post. Couldn't I just run DDS along with GMER?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI