Am I still attacked with keylogger + Windows 7 shutting down automatically...

nac

Aspiring Novelist
Out of doubt, I raised this query on other thread. This thread is continuation of that and issues (assuming) I am facing since then... :(

Hey, I have downloaded and installed keylogger sometime ago. But nobody asked me to do so. Just out of interest, I did. What does it mean? Could someone/body getting the information like my id, password and all...????
I don't know what is actual keylogger and what is not I thought this is what I was doing. I didn't know it would send the information online to someone. I came across that this tool would track every key stroke. Just out of curiosity, I tried that software. Even though I haven't used that software, it was there in my system installed for few months (may be an year). I don't remember the tool name. I googled and downloaded it from somewhere. I don't remember the site address.

By the way, it's not happening now. I did try this tool about 4 or 5 yrs ago. But still... I have been using the same email id and all...

Ever since I bought this computer, always there is antivirus updated and running.
^ I will do that...

BTW, The keylogger I tried was in different OS and the HDD was different. It's less likely to be in my system right now. But I will do as you suggested.
After discussing things with you guys about the keylogger, I didn't find any issues with the computer, yesterday. But now I am facing an issue - Windows rebooting itself.

I turned on my computer today, Adobe flash update window popped up and I clicked INSTALL. PC hanged and restarted automatically (I wasn't in front of the system when that happened). When rebooting windows shows the message that "the windows wasn't shutdown properly", I chose "Start windows normally". But the windows stayed blank for about 5-10 minutes. I manually rebooted (by pressing physical button in the CPU cabinet). Windows asked whether to launch repair or start normally. I clicked "Launch Repair". After 10 minutes, windows couldn't repair it and restarted. I went to Safe Mode and did system restore. Even after that the issue (system rebooting) is not gone. Till now system have rebooted about half a dozen times, once I noticed the blue screen (Windows have detected a problem and shuttingdown...) Before reading everything, system shutdown(ed?). Somewhere in the middle I read TCP.ip

Now I think, about 3-4 times system rebooted when I tried to access internet. But I am not sure whether that I am wildly assuming it after reading that "TCP.ip" or that's the fact.

I have downloaded and installed Malwarebyte to detect any trace of keylogger. It detected something called "Opencandy" in roaming folder and removed them. I guess it's nothing to do with keylogger.

Coming to my current problem, what could be the issue?
* Should I do memory test, HDD test?
* If there is any problem I am facing recently, that would be with my DVD drive. But it's been like that for quite sometime. Now I have removed it from the computer.
* PSU fan is up and running, so I don't think it's because of heat or something to do with power. (Few years ago, I had similar problem and had to replace PSU then).
* A new pen drive was used yesterday. (No, it's not connected now).

Is this problem something to do with the discussion I had yesterday :( (like someone playing or attacking) or it's just the coincidence and actually there is a problem in my computer?

- - - Updated - - -

I forgot to add this...
After seeing TCP.ip, I uninstalled LAN/ethernet drivers and restarted to let windows install the driver when loaded.

I think, since then I am not facing any issue (but I am not sure). I am online for more than one hour without getting rebooted.

When I tried to find crash dump, only one file exists in that folder. (I think that's the one when I saw the TCP.ip blue screen notice before windows shutdown)

- - - Updated - - -

In the last 45 minute system had shutdown thrice due to OS detected some error in tcpip.sys. After second time, I unplugged DVD drive connection. But still PC shutdown even after disconnecting dvd drive. I am trying to find the cause for this issue. I would really appreciate any help regarding this. :)

- - - Updated - - -

Today, so far system rebooted about 4 times.

I ran chkdsk, it ran for more than an hour. While it was running, sometime it stayed idle for long time. I thought it's frozen. But suddenly it started running. At the end of the process, it said "an unspecified error occurred" and alphanumeric code like thing.
And "Unable to set chkdsk ran once flag" and frozen for about 15 minutes before restarting just to continue the chkdsk process. I let it run, and it did run for another hour and frozen at the end. Again it said "an unspecified error occurred" but two errors this time. I waited for windows to reboot itself, but it didn't for more than 30 minutes and I lost my patience. So I manually rebooted, and tried to repair. But windows couldn't find a problem. Checked system restore, now it shows an older one which I didn't see it yesterday. Ran Windows memory diagnostic and I didn't see the result when I logged in after rebooting.

Now this issue is really annoying. I couldn't work.

Finally, I found the crash dump. Here is the last two...

A problem has been detected and Windows has been shut down to prevent damage
to your computer.

The problem seems to be caused by the following file: tcpip.sys

PAGE_FAULT_IN_NONPAGED_AREA

If this is the first time you've seen this stop error screen,
restart your computer. If this screen appears again, follow
these steps:

Check to make sure any new hardware or software is properly installed.
If this is a new installation, ask your hardware or software manufacturer
for any Windows updates you might need.

If problems continue, disable or remove any newly installed hardware
or software. Disable BIOS memory options such as caching or shadowing.
If you need to use safe mode to remove or disable components, restart
your computer, press F8 to select Advanced Startup Options, and then
select Safe Mode.

Technical Information:

*** STOP: 0x00000050 (0xcccccdd8, 0x00000000, 0x8bae950c, 0x00000002)

*** tcpip.sys - Address 0x8ba6d854 base at 0x8ba30000 DateStamp 0x522bca92

A problem has been detected and Windows has been shut down to prevent damage
to your computer.

The problem seems to be caused by the following file: tcpip.sys

KERNEL_MODE_EXCEPTION_NOT_HANDLED

If this is the first time you've seen this stop error screen,
restart your computer. If this screen appears again, follow
these steps:

Check to make sure any new hardware or software is properly installed.
If this is a new installation, ask your hardware or software manufacturer
for any Windows updates you might need.

If problems continue, disable or remove any newly installed hardware
or software. Disable BIOS memory options such as caching or shadowing.
If you need to use safe mode to remove or disable components, restart
your computer, press F8 to select Advanced Startup Options, and then
select Safe Mode.

Technical Information:

*** STOP: 0x1000008e (0xc0000005, 0x8b8b950c, 0x951ffa30, 0x00000000)

*** tcpip.sys - Address 0x8b8b950c base at 0x8b800000 DateStamp 0x522bca92

There is nothing new hardware/software I installed on 22nd night (that was the last day my system was running fine). But suddenly on 23rd morning out of blue this issue popped up and I couldn't do my work yesterday.

Please help me to fix this issue. I want the system to be up and running before Monday morning.
 

rijinpk1

Aspiring Novelist
can you download bitdefender rescue disk and boot it ,scan it and see if it detects any malware. are you sure the new pendrive you connected to your pc is clean??
also try sfc/ scannow in cmd as administrator and see if it solves your particular problem before scanning with antivirus.
 
OP
nac

nac

Aspiring Novelist
^ The pendrive I put was a brand new out of the box one. So I don't think there would be any virus.

Yes, I can download and do the scan via USB flash drive. But the file size is too big and it will take more than 2hrs to download.

Yeah, I sure do that scannow before booting with bitdefender. I have done that scannow for tcpip.sys file an hour ago and found no integrity violation.

- - - Updated - - -

System Config:
Windows 7 Ultimate SP1 32-bit
Intel Pentium Dual Core E2160 @ 1.8GHz
3GB RAM (1+2 Transcend DDR 2)
ASUS P5G MX
DVD drive disconnected.
Seagate HDD 160GB (which replaced by manufacture last year, I think it's refurbished)
Zebronics generic cabinet with SMPS (Omax 450W which I replaced about 2yrs ago, I think).
Samsung 17" LCD monitor
Local brand Rs. 400/- speaker and about Rs. 200/- headphone
Samsung generic keyboard and zebronics optical mouse.
TP Link WIFI modem.

OS and all the softwares are up to date. Even ran "check for updates" and installed everything excluding optional language pack updates.

tcpip.sys version installed in my system - 6.1.7601.18254

Found the memory diagnostic log and found no error.
 

rijinpk1

Aspiring Novelist
do you experience any such problems in the safe mode??

- - - Updated - - -

this thread should have been here. *www.thinkdigit.com/forum/hardware-q/. you might get better replies.
 
OP
nac

nac

Aspiring Novelist
scannow didn't find any integrity violation. Download will take more than 3hrs... 631MB :(
 
OP
nac

nac

Aspiring Novelist
I am not sure, as far as I remember I think I didn't find any issues in safe mode/safe mode with networking.

Thanks for pointing that out which section this thread supposed to be...

I actually started this thread in "Software Q&A" yesterday, as there was no reply since yesterday morning. I asked mod to move the thread here (cause this is where the discussion started). If I ask him again, sure he will get annoyed @Anorion ;)
 

rijinpk1

Aspiring Novelist
I am not sure, as far as I remember I think I didn't find any issues in safe mode/safe mode with networking.

Thanks for pointing that out which section this thread supposed to be...

I actually started this thread in "Software Q&A" yesterday, as there was no reply since yesterday morning. I asked mod to move the thread here (cause this is where the discussion started). If I ask him again, sure he will get annoyed @Anorion ;)

probably a re-install would fix this. anyway try bitdefender rescue disk first.
 
OP
nac

nac

Aspiring Novelist
faulty psu can also cause random reboots.
try with another if you have a spare one.
This was my very first doubt as I have had a similar issue two years ago. The fan in the PSU wan't functioning. It took me more than a week to find the problem. The first thing I checked now was the fan in PSU.

- - - Updated - - -

probably a re-install would fix this. anyway try bitdefender rescue disk first.
Re-install??? Meaning > Fresh OS installation? That's a time consuming thing... :(
 

rijinpk1

Aspiring Novelist
This was my very first doubt as I have had a similar issue two years ago. The fan in the PSU wan't functioning. It took me more than a week to find the problem. The first thing I checked now was the fan in PSU.

even if the fan is rotating, the psu can malfunction!!
 
OP
nac

nac

Aspiring Novelist
Rijin, Thank you so much for helping me to find the issue. I really appreciate your help and glad there is someone helping me... Hope soon this issue will be fixed. :)

- - - Updated - - -

even if the fan is rotating, the psu can malfunction!!

Oops!!! How can I find it? Any stress test? I don't think anyone I know in my neighborhood using desktop, so it's less likely to borrow one to test it.
 

rijinpk1

Aspiring Novelist
Re-install??? Meaning > Fresh OS installation? That's a time consuming thing... :(

yups. let this be your last resort after trying all possible ways to solve your issue..



Rijin, Thank you so much for helping me to find the issue. I really appreciate your help and glad there is someone helping me... Hope soon this issue will be fixed. :)

hope for the best ;)


Oops!!! How can I find it? Any stress test? I don't think anyone I know in my neighborhood using desktop, so it's less likely to borrow one to test it.

borrowing will help. dont do stress test on a local psu. it might burn/blast.
but i guess ,you should try bitdefender rescue disk first.
 

Anorion

Sith Lord
Staff member
Admin
oh I was also unsure what problem this was, its in right section now
think some files must have gotten corrupted, finding out which ones can be nasty
 
OP
nac

nac

Aspiring Novelist
Thank you Ano :)

Rijin, I will update with the bitdefender result. And I will also unplug and plug the hardware too to make sure there is no loose connection.

- - - Updated - - -

I downloaded rescue disc from here... *download.bitdefender.com/rescue_cd/2013/
Followed this instruction to load it from usb *www.bitdefender.com/support/how-to-create-a-bitdefender-rescue-cd-627.html
Download unetbootin here *unetbootin.sourceforge.net/

I don't know where it went wrong, it's not working. Gonna try stickifier, will let you know later...
 
OP
nac

nac

Aspiring Novelist
I will try that...
Stickifier also shows some error and loaded saying GNU grub (er???) sounds like linux? I didn't understood that... Again I am here...

- - - Updated - - -

Is the one I downloaded right? Should I downloaded the one they have given (link) in the instruction site?
 

rijinpk1

Aspiring Novelist
or this will help *www.pendrivelinux.com/downloads/Universal-USB-Installer/Universal-USB-Installer-1.9.5.2.exe

- - - Updated - - -

Is the one I downloaded right? Should I downloaded the one they have given (link) in the instruction site?

631mb file should be the latest with most upto date virus definitions.
 
OP
nac

nac

Aspiring Novelist
I tried power ISO, now bios don't even recognize USB. When I logged in (normal) it showed only 2MB usb drive. I was little scared at first, I messed up the thumb drive :D Then tried google.... there it goes "windows detected a problem...." Coz I wasn't in safe mode :(

With the help of google search found solution to get the full size of the thumb drive and trying pendrivelinux. I have lot of work tomorrow, got to get up early. If this attempt goes unsuccessful, I am going bed ;)

- - - Updated - - -

So the one, I downloaded is the right one. :)

- - - Updated - - -

:( Couldn't find the boot file :(

bitdefender-rescue-cd.iso.md5sum What's this file? Should I add this file along with the 631MB ISO file?

Now I am going bed. I got some work tomorrow, I will get back to you by tomorrow night.
 

rijinpk1

Aspiring Novelist
I tried power ISO, now bios don't even recognize USB. When I logged in (normal) it showed only 2MB usb drive. I was little scared at first, I messed up the thumb drive :D Then tried google.... there it goes "windows detected a problem...." Coz I wasn't in safe mode :(

With the help of google search found solution to get the full size of the thumb drive and trying pendrivelinux. I have lot of work tomorrow, got to get up early. If this attempt goes unsuccessful, I am going bed ;)

- - - Updated - - -

So the one, I downloaded is the right one. :)

- - - Updated - - -

:( Couldn't find the boot file :(

bitdefender-rescue-cd.iso.md5sum What's this file? Should I add this file along with the 631MB ISO file?

Now I am going bed. I got some work tomorrow, I will get back to you by tomorrow night.

you dont need the second file. just the iso is enough. something is wrong. give unetbootin another try tomorrow.
 

chris

In the zone
Get a Ubuntu DVD. Boot it (you don't have to install). See if you can do you work on it :mrgreen:

If ubuntu works, it proves that your hardware is working properly. Now time to fix windows, better to a fresh install as it is much easier than fixing a bad windows install, recently i reinstalled my windows (after 2 years) and windows boot much faster now.
 
Top Bottom