Many backdoors/various Trojans/rootkit. Shutdowner present

Page 2 of 4 FirstFirst 1234 LastLast

  1. Posts : 1,436
    Windows 8.1 Pro x64
       #11

    Try a system restore to the point before you clicked on the spam and such.

    Like what borg said, it may not be fixable.

    -Justin
      My Computer


  2. Posts : 156
    Windows 7 64-Bit Home Premium Service Pack 1
    Thread Starter
       #12

    Click on Repair your computer. (See screenshot below)
    5. Select which operating system you want to restore and the click on Next. (See screenshot below)
    NOTE: If Windows 7 is not listed here, or it is blank, then it is ok. Click on Next anyway.
    It wasn't listed, it was blank, and I clicked Next anyway. I went to System Restore and it said:

    To use System Restore, you must specify which Windows installation to restore. Restart this computer, select an operating system, and then select System Restore.

    I thought I could leave it blank?

    I didn't click Load Drivers. Should I try that?
      My Computer


  3. Posts : 2,171
    Windows 7 Ultimate x64
       #13

    Although you might be able to get a deeply infected machine back into a 'workable' state it will likely take more than one program to do it.

    But even if you can get it back into that 'workable' state I wouldn't trust it. I'd wipe that disk clean and reinstall. Quicker that way, and you can then be confident that it's secure.

    Back up all your data to reliable media first though.
      My Computer


  4. Posts : 2,171
    Windows 7 Ultimate x64
       #14

    MelancholyRose said:
    To use System Restore, you must specify which Windows installation to restore. Restart this computer, select an operating system, and then select System Restore.

    I thought I could leave it blank?

    I didn't click Load Drivers. Should I try that?
    System Restore might work, but you should be aware that your restore points can contain the malware too. Definitely contains it if you've been infected for some time.
      My Computer


  5. Posts : 156
    Windows 7 64-Bit Home Premium Service Pack 1
    Thread Starter
       #15

    I need to get that shutdown to stop happening before I can back anything up. I'm having a friend help me.
      My Computer


  6. Posts : 2,913
    Windows 7 Ultimate x64 SP1
       #16

    The easiest thing to do is to remove the drive and slave it into another computer (with up to date virus definitions, of course). Copy your essential files to the other computer. Put the drive back into the original computer, and reinstall Windows.
      My Computer


  7. Posts : 156
    Windows 7 64-Bit Home Premium Service Pack 1
    Thread Starter
       #17

    Apparently the Services.exe file is damaged, and that's what's causing the shut downs, not a virus. I thought to do an sfc scannow, but for some reason my computer just doesn't show my OS. It acts like I don't have one, even though I definitely do.

    What I think is causing that is, I use a RAID 1 mirror. My other hard drive isn't being used right now, it hasn't been used for a while, so I'm using only the one drive. Do I need my RAID driver to get to my OS?

    If so, do I need to use RAID drivers or Chipset drivers? http://support.amd.com/us/gpudownloa...d_windows.aspx [EDIT: I'm thinking it's the AHCI Controller Driver under chipsets.]

    EDIT: Looks like this is probably it. SATA Drivers - Load in Windows Recovery Options
    Last edited by MelancholyRose; 01 Aug 2012 at 20:48.
      My Computer


  8. Posts : 687
    Microsoft Windows 10 Professional / Windows 7 Professional
       #18

    My mother in law's laptop got infected and I got tired of fighting this rootkit because of the afterall damage to core files which SFC couldnt fix, ended wiping the disk and reinstalling clean, one thing I'm clueless about is how is this infection spreaded?
      My Computer


  9. Posts : 156
    Windows 7 64-Bit Home Premium Service Pack 1
    Thread Starter
       #19

    Judging on what I've read/been told about Sirefef is that if you try to remove it, it hides in system files and copies itself to Registry keys and such.
      My Computer


  10. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #20

    This sounds like the Zero Access Rootkit. It has created a hidden partition to hide itself from being found and fixed. This is quite a nasty Rootkit!

    Save what you can (pictures, important documents), then wipe your OS and do a "clean" install.
      My Computer


 
Page 2 of 4 FirstFirst 1234 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:10.
Find Us