Stop Errors, Crashing, Spyware...the Works!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Criscoih, Jun 12, 2005.

  1. Criscoih

    Criscoih Private E-2

    Hello all,
    I'm new here to these forums and I would like to state now that I am in no way a tech-head, but I like to think I can get around on the comp. I recently got back from school for the summer to find that my old home computer is VERY sick. Apparently my sister has taken the liberty to download every sort of p2p program available on the net because of a lust for music. When I first experienced a stop error in the beginning of May, I didn't think much of it (thought it was a weird driver conflict). But then they became more frequent and more intrusive. Now it has gotten to the point where I can't even run a virus scan in safe mode without the machine giving me a stop error BSoD or rebooting on its own accord. After I realized that I had a serious problem on my hands (about a week ago because I don't use that particular machine that often until recently) I googled a few of the errors and found these forums, signed up and assumed that I had a spyware issue.
    I figure its a spyware issue because apparently I have an LSP conflict and my internet just stopped working on the machine (My antivirus software-EzArmor from E-Trust- does a network diagnosis on start up and as of a week ago tells me the network is not functioning because of LSP issues. So after researching what an LSP was (don't laugh) I figured I had some sort of bad spyware (malware?) that was wreaking havok on my registry. So I hope I am in the right forum.
    NOw that the preface is out of the way, I'll get down to business. Here is the current status of the issue: My computer still does not have internet connection, it still has an LSP conflict, I am still infected with spyware (i can pick it up on scans everytime I reboot my comp), and it still gives me random stop errors and reboots on me. When I tried to remedy these issues by following the instructions provided by the staff of this site for prepping for adware removal (the steps to take before posting a hijack this logfile) I found that I'm not even safe in SAFEMODE ANYMORE! The only way I had access to the internet was through safemode. I followed all of the steps until i got to the scanning and removal portion where it links to trendmicro's housecall virus scan...I start the scan and about halfway through the computer either reboots or gives me this error (which I will abreviate the hexidecimal crap where possible):

    STOP 0x...7F (0x...D, 0x...0, 0x...0, 0x...0)
    UNEXPECTED_KERNEL_MODE_TRAP
    beginning dump of physical memory


    Now, I have several other reoccuring stop errors which I have recorded and can provide to anyone who is willing to assist me at there request.

    The specs for the system are as follows:

    AMD Athlon 1333 mHz
    512 megs DDR PC2100 ram
    64 meg nvidia GeForce 2 MX (whose display drivers i have uninstalled..reinstalling them is now the least of my concerns)
    Windows 2000 pro

    I'm sure more information will be needed and I will gladly provide it ASAP.

    NOTE: I have followed every preparational step that this site mandates up to the actual scanning and removal of spyware because I can't actually virus scan now without an arbitrary reboot or stop of the machine.

    Thank you so much in advance for all help provided. These forums seem like a blessing for people like me- people that are known as the resident "computer nerds" as a direct result of other resident's complete ignorance of technology ;).
     
  2. Criscoih

    Criscoih Private E-2

    Here are some elaborated specs I recieved using AIDA32:

    Operating System Microsoft Windows 2000 Professional
    OS Service Pack Service Pack 4
    Internet Explorer 6.0.2800.1106 (IE 6.0 SP1)

    Motherboard
    CPU Type AMD Athlon-PECM, 1333 MHz
    Motherboard Name Gigabyte GA-7DX(C) (5 PCI, 1 AGP, 1 AMR, 2 DIMM, Audio)
    Motherboard Chipset AMD-760
    System Memory 512 MB
    BIOS Type Award Modular (04/11/02)
    Communication Port Communications Port (COM1)
    Communication Port Communications Port (COM2)
    Communication Port Printer Port (LPT1)

    Display
    Video Adapter nVIDIA GeForce2 MX/MX 400
    3D Accelerator nVIDIA GeForce2 MX/MX 400

    Multimedia
    Audio Adapter Creative SB PCI128 (Ensoniq ES5880) Sound Card

    Storage
    Disk Drive IBM-DTLA-307030 (30 GB, 7200 RPM, Ultra-ATA/100)
    Optical Drive LITE-ON LTR-12101B (12x/10x/32x CD-RW)
    Optical Drive PIONEER DVD-ROM DVD-106 (16x/40x DVD-ROM)

    Partitions
    C: (FAT32) 29291 MB (14583 MB free)
     
  3. JaxMacFL

    JaxMacFL Private E-2

  4. Criscoih

    Criscoih Private E-2

    Its funny that I gave up researching the error messages when I got to that one. Thanks for the article, I'll read it and see if I can make sense of this mess.
    thanks again
     
  5. SpamHater

    SpamHater Private E-2

    If your system is compromised you will have to reinstall windows to absolutely make sure it is no longer compromised. Here is why. Many of the problems are not necessarily spyware, but Trojans. Some of them actually overwrite windows programs with their bogus copy. A common one is svchost.

    That said, you may have a chance by doing the following. Try downloading Microsoft's new beta antispyware and running it. Another decent one is Adware, but be careful that you get the real adware and not the look-a-like out there. Here is a cnet link

    Edit by chaslang: changed link for to MG's download page Ad-Aware SE

    If you cannot get them to run, you could try running the windows update (update windows on the IE Tools menu). You can also try running your antivirus scan from a dos bootup. If one or more of your windows components are compromised, your antivirus scan will be useless.

    I would highly recommend for anyone who does not completely tighten up their security and likes to traverse the Internet at will, they delete the disk, reload windows and their anti-virus and firewall (firewall not needed for XP), go out and get the latest updates and then back it all up. Then go have fun and when things start getting funny, delete and reload the backup. If you do this right, it will only take 5 or 10 minutes to completely recover.
     
    Last edited by a moderator: Jun 12, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do reference tools on MGs. If you are not familiar with our files systems then please get familiar with them. Many tools are already here.

    Reinstalling Windows is rarely necessary to resolve malware problems. Sometimes it could be the fastest/simpliest solution. But that depened on the users circumstances (like how much data needs be backed up, can the user even do backups, does the user have the ability to reinstall his system...etc).

    Also note a firewall is still required even if you are using WinXP. The one built into WinXP SP2 is not a complete firewall and does not provide sufficient protection.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Criscoih,

    If you are having malware problems, you should follow the steps below.

    Please follow the steps below (to the best of your abilities given the problems your system is having):

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds