BSOD spooldr.sys file

Discussion in 'Malware Help (A Specialist Will Reply)' started by PooLips, Aug 26, 2007.

  1. PooLips

    PooLips Private E-2

    Hi all,
    My wife was using the laptop and whilst on the internet the computer restarted then kept restarting.
    The BSOD message says its caused by the file spooldr.sys
    PAGE_FAULT_IN_NONPAGED_AREA
    I can't seem to start in safe mode.
    Thanks
    Andre
     
  2. abri

    abri MajorGeek

    Hi PooLips !!

    You may have a trojan. Please read through the box below and then click on the link to READ & RUN ME FIRST and follow the instructions. If you have any questions, please ask. We'll look at your logs when you get done!
    abri

     
  3. PooLips

    PooLips Private E-2

    Thanks for the reply Abri. Unfortunately i cannot get windows to boot normally or in safemode. I am not very computer savvy so don't know what to do now.
    Thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. PooLips

    PooLips Private E-2

    Thanks TimW. I ended up doing a repair install which fixed the problem then AVG found the trojan and healed it. Everything seems to be working well now.
    Do you think I should proceed with the Read and Run process anyway or just see how it goes?
    Thanks
     
  6. abri

    abri MajorGeek

    Hi PooLips!!

    There's a rootkit virus with the name you mentioned: spooldr.sys
    What you did may have fixed your problem or not, depending on what caused it, but it would be a good idea to run the following scan.
    abri
     
  7. PooLips

    PooLips Private E-2

    Thanks heaps Abri for your help.
    The Blacklight scan did not turn up anything.
    A few times AVG has healed somethings to do with spooldr.sys. I wonder where that nasty thing came from.

    Andre
     
  8. abri

    abri MajorGeek

    Hi Andre,
    Are you able to get into the computer since you did the repair install? We have a removal tool for the spooldr.sys problem, but it would be nice to identify it first. Has AVG continued to find it and heal it since then? When you did the repair installation, did your computer set a new restore point? Could you check? Go to Start/All Programs/Accessories/System Tools/System Restore. Click on Restore My Computer to an Earlier Time, then click on next. You'll see a calendar. See if any dates are darkened in. Then hit cancel.
    If AVG is still finding this, I will give you instructions for a removal tool.
    abri
     
  9. PooLips

    PooLips Private E-2

    Hi Abri,
    I am able to use the computer since the repair. Since then AVG has managed to locate several trojans once each time then heal them. I don't think they keep reappearing. (I probably should have paid closer attention and written them down). I've done a full scan with AVG and nothing turns up now.
    The computer set a new restore point after the repair install.
    Thanks
    Andre
     
  10. abri

    abri MajorGeek

    PooLips,
    since AVG is still finding trojans, it would be a very good idea if you would go through the READ & RUN ME FIRST instructions. They take some time but are not difficult. I'll post you the link below. We can tell you a lot more about what's going on with that computer if we can take a look at your logs. I think with the possibility that you have a rootkit, it would be time well spent.
    Here's the link:

    READ & RUN ME FIRST


    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds