Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys restore

Discussion in 'Malware Help (A Specialist Will Reply)' started by mladyraven, Jan 4, 2013.

  1. mladyraven

    mladyraven Corporal

    Dell Inspiron 660S - Win 7 Home 64bit 3 months old. 4gig Ram Service pack1
    3 days ago Blue Screen stating above message about driver. Windows tried to fix it and said it was fixed. It happened again yesterday and again today. I called Dell. They ran Mbam and found 4 Trojans. They said my warranty was up 3 days ago and they wanted 89 dollars to fix this. So, I decided to try to use your program here. After I deleted the Trojans ran mbam again and it came clean. Ran the other programs and will include the results. I am not sure if the problem is fixed because it happens intermittently. Dell said my only other choice was to reformat and re-install the operating system I would prefer not doing that, only as a last resort. Thank you for your assistance. Assuming I should put setting back the way they were until I hear from you. :wave
    I posted both copies of mbam test.
     

    Attached Files:

  2. mladyraven

    mladyraven Corporal

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    PS. The Dell rep had me re- start the computer and hit F12 to try to get me to a different page then the regular windows starting page. However, we tried 4 times and it would not let me hit F12 and get to that page it always went directly to the starting page. I forgot to add that. Ty.
     
  3. mladyraven

    mladyraven Corporal

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    OK, it's not fixed I just got the got blue screen again... Computer shutting down Driver IRQ not equal.... can't see the rest of the code before it shuts down. I was just reading my email when it happened. Sometimes I am watching a video, sometimes just surfing the net, there is not pattern to it, except that it is happening more often. I am wondering if the Trojan destroyed a driver and I am going to have to reformatt. I am concerned because I do not know how to get my information back on to the computer from the external HD and my favorites from FF. Dell said they will only put the operating system back on and I have to do the rest which is BS to me on a 3 month old computer. I am 64 and disabled so I cannot pay them 89$ to fix my virus program. Thank you, I am grateful for any assistance you can provide.
    Raven
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    I am not seeing any malware in those logs.
     
  5. mladyraven

    mladyraven Corporal

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    Sorry it took me awhile to get back to you, I was having problems with my password.

    The problem is still continuing. The computer just crashed again a minute ago. It went 2 days without crashing and then yesterday it disconnected the router.
    Now today the blue screen with error message
    If this is the first time you are seeing this message restart, if not contact your networking... I live alone, one computer.
    Driver IRQ not Equal
    I saw this, could this be the problem : http://www.sevenforums.com/crashes-debugging/178107-driver-irql-not-equal-less.html

    Dell History Log
    Operating System crash The computer has rebooted from a bug check. The bug check was 0x000000d1 ( 0x0000000000000008) 0x0000000000000002 , 0xfffff8801946a1d, A dump was saved in C:\WINDOW\MEMORY.DMP Report ID
    010913-14648-.01 The event on the 4th the 3rd, etc all have the same message in the history event log.
    I did a complete mbam and deleted the Trojans it said were there.
    Files Detected: 4
    C:\System Volume Information\SystemRestore\FRStaging\Users\Nicole\Downloads\Archangel s Blade(1).exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\SystemRestore\FRStaging\Users\Nicole\Downloads\Archangel s Blade.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Nicole\Downloads\Archangel s Blade(1).exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Nicole\Downloads\Archangel s Blade.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    After all that was deleted I came to the site. Ran the Malware tests you suggest and then attached. Later that day it crashed again. I ran mbam in safe mode and it was still clean. I am at a loss to know what to do, any suggestions on what this can be? Thank you!
     
  6. mladyraven

    mladyraven Corporal

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    Had two more crashes tonight same message so I deleted McAfee , ran a virus scan and am hoping for the best but just don't know what is going on. Ty
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Blue Screen Crash Driver IRQ not Equal and found 4 Trojans in file and in sys res

    I suggest that you post in the software forum for further assistance. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds