I'm new..please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by a2a, Oct 10, 2006.

  1. a2a

    a2a Private E-2

    Okay,

    So it seems you regulars take posting on this board pretty serious and I dont want to upset anybody by being too far off topic..

    So I first came to this board searching for hijack this....

    I have what may seem to be a pretty serious problem..

    I feel fortunate to even be online right now.

    Its started while I was running two java applications(chat programs)

    I had an blue screen error(?)...Thought I may have been hacked, wouldnt have the slightest clue as to how to tell..

    But the problem has been reoccuring and I have to use selective startup to even get the computer up and running..

    So I went to find hijack this, I have no clue about it but all the warnings made me take heed.

    So I started to go through the whole list of things to do first...did them...and read "restart your computer in safe mode"

    I cant, it just wont start in safe mode, that happened after the initial incident, as well as losing all my restore points, it was turned off mysteriously along with updates, and what made me stop and go hmm was my remote assistance was on!!!!

    So I am lost at this point, and if anyone could help me I would ever so much appreciate it..
    Error type : Windows stop error (A message appears on a blue screen with error code information)
    Solution available? : No (see Next steps)
    What does this error mean? : Windows has encountered an error from which it cannot recover and needs to restart
    Cause : Unknown device driver
    Computer symptoms : A message appears on a blue screen with error code information (for example: e.g. 0x0000001E, KMODE_EXCEPTION_NOT_HANDLED)
    Additional steps for you to take : Important: Please continue to send error reports so analysts at Microsoft can study and try to correct the problem as quickly as possible

    Ken:confused: :eek: :confused: :eek:
     
  2. a2a

    a2a Private E-2

    And the newest....What does it mean?

    And am I in the right place?

    Could you direct me somewhere if not?


    Error caused by a video device driver

    Thank you for sending an error report to Microsoft.

    Error report summary

    Error type Windows stop error (A message appears on a blue screen with error code information)
    Solution available? Yes
    What does this error mean? You received this message because a device driver installed on your computer caused the Windows operating system to stop unexpectedly. This type of error is referred to as a "stop error." A stop error requires you to restart your computer.
    Cause A video adapter device driver
    Computer symptoms A message appears on a blue screen with error code information:

    STOP 0x000000EA THREAD_STUCK_IN_DEVICE_DRIVER
    - or -
    STOP: 0x100000EA THREAD_STUCK_IN_DEVICE_DRIVER_M

    Action for you to take

    We have analyzed your error report and there are two solutions for this problem for you to choose between.
    + Solution 1: Install the most current driver for your video card

    * Go to the Microsoft Update website to see if there are any updated drivers for your video card. A driver is software that enables hardware or devices (such as a printer, mouse, or keyboard) to work with your computer. Every device needs a driver in order for it to work. If there are any drivers listed, you should install them.
    * If there are no updated drivers at Microsoft Update, and you know the manufacturer of the video card, contact the card manufacturer's product support service for assistance.
    * If there are no updated drivers at Microsoft Update, you don't know the name of the manufacturer of the video card, and you need more help diagnosing and resolving this problem, contact your computer manufacturer's product support service.

    + Solution 2: Manually decrease Hardware Acceleration for your video adapter

    This procedure prevents the display driver from programming the hardware incorrectly, but you may lose some display functionality and performance. Although you can increase the hardware acceleration settings higher than None to regain functionality and performance, these settings increase the chance that the issue will occur again. For maximum stability, leave hardware acceleration turned off.

    1. Click Start, click Control Panel, and then double-click Display.
    2. Click the Settings tab, and then click Advanced.
    3. Click the Troubleshoot tab, move the Hardware Acceleration slider to None, and then clear the Enable Write Combining check box.
    4. Click OK, and then click OK.
    Note: This procedure prevents the display driver from programming the hardware incorrectly, but you may lose some display functionality and performance. Although you can increase the hardware acceleration settings higher than None to regain functionality and performance, these settings increase the chance that the issue will occur again. For maximum stability, leave hardware acceleration off.

    Article ID : 11
    Last Review : February 28, 2006
    Revision : 1.0

    Additional Technical Information

    * Error Message: STOP 0x000000EA THREAD_STUCK_IN_DEVICE_DRIVER (Q293078)
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. a2a

    a2a Private E-2

    Will bit defender interfere with Avast though?


    And the first link....

    I am unable to start in safe mode!
     
  5. a2a

    a2a Private E-2

    Bitdefender was unable to load virus definitions
    I am running anyways...

    I hope thats not bad
     
  6. a2a

    a2a Private E-2

    It found Generic.Botget.OCB7BF21 and is still running..

    How do I tell if I was hacked?
     
  7. a2a

    a2a Private E-2

    Okay,
    after running bitdefender and Microsofts Latest update...

    I still can not start in safe mode...

    Any suggestions? Couldnt hijack this help?

    If only I knew how to read it...

    I have no idea what to do....

    Microsofts website says I need a new video card?????

    Is that possible?

    It seems fine to me..

    But I really dont know.....

    I have ran bit defender.. it deleted something..I think thats good

    Spybot doesnt find nothing different than it usually does...

    CC cleaner cleaned ALOT of files out....

    Avast doesnt do nothing...it usually doesnt(does it even work?)

    I am at a loss..I know now I am suppose to clean with everything in safe mode but nothing happens when I reboot to safe mode..

    And now the only way I can even get my computer to start is in selective startup..

    What should I do now?

    Please help

    Ken
     
  8. a2a

    a2a Private E-2

    I am thinking maybe I should just post my hijack this log
     
  9. a2a

    a2a Private E-2

    Please tell me...

    if I cant reboot in safe mode so I can run those programs like it said to do before I can get help..

    Am I just shit out of luck?
     
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Basically by bumping your thread continually, you have dropped each time to be bottom of the workpile queue in this a very busy part of the forum, as the malware guys DO NOT work from the 1st page backwards, they always work from say for example the last current outstanding thread that maybe on pages 3,4,5 etc

    So by bumping you have missed Chaslang or the other regular malware guy's reading your thread over the space of the past day, as like all of us we only have a certain amount of freetime to answer questions, due to busy home or work lives, as helping others we do freely because we like to help, but at present as many security forums are not stopping assisting or reading malware logs, we have become busier and as you'll apprieciate removing malware and reading the necassary logs is time consuming, so you'll just have to bare with us.


    Also the Hijackthis logs have been deleted as you have not followed the guide ( which I will post a summary of below ) to start the removals process that TimW posted in post #3, malware is as you will now know are sneeky little buggers and hide themselfs from a HijackThis scan that has not been installed and re-named as mentioned in the guide, while Hijackthis is a good malware scanner it cannot locate all the malware that could be infesting your PC, so running through the guide in the steps as laid out will not only start the removals process but also get your PC to a position in which we should know what malware you have and how to remove it, in which one of the malware guys will post some further instuctions for you to follow which are tailored to your pc and the infection you have.


    WE know malware is stressful and causes grief but if you dont continually bump or start new threads to get on the 1st page your logs will be looked at more quickly :)



    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!



    Cheers.
     
    Last edited: Oct 12, 2006
  11. a2a

    a2a Private E-2

    Okay,

    Thank you for explaining this to me, that was very helpful..

    I cannot start in normal mode..

    My computer just continues to crash :(
    * MSConfig Startup Mode
    Please go to Start > Run > type msconfig and click OK!
    Select the General tab and select Normal Startup.

    Thenclick Apply and OK and reboot PC before continuing.
    Remain in this Normal Startup mode while your PC is being cleaned of malware.
    I cannot do Step 0

    Spybot does not work in default....It just says scan aborted by user...

    In advanced mode it runs and only finds cookies...

    CC cleaner cleaned a bunch of stuff

    Then I updated my computer thinking it may be repaired but only to have the same difficulty starting my machine...

    Bit defender seemed promising and removed Generic.Botget.OCB7BF21..

    But still I am unable to start without msconfig selective startup

    And I still cannot access safe mode

    That is where I am at....

    I am patiently awaiting your reply now..

    Much Thanks
     
  12. matt.chugg

    matt.chugg MajorGeek

    Your last post contradicts itself slightly

    Just run the scans from normal mode, if you cannot access safe mode. If the only way you can boot is to run from selective startup then do that. We will be able to see what is being blocked by the startup from your runkeys log.

    Carry on with the scans now and let us know if you have any issues with them you should have no problem with shownew, runkeys and hijackthis anwyay.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds