Malware and Trojans and Blue Screens, Oh My!, Winifixer, Rogue.Virus Isolator, Zlob, and STOP error |
![]() ![]() |
Malware and Trojans and Blue Screens, Oh My!, Winifixer, Rogue.Virus Isolator, Zlob, and STOP error |
May 9 2008, 03:52 PM
Post
#1
|
|
|
New Member ![]() Posts: 6 From: Minneapolis OS: Windows XP Media Center Edition 2005 w/ SP2 |
Hi! I’m new here and sure hope you can help me. Apologies in advance for the length of this post but I want to include as much info for you as I can. We’re running Windows XP Media Center Edition with SP2 on a Dell Dimension, and use Trend Micro PC-cillin for virus/spyware protection. We recently returned from vacation to find a very sick computer, thanks to a well-meaning-but-not-very-computer-savvy friend. There were at least four different (bogus) Windows Security warnings that popped up repeatedly, and when we tried to access Internet Explorer, our homepage was redirected (unsuccessfully, thanks to PC-cillin) to “softwarereferral.com” or “safenavweb.com”.
I ran a virus/spyware scan but didn’t find anything. I installed, updated and ran Ad-Aware Plus, which didn’t find anything either. Then I found your site. I initially thought Zlob was the problem, so I followed the Option 1 instructions on “How to Remove Zlob.trojan.Media-Codec, Goldcodec, Silvercodec, Braincodec” -- I downloaded SmitfraudFix (by S!Ri), removed the infected files it found, and saved the textfile log. The problems persisted, though, so I then found your instructions on Malware Removal (“You Must Read This Before Posting a Hijackthis Log”). 1. I downloaded and ran ATF-Cleaner.exe. I then created a new System Restore point. 2. I downloaded and ran Malwarebytes’ Anti-Malware. It found and removed about ten things, and I saved the log. 3. I downloaded and ran SUPERAntiSpyware Home Edition. After 2.5 hrs, it found an additional five things which it quarantined; I successfully rebooted and everything was looking great! No more warning pop-ups, no more homepage redirection. I copied and saved the log information. 4. I went to the Online - Panda ActiveScan site. There was no “Scan your PC” button, just a “Scan Now” or a “Register” button. I registered, then clicked the “Scan Now” button; I believe it installed an ActiveX component (which your instructions said was OK), but I couldn’t get the scan started. I wasn’t too concerned because I really thought I was out of the woods at this point. I’d found and cleaned Winifixer, Rogue.VirusIsolator, Zlob, (maybe others but those are the ones I remember), so I proceeded to the next step. 5. Windows Update – I found a critical update for Windows XP Service Pack 3, which I installed. When I rebooted, I got the following blue screen message: A problem has been detected and Windows has been shut down to prevent damage to your computer. Rebooting in safe mode brings up the same stop screen and I either can’t or don’t know how to do anything else from there. Too late, I read your warning about installing SP2 if malware is still present. I’m guessing that warning applies to SP3 as well and that there was still some malware present when I installed SP3. I’d gladly send you the logs but at this point I can’t get to them. So I’m stuck -- what do I do now (besides cry in frustration)? |
|
|
May 15 2008, 03:27 PM
Post
#2
|
|
![]() GeekU Teacher Posts: 41,926 From: Dublin OS: XP |
Can you get into Normal or Safe Mode ?
|
|
|
May 16 2008, 10:25 AM
Post
#3
|
|
|
New Member ![]() Posts: 6 From: Minneapolis OS: Windows XP Media Center Edition 2005 w/ SP2 |
Thanks for replying - I really appreciate the help!
If I just turn on the computer and don’t do anything else, I first get a Dell screen for about a second, then a black screen that says: We apologize for the inconvenience, but Windows did not start successfully. A recent hardware of software change might have caused this. If instead I start the computer and hit F8, I am able to get to the black screen with the Windows Advanced Options menu. Safe Mode From there, I’m given a choice of operating systems – WindowsXP Media Center Edition is the only option. Starting either way, if I choose Safe Mode, I get lots of lines of white text like: multi (0),disk (0), rdisk (0), partition(2)\WINDOWS\System 32\Drivers\ (etc, etc) Then I get a blue screen / stop error indicating Page_fault_in_nonpaged_area, with the following technical information line: 0x00000050 (0xFFFFFF96, 0x00000000, 0xF7AFB8E8, 0x00000000) If instead I choose either Last Know Good Configuration or Start Normally, I get the Windows startup screen for a few seconds, then the blue screen / stop error (text in previous post) indicating that an attempt was made to execute non-executable memory, with the following technical information line: 0x000000FC (0xF7AA98E8, 0x07354963, 0xF7AA9848, 0x00000001) |
|
|
May 16 2008, 11:13 AM
Post
#4
|
|
![]() GeekU Teacher Posts: 41,926 From: Dublin OS: XP |
Do you have an AMD processor ?
I don't think this is malware related |
|
|
May 16 2008, 02:06 PM
Post
#5
|
|
|
New Member ![]() Posts: 6 From: Minneapolis OS: Windows XP Media Center Edition 2005 w/ SP2 |
Here's all the tech info on my system:
MS Windows XP Media Center Edition 2005 running on Dell Dimension E510 Intel Pentium 4 Processor 630 with HT Technology (3.0 GHz) 1 GB DDR2 SDRAM at 533 MHz 160GB Serial ATA Hard Drive (7200RPM) 256MB ATI Hyper Memory PCI-Express X16 (DVI/VGA/TV out) Radeon X600 SE video card Intel Pro 100M Integrated PCI NIC Card Trend Micro PC-cillian anti-virus & anti-spyware Thanks! |
|
|
May 18 2008, 11:31 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 41,926 From: Dublin OS: XP |
Ok I would recommend that you post this problem in the Windows XP forum
Tell them I sent you over Once they have you logging back in, come back here and we will remove the malware |
|
|
May 18 2008, 11:59 AM
Post
#7
|
|
|
New Member ![]() Posts: 6 From: Minneapolis OS: Windows XP Media Center Edition 2005 w/ SP2 |
Many thanks for your help and advice - with a little luck I'll be back soon!
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
0 / 283 | 21st June 2006 - 10:06 AM PegLeg1538 started - last by PegLeg1538 |
|||||
![]() |
19 / 1,046 | 29th June 2006 - 02:40 AM Xclusyv started - last by teacup61 |
|||||
![]() |
2 / 346 | 30th June 2007 - 11:20 PM Des0609 started - last by RiP |
|||||
![]() |
1 / 223 | 18th December 2008 - 06:54 AM tjhayesj started - last by Octagonal |
|||||
|
Time is now: 9th February 2010 - 09:06 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising