Welcome Guest ( Log In | Join )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Want to ask a question, reply to a topic, or remove all advertising? It's easy, fast and free. Join today!
Spyware, virus, trojan, fake security or privacy alerts? Please start with our malware cleaning guide.
     
 
Closed TopicStart new topic
Trojan.Vundo; virtumonde; BSOD, STOP OxOOOOOO7A, Event log ID's 7
lucing1
post Nov 16 2008, 12:27 AM
Post #1


New Member
*
Posts: 2
OS: Windows XP



I started getting the BSOD about 10 days ago. The stop was 0x0000007A followed by 0xc03E098, 0xc000000E, 0xF842650C, 0x1ABA1860.

The event log showed error ID's number 7 and 51 repeatedly. I ran Check Disk which "bombed" before it finished. I updated the BIOS in response to Windows' Knowledge Base advice.

I took the computer to Best Buy's Geek Squad. Their Diagnostics indicated that the computer is infected with Virtumonde. They told me that was probably the cause of the BSOD and disk error messages.

Following the instructions on this forum I downloaded Malwarebytes anti malware which found the Trojan.vundo virus. I also downloaded Avast and ran the boot scan, which bombed. I removed McAfee and Spyware Doctor from the computer, turned off system restore and ran Malwarebytes in Safe Mode. It didn't find any more viruses. I turned on system restore again.

Meanwhile the event log continues to show the errors 7 and 51. I ran check disk and it bombed again. I am not sure if I have a hardware problem or if the virtumonde virus is still on my computer and causing all the trouble.

Before posting this message I ran the Erund software again to back up the registry and got an "error saving file message" that said there was an I/O error and it could not save the file named ....Users\00000001\USERS\DAT!. I did another backup (in addition to the sysrestore) using the XP back up utility to be sure I had a registry backup.

I don't know if the hard disk really has a problem or if the virtumunde virus is still present on this computer. Please advise me on what you think I should do next.

Thank you!

This post has been edited by lucing1: Nov 17 2008, 09:45 AM
Go to the top of the page
 
+Quote Post
emeraldnzl
post Nov 22 2008, 03:19 PM
Post #2


Trusted Helper
Group Icon
Posts: 3,299
OS: XP Pro



Hello lucing1,

Welcome to Geekstogo.

Sorry for the delay.

Now lets have a look at things on your computer.

  • Please download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Go to the top of the page
 
+Quote Post
emeraldnzl
post Nov 28 2008, 05:14 PM
Post #3


Trusted Helper
Group Icon
Posts: 3,299
OS: XP Pro



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   0 / 442 9th December 2007 - 04:12 PM
arnoota started - last by arnoota
No new   17 / 3,128 20th January 2008 - 09:21 AM
Krib started - last by kahdah
No New Posts   2 / 288 6th February 2008 - 07:30 AM
dmb60614 started - last by Rorschach112
No new   16 / 228 5th January 2009 - 08:12 AM
nessa718 started - last by Fred21543

RSS Time is now: 8th January 2009 - 02:25 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.