What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
 
Closed TopicStart new topic
> [Closed] Serious virus problem
urbanwerebear
post Feb 11 2009, 09:35 PM
Post #1


New Member
*

Group: New Member
Posts: 2
Joined: 11-February 09
Member No.: 84,142
Operating System: Vista, XP



Okay, this is a nasty one. Virus infection on a Compaq laptop running XP. It's so bad the laptop will not even start on safe mode unless you're working from the command prompt. Ohterwise, the desktop wallpaper comes up with no icons, then BSOD.

BSOD display reads-

A problem has been detected and Windows has been shut down to prevent damage to your computer.

The problem seems to be caused by the following file: ndisio.sys

DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS

If this is the...

...select safe mode.

Technical Information:

*** STOP: 0x000000CE (0xF975384D, 0x00000008, 0xF975384D, 0x00000000)

ndisio.sys
Beginning dump of physical memory
Physical memory dump complete.
Contact your system administrator or technical support group for further assistance.




This apparently started when my friend got a pop-up for an update to Spyware Guard 2008. She downloaded and installed the "update", and this was the result.

Can't get online with the laptop, and I'm not sure I can install anything from CD yet. We're trying to find the restore CD and, failing that, an XP install CD to reinstall after format.

I've tried the Advanced Options menu, and Safe Mode with Command Prompt is the only one which works. I'm not willing to delete the file that is supposedly causing the problem, since I don't know what it does and don't know if that's really where the problem is.

I hope someone can help with this.

Urban Werebear
Go to the top of the page
 
+Quote Post
ken545
post Feb 15 2009, 05:07 PM
Post #2


Forum God
Group Icon

Group: Classroom Teacher
Posts: 11,319
Joined: 3-December 04
From: Darien, Connecticut
Member No.: 19,436
Operating System: Win 7 Ultimate
Win Xp Home SP3

MVP


Hello urbanwerebear

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


SpywareGuard by JavaCool <---is a respected program
Spyware Guard 2008 <--This is a trojan

ndisio.sys <-- This is a backdoor trojan that lets other garbage in.

You need to get the CD and do a System Repair, then post a HJT log and lets see where we stand

Download Trendmicros Hijackthis to your desktop.
  • Double click it to install
  • Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the Submit Reply and not start a New Thread.

DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Go to the top of the page
 
+Quote Post
urbanwerebear
post Feb 15 2009, 09:21 PM
Post #3


New Member
*

Group: New Member
Posts: 2
Joined: 11-February 09
Member No.: 84,142
Operating System: Vista, XP



Cool. Thanks for the help so far.

I should have an update within a couple of days. I work weekends, so Tuesday will be the earliest I can work on the laptop again.
Go to the top of the page
 
+Quote Post
ken545
post Feb 23 2009, 03:42 AM
Post #4


Forum God
Group Icon

Group: Classroom Teacher
Posts: 11,319
Joined: 3-December 04
From: Darien, Connecticut
Member No.: 19,436
Operating System: Win 7 Ultimate
Win Xp Home SP3

MVP


Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic

 


RSS Time is now: 21st March 2010 - 06:14 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy