This is a read-only archive. No new posts or registrations. Privacy Page
Software

lsass.exe NTVDM CPU illegal instructions on starting Windows

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone, I have a Dell XPS that's about a year and a half old. It originally had Windows Vista 32-bit on it and I upgraded to Windows 7 32-bit a few months ago. Here's my problem. I had been away from my computer one afternoon when I came back… I could hear as if a ton of people were all talking at once through my spearkers. I opened the task manager and closed iexplorer.exe which was creating a sound output. Finally the voices stopped. I ran my virus checker and stuff… It came up with deleting a file svchost.exe or something. So… not sure if this post should be in the Spyware/Malware/Virus section or not but… Anyways. When I start my computer it goes to the login screen, I type my password and it goes to a black screen with the following error: C:\Users\THEGRA~1\AppData\Roaming\lsass.exe The NTVDM CPU has encountered an illegal instruction. CS:0000 IP:ffee OP:18 8b 0e b8 6b Choose "Close" to terminate the application. I am then stuck on the black screen with the mouse cursor. I am able to open the task manager with Ctrl-Alt-Delete and then use it to start new tasks (so as to open folders and applications). I ran HiJackThis and here's my log file or whatever. 📎HJT_for_GrandmasterJR.txt Everytime I try to restart computer I get the same error. I've tried booting with my Windows CD but it just wants to Install Windows or something… Can anyone help me?
Well apparently I fixed the issue myself here… I had never used HiJackThis before so I just went through and found the two entries that ended in lsass.exe and svchost.exe, clicked fix/repair or whatever and restarted. It seemed to work.
OK, you "fixed" it, but may not know precisely what it was that you caused to happen by using your HJT tool to perform the "fix". Actually, the machine may continue to be vulnerable. lsass.exe buffer overrun can allow remote execution of code from an attacker. Head on over to our Malware Removal Forum for assistance from one of our Specialists. In the meantime, do not use your machine for any online banking, business transactions or email sending/receiving. Best Regards
When I restarted the computer, I received a message stating that malicious software or whatever had been removed and that a worm had been detected/deleted. Would my computer still be vulnerable?

When I restarted the computer, I received a message stating that malicious software or whatever had been removed and that a worm had been detected/deleted. Would my computer still be vulnerable?


Maybe.

Was it Windows, or a specific utility that generated that message?
What detected/deleted the worm?
Can you produce the exact wording from the alert/message you received upon restarting your computer?

It would seem sensible for you to read the instructions, here, and then post to our Infections Removal Forum, here.
And that's what I recommend to you.

Best Regards

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI