Tech Support Forum banner
Status
Not open for further replies.
1 - 2 of 2 Posts

· Registered
Joined
·
5 Posts
Discussion Starter · #1 ·
Hello,
I have a friend's computer that was infected with a rogue antivirus software...I believe it was called Security Essentials, or something along those lines. It hid everything on the desktop, as well as the start menu, and shut down task manager, Microsoft Security Essentials, etc. I booted into safe mode and I was able to remove the infections using Malwarebytes and SuperAntiSpyware...I ran Rkill from bleepingcomputers.com first, and afterwards I ran RogueKiller to unhide the hidden folders, start-menu items etc.
Already before I had done this the computer was crashing, but I thought that this was probably just caused by the infection. But even after the infection has been removed, it still keeps doing this. I opened a crash-dump and it seems to point to http.sys. I've already ran checkdisc, as well as sfc /scanboot, and nothing has fixed the issue yet. I also tested the memory, but that all showed as being good.
I somewhat suspect a driver somewhere, because I never had it crash on me while running in safe-mode.
Computer Specs:
Windows XP Pro SP3
Dell Vostro 200
Intel Core 2 Duo E450D
3.25 GB RAM

I also have a hijackthis log, and the results from a crash dump that I opened in windows debugger if anybody would find them useful
 

· Global Moderator
Using Google to solve problems
Joined
·
45,006 Posts
BSOD caused by http.sys may be caused by bad memory. Download the ISO image for Memtest in my signature and burn the image to CD using IMGBurn also in my signature. Remove all but one stick of RAM and boot off of the newly created CD. Run the tests on each stick of RAM separately. If you get any errors (red) that stick is bad and needs to be replaced.
I would still suspect that the computer is still infected. Due to Forum Rules we cannot comment or assist on Virus Removal here. Please click on the link in my signature for Virus/Malware Help and do those things in Safe Mode, and post your HiJackThis log in that section of the Forum. Once it is deemed that the computer is clean, if you are still getting BSOD's run this program BSOD_XP_v1.3_jcgriff2_PROD.exe. and go to My Documents and zip up the file TSF_XP_SUPPORT and attach that in your next post here. That will include all your mini-crash dumps and tell us more about your computer.
 
1 - 2 of 2 Posts
Status
Not open for further replies.
Top