ClickRight
Member
- Reaction score
- 18
- Location
- BC, Canada
I have a computer which came in with complaints of slowness and spyware.
First thing I did was throw 2GB of RAM in to the machine (It's a Gateway with only 1GB running Vista.)
When I first booted it, all I got was a black screen with a cursor. It's running Vista X86 WITH NO SERVICE PACKS (they won't install!)
I booted in safe mode and immediately found some spyware (Personal AV.) I ran through Combofix which found the UAC rootkit and a couple other things. (I was going to attach the log to this post, but when I went to open it Notepad says "The process cannot access the file because it is being used by another process" even though nothing is running and Unlocker can't unlock it.)
Anyways, I ran through ComboFix TWICE, MBAM TWICE, and did a manual check. MBAM found a few more pieces of the UAC rootkit, and Personal AV. My manual search returned nothing.
Now the problems:
Anyways, I'm going to run some rootkit scanners and see what I can come up with. Sorry for the lack of details in the post, it's time for bed and I've had it with this computer. I'll add more details when I have a better idea of what's going on.
First thing I did was throw 2GB of RAM in to the machine (It's a Gateway with only 1GB running Vista.)
When I first booted it, all I got was a black screen with a cursor. It's running Vista X86 WITH NO SERVICE PACKS (they won't install!)
I booted in safe mode and immediately found some spyware (Personal AV.) I ran through Combofix which found the UAC rootkit and a couple other things. (I was going to attach the log to this post, but when I went to open it Notepad says "The process cannot access the file because it is being used by another process" even though nothing is running and Unlocker can't unlock it.)
Anyways, I ran through ComboFix TWICE, MBAM TWICE, and did a manual check. MBAM found a few more pieces of the UAC rootkit, and Personal AV. My manual search returned nothing.
Now the problems:
- CONSTANT 0x00000050 BSODS
- I have looked at the minidumps but couldn't interpret them. None specified a driver and they all specified "ntkrpamp.exe" as the IMAGE_NAME.
- This happens randomly, but most often during a windows update.
- I have updates all the drivers (Chipset, video, NIC)
- I have TESTED (Memtest - overnight) and REMOVED the 2GB of RAM I added - the problem persists.
- Windows updates will not install
- I tried to install Vista SP1, which gave a "0x80070002" error code. of course I gogled it but only got MS's advise which I couldn't make work and a bunch of people with ideas but no concrete solution. I'm still exploring some of these.
- Automatic updates always fail and are usually interrupted by BSODs.
- The updates you download are corrupt as well. For example, I downloaded the "Vista updates readiness tool" and when I launch the installer it says: "Installer encountered an error: 0x80070000d. The Data is invalid"
- Most downloads are corrupt
- For example, when I downloaded the graphics drivers, explorer refused to extract them and 7-zip threw an incomplete archive error. Downloading them again worked.
- ALl downloaded windows updates produce an error during installation, whether downloaded from IE or Firefox.
- HOWEVER, I downloaded and installed Firefox just fine.
- I can't initiate a download from some websites in IE, but they will work in Firefox also.
Anyways, I'm going to run some rootkit scanners and see what I can come up with. Sorry for the lack of details in the post, it's time for bed and I've had it with this computer. I'll add more details when I have a better idea of what's going on.
Last edited: