I had no choice but to use system restore as i was unable to boot into normal mode or any safe modeThe BSODs appeared early in the boot sequence and just flashed up for a split second before re-starting the machine, so I couldn't tell you what they said....
When I first had the problems, I was only getting BSODs when booting into normal mode. They were either Bad Pool Caller, or IRQ Less Than Equal errors, both with the file NDIS.sys
I have a corporate version of symantec AV on the laptop (it's an old work laptop) which I can't seem to uninstall even as administrator. This is especially annoying as it now seems to be corrupted. But I asssume it's still best not try another AV prog as well if symantec is on the system?
I also can't install AVG Anti-spyware as it won't run on 64 bit windows.
I've just re-booted successfully into safe mode and am currently running the spybot scan, once that finishes I'll try re-booting into normal mode again (fingers crossed!) and post a new HJT log.
For reference, below is a log of what Symantec AV has quarantined since the problems appeared:
Date,Filename,Threat,Original Location,Status
5/9/2007 11:42:19 PM,tmp286.tmp.dll,Trojan.Vundo,C:\WINDOWS\system32 \,Infected
5/9/2007 11:41:50 PM,sony.exe.exe,Trojan Horse,C:\WINDOWS\system32\,Infected
5/9/2007 11:41:47 PM,sony.exe,Trojan Horse,C:\WINDOWS\system32\,Infected
5/9/2007 10:56:11 PM,sony[1].exe,Trojan Horse,C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\67QRSW0G\,Infected
5/9/2007 10:54:21 PM,wnset.exe,Trojan.Adclicker,C:\Documents and Settings\Administrator\Local Settings\Temp\,Infected
5/13/2007 5:12:52 PM,ndis.sys,Hacktool.Rootkit,C:\WINDOWS\system32\d rivers\,Infected
5/4/2007 12:59:30 AM,poof,Hacktool.Rootkit,C:\WINDOWS\system32\,Infe cted
5/4/2007 12:58:31 AM,kprof,Hacktool.Rootkit,C:\WINDOWS\system32\,Inf ected
5/4/2007 12:58:31 AM,koos.exe,Trojan.Alpiok,C:\WINDOWS\system32\,Inf ected
5/4/2007 12:58:23 AM,ipv6monl.dll_tobedeleted_old,Infostealer.Bzup,C :\WINDOWS\system32\,Infected
5/4/2007 12:10:48 AM,old-winlogon.exe,W32.Grum.A,C:\Documents and Settings\Administrator\Local Settings\Temp\,Infected


The BSODs appeared early in the boot sequence and just flashed up for a split second before re-starting the machine, so I couldn't tell you what they said....
Reply With Quote