2

My computer has blue screened on and off over the past week or so and a system restore had fixed this up until yesterday.

Yesterday I noticed that Norton Antivirus kept sending a notification that it had blocked an attack from a host website blah blah blah with a high risk and that no action was needed.

This was the third time this week I had seen this, and a google search lead to a post on the symantec forums by a guy with the same issue. I read that it might be a virus attempting to download other viruses from malicious sites. So I decided to run a full system scan.

I clicked on my Norton Icon in the bottom right hand corner of the screen and the action center popped up, then disappeared. I tried opening every known shortcut to the program and nothing worked. So I opened up the Norton recovery tool and my computer blue screened with the stop error 0x0000001E. I have a picture of all the other codes following that if needed. There was no error code in text. So I booted into safe mode and ran a full system scan which worked fine and found 30 tracking cookies -__- which of course mean nothing. I did a system restore to the 22nd and then used Mbam in normal mode.

Side note - Norton also had been sending notifications for high cpu usage by winrscmde.

I scanned with Malwarebytes and it detected a bunch of stuff, two of which were Trojans in Windows/Svchost.exe so I deleted them all then restarted. On the first restart it showed a black screen with Cursur so I forced it to shutoff and then I started it up again an it said svchost was trying to start so I quarantined it but I still couldn't open Norton.

Further reasearch lead me to download and run TDSS Killer by Kaspersky.

Resolution -

I ran TDSS killer and it detected and quarantined the svchost.exe virus, it disappeared from the windows folder for good. This looks like the only resolution to getting rid of the virus.

It's all summed up in this tutorial on how to remove the virus: http://averablog.blogspot.com/

4
  • is the "0x0000001E" error followed by a *.sys file? if so, deactivate the driver associated to it, then, run sfc /scannow from an elevated command prompt. Commented Dec 26, 2012 at 16:02
  • No its just followed by a bunch of other codes in parentheses.
    – Nick
    Commented Dec 26, 2012 at 16:07
  • 1
    i would, then, follow the suggestions/possible answers other people posted below. they may (and probably) prove successful. (scanning with an AV at boot). Commented Dec 26, 2012 at 16:10
  • 1
    Post your solution as an answer - or more properly a comment on the accepted answer. There's also no need to add "Solved" or "Resolved" to the title. The fact you have accepted an answer shows that the problem is solved to your satisfaction.
    – ChrisF
    Commented Jan 4, 2013 at 13:39

3 Answers 3

2

This does sound like virus activity. I would run a full scan of Malwarebytes and see what that finds.

Other scans you could run include:

3
  • Malwarebytes is still scanning but it said it blocked an outgoing call by svchost.exe, then about 5 minutes later is said it stopped svchost.exe from starting and i quarantined it, it labeled it as a trojan. does it sound familiar?
    – Nick
    Commented Dec 26, 2012 at 16:29
  • yep :) Malwarebytes has fixed many computers with similar problems for me Commented Dec 26, 2012 at 16:30
  • TDSS killer did it
    – Nick
    Commented Jan 3, 2013 at 22:58
3

Have you tried another anti virus scanner?
Ideally a portable one (the risk to get blocked by a potential virus is lower).
Here are some portable anti virus scanner from my emergency stick

4
  • Malwarebytes is still scanning but it said it blocked an outgoing call by svchost.exe, then about 5 minutes later is said it stopped svchost.exe from starting and i quarantined it, it labeled it as a trojan. does it sound familiar?
    – Nick
    Commented Dec 26, 2012 at 16:33
  • Is it definately svchost.exe? Some virii/trojans call themselves eg. scvhost.exe (note the different spelling) to 'hide' in the task list.
    – DaveP
    Commented Dec 26, 2012 at 16:41
  • yeah it said svc host, and said it quarantined it. The scan just finished and it says it found 2 trojan.agents in windows/svchost.exe delete them?
    – Nick
    Commented Dec 26, 2012 at 19:01
  • 1
    It sounds like this is it answers.yahoo.com/question/index?qid=20120331135252AAQUKIV
    – Nick
    Commented Dec 26, 2012 at 19:02
0

Uninstall current antivirus by accessing task manager you can open task manager even your screen is black, press CTRL+Shift+Esc GO TO file > new task > and type control panel it will open control panel and uninstall current antivirus from Program & Feature. Restart > try some another antivirus live avg, avast, or Comodo Internet Security 6 BetaCIS 2013 which(Comodo already mention that they fix this black screen error.)

You must log in to answer this question.

Not the answer you're looking for? Browse other questions tagged .