Running WinXP on a Gateway system with no viruses, malware, adware, etc. I am getting the BSOD only when connecting to the Internet. After each reboot, I get the same error codes and Kypkjts- address F8AEF484. There is no mention of any devices. I uninstalled my Intel Pro/100 VE Network card, reinstalled, looked for updated drivers, etc. There is no hardware attached, no USB devices, and no conflicts in Device Manager. If I unplug my Ethernet cable, the computer runs fine. With the Ethernet cable attached, the BSOD appears seconds after clicking on the IE 6.0 icon on my desktop.
Thanks.
Adam
cpc2004
08-10-2005, 12:22 AM
When Windows crashes with blue screen, it writes a system event 1001 and a minidump to the folder \windows\minidump
Check system event 1001 and it has the content of the blue screen
Event ID: 1001
Source: Save Dump
Description:
The computer has rebooted from a bugcheck.The bugcheck was : 0xc000000a (0xe1270188, 0x00000002, 0x00000000, 0x804032100).
Microsoft Windows..... A dump was saved in: .......
Control Panel -> Adminstrative Tools -> Event Viewer -> System -> Event 1001. Copy the content and paste it back here
Zip 5 to 6 minidumps and attach the zip files here. I will study the dump and find out the culprit.
Ad
08-10-2005, 12:22 AM
amstuart
08-10-2005, 09:58 AM
Hi:
Sorry for the quick question. What program should be used to open the .dmp files? MS Word allows Windows Default, MS-DOS, or other encoding: the majority of the text is nonsense characters for any choice. Notepad and Wordpad also yield nonsense characters.
Thanks.
cpc2004
08-10-2005, 11:36 AM
microsoft windbg
amstuart
08-10-2005, 11:42 AM
Hi:
Attached are 5 minidmp files. Hoping to hear good news.
Thank you.
Adam
cpc2004
08-10-2005, 12:56 PM
This is the third time I handle this problem. Your windows is infected with virus. The time stamp of failing module of kypkjts is the same as the failing module of the following case.
http://www.computing.net/windows2000/wwwboard/forum/62004.html
If you search kypkjts at google, you cannot find any hit. I also find the same problem at exchange-experts.
http://www.experts-exchange.com/Operating_Systems/WinXP/Q_21412430.html
Debug report of your minidumps
BugCheck A, {fb4c0000, 2, 0, 804db48c}
Probably caused by : kypkjts ( kypkjts+479 )
f8aef000 f8af05e0 kypkjts kypkjts Mon Apr 18 22:31:48 2005 (4263C4D4)
Run antivirus to make sure this windows does not infect with virus. Get rid of kypkjts.
amstuart
08-10-2005, 01:11 PM
I appreciate the quick analysis. Since this is your thirs experience with this BSOD message, do you know which virus the OS was infected with? I have run updated Norton antiviral scans, MS Beta antispyware, Spyware Search and Destroy, Spyblaster is installed and updated, and WinPatrol is installed.
I have GOOGLEd kypkjts+479 and can't find anything.
Thanks.
cpc2004
08-10-2005, 01:25 PM
This virus rename the infected module to another name. For your case it is kypkjts. For the another case at expert exchange, the infected module name is woouhwq. From the stack trace, the infected module is a network module. Unfortunately the problem owner at Computing.net never respond to my message. You may install hijackthis and post your hijackthis log here. You can find a lot of posts of hijackthis at this forum.
Another hit of the same problem and the infected module is wwackxt
http://forums.tomcoyote.org/Help_Badly_Infected_Computer-t35912.html
Logfile of HijackThis v1.99.1
Scan saved at 12:43:08 PM, on 8/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Your hijackthis analysis report
http://www.hijackthis.de/logfiles/5252a35a435f0833cdbdac3d55fc6a67.html
Remove the following unknown processes and application
C:\WINNT\system32\wbphj\rvkjlui.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrolEx.exe
C:\Program Files\Norton AntiVirus\NAVW32.EXE
C:\WINNT\System32\brckpc.exe
C:\WINNT\system32\whrobnwx\mbgo.exe
Ad
08-11-2005, 09:07 AM
amstuart
08-11-2005, 09:28 AM
Hi:
Ran Ewido Trojan's/Malware Remover in SAFE mode, cleaned the Prefetch folder, deleted the HijackThis items that were bulleted, re-ran AdAware, cleaned temp files, ran Killbox, ran Cleanup!, and re-ran HijackThis. These entries remain:
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
Not sure whether to try connecting the computer to the Internet or manually remove the above two items first?
Adam
amstuart
08-11-2005, 10:41 AM
Hi:
Thank you for getting my computer back in business! I manually deleted the remaining items with KillBox.exe and everything appears fine after connecting to the Internet.
A million thank-you's for your time and patience.
Adam
nicofede
08-12-2005, 01:40 PM
Hi,
I found the same issue since I installed an ADSL modem on my desktop: at my first access on the web I got the problem.
Some people on the net argued that the problem could reise from a driver conflict of the different modems. I disabled all modems but the ADSL one, and I still get the error. Yet, this only happens when I get online.
I updated and ran several times McAfee AV and Ad-Aware, cleaned up everything.
I installed Autoruns, but cannot find a suspected entry.
Do you have any suggestions?
amstuart
08-12-2005, 01:55 PM
Hi:
As the experts will admonish, what worked for me might not work for you, even though the Driver IRQL BSOD end-result is the same. The order of attack is important: look at topic 53181 on the Geekstogo forum. Post #2, written by Kc (Thatman) gave me great advice on how to solve the issue. I'm not sure how acceptable another forum's column would be to reproduce here (even though we are all friends), so email me privately and I can copy and paste the instructions if you would like.
Adam
amstuart@sprintmail.com
p1ishr
11-14-2005, 12:26 AM
Hello, I just finished installing a Netgear Gigabit Ethernet PCI card in a Dell Dimensions PC running MS Windows 2000 Pro and after rebooting, received the following BSOD (only if I'm physically connected to the cable/dsl router and the Internet connection is up:
Due to some odd occurances concerning the use of things Internet-enabled (mostly mail related such as MS Outlook and Yahoo Mail), I suspect a virus. Here are the results of running HiJackThis:
Logfile of HijackThis v1.99.1
Scan saved at 10:52:29 PM, on 11/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Also, here are the three zipped minidump files that were generated after three reboots with an active Internet connection present:
No entries have been deleted yet after running HiJackThis>
p1ishr
11-14-2005, 12:31 AM
Sorry...I sent the individual .dmp files instead of one .zip of all three...here is the zip:
cpc2004
11-14-2005, 12:53 AM
Hi,
One a new thread for a new problem.
bmdurr
11-15-2005, 01:11 AM
I continue to have problems with errors on device drivers and saw the Hijack This reference so ran the free download and resulted in identifying several high threats - so had to purchase software to remove. Here is the log from Hijack This. Anyone who can understand and advise if identified threats were causing the problems (major concerns with Trojan/CWS combo)? Sorry for all the stuff - I to delete alot not sure if took out valuable stuff.
<?xml version = "1.0"?>
<Session START = "14 Nov 05 20:16:15" END = "14 Nov 05 20:16:15">
<Information Version = "4.17" DatabaseVersion = "127" DataBaseDate = "8 Nov 2005"/>
<PROCESS NAME = "C:\WINDOWS\system32\services.exe" MD5 = "c6ce6eec82f187615d1002bb3bb50ed4"/>
<PROCESS NAME = "C:\WINDOWS\system32\lsass.exe" MD5 = "84885f9b82f4d55c6146ebf6065d75d2"/>
<PROCESS NAME = "C:\WINDOWS\system32\Ati2evxx.exe" MD5 = "d24907c31a3004a560385e5048c72dd7"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\spoolsv.exe" MD5 = "da81ec57acd4cdc3d4c51cf3d409af9f"/>
<PROCESS NAME = "C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" MD5 = "a80f0e7dc789150c3ae4f504e3b96b06"/>
<PROCESS NAME = "C:\Program Files\Network Associates\VirusScan\mcshield.exe" MD5 = "fe7985dae11fa70829762c5af39dbb27"/>
<PROCESS NAME = "C:\Program Files\Network Associates\VirusScan\vstskmgr.exe" MD5 = "dae0d925fa8d4aec46e924a136b93a32"/>
<PROCESS NAME = "C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe" MD5 = "331b69d20d0983b93baf2f7e6daebb80"/>
<PROCESS NAME = "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe" MD5 = "0efee4f2d23ba2d8b27fba942106e0e1"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\wdfmgr.exe" MD5 = "ab0a7ca90d9e3d6a193905dc1715ded0"/>
<PROCESS NAME = "C:\WINDOWS\System32\alg.exe" MD5 = "f1958fbf86d5c004cf19a5951a9514b7"/>
<PROCESS NAME = "C:\WINDOWS\system32\Ati2evxx.exe" MD5 = "d24907c31a3004a560385e5048c72dd7"/>
<PROCESS NAME = "C:\WINDOWS\Explorer.EXE" MD5 = "a0732187050030ae399b241436565e64"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe" MD5 = "3f261a8554d95d66009863dcff1b2f72"/>
<PROCESS NAME = "C:\Program Files\Intuit\QAgent\QAGENT.EXE" MD5 = "5b55861c2ce7d72d8e55f98ffbf95fb8"/>
<PROCESS NAME = "C:\WINDOWS\system32\carpserv.exe" MD5 = "ea3be7f5cdef0fe4df1bf6dbfe7abde0"/>
<PROCESS NAME = "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" MD5 = "b5eca5948d7f8eaa00333231f33ea31a"/>
<PROCESS NAME = "C:\WINDOWS\SOUNDMAN.EXE" MD5 = "d968b3259421c4a0627a62f4e0e96d6d"/>
<PROCESS NAME = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" MD5 = "c6fa9370324cde99ec1c3f4a22a9be56"/>
<PROCESS NAME = "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" MD5 = "7fdd96f93adbe7e986aabae0ca446011"/>
<PROCESS NAME = "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" MD5 = "e4a7b1aa1e40676153a824ac00ec3450"/>
<PROCESS NAME = "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" MD5 = "78915c3ad0024bacd46f41bf02ee4415"/>
<PROCESS NAME = "C:\Program Files\iTunes\iTunesHelper.exe" MD5 = "1c2b9fcd48112b0297b83e7fc43d1b42"/>
<PROCESS NAME = "C:\Program Files\QuickTime\qttask.exe" MD5 = "3e7d91f24d28c968b92c85c7e2882eed"/>
<PROCESS NAME = "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\Bin\HPOstr05.exe" MD5 = "1666422fbd939586b1e54edad87e3c94"/>
<PROCESS NAME = "C:\Program Files\iPod\bin\iPodService.exe" MD5 = "5590c0e3b40c924c2b94cb5868b8360a"/>
<PROCESS NAME = "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\bin\HPOVDX05.EXE" MD5 = "83fe7a2a31fab5afd2ba5ef8cb0bb530"/>
<PROCESS NAME = "C:\WINDOWS\system32\hpoipm07.exe" MD5 = "dac39ffd1bce3b239616226b47594ab4"/>
<PROCESS NAME = "C:\Program Files\Internet Explorer\iexplore.exe" MD5 = "e7484514c0464642be7b4dc2689354c8"/>
<PROCESS NAME = "C:\Program Files\XoftSpy\XoftSpy.exe" MD5 = "8107deb204f560cd5e8326d6364f56db"/>
<ScanningRegKeys>
</ScanningRegKeys>
<ScanningRegValues>
</SW>
<SW NAME = "Lycos Sidesearch">
<REGVALUE VALUE = "Lycos Sidesearch Software\Microsoft\Internet Explorer\extensions\cmdmapping\{000007c6-17df-4438-92a4-de5537471ba3}"/>
<REGVALUEFOUND NAME = "Software\Microsoft\Internet Explorer\extensions\cmdmapping\{000007c6-17df-4438-92a4-de5537471ba3}"/>
</SW>
<SW NAME = "Favoriteman">
<REGVALUE VALUE = "Favoriteman software\microsoft\windows\counter"/>
<REGVALUEFOUND NAME = "software\microsoft\windows\counter"/>
</SW>
<SW NAME = "Favoriteman">
<REGVALUE VALUE = "Favoriteman software\microsoft\windows\server"/>
<REGVALUEFOUND NAME = "software\microsoft\windows\server"/>
</ScanningRegValues>
<ScanningRegValuesChanged>
</ScanningRegValuesChanged>
<FILE PATH = "Trojan/CWS Combo C:\WINDOWS\system32\MSrev21.dll"/>
<FILE PATH = "C:\WINDOWS\system32\MSrev21.dll"/>
<FILE PATH = "Trojan/CWS Combo C:\WINDOWS\system32\MSrev41.dll"/>
<FILE PATH = "C:\WINDOWS\system32\MSrev41.dll"/>
<FILE PATH = "Favoriteman C:\WINDOWS\system32\vg.dat"/>
<FILE PATH = "C:\WINDOWS\system32\vg.dat"/>
</Scanning>
<Information Message = "Starting to Quarantine 61 Items"/>
<Quarantines>
<QTFILE PATH = "C:\Program Files\XoftSpy\Quarantine\Quarantine14-11-2005-20-30-50.xpy" />
<INFO ACTION = "Added"/>
<INFO TIME = "14-11-2005-20-30-50"/>
<REGVALUE RES = "{000007c6-17df-4438-92a4-de5537471ba3} = dword:00002008
">
<REGVALUE RES = "counter = dword:00000001
">
<REGVALUE RES = "server = www.f1organizer.com
">
<QInformation Message = "Quarantining File Trojan/CWS Combo - C:\WINDOWS\system32\MSrev21.dll"/>
<QInformation Message = "Quarantining File Trojan/CWS Combo - C:\WINDOWS\system32\MSrev41.dll"/>
<QInformation Message = "Quarantining File Favoriteman - C:\WINDOWS\system32\vg.dat"/>
<QInformation Message = "Quarantining File 247realmedia cookie -
<Removal>
<SW NAME = "Lycos Sidesearch">
<REGVALUE NAME = "Software\Microsoft\Internet Explorer\extensions\cmdmapping\{000007c6-17df-4438-92a4-de5537471ba3}"/>
<REGVALUE RES = "Successfully Removed"/>
</SW>
<SW NAME = "Favoriteman">
<REGVALUE NAME = "software\microsoft\windows\counter"/>
<REGVALUE RES = "Successfully Removed"/>
<REGVALUE NAME = "software\microsoft\windows\server"/>
<REGVALUE RES = "Successfully Removed"/>
</SW>
<SW NAME = "Trojan/CWS Combo">
<FILE NAME = "C:\WINDOWS\system32\MSrev21.dll"/>
<FILE RES = "C:\WINDOWS\system32\MSrev21.dll Successfully ReMoved"/>
<FILE NAME = "C:\WINDOWS\system32\MSrev41.dll"/>
<FILE RES = "C:\WINDOWS\system32\MSrev41.dll Successfully ReMoved"/>
</SW>
<SW NAME = "Favoriteman">
<FILE NAME = "C:\WINDOWS\system32\vg.dat"/>
<FILE RES = "C:\WINDOWS\system32\vg.dat Successfully ReMoved"/>