Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown Malware on Multiple Computers


  • Please log in to reply
No replies to this topic

#1 Netwit

Netwit

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 18 April 2011 - 09:28 PM

Hello,

I'm an IT Manager for a medium sized company.

I've fought this problem for a solid week. It's occuring on about a dozen computers out of 150, all Windows XP Professional Service Pack 2.

They get the following error in a window:

ERROR: 16 bit MS-DOS Subsystem
C:\WINDOWS\system32\a.exe
The NTVDM CPU has encountered an illegal instruction. (etc)

(Buttons to select "Close and Ignore") If the user clicks "Ignore" NTVDM will use from 20 to 50 cpu dealing with it, evenually slowing it to a craw if ignore is pressed repeatedly. If "Close" is pressed life goes on as usual till the next error.

After the 16 bit error window our Trend Micro Worry Free Business Antivirus comes up with one or more websites it blocked.

I can delete the a.exe file and in 10 minutes to an hour it will reappear.

I've run Malwarebytes, Kaspersky Virus Removal Tool, Trend Micro Sysclean, Macafee Stinger, Combofix, Trend Micro Housecall, Norton System Scan, OTL.exe, RKill and others. They find some malware but the problem continues.

None of the affected machines seem to be on tonight so I can't connect to them from home as I usually can. I can post results from them tommorrow. I'll recheck the post then.

I would appreciate any help offered. Thanks in advance.

Edit: Moved topic from XP to the more appropriate forum. ~ Animal

BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users