From: Erimyalcin on
Hi,

I 've got the following blue screen message :

' STOP: 0x0000007E (0XC0000005,0XF39145B8,0xF12EEC24,0xF12EE920)


V00080EVX.sys

- Address F39145B8 base at F3914000, DateStamp 40ad9c32

'

is there any hotfix for this problem ?

I've recently used vendor repair cd (come up with the computer Medion).

Any help , I'll appreciate. is there any microsoft fix for this problem?

Regards,

Erim



Logfile of HijackThis v1.99.1
Scan saved at 10:30:38 AM, on 26/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\CNYHKey.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\mHotkey.exe
C:\KillWin\KillWin.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\Dit.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.addgoo.com/default.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,AutoConfigURL = http://localhost:9100/proxy.pac
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}
- C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} -
C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: &Google Web Accelerator Helper -
{69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web
Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper -
{9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common
Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Google Web Accelerator -
{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web
Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop
Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kill Win] C:\KillWin\KillWin.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKCU\..\Run: [WeatherEye] "C:\Program
Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat
7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\Nero
PhotoShow 4\data\Xtras\mssysmgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky
Lab\Kaspersky Anti-Hacker\KAVPF.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program
Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program
files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program
files\google\GoogleToolbar1.
From: Falcon on
Erimyalcin wrote:

> Hi,
>
> I 've got the following blue screen message :
>
> ' STOP: 0x0000007E (0XC0000005,0XF39145B8,0xF12EEC24,0xF12EE920)
>
>
> V00080EVX.sys
>
> - Address F39145B8 base at F3914000, DateStamp 40ad9c32
>
> '
>
> is there any hotfix for this problem ?
>
> I've recently used vendor repair cd (come up with the computer Medion).
>
> Any help , I'll appreciate. is there any microsoft fix for this problem?
>
> Regards,
>
> Erim
[...]

This is not the place to post hijackthis logs, however from a brief look at
the information you provided it's obvious that your machine is heavily
infected with malware. Please go to
http://www.bleepingcomputer.com/forums/topic34773.html and follow the
instructions.

--
Falcon:
fide, sed cui vide. (L)


From: moose on
Erim,

You must have some pretty good hardware to support all that you have running
on your machine. I recently had some problems after I installed google web
accelerator.
The machine would lockup the unlock continually, had to shut down with the
push and hold method.

I would suggest that you uninstall all of your accelerators and browser
helpers, then dump your browsers cache file. It might be a good time to check
some of the other programs you have loaded and see if you can live without
them. Once this is done, do a thourough scan of your system for spyware (you
have some) and if you don't have it yet, get CCleaner at any download site
(it is free) and use it to clean up your machine.
CCleaner will also repair issues with your registry. Just don't forget to
Back it Up>

Good Luck!

"Erimyalcin" wrote:

> Hi,
>
> I 've got the following blue screen message :
>
> ' STOP: 0x0000007E (0XC0000005,0XF39145B8,0xF12EEC24,0xF12EE920)
>
>
> V00080EVX.sys
>
> - Address F39145B8 base at F3914000, DateStamp 40ad9c32
>
> '
>
> is there any hotfix for this problem ?
>
> I've recently used vendor repair cd (come up with the computer Medion).
>
> Any help , I'll appreciate. is there any microsoft fix for this problem?
>
> Regards,
>
> Erim
>
>
>
> Logfile of HijackThis v1.99.1
> Scan saved at 10:30:38 AM, on 26/08/2006
> Platform: Windows XP SP2 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\Program Files\Ahead\InCD\InCDsrv.exe
> C:\WINDOWS\Explorer.EXE
> C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
> C:\WINDOWS\system32\CNYHKey.exe
> C:\WINDOWS\system32\rundll32.exe
> C:\WINDOWS\system32\mHotkey.exe
> C:\KillWin\KillWin.exe
> C:\WINDOWS\system32\RunDll32.exe
> C:\Program Files\iTunes\iTunesHelper.exe
> C:\WINDOWS\eHome\ehRecvr.exe
> C:\WINDOWS\ehome\ehtray.exe
> C:\WINDOWS\eHome\ehSched.exe
> C:\Program Files\ewido anti-spyware 4.0\guard.exe
> C:\WINDOWS\system32\Dit.exe
> C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
> C:\WINDOWS\system32\ctfmon.exe
> C:\PROGRA~1\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr.exe
> C:\Program Files\Common Files\LightScribe\LSSrvc.exe
> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
> C:\WINDOWS\system32\nvsvc32.exe
> C:\WINDOWS\system32\HPZipm12.exe
> C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
> C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
> C:\WINDOWS\system32\svchost.exe
> C:\Program Files\UPHClean\uphclean.exe
> C:\WINDOWS\System32\ups.exe
> C:\Program Files\iPod\bin\iPodService.exe
> C:\WINDOWS\system32\dllhost.exe
> C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
> C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
> C:\WINDOWS\system32\mmc.exe
> C:\Program Files\Skype\Phone\Skype.exe
> C:\WINDOWS\system32\SNDVOL32.EXE
> C:\WINDOWS\system32\cmd.exe
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\WINDOWS\system32\taskmgr.exe
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\Program Files\Hijackthis\HijackThis.exe
>
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://www.addgoo.com/default.asp
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
> Settings,AutoConfigURL = http://localhost:9100/proxy.pac
> R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}
> - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
> O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
> O2 - BHO: Adobe PDF Reader Link Helper -
> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
> 7.0\ActiveX\AcroIEHelper.dll
> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
> C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
> O2 - BHO: &Google Web Accelerator Helper -
> {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web
> Accelerator\GoogleWebAccToolbar.dll
> O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
> C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
> O2 - BHO: Windows Live Sign-in Helper -
> {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common
> Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
> O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
> c:\program files\google\googletoolbar1.dll
> O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
> O3 - Toolbar: Google Web Accelerator -
> {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web
> Accelerator\GoogleWebAccToolbar.dll
> O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
> files\google\googletoolbar1.dll
> O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
> O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
> -atboottime
> O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
> C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
> O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
> O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop
> Album Starter Edition\3.0\Apps\apdproxy.exe"
> O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
> O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
> O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
> C:\WINDOWS\system32\NvCpl.dll,NvStartup
> O4 - HKLM\..\Run: [Kill Win] C:\KillWin\KillWin.exe
> O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
> O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
> O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
> O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
> O4 - HKLM\..\Run: [Dit] Dit.exe
> O4 - HKCU\..\Run: [WeatherEye] "C:\Program
> Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe"
> O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat
> 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
> O4 - HKCU\..\Run: [ctfmon.
From: Ron Martell on
Erimyalcin <Erimyalcin(a)discussions.microsoft.com> wrote:

>Hi,
>
>I 've got the following blue screen message :
>
>' STOP: 0x0000007E (0XC0000005,0XF39145B8,0xF12EEC24,0xF12EE920)
>
>
>V00080EVX.sys
>
> - Address F39145B8 base at F3914000, DateStamp 40ad9c32
>
>'
>
>is there any hotfix for this problem ?
>
>I've recently used vendor repair cd (come up with the computer Medion).
>
>Any help , I'll appreciate. is there any microsoft fix for this problem?
>
>Regards,
>
>Erim
>

There are seldom if ever hotfixes for problems that are caused by
non-Microsoft software or hardware.

Your problem is being caused by a file named V00080EVX.sys which is
not a standard Windows component. In fact a Google web search fails
to turn up a single reference to anything named V00080EVX.sys or
V00080EVX which indicates that it is either a virus/trojan/spyware
related item or it is some sort of custom software that is not widely
used.

Search your harddrive for files named V00080EVX and see what it finds.
If a file or files with that name are found, right-click on the file
name, select Properties and go to the Version tab. The information
there will tell you who created the file and what application it
belongs to. At least it will if it is a legitimate file. Contact
them for assistance with your problem.

Good luck
Ron Martell Duncan B.C. Canada
--
Microsoft MVP (1997 - 2006)
On-Line Help Computer Service
http://onlinehelp.bc.ca
Syberfix Remote Computer Repair

"Anyone who thinks that they are too small to make a difference
has never been in bed with a mosquito."