The Bsod Is Killing Me.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ksadeckas, Feb 9, 2016.

  1. ksadeckas

    ksadeckas Private E-2

    I got my Defender fixed and Smart Screen. I went through the full check up and then went about 30 hours without a BSOD, then I plugged in my phone to transfer a file and BAM! the BSOD. Attached are the required files. I am holding off loading WhoCrashedFree unless you say it OK, since the full check up instructions say not to load anything. Please let me know if I should.

    I will upload the Malwarebytes log in the next message, I am limited to 5.

    I appreciate your help.
     

    Attached Files:

  2. ksadeckas

    ksadeckas Private E-2

    I am trying to attach a malware report, but the system says it has the wrong extension (xml) so I opened and saved it in Word as text. Please tell me if I need to do something different. I am also attaching the latest crash report. Thanks.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Yes for Malware Bytes you need to follow the instructions carefully to obtain a log.

    See my screenshot for help. You want to save as .txt
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, do you want to upload the log from Malware Bytes please?
     
  5. ksadeckas

    ksadeckas Private E-2

    Kestrel, here are 2 reports. one which I ran from the history before I ran MB again and one after. I hope this is what you need. Thanks for your help.
    Ken
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.



    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Hidden.ADS][Stream] C:\Windows\SysWOW64:Win32App_1 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman Pro and have it remove all that it finds. Except Hola if you use it.

    Re run Malware Bytes and let it remove anything else it may find.

    Give Ccleaner a run, to be rid of some temp files.


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  7. ksadeckas

    ksadeckas Private E-2

    Thanks, Rogue Killer did not report the file you identified I needed to delete and did not automatically produce the report: RKreport[2].txt, But I clicked on REPORT and generated the attached file RGReport 2-13.txt. I hope this has the info you need.

    I was able to add the fixME.reg line to registry.

    When I ran JRT, I got an error message, it is attached as a png file in case it matters. I also got a warning from Hijack This, also posted as a png.

    I think I did everything that you listed. Please let me know if I need to do anything else. Thanks for your help.

    Ken from Atlanta
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  9. ksadeckas

    ksadeckas Private E-2

    Here are the 2 files. I am glad you understand them.. Thanks
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing anything else to do here in in this forum. I suggest you post about the BSOD in the software forum. Best of luck!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  11. ksadeckas

    ksadeckas Private E-2

    Thanks for your help. I have not had any problems since you have been involved, I have my fingers crossed.
    Best to you.
     
    Kestrel13! likes this.
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds