Blue Screen error and auto restart during MG Tools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by factor_j, Aug 3, 2011.

  1. factor_j

    factor_j Private E-2

    Hi,

    Im running Win XP home edition 2002 SP3 on an eepc 1000HE w. 2GB RAM.

    I originally suspected a problem when having trouble with start-up. Power was going on, but only resulting in a black screen with flashing cursor. Turned off some quick boot options and was able to get it to start and load windows.

    I did some searching and reading on the web and noted that it was possibly being caused by a virus affecting the BIOS. An AVG scan came came up with nothing. A Spybot Search and Destroy scan reported virtumonde infections. I then downloaded Malwarebytes and ran a scan.

    There was still some performance issues after quarantine and removal by spybot and malwarebytes, and i noticed that my ISP's software interface was showing outgoing data out even when no browser was open.

    I then checked majorgeeksforums for similar issues previously posted. I have since run your READ THIS FIRST procedure. (please find logs attached). All steps were successfully run until MG Tools.

    At "I accept" for Trend Micro Hijack This i got an error:
    Unexpected error has occured at procedure:
    modRegistry_IniGetString(sFile=win.ini,sSection=windows,sValue=load)
    Error#5 - Invalid procedure call or augment​
    Computer crashed with blue screen error and restarted itself.

    It all happened so quickly, so I attempted to run MG Tools again. This time MGTools completed "running analyse.exe" and then "miscInfo.???" at which point blue ecreen error occured and the computer restarted. This was the same result after a number of attempts.

    I also tried running MG Tools in safe mode, but the computer froze each time.

    Can you please let me know if the pc is now clean of malware?
    In whihc case I may still have a hardware or bios issue?

    Thanks so much for the a great resource and service.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The C:\MGlogs.zip from MGtools will still exist. Please attach it.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also run the below steps.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller



    Now please also download MBRCheck to your desktop.
    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. factor_j

    factor_j Private E-2

    Great.

    TDS Killer found a Root Kit.

    Please find attached:
    - MG Tools logs
    - TDS Killer log
    - MDR Check log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Run it one more time and attach the new log so that we can be sure it was able to remove the infection.

    Also tell me how things are currently working?
     
  6. factor_j

    factor_j Private E-2

    I had run it again yesterday just to be sure. And I have run it again today. Both times it reported no issues, but i did not check the logs. Please find todays log attached.

    I have not really had the chance to use the pc much yet, but it seems ok so far.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. factor_j

    factor_j Private E-2

    I was all set to do follow your close out procedures and then I was reminded by Malwarebytes (trial) that i still have unsolicited incoming and outgoing traffic being blocked.

    I have cleared the history/cookies/forms/passwords from explorer, safari, and chrome. Malwarebytes (trial) is still blocking incoming at least.

    Please find MB protection log attached from 2hrs spent online this morning.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a sign of malware on your PC. It is why you need protection software and why you need to follow the instructions in the link at the end of my last message. You need to have your PC properly protected. It was not properly protected.

    You need all of the below:
    • A hardware firewall - normally provided by a router placed inbetween your ISPs modem and your PC.
    • A software firewall - not the Windows XP firewall because it is very inadequate
    • An antivirus program - you had none
    • Antispyware protection - you say you have a trial of Malwarebytes. You need to purchase it before the trial runs out.
    • Misc other protection tips as given in the link
    The IP addresses in your log relate to the below
    The ones from China are quite typical and are bot nets out there hunting for unprotected or improperly protected PCs. The one from OC3 Networks could be related to some software you use on your PC.
     
  10. factor_j

    factor_j Private E-2

    I had been running AVG (free), but your pages advised me to uninstall AVG.

     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, then you can reinstall it now. You do need to address the other items I mentioned too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds