Computer encounters a critical error after one minute / Siref.AH

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Marine0341, Aug 3, 2012.

  1. Marine0341

    Marine0341 Private E-2

    When I started this post i read through the similar threads and was trying to run the FRST.exe found through this link.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.

    followed its directions and got to the disclaimer and accepted.

    a split second later before i could even click scan the computer powers down.

    now the computer wont get past the bios load.

    Is there anything that can still be done? Any help would be appreciated.


    ORIGINAL ISSUE

    Her computer has the Siref.AH and it wont stay on for longer than one or two minutes before it says "Windows has encountered a critical error restarting in one minute"
     
  2. Marine0341

    Marine0341 Private E-2

    Well my bout of foolishness is over the computer was unplugged and the battery died.

    here is the FRST log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need some additional info before we can work up a fix.

    Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (See How to attach)
     
  4. Marine0341

    Marine0341 Private E-2

    Thank you for the reply.

    Additional information I left out in my haste, this is a laptop 32 bit system, windows 7 professional.

    Here are the new FRST and the services.txt.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Now from normal Windows, run MGtools per the below instructions and attach the C:\MGlogs.zip file.

    Using MGtools

    Make sure you tell me how things are working now!
     
  6. Marine0341

    Marine0341 Private E-2

    So far it is stable again. currently running for one hour with out a critical error.


    seems to have some issues with windows firewall that will need to be repaired but other than that every thing seems back to normal
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you do along with a couple other services.


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Marine0341

    Marine0341 Private E-2

    There still seems to be some permission issues and a few programs i don't recognize on her computer. To be honest i don't know what she was doing to get this.

    I did notice a folder called Tweaking.com_Windows_Repair_Logs do you want the logs located in there. It has seven text documents.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to be more specific. The firewall issue and a couple others are fixed now.

    Not necessary right now as everything looks okay.


    BUT... I do notice that the BITS service required for Windows Update is missing. Is this what you meant above?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the below file and save it to your Desktop

    BITS.reg

    Then right click on it and select Merge. If prompted, allow it to be added to your registry. Then reboot.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  11. Marine0341

    Marine0341 Private E-2

    the BITS.reg does not seem to be downloadable should i save what comes up to a text file

    Sorry for the late reply
     
  12. thisisu

    thisisu Malware Consultant

    Hello Marine0341,

    To keep you going I have attached the BITS.reg file to this message.
    You will need to extract it from the BITS.zip file first though.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried doing what thisisu gave you to get BITS.reg ?
     
  14. Marine0341

    Marine0341 Private E-2

    here are the new logs.

    as to what i am still seeing maybe it is files that were hidden in the past and are visible now. one issue i cant figure out i when i go into my computer or any file the view is set to large even after i change the view to say something like details. also desktop icons wont stay where i put them and auto align is not on.
     

    Attached Files:

  15. Marine0341

    Marine0341 Private E-2

    Sorry for the second reply but i just remembered a question. Whenever i run the MGTools to get the logs a program called SteeWerx WhoAmI is stopped. i don't recognize the program is it anything dangerous?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's used by MGtools and was explained during the execution of the program in the command prompt window.

    The BITS service is fixed now. Are you having any other malware issues?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds