unknown problem, system restarts, bsod

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zhuya, May 2, 2010.

  1. zhuya

    zhuya Private E-2

    my pc keeps freezing and shutting down at random times giving me the blue stop screen, sometimes it doesn't happen for days, and sometimes it happens a couple of times in one day, I know it could/should be a problem with hardware, but i thought I'd give it a try here if it's some virus or similar problem, before I turn it in for repair.. btw the error message says Stop: 0x0000009c (0x00000004, 0x8054D5F0, 0xB2000000, 0x00070F0F)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect that part of your problem is due to having two AV programs installed:
    AVG Free 8.0"
    Avira AntiVir Personal - Free Antivirus
    Chose one and uninstall the other!!

    While you are at it, also uninstall:
    RelevantKnowledge

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    cdrmkaun
    ypyyelk
    vpgxkmeb
    File::
    c:\docume~1\ADMINI~1\LOCALS~1\Temp\cdrmkaun.sys
    C:\WINDOWS\system32\drivers\vpgxkmeb.sys
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please run this: GMER - running with a random name and attach the log from GMER.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * GMER log
    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  3. zhuya

    zhuya Private E-2

    I was unable to uninstall AVG using the normal uninstall so I used Kaspersky AVG Kleaner, so I hope it's uninstalled now..

    As for RelevantKnowledge, I couldn't find it anywhere, except in the Spyware Search&Destroy recovery, as a quarantined item, so I purged it from there.

    As for the rest, there weren't any problems, here are the logs
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better.

    Are you not seeing RelevantKnowledge in your add/remove programs list?

    One last time and you are good to go:

    Use windows explorer to find and delete:
    C:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. zhuya

    zhuya Private E-2

    No, I checked again, no sign of RelevantKnowledge, I can't remember ever seeing it in add/remove programs...

    As for Regedit, I've got the success message, no problems with that.

    There was no bsod or restarts/lock-ups today so I'm hoping that it's all fixed now! Thank you so much for the assistance!

    I just have one more question, which is probably not related to all this.. I ran across a .txt file in C:\ named "cltest" that is 8,03 GB large!! So I was wandering if you have any idea what it is, and is it safe to delete it?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No idea what that is. You might want to right click it and check it's properties to see if that gives you a hint.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not 8 GB. It is only 33 MB.
    Code:
    "C:\"
    cltest.txt    May 31 2007    33040354  "cltest.txt"
    
    The 8 GB file is your pagefile.sys file which is a system file.

    cltest.txt is likely just a file left over from Cyberlink's Power DVD which you may have had installed at sometime. Just delete it.
     
  8. zhuya

    zhuya Private E-2

    I do remember having Power DVD installed, probably up untill that time that it was last modified, cause I uninstalled it long time ago, I'll delete it then.

    Thanks again for all the help, everything is still running great, so I guess this is solved
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds