Blue screen, serious error....help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theymademedoit, Nov 11, 2011.

  1. theymademedoit

    theymademedoit Private E-2

    Hi,
    I have a feeling this is a malware problem.
    A couple of nights ago I went to shut down my desktop (XP) and it seemed to take a little longer than usual.
    The morning after I fired it up and had the ‘start windows using last known configuration/safemode etc’…I chose start normally and was then faced with the blue screen saying that there had been a problem and windows had to re-start to prevent damage etc.
    This happened 3 or 4 times in a row and I eventually turned off the PC and unplugged my USB ext hard drive and it then started up and stayed on all day.
    I ran Malwarebytes and it found a Trojan and I then deleted it.

    When I went to shut down last night, again it took longer and this morning the whole thing happened again…including the unplugging of the ext hard drive.

    This time I ran chkdsk however I am not sure if it completed (or even if I ran it correctly as said in read only mode) as when I can back in the room there was nothing on the screen.
    I then tried running chkdsk /f and it said it couldn’t be completed as something was in use – did I want to run on next start up….I said yes, restarted and was then hit with this error….(see attached).

    Any ideas?

    Cheers,
    Al
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, theymademedoit!

    The attachment you provided basically tells us that you received a BSOD with the error code 0X8E previously. 0X8E is typically bad RAM, driver, or pagefile issue.

    If you would like us to check for malware, go through the below: READ & RUN ME FIRST Malware Removal Guide
     
  3. theymademedoit

    theymademedoit Private E-2

    Hi there.
    Over the weekend I tried booting up with the USB HD attached and I get the blue screen.
    This morning I boot up without and all is fine.
    Is this something I can sort in the BIOS or is the EXT HD likely screwed?
     
  4. thisisu

    thisisu Malware Consultant

    It wouldn't be something from the BIOS.

    What happens when you connect the USB external hard drive once you are in Windows? Are you able to read what's on the external drive?

    Can you run the below scan while the USB external hard drive is connected?

    Please download MBRCheck by GeeksToGo to your desktop.
    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (Vista and Win7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (How to attach items to your post)
     
  5. theymademedoit

    theymademedoit Private E-2

     
  6. theymademedoit

    theymademedoit Private E-2

    Hi there.
    I ran the MBRcheck and the screen went black then I got the BSOD which gave the following info -
    driver_irql_not_less_or_equal

    Stop: 0x000000D1, (0x52004400, 0x000000ff, 0x00000001, 0x8a2a6955

    Then when I started a log was created from the MBRcheck see attached.

    Any ideas mate?
     

    Attached Files:

  7. thisisu

    thisisu Malware Consultant

    I have a feeling the external drive may have some problems. Possibly an infected Master Boot Record (MBR).

    I would need you to go through this thread first: READ & RUN ME FIRST Malware Removal Guide
    If you still have problems, attach all the logs requested from here and then we will go from there.
     
  8. theymademedoit

    theymademedoit Private E-2

    Hi,
    Well I tried to turn my pc on this morning (without the ext HD attached) and it kept booting to the BSOD, with a message saying ‘page_fault_in_nonpaged_area’.
    I tried restarting in safemode, last known good config and normally and nothing.
    I then turned it off for a while and tried again.
    This time it booted and I disabled the internet, uninstalled my AVIRA and ran chkdsk /r /f and it came up clean and then booted ok.
    I am now at work and left it running Malwarebytes again.
    I really don’t know what to do next.
    I don’t mind formatting and reinstalling XP as I have all my stuff on an ext hd.

    What would you suggest?
    Re-seating the RAM, cleaning the fans etc?
    Could it be my anti-virus?
     
  9. thisisu

    thisisu Malware Consultant

    Error Message:

    PAGE_FAULT_IN_NONPAGED_AREA

    Explanation:

    This Stop message occurs when requested data is not found in memory. The system generates a fault, which normally indicates that the system looks for data in the paging file. In this circumstance, however, the missing data is identified as being located within an area of memory that cannot be paged out to disk. The system faults, but cannot find, the data and is unable to recover. Faulty hardware, a buggy system service, antivirus software, and a corrupted NTFS volume can all generate this type of error.

    This Stop message usually occurs after the installation of faulty hardware or in the event of failure of installed hardware (usually related to defective RAM, either main memory, L2 RAM cache, or video RAM). If hardware has been added to the system recently, remove it to see if the error recurs. If existing hardware has failed, remove or replace the faulty component. Run hardware diagnostics supplied by the system manufacturer. For details on these procedures, see the owners manual for your computer. Another cause of this Stop message is the installation of a buggy system service. Disable the service and determine if this resolves the error. If so, contact the manufacturer of the system service about a possible update. If the error occurs during system startup, restart your computer, and press F8 at the character-mode menu that displays the operating system choices. At the resulting Windows 2000 Advanced Options menu, choose the Last Known Good Configuration option. This option is most effective when only one driver or service is added at a time. Antivirus software can also trigger this Stop message. Disable the program and determine if this resolves the error. If it does, contact the manufacturer of the program about a possible update. A corrupted NTFS volume can also generate this Stop message. Run Chkdsk /f /r to detect and repair disk errors. Restart the system before the disk scan begins on a system partition. If the hard disk is SCSI, check for problems between the SCSI controller and the disk. Finally, check the System Log in Event Viewer for additional error messages that might help pinpoint the device or driver causing the error. Disabling memory caching of the BIOS might also resolve it. For more troubleshooting information about this Stop message, refer to the Microsoft Knowledge Base at http://support.microsoft.com/support.

    Source: http://technet.microsoft.com/en-us/library/cc957625.aspx

    You may still have malware problems but it I would address this Windows / hardware problem first. Try our Software forum for more assistance.
     
  10. theymademedoit

    theymademedoit Private E-2

    Hi,
    I got my CD drive unlocked…it seemed IMGBURN had locked it.
    I then ran MEMTEST which gave no errors.
    I uninstalled AVIRA and re-installed the newest version (which I ran with no issues found).
    I then ran Malwarebytes on both the ext hd and the pc (no issues found).
    I ran Superantispyware on both the ext hd and the pc (29 issues found and deleted).
    I booted up this morning no probs with and without the ext hd attached several times.
    I don’t know if it’s sorted only time will tell, however it’s looking better than it was yesterday!
    Again thanks for your help and I will keep you posted on how it goes.

    Al
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds