BSOD IRQL_NOT_LESS_THAN_OR_EQUAL related to Malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dsl55, Aug 7, 2013.

  1. dsl55

    dsl55 Private E-2

    Hi
    I have just started getting a BSOD randomly, havent been able to get a screen shot of it as yet but will do that next time it happens unless I find another way to get it as I'm sure there'll be one

    The heading is usually as per thread title or it starts Driver_IRQL etc. Has happened about 8 days out of the last 10, no pattern to when.

    I havent installed anything recently

    Before I came across your forum a day or 2 ago I ran malwarebytes which found some stuff related to PUP virus which it removed.

    I have since done the things on your read me and run section and have hopefully attached to this thread, there doesnt seem to be anything obvious to me but I am a layman as far as this stuff goes so any advice would be appreciated
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your issues are not malware related. However, there is a bunch of junk to remove.

    Run CCleaner and clean out your temp folders.

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     
  3. dsl55

    dsl55 Private E-2

    Hi, thanks for the guidance so far, have attached as per

    Given my issue doesnt seem to be malware related would you recommend I post this in another area of the forum?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn;t run CCleaner. You need to delete all of this:
    Code:
    C:\Documents and Settings\Stephen Barratt\Local Settings\Temp\"
    10.tmp        25 Jul 2013         165  "10.tmp"
    11.tmp        29 Jul 2013         165  "11.tmp"
    11d.tmp       27 Jun 2013       28672  "11D.tmp"
    12.tmp        30 Jul 2013         165  "12.tmp"
    13.tmp        30 Jul 2013         165  "13.tmp"
    136.tmp       22 Jun 2013         166  "136.tmp"
    138.tmp       29 Jun 2013       28672  "138.tmp"
    142.tmp        4 Jul 2013         165  "142.tmp"
    162.tmp        6 Jun 2013         165  "162.tmp"
    16b.tmp       24 Jun 2013       28672  "16B.tmp"
    16e.tmp       10 Jul 2013         165  "16E.tmp"
    16f.tmp       25 Jun 2013       28672  "16F.tmp"
    185.tmp       30 Jun 2013       28672  "185.tmp"
    189.tmp       26 Jun 2013       28672  "189.tmp"
    1a5.tmp       16 Jul 2013         165  "1A5.tmp"
    1a6.tmp       19 Jul 2013         165  "1A6.tmp"
    1b3.tmp       13 Jun 2013         165  "1B3.tmp"
    1cf.tmp        5 Jul 2013         165  "1CF.tmp"
    1d5.tmp       15 Jul 2013         165  "1D5.tmp"
    1d7.tmp       21 Jul 2013         165  "1D7.tmp"
    1f2.tmp        9 Jul 2013         165  "1F2.tmp"
    1f9.tmp       17 Jul 2013         165  "1F9.tmp"
    2.tmp         16 Jun 2013         165  "2.tmp"
    210.tmp       14 Jun 2013         165  "210.tmp"
    21f.tmp        2 Jul 2013       28672  "21F.tmp"
    235.tmp       18 Jul 2013         165  "235.tmp"
    24b.tmp       10 Jun 2013         165  "24B.tmp"
    24f.tmp        3 Jul 2013       28672  "24F.tmp"
    256.tmp        2 Aug 2013     1173456  "256.tmp"
    259.tmp       12 Jul 2013         165  "259.tmp"
    287.tmp       12 Jun 2013         165  "287.tmp"
    2b3.tmp        5 Jun 2013         165  "2B3.tmp"
    3.tmp          5 Jul 2013         165  "3.tmp"
    31f.tmp        1 Jul 2013       28672  "31F.tmp"
    34.tmp         2 Aug 2013         170  "34.tmp"
    35b.tmp       11 Jun 2013         165  "35B.tmp"
    37.tmp         8 Jul 2013         165  "37.tmp"
    3c.tmp        17 Jun 2013         166  "3C.tmp"
    4.tmp         28 Jun 2013       28672  "4.tmp"
    5.tmp          8 Jun 2013         165  "5.tmp"
    53.tmp         9 Jun 2013         165  "53.tmp"
    5d.tmp        19 Jun 2013         166  "5D.tmp"
    6.tmp          3 Jul 2013       28672  "6.tmp"
    7.tmp          7 Jul 2013         165  "7.tmp"
    71.tmp         7 Jun 2013         165  "71.tmp"
    8.tmp         11 Jul 2013         165  "8.tmp"
    8F36D6~1      27 May 2013              "8F36D6C6-BAB0-7891-8175-AF4732003CAF"
    9.tmp         13 Jul 2013         165  "9.tmp"
    91.tmp        21 Jun 2013         166  "91.tmp"
    98.tmp        24 Jul 2013         165  "98.tmp"
    9c.tmp        31 Jul 2013         165  "9C.tmp"
    adobearm.log   8 Aug 2013      606154  "AdobeARM.log"
    APNLOGS       15 Jun 2013              "APNLogs"
    armpa2bk.htm   7 Aug 2013         503  "ARMPA2BK.htm"
    au78ee~1.xml   7 Aug 2013        8818  "au-descriptor-1.7.0_25-b17.xml"
    auchec~1.txt   7 Aug 2013        2652  "AUCHECK_PARSER.txt"
    b.tmp         14 Jul 2013         165  "B.tmp"
    c.tmp         20 Jun 2013         166  "C.tmp"
    ca.tmp        18 Jun 2013         166  "CA.tmp"
    chrome~2.log   3 Aug 2013       66925  "chrome_installer.log"
    CRX_75~1       8 Aug 2013              "CRX_75DAF8CB7768"
    d.tmp         14 Jul 2013         165  "D.tmp"
    d8.tmp        13 Jul 2013         165  "D8.tmp"
    dalmea~1.log   3 Aug 2013       52622  "DalMeasurementFile2.log"
    dla_in~1.zip  27 May 2013     2671578  "dla_install.zip"
    dw.log        28 May 2013         209  "dw.log"
    e.tmp         15 Jul 2013         165  "E.tmp"
     
  5. dsl55

    dsl55 Private E-2

    Hi, i ran it prior to my first post on the 7th Aug as per the read me first instructions so not sure how those files there. Will try it again i guess
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When done, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Attach the new log.
     
  7. dsl55

    dsl55 Private E-2

    I have also ran sfc /scannow and it doesnt get anywhere, first message says 'files that are required for windows have been repolaced by unrecognised versions. To restore originals please insert XP Professional SP3 CD' - which I dont have and never have had

    It then throws a message about files need copying to the DLL cache

    The computer is approx 7 years old, Xp Media Center Edition 2002 SP3. I have the recovery CD that came with it but that feels like a last resort!?
     
  8. dsl55

    dsl55 Private E-2

    New MG Log thing....
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\Documents and Settings\Stephen Barratt\Local Settings\Temp\*.*
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista ,Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. dsl55

    dsl55 Private E-2

    Well, i got as far as clicking run fix and it threw a blue screen. Didnt have any title this time, no IRQL_ etc, just the following codes 2 thirds of the way down the page

    Ox0000008e (oxc0000005, ox804f4d86, oxbc6da98, ox0000000)

    Going to try and run OTL again but didnt know if this info helped?!
     
  11. dsl55

    dsl55 Private E-2

    OTL log attached, says right at the top there was an error interpreting something?!

    Just running MS Log again now
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that got rid of all the temp files.

    I noticed ( you can look at the MGLogs.zip and open the Newfiles text ) that you have duplicates of a lot of files. That may or may not be related to your problems. However, your issues are not malware related. So I suggest you post in the software forum for additional assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows
          defaults.


    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ &
      RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall,
      don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking
      on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if
      running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore
      points:
      • Refer to the instructions for your WIndows version in this link:

        Disable And Enable System Restore

      • What we want you to do is to first disable System Restore to flush restore points some of which
        could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  13. dsl55

    dsl55 Private E-2

    Last MG Log attached

    Thanks for your help, will move on then and see if I cant get to bottom of BSOD thing.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck with the BSOD issue. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds