blue screen, memory dump, safe mode boot hangs up

Discussion in 'Malware Help (A Specialist Will Reply)' started by ctalmage, Sep 24, 2010.

  1. ctalmage

    ctalmage Private E-2

    Hi - had a blue screen, memory dump issue and booting in safe mode would hang up and not complete the boot cycle. I rebooted holding down F8 which gave me a number of boot options.

    I chose boot to last know good configuration and the system booted up. I did get an error message after boot which read:


    Microsoft windows
    The system has recovered from a serious error.

    A log of this error has been created.
    Please tell Microsoft about this problem.
    We have created an error report that you can send to us to help us improve Microsoft windows. We will treat this report as confidential and anonymous.
    To see what data this error report contains, click here

    Which gave

    Microsoft windows

    Error signature
    BCCode : 1000007e BCP1 : C0000005 BCP2 : A7A6CB37 BCP3 : F8990B7C
    BCP4 : F8990878 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

    Reporting Details
    This error report includes: information regarding the condition…..
    To view technical information about the error report, click here

    Which gave

    Error report contents

    The following files will be included in this error report

    C:\DOCUME~1\CALTAL~1\LOCALS~1\Temp\WERe61a.dir00\Mini092110-01.dmp
    C:\DOCUME~1\CALTAL~1\LOCALS~1\Temp\WERe61a.dir00\sysdata.xml


    Not sure if any of that means anything. I did a full clean per the read and run me first instructions and am attaching logs on this message and the next. Am I clean or do I need to do anything else?

    Thanks for your help.
    Cal

    View attachment SAS Log 09-23-2010.txt

    View attachment mbam-log-2010-09-23 (18-11-28).txt

    View attachment ComboFix.txt

    View attachment Root Repeal Log 092410.txt
     
  2. ctalmage

    ctalmage Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC without an antivirus program and no real firewall?

    In addition, you are running AVG Anti-Spyware which is years out of date. Grisoft stopped supporting it a long time ago. You should uninstall this and start using something that is current and that can get updates.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. ctalmage

    ctalmage Private E-2

    hi - attached are the logs you requested.

    system is running ok, boots ok without the blue screen although the boot takes a long time.

    what do you recommend for antivirus software?

    can you pass on instructions on setting up a firewall?

    what do you recommend for anti-spyware?

    Thanks again for all your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's just due to all the junk you load at startup and also due to the fact that you do not have sufficient memory in your PC to run Windows XP SP3 and all the other software you are loading. Your logs show
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 120.39 MB
    At a minimum, you need to double your memory to 1GB but 2 GB is highly recommended.


    All part of final instructions.;) when we get to them, but first let's see if we can work on your startup processes a little.

    If you want to improve startup, you could stop all of the below from loading at startup as you really do not need this. Try the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

    After clicking Fix, exit HJT.

    Now reboot and see how your startup time looks.
     
  6. ctalmage

    ctalmage Private E-2

    Wow - that made a huge difference on the boot time....thanks!

    I will install new larger memory in the next day or 2.

    Thanks again!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. ctalmage

    ctalmage Private E-2

    Thanks again for all your help.

    I went thru everything below and installed avast and the comodo firewall. I'm now getting the following message when I try to access the internet (which I never had before) --

    Windows Installer window pop-up

    The feature you are trying to use is on a CD ROM or other removable disk that is not available.

    Insert the ‘TurboTax ItsDeductible 2006’ disk and click OK



    I have tried to remove the program several times with the add/remove programs and get the same pop up there. How can I get rid of this?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the below

    Windows Installer CleanUp Utility

    See if it shows the TurboTax ItsDeductible 2006 entry. If so, remove it. If the problem continues, I suggest that you post in the Software Forum for non-malware help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds