When I run RogueKiller I get bluescreen of death in the middle of scan

Discussion in 'Malware Help (A Specialist Will Reply)' started by dorkycyclist, Sep 27, 2013.

  1. dorkycyclist

    dorkycyclist Private E-2

    When I run RogueKiller my computer crashes and I get a bluescreen., I am running Windows XP on a Dell Latitude D620. I have two partitions. I used the error reporting service for Microsoft and this linked me to a message that attributed the issue to a driver.

    Attached is an image of the blue screen of death message. It attributes the problem to a driver connected to my Sygate firewall.

    Also attached are the logs from MGTools.

    I don't trust what is going on here with the Sygate driver. I did a search to see if other people have had issues with Sygate firewall drivers conflicting with RogueKiller. I didn't find any instances other people having this problem.

    I have also had various processes eating up too much memory on my CPU.

    Norton caught this process using up too much memory:
    c:\program files\java\jre7\bin\jqs.exe

    Norton caught this process using up too much memory:
    c:\program files\mozilla firefox\plugin-container.exe

    Also, Norton caught this process also using up too much memory:
    c:\windows\system32\config\systemprofile\local settings\temp\cr_ca067.tmp\setup.exe

    Norton also found svchost.exe using up too much memory. I did a cursory scan for Conficker using the tool Symantec provides, but it said my system didn't have conficker . I'm not ruling out conficker or anything yet. :confused


    Also:
    I uninstalled the Java 7 runtime environment from my computer when the high CPU usage issue first appeared. Java was indicated as the source of the problem. I strangely have been unable to uninstall one of the Java components in the control panel. This component is Java 7 Update 25.

    Since this problem emerged I've been repeatedly unable to reinstall Java- no matter what installation method I've used. The Java installation stops mid-process saying the file c:\windows\installer\jer1.7.0_25-c.msi is corrupted or missing.

    Any help would be greatly appreciated.
     

    Attached Files:

    Last edited: Sep 27, 2013
  2. dorkycyclist

    dorkycyclist Private E-2

    Edit: I just had an "oh-duh" moment. :-o
    I think this issue is related to my Sygate firewall taking it upon itself to regularly prevent the NT Kernal and System from connecting to the network. I uninstalled and reinstalled Sygate Firewall, but even after the new installation, the firewall takes it upon itself to block the NT Kernal from accessing the network. I don't exactly know how to prevent this from happening. :(
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall your firewall for the time being. Run the requested scans ( you dd not attach the MGLogs.zip ) and attach them when you are done.
     
  4. dorkycyclist

    dorkycyclist Private E-2

    Oops- sorry- This time the zip file for MGTools is attached. So is a report from RogueKiler.

    I was able to run RogueKiller after uninstalling Sygate Firewall. It found about 7 different different hijacked registry entries.

    I tried reinstalling Sygate Firewall however, I got the BSOD when I ran RogueKiller the second time after reinstalling SygateFW.

    I gave up on Sygate and tried installing PCTools firewall.

    During the installation of PCToolsFW, a BSOD appeared and forced my computer to reboot.

    The BSOD appeared each time my machine booted, making my computer shut down and restart perpetually. I stopped this by running System Restore from safe mode.

    I just installed Online Armor's firewall and machine seems to be stable for the moment. I'm going to reboot now after this install and hope nothing goes wrong again.

    My guess is the malware is still on my machine somewhere. I ran MalwareBytes, NortonAV, TDSS Killer and MGTools for good measure and these found nothing.

    Thanks for good advice so far. :cool
     

    Attached Files:

    Last edited: Sep 28, 2013
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach the log from running Hitman. However, I am not finding any malware in the logs you did attach.

    Why haven't you upgrades to SP3?
     
  6. dorkycyclist

    dorkycyclist Private E-2

    Attached is the Hitman record. I haven't been able to run automatic updates for Windows at all since I reinstalled windows using the set up on this machine. As I explained, I bought this machine from Computers Now- company that sells refurbished computers. http://www.computersnow.com/.

    A couple weeks ago I started having virus-like issues with the machine. I booted into safe mode to run my Antivirus to deal with the problem. Norton didn't find anything.

    I noticed when I booted into SafeMode on this computer, the desktop shows an icon to restore the operating system. If you click on this a phone number for the Computers Now tech support appears suggesting you call the company for assistance for help with restoring a copy of windows.

    I'll reboot my computer and try to get a screen shot of this.

    Anyhow, I called the number and rather than help me reinstall windows, the tech rep said they would send out a new hard drive instead.

    Now I have to wait for this hard drive.

    My guess is that the version on this partition to reinstall the operating system isn't using a legit version of windows and that is why the company is sending me a new one free of charge.

    Being impatient and wanting to get online while I waited inspired me to try using the company's own set up to restore windows.

    I think because the company doesn't ship an XP CD with the computer, they have their ways of trying to get around it. When I had my Dell Dimension 8400, Dell indeed sent me the XP CD and other CDs specific to my Dimension 8400.

    That software, safe for a few device drivers, is pretty useless on this machine which is not a Dell Dimension. Still, the drivers got the wifi and sound card on this machine working which is about all I need.

    I'm not sure, but i'm guessing that this version of XP that the reinstallation partition initiates isn't a valid copy of XP. My hunch is that the company sends out the new hard drives to deal with this issue. While, I was able to authenticate this version the reinstallation partition installed using the service tag on this computer, automatic updates has failed to run in a big way.

    I have no idea what is going on as far as this. I mean, I'm glad the company is sending me a new hard drive basically free of charge, sans postage. I have just never dealt with a company like this before.

    It is sad to say,but their tech support is much better than Dells and I am glad to get a new hard drive. I think I like the company. This computer is in great shape, for one.

    As for everything else, I have no idea what's going on. Maybe they have a group license for XP which only covers machines in their care and allows them to install on hard drives. I'd bet they'd have to pay serious money to ship a XP CD with every machine they sell to a customer like me.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this while you wait:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    It may take some time, so be patient.
     
  8. dorkycyclist

    dorkycyclist Private E-2

    I'm having trouble completing this process. I need an XP CD and the one I own is for my old Dell
     
  9. dorkycyclist

    dorkycyclist Private E-2

    Also- I did some checking what drivers were causing my BSOD and looked at which one caused the crash using BluescreenView. Then I just looked up the file. I had another BSOD appear and was curious what the issue was since Sygate and all its drivers were removed. It turned out that the driver that caused my machine to crash when I tried to install a different firewall was called truesight.sys.

    I followed directions on the removal of this and my processing speed went back to normal. I still am struggling to reinstall Java, but getting rid of truesight.sys seems to have improved things. I've been running Malwarebytes, Norton, RogueKiller,, et. al. again just to make sure I've gotten rid of everything. Thanks again for the help!:)
     
    Last edited: Sep 30, 2013
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.


    After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds