Blue Screen, Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mulsiphix, May 14, 2009.

  1. Mulsiphix

    Mulsiphix Private E-2

    I've got a bit of a weird Blue Screen issue. I'm not sure what is causing it and would be most thankful if you fine folks could offer me some advice.

    Crashing Information
    Causing The Crash: When I reboot Windows using Start -> Shut Down -> Restart

    What Happens Next: My PC starts to boot like normal. It posts just fine, sits at the Windows loading screen for a few seconds, and then the blue screen pops up.

    The Blue Screen Error:
    *** STOP:0x0000008E (0xc00000, 0x00000000, 0xb9b02250, 0x00000000)

    Crash Condition Notes: If I turn on my PC (when it is off) the Blue screen does not appear. If I restart using the reset button on my case it does not appear (note I only press this button at the Blue Screen, not actually from within Windows.

    System Specs
    OS: Microsoft Windows XP Pro w/SP3
    CPU: Intel Core 2 Duo E4300 @ 3.15Ghz
    Memory: 3GB GeIL DDR2-800Mhz (3 Sticks)
    Motherboard: MSI P6N SLI Platinum
    Hard Drives: 500GB Samsung / 320GB Seagate / 80GB Hitachi
    Video Card: GeForce GTX 260 w/896 RAM)
    Sound: X-Fi XtremeGamer PCI-E
    PSU: Thermaltake Toughpower 750W

    Testing My Hardware
    Last night I ran memtest86 for 13 hours and no errors were produced. Today I ran an Orthos Blend Stress Test for 9 hours with no errors. My CPU is overclocked but my RAM is not. All the timings are their default values. My motherboard comes with some feature that allows me to clock the CPU without having to mess with RAM clock settings. My computer reports my RAM is running at its rated 800MHz so I'm pretty darn positive that it is not OC'ed.

    System Maintenance
    I ran a full maintenance on the computer two days ago. Note that I have been running this machine with no hardware or OS changes for two years using this maintenance regime. For it to cause problems now seems highly unlikely to me. This it he program set I run for maintenance and in this order, one by one.

    1. Windows Update
    2. REBOOT
    3. SpywareBlaster
    4. Spybot S&D
    5. Ad-Aware
    6. AVG Free Virus Scanner v8.5
    7. REBOOT
    8. Windows Disk Check On All Four Partitions (set to run on reboot)
    9. REBOOT
    10. CClean
    11. RegSupreme
    12. NTREGOPT
    13. REBOOT
    14. PerfectDisk
    15. PageDefrag
    16. REBOOT
    17. ERUNT
    18. BootVis
    19. REBOOT

    On this most recent maintenance run AVG found an infected file which it tagged as Trojan Horse Agent 2.EWE. It was a .dll file found in the Windows\System32 directory. When I moved that file to the Virus Vault I couldn't run a single program or even open Windows Explorer without me receiving an error message telling me that the .dll file in question was missing and I needed to reinstall the associated software.

    Recent Trouble With Malware
    This lead me to the MajorGeeks Malware Removal Guide which directed me to the Windows XP Cleaning Procedure which I followed to a tee. I did not have any of the programs required installed. None of the programs, once installed and run, said I had a single infection. Only after running combofix was the infection gone. The .dll file still remained however. This time when I removed it there were no more error messages. I kept the error logs, which I have attached to this post, but removed all of the programs as I no longer needed them.

    I did not start receiving this blue screen until yesterday morning. I have probably rebooted twice since running combofix and it wasn't until today that my third reboot produced the blue screen. Now every Windows based reboot generates it. I should note that AVG said that it could not completely remove the infection because one of the files, Winlogon.exe, was still in use. I thought that combofix, since it uses the Windows Recovery Console, replaced winlogon.exe with an uninfected version to cure the infection. I reran all of the normal maintenance malware programs today and no infections were found. All have the latest updates of course.
     

    Attached Files:

  2. Mulsiphix

    Mulsiphix Private E-2

    I realize there is a lot of information in the above post. I'm not too sure where else I could post this other than Major Geeks though. Any suggestions on other places I might find help would be most appreciated too :-o
     
  3. Mulsiphix

    Mulsiphix Private E-2

    Well I fixed the problem. Turns out it was being caused by Sun's Virtual Box. It added a driver to my network connection which was causing some sort of conflict. I've been stable for over a day now and I have rebooted more times than I probably do in the average half-year. Thanks anyway guys.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your welcome?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds