Blue screen when I boot

Discussion in 'Malware Help (A Specialist Will Reply)' started by lyckos, Mar 6, 2010.

  1. lyckos

    lyckos Private E-2

    Hello
    I have a problem with my Windows.
    When I try to boot, the system restarts a moment after a blue screen appears.
    I tried to boot in a)safe mode, b)safe mode with internet, c)run last known good configuration, and they all ended up with rebooting.
    I tried to get into the Recovery Console but I ended up again with a blue screen that says in a few words that there seems to be a problem
    with my Windows and as possible cause it gives either a virus or a HDD problem. It proposes to me to run a scan and a chkdks /f.
    Finally i says: Stop: 0x0000007B (0xF789E528, 0x00000034, 0x00000000, 0x00000000)

    Thankfully I have windows installed on another partition so I managed to boot to them. I did a full scan with my AVG and it showed a virus identified Win32/Patched.CJ
    wich I put to vault.
    I also rebooted in safe mode command prompt and I died a chkdsk /f at C: where my problematic windows are but it didn't find bad sectors or anything else wrong
    I have attached the logs from the programs you want, except the mgtools log because it seems it is not created although the mgtools dir appears on the root after I run Mgtools.exe
    Is there something I can do through my second OS that is working?
     

    Attached Files:

  2. lyckos

    lyckos Private E-2

    Of course I ran all the house cleaning programs on the OS that does work
     
  3. lyckos

    lyckos Private E-2

    Noone guys??
    any answer would be usefull
     
  4. lyckos

    lyckos Private E-2

    excuse me fellows, some help please? no reply at all???
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    You should have read the sticky threads and this was also given to you in the READ & RUN ME:

    Don't Bump! It Only Hurts You!!!

    More than likely not a malware problem. You need to post in the Software Forum for help repairing or reinstalling your Windows Operating System.

    Also I see the below in your Malwarebytes log which you did not fix:
    You also need to read this sticky: Warning about Porn, Keygens, Cracks, and other Illegal Software

    While this is possibly useful to get started, you need to be able to boot the partition that you thought was infected inorder to fully check it for malware. Unless it is bootable, there is nothing else we can do for you except recommend other scanner/repair methods like below:
     
  6. lyckos

    lyckos Private E-2

    First of all thank you for the reply and I am sorry for the bump, as now I understand your method.
    I have no comment to make for the Porn, Keygens etc. comment. I take full responsibility for my actions, but that doesnt prevent me having the greatest admire to your site and the help it gives to people like me.

    Now about restoring the older registry manually, the procedure is great and although I am an amateur user, I fond of the whole procedure. The article at Microsoft Support wich is by the way very good, says I must boot from a Windows XP CD. I do have the CD but I wanted to ask on that if I may do the whole procedure through my second alternative OS (Windows XP also) that I have got on my PC thus backing up the original registry files and then go straight to copying registry files I selected from a snapshot of older date from the System volume information to my windows/system32/config.
    Before that though I am willing to scan my hard disk to another PC, THEN boot from one of the special CDs you are proposing, and AFTER THAT repair the registry so I can eliminate the possibility of the existance of virus or any malware.
    What do you think?

    P.S. Sorry I didnt mension that I have XP Home Edition SP2, I thought it showed in the logs I uploaded....again excuse me
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if you understand what that procedure is doing, you can accomplish the same steps much easier by booting another partition ( or even a special boot CD). You must make sure that the files and registry keys you work on are for the infection partition and not the one you are booting with your second alternative partition.

    Something else you may want to quickly check before running that procedure is to see if the C:\Windows\system32\drivers\atapi.sys file exists on the infected/bad partition. If this file is missing or infected, it could be the problem.


    No! Only the secondary partition info shows since that is what you booted to when you ran the scans. And it shows Microsoft Windows XP Professional SP3
     
  8. lyckos

    lyckos Private E-2

    I tried to get into Recovery Console from the problematic partition but it ended up with the same blue screen I mentioned at the beginning.
    I tried to get into Recovery Console from the Win XP CD and it came up with a message saying that recovery console could not find installed Hard disk units.
    I booted with my second working partition and I copied from the c:\windows\repair the genuine files (system, sam etc.) to c:\windows\system32\config
    Then I tried to boot in safe mode and I succeeded!
    This was the first time I could boot into that partition.
    I got in System Volume Information and I discovered that I only have restore points from 8/2/2010 since 7/3/2010. I can't understand why there aren't any older restore points.
    Anyway I copied the oldest restore points into c:\windows\tmp and I renamed them as microsoft support says.
    Then I tried to boot again in Recovery Console but it ended up the same way I said in the begining (CD or problematic partition).
    I booted into the ok partition and I copied from there the restore point of 8/2/2010 files to the c:\windows\system32\config and then I tried to boot in the problematic partition but it started rebooting again!!!
    What else can I do?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My suggestion is to reinstall or seek help in the Software Forum to try and repair your Windows installation. This is currently not a malware problem. If you can make this partition bootable, we could then check to see if there is any malware present. But until bootable, there is nothing more for us to do here than what I suggested message # 5 or I could give you other similar procedures if you wish like the below.


    This will require downloading two programs. One is an ISO file and the other is an ISO file burner for your CD burner.


    First download:

    ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the programme, from there on in it is fairly automatic.Instructions

    Second download the ISO file
    • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
    • When downloaded double click and this will then open ISOBurner to burn the file to CD
    • Reboot your system using the boot CD you just created.

      Note : If you do not know how to set your computer to boot from CD follow the stepshere
    • Your system should now display a REATOGO-X-PE desktop.
    • Double-click on the OTLPE icon.
    • When asked "Do you wish to load the remote registry", select Yes
    • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
    • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start. Change the following settings
      • Change Drivers to Non-Microsoft
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\_OTL\MovedFiles
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please attach the OTL.txt file to your reply. (See: HOW TO: Attach Items To Your Post )
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds