Blue screen when running virus scan

Discussion in 'Malware Help (A Specialist Will Reply)' started by OsterKate, Feb 18, 2013.

  1. OsterKate

    OsterKate Private E-2

    Hello

    I have a Dell Inspiron ONE2310, 4gb ram, running Windows 7

    I have been unable to complete a virus scan for a couple of months. Have tried different avira and avast but both get about half way and then the blue screen appears.

    I am also having trouble streaming content from Iplayer or 4OD, it keeps stopping and starting.

    I have completed the READ & RUN ME FIRST Malware Removal Guide but no change...

    Any help greatly appreciated..... Thank you!

    Here are the logs.

    Malwarebytes Anti-Malware (Trial) 1.70.0.1100
    www.malwarebytes.org

    Database version: v2013.02.18.05

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Kate :: KATE-PC [administrator]

    Protection: Enabled

    18/02/2013 09:30:51
    mbam-log-2013-02-18 (09-30-51).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 204519
    Time elapsed: 2 minute(s), 6 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 2
    C:\Users\Kate\Downloads\DownloadSetup (1).exe (PUP.Offerware) -> Quarantined and deleted successfully.
    C:\Users\Kate\Downloads\DownloadSetup.exe (PUP.Offerware) -> Quarantined and deleted successfully.

    (end)

    TDSSKiller - no threats found.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use add/remove programs to uninstall:
    Anti-phishing Domain Advisor

    Now use windows explorer to see if this still exists and delete it if it does:
    C:\ProgramData\Anti-phishing Domain Advisor

    Now re-run RogueKiller and have it delete this ( again, if it still exists):
    [RUN][SUSP PATH] HKLM\[...]\Wow6432Node\Run : Anti-phishing Domain Advisor ("C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe") [7] -> FOUND

    Re-run Hitman and have it fix everything it finds.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and re-scan with both RogueKiller and Hitman and attach the new logs.
     
  3. OsterKate

    OsterKate Private E-2

    Thanks for your help TimW. I've followed your instructions.

    I received a success message that the registry has been updated. The new logs are attached...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is all clean. Tell me how things are running.
     
  5. OsterKate

    OsterKate Private E-2

    All seems to be running fine now. Completed a virus scan without a blue screen and video is streaming ok.

    Thanks for your help TimW
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. OsterKate

    OsterKate Private E-2

    Thanks again TimW

    When I went to uninstall them, RogueKiller and HitManPro were not in the list of programmes, just on the desktop. However, they appear to have been removed by the MGclean.bat file. HijackThis was also not in the list of programmes. Is any of this a problem?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of it is a problem. ;)
     
  9. OsterKate

    OsterKate Private E-2

    Hi TimW

    I went through the How to protect yourself from Malware procedure which all went fine except when I tried to disable autorun. I got an error message saying

    Cannot import C:\Users\Kate\Desktop\AutoRunDisable.Reg: Not all data was successfully written to the registry. Some keys are open by the system or other processes.

    Do I need to do something to fix this?

    Thanks
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. OsterKate

    OsterKate Private E-2

    I've downloaded it but the application won't run....
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to pursue this in the software forum.
     
  13. OsterKate

    OsterKate Private E-2

    I'm now having the same problem as I had originally. PC very slow on the internet and blue screen when running virus scan.

    I've gone through the same procedure again. Here are the logs.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and click on the DNS tab and have it fix that. Then please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    I am not finding any malware in your logs. If you still are having issues with slowness, please post in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds