Blue Screen

Discussion in 'Malware Help (A Specialist Will Reply)' started by smdmartin, Sep 25, 2008.

  1. smdmartin

    smdmartin Private E-2

    I am running windows Vista 32 bit on a Toshiba Satellite Laptop and keep getting the blue screen error. The following is information relayed from windows:
    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.0.6001.2.1.0.768.3
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 50
    BCP1: B3E97000
    BCP2: 00000000
    BCP3: 82126558
    BCP4: 00000000
    OS Version: 6_0_6001
    Service Pack: 1_0
    Product: 768_1

    Files that help describe the problem:
    C:\Windows\Minidump\Mini092008-01.dmp
    C:\Users\Shawn Martin\AppData\Local\Temp\WER-71464-0.sysdata.xml
    C:\Users\Shawn Martin\AppData\Local\Temp\WER9B73.tmp.version.txt

    This problem was caused by WinNT / Bagle.gen, a known computer virus.

    WinNT / Bagle.gen is also known by the following names:

    Win32/Ursnif
    Trojan-Downloader.Win32.Bagle.cu
    W32.Beagle.GM
    Troj/BagleDl-DB
    Troj/Bagle-TH

    I have completed the process on the RUN ME FIRST - MALWARE REMOVAL GUIDE and have attached the logs as requested. Also as requested, here are the issues I ran into while following the procedures:
    1. when running msconfig I received a blue screen and said it could not start. A start up repair was then ran.
    2. on my view tab there was no option to show hidden files
    3. on the 1st attempt to run the super anti-spyware I received a blue scree, but on round 2 it worked
    4. spybot would not work: unable to execute file, create process failed, code 193. % 1 is not a valid win32 application. I had the same issue a few days ago with spybot.
    5. combofix.exe would not run (said it is not a valid win32 application).
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
    Last edited: Sep 26, 2008
  3. smdmartin

    smdmartin Private E-2

    I ran HJT and have attached the log. The Avenger I did not run because the program was not as described and I did not want to mess up the comp. When opened there was no insert script manually box to be checked nor was there a magnifying glass icon or a done button. There were only 3 buttons for adding script from a file, URL, or clipboard. On the bottom there was an execute button and scan for rootkits and a Auto disable rootkits check boxes. As for the files you said to delete:
    C:\WINDOWS\Temp: all files were from today and could not be deleted. the only other items were the cookies, history, MP telemetry submit, sxs temp, and temp internet files folder all of which I did not delete.
    C:\Documents and Settings\%username%\Local Settings\Temp: Access was denied to the documents and settings folder.
    I have been able to run Spybot since the original steps taken just prior to these and have removed several infections with it.
    If there is any further insight into this please let me know. Thank you.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just copy and paste...then run it.
     
  5. smdmartin

    smdmartin Private E-2

    I ran the program and it ave some sort of error message about the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\german.exe. I do not however remember exactly what it said. I attempted to retrieve the log and in the avenger folder there was a rar file. inside there was the text file as you described but it ask for a password for the encrypted file. That is where I am at for now.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me give it to you again as I may have oopsed the fix :

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  7. smdmartin

    smdmartin Private E-2

    Again I am getting errors and so not to hurt the comp I aborted the Avenger program to be safe. The error I am getting is the same as before.

    Error: Invalid registry syntax in command:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run drvsyskit
    Only register keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
    Skipping line. (Register Key deletion mode)

    I hit ok and proceeded but got a similar message except it said "...\run german.exe" (rather than drvsyskit as it did above).

    If I may ask, what is this procedure going to do? I get the warning of how powerful the Avenger program is and I do not want to have to reformat my comp.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are trying to remove those two registry values....and not having much luck. :(

    Possibly we have cleaned enough to get ComboFix to run......is it still on your desktop? If so just double click and let me know.

    and then let's try a regular reg patch:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  9. smdmartin

    smdmartin Private E-2

    here are the logs from the 2 programs.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well happy days! :) Your logs look clean.
    Now lets clean up from the scans:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  11. smdmartin

    smdmartin Private E-2

    I attempted as directed and received the following error message:
    Cannot import C:\Users\Shawn Martin\Desktop\fixME.reg: The specific file is not a registry script. You can only import binary registry files from within the registry editor.
    I have stopped at this point in the directions.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you save the file type as "all files" and only copy what was in the quote box?
     
  13. smdmartin

    smdmartin Private E-2

    I retried it and it worked. I have completed the other steps as well. Thank you for all of your help with this. I run the newest version of the free edition of AVG. Is this good enough protection? I don't really want to purchase any programs.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I do not run any paid for AV or AS software......just read the thread on How to Protect Yourself......and keep SAS and MWB's for backup scans when you feel in doubt.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds