Blue screen

Discussion in 'Malware Help (A Specialist Will Reply)' started by alyssa, Jan 7, 2013.

  1. alyssa

    alyssa Private E-2

    I had/have a problem with a Dell Inspiron E1505 laptop running Windows XP Pro.
    The computer would only operate for short periods of time in any application before it would lock up. About a week ago it started failing to even start up on most occasions.
    The Blue Screen comes up with an atapi.sys error message. I googled the error message and found a discussion that recommended using regedit and editing HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adapi clicking on the START icon and changing the Value data from 0 to 4.
    I did this and the system started to operate properly for a time but then locked up again.
    This fix did allow the system to operate long enough for me to run your "Read and Run me first"
    I downloaded, updated and ran CCleaner. No problems.
    I next downloaded the five tools that you specified for the Windows XP. It took a considerable length of time because the system continued to lock up during the downloads.
    I then started and ran Roguekiller.
    First attempt resulted in the atapi.sys error requiring a Power Off reset.
    Second attempt same as the first.
    Third attempt seemed to lock up in scan mode but exited OK. However, RK remained in the taskbar and mouse pointer entry into the taskbar only gave the hourglass icon with inability to open or restore anything. I noted an RK_Quarantine folder but could not open internal text files.
    At this point I gave bypassed RogueKiller
    Fourth attempt I went straight to Malwarebytes. The system froze requiring a Power Off reset.
    Fifth attempt yielded the message "Updating Malwarebytes Anti-Malware" "Connecting to server" The system locked up requiring another Power Off reset.
    I bypassed Malwarebytes
    I ran TDSSkiller
    \Device\Harddisk0\DR0
    Rootkit.boot.Pihar.c (high risk Malware object)
    1 threat found/neutralized
    14 objects quarantined
    Rebooted computer
    Got the "more difficult versions" screen
    Reran the scan
    No threats found
    2013_14.35.26 log file is the first scan with the threats and quarantines
    2013_14.46.12 log file is the second "clean" scan
    I then went back to try Malwarebytes and it performed correctly and created a log file.
    I restarted the computer immediately.
    Ran Hitman with no problems and created log file
    Ran MGTools
    Got a processdll error. Clicked Enter to continue. Created .zip file.
    The system seems to be working fine now, although I did get one blue screen with the adapi.sys error called out about an hour after I ran all these scans (6 days ago).
    Logs are attached except the RKreport.txt. I never got RogueKiller to run properly.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Viewpoint Media Player
    <--- Uninstall this as requested per the R&R.

    Re run Hitman and have it delete Potential Unwanted Programs


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file)
    • O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)
    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix exit HJT.

    Delete these files:
    C:\Documents and Settings\Ann Kohls\Templates\547eq3ocsl3hy386t8e2jfnolihd7c85p8h837815
    C:\Documents and Settings\Ann Kohls\Local Settings\Application Data\547eq3ocsl3hy386t8e2jfnolihd7c85p8h837815

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. alyssa

    alyssa Private E-2

    Removed Viewpoint Media Player using Control Panel\Add and Remove Programs.
    Ran msconfig from Start\Run. Then performed Restart.
    Ran Hitman after changing "Default action" on Scan for PUPs to "Delete". This did not create a log file. After the scan all files were checked delete. The files were deleted.
    Went to Security Essentials and turned OFF Real-Time Protection (no "deactivate" setting).
    Control Panel\Security Center: Firewall could not be turned off. Automatic Updates turned OFF. Virus Protection tab says AVG Anti-Virus Free Edition 2011 is running but cannot turn it Off. Could not find this program in the "Currently installed programs" listing under Add or Remove Programs.
    At this point I was unable to re-open the Security Center via the Control Panel but I went on anyway.
    Ran analyse.exe with everything closed. Performed the specified fixes.
    Exited HJT and deleted the specified files on the C: drive.
    Created the fixMe.reg file and ran it.
    Got the message "... has been successfully entered into the registry."
    At this point I was unable to access the internet "Internet Explorer could not open the web page". Tried several times without success.
    Tried turning Real-Time Protection back on and then automatic updates. Still no success.
    Restarted computer.
    Got a brief Hitman Pro screen that came on for 3 to 5 seconds on the first restart. Still no internet. The second restart did not display the Hitman screen.
    Access to internet resumed after the second restart.
    Entered your site, downloaded the new MGtools and ran it. zip file attached
     

    Attached Files:

  4. alyssa

    alyssa Private E-2

    Previous reply had attached the MGlogs.zip file generated by MGTools.exe
    This reply has attached the MGlogs.zip file generated by GetLogs.bat

    I forgot to note on the previous reply that I got a ProcessDll.exe screen.
    "Application has generated an exception that could not be handled"
    "Process id=0xa1c(2588), thread id=0xb94 (2964)"
    "Click OK to terminate the application"
    "Click CANCEL to debug the application"

    I clicked on the OK button.


    When I ran the GetLogs.bat I, again, received a ProcessDll.exe screen.
    "Application has generated an exception that could not be handled"
    "Process id=0x1694(5780), thread id=0xb98 (2968)"
    "Click OK to terminate the application"
    "Click CANCEL to debug the application"

    I, again, clicked the OK button.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this file: C:\WINDOWS\system32\_000005_.tmp.dll Then tell me what malware issues remain.
     
  6. alyssa

    alyssa Private E-2

    Thank you so much for the valuable assistance. We do not seem to be having any further problems with malware. I would like to figure out how to get rid of the AVG Free 2011 thing that the security center says is running just to clean things up.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this. AVG Removal Tool

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds