Blue Screens & Overzealousness

Discussion in 'Malware Help (A Specialist Will Reply)' started by nyw11, Jul 31, 2009.

  1. nyw11

    nyw11 Private E-2

    My brother, who isn't very computer savvy, asked me to take a look at his computer. He said that at startup, the computer would make it to the Windows XP loading screen, but would then crash with a BSoD. I brought the computer to my house, and was able to start the computer without issue. (I only had a USB mouse plugged in, whereas he probably had a webcam, printer, keyboard, and mouse, though I'm not sure if this made a difference)

    I then ran CCleaner, removing about a gig of information from his two user accounts. I ran MalwareBytes, and SuperAntiSpyware, each of which found little wrong. After each scan, I ran the the Registry Integrity portion of CCleaner, and may have been a bit hasty in my removal of entries. I found that AVG (which I think I installed a while back), was not starting correctly. I uninstalled, and then ran the AVG removal tool. There were still AVG entries on the computer, so I deleted them. (And ran the registry cleaner again) I then tried to reinstall AVG, but was met with errors during installation with files from various locations. I then tried to install Avast, but was unable to. I decided that I would start the "Read and Run Me First guide" from the beginning, and come here for help.

    I Uninstalled all the tools, and followed the procedure.

    SAS
    I was able to install SAS, but was unable to update it from within the program, or using the executable updates from the website.

    MB
    I was unable to Install MB, I was presented with the following error --
    "Microsoft Visual C++ Runtime Library"
    ---------------
    Runtime Error!

    Program C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    This application has requested the runtime to terminate it in an unusual way.
    Please Contact the application's support team for more information.
    ----------------

    ComboFix & RootRepeal
    Each of these tools presented with a BlueScreen crash, but I didn't write down the specific errors. (another cardinal rule broken)

    MGtools
    Ran fine as far as I can tell.


    The logs posted were the only ones that I was able to retrieve.
    I'm mostly here because it seems that malware, or very likely I, has/have screwed up this computer. Any help would be greatly appreciated.
    -nick

    View attachment SASlog.log
    View attachment MGlogs.zip
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears as though you had a user account corruption at some point:
    C:\Documents and Settings\Jason Walker.WALKERS1979
    C:\Documents and Settings\Jason Walker

    I have no idea how these were created:
    Code:
    "C:\WINDOWS\SYSTEM32\"
    %SYSTE~1      Jul 30 2009              "%systemroov%"
    %SYSTE~2      Jul 30 2009              "%systeoroot%"
    %SYSTE~3      Jul 30 2009              "%syste-root%"
    %S{STE~1      Jul 30 2009              "%s{stemroot%"
    -UI           Jul 30 2009              "-ui"
    
    They are all garbage folders.

    This folder need to be cleaned out:
    C:\Documents and Settings\Jason Walker.WALKERS1979\Local Settings\Temp\

    If you have been having the "C++ runtime-error" crashes with 1.39, please download a hotfix version of mbam.exe from here:
    http://www.malwarebytes.org/~marcin/mbam.exe

    Drop this version into the C:\Program Files\Malwarebytes' Anti-Malware directory, and overwrite the previous copy of mbam.exe. Then please make sure MBAM now runs correctly.

    There is this fix:
    http://www.malwarebytes.org/forums/i...howtopic=19388

    I believe this is not a malware issue. But try the fix for MBAM and let me know.

    Does they system crash if you run Combo in safe mode? What is the BSOD error?
     
  3. nyw11

    nyw11 Private E-2

    Should I do anything to the folders that you call "garbage folders"? (Like deletion)

    I cleaned out the Temp folder for the odd account.

    After dropping the new mbam.exe file into the program folder, MB was still unable to run. "error code: 707 (2)"
    In that forum topic, someone mentioned reinstalling MB, should I do that?

    In Safe Mode, Combo starts, but after the initial blue startup screen, it presents with "grep.exe has encounter a problem and needs..." After I choose whether or not to send out the bug report, the "Caution" screen comes up. If I continue to let Combo run, it presents with "pev.cfexe has encountered a problem..." (twice) all the while Combo claims to be scanning. Then the computer restarted. No blue screen this time.

    RootRepeal was able to run in safe mode. I've attached the log.

    Thanks again!

    View attachment RRlog.txt
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try opening each folder and tell me what is there.....

    Yes, try reinstalling MB.

    Can you run the system under the C:\Documents and Settings\Jason Walker profile?
     
  5. nyw11

    nyw11 Private E-2

    Sorry about the late reply, I got a little bogged down with other things.

    It looks as if there is a more serious problem now.
    In trying to start the computer normally, I encounter the follow BSoD

    Code:
    STOP C0000221 - Bad Image Checksum
    The image ntvdm.exe is possibly corrupt, the header checksum does not match the computed checksum. 
    In trying to boot the computer into safe mode, it appears to stall at agpCPQ.sys.

    If the computer is run in "Last Known Good Configuration" The Same BSoD appears, but it names wininet.dll as possibly being corrupt.

    RootRepeal was run under the "Jason Walker" account. Jason Walker.WALKERS1979 is(was) unreachable.
     
  6. nyw11

    nyw11 Private E-2

    **Update**
    My brother said he would be comfortable with reinstalling windows. Since he doesn't have much data on the drive, I copied his data (+/-13gigs) to an external of mine. I'll be reinstalling later today.

    Thanks for your help, it is really appreciated.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.....hope all goes well. :)
     
  8. nyw11

    nyw11 Private E-2

    After a few hours spent with various live OS disks, I finally figured out that it was a failing RAM stick. I took out one stick, and tried to install Windows, that failed. Swapped it for the other stick, and Windows installed! After I got it running, I put the bad stick back in, and the system still started up. I was able to crash the system by opening many programs at once, forcing the use of the broken RAM. I took it back out, ran a bunch of programs, and found the only issue to be lag, which was acceptable on a system with only 256MB.

    This is really my first time encountering a RAM failure, but now I know to try that next time.

    Hope this helps anyone who happens to come across this thread.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds