BSOD problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jhnybgood, Feb 17, 2010.

  1. jhnybgood

    jhnybgood Private E-2

    Hi,
    I have one computer that seems to have a random BSOD problem that won't go away. There's been no new software or hardware installed, I've updated the drivers, ran all the "READ ME FIRST" scans, but am still getting the BSOD.

    The first BSOD code was:
    IRQL-NOT-LESS-OR EQUAL
    STOP:0x0000000A (0x00000000,0x0000001C,0x00000000,0x80538102)
    This was the error code before running all the scans.



    Today I received this error code:

    STOP: 0x0000008E (0xC0000005,0x805BE7FA,0x9FA0EA68,0x00000000)

    Any help you all can give me on this would be greatly appreciated.

    Thanks

    John
     

    Attached Files:

  2. jhnybgood

    jhnybgood Private E-2

    Here's the last log file

    Thanks again
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have a Master Boot Record infection. We will need to boot to the Recovery Console to remove this infection. You will need your Windows XP boot CD.

    Now boot to the Recovery Console and run the fixmbrto clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below. Don't bother doing any of the below until you have run fixmbr as the below will be a waste of time until fixmbr has run.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Kyle\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. jhnybgood

    jhnybgood Private E-2

    Thanks for the quick reply. Now it seems I have another problem. I installed the Recovery Console fine. But when I tried to boot to it, I got a "Drive read error occured" ctrl, alt delete to restart.

    OK, so I thought I might be able to get around that by booting from the CD and running the console from there. well. when I tried that, the computer froze after pressing enter to boot from CD. OK, maybe I'm having a ROM issue. Changed the ROM drive, still having the same problem.

    So, anything you can do to help me or is this a problem for the manufacturer?

    Thanks again
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be able to boot from the CD. The installed version of the RC is no good for this infection. If you cannot get to the RC from your CD then you have other issues and will need to work them with the manufacturer (as you suggested) or in the Software/Hardware Forum. Is your CD and original Windows CD? Do you have any strange harddisk partitioning or special drivers needed to run your system?

    You better check out all of those \\Rnm-xp1\BENIVEY and similar networked systems too for malware.
     
  6. jhnybgood

    jhnybgood Private E-2

    OK, fixed the boot problem. Turned out to be a bad windows disk! Go figure! I ran the fixmbr and did everything else you suggested. attached are the 2 log files. I'll let you know how the computer acts after I've ran it for a few days.

    Thanks again
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your new MGlogs.zip file is incomplete. Please run GetLogs.bat again and make sure you let it finish running. Then attach the new log so we can be sure the infection was really removed.
     
  8. jhnybgood

    jhnybgood Private E-2

    Ok, ran a new scan. Log file attached.

    Thanks again
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's continue with your MBR infection cleanup. We have some more to do.

    Now download and run the newest MGtools which was just updated. Just download and run it. I don't want you to attach a log right now. We just need the new program installed before we can do the below.

    Now run the C:\MGtools\hafix.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). When it finishes, it will pause, take note of any error message before hitting a key and then hit any key to close the command prompt window.

    Now REBOOT your PC.

    After reboot run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
  10. jhnybgood

    jhnybgood Private E-2

    WTF!!?!?!?!?!? I don't know what the hafix.bat did, but it removed damn near everything from my user profile (doc/settings) and I mean everything. My outlook files, everything from my programs list and on and on. Pretty much making my computer useless and in need to a full reformat! My outlook psd files? GONE! I can't get to mt system recovery to try and move back to an earlier date! My admin tools in the control panel? ALL GONE!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm extremely sorry about this! :-o Not sure what went wrong but this automated fix some how lost information and deleted the wrong folders instead of the HelpAssistant user account only. I'm try to see if there is any file recover software that could possibly be used to help recover the deleted info. Not sure if this will work. In the meantime it would be best not to install/run any addition sofware on the PC ( if that is even possible now) since it would make recovery more difficult.
     
    Last edited: Mar 10, 2010
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    However if you can install anything, see if the below will run:

    Recuva (Slim)

    Choose to recovery all the possible File types and then on the File location form select the option In a specific location and then click the Browse button and select C:\Documents and Settings

    See if this can recover anything.
     
  13. jhnybgood

    jhnybgood Private E-2

    Thanks for the info. I've already reformatted the computer and reinstalled all of the software onto it. Fortunately I had backed up the outlook psd and a few other important files the user had before we started all of this, so she didn't lose very much.

    Thanks again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Again I'm very sorry about the problems this caused. It rarely happens, but procedures for new types of malware problems sometime result in problems even though we try our best to debug them before posting.

    Make sure to check this out: How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds