Error signature and now must boot in safe mode.

Discussion in 'Malware Help (A Specialist Will Reply)' started by jaypegg, Nov 8, 2009.

  1. jaypegg

    jaypegg Private E-2

    Hi
    My computer went to blue screen with the following message
    Error signature

    BCCode : 100000d1 BCP1 : 00000001 BCP2 : 000000FF BCP3 : 00000001
    BCP4 : 0013FB1E OSVer : 5_1_2600 SP : 3_0 Product : 768_1

    C:\DOCUME~1\shelly\LOCALS~1\Temp\WERa13f.dir00\Mini110309-01.dmp
    C:\DOCUME~1\shelly\LOCALS~1\Temp\WERa13f.dir00\sysdata.xml

    Any virus software makes the computer reboot at different points of the removal.
    Is this malware? Can I test my motherboard, or anything else?
    I have swapped out my simms cards thinking one is bad, but computer still reboots, so I put them back in.
    The computer is running at below 60c after running speedfan.
    Any help would be great.
    Jaypegg
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:31:48 PM, on 11/7/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
     
  2. evilfantasy

    evilfantasy Malware Fighter

  3. jaypegg

    jaypegg Private E-2

    Hi
    After much reboots I have the following:
    I cannot download or run SuperAntiv or Combo Fix
    I am including my log files from Hijackthis. and Malwarebytes.
    I ran CCshredder and Killbox to delete my temp files and anything else.
    My computer just reboots when it has had enough I guess.
    Help Jan
    I cannot upload from explorer so I will post attachments from Firefox!!:cry
     

    Attached Files:

    Last edited: Nov 11, 2009
  4. evilfantasy

    evilfantasy Malware Fighter

    What happens when you try to download them?

    Could you run MGtools and if not what happens?
     
  5. jaypegg

    jaypegg Private E-2

    When I download them I save them to a folder. Once they are running, the computer will just reboot into the black screen, and I then run safe mode. Sometimes the keyboard works sometimes not. The scan can run anywhere from 3 seconds to 3 minutes befor it just reboots.
    Thanks Jan:confused
     
  6. evilfantasy

    evilfantasy Malware Fighter

    Try this please.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the next one.

    Vista and Windows 7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.pif
    * Rkill.exe

    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.
    * If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run then try to immediately run the following.


    Download and run exeHelper

    * Please download exeHelper from Raktor to your desktop.
    * Double-click on exeHelper.com to run the fix.
    * A black window should pop up, press any key to close once the fix is completed.
    * A log file named log.txt will be created in the directory where you ran exeHelper.com
    * Attach the log.txt file to your next message.


    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds