help (repost from driver thread)

Discussion in 'Malware Help (A Specialist Will Reply)' started by doggyexe, Dec 17, 2012.

  1. doggyexe

    doggyexe Private E-2

    I have been getting BSOD errors related to bad drivers but have been unable to identify which ones (the malware removal guide replaced qmgr.dll but the problem persists) computer runs at normal speed in safe mode without errors, but in normal mode it is only a matter of time before explorer.exe crashes which makes it difficult to install any new software
    (other symptoms: desktop icons keep refreshing themselves)

    any help or fresh ideas to try is appreciated

    PC: XP home, Pentium 4, 2G RAM, 4G pagefile, 80G HD
    anitvirus: avira (no detections in logs prior to problem though I've seen several computers get infected by scareware despite avira, spywareblaster, and using spybotS&D's host file so i know avira is not reliable for everything)
    firewall: sygate
    browser: firefox
    scan disk: did not find any file corruption or bad sectors on hard drive
    driver verifier: identified ctjystk.sys and cdralw2k and I have disabled them via autoruns and their associated windows service but explorer crash problems persist
    sfc /scannow: could not complete due to explorer crash in normal mode and could not initiate in safemode
    recovery console: could not install due to explorer crash in normal mode and could not install in safemode

    RogueKiller (could not install/run in safemode)
    Malwarebytes Anti-Malware (no detections when I ran the scan, this is a shared computer so it is possible it was infected and whoever tried to remove the infection only removed it partially)
    TDSSKiller (could not install/run in safemode)
    HitmanPro (could not install/run in safemode)
    MGtools (ran and logs are attached)

    either malwarebytes or MGtools disabled my system restore so that is no longer an option either(never had 100% success with restores anyways)

    btw, are there any successful methods of preventing scareware from getting onto a computer?
     

    Attached Files:

    • old.zip
      File size:
      96.8 KB
      Views:
      3
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The should all run in safe boot mode. What problem are you having. These don't even install. They just run.

    Please attach the correct C:\MGlogs.zip file not a log that you have created.

    They do not do this.


    Safe surfing habits work very well >>> How to Protect yourself from malware!

    But nothing is perfect especially since security starts and ends with the people using the PC.
     
  3. doggyexe

    doggyexe Private E-2

    when i click on the icons nothing happens (do they require network enabled safemode perhaps? or is an infection preventing those programs from executing?)

    those are all the logs from the C:\ directory that I zipped, if MG tools creates a zipped log file by itself, what directory is it in?

    well my system restore points were intact before running those two tools and attempting to run the other 3, and afterwards my system restore was completely turned off without any program asking me to. I was only prompted to reboot.

    you are preaching to the choir, I've been using the advice on this forum for years, and for a computer to run for 12+years before it gets its first infection is a pretty good testament about the effectiveness of the advice offered in these forums. I was merely wondering if anyone knew of specific prevention software to block known rouges from ever installing themselves onto your system(along the same lines as spywareblaster and spybotS&D blacklisting known bad websites to prevent users from ever going there), since googling only turned up afterthefact removal methods and not prevention. Or is there an AV that performs better at this particular portion of the protection than avira since avira does great at detecting and quarantining other things but does not catch all the rouges out there.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot comment on whether it is an infection or not until I see some logs but no they do not require a network connection.


    As stated on the instructions C:\MGlogs.zip It is not in the MGtools folder. What you attached is a 7Zip file which is not a standard Zip file and would thus require every malware helper to install 7Zip in order to look at the file. We don't want to have to do this so we use a standard zip program to create normal ZIP files that everyone can easily look at.


    Okay but I can still tell you that they do not do this. They have no ability built in to do that.



    There is no way to do this which is why this forum exists. SpywareBlaster and Spybot are basically toys these days compared to how advance malware has become. While I still do recommend SpywareBlaster for the items it does help to prevent, they are insignificant compared to what real infections plague forums like this everyday.

    No AVs provide full protection. If they did, this forum would not be so busy. Every thread in the forum has infections being missed by free as well as paid software and even when they detect the infections ( which is no always the case ) the don't have the ability to properly remove them ( again which is why this forum exists and is so busy as are many others ).
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I booted up another PC where I knew I already had 7Zip installed. This PC of yours has original non-updated Windows XP. Why would you leave it at original base level with none of the service packs installed? This is in direct violation of step 1 in How to Protect yourself from malware! which you say you are following. I even wonder if not being able to run some of the tools is due to this. Most prgrams these days will require at least SP2 and some SP3. Not sure if this some how was an indirect cause of restore points going missing.

    The above is the only issue observed in your logs. There is no malware showing.

    I reatatched your ZIP file in standard ZIp form
     

    Attached Files:

    Last edited: Dec 20, 2012
  6. doggyexe

    doggyexe Private E-2

    thank you very much for taking the time to figure out what happened, I think you are right, the lack of updates was probably incompatible with some of the malware removal software. Before all this I was not able to update my AV(program, not database) because the newest version did not support my version of windows as well.

    I have reformatted and installed xp pro sp3 and have no problems at the moment with the same hardware and drivers.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you have it working and updated. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds