Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freezes

Discussion in 'Malware Help (A Specialist Will Reply)' started by persevefrance, Dec 28, 2010.

  1. persevefrance

    persevefrance Private E-2

    Hi. It's been more than a week since I've experienced problems with my Asus K42J laptop. My computer has been infected by malware. I remembered that one time I disabled my Avast Free for some reason. I forgot to re-enable it so I think that's the reason why my computer started to get sick.

    Now, I'm experiencing bluescreen error. I also noticed that when I play Flyff, an online rpg, I cannot open my Firefox because it says that firefox has crashed. HOwever, when I'm not playing the game, I can use this browser just like now. I did a virus scan but that wasn't enough.

    I followed by heart the RUN & READ ME FIRST. Malware Removal Guide.

    There were two things I couldn't run: ComboFix and RootRepeal. When I ran ComboFix (I did it thrice), It also resulted to BlueScreen thrice. I knew I disabled the antivirus, firewall and antispyware before I executed ComboFix but it really won't run.

    I double clicked RootRepeal.exe (which I put on my desktop) but a pop-up message appeared saying "RoorRepeal Error FOPS - DeviceIoControlError! Error Code = 0x0000024 Extended Info (0x000000dc)"

    When I clicked "OK" and clicked Scan, a pop-up would read "Could not initialize driver! Please contact the author!" Then I click "OK" again and it read "Could not scan Drive C (error 0x0000024). I just had to close this program.

    Attached here are the logs after performing scans. Looking forward for your assitance. Thank you.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    What is this file? C:\VOTAN

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    • O23 - Service: UBPYB - Unknown owner - C:\Users\Advanced\AppData\Local\Temp\UBPYB.exe (file missing)
    After clicking Fix exit HJT.

    Open notepad and copy and paste the following text in the quote box into the window:

    Save this as fix.bat
    Choose to save as all files.
    Double click fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Are things any better now?
     
  3. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Hi Kestrel13! Thank you for your time. I don't know what C:\VOTAN is.

    Anyway, I followed your instructions. I don't think my problems are solved yet. When I tried to run that online game, then try to open my firefox, it still won't open. A pop-up box says that it has crashed. If I click restart firefox, nothing happens. Even internet explorer won't open. Actually, any other program won't open (such as my computer and my documents). Just a pop-up box stating "EXPLORER.EXE The dependency service or group failed to start."

    Even after I closed the game, still nothing won't run. I had to restart my computer to be able to write you this reply. By the way, when I restart, it usually states "waiting for background programs to close" Usually it doesn't state what background program it is. It's just blank. Sometimes though it states "explorer.exe" or "task host" or "logon sound".

    I don't know if it's appropriate to post this here but I'd like to share what's in my Event Viewer. I just thought it might give you a better picture.

    Just this restart tonight, under Event Viewer-Windows Logs-Application, I see this:
    Warning (8:16:08) - LMS Service cannot connect to Intel(R) MEI driver
    Warning (8:15:16) - The winlogon notification subscriber <Profiles> failed a notification event.
    Warning (8:15:16) - The winlogon notification subscriber <Profiles> was unavailable to handle a notification event.
    Warning (8:15:16) - The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
    Warning (8:15:16) - The winlogon notification subscriber <Sens> failed a notification event.
    Warning (8:15:15) - The winlogon notification subscriber <GPClient> failed a notification event.
    Warning (8:15:15) - The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

    Error - Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x00017b4c
    Faulting process id: 0x7e4
    Faulting application start time: 0x01cba75123c3a2d5
    Faulting application path: C:\Windows\System32\svchost.exe
    Faulting module path: unknown
    Report Id: 6aabf61b-1344-11e0-86e7-1c4bd60b978e

    The error above appeared six (6) times at these times tonight: 8:08:59, 8:08:42, 8:05:26, 8:04:27, 8:03:13, & 7:52:58.

    The error below appeared once at 7:46:55.
    Error - Faulting application name: swwhoami.exe, version: 1.0.0.1, time stamp: 0x2a425e19
    Faulting module name: swwhoami.exe, version: 1.0.0.1, time stamp: 0x2a425e19
    Exception code: 0xc0000005
    Fault offset: 0x000069f8
    Faulting process id: 0x1388
    Faulting application start time: 0x01cba74e16947768
    Faulting application path: C:\MGTools\swwhoami.exe
    Faulting module path: C:\MGTools\swwhoami.exe
    Report Id: 55101a00-1341-11e0-86e7-1c4bd60b978e
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Right click it and check properties, if nothing seems familiar then delete it. Reboot and check it is gone.

    So you are not able to get me new logs to review. Hmm.

    Try this and then follow the next instructions.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Hi again. I deleted Votan, restarted and it's gone. By the way, I forgot to tell you in the previous post that I did run GetLogs.bat but I didn't see the zip file. I couldn't find it. Even with this lasts run, I successfully finished it but I couldn't locate the mglogs.zip.

    I tried running Rkill.exe, Rkill.com and Rkill.scr one at a time, but it each time it caused a system crash; a bluescreen with the following details after windows recovers:

    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.1.7600.2.0.0.256.1
    Locale ID: 1033

    Additional information about the problem:
    BCCode: d1
    BCP1: BFFFFFD9
    BCP2: 00000002
    BCP3: 00000001
    BCP4: 83E60D9E
    OS Version: 6_1_7600
    Service Pack: 0_0
    Product: 256_1

    Files that help describe the problem:
    C:\Windows\Minidump\123010-15912-01.dmp
    C:\Users\Advanced\AppData\Local\Temp\WER-42962-0.sysdata.xml

    I can't download Rkill.pif because "404 file not found"

    I still executed AVPFind.bat and exehelper. Attached here are the two logs. Once again, MGlogs.zip couldn't be located.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Try this and let me know how you get on.

    Try renaming combofix.exe to 167gy.com and see if it then runs in either normal or safe mode.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    I am not sure at this point whether your problems are malware related or not. Only thing I was seeing was that unnusual service, which may still be running. Until I see logs I wont know.
     
  7. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Combofix, which I renamed to 167gy.com, still won't run under normal and safe modes. Both caused bluescreens again.

    I did the OTL and attached the logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    C:\Users\Advanced\Desktop\167gy.com.exe <--- I had asked for it to be renamed with just .com though, not .com.exe

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Tell me or show me with a screenshot in case system look does not work, the contents of this folder:

    C:\Users\Advanced <--- Do not click on anything inside of there!


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :services
    UBPYB
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :dir
      Advanced
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now run OTL again and attach it's log.

    Try to run C:\MGTools.exe and attach the C:\MGlogs.zip if successful.

    How are things running now?
     
  9. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Oh sorry about that 167gy.com.exe... How exactly do I make it just .com if it's .exe in the first place? Just a question.

    Anyway, I attached a screenshot. Did I understand it right?

    The following post contains the fifth attachment.
     

    Attached Files:

  10. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Finally, I saw the MGlogs.zip and attached it here.

    Well, Before I posted this one, I tried to run the online game. Once, it's up, I clicked on firefox and the system suddenly froze. I forced restart and sent you this post. However, when I click now the Windows Explorer icon in the taskbar, the window opens up at once. Before I had to click it twice just to open it. So, I guess my system's better now but there might still be something wrong.

    This was the Error in the Events Log:

    Event 1000, Application Error

    Faulting application name: swwhoami.exe, version: 1.0.0.1, time stamp: 0x2a425e19
    Faulting module name: swwhoami.exe, version: 1.0.0.1, time stamp: 0x2a425e19
    Exception code: 0xc0000005
    Fault offset: 0x000069f8
    Faulting process id: 0x1028
    Faulting application start time: 0x01cba91ccc9225bd
    Faulting application path: C:\MGTools\swwhoami.exe
    Faulting module path: C:\MGTools\swwhoami.exe

    And... before anything else, I just wanna greet you and the whole MajorGeeks community a HAPPY NEW YEAR!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Okay well that service has gonw now.

    That was the only problem I was seeing. You can delete this with windows explorer. C:\Windows\System32\svchost.exe.exp.log

    Just by renaming it. It will pop up a warning "Are you sure you want to rename, it could make the file unusable" etc. But you have to have hidden files and folders set to show so you don't end up with a double extension like .com.exe. You need to rename it back now to combofix.exe

    A very Happy new Year to you too. :)

    Any remaining issues you have are not malware related.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jan 1, 2011
  12. persevefrance

    persevefrance Private E-2

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    Thank you very much Kestrel13. You have helped me a lot. I have to say though, I have remaining other issues. But as far as malware deletion, thank you.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help! Still Having Problems: BlueScreen of Death, Crashing Firefox, System Freeze

    You're welcome. Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds