Improper shutdown on sleep - bluescreen error

Discussion in 'Malware Help (A Specialist Will Reply)' started by SabreGirl, Jan 10, 2014.

  1. SabreGirl

    SabreGirl Private E-2

    Cannot get this fixed! I get an improper shutdown every time my laptop goes to sleep. After improper shutdown, this is my message:

    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.1.7601.2.1.0.768.3
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 9f
    BCP1: 0000000000000003
    BCP2: FFFFFA80041B0E30
    BCP3: FFFFF80005624518
    BCP4: FFFFFA8004D46450
    OS Version: 6_1_7601
    Service Pack: 1_0
    Product: 768_1

    Now, this is all Greek to me. I've tried searching for answers for 5 days and I'm just done. I don't get it. I have a paid Kaspersky AV that hasn't caught anything and Spybot found a trojan that it fails to remove. I THINK I successfully completed the read/run first requirements, I'm attaching those logs - please help :confused
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Sabregirl,



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Jennis & Wendy\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : BackgroundContainer ("C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Jennis & Wendy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun [7][7][x]) -> FOUND
    • [V2][SUSP PATH] BackgroundContainer Startup Task : "C:\Windows\SysWOW64\Rundll32.exe" - "C:\Users\Jennis & Wendy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun [7][7][x] -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Now re run Hitman Pro and have it remove Potential Unwanted Programs (Conduit, rocketfuel etc..)



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Jennis & Wendy\AppData\Roaming\SearchProtect
    C:\ProgramData\BitDefender
    C:\ProgramData\Conduit
    C:\ProgramData\DP45977C.lfl
    C:\Program Files (x86)\Conduit
    C:\Program Files (x86)\SearchProtect
    C:\Windows\SysWOW64\iertutil(69).dll
    C:\Windows\SysWOW64\urlmon(71).dll
    C:\Windows\SysWOW64\wininet(72).dll
    C:\Users\Jennis & Wendy\AppData\Local\Conduit
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!


    Note:
    If you continue to have BSOD's after we have finished working here in the malware forum, I will have to refer you to the software forum. :)
     
  3. SabreGirl

    SabreGirl Private E-2

    Hi Kestrel13 - thanks for your reply.

    I ran what you said, here are the results. When I ran RogueKiller, it only found two SUS PATH and I did have a couple errors while running OTM, I got 2 popups "OTM.exe - Ordinal not found: The ordinal 298 could not be located in the dynamic link library iertutil.dll". I clicked OK and finished all scanning.

    I shut my laptop to put it to sleep and when I came back to wake it up, the light was on, the screen was black and wouldn't respond. I had to push and hold the power button and improperly shut it down. I'm going to leave it now and see if it goes into an improper shutdown by itself.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you forget this part? :)


     
  5. SabreGirl

    SabreGirl Private E-2

    Ugh, yes....
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Sabregirl,

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. SabreGirl

    SabreGirl Private E-2

    OK, avenger seemed to work right, prompted restart but never gave me a log file. Can't find it with a file search either. Didn't want to re-do it, thought I'd wait and see what you thought after seeing the MG log.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are using more than one antivirus! You must uninstall one right now before we continue, I'd keep Kaspersky and ditch Adaware.

    • Ad-Aware Antivirus
      [*]Kaspersky PURE


    Please download Combofix to your desktop. Please refer to these instructions prior to running.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Program Files\Internet Explorer\ieproxy(12).dll
    C:\Program Files\Internet Explorer\ieproxy(48).dll
    C:\Windows\SysNative\urlmon(65).dll
    C:\Windows\SysNative\wininet(66).dll
    C:\Windows\SysNative\iertutil(56).dll
    C:\Windows\SysWOW64\iertutil(69).dll
    C:\Windows\SysWOW64\urlmon(71).dll
    C:\Windows\SysWOW64\wininet(72).dll
    
    Folder::
    C:\ProgramData\BitDefender
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. SabreGirl

    SabreGirl Private E-2

    WOW, I can't believe I completely forgot about Adaware being AV! I also had to ditch Spybot. So sorry:-o
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to remove Some Adaware remnants now and a few files to be rid of.

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    BdfNdisf
    bdfwfpf
    
    File::
    c:\windows\SysWow64\drivers\mgkeif.sys
    C:\Windows\SysNative\iertutil(56).dll
    C:\Windows\SysNative\urlmon(65).dll
    C:\Windows\SysNative\wininet(66).dll
    
    Folder::
    c:\program files\lavasoft
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. SabreGirl

    SabreGirl Private E-2

    OK. All scans ran fine, still getting the improper restart on sleep.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, it's a little stubborn... but we may nail it this time round.


    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    nclk
    
    File::
    c:\windows\system32\drivers\mgkeif.sys
    C:\Windows\vvyqlaee.txt
    C:\Windows\SysNative\iertutil(56).dll
    C:\Windows\SysNative\urlmon(65).dll
    C:\Windows\SysNative\wininet(66).dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. SabreGirl

    SabreGirl Private E-2

    I THINK that did it... I'm cautiously optimistic. I uninstalled some things before running the scans because I didn't know if they had any real-time protection that might have been holding onto junk. I was having problems last night with my scanner but just tested it and seems to be OK now - I don't know if it was a new problem or not, I don't use my scanner often. It was some kind of communication and RAM memory problem. Tested sleep/shutdown and woke up without issues! Oh, I also DID get the error when running combofix ... the WhoIAM, I think it's called, that combofix asks you not to hit cancel but to wait until the close button pops up. I had never gotten that error before on previous scans
     

    Attached Files:

    Last edited: Jan 14, 2014
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Sabregirl,

    surf around for a night, post back tomorrow and let me know how things are running. The logs look good, so if the problem crops up again, you may need to post in the software forum about it. :)
     
  15. SabreGirl

    SabreGirl Private E-2

    Haven't had any issues with sleep. I am having an issue with Kapersky this morning, it won't update. It just says 'update failed' but I can't find any info on why.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to uninstall it and reinstall it? :confused
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds