Win7 64 BSOD STOP error

Discussion in 'Malware Help (A Specialist Will Reply)' started by qsek, Jun 15, 2012.

  1. qsek

    qsek Private E-2

    Hi,
    In my last windows session i did:
    • installed webcam software + driver + AskToolbar
    • Downloaded and installed about 14 Windows Updates including several .net Framework and Win7 "core" updates.
    • Chose restart now; after the desktop closed; windows update did some work ; waited until BIOS Logo came up; booted into BIOS; turned off the computer with switch. (It was late)
    • Next day: Booted into Windows Logo, after the windows logo assembled i got a bluescreen.

      STOP: 0x0000007B (0xFFFFF880009A9928, 0xFFFFFFFFC000000D, 0x0000000000000000, 0x0000000000000000)

      The computer restarted and i did a system repair (several times)
      But the recovery screen told me that the system could not been repaired.

      ProblemName: StartupRepairOffline
      Problemsignature 01: 6.1.7600.16385
      Problemsignature 02: 6.1.7600.16385
      Problemsignature 03: unknown
      Problemsignature 04: 21200192
      Problemsignature 05: AutoFailover
      Problemsignature 06: 19
      Problemsignature 07: BadDriver
      Operatingversion: 6.1.7600.2.0.0.256.1

    I also get this bluescreen when i boot into safe mode (with all options). Drivers are loading, then bluesceen.

    What i tried to fix the Problem:
    Boot from last good restore point option: No effect.
    System Restore: Not working. I had several Restore Points from the last days. None of them worked in the recovery screen. It just said that it could not complete the operation.

    Unplugged all USB devices: No effect.
    Disabled USB Legacy Support: No effect.
    Unplugged all HDDs except my SSD where the Win7 64 is on: No effect.
    Unplugged all HDDs, removed from BIOS list also, replugged and let BIOS detect again: No effect.

    Recovery console:
    sfc /scannow - Has found some errors but could not repair all.
    chkdsk /f - Could not access the drive.
    bootrec /fixmbr - Done, but no effect, still getting the same BSOD.
    bootrec /rebuildbcd - Could not find any valid windows installation ( Found windows versions : 0 ).
    Win7DVD:\boot\bootsec.exe /nt60 all /force - Done, no effect.

    Windows Drive scanning on startup (i did this from an WinXP 32 OS on another HDD): Fixed some errors with ~"Capital Letter Filetable" but other than that, all clean.


    Additional note: I can see the System Reserved partition in my winXP 32 system as C: drive and the SSD (Win7 64) is on F: among my other SCSI drives.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Moving this to the Software Forum because I don't see a reason to suspect malware. Unless you can provide some other information as to why you suspected malware to be the cause of your problem.
     
  3. qsek

    qsek Private E-2

    Ok i have done a scan with Windows Removal Tool for malicious software and i got three hits on the Win7 64 SSD:

    trojan:Win32/Alureon.DX - partly removed, manual steps necessary
    Trojan:Win32/Bamital.I - Removed
    TrojanDownloader:Win32/Harnig.S - Removed

    I could not complete the manual steps because it gave me an error when i clicked on the link in the error report for Win32/Alureon.DX

    I still dont know if this is the cause for the BSOD, but i posted the malware forums because i found that topic with another guy having the same BSOD with an Alureon Trojan also.

    What tools can i use to detect/remove/get logs from this Alureon on my SSD?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay with this additional info, then let's try the below ( and I'll move this back to the Malware Forum too ).

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  5. qsek

    qsek Private E-2

    I had to unplug two of my HDDs including this WinXP 32 (from where im posting this) so that FRST64.exe would detect the SSD where the Win7 64 is.

    I also deleted some porn download entrys of mine in the log file :innocent
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot into normal Windows
     
  7. qsek

    qsek Private E-2

    Awesome! my system started just fine, it even finished the windows updates i could not complete before.
    Thank you very much for your help!
    Actually two times i was very close to just format and reinstall: before i posted here and before i ran the Windows Tool and detected the Trojan.
    This one hell of a virus and i cant belive that it managed to modify a windows file so that one will boot into a BSOD.
    Honestly i've had problems with AppData\Roaming\Bc\svhst stuff before, despite having Firewall and Malwaresoftware.
    Is there a way (apart from using Firewall/Malwaresoftware) to protect yourself from this Virus variant exclusively?
    Maybe alter the folder rights so the system can not write into this folder anymore?
    Also can these steps be done by myself when i encouter a similar problem again? What software do i need to utilize this logs?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There is no absolute 100% protection method but the most important component element of security begins with the users of the PC. ;) The below can help, but again, malware has risen to new all time levels and bypasses and breaks most security programs who lag far behind.

    Will not help. Anything you can change, malware can change too and actually, since they know Windows inside and out better than most people, they will change things that even you cannot change even if you are the admin.

    No not really because if is rare that infections are exactly the same each time. Infections can change what they do, what files they impact,....etc many times per day. You really need to be trained in the Windows OS and in the art of malware removal.

    If you find that you still have malware problems, the below would be your starting point:

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds