Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard network operating system printer problem ram registry router slow software sound svchost.exe toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Solved: Blue Screen of Death (Likely Cause: Malware?)

Reply  
Thread Tools
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
14-Aug-2009, 05:35 AM #1
Unhappy Blue Screen of Death (Likely Cause: Malware?)
Hello,

I was told to repost in this forum for a better answer. Basically I have a laptop with Windows Vista. I installed a program from an unknown publisher (yes, I'm that stupid). Afterward, I uninstalled the program but problems only got worse. First, internet explorer wouldn't reopen after closing it. Logging off and then back on didn't fix the problem. I also kept getting error messages regarding adobe reader. I uninstalled the program but still no solution. I was about to uninstall Internet explorer but I wanted to restart the computer to make sure it wasn't fixable in that way.

After restarting, I went to log on and got the blue screen error (blue screen of death). It restarted and I chose safe mode this time. With "safe mode with networking", I'm able to use most programs (including IE) just fine. I ran a McAfee scan on my computer. It detected and fixed one problem. But my computer still only worked on safe mode. I tried the free internet scan on "Trend Micro"s website. It turned up results in the scan but had difficulty retrieving info on how to remove it (maybe b/c of safe mode, but maybe b/c of a virus). I researched more trying to find a virus scan that works in safe mode. I re-scanned with "Avira AntiVir" (which works in safe mode) but it turned up no results.

I also have uninstalled all the programs I installed around the time of the BSOD problem through "Control Panel --> Programs and Features". Not only that, I've tried using system restore. However, the restore point is long before the time this problems started occuring. Also, the computer had to restart to finish the restore. When it did, it said the restore was unsuccessful.

I haven't tried "rolling back the drivers" or anything else that some websites recommend when you see a blue screen of death because I don't think those are the causes. I think it has something to do with that unknown publisher's program. That's exactly the time problems started occurring.

I've also run a hijack this scan and the results should be attached. Any help is greatly appreciated. (I also apologize if I had terrible grammar above. It's late and I've been working on this for a while ).

-CouchPotatoGuy
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
14-Aug-2009, 07:52 PM #2
So just to clarify (I know it might be hard to read what I was trying to say), I think I have a virus, but I haven't been able to use any good virus scans that detect malware because I can only access my computer through safe mode. I used AntiVir (which has the benefit of working in safe mode) but it didn't turn up anything. If anyone knows any malware scanning software that's really good and works in safe mode, please suggest it.

Thanks
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
14-Aug-2009, 11:19 PM #3
Further Information
Not being impatient. I just found a way to capture more useful information that will hopefully make it easier to solve. I was able to stop the blue screen from flashing away before I could read the info. I snapped a picure of it and it can be found HERE. The relevant info (I think) is down below. It says:

Technical Information:

*** Stop: 0x0000008E (0xc0000005, 0x94c42B4B, 0x8A164FE0, 0x00000000)

-CouchPotatoGuy

Last edited by CouchPotatoGuy; 15-Aug-2009 at 04:33 AM.. Reason: I rotated the bluescreen image for better viewing
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
18-Aug-2009, 12:58 AM #4
Bump
Bump
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
20-Aug-2009, 10:26 PM #5
Bump 2
Bump
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
22-Aug-2009, 03:02 PM #6
Bump 3
Bump
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
24-Aug-2009, 05:14 PM #7
Bump 4
Bump
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
26-Aug-2009, 03:54 PM #8
Bump
muppy03's Avatar
Senior Member with 1,881 posts.
 
Join Date: Jun 2006
Location: Australia
Experience: gettin there
27-Aug-2009, 03:34 AM #9
Hello and welcome to TSG

IMPORTANT

Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
To make cleaning this machine easier:-
  • Continue to respond to this thread until I give you the All Clean!
  • Please DO NOT uninstall/install any programs unless asked to. It is more difficult when files/programs appear or disappear from the logs.
  • Please do not run any scans other than those requested and do not post any logs/reports unless specifically requested to do so.
  • Please follow all instructions in the order posted.
  • If you have any questions or do not understand instructions, please ask before continuing.
  • Please reply to this thread. Do not start a new topic.

Open Hijack This and select Do a System Scan Only place a check next to the below lines if still present
  • R3 - URLSearchHook: (no name) - - (no file)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...tup1.0.1.2.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{114F5C11-9BDC-4C18-8385-68D5B3C14B77}: NameServer = 85.255.112.147,85.255.112.103
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE3EEAA-32EE-4018-BAA4-72E385CA0165}: NameServer = 85.255.112.147,85.255.112.103
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.147,85.255.112.103
    O17 - HKLM\System\CS1\Services\Tcpip\..\{114F5C11-9BDC-4C18-8385-68D5B3C14B77}: NameServer = 85.255.112.147,85.255.112.103
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.147,85.255.112.103

Once selected close all windows except HJT an click on Fix Checked

See if you can now BOOT in Normal Mode

Please download Malwarebytes' Anti-Malware and save to your desktop. When saving RENAME to muppy.exe.
  • Double-click muppy.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:

    Update Malwarebytes' Anti-Malware
    Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply

    Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.

Please reply with:-
  • MBAM log
  • New HJT log
__________________
Teacher - Malware Removal University - You too could train to help others

Topics not replied to within 3 days will be removed from my Subscribed Threads List
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
28-Aug-2009, 12:01 AM #10
I did everything up to "boot in normal mode". After clicking "fix checked" and restarting, I was unable to login without the blue screen popping up again. I still was able to install MBAM. But it doesn't run in safe mode. I do apologize. I accidentally installed another program that I thought was MBAM but instead was just a popup. Attached is my new HiJackThis log.
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
muppy03's Avatar
Senior Member with 1,881 posts.
 
Join Date: Jun 2006
Location: Australia
Experience: gettin there
28-Aug-2009, 12:15 AM #11
Did you rename MBAM?
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
29-Aug-2009, 04:27 PM #12
Yes, I renamed the installer "muppy.exe".
muppy03's Avatar
Senior Member with 1,881 posts.
 
Join Date: Jun 2006
Location: Australia
Experience: gettin there
29-Aug-2009, 10:37 PM #13
Download and Run: RSIT
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
__________________
Teacher - Malware Removal University - You too could train to help others

Topics not replied to within 3 days will be removed from my Subscribed Threads List
CouchPotatoGuy's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Jun 2009
Experience: Beginner
29-Aug-2009, 11:21 PM #14
Both of the requested documents are attached.
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
muppy03's Avatar
Senior Member with 1,881 posts.
 
Join Date: Jun 2006
Location: Australia
Experience: gettin there
30-Aug-2009, 01:08 AM #15
Quote:
I installed a program from an unknown publisher (yes, I'm that stupid). Afterward, I uninstalled the program but problems only got worse.
What Program was it please?

Do you know what these are?
  • C:\Program Files\Causes
    C:\Program Files\African Safari

Double check MBAM was renamed and try to run again make sure you right click and choose run as administrator

If no luck please run GMER
  • Download GMER by GMER from one of the links below:
    Link1
    Link2
  • Unzip it to a folder on your desktop
  • Double click on gmer.exe to launch GMER
  • If asked, allow the gmer.sys driver load
  • If it warns you about rootkit activity and asks if you want to run scan, click OK
  • If you don't get a warning then
    • Click the rootkit tab
    • Click Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerrk.txt
  • Click on the >>> tab
  • This will open up the rest of the tabs for you
  • Click on the Autostart tab
  • Click on Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerautos.txt
  • Copy and paste the contents of gmerautos.txt and gmerrk.txt as a reply to this topic


Please reply with:-
  • MBAM log
  • 2 x GMER Logs
__________________
Teacher - Malware Removal University - You too could train to help others

Topics not replied to within 3 days will be removed from my Subscribed Threads List
Reply

Tags
blue screen error, blue screen of death, bsod, malware

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:21 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.