1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Blue screen of death crashing problems! :(

Discussion in 'Virus & Other Malware Removal' started by High hope, Jul 16, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Hi "MR HELPER", i hope im not going to be a big problem for you!
    Im running windows xp on my toshiba x100 laptop,and for the last two months or so,i have been getting this very irritating blue screen at the worst of times followed by a reboot. After a long struggle i managed to find this error code somewhere in the administrater. I could not read what the blue screen had to say because it would only show for a second or two and then reboot. This is the error i found,
    0*10000050 (0*xe15c3000, 0*00000000, 0804faff5, 0*00000001)
    I hope you can help me fix this up.
    Thanks a million in advance.
     
  2. spdabbs

    spdabbs

    Joined:
    Feb 23, 2007
    Messages:
    548
  3. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Hi there! I got your mail you sent me,i downloaded the ram check you told me to download, but when i click on the application it asked me to put a cd in my d: drive,and after it burnt on to the cd,it asked whether i would like to reboot or not and that i should keep the cd in the drive,i selected YES.,after the reboot it just came to my normal windows and did nothing after that.
    Could you please help me on that now?
     
  4. engti

    engti

    Joined:
    Oct 5, 2005
    Messages:
    129
    When u reboot, press F8 and see if it allows you to boot from cd.

    Otherwise,
    restart,
    press del,
    go into the BIOS and change the boot order to start with the CD drive.
     
  5. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Ok,i wil try that when i get back home. Wil get back to you some time in the afternoon. Thats a lot once again.
     
  6. spdabbs

    spdabbs

    Joined:
    Feb 23, 2007
    Messages:
    548
    On a Tosh, holding down either the "C" or "F12" key should either boot direct from CD or bring up the menu should F8 fail.
     
  7. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    Not all computers have an "F12" boot menu and you may have to select the boot order in the BIOS "setup" as mentioned.

    But for now:

    Run: sysdm.cpl and select Advanced > Startup and Recovery and take the check out of "automatically restart".

    That should get you a full blue screen to read at your leisure. Pay attention to any driver named.

    Also, you can do this:

    1 > create a new folder on the desktop and call it "dumpcheck" or whatever you like
    2 > navigate to %systemroot%\minidump and copy the last few minidump files to that folder.%systemroot% is normally c:\windows. They are numbered by date. You can paste that address in address bar to get there.
    3 > close the folder and right click on it and select Send to Compressed (zipped) Folder.
    4 > use the "manage attachments" in the "advanced" reply window to upload that zip file here as an attachment.

    This might point us to a 3rd party driver causing the error, if one exists for it.
     
  8. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Hallo. I tried replying twice,but i was having problems. Anyway,i hope this goes through.
    I tried using the F12,F8 and DEL options separately. I got a page with about 10 options to pick from when i used the F12 key,but there was nothing like 'boot from cd', so i tried using F2 and i was to find the BIOS settings.
    I selected 'run from cd drive' saved the setting and it took me to windows. A few moments after getting to the windows page,i got th blue screen and it rebooted.
    After the boot,it came to windows again but no blue appeared and no ram test was conducted,so i zipped the minidump and a word document (with a few error codes i collected). I hope you wil be able to help me.
     
  9. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    I am not on the laptop yet. I am using my phone browser,since i dont have a land line telephone (being a student at a university).
    Could you provide me with an e-mail address so that i may mail you the zipped files?,because i cant upload them from the phone.
     
  10. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    Can you tell me just how you created the memory tester?

    Assuming that you have correctly configured the CD drive to be bootable -- it should run the test if it was properly created.

    You do not just copy or drag and drop the ISO file to a writable CD.

    You must normally "run" it and your Burning software such as Roxio or Nero will open and prompt you for the rest.

    If you don't have burning software which supports the ISO extension you can use Deep Burner. I recommend the portable version. Since it does not associate ISO files automatically you must select the proper interface.

    See the attachment.

    http://www.deepburner.com/index.php?r=download
     

    Attached Files:

  11. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Hi there! Ok, i have sent an email to you with the zipped minidump file and a zipped document file in which i have stated some of the error codes i managed to find.
    I would also like to let you know that i feel that this is a problem related to a third party program that i downloaded or copied from a friends laptop who was also having the same problems.
    At time a whole week would go past without getting that BSOD,but at times it shows up maybe 3 times a days.
    I would be really glad if you could work out the problem for me.
    Thanks a lot once again.
     
  12. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    An examination of just the last 2 dump files shows you have a rootkit trojan:

    BugCheck 1000008E, {c0000005, 804ffe67, ef966c98, 0}

    Probably caused by : windev-7f1f-743a.sys ( windev_7f1f_743a+647 )

    http://www.symantec.com/security_response/writeup.jsp?docid=2007-041314-1900-99&tabid=2


    >> I'm going to move your thread to the Security forum and request some help for you there.

    In the meantime can you post a HijackThis Scanlog :

    Download and install HijackThis using the "self extractor". Run it and select "do a system scan and save the log file". Then copy/paste the contents of the log to a reply

    http://www.thespykiller.co.uk/files/hijackthis_sfx.exe
     
  13. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    115,366
    First Name:
    Karen
    Rog asked me to assist with this so once you've posted your HijackThis log as requested, I will post further instructions for you.
     
  14. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    Ok. Thanks for the help so far. I just hope this 'big problem' wil be solved.
    I wil download it when i get home.:)
     
  15. High hope

    High hope Thread Starter

    Joined:
    Jul 16, 2007
    Messages:
    64
    This is the log files that you requested from me, which I acquired after downloading HijachThis and running it after you instructed me :)



    .........................................................

    Logfile of HijackThis v1.99.1
    Scan saved at 10:17:38 AM, on 7/19/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\U0hBUlVLSCBKQVZB\command.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\toshiba\ivp\ism\pinger.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\taskswitch.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Toshiba\Tvs\TvsTray.exe
    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\GetRight\getright.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\PROGRA~1\WinZip\winzip32.exe
    C:\Documents and Settings\SHARUKH JAVA\Desktop\hijackthis_sfx.exe
    C:\Documents and Settings\SHARUKH JAVA\Desktop\PC software\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.za/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\msdxm.ocx
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,[email protected]
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
    O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: GetRight Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
    O15 - Trusted Zone: www.sgnappo.com
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://ak.exe.imgfarm.com/images/no...ularScreenSaversFWBInitialSetup1.0.0.15-3.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{15031CAE-B5BF-4A1E-8035-52679079F5ED}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CCS\Services\Tcpip\..\{27A2949F-9C9B-4C11-8FE9-23935E5DB79A}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CCS\Services\Tcpip\..\{37CFB3F3-66BC-41C9-AEBA-ED1B4E8BC49E}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CCS\Services\Tcpip\..\{46D7D91F-5E69-442C-B892-61CB3157340F}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D51F2A34-09CC-40CF-8675-4438DB495F4D}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.26 85.255.112.104
    O17 - HKLM\System\CS1\Services\Tcpip\..\{15031CAE-B5BF-4A1E-8035-52679079F5ED}: NameServer = 62.94.144.232,151.13.150.22
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.26 85.255.112.104
    O17 - HKLM\System\CS2\Services\Tcpip\..\{15031CAE-B5BF-4A1E-8035-52679079F5ED}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.26 85.255.112.104
    O17 - HKLM\System\CS3\Services\Tcpip\..\{15031CAE-B5BF-4A1E-8035-52679079F5ED}: NameServer = 85.255.116.26,85.255.112.104
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.26 85.255.112.104
    O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
    O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - (no file)
    O21 - SSODL: sMXWGVukbX - {606A9EA5-CAC0-340F-EE61-6D5A79CB5224} - (no file)
    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U0hBUlVLSCBKQVZB\command.exe
    O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/596539

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice