Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

> 

When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.

 
Reply to this topicStart new topic
> Bsod Superantispyware
Jeff Finnan
post Jul 5 2008, 07:02 AM
Post #1


New Member
*

Group: Members
Posts: 13
Joined: 3-July 08
Member No.: 220,131



While installing SUPERAntiSpyware in normal mode I got a BSOD

Stop: 0x1000007e(0xc0000005, 0xb17b6f83, 0xbacf3b98, bacf3894)

Saskutil.sys address b17b6f83 base at b178100, datastamp 48163ef6

Here is the .dmp result:

Loading dump file mini070508-01.dmp
----- 32 bit Kernel Mini Dump Analysis

DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 0b6c0020
PfnDataBase 805620c8
PsLoadedModuleList 8055d720
PsActiveProcessHead 805638b8
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000007e
BugCheckParameter1 c0000005
BugCheckParameter2 b17b6f83
BugCheckParameter3 bacf3b98
BugCheckParameter4 bacf3894
PaeEnabled 00000001
KdDebuggerDataBlock 8054d2e0
MiniDumpFields 000004ff

TRIAGE_DUMP32:
ServicePackBuild 00000300
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 00002268
ThreadOffset 000024c0
CallStackOffset 00002720
SizeOfCallStack 00004000
DriverListOffset 000069b0
DriverCount 00000092
StringPoolOffset 00009508
StringPoolSize 00002d20
BrokenDriverOffset 00000000
TriageOptions ffffffff
TopOfStack bacf3c60
DebuggerDataOffset 00006720
DebuggerDataSize 00000290


Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible

Built by: 2600.xpsp.080413-2111
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Jul 05 06:23:04 2008
System Uptime: 0 days 0:17:18
start end module name
804d7000 806e4000 nt Checksum: 001F442E Timestamp: Sun Apr 13 14:
31:06 2008 (4802516A)

Unloaded modules:
b431f000 b434a000 kmixer.sys Timestamp: unavailable (00000000)
b5d0b000 b5d18000 STREAM.SYS Timestamp: unavailable (00000000)
b5dc1000 b5dc4000 SLIP.sys Timestamp: unavailable (00000000)
b5f56000 b5f81000 kmixer.sys Timestamp: unavailable (00000000)
baedb000 baedc000 drmkaud.sys Timestamp: unavailable (00000000)
b72f3000 b7300000 DMusic.sys Timestamp: unavailable (00000000)
baaa8000 baab6000 swmidi.sys Timestamp: unavailable (00000000)
b5f81000 b5fa4000 aec.sys Timestamp: unavailable (00000000)
bae3c000 bae3e000 splitter.sys Timestamp: unavailable (00000000)
b5d99000 b5dad000 parport.sys Timestamp: unavailable (00000000)
ba094000 ba098000 kbdhid.sys Timestamp: unavailable (00000000)
bac80000 bac85000 Cdaudio.SYS Timestamp: unavailable (00000000)
ba098000 ba09b000 Sfloppy.SYS Timestamp: unavailable (00000000)

Finished dump check

C:\WINDOWS\Minidump>

It will only start in Safe Mode. SUPERAntiSpyware will run in Safe Mode. I tried to uninstall it there but it does not show up in Add/Remove nor can I find and uninstall in SUPERAntiSpyware program files. I tried to reinstall but it says Administrative policies do not allow it in Safe Mode. Can I change that and if so how? Is there a better approach to fixing this?

Thanks,
Jeff
Go to the top of the page
 
+Quote Post
hamluis
post Jul 5 2008, 11:42 AM
Post #2


Forum Addict
******

Group: Members
Posts: 4,974
Joined: 3-September 05
From: Killeen, TX
Member No.: 33,068



I'd try running chkdsk /r on the system...not sure why you got the BSOD.

Done any other malware scans?

Louis
Go to the top of the page
 
+Quote Post
Jeff Finnan
post Jul 5 2008, 12:15 PM
Post #3


New Member
*

Group: Members
Posts: 13
Joined: 3-July 08
Member No.: 220,131



Here's is how I got to this state: http://www.techspot.com/vb/topic107890.html

While I waited for a response I thought I would post here too. I am doing the vundo check at the moment.


QUOTE(hamluis @ Jul 5 2008, 12:42 PM) *
I'd try running chkdsk /r on the system...not sure why you got the BSOD.

Done any other malware scans?

Louis


This post has been edited by Jeff Finnan: Jul 5 2008, 12:18 PM
Go to the top of the page
 
+Quote Post
hamluis
post Jul 5 2008, 12:25 PM
Post #4


Forum Addict
******

Group: Members
Posts: 4,974
Joined: 3-September 05
From: Killeen, TX
Member No.: 33,068



BleepingComputer.com - Am I infected What do I do - http://www.bleepingcomputer.com/forums/forum103.html

My suggestion is that you post to the above link, where dedicated assistance is available for malware issues.

The fact that you seem to have something preventing/interfering with installation of malware-defense programs...convinces me that this should be the suggested course of action for you.

If you go that route, please follow all procedures/guidelines for facilitating expeditious, accurate assistance.

Louis
Go to the top of the page
 
+Quote Post
usasma
post Jul 5 2008, 02:54 PM
Post #5


Visually handicapped, hence the avatar :0)
******

Group: Moderator
Posts: 13,376
Joined: 2-October 05
From: Southeastern CT, USA
Member No.: 35,824



I suspect that you're still infected also - and that's what's generating the crashes - although your Norton Antivirus could also be causing this.
I'll move this over to the Am I Infected forum for some more expert help from there.


--------------------
- John
**If you need a more detailed explanation, please ask for it. I have the Knack. **
Go to the top of the page
 
+Quote Post
Jeff Finnan
post Jul 5 2008, 09:00 PM
Post #6


New Member
*

Group: Members
Posts: 13
Joined: 3-July 08
Member No.: 220,131



The computer will constantly try to reboot after showing the startup Windows screen with the moving blue bar. It goes for a little bit and then reboots. I tried a repair from the Windows XP CD. Still the same. I probably should not have done that because I think it wants to continue with setup.

If I F8 and go to Safe Mode, I am pretty sure that it wants to do a Chkdsk /R after about an hour it reboots and if I F8 and Safe Mode it Says It cannot install in Safe Mode and the reboots return.

I went into the recovery console.
Did a fixmbr,
ATTRIB -H C:\\boot.ini
ATTRIB -S C:\\boot.ini
ATRIB -R C:\\boot.ini
del boot.ini
BOOTCFG /Rebuild
FIXBOOT

Still get the constant rebooting.
I even tried a boot floppy and still the same result.

QUOTE(usasma @ Jul 5 2008, 03:54 PM) *
I suspect that you're still infected also - and that's what's generating the crashes - although your Norton Antivirus could also be causing this.
I'll move this over to the Am I Infected forum for some more expert help from there.


This post has been edited by Jeff Finnan: Jul 5 2008, 09:02 PM
Go to the top of the page
 
+Quote Post
Jeff Finnan
post Jul 6 2008, 05:36 AM
Post #7


New Member
*

Group: Members
Posts: 13
Joined: 3-July 08
Member No.: 220,131



I am thinking that I will put in a new drive.

Since I was considering a new drive, I decided to see if an new installation of Windows rather than a repair which kept giving me the rebooting. It turns out the new installation is proceeding.



This post has been edited by Jeff Finnan: Jul 6 2008, 08:19 AM
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 4th September 2008 - 11:47 PM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.