1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Copy errors from XP CD and Windows Component Wizard

Discussion in 'Malware and Virus Removal Archive' started by IndustrialOne, 2014/02/24.

  1. 2014/03/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Reader and Java must be kept up to date for security reason.
    If you insist to keep your your computer at security risk I have to way to force you to update those two.
    Just a friendly warning.

    Here is a screenshot from my XP installation:

    [​IMG]
     
  2. 2014/03/10
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    Oh I found it now, on my installation it's called "BITS "

    [​IMG]
     

  3. to hide this advert.

  4. 2014/03/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's the one :)
     
  5. 2014/03/11
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    I set BITS to automatic but it just stays on "starting ".
    Also I got a bluescreen just now while doing some audio mixing. IRQL_NOT_LESS_THAN_EQUAL or something like that (I'm recalling from memory, not sure if thats the exact message)
     
  6. 2014/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download BlueScreenView
    Unzip downloaded file.
    Double click on BlueScreenView.exe file to run the program.
    When scanning is done, go Edit>Select All.
    Go File>Save Selected Items, and save the report as BSOD.txt.
    Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.
     
  7. 2014/03/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
  8. 2014/03/19
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    Hey, sorry, it's been a hectic week.

    I downloaded Bluescreenview and the latest crash it displays was on 12/17/2013 but the history goes all the way back to 2007 a little before I got my first job, lol.

    Should I still paste it? I remember that I didn't let it finish dumping so that's probably why there's no record of the crash a week ago.
     
  9. 2014/03/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Post just some recent (10-15) occurrences.
     
  10. 2014/03/20
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    I only have 15 of them total but here you go.

    ==================================================
    Dump File : Mini121713-01.dmp
    Crash Time : 12/17/2013 7:17:07 AM
    Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000007e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x8b376e73
    Parameter 3 : 0xb852b914
    Parameter 4 : 0xb852b610
    Caused By Driver : avgntflt.sys
    Caused By Address : avgntflt.sys+130fc
    File Description : Avira Minifilter Driver
    Product Name : Avira Product Family
    Company : Avira Operations GmbH & Co. KG
    File Version : 14.0.2.236
    Processor : 32-bit
    Crash Address :
    Stack Address 1 : avgntflt.sys+14067
    Stack Address 2 : fltMgr.sys+118ff
    Stack Address 3 : fltMgr.sys+11e86
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini121713-01.dmp
    Processors Count : 8
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 12/17/2013 7:21:14 AM
    ==================================================

    ==================================================
    Dump File : Mini111612-01.dmp
    Crash Time : 11/16/2012 9:43:36 PM
    Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
    Bug Check Code : 0x00000050
    Parameter 1 : 0xfffffff4
    Parameter 2 : 0x00000000
    Parameter 3 : 0x805c4a27
    Parameter 4 : 0x00000000
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+22f5f
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 5.1.2600.5512 (xpsp.080413-2111)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+22f5f
    Stack Address 1 : ntkrnlpa.exe+493ae
    Stack Address 2 : ntkrnlpa.exe+6d600
    Stack Address 3 : ntkrnlpa.exe+eda27
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini111612-01.dmp
    Processors Count : 8
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 11/16/2012 9:53:40 PM
    ==================================================

    ==================================================
    Dump File : Mini080608-01.dmp
    Crash Time : 8/6/2008 1:20:56 AM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf50edb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini080608-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 8/6/2008 1:23:34 AM
    ==================================================

    ==================================================
    Dump File : Mini080408-01.dmp
    Crash Time : 8/4/2008 9:16:49 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf51ddb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini080408-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 8/4/2008 9:20:17 PM
    ==================================================

    ==================================================
    Dump File : Mini051508-02.dmp
    Crash Time : 5/15/2008 2:01:29 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf3e3eb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini051508-02.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 5/15/2008 2:04:01 PM
    ==================================================

    ==================================================
    Dump File : Mini051508-01.dmp
    Crash Time : 5/15/2008 1:53:36 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf481eb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini051508-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 5/15/2008 1:57:44 PM
    ==================================================

    ==================================================
    Dump File : Mini041808-01.dmp
    Crash Time : 4/18/2008 9:54:12 AM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf3ab2b8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini041808-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 4/18/2008 9:56:58 AM
    ==================================================

    ==================================================
    Dump File : Mini041208-01.dmp
    Crash Time : 4/12/2008 9:03:25 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf4bcbb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini041208-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 4/12/2008 9:05:59 PM
    ==================================================

    ==================================================
    Dump File : Mini041108-01.dmp
    Crash Time : 4/11/2008 9:22:37 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf51beb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini041108-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 4/11/2008 9:25:08 PM
    ==================================================

    ==================================================
    Dump File : Mini022208-01.dmp
    Crash Time : 2/22/2008 12:25:20 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf528cb8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini022208-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 2/22/2008 12:28:03 PM
    ==================================================

    ==================================================
    Dump File : Mini021808-01.dmp
    Crash Time : 2/18/2008 6:01:54 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x804d9e6d
    Parameter 3 : 0xf4c05b8c
    Parameter 4 : 0x00000000
    Caused By Driver : pgfilter.sys
    Caused By Address : pgfilter.sys+1032
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+2e6d
    Stack Address 1 : pgfilter.sys+1032
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini021808-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 2/18/2008 6:04:26 PM
    ==================================================

    ==================================================
    Dump File : Mini122607-01.dmp
    Crash Time : 12/26/2007 8:38:11 AM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x8054bf8e
    Parameter 3 : 0xf3ff7b88
    Parameter 4 : 0x00000000
    Caused By Driver : ntoskrnl.exe
    Caused By Address : ntoskrnl.exe+74f8e
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 5.1.2600.5512 (xpsp.080413-2111)
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+74f8e
    Stack Address 1 : ntoskrnl.exe+aca07
    Stack Address 2 : ntoskrnl.exe+ae36f
    Stack Address 3 : ntoskrnl.exe+ac6c7
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini122607-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 12/26/2007 8:40:44 AM
    ==================================================

    ==================================================
    Dump File : Mini120107-01.dmp
    Crash Time : 12/1/2007 8:19:48 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xaf62af62
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000000
    Parameter 4 : 0x804dc80d
    Caused By Driver : ntoskrnl.exe
    Caused By Address : ntoskrnl.exe+b158
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 5.1.2600.5512 (xpsp.080413-2111)
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+b158
    Stack Address 1 : ntoskrnl.exe+580d
    Stack Address 2 : ntoskrnl.exe+ddfc
    Stack Address 3 : ntoskrnl.exe+de2e
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini120107-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 12/1/2007 8:22:12 PM
    ==================================================

    ==================================================
    Dump File : Mini111507-01.dmp
    Crash Time : 11/15/2007 6:38:57 AM
    Bug Check String : BAD_POOL_CALLER
    Bug Check Code : 0x000000c2
    Parameter 1 : 0x00000007
    Parameter 2 : 0x00000cd4
    Parameter 3 : 0x00000000
    Parameter 4 : 0xe1062570
    Caused By Driver : win32k.sys
    Caused By Address : win32k.sys+57a3
    File Description : Multi-User Win32 Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 5.1.2600.5512 (xpsp.080413-2105)
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+5c9ae
    Stack Address 1 : ntoskrnl.exe+74e41
    Stack Address 2 : win32k.sys+29ef
    Stack Address 3 : win32k.sys+ab3
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini111507-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 11/15/2007 6:41:53 AM
    ==================================================

    ==================================================
    Dump File : Mini111207-01.dmp
    Crash Time : 11/12/2007 1:52:34 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x00000016
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000000
    Parameter 4 : 0x804dc352
    Caused By Driver : ntoskrnl.exe
    Caused By Address : ntoskrnl.exe+b158
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 5.1.2600.5512 (xpsp.080413-2111)
    Processor : 32-bit
    Crash Address : ntoskrnl.exe+b158
    Stack Address 1 : ntoskrnl.exe+5352
    Stack Address 2 : ntoskrnl.exe+cf72
    Stack Address 3 : IoloFltr.sys+afdb
    Computer Name :
    Full Path : C:\WINDOWS\Minidump\Mini111207-01.dmp
    Processors Count : 1
    Major Version : 15
    Minor Version : 2600
    Dump File Size : 65,536
    Dump File Time : 11/12/2007 1:54:59 PM
    ==================================================
     
  11. 2014/03/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    The most recent report comes from 12/17/2013 so I'm not sure where are the latest BSODs reports.
    Any clue?
     
  12. 2014/03/20
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    Is it because I didn't let it finish dumping when it happened?
     
  13. 2014/03/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very possible.
    We'll have to wait until 3-4 more BSOD happen.
     
  14. 2014/03/20
    IndustrialOne

    IndustrialOne Inactive Thread Starter

    Joined:
    2014/02/23
    Messages:
    45
    Likes Received:
    0
    It's a useful tool though, I didn't even know PeerGuardian is the reason I got so many **** crashes back in 2008, thank god I don't use that gayass program anymore.

    Thanks for all the help in removing those 2 parasites I didn't even know I had. One of them I think is caused by the adware installed by Youtube downloader. It ***** I have to uninstall it because it's a useful program.

    Right now my system appears to be running smoothly and no bluescreens happened since.
     
  15. 2014/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    In that case...

    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.