Question

BSOD on boot to safe mode ONLY

Asked by: dgoldfluss

I have a laptop that is infected with some virus or malware.   The syptoms are an auto redirect from any broswer when clicking on a search engine link (at first i thought it was just bing and firefox, but it is in IE and google as well).  Some links work, some will just redirect to another page.  SPybot S&D fond nothing  malwarbytes found hijack.shell and disable.securitycenter in quarantine.  VIPRE AV found fraudtool,win32.roguesecurity.  I have gone through the hijack this and removed any suspect entries...

Now i wanted to boot to safe mode to help disinfect the machine.  When i try to start into safe mode (all options) i get a BSOD with  PAGE_FAULT_IN_NONPAGE_AREA.  Regular boot works fine every time.  Upon research I get two problems associated with this BSOD, one would be bad memory, the other is driver issue.  The first i cannot see a problem, the second i do not get since i am booting in safe mode is a driver not loading??
'
HELP!!

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-10-23 at 14:26:05ID24839525
Tags

windows xp; virus; malware

Topics

Windows XP Operating System

,

Anti-Virus

,

Anti-Spyware

,

Miscellaneous Hardware

Participating Experts
9
Points
500
Comments
33

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Hijack this and spybot
    Hi, Recently had a trojan virus on my system, im running windows xp. My virus scan detected it and deleted it but it keeps coming back. Ive run Hijack this, deleted the lines connected to the virus, and they keep coming back. Ran Spybot and the same happens i just cant shift ...
  2. MALWARE
    HI ALL I HAVE A MALWARE PROBLEM OR SOMETHIG LIKE THAT I HAVE A RESIDENT UCLEANER PROBLEM THAT ASK ME TO BUY EVERY TIME ASLO A ERROR SAFE I CANT DEAL WITH IT , I USE A LOT OF ANTI SPAM, ANTI VIRUS, ETC BUT NOTHING MY SOLUTION WAS DELETE DE DOCUMENT AND SETTINGS USERS AND STA...
  3. Malware Hijacking Browser
    Recently, my browser is being hijacked by some malware inadvertently placed on my computer. I have tried Ad-Aware, Vundo and ComboFix. Vundo does not find anything, Ad-Aware finds things, but when trying to remove the Tracking Cookies it finds, they reappear in the window and...
  4. Hijack of Firefox search
    When I do a search on Firefox I am redirected to random websites. I ran the Hijackthis analysis, pasted the url into the little box and got myself here...how do I get rid of the nasty that has hijacked my firefox search ability?
  5. New tpye of browser / DNS hijack infection?
    I seem to have found a new / yet-undocumented type of browser/OS hijacking. This particular method aims to redirect all my searches (yahoo, msn, google, etc) to a page full of advertisements (see attachement). It started with my searches being hijacked in Internet Explorer. ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: houssam_balloutPosted on 2009-10-23 at 14:30:12ID: 25648862

Try to remove all additional hardware , remove one RAM slot ,
& try to login via safe mode.

 

by: TheNauticanPosted on 2009-10-23 at 14:32:49ID: 25648878

check your event viewer to see what's causing the fault. Also, some spyware/adware hides pretty well these days. I suggest making a UBCD4Win CD (http://www.ubcd4win.com/) with the spybot and Malwarebytes plugins and anti virus plugins as well and scan with that.

 

by: dgoldflussPosted on 2009-10-23 at 14:35:31ID: 25648896

thanks i will start by undocking the laptop and anything else connected.  I did try UBCD with VIPRE.  I think i need an updated UBCD so I will download and setup again....

 I tried using combo fix as well.....  

Thanks I will let you knwo the results

 

by: optomaPosted on 2009-10-23 at 14:45:10ID: 25648992

-If issues still exist after above experts suggestions try scanning that system with this live cd:
Kaspersky live cd http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/

--It is in iso/image format so you will have to burn it to a cd.
--Once the cd is created, boot the infected machine to that cd and scan your system
NB-Update the virus database in live cd before scanning.



Also, do you have your installation media?
If so you may have to do a repair installation afterwards, depending on what infected files are removed:
http://michaelstevenstech.com/XPrepairinstall.htm

 

by: dnilsonPosted on 2009-10-23 at 14:57:19ID: 25649091

1) Download COMBOFIX from www.bleepingcomputer.com using a known good system.  burn onto a CD and then execute  ( http://www.bleepingcomputer.com/combofix/how-to-use-combofix)

DO NOT DOWNLOAD FROM COMBOFIX.ORG ...it may come up first in google, but its a bogus site.

2) Let combofix do its thing.   see second link above for tutorial.

Depending on what was done earlier  the BSOD may be afunction of hte malware, or the rough removal of malware from another tool.   hard to tell.

3 )Put the system back in functional shape with Dial-A-Fix  http://wiki.lunarsoft.net/wiki/Dial-a-fix

4) Get out the install dik and run sfc /scannow (with a known good instal lCD i nthe drive)

5) reboot and rerun MS-Updates

It may be wise to reverse the order of 3 & 4 depending o nthe isuse.

 

by: dgoldflussPosted on 2009-10-23 at 15:50:48ID: 25649441

Undock did not work.  There was only one ram module which i swapped from another machine.  Nothing.

Kaspersky disk did not start the scan with a corrupt database.  Trying to get a UBCD together, but have 10 minutes before i leave for the weekend!

 

by: optomaPosted on 2009-10-23 at 16:53:54ID: 25649909

After the weekend try the scan again. The updates being pulled down maybe ok then :)

 

by: rpggamergirlPosted on 2009-10-24 at 05:38:13ID: 25651899

Can you please attach or paste here the MalwareBytes and the Combofix logs?
The logs might help us point to the culprit.

 

by: dgoldflussPosted on 2009-10-24 at 12:45:36ID: 25653926

here is combofix and hijackthis logs. i guess i did not save a log file for malwarebytes i cannot find it....

 

by: rpggamergirlPosted on 2009-10-24 at 15:38:15ID: 25654711

Is the search still being redirected?
Thanks for the logs, I couldn't find any suspicious entry in the CF log that would help point to the culprit, like you said it could also be a driver that isn't loading.
I thought it could be a patched system file but no indication in the CF log.



Try running these scanners and let's see the their logs show.

1.  Download the GMER Rootkit Scanner. Unzip it to your Desktop.
http://www.gmer.net/gmer.zip

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.



2.  Download RootRepeal from either one of the links below and save it to your desktop.
http://ad13.geekstogo.com/RootRepeal.zip
http://ad13.geekstogo.com/RootRepeal.rar


Extract RootRepeal.exe from the archive.
Open RootRepeal on your desktop.
Click the "Report" tab.
Click the "Scan" button.
Check all seven boxes:

o Drivers
o Files
o Processes
o SSDT
o Stealth Objects
o Hidden Services
o Shadow SSDT

Push Yes
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the "Save Report" button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

 

by: dgoldflussPosted on 2009-10-28 at 07:54:18ID: 25683910

ok so i created a new UBCD for myself, good thing since mine was too old.  I ran most every scanner that would work and function.   Including spybot s&d, avast, vipre, gmer.  

Spybot found a microsoft.windows.security registry change.  Avast nothing Vipre nothing.  I think gmer found nothing, but will attach log.  I did make sure all scanners were up to date.

I also created a kasparsky rescue disk and got it to update (a pain in the arse).   It found nothing.

I also ran root repeal...

then ran combo fix from windows.   i could not get combofix to run out of the UBCD environment

i will attach all log files...

i am hitting my head because after about 10 minutes, the first entry for wikipedia in a search brought me back to the crap.  Seems when it is run once, it tends to infect more pages.....

 

by: rpggamergirlPosted on 2009-10-30 at 05:34:04ID: 25702277

Thanks for the logs... I still don't know wha caused the BSOD in safe mode....
Could be one of your software causing this when unable to load their drivers, since you have so many services there.

Or could be one of the recent nasties that eludes the scanners we used.
Try scanning with OTL(the first scan will just enumerates what's runnning similar to a diagnostic tool.

Download OTL to your Desktop
http://oldtimer.geekstogo.com/OTL.exe

Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
Under the Custom Scan box paste this in (bolded text below)

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5


Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL, please attach the logs.

 

by: dgoldflussPosted on 2009-10-30 at 14:12:19ID: 25706833

here are the log files from OTL....

 

by: rpggamergirlPosted on 2009-10-31 at 02:18:17ID: 25708971

I don't see any suspicious\malicious entries in the logs....
I'll call for help in case this is a hardware or software issue, Experts in those areas might be able to find the solution.

 

by: optomaPosted on 2009-10-31 at 02:38:09ID: 25709017

Could you upload the three latest minidump files located at
C:\Windows\Minidump
Rename them from .dmp to .txt to upload

 

by: gecko_au2003Posted on 2009-10-31 at 06:37:23ID: 25709700

use a bart pe disc or a linux live disc of some description and backup any data you want to keep , do a full format ( which will also check for bad sectors etc on the hdd ) then do a fresh install along with latest drivers and re install any software.

Then try again ref safe mode etc

Also before you run any scans if you want to go down that route, disable system restore , delete restore points and then do the scans but again I would backup data first

 

by: willcompPosted on 2009-10-31 at 08:04:24ID: 25710016

Re: BSOD in safe mode. I agree with optoma that minidumps -- if created -- should help pinpoint the cause.

You seem to have a driver issue which is a reversal from the norm. Intrinsic (built-in) drivers are used in safe mode (e.g. Standard VGA driver in lieu of video card manufacturer's driver) and one of those intrinsic drivers may be corrupt. To see if it is the VGA driver, try booting into VGA Only Mode instead of Safe Mode.

 

by: Netman66Posted on 2009-10-31 at 08:40:12ID: 25710165

When you're in safe mode, check the HOSTS file - it should only contain one entry for localhost unless you are specifically using a HOST file for added protection.

You'll find the HOSTS file in C:\Windows\System32\drivers\etc.  Open it in Notepad, but make sure you uncheck the box for Always use this program...

As for your BSOD, you might want to download this and somehow get it installed and running to get some logs for us.

 

by: dgoldflussPosted on 2009-11-02 at 09:26:03ID: 25721400

I am not finding a mindump created!!!

THe host file was switched, probably by one of these scanning programs to just 127.0.0.1

I switched back to my original hosts which includes entries from spybot s & d to route bad sites to loopback.

I tried booting in VGA mode, worked fine.

I am going on vacation, so i do not have the time to do a full format and reinstallation, something i wsa avoiding in the first place.   My main issue is not the safe mode boot, but the redirection of search engine results, just scares me.  I have started using google chrome which seems to have not been affected.  

 

by: slashbluePosted on 2009-11-09 at 22:53:10ID: 25782955

One of the scans likely resolved the malware issue, but the safe mode issue still needs to be resolved.  Try this (it applies to XP SP3 too):
http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/

 

by: slashbluePosted on 2009-11-09 at 23:08:12ID: 25783012

Sorry, one follow-up to my previous post: I ran into these same issues on several pc's, and the link I posted fixes the safe mode problem, but to fix the link redirection:
I attached the drive to another computer and ran a full battery of scans against it (you might be able to use BartPE or some other LiveCD alternatively).
Specifically, http://www.freedrweb.com/cureit/ ended up finding that the atapi.sys driver was corrupted. I ran other av programs too, malwarebytes is a good idea, perhaps http://www.trendmicro.com/download/dcs.asp (with pattern files: http://www.trendmicro.com/download/pattern.asp) too.

Once that's done, put the drive back in, boot the machine up, and Run combofix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix), which removed a few more things and on one machine actually fixed the safe mode issue at the same time!

Once safe mode is working (either from these steps or the .reg merge), I'd suggest running some of these tools again, just to be sure.

 

by: dgoldflussPosted on 2009-11-18 at 12:37:54ID: 25854492

Well here we go....

Took the drive out and did a malwarebytes scan on it from another pc.  Found one issue with backdoor.brediva in \WINDOWS\system32\cpcp.cpo.  After cleaning the file, computer goes to BSOD no matter what....  

 

by: slashbluePosted on 2009-11-18 at 13:38:44ID: 25855170

A search online shows this is a virus file, so hopefully the file was removed, not just cleaned.  I'd put that hard drive on another system again, then mount the registry hives and search for references to that file to see if you can track the offending entry down, post what you find.  More than likely there's references to it that prevent the system from booting.

The blue screen error may shed light on the issue as well if you can post it.

 

by: Netman66Posted on 2009-11-18 at 13:51:15ID: 25855283

Agreed.  Load the Hives from that drive into the host's registry before you run MBAM again.

You'll have to load SYSTEM then scan, then unload it and load SOFTWARE then scan it again in order to get all the keys from the infected PC - other than the USERS key, which shouldn't matter much if the files and critical registry entries are removed.

Once it's bootable again then you can rerun MBAM on the real system when it's live.

 

by: dgoldflussPosted on 2009-11-18 at 13:56:48ID: 25855341

I did a repair using the XP install disk and have the machine up and running.   I have yet to check if the bug is still there.  I did delete the file when i did the malwarebytes scan.  

I will see if the redirect still occurs.   FYI when i started the MBAM scan from my Win7 machine with the laptop harddrive connected externally i got blue screened immediately......

 

by: slashbluePosted on 2009-11-18 at 13:57:06ID: 25855344

@Netman66: will MBAM actually scan hives that are just mounted and not on the local system?  That'd be pretty sweet, I wouldn't think it would detect them since they are not in use by the active system.

 

by: dgoldflussPosted on 2009-11-18 at 14:03:02ID: 25855400

On my initial testing, looks like my offending redirects are gone....

AND SAFE MODE WORKS!!!!

 

by: slashbluePosted on 2009-11-18 at 14:17:32ID: 25855532

That's great, congrats!

 

by: dgoldflussPosted on 2009-11-18 at 14:20:39ID: 25855559

I know!!!!  Should have done that awhile back, although using Google Chrome as a browser helped me avoid the problem while on vacation.

I'd like to thank the academy.....

 

by: dgoldflussPosted on 2009-11-18 at 14:24:32ID: 31645283

finally solved my problem, all the help was appreciated

 

by: Netman66Posted on 2009-11-18 at 14:59:46ID: 25855935

@slashblue:  If the Hives are mounted, they should get scanned with the "live" registry.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...