Can someone please take a look at my minidump files??

Status
Not open for further replies.
I'm having a very hard time debugging a friends laptop. Everytime I boot the laptop, after about 30 seconds i get a bsod. i have attached several minidump files that I saved. I noticed in one of the files that rtvscan.exe was named. I thought that there might be a problem with Norton AV, but I'm unable to uninstall it before the laptop hangs. I renamed the rtvscan.exe file in safe mode hoping that it wouldn't blue screen on me and I would be able to uninstall it, but I didn't have any luck. it blue screened anyway. If anyone has any suggestions I would really appreciate it. Thanks
 
You have an infection. See HERE for the same one (post #2), and the story continues HERE. Go HERE.

BugCheck 1000008E, {c0000005, 0, eef70cf0, 0}
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
ef5e6000 ef5f3800 wincom32 wincom32.sys Wed Mar 21 18:21:25 2007 (4600F915)
 
Safe Mode?

I read through the steps in the post that you recommend I follow, and I had one question before I start. This laptop reboots every single time that I boot it normally. It is alright to follow as many steps as possible in safe mode? That means that I wouldn't have any real time monitoring softare running (step 1), not sure if I could install the anitvirus and firewall in safe mode (step 2), I can't run the online scanner b/c no network connection in safe mode (step 3.....btw, if I load safe mode with networking i get the bsod).....etc.

any advice??
 
Hello and welcome to Techspot.

I have moved your post and it`s replies to their own thread. This will save any confusion.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

Also, let me know the results of the AVG Antirootkit scan.

Since you can`t boot into normal mode, follow the instructions from safe mode for now.

Regards Howard :wave: :wave:
 
Followed all the step I could

Hello,

I have followed all the steps that I could. Being that I couldn't boot except for in safe mode, I wasn't able to do everything.

Here is a list of the problems that I had:
Ad-aware wouldn't install in safe mode
Look2Me-Destroyer never came back after clicking on run as task
AVG Anti-RootKit wouldn't run in safe mode
I tried to let combo fix reboot back into normal mode (thinking it would work this time) but it bsod'ed before the log was fully created.....ran it again in safe mode, not sure if the log is accurate now

Attached are the HJT log, the AVG Anti Spyware Log, and the Combofix Log. Any help would be greatly appreciated.

By the way, I still can't boot expect for in safe mode
 
Your system is absolutely overrun with malware. Even if we attempted to clean it, I don`t think it`d ever run properly.

I strongly advise you to backup your important data, reformat and reinstall from scratch.

Regards Howard :)

This thread is for the use of cbusso only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Thanks for your help

Thank you very much for your quick reply. Just out of my own curiousity, can you please explain to me how you know that it's overrun?? That way, in the future, I can make the assessment for myself. Thanks again
 
Please see attached, part of your Combofix log. All the .exe files you can see are nasty.

Does that help to explain what I mean by overrun with malware?

Regards Howard :)

This thread is for the use of cbusso only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 

Attachments

  • New Text Document.txt
    14.4 KB · Views: 6
Status
Not open for further replies.
Back