You are not connected. Please login or register

Goto page : Previous  1, 2

View previous topic View next topic Go down  Message [Page 2 of 2]

16 Re: "antiriceonline" virus ? on Wed Jan 20, 2010 8:31 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
I tried to scan again. I got BSOD again. BTW, is there another way to get off of the BSOD other than by using the power button on the computer?

View user profile

17 Re: "antiriceonline" virus ? on Thu Jan 21, 2010 5:38 pm

Yeah. Control-Alt-Delete.

On boot-up, quickly press F8, and you will get a boot menu. Use the arrow key and go down to "Disable automatic restart..."

Then, run the scan again, so it can reproduce the BSOD. Then, please post the details of it.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

18 Re: "antiriceonline" virus ? on Thu Jan 21, 2010 6:49 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
Crash dump directory: C:\WINDOWS\Minidump

Crash dumps are enabled on your computer.


On Thu 1/21/2010 1:02:39 AM your computer crashed
This was likely caused by the following module: iastor.sys
Bugcheck code: 0x1000007E (0xC0000005, 0xF778B9CC, 0xF7D13C4C, 0xF7D13948)
Error: SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M
Dump file: C:\WINDOWS\Minidump\Mini012010-01.dmp
file path: C:\WINDOWS\system32\drivers\iastor.sys
product: Intel Application Accelerator driver
company: Intel Corporation
description: Intel Application Accelerator driver



On Tue 1/19/2010 1:42:08 AM your computer crashed
This was likely caused by the following module: ntoskrnl.exe
Bugcheck code: 0x8086 (0x0, 0x0, 0x0, 0x0)
Error: Unknown
Dump file: C:\WINDOWS\Minidump\Mini011810-02.dmp
file path: C:\WINDOWS\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit may be another driver on your system which cannot be identified at this time.



On Mon 1/18/2010 11:29:26 PM your computer crashed
This was likely caused by the following module: ntoskrnl.exe
Bugcheck code: 0x8086 (0x0, 0x0, 0x0, 0x0)
Error: Unknown
Dump file: C:\WINDOWS\Minidump\Mini011810-01.dmp
file path: C:\WINDOWS\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit may be another driver on your system which cannot be identified at this time.

View user profile

19 Re: "antiriceonline" virus ? on Thu Jan 21, 2010 6:51 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
The crash on the 19th and 21st happened when I tried to scan with MBAM. I'm going to restart now and follow your instructions.

BTW, I tried cont/alt/delete several times and still could not get out of the blue screen. It didn't respond to any of that in any way.

View user profile

20 Re: "antiriceonline" virus ? on Thu Jan 21, 2010 7:05 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
Ok, what have I done to this computer? When I just closed out Outlook Express, I got an error message/signature. It also included reporting details. AppName: msimn.exe AppVer: 6.0.2900.5512
ModName: mlfoe.dll
ModVer: 6.0.0.2383
Offset: 0000cf42

It also included "Error Report Contents", which was a "regular" looking window with A LOT of info in it. I could not copy and paste it. I still have it up........in case there is another way to capture the info in this window. I've never seen this error before. It contained this file on the error: C:\DOCUME~1\TRICIA~1\LOCALS~1\Temp\805d_appcompat.txt

View user profile

21 Re: "antiriceonline" virus ? on Fri Jan 22, 2010 4:10 pm

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    msimn.exe


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

22 Re: "antiriceonline" virus ? on Sat Jan 23, 2010 1:48 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 13:41 on 23/01/2010 by Tricia & Roger (Administrator - Elevation successful)

========== filefind ==========

Searching for "msimn.exe"
C:\I386\MSIMN.EXE --a--- 60416 bytes [00:04 04/12/2004] [11:00 04/08/2004] 091C14F4C71328D4316248A2421190DE
C:\Program Files\Outlook Express\msimn.exe --a--- 60416 bytes [11:00 04/08/2004] [00:12 14/04/2008] 1EEAE496A51F017D04DD41322935D2B9
C:\WINDOWS\$NtServicePackUninstall$\msimn.exe -----c 60416 bytes [16:00 08/10/2008] [11:00 04/08/2004] 091C14F4C71328D4316248A2421190DE
C:\WINDOWS\ServicePackFiles\i386\msimn.exe ------ 60416 bytes [23:43 18/08/2008] [00:12 14/04/2008] 1EEAE496A51F017D04DD41322935D2B9

-=End Of File=-

View user profile

23 Re: "antiriceonline" virus ? on Sat Jan 23, 2010 1:50 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
I don't think I could ever get MBAM to work, but I'm going to try again.

***Ok, tried to scan again, and it gave the BSOD.*** Sorry. Sad It just gave me the message about downloading the RAID driver.

I feel bad that this is taking time....I'm beginning to think I've got multiple problems (that I've caused, of course) on this computer. Rolling Eyes

View user profile

24 Re: "antiriceonline" virus ? on Sat Jan 23, 2010 9:44 pm

Please go HERE. Copy and paste the following file path in to the box.

C:\I386\MSIMN.EXE

Then click submit.

Please post the results (URL) to your next reply.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

25 Re: "antiriceonline" virus ? on Sat Jan 23, 2010 10:23 pm

TriciaM


Forum Enthusiast
Forum Enthusiast
It would not allow me to paste into the box, so I had to just locate it by the browse button....This is the result of the new scan I did on it. The first result it gave me was a result that showed that one of the programs found it suspicious (when I had it scan C:\Program Files\Outlook Express\msimn.exe. )

File MSIMN.EXE received on 2010.01.24 03:18:18 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.24 -
AhnLab-V3 5.0.0.2 2010.01.23 -
AntiVir 7.9.1.146 2010.01.22 -
Antiy-AVL 2.0.3.7 2010.01.22 -
Authentium 5.2.0.5 2010.01.23 -
Avast 4.8.1351.0 2010.01.23 -
AVG 9.0.0.730 2010.01.23 -
BitDefender 7.2 2010.01.24 -
CAT-QuickHeal 10.00 2010.01.22 -
ClamAV 0.94.1 2010.01.22 -
Comodo 3687 2010.01.24 -
DrWeb 5.0.1.12222 2010.01.24 -
eSafe 7.0.17.0 2010.01.21 -
eTrust-Vet 35.2.7255 2010.01.22 -
F-Prot 4.5.1.85 2010.01.23 -
F-Secure 9.0.15370.0 2010.01.23 -
Fortinet 4.0.14.0 2010.01.23 -
GData 19 2010.01.24 -
Ikarus T3.1.1.80.0 2010.01.24 -
Jiangmin 13.0.900 2010.01.23 -
K7AntiVirus 7.10.952 2010.01.22 -
Kaspersky 7.0.0.125 2010.01.24 -
McAfee 5870 2010.01.23 -
McAfee+Artemis 5870 2010.01.23 -
McAfee-GW-Edition 6.8.5 2010.01.24 -
Microsoft 1.5405 2010.01.24 -
NOD32 4800 2010.01.23 -
Norman 6.04.03 2010.01.23 -
nProtect 2009.1.8.0 2010.01.23 -
Panda 10.0.2.2 2010.01.23 -
PCTools 7.0.3.5 2010.01.24 -
Prevx 3.0 2010.01.24 -
Rising 22.31.06.01 2010.01.24 -
Sophos 4.50.0 2010.01.24 -
Sunbelt 3.2.1858.2 2010.01.23 -
Symantec 20091.2.0.41 2010.01.24 -
TheHacker 6.5.0.9.160 2010.01.24 -
TrendMicro 9.120.0.1004 2010.01.23 -
VBA32 3.12.12.1 2010.01.23 -
ViRobot 2010.1.23.2152 2010.01.23 -
VirusBuster 5.0.21.0 2010.01.23 -
Additional information
File size: 60416 bytes
MD5...: 091c14f4c71328d4316248a2421190de
SHA1..: 2f3645e24caee5898d086890752400d7c8862505
SHA256: 3f7409a5f661c5a17068757d03a3b90f5c2688ae5391aed83fa1eb98a9ec28dc
ssdeep: 768:8nZvk2JRV6P6RZcSp9RlTddT1T6MMMMM2MMMMMZ1d:4ZJnV6Cc49R/dT12MM
MMM2MMMMMZ1d

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x26d1
timedatestamp.....: 0x41107b0e (Wed Aug 04 05:58:38 2004)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2080 0x2200 5.87 c8b8b38f9b3c5aef7d0eeddb9dd1b9b0
.data 0x4000 0xb8 0x200 0.21 10a3ce6bebaf2ba41f882aa8d96652b0
.rsrc 0x5000 0xc260 0xc400 5.53 95c5411580080c9ea6b7df157178a280

( 5 imports )
> msvcrt.dll: _vsnprintf
> ADVAPI32.dll: RegOpenKeyExA, RegCloseKey, RegQueryValueExA
> KERNEL32.dll: GetVersionExA, UnhandledExceptionFilter, CloseHandle, ReleaseMutex, GetFileAttributesA, GetLastError, FreeLibrary, GetProcAddress, LoadLibraryA, lstrlenW, WaitForSingleObject, CreateMutexA, ExitProcess, GetModuleHandleA, GetStartupInfoA, SetErrorMode, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, lstrcpynA, SetUnhandledExceptionFilter, lstrlenA, GetEnvironmentVariableA, GetModuleFileNameA
> USER32.dll: GetWindowThreadProcessId, SetForegroundWindow, SendMessageTimeoutA, LoadStringA, MessageBoxA
> SHLWAPI.dll: SHGetValueA, StrCmpIW, -, SHSetValueA, StrStrIA, PathRemoveFileSpecA, -

( 0 exports )

RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (80.9%)
Win32 Executable Generic (8.0%)
Win32 Dynamic Link Library (generic) (7.1%)
Generic Win/DOS Executable (1.8%)
DOS Executable Generic (1.8%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) 2004 Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: Outlook Express
original name: MSIMN.EXE
internal name: MSIMN
file version.: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned

View user profile

26 Re: "antiriceonline" virus ? on Sun Jan 24, 2010 10:38 pm

Ok. This computer is clean.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

View previous topic View next topic Back to top  Message [Page 2 of 2]

Goto page : Previous  1, 2

Permissions in this forum:
You cannot reply to topics in this forum