New
#31
I would suggest you to run memtest86+ for one more time.
BTW, what is a Malwarebyte memory?
Good morning to all, and we have little for the weekend and relax.
Excuse my college English ARC.
I did not know how to express and rush writing ...
When I go to the notification area and the Malwarebyte program icon, I right click and select end program, then the PC is I totally hung, frozen, stopped.
Yesterday I put the new memory that Kingston sent me. It is a memory that made for this computer, and yesterday I worked all day perfect.
Now when windows starts, it opens and closes very fast msdos window, that was not previously. Not if it's the Malwarebyte. Since not previously used it.
I disabled in BIOS bluetooth, card reader and the little port for hard disks, is a small plug.
I also disabled the usb external power when the PC is off, since not usually use. I think only once, refresh the mobile phone in an emergency but I have not use this function.
The external esata I've been on.
No meeting so that they can disable the infrared.
testing is critical, when usually leave the pantallado, there are two moments that usually does:
- In the morning when I turn on the computer. Today has not happened.
- When I go to a client, turn on my computer the first time. Blue Screen and my poker face.
symptoms that I found on the computer that did not happen.
A. - USB port
One of the USB ports. Sometimes dell analysis tells me that does not pass the check.
In this port is connected a keyboard of old, 15 years I've been using it.
There are times when I am working and momentarily look like I'm out mouse and keyboard sounds that sound something usb is unplugged and re-plugged while.
At the end of last year, remove the keyboard to clean it well, and returned to ride all its parts.
plug and keyboard not working. Use another, and a week later, plug the keyboard that had cleared and worked ...
I know it's weird. not if some bad contact inside the keyboard, humidity.
Do you really this ubiera been enough to vary the voltage and damage the USB port?
Now the keyboard is enchufadoy since I use the automatic detector intel drivers, so good.
Not if there is a specific program to check the USB ports.
B - Audio
The other symptom that I notice the laptop is the Audio.
With the dell quickset comes, is very comfortable, I hit the keyboard and see a large volume bar on the screen. I called Dell Quickset, in other notebooks not his name, but they take all.
Just before the problems began screenshots, leave the volume bar appear on the screen.
The VLC started to take a long time to load the videos.
By clicking on the video and took about 4 seconds.
When listening to music, no matter from what source, he cut a few milliseconds STAYING sound as fitted.
I have the feeling that when hung in the morning it does in the windows welcome sound because I do not listen, then blue screen.
And when the computer boots up, and before I open client with chrome and put some sound to see crashes.
Viewing AppCrashView logs, I see that just when to stay frozen PC. There are times it has been frozen without showing the blue screen.
The application program tells me, several strange things:
About the USB:
AppName = Driver software installation
AppPath = C: \ Windows \ System32 \ rundll32.exe
REPORTDESCRIPTION = Windows installed driver software that supports the basic features of the USB input device. Its manufacturer may provide software that enables additional features.
About the Audio:
FriendlyEventName = Could not install driver software.
ConsentKey = PnPDriverImportError
AppName = Driver software installation
AppPath = C: \ Windows \ Temp \ AlcUpd64.exe
REPORTDESCRIPTION = Windows could not copy all the files needed to install the software for this device driver. This sometimes occurs when the driver software was not designed for this version of Windows.
In this execution path seems very strange. TEMP???
And finally this do not understand, or is not, I copied it and pasted, but before that tengais wish you an excellent day and thank you for being there....
attentively
Freddy
Code:Version = 1 EventType = CLR20r3 EventTime = 130155882526486011 ReportType = 2 Consent = 1 UploadTime = 130155882532570021 ReportIdentifier = 2515577b-D409-11e2-9DAF-b8ac6f6f2d41 WOW64 = 1 Response.BucketId = 3556451825 Response.BucketTable = 5 Response.type = 4 Sig [0]. Name = Problem Signature 01 Sig [0]. Value = msi5324.tmp Sig. [1] Name = Problem Signature 02 Sig [1]. Value = 1.0.0.0 Sig [2]. Name = Problem Signature 03 Sig [2]. Value = 513eda28 Sig. [3] Name = Problem Signature 04 Sig [3]. Value = mscorlib Sig [4]. Name = Problem Signature 05 Sig [4]. Value = 2.0.0.0 Sig [5]. Name = Problem Signature 06 Sig [5]. Value = 503f01b1 Sig [6]. Name = Problem Signature 07 Sig [6]. Value = 3452 Sig [7]. Name = Problem Signature 08 Sig [7]. Value = 119 Sig [8]. Name = Problem Signature 09 Sig [8]. Value = System.IO.DirectoryNotFound DynamicSig [1]. Name = operating system version DynamicSig [1]. Value = 6.1.7601.2.1.0.768.3 DynamicSig [2]. Name = ID Locale DynamicSig [2]. Value = 3082 UI [2] = C: \ Windows \ Installer \ MSI5324.tmp UI [3] = CleanQtrax stopped working UI [4] = Windows can check online for a solution to the problem. UI [5] = Check online for a solution and close the program UI [6] = Check online for a solution later and close the program UI [7] = Close the program LoadedModule [0] = C: \ Windows \ Installer \ MSI5324.tmp LoadedModule [1] = C: \ Windows \ SysWOW64 \ ntdll.dll LoadedModule [2] = C: \ Windows \ system32 \ MSCOREE.DLL LoadedModule [3] = C: \ Windows \ syswow64 \ KERNEL32.dll LoadedModule [4] = C: \ Windows \ syswow64 \ KERNELBASE.dll LoadedModule [5] = C: \ Windows \ syswow64 \ ADVAPI32.dll LoadedModule [6] = C: \ Windows \ syswow64 \ msvcrt.dll LoadedModule [7] = C: \ Windows \ SysWOW64 \ sechost.dll LoadedModule [8] = C: \ Windows \ syswow64 \ rpcrt4.dll LoadedModule [9] = C: \ Windows \ syswow64 \ SspiCli.dll LoadedModule [10] = C: \ Windows \ syswow64 \ CRYPTBASE.dll LoadedModule [11] = C: \ Windows \ Microsoft.NET \ Framework \ v4.0.30319 \ mscoreei.dll LoadedModule [12] = C: \ Windows \ syswow64 \ SHLWAPI.dll LoadedModule [13] = C: \ Windows \ syswow64 \ GDI32.dll LoadedModule [14] = C: \ Windows \ syswow64 \ USER32.dll LoadedModule [15] = C: \ Windows \ syswow64 \ lpk.dll LoadedModule [16] = C: \ Windows \ syswow64 \ usp10.dll LoadedModule [17] = C: \ Windows \ system32 \ IMM32.DLL LoadedModule [18] = C: \ Windows \ syswow64 \ MSCTF.dll LoadedModule [19] = C: \ Windows \ Microsoft.NET \ Framework \ v2.0.50727 \ mscorwks.dll LoadedModule [21] = C: \ Windows \ syswow64 \ shell32.dll LoadedModule [22] = C: \ Windows \ syswow64 \ ole32.dll LoadedModule [23] = C: \ Windows \ system32 \ profapi.dll LoadedModule [25] = C: \ Windows \ Microsoft.NET \ Framework \ v2.0.50727 \ mscorjit.dll LoadedModule [27] = C: \ Windows \ system32 \ Version.dll LoadedModule [28] = C: \ Windows \ system32 \ apphelp.dll State [0]. Key = Transport.DoneStage1 State [0]. Value = 1 FriendlyEventName = stopped working ConsentKey = CLR20r3 AppName = CleanQtrax AppPath = C: \ Windows \ Installer \ MSI5324.tmp REPORTDESCRIPTION = Stopped working
Last edited by Brink; 04 Jul 2013 at 13:42. Reason: code box
I have requested Saurabh A too have a look at your issue. He will be able to guide you in the proper way.
Good afternoon, no news.
Blue Screen now.
bluescrrenview not indicate the error.
But I've seen with my eyes, and reporting dell caught it.
I attached an image with the screen capture.
Refers to iastor.sys
I've looked at the forum this is and I've found
BSOD iaStor.sys error
Following the instructions I have spent the TDSKILLER in safe mode and found things actually ...
I attached a picture.
Of the things that curiously found the computer has been locked with those services. Indicates some Epson printer, and one day actually printing the screen went blue. Wamp also indicates something of Apache and effectively using the Wamp Server one day the computer was left with a nice roasted blue screen.
Not to do with what you have found, I guess that I have to say delete.
I attached the log of your magnificent utility.
Having good evening
infinite thanks
attentively
Freddy
Get rid of intel rapid storage. First uninstall it from Control Panel > Programs and Features. Then Uninstall the driver from device manager.
- Right click on "my computer" icon and click "manage" on the context menu.
- It will open the "computer management" window.
- Select "Device Manager" in the left pane, It will list all the existing devices up.
- Expand "IDE ATA/ATAPI controllers" by clicking on the triangle in front of it.
- Select one Intel device item under it, right click, uninstall.
- Continue the process for all Intel items under "IDE ATA/ATAPI controllers"
- Now restart the computer. At restart, windows will auto configure the appropriate native system driver.
Run TDSSKiller again ... delete all the files those are caught. Then run Windows Defender Offline to make it sure that the system is not infected anymore or not.
Also uninstall CleanQtrax software, it is a malware/trojan which can d/l more such things.
Try the online ESET online scanner to remove it
Free Virus Scan | Online Virus Scanner from ESET
After running ESET check this guide for the files mentioned and delete them if found. http://forums.spybot.info/showthread.php?68496-Manual-Removal-Guide-for-Qtrax
Good morning.
The online eset has not detected anything.
The online windows defender booted from cd not detect anything.
And today tdskiller gone mad, because it detects almost 300 things ... I leave the log.
I'm keeping some things and restablezo from a backup image of more than a year ago.
Then cometh the tdskiller him again.
not find it anywhere on
CleanQtrax software
But if I have ever seen sounds, can not remember, but it sounds
What are the chances that this has infected my backups I do on the NAS?
Thanks for the help, have a good day
Atenamente
Freddy
Senor FreddyKrueger,
Como le va?
Took a look at the TDSSKiller report, and there are quite a few unsigned files present. However, selected 25 files (one or more for every letter of the alphabet) and checked its MD5 (value used to verify file). All the MD5s verified at VirusTotal (a website that checks files for viruses), came up without infection.
Not sure that the problem here is malware related. This issue may happen if Windows Update components get corrupted and do not update software or hardware drivers properly.
However, to be safe, rather than sorry, please do the following:
Download the Farbar Recovery Scan Tool
Select the 64-bit version.
Save it to the Desktop.
Please provide the FRST.txt in your reply. <<---
- Double-click the downloaded file to run it.
- When the tool opens click Yes to disclaimer.
- Press the Scan button.
- FRST64 makes a log (FRST.txt) in the same directory from which the tool is run (Desktop).
The first time the tool is run, it also makes another log: Addition.txt
Also post the Addition.txt in your reply. <<---
Also, download Farbar Service Scanner
Save to the Desktop
Please provide the FSS.txt in your reply. <<---
- Make sure the following options are checked:
- Internet Services
- Windows Firewall
- System Restore
- Security Center
- Windows Update
- Windows Defender
- Press: Scan
- FSS creates a log, FSS.txt, on the Desktop.
To check the system for malware, please post the results requested for the programs above in the System Security forum:
System Security - Windows 7 Help Forums
Title the topic: Possible Malware (attn: cottonball)
Also, provide a link to this thread (without the > < angle brackets):
>https://www.sevenforums.com/bsod-help-support/292013-ntoskrnl-exe-irql-not-less-equal-page_fault_in_nonpaged_area.html<
Thanks!
Good morning everyone :)
I'm alive.
My PC is alive, working perfectly, no blue screen :)
I waited a week to watch but that's it.
:)
Britton30, thanks for the TDSSKiller.
It was the solution.
the first day I indicated that there were some things I remember 7 objects.
The next day was more than 300.
Retrieve a backup in a while, as I always do.
And there we had the problem.
These 7 individuals already in the system image.
It was remove the infected items, back to my original settings my usual programs, and behaves perfect PC.
Now when everything is okay is when you remember that you forgot that it is normal that late more than 40 seconds to boot.
It all goes very fast.
Aftter perfect re-renders effects.
The system is not heated, up from oven.
I have no words of thanks to all of you.
PC Lifetime, and never thought a malware could affect both the system.
It was suspected that the blue screen did not tell us was that driver.
It was suspected that forcing drivers test out the blue screen no.
was suspected to have changed memory and hard disk completely new elements.
Now everything perfect.
The audio is fine and does not break.
No blue screens.
The system boots in just 40 seconds.
Everything goes smoothly.
infinite thanks
I have no words
attentively
F.