OS Screen C: Drive Inconsistency, BSODs and FF issue

Zexx

Level 1
Thread author
Verified
Mar 23, 2014
47
Copy and Paste of the BSOD issue/report

So I saved the BSOD in a notepad file, and there's two major problems;

1) The latest crash it reports is in 2014,

and 2) The ONLY BSOD crash I have EVER had on this laptop (and this laptop is mine; no one else uses it) is the day before this forum was made. So uh.... wth?


_________________________________________________________________________Paste:

==================================================
Dump File : 100414-62915-01.dmp
Crash Time : 2014/10/03 22:38:49
Bug Check String : DRIVER_POWER_STATE_FAILURE
Bug Check Code : 0x0000009f
Parameter 1 : 00000000`00000003
Parameter 2 : fffffa80`0750e060
Parameter 3 : fffff800`03c073d8
Parameter 4 : fffffa80`0fe5f010
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+75bc0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7601.18741 (win7sp1_gdr.150202-1526)
Processor : x64
Crash Address : ntoskrnl.exe+75bc0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\100414-62915-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 7601
Dump File Size : 1,007,192
Dump File Time : 2014/10/04 10:26:58
==================================================

==================================================
Dump File : 081914-54647-01.dmp
Crash Time : 2014/08/19 21:07:49
Bug Check String : DRIVER_POWER_STATE_FAILURE
Bug Check Code : 0x0000009f
Parameter 1 : 00000000`00000003
Parameter 2 : fffffa80`0750e9b0
Parameter 3 : fffff800`03c0d748
Parameter 4 : fffffa80`0d887280
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+75bc0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7601.18741 (win7sp1_gdr.150202-1526)
Processor : x64
Crash Address : ntoskrnl.exe+75bc0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\081914-54647-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 7601
Dump File Size : 1,007,192
Dump File Time : 2014/08/19 22:06:54
==================================================

==================================================
Dump File : 071214-54303-01.dmp
Crash Time : 2014/07/12 2:30:49
Bug Check String : DRIVER_POWER_STATE_FAILURE
Bug Check Code : 0x0000009f
Parameter 1 : 00000000`00000003
Parameter 2 : fffffa80`07512060
Parameter 3 : fffff800`0440d748
Parameter 4 : fffffa80`072ef6a0
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+75bc0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7601.18741 (win7sp1_gdr.150202-1526)
Processor : x64
Crash Address : ntoskrnl.exe+75bc0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\071214-54303-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 7601
Dump File Size : 1,007,248
Dump File Time : 2014/07/12 7:52:41
==================================================

==================================================
Dump File : 122113-42167-01.dmp
Crash Time : 2013/12/20 22:44:37
Bug Check String : DRIVER_POWER_STATE_FAILURE
Bug Check Code : 0x0000009f
Parameter 1 : 00000000`00000003
Parameter 2 : fffffa80`071ac060
Parameter 3 : fffff800`04cd53d8
Parameter 4 : fffffa80`0b90f810
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+75bc0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7601.18741 (win7sp1_gdr.150202-1526)
Processor : x64
Crash Address : ntoskrnl.exe+75bc0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\122113-42167-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 7601
Dump File Size : 1,006,840
Dump File Time : 2013/12/21 10:33:09
==================================================







Copy and Paste of Adw Stuff:



Sorry for the super late reply-illness/work/university got in the way.

Can I just give two/three updates here and then move over?

First the Adw stuff (going through the Adw folder, there seems to be three reports from that day: C2, S3, and Quarantine. The one that popped up after restart was C2 I think):
________________________________________________________________________________________________________
# AdwCleaner v5.031 - Logfile created 30/01/2016 at 22:36:42
# Updated 25/01/2016 by Xplode
# Database : 2016-01-25.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : SMJ - SMJ-TOPSECRET
# Running from : C:\Users\SMJ\Downloads\adwcleaner_5.031.exe
# Option : Cleaning
# Support : Forum - ToolsLib

***** [ Services ] *****

[-] Service Deleted : vToolbarUpdater40.2.4

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[-] Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\AVG Security Toolbar
[-] Folder Deleted : C:\Users\SMJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc

***** [ Files ] *****

[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
[-] File Deleted : C:\Users\SMJ\AppData\Roaming\Mozilla\Firefox\Profiles\00o75v1o.default\Extensions\Avg@toolbar.xpi
[-] File Deleted : C:\Users\SMJ\AppData\Roaming\Mozilla\Firefox\Profiles\00o75v1o.default\searchplugins\avg-secure-search.xml

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : AVG-Secure-Search-Update_JUNE2013_TB_rmv
[-] Task Deleted : AVG-Secure-Search-Update_JUNE2013_TB_rmv

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainerV2
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]

***** [ Web browsers ] *****

[-] [C:\Users\SMJ\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bohapeiooecafommnlaiccilacgmkaoc

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [3643 bytes] ##########
_____________________________________________________________________________________________________________END





In addition to this, when it was done and the restart was going on, the C: drive inconsistency thing came up again (a black screen, not blue) and ran through whatever. It seemed to have gotten through- it didn't freeze this time around. But when I was watching it a bunch've questions came up in my head in regards to the places this thing was referencing.

-What is file q?
-WHat's $SDH?
-What's index $SIT of file q?
-what does it mean when inserting an index entry with ID 5052 into index $SII of file 9?

That's all I managed to write down as it was going fast. WTH is this stuff? @_@
After that was done, it came back up and the above report was open.




HOWEVER, a day or two later I had another BSOD! -.-'

And then yesterday I had a weird BSOD where I could customize stuff? It had serial information and I could change date... there were some other tabs that I could open but I didn't go there.

I don't know if I should post the serial stuff here or whether it would help.

And finally, yea, I'll move this to the other thread soon.




Please tell me if there is anything else from these reports that you are looking for and is not here.
 

Zexx

Level 1
Thread author
Verified
Mar 23, 2014
47
RIGHT! I FORGOT!


There is another EXTREMELY WEIRD issue which I have no idea as to how it happened, and this is messed....


So I open up Skype, and there's someone else's username on there (as in remembered).... who has never used this laptop. I should like to add once more that this laptop always stays with me. They are not someone who would touch this laptop.
 

Zexx

Level 1
Thread author
Verified
Mar 23, 2014
47
I just turned on the computer right now (9:10), and it said that Windows had recovered from an unexpected crash- but it was fine the last time I used it last night. So I'm guessing it did a ghost thing in the night again ;-;.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top