Bluescreen of death + can't boot into safe mode or reinstall windows??

Alright, I think I found something that might be a bit relevant.

Blue screen from volsnap.sys during boot-up

It discusses the errors caused (similar to what you mentioned) and their solution using the Virtual Environments like BartPE or even a live Knoppix CD.

All you need to do is copy a fresh volsnap.sys to a USD drive - then boot from a Knoppix live CD or something similar and reokace your existing file with the new one.

This should have you good to go!
 


> This should have you good to go!

It is likely not a system bug, because it happened on two different computers. Assuming they were part of a home network, then it is more likely to be a trojan rootkit travelling from one to the other. Either that or he may have installed the same torrented app on both machines recently.
 
try to take out the graphi card or ram

Yeah, that sounds like a great solution :rolleyes:

Hate to say this OP, cause it sucks to hear it, but I have to agree with Chianti... if you've been rooted then you're wasting your time doing anything but a complete reformat.

Also, if you have websites on a server somewhere and use an FTP program like Filezilla, you better check to make sure your server(s) hasn't been compromised. I had my box rooted about a year ago, and I know another WF user that had his hit about a month ago, and both of us had sites on our servers infected with the same script that infected us because we used regular FTP instead of SFTP and the login info was stolen out of Filezilla.
 
Ok.. the name of his file is a joke (to himself) volsnap.sys is he turns off ex: makes take a 'nap' the 'vols' a term used to describe the drive when it's mounted. So, he unmounts 'nap' the drive 'vols' and it's embedded as a sys(tem) file at boot. Renaming will cause sys to ignore (can't find) the file and should/may give you back enough controll. Another option would be to rename (I like to look at the code layer) volsnap and make new zero length file named volsnap.sys and change privilege to owner, or restrict read or Somesuch.
Plus the name is double entendre could be "vol" 'snap' but as in snap, jokes on you. I know this a-hole, seen his work. Usually OS part is so slow to load if you get to desktop you can roll system back to early date. If I do reinstall, i rename window's dir as backup. Do install just to get clean basic registry, export registry, rename new windows dir and name old windows dir back and import saved clean install registry to clean the EXTensions. Clean, run regs while at it and.. done in an hour or less everything intact and bad guy permanently locked out.

Droidx-Tapatalk

I'll have some of whatever you're having. Although a little less of it please, because you're clearly off your face. Or trolling.
 
Save yourself time and a headache.

Download a destop version of a Linux Distro (Ubuntu, Fedora, etc..). Boot up in to the installer, drop to the desktop. Mount the old file system and connect an external hard drive to the computer. Copy off anything you need. Reformat and reinstall.
 
  • Like
Reactions: Staccs
I get responses like this from Linux users all the time. (One of my best friends for example) My usual response would be something like... yes it's easy to avoid infection when the target audience is so small the blaggards think, "why bother ". or It's not the OS that saves them, it's the 'relatively small number of users and the ensuing anonymity that protects them. " or, when I want to return to DOS days and the inception of Windows (2.0?) I'll think about taking up Linux. Still, as a MS man, there's nothing like learning a new language and learning to socialize by poking pinholes in your eyelids to restrict the light and praying nothing sees you, or you them, to protecting yourself from attack. It works for the ostrich.

Droidx-Tapatalk

Ok.. the name of his file is a joke (to himself) volsnap.sys is he turns off ex: makes take a 'nap' the 'vols' a term used to describe the drive when it's mounted. So, he unmounts 'nap' the drive 'vols' and it's embedded as a sys(tem) file at boot. Renaming will cause sys to ignore (can't find) the file and should/may give you back enough controll. Another option would be to rename (I like to look at the code layer) volsnap and make new zero length file named volsnap.sys and change privilege to owner, or restrict read or Somesuch.
Plus the name is double entendre could be "vol" 'snap' but as in snap, jokes on you. I know this a-hole, seen his work. Usually OS part is so slow to load if you get to desktop you can roll system back to early date. If I do reinstall, i rename window's dir as backup. Do install just to get clean basic registry, export registry, rename new windows dir and name old windows dir back and import saved clean install registry to clean the EXTensions. Clean, run regs while at it and.. done in an hour or less everything intact and bad guy permanently locked out.

Droidx-Tapatalk

lmao this reminds me how we used to write in theory exam papers while in engineering college but damn you are really an expert at it. Its too hard to figure out the nonsense by just skimming, one will need to read it all to make sure it is nonsense.
 
Save yourself time and a headache.

Download a destop version of a Linux Distro (Ubuntu, Fedora, etc..). Boot up in to the installer, drop to the desktop. Mount the old file system and connect an external hard drive to the computer. Copy off anything you need. Reformat and reinstall.

Can't believe it took 20+ replies for this. tencentpiece, do this ^.
 
Save yourself time and a headache.

Download a destop version of a Linux Distro (Ubuntu, Fedora, etc..). Boot up in to the installer, drop to the desktop. Mount the old file system and connect an external hard drive to the computer. Copy off anything you need. Reformat and reinstall.

Agreed. When you eventually do your reformat (because you will have to) put the Distro on (dual boot, or whatever) so you can play around with it when you're bored. You might actually like it more than windows, at least for your non-business activities.
 
Yeah, that sounds like a great solution :rolleyes:

Hate to say this OP, cause it sucks to hear it, but I have to agree with Chianti... if you've been rooted then you're wasting your time doing anything but a complete reformat.

Also, if you have websites on a server somewhere and use an FTP program like Filezilla, you better check to make sure your server(s) hasn't been compromised. I had my box rooted about a year ago, and I know another WF user that had his hit about a month ago, and both of us had sites on our servers infected with the same script that infected us because we used regular FTP instead of SFTP and the login info was stolen out of Filezilla.

I know this sounds like a retarded question, but what's the best way to do a complete reformat? As I said, I really don't care about the files on either of those PC's because they are mostly for farming/scarping anyway. I just want them to be usable - I've tried reinstalling windows without luck. When you say "completely reformat" how can I go about that (assuming I am semi retarded).

I've already changed all of my passwords that were accessed on either of those PCs as well.

You're not running Vista are you? Before moving to Win 7 I had Vista and it would break a lot, usually after some kind of update was pushed out.


Nope, was always using win 7 on both of these computers.
 
There are Two softwares there.

1.Copywipe.

2.UBCD

In that download any of that.And make it a bootable CD.
Load it and choose the option Wipe complete drive or reformat with 0000
Done.
You can install fresh xp.If you have any more doubt ask me.
 
Use dban

It's open source and does the trick. You'll have to burn the program on to a disk, then set your bios to load from the cd/dvd drive. When the program loads you can choose what wiping method you want (dod, gutman, etc.) and how many passes you want it to make of the harddrive.

It doesn't really matter though: You can set it to make a single pass with whichever method you want and you'll be ready for a reinstall. If you didn't have a bug on there, it would be much easier, but I'd wipe it before reinstalling.
 
. . . Also, if you have websites on a server somewhere and use an FTP program like Filezilla, you better check to make sure your server(s) hasn't been compromised. I had my box rooted about a year ago, and I know another WF user that had his hit about a month ago, and both of us had sites on our servers infected with the same script that infected us because we used regular FTP instead of SFTP and the login info was stolen out of Filezilla.
(OP pardon the side step)

Fatbat sounds like I'm flying without a net here. What ftp program did you switch too?
 
wow so many complicated pain in the ass solutions for such a simple problem. No offense but you guys are never allowed near my computer when there's data to be lost :)

Boot from the windows cd. Go to the repair console (not a windows repair, its the second option (R) when you go start a fresh install. It'll bring you to a command prompt)
chkdsk /r <-this will scan your system files for curruption and replace them with the originals on the cd.
fixmbr <-this will fix the problem by restoring your masterbootrecord.
exit <-this will restart your computer.
 
> What ftp program did you switch to?

Can't speak for fatbat, but I can tell you that when I found out that Filezilla kept my passwords in plaintext, I looked at other ftp programs and couldn't find one I liked better. So I still use filezilla, but keep all the passwords in KeePass instead.

I would use sftp, except that both my VPS servers have a really weird, undocumented bug whereby if sftp is enabled/allowed, the ftp program can break out of the cpanel and browse directories above where you're supposed to be able to. I won't use sftp until I've nailed the reason for that.
 
wow so many complicated pain in the ass solutions for such a simple problem. No offense but you guys are never allowed near my computer when there's data to be lost :)

Boot from the windows cd. Go to the repair console (not a windows repair, its the second option (R) when you go start a fresh install. It'll bring you to a command prompt)
chkdsk /r <-this will scan your system files for curruption and replace them with the originals on the cd.
fixmbr <-this will fix the problem by restoring your masterbootrecord.
exit <-this will restart your computer.

Most newer laptops also have a factory partition that allows these options as well. It's usually a matter of holding a specific button while powering it on.

You're saying this will completely correct any virus issues, or that it will allow him to just fix the boot error? The way you're wording it he can boot the pc up after and be worry free. I know this is what most repair shops would do, but is it the safest? On my laptop there is a specific warning about not using this feature to fix virus-related problems.
 
I get responses like this from Linux users all the time. (One of my best friends for example) My usual response would be something like... yes it's easy to avoid infection when the target audience is so small the blaggards think, "why bother ".

The way linux is structured with the root permissions and such, even if virus makers made it their #1 target, it would still be very hard for them to get many infections.
 
Most newer laptops also have a factory partition that allows these options as well. It's usually a matter of holding a specific button while powering it on.

You're saying this will completely correct any virus issues, or that it will allow him to just fix the boot error? The way you're wording it he can boot the pc up after and be worry free. I know this is what most repair shops would do, but is it the safest? On my laptop there is a specific warning about not using this feature to fix virus-related problems.
It'll revert any system files and the master boot records that got corrupted by the virus with clean ones from the install cd, so you can get into windows and start do a virus scan to get rid of the virus itself. It's a safer way to go because viruses often infect the recovery partition as well. It's a good idea to never trust the recovery files when you have a virus. Think about it, if it got to your protected volsnap it probably got to your recovery partition