Win32:Rloader-B blocks Windows from booting

Hi,

I have a laptop with Windows XP Pro on it. Every time I boot, I get a BSOD with the message 0x7b STOP. When I try booting in any of safe modi I get the same result. With a Hirens bootcd I managed to copy the entire hard drive data on a usb stick and I ran a virusscan on that. That’s when Avast told me it was a Win32:Rloader-B. But I can’t seem to remove it since no (bootable) virusscanner is able to find it. Can you help me?

Kind regards,

Roel

hey and welcome to the forum.

please follow this guide and attach your logs a malware expert will guide you from there.

http://forum.avast.com/index.php?topic=53253.0

good luck.

What is the OS ? I.e xp, vista, 7
If vista or 7 is it 32bit or 64bit ?

Oops must learn how to read
Please print these instruction out so that you know what you are doing

[*]Download OTLPENet.exe to your desktop
[]Download Farbar Recovery Scan Tool and save it to a flash drive.
[*]Ensure that you have a blank CD in the drive
[*]Double click OTLPENet.exe and this will then open imgburn to burn the file to CD
[*]Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
[*]As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :slight_smile:
[*]Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
[
]Insert the flash drive with FRST on it
[]Locate the flash drive and run FSRT
[
]The tool will start to run.

http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FRST2.gif

[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Here is the log from the Farbar Recovery Tool:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-10-2012 01
Ran by SYSTEM at 05-10-2012 19:18:20
Running from D:
Microsoft Windows XP (X86) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM.…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [7401472 2006-01-19] (NVIDIA Corporation)
HKLM.…\Run: [nwiz] nwiz.exe /installquiet
HKLM.…\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
HKLM.…\Run: [SigmatelSysTrayApp] stsystra.exe
HKLM.…\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [802816 2006-10-18] (Intel Corporation)
HKLM.…\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless [696320 2006-10-18] (Intel Corporation)
HKLM.…\Run: [Adobe ARM] “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM.…\Run: [MSC] “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey [947176 2012-09-12] (Microsoft Corporation)
HKU\Administrator.…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Administrator.…\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [39408 2011-02-04] (Google Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 195.130.131.132 195.130.130.4

==================== Services (Whitelisted) ===================

2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation)
2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [946176 2006-10-18] (Intel Corporation )
2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [290816 2006-10-18] (Intel(R) Corporation)
4 HidServ; C:\Windows\System32\hidserv.dll
2 MsMpSvc; “c:\Program Files\Microsoft Security Client\MsMpEng.exe”

==================== Drivers (Whitelisted) ====================

2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21425 2011-01-07] (Meetinghouse Data Communications)
3 b57w2k; C:\Windows\System32\DRIVERS\b57xp32.sys [142720 2005-10-26] (Broadcom Corporation)
3 guardian2; C:\Windows\System32\Drivers\oz776.sys [61312 2006-11-21] (O2Micro)
3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [193552 2012-08-30] (Microsoft Corporation)
3 NETw3x32; C:\Windows\System32\DRIVERS\NETw3x32.sys [1711104 2006-10-17] (Intel® Corporation)
2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [12544 2006-10-19] (Intel Corporation)
3 STHDA; C:\Windows\System32\drivers\sthda.sys [1171464 2006-07-27] (SigmaTel, Inc.)
4 Abiosdsk;
4 abp480n5;
4 adpu160m;
4 Aha154x;
4 aic78u2;
4 aic78xx;
4 AliIde;
4 amsint;
4 asc;
4 asc3350p;
4 asc3550;
4 Atdisk;
4 cd20xrnt;
1 Changer;
4 CmdIde;
4 Cpqarray;
4 dac2w2k;
4 dac960nt;
4 dpti2o;
4 hpn;
1 i2omgmt;
4 i2omp;
4 ini910u;
4 IntelIde;
1 lbrtfdc;
1 MpKsl47ac2eb8; ??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates{8C7F894C-785E-4600-B1C5-05B295E70124}\MpKsl47ac2eb8.sys
4 mraid35x;
1 PCIDump;
3 PDCOMP;
3 PDFRAME;
3 PDRELI;
3 PDRFRAME;
4 perc2;
4 perc2hib;
4 ql1080;
4 Ql10wnt;
4 ql12160;
4 ql1240;
4 ql1280;
4 Simbad;
4 Sparrow;
4 symc810;
4 symc8xx;
4 sym_hi;
4 sym_u3;
4 TosIde;
4 ultra;
4 ViaIde;
3 WDICA;

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2012-10-05 19:18 - 2012-10-05 19:18 - 00000000 ____D C:\FRST
2012-10-04 19:32 - 2012-10-04 19:32 - 00000050 ____A C:\Windows\System32.directory
2012-10-04 17:53 - 2012-10-05 11:53 - 00000000 ____D C:\RegBackups
2012-10-03 17:21 - 2012-10-03 17:45 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-10-03 11:37 - 2012-10-03 11:37 - 00000386 ___AH C:\Windows\Tasks\Microsoft Antimalware Scheduled Scan.job
2012-09-22 10:31 - 2012-09-22 10:32 - 00015035 ____A C:\Windows\KB2744842-IE8.log
2012-09-13 10:08 - 2012-09-13 10:08 - 00000000 __HDC C:\Windows$NtUninstallKB2736233$
2012-09-13 10:07 - 2012-09-13 10:08 - 00006039 ____A C:\Windows\KB2736233.log

==================== 3 Months Modified Files ==================

2012-10-04 19:32 - 2012-10-04 19:32 - 00000050 ____A C:\Windows\System32.directory
2012-10-04 17:41 - 2011-01-07 05:55 - 00000245 ___SH C:\boot.ini
2012-10-03 11:53 - 2011-01-07 05:16 - 00000178 __ASH C:\Documents and Settings\Administrator\ntuser.ini
2012-10-03 11:53 - 2011-01-07 05:13 - 00032652 ____A C:\Windows\SchedLgU.Txt
2012-10-03 11:53 - 2011-01-07 05:13 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-03 11:53 - 2011-01-07 05:07 - 01266924 ____A C:\Windows\WindowsUpdate.log
2012-10-03 11:52 - 2011-01-07 05:56 - 00436473 ____A C:\Windows\setupapi.log
2012-10-03 11:37 - 2012-10-03 11:37 - 00000386 ___AH C:\Windows\Tasks\Microsoft Antimalware Scheduled Scan.job
2012-10-03 11:32 - 2011-01-07 05:57 - 00001832 ____A C:\Windows\System32\PerfStringBackup.INI
2012-10-03 11:29 - 2011-01-07 06:43 - 00000438 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{58515C2B-FA08-47EC-ADFA-20B3FE44805D}.job
2012-10-03 11:28 - 2011-01-07 06:00 - 00011665 ____A C:\Windows\System32\nvModes.001
2012-10-03 11:28 - 2011-01-07 06:00 - 00000000 ____A C:\Windows\System32\NvwsApps.xml
2012-10-03 11:28 - 2004-08-12 09:34 - 00013646 ____A C:\Windows\System32\wpa.dbl
2012-10-03 11:27 - 2011-02-04 12:21 - 00001054 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-10-03 11:27 - 2011-01-07 05:16 - 00000062 __ASH C:\Documents and Settings\Administrator\Local Settings\desktop.ini
2012-10-03 11:27 - 2011-01-07 05:13 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2012-10-03 11:27 - 2011-01-07 05:12 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2012-10-02 13:41 - 2011-01-07 07:15 - 00001945 ____A C:\Windows\epplauncher.mif
2012-10-02 13:24 - 2011-02-04 12:21 - 00001058 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-22 10:32 - 2012-09-22 10:31 - 00015035 ____A C:\Windows\KB2744842-IE8.log
2012-09-22 10:32 - 2011-01-07 06:26 - 00208517 ____A C:\Windows\updspapi.log
2012-09-22 10:32 - 2011-01-07 05:57 - 01816213 ____A C:\Windows\iis6.log
2012-09-22 10:32 - 2011-01-07 05:57 - 01662387 ____A C:\Windows\FaxSetup.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00800813 ____A C:\Windows\ocgen.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00762452 ____A C:\Windows\tsoc.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00511354 ____A C:\Windows\msmqinst.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00452204 ____A C:\Windows\comsetup.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00291625 ____A C:\Windows\netfxocm.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00271802 ____A C:\Windows\ntdtcsetup.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00114919 ____A C:\Windows\MedCtrOC.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00084487 ____A C:\Windows\tabletoc.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00083218 ____A C:\Windows\msgsocm.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00072866 ____A C:\Windows\ocmsn.log
2012-09-22 10:32 - 2011-01-07 05:57 - 00001374 ____A C:\Windows\imsins.log
2012-09-13 10:08 - 2012-09-13 10:07 - 00006039 ____A C:\Windows\KB2736233.log
2012-09-13 10:08 - 2011-01-07 05:57 - 00001374 ____A C:\Windows\imsins.BAK
2012-09-13 10:06 - 2011-01-07 06:26 - 62164608 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-30 16:03 - 2010-10-24 16:25 - 00193552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-28 14:44 - 2011-01-07 06:36 - 11111424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieframe.dll
2012-08-28 14:44 - 2009-03-07 23:39 - 11111424 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-28 11:14 - 2012-06-15 03:41 - 00521728 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsdbgui.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 02000384 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iertutil.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 00743424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedvtool.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 00630272 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeeds.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 00247808 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieproxy.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 00055296 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeedsbs.dll
2012-08-28 11:14 - 2011-01-07 06:36 - 00012800 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\xpshims.dll
2012-08-28 11:14 - 2009-03-07 23:32 - 02000384 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-28 11:14 - 2009-03-07 23:32 - 00630272 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-28 11:14 - 2009-03-07 23:31 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-08-28 11:14 - 2004-08-12 09:33 - 00916992 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wininet.dll
2012-08-28 11:14 - 2004-08-12 09:33 - 00916992 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-28 11:14 - 2004-08-12 09:31 - 01212416 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\urlmon.dll
2012-08-28 11:14 - 2004-08-12 09:31 - 01212416 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-28 11:14 - 2004-08-12 09:31 - 00105984 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\url.dll
2012-08-28 11:14 - 2004-08-12 09:31 - 00105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-28 11:14 - 2004-08-12 09:25 - 00206848 ____N (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-08-28 11:14 - 2004-08-12 09:25 - 00206848 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\occache.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 06008832 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 06008832 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 00611840 ____N (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 00611840 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mstime.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 00067072 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mshtmled.dll
2012-08-28 11:14 - 2004-08-12 09:23 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-28 11:14 - 2004-08-12 09:21 - 00043520 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\licmgr10.dll
2012-08-28 11:14 - 2004-08-12 09:21 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-08-28 11:14 - 2004-08-12 09:20 - 01469440 ____N (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-28 11:14 - 2004-08-12 09:20 - 01469440 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\inetcpl.cpl
2012-08-28 11:14 - 2004-08-12 09:20 - 00025600 ____N (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-28 11:14 - 2004-08-12 09:20 - 00025600 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsproxy.dll
2012-08-28 11:14 - 2004-08-12 09:19 - 00387584 ____N (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-08-28 11:14 - 2004-08-12 09:19 - 00387584 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedkcs32.dll
2012-08-28 11:14 - 2004-08-12 09:19 - 00184320 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iepeers.dll
2012-08-28 11:14 - 2004-08-12 09:19 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-08-28 08:07 - 2004-08-12 09:19 - 00385024 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-08-28 08:07 - 2004-08-12 09:19 - 00174080 ____N (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-08-28 08:07 - 2004-08-12 09:19 - 00174080 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ie4uinit.exe
2012-08-22 04:54 - 2011-01-07 05:56 - 00264616 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-19 17:35 - 2012-08-18 08:12 - 00016506 ____A C:\Windows\KB2712808.log
2012-08-19 17:34 - 2012-08-19 17:34 - 00012242 ____A C:\Windows\KB2731847.log
2012-08-19 17:32 - 2012-08-19 17:32 - 00010854 ____A C:\Windows\KB2723135.log
2012-08-19 17:32 - 2012-08-18 08:12 - 00016054 ____A C:\Windows\KB2705219.log
2012-08-19 17:30 - 2012-08-19 17:29 - 00015239 ____A C:\Windows\KB2722913-IE8.log
2012-07-13 11:44 - 2012-07-13 11:44 - 00008709 ____A C:\Windows\KB2718523.log
2012-07-13 11:44 - 2012-07-12 02:29 - 00013398 ____A C:\Windows\KB2691442.log
2012-07-13 11:43 - 2012-07-12 02:29 - 00012499 ____A C:\Windows\KB2655992.log
2012-07-13 11:43 - 2004-08-12 09:33 - 00000552 ____A C:\Windows\win.ini
2012-07-13 11:42 - 2012-07-12 02:29 - 00012192 ____A C:\Windows\KB2719985.log
2012-07-13 11:40 - 2012-07-13 11:39 - 00008509 ____A C:\Windows\KB2698365.log

==================== Known DLLs (Whitelisted) =================

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM.….exe: exefile => OK
HKLM.…\exefile\DefaultIcon: %1 => OK
HKLM.…\exefile\open\command: “%1” %* => OK

==================== Restore Points (XP) =====================

==================== Memory info ===========================

Percentage of memory in use: 19%
Total physical RAM: 1022.05 MB
Available physical RAM: 827.85 MB
Total Pagefile: 905.6 MB
Available Pagefile: 836.58 MB
Total Virtual: 2047.88 MB
Available Virtual: 2002.18 MB

==================== Partitions =============================

1 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
2 Drive c: () (Fixed) (Total:149.05 GB) (Free:140.73 GB) NTFS ==>[Drive with boot components (Windows XP)]
3 Drive d: (ITSREMOVABL) (Removable) (Total:7.45 GB) (Free:7.17 GB) FAT32
4 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS

Disk ### Status Size Free Dyn Gpt


Disk 0 Online 149 GB 0 B

Partitions of Disk 0:

Partition ### Type Size Offset


Partition 1 Primary 149 GB 32 KB

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info


  • Volume 1 C NTFS Partition 149 GB Healthy
    =========================================================
    ==================== End Of Log ============================

I’m posting from a different computer as I’m not able to boot into windows on the laptop.

It is Windows XP Pro 32 bit.

OK return to the Reatogo desktop

Double-click on the MBRFix icon from the OTLPE desktop, a command window will open

http://www.hdrcgb.org.uk/g2g/mbrfix1.jpg

In the command window type in the following lines and press enter after each:

MbrFix /drive 0 savembr C:\Backup_MBR_0.bin
MbrFix /drive 0 fixmbr /xp /yes

Try and reboot normally into your computer.

I did what you proposed, but I still get the:

*** STOP: 0x0000007B (0xF7A35524, 0xC0000034, 0x00000000, 0x00000000)

Same error pops up when I boot into safe mode

OK next trick

Enter BIOS at startup, go to “Integrated Peripherals” or something similar where you can find the “SATA Mode” option and change it from AHCI to ATA or IDE

Try to reboot again

I can’t. The laptop is a Dell Latitude 620. I can either setup, where I can change the bootsequence. But I don’t see a “SATA Mode” of the HD.

http://www.ehow.com/how_5946396_enter-bios-dell-latitude.html

I can enter the BIOS (Version A10) by hitting F2. But I can’t see any “SATA Mode” of the HD. The only information I see from the HD is:

Primary Hard Drive = 160 GB HDD.
HDD Acoustic Mode “Bypass, Quiet, Performance”.

And I can set a password for HDD. That is it…

Hmm that stop indicator is normally related to an MBR problem

Could you run the following tool from the reatogo desktop

Listparts

Run the tool, click Scan and post the log (Result.txt) it makes.

https://dl.dropbox.com/u/73555776/listparts.GIF

Here is the log:

ListParts by Farbar Version: 02-10-2012
Ran by SYSTEM (administrator) on 06-10-2012 at 14:17:36
Windows XP (X86)
Running From: D:
Language: 0409


========================= Memory info ======================

Percentage of memory in use: 15%
Total physical RAM: 1022.05 MB
Available physical RAM: 860.92 MB
Total Pagefile: 905.6 MB
Available Pagefile: 842.99 MB
Total Virtual: 2047.88 MB
Available Virtual: 2009.38 MB

======================= Partitions =========================

1 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
2 Drive c: () (Fixed) (Total:149.05 GB) (Free:140.73 GB) NTFS ==>[Drive with boot components (Windows XP)]
3 Drive d: (ITSREMOVABL) (Removable) (Total:7.45 GB) (Free:7.17 GB) FAT32
4 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS

Disk ### Status Size Free Dyn Gpt


Disk 0 Online 149 GB 0 B

Partitions of Disk 0:

Partition ### Type Size Offset


Partition 1 Primary 149 GB 32 KB

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info


  • Volume 1 C NTFS Partition 149 GB Healthy
    ======================================================================================================

****** End Of Log ******

I get the BSOD with the stop message just after seeing the Windows XP Logo for a second or so. The laptop boots, the logo pops up and then boem → BSOD.

Do you get the Safe mode menu when you repeatedly press F8 at Boot ?

If so then try last known good

I automatically get the menu where I can select Normal mode, Safe Mode, Safe Mode with Network, Safe Mode with MS Dos, or load the last known configuration, since Windows has not been shut down properly.

All the safe modi crash just after they loaded the mup.sys driver. The last known good configuration also crashes with the 0x7b Stop error.

Just the data I was after

The most common cause is the executing PnP (Plug and Play) and ACPI routines issue.
To fix the issue, we need to access the computer from Recovery Console.

If you do have your Windows CD

  1. To start the Recovery Console directly from the Windows XP CD you would do the following:

[*]Insert the Windows XP cd in your computer.[*]Restart your computer so you are booting off of the CD.[*]When the Welcome to Setup screen appears, press the R button on your keyboard to start the Recovery Console.[*]The Recovery Console will start and ask you which Windows installation you would like to log on to. If you have multiple Windows installations, it will list each one, and you would enter the number associated with the installation you would like to work on and press enter. If you have just one Windows installation, type 1 and press enter.[*]It will then prompt you for the Administrator’s password. If there is no password, simply press enter. Otherwise type in the password and then press enter.[*]If you entered the correct password you will now be presented with a C:\Windows> prompt and you can start using the Recovery Console.

  1. Type map and press enter.
    It will give you the drive letters.
    Note down the letter of you CD-ROM.
    If it is a letter other than E you should replace the letter E with your CD drive letter when applying the expand command later on if the command is needed to be applied.

Type following commmands, pressing Enter after each one.

[*]ren c:\windows\system32\drivers\atapi.sys atapi.old
(It will returns to the prompt again without notification)[*]copy c:\windows\servicepackfiles\i386\atapi.sys c:\windows\system32\drivers
(If you get a notification “1 file(s) copied” you don’t need to do the next expand command and go to exit command. But if you get notification that the file doesn’t exist proceed with expand command)[*]expand e:\I386\atapi.sy_ c:\windows\system32\drivers
(You should be notified that the file expanded)[*]exit

    You may remove the CD or let Windows boot normally. 

If you don’t have your Windows CD
Please download ARCDC from Artellos.com.

[*]Double click ARCDC.exe
[*]Follow the dialog until you see 6 options. Please pick: [i]Windows Professional SP2 & SP3[/i]
[*]You will be prompted with a Terms of Use by Microsoft, please accept.
[*]You will see a few dos screens flash by, this is normal.
[*]Next you will be able to choose to add extra files. Select the Default Files.
[*]The last window will allow you to burn the disk using BurnCDCC
Then, follow instructions from Step #1 above.

I followed the instructions of not having the original disk. After completion I rebooted normally but I still get the same error. Booting into safe modus also still gives the same error.

EDIT: Strange, I just reviewed the drivers folder c:\WINDOWS\system32\drivers with the OTL bootable disk. And although the date of the last modification is today, I can’t see any atapi.old.

I also just found out that Microsoft Security Essentials was installed on the laptop. Apparently that can also result into problems if it is installed on a XP machine.