New
#21
how do I do that?
how do I do that?
I tried %systemroot%\system32\restore\rstrui.exe but this command is not recognized. I looked in the folder C:\windows\system32\restore and it seems to be empty (is this ok?). So I could not make a system restore yet, please advise how to do it, I am a bit lost now.
Hi,
All but two of your twenty BSOD blame iaStor.sys. This is the Intel Storage controller driver.
As you can see, it is up to date. I do not think that the driver is the cause here. I have a suspicion that malware is to blame:Code:iaStor.sys Thu Mar 04 15:51:31 2010 (4B8F2033)
To check if you have this, please run this tool - How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)?usasma said:
Regards,
Reventon
BUGCHECK SUMMARY
Code:Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 08:05:56.009 2011 (GMT+13) System Uptime: 0 days 0:01:31.899 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: WerFault.exe FAILURE_BUCKET_ID: X64_0x1E_iaStor+50af5 Bugcheck code 0000001E Arguments 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 05:37:08.880 2011 (GMT+13) System Uptime: 0 days 0:01:26.254 BugCheck D1, {0, 2, 1, fffff880012c1af5} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+50af5 Bugcheck code 000000D1 Arguments 00000000`00000000 00000000`00000002 00000000`00000001 fffff880`012c1af5 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 05:32:51.914 2011 (GMT+13) System Uptime: 0 days 0:00:54.662 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50afe ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xBE PROCESS_NAME: WerFault.exe FAILURE_BUCKET_ID: X64_0xBE_iaStor+50afe Bugcheck code 000000BE Arguments fffff880`01515fe8 00000000`05af7121 fffff800`00ba2a10 00000000`0000000a SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 05:31:11.080 2011 (GMT+13) System Uptime: 0 days 0:02:34.970 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+7257e ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT PROCESS_NAME: System BUGCHECK_STR: 0x7E FAILURE_BUCKET_ID: X64_0x7E_iaStor+7257e Bugcheck code 1000007E Arguments ffffffff`c0000005 fffff880`0127657e fffff880`0232b948 fffff880`0232b1b0 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 05:27:36.285 2011 (GMT+13) System Uptime: 0 days 0:00:39.659 Probably caused by : ntkrnlmp.exe ( nt!KiApcInterrupt+1f1 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: WerFault.exe FAILURE_BUCKET_ID: X64_0x1E_nt!KiApcInterrupt+1f1 Bugcheck code 0000001E Arguments ffffffff`c0000005 fffff800`02c64591 00000000`00000000 ffffffff`ffffffff SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 05:01:23.831 2011 (GMT+13) System Uptime: 0 days 0:01:07.346 BugCheck D1, {fffff880039dc3b8, 2, 0, fffff880012f616a} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+a16a ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+a16a Bugcheck code 000000D1 Arguments fffff880`039dc3b8 00000000`00000002 00000000`00000000 fffff880`012f616a SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Thu Feb 17 04:53:44.415 2011 (GMT+13) System Uptime: 0 days 0:00:52.789 Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+174 ) BUGCHECK_STR: 0xC5_2 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT PROCESS_NAME: WerFault.exe FAILURE_BUCKET_ID: X64_0xC5_2_nt!ExDeferredFreePool+174 Bugcheck code 000000C5 Arguments ffffffff`ffffff18 00000000`00000002 00000000`00000000 fffff800`02dfb000 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 20:52:04.808 2011 (GMT+13) System Uptime: 0 days 0:02:50.166 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+7257e ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT PROCESS_NAME: System BUGCHECK_STR: 0x7E FAILURE_BUCKET_ID: X64_0x7E_iaStor+7257e Bugcheck code 1000007E Arguments ffffffff`c0000005 fffff880`012fa57e fffff880`03710948 fffff880`037101b0 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 20:48:28.776 2011 (GMT+13) System Uptime: 0 days 0:01:02.524 BugCheck D1, {ffffe88003708138, 2, 1, fffff880012845b0} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+725b0 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+725b0 Bugcheck code 000000D1 Arguments ffffe880`03708138 00000000`00000002 00000000`00000001 fffff880`012845b0 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 20:45:57.899 2011 (GMT+13) System Uptime: 0 days 0:00:43.789 BugCheck D1, {fffffa7fffffffd0, 2, 1, fffff88001261b7f} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+2db7f ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+2db7f Bugcheck code 000000D1 Arguments fffffa7f`ffffffd0 00000000`00000002 00000000`00000001 fffff880`01261b7f SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 20:43:39.320 2011 (GMT+13) System Uptime: 0 days 0:00:45.678 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50a16 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT PROCESS_NAME: System BUGCHECK_STR: 0x7E FAILURE_BUCKET_ID: X64_0x7E_iaStor+50a16 Bugcheck code 1000007E Arguments ffffffff`c0000005 fffff880`01306a16 fffff880`03710968 fffff880`037101d0 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 20:42:08.410 2011 (GMT+13) System Uptime: 0 days 0:00:46.300 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0x1E_iaStor+50af5 Bugcheck code 0000001E Arguments 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 09:41:54.617 2011 (GMT+13) System Uptime: 0 days 0:00:52.975 BugCheck D1, {0, 2, 1, fffff880012afaf5} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+50af5 Bugcheck code 000000D1 Arguments 00000000`00000000 00000000`00000002 00000000`00000001 fffff880`012afaf5 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:36:56.731 2011 (GMT+13) System Uptime: 0 days 0:00:45.479 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+a068 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0x1E_iaStor+a068 Bugcheck code 0000001E Arguments ffffffff`c0000005 fffff880`01252068 00000000`00000000 ffffffff`ffffffff SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:35:29.938 2011 (GMT+13) System Uptime: 0 days 0:00:28.828 BugCheck D1, {7efdffd1, 2, 1, fffff8800124cb7f} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+2db7f ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+2db7f Bugcheck code 000000D1 Arguments 00000000`7efdffd1 00000000`00000002 00000000`00000001 fffff880`0124cb7f SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:30:02.625 2011 (GMT+13) System Uptime: 0 days 0:00:59.373 BugCheck D1, {ffffe88003708138, 2, 1, fffff880013675b0} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+725b0 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+725b0 Bugcheck code 000000D1 Arguments ffffe880`03708138 00000000`00000002 00000000`00000001 fffff880`013675b0 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:22:23.546 2011 (GMT+13) System Uptime: 0 days 0:00:49.436 BugCheck D1, {0, 2, 1, fffff88001271af5} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+50af5 Bugcheck code 000000D1 Arguments 00000000`00000000 00000000`00000002 00000000`00000001 fffff880`01271af5 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:20:34.271 2011 (GMT+13) System Uptime: 0 days 0:00:55.161 BugCheck D1, {0, 2, 1, fffff880012e1af5} *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+50af5 ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xD1_iaStor+50af5 Bugcheck code 000000D1 Arguments 00000000`00000000 00000000`00000002 00000000`00000001 fffff880`012e1af5 SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:18:53.399 2011 (GMT+13) System Uptime: 0 days 0:00:46.147 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+2db7f ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xBE PROCESS_NAME: AtBroker.exe FAILURE_BUCKET_ID: X64_0xBE_iaStor+2db7f Bugcheck code 000000BE Arguments fffff880`00fea872 52500000`a18c0121 fffff880`03192a50 00000000`0000000a SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии`` Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Debug session time: Wed Feb 16 07:17:23.425 2011 (GMT+13) System Uptime: 0 days 0:00:38.173 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+2db7f ) DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xBE PROCESS_NAME: System FAILURE_BUCKET_ID: X64_0xBE_iaStor+2db7f Bugcheck code 000000BE Arguments 00000000`77985fd0 cb900000`004b7025 fffff880`031fb820 00000000`0000000a SystemProductName = Vostro 3500 ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
dear reventon, i just ran the TDSSKiller as you suggested, it found one malicious object: Rootkit.win32.tdss.tdl4
it suggests to cure. Should I do this? And what is next?
Go ahead and have that Kaspersky tool clean it up.
Looks like Ben had it right, I suspect that virus removal will do the trick for you. After it's removed, just cross your fingers and hope that it doesn't return!
oke it seems to work, for now I started and logged in normally. Iam now running my virusscanner first and will later try to connect to the web. I┤ll keep you all posted on the progress.
For now everybody who helped thank you very much, I would not have known what to do without you all. Tumbs up!
Regards
ok all still works, no more viruses found, internet works, reboot works, so I think we did it, again many thanks to you all.
Glad to hear that you managed to get rid of it!