Suspected Malware Causing BSOD


  1. Posts : 24
    Windows 7 Professional X64 SP1
       #1

    Suspected Malware Causing BSOD


    I'm posting this thread according to Arc's and cottonball's guide in my previous thread in BSOD section to provide reports from Farbar Recovery Scan Tool and Farbar service scanner. You can check the reports in the attached file.
    Suspected Malware Causing BSOD Attached Files
      My Computer


  2. Posts : 2,470
    Windows 7 Home Premium
       #2

    Icezed,

    My apology for the delay...did not see your post.

    BugCheck Analysis is just not my thing, however, can see how an entry for ataport! leads one to look at atapi.sys Also, atapi.sys has been a common target of the TDSS TDL4 (Alureon) RootKit.

    In this particular case, TDSSKiller, a prime candidate for finding the rootkit and resolving the bluescreen issue, detected nothing, as you mentioned, in both normal and safe mode.

    The Farbar Recovery Scan Tool (FRST), another outstanding tool for detecting RootKits and hard to detect malware, did not identify anything pertinent to ataport or atapi.sys

    We can run more tools, like GMER and Malwarebytes Anti-Malware, if you wish, but, personally, do not expect these additional tools to find entries related to ATA Port's interface.

    The Additions.txt produced by FRST does show an entry under Faulty Device Manager Devices, as well as Event Log errors.

    The use of sxstrace.exe is indicated, WinMgmt based entries are identified, and, interestingly enough, one of the Event Log errors is:
    Error: (07/04/2013 00:46:55 AM) (Source: Microsoft Security Client Setup) (User: Icezed-PC)
    Description: HRESULT:0x8004FF66
    Description:Windows did not pass genuine validation....etc.

    This is rather unusual for a new computer!

    Also, not sure that pursuing all these issues is going to get us ahead...

    Was this computer built by someone you paid to do so, or is it a brand name machine that came out of a box? If brand name, can it be restored to factory defaults?

    Also see where Arc suggested to go for a Clean Reinstall - Factory OEM Windows 7




    Will qualify these comments with the assertion that I am not an expert at anything. Just like bustin' malware.

    If someone sees something else here, please jump in!
      My Computer


  3. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #3

    Icezed

    Run a MGAdiag report and post the log inside this thread https://www.sevenforums.com/windows-updates-activation

    Please download MGADiag and save it to your desktop.

    Double click icon on your desktop.

    Click on the button

    Click on the button

    Paste the log inside the box . Highlight all of the text then code wrap by pressing on the # icon on the top .
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:09.
Find Us