Fake Bsod 0x00009af8 virus

pvtmadness

New member
Local time
8:31 PM
Messages
7
I am running Win 7 64bit Home Premium on HP Pavillion p6837c with SvcPac 1 installed and have auto updates enabled. About 4 days ago started getting random BSOD '0X00009AF8 Driver_IRQL Pending Operation'. Goes away on reboot and occurs randomly during the day. Can not find this error number via google search so thanks in advance for any help!
 

Attachments

  • IMG_2314.JPG
    IMG_2314.JPG
    279.1 KB · Views: 0

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
The screen looks unusual, a windows BSOD screen does not look like that, and dont say those texts. Specially the contracts, this part looks like a scam.

On the other side, it is a stop 0xD1 BSOD which is a driver related issue in most of the cases. But as the upload does not contain any crash dump, we cannot check them to find out the probleming driver. There is no such irql.sys as the screenshot says. IRQL is Interrupt Request Level (IRQL) is a level of priority of the computers internal environment, not a sys file.


Follow it: http://www.sevenforums.com/tutorials/174459-dump-files-configure-windows-create-bsod.html
Go to Option Two, Point 2. Download the .reg file and merge it in registry by double clicking it.

Now wait for another BSOD. When it occurred, search the .dmp files manually in the default path: C:\Windows\Minidump or %SystemRoot%\Minidump. See if the crash dump is recorded or not (hopefully it will be recorded).Post it following the Blue Screen of Death (BSOD) Posting Instructions.

Dont run any disc cleanup tool before you upload another zip.
 

My Computer My Computer

At a glance

Microsoft Windows 10 Pro Insider Preview 64-bitIntel(R) Core(TM) i3-4130 CPU @ 3.40GHzCorsair Vengence 4GB x2 (8.00GB Dual-Channel ...2047MB GeForce GTS 450 (ZOTAC International)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Assembled
OS
Microsoft Windows 10 Pro Insider Preview 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
Gigabyte Technology Co., Ltd. B85M-D3H
Memory
Corsair Vengence 4GB x2 (8.00GB Dual-Channel DDR3 @ 798MHz)
Graphics Card(s)
2047MB GeForce GTS 450 (ZOTAC International)
Sound Card
Onboard (Realtek High Definition Audio)
Monitor(s) Displays
LG Flatron E2040T
Screen Resolution
1600x900
Hard Drives
Western Digital 1 TB
Seagate 500 GB
PSU
Corsair VS550
Case
Cooler Master K380
Cooling
Cooler Master Seidon 120V Plus
Keyboard
Logitech MK260r
Mouse
Logitech MK260r
Internet Speed
PMPL Broadband
Antivirus
Windows Defender + MBAM
Browser
Firefox
Other Info
Dell Studio 15" Laptop
Please move it to the system security forum then, John?

Edit: @pvtmadness, It is not a BSOD screen. The data you uploaded does not show a BSOD. You are scammed. Something you have downloaded willingly or unwillingly in your computer which is resulting this screen.

If I have been in place of you, I would have formatted the HDD at once.
 

My Computer My Computer

At a glance

Microsoft Windows 10 Pro Insider Preview 64-bitIntel(R) Core(TM) i3-4130 CPU @ 3.40GHzCorsair Vengence 4GB x2 (8.00GB Dual-Channel ...2047MB GeForce GTS 450 (ZOTAC International)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Assembled
OS
Microsoft Windows 10 Pro Insider Preview 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
Gigabyte Technology Co., Ltd. B85M-D3H
Memory
Corsair Vengence 4GB x2 (8.00GB Dual-Channel DDR3 @ 798MHz)
Graphics Card(s)
2047MB GeForce GTS 450 (ZOTAC International)
Sound Card
Onboard (Realtek High Definition Audio)
Monitor(s) Displays
LG Flatron E2040T
Screen Resolution
1600x900
Hard Drives
Western Digital 1 TB
Seagate 500 GB
PSU
Corsair VS550
Case
Cooler Master K380
Cooling
Cooler Master Seidon 120V Plus
Keyboard
Logitech MK260r
Mouse
Logitech MK260r
Internet Speed
PMPL Broadband
Antivirus
Windows Defender + MBAM
Browser
Firefox
Other Info
Dell Studio 15" Laptop

My Computer My Computer

At a glance

Microsoft Windows 10 Pro Insider Preview 64-bitIntel(R) Core(TM) i3-4130 CPU @ 3.40GHzCorsair Vengence 4GB x2 (8.00GB Dual-Channel ...2047MB GeForce GTS 450 (ZOTAC International)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Assembled
OS
Microsoft Windows 10 Pro Insider Preview 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
Gigabyte Technology Co., Ltd. B85M-D3H
Memory
Corsair Vengence 4GB x2 (8.00GB Dual-Channel DDR3 @ 798MHz)
Graphics Card(s)
2047MB GeForce GTS 450 (ZOTAC International)
Sound Card
Onboard (Realtek High Definition Audio)
Monitor(s) Displays
LG Flatron E2040T
Screen Resolution
1600x900
Hard Drives
Western Digital 1 TB
Seagate 500 GB
PSU
Corsair VS550
Case
Cooler Master K380
Cooling
Cooler Master Seidon 120V Plus
Keyboard
Logitech MK260r
Mouse
Logitech MK260r
Internet Speed
PMPL Broadband
Antivirus
Windows Defender + MBAM
Browser
Firefox
Other Info
Dell Studio 15" Laptop
My customer had a similar fake BSOD with different phone number this morning:

fakebsod.jpg

No files dropped, I know of, closing IE in the task manager got rid of it. Rebooted the system and it did not return as of yet...
 

My Computer My Computer

At a glance

Windows 7 64-bit, Windows 8.1 64-bit, OSX El ...Intel i5-3350P 3.1 GHz16 GBs GSkill SniperRadeon HD 7850
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built at Home
OS
Windows 7 64-bit, Windows 8.1 64-bit, OSX El Capitan, Windows 10 (VMware)
CPU
Intel i5-3350P 3.1 GHz
Motherboard
Gigabyte GA-Z77X-UP5 TH
Memory
16 GBs GSkill Sniper
Graphics Card(s)
Radeon HD 7850
Sound Card
VIA HD Audio
Monitor(s) Displays
Dell U2410 24"
Screen Resolution
1920x1200
Hard Drives
1 x Intel 520 240 GBs
1 x Seagate 1TBs SATA 2.0,
1 x Seagate 1TBs eSATA 2.0
PSU
Thermaltake 850W
Case
Antec P183
Cooling
Noctua NH-D14 Heatsink 2 x 120mm fans, 4 x 120mm case fans
Keyboard
Dell Multimedia keyboard
Mouse
Logitech Trackball
Internet Speed
28.5 Mb/s
Thanks to all of you!! I will continue to follow on security forum.

Will
 

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
Hmm this is an interesting one and although it is a nuisance makes one wonder what the source was trying to do ? sell the OS again??
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
In an interesting turn of events, there is now a line at the bottom of the BSOD screen that says something along the lines of " If you want to get out of this screen hit escape at your own risk" Exact wording not available because the "BSOD" is not up at the moment. I called the number on the page for the "microsoft technician" and, of course, the person answering the phone won't talk to me unless I give him a credit card number. Ha! Balls! So I am now convinced this is adware of some type and they are either selling the ability to help me "resolve" the problem, perhaps by sharing my screen (yikes!), or even to sell me security software. Disappointingly, MWB did not catch it, nor did Windows Security Essentials. In the end, hitting escape does in fact take me back to what I was doing with no other problems...that I can see. Now to figure out how to get rid of it....
 

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
Now that I have "escaped" from the fake BSOD a few times, I received a "system" warning about dangers to my PC from not being protected. Obviously this is true if both MWB and Windows Security Essentials are not catching this. See attached SS
 

Attachments

  • SS  080115.png
    SS 080115.png
    84.7 KB · Views: 2

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
This is not Microsoft Security Essentials.

Your system is compromised. It would be the best for you if you format the HDD and start afresh.
 

My Computer My Computer

At a glance

Microsoft Windows 10 Pro Insider Preview 64-bitIntel(R) Core(TM) i3-4130 CPU @ 3.40GHzCorsair Vengence 4GB x2 (8.00GB Dual-Channel ...2047MB GeForce GTS 450 (ZOTAC International)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Assembled
OS
Microsoft Windows 10 Pro Insider Preview 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
Gigabyte Technology Co., Ltd. B85M-D3H
Memory
Corsair Vengence 4GB x2 (8.00GB Dual-Channel DDR3 @ 798MHz)
Graphics Card(s)
2047MB GeForce GTS 450 (ZOTAC International)
Sound Card
Onboard (Realtek High Definition Audio)
Monitor(s) Displays
LG Flatron E2040T
Screen Resolution
1600x900
Hard Drives
Western Digital 1 TB
Seagate 500 GB
PSU
Corsair VS550
Case
Cooler Master K380
Cooling
Cooler Master Seidon 120V Plus
Keyboard
Logitech MK260r
Mouse
Logitech MK260r
Internet Speed
PMPL Broadband
Antivirus
Windows Defender + MBAM
Browser
Firefox
Other Info
Dell Studio 15" Laptop
Thanks for your response, Arc. Yes, I agree, this is not MS Security Essentials, it is a fake. The question is, where is it getting in if both MWB and MS SE are not catching it? In my opinion, reformatting, which would certainly get rid of the problem, is not the first step that I want to take. It is like someone who has a shoulder pain and elects radical surgery before trying physical therapy first. Surely there is a special tool that can be recommended to scan for this type of malware and remove it. I will download Defender Offline first and see what comes of that.
 

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
This is something more than just a malware or adware. It is an attempt to hack your system. Removal of the particular item/items will not be the best thing there, IMHO.

I have requested Cottonball to have a look.
 

My Computer My Computer

At a glance

Microsoft Windows 10 Pro Insider Preview 64-bitIntel(R) Core(TM) i3-4130 CPU @ 3.40GHzCorsair Vengence 4GB x2 (8.00GB Dual-Channel ...2047MB GeForce GTS 450 (ZOTAC International)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Assembled
OS
Microsoft Windows 10 Pro Insider Preview 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
Gigabyte Technology Co., Ltd. B85M-D3H
Memory
Corsair Vengence 4GB x2 (8.00GB Dual-Channel DDR3 @ 798MHz)
Graphics Card(s)
2047MB GeForce GTS 450 (ZOTAC International)
Sound Card
Onboard (Realtek High Definition Audio)
Monitor(s) Displays
LG Flatron E2040T
Screen Resolution
1600x900
Hard Drives
Western Digital 1 TB
Seagate 500 GB
PSU
Corsair VS550
Case
Cooler Master K380
Cooling
Cooler Master Seidon 120V Plus
Keyboard
Logitech MK260r
Mouse
Logitech MK260r
Internet Speed
PMPL Broadband
Antivirus
Windows Defender + MBAM
Browser
Firefox
Other Info
Dell Studio 15" Laptop
The interesting thing is that whoever it is has put up this fake BSOD and is now making a *timely* offering of software to fix the problem, all under the ruse of being MS. This appears to be a well thought out campaign to sell their product and I'm surprised this isn't more widely reported on the internet.
 

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
FYI, I googled the number in the ad and came up with a number of articles on fake pop ups and scams, including this one by MWB https://blog.malwarebytes.org/tech-support-scams/ In the article MWB says to run a full scan to get rid of these but that doesn't seem to be working on my PC. Chalk one up for the scammers.

Also, googling "pc-techies", the name in the URL, comes up with all sorts of stories about them being a scammer operation...yet, no word on how to block them.
 

My Computer My Computer

At a glance

64 home premium
Computer type
PC/Desktop
OS
64 home premium
It probably came in on something you downloaded and installed recently. If the code is not performing unusual tasks, it probably won't be caught by any malware scanner. And simply displaying text is not an unusual task. The damage will be done when you let them into your system. Check to see if you can identify the program that is running in Task Manager when the screen appears. If you can find it, delete the program file.

The fact that it reappears suggest that it may be a two-part problem aided by the software you installed. It may have generated a Scheduled Task, a Start Up task or something is running all the time to issue the display.

Forgot to ask: Are you using Gadgets?

Also, Go to Programs and Features, sort the list by clicking on the "Installed on" column header then post a snip of it.
 

My Computer My Computer

At a glance

Windows 7 Pro-x64i7-2600 3.4GHz - 3.8GHz Turbo8Gb - 2x4GB, Muskin 991770 PC3-1333Integrated Intel HD 2000
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
I'd try Malware Bytes' Junkware Removal Tool, and, AdwCleaner....

You might also consider Comodo's AutoRuns, or SysInternal's AutoRuns, which might let you track down the source of who/what is initiating the popup/fake warning, so that you might be able to delete it.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 bitAMD A45 GBIntegrated Radeon
Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Home Premium 64 bit
CPU
AMD A4
Memory
5 GB
Graphics Card(s)
Integrated Radeon
Hard Drives
500 gb WD
Antivirus
360 TS
Browser
IE
If no one minds me putting in two cents worth I think a run with a rescue disk is worth a try there are two I would recommend
Kaspersky Rescue Disk 10 or How to create a Bitdefender Rescue CD

I personally find the Kaspersky the easiest to run but the choice if you want it try - got nothing to lose and it will not require Windows to boot at all


There is also a ton of security stuff in here too only they have reorganised it because the rescue disks were in a section of their own Free Windows Desktop Software Security List - Entire List | Gizmo's Freeware
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
" The system have found 35....."

It's a good thing most scam tards can't compose a simple sentence correctly!
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 bitAMD A45 GBIntegrated Radeon
Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Home Premium 64 bit
CPU
AMD A4
Memory
5 GB
Graphics Card(s)
Integrated Radeon
Hard Drives
500 gb WD
Antivirus
360 TS
Browser
IE
Back
Top