Suspected Malware Causing BSOD

Icezed

New member
Local time
11:59 AM
Messages
24
I'm posting this thread according to Arc's and cottonball's guide in my previous thread in BSOD section to provide reports from Farbar Recovery Scan Tool and Farbar service scanner. You can check the reports in the attached file.
 

Attachments

My Computer

Computer type
PC/Desktop
OS
Windows 7 Professional X64 SP1
Sound Card
Onboard
Icezed,

My apology for the delay...did not see your post.

BugCheck Analysis is just not my thing, however, can see how an entry for ataport! leads one to look at atapi.sys Also, atapi.sys has been a common target of the TDSS TDL4 (Alureon) RootKit.

In this particular case, TDSSKiller, a prime candidate for finding the rootkit and resolving the bluescreen issue, detected nothing, as you mentioned, in both normal and safe mode.

The Farbar Recovery Scan Tool (FRST), another outstanding tool for detecting RootKits and hard to detect malware, did not identify anything pertinent to ataport or atapi.sys

We can run more tools, like GMER and Malwarebytes Anti-Malware, if you wish, but, personally, do not expect these additional tools to find entries related to ATA Port's interface.

The Additions.txt produced by FRST does show an entry under Faulty Device Manager Devices, as well as Event Log errors.

The use of sxstrace.exe is indicated, WinMgmt based entries are identified, and, interestingly enough, one of the Event Log errors is:
Error: (07/04/2013 00:46:55 AM) (Source: Microsoft Security Client Setup) (User: Icezed-PC)
Description: HRESULT:0x8004FF66
Description:Windows did not pass genuine validation....etc.

This is rather unusual for a new computer!

Also, not sure that pursuing all these issues is going to get us ahead...

Was this computer built by someone you paid to do so, or is it a brand name machine that came out of a box? If brand name, can it be restored to factory defaults?

Also see where Arc suggested to go for a http://www.sevenforums.com/tutorials/219487-clean-reinstall-factory-oem-windows-7-a.html




Will qualify these comments with the assertion that I am not an expert at anything. Just like bustin' malware.

If someone sees something else here, please jump in!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Icezed

Run a MGAdiag report and post the log inside this thread http://www.sevenforums.com/windows-updates-activation

Please download MGADiag and save it to your desktop.

:ar: Double click
2novly.png
icon on your desktop.

:ar: Click on the
2j8t3t.png
button

:ar: Click on the
av68hu.png
button

:ar: Paste the log inside the box . Highlight all of the text then code wrap by pressing on the # icon on the top .
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Back
Top