Suspect BSOD caused by malware

Jonboy

Contributor
Joined
Aug 29, 2013
Posts
42
Location
Worcestershire, England
I have just installed Win7 32 bit on an old laptop - Fujitsu Siemens Amilo L1310G - that previously ran XP. I started by fitting a new hard drive so that no old corruptions can carry through and there is a Plan B if all else fails.

I also upgraded the bios using the FS support site. This was successful and the machine worked fine before I started the Win 7 upgrade on the new hard drive.

So all went well with the clean install and after a couple of days I had almost finished the updates and found and installed most of the drivers through makers websites. I had also installed Microsoft Security Essentials at an early stage. Then in attempt to get the SD card reader to work I went looking for drivers and found Maxdriver website offering the driver I wanted.

This I believe was a big mistake. To access the free drivers I was asked to download their installer and the actual driver downloads were long and tedious having to queue with the machine switched on for 1 to 3 hours before being able to download one driver. The installer told me 13 drivers were out of date or missing and I managed to download 5 before abandoning and uninstalling the Maxdriver software.

In the course of the this process I suffered multiple BSOD and recoveries from an unexpected errors. Since uninstalling Maxdriver software I have tried to scan with MSE but it fails after ~80% scan and turns off. I have downloaded Malwarebytes and this too failed partway through the scan. I have run Chameleon 6 times on different keys and completed the malwarebytes scan but found nothing.

The machine is still crashing randomly sometimes requiring safe mode starts and recovery.

Wondering whether its is possible to get it cleaned up or whether to format and start again (probably 3 days effort).

I'd be grateful for any advice.

PS I did get the card reader to work!
 
Hi,

Honestly, considering the install is still so new and you haven't done much, it's best to wipe it and save yourself headaches. I would from this point on (if you have not gathered this already on your own) heavily recommend not downloading drivers from non-manufacturer websites, not even drivers spoken so highly about such as the unofficial PAX Creative drivers. The main thing that got you here was their installer, as it probably installed a bunch of crapware.

Regards,

Patrick
 
Hi Patrick,

I do agree with your comments entirely but half of me doesn't want to spend another 3days and I couldn't and windows couldn't find the Texas instrument driver for the card reader.

Since posting I've had a further crash and had a good luck at event viewer. This has led me to run 2 windows fix it progs for error codes 80070003 and 80041003. I haven't crashed yet and just downloaded the latest updates including May's mrt which is running now.

Whoops! MRT has just encountered a problem and stopped. No surprise there then..... and the other thing I tried was to use System Restore to a time before I installed Max Driver software. System Restore encountered a problem and did not change any settings or go back in time.

There is bunch of minidump files that has accumulated. This is unexplored territory to me. Is there any point in investigating here? I would need guidance as I it appears I can't read dmp files without further tools which look to be beyond my capabilities?

Andy
 
Hiya Bassfisher6522

Yeah I did all that. The machine isn't supported by FS for Win 7 but Win7Advisor said it would ok for 32 bit. The big worry was getting the wi-fi button to work. You have to install a little program called Power Manager which went on okay and the wi-fi is good. Sound isn't great even though I've got realtek AC'97 6/19/09 driver - latest showing on Realtek site. The infamous Max Driver was offering a later version 2012 vintage. Why don't I see that on the Realtek website?

I think FS support recommended the bios upgrade which I did.

One other dodgy matter is the install disc. Bought cheap as an OEM reinstallation disc (DELL) It has a legitimate product key and has activated properly but it did hang during the install - saying missing info or corrupt. On exploring the disc I found the en-UK language folder was empty. I changed to the en-US version and hey presto the install completed. Looks like these discs were never meant for the UK market?

Well MSE has stopped again during the full scan and initiated a reboot. Looks like I'm some way from cleaning up this machine.

Cheers Andy
 
If you want, I could take a look at your crash dumps and see what's going on. FWIW though, I really think this is just a matter of crapware causing OS corruption. It may be fixable with some help that you've gotten here before, but like I said, given the OS is so new/recent, a wipe (even though a little painful) would be the best route, IMO. Of course it is your system, and it's all up to you. If you'd like to battle through the possibilities of trying to fix it first, we'll do our best.

Regards,

Patrick
 
Thanks Patrick. Got your message loud and clear.

Nevertheless I am a little fascinated by what's going on here.

MRT wouldn't complete. MSE wont complete a scan. Malwarebytes wont scan. Chameleon hasn't found anything on 7 keys but the scan has be interrupted and stopped twice. System restore wont go back in time beyond the assumed corruption point.
This is a clever animal?

I don't want to be seen as a time waster but I see this as an opportunity to broaden my knowledge on the minidump front. Later today I'll start up the Amilo and follow the BSOD posting instructions. I'm checking this on my regular PC.

If the Amilo allows me to complete the BSOD posting instructions without crashing we'll see where that gets us?

Thanks again
Andy
 
Stopped part way through. Yesterday I tried MSE again several times. Every time after a few minutes running the scan, the machine went into reboot mode automatically and did a restart with the message that windows has recovered from an unexpected shutdown. So it hasn't completed a scan in the normal manner. Very weird behaviour?
 
Some sort of malware, probably. Again though, it's up to you. If you want to fight the beast, the first thing I'd do is head over to the Security forums here and take care of that first/see if Corrine can help you.

Regards,

Patrick
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top