Search This Blog

Wednesday, February 26, 2014

another day of heroic rootkit clean action -- tssdkiller did it, and I recovered it from bluescreen

another day of heroic rootkit clean action

the customer said they killed , but the anti-virus program wont start/run in real-time protection

avast can't do it,

remove avast,

install avast 2014 , it got an error, failed to install

install avir , installed ok, but avir failed to enable real time protection

tried nod32 online scan,  97% , the browser crashed

run malwarebyte scan, nothing found

then I spoted kapersky tssdkiller in my toolkit, run it, I saw a driver error message,

run again, it found a rootkit, kill it many times

started the PC in normal mode, crashed big time.... long story short

win32k.sys

page_fault_in_nonpaged_area

STOP : oxoooooo50

search the net, found internet comment about ati/amd driver package crashes win32k.sys. did a manual , driver only install of display driver.

all good.

btw the PC is windows XP x64 with SP2




1 comment:

  1. I have used AVG Anti virus for a number of years now, I would recommend this product to everyone.

    ReplyDelete