ie8 fix
madison

Hardware 2.0

Adrian Kingsley-Hughes

Is a rootkit behind the XP BSoDs?

By | February 12, 2010, 2:32pm PST

Summary: Is a rootkit behind the recent spate of Windows XP BSoDs? According to an investigation carried out by security journalist Brian Krebs, it could play a part.

Is a rootkit infection behind the recent spate of Windows XP BSoDs? According to an investigation carried out by security journalist Brian Krebs, it could play a part:

Patrick W. Barnes, a systems administrator at Cat-man-du, a technology services firm in Amarillo, Texas, said at least three different customers came into his shop with the same blue screen of death after installing Tuesday’s patches on their XP systems. Barnes said that on closer inspection, he found that each had been previously infected with a rootkit, a set of tools sometimes installed by malware that are designed to hide the presence of the infection on the host system.

Barnes said he traced the problem on each machine back to “atapi.sys” — a Windows storage driver(which lives in %System32\drivers\). When he sent the atapi.sys files that were on the customer machines up for a scan at Virustotal.com, the results suggested malware had injected itself into the system file.

Here’s the Virustotal report of the affected file.

It might be a good idea for anyone seeing this problem to give their system a quick scan with F-Secure’s Blacklight rootkit detector after removing the Windows Update patches and getting the system up and running.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Adrian Kingsley-Hughes is an internationally published technology author who has devoted over a decade to helping users get the most from technology.

Disclosure

Adrian Kingsley-Hughes

All opinions expressed on Hardware 2.0 are those of Adrian Kingsley-Hughes. Every effort is made to ensure that the information posted is accurate. If you have any comments, queries or corrections, please contact Adrian via the email link here. Any possible conflicts of interest will be posted below. [Updated: February 23, 2010] - Adrian Kingsley-Hughes has no business relationships, affiliations, investments, or other actual/potential conflicts of interest relating to the content posted so far on this blog.

Biography

Adrian Kingsley-Hughes

Adrian Kingsley-Hughes is an internationally published technology author who has devoted over a decade to helping users get the most from technology -- whether that be by learning to program, building a PC from a pile of parts, or helping them get the most from their new MP3 player or digital camera.

Adrian has authored/co-authored technical books on a variety of topics, ranging from programming to building and maintaining PCs. His most recent books include "Build the Ultimate Custom PC", "Beginning Programming" and "The PC Doctor's Fix It Yourself Guide". He has also written training manuals that have been used by a number of Fortune 500 companies.

Adrian also runs a popular blog under the name The PC Doctor, where he covers a range of computer-related topics -- from security to repairing and upgrading.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
69
Comments

Join the conversation!

Just In

Once again, Schmitz, all "in your own mind"...
Randy3147 15th Feb 2010
and please re-read the last part of Earthling's last post...it would do you a world of good:

http://en.wikipedia.org/wiki/Self_propaganda

Essentially, it is the act of telling one's self (or a group telling themselves) something that they consider to be true, or to convince themselves, with the unfortunate repercussion of their having no doubts. Because of what they do to themselves, they will go over every aspect of their side of the "argument" to prove to themselves that they are right, and will refuse to look at any alternatives.
0 Votes
+ -
Blacklight not compatible with Win7
donniebnyc666 12th Feb 2010
It doesn't run in WinXP mode either.
0 Votes
+ -
Oh, Noez!
Whyaylooh 12th Feb 2010
Blacklight doesn't run on Windows 7?! Then all is lost! How will people who install this patch that causes Windows XP to BSoD when this rootkit is installed be able to remove this rootkit so they can get their Windows XP machine running properly again, if they are running Windows 7?

Hm . . .
0 Votes
+ -
As I have said many times before, on a virus-free system, I have NEVER had ANY problems installing updates after doing a registry clean, which I always do immediately before installing updates.
0 Votes
+ -
Nope. Changed my mind. Raise your hand...
D.T.Schmitz 12th Feb 2010
...if you have grown tired of this.
Isn't this embarrassing?
It happens over and over and over again.
Do you wish you had another choice?

Step off of the Windows Infection treadmill and come over to safe, secure Linux.

May I recommend Ubuntu Linux 9.10?

It's FREE and you won't need to take any hardware upgrade on that XP machine of yours.

No activation required and make as many copies as you wish for Family and Friends.

Note that when you've installed Ubuntu, you'll not find any Anti-Virus software present. Not needed.

Ubuntu Linux 9.10: the safest operating system on the planet.

Dietrich T. Schmitz
Linux Advocate
0 Votes
+ -
I'd consider it....
Fark 12th Feb 2010
but I'm worried I'll become an effete elitist snob who cannot read a single ZDNet thread without commenting on the superiority of my OS.

If you, LinuxGeek, Mentalist, and the rest of the 'I can't help but comment on LINUX all the time' folks are a good sample of the Linux mentality, I'll pass. I'm less worried about having an infested PC than becoming a "Linux Advocate."

I'm not sure what's worse; the fact that you can't help but constantly spout off about your OS or the fact that the tone of almost all your posts implies that anyone who thinks differently is somehow less intelligent or willfully ignorant.

If you want to get people to try Linux, stop sounding like the kind of person we'd never want to deal with in real life.

(this is of course my humble opinion... I've been known to be wrong... and it's been a long day)
0 Votes
+ -
You DO realize what he's doing... He's trying to advertise himself as a consultant who will "save you from your own stupidity for running Windows."

Sorry Dietrich... Your cover is blown.
Now I know I have struck a nerve.

I feel at times like this that my dedication is paying off.

You have much 'negative energy' and I feel your pain, all the more so that I want to help you find your way to freedom of choice, thought.

A month, maybe two in your case, would be well-spent in Windows detox using Ubuntu Linux.

You would find your true self, enlightenment, happiness, new friends in the Linux community (me being one of them) who are here to help you in your most troubled of times.

Make a switch to Ubuntu Linux, the safest operating system on the planet.
  • Flagged
0 Votes
+ -
You just proved Fark right! Jerk.
Coogol 13th Feb 2010
nt
0 Votes
+ -
Talking To Yourself, Again?
The Mentalist 13th Feb 2010
Not a good sign.
Linux! Good work guys!!
0 Votes
+ -
Above average?????
The Mentalist 13th Feb 2010
You willingly choose the wrong way only to counter us and yet you claim to be above average?
0 Votes
+ -
138 IQ, Above Average! NT
AboveAverageJoe 13th Feb 2010
.
0 Votes
+ -
no hate
zelrikriando 13th Feb 2010
So it's ok to say that windows 7 is the best OS
and not ubuntu?

Fanboys are everywhere, Mac, Linux, Microsoft...
and now Google.

The best thing to do is to consider all options
and not randomly bash any of them.
0 Votes
+ -
Do you also insist on eating junk food because the healthy food advocates keep annoying you with the truth?
0 Votes
+ -
Re:
dvm Updated - 12th Feb 2010
You make some valid points regarding Linux. But if you read about Windows, you will found many security features available since Vista that protect the OS.
Kernel Patch Protection
http://en.wikipedia.org/wiki/Kernel_Patch_Protection
DEP
http://en.wikipedia.org/wiki/Data_Execution_Prevention
UAC
http://en.wikipedia.org/wiki/User_Account_Control
So Windows Vista / 7 is a lot better than XP securitywise.

Still, how important is security if you can't be productive. For example,
Does Linux have an Office suite as powerful/integrated as MS Office (Word, Excel, PowerPoint, Outlook, OneNote, Publisher, InfoPath, Visio).
Does Linux have a simpler / powerful application as iWork?
Does Linux have a easy to home suite as iLife?
Does Linux have an integrated suite as Adobe CS4?
Does Linux have AutoCAD, Revit, or similar application?
Here are some examples from applications people use everyday, and although there are "similar" OSS applications, there are very weak compared with the applications available for Windows or Mac. So, when the OSS are going to step up and focus in usuability and productivity?
Yes, I know, once you enter the unit you are in lock-down, but you'll find the accommodations during your stay comfortable.

There's ping pong, card playing, games, cross word puzzles, arts and crafts, big-screen tv, we show a movie every evening before your 8pm bedtime curfiew.

When you have gone through our two-month Windows detox program, I promise you, there will be new spirituality in your heart, a sense of connection to humanity experienced never before and you'll see the world and everyone in a new light with tolerance, love and respect.

That's Ubuntu.

Please come in and Welcome to our clinic!
  • Flagged
0 Votes
+ -
Re:
dvm 13th Feb 2010
First, you didn't answer the question I posted.
Second, you want me to detox from Windows
although in my post I talked about Windows and
Mac.

If you like Linux, good for you. Again,
security is very important and posted security
features that prove Windows is getting better.
Plus the long list of excellent desktop
applications. Same in Mac environment.
In Linux I have a very secure environment,
nothing more.
In that case, I prefer the secure / productive
Mac / Windows environment than the Secure /
nothing more environment.

my two cents...
0 Votes
+ -
Nonsense, there's tuxracer
crazydanr@... 14th Feb 2010
And the gimp, grep, awk, sed... the list of exciting, intuitive, and widely adopted desktop applications goes on and on.

Develop unreadable and cryptic scripts with Perl to show how clever you are with useless syntax!

Manage your system at a console instead of a UI, and perform other overly complex tasks to show how Windows users are "simpletons"!

Spend your free time reviewing the source code of all your applications and current kernel build, looking for bugs or security holes!

Spend the rest of your time in the basement online, posting how awesome linux is!
0 Votes
+ -
nt
0 Votes
+ -
Oh dear...
The Mentalist 13th Feb 2010
Talking to yourself again, no signs of improvement.

Your case is getting desperate.
0 Votes
+ -
That Linux is LESS safe than Windows is when it comes down to it, not more! Need I also remind you that Linux is still an "ALSO-RAN, ALSO-RAN YES IT IS! (sing this with me)" OS and THAT is the reason why no one is attacking it YET!

Get off the Lintard stuff and get SANE about Linux.... it's a good TECHIE operating system... but for the average user, it's still TOO FARKING COMMAND-LINE ONLY.... I've tried it very recently (Ubuntu) and it's still too command-line only.
0 Votes
+ -
Yes, I know, you can't leave once you enter because our facility is a safe house for people like you in need of help and compassion most.

Our facility will help you detox from Windows gradually over a period of two months.

When you've finished our program you will be given an Ubuntu User Certificate which says you are a member of the human race, a person with a heart filled with hope, love, and all of the possibilities that Ubuntu can bring in life.

So, please come to our clinic. I and our staff will be here to help you!

Ubuntu Linux: The safest operating system on the planet.

Dietrich T. Schmitz
Windows Detox Program Administrator,
Linux Advocate,
Legend in my Own Mind
  • Flagged
0 Votes
+ -
nt
As part of our program we can treat your condition as well.

The best part of your completion of our Ubuntu Linux for Human Beings program is that in addition to becoming a true member of the Human Race, no longer will you feel embarassed in public by the random blurt of inappropriate words.

At worst, you might find yourself shouting things like "Ubuntu is my guide" or "I got the whole Ubuntu in my hand" but gone will be those offensive statements and what will surface is pure joy in the spiritual knowledge that with Ubuntu Linux as your guide you can be God's servant to Humanity.

Come Coogol. Our clinic has a place for you.


Dietrich T. Schmitz
Windows Detox Program Clinic Administrator
Linux Advocate
Legend in my Own Mind
Yawn, your repetitiveness is boring. We already proved why you are wrong and since linux is not the subject here I'm marking your post as spam.
Yawn, your repetitiveness is also boring Loverock. Have you ever noticet how may refute your dribble and you come back with a logical reply? sad
will help your condition. I am sorry.
  • Flagged
0 Votes
+ -
Too bad it can't be done on you
The Mentalist 13th Feb 2010
There's nothing to remove, only air.
0 Votes
+ -
Typical comments
zelrikriando 13th Feb 2010
I like how the comments in here are productive.

100% personal attack
0% factual
0 Votes
+ -
And most of them are from the same person
AboveAverageJoe 14th Feb 2010
logging in with different user names! As if that would be hard to figure out.
0 Votes
+ -
Couple things D...
Cylon Centurion Updated - 12th Feb 2010
Businesses and users just can't hobble off Windows as DTS and Friends make it seem. It takes years, training, data migration/conversion, and money to make the switch. I'm willing to bet that any business that does, will also be spending the money for professional support that Canonical offers, rather than rely on the 1337 lounging around various spots on the Interwebz. So, after spending all that money to switch over, your still paying support costs, etc which make licensing fees look like nothing. It all boils down to what you need. Linux isn't an answer to everything IT.

Second, Many companies still (Sadly) rely on XP. MAJOR security upgrades have come along with Vista and 7 that make it more damn secure than XP will ever be. Drive-bys, rootkits, pop-ups are a thing of the past. Various comments by you and your gang make me think you haven't really touched base on these technologies yet. I implore you to check them out. If Zack Whittaker can go OSS for a day, then I'd like you to go proprietary for a day. Try it and see what happens. Also, many folks still rely on a lot of data and programs that would need to be converted, or re-written completely, further raising costs.
You like to mention about saving money, yet switching to Linux seems to want to cost more than simply upgrading to Vista or 7; While still costing money, this would most likely save you money in the long run. The learning curve is smaller, very little re-training is needed, minor compatibility woes, and security is plentiful.


OSS is great for certain things, yet in many lines of work, it just won't do. You know that, I know that, and the bloggers know that too. To may people OSS is that guy that sells you a cheap knock off purse or watch on the street corner, and until that changes, OSS will simply remain a very minor player on people's desktops.
and even then I am afraid you are not a good candidate for entering the Ubuntu "Linux for Human Beings" program.

Again, I am sorry.

Dietrich T. Schmitz
Windows Detox Program Clinic Administrator
Linux Advocate
Legend in my Own Mind
  • Flagged
0 Votes
+ -
D
Cylon Centurion Updated - 13th Feb 2010
ZDNet Mods, Ed Bott, and various other talkbackers have pointed out that you do nothing to contribute to the discussion. They're constantly deleted and marked as spam. Your talkbacks gain the attention of nobody. CIOs and CEOs are smarter than that to listen to your constant 2-dimensional rubbish and childish name calling. You're not in charge of their company/assets. You don't know their IT needs. Doesn't that mean anything to you? You can't seem to grasp the politics of IT, or you would understand why Windows is still number 1 with companies.

As I pointed out above there are a lot of factors to consider before switching, that people need to consider beforehand. Linux isn't all flowers and fairies as you claim, and switching certainly isn't either.

I implore other talkbackers to quit responding to this person.
0 Votes
+ -
Start self-imploring then
The Mentalist 13th Feb 2010
No one will listen to you unless you lead by example.
That kind of tirade is clearly a 'cry for help'.

Maybe our clinic can do something for you after all.

Under all of those complicated layers of cruft lies a "Human Being".

It's just a matter of time before we have a breakthrough.

In the meantime, please go to your room and recite 50 times the "I am an Ubuntu Human Being" prayer while you wait for the clinician.

You will get better.
  • Flagged
0 Votes
+ -
Do you ever shut up?
Randy3147 Updated - 13th Feb 2010
I use (and have come to love) backtrack, and have ubuntu, suse, xp, and 7 all on machines or vm's...pretty much just for academic purposes as I'm an admin and I feel I need to be well versed in multiple os's...

I like ubuntu...I like suse...for the, what, 10 years now? I've used XP, I liked it. I like 7. And, no viruses...on any of them. But, I know how (and how NOT) to use a computer.

but man, if i was a run of the mill user, and wasn't concerned about running multiple platforms, your constant badgering would turn me off of linux.

I don't use a Mac because #1 I can't justify paying 2-3x what a computer is worth for a Mac. #2 the Mac fanboy constant crap of "our stuff works" "our stuff is secure" is a turnoff. Plus, I know better and i know their product isn't worth it.

Dietrich, your attitude is really starting to come off as Mac Fanboy-ish. You saying Ubuntu is the most secure o/s on the planet and the constant badgering sounds just like all the Mactards who say "no vulnerability here" and "our stuff just works", meanwhile, there are holes in Macs, and Apple is issuing refunds for iMacs that "don't just work"...well, there are issues with linux, too. Just because someone switches to linux, champagne is not going to flow from the Heavens and cancer is not going to be cured...and the user is certainly going to have a problem at some point.

In short, if you really want people to consider the switch, lighten up. What's the saying? "You can catch alot more flies with honey than you can with vinegar?"
0 Votes
+ -
The door to our clinic is open and I have personally made a reservation for your stay.

If you've skimmed my comments to others here, the accommodations are wonderful, and we hope you will find the two month Windows detox program worth while.

Two months sounds long to be locked away, but I promise, you'll thank me when you leave as I hand you your Ubuntu "I am a Human Being" certificate during the graduation ceremony on your last day at our clinic.

So, pack your bags and be ready to enter our clinic and come out a Human Being filled with love and compassion for the possibilities that Ubuntu brings to Life.

Ubuntu Linux, the safest operating system on the planet.

Dietrich T. Schmitz
Windows Detox Program Clinic Administrator
Linux Advocate
Legend in my Own Mind
  • Flagged
0 Votes
+ -
wow...or just live up to the stereotype
Randy3147 Updated - 13th Feb 2010
Part of the problem of linux adoption is the stereotype of it's community members as being a$$hole$, you're only helping to confirm that prejudice.

but have at it, I guess you can't change who you are.
0 Votes
+ -
Do you know who you are? Maybe you didn't like my 'schtick'.

Call it a 'prop' if you will, but it serves the purpose to illustrate that Windows IT Folk have bolstered themselves with elaborate rationalizations for why they need to stay on Windows 7.

It's funny really because it is mostly untrue.

A month spent conducting use cases for IT would show anyone that Windows 7 is not essential and replaceable by low or no cost Linux.

I happen to be an Ubuntu Linux Advocate.
Feel free to challenge me on a point-by-point basis and you'll lose the argument every time.
There is a place for you in our clinic.

Get help.
But it can't be legal ANYWHERE in the world. You are too busy bashing Microsoft and Windows, and saying "Switch to Linux", that you're blind to the fact that PC GAMES ARE WINDOWS BASED! They won't run on Linux Distros.
Show me one game that is LINUX based, and I'm sure you's win $1,000,000 from Terry Fator, if not Bill Gates!
Read my comments to others above, and please don't fear when the automated Door lock clacks shut when you've entered our clinic compound.

You will be safe and the good news is that since you are a gamer, we have many many games for you.

Puzzles,
Connect the dots (one of my favorites)
Color Crayons,
Pencils and paper for you to write about how you feel,
Ping Pong,

Stuff like that will fill much if not all of your time during a two-month rigorous Windows Detox Program.

At the end on your last day, I will be present to shake your hand at Graduation ceremonies and look into your eyes and say: "Welcome to the Ubuntu Human Race".

So, please, I've personally reserved a room for you here at the clinic. Please come in.

Dietrich T. Schmitz
Windows Detox Program Clinic Administrator
Linux Advocate
Legend in my Own Mind
  • Flagged
0 Votes
+ -
Step onto the update treadmill
Earthling2 13th Feb 2010
Ubuntu Linux: patch-a-day treadmill:
105 vulnerabilities in 33 advisories
http://secunia.com/advisories/product/28063/?task=advisories

While you're on it, don't forget to patch the latest and greatest version of OO.o...:
http://secunia.com/advisories/38568/

Hearing you talk about Windows being insecure feels like you're living a decade or two ago when Linux had command-line interface or had to recompile the kernel to reconfiture the system.

In Vista and Win7 the users do not have to run as administrators and have many additional features built into OS and runtime to protect against malware.

However, I sincerely wish desktop Linux gained an additional share of users... No, wait... even if it doubles or quadruples its share, it won't help to get a significant portion of XP users off an insecure OS; neither will it shift the focus of malware creators: simply, there would still be no return on investment.

Thanks anyway, you're a dedicated evangelist.
I have personally reserved a room for you Earthling2, possibly the most challenging patient our clinic will come into contact with.

But I am always hopeful, yes, you need not worry when the entrance Door latches shut, your stay will be filled with many fun activities and even though you will feel some pain from Windows Detox, it will recede and each day your layers of Windows cruft will peel away to reveal the true Human Being inside.

A Human Being with tolerance, compassion and love for others, an Ubuntu Linux Human Being I promise you will be as I hand you your certificate on Graduation Day that says: "I am an Ubuntu Linux Human Being."

I look forward to that day Earthling2, so please come to our clinic and find your true self.


Dietrich T. Schmitz
Windows Detox Program Clinic Administrator
Linux Advocate
Legend in my Own Mind
  • Flagged
0 Votes
+ -
This is hardly comforting news!
Zogg 12th Feb 2010
So the reason that an update causes BSODs is because the box has already been firmly rooted?!

Excuse me, but that sounds like a doctor telling a patient that s/he won't probably won't die of lung cancer because s/he is already suffering from bowel cancer!

Thank you, but no. I can do and am doing without nonsense like that!
0 Votes
+ -
How?
Lerianis10 12th Feb 2010
By never going on the internet, or never going on the internet WITHOUT ANTIVIRUS AND FIREWALL!
0 Votes
+ -
Eh? How "what"?
Zogg 13th Feb 2010
Your response makes no sense, since you can't post on ZD-Net in the first place without Internet access!
0 Votes
+ -
and please re-read the last part of Earthling's last post...it would do you a world of good:

http://en.wikipedia.org/wiki/Self_propaganda

Essentially, it is the act of telling one's self (or a group telling themselves) something that they consider to be true, or to convince themselves, with the unfortunate repercussion of their having no doubts. Because of what they do to themselves, they will go over every aspect of their side of the "argument" to prove to themselves that they are right, and will refuse to look at any alternatives.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix