Go Back   TechArena Community > Technical Support > Computer Help > AntiVirus Software
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



bsod: attempt made to write to read only memory = rootkit

AntiVirus Software


Reply
 
Thread Tools Search this Thread
  #1  
Old 12-02-2010
Smurf
 
Posts: n/a
bsod: attempt made to write to read only memory = rootkit

First time came across this curious blue screen of death, on startup, before
windows logon, creating a reboot cycle. Did the obvious, checked memory,
checked hard drive, no joy, checked google, which suggested checking hard
drive and checking memory.

Thought i would just give a check to see if any rootkit activity was going
on (on questioning, it seems that a redirector was causing problems before
reboot cycle, sending users to different web addresses), loaded up mini xp
boot disk, went to system32/drivers noticed two recently changed *.sys
files, a random named file and an atapi.sys.

An infected atapi.sys it seems has been very busy of late, it is responsible
for a google redirector which is missed by both combofix and malwarebytes.
Did a search for previous copies of atapi.sys, got the most recent one,
deleted both the system32/drivers one and the one laying around in the dll
cache folder waiting to reinfect, and copied over the one from the sp
install folder.

Problem sorted, can get into windows and continue cleaning up system.

I was fortunate in picking up on the problem quite quickly, but you could
easily spend a long time trying to trace this little sod down, thought i
would give a heads up...


Reply With Quote
  #2  
Old 16-05-2011
Member
 
Join Date: Aug 2009
Posts: 3,728
Re: bsod: attempt made to write to read only memory = rootkit

Well, I do not feel qualified to deal with BSOD in Windows 7 yet, but I will be happy at least see your BSOD and see what I can see. I have no idea to analyze dump Windows 7 yet (XP crash dumps I can understand) and it would take to send some of the crash dumps and would be able to point you in a better direction. The two RAM sticks are identical, as purchasing a matched pair. Because RAM is usually the case, I've tried to pull a rope and run memtest. I also tested the RAM in a different computer.
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > AntiVirus Software


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "bsod: attempt made to write to read only memory = rootkit"
Thread Thread Starter Forum Replies Last Post
Only part of a Read or Write Process Memory request was completed error occur while installing new software Antton Operating Systems 4 01-04-2011 11:37 PM
Memory write read failure / Decreasing available memory koen* Hardware Peripherals 3 18-08-2009 07:55 PM
Attempted to read or write protected memory error ASTON Software Development 3 05-06-2009 11:00 AM
Stop:0x000000FC "an attempt was made to execute non-executable memory" Dietrich Operating Systems 3 23-02-2009 09:30 AM
How to toggle between read-only and read-write in Word 2007 Avogadro MS Office Support 2 13-02-2008 04:26 AM


All times are GMT +5.5. The time now is 09:00 AM.