Windows 10: PC running slowly after BSOD, rootkit/malware suspected

Discus and support PC running slowly after BSOD, rootkit/malware suspected in Windows 10 BSOD Crashes and Debugging to solve the problem; Hi everyone absolute newbie here So just this day i was working on my thesis and i had to use a friend's flash drive cause our files were in there,... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by HootenannyMagic, Aug 19, 2017.

  1. PC running slowly after BSOD, rootkit/malware suspected


    Hi everyone absolute newbie here

    So just this day i was working on my thesis and i had to use a friend's flash drive cause our files were in there, so
    i scanned it thoroughly first with Malwarebytes and Avast, and it showed no viruses.

    But after i finished my work and i started scanning my own computer with AV and aswMBR, aswMBR crashed and i was shown a bluescreen with an error CRITICAL_STRUCTURE_CORRUPTION.
    I had absolutely no clue that it would happen.

    The results with WhoCrashed were:



    On Sun 8/20/2017 3:48:04 PM your computer crashed
    crash dump file: C:\WINDOWS\Minidump\082017-32578-01.dmp
    This was probably caused by the following module: aswmbr.sys (aswMBR+0x1569)
    Bugcheck code: 0xC4 (0xF6, 0x1C8, 0xFFFFE00190B97080, 0xFFFFF801246D1569)
    Error: DRIVER_VERIFIER_DETECTED_VIOLATION
    Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
    A driver references a user-mode handle as kernel mode. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: aswmbr.sys .
    Google query: aswmbr.sys DRIVER_VERIFIER_DETECTED_VIOLATION

    On Sun 8/20/2017 2:10:10 PM your computer crashed
    crash dump file: C:\WINDOWS\Minidump\082017-23421-01.dmp
    This was probably caused by the following module: ntoskrnl.exe (nt+0x1429F0)
    Bugcheck code: 0x109 (0xA3A01F59BFF764F1, 0xB3B72BE01278371E, 0xFFFFD00173A8D930, 0x2)
    Error: CRITICAL_STRUCTURE_CORRUPTION
    file path: C:\WINDOWS\system32\ntoskrnl.exe
    product: Microsoft® Windows® Operating System
    company: Microsoft Corporation
    description: NT Kernel & System
    Bug check description: This indicates that the kernel has detected critical kernel code or data corruption.
    This might be a case of memory corruption. More often memory corruption happens because of software errors in buggy drivers, not because of faulty RAM modules.
    The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

    On Sun 8/20/2017 2:10:10 PM your computer crashed
    crash dump file: C:\WINDOWS\memory.dmp
    This was probably caused by the following module: ntkrnlmp.exe (nt!KeBugCheckEx+0x0)
    Bugcheck code: 0x109 (0xA3A01F59BFF764F1, 0xB3B72BE01278371E, 0xFFFFD00173A8D930, 0x2)
    Error: CRITICAL_STRUCTURE_CORRUPTION
    Bug check description: This indicates that the kernel has detected critical kernel code or data corruption.
    This might be a case of memory corruption. More often memory corruption happens because of software errors in buggy drivers, not because of faulty RAM modules.
    The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



    So i searched it up and it appeared that the others had rootkits while experiencing the same problem. I checked with FRST,DDS GMER, and RogueKiller on safe mode and GMER had no problems,Roguekiller just detected YTD downloader as an adware but i've been using it for months now and i have no problem with it.
    (FRST logs are attached)
    The thing is i still don't know the cause of that extremely random BSOD cause all i did was write my documents, and i even reinstalled my graphics driver just to be sure.

    So far after the BSOD, everything on my desktop is laggy and slow, refreshing takes 2 seconds, opening files takes 2-5 seconds. but on safe mode everything seems to work fine.

    Any help would be appreciated cause i still don't know everything about these things *Sad.
    HUGE thanks. (and sorry if this is on the wrong forum)

    :)
     
    HootenannyMagic, Aug 19, 2017
    #1
  2. debba1 Win User

    Is Logger.js a harmful download?

    After it started popping up on my pc yesterday, I ran Malwarebytes anti-malware. It found 2 rootkits and removed them. Since then, I have not had any more popups.
     
    debba1, Aug 19, 2017
    #2
  3. Smorboll Win User
    Computer is running slow and Windows Defender won't start.

    I am uncertain where in Windows Defender you list your problem. Windows Defender scans your device for malware. If Windows Defender didn't provide you with anything, the scan must not have caught anything. If your device is running slowly and suspect malware,
    but cannot find the malware, I would suggest doing a complete reset of your PC.

    To reset your PC:

    • Press Windows Key and type Settings. Press Enter on your keyboard.
    • On the left-hand pane, choose Recovery.
    • Under Reset this PC, choose Get Started.
    • Then choose the Remove Everything* option to reset your PC and get it working right again.
    • *Please note this will remove ALL files on your computer. I would recommend not doing a backup, as you cannot be certain which files contain the malware and you could simply reinstall malware to your device after the reset.
     
    Smorboll, Aug 19, 2017
    #3
  4. Borg 386 Win User

    PC running slowly after BSOD, rootkit/malware suspected

    Malwarebytes comes with a rootkit scanner. I believe you have to select the option & then reboot for it to scan.

    Other scanners you could use:

    TDSSKiller

    PC running slowly after BSOD, rootkit/malware suspected [​IMG]
    Note When running TDSSKiller, launch the program, click on the blue text "Change Parameters" & check the box marked "Detect TDLFS File system." Click OK & then run the scan.

    Norton Power Eraser

    This scanner also includes a rootkit scan.

    Other options you could try are a refresh, reset or repair.

    Refresh Windows 10 Windows 10 Installation Upgrade Tutorials

    Reset Windows 10 Windows 10 Installation Upgrade Tutorials

    Repair Install Windows 10 with an In-place Upgrade Windows 10 Installation Upgrade Tutorials
     
    Borg 386, Aug 19, 2017
    #4
  5.  
    HootenannyMagic, Aug 20, 2017
    #5
  6. Can someone help me with this please?
    I seriously need this PC. I am already thinking of refreshing Windows, but i am too busy to reinstall all of my apps and my connection is seriously retarded.

    I've been scanning all day and nothing comes up on mbam, not even a single rootkit. Avast blocked GMER's setting so i cant click on system, sections etc. but it showed a bios64 entry in red.

    I dont know what i should be doing right now.
    Please help me.
     
    HootenannyMagic, Aug 20, 2017
    #6
  7. axe0 New Member
    Hi HootenannyMagic,

    You'll want to remove Avast while troubleshooting.

    Crashes are usually system specific, searching a BSOD error code shows only what others experienced which may not be the case for you. Out of hundreds of systems I've helped troubleshoot BSOD crashes, only a few were infected by something.
    The point, I doubt you have malware that's causing this.

    Follow BSOD Posting Instructions and upload the zip in your next reply.
     
  8. PC running slowly after BSOD, rootkit/malware suspected

    Hello! huge thanks for answering (sir).
    Sorry i had to prematurely assume that it was a rootkit...but i have the zip attached
    I know disabling Avast's shields arent enough but i dont know...
    I kind of figured it out though...
    I believed i was just too paranoid about the infected flash drive that i scanned with many antimalware/adware up to antirootkits and such, until it kind of interfered with Avast and caused the system to crash (at least thats what i hypothesized).
    Also, due to the paranoia, i have turned on Driver Verifier and forgot to turn it off, causing my pc to crash consequently with all the scanning.
    And i also observed that the BSODs only happened yesterday when i was busy scanning. And almost all of it blames the windows kernel (ntoskrnl.exe and ntkrnlmp.exe), and kwldifoc.sys.
    I still cant form a full conclusion, but i must blame my sudden paranoia.*Huh
     
    HootenannyMagic, Aug 21, 2017
    #8
  9. axe0 New Member
    You ran multiple rootkit scans from which can be said to be very good. They catch most, not all, rootkits. The chance you get any rootkit they don't/can't catch is very small (relatively spoken) and since the scans did not come with signs of infection I'd say your clean of rootkits.

    Please do the following

    • Download TFC from: TFC Download
    • Close ALL running applications as TFC will terminate them before attempting to clean up the temporary files.
    • Double-click on the TFC icon.
    • When the program starts, click on the Start button. TFC will terminate the Explorer process and all running applications and then begin the process of cleaning out all of your temp folders.
    • When done, press OK to reboot your computer and finish the cleanup.
    (copy/pasted from BleepingComputer)

    Please make sure that you remove Avast, it seems to have caused multiple of the crashes.
     
  10. axe0 New Member
    Before I forget, make sure that Windows is fully updated regarding feature updates.
     
  11. Bat 1 Win User
    OP might want to consider a fresh install without any pirated software and see if they still have the problem ?
     
    Bat 1, Apr 5, 2018
    #11
Thema:

PC running slowly after BSOD, rootkit/malware suspected

Loading...
  1. PC running slowly after BSOD, rootkit/malware suspected - Similar Threads - running slowly BSOD

  2. PC running slowly

    in Windows 10 Gaming
    PC running slowly: I'm on Windows 11 and for a while I haven't had any issues, but lately usually after I run Steam my computer has been slowing down like I'm out of RAM. When I eventually open Task Manager, which normally takes almost 70 seconds since my computer responds so slowly, it always...
  3. PC running slowly

    in Windows 10 Software and Apps
    PC running slowly: I'm on Windows 11 and for a while I haven't had any issues, but lately usually after I run Steam my computer has been slowing down like I'm out of RAM. When I eventually open Task Manager, which normally takes almost 70 seconds since my computer responds so slowly, it always...
  4. Suspected Malware In Startup

    in AntiVirus, Firewalls and System Security
    Suspected Malware In Startup: The program circled appears in my startup, it changes symbols making it difficult to find/search.. The Microsoft Safety Scanner Detects nothing. Only thing I could do is turn it off. Any help would be appreciated....
  5. Suspected malware

    in AntiVirus, Firewalls and System Security
    Suspected malware: Dear sir,Someone sent me a file on WhatsApp and when i opened this file it opened in OneDrive. After that i suspected, this person was trying to hack my mobile phone so i started to search for the file he sent me many times and i cannot find it! I'm trying to restore my...
  6. Suspected malware

    in AntiVirus, Firewalls and System Security
    Suspected malware: I was using kmplayer as my video player and when I scanned it in virustotal it showed there was virus in the app.So I deleted it.Now in appdata/local/Microsoft/windows there is a usrclass.dat file and it shows its type as kmplayer64.dat .Is it a malware?If it is how to delete...
  7. PC suddenly runs slowly.

    in Windows 10 BSOD Crashes and Debugging
    PC suddenly runs slowly.: I was playing a game on the Xbox app when suddenly the game starts running really poorly load times are longer,10 frames a second. I checked some games on Steam and they're running poorly too. I restarted my PC and I noticed that it takes longer to boot up now. I've got...
  8. Can I remove a RootKit malware?

    in AntiVirus, Firewalls and System Security
    Can I remove a RootKit malware?: Corrupted system files with a type of malware that even after system reinstall it is still in my system even without connecting the system to the internet, from what I gathered it is possibly a RootKit malware I don't know other types of malware that is hidden and still can...
  9. Stealthy Malware Suspected

    in AntiVirus, Firewalls and System Security
    Stealthy Malware Suspected: I suspect I may have some hidden malware/rootkit on my machine. Weird unexpected things happening on my PC. A few unexplained uninstalls and application launches. SFC and DISM scans all show everything fine. SFC scans always fix corruption after updates. The logs all look...
  10. malware and malwarebytes beta rootkit

    in AntiVirus, Firewalls and System Security
    malware and malwarebytes beta rootkit: Anyway to get the free malwarebytes beta anti-rootkit to scan a external hard drive for malware? https://answers.microsoft.com/en-us/protect/forum/all/malware-and-malwarebytes-beta-rootkit/87616022-f898-49ed-ad37-b5ab8ee7c27a