Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Windows Patch Leaves Many XP Users With Blue Screens
slashdot ^ | 02/11/2010 | Slashdot

Posted on 02/12/2010 10:34:08 AM PST by zeugma

"Tuesday's security updates from Microsoft have crippled Windows XP PCs with the notorious Blue Screen of Death, users have reported on the company's support forum. Complaints began early yesterday, and gained momentum throughout the day. 'I updated 11 Windows XP updates today and restarted my PC like it asked me to,' said a user identified as 'tansenroy' who kicked off a growing support thread: 'From then on, Windows cannot restart again! It is stopping at the blue screen with the following message: 'A problem has been detected and Windows has been shutdown to prevent damage to your computer.' Others joined in with similar reports. Several users posted solutions, but the one laid out by 'maxyimus' was marked by a Microsoft support engineer as the way out of the perpetual blue screens."

Update: 2/12/2010:

Rootkit May Be Behind Windows Blue Screen

 "A rootkit infection may be the cause of a Windows Blue Screen of Death issue experienced by Windows XP users who applied the latest round of Microsoft patches. It appears that the affected Windows PCs had the rootkit infection prior to deploying the Microsoft patches. Researcher Patrick W. Barnes, investigating the issue, has isolated the infection to the Windows atapi.sys file, a driver used by Windows to connect hard drives and other components. Barnes identified the infection as the Tdss-rootkit, which surfaced last November and has been spreading quickly, creating zombie machines for botnet activity."


TOPICS: News/Current Events; Technical
KEYWORDS: bluescreen; bsod; lowqualitycrap; microsofttax; rootkits; windowsupdate
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-64 next last
So, for XP users, before you install any new updates, check for the rootkit with any AV scanners you may have. Since the rootkit has been identified and known to modify a specific file, "atapi.sys", I'd probably try to find out what the correct md5sum of the file should be as a quick way of determining if you have an issue with this update.

If you find the specified rootkit, I'd strongly advise saving your data, wiping the disk, and install from known good media.

1 posted on 02/12/2010 10:34:08 AM PST by zeugma
[ Post Reply | Private Reply | View Replies]

To: zeugma

bttt


2 posted on 02/12/2010 10:35:29 AM PST by bmwcyle (Free the Navy Seals)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Interesting - my dad updated his XpPro, went ok ... so???


3 posted on 02/12/2010 10:36:15 AM PST by SkyDancer (If you don't read the newspaper you are uninformed, if you do read the newspaper you are misinformed)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

I got nuked last Saturday by a Vista update. Lost almost everything.

Working on my new gaming build a little faster now.


4 posted on 02/12/2010 10:38:37 AM PST by RandallFlagg (30-year smoker, E-Cigs helped me quit, and O wants me back smoking again?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

I got it a few weeks ago. Hub fixed it since I don’t know how to do anything on a puter except turn it off and on. I thought it was from a game I had installed......oooops to the game provider for thinking they had a corrupted game.


5 posted on 02/12/2010 10:38:52 AM PST by Dawgreg (Happiness is not having what you want, but wanting what you have.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

6 posted on 02/12/2010 10:39:07 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
All part of the plan!
7 posted on 02/12/2010 10:40:31 AM PST by Jagman
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Good advice except most AV products will not detect rootkits.


8 posted on 02/12/2010 10:41:55 AM PST by NY.SS-Bar9 (Bread and Circuses)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
I use a resident antivirus, firewall and spyware scanner (three separate products - I'm leery of the all-in one approach) on my XP machines which are all still SP2.

I do all my internet access in a virtual machine (Sun Virtualbox).

I install MS patches only after they've been out for a few weeks and when I know that what they do is something that I want done on my systems.

Never had a problem yet (knock wood)

9 posted on 02/12/2010 10:44:01 AM PST by Notary Sojac ("Goldman Sachs" is to "US economy" as "lamprey" is to "lake trout")
[ Post Reply | Private Reply | To 1 | View Replies]

To: NY.SS-Bar9

Rootkits are nasty since you never really know if you are clean. It almost always call for a wipe and reload.


10 posted on 02/12/2010 10:44:27 AM PST by TSgt (I long for Norman Rockwell's America.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: NY.SS-Bar9

Just did an update on XP Pro and now have an invalid windows image error keep popping up.


11 posted on 02/12/2010 10:45:09 AM PST by sniper63 (Bang,Bang, Maxwell's Silver hammer........)
[ Post Reply | Private Reply | To 8 | View Replies]

To: NY.SS-Bar9

Ping


12 posted on 02/12/2010 10:45:21 AM PST by Truth is a Weapon (Truth, it hurts soooo good!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: zeugma

Do not let your system or Microsoft update your machine as a routine. I have about ten PCs and NONE of them allow updates.

If it ain’t broken, it don’t need another fix!


13 posted on 02/12/2010 10:45:44 AM PST by George from New England (escaped CT 2006; now living north of Tampa Bay)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Do not let your system or Microsoft update your machine as a routine. I have about ten PCs and NONE of them allow updates.

If it ain’t broken, it don’t need another fix!


14 posted on 02/12/2010 10:45:46 AM PST by George from New England (escaped CT 2006; now living north of Tampa Bay)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Notary Sojac

I’m always 100% patched and have my virus software current however don’t forget about java, flash, etc. updates.

I got nailed several weeks ago by a java exploit even with everything else 100% current.


15 posted on 02/12/2010 10:46:21 AM PST by TSgt (I long for Norman Rockwell's America.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: All

I think Avira’s free version includes a root kit scanner.

“Avira encounters this malware spreading by integrating the rootkit technology into the entire product range. Avira AntiVir PersonalEdition Classic is a basic protection that can be downloaded for free from: www.free-av.com.”


16 posted on 02/12/2010 10:46:53 AM PST by Jonah Johansen ("Coming soon to a neighborhood near you")
[ Post Reply | Private Reply | To 8 | View Replies]

To: George from New England

I swear. I only clicked once.


17 posted on 02/12/2010 10:47:06 AM PST by George from New England (escaped CT 2006; now living north of Tampa Bay)
[ Post Reply | Private Reply | To 14 | View Replies]

To: zeugma

I fail to friggin’ understand - Toyota is being raked over the coals because of a so-called “sticking gas pedal” which any reasonable driver would know enough to throw the car in neutral and turn off the key.

And this problem only affects what, one car in a million?

Yet Microsoft products for OVER TWENTY YEARS are rife with bugs, insecurities, problems, errors, unusable crap, ... and Microsoft executives are NEVER HELD ACCOUNTABLE!

This is pure Bull Ship!!!


18 posted on 02/12/2010 10:47:16 AM PST by FroggyTheGremlim
[ Post Reply | Private Reply | To 1 | View Replies]

To: George from New England
If it ain’t broken, it don’t need another fix!

Until you hit an infected webpage and get owned because you didn't install that zero day update...
19 posted on 02/12/2010 10:47:23 AM PST by TSgt (I long for Norman Rockwell's America.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: SkyDancer
Interesting - my dad updated his XpPro, went ok ... so???

Well, that probably means that at least he doesn't have this rootkit. :-)

20 posted on 02/12/2010 10:48:31 AM PST by zeugma (Proofread a page a day: http://www.pgdp.net/)
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-64 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson