Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

KERNEL_DATA_INPAGE_ERROR BSODs


  • Please log in to reply
36 replies to this topic

#31 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 38,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:23 AM

Posted 28 February 2012 - 04:46 PM

IMPORTANT NOTE: Your scan log results indicate you are using keygens/crack tools.

The practice of using cracking tools, keygens, warez or any pirated software is not only considered illegal activity but it is a serious security risk.

Cracking applications are used for illegally breaking (cracking) various copy-protection and registration techniques used in commercial software. These programs may be distributed via Web sites, Usenet, and P2P networks.

trendmicro.com/vinfo

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...

Keygen and Crack Sites Distribute VIRUX and FakeAV

...warez/piracy sites ranked the highest in downloading spyware...just opening the web page usually sets off an exploit, never mind actually downloading anything. And by the time the malware is finished downloading, often the machine is trashed and rendered useless.

University of Washington spyware study

...One of the most aggressive and intrusive of all bad websites on the Internet are serial, warez, software cracking type sites...they sneak malware onto your system...Where do trojan viruses originate? One of the biggest malware distributors on the Internet are serial/warez/code cracking sites.

Bad Web Sites: Malware

When you use these kind of programs, be forewarned that some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, those sites are infested with a smörgåsbord of malware and an increasing source of system infection. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

I strongly recommend that you remove all cracks and keygens immediately to reduce the risk of infection/reinfection. If not, then we are just wasting time trying to clean your system. Further, other tools used during the disinfection process may detect crack and keygens so we need to ensure they have been removed.

Using these types of programs or the websites visited to get them is almost a guaranteed way to get yourself infected!!


The "Objects scanned" above says 481k files - but Norton scanned 935k files, and took 3.5 hours.


The speed and ability to complete an anti-virus or anti-malware scan depends on a variety of factors.
  • The program itself and how its scanning engine is designed to scan: using a signature database vs heuristic scanning or a combination of both.
  • Options to scan for spyware, adware, riskware and potentially unwanted programs (PUPS).
  • Options to scan memory, boot sectors, registry and alternate data streams (ADS).
  • Type of scan performed: Deep, Quick or Custom scanning.
  • What action has to be performed when malware is detected.
  • A computer's hard drive size.
  • Disk used capacity (number of files to include temporary files) that have to be scanned.
  • Types of files (.exe, .dll, .sys, .cab, archived, compressed, packed, email, etc) that are scanned.
  • Whether external drives are included in the scan.
  • Competition for and utilization of system resources by the scanner.
  • Other running processes and programs in the background.
  • Interference from malware.
  • Interference from the user.
-- Using two security scanning engines at the same time can cause each to interfere with the other, cause systems hangs, false detections, unreliable results and other unpredictable behavior.

-- If the screensaver, hibernation or Sleep Mode are not turned off before scanning, those features can sometimes have odd effects when attempting to resume normal mode.


Note: It is not unusual for an anti-virus or anti-malware scanner to be suspicious of some compressed, archived, .cab .jar and packed files because they have difficulty reading what is inside them. These kind of files often trigger alerts by security software using heuristic detection because they are resistant to scanning (difficult to read). This resistance may also result in some scanners to stall (hang) on these particular types of files or just ignore (skip) them. Certain files in the System Volume Information Folder like the Tracking.log (created by the Distributed Link Tracking Service to store maintenance information) have also been reported as a source causing some scanners to hang.



Complements of Quietman7
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

BC AdBot (Login to Remove)

 


#32 AustrAlien

AustrAlien

    Inquisitor


  •  Avatar image
  • Members
  • 6,772 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:11:23 AM

Posted 28 February 2012 - 05:00 PM

I think I'm just going to reinstall Windows. If I continue to get BSODs after that point, then I know for a fact that it's a hardware issue.

That sounds like the quickest and easiest way way to both trouble-shoot and/or fix your problem. Since you are pressed for time, I suggest that you go ahead with it.

I think the problem may well be malware (rootkit) related ... but cannot be sure at this stage.

==========================
BSOD BUGCHECK SUMMARY
................................................................
Loading Dump File [C:\CactusIsland\robot85_BC\Windows7_Vista_jcgriff2\022812-30825-01.dmp]
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Debug session time: Wed Feb 29 02:11:22.259 2012 (UTC + 11:00)
System Uptime: 0 days 17:46:15.147
Unable to load image \SystemRoot\system32\DRIVERS\amdxata.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for amdxata.sys
*** ERROR: Module load completed but symbols could not be loaded for amdxata.sys
Probably caused by : storport.sys ( storport!RaUnitScsiIrp+3ba )
KERNEL_DATA_INPAGE_ERROR (7a)
The requested page of kernel data could not be read in. Typically caused by
a bad block in the paging file or disk controller error. Also see
KERNEL_STACK_INPAGE_ERROR.
If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
it means the disk subsystem has experienced a failure.
Arguments:
Arg1: 0000000000000020, lock type that was held (value 1,2,3, or PTE address)
Arg2: ffffffffc000009d, error status (normally i/o status code)
Arg3: fffffa80059397c8, current process (virtual address for lock type 3, or PTE)
Arg4: 0000000000000000, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)
ERROR_CODE: (NTSTATUS) 0xc000009d - STATUS_DEVICE_NOT_CONNECTED
DISK_HARDWARE_ERROR: There was error with disk hardware
BUGCHECK_STR: 0x7a_c000009d
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_0x7a_c000009d_storport!RaUnitScsiIrp+3ba
Bugcheck code 0000007A
Arguments 00000000`00000020 ffffffff`c000009d fffffa80`059397c8 00000000`00000000
BiosVersion = F.07
BiosReleaseDate = 04/27/2010
SystemManufacturer = Hewlett-Packard
SystemProductName = HP G62 Notebook PC
................................................................
Loading Dump File [C:\CactusIsland\robot85_BC\Windows7_Vista_jcgriff2\022212-35115-01.dmp]
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Debug session time: Thu Feb 23 09:45:29.253 2012 (UTC + 11:00)
System Uptime: 4 days 9:45:55.001
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+34bce )
KERNEL_DATA_INPAGE_ERROR (7a)
ERROR_CODE: (NTSTATUS) 0xc00000c0 - This device does not exist.
BUGCHECK_STR: 0x7a_c00000c0
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: vmware-authd.e
FAILURE_BUCKET_ID: X64_0x7a_c00000c0_nt!_??_::FNODOBFM::_string_+34bce
Bugcheck code 0000007A
Arguments fffff6fb`40000098 ffffffff`c00000c0 00000000`1c2c8884 fffff680`00013000
................................................................
Loading Dump File [C:\CactusIsland\robot85_BC\Windows7_Vista_jcgriff2\021612-82056-01.dmp]
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Debug session time: Fri Feb 17 10:23:55.413 2012 (UTC + 11:00)
System Uptime: 0 days 0:01:05.301
Probably caused by : ntkrnlmp.exe ( nt!CmpLoadHiveThread+23a )
BAD_SYSTEM_CONFIG_INFO (74)
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x74
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_0x74_nt!CmpLoadHiveThread+23a
Bugcheck code 00000074
Arguments 00000000`00000002 fffff880`03030b20 00000000`00000002 ffffffff`c000003a
................................................................
Loading Dump File [C:\CactusIsland\robot85_BC\Windows7_Vista_jcgriff2\020312-20092-01.dmp]
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Debug session time: Sat Feb 4 12:34:18.767 2012 (UTC + 11:00)
System Uptime: 1 days 2:38:52.656
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
KERNEL_DATA_INPAGE_ERROR (7a)
The requested page of kernel data could not be read in. Typically caused by
a bad block in the paging file or disk controller error. Also see
KERNEL_STACK_INPAGE_ERROR.
If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
it means the disk subsystem has experienced a failure.
Arguments:
Arg1: fffff6fc400089b0, lock type that was held (value 1,2,3, or PTE address)
Arg2: ffffffffc00000c0, error status (normally i/o status code)
Arg3: 00000000ce8bc860, current process (virtual address for lock type 3, or PTE)
Arg4: fffff88001136000, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)
ERROR_CODE: (NTSTATUS) 0xc00000c0 - This device does not exist.
BUGCHECK_STR: 0x7a_c00000c0
DEFAULT_BUCKET_ID: CODE_CORRUPTION
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE_4096
Bugcheck code 0000007A
Arguments fffff6fc`400089b0 ffffffff`c00000c0 00000000`ce8bc860 fffff880`01136000
................................................................
Loading Dump File [C:\CactusIsland\robot85_BC\Windows7_Vista_jcgriff2\020112-38438-01.dmp]
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Debug session time: Thu Feb 2 11:26:33.407 2012 (UTC + 11:00)
System Uptime: 0 days 8:19:14.296
Probably caused by : wininit.exe
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
PROCESS_NAME: wininit.exe
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xF4_C0000005
FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_wininit.exe
Bugcheck code 000000F4
Arguments 00000000`00000003 fffffa80`06080b30 fffffa80`06080e10 fffff800`035cd300
................................................................

Edited by AustrAlien, 28 February 2012 - 05:08 PM.

AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#33 robot85

robot85
  • Topic Starter

  •  Avatar image
  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:23 PM

Posted 28 February 2012 - 05:12 PM

Cryptodan: I understand the risks associated with using those programs. But I've never considered rootkits or malware that just "sits" there behind the scenes (without showing any signs of infection). Thanks for the info. :)

AA: I will go ahead with the reinstall then. I already have all of my data backed up. I will make a new topic if I have any problems after this. Thank you both for your time and patience. :thumbsup:

#34 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 38,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:23 AM

Posted 28 February 2012 - 05:35 PM

The Random Blue Screens are an easy indication that there could be malicious activity going on behind the signs. If you know the risks of using keygens and other tools then why use them?
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

#35 robot85

robot85
  • Topic Starter

  •  Avatar image
  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:23 PM

Posted 04 March 2012 - 06:49 PM

*sigh*

I am back... again. I'm gonna make a new topic. Cheezus Christie. Reinstalling didn't fix the problem! Yup~! New topic then.

#36 AustrAlien

AustrAlien

    Inquisitor


  •  Avatar image
  • Members
  • 6,772 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:11:23 AM

Posted 04 March 2012 - 07:00 PM

I think you might do just as well continuing in this topic where the previous information is readily available. But ... it doesn't really matter. It's your choice: Which ever you prefer.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#37 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 38,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:23 AM

Posted 04 March 2012 - 07:24 PM

Sounds to me like its time to wither replace the motherboard or the CPU.
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users