ok guys so I own a small business and my server runs a sql server. Randomly thursday my software started crashing every two minutes. we had no idea why or what was going on at first. So I used to much more avid into windows back in the xp days and before. I kinda switched to mac and haven't messed with newer windows. I actually just picked up a win 8 surface pro to use for tuning trucks and quickbooks.
So as I've looked at it at first ive though malware. Cause it would stay open in safe mode but not in reg mode. And my software wont run in safe mode so can't backup my data. So I've scanned with windows malicious software tools, I've scanned with pcmatic from pc pitstop as we use it for used laptops we sell and works relatively well. Tried iola which works rather well there system mechanic. So far the windows tools found 4 malware which were according to all scans removed. Then if i go to certain settings or windows update or such it shuts off instantly. I figured its either malware, memory, a driver or registry error. I don't think its memory or i would think it would shut down the same in safe mode.
The error I get with windows update is just a straight crash
If I go to dell and go to the driver update tool i get "unable to install or run this application. This application requires your system to be updated to Microsoft common language runtime version 4.0.30319.0"
Also when the computer comes back up from its blue screen I get run dl error "there was a problem starting c:users/server/appdata/roaming/msrex.dll the specified module couldn't be found"
Second error was a run dl "there was a problem starting c:users/server/appdata/roaming/rcsnpa.dll the specified module could not be found."
The blue screen states technical information:
**** stop: 0x0000008e (0xc0000005,0x835c7487,0xb653f66c,0x00000000)
*** atport.sys - adress 835c7487 base at 835c1000, datestamp 4ce788e8
The trojans found since 5/10 was trojan:win32/medfos.x and medfos.b on the 11th was trojan:html/redirector.bb and two copies of that. At last scan nothing found anything else. There was one more program found when i put it into an external lightning jig on my mac clam found but i forgot what it was it was something trojan.something..
I have attached the rammon file and I'm going to use the driver utility to try and list the drivers. I really need this up online or I'm going to be loosing business fast and cash....