About Steve Schardein

The owner of the website!

Disk corruption, LPM, and the iaStor.sys factor

Recently, I took delivery of a sick laptop where the customer had complained of instability and general slowness of operation, as well as system errors of various types. He was relatively tech-savvy and had attempted some repairs on his own.

Anyhow, after some serious chkdsking and system file repairs, I was left with a system that misbehaved rather curiously on a regular basis. Any time significant disk access was required, the system would hang for what seemed to be an indefinite period of time, prompting me to perform a hard reboot. It was very frustrating indeed.

Event Log errors pointed to a possible problem with iaStor.sys, the Intel disk driver.

This customer did not have Intel Matrix Storage Manager of any version installed, and Windows Update declared the drivers up to date. Intel’s automated driver update utility also cleared the system without any recommendations.

Intel Rapid Storage Technology

However, having noted the driver date of 2006, I decided in desperation to update the disk driver. The newest version of the driver is bundled with the new version of Matrix Storage Manager, which has been renamed to Intel Rapid Storage Technology [download here]. I first downloaded and installed this.

Next, I noted problems reported by users of the Intel drivers with older SATA drives, apparently related to Link Power Management. Although the new drivers reportedly correct this by disabling LPM on these drives, I don’t entirely trust Intel’s resolution, as the registry entries still indicate that it is enabled. There’s an easy fix for this also:

  1. Open Regedit.
  2. Navigate to HKLM\SYSTEM\CurrentControlSet\Services\iaStor\Parameters\PortX
    (where X is any number representing the port of each installed drive)
  3. Change the Value of LPMDSTATE from 1 to 0 for each key.
  4. Reboot the PC.

Upon the completion of these steps, the problems were resolved, and disk access on the machine was much faster (not to mention reliable). A number of other repairs were still necessary following this thanks to the aftermath of the disk corruption (such as additional system file repairs, software install problems including .NET Framework issues, and deep-seated MS Office issues), but after all of the repairs were complete, the PC was working like new again.

If you’re looking for computer help in the Louisville area, look no further.  Call me today and get it done right!

TDL4

In keeping with tradition, this year has seen a great number of TDSS (Win32/Alureon) rootkit infections, many of which go undiagnosed by the average tech. Although the numbers have dropped off some, the difference now is that those who are infected face a much more difficult diagnosis, as TDSS (a.k.a. Win32/Alureon) has continued to evolve.

The latest of these iterations is TDL4 (referred to here as DOS/Alureon), which manages to infect the MBR, as well as in some cases, a kernel-mode driver. This technically classifies it as both a bootkit and a kernel-mode rootkit (although theoretically these are wholly separate infections), making detection and removal extremely difficult and risky.

Even worse is the fact that TDL4 stores its primary rootkit code in an encrypted virtual file system. In cases where a combination infection is present, if the bootkit is removed, the kernel-mode rootkit can seemingly resume activities regardless.

Symptoms and diagnosis

The purpose of TDSS is to provide control over an infected PC so that it can be administered by an attacker (generally, a customer of the malware authors), who can then use the PC for whatever they choose: generation of web page hits, advertising, spam, or information theft.

The primary symptom of a TDSS infection has not changed: most often, the infected computer will redirect internet searches to pages of its own choosing. The mechanism behind this works on the HTTP protocol level; typically, the infected computer’s network traffic is also routed through a fake network proxy which actually redirects all network application traffic first through the rootkit. Attempts to remove this proxy setting will, of course, be reversed if the rootkit is not first dealt with.

One way to diagnose whether or not a system is under the control of TDL4 is to open a Command Prompt and type diskpart, followed by lis dis. If you receive the response there are no fixed disks to show, it is likely you are dealing with a TDL4 rootkit.

A wealth of utilities exist which claim to be able to diagnose and remove this threat. Most of them work quite well, but all of them are risky. Since TDSS is updated on a very regular basis, new variants adjust their strategies. As a result, running one of these utilities without a full system drive image can occasionally result in an unbootable computer. The only way to correct this if it occurs is to find the offending patched system file from offline and replace it with a known good copy.

Personally, I have written a script to search for patched system files and replace them automatically to ensure I do not miss any kernel-mode rootkits when suspected.

My most recent encounter

Although I generally still encounter TDSS on a weekly basis, the most recent version of the infection I saw was a combination of the TDL4 bootkit and the TDL3 random system driver rootkit. It was not clear whether the TDL3 rootkit was still active in any way following the TDL4 infection; naturally, I didn’t allow it to stick around long enough to find out.

Regardless, the bootkit was first removed, after which the system file, isapnp.sys in this example, was replaced offline with a known good copy (in this case, found in the computer’sdllcache folder). Afterwards, I removed the conventional fake network proxy to restore internet connectivity, as well as cleaned up some NTFS mount points which were probably left by another unrelated infection (possibly the max++ rootkit from last year).

And, of course, the final step was to kill a boring old rogue antivirus application that just wouldn’t go away with TDSS’ protection behind it. Good riddance!

If you’re looking for computer help in the Louisville area, look no further.  Call me today and get it done right!

When Last Known Good Configuration fails

Sometimes when things go wrong, booting into Windows becomes difficult. As a tech, I often run into situations where the aftermath of an infection or a severe system file corruption prevents me from reaching the Windows desktop on a troubled PC.

My first step in such situations now is simple. I boot to a remote operating system of my creation, open up the system32\config directory, and copy the registry hive files to a backup folder inside of the config folder. The following files, of course, are the registry hives:

  • SAM
  • SECURITY
  • SOFTWARE
  • SYSTEM
  • DEFAULT

Once these files have been backed up, I navigate to any recent backup of the hives in the config folder (most often the one in the  RegBack subfolder will work) and simply copy those same files from that folder directly into the config folder. This essentially replaces the registry hives with older, working copies of those hives.

On XP machines, it’s a bit more complicated.  You’ll have to actually manually navigate into a restore point folder and copy the backup hives from there.  These are pretty easy to get to, however.  Look for the %SYSTEMDRIVE%\System Volume Information folder, and find a recently-dated _restore{GUID}RP#\snapshot folder inside it (the “RP” indicates it’s a restore point).  In this folder, simply copy the five hive files to the system32\config folder and rename them to match the hive files you removed above.

Generally, once this is complete, the PC is once again bootable. I highly recommend starting in Safe Mode next, however, as some of the drivers (whether filesystem or device) may not be accurately catalogued after this procedure. From there, repairs can be carried out to correct any remaining issues with startup applications or drivers.

It isn’t technically necessary to replace all of the hives to correct boot problems, but it’s good practice.

If you’re looking for computer help in the Louisville area, look no further.  Call me today and get it done right!