Jump to content

A month or two ago Malwarebytes found a Trojan and now nothing works.

Recommended Posts

Around 2 months ago Malwarebytes said it detected a Trojan in my drivers. Malwarebytes has been reliable in the past, so I had it remove the thing after it was quarantined.

Shortly after I did so my games started crashing due to "Video Driver stopped responding and has recovered" and D3D Device missing errors. My PC has also gotten a black screen and has had loud, unpleasant noise transmitted through my headphones, which can't be fixed without hitting the reboot button. Doing so only fixes the problem temporarily.

At this time I can't run any games without them crashing due to the various driver-related errors. I can still watch videos and surf the net as desired.

I have run multiple scans with Malwarebytes, Avast, tried ADWcleaner and they haven't found anything since the Trojan. I have uninstalled and reinstalled Windows, tried to format my drive using Dban, and reinstalled the video and Ethernet drivers. A few minutes ago I ran a scan with Farbar Recovery Scan Tool (FRST)  since it was recommended in another thread and it seems to have found something. The problem is I have no idea what to do to fix it. I will attach the log files I mentioned to this post.  I would greatly appreciate any help you can provide.



Edited by Demonlord
Link to post
Share on other sites

  • Root Admin

The computer does not appear to be infected. There are quite a few errors in the logs, most being repeats of Windows Search Index which is broken.

You have some hardware devices that are not installed properly too. In some cases if you install all the Windows updates including the "other software" by Microsoft it can find and update some drivers, but not all of them. 

==================== Faulty Device Manager Devices =============

Name: Ethernet Controller
Description: Ethernet Controller
Class Guid: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Then these errors

==================== Event log errors: =========================

Application errors:
Error: (11/19/2017 03:26:43 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:43 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.

Context: Windows Application

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:43 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:43 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

	Element not found.  (HRESULT : 0x80070490) (0x80070490)

Error: (11/19/2017 03:26:42 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:42 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.

Context: Windows Application, SystemIndex Catalog

	The content index database is corrupt.  (HRESULT : 0xc0041800) (0xc0041800)

Error: (11/19/2017 03:26:42 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:42 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index.

	The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (11/19/2017 03:26:42 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.

	0x%08x (0xc0041800 - The content index database is corrupt.  (HRESULT : 0xc0041800))

Error: (11/19/2017 03:26:42 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (860) Windows: Error -1811 occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00006.log.



System errors:
Error: (11/19/2017 03:53:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The NVIDIA LocalSystem Container service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 6000 milliseconds: Restart the service.

Error: (11/19/2017 03:53:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The NVIDIA Display Container LS service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.

Error: (11/19/2017 03:47:00 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.

Error: (11/19/2017 03:46:59 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.

Error: (11/19/2017 03:46:59 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.

Error: (11/19/2017 03:41:37 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.

Error: (11/19/2017 03:41:37 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.

Error: (11/19/2017 03:41:37 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.

Error: (11/19/2017 03:26:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (11/19/2017 03:26:43 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The Windows Search service terminated with service-specific error %%-1073473535.


I can try to assist you in getting the computer to work correctly, but it's not due to an infection. You have a new installation of Windows which has no bearing on any previous installation of Windows.

Let me know if you'd like me to try to assist you in fixing your installation of Windows. There is no promise that we can get it working correctly, but we'll try.




Link to post
Share on other sites

Worth a shot I suppose. It certainly beats building a new PC from scratch.


I'm not terribly concerned about the Windows Search nonsense. Odds are that was from my use of CCleaner to remove old MS Search files. I've also tried to delete the old Ethernet drivers that came with my parts and install new ones from Intel's website. It seemed to work for 1 day, then the problems with the Nvidia drivers crashing returned.

I am not going to be installing drivers via Windows Update. I've learned the hard way that doing so does more harm than good. But if you have any other ideas, I'm open to suggestions.

Link to post
Share on other sites

  • Root Admin

You're living in the past. If you don't want to install the Windows updates then you might as well switch over to Mac or Linux your Windows computer is always going to have issues without those updates. Almost all software nowadays uses .Net installers that also rely on updates, etc. There are hundreds of security issues fixed by those updates too.



Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.