Slashdot Mirror


Windows Patch Leaves Many XP Users With Blue Screens

CWmike writes "Tuesday's security updates from Microsoft have crippled Windows XP PCs with the notorious Blue Screen of Death, users have reported on the company's support forum. Complaints began early yesterday, and gained momentum throughout the day. 'I updated 11 Windows XP updates today and restarted my PC like it asked me to,' said a user identified as 'tansenroy' who kicked off a growing support thread: 'From then on, Windows cannot restart again! It is stopping at the blue screen with the following message: 'A problem has been detected and Windows has been shutdown to prevent damage to your computer.' Others joined in with similar reports. Several users posted solutions, but the one laid out by 'maxyimus' was marked by a Microsoft support engineer as the way out of the perpetual blue screens."

112 of 658 comments (clear)

  1. ha ha suckers!!! by gandhi_2 · · Score: 5, Funny

    first po

    Stop OxOOOOOOFC (OxB5FD7D64, Ox76F3E963, OxB5FD7CDC, OxOOOOOOO1)

    A problem has been detected and windows has been shut down to prevent damage to your computer.

    1. Re:ha ha suckers!!! by Anonymous Coward · · Score: 2, Interesting

      Oh God. WHY did you use the letter instead of the number? *shudder*

    2. Re:ha ha suckers!!! by Anonymous Coward · · Score: 5, Funny

      Please don't joke about this. I have been affected, and at the worst possible time, too. I have to submit my PhD dissertation tomorrow, and I don't know what the fuck I'm supposed to do now.

      I can't boot up, and I have one of those HP computers that has everything built into the screen, so I can't even take the hard drive out.

      I CAN'T GET MY FUCKING PHD DISSERTATION. I AM SO FUCKED.

    3. Re:ha ha suckers!!! by biryokumaru · · Score: 4, Informative

      It's not like the hard drive is bad. Just use knoppix or something. You're pretty dumb for someone getting a PhD. Maybe this is just the gods way of sending you a message.

      --
      When you're afraid to download music illegally in your own home, then the terrorists have won!
    4. Re:ha ha suckers!!! by Anonymous Coward · · Score: 5, Insightful

      What I don't get is why people don't bother backing up important things like that.

    5. Re:ha ha suckers!!! by Beardo+the+Bearded · · Score: 5, Informative

      First, take a deep breath. The most important rule is "Don't Panic".

      Next, you download a Linux distro with a LiveCD. Ubuntu's a little bloaty, but it's got a lot of drivers right out of the box. If you've got internet access, you should be able to do that. If not, then you'll have to contact a friend with access or do it from the lab. Grab a beer while you wait -- it'll be a while.

      Burn the liveCD and boot with that. You might have to edit your BIOS settings to boot from CD first. Choose the "try Ubuntu without making any changes to your computer" option. Once it boots up, you'll be able to access your hard drive, and most importantly, your dissertation. Print the fucking thing, email it to your gmail account, and while you're at it, email what you've got to your professor. Let him know that you're "having computer problems, so I'm sending what I could recover in the meantime." Remember that computers fail all the time so you have to keep copies of important papers on physically separate systems.

      You're apparently a smart enough guy to get a PhD, so you should be able to figure out how to navigate Ubuntu. It's basically the same as Windown, but with the bar on the top instead of the bottom. My daughter's six and she can use Puppy Linux.

      Actually, you could probably use Puppy. The whole OS is only 150MB, so it'll download in a much shorter time than Ubuntu. It's not quite as polished, but I've had good luck with it.

      --

      ---
      ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
    6. Re:ha ha suckers!!! by Anonymous Coward · · Score: 5, Funny

      first po
      Stop OxOOOOOOFC (OxB5FD7D64, Ox76F3E963, OxB5FD7CDC, OxOOOOOOO1)

      A problem has been detected and windows has been shut down to prevent damage to your computer.

      Look, if he was bluescreening he wouldn't bother to type "0x0000FFFF" He'd just say it.

      "Oooooooo FFFFFFFF..."

    7. Re:ha ha suckers!!! by david_thornley · · Score: 4, Funny

      AC didn't say what his or her major was. I'd expect different computer competencies from a Computer Science major and a French Literature major. Or, given that AC is on Slashdot, perhaps an Anthropology major.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    8. Re:ha ha suckers!!! by harrkev · · Score: 5, Informative

      Agreed.

      As long as you haven't turned on file encryption (only an option with XP Pro), you can easily recover everything. Do this:

      1) Go to a friend's computer. Download and burn a copy of your favorite linux distro (I use Ubuntu).

      2) Live-boot from the CD.

      3) Mount the hard drive.

      4) Insert your favorite USB storage device (make sure it is large enough).

      5) Copy ALL important files to the USB drive (probably safest to copy your entire user directory, if your USB drive is big enough.

      6) When done, re-format your hard drive and re-install XP.

      7) Update your system completely.

      8) Re-install all applications you need (office, etc.)

      9) Copy your important files off of the USB drive.

      Really, it is time-consuming, but I have had to do this exact same process for friends a bunch of times.

      As far as the PhD goes, go up to step 5, and then use the friend's computer to print everything. Do steps 6-8 some other day.

      --
      "-1 Troll" is the apparently the same as "-1 I disagree with you."
    9. Re:ha ha suckers!!! by interkin3tic · · Score: 4, Funny

      You're pretty dumb for someone getting a PhD

      I'm not sure if I should laugh at how wrong this is, or cry because of how wrong this is.

    10. Re:ha ha suckers!!! by alvieboy · · Score: 3, Insightful

      "The most important rule is "Don't Panic"."

      The second one: "Install Linux"

      (Douglas would be proud of this one).

    11. Re:ha ha suckers!!! by S.O.B. · · Score: 2, Informative

      Don't bother with a live CD like one of the other posters recommended. Try the System Rescue CD. It's a lot faster to download and has all the tools you'll need to get your dissertation off your computer.

      --
      Some of what I say is fact, some is conjecture, the rest I'm just blowing out my ass...you guess.
    12. Re:ha ha suckers!!! by DJRumpy · · Score: 5, Funny

      Well that and the fact that the fix is a bit easier that formatting and reinstalling. From TFA:
      I had the same problem. Since I didn't have time to identify which one of today's updates caused the problem, I removed them all and now my computer is back to normal.

      Follow these steps:

      1. Boot from your Windows XP CD or DVD and start the recovery console (see this Microsoft article for help with this step)

      Once you are in the Repair Screen..

      2. Type this command: CHDIR $NtUninstallKB978262$\spuninst

      3. Type this command: BATCH spuninst.txt

      4. Type this command: systemroot

      5. Repeat steps 2 - 4 for each of the following updates provided by FindMeFollowMe:

              * KB978262
              * KB971468
              * KB978037
              * KB975713
              * KB978251
              * KB978706
              * KB977165
              * KB975560
              * KB977914

      6. When complete, type this command: exit

      Your computer should restart and everything should be back to normal.

    13. Re:ha ha suckers!!! by element-o.p. · · Score: 4, Funny

      I'm sure there's a joke in there regarding LaTeX and safe computing somewhere...

      --
      MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
    14. Re:ha ha suckers!!! by nevillethedevil · · Score: 2, Interesting

      Actually this is about average for a PhD. I have seen so many lose several years worth of work because their HDD dies and they never backed up.

      --
      Be gone from my sight or prepare to feel my flaming wraith!
    15. Re:ha ha suckers!!! by snuf23 · · Score: 2, Informative

      In Windows XP the user folder is usually located in C:\Documents and Settings\username.
      In Vista and Win 7 it is usually C:\Users\username.

      Files specific to that user's accounts are stored under those directories such as Desktop, Documents etc.

      --
      Sometimes my arms bend back.
    16. Re:ha ha suckers!!! by Pentium100 · · Score: 5, Insightful

      Microsoft Windows is not a new product. If you don't know that it can't be counted on to work like a normal computer, that doesn't just mean you're not technical. It means you have been living under a rock for 20 years.

      Strange, under my rock, Windows XP/2003 work well, I rarely have to restart my computers and when I do it is usually because of a hardware problem, long power outage (long enough to discharge UPS batteries) or because I am installing some software that needs a reboot. I get bluescreens very rarely.

      for example:

      Current System Uptime: 28 day(s), 3 hour(s), 27 minute(s), 48 second(s)
       
      Since 2009.03.27:
       
                System Availability: 99.9270%
                        Total Uptime: 321d 11h:16m:42s
                      Total Downtime: 0d 5h:38m:22s
                      Total Reboots: 11
          Mean Time Between Reboots: 29.25 days
                  Total Bluescreens: 0

      Those 5 hours? Most of them were spent when I added more RAM, but had either a bad module or a bad slot, so I took that long to finally give up and disable 4 modules from BIOS, leaving 3GB (instead of 5GB what I wanted and 1GB of what was before). That was ~28 days ago. Then there were a few power outages and this PC was connected to a smaller UPS. IIRC only one of those 11 reboots was because the PC froze for some reason.

      OS: 2003

    17. Re:ha ha suckers!!! by BabyDuckHat · · Score: 5, Funny

      That's almost as user friendly as Linux right there.

    18. Re:ha ha suckers!!! by ignavus · · Score: 2, Insightful

      Why not use a Windows live CD like Bart PE rather than Linux. It's easier for the people who've only ever used Windows and the NTFS drivers come from Microsoft.

      Given that Microsoft were the ones to issue the problematic update in the first place, I don't think saying the NTFS drivers in a Windows live CD come from Microsoft is really any sort of recommendation.

      Except maybe to scream.

      --
      I am anarch of all I survey.
    19. Re:ha ha suckers!!! by PCM2 · · Score: 2, Interesting

      You should try Live Mesh.

      Not a troll! I am serious -- I use it all the time. I use it to sync files between several computers AND Microsoft's servers, so I have a backup of anything important "in the cloud," accessible by Web browser if I ever need it.

      --
      Breakfast served all day!
    20. Re:ha ha suckers!!! by aflag · · Score: 2, Interesting

      I'd say he's pretty much the avarage PhD student. Anyhow, the good thing about a PhD dissertation is that nobody really cares about it anyway. When I got to college I thought I'd see science in the making if watched presentations by PhD students. What a disillusion... It felt like I was in a party watching some dude showing off, the only difference is that the PhD student will use graphs instead of drinking straight from a keg. You can almost hear the guy saying "please aprove me!"

    21. Re:ha ha suckers!!! by trytoguess · · Score: 2, Insightful

      Intelligence, even extreme intelligence in something doesn't imply aptitude in all common things. I mean, what you think every person on slashdot is a well adjusted social individual?

    22. Re:ha ha suckers!!! by Stormwatch · · Score: 2, Interesting

      6) When done, re-format your hard drive and install Linux.

      Fixed.

    23. Re:ha ha suckers!!! by keeboo · · Score: 2, Insightful

      Hmm... I'll stay using Linux.
      It seems that Windows is not much user-friendly yet.

      It looks like an interesting OS, perhaps in 1 or 2 years I'll try Windows again.

    24. Re:ha ha suckers!!! by Sanat · · Score: 5, Informative

      Actually it is * KB977165 only that needs to be un-installed.

       

      --
      And in the end, the love you take is equal to the love you make
    25. Re:ha ha suckers!!! by keeboo · · Score: 3, Funny

      Microsoft Windows is not a new product. If you don't know that it can't be counted on to work like a normal computer, that doesn't just mean you're not technical. It means you have been living under a rock for 20 years.

      Strange, under my rock, Windows XP/2003 work well, I rarely have to restart my computers and when I do it is usually because of a hardware problem, long power outage (long enough to discharge UPS batteries) or because I am installing some software that needs a reboot.

      C'mon, don't be like that. You're ruining the moment.

      Be a nice guy and let we Linux/BSD/etc users laugh at the cost of your OS, okay?

    26. Re:ha ha suckers!!! by icannotthinkofaname · · Score: 4, Insightful

      You're pretty dumb for someone getting a PhD.

      Because "getting a PhD" == "being an expert in everything"

      Except for the part where it doesn't. It's more like "being an impressive expert in one field"

      Did you even bother to figure out what the AC's degree is in? How do you the AC should know how to deal with something like that happening?

      --
      Let q be a radix > 1. I am in ur base-q, killing 10 d00ds.
    27. Re:ha ha suckers!!! by Z34107 · · Score: 2, Informative

      A handy guide:

      /export/home => c:\users on Vista or c:\documents and settings on XP.

      /usr => c:\program files

      /dev => Roughly equivalent to \\.\PhysicalDriveN or \Device\blargh

      /etc => VERY roughly equivalent to c:\windows\system32

      --
      DATABASE WOW WOW
    28. Re:ha ha suckers!!! by PixetaledPikachu · · Score: 2, Interesting

      You should try Live Mesh.

      Not a troll! I am serious -- I use it all the time. I use it to sync files between several computers AND Microsoft's servers, so I have a backup of anything important "in the cloud," accessible by Web browser if I ever need it.

      I've been doing that with dropbox on my ubuntu box

    29. Re:ha ha suckers!!! by socceroos · · Score: 3, Interesting

      I've been doing that with dropbox [dropbox.com] on my ubuntu box

      I've been doing that with ubuntuone on my ubuntu box.

    30. Re:ha ha suckers!!! by westyx · · Score: 5, Funny

      Of course not. Same folder, different name.

    31. Re:ha ha suckers!!! by kimvette · · Score: 3, Informative

      I know you meant it as a joke, but single user mode (and "recovery console" equivalents on install disks) are far more capable than Windows' recovery console.

      --
      The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
    32. Re:ha ha suckers!!! by NatasRevol · · Score: 2, Funny

      Windows is cheap if your time is worth nothing!

      Depending on your install disc, amount of files & apps to install, this could take up to a whole day!

      --
      There are two types of people in the world: Those who crave closure
    33. Re:ha ha suckers!!! by Chris+Mattern · · Score: 2, Informative

      it would be very like Gnome to make this difficult or impossible,

      In fact, in Gnome, it works just like Windows: grab the bar (actually, Gnome calls it a "panel") and drag it to the screen edge you want it at. You can also have more than one of them, if you want; by default Gnome gives you two, on the top and bottom, but the right click menu on a panel gives you the options to add more panels or to delete the one you're right-clicking. Two works nicely since you can do more with a Gnome panel than a Windows bar; you can easily make your own quicklaunch icons, you'll generally have multiple menus on it (instead of one big Start menu) and it's where your Workspace Switcher lives (if only Windows had something that useful out of the box), in addition to doing absolutely everything the Windows bar does. It's all user-configurable, too.

    34. Re:ha ha suckers!!! by Anonymous Coward · · Score: 5, Funny

      My grandma is going to do this? Clearly, Windows is not ready for the desktop.

    35. Re:ha ha suckers!!! by xettera · · Score: 2, Funny

      Should have been writing your dissertation with Google Docs

    36. Re:ha ha suckers!!! by pz · · Score: 2, Interesting

      Assuming this isn't a troll --

      1. Sit. Down. Breathe.

      2. Go to the store and fill a shopping bag full of fatty snax, Doritos, Pringles, Kit-Kat bars, Coke, Red Bull, etc.

      3. Bring your computer and the bag to the university IT department and beg for help. Let them know that you don't care about the computer (because compared to N years of effort, one computer is nothing), just the contents of the hard drive.

      4. While the IT department is working on your computer, go to your departmental administrative office and talk to the secretary in charge of accepting doctoral dissertations. Beg for a one-day extension. Involve your advisor's secretary.

      5. Return to the IT department to retrieve your dissertation. Do whatever you were going to do to get it printed.

      6. Once everything works out, reward the people who saved your ass with more goodies and/or flowers.

      --

      Put my fist through my alarm clock with its ding-dong death inside my ear. - The Blackjacks.
    37. Re:ha ha suckers!!! by sillybilly · · Score: 2, Informative

      PhD stands for philosophiae doctor - teacher of philosophy.

      The following assumes there is a limited, finite mental capacity for humans:

      "Philosophers are people who know less and less about more and more, until they know nothing about everything. Scientists are people who know more and more about less and less, until they know everything about nothing." (quote from somebody smart)

      Therefore PhD in science is an oxymoron. Actually, no it's not. You can both know everything about nothing, and nothing about everything, at the same time. You can have limit(x->infinity)x*1/2x+1/2x*x=1, or infinity*0+0*infinity=1, a finite number.

    38. Re:ha ha suckers!!! by westyvw · · Score: 2, Interesting

      As a linux user, the reboot because you installed something is sure strange.....
      I usually measure the uptime in months or years, but whatever works for you....

    39. Re:ha ha suckers!!! by golden+age+villain · · Score: 2, Insightful

      Backup anyone?

    40. Re:ha ha suckers!!! by 1s44c · · Score: 2, Insightful

      I CAN'T GET MY FUCKING PHD DISSERTATION. I AM SO FUCKED.

      You can still get your data off but it might not be easy. Your local PC shop should be able to do it.

      People like me have been telling people like you not to trust windows for -DECADES-. You thought we were ignorant bigots and ignored us. Now you are suffering from the very problems we warned you about countless times. I don't mean to sound uncaring but you brought this on yourself.

    41. Re:ha ha suckers!!! by drsmithy · · Score: 2, Informative

      You lost me here.....windows has the equivalent of /home directories??

      Yes.

      I don't use windows that much [...]

      Clearly, since it's something that appeared in Windows around 12-13 years ago.

    42. Re:ha ha suckers!!! by vtcodger · · Score: 2, Insightful

      ***Install Ubuntu and live problem free***

      Ah come on. The 9.04 Ubuntu upgrade about four months ago -- Krackpot Kingfisher or some such -- did pretty much the same damn thing to a number of people. And some of the problems weren't especially easy to fix. (You ever tried booting a Linux PC with an empty menu.lst file and no kernel? Not as easy as you probably think) The major differences would be that Ubuntu users didn't pay money for the privilege of having their PC bricked. And that repairing a Unix PC is generally less painful than repairing a Windows PC.

      The problem is that it is quite impossible to test updates against every possible hardware and software configuration that might be in use. I'm sure that Microsoft and Canonical try and try hard. But impossible means just that -- impossible.

      The lessons, of course, are don't install updates until a few days after they are released, make sure that you have bootable media for your OS (if possible), and back up frequently. I learned that in 1963. Other people have been learning it ever since.

      This incident, BTW, is a warning. It is highly likely if not inevitable that sooner or later the Windows automatic update mechanism is going to shut down much of the world's infrastructure either because the kids in Redmond have screwed up, or because some sociopaths somewhere in Eurasia have hijacked the update mechanism and used to to download something really grim, or because some country that the Western powers are trying to bully decides to retaliate.

      --
      You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
    43. Re:ha ha suckers!!! by Pentium100 · · Score: 2, Informative

      No, you read it wrong.

      The current uptime was 28 days.

      The total up/downtime was used to calculate availability, which was ~99.92%. So, during that time(2009 03 27 - 2010 02 12), the computer was working 321 days (not continuously) and not working 5 hours (also not continuously) with a total of 11 reboots during that time which means average 29 days between reboots (even though most of those reboots were used all one after the other when fixing a hardware problem).

      I think this is pretty stable. As I said, only one reboot was because the PC froze (and as such could be blamed on Windows, I do not know the actual cause), others were because of a hardware problem, hardware addition or power failure, all of which cannot be blamed on Windows.

    44. Re:ha ha suckers!!! by paganizer · · Score: 4, Funny

      I've been doing that with "XCOPY" on my dos 6.21 box.

      --
      Why, yes, I AM a Pagan Libertarian.
    45. Re:ha ha suckers!!! by paganizer · · Score: 2, Informative

      Whoa.
      I just did a little research on this; KB977165, the apparent cause of this, is the "fix" for the recently reported "17 year old vulnerability", which (as far as I can tell) was nothing of the sort, but the NTVDM (MSA979682).
      The NTVDM is a "feature", not a bug; any exploit of it is something that was by design allowed to happen; Microsoft "patching it" is a Scary Thing.
      That we are seeing blue-screens from this is not surprising. it IS surprising that they are trying to play this off as a XP-only problem, since essentially every version of windows is reporting problems.

      --
      Why, yes, I AM a Pagan Libertarian.
    46. Re:ha ha suckers!!! by SharpFang · · Score: 2, Insightful

      Dropbox works on Linux.
      Ubuntuone doesn't work on Windows.

      No cross-platform support = showstopper.

      --
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    47. Re:ha ha suckers!!! by Jaruzel · · Score: 2, Funny

      No he wouldn't. Douglas was a Mac fan.

      -Jar

      --
      Together, We Can Make Slashdot Better. I Do NOT Mod ACs. - Check Me Out
    48. Re:ha ha suckers!!! by Anonymous Coward · · Score: 2, Funny

      Current System Uptime: 28 day(s), 3 hour(s), 27 minute(s), 48 second(s)

          Mean Time Between Reboots: 29.25 days

      Looks like it's going down very soon...

  2. Did you see the solution? by Cryacin · · Score: 5, Funny

    All I keep hearing in my head is:
    They put the update in, you take the update out!
    They put the update in, shake your laptop all about!
    "You do the hokey pokey and you uninstall the patch! That's what it's all about!"

    "ooooh... the windows bluescreen."
    "ooooh... the windows bluescreen."
    "ooooh... the windows bluescreen."
    "That's what it's all about!"

    --
    Science advances one funeral at a time- Max Planck
  3. Saw this last month by Anonymous Coward · · Score: 2, Informative

    I saw and fixed a similar issue in January. A particular KB had patched a .dll that was in fact rootkit infected, breaking the reference to some function call. Windows BSOD'd, claiming the whole partition was unmountable. Rolled back the KB in Recovery Console, sanitized the OS, and reapplied the KB. Problem solved.

    1. Re:Saw this last month by Dorkmunder · · Score: 5, Informative

      From the comments over a DShield on this topic http://isc.sans.org/diary.html?storyid=8209 it looks like this might be the case again

    2. Re:Saw this last month by Johnno74 · · Score: 2, Interesting

      Does the Windows update process, in fact, just naively apply patches to files that have the correct name and path, without verifying hashes or signatures, thus running a very high risk of breaking hard any file that had been slightly modified?

      Or was this some subtler and more complex situation, where the modified file itself was fine; but some tampered-with component was depending on the precise behavior of the modified file?

      Sounds like that is exactly what this is. The file being patched isn't infected, but the rootkit has some dependancy on the exact layout of this file, and when the file is updated by the patch the rootkit (accidently) causes a bluescreen. Possibly the rootkit tries to patch the in-memory image of this file, which messes things up.

      What I find really frightening about this situation is how widespread the rootkit that is causing this problem is. Most people have no idea they were infected. (and still do, they are blaming microsoft)
      MS is really gonna cop some flak for this one. Unfortunately this rootkit seems to be so stealthy that its damn hard to tell if the machine is infected until its too late and your machine won't boot.

      A machine that had been on our network has the patch yesterday and won't boot, could be some be _very_ interesting when we roll out the patch via SUS to the rest of the machines in the network and smoke out how many are really infected.

  4. Note to self: clone hard disk before rebooting . . by PolygamousRanchKid+ · · Score: 2, Insightful

    . . . my Windows XP updates get pushed, pulled or shoved down my throat . . . this sounds like an excellent reason to clone my hard disk before rebooting, and logging on to my company's network . . .

    --
    Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
  5. Liars! by interkin3tic · · Score: 5, Funny

    You know how I know they are lying? They are posting complaints online. We designed this patch -specifically- to stop online complaints about updates. They clearly haven't actually updated.

    -Bill Gates

  6. What? by dangitman · · Score: 5, Funny

    'I updated 11 Windows XP updates today...

    You updated your updates? You're doing it wrong.

    --
    ... and then they built the supercollider.
    1. Re:What? by Arthur+Grumbine · · Score: 4, Funny

      To be fair, his computer had just been pimped by Xzibit...

      --
      Now that I think about it, I'm pretty sure everything I just said is completely wrong.
  7. Need confirmation by dave562 · · Score: 5, Interesting

    An MVP poster in the thread claims that KB977165 causes the problem, and that the problem only occurs on computers that have been compromised by exploit code. The patch in question patches the NT kernel executable files.

    If it is true that only compromised computers blue screen then it's hard to fault Microsoft for their patch code choking when it stumbles across the exploit code.

    I wonder if they are going to push out an updated patch that at least performs some sort of sanity checking before attempting to modify the files. I doubt it. They'll just pass the buck and tell users that their computers were already hosed and that the BSOD is a "feature" and that they should have re-installed the OS anyway (because we all know that once your Windows box is pwnt, the only way to deal with it is full format and re-install).

    1. Re:Need confirmation by Hatta · · Score: 4, Insightful

      If it is true that only compromised computers blue screen then it's hard to fault Microsoft for their patch code choking when it stumbles across the exploit code.

      It's pretty easy to fault them for not taking a checksum before they patch to ensure that the file isn't modified. If it is, warn the user.

      --
      Give me Classic Slashdot or give me death!
    2. Re:Need confirmation by RobDude · · Score: 4, Insightful

      Sort of.....

      You can't really blame MS for a crash that happens because the .DLLs/code on someone's machine has been modified by a malicious 3rd party.

      But, you can expect an MS (or any other OS) to take appropriate actions to avoid patching a file that isn't exactly what is expected.

      What you'd really hope for, is that when a problem is detected during the update process (IE - Crap - this .DLL isn't the .DLL we expect. Something is wrong!' - instead of modifying the .DLL it would present the user with some meaningful information like, 'Hey - this patch failed. You probably have a virus....you should get that fixed'. Or something similar.

      It's possible that the patch took some reasonable efforts to ensure the patch would only be applied as expected; but I don't know. I do know that, even if it did, it didn't work.

      There is a world of difference between an 'infected' Windows machine that has some annoying pop-ups showing up every 15 minutes, but is otherwise functional, and a Windows machine that won't boot because of a recently installed patch.

    3. Re:Need confirmation by russotto · · Score: 5, Insightful

      There is a world of difference between an 'infected' Windows machine that has some annoying pop-ups showing up every 15 minutes, but is otherwise functional, and a Windows machine that won't boot because of a recently installed patch.

      Yeah. The owner of the machine would rather have the former... while everyone else on the Internet would rather they had the latter, as the former is probably sending out spam and trying to infect every other machine it can find as well.

    4. Re:Need confirmation by jedidiah · · Score: 3, Insightful

      I was thinking that perhaps mebbe they should have a backup copy of that pre-patched kernel somewhere and give you the option to boot from it as a failsafe.

      --
      A Pirate and a Puritan look the same on a balance sheet.
    5. Re:Need confirmation by bertok · · Score: 4, Informative

      If it is true that only compromised computers blue screen then it's hard to fault Microsoft for their patch code choking when it stumbles across the exploit code.

      It's pretty easy to fault them for not taking a checksum before they patch to ensure that the file isn't modified. If it is, warn the user.

      Microsoft patches are file-level, not delta-patches. They always overwrite complete files, and never try to modify files in-place.

      That's why their patches are so huge, if there's a systematic error in many related files, then they all need to be replaced in their entirety.

      It's a waste of bandwidth, but it's much more reliable.

      I suspect what happened here is that Microsoft replaced one of two related files, but the other file was modified by the root-kit, and the mixed versions don't work together any more.

    6. Re:Need confirmation by Rockoon · · Score: 2, Insightful

      This doesnt make sense.

      Even if the file was modified, over-writing it with a valid one will not cause a problem under normal operation.

      When the file is over-written, those modifications that you are thinking of are gone. The modifications can't come back from the grave as ghosts and cause a problem.

      The only way there can be a problem is if 'something else' is making an assumption about that file incorrectly, and that does not mean that the assumption is that the file has been modified. More likely the assumption that it will NEVER be modified, which leads to the likely conclusion that it was in fact never modified. The file was exactly as expected by the updater and no matter how many times or ways you run a hash on it, equal is equal.

      --
      "His name was James Damore."
    7. Re:Need confirmation by initialE · · Score: 4, Interesting

      It's bad news for Microsoft at so many levels -
      1. it's a 17-year-old bug
      2. The disclosure and proof-of-concept attack was done by Google, clearly not Microsoft's best friend
      3. Microsoft was forced to release a patch that is not fully tested
      4. The cure is worse than the illness
      5. Lots of windows users find out they have been compromised for how long? Nobody really knows!
      6. The only remedy now is to restore your computer to it's previous state, which means you carry on using your computer in it's compromised state

      --
      Starbucks, Harbuckle of Breath.
    8. Re:Need confirmation by Erikderzweite · · Score: 2, Insightful

      Good idea, besides, it's not like such thing hasn't been done by others before.

    9. Re:Need confirmation by PsychoSlashDot · · Score: 2, Interesting

      It's pretty easy to fault them for not taking a checksum before they patch to ensure that the file isn't modified. If it is, warn the user.

      You're both missing what's actually happening here.

      1} The "patch code" doesn't choke. The patched kernel does next reboot.
      2} The patch doesn't touch the infected file.

      The problem appears to be a compromised atapi.sys driver. Is it really reasonable for Microsoft's patch to the kernel to react gracefully to whatever corruption is present in that driver? I know the obvious is that Windows should fail gracefully on any fault, but really... we don't have any clue what's present in that file.

      Summary: patch patches the kernel. Kernel tries to initialize a compromised driver. BSOD.

      Extra stuff...

      I actually encountered such a machine this morning. This was pretty much while folks were realizing what was going on, before we collectively knew WHICH patch was responsible. I backed out the offending patch and got the system back up. I then found the box was WinXP Pro SP2, so I applied SP3. The SP3 install choked while examining the environment, saying that something had a handle on ATAPI.SYS Well, being a tech, I fired up some tools, found a system process had the handle, closed it, and let SP3 continue. I then patched up everything else. Finally, I reinstalled KB977165. Lo and behold, the system worked fine. So in hindsight I can see that yeah, something was funky about that file in particular. Malware or not, something wasn't right about it. For the record, the system in question did have current AV (Norton 360) and was behind a simple NAT router but the user did have admin rights. Zero other signs of infection.

      For all we know we're going to find out that this was actually some bull-crap DRM solution.

      --
      "Oh no... he found the .sig setting."
  8. Re:microsoft screws users again. Why is this news? by Anonymous Coward · · Score: 2, Insightful

    And people will still be ignoring it.

  9. Intentional? by Jawshie · · Score: 4, Insightful

    Well duh... How is Microsoft supposed to make any more money from you if they don't trash their old OS?

  10. Just close your eyes and chant by harris+s+newman · · Score: 4, Funny

    Windows costs less, is more secure, and superior to opensource OS's. And hope your boss hears you before your fired.

    1. Re:Just close your eyes and chant by Tetsujin · · Score: 5, Funny

      Windows costs less, is more secure, and superior to opensource OS's.

      And hope your boss hears you before your fired.

      Before my fired what?

      --
      Bow-ties are cool.
    2. Re:Just close your eyes and chant by ZarathustraDK · · Score: 5, Funny

      Before my fired what?

      Don't correct me, your fired.

      Regards
      you're Boss

      --
      If you quote this signature there'll be 72 copies of Windows ME waiting for you in Heaven.
    3. Re:Just close your eyes and chant by Noren · · Score: 3, Funny

      Woo Hoo! I'm boss!

      Now why are these gentlemen escorting me out of the building?

  11. Re:Remove automatic updates from your slipstream by Savage-Rabbit · · Score: 5, Insightful

    Here is a list of Microsoft stuff to remove from your XP slipstream:

    Automatic Updates (for reasons related to the article)
    Windows media player (including 6.4) because it downloads codecs at will.
    Accessibility Options (unless you need them)
    ClipBook Viewer (useless)
    Games
    Internet Games ...

    Long list, wouldn't it be simpler to just remove Windows XP in it's entirety from your PC and replace it with something else?

    --
    Only to idiots, are orders laws.
    -- Henning von Tresckow
  12. I always wait for a while by reboot246 · · Score: 4, Insightful

    I let Windows inform me about updates, and I choose when to download them and install them. If nobody else has any problems after a week or so, then and only then will I download and install the updates. I learned a long time ago not to trust anything from Microsoft.

    I'd like to thank all of you who beta tested the updates for me!

  13. Yay, no problems here! by HouseOfMisterE · · Score: 2, Funny

    I updated yesterday and haven't had any problems. I feel like I won the lottery!

  14. Re:Remove automatic updates from your slipstream by pluther · · Score: 3, Insightful

    But then how will I run Mass Effect 2?

    --
    If the masses can keep you down, you're not the Ubermensch.
  15. Re:I dont' HAVE a DVD or CD... it's a hard drive p by maxume · · Score: 2, Informative

    You can install the recovery console as a boot option:

    http://support.microsoft.com/kb/307654

    (You should have an I386 folder somewhere)

    It is more complicated for Vista and later:

    http://blogs.msdn.com/winre/archive/2007/01/12/how-to-install-winre-on-the-hard-disk.aspx

    --
    Nerd rage is the funniest rage.
  16. Re:Remove automatic updates from your slipstream by buswolley · · Score: 2, Funny

    Keep Pinball. I love that old game. Very well done, and might be the best Win software ever.

    --

    A Good Troll is better than a Bad Human.

  17. A quick fix by Bloom+Berg · · Score: 5, Informative

    from ars: Users in the thread have tracked down a fix, though it requires using a copy of the Windows disc (or for netbook users without an optical drive, a bootable USB drive with Windows on it): Boot from your Windows XP CD or DVD and start the recovery console (see KB307654 for help with this step) Type this command: CHDIR $NtUninstallKB977165 $\spuninst Type this command: BATCH spuninst.txt Type this command: systemroot Good luck. When complete, type this command: exit

  18. Resistance is futile. You will upgrade. by Animats · · Score: 3, Insightful

    Resistance is futile. You WILL upgrade to Windows 7 as instructed. We are in full control of your computer. Your computer will remain deactivated until you comply with our instructions. You have no alternative but to obey.

  19. Lucky Me by Penguinshit · · Score: 5, Interesting
    Fortunately I didn't get bitten by this. I would be devastated. Here's why:

    I am quadriplegic with a tracheostomy to breathe. That means no keyboard or mouse and no auditory input. I control my computer with eye movement (the only muscles I still fully control) tracked via infrared camera. Almost every system built to assist communication for people like me are built on top of WinXP. There is a Mac version I have heard of but AFAIK doesn't do full control like the one I use. There is no Linux availability at all (oh how I wish).

    So I am stuck. This system is my voice and my window to the world (travel is a major production requiring a team of assistants). it controls my immediate environment (tv, lights, etc.). It represents the last bit of independence I possess. It is a Tablet so "pop in the CD isn't so easy.

    I am very careful to avoid viruses and other malware (always was when i was healthy and Win32 was only a secondary OS for me then). But to be stabbed in the back would be utterly devastating to me. It could be weeks before I could get qualified help (Nerd Herd, etc. need not apply).

    1. Re:Lucky Me by Arccot · · Score: 2, Interesting

      Almost every system built to assist communication for people like me are built on top of WinXP. There is a Mac version I have heard of but AFAIK doesn't do full control like the one I use. There is no Linux availability at all (oh how I wish).

      Hmmm... that's pretty interesting. What's the software you normally use, and what's the device? There's tons of OSS developers out there just looking for a worthy cause.

    2. Re:Lucky Me by Penguinshit · · Score: 2, Informative

      Or I could be a longtime Linux user struck down by ALS.

      But you're probably right...

    3. Re:Lucky Me by Penguinshit · · Score: 2, Informative

      .It's the ERICA from Eye Response Technologies (now Dynavox).

  20. Obviously by bangthegong · · Score: 2, Funny

    This is how they solve the problem of backwards compatibility and get everyone onto Windows.Next or Win8 or whatever. Break all OSes prior to Win7 with "patches" thereby forcing everyone to PAY UP SUCKAS....

  21. Re:I dont' HAVE a DVD or CD... it's a hard drive p by BitterOak · · Score: 3, Informative

    You can install the recovery console as a boot option:

    http://support.microsoft.com/kb/307654

    (You should have an I386 folder somewhere)

    It is more complicated for Vista and later:

    http://blogs.msdn.com/winre/archive/2007/01/12/how-to-install-winre-on-the-hard-disk.aspx

    Nope. If you follow that link, you'll see you still need the Windows XP DVD to install the recovery console. Sadly, it was not uncommon for XP systems to be sold with no recovery console. My Toshiba laptop (I'll never buy another) did not come with a Windows XP DVD, merely a "product recovery disk" which wipes everything off the hard drive and does a fresh install. No recovery console available. Apparently there's a huge difference between buying a computer that comes with XP and buying a computer that comes with "XP installed."

    --
    If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
  22. Re:I dont' HAVE a DVD or CD... it's a hard drive p by maxume · · Score: 2, Informative

    As I alluded to in my comment, all you need is the I386 folder. It is mostly likely present at C:\I386.

    (I am typing this on a computer that did not come with an installation disc; I used the I386 folder to build one (with SP3 slip-streamed in). I have used that CD to install Windows into a VM.)

    --
    Nerd rage is the funniest rage.
  23. Re:LOL by Sir_Lewk · · Score: 3, Insightful

    No shit Sherlock.

    He was implying that the poster has only played those games, since he hasn't been using windows and those games are pretty famous for being cross platform.

    What I don't understand is why "you can't play games" is supposed to be some sort of universal knock against people who don't use windows. I never played games even when I did use windows, it's just not my thing.

    --
    "linux is just DOS with a UNIX like syntax" -- Galactic Dominator (944134)
  24. Windows cannot start again. So? by gestalt_n_pepper · · Score: 4, Funny

    You say this like it's a *bad* thing...

    --
    Please do not read this sig. Thank you.
  25. Re:microsoft screws users again. Why is this news? by Beardo+the+Bearded · · Score: 4, Insightful

    The problem with Linux is that it's inarticulate. Look at Ubuntu, which is arguably the easiest way to get someone to use Linux if they're from a Windows background.

    It works great, it's faster, and most configurations work right out of the box. if you have one of the few configurations that have been checked by the developers. (If you've got an ATI card like I do, Fuck You.) If you've got an older machine without one of the specific wireless cards detailed in document XR-122-65_rev_a_kernel26.6.1, you can with ndiswrapper and wpasupplicant. Rolling back the kernel version will also improve compatibilty on older systems. All of thse commands can be found on forums online, so there's lots of support for... ...what the FUCK are you talking about, Beardo? My machine USED to work, and now it doesn't and that's because I listened to you.

    Windows is dominant because they write and market to people who aren't technical users. Read that bolded sentence again. Apple is hauling up their maketshare for the same reason -- they are marketing to the vast majority of people that want a computer but didn't spend their childhood in the CS lab. My dad doesn't want to learn how to use a command line to set up the email. My wife, lead tech support for distance education for a College, didn't like Ubuntu because of the Flash problem.

    NOBODY GIVES A FUCK ABOUT PROPRIETARY DRIVERS. IF THE SHIT DOESN'T WORK THEN IT IS A LINUX PROBLEM. (Yes, even if it isn't.)

    Hell, MS still has their ridiculous search, when you could just drop to a shell and type "dir *foo*.ext /s | more" and be done in 10 seconds. But you see, if you weren't the kind of person who reads /., I just a) bored you and b) acted condescending and c) said something unintelligible.

    Linux is a spectacular tool, but like calipers, $30 ESD wirecutters, or my $200 soldering station, just aren't the right tool for the majority of people out there. If the developers get their heads out of their asses and learn how to market the software AND give the public what it wants, then and only then will Linux get its fair share of the market.

    --

    ---
    ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
  26. Re:The nut behind the wheel by Sir_Lewk · · Score: 4, Insightful

    Uuuuuuuh..... A home user? Re-read that quotation that you so handily provided one more time.

    I updated 11 Windows XP updates today and restarted my PC like it asked me to

    See it?

    my PC

    It's singular. He applied updates to a single computer.

    What sort of loon thinks that expecting home users to somehow test patches from their goddamn vendor before applying them is acceptable?

    --
    "linux is just DOS with a UNIX like syntax" -- Galactic Dominator (944134)
  27. Re:wtf by bmk67 · · Score: 2, Informative

    why are you people still using xp?

    Because -

    a) I already own a license

    b) It suits my needs

    c) It's what my employer requires me to have on my at-home on-call PC. Since they're footing the bill, I can hardly complain. See a) and b) above.

  28. Interesting read, this link... by Erikderzweite · · Score: 2, Insightful

    From TFA: "To regain control of their PCs, users were told to boot from their Windows XP installation disc, launch the Recovery Console and enter a series of commands."

    STOP COPYING LINUX ALREADY!

  29. One word - HIBERFIL.SYS by fibrewire · · Score: 2, Informative

    Try this before the "maxyimus" fix - boot Ubuntu or Systernals ERD and delete that pesky HIBERFIL.SYS and the $RECYCLER while your at it. Reboot to a functional computer. If this doesn't fix then "maxyimus" it is.

  30. Re:microsoft screws users again. Why is this news? by cetialphav · · Score: 4, Insightful

    If the developers get their heads out of their asses and learn how to market the software AND give the public what it wants, then and only then will Linux get its fair share of the market.

    The question is why would developers want to expand their market share among the non-technical users? Personally, I could care less if my mom uses Linux. You know why? Because she is not a developer and will not contribute one line of code to the OSS world. I want Linux to develop a following among the technical/programmer crowd. This means a larger developer base, which means a greater pace of improvement. This has been happening consistently for the 15 years I've been using Linux and that keeps me happily on this platform. Its all about Developers! Developers! Developers! to me. Microsoft and Apple can have all the rest.

    When someone decides that there is money in getting non-techies onto Linux, they will be able to polish Linux into something really slick. Ubuntu is trying, but there really doesn't seem to be enough money in it now so they aren't able to apply a lot of resources to it. Who knows? There may never be any real money in that kind of market (for Linux, anyway).

  31. History Repeats Itself by fibrewire · · Score: 2, Interesting

    NT - http://technet.microsoft.com/en-us/library/cc750081.aspx
    2000 - http://support.microsoft.com/kb/174630
    Now the same with Windows XP? Come on now, who are they fooling?
    Reminds me of that stupid stride commercial - http://www.youtube.com/watch?v=jxBlKFxGhNk
    For those of you who feel left out with a working computer - http://technet.microsoft.com/en-us/sysinternals/bb897558.aspx

  32. One copy... on a floppy! by KingSkippus · · Score: 5, Interesting

    When I was in college, a friend of mine who lived down the hall from me came to my door one day frantically knocking. She had stored the only copy of her PhD dissertation on a floppy disk, and the disk had gotten corrupted, and she didn't know what to do.

    I poked around on it for a little while, trying out a disk sector editor I had to see if I could recover anything, and I couldn't. It was just lost, period.

    She ended up going dumpster-diving. She had thrown away a printed hard copy the day before, and they hadn't taken the trash away yet. She was literally in the trash dumpster, sifting through two apartment buildings' worth of trash to find it, and spent that entire night retyping it from scratch.

    I felt sorry for her, and I remember thinking, "Well, I guess that's one way to learn a lesson that you'll never forget..." I was also really glad that I wasn't her significant other, because you know who would have been sifting through that dumpster.

  33. Re:Legacy by Renraku · · Score: 3, Insightful

    Okay. *upgrades to Ubuntu*

    *tries to install Modern Warfare 2*

    Hey, I can't run the installer, what's going on? *reads forums* What? Ubuntu doesn't support the latest Direct X? Fuck this, I'm going back to Windows.

    --
    Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
  34. Re:microsoft screws users again. Why is this news? by Pentium100 · · Score: 2, Funny

    Also, while command line may be faster than GUI, GUI is easier and here's why: if I want to do some task, I can look at the toolbars and in the menus to fins an item that looks like what I need to do (for example, if I want to find a file, I'll look for a button or menu item named "Search", "Find" or something like that. I will recognize it when I see it), but on a command line, I basically need to remember the exact command for doing what I want to do, for example, I would need to remember the whole "dir *foo*.ext /s | more" command if I want to find the file, it won't work if I type ls instead of dir or if I type search instead of find or I forget to write the /s. For less used commands this gets difficult.

    Linux is great, but only when it works right after install and you do not need to install other programs. Otherwise it gets very difficult very fast.

  35. Re:Why On Earth Do People Still Use Window? by the+eric+conspiracy · · Score: 3, Informative

    XP is a 10 years old OS that was meant to be decomissioned years ago

    Microsoft has had 10 years to introduce fixes to whatever problems Windows XP has. Systems are supposed to get MORE stable as they age, not get worse or show no improvement over time.

  36. Re:microsoft screws users again. Why is this news? by element-o.p. · · Score: 2, Insightful

    Meh...

    If most people had to install Windows to get it to work on their PCs, they'd be in the same boat they are currently in with Linux -- they wouldn't have any more clue how to install and configure Windows than they do Ubuntu. Having installed multiple flavors of both Windows and Linux, Ubuntu currently has the easiest installer I've ever seen, bar none. And I've had all the same problems you've described with Linux when I've had to install Windows from a retail (vice OEM) CD. In fact, I've even had to boot a PC with Knoppix, just to find out what kind of hardware was inside the case so I could go download Windows drivers to make the hardware work. However, since every PC maker since Windows 95 has included Windows installed by default (at least until recently), non-techie Windows users typically don't have to worry about it. Now, Windows is what Grandma expects on her PC. And since people, as a rule, are afraid of change, that will be the default until someone gives someone a compelling enough reason to use something else. Unfortunately, at this point, I suspect the only thing that will be compelling enough is, "You can't get a PC with Windows, anymore, ma'am...".

    --
    MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
  37. this is a pretty big if by YesIAmAScript · · Score: 2, Interesting

    As you may have read elsewhere, MS doesn't use context or offset diffs. They just replace files. So the case you speak of is unlikely.

    The most likely case is that people who are having the problem have a foreign DLL in their system that calls directly into an offset into this DLL without version checking it. This DLL does so because it's a rootkit, and it wants to fly under the radar. When you change this DLL that other DLL is now calling into invalid code.

    But the problem here is this other DLL is bad. It isn't a problem in MS' DLL at all. And how is MS to prevent this, are they to somehow figure out every other DLL in your system that could try to call into this DLL using surreptitious means?

    MS didn't know this rootkit existed, or if they knew, they didn't test with it. That's about as far as I can blame them without any more info.

    --
    http://lkml.org/lkml/2005/8/20/95
  38. Potential cause for the blue-screens by ThePeeWeeMan · · Score: 5, Informative

    It seems like someone's figured out what was causing the bluescreens... from the MS forum thread:

    I had an Eee PC with XP Home brought to me with this same problem. I rolled back KB977165, rebooted and the system worked fine. I reapplied KB977165 and the rest of the updates available at Microsoft Update, and the problem returned. I replaced %System32%\drivers\atapi.sys with a clean version from a XP SP3 distribution folder and rebooted... voila! Problem solved.

    For reference, the SHA1SUMs of the atapi.sys files:

    Non-working:
    bb3e36ad0c8ed6daab38653ea4a942d74b9f4ff6

    Working:
    a719156e8ad67456556a02c34e762944234e7a44

    If anyone wants to look at the non-working atapi.sys:
    https://patrickwbarnes.com/pub/atapi.sys

    I will be looking at this more in-depth. If I find anything more, it will be posted in a follow-up comment at the ISC:
    http://isc.sans.org/diary.html?storyid=8209

    UPDATE :
    I uploaded the non-working atapi.sys file to VirusTotal, and this is the result:
    http://www.virustotal.com/analisis/85aa49f587f69f30560f02151af2900f3dc71d39d1357727ab41b11ef828a7ff-1265925529

    Apparently, this update problem is the result of an infection.

  39. Re:One copy... on a floppy! by steelfood · · Score: 4, Funny

    Ph.D. on a floppy? Should we get off your lawn?

    --
    "If a nation expects to be ignorant and free in a state of civilization, it expects what never was and never will be."
  40. Re:One copy... on a floppy! by BrokenHalo · · Score: 2, Interesting

    ...sifting through two apartment buildings' worth of trash to find it, and spent that entire night retyping it from scratch.

    PhD "dissertation"? Normally one writes a thesis for a PhD, and a typical length is in the region of 50,000 words. I don't know about you, but that's way more than I can type in a night.

  41. Re:microsoft screws users again. Why is this news? by tsajeff · · Score: 2, Insightful

    Developers may want to expand their markets to non-technical users so they have a larger paying customer base to fund innovation.

  42. This one must have been fun to track down by Torodung · · Score: 2, Interesting

    There were 8 freaking OS security patches in this last patch Tuesday. It must have been a joy to track down the one update that was causing the problem (KB977165).

    I have honest pangs of sympathy for the poor sucker that had to figure out that that one update was rendering infected systems unbootable.

    This is why monoculture sucks. *Healthy* cultures are diverse. "Mono" doesn't enter into it. Pun very much intended.

    --
    Toro

  43. Re:in b4 the flamewar? by Anonymous Coward · · Score: 2, Insightful

    True. Why does Linux suck so bad? Every 6 months Ubuntu breaks something.

    Heh, if we made slashdot front page stories about those forum posts then even fewer than 1% would use Linux. But ofcource we just have to publicize forum posts about XP problems to give a skewed opinion. Oh well..

  44. Re:One copy... on a floppy! by CecilPL · · Score: 3, Funny

    I guess she should have copied that floppy. That's what you get for listening to M.E. Hart.

  45. Rootkit false positive? by bjs555 · · Score: 2, Informative

    My machines are running ok but I thought I'd look to see if KB977165 which is reported to cause the blue screens was on any of them. It was installed on one machine and not on another. So I thought I'd check a few more things that others say may be causing the problem.

    It has been suggested that atapi.sys in the system32/drivers folder might be rootkitted by the update. I compared the SHA-1 hash of atapi.sys on both machines and they were the same (A719156E8AD67456556A02C34E762944234E7A44) so, apparently, update KB977165 didn't change that file in my case.

    Some people are saying that atapi.sys is infected with a rootkit. I ran scanned the file through Jotti.com and it found nothing. I also scanned the file at VirusTotal.com and only eSafe reported a problem as follows:
    eSafe 7.0.17.0 2010.02.11 Win32.Rootkit

    I think this is a false positive since I have identical copies of atapi.sys on both machines and both show the same result on eSafe.

    It's possible, I suppose, that I was rooted by something other than the Windows updates but, so far, Sysinternals Rootkit Revealer has shown nothing suspicious.

    Do these results agree with anybody elses?

  46. Re:One copy... on a floppy! by AmonTheMetalhead · · Score: 2, Informative

    I've worked for 9 years in a support role for mac & windows, HFS+ and HFS aren't all that stable, however, recovery tended to be abit eaiser with HFS(+) compared to NTFS.

    I'm not going to claim however that HFS was solely to blame, it's always possible that corruption occurred due the ocasional kernel panic on OSX, or bombs in the old days or applications doing something wonky, but it happened, and more often then the (more numerous) windows installations.

    In the end though, it doesn't really matter, in most circumstances the corruption wasn't fatal and we had good backups, and there is no such thing as a perfect computer