Showing results for 
Search instead for 
Do you mean 
Reply
WWAN
Posts: 424
Registered: ‎01-22-2008
Location: US
Message 1 of 53 (6,352 Views)

RapidBoot Fails on Unsigned Driver

Getting a popup at bootup about an unsigned driver and getting the following in Event Viewer:

 

The PHCORE service failed to start due to the following error:

Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

PHCORE is part of RapidBoot.

 

Any ideas?

Lenovo Staff
Posts: 3,176
Registered: ‎10-29-2009
Location: NC
Message 2 of 53 (6,346 Views)

Re: RapidBoot Fails on Unsigned Driver

I've heard of this problem from someone else, but I think it went away after a reboot?  And I've never been able to reproduce the issue myself.

 

To verify that the driver is digitally signed, find phcore.sys or phcore64.sys (should be in c:\program files\lenovo\rapidboot), then right-click on it -> properties.  Is there a digital signatures tab?  Click on the signature and then click on the "details" button to see if there is any problem with it.

WWAN
Posts: 424
Registered: ‎01-22-2008
Location: US
Message 3 of 53 (6,340 Views)

Re: RapidBoot Fails on Unsigned Driver

Thanks for the quick reply. Windows reports the signature of phcore64 as ok, VeraSign Class 3 Code. Yet Event Viewer is showing the following at every cold start.

 

The PHCORE service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

And although I have RapidBoot logging turned on, the log is empty, so I know it's not happening.

Lenovo Staff
Posts: 3,176
Registered: ‎10-29-2009
Location: NC
Message 4 of 53 (6,336 Views)

Re: RapidBoot Fails on Unsigned Driver

It seems like something is interfering with the digital signature verficiation on that one file during startup.  But I have no idea what could be causing it.

Posts: 2,438
Topics: 20
Kudos: 421
Solutions: 193
Registered: ‎12-01-2007
Location: California, USA
Message 5 of 53 (6,323 Views)

Re: RapidBoot Fails on Unsigned Driver

Hello,

 

Just out of curiosity, have you checked the computer for a bootkit type of rootkit?  This is usually best done by booting the computer from a CD or USB flash drive so that nothing is run off the hard disk drive and checking it from there.  Most anti-malware software vendors offer some sort of program you can download to create such a disc/USB flash drive.

 

Regards,

 

Aryeh Goretsky

 



I am a volunteer and neither a Lenovo nor a Microsoft employee. • Dexter is a good dog • Dexter je dobrý pes
S230u (3347-4HU)X220 (4286-CTO)W510 (4318-CTO)W530 (2441-4R3)X100e (3508-CTO)X120e (0596-CTO)T61p (6459-CTO)T43p (2678-H7U)T42 (2378-R4U)T23 (2648-LU7)
  Deutsche Community   Comunidad en Español Русскоязычное Сообщество
WWAN
Posts: 424
Registered: ‎01-22-2008
Location: US
Message 6 of 53 (6,313 Views)

Re: RapidBoot Fails on Unsigned Driver


goretsky wrote:

Hello,

 

Just out of curiosity, have you checked the computer for a bootkit type of rootkit?  This is usually best done by booting the computer from a CD or USB flash drive so that nothing is run off the hard disk drive and checking it from there.  Most anti-malware software vendors offer some sort of program you can download to create such a disc/USB flash drive.

 

Regards,

 

Aryeh Goretsky

 


At your suggestion I ran the Sophos rootkit tool and as a backup the GMER rootkit too. Both negative. I have to ask, why would a rootkit target the RapidBoot driver and nothing else? Seems a bit specialized. Remember, the computer works fine; no problems, no slowdowns, no warnings from MalwareBytes, no warnings from Symantec Endpoint Protection. The first symptom was no observed decrease in boot time, the second was no entries in the RapidBoot log and the third was the repeated warnings in Event Viewer.and of course the popup advising me of the unsigned driver. Forgot about that.

WWAN
Posts: 424
Registered: ‎01-22-2008
Location: US
Message 7 of 53 (6,306 Views)

Re: RapidBoot Fails on Unsigned Driver

[ Edited ]

Just to refresh and clarify. Please click on the attachment to see.

Lenovo Staff
Posts: 3,176
Registered: ‎10-29-2009
Location: NC
Message 8 of 53 (6,292 Views)

Re: RapidBoot Fails on Unsigned Driver

mixz1,

 

I understand the issue you are reporting.  But I don't know why it is happening when the signature on the phcore64.sys is in fact present and valid.  I don't think this has anything to do with malware or virus.  I have asked our software team for their input on this issue.  I will post back here if I learn anything about it.

WWAN
Posts: 424
Registered: ‎01-22-2008
Location: US
Message 9 of 53 (6,275 Views)

Re: RapidBoot Fails on Unsigned Driver


someotherguy wrote:

mixz1,

 

I understand the issue you are reporting.  But I don't know why it is happening when the signature on the phcore64.sys is in fact present and valid.  I don't think this has anything to do with malware or virus.  I have asked our software team for their input on this issue.  I will post back here if I learn anything about it.


Thank you. I would have preferred "I will post back here when I learn something about it", but I'll just have to assume I'm not the soleT520 user with this problem and eventually it will be solved. Again, thanks.

Highlighted
Posts: 2,438
Topics: 20
Kudos: 421
Solutions: 193
Registered: ‎12-01-2007
Location: California, USA
Message 10 of 53 (6,241 Views)

Re: RapidBoot Fails on Unsigned Driver

Hello,

 

I know that some malware interferes with device driving signing.  Apparently, though, not the case with this issue.

 

Regards,

 

Aryeh Goretsky

 



I am a volunteer and neither a Lenovo nor a Microsoft employee. • Dexter is a good dog • Dexter je dobrý pes
S230u (3347-4HU)X220 (4286-CTO)W510 (4318-CTO)W530 (2441-4R3)X100e (3508-CTO)X120e (0596-CTO)T61p (6459-CTO)T43p (2678-H7U)T42 (2378-R4U)T23 (2648-LU7)
  Deutsche Community   Comunidad en Español Русскоязычное Сообщество
top kudoed authors
User Kudos Count
1