XP Pro sp2 - Random bsod and restart

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by necro61, Feb 24, 2009.

  1. necro61

    necro61 Specialist

    Hello fellow geeks,

    Platform: Itech - P4 2.4GHz / 40Gb HDD / 512mb DDR ram
    O/S: XP Pro SP2 - Direct-X 9.0c
    Single Drive: C:\
    Antivirii software: Bitdefender 10 free: current updated every 24 hours
    Accounts: Administrator / Power user & user / user

    Have an issue with this unit that doesnt suffer from the faulty crapacitor issue, early symptoms being similar...random restarts..been there before on another unit. Done close visual inspection, no bulges or leaks visible.

    Have run chk disk via the right click C:\ tools \ select both the options and run.

    Wondering if scandisk will make any difference? havent attempted to run this yet.

    Noted during a defrag, using Ultimate Defrag, there is just over 8% that cant be defragged, this is a first for me, using ultimate defrag used this app a fair bit on other units and love it. It is currently set as the default defragger superseeding the MS stodgey horrible variant.

    Hoping the unable to defrag issue isnt the cause. Although have option available ghost current C:\ to another drive if this the issue bad damaged sectors etc...

    With ultimate defrag one can click on the files as shown in a circular disc layout and then open the block to look at the files stored in it - alot - of the 8% of the drive which is undefragmentable (new word of the week) seem to be related to the master file table (mft).

    Considering running memtest86 to see if the issue is there, the user reports that the issue first occurred approx 2 weeks ago, and I was unaware untill Monday when it restarted 3 times in one day, then the user decided to inform me.

    Anitvirii check comes back clean have a space then wowexec.exe in task manager but is in right location and 11kb in size which according to online research suggests is normal for this.

    I had the unit running seemingly fine for 3.5 to 4 hours while investigating the issue..and other unrelated issues on other units...untill 15mins before finishing work yesterday. Then unit restarted with no prompting from me whatsoever.

    I was also on a different account than what the user normally is and the only file open was a connection to the internet and msn messenger running although minimized and had nothing going on there at the time...

    Have noted that when checking media player that it was just like media player 9 was being setup for the first time where you set the privacy and cookies etc this has happened twice and maybe related??

    Checked the recent updates to see if there was a bad install from microsoft auto updates nothing apparent from this.

    Did have a Error report - Recovery from serious error on restart with the following which may help...?? This after media player had been setup for the second time, its like the original settings never held.

    BCCode10000050
    BCP1F668ce42
    BCP00000000
    BCPf76AABAD
    BCP400000000

    The units primary use is for playback of recorded audio for typing - two programs are used to facilitate this, Express Scribe and Netscribe also required is a VEC foot (audio control) is used for << and >> etc... Everything else apart from ms office and our own company logo with using an element from sys internals to display the i.p computer name cpu ram etc.. is pretty much a stock "vanilla" install. Wondering if Media player codec or similar might be part of the mix conflicting or sharing the same.

    Any thoughts on this would be appreciated. Not familiar with Hijack this and appreciate mediators requests not to post those reports here. :wave

    Another after-thought is windows might think its core operating system files are being attacked and the unit maybe configured to restart in this instance..although havent follwed up on this yet.

    Had this unit running seemingly stable today but am cautious as to releasing it to the user. As i am unsure as to its status.

    Have put this in the malware section as i dont believe it to be hardware related.

    Thanx to any one offering suggestions on a fix from this eclectic mix of info :confused
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. necro61

    necro61 Specialist

    Thanks again Tim,

    the saga continues..

    I have followed some advice from the windows error reporting service it actually had a suggestion for a change, it mentioned to check for a device or device software update and that it may cause the unit to restart. As the machine hadnt had any new hardware and had been seemingly stable for over a year I was somewhat flumexed by this suggestion.

    I then noted that automatic updates were on and thought perhaps there was a device that had an update and this potentialy caused the issue. There was nothing to indicate that any of the devices had an issue yellow exclamation marks etc.. So went through each device and found that a gameport on the expansion card required an update and another device also..cant recall which ..sorry not very geeky of me.

    On restarts logging in to the admin account after the issue occured i would get two msgs of "your computer has recovered from a serious error" issue. I am hoping at this time that these related to these two devices. Also had two devices sharing the same IRQ but no conflicts listed - if i recall one of them is the acpi..

    Also noted when checking the firewall settings when i disabled an allow limewire (grrr..) that a pop up in the sytem tray said "xp service pack 3 installation cancelled" ...go figure. I'm thinking the user may have tried to do this, at some stage and this may play a part..? Automatic updates were set to allow user the choice of when to install.

    Thanks will update this post if the issue continues it had been "supposedly" stable for the last 2 days..:cry
     
    Last edited: Feb 26, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what you find out.
     
  5. necro61

    necro61 Specialist

    Hi just an update,

    Appears that the Hdd itself had issue's, first inkling of this being the case was that the hard drive wouldnt totally defrag, its used in a business environment and 40gb drives are old enough now I guess to start failing.

    Run the diagnostics for the H drive failed minimal test and smart / extended test. That was it - imaged the drive no issues since, also discovered the cpu was incorrectly configured and got and extra 6ooMhz out of it when set to correct speed. So all in all not a totaly useless exercise.:cool

    Thanks for the support.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know you got it sorted out. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds