Windows xp -page_fault_in_nonpaged_area

Discussion in 'Malware Help (A Specialist Will Reply)' started by kousikb, Apr 26, 2012.

  1. kousikb

    kousikb Private E-2

    Hello,

    Last week my problem started. I have Dell laptop with Windows xp. Suddenly, my intel wireless stopped working with message 'can't find adapter' and then computer stopped with blue screen having full page message that starts with 'page_fault_in_nonpaged_area' error. I restarted the machine couple of times, but it always crashes with blue screen after sometime.

    I read similar threads in your forum, but couldn't find a relevant one. So I started reading and executing steps written in "read and me first " of your forum.

    Step 1-6 executed successfully

    Here are results and problems with Step 7 (Windows OS Specific Cleaning Instructions):

    i) SUPERAntiSpyware - ran successfully (log attached)

    ii) Malwarebytes Anti-Malware -- ran successfully (log attached)

    iii) Combofix - When I ran it, it has detected Rootkit in tcp/ip stack. It automatically rebooted the system, and started executing stages. It got stuck at stage_46 . I waited for few hours then , forcefully shutdown and started again. I saw that you instructed to go ahead if we have problem in combofix, so moved to next one. I could not find combofix log (loked at C:\) , so could not attach.

    iv) RootRepeal -- As soon as I run it, computer rashes with same vlue screen. I tried twice, but the result is same. So stopped executing anymore step.

    I can see that my intel wirless is working., but windows is crashing again after sometime with same blue screen (''page_fault_in_nonpaged_area' ). Also, I found that under c: drive, we have a "combofix" icon like mycomputer and under that c:, d:, e: drives having all folders and files. Looks like due to incompletion of combofix, it left system like that.

    Please advise.

    Kousik
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were not supposed to stop. The first instructions in the READ & RUN ME FIRST include the below lines
    So finish the rest which includes running MGtools and attach the C:\MGlogs.zip file that we need to get started.
     
  3. kousikb

    kousikb Private E-2

    Thanks for quick reply.

    As you suggested, I tried to run MGtools, but it stopped in between as laptop crashed with blue screen. But this time, the message is not 'page_fault_in_nonpaged_area' . It has **** STOP: (some address)
    *** atapi.sys - address ...... base ..... datestamp

    Please advise.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seems the crash messed up your computer. MGtools does not remove anything of significance. It is primarily just an information collector it would not be the reason why you cannot boot. Sounds like oneor more system file may have been corrupted or deleted during the crash. Also note that it is very important that you do not paraphrase error messgaes. Complete and exact messages are a must.

    Do you have your Windows XP Boot Disk?
     
  5. kousikb

    kousikb Private E-2

    Sorry for late reply. I could boot in safe mode, and in normal mode also it stays for 30-60 minutes before it crashes. Since the blue screen messages can not be copied, I only noted down few important phrases. Next time, I will note down the whole message. Also, I do not have boot CD. I am searching to see if I have original installation CD or not.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then this is more than enough time to run MGtools. So startup your PC and immediately run MGtools and when it finishes attach the C:\MGlogs.zip file.

    Your problems are not sounding like malware but we need to collect more info first before we can decide.
     
  7. kousikb

    kousikb Private E-2

    I tried twice but on both times system crashed with blue screen while MGTools was running. Please find below the message in the blue screen:
    A problem has been detected and windows has been shutdown to prevent damage to your computer.

    If this is the first time you've seen this stop error screen,
    restart your computer. If this screen appears again, follow these steps:

    Check to be sure you have adequate disk space. If a driver is identified in the stop message,
    disable the driver or check with the manufacturer for driver updates. Try changing video
    adapters.

    Check with your hardware vendor for any bios updates. Disable BIOS memory options such as
    caching or shadowing. If you need to use safe mode to remove or disable components, restart
    your computer, press F8 to select Adavnced startup options, and then select safe Mode.

    Technical information:

    *** STOP: 0XOOOOOO8E (0XC0000005, 0XB9F1571D, 0XAEB1B580, 0X00000000)

    *** atapi.sys - Address 0XB9F1571D base at B9F0B000, Datestamp 4802539d

    Beginning dump of physical memory
    Physical memory dump complete.
    Contact your system administrator or technical support group for further assistance.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. kousikb

    kousikb Private E-2

    I am extremely sorry to reply you so late. I was very busy with my official tasks, so could not pay attention to my personal laptop.

    I did system restore twice, taking it well back in time, but problem remains. Now It stays for sometime then suddenly desktop color, taskbar changes like what we see in a safe mode. System response bocomes very slow, and then crashes with blue screen.

    Please help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not looking too good! Do you have your Windows XP boot CD?
     
  11. kousikb

    kousikb Private E-2

    Yes I fould the original Windows XP CD. However, my CD/DVD driver not working properly. Its loading content sometime, and sometime not. I guess we might have an work around. Please guide what to do with Windows XP CD.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This instructions here guide you on boot your Windows XP CD to access the Recovery Console. Prior to following these instructons you must have configured your BIOS to allow booting from the CD drive. If you do not know how to do configure the BIOS to do this, the below links may be helpful in showing you how to do this.

    http://www.hiren.info/pages/bios-boot-cdrom

    http://pcsupport.about.com/od/tipstricks/ht/bootcddvd.htm

    http://www.computing.net/answers/windows-xp/how-to-boot-from-xp-cd-in-bios/133187.html

    Once you have been able setup your BIOS to boot from CD first, continue with the below.

    1. Boot from the Windows XP CD ( i.e., put the CD in the drive and reboot your PC or put the CD into the drive while you are still in the BIOS and exit the BIOS after saving your boot order changes.

    2. When the text-based part of Setup begins, follow the prompts. Select the repair or recover option by pressing R as seen in the below image ( click to expand the thumbnail - note: your CD may not be Windows XP Professional like in this example )

    http://forums.majorgeeks.com/chaslang/images/RC/Rec_Cons1.gif

    3. After selecting R, you should see a screen like below showing the Recovery Console:

    http://forums.majorgeeks.com/chaslang/images/RC/Rec_Cons2.gif

    4. Once you are at the Recovery Console, you will be given at least one choice of Windows installations. Normally the choice you want is number 1 . Click the number 1 key at the "top" of the keyboard and click enter.

    NOTE: At this point your the numbers to the right of your keyboard is are off. If you insist on using these keys for your numbers, remember to hit the Num Lock key before clicking a number over there or your computer will automatically reboot and you will have to wait through the previous steps to get back to the recovery console.

    5. Now you will be given a message asking for the Administrator password. Depending on whether you ( or someone else ) ever configured this password or not, it may just be blank. So enter your known password or try leaving it blank ( by just hitten the Enter key ) if you are not sure you have one.

    6. Now you will have a prompt in the black command prompt window that shows the below:

    X:\WINDOWS>

    Note: Where X: is to be replaced with your drive letter which is typically C: This applies to all steps below showing X:

    7. Type the below commands each followed by the enter key. The last command will cause the PC to reboot. Reboot to normal Windows without using the CD to boot.
    • fixmbr
    • fixboot
    • exit
    Test to see if your PC works any better now. If this does not help, you will likely have to reinstall.
     
  13. kousikb

    kousikb Private E-2

    Once again sorry for the delay. I had to struggle a lot to have my CD-ROM working. Anyway I could change the boot sequence through bios and go for Recovery option through Installation CD (as told by you). Please see my results below:

    When I ran fixmbr it says

    The computer appears to have non-standard or Invalid master boot record.
    Fixing may damage your partition table if you proceed.

    This could cause all the partitions in the current hard disk to become inaccessible.

    If you are not having any problem accessing your device, do not continue.

    Are you sure you want to write a new MBR?

    I entered Y to proceed.

    Then it says:

    Writing new master boot record in physical drive
    \Device\Harddisk0\Partition0

    The new master boot record has been successfully written.


    Then I executed fixboot

    c:\Windows\fixboot

    Fixboot can not find the system drive , or the drive specified is not valid.

    Then I put exit to get out of that.


    I rebooted normally then using hard drive installation. I am not waiting to see if it crashes or not. But the boot time is very high (around 20 minutes). Please advise whether I should go for reinstallation or not. I have both installation CD and driver CD. I have 2 drives, namely C and D. I have my data in D drive. I guess reinstallation will keep my data in D drive safe. Please advise.
     
  14. kousikb

    kousikb Private E-2

    My laptop crashed again.

    Please advise whether I should go for reinstallation or not. I have both installation CD and driver CD. I have 2 drives, namely C and D. I have my data in D drive. I guess reinstallation will keep my data in D drive safe. Please advise.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry, I was on vacation for 2 weeks. Are you still having crashes?

    If you wish to reinstall you can do this. I suggest backing up all important data first and it would be a better idea to back it up to someplace other than your internal hard disk ( just to be safe ). Normally if you do not delete partitions and just reinstall Windows to the same drive it is currently install to, it should not impact that other partition at all.
     
  16. kousikb

    kousikb Private E-2

    I have reinstalled windows xp , and installed all drivers etc using my original CD. Everything looks to be normal now.
    Thank you very much for all your help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you have it working again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds