Computer Randomly Rebooting

Discussion in 'Malware Help (A Specialist Will Reply)' started by A6AC5, Sep 5, 2023.

  1. A6AC5

    A6AC5 Private E-2

    For the past couple of weeks the computer that I'm posting this from has been mysteriously rebooting itself. When this happens there is no blue screen of death or any other warning: the screen just goes off and then about 15 seconds later the MSI splash screen appears and the computer boots back up. The reboots don't seem to be tied to any particular activity or event and they happen at random times - sometimes it'll be days before it happens and sometimes the computer will only but up for a minute or two before it reboots.

    I've run across is a message in the system log as follows - this seems to happen at the time of every reboot
    The computer has rebooted from a bugcheck...

    On the off chance this was malware, I ran a bunch of virus scans at another site - none of those found anything. After that I remembered about the procedure in the readme for this forum and ran that procedure. RogueKiller found about 4 suspicious items and Hitman Pro flagged Dwarf Fortress LNP as a potential threat.

    This is weird. Haaaalp!

    Also let me know if this is the wrong thread for this post.


    For starters I'm running Windows 10 Pro (22H2). I'll wait to provide more info if someone asks for it - don't want to dash a bunch of useless stuff out there.
     
  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the Major Geeks Malware Forum.

    Let's start with this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Right click on FRST64, select Save Link As..., and save the file on your Desktop
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • When completed, FRST.txt and Addition.txt reports will be saved on the Desktop
    • Please attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • Attached reports
     
  3. A6AC5

    A6AC5 Private E-2

    I decided to try a full reinstall before posting in hopes that would solve my problem. My main and admin user accounts have been recreated and Bitdefender, Firefox, and RoboForm were successfully reinstalled with no issues. Steam also appeared to install successfully as well as Mumble but then 3 reboots happened back-to-back. Mumble and Steam were both active, and Steam was downloading a game (Ark) when the first reboot happened. The second and third reboot happened before any applications could be opened. The attached logs were collected after the third reboot.

    As on previous occasions the reboots appear to be accompanied with this message in the system event log:
    Code:
    The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000116 (0xffff8b0716be8010, 0xfffff80473386c98, 0xffffffffc000009a, 0x0000000000000004). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: bc1a7b32-b5fa-4b25-8aac-64de354d60d6.
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Please log into the shill User Profile and rerun a FRST Scan. We will get more information to review that way.
     
  5. A6AC5

    A6AC5 Private E-2

    According to the previous memory dump file, my issue originated in the graphics driver so, as a potential fix, I installed the GeForce experience program and let it install its own driver. I also installed the full set of drivers for my motherboard from MSI support site which included the chip set driver. Everything ran fine overnight and up til a few minutes ago. Roboform was out of day a few minor versions so I upgraded it (from 9.3 to 9.5, iirc). When I tried opening Roboform, the computer rebooted itself immediately. After the reboot I got a message box with the following error:
    This is similar to a message I got before the reinstall when I was trying to start Mumble. A reboot happened while Mumble was starting and after the reboot, when I would try to open Mumble a similar message box would pop up with this error:
    As with previous reboots, this one was accompanied with an error in the system log:
    Based on the crash dump file it seems like the video driver again.
     
  6. A6AC5

    A6AC5 Private E-2

    Attaching files obtained using the shill account.
     

    Attached Files:

  7. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Thank you for the detailed report. Yes, the errors seem to point to a graphics driver issue. If you did not completely uninstall and reinstall the NVIDIA drivers I would recommend that.

    I would like to review all of the dump files. Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    Zip: C:\Windows\Minidump
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will create a zipped folder on your Desktop with today's date, example: 06.20.2023_13.24.50.zip. Attach the file to your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Attached zip file
     
  8. A6AC5

    A6AC5 Private E-2

    Here ya go...
    Thank you kindly for your help
    WW
     

    Attached Files:

  9. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the uploads.

    In case you missed it.
     
  10. A6AC5

    A6AC5 Private E-2

    The drivers were reinstalled before the Farbar fix was applied. I double checked in device manager after the uninstall and it reported that the graphics card was using the default driver. Once that was confirmed and the GeForce Experience software was reinstalled as well as its driver, device manager reported that the graphics card was using the Nvidia driver again. The Farbar fix wasn't applied until after this was complete.

    Have a great rest of your day!

    -ww
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    How did you do this, allow NVIDIA to identify and install the software via website or did you manually download the software and install it?
     
  12. A6AC5

    A6AC5 Private E-2

    I just installed the software and let it download the appropriate driver.

    -ww
     
  13. Oh My!

    Oh My! Malware Expert Staff Member

    Which NVIDIA card do you have?
     
  14. A6AC5

    A6AC5 Private E-2

    Display adapter is an NVIDIA GeForce RTX 3060

    Also, there was another unexpected reboot last night when I shut a game down. Found this in the system log...
    Also, I just noticed a few Windows updates that need to be installed.
    • 2023-08 Cumulative Update for .NET Framework 3.5, 4.8 and 4.8.1 for Windows 10 Version 22H2 for x64 (KB5029649)
    • 5 driver updates labeled INTEL - System
    • 2 driver updates labeled Intel 200 Series Chipset
    • Intel PCIe driver
     
  15. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the information.

    I would like us to attempt a more thorough uninstall of the NVIDIA drivers and reinstall them.

    Please do this.

    ===================================================

    Manually Creating a System Restore Point

    --------------------

    • Click Start, type Restore Point then click on Create a restore point
    • Click Create
    • In the Description section type Uninstall NVIDIA
    • Click Create and allow the process to complete
    • Confirm the Restore point was successfully created prior to completing the below
    ===================================================

    Display Driver Uninstaller - NVIDIA

    ----------
    • Download GeForce Game Ready Driver - 537.13 - WHQL and save it to your Desktop
    • Download Display Driver Uninstaller and save it to your Desktop
    • Unzip the folder onto your Desktop
    • Boot into Safe Mode using the instructions under From Settings
    • Double click on the DDU folder
    • Right click the on the Display Driver Uninstaller.exe icon and select Run as administrator
    • Review and click OK on the warning screen, if it appears
    • On the Options window uncheck Show offers from our partners and check Prevent downloads of drivers from "Windows update" when "Windows" search for a driver for a device
    • Close the Options window
    • Under ---Select device type--- select GPU
    • Select NVIDIA
    • Click Clean and restart (Highly Recommended)
    • Following reboot right click on the previously downloaded GeForce Game Ready Driver - 537.13 - WHQL file, select Run as administrator, and follow the installation instructions
    • If desired, download and install GeForce Experience
    • Check your video performance and monitor for computer crashes
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Restore point created?
    • Results?
     
  16. A6AC5

    A6AC5 Private E-2

    Done. The only place I deviated from the instructions was to disable the HD audio driver it wanted to install.
     
  17. Oh My!

    Oh My! Malware Expert Staff Member

    Very good, let me know how things go.
     
  18. A6AC5

    A6AC5 Private E-2

    :rolleyes:

     
  19. the mekanic

    the mekanic Major Mekanical Geek

    This is a DPC Watchdog violation. Would seem to be driver related. Which one? Also perhaps some corrupt files. Hmmmm...

    How old is your rig?
     
    Last edited: Sep 11, 2023
  20. A6AC5

    A6AC5 Private E-2

    They're coming hard and fast tonight.
    9:15
    9:17, 9:20, 9:30
     
  21. the mekanic

    the mekanic Major Mekanical Geek

    How old is your C: drive? RAM? System board?
     
  22. A6AC5

    A6AC5 Private E-2

    Chip, RAM, and mobo were purchased/installed in 2021; display adapter is this year. Drives are a mix of 2021 and 2023 purchases.

    On a side note, Windows installed a .Net framework update and Cumulative Update KB5029331 so I also let it install a bunch of optional driver updates. (mostly Intel stuff).
     
    Last edited: Sep 11, 2023
  23. A6AC5

    A6AC5 Private E-2

    During the reboot from those updates, I decided to make a stopover in BIOS to check if I was behind. In fact I appear to be 2 versions behind. Current version is E7A71IMS.520 which I think corresponds to "7A71v52" on https://www.msi.com/Motherboard/H270-A-PRO/support#bios
     
  24. the mekanic

    the mekanic Major Mekanical Geek

    In the event logs, I noted that besides the nVidia issues, there was also a BitDefender incident in there as well.
     
  25. A6AC5

    A6AC5 Private E-2

    Upgraded BIOS to the latest version and installed all of the outstanding Windows updates. Now to wait a few days and see what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds