![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2006
Location: Rhode Island
Posts: 5
OS: Windows XP Home SP2
|
W32.Sasser.Worm-like activity
Hello to everyone, I'm new to the forum.
Last night, my computer started having some problems, and I can't pin down what's causing them, let alone how to solve them. Any help would be greatly appreciated. I installed a 1GB stick of PC3200 memory last night - the memory I was installing was made by VData (birthday gift), and I set it up in a dual-channel configuration with the existing 1GB stick of PC3200 made by Rosewill. The motherboard they were installed in is an ASRock P4V88. I might note that the Auto-Detect memory speed function in BIOS setup thought both of these sticks of memory were PC2700. Anyways, after installing the new memory, the system posted fine, booted into Windows with no problems, so I took it off my bench and moved it back into my bedroom. After running for 5-10 minutes in my room, the computer restarted itself. My first thought was that this was a heat issue - my bedroom is warmer and has poorer ventilation than my work area. And the CPU Temp (as reported in BIOS Setup) was high - between 66 and 69 degrees Celsius. I moved the computer back out to my workbench, and the temps went down - but the restart problem persisted. I next suspected it might be a RAM-related problem, considering that was the last change I had made. I tried running the computer with each stick of memory indiidually, to see if I could isolate one as problematic. I haven't used a stick from a different computer yet, but I will if it becomes necessary. Additionally, I've been running Memtest86+ for over an hour now, and on the first pass it found no errors - it's going through the second pass now. Next, I changed the System Failure settings in Windows so that it would BSOD rather than restart upon system failure. Since then, I've recieved several BSODs, both the PAGE_FAULT_IN_NONPAGED_AREA and BAD_POOL_HEADER stops, indicating either the ntfs.sys or win32k.sys files to be at fault. Also, and this is what reminds me of W32.Sasser.Worm, when I start the computer in Safe Mode (and possibly Safe Mode with Networking, I really can't recall either way) I get the System Shutdown dialog box... "Initiated by NT AUTHORITY/SYSTEM" indicating C:\WINDOWS\system32\lsass.exe. When I log in as myself, this message appears after 'prox 5 minutes, but when I log in as Administrator, it appears before the desktop loads. I've tried multiple times to run NAV2003, but the system ALWAYS BOSDs while scanning. The system also BSODed while I tried to run an online virus scan. I can't contact Symantec because I'm using a cracked version of NAV. I did run the latest Microsoft Malicious Software Removal Tool and it didn't find anything. I'm thinking that this may be a new virus, but I'm not certain of anything at this point, other than I'm fairly certain that it isn't the RAM. If anyone has any ideas or suggestions, I would GREATLY appreciate your assistance. Thanks, Teh_Bear EDIT: I forgot to note: I'm unable to browse My Computer. When I double-click the My Computer icon or select it from the Start Menu, all I get is the flashlight "searching" icon. However, I can view my files by running cmd.exe and using the "dir" command. Last edited by Teh_Bear; 01-03-2006 at 03:13 PM. |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) | |
|
Register user
Join Date: Mar 2005
Posts: 5,931
OS: XP
|
Quote:
lets see if the security section can help you in the meantime if you are concerned with a heat issue, leave the side off with a floor fan blowing in to see the results |
|
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jan 2006
Location: Rhode Island
Posts: 5
OS: Windows XP Home SP2
|
Update: there is definately a problem with faulty RAM. Memtest86+ found an error on the second pass - I'm nowhere near skilled enough at interpreting hex addresses to figure out which stick was indicated as problematic, so I tried running the computer with only the new RAM, and got a BSOD during Safe Mode Boot. Tried the old stick, and I could boot to safe mode. I'll give the new RAM to my dad so he can RMA it. I'll have to test further to see if there's other problems still.
|
|
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jan 2006
Location: Rhode Island
Posts: 5
OS: Windows XP Home SP2
|
Update 2: The RAM wasn't the only problem. I'm still getting the "System Shutdown" dialog box in Safe Mode - I suspect this is being triggered when I open NAV, at least when I am logged in as myself and not as Administrator. Still getting the flashlight when I open My Computer. Still getting BSODs. Also, and I am not sure if I mentioned this before, but when I shut down/restart my computer, it stays at the "Please Wait" dialog box with the words "logging off" for a loooooong time - perhaps indefinately, I always restart the computer manually after a few minutes.
|
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jan 2006
Location: Rhode Island
Posts: 5
OS: Windows XP Home SP2
|
Update 3: I've been able to run NAV through a complete scan, in both Normal and Safe Mode. No viruses were detected (using the latest virus definitions as of 1/3/2006). I've attempted several times to run an online virus scan (Trend Micro) but my system is too unstable - both Internet Explorer and Firefox lock up during the scan.
I've run Norton/Symantec's Sasser removal tool, Microsoft's Malicious Software Removal Tool, McAffee's Stinger, and CWShredder. No results on any of them. AdAware came up with one entry, which I removed. Problems persist. Spybot S&D came back negative for problems. I haven't bothered with the Microsoft Anti-Spyware, because it's useless. I can post HijackThis logs if they're requestid, but all they show is stuff for Norton and for my soundcard (Creative Audigy 2ZS). I'm starting to think that there isn't a virus present, and that my system is just legitimately screwed up - although I must confess I have no idea how, as it was working fine until I tossed in that RAM yesterday. I may have to format and re-install, but I REALLY don't want to do that if I don't have to. If ANYONE has any suggestions/comments, I would really appreciate it, as I've run out of ideas. |
|
|
|
![]() |
| Thread Tools | |
|
|