Client calls today in a panic...NT server is dumping the memory shutting down and upon boot up would dump the memory again...the stop error meesage is
STOP 0X00000001E Kmode_Exception_Not_Handled in Win32K.sys (Knowlege Base Q294728)
We droped another NT drive into the box and have a dual boot machine...by Dual booting we have the clean hard drive as the boot drive and we can search the "infected drive"
How do we see/open the registery on the other drive?
How do we see the logs for the other drive?
What do you think of the following files tftp879.exe, airfreight.pdf.exe,alot of the PC anywhere files were amended around 8:41 right when the server bogged, 20021003124206703.livereg, my profile.userprofile
There is an Built in User that is called Unkown...never heard of it and it doesnt shouw up in the user but if you go to rights under some of thoes files it has change rights...
any help...
STOP 0X00000001E Kmode_Exception_Not_Handled in Win32K.sys (Knowlege Base Q294728)
We droped another NT drive into the box and have a dual boot machine...by Dual booting we have the clean hard drive as the boot drive and we can search the "infected drive"
How do we see/open the registery on the other drive?
How do we see the logs for the other drive?
What do you think of the following files tftp879.exe, airfreight.pdf.exe,alot of the PC anywhere files were amended around 8:41 right when the server bogged, 20021003124206703.livereg, my profile.userprofile
There is an Built in User that is called Unkown...never heard of it and it doesnt shouw up in the user but if you go to rights under some of thoes files it has change rights...
any help...