in the middle of the game, all of a sudden i get booted out to my desktop with an alert prompt saying something along the lines of "The computer needs to restart. Please save any important documents as you will lose this data." then it mentions something about an unexpected termination code equaling zero which probably caused that prompt. unfortunately, i don't remember exactly what it said at the time but i did remember seeing the message mentioning then something about SYSTMEM.exe (not system.exe). i wasn't sure what happened and this has never happened before.
i thought it was a glitch so the comp restarted. everything was fine with load up back to windows. it wasn't until i got an error message prompt as soon as i could see my desktop saying "Error - could not find path C:\Program" that i began to think maybe this is a virus.
then trying to see my task manager to see that executable file, i found that my access to getting there was disabled by the administator. problem is I AM THE ADMIN. i couldn't do regedit either by using Run. that's all i saw for now... didn't notice anything else different. fortunately i was still able to get on the web, so i looked up this "SYSTMEM.exe" but couldn't find anything. i have a program called WinPatrol which guards against hijacks, etc. and was able to temporarily stop this SYSTMEM.exe file.
i ran ad-aware and spybot and they detected that my registry disabled those functions in addition to a whole lot more, including windows security center, firewall, etc. i cleaned the problems and was able to get access to regedit and the task manager again and i'm guessing that the SYSTMEM.exe was the culprit.
i found that SYSTMEM.exe is not only a hidden file but a hidden system file but apparently it's not a legit file. it hid itself in my program files directory and i'm guessing it disabled a whole bunch of settings in my registry. now, it's clean but i'm surprised my virus checker didn't spot it as a trojan or virus. this is weird because i haven't been to any random sites which were questionable so i don't know how i got this "thing" or installed any questionable software.
... fast forward to yesterday. after running all these scans (including malwarebytes, spybot, ad-aware, and my PC Tools virus checker), i felt better thinking that the problem would be resolved but i guess i was wrong.
i decided to LAN with my brother again via Hamachi and everything was good and normal until randomly again in the middle of the game, i get booted out to my desktop. i can still get back in the game but i get another shutdown message but this time i paid attention to the message (but this time it had a different file):
This shutdown was initiated by NT AUTHORITY\SYSTEM. The system process C:\WINDOWS\SYSTEM32\ISASS.EXE terminated unexpectedly with status code 0.
the computer restarts and everything is normal and i don't see anything out of the ordinary and no weird startup prompt either. my task manager/regedit aren't disabled this time around. i looked online to see if anyone knew what this could be and i came across articles about the blaster worm and sasser worm. but researching them a little more closely, i don't have the files that they supposedly copy onto your computer. and i don't get a restart prompt or anything when i go on the internet, whereas other people said they only had 2 min when they load into windows then they get that prompt for system shutdown. from a surface glance, i don't notice anything out of the ordinary in terms of function. i can go on the web - no problems.
so you can see - i'm clueless as to what the issue is. i've ran the checkers and thought it picked up everything but not sure if they did... apparently not. as i said, i'm able to get on the internet, browse webpages, have full/normal functionality with task manager and regedit and my command prompt, as well as other programs. nothing seems out of the ordinary.
seems like i get that system restart thing when i try LANing, but that only occurs during the middle of the game. the thing that's weird is that i've never had that problem before when i LANed using Hamachi... just happened this past sunday (in the new year so maybe the timeframe set off a dormant virus or something?)... i'm not sure. again, we've LANed the same game before without any problems or trouble and no weird shutdown prompt.
** btw - one of my IT fellows that works with me said to maybe disable windows messenger service and see if that'll help since most viruses and trojans exploit that. or maybe get a different virus checker like AVG or something similar? or maybe the problem is coming from my brother's computer since we're "connected"?
please help... thanks!
Edited by Rutt Roh, 07 January 2009 - 06:20 PM.