Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Boot BSOD - TDSS rootkit?


  • Please log in to reply
No replies to this topic

#1 shallowbreath

shallowbreath

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 12 February 2010 - 05:49 PM

AW aurora m9700 Windows XP Pro sp3, nVidia RAID 0

I restarted my computer after some windows updates on Feb 9 in the evening, and began getting boot BSODs from there on out.

From research, it seems I am having similar problems (in a very similar timeframe) with the windows update KB977165.

I can't really afford to lose the data on the computer. The main problem I have had was not having an XP OEM CD (mine was cracked). I started a repair install with a VOL sp3 CD and nearly finished when I experienced a BSOD (0x0-7B) and learned that may be because I tried to repair an OEM system with a VOL CD. I used my 'recovery' disk and nLite to make a bootable repair disk, slipstreamed my raid drivers - nVidia's -, sp3, and ran another repair install. Since then I am stuck at a 0x-50 BSOD - PAGE_FAULT_IN_NONPAGED_AREA.

Things I've tried:

bootcfg /rebuild
replacing ntoskrnl.exe from the disc
Avira boot CD -- could not scan for anything, perhaps couldnt mount my RAID?
safe mode / lastgood
uninstalling all the Feb 9th updates from the recovery console
repair install with OEM CD
removing RAM and cleaning all contacts with compressed air
memtest86 - ran 5 passes, no errors
chkdsk /r - twice, made 3 changes each time 'performing additional checking or recovery'

things I have NOT tried

fixboot
fixmbr
other boot CD's

I don't know if my sp3 CD has this update, but it is not listed in the updates when i use dir on my windows folder. Should I try again with just a sp2 version of my disk? How do I get a rootkit or antivirus boot CD to read my RAID? I have my drivers available.

also -- I don't think I have memory dumps enabled, my windows\minidump folder is empty. Is there any way to enable and debug those without being able to boot windows?

Thanks!!

Edited by shallowbreath, 12 February 2010 - 06:05 PM.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users