PDA

View Full Version : HJT - BSOD



NZHawk
07-06-2011, 12:54 PM
Have a Windows XP media centre
blue screens on normal boot
can boot into safe mode
have ran a test on both hard drive & ram: passed
updated drives still BSOD
ran: TDSSKiller: clean
ran: rustbfix: clean

Could someone look through this hjt log possibly an infection

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:44:04 a.m., on 7/06/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Compaq_Administrator\Desktop\2 Cleaning Tools\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NZ&c=64&bd=PRESARIO&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -RESTART
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [UpdateMyDrivers] C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 7958 bytes

Speedy Gonzales
07-06-2011, 01:37 PM
Whats the stop error? Get bluescreenview, see what it says

http://www.nirsoft.net/utils/blue_screen_view.html

Update this to SP3

Tick these then tick fix checked. Close browsers. Or delete the entries in ccleaner (under startup)

Uninstall all versions of java its out of date, then install the latest version only

I would get rid of Nortons

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -RESTART

O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent

O4 - HKCU\..\Run: [UpdateMyDrivers] C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss

NZHawk
07-06-2011, 02:14 PM
I can't install SP3 until I can get a clean boot

Here are some of the BSOD - could some assist with understanding what they say:
==================================================
Dump File : Mini060711-02.dmp
Crash Time : 7/06/2011 11:36:27 a.m.
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x805b768b
Parameter 3 : 0xf76abb60
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+e068b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Processor : 32-bit
Crash Address : ntoskrnl.exe+e068b
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini060711-02.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini060711-01.dmp
Crash Time : 7/06/2011 11:06:31 a.m.
Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x100000d1
Parameter 1 : 0x7c83e761
Parameter 2 : 0x00000002
Parameter 3 : 0x00000008
Parameter 4 : 0x7c83e761
Caused By Driver :
Caused By Address :
File Description :
Product Name :
Company :
File Version :
Processor : 32-bit
Crash Address :
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini060711-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini060311-18.dmp
Crash Time : 3/06/2011 3:35:42 p.m.
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc000001d
Parameter 2 : 0x805b039e
Parameter 3 : 0xb74f77e8
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+d939e
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Processor : 32-bit
Crash Address : ntoskrnl.exe+d939e
Stack Address 1 : ntoskrnl.exe+d970a
Stack Address 2 : ntoskrnl.exe+16ff1
Stack Address 3 : ntoskrnl.exe+93298
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini060311-18.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini060311-17.dmp
Crash Time : 3/06/2011 2:02:08 p.m.
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000099
Parameter 2 : 0x0000b6fc
Parameter 3 : 0x00000003
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21925
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21925
Stack Address 1 : ntoskrnl.exe+3c4f0
Stack Address 2 : ntoskrnl.exe+47039
Stack Address 3 : ntoskrnl.exe+474ae
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini060311-17.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

Speedy Gonzales
07-06-2011, 02:59 PM
PFN_LIST_CORRUPT is related to memory probs. Test it with memtest

NZHawk
07-06-2011, 03:04 PM
thank you for your reply - but I have run memtest and it passed with one pass - it's actually installing service pack 3 so I will run memtest again and let it run 3 passes.

NZHawk
07-06-2011, 03:59 PM
it's cycled through memtest 3 times - no errors
any further suggestions?

Speedy Gonzales
07-06-2011, 04:07 PM
It needs more than 3 passes. Let it run for a few hours / overnight

NZHawk
07-06-2011, 04:08 PM
ok - report back tomorrow

NZHawk
08-06-2011, 10:16 AM
memtest ran successfully (72 passes) overnight - no errors

Speedy Gonzales
08-06-2011, 10:24 AM
Has it crashed since you installed SP3?

NZHawk
08-06-2011, 10:27 AM
No - haven't really tested that as I moved straight into memtest.
Doing windows updates now - seemingly successful so far.

NZHawk
08-06-2011, 12:26 PM
Bugger - was in the process of rebooting after the Windows updates and Blue Screened:
Stop: 0x0000008E, (0xC0000005...
fltmgr.sys - address F7406CF3 BASE AT F740400, dATEsTAMP 480251DA

???

NZHawk
08-06-2011, 12:38 PM
rebooted another different BSOD:
stop: 0x00000024, (0x001902FE....

NTFS.SYS - Address F7372BE9 base at F734E00 DateStam 48025be5

Speedy Gonzales
08-06-2011, 12:53 PM
0x00000024 isnt a good sign, that can mean the hdd is corrupt / buggered / full of errors. And may have to be replaced

NZHawk
08-06-2011, 12:59 PM
Thank you now based on that is there a thorough hdd diagnostics that can confirm that?

That being said - he did bring it to me in the back of a van.

Samsung SATA 160Gb

Speedy Gonzales
08-06-2011, 01:12 PM
You could try another SATA cable. How is connected to the power?? With a molex adapter, or a SATA connector from the PSU?

Do Samsung have hdd diag programs? You could try defraggler, its got a check drive for errors option (after you install it, right mouse on C / advanced)

http://www.filehippo.com/download_defraggler

NZHawk
08-06-2011, 01:21 PM
How is connected to the power?? SATA connector from the PSU

Do Samsung have hdd diag programs? yes
I have downloaded it & will run it through a couple of times.

Thank you

Speedy Gonzales
08-06-2011, 01:26 PM
Sweet, no probs

NZHawk
14-06-2011, 12:23 PM
I installed a new 500Gb Seagate HDD
Installed alternative ram
clean install of Windows Media Centre
starting to do further install
plugged a usb into the front panel started to copy files onto the desktop and the computer shut down & rebooted.
Could someone look at this event & help me discern what the problem is. - many thanks

==================================================
Dump File : Mini061411-01.dmp
Crash Time : 14/06/2011 11:12:19 a.m.
Bug Check String : BAD_POOL_CALLER
Bug Check Code : 0x000000c2
Parameter 1 : 0x00000007
Parameter 2 : 0x00000cd4
Parameter 3 : 0x04080400
Parameter 4 : 0xe26db008
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21cc5
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21cc5
Stack Address 1 : ntoskrnl.exe+6db86
Stack Address 2 : ntoskrnl.exe+30f3e
Stack Address 3 : ntoskrnl.exe+3265e
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

Speedy Gonzales
14-06-2011, 01:22 PM
Delete everything under usb controllers in device manager, then reboot. Then see what happens.

What if you plug it into a USB port at the back (if its got them)?? Does it still crash?

NZHawk
14-06-2011, 01:24 PM
I unplugged the front usb panels / sd card reader (2)
and then used the rear usb ports - still crashed

NZHawk
14-06-2011, 01:45 PM
Delete everything under usb controllers in device manager, then rebooted.
Tried to do windows updates: started then blue screened:

==================================================
Dump File : Mini061411-05.dmp
Crash Time : 14/06/2011 12:41:57 p.m.
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000002
Parameter 2 : 0x000651d8
Parameter 3 : 0x0002beef
Parameter 4 : 0x000095c3
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21cc5
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21cc5
Stack Address 1 : ntoskrnl.exe+47472
Stack Address 2 : ntoskrnl.exe+35432
Stack Address 3 : ntoskrnl.exe+35e98
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-05.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini061411-04.dmp
Crash Time : 14/06/2011 12:27:22 p.m.
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80526f7f
Parameter 3 : 0xf78bc424
Parameter 4 : 0x00000000
Caused By Driver : win32k.sys
Caused By Address : win32k.sys+529b
File Description : Multi-User Win32 Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6090 (xpsp_sp3_gdr.110303-1621)
Processor : 32-bit
Crash Address : ntoskrnl.exe+4ff7f
Stack Address 1 : ntoskrnl.exe+6dc90
Stack Address 2 : win32k.sys+2a45
Stack Address 3 : win32k.sys+b83
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-04.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini061411-03.dmp
Crash Time : 14/06/2011 11:54:56 a.m.
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000007
Parameter 2 : 0x000292d8
Parameter 3 : 0x000292d7
Parameter 4 : 0x00000000
Caused By Driver : Ntfs.sys
Caused By Address : Ntfs.sys+208e2
File Description : NT File System Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2111)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21cc5
Stack Address 1 : ntoskrnl.exe+48313
Stack Address 2 : ntoskrnl.exe+3521f
Stack Address 3 : ntoskrnl.exe+35e98
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-03.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini061411-02.dmp
Crash Time : 14/06/2011 11:19:58 a.m.
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000099
Parameter 2 : 0x000002fc
Parameter 3 : 0x00000000
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21cc5
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21cc5
Stack Address 1 : ntoskrnl.exe+483db
Stack Address 2 : ntoskrnl.exe+37cd4
Stack Address 3 : ntoskrnl.exe+ce801
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-02.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini061411-01.dmp
Crash Time : 14/06/2011 11:12:19 a.m.
Bug Check String : BAD_POOL_CALLER
Bug Check Code : 0x000000c2
Parameter 1 : 0x00000007
Parameter 2 : 0x00000cd4
Parameter 3 : 0x04080400
Parameter 4 : 0xe26db008
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21cc5
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)
Processor : 32-bit
Crash Address : ntoskrnl.exe+21cc5
Stack Address 1 : ntoskrnl.exe+6db86
Stack Address 2 : ntoskrnl.exe+30f3e
Stack Address 3 : ntoskrnl.exe+3265e
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini061411-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

Speedy Gonzales
14-06-2011, 02:00 PM
Put the old ram back in. It sounds like the new ram you installed is buggered, or something is wrong with it. Make sure you install the ram properly (push the memory sticks right in, and installed the right way). Why the PFN_LIST_CORRUPT stop errors are coming up. Thats ram/memory related

NZHawk
14-06-2011, 02:41 PM
Ok,
Have replaced the ram - will try windows update again
will report back

NZHawk
14-06-2011, 02:42 PM
wont boot, I recheck the ram was seated well.
There are four slots 2 blue (closest to the cpu) and 2 black
The ram is in the two closest to the cpu

Speedy Gonzales
14-06-2011, 02:56 PM
Does it take DDR / 2 or DDR 3 ram why it has 4 slots?? You're not trying to install DDR ram into a mobo that takes DDR 2 or DDR 3 ram are you??

Whats the brand / model of the mobo??

NZHawk
14-06-2011, 03:03 PM
MB model number: A8M2N-LA
in a Compaq Presario SR1925AN

the ram is 2-256 Mb PC4200 DDR2

Speedy Gonzales
14-06-2011, 03:17 PM
This may apply, since this is an AM2 system. And before you install SP3 (if its not installed now)

http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01457284&lc=en&dlc=en&cc=us&os=228&product=3264569&sw_lang=

What happens, if you put the ram in the black slots?? Will it boot? What slots were the old sticks in when it booted?

NZHawk
14-06-2011, 03:28 PM
What happens, if you put the ram in the black slots??
Nothing - wont boot

What slots were the old sticks in when it booted?
black

Speedy Gonzales
14-06-2011, 03:36 PM
Hmm does it beep then when it doesnt boot? Or does it do anything?

NZHawk
14-06-2011, 03:38 PM
no no sounds other than the fans

Speedy Gonzales
14-06-2011, 03:48 PM
Something sounds stuffed to me. If new ram wont work in the same slots, the old ram worked in. Or the new ram isnt compatible, or something. Or its dead

NZHawk
14-06-2011, 03:56 PM
I am inclined to believe "or its dead"
- the original ram test 7hrs +
- new hard drive - wont boot with original ram
- replace ram same slots - boots but starts to crash
the inconsistency in the errors & performance will lead me to believe that it's deteriorating

Speedy Gonzales
14-06-2011, 04:00 PM
I would try and find another AM2 mobo and case. Remove the CPU, put it on the new mobo. And biff the case and PSU. And buy another case and PSU

NZHawk
14-06-2011, 04:05 PM
thank you for your help through out this saga.
will take your advise on board.