troubleshooting Question

I think I may have a rootkit, but how can I be sure?

Avatar of allgoodusrnamesaretaken
allgoodusrnamesaretaken asked on
Windows XPAnti-Spyware
7 Comments1 Solution465 ViewsLast Modified:
I have 4 or five workstations (XP SP3) that are randomly restarting themselves during the day.  The event logs show the following System Event each time:
Source: System error
Category: (102)
ID: 1003
Description: Error Code 1000008e, parameter1 c0000005, param2 xxxxx, param3 xxxxx, param4 xxxx

From what I have seen while researching this, it is possibly a rootkit.  How can I determine this for sure?  I have atached a minidump from one of the machines that i can't make anything out of.  I've found some possible links on this site, but they are all 3 to 4 years old.  Help Please!
Mini092410-02.dmp
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 7 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros