Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Internet & Networking > Internet Explorer

Internet Explorer Post your Internet Explorer questions here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 26th May 2009   #1
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


IE gives Blue screen then restart the PC

Hello Everyone

well this is my first post as I am a new member
I have a problem with IE. Simply when I tried to run IE the computer gives me a blue screen then a restart. after that and when I logged again to my system windows displays a massage "The has recovered from a serious error" or something like that.

I have tried to upgrade to IE7and IE8 but still the same problem

I can access the net using Firefox

I have checked my system for viruses spyware and Maleware but it is clean

any suggestions. Thanks

waelnour is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 26th May 2009   #2
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Welcome to WindowsBBS

Always helps to post your OS otherwise we are in the dark.

First set up the computer not to restart after a system failure and post the Stop message, if any from the blue screen ....

Quote:
Control Panel > System > Advanced > Startup and Recovery > Settings ....

Under System failure uncheck 'Automatically restart' and under Write debugging information select 'Kernel memory dump' from the dropdown list and OK out.

The computer will now show the BSOD in the event of a System failure giving details of the Stop message and the contents of the memory will be dumped to disk.
Try starting IE with no-add-ons ....

Right click IE icon on desktop > Start without add-ons, or .....

Start > Programs > Accessories > System Tools - IE (no add-ons)

Does this solve the problem?

PeteC is offline   Reply With Quote
Old 27th May 2009   #3
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Thank you PeteC for your reply

well I always do mistakes when I am angry. I forgot to write that I have XP pro.

OK I have done what you have told me and know I can see what is written in the blue screen.

The only thing I was able to understood that maybe there is some error in "tcpip.sys" file.


IE without add-ons is not working it gives me an error message "The file does not have a program associated with it for preforming this action ......." and that happens only when I select "NoAddOns"

I am not sure what to do with the dump file I was able to view the "memory.dmp" file using "dumpchk.exe"

I do not know what to do next

waelnour is offline   Reply With Quote
Old 27th May 2009   #4
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Let's see tha debug log of the dump data = please follow the instructions here and note .....
Quote:
Unfortunately these logs require expert knowledge to analyze and there are currently no members that have the depth of knowledge necessary. Members can only make observations and suggestions as to how you might proceed toward finding the cause ....
Which version of IE is installed at present and which XP Service Pack is installed?

PeteC is offline   Reply With Quote
Old 27th May 2009   #5
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


widows XP SP3 & (currently) IE 6. I have tried to upgrade to 7 & 8 but i am facing the same problem!
waelnour is offline   Reply With Quote
Old 27th May 2009   #6
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Is the upgrade 'successful', but the problem remains with 7 & 8?
PeteC is offline   Reply With Quote
Old 27th May 2009   #7
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Yes, and when I double click the application icon it starts to run giving me the first blank window for 3 sec. then blue screen
waelnour is offline   Reply With Quote
Old 27th May 2009   #8
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Let's see the dump log - post #4
PeteC is offline   Reply With Quote
Old 27th May 2009   #9
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Fine. I am downloading the Debugging Tools right now
waelnour is offline   Reply With Quote
Old 27th May 2009   #10
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Finish downloading and creation the log file.

Now what should I do?

waelnour is offline   Reply With Quote
Old 27th May 2009   #11
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Open the file & copy/paste contents into your next post here.
PeteC is offline   Reply With Quote
Old 27th May 2009   #12
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Opened log file 'c:debuglog.txt'

Microsoft (R) Windows Debugger Version 6.8.0004.0 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOW\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: C:\WINDOW;C:\WINDOW\system32;C:\WINDOW\system32\drivers
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp3_gdr.090206-1234
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Wed May 27 11:57:36.406 2009 (GMT+3)
System Uptime: 0 days 0:56:44.124
Loading Kernel Symbols
........................................................................... ...............................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details
Loading unloaded module list
..........
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****

Use !analyze -v to get detailed debugging information.

BugCheck 8E, {c0000005, ed9d4217, b75cd7c0, 0}

*** ERROR: Module load completed but symbols could not be loaded for kl1.sys
*** ERROR: Module load completed but symbols could not be loaded for bckd.sys

PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details
Probably caused by : kl1.sys ( kl1+2177 )

Followup: MachineOwner
---------

1: kd> !analyze -v;r;kv;lmtn;.logclose;q
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****

KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: ed9d4217, The address that the exception occurred at
Arg3: b75cd7c0, Trap Frame
Arg4: 00000000

Debugging Details:
------------------


PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
tcpip!TCPCreate+75
ed9d4217 89710c mov dword ptr [ecx+0Ch],esi

TRAP_FRAME: b75cd7c0 -- (.trap 0xffffffffb75cd7c0)
.trap 0xffffffffb75cd7c0
ErrCode = 00000002
eax=856154ac ebx=00000000 ecx=03000100 edx=47fd0001 esi=85f4f258 edi=00000000
eip=ed9d4217 esp=b75cd834 ebp=b75cd868 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
tcpip!TCPCreate+0x75:
ed9d4217 89710c mov dword ptr [ecx+0Ch],esi ds:0023:0300010c=????????
.trap
Resetting default scope

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x8E

PROCESS_NAME: explorer.exe

LAST_CONTROL_TRANSFER: from 804fe827 to 804f9f43

STACK_TEXT:
b75cd388 804fe827 0000008e c0000005 ed9d4217 nt!KeBugCheckEx+0x1b
b75cd750 80542095 b75cd76c 00000000 b75cd7c0 nt!KiDispatchException+0x3b1
b75cd7b8 80542046 b75cd868 ed9d4217 badb0d00 nt!CommonDispatchException+0x4d
b75cd868 ed9944b4 865d9350 856153d0 856154ac nt!Kei386EoiHelper+0x18a
b75cd868 ed9944b4 865d9350 856153d0 856154ac tcpip!TCPDispatch+0x10b
b75cd8a4 804ef19f 865d9350 856153d0 856153d0 tcpip!TCPDispatch+0x10b
b75cd8e0 f7306177 865ec588 856153d0 862540d0 nt!IopfCallDriver+0x31
WARNING: Stack unwind information not available. Following frames may be wrong.
b75cd908 804ef19f 865ec588 856153d0 858f6fa8 kl1+0x2177
b75cd918 ed930851 855da4f8 858f6fa8 855da440 nt!IopfCallDriver+0x31
00000000 00000000 00000000 00000000 00000000 bckd+0x8851


STACK_COMMAND: kb

FOLLOWUP_IP:
kl1+2177
f7306177 5f pop edi

SYMBOL_STACK_INDEX: 7

SYMBOL_NAME: kl1+2177

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: kl1

IMAGE_NAME: kl1.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4805d347

FAILURE_BUCKET_ID: 0x8E_kl1+2177

BUCKET_ID: 0x8E_kl1+2177

Followup: MachineOwner
---------

eax=f787313c ebx=ed9d4217 ecx=00000000 edx=80546e22 esi=b75cd76c edi=00000000
eip=804f9f43 esp=b75cd370 ebp=b75cd388 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
nt!KeBugCheckEx+0x1b:
804f9f43 5d pop ebp
ChildEBP RetAddr Args to Child
b75cd388 804fe827 0000008e c0000005 ed9d4217 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
b75cd750 80542095 b75cd76c 00000000 b75cd7c0 nt!KiDispatchException+0x3b1 (FPO: [Non-Fpo])
b75cd7b8 80542046 b75cd868 ed9d4217 badb0d00 nt!CommonDispatchException+0x4d (FPO: [0,20,0])
b75cd868 ed9944b4 865d9350 856153d0 856154ac nt!Kei386EoiHelper+0x18a
b75cd868 ed9944b4 865d9350 856153d0 856154ac tcpip!TCPDispatch+0x10b (FPO: [Non-Fpo])
b75cd8a4 804ef19f 865d9350 856153d0 856153d0 tcpip!TCPDispatch+0x10b (FPO: [Non-Fpo])
b75cd8e0 f7306177 865ec588 856153d0 862540d0 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
WARNING: Stack unwind information not available. Following frames may be wrong.
b75cd908 804ef19f 865ec588 856153d0 858f6fa8 kl1+0x2177
b75cd918 ed930851 855da4f8 858f6fa8 855da440 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
00000000 00000000 00000000 00000000 00000000 bckd+0x8851
start end module name
804d7000 806e4000 nt ntkrpamp.exe Fri Feb 06 12:32:51 2009 (498C11D3)
806e4000 80704d00 hal halmacpi.dll Sun Apr 13 20:31:27 2008 (4802517F)
b753b000 b7565180 kmixer kmixer.sys Sun Apr 13 20:45:07 2008 (480254B3)
b7566000 b757d900 dump_atapi dump_atapi.sys Sun Apr 13 20:40:29 2008 (4802539D)
b7b73000 b7bb3a80 HTTP HTTP.sys Sun Apr 13 20:53:48 2008 (480256BC)
b7fc4000 b7fd8480 wdmaud wdmaud.sys Sun Apr 13 21:17:18 2008 (48025C3E)
b81e1000 b8232880 srv srv.sys Thu Dec 11 12:57:07 2008 (4940F203)
b83c3000 b83ef180 mrxdav mrxdav.sys Sun Apr 13 20:32:42 2008 (480251CA)
b86d8000 b86db900 ndisuio ndisuio.sys Sun Apr 13 20:55:57 2008 (4802573D)
b87c8000 b87d6d80 sysaudio sysaudio.sys Sun Apr 13 21:15:55 2008 (48025BEB)
bf000000 bf011600 dxg dxg.sys Sun Apr 13 20:38:27 2008 (48025323)
bf012000 bf063000 ati2dvag ati2dvag.dll Mon Dec 01 22:51:31 2008 (49344E53)
bf063000 bf0f0000 ati2cqag ati2cqag.dll Mon Dec 01 21:45:31 2008 (49343EDB)
bf0f0000 bf163000 atikvmag atikvmag.dll Mon Dec 01 21:53:35 2008 (493440BF)
bf163000 bf1ad000 atiok3x2 atiok3x2.dll Mon Dec 01 21:50:52 2008 (4934401C)
bf1ad000 bf59af40 ati3duag ati3duag.dll Mon Dec 01 22:27:51 2008 (493448C7)
bf59b000 bf7fc380 ativvaxx ativvaxx.dll Mon Dec 01 22:11:52 2008 (49344508)
bf800000 bf9c2e00 win32k win32k.sys Mon Feb 09 13:13:13 2009 (49900FC9)
ed7d2000 ed841280 mrxsmb mrxsmb.sys Fri Oct 24 13:21:07 2008 (4901AFA3)
ed842000 ed86ce80 rdbss rdbss.sys Sun Apr 13 21:28:38 2008 (48025EE6)
ed86d000 ed88e000 SASKUTIL SASKUTIL.sys Tue Apr 29 00:17:42 2008 (48163EF6)
ed8da000 ed8dc900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
ed8de000 ed8ffd00 afd afd.sys Thu Aug 14 13:04:35 2008 (48A40333)
ed900000 ed927c00 netbt netbt.sys Sun Apr 13 21:20:59 2008 (48025D1B)
ed928000 ed93c000 bckd bckd.sys Wed Jan 14 01:38:05 2009 (496D25DD)
ed93c000 ed961500 ipnat ipnat.sys Sun Apr 13 20:57:10 2008 (48025786)
ed98a000 ed9e2480 tcpip tcpip.sys Fri Jun 20 14:51:09 2008 (485B99AD)
ed9e3000 ed9f5600 ipsec ipsec.sys Sun Apr 13 21:19:42 2008 (48025CCE)
edbb1000 edbe9000 klif klif.sys Thu Jan 29 15:06:28 2009 (4981A9D4)
edc5b000 edc7ea80 portcls portcls.sys Sun Apr 13 21:19:40 2008 (48025CCC)
edc7f000 ee130000 RtkHDAud RtkHDAud.sys Thu Jul 24 13:02:34 2008 (4888533A)
f61b7000 f6214f00 update update.sys Sun Apr 13 20:39:46 2008 (48025372)
f6215000 f6244e80 rdpdr rdpdr.sys Sun Apr 13 20:32:50 2008 (480251D2)
f6245000 f6255e00 psched psched.sys Sun Apr 13 20:56:36 2008 (48025764)
f6256000 f626c580 ndiswan ndiswan.sys Sun Apr 13 21:20:41 2008 (48025D09)
f626d000 f628f700 ks ks.sys Sun Apr 13 21:16:34 2008 (48025C12)
f6290000 f62a3900 parport parport.sys Sun Apr 13 20:40:09 2008 (48025389)
f62a4000 f62c7200 USBPORT USBPORT.SYS Sun Apr 13 20:45:34 2008 (480254CE)
f62c8000 f62e4480 Rtenicxp Rtenicxp.sys Thu Oct 16 08:00:30 2008 (48F6D87E)
f62e5000 f630d000 HDAudBus HDAudBus.sys Thu May 26 18:46:29 2005 (4295EF55)
f630d000 f6320f00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 20:44:39 2008 (48025497)
f6321000 f6855000 ati2mtag ati2mtag.sys Mon Dec 01 22:51:07 2008 (49344E3B)
f6855000 f685d900 msgpc msgpc.sys Sun Apr 13 20:56:32 2008 (48025760)
f6865000 f6870d00 raspptp raspptp.sys Sun Apr 13 21:19:47 2008 (48025CD3)
f6875000 f687f200 raspppoe raspppoe.sys Sun Apr 13 20:57:31 2008 (4802579B)
f6885000 f6891880 rasl2tp rasl2tp.sys Sun Apr 13 21:19:43 2008 (48025CCF)
f6895000 f68a3100 redbook redbook.sys Sun Apr 13 20:40:27 2008 (4802539B)
f68a5000 f68b4600 cdrom cdrom.sys Sun Apr 13 20:40:45 2008 (480253AD)
f68b5000 f68bf480 imapi imapi.sys Sun Apr 13 20:40:57 2008 (480253B9)
f68c5000 f68d1d00 i8042prt i8042prt.sys Sun Apr 13 21:17:59 2008 (48025C67)
f68d5000 f68e4c00 serial serial.sys Sun Apr 13 21:15:44 2008 (48025BE0)
f68e5000 f68ee000 klfltdev klfltdev.sys Thu Mar 13 17:02:27 2008 (47D94203)
f71d3000 f71d6c80 mssmbios mssmbios.sys Sun Apr 13 20:36:45 2008 (480252BD)
f71eb000 f71ed780 ndistapi ndistapi.sys Sun Apr 13 20:57:27 2008 (48025797)
f7304000 f7321000 kl1 kl1.sys Wed Apr 16 12:21:59 2008 (4805D347)
f7321000 f733ab80 Mup Mup.sys Sun Apr 13 21:17:05 2008 (48025C31)
f733b000 f7367980 NDIS NDIS.sys Sun Apr 13 21:20:35 2008 (48025D03)
f7368000 f73f4600 Ntfs Ntfs.sys Sun Apr 13 21:15:49 2008 (48025BE5)
f73f5000 f740b880 KSecDD KSecDD.sys Sun Apr 13 20:31:40 2008 (4802518C)
f740c000 f741df00 sr sr.sys Sun Apr 13 20:36:50 2008 (480252C2)
f741e000 f743db00 fltmgr fltmgr.sys Sun Apr 13 20:32:58 2008 (480251DA)
f743e000 f7455900 atapi atapi.sys Sun Apr 13 20:40:29 2008 (4802539D)
f7456000 f747b700 dmio dmio.sys Sun Apr 13 20:44:45 2008 (4802549D)
f747c000 f749a880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
f749b000 f74aba80 pci pci.sys Sun Apr 13 20:36:43 2008 (480252BB)
f74ac000 f74d9d80 ACPI ACPI.sys Sun Apr 13 20:36:33 2008 (480252B1)
f75db000 f75e4180 isapnp isapnp.sys Sun Apr 13 20:36:40 2008 (480252B8)
f75eb000 f75f5580 MountMgr MountMgr.sys Sun Apr 13 20:39:45 2008 (48025371)
f75fb000 f7607c80 VolSnap VolSnap.sys Sun Apr 13 20:41:00 2008 (480253BC)
f760b000 f7613e00 disk disk.sys Sun Apr 13 20:40:46 2008 (480253AE)
f761b000 f7627180 CLASSPNP CLASSPNP.SYS Sun Apr 13 21:16:21 2008 (48025C05)
f762b000 f7636000 klbg klbg.sys Mon Dec 15 18:41:09 2008 (494688A5)
f763b000 f7643b80 PxHelp20 PxHelp20.sys Fri Feb 02 23:23:57 2007 (45C3ABED)
f775b000 f7763e00 intelppm intelppm.sys Sun Apr 13 20:31:31 2008 (48025183)
f776b000 f7774f00 termdd termdd.sys Sun Apr 13 20:38:36 2008 (4802532C)
f777b000 f7784e80 NDProxy NDProxy.SYS Sun Apr 13 20:57:28 2008 (48025798)
f77ab000 f77b9b00 drmk drmk.sys Sun Apr 13 20:45:12 2008 (480254B8)
f77bb000 f77c9880 usbhub usbhub.sys Sun Apr 13 20:45:36 2008 (480254D0)
f77eb000 f77f3700 wanarp wanarp.sys Sun Apr 13 20:57:20 2008 (48025790)
f77fb000 f7803780 netbios netbios.sys Sun Apr 13 20:56:01 2008 (48025741)
f780b000 f7818000 SCDEmu SCDEmu.SYS Sun Nov 02 10:44:10 2008 (490D685A)
f781b000 f7827380 ikhlayer ikhlayer.sys Mon Dec 12 01:09:56 2005 (439CB1C4)
f782b000 f7835e00 Fips Fips.SYS Sun Apr 13 20:33:27 2008 (480251F7)
f783b000 f784a900 Cdfs Cdfs.SYS Sun Apr 13 21:14:21 2008 (48025B8D)
f785b000 f7861180 PCIIDEX PCIIDEX.SYS Sun Apr 13 20:40:29 2008 (4802539D)
f7863000 f7867d00 PartMgr PartMgr.sys Sun Apr 13 20:40:48 2008 (480253B0)
f786b000 f786fa80 TDI TDI.SYS Sun Apr 13 21:00:04 2008 (48025834)
f78b3000 f78b8080 usbuhci usbuhci.sys Sun Apr 13 20:45:34 2008 (480254CE)
f78bb000 f78c2600 usbehci usbehci.sys Sun Apr 13 20:45:34 2008 (480254CE)
f78c3000 f78c9b00 fdc fdc.sys Sun Apr 13 20:40:25 2008 (48025399)
f78cb000 f78d0a00 mouclass mouclass.sys Sun Apr 13 20:39:47 2008 (48025373)
f78d3000 f78d9000 kbdclass kbdclass.sys Sun Apr 13 20:39:46 2008 (48025372)
f78db000 f78e1000 gdihook5 gdihook5.sys Thu Oct 09 12:37:13 2008 (48EDDED9)
f78e3000 f78eb000 klim5 klim5.sys Tue Mar 25 18:06:52 2008 (47E9231C)
f78eb000 f78ef580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
f78f3000 f78f7080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
f78fb000 f7900000 flpydisk flpydisk.sys Sun Apr 13 20:40:24 2008 (48025398)
f790b000 f7913000 pcisys pcisys.sys Thu Oct 09 12:37:10 2008 (48EDDED6)
f7913000 f7918200 vga vga.sys Sun Apr 13 20:44:40 2008 (48025498)
f791b000 f791fa80 Msfs Msfs.SYS Sun Apr 13 20:32:38 2008 (480251C6)
f7923000 f792a880 Npfs Npfs.SYS Sun Apr 13 20:32:38 2008 (480251C6)
f792b000 f7932000 SASDIFSV SASDIFSV.SYS Wed Apr 16 23:39:35 2008 (48067217)
f7943000 f7947500 watchdog watchdog.sys Sun Apr 13 20:44:59 2008 (480254AB)
f79bb000 f79c1b00 npf npf.sys Tue Nov 06 22:09:15 2007 (4730C9EB)
f79eb000 f79ee000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
f7a9b000 f7a9ed00 FolderProtectDriver FolderProtectDriver.sys Fri Jan 11 08:46:58 2008 (478710E2)
f7a9f000 f7aa1280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
f7aab000 f7aaed80 serenum serenum.sys Sun Apr 13 20:40:12 2008 (4802538C)
f7adb000 f7adcb80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
f7add000 f7ade100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
f7adf000 f7ae0700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
f7b3b000 f7b3c100 swenum swenum.sys Sun Apr 13 20:39:52 2008 (48025378)
f7b3f000 f7b40280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
f7b41000 f7b42f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
f7b43000 f7b44080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
f7b45000 f7b46080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
f7b47000 f7b48080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
f7b53000 f7b54100 dump_WMILIB dump_WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
f7b85000 f7b86a80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
f7ba3000 f7ba3d00 pciide pciide.sys Fri Aug 17 23:51:49 2001 (3B7D83E5)
f7c26000 f7c26b80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
f7c5b000 f7c5bd00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)
f7d19000 f7d19c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)

Unloaded modules:
ece02000 ece1a000 dump_atapi.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
b7553000 b757e000 kmixer.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
b7f76000 b7fa1000 kmixer.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f7cf0000 f7cf1000 drmkaud.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
b7fa1000 b7fc4000 aec.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
b8129000 b8136000 DMusic.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
b8139000 b8147000 swmidi.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f7b2b000 f7b2d000 splitter.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f7903000 f7908000 Cdaudio.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
f7a8f000 f7a92000 Sfloppy.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
Closing open log file c:debuglog.txt

waelnour is offline   Reply With Quote
Old 27th May 2009   #13
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Bearing in mind the rider I posted earlier ....
Quote:
Unfortunately these logs require expert knowledge to analyze and there are currently no members that have the depth of knowledge necessary. Members can only make observations and suggestions as to how you might proceed toward finding the cause ....
I will give you my 2 cents worth ....
Quote:
PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details
Probably caused by : kl1.sys ( kl1+2177 )
This is part of Kaspersky which I guess you have installed? See http://www.bleepingcomputer.com/star...sys-15140.html
Quote:
*** ERROR: Module load completed but symbols could not be loaded for bckd.sys
Info on this is scanty and Previx lists it as possible malware, but I would need to refer you to the Malware & Virus Removal forum for a realistic opinion.
Quote:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
You may have a memory problem, but the more likely cause is your AV .....
Quote:
0x00000005: INVALID_PROCESS_ATTACH_ATTEMPT
Generally, use the General Troubleshooting of STOP Messages checklist above to troubleshoot this problem. A specific problem is known to exist with Win XP SP2 and Server 2003 in combination with certain antivirus programs, firewalls, and similar software; see the article linked below for details and current status of a fix from Microsoft.
So the bottom line is that your problem may be caused by your AV, which is Kasperky?

PeteC is offline   Reply With Quote
Old 28th May 2009   #14
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 4,603
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System

Please, upload following files to http://www.virustotal.com/ for security check:
bckd.sys file located in c:\windows\system32\drivers
Post scan results.

Some infection is very possible in this case here. Check the above file, first, though.

broni is offline   Reply With Quote
Old 31st May 2009   #15
Member
 
Profile:
Join Date: May 2009
Posts: 15
Computer Experience:
Intermediate
waelnour Reputation Level


Sorry for my late response (out of the office)

Broni,
Here is the result link analisis/d7a61423734a70aa700bd99a8d56d09454c832dbabce89dcc14317ff49c9631b-1240917311
All results are (-)

By the way I have tried to run "Internet Explorer"in windows "safe mode with network support"
And it is working

first time when windows safe mode listing the loaded files it reached the file "TDI.SYS" then the computer restart by it self.
again I ran windows in safe mode and it is OK this time and also IE works ?

Do you think it is one of windows files ?

waelnour is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
shows blue Stop Error Screen bobm735 Windows XP 1 2nd June 2007 08:59
'Blue Screen of Death' BrynTheSkits Windows XP 13 14th May 2007 11:46
blue screen: driver or memory fault? Ulrike Windows XP 3 19th April 2007 23:33
Hotkey to stop windows blue screen loop... PGrass Windows XP 3 1st December 2004 04:31
Blue screen (no message) but I hear sound anthonyl Windows XP 3 1st November 2004 07:19


All times are GMT +1. The time now is 11:03.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]