1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Blue Screen bugcheck.

Discussion in 'Windows XP' started by hallan, 2006/03/13.

  1. 2006/03/13
    hallan

    hallan Inactive Thread Starter

    Joined:
    2006/03/10
    Messages:
    4
    Likes Received:
    0
    Hi,

    I've been getting random Blue Screen bugchecks on my XP Laptop, but unfortunately the Save Dump does not contain any Process Exceptions that could point me in the direction of a problem process.

    So I have enabled the Special Pool feature to try and trap the offending driver, and after two days with this option turned on! I finally got a Blue Screen, not that I was looking forward to it :(

    The information onscreen specified that the error was likely caused by the file:
    filespy5.sys, which worried me until I found out it was part of my Bullguard AV software, the FileScanner to be precise.

    Below is the original bugcheck before Special Pool was enabled, and then the one after.

    I was hoping that someone could provide further analysis for me on the specifics of the dump.
    In addition the Memory.DMP file saved from the Special Pool feature does not contain the same information that was Onscreen when the bugcheck occurred, is there anyway for me to retrieve this information, or do I have to enable something else for it to be saved?

    Here are the regkeys I have entered to enable Special Pool.:
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management]
    "PoolTag "=dword:0000002a
    "PoolTagOverruns "=dword:00000001

    EventID 1001 (Before Special Pool)
    The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007f (0x00000008, 0x80042000, 0x00000000, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP.

    Dump File (Before Special Pool)
    Loading dump file Mini031106-04.dmp
    ----- 32 bit Kernel Mini Dump Analysis

    DUMP_HEADER32:
    MajorVersion 0000000f
    MinorVersion 00000a28
    DirectoryTableBase 0aa804c0
    PfnDataBase 80557b48
    PsLoadedModuleList 805531a0
    PsActiveProcessHead 80559258
    MachineImageType 0000014c
    NumberProcessors 00000001
    BugCheckCode 1000007f
    BugCheckParameter1 00000008
    BugCheckParameter2 80042000
    BugCheckParameter3 00000000
    BugCheckParameter4 00000000
    PaeEnabled 00000001
    KdDebuggerDataBlock 80544ce0
    MiniDumpFields 000004ff

    TRIAGE_DUMP32:
    ServicePackBuild 00000200
    SizeOfDump 00010000
    ValidOffset 0000fffc
    ContextOffset 00000320
    ExceptionOffset 000007d0
    MmOffset 00001068
    UnloadedDriversOffset 000010a0
    PrcbOffset 00001878
    ProcessOffset 00002268
    ThreadOffset 000024c0
    CallStackOffset 00002720
    SizeOfCallStack 00004000
    DriverListOffset 000069b0
    DriverCount 000000be
    StringPoolOffset 0000a218
    StringPoolSize 000031a0
    BrokenDriverOffset 00000000
    TriageOptions ffffffff
    TopOfStack f7a19000
    DebuggerDataOffset 00006720
    DebuggerDataSize 00000290


    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Built by: 2600.xpsp_sp2_gdr.050301-1519
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Sat Mar 11 21:23:17 2006
    System Uptime: 0 days 2:02:53
    start end module name
    804d7000 806cd280 nt Checksum: 001F632B Timestamp: Wed Mar 02 00:34:37 2005 (42250A1D)

    Unloaded modules:
    b8523000 b854d000 kmixer.sys Timestamp: unavailable (00000000)
    b8d4d000 b8d77000 kmixer.sys Timestamp: unavailable (00000000)
    f44a4000 f44a7000 mouhid.sys Timestamp: unavailable (00000000)
    b96b7000 b96e1000 kmixer.sys Timestamp: unavailable (00000000)
    b99d3000 b99fd000 kmixer.sys Timestamp: unavailable (00000000)
    ba87e000 ba8a8000 kmixer.sys Timestamp: unavailable (00000000)
    f7c39000 f7c3a000 drmkaud.sys Timestamp: unavailable (00000000)
    ba8a8000 ba8cb000 aec.sys Timestamp: unavailable (00000000)
    bab4d000 bab5a000 DMusic.sys Timestamp: unavailable (00000000)
    f21a4000 f21b2000 swmidi.sys Timestamp: unavailable (00000000)
    f7b48000 f7b4a000 splitter.sys Timestamp: unavailable (00000000)
    babe9000 babfd000 Parport.SYS Timestamp: unavailable (00000000)
    f69a7000 f69b2000 p3.sys Timestamp: unavailable (00000000)
    f7910000 f7915000 Cdaudio.SYS Timestamp: unavailable (00000000)
    f6a12000 f6a15000 Sfloppy.SYS Timestamp: unavailable (00000000)

    Finished dump check

    EventID 1001 (Special Pool Enabled)
    The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d5 (0xa771afc0, 0x00000000, 0xf7929b25, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP.

    Dump File (Special Pool Enabled)
    Loading dump file MEMORY_SpecialPool-1.DMP
    ----- 32 bit Kernel Summary Dump Analysis

    DUMP_HEADER32:
    MajorVersion 0000000f
    MinorVersion 00000a28
    DirectoryTableBase 30240580
    PfnDataBase 818e6000
    PsLoadedModuleList 805531a0
    PsActiveProcessHead 80559258
    MachineImageType 0000014c
    NumberProcessors 00000001
    BugCheckCode 000000d5
    BugCheckParameter1 a771afc0
    BugCheckParameter2 00000000
    BugCheckParameter3 f7929b25
    BugCheckParameter4 00000000
    PaeEnabled 00000001
    KdDebuggerDataBlock 80544ce0

    SUMMARY_DUMP32:
    DumpOptions 504d4453
    HeaderSize 00009000
    BitmapSize 0003fee0
    Pages 000171bd
    Bitmap.SizeOfBitMap 0003fee0

    KiProcessorBlock at 80552020
    1 KiProcessorBlock entries:
    ffdff120


    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Built by: 2600.xpsp_sp2_gdr.050301-1519
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Mon Mar 13 11:33:27 2006
    System Uptime: 0 days 1:59:07
    start end module name
    804d7000 806cd280 nt Checksum: 001F632B Timestamp: Wed Mar 02 00:34:37 2005 (42250A1D)

    Unloaded modules:
    b5957000 b5981000 kmixer.sys Timestamp: Mon Mar 13 10:51:40 2006 (44154EBC)
    b7207000 b7231000 kmixer.sys Timestamp: Mon Mar 13 10:08:10 2006 (4415448A)
    b8375000 b839f000 kmixer.sys Timestamp: Mon Mar 13 09:43:53 2006 (44153ED9)
    ba6fe000 ba728000 kmixer.sys Timestamp: Mon Mar 13 09:36:16 2006 (44153D10)
    f7c48000 f7c49000 drmkaud.sys Timestamp: Mon Mar 13 09:35:35 2006 (44153CE7)
    ba728000 ba74b000 aec.sys Timestamp: Mon Mar 13 09:35:35 2006 (44153CE7)
    bac0f000 bac1c000 DMusic.sys Timestamp: Mon Mar 13 09:35:35 2006 (44153CE7)
    baac3000 baad1000 swmidi.sys Timestamp: Mon Mar 13 09:35:35 2006 (44153CE7)
    f7b3a000 f7b3c000 splitter.sys Timestamp: Mon Mar 13 09:35:35 2006 (44153CE7)
    ba774000 ba788000 Parport.SYS Timestamp: Mon Mar 13 09:35:02 2006 (44153CC6)
    f6d64000 f6d6f000 p3.sys Timestamp: Mon Mar 13 09:34:40 2006 (44153CB0)
    f7928000 f792d000 Cdaudio.SYS Timestamp: Mon Mar 13 09:34:40 2006 (44153CB0)
    f6e0f000 f6e12000 Sfloppy.SYS Timestamp: Mon Mar 13 09:34:40 2006 (44153CB0)

    Finished dump check
     
  2. 2006/03/13
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Run the dump file through our tool.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2006/03/13
    hallan

    hallan Inactive Thread Starter

    Joined:
    2006/03/10
    Messages:
    4
    Likes Received:
    0
    Ahh, thanks, here is the output:

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.6.0003.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\MEMORY_SpecialPool-1.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.050301-1519
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Mon Mar 13 11:33:27.140 2006 (GMT+0)
    System Uptime: 0 days 1:59:07.732
    Loading Kernel Symbols
    ...............................................................................................................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
    Loading unloaded module list
    .............
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D5, {a771afc0, 0, f7929b25, 0}

    *** ERROR: Module load completed but symbols could not be loaded for filespy5.sys
    *** ERROR: Module load completed but symbols could not be loaded for wpsdrvnt.sys
    Probably caused by : filespy5.sys ( filespy5+1b25 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    DRIVER_PAGE_FAULT_IN_FREED_SPECIAL_POOL (d5)
    Memory was referenced after it was freed.
    This cannot be protected by try-except.
    When possible, the guilty driver's name (Unicode string) is printed on
    the bugcheck screen and saved in KiBugCheckDriver.
    Arguments:
    Arg1: a771afc0, memory referenced
    Arg2: 00000000, value 0 = read operation, 1 = write operation
    Arg3: f7929b25, if non-zero, the address which referenced memory.
    Arg4: 00000000, (reserved)

    Debugging Details:
    ------------------


    READ_ADDRESS: a771afc0 Special pool

    FAULTING_IP:
    filespy5+1b25
    f7929b25 668b4930 mov cx,[ecx+0x30]

    MM_INTERNAL_CODE: 0

    IMAGE_NAME: filespy5.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4339671c

    MODULE_NAME: filespy5

    FAULTING_MODULE: f7928000 filespy5

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xD5

    LAST_CONTROL_TRANSFER: from 8051bf07 to 804f8925

    STACK_TEXT:
    f4894938 8051bf07 00000050 a771afc0 00000000 nt!KeBugCheckEx+0x1b
    f4894998 8053f6ec 00000000 a771afc0 00000000 nt!MmAccessFault+0x8e7
    f4894998 f7929b25 00000000 a771afc0 00000000 nt!KiTrap0E+0xcc
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f4894a3c f792a593 a6bd4f90 9a4d8fc0 850f8000 filespy5+0x1b25
    f4894b14 804eddf9 9a4d8f08 8588bd08 8588bd08 filespy5+0x2593
    f4894b24 80577ad6 a6bd4f78 8747ae70 00000001 nt!IopfCallDriver+0x31
    f4894b58 805b0beb 9c8d4da0 9a4d8f08 00120089 nt!IopCloseFile+0x27c
    f4894b88 805b053f 9c8d4da0 a6bd4f90 8747ae70 nt!ObpDecrementHandleCount+0x119
    f4894bb0 805b6cfb 9a20efb8 a6bd4f90 000007d8 nt!ObpCloseHandleTableEntry+0x14d
    f4894bd0 80602c4d e108bfb0 000007d8 f4894c20 nt!ObpCloseHandleProcedure+0x1f
    f4894c00 805b6df4 9a20efb8 805b6cdc f4894c20 nt!ExSweepHandleTable+0x4f
    f4894c2c 805c7177 9c8d4da0 9d5a0da8 9d5a0ff0 nt!ObKillProcess+0x5c
    f4894cd4 805c73d0 00000000 9d5a0da8 00000000 nt!PspExitThread+0x5e9
    f4894cf4 805c75ab 9d5a0da8 00000000 f4894d58 nt!PspTerminateThreadByPointer+0x52
    f4894d20 f7991e85 00000000 00000000 f4894d64 nt!NtTerminateProcess+0x105
    f4894ddc 80540fa2 bacecb85 9ff42fc8 00000000 wpsdrvnt+0x1e85
    f4894de0 bacecb84 9ff42fc8 00000000 0000027f nt!KiThreadStartup+0x16
    f4894de4 9ff42fc8 00000000 0000027f 00000000 NDIS!___PchSym_+0xc
    f4894de8 00000000 0000027f 00000000 00000000 0x9ff42fc8


    STACK_COMMAND: .bugcheck ; kb

    FOLLOWUP_IP:
    filespy5+1b25
    f7929b25 668b4930 mov cx,[ecx+0x30]

    SYMBOL_STACK_INDEX: 3

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: filespy5+1b25

    FAILURE_BUCKET_ID: 0xD5_filespy5+1b25

    BUCKET_ID: 0xD5_filespy5+1b25

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00000000 ecx=00000000 edx=80540fed esi=c053b8d0 edi=00000000
    eip=804f8925 esp=f4894920 ebp=f4894938 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8925 5d pop ebp
    ChildEBP RetAddr Args to Child
    f4894938 8051bf07 00000050 a771afc0 00000000 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    f4894998 8053f6ec 00000000 a771afc0 00000000 nt!MmAccessFault+0x8e7 (FPO: [Non-Fpo])
    f4894998 f7929b25 00000000 a771afc0 00000000 nt!KiTrap0E+0xcc (FPO: [0,0] TrapFrame @ f48949b0)
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f4894a3c f792a593 a6bd4f90 9a4d8fc0 850f8000 filespy5+0x1b25
    f4894b14 804eddf9 9a4d8f08 8588bd08 8588bd08 filespy5+0x2593
    f4894b24 80577ad6 a6bd4f78 8747ae70 00000001 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    f4894b58 805b0beb 9c8d4da0 9a4d8f08 00120089 nt!IopCloseFile+0x27c (FPO: [Non-Fpo])
    f4894b88 805b053f 9c8d4da0 a6bd4f90 8747ae70 nt!ObpDecrementHandleCount+0x119 (FPO: [Non-Fpo])
    f4894bb0 805b6cfb 9a20efb8 a6bd4f90 000007d8 nt!ObpCloseHandleTableEntry+0x14d (FPO: [Non-Fpo])
    f4894bd0 80602c4d e108bfb0 000007d8 f4894c20 nt!ObpCloseHandleProcedure+0x1f (FPO: [Non-Fpo])
    f4894c00 805b6df4 9a20efb8 805b6cdc f4894c20 nt!ExSweepHandleTable+0x4f (FPO: [Non-Fpo])
    f4894c2c 805c7177 9c8d4da0 9d5a0da8 9d5a0ff0 nt!ObKillProcess+0x5c (FPO: [Non-Fpo])
    f4894cd4 805c73d0 00000000 9d5a0da8 00000000 nt!PspExitThread+0x5e9 (FPO: [Non-Fpo])
    f4894cf4 805c75ab 9d5a0da8 00000000 f4894d58 nt!PspTerminateThreadByPointer+0x52 (FPO: [Non-Fpo])
    f4894d20 f7991e85 00000000 00000000 f4894d64 nt!NtTerminateProcess+0x105 (FPO: [Non-Fpo])
    f4894ddc 80540fa2 bacecb85 9ff42fc8 00000000 wpsdrvnt+0x1e85
    f4894de0 bacecb84 9ff42fc8 00000000 0000027f nt!KiThreadStartup+0x16
    f4894de4 9ff42fc8 00000000 0000027f 00000000 NDIS!___PchSym_+0xc
    f4894de8 00000000 0000027f 00000000 00000000 0x9ff42fc8
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Wed Mar 02 00:34:37 2005 (42250A1D)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 06:59:05 2004 (41107B29)
    b5957000 b5980f00 kmixer kmixer.sys Wed Aug 04 07:07:46 2004 (41107D32)
    ba053000 ba093100 HTTP HTTP.sys Sat Oct 09 00:48:20 2004 (41672744)
    ba4cc000 ba51d300 srv srv.sys Tue May 10 01:17:49 2005 (427FFDAD)
    ba6d6000 ba6d8300 uphcleanhlp uphcleanhlp.sys Wed Apr 27 19:58:56 2005 (426FE0F0)
    ba74b000 ba75f400 wdmaud wdmaud.sys Wed Aug 04 07:15:03 2004 (41107EE7)
    ba788000 ba7b4400 mrxdav mrxdav.sys Wed Aug 04 07:00:49 2004 (41107B91)
    ba865000 ba873d80 sysaudio sysaudio.sys Wed Aug 04 07:15:54 2004 (41107F1A)
    ba979000 ba97be40 mdmxsdk mdmxsdk.sys Wed Mar 17 19:04:10 2004 (4058A12A)
    baa85000 baa9a580 irda irda.sys Wed Aug 04 07:00:50 2004 (41107B92)
    baab7000 baab9ae0 wg3n wg3n.sys Sun May 04 00:00:37 2003 (3EB44A15)
    bab63000 bab66280 ndisuio ndisuio.sys Wed Aug 04 07:03:10 2004 (41107C1E)
    babc3000 babc6500 s24trans s24trans.sys Wed Dec 28 21:22:07 2005 (43B301FF)
    bac03000 bac05280 rasacd rasacd.sys Fri Aug 17 21:55:39 2001 (3B7D84CB)
    bac0b000 bac0d580 ndistapi ndistapi.sys Fri Aug 17 21:55:29 2001 (3B7D84C1)
    bac2f000 bac3d100 usbhub usbhub.sys Wed Aug 04 07:08:40 2004 (41107D68)
    bac4f000 bac5d900 rfcomm rfcomm.sys Wed Aug 04 07:10:38 2004 (41107DDE)
    bac7f000 bac8ae00 STREAM STREAM.SYS Wed Aug 04 07:07:58 2004 (41107D3E)
    bac8f000 bac9db80 drmk drmk.sys Wed Aug 04 07:07:54 2004 (41107D3A)
    bacaf000 bacc9580 Mup Mup.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    bacca000 bace6000 Teefer Teefer.sys Fri Sep 05 00:46:06 2003 (3F57CEBE)
    bace6000 bad12a80 NDIS NDIS.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    bad13000 bad9f480 Ntfs Ntfs.sys Wed Aug 04 07:15:06 2004 (41107EEA)
    bada0000 badb6780 KSecDD KSecDD.sys Wed Aug 04 06:59:45 2004 (41107B51)
    badb7000 badc8f00 sr sr.sys Wed Aug 04 07:06:22 2004 (41107CDE)
    badc9000 bade7780 fltMgr fltMgr.sys Wed Aug 04 07:01:17 2004 (41107BAD)
    bade8000 bae13d80 dac2w2k dac2w2k.sys Fri Aug 17 21:52:13 2001 (3B7D83FD)
    bae14000 bae2ce00 adpu160m adpu160m.sys Wed May 30 10:18:22 2001 (3B14BADE)
    bae2d000 bae44480 atapi atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    bae45000 bae5c800 SCSIPORT SCSIPORT.SYS Wed Aug 04 06:59:39 2004 (41107B4B)
    bae5d000 bae82700 dmio dmio.sys Wed Aug 04 07:07:13 2004 (41107D11)
    bae83000 baea1880 ftdisk ftdisk.sys Fri Aug 17 21:52:41 2001 (3B7D8419)
    baea2000 baebf480 pcmcia pcmcia.sys Wed Aug 04 07:07:45 2004 (41107D31)
    baec0000 baed0a80 pci pci.sys Wed Aug 04 07:07:45 2004 (41107D31)
    baed1000 baefed80 ACPI ACPI.sys Wed Aug 04 07:07:35 2004 (41107D27)
    bf800000 bf9c1180 win32k win32k.sys Thu Oct 06 01:05:44 2005 (43446A58)
    bf9c2000 bf9d3580 dxg dxg.sys Wed Aug 04 07:00:51 2004 (41107B93)
    bf9d4000 bfd8f700 nv4_disp nv4_disp.dll Tue Sep 27 00:56:49 2005 (43388AC1)
    f42c3000 f42c7b20 AegisP AegisP.sys Mon Oct 24 15:38:50 2005 (435CF1FA)
    f42eb000 f4302480 dump_atapi dump_atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    f4303000 f4326000 Fastfat Fastfat.SYS Wed Aug 04 07:14:15 2004 (41107EB7)
    f4326000 f43c7c80 BisonCam BisonCam.sys Sun Jul 03 14:06:53 2005 (42C7E2ED)
    f43e4000 f43e7800 asyncmac asyncmac.sys Wed Aug 04 07:05:02 2004 (41107C8E)
    f44c4000 f4532400 mrxsmb mrxsmb.sys Wed Jan 19 04:26:50 2005 (41EDE18A)
    f4533000 f455da00 rdbss rdbss.sys Thu Oct 28 02:13:57 2004 (418047D5)
    f455e000 f457fd00 afd afd.sys Wed Aug 04 07:14:13 2004 (41107EB5)
    f4580000 f45c2f80 bthport bthport.sys Wed Aug 04 07:10:34 2004 (41107DDA)
    f45c3000 f45eac00 netbt netbt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    f45eb000 f460bf00 ipnat ipnat.sys Wed Sep 29 23:28:36 2004 (415B3714)
    f460c000 f4663d80 tcpip tcpip.sys Fri Jan 13 02:28:12 2006 (43C7103C)
    f4664000 f4676400 ipsec ipsec.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    f469b000 f469d900 Dxapi Dxapi.sys Fri Aug 17 21:53:19 2001 (3B7D843F)
    f46b1000 f46e2080 UDFReadr UDFReadr.SYS Sat Sep 25 09:26:38 2004 (41552BBE)
    f46f5000 f4717780 DVDVRRdr_xp DVDVRRdr_xp.SYS Sat Sep 25 09:29:48 2004 (41552C7C)
    f472a000 f4770c00 cdudf_xp cdudf_xp.SYS Sat Sep 25 09:39:05 2004 (41552EA9)
    f488d000 f488ff80 mouhid mouhid.sys Fri Aug 17 21:47:57 2001 (3B7D82FD)
    f48a9000 f48ca700 portcls portcls.sys Tue Mar 16 18:58:17 2004 (40574E49)
    f48cb000 f4c96000 RtkHDAud RtkHDAud.sys Thu Aug 18 08:35:01 2005 (43043A25)
    f6c96000 f6c98580 hidusb hidusb.sys Fri Aug 17 22:02:16 2001 (3B7D8658)
    f6cbe000 f6cf1200 update update.sys Wed Aug 04 06:58:32 2004 (41107B08)
    f6cf2000 f6d22100 rdpdr rdpdr.sys Wed Aug 04 07:01:10 2004 (41107BA6)
    f6d23000 f6d33e00 psched psched.sys Wed Aug 04 07:04:16 2004 (41107C60)
    f6d54000 f6d5c880 Fips Fips.SYS Sat Aug 18 02:31:49 2001 (3B7DC585)
    f6d74000 f6d7c700 netbios netbios.sys Wed Aug 04 07:03:19 2004 (41107C27)
    f6d84000 f6d8c700 wanarp wanarp.sys Wed Aug 04 07:04:57 2004 (41107C89)
    f6dd4000 f6dea680 ndiswan ndiswan.sys Wed Aug 04 07:14:30 2004 (41107EC6)
    f6e13000 f6e2fb80 pwd_2k pwd_2k.SYS Sat Sep 25 09:23:14 2004 (41552AF2)
    f6e30000 f6e52680 ks ks.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    f6e53000 f6e63800 sdbus sdbus.sys Wed Aug 04 07:07:47 2004 (41107D33)
    f6e64000 f6e88080 tifm21 tifm21.sys Wed Jan 05 20:35:19 2005 (41DC4F87)
    f6e89000 f71ae480 w29n51 w29n51.sys Mon Sep 12 18:49:42 2005 (4325BFB6)
    f71af000 f71d1e80 USBPORT USBPORT.SYS Wed Aug 04 07:08:34 2004 (41107D62)
    f71d2000 f720d800 yk51x86 yk51x86.sys Wed Jan 04 10:35:12 2006 (43BBA4E0)
    f720e000 f7233000 HDAudBus HDAudBus.sys Sat Jan 08 01:07:15 2005 (41DF3243)
    f7233000 f7246780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 07:07:04 2004 (41107D08)
    f7247000 f755a220 nv4_mini nv4_mini.sys Tue Sep 27 01:01:57 2005 (43388BF5)
    f7594000 f7597c80 mssmbios mssmbios.sys Wed Aug 04 07:07:47 2004 (41107D33)
    f75d0000 f75d8c00 isapnp isapnp.sys Fri Aug 17 21:58:01 2001 (3B7D8559)
    f75e0000 f75ea500 MountMgr MountMgr.sys Wed Aug 04 06:58:29 2004 (41107B05)
    f75f0000 f75fcc80 VolSnap VolSnap.sys Wed Aug 04 07:00:14 2004 (41107B6E)
    f7600000 f760de80 aic78xx aic78xx.sys Thu May 10 21:23:40 2001 (3AFAF8CC)
    f7610000 f7618180 ql10wnt ql10wnt.sys Fri Aug 17 21:52:14 2001 (3B7D83FE)
    f7620000 f7629e00 ql1240 ql1240.sys Fri Aug 17 21:52:14 2001 (3B7D83FE)
    f7630000 f763d780 aic78u2 aic78u2.sys Thu May 10 21:23:41 2001 (3AFAF8CD)
    f7640000 f7648f80 ultra ultra.sys Fri Aug 17 21:52:19 2001 (3B7D8403)
    f7650000 f7659d80 ql1080 ql1080.sys Fri Aug 17 21:52:18 2001 (3B7D8402)
    f7660000 f766bf80 ql1280 ql1280.sys Fri Aug 17 21:52:16 2001 (3B7D8400)
    f7670000 f767b100 ql12160 ql12160.sys Fri Aug 17 21:52:18 2001 (3B7D8402)
    f7680000 f7688e00 disk disk.sys Wed Aug 04 06:59:53 2004 (41107B59)
    f7690000 f769c200 CLASSPNP CLASSPNP.SYS Wed Aug 04 07:14:26 2004 (41107EC2)
    f76a0000 f76aa500 viaagp viaagp.sys Wed Aug 04 07:07:42 2004 (41107D2E)
    f76b0000 f76ba080 sisagp sisagp.sys Wed Aug 04 07:07:42 2004 (41107D2E)
    f76c0000 f76cee80 ohci1394 ohci1394.sys Wed Aug 04 07:10:05 2004 (41107DBD)
    f76d0000 f76dd000 1394BUS 1394BUS.SYS Wed Aug 04 07:10:03 2004 (41107DBB)
    f76e0000 f76ea700 alim1541 alim1541.sys Wed Aug 04 07:07:40 2004 (41107D2C)
    f76f0000 f76fa800 amdagp amdagp.sys Wed Aug 04 07:07:42 2004 (41107D2E)

    CONT......
     
  5. 2006/03/13
    hallan

    hallan Inactive Thread Starter

    Joined:
    2006/03/10
    Messages:
    4
    Likes Received:
    0
    Cont....

    f7700000 f770a580 agp440 agp440.sys Wed Aug 04 07:07:40 2004 (41107D2C)
    f7710000 f771af80 agpCPQ agpCPQ.sys Wed Aug 04 07:07:42 2004 (41107D2E)
    f7730000 f7738d00 intelppm intelppm.sys Wed Aug 04 06:59:19 2004 (41107B37)
    f7750000 f775fd80 serial serial.sys Wed Aug 04 07:15:51 2004 (41107F17)
    f7760000 f776ce00 i8042prt i8042prt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    f7770000 f777a380 imapi imapi.sys Wed Aug 04 07:00:12 2004 (41107B6C)
    f7780000 f778ad00 Cdr4_xp Cdr4_xp.SYS Sat Sep 25 09:29:51 2004 (41552C7F)
    f7790000 f779c180 cdrom cdrom.sys Wed Aug 04 06:59:52 2004 (41107B58)
    f77a0000 f77ae080 redbook redbook.sys Wed Aug 04 06:59:34 2004 (41107B46)
    f77b0000 f77bc880 rasl2tp rasl2tp.sys Wed Aug 04 07:14:21 2004 (41107EBD)
    f77c0000 f77ca200 raspppoe raspppoe.sys Wed Aug 04 07:05:06 2004 (41107C92)
    f77d0000 f77dbd00 raspptp raspptp.sys Wed Aug 04 07:14:26 2004 (41107EC2)
    f77e0000 f77e8900 msgpc msgpc.sys Wed Aug 04 07:04:11 2004 (41107C5B)
    f7800000 f7809800 net6im51 net6im51.sys Wed Mar 09 19:05:30 2005 (422F48FA)
    f7810000 f781e940 odysseyIM3 odysseyIM3.sys Mon Apr 21 05:38:08 2003 (3EA375B0)
    f7820000 f7829f00 termdd termdd.sys Wed Aug 04 06:58:52 2004 (41107B1C)
    f7830000 f7838d80 HIDCLASS HIDCLASS.SYS Wed Aug 04 07:08:18 2004 (41107D52)
    f7840000 f7849480 NDProxy NDProxy.SYS Fri Aug 17 21:55:30 2001 (3B7D84C2)
    f7850000 f7856200 PCIIDEX PCIIDEX.SYS Wed Aug 04 06:59:40 2004 (41107B4C)
    f7858000 f785c900 PartMgr PartMgr.sys Sat Aug 18 02:32:23 2001 (3B7DC5A7)
    f7860000 f7864a80 sparrow sparrow.sys Fri Dec 08 17:40:58 2000 (3A311D2A)
    f7868000 f786e780 asc asc.sys Fri Aug 17 21:51:58 2001 (3B7D83EE)
    f7870000 f7874380 mraid35x mraid35x.sys Fri Aug 17 21:52:11 2001 (3B7D83FB)
    f7878000 f787c880 i2omp i2omp.sys Wed Aug 04 07:00:49 2004 (41107B91)
    f7880000 f7887f80 symc8xx symc8xx.sys Fri Dec 08 17:40:59 2000 (3A311D2B)
    f7888000 f788eee0 sym_hi sym_hi.sys Tue Mar 20 05:51:22 2001 (3AB6EFDA)
    f7890000 f78977e0 sym_u3 sym_u3.sys Tue Mar 20 05:36:17 2001 (3AB6EC51)
    f7898000 f789dc00 ABP480N5 ABP480N5.SYS Fri Aug 17 21:51:59 2001 (3B7D83EF)
    f78a0000 f78a5780 asc3350p asc3350p.sys Fri Aug 17 21:52:01 2001 (3B7D83F1)
    f78a8000 f78acee0 dpti2o dpti2o.sys Tue Mar 20 19:07:16 2001 (3AB7AA64)
    f78b0000 f78b6aa0 perc2 perc2.sys Mon Apr 23 11:51:37 2001 (3AE40939)
    f78b8000 f78be560 hpn hpn.sys Mon Apr 23 11:51:37 2001 (3AE40939)
    f78c0000 f78c4e20 PxHelp20 PxHelp20.sys Mon Apr 25 20:48:02 2005 (426D4972)
    f78d8000 f78de180 HIDPARSE HIDPARSE.SYS Wed Aug 04 07:08:15 2004 (41107D4F)
    f78e0000 f78e4280 BthEnum BthEnum.sys Wed Aug 04 07:10:38 2004 (41107DDE)
    f78e8000 f78edd80 dvd_2K dvd_2K.SYS Sat Sep 25 09:38:30 2004 (41552E86)
    f78f0000 f78f6400 hidbth hidbth.sys Wed Aug 04 07:10:35 2004 (41107DDB)
    f7900000 f7904500 watchdog watchdog.sys Wed Aug 04 07:07:32 2004 (41107D24)
    f7918000 f791d000 usbuhci usbuhci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    f7920000 f7926800 usbehci usbehci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    f7928000 f7930000 filespy5 filespy5.sys Tue Sep 27 16:37:00 2005 (4339671C)
    f7930000 f7935200 vga vga.sys Wed Aug 04 07:07:06 2004 (41107D0A)
    f7940000 f7947000 nscirda nscirda.sys Wed Aug 04 07:00:49 2004 (41107B91)
    f7948000 f794e000 kbdclass kbdclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    f7950000 f7954a80 Msfs Msfs.SYS Wed Aug 04 07:00:37 2004 (41107B85)
    f7958000 f795e580 Ktp Ktp.sys Tue Apr 19 10:24:52 2005 (4264CE64)
    f7960000 f7965a00 mouclass mouclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    f7970000 f7977880 Npfs Npfs.SYS Wed Aug 04 07:00:38 2004 (41107B86)
    f7988000 f798e100 Cdralw2k Cdralw2k.SYS Sat Sep 25 09:32:38 2004 (41552D26)
    f7990000 f7998000 wpsdrvnt wpsdrvnt.sys Fri Sep 05 00:48:13 2003 (3F57CF3D)
    f7998000 f799cc80 rasirda rasirda.sys Fri Aug 17 21:51:29 2001 (3B7D83D1)
    f79a0000 f79a4a00 BTHUSB BTHUSB.sys Wed Aug 04 07:10:33 2004 (41107DD9)
    f79a8000 f79ac880 TDI TDI.SYS Wed Aug 04 07:07:47 2004 (41107D33)
    f79b8000 f79be000 Cinemsup Cinemsup.SYS Fri Jul 19 14:10:18 2002 (3D380FBA)
    f79c8000 f79cc580 ptilink ptilink.sys Fri Aug 17 21:49:53 2001 (3B7D8371)
    f79d8000 f79dc080 raspti raspti.sys Fri Aug 17 21:55:32 2001 (3B7D84C4)
    f79e0000 f79e3000 BOOTVID BOOTVID.dll Fri Aug 17 21:49:09 2001 (3B7D8345)
    f79e4000 f79e6480 compbatt compbatt.sys Fri Aug 17 21:57:58 2001 (3B7D8556)
    f79e8000 f79eb700 BATTC BATTC.SYS Fri Aug 17 21:57:52 2001 (3B7D8550)
    f79ec000 f79eed80 ACPIEC ACPIEC.sys Fri Aug 17 21:57:55 2001 (3B7D8553)
    f79f0000 f79f3a80 cpqarray cpqarray.sys Fri Aug 17 21:52:05 2001 (3B7D83F5)
    f79f4000 f79f7200 aha154x aha154x.sys Fri Aug 17 21:51:59 2001 (3B7D83EF)
    f79f8000 f79fbf80 symc810 symc810.sys Fri Dec 08 17:40:59 2000 (3A311D2B)
    f79fc000 f79ff980 dac960nt dac960nt.sys Fri Aug 17 21:52:13 2001 (3B7D83FD)
    f7a00000 f7a02f00 amsint amsint.sys Fri Aug 17 21:52:01 2001 (3B7D83F1)
    f7a04000 f7a07a00 asc3550 asc3550.sys Fri Aug 17 21:51:56 2001 (3B7D83EC)
    f7a08000 f7a0be80 ini910u ini910u.sys Fri Aug 17 21:52:07 2001 (3B7D83F7)
    f7a0c000 f7a0f680 cbidf2k cbidf2k.sys Fri Aug 17 21:52:06 2001 (3B7D83F6)
    f7a94000 f7a97700 CmBatt CmBatt.sys Wed Aug 04 07:07:39 2004 (41107D2B)
    f7aa8000 f7aabc80 serenum serenum.sys Wed Aug 04 06:59:06 2004 (41107B2A)
    f7aac000 f7aaec00 irenum irenum.sys Wed Aug 04 07:00:45 2004 (41107B8D)
    f7ad0000 f7ad1b80 kdcom kdcom.dll Fri Aug 17 21:49:10 2001 (3B7D8346)
    f7ad2000 f7ad3100 WMILIB WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    f7ad4000 f7ad5480 aliide aliide.sys Fri Aug 17 21:51:54 2001 (3B7D83EA)
    f7ad6000 f7ad7a00 cmdide cmdide.sys Fri Aug 17 21:51:51 2001 (3B7D83E7)
    f7ad8000 f7ad9380 toside toside.sys Fri Aug 17 21:51:52 2001 (3B7D83E8)
    f7ada000 f7adb500 viaide viaide.sys Wed Aug 04 06:59:42 2004 (41107B4E)
    f7adc000 f7add580 intelide intelide.sys Wed Aug 04 06:59:40 2004 (41107B4C)
    f7ade000 f7adf700 dmload dmload.sys Fri Aug 17 21:58:15 2001 (3B7D8567)
    f7ae0000 f7ae1e00 cd20xrnt cd20xrnt.sys Fri Aug 17 21:52:04 2001 (3B7D83F4)
    f7ae2000 f7ae3580 perc2hib perc2hib.sys Mon Apr 23 11:51:37 2001 (3AE40939)
    f7af0000 f7af1100 swenum swenum.sys Wed Aug 04 06:58:41 2004 (41107B11)
    f7afe000 f7aff280 USBD USBD.SYS Fri Aug 17 22:02:58 2001 (3B7D8682)
    f7b04000 f7b06000 i2omgmt i2omgmt.SYS Wed Aug 04 07:00:50 2004 (41107B92)
    f7b08000 f7b09f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 21:49:37 2001 (3B7D8361)
    f7b0c000 f7b0d080 Beep Beep.SYS Fri Aug 17 21:47:33 2001 (3B7D82E5)
    f7b10000 f7b11080 mnmdd mnmdd.SYS Fri Aug 17 21:57:28 2001 (3B7D8538)
    f7b14000 f7b15080 RDPCDD RDPCDD.sys Fri Aug 17 21:46:56 2001 (3B7D82C0)
    f7b22000 f7b23100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    f7b80000 f7b81980 reconn reconn.sys Tue Sep 28 16:50:04 2004 (4159882C)
    f7b98000 f7b98d00 pciide pciide.sys Fri Aug 17 21:51:49 2001 (3B7D83E5)
    f7b99000 f7b99d80 OPRGHDLR OPRGHDLR.SYS Fri Aug 17 21:57:55 2001 (3B7D8553)
    f7c68000 f7c68c00 audstub audstub.sys Fri Aug 17 21:59:40 2001 (3B7D85BC)
    f7c8c000 f7c8cd00 dxgthk dxgthk.sys Fri Aug 17 21:53:12 2001 (3B7D8438)
    f7ccb000 f7ccbb80 Null Null.SYS Fri Aug 17 21:47:39 2001 (3B7D82EB)

    Unloaded modules:
    b5957000 b5981000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b7207000 b7231000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8375000 b839f000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba6fe000 ba728000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7c48000 f7c49000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba728000 ba74b000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bac0f000 bac1c000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    baac3000 baad1000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b3a000 f7b3c000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba774000 ba788000 Parport.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6d64000 f6d6f000 p3.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7928000 f792d000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6e0f000 f6e12000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  6. 2006/03/13
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    There was an issue with the filespy5.sys file (av file monitoring driver) contact BullGuard Ltd. for an update.

    See: http://oca.microsoft.com/en/Response.aspx?SID=807
     
    Arie,
    #5
  7. 2006/03/14
    hallan

    hallan Inactive Thread Starter

    Joined:
    2006/03/10
    Messages:
    4
    Likes Received:
    0
    Hi,

    Thanks for the link, I have now removed Bullguard and installed a decent AV suite (McAfee), thanks for all your help, this site is the best resource on the Web I've found so far for all Windows related issues. Keep up the excellent work, Cheers.

    Regards, Tony.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.