1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

IE gives Blue screen then restart the PC

Discussion in 'Internet Explorer & Microsoft Edge' started by waelnour, 2009/05/26.

  1. 2009/05/26
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Hello Everyone

    well this is my first post as I am a new member
    I have a problem with IE. Simply when I tried to run IE the computer gives me a blue screen then a restart. after that and when I logged again to my system windows displays a massage "The has recovered from a serious error" or something like that.

    I have tried to upgrade to IE7and IE8 but still the same problem

    I can access the net using Firefox

    I have checked my system for viruses spyware and Maleware but it is clean

    any suggestions. Thanks
     
  2. 2009/05/26
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

    Always helps to post your OS otherwise we are in the dark.

    First set up the computer not to restart after a system failure and post the Stop message, if any from the blue screen ....

    Try starting IE with no-add-ons ....

    Right click IE icon on desktop > Start without add-ons, or .....

    Start > Programs > Accessories > System Tools - IE (no add-ons)

    Does this solve the problem?
     

  3. to hide this advert.

  4. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Thank you PeteC for your reply

    well I always do mistakes when I am angry:mad:. I forgot to write that I have XP pro.

    OK I have done what you have told me and know I can see what is written in the blue screen.

    The only thing I was able to understood that maybe there is some error in "tcpip.sys" file.


    IE without add-ons is not working it gives me an error message "The file does not have a program associated with it for preforming this action ......." and that happens only when I select "NoAddOns"

    I am not sure what to do with the dump file I was able to view the "memory.dmp" file using "dumpchk.exe "

    I do not know what to do next
     
  5. 2009/05/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Let's see tha debug log of the dump data = please follow the instructions here and note .....
    Which version of IE is installed at present and which XP Service Pack is installed?
     
  6. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    widows XP SP3 & (currently) IE 6. I have tried to upgrade to 7 & 8 but i am facing the same problem!
     
  7. 2009/05/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Is the upgrade 'successful', but the problem remains with 7 & 8?
     
  8. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Yes, and when I double click the application icon it starts to run giving me the first blank window for 3 sec. then blue screen
     
  9. 2009/05/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Let's see the dump log - post #4
     
  10. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Fine. I am downloading the Debugging Tools right now
     
  11. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Finish downloading and creation the log file.

    Now what should I do? :confused:
     
  12. 2009/05/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Open the file & copy/paste contents into your next post here.
     
  13. 2009/05/27
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Opened log file 'c:debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.8.0004.0 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOW\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOW;C:\WINDOW\system32;C:\WINDOW\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp3_gdr.090206-1234
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
    Debug session time: Wed May 27 11:57:36.406 2009 (GMT+3)
    System Uptime: 0 days 0:56:44.124
    Loading Kernel Symbols
    ..........................................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details
    Loading unloaded module list
    ..........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 8E, {c0000005, ed9d4217, b75cd7c0, 0}

    *** ERROR: Module load completed but symbols could not be loaded for kl1.sys
    *** ERROR: Module load completed but symbols could not be loaded for bckd.sys

    PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

    PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details
    Probably caused by : kl1.sys ( kl1+2177 )

    Followup: MachineOwner
    ---------

    1: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: ed9d4217, The address that the exception occurred at
    Arg3: b75cd7c0, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

    PEB is paged out (Peb.Ldr = 7ffdd00c). Type ".hh dbgerr001" for details

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    tcpip!TCPCreate+75
    ed9d4217 89710c mov dword ptr [ecx+0Ch],esi

    TRAP_FRAME: b75cd7c0 -- (.trap 0xffffffffb75cd7c0)
    .trap 0xffffffffb75cd7c0
    ErrCode = 00000002
    eax=856154ac ebx=00000000 ecx=03000100 edx=47fd0001 esi=85f4f258 edi=00000000
    eip=ed9d4217 esp=b75cd834 ebp=b75cd868 iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    tcpip!TCPCreate+0x75:
    ed9d4217 89710c mov dword ptr [ecx+0Ch],esi ds:0023:0300010c=????????
    .trap
    Resetting default scope

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: explorer.exe

    LAST_CONTROL_TRANSFER: from 804fe827 to 804f9f43

    STACK_TEXT:
    b75cd388 804fe827 0000008e c0000005 ed9d4217 nt!KeBugCheckEx+0x1b
    b75cd750 80542095 b75cd76c 00000000 b75cd7c0 nt!KiDispatchException+0x3b1
    b75cd7b8 80542046 b75cd868 ed9d4217 badb0d00 nt!CommonDispatchException+0x4d
    b75cd868 ed9944b4 865d9350 856153d0 856154ac nt!Kei386EoiHelper+0x18a
    b75cd868 ed9944b4 865d9350 856153d0 856154ac tcpip!TCPDispatch+0x10b
    b75cd8a4 804ef19f 865d9350 856153d0 856153d0 tcpip!TCPDispatch+0x10b
    b75cd8e0 f7306177 865ec588 856153d0 862540d0 nt!IopfCallDriver+0x31
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b75cd908 804ef19f 865ec588 856153d0 858f6fa8 kl1+0x2177
    b75cd918 ed930851 855da4f8 858f6fa8 855da440 nt!IopfCallDriver+0x31
    00000000 00000000 00000000 00000000 00000000 bckd+0x8851


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    kl1+2177
    f7306177 5f pop edi

    SYMBOL_STACK_INDEX: 7

    SYMBOL_NAME: kl1+2177

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: kl1

    IMAGE_NAME: kl1.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4805d347

    FAILURE_BUCKET_ID: 0x8E_kl1+2177

    BUCKET_ID: 0x8E_kl1+2177

    Followup: MachineOwner
    ---------

    eax=f787313c ebx=ed9d4217 ecx=00000000 edx=80546e22 esi=b75cd76c edi=00000000
    eip=804f9f43 esp=b75cd370 ebp=b75cd388 iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f9f43 5d pop ebp
    ChildEBP RetAddr Args to Child
    b75cd388 804fe827 0000008e c0000005 ed9d4217 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    b75cd750 80542095 b75cd76c 00000000 b75cd7c0 nt!KiDispatchException+0x3b1 (FPO: [Non-Fpo])
    b75cd7b8 80542046 b75cd868 ed9d4217 badb0d00 nt!CommonDispatchException+0x4d (FPO: [0,20,0])
    b75cd868 ed9944b4 865d9350 856153d0 856154ac nt!Kei386EoiHelper+0x18a
    b75cd868 ed9944b4 865d9350 856153d0 856154ac tcpip!TCPDispatch+0x10b (FPO: [Non-Fpo])
    b75cd8a4 804ef19f 865d9350 856153d0 856153d0 tcpip!TCPDispatch+0x10b (FPO: [Non-Fpo])
    b75cd8e0 f7306177 865ec588 856153d0 862540d0 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b75cd908 804ef19f 865ec588 856153d0 858f6fa8 kl1+0x2177
    b75cd918 ed930851 855da4f8 858f6fa8 855da440 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    00000000 00000000 00000000 00000000 00000000 bckd+0x8851
    start end module name
    804d7000 806e4000 nt ntkrpamp.exe Fri Feb 06 12:32:51 2009 (498C11D3)
    806e4000 80704d00 hal halmacpi.dll Sun Apr 13 20:31:27 2008 (4802517F)
    b753b000 b7565180 kmixer kmixer.sys Sun Apr 13 20:45:07 2008 (480254B3)
    b7566000 b757d900 dump_atapi dump_atapi.sys Sun Apr 13 20:40:29 2008 (4802539D)
    b7b73000 b7bb3a80 HTTP HTTP.sys Sun Apr 13 20:53:48 2008 (480256BC)
    b7fc4000 b7fd8480 wdmaud wdmaud.sys Sun Apr 13 21:17:18 2008 (48025C3E)
    b81e1000 b8232880 srv srv.sys Thu Dec 11 12:57:07 2008 (4940F203)
    b83c3000 b83ef180 mrxdav mrxdav.sys Sun Apr 13 20:32:42 2008 (480251CA)
    b86d8000 b86db900 ndisuio ndisuio.sys Sun Apr 13 20:55:57 2008 (4802573D)
    b87c8000 b87d6d80 sysaudio sysaudio.sys Sun Apr 13 21:15:55 2008 (48025BEB)
    bf000000 bf011600 dxg dxg.sys Sun Apr 13 20:38:27 2008 (48025323)
    bf012000 bf063000 ati2dvag ati2dvag.dll Mon Dec 01 22:51:31 2008 (49344E53)
    bf063000 bf0f0000 ati2cqag ati2cqag.dll Mon Dec 01 21:45:31 2008 (49343EDB)
    bf0f0000 bf163000 atikvmag atikvmag.dll Mon Dec 01 21:53:35 2008 (493440BF)
    bf163000 bf1ad000 atiok3x2 atiok3x2.dll Mon Dec 01 21:50:52 2008 (4934401C)
    bf1ad000 bf59af40 ati3duag ati3duag.dll Mon Dec 01 22:27:51 2008 (493448C7)
    bf59b000 bf7fc380 ativvaxx ativvaxx.dll Mon Dec 01 22:11:52 2008 (49344508)
    bf800000 bf9c2e00 win32k win32k.sys Mon Feb 09 13:13:13 2009 (49900FC9)
    ed7d2000 ed841280 mrxsmb mrxsmb.sys Fri Oct 24 13:21:07 2008 (4901AFA3)
    ed842000 ed86ce80 rdbss rdbss.sys Sun Apr 13 21:28:38 2008 (48025EE6)
    ed86d000 ed88e000 SASKUTIL SASKUTIL.sys Tue Apr 29 00:17:42 2008 (48163EF6)
    ed8da000 ed8dc900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    ed8de000 ed8ffd00 afd afd.sys Thu Aug 14 13:04:35 2008 (48A40333)
    ed900000 ed927c00 netbt netbt.sys Sun Apr 13 21:20:59 2008 (48025D1B)
    ed928000 ed93c000 bckd bckd.sys Wed Jan 14 01:38:05 2009 (496D25DD)
    ed93c000 ed961500 ipnat ipnat.sys Sun Apr 13 20:57:10 2008 (48025786)
    ed98a000 ed9e2480 tcpip tcpip.sys Fri Jun 20 14:51:09 2008 (485B99AD)
    ed9e3000 ed9f5600 ipsec ipsec.sys Sun Apr 13 21:19:42 2008 (48025CCE)
    edbb1000 edbe9000 klif klif.sys Thu Jan 29 15:06:28 2009 (4981A9D4)
    edc5b000 edc7ea80 portcls portcls.sys Sun Apr 13 21:19:40 2008 (48025CCC)
    edc7f000 ee130000 RtkHDAud RtkHDAud.sys Thu Jul 24 13:02:34 2008 (4888533A)
    f61b7000 f6214f00 update update.sys Sun Apr 13 20:39:46 2008 (48025372)
    f6215000 f6244e80 rdpdr rdpdr.sys Sun Apr 13 20:32:50 2008 (480251D2)
    f6245000 f6255e00 psched psched.sys Sun Apr 13 20:56:36 2008 (48025764)
    f6256000 f626c580 ndiswan ndiswan.sys Sun Apr 13 21:20:41 2008 (48025D09)
    f626d000 f628f700 ks ks.sys Sun Apr 13 21:16:34 2008 (48025C12)
    f6290000 f62a3900 parport parport.sys Sun Apr 13 20:40:09 2008 (48025389)
    f62a4000 f62c7200 USBPORT USBPORT.SYS Sun Apr 13 20:45:34 2008 (480254CE)
    f62c8000 f62e4480 Rtenicxp Rtenicxp.sys Thu Oct 16 08:00:30 2008 (48F6D87E)
    f62e5000 f630d000 HDAudBus HDAudBus.sys Thu May 26 18:46:29 2005 (4295EF55)
    f630d000 f6320f00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 20:44:39 2008 (48025497)
    f6321000 f6855000 ati2mtag ati2mtag.sys Mon Dec 01 22:51:07 2008 (49344E3B)
    f6855000 f685d900 msgpc msgpc.sys Sun Apr 13 20:56:32 2008 (48025760)
    f6865000 f6870d00 raspptp raspptp.sys Sun Apr 13 21:19:47 2008 (48025CD3)
    f6875000 f687f200 raspppoe raspppoe.sys Sun Apr 13 20:57:31 2008 (4802579B)
    f6885000 f6891880 rasl2tp rasl2tp.sys Sun Apr 13 21:19:43 2008 (48025CCF)
    f6895000 f68a3100 redbook redbook.sys Sun Apr 13 20:40:27 2008 (4802539B)
    f68a5000 f68b4600 cdrom cdrom.sys Sun Apr 13 20:40:45 2008 (480253AD)
    f68b5000 f68bf480 imapi imapi.sys Sun Apr 13 20:40:57 2008 (480253B9)
    f68c5000 f68d1d00 i8042prt i8042prt.sys Sun Apr 13 21:17:59 2008 (48025C67)
    f68d5000 f68e4c00 serial serial.sys Sun Apr 13 21:15:44 2008 (48025BE0)
    f68e5000 f68ee000 klfltdev klfltdev.sys Thu Mar 13 17:02:27 2008 (47D94203)
    f71d3000 f71d6c80 mssmbios mssmbios.sys Sun Apr 13 20:36:45 2008 (480252BD)
    f71eb000 f71ed780 ndistapi ndistapi.sys Sun Apr 13 20:57:27 2008 (48025797)
    f7304000 f7321000 kl1 kl1.sys Wed Apr 16 12:21:59 2008 (4805D347)
    f7321000 f733ab80 Mup Mup.sys Sun Apr 13 21:17:05 2008 (48025C31)
    f733b000 f7367980 NDIS NDIS.sys Sun Apr 13 21:20:35 2008 (48025D03)
    f7368000 f73f4600 Ntfs Ntfs.sys Sun Apr 13 21:15:49 2008 (48025BE5)
    f73f5000 f740b880 KSecDD KSecDD.sys Sun Apr 13 20:31:40 2008 (4802518C)
    f740c000 f741df00 sr sr.sys Sun Apr 13 20:36:50 2008 (480252C2)
    f741e000 f743db00 fltmgr fltmgr.sys Sun Apr 13 20:32:58 2008 (480251DA)
    f743e000 f7455900 atapi atapi.sys Sun Apr 13 20:40:29 2008 (4802539D)
    f7456000 f747b700 dmio dmio.sys Sun Apr 13 20:44:45 2008 (4802549D)
    f747c000 f749a880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    f749b000 f74aba80 pci pci.sys Sun Apr 13 20:36:43 2008 (480252BB)
    f74ac000 f74d9d80 ACPI ACPI.sys Sun Apr 13 20:36:33 2008 (480252B1)
    f75db000 f75e4180 isapnp isapnp.sys Sun Apr 13 20:36:40 2008 (480252B8)
    f75eb000 f75f5580 MountMgr MountMgr.sys Sun Apr 13 20:39:45 2008 (48025371)
    f75fb000 f7607c80 VolSnap VolSnap.sys Sun Apr 13 20:41:00 2008 (480253BC)
    f760b000 f7613e00 disk disk.sys Sun Apr 13 20:40:46 2008 (480253AE)
    f761b000 f7627180 CLASSPNP CLASSPNP.SYS Sun Apr 13 21:16:21 2008 (48025C05)
    f762b000 f7636000 klbg klbg.sys Mon Dec 15 18:41:09 2008 (494688A5)
    f763b000 f7643b80 PxHelp20 PxHelp20.sys Fri Feb 02 23:23:57 2007 (45C3ABED)
    f775b000 f7763e00 intelppm intelppm.sys Sun Apr 13 20:31:31 2008 (48025183)
    f776b000 f7774f00 termdd termdd.sys Sun Apr 13 20:38:36 2008 (4802532C)
    f777b000 f7784e80 NDProxy NDProxy.SYS Sun Apr 13 20:57:28 2008 (48025798)
    f77ab000 f77b9b00 drmk drmk.sys Sun Apr 13 20:45:12 2008 (480254B8)
    f77bb000 f77c9880 usbhub usbhub.sys Sun Apr 13 20:45:36 2008 (480254D0)
    f77eb000 f77f3700 wanarp wanarp.sys Sun Apr 13 20:57:20 2008 (48025790)
    f77fb000 f7803780 netbios netbios.sys Sun Apr 13 20:56:01 2008 (48025741)
    f780b000 f7818000 SCDEmu SCDEmu.SYS Sun Nov 02 10:44:10 2008 (490D685A)
    f781b000 f7827380 ikhlayer ikhlayer.sys Mon Dec 12 01:09:56 2005 (439CB1C4)
    f782b000 f7835e00 Fips Fips.SYS Sun Apr 13 20:33:27 2008 (480251F7)
    f783b000 f784a900 Cdfs Cdfs.SYS Sun Apr 13 21:14:21 2008 (48025B8D)
    f785b000 f7861180 PCIIDEX PCIIDEX.SYS Sun Apr 13 20:40:29 2008 (4802539D)
    f7863000 f7867d00 PartMgr PartMgr.sys Sun Apr 13 20:40:48 2008 (480253B0)
    f786b000 f786fa80 TDI TDI.SYS Sun Apr 13 21:00:04 2008 (48025834)
    f78b3000 f78b8080 usbuhci usbuhci.sys Sun Apr 13 20:45:34 2008 (480254CE)
    f78bb000 f78c2600 usbehci usbehci.sys Sun Apr 13 20:45:34 2008 (480254CE)
    f78c3000 f78c9b00 fdc fdc.sys Sun Apr 13 20:40:25 2008 (48025399)
    f78cb000 f78d0a00 mouclass mouclass.sys Sun Apr 13 20:39:47 2008 (48025373)
    f78d3000 f78d9000 kbdclass kbdclass.sys Sun Apr 13 20:39:46 2008 (48025372)
    f78db000 f78e1000 gdihook5 gdihook5.sys Thu Oct 09 12:37:13 2008 (48EDDED9)
    f78e3000 f78eb000 klim5 klim5.sys Tue Mar 25 18:06:52 2008 (47E9231C)
    f78eb000 f78ef580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f78f3000 f78f7080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f78fb000 f7900000 flpydisk flpydisk.sys Sun Apr 13 20:40:24 2008 (48025398)
    f790b000 f7913000 pcisys pcisys.sys Thu Oct 09 12:37:10 2008 (48EDDED6)
    f7913000 f7918200 vga vga.sys Sun Apr 13 20:44:40 2008 (48025498)
    f791b000 f791fa80 Msfs Msfs.SYS Sun Apr 13 20:32:38 2008 (480251C6)
    f7923000 f792a880 Npfs Npfs.SYS Sun Apr 13 20:32:38 2008 (480251C6)
    f792b000 f7932000 SASDIFSV SASDIFSV.SYS Wed Apr 16 23:39:35 2008 (48067217)
    f7943000 f7947500 watchdog watchdog.sys Sun Apr 13 20:44:59 2008 (480254AB)
    f79bb000 f79c1b00 npf npf.sys Tue Nov 06 22:09:15 2007 (4730C9EB)
    f79eb000 f79ee000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f7a9b000 f7a9ed00 FolderProtectDriver FolderProtectDriver.sys Fri Jan 11 08:46:58 2008 (478710E2)
    f7a9f000 f7aa1280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f7aab000 f7aaed80 serenum serenum.sys Sun Apr 13 20:40:12 2008 (4802538C)
    f7adb000 f7adcb80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f7add000 f7ade100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f7adf000 f7ae0700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
    f7b3b000 f7b3c100 swenum swenum.sys Sun Apr 13 20:39:52 2008 (48025378)
    f7b3f000 f7b40280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f7b41000 f7b42f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f7b43000 f7b44080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
    f7b45000 f7b46080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f7b47000 f7b48080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f7b53000 f7b54100 dump_WMILIB dump_WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f7b85000 f7b86a80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
    f7ba3000 f7ba3d00 pciide pciide.sys Fri Aug 17 23:51:49 2001 (3B7D83E5)
    f7c26000 f7c26b80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f7c5b000 f7c5bd00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)
    f7d19000 f7d19c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)

    Unloaded modules:
    ece02000 ece1a000 dump_atapi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b7553000 b757e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b7f76000 b7fa1000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7cf0000 f7cf1000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b7fa1000 b7fc4000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8129000 b8136000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8139000 b8147000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b2b000 f7b2d000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7903000 f7908000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7a8f000 f7a92000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:debuglog.txt
     
  14. 2009/05/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Bearing in mind the rider I posted earlier ....
    I will give you my 2 cents worth ....
    This is part of Kaspersky which I guess you have installed? See http://www.bleepingcomputer.com/startups/kl1.sys-15140.html
    Info on this is scanty and Previx lists it as possible malware, but I would need to refer you to the Malware & Virus Removal forum for a realistic opinion.
    You may have a memory problem, but the more likely cause is your AV .....
    So the bottom line is that your problem may be caused by your AV, which is Kasperky?
     
  15. 2009/05/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, upload following files to http://www.virustotal.com/ for security check:
    bckd.sys file located in c:\windows\system32\drivers
    Post scan results.

    Some infection is very possible in this case here. Check the above file, first, though.
     
  16. 2009/05/31
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Sorry for my late response (out of the office)

    Broni,
    Here is the result link analisis/d7a61423734a70aa700bd99a8d56d09454c832dbabce89dcc14317ff49c9631b-1240917311
    All results are (-)

    By the way I have tried to run "Internet Explorer "in windows "safe mode with network support"
    And it is working :confused: :eek:

    first time when windows safe mode listing the loaded files it reached the file "TDI.SYS" then the computer restart by it self.
    again I ran windows in safe mode and it is OK this time and also IE works ?

    Do you think it is one of windows files ?
     
  17. 2009/05/31
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
  18. 2009/05/31
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
  19. 2009/05/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    As Pete pointed out, your BSOD error was caused by Kaspersky.
    Kaspersky doesn't load in Safe Mode, and apparently IE works fine there.
    It may be Kaspersky issue.

    To double check, let's try one more test.

    Go Start>Run (Start Search in Vista), type in:
    msconfig
    Click OK (hit Enter in Vista).

    Click on Startup tab.
    Click Disable all

    Click Services tab.
    Put checkmark in Hide all Microsoft services
    Click Disable all.

    Click OK.
    Restart computer in Normal Mode.

    NOTE. If you use different firewall, than Windows firewall, turn Windows firewall on, just for this test, since your regular firewall won't be running.
    If you use Windows firewall, you're fine.

    Same problem?
     
  20. 2009/06/01
    waelnour

    waelnour Inactive Thread Starter

    Joined:
    2009/05/26
    Messages:
    15
    Likes Received:
    0
    Yes, Same problem

    but I am running Kaspersky on the PC for over than 3 months now ?

    should I uninstall it ?
     
  21. 2009/06/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Yes - on a trial basis to confirm, or otherwise, that it is the source of the problem. It is possible that the install is corrupted or that an update (to Kaspersky) is the source of the problem.

    Here is a basic guide ....

    http://usa.kaspersky.com/support/193239348/
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.