1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BSOD Followed by Reboot [DUMP DATA]

Discussion in 'Windows XP' started by Cms12682, 2011/01/05.

  1. 2011/01/05
    Cms12682

    Cms12682 Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    3
    Likes Received:
    0
    I've just had my computer reboot itself without warning for the third time. There was a week in between the first and second occurrences and only a few hours between the second and third.

    This is not a great machine. It's relatively new, but it's only used for internet, word processing, etc. Nothing all that intensive. It's XP, SP3. 1 GB of RAM. Dual processor.

    After the last reboot I went through the device manager and checked to see which ones needed an update. This included the Intel 82945G Express Chipset video card (terrible card, I know) and the IDE Controller.

    Since there's no specific action or time when this occurs, I thought it made sense to post the info from the second and third BSOD and the dmp file here to see if someone could interpret it.

    The first and second BSOD said this:
    Error code 1000008e, parameter1 c0000005, parameter2 bf8b15be, parameter3 a8d16ae4, parameter4 00000000.

    The third BSOD said this:
    Error code 1000007e, parameter1 c0000005, parameter2 a84ea481, parameter3 f7a05a74, parameter4 f7a05770.

    And here's the info from the dmp file:
    Opened log file 'c:debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini010411-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp3_gdr.100427-1636
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
    Debug session time: Tue Jan 4 19:57:40.031 2011 (UTC - 6:00)
    System Uptime: 0 days 2:20:47.713
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...............
    Loading User Symbols
    Loading unloaded module list
    ..................
    Unable to load image dwprot.sys, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for dwprot.sys
    *** ERROR: Module load completed but symbols could not be loaded for dwprot.sys
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000007E, {c0000005, a84ea481, f7a05a74, f7a05770}

    Probably caused by : dwprot.sys ( dwprot+9481 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: a84ea481, The address that the exception occurred at
    Arg3: f7a05a74, Exception Record Address
    Arg4: f7a05770, Context Record Address

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    dwprot+9481
    a84ea481 8b760c mov esi,dword ptr [esi+0Ch]

    EXCEPTION_RECORD: f7a05a74 -- (.exr 0xfffffffff7a05a74)
    .exr 0xfffffffff7a05a74
    ExceptionAddress: a84ea481 (dwprot+0x00009481)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 6366745a
    Attempt to read from address 6366745a

    CONTEXT: f7a05770 -- (.cxr 0xfffffffff7a05770)
    .cxr 0xfffffffff7a05770
    eax=00000a28 ebx=805008a4 ecx=8054d0e8 edx=f7a05b48 esi=6366744e edi=8052baf2
    eip=a84ea481 esp=f7a05b3c ebp=f7a05b40 iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    dwprot+0x9481:
    a84ea481 8b760c mov esi,dword ptr [esi+0Ch] ds:0023:6366745a=????????
    .cxr
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 2

    PROCESS_NAME: System

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    EXCEPTION_PARAMETER1: 00000000

    EXCEPTION_PARAMETER2: 6366745a

    READ_ADDRESS: 6366745a

    FOLLOWUP_IP:
    dwprot+9481
    a84ea481 8b760c mov esi,dword ptr [esi+0Ch]

    BUGCHECK_STR: 0x7E

    DEFAULT_BUCKET_ID: STRING_DEREFERENCE

    LAST_CONTROL_TRANSFER: from a84ea49f to a84ea481

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f7a05b40 a84ea49f 00000000 f7a05bc0 a84ec483 dwprot+0x9481
    f7a05b4c a84ec483 e15316b8 00000000 5fe603b4 dwprot+0x949f
    f7a05bc0 a84ea4d6 f7a05bd8 a84ea492 00000000 dwprot+0xb483
    f7a05be0 a84fc91e 5fe60440 857e3000 863c2be8 dwprot+0x94d6
    f7a05c34 a84fc72a 857e3000 5fe604f0 85e20500 dwprot+0x1b91e
    f7a05c84 80581377 85e20500 857e3000 00000000 dwprot+0x1b72a
    f7a05d54 80581487 80000624 00000001 00000000 nt!IopLoadDriver+0x66d
    f7a05d7c 8053879d 80000624 00000000 865c2da8 nt!IopLoadUnloadDriver+0x45
    f7a05dac 805cff62 a905bcf4 00000000 00000000 nt!ExpWorkerThread+0xef
    f7a05ddc 8054612e 805386ae 00000001 00000000 nt!PspSystemThreadStartup+0x34
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: dwprot+9481

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: dwprot

    IMAGE_NAME: dwprot.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4cef6120

    STACK_COMMAND: .cxr 0xfffffffff7a05770 ; kb

    FAILURE_BUCKET_ID: 0x7E_dwprot+9481

    BUCKET_ID: 0x7E_dwprot+9481

    Followup: MachineOwner
    ---------

    eax=00000a28 ebx=805008a4 ecx=8054d0e8 edx=f7a05b48 esi=6366744e edi=8052baf2
    eip=a84ea481 esp=f7a05b3c ebp=f7a05b40 iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    dwprot+0x9481:
    a84ea481 8b760c mov esi,dword ptr [esi+0Ch] ds:0023:6366745a=????????
    ChildEBP RetAddr Args to Child
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f7a05b40 a84ea49f 00000000 f7a05bc0 a84ec483 dwprot+0x9481
    f7a05b4c a84ec483 e15316b8 00000000 5fe603b4 dwprot+0x949f
    f7a05bc0 a84ea4d6 f7a05bd8 a84ea492 00000000 dwprot+0xb483
    f7a05be0 a84fc91e 5fe60440 857e3000 863c2be8 dwprot+0x94d6
    f7a05c34 a84fc72a 857e3000 5fe604f0 85e20500 dwprot+0x1b91e
    f7a05c84 80581377 85e20500 857e3000 00000000 dwprot+0x1b72a
    f7a05d54 80581487 80000624 00000001 00000000 nt!IopLoadDriver+0x66d (FPO: [Non-Fpo])
    f7a05d7c 8053879d 80000624 00000000 865c2da8 nt!IopLoadUnloadDriver+0x45 (FPO: [Non-Fpo])
    f7a05dac 805cff62 a905bcf4 00000000 00000000 nt!ExpWorkerThread+0xef (FPO: [Non-Fpo])
    f7a05ddc 8054612e 805386ae 00000001 00000000 nt!PspSystemThreadStartup+0x34 (FPO: [Non-Fpo])
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
    start end module name
    804d7000 806e4000 nt ntkrpamp.exe Tue Apr 27 08:04:40 2010 (4BD6E0E8)
    806e4000 80704d00 hal halmacpi.dll Sun Apr 13 13:31:27 2008 (4802517F)
    a84e1000 a8500580 dwprot dwprot.sys Fri Nov 26 01:26:24 2010 (4CEF6120)
    a8778000 a879a000 SASKUTIL SASKUTIL.SYS Mon May 10 12:15:22 2010 (4BE83F2A)
    a8d23000 a8d63e00 HTTP HTTP.sys Tue Oct 20 11:20:15 2009 (4ADDE33F)
    a90dc000 a90e2000 SASDIFSV SASDIFSV.SYS Wed Feb 17 12:19:19 2010 (4B7C3327)
    a928c000 a92b4000 AVGIDSDriver AVGIDSDriver.Sys Tue Aug 03 17:23:56 2010 (4C5896FC)
    a9804000 a985b380 srv srv.sys Thu Aug 26 08:39:48 2010 (4C766EA4)
    a98d4000 a98de000 AVGIDSFilter AVGIDSFilter.Sys Tue Aug 03 17:23:14 2010 (4C5896D2)
    a994c000 a995ce80 adfs adfs.SYS Thu Aug 14 09:57:15 2008 (48A447CB)
    a9a25000 a9a51180 mrxdav mrxdav.sys Sun Apr 13 13:32:42 2008 (480251CA)
    a9bc0000 a9bd4480 wdmaud wdmaud.sys Sun Apr 13 14:17:18 2008 (48025C3E)
    a9bd5000 a9bdf000 AVGIDSShim AVGIDSShim.Sys Tue Aug 03 17:25:52 2010 (4C589770)
    a9ecd000 a9ee3340 DLAUDF_M DLAUDF_M.SYS Fri Feb 22 12:19:06 2008 (47BF121A)
    a9ee4000 a9ef96c0 DLAUDFAM DLAUDFAM.SYS Fri Feb 22 12:19:35 2008 (47BF1237)
    a9efa000 a9f11d40 DLAIFS_M DLAIFS_M.SYS Fri Feb 22 12:18:44 2008 (47BF1204)
    a9f36000 a9f39900 ndisuio ndisuio.sys Sun Apr 13 13:55:57 2008 (4802573D)
    aa052000 aa069900 dump_atapi dump_atapi.sys Sun Apr 13 13:40:29 2008 (4802539D)
    aa0ce000 aa0d0900 Dxapi Dxapi.sys Fri Aug 17 15:53:19 2001 (3B7D843F)
    aa10a000 aa145d00 avgldx86 avgldx86.sys Tue Dec 07 20:00:20 2010 (4CFEE6B4)
    aa146000 aa1b5400 mrxsmb mrxsmb.sys Wed Feb 24 07:11:05 2010 (4B852569)
    aa1b6000 aa1e0e80 rdbss rdbss.sys Sun Apr 13 14:28:38 2008 (48025EE6)
    aa1e1000 aa202d00 afd afd.sys Thu Aug 14 05:04:35 2008 (48A40333)
    aa203000 aa22ac00 netbt netbt.sys Sun Apr 13 14:20:59 2008 (48025D1B)
    aa256000 aa27b500 ipnat ipnat.sys Sun Apr 13 13:57:10 2008 (48025786)
    aa27c000 aa2c3980 avgtdix avgtdix.sys Fri Nov 12 05:05:58 2010 (4CDD1F96)
    aa2c4000 aa31c480 tcpip tcpip.sys Fri Jun 20 06:51:09 2008 (485B99AD)
    aa31d000 aa32f600 ipsec ipsec.sys Sun Apr 13 14:19:42 2008 (48025CCE)
    aa350000 aa363000 mozy mozy.sys Mon Nov 08 16:26:36 2010 (4CD8791C)
    aa780000 aa78ed80 sysaudio sysaudio.sys Sun Apr 13 14:15:55 2008 (48025BEB)
    bf000000 bf011600 dxg dxg.sys Sun Apr 13 13:38:27 2008 (48025323)
    bf012000 bf020000 ialmrnt5 ialmrnt5.dll Tue Apr 05 16:38:42 2005 (42530562)
    bf020000 bf040000 ialmdnt5 ialmdnt5.dll Tue Apr 05 16:38:35 2005 (4253055B)
    bf040000 bf06f680 ialmdev5 ialmdev5.DLL Tue Apr 05 16:38:25 2005 (42530551)
    bf070000 bf14c000 ialmdd5 ialmdd5.DLL Tue Apr 05 16:45:43 2005 (42530707)
    bf800000 bf9c4780 win32k win32k.sys Tue Oct 26 08:24:50 2010 (4CC6D6A2)
    bffa0000 bffe6d00 ATMFD ATMFD.DLL Thu Oct 28 08:13:22 2010 (4CC976F2)
    f6cb5000 f6d12f00 update update.sys Sun Apr 13 13:39:46 2008 (48025372)
    f6d13000 f6d42e80 rdpdr rdpdr.sys Sun Apr 13 13:32:50 2008 (480251D2)
    f6d43000 f6d53e00 psched psched.sys Sun Apr 13 13:56:36 2008 (48025764)
    f6d54000 f6d6a580 ndiswan ndiswan.sys Sun Apr 13 14:20:41 2008 (48025D09)
    f6d6b000 f6da4000 azl3b5hk azl3b5hk.SYS Tue Jul 14 16:12:41 2009 (4A5CF4C9)
    f6da4000 f6db7900 parport parport.sys Sun Apr 13 13:40:09 2008 (48025389)
    f6db8000 f6e6af00 senfilt senfilt.sys Thu Sep 16 21:02:52 2004 (414A45CC)
    f6e6b000 f6e8d700 ks ks.sys Sun Apr 13 14:16:34 2008 (48025C12)
    f6e8e000 f6eb1a80 portcls portcls.sys Sun Apr 13 14:19:40 2008 (48025CCC)
    f6eb2000 f6ef1900 smwdm smwdm.sys Thu Jan 27 14:31:04 2005 (41F94F88)
    f6ef2000 f6f15200 USBPORT USBPORT.SYS Sun Apr 13 13:45:34 2008 (480254CE)
    f6f16000 f6f36600 b57xp32 b57xp32.sys Thu Mar 17 19:30:08 2005 (423A2110)
    f6f37000 f6f4af00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 13:44:39 2008 (48025497)
    f6f4b000 f7015c60 ialmnt5 ialmnt5.sys Tue Apr 05 16:46:26 2005 (42530732)
    f717e000 f7181c80 mssmbios mssmbios.sys Sun Apr 13 13:36:45 2008 (480252BD)
    f71c3000 f71dcb80 Mup Mup.sys Sun Apr 13 14:17:05 2008 (48025C31)
    f71dd000 f7209980 NDIS NDIS.sys Sun Apr 13 14:20:35 2008 (48025D03)
    f720a000 f7296600 Ntfs Ntfs.sys Sun Apr 13 14:15:49 2008 (48025BE5)
    f7297000 f72adb00 KSecDD KSecDD.sys Wed Jun 24 06:18:40 2009 (4A420B90)
    f72ae000 f72cdf80 symsnap symsnap.sys Wed Dec 12 13:31:49 2007 (47603725)
    f72ce000 f72e3fe0 DRVMCDB DRVMCDB.SYS Fri Jul 21 13:20:31 2006 (44C11AEF)
    f72e4000 f72f5f00 sr sr.sys Sun Apr 13 13:36:50 2008 (480252C2)
    f72f6000 f7315b00 fltMgr fltMgr.sys Sun Apr 13 13:32:58 2008 (480251DA)
    f7316000 f732d900 atapi atapi.sys Sun Apr 13 13:40:29 2008 (4802539D)
    f732e000 f7353700 dmio dmio.sys Sun Apr 13 13:44:45 2008 (4802549D)
    f7354000 f7372880 ftdisk ftdisk.sys Fri Aug 17 15:52:41 2001 (3B7D8419)
    f7373000 f7383a80 pci pci.sys Sun Apr 13 13:36:43 2008 (480252BB)
    f7384000 f73b1d80 ACPI ACPI.sys Sun Apr 13 13:36:33 2008 (480252B1)
    f73b2000 f73c9880 SCSIPORT SCSIPORT.SYS Sun Apr 13 13:40:29 2008 (4802539D)
    f73ca000 f74bd000 sptd sptd.sys Sun Oct 11 15:54:02 2009 (4AD245EA)
    f75be000 f75c7180 isapnp isapnp.sys Sun Apr 13 13:36:40 2008 (480252B8)
    f75ce000 f75d8580 MountMgr MountMgr.sys Sun Apr 13 13:39:45 2008 (48025371)
    f75de000 f75eac80 VolSnap VolSnap.sys Sun Apr 13 13:41:00 2008 (480253BC)
    f75ee000 f75f6e00 disk disk.sys Sun Apr 13 13:40:46 2008 (480253AE)
    f75fe000 f760a180 CLASSPNP CLASSPNP.SYS Sun Apr 13 14:16:21 2008 (48025C05)
    f760e000 f7616b40 PxHelp20 PxHelp20.sys Mon Jul 24 19:18:21 2006 (44C5634D)
    f761e000 f7627000 AVGIDSEH AVGIDSEH.Sys Mon Sep 13 17:46:31 2010 (4C8EA9C7)
    f763e000 f764c100 redbook redbook.sys Sun Apr 13 13:40:27 2008 (4802539B)
    f764e000 f765a880 rasl2tp rasl2tp.sys Sun Apr 13 14:19:43 2008 (48025CCF)
    f765e000 f7668200 raspppoe raspppoe.sys Sun Apr 13 13:57:31 2008 (4802579B)
    f766e000 f7679d00 raspptp raspptp.sys Sun Apr 13 14:19:47 2008 (48025CD3)
    f767e000 f7686900 msgpc msgpc.sys Sun Apr 13 13:56:32 2008 (48025760)
    f768e000 f7697f00 termdd termdd.sys Sun Apr 13 13:38:36 2008 (4802532C)
    f769e000 f76a8000 NDProxy NDProxy.SYS Tue Nov 02 10:17:02 2010 (4CD02B6E)
    f76ee000 f76f8600 DRVNDDM DRVNDDM.SYS Fri Feb 09 14:33:42 2007 (45CCDAA6)
    f770e000 f771c880 usbhub usbhub.sys Sun Apr 13 13:45:36 2008 (480254D0)
    f773e000 f774a000 avgmfx86 avgmfx86.sys Mon Sep 06 19:48:01 2010 (4C858BC1)
    f775e000 f7766700 wanarp wanarp.sys Sun Apr 13 13:57:20 2008 (48025790)
    f776e000 f7777000 HIDCLASS HIDCLASS.SYS Sun Apr 13 13:45:25 2008 (480254C5)
    f777e000 f7786780 netbios netbios.sys Sun Apr 13 13:56:01 2008 (48025741)
    f778e000 f7798e00 Fips Fips.SYS Sun Apr 13 13:33:27 2008 (480251F7)
    f77ce000 f77dd900 Cdfs Cdfs.SYS Sun Apr 13 14:14:21 2008 (48025B8D)
    f77ee000 f77f6e00 intelppm intelppm.sys Sun Apr 13 13:31:31 2008 (48025183)
    f77fe000 f780cb00 drmk drmk.sys Sun Apr 13 13:45:12 2008 (480254B8)
    f780e000 f781dc00 serial serial.sys Sun Apr 13 14:15:44 2008 (48025BE0)
    f781e000 f7828480 imapi imapi.sys Sun Apr 13 13:40:57 2008 (480253B9)
    f782e000 f783d600 cdrom cdrom.sys Sun Apr 13 13:40:45 2008 (480253AD)
    f783e000 f7844180 PCIIDEX PCIIDEX.SYS Sun Apr 13 13:40:29 2008 (4802539D)
    f7846000 f784ad00 PartMgr PartMgr.sys Sun Apr 13 13:40:48 2008 (480253B0)
    f784e000 f7852b80 avgrkx86 avgrkx86.sys Mon Sep 06 19:48:16 2010 (4C858BD0)
    f78ae000 f78b5d80 usbccgp usbccgp.sys Sun Apr 13 13:45:38 2008 (480254D2)
    f78be000 f78c32e0 DLARTL_M DLARTL_M.SYS Thu Feb 08 22:04:41 2007 (45CBF2D9)
    f78c6000 f78cc180 HIDPARSE HIDPARSE.SYS Sun Apr 13 13:45:22 2008 (480254C2)
    f78ce000 f78d3200 vga vga.sys Sun Apr 13 13:44:40 2008 (48025498)
    f78d6000 f78d7000 Msfs Msfs.SYS unavailable (00000000)
    f78de000 f78e5880 Npfs Npfs.SYS Sun Apr 13 13:32:38 2008 (480251C6)
    f78e6000 f78ea500 watchdog watchdog.sys Sun Apr 13 13:44:59 2008 (480254AB)
    f78f6000 f78fabc0 DLAOPIOM DLAOPIOM.SYS Fri Feb 22 12:20:52 2008 (47BF1284)
    f78fe000 f7904e20 DLABMFSM DLABMFSM.SYS Fri Feb 22 12:19:59 2008 (47BF124F)
    f7906000 f790c3e0 DLABOIOM DLABOIOM.SYS Fri Feb 22 12:19:53 2008 (47BF1249)
    f790e000 f7913080 usbuhci usbuhci.sys Sun Apr 13 13:45:34 2008 (480254CE)
    f7916000 f791d600 usbehci usbehci.sys Sun Apr 13 13:45:34 2008 (480254CE)
    f791e000 f7925000 GEARAspiWDM GEARAspiWDM.sys Mon Aug 07 12:11:27 2006 (44D7743F)
    f7966000 f796aa80 LVPr2Mon LVPr2Mon.sys Fri May 07 20:36:25 2010 (4BE4C019)
    f7986000 f798aa80 TDI TDI.SYS Sun Apr 13 14:00:04 2008 (48025834)
    f798e000 f7992580 ptilink ptilink.sys Fri Aug 17 15:49:53 2001 (3B7D8371)
    f7996000 f799a080 raspti raspti.sys Fri Aug 17 15:55:32 2001 (3B7D84C4)
    f799e000 f79a4000 kbdclass kbdclass.sys Sun Apr 13 13:39:46 2008 (48025372)
    f79a6000 f79aba00 mouclass mouclass.sys Sun Apr 13 13:39:47 2008 (48025373)
    f79be000 f79c5f80 v2imount v2imount.sys Wed Dec 12 13:07:19 2007 (47603167)
    f79ce000 f79d1000 BOOTVID BOOTVID.dll Fri Aug 17 15:49:09 2001 (3B7D8345)
    f7a72000 f7a74280 rasacd rasacd.sys Fri Aug 17 15:55:39 2001 (3B7D84CB)
    f7a8a000 f7a8c880 hidusb hidusb.sys Sun Apr 13 13:45:27 2008 (480254C7)
    f7a92000 f7a94f80 mouhid mouhid.sys Fri Aug 17 15:47:57 2001 (3B7D82FD)
    f7a9a000 f7a9d900 kbdhid kbdhid.sys Sun Apr 13 13:39:47 2008 (48025373)
    f7a9e000 f7aa1d80 serenum serenum.sys Sun Apr 13 13:40:12 2008 (4802538C)
    f7ab2000 f7ab4780 ndistapi ndistapi.sys Sun Apr 13 13:57:27 2008 (48025797)
    f7abe000 f7abfb80 kdcom kdcom.dll Fri Aug 17 15:49:10 2001 (3B7D8346)
    f7ac0000 f7ac1100 WMILIB WMILIB.SYS Fri Aug 17 16:07:23 2001 (3B7D878B)
    f7ac2000 f7ac3000 dmload dmload.sys unavailable (00000000)
    f7ae6000 f7ae7740 DLACDBHM DLACDBHM.SYS Thu Feb 08 22:05:12 2007 (45CBF2F8)
    f7aec000 f7aed100 swenum swenum.sys Sun Apr 13 13:39:52 2008 (48025378)
    f7b02000 f7b03280 USBD USBD.SYS Fri Aug 17 16:02:58 2001 (3B7D8682)
    f7b04000 f7b05000 Fs_Rec Fs_Rec.SYS unavailable (00000000)
    f7b06000 f7b07080 Beep Beep.SYS Fri Aug 17 15:47:33 2001 (3B7D82E5)
    f7b08000 f7b09080 mnmdd mnmdd.SYS Fri Aug 17 15:57:28 2001 (3B7D8538)
    f7b0a000 f7b0b080 RDPCDD RDPCDD.sys Fri Aug 17 15:46:56 2001 (3B7D82C0)
    f7b2e000 f7b2f100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 16:07:23 2001 (3B7D878B)
    f7b34000 f7b35dc0 DLAPoolM DLAPoolM.SYS Fri Feb 22 12:18:47 2008 (47BF1207)
    f7b5c000 f7b5da80 ParVdm ParVdm.SYS Fri Aug 17 15:49:49 2001 (3B7D836D)
    f7b86000 f7b86d00 pciide pciide.sys Fri Aug 17 15:51:49 2001 (3B7D83E5)
    f7ca2000 f7ca2d00 dxgthk dxgthk.sys Fri Aug 17 15:53:12 2001 (3B7D8438)
    f7cdd000 f7cde000 Null Null.SYS unavailable (00000000)
    f7ce0000 f7ce09c0 DLADResM DLADResM.SYS Fri Feb 22 12:21:53 2008 (47BF12C1)
    f7cf8000 f7cf8860 BANTExt BANTExt.sys Wed May 27 21:43:29 1998 (356CCF51)
    f7d07000 f7d07c00 audstub audstub.sys Fri Aug 17 15:59:40 2001 (3B7D85BC)

    Unloaded modules:
    a85f1000 a861c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a862d000 a8658000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8bbb000 a8be6000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a911c000 a9124000 mbamswissarm
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00008000
    a8bf7000 a8c22000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8bf7000 a8c22000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a9b72000 a9b9d000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    f7c46000 f7c47000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00001000
    a9d55000 a9d62000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000D000
    f76ce000 f76dc000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000E000
    a9b9d000 a9bc0000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00023000
    f7b4c000 f7b4e000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00002000
    f7a6e000 f7a72000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00004000
    f774e000 f775b000 i8042prt.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000D000
    f78b6000 f78bb000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00005000
    f7a66000 f7a69000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00003000
    f78a6000 f78ab000 Flpydisk.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00005000
    f789e000 f78a5000 Fdc.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00007000
    Closing open log file c:debuglog.txt
     
  2. 2011/01/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)
    which is either an element of Doctor Web Antivirus or Malware

    If you have Doctor Web AV installed I would remove it and use MSE (Microsoft Security Essentials)

    If you do not I would head over to the Malware & Virus Removal forum and .....

    Please read this as indicated at the head of the forum and post the logs requested in a new thread.
     

  3. to hide this advert.

  4. 2011/01/05
    Cms12682

    Cms12682 Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    3
    Likes Received:
    0
    Thanks for the super fast reply, Pete! I do have Doctor Web AV installed and I'm about to remove it. The thing is, I didn't install it until after the second BSOD. So it may have caused that third one, but I don't think it's related to the first two occurrences.

    I installed it because someone mentioned it might be the Backdoor.Rustock trojan causing the problem and that DW was the only software that caught it.

    Malware Bytes and Spybot didn't find anything so I wanted to give that one a shot.

    Like I said, I'll uninstall the program but I'm still nervous something else was behind this. Thanks again for your help.
     
  5. 2011/01/05
    markmadras

    markmadras Banned

    Joined:
    2010/08/23
    Messages:
    1,529
    Likes Received:
    105
    Please provide the dump file from the first BSOD.
     
  6. 2011/01/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Your first 2 BSODs .....
    Post the debug log for one of these dumps.
    In which case visit the Malware & Virus Removal forum as I suggested.
     
  7. 2011/01/05
    Cms12682

    Cms12682 Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    3
    Likes Received:
    0
    Here's the dump file from the first BSOD:

    Opened log file 'c:debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini122710-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp3_gdr.100427-1636
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
    Debug session time: Mon Dec 27 21:20:29.062 2010 (UTC - 6:00)
    System Uptime: 0 days 14:12:13.835
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ............
    Loading User Symbols
    Loading unloaded module list
    ...............................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, bf8b15be, a872aae4, 0}

    Probably caused by : win32k.sys ( win32k!PFEOBJ::vFreepfdg+45 )

    Followup: MachineOwner
    ---------

    1: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: bf8b15be, The address that the exception occurred at
    Arg3: a872aae4, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    win32k!PFEOBJ::vFreepfdg+45
    bf8b15be f6412180 test byte ptr [ecx+21h],80h

    TRAP_FRAME: a872aae4 -- (.trap 0xffffffffa872aae4)
    .trap 0xffffffffa872aae4
    ErrCode = 00000000
    eax=e16ef858 ebx=00000000 ecx=00000201 edx=00000000 esi=a872ab80 edi=e1999130
    eip=bf8b15be esp=a872ab58 ebp=a872ab68 iopl=0 nv up ei pl nz ac pe cy
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010217
    win32k!PFEOBJ::vFreepfdg+0x45:
    bf8b15be f6412180 test byte ptr [ecx+21h],80h ds:0023:00000222=??
    .trap
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: chrome.exe

    LAST_CONTROL_TRANSFER: from bf8b1692 to bf8b15be

    STACK_TEXT:
    a872ab68 bf8b1692 e3432d08 00000000 a872abdc win32k!PFEOBJ::vFreepfdg+0x45
    a872ab88 bf8e0448 00000000 00000000 00000000 win32k!RFONTOBJ::bDeleteRFONT+0x1d
    a872abac bf8e0940 a872abdc 00000000 e3569210 win32k!PUBLIC_PFTOBJ::bLoadAFont+0x21f
    a872abd4 bf8258bb e3146830 e3569210 00000000 win32k!PFTOBJ::bUnloadWorkhorse+0x112
    a872ac00 bf825573 e17f5610 00000000 00000000 win32k!vCleanupPrivateFonts+0x4d
    a872ac18 bf823bf7 e17f5610 00000000 00000000 win32k!NtGdiCloseProcess+0xb9
    a872ac30 bf820da3 e17f5610 00000000 865dc240 win32k!GdiProcessCallout+0x102
    a872ac4c 805d2473 85795020 00000000 8581ea50 win32k!W32pProcessCallout+0x5c
    a872acf0 805d27cd 00000000 a872ad4c 804ff94f nt!PspExitThread+0x409
    a872acfc 804ff94f 8581ea50 a872ad48 a872ad3c nt!PsExitSpecialApc+0x23
    a872ad4c 806e6ef2 00000001 00000000 a872ad64 nt!KiDeliverApc+0x1af
    a872ad4c 01d09d21 00000001 00000000 a872ad64 hal!HalpApcInterrupt+0xc6
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012f8f4 00000000 00000000 00000000 00000000 0x1d09d21


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    win32k!PFEOBJ::vFreepfdg+45
    bf8b15be f6412180 test byte ptr [ecx+21h],80h

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: win32k!PFEOBJ::vFreepfdg+45

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4cc6d6a2

    FAILURE_BUCKET_ID: 0x8E_win32k!PFEOBJ::vFreepfdg+45

    BUCKET_ID: 0x8E_win32k!PFEOBJ::vFreepfdg+45

    Followup: MachineOwner
    ---------

    eax=e16ef858 ebx=00000000 ecx=00000201 edx=00000000 esi=a872ab80 edi=e1999130
    eip=bf8b15be esp=a872ab58 ebp=a872ab68 iopl=0 nv up ei pl nz ac pe cy
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010217
    win32k!PFEOBJ::vFreepfdg+0x45:
    bf8b15be f6412180 test byte ptr [ecx+21h],80h ds:0023:00000222=??
    ChildEBP RetAddr Args to Child
    a872ab68 bf8b1692 e3432d08 00000000 a872abdc win32k!PFEOBJ::vFreepfdg+0x45 (FPO: [Non-Fpo])
    a872ab88 bf8e0448 00000000 00000000 00000000 win32k!RFONTOBJ::bDeleteRFONT+0x1d (FPO: [Non-Fpo])
    a872abac bf8e0940 a872abdc 00000000 e3569210 win32k!PUBLIC_PFTOBJ::bLoadAFont+0x21f (FPO: [Non-Fpo])
    a872abd4 bf8258bb e3146830 e3569210 00000000 win32k!PFTOBJ::bUnloadWorkhorse+0x112 (FPO: [Non-Fpo])
    a872ac00 bf825573 e17f5610 00000000 00000000 win32k!vCleanupPrivateFonts+0x4d (FPO: [Non-Fpo])
    a872ac18 bf823bf7 e17f5610 00000000 00000000 win32k!NtGdiCloseProcess+0xb9 (FPO: [Non-Fpo])
    a872ac30 bf820da3 e17f5610 00000000 865dc240 win32k!GdiProcessCallout+0x102 (FPO: [Non-Fpo])
    a872ac4c 805d2473 85795020 00000000 8581ea50 win32k!W32pProcessCallout+0x5c (FPO: [Non-Fpo])
    a872acf0 805d27cd 00000000 a872ad4c 804ff94f nt!PspExitThread+0x409 (FPO: [Non-Fpo])
    a872acfc 804ff94f 8581ea50 a872ad48 a872ad3c nt!PsExitSpecialApc+0x23 (FPO: [Non-Fpo])
    a872ad4c 806e6ef2 00000001 00000000 a872ad64 nt!KiDeliverApc+0x1af (FPO: [Non-Fpo])
    a872ad4c 01d09d21 00000001 00000000 a872ad64 hal!HalpApcInterrupt+0xc6 (FPO: [0,2] TrapFrame @ a872ad64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012f8f4 00000000 00000000 00000000 00000000 0x1d09d21
    start end module name
    804d7000 806e4000 nt ntkrpamp.exe Tue Apr 27 08:04:40 2010 (4BD6E0E8)
    806e4000 80704d00 hal halmacpi.dll Sun Apr 13 13:31:27 2008 (4802517F)
    a8076000 a80a0180 kmixer kmixer.sys Sun Apr 13 13:45:07 2008 (480254B3)
    a8f6a000 a8faae00 HTTP HTTP.sys Tue Oct 20 11:20:15 2009 (4ADDE33F)
    a9323000 a9327a80 LVPr2Mon LVPr2Mon.sys Fri May 07 20:36:25 2010 (4BE4C019)
    a9433000 a945b000 AVGIDSDriver AVGIDSDriver.Sys Tue Aug 03 17:23:56 2010 (4C5896FC)
    a954b000 a9555000 AVGIDSFilter AVGIDSFilter.Sys Tue Aug 03 17:23:14 2010 (4C5896D2)
    a9753000 a97aa380 srv srv.sys Thu Aug 26 08:39:48 2010 (4C766EA4)
    a9b43000 a9b53e80 adfs adfs.SYS Thu Aug 14 09:57:15 2008 (48A447CB)
    a9b54000 a9b80180 mrxdav mrxdav.sys Sun Apr 13 13:32:42 2008 (480251CA)
    a9e57000 a9e6b480 wdmaud wdmaud.sys Sun Apr 13 14:17:18 2008 (48025C3E)
    aa0c4000 aa0da340 DLAUDF_M DLAUDF_M.SYS Fri Feb 22 12:19:06 2008 (47BF121A)
    aa0db000 aa0f06c0 DLAUDFAM DLAUDFAM.SYS Fri Feb 22 12:19:35 2008 (47BF1237)
    aa0f1000 aa108d40 DLAIFS_M DLAIFS_M.SYS Fri Feb 22 12:18:44 2008 (47BF1204)
    aa12d000 aa130900 ndisuio ndisuio.sys Sun Apr 13 13:55:57 2008 (4802573D)
    aa1c9000 aa1d7d80 sysaudio sysaudio.sys Sun Apr 13 14:15:55 2008 (48025BEB)
    aa249000 aa260900 dump_atapi dump_atapi.sys Sun Apr 13 13:40:29 2008 (4802539D)
    aa2e5000 aa2e7900 Dxapi Dxapi.sys Fri Aug 17 15:53:19 2001 (3B7D843F)
    aa301000 aa33c400 avgldx86 avgldx86.sys Mon Sep 06 19:48:07 2010 (4C858BC7)
    aa33d000 aa3ac400 mrxsmb mrxsmb.sys Wed Feb 24 07:11:05 2010 (4B852569)
    aa3ad000 aa3d7e80 rdbss rdbss.sys Sun Apr 13 14:28:38 2008 (48025EE6)
    aa3d8000 aa3f9d00 afd afd.sys Thu Aug 14 05:04:35 2008 (48A40333)
    aa3fa000 aa421c00 netbt netbt.sys Sun Apr 13 14:20:59 2008 (48025D1B)
    aa44d000 aa472500 ipnat ipnat.sys Sun Apr 13 13:57:10 2008 (48025786)
    aa473000 aa4ba980 avgtdix avgtdix.sys Tue Nov 09 14:11:29 2010 (4CD9AAF1)
    aa4bb000 aa513480 tcpip tcpip.sys Fri Jun 20 06:51:09 2008 (485B99AD)
    aa514000 aa526600 ipsec ipsec.sys Sun Apr 13 14:19:42 2008 (48025CCE)
    aa547000 aa55a000 mozy mozy.sys Mon Nov 08 16:26:36 2010 (4CD8791C)
    aa720000 aa72a600 DRVNDDM DRVNDDM.SYS Fri Feb 09 14:33:42 2007 (45CCDAA6)
    aa730000 aa73a000 AVGIDSShim AVGIDSShim.Sys Tue Aug 03 17:25:52 2010 (4C589770)
    bf000000 bf011600 dxg dxg.sys Sun Apr 13 13:38:27 2008 (48025323)
    bf012000 bf020000 ialmrnt5 ialmrnt5.dll Tue Apr 05 16:38:42 2005 (42530562)
    bf020000 bf040000 ialmdnt5 ialmdnt5.dll Tue Apr 05 16:38:35 2005 (4253055B)
    bf040000 bf06f680 ialmdev5 ialmdev5.DLL Tue Apr 05 16:38:25 2005 (42530551)
    bf070000 bf14c000 ialmdd5 ialmdd5.DLL Tue Apr 05 16:45:43 2005 (42530707)
    bf800000 bf9c4780 win32k win32k.sys Tue Oct 26 08:24:50 2010 (4CC6D6A2)
    bffa0000 bffe6d00 ATMFD ATMFD.DLL Thu Oct 28 08:13:22 2010 (4CC976F2)
    f6bf7000 f6c54f00 update update.sys Sun Apr 13 13:39:46 2008 (48025372)
    f6c55000 f6c84e80 rdpdr rdpdr.sys Sun Apr 13 13:32:50 2008 (480251D2)
    f6c85000 f6c95e00 psched psched.sys Sun Apr 13 13:56:36 2008 (48025764)
    f6c96000 f6cac580 ndiswan ndiswan.sys Sun Apr 13 14:20:41 2008 (48025D09)
    f6cad000 f6ce6000 azogr9nv azogr9nv.SYS Tue Jul 14 16:12:41 2009 (4A5CF4C9)
    f6ce6000 f6cf9900 parport parport.sys Sun Apr 13 13:40:09 2008 (48025389)
    f6cfa000 f6dacf00 senfilt senfilt.sys Thu Sep 16 21:02:52 2004 (414A45CC)
    f6dad000 f6dcf700 ks ks.sys Sun Apr 13 14:16:34 2008 (48025C12)
    f6dd0000 f6df3a80 portcls portcls.sys Sun Apr 13 14:19:40 2008 (48025CCC)
    f6df4000 f6e33900 smwdm smwdm.sys Thu Jan 27 14:31:04 2005 (41F94F88)
    f6e34000 f6e57200 USBPORT USBPORT.SYS Sun Apr 13 13:45:34 2008 (480254CE)
    f6e58000 f6e78600 b57xp32 b57xp32.sys Thu Mar 17 19:30:08 2005 (423A2110)
    f6e79000 f6e8cf00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 13:44:39 2008 (48025497)
    f6e8d000 f6f57c60 ialmnt5 ialmnt5.sys Tue Apr 05 16:46:26 2005 (42530732)
    f7182000 f7185c80 mssmbios mssmbios.sys Sun Apr 13 13:36:45 2008 (480252BD)
    f71c3000 f71dcb80 Mup Mup.sys Sun Apr 13 14:17:05 2008 (48025C31)
    f71dd000 f7209980 NDIS NDIS.sys Sun Apr 13 14:20:35 2008 (48025D03)
    f720a000 f7296600 Ntfs Ntfs.sys Sun Apr 13 14:15:49 2008 (48025BE5)
    f7297000 f72adb00 KSecDD KSecDD.sys Wed Jun 24 06:18:40 2009 (4A420B90)
    f72ae000 f72cdf80 symsnap symsnap.sys Wed Dec 12 13:31:49 2007 (47603725)
    f72ce000 f72e3fe0 DRVMCDB DRVMCDB.SYS Fri Jul 21 13:20:31 2006 (44C11AEF)
    f72e4000 f72f5f00 sr sr.sys Sun Apr 13 13:36:50 2008 (480252C2)
    f72f6000 f7315b00 fltMgr fltMgr.sys Sun Apr 13 13:32:58 2008 (480251DA)
    f7316000 f732d900 atapi atapi.sys Sun Apr 13 13:40:29 2008 (4802539D)
    f732e000 f7353700 dmio dmio.sys Sun Apr 13 13:44:45 2008 (4802549D)
    f7354000 f7372880 ftdisk ftdisk.sys Fri Aug 17 15:52:41 2001 (3B7D8419)
    f7373000 f7383a80 pci pci.sys Sun Apr 13 13:36:43 2008 (480252BB)
    f7384000 f73b1d80 ACPI ACPI.sys Sun Apr 13 13:36:33 2008 (480252B1)
    f73b2000 f73c9880 SCSIPORT SCSIPORT.SYS Sun Apr 13 13:40:29 2008 (4802539D)
    f73ca000 f74bd000 sptd sptd.sys Sun Oct 11 15:54:02 2009 (4AD245EA)
    f75be000 f75c7180 isapnp isapnp.sys Sun Apr 13 13:36:40 2008 (480252B8)
    f75ce000 f75d8580 MountMgr MountMgr.sys Sun Apr 13 13:39:45 2008 (48025371)
    f75de000 f75eac80 VolSnap VolSnap.sys Sun Apr 13 13:41:00 2008 (480253BC)
    f75ee000 f75f6e00 disk disk.sys Sun Apr 13 13:40:46 2008 (480253AE)
    f75fe000 f760a180 CLASSPNP CLASSPNP.SYS Sun Apr 13 14:16:21 2008 (48025C05)
    f760e000 f7616b40 PxHelp20 PxHelp20.sys Mon Jul 24 19:18:21 2006 (44C5634D)
    f761e000 f7627000 AVGIDSEH AVGIDSEH.Sys Mon Sep 13 17:46:31 2010 (4C8EA9C7)
    f763e000 f7647f00 termdd termdd.sys Sun Apr 13 13:38:36 2008 (4802532C)
    f764e000 f7658000 NDProxy NDProxy.SYS Tue Nov 02 10:17:02 2010 (4CD02B6E)
    f76be000 f76cc880 usbhub usbhub.sys Sun Apr 13 13:45:36 2008 (480254D0)
    f76de000 f76ea000 avgmfx86 avgmfx86.sys Mon Sep 06 19:48:01 2010 (4C858BC1)
    f76fe000 f7706700 wanarp wanarp.sys Sun Apr 13 13:57:20 2008 (48025790)
    f770e000 f7716780 netbios netbios.sys Sun Apr 13 13:56:01 2008 (48025741)
    f771e000 f7728e00 Fips Fips.SYS Sun Apr 13 13:33:27 2008 (480251F7)
    f772e000 f7737000 HIDCLASS HIDCLASS.SYS Sun Apr 13 13:45:25 2008 (480254C5)
    f774e000 f775d900 Cdfs Cdfs.SYS Sun Apr 13 14:14:21 2008 (48025B8D)
    f779e000 f77a6e00 intelppm intelppm.sys Sun Apr 13 13:31:31 2008 (48025183)
    f77ae000 f77bcb00 drmk drmk.sys Sun Apr 13 13:45:12 2008 (480254B8)
    f77be000 f77cdc00 serial serial.sys Sun Apr 13 14:15:44 2008 (48025BE0)
    f77ce000 f77d8480 imapi imapi.sys Sun Apr 13 13:40:57 2008 (480253B9)
    f77de000 f77ed600 cdrom cdrom.sys Sun Apr 13 13:40:45 2008 (480253AD)
    f77ee000 f77fc100 redbook redbook.sys Sun Apr 13 13:40:27 2008 (4802539B)
    f77fe000 f780a880 rasl2tp rasl2tp.sys Sun Apr 13 14:19:43 2008 (48025CCF)
    f780e000 f7818200 raspppoe raspppoe.sys Sun Apr 13 13:57:31 2008 (4802579B)
    f781e000 f7829d00 raspptp raspptp.sys Sun Apr 13 14:19:47 2008 (48025CD3)
    f782e000 f7836900 msgpc msgpc.sys Sun Apr 13 13:56:32 2008 (48025760)
    f783e000 f7844180 PCIIDEX PCIIDEX.SYS Sun Apr 13 13:40:29 2008 (4802539D)
    f7846000 f784ad00 PartMgr PartMgr.sys Sun Apr 13 13:40:48 2008 (480253B0)
    f784e000 f7852b80 avgrkx86 avgrkx86.sys Mon Sep 06 19:48:16 2010 (4C858BD0)
    f78a6000 f78add80 usbccgp usbccgp.sys Sun Apr 13 13:45:38 2008 (480254D2)
    f78b6000 f78bb2e0 DLARTL_M DLARTL_M.SYS Thu Feb 08 22:04:41 2007 (45CBF2D9)
    f78be000 f78c4180 HIDPARSE HIDPARSE.SYS Sun Apr 13 13:45:22 2008 (480254C2)
    f78c6000 f78cb200 vga vga.sys Sun Apr 13 13:44:40 2008 (48025498)
    f78ce000 f78d2a80 Msfs Msfs.SYS Sun Apr 13 13:32:38 2008 (480251C6)
    f78d6000 f78dd880 Npfs Npfs.SYS Sun Apr 13 13:32:38 2008 (480251C6)
    f78fe000 f7903080 usbuhci usbuhci.sys Sun Apr 13 13:45:34 2008 (480254CE)
    f7906000 f790d600 usbehci usbehci.sys Sun Apr 13 13:45:34 2008 (480254CE)
    f790e000 f7915000 GEARAspiWDM GEARAspiWDM.sys Mon Aug 07 12:11:27 2006 (44D7743F)
    f7916000 f791a500 watchdog watchdog.sys Sun Apr 13 13:44:59 2008 (480254AB)
    f7926000 f792abc0 DLAOPIOM DLAOPIOM.SYS Fri Feb 22 12:20:52 2008 (47BF1284)
    f792e000 f7934e20 DLABMFSM DLABMFSM.SYS Fri Feb 22 12:19:59 2008 (47BF124F)
    f7936000 f793c3e0 DLABOIOM DLABOIOM.SYS Fri Feb 22 12:19:53 2008 (47BF1249)
    f793e000 f7945f80 v2imount v2imount.sys Wed Dec 12 13:07:19 2007 (47603167)
    f7976000 f797aa80 TDI TDI.SYS Sun Apr 13 14:00:04 2008 (48025834)
    f797e000 f7982580 ptilink ptilink.sys Fri Aug 17 15:49:53 2001 (3B7D8371)
    f7986000 f798a080 raspti raspti.sys Fri Aug 17 15:55:32 2001 (3B7D84C4)
    f798e000 f7994000 kbdclass kbdclass.sys Sun Apr 13 13:39:46 2008 (48025372)
    f7996000 f799ba00 mouclass mouclass.sys Sun Apr 13 13:39:47 2008 (48025373)
    f79ce000 f79d1000 BOOTVID BOOTVID.dll Fri Aug 17 15:49:09 2001 (3B7D8345)
    f7a6e000 f7a70280 rasacd rasacd.sys Fri Aug 17 15:55:39 2001 (3B7D84CB)
    f7a86000 f7a88880 hidusb hidusb.sys Sun Apr 13 13:45:27 2008 (480254C7)
    f7a92000 f7a94f80 mouhid mouhid.sys Fri Aug 17 15:47:57 2001 (3B7D82FD)
    f7a9a000 f7a9dd80 serenum serenum.sys Sun Apr 13 13:40:12 2008 (4802538C)
    f7aa2000 f7aa5900 kbdhid kbdhid.sys Sun Apr 13 13:39:47 2008 (48025373)
    f7aae000 f7ab0780 ndistapi ndistapi.sys Sun Apr 13 13:57:27 2008 (48025797)
    f7abe000 f7abfb80 kdcom kdcom.dll Fri Aug 17 15:49:10 2001 (3B7D8346)
    f7ac0000 f7ac1100 WMILIB WMILIB.SYS Fri Aug 17 16:07:23 2001 (3B7D878B)
    f7ac2000 f7ac3000 dmload dmload.sys unavailable (00000000)
    f7af2000 f7af3740 DLACDBHM DLACDBHM.SYS Thu Feb 08 22:05:12 2007 (45CBF2F8)
    f7af8000 f7af9100 swenum swenum.sys Sun Apr 13 13:39:52 2008 (48025378)
    f7b0e000 f7b0f280 USBD USBD.SYS Fri Aug 17 16:02:58 2001 (3B7D8682)
    f7b10000 f7b11000 Fs_Rec Fs_Rec.SYS unavailable (00000000)
    f7b12000 f7b13080 Beep Beep.SYS Fri Aug 17 15:47:33 2001 (3B7D82E5)
    f7b14000 f7b15080 mnmdd mnmdd.SYS Fri Aug 17 15:57:28 2001 (3B7D8538)
    f7b16000 f7b17080 RDPCDD RDPCDD.sys Fri Aug 17 15:46:56 2001 (3B7D82C0)
    f7b1e000 f7b1f100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 16:07:23 2001 (3B7D878B)
    f7b28000 f7b29dc0 DLAPoolM DLAPoolM.SYS Fri Feb 22 12:18:47 2008 (47BF1207)
    f7b56000 f7b57000 ParVdm ParVdm.SYS unavailable (00000000)
    f7b86000 f7b86d00 pciide pciide.sys Fri Aug 17 15:51:49 2001 (3B7D83E5)
    f7c1d000 f7c1dd00 dxgthk dxgthk.sys Fri Aug 17 15:53:12 2001 (3B7D8438)
    f7cae000 f7cae9c0 DLADResM DLADResM.SYS Fri Feb 22 12:21:53 2008 (47BF12C1)
    f7cda000 f7cdb000 Null Null.SYS unavailable (00000000)
    f7cfb000 f7cfbc00 audstub audstub.sys Fri Aug 17 15:59:40 2001 (3B7D85BC)

    Unloaded modules:
    a78d3000 a78fe000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a7d9b000 a7dc6000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a832e000 a8359000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a7b36000 a7b61000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8622000 a864d000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a866f000 a869a000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a9e6c000 a9e70000 HPZipr12.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00004000
    a8c1c000 a8c29000 HPZid412.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000D000
    f78e6000 f78ed000 USBSTOR.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00007000
    f7956000 f795c000 HPZius12.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00006000
    a931b000 a9322000 usbprint.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00007000
    a9053000 a9057000 usbscan.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00004000
    a8a6b000 a8a96000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8a5a000 a8a85000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8afc000 a8b27000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8b51000 a8b7c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8cbc000 a8ce7000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8dd7000 a8e02000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a8dd7000 a8e02000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    a9d69000 a9d94000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0002B000
    f7cdc000 f7cdd000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00001000
    aa740000 aa74d000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000D000
    aa1a9000 aa1b7000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000E000
    a9d94000 a9db7000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00023000
    f7b36000 f7b38000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00002000
    f7a6a000 f7a6e000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00004000
    f76ee000 f76fb000 i8042prt.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000D000
    f78ae000 f78b3000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00005000
    f6f58000 f6f5b000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00003000
    f789e000 f78a3000 Flpydisk.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00005000
    f7896000 f789d000 Fdc.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00007000
    Closing open log file c:debuglog.txt
     
  8. 2011/01/05
    markmadras

    markmadras Banned

    Joined:
    2010/08/23
    Messages:
    1,529
    Likes Received:
    105
    This log points to Google, do you have any Google components installed?

    Apart from a handfull of drivers dating back to 2001 I can't see much wrong and as google is not usually a problem I would go to our Malware and Virus forum and have your system checked out. The link is in PeteC's post.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.