Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

0x000000C5 BSOD error


  • Please log in to reply
17 replies to this topic

#1 ermat_46

ermat_46

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 07 February 2012 - 05:00 PM

Appearently, I'm having a BSOD (2 times) when I boot Windows. The stop error is 0x000000C5 (0x00020214, 0x00000002, 0x00000001, 0x82B6037D). There is no technical error listed, and the only step I did is to look at BlueScreenView. I haven't scanned yet for any virus. Also, I'm using AVG as anti-virus, and Spybot 2.0.

Attached are the minidumps.

Also, here are the specs:

---- System ----
Manufacturer: GIGABYTE
Processor: Intel® Pentium® D CPU 3.00GHz
RAM: 2.00 MB
System Type: 32-bit Operating System
---------------
Free Space:
C:/ (Main Drive. One with the OS Installed) - 9.58 GB of 31.3 GB
D:/ (Extra Drive) - 2.04 GB of 232 GB

Please help. Thanks.

Attached Files



BC AdBot (Login to Remove)

 


#2 Allan

Allan

  • BC Advisor
  • 8,562 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey
  • Local time:12:07 PM

Posted 07 February 2012 - 05:04 PM

Download BlueScreenView:
http://www.nirsoft.net/utils/blue_screen_view.html
unzip downloaded file and double click on BlueScreenView.exe to run the program.
when scanning is done, go to EDIT - Select All
Go to FILE - SAVE Selected Items, and save the report as BSOD.txt
Open BSOD.txt in Notepad, copy all of the content, and paste it into your next reply

#3 ReviverSoft

ReviverSoft

    Happy to help!


  • Members
  • 1,552 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere on this planet...
  • Local time:09:07 AM

Posted 07 February 2012 - 07:55 PM

The 0x000000C5 stop error (bsod) indicates a problem with the device drivers. A faulty driver that's acting up or a recent driver update that is incompatible.

If you recently updated a driver on your PC, you might want to restart your PC in the safe mode and roll back to the original driver. Alternatively, if you have the original driver installed, try updating it to the latest version.
ReviverSoft - Happy to help!

#4 ermat_46

ermat_46
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 08 February 2012 - 02:46 AM

==================================================
Dump File : 020812-27281-01.dmp
Crash Time : 2/8/2012 5:23:28 AM
Bug Check String : DRIVER_CORRUPTED_EXPOOL
Bug Check Code : 0x000000c5
Parameter 1 : 0x00020214
Parameter 2 : 0x00000002
Parameter 3 : 0x00000001
Parameter 4 : 0x82b6037d
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+467eb
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+467eb
Stack Address 1 : ntkrnlpa.exe+12037d
Stack Address 2 : ntkrnlpa.exe+8c727
Stack Address 3 : ntkrnlpa.exe+b6acf
Computer Name :
Full Path : C:\Windows\Minidump\020812-27281-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 151,344
==================================================

==================================================
Dump File : 020412-39093-01.dmp
Crash Time : 2/4/2012 3:10:46 PM
Bug Check String : DRIVER_CORRUPTED_EXPOOL
Bug Check Code : 0x000000c5
Parameter 1 : 0x00000404
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0x82b2a87b
Caused By Driver : Ntfs.sys
Caused By Address : Ntfs.sys+9437d
File Description : NT File System Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+467eb
Stack Address 1 : ntkrnlpa.exe+12087b
Stack Address 2 : ntkrnlpa.exe+11f8aa
Stack Address 3 : ntkrnlpa.exe+25f750
Computer Name :
Full Path : C:\Windows\Minidump\020412-39093-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 151,264
==================================================


Also @ReviverSoft, I didn't update any driver on my PC. It was just freshly reformatted because I had the motherboard of the CPU replaced. I looked at the Device Manager in Control Panel, and no one gives a warning sign.

#5 Allan

Allan

  • BC Advisor
  • 8,562 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey
  • Local time:12:07 PM

Posted 08 February 2012 - 06:26 AM

After reinstalling the OS did you download and install all of the CORRECT drivers starting with the CHIPSET driver? And the fact that it is a brand new install is something you should have mentioned in your first post (try to give as much accurate and relevant information as possible so we have everything we need to try to help)

#6 hamluis

hamluis

    Moderator


  • Moderator
  • 55,378 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:11:07 AM

Posted 08 February 2012 - 11:43 AM

<<It was just freshly reformatted because I had the motherboard of the CPU replaced>>

What disk or other method...was used to do this install?

Publish a Snapshot using Speccy - http://www.bleepingcomputer.com/forums/topic323892.html/page__p__1797792#entry1797792

Louis

#7 ermat_46

ermat_46
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 February 2012 - 04:45 AM

After reinstalling the OS did you download and install all of the CORRECT drivers starting with the CHIPSET driver? And the fact that it is a brand new install is something you should have mentioned in your first post (try to give as much accurate and relevant information as possible so we have everything we need to try to help)


Sorry. Is there a way to check if I have installed all the correct drivers? I think I've installed them correctly, but I want to make sure. Thanks.

I tried to do hamluis' suggestion to post the complete specs anyway, here's the link: http://speccy.piriform.com/results/lm1PnaSn0agvj84RLwlNelH
I hope that this would help.

#8 Allan

Allan

  • BC Advisor
  • 8,562 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey
  • Local time:12:07 PM

Posted 09 February 2012 - 07:55 AM

Did you install the chipset driver for your new motherboard?

#9 jcgriff2

jcgriff2

  • BSOD Kernel Dump Expert
  • 1,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey Shore
  • Local time:12:07 PM

Posted 09 February 2012 - 09:48 AM

Hi -

Bugcheck 0xc5 = invalid memory referenced

AVG was named probable cause in the 4 Feb dump.

I suggest AVG removal for now - http://kb.eset.com/esetkb/index?page=content&id=SOLN146

I know you recently reinstalled Windows 7, but why are there no Windows updates installed?
www.update.microsoft.com

See if Driver Verifier flags any 3rd party drivers - http://sysnative.com/0x1/Driver_Verifier.htm

How old is the hardware? Check for BIOS update -
BiosVendor = Award Software International, Inc.
BiosVersion = F8
BiosReleaseDate = 08/31/2006

Regards. . .

jcgriff2



`


Opened log file 'C:\Users\PalmDesert\_jcgriff2_\dbug\__Kernel__\_99-dbug.txt'Microsoft (R) Windows Debugger Version 6.2.8102.0 AMD64Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\Users\PalmDesert\_jcgriff2_\dbug\__Kernel__\020412-39093-01.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: SRV*a:\symbols*http://msdl.microsoft.com/download/symbolsExecutable search path is: Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSBuilt by: 7600.16385.x86fre.win7_rtm.090713-1255Machine Name:Kernel base = 0x82a0a000 PsLoadedModuleList = 0x82b52810Debug session time: Sat Feb  4 02:09:07.859 2012 (UTC - 5:00)System Uptime: 0 days 0:00:54.937Loading Kernel Symbols..............................................................................................................................................Loading User SymbolsLoading unloaded module list....********************************************************************************                                                                             **                        Bugcheck Analysis                                    **                                                                             ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck C5, {404, 2, 0, 82b2a87b}*** WARNING: Unable to verify timestamp for avgmfx86.sys*** ERROR: Module load completed but symbols could not be loaded for avgmfx86.sysProbably caused by : Pool_Corruption ( nt!ExDeferredFreePool+21b )Followup: Pool_corruption---------0: kd> !analyze -v;r;kv;lmtn;lmtsmn;.bugcheck;!peb;!sysinfo cpuinfo;!sysinfo machineid; !sysinfo cpuspeed; !sysinfo smbios********************************************************************************                                                                             **                        Bugcheck Analysis                                    **                                                                             ********************************************************************************DRIVER_CORRUPTED_EXPOOL (c5)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high.  This iscaused by drivers that have corrupted the system pool.  Run the driververifier against any new (or suspect) drivers, and if that doesn't turn upthe culprit, then use gflags to enable special pool.Arguments:Arg1: 00000404, memory referencedArg2: 00000002, IRQLArg3: 00000000, value 0 = read operation, 1 = write operationArg4: 82b2a87b, address which referenced memoryDebugging Details:------------------TRIAGER: Could not open triage file : K:\WinDDK\Windows Kits\8.0\Debuggers\x64\triage\modclass.ini, error 2BUGCHECK_STR:  0xC5_2CURRENT_IRQL:  2FAULTING_IP: nt!ExDeferredFreePool+21b82b2a87b 397b04          cmp     dword ptr [ebx+4],ediCUSTOMER_CRASH_COUNT:  1DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULTPROCESS_NAME:  avgwdsvc.exeTRAP_FRAME:  9095375c -- (.trap 0xffffffff9095375c)ErrCode = 00000000eax=86b071a0 ebx=00000400 ecx=000001ff edx=00000000 esi=86b07000 edi=86b07008eip=82b2a87b esp=909537d0 ebp=90953808 iopl=0         nv up ei pl nz na po nccs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010202nt!ExDeferredFreePool+0x21b:82b2a87b 397b04          cmp     dword ptr [ebx+4],edi ds:0023:00000404=????????Resetting default scopeLAST_CONTROL_TRANSFER:  from 82b2a87b to 82a507ebSTACK_TEXT:  9095375c 82b2a87b badb0d00 00000000 00000000 nt!KiTrap0E+0x2cf90953808 82b298aa 82b3f8c0 00000000 00000000 nt!ExDeferredFreePool+0x21b90953870 82c69750 8677d3f8 00000000 909538b4 nt!ExFreePoolWithTag+0x8a490953894 82c4be9a 864fd038 848bd4c0 864fd020 nt!IopDeleteFileObjectExtension+0xea909538dc 82c2b6f4 864fd038 864fd038 864fd020 nt!IopDeleteFile+0x1df909538f4 82a72f60 00000000 85f42a58 864fd020 nt!ObpRemoveObjectRoutine+0x5990953908 82a72ed0 864fd038 82c4f78c 89801d68 nt!ObfDereferenceObjectWithTag+0x8890953910 82c4f78c 89801d68 85f42a58 000011f8 nt!ObfDereferenceObject+0xd90953950 82c50f72 89801d68 996523f0 8483bbb0 nt!ObpCloseHandleTableEntry+0x21d90953980 82c510ea 8483bbb0 00000000 90953a24 nt!ObpCloseHandle+0x7f9095399c 82a4d42a 800011f8 90953a44 82a4ad8d nt!NtClose+0x4e9095399c 82a4ad8d 800011f8 90953a44 82a4ad8d nt!KiFastCallEntry+0x12a90953a18 889ab082 800011f8 00000000 86a53a28 nt!ZwClose+0x1190953a44 889abdf4 00a53a28 00000000 86a53a28 fltmgr!FltpExpandShortNames+0x30490953a60 889ac505 86a50000 00000000 86a4f384 fltmgr!FltpGetNormalizedFileNameWorker+0xae90953a78 889a9765 86a53a28 00000000 86a53a28 fltmgr!FltpGetNormalizedFileName+0x1990953a90 88993b21 86a53a28 00000000 00000000 fltmgr!FltpCreateFileNameInformation+0x8190953ac0 88993fa3 86a28904 865fc898 90953b38 fltmgr!FltpGetFileNameInformation+0x32190953ae8 88c0148e 12b073d8 00000401 90953b10 fltmgr!FltGetFileNameInformation+0x12bWARNING: Stack unwind information not available. Following frames may be wrong.90953b18 8898daeb 86b073d8 90953b38 90953b64 avgmfx86+0x148e90953b84 889909f0 90953bd8 86b8d3d0 86b8d5a8 fltmgr!FltpPerformPreCallbacks+0x34d90953b9c 88990f01 90953bd8 00000000 85644c80 fltmgr!FltpPassThroughInternal+0x4090953bc0 889913ba 12953bd8 85644c80 00000000 fltmgr!FltpPassThrough+0x20390953bf0 82a464bc 85644c80 86b8d3d0 8588c038 fltmgr!FltpDispatch+0xb490953c08 82c65ea2 848bd4c0 8588c020 00000001 nt!IofCallDriver+0x6390953c48 82c2cc0a 8674e330 8588c038 00000001 nt!IopCloseFile+0x2f390953c94 82c4f772 8674e330 96718f68 85f42a58 nt!ObpDecrementHandleCount+0x13990953cdc 82c50f72 96718f68 9672b7d0 8674e330 nt!ObpCloseHandleTableEntry+0x20390953d0c 82c510ea 8674e330 85f42a01 0238f604 nt!ObpCloseHandle+0x7f90953d28 82a4d42a 000003e8 0238f9c0 775e64f4 nt!NtClose+0x4e90953d28 775e64f4 000003e8 0238f9c0 775e64f4 nt!KiFastCallEntry+0x12a0238f9c0 00000000 00000000 00000000 00000000 0x775e64f4STACK_COMMAND:  kbFOLLOWUP_IP: nt!ExDeferredFreePool+21b82b2a87b 397b04          cmp     dword ptr [ebx+4],ediSYMBOL_STACK_INDEX:  1SYMBOL_NAME:  nt!ExDeferredFreePool+21bFOLLOWUP_NAME:  Pool_corruptionIMAGE_NAME:  Pool_CorruptionDEBUG_FLR_IMAGE_TIMESTAMP:  0MODULE_NAME: Pool_CorruptionFAILURE_BUCKET_ID:  0xC5_2_nt!ExDeferredFreePool+21bBUCKET_ID:  0xC5_2_nt!ExDeferredFreePool+21bFollowup: Pool_corruption---------eax=82b4117c ebx=90953802 ecx=00000001 edx=00000000 esi=82b33d20 edi=00000000eip=82a507eb esp=90953744 ebp=9095375c iopl=0         nv up ei pl nz na po nccs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00000202nt!KiTrap0E+0x2cf:82a507eb 833dc4dab68200  cmp     dword ptr [nt!KiFreezeFlag (82b6dac4)],0 ds:0023:82b6dac4=????????ChildEBP RetAddr  Args to Child              9095375c 82b2a87b badb0d00 00000000 00000000 nt!KiTrap0E+0x2cf (FPO: [0,0] TrapFrame @ 9095375c)90953808 82b298aa 82b3f8c0 00000000 00000000 nt!ExDeferredFreePool+0x21b90953870 82c69750 8677d3f8 00000000 909538b4 nt!ExFreePoolWithTag+0x8a490953894 82c4be9a 864fd038 848bd4c0 864fd020 nt!IopDeleteFileObjectExtension+0xea909538dc 82c2b6f4 864fd038 864fd038 864fd020 nt!IopDeleteFile+0x1df909538f4 82a72f60 00000000 85f42a58 864fd020 nt!ObpRemoveObjectRoutine+0x5990953908 82a72ed0 864fd038 82c4f78c 89801d68 nt!ObfDereferenceObjectWithTag+0x88 (FPO: [0,0,3])90953910 82c4f78c 89801d68 85f42a58 000011f8 nt!ObfDereferenceObject+0xd (FPO: [0,1,0])90953950 82c50f72 89801d68 996523f0 8483bbb0 nt!ObpCloseHandleTableEntry+0x21d90953980 82c510ea 8483bbb0 00000000 90953a24 nt!ObpCloseHandle+0x7f9095399c 82a4d42a 800011f8 90953a44 82a4ad8d nt!NtClose+0x4e9095399c 82a4ad8d 800011f8 90953a44 82a4ad8d nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ 909539a8)90953a18 889ab082 800011f8 00000000 86a53a28 nt!ZwClose+0x11 (FPO: [1,0,0])90953a44 889abdf4 00a53a28 00000000 86a53a28 fltmgr!FltpExpandShortNames+0x304 (FPO: [Non-Fpo])90953a60 889ac505 86a50000 00000000 86a4f384 fltmgr!FltpGetNormalizedFileNameWorker+0xae (FPO: [Non-Fpo])90953a78 889a9765 86a53a28 00000000 86a53a28 fltmgr!FltpGetNormalizedFileName+0x19 (FPO: [Non-Fpo])90953a90 88993b21 86a53a28 00000000 00000000 fltmgr!FltpCreateFileNameInformation+0x81 (FPO: [Non-Fpo])90953ac0 88993fa3 86a28904 865fc898 90953b38 fltmgr!FltpGetFileNameInformation+0x321 (FPO: [Non-Fpo])90953ae8 88c0148e 12b073d8 00000401 90953b10 fltmgr!FltGetFileNameInformation+0x12b (FPO: [Non-Fpo])WARNING: Stack unwind information not available. Following frames may be wrong.90953b18 8898daeb 86b073d8 90953b38 90953b64 avgmfx86+0x148e90953b84 889909f0 90953bd8 86b8d3d0 86b8d5a8 fltmgr!FltpPerformPreCallbacks+0x34d (FPO: [Non-Fpo])90953b9c 88990f01 90953bd8 00000000 85644c80 fltmgr!FltpPassThroughInternal+0x40 (FPO: [Non-Fpo])90953bc0 889913ba 12953bd8 85644c80 00000000 fltmgr!FltpPassThrough+0x203 (FPO: [Non-Fpo])90953bf0 82a464bc 85644c80 86b8d3d0 8588c038 fltmgr!FltpDispatch+0xb4 (FPO: [Non-Fpo])90953c08 82c65ea2 848bd4c0 8588c020 00000001 nt!IofCallDriver+0x6390953c48 82c2cc0a 8674e330 8588c038 00000001 nt!IopCloseFile+0x2f390953c94 82c4f772 8674e330 96718f68 85f42a58 nt!ObpDecrementHandleCount+0x13990953cdc 82c50f72 96718f68 9672b7d0 8674e330 nt!ObpCloseHandleTableEntry+0x20390953d0c 82c510ea 8674e330 85f42a01 0238f604 nt!ObpCloseHandle+0x7f90953d28 82a4d42a 000003e8 0238f9c0 775e64f4 nt!NtClose+0x4e90953d28 775e64f4 000003e8 0238f9c0 775e64f4 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ 90953d34)0238f9c0 00000000 00000000 00000000 00000000 0x775e64f4start    end        module name80ba1000 80ba9000   kdcom    kdcom.dll    Mon Jul 13 21:08:58 2009 (4A5BDAAA)82a0a000 82e1a000   nt       ntkrpamp.exe Mon Jul 13 19:15:19 2009 (4A5BC007)82e1a000 82e51000   hal      halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)88601000 88679000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:06:41 2009 (4A5BDA21)88679000 8868a000   PSHED    PSHED.dll    Mon Jul 13 21:09:36 2009 (4A5BDAD0)8868a000 88692000   BOOTVID  BOOTVID.dll  Mon Jul 13 21:04:34 2009 (4A5BD9A2)88692000 886d4000   CLFS     CLFS.SYS     Mon Jul 13 19:11:10 2009 (4A5BBF0E)886d4000 8877f000   CI       CI.dll       Mon Jul 13 21:09:28 2009 (4A5BDAC8)8877f000 887f0000   Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)887f0000 887fe000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:11:25 2009 (4A5BBF1D)88800000 88808000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:01:40 2009 (4A5BCAE4)88808000 88810000   rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)88810000 88818000   rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)88818000 88823000   Msfs     Msfs.SYS     Mon Jul 13 19:11:26 2009 (4A5BBF1E)88823000 88831000   Npfs     Npfs.SYS     Mon Jul 13 19:11:31 2009 (4A5BBF23)88831000 88879000   ACPI     ACPI.sys     Mon Jul 13 19:11:11 2009 (4A5BBF0F)88879000 88882000   WMILIB   WMILIB.SYS   Mon Jul 13 19:11:22 2009 (4A5BBF1A)88882000 8888a000   msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)8888a000 888b4000   pci      pci.sys      Mon Jul 13 19:11:16 2009 (4A5BBF14)888b4000 888bf000   vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)888bf000 888d0000   partmgr  partmgr.sys  Mon Jul 13 19:11:35 2009 (4A5BBF27)888d0000 888e0000   volmgr   volmgr.sys   Mon Jul 13 19:11:25 2009 (4A5BBF1D)888e0000 8892b000   volmgrx  volmgrx.sys  Mon Jul 13 19:11:41 2009 (4A5BBF2D)8892b000 88932000   intelide intelide.sys Mon Jul 13 19:11:19 2009 (4A5BBF17)88932000 88940000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:11:15 2009 (4A5BBF13)88940000 88956000   mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)88956000 8895f000   atapi    atapi.sys    Mon Jul 13 19:11:15 2009 (4A5BBF13)8895f000 88982000   ataport  ataport.SYS  Mon Jul 13 19:11:18 2009 (4A5BBF16)88982000 8898b000   amdxata  amdxata.sys  Tue May 19 13:57:35 2009 (4A12F30F)8898b000 889bf000   fltmgr   fltmgr.sys   Mon Jul 13 19:11:13 2009 (4A5BBF11)889bf000 889d0000   fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)889d0000 889f1000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)889f1000 889fe000   watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)88a00000 88a09000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:11:14 2009 (4A5BBF12)88a09000 88a10000   Null     Null.SYS     Mon Jul 13 19:11:12 2009 (4A5BBF10)88a10000 88a17000   Beep     Beep.SYS     Mon Jul 13 19:45:00 2009 (4A5BC6FC)88a17000 88a23000   vga      vga.sys      Mon Jul 13 19:25:50 2009 (4A5BC27E)88a27000 88b56000   Ntfs     Ntfs.sys     Mon Jul 13 19:12:05 2009 (4A5BBF45)88b56000 88b81000   msrpc    msrpc.sys    Mon Jul 13 19:11:59 2009 (4A5BBF3F)88b81000 88b94000   ksecdd   ksecdd.sys   Mon Jul 13 19:11:56 2009 (4A5BBF3C)88b94000 88bf1000   cng      cng.sys      Mon Jul 13 19:32:55 2009 (4A5BC427)88bf1000 88bff000   pcw      pcw.sys      Mon Jul 13 19:11:10 2009 (4A5BBF0E)88c00000 88c0c000   avgmfx86 avgmfx86.sys Tue Mar 01 07:23:55 2011 (4D6CE55B)88c0e000 88cc5000   ndis     ndis.sys     Mon Jul 13 19:12:24 2009 (4A5BBF58)88cc5000 88d03000   NETIO    NETIO.SYS    Mon Jul 13 19:12:35 2009 (4A5BBF63)88d03000 88d28000   ksecpkg  ksecpkg.sys  Mon Jul 13 19:34:00 2009 (4A5BC468)88d28000 88d38000   mup      mup.sys      Mon Jul 13 19:14:14 2009 (4A5BBFC6)88d38000 88d40000   hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)88d40000 88d72000   fvevol   fvevol.sys   Mon Jul 13 19:13:01 2009 (4A5BBF7D)88d72000 88d83000   disk     disk.sys     Mon Jul 13 19:11:28 2009 (4A5BBF20)88d83000 88da8000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)88da8000 88dabf80   AVGIDSEH AVGIDSEH.Sys Tue Feb 22 00:22:33 2011 (4D634819)88dde000 88dfd000   cdrom    cdrom.sys    Mon Jul 13 19:11:24 2009 (4A5BBF1C)88e00000 88e06500   avgrkx86 avgrkx86.sys Wed Mar 16 10:05:26 2011 (4D80C3A6)88e07000 88f50000   tcpip    tcpip.sys    Mon Jul 13 19:13:18 2009 (4A5BBF8E)88f50000 88f81000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)88f81000 88f89380   vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)88f8a000 88fc9000   volsnap  volsnap.sys  Mon Jul 13 19:11:34 2009 (4A5BBF26)88fc9000 88fd1000   spldr    spldr.sys    Mon May 11 12:13:47 2009 (4A084EBB)88fd1000 88ffe000   rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)8ce33000 8ce4b000   raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)8ce4b000 8ce62000   raspptp  raspptp.sys  Mon Jul 13 19:54:47 2009 (4A5BC947)8ce62000 8ce79000   rassstp  rassstp.sys  Mon Jul 13 19:54:57 2009 (4A5BC951)8ce79000 8ce83000   rdpbus   rdpbus.sys   Mon Jul 13 20:02:40 2009 (4A5BCB20)8ce83000 8ce84380   swenum   swenum.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)8ce85000 8ceb9000   ks       ks.sys       Mon Jul 13 19:45:13 2009 (4A5BC709)8ceb9000 8cec7000   umbus    umbus.sys    Mon Jul 13 19:51:38 2009 (4A5BC88A)8cec7000 8cf0b000   usbhub   usbhub.sys   Mon Jul 13 19:52:06 2009 (4A5BC8A6)8cf0b000 8cf1c000   NDProxy  NDProxy.SYS  Mon Jul 13 19:54:27 2009 (4A5BC933)8cf1c000 8cfa1000   HTTP     HTTP.sys     Mon Jul 13 19:12:53 2009 (4A5BBF75)8cfa1000 8cfba000   bowser   bowser.sys   Mon Jul 13 19:14:21 2009 (4A5BBFCD)8cfba000 8cfdd000   mrxsmb   mrxsmb.sys   Mon Jul 13 19:14:24 2009 (4A5BBFD0)8dc10000 8dc21000   avgfwd6x avgfwd6x.sys Sun Jul 11 21:37:25 2010 (4C3A71D5)8dc21000 8dc38000   tdx      tdx.sys      Mon Jul 13 19:12:10 2009 (4A5BBF4A)8dc38000 8dc43000   TDI      TDI.SYS      Mon Jul 13 19:12:12 2009 (4A5BBF4C)8dc43000 8dc89e80   avgtdix  avgtdix.sys  Mon Apr 04 17:53:24 2011 (4D9A3DD4)8dc8a000 8dcbc000   netbt    netbt.sys    Mon Jul 13 19:12:18 2009 (4A5BBF52)8dcbc000 8dd16000   afd      afd.sys      Mon Jul 13 19:12:34 2009 (4A5BBF62)8dd16000 8dd1d000   wfplwf   wfplwf.sys   Mon Jul 13 19:53:51 2009 (4A5BC90F)8dd1d000 8dd3c000   pacer    pacer.sys    Mon Jul 13 19:53:58 2009 (4A5BC916)8dd3c000 8dd4a000   netbios  netbios.sys  Mon Jul 13 19:53:54 2009 (4A5BC912)8dd4a000 8dd64000   serial   serial.sys   Mon Jul 13 19:45:33 2009 (4A5BC71D)8dd64000 8dd77000   wanarp   wanarp.sys   Mon Jul 13 19:55:02 2009 (4A5BC956)8dd77000 8dd87000   termdd   termdd.sys   Mon Jul 13 20:01:35 2009 (4A5BCADF)8dd87000 8dd8eb00   SDHookDrv32 SDHookDrv32.sys Thu Jan 07 10:13:56 2010 (4B45FA34)8dd8f000 8ddd0000   rdbss    rdbss.sys    Mon Jul 13 19:14:26 2009 (4A5BBFD2)8ddd0000 8ddda000   nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)8ddda000 8dde4000   mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)8dde4000 8ddf0000   discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)8e40e000 8e472000   csc      csc.sys      Mon Jul 13 19:15:08 2009 (4A5BBFFC)8e472000 8e48a000   dfsc     dfsc.sys     Mon Jul 13 19:14:16 2009 (4A5BBFC8)8e48a000 8e498000   blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)8e498000 8e4d3100   avgldx86 avgldx86.sys Thu Jan 06 23:35:29 2011 (4D269811)8e4d4000 8e4f5000   tunnel   tunnel.sys   Mon Jul 13 19:54:03 2009 (4A5BC91B)8e4f5000 8e507000   intelppm intelppm.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)8e507000 8e543000   b57nd60x b57nd60x.sys Sun Apr 26 07:15:34 2009 (49F44256)8e543000 8e58e000   USBPORT  USBPORT.SYS  Mon Jul 13 19:51:13 2009 (4A5BC871)8e58e000 8e59b000   kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)8e59b000 8e5a8000   CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)8e5a8000 8e5ba000   AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)8e5ba000 8e5d2000   rasl2tp  rasl2tp.sys  Mon Jul 13 19:54:33 2009 (4A5BC939)8e5d2000 8e5f4000   ndiswan  ndiswan.sys  Mon Jul 13 19:54:34 2009 (4A5BC93A)8ee00000 8ee18000   parport  parport.sys  Mon Jul 13 19:45:34 2009 (4A5BC71E)8ee18000 8ee30000   i8042prt i8042prt.sys Mon Jul 13 19:11:23 2009 (4A5BBF1B)8ee30000 8ee3b000   ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)8ee3b000 8f8b8dc0   nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:14 2010 (4C379162)8f8b9000 8f8ba040   nvBridge nvBridge.kmd Fri Jul 09 17:10:11 2010 (4C379033)8f8bb000 8f972000   dxgkrnl  dxgkrnl.sys  Mon Jul 13 19:26:15 2009 (4A5BC297)8f972000 8f9ab000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:25:25 2009 (4A5BC265)8f9ab000 8f9ca000   HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)8f9ca000 8f9d5000   usbuhci  usbuhci.sys  Mon Jul 13 19:51:10 2009 (4A5BC86E)8f9d5000 8f9e4000   usbehci  usbehci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)8f9e4000 8f9ee000   serenum  serenum.sys  Mon Jul 13 19:45:27 2009 (4A5BC717)8f9ee000 8f9fb000   mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)8fc00000 8fc12000   mpsdrv   mpsdrv.sys   Mon Jul 13 19:52:52 2009 (4A5BC8D4)8fc13000 8ff0e2c0   RTKVHDA  RTKVHDA.sys  Tue Jul 06 06:02:40 2010 (4C32FF40)8ff0f000 8ff3e000   portcls  portcls.sys  Mon Jul 13 19:51:00 2009 (4A5BC864)8ff3e000 8ff57000   drmk     drmk.sys     Mon Jul 13 20:36:05 2009 (4A5BD2F5)8ff57000 8ff64000   crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)8ff64000 8ff6f000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)8ff6f000 8ff78000   dump_atapi dump_atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)8ff78000 8ff89000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)8ff89000 8ff93000   Dxapi    Dxapi.sys    Mon Jul 13 19:25:25 2009 (4A5BC265)8ff93000 8ff9e000   monitor  monitor.sys  Mon Jul 13 19:25:58 2009 (4A5BC286)8ff9e000 8ffb9000   luafv    luafv.sys    Mon Jul 13 19:15:44 2009 (4A5BC020)8ffb9000 8ffd3000   WudfPf   WudfPf.sys   Mon Jul 13 19:50:13 2009 (4A5BC835)8ffd3000 8ffe3000   lltdio   lltdio.sys   Mon Jul 13 19:53:18 2009 (4A5BC8EE)8ffe3000 8fff6000   rspndr   rspndr.sys   Mon Jul 13 19:53:20 2009 (4A5BC8F0)94a00000 94c4a000   win32k   win32k.sys   Mon Jul 13 19:26:26 2009 (4A5BC2A2)94c60000 94c69000   TSDDD    TSDDD.dll    Mon Jul 13 20:01:40 2009 (4A5BCAE4)94c90000 94cae000   cdd      cdd.dll      unavailable (00000000)94cb0000 94cfd000   ATMFD    ATMFD.DLL    Mon Jul 13 19:25:23 2009 (4A5BC263)98e2c000 98e67000   mrxsmb10 mrxsmb10.sys Mon Jul 13 19:14:34 2009 (4A5BBFDA)98e67000 98e82000   mrxsmb20 mrxsmb20.sys Mon Jul 13 19:14:29 2009 (4A5BBFD5)98e82000 98e89000   parvdm   parvdm.sys   Mon Jul 13 19:45:29 2009 (4A5BC719)98e89000 98e8cb80   AVGIDSShim AVGIDSShim.Sys Wed Feb 09 23:59:09 2011 (4D53709D)98e8d000 98e96000   cpuz135_x32 cpuz135_x32.sys Tue Nov 09 08:32:57 2010 (4CD94D89)98e96000 98f2d000   peauth   peauth.sys   Mon Jul 13 20:35:44 2009 (4A5BD2E0)98f2d000 98f37000   secdrv   secdrv.SYS   Wed Sep 13 09:18:32 2006 (45080528)98f37000 98f58000   srvnet   srvnet.sys   Mon Jul 13 19:14:45 2009 (4A5BBFE5)98f58000 98fc2000   spsys    spsys.sys    Mon May 11 12:37:10 2009 (4A085436)98fc2000 98fcf000   tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)98fcf000 98fd3400   AVGIDSFilter AVGIDSFilter.Sys Wed Feb 09 23:59:07 2011 (4D53709B)Unloaded modules:88dac000 88db9000   crashdmp.sys    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000D00088db9000 88dc4000   dump_ataport    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000B00088dc4000 88dcd000   dump_atapi.s    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000900088dcd000 88dde000   dump_dumpfve    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  00011000start    end        module name88831000 88879000   ACPI     ACPI.sys     Mon Jul 13 19:11:11 2009 (4A5BBF0F)8dcbc000 8dd16000   afd      afd.sys      Mon Jul 13 19:12:34 2009 (4A5BBF62)8e5a8000 8e5ba000   AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)88982000 8898b000   amdxata  amdxata.sys  Tue May 19 13:57:35 2009 (4A12F30F)88956000 8895f000   atapi    atapi.sys    Mon Jul 13 19:11:15 2009 (4A5BBF13)8895f000 88982000   ataport  ataport.SYS  Mon Jul 13 19:11:18 2009 (4A5BBF16)94cb0000 94cfd000   ATMFD    ATMFD.DLL    Mon Jul 13 19:25:23 2009 (4A5BC263)8dc10000 8dc21000   avgfwd6x avgfwd6x.sys Sun Jul 11 21:37:25 2010 (4C3A71D5)88da8000 88dabf80   AVGIDSEH AVGIDSEH.Sys Tue Feb 22 00:22:33 2011 (4D634819)98fcf000 98fd3400   AVGIDSFilter AVGIDSFilter.Sys Wed Feb 09 23:59:07 2011 (4D53709B)98e89000 98e8cb80   AVGIDSShim AVGIDSShim.Sys Wed Feb 09 23:59:09 2011 (4D53709D)8e498000 8e4d3100   avgldx86 avgldx86.sys Thu Jan 06 23:35:29 2011 (4D269811)88c00000 88c0c000   avgmfx86 avgmfx86.sys Tue Mar 01 07:23:55 2011 (4D6CE55B)88e00000 88e06500   avgrkx86 avgrkx86.sys Wed Mar 16 10:05:26 2011 (4D80C3A6)8dc43000 8dc89e80   avgtdix  avgtdix.sys  Mon Apr 04 17:53:24 2011 (4D9A3DD4)8e507000 8e543000   b57nd60x b57nd60x.sys Sun Apr 26 07:15:34 2009 (49F44256)88a10000 88a17000   Beep     Beep.SYS     Mon Jul 13 19:45:00 2009 (4A5BC6FC)8e48a000 8e498000   blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)8868a000 88692000   BOOTVID  BOOTVID.dll  Mon Jul 13 21:04:34 2009 (4A5BD9A2)8cfa1000 8cfba000   bowser   bowser.sys   Mon Jul 13 19:14:21 2009 (4A5BBFCD)94c90000 94cae000   cdd      cdd.dll      unavailable (00000000)88dde000 88dfd000   cdrom    cdrom.sys    Mon Jul 13 19:11:24 2009 (4A5BBF1C)886d4000 8877f000   CI       CI.dll       Mon Jul 13 21:09:28 2009 (4A5BDAC8)88d83000 88da8000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)88692000 886d4000   CLFS     CLFS.SYS     Mon Jul 13 19:11:10 2009 (4A5BBF0E)88b94000 88bf1000   cng      cng.sys      Mon Jul 13 19:32:55 2009 (4A5BC427)8e59b000 8e5a8000   CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)98e8d000 98e96000   cpuz135_x32 cpuz135_x32.sys Tue Nov 09 08:32:57 2010 (4CD94D89)8ff57000 8ff64000   crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)8e40e000 8e472000   csc      csc.sys      Mon Jul 13 19:15:08 2009 (4A5BBFFC)8e472000 8e48a000   dfsc     dfsc.sys     Mon Jul 13 19:14:16 2009 (4A5BBFC8)8dde4000 8ddf0000   discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)88d72000 88d83000   disk     disk.sys     Mon Jul 13 19:11:28 2009 (4A5BBF20)8ff3e000 8ff57000   drmk     drmk.sys     Mon Jul 13 20:36:05 2009 (4A5BD2F5)8ff6f000 8ff78000   dump_atapi dump_atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)8ff64000 8ff6f000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)8ff78000 8ff89000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)8ff89000 8ff93000   Dxapi    Dxapi.sys    Mon Jul 13 19:25:25 2009 (4A5BC265)8f8bb000 8f972000   dxgkrnl  dxgkrnl.sys  Mon Jul 13 19:26:15 2009 (4A5BC297)8f972000 8f9ab000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:25:25 2009 (4A5BC265)889bf000 889d0000   fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)8898b000 889bf000   fltmgr   fltmgr.sys   Mon Jul 13 19:11:13 2009 (4A5BBF11)88a00000 88a09000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:11:14 2009 (4A5BBF12)88d40000 88d72000   fvevol   fvevol.sys   Mon Jul 13 19:13:01 2009 (4A5BBF7D)88f50000 88f81000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)82e1a000 82e51000   hal      halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)8f9ab000 8f9ca000   HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)8cf1c000 8cfa1000   HTTP     HTTP.sys     Mon Jul 13 19:12:53 2009 (4A5BBF75)88d38000 88d40000   hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)8ee18000 8ee30000   i8042prt i8042prt.sys Mon Jul 13 19:11:23 2009 (4A5BBF1B)8892b000 88932000   intelide intelide.sys Mon Jul 13 19:11:19 2009 (4A5BBF17)8e4f5000 8e507000   intelppm intelppm.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)8e58e000 8e59b000   kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)80ba1000 80ba9000   kdcom    kdcom.dll    Mon Jul 13 21:08:58 2009 (4A5BDAAA)8ce85000 8ceb9000   ks       ks.sys       Mon Jul 13 19:45:13 2009 (4A5BC709)88b81000 88b94000   ksecdd   ksecdd.sys   Mon Jul 13 19:11:56 2009 (4A5BBF3C)88d03000 88d28000   ksecpkg  ksecpkg.sys  Mon Jul 13 19:34:00 2009 (4A5BC468)8ffd3000 8ffe3000   lltdio   lltdio.sys   Mon Jul 13 19:53:18 2009 (4A5BC8EE)8ff9e000 8ffb9000   luafv    luafv.sys    Mon Jul 13 19:15:44 2009 (4A5BC020)88601000 88679000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:06:41 2009 (4A5BDA21)8ff93000 8ff9e000   monitor  monitor.sys  Mon Jul 13 19:25:58 2009 (4A5BC286)8f9ee000 8f9fb000   mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)88940000 88956000   mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)8fc00000 8fc12000   mpsdrv   mpsdrv.sys   Mon Jul 13 19:52:52 2009 (4A5BC8D4)8cfba000 8cfdd000   mrxsmb   mrxsmb.sys   Mon Jul 13 19:14:24 2009 (4A5BBFD0)98e2c000 98e67000   mrxsmb10 mrxsmb10.sys Mon Jul 13 19:14:34 2009 (4A5BBFDA)98e67000 98e82000   mrxsmb20 mrxsmb20.sys Mon Jul 13 19:14:29 2009 (4A5BBFD5)88818000 88823000   Msfs     Msfs.SYS     Mon Jul 13 19:11:26 2009 (4A5BBF1E)88882000 8888a000   msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)88b56000 88b81000   msrpc    msrpc.sys    Mon Jul 13 19:11:59 2009 (4A5BBF3F)8ddda000 8dde4000   mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)88d28000 88d38000   mup      mup.sys      Mon Jul 13 19:14:14 2009 (4A5BBFC6)88c0e000 88cc5000   ndis     ndis.sys     Mon Jul 13 19:12:24 2009 (4A5BBF58)8ee30000 8ee3b000   ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)8e5d2000 8e5f4000   ndiswan  ndiswan.sys  Mon Jul 13 19:54:34 2009 (4A5BC93A)8cf0b000 8cf1c000   NDProxy  NDProxy.SYS  Mon Jul 13 19:54:27 2009 (4A5BC933)8dd3c000 8dd4a000   netbios  netbios.sys  Mon Jul 13 19:53:54 2009 (4A5BC912)8dc8a000 8dcbc000   netbt    netbt.sys    Mon Jul 13 19:12:18 2009 (4A5BBF52)88cc5000 88d03000   NETIO    NETIO.SYS    Mon Jul 13 19:12:35 2009 (4A5BBF63)88823000 88831000   Npfs     Npfs.SYS     Mon Jul 13 19:11:31 2009 (4A5BBF23)8ddd0000 8ddda000   nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)82a0a000 82e1a000   nt       ntkrpamp.exe Mon Jul 13 19:15:19 2009 (4A5BC007)88a27000 88b56000   Ntfs     Ntfs.sys     Mon Jul 13 19:12:05 2009 (4A5BBF45)88a09000 88a10000   Null     Null.SYS     Mon Jul 13 19:11:12 2009 (4A5BBF10)8f8b9000 8f8ba040   nvBridge nvBridge.kmd Fri Jul 09 17:10:11 2010 (4C379033)8ee3b000 8f8b8dc0   nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:14 2010 (4C379162)8dd1d000 8dd3c000   pacer    pacer.sys    Mon Jul 13 19:53:58 2009 (4A5BC916)8ee00000 8ee18000   parport  parport.sys  Mon Jul 13 19:45:34 2009 (4A5BC71E)888bf000 888d0000   partmgr  partmgr.sys  Mon Jul 13 19:11:35 2009 (4A5BBF27)98e82000 98e89000   parvdm   parvdm.sys   Mon Jul 13 19:45:29 2009 (4A5BC719)8888a000 888b4000   pci      pci.sys      Mon Jul 13 19:11:16 2009 (4A5BBF14)88932000 88940000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:11:15 2009 (4A5BBF13)88bf1000 88bff000   pcw      pcw.sys      Mon Jul 13 19:11:10 2009 (4A5BBF0E)98e96000 98f2d000   peauth   peauth.sys   Mon Jul 13 20:35:44 2009 (4A5BD2E0)8ff0f000 8ff3e000   portcls  portcls.sys  Mon Jul 13 19:51:00 2009 (4A5BC864)88679000 8868a000   PSHED    PSHED.dll    Mon Jul 13 21:09:36 2009 (4A5BDAD0)8e5ba000 8e5d2000   rasl2tp  rasl2tp.sys  Mon Jul 13 19:54:33 2009 (4A5BC939)8ce33000 8ce4b000   raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)8ce4b000 8ce62000   raspptp  raspptp.sys  Mon Jul 13 19:54:47 2009 (4A5BC947)8ce62000 8ce79000   rassstp  rassstp.sys  Mon Jul 13 19:54:57 2009 (4A5BC951)8dd8f000 8ddd0000   rdbss    rdbss.sys    Mon Jul 13 19:14:26 2009 (4A5BBFD2)8ce79000 8ce83000   rdpbus   rdpbus.sys   Mon Jul 13 20:02:40 2009 (4A5BCB20)88800000 88808000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:01:40 2009 (4A5BCAE4)88808000 88810000   rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)88810000 88818000   rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)88fd1000 88ffe000   rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)8ffe3000 8fff6000   rspndr   rspndr.sys   Mon Jul 13 19:53:20 2009 (4A5BC8F0)8fc13000 8ff0e2c0   RTKVHDA  RTKVHDA.sys  Tue Jul 06 06:02:40 2010 (4C32FF40)8dd87000 8dd8eb00   SDHookDrv32 SDHookDrv32.sys Thu Jan 07 10:13:56 2010 (4B45FA34)98f2d000 98f37000   secdrv   secdrv.SYS   Wed Sep 13 09:18:32 2006 (45080528)8f9e4000 8f9ee000   serenum  serenum.sys  Mon Jul 13 19:45:27 2009 (4A5BC717)8dd4a000 8dd64000   serial   serial.sys   Mon Jul 13 19:45:33 2009 (4A5BC71D)88fc9000 88fd1000   spldr    spldr.sys    Mon May 11 12:13:47 2009 (4A084EBB)98f58000 98fc2000   spsys    spsys.sys    Mon May 11 12:37:10 2009 (4A085436)98f37000 98f58000   srvnet   srvnet.sys   Mon Jul 13 19:14:45 2009 (4A5BBFE5)8ce83000 8ce84380   swenum   swenum.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)88e07000 88f50000   tcpip    tcpip.sys    Mon Jul 13 19:13:18 2009 (4A5BBF8E)98fc2000 98fcf000   tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)8dc38000 8dc43000   TDI      TDI.SYS      Mon Jul 13 19:12:12 2009 (4A5BBF4C)8dc21000 8dc38000   tdx      tdx.sys      Mon Jul 13 19:12:10 2009 (4A5BBF4A)8dd77000 8dd87000   termdd   termdd.sys   Mon Jul 13 20:01:35 2009 (4A5BCADF)94c60000 94c69000   TSDDD    TSDDD.dll    Mon Jul 13 20:01:40 2009 (4A5BCAE4)8e4d4000 8e4f5000   tunnel   tunnel.sys   Mon Jul 13 19:54:03 2009 (4A5BC91B)8ceb9000 8cec7000   umbus    umbus.sys    Mon Jul 13 19:51:38 2009 (4A5BC88A)8f9d5000 8f9e4000   usbehci  usbehci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)8cec7000 8cf0b000   usbhub   usbhub.sys   Mon Jul 13 19:52:06 2009 (4A5BC8A6)8e543000 8e58e000   USBPORT  USBPORT.SYS  Mon Jul 13 19:51:13 2009 (4A5BC871)8f9ca000 8f9d5000   usbuhci  usbuhci.sys  Mon Jul 13 19:51:10 2009 (4A5BC86E)888b4000 888bf000   vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)88a17000 88a23000   vga      vga.sys      Mon Jul 13 19:25:50 2009 (4A5BC27E)889d0000 889f1000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)88f81000 88f89380   vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)888d0000 888e0000   volmgr   volmgr.sys   Mon Jul 13 19:11:25 2009 (4A5BBF1D)888e0000 8892b000   volmgrx  volmgrx.sys  Mon Jul 13 19:11:41 2009 (4A5BBF2D)88f8a000 88fc9000   volsnap  volsnap.sys  Mon Jul 13 19:11:34 2009 (4A5BBF26)8dd64000 8dd77000   wanarp   wanarp.sys   Mon Jul 13 19:55:02 2009 (4A5BC956)889f1000 889fe000   watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)8877f000 887f0000   Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)887f0000 887fe000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:11:25 2009 (4A5BBF1D)8dd16000 8dd1d000   wfplwf   wfplwf.sys   Mon Jul 13 19:53:51 2009 (4A5BC90F)94a00000 94c4a000   win32k   win32k.sys   Mon Jul 13 19:26:26 2009 (4A5BC2A2)88879000 88882000   WMILIB   WMILIB.SYS   Mon Jul 13 19:11:22 2009 (4A5BBF1A)8ffb9000 8ffd3000   WudfPf   WudfPf.sys   Mon Jul 13 19:50:13 2009 (4A5BC835)Unloaded modules:88dac000 88db9000   crashdmp.sys    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000D00088db9000 88dc4000   dump_ataport    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000B00088dc4000 88dcd000   dump_atapi.s    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  0000900088dcd000 88dde000   dump_dumpfve    Timestamp: unavailable (00000000)    Checksum:  00000000    ImageSize:  00011000Bugcheck code 000000C5Arguments 00000404 00000002 00000000 82b2a87bPEB at 7ffd8000error 1 InitTypeRead( nt!_PEB at 7ffd8000)...[CPU Information]~MHz = REG_DWORD 3014Component Information = REG_BINARY 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0Configuration Data = REG_FULL_RESOURCE_DESCRIPTOR ff,ff,ff,ff,ff,ff,ff,ff,0,0,0,0,0,0,0,0Identifier = REG_SZ x86 Family 15 Model 6 Stepping 2ProcessorNameString = REG_SZ Intel(R) Pentium(R) D CPU 3.00GHzUpdate Signature = REG_BINARY 0,0,0,0,f,0,0,0Update Status = REG_DWORD 6VendorIdentifier = REG_SZ GenuineIntelMSR8B = REG_QWORD f00000000Machine ID Information [From Smbios 2.3, DMIVersion 35, Size=1169]BiosVendor = Award Software International, Inc.BiosVersion = F8BiosReleaseDate = 08/31/2006SystemManufacturer =  SystemProductName =  SystemVersion =  BaseBoardManufacturer = Gigabyte Technology Co., Ltd.BaseBoardProduct = 8I945PL-GBaseBoardVersion =  CPUID:        "Intel(R) Pentium(R) D CPU 3.00GHz"MaxSpeed:     3000CurrentSpeed: 3014[SMBIOS Data Tables v2.3][DMI Version - 35][2.0 Calling Convention - No][Table Size - 1169 bytes][BIOS Information (Type 0) - Length 20 - Handle 0000h]  Vendor                        Award Software International, Inc.  BIOS Version                  F8  BIOS Starting Address Segment e000  BIOS Release Date             08/31/2006  BIOS ROM Size                 80000  BIOS Characteristics       07: - PCI Supported       09: - Plug and Play Supported       10: - APM Supported       11: - Upgradeable FLASH BIOS       12: - BIOS Shadowing Supported       15: - CD-Boot Supported       16: - Selectable Boot Supported       19: - EDD Supported       22: - 360KB Floppy Supported       23: - 1.2MB Floppy Supported       24: - 720KB Floppy Supported       25: - 2.88MB Floppy Supported       26: - Print Screen Device Supported       27: - Keyboard Services Supported       28: - Serial Services Supported       29: - Printer Services Supported       30: - CGA/Mono Services Supported  BIOS Characteristic Extensions       00: - ACPI Supported       01: - USB Legacy Supported       04: - LS120-Boot Supported       05: - ATAPI ZIP-Boot Supported       08: - BIOS Boot Specification Supported[System Information (Type 1) - Length 25 - Handle 0001h]  Manufacturer                     Product Name                     Version                          Serial Number                    UUID                          00000000-0000-0000-0000-000000000000  Wakeup Type                   Power Switch[BaseBoard Information (Type 2) - Length 8 - Handle 0002h]  Manufacturer                  Gigabyte Technology Co., Ltd.  Product                       8I945PL-G  Version                          Serial Number                  [System Enclosure (Type 3) - Length 17 - Handle 0003h]  Manufacturer                     Chassis Type                  Desktop  Version                          Serial Number                    Asset Tag Number                 Bootup State                  Unknown  Power Supply State            Unknown  Thermal State                 Unknown  Security Status               Unknown  OEM Defined                   0[Processor Information (Type 4) - Length 35 - Handle 0004h]  Socket Designation            Socket 775  Processor Type                Central Processor  Processor Family              b2h - Pentium IV Processor  Processor Manufacturer        Intel  Processor ID                  620f0000fffbebbf  Processor Version             Intel(R) Pentium(R) D CPU  Processor Voltage             8dh - 1.3V  External Clock                200MHz  Max Speed                     4000MHz  Current Speed                 3000MHz  Status                        Enabled Populated  Processor Upgrade             Socket 478  L1 Cache Handle               000ah  L2 Cache Handle               000bh  L3 Cache Handle               [Not Present]  Serial Number                    Asset Tag Number                 Part Number                    [Memory Controller Information (Type 5) - Length 24 - Handle 0005h]  Error Detecting Method        04h - 8-bit Parity  Error Correcting Capability   04h - None   Supported Interleave          03h - One Way Interleave  Current Interleave            03h - One Way Interleave  Maximum Memory Module Size    0ah - 1024MB  Supported Speeds              0001h - Other   Supported Memory Types        0001h - Other   Memory Module Voltage         5V   Number of Memory Slots        4  Memory Slot Handle            0006h  Memory Slot Handle            0007h  Memory Slot Handle            0008h  Memory Slot Handle            0009h  Enabled Err Correcting Caps   04h - None [Memory Module Information (Type 6) - Length 12 - Handle 0006h]  Socket Designation            A0  Bank Connections              1fh - 1  Current Speed                 31ns  Current Memory Type           0002h - Unknown   Installed Size                7fh - [Not Installed] [single bank]  Enabled Size                  7fh - [Not Installed] [single bank]  Error Status                  00h - [No Errors] [Memory Module Information (Type 6) - Length 12 - Handle 0007h]  Socket Designation            A1  Bank Connections              2fh - 2  Current Speed                 47ns  Current Memory Type           0002h - Unknown   Installed Size                7fh - [Not Installed] [single bank]  Enabled Size                  7fh - [Not Installed] [single bank]  Error Status                  00h - [No Errors] [Memory Module Information (Type 6) - Length 12 - Handle 0008h]  Socket Designation            A2  Bank Connections              3fh - 3  Current Speed                 63ns  Current Memory Type           0500h - DIMM SDRAM   Installed Size                8ah - 1024 [double bank]  Enabled Size                  8ah - 1024 [double bank]  Error Status                  00h - [No Errors] [Memory Module Information (Type 6) - Length 12 - Handle 0009h]  Socket Designation            A3  Bank Connections              4fh - 4  Current Speed                 79ns  Current Memory Type           0002h - Unknown   Installed Size                7fh - [Not Installed] [single bank]  Enabled Size                  7fh - [Not Installed] [single bank]  Error Status                  00h - [No Errors] [Cache Information (Type 7) - Length 19 - Handle 000ah]  Socket Designation            Internal Cache  Cache Configuration           0180h - WB Enabled Int NonSocketed L1  Maximum Cache Size            0010h - 16K  Installed Size                0010h - 16K  Supported SRAM Type           0020h - Synchronous   Current SRAM Type             0020h - Synchronous   Cache Speed                   0ns  Error Correction Type         Unknown  System Cache Type             Unknown  Associativity                 Unknown[Cache Information (Type 7) - Length 19 - Handle 000bh]  Socket Designation            External Cache  Cache Configuration           0181h - WB Enabled Int NonSocketed L2  Maximum Cache Size            0400h - 1024K  Installed Size                0800h - 2048K  Supported SRAM Type           0020h - Synchronous   Current SRAM Type             0020h - Synchronous   Cache Speed                   0ns  Error Correction Type         Unknown  System Cache Type             Unknown  Associativity                 Unknown[Physical Memory Array (Type 16) - Length 15 - Handle 001bh]  Location                      03h - SystemBoard/Motherboard  Use                           03h - System Memory  Memory Error Correction       03h - None  Maximum Capacity              4194304KB  Memory Error Inf Handle       [Not Provided]  Number of Memory Devices      4[Memory Device (Type 17) - Length 27 - Handle 001ch]  Physical Memory Array Handle  001bh  Memory Error Info Handle      [Not Provided]  Total Width                   [Unknown]  Data Width                    [Unknown]  Size                          [Not Populated]  Form Factor                   09h - DIMM  Device Set                    [None]  Device Locator                A0  Bank Locator                  Bank0/1  Memory Type                   02h - Unknown  Type Detail                   0000h -  Speed                         0MHz  Manufacturer                  None  Serial Number                       Asset Tag Number                    Part Number                   None[Memory Device (Type 17) - Length 27 - Handle 001dh]  Physical Memory Array Handle  001bh  Memory Error Info Handle      [Not Provided]  Total Width                   [Unknown]  Data Width                    [Unknown]  Size                          [Not Populated]  Form Factor                   09h - DIMM  Device Set                    [None]  Device Locator                A1  Bank Locator                  Bank2/3  Memory Type                   02h - Unknown  Type Detail                   0000h -  Speed                         0MHz  Manufacturer                  None  Serial Number                       Asset Tag Number                    Part Number                   None[Memory Device (Type 17) - Length 27 - Handle 001eh]  Physical Memory Array Handle  001bh  Memory Error Info Handle      [Not Provided]  Total Width                   64 bits  Data Width                    64 bits  Size                          1024MB  Form Factor                   09h - DIMM  Device Set                    [None]  Device Locator                A2  Bank Locator                  Bank4/5  Memory Type                   02h - Unknown  Type Detail                   0000h -  Speed                         66MHz  Manufacturer                  None  Serial Number                       Asset Tag Number                    Part Number                   None[Memory Device (Type 17) - Length 27 - Handle 001fh]  Physical Memory Array Handle  001bh  Memory Error Info Handle      [Not Provided]  Total Width                   [Unknown]  Data Width                    [Unknown]  Size                          [Not Populated]  Form Factor                   09h - DIMM  Device Set                    [None]  Device Locator                A3  Bank Locator                  Bank6/7  Memory Type                   02h - Unknown  Type Detail                   0000h -  Speed                         0MHz  Manufacturer                  None  Serial Number                       Asset Tag Number                    Part Number                   None[Memory Array Mapped Address (Type 19) - Length 15 - Handle 0020h]  Starting Address              00000000h  Ending Address                000fffffh  Memory Array Handle           001bh  Partition Width               01[Memory Device Mapped Address (Type 20) - Length 19 - Handle 0021h]  Starting Address              00000000h  Ending Address                00000000h  Memory Device Handle          001ch  Mem Array Mapped Adr Handle   0020h  Partition Row Position        01  Interleave Position           [None]  Interleave Data Depth         [None][Memory Device Mapped Address (Type 20) - Length 19 - Handle 0022h]  Starting Address              00000000h  Ending Address                00000000h  Memory Device Handle          001dh  Mem Array Mapped Adr Handle   0020h  Partition Row Position        01  Interleave Position           [None]  Interleave Data Depth         [None][Memory Device Mapped Address (Type 20) - Length 19 - Handle 0023h]  Starting Address              00000000h  Ending Address                000fffffh  Memory Device Handle          001eh  Mem Array Mapped Adr Handle   0020h  Partition Row Position        01  Interleave Position           [None]  Interleave Data Depth         [None][Memory Device Mapped Address (Type 20) - Length 19 - Handle 0024h]  Starting Address              00000000h  Ending Address                00000000h  Memory Device Handle          001fh  Mem Array Mapped Adr Handle   0020h  Partition Row Position        01  Interleave Position           [None]  Interleave Data Depth         [None][codebox]Opened log file 'C:\Users\PalmDesert\_jcgriff2_\dbug\__Kernel__\_99-dbug.txt'Opened log file 'C:\Users\PalmDesert\_jcgriff2_\dbug\__Kernel__\_99-dbug.txt'Opened log file 'C:\Users\PalmDesert\_jcgriff2_\dbug\__Kernel__\_99-dbug.txt'

Microsoft MVP 2009-2015

#10 hamluis

hamluis

    Moderator


  • Moderator
  • 55,378 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:11:07 AM

Posted 09 February 2012 - 03:58 PM

FWIW: 32-bit Drivers

Louis

You only have 1 RAM module installed, board supports dual-channel, no dual-channel possible with one module.

Edited by hamluis, 09 February 2012 - 04:10 PM.


#11 jcgriff2

jcgriff2

  • BSOD Kernel Dump Expert
  • 1,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey Shore
  • Local time:12:07 PM

Posted 09 February 2012 - 04:44 PM

I missed the RAM .... nice catch hamluis !
Microsoft MVP 2009-2015

#12 ermat_46

ermat_46
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 10 February 2012 - 05:03 PM

I tried Driver Verifier. Didn't last a second before a BSOD came in. I can't boot into normal mode now.

==================================================
Dump File : 021112-15015-01.dmp
Crash Time : 2/11/2012 6:00:40 AM
Bug Check String : DRIVER_VERIFIER_DETECTED_VIOLATION
Bug Check Code : 0x000000c4
Parameter 1 : 0x000000f6
Parameter 2 : 0x00000280
Parameter 3 : 0x9258e030
Parameter 4 : 0x8a54f61c
Caused By Driver : SDHookDrv32.sys
Caused By Address : SDHookDrv32.sys+661c
File Description :
Product Name :
Company :
File Version :
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcd10
Stack Address 1 : ntkrnlpa.exe+334f03
Stack Address 2 : ntkrnlpa.exe+339766
Stack Address 3 : ntkrnlpa.exe+22426c
Computer Name :
Full Path : C:\Windows\Minidump\021112-15015-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 150,248
==================================================

==================================================
Dump File : 021112-17656-01.dmp
Crash Time : 2/11/2012 5:59:20 AM
Bug Check String : DRIVER_VERIFIER_DETECTED_VIOLATION
Bug Check Code : 0x000000c4
Parameter 1 : 0x000000f6
Parameter 2 : 0x000002e0
Parameter 3 : 0x92591530
Parameter 4 : 0x8bd5161c
Caused By Driver : SDHookDrv32.sys
Caused By Address : SDHookDrv32.sys+661c
File Description :
Product Name :
Company :
File Version :
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcd10
Stack Address 1 : ntkrnlpa.exe+334f03
Stack Address 2 : ntkrnlpa.exe+339766
Stack Address 3 : ntkrnlpa.exe+22426c
Computer Name :
Full Path : C:\Windows\Minidump\021112-17656-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 150,248
==================================================

#13 James Litten

James Litten

    ¿Ԁǝǝ˥q


  • BC Advisor
  • 1,945 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey
  • Local time:11:07 AM

Posted 10 February 2012 - 08:13 PM

Hi

Do you have Spybot Search and Destroy installed on that computer? I believe that's what the driver SDHookDrv32.sys is for.

James

#14 jcgriff2

jcgriff2

  • BSOD Kernel Dump Expert
  • 1,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New Jersey Shore
  • Local time:12:07 PM

Posted 10 February 2012 - 11:20 PM

Driver Verifier flagged the Spybot driver.

Boot into Recovery using the HDD recovery partition or Windows DVD and run "Windows System Restore".

Remove Spybot.
Microsoft MVP 2009-2015

#15 ermat_46

ermat_46
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 11 February 2012 - 03:24 PM

Driver Verifier flagged the Spybot driver.

Boot into Recovery using the HDD recovery partition or Windows DVD and run "Windows System Restore".

Remove Spybot.


I removed Spybot using the uninstaller in Control Panel. Is it okay? Do I still have to use System Restore? Thanks.




2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users