Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

BSOD ntoskrnl.exe and igdkmd64.sys


  • Please log in to reply
9 replies to this topic

#1 sadj2885

sadj2885

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:06:43 AM

Posted 16 September 2014 - 09:44 AM

Every few days one machine get this error. Its a Toshiba Prtege R830 with Windows 7 64 bit. The issue started once I upgraded the laptop with an SSD and new memory and a fresh OS install. It seems to the graphics drivers, but i have installed more versions than i can count and the issue persists. Event viewer shows error code 0x0000007f when it crashes.

 

I have run memory scans and have done an sfc scan and neither returned any errors. Im at a loss as to what else i can do.

 

Dump file is attached.

 

Thanks for your help.



BC AdBot (Login to Remove)

 


m

#2 hamluis

hamluis

    Moderator


  • Moderator
  • 54,830 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:04:43 AM

Posted 16 September 2014 - 11:35 AM

Please download MiniToolBox  , save it to your desktop and run it. 

Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory

Click Go and paste the content into your next post.

Also...please Publish a Snapshot using Speccy - http://www.bleepingcomputer.com/forums/topic323892.html/page__p__1797792#entry1797792 , taking care to post the link of the snapshot in your next post.

Louis



#3 sadj2885

sadj2885
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:06:43 AM

Posted 16 September 2014 - 01:57 PM

Here are the results:

 

MiniToolBox by Farbar  Version: 21-07-2014
Ran by nseitelman (administrator) on 16-09-2014 at 14:45:45
Running from "C:\Tools"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (09/16/2014 10:54:04 AM) (Source: Symantec AntiVirus) (User: )
Description: Symantec Endpoint Protection has failed to load the latest virus definitions.

Error: (09/16/2014 10:53:15 AM) (Source: Symantec AntiVirus) (User: )
Description: Symantec Endpoint Protection has failed to load the latest virus definitions.

Error: (09/16/2014 10:51:04 AM) (Source: Symantec AntiVirus) (User: )
Description: Symantec Endpoint Protection has determined that the virus definitions are missing on this computer. This computer will remain unprotected from viruses until virus definitions are downloaded to this computer.Application has encountered an error.
For more information, please go to: http://www.symantec.com/techsupp/servlet/ProductMessages?product=SAVCORP&version=12.1.2015.2015&language=english&module=1000&error=0009&build=symantec_ent

Error: (09/16/2014 10:48:32 AM) (Source: Symantec AntiVirus) (User: )
Description: Symantec Endpoint Protection has determined that the virus definitions are missing on this computer. This computer will remain unprotected from viruses until virus definitions are downloaded to this computer.Application has encountered an error.
For more information, please go to: http://www.symantec.com/techsupp/servlet/ProductMessages?product=SAVCORP&version=12.1.2015.2015&language=english&module=1000&error=0009&build=symantec_ent

Error: (09/16/2014 10:48:27 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/16/2014 10:37:31 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000CC9E440.72).  hr = 0x8007001f, A device attached to the system is not functioning.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:31 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000CC9E440.72).  hr = 0x8007001f, A device attached to the system is not functioning.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:28 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000964,(null),0,REG_BINARY,00000000010BCEF0.72).  hr = 0x8007001f, A device attached to the system is not functioning.
.


Operation:
   Gather writers' status

Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:28 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000964,(null),0,REG_BINARY,00000000010BCEF0.72).  hr = 0x8007001f, A device attached to the system is not functioning.
.


Operation:
   Gather writers' status

Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:11 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000328D1C0.72).  hr = 0x8007001f, A device attached to the system is not functioning.
.


Operation:
   PostSnapshot Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}


System errors:
=============
Error: (09/16/2014 10:49:29 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (09/16/2014 10:48:26 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SRTSP

Error: (09/16/2014 10:48:13 AM) (Source: SRTSP) (User: )
Description: Error loading virus definitions.

Error: (09/16/2014 10:29:55 AM) (Source: DCOM) (User: )
Description: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (09/16/2014 10:27:16 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (09/16/2014 10:19:08 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (09/16/2014 10:18:02 AM) (Source: Microsoft-Windows-GroupPolicy) (User: GBC2003)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.

Error: (09/16/2014 10:17:42 AM) (Source: Microsoft-Windows-GroupPolicy) (User: NT AUTHORITY)
Description: The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following:
a) Name Resolution failure on the current domain controller.
B) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Error: (09/16/2014 10:17:41 AM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain GBC2003 due to the following:
%%1311

This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.



ADDITIONAL INFO

If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.

Error: (09/16/2014 10:12:44 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)


Microsoft Office Sessions:
=========================
Error: (09/16/2014 10:54:04 AM) (Source: Symantec AntiVirus)(User: )
Description: Symantec Endpoint Protection has failed to load the latest virus definitions.

Error: (09/16/2014 10:53:15 AM) (Source: Symantec AntiVirus)(User: )
Description: Symantec Endpoint Protection has failed to load the latest virus definitions.

Error: (09/16/2014 10:51:04 AM) (Source: Symantec AntiVirus)(User: )
Description: Symantec Endpoint Protection has determined that the virus definitions are missing on this computer. This computer will remain unprotected from viruses until virus definitions are downloaded to this computer.Application has encountered an error.
For more information, please go to: http://www.symantec.com/techsupp/servlet/ProductMessages?product=SAVCORP&version=12.1.2015.2015&language=english&module=1000&error=0009&build=symantec_ent

Error: (09/16/2014 10:48:32 AM) (Source: Symantec AntiVirus)(User: )
Description: Symantec Endpoint Protection has determined that the virus definitions are missing on this computer. This computer will remain unprotected from viruses until virus definitions are downloaded to this computer.Application has encountered an error.
For more information, please go to: http://www.symantec.com/techsupp/servlet/ProductMessages?product=SAVCORP&version=12.1.2015.2015&language=english&module=1000&error=0009&build=symantec_ent

Error: (09/16/2014 10:48:27 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/16/2014 10:37:31 AM) (Source: VSS)(User: )
Description: RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000CC9E440.72)0x8007001f, A device attached to the system is not functioning.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:31 AM) (Source: VSS)(User: )
Description: RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000CC9E440.72)0x8007001f, A device attached to the system is not functioning.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:28 AM) (Source: VSS)(User: )
Description: RegSetValueExW(0x00000964,(null),0,REG_BINARY,00000000010BCEF0.72)0x8007001f, A device attached to the system is not functioning.


Operation:
   Gather writers' status

Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:28 AM) (Source: VSS)(User: )
Description: RegSetValueExW(0x00000964,(null),0,REG_BINARY,00000000010BCEF0.72)0x8007001f, A device attached to the system is not functioning.


Operation:
   Gather writers' status

Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}

Error: (09/16/2014 10:37:11 AM) (Source: VSS)(User: )
Description: RegSetValueExW(0x00000964,(null),0,REG_BINARY,000000000328D1C0.72)0x8007001f, A device attached to the system is not functioning.


Operation:
   PostSnapshot Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {b1092543-add4-4294-b6aa-817411360ee0}


CodeIntegrity Errors:
===================================
  Date: 2014-07-25 08:32:24.152
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-07-25 08:32:24.152
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-07-25 08:30:30.137
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-07-25 08:30:30.121
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-07-25 08:28:47.742
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-07-25 08:28:47.742
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.



=========================== Installed Programs ============================
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v9.10.00(T) - TOSHIBA CORPORATION)
Box Sync (HKLM\...\{7A68193F-E9C4-4F5E-80E7-0A9250D4A336}) (Version: 4.0.5253.0 - Box, Inc.)
Box Sync (x32 Version: 4.0.5116.0 - Box Inc.) Hidden
Check Point VPN (HKLM-x32\...\{CFB52646-DD86-4575-9932-FD8168F254FF}) (Version: 83.50.7083 - Check Point Software Technologies Ltd.)
Citrix Online Launcher (HKLM-x32\...\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
CutePDF Professional 3.6 (HKLM-x32\...\{F10D1D8F-C20C-4F0D-B243-688C0C6873F6}) (Version: 3.6.2.0 - Acro Software Inc.)
CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version:  - )
Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GoToMeeting 6.3.0.1468 (HKCU\...\GoToMeeting) (Version: 6.3.0.1468 - CitrixOnline)
GoToMeeting 6.3.1468 IT Installer (x32 Version: 6.3.1468 - Citrix) Hidden
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: 17.3 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle)
Lotus Notes 8.5.2 (HKLM-x32\...\{E11DFB27-BAF4-46D6-AD76-D5519C0E6786}) (Version: 8.52.10222 - IBM)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Business 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{751EE164-9F12-4E57-ADB0-02D8F34A10AD}) (Version: 9.00.1399.06 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PaperVision Document Viewer Controls (HKLM-x32\...\{491C1345-A353-4A71-A824-16991C7B2CC8}) (Version: 74.5.0.16 - Digitech Systems, Inc.)
QAD Enterprise Applications 2011 SE ( C:\Program Files (x86)\QAD\QAD Enterprise Applications 2011 SE ) (HKLM-x32\...\{F99BCE05-345D-42EF-8B1E-A5A72E049794}) (Version: 2.9.4.41 - QAD)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6293 - Realtek Semiconductor Corp.)
RtkClassFilter (HKLM-x32\...\InstallShield_{8220FCF2-A57F-4236-BFCC-C6C2268E851E}) (Version: 1.2.1.4 - REALTEK Semiconductor Corp)
RtkClassFilter (x32 Version: 1.2.1.4 - REALTEK Semiconductor Corp) Hidden
SalesLogix Network Client (HKLM-x32\...\{893F65B1-C697-4149-A766-B3D80D9B2A49}) (Version: 7.54.7048 - SalesLogix, Sage Software, Inc.)
SnagIt 8 (HKLM-x32\...\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}) (Version: 8.2.3 - TechSmith Corporation)
Symantec Endpoint Protection (HKLM\...\{C2103AF2-E66C-446B-9791-9207840EC821}) (Version: 12.1.2015.2015 - Symantec Corporation)
Synergis Adept 2014 Client Service Pack 1 (HKLM-x32\...\{83C3C050-682B-4460-881C-5F1E677EBC1E}) (Version: 8.8.1.49 - Synergis Software)
Synergis Adept 2014 Desktop Deployment Viewer (HKLM-x32\...\{F22F7E52-2DE4-466F-8BB4-4B28FE3BFAE3}) (Version: 20.2.2001 - Synergis Software)
Synergis Adept 2014 x64 Integration Pack (HKLM\...\{DE0296EA-646D-404C-898A-38F344C9F4DA}) (Version: 8.8.305 - Synergis Software)
System Requirements Lab for Intel (HKLM-x32\...\{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}) (Version: 4.5.24.0 - Husdawg, LLC)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TightVNC (HKLM\...\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}) (Version: 2.7.10.0 - GlavSoft LLC.)
Windows Driver Package - Realtek Semiconductor Corp. RtkBtFilter Bluetooth  (12/02/2011 2.3.8.1) (HKLM\...\EA90D42054890B3938D0BEF1E8A316D20C6D6003) (Version: 12/02/2011 2.3.8.1 - Realtek Semiconductor Corp.)
WinRAR 4.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)

========================= Memory info: ===================================

Percentage of memory in use: 43%
Total physical RAM: 8095.43 MB
Available physical RAM: 4599.41 MB
Total Pagefile: 16189.03 MB
Available Pagefile: 12483.95 MB
Total Virtual: 4095.88 MB
Available Virtual: 3969.24 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:223.47 GB) (Free:168.16 GB) NTFS
3 Drive g: () (Network) (Total:479.99 GB) (Free:9.4 GB)
4 Drive h: () (Network) (Total:479.99 GB) (Free:9.4 GB)

========================= Users: ========================================

User accounts for \\NSEITELMAN-7

Administrator            gbcuser                  Guest                    


**** End of log ****

 

Speccy snaptop:   http://speccy.piriform.com/results/jkAqm76fD7X0sCwZ5iIUKiy
 

 

Thanks.



#4 sflatechguy

sflatechguy

  • BC Advisor
  • 2,164 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:43 AM

Posted 16 September 2014 - 03:13 PM

I see a number of issues here.

 

The 0x7f bugcheck code occurs when faulty or mismatched hardware is installed, or when a fault occurs while trying to process another fault. Check the first parameter in that bugcheck code to see what could be causing that. http://msdn.microsoft.com/en-us/library/windows/hardware/ff559244%28v=vs.85%29.aspx

 

Your Symantec isn't even loading at startup, because the SRTSP driver isn't loading. You may want to uninstall and reinstall that.

 

Your Windows backup service isn't running, because the Windows Backup, Volume Shadow Copy, Remote Procedure Call, and Block Level Backup Engine Service services are all stopped. Make sure those are running and set to Automatic.

 

I see the computer is connected to a domain. The DHCP and DNS client services are running on the computer, so there are problems in your local DNS resolving where the domain controller is, and that's why the group policy failed to process. Check to make sure the DNS and default gateway settings are correct.



#5 sadj2885

sadj2885
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:06:43 AM

Posted 16 September 2014 - 05:26 PM

Thanks for your response.

 

Im guessing i will have to learn to use the debugger to diagnose the issue with the 0x7f code.

 

I will reinstall symantec. Backups are disabled on all domain computers in the office, but i dont think this would cause the blue screen. DNS issues will be corrected over the coming year once our servers are updated to Server 2012, they are still on 03, but again this shouldnt cause a blue screen.



#6 sflatechguy

sflatechguy

  • BC Advisor
  • 2,164 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:43 AM

Posted 16 September 2014 - 06:17 PM

That is correct. Those other issues won't cause blue screens. I was pointing them out, but you are clearly on top of them. :)

 

If you don't have Debugging Tools for Windows installed, install it. If you get stuck or need help diagnosing the minidumps, post them here and we'll have a look at them.



#7 sadj2885

sadj2885
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:06:43 AM

Posted 19 September 2014 - 08:14 AM

So I ran the debugging tools and all i can understand form it is the igdkmd64.sys file is causing the issue, but I have tried reinstall the graphics drivers numerous times and with different versions. I'm not sure if there is anything else in the minidump that can help pinpoint what exactly it is doing. The analysis info is below. Any help will be greatly appreciated.

 

************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

Microsoft ® Windows Debugger Version 6.3.9600.17237 AMD64
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\psadej\Desktop\091614-12963-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`0304e000 PsLoadedModuleList = 0xfffff800`03291890
Debug session time: Tue Sep 16 09:37:55.621 2014 (UTC - 4:00)
System Uptime: 19 days 0:50:51.951
Loading Kernel Symbols
...............................................................
................................................................
.....................................................
Loading User Symbols
Loading unloaded module list
..................................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 7F, {8, 80050033, 406f8, fffff88004c1834d}

*** WARNING: Unable to verify timestamp for igdkmd64.sys
*** ERROR: Module load completed but symbols could not be loaded for igdkmd64.sys
Probably caused by : igdkmd64.sys ( igdkmd64+17534d )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

UNEXPECTED_KERNEL_MODE_TRAP (7f)
This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault).  The first number in the
bugcheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
        use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
        use .trap on that value
Else
        .trap on the appropriate frame will show where the trap was taken
        (on x86, this will be the ebp that goes with the procedure KiTrap)
Endif
kb will then show the corrected stack.
Arguments:
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: 0000000080050033
Arg3: 00000000000406f8
Arg4: fffff88004c1834d

Debugging Details:
------------------


BUGCHECK_STR:  0x7f_8

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  System

CURRENT_IRQL:  9

ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre

LAST_CONTROL_TRANSFER:  from fffff800030c3169 to fffff800030c3bc0

STACK_TEXT:  
fffff800`00ba4d28 fffff800`030c3169 : 00000000`0000007f 00000000`00000008 00000000`80050033 00000000`000406f8 : nt!KeBugCheckEx
fffff800`00ba4d30 fffff800`030c1632 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff800`00ba4e70 fffff880`04c1834d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0xb2
fffff880`0926dd70 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : igdkmd64+0x17534d


STACK_COMMAND:  kb

FOLLOWUP_IP:
igdkmd64+17534d
fffff880`04c1834d 48c744246000000000 mov   qword ptr [rsp+60h],0

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  igdkmd64+17534d

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: igdkmd64

IMAGE_NAME:  igdkmd64.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  532b0bef

FAILURE_BUCKET_ID:  X64_0x7f_8_igdkmd64+17534d

BUCKET_ID:  X64_0x7f_8_igdkmd64+17534d

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0x7f_8_igdkmd64+17534d

FAILURE_ID_HASH:  {0e4260de-cd7f-a880-f9e3-c153788785d5}

Followup: MachineOwner
---------
 



#8 sflatechguy

sflatechguy

  • BC Advisor
  • 2,164 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:43 AM

Posted 19 September 2014 - 10:04 AM

Given that it keeps blue screening on the graphics driver, and the fact that you have reinstalled that driver numerous times, and the fact that the first parameter is 8, it seems likely that your graphics card itself is the issue. The 8 parameter can occur when the hardware itself is not performing optimally.

 

Doublecheck to make sure you have installed the correct driver. http://www.mytoshiba.com.au/support/computers/portege/r830/pt320a-06k031/download

If that doesn't fix it, then the integrated video on your laptop has gone bad. If the laptop is under warranty, you could take it in to get it repaired.


Edited by sflatechguy, 19 September 2014 - 10:04 AM.


#9 sadj2885

sadj2885
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:06:43 AM

Posted 19 September 2014 - 01:01 PM

Thanks for your quick response. I will try using Intel's driver update utility to see if it finds newer drivers. I tried all the ones from the Toshiba site and some didnt work at all and others caused it to crash within a day or two. It may be time to repalce the laptop though.



#10 sflatechguy

sflatechguy

  • BC Advisor
  • 2,164 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:43 AM

Posted 19 September 2014 - 01:07 PM

Give the Intel utility a try. But my guess is it's the hardware. :(

You're welcome, and good luck.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users