BSOD for some reason, pc works fine in safe mode.

Discussion in 'Windows 7 Blue Screen of Death (BSOD)' started by pwrmngr, Dec 14, 2010.

  1. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Customers PC running 7 Home Premium, runs for 2-4 minutes then BSOD. Scanned memory and h/d no problems found. The PC runs fine in safe mode which leads me to believe a drive.

    Scanned for malware and viri's nothing found.

    Windows Forum zip attached.

    Any help? [​IMG] Thanx
     

    Attached Files:

  2. cybercore

    cybercore New Member

    Joined:
    Jul 7, 2009
    Messages:
    15,823
    Likes Received:
    321
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced. Typically the address is just plain bad or it is pointing at freed memory.
    Stack ntfs nt
    PROCESS_NAME: System
    X64_0x50_Ntfs!memmove


    Remove Avira and install MSE:

    |MG| AVIRA Removal Tool for Windows 3.0.1.17 Download

    http://www.microsoft.com/security_essentials/




    Update drivers:

    RimSerial_AMD64.sys Mon Nov 24 12:01:01 2008
    RIM Modem - update or disable

    e1y62x64.sys Fri Jun 12 21:16:42 2009
    Intel(R) Gigabit Network Connection

    igdkmd64.sys Mon Dec 14 21:26:44 2009
    Intel GMA

    mwlPSDVDisk.sys Tue Jun 02 06:15:29 2009
    MyWinLocker

    UBHelper.sys Mon Apr 27 04:48:19 2009
    Dragon HLP NewTech Infosystems




    Keep attaching your latest crash dumps for further analysis.




    Code:
    Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [F:\a\Minidump\D M P\121410-14305-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7600 MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
    Machine Name:
    Kernel base = 0xfffff800`02e00000 PsLoadedModuleList = 0xfffff800`0303de50
    Debug session time: Tue Dec 14 09:04:26.826 2010 (UTC - 5:00)
    System Uptime: 0 days 0:01:05.745
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...........
    Loading User Symbols
    Loading unloaded module list
    ...
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 50, {fffff9810c342698, 0, fffff880012424e0, 5}
    
    
    Could not read faulting driver name
    Probably caused by : Ntfs.sys ( Ntfs!memmove+250 )
    
    Followup: MachineOwner
    ---------
    
    2: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except,
    it must be protected by a Probe.  Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: fffff9810c342698, memory referenced.
    Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
    Arg3: fffff880012424e0, If non-zero, the instruction address which referenced the bad memory
    	address.
    Arg4: 0000000000000005, (reserved)
    
    Debugging Details:
    ------------------
    
    
    Could not read faulting driver name
    
    READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030a80e0
     fffff9810c342698 
    
    FAULTING_IP: 
    Ntfs!memmove+250
    fffff880`012424e0 488b440af8      mov     rax,qword ptr [rdx+rcx-8]
    
    MM_INTERNAL_CODE:  5
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x50
    
    PROCESS_NAME:  System
    
    CURRENT_IRQL:  0
    
    TRAP_FRAME:  fffff88002f8bd60 -- (.trap 0xfffff88002f8bd60)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000020 rbx=0000000000000000 rcx=fffff9810c3426c8
    rdx=ffffffffffffffd8 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff880012424e0 rsp=fffff88002f8bef8 rbp=fffff9800c342718
     r8=00000000ffffff68  r9=0000000007fffffb r10=fffff8a0046cf510
    r11=fffff9800c342760 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei pl nz na po nc
    Ntfs!memmove+0x250:
    fffff880`012424e0 488b440af8      mov     rax,qword ptr [rdx+rcx-8] ds:fffff981`0c342698=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002eef8c1 to fffff80002e70740
    
    STACK_TEXT:  
    fffff880`02f8bbf8 fffff800`02eef8c1 : 00000000`00000050 fffff981`0c342698 00000000`00000000 fffff880`02f8bd60 : nt!KeBugCheckEx
    fffff880`02f8bc00 fffff800`02e6e82e : 00000000`00000000 00000000`00000028 00000000`00000000 fffff880`013004a3 : nt! ?? ::FNODOBFM::`string'+0x40e8b
    fffff880`02f8bd60 fffff880`012424e0 : fffff880`01301310 fffffa80`05c56010 fffff880`02f8bf50 fffff8a0`00000400 : nt!KiPageFault+0x16e
    fffff880`02f8bef8 fffff880`01301310 : fffffa80`05c56010 fffff880`02f8bf50 fffff8a0`00000400 fffff8a0`046c3d20 : Ntfs!memmove+0x250
    fffff880`02f8bf00 fffff880`01301dbc : fffff8a0`046c3d20 fffff800`030155a0 fffff8a0`046c3d20 00000000`00000000 : Ntfs!NtfsRestartInsertSimpleRoot+0x50
    fffff880`02f8bf40 fffff880`012fb54f : fffffa80`05c56010 fffffa80`05e5a180 fffff880`02f8c0d8 fffff880`02f8c110 : Ntfs!InsertSimpleRoot+0xb8
    fffff880`02f8c010 fffff880`012afe17 : 00000000`00000000 fffff8a0`046c3d20 fffff880`02f8c0d8 fffff880`02f8c168 : Ntfs!AddToIndex+0xcf
    fffff880`02f8c090 fffff880`012b4665 : fffffa80`05c56010 fffff8a0`046c3d20 fffff8a0`04627b78 fffffa80`00000000 : Ntfs!NtOfsAddRecords+0x167
    fffff880`02f8c270 fffff880`012faebc : fffffa80`05c56010 fffff8a0`04627b70 00000000`0009ac0c 00000000`0009ac10 : Ntfs!GetSecurityIdFromSecurityDescriptorUnsafe+0x1fd
    fffff880`02f8c320 fffff880`013334be : fffffa80`05c56010 fffffa80`05e5a180 00000000`00000000 fffff980`0c342d00 : Ntfs!NtfsCacheSharedSecurityByDescriptor+0xa0
    fffff880`02f8c370 fffff880`012b98fd : fffffa80`05c56010 fffffa80`05e5a180 fffff800`030155a0 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x11130
    fffff880`02f8c3f0 fffff880`012546c4 : fffffa80`05c56010 fffff880`0127ea00 fffffa80`05c56010 fffff8a0`04766a90 : Ntfs!NtfsUpdateFcbInfoFromDisk+0x4fe
    fffff880`02f8c540 fffff880`01321c66 : fffffa80`05c56010 00000000`00000000 00000000`00000000 fffff8a0`04766a90 : Ntfs!NtfsInitializeDirectory+0x254
    fffff880`02f8c650 fffff880`0131690a : fffffa80`05c56010 fffffa80`05e5a180 00000000`00000000 fffffa80`05e5a180 : Ntfs!NtfsInitializeExtendDirectory+0x3d6
    fffff880`02f8c810 fffff880`012b2c79 : 00000000`00000000 fffffa80`05e43bd0 00000000`00000001 00000000`00000000 : Ntfs!NtfsMountVolume+0x1691
    fffff880`02f8cb50 fffff880`0123a51d : 00000000`00000000 00000000`00000000 fffffa80`05c56010 00000000`00000000 : Ntfs!NtfsCommonFileSystemControl+0x59
    fffff880`02f8cb90 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspDispatch+0x2ad
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    Ntfs!memmove+250
    fffff880`012424e0 488b440af8      mov     rax,qword ptr [rdx+rcx-8]
    
    SYMBOL_STACK_INDEX:  3
    
    SYMBOL_NAME:  Ntfs!memmove+250
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: Ntfs
    
    IMAGE_NAME:  Ntfs.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc14f
    
    FAILURE_BUCKET_ID:  X64_0x50_Ntfs!memmove+250
    
    BUCKET_ID:  X64_0x50_Ntfs!memmove+250
    
    Followup: MachineOwner
    ---------
    



    DRIVERS:

    Code:
    start             end                 module name
    fffff880`04600000 fffff880`0463e000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
    fffff880`00f88000 fffff880`00fdf000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
    fffff880`03a63000 fffff880`03aed000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`00c8c000 fffff880`00ca2000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
    fffff880`01122000 fffff880`0112d000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
    fffff880`0215f000 fffff880`0217a000   avgntflt avgntflt.sys Fri Nov 20 04:12:33 2009 (4B065D81)
    fffff880`02a52000 fffff880`02a59000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
    fffff880`015de000 fffff880`015ef000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
    fffff880`021c8000 fffff880`021e6000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
    fffff960`00740000 fffff960`00767000   cdd      cdd.dll      unavailable (00000000)
    fffff880`02adb000 fffff880`02af8000   cdfs     cdfs.sys     Mon Jul 13 19:19:46 2009 (4A5BC112)
    fffff880`02a00000 fffff880`02a2a000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00e15000 fffff880`00ed5000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
    fffff880`0159d000 fffff880`015cd000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00d02000 fffff880`00d60000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01485000 fffff880`014f8000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
    fffff880`015ef000 fffff880`015ff000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`02af8000 fffff880`02b06000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
    fffff880`03a35000 fffff880`03a53000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
    fffff880`03a26000 fffff880`03a35000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
    fffff880`01587000 fffff880`0159d000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`05a00000 fffff880`05a22000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
    fffff880`02129000 fffff880`0213c000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    fffff880`0200d000 fffff880`02129000   dump_iaStor dump_iaStor.sys Thu Jun 04 21:53:40 2009 (4A287AA4)
    fffff880`05beb000 fffff880`05bf7000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
    fffff880`040d6000 fffff880`041ca000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
    fffff880`04000000 fffff880`04046000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
    fffff880`04046000 fffff880`0408f000   e1y62x64 e1y62x64.sys Fri Jun 12 21:16:42 2009 (4A32FDFA)
    fffff880`01179000 fffff880`0118d000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
    fffff880`0112d000 fffff880`01179000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
    fffff880`01509000 fffff880`01513000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
    fffff880`0154d000 fffff880`01587000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
    fffff880`01400000 fffff880`0144a000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
    fffff800`033dc000 fffff800`03425000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
    fffff880`040ad000 fffff880`040d1000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
    fffff880`02b06000 fffff880`02bce000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
    fffff880`017f2000 fffff880`017fb000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
    fffff880`041ca000 fffff880`041e8000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01006000 fffff880`01122000   iaStor   iaStor.sys   Thu Jun 04 21:53:40 2009 (4A287AA4)
    fffff880`04645000 fffff880`04dee840   igdkmd64 igdkmd64.sys Mon Dec 14 21:26:44 2009 (4B26F3E4)
    fffff880`04fd7000 fffff880`04ffe000   IntcHdmi IntcHdmi.sys Tue May 26 07:13:09 2009 (4A1BCEC5)
    fffff880`00c76000 fffff880`00c8c000   intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    fffff880`041e8000 fffff880`041f7000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff800`00ba9000 fffff800`00bb3000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
    fffff880`04f82000 fffff880`04fc5000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
    fffff880`013da000 fffff880`013f4000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
    fffff880`01761000 fffff880`0178c000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
    fffff880`05be5000 fffff880`05bea200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
    fffff880`0219b000 fffff880`021b0000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`0213c000 fffff880`0215f000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
    fffff880`00caa000 fffff880`00cee000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
    fffff880`01475000 fffff880`01484000   modem    modem.sys    Mon Jul 13 20:10:48 2009 (4A5BCD08)
    fffff880`04eac000 fffff880`04eba000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
    fffff880`04def000 fffff880`04dfe000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`00c5c000 fffff880`00c76000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`02a33000 fffff880`02a49000   mozy     mozy.sys     Mon Nov 08 17:38:55 2010 (4CD87BFF)
    fffff880`021e6000 fffff880`021fe000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
    fffff880`03c93000 fffff880`03cc0000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
    fffff880`03cc0000 fffff880`03d0e000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
    fffff880`03d0e000 fffff880`03d31000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
    fffff880`02bf0000 fffff880`02bfb000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00fe8000 fffff880`00ff2000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
    fffff880`0118d000 fffff880`011eb000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
    fffff880`03a1b000 fffff880`03a26000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
    fffff880`017e0000 fffff880`017f2000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
    fffff880`02a2a000 fffff880`02a33000   mwlPSDFilter mwlPSDFilter.sys Tue Jun 02 06:07:30 2009 (4A24F9E2)
    fffff880`03a13000 fffff880`03a1b000   mwlPSDNServ mwlPSDNServ.sys Tue Jun 02 06:07:39 2009 (4A24F9EB)
    fffff880`03a00000 fffff880`03a13000   mwlPSDVDisk mwlPSDVDisk.sys Tue Jun 02 06:15:29 2009 (4A24FBC1)
    fffff880`0160f000 fffff880`01701000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`04ee7000 fffff880`04ef3000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
    fffff880`04ef3000 fffff880`04f22000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`04e5a000 fffff880`04e6f000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
    fffff880`03b61000 fffff880`03b70000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`03aed000 fffff880`03b32000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
    fffff880`01701000 fffff880`01761000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
    fffff880`015cd000 fffff880`015de000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`03bf0000 fffff880`03bfc000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
    fffff800`02e00000 fffff800`033dc000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
    fffff880`01237000 fffff880`013da000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
    fffff880`03a53000 fffff880`03a5b000   NTIDrvr  NTIDrvr.sys  Tue Mar 24 23:09:39 2009 (49C9A073)
    fffff880`02a49000 fffff880`02a52000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
    fffff880`03b3b000 fffff880`03b61000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
    fffff880`00e00000 fffff880`00e15000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00d60000 fffff880`00d93000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`014f8000 fffff880`01509000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
    fffff880`03d31000 fffff880`03dd7000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
    fffff880`04e6f000 fffff880`04eac000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`00cee000 fffff880`00d02000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
    fffff880`04ec3000 fffff880`04ee7000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`04f22000 fffff880`04f3d000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
    fffff880`04f3d000 fffff880`04f5e000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
    fffff880`04f5e000 fffff880`04f78000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
    fffff880`03b9f000 fffff880`03bf0000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
    fffff880`02a9c000 fffff880`02aa5000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`02aa5000 fffff880`02aae000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`02aae000 fffff880`02ab7000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
    fffff880`01513000 fffff880`0154d000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
    fffff880`04f78000 fffff880`04f7fc00   RimSerial_AMD64 RimSerial_AMD64.sys Mon Nov 24 12:01:01 2008 (492ADDCD)
    fffff880`03a5b000 fffff880`03a63000   RootMdm  RootMdm.sys  Mon Jul 13 20:10:47 2009 (4A5BCD07)
    fffff880`021b0000 fffff880`021c8000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`05a27000 fffff880`05be4a00   RTKVHD64 RTKVHD64.sys Mon Jul 20 06:52:29 2009 (4A644C6D)
    fffff880`03dd7000 fffff880`03de2000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
    fffff880`017d8000 fffff880`017e0000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
    fffff880`05f2d000 fffff880`05fc3000   srv      srv.sys      Thu Aug 26 23:38:00 2010 (4C773318)
    fffff880`05ec6000 fffff880`05f2d000   srv2     srv2.sys     Thu Aug 26 23:37:46 2010 (4C77330A)
    fffff880`03c00000 fffff880`03c2d000   srvnet   srvnet.sys   Thu Aug 26 23:37:24 2010 (4C7732F4)
    fffff880`03c2d000 fffff880`03c35000   SSPORT   SSPORT.sys   Thu Aug 11 19:07:32 2005 (42FBDA34)
    fffff880`04f80000 fffff880`04f81480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
    fffff880`03801000 fffff880`039fe000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
    fffff880`03c35000 fffff880`03c47000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
    fffff880`01468000 fffff880`01475000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
    fffff880`0144a000 fffff880`01468000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
    fffff880`03b8b000 fffff880`03b9f000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
    fffff960`005f0000 fffff960`005fa000   TSDDD    TSDDD.dll    unavailable (00000000)
    fffff880`01200000 fffff880`01226000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
    fffff880`041f7000 fffff880`041ff000   UBHelper UBHelper.sys Mon Apr 27 04:48:19 2009 (49F57153)
    fffff880`04fc5000 fffff880`04fd7000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
    fffff880`05bf7000 fffff880`05bf8f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
    fffff880`0409c000 fffff880`040ad000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`04e00000 fffff880`04e5a000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
    fffff880`00da8000 fffff880`00dfe000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`02ac0000 fffff880`02adb000   USBSTOR  USBSTOR.SYS  Mon Jul 13 20:06:34 2009 (4A5BCC0A)
    fffff880`0408f000 fffff880`0409c000   usbuhci  usbuhci.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`00ff2000 fffff880`00fff000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
    fffff880`02a59000 fffff880`02a67000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
    fffff880`02a67000 fffff880`02a8c000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
    fffff880`00d93000 fffff880`00da8000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00c00000 fffff880`00c5c000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
    fffff880`0178c000 fffff880`017d8000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
    fffff880`03b70000 fffff880`03b8b000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
    fffff880`02a8c000 fffff880`02a9c000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
    fffff880`00ed5000 fffff880`00f79000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
    fffff880`00f79000 fffff880`00f88000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`03b32000 fffff880`03b3b000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff960`00080000 fffff960`0038f000   win32k   win32k.sys   unavailable (00000000)
    fffff880`02ab7000 fffff880`02ac0000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`00fdf000 fffff880`00fe8000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`0217a000 fffff880`0219b000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)
    fffff880`05fc3000 fffff880`05ff4000   WUDFRd   WUDFRd.sys   Mon Jul 13 20:06:06 2009 (4A5BCBEE)
    
    Unloaded modules:
    fffff880`01600000 fffff880`0160e000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  0000E000
    fffff880`02ac1000 fffff880`02bdd000   dump_iaStor.
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  0011C000
    fffff880`02bdd000 fffff880`02bf0000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00013000
    
     
  3. cybercore

    cybercore New Member

    Joined:
    Jul 7, 2009
    Messages:
    15,823
    Likes Received:
    321
    First of all remove Avira and update drivers. Next check your RAM.


    ~~~~~~~~~~~~~

    Hardware diagnostics:

    RAM - ensure it's set right in the bios. Bad ram sometimes causes ntfs errors.

    RAM - Test with Memtest86+ - Windows 7 Forums



    Hard drive:

    1. NTFS check - cmd -> chkdsk /r

    2. HDD health:

    a) HDDScan - SMART

    b) HD Diagnostic
     
  4. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Uninstalled all software above and updated pertinant drivers. Ran all the software above except the chkdsk as when i do it BSOD.

    attached are the new minidumps and screen shots of tests and test results.

    Thanx huge :)

    <SNIP>
    Got the chkdsk /r to run :)
     

    Attached Files:

    #4 pwrmngr, Dec 14, 2010
    Last edited: Dec 14, 2010
  5. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    Update this Intel Rapid Storage driver from Intel's site to March 2010 version:

    iaStor iaStor.sys Thu Jun 04 21:53:40 200


    -----

    Uninstall MyWinLocker. It is responsible for the issues. Enjoy.
     
    #5 TorrentG, Dec 14, 2010
    Last edited: Dec 14, 2010
  6. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    1. Tired the Rapid Storage driver update but it said I had the newest one.
    2. Ran cpu-z and screens are included in zip.
    3. Ran chkdsk /r no problems.
    4. Tried to uninstal MyWinlocker BSOD.

    Capture.PNG Capture1.PNG
     

    Attached Files:

  7. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    Intel Rapid storage not updated and MyWinLocker not uninstalled. Running some commands here on your latest crash dump 121410-15366-01

    Code:
    2: kd> lmvm  mwlPSDNServ
    start             end                 module name
    fffff880`03e84000 fffff880`03e8c000   mwlPSDNServ   (deferred)             
        Image path: \SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
        Image name: mwlPSDNServ.sys
        Timestamp:        Tue Jun 02 06:07:39 2009 (4A24F9EB)
        CheckSum:         0000AC2F
        ImageSize:        00008000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    
    Code:
    mwlPSDVDisk mwlPSDVDisk.sys Tue Jun 02 06:15:29 2009
    mwlPSDNServ mwlPSDNServ.sys Tue Jun 02 06:07:39 2009
    Code:
    2: kd> lmvm mwlPSDVDisk
    start             end                 module name
    fffff880`03e71000 fffff880`03e84000   mwlPSDVDisk   (deferred)             
        Image path: \SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
        Image name: mwlPSDVDisk.sys
        Timestamp:        Tue Jun 02 06:15:29 2009 (4A24FBC1)
        CheckSum:         0001C2BD
        ImageSize:        00013000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    
    Code:
    2: kd> lmvm iastor
    start             end                 module name
    fffff880`01000000 fffff880`0111c000   iaStor     (deferred)             
        Image path: \SystemRoot\system32\DRIVERS\iaStor.sys
        Image name: iaStor.sys
        Timestamp:        Thu Jun 04 21:53:40 2009 (4A287AA4)
        CheckSum:         000640D7
        ImageSize:        0011C000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    ----------

    If you post new dumps which will not be necessary if you actually update and uninstall what I've said, please copy only new ones from C:\Widows\Minidump folder to any other folder, then zip them, and attach to a post.
     
  8. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
  9. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Ok when I tried to update the drivers it wasn't this file you sent me the link too.

    Everytime I try and uninstall MyWinLocker I get a BSOD and in safe mode I can't uninstall it :(

    Thanx
     
  10. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Ok updated Intel Rapid storage drivers and when I try and uninstall winlocker BSOD :(
     

    Attached Files:

    #10 pwrmngr, Dec 14, 2010
    Last edited: Dec 14, 2010
  11. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    Boot to safe mode and delete these 3 MyWinLocker drivers in C:\Windows\System32\drivers. Reboot and uninstall the rest of the program normally.

    mwlPSDFilter mwlPSDFilter.sys Tue Jun 02 06:07:30 2009 (4A24F9E2)
    mwlPSDNServ mwlPSDNServ.sys Tue Jun 02 06:07:39 2009 (4A24F9EB)
    mwlPSDVDisk mwlPSDVDisk.sys Tue Jun 02 06:15:29 2009 (4A24FBC1)
     
    #11 TorrentG, Dec 14, 2010
    Last edited: Dec 14, 2010
  12. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Ok deleted all the files, 3, above rebooted and I get a CRITICAL_SERVICE_FAILED error.

    attached is the last mini dump.

    thanx huge for all the help.
     

    Attached Files:

  13. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    Ehhh....

    Weird type of crash in that I can't see the drivers. Only about 5 percent of them....but I do see new Intel.

    Run a sfc /scannow command from an elevated prompt...

    If any more crashes, please post them.

    Good progress though. Whatever any issues are left, we'll rid them no problem.

    You're welcome.
     
  14. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    TG I REALLY appreciate your help :)

    Thanx
     
  15. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Ok ran the sfc attached is the screen.

    Thanx
     

    Attached Files:

  16. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    1) Run the installer once. Reboot then run it again one more time, to update this:

    RTKVHD64 RTKVHD64.sys Mon Jul 20 06:52:29 2009

    Realtek

    "Vista, Windows7 Driver (32/64bits) Driver only (Executable file)"

    2) Navigate to C:\Windows\System32\drivers and delete this file:

    NTIDrvr NTIDrvr.sys Tue Mar 24 23:09:39 2009

    Reboot.

    Check if CD/DVD drive still works. If so, great. If not, no problem...just let me know and there's a very easy fix.

    3) This driver is from Research In Motion. Probably for a Blackberry. Update the entire software for it from manufacturer's site:

    RimSerial_AMD64 RimSerial_AMD64.sys Mon Nov 24 12:01:01 2008

    Or if you're not completely sure, best to simply delete it and reboot. Same driver folder as above.

    4) Update this Intel gigabit ethernet driver:

    e1y62x64 e1y62x64.sys Fri Jun 12 21:16:42 2009

    http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=18713&lang=eng

    5) Delete this driver in the driver folder then reboot:

    SSPORT SSPORT.sys Thu Aug 11 19:07:32 2005

    ------------------

    If this is all followed well to a tee, the machine will be without issue.

    Let me know and good luck.

     
  17. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    Ok did all above and all went off without a hitch.

    Rebooted final time got the BSOD and CRITICAL error again :(

    attached are the dumps

    Thanx

    <SNIP>
    dvd drive doesnt work :)
     

    Attached Files:

    #17 pwrmngr, Dec 15, 2010
    Last edited: Dec 15, 2010
  18. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    This will fix the DVD/CD. Looking into crash dump now:


    1. Click Start

      [​IMG]
      , and then click All Programs.
    2. Click Accessories, and then click Run.
    3. Type regedit, and then click OK.

      [​IMG]
      If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
    4. In the navigation pane, locate and then click the following registry subkey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
    5. In the right pane, click UpperFilters.

      Note You may also see an UpperFilters.bak registry entry. You do not have to remove that entry. Click UpperFilters only. If you do not see the UpperFilters registry entry, you still might have to remove the LowerFilters registry entry. To do this, go to step 8.
    6. On the Edit menu, click Delete.
    7. When you are prompted to confirm the deletion, click Yes.
    8. In the right pane, click LowerFilters.
    9. On the Edit menu, click Delete.
    10. When you are prompted to confirm the deletion, click Yes.
    11. Exit Registry Editor.
    12. Restart the computer.
     
  19. TorrentG

    TorrentG Banned

    Joined:
    May 31, 2010
    Messages:
    7,814
    Likes Received:
    372
    Yeah, the crash dump is another critical service failed.

    I know what it is, not by analyzing, just by what we've done.

    Make sure MyWinLocker is now completely uninstalled.

    --------------

    Then download and run this trial version of DameWare NT Utilities:

    DameWare Downloads Page

    Run the actual DameWare NT Utilities program itself, of the few it installs.

    On the left side, double click on Workstations. Look for the actual PC you are on now.

    Double click it. (If it is not there, go to Favorite Machines section and add 127.0.0.1 to it and use this entry instead.)

    Double click Services.

    Then double click Remove Service. Click next.

    Use the dropdown to find any and all MyWinLocker entries. Go over the list and if you're not sure about any, let me know. Delete them all, while checking the box to "Include Device Drivers" for good measure.

    This should take care of any issues left if entirely removing MyWinLocker did not already, in and of itself.
     
  20. pwrmngr

    pwrmngr New Member

    Joined:
    May 27, 2009
    Messages:
    50
    Likes Received:
    0
    ok i cant uninstall MWL as it BSOD and in safe mode wont allow it.
    I will try the dameware :)

    Hang tight and THANX
     

Share This Page

Loading...