BSOD maybe random


Tthe bsod's seem random. The latest one occured while I was watching a movie on VLC media player.

Unfortunately only the last 2 got captured as CC Cleaner wiped the earlier ones.
I captured the last two which are included in the rar file along with the output of BlueScreenView and a screenshot of a basic Everest output. A full Everest report can be generated if that's not sufficient.

I ran MemTest last night and it registered 1067 errors (more or less) in 3 runs.
MemTest won't log but it was a little alarming.

I'm pretty sure the rest is on the everest image. This is the memory. 1A-DATA 4GB (2 x 2GB) 240-Pin DDR2 SDRAM DDR2 800 (PC2 6400) Dual Channel Kit Desktop Memory Model AD2U800B2G5-DRH The system is OC to a hair over 3 GHz via the BIOS. This is a setting that other users mentioned was very stable with the same board/cpu combo. The RAM is compatable according to MSI as far as I know.

Hope I did this right. Please let me know what your thoughts are.
Thanks so much for your help!


RAM is the causer of your sporadic crashes.

Attach CPUZ snips of memory and CPU tabs.

To be sure it's not the software bugging out somehow,


pbfilter.sys Sat Nov 06 22:23:54 2010

AVG Worldwide - Download tools
(Virus, Spyware & Malware Protection | Microsoft Security Essentials)

Update drivers:

Realtek LAN
Rt64win7.sys Thu Feb 26 04:04:13 2009

Elaborate Bytes Virtual Clone
VClone.sys Sun Aug 09 17:25:45 2009

Intel GMA
Intel® Driver Update Utility

Pcouffin diver, a part of many different CD/DVD burning programs
pcouffin.sys Tue Dec 05 09:39:30 2006


Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [F:\DMP\041811-62125-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*
Executable search path is: 
Windows 7 Kernel Version 7600 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a4a000 PsLoadedModuleList = 0xfffff800`02c87e50
Debug session time: Mon Apr 18 23:21:25.451 2011 (UTC - 4:00)
System Uptime: 0 days 12:45:47.029
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {41790, fffffa8000250a70, ffff, 0}

Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339d6 )

Followup: MachineOwner

0: kd> !analyze -v
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *

    # Any other values for parameter 1 must be individually examined.
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8000250a70
Arg3: 000000000000ffff
Arg4: 0000000000000000

Debugging Details:

BUGCHECK_STR:  0x1a_41790



PROCESS_NAME:  SearchProtocol


LAST_CONTROL_TRANSFER:  from fffff80002b2e26e to fffff80002abbf00

fffff880`079e5758 fffff800`02b2e26e : 00000000`0000001a 00000000`00041790 fffffa80`00250a70 00000000`0000ffff : nt!KeBugCheckEx
fffff880`079e5760 fffff800`02aef5d9 : fffffa80`00000000 000007fe`ee345fff 00000000`00000000 fffffa80`07f33d18 : nt! ?? ::FNODOBFM::`string'+0x339d6
fffff880`079e5920 fffff800`02a8f080 : ffffffff`ffffffff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`079e5a40 fffff800`02d9e7af : fffff8a0`0371a530 00000000`00000001 00000000`00000000 fffffa80`03f18a10 : nt!MmCleanProcessAddressSpace+0x228
fffff880`079e5a90 fffff800`02d77cb8 : 00000000`00000000 00000000`00000001 000007ff`fffde000 00000000`00000000 : nt!PspExitThread+0x47f
fffff880`079e5b60 fffff800`02abb153 : fffffa80`043adb30 00000000`00000000 fffffa80`03f18a10 fffffa80`07d65690 : nt!NtTerminateProcess+0x138
fffff880`079e5be0 00000000`776c15da : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`000efac8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776c15da


nt! ?? ::FNODOBFM::`string'+339d6
fffff800`02b2e26e cc              int     3


SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+339d6

FOLLOWUP_NAME:  MachineOwner


IMAGE_NAME:  ntkrnlmp.exe


FAILURE_BUCKET_ID:  X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6

BUCKET_ID:  X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6

Followup: MachineOwner

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [F:\DMP\042011-39593-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*
Executable search path is: 
Windows 7 Kernel Version 7600 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a12000 PsLoadedModuleList = 0xfffff800`02c4fe50
Debug session time: Wed Apr 20 22:59:15.021 2011 (UTC - 4:00)
System Uptime: 0 days 9:29:47.599
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *

Use !analyze -v to get detailed debugging information.

BugCheck 7F, {8, 80050031, 406f8, fffff80002a8a609}

Probably caused by : memory_corruption

Followup: memory_corruption

1: kd> !analyze -v
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *

This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault).  The first number in the
bugcheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
        use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
        use .trap on that value
        .trap on the appropriate frame will show where the trap was taken
        (on x86, this will be the ebp that goes with the procedure KiTrap)
kb will then show the corrected stack.
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: 0000000080050031
Arg3: 00000000000406f8
Arg4: fffff80002a8a609

Debugging Details:




PROCESS_NAME:  sidebar.exe


LAST_CONTROL_TRANSFER:  from fffff80002a83469 to fffff80002a83f00

fffff880`009efc68 fffff800`02a83469 : 00000000`0000007f 00000000`00000008 00000000`80050031 00000000`000406f8 : nt!KeBugCheckEx
fffff880`009efc70 fffff800`02a81932 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`009efdb0 fffff800`02a8a609 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0xb2
fffff880`02f1cfc0 fffff800`02a899e4 : 0020000a`000d003e fffff880`02f1d2e0 fffff880`02f1d2e0 00640061`003c0020 : nt!SepNormalAccessCheck+0x29
fffff880`02f1d050 fffff800`02a89410 : fffff880`02f1d2c0 00000000`00000000 fffff880`02f1d2c0 fffff880`02f1d2e0 : nt!SepAccessCheck+0x1d4
fffff880`02f1d180 fffff800`02a4c842 : fffffa80`0472df60 00000000`00000001 00000000`00000000 fffffa80`05ecc7c8 : nt!SeAccessCheckWithHint+0x180
fffff880`02f1d260 fffff880`01405a4a : 00200020`00200020 003c0020`00200020 00650072`00690064 006f0069`00740063 : nt!SeAccessCheckFromState+0x102
fffff880`02f1d950 fffff880`014052af : 00720070`00000000 0063006f`00000000 00760020`006c006f 00650075`006c0061 : NETIO!CompareSecurityContexts+0x6a
fffff880`02f1d9c0 fffff880`01405444 : 00200020`00200020 00200020`00200020 00700072`003c0020 fffff880`014c2999 : NETIO!MatchValues+0xef
fffff880`02f1da10 fffff880`014057c1 : fffffa80`07053270 fffffa80`076e35d0 fffff880`02f1e290 fffff880`02f1dc50 : NETIO!FilterMatch+0x94
fffff880`02f1da60 fffff880`014066fc : fffff880`02f10003 00000000`00000000 fffff880`02f1e290 fffff880`02f1dc50 : NETIO!IndexHashClassify+0x151
fffff880`02f1db10 fffff880`0173f819 : fffff880`02f1e290 fffff880`02f1dfc8 fffff880`02f1ede0 fffffa80`05158950 : NETIO!KfdClassify+0xa4e
fffff880`02f1de80 fffff880`017076f8 : fffffa80`053fe850 fffff880`02f1ed08 fffff880`018057a0 fffff880`02f1ede0 : tcpip!WfpAleClassify+0x49
fffff880`02f1ded0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : tcpip!WfpAlepAuthorizeReceive+0x818


CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
    fffff80002a8a105 - nt!SwapContext_PatchXSave+2
	[ 01:21 ]
    fffff80002a8a1e8 - nt!SwapContext_PatchXRstor+2 (+0xe3)
	[ 09:29 ]
    fffff80002a8a3a5 - nt!EnlightenedSwapContext_PatchXSave+2 (+0x1bd)
	[ 01:21 ]
    fffff80002a8a48a - nt!EnlightenedSwapContext_PatchXRstor+2 (+0xe5)
	[ 09:29 ]
4 errors : !nt (fffff80002a8a105-fffff80002a8a48a)

MODULE_NAME: memory_corruption

IMAGE_NAME:  memory_corruption

FOLLOWUP_NAME:  memory_corruption





Followup: memory_corruption


Thanks for the reply Cybercore!

I lack your sophistication so please bear with me. I might need a little hand holding if I didn't understand your instructions completely.

It seems like you concluded that I probably have bad RAM.

I installed PeerBlock although that is only loaded with a BitTorrent client. They were probably both running along with VLC during my last BSOD

What about installing AVG? I'm running Pro 9.XX
Do you mean permanently or what? I've tried Avast, Bitdefender and a couple of others and was underwhelmed. I'll do as you suggest with some clarification but don't want to run with no AV entirely.

I was unable to find Security Essentials in Control Panel of Windows features but I know its running somewhere. That didn't get installed.

I also didn't find Pcouffin diver but reinstalled Elby virtual clone from their site.

One thing that I neglected to mention was that I did a clean install of Win 7 ultimate. I left an installation of XP pro 32 bit on a different partition of the same physical HD hoping to run some older peripherals. That didn't work quite right and my have "confused" things.

There is some discrepancy over which partition is the System and which is the local drive. What I did was flip some SATA cables around trying to achieve a dual boot system. Whereas after the install of Win7 it would only boot to Win7 after switching cables, it would only boot to XP even with changing the boot order in the BIOS.

I did a Repair install of 7 resulting in the system only booting to 7 now. After that I tried virtual xp. The software for the old neg/slide scanner still didn't function properly so I uninstalled it.Having said that, I have no idea if some of the files from the x86 XP ver are somehow still in use.

I can probably format the XP partition but I can't imagine how that would help.

I'm going to dump out of most everything and run the diagnostic software you suggested. I'll include the snippets in my next post later.

If you have any other sage advice, particularly if it has to do with AV, please let me know soonest.

One last thing (off topic) I had a lot of time registering with your CAPATCHA (random question) and finally registered through FB. That imported my real name. I would prefer to use another user nm. Is that possible?

Thanks for reading!

Ok, let's go step by step. Attach this stuff:

CPUZ snips of memory and CPU tabs.

This is to see what memory sticks you've got and what your current ram settings are.

I hope I got this right.
If I missed something lemme no.
Its interesting that Burning detected bad ram whereas Reimage saw naught but wanted to repair some things.
UniBlue product detected a boatload of registry errors but so does PC Tools product which it "repairs".
I don't mind telling you that I have despised uniBlu since they launched a malware campaign.
Clearly there's a issue with the maybe not.
AlData doesn't have a procedure to ship good ran & then ship the bad back. That will put me out of biz for about 2 weeks.

Oh BTW thanks your you're patience


Last edited:
Hi Ed, thank you for the attachments and let's read my "sophisticated" post again:

Ok, let's go step by step. Attach this stuff:

---> CPUZ snips of memory and CPU tabs.

This is to see what memory sticks you've got and what your current ram settings are.
I see the CPU-Z shots but there's no RAMMon. Attach it kindly if you would because I'd like to look up your sticks model number to be sure your current settings (800 5 5 5 15) are correct.

Your Celeron E3300 @2,5Ghz is running 3012.5Mhz which means it is overclocked and the EIST (frequency throttle down) feature is off.

1. Set your hardware at stock, no overclocking even with the use of Intel Turbo Boost.
2. Enable EIST in the bios.

You can do 1 & 2 manually or you can load setup/fail-safe/optimized defaults.


1. Set hardware strictly at stock values, no overclocking
2. Enable the Enhanced Intel Speedstep Technology in the bios
3. Attach RAMMon

Do so and let's take it from there. When done, re-attach the MEMORY and CPU snips so I can see if your hardware is set right.

Told ya it was OC'd Was afraid you were going to suggest that.
OK then.

The RAM specs are available here - A-DATA 4GB (2 x 2GB) 240-Pin DDR2 SDRAM DDR2 800 (PC2 6400) Dual Channel Kit Desktop Memory Model AD2U800B2G5-DRH

It irks me that I paid so much more for it.

Couple of things. You wanted me to uninstall AVG which I have yet to do and am disinclined unless I have some manner of AV, AM strategy in place, Could you elaborate on that?

I'm not sure this BIOS has speedstep but will check, bring everything back to stock etc.

I had a couple of BSOD's since we last typed. One happened when running VLC The other I can't remember.

Running BurnIn with the default settings rested in choppy video & audio. Drove me crazy. You will notice that the results I sent were individual component tests.

Finally do you want me to run all the tests after setting everything to stock & attach 'em?




Told ya it was OC'd Was afraid you were going to suggest that.
OK then.
Exactly, since it is in fact overclocked and your bsod's are related to hardware -- I had to mention to disable the overclocking. Set the hardware at stock. This is really step #1. Do as I ask and re-attach 1 screenshot of the CPU-Z CPU tab, alright?


Your RAM is alright, but since you're having blue screens related to memory management, disable the overclocking for now.


Step #2 will be to update drivers as in my 1st post.

Step #3, if blue screens persists after you have set the hardware at stock and updated the drivers, will be to uninstall AVG.

Sounds good ? Ed?

Well tis done Cybercore.

After some difficulty the scariest of which was the BIOS scrambling the boot directory with predictable results.
I UL'd 2 screenshots.
It seems like I had to validate some of the tabbed screens to generate an accurate result.

For some reason subsequent posts to this forum are not making it to my email addy.
Checked you profile and all seems to be in order.
Mike changed my usernm but the issue preceded that.

Don't know how you can really glean much useful info from this other than to verify that I did what you suggested.

Looking forward to the next blast Mr. Core or can I call you Cyber?


Thanks a bunch!


1. From what I see in your screenshot, CPU is at stock with EIST on.
Well done.

2. You have updated Realtek Lan, Intel GMA, and Virtual Clone, right?

3. Have you had any crashes so far?

Yup. All updated as far as I know

Ran Registry Mechanic & CC Cleaner Registry module.

Slowly I boot. Bit by Bit, Byte by Byte.
System is noticeably slower.

Not yet but a initial test tests indicate memory problem. I ran a quick BurnIn (RAM only) & Win7 native test which flashed by a bunch of stuff that couldn't be installed. It ran a test & indicated what sounded like a problem.

Windows suddenly has the urge to reactivate and reinstall SP1-64. I allowed it.

I ran a few tests that indicated that RAM is fried. I ran others that made no mention of RAM issues. I have the results.

I also ran a Windows reliability test. This test had a LOT of detail displayed graphically with links to detail and hyperlinks to MS solutions.
There was an XML export option but it opened in notepad at first.
I dl'ed a program that just might display the results in a more meaningful fashion. I imported the delimited data but haven't looked at it yet.
If this cooks so that it can be transmitted, it may be an invaluable tool.

I'd really like to avoid RMAing the RAM. I don't want to sink a Penny into legacy RAM as a temporary replacement.

Suggestions? Rants? Let me Know.

I'm up for any ideas or will test further at your behest Big Guy.


Last edited:
I ran a few tests that indicated that RAM is fried.
I see. What I would do if this was my PC:

1. Load setup defaults in the bios - as you already did.
2. Format the partition and clean install the system.
3. Avoid old drivers and software.
4. Avoid all sorts of registry mechanics, boosters, and optimizers. Especially given that your hardware is quite powerful without a need for any of those tools.

You should be right. Of course if RAM is really "fried" you'll need to replace it, but before doing so the hardware must be set strictly at stock and the RAM should be given a good number of passes (10 +) with Memtest86+ - Advanced Memory Diagnostic Tool.

Thaks for all your help!

I have learned a bit about available tests. That's a good thing. I'll RMA the ram.
I stll want to know what AVG might have to do with all this.

Thaks again!


AVG is almost always recommended to uninstall whenever someone has blue screens, including cases of memory management.
Combined with old drivers, AVG is a sure causer of BSOD, sooner or later.
However, if you know for sure your RAM is bad, uninstalling AVG will fix nothing. Before RMA'ing the RAM, follow my previous post.

Good luck.

