Windows 7 BSODs after system restore

ParanoidPlumber

New Member
When I upgraded my video card months ago I had problems with the video drivers causing BSODs. I fixed that problem after updating the drivers properly.

Just recently I reverted to a restore point and now the same problem appears to have come back. The restore point seems to have created a mismatch in drivers or a windows update.To fix the problem I've updated multiple drivers and I still get BSODs. It most often happens when playing a game. Sometimes the games graphics appear to be skipping and having trouble and then the BSOD happens. Although, I have had BSODs without having anything intensive running too. Many times once I restart the computer it will crash again real soon.
 

Attachments

  • Seven Forums.zip
    948.8 KB · Views: 445
  • cpuz.gif
    cpuz.gif
    125.6 KB · Views: 719
Last edited:
Let's see:



050611-19094-01.dmp
BugCheck C5, {8, 2, 1, fffff80003006617}
Probably caused by : aswSnx.SYS ( aswSnx+3fb84 )

050611-19422-01.dmp
BugCheck 24, {1904fb, fffff88009d02888, fffff88009d020e0, fffff8800124ec1f}
Probably caused by : Ntfs.sys ( Ntfs!NtfsCleanupIrpContext+39a )

050611-26473-01.dmp
BugCheck 1000007E, {ffffffffc0000005, fffff88004026270, fffff8800215d668, fffff8800215cec0}
Probably caused by : dxgmms1.sys ( dxgmms1!VIDMM_GLOBAL::EndPreparation+48 )

050611-19094-02.dmp
BugCheck 3B, {c000001d, fffff800031d4e3e, fffff8800753d710, 0}
Probably caused by : ntkrnlmp.exe ( nt!ObOpenObjectByName+1ee )



1. Uninstall AVAST

avast! Uninstall Utility


2. Install MSE

Link Removed due to 404 Error


3. Update UltraMon
UltraMonUtility.sys Thu Nov 13 20:10:30 2008


4. Update Speedfan
speedfan.sys Sun Sep 24 09:26:48 2006
(the latest is 2010)


5. Command Prompt > chkdsk /f


It does look like hardware is involved too. So,


6. Attach CPUZ C P U tab screenshot


7. Attach Passmark RAMMon HTML.zip





CRASH DUMPS

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050611-19094-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e5b000 PsLoadedModuleList = 0xfffff800`030a0e90
Debug session time: Fri May  6 18:51:14.425 2011 (UTC - 4:00)
System Uptime: 0 days 0:20:21.017
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C5, {8, 2, 1, fffff80003006617}

Unable to load image \SystemRoot\System32\Drivers\aswSnx.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for aswSnx.SYS
*** ERROR: Module load completed but symbols could not be loaded for aswSnx.SYS
Probably caused by : aswSnx.SYS ( aswSnx+3fb84 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is
caused by drivers that have corrupted the system pool.  Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff80003006617, address which referenced memory

Debugging Details:
------------------


BUGCHECK_STR:  0xC5_2

CURRENT_IRQL:  2

FAULTING_IP: 
nt!ExAllocatePoolWithTag+537
fffff800`03006617 48895808        mov     qword ptr [rax+8],rbx

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  services.exe

TRAP_FRAME:  fffff880082af3b0 -- (.trap 0xfffff880082af3b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa800461dd30
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003006617 rsp=fffff880082af540 rbp=0000000000001000
 r8=0000000000000000  r9=fffff80003062820 r10=fffff800030626c8
r11=fffffa8004484d18 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
nt!ExAllocatePoolWithTag+0x537:
fffff800`03006617 48895808        mov     qword ptr [rax+8],rbx ds:00000000`00000008=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002edabe9 to fffff80002edb640

STACK_TEXT:  
fffff880`082af268 fffff800`02edabe9 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`082af270 fffff800`02ed9860 : 00000000`00000000 00000000`00000702 fffff880`082af5b0 fffff800`03062820 : nt!KiBugCheckDispatch+0x69
fffff880`082af3b0 fffff800`03006617 : fffff880`082af500 fffff880`082af548 fffff880`082af548 fffff880`082af558 : nt!KiPageFault+0x260
fffff880`082af540 fffff880`03e51b84 : 00000000`00000000 fffffa80`04aa8cd8 00000000`00000000 fffffa80`00000000 : nt!ExAllocatePoolWithTag+0x537
fffff880`082af630 00000000`00000000 : fffffa80`04aa8cd8 00000000`00000000 fffffa80`00000000 fffff8a0`02597010 : aswSnx+0x3fb84


STACK_COMMAND:  kb

FOLLOWUP_IP: 
aswSnx+3fb84
fffff880`03e51b84 ??              ???

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  aswSnx+3fb84

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: aswSnx

IMAGE_NAME:  aswSnx.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  4dac7246

FAILURE_BUCKET_ID:  X64_0xC5_2_aswSnx+3fb84

BUCKET_ID:  X64_0xC5_2_aswSnx+3fb84

Followup: MachineOwner
---------




Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050611-19422-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e51000 PsLoadedModuleList = 0xfffff800`03096e90
Debug session time: Fri May  6 23:11:23.040 2011 (UTC - 4:00)
System Uptime: 0 days 0:16:20.632
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 24, {1904fb, fffff88009d02888, fffff88009d020e0, fffff8800124ec1f}

Probably caused by : Ntfs.sys ( Ntfs!NtfsCleanupIrpContext+39a )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88009d02888
Arg3: fffff88009d020e0
Arg4: fffff8800124ec1f

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff88009d02888 -- (.exr 0xfffff88009d02888)
ExceptionAddress: fffff8800124ec1f (Ntfs!NtfsCleanupIrpContext+0x000000000000039a)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff88009d020e0 -- (.cxr 0xfffff88009d020e0)
rax=fffff8a0024a3140 rbx=fffffa800404d880 rcx=fffff8a0024a3140
rdx=0000000000000001 rsi=000000000000ffff rdi=fffffa800404d8c8
rip=fffff8800124ec1f rsp=fffff88009d02ac0 rbp=fffff8a0024a3010
 r8=0000000000000000  r9=0000000000000727 r10=0000000000000000
r11=fffffa8003f9af68 r12=fffffa800404d930 r13=fffffa800404d9d8
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
Ntfs!NtfsCleanupIrpContext+0x39a:
fffff880`0124ec1f 488b4930        mov     rcx,qword ptr [rcx+30h] ds:002b:fffff8a0`024a3170=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  firefox.exe

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800031020e8
 ffffffffffffffff 

FOLLOWUP_IP: 
Ntfs!NtfsCleanupIrpContext+39a
fffff880`0124ec1f 488b4930        mov     rcx,qword ptr [rcx+30h]

FAULTING_IP: 
Ntfs!NtfsCleanupIrpContext+39a
fffff880`0124ec1f 488b4930        mov     rcx,qword ptr [rcx+30h]

BUGCHECK_STR:  0x24

LAST_CONTROL_TRANSFER:  from fffff88001250e44 to fffff8800124ec1f

STACK_TEXT:  
fffff880`09d02ac0 fffff880`01250e44 : fffffa80`0404d880 00000000`00000001 00000000`00000000 00000000`00000000 : Ntfs!NtfsCleanupIrpContext+0x39a
fffff880`09d02b10 fffff880`012e86ec : 00000000`00000000 fffffa80`03ead750 fffff880`09b2da40 fffffa80`0404d880 : Ntfs!NtfsExtendedCompleteRequestInternal+0xd4
fffff880`09d02b50 fffff880`0124fa3d : fffffa80`0404d880 fffffa80`03f9ac10 fffff880`09b2da40 fffffa80`03a06000 : Ntfs!NtfsCommonCreate+0x21b5
fffff880`09d02d30 fffff800`02ec9157 : fffff880`09b2d9b0 ff070605`ff070605 ff070605`ff070605 ff070605`ff070605 : Ntfs!NtfsCommonCreateCallout+0x1d
fffff880`09d02d60 fffff800`02ec9111 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxSwitchKernelStackCallout+0x27
fffff880`09b2d880 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  Ntfs!NtfsCleanupIrpContext+39a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce792f9

STACK_COMMAND:  .cxr 0xfffff88009d020e0 ; kb

FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsCleanupIrpContext+39a

BUCKET_ID:  X64_0x24_Ntfs!NtfsCleanupIrpContext+39a

Followup: MachineOwner
---------




Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050611-26473-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e07000 PsLoadedModuleList = 0xfffff800`0304ce90
Debug session time: Fri May  6 18:28:47.249 2011 (UTC - 4:00)
System Uptime: 0 days 1:05:02.826
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {ffffffffc0000005, fffff88004026270, fffff8800215d668, fffff8800215cec0}

Probably caused by : dxgmms1.sys ( dxgmms1!VIDMM_GLOBAL::EndPreparation+48 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003.  This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG.  This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG.  This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88004026270, The address that the exception occurred at
Arg3: fffff8800215d668, Exception Record Address
Arg4: fffff8800215cec0, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
dxgmms1!VIDMM_GLOBAL::EndPreparation+48
fffff880`04026270 488908          mov     qword ptr [rax],rcx

EXCEPTION_RECORD:  fffff8800215d668 -- (.exr 0xfffff8800215d668)
ExceptionAddress: fffff88004026270 (dxgmms1!VIDMM_GLOBAL::EndPreparation+0x0000000000000048)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000001
   Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000

CONTEXT:  fffff8800215cec0 -- (.cxr 0xfffff8800215cec0)
rax=0000000000000000 rbx=fffffa8005a11000 rcx=0000000000000000
rdx=0000000000000000 rsi=000000000000000d rdi=fffffa8005a11000
rip=fffff88004026270 rsp=fffff8800215d8a0 rbp=fffffa8004aa46e0
 r8=fffffa8005a11bb0  r9=0000000000000000 r10=fffffa8005a11c40
r11=000000000000000d r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010287
dxgmms1!VIDMM_GLOBAL::EndPreparation+0x48:
fffff880`04026270 488908          mov     qword ptr [rax],rcx ds:002b:00000000`00000000=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  NULL_DEREFERENCE

PROCESS_NAME:  System

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  0000000000000000

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030b80e8
 0000000000000000 

FOLLOWUP_IP: 
dxgmms1!VIDMM_GLOBAL::EndPreparation+48
fffff880`04026270 488908          mov     qword ptr [rax],rcx

BUGCHECK_STR:  0x7E

LAST_CONTROL_TRANSFER:  from fffff8800401e79d to fffff88004026270

STACK_TEXT:  
fffff880`0215d8a0 fffff880`0401e79d : 00000000`00000000 fffffa80`05baa000 00000000`0000000d 00000000`00000000 : dxgmms1!VIDMM_GLOBAL::EndPreparation+0x48
fffff880`0215d910 fffff880`0403865d : 00000000`00000000 fffff8a0`0b3ee8e0 fffffa80`00000000 fffffa80`04aa46e0 : dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+0xd09
fffff880`0215dae0 fffff880`04038398 : fffff800`043ff080 fffff880`04037d00 fffffa80`00000000 fffffa80`00000000 : dxgmms1!VidSchiSubmitRenderCommand+0x241
fffff880`0215dcd0 fffff880`04037e96 : 00000000`0000070a fffffa80`058db5d0 00000000`00000080 fffffa80`04dd3410 : dxgmms1!VidSchiSubmitQueueCommand+0x50
fffff880`0215dd00 fffff800`03124cce : 00000000`04694977 fffffa80`05592b60 fffffa80`03a57040 fffffa80`05592b60 : dxgmms1!VidSchiWorkerThread+0xd6
fffff880`0215dd40 fffff800`02e78fe6 : fffff800`02ff9e80 fffffa80`05592b60 fffff800`03007cc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0215dd80 00000000`00000000 : fffff880`0215e000 fffff880`02158000 fffff880`0215d680 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!VIDMM_GLOBAL::EndPreparation+48

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

STACK_COMMAND:  .cxr 0xfffff8800215cec0 ; kb

FAILURE_BUCKET_ID:  X64_0x7E_dxgmms1!VIDMM_GLOBAL::EndPreparation+48

BUCKET_ID:  X64_0x7E_dxgmms1!VIDMM_GLOBAL::EndPreparation+48

Followup: MachineOwner
---------





Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050611-19094-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e59000 PsLoadedModuleList = 0xfffff800`0309ee90
Debug session time: Fri May  6 23:25:41.492 2011 (UTC - 4:00)
System Uptime: 0 days 0:13:08.069
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c000001d, fffff800031d4e3e, fffff8800753d710, 0}

Probably caused by : ntkrnlmp.exe ( nt!ObOpenObjectByName+1ee )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c000001d, Exception code that caused the bugcheck
Arg2: fffff800031d4e3e, Address of the instruction which caused the bugcheck
Arg3: fffff8800753d710, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION}  Illegal Instruction  An attempt was made to execute an illegal instruction.

FAULTING_IP: 
nt!ObOpenObjectByName+1ee
fffff800`031d4e3e 4d8db708020000  lea     r14,[r15+208h]

CONTEXT:  fffff8800753d710 -- (.cxr 0xfffff8800753d710)
rax=0000000000000000 rbx=fffffa800408bb10 rcx=fffffa800408bcc8
rdx=0000000000000000 rsi=fffffa8003acfa9c rdi=fffffa800408bbf0
rip=fffff800031d4e3e rsp=fffff8800753e0f0 rbp=fffffa80062d2b60
 r8=0000000000000000  r9=0000000000000000 r10=0044006d00770044
r11=fffff8800753e0c0 r12=0000000000000002 r13=fffffa8003acfa50
r14=0000000000000000 r15=fffffa8006201b30
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
nt!ObOpenObjectByName+0x1ee:
fffff800`031d4e3e 4d8db708020000  lea     r14,[r15+208h]
Resetting default scope

CUSTOMER_CRASH_COUNT:  2

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  dwm.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff800031d4e3e

STACK_TEXT:  
fffff880`0753e0f0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByName+0x1ee


FOLLOWUP_IP: 
nt!ObOpenObjectByName+1ee
fffff800`031d4e3e 4d8db708020000  lea     r14,[r15+208h]

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!ObOpenObjectByName+1ee

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

STACK_COMMAND:  .cxr 0xfffff8800753d710 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_nt!ObOpenObjectByName+1ee

BUCKET_ID:  X64_0x3B_nt!ObOpenObjectByName+1ee

Followup: MachineOwner
---------





DRIVERS

Code:
start             end                 module name
fffff880`00fa2000 fffff880`00ff9000   ACPI     ACPI.sys     Sat Nov 20 04:19:16 2010 (4CE79294)
fffff880`03e50000 fffff880`03ed9000   afd      afd.sys      Sat Nov 20 04:23:27 2010 (4CE7938F)
fffff880`045d0000 fffff880`045e6000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`0525e000 fffff880`05272000   amdiox64 amdiox64.sys Thu Feb 18 10:17:53 2010 (4B7D5A21)
fffff880`041c8000 fffff880`041dd000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00de6000 fffff880`00df1000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`03a80000 fffff880`03a89000   aswFsBlk aswFsBlk.SYS Mon Apr 18 13:13:00 2011 (4DAC711C)
fffff880`03a46000 fffff880`03a80000   aswMonFlt aswMonFlt.sys Mon Apr 18 13:13:11 2011 (4DAC7127)
fffff880`03ed9000 fffff880`03ee3000   aswRdr   aswRdr.SYS   Mon Apr 18 13:13:23 2011 (4DAC7133)
fffff880`03ee7000 fffff880`03f7f000   aswSnx   aswSnx.SYS   Mon Apr 18 13:17:58 2011 (4DAC7246)
fffff880`04155000 fffff880`041a2000   aswSP    aswSP.SYS    Mon Apr 18 13:17:56 2011 (4DAC7244)
fffff880`03e40000 fffff880`03e50000   aswTdi   aswTdi.SYS   Mon Apr 18 13:16:21 2011 (4DAC71E5)
fffff880`08a00000 fffff880`08a0b000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00ee0000 fffff880`00ee9000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00c50000 fffff880`00c7a000   ataport  ataport.SYS  Sat Nov 20 04:19:15 2010 (4CE79293)
fffff880`04884000 fffff880`05180000   atikmdag atikmdag.sys Wed Jan 26 17:48:28 2011 (4D40A4BC)
fffff880`04413000 fffff880`04461000   atikmpag atikmpag.sys Wed Jan 26 17:13:33 2011 (4D409C8D)
fffff960`00970000 fffff960`009d1000   ATMFD    ATMFD.DLL    Sat Feb 19 04:00:32 2011 (4D5F86B0)
fffff880`03f88000 fffff880`03f8f000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04144000 fffff880`04155000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`03bd6000 fffff880`03bf4000   bowser   bowser.sys   Tue Feb 22 23:55:04 2011 (4D649328)
fffff960`006a0000 fffff960`006c7000   cdd      cdd.dll      Sat Nov 20 07:55:34 2010 (4CE7C546)
fffff880`0158e000 fffff880`015b8000   cdrom    cdrom.sys    Sat Nov 20 04:19:20 2010 (4CE79298)
fffff880`00cfc000 fffff880`00dbc000   CI       CI.dll       Sat Nov 20 08:12:36 2010 (4CE7C944)
fffff880`01600000 fffff880`01630000   CLASSPNP CLASSPNP.SYS Sat Nov 20 04:19:23 2010 (4CE7929B)
fffff880`00c9e000 fffff880`00cfc000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01100000 fffff880`01172000   cng      cng.sys      Sat Nov 20 05:08:45 2010 (4CE79E2D)
fffff880`045c0000 fffff880`045d0000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`053bf000 fffff880`053cd000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`040a3000 fffff880`04126000   csc      csc.sys      Sat Nov 20 04:27:12 2010 (4CE79470)
fffff880`04126000 fffff880`04144000   dfsc     dfsc.sys     Sat Nov 20 04:26:31 2010 (4CE79447)
fffff880`04094000 fffff880`040a3000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`019c8000 fffff880`019de000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`05397000 fffff880`053b9000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`053d9000 fffff880`053e2000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`053cd000 fffff880`053d9000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`053e2000 fffff880`053f5000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`013f3000 fffff880`013ff000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`04461000 fffff880`04555000   dxgkrnl  dxgkrnl.sys  Sat Nov 20 04:50:50 2010 (4CE799FA)
fffff880`05180000 fffff880`051c6000   dxgmms1  dxgmms1.sys  Sat Nov 20 04:49:53 2010 (4CE799C1)
fffff880`03ad7000 fffff880`03b0d000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`04875000 fffff880`04882000   fdc      fdc.sys      Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`0108e000 fffff880`010a2000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`052de000 fffff880`052e9000   flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`01042000 fffff880`0108e000   fltmgr   fltmgr.sys   Sat Nov 20 04:19:24 2010 (4CE7929C)
fffff880`0122c000 fffff880`01236000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`0198e000 fffff880`019c8000   fvevol   fvevol.sys   Sat Nov 20 04:24:06 2010 (4CE793B6)
fffff880`01884000 fffff880`018ce000   fwpkclnt fwpkclnt.sys Sat Nov 20 04:21:37 2010 (4CE79321)
fffff800`02e10000 fffff800`02e59000   hal      hal.dll      Sat Nov 20 08:00:25 2010 (4CE7C669)
fffff880`051c6000 fffff880`051ea000   HDAudBus HDAudBus.sys Sat Nov 20 05:43:42 2010 (4CE7A65E)
fffff880`052fe000 fffff880`0535a000   HdAudio  HdAudio.sys  Sat Nov 20 05:44:23 2010 (4CE7A687)
fffff880`0163e000 fffff880`01657000   HIDCLASS HIDCLASS.SYS Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`053f7000 fffff880`053ff080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`01630000 fffff880`0163e000   hidusb   hidusb.sys   Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`03b0d000 fffff880`03bd6000   HTTP     HTTP.sys     Sat Nov 20 04:24:30 2010 (4CE793CE)
fffff880`01985000 fffff880`0198e000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`04400000 fffff880`0440f000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`00df1000 fffff880`00dff000   kbdhid   kbdhid.sys   Sat Nov 20 05:33:25 2010 (4CE7A3F5)
fffff800`00bc4000 fffff800`00bce000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`0521b000 fffff880`0525e000   ks       ks.sys       Sat Nov 20 05:33:23 2010 (4CE7A3F3)
fffff880`01200000 fffff880`0121b000   ksecdd   ksecdd.sys   Sat Nov 20 04:21:15 2010 (4CE7930B)
fffff880`01563000 fffff880`0158e000   ksecpkg  ksecpkg.sys  Sat Nov 20 05:10:34 2010 (4CE79E9A)
fffff880`053b9000 fffff880`053be200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`03aaa000 fffff880`03abf000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`03a23000 fffff880`03a46000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c7d000 fffff880`00c8a000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`03a15000 fffff880`03a23000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`01400000 fffff880`0140f000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`01657000 fffff880`01664000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00dcc000 fffff880`00de6000   mountmgr mountmgr.sys Sat Nov 20 04:19:21 2010 (4CE79299)
fffff880`07080000 fffff880`07098000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`07098000 fffff880`070c5000   mrxsmb   mrxsmb.sys   Tue Feb 22 23:56:22 2011 (4D649376)
fffff880`070c5000 fffff880`07112000   mrxsmb10 mrxsmb10.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`07112000 fffff880`07136000   mrxsmb20 mrxsmb20.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`03fed000 fffff880`03ff8000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e09000 fffff880`00e13000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`010a2000 fffff880`01100000   msrpc    msrpc.sys    Sat Nov 20 04:21:56 2010 (4CE79334)
fffff880`04089000 fffff880`04094000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`01973000 fffff880`01985000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01410000 fffff880`01503000   ndis     ndis.sys     Sat Nov 20 04:23:30 2010 (4CE79392)
fffff880`045e6000 fffff880`045f2000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`011b3000 fffff880`011e2000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`052e9000 fffff880`052fe000   NDProxy  NDProxy.SYS  Sat Nov 20 05:52:20 2010 (4CE7A864)
fffff880`0166f000 fffff880`0167e000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`015b8000 fffff880`015fd000   netbt    netbt.sys    Sat Nov 20 04:23:18 2010 (4CE79386)
fffff880`01503000 fffff880`01563000   NETIO    NETIO.SYS    Sat Nov 20 04:23:13 2010 (4CE79381)
fffff880`03e00000 fffff880`03e11000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`0407d000 fffff880`04089000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e59000 fffff800`03443000   nt       ntkrnlmp.exe Sat Nov 20 04:30:02 2010 (4CE7951A)
fffff880`01250000 fffff880`013f3000   Ntfs     Ntfs.sys     Sat Nov 20 04:20:57 2010 (4CE792F9)
fffff880`03f7f000 fffff880`03f88000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`01172000 fffff880`01198000   pacer    pacer.sys    Sat Nov 20 05:52:18 2010 (4CE7A862)
fffff880`00e53000 fffff880`00e68000   partmgr  partmgr.sys  Sat Nov 20 04:20:00 2010 (4CE792C0)
fffff880`00e13000 fffff880`00e46000   pci      pci.sys      Sat Nov 20 04:19:11 2010 (4CE7928F)
fffff880`00ed9000 fffff880`00ee0000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00dbc000 fffff880`00dcc000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`0121b000 fffff880`0122c000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`07136000 fffff880`071dc000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`0535a000 fffff880`05397000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c8a000 fffff880`00c9e000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`04000000 fffff880`04024000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`041dd000 fffff880`041f8000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`01000000 fffff880`01021000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`01021000 fffff880`0103b000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`0402c000 fffff880`0407d000   rdbss    rdbss.sys    Sat Nov 20 04:27:51 2010 (4CE79497)
fffff880`045f2000 fffff880`045fd000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`03fd2000 fffff880`03fdb000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`03fdb000 fffff880`03fe4000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`03fe4000 fffff880`03fed000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01939000 fffff880`01973000   rdyboost rdyboost.sys Sat Nov 20 04:43:10 2010 (4CE7982E)
fffff880`03abf000 fffff880`03ad7000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04800000 fffff880`0486a000   Rt64win7 Rt64win7.sys Wed Jan 26 08:34:03 2011 (4D4022CB)
fffff880`071dc000 fffff880`071e7000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`045ab000 fffff880`045b7000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`019de000 fffff880`019fb000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`01932000 fffff880`01939000   speedfan speedfan.sys Sun Sep 24 09:26:48 2006 (45168798)
fffff880`0192a000 fffff880`01932000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`08abc000 fffff880`08b54000   srv      srv.sys      Tue Feb 22 23:56:21 2011 (4D649375)
fffff880`08a52000 fffff880`08abc000   srv2     srv2.sys     Tue Feb 22 23:56:00 2011 (4D649360)
fffff880`07000000 fffff880`07031000   srvnet   srvnet.sys   Tue Feb 22 23:55:44 2011 (4D649350)
fffff880`04882000 fffff880`04883480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01680000 fffff880`01884000   tcpip    tcpip.sys    Sat Nov 20 04:25:52 2010 (4CE79420)
fffff880`07031000 fffff880`07043000   tcpipreg tcpipreg.sys Sat Nov 20 05:51:48 2010 (4CE7A844)
fffff880`03e33000 fffff880`03e40000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`03e11000 fffff880`03e33000   tdx      tdx.sys      Sat Nov 20 04:21:54 2010 (4CE79332)
fffff880`01236000 fffff880`0124a000   termdd   termdd.sys   Sat Nov 20 06:03:40 2010 (4CE7AB0C)
fffff960`00410000 fffff960`0041a000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`041a2000 fffff880`041c8000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`07043000 fffff880`0704c000   UltraMonUtility UltraMonUtility.sys Thu Nov 13 20:10:30 2008 (491CD006)
fffff880`05272000 fffff880`05284000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`011e2000 fffff880`011ff000   usbccgp  usbccgp.sys  Sat Nov 20 05:44:03 2010 (4CE7A673)
fffff880`053f5000 fffff880`053f6f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`051ea000 fffff880`051fb000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`05284000 fffff880`052de000   usbhub   usbhub.sys   Sat Nov 20 05:44:30 2010 (4CE7A68E)
fffff880`0486a000 fffff880`04875000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04555000 fffff880`045ab000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`05200000 fffff880`0521b000   USBSTOR  USBSTOR.SYS  Sat Nov 20 05:44:05 2010 (4CE7A675)
fffff880`00e46000 fffff880`00e53000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`03f8f000 fffff880`03f9d000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`03f9d000 fffff880`03fc2000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00c00000 fffff880`00c3c000   vmbus    vmbus.sys    Sat Nov 20 04:57:29 2010 (4CE79B89)
fffff880`018ce000 fffff880`018de000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00e68000 fffff880`00e7d000   volmgr   volmgr.sys   Sat Nov 20 04:19:28 2010 (4CE792A0)
fffff880`00e7d000 fffff880`00ed9000   volmgrx  volmgrx.sys  Sat Nov 20 04:20:43 2010 (4CE792EB)
fffff880`018de000 fffff880`0192a000   volsnap  volsnap.sys  Sat Nov 20 04:20:08 2010 (4CE792C8)
fffff880`01198000 fffff880`011b3000   wanarp   wanarp.sys   Sat Nov 20 05:52:36 2010 (4CE7A874)
fffff880`03fc2000 fffff880`03fd2000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00eef000 fffff880`00f93000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f93000 fffff880`00fa2000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`01666000 fffff880`0166f000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00050000 fffff960`00362000   win32k   win32k.sys   Wed Mar 02 22:51:40 2011 (4D6F104C)
fffff880`00c3c000 fffff880`00c50000   winhv    winhv.sys    Sat Nov 20 04:20:02 2010 (4CE792C2)
fffff880`045b7000 fffff880`045c0000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00e00000 fffff880`00e09000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`03a89000 fffff880`03aaa000   WudfPf   WudfPf.sys   Sat Nov 20 05:42:44 2010 (4CE7A624)
fffff880`08b54000 fffff880`08b85000   WUDFRd   WUDFRd.sys   Sat Nov 20 05:43:32 2010 (4CE7A654)

Unloaded modules:
fffff880`08b85000 fffff880`08bf6000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`01630000 fffff880`0163e000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0163e000 fffff880`0164a000   dump_ataport
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`0164a000 fffff880`01653000   dump_atapi.s
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00009000
fffff880`01653000 fffff880`01666000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
 
Is MSE better than AVAST?

Ultramon and Speedfan appear to be current but I updated them to be sure.

If it is hardware, should I run memtests?

Missing attachments added.
 

Attachments

  • cpu.gif
    cpu.gif
    70 KB · Views: 492
  • RAMMon - SPD Info.zip
    3.1 KB · Views: 390
Memtest? Not yet, not untill you set the memory to its recommended rates and follow my 1st post as well.

~~~~~~~~~

You're currently set at 1333mhz 9 9 9 24. F3-12800CL9-2GBRL is rated 1600mhz 9-9-9-24. Check the manufacturer's site for more details and any special notes such as the voltage sometimes to be set manually.

You can leave it 1333mhz, but since you're having blue screens it is a very good idea to set as manufacturer recommends. Voltage is very important, sometimes you need to set it manually or adjust a little bit ~ +0.05v to give the memory more juice. But again, first of all you should set it exactly as he ram maker recommends.
 
Is MSE better than AVAST?

And what do you think ?

MSE is better for better memory management, unlike Avast MSE does not cause crashes. Since one of your blue screens was caused by Avast, I'd recommend to uninstall it if your blue screens persist:



050611-19094-01.dmp
BugCheck C5, {8, 2, 1, fffff80003006617}
Probably caused by : aswSnx.SYS ( aswSnx+3fb84 )


So follow my posts to uninstall Avast, update drivers, and further if necessary adjust the memory settings in the bios.
 
Thanks for the help and advice.

I followed the suggestions and I was just wondering why one was better. Good to know.

I'll update how this goes.
 
BSODs much less frequent after following the fixes, only 1 crash today.

I've attached the dump file.
 

Attachments

  • 050711-19328-01.rar
    16.8 KB · Views: 345
BSODs much less frequent after following the fixes, only 1 crash today.

I've attached the dump file.


" Less frequent " is still bad. One bsod is enough to have worst experience ever.


RAM again:

050711-19328-01.dmp
ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY (fc)
An attempt was made to execute non-executable memory.
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+45e8c )


Uninstall UltraMon
UltraMonUtility.sys Thu Nov 13 20:10:30 2008


Follow this advice:

You're currently set at 1333mhz 9 9 9 24. F3-12800CL9-2GBRL is rated 1600mhz 9-9-9-24. Check the manufacturer's site for more details and any special notes such as the voltage sometimes to be set manually.
Re-attach CPU-Z MEMORY snip. Again, the voltage must be set right - 1.5v or 1.65v not sure what it is in your case. (See the mnufacturer's web page).



















CRASH DUMPS

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050711-19328-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e05000 PsLoadedModuleList = 0xfffff800`0304ae90
Debug session time: Sat May  7 15:34:02.680 2011 (UTC - 4:00)
System Uptime: 0 days 0:04:52.240
Loading Kernel Symbols
...............................................................
................................................................
..........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck FC, {fffff88009f203d0, 8000000091e0a963, fffff88009f20200, 2}

Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+45e8c )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY (fc)
An attempt was made to execute non-executable memory.  The guilty driver
is on the stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff88009f203d0, Virtual address for the attempted execute.
Arg2: 8000000091e0a963, PTE contents.
Arg3: fffff88009f20200, (reserved)
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xFC

PROCESS_NAME:  League of Lege

CURRENT_IRQL:  0

TRAP_FRAME:  fffff88009f20200 -- (.trap 0xfffff88009f20200)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffff88009f204d0
rdx=fffff88009f20a40 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88009f203d0 rsp=fffff88009f20398 rbp=fffff88009f20b78
 r8=fffff88009f203d0  r9=0000000000010040 r10=000000000010001f
r11=fffff88009f203d0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po nc
fffff880`09f203d0 b8e2080000      mov     eax,8E2h
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002e30f74 to fffff80002e85640

STACK_TEXT:  
fffff880`09f20098 fffff800`02e30f74 : 00000000`000000fc fffff880`09f203d0 80000000`91e0a963 fffff880`09f20200 : nt!KeBugCheckEx
fffff880`09f200a0 fffff800`02e8376e : 00000000`00000008 fffff880`09f203d0 ffffffff`ffb3b400 fffff800`02ec0d5f : nt! ?? ::FNODOBFM::`string'+0x45e8c
fffff880`09f20200 fffff880`09f203d0 : fffff800`02ec0d5f fffff880`09f20b78 fffff880`09f208d0 fffff880`09f20c20 : nt!KiPageFault+0x16e
fffff880`09f20398 fffff800`02ec0d5f : fffff880`09f20b78 fffff880`09f208d0 fffff880`09f20c20 00000000`0018ec88 : 0xfffff880`09f203d0
fffff880`09f203a0 00000000`44ba8890 : 00000000`00000000 00000000`3a77b000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0xd3
fffff880`09f20ce8 00000000`00000000 : 00000000`3a77b000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x44ba8890


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt! ?? ::FNODOBFM::`string'+45e8c
fffff800`02e30f74 cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+45e8c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

FAILURE_BUCKET_ID:  X64_0xFC_nt!_??_::FNODOBFM::_string_+45e8c

BUCKET_ID:  X64_0xFC_nt!_??_::FNODOBFM::_string_+45e8c

Followup: MachineOwner
---------





DRIVERS

Code:
start             end                 module name
fffff880`00edc000 fffff880`00f33000   ACPI     ACPI.sys     Sat Nov 20 04:19:16 2010 (4CE79294)
fffff880`03e51000 fffff880`03eda000   afd      afd.sys      Sat Nov 20 04:23:27 2010 (4CE7938F)
fffff880`043e0000 fffff880`043f6000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`041a4000 fffff880`041b8000   amdiox64 amdiox64.sys Thu Feb 18 10:17:53 2010 (4B7D5A21)
fffff880`04362000 fffff880`04377000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`010b8000 fffff880`010c3000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`073b0000 fffff880`073bb000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00ff5000 fffff880`00ffe000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`0108e000 fffff880`010b8000   ataport  ataport.SYS  Sat Nov 20 04:19:15 2010 (4CE79293)
fffff880`0407a000 fffff880`0409a000   AtihdW76 AtihdW76.sys Mon Aug 16 06:41:02 2010 (4C6915BE)
fffff880`04861000 fffff880`05098000   atikmdag atikmdag.sys Tue Jan 04 21:48:52 2011 (4D23DC14)
fffff880`04377000 fffff880`043c4000   atikmpag atikmpag.sys Tue Jan 04 21:19:38 2011 (4D23D53A)
fffff960`008d0000 fffff960`00931000   ATMFD    ATMFD.DLL    Sat Feb 19 04:00:32 2011 (4D5F86B0)
fffff880`019ea000 fffff880`019f1000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`0432b000 fffff880`0433c000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`0552c000 fffff880`0554a000   bowser   bowser.sys   Tue Feb 22 23:55:04 2011 (4D649328)
fffff960`00760000 fffff960`00787000   cdd      cdd.dll      Sat Nov 20 07:55:34 2010 (4CE7C546)
fffff880`0142b000 fffff880`01455000   cdrom    cdrom.sys    Sat Nov 20 04:19:20 2010 (4CE79298)
fffff880`00ccf000 fffff880`00d8f000   CI       CI.dll       Sat Nov 20 08:12:36 2010 (4CE7C944)
fffff880`0197b000 fffff880`019ab000   CLASSPNP CLASSPNP.SYS Sat Nov 20 04:19:23 2010 (4CE7929B)
fffff880`00c71000 fffff880`00ccf000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01181000 fffff880`011f3000   cng      cng.sys      Sat Nov 20 05:08:45 2010 (4CE79E2D)
fffff880`043d0000 fffff880`043e0000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`06477000 fffff880`06485000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`0428a000 fffff880`0430d000   csc      csc.sys      Sat Nov 20 04:27:12 2010 (4CE79470)
fffff880`0430d000 fffff880`0432b000   dfsc     dfsc.sys     Sat Nov 20 04:26:31 2010 (4CE79447)
fffff880`03e17000 fffff880`03e26000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01965000 fffff880`0197b000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`040d7000 fffff880`040f9000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`06491000 fffff880`0649a000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06485000 fffff880`06491000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`0649a000 fffff880`064ad000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`06532000 fffff880`0653e000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`05098000 fffff880`0518c000   dxgkrnl  dxgkrnl.sys  Sat Nov 20 04:50:50 2010 (4CE799FA)
fffff880`0518c000 fffff880`051d2000   dxgmms1  dxgmms1.sys  Sat Nov 20 04:49:53 2010 (4CE799C1)
fffff880`065bd000 fffff880`065f3000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`0427b000 fffff880`04288000   fdc      fdc.sys      Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`0110f000 fffff880`01123000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`0405a000 fffff880`04065000   flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`010c3000 fffff880`0110f000   fltmgr   fltmgr.sys   Sat Nov 20 04:19:24 2010 (4CE7929C)
fffff880`01211000 fffff880`0121b000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`0192b000 fffff880`01965000   fvevol   fvevol.sys   Sat Nov 20 04:24:06 2010 (4CE793B6)
fffff880`0181e000 fffff880`01868000   fwpkclnt fwpkclnt.sys Sat Nov 20 04:21:37 2010 (4CE79321)
fffff800`033ef000 fffff800`03438000   hal      hal.dll      Sat Nov 20 08:00:25 2010 (4CE7C669)
fffff880`051d2000 fffff880`051f6000   HDAudBus HDAudBus.sys Sat Nov 20 05:43:42 2010 (4CE7A65E)
fffff880`0641b000 fffff880`06477000   HdAudio  HdAudio.sys  Sat Nov 20 05:44:23 2010 (4CE7A687)
fffff880`064d8000 fffff880`064f1000   HIDCLASS HIDCLASS.SYS Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`064f1000 fffff880`064f9080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`064ca000 fffff880`064d8000   hidusb   hidusb.sys   Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`05463000 fffff880`0552c000   HTTP     HTTP.sys     Sat Nov 20 04:24:30 2010 (4CE793CE)
fffff880`01922000 fffff880`0192b000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`04141000 fffff880`04150000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06524000 fffff880`06532000   kbdhid   kbdhid.sys   Sat Nov 20 05:33:25 2010 (4CE7A3F5)
fffff800`00bbd000 fffff800`00bc7000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`04161000 fffff880`041a4000   ks       ks.sys       Sat Nov 20 05:33:23 2010 (4CE7A3F3)
fffff880`013e0000 fffff880`013fb000   ksecdd   ksecdd.sys   Sat Nov 20 04:21:15 2010 (4CE7930B)
fffff880`01400000 fffff880`0142b000   ksecpkg  ksecpkg.sys  Sat Nov 20 05:10:34 2010 (4CE79E9A)
fffff880`041ca000 fffff880`041cf200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`06590000 fffff880`065a5000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0654c000 fffff880`0656f000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c50000 fffff880`00c5d000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`0653e000 fffff880`0654c000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`04150000 fffff880`0415f000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`064fa000 fffff880`06507000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00fc7000 fffff880`00fe1000   mountmgr mountmgr.sys Sat Nov 20 04:19:21 2010 (4CE79299)
fffff880`01455000 fffff880`01486000   MpFilter MpFilter.sys Tue Sep 14 20:19:28 2010 (4C901110)
fffff880`0554a000 fffff880`05562000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`05562000 fffff880`0558f000   mrxsmb   mrxsmb.sys   Tue Feb 22 23:56:22 2011 (4D649376)
fffff880`0558f000 fffff880`055dc000   mrxsmb10 mrxsmb10.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`055dc000 fffff880`05600000   mrxsmb20 mrxsmb20.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`015ef000 fffff880`015fa000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f3c000 fffff880`00f46000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01123000 fffff880`01181000   msrpc    msrpc.sys    Sat Nov 20 04:21:56 2010 (4CE79334)
fffff880`03e0c000 fffff880`03e17000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`01910000 fffff880`01922000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01493000 fffff880`01586000   ndis     ndis.sys     Sat Nov 20 04:23:30 2010 (4CE79392)
fffff880`01047000 fffff880`01053000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`01053000 fffff880`01082000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`04065000 fffff880`0407a000   NDProxy  NDProxy.SYS  Sat Nov 20 05:52:20 2010 (4CE7A864)
fffff880`03f4e000 fffff880`03f5d000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`03eda000 fffff880`03f1f000   netbt    netbt.sys    Sat Nov 20 04:23:18 2010 (4CE79386)
fffff880`01586000 fffff880`015e6000   NETIO    NETIO.SYS    Sat Nov 20 04:23:13 2010 (4CE79381)
fffff880`072f9000 fffff880`0730e000   NisDrvWFP NisDrvWFP.sys Tue Sep 14 20:20:25 2010 (4C901149)
fffff880`0121b000 fffff880`0122c000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03e00000 fffff880`03e0c000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e05000 fffff800`033ef000   nt       ntkrnlmp.exe Sat Nov 20 04:30:02 2010 (4CE7951A)
fffff880`0123d000 fffff880`013e0000   Ntfs     Ntfs.sys     Sat Nov 20 04:20:57 2010 (4CE792F9)
fffff880`019e1000 fffff880`019ea000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`03f28000 fffff880`03f4e000   pacer    pacer.sys    Sat Nov 20 05:52:18 2010 (4CE7A862)
fffff880`00f86000 fffff880`00f9b000   partmgr  partmgr.sys  Sat Nov 20 04:20:00 2010 (4CE792C0)
fffff880`00f46000 fffff880`00f79000   pci      pci.sys      Sat Nov 20 04:19:11 2010 (4CE7928F)
fffff880`00fb0000 fffff880`00fb7000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00fb7000 fffff880`00fc7000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01200000 fffff880`01211000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0708a000 fffff880`07130000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`0409a000 fffff880`040d7000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c5d000 fffff880`00c71000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`03e26000 fffff880`03e4a000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`00e00000 fffff880`00e1b000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`040fb000 fffff880`0411c000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`0411c000 fffff880`04136000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03fa9000 fffff880`03ffa000   rdbss    rdbss.sys    Sat Nov 20 04:27:51 2010 (4CE79497)
fffff880`04136000 fffff880`04141000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`01610000 fffff880`01619000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01486000 fffff880`0148f000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`015e6000 fffff880`015ef000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`018d6000 fffff880`01910000   rdyboost rdyboost.sys Sat Nov 20 04:43:10 2010 (4CE7982E)
fffff880`065a5000 fffff880`065bd000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04200000 fffff880`0426a000   Rt64win7 Rt64win7.sys Wed Jan 26 08:34:03 2011 (4D4022CB)
fffff880`07130000 fffff880`0713b000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`043c4000 fffff880`043d0000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03f5d000 fffff880`03f7a000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`018cc000 fffff880`018d6000   speedfan speedfan.sys Sat Dec 18 06:03:51 2010 (4D0C9517)
fffff880`018c4000 fffff880`018cc000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0733f000 fffff880`073b0000   spsys    spsys.sys    Mon May 11 13:20:58 2009 (4A085E7A)
fffff880`07261000 fffff880`072f9000   srv      srv.sys      Tue Feb 22 23:56:21 2011 (4D649375)
fffff880`07187000 fffff880`071f1000   srv2     srv2.sys     Tue Feb 22 23:56:00 2011 (4D649360)
fffff880`0713b000 fffff880`0716c000   srvnet   srvnet.sys   Tue Feb 22 23:55:44 2011 (4D649350)
fffff880`0415f000 fffff880`04160480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`0161a000 fffff880`0181e000   tcpip    tcpip.sys    Sat Nov 20 04:25:52 2010 (4CE79420)
fffff880`0716c000 fffff880`0717e000   tcpipreg tcpipreg.sys Sat Nov 20 05:51:48 2010 (4CE7A844)
fffff880`0122c000 fffff880`01239000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`01025000 fffff880`01047000   tdx      tdx.sys      Sat Nov 20 04:21:54 2010 (4CE79332)
fffff880`03f95000 fffff880`03fa9000   termdd   termdd.sys   Sat Nov 20 06:03:40 2010 (4CE7AB0C)
fffff960`00450000 fffff960`0045a000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`0433c000 fffff880`04362000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`0717e000 fffff880`07187000   UltraMonUtility UltraMonUtility.sys Thu Nov 13 20:10:30 2008 (491CD006)
fffff880`041b8000 fffff880`041ca000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06507000 fffff880`06524000   usbccgp  usbccgp.sys  Sat Nov 20 05:44:03 2010 (4CE7A673)
fffff880`064c8000 fffff880`064c9f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`0426a000 fffff880`0427b000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04000000 fffff880`0405a000   usbhub   usbhub.sys   Sat Nov 20 05:44:30 2010 (4CE7A68E)
fffff880`04800000 fffff880`0480b000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0480b000 fffff880`04861000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`064ad000 fffff880`064c8000   USBSTOR  USBSTOR.SYS  Sat Nov 20 05:44:05 2010 (4CE7A675)
fffff880`00f79000 fffff880`00f86000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`019f1000 fffff880`019ff000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`01000000 fffff880`01025000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00c00000 fffff880`00c3c000   vmbus    vmbus.sys    Sat Nov 20 04:57:29 2010 (4CE79B89)
fffff880`01868000 fffff880`01878000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00f9b000 fffff880`00fb0000   volmgr   volmgr.sys   Sat Nov 20 04:19:28 2010 (4CE792A0)
fffff880`00d8f000 fffff880`00deb000   volmgrx  volmgrx.sys  Sat Nov 20 04:20:43 2010 (4CE792EB)
fffff880`01878000 fffff880`018c4000   volsnap  volsnap.sys  Sat Nov 20 04:20:08 2010 (4CE792C8)
fffff880`03f7a000 fffff880`03f95000   wanarp   wanarp.sys   Sat Nov 20 05:52:36 2010 (4CE7A874)
fffff880`01600000 fffff880`01610000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e29000 fffff880`00ecd000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00ecd000 fffff880`00edc000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`03f1f000 fffff880`03f28000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00080000 fffff960`00392000   win32k   win32k.sys   Wed Mar 02 22:51:40 2011 (4D6F104C)
fffff880`00fe1000 fffff880`00ff5000   winhv    winhv.sys    Sat Nov 20 04:20:02 2010 (4CE792C2)
fffff880`051f6000 fffff880`051ff000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f33000 fffff880`00f3c000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`0656f000 fffff880`06590000   WudfPf   WudfPf.sys   Sat Nov 20 05:42:44 2010 (4CE7A624)
fffff880`0730e000 fffff880`0733f000   WUDFRd   WUDFRd.sys   Sat Nov 20 05:43:32 2010 (4CE7A654)

Unloaded modules:
fffff880`019ab000 fffff880`019b9000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`019b9000 fffff880`019c5000   dump_ataport
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`019c5000 fffff880`019ce000   dump_atapi.s
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00009000
fffff880`019ce000 fffff880`019e1000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
 
[langtitle=id]Re: BSODs after system restore[/langtitle]

In the bios, usu. Advanced DRAM Configuration.
 
Re: [langtitle=id]Re: BSODs after system restore[/langtitle]

The RAM voltage settings I could find were:

Memory Over Voltage - 1.6V
HT Over Voltage - 1.2V

The sticks are rated for 1.5V, so what should I change?

These BIOS configurations are confusing me. I have very little experience with BIOS.

Also, I've been experiencing very slow startup times randomly.

Update: BSOD today and then computer appears to freeze on startup twice in a row. Restarted again and BSOD at the login screen to Windows 7. I must have did something wrong in the BIOS because the only way to startup properly was to set BIOS back to all the defaults (actually, maybe that didn't help but appeared to). I had only changed the RAM speeds and didn't touch the voltages yet. I can only find 1 dump file after 2 BSODs.

Update 2: I just crashed twice in a row where the computer freezes real fast and then immediately restarts. Did not give a BSOD. This has happened a few times this week but I didn't realize what was happening before.
 

Attachments

  • 050811-18096-01.rar
    18.2 KB · Views: 313
Last edited:
Re: [langtitle=id]Re: BSODs after system restore[/langtitle]

I think I have all the RAM settings proper now. I've been running so far with no errors since then.
 
Ok, good to hear. Inded whenever it comes to memory erors the very first thing to do is to check settings. The latest crash was memory again:


CRASH DUMPS

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050811-18096-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e5b000 PsLoadedModuleList = 0xfffff800`030a0e90
Debug session time: Sun May  8 17:39:22.371 2011 (UTC - 4:00)
System Uptime: 0 days 2:13:08.542
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {5003, fffff70001080000, c1a4, bf3100018308}

Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+398d6 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000005003, The subtype of the bugcheck.
Arg2: fffff70001080000
Arg3: 000000000000c1a4
Arg4: 0000bf3100018308

Debugging Details:
------------------


BUGCHECK_STR:  0x1a_5003

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  MsMpEng.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff80002f4c436 to fffff80002edb640

STACK_TEXT:  
fffff880`06edb9a8 fffff800`02f4c436 : 00000000`0000001a 00000000`00005003 fffff700`01080000 00000000`0000c1a4 : nt!KeBugCheckEx
fffff880`06edb9b0 fffff800`02ee8979 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x398d6
fffff880`06edbac0 fffff800`02ed976e : 00000000`00000000 00000000`106d0000 fffffa80`03a89301 00000000`0462d910 : nt!MmAccessFault+0x359
fffff880`06edbc20 000007fe`fd7f5969 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`0462d388 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd7f5969


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt! ?? ::FNODOBFM::`string'+398d6
fffff800`02f4c436 cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+398d6

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

FAILURE_BUCKET_ID:  X64_0x1a_5003_nt!_??_::FNODOBFM::_string_+398d6

BUCKET_ID:  X64_0x1a_5003_nt!_??_::FNODOBFM::_string_+398d6

Followup: MachineOwner
---------





DRIVERS

Code:
start             end                 module name
fffff880`00f00000 fffff880`00f57000   ACPI     ACPI.sys     Sat Nov 20 04:19:16 2010 (4CE79294)
fffff880`02c9e000 fffff880`02d27000   afd      afd.sys      Sat Nov 20 04:23:27 2010 (4CE7938F)
fffff880`04308000 fffff880`0431e000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`04243000 fffff880`04257000   amdiox64 amdiox64.sys Thu Feb 18 10:17:53 2010 (4B7D5A21)
fffff880`040f9000 fffff880`0410e000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`01127000 fffff880`01132000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`06c71000 fffff880`06c7c000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00e2e000 fffff880`00e37000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`010fd000 fffff880`01127000   ataport  ataport.SYS  Sat Nov 20 04:19:15 2010 (4CE79293)
fffff880`05b3c000 fffff880`05b5c000   AtihdW76 AtihdW76.sys Mon Aug 16 06:41:02 2010 (4C6915BE)
fffff880`0486d000 fffff880`050a4000   atikmdag atikmdag.sys Tue Jan 04 21:48:52 2011 (4D23DC14)
fffff880`0410e000 fffff880`0415b000   atikmpag atikmpag.sys Tue Jan 04 21:19:38 2011 (4D23D53A)
fffff960`00970000 fffff960`009d1000   ATMFD    ATMFD.DLL    Sat Feb 19 04:00:32 2011 (4D5F86B0)
fffff880`0161c000 fffff880`01623000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`040c2000 fffff880`040d3000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`05572000 fffff880`05590000   bowser   bowser.sys   Tue Feb 22 23:55:04 2011 (4D649328)
fffff960`00650000 fffff960`00677000   cdd      cdd.dll      unavailable (00000000)
fffff880`015d4000 fffff880`015fe000   cdrom    cdrom.sys    Sat Nov 20 04:19:20 2010 (4CE79298)
fffff880`00cd3000 fffff880`00d93000   CI       CI.dll       Sat Nov 20 08:12:36 2010 (4CE7C944)
fffff880`0199b000 fffff880`019cb000   CLASSPNP CLASSPNP.SYS Sat Nov 20 04:19:23 2010 (4CE7929B)
fffff880`00c75000 fffff880`00cd3000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01000000 fffff880`01072000   cng      cng.sys      Sat Nov 20 05:08:45 2010 (4CE79E2D)
fffff880`042f8000 fffff880`04308000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`05a5c000 fffff880`05a6a000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`04021000 fffff880`040a4000   csc      csc.sys      Sat Nov 20 04:27:12 2010 (4CE79470)
fffff880`040a4000 fffff880`040c2000   dfsc     dfsc.sys     Sat Nov 20 04:26:31 2010 (4CE79447)
fffff880`02c68000 fffff880`02c77000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01985000 fffff880`0199b000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`05b99000 fffff880`05bbb000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`05a76000 fffff880`05a7f000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05a6a000 fffff880`05a76000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05a7f000 fffff880`05a92000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05a92000 fffff880`05a9e000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`050a4000 fffff880`05198000   dxgkrnl  dxgkrnl.sys  Sat Nov 20 04:50:50 2010 (4CE799FA)
fffff880`05198000 fffff880`051de000   dxgmms1  dxgmms1.sys  Sat Nov 20 04:49:53 2010 (4CE799C1)
fffff880`010b2000 fffff880`010e8000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`042d6000 fffff880`042e3000   fdc      fdc.sys      Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`0117e000 fffff880`01192000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`05b1c000 fffff880`05b27000   flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`01132000 fffff880`0117e000   fltmgr   fltmgr.sys   Sat Nov 20 04:19:24 2010 (4CE7929C)
fffff880`01211000 fffff880`0121b000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`0194b000 fffff880`01985000   fvevol   fvevol.sys   Sat Nov 20 04:24:06 2010 (4CE793B6)
fffff880`0183e000 fffff880`01888000   fwpkclnt fwpkclnt.sys Sat Nov 20 04:21:37 2010 (4CE79321)
fffff800`02e12000 fffff800`02e5b000   hal      hal.dll      Sat Nov 20 08:00:25 2010 (4CE7C669)
fffff880`04800000 fffff880`04824000   HDAudBus HDAudBus.sys Sat Nov 20 05:43:42 2010 (4CE7A65E)
fffff880`05a00000 fffff880`05a5c000   HdAudio  HdAudio.sys  Sat Nov 20 05:44:23 2010 (4CE7A687)
fffff880`05bcf000 fffff880`05be8000   HIDCLASS HIDCLASS.SYS Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`05be8000 fffff880`05bf0080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`05bc1000 fffff880`05bcf000   hidusb   hidusb.sys   Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`054a9000 fffff880`05572000   HTTP     HTTP.sys     Sat Nov 20 04:24:30 2010 (4CE793CE)
fffff880`01942000 fffff880`0194b000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`043de000 fffff880`043ed000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`0484c000 fffff880`0485a000   kbdhid   kbdhid.sys   Sat Nov 20 05:33:25 2010 (4CE7A3F5)
fffff800`00ba9000 fffff800`00bb3000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`04200000 fffff880`04243000   ks       ks.sys       Sat Nov 20 05:33:23 2010 (4CE7A3F3)
fffff880`013e0000 fffff880`013fb000   ksecdd   ksecdd.sys   Sat Nov 20 04:21:15 2010 (4CE7930B)
fffff880`015a9000 fffff880`015d4000   ksecpkg  ksecpkg.sys  Sat Nov 20 05:10:34 2010 (4CE79E9A)
fffff880`05bbb000 fffff880`05bc0200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`041e8000 fffff880`041fd000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`041c5000 fffff880`041e8000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c54000 fffff880`00c61000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`0485a000 fffff880`04868000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`043ed000 fffff880`043fc000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`05bf1000 fffff880`05bfe000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00e00000 fffff880`00e1a000   mountmgr mountmgr.sys Sat Nov 20 04:19:21 2010 (4CE79299)
fffff880`01400000 fffff880`01431000   MpFilter MpFilter.sys Tue Sep 14 20:19:28 2010 (4C901110)
fffff880`05590000 fffff880`055a8000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`055a8000 fffff880`055d5000   mrxsmb   mrxsmb.sys   Tue Feb 22 23:56:22 2011 (4D649376)
fffff880`05400000 fffff880`0544d000   mrxsmb10 mrxsmb10.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`0544d000 fffff880`05471000   mrxsmb20 mrxsmb20.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`0122d000 fffff880`01238000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f60000 fffff880`00f6a000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01192000 fffff880`011f0000   msrpc    msrpc.sys    Sat Nov 20 04:21:56 2010 (4CE79334)
fffff880`02c5d000 fffff880`02c68000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`01930000 fffff880`01942000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01456000 fffff880`01549000   ndis     ndis.sys     Sat Nov 20 04:23:30 2010 (4CE79392)
fffff880`04342000 fffff880`0434e000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`0434e000 fffff880`0437d000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`05b27000 fffff880`05b3c000   NDProxy  NDProxy.SYS  Sat Nov 20 05:52:20 2010 (4CE7A864)
fffff880`02d9b000 fffff880`02daa000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02d27000 fffff880`02d6c000   netbt    netbt.sys    Sat Nov 20 04:23:18 2010 (4CE79386)
fffff880`01549000 fffff880`015a9000   NETIO    NETIO.SYS    Sat Nov 20 04:23:13 2010 (4CE79381)
fffff880`06d83000 fffff880`06d98000   NisDrvWFP NisDrvWFP.sys Tue Sep 14 20:20:25 2010 (4C901149)
fffff880`01072000 fffff880`01083000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02c51000 fffff880`02c5d000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e5b000 fffff800`03445000   nt       ntkrnlmp.exe Sat Nov 20 04:30:02 2010 (4CE7951A)
fffff880`0123d000 fffff880`013e0000   Ntfs     Ntfs.sys     Sat Nov 20 04:20:57 2010 (4CE792F9)
fffff880`01613000 fffff880`0161c000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`02d75000 fffff880`02d9b000   pacer    pacer.sys    Sat Nov 20 05:52:18 2010 (4CE7A862)
fffff880`00faa000 fffff880`00fbf000   partmgr  partmgr.sys  Sat Nov 20 04:20:00 2010 (4CE792C0)
fffff880`00f6a000 fffff880`00f9d000   pci      pci.sys      Sat Nov 20 04:19:11 2010 (4CE7928F)
fffff880`00fd4000 fffff880`00fdb000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00fdb000 fffff880`00feb000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01200000 fffff880`01211000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`06a84000 fffff880`06b2a000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`05b5c000 fffff880`05b99000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c61000 fffff880`00c75000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`0431e000 fffff880`04342000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`0437d000 fffff880`04398000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`04398000 fffff880`043b9000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`043b9000 fffff880`043d3000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02c00000 fffff880`02c51000   rdbss    rdbss.sys    Sat Nov 20 04:27:51 2010 (4CE79497)
fffff880`043d3000 fffff880`043de000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`01631000 fffff880`0163a000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`0121b000 fffff880`01224000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01224000 fffff880`0122d000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`018f6000 fffff880`01930000   rdyboost rdyboost.sys Sat Nov 20 04:43:10 2010 (4CE7982E)
fffff880`04000000 fffff880`04018000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0415b000 fffff880`041c5000   Rt64win7 Rt64win7.sys Wed Jan 26 08:34:03 2011 (4D4022CB)
fffff880`06b2a000 fffff880`06b35000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`042e3000 fffff880`042ef000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`02daa000 fffff880`02dc7000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`018ec000 fffff880`018f6000   speedfan speedfan.sys Sat Dec 18 06:03:51 2010 (4D0C9517)
fffff880`018e4000 fffff880`018ec000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`06ceb000 fffff880`06d83000   srv      srv.sys      Tue Feb 22 23:56:21 2011 (4D649375)
fffff880`06b78000 fffff880`06be2000   srv2     srv2.sys     Tue Feb 22 23:56:00 2011 (4D649360)
fffff880`06b35000 fffff880`06b66000   srvnet   srvnet.sys   Tue Feb 22 23:55:44 2011 (4D649350)
fffff880`043fc000 fffff880`043fd480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`0163a000 fffff880`0183e000   tcpip    tcpip.sys    Sat Nov 20 04:25:52 2010 (4CE79420)
fffff880`06b66000 fffff880`06b78000   tcpipreg tcpipreg.sys Sat Nov 20 05:51:48 2010 (4CE7A844)
fffff880`010a5000 fffff880`010b2000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`01083000 fffff880`010a5000   tdx      tdx.sys      Sat Nov 20 04:21:54 2010 (4CE79332)
fffff880`02de2000 fffff880`02df6000   termdd   termdd.sys   Sat Nov 20 06:03:40 2010 (4CE7AB0C)
fffff960`005d0000 fffff960`005da000   TSDDD    TSDDD.dll    Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`040d3000 fffff880`040f9000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`04257000 fffff880`04269000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`0482f000 fffff880`0484c000   usbccgp  usbccgp.sys  Sat Nov 20 05:44:03 2010 (4CE7A673)
fffff880`05ab9000 fffff880`05abaf00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`042c5000 fffff880`042d6000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`05ac2000 fffff880`05b1c000   usbhub   usbhub.sys   Sat Nov 20 05:44:30 2010 (4CE7A68E)
fffff880`04824000 fffff880`0482f000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0426f000 fffff880`042c5000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`05a9e000 fffff880`05ab9000   USBSTOR  USBSTOR.SYS  Sat Nov 20 05:44:05 2010 (4CE7A675)
fffff880`00f9d000 fffff880`00faa000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01623000 fffff880`01631000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`01431000 fffff880`01456000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00c00000 fffff880`00c3c000   vmbus    vmbus.sys    Sat Nov 20 04:57:29 2010 (4CE79B89)
fffff880`01888000 fffff880`01898000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00fbf000 fffff880`00fd4000   volmgr   volmgr.sys   Sat Nov 20 04:19:28 2010 (4CE792A0)
fffff880`00d93000 fffff880`00def000   volmgrx  volmgrx.sys  Sat Nov 20 04:20:43 2010 (4CE792EB)
fffff880`01898000 fffff880`018e4000   volsnap  volsnap.sys  Sat Nov 20 04:20:08 2010 (4CE792C8)
fffff880`02dc7000 fffff880`02de2000   wanarp   wanarp.sys   Sat Nov 20 05:52:36 2010 (4CE7A874)
fffff880`019ee000 fffff880`019fe000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e4d000 fffff880`00ef1000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00ef1000 fffff880`00f00000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02d6c000 fffff880`02d75000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00000000 fffff960`00312000   win32k   win32k.sys   Wed Mar 02 22:51:40 2011 (4D6F104C)
fffff880`00e1a000 fffff880`00e2e000   winhv    winhv.sys    Sat Nov 20 04:20:02 2010 (4CE792C2)
fffff880`042ef000 fffff880`042f8000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f57000 fffff880`00f60000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`051de000 fffff880`051ff000   WudfPf   WudfPf.sys   Sat Nov 20 05:42:44 2010 (4CE7A624)
fffff880`06d98000 fffff880`06dc9000   WUDFRd   WUDFRd.sys   Sat Nov 20 05:43:32 2010 (4CE7A654)

Unloaded modules:
fffff880`06c00000 fffff880`06c71000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`019cb000 fffff880`019d9000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`019d9000 fffff880`019e5000   dump_ataport
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`019e5000 fffff880`019ee000   dump_atapi.s
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00009000
fffff880`01600000 fffff880`01613000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
 
Today I blue screened and afterward it took a long time to reboot. Once Windows loaded BSOD again. I think it also BSOD at the login page too.

Once I restarted it failed to load windows. Gave the options of start windows normally or start system repair. Windows wouldn't start normally so I ran system repair. I'm pretty sure I got a BSOD when repairing. So I restarted and ran system repair again.

Then it said a disk had to be checked, file system NTFS. It looked like the chkdsk /f command I already did. When I ran that command before, once the disk checker finished I didn't know what it did or I never saw a report. I still don't know if the disk checker found anything wrong because once it is done, it just reboots. After it ran, Windows finally booted up.

After 4-5 BSODs I could only find 2 dump files. I think these are the 2 BSOD I got from the desktop and the others weren't in the dump files because they happened on startup.

One of the BSOD reports not shown that I remember stated: SYSTEM_SERVICE_EXCEPTION.


At one point I also got an error on startup that said: ERROR ... ... DRAM frequency reset to lower frequency.
Or something... can't quite remember.
Does my RAM default to lower than manufacturer settings because they have to run in accordance with the CPU? If I'm adjusting RAM settings, wouldn't it also be necessary to modfiy CPU settings? Also, why would adjusting these settings fix my problems after I've run on default settings for close to a year with no problems?


Lots of errors and events to remember, I might have got the story wrong somewhere.
At one point I was typing this on another computer because windows wouldn't load and system repair wouldn't work either.

Edit: another BSOD, attached
 

Attachments

  • Minidump.rar
    40.7 KB · Views: 347
  • 050911-27284-01.rar
    20.4 KB · Views: 338
Last edited:
Then it said a disk had to be checked, file system NTFS. It looked like the chkdsk /f command I already did. When I ran that command before, once the disk checker finished I didn't know what it did or I never saw a report.


Run HDD diagnostics:

bootable -- Link Removed - Invalid URL

windows -- HDDScan PassMark DiskCheckup - SMART hard drive monitoring utility


At one point I also got an error on startup that said: ERROR ... ... DRAM frequency reset to lower frequency.
Or something... can't quite remember.
Does my RAM default to lower than manufacturer settings because they have to run in accordance with the CPU? If I'm adjusting RAM settings, wouldn't it also be necessary to modfiy CPU settings? Also, why would adjusting these settings fix my problems after I've run on default settings for close to a year with no problems?

Does my RAM default to lower than manufacturer settings because they have to run in accordance with the CPU? If I'm adjusting RAM settings, wouldn't it also be necessary to modfiy CPU settings?

- No, whatever they are, RAM settings do not default on their own, unless some special bios feature doing it. Such as ASUS CrashFree BIOS, for example.



- Also, why would adjusting these settings fix my problems after I've run on default settings for close to a year with no problems?

Hardware can work even at overclocked rates for long, a well known fact, but if you are having blue screens it is a very good idea to set hardware at its stock recommended settings.

If you load bios defaults and then ensure memory is up to its recommended rates (as stipulated by the manufacturer), you should be right. But if you keep getting crashes despite all, diagnose your hardware and once you find the guilty part, replace it.


Memory - 10 passes Memtest86+ - Advanced Memory Diagnostic Tool

HDD - Link Removed - Invalid URL
HDDScan
PassMark DiskCheckup - SMART hard drive monitoring utility



CRASH DUMPS

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050911-23056-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e51000 PsLoadedModuleList = 0xfffff800`03096e90
Debug session time: Mon May  9 23:21:47.460 2011 (UTC - 4:00)
System Uptime: 0 days 10:14:10.005
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {ffffffffc0000005, fffff80002ea7308, fffff880031a7fc8, fffff880031a7820}

Probably caused by : cng.sys ( cng!GatherRandomKey+294 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003.  This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG.  This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG.  This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002ea7308, The address that the exception occurred at
Arg3: fffff880031a7fc8, Exception Record Address
Arg4: fffff880031a7820, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
nt!ExpGetLookasideInformation+8c
fffff800`02ea7308 0fb742c0        movzx   eax,word ptr [rdx-40h]

EXCEPTION_RECORD:  fffff880031a7fc8 -- (.exr 0xfffff880031a7fc8)
Cannot read Exception record @ fffff880031a7fc8

CONTEXT:  fffff880031a7820 -- (.cxr 0xfffff880031a7820)
rax=00000000fffff880 rbx=0000000000000ff4 rcx=fffff8800b73dc50
rdx=00000023da180005 rsi=0000000000000000 rdi=0000000000000001
rip=fffff80002ea7308 rsp=fffff880031a8200 rbp=0000000000000057
 r8=fffff8000306e780  r9=0000000000000000 r10=0000000000000000
r11=0000fffffffff000 r12=fffff880031a82d0 r13=000000000001fe90
r14=fffff880031a8840 r15=0000000000000000
iopl=0         nv up ei pl nz na pe cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010203
nt!ExpGetLookasideInformation+0x8c:
fffff800`02ea7308 0fb742c0        movzx   eax,word ptr [rdx-40h] ds:002b:00000023`da17ffc5=????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  System

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  00000023da17ffc5

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800031020e8
 00000023da17ffc5 

FOLLOWUP_IP: 
cng!GatherRandomKey+294
fffff880`01191ef4 85c0            test    eax,eax

BUGCHECK_STR:  0x7E

LAST_CONTROL_TRANSFER:  from fffff800031db528 to fffff80002ea7308

STACK_TEXT:  
fffff880`031a8200 fffff800`031db528 : 00000000`00000000 00000000`00000ff4 fffff880`031a82d0 00000000`00000000 : nt!ExpGetLookasideInformation+0x8c
fffff880`031a8290 fffff800`031db949 : fffff8a0`0f200170 00000000`00000000 00000000`00000004 00000000`00000000 : nt!ExpQuerySystemInformation+0x15e8
fffff880`031a8640 fffff800`02ed08d3 : fffff8a0`0f210000 00000000`00000000 00000000`00000041 00000000`00000000 : nt!NtQuerySystemInformation+0x4d
fffff880`031a8680 fffff800`02ecce70 : fffff880`01191ef4 00000000`00020000 fffff880`031a8844 fffff8a0`0f200148 : nt!KiSystemServiceCopyEnd+0x13
fffff880`031a8818 fffff880`01191ef4 : 00000000`00020000 fffff880`031a8844 fffff8a0`0f200148 00000000`00000000 : nt!KiServiceLinkage
fffff880`031a8820 fffff880`011923ed : fffffa80`03af38c0 fffff800`02ed99f3 fffffa80`20206f49 0000000e`00000028 : cng!GatherRandomKey+0x294
fffff880`031a8be0 fffff800`031c7f4d : 00000000`00000001 00000000`00000001 fffffa80`06318470 fffffa80`039e7040 : cng!scavengingWorkItemRoutine+0x3d
fffff880`031a8c80 fffff800`02edba21 : fffff800`0306e600 fffff800`031c7f01 fffffa80`039e7000 fffff800`0306e658 : nt!IopProcessWorkItem+0x3d
fffff880`031a8cb0 fffff800`0316ecce : 00000000`00000000 fffffa80`039e7040 00000000`00000080 fffffa80`039d5040 : nt!ExpWorkerThread+0x111
fffff880`031a8d40 fffff800`02ec2fe6 : fffff880`02f63180 fffffa80`039e7040 fffff880`02f6dfc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`031a8d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX:  5

SYMBOL_NAME:  cng!GatherRandomKey+294

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: cng

IMAGE_NAME:  cng.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce79e2d

STACK_COMMAND:  .cxr 0xfffff880031a7820 ; kb

FAILURE_BUCKET_ID:  X64_0x7E_cng!GatherRandomKey+294

BUCKET_ID:  X64_0x7E_cng!GatherRandomKey+294

Followup: MachineOwner
---------




Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\050911-27284-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e13000 PsLoadedModuleList = 0xfffff800`03058e90
Debug session time: Mon May  9 23:51:01.268 2011 (UTC - 4:00)
System Uptime: 0 days 0:12:09.813
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {ffffea8003d61b68, 2, 0, fffff80002e73828}

Probably caused by : ntkrnlmp.exe ( nt!KeTerminateThread+314 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffea8003d61b68, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002e73828, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030c40e8
 ffffea8003d61b68 

CURRENT_IRQL:  2

FAULTING_IP: 
nt!KeTerminateThread+314
fffff800`02e73828 488b6d00        mov     rbp,qword ptr [rbp]

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xA

PROCESS_NAME:  plugin-contain

TRAP_FRAME:  fffff8800296a720 -- (.trap 0xfffff8800296a720)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8003c95848
rdx=ffffea8003d61b68 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002e73828 rsp=fffff8800296a8b0 rbp=ffffea8003d61b68
 r8=0000000000000041  r9=0000000000000000 r10=fffffffffffffffd
r11=fffff880009e8180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po cy
nt!KeTerminateThread+0x314:
fffff800`02e73828 488b6d00        mov     rbp,qword ptr [rbp] ss:0018:ffffea80`03d61b68=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002e92be9 to fffff80002e93640

STACK_TEXT:  
fffff880`0296a5d8 fffff800`02e92be9 : 00000000`0000000a ffffea80`03d61b68 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0296a5e0 fffff800`02e91860 : 00000000`ffff0000 00000000`00000000 fffff8a0`0a5239d0 fffffa80`03d61b60 : nt!KiBugCheckDispatch+0x69
fffff880`0296a720 fffff800`02e73828 : fffffa80`03d61b60 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x260
fffff880`0296a8b0 fffff800`03168f48 : 00000000`fff9b000 fffff880`0296ac20 fffff880`0296ac20 fffffa80`03d61b60 : nt!KeTerminateThread+0x314
fffff880`0296a930 fffff800`0314e37d : 00000000`c0000005 00000000`00000000 00000000`fff9b000 00000000`00000000 : nt!PspExitThread+0x418
fffff880`0296aa30 fffff800`02e86dfa : fffffa80`03d61b60 fffff800`02e86d31 00000000`00000000 00000000`00000000 : nt!PsExitSpecialApc+0x1d
fffff880`0296aa60 fffff800`02e87140 : 00000000`00000246 fffff880`0296aae0 fffff800`0314e2f0 00000000`00000001 : nt!KiDeliverApc+0x2ca
fffff880`0296aae0 fffff800`02e92977 : 00000000`00000246 fffff880`0296aca0 ffffffff`ffffd8f0 00000000`fff9b000 : nt!KiInitiateUserApc+0x70
fffff880`0296ac20 00000000`73fa2e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`0281f008 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73fa2e09


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!KeTerminateThread+314
fffff800`02e73828 488b6d00        mov     rbp,qword ptr [rbp]

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  nt!KeTerminateThread+314

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

FAILURE_BUCKET_ID:  X64_0xA_nt!KeTerminateThread+314

BUCKET_ID:  X64_0xA_nt!KeTerminateThread+314

Followup: MachineOwner
---------





DRIVERS

Code:
start             end                 module name
fffff880`00ec5000 fffff880`00f1c000   ACPI     ACPI.sys     Sat Nov 20 04:19:16 2010 (4CE79294)
fffff880`03ea8000 fffff880`03f31000   afd      afd.sys      Sat Nov 20 04:23:27 2010 (4CE7938F)
fffff880`051aa000 fffff880`051c0000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`0406c000 fffff880`04080000   amdiox64 amdiox64.sys Thu Feb 18 10:17:53 2010 (4B7D5A21)
fffff880`04160000 fffff880`04175000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00de2000 fffff880`00ded000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`07bc8000 fffff880`07bd3000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00dd9000 fffff880`00de2000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00c00000 fffff880`00c2a000   ataport  ataport.SYS  Sat Nov 20 04:19:15 2010 (4CE79293)
fffff880`0667c000 fffff880`0669c000   AtihdW76 AtihdW76.sys Mon Aug 16 06:41:02 2010 (4C6915BE)
fffff880`0483c000 fffff880`05138000   atikmdag atikmdag.sys Wed Jan 26 17:48:28 2011 (4D40A4BC)
fffff880`04175000 fffff880`041c3000   atikmpag atikmpag.sys Wed Jan 26 17:13:33 2011 (4D409C8D)
fffff960`008a0000 fffff960`00901000   ATMFD    ATMFD.DLL    Sat Feb 19 04:00:32 2011 (4D5F86B0)
fffff880`019e7000 fffff880`019ee000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04129000 fffff880`0413a000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`03be0000 fffff880`03bfe000   bowser   bowser.sys   Tue Feb 22 23:55:04 2011 (4D649328)
fffff960`00650000 fffff960`00677000   cdd      cdd.dll      Sat Nov 20 07:55:34 2010 (4CE7C546)
fffff880`015b4000 fffff880`015de000   cdrom    cdrom.sys    Sat Nov 20 04:19:20 2010 (4CE79298)
fffff880`00caf000 fffff880`00d6f000   CI       CI.dll       Sat Nov 20 08:12:36 2010 (4CE7C944)
fffff880`01978000 fffff880`019a8000   CLASSPNP CLASSPNP.SYS Sat Nov 20 04:19:23 2010 (4CE7929B)
fffff880`00c51000 fffff880`00caf000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0112d000 fffff880`0119f000   cng      cng.sys      Sat Nov 20 05:08:45 2010 (4CE79E2D)
fffff880`0519a000 fffff880`051aa000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`0675d000 fffff880`0676b000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`04088000 fffff880`0410b000   csc      csc.sys      Sat Nov 20 04:27:12 2010 (4CE79470)
fffff880`0410b000 fffff880`04129000   dfsc     dfsc.sys     Sat Nov 20 04:26:31 2010 (4CE79447)
fffff880`03e68000 fffff880`03e77000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01962000 fffff880`01978000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`066d9000 fffff880`066fb000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`06777000 fffff880`06780000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`0676b000 fffff880`06777000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06780000 fffff880`06793000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`0662b000 fffff880`06637000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`042a4000 fffff880`04398000   dxgkrnl  dxgkrnl.sys  Sat Nov 20 04:50:50 2010 (4CE799FA)
fffff880`04398000 fffff880`043de000   dxgmms1  dxgmms1.sys  Sat Nov 20 04:49:53 2010 (4CE799C1)
fffff880`03ae1000 fffff880`03b17000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`043ef000 fffff880`043fc000   fdc      fdc.sys      Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`010bb000 fffff880`010cf000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`03e89000 fffff880`03e94000   flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`0106f000 fffff880`010bb000   fltmgr   fltmgr.sys   Sat Nov 20 04:19:24 2010 (4CE7929C)
fffff880`01211000 fffff880`0121b000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`01928000 fffff880`01962000   fvevol   fvevol.sys   Sat Nov 20 04:24:06 2010 (4CE793B6)
fffff880`0181b000 fffff880`01865000   fwpkclnt fwpkclnt.sys Sat Nov 20 04:21:37 2010 (4CE79321)
fffff800`033fd000 fffff800`03446000   hal      hal.dll      Sat Nov 20 08:00:25 2010 (4CE7C669)
fffff880`04200000 fffff880`04224000   HDAudBus HDAudBus.sys Sat Nov 20 05:43:42 2010 (4CE7A65E)
fffff880`06701000 fffff880`0675d000   HdAudio  HdAudio.sys  Sat Nov 20 05:44:23 2010 (4CE7A687)
fffff880`067be000 fffff880`067d7000   HIDCLASS HIDCLASS.SYS Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`067d7000 fffff880`067df080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`067b0000 fffff880`067be000   hidusb   hidusb.sys   Sat Nov 20 05:43:49 2010 (4CE7A665)
fffff880`03b17000 fffff880`03be0000   HTTP     HTTP.sys     Sat Nov 20 04:24:30 2010 (4CE793CE)
fffff880`0191f000 fffff880`01928000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`051f0000 fffff880`051ff000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`0661d000 fffff880`0662b000   kbdhid   kbdhid.sys   Sat Nov 20 05:33:25 2010 (4CE7A3F5)
fffff800`00ba0000 fffff800`00baa000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`04029000 fffff880`0406c000   ks       ks.sys       Sat Nov 20 05:33:23 2010 (4CE7A3F3)
fffff880`013d9000 fffff880`013f4000   ksecdd   ksecdd.sys   Sat Nov 20 04:21:15 2010 (4CE7930B)
fffff880`01589000 fffff880`015b4000   ksecpkg  ksecpkg.sys  Sat Nov 20 05:10:34 2010 (4CE79E9A)
fffff880`066fb000 fffff880`06700200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`019c9000 fffff880`019de000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`06645000 fffff880`06668000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c30000 fffff880`00c3d000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`06637000 fffff880`06645000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`0401a000 fffff880`04029000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`067e0000 fffff880`067ed000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00d6f000 fffff880`00d89000   mountmgr mountmgr.sys Sat Nov 20 04:19:21 2010 (4CE79299)
fffff880`01400000 fffff880`01431000   MpFilter MpFilter.sys Tue Sep 14 20:19:28 2010 (4C901110)
fffff880`03ab6000 fffff880`03ac6000   MpNWMon  MpNWMon.sys  Tue Sep 14 20:19:30 2010 (4C901112)
fffff880`03a00000 fffff880`03a18000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`03a18000 fffff880`03a45000   mrxsmb   mrxsmb.sys   Tue Feb 22 23:56:22 2011 (4D649376)
fffff880`03a45000 fffff880`03a92000   mrxsmb10 mrxsmb10.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`03a92000 fffff880`03ab6000   mrxsmb20 mrxsmb20.sys Tue Feb 22 23:55:12 2011 (4D649330)
fffff880`0121b000 fffff880`01226000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f25000 fffff880`00f2f000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`010cf000 fffff880`0112d000   msrpc    msrpc.sys    Sat Nov 20 04:21:56 2010 (4CE79334)
fffff880`03e5d000 fffff880`03e68000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`0190d000 fffff880`0191f000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01436000 fffff880`01529000   ndis     ndis.sys     Sat Nov 20 04:23:30 2010 (4CE79392)
fffff880`051e4000 fffff880`051f0000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`04800000 fffff880`0482f000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`0105a000 fffff880`0106f000   NDProxy  NDProxy.SYS  Sat Nov 20 05:52:20 2010 (4CE7A864)
fffff880`03fa5000 fffff880`03fb4000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`03f31000 fffff880`03f76000   netbt    netbt.sys    Sat Nov 20 04:23:18 2010 (4CE79386)
fffff880`01529000 fffff880`01589000   NETIO    NETIO.SYS    Sat Nov 20 04:23:13 2010 (4CE79381)
fffff880`07b11000 fffff880`07b26000   NisDrvWFP NisDrvWFP.sys Tue Sep 14 20:20:25 2010 (4C901149)
fffff880`011c4000 fffff880`011d5000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03e51000 fffff880`03e5d000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e13000 fffff800`033fd000   nt       ntkrnlmp.exe Sat Nov 20 04:30:02 2010 (4CE7951A)
fffff880`01236000 fffff880`013d9000   Ntfs     Ntfs.sys     Thu Mar 10 22:39:39 2011 (4D79997B)
fffff880`019de000 fffff880`019e7000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`03f7f000 fffff880`03fa5000   pacer    pacer.sys    Sat Nov 20 05:52:18 2010 (4CE7A862)
fffff880`00f6f000 fffff880`00f84000   partmgr  partmgr.sys  Sat Nov 20 04:20:00 2010 (4CE792C0)
fffff880`00f2f000 fffff880`00f62000   pci      pci.sys      Sat Nov 20 04:19:11 2010 (4CE7928F)
fffff880`00ff5000 fffff880`00ffc000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00e00000 fffff880`00e10000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01200000 fffff880`01211000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`06ed4000 fffff880`06f7a000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`0669c000 fffff880`066d9000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c3d000 fffff880`00c51000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`051c0000 fffff880`051e4000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`041c3000 fffff880`041de000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`041de000 fffff880`041ff000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`04000000 fffff880`0401a000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03e00000 fffff880`03e51000   rdbss    rdbss.sys    Sat Nov 20 04:27:51 2010 (4CE79497)
fffff880`0482f000 fffff880`0483a000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`015de000 fffff880`015e7000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`015e7000 fffff880`015f0000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`015f0000 fffff880`015f9000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`018d3000 fffff880`0190d000   rdyboost rdyboost.sys Sat Nov 20 04:43:10 2010 (4CE7982E)
fffff880`03ac9000 fffff880`03ae1000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04224000 fffff880`0428e000   Rt64win7 Rt64win7.sys Wed Jan 26 08:34:03 2011 (4D4022CB)
fffff880`06f7a000 fffff880`06f85000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`0518e000 fffff880`0519a000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03fb4000 fffff880`03fd1000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`018c9000 fffff880`018d3000   speedfan speedfan.sys Sat Dec 18 06:03:51 2010 (4D0C9517)
fffff880`018c1000 fffff880`018c9000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`07a79000 fffff880`07b11000   srv      srv.sys      Tue Feb 22 23:56:21 2011 (4D649375)
fffff880`06e00000 fffff880`06e6a000   srv2     srv2.sys     Tue Feb 22 23:56:00 2011 (4D649360)
fffff880`06f85000 fffff880`06fb6000   srvnet   srvnet.sys   Tue Feb 22 23:55:44 2011 (4D649350)
fffff880`042a2000 fffff880`042a3480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01617000 fffff880`0181b000   tcpip    tcpip.sys    Sat Nov 20 04:25:52 2010 (4CE79420)
fffff880`06fb6000 fffff880`06fc8000   tcpipreg tcpipreg.sys Sat Nov 20 05:51:48 2010 (4CE7A844)
fffff880`01226000 fffff880`01233000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`011d5000 fffff880`011f7000   tdx      tdx.sys      Sat Nov 20 04:21:54 2010 (4CE79332)
fffff880`03fec000 fffff880`04000000   termdd   termdd.sys   Sat Nov 20 06:03:40 2010 (4CE7AB0C)
fffff960`005a0000 fffff960`005aa000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`0413a000 fffff880`04160000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`03e77000 fffff880`03e89000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06600000 fffff880`0661d000   usbccgp  usbccgp.sys  Sat Nov 20 05:44:03 2010 (4CE7A673)
fffff880`067ae000 fffff880`067aff00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`043de000 fffff880`043ef000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`01000000 fffff880`0105a000   usbhub   usbhub.sys   Sat Nov 20 05:44:30 2010 (4CE7A68E)
fffff880`0428e000 fffff880`04299000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`05138000 fffff880`0518e000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`06793000 fffff880`067ae000   USBSTOR  USBSTOR.SYS  Thu Mar 10 23:37:16 2011 (4D79A6FC)
fffff880`00f62000 fffff880`00f6f000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`019ee000 fffff880`019fc000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`0119f000 fffff880`011c4000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00d89000 fffff880`00dc5000   vmbus    vmbus.sys    Sat Nov 20 04:57:29 2010 (4CE79B89)
fffff880`01865000 fffff880`01875000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00f84000 fffff880`00f99000   volmgr   volmgr.sys   Sat Nov 20 04:19:28 2010 (4CE792A0)
fffff880`00f99000 fffff880`00ff5000   volmgrx  volmgrx.sys  Sat Nov 20 04:20:43 2010 (4CE792EB)
fffff880`01875000 fffff880`018c1000   volsnap  volsnap.sys  Sat Nov 20 04:20:08 2010 (4CE792C8)
fffff880`03fd1000 fffff880`03fec000   wanarp   wanarp.sys   Sat Nov 20 05:52:36 2010 (4CE7A874)
fffff880`01600000 fffff880`01610000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e12000 fffff880`00eb6000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00eb6000 fffff880`00ec5000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`03f76000 fffff880`03f7f000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00010000 fffff960`00322000   win32k   win32k.sys   Wed Mar 02 22:51:40 2011 (4D6F104C)
fffff880`00dc5000 fffff880`00dd9000   winhv    winhv.sys    Sat Nov 20 04:20:02 2010 (4CE792C2)
fffff880`04299000 fffff880`042a2000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f1c000 fffff880`00f25000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`019a8000 fffff880`019c9000   WudfPf   WudfPf.sys   Sat Nov 20 05:42:44 2010 (4CE7A624)
fffff880`07b26000 fffff880`07b57000   WUDFRd   WUDFRd.sys   Sat Nov 20 05:43:32 2010 (4CE7A654)

Unloaded modules:
fffff880`07b57000 fffff880`07bc8000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`019a8000 fffff880`019b6000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`019b6000 fffff880`019c2000   dump_ataport
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`019c2000 fffff880`019cb000   dump_atapi.s
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00009000
fffff880`019cb000 fffff880`019de000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
 
Ran memtest86 X10 with no errors.
HD diagnostics ran and found nothing wrong.
PassMark/HDDScan showed everything OK.

I had a BSOD where the entire screen went blue with no error messages.

Lots of times when I boot View attachment Minidump.rarup, nothing will happen. Computer appears to be on but blank screens. Windows also will fail to load on occasion.

Or, I'll get an error that says: DQS training failed on previous boot, reverted to slower DRAM speed.
Then it gives options to reboot, change settings, etc. Sometimes at this very screen the whole computer will lock up/freeze.

Is it possible to freeze while the BSOD is dumping files? It appears to have done this a few times.

Also I've had the screen freeze in BIOS. How does a computer possibly freeze while in BIOS? Does this rule out a hard drive/software problem? Still a RAM issue? What should I do?
 

Attachments

  • 051211-13634-01.rar
    19.8 KB · Views: 303
Last edited:
051211-14180-01.dmp
BugCheck 3B, {c0000005, fffff8800452fc60, fffff880082dad90, 0}
Probably caused by : dxgmms1.sys ( dxgmms1!VidMmTerminateAllocation+144 )

051211-16052-01.dmp
Bugcheck 50
Probably caused by : atikmdag.sys ( atikmdag+46c0e4 )

051211-13634-01.dmp
BugCheck 18, {0, fffffa80068e9ce0, 2, fffffa80068e9ca7}

Ran memtest86 X10 with no errors.
HD diagnostics ran and found nothing wrong.
PassMark/HDDScan showed everything OK.

Lots of times when I boot up, nothing will happen. Computer appears to be on but blank screens. Windows also will fail to load on occasion.


It could be your video card.





CRASH DUMPS

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\051211-14180-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17592.amd64fre.win7sp1_gdr.110408-1631
Machine Name:
Kernel base = 0xfffff800`02e57000 PsLoadedModuleList = 0xfffff800`0309c650
Debug session time: Thu May 12 13:10:03.350 2011 (UTC - 4:00)
System Uptime: 0 days 0:12:26.942
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff8800452fc60, fffff880082dad90, 0}

Unable to load image \SystemRoot\system32\DRIVERS\atikmdag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Probably caused by : dxgmms1.sys ( dxgmms1!VidMmTerminateAllocation+144 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8800452fc60, Address of the instruction which caused the bugcheck
Arg3: fffff880082dad90, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************

ADDITIONAL_DEBUG_TEXT:  
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: dxgmms1

FAULTING_MODULE: fffff80002e57000 nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
dxgmms1!VidMmTerminateAllocation+144
fffff880`0452fc60 4c8ba938010000  mov     r13,qword ptr [rcx+138h]

CONTEXT:  fffff880082dad90 -- (.cxr 0xfffff880082dad90)
rax=fffff8a00972e430 rbx=fffffa8005a23000 rcx=000001290000010b
rdx=0000000000000000 rsi=0000000000150000 rdi=fffff8a002ea7b40
rip=fffff8800452fc60 rsp=fffff880082db770 rbp=fffffa8006506800
 r8=0000000000000000  r9=0000000000000000 r10=fffff88002f64a60
r11=fffff880082db740 r12=fffff8a002ea7be0 r13=fffff88004458a08
r14=0000000000000001 r15=0000000000000001
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
dxgmms1!VidMmTerminateAllocation+0x144:
fffff880`0452fc60 4c8ba938010000  mov     r13,qword ptr [rcx+138h] ds:002b:00000129`00000243=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8800452fc60

STACK_TEXT:  
fffff880`082db770 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : dxgmms1!VidMmTerminateAllocation+0x144


FOLLOWUP_IP: 
dxgmms1!VidMmTerminateAllocation+144
fffff880`0452fc60 4c8ba938010000  mov     r13,qword ptr [rcx+138h]

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!VidMmTerminateAllocation+144

FOLLOWUP_NAME:  MachineOwner

IMAGE_NAME:  dxgmms1.sys

STACK_COMMAND:  .cxr 0xfffff880082dad90 ; kb

BUCKET_ID:  WRONG_SYMBOLS

Followup: MachineOwner
---------




Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\051211-16052-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17592.amd64fre.win7sp1_gdr.110408-1631
Machine Name:
Kernel base = 0xfffff800`02e4f000 PsLoadedModuleList = 0xfffff800`03094650
Debug session time: Thu May 12 01:10:06.825 2011 (UTC - 4:00)
System Uptime: 0 days 0:00:59.402
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 50, {fffff8c004d530c7, 1, fffff88004d530e4, 5}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Unable to load image \SystemRoot\system32\DRIVERS\atikmdag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Probably caused by : atikmdag.sys ( atikmdag+46c0e4 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8c004d530c7, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff88004d530e4, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000005, (reserved)

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************

ADDITIONAL_DEBUG_TEXT:  
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

FAULTING_MODULE: fffff80002e4f000 nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4d40a4bc

WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
 fffff8c004d530c7 

FAULTING_IP: 
atikmdag+46c0e4
fffff880`04d530e4 41c7000f65c190  mov     dword ptr [r8],90C1650Fh

MM_INTERNAL_CODE:  5

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x50

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff80002e793cf to fffff80002eced00

STACK_TEXT:  
fffff880`05be4928 fffff800`02e793cf : 00000000`00000050 fffff8c0`04d530c7 00000000`00000001 fffff880`05be4a90 : nt+0x7fd00
fffff880`05be4930 00000000`00000050 : fffff8c0`04d530c7 00000000`00000001 fffff880`05be4a90 00000000`00000005 : nt+0x2a3cf
fffff880`05be4938 fffff8c0`04d530c7 : 00000000`00000001 fffff880`05be4a90 00000000`00000005 fffff800`02ed16ef : 0x50
fffff880`05be4940 00000000`00000001 : fffff880`05be4a90 00000000`00000005 fffff800`02ed16ef 00000000`00000000 : 0xfffff8c0`04d530c7
fffff880`05be4948 fffff880`05be4a90 : 00000000`00000005 fffff800`02ed16ef 00000000`00000000 00000000`00000000 : 0x1
fffff880`05be4950 00000000`00000005 : fffff800`02ed16ef 00000000`00000000 00000000`00000000 fffff880`02fddfc0 : 0xfffff880`05be4a90
fffff880`05be4958 fffff800`02ed16ef : 00000000`00000000 00000000`00000000 fffff880`02fddfc0 fffff800`02ed19e5 : 0x5
fffff880`05be4960 00000000`00000000 : 00000000`00000000 fffff880`02fddfc0 fffff800`02ed19e5 fffff6fc`60026a98 : nt+0x826ef


STACK_COMMAND:  .bugcheck ; kb

FOLLOWUP_IP: 
atikmdag+46c0e4
fffff880`04d530e4 41c7000f65c190  mov     dword ptr [r8],90C1650Fh

SYMBOL_NAME:  atikmdag+46c0e4

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: atikmdag

IMAGE_NAME:  atikmdag.sys

BUCKET_ID:  WRONG_SYMBOLS

Followup: MachineOwner
---------



Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\DMP\051211-13634-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17592.amd64fre.win7sp1_gdr.110408-1631
Machine Name:
Kernel base = 0xfffff800`02e03000 PsLoadedModuleList = 0xfffff800`03048650
Debug session time: Thu May 12 13:38:09.767 2011 (UTC - 4:00)
System Uptime: 0 days 0:06:35.969
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
................................................
Loading User Symbols
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 18, {0, fffffa80068e9ce0, 2, fffffa80068e9ca7}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

Unable to open image file: E:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
The system cannot find the file specified.

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*************************************************************************
Probably caused by : ntoskrnl.exe ( nt+89509 )

Followup: MachineOwner
---------





DRIVERS

Code:
start             end                 module name
fffff880`00f83000 fffff880`00fda000   ACPI     ACPI.sys     unavailable (00000000)
fffff880`00c2a000 fffff880`00c35000   amdxata  amdxata.sys  unavailable (00000000)
fffff880`00de0000 fffff880`00de9000   atapi    atapi.sys    unavailable (00000000)
fffff880`00c00000 fffff880`00c2a000   ataport  ataport.SYS  unavailable (00000000)
fffff880`00cb6000 fffff880`00d76000   CI       CI.dll       unavailable (00000000)
fffff880`01650000 fffff880`01680000   CLASSPNP CLASSPNP.SYS unavailable (00000000)
fffff880`00c58000 fffff880`00cb6000   CLFS     CLFS.SYS     unavailable (00000000)
fffff880`01000000 fffff880`01072000   cng      cng.sys      unavailable (00000000)
fffff880`0163a000 fffff880`01650000   disk     disk.sys     unavailable (00000000)
fffff880`01134000 fffff880`01148000   fileinfo fileinfo.sys unavailable (00000000)
fffff880`010e8000 fffff880`01134000   fltmgr   fltmgr.sys   unavailable (00000000)
fffff880`0122c000 fffff880`01236000   Fs_Rec   Fs_Rec.sys   unavailable (00000000)
fffff880`01600000 fffff880`0163a000   fvevol   fvevol.sys   unavailable (00000000)
fffff880`018cb000 fffff880`01915000   fwpkclnt fwpkclnt.sys unavailable (00000000)
fffff800`033ec000 fffff800`03435000   hal      hal.dll      Sat Nov 20 08:00:25 2010 (4CE7C669)
fffff880`019cf000 fffff880`019d8000   hwpolicy hwpolicy.sys unavailable (00000000)
fffff800`00ba8000 fffff800`00bb2000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`01200000 fffff880`0121b000   ksecdd   ksecdd.sys   unavailable (00000000)
fffff880`01460000 fffff880`0148b000   ksecpkg  ksecpkg.sys  unavailable (00000000)
fffff880`00c37000 fffff880`00c44000   mcupdate mcupdate.dll unavailable (00000000)
fffff880`00d76000 fffff880`00d90000   mountmgr mountmgr.sys unavailable (00000000)
fffff880`00fe3000 fffff880`00fed000   msisadrv msisadrv.sys unavailable (00000000)
fffff880`01148000 fffff880`011a6000   msrpc    msrpc.sys    unavailable (00000000)
fffff880`019bd000 fffff880`019cf000   mup      mup.sys      unavailable (00000000)
fffff880`014ff000 fffff880`015f2000   ndis     ndis.sys     unavailable (00000000)
fffff880`01400000 fffff880`01460000   NETIO    NETIO.SYS    unavailable (00000000)
fffff800`02e03000 fffff800`033ec000   nt       ntoskrnl.exe Sat Apr 09 00:15:23 2011 (4D9FDD5B)
fffff880`0125b000 fffff880`013fe000   Ntfs     Ntfs.sys     unavailable (00000000)
fffff880`00e40000 fffff880`00e55000   partmgr  partmgr.sys  unavailable (00000000)
fffff880`00e00000 fffff880`00e33000   pci      pci.sys      unavailable (00000000)
fffff880`00ec6000 fffff880`00ecd000   pciide   pciide.sys   unavailable (00000000)
fffff880`00fed000 fffff880`00ffd000   PCIIDEX  PCIIDEX.SYS  unavailable (00000000)
fffff880`0121b000 fffff880`0122c000   pcw      pcw.sys      unavailable (00000000)
fffff880`00c44000 fffff880`00c58000   PSHED    PSHED.dll    unavailable (00000000)
fffff880`01983000 fffff880`019bd000   rdyboost rdyboost.sys unavailable (00000000)
fffff880`01979000 fffff880`01983000   speedfan speedfan.sys unavailable (00000000)
fffff880`01971000 fffff880`01979000   spldr    spldr.sys    unavailable (00000000)
fffff880`016c7000 fffff880`018cb000   tcpip    tcpip.sys    unavailable (00000000)
bd7465ab`7ef416f9 bd7465ac`7c4dcef9   Unknown_Module_bd7465ab_7ef416f9 Unknown_Module_bd7465ab`7ef416f9 unavailable (00000000)
fffff880`00e33000 fffff880`00e40000   vdrvroot vdrvroot.sys unavailable (00000000)
fffff880`00d90000 fffff880`00dcc000   vmbus    vmbus.sys    unavailable (00000000)
fffff880`01915000 fffff880`01925000   vmstorfl vmstorfl.sys unavailable (00000000)
fffff880`00e55000 fffff880`00e6a000   volmgr   volmgr.sys   unavailable (00000000)
fffff880`00e6a000 fffff880`00ec6000   volmgrx  volmgrx.sys  unavailable (00000000)
fffff880`01925000 fffff880`01971000   volsnap  volsnap.sys  unavailable (00000000)
fffff880`00ed0000 fffff880`00f74000   Wdf01000 Wdf01000.sys unavailable (00000000)
fffff880`00f74000 fffff880`00f83000   WDFLDR   WDFLDR.SYS   unavailable (00000000)
fffff880`00dcc000 fffff880`00de0000   winhv    winhv.sys    unavailable (00000000)
fffff880`00fda000 fffff880`00fe3000   WMILIB   WMILIB.SYS   unavailable (00000000)
 
Last edited:
Back
Top