lambarda

New Member
Joined
Feb 22, 2011
Messages
6
Hi guys, getting BSOD at all kinds of times, tried many things but to no avail, here are the dump files on bluescreen event viewer

Dump File : 022011-91853-01.dmp
Crash Time : 20/02/2011 21:45:33
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82e494a0
Parameter 3 : 0x8d39b774
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+23e4a0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\022011-91853-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 140,064
==================================================

==================================================
Dump File : 022011-76549-01.dmp
Crash Time : 20/02/2011 20:38:46
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82e424a0
Parameter 3 : 0x8d197774
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+23e4a0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\022011-76549-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 147,472
==================================================

==================================================
Dump File : 021711-149994-01.dmp
Crash Time : 17/02/2011 22:53:12
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82e534a0
Parameter 3 : 0x8ca4f774
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+23e4a0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\021711-149994-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 144,232
==================================================

==================================================
Dump File : 021711-69685-01.dmp
Crash Time : 17/02/2011 22:03:31
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82d043e1
Parameter 3 : 0x8d39ba60
Parameter 4 : 0x8d39b640
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+bb3e1
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\021711-69685-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 144,232
==================================================

==================================================
Dump File : 021711-107952-01.dmp
Crash Time : 17/02/2011 21:56:06
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82d0f3e1
Parameter 3 : 0x8d58fa60
Parameter 4 : 0x8d58f640
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+bb3e1
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\021711-107952-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 144,232
==================================================

==================================================
Dump File : 021711-120042-01.dmp
Crash Time : 17/02/2011 21:49:48
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 0x000000a0
Parameter 2 : 0x00000002
Parameter 3 : 0x00000001
Parameter 4 : 0x82c8186c
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+4681b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\021711-120042-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 144,232
==================================================

==================================================
Dump File : 021511-52119-01.dmp
Crash Time : 15/02/2011 12:59:55
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82e584a0
Parameter 3 : 0x8d5cb774
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+23e4a0
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\021511-52119-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 144,232
==================================================

==================================================
Dump File : 091610-33087-01.dmp
Crash Time : 16/09/2010 18:30:51
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 0x00000020
Parameter 2 : 0xc000009d
Parameter 3 : 0x87f347c4
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+832f4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\091610-33087-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 150,408
==================================================

==================================================
Dump File : 091310-35271-01.dmp
Crash Time : 13/09/2010 14:07:09
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 0xc07f44c0
Parameter 2 : 0xc000009d
Parameter 3 : 0x38fdc8c0
Parameter 4 : 0xfe898320
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcd10
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\091310-35271-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 150,408
==================================================

==================================================
Dump File : 091210-56019-01.dmp
Crash Time : 12/09/2010 11:15:53
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 0x00000020
Parameter 2 : 0xc000009d
Parameter 3 : 0x87ddf044
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+832f4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16695 (win7_gdr.101026-1503)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\091210-56019-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 150,408
====================================
 

Solution
Wow, that's quite a few of crashes! I am impressed.


1. PCTools is a bad idea when Symantec Norton is running alongside.

- Uninstall PCTools
- Then if crashes persist, uninstall Norton too

Link Removed due to 404 Error

Link Removed due to 404 Error



2. Update Intel Gigabit Adapter
e1k6232.sys Mon Jun 22 14:04:20 2009
Link Removed






Crash Dumps:

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\a\Minidump\D M P\DMP\021711-107952-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is...
here are the files
 

Attachments

Wow, that's quite a few of crashes! I am impressed.


1. PCTools is a bad idea when Symantec Norton is running alongside.

- Uninstall PCTools
- Then if crashes persist, uninstall Norton too

Link Removed due to 404 Error

Link Removed due to 404 Error



2. Update Intel Gigabit Adapter
e1k6232.sys Mon Jun 22 14:04:20 2009
Link Removed






Crash Dumps:

Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\a\Minidump\D M P\DMP\021711-107952-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.x86fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0x82c54000 PsLoadedModuleList = 0x82d9c810
Debug session time: Thu Feb 17 16:53:08.169 2011 (UTC - 5:00)
System Uptime: 0 days 0:05:32.558
Loading Kernel Symbols
...............................................................
................................................................
.......................................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {c0000005, 82d0f3e1, 8d58fa60, 8d58f640}

Probably caused by : ntkrpamp.exe ( nt!RtlImageNtHeaderEx+4a )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003.  This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG.  This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG.  This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 82d0f3e1, The address that the exception occurred at
Arg3: 8d58fa60, Exception Record Address
Arg4: 8d58f640, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
nt!RtlImageNtHeaderEx+4a
82d0f3e1 663902          cmp     word ptr [edx],ax

EXCEPTION_RECORD:  8d58fa60 -- (.exr 0xffffffff8d58fa60)
ExceptionAddress: 82d0f3e1 (nt!RtlImageNtHeaderEx+0x0000004a)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000000
   Parameter[1]: 7ffa0000
Attempt to read from address 7ffa0000

CONTEXT:  8d58f640 -- (.cxr 0xffffffff8d58f640)
eax=00005a4d ebx=89cfc244 ecx=00000000 edx=7ffa0000 esi=00000000 edi=8d58fb3c
eip=82d0f3e1 esp=8d58fb28 ebp=8d58fb28 iopl=0         nv up ei pl zr na pe nc
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010246
nt!RtlImageNtHeaderEx+0x4a:
82d0f3e1 663902          cmp     word ptr [edx],ax        ds:0023:7ffa0000=????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  00000000

EXCEPTION_PARAMETER2:  7ffa0000

READ_ADDRESS: GetPointerFromAddress: unable to read from 82dbc718
Unable to read MiSystemVaType memory at 82d9c160
 7ffa0000 

FOLLOWUP_IP: 
nt!RtlImageNtHeaderEx+4a
82d0f3e1 663902          cmp     word ptr [edx],ax

BUGCHECK_STR:  0x7E

LAST_CONTROL_TRANSFER:  from 82d13484 to 82d0f3e1

STACK_TEXT:  
8d58fb28 82d13484 00000000 00000000 89cfc008 nt!RtlImageNtHeaderEx+0x4a
8d58fb5c 82c6bc95 859ff468 00000000 00000004 nt!RtlImageNtHeader+0x1a
8d58fc18 82c22ba9 89cfc008 00000000 8d58fc60 nt!EtwpCCSwapTrace+0x433
8d58fd00 82cc203b 80002930 00000000 859dd4c0 hal!KfLowerIrql+0x61
8d58fd50 82e629df 00000001 a00e5b57 00000000 nt!ExpWorkerThread+0x10d
8d58fd90 82d141d9 82cc1f2e 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!RtlImageNtHeaderEx+4a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4cc78ed4

STACK_COMMAND:  .cxr 0xffffffff8d58f640 ; kb

FAILURE_BUCKET_ID:  0x7E_nt!RtlImageNtHeaderEx+4a

BUCKET_ID:  0x7E_nt!RtlImageNtHeaderEx+4a

Followup: MachineOwner
---------



Drivers:

Code:
start    end        module name
957d4000 95800000   1394ohci 1394ohci.sys Mon Jul 13 19:51:59 2009 (4A5BC89F)
834ba000 83502000   ACPI     ACPI.sys     Mon Jul 13 19:11:11 2009 (4A5BBF0F)
92903000 9295d000   afd      afd.sys      Mon Jul 13 19:12:34 2009 (4A5BBF62)
93400000 93412000   AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)
833ad000 833b6000   amdxata  amdxata.sys  Tue May 19 13:57:35 2009 (4A12F30F)
83400000 83409000   atapi    atapi.sys    Mon Jul 13 19:11:15 2009 (4A5BBF13)
83409000 8342c000   ataport  ataport.SYS  Mon Jul 13 19:11:18 2009 (4A5BBF16)
95018000 95638000   atikmdag atikmdag.sys Tue Aug 03 21:35:57 2010 (4C58C3FD)
9358a000 935c3000   atikmpag atikmpag.sys Tue Aug 03 21:15:28 2010 (4C58BF30)
8b95a000 8b961000   Beep     Beep.SYS     Mon Jul 13 19:45:00 2009 (4A5BC6FC)
934ab000 93557000   BHDrvx86 BHDrvx86.sys Mon Nov 15 17:35:02 2010 (4CE1B596)
9349d000 934ab000   blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)
832aa000 832b2000   BOOTVID  BOOTVID.dll  Mon Jul 13 21:04:34 2009 (4A5BD9A2)
96b8e000 96ba7000   bowser   bowser.sys   Mon Jul 13 19:14:21 2009 (4A5BBFCD)
9341e000 9349d000   ccHPx86  ccHPx86.sys  Fri Feb 05 15:57:22 2010 (4B6C8632)
9a790000 9a7ae000   cdd      cdd.dll      unavailable (00000000)
8b8b4000 8b8d3000   cdrom    cdrom.sys    Mon Jul 13 19:11:24 2009 (4A5BBF1C)
832f4000 8339f000   CI       CI.dll       Mon Jul 13 21:09:28 2009 (4A5BDAC8)
8b85c000 8b881000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)
832b2000 832f4000   CLFS     CLFS.SYS     Mon Jul 13 19:11:10 2009 (4A5BBF0E)
8b5a2000 8b5ff000   cng      cng.sys      Mon Jul 13 19:32:55 2009 (4A5BC427)
935ec000 935f9000   CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)
98993000 989a0000   crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)
92f54000 92fb8000   csc      csc.sys      Mon Jul 13 19:15:08 2009 (4A5BBFFC)
92fb8000 92fd0000   dfsc     dfsc.sys     Mon Jul 13 19:14:16 2009 (4A5BBFC8)
92f48000 92f54000   discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)
8b84b000 8b85c000   disk     disk.sys     Mon Jul 13 19:11:28 2009 (4A5BBF20)
9897a000 98993000   drmk     drmk.sys     Mon Jul 13 20:36:05 2009 (4A5BD2F5)
989a0000 989ab000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)
989b5000 989c6000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)
989ab000 989b5000   dump_msahci dump_msahci.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)
8b881000 8b88b000   Dxapi    Dxapi.sys    Mon Jul 13 19:25:25 2009 (4A5BC265)
95638000 956ef000   dxgkrnl  dxgkrnl.sys  Mon Nov 01 22:37:53 2010 (4CCF7981)
956ef000 95728000   dxgmms1  dxgmms1.sys  Wed Feb 02 22:34:49 2011 (4D4A2259)
95747000 9577a000   e1k6232  e1k6232.sys  Mon Jun 22 14:04:20 2009 (4A3FC7A4)
92eea000 92f48000   eeCtrl   eeCtrl.sys   Fri May 21 17:44:53 2010 (4BF6FED5)
96a31000 96a5b000   fastfat  fastfat.SYS  Mon Jul 13 19:14:01 2009 (4A5BBFB9)
8366e000 8367f000   fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
8350b000 8353f000   fltmgr   fltmgr.sys   Mon Jul 13 19:11:13 2009 (4A5BBF11)
8b40e000 8b417000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:11:14 2009 (4A5BBF12)
8b819000 8b84b000   fvevol   fvevol.sys   Fri Sep 25 22:24:21 2009 (4ABD7B55)
8b74e000 8b77f000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)
935dd000 935e2280   GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:16:53 2009 (4A1151B5)
82c1d000 82c54000   hal      halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)
95728000 95747000   HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)
988fb000 9894b000   HdAudio  HdAudio.sys  Mon Jul 13 19:51:46 2009 (4A5BC892)
8b800000 8b813000   HIDCLASS HIDCLASS.SYS Mon Jul 13 19:51:01 2009 (4A5BC865)
989f6000 989fc480   HIDPARSE HIDPARSE.SYS Mon Jul 13 19:50:59 2009 (4A5BC863)
8b91a000 8b925000   hidusb   hidusb.sys   Mon Jul 13 19:51:04 2009 (4A5BC868)
96b09000 96b8e000   HTTP     HTTP.sys     Mon Jul 13 19:12:53 2009 (4A5BBF75)
8b427000 8b42f000   hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)
92e8f000 92eea000   IDSvix86 IDSvix86.sys Fri Nov 05 17:11:46 2010 (4CD47312)
93578000 9358a000   intelppm intelppm.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)
8b92a000 8b949000   Ironx86  Ironx86.SYS  Tue Apr 27 20:47:15 2010 (4BD78593)
935c3000 935d0000   kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
8b88b000 8b897000   kbdhid   kbdhid.sys   Mon Jul 13 19:45:09 2009 (4A5BC705)
8726a000 87272000   kdcom    kdcom.dll    Mon Jul 13 21:08:58 2009 (4A5BDAAA)
98807000 9883b000   ks       ks.sys       Wed Mar 03 22:57:52 2010 (4B8F2FC0)
8b58f000 8b5a2000   ksecdd   ksecdd.sys   Mon Jul 13 19:11:56 2009 (4A5BBF3C)
833b6000 833db000   ksecpkg  ksecpkg.sys  Thu Dec 10 23:04:22 2009 (4B21C4C6)
96a90000 96aa0000   lltdio   lltdio.sys   Mon Jul 13 19:53:18 2009 (4A5BC8EE)
96a5b000 96a76000   luafv    luafv.sys    Mon Jul 13 19:15:44 2009 (4A5BC020)
83221000 83299000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:06:41 2009 (4A5BDA21)
8b8a2000 8b8ad000   monitor  monitor.sys  Mon Jul 13 19:25:58 2009 (4A5BC286)
935d0000 935dd000   mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
8b897000 8b8a2000   mouhid   mouhid.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)
835e8000 835fe000   mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)
96ba7000 96bb9000   mpsdrv   mpsdrv.sys   Mon Jul 13 19:52:52 2009 (4A5BC8D4)
96bb9000 96bdc000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:32:02 2010 (4B88CA72)
9fa03000 9fa3e000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:32:21 2010 (4B88CA85)
9fa3e000 9fa59000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:32:11 2010 (4B88CA7B)
8342c000 83436000   msahci   msahci.sys   Mon Jul 13 19:45:50 2009 (4A5BC72E)
8b9b3000 8b9be000   Msfs     Msfs.SYS     Mon Jul 13 19:11:26 2009 (4A5BBF1E)
8353f000 83547000   msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)
8b564000 8b58f000   msrpc    msrpc.sys    Mon Jul 13 19:11:59 2009 (4A5BBF3F)
92e85000 92e8f000   mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
8b417000 8b427000   mup      mup.sys      Mon Jul 13 19:14:14 2009 (4A5BBFC6)
83707000 837be000   ndis     ndis.sys     Mon Jul 13 19:12:24 2009 (4A5BBF58)
93412000 9341d000   ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)
96ae6000 96af6000   ndisuio  ndisuio.sys  Mon Jul 13 19:53:51 2009 (4A5BC90F)
92e00000 92e22000   ndiswan  ndiswan.sys  Mon Jul 13 19:54:34 2009 (4A5BC93A)
988ea000 988fb000   NDProxy  NDProxy.SYS  Mon Jul 13 19:54:27 2009 (4A5BC933)
929df000 929ed000   netbios  netbios.sys  Mon Jul 13 19:53:54 2009 (4A5BC912)
9295d000 9298f000   netbt    netbt.sys    Mon Jul 13 19:12:18 2009 (4A5BBF52)
837be000 837fc000   NETIO    NETIO.SYS    Mon Jul 13 19:12:35 2009 (4A5BBF63)
8b9be000 8b9cc000   Npfs     Npfs.SYS     Mon Jul 13 19:11:31 2009 (4A5BBF23)
92e7b000 92e85000   nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)
82c54000 83064000   nt       ntkrpamp.exe Tue Oct 26 22:30:44 2010 (4CC78ED4)
8b435000 8b564000   Ntfs     Ntfs.sys     Mon Jul 13 19:12:05 2009 (4A5BBF45)
98800000 98807000   NuidFltr NuidFltr.sys Fri May 08 04:35:42 2009 (4A03EEDE)
8b953000 8b95a000   Null     Null.SYS     Mon Jul 13 19:11:12 2009 (4A5BBF10)
96aa0000 96ae6000   nwifi    nwifi.sys    Mon Jul 13 19:51:59 2009 (4A5BC89F)
9299f000 929be000   pacer    pacer.sys    Mon Jul 13 19:53:58 2009 (4A5BC916)
8357c000 8358d000   partmgr  partmgr.sys  Mon Jul 13 19:11:35 2009 (4A5BBF27)
83547000 83571000   pci      pci.sys      Mon Jul 13 19:11:16 2009 (4A5BBF14)
8339f000 833ad000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:11:15 2009 (4A5BBF13)
8367f000 836b8000   PCTCore  PCTCore.sys  Sun Mar 28 18:47:11 2010 (4BAFDC6F)
928af000 928e5f00   pctgntdi pctgntdi.sys Thu Feb 04 13:33:31 2010 (4B6B12FB)
9fbe0000 9fbef780   pctplsg  pctplsg.sys  Thu Apr 08 00:29:33 2010 (4BBD5BAD)
928e6000 92903000   PctWfpFilter PctWfpFilter.sys Thu Feb 04 13:41:56 2010 (4B6B14F4)
8b400000 8b40e000   pcw      pcw.sys      Mon Jul 13 19:11:10 2009 (4A5BBF0E)
9fa71000 9fb08000   peauth   peauth.sys   Mon Jul 13 20:35:44 2009 (4A5BD2E0)
9894b000 9897a000   portcls  portcls.sys  Mon Jul 13 19:51:00 2009 (4A5BC864)
83299000 832aa000   PSHED    PSHED.dll    Mon Jul 13 21:09:36 2009 (4A5BDAD0)
92fd0000 92fe8000   rasl2tp  rasl2tp.sys  Mon Jul 13 19:54:33 2009 (4A5BC939)
92e22000 92e3a000   raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)
92fe8000 92fff000   raspptp  raspptp.sys  Mon Jul 13 19:54:47 2009 (4A5BC947)
92810000 92827000   rassstp  rassstp.sys  Mon Jul 13 19:54:57 2009 (4A5BC951)
92e3a000 92e7b000   rdbss    rdbss.sys    Mon Jul 13 19:14:26 2009 (4A5BBFD2)
92827000 92831000   rdpbus   rdpbus.sys   Mon Jul 13 20:02:40 2009 (4A5BCB20)
8b99b000 8b9a3000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:01:40 2009 (4A5BCAE4)
8b9a3000 8b9ab000   rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)
8b9ab000 8b9b3000   rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)
8b7cf000 8b7fc000   rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)
96af6000 96b09000   rspndr   rspndr.sys   Mon Jul 13 19:53:20 2009 (4A5BC8F0)
9fb08000 9fb12000   secdrv   secdrv.SYS   Wed Sep 13 09:18:32 2006 (45080528)
8b7c7000 8b7cf000   spldr    spldr.sys    Mon May 11 12:13:47 2009 (4A084EBB)
8b949000 8b952080   SRTSPX   SRTSPX.SYS   Wed Feb 24 18:55:07 2010 (4B85BC5B)
9fb8f000 9fbe0000   srv      srv.sys      Thu Aug 26 23:31:26 2010 (4C77318E)
9fb40000 9fb8f000   srv2     srv2.sys     Thu Aug 26 23:30:45 2010 (4C773165)
9fb12000 9fb33000   srvnet   srvnet.sys   Thu Aug 26 23:30:39 2010 (4C77315F)
935f9000 935fa380   swenum   swenum.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)
83618000 8366e000   SYMDS    SYMDS.SYS    Mon Aug 17 19:34:39 2009 (4A89E90F)
836b8000 836e5000   SYMEFA   SYMEFA.SYS   Wed Apr 21 17:46:52 2010 (4BCF724C)
9288a000 928af000   SYMEVENT SYMEVENT.SYS Thu Aug 13 18:22:41 2009 (4A849231)
92831000 9288a000   SYMTDIV  SYMTDIV.SYS  Tue May 04 00:29:10 2010 (4BDFA296)
8b605000 8b74e000   tcpip    tcpip.sys    Sun Jun 13 23:36:59 2010 (4C15A3DB)
9fb33000 9fb40000   tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)
8b9e3000 8b9ee000   TDI      TDI.SYS      Mon Jul 13 19:12:12 2009 (4A5BBF4C)
8b9cc000 8b9e3000   tdx      tdx.sys      Mon Jul 13 19:12:10 2009 (4A5BBF4A)
92800000 92810000   termdd   termdd.sys   Mon Jul 13 20:01:35 2009 (4A5BCADF)
836e5000 836f6000   TfFsMon  TfFsMon.sys  Mon Feb 01 13:56:36 2010 (4B6723E4)
836f6000 83707000   TfSysMon TfSysMon.sys Mon Feb 01 13:56:44 2010 (4B6723EC)
9a760000 9a769000   TSDDD    TSDDD.dll    Mon Jul 13 20:01:40 2009 (4A5BCAE4)
93557000 93578000   tunnel   tunnel.sys   Mon Jul 13 19:54:03 2009 (4A5BC91B)
9883b000 98849000   umbus    umbus.sys    Mon Jul 13 19:51:38 2009 (4A5BC88A)
989c6000 989dd000   usbccgp  usbccgp.sys  Mon Jul 13 19:51:31 2009 (4A5BC883)
9886e000 9886f700   USBD     USBD.SYS     Mon Jul 13 19:51:05 2009 (4A5BC869)
9577a000 95789000   usbehci  usbehci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)
988a6000 988ea000   usbhub   usbhub.sys   Mon Jul 13 19:52:06 2009 (4A5BC8A6)
95789000 957d4000   USBPORT  USBPORT.SYS  Mon Jul 13 19:51:13 2009 (4A5BC871)
989eb000 989f6000   usbprint usbprint.sys Mon Jul 13 20:17:06 2009 (4A5BCE82)
98861000 9886e000   usbrpm   usbrpm.sys   Mon Jul 13 20:14:30 2009 (4A5BCDE6)
989dd000 989eb000   usbscan  usbscan.sys  Mon Jul 13 20:14:44 2009 (4A5BCDF4)
95000000 95017000   USBSTOR  USBSTOR.SYS  Mon Jul 13 19:51:19 2009 (4A5BC877)
83571000 8357c000   vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)
8b961000 8b96d000   vga      vga.sys      Mon Jul 13 19:25:50 2009 (4A5BC27E)
8b96d000 8b98e000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)
8b77f000 8b787380   vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)
8358d000 8359d000   volmgr   volmgr.sys   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
8359d000 835e8000   volmgrx  volmgrx.sys  Mon Jul 13 19:11:41 2009 (4A5BBF2D)
8b788000 8b7c7000   volsnap  volsnap.sys  Mon Jul 13 19:11:34 2009 (4A5BBF26)
98870000 988a6000   vpchbus  vpchbus.sys  Tue Sep 22 21:18:06 2009 (4AB9774E)
929cf000 929df000   vpcnfltr vpcnfltr.sys Tue Sep 22 21:18:04 2009 (4AB9774C)
98849000 98861000   vpcusb   vpcusb.sys   Tue Sep 22 21:18:08 2009 (4AB97750)
8b8d3000 8b919880   vpcvmm   vpcvmm.sys   Thu Dec 31 01:47:17 2009 (4B3C48F5)
929be000 929cf000   vwififlt vwififlt.sys Mon Jul 13 19:52:03 2009 (4A5BC8A3)
929ed000 92a00000   wanarp   wanarp.sys   Mon Jul 13 19:55:02 2009 (4A5BC956)
8b98e000 8b99b000   watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)
8343b000 834ac000   Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)
834ac000 834ba000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
92998000 9299f000   wfplwf   wfplwf.sys   Mon Jul 13 19:53:51 2009 (4A5BC90F)
9a500000 9a74b000   win32k   win32k.sys   Tue Jan 04 22:37:16 2011 (4D23E76C)
935e3000 935ec000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:19:16 2009 (4A5BC0F4)
83502000 8350b000   WMILIB   WMILIB.SYS   Mon Jul 13 19:11:22 2009 (4A5BBF1A)
9298f000 92998000   ws2ifsl  ws2ifsl.sys  Mon Jul 13 19:55:01 2009 (4A5BC955)
96a76000 96a90000   WudfPf   WudfPf.sys   Mon Jul 13 19:50:13 2009 (4A5BC835)

Unloaded modules:
96a00000 96a21000   WUDFRd.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00021000
96bdc000 96bfd000   WUDFRd.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00021000
9fa59000 9fa71000   parport.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00018000
8b881000 8b88e000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000D000
8b88e000 8b899000   dump_pciidex
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
8b899000 8b8a3000   dump_msahci.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
8b8a3000 8b8b4000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00011000
95000000 95018000   i8042prt.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00018000
8b8d3000 8b92a000   SRTSP.SYS
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00057000
 

Solution
Back
Top