New
#1
BSOD Please help debug
Hello,
Can someone please take a look at my dump file. I get lots of win7 crashes with different error codes, and I'm not sure where to start.
Thanks,
Bill
Hello,
Can someone please take a look at my dump file. I get lots of win7 crashes with different error codes, and I'm not sure where to start.
Thanks,
Bill
Hi and welcome to the forum, please read this tutorial and upload the files to us. We will be glad to help you.
https://www.sevenforums.com/crashes-d...tructions.html
Hi carl,
Thanks for the info interestingly I followed the directions and the perfmon report had an error when it was created. The first file is called $RAM_info.html then I did a manual save to Perfmon-Info.html. All of the files are in the attached zip.
Thanks Again for your time!
Bill
Bill, thanks for uploading the files. I looked at your four most recent dumps and you have quite a few. Each of the four shows a different error code. This usually means a hardware or hardware related problem. All four of the dumps indicate memory corruption. Since no specific cause is given, you will have to troubleshoot.
To begin troubleshooting I recommend that you uninstall Norton/Symantec. Norton is a know cause of BSOD's on some Win 7 systems and it was involved in some of your crashes. Use this removal tool: Tool. Download and install Microsoft Security Essentials in its place and make sure Windows Firewall is turned on. You can reinstall Norton once you get your system stable; but I do not recommend doing so.
Outdated drivers can and do cause memory corruption. I find out of date drivers loaded on your system. Those in red font are really obsolete. Update these drivers or uninstall the software/hardware they are associated with.
iaStorV.sys Wed Apr 08 12:57:17 2009 - Intel Matrix Storage Manager driver (base). http://downloadcenter.intel.com/Default.aspx. Update this driver.
Sahdad64.sys Mon Oct 27 23:56:11 2008 - Unknown driver - suspect it's part of Saitek device (Saitek HDD Filter Driver) Download drivers and software for Saitek products. Update this driver. If no update is available rename it. See Note below.
Saibad64.sys Mon Oct 27 23:56:15 2008 - Saitek Volume Filter Driver. Download drivers and software for Saitek products. Update or uninstall the software or rename this driver.
SaibVdAd64.sys Mon Oct 27 23:56:20 2008 - Saitek Virtual Disk Driver. Download drivers and software for Saitek products. See above.
WibuKey64.sys Wed Nov 22 07:09:49 2006 - WIBU-KEY Software Protection System. WIBU-SYSTEMS: Support. This is XP software. Uninstall it.
NoteRenaming Drivers - using Windows Explorer, navigate to C:\Windows\System32\Drivers, locate the driver files, and rename them from .sys to .bak. Reboot and the drivers will not load. This will break whatever software or hardware these drivers are associated with.
How to find drivers -- I have listed links to most of the drivers in the code box above. Please use the links there to see what info I've found about those drivers.
- search Google for the name of the driver
- compare the Google results with what's installed on your system to figure out which device/program it belongs to
- visit the web site of the manufacturer of the hardware/program to get the latest drivers (DON'T use Windows Update or the Update driver function of Device Manager).
- if there are difficulties in locating them, post back with questions and someone will try and help you locate the appropriate program.
- - The most common drivers are listed on this page: Driver Reference
- - Driver manufacturer links are on this page: Drivers and Downloads
Follow these suggestions and let's see how your system runs. Update us and let us know. If you get another BSOD, upload it to us and we will go from there. If you need help with the drivers, please ask.
Code:Windows 7 Kernel Version 7600 MP (8 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7600.16617.amd64fre.win7_gdr.100618-1621 Machine Name: Kernel base = 0xfffff800`02c62000 PsLoadedModuleList = 0xfffff800`02e9fe50 Debug session time: Wed Dec 8 07:11:40.500 2010 (GMT-5) System Uptime: 0 days 19:50:21.546 Loading Kernel Symbols ............................................................... ................................................................ ............................................ Loading User Symbols Loading unloaded module list ............ ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck A, {fffffac00cc2d03b, 2, 0, fffff80002cdde13} Probably caused by : ntkrnlmp.exe ( nt!KiProcessExpiredTimerList+103 ) Followup: MachineOwner --------- 4: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: fffffac00cc2d03b, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000000, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status) Arg4: fffff80002cdde13, address which referenced memory Debugging Details: ------------------ READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f0a0e0 fffffac00cc2d03b CURRENT_IRQL: 2 FAULTING_IP: nt!KiProcessExpiredTimerList+103 fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh] CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xA PROCESS_NAME: System TRAP_FRAME: fffff880009da450 -- (.trap 0xfffff880009da450) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000000000 rbx=0000000000000000 rcx=000000000cc89403 rdx=fffffa800cc2d3a0 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80002cdde13 rsp=fffff880009da5e0 rbp=fffffac00cc2d010 r8=0000000000000013 r9=0000000000000000 r10=0000000000000063 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na pe nc nt!KiProcessExpiredTimerList+0x103: fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh] ds:00000000`0000002b=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002cd1ca9 to fffff80002cd2740 STACK_TEXT: fffff880`009da308 fffff800`02cd1ca9 : 00000000`0000000a fffffac0`0cc2d03b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx fffff880`009da310 fffff800`02cd0920 : 00000000`00000008 fffffac0`0cc2d010 fffffa80`0b32d5b0 00000000`006cfc00 : nt!KiBugCheckDispatch+0x69 fffff880`009da450 fffff800`02cdde13 : fffffa80`0cc4a060 fffffa80`0e800c68 fffffa80`0e800c68 00000000`00000000 : nt!KiPageFault+0x260 fffff880`009da5e0 fffff800`02cde4be : 000000a6`4a8f2ece fffff880`009dac58 00000000`0045bf63 fffff880`009b51e8 : nt!KiProcessExpiredTimerList+0x103 fffff880`009dac30 fffff800`02cddcb7 : 0000002f`bec484c1 0000002f`0045bf63 0000002f`bec484fe 00000000`00000063 : nt!KiTimerExpiration+0x1be fffff880`009dacd0 fffff800`02cdaeea : fffff880`009b2180 fffff880`009bd0c0 00000000`00000000 fffff880`0165cc50 : nt!KiRetireDpcList+0x277 fffff880`009dad80 00000000`00000000 : fffff880`009db000 fffff880`009d5000 fffff880`009dad40 00000000`00000000 : nt!KiIdleLoop+0x5a STACK_COMMAND: kb FOLLOWUP_IP: nt!KiProcessExpiredTimerList+103 fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh] SYMBOL_STACK_INDEX: 3 SYMBOL_NAME: nt!KiProcessExpiredTimerList+103 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9 FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+103 BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+103 Followup: MachineOwner --------- 4: kd> lmtsmn start end module name fffff880`04a57000 fffff880`04a95000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30) fffff880`00f19000 fffff880`00f70000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106) fffff880`02f32000 fffff880`02fbc000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184) fffff880`047db000 fffff880`047f1000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0) fffff880`011a3000 fffff880`011ae000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB) fffff880`07e20000 fffff880`07e2b000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5) fffff880`01170000 fffff880`01179000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`01179000 fffff880`011a3000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118) fffff960`008e0000 fffff960`00941000 ATMFD ATMFD.DLL unavailable (00000000) fffff880`01b45000 fffff880`01b4c000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D) fffff880`04ab0000 fffff880`04b9d000 BHDrvx64 BHDrvx64.sys Mon Nov 15 18:11:35 2010 (4CE1BE27) fffff880`047ba000 fffff880`047cb000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF) fffff880`02bbf000 fffff880`02bdd000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206) fffff880`0471e000 fffff880`047ba000 ccHPx64 ccHPx64.sys Fri Feb 05 16:05:45 2010 (4B6C8829) fffff960`006a0000 fffff960`006c7000 cdd cdd.dll unavailable (00000000) fffff880`07b76000 fffff880`07b93000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112) fffff880`01b12000 fffff880`01b3c000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`00cf3000 fffff880`00db3000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D) fffff880`01aac000 fffff880`01adc000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E) fffff880`00c95000 fffff880`00cf3000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`0135c000 fffff880`013cf000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814) fffff880`047cb000 fffff880`047db000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1) fffff880`074c9000 fffff880`074d7000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD) fffff880`0467d000 fffff880`04700000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A) fffff880`04700000 fffff880`0471e000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200) fffff880`043a4000 fffff880`043b3000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E) fffff880`01a96000 fffff880`01aac000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`07437000 fffff880`0745f000 Dot4 Dot4.sys Mon Jul 13 20:00:16 2009 (4A5BCA90) fffff880`0745f000 fffff880`07469000 Dot4Prt Dot4Prt.sys Mon Jul 13 20:00:13 2009 (4A5BCA8D) fffff880`07427000 fffff880`07437000 dot4usb dot4usb.sys Mon Jul 13 20:00:20 2009 (4A5BCA94) fffff880`0776a000 fffff880`0778c000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5) fffff880`074e3000 fffff880`074ec000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`074d7000 fffff880`074e3000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`051b8000 fffff880`051cb000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F) fffff880`07469000 fffff880`07475000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574) fffff880`04ca1000 fffff880`04d95000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E) fffff880`04d95000 fffff880`04ddb000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578) fffff880`04309000 fffff880`0437f000 eeCtrl64 eeCtrl64.sys Fri May 21 17:44:45 2010 (4BF6FECD) fffff880`07e00000 fffff880`07e20000 ENG64 ENG64.SYS Wed Sep 15 06:25:35 2010 (4C909F1F) fffff880`0437f000 fffff880`043a4000 EraserUtilRebootDrv EraserUtilRebootDrv.sys Fri May 21 17:44:45 2010 (4BF6FECD) fffff880`07e2b000 fffff880`07fe9000 EX64 EX64.SYS Wed Sep 15 06:33:41 2010 (4C90A105) fffff880`07b93000 fffff880`07bc9000 fastfat fastfat.SYS Mon Jul 13 19:23:28 2009 (4A5BC1F0) fffff880`04de8000 fffff880`04df5000 fdc fdc.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6) fffff880`012a3000 fffff880`012b7000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481) fffff880`05198000 fffff880`051a3000 flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6) fffff880`011ae000 fffff880`011fa000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F) fffff880`015d5000 fffff880`015df000 Fs_Rec Fs_Rec.sys unavailable (00000000) fffff880`01a5c000 fffff880`01a96000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2) fffff880`01600000 fffff880`0164a000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164) fffff880`04c8b000 fffff880`04c98000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0) fffff800`02c19000 fffff800`02c62000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08) fffff880`04c67000 fffff880`04c8b000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5) fffff880`077bf000 fffff880`077d8000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD) fffff880`077d8000 fffff880`077e0080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9) fffff880`077b1000 fffff880`077bf000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE) fffff880`02af7000 fffff880`02bbf000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8) fffff880`017f4000 fffff880`017fd000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA) fffff880`04bd9000 fffff880`04bf7000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`01052000 fffff880`01170000 iaStorV iaStorV.sys Wed Apr 08 12:57:17 2009 (49DCD76D) fffff880`05600000 fffff880`0567b000 IDSvia64 IDSvia64.sys Fri Nov 05 17:13:11 2010 (4CD47367) fffff880`04bc3000 fffff880`04bd9000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD) fffff880`01a00000 fffff880`01a27000 Ironx64 Ironx64.SYS Tue Apr 27 20:48:23 2010 (4BD785D7) fffff880`04a95000 fffff880`04aa4000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116) fffff800`00bb7000 fffff800`00bc1000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB) fffff880`050e9000 fffff880`0512c000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9) fffff880`015aa000 fffff880`015c4000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156) fffff880`017ad000 fffff880`017d8000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4) fffff880`0778c000 fffff880`07791200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93) fffff880`05021000 fffff880`05036000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92) fffff880`051d9000 fffff880`051fc000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295) fffff880`00c3d000 fffff880`00c81000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66) fffff880`051cb000 fffff880`051d9000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C) fffff880`05800000 fffff880`0580f000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116) fffff880`00db3000 fffff880`00dcd000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`02bdd000 fffff880`02bf5000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79) fffff880`02a00000 fffff880`02a2d000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33) fffff880`02a2d000 fffff880`02a7b000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C) fffff880`02a7b000 fffff880`02a9e000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A) fffff880`01baa000 fffff880`01bb5000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`00f79000 fffff880`00f83000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE) fffff880`012fe000 fffff880`0135c000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C) fffff880`04283000 fffff880`0428e000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE) fffff880`015df000 fffff880`015f1000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201) fffff880`0165b000 fffff880`0174d000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184) fffff880`04aa4000 fffff880`04ab0000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8) fffff880`04624000 fffff880`04653000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3) fffff880`051a3000 fffff880`051b8000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD) fffff880`02fbc000 fffff880`02fcb000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6) fffff880`02e00000 fffff880`02e45000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178) fffff880`0174d000 fffff880`017ad000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A) fffff880`01bb5000 fffff880`01bc6000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114) fffff880`04277000 fffff880`04283000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E) fffff800`02c62000 fffff800`0323e000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9) fffff880`01407000 fffff880`015aa000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F) fffff880`01b3c000 fffff880`01b45000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109) fffff880`063f3000 fffff880`063f4180 nvBridge nvBridge.kmd Tue Jul 27 00:54:49 2010 (4C4E6699) fffff880`05811000 fffff880`063f2980 nvlddmkm nvlddmkm.sys Tue Jul 27 00:54:50 2010 (4C4E669A) fffff880`02e4e000 fffff880`02e74000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5) fffff880`00fc3000 fffff880`00fd8000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E) fffff880`00f83000 fffff880`00fb6000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117) fffff880`00e5c000 fffff880`00e63000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115) fffff880`00fed000 fffff880`00ffd000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114) fffff880`015c4000 fffff880`015d5000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF) fffff880`0567d000 fffff880`05723000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF) fffff880`0772d000 fffff880`0776a000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03) fffff880`00c81000 fffff880`00c95000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027) fffff880`012f2000 fffff880`012fde00 PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253) fffff880`04600000 fffff880`04624000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3) fffff880`04653000 fffff880`0466e000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9) fffff880`043b3000 fffff880`043d4000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA) fffff880`043d4000 fffff880`043ee000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1) fffff880`04226000 fffff880`04277000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219) fffff880`063f5000 fffff880`06400000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA) fffff880`01b8f000 fffff880`01b98000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62) fffff880`01b98000 fffff880`01ba1000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62) fffff880`01ba1000 fffff880`01baa000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63) fffff880`00c00000 fffff880`00c3a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A) fffff880`05036000 fffff880`0504e000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92) fffff880`04a00000 fffff880`04a57000 Rt64win7 Rt64win7.sys Mon Mar 22 05:57:14 2010 (4BA73EFA) fffff880`074ee000 fffff880`0772c580 RTKVHD64 RTKVHD64.sys Fri Apr 30 05:05:58 2010 (4BDA9D76) fffff880`017e9000 fffff880`017f4000 Sahdad64 Sahdad64.sys Mon Oct 27 23:56:11 2008 (49068D5B) fffff880`017e0000 fffff880`017e9000 Saibad64 Saibad64.sys Mon Oct 27 23:56:15 2008 (49068D5F) fffff880`01a3b000 fffff880`01a45000 SaibVdAd64 SaibVdAd64.sys Mon Oct 27 23:56:20 2008 (49068D64) fffff880`05723000 fffff880`0572e000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E) fffff880`017d8000 fffff880`017e0000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB) fffff880`07a4e000 fffff880`07ad4000 SRTSP64 SRTSP64.SYS Wed Feb 24 18:59:29 2010 (4B85BD61) fffff880`01a27000 fffff880`01a3b000 SRTSPX64 SRTSPX64.SYS Wed Feb 24 18:59:48 2010 (4B85BD74) fffff880`0504e000 fffff880`050e4000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318) fffff880`05788000 fffff880`057ef000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A) fffff880`0572e000 fffff880`0575b000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4) fffff880`04dfe000 fffff880`04dff480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92) fffff880`01235000 fffff880`012a3000 SYMDS64 SYMDS64.SYS Mon Aug 17 19:35:30 2009 (4A89E942) fffff880`012b7000 fffff880`012f2000 SYMEFA64 SYMEFA64.SYS Wed Apr 21 17:47:39 2010 (4BCF727B) fffff880`02efc000 fffff880`02f32000 SYMEVENT64x86 SYMEVENT64x86.SYS Thu Aug 13 18:28:21 2009 (4A849385) fffff880`02e74000 fffff880`02e86000 SymIMv SymIMv.sys Fri Apr 30 22:12:21 2010 (4BDB8E05) fffff880`02e86000 fffff880`02efc000 SYMTDIV SYMTDIV.SYS Tue May 04 00:38:27 2010 (4BDFA4C3) fffff880`01803000 fffff880`01a00000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458) fffff880`0575b000 fffff880`0576d000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD) fffff880`01be4000 fffff880`01bf1000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E) fffff880`01bc6000 fffff880`01be4000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B) fffff880`02fe6000 fffff880`02ffa000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64) fffff960`005e0000 fffff960`005ea000 TSDDD TSDDD.dll unavailable (00000000) fffff880`04b9d000 fffff880`04bc3000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1) fffff880`07475000 fffff880`074c9000 udfs udfs.sys Mon Jul 13 19:23:37 2009 (4A5BC1F9) fffff880`0512c000 fffff880`0513e000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20) fffff880`07400000 fffff880`0741ac00 usbaudio usbaudio.sys Mon Jul 13 20:06:31 2009 (4A5BCC07) fffff880`07792000 fffff880`077af000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15) fffff880`077af000 fffff880`077b0f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF) fffff880`04c56000 fffff880`04c67000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06) fffff880`0513e000 fffff880`05198000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D) fffff880`04c00000 fffff880`04c56000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07) fffff880`0741b000 fffff880`07427000 usbprint usbprint.sys Mon Jul 13 20:38:18 2009 (4A5BD37A) fffff880`077e1000 fffff880`077fc000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A) fffff880`04ddb000 fffff880`04de8000 usbuhci usbuhci.sys Mon Jul 13 20:06:27 2009 (4A5BCC03) fffff880`00fb6000 fffff880`00fc3000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB) fffff880`01b4c000 fffff880`01b5a000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587) fffff880`01b5a000 fffff880`01b7f000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B) fffff880`0164a000 fffff880`0165a000 vmstorfl vmstorfl.sys unavailable (00000000) fffff880`00fd8000 fffff880`00fed000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`00e00000 fffff880`00e5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141) fffff880`01000000 fffff880`0104c000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128) fffff880`02fcb000 fffff880`02fe6000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED) fffff880`01b7f000 fffff880`01b8f000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F) fffff880`00e66000 fffff880`00f0a000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F) fffff880`00f0a000 fffff880`00f19000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`02e45000 fffff880`02e4e000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6) fffff880`0576d000 fffff880`05787200 WibuKey64 WibuKey64.sys Wed Nov 22 07:09:49 2006 (45643E0D) fffff960`000b0000 fffff960`003bf000 win32k win32k.sys unavailable (00000000) fffff880`04df5000 fffff880`04dfe000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6) fffff880`00f70000 fffff880`00f79000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117) fffff880`05000000 fffff880`05021000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1) fffff880`07ad4000 fffff880`07b05000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE) Unloaded modules: fffff880`07e00000 fffff880`07e20000 ENG64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07e2b000 fffff880`07fe9000 EX64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`0428e000 fffff880`04309000 IDSvia64.sys Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07e00000 fffff880`07e20000 ENG64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07e2b000 fffff880`07fe9000 EX64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07e00000 fffff880`07e20000 ENG64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07e2e000 fffff880`07fec000 EX64.SYS Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`07b05000 fffff880`07b76000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01adc000 fffff880`01aea000 crashdmp.sys Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01aea000 fffff880`01af6000 dump_ataport Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01af6000 fffff880`01aff000 dump_atapi.s Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01aff000 fffff880`01b12000 dump_dumpfve Timestamp: unavailable (00000000) Checksum: 00000000 Debug session time: Thu Dec 2 05:03:18.072 2010 (GMT-5) System Uptime: 1 days 13:50:38.228 Loading Kernel Symbols ............................................................... ................................................................ ............................................. Loading User Symbols Loading unloaded module list ................. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 50, {fffff900c542eb18, 0, fffff96000143188, 0} Could not read faulting driver name Probably caused by : win32k.sys ( win32k!GreGetClipBox+140 ) Followup: MachineOwner --------- 6: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: fffff900c542eb18, memory referenced. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation. Arg3: fffff96000143188, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000000, (reserved) Debugging Details: ------------------ Could not read faulting driver name READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eaa0e0 fffff900c542eb18 FAULTING_IP: win32k!GreGetClipBox+140 fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h] MM_INTERNAL_CODE: 0 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x50 PROCESS_NAME: sidebar.exe CURRENT_IRQL: 0 TRAP_FRAME: fffff88008465150 -- (.trap 0xfffff88008465150) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000000001 rbx=0000000000000000 rcx=fffff900c502e9e0 rdx=fffff88008465300 rsi=0000000000000000 rdi=0000000000000000 rip=fffff96000143188 rsp=fffff880084652e0 rbp=0000000000000001 r8=0000000000000402 r9=0000000000000082 r10=0000000000000000 r11=0000000000000059 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc win32k!GreGetClipBox+0x140: fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h] ds:0001:fffff900`c502eb18=???????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002cf2f14 to fffff80002c72740 STACK_TEXT: fffff880`08464fe8 fffff800`02cf2f14 : 00000000`00000050 fffff900`c542eb18 00000000`00000000 fffff880`08465150 : nt!KeBugCheckEx fffff880`08464ff0 fffff800`02c7082e : 00000000`00000000 fffff880`0846543c fffff900`c4b9de00 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x42837 fffff880`08465150 fffff960`00143188 : fffff900`c00e5010 fffff880`0846543c 00000000`00000001 ffffffff`99042a2a : nt!KiPageFault+0x16e fffff880`084652e0 fffff960`0011579f : fffff900`c06198e0 fffff880`08465520 ffffffff`99042a2a 00000000`24042d7a : win32k!GreGetClipBox+0x140 fffff880`08465370 fffff960`001ad310 : 00000000`00000000 fffff880`08465520 00000000`00000000 00000000`0300f2e0 : win32k!xxxBeginPaint+0x1af fffff880`084653d0 fffff800`02c71993 : fffffa80`0e8b8b60 00000000`00000000 fffffa80`0e8b8b60 fffffa80`0e8b8b01 : win32k!NtUserBeginPaint+0x8c fffff880`084654a0 00000000`7758b3aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0300ede8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7758b3aa STACK_COMMAND: kb FOLLOWUP_IP: win32k!GreGetClipBox+140 fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h] SYMBOL_STACK_INDEX: 3 SYMBOL_NAME: win32k!GreGetClipBox+140 FOLLOWUP_NAME: MachineOwner MODULE_NAME: win32k IMAGE_NAME: win32k.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c FAILURE_BUCKET_ID: X64_0x50_win32k!GreGetClipBox+140 BUCKET_ID: X64_0x50_win32k!GreGetClipBox+140 Followup: MachineOwner --------- Debug session time: Tue Nov 30 15:11:33.300 2010 (GMT-5) System Uptime: 1 days 3:05:42.347 Unable to load image Unknown_Module_4dd5333b`c7e94772, Win32 error 0n2 *** WARNING: Unable to verify timestamp for Unknown_Module_4dd5333b`c7e94772 *** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_4dd5333b`c7e94772 Debugger can not determine kernel base address Loading Kernel Symbols . Loading User Symbols ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 18, {fffffa8009760570, fffffa800a4b18f0, 1, 4000000000} ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057. Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* REFERENCE_BY_POINTER (18) Arguments: Arg1: fffffa8009760570, Object type of the object whose reference count is being lowered Arg2: fffffa800a4b18f0, Object whose reference count is being lowered Arg3: 0000000000000001, Reserved Arg4: 0000004000000000, Reserved The reference count of an object is illegal for the current state of the object. Each time a driver uses a pointer to an object the driver calls a kernel routine to increment the reference count of the object. When the driver is done with the pointer the driver calls another kernel routine to decrement the reference count. Drivers must match calls to the increment and decrement routines. This bugcheck can occur because an object's reference count goes to zero while there are still open handles to the object, in which case the fourth parameter indicates the number of opened handles. It may also occur when the object’s reference count drops below zero whether or not there are open handles to the object, and in that case the fourth parameter contains the actual value of the pointer references count. Debugging Details: ------------------ ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057. CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x18 CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff80002c7f24a to fffff880044039c2 STACK_TEXT: fffff800`041c7c98 fffff800`02c7f24a : 00000000`002bcf70 fffffa80`0c675dd8 fffff800`02df9c40 00000000`00000001 : 0xfffff880`044039c2 fffff800`041c7ca0 00000000`002bcf70 : fffffa80`0c675dd8 fffff800`02df9c40 00000000`00000001 fffff800`02debe80 : 0xfffff800`02c7f24a fffff800`041c7ca8 fffffa80`0c675dd8 : fffff800`02df9c40 00000000`00000001 fffff800`02debe80 fffff800`02c7ccb7 : 0x2bcf70 fffff800`041c7cb0 fffff800`02df9c40 : 00000000`00000001 fffff800`02debe80 fffff800`02c7ccb7 00000041`336f76b8 : 0xfffffa80`0c675dd8 fffff800`041c7cb8 00000000`00000001 : fffff800`02debe80 fffff800`02c7ccb7 00000041`336f76b8 00000041`336f6fe9 : 0xfffff800`02df9c40 fffff800`041c7cc0 fffff800`02debe80 : fffff800`02c7ccb7 00000041`336f76b8 00000041`336f6fe9 00000041`336f76b8 : 0x1 fffff800`041c7cc8 fffff800`02c7ccb7 : 00000041`336f76b8 00000041`336f6fe9 00000041`336f76b8 00000000`00000095 : 0xfffff800`02debe80 fffff800`041c7cd0 00000041`336f76b8 : 00000041`336f6fe9 00000041`336f76b8 00000000`00000095 fffffa80`0c675d40 : 0xfffff800`02c7ccb7 fffff800`041c7cd8 00000041`336f6fe9 : 00000041`336f76b8 00000000`00000095 fffffa80`0c675d40 400000c2`400000c1 : 0x41`336f76b8 fffff800`041c7ce0 00000041`336f76b8 : 00000000`00000095 fffffa80`0c675d40 400000c2`400000c1 0000000b`400000c3 : 0x41`336f6fe9 fffff800`041c7ce8 00000000`00000095 : fffffa80`0c675d40 400000c2`400000c1 0000000b`400000c3 0000003d`0c72f543 : 0x41`336f76b8 fffff800`041c7cf0 fffffa80`0c675d40 : 400000c2`400000c1 0000000b`400000c3 0000003d`0c72f543 fffff800`041c1080 : 0x95 fffff800`041c7cf8 400000c2`400000c1 : 0000000b`400000c3 0000003d`0c72f543 fffff800`041c1080 fffffa80`0973f890 : 0xfffffa80`0c675d40 fffff800`041c7d00 0000000b`400000c3 : 0000003d`0c72f543 fffff800`041c1080 fffffa80`0973f890 00000000`00000000 : 0x400000c2`400000c1 fffff800`041c7d08 0000003d`0c72f543 : fffff800`041c1080 fffffa80`0973f890 00000000`00000000 000104cd`07083b40 : 0xb`400000c3 fffff800`041c7d10 fffff800`041c1080 : fffffa80`0973f890 00000000`00000000 000104cd`07083b40 000104cd`07083ff0 : 0x3d`0c72f543 fffff800`041c7d18 fffffa80`0973f890 : 00000000`00000000 000104cd`07083b40 000104cd`07083ff0 fffff800`02c779a2 : 0xfffff800`041c1080 fffff800`041c7d20 00000000`00000000 : 000104cd`07083b40 000104cd`07083ff0 fffff800`02c779a2 fffff800`041c1080 : 0xfffffa80`0973f890 STACK_COMMAND: kb SYMBOL_NAME: ANALYSIS_INCONCLUSIVE FOLLOWUP_NAME: MachineOwner MODULE_NAME: Unknown_Module IMAGE_NAME: Unknown_Image DEBUG_FLR_IMAGE_TIMESTAMP: 0 BUCKET_ID: CORRUPT_MODULELIST Followup: MachineOwner --------- Debug session time: Fri Nov 26 10:14:15.009 2010 (GMT-5) System Uptime: 0 days 2:26:58.181 Loading Kernel Symbols ............................................................... ................................................................ ............................................. Loading User Symbols Loading unloaded module list ....... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff960001a000b, fffff880026b5010, 0} Probably caused by : win32k.sys ( win32k!zzzSetDesktop+187 ) Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff960001a000b, Address of the exception record for the exception that caused the bugcheck Arg3: fffff880026b5010, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. FAULTING_IP: win32k!zzzSetDesktop+187 fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h] CONTEXT: fffff880026b5010 -- (.cxr 0xfffff880026b5010) rax=0000000000000389 rbx=fffff900c00f5c30 rcx=fffffa800c45a400 rdx=fffff900c0aed270 rsi=0000000000000000 rdi=0000000000000000 rip=fffff960001a000b rsp=fffff880026b59e0 rbp=0000000000000000 r8=0000000000000000 r9=00000000ffffffff r10=0000000000002407 r11=fffff900c00f5c30 r12=fffff900c0c14a50 r13=0000000000000000 r14=0000000000000001 r15=fffffa800c45a400 iopl=0 nv up ei ng nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286 win32k!zzzSetDesktop+0x187: fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h] ds:002b:fffff900`c00f5e98=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: csrss.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff960001612bd to fffff960001a000b STACK_TEXT: fffff880`026b59e0 fffff960`001612bd : fffff900`c00f5c30 00000000`00000000 fffffa80`0cc93b80 fffff800`000025ff : win32k!zzzSetDesktop+0x187 fffff880`026b5ac0 fffff960`00161448 : fffff880`026b5bf8 fffffa80`0b7d6b60 fffff880`026b5bf0 00000000`00000003 : win32k!xxxSetThreadDesktop+0x1ad fffff880`026b5b10 fffff960`00160fe1 : 00000000`00000000 fffff880`026b5bf0 00000000`00000000 fffff800`02c7d1e3 : win32k!xxxRestoreCsrssThreadDesktop+0x64 fffff880`026b5b80 fffff960`00160e8d : 00000000`00000018 fffff880`026b5ca0 00000000`00000018 00000000`01f2f508 : win32k!xxxSetInformationThread+0xf9 fffff880`026b5bd0 fffff800`02c70993 : fffffa80`0b7d6b60 00000000`00000000 00000000`00000020 00000000`00000000 : win32k!NtUserSetInformationThread+0xbd fffff880`026b5c20 000007fe`fd131c2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`01f2f4b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd131c2a FOLLOWUP_IP: win32k!zzzSetDesktop+187 fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h] SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: win32k!zzzSetDesktop+187 FOLLOWUP_NAME: MachineOwner MODULE_NAME: win32k IMAGE_NAME: win32k.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c STACK_COMMAND: .cxr 0xfffff880026b5010 ; kb FAILURE_BUCKET_ID: X64_0x3B_win32k!zzzSetDesktop+187 BUCKET_ID: X64_0x3B_win32k!zzzSetDesktop+187 Followup: MachineOwner ---------
Team,
I removed Norton and loaded the MS anti-virus you suggested also updated the intel driver. I'll give this a try for a while to see what happens. What is the "Intel Matrix Storage Manager driver" for, is it the intel SS drive or the RAID?
I also have had many problems with the driver for the Nvidia graphics card causing crashes with the newest driver so I went back to an older driver, but noticed I had to disable the option for letting the "3d app decide the performance" and just set "use my preference, Quality" as it seemed that the graphics card was switching modes and causing problems.
Thanks, I'll let you know what happens-
Bill
Bill, graphics drivers can be very finicky; I had to use an older driver with my NVidia card, too. I cannot tell you precisely what the Intel Matrix Storage Manager driver is for. I have it on my system and I have neither RAID not SSD. It is part of the basic Intel driver set.
Please do keep us updated. And good luck!
Hello again,
I've been very busy with an large animation so I've been putting up with the crashes.
I've upgraded my Power supply to 800W, and reworked my liquid cooler (now running at 32deg C normally) I've downloaded a few new drivers.
I'm mostly getting a IRQL_NOT_EQUAL error or a Iastorv.sys error on my crashes so I loaded the latest Win 64X Intel Matrix driever for RIAD, now I'm getting a IAstor.sys error (maybe a wrong driver?). the Perfmon report says there is no Anti-Virus (which there is- MS essentials). I'm sure where to go at this point.
Attached is the latest dump zip...
Hopefully someone can make some sense out of this.
Thanks,
Bill
Hi, Bill. At this point you need to update your outdated drivers or eliminate them by uninstalling whatever they are associated with or renaming them - which will break whatever they are associated with. Start with the 2006 driver it is and XP driver and it involves security, either of which can cause conflicts and crashes. If there is no update for iaStorV.sys, ignore it for now. It is a Vista driver and may work.
iaStorV.sys Wed Apr 08 12:57:17 2009 - Intel Matrix Storage Manager driver (base). http://downloadcenter.intel.com/Default.aspx. Update this driver.
Sahdad64.sys Mon Oct 27 23:56:11 2008 - Unknown driver - suspect it's part of Saitek device (Saitek HDD Filter Driver) Download drivers and software for Saitek products. Update this driver. If no update is available rename it. See Note below.
Saibad64.sys Mon Oct 27 23:56:15 2008 - Saitek Volume Filter Driver. Download drivers and software for Saitek products. Update or uninstall the software or rename this driver.
SaibVdAd64.sys Mon Oct 27 23:56:20 2008 - Saitek Virtual Disk Driver. Download drivers and software for Saitek products. See above.
WibuKey64.sys Wed Nov 22 07:09:49 2006 - WIBU-KEY Software Protection System. WIBU-SYSTEMS: Support. This is XP software. Uninstall it.
You are running a RAID array. Win 7 is very finicky about RAID. It is too early to tell if RAID was involved in the crashes.
Code:Windows 7 Kernel Version 7600 MP (8 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7600.16617.amd64fre.win7_gdr.100618-1621 Machine Name: Kernel base = 0xfffff800`02e5c000 PsLoadedModuleList = 0xfffff800`03099e50 Debug session time: Thu Jan 27 18:30:10.084 2011 (GMT-5) System Uptime: 0 days 1:32:31.131 Loading Kernel Symbols ................................................... Loading User Symbols ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck A, {fffffac00ced1ba0, 2, 1, fffff80002ed62a9} Probably caused by : ntkrnlmp.exe ( nt!KiTimerWaitTest+189 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: fffffac00ced1ba0, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status) Arg4: fffff80002ed62a9, address which referenced memory Debugging Details: ------------------ WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800031040e0 fffffac00ced1ba0 CURRENT_IRQL: 0 FAULTING_IP: nt!KiTimerWaitTest+189 fffff800`02ed62a9 f0490fba6c244000 lock bts qword ptr [r12+40h],0 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xA PROCESS_NAME: System LAST_CONTROL_TRANSFER: from fffff80002eda24a to fffff880014349c2 STACK_TEXT: fffff800`00b9cc98 fffff800`02eda24a : 00000000`002bcf66 fffffa80`0bb9f868 fffff800`03054c40 00000000`00000001 : 0xfffff880`014349c2 fffff800`00b9cca0 fffff800`02ed4ebc : fffff800`03046e80 fffff800`00000000 00000000`00000000 fffff880`040e0db0 : nt!PoIdle+0x53a fffff800`00b9cd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c STACK_COMMAND: .bugcheck ; kb FOLLOWUP_IP: nt!KiTimerWaitTest+189 fffff800`02ed62a9 f0490fba6c244000 lock bts qword ptr [r12+40h],0 SYMBOL_NAME: nt!KiTimerWaitTest+189 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9 FAILURE_BUCKET_ID: X64_0xA_nt!KiTimerWaitTest+189 BUCKET_ID: X64_0xA_nt!KiTimerWaitTest+189 Followup: MachineOwner --------- Debug session time: Thu Jan 27 00:31:51.238 2011 (GMT-5) System Uptime: 0 days 0:24:05.269 Loading Kernel Symbols ............................................................... ................................................................ ........................... Loading User Symbols Loading unloaded module list ...... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck A, {fffffac00d1e9798, 2, 1, fffff80002ccde36} Probably caused by : ntkrnlmp.exe ( nt!KiProcessExpiredTimerList+126 ) Followup: MachineOwner --------- 4: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: fffffac00d1e9798, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status) Arg4: fffff80002ccde36, address which referenced memory Debugging Details: ------------------ WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002efa0e0 fffffac00d1e9798 CURRENT_IRQL: 2 FAULTING_IP: nt!KiProcessExpiredTimerList+126 fffff800`02ccde36 488908 mov qword ptr [rax],rcx CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xA PROCESS_NAME: System TRAP_FRAME: fffff880009da450 -- (.trap 0xfffff880009da450) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=fffffac00d1e9798 rbx=0000000000000000 rcx=fffffa800d1e9798 rdx=fffffa800b4c9f40 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80002ccde36 rsp=fffff880009da5e0 rbp=fffffa800b4c9a00 r8=000000000000001c r9=0000000000000000 r10=0000000000000051 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc nt!KiProcessExpiredTimerList+0x126: fffff800`02ccde36 488908 mov qword ptr [rax],rcx ds:fffffac0`0d1e9798=???????????????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002cc1ca9 to fffff80002cc2740 STACK_TEXT: fffff880`009da308 fffff800`02cc1ca9 : 00000000`0000000a fffffac0`0d1e9798 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx fffff880`009da310 fffff800`02cc0920 : 00000000`00000008 fffffa80`0b4c9a00 fffffa80`0b3355b0 00000000`0002353c : nt!KiBugCheckDispatch+0x69 fffff880`009da450 fffff800`02ccde36 : fffffa80`0c4839f0 fffffa80`0cff8450 fffffa80`0cff8450 00000000`00000000 : nt!KiPageFault+0x260 fffff880`009da5e0 fffff800`02cce4be : 00000003`5d72a110 fffff880`009dac58 00000000`00016951 fffff880`009b4fa8 : nt!KiProcessExpiredTimerList+0x126 fffff880`009dac30 fffff800`02ccdcb7 : 00000000`f78622c1 00000000`00016951 00000000`f78622f1 00000000`00000051 : nt!KiTimerExpiration+0x1be fffff880`009dacd0 fffff800`02ccaeea : fffff880`009b2180 fffff880`009bd0c0 00000000`00000000 fffff800`02de2da0 : nt!KiRetireDpcList+0x277 fffff880`009dad80 00000000`00000000 : fffff880`009db000 fffff880`009d5000 fffff880`009dad40 00000000`00000000 : nt!KiIdleLoop+0x5a STACK_COMMAND: kb FOLLOWUP_IP: nt!KiProcessExpiredTimerList+126 fffff800`02ccde36 488908 mov qword ptr [rax],rcx SYMBOL_STACK_INDEX: 3 SYMBOL_NAME: nt!KiProcessExpiredTimerList+126 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9 FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+126 BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+126 Followup: MachineOwner --------- 4: kd> lmtsmn start end module name fffff880`04320000 fffff880`0435e000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30) fffff880`00f90000 fffff880`00fe7000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106) fffff880`02c00000 fffff880`02c8a000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184) fffff880`043c0000 fffff880`043d6000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0) fffff880`0102a000 fffff880`01035000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB) fffff880`05e71000 fffff880`05e7c000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5) fffff880`011cf000 fffff880`011d8000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`01000000 fffff880`0102a000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118) fffff960`00990000 fffff960`009f1000 ATMFD ATMFD.DLL unavailable (00000000) fffff880`02d3b000 fffff880`02d42000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D) fffff880`0415d000 fffff880`0416e000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF) fffff880`04ba3000 fffff880`04bc1000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206) fffff960`00720000 fffff960`00747000 cdd cdd.dll unavailable (00000000) fffff880`02cd7000 fffff880`02d01000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`00d0f000 fffff880`00dcf000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D) fffff880`00c00000 fffff880`00c30000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E) fffff880`00cb1000 fffff880`00d0f000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`014a5000 fffff880`01518000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814) fffff880`043b0000 fffff880`043c0000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1) fffff880`02ae0000 fffff880`02ae9000 cpuz135_x64 cpuz135_x64.sys Tue Nov 09 08:33:36 2010 (4CD94DB0) fffff880`0673d000 fffff880`0674b000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD) fffff880`040bc000 fffff880`0413f000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A) fffff880`0413f000 fffff880`0415d000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200) fffff880`040ad000 fffff880`040bc000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E) fffff880`015e8000 fffff880`015fe000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`066ff000 fffff880`06727000 Dot4 Dot4.sys Mon Jul 13 20:00:16 2009 (4A5BCA90) fffff880`06727000 fffff880`06731000 Dot4Prt Dot4Prt.sys Mon Jul 13 20:00:13 2009 (4A5BCA8D) fffff880`066ef000 fffff880`066ff000 dot4usb dot4usb.sys Mon Jul 13 20:00:20 2009 (4A5BCA94) fffff880`06681000 fffff880`066a3000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5) fffff880`06757000 fffff880`06760000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`0674b000 fffff880`06757000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`06760000 fffff880`06773000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F) fffff880`06731000 fffff880`0673d000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574) fffff880`10ac7000 fffff880`10bbb000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E) fffff880`0fe00000 fffff880`0fe46000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578) fffff880`0435e000 fffff880`0436b000 fdc fdc.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6) fffff880`01081000 fffff880`01095000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481) fffff880`04abb000 fffff880`04ac6000 flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6) fffff880`01035000 fffff880`01081000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F) fffff880`01529000 fffff880`01533000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111) fffff880`013c5000 fffff880`013ff000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2) fffff880`0168b000 fffff880`016d5000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164) fffff880`10bdf000 fffff880`10bec000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0) fffff800`02c09000 fffff800`02c52000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08) fffff880`10bbb000 fffff880`10bdf000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5) fffff880`04adb000 fffff880`04ba3000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8) fffff880`017f4000 fffff880`017fd000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA) fffff880`0436b000 fffff880`04389000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`010b1000 fffff880`011cf000 iaStorV iaStorV.sys Wed Apr 08 12:57:17 2009 (49DCD76D) fffff880`04194000 fffff880`041aa000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD) fffff880`04398000 fffff880`043a7000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116) fffff800`00bba000 fffff800`00bc4000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB) fffff880`04000000 fffff880`04043000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9) fffff880`0148b000 fffff880`014a5000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156) fffff880`01660000 fffff880`0168b000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4) fffff880`066a3000 fffff880`066a8200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93) fffff880`067c5000 fffff880`067da000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92) fffff880`06781000 fffff880`067a4000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295) fffff880`00c59000 fffff880`00c9d000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66) fffff880`06773000 fffff880`06781000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C) fffff880`04389000 fffff880`04398000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116) fffff880`00dcf000 fffff880`00de9000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`02d01000 fffff880`02d32000 MpFilter MpFilter.sys Tue Sep 14 20:19:28 2010 (4C901110) fffff880`02b8f000 fffff880`02b9f000 MpNWMon MpNWMon.sys Tue Sep 14 20:19:30 2010 (4C901112) fffff880`04bc1000 fffff880`04bd9000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79) fffff880`04a00000 fffff880`04a2d000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33) fffff880`02a6f000 fffff880`02abd000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C) fffff880`02abd000 fffff880`02ae0000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A) fffff880`02da0000 fffff880`02dab000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113) fffff880`00ff0000 fffff880`00ffa000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE) fffff880`0142d000 fffff880`0148b000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C) fffff880`040a2000 fffff880`040ad000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE) fffff880`015d6000 fffff880`015e8000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201) fffff880`016f7000 fffff880`017e9000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184) fffff880`04200000 fffff880`0420c000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8) fffff880`0420c000 fffff880`0423b000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3) fffff880`04ac6000 fffff880`04adb000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD) fffff880`02df0000 fffff880`02dff000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6) fffff880`02c8a000 fffff880`02ccf000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178) fffff880`01600000 fffff880`01660000 NETIO NETIO.SYS Thu Apr 08 22:43:59 2010 (4BBE946F) fffff880`05f91000 fffff880`05fa6000 NisDrvWFP NisDrvWFP.sys Tue Sep 14 20:20:25 2010 (4C901149) fffff880`02dab000 fffff880`02dbc000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114) fffff880`04096000 fffff880`040a2000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E) fffff800`02c52000 fffff800`0322e000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9) fffff880`01222000 fffff880`013c5000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F) fffff880`02d32000 fffff880`02d3b000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109) fffff880`10ac5000 fffff880`10ac6180 nvBridge nvBridge.kmd Mon Dec 27 21:22:41 2010 (4D1949F1) fffff880`0fe6a000 fffff880`10ac4d80 nvlddmkm nvlddmkm.sys Mon Dec 27 21:26:53 2010 (4D194AED) fffff880`011d8000 fffff880`011fe000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5) fffff880`00e40000 fffff880`00e55000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E) fffff880`00e00000 fffff880`00e33000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117) fffff880`00ec6000 fffff880`00ecd000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115) fffff880`00ecd000 fffff880`00edd000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114) fffff880`01518000 fffff880`01529000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF) fffff880`02ae9000 fffff880`02b8f000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF) fffff880`06644000 fffff880`06681000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03) fffff880`00c9d000 fffff880`00cb1000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027) fffff880`01095000 fffff880`010a0e00 PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253) fffff880`043d6000 fffff880`043fa000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3) fffff880`0423b000 fffff880`04256000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9) fffff880`04256000 fffff880`04277000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA) fffff880`04277000 fffff880`04291000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1) fffff880`04045000 fffff880`04096000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219) fffff880`04291000 fffff880`0429c000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA) fffff880`02d85000 fffff880`02d8e000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62) fffff880`02d8e000 fffff880`02d97000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62) fffff880`02d97000 fffff880`02da0000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63) fffff880`0159c000 fffff880`015d6000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A) fffff880`067da000 fffff880`067f2000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92) fffff880`042ba000 fffff880`04320000 Rt64win7 Rt64win7.sys Thu Nov 11 01:35:36 2010 (4CDB8EB8) fffff880`06405000 fffff880`06643580 RTKVHD64 RTKVHD64.sys Fri Apr 30 05:05:58 2010 (4BDA9D76) fffff880`017e9000 fffff880`017f4000 Sahdad64 Sahdad64.sys Mon Oct 27 23:56:11 2008 (49068D5B) fffff880`016ed000 fffff880`016f6000 Saibad64 Saibad64.sys Mon Oct 27 23:56:15 2008 (49068D5F) fffff880`01423000 fffff880`0142d000 SaibVdAd64 SaibVdAd64.sys Mon Oct 27 23:56:20 2008 (49068D64) fffff880`0157f000 fffff880`0159c000 sbp2port sbp2port.sys Mon Jul 13 19:19:53 2009 (4A5BC119) fffff880`02b9f000 fffff880`02baa000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E) fffff880`016e5000 fffff880`016ed000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB) fffff880`05efb000 fffff880`05f91000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318) fffff880`05e94000 fffff880`05efb000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A) fffff880`02baa000 fffff880`02bd7000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4) fffff880`0429c000 fffff880`0429d480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92) fffff880`01802000 fffff880`019ff000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458) fffff880`02bd7000 fffff880`02be9000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD) fffff880`02dda000 fffff880`02de7000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E) fffff880`02dbc000 fffff880`02dda000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B) fffff880`00de9000 fffff880`00dfd000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64) fffff960`005e0000 fffff960`005ea000 TSDDD TSDDD.dll unavailable (00000000) fffff880`0416e000 fffff880`04194000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1) fffff880`0429e000 fffff880`042b0000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20) fffff880`066a9000 fffff880`066c6000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15) fffff880`066c6000 fffff880`066c7f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF) fffff880`0fe53000 fffff880`0fe64000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06) fffff880`04a61000 fffff880`04abb000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D) fffff880`041aa000 fffff880`04200000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07) fffff880`066e3000 fffff880`066ef000 usbprint usbprint.sys Mon Jul 13 20:38:18 2009 (4A5BD37A) fffff880`066c8000 fffff880`066e3000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A) fffff880`0fe46000 fffff880`0fe53000 usbuhci usbuhci.sys Mon Jul 13 20:06:27 2009 (4A5BCC03) fffff880`00e33000 fffff880`00e40000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB) fffff880`02d42000 fffff880`02d50000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587) fffff880`02d50000 fffff880`02d75000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B) fffff880`016d5000 fffff880`016e5000 vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E) fffff880`00e55000 fffff880`00e6a000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D) fffff880`00e6a000 fffff880`00ec6000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141) fffff880`01533000 fffff880`0157f000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128) fffff880`00c30000 fffff880`00c4b000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED) fffff880`02d75000 fffff880`02d85000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F) fffff880`00edd000 fffff880`00f81000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F) fffff880`00f81000 fffff880`00f90000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A) fffff880`02de7000 fffff880`02df0000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6) fffff880`02a00000 fffff880`02a1a200 WibuKey64 WibuKey64.sys Wed Nov 22 07:09:49 2006 (45643E0D) fffff960`00000000 fffff960`00310000 win32k win32k.sys unavailable (00000000) fffff880`043a7000 fffff880`043b0000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6) fffff880`00fe7000 fffff880`00ff0000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117) fffff880`067a4000 fffff880`067c5000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1) fffff880`05fa6000 fffff880`05fd7000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE) Unloaded modules: fffff880`05e7c000 fffff880`05e8f000 GenericMount Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`05e00000 fffff880`05e71000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01400000 fffff880`0140e000 crashdmp.sys Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`0140e000 fffff880`0141a000 dump_ataport Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`0141a000 fffff880`01423000 dump_atapi.s Timestamp: unavailable (00000000) Checksum: 00000000 fffff880`01200000 fffff880`01213000 dump_dumpfve Timestamp: unavailable (00000000) Checksum: 00000000 Debug session time: Thu Jan 27 19:11:01.683 2011 (GMT-5) System Uptime: 0 days 0:27:02.714 Loading Kernel Symbols ............................................................... ................................................................ ............................. Loading User Symbols Loading unloaded module list ..... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 50, {fffffac00ab91ff0, 0, fffff880012a459c, 5} Unable to load image \SystemRoot\system32\DRIVERS\iaStor.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Could not read faulting driver name Probably caused by : iaStor.sys ( iaStor+d59c ) Followup: MachineOwner --------- 5: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: fffffac00ab91ff0, memory referenced. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation. Arg3: fffff880012a459c, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000005, (reserved) Debugging Details: ------------------ Could not read faulting driver name READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030bd0e0 fffffac00ab91ff0 FAULTING_IP: iaStor+d59c fffff880`012a459c 488b7718 mov rsi,qword ptr [rdi+18h] MM_INTERNAL_CODE: 5 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x50 PROCESS_NAME: System CURRENT_IRQL: 0 TRAP_FRAME: fffff88003947a10 -- (.trap 0xfffff88003947a10) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=fffffa800ac56d78 rbx=0000000000000000 rcx=fffffa800aa897a8 rdx=0000000000000004 rsi=0000000000000000 rdi=0000000000000000 rip=fffff880012a459c rsp=fffff88003947ba0 rbp=0000000000000000 r8=fffffa800a619ca8 r9=00000000038fefff r10=fffffa800a619ca8 r11=0000000000000001 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc iaStor+0xd59c: fffff880`012a459c 488b7718 mov rsi,qword ptr [rdi+18h] ds:aa60:00000000`00000018=???????????????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002f048c1 to fffff80002e85740 STACK_TEXT: fffff880`039478a8 fffff800`02f048c1 : 00000000`00000050 fffffac0`0ab91ff0 00000000`00000000 fffff880`03947a10 : nt!KeBugCheckEx fffff880`039478b0 fffff800`02e8382e : 00000000`00000000 fffffa80`0aa897a8 fffff880`03947d00 fffffa80`0a11b030 : nt! ?? ::FNODOBFM::`string'+0x40e8b fffff880`03947a10 fffff880`012a459c : fffffa80`0bffcc30 fffffa80`0e8ff350 fffff880`009b7040 fffff880`012b83d4 : nt!KiPageFault+0x16e fffff880`03947ba0 fffffa80`0bffcc30 : fffffa80`0e8ff350 fffff880`009b7040 fffff880`012b83d4 00000000`00000003 : iaStor+0xd59c fffff880`03947ba8 fffffa80`0e8ff350 : fffff880`009b7040 fffff880`012b83d4 00000000`00000003 fffff880`012a5363 : 0xfffffa80`0bffcc30 fffff880`03947bb0 fffff880`009b7040 : fffff880`012b83d4 00000000`00000003 fffff880`012a5363 fffffa80`0abd7738 : 0xfffffa80`0e8ff350 fffff880`03947bb8 fffff880`012b83d4 : 00000000`00000003 fffff880`012a5363 fffffa80`0abd7738 00000000`00000080 : 0xfffff880`009b7040 fffff880`03947bc0 00000000`00000003 : fffff880`012a5363 fffffa80`0abd7738 00000000`00000080 00000000`00000428 : iaStor+0x213d4 fffff880`03947bc8 fffff880`012a5363 : fffffa80`0abd7738 00000000`00000080 00000000`00000428 fffffa80`0a616518 : 0x3 fffff880`03947bd0 fffffa80`0abd7738 : 00000000`00000080 00000000`00000428 fffffa80`0a616518 fffffa80`0a616518 : iaStor+0xe363 fffff880`03947bd8 00000000`00000080 : 00000000`00000428 fffffa80`0a616518 fffffa80`0a616518 fffff880`012dbadf : 0xfffffa80`0abd7738 fffff880`03947be0 00000000`00000428 : fffffa80`0a616518 fffffa80`0a616518 fffff880`012dbadf fffffa80`0a8885b0 : 0x80 fffff880`03947be8 fffffa80`0a616518 : fffffa80`0a616518 fffff880`012dbadf fffffa80`0a8885b0 fffffa80`0ac56d90 : 0x428 fffff880`03947bf0 fffffa80`0a616518 : fffff880`012dbadf fffffa80`0a8885b0 fffffa80`0ac56d90 fffffa80`0a616de0 : 0xfffffa80`0a616518 fffff880`03947bf8 fffff880`012dbadf : fffffa80`0a8885b0 fffffa80`0ac56d90 fffffa80`0a616de0 fffff880`012a591e : 0xfffffa80`0a616518 fffff880`03947c00 fffffa80`0a8885b0 : fffffa80`0ac56d90 fffffa80`0a616de0 fffff880`012a591e 00000000`00000000 : iaStor+0x44adf fffff880`03947c08 fffffa80`0ac56d90 : fffffa80`0a616de0 fffff880`012a591e 00000000`00000000 fffffa80`0a9dfa38 : 0xfffffa80`0a8885b0 fffff880`03947c10 fffffa80`0a616de0 : fffff880`012a591e 00000000`00000000 fffffa80`0a9dfa38 fffffa80`0aa47cb8 : 0xfffffa80`0ac56d90 fffff880`03947c18 fffff880`012a591e : 00000000`00000000 fffffa80`0a9dfa38 fffffa80`0aa47cb8 fffff880`012b4700 : 0xfffffa80`0a616de0 fffff880`03947c20 00000000`00000000 : fffffa80`0a9dfa38 fffffa80`0aa47cb8 fffff880`012b4700 00000000`000007ff : iaStor+0xe91e STACK_COMMAND: kb FOLLOWUP_IP: iaStor+d59c fffff880`012a459c 488b7718 mov rsi,qword ptr [rdi+18h] SYMBOL_STACK_INDEX: 3 SYMBOL_NAME: iaStor+d59c FOLLOWUP_NAME: MachineOwner MODULE_NAME: iaStor IMAGE_NAME: iaStor.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4cd50774 FAILURE_BUCKET_ID: X64_0x50_iaStor+d59c BUCKET_ID: X64_0x50_iaStor+d59c Followup: MachineOwner ---------
Hi Carl,
Thanks for taking the time to go thru this again. I removed the WIBU drivers and re-boot was fine. But I couldn't figure out what the Saitek drivers are for or where to uninstall them. I was on their website but couldn't find any of their products I use. So then I renamed them but then my PC wouldn't boot so I renamed them back to their original names and it started up again.
Also I can't find an IastorV.sys driver on Intel drivers page, when I run their software "Driver Update utility" it doesn't check this driver?
The good news is my PC has not crashed yet, so I'm keeping my fingers crossed!
Bill
Hello Again,
I dug around a bit in the registry and found that the SAI*.sys files were loading with Roxio CD creator 2010 Pro. This actually loads when installing CD creator(actually a sub-program "Back on track home") which is a recovery program. Although I don't use the recovery program I do use CD creator. I un-installed and re-installed, but there is no option not to install without this recovery program. So for now it stays, unless I keep crashing, then I find another CD creator.
Thanks-
Bill