Uninstall Symantec:
Download and run the Norton Removal Tool to uninstall your Norton product | Norton Support
Install MSE:
http://www.microsoft.com/security_essentials/
Remove Daemon Tools:
sptd.sys Sun Oct 11 16:55:14 2009
Use this tool to remove its driver sptd.sys:
DuplexSecure - FAQ
Update:
viahduaa.sys Mon Aug 17 07:20:43 2009
VIA Audio
Crash Dumps:
Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121510-18408-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e1f000 PsLoadedModuleList = 0xfffff800`0305ce50
Debug session time: Wed Dec 15 13:37:52.493 2010 (UTC - 5:00)
System Uptime: 0 days 0:12:46.101
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {31, fffffa8003fbd5c0, fffff88002c15000, fffff8a00c3782fb}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::NNGAKEGL::`string'+6368 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000031, The subtype of the bugcheck.
Arg2: fffffa8003fbd5c0
Arg3: fffff88002c15000
Arg4: fffff8a00c3782fb
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_31
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800031bb74d to fffff80002e8f740
STACK_TEXT:
fffff880`0692f078 fffff800`031bb74d : 00000000`0000001a 00000000`00000031 fffffa80`03fbd5c0 fffff880`02c15000 : nt!KeBugCheckEx
fffff880`0692f080 fffff800`031770b1 : fffff880`02c15000 00000000`02550000 00000000`00023000 fffffa80`002c5c80 : nt! ?? ::NNGAKEGL::`string'+0x6368
fffff880`0692f0d0 fffff800`03164344 : 00000000`00000000 00000000`00000000 fffff6fc`40013f88 fffff800`00000000 : nt!MiPerformFixups+0x65
fffff880`0692f120 fffff800`02e7168d : 00000000`0000ec98 00000000`00000023 fffff8a0`088129d0 00000000`00000002 : nt!MiRelocateImagePfn+0x114
fffff880`0692f180 fffff800`0317700d : fffffa80`05210510 fffff6fc`40013f88 fffff8a0`00000002 00000000`00000000 : nt!MiValidateImagePages+0x2bd
fffff880`0692f220 fffff800`03176720 : ffffffff`ffffffff 00000000`00000001 fffff8a0`0c377000 00000000`00000007 : nt!MiSwitchBaseAddress+0x61
fffff880`0692f250 fffff800`0318a7ce : 00000000`00000004 00000000`01000000 00000000`00000000 00000000`00000000 : nt!MiRelocateImageAgain+0x100
fffff880`0692f2a0 fffff800`03180013 : fffff880`0692f500 00000000`00000000 fffff880`0692f5a8 fffff880`0692f4f8 : nt!MmCreateSection+0x302
fffff880`0692f4b0 fffff800`032eb6b5 : fffff8a0`0f749690 00000000`00000000 00000000`00000001 00000002`00000000 : nt!NtCreateSection+0x162
fffff880`0692f530 fffff800`032eba67 : 00000000`00000010 fffff8a0`0f53db20 fffff880`0692f6c0 00000000`0000002c : nt!PfSnGetSectionObject+0x2d5
fffff880`0692f620 fffff800`032ebe97 : fffff880`0692f740 00000000`00000001 00000000`00000000 00000000`00000000 : nt!PfSnPrefetchSections+0x247
fffff880`0692f710 fffff800`032ec2bf : 00000002`839fc9b9 fffffa80`0790b060 fffff8a0`0f8e2000 00000000`c00000ce : nt!PfSnPrefetchScenario+0x187
fffff880`0692f980 fffff800`030e46df : 00000000`00000000 00000000`37549b7e fffffa80`079543d0 00000000`00000000 : nt!PfSnBeginAppLaunch+0x35f
fffff880`0692fa50 fffff800`0315d2fc : fffffa80`07957460 fffffa80`079543d0 00000000`16050800 00000000`7efde000 : nt! ?? ::NNGAKEGL::`string'+0x50100
fffff880`0692fa80 fffff800`02e6dd55 : fffff800`03009e80 00000000`00000000 fffff800`0315d200 fffffa80`07957460 : nt!PspUserThreadStartup+0xfc
fffff880`0692fae0 fffff800`02e6dcd7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThread+0x16
fffff880`0692fc20 00000000`77c63000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThreadReturn
00000000`001ef958 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77c63000
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::NNGAKEGL::`string'+6368
fffff800`031bb74d cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::NNGAKEGL::`string'+6368
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_31_nt!_??_::NNGAKEGL::_string_+6368
BUCKET_ID: X64_0x1a_31_nt!_??_::NNGAKEGL::_string_+6368
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-18751-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e11000 PsLoadedModuleList = 0xfffff800`0304ee50
Debug session time: Sat Dec 18 06:56:01.969 2010 (UTC - 5:00)
System Uptime: 0 days 0:01:19.577
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {3, fffff88003bf2670, fffff88003bf0670, fffff88003bf2670}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+a56 )
Followup: Pool_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffff88003bf2670, the pool entry being checked.
Arg3: fffff88003bf0670, the read back flink freelist value (should be the same as 2).
Arg4: fffff88003bf2670, the read back blink freelist value (should be the same as 2).
Debugging Details:
------------------
BUGCHECK_STR: 0x19_3
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002fb4d6f to fffff80002e81740
STACK_TEXT:
fffff880`083988d8 fffff800`02fb4d6f : 00000000`00000019 00000000`00000003 fffff880`03bf2670 fffff880`03bf0670 : nt!KeBugCheckEx
fffff880`083988e0 fffff960`001660d0 : fffff900`00000000 00000000`00000000 fffff880`08398d00 fffff880`00000000 : nt!ExDeferredFreePool+0xa56
fffff880`083989d0 fffff960`0011440a : fffff880`00000000 fffff900`00000000 fffff880`08398b80 00000000`fffffffe : win32k!AllocThreadBufferWithTag+0x24
fffff880`08398a00 fffff960`0011397d : fffff900`c1e716d8 fffff880`00000028 fffff900`c1ce4010 fffff880`08398f50 : win32k!EngTextOut+0x4aa
fffff880`08398d90 fffff960`00111be7 : fffff900`c1d3cd58 00000000`00000013 00000000`00000005 00000000`01011513 : win32k!GreExtTextOutWLocked+0x1d29
fffff880`083991b0 fffff960`002d945d : 00000000`00000000 fffff880`08399520 fffff900`c00810f8 fffff960`00192b29 : win32k!GreExtTextOutWInternal+0x10f
fffff880`08399260 fffff800`02e80993 : 00000000`00000000 fffff880`08399520 00000000`00000001 fffff880`08399480 : win32k!NtGdiExtTextOutW+0x341
fffff880`08399430 000007fe`fde2373a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0017cff8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fde2373a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+a56
fffff800`02fb4d6f cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExDeferredFreePool+a56
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
Followup: Pool_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-19297-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e19000 PsLoadedModuleList = 0xfffff800`03056e50
Debug session time: Sat Dec 18 08:36:13.186 2010 (UTC - 5:00)
System Uptime: 0 days 1:37:10.794
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4E, {99, 65e7e, 2, 65dfd}
Probably caused by : memory_corruption ( nt!MiBadShareCount+4c )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 0000000000065e7e, page frame number
Arg3: 0000000000000002, current page state
Arg4: 0000000000065dfd, 0
Debugging Details:
------------------
BUGCHECK_STR: 0x4E_99
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: iexplore.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002f1938c to fffff80002e89740
STACK_TEXT:
fffff880`08cc3718 fffff800`02f1938c : 00000000`0000004e 00000000`00000099 00000000`00065e7e 00000000`00000002 : nt!KeBugCheckEx
fffff880`08cc3720 fffff800`02efb9e5 : 00000000`00000000 fffff680`00022a90 00000000`00000002 00000000`00000001 : nt!MiBadShareCount+0x4c
fffff880`08cc3760 fffff800`02e5dc23 : fffffa80`04672060 fffff700`000031d7 0000007f`fffffff8 fffff8a0`07784120 : nt! ?? ::FNODOBFM::`string'+0x3222c
fffff880`08cc37f0 fffff800`02e5c68a : fffffa80`04672060 fffffa80`00000000 fffff880`0000127b fffff800`00000000 : nt!MiDeleteAddressesInWorkingSet+0x307
fffff880`08cc40a0 fffff800`0316edcf : fffff8a0`0c7eb060 fffff880`08cc43a0 00000000`00000000 fffffa80`07a54980 : nt!MmCleanProcessAddressSpace+0x96
fffff880`08cc40f0 fffff800`03147635 : 00000000`00000000 fffffa80`04631001 00000000`7ef62000 fffffa80`07b70390 : nt!PspExitThread+0x92f
fffff880`08cc41b0 fffff800`02e661db : fffffa80`04672060 fffffa80`07a54980 00000000`00000000 fffff880`08cc4240 : nt!PsExitSpecialApc+0x1d
fffff880`08cc41e0 fffff800`02e66620 : 00000000`069ce7e0 fffff880`08cc4260 fffff800`0314774c 00000000`00000001 : nt!KiDeliverApc+0x2eb
fffff880`08cc4260 fffff800`02e88a37 : fffffa80`07a54980 00000000`7ef62000 00000000`00000020 fffffa80`04631060 : nt!KiInitiateUserApc+0x70
fffff880`08cc43a0 00000000`772ffc46 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`069ce760 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x772ffc46
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiBadShareCount+4c
fffff800`02f1938c cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiBadShareCount+4c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x4E_99_nt!MiBadShareCount+4c
BUCKET_ID: X64_0x4E_99_nt!MiBadShareCount+4c
Followup: MachineOwner
---------
Drivers:
Code:
start end module name
fffff880`04490000 fffff880`044ce000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`04582000 fffff880`045c7000 ace0qrja ace0qrja.SYS Tue Jul 14 17:12:55 2009 (4A5CF4D7)
fffff880`01000000 fffff880`01057000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02e00000 fffff880`02e8a000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`045d7000 fffff880`045ed000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`00fe4000 fffff880`00fef000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`04524000 fffff880`0452c000 ASACPI ASACPI.sys Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`0426e000 fffff880`04274000 AsIO AsIO.sys Mon Apr 06 03:21:08 2009 (49D9AD64)
fffff880`08420000 fffff880`0842b000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00fdb000 fffff880`00fe4000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00db8000 fffff880`00de2000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff960`008d0000 fffff960`00931000 ATMFD ATMFD.DLL Tue Oct 19 23:05:45 2010 (4CBE5C89)
fffff880`01ab5000 fffff880`01abc000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04217000 fffff880`0426e000 BHDrvx64 BHDrvx64.sys Wed Jul 29 21:07:44 2009 (4A70F260)
fffff880`041e1000 fffff880`041f2000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`06f98000 fffff880`06fb6000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff880`04052000 fffff880`040e5000 ccHPx64 ccHPx64.sys Fri Jun 19 19:28:39 2009 (4A3C1F27)
fffff960`00750000 fffff960`00777000 cdd cdd.dll Wed May 19 15:48:26 2010 (4BF4408A)
fffff880`01a82000 fffff880`01aac000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00ebe000 fffff880`00f7e000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01a1c000 fffff880`01a4c000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00cfe000 fffff880`00d5c000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01200000 fffff880`01273000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`045c7000 fffff880`045d7000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`06bcd000 fffff880`06bdb000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`04034000 fffff880`04052000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`04025000 fffff880`04034000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`0141b000 fffff880`01431000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`06855000 fffff880`06877000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`06be7000 fffff880`06bf0000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06bdb000 fffff880`06be7000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06a00000 fffff880`06a13000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`06bc1000 fffff880`06bcd000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`042b0000 fffff880`043a4000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`043a4000 fffff880`043ea000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`0416b000 fffff880`041e1000 eeCtrl64 eeCtrl64.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`08400000 fffff880`08420000 ENG64 ENG64.SYS Mon Dec 13 20:47:30 2010 (4D06CCB2)
fffff880`04000000 fffff880`04025000 EraserUtilRebootDrv EraserUtilRebootDrv.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`08439000 fffff880`085f3000 EX64 EX64.SYS Mon Dec 13 20:55:48 2010 (4D06CEA4)
fffff880`00c4c000 fffff880`00c60000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00c00000 fffff880`00c4c000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`01411000 fffff880`0141b000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`00c60000 fffff880`00c9a000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`01600000 fffff880`0164a000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`033f5000 fffff800`0343e000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04405000 fffff880`04429000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`068d1000 fffff880`068ea000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`068ea000 fffff880`068f2080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`06bf0000 fffff880`06bfe000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`06ed0000 fffff880`06f98000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`017e2000 fffff880`017eb000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`04538000 fffff880`04556000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`040f0000 fffff880`0416b000 IDSvia64 IDSvia64.sys Fri Nov 05 17:13:11 2010 (4CD47367)
fffff880`0429a000 fffff880`042b0000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`04556000 fffff880`04565000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00b9d000 fffff800`00ba7000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`058d5000 fffff880`05918000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`015e5000 fffff880`015ff000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`0179d000 fffff880`017c8000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`06877000 fffff880`0687c200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`06944000 fffff880`06959000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`06900000 fffff880`06923000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00ca6000 fffff880`00cea000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`06a13000 fffff880`06a21000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`058c4000 fffff880`058d3000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`068f3000 fffff880`06900000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00fc1000 fffff880`00fdb000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`06fb6000 fffff880`06fce000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`06fce000 fffff880`06ffb000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`06e00000 fffff880`06e4e000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`06e4e000 fffff880`06e71000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`01b1a000 fffff880`01b25000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01057000 fffff880`01061000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01340000 fffff880`0139e000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`02fd5000 fffff880`02fe0000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`017d0000 fffff880`017e2000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`0164b000 fffff880`0173d000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`05833000 fffff880`0583f000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`0583f000 fffff880`0586e000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`05984000 fffff880`05999000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02f09000 fffff880`02f18000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02e8a000 fffff880`02ecf000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0173d000 fffff880`0179d000 NETIO NETIO.SYS Mon Jul 13 19:21:46 20098 (4A5BC18A)
fffff880`01b25000 fffff880`01b36000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02fc9000 fffff880`02fd5000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e19000 fffff800`033f5000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01442000 fffff880`015e5000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`01aac000 fffff880`01ab5000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`055ea000 fffff880`055eb180 nvBridge nvBridge.kmd Fri Oct 08 02:47:30 2010 (4CAEBE82)
fffff880`05999000 fffff880`059c2000 nvhda64v nvhda64v.sys Tue Sep 07 16:08:40 2010 (4C869BC8)
fffff880`04a18000 fffff880`055e9180 nvlddmkm nvlddmkm.sys Fri Oct 08 03:41:00 2010 (4CAECB0C)
fffff880`02ed8000 fffff880`02efe000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`04565000 fffff880`04582000 parport parport.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`011d5000 fffff880`011ea000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f7e000 fffff880`00fb1000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`0106e000 fffff880`01075000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00fb1000 fffff880`00fc1000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01400000 fffff880`01411000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`07446000 fffff880`074ec000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`059c2000 fffff880`059ff000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00cea000 fffff880`00cfe000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`0580f000 fffff880`05833000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`0586e000 fffff880`05889000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`05889000 fffff880`058aa000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`058aa000 fffff880`058c4000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02f78000 fffff880`02fc9000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`01aff000 fffff880`01b08000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01b08000 fffff880`01b11000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01b11000 fffff880`01b1a000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`0139e000 fffff880`013d8000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`06959000 fffff880`06971000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`044ce000 fffff880`04524000 Rt64win7 Rt64win7.sys Wed Jun 23 05:10:45 2010 (4C21CF95)
fffff880`011a6000 fffff880`011d5000 SCSIPORT SCSIPORT.SYS Mon Jul 13 20:01:04 2009 (4A5BCAC0)
fffff880`074ec000 fffff880`074f7000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`0452c000 fffff880`04538000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`02f18000 fffff880`02f35000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`017c8000 fffff880`017d0000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`01077000 fffff880`0119d000 sptd sptd.sys Sun Oct 11 16:55:14 2009 (4AD24632)
fffff880`07913000 fffff880`07991000 SRTSP64 SRTSP64.SYS Mon Jun 22 22:45:21 2009 (4A4041C1)
fffff880`02f64000 fffff880`02f78000 SRTSPX64 SRTSPX64.SYS Mon Jun 22 22:47:54 2009 (4A40425A)
fffff880`0787d000 fffff880`07913000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`07536000 fffff880`0759d000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`074f7000 fffff880`07524000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`058d3000 fffff880`058d4480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`012d9000 fffff880`01340000 SYMEFA64 SYMEFA64.SYS Tue Jun 23 17:52:39 2009 (4A414EA7)
fffff880`01bad000 fffff880`01be3000 SYMEVENT64x86 SYMEVENT64x86.SYS Wed Jun 24 16:19:12 2009 (4A428A40)
fffff880`013d8000 fffff880`013fa000 SYMFW SYMFW.SYS Mon Jul 06 20:29:22 2009 (4A5296E2)
fffff880`02efe000 fffff880`02f09000 SymIMv SymIMv.sys Mon Jun 22 19:11:56 2009 (4A400FBC)
fffff880`01be3000 fffff880`01bf3000 SYMNDISV SYMNDISV.SYS Mon Jul 06 20:33:26 2009 (4A5297D6)
fffff880`01b61000 fffff880`01bad000 SYMTDI SYMTDI.SYS Mon Jul 06 20:28:48 2009 (4A5296C0)
fffff880`01802000 fffff880`019ff000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`07524000 fffff880`07536000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`01b54000 fffff880`01b61000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`01b36000 fffff880`01b54000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02f50000 fffff880`02f64000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00400000 fffff960`0040a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`04274000 fffff880`0429a000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`0687d000 fffff880`068d1000 udfs udfs.sys Mon Jul 13 19:23:37 2009 (4A5BC1F9)
fffff880`05918000 fffff880`0592a000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`06bfe000 fffff880`06bfff00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`04429000 fffff880`0443a000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0592a000 fffff880`05984000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`0443a000 fffff880`04490000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`01061000 fffff880`0106e000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01abc000 fffff880`01aca000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`06a27000 fffff880`06bc1000 viahduaa viahduaa.sys Mon Aug 17 07:20:43 2009 (4A893D0B)
fffff880`01aca000 fffff880`01aef000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`011ea000 fffff880`011ff000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00d5c000 fffff880`00db8000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01273000 fffff880`012bf000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02f35000 fffff880`02f50000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`01aef000 fffff880`01aff000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e00000 fffff880`00ea4000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00ea4000 fffff880`00eb3000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02ecf000 fffff880`02ed8000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00060000 fffff960`00370000 win32k win32k.sys Tue Oct 19 23:08:46 2010 (4CBE5D3E)
fffff880`0119d000 fffff880`011a6000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`06923000 fffff880`06944000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
Unloaded modules:
fffff880`07800000 fffff880`07871000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00071000
fffff880`01a4c000 fffff880`01a5a000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`01a5a000 fffff880`01a66000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`01a66000 fffff880`01a6f000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`01a6f000 fffff880`01a82000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000