Running the memory dumps from May and June
Daemon Tools (and Alcohol % software) are known to cause BSOD's on some Windows 7 systems (mostly due to the sptd.sys driver, although I have seen dtsoftbus01.sys blamed on several occasions).
Please uninstall the program, then use the following free tool to ensure that the troublesome sptd.sys driver is removed from your system (pick the 32 or 64 bit system depending on your system's configuration):
DuplexSecure - FAQ
Some free alternatives (I don't use them, so I can't comment on them)
MagicISO - Convert BIN to ISO, Create, Edit, Burn, Extract ISO file, ISO/BIN converter/extractor/editor
You may be infected. This program executes from your startups: MgKPyEORiQUvGj.exe
A google search shows lot's of posts related to malware. Please perform several of the free scans from here:
Free Online AntiMalware Resources
Have you recently updated your MalwareBytes program? - I see 2 instances of it in the memory dump files.
Hamachi/LogMeIn drivers date from 2009, please update them.
Check to see if McAfee is compromised:
Quote:
Anti-Virus Removal:
Please do the following:
- download a free antivirus for testing purposes:
Free AntiVirus
- uninstall the
McAfee from your system (you can reinstall it, if so desired, when we're done troubleshooting)
- remove any remnants of
McAfee using this free tool:
http://service.mcafee.com/FAQDocument.aspx?id=TS100507
-
IMMEDIATELY install and update the free antivirus, then check to ensure that the Windows Firewall is turned on.
- check to see if this fixes the BSOD's
NOTE: NEVER run more than 1 anti-virus, firewall, Internet Security/Security Center application at the same time.
Memory dumps mention your video drivers (but don't directly blame them). I'd suggest updating them from the nVidia website (
World Leader in Visual Computing Technologies | NVIDIA )
The following info is just FYI, I've already addressed the issues that I saw in the above paragraphs
- Further info on BSOD error messages available at:
http://www.carrona.org/bsodindx.html
- Info on how to troubleshoot BSOD's (DRAFT):
http://www.carrona.org/userbsod.html
- How I do it:
http://www.carrona.org/howidoit.html 3RD PARTY DRIVERS PRESENT IN THE DUMP FILES Code:
Accelern.sys Fri Aug 20 14:04:57 2010 (4C6EC3C9)
CtClsFlt.sys Wed Jan 19 22:20:46 2011 (4D37AA0E)
EMSC.SYS Fri Jun 19 16:35:47 2009 (4A3BF6A3)
HECIx64.sys Tue Oct 19 19:33:43 2010 (4CBE2AD7)
IntcDAud.sys Fri Oct 15 04:28:17 2010 (4CB810A1)
L1C62x64.sys Mon Sep 27 02:36:23 2010 (4CA03B67)
PxHlpa64.sys Tue Oct 20 14:08:42 2009 (4ADDFCAA)
RtsPStor.sys Fri Oct 29 04:58:12 2010 (4CCA8CA4)
SynTP.sys Thu Oct 14 21:31:11 2010 (4CB7AEDF)
amdxata.sys Fri Mar 19 12:18:18 2010 (4BA3A3CA)
bcmwl664.sys Thu Jan 21 22:30:58 2010 (4B591BF2)
btwampfl.sys Mon Jul 12 21:41:18 2010 (4C3BC43E)
cfwids.sys Mon Feb 13 18:40:56 2012 (4F399F88)
dtsoftbus01.sys Fri Jun 17 03:38:37 2011 (4DFB047D)
dump_iaStor.sys Mon Sep 13 21:23:32 2010 (4C8ECE94)
hamachi.sys Thu Feb 19 05:36:41 2009 (499D3639)
iaStor.sys Mon Sep 13 21:23:32 2010 (4C8ECE94)
iaStorV.sys Thu Jun 10 20:46:19 2010 (4C11875B)
igdkmd64.sys Wed Aug 31 15:53:13 2011 (4E5E9129)
mbam.sys Tue Mar 20 12:04:48 2012 (4F68AAA0)
mbam.sys Wed Nov 02 09:07:48 2011 (4EB140A4)
mfeapfk.sys Mon Feb 13 18:37:01 2012 (4F399E9D)
mfeavfk.sys Mon Feb 13 18:37:27 2012 (4F399EB7)
mfefirek.sys Mon Feb 13 18:40:07 2012 (4F399F57)
mfehidk.sys Mon Feb 13 18:36:14 2012 (4F399E6E)
mfenlfk.sys Mon Feb 13 18:36:45 2012 (4F399E8D)
mfewfpk.sys Mon Feb 13 18:36:29 2012 (4F399E7D)
nusb3hub.sys Thu Feb 10 00:52:32 2011 (4D537D20)
nusb3xhc.sys Thu Feb 10 00:52:33 2011 (4D537D21)
nvkflt.sys Thu Feb 09 21:04:06 2012 (4F347B16)
nvlddmkm.sys Thu Feb 09 21:02:58 2012 (4F347AD2)
nvpciflt.sys Thu Feb 09 21:03:48 2012 (4F347B04)
stdcfltn.sys Fri Aug 20 14:05:01 2010 (4C6EC3CD)
stwrt64.sys Thu Mar 17 04:21:47 2011 (4D81C49B)
http://www.carrona.org/drivers/driver.php?id=Accelern.sys http://www.carrona.org/drivers/driver.php?id=CtClsFlt.sys http://www.carrona.org/drivers/driver.php?id=EMSC.SYS http://www.carrona.org/drivers/driver.php?id=HECIx64.sys http://www.carrona.org/drivers/driver.php?id=IntcDAud.sys http://www.carrona.org/drivers/driver.php?id=L1C62x64.sys http://www.carrona.org/drivers/driver.php?id=PxHlpa64.sys http://www.carrona.org/drivers/driver.php?id=RtsPStor.sys http://www.carrona.org/drivers/driver.php?id=SynTP.sys http://www.carrona.org/drivers/driver.php?id=amdxata.sys http://www.carrona.org/drivers/driver.php?id=bcmwl664.sys http://www.carrona.org/drivers/driver.php?id=btwampfl.sys http://www.carrona.org/drivers/driver.php?id=cfwids.sys http://www.carrona.org/drivers/driver.php?id=dtsoftbus01.sys http://www.carrona.org/drivers/driver.php?id=dump_iaStor.sys http://www.carrona.org/drivers/driver.php?id=hamachi.sys http://www.carrona.org/drivers/driver.php?id=iaStor.sys http://www.carrona.org/drivers/driver.php?id=iaStorV.sys http://www.carrona.org/drivers/driver.php?id=igdkmd64.sys http://www.carrona.org/drivers/driver.php?id=mbam.sys http://www.carrona.org/drivers/driver.php?id=mfeapfk.sys http://www.carrona.org/drivers/driver.php?id=mfeavfk.sys http://www.carrona.org/drivers/driver.php?id=mfefirek.sys http://www.carrona.org/drivers/driver.php?id=mfehidk.sys http://www.carrona.org/drivers/driver.php?id=mfenlfk.sys http://www.carrona.org/drivers/driver.php?id=mfewfpk.sys http://www.carrona.org/drivers/driver.php?id=nusb3hub.sys http://www.carrona.org/drivers/driver.php?id=nusb3xhc.sys http://www.carrona.org/drivers/driver.php?id=nvkflt.sys http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys http://www.carrona.org/drivers/driver.php?id=nvpciflt.sys http://www.carrona.org/drivers/driver.php?id=stdcfltn.sys http://www.carrona.org/drivers/driver.php?id=stwrt64.sys Code:
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\050612-31652-01.dmp]
Built by: 7601.17790.amd64fre.win7sp1_gdr.120305-1505
Debug session time: Sun May 6 02:41:44.047 2012 (UTC - 4:00)
System Uptime: 2 days 15:02:36.319
BugCheck 9F, {3, fffffa8004f85a10, fffff80000b9c3d8, fffffa8004dbe910}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : pci.sys
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_0x9F_3_ACPI_IMAGE_pci.sys
Bugcheck code 0000009F
Arguments 00000000`00000003 fffffa80`04f85a10 fffff800`00b9c3d8 fffffa80`04dbe910
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\050812-19936-01.dmp]
Built by: 7601.17790.amd64fre.win7sp1_gdr.120305-1505
Debug session time: Tue May 8 13:50:33.916 2012 (UTC - 4:00)
System Uptime: 2 days 9:59:07.974
BugCheck 9F, {3, fffffa800684ba10, fffff80004c77748, fffffa800b488490}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : pci.sys
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: PhoenixViewer.
FAILURE_BUCKET_ID: X64_0x9F_3_ACPI_IMAGE_pci.sys
Bugcheck code 0000009F
Arguments 00000000`00000003 fffffa80`0684ba10 fffff800`04c77748 fffffa80`0b488490
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\051012-18688-01.dmp]
Built by: 7601.17803.amd64fre.win7sp1_gdr.120330-1504
Debug session time: Thu May 10 22:05:32.336 2012 (UTC - 4:00)
System Uptime: 0 days 8:54:21.257
BugCheck 9F, {3, fffffa800684da10, fffff80000b9c3d8, fffffa80078b4700}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\052612-18314-01.dmp]
Built by: 7601.17803.amd64fre.win7sp1_gdr.120330-1504
Debug session time: Sat May 26 13:45:39.460 2012 (UTC - 4:00)
System Uptime: 9 days 4:55:38.753
BugCheck 9F, {3, fffffa8006850a10, fffff80004c713d8, fffffa800b319b80}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : pci.sys
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_0x9F_3_ACPI_IMAGE_pci.sys
Bugcheck code 0000009F
Arguments 00000000`00000003 fffffa80`06850a10 fffff800`04c713d8 fffffa80`0b319b80
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\061812-17940-01.dmp]
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Debug session time: Mon Jun 18 10:16:15.173 2012 (UTC - 4:00)
System Uptime: 0 days 0:12:10.094
BugCheck 9F, {3, fffffa8004f9fa10, fffff80004c86748, fffffa8007928900}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : pci.sys
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: xrEngine.exe
FAILURE_BUCKET_ID: X64_0x9F_3_ACPI_IMAGE_pci.sys
Bugcheck code 0000009F
Arguments 00000000`00000003 fffffa80`04f9fa10 fffff800`04c86748 fffffa80`07928900
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\061812-19812-01.dmp]
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Debug session time: Mon Jun 18 10:03:42.180 2012 (UTC - 4:00)
System Uptime: 4 days 1:34:51.108
BugCheck 9F, {3, fffffa800684fa10, fffff80000ba2748, fffffa8004bf4580}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : pci.sys
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: dwm.exe
FAILURE_BUCKET_ID: X64_0x9F_3_ACPI_IMAGE_pci.sys
Bugcheck code 0000009F
Arguments 00000000`00000003 fffffa80`0684fa10 fffff800`00ba2748 fffffa80`04bf4580
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``