BSOD on Win7 Professional shutdown

Page 1 of 2 12 LastLast

  1. Posts : 5
    Win7 Professional
       #1

    BSOD on Win7 Professional shutdown


    Hallo,

    i desperately need help with a BSOD. It randomly comes while closing down windows even in the last second before the power should turn off. I tried to close win down several times without doing anything, i don't change anything, do not open a program or anything else and sometimes it closes down correctly and sometimes i have this bluescreen.

    I run a Win7 Upgrade license but installed it to a new harddisk, on my old harddisk is win xp which still works perfectly when i put this hd into my computer. Microsoft Upgrade Advisor told me that my system is win7 ready (it is a vista laptop but i installed xp because i didn't like vista).

    I checked the new harddisk with several programs and it is fine and i also checked the Ram with memtest86.

    I tried to update the drivers which is not so easy on a laptop for win7 but the problem appears with fresh installed win7 even as with new drivers (most of them are vista drivers) installed.

    Windows debugging tools say that it is probably caused by a kernel module which means everything and nothing for me.

    BlueScreenView tells me about a conflict between halmacpi.dll and ntkrnlpa.exe which are both part of windows.

    I tried nearly everything and google is my best friend but i don't come along so i need a little bit help please.

    My System:

    Laptop Asus F5VL

    Mainboard Asus F5VL
    Graphics ATI Radeon x 2300
    2 GB Ram
    new Harddisk Hitachi Travelstar 5K500.B 500GB, SATA II 2,5" (HTS545050B9A300)
    Intel Dual Core T2330 1,6 Ghz
    Win7 Professional

    Greetings,

    Sonja

    P.S.: I zipped up all minidump files, but the problem with the ati driver is already fixed. For whatever reason windows did only write a dump file for this problem two times even if have the same BSOD with exactly the same stop code nearly every time i close down win7.
      My Computer


  2. Posts : 28,845
    Win 8 Release candidate 8400
       #2

    Sonja said:
    Hallo,

    i desperately need help with a BSOD. It randomly comes while closing down windows even in the last second before the power should turn off. I tried to close win down several times without doing anything, i don't change anything, do not open a program or anything else and sometimes it closes down correctly and sometimes i have this bluescreen.

    I run a Win7 Upgrade license but installed it to a new harddisk, on my old harddisk is win xp which still works perfectly when i put this hd into my computer. Microsoft Upgrade Advisor told me that my system is win7 ready (it is a vista laptop but i installed xp because i didn't like vista).

    I checked the new harddisk with several programs and it is fine and i also checked the Ram with memtest86.

    I tried to update the drivers which is not so easy on a laptop for win7 but the problem appears with fresh installed win7 even as with new drivers (most of them are vista drivers) installed.

    Windows debugging tools say that it is probably caused by a kernel module which means everything and nothing for me.

    BlueScreenView tells me about a conflict between halmacpi.dll and ntkrnlpa.exe which are both part of windows.

    I tried nearly everything and google is my best friend but i don't come along so i need a little bit help please.

    My System:

    Laptop Asus F5VL

    Mainboard Asus F5VL
    Graphics ATI Radeon x 2300
    2 GB Ram
    new Harddisk Hitachi Travelstar 5K500.B 500GB, SATA II 2,5" (HTS545050B9A300)
    Intel Dual Core T2330 1,6 Ghz
    Win7 Professional

    Greetings,

    Sonja

    P.S.: I zipped up all minidump files, but the problem with the ati driver is already fixed. For whatever reason windows did only write a dump file for this problem two times even if have the same BSOD with exactly the same stop code nearly every time i close down win7.
    Hi Sonja and welcome

    I took a look at about half of the dmps. they are very similar. Most point to your video driver as the probable cause of the crashes

    It makes sense given that the video driver you are using is almost 3 years old
    ,


    DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
    A device driver attempting to corrupt the system has been caught. This is
    because the driver was specified in the registry as being suspect (by the
    administrator) and the kernel has enabled substantial checking of this driver.

    If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
    be among the most commonly seen crashes.


    This is exactly why microsoft suggests that win 7 be installed clean not upgraded

    I would

    update ALL you drivers, BIOS, video, audio, etc

    Run a system file check
    type cmd in search>right click and run as admin>SFC /SCANNOW


    Ken J+

    .



    atikmdag.sys atikmdag.sys+259d4 0x8d41c000 0x8dac5000 0x006a9000 0x45ee2bba 3/6/2007 10:04:26 PM







    secdrv.SYS 0x9971e000 0x99728000 0x0000a000 0x45080528 9/13/2006 8:18:32 AM
    ATKACPI.sys 0x8da6f000 0x8da77000 0x00008000 0x4580f93d 12/14/2006 2:11:57 AM
    StkCPipe.sys 0x94030000 0x94bfb700 0x00bcb700 0x45a5fda1 1/11/2007 4:04:33 AM
    StkCMini.sys 0x9321c000 0x9334bf80 0x0012ff80 0x45d14170 2/12/2007 11:41:20 PM
    RTKVHDA.sys 0x92c2e000 0x92dd5540 0x001a7540 0x45d2a808 2/14/2007 1:11:20 AM
    Rtnicxp.sys 0x8256a000 0x82579000 0x0000f000 0x4840194b 5/30/2008 10:12:11 AM



    Code:
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [C:\Users\K\Desktop\120909-58687-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16385.x86fre.win7_rtm.090713-1255
    Machine Name:
    Kernel base = 0x8280d000 PsLoadedModuleList = 0x82955810
    Debug session time: Wed Dec  9 03:24:43.458 2009 (GMT-5)
    System Uptime: 0 days 0:04:27.255
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..........................
    Loading User Symbols
    Loading unloaded module list
    .....
    1: kd> !thread;!analyze -v;r;kv;lmtn;lmtsmn
    GetPointerFromAddress: unable to read from 8297571c
    THREAD 9d7dbcc0  Cid 0bcc.0c20  Teb: 7ffd8000 Win32Thread: f9cfcde0 RUNNING on processor 1
    Not impersonating
    GetUlongFromAddress: unable to read from 8293549c
    Owning Process            9ddc8d40       Image:         CCC.exe
    Attached Process          N/A            Image:         N/A
    ffdf0000: Unable to get shared data
    Wait Start TickCount      17104        
    Context Switch Count      9703             
    ReadMemory error: Cannot get nt!KeMaximumIncrement value.
    UserTime                  00:00:00.000
    KernelTime                00:00:00.000
    Win32 Start Address 0x72dc1e83
    Stack Init b36c3fd0 Current b36c3940 Base b36c4000 Limit b36c1000 Call 0
    Priority 9 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
    *** WARNING: Unable to verify timestamp for atikmdag.sys
    *** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
    *** WARNING: Unable to verify timestamp for dxgkrnl.sys
    *** ERROR: Module load completed but symbols could not be loaded for dxgkrnl.sys
    ChildEBP RetAddr  Args to Child              
    b36c3834 82b41f03 000000c4 000000f6 0000056c nt!KeBugCheckEx+0x1e
    b36c3854 82b46766 0000056c 9ddc8d40 9d7dbcc0 nt!VerifierBugCheckIfAppropriate+0x30
    b36c38e8 82a3126c 0000056c b36c3ba0 00000000 nt!VfCheckUserHandle+0x14f
    b36c391c 82a31126 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandleWithTag+0x13b
    b36c3940 82b4f736 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandle+0x21
    b36c3968 8f62d9d4 0000056c 000f001f 00000000 nt!VerifierObReferenceObjectByHandle+0x21
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b36c3998 8f62468f 00000000 b36c39e0 b36c3ba0 atikmdag+0x259d4
    b36c39b0 8f620024 b36c3b90 00000020 b36c3ba0 atikmdag+0x1c68f
    b36c39e4 8f620210 00000000 b36c3b0c b36c3b90 atikmdag+0x18024
    b36c3a04 8fcdd435 98b80fc8 b36c3a60 8660c000 atikmdag+0x18210
    b36c3a2c 8fcdce4a b36c3a60 3ca08b19 0415dcb4 dxgkrnl+0x2c435
    b36c3d28 8285042a 0415dcb4 0415dcf0 771264f4 dxgkrnl+0x2be4a
    b36c3d28 771264f4 0415dcb4 0415dcf0 771264f4 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ b36c3d34)
    0415dcf0 00000000 00000000 00000000 00000000 0x771264f4
    
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
    A device driver attempting to corrupt the system has been caught.  This is
    because the driver was specified in the registry as being suspect (by the
    administrator) and the kernel has enabled substantial checking of this driver.
    If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
    be among the most commonly seen crashes.
    Arguments:
    Arg1: 000000f6, Referencing user handle as KernelMode.
    Arg2: 0000056c, Handle value being referenced.
    Arg3: 9ddc8d40, Address of the current process.
    Arg4: 8f62d9d4, Address inside the driver that is performing the incorrect reference.
    
    Debugging Details:
    ------------------
    
    
    BUGCHECK_STR:  0xc4_f6
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VERIFIER_ENABLED_VISTA_MINIDUMP
    
    PROCESS_NAME:  CCC.exe
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from 82b41f03 to 828e9d10
    
    STACK_TEXT:  
    b36c3834 82b41f03 000000c4 000000f6 0000056c nt!KeBugCheckEx+0x1e
    b36c3854 82b46766 0000056c 9ddc8d40 9d7dbcc0 nt!VerifierBugCheckIfAppropriate+0x30
    b36c38e8 82a3126c 0000056c b36c3ba0 00000000 nt!VfCheckUserHandle+0x14f
    b36c391c 82a31126 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandleWithTag+0x13b
    b36c3940 82b4f736 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandle+0x21
    b36c3968 8f62d9d4 0000056c 000f001f 00000000 nt!VerifierObReferenceObjectByHandle+0x21
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b36c3998 8f62468f 00000000 b36c39e0 b36c3ba0 atikmdag+0x259d4
    b36c39b0 8f620024 b36c3b90 00000020 b36c3ba0 atikmdag+0x1c68f
    b36c39e4 8f620210 00000000 b36c3b0c b36c3b90 atikmdag+0x18024
    b36c3a04 8fcdd435 98b80fc8 b36c3a60 8660c000 atikmdag+0x18210
    b36c3a2c 8fcdce4a b36c3a60 3ca08b19 0415dcb4 dxgkrnl+0x2c435
    b36c3d28 8285042a 0415dcb4 0415dcf0 771264f4 dxgkrnl+0x2be4a
    b36c3d28 771264f4 0415dcb4 0415dcf0 771264f4 nt!KiFastCallEntry+0x12a
    0415dcf0 00000000 00000000 00000000 00000000 0x771264f4
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    atikmdag+259d4
    8f62d9d4 3bc7            cmp     eax,edi
    
    SYMBOL_STACK_INDEX:  6
    
    SYMBOL_NAME:  atikmdag+259d4
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: atikmdag
    
    IMAGE_NAME:  atikmdag.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  45ee2bba
    
    FAILURE_BUCKET_ID:  0xc4_f6_VRF_atikmdag+259d4
    
    BUCKET_ID:  0xc4_f6_VRF_atikmdag+259d4
    
    Followup: MachineOwner
    ---------
    
    eax=8294417c ebx=00000000 ecx=0000000b edx=00000000 esi=807c2120 edi=00000000
    eip=828e9d10 esp=b36c3818 ebp=b36c3834 iopl=0         nv up ei pl nz na pe nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00000206
    nt!KeBugCheckEx+0x1e:
    828e9d10 cc              int     3
    ChildEBP RetAddr  Args to Child              
    b36c3834 82b41f03 000000c4 000000f6 0000056c nt!KeBugCheckEx+0x1e
    b36c3854 82b46766 0000056c 9ddc8d40 9d7dbcc0 nt!VerifierBugCheckIfAppropriate+0x30
    b36c38e8 82a3126c 0000056c b36c3ba0 00000000 nt!VfCheckUserHandle+0x14f
    b36c391c 82a31126 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandleWithTag+0x13b
    b36c3940 82b4f736 0000056c 000f001f 00000000 nt!ObReferenceObjectByHandle+0x21
    b36c3968 8f62d9d4 0000056c 000f001f 00000000 nt!VerifierObReferenceObjectByHandle+0x21
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b36c3998 8f62468f 00000000 b36c39e0 b36c3ba0 atikmdag+0x259d4
    b36c39b0 8f620024 b36c3b90 00000020 b36c3ba0 atikmdag+0x1c68f
    b36c39e4 8f620210 00000000 b36c3b0c b36c3b90 atikmdag+0x18024
    b36c3a04 8fcdd435 98b80fc8 b36c3a60 8660c000 atikmdag+0x18210
    b36c3a2c 8fcdce4a b36c3a60 3ca08b19 0415dcb4 dxgkrnl+0x2c435
    b36c3d28 8285042a 0415dcb4 0415dcf0 771264f4 dxgkrnl+0x2be4a
    b36c3d28 771264f4 0415dcb4 0415dcf0 771264f4 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ b36c3d34)
    0415dcf0 00000000 00000000 00000000 00000000 0x771264f4
    start    end        module name
    80bc3000 80bcb000   kdcom    kdcom.dll    Mon Jul 13 21:08:58 2009 (4A5BDAAA)
    8280d000 82c1d000   nt       ntkrpamp.exe Mon Jul 13 19:15:19 2009 (4A5BC007)
    82c1d000 82c54000   hal      halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)
    82e00000 82e11000   partmgr  partmgr.sys  Mon Jul 13 19:11:35 2009 (4A5BBF27)
    82e11000 82e1c000   BATTC    BATTC.SYS    Mon Jul 13 19:19:15 2009 (4A5BC0F3)
    82e1c000 82e2c000   volmgr   volmgr.sys   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
    82e2c000 82e3c000   termdd   termdd.sys   Mon Jul 13 20:01:35 2009 (4A5BCADF)
    82e3e000 82eb6000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:06:41 2009 (4A5BDA21)
    82eb6000 82ec7000   PSHED    PSHED.dll    Mon Jul 13 21:09:36 2009 (4A5BDAD0)
    82ec7000 82ecf000   BOOTVID  BOOTVID.dll  Mon Jul 13 21:04:34 2009 (4A5BD9A2)
    82ecf000 82f11000   CLFS     CLFS.SYS     Mon Jul 13 19:11:10 2009 (4A5BBF0E)
    82f11000 82fbc000   CI       CI.dll       Mon Jul 13 21:09:28 2009 (4A5BDAC8)
    82fbc000 82fc7000   vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)
    82fc7000 82ff1000   pci      pci.sys      Mon Jul 13 19:11:16 2009 (4A5BBF14)
    84c05000 84c76000   Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)
    84c76000 84c84000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
    84c84000 84d77000   sptd     sptd.sys     Sun Oct 11 16:54:02 2009 (4AD245EA)
    84d77000 84d80000   WMILIB   WMILIB.SYS   Mon Jul 13 19:11:22 2009 (4A5BBF1A)
    84d80000 84da6000   SCSIPORT SCSIPORT.SYS Mon Jul 13 19:45:55 2009 (4A5BC733)
    84da6000 84dee000   ACPI     ACPI.sys     Mon Jul 13 19:11:11 2009 (4A5BBF0F)
    84dee000 84df6000   msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)
    84df6000 84dfe000   compbatt compbatt.sys Mon Jul 13 19:19:18 2009 (4A5BC0F6)
    84e0f000 84e5a000   volmgrx  volmgrx.sys  Mon Jul 13 19:11:41 2009 (4A5BBF2D)
    84e5a000 84e61000   pciide   pciide.sys   Mon Jul 13 19:11:19 2009 (4A5BBF17)
    84e61000 84e6f000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:11:15 2009 (4A5BBF13)
    84e6f000 84e85000   mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)
    84e85000 84e8e000   atapi    atapi.sys    Mon Jul 13 19:11:15 2009 (4A5BBF13)
    84e8e000 84eb1000   ataport  ataport.SYS  Mon Jul 13 19:11:18 2009 (4A5BBF16)
    84eb1000 84eba000   amdxata  amdxata.sys  Tue May 19 13:57:35 2009 (4A12F30F)
    84eba000 84eee000   fltmgr   fltmgr.sys   Mon Jul 13 19:11:13 2009 (4A5BBF11)
    84eee000 84eff000   fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    84eff000 84fb6000   ndis     ndis.sys     Mon Jul 13 19:12:24 2009 (4A5BBF58)
    84fb6000 84ff4000   NETIO    NETIO.SYS    Mon Jul 13 19:12:35 2009 (4A5BBF63)
    85007000 85136000   Ntfs     Ntfs.sys     Mon Jul 13 19:12:05 2009 (4A5BBF45)
    85136000 85161000   msrpc    msrpc.sys    Mon Jul 13 19:11:59 2009 (4A5BBF3F)
    85161000 85174000   ksecdd   ksecdd.sys   Mon Jul 13 19:11:56 2009 (4A5BBF3C)
    85174000 851d1000   cng      cng.sys      Mon Jul 13 19:32:55 2009 (4A5BC427)
    851d1000 851df000   pcw      pcw.sys      Mon Jul 13 19:11:10 2009 (4A5BBF0E)
    851df000 851e8000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:11:14 2009 (4A5BBF12)
    851e8000 851fb000   wanarp   wanarp.sys   Mon Jul 13 19:55:02 2009 (4A5BC956)
    85200000 85217000   tdx      tdx.sys      Mon Jul 13 19:12:10 2009 (4A5BBF4A)
    85217000 85222000   TDI      TDI.SYS      Mon Jul 13 19:12:12 2009 (4A5BBF4C)
    85222000 85230000   netbios  netbios.sys  Mon Jul 13 19:53:54 2009 (4A5BC912)
    85231000 85256000   ksecpkg  ksecpkg.sys  Mon Jul 13 19:34:00 2009 (4A5BC468)
    85256000 8539f000   tcpip    tcpip.sys    Mon Jul 13 19:13:18 2009 (4A5BBF8E)
    8539f000 853d0000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)
    853d0000 853d8380   vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)
    853d9000 853e1000   rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)
    853e1000 853ec000   Msfs     Msfs.SYS     Mon Jul 13 19:11:26 2009 (4A5BBF1E)
    853ec000 853fa000   Npfs     Npfs.SYS     Mon Jul 13 19:11:31 2009 (4A5BBF23)
    85400000 85421000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)
    85421000 85429000   rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)
    8542b000 8546a000   volsnap  volsnap.sys  Mon Jul 13 19:11:34 2009 (4A5BBF26)
    8546a000 85472000   spldr    spldr.sys    Mon May 11 12:13:47 2009 (4A084EBB)
    85472000 8549f000   rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)
    8549f000 854af000   mup      mup.sys      Mon Jul 13 19:14:14 2009 (4A5BBFC6)
    854af000 854bc000   klbg     klbg.sys     Wed Oct 14 13:18:07 2009 (4AD607CF)
    854bc000 854c4000   hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)
    854c4000 854f6000   fvevol   fvevol.sys   Mon Jul 13 19:13:01 2009 (4A5BBF7D)
    854f6000 85507000   disk     disk.sys     Mon Jul 13 19:11:28 2009 (4A5BBF20)
    85507000 8552c000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)
    8555e000 8557d000   cdrom    cdrom.sys    Mon Jul 13 19:11:24 2009 (4A5BBF1C)
    8557d000 855ce000   klif     klif.sys     Wed Nov 11 08:32:39 2009 (4AFABCF7)
    855ce000 855d5000   Null     Null.SYS     Mon Jul 13 19:11:12 2009 (4A5BBF10)
    855d5000 855dc000   Beep     Beep.SYS     Mon Jul 13 19:45:00 2009 (4A5BC6FC)
    855dc000 855e8000   vga      vga.sys      Mon Jul 13 19:25:50 2009 (4A5BC27E)
    855e8000 855f5000   watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)
    855f5000 855fd000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:01:40 2009 (4A5BCAE4)
    86800000 8682a000   fastfat  fastfat.SYS  Mon Jul 13 19:14:01 2009 (4A5BBFB9)
    86830000 873fb700   StkCPipe StkCPipe.sys Thu Jan 11 04:04:33 2007 (45A5FDA1)
    8e400000 8e411000   vwififlt vwififlt.sys Mon Jul 13 19:52:03 2009 (4A5BC8A3)
    8e411000 8e418000   klim6    klim6.sys    Tue Nov 03 08:33:26 2009 (4AF03126)
    8e421000 8e941000   kl1      kl1.sys      Tue Sep 01 07:29:07 2009 (4A9D0583)
    8e941000 8e99b000   afd      afd.sys      Mon Jul 13 19:12:34 2009 (4A5BBF62)
    8e99b000 8e9cd000   netbt    netbt.sys    Mon Jul 13 19:12:18 2009 (4A5BBF52)
    8e9cd000 8e9d4000   wfplwf   wfplwf.sys   Mon Jul 13 19:53:51 2009 (4A5BC90F)
    8e9d4000 8e9f3000   pacer    pacer.sys    Mon Jul 13 19:53:58 2009 (4A5BC916)
    8ee10000 8ee51000   rdbss    rdbss.sys    Mon Jul 13 19:14:26 2009 (4A5BBFD2)
    8ee51000 8ee5b000   nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)
    8ee5b000 8ee65000   mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    8ee65000 8ee71000   discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)
    8ee71000 8eed5000   csc      csc.sys      Mon Jul 13 19:15:08 2009 (4A5BBFFC)
    8eed5000 8eeed000   dfsc     dfsc.sys     Mon Jul 13 19:14:16 2009 (4A5BBFC8)
    8eeed000 8eefb000   blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)
    8eefb000 8ef1c000   tunnel   tunnel.sys   Mon Jul 13 19:54:03 2009 (4A5BC91B)
    8ef1c000 8ef24000   ATKACPI  ATKACPI.sys  Thu Dec 14 02:11:57 2006 (4580F93D)
    8ef24000 8ef36000   intelppm intelppm.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)
    8ef36000 8ef3f000   klmouflt klmouflt.sys Fri Oct 02 11:38:31 2009 (4AC61E77)
    8ef3f000 8ef4c000   mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    8ef4c000 8ef56000   usbohci  usbohci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)
    8ef56000 8efa1000   USBPORT  USBPORT.SYS  Mon Jul 13 19:51:13 2009 (4A5BC871)
    8efa1000 8efb0000   usbehci  usbehci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)
    8efb0000 8efc7000   raspptp  raspptp.sys  Mon Jul 13 19:54:47 2009 (4A5BC947)
    8efc7000 8efde000   rassstp  rassstp.sys  Mon Jul 13 19:54:57 2009 (4A5BC951)
    8efde000 8eff5000   USBSTOR  USBSTOR.SYS  Mon Jul 13 19:51:19 2009 (4A5BC877)
    8f608000 8fcb1000   atikmdag atikmdag.sys Tue Mar 06 22:04:26 2007 (45EE2BBA)
    8fcb1000 8fd68000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 20:48:33 2009 (4AC54DE1)
    8fd68000 8fda1000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:25:25 2009 (4A5BC265)
    8fda1000 8fdb9000   i8042prt i8042prt.sys Mon Jul 13 19:11:23 2009 (4A5BBF1B)
    8fdb9000 8fdc6000   kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    8fdc6000 8fdfc380   SynTP    SynTP.sys    Thu Aug 27 21:59:32 2009 (4A973A04)
    8fdfd000 8fdfe700   USBD     USBD.SYS     Mon Jul 13 19:51:05 2009 (4A5BC869)
    99000000 99018000   raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)
    99018000 99022000   rdpbus   rdpbus.sys   Mon Jul 13 20:02:40 2009 (4A5BCB20)
    99022000 99023380   swenum   swenum.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)
    99028000 99155000   athr     athr.sys     Mon Oct 05 12:31:48 2009 (4ACA1F74)
    99155000 9915f000   vwifibus vwifibus.sys Mon Jul 13 19:52:02 2009 (4A5BC8A2)
    9915f000 9916e000   Rtnicxp  Rtnicxp.sys  Fri May 30 11:12:11 2008 (4840194B)
    9916e000 9918d000   HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)
    9918d000 99190700   CmBatt   CmBatt.sys   Mon Jul 13 19:19:18 2009 (4A5BC0F6)
    99191000 9919e000   CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)
    9919e000 991b0000   AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)
    991b0000 991c8000   rasl2tp  rasl2tp.sys  Mon Jul 13 19:54:33 2009 (4A5BC939)
    991c8000 991d3000   ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)
    991d3000 991f5000   ndiswan  ndiswan.sys  Mon Jul 13 19:54:34 2009 (4A5BC93A)
    99600000 99611000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)
    99616000 9964a000   ks       ks.sys       Mon Jul 13 19:45:13 2009 (4A5BC709)
    9964a000 99658000   umbus    umbus.sys    Mon Jul 13 19:51:38 2009 (4A5BC88A)
    99658000 9969c000   usbhub   usbhub.sys   Mon Jul 13 19:52:06 2009 (4A5BC8A6)
    9969c000 996ad000   NDProxy  NDProxy.SYS  Mon Jul 13 19:54:27 2009 (4A5BC933)
    996ad000 997b8900   smserial smserial.sys Mon Oct 26 11:08:57 2009 (4AE5BB89)
    997b9000 997c6000   modem    modem.sys    Mon Jul 13 19:55:24 2009 (4A5BC96C)
    997c6000 997d0000   MODEMCSA MODEMCSA.sys Mon Jul 13 19:55:25 2009 (4A5BC96D)
    997d0000 997dd000   crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)
    997dd000 997e8000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)
    997e8000 997f1000   dump_atapi dump_atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    997f1000 997fb000   Dxapi    Dxapi.sys    Mon Jul 13 19:25:25 2009 (4A5BC265)
    9b400000 9b419000   drmk     drmk.sys     Mon Jul 13 20:36:05 2009 (4A5BD2F5)
    9b421000 9b5c8540   RTKVHDA  RTKVHDA.sys  Wed Feb 14 01:11:20 2007 (45D2A808)
    9b5c9000 9b5f8000   portcls  portcls.sys  Mon Jul 13 19:51:00 2009 (4A5BC864)
    9be60000 9c0aa000   win32k   win32k.sys   Mon Jul 13 19:26:26 2009 (4A5BC2A2)
    9c0c0000 9c0c9000   TSDDD    TSDDD.dll    unavailable (00000000)
    9c0f0000 9c10e000   cdd      cdd.dll      Mon Jul 13 21:04:18 2009 (4A5BD992)
    9cc3e000 9cd6df80   StkCMini StkCMini.sys Mon Feb 12 23:41:20 2007 (45D14170)
    9cd6e000 9cd79000   monitor  monitor.sys  Mon Jul 13 19:25:58 2009 (4A5BC286)
    9cd79000 9cd94000   luafv    luafv.sys    Mon Jul 13 19:15:44 2009 (4A5BC020)
    9cd94000 9cdae000   WudfPf   WudfPf.sys   Mon Jul 13 19:50:13 2009 (4A5BC835)
    9cdae000 9cdbe000   lltdio   lltdio.sys   Mon Jul 13 19:53:18 2009 (4A5BC8EE)
    a601a000 a6060000   nwifi    nwifi.sys    Mon Jul 13 19:51:59 2009 (4A5BC89F)
    a6060000 a6070000   ndisuio  ndisuio.sys  Mon Jul 13 19:53:51 2009 (4A5BC90F)
    a6070000 a6083000   rspndr   rspndr.sys   Mon Jul 13 19:53:20 2009 (4A5BC8F0)
    a6083000 a6108000   HTTP     HTTP.sys     Mon Jul 13 19:12:53 2009 (4A5BBF75)
    a6108000 a6121000   bowser   bowser.sys   Mon Jul 13 19:14:21 2009 (4A5BBFCD)
    a6121000 a6133000   mpsdrv   mpsdrv.sys   Mon Jul 13 19:52:52 2009 (4A5BC8D4)
    a6133000 a6156000   mrxsmb   mrxsmb.sys   Mon Jul 13 19:14:24 2009 (4A5BBFD0)
    a6156000 a6191000   mrxsmb10 mrxsmb10.sys Mon Jul 13 19:14:34 2009 (4A5BBFDA)
    a6191000 a61ac000   mrxsmb20 mrxsmb20.sys Mon Jul 13 19:14:29 2009 (4A5BBFD5)
    afe3c000 afed3000   peauth   peauth.sys   Mon Jul 13 20:35:44 2009 (4A5BD2E0)
    afed3000 afedd000   secdrv   secdrv.SYS   Wed Sep 13 09:18:32 2006 (45080528)
    afedd000 afefe000   srvnet   srvnet.sys   Mon Jul 13 19:14:45 2009 (4A5BBFE5)
    afefe000 aff0b000   tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)
    aff0b000 aff5a000   srv2     srv2.sys     Mon Jul 13 19:14:52 2009 (4A5BBFEC)
    aff5a000 affab000   srv      srv.sys      Mon Jul 13 19:15:10 2009 (4A5BBFFE)
    affab000 affcb480   WUDFRd   WUDFRd.sys   Mon Jul 13 19:50:44 2009 (4A5BC854)
    
    Unloaded modules:
    a61ac000 a61c4000   parport.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    8552c000 85539000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    85539000 85544000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    85544000 8554d000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    8554d000 8555e000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    start    end        module name
    84da6000 84dee000   ACPI     ACPI.sys     Mon Jul 13 19:11:11 2009 (4A5BBF0F)
    8e941000 8e99b000   afd      afd.sys      Mon Jul 13 19:12:34 2009 (4A5BBF62)
    9919e000 991b0000   AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)
    84eb1000 84eba000   amdxata  amdxata.sys  Tue May 19 13:57:35 2009 (4A12F30F)
    84e85000 84e8e000   atapi    atapi.sys    Mon Jul 13 19:11:15 2009 (4A5BBF13)
    84e8e000 84eb1000   ataport  ataport.SYS  Mon Jul 13 19:11:18 2009 (4A5BBF16)
    99028000 99155000   athr     athr.sys     Mon Oct 05 12:31:48 2009 (4ACA1F74)
    8f608000 8fcb1000   atikmdag atikmdag.sys Tue Mar 06 22:04:26 2007 (45EE2BBA)
    8ef1c000 8ef24000   ATKACPI  ATKACPI.sys  Thu Dec 14 02:11:57 2006 (4580F93D)
    82e11000 82e1c000   BATTC    BATTC.SYS    Mon Jul 13 19:19:15 2009 (4A5BC0F3)
    855d5000 855dc000   Beep     Beep.SYS     Mon Jul 13 19:45:00 2009 (4A5BC6FC)
    8eeed000 8eefb000   blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)
    82ec7000 82ecf000   BOOTVID  BOOTVID.dll  Mon Jul 13 21:04:34 2009 (4A5BD9A2)
    a6108000 a6121000   bowser   bowser.sys   Mon Jul 13 19:14:21 2009 (4A5BBFCD)
    9c0f0000 9c10e000   cdd      cdd.dll      Mon Jul 13 21:04:18 2009 (4A5BD992)
    8555e000 8557d000   cdrom    cdrom.sys    Mon Jul 13 19:11:24 2009 (4A5BBF1C)
    82f11000 82fbc000   CI       CI.dll       Mon Jul 13 21:09:28 2009 (4A5BDAC8)
    85507000 8552c000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)
    82ecf000 82f11000   CLFS     CLFS.SYS     Mon Jul 13 19:11:10 2009 (4A5BBF0E)
    9918d000 99190700   CmBatt   CmBatt.sys   Mon Jul 13 19:19:18 2009 (4A5BC0F6)
    85174000 851d1000   cng      cng.sys      Mon Jul 13 19:32:55 2009 (4A5BC427)
    84df6000 84dfe000   compbatt compbatt.sys Mon Jul 13 19:19:18 2009 (4A5BC0F6)
    99191000 9919e000   CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)
    997d0000 997dd000   crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)
    8ee71000 8eed5000   csc      csc.sys      Mon Jul 13 19:15:08 2009 (4A5BBFFC)
    8eed5000 8eeed000   dfsc     dfsc.sys     Mon Jul 13 19:14:16 2009 (4A5BBFC8)
    8ee65000 8ee71000   discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)
    854f6000 85507000   disk     disk.sys     Mon Jul 13 19:11:28 2009 (4A5BBF20)
    9b400000 9b419000   drmk     drmk.sys     Mon Jul 13 20:36:05 2009 (4A5BD2F5)
    997e8000 997f1000   dump_atapi dump_atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    997dd000 997e8000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)
    99600000 99611000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)
    997f1000 997fb000   Dxapi    Dxapi.sys    Mon Jul 13 19:25:25 2009 (4A5BC265)
    8fcb1000 8fd68000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 20:48:33 2009 (4AC54DE1)
    8fd68000 8fda1000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:25:25 2009 (4A5BC265)
    86800000 8682a000   fastfat  fastfat.SYS  Mon Jul 13 19:14:01 2009 (4A5BBFB9)
    84eee000 84eff000   fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    84eba000 84eee000   fltmgr   fltmgr.sys   Mon Jul 13 19:11:13 2009 (4A5BBF11)
    851df000 851e8000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:11:14 2009 (4A5BBF12)
    854c4000 854f6000   fvevol   fvevol.sys   Mon Jul 13 19:13:01 2009 (4A5BBF7D)
    8539f000 853d0000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)
    82c1d000 82c54000   hal      halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)
    9916e000 9918d000   HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)
    a6083000 a6108000   HTTP     HTTP.sys     Mon Jul 13 19:12:53 2009 (4A5BBF75)
    854bc000 854c4000   hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)
    8fda1000 8fdb9000   i8042prt i8042prt.sys Mon Jul 13 19:11:23 2009 (4A5BBF1B)
    8ef24000 8ef36000   intelppm intelppm.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)
    8fdb9000 8fdc6000   kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    80bc3000 80bcb000   kdcom    kdcom.dll    Mon Jul 13 21:08:58 2009 (4A5BDAAA)
    8e421000 8e941000   kl1      kl1.sys      Tue Sep 01 07:29:07 2009 (4A9D0583)
    854af000 854bc000   klbg     klbg.sys     Wed Oct 14 13:18:07 2009 (4AD607CF)
    8557d000 855ce000   klif     klif.sys     Wed Nov 11 08:32:39 2009 (4AFABCF7)
    8e411000 8e418000   klim6    klim6.sys    Tue Nov 03 08:33:26 2009 (4AF03126)
    8ef36000 8ef3f000   klmouflt klmouflt.sys Fri Oct 02 11:38:31 2009 (4AC61E77)
    99616000 9964a000   ks       ks.sys       Mon Jul 13 19:45:13 2009 (4A5BC709)
    85161000 85174000   ksecdd   ksecdd.sys   Mon Jul 13 19:11:56 2009 (4A5BBF3C)
    85231000 85256000   ksecpkg  ksecpkg.sys  Mon Jul 13 19:34:00 2009 (4A5BC468)
    9cdae000 9cdbe000   lltdio   lltdio.sys   Mon Jul 13 19:53:18 2009 (4A5BC8EE)
    9cd79000 9cd94000   luafv    luafv.sys    Mon Jul 13 19:15:44 2009 (4A5BC020)
    82e3e000 82eb6000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:06:41 2009 (4A5BDA21)
    997b9000 997c6000   modem    modem.sys    Mon Jul 13 19:55:24 2009 (4A5BC96C)
    997c6000 997d0000   MODEMCSA MODEMCSA.sys Mon Jul 13 19:55:25 2009 (4A5BC96D)
    9cd6e000 9cd79000   monitor  monitor.sys  Mon Jul 13 19:25:58 2009 (4A5BC286)
    8ef3f000 8ef4c000   mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
    84e6f000 84e85000   mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)
    a6121000 a6133000   mpsdrv   mpsdrv.sys   Mon Jul 13 19:52:52 2009 (4A5BC8D4)
    a6133000 a6156000   mrxsmb   mrxsmb.sys   Mon Jul 13 19:14:24 2009 (4A5BBFD0)
    a6156000 a6191000   mrxsmb10 mrxsmb10.sys Mon Jul 13 19:14:34 2009 (4A5BBFDA)
    a6191000 a61ac000   mrxsmb20 mrxsmb20.sys Mon Jul 13 19:14:29 2009 (4A5BBFD5)
    853e1000 853ec000   Msfs     Msfs.SYS     Mon Jul 13 19:11:26 2009 (4A5BBF1E)
    84dee000 84df6000   msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)
    85136000 85161000   msrpc    msrpc.sys    Mon Jul 13 19:11:59 2009 (4A5BBF3F)
    8ee5b000 8ee65000   mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    8549f000 854af000   mup      mup.sys      Mon Jul 13 19:14:14 2009 (4A5BBFC6)
    84eff000 84fb6000   ndis     ndis.sys     Mon Jul 13 19:12:24 2009 (4A5BBF58)
    991c8000 991d3000   ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)
    a6060000 a6070000   ndisuio  ndisuio.sys  Mon Jul 13 19:53:51 2009 (4A5BC90F)
    991d3000 991f5000   ndiswan  ndiswan.sys  Mon Jul 13 19:54:34 2009 (4A5BC93A)
    9969c000 996ad000   NDProxy  NDProxy.SYS  Mon Jul 13 19:54:27 2009 (4A5BC933)
    85222000 85230000   netbios  netbios.sys  Mon Jul 13 19:53:54 2009 (4A5BC912)
    8e99b000 8e9cd000   netbt    netbt.sys    Mon Jul 13 19:12:18 2009 (4A5BBF52)
    84fb6000 84ff4000   NETIO    NETIO.SYS    Mon Jul 13 19:12:35 2009 (4A5BBF63)
    853ec000 853fa000   Npfs     Npfs.SYS     Mon Jul 13 19:11:31 2009 (4A5BBF23)
    8ee51000 8ee5b000   nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)
    8280d000 82c1d000   nt       ntkrpamp.exe Mon Jul 13 19:15:19 2009 (4A5BC007)
    85007000 85136000   Ntfs     Ntfs.sys     Mon Jul 13 19:12:05 2009 (4A5BBF45)
    855ce000 855d5000   Null     Null.SYS     Mon Jul 13 19:11:12 2009 (4A5BBF10)
    a601a000 a6060000   nwifi    nwifi.sys    Mon Jul 13 19:51:59 2009 (4A5BC89F)
    8e9d4000 8e9f3000   pacer    pacer.sys    Mon Jul 13 19:53:58 2009 (4A5BC916)
    82e00000 82e11000   partmgr  partmgr.sys  Mon Jul 13 19:11:35 2009 (4A5BBF27)
    82fc7000 82ff1000   pci      pci.sys      Mon Jul 13 19:11:16 2009 (4A5BBF14)
    84e5a000 84e61000   pciide   pciide.sys   Mon Jul 13 19:11:19 2009 (4A5BBF17)
    84e61000 84e6f000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:11:15 2009 (4A5BBF13)
    851d1000 851df000   pcw      pcw.sys      Mon Jul 13 19:11:10 2009 (4A5BBF0E)
    afe3c000 afed3000   peauth   peauth.sys   Mon Jul 13 20:35:44 2009 (4A5BD2E0)
    9b5c9000 9b5f8000   portcls  portcls.sys  Mon Jul 13 19:51:00 2009 (4A5BC864)
    82eb6000 82ec7000   PSHED    PSHED.dll    Mon Jul 13 21:09:36 2009 (4A5BDAD0)
    991b0000 991c8000   rasl2tp  rasl2tp.sys  Mon Jul 13 19:54:33 2009 (4A5BC939)
    99000000 99018000   raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)
    8efb0000 8efc7000   raspptp  raspptp.sys  Mon Jul 13 19:54:47 2009 (4A5BC947)
    8efc7000 8efde000   rassstp  rassstp.sys  Mon Jul 13 19:54:57 2009 (4A5BC951)
    8ee10000 8ee51000   rdbss    rdbss.sys    Mon Jul 13 19:14:26 2009 (4A5BBFD2)
    99018000 99022000   rdpbus   rdpbus.sys   Mon Jul 13 20:02:40 2009 (4A5BCB20)
    855f5000 855fd000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:01:40 2009 (4A5BCAE4)
    85421000 85429000   rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)
    853d9000 853e1000   rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)
    85472000 8549f000   rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)
    a6070000 a6083000   rspndr   rspndr.sys   Mon Jul 13 19:53:20 2009 (4A5BC8F0)
    9b421000 9b5c8540   RTKVHDA  RTKVHDA.sys  Wed Feb 14 01:11:20 2007 (45D2A808)
    9915f000 9916e000   Rtnicxp  Rtnicxp.sys  Fri May 30 11:12:11 2008 (4840194B)
    84d80000 84da6000   SCSIPORT SCSIPORT.SYS Mon Jul 13 19:45:55 2009 (4A5BC733)
    afed3000 afedd000   secdrv   secdrv.SYS   Wed Sep 13 09:18:32 2006 (45080528)
    996ad000 997b8900   smserial smserial.sys Mon Oct 26 11:08:57 2009 (4AE5BB89)
    8546a000 85472000   spldr    spldr.sys    Mon May 11 12:13:47 2009 (4A084EBB)
    84c84000 84d77000   sptd     sptd.sys     Sun Oct 11 16:54:02 2009 (4AD245EA)
    aff5a000 affab000   srv      srv.sys      Mon Jul 13 19:15:10 2009 (4A5BBFFE)
    aff0b000 aff5a000   srv2     srv2.sys     Mon Jul 13 19:14:52 2009 (4A5BBFEC)
    afedd000 afefe000   srvnet   srvnet.sys   Mon Jul 13 19:14:45 2009 (4A5BBFE5)
    9cc3e000 9cd6df80   StkCMini StkCMini.sys Mon Feb 12 23:41:20 2007 (45D14170)
    86830000 873fb700   StkCPipe StkCPipe.sys Thu Jan 11 04:04:33 2007 (45A5FDA1)
    99022000 99023380   swenum   swenum.sys   Mon Jul 13 19:45:08 2009 (4A5BC704)
    8fdc6000 8fdfc380   SynTP    SynTP.sys    Thu Aug 27 21:59:32 2009 (4A973A04)
    85256000 8539f000   tcpip    tcpip.sys    Mon Jul 13 19:13:18 2009 (4A5BBF8E)
    afefe000 aff0b000   tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)
    85217000 85222000   TDI      TDI.SYS      Mon Jul 13 19:12:12 2009 (4A5BBF4C)
    85200000 85217000   tdx      tdx.sys      Mon Jul 13 19:12:10 2009 (4A5BBF4A)
    82e2c000 82e3c000   termdd   termdd.sys   Mon Jul 13 20:01:35 2009 (4A5BCADF)
    9c0c0000 9c0c9000   TSDDD    TSDDD.dll    unavailable (00000000)
    8eefb000 8ef1c000   tunnel   tunnel.sys   Mon Jul 13 19:54:03 2009 (4A5BC91B)
    9964a000 99658000   umbus    umbus.sys    Mon Jul 13 19:51:38 2009 (4A5BC88A)
    8fdfd000 8fdfe700   USBD     USBD.SYS     Mon Jul 13 19:51:05 2009 (4A5BC869)
    8efa1000 8efb0000   usbehci  usbehci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)
    99658000 9969c000   usbhub   usbhub.sys   Mon Jul 13 19:52:06 2009 (4A5BC8A6)
    8ef4c000 8ef56000   usbohci  usbohci.sys  Mon Jul 13 19:51:14 2009 (4A5BC872)
    8ef56000 8efa1000   USBPORT  USBPORT.SYS  Mon Jul 13 19:51:13 2009 (4A5BC871)
    8efde000 8eff5000   USBSTOR  USBSTOR.SYS  Mon Jul 13 19:51:19 2009 (4A5BC877)
    82fbc000 82fc7000   vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)
    855dc000 855e8000   vga      vga.sys      Mon Jul 13 19:25:50 2009 (4A5BC27E)
    85400000 85421000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)
    853d0000 853d8380   vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)
    82e1c000 82e2c000   volmgr   volmgr.sys   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
    84e0f000 84e5a000   volmgrx  volmgrx.sys  Mon Jul 13 19:11:41 2009 (4A5BBF2D)
    8542b000 8546a000   volsnap  volsnap.sys  Mon Jul 13 19:11:34 2009 (4A5BBF26)
    99155000 9915f000   vwifibus vwifibus.sys Mon Jul 13 19:52:02 2009 (4A5BC8A2)
    8e400000 8e411000   vwififlt vwififlt.sys Mon Jul 13 19:52:03 2009 (4A5BC8A3)
    851e8000 851fb000   wanarp   wanarp.sys   Mon Jul 13 19:55:02 2009 (4A5BC956)
    855e8000 855f5000   watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)
    84c05000 84c76000   Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)
    84c76000 84c84000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:11:25 2009 (4A5BBF1D)
    8e9cd000 8e9d4000   wfplwf   wfplwf.sys   Mon Jul 13 19:53:51 2009 (4A5BC90F)
    9be60000 9c0aa000   win32k   win32k.sys   Mon Jul 13 19:26:26 2009 (4A5BC2A2)
    84d77000 84d80000   WMILIB   WMILIB.SYS   Mon Jul 13 19:11:22 2009 (4A5BBF1A)
    9cd94000 9cdae000   WudfPf   WudfPf.sys   Mon Jul 13 19:50:13 2009 (4A5BC835)
    affab000 affcb480   WUDFRd   WUDFRd.sys   Mon Jul 13 19:50:44 2009 (4A5BC854)
    
    Unloaded modules:
    a61ac000 a61c4000   parport.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    8552c000 85539000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    85539000 85544000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    85544000 8554d000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    8554d000 8555e000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    EDIT;

    THIS IS THE MOST RECENT DMP AND IT STILL POINTS TO THE VIDEO DRIVER SO IT IS NOT FIXED
    Code:
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [C:\Users\K\Desktop\120909-122500-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16385.x86fre.win7_rtm.090713-1255
    Machine Name:
    Kernel base = 0x8283e000 PsLoadedModuleList = 0x82986810
    Debug session time: Wed Dec  9 02:49:41.638 2009 (GMT-5)
    System Uptime: 0 days 0:04:30.388
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..........................
    Loading User Symbols
    Loading unloaded module list
    .....
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
    A device driver attempting to corrupt the system has been caught.  This is
    because the driver was specified in the registry as being suspect (by the
    administrator) and the kernel has enabled substantial checking of this driver.
    If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
    be among the most commonly seen crashes.
    Arguments:
    Arg1: 000000f6, Referencing user handle as KernelMode.
    Arg2: 00000558, Handle value being referenced.
    Arg3: 86a7aa58, Address of the current process.
    Arg4: 90429ac8, Address inside the driver that is performing the incorrect reference.
    
    Debugging Details:
    ------------------
    
    *** WARNING: Unable to verify timestamp for atikmdag.sys
    *** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
    *** WARNING: Unable to verify timestamp for dxgkrnl.sys
    *** ERROR: Module load completed but symbols could not be loaded for dxgkrnl.sys
    
    BUGCHECK_STR:  0xc4_f6
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VERIFIER_ENABLED_VISTA_MINIDUMP
    
    PROCESS_NAME:  CCC.exe
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from 82b72f03 to 8291ad10
    
    STACK_TEXT:  
    b2a6f7d4 82b72f03 000000c4 000000f6 00000558 nt!KeBugCheckEx+0x1e
    b2a6f7f4 82b77766 00000558 86a7aa58 89a2c488 nt!VerifierBugCheckIfAppropriate+0x30
    b2a6f888 82a6226c 00000558 b2a6fba0 00000000 nt!VfCheckUserHandle+0x14f
    b2a6f8bc 82a62126 00000558 000f001f 00000000 nt!ObReferenceObjectByHandleWithTag+0x13b
    b2a6f8e0 82b80736 00000558 000f001f 00000000 nt!ObReferenceObjectByHandle+0x21
    b2a6f908 90429ac8 00000558 000f001f 00000000 nt!VerifierObReferenceObjectByHandle+0x21
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b2a6f938 90413911 00000000 b2a6fba0 8fda8fc0 atikmdag+0x29ac8
    b2a6f958 90416b7d b2a6fba0 8fda8fc0 b2a6fba0 atikmdag+0x13911
    b2a6f974 90410331 b2a6fb90 00000020 b2a6fba0 atikmdag+0x16b7d
    b2a6f9d8 9041085c 00000000 b2a6fb0c 00000038 atikmdag+0x10331
    b2a6fa04 908ae435 8fda8fc0 b2a6fa60 86b19000 atikmdag+0x1085c
    b2a6fa2c 908ade4a b2a6fa60 222f39bf 00dcddc0 dxgkrnl+0x2c435
    b2a6fd28 8288142a 00dcddc0 00dcddfc 77d964f4 dxgkrnl+0x2be4a
    b2a6fd28 77d964f4 00dcddc0 00dcddfc 77d964f4 nt!KiFastCallEntry+0x12a
    00dcddfc 00000000 00000000 00000000 00000000 0x77d964f4
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    atikmdag+29ac8
    90429ac8 3bc7            cmp     eax,edi
    
    SYMBOL_STACK_INDEX:  6
    
    SYMBOL_NAME:  atikmdag+29ac8
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: atikmdag
    
    IMAGE_NAME:  atikmdag.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  49a5bd7e
    
    FAILURE_BUCKET_ID:  0xc4_f6_VRF_atikmdag+29ac8
    
    BUCKET_ID:  0xc4_f6_VRF_atikmdag+29ac8
    
    Followup: MachineOwner
    ---------
      My Computer


  3. Posts : 5
    Win7 Professional
    Thread Starter
       #3

    Dear Ken,

    as I wrote in my first post I made a clean install onto a new harddisk - it is only a upgrade license I run. I took my old harddisk out of my laptop and bought a new one for installing Win7 - even it is not possible to make an upgrade from xp. Microsoft is selling these licenses in Germany but installing as an upgrade is only possible from Vista and I prefer clean install for an OS so I didn't install Vista first.

    In my first post I wrote that the problem with the driver is fixed, please believe that. I was looking for a solution and tried a desktop driver for the ati radeon which should - according to a german forum - work with some modifications. These bluescreens were the results and because the beta drivers for win 7 laptops from the ati page causes problems as well I use now Vista drivers and my graphic card works fine and I do no longer have BSODs because of the graphics.

    The problem is in the first two dump files with the date of 8.12.2009.

    Getting new drivers for a laptop with win7 is a problem as I wrote above I tried to update all drivers but I didn't find all. Maybe you could have a look at the first two dump files and help me?

    Thanks in advance,

    Sonja
      My Computer


  4. Posts : 28,845
    Win 8 Release candidate 8400
       #4

    Sonja said:
    Dear Ken,

    as I wrote in my first post I made a clean install onto a new harddisk - it is only a upgrade license I run. I took my old harddisk out of my laptop and bought a new one for installing Win7 - even it is not possible to make an upgrade from xp. Microsoft is selling these licenses in Germany but installing as an upgrade is only possible from Vista and I prefer clean install for an OS so I didn't install Vista first.

    In my first post I wrote that the problem with the driver is fixed, please believe that. I was looking for a solution and tried a desktop driver for the ati radeon which should - according to a german forum - work with some modifications. These bluescreens were the results and because the beta drivers for win 7 laptops from the ati page causes problems as well I use now Vista drivers and my graphic card works fine and I do no longer have BSODs because of the graphics.

    The problem is in the first two dump files with the date of 8.12.2009.

    Getting new drivers for a laptop with win7 is a problem as I wrote above I tried to update all drivers but I didn't find all. Maybe you could have a look at the first two dump files and help me?

    Thanks in advance,

    Sonja

    Sonja

    I read that the problem was fixed which is exactly why I did the oldest and newest dmps and posted them. They still are the probable cause of the crashes. I wonder if it may not be a video hardware problem. Also I am thinking a heat issue.

    There is another option. Driver verifier. It will make whatever is causing this problem to fail. We have a wizard with it and I am going to PM him a link to this thread


    Ken J+
      My Computer


  5. Posts : 5,705
    Win7 x64 + x86
       #5

    Driver Verifier has verified that it's the ATI drivers that are crashing the system. This is a bit misleading - actually it's the ATI drivers that are crashing due to another component/driver - and that's what's crashing the system.

    The first place to start is with the drivers that zigzag3143 mentions in his post. They must be updated or removed from the system in order to rule them out as a cause.

    Next, uninstall all ATI stuff from Control Panel...Programs...Uninstall a program.
    Then download ONLY the latest ATI drivers. DO NOT GET THE ONE with the Catalyst Control Center - get the Display Driver only!!!
    Install the display drivers and test to see if it still BSOD's.

    Several other things to look at:
    - motherboard/chipset drivers
    - video card issues such as hardware failure, overheating, etc
    - incompatibility issues of assorted programs, especially those that use the video sub-system.

    Only install Windows 7 drivers on the system
    Then, if there are remaining devices:
    - disable them if not essential to the running of the system
    - Install Vista drivers using the following procedure:
    Compatibilty Mode
    1 - Download the latest driver from the manufacturer's website.
    2 - Uninstall the current drivers using the Control Panel...Programs and features...Uninstall a program applet. Then verify that the driver/device has been removed in Device Manager
    3 - Right click on freshly downloade driver installation file and select "Properties"
    4 - Select the Compatibility tab - and do the following:
    - Click on the "Change settings for all users" button
    - Click on the box to select "Run this program in compatibility mode for" and then select Windows Vista Service Pack 1
    - Click on the box to select "Run as administrator"
    - Click on OK to exit all the dialogs
    5 - Right click on the driver installation file and select "Run as administrator"
    6 - Let it install and see if that stops the BSOD's.
    Once all that's done, turn off Driver Verifier by using the Delete existing settings button on the first screen.
    Then wait for the next BSOD and let us see it.
      My Computer


  6. Posts : 5
    Win7 Professional
    Thread Starter
       #6

    Dear Ken,

    we are talking about different things. I attached the oldest dumps again, the error ocurred without and before changing graphic drivers, please believe me.

    The error code is 0x000000D1 (0xCFF30023, 0x000000FF, 0x00000008, 0xCFF30023). It occurs on a new installed system without any changes.



    0: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: cff30023, memory referenced
    Arg2: 000000ff, IRQL
    Arg3: 00000008, value 0 = read operation, 1 = write operation
    Arg4: cff30023, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: GetPointerFromAddress: unable to read from 829a6718
    Unable to read MiSystemVaType memory at 82986160
    cff30023

    CURRENT_IRQL: 2

    FAULTING_IP:
    +ffffffffcff30023
    cff30023 ?? ???

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

    BUGCHECK_STR: 0xD1

    PROCESS_NAME: System

    TRAP_FRAME: 95987b1c -- (.trap 0xffffffff95987b1c)
    ErrCode = 00000010
    eax=00002c01 ebx=00000000 ecx=00002c00 edx=00000804 esi=00003703 edi=00000000
    eip=cff30023 esp=95987b90 ebp=95987bbc iopl=0 nv up di pl nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010002
    cff30023 ?? ???
    Resetting default scope

    LAST_CONTROL_TRANSFER: from cff30023 to 828847eb

    FAILED_INSTRUCTION_ADDRESS:
    +ffffffffcff30023
    cff30023 ?? ???

    STACK_TEXT:
    95987b1c cff30023 badb0d00 00000804 95987b58 nt!KiTrap0E+0x2cf
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    95987b8c 00000000 95987c70 95987cac 82967d20 0xcff30023


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!KiTrap0E+2cf
    828847eb 833dc41a9a8200 cmp dword ptr [nt!KiFreezeFlag (829a1ac4)],0

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt!KiTrap0E+2cf

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrpamp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007

    FAILURE_BUCKET_ID: 0xD1_CODE_AV_BAD_IP_nt!KiTrap0E+2cf

    BUCKET_ID: 0xD1_CODE_AV_BAD_IP_nt!KiTrap0E+2cf

    Followup: MachineOwner
    ---------
      My Computer


  7. Posts : 28,845
    Win 8 Release candidate 8400
       #7

    Sonja

    I understand. I asked John to take a look as he has much more experience than I.

    Usamsa has an index of error codes here BSOD Index and you might want to take a look

    Let us know if we can help you with something

    Ken J+
      My Computer


  8. Posts : 5
    Win7 Professional
    Thread Starter
       #8

    usasma said:
    Next, uninstall all ATI stuff from Control Panel...Programs...Uninstall a program.
    Then download ONLY the latest ATI drivers. DO NOT GET THE ONE with the Catalyst Control Center - get the Display Driver only!!!
    Install the display drivers and test to see if it still BSOD's.
    I removed all ati stuff already yesterday and the BSODs are still there. Newer drivers are unavailable, ati offers only a beta version which also causes problems. Thats why I tried the modified desktop drivers - even if I am not sure if the problem is the graphics driver.


    usasma said:
    Several other things to look at:
    - motherboard/chipset drivers
    - video card issues such as hardware failure, overheating, etc
    - incompatibility issues of assorted programs, especially those that use the video sub-system.
    The error ocurred on a fresh installed system without any programs installed. I don't believe that it is a hardware failure because when putting my old hd with xp installed into the laptop everything works fine.

    Newer motherboard driver are unavailable for this board, the chipset drivers I downloaded from SiS are not being installed because Win7 tells me that they are not suitable for my system.

    Working Win7 drivers I got only for the touchpad.

    Drivers for audio, graphics, modem (is this the correct english word?), wireless network adapter and ethernet card came with win7 and are the latest working driver I found.

    I will install the rest in compatibility mode this evening and try if it works.

    Ken, thank you very much, so much to read... Some of the articles of the knowledge base I already know, some I don't. I think I have to spent my evening with reading and installing

    Sonja
      My Computer


  9. Posts : 5,705
    Win7 x64 + x86
       #9

    If it's not a hardware problem, then it's gotta be an incompatibility with what's installed on the system and Windows 7 (most likely the chipset IMO, since there's nothing available for it from SiS)

    Compatibilty Mode Driver Installation
    1 - Download the latest driver from the manufacturer's website.
    2 - Uninstall the current drivers using the Control Panel...Programs and features...Uninstall a program applet. Then verify that the driver/device has been removed in Device Manager
    3 - Right click on freshly downloade driver installation file and select "Properties"
    4 - Select the Compatibility tab - and do the following:
    - Click on the "Change settings for all users" button
    - Click on the box to select "Run this program in compatibility mode for" and then select Windows Vista Service Pack 1
    - Click on the box to select "Run as administrator"
    - Click on OK to exit all the dialogs
    5 - Right click on the driver installation file and select "Run as administrator"
    6 - Let it install and see if that stops the BSOD's.
      My Computer


  10. Posts : 5
    Win7 Professional
    Thread Starter
       #10

    Thank you all for your help, I solved the problem and wanted to tell this for the next desperate person

    It was not a hardware problem and not a problem with the graphics, but indeed a driver problem. I reinstalled all drivers in compatibility mode and this caused many new problems and BSODs so I decided to install Win7 completely new.

    The last times when having installed 7 the first thing I made was getting Win updates, this time I installed Vista drivers for my laptop first.

    The solution:

    After having installed Win7 I took a look into device manager and had one unknown device with a yellow exclamation mark. With a right-click on drivers for this device I searched for drivers in my Vista driver folder and there the solution was - the ATK0100 ACPI Utility.

    The last time when I installed the drivers from Win update I got a driver for the ACPI Utility as well - but for whatever reason it did not work properly and caused problems at shutdown. Now I run quite old drivers in fact, but they are working and I don't have any more problems on shutdown.

    For those who do not know what ACPI is (including myself, I had to ask google once more):

    ACPI establishes industry-standard interfaces enabling OS-directed configuration, power management, and thermal management of mobile, desktop, and server platforms.

    So it makes sense getting bluescreens only on shutdown when having problems with the power management

    Greetings,

    Sonja
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:30.
Find Us