| Windows 7: BSOD: Software (Isys) Causing Issue? |
22 Jul 2010
|
#1 | | |
BSOD: Software (Isys) Causing Issue? New Systems just deployed to users
Dell Optiplex 960
Windows 7 Buisness X64
Intel Core 2 Duo E8400 Wolfdale 3.0GHz
8 GB Ram
HDD 80 GB
ATI Radeon HD 3450
Have multiple machines with same specs and same base image. Systems with Isys (Search Software) are having BSOD issue.
Used the the Debugger and received some of the following below. HTML Code: icrosoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Documents and Settings\jrobinson\Desktop\072110-31371-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`0285d000 PsLoadedModuleList = 0xfffff800`02a9ae50
Debug session time: Wed Jul 21 14:07:11.625 2010 (UTC - 4:00)
System Uptime: 0 days 2:54:52.155
Loading Kernel Symbols
...............................................................
................................................................
..................................................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {80000003, fffff800028c6f40, fffff88007a0fe50, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceHandler+7c )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 0000000080000003, Exception code that caused the bugcheck
Arg2: fffff800028c6f40, Address of the instruction which caused the bugcheck
Arg3: fffff88007a0fe50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (HRESULT) 0x80000003 (2147483651) - One or more arguments are invalid
FAULTING_IP:
nt!DbgBreakPoint+0
fffff800`028c6f40 cc int 3
CONTEXT: fffff88007a0fe50 -- (.cxr 0xfffff88007a0fe50)
rax=fffff8000297e6d0 rbx=fffffa80093f3540 rcx=fffff88005bd0860
rdx=fffffa80093f3540 rsi=0000000000000000 rdi=fffffa80093f3540
rip=fffff800028c6f40 rsp=fffff88007a10838 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=fffff80002a487c0
r11=fffffa8009826b60 r12=0000000000000000 r13=0000000000000000
r14=fffffa80093f3540 r15=0000000000000001
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000282
nt!DbgBreakPoint:
fffff800`028c6f40 cc int 3
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: IQW.EXE
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800028c6f40
STACK_TEXT:
fffff880`07a0f588 fffff800`028ce469 : 00000000`0000003b 00000000`80000003 fffff800`028c6f40 fffff880`07a0fe50 : nt!KeBugCheckEx
fffff880`07a0f590 fffff800`028cddbc : fffff880`07a105f8 fffff880`07a0fe50 00000000`00000000 fffff800`028fd450 : nt!KiBugCheckDispatch+0x69
fffff880`07a0f6d0 fffff800`028f4bed : fffff800`02aee464 fffff800`02a2cef4 fffff800`0285d000 fffff880`07a105f8 : nt!KiSystemServiceHandler+0x7c
fffff880`07a0f710 fffff800`028fc250 : fffff800`02a1d1e8 fffff880`07a0f788 fffff880`07a105f8 fffff800`0285d000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`07a0f740 fffff800`029091b5 : fffff880`07a105f8 fffff880`07a0fe50 fffff880`00000000 fffffa80`00000005 : nt!RtlDispatchException+0x410
fffff880`07a0fe20 fffff800`028ce542 : fffff880`07a105f8 fffffa80`093f3540 fffff880`07a106a0 00000000`00000000 : nt!KiDispatchException+0x135
fffff880`07a104c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceHandler+7c
fffff800`028cddbc b801000000 mov eax,1
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceHandler+7c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
Followup: MachineOwner
--------- | My System Specs |
| System Manufacturer/Model Number Dell Optiplex 960 OS Windows 7 |
22 Jul 2010
|
#2 | | Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit |
| My System Specs | | System Manufacturer/Model Number Samsung NP550P5C-S02IN OS Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit CPU Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach Memory 8 GB Graphics Card NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno Sound Card SoundAlive™ JBL 3 Speakers (With sub-Woofer) Monitor(s) Displays 39.62cm (15.6) SuperBright 300nit HD+ LED Display Screen Resolution 1,600 x 900, Anti-Reflective Hard Drives 1TB S-ATA II Hard Drive (5,400RPM) |
22 Jul 2010
|
#3 | | Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit |
Hello,
The Dump files unfortunately didn't help much. But few thing i would point to is out-dated driver the main reason to crash the System. Update them. Code: PBADRV64.sys Tue Jan 08 00:42:13 2008
dfmirage.sys Sat Jan 12 02:34:26 2008 Uninstall Symantec seems like something is causing trouble to it. Make sure you run the Cleanup Tool to clean the left over entries.
The crash has happen when IQW.EXE is running. From google few of them says it Trojan few says it from Company ISYS so if you don't have any program from ISYS then run Malwarebytes and do a complete system scan.
Hope this helps,
Captain | My System Specs | | System Manufacturer/Model Number Samsung NP550P5C-S02IN OS Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit CPU Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach Memory 8 GB Graphics Card NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno Sound Card SoundAlive™ JBL 3 Speakers (With sub-Woofer) Monitor(s) Displays 39.62cm (15.6) SuperBright 300nit HD+ LED Display Screen Resolution 1,600 x 900, Anti-Reflective Hard Drives 1TB S-ATA II Hard Drive (5,400RPM) |
23 Jul 2010
|
#4 | | |

Quote: Originally Posted by Capt.Jack Sparrow Hello,
The Dump files unfortunately didn't help much. But few thing i would point to is out-dated driver the main reason to crash the System. Update them. Code: PBADRV64.sys Tue Jan 08 00:42:13 2008
dfmirage.sys Sat Jan 12 02:34:26 2008 Uninstall Symantec seems like something is causing trouble to it. Make sure you run the Cleanup Tool to clean the left over entries.
Captain Is symantec not going to work with Isys, a search program we have, or may there be a way to install symantec in a way that Isys would work?
Also what driver is pbadrv64.sys pointing to? Google search is coming up mostly empty. | My System Specs | | System Manufacturer/Model Number Dell Optiplex 960 OS Windows 7 |
23 Jul 2010
|
#5 | | Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit |
If it's a search Program then you can leave it alone. Regarding the Symantec uninstall it and see how it goes if the system is stable then you know what i causing it. pbadrv64.sys belongs to DLS_Dell_Smartcard
- Captain | My System Specs | | System Manufacturer/Model Number Samsung NP550P5C-S02IN OS Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit CPU Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach Memory 8 GB Graphics Card NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno Sound Card SoundAlive™ JBL 3 Speakers (With sub-Woofer) Monitor(s) Displays 39.62cm (15.6) SuperBright 300nit HD+ LED Display Screen Resolution 1,600 x 900, Anti-Reflective Hard Drives 1TB S-ATA II Hard Drive (5,400RPM) |
23 Jul 2010
|
#6 | | |
In looking at the dump for a bit, it looks like the IQW.EXE process is terminating when the crash occurs. You've got unloaded virus def files, so I think Captain Jack is onto something here: Code: 1: kd> lmvm EX64
start end module name
fffff880`03c10000 fffff880`03dca000 EX64 (deferred)
Image path: \??\C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20100721.002\EX64.SYS
Image name: EX64.SYS
Timestamp: Thu Jul 01 14:19:15 2010 (4C2CDC23)
CheckSum: 001B81CB
ImageSize: 001BA000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
1: kd> lmvm SYMEVENT64x86
start end module name
fffff880`03dca000 fffff880`03e00000 SYMEVENT64x86 (deferred)
Image path: \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
Image name: SYMEVENT64x86.SYS
Timestamp: Wed Jun 24 16:19:12 2009 (4A428A40)
CheckSum: 0002B2E0
ImageSize: 00036000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4 I would suggest upgrading the engine too for Symantec when (or if, maybe) you reinstall it. Updates to the Symantec engine can be found here, for reference (the page on how to update symevent files that this was gathered from is here). The latest version is 12.5.3.2, and it's very recent. Yours is older, so upgrading that is always a good idea when symevent is involved. I would agree though, testing without Symantec installed (at all) is your best bet - if IQW still crashes, let's get more dumps. | My System Specs | | System Manufacturer/Model Number HP Z400 workstation OS Windows Server 2008 R2 CPU Intel Xeon 3550 @3.06GHz Motherboard HP Memory 16GB DDR3 Graphics Card Nvidia Quadro 600 Sound Card Realtek ALC262 Monitor(s) Displays 2x Hanns-G HG281 Screen Resolution 1920x1200 Keyboard Microsoft Natural Ergonomic Keyboard 7000 Mouse Microsoft Intellimouse Explorer 3.0 PSU HP Case HP Hard Drives 1x Samsung 160GB SSD
2x WD 1TB (RAID1) |
27 Jul 2010
|
#7 | | |
thanks for all your help guys, after updating the appropriate drivers and updating the engine it crashed on me.....i uninstalled symantec and it has yet to crash but i dont think we can afford not using this antivirus | My System Specs | | System Manufacturer/Model Number Dell Optiplex 960 OS Windows 7 |
27 Jul 2010
|
#8 | | Windows 7 Professional x64 Rednecksville |
Be sure to use Microsoft Security Essentials as your anti-virus. www.microsoft.com/Security_Essentials/ | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 Professional x64 CPU Intel i7 2600K OC'd @ 4620 MHz Motherboard Asus P8Z68-V Pro Memory 16GB GSkill Sniper 2133 Mhz (4x4GB) Graphics Card EVGA GeForce GTX 480 SuperClocked+ Sound Card Realtek High Definition Audio Monitor(s) Displays 2x Acer S273HLbmii 27" Screen Resolution 2 x 1920x1080 Keyboard Logitech MK320 (wireless) Mouse Logitech MK320 (wireless) PSU Corsair HW Series 750w (modular) Case Cooler Master HAF 932 Advanced Blue Edition Cooling CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans Hard Drives 64GB Crucial M4 SSD
Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM Internet Speed 30 Mb/s : 2 Mb/s |
27 Jul 2010
|
#9 | | Windows 7 Ultimate 32 bit Orlando, Florida |
John, Symantec is a known cause of crashes on some Win 7 systems. Take Jonathan's advice and install MSE. Also make sure Windows Firewall is turned on. Most 3rd party security suites, antivirus programs and firewalls have problems with Win 7, at least on some systems. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 Ultimate 32 bit CPU Intel(R) Pentium(R) 4 CPU 3.00GHz Motherboard ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5 Memory 2.50 GB RAM Graphics Card NVIDIA GeForce 7600 GS Sound Card SoundMax Integrated Digital Audio (Chip) Monitor(s) Displays ViewSonic VX 1962 wm Screen Resolution 1680 X 1050 Keyboard Microsoft Comfort Curve Keyboard 2000 v10 USB Mouse Logitec optic USB Cooling Fan based Hard Drives Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB Internet Speed 3.01 Mb/s download 0.64 Mb/s upload |
28 Jul 2010
|
#10 | | |
thanks for the tips, isys is not supported by win 7 ....i will try without symantec | My System Specs | | System Manufacturer/Model Number Dell Optiplex 960 OS Windows 7 BSOD: Software (Isys) Causing Issue? problems? All times are GMT -5. The time now is 05:07 PM. | |