BSOD - Memory

Page 1 of 3 123 LastLast

  1. Posts : 37
    Windows 7 Ultimate 32-bit
       #1

    BSOD - Memory


    Hello,

    I recently fixed a BSOD what I kept getting by re-formatting my computer; now. When I start to play a game, or watch a You Tube video or anything as high resource then it will give me a BSOD; driver_irql_not_less_or_equal .

    I believe it could be my hard drive, but I honestly am not to sure; I will give you all the files you guys need.
      My Computer


  2. Posts : 6,668
    Windows 7 x64
       #2

    I'm showing your nvidia driver as the source of the problem.
    Debugger is being really really slow this morning, so give me some time and I'll be back with some more info.

    Code:
    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: e491db48, memory referenced
    Arg2: 00000004, IRQL
    Arg3: 00000008, value 0 = read operation, 1 = write operation
    Arg4: e491db48, address which referenced memory
    
    Debugging Details:
    ------------------
    
    
    READ_ADDRESS: GetPointerFromAddress: unable to read from 831bb718
    Unable to read MiSystemVaType memory at 8319b160
     e491db48 
    
    CURRENT_IRQL:  4
    
    FAULTING_IP: 
    +6132396263366133
    e491db48 ??              ???
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0xD1
    
    PROCESS_NAME:  Wow.exe
    
    TRAP_FRAME:  af4b7b64 -- (.trap 0xffffffffaf4b7b64)
    ErrCode = 00000010
    eax=87176009 ebx=00000000 ecx=00000017 edx=00000002 esi=85a34008 edi=00000001
    eip=e491db48 esp=af4b7bd8 ebp=af4b7c78 iopl=0         nv up ei ng nz na pe nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010286
    e491db48 ??              ???
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from e491db48 to 8309981b
    
    FAILED_INSTRUCTION_ADDRESS: 
    +6132396263366133
    e491db48 ??              ???
    
    STACK_TEXT:  
    af4b7b64 e491db48 badb0d00 00000002 87176008 nt!KiTrap0E+0x2cf
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    af4b7bd4 91b42a69 87176009 00000100 00000000 0xe491db48
    af4b7c78 91b38cc7 87176008 9243d698 00000000 nvlddmkm+0x139a69
    af4b7c94 91ac2a3a 85a04a68 8731fbb0 8731f000 nvlddmkm+0x12fcc7
    af4b7cb0 91ac477d 00000000 91a8b1f9 9243d698 nvlddmkm+0xb9a3a
    af4b7ce4 9248a8ec 91a1c274 00000000 af4b7d08 nvlddmkm+0xbb77d
    af4b7cf4 9249bc38 875ecc80 859f3340 00000000 dxgkrnl!DpiFdoMessageInterruptRoutine+0x17
    af4b7d08 8309279d 875ecc80 859f3340 af4b7d34 dxgkrnl!DpiFdoLineInterruptRoutine+0x12
    af4b7d08 771369e5 875ecc80 859f3340 af4b7d34 nt!KiInterruptDispatch+0x6d
    16e9fb04 00000000 00000000 00000000 00000000 0x771369e5
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nvlddmkm+139a69
    91b42a69 ??              ???
    
    SYMBOL_STACK_INDEX:  2
    
    SYMBOL_NAME:  nvlddmkm+139a69
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nvlddmkm
    
    IMAGE_NAME:  nvlddmkm.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c379162
    
    FAILURE_BUCKET_ID:  0xD1_CODE_AV_BAD_IP_nvlddmkm+139a69
    
    BUCKET_ID:  0xD1_CODE_AV_BAD_IP_nvlddmkm+139a69
    
    Followup: MachineOwner
    ---------
    Mind you, there is an enormous number of dumpfiles in your info there and I'm just focusing on the most recent one right now.

    You have a whole set of drivers I have never seen before, and that are not registered in the driver database online.

    90c14000 90c19900 MpKslf3de4cbc MpKslf3de4cbc.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    90c1a000 90c1f900 MpKsl917f11d6 MpKsl917f11d6.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    90c20000 90c25900 MpKsl73f71863 MpKsl73f71863.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    90c26000 90c2b900 MpKsl53cc62a3 MpKsl53cc62a3.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    90c2c000 90c31900 MpKsl42dc0f1d MpKsl42dc0f1d.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    90c32000 90c37900 MpKsl2e27b32a MpKsl2e27b32a.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)

    google also returns nothing on these drivers. Do you know what they relate to?

    My first two suggestions is to either update or rollback the nvidia driver, and to run a malware scan on your system.
      My Computer


  3. Posts : 37
    Windows 7 Ultimate 32-bit
    Thread Starter
       #3

    Maguscreed said:
    I'm showing your nvidia driver as the source of the problem.
    Debugger is being really really slow this morning, so give me some time and I'll be back with some more info.
    Okay thank you, I will see what I can do to update it; will this be my nVida Chipset or my display driver?
      My Computer


  4. Posts : 6,668
    Windows 7 x64
       #4

    See above for additional information.

    It's the nvidia kernel that is crashing so I can't distinguish whether it's motherboard or graphics because the kernel is present in both.
      My Computer


  5. Posts : 37
    Windows 7 Ultimate 32-bit
    Thread Starter
       #5

    Maguscreed said:
    See above for additional information.

    It's the nvidia kernel that is crashing so I can't distinguish whether it's motherboard or graphics because the kernel is present in both.
    Right, the drivers you said I haven't ever seen before. I will spend an hour or so to-do my best to update any possible driver I am aware of.

    Then, after i have done that I will post on the thread saying so and we will see if a BSOD will occur again.
      My Computer


  6. Posts : 6,668
    Windows 7 x64
       #6

    Go ahead and clear out the minidumps, there are so many it will be hard to distinguish between them and new ones. The current ones are already a part of your first upload.
      My Computer


  7. Posts : 37
    Windows 7 Ultimate 32-bit
    Thread Starter
       #7

    Maguscreed said:
    Go ahead and clear out the minidumps, there are so many it will be hard to distinguish between them and new ones. The current ones are already a part of your first upload.
    Right, I have updated nearly 8 drivers using; Driver Genius. It detected quite a few drivers.

    The chipset, display, HD Recorder, sound and even my Logitech keyboard was updated.

    If I receive a BSOD then I post all the information you need if I receive it.
      My Computer


  8. Posts : 37
    Windows 7 Ultimate 32-bit
    Thread Starter
       #8

    Right, I just received the same BSOD as I did with the others; here is the attachment.
      My Computer


  9. Posts : 6,668
    Windows 7 x64
       #9

    Actually it has changed in the bugcheck as it now is targeting tcpip.sys directly.
    Code:
    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: 00000000, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000008, value 0 = read operation, 1 = write operation
    Arg4: 00000000, address which referenced memory
    
    Debugging Details:
    ------------------
    
    
    READ_ADDRESS: GetPointerFromAddress: unable to read from 831ab718
    Unable to read MiSystemVaType memory at 8318b160
     00000000 
    
    CURRENT_IRQL:  2
    
    FAULTING_IP: 
    +6132396263366133
    00000000 ??              ???
    
    PROCESS_NAME:  System
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0xD1
    
    TRAP_FRAME:  831692b0 -- (.trap 0xffffffff831692b0)
    ErrCode = 00000010
    eax=00000000 ebx=00000000 ecx=000a45dc edx=00000000 esi=884ac110 edi=ffffffff
    eip=00000000 esp=83169324 ebp=8316935c iopl=0         nv up ei pl zr na pe nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010246
    00000000 ??              ???
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from 00000000 to 8308981b
    
    FAILED_INSTRUCTION_ADDRESS: 
    +6132396263366133
    00000000 ??              ???
    
    STACK_TEXT:  
    831692b0 00000000 badb0d00 00000000 831694ac nt!KiTrap0E+0x2cf
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    83169320 b6800000 00000000 00001b0c 00000000 0x0
    8316935c 8ba91594 86019690 00000b68 00000001 0xb6800000
    83169380 8ba62e5f 01019690 014ac110 c4ce46e9 tcpip!TcpBwManageTrackedData+0xa1
    8316939c 8ba62df5 86019690 c4ce46e9 0000037c tcpip!TcpBwNotifyInboundStatusChange+0x48
    831693d0 8ba8d117 86019690 0000037c 00000000 tcpip!TcpRtbNotifyDelivery+0xd5
    831693ec 8ba92eee 86019690 0000037c 85bb9f00 tcpip!TcpAdvanceTcbRcvWnd+0x1f
    83169470 8ba93661 86019690 86019788 831694ac tcpip!TcpDeliverDataToClient+0x283
    831694c4 8bad0d4f 86019690 86019788 85bb9f00 tcpip!TcpDeliverReceive+0x96
    831694f4 8ba98362 86019690 86019788 85bb9f00 tcpip!TcpInspectReceive+0x77
    83169544 8ba975a6 86019690 83169568 831695a0 tcpip!TcpTcbFastDatagram+0x2fd
    831695ac 8ba979ac 867cdf40 86019690 00169620 tcpip!TcpTcbReceive+0x142
    83169614 8ba86b4c 86354e68 867bd000 00000000 tcpip!TcpMatchReceive+0x237
    83169664 8ba868ae 867cdf40 867bd000 00005000 tcpip!TcpPreValidatedReceive+0x293
    83169680 8ba8c273 867cdf40 867bd000 831696bc tcpip!TcpReceive+0x2d
    83169690 8babe50e 831696a4 c000023e 00000000 tcpip!TcpNlClientReceiveDatagrams+0x12
    831696bc 8babe2d1 8bb1df88 83169710 c000023e tcpip!IppDeliverListToProtocol+0x49
    831696dc 8babdfa6 8bb1dd98 00000006 83169710 tcpip!IppProcessDeliverList+0x2a
    83169734 8babbbe4 8bb1dd98 00000006 00000000 tcpip!IppReceiveHeaderBatch+0x1f2
    831697c8 8babab75 871de0b0 00000000 00000001 tcpip!IpFlcReceivePackets+0xbe5
    83169844 8babace6 87ad7780 8789da80 00000000 tcpip!FlpReceiveNonPreValidatedNetBufferListChain+0x746
    83169878 830d3092 8789da80 aebaf489 867a37c0 tcpip!FlReceiveNetBufferListChainCalloutRoutine+0x11e
    831698e0 8babad6e 8bababc8 83169908 00000000 nt!KeExpandKernelStackAndCalloutEx+0x132
    8316991c 8b8a018d 87ad7702 8789da00 00000000 tcpip!FlReceiveNetBufferListChain+0x7c
    83169954 8b88e670 87af9008 8789da80 00000000 ndis!ndisMIndicateNetBufferListsToOpen+0x188
    8316997c 8b88e5e7 00000000 8789da80 871ad0e0 ndis!ndisIndicateSortedNetBufferLists+0x4a
    83169af8 8b839ca5 871ad0e0 00000000 00000000 ndis!ndisMDispatchReceiveNetBufferLists+0x129
    83169b14 8b88ea2e 871ad0e0 8789da80 00000000 ndis!ndisMTopReceiveNetBufferLists+0x2d
    83169b3c 8b839c1e 871ad0e0 8789da80 00000000 ndis!ndisMIndicateReceiveNetBufferListsInternal+0x62
    83169b64 9257d74a 871ad0e0 8789da80 00000000 ndis!NdisMIndicateReceiveNetBufferLists+0x52
    83169b90 92595d46 00000001 8789da80 8f38d000 nvmf6232+0x474a
    83169bcc 92596749 000005ea 83169be8 00000000 nvmf6232+0x1cd46
    83169bf8 9257ebb8 00000000 00000000 83169c40 nvmf6232+0x1d749
    83169c10 8b88e301 925abbb8 00000000 00000000 nvmf6232+0x5bb8
    83169c50 8b8399f4 87967f2c 00967d98 00000000 ndis!ndisMiniportDpc+0xda
    83169c78 830ab4f5 87967f2c 87967d98 00000000 ndis!ndisInterruptDpc+0xaf
    83169cd4 830ab358 8316cd20 83176280 00000000 nt!KiExecuteAllDpcs+0xf9
    83169d20 830ab178 00000000 0000000e 00000000 nt!KiRetireDpcList+0xd5
    83169d24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    tcpip!TcpBwManageTrackedData+a1
    8ba91594 807d0b00        cmp     byte ptr [ebp+0Bh],0
    
    SYMBOL_STACK_INDEX:  3
    
    SYMBOL_NAME:  tcpip!TcpBwManageTrackedData+a1
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: tcpip
    
    IMAGE_NAME:  tcpip.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c15a3db
    
    FAILURE_BUCKET_ID:  0xD1_CODE_AV_NULL_IP_tcpip!TcpBwManageTrackedData+a1
    
    BUCKET_ID:  0xD1_CODE_AV_NULL_IP_tcpip!TcpBwManageTrackedData+a1
    
    Followup: MachineOwner
    ---------
    What security/antivirus software are you using?
    This could be caused by a overzealous firewall application.
    I'm going to do a complete driver dump this time, it will take a bit longer than before. Check back in about 20 minutes and I'll edit this post.

    Meanwhile run a full scan with malwarebytes (update after install)
    http://www.malwarebytes.org/
    you have some files I'm not familiar with appearing in the driver dump, this could be a sign of a malware infection.

    Driver dump follows for reference.

    Code:
    80b9b000 80ba3000   kdcom    kdcom.dll    Mon Jul 13 20:08:58 2009 (4A5BDAAA)
    82600000 82609000   TSDDD    TSDDD.dll    unavailable (00000000)
    82630000 8264e000   cdd      cdd.dll      unavailable (00000000)
    82650000 8269d000   ATMFD    ATMFD.DLL    unavailable (00000000)
    827a0000 829eb000   win32k   win32k.sys   unavailable (00000000)
    8300c000 83043000   hal      halmacpi.dll Mon Jul 13 18:11:03 2009 (4A5BBF07)
    83043000 83453000   nt       ntkrpamp.exe Tue Oct 26 21:30:44 2010 (4CC78ED4)
    83612000 8368a000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 20:06:41 2009 (4A5BDA21)
    8368a000 8369b000   PSHED    PSHED.dll    Mon Jul 13 20:09:36 2009 (4A5BDAD0)
    8369b000 836a3000   BOOTVID  BOOTVID.dll  Mon Jul 13 20:04:34 2009 (4A5BD9A2)
    836a3000 836e5000   CLFS     CLFS.SYS     Mon Jul 13 18:11:10 2009 (4A5BBF0E)
    836e5000 83790000   CI       CI.dll       Mon Jul 13 20:09:28 2009 (4A5BDAC8)
    83790000 837c4000   fltmgr   fltmgr.sys   Mon Jul 13 18:11:13 2009 (4A5BBF11)
    837c4000 837ea680   MpFilter MpFilter.sys Tue Sep 14 16:23:59 2010 (4C8FE7EF)
    837eb000 837fe000   HIDCLASS HIDCLASS.SYS Mon Jul 13 18:51:01 2009 (4A5BC865)
    8b400000 8b411000   fileinfo fileinfo.sys Mon Jul 13 18:21:51 2009 (4A5BC18F)
    8b411000 8b418d80   LHidFilt LHidFilt.Sys Tue Aug 24 12:20:48 2010 (4C73FF70)
    8b41f000 8b490000   Wdf01000 Wdf01000.sys Mon Jul 13 18:11:36 2009 (4A5BBF28)
    8b490000 8b49e000   WDFLDR   WDFLDR.SYS   Mon Jul 13 18:11:25 2009 (4A5BBF1D)
    8b49e000 8b4e6000   ACPI     ACPI.sys     Mon Jul 13 18:11:11 2009 (4A5BBF0F)
    8b4e6000 8b4ef000   WMILIB   WMILIB.SYS   Mon Jul 13 18:11:22 2009 (4A5BBF1A)
    8b4ef000 8b4f7000   msisadrv msisadrv.sys Mon Jul 13 18:11:09 2009 (4A5BBF0D)
    8b4f7000 8b521000   pci      pci.sys      Mon Jul 13 18:11:16 2009 (4A5BBF14)
    8b521000 8b52c000   vdrvroot vdrvroot.sys Mon Jul 13 18:46:19 2009 (4A5BC74B)
    8b52c000 8b53d000   partmgr  partmgr.sys  Mon Jul 13 18:11:35 2009 (4A5BBF27)
    8b53d000 8b54d000   volmgr   volmgr.sys   Mon Jul 13 18:11:25 2009 (4A5BBF1D)
    8b54d000 8b598000   volmgrx  volmgrx.sys  Mon Jul 13 18:11:41 2009 (4A5BBF2D)
    8b598000 8b59f000   pciide   pciide.sys   Mon Jul 13 18:11:19 2009 (4A5BBF17)
    8b59f000 8b5ad000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 18:11:15 2009 (4A5BBF13)
    8b5ad000 8b5c3000   mountmgr mountmgr.sys Mon Jul 13 18:11:27 2009 (4A5BBF1F)
    8b5c3000 8b5cc000   atapi    atapi.sys    Mon Jul 13 18:11:15 2009 (4A5BBF13)
    8b5cc000 8b5ef000   ataport  ataport.SYS  Mon Jul 13 18:11:18 2009 (4A5BBF16)
    8b5ef000 8b5f8000   amdxata  amdxata.sys  Tue May 19 12:57:35 2009 (4A12F30F)
    8b601000 8b730000   Ntfs     Ntfs.sys     Mon Jul 13 18:12:05 2009 (4A5BBF45)
    8b730000 8b75b000   msrpc    msrpc.sys    Mon Jul 13 18:11:59 2009 (4A5BBF3F)
    8b75b000 8b76e000   ksecdd   ksecdd.sys   Mon Jul 13 18:11:56 2009 (4A5BBF3C)
    8b76e000 8b7cb000   cng      cng.sys      Mon Jul 13 18:32:55 2009 (4A5BC427)
    8b7cb000 8b7d9000   pcw      pcw.sys      Mon Jul 13 18:11:10 2009 (4A5BBF0E)
    8b7d9000 8b7e2000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 18:11:14 2009 (4A5BBF12)
    8b7e2000 8b7ee000   vga      vga.sys      Mon Jul 13 18:25:50 2009 (4A5BC27E)
    8b7ee000 8b7f9000   mouhid   mouhid.sys   Mon Jul 13 18:45:08 2009 (4A5BC704)
    8b800000 8b80c000   kbdhid   kbdhid.sys   Mon Jul 13 18:45:09 2009 (4A5BC705)
    8b811000 8b830000   cdrom    cdrom.sys    Mon Jul 13 18:11:24 2009 (4A5BBF1C)
    8b830000 8b837000   Null     Null.SYS     Mon Jul 13 18:11:12 2009 (4A5BBF10)
    8b838000 8b8ef000   ndis     ndis.sys     Mon Jul 13 18:12:24 2009 (4A5BBF58)
    8b8ef000 8b92d000   NETIO    NETIO.SYS    Thu Apr 08 21:32:21 2010 (4BBE91B5)
    8b92d000 8b952000   ksecpkg  ksecpkg.sys  Thu Dec 10 22:04:22 2009 (4B21C4C6)
    8b952000 8b962000   mup      mup.sys      Mon Jul 13 18:14:14 2009 (4A5BBFC6)
    8b962000 8b96a000   hwpolicy hwpolicy.sys Mon Jul 13 18:11:01 2009 (4A5BBF05)
    8b96a000 8b99c000   fvevol   fvevol.sys   Fri Sep 25 21:24:21 2009 (4ABD7B55)
    8b99c000 8b9ad000   disk     disk.sys     Mon Jul 13 18:11:28 2009 (4A5BBF20)
    8b9ad000 8b9d2000   CLASSPNP CLASSPNP.SYS Mon Jul 13 18:11:20 2009 (4A5BBF18)
    8b9d2000 8b9e9000   usbccgp  usbccgp.sys  Mon Jul 13 18:51:31 2009 (4A5BC883)
    8b9e9000 8b9f1580   LEqdUsb  LEqdUsb.Sys  Tue Aug 24 12:20:28 2010 (4C73FF5C)
    8b9f3000 8b9fa000   Beep     Beep.SYS     Mon Jul 13 18:45:00 2009 (4A5BC6FC)
    8ba00000 8ba2d000   rdyboost rdyboost.sys Mon Jul 13 18:22:02 2009 (4A5BC19A)
    8ba2d000 8ba2d680   giveio   giveio.sys   Wed Apr 03 21:33:25 1996 (316334F5)
    8ba34000 8bb7d000   tcpip    tcpip.sys    Sun Jun 13 22:36:59 2010 (4C15A3DB)
    8bb7d000 8bbae000   fwpkclnt fwpkclnt.sys Mon Jul 13 18:12:03 2009 (4A5BBF43)
    8bbae000 8bbb6380   vmstorfl vmstorfl.sys Mon Jul 13 18:28:44 2009 (4A5BC32C)
    8bbb7000 8bbf6000   volsnap  volsnap.sys  Mon Jul 13 18:11:34 2009 (4A5BBF26)
    8bbf6000 8bbfe000   spldr    spldr.sys    Mon May 11 11:13:47 2009 (4A084EBB)
    8bbfe000 8bbff480   speedfan speedfan.sys Sun Sep 24 08:28:47 2006 (4516880F)
    8fe00000 8fe17000   raspptp  raspptp.sys  Mon Jul 13 18:54:47 2009 (4A5BC947)
    8fe17000 8fe2e000   rassstp  rassstp.sys  Mon Jul 13 18:54:57 2009 (4A5BC951)
    8fe2e000 8fe38000   rdpbus   rdpbus.sys   Mon Jul 13 19:02:40 2009 (4A5BCB20)
    8fe3d000 8fea1000   csc      csc.sys      Mon Jul 13 18:15:08 2009 (4A5BBFFC)
    8fea1000 8feb9000   dfsc     dfsc.sys     Mon Jul 13 18:14:16 2009 (4A5BBFC8)
    8feb9000 8fec7000   blbdrive blbdrive.sys Mon Jul 13 18:23:04 2009 (4A5BC1D8)
    8fec7000 8fee8000   tunnel   tunnel.sys   Mon Jul 13 18:54:03 2009 (4A5BC91B)
    8fee8000 8fefa000   intelppm intelppm.sys Mon Jul 13 18:11:03 2009 (4A5BBF07)
    8fefa000 8ff05000   fdc      fdc.sys      Mon Jul 13 18:45:45 2009 (4A5BC729)
    8ff05000 8ff0f000   serenum  serenum.sys  Mon Jul 13 18:45:27 2009 (4A5BC717)
    8ff0f000 8ff1a000   irsir    irsir.sys    Fri Jan 18 23:55:21 2008 (479190C9)
    8ff1a000 8ff23000   irenum   irenum.sys   Mon Jul 13 18:53:27 2009 (4A5BC8F7)
    8ff23000 8ff2c000   nvsmu    nvsmu.sys    Mon Jun 29 02:36:34 2009 (4A486F02)
    8ff2c000 8ff36000   usbohci  usbohci.sys  Mon Jul 13 18:51:14 2009 (4A5BC872)
    8ff36000 8ff81000   USBPORT  USBPORT.SYS  Mon Jul 13 18:51:13 2009 (4A5BC871)
    8ff81000 8ff90000   usbehci  usbehci.sys  Fri Oct 23 22:58:55 2009 (4AE27B7F)
    8ff90000 8ffaf000   HDAudBus HDAudBus.sys Mon Jul 13 18:50:55 2009 (4A5BC85F)
    8ffaf000 8ffba000   ndistapi ndistapi.sys Mon Jul 13 18:54:24 2009 (4A5BC930)
    8ffba000 8ffdc000   ndiswan  ndiswan.sys  Mon Jul 13 18:54:34 2009 (4A5BC93A)
    8ffdc000 8fff4000   raspppoe raspppoe.sys Mon Jul 13 18:54:53 2009 (4A5BC94D)
    8fff4000 8ffff000   hidusb   hidusb.sys   Mon Jul 13 18:51:04 2009 (4A5BC868)
    90800000 9080d000   mouclass mouclass.sys Mon Jul 13 18:11:15 2009 (4A5BBF13)
    90814000 90835000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 18:25:49 2009 (4A5BC27D)
    90835000 90842000   watchdog watchdog.sys Mon Jul 13 18:24:10 2009 (4A5BC21A)
    90842000 9084a000   RDPCDD   RDPCDD.sys   Mon Jul 13 19:01:40 2009 (4A5BCAE4)
    9084a000 90852000   rdpencdd rdpencdd.sys Mon Jul 13 19:01:39 2009 (4A5BCAE3)
    90852000 9085a000   rdprefmp rdprefmp.sys Mon Jul 13 19:01:41 2009 (4A5BCAE5)
    9085a000 90865000   Msfs     Msfs.SYS     Mon Jul 13 18:11:26 2009 (4A5BBF1E)
    90865000 90873000   Npfs     Npfs.SYS     Mon Jul 13 18:11:31 2009 (4A5BBF23)
    90873000 9088a000   tdx      tdx.sys      Mon Jul 13 18:12:10 2009 (4A5BBF4A)
    9088a000 90895000   TDI      TDI.SYS      Mon Jul 13 18:12:12 2009 (4A5BBF4C)
    90895000 908ef000   afd      afd.sys      Mon Jul 13 18:12:34 2009 (4A5BBF62)
    908ef000 90921000   netbt    netbt.sys    Mon Jul 13 18:12:18 2009 (4A5BBF52)
    90921000 90928000   wfplwf   wfplwf.sys   Mon Jul 13 18:53:51 2009 (4A5BC90F)
    90928000 90947000   pacer    pacer.sys    Mon Jul 13 18:53:58 2009 (4A5BC916)
    90947000 90955000   netbios  netbios.sys  Mon Jul 13 18:53:54 2009 (4A5BC912)
    90955000 9096f000   serial   serial.sys   Mon Jul 13 18:45:33 2009 (4A5BC71D)
    9096f000 90982000   wanarp   wanarp.sys   Mon Jul 13 18:55:02 2009 (4A5BC956)
    90982000 90992000   termdd   termdd.sys   Mon Jul 13 19:01:35 2009 (4A5BCADF)
    90992000 909d3000   rdbss    rdbss.sys    Mon Jul 13 18:14:26 2009 (4A5BBFD2)
    909d3000 909dd000   nsiproxy nsiproxy.sys Mon Jul 13 18:12:08 2009 (4A5BBF48)
    909dd000 909e7000   mssmbios mssmbios.sys Mon Jul 13 18:19:25 2009 (4A5BC0FD)
    909e7000 909f3000   discache discache.sys Mon Jul 13 18:24:04 2009 (4A5BC214)
    909f3000 90a00000   kbdclass kbdclass.sys Mon Jul 13 18:11:15 2009 (4A5BBF13)
    91a00000 91a06480   HIDPARSE HIDPARSE.SYS Mon Jul 13 18:50:59 2009 (4A5BC863)
    91a09000 92486dc0   nvlddmkm nvlddmkm.sys Fri Jul 09 16:15:14 2010 (4C379162)
    92487000 92488040   nvBridge nvBridge.kmd Fri Jul 09 16:10:11 2010 (4C379033)
    92489000 92540000   dxgkrnl  dxgkrnl.sys  Mon Nov 01 21:37:53 2010 (4CCF7981)
    92540000 92579000   dxgmms1  dxgmms1.sys  Wed Feb 02 21:34:49 2011 (4D4A2259)
    92579000 925bd880   nvmf6232 nvmf6232.sys Thu Jul 30 18:47:55 2009 (4A72312B)
    925be000 925c7000   wmiacpi  wmiacpi.sys  Mon Jul 13 18:19:16 2009 (4A5BC0F4)
    925c7000 925d4000   CompositeBus CompositeBus.sys Mon Jul 13 18:45:26 2009 (4A5BC716)
    925d4000 925e6000   AgileVpn AgileVpn.sys Mon Jul 13 18:55:00 2009 (4A5BC954)
    925e6000 925fe000   rasl2tp  rasl2tp.sys  Mon Jul 13 18:54:33 2009 (4A5BC939)
    94237000 9425d780   hcwhdpvr hcwhdpvr.sys Wed Jun 23 12:21:28 2010 (4C224298)
    9425e000 94269000   AmUStor  AmUStor.SYS  Fri Aug 21 01:48:12 2009 (4A8E432C)
    94269000 9427cb00   usbaudio usbaudio.sys Mon Jul 13 18:51:23 2009 (4A5BC87B)
    9427d000 94298000   luafv    luafv.sys    Mon Jul 13 18:15:44 2009 (4A5BC020)
    94298000 942b2000   WudfPf   WudfPf.sys   Mon Jul 13 18:50:13 2009 (4A5BC835)
    942b2000 942d0000   irda     irda.sys     Mon Jul 13 18:53:30 2009 (4A5BC8FA)
    942d0000 942e0000   lltdio   lltdio.sys   Mon Jul 13 18:53:18 2009 (4A5BC8EE)
    942e0000 942f3000   rspndr   rspndr.sys   Mon Jul 13 18:53:20 2009 (4A5BC8F0)
    942f3000 94378000   HTTP     HTTP.sys     Mon Jul 13 18:12:53 2009 (4A5BBF75)
    94378000 94391000   bowser   bowser.sys   Mon Jul 13 18:14:21 2009 (4A5BBFCD)
    94391000 943a3000   mpsdrv   mpsdrv.sys   Mon Jul 13 18:52:52 2009 (4A5BC8D4)
    943a3000 943c6000   mrxsmb   mrxsmb.sys   Sat Feb 27 01:32:02 2010 (4B88CA72)
    96600000 96611000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 18:12:47 2009 (4A5BBF6F)
    96611000 9661c000   monitor  monitor.sys  Mon Jul 13 18:25:58 2009 (4A5BC286)
    9661c000 9661d700   USBD     USBD.SYS     Mon Jul 13 18:51:05 2009 (4A5BC869)
    9661e000 9661ee80   LHidEqd  LHidEqd.Sys  Tue Aug 24 12:20:32 2010 (4C73FF60)
    96624000 96640800   mcdbus   mcdbus.sys   Tue Feb 24 04:42:13 2009 (49A3CF05)
    96641000 96667000   SCSIPORT SCSIPORT.SYS Mon Jul 13 18:45:55 2009 (4A5BC733)
    96667000 96668380   swenum   swenum.sys   Mon Jul 13 18:45:08 2009 (4A5BC704)
    96669000 9669d000   ks       ks.sys       Wed Mar 03 21:57:52 2010 (4B8F2FC0)
    9669d000 966ab000   umbus    umbus.sys    Mon Jul 13 18:51:38 2009 (4A5BC88A)
    966ab000 966b5000   flpydisk flpydisk.sys Mon Jul 13 18:45:45 2009 (4A5BC729)
    966b5000 966f9000   usbhub   usbhub.sys   Fri Oct 23 23:00:05 2009 (4AE27BC5)
    966f9000 9670a000   NDProxy  NDProxy.SYS  Mon Jul 13 18:54:27 2009 (4A5BC933)
    9675a000 96789000   portcls  portcls.sys  Mon Jul 13 18:51:00 2009 (4A5BC864)
    96789000 967a2000   drmk     drmk.sys     Mon Jul 13 19:36:05 2009 (4A5BD2F5)
    967a2000 967bf000   nvhda32v nvhda32v.sys Mon Jun 21 17:07:07 2010 (4C1FE28B)
    967bf000 967c9000   Dxapi    Dxapi.sys    Mon Jul 13 18:25:25 2009 (4A5BC265)
    967c9000 967df000   cdfs     cdfs.sys     Mon Jul 13 18:11:14 2009 (4A5BBF12)
    967df000 967ec000   crashdmp crashdmp.sys Mon Jul 13 18:45:50 2009 (4A5BC72E)
    967ec000 967f7000   dump_dumpata dump_dumpata.sys Mon Jul 13 18:11:16 2009 (4A5BBF14)
    967f7000 96800000   dump_atapi dump_atapi.sys Mon Jul 13 18:11:15 2009 (4A5BBF13)
    9ba3f000 9ba7a000   mrxsmb10 mrxsmb10.sys Sat Feb 27 01:32:21 2010 (4B88CA85)
    9ba7a000 9ba95000   mrxsmb20 mrxsmb20.sys Sat Feb 27 01:32:11 2010 (4B88CA7B)
    9baad000 9bab6000   cpuz135_x32 cpuz135_x32.sys Tue Nov 09 07:32:57 2010 (4CD94D89)
    9bab6000 9bb4d000   peauth   peauth.sys   Mon Jul 13 19:35:44 2009 (4A5BD2E0)
    9bb4d000 9bb57000   secdrv   secdrv.SYS   Wed Sep 13 08:18:32 2006 (45080528)
    9bb57000 9bb78000   srvnet   srvnet.sys   Thu Aug 26 22:30:39 2010 (4C77315F)
    9bb78000 9bb85000   tcpipreg tcpipreg.sys Mon Jul 13 18:54:14 2009 (4A5BC926)
    9bb85000 9bbd4000   srv2     srv2.sys     Thu Aug 26 22:30:45 2010 (4C773165)
    9ca12000 9ca63000   srv      srv.sys      Thu Aug 26 22:31:26 2010 (4C77318E)
    9ca63000 9ca6c200   MpNWMon  MpNWMon.sys  Tue Sep 14 16:23:50 2010 (4C8FE7E6)
    9ca6d000 9ca72900   MpKslcc908e06 MpKslcc908e06.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
    9ca73000 9ca7ec00   NisDrvWFP NisDrvWFP.sys Tue Sep 14 16:24:12 2010 (4C8FE7FC)
    9ca7f000 9ca9f480   WUDFRd   WUDFRd.sys   Mon Jul 13 18:50:44 2009 (4A5BC854)
    9caa0000 9caca000   fastfat  fastfat.SYS  Mon Jul 13 18:14:01 2009 (4A5BBFB9)
    ac431000 ac76a340   RTKVHDA  RTKVHDA.sys  Tue Jan 25 04:29:34 2011 (4D3EA60E)
    
    Unloaded modules:
    ac77b000 ac77d000   MSPQM.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00002000
    ac774000 ac77b000   drmkaud.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00007000
    ac772000 ac774000   MSTEE.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00002000
    ac770000 ac772000   MSPQM.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00002000
    ac76d000 ac770000   MSKSSRV.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00003000
    ac76b000 ac76d000   MSPCLOCK.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00002000
    9670a000 9675a000   HdAudio.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00050000
    9ba95000 9baad000   parport.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00018000
    8b9d2000 8b9df000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  0000D000
    8b9df000 8b9ea000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  0000B000
    8b9ea000 8b9f3000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00009000
    8b800000 8b811000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
        ImageSize:  00011000
    Please uninstall speedfan for the time being as well.
    still unable to identify
    Code:
    9ca6d000 9ca72900   MpKslcc908e06 MpKslcc908e06.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
      My Computer


  10. Posts : 37
    Windows 7 Ultimate 32-bit
    Thread Starter
       #10

    Okay;

    The Anti-Virus, I use only 'Microsoft Security Essentials'. I'm not sure, but I may also use AVG; I honestly don't think I do.

    I will run the malwarebytes test now, and I will keep check on the post.

    I think this maybe MagicISO? Or has that already been identified, I know that MagicISO uses there own drivers.
    Code:
    9ca6d000 9ca72900   MpKslcc908e06 MpKslcc908e06.sys Tue Mar 30 21:06:14 2010 (4BB2AE16)
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 04:31.
Find Us