New
#1
SURPRISE BSOD
here are the dump files.help me pls
ekrn.exe which is part of your Eset/Nod32 Antivirus was involved in the crash, remove Eset and use MSE
Code:ehdrv.sys ehdrv.sys+17543 fffff880`0108e000 fffff880`010b3000 0x00025000 0x4b82a629 22/02/2010 19:43:37Code:******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 50, {fffffa8009433000, 0, fffffa8002ab9393, 0} Could not read faulting driver name Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+42877 ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: fffffa8009433000, memory referenced. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation. Arg3: fffffa8002ab9393, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000000, (reserved) Debugging Details: ------------------ Could not read faulting driver name READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ebe0e0 fffffa8009433000 FAULTING_IP: +0 fffffa80`02ab9393 66f2af repne scas word ptr [rdi] MM_INTERNAL_CODE: 0 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x50 PROCESS_NAME: ekrn.exe CURRENT_IRQL: 0 TRAP_FRAME: fffff8800293e610 -- (.trap 0xfffff8800293e610) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000000000 rbx=0000000000000000 rcx=ffffffffffff77ff rdx=0000000000000104 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa8002ab9393 rsp=fffff8800293e7a0 rbp=fffffa8009422000 r8=fffffa8009422000 r9=0000000000000050 r10=fffff880009e7b80 r11=fffffa80084c6af0 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na pe cy fffffa80`02ab9393 66f2af repne scas word ptr [rdi] Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002d06e54 to fffff80002c86600 STACK_TEXT: fffff880`0293e4a8 fffff800`02d06e54 : 00000000`00000050 fffffa80`09433000 00000000`00000000 fffff880`0293e610 : nt!KeBugCheckEx fffff880`0293e4b0 fffff800`02c846ee : 00000000`00000000 00000000`04e6f37c fffff800`02e15a00 fffff880`009e7180 : nt! ?? ::FNODOBFM::`string'+0x42877 fffff880`0293e610 fffffa80`02ab9393 : 00000000`04e6f37c 00000000`00000104 fffffa80`09422000 00000000`00000014 : nt!KiPageFault+0x16e fffff880`0293e7a0 00000000`04e6f37c : 00000000`00000104 fffffa80`09422000 00000000`00000014 00000000`00000104 : 0xfffffa80`02ab9393 fffff880`0293e7a8 00000000`00000104 : fffffa80`09422000 00000000`00000014 00000000`00000104 fffffa80`02aadd0b : 0x4e6f37c fffff880`0293e7b0 fffffa80`09422000 : 00000000`00000014 00000000`00000104 fffffa80`02aadd0b 00000000`04e6f37c : 0x104 fffff880`0293e7b8 00000000`00000014 : 00000000`00000104 fffffa80`02aadd0b 00000000`04e6f37c 00000000`00000051 : 0xfffffa80`09422000 fffff880`0293e7c0 00000000`00000104 : fffffa80`02aadd0b 00000000`04e6f37c 00000000`00000051 00000000`000080e8 : 0x14 fffff880`0293e7c8 fffffa80`02aadd0b : 00000000`04e6f37c 00000000`00000051 00000000`000080e8 00000000`00000000 : 0x104 fffff880`0293e7d0 00000000`04e6f37c : 00000000`00000051 00000000`000080e8 00000000`00000000 fffffa80`0366e060 : 0xfffffa80`02aadd0b fffff880`0293e7d8 00000000`00000051 : 00000000`000080e8 00000000`00000000 fffffa80`0366e060 fffffa80`02abf787 : 0x4e6f37c fffff880`0293e7e0 00000000`000080e8 : 00000000`00000000 fffffa80`0366e060 fffffa80`02abf787 fffffa80`0366e060 : 0x51 fffff880`0293e7e8 00000000`00000000 : fffffa80`0366e060 fffffa80`02abf787 fffffa80`0366e060 00000000`00000001 : 0x80e8 STACK_COMMAND: kb FOLLOWUP_IP: nt! ?? ::FNODOBFM::`string'+42877 fffff800`02d06e54 cc int 3 SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+42877 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cfeb FAILURE_BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+42877 BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+42877 Followup: MachineOwner ---------
Hi sonnycrys.
STOP 0x0000003B: SYSTEM_SERVICE_EXCEPTION
Usual causes: System service, Device driver, graphics driver, ?memory
Your latest dump file lists cdd.dll as the probable cause. This is a Windows System file and for it to be the cause of your crash is highly unlikely.
Old and incompatible drivers can and do cause issues with Windows 7, often giving false error codes.
As a Priority:
The sptd.sys driver is notorious for causing BSOD's with Windows 7. It's a driver used and installed along with Daemon Tools and Alcohol 120 which you'll also have to uninstall.
Then use the correct (32bit or 64bit) download from Duplex Secure - Downloads to uninstall the SPTD.SYS driver.
Make sure to select the uninstall button! DO NOT SELECT INSTALL!!
Download the latest Catalyst SetUp.**
Download and install Driver Sweeper.
Boot to Safe Mode
Uninstall your current Catalyst SetUp.
Run Driver Sweeper to clean up any left overs.
Reboot to Normal Mode.
Install your new Catalyst SetUp.
eamonm.sys Mon Feb 22 15:43:00 2010
ehdrv.sys Mon Feb 22 15:43:37 2010
epfwwfpr.sys Mon Feb 22 15:39:54 2010 Your ESET Security, Update.
Outdated Drivers. Update:
Rt64win7.sys Thu Mar 04 13:42:52 2010 Realtek PCIe GBE Family Controller v7.043
RTKVHD64.sys Mon Feb 08 10:24:50 2010 Realtek HD Audio R2.59
Bugcheck Analysis:Drivers:Code:******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff80002c8e6de, Address of the instruction which caused the bugcheck Arg3: fffff88007c32e40, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. FAULTING_IP: nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+26 fffff800`02c8e6de f00fba3100 lock btr dword ptr [rcx],0 CONTEXT: fffff88007c32e40 -- (.cxr 0xfffff88007c32e40) rax=fffffa8001db9060 rbx=0000000000000000 rcx=0000000000000000 rdx=fffffa8001db9060 rsi=00000000ffffffff rdi=fffffa8001db9060 rip=fffff80002c8e6de rsp=fffff88007c33810 rbp=0000000000000001 r8=0000000000000000 r9=0000000000000000 r10=0000000000003060 r11=fffff88007c33860 r12=0000000000000000 r13=0000000000000001 r14=0000000000000000 r15=fffff900c26479f0 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+0x26: fffff800`02c8e6de f00fba3100 lock btr dword ptr [rcx],0 ds:002b:00000000`00000000=???????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: ehshell.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff9600079dce0 to fffff80002c8e6de STACK_TEXT: fffff880`07c33810 fffff960`0079dce0 : 00000000`00000000 0000045c`00000000 00001020`00000000 00000000`00000001 : nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+0x26 fffff880`07c33840 fffff960`000f5080 : 00000000`00000001 fffff900`c00bf010 00000000`00000001 fffff900`c3060cd0 : cdd!CddBitmapHw::Release+0xc0 fffff880`07c33880 fffff960`000fd4a9 : 00000000`00000000 00000000`00000001 fffff900`c3060cd0 fffff900`00000000 : win32k!SURFACE::bDeleteSurface+0x358 fffff880`07c339d0 fffff960`000f4920 : 00000000`0000045c 00000000`00000000 fffff900`c09f9ce0 fffff960`00000000 : win32k!NtGdiCloseProcess+0x2c9 fffff880`07c33a30 fffff960`000f4063 : fffffa80`03680600 00000000`00000001 fffffa80`01db9060 fffffa80`03242b30 : win32k!GdiProcessCallout+0x200 fffff880`07c33ab0 fffff800`02faa881 : fffffa80`03680690 00000000`00000000 00000000`00000000 fffffa80`01db9060 : win32k!W32pProcessCallout+0x6b fffff880`07c33ae0 fffff800`02f826eb : 00000000`00000000 00000000`00000001 fffffa80`03242b00 00000000`00000000 : nt!PspExitThread+0x561 fffff880`07c33ba0 fffff800`02cc3853 : fffffa80`03242b30 fffff880`00000000 00000000`00203f20 fffffa80`01db9060 : nt!NtTerminateProcess+0x25b fffff880`07c33c20 00000000`777e017a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0015fdb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777e017a FOLLOWUP_IP: cdd!CddBitmapHw::Release+c0 fffff960`0079dce0 488b4738 mov rax,qword ptr [rdi+38h] SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: cdd!CddBitmapHw::Release+c0 FOLLOWUP_NAME: MachineOwner MODULE_NAME: cdd IMAGE_NAME: cdd.dll DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bde94 STACK_COMMAND: .cxr 0xfffff88007c32e40 ; kb FAILURE_BUCKET_ID: X64_0x3B_cdd!CddBitmapHw::Release+c0 BUCKET_ID: X64_0x3B_cdd!CddBitmapHw::Release+c0 Followup: MachineOwnerLet us know how it goes.Code:fffff880`00c00000 fffff880`00c57000 ACPI ACPI.sys Tue Jul 14 00:19:34 2009 (4A5BC106) fffff880`043af000 fffff880`043c7000 adfs adfs.SYS Thu Jun 26 21:52:37 2008 (48640195) fffff880`02c7c000 fffff880`02d06000 afd afd.sys Tue Jul 14 00:21:40 2009 (4A5BC184) fffff880`0419f000 fffff880`041b5000 AgileVpn AgileVpn.sys Tue Jul 14 01:10:24 2009 (4A5BCCF0) fffff880`03cff000 fffff880`03d16000 amdk8 amdk8.sys Tue Jul 14 00:19:25 2009 (4A5BC0FD) fffff880`01141000 fffff880`0114c000 amdxata amdxata.sys Tue May 19 18:56:59 2009 (4A12F2EB) fffff880`01103000 fffff880`0110c000 atapi atapi.sys Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`0110c000 fffff880`01136000 ataport ataport.SYS Tue Jul 14 00:19:52 2009 (4A5BC118) fffff880`052f2000 fffff880`05312000 AtihdW76 AtihdW76.sys Fri Sep 24 06:44:48 2010 (4C9C3AD0) fffff880`04807000 fffff880`04ffc000 atikmdag atikmdag.sys Wed Oct 27 03:29:53 2010 (4CC78EA1) fffff880`03c7b000 fffff880`03cc6000 atikmpag atikmpag.sys Wed Oct 27 03:14:23 2010 (4CC78AFF) fffff960`00950000 fffff960`009b1000 ATMFD ATMFD.DLL Thu Jul 30 06:07:22 2009 (4A712A8A) fffff880`011d6000 fffff880`011dd000 Beep Beep.SYS Tue Jul 14 01:00:13 2009 (4A5BCA8D) fffff880`02d89000 fffff880`02d9a000 blbdrive blbdrive.sys Tue Jul 14 00:35:59 2009 (4A5BC4DF) fffff880`02bc8000 fffff880`02be6000 bowser bowser.sys Tue Jul 14 00:23:50 2009 (4A5BC206) fffff960`00790000 fffff960`007b7000 cdd cdd.dll Tue Jul 14 02:25:40 2009 (4A5BDE94) fffff880`011ac000 fffff880`011d6000 cdrom cdrom.sys Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff880`00d00000 fffff880`00dc0000 CI CI.dll Tue Jul 14 02:32:13 2009 (4A5BE01D) fffff880`01200000 fffff880`01230000 CLASSPNP CLASSPNP.SYS Tue Jul 14 00:19:58 2009 (4A5BC11E) fffff880`00ca2000 fffff880`00d00000 CLFS CLFS.SYS Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`0147c000 fffff880`014ef000 cng cng.sys Tue Jul 14 00:49:40 2009 (4A5BC814) fffff880`0418f000 fffff880`0419f000 CompositeBus CompositeBus.sys Tue Jul 14 01:00:33 2009 (4A5BCAA1) fffff880`0531e000 fffff880`0532c000 crashdmp crashdmp.sys Tue Jul 14 01:01:01 2009 (4A5BCABD) fffff880`00f58000 fffff880`00fdb000 csc csc.sys Tue Jul 14 00:24:26 2009 (4A5BC22A) fffff880`00c57000 fffff880`00c75000 dfsc dfsc.sys Tue Jul 14 00:23:44 2009 (4A5BC200) fffff880`02c68000 fffff880`02c77000 discache discache.sys Tue Jul 14 00:37:18 2009 (4A5BC52E) fffff880`017ca000 fffff880`017e0000 disk disk.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`052ca000 fffff880`052ec000 drmk drmk.sys Tue Jul 14 02:01:25 2009 (4A5BD8E5) fffff880`05338000 fffff880`05341000 dump_atapi dump_atapi.sys Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`0532c000 fffff880`05338000 dump_ataport dump_ataport.sys Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`05341000 fffff880`05354000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 00:21:51 2009 (4A5BC18F) fffff880`05312000 fffff880`0531e000 Dxapi Dxapi.sys Tue Jul 14 00:38:28 2009 (4A5BC574) fffff880`04055000 fffff880`04149000 dxgkrnl dxgkrnl.sys Fri Oct 02 02:00:14 2009 (4AC5509E) fffff880`04149000 fffff880`0418f000 dxgmms1 dxgmms1.sys Tue Jul 14 00:38:32 2009 (4A5BC578) fffff880`02a92000 fffff880`02b7a000 eamonm eamonm.sys Mon Feb 22 15:43:00 2010 (4B82A604) fffff880`00eb5000 fffff880`00eda000 ehdrv ehdrv.sys Mon Feb 22 15:43:37 2010 (4B82A629) fffff880`043c7000 fffff880`043e8000 epfwwfpr epfwwfpr.sys Mon Feb 22 15:39:54 2010 (4B82A54A) fffff880`03d16000 fffff880`03d23000 fdc fdc.sys Tue Jul 14 01:00:54 2009 (4A5BCAB6) fffff880`01198000 fffff880`011ac000 fileinfo fileinfo.sys Tue Jul 14 00:34:25 2009 (4A5BC481) fffff880`04335000 fffff880`04340000 flpydisk flpydisk.sys Tue Jul 14 01:00:54 2009 (4A5BCAB6) fffff880`0114c000 fffff880`01198000 fltmgr fltmgr.sys Tue Jul 14 00:19:59 2009 (4A5BC11F) fffff880`01500000 fffff880`0150a000 Fs_Rec Fs_Rec.sys Tue Jul 14 00:19:45 2009 (4A5BC111) fffff880`01790000 fffff880`017ca000 fvevol fvevol.sys Tue Jul 14 00:22:15 2009 (4A5BC1A7) fffff880`0168d000 fffff880`016d7000 fwpkclnt fwpkclnt.sys Tue Jul 14 00:21:08 2009 (4A5BC164) fffff800`02c0b000 fffff800`02c54000 hal hal.dll Tue Jul 14 02:27:36 2009 (4A5BDF08) fffff880`03c00000 fffff880`03c24000 HDAudBus HDAudBus.sys Tue Jul 14 01:06:13 2009 (4A5BCBF5) fffff880`05362000 fffff880`0537b000 HIDCLASS HIDCLASS.SYS Tue Jul 14 01:06:21 2009 (4A5BCBFD) fffff880`0537b000 fffff880`05383080 HIDPARSE HIDPARSE.SYS Tue Jul 14 01:06:17 2009 (4A5BCBF9) fffff880`05354000 fffff880`05362000 hidusb hidusb.sys Tue Jul 14 01:06:22 2009 (4A5BCBFE) fffff880`04200000 fffff880`042c8000 HTTP HTTP.sys Tue Jul 14 00:22:16 2009 (4A5BC1A8) fffff880`01787000 fffff880`01790000 hwpolicy hwpolicy.sys Tue Jul 14 00:19:22 2009 (4A5BC0FA) fffff880`03d40000 fffff880`03d5e000 i8042prt i8042prt.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`03cc6000 fffff880`03cd5000 kbdclass kbdclass.sys Tue Jul 14 00:19:50 2009 (4A5BC116) fffff880`05386000 fffff880`05394000 kbdhid kbdhid.sys Tue Jul 14 01:00:20 2009 (4A5BCA94) fffff800`00bb8000 fffff800`00bc2000 kdcom kdcom.dll Tue Jul 14 02:31:07 2009 (4A5BDFDB) fffff880`042e0000 fffff880`04323000 ks ks.sys Tue Jul 14 01:00:31 2009 (4A5BCA9F) fffff880`01462000 fffff880`0147c000 ksecdd ksecdd.sys Tue Jul 14 00:20:54 2009 (4A5BC156) fffff880`01662000 fffff880`0168d000 ksecpkg ksecpkg.sys Tue Jul 14 00:50:34 2009 (4A5BC84A) fffff880`052ec000 fffff880`052f1200 ksthunk ksthunk.sys Tue Jul 14 01:00:19 2009 (4A5BCA93) fffff880`02b9b000 fffff880`02bb0000 lltdio lltdio.sys Tue Jul 14 01:08:50 2009 (4A5BCC92) fffff880`0500e000 fffff880`05031000 luafv luafv.sys Tue Jul 14 00:26:13 2009 (4A5BC295) fffff880`00c81000 fffff880`00c8e000 mcupdate mcupdate.dll Tue Jul 14 02:29:09 2009 (4A5BDF65) fffff880`05000000 fffff880`0500e000 monitor monitor.sys Tue Jul 14 00:38:52 2009 (4A5BC58C) fffff880`03d5e000 fffff880`03d6d000 mouclass mouclass.sys Tue Jul 14 00:19:50 2009 (4A5BC116) fffff880`010e9000 fffff880`01103000 mountmgr mountmgr.sys Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff880`02be6000 fffff880`02bfe000 mpsdrv mpsdrv.sys Tue Jul 14 01:08:25 2009 (4A5BCC79) fffff880`02a00000 fffff880`02a2d000 mrxsmb mrxsmb.sys Sat Feb 27 07:52:19 2010 (4B88CF33) fffff880`02a2d000 fffff880`02a7b000 mrxsmb10 mrxsmb10.sys Sat Feb 27 07:52:28 2010 (4B88CF3C) fffff880`05031000 fffff880`05054000 mrxsmb20 mrxsmb20.sys Sat Feb 27 07:52:26 2010 (4B88CF3A) fffff880`01136000 fffff880`01141000 msahci msahci.sys Tue Jul 14 01:01:01 2009 (4A5BCABD) fffff880`00f11000 fffff880`00f1c000 Msfs Msfs.SYS Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`01042000 fffff880`0104c000 msisadrv msisadrv.sys Tue Jul 14 00:19:26 2009 (4A5BC0FE) fffff880`01404000 fffff880`01462000 msrpc msrpc.sys Tue Jul 14 00:21:32 2009 (4A5BC17C) fffff880`02c5d000 fffff880`02c68000 mssmbios mssmbios.sys Tue Jul 14 00:31:10 2009 (4A5BC3BE) fffff880`01775000 fffff880`01787000 mup mup.sys Tue Jul 14 00:23:45 2009 (4A5BC201) fffff880`0150a000 fffff880`015fc000 ndis ndis.sys Tue Jul 14 00:21:40 2009 (4A5BC184) fffff880`041d9000 fffff880`041e5000 ndistapi ndistapi.sys Tue Jul 14 01:10:00 2009 (4A5BCCD8) fffff880`04000000 fffff880`0402f000 ndiswan ndiswan.sys Tue Jul 14 01:10:11 2009 (4A5BCCE3) fffff880`0439a000 fffff880`043af000 NDProxy NDProxy.SYS Tue Jul 14 01:10:05 2009 (4A5BCCDD) fffff880`02d7a000 fffff880`02d89000 netbios netbios.sys Tue Jul 14 01:09:26 2009 (4A5BCCB6) fffff880`02d06000 fffff880`02d4b000 netbt netbt.sys Tue Jul 14 00:21:28 2009 (4A5BC178) fffff880`01602000 fffff880`01662000 NETIO NETIO.SYS Tue Jul 14 00:21:46 2009 (4A5BC18A) fffff880`00f1c000 fffff880`00f2d000 Npfs Npfs.SYS Tue Jul 14 00:19:48 2009 (4A5BC114) fffff880`02c51000 fffff880`02c5d000 nsiproxy nsiproxy.sys Tue Jul 14 00:21:02 2009 (4A5BC15E) fffff800`02c54000 fffff800`03230000 nt ntkrnlmp.exe Sat Feb 27 07:55:23 2010 (4B88CFEB) fffff880`0125b000 fffff880`013fe000 Ntfs Ntfs.sys Tue Jul 14 00:20:47 2009 (4A5BC14F) fffff880`0124c000 fffff880`01255000 Null Null.SYS Tue Jul 14 00:19:37 2009 (4A5BC109) fffff880`02d54000 fffff880`02d7a000 pacer pacer.sys Tue Jul 14 01:09:41 2009 (4A5BCCC5) fffff880`03d23000 fffff880`03d40000 parport parport.sys Tue Jul 14 01:00:40 2009 (4A5BCAA8) fffff880`0104c000 fffff880`01061000 partmgr partmgr.sys Tue Jul 14 00:19:58 2009 (4A5BC11E) fffff880`0100f000 fffff880`01042000 pci pci.sys Tue Jul 14 00:19:51 2009 (4A5BC117) fffff880`010d2000 fffff880`010d9000 pciide pciide.sys Tue Jul 14 00:19:49 2009 (4A5BC115) fffff880`010d9000 fffff880`010e9000 PCIIDEX PCIIDEX.SYS Tue Jul 14 00:19:48 2009 (4A5BC114) fffff880`014ef000 fffff880`01500000 pcw pcw.sys Tue Jul 14 00:19:27 2009 (4A5BC0FF) fffff880`058a8000 fffff880`0594e000 peauth peauth.sys Tue Jul 14 02:01:19 2009 (4A5BD8DF) fffff880`0528d000 fffff880`052ca000 portcls portcls.sys Tue Jul 14 01:06:27 2009 (4A5BCC03) fffff880`00c8e000 fffff880`00ca2000 PSHED PSHED.dll Tue Jul 14 02:32:23 2009 (4A5BE027) fffff880`041b5000 fffff880`041d9000 rasl2tp rasl2tp.sys Tue Jul 14 01:10:11 2009 (4A5BCCE3) fffff880`0402f000 fffff880`0404a000 raspppoe raspppoe.sys Tue Jul 14 01:10:17 2009 (4A5BCCE9) fffff880`03ddf000 fffff880`03e00000 raspptp raspptp.sys Tue Jul 14 01:10:18 2009 (4A5BCCEA) fffff880`041e5000 fffff880`041ff000 rassstp rassstp.sys Tue Jul 14 01:10:25 2009 (4A5BCCF1) fffff880`02c00000 fffff880`02c51000 rdbss rdbss.sys Tue Jul 14 00:24:09 2009 (4A5BC219) fffff880`0404a000 fffff880`04055000 rdpbus rdpbus.sys Tue Jul 14 01:17:46 2009 (4A5BCEAA) fffff880`01000000 fffff880`01009000 RDPCDD RDPCDD.sys Tue Jul 14 01:16:34 2009 (4A5BCE62) fffff880`00eff000 fffff880`00f08000 rdpencdd rdpencdd.sys Tue Jul 14 01:16:34 2009 (4A5BCE62) fffff880`00f08000 fffff880`00f11000 rdprefmp rdprefmp.sys Tue Jul 14 01:16:35 2009 (4A5BCE63) fffff880`0173b000 fffff880`01775000 rdyboost rdyboost.sys Tue Jul 14 00:34:34 2009 (4A5BC48A) fffff880`02bb0000 fffff880`02bc8000 rspndr rspndr.sys Tue Jul 14 01:08:50 2009 (4A5BCC92) fffff880`03c24000 fffff880`03c7b000 Rt64win7 Rt64win7.sys Thu Mar 04 13:42:52 2010 (4B8FB8DC) fffff880`05065000 fffff880`0528cf80 RTKVHD64 RTKVHD64.sys Mon Feb 08 10:24:50 2010 (4B6FE672) fffff880`02dd5000 fffff880`02def000 SCDEmu SCDEmu.SYS Mon Apr 12 09:52:25 2010 (4BC2DF49) fffff880`00dc0000 fffff880`00def000 SCSIPORT SCSIPORT.SYS Tue Jul 14 01:01:04 2009 (4A5BCAC0) fffff880`0594e000 fffff880`05959000 secdrv secdrv.SYS Wed Sep 13 14:18:38 2006 (4508052E) fffff880`01733000 fffff880`0173b000 spldr spldr.sys Mon May 11 17:56:27 2009 (4A0858BB) fffff880`05cca000 fffff880`05d62000 srv srv.sys Tue Dec 08 08:32:55 2009 (4B1E0F37) fffff880`05c61000 fffff880`05cca000 srv2 srv2.sys Tue Jul 14 00:25:02 2009 (4A5BC24E) fffff880`05959000 fffff880`05986000 srvnet srvnet.sys Tue Dec 08 08:32:26 2009 (4B1E0F1A) fffff880`04ffc000 fffff880`04ffd480 swenum swenum.sys Tue Jul 14 01:00:18 2009 (4A5BCA92) fffff880`01803000 fffff880`01a00000 tcpip tcpip.sys Tue Jul 14 00:25:34 2009 (4A5BC26E) fffff880`05986000 fffff880`05998000 tcpipreg tcpipreg.sys Tue Jul 14 01:09:49 2009 (4A5BCCCD) fffff880`00f4b000 fffff880`00f58000 TDI TDI.SYS Tue Jul 14 00:21:18 2009 (4A5BC16E) fffff880`00f2d000 fffff880`00f4b000 tdx tdx.sys Tue Jul 14 00:21:15 2009 (4A5BC16B) fffff880`02dc1000 fffff880`02dd5000 termdd termdd.sys Tue Jul 14 01:16:36 2009 (4A5BCE64) fffff960`00540000 fffff960`0054a000 TSDDD TSDDD.dll Tue Jul 14 01:16:34 2009 (4A5BCE62) fffff880`05d62000 fffff880`05d6a000 TuneUpUtilitiesDriver64 TuneUpUtilitiesDriver64.sys Thu Sep 17 12:54:52 2009 (4AB2238C) fffff880`03cd9000 fffff880`03cff000 tunnel tunnel.sys Tue Jul 14 01:09:37 2009 (4A5BCCC1) fffff880`04323000 fffff880`04335000 umbus umbus.sys Tue Jul 14 01:06:56 2009 (4A5BCC20) fffff880`053df000 fffff880`053f9c00 usbaudio usbaudio.sys Tue Jul 14 01:06:31 2009 (4A5BCC07) fffff880`05394000 fffff880`053b1000 usbccgp usbccgp.sys Tue Jul 14 01:06:45 2009 (4A5BCC15) fffff880`05384000 fffff880`05385f00 USBD USBD.SYS Tue Jul 14 01:06:23 2009 (4A5BCBFF) fffff880`03dce000 fffff880`03ddf000 usbehci usbehci.sys Sat Oct 24 05:27:33 2009 (4AE28235) fffff880`04340000 fffff880`0439a000 usbhub usbhub.sys Sat Oct 24 05:28:24 2009 (4AE28268) fffff880`03d6d000 fffff880`03d78000 usbohci usbohci.sys Tue Jul 14 01:06:30 2009 (4A5BCC06) fffff880`03d78000 fffff880`03dce000 USBPORT USBPORT.SYS Tue Jul 14 01:06:31 2009 (4A5BCC07) fffff880`053b1000 fffff880`053de100 usbvideo usbvideo.sys Tue Jul 14 01:07:00 2009 (4A5BCC24) fffff880`00fe5000 fffff880`00ff2000 vdrvroot vdrvroot.sys Tue Jul 14 01:01:31 2009 (4A5BCADB) fffff880`011dd000 fffff880`011eb000 vga vga.sys Tue Jul 14 00:38:47 2009 (4A5BC587) fffff880`00eda000 fffff880`00eff000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 00:38:51 2009 (4A5BC58B) fffff880`016d7000 fffff880`016e7000 vmstorfl vmstorfl.sys Tue Jul 14 00:42:54 2009 (4A5BC67E) fffff880`01061000 fffff880`01076000 volmgr volmgr.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`01076000 fffff880`010d2000 volmgrx volmgrx.sys Tue Jul 14 00:20:33 2009 (4A5BC141) fffff880`016e7000 fffff880`01733000 volsnap volsnap.sys Tue Jul 14 00:20:08 2009 (4A5BC128) fffff880`02da6000 fffff880`02dc1000 wanarp wanarp.sys Tue Jul 14 01:10:21 2009 (4A5BCCED) fffff880`011eb000 fffff880`011fb000 watchdog watchdog.sys Tue Jul 14 00:37:35 2009 (4A5BC53F) fffff880`00e02000 fffff880`00ea6000 Wdf01000 Wdf01000.sys Tue Jul 14 00:22:07 2009 (4A5BC19F) fffff880`00ea6000 fffff880`00eb5000 WDFLDR WDFLDR.SYS Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff880`02d4b000 fffff880`02d54000 wfplwf wfplwf.sys Tue Jul 14 01:09:26 2009 (4A5BCCB6) fffff960`00030000 fffff960`0033f000 win32k win32k.sys Tue Jul 14 00:40:16 2009 (4A5BC5E0) fffff880`00fdc000 fffff880`00fe5000 WMILIB WMILIB.SYS Tue Jul 14 00:19:51 2009 (4A5BC117) fffff880`02b7a000 fffff880`02b9b000 WudfPf WudfPf.sys Tue Jul 14 01:05:37 2009 (4A5BCBD1) Unloaded modules: fffff880`05800000 fffff880`05871000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`017e0000 fffff880`017ee000 crashdmp.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`017ee000 fffff880`017fa000 dump_ataport Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000C000 fffff880`01230000 fffff880`01239000 dump_atapi.s Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00009000 fffff880`01239000 fffff880`0124c000 dump_dumpfve Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00013000 fffff880`02d89000 fffff880`02da6000 serial.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0001D000 fffff880`00eb5000 fffff880`00fdc000 sptd.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00127000
HTH.
thx i will let you know how the thing work