New
#11
Johny, your crash dump makes me a bit . It's strange, and its rare.
So, it says that it is manually initiated. It may not be a fact, coz only the trolls do it, and you are not a troll :) It may be something happened, may be something played there beyond your knowledge.Code:Unable to load image rspCrash32.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for rspCrash32.sys *** ERROR: Module load completed but symbols could not be loaded for rspCrash32.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck DEADDEAD, {0, 0, 189dbc49, 3c2a58ed} Probably caused by : rspCrash32.sys ( rspCrash32+10b2 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* MANUALLY_INITIATED_CRASH1 (deaddead) The user manually initiated this crash dump. Arguments: Arg1: 00000000 Arg2: 00000000 Arg3: 189dbc49 Arg4: 3c2a58ed Debugging Details: ------------------ CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT BUGCHECK_STR: 0xDEADDEAD PROCESS_NAME: WhoCrashedEx.e CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from 9c5480b2 to 83d2ae98 STACK_TEXT: aef82ad0 9c5480b2 deaddead 00000000 00000000 nt!KeBugCheckEx+0x1e WARNING: Stack unwind information not available. Following frames may be wrong. aef82aec 84a2ead1 00000000 0012f508 00000018 rspCrash32+0x10b2 aef82b38 84a44641 9cf10c28 0012f508 00000018 fltmgr!FltpFilterMessage+0x9d aef82b6c 84a44a69 8b4dc300 00000000 0012f508 fltmgr!FltpMsgDeviceControl+0xa9 aef82bb0 84a2d339 8b3b0148 a0ea6f68 8b2c2898 fltmgr!FltpMsgDispatch+0x91 aef82bdc 83f7e6c3 8b3b0148 a0ea6f68 8b4dc398 fltmgr!FltpDispatch+0x33 aef82c00 83c82be0 00000000 a0ea6f68 8b3b0148 nt!IovCallDriver+0x258 aef82c14 83e77b29 8b4dc398 a0ea6f68 a0ea6fd8 nt!IofCallDriver+0x1b aef82c34 83e7acfb 8b3b0148 8b4dc398 00000000 nt!IopSynchronousServiceTail+0x1f8 aef82cd0 83ec163b 8b3b0148 a0ea6f68 00000000 nt!IopXxxControlFile+0x6aa aef82d04 83c898fa 000001cc 00000000 00000000 nt!NtDeviceIoControlFile+0x2a aef82d04 77147094 000001cc 00000000 00000000 nt!KiFastCallEntry+0x12a 0012f490 00000000 00000000 00000000 00000000 0x77147094 STACK_COMMAND: kb FOLLOWUP_IP: rspCrash32+10b2 9c5480b2 6a04 push 4 SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: rspCrash32+10b2 FOLLOWUP_NAME: MachineOwner MODULE_NAME: rspCrash32 IMAGE_NAME: rspCrash32.sys DEBUG_FLR_IMAGE_TIMESTAMP: 50976853 FAILURE_BUCKET_ID: 0xDEADDEAD_rspCrash32+10b2 BUCKET_ID: 0xDEADDEAD_rspCrash32+10b2 Followup: MachineOwner --------- 0: kd> lmvm rspCrash32 start end module name 9c547000 9c54e000 rspCrash32 T (no symbols) Loaded symbol image file: rspCrash32.sys Image path: rspCrash32.sys Image name: rspCrash32.sys Timestamp: Mon Nov 05 12:48:43 2012 (50976853) CheckSum: 000041EC ImageSize: 00007000 Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
This bugcheck code 0xDEADDEAD is some results of a registry manipulation, some registries of keyboard/mouse usage. TuneUp may cause it, as it mess up with the registries upto a great extent, and sometimes it comes to be beyond repair. Uninstall TuneUp Utilities. Run SFC /SCANNOW Command - System File Checker
It is expected that SFC will recover those errors of registry. If not, we need to take some different ways.
At the same time, rspCrash32.sys indicates to WhoCrashed. So better you uninstall it, too.
Let us know the results.