Security App
Code:
2: kd> !thread
Stack Init fffff880033a8c70 Current fffff880033a7f00
Base fffff880033a9000 Limit fffff880033a3000 Call 0
2: kd> dps fffff880033a3000 fffff880033a9000
fffff880`033a8b08 fffff880`04591f3eUnable to load image \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for SYMEVENT64x86.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT64x86.SYS
SYMEVENT64x86+0x1cf3e
Crashes indicate Norton being a possible cause. Remove Norton and replace with Microsoft Security Essentials to see if it provides more stability. Uninstallers (removal tools) for common antivirus software
Microsoft Security Essentials and Malwarebytes, both recommended from a strict BSOD perspective.
Microsoft Security Essentials, Free antivirus for windows
Malwarebytes Anti-Malware Free
Information
DO NOT start the free trial of MalwareBytes. Deselect the option when prompted.
Tip
Make full scans with both separately.
Virus check
Scan your system with the following:
Kaspersky TDSSKiller - How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)
ESET online scanner - One-time virus scanner free with ESET online scanner
Daemon Tools/Alcohol %
Code:
sptd.sys Sun Aug 19 03:05:38 2012 (503003A2)
Daemon Tools (and Alcohol % software) are known to cause BSOD's on some Win7 systems (mostly due to the sptd.sys driver, although we have seen dtsoftbus01.sys blamed on several occasions). Please uninstall the program, then use the following free tool to ensure that the troublesome sptd.sys driver is removed from your system (pick the 32 or 64 bit system depending on your system's configuration): DuplexSecure - FAQ
As an alternative, many people recommend the use of Total Mounter or Magic ISO
This tutorial USB Selective Suspend - Turn On or Off may help you:
To Disable Selective Suspend:
Code:
1. open the control panel
2. go to power options (you may have to set view to small icons)
3. click change plan settings
4. in the window that opens:
5. click change plan settings
6. click change advanced power settings, expand usb and ensure usb selective suspend is disabled.
Check for an update on the drivers listed below. If no updates are available I recommend removal of the software using Revo uninstaller free.
Code:
wanatw64.sys Tue Apr 12 04:07:10 2005 (425AF50E)
Wan Miniport (ATW) America Online Driver Reference Table - wanatw64.sys
Code:
TVALZFL.sys Fri Jun 19 16:05:44 2009 (4A3B62F8)
TVALZ Filter Driver - Toshiba Driver Reference Table - TVALZFL.sys
Code:
FwLnk.sys Tue Jul 7 06:51:41 2009 (4A529C1D)
Toshiba Firmware Linkage service system driver (included in the Toshiba Value Added Package Driver Reference Table - FwLnk.sys
Basic checks: Please run these tests and report back the results
1. SFC /scannow to check windows for corruption - SFC /SCANNOW Command - System File Checker
2. Disk check for errors on the hard drive - How to Run Disk Check in Windows 7
3. Troubleshoot applications by a clean boot - Troubleshoot Application Conflicts by Performing a Clean Startup
4. Memtest86+ paying close attention to part 3 - RAM - Test with Memtest86+
5. Hard drive test from HDD mfg website - Hard Drive Diagnostic Procedure
Follow general fix for USB as well: USB Driver - General Fix for Problems
BSOD BUGCHECK SUMMARY
Code:
Debug session time: Mon May 13 14:26:35.084 2013 (UTC + 6:00)
Loading Dump File [C:\Users\Yusra\SysnativeBSODApps\051313-33649-01.dmp]
Built by: 7601.18113.amd64fre.win7sp1_gdr.130318-1533
System Uptime: 0 days 12:37:06.395
*** WARNING: Unable to verify timestamp for usbfilter.sys
*** ERROR: Module load completed but symbols could not be loaded for usbfilter.sys
Probably caused by : USBSTOR.SYS ( USBSTOR!memmove+80 )
BugCheck 50, {fffffa800b85d000, 0, fffff88009580a10, 0}
BugCheck Info: PAGE_FAULT_IN_NONPAGED_AREA (50)
Bugcheck code 00000050
Arguments:
Arg1: fffffa800b85d000, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff88009580a10, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
BUGCHECK_STR: 0x50
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
FAILURE_BUCKET_ID: X64_0x50_USBSTOR!memmove+80
BiosVersion = 1.30
BiosReleaseDate = 06/18/2012
SystemManufacturer = TOSHIBA
SystemProductName = Satellite S855D
ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``