Bsod first time ntoskrnl.exe help me please

drugo

New member
Member
VIP
Local time
9:26 PM
Messages
476
Bsod first time ntoskrnl.exe help me please crash ntoskrnl.exe+75c00

hi

some seconds ago i got a bsod w7 64bit ultimate

i used BlueScreenView.exe
and i got

A problem has been detected and Windows has been shut down to prevent damage
to your computer.

The problem seems to be caused by the following file: ntoskrnl.exe

IRQL_NOT_LESS_OR_EQUAL

If this is the first time you've seen this stop error screen,
restart your computer. If this screen appears again, follow
these steps:

Check to make sure any new hardware or software is properly installed.
If this is a new installation, ask your hardware or software manufacturer
for any Windows updates you might need.

If problems continue, disable or remove any newly installed hardware
or software. Disable BIOS memory options such as caching or shadowing.
If you need to use safe mode to remove or disable components, restart
your computer, press F8 to select Advanced Startup Options, and then
select Safe Mode.

Technical Information:

*** STOP: 0x0000000a (0x0000000000000000, 0x0000000000000002, 0x0000000000000001,
0xfffff80002c8dc2f)

*** ntoskrnl.exe - Address 0xfffff80002c84c00 base at 0xfffff80002c0f000 DateStamp
0x5147d9c6
==================================================
Filename : ntoskrnl.exe
Address In Stack : ntoskrnl.exe+f20c4
From Address : fffff800`02c0f000
To Address : fffff800`031f5000
Size : 0x005e6000
Time Stamp : 0x5147d9c6
Time String : 19/03/2013 05:21:42
Product Name : Microsoft® Windows® Operating System
File Description : NT Kernel & System
File Version : 6.1.7601.18113 (win7sp1_gdr.130318-1533)
Company : Microsoft Corporation
Full Path : C:\Windows\system32\ntoskrnl.exe
==================================================
i have Not installed new hardware or software or drivers

uploaded sf diagnostic tool too
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 ultimate 64bit
It appears that the cause of your BSOD is ESET epfwwfp.sys - ESET Personal Firewall Driver.

As a test, please remove ESET with Microsoft Security Essentials & the Free version of Malwarebytes, update and make full scans separately:
  • :info: Do not start the trial version of MalwareBytes
    picture.php
You may also take a look at:

Reduce items at start up:
Your Antivirus software is basically whats just needed there.

Use the System File Checker tool and Run Disk Check:

Code:
[FONT="Lucida Console"]BugCheck A, {0, 2, 1, fffff80002c8dc2f}
*** WARNING: Unable to verify timestamp for epfwwfp.sys
*** ERROR: Module load completed but symbols could not be loaded for epfwwfp.sys
Probably caused by : NETIO.SYS ( NETIO!WfpExpireEntryLru+17 )

Followup: MachineOwner
---------

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ebc100
GetUlongFromAddress: unable to read from fffff80002ebc1c0
 0000000000000000 Nonpaged pool

CURRENT_IRQL:  2

FAULTING_IP: 
nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+4f
fffff800`02c8dc2f 488713          xchg    rdx,qword ptr [rbx]

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0xA

PROCESS_NAME:  ekrn.exe

LAST_CONTROL_TRANSFER:  from fffff80002c841a9 to fffff80002c84c00

STACK_COMMAND:  kb

FOLLOWUP_IP: 
NETIO!WfpExpireEntryLru+17
fffff880`0194e9a7 488b4310        mov     rax,qword ptr [rbx+10h]

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  NETIO!WfpExpireEntryLru+17

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: NETIO

IMAGE_NAME:  NETIO.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  5034f6a0

FAILURE_BUCKET_ID:  X64_0xA_NETIO!WfpExpireEntryLru+17

BUCKET_ID:  X64_0xA_NETIO!WfpExpireEntryLru+17

Followup: MachineOwner
---------[/FONT]
Code:
STACK_TEXT:  
fffff880`09e39e78 fffff800`02c841a9 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`09e39e80 fffff800`02c82e20 : 00000000`00000010 fffff880`09e3a1b0 fffff880`00000003 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`09e39fc0 fffff800`02c8dc2f : 00000000`00000003 00000000`00000001 00000000`00000003 00000000`00000001 : nt!KiPageFault+0x260
fffff880`09e3a150 fffff880`0194e9a7 : 00000000`00000008 fffff880`09e3a430 00000000`00000000 fffffa80`0ccd97c8 : nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+0x4f
fffff880`09e3a1a0 fffff880`01ae5d4d : fffffa80`10d76af0 fffffa80`0ebfe010 fffff880`09e3a430 00000000`00000000 : NETIO!WfpExpireEntryLru+0x17
fffff880`09e3a1f0 fffff880`01aaa8d7 : 00000000`00000004 fffff880`01920030 fffffa80`0ce19060 00000000`00000001 : tcpip!WfpAleCloseRemoteEndpointConnection+0x2d
fffff880`09e3a220 fffff880`01b25b1b : fffffa80`10d76af0 fffffa80`112edc0a 00000000`00000028 fffffa80`10d76af0 : tcpip! ?? ::FNODOBFM::`string'+0x220a2
fffff880`09e3a370 fffff880`01b25ea2 : 00000000`4f196ada fffffa80`112edb40 00000000`00000000 00000000`00000028 : tcpip!WfpAleHandleSendCompletion+0xeb
fffff880`09e3a490 fffff880`01b30372 : fffffa80`111c9a30 fffffa80`111c9a30 00000000`00000000 00000000`00000000 : tcpip!WfpAlepAuthorizeSendCompletion+0x32
fffff880`09e3a4e0 fffff880`019b3af2 : 00000000`00000000 00000000`00000000 fffff880`0180e740 00000000`00000028 : tcpip!WfpAleCompleteOperation+0x162
fffff880`09e3a580 fffff880`01809141 : 00000000`00000000 00000000`00000000 fffff880`0180e740 00000000`00000028 : fwpkclnt!FwpsCompleteOperation0+0x1e
fffff880`09e3a5b0 00000000`00000000 : 00000000`00000000 fffff880`0180e740 00000000`00000028 00000000`00000001 : epfwwfp+0x9141
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self assembled
OS
Windows 10 Home 64Bit
CPU
Intel Core i5 10400 @ 2.90GHz
Motherboard
Intel Corporation DG41WV (PROCESSOR)
Memory
8.00GB Single-Channel Unknown @ 1329MHz (16-20-20-38)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E170S
Screen Resolution
1280x1024 pixels
Hard Drives
931GB TOSHIBA DT01ACA100 (SATA)
238GB TEAM TM8PS7256G (SATA SSD)
Case
Nothing Fancy
Cooling
Fans
Keyboard
A4 Tech Co LTD
Mouse
A4 Tech Co Ltd/Logitech
Internet Speed
25 Mbps
It appears that the cause of your BSOD is ESET epfwwfp.sys - ESET Personal Firewall Driver.

As a test, please remove ESET with Microsoft Security Essentials & the Free version of Malwarebytes, update and make full scans separately:

thanks a lot for answer

i have only smart security v5 64bit last buily
i have no malwarebytes


Code:
[FONT=Lucida Console]BugCheck A, {0, 2, 1, fffff80002c8dc2f}
*** WARNING: Unable to verify timestamp for epfwwfp.sys
*** ERROR: Module load completed but symbols could not be loaded for epfwwfp.sys
Probably caused by : NETIO.SYS ( NETIO!WfpExpireEntryLru+17 )

Followup: MachineOwner
---------

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ebc100
GetUlongFromAddress: unable to read from fffff80002ebc1c0
 0000000000000000 Nonpaged pool

CURRENT_IRQL:  2

FAULTING_IP: 
nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+4f
fffff800`02c8dc2f 488713          xchg    rdx,qword ptr [rbx]

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0xA

PROCESS_NAME:  ekrn.exe

LAST_CONTROL_TRANSFER:  from fffff80002c841a9 to fffff80002c84c00

STACK_COMMAND:  kb

FOLLOWUP_IP: 
NETIO!WfpExpireEntryLru+17
fffff880`0194e9a7 488b4310        mov     rax,qword ptr [rbx+10h]

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  NETIO!WfpExpireEntryLru+17

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: NETIO

IMAGE_NAME:  NETIO.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  5034f6a0

FAILURE_BUCKET_ID:  X64_0xA_NETIO!WfpExpireEntryLru+17

BUCKET_ID:  X64_0xA_NETIO!WfpExpireEntryLru+17

Followup: MachineOwner
---------[/FONT]
Code:
STACK_TEXT:  
fffff880`09e39e78 fffff800`02c841a9 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`09e39e80 fffff800`02c82e20 : 00000000`00000010 fffff880`09e3a1b0 fffff880`00000003 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`09e39fc0 fffff800`02c8dc2f : 00000000`00000003 00000000`00000001 00000000`00000003 00000000`00000001 : nt!KiPageFault+0x260
fffff880`09e3a150 fffff880`0194e9a7 : 00000000`00000008 fffff880`09e3a430 00000000`00000000 fffffa80`0ccd97c8 : nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+0x4f
fffff880`09e3a1a0 fffff880`01ae5d4d : fffffa80`10d76af0 fffffa80`0ebfe010 fffff880`09e3a430 00000000`00000000 : NETIO!WfpExpireEntryLru+0x17
fffff880`09e3a1f0 fffff880`01aaa8d7 : 00000000`00000004 fffff880`01920030 fffffa80`0ce19060 00000000`00000001 : tcpip!WfpAleCloseRemoteEndpointConnection+0x2d
fffff880`09e3a220 fffff880`01b25b1b : fffffa80`10d76af0 fffffa80`112edc0a 00000000`00000028 fffffa80`10d76af0 : tcpip! ?? ::FNODOBFM::`string'+0x220a2
fffff880`09e3a370 fffff880`01b25ea2 : 00000000`4f196ada fffffa80`112edb40 00000000`00000000 00000000`00000028 : tcpip!WfpAleHandleSendCompletion+0xeb
fffff880`09e3a490 fffff880`01b30372 : fffffa80`111c9a30 fffffa80`111c9a30 00000000`00000000 00000000`00000000 : tcpip!WfpAlepAuthorizeSendCompletion+0x32
fffff880`09e3a4e0 fffff880`019b3af2 : 00000000`00000000 00000000`00000000 fffff880`0180e740 00000000`00000028 : tcpip!WfpAleCompleteOperation+0x162
fffff880`09e3a580 fffff880`01809141 : 00000000`00000000 00000000`00000000 fffff880`0180e740 00000000`00000028 : fwpkclnt!FwpsCompleteOperation0+0x1e
fffff880`09e3a5b0 00000000`00000000 : 00000000`00000000 fffff880`0180e740 00000000`00000028 00000000`00000001 : epfwwfp+0x9141
may i know what is it this? i'm really a novice
is the minidump? is threre a program to read it?
do you find a here that can be eset?
thanks
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 ultimate 64bit

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self assembled
OS
Windows 10 Home 64Bit
CPU
Intel Core i5 10400 @ 2.90GHz
Motherboard
Intel Corporation DG41WV (PROCESSOR)
Memory
8.00GB Single-Channel Unknown @ 1329MHz (16-20-20-38)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E170S
Screen Resolution
1280x1024 pixels
Hard Drives
931GB TOSHIBA DT01ACA100 (SATA)
238GB TEAM TM8PS7256G (SATA SSD)
Case
Nothing Fancy
Cooling
Fans
Keyboard
A4 Tech Co LTD
Mouse
A4 Tech Co Ltd/Logitech
Internet Speed
25 Mbps
Look here: BugCheck A, {0, 2, 1, fffff80002c8dc2f}
*** WARNING: Unable to verify timestamp for epfwwfp.sys
*** ERROR: Module load completed but symbols could not be loaded for epfwwfp.sys
Probably caused by : NETIO.SYS ( NETIO!WfpExpireEntryLru+17 )


Driver Reference Table - epfwwfp.sys

epfwwfp.sys

Driver Description: ESET Personal Firewall Driver

Driver Update Site: Antivirus Downloads | ESET Internet Security Software Downloads

thanks i will uninstall and update
may i know which program did you use to open and read the dumpfile ?
i mean
BugCheck A, {0, 2, 1, fffff80002c8dc2f}
*** WARNING: Unable to verify timestamp for epfwwfp.sys
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 ultimate 64bit

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self assembled
OS
Windows 10 Home 64Bit
CPU
Intel Core i5 10400 @ 2.90GHz
Motherboard
Intel Corporation DG41WV (PROCESSOR)
Memory
8.00GB Single-Channel Unknown @ 1329MHz (16-20-20-38)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E170S
Screen Resolution
1280x1024 pixels
Hard Drives
931GB TOSHIBA DT01ACA100 (SATA)
238GB TEAM TM8PS7256G (SATA SSD)
Case
Nothing Fancy
Cooling
Fans
Keyboard
A4 Tech Co LTD
Mouse
A4 Tech Co Ltd/Logitech
Internet Speed
25 Mbps

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self assembled
OS
Windows 10 Home 64Bit
CPU
Intel Core i5 10400 @ 2.90GHz
Motherboard
Intel Corporation DG41WV (PROCESSOR)
Memory
8.00GB Single-Channel Unknown @ 1329MHz (16-20-20-38)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E170S
Screen Resolution
1280x1024 pixels
Hard Drives
931GB TOSHIBA DT01ACA100 (SATA)
238GB TEAM TM8PS7256G (SATA SSD)
Case
Nothing Fancy
Cooling
Fans
Keyboard
A4 Tech Co LTD
Mouse
A4 Tech Co Ltd/Logitech
Internet Speed
25 Mbps
Back
Top