Będę sukcesywnie po kolei debugował bsody od najnowszych.
SYSTEM_SERVICE_EXCEPTION (3b)
Błąd oznacza iż nastąpił wyjątek (exception) podczas wykonywania procedury/funkcji (routine) obsługiwanym przez uruchomiony wątek i próbujący stać się takim który ma uprawnienia na wykonywanie operacji I/O (privileged code).
W tym wypadku proces avastui czyli interfejs graficzny Avasta wygenerował wyjątek podczas przetwarzania funkcji win32k!EngFntCacheLookUp (zwraca wskaźnik do pliku z fontami) w pliku win32k.sys do którego musi mieć dostęp.
Mam mocne podejrzenie iż jest on zainfekowany jakimś rootkitem którego avast nie wykrywa.
Proszę załatwić sobie pakiet bootwalny hirens'a ->
http://www.hirensbootcd.org i wykonać pełne skanowanie Eset Online Scanerem oraz dorwać Malwarebytes'a oraz Adwcleaner. Do tego można użyć TDSSKiller i Gmer'a. Dla Illidana w dziale bezpieczeństwo proszę wykonać logi OTL.
Zalecałbym także korzystanie od czasu do czasu z MBAM'a podczas pracy w systemie.
Kod:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C: \Users\user\Desktop\bsody\100\072114-22776-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: symsrv*symsrv.dll*c: \symb*http: //msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18113.amd64fre.win7sp1_gdr.130318-1533
Machine Name:
Kernel base = 0xfffff800`02e16000 PsLoadedModuleList = 0xfffff800`03059670
Debug session time: Mon Jul 21 23: 23: 58.169 2014 (UTC + 2: 00)
System Uptime: 0 days 9: 49: 52.981
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff96000103b47, fffff8800b1e7d70, 0}
Probably caused by : win32k.sys ( win32k!EngFntCacheLookUp+164c3 )
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff96000103b47, Address of the instruction which caused the bugcheck
Arg3: fffff8800b1e7d70, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instrukcja spod 0x%08lx odwo
FAULTING_IP:
win32k!EngFntCacheLookUp+164c3
fffff960`00103b47 017314 add dword ptr [rbx+14h],esi
CONTEXT: fffff8800b1e7d70 -- (.cxr 0xfffff8800b1e7d70)
rax=00000000fffffe0a rbx=8bfffa80087e5d20 rcx=fffff900c2311ce0
rdx=fffff900c2f80970 rsi=0000000000000001 rdi=000000000000004a
rip=fffff96000103b47 rsp=fffff8800b1e8750 rbp=fffff900c0605bd0
r8=000000000000004a r9=0000000000010230 r10=fffff900c0605bd0
r11=fffff8800b1e8720 r12=0000000000000000 r13=fffff900c2f80970
r14=fffff8800b1e89c0 r15=0000000000000004
iopl=0 nv up ei ng nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010283
win32k!EngFntCacheLookUp+0x164c3:
fffff960`00103b47 017314 add dword ptr [rbx+14h],esi ds: 002b: 8bfffa80`087e5d34=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: avastui.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff96000103b47
STACK_TEXT:
fffff880`0b1e8750 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!EngFntCacheLookUp+0x164c3
FOLLOWUP_IP:
win32k!EngFntCacheLookUp+164c3
fffff960`00103b47 017314 add dword ptr [rbx+14h],esi
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!EngFntCacheLookUp+164c3
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 51302206
STACK_COMMAND: .cxr 0xfffff8800b1e7d70 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!EngFntCacheLookUp+164c3
BUCKET_ID: X64_0x3B_win32k!EngFntCacheLookUp+164c3
Followup: MachineOwner
---------
rax=fffff8800b1e75b0 rbx=fffff80002fdb6c4 rcx=000000000000003b
rdx=00000000c0000005 rsi=fffff80002e16000 rdi=0000000000000000
rip=fffff80002e8bc00 rsp=fffff8800b1e74a8 rbp=0000000000000000
r8=fffff96000103b47 r9=fffff8800b1e7d70 r10=0000000000000000
r11=fffff8800b1e76a8 r12=fffff80002e8ae93 r13=fffff80003099b10
r14=fffff80002e8aa80 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000282
nt!KeBugCheckEx:
fffff800`02e8bc00 48894c2408 mov qword ptr [rsp+8],rcx ss: 0018: fffff880`0b1e74b0=000000000000003b
Child-SP RetAddr : Args to Child : Call Site
fffff880`0b1e74a8 fffff800`02e8b1a9 : 00000000`0000003b 00000000`c0000005 fffff960`00103b47 fffff880`0b1e7d70 : nt!KeBugCheckEx
fffff880`0b1e74b0 fffff800`02e8aafc : fffff880`0b1e8518 fffff880`0b1e7d70 00000000`00000000 fffff960`00323e40 : nt!KiBugCheckDispatch+0x69
fffff880`0b1e75f0 fffff800`02eb675d : fffff960`0036b594 fffff960`00338ec0 fffff960`00080000 fffff880`0b1e8518 : nt!KiSystemServiceHandler+0x7c
fffff880`0b1e7630 fffff800`02eb5535 : fffff800`02fdb6c4 fffff880`0b1e76a8 fffff880`0b1e8518 fffff800`02e16000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`0b1e7660 fffff800`02ec64d1 : fffff880`0b1e8518 fffff880`0b1e7d70 fffff880`00000000 00000000`0000004a : nt!RtlDispatchException+0x415
fffff880`0b1e7d40 fffff800`02e8b282 : fffff880`0b1e8518 8bfffa80`087e5d20 fffff880`0b1e85c0 00000000`00000001 : nt!KiDispatchException+0x135
fffff880`0b1e83e0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
start end module name
fffff800`00ba1000 fffff800`00bab000 kdcom kdcom.dll Sat Feb 05 17: 52: 49 2011 (4D4D8061)
fffff800`02e16000 fffff800`033fc000 nt ntkrnlmp.exe Tue Mar 19 04: 21: 42 2013 (5147D9C6)
fffff800`033fc000 fffff800`03445000 hal hal.dll Sat Nov 20 14: 00: 25 2010 (4CE7C669)
fffff880`00c00000 fffff880`00c5c000 volmgrx volmgrx.sys Sat Nov 20 10: 20: 43 2010 (4CE792EB)
fffff880`00c5c000 fffff880`00c63000 pciide pciide.sys Tue Jul 14 01: 19: 49 2009 (4A5BC115)
fffff880`00c63000 fffff880`00c73000 PCIIDEX PCIIDEX.SYS Tue Jul 14 01: 19: 48 2009 (4A5BC114)
fffff880`00c73000 fffff880`00c8d000 mountmgr mountmgr.sys Sat Nov 20 10: 19: 21 2010 (4CE79299)
fffff880`00c8e000 fffff880`00cdd000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 14: 03: 51 2010 (4CE7C737)
fffff880`00cdd000 fffff880`00cf1000 PSHED PSHED.dll Tue Jul 14 03: 32: 23 2009 (4A5BE027)
fffff880`00cf1000 fffff880`00d4f000 CLFS CLFS.SYS Tue Jul 14 01: 19: 57 2009 (4A5BC11D)
fffff880`00d4f000 fffff880`00da6000 ACPI ACPI.sys Sat Nov 20 10: 19: 16 2010 (4CE79294)
fffff880`00da6000 fffff880`00dbb000 volmgr volmgr.sys Sat Nov 20 10: 19: 28 2010 (4CE792A0)
fffff880`00dbb000 fffff880`00df7000 vmbus vmbus.sys Sat Nov 20 10: 57: 29 2010 (4CE79B89)
fffff880`00e00000 fffff880`00ec2000 Wdf01000 Wdf01000.sys Thu Jul 26 04: 25: 13 2012 (5010AA89)
fffff880`00ec2000 fffff880`00ed2000 WDFLDR WDFLDR.SYS Thu Jul 26 04: 29: 04 2012 (5010AB70)
fffff880`00ed2000 fffff880`00edb000 WMILIB WMILIB.SYS Tue Jul 14 01: 19: 51 2009 (4A5BC117)
fffff880`00edb000 fffff880`00ee5000 msisadrv msisadrv.sys Tue Jul 14 01: 19: 26 2009 (4A5BC0FE)
fffff880`00ee5000 fffff880`00efa000 partmgr partmgr.sys Sat Mar 17 06: 06: 09 2012 (4F641BC1)
fffff880`00efe000 fffff880`00fbe000 CI CI.dll Sat Nov 20 14: 12: 36 2010 (4CE7C944)
fffff880`00fbe000 fffff880`00ff1000 pci pci.sys Sat Nov 20 10: 19: 11 2010 (4CE7928F)
fffff880`00ff1000 fffff880`00ffe000 vdrvroot vdrvroot.sys Tue Jul 14 02: 01: 31 2009 (4A5BCADB)
fffff880`01040000 fffff880`01054000 winhv winhv.sys Sat Nov 20 10: 20: 02 2010 (4CE792C2)
fffff880`01054000 fffff880`0105d000 atapi atapi.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`0105d000 fffff880`01087000 ataport ataport.SYS Sat Nov 20 10: 19: 15 2010 (4CE79293)
fffff880`01087000 fffff880`01092000 amdxata amdxata.sys Fri Mar 19 17: 18: 18 2010 (4BA3A3CA)
fffff880`01092000 fffff880`010de000 fltmgr fltmgr.sys Sat Nov 20 10: 19: 24 2010 (4CE7929C)
fffff880`010de000 fffff880`010f2000 fileinfo fileinfo.sys Tue Jul 14 01: 34: 25 2009 (4A5BC481)
fffff880`010f2000 fffff880`01150000 msrpc msrpc.sys Sat Nov 20 10: 21: 56 2010 (4CE79334)
fffff880`01150000 fffff880`011c2000 cng cng.sys Sat Jun 02 05: 25: 51 2012 (4FC987BF)
fffff880`011c2000 fffff880`011f1000 ndiswan ndiswan.sys Sat Nov 20 11: 52: 32 2010 (4CE7A870)
fffff880`01200000 fffff880`01211000 pcw pcw.sys Tue Jul 14 01: 19: 27 2009 (4A5BC0FF)
fffff880`01211000 fffff880`0121b000 Fs_Rec Fs_Rec.sys Thu Mar 01 04: 41: 06 2012 (4F4EEFD2)
fffff880`01234000 fffff880`013dd000 Ntfs Ntfs.sys Fri Jan 24 02: 14: 50 2014 (52E1BE8A)
fffff880`013dd000 fffff880`013f8000 ksecdd ksecdd.sys Sat Jun 02 04: 50: 23 2012 (4FC97F6F)
fffff880`01400000 fffff880`01460000 NETIO NETIO.SYS Wed Aug 22 17: 11: 28 2012 (5034F6A0)
fffff880`01460000 fffff880`0148a000 ksecpkg ksecpkg.sys Sat Jun 02 05: 27: 11 2012 (4FC9880F)
fffff880`0148a000 fffff880`014d3000 fwpkclnt fwpkclnt.sys Thu Jan 03 04: 06: 48 2013 (50E4F5C8)
fffff880`014e0000 fffff880`015d3000 ndis ndis.sys Sat Nov 20 10: 23: 30 2010 (4CE79392)
fffff880`015d3000 fffff880`015e3000 vmstorfl vmstorfl.sys Sat Nov 20 10: 57: 30 2010 (4CE79B8A)
fffff880`015e3000 fffff880`015fd000 rassstp rassstp.sys Tue Jul 14 02: 10: 25 2009 (4A5BCCF1)
fffff880`01600000 fffff880`01800000 tcpip tcpip.sys Thu Jan 03 04: 11: 48 2013 (50E4F6F4)
fffff880`01800000 fffff880`01814000 termdd termdd.sys Sat Nov 20 12: 03: 40 2010 (4CE7AB0C)
fffff880`01814000 fffff880`01835000 raspptp raspptp.sys Sat Nov 20 11: 52: 31 2010 (4CE7A86F)
fffff880`01838000 fffff880`01884000 volsnap volsnap.sys Sat Nov 20 10: 20: 08 2010 (4CE792C8)
fffff880`01884000 fffff880`0188c000 spldr spldr.sys Mon May 11 18: 56: 27 2009 (4A0858BB)
fffff880`0188c000 fffff880`018c6000 rdyboost rdyboost.sys Sat Nov 20 10: 43: 10 2010 (4CE7982E)
fffff880`018c6000 fffff880`018d8000 mup mup.sys Tue Jul 14 01: 23: 45 2009 (4A5BC201)
fffff880`018d8000 fffff880`018e1000 hwpolicy hwpolicy.sys Sat Nov 20 10: 18: 54 2010 (4CE7927E)
fffff880`018e1000 fffff880`0191b000 fvevol fvevol.sys Thu Jan 24 04: 11: 24 2013 (5100A65C)
fffff880`0191b000 fffff880`01931000 disk disk.sys Tue Jul 14 01: 19: 57 2009 (4A5BC11D)
fffff880`01931000 fffff880`01961000 CLASSPNP CLASSPNP.SYS Sat Nov 20 10: 19: 23 2010 (4CE7929B)
fffff880`01961000 fffff880`01996000 aswVmm aswVmm.sys Thu Apr 17 13: 04: 55 2014 (534FB557)
fffff880`01996000 fffff880`019a9000 aswRvrt aswRvrt.sys Thu Apr 17 13: 04: 41 2014 (534FB549)
fffff880`019df000 fffff880`019fa000 wanarp wanarp.sys Sat Nov 20 11: 52: 36 2010 (4CE7A874)
fffff880`02c00000 fffff880`02c07000 Beep Beep.SYS Tue Jul 14 02: 00: 13 2009 (4A5BCA8D)
fffff880`02c07000 fffff880`02c15000 vga vga.sys Tue Jul 14 01: 38: 47 2009 (4A5BC587)
fffff880`02c15000 fffff880`02c3a000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 01: 38: 51 2009 (4A5BC58B)
fffff880`02c3a000 fffff880`02c4a000 watchdog watchdog.sys Tue Jul 14 01: 37: 35 2009 (4A5BC53F)
fffff880`02c4a000 fffff880`02c53000 RDPCDD RDPCDD.sys Tue Jul 14 02: 16: 34 2009 (4A5BCE62)
fffff880`02c53000 fffff880`02c5c000 rdpencdd rdpencdd.sys Tue Jul 14 02: 16: 34 2009 (4A5BCE62)
fffff880`02c5c000 fffff880`02c65000 rdprefmp rdprefmp.sys Tue Jul 14 02: 16: 35 2009 (4A5BCE63)
fffff880`02c65000 fffff880`02c70000 Msfs Msfs.SYS Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`02c70000 fffff880`02c81000 Npfs Npfs.SYS Tue Jul 14 01: 19: 48 2009 (4A5BC114)
fffff880`02c83000 fffff880`02d84000 aswSnx aswSnx.sys Mon May 05 10: 04: 42 2014 (5367461A)
fffff880`02d84000 fffff880`02df1000 aswSP aswSP.sys Mon May 05 10: 11: 11 2014 (5367479F)
fffff880`02df1000 fffff880`02dfa000 Null Null.SYS Tue Jul 14 01: 19: 37 2009 (4A5BC109)
fffff880`04000000 fffff880`04089000 afd afd.sys Wed Dec 28 04: 59: 20 2011 (4EFA9418)
fffff880`04089000 fffff880`040a3000 aswRdr2 aswRdr2.sys Thu Apr 17 13: 02: 56 2014 (534FB4E0)
fffff880`040a3000 fffff880`040e8000 netbt netbt.sys Sat Nov 20 10: 23: 18 2010 (4CE79386)
fffff880`040e8000 fffff880`040f1000 wfplwf wfplwf.sys Tue Jul 14 02: 09: 26 2009 (4A5BCCB6)
fffff880`040fc000 fffff880`04144000 dtsoftbus01 dtsoftbus01.sys Fri Feb 21 10: 49: 36 2014 (53072130)
fffff880`04144000 fffff880`0416e000 cdrom cdrom.sys Sat Nov 20 10: 19: 20 2010 (4CE79298)
fffff880`0416e000 fffff880`04190000 tdx tdx.sys Sat Nov 20 10: 21: 54 2010 (4CE79332)
fffff880`04190000 fffff880`0419d000 TDI TDI.SYS Sat Nov 20 10: 22: 06 2010 (4CE7933E)
fffff880`0419d000 fffff880`041c3000 pacer pacer.sys Sat Nov 20 11: 52: 18 2010 (4CE7A862)
fffff880`041c3000 fffff880`041d2000 netbios netbios.sys Tue Jul 14 02: 09: 26 2009 (4A5BCCB6)
fffff880`041d2000 fffff880`041ef000 serial serial.sys Tue Jul 14 02: 00: 40 2009 (4A5BCAA8)
fffff880`041ef000 fffff880`041fe000 mouclass mouclass.sys Tue Jul 14 01: 19: 50 2009 (4A5BC116)
fffff880`05400000 fffff880`05424000 mrxsmb20 mrxsmb20.sys Wed Apr 27 04: 39: 37 2011 (4DB781E9)
fffff880`05424000 fffff880`0542e000 aswHwid aswHwid.sys Tue Apr 08 17: 43: 26 2014 (5344191E)
fffff880`0542e000 fffff880`05439000 secdrv secdrv.SYS Wed Sep 13 15: 18: 38 2006 (4508052E)
fffff880`05439000 fffff880`0546a000 srvnet srvnet.sys Fri Apr 29 05: 05: 35 2011 (4DBA2AFF)
fffff880`0546a000 fffff880`0547c000 tcpipreg tcpipreg.sys Sat Nov 20 11: 51: 48 2010 (4CE7A844)
fffff880`05484000 fffff880`0554d000 HTTP HTTP.sys Sat Nov 20 10: 24: 30 2010 (4CE793CE)
fffff880`0554d000 fffff880`0556b000 bowser bowser.sys Wed Feb 23 05: 55: 04 2011 (4D649328)
fffff880`0556b000 fffff880`05583000 mpsdrv mpsdrv.sys Tue Jul 14 02: 08: 25 2009 (4A5BCC79)
fffff880`05583000 fffff880`055b0000 mrxsmb mrxsmb.sys Wed Apr 27 04: 40: 38 2011 (4DB78226)
fffff880`055b0000 fffff880`055fe000 mrxsmb10 mrxsmb10.sys Sat Jul 09 04: 46: 28 2011 (4E17C104)
fffff880`06c00000 fffff880`06c56000 Rt64win7 Rt64win7.sys Wed Jun 23 11: 10: 45 2010 (4C21CF95)
fffff880`06c56000 fffff880`06c7a000 rasl2tp rasl2tp.sys Sat Nov 20 11: 52: 34 2010 (4CE7A872)
fffff880`06c7a000 fffff880`06c89000 kbdclass kbdclass.sys Tue Jul 14 01: 19: 50 2009 (4A5BC116)
fffff880`06c91000 fffff880`06ce2000 rdbss rdbss.sys Sat Nov 20 10: 27: 51 2010 (4CE79497)
fffff880`06ce2000 fffff880`06cee000 nsiproxy nsiproxy.sys Tue Jul 14 01: 21: 02 2009 (4A5BC15E)
fffff880`06cee000 fffff880`06cf9000 mssmbios mssmbios.sys Tue Jul 14 01: 31: 10 2009 (4A5BC3BE)
fffff880`06cf9000 fffff880`06d08000 discache discache.sys Tue Jul 14 01: 37: 18 2009 (4A5BC52E)
fffff880`06d08000 fffff880`06d8b000 csc csc.sys Sat Nov 20 10: 27: 12 2010 (4CE79470)
fffff880`06d8b000 fffff880`06da9000 dfsc dfsc.sys Sat Nov 20 10: 26: 31 2010 (4CE79447)
fffff880`06da9000 fffff880`06dba000 blbdrive blbdrive.sys Tue Jul 14 01: 35: 59 2009 (4A5BC4DF)
fffff880`06dba000 fffff880`06de0000 tunnel tunnel.sys Sat Nov 20 11: 51: 50 2010 (4CE7A846)
fffff880`06de0000 fffff880`06dfb000 raspppoe raspppoe.sys Tue Jul 14 02: 10: 17 2009 (4A5BCCE9)
fffff880`07200000 fffff880`07216000 AgileVpn AgileVpn.sys Tue Jul 14 02: 10: 24 2009 (4A5BCCF0)
fffff880`07216000 fffff880`07222000 ndistapi ndistapi.sys Tue Jul 14 02: 10: 00 2009 (4A5BCCD8)
fffff880`07222000 fffff880`0722f000 tap0901t tap0901t.sys Wed Sep 16 08: 02: 43 2009 (4AB07F83)
fffff880`07237000 fffff880`072da000 atikmpag atikmpag.sys Fri Apr 18 03: 07: 07 2014 (53507ABB)
fffff880`072da000 fffff880`073ce000 dxgkrnl dxgkrnl.sys Thu Aug 01 09: 58: 53 2013 (51FA153D)
fffff880`073ce000 fffff880`073e4000 intelppm intelppm.sys Tue Jul 14 01: 19: 25 2009 (4A5BC0FD)
fffff880`073e4000 fffff880`073f4000 CompositeBus CompositeBus.sys Sat Nov 20 11: 33: 17 2010 (4CE7A3ED)
fffff880`073f4000 fffff880`073ff000 rdpbus rdpbus.sys Tue Jul 14 02: 17: 46 2009 (4A5BCEAA)
fffff880`07400000 fffff880`07422000 drmk drmk.sys Tue Jul 14 03: 01: 25 2009 (4A5BD8E5)
fffff880`07422000 fffff880`07427200 ksthunk ksthunk.sys Tue Jul 14 02: 00: 19 2009 (4A5BCA93)
fffff880`07428000 fffff880`074ce000 peauth peauth.sys Tue Jul 14 03: 01: 19 2009 (4A5BD8DF)
fffff880`074d0000 fffff880`07513000 ks ks.sys Sat Nov 20 11: 33: 23 2010 (4CE7A3F3)
fffff880`07513000 fffff880`07525000 umbus umbus.sys Sat Nov 20 11: 44: 37 2010 (4CE7A695)
fffff880`07525000 fffff880`0757f000 usbhub usbhub.sys Fri Mar 25 04: 29: 25 2011 (4D8C0C15)
fffff880`0757f000 fffff880`07594000 NDProxy NDProxy.SYS Sat Nov 20 11: 52: 20 2010 (4CE7A864)
fffff880`07594000 fffff880`075af000 AtihdW76 AtihdW76.sys Fri Dec 20 04: 15: 49 2013 (52B3B665)
fffff880`075af000 fffff880`075ec000 portcls portcls.sys Tue Jul 14 02: 06: 27 2009 (4A5BCC03)
fffff880`0821d000 fffff880`08470700 RTKVHD64 RTKVHD64.sys Wed Jul 28 12: 01: 36 2010 (4C500000)
fffff880`08471000 fffff880`0848e000 cdfs cdfs.sys Tue Jul 14 01: 19: 46 2009 (4A5BC112)
fffff880`0848e000 fffff880`0849c000 crashdmp crashdmp.sys Tue Jul 14 02: 01: 01 2009 (4A5BCABD)
fffff880`0849c000 fffff880`084a8000 dump_dumpata dump_dumpata.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`084a8000 fffff880`084b1000 dump_atapi dump_atapi.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`084b1000 fffff880`084c4000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 01: 21: 51 2009 (4A5BC18F)
fffff880`084c4000 fffff880`084d0000 Dxapi Dxapi.sys Tue Jul 14 01: 38: 28 2009 (4A5BC574)
fffff880`084d0000 fffff880`084de000 hidusb hidusb.sys Sat Nov 20 11: 43: 49 2010 (4CE7A665)
fffff880`084de000 fffff880`084f7000 HIDCLASS HIDCLASS.SYS Sat Nov 20 11: 43: 49 2010 (4CE7A665)
fffff880`084f7000 fffff880`084ff080 HIDPARSE HIDPARSE.SYS Tue Jul 14 02: 06: 17 2009 (4A5BCBF9)
fffff880`08500000 fffff880`08501f00 USBD USBD.SYS Fri Mar 25 04: 28: 59 2011 (4D8C0BFB)
fffff880`08502000 fffff880`0850f000 mouhid mouhid.sys Tue Jul 14 02: 00: 20 2009 (4A5BCA94)
fffff880`0850f000 fffff880`0852c000 usbccgp usbccgp.sys Fri Mar 25 04: 29: 14 2011 (4D8C0C0A)
fffff880`0852c000 fffff880`0853a000 kbdhid kbdhid.sys Sat Nov 20 11: 33: 25 2010 (4CE7A3F5)
fffff880`0853a000 fffff880`08548000 monitor monitor.sys Tue Jul 14 01: 38: 52 2009 (4A5BC58C)
fffff880`08548000 fffff880`0856b000 luafv luafv.sys Tue Jul 14 01: 26: 13 2009 (4A5BC295)
fffff880`0856b000 fffff880`0858d000 aswMonFlt aswMonFlt.sys Thu Apr 17 13: 04: 01 2014 (534FB521)
fffff880`0858d000 fffff880`085a6000 WudfPf WudfPf.sys Thu Jul 26 04: 26: 45 2012 (5010AAE5)
fffff880`085a6000 fffff880`085be000 aswStm aswStm.sys Mon May 05 10: 11: 48 2014 (536747C4)
fffff880`085be000 fffff880`085d3000 lltdio lltdio.sys Tue Jul 14 02: 08: 50 2009 (4A5BCC92)
fffff880`085d3000 fffff880`085eb000 rspndr rspndr.sys Tue Jul 14 02: 08: 50 2009 (4A5BCC92)
fffff880`0864d000 fffff880`086b6000 srv2 srv2.sys Fri Apr 29 05: 05: 46 2011 (4DBA2B0A)
fffff880`086b6000 fffff880`0874e000 srv srv.sys Fri Apr 29 05: 06: 06 2011 (4DBA2B1E)
fffff880`0f000000 fffff880`0f011000 usbehci usbehci.sys Fri Mar 25 04: 29: 04 2011 (4D8C0C00)
fffff880`0f011000 fffff880`0f067000 USBPORT USBPORT.SYS Fri Mar 25 04: 29: 12 2011 (4D8C0C08)
fffff880`0f067000 fffff880`0f073000 serenum serenum.sys Tue Jul 14 02: 00: 33 2009 (4A5BCAA1)
fffff880`0f073000 fffff880`0f074480 swenum swenum.sys Tue Jul 14 02: 00: 18 2009 (4A5BCA92)
fffff880`0f07b000 fffff880`0ff8b000 atikmdag atikmdag.sys Fri Apr 18 04: 13: 16 2014 (53508A3C)
fffff880`0ff8b000 fffff880`0ffd1000 dxgmms1 dxgmms1.sys Wed Apr 10 05: 27: 15 2013 (5164DC13)
fffff880`0ffd1000 fffff880`0fff5000 HDAudBus HDAudBus.sys Sat Nov 20 11: 43: 42 2010 (4CE7A65E)
fffff880`0fff5000 fffff880`10000000 hamachi hamachi.sys Thu Feb 19 11: 36: 41 2009 (499D3639)
fffff960`00080000 fffff960`00396000 win32k win32k.sys Fri Mar 01 04: 35: 34 2013 (51302206)
fffff960`005a0000 fffff960`005aa000 TSDDD TSDDD.dll unavailable (00000000)
fffff960`00670000 fffff960`00697000 cdd cdd.dll Thu Feb 03 12: 25: 25 2011 (4D4A90A5)
fffff960`008e0000 fffff960`00941000 ATMFD ATMFD.DLL Sun Dec 16 15: 45: 03 2012 (50CDDE6F)
Unloaded modules:
fffff880`019a9000 fffff880`019b7000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`019b7000 fffff880`019c3000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`019c3000 fffff880`019cc000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`019cc000 fffff880`019df000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000
Bugcheck code 0000003B
Arguments 00000000`c0000005 fffff960`00103b47 fffff880`0b1e7d70 00000000`00000000
[CPU Information]
~MHz = REG_DWORD 3292
Component Information = REG_BINARY 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
Configuration Data = REG_FULL_RESOURCE_DESCRIPTOR ff,ff,ff,ff,ff,ff,ff,ff,0,0,0,0,0,0,0,0
Identifier = REG_SZ Intel64 Family 6 Model 42 Stepping 7
ProcessorNameString = REG_SZ Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Update Signature = REG_BINARY 0,0,0,0,25,0,0,0
Update Status = REG_DWORD 2
VendorIdentifier = REG_SZ GenuineIntel
MSR8B = REG_QWORD 2500000000
Machine ID Information [From Smbios 2.7, DMIVersion 39, Size=1541]
BiosMajorRelease = 4
BiosMinorRelease = 6
BiosVendor = American Megatrends Inc.
BiosVersion = P3.20
BiosReleaseDate = 05/11/2012
SystemManufacturer = To Be Filled By O.E.M.
SystemProductName = To Be Filled By O.E.M.
SystemFamily = To Be Filled By O.E.M.
SystemVersion = To Be Filled By O.E.M.
SystemSKU = To Be Filled By O.E.M.
BaseBoardManufacturer = ASRock
BaseBoardProduct = P67 Pro3
BaseBoardVersion =
CPUID: "Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz"
MaxSpeed: 3300
CurrentSpeed: 3292
[SMBIOS Data Tables v2.7]
[DMI Version - 39]
[2.0 Calling Convention - No]
[Table Size - 1541 bytes]
[BIOS Information (Type 0) - Length 24 - Handle 0000h]
Vendor American Megatrends Inc.
BIOS Version P3.20
BIOS Starting Address Segment f000
BIOS Release Date 05/11/2012
BIOS ROM Size 800000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
27: - Keyboard Services Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Specification Reserved
11: - Specification Reserved
BIOS Major Revision 4
BIOS Minor Revision 6
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer To Be Filled By O.E.M.
Product Name To Be Filled By O.E.M.
Version To Be Filled By O.E.M.
Serial Number
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber To Be Filled By O.E.M.
Family To Be Filled By O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer ASRock
Product P67 Pro3
Version
Serial Number
Asset Tag
Feature Flags 09h
265960820: - Þ
265960780: - Þ
Location
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
Manufacturer To Be Filled By O.E.M.
Chassis Type Desktop
Version To Be Filled By O.E.M.
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 0
Contained Element Size 0
[OEM Strings (Type 11) - Length 5 - Handle 000bh]
Number of Strings 1
1 To Be Filled By O.E.M.
[Cache Information (Type 7) - Length 19 - Handle 000dh]
Socket Designation CPU Internal L2
Cache Configuration 0081h - WT Enabled Int NonSocketed L2
Maximum Cache Size 0400h - 1024K
Installed Size 0400h - 1024K
Supported SRAM Type 0002h - Unknown
Current SRAM Type 0002h - Unknown
Cache Speed 0ns
Error Correction Type Specification Reserved
System Cache Type Instruction
Associativity 16-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 000eh]
Socket Designation CPU Internal L1
Cache Configuration 0080h - WT Enabled Int NonSocketed L1
Maximum Cache Size 0080h - 128K
Installed Size 0080h - 128K
Supported SRAM Type 0002h - Unknown
Current SRAM Type 0002h - Unknown
Cache Speed 0ns
Error Correction Type ParitySingle-Bit ECC
System Cache Type Other
Associativity 16-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 000fh]
Socket Designation CPU Internal L3
Cache Configuration 0182h - WB Enabled Int NonSocketed L3
Maximum Cache Size 1800h - 6144K
Installed Size 1800h - 6144K
Supported SRAM Type 0002h - Unknown
Current SRAM Type 0002h - Unknown
Cache Speed 0ns
Error Correction Type Specification Reserved
System Cache Type Instruction
Associativity Specification Reserved
[Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle [Not Provided]
Number of Memory Devices 4
[Processor Information (Type 4) - Length 42 - Handle 0011h]
Socket Designation CPUSocket
Processor Type Central Processor
Processor Family cdh - Specification Reserved
Processor Manufacturer Intel(R) Corporation
Processor ID a7060200fffbebbf
Processor Version Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 3800MHz
Current Speed 3300MHz
Status Enabled Populated
Processor Upgrade Specification Reserved
L1 Cache Handle 000eh
L2 Cache Handle 000dh
L3 Cache Handle 000fh
Serial Number [String Not Specified]
Asset Tag Number
Part Number Fill By OEM
[Memory Device (Type 17) - Length 34 - Handle 0012h]
Physical Memory Array Handle 0010h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM0
Bank Locator BANK 0
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number
Part Number [Empty]
[Memory Device (Type 17) - Length 34 - Handle 0013h]
Physical Memory Array Handle 0010h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 4096MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM1
Bank Locator BANK 1
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1333MHz
Manufacturer 859B
Serial Number
Asset Tag Number
Part Number BLS4G3D1339DS1S00.
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0014h]
Starting Address 00000000h
Ending Address 003fffffh
Memory Device Handle 0013h
Mem Array Mapped Adr Handle 0018h
Partition Row Position 01
Interleave Position 01
Interleave Data Depth 02
[Memory Device (Type 17) - Length 34 - Handle 0015h]
Physical Memory Array Handle 0010h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM0
Bank Locator BANK 2
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number
Part Number [Empty]
[Memory Device (Type 17) - Length 34 - Handle 0016h]
Physical Memory Array Handle 0010h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 4096MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM1
Bank Locator BANK 3
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1333MHz
Manufacturer 859B
Serial Number
Asset Tag Number
Part Number BLS4G3D1339DS1S00.
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0017h]
Starting Address 00400000h
Ending Address 007fffffh
Memory Device Handle 0016h
Mem Array Mapped Adr Handle 0018h
Partition Row Position 01
Interleave Position 02
Interleave Data Depth 02
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0018h]
Starting Address 00000000h
Ending Address 007fffffh
Memory Array Handle 0010h
Partition Width 04
0: kd> lmvm win32k
start end module name
fffff960`00080000 fffff960`00396000 win32k (export symbols) win32k.sys
Loaded symbol image file: win32k.sys
Mapped memory image file: c: \symb\win32k.sys\51302206316000\win32k.sys
Image path: \SystemRoot\System32\win32k.sys
Image name: win32k.sys
Timestamp: Fri Mar 01 04: 35: 34 2013 (51302206)
CheckSum: 0030525A
ImageSize: 00316000
File version: 6.1.7601.18105
Product version: 6.1.7601.18105
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: win32k.sys
OriginalFilename: win32k.sys
ProductVersion: 6.1.7601.18105
FileVersion: 6.1.7601.18105 (win7sp1_gdr.130228-1432)
FileDescription: Multi-User Win32 Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
0: kd> ln fffff96000103b47
(fffff960`000ed684) win32k!EngFntCacheLookUp+0x164c3 | (fffff960`00106a00) win32k!EngCopyBits
0: kd> k
Child-SP RetAddr Call Site
fffff880`0b1e74a8 fffff800`02e8b1a9 nt!KeBugCheckEx
fffff880`0b1e74b0 fffff800`02e8aafc nt!KiBugCheckDispatch+0x69
fffff880`0b1e75f0 fffff800`02eb675d nt!KiSystemServiceHandler+0x7c
fffff880`0b1e7630 fffff800`02eb5535 nt!RtlpExecuteHandlerForException+0xd
fffff880`0b1e7660 fffff800`02ec64d1 nt!RtlDispatchException+0x415
fffff880`0b1e7d40 fffff800`02e8b282 nt!KiDispatchException+0x135
fffff880`0b1e83e0 00000000`00000000 nt!KiExceptionDispatch+0xc2
A0000001
Jest to kod błędu występujący jedynie z układami firmy AMD.
Po wykonaniu zapytania o informacje o sterowniku lmvm atikmdag.sys z timestampa wynika iż jest to edycja z kwietnia 2014.
Prosze usunąć je przy pomocy oficjalnego narzędzia
AMD Catalyst Un-install Utility
Pobrać najnowszą paczkę ale instalować same drivery oprócz Catalyst Control Center.
Do tego zaproponować mogę jakiś test obciążeniowy grafiki np Furmark (opis u nas na forum w faq kiedyś robiłem).
Bsod może być związany z wyższa temperaturą układu GPU w szczycie, to pokaże program. Także przed zabawą zrobić konserwację i dobry podmuch na grafikę. Może ona się po prostu gotuje gdzieś w biurku.
Aktualizacje biosu także zalecam od płyty głównej do wersji P3.30
Cytat:1. Update CPU code.
2. Improve VGA compatibility.
3. Add Dehumidifier Function.
4. Improve memory compatibility.
Kod:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C: \Users\user\Desktop\bsody\100\072014-18376-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: symsrv*symsrv.dll*c: \symb*http: //msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18113.amd64fre.win7sp1_gdr.130318-1533
Machine Name:
Kernel base = 0xfffff800`02e18000 PsLoadedModuleList = 0xfffff800`0305b670
Debug session time: Sun Jul 20 03: 56: 54.039 2014 (UTC + 2: 00)
System Uptime: 0 days 13: 47: 20.866
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
Unable to load image \SystemRoot\system32\DRIVERS\atikmdag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A0000001, {5, 0, 0, 0}
Probably caused by : atikmdag.sys ( atikmdag+28ece )
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Unknown bugcheck code (a0000001)
Unknown bugcheck description
Arguments:
Arg1: 0000000000000005
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA0000001
PROCESS_NAME: System
CURRENT_IRQL: a
LAST_CONTROL_TRANSFER: from fffff8800f0e5ece to fffff80002e8dc00
STACK_TEXT:
fffff800`044af6b8 fffff880`0f0e5ece : 00000000`a0000001 00000000`00000005 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff800`044af6c0 00000000`a0000001 : 00000000`00000005 00000000`00000000 00000000`00000000 00000000`00000000 : atikmdag+0x28ece
fffff800`044af6c8 00000000`00000005 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`08c3d760 : 0xa0000001
fffff800`044af6d0 00000000`00000000 : 00000000`00000000 00000000`00000000 fffffa80`08c3d760 00000000`00000000 : 0x5
STACK_COMMAND: kb
FOLLOWUP_IP:
atikmdag+28ece
fffff880`0f0e5ece ? ?
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: atikmdag+28ece
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: atikmdag
IMAGE_NAME: atikmdag.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 53508a3c
FAILURE_BUCKET_ID: X64_0xA0000001_atikmdag+28ece
BUCKET_ID: X64_0xA0000001_atikmdag+28ece
Followup: MachineOwner
---------
rax=0000000000000001 rbx=fffffa8008970320 rcx=00000000a0000001
rdx=0000000000000005 rsi=fffffa8008b9c000 rdi=fffffa8008b9d390
rip=fffff80002e8dc00 rsp=fffff800044af6b8 rbp=fffffa8008baa320
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff800044af2e0 r12=0000000000000000 r13=0000000000000000
r14=fffffa8008b9c000 r15=fffffa8008b9d368
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000246
nt!KeBugCheckEx:
fffff800`02e8dc00 48894c2408 mov qword ptr [rsp+8],rcx ss: 0018: fffff800`044af6c0=00000000a0000001
Child-SP RetAddr : Args to Child : Call Site
fffff800`044af6b8 fffff880`0f0e5ece : 00000000`a0000001 00000000`00000005 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff800`044af6c0 00000000`a0000001 : 00000000`00000005 00000000`00000000 00000000`00000000 00000000`00000000 : atikmdag+0x28ece
fffff800`044af6c8 00000000`00000005 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`08c3d760 : 0xa0000001
fffff800`044af6d0 00000000`00000000 : 00000000`00000000 00000000`00000000 fffffa80`08c3d760 00000000`00000000 : 0x5
start end module name
fffff800`00ba7000 fffff800`00bb1000 kdcom kdcom.dll Sat Feb 05 17: 52: 49 2011 (4D4D8061)
fffff800`02e18000 fffff800`033fe000 nt ntkrnlmp.exe Tue Mar 19 04: 21: 42 2013 (5147D9C6)
fffff800`033fe000 fffff800`03447000 hal hal.dll Sat Nov 20 14: 00: 25 2010 (4CE7C669)
fffff880`00c00000 fffff880`00c5c000 volmgrx volmgrx.sys unavailable (00000000)
fffff880`00c5c000 fffff880`00c63000 pciide pciide.sys Tue Jul 14 01: 19: 49 2009 (4A5BC115)
fffff880`00c63000 fffff880`00c73000 PCIIDEX PCIIDEX.SYS Tue Jul 14 01: 19: 48 2009 (4A5BC114)
fffff880`00c83000 fffff880`00cd2000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 14: 03: 51 2010 (4CE7C737)
fffff880`00cd2000 fffff880`00ce6000 PSHED PSHED.dll Tue Jul 14 03: 32: 23 2009 (4A5BE027)
fffff880`00ce6000 fffff880`00d44000 CLFS CLFS.SYS Tue Jul 14 01: 19: 57 2009 (4A5BC11D)
fffff880`00d44000 fffff880`00d77000 pci pci.sys Sat Nov 20 10: 19: 11 2010 (4CE7928F)
fffff880`00d77000 fffff880`00d84000 vdrvroot vdrvroot.sys Tue Jul 14 02: 01: 31 2009 (4A5BCADB)
fffff880`00d84000 fffff880`00d99000 partmgr partmgr.sys Sat Mar 17 06: 06: 09 2012 (4F641BC1)
fffff880`00d99000 fffff880`00dae000 volmgr volmgr.sys Sat Nov 20 10: 19: 28 2010 (4CE792A0)
fffff880`00dae000 fffff880`00dc8000 mountmgr mountmgr.sys Sat Nov 20 10: 19: 21 2010 (4CE79299)
fffff880`00dc8000 fffff880`00dea000 tdx tdx.sys Sat Nov 20 10: 21: 54 2010 (4CE79332)
fffff880`00e00000 fffff880`00e09000 WMILIB WMILIB.SYS Tue Jul 14 01: 19: 51 2009 (4A5BC117)
fffff880`00e09000 fffff880`00e13000 msisadrv msisadrv.sys Tue Jul 14 01: 19: 26 2009 (4A5BC0FE)
fffff880`00e17000 fffff880`00ed7000 CI CI.dll Sat Nov 20 14: 12: 36 2010 (4CE7C944)
fffff880`00ed7000 fffff880`00f99000 Wdf01000 Wdf01000.sys Thu Jul 26 04: 25: 13 2012 (5010AA89)
fffff880`00f99000 fffff880`00fa9000 WDFLDR WDFLDR.SYS Thu Jul 26 04: 29: 04 2012 (5010AB70)
fffff880`00fa9000 fffff880`01000000 ACPI ACPI.sys Sat Nov 20 10: 19: 16 2010 (4CE79294)
fffff880`01000000 fffff880`0105e000 msrpc msrpc.sys unavailable (00000000)
fffff880`0105e000 fffff880`010d0000 cng cng.sys Sat Jun 02 05: 25: 51 2012 (4FC987BF)
fffff880`010d5000 fffff880`01111000 vmbus vmbus.sys Sat Nov 20 10: 57: 29 2010 (4CE79B89)
fffff880`01111000 fffff880`01125000 winhv winhv.sys Sat Nov 20 10: 20: 02 2010 (4CE792C2)
fffff880`01125000 fffff880`0112e000 atapi atapi.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`0112e000 fffff880`01158000 ataport ataport.SYS Sat Nov 20 10: 19: 15 2010 (4CE79293)
fffff880`01158000 fffff880`01163000 amdxata amdxata.sys Fri Mar 19 17: 18: 18 2010 (4BA3A3CA)
fffff880`01163000 fffff880`011af000 fltmgr fltmgr.sys Sat Nov 20 10: 19: 24 2010 (4CE7929C)
fffff880`011af000 fffff880`011c3000 fileinfo fileinfo.sys Tue Jul 14 01: 34: 25 2009 (4A5BC481)
fffff880`011c3000 fffff880`011ed000 cdrom cdrom.sys Sat Nov 20 10: 19: 20 2010 (4CE79298)
fffff880`0121d000 fffff880`013c6000 Ntfs Ntfs.sys Fri Jan 24 02: 14: 50 2014 (52E1BE8A)
fffff880`013c6000 fffff880`013e1000 ksecdd ksecdd.sys Sat Jun 02 04: 50: 23 2012 (4FC97F6F)
fffff880`013e1000 fffff880`013f2000 pcw pcw.sys Tue Jul 14 01: 19: 27 2009 (4A5BC0FF)
fffff880`013f2000 fffff880`013fc000 Fs_Rec Fs_Rec.sys unavailable (00000000)
fffff880`01417000 fffff880`0150a000 ndis ndis.sys Sat Nov 20 10: 23: 30 2010 (4CE79392)
fffff880`0150a000 fffff880`0156a000 NETIO NETIO.SYS Wed Aug 22 17: 11: 28 2012 (5034F6A0)
fffff880`0156a000 fffff880`01594000 ksecpkg ksecpkg.sys Sat Jun 02 05: 27: 11 2012 (4FC9880F)
fffff880`01594000 fffff880`015dd000 fwpkclnt fwpkclnt.sys Thu Jan 03 04: 06: 48 2013 (50E4F5C8)
fffff880`015dd000 fffff880`015ed000 vmstorfl vmstorfl.sys unavailable (00000000)
fffff880`015ed000 fffff880`015fa000 TDI TDI.SYS Sat Nov 20 10: 22: 06 2010 (4CE7933E)
fffff880`01600000 fffff880`01800000 tcpip tcpip.sys Thu Jan 03 04: 11: 48 2013 (50E4F6F4)
fffff880`01813000 fffff880`0185b000 dtsoftbus01 dtsoftbus01.sys Fri Feb 21 10: 49: 36 2014 (53072130)
fffff880`01864000 fffff880`018b0000 volsnap volsnap.sys Sat Nov 20 10: 20: 08 2010 (4CE792C8)
fffff880`018b0000 fffff880`018b8000 spldr spldr.sys Mon May 11 18: 56: 27 2009 (4A0858BB)
fffff880`018b8000 fffff880`018f2000 rdyboost rdyboost.sys Sat Nov 20 10: 43: 10 2010 (4CE7982E)
fffff880`018f2000 fffff880`01904000 mup mup.sys Tue Jul 14 01: 23: 45 2009 (4A5BC201)
fffff880`01904000 fffff880`0190d000 hwpolicy hwpolicy.sys Sat Nov 20 10: 18: 54 2010 (4CE7927E)
fffff880`0190d000 fffff880`01947000 fvevol fvevol.sys Thu Jan 24 04: 11: 24 2013 (5100A65C)
fffff880`01947000 fffff880`0195d000 disk disk.sys Tue Jul 14 01: 19: 57 2009 (4A5BC11D)
fffff880`0195d000 fffff880`0198d000 CLASSPNP CLASSPNP.SYS Sat Nov 20 10: 19: 23 2010 (4CE7929B)
fffff880`0198d000 fffff880`019c2000 aswVmm aswVmm.sys Thu Apr 17 13: 04: 55 2014 (534FB557)
fffff880`019c2000 fffff880`019d5000 aswRvrt aswRvrt.sys unavailable (00000000)
fffff880`03e00000 fffff880`03e51000 rdbss rdbss.sys Sat Nov 20 10: 27: 51 2010 (4CE79497)
fffff880`03e51000 fffff880`03e5d000 nsiproxy nsiproxy.sys Tue Jul 14 01: 21: 02 2009 (4A5BC15E)
fffff880`03e5d000 fffff880`03e68000 mssmbios mssmbios.sys Tue Jul 14 01: 31: 10 2009 (4A5BC3BE)
fffff880`03e68000 fffff880`03e77000 discache discache.sys Tue Jul 14 01: 37: 18 2009 (4A5BC52E)
fffff880`03e80000 fffff880`03f09000 afd afd.sys Wed Dec 28 04: 59: 20 2011 (4EFA9418)
fffff880`03f09000 fffff880`03f23000 aswRdr2 aswRdr2.sys Thu Apr 17 13: 02: 56 2014 (534FB4E0)
fffff880`03f23000 fffff880`03f68000 netbt netbt.sys Sat Nov 20 10: 23: 18 2010 (4CE79386)
fffff880`03f68000 fffff880`03f71000 wfplwf wfplwf.sys Tue Jul 14 02: 09: 26 2009 (4A5BCCB6)
fffff880`03f71000 fffff880`03f97000 pacer pacer.sys Sat Nov 20 11: 52: 18 2010 (4CE7A862)
fffff880`03f97000 fffff880`03fa6000 netbios netbios.sys Tue Jul 14 02: 09: 26 2009 (4A5BCCB6)
fffff880`03fa6000 fffff880`03fc3000 serial serial.sys Tue Jul 14 02: 00: 40 2009 (4A5BCAA8)
fffff880`03fc3000 fffff880`03fde000 wanarp wanarp.sys Sat Nov 20 11: 52: 36 2010 (4CE7A874)
fffff880`03fde000 fffff880`03ff2000 termdd termdd.sys Sat Nov 20 12: 03: 40 2010 (4CE7AB0C)
fffff880`04600000 fffff880`04631000 srvnet srvnet.sys Fri Apr 29 05: 05: 35 2011 (4DBA2AFF)
fffff880`0463f000 fffff880`04708000 HTTP HTTP.sys Sat Nov 20 10: 24: 30 2010 (4CE793CE)
fffff880`04708000 fffff880`04726000 bowser bowser.sys Wed Feb 23 05: 55: 04 2011 (4D649328)
fffff880`04726000 fffff880`0473e000 mpsdrv mpsdrv.sys Tue Jul 14 02: 08: 25 2009 (4A5BCC79)
fffff880`0473e000 fffff880`0476b000 mrxsmb mrxsmb.sys Wed Apr 27 04: 40: 38 2011 (4DB78226)
fffff880`0476b000 fffff880`047b9000 mrxsmb10 mrxsmb10.sys Sat Jul 09 04: 46: 28 2011 (4E17C104)
fffff880`047b9000 fffff880`047dd000 mrxsmb20 mrxsmb20.sys Wed Apr 27 04: 39: 37 2011 (4DB781E9)
fffff880`047dd000 fffff880`047e7000 aswHwid aswHwid.sys Tue Apr 08 17: 43: 26 2014 (5344191E)
fffff880`047e7000 fffff880`047f2000 secdrv secdrv.SYS Wed Sep 13 15: 18: 38 2006 (4508052E)
fffff880`06a00000 fffff880`06a6d000 aswSP aswSP.sys Mon May 05 10: 11: 11 2014 (5367479F)
fffff880`06a6d000 fffff880`06a76000 Null Null.SYS unavailable (00000000)
fffff880`06a76000 fffff880`06a7d000 Beep Beep.SYS Tue Jul 14 02: 00: 13 2009 (4A5BCA8D)
fffff880`06a7d000 fffff880`06a8b000 vga vga.sys Tue Jul 14 01: 38: 47 2009 (4A5BC587)
fffff880`06a8b000 fffff880`06ab0000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 01: 38: 51 2009 (4A5BC58B)
fffff880`06ab0000 fffff880`06ac0000 watchdog watchdog.sys Tue Jul 14 01: 37: 35 2009 (4A5BC53F)
fffff880`06ac2000 fffff880`06bc3000 aswSnx aswSnx.sys Mon May 05 10: 04: 42 2014 (5367461A)
fffff880`06bc3000 fffff880`06bcc000 RDPCDD RDPCDD.sys Tue Jul 14 02: 16: 34 2009 (4A5BCE62)
fffff880`06bcc000 fffff880`06bd5000 rdpencdd rdpencdd.sys Tue Jul 14 02: 16: 34 2009 (4A5BCE62)
fffff880`06bd5000 fffff880`06bde000 rdprefmp rdprefmp.sys Tue Jul 14 02: 16: 35 2009 (4A5BCE63)
fffff880`06bde000 fffff880`06be9000 Msfs Msfs.SYS Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`06be9000 fffff880`06bfa000 Npfs Npfs.SYS Tue Jul 14 01: 19: 48 2009 (4A5BC114)
fffff880`06e00000 fffff880`06ea3000 atikmpag atikmpag.sys Fri Apr 18 03: 07: 07 2014 (53507ABB)
fffff880`06ea3000 fffff880`06ec4000 raspptp raspptp.sys Sat Nov 20 11: 52: 31 2010 (4CE7A86F)
fffff880`06ec7000 fffff880`06f4a000 csc csc.sys Sat Nov 20 10: 27: 12 2010 (4CE79470)
fffff880`06f4a000 fffff880`06f68000 dfsc dfsc.sys Sat Nov 20 10: 26: 31 2010 (4CE79447)
fffff880`06f68000 fffff880`06f79000 blbdrive blbdrive.sys Tue Jul 14 01: 35: 59 2009 (4A5BC4DF)
fffff880`06f79000 fffff880`06f9f000 tunnel tunnel.sys Sat Nov 20 11: 51: 50 2010 (4CE7A846)
fffff880`06f9f000 fffff880`06fb9000 rassstp rassstp.sys Tue Jul 14 02: 10: 25 2009 (4A5BCCF1)
fffff880`06fb9000 fffff880`06fc6000 tap0901t tap0901t.sys Wed Sep 16 08: 02: 43 2009 (4AB07F83)
fffff880`06fc6000 fffff880`06fd1000 hamachi hamachi.sys Thu Feb 19 11: 36: 41 2009 (499D3639)
fffff880`06fd1000 fffff880`06fdc000 rdpbus rdpbus.sys Tue Jul 14 02: 17: 46 2009 (4A5BCEAA)
fffff880`06fdc000 fffff880`06feb000 kbdclass kbdclass.sys Tue Jul 14 01: 19: 50 2009 (4A5BC116)
fffff880`06feb000 fffff880`06ffa000 mouclass mouclass.sys Tue Jul 14 01: 19: 50 2009 (4A5BC116)
fffff880`07200000 fffff880`07210000 CompositeBus CompositeBus.sys Sat Nov 20 11: 33: 17 2010 (4CE7A3ED)
fffff880`07210000 fffff880`07211480 swenum swenum.sys Tue Jul 14 02: 00: 18 2009 (4A5BCA92)
fffff880`07219000 fffff880`0730d000 dxgkrnl dxgkrnl.sys Thu Aug 01 09: 58: 53 2013 (51FA153D)
fffff880`0730d000 fffff880`07353000 dxgmms1 dxgmms1.sys Wed Apr 10 05: 27: 15 2013 (5164DC13)
fffff880`07353000 fffff880`07377000 HDAudBus HDAudBus.sys Sat Nov 20 11: 43: 42 2010 (4CE7A65E)
fffff880`07377000 fffff880`07388000 usbehci usbehci.sys Fri Mar 25 04: 29: 04 2011 (4D8C0C00)
fffff880`07388000 fffff880`073de000 USBPORT USBPORT.SYS Fri Mar 25 04: 29: 12 2011 (4D8C0C08)
fffff880`073de000 fffff880`073ea000 serenum serenum.sys Tue Jul 14 02: 00: 33 2009 (4A5BCAA1)
fffff880`073ea000 fffff880`07400000 intelppm intelppm.sys Tue Jul 14 01: 19: 25 2009 (4A5BC0FD)
fffff880`07400000 fffff880`07422000 drmk drmk.sys Tue Jul 14 03: 01: 25 2009 (4A5BD8E5)
fffff880`07422000 fffff880`07427200 ksthunk ksthunk.sys Tue Jul 14 02: 00: 19 2009 (4A5BCA93)
fffff880`07428000 fffff880`074ce000 peauth peauth.sys Tue Jul 14 03: 01: 19 2009 (4A5BD8DF)
fffff880`074df000 fffff880`07522000 ks ks.sys Sat Nov 20 11: 33: 23 2010 (4CE7A3F3)
fffff880`07522000 fffff880`07534000 umbus umbus.sys Sat Nov 20 11: 44: 37 2010 (4CE7A695)
fffff880`07534000 fffff880`0758e000 usbhub usbhub.sys Fri Mar 25 04: 29: 25 2011 (4D8C0C15)
fffff880`0758e000 fffff880`075a3000 NDProxy NDProxy.SYS Sat Nov 20 11: 52: 20 2010 (4CE7A864)
fffff880`075a3000 fffff880`075be000 AtihdW76 AtihdW76.sys Fri Dec 20 04: 15: 49 2013 (52B3B665)
fffff880`075be000 fffff880`075fb000 portcls portcls.sys Tue Jul 14 02: 06: 27 2009 (4A5BCC03)
fffff880`07e02000 fffff880`07e6b000 srv2 srv2.sys Fri Apr 29 05: 05: 46 2011 (4DBA2B0A)
fffff880`07e6b000 fffff880`07f03000 srv srv.sys Fri Apr 29 05: 06: 06 2011 (4DBA2B1E)
fffff880`0820f000 fffff880`08462700 RTKVHD64 RTKVHD64.sys Wed Jul 28 12: 01: 36 2010 (4C500000)
fffff880`08463000 fffff880`08480000 cdfs cdfs.sys Tue Jul 14 01: 19: 46 2009 (4A5BC112)
fffff880`08480000 fffff880`0848e000 crashdmp crashdmp.sys Tue Jul 14 02: 01: 01 2009 (4A5BCABD)
fffff880`0848e000 fffff880`0849a000 dump_dumpata dump_dumpata.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`0849a000 fffff880`084a3000 dump_atapi dump_atapi.sys Tue Jul 14 01: 19: 47 2009 (4A5BC113)
fffff880`084a3000 fffff880`084b6000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 01: 21: 51 2009 (4A5BC18F)
fffff880`084b6000 fffff880`084c4000 hidusb hidusb.sys Sat Nov 20 11: 43: 49 2010 (4CE7A665)
fffff880`084c4000 fffff880`084dd000 HIDCLASS HIDCLASS.SYS Sat Nov 20 11: 43: 49 2010 (4CE7A665)
fffff880`084dd000 fffff880`084e5080 HIDPARSE HIDPARSE.SYS Tue Jul 14 02: 06: 17 2009 (4A5BCBF9)
fffff880`084e6000 fffff880`084e7f00 USBD USBD.SYS Fri Mar 25 04: 28: 59 2011 (4D8C0BFB)
fffff880`084e8000 fffff880`084f4000 Dxapi Dxapi.sys Tue Jul 14 01: 38: 28 2009 (4A5BC574)
fffff880`084f4000 fffff880`08501000 mouhid mouhid.sys Tue Jul 14 02: 00: 20 2009 (4A5BCA94)
fffff880`08501000 fffff880`0851e000 usbccgp usbccgp.sys Fri Mar 25 04: 29: 14 2011 (4D8C0C0A)
fffff880`0851e000 fffff880`0852c000 kbdhid kbdhid.sys Sat Nov 20 11: 33: 25 2010 (4CE7A3F5)
fffff880`0852c000 fffff880`0853a000 monitor monitor.sys Tue Jul 14 01: 38: 52 2009 (4A5BC58C)
fffff880`0853a000 fffff880`0855d000 luafv luafv.sys Tue Jul 14 01: 26: 13 2009 (4A5BC295)
fffff880`0855d000 fffff880`0857f000 aswMonFlt aswMonFlt.sys Thu Apr 17 13: 04: 01 2014 (534FB521)
fffff880`0857f000 fffff880`08598000 WudfPf WudfPf.sys Thu Jul 26 04: 26: 45 2012 (5010AAE5)
fffff880`08598000 fffff880`085b0000 aswStm aswStm.sys Mon May 05 10: 11: 48 2014 (536747C4)
fffff880`085b0000 fffff880`085c5000 lltdio lltdio.sys Tue Jul 14 02: 08: 50 2009 (4A5BCC92)
fffff880`085c5000 fffff880`085dd000 rspndr rspndr.sys Tue Jul 14 02: 08: 50 2009 (4A5BCC92)
fffff880`085dd000 fffff880`085ef000 tcpipreg tcpipreg.sys Sat Nov 20 11: 51: 48 2010 (4CE7A844)
fffff880`0f000000 fffff880`0f056000 Rt64win7 Rt64win7.sys Wed Jun 23 11: 10: 45 2010 (4C21CF95)
fffff880`0f056000 fffff880`0f06c000 AgileVpn AgileVpn.sys Tue Jul 14 02: 10: 24 2009 (4A5BCCF0)
fffff880`0f06c000 fffff880`0f090000 rasl2tp rasl2tp.sys Sat Nov 20 11: 52: 34 2010 (4CE7A872)
fffff880`0f090000 fffff880`0f09c000 ndistapi ndistapi.sys Tue Jul 14 02: 10: 00 2009 (4A5BCCD8)
fffff880`0f09c000 fffff880`0f0b7000 raspppoe raspppoe.sys Tue Jul 14 02: 10: 17 2009 (4A5BCCE9)
fffff880`0f0bd000 fffff880`0ffcd000 atikmdag atikmdag.sys Fri Apr 18 04: 13: 16 2014 (53508A3C)
fffff880`0ffcd000 fffff880`0fffc000 ndiswan ndiswan.sys Sat Nov 20 11: 52: 32 2010 (4CE7A870)
fffff960`00070000 fffff960`00386000 win32k win32k.sys unavailable (00000000)
fffff960`00400000 fffff960`0040a000 TSDDD TSDDD.dll unavailable (00000000)
fffff960`00690000 fffff960`006b7000 cdd cdd.dll unavailable (00000000)
fffff960`00950000 fffff960`009b1000 ATMFD ATMFD.DLL unavailable (00000000)
Unloaded modules:
fffff880`019d5000 fffff880`019e3000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`019e3000 fffff880`019ef000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`019ef000 fffff880`019f8000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`01800000 fffff880`01813000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000