BSOD's
Hi, I've been browsing through here most of the morning. I have a PC with XP Home SP2 that's giving me fits.
First off, the file system was corrupt and it would display the XP Splash screen and then there would be a never ending reboot cycle.
I ran chkdsk and fixed all the errors and now it boots ok, however, within about 15 seconds of the desktop coming up....BAM! Get a BSOD.
No specific stop error message (like the irql_not_less_or_equal or anything like that)
Just 0x0000008e (0xC000005, bla bla bla)
It seems to run perfectly fine in safe mode. The event viewer says it created a dmp file, but that it didn't complete.
I tried the disabling pe386 trick...didn't have anything to disable. I can't install a virus scanner in safe mode, and my corpmod boot CD for some reason I can't get it to work properly after updating the virus defs.
I'm running the latest version of memtest-86 as we speak and it hasn't popped up any errors yet, but it seems to be running rather slow. I've ran the Microsoft Memory analyzer also and after the first pass, it started running slow also, but no errors.
I have Microscope 2005 also, but it won't get past the HDD detection since it's a SATA HDD.
Anybody have any other ideas?
This is probably the 5th random BSOD computer I've seen in the last 2 days. It's crazy all of a sudden...makes me think it's a virus of some sort, but I have no way to do anything at this point. Maybe I'm not thinking clearly enough to think of something...
First off, the file system was corrupt and it would display the XP Splash screen and then there would be a never ending reboot cycle.
I ran chkdsk and fixed all the errors and now it boots ok, however, within about 15 seconds of the desktop coming up....BAM! Get a BSOD.
No specific stop error message (like the irql_not_less_or_equal or anything like that)
Just 0x0000008e (0xC000005, bla bla bla)
It seems to run perfectly fine in safe mode. The event viewer says it created a dmp file, but that it didn't complete.
I tried the disabling pe386 trick...didn't have anything to disable. I can't install a virus scanner in safe mode, and my corpmod boot CD for some reason I can't get it to work properly after updating the virus defs.
I'm running the latest version of memtest-86 as we speak and it hasn't popped up any errors yet, but it seems to be running rather slow. I've ran the Microsoft Memory analyzer also and after the first pass, it started running slow also, but no errors.
I have Microscope 2005 also, but it won't get past the HDD detection since it's a SATA HDD.
Anybody have any other ideas?
This is probably the 5th random BSOD computer I've seen in the last 2 days. It's crazy all of a sudden...makes me think it's a virus of some sort, but I have no way to do anything at this point. Maybe I'm not thinking clearly enough to think of something...
0
Comments
**NEW HJT LOG POSTED BELOW**
I've moved your thread to the Spyware forum. Lets check if there is malware on the computer. We'll need to update HijackThis as you're using an old version. Go into Add/Remove programs in Control Panel and Uninstall/Remove HijackThis, and then do the following...
Download HJTInstall.exe to your Desktop.
Anywhoo, here is my new hjt log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:11:32 PM, on 9/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\tech1\HJTInstall.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe"
O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe"
O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
O4 - HKLM\..\Run: [Easy PDF Creator] C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Xerox_WorkCenter_C2424] C:\Program Files\Xerox\WorkCentre C2424\xc24bgts.exe 1
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus Photo R320 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9FA.EXE /P30 "EPSON Stylus Photo R320 Series" /O6 "USB001" /M "Stylus Photo R320"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GoToMyPC] C:\Program Files\Citrix\GoToMyPC\g2svc.exe -logon
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R320 Series on STUDIO220-PC] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9FA.EXE /P51 "Auto EPSON Stylus Photo R320 Series on STUDIO220-PC" /O45 "[URL="file://\\STUDIO220-PC\EPSON"]\\STUDIO220-PC\EPSON[/URL] Stylus Photo R320 Series" /M "Stylus Photo R320"
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MonacoGamma.lnk = C:\Program Files\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe
O4 - Global Startup: MonacoReminder.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {40F8967E-34A6-474A-837A-CEC1E7DAC54C} - https://accounting.quickbooks.com/c7/v15.585/qboax9.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} (QuickBooks Online Edition Utilities Class v10) - https://accounting.quickbooks.com/c12/v16.607/qboax10.cab
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} - https://accounting.quickbooks.com/c7/v15.236/qboax8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - OSA Technologies Inc., An Avocent Company - C:\Program Files\Intel\IDU\awServ.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
--
End of file - 9433 bytes
This is the actual BSOD I get:
I'm moving the thread back to Emergency help.
Can you tell us the result of memtest?
I still think this is a hardware problem.
I am getting the same error as in the screen shot from arvetus 09-06-2007, 06:13 PM #5, except for the memory addresses inside the parentheses are a little different
The actual BSOD uses stop 0x0000008e, but the Windows system event log is a bit different:
Date: 9/23/2007 Source: System Error
Time: 4:19:17 PM Catagory: (102)
Type: Error Event ID: 1003
Error code 1000008e, parameter1 c0000005, parameter2 806ff94f, parameter3 a9882d88, parameter4 00000000.
---the above error occurred in direct response to right clicking on the system tray icon for "GoToMyPC" and selecting preferences" and is the first break I've had in trying to figure this problem out since I received this PC on 9/21 to "figure it out"
---The errors which previously only occurred at startup within the first minute (according to the uptime in the minidump) and always while still at the login screen (system is running XP pro and has classic style login prompt)
the previous errors are all the same, the most recent sample at startup:
Date: 9/23/2007 Source: Save Dump
Time: 3:50:10 PM Catagory: None
Type: Information Event ID: 1001
The computer has rebooted from a bugcheck. The bugcheck was: 0x1000008e (0xc0000005, 0x806ff94f, 0xa9882d88, 0x00000000). A dump was saved in: C:\WINDOWS\Minidump\Mini092307-08.dmp.
----it does not actually reboot as stated b/c the auto reboot was disabled a few days ago when I was first given this PC to look at
Prior to this break through I had suspected the ethernet card since there were some errors about it that would show up together with the save dumps, but after rebooting with both the ethernet card disabled/enabled and having upgraded the driver (Broadcom BCM5705 A3 Driver version from 7 to 10.24.0.0 12/15/2006) and both providing it with a connection and keeping the cable unplugged, the ethernet card seems to have no effect on whether the BSOD will happen at startup, the same was also ruled out for the Wireless card Cisco Aironet 802.11a/b/g Wireless Adapter
Since the first time I booted up the PC after I received it, if of course had started up fine, I opened up every application that the owner of the PC was known to use, and all at the same time - no response other than to get a bit slower.
--- I left it on for 2 days straight running both a defrag and a NAV scan at the same time I didn't actually see the BSOD that was being reported until I rebooted it after it had run happily but unattended for 2 days, it did that 2-3 times in a row before I unplugged everything and held down the power button to reset it, started it back up, and it behaved normally again, rebooted it several more times and randomly got the BSOD, sometimes it went away on its own after 2-3 reboots, sometimes I got tired of waiting and power cycled it as that had worked before ---first thing that was moderately consistent
---- between the fact that it generally runs everything fine once it's actually on, and that and it passed chkdsk /r without errors, the hard drive is definitely fine (Stop 0x08e isn't a hard drive error anyway)
I wanted to rule out memory although didn't really suspect it since there were no other performance issues after login, ran the memtest boot CD all night, it completed 26 passes with no errors.
I was backing up the data to CD when the owner of the PC decided to remote in via "GoToMyPC" I informed him I was still working on it, and he disconnected...I then decided to check the log, turn off access so I wouldn't be disturbed again at which point the PC crashed as stated above when I was accessing the prefs.
I have since turned off the setting for "GoToMyPC" to start the service before login, and instead have set it to wait until after login...I'll reboot a few more times and see if I can get it to crash again, or if uninstalling it helps, but I wanted to get this post up sooner to see if anyone else has any ideas or similar experiences with this application or error.
Thanks to anyone that actually bothered to read this much of the post!
Below are the contents of several minidumps (I would attach a file but I'm too new to the forum)
C:\Program Files\Support Tools>dumpchk C:\WINDOWS\Minidump\Mini091407-01.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091407-01.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 2140a000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9a30b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9a30b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Fri Sep 14 18:40:09 2007
System Uptime: 0 days 0:00:41
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 04:
08:32 2007 (45E54690)
Unloaded modules:
f779b000 f77a4000 processr.sys Timestamp: unavailable (00000000)
f7983000 f7988000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7390000 f7393000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -e C:\WINDOWS\Minidump\Mini091907-05.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-05.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 2614a000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a8fa8b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a8fa8b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:35:24 2007
System Uptime: 0 days 0:00:44
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f781b000 f7824000 processr.sys Timestamp: unavailable (00000000)
f79b3000 f79b8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7398000 f739b000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -e C:\WINDOWS\Minidump\Mini091907-04.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-04.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 261d4000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9b08b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9b08b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:27:43 2007
System Uptime: 0 days 0:00:46
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f781b000 f7824000 processr.sys Timestamp: unavailable (00000000)
f79b3000 f79b8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aa7000 f7aaa000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -ve C:\WINDOWS\Minidump\Mini091907-04.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-04.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 261d4000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9b08b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9b08b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:27:43 2007
System Uptime: 0 days 0:00:46
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f781b000 f7824000 processr.sys Timestamp: unavailable (00000000)
f79b3000 f79b8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aa7000 f7aaa000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -ve C:\WINDOWS\Minidump\Mini091907-03.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-03.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 25c94000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9986b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a1
StringPoolOffset 000060b8
StringPoolSize 00001678
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9986b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 00007730
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:24:37 2007
System Uptime: 0 days 0:00:54
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f781b000 f7824000 processr.sys Timestamp: unavailable (00000000)
f79b3000 f79b8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7a9f000 f7aa2000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -ve C:\WINDOWS\Minidump\Mini091907-02.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-02.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 25d54000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a8721b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a8721b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:22:40 2007
System Uptime: 0 days 0:00:48
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f783b000 f7844000 processr.sys Timestamp: unavailable (00000000)
f79c3000 f79c8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aaf000 f7ab2000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -ve C:\WINDOWS\Minidump\Mini091907-01.dmp
Loading dump file C:\WINDOWS\Minidump\Mini091907-01.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 2600a000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9eedb18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 000000a0
StringPoolOffset 00006068
StringPoolSize 00001658
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9eedb28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 000076c0
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Wed Sep 19 11:21:02 2007
System Uptime: 0 days 0:00:44
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
f785b000 f7864000 processr.sys Timestamp: unavailable (00000000)
f79b3000 f79b8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7390000 f7393000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk -vec C:\WINDOWS\Minidump\Mini091807-01.dm
p
Loading dump file C:\WINDOWS\Minidump\Mini091807-01.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 2234a000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9ae2b18
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000004d8
DriverListOffset 000030e8
DriverCount 0000009f
StringPoolOffset 00006020
StringPoolSize 00001638
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9ae2b28
DebuggerDataOffset 00002e58
DebuggerDataSize 00000290
DataBlocksOffset 00007658
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Tue Sep 18 09:11:43 2007
System Uptime: 0 days 0:00:53
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 01:
08:32 2007 (45E54690)
Unloaded modules:
aa306000 aa35f000 WPN111.sys Timestamp: unavailable (00000000)
f784b000 f7854000 processr.sys Timestamp: unavailable (00000000)
f7973000 f7978000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aaf000 f7ab2000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>
C:\Program Files\Support Tools>dumpchk C:\WINDOWS\Minidump\Mini092307-08.dmp
Loading dump file C:\WINDOWS\Minidump\Mini092307-08.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 068c0000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 a9882d88
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 00001268
DriverListOffset 00003e78
DriverCount 00000096
StringPoolOffset 00006b00
StringPoolSize 000014d8
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack a9882d98
DebuggerDataOffset 00003be8
DebuggerDataSize 00000290
DataBlocksOffset 00007fd8
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Sep 23 15:49:05 2007
System Uptime: 0 days 1:02:30
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 04:
08:32 2007 (45E54690)
Unloaded modules:
f7b2d000 f7b2f000 splitter.sys Timestamp: unavailable (00000000)
a8db3000 a8dc6000 NAVENG.SYS Timestamp: unavailable (00000000)
a8dc6000 a8e98000 NAVEX15.SYS Timestamp: unavailable (00000000)
a95da000 a9605000 kmixer.sys Timestamp: unavailable (00000000)
f7d57000 f7d58000 drmkaud.sys Timestamp: unavailable (00000000)
a97c4000 a97e7000 aec.sys Timestamp: unavailable (00000000)
a96f5000 a9724000 MidiSyn.sys Timestamp: unavailable (00000000)
a9974000 a9981000 DMusic.sys Timestamp: unavailable (00000000)
a99c4000 a99d2000 swmidi.sys Timestamp: unavailable (00000000)
f7bc5000 f7bc7000 splitter.sys Timestamp: unavailable (00000000)
f77db000 f77e4000 processr.sys Timestamp: unavailable (00000000)
f796b000 f7970000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aaf000 f7ab2000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk C:\WINDOWS\Minidump\Mini092307-07.dmp
Loading dump file C:\WINDOWS\Minidump\Mini092307-07.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 068c0000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 f7a5a694
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 0000095c
DriverListOffset 00003570
DriverCount 00000090
StringPoolOffset 00006030
StringPoolSize 00001400
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack f7a5a6a4
DebuggerDataOffset 000032e0
DebuggerDataSize 00000290
DataBlocksOffset 00007430
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Sep 23 15:38:01 2007
System Uptime: 0 days 0:00:28
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 04:
08:32 2007 (45E54690)
Unloaded modules:
f782b000 f7834000 processr.sys Timestamp: unavailable (00000000)
f79a3000 f79a8000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aa3000 f7aa6000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk C:\WINDOWS\Minidump\Mini092307-05.dmp
Loading dump file C:\WINDOWS\Minidump\Mini092307-05.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 068c0000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 f7a56694
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 0000095c
DriverListOffset 00003570
DriverCount 00000092
StringPoolOffset 000060c8
StringPoolSize 00001448
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack f7a566a4
DebuggerDataOffset 000032e0
DebuggerDataSize 00000290
DataBlocksOffset 00007510
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Sep 23 15:27:03 2007
System Uptime: 0 days 0:00:39
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 04:
08:32 2007 (45E54690)
Unloaded modules:
f783b000 f7844000 processr.sys Timestamp: unavailable (00000000)
f79ab000 f79b0000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7390000 f7393000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>dumpchk C:\WINDOWS\Minidump\Mini092307-04.dmp
Loading dump file C:\WINDOWS\Minidump\Mini092307-04.dmp
32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 068c0000
PfnDataBase 81053000
PsLoadedModuleList 805624a0
PsActiveProcessHead 80568558
MachineImageType 0000014c
NumberProcessors 00000002
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 806ff94f
BugCheckParameter3 f7a5a694
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 805522e0
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 0000095c
DriverListOffset 00003570
DriverCount 00000092
StringPoolOffset 000060c8
StringPoolSize 00001448
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack f7a5a6a4
DebuggerDataOffset 000032e0
DebuggerDataSize 00000290
DataBlocksOffset 00007510
DataBlocksCount 00000006
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Sep 23 15:22:11 2007
System Uptime: 0 days 0:00:28
start end module name
804d7000 806fd000 nt Checksum: 0020DAE3 Timestamp: Wed Feb 28 04:
08:32 2007 (45E54690)
Unloaded modules:
f783b000 f7844000 processr.sys Timestamp: unavailable (00000000)
f79ab000 f79b0000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7aa3000 f7aa6000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
C:\Program Files\Support Tools>