Are these minidumps hardware failure related?

Discussion in 'Software' started by thisisu, May 6, 2013.

  1. thisisu

    thisisu Malware Consultant

    Hi,

    I have a laptop here that is giving BSOD 0x7e upon boot up. I attached the latest minidumps I have for review as I am no expert at analyzing them.

    Code:
    IO_ERROR: (NTSTATUS) 0xc0000185 - The I/O device reported an I/O error.
    MODULE_NAME: hardware_disk
    IMAGE_NAME:  hardware_disk
    Is it safe to say that this is HDD failure related? I can still see all the data on the drive when booting from a boot CD, not hearing any sound "clicks". Memtest passed (2 passes). I've done offline SFC /scannow and full chkdsk without any issue. The computer doesn't lock up ever, just this BSOD code.

    Windows 7.

    Let me know if you need additional info about the laptop.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    I should have tried this immediately after noticing those BSODs, I ran Spinrite (hdd diagnostic tool) and it's stuck on the second block of the OS partition (partition #3).

    Going to back up the data that I can see and then let the scan continue.
     
  3. plastidust

    plastidust Command Sergeant Major

    Blue Screen View has your minidump files showing:

    5/3/2013 19:53:30 | SYSTEM_THREAD_EXCEPTION_NOT_HANDLED | CI.dll | CI.dll+4840

    5/3/2013 19:05:02 | CRITICAL_OBJECT_TERMINATION | ntkrnlpa.exe | ntkrnlpa.exe+dec2c

    4/30/2013 17:43:14 | SYSTEM_THREAD_EXCEPTION_NOT_HANDLED | CI.dll | CI.dll+4840

    4/27/2013 20:18:02 | SYSTEM_THREAD_EXCEPTION_NOT_HANDLED | CI.dll | CI.dll+9e68

    The ntkrnlpa.exe error might indicate a failing HDD, but it looks more like CI.dll(Code Integrity Module) is corrupt. The bulk of what I've found so far, CI.dll is not really the problem. The error is do to an infection that Kaspersky's TDSSKiller can do away with. These reports, all showing a similar fix involving TDSSKiller, are from 2010 and 2011. The reports that didn't include TDSSKiller did include a format/re-installation.

    Anyway, if it might be an infection, you and the experts in the Malware Removal Forum are much better equipped to determine that than I am, but it's something to check. I suppose you could just replace the CI.dll file and see what happens. But that only worked in once case.
     
  4. satrow

    satrow Major Geek Extraordinaire

    Yup, looks like the HDD has issues :( directly blamed in the 3x 0x7E's, 0xF4 is frequently associated with HDD/SSD problems too.


    3rd party driver list, for info only:

    TVALZ_O.SYS Fri Nov 9 03:07:46 2007 (4733CF02)
    TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver
    http://www.carrona.org/drivers/driver.php?id=TVALZ_O.SYS

    AGRSM.sys Mon Nov 10 14:56:37 2008 (49184BA5)
    Agere SoftModem Driver
    http://www.carrona.org/drivers/driver.php?id=AGRSM.sys

    Rt86win7.sys Thu Feb 26 09:04:22 2009 (49A65B16)
    Realtek NIC
    http://www.carrona.org/drivers/driver.php?id=Rt86win7.sys

    GEARAspiWDM.sys Mon May 18 13:16:53 2009 (4A1151B5)
    CD-ROM Class Filter Driver by Gear Software.[br]Also comes with iTunes
    http://www.carrona.org/drivers/driver.php?id=GEARAspiWDM.sys

    atikmdag.sys Tue Aug 18 04:03:58 2009 (4A8A1A1E)
    ATI Video driver (remove the Catalyst Control Center and only install the Display Driver)
    http://www.carrona.org/drivers/driver.php?id=atikmdag.sys

    athr.sys Mon Sep 21 18:58:25 2009 (4AB7BEC1)
    Atheros Extensible Wireless LAN driver for CB42/CB43/MB42/MB43 Network Adapter - D-Link AirPlus DWL-G520 Wireless PCI Adapter(rev.B) discontinued 2008
    http://www.carrona.org/drivers/driver.php?id=athr.sys

    amdxata.sys Fri Mar 19 16:19:01 2010 (4BA3A3F5)
    AMD storage controller driver - usually from the Windows 7 DVD
    http://www.carrona.org/drivers/driver.php?id=amdxata.sys

    avgtpx86.sys Tue Jan 29 10:44:39 2013 (5107A817)
    AVG Driver
    http://www.carrona.org/drivers/driver.php?id=avgtpx86.sys

    BSOD BUGCHECK SUMMARY
    Code:
    [font=lucida console]
    Debug session time: Sat May  4 01:51:49.074 2013 (GMT+1)
    Loading Dump File [C:\Users\RoLY\SysnativeBSODApps\050313-41043-01.dmp]
    Built by: 7601.18113.x86fre.win7sp1_gdr.130318-1533
    System Uptime: 0 days 0:02:40.415
    [B]Probably caused by : hardware_disk[/B]
    BugCheck 1000007E, {c0000006, 828a7fea, 9701faa8, 9701f680}
    BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x1000007E]SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)[/url]
    Bugcheck code 1000007E
    Arguments: 
    Arg1: c0000006, The exception code that was not handled
    Arg2: 828a7fea, The address that the exception occurred at
    Arg3: 9701faa8, Exception Record Address
    Arg4: 9701f680, Context Record Address
    PROCESS_NAME:  System
    BUGCHECK_STR:  0x7E
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    [B]FAILURE_BUCKET_ID:  0x7E_IMAGE_hardware_disk[/B]
    BiosVersion = 1.40
    BiosReleaseDate = 11/24/2008
    SystemManufacturer = TOSHIBA
    SystemProductName = Satellite L305D
    ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
    Debug session time: Wed May  1 23:45:46.925 2013 (GMT+1)
    Loading Dump File [C:\Users\RoLY\SysnativeBSODApps\050313-20716-01.dmp]
    Built by: 7601.18113.x86fre.win7sp1_gdr.130318-1533
    System Uptime: 0 days 0:07:48.265
    BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x000000F4]CRITICAL_OBJECT_TERMINATION (f4)[/url]
    Bugcheck code 000000f4
    Arguments: 
    Arg1: 00000003, Process
    Arg2: 85ec9030, Terminating object
    Arg3: 85ec919c, Process image file name
    Arg4: 82a58eb0, Explanatory message (ascii)
    PROCESS_NAME:  csrss.exe
    BUGCHECK_STR:  0xF4_IOERR
    FAILURE_BUCKET_ID:  0xF4_IOERR_IMAGE_csrss.exe
    BiosVersion = 1.40
    BiosReleaseDate = 11/24/2008
    SystemManufacturer = TOSHIBA
    SystemProductName = Satellite L305D
    ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
    Debug session time: Tue Apr 30 23:41:56.221 2013 (GMT+1)
    Loading Dump File [C:\Users\RoLY\SysnativeBSODApps\043013-18813-01.dmp]
    Built by: 7601.18113.x86fre.win7sp1_gdr.130318-1533
    System Uptime: 0 days 1:54:45.437
    [B]Probably caused by : hardware_disk[/B]
    BugCheck 1000007E, {c0000006, 828d9fea, 958d5aa8, 958d5680}
    BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x1000007E]SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)[/url]
    Bugcheck code 1000007E
    Arguments: 
    Arg1: c0000006, The exception code that was not handled
    Arg2: 828d9fea, The address that the exception occurred at
    Arg3: 958d5aa8, Exception Record Address
    Arg4: 958d5680, Context Record Address
    PROCESS_NAME:  System
    BUGCHECK_STR:  0x7E
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    [B]FAILURE_BUCKET_ID:  0x7E_IMAGE_hardware_disk[/B]
    BiosVersion = 1.40
    BiosReleaseDate = 11/24/2008
    SystemManufacturer = TOSHIBA
    SystemProductName = Satellite L305D
    ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
    Debug session time: Sun Apr 28 02:15:59.449 2013 (GMT+1)
    Loading Dump File [C:\Users\RoLY\SysnativeBSODApps\042713-63554-01.dmp]
    Built by: 7601.18113.x86fre.win7sp1_gdr.130318-1533
    System Uptime: 0 days 0:02:10.790
    [B]Probably caused by : hardware_disk[/B]
    BugCheck 1000007E, {c0000006, 82e9fe68, 9511da2c, 9511d610}
    BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x1000007E]SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)[/url]
    Bugcheck code 1000007E
    Arguments: 
    Arg1: c0000006, The exception code that was not handled
    Arg2: 82e9fe68, The address that the exception occurred at
    Arg3: 9511da2c, Exception Record Address
    Arg4: 9511d610, Context Record Address
    PROCESS_NAME:  System
    BUGCHECK_STR:  0x7E
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    [B]FAILURE_BUCKET_ID:  0x7E_IMAGE_hardware_disk[/B]
    BiosVersion = 1.40
    BiosReleaseDate = 11/24/2008
    SystemManufacturer = TOSHIBA
    SystemProductName = Satellite L305D[/font]
     
  5. thisisu

    thisisu Malware Consultant

    Thanks guys! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds