Need BSOD Minidump Analysis

Discussion in 'Software' started by mannshands, Sep 5, 2010.

  1. mannshands

    mannshands Private First Class

    Hello,
    I need a minidump analyzed. It is attached. Here is the backround info:

    My ADVENT laptop started acting sluggish and locking up while running multiple apps, that it normally can handle. It started in the hot part of the day, but now can be anytime. Example, dl'ing torrents, streaming web-radio and surfing simultaneously. Task mgr cpu was very high use, but no process/app was using that much cpu. Then I started getting BSODs with this info:
    0x40000080 (0x89D756C0, 0x89C1BA80, 0x80551388, 0x00000001)
    I saw nothing directly related to these crashes in Event Viewer. I noticed debugging had been disabled, so I enabled it. I found that odd! I noticed alot of network access denied errors, nothing in the MS error reference link explained those. Also found event warnings regarding wscsvc service, TfFs Mon and TfSys Mon. I seem to have more services than before.
    I used ProcExp and found the prob was Hardware Interrupts using 40-80% of my cpu. Research suggested a router problem and resetting the router does fix the Hardware interrupts problem, but then it BSOD, or it may run for a few hrs, then Hardware Interrupts goes wild again.
    The pattern is: lose internet connect>cpu use shoots up(hardware interrupts)>unit gets hotter>screen freeze on browser>reset router>bsod
    I thought it was a virus because one day I started the laptop and mysteriously my FFox wouldnt connect...setting was changed to use proxies. And my IDE primary controller had been changed to PIO only, not DMA. I ran TrendMicro Housecall/SAS/MBAM/CF/Saphos rootkit when this first happened. Again 2 days ago. A few minor threats may come up, but nothing major. Fans and cooling duct clean. Did have some video driver issues 2 months ago, but Driver Genius Pro sorted that out(i think). Advent provides no XP video driver for this model, and the ones I got from devid.info lasted almost a year before they developed problems. Maybe it is related, I don't know...and no, no kids messing with unit or anything like that.

    Here is the minidump attached. Looks like a SiS ethernet driver(SiS 191). That does come from Advent. I uninstalled it, and tried a newer driver direct from SiS. New driver couldn't locate the SiS 191. I went back to the Advent supplied driver and am still no closer to an answer.

    Any help appreciated!
    mannshands

    Advent 5530 laptop, 2Gb ram, Intel Core2Duo 1.8GHz, orig. Vista wiped, downgraded to XP Pro sp3, MBAM Pro
     

    Attached Files:

    Last edited: Sep 5, 2010
  2. Rikky

    Rikky Wile E. Coyote - One of a kind

    Uninstall malwarebytes and see if the problem goes away.
     
  3. dlb

    dlb MajorGeek

    If problems persist after Rikky's suggestion, please post the exact model of your Advent laptop. It seems odd to me that MalwareBytes would cause a BSOD. I have used MBAM since it was in beta (I was an original beta tester), and I have NEVER had MBAM be the cause of a BSOD crash. Never. Since SiS is known to have 'not-the-greatest' chipsets and drivers, this is likely the cause of the problems. I have attached the WinXP drivers for SiS190/191 ethernet in a zip file below. Extract it as usual. There's no SETUP.EXE file so you have to install via the Device Manager. Be sure to uninstall your current ethernet drivers first, reboot, then try the drivers attached below.....

    (if you're unsure on how to install drivers thru the Device Manager, just ask and I'll help you out ;) )
     

    Attached Files:

  4. dlb

    dlb MajorGeek

    BTW - tfsysmon is related to the program "ThreatFire" - if it's installed, remove it and see if that helps.... most file names (not all, of course) that start with "tf" are usually "ThreatFire" related.
     
  5. mannshands

    mannshands Private First Class

    Re: Model and sys summary

    This is actually an Advent 5302, supported by Tech Guys, see:
    http://support.thetechguys.com/layout.aspx?CatID={1a907250-27a5-4b05-bec1-c3c547499a79}&ID={f2f469ce-d141-44ca-8028-91bbea022816}

    System summary by Everest attached. I agree MBAM is reliable.

    I searched but cannot find any files or services related to the tfsys errors in event viewer. Can they be traced from the event viewer? I didn't see any way to do this.The MS link says unknown event.
     

    Attached Files:

  6. mannshands

    mannshands Private First Class

    Update. Uninstalled MBAM. Got another bsod.
    Uninstalled Sis driver. It keeps loading the old driver on startup as new hardware, before I can get a chance to install the one you provided. It's the same version as the one I was using. But maybe mine is corrupt. So I rolled back to an older version, then updated using the one you gave me. It installed ok.
    Just bsod'd again. :cry Need to get a nap before I check the minidump debugger.
    Adios
     
  7. dlb

    dlb MajorGeek

    It could very well be that your onboard ethernet is failing. Try to get your hands on a PCI ethernet card and disable the on-board ethernet in the BIOS. You should be able to pick up a used PCI ethernet card at your local used PC shop for under $10 (probably closer to $5). Be sure to ask 'em for the drivers!
     
  8. mannshands

    mannshands Private First Class

    This is a laptop. PCI ethernet cards are for towers aren't they? Not many pc shops here in Andalucia. Maybe I can order an ethernet>usb cable.

    New mini dump attached.
     

    Attached Files:

  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    In Device Manager do you have any yellow ! marks by devices, please name them all?

    Also boot into Safe Mode (F8 at boot) and choose Safe Mode with Networking and do you get any same BSOD?

    Even these days if you think some malware infections are minor, they may well not be as malware comes like a pack of wolves these days with a few trying to hide the main infection from scanners, I would definatly run throught the guide below and see if our malware experts in the malware area of the forum give you an all clear.


     
  10. mannshands

    mannshands Private First Class

    Yellow marked items in DevMgr
    -Non plug and play drivers/sptd
    -Other Devices/Acer XD1270D Projector

    Been multitasking hard in Safe Mode with Network for 3 hrs, no bsod so far and performing well. What does that indicate?
    THX
    mannshands
     
  11. mannshands

    mannshands Private First Class

    I'm back. It has bsod'ed in Safe Mode now. It bsod's every 2hrs or so in normal mode, even when not connected to isp! If it does connect to isp at all it is only for 20 mins before the hardware interrupts freeze it up. Plus I get random black screen shutdowns, as if it ran out of power, but only if the unit is on but inactive for half an hour. I am gonna uninstall the network card and see if I can get it to bsod again. Unless you have a better suggestion?
    thx
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds