Win7 random shutdown & blue screen

Discussion in 'Software' started by tjmoes, Jan 10, 2013.

  1. tjmoes

    tjmoes Private E-2

    I have a hp model p6510, am constantly getting bsod, last one was a rdpencdd.sys error, have included speccy file named TED-6510 and bsod view text file
     
  2. falconattack

    falconattack Command Sergeant Major

    Hi my friend , welcome to MG's :major

    You can give the specifications of your computer

    http://majorgeeks.com/download4181.html
    http://www.softpedia.com/progScreenshots/Everest-Home-Edition-Screenshot-16369.html

    Go to

    from the left side you must opt for
    menu
    Summary ( wait 30 seconds until report is generated )
    you have to select
    Report from bar menu
    from sub menu
    Quick Report
    Plain Text

    opting for
    Desktop as saving location
    follow this

    http://forums.majorgeeks.com/showthread.php?t=86880

    attaching the report , even when windows is starting up push either F8 or F10 entering to Advanced System Options opting for

    Disable Automatic restart on system Failure :wave
     

    Attached Files:

  3. tjmoes

    tjmoes Private E-2

    Report attached - Report-hp-p6510
     
  4. tjmoes

    tjmoes Private E-2

    dont know if report got attached
     
  5. tjmoes

    tjmoes Private E-2

    is there a way to read the minidump file from the bsod
     
  6. satrow

    satrow Major Geek Extraordinaire

    To give a decent chance of tracking down the cause of the BSOD's, please collect and attach the required data as per the instructions here.

    This will include the minidmps so that we can analyse them. The output is likely to be too big to attach as one zip file, you may need to split the files into 3+ zips. How to attach items to your Posts.

    Once you have the required files, please attach them to a reply here so we can check them over.
     
  7. tjmoes

    tjmoes Private E-2

    thank you for helping, zip file is attached
     

    Attached Files:

  8. tjmoes

    tjmoes Private E-2

    forgot to include computer info which is attached as Teds6510
     

    Attached Files:

    Last edited: Jan 19, 2013
  9. tjmoes

    tjmoes Private E-2

    Re: (help) Win7 random shutdown & blue screen

    In real trouble now, I ran the verifier program as suggested, now windows will not start, crashes at the start flag with bsod :cry
     
  10. tjmoes

    tjmoes Private E-2

    Was able to revert back to last known configuration all is well sorta :celebrate
     
  11. satrow

    satrow Major Geek Extraordinaire

    On the Driver Verifier page, did you do step #1?
    If so:
     
  12. tjmoes

    tjmoes Private E-2

    I did make a restore point so i would have to run the verifier from safe mode? I have been able to startup windows without the restore point
     
  13. satrow

    satrow Major Geek Extraordinaire

    There's no need (yet) to run Driver Verifier at all, please check that it's now turned off.
    The data collection was not complete - and what was there was very sparse, have you 'tweaked' Windows to reduce logging? - one section that was missing was the Autoruns.arn data, that may be due to not running the collection app. as Administrator.

    I see one potentially 'bad' driver in the crash dump, please uninstall the software it comes with:
    AODDriver2.sys Thu Apr 5 10:23:37 2012 (4F7D6499)
    AMD Overdrive; also in EasyTune6 for Gigabyte motherboard Known BSOD issues in Win7
    http://www.carrona.org/drivers/driver.php?id=AODDriver2.sys <--- could this be AMD Fuel?

    The only dump collected (see Caliban's tutorial for saving minidumps, ensure that it's not set to overwrite) doesn't give me many clues to work with:
    Code:
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff80004dcbc9f, Address of the exception record for the exception that caused the bugcheck
    Arg3: fffff88009b3b3a0, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    FAULTING_IP: 
    nt!ObpLookupDirectoryEntry+5f
    fffff800`04dcbc9f 488b1f          mov     rbx,qword ptr [rdi]
    
    CONTEXT:  fffff88009b3b3a0 -- (.cxr 0xfffff88009b3b3a0)
    rax=0000000000000001 rbx=fffff80004a56000 rcx=fffff8a0000046e0
    rdx=fffff88009b3be70 rsi=0000000000000000 rdi=ff7ff8a01a3d58f2
    rip=fffff80004dcbc9f rsp=fffff88009b3bd80 rbp=ffdfffdfffdfffdf
     r8=0000000000000240  r9=0000000000000001 r10=0000000000000000
    r11=0000000000000006 r12=fffff88009b3be70 r13=ff80ff80ff80ff80
    r14=0000000000000240 r15=fffff8a0000046e0
    iopl=0         nv up ei pl zr na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
    nt!ObpLookupDirectoryEntry+0x5f:
    fffff800`04dcbc9f 488b1f          mov     rbx,qword ptr [rdi] ds:002b:ff7ff8a0`1a3d58f2=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x3B
    
    PROCESS_NAME:  SolutoService.
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from fffff80004dcb2d9 to fffff80004dcbc9f
    
    STACK_TEXT:  
    fffff880`09b3bd80 fffff800`04dcb2d9 : fffffa80`109db9a8 fffff880`09b3be70 fffffa80`0cd78f01 fffff8a0`00000001 : nt!ObpLookupDirectoryEntry+0x5f
    fffff880`09b3bde0 fffff800`04dcc5f6 : 00000000`00000000 fffffa80`109db7f0 fffff880`09b3c2d0 fffffa80`0c782f30 : nt!ObpLookupObjectName+0x489
    fffff880`09b3bed0 fffff800`04dcdefc : fffffa80`0cd78b50 00000000`00000000 fffff880`09b3bf00 fffff880`09b3bfb8 : nt!ObOpenObjectByName+0x306
    fffff880`09b3bfa0 fffff800`04d756bb : fffffa80`107bb5e8 fffffa80`00100001 fffff880`09b3c190 fffff880`09b3c160 : nt!IopCreateFile+0x2bc
    fffff880`09b3c040 fffff880`010e4180 : fffffa80`107bb510 00000000`00000017 fffffa80`0d49bdd8 00000000`00000000 : nt!IoCreateFileEx+0xfb
    fffff880`09b3c0e0 fffff880`010e3be9 : fffffa80`0d49bdd8 00000000`00000000 00000000`00000017 fffff880`010e4fe0 : fltmgr!FltpNormalizeNameFromCache+0x190
    fffff880`09b3c200 fffff880`010e4f81 : fffffa80`000000a0 00000000`000000a0 00000000`0000007a 00000000`00000000 : fltmgr!FltpExpandShortNames+0x239
    fffff880`09b3c260 fffff880`010e4e1e : fffffa80`107bb510 fffff880`010e0000 00000000`00000000 00000000`00000000 : fltmgr!FltpGetNormalizedFileNameWorker+0xc1
    fffff880`09b3c2a0 fffff880`010c64fb : fffffa80`0d15b100 00000000`00000000 fffffa80`107ea0a0 fffff880`09b3d000 : fltmgr!FltpCreateFileNameInformation+0xee
    fffff880`09b3c300 fffff880`010d1b44 : 00000000`00008000 fffffa80`107ea0a0 00000000`00000000 00000000`00000401 : fltmgr!FltpGetFileNameInformation+0x26b
    fffff880`09b3c380 fffff880`0111536b : fffffa80`107bb510 fffff8a0`1a451d80 00000000`00000000 fffff880`09b3c4b0 : fltmgr!FltGetFileNameInformation+0x184
    fffff880`09b3c410 fffff880`01113bdb : fffff140`343c2ca6 00000000`00000001 00000000`00000000 00000000`0000c59f : fileinfo!FIStreamGetInfo+0x11f
    fffff880`09b3c490 fffff880`010c4288 : 00000000`00000000 fffff8a0`1a451d80 fffffa80`0e245850 00000000`00000000 : fileinfo!FIPostCreateCallback+0x1c7
    fffff880`09b3c520 fffff880`010c2d1b : fffffa80`0e691030 fffffa80`0d5071e0 fffffa80`0e6d17b0 fffffa80`0e6d19d0 : fltmgr!FltpPerformPostCallbacks+0x368
    fffff880`09b3c5f0 fffff880`010e22b9 : fffffa80`0e2454b0 fffffa80`0e6841a0 fffffa80`0e245400 fffffa80`0e6849e0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x39b
    fffff880`09b3c680 fffff800`04dceb35 : 00000000`00000005 fffffa80`0e21ccc8 fffffa80`1094fa50 00000000`00000000 : fltmgr!FltpCreate+0x2a9
    fffff880`09b3c730 fffff800`04dcb3d8 : fffffa80`0d6dccd0 fffff800`00000000 fffffa80`0e21cb10 fffff8a0`03381301 : nt!IopParseDevice+0x5a5
    fffff880`09b3c8c0 fffff800`04dcc5f6 : 00000000`00000000 fffffa80`0e21cb10 fffff8a0`04bae8c0 fffffa80`0c782f30 : nt!ObpLookupObjectName+0x588
    fffff880`09b3c9b0 fffff800`04dcdefc : fffffa80`0cd78b50 00000000`00000000 fffffa80`0e1f8901 fffff880`09b3ca98 : nt!ObOpenObjectByName+0x306
    fffff880`09b3ca80 fffff800`04db9734 : 00000000`1e4ed570 fffff8a0`00100001 00000000`1e4ed5c8 00000000`1e4ed5b8 : nt!IopCreateFile+0x2bc
    fffff880`09b3cb20 fffff800`04ad4253 : ffffffff`ffffffff 00000000`00000001 00000000`1e4edc70 fffff800`00000004 : nt!NtOpenFile+0x58
    fffff880`09b3cbb0 00000000`773c164a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`1e4ed4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x773c164a
    
    
    FOLLOWUP_IP: 
    fileinfo!FIStreamGetInfo+11f
    fffff880`0111536b 85c0            test    eax,eax
    
    SYMBOL_STACK_INDEX:  b
    
    SYMBOL_NAME:  fileinfo!FIStreamGetInfo+11f
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: fileinfo
    
    IMAGE_NAME:  fileinfo.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc481
    
    STACK_COMMAND:  .cxr 0xfffff88009b3b3a0 ; kb
    
    FAILURE_BUCKET_ID:  X64_0x3B_fileinfo!FIStreamGetInfo+11f
    
    BUCKET_ID:  X64_0x3B_fileinfo!FIStreamGetInfo+11f
    
    Followup: MachineOwner
    ---------
    As the data available is so limited, and the only available dump is different to that mentioned in your OP, the real cause may be bad hardware, malware infection, badly 'tweaked' Windows etc. - it's impossible for me to tell.
     
  14. tjmoes

    tjmoes Private E-2

    not sure but i did run the autoruns.exe as admin, cant get the zip uploaded
     
  15. tjmoes

    tjmoes Private E-2

    computer info was in the ted p6510 zip file shows all the info
     
  16. tjmoes

    tjmoes Private E-2

    uploaded complete mini dump
     

    Attached Files:

  17. satrow

    satrow Major Geek Extraordinaire

    Another 0x3B, that may be good news as the AODDriver2.sys still needs uninstalling.
    Code:
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff80004dc6c9f, Address of the exception record for the exception that caused the bugcheck
    Arg3: fffff8800a5d8340, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    FAULTING_IP: 
    nt!ObpLookupDirectoryEntry+5f
    fffff800`04dc6c9f 488b1f          mov     rbx,qword ptr [rdi]
    
    CONTEXT:  fffff8800a5d8340 -- (.cxr 0xfffff8800a5d8340)
    rax=0000000000000001 rbx=fffff80004a51000 rcx=fffff8a0000046e0
    rdx=fffff8800a5d8e10 rsi=0000000000000000 rdi=ff7ff8a0175459d2
    rip=fffff80004dc6c9f rsp=fffff8800a5d8d20 rbp=ffdfffdfffdfffdf
     r8=0000000000000240  r9=0000000000000001 r10=0000000000000000
    r11=0000000000000006 r12=fffff8800a5d8e10 r13=ff80ff80ff80ff80
    r14=0000000000000240 r15=fffff8a0000046e0
    iopl=0         nv up ei pl zr na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
    nt!ObpLookupDirectoryEntry+0x5f:
    fffff800`04dc6c9f 488b1f          mov     rbx,qword ptr [rdi] ds:002b:ff7ff8a0`175459d2=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x3B
    
    PROCESS_NAME:  explorer.exe
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from fffff80004dc62d9 to fffff80004dc6c9f
    
    STACK_TEXT:  
    fffff880`0a5d8d20 fffff800`04dc62d9 : fffffa80`0d57d1c8 fffff880`0a5d8e10 fffff8a0`06bdfa01 fffff8a0`00000001 : nt!ObpLookupDirectoryEntry+0x5f
    fffff880`0a5d8d80 fffff800`04dc75f6 : 00000000`00000000 fffffa80`0d57d010 fffff8a0`093b8518 fffffa80`0c78cf30 : nt!ObpLookupObjectName+0x489
    fffff880`0a5d8e70 fffff800`04dc8efc : fffffa80`0ca2e860 00000000`00000000 fffffa80`0d3d5f00 fffff880`0107b75b : nt!ObOpenObjectByName+0x306
    fffff880`0a5d8f40 fffff800`04d706bb : fffffa80`0cb23930 fffffa80`00100001 fffff880`0a5d9140 fffff880`0a5d9110 : nt!IopCreateFile+0x2bc
    fffff880`0a5d8fe0 fffff880`01087ac5 : 00000000`00000020 00000000`00000000 fffffa80`0cb238a0 00000000`00000000 : nt!IoCreateFileEx+0xfb
    fffff880`0a5d9080 fffff880`010892fe : fffff880`0a5da000 fffff880`0a5d0026 fffffa80`0d5e1468 00000000`00000000 : fltmgr!FltpExpandFilePathWorker+0x255
    fffff880`0a5d91c0 fffff880`0107bed8 : 00000000`00000000 00000000`00000000 fffffa80`0cb238a0 fffff880`0a5d9690 : fltmgr!FltpExpandFilePath+0x1e
    fffff880`0a5d91f0 fffff880`01075e1e : fffffa80`0cb238a0 fffff8a0`093b8510 00000000`00000000 fffff8a0`00fc2258 : fltmgr! ?? ::NNGAKEGL::`string'+0x1ed8
    fffff880`0a5d9230 fffff880`01061b9d : c00000bb`18764400 00000000`00000000 fffffa80`0fefdb00 fffff880`0a5da000 : fltmgr!FltpCreateFileNameInformation+0xee
    fffff880`0a5d9290 fffff880`0105bbf6 : fffffa80`0c755100 fffffa80`0fefd010 fffffa80`0e8eb8f8 fffffa80`00000000 : fltmgr!HandleStreamListNotSupported+0x15d
    fffff880`0a5d92d0 fffff880`01062b44 : 00000000`00000000 00000000`00000000 fffffa80`0fefd010 00000000`00000401 : fltmgr! ?? ::FNODOBFM::`string'+0x30f3
    fffff880`0a5d9350 fffff880`019e3960 : fffffa80`0cb238a0 00000000`00000000 00000000`00000001 00000000`80000000 : fltmgr!FltGetFileNameInformation+0x184
    fffff880`0a5d93e0 fffffa80`0cb238a0 : 00000000`00000000 00000000`00000001 00000000`80000000 fffff8a0`1876a3d0 : avgmfx64+0x4960
    fffff880`0a5d93e8 00000000`00000000 : 00000000`00000001 00000000`80000000 fffff8a0`1876a3d0 00000000`00000040 : 0xfffffa80`0cb238a0
    
    
    FOLLOWUP_IP: 
    avgmfx64+4960
    fffff880`019e3960 ??              ???
    
    SYMBOL_STACK_INDEX:  c
    
    SYMBOL_NAME:  avgmfx64+4960
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: avgmfx64
    
    IMAGE_NAME:  avgmfx64.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  50a566c6
    
    STACK_COMMAND:  .cxr 0xfffff8800a5d8340 ; kb
    
    FAILURE_BUCKET_ID:  X64_0x3B_avgmfx64+4960
    
    BUCKET_ID:  X64_0x3B_avgmfx64+4960
    
    Followup: MachineOwner
    If you have the autoruns.arn file now, zip it and attach it please.

    Look for an update to your Arcsoft programs, the Afc.sys driver pre-dates the release of W7 and needs updating or uninstalling.

    Driver loaded in the dump file - for information only:
    Code:
    [COLOR=RED][B]Afc.sys                       Wed Jul 12 06:48:20 2006 (44B48D24)[/B][/COLOR]
    Arcsoft(R) ASPI Shell (CD/DVD program)
    [url=http://www.carrona.org/drivers/driver.php?id=Afc.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]Afc.sys[/COLOR][/B][/url]
     
    ahcix64s.sys                  Wed Sep 23 13:52:47 2009 (4ABA1A1F)
    AMD AHCI Compatible RAID Controller
    [url=http://www.carrona.org/drivers/driver.php?id=ahcix64s.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]ahcix64s.sys[/COLOR][/B][/url]
     
    usbfilter.sys                 Wed Oct  7 08:44:08 2009 (4ACC46C8)
    AMD USB Filter Driver (likely part of the chipset drivers)
    [url=http://www.carrona.org/drivers/driver.php?id=usbfilter.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]usbfilter.sys[/COLOR][/B][/url]
     
    amdiox64.sys                  Thu Feb 18 15:17:53 2010 (4B7D5A21)
    AMD IO Driver
    [url=http://www.carrona.org/drivers/driver.php?id=amdiox64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]amdiox64.sys[/COLOR][/B][/url]
     
    AtiPcie64.sys                 Wed Mar 10 14:33:45 2010 (4B97ADC9)
    AMD PCIE Filter Driver[br]Found in my ATI video drivers (I have an Intel chipset)
    [url=http://www.carrona.org/drivers/driver.php?id=AtiPcie64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]AtiPcie64.sys[/COLOR][/B][/url]
     
    amdxata.sys                   Fri Mar 19 16:18:18 2010 (4BA3A3CA)
    AMD storage controller driver - usually from the Windows 7 DVD
    [url=http://www.carrona.org/drivers/driver.php?id=amdxata.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]amdxata.sys[/COLOR][/B][/url]
     
    RtsUStor.sys                  Thu Jun 17 10:17:45 2010 (4C19E839)
    Realtek USB Card Reader
    [url=http://www.carrona.org/drivers/driver.php?id=RtsUStor.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]RtsUStor.sys[/COLOR][/B][/url]
     
    RTKVHD64.sys                  Tue Sep  7 12:17:23 2010 (4C861F43)
    Realtek High Definition Audio Function Driver
    [url=http://www.carrona.org/drivers/driver.php?id=RTKVHD64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]RTKVHD64.sys[/COLOR][/B][/url]
     
    vpcnfltr.sys                  Sat Nov 20 11:35:20 2010 (4CE7B278)
    VMware Virtual Network driver
    [url=http://www.carrona.org/drivers/driver.php?id=vpcnfltr.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]vpcnfltr.sys[/COLOR][/B][/url]
     
    vpcusb.sys                    Sat Nov 20 11:35:31 2010 (4CE7B283)
    VMware
    [url=http://www.carrona.org/drivers/driver.php?id=vpcusb.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]vpcusb.sys[/COLOR][/B][/url]
     
    vpchbus.sys                   Sat Nov 20 11:35:38 2010 (4CE7B28A)
    VMware
    [url=http://www.carrona.org/drivers/driver.php?id=vpchbus.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]vpchbus.sys[/COLOR][/B][/url]
     
    vpcvmm.sys                    Sat Nov 20 11:35:48 2010 (4CE7B294)
    VMware
    [url=http://www.carrona.org/drivers/driver.php?id=vpcvmm.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]vpcvmm.sys[/COLOR][/B][/url]
     
    Soluto.sys                    Mon Feb 14 12:25:50 2011 (4D591F4E)
    Soluto driver
    [url=http://www.carrona.org/drivers/driver.php?id=Soluto.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]Soluto.sys[/COLOR][/B][/url]
     
    speedfan.sys                  Fri Mar 18 16:08:46 2011 (4D83838E)
    SpeedFan
    [url=http://www.carrona.org/drivers/driver.php?id=speedfan.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]speedfan.sys[/COLOR][/B][/url]
     
    atikmpag.sys                  Thu Jun 30 04:00:51 2011 (4E0BE6E3)
    ATI Video driver (remove the Catalyst Control Center and only install the Display Driver)
    [url=http://www.carrona.org/drivers/driver.php?id=atikmpag.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]atikmpag.sys[/COLOR][/B][/url]
     
    atikmdag.sys                  Thu Jun 30 04:59:27 2011 (4E0BF49F)
    ATI Video driver (remove the Catalyst Control Center and only install the Display Driver)
    [url=http://www.carrona.org/drivers/driver.php?id=atikmdag.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]atikmdag.sys[/COLOR][/B][/url]
     
    dvdfab.sys                    Thu Aug 11 04:05:10 2011 (4E4346E6)
     
    dvdfab.sys - this driver hasn't been added to the DRT as of this run. Please search Google/Bing for the driver if additional information is needed.
     
    fltsrv.sys                    Thu Nov 17 12:29:13 2011 (4EC4FE19)
    Acronis Storage Filter Management Driver
    [url=http://www.carrona.org/drivers/driver.php?id=fltsrv.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]fltsrv.sys[/COLOR][/B][/url]
     
    vsflt67.sys                   Wed Dec 14 11:43:33 2011 (4EE88BE5)
     
    vsflt67.sys - this driver hasn't been added to the DRT as of this run. Please search Google/Bing for the driver if additional information is needed.
     
    lvbflt64.sys                  Wed Jan 18 06:39:53 2012 (4F166939)
    Logitech Webcam Software driver
    [url=http://www.carrona.org/drivers/driver.php?id=lvbflt64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]lvbflt64.sys[/COLOR][/B][/url]
     
    lvrs64.sys                    Wed Jan 18 06:40:36 2012 (4F166964)
    Logitech Camera driver
    [url=http://www.carrona.org/drivers/driver.php?id=lvrs64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]lvrs64.sys[/COLOR][/B][/url]
     
    lvuvc64.sys                   Wed Jan 18 06:41:08 2012 (4F166984)
    Logitech USB Video Class Driver (WebCam)
    [url=http://www.carrona.org/drivers/driver.php?id=lvuvc64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]lvuvc64.sys[/COLOR][/B][/url]
     
    Rt64win7.sys                  Fri Mar  9 12:40:37 2012 (4F59FA45)
    Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC
    [url=http://www.carrona.org/drivers/driver.php?id=Rt64win7.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]Rt64win7.sys[/COLOR][/B][/url]
     
    [COLOR=RED][B]AODDriver2.sys                Thu Apr  5 10:23:37 2012 (4F7D6499)[/B][/COLOR]
    AMD Overdrive; also in EasyTune6 for Gigabyte motherboard  [br]  Known [COLOR=RED]BSOD[/COLOR] issues in Win7
    [url=http://www.carrona.org/drivers/driver.php?id=AODDriver2.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]AODDriver2.sys[/COLOR][/B][/url]
     
    TuneUpUtilitiesDriver64.sys   Fri May 25 11:28:19 2012 (4FBF5EC3)
    TuneUpUtilitiesDrv
    [url=http://www.carrona.org/drivers/driver.php?id=TuneUpUtilitiesDriver64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]TuneUpUtilitiesDriver64.sys[/COLOR][/B][/url]
     
    avgrkx64.sys                  Fri Sep 14 01:41:40 2012 (50527D44)
    AVG Anti-Rootkit Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgrkx64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgrkx64.sys[/COLOR][/B][/url]
     
    avgloga.sys                   Fri Sep 21 02:23:51 2012 (505BC1A7)
    AVG Logging Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgloga.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgloga.sys[/COLOR][/B][/url]
     
    avgtdia.sys                   Fri Sep 21 02:25:33 2012 (505BC20D)
    AVG TDI Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgtdia.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgtdia.sys[/COLOR][/B][/url]
     
    avgldx64.sys                  Tue Oct  2 02:05:50 2012 (506A3DEE)
    AVG AVI Loader Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgldx64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgldx64.sys[/COLOR][/B][/url]
     
    avgidsha.sys                  Mon Oct 15 02:22:54 2012 (507B656E)
    AVG IDS Application Activity Monitor Helper Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgidsha.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgidsha.sys[/COLOR][/B][/url]
     
    avgidsdrivera.sys             Mon Oct 22 11:47:11 2012 (5085242F)
    AVG IDS Application Activity Monitor Driver
    [url=http://www.carrona.org/drivers/driver.php?id=avgidsdrivera.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgidsdrivera.sys[/COLOR][/B][/url]
     
    cpuz136_x64.sys               Sat Oct 27 18:24:41 2012 (508C18D9)
    CPUID CPU-Z driver
    [url=http://www.carrona.org/drivers/driver.php?id=cpuz136_x64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]cpuz136_x64.sys[/COLOR][/B][/url]
     
    avgmfx64.sys                  Thu Nov 15 22:03:50 2012 (50A566C6)
    AVG Mini-Filter Resident Anti-Virus Shield
    [url=http://www.carrona.org/drivers/driver.php?id=avgmfx64.sys]http://www.carrona.org/drivers/driver.php?id=[B][COLOR="BLUE"]avgmfx64.sys[/COLOR][/B][/url]
     
     
  18. tjmoes

    tjmoes Private E-2

    i couldnt zip the an file but it is uploaded to my sitehttp://tjmoes.com/AutoRuns.arn

    there isnt any uninstall for the amd fuel and i stopped the fuel service but it reverts back to auto start in services
    95% of the bsod are 0x3B
     
  19. falconattack

    falconattack Command Sergeant Major

    0x3B is related that graphic driver is the problem i think , you have to wait suggestions by satrow
     
  20. satrow

    satrow Major Geek Extraordinaire

    I think that if you run the main AMD/ATI graphics uninstaller, you'll get a selection that you can choose to remove, all you really need is the graphics drivers.

    The Autoruns wasn't run as part of the collection app., the details aren't good enough on a normal run for me to be able to check certain things, like the likelihood of malware infections - I do see part of a Bandoo/Seachqu toolbar though, that will need dealing with.
     
  21. tjmoes

    tjmoes Private E-2

    i dont know what u want i have run all that 3 times and u keep saying its incomplete
     
  22. tjmoes

    tjmoes Private E-2

    now iim getting new bsod code 0x0000007E (0xffffffffC00005, 0xfffff80004a6d81b, ffffff880009a93d8, fffff880009a8c30) have a new dump file attached
     

    Attached Files:

  23. satrow

    satrow Major Geek Extraordinaire

    Please update us on every change that you've made, it helps a lot ;)

    Let's try running the collection app again:
    The latest dump uploaded is another 0x3B, the pattern shows that drives are being corrupted whilst in memory, this could be by a bad driver or other reasons including malware.

    Please check that minidumps are not set to overwrite! Caliban's tutorial.
     
  24. tjmoes

    tjmoes Private E-2

    i hope this is complete now
     

    Attached Files:

  25. satrow

    satrow Major Geek Extraordinaire

    Still no verification or filtering in the Autoruns file. Start Autoruns and hit Esc, Options > Filter options and check Verify code signatures and Hide Microsoft drivers then hit Refresh or F5, once it's fully loaded - watch the Status bar - save it, zip it and attach it please.

    Also the MSInfo32.nfo file is corrupt this time, maybe because it was saved/zipped too soon, maybe not ... :(
     
  26. tjmoes

    tjmoes Private E-2

    the MSInfo32.nfo is being saved as DAmm nfo viewer file and it says only 500kb is viewable you have another way to save msinfo32
     

    Attached Files:

  27. tjmoes

    tjmoes Private E-2

    msinfo32 saved as text file
     

    Attached Files:

  28. tjmoes

    tjmoes Private E-2

    any solutions yet
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds