Vista bluescreen gefolgt von CHKDSK

Orios das Auge

Ehrbarer Bürger
Hallo

Als ich mit mein lappi heute ein bischen gesurft habe und ihn danach ne weile stehen lassen habe ging er Plötzlich aus und nachdem ich ihn wieder Anschaltete machte er CHKDSK wodurch ich schon ein wenig Skeptisch wurde und sicherheitshalber Avira drüberlafen lassen wollte der wiederum bei 10,irgendwas Prozent ungefähr ne Stunde fest hing(war bei irgendeiner html Datei). Danach Bluescreen, Automatischer neustart und wieder CHKDSK o_O

Läuft mein lappi jetzt gefahr das er irgendwann garnicht mehr angeht (was eine Katastrophe wär). Kann ich irgendwas machen um ggf beschädigte Komponenten zu reparieren (mit einen Programm oder so). Eine Windows neuinstallation ist in absehbarer zeit nicht möglich da meine Windows cd bei einen Bekannten liegt wo ich in naher Zukunft nicht ran komme.

Danke schon mal im voraus
 
Wenn sich das BS des Lappi wie WinXP verhält, dann scheint dein Lappi im laufenden Betrieb ausgegeangen zu sein. Dann kann es sein, dass er einige Daten, die beim normalen Beenden auf die Platte zurückgeschrieben hätte nicht mehr findet bzw das einige Teile von Programmen die aprupt beendet wurden in Fragmenten auf der Platte liegen.

Das BS vermutet dann in einem solchen Falle immer einen Festplattendefekt und will Chkdsk ausführen. Lass es einfach durchlaufen und dann wird diese Meldung beim nächsten Start verschwinden.

Schlimmer wäre eine Meldung wie ntldr not found. Dann hilft meistens nur eine Neuinstallation wenn man sich nicht genau auskennt und weiß wie man das mit der Installationscd wieder hinbiegen kann.
 
solch eine meldung ist mir nicht aufgefallen wo erscheint die denn falls sie auftaucht.

So mein Anitivirus ist jetzt wieder bei 10 prozent es handelt sich bei der Datei um irgend eine html datei im hilfe ordner von mein Adobe cs 3. Allerdings leidet mein lappi gerade an einem komplett freez (nix geht mehr es sind auch keine großartigen Hardware Anstrengungen obwohl die Ladelampe kontinuierlich leuchtet zu vernehmen).
 
Dann merke dir doch mal den Datei-Namen und lösche sie beim nächsten reeboot, und schaue was passirt;)
 
So mein OS ist nun tod :cry:

Fehlermeldung

Datei: /Windows/system32/Config/system

Status: 0xc000014c

info: Windows konnte nicht geladen werden da die systemregestrierungsdatei nicht vorhanden oder beschädigt ist.

Ohne cd geht da gar nichts mehr oder?
 
Also da Steht man kann die Datei aus den catch ziehen man muss nur vorher mit cd booten. Würde es nich auch gehen wenn ich die lappi fest platte raus nehme an meinem tower anklemme und darüber das mache?
 
Er lebt wieder :hah:
brauchte nur die eine Datei ersetzen

aber am Grund Problem hat sich nix geändert er hat mich gleich wieder mit CHKDSK begrüßt auch am PC von meinem Bruder (wo ich das System wiederhergestellt habe)
hat er das gemacht
 
Nein da liegst du falsch (Kannst beruhigt sein^^)
das war ja nur eine Adobe hilfe datei

Es ist zustande gekommen als ich nach einem Blackscreen freez den aus Knopf gedrückt habe:)

Edit: Kleine frage am Rande kann ich irgendwie eine boot cd erstellen damit ich meine fest platte nicht ausbauen muss Fall´s mir so was wieder passiert?
 
Zuletzt bearbeitet:
So mein Vista läuft leider immer noch nicht ganz rund X(
Gestern Lag ihn ein Update quer (Er wollte nicht booten erst nach dem 1000 Start versuch kam er auf die Idee das 3te update zu konfigurieren). Naja denn lief er wieder
(zumindest bis heute morgen wo er nach dem hochfahren rund 5-10 Minuten später freezte nachdem ich STRG+ALT+ENTF drückte wurde der Bildschirm Schwatz und etwas später kam die Fehlermeldung:

Überschrift: Fehler beim Erstellen des Sicherheitsoptionen-Dialogfelds

Fehler Sicherheitsoptionen

OK als an klick Möglichkeit

Nach der Fehlermeldung blieb mir nix anderes übrig als den Rechner neu zu starten.
Das Spiel ging denn ungefähr 6 mal so weiter. Naja jetzt läuft er wieder seit knapp 2 Stunden.

Ich habe denn danach gegoogelt und Stieß Auf diesen Interessanten Beitrag.
Was ich natürlich gleich Ausprobiert habe.

Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18304.amd64fre.vistasp1_gdr.090805-0102
Machine Name:
Kernel base = 0xfffff800`02618000 PsLoadedModuleList = 0xfffff800`027dddb0
Debug session time: Sun Feb 7 14:57:52.694 2010 (GMT+1)
System Uptime: 0 days 1:57:06.857
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols

Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 9F, {3, fffffa8009b88a10, fffffa8009b88a10, fffffa800546fbd0}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Probably caused by : ntkrnlmp.exe ( nt!wctomb+14962 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_POWER_STATE_FAILURE (9f)
A driver is causing an inconsistent power state.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
Arg2: fffffa8009b88a10, Physical Device Object of the stack
Arg3: fffffa8009b88a10, Functional Device Object of the stack
Arg4: fffffa800546fbd0, The blocked IRP

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_IRP ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************

ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: nt

FAULTING_MODULE: fffff80002618000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 4a796b09

DRVPOWERSTATE_SUBCODE: 3

IRP_ADDRESS: fffffa800546fbd0

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x9F

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff800026cc01e to fffff8000266c6d0

STACK_TEXT:
fffff800`0387f9f8 fffff800`026cc01e : 00000000`0000009f 00000000`00000003 fffffa80`09b88a10 fffffa80`09b88a10 : nt!KeBugCheckEx
fffff800`0387fa00 fffff800`02674bb3 : fffff800`0387fad8 00000000`00000000 00000000`00000002 fffffa80`063ba501 : nt!wctomb+0x14962
fffff800`0387fa70 fffff800`02675538 : fffff800`0387fcd0 fffffa80`06368a02 fffff800`0387fcc8 fffffa60`00000010 : nt!KeInsertQueue+0x743
fffff800`0387fca0 fffff800`02675d9f : 00000c1c`c25ff090 00000000`00000000 fffffa80`00000010 fffff800`0278fa80 : nt!KeUpdateRunTime+0x548
fffff800`0387fd10 fffff800`02676e72 : fffff800`0278c680 fffff800`0278c680 00000000`00000000 fffff800`02791b80 : nt!KeSetTimer+0x42f
fffff800`0387fd80 fffff800`028455c0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExEnterPriorityRegionAndAcquireResourceExclusive+0x182
fffff800`0387fdb0 00000000`fffff800 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlGetCompressionWorkSpaceSize+0x700
fffff800`038790b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00680000`00000000 : 0xfffff800


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!wctomb+14962
fffff800`026cc01e cc int 3

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!wctomb+14962

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: ntkrnlmp.exe

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

0: kd> lmv
start end module name
fffff800`02618000 fffff800`02b30000 nt (export symbols) ntkrnlmp.exe
Loaded symbol image file: ntkrnlmp.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Wed Aug 05 13:20:41 2009 (4A796B09)
CheckSum: 0048635A
ImageSize: 00518000
File version: 6.0.6001.18304
Product version: 6.0.6001.18304
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.0.6001.18304
FileVersion: 6.0.6001.18304 (vistasp1_gdr.090805-0102)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffff800`02b30000 fffff800`02b76000 hal (deferred)
Image path: hal.dll
Image name: hal.dll
Timestamp: Sat Jan 19 08:55:25 2008 (4791ACED)
CheckSum: 00043CEE
ImageSize: 00046000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffff960`00080000 fffff960`00333000 win32k (deferred)
Image path: \SystemRoot\System32\win32k.sys
Image name: win32k.sys
Timestamp: Fri Aug 14 16:43:51 2009 (4A857827)
CheckSum: 002A220F
ImageSize: 002B3000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffff960`004e0000 fffff960`004ea000 TSDDD (deferred)
Image path: \SystemRoot\System32\TSDDD.dll
Image name: TSDDD.dll
Timestamp: Sat Jan 19 07:42:04 2008 (47919BBC)
CheckSum: 00012267
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffff960`00640000 fffff960`00651000 cdd (deferred)
Image path: \SystemRoot\System32\cdd.dll
Image name: cdd.dll
Timestamp: Sat Aug 02 05:40:21 2008 (4893D725)
CheckSum: 0000E6EF
ImageSize: 00011000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffff960`008b0000 fffff960`00911000 ATMFD (deferred)
Image path: \SystemRoot\System32\ATMFD.DLL
Image name: ATMFD.DLL
Timestamp: Mon Jun 15 15:17:34 2009 (4A3649EE)
CheckSum: 000641BB
ImageSize: 00061000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`0060c000 fffffa60`00616000 kdcom (deferred)
Image path: kdcom.dll
Image name: kdcom.dll
Timestamp: Sat Jan 19 08:58:25 2008 (4791ADA1)
CheckSum: 00010852
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00616000 fffffa60`0062a000 PSHED (deferred)
Image path: \SystemRoot\system32\PSHED.dll
Image name: PSHED.dll
Timestamp: Sat Jan 19 08:58:13 2008 (4791AD95)
CheckSum: 00011D76
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`0062a000 fffffa60`00687000 CLFS (deferred)
Image path: \SystemRoot\system32\CLFS.SYS
Image name: CLFS.SYS
Timestamp: Sat Jan 19 06:53:58 2008 (47919076)
CheckSum: 0006703C
ImageSize: 0005D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00687000 fffffa60`00739000 CI (deferred)
Image path: \SystemRoot\system32\CI.dll
Image name: CI.dll
Timestamp: Fri Feb 22 06:20:54 2008 (47BE5BB6)
CheckSum: 000612B8
ImageSize: 000B2000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00739000 fffffa60`0077f000 fltmgr (deferred)
Image path: \SystemRoot\system32\drivers\fltmgr.sys
Image name: fltmgr.sys
Timestamp: Sat Jan 19 06:54:10 2008 (47919082)
CheckSum: 00052A4F
ImageSize: 00046000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`0077f000 fffffa60`007d5000 SynTP (deferred)
Image path: \SystemRoot\system32\DRIVERS\SynTP.sys
Image name: SynTP.sys
Timestamp: Fri Mar 28 02:15:32 2008 (47EC46B4)
CheckSum: 00058FCC
ImageSize: 00056000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`007d5000 fffffa60`007fc000 mrxdav (deferred)
Image path: \SystemRoot\system32\drivers\mrxdav.sys
Image name: mrxdav.sys
Timestamp: Sat Jan 19 06:55:28 2008 (479190D0)
CheckSum: 0002C95B
ImageSize: 00027000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00802000 fffffa60`008dc000 Wdf01000 (deferred)
Image path: \SystemRoot\system32\drivers\Wdf01000.sys
Image name: Wdf01000.sys
Timestamp: Sat Jan 19 07:33:27 2008 (479199B7)
CheckSum: 000D946B
ImageSize: 000DA000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`008dc000 fffffa60`008ea000 WDFLDR (deferred)
Image path: \SystemRoot\system32\drivers\WDFLDR.SYS
Image name: WDFLDR.SYS
Timestamp: Sat Jan 19 07:32:33 2008 (47919981)
CheckSum: 00018BBD
ImageSize: 0000E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`008ea000 fffffa60`0091a000 pci (deferred)
Image path: \SystemRoot\system32\drivers\pci.sys
Image name: pci.sys
Timestamp: Sat Jan 19 07:02:57 2008 (47919291)
CheckSum: 0002E1DA
ImageSize: 00030000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: pci.sys
OriginalFilename: pci.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: NT Plug and Play PCI Enumerator
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`0091a000 fffffa60`0092e000 volmgr (deferred)
Image path: \SystemRoot\system32\drivers\volmgr.sys
Image name: volmgr.sys
Timestamp: Sat Jan 19 07:29:12 2008 (479198B8)
CheckSum: 0001A150
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`0092e000 fffffa60`00994000 volmgrx (deferred)
Image path: \SystemRoot\System32\drivers\volmgrx.sys
Image name: volmgrx.sys
Timestamp: Sat Jan 19 07:29:45 2008 (479198D9)
CheckSum: 000736D8
ImageSize: 00066000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00994000 fffffa60`009a7000 mountmgr (deferred)
Image path: \SystemRoot\System32\drivers\mountmgr.sys
Image name: mountmgr.sys
Timestamp: Sat Jan 19 07:28:01 2008 (47919871)
CheckSum: 000157AE
ImageSize: 00013000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`009a7000 fffffa60`009cb000 ataport (deferred)
Image path: \SystemRoot\system32\drivers\ataport.SYS
Image name: ataport.SYS
Timestamp: Sat Jan 19 07:28:52 2008 (479198A4)
CheckSum: 0002D9AD
ImageSize: 00024000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`009cb000 fffffa60`009d5000 msahci (deferred)
Image path: \SystemRoot\system32\drivers\msahci.sys
Image name: msahci.sys
Timestamp: Sat Jan 19 07:28:58 2008 (479198AA)
CheckSum: 00010AEA
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`009d5000 fffffa60`009e5000 PCIIDEX (deferred)
Image path: \SystemRoot\system32\drivers\PCIIDEX.SYS
Image name: PCIIDEX.SYS
Timestamp: Sat Jan 19 07:28:53 2008 (479198A5)
CheckSum: 000105D1
ImageSize: 00010000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`009e5000 fffffa60`009f9000 fileinfo (deferred)
Image path: \SystemRoot\system32\drivers\fileinfo.sys
Image name: fileinfo.sys
Timestamp: Sat Jan 19 07:05:23 2008 (47919323)
CheckSum: 0002031C
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00a00000 fffffa60`00a08000 atapi (deferred)
Image path: \SystemRoot\system32\drivers\atapi.sys
Image name: atapi.sys
Timestamp: Sat Jan 19 07:28:49 2008 (479198A1)
CheckSum: 0000905D
ImageSize: 00008000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00a0a000 fffffa60`00b3e000 sptd (deferred)
Image path: \SystemRoot\System32\Drivers\sptd.sys
Image name: sptd.sys
Timestamp: Thu Mar 06 01:34:27 2008 (47CF3C13)
CheckSum: 000DA3DE
ImageSize: 00134000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00b3e000 fffffa60`00b47000 WMILIB (deferred)
Image path: \SystemRoot\System32\Drivers\WMILIB.SYS
Image name: WMILIB.SYS
Timestamp: Sat Jan 19 07:33:45 2008 (479199C9)
CheckSum: 0000994C
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00b47000 fffffa60`00b75000 SCSIPORT (deferred)
Image path: \SystemRoot\System32\Drivers\SCSIPORT.SYS
Image name: SCSIPORT.SYS
Timestamp: Sat Jan 19 07:28:52 2008 (479198A4)
CheckSum: 0002E61E
ImageSize: 0002E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00b75000 fffffa60`00bcb000 acpi (deferred)
Image path: \SystemRoot\system32\drivers\acpi.sys
Image name: acpi.sys
Timestamp: Sat Jan 19 07:02:45 2008 (47919285)
CheckSum: 00058740
ImageSize: 00056000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00bcb000 fffffa60`00bd5000 msisadrv (deferred)
Image path: \SystemRoot\system32\drivers\msisadrv.sys
Image name: msisadrv.sys
Timestamp: Sat Jan 19 07:02:50 2008 (4791928A)
CheckSum: 0000AD81
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00bd5000 fffffa60`00bea000 partmgr (deferred)
Image path: \SystemRoot\System32\drivers\partmgr.sys
Image name: partmgr.sys
Timestamp: Sat Jan 19 07:29:14 2008 (479198BA)
CheckSum: 0001E741
ImageSize: 00015000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00bea000 fffffa60`00bed400 compbatt (deferred)
Image path: \SystemRoot\system32\DRIVERS\compbatt.sys
Image name: compbatt.sys
Timestamp: Sat Jan 19 07:02:42 2008 (47919282)
CheckSum: 00006BD1
ImageSize: 00003400
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00bee000 fffffa60`00bfa000 BATTC (deferred)
Image path: \SystemRoot\system32\DRIVERS\BATTC.SYS
Image name: BATTC.SYS
Timestamp: Sat Jan 19 07:02:38 2008 (4791927E)
CheckSum: 0000A722
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00c0f000 fffffa60`00c96000 ksecdd (deferred)
Image path: \SystemRoot\System32\Drivers\ksecdd.sys
Image name: ksecdd.sys
Timestamp: Mon Jun 15 15:27:03 2009 (4A364C27)
CheckSum: 00082476
ImageSize: 00087000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00c96000 fffffa60`00ce6000 msrpc (deferred)
Image path: \SystemRoot\system32\drivers\msrpc.sys
Image name: msrpc.sys
Timestamp: Sat Jan 19 07:27:01 2008 (47919835)
CheckSum: 000568B6
ImageSize: 00050000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00ce6000 fffffa60`00d3e000 NETIO (deferred)
Image path: \SystemRoot\system32\drivers\NETIO.SYS
Image name: NETIO.SYS
Timestamp: Sat Jan 19 07:37:27 2008 (47919AA7)
CheckSum: 00062189
ImageSize: 00058000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00d3e000 fffffa60`00d6a000 CLASSPNP (deferred)
Image path: \SystemRoot\system32\drivers\CLASSPNP.SYS
Image name: CLASSPNP.SYS
Timestamp: Sat Jan 19 07:28:53 2008 (479198A5)
CheckSum: 0003398B
ImageSize: 0002C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00d87000 fffffa60`00d93000 tunnel (deferred)
Image path: \SystemRoot\system32\DRIVERS\tunnel.sys
Image name: tunnel.sys
Timestamp: Sat Jan 19 07:36:44 2008 (47919A7C)
CheckSum: 00009336
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00d93000 fffffa60`00d9c000 tunmp (deferred)
Image path: \SystemRoot\system32\DRIVERS\tunmp.sys
Image name: tunmp.sys
Timestamp: Sat Jan 19 07:36:30 2008 (47919A6E)
CheckSum: 0000DBCB
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00d9c000 fffffa60`00daf000 processr (deferred)
Image path: \SystemRoot\system32\DRIVERS\processr.sys
Image name: processr.sys
Timestamp: Sat Jan 19 06:52:45 2008 (4791902D)
CheckSum: 00012129
ImageSize: 00013000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00daf000 fffffa60`00dc7000 rassstp (deferred)
Image path: \SystemRoot\system32\DRIVERS\rassstp.sys
Image name: rassstp.sys
Timestamp: Sat Jan 19 07:37:42 2008 (47919AB6)
CheckSum: 00021F4E
ImageSize: 00018000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00dc7000 fffffa60`00de2000 wanarp (deferred)
Image path: \SystemRoot\system32\DRIVERS\wanarp.sys
Image name: wanarp.sys
Timestamp: Sat Jan 19 07:37:35 2008 (47919AAF)
CheckSum: 00024097
ImageSize: 0001B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00e03000 fffffa60`00fc6000 ndis (deferred)
Image path: \SystemRoot\system32\drivers\ndis.sys
Image name: ndis.sys
Timestamp: Sat Jan 19 07:37:13 2008 (47919A99)
CheckSum: 000BF30F
ImageSize: 001C3000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00fc6000 fffffa60`00fda000 disk (deferred)
Image path: \SystemRoot\system32\drivers\disk.sys
Image name: disk.sys
Timestamp: Sat Jan 19 07:29:02 2008 (479198AE)
CheckSum: 0001E740
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`00fda000 fffffa60`00fe4000 crcdisk (deferred)
Image path: \SystemRoot\system32\drivers\crcdisk.sys
Image name: crcdisk.sys
Timestamp: Sat Jan 19 07:30:12 2008 (479198F4)
CheckSum: 0001435C
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`01004000 fffffa60`01177000 tcpip (deferred)
Image path: \SystemRoot\System32\drivers\tcpip.sys
Image name: tcpip.sys
Timestamp: Fri Aug 14 17:13:02 2009 (4A857EFE)
CheckSum: 00162CE6
ImageSize: 00173000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`01177000 fffffa60`011a3000 fwpkclnt (deferred)
Image path: \SystemRoot\System32\drivers\fwpkclnt.sys
Image name: fwpkclnt.sys
Timestamp: Sat Jan 19 07:36:43 2008 (47919A7B)
CheckSum: 0002AB85
ImageSize: 0002C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`011a3000 fffffa60`011cf000 ecache (deferred)
Image path: \SystemRoot\System32\drivers\ecache.sys
Image name: ecache.sys
Timestamp: Sat Jan 19 07:30:39 2008 (4791990F)
CheckSum: 0002BD24
ImageSize: 0002C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`011cf000 fffffa60`011f8000 fvevol (deferred)
Image path: \SystemRoot\System32\DRIVERS\fvevol.sys
Image name: fvevol.sys
Timestamp: Sat Jan 19 06:52:29 2008 (4791901D)
CheckSum: 00030106
ImageSize: 00029000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`01200000 fffffa60`01208000 AtiPcie (deferred)
Image path: \SystemRoot\system32\DRIVERS\AtiPcie.sys
Image name: AtiPcie.sys
Timestamp: Mon Nov 06 17:59:54 2006 (454F6A0A)
CheckSum: 000104A1
ImageSize: 00008000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`0120d000 fffffa60`01391000 Ntfs (deferred)
Image path: \SystemRoot\System32\Drivers\Ntfs.sys
Image name: Ntfs.sys
Timestamp: Sat Jan 19 06:55:29 2008 (479190D1)
CheckSum: 001871E2
ImageSize: 00184000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntfs.sys
OriginalFilename: ntfs.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: NT File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`01391000 fffffa60`013d5000 volsnap (deferred)
Image path: \SystemRoot\system32\drivers\volsnap.sys
Image name: volsnap.sys
Timestamp: Sat Jan 19 07:29:47 2008 (479198DB)
CheckSum: 0004D804
ImageSize: 00044000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`013d5000 fffffa60`013dd000 spldr (deferred)
Image path: \SystemRoot\System32\Drivers\spldr.sys
Image name: spldr.sys
Timestamp: Fri Jun 22 02:57:56 2007 (467B1E94)
CheckSum: 0000FB4D
ImageSize: 00008000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`013dd000 fffffa60`013ef000 mup (deferred)
Image path: \SystemRoot\System32\Drivers\mup.sys
Image name: mup.sys
Timestamp: Sat Jan 19 06:54:18 2008 (4791908A)
CheckSum: 0001BB47
ImageSize: 00012000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`013ef000 fffffa60`013f9000 hpdskflt (deferred)
Image path: \SystemRoot\system32\DRIVERS\hpdskflt.sys
Image name: hpdskflt.sys
Timestamp: Thu Aug 07 16:28:04 2008 (489B0674)
CheckSum: 0000BDD8
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12205000 fffffa60`1237d000 bcmwl664 (deferred)
Image path: \SystemRoot\system32\DRIVERS\bcmwl664.sys
Image name: bcmwl664.sys
Timestamp: Thu Oct 23 02:41:31 2008 (48FFC83B)
CheckSum: 00182E0F
ImageSize: 00178000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`1237d000 fffffa60`12399000 cdrom (deferred)
Image path: \SystemRoot\system32\DRIVERS\cdrom.sys
Image name: cdrom.sys
Timestamp: Sat Jan 19 07:29:04 2008 (479198B0)
CheckSum: 00021C5B
ImageSize: 0001C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12399000 fffffa60`123a4000 usbohci (deferred)
Image path: \SystemRoot\system32\DRIVERS\usbohci.sys
Image name: usbohci.sys
Timestamp: Sat Jan 19 07:33:56 2008 (479199D4)
CheckSum: 00014EDD
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`123a4000 fffffa60`123ea000 USBPORT (deferred)
Image path: \SystemRoot\system32\DRIVERS\USBPORT.SYS
Image name: USBPORT.SYS
Timestamp: Sat Jan 19 07:34:00 2008 (479199D8)
CheckSum: 00047A81
ImageSize: 00046000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: usbport.sys
OriginalFilename: usbport.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: USB 1.1 & 2.0 Port Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`123ea000 fffffa60`123fb000 usbehci (deferred)
Image path: \SystemRoot\system32\DRIVERS\usbehci.sys
Image name: usbehci.sys
Timestamp: Sat Jan 19 07:33:57 2008 (479199D5)
CheckSum: 00012DBE
ImageSize: 00011000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`123fb000 fffffa60`123fce00 USBD (deferred)
Image path: \SystemRoot\system32\DRIVERS\USBD.SYS
Image name: USBD.SYS
Timestamp: Sat Jan 19 07:33:53 2008 (479199D1)
CheckSum: 00010C2B
ImageSize: 00001E00
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: usbd.sys
OriginalFilename: usbd.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Universal Serial Bus Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`1240f000 fffffa60`12a61000 atikmdag (deferred)
Image path: \SystemRoot\system32\DRIVERS\atikmdag.sys
Image name: atikmdag.sys
Timestamp: Thu Sep 11 06:17:05 2008 (48C89BC1)
CheckSum: 004715F9
ImageSize: 00652000
File version: 7.1.1.798
Product version: 7.1.1.798
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 3.4 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: ATI Technologies Inc.
ProductName: ATI Radeon Family
InternalName: atikmdag.sys
OriginalFilename: atikmdag.sys
ProductVersion: 7.01.01.798
FileVersion: 7.01.01.798
FileDescription: ATI Radeon Kernel Mode Driver
LegalCopyright: Copyright (C) 1998-2006 ATI Technologies Inc.
fffffa60`12a61000 fffffa60`12b40000 dxgkrnl (deferred)
Image path: \SystemRoot\System32\drivers\dxgkrnl.sys
Image name: dxgkrnl.sys
Timestamp: Sat Aug 02 03:19:59 2008 (4893B63F)
CheckSum: 000E5D5E
ImageSize: 000DF000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12b40000 fffffa60`12b4f000 watchdog (deferred)
Image path: \SystemRoot\System32\drivers\watchdog.sys
Image name: watchdog.sys
Timestamp: Sat Jan 19 07:07:23 2008 (4791939B)
CheckSum: 0000BD94
ImageSize: 0000F000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: watchdog.sys
OriginalFilename: watchdog.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Watchdog Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12b4f000 fffffa60`12bb7000 yk60x64 (deferred)
Image path: \SystemRoot\system32\DRIVERS\yk60x64.sys
Image name: yk60x64.sys
Timestamp: Fri Apr 04 15:26:07 2008 (47F62C6F)
CheckSum: 0006B61A
ImageSize: 00068000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12bb7000 fffffa60`12bca000 HDAudBus (deferred)
Image path: \SystemRoot\system32\DRIVERS\HDAudBus.sys
Image name: HDAudBus.sys
Timestamp: Wed Nov 28 00:24:06 2007 (474CA716)
CheckSum: 00016CCD
ImageSize: 00013000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12bca000 fffffa60`12be0000 i8042prt (deferred)
Image path: \SystemRoot\system32\DRIVERS\i8042prt.sys
Image name: i8042prt.sys
Timestamp: Sat Jan 19 07:28:08 2008 (47919878)
CheckSum: 0001AA50
ImageSize: 00016000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12be0000 fffffa60`12bee000 kbdclass (deferred)
Image path: \SystemRoot\system32\DRIVERS\kbdclass.sys
Image name: kbdclass.sys
Timestamp: Sat Jan 19 07:28:05 2008 (47919875)
CheckSum: 0000AF5D
ImageSize: 0000E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12bee000 fffffa60`12bfa000 mouclass (deferred)
Image path: \SystemRoot\system32\DRIVERS\mouclass.sys
Image name: mouclass.sys
Timestamp: Sat Jan 19 07:28:05 2008 (47919875)
CheckSum: 00017BB4
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12c08000 fffffa60`12c7e000 auchpyvw (deferred)
Image path: \SystemRoot\System32\Drivers\auchpyvw.SYS
Image name: auchpyvw.SYS
Timestamp: Thu Mar 27 13:24:50 2008 (47EB9212)
CheckSum: 0005BDFD
ImageSize: 00076000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12c7e000 fffffa60`12c8a000 Accelerometer (deferred)
Image path: \SystemRoot\system32\DRIVERS\Accelerometer.sys
Image name: Accelerometer.sys
Timestamp: Thu Aug 07 16:28:04 2008 (489B0674)
CheckSum: 00019B1E
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12c8a000 fffffa60`12c8e580 CmBatt (deferred)
Image path: \SystemRoot\system32\DRIVERS\CmBatt.sys
Image name: CmBatt.sys
Timestamp: Sat Jan 19 07:02:42 2008 (47919282)
CheckSum: 00011FE7
ImageSize: 00004580
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12c8f000 fffffa60`12c92180 cpqbttn64 (deferred)
Image path: \SystemRoot\system32\DRIVERS\cpqbttn64.sys
Image name: cpqbttn64.sys
Timestamp: Wed Jun 28 17:40:47 2006 (44A2A2FF)
CheckSum: 0000F5D9
ImageSize: 00003180
File version: 4.20.2.3
Product version: 5.1.2600.0
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Hewlett-Packard Development Company, L.P.
ProductName: HP Quick Launch Buttons
InternalName: CPQBttn.sys
OriginalFilename: CPQBttn.sys
ProductVersion: 4.20.02.03
FileVersion: 4.20.02.03 built by: WinDDK
FileDescription: HP Tablet PC Key Button HID Driver
LegalCopyright: © Copyright 2002-2005 Hewlett-Packard Development Company, L.P.
fffffa60`12c93000 fffffa60`12ca5000 HIDCLASS (deferred)
Image path: \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
Image name: HIDCLASS.SYS
Timestamp: Sat Jan 19 07:33:52 2008 (479199D0)
CheckSum: 0001B17C
ImageSize: 00012000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: hidclass.sys
OriginalFilename: hidclass.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Hid Class Library
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12ca5000 fffffa60`12cacb80 HIDPARSE (deferred)
Image path: \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
Image name: HIDPARSE.SYS
Timestamp: Sat Jan 19 07:33:51 2008 (479199CF)
CheckSum: 0001084B
ImageSize: 00007B80
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: hidparse.sys
OriginalFilename: hidparse.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Hid Parsing Library
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12cad000 fffffa60`12cb6000 wmiacpi (deferred)
Image path: \SystemRoot\system32\DRIVERS\wmiacpi.sys
Image name: wmiacpi.sys
Timestamp: Sat Jan 19 07:02:42 2008 (47919282)
CheckSum: 0000936F
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12cb6000 fffffa60`12cc4000 vcd9bus (deferred)
Image path: \SystemRoot\system32\DRIVERS\vcd9bus.sys
Image name: vcd9bus.sys
Timestamp: Tue Jan 23 08:30:45 2007 (45B5B9A5)
CheckSum: 000141A6
ImageSize: 0000E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12cc4000 fffffa60`12cc6680 wacomvhid (deferred)
Image path: \SystemRoot\system32\DRIVERS\wacomvhid.sys
Image name: wacomvhid.sys
Timestamp: Tue Aug 19 00:44:49 2008 (48A9FB61)
CheckSum: 00009016
ImageSize: 00002680
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12cc7000 fffffa60`12cc8c80 WacomVKHid (deferred)
Image path: \SystemRoot\system32\DRIVERS\WacomVKHid.sys
Image name: WacomVKHid.sys
Timestamp: Fri Feb 16 00:10:54 2007 (45D4E87E)
CheckSum: 0000F2B4
ImageSize: 00001C80
File version: 1.1.0.0
Product version: 1.1.0.0
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Wacom Technology
ProductName: Wacom Virtual HID Driver
InternalName: wacomvhid.sys
OriginalFilename: wacomvhid.sys
ProductVersion: 1.1.0000.0
FileVersion: 1.1.0000.0
FileDescription: Virtual Hid Device
LegalCopyright: © Wacom Technology. All rights reserved.
fffffa60`12cc9000 fffffa60`12d01000 msiscsi (deferred)
Image path: \SystemRoot\system32\DRIVERS\msiscsi.sys
Image name: msiscsi.sys
Timestamp: Sat Jan 19 07:30:31 2008 (47919907)
CheckSum: 00037F21
ImageSize: 00038000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12d01000 fffffa60`12d5e000 storport (deferred)
Image path: \SystemRoot\system32\DRIVERS\storport.sys
Image name: storport.sys
Timestamp: Sat Jan 19 07:29:09 2008 (479198B5)
CheckSum: 0002A26D
ImageSize: 0005D000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: storport.sys
OriginalFilename: storport.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Microsoft Storage Port Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12d5e000 fffffa60`12d6b000 TDI (deferred)
Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
Image name: TDI.SYS
Timestamp: Sat Jan 19 07:38:11 2008 (47919AD3)
CheckSum: 00011EE5
ImageSize: 0000D000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: tdi.sys
OriginalFilename: tdi.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: TDI Wrapper
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12d6b000 fffffa60`12d8e000 rasl2tp (deferred)
Image path: \SystemRoot\system32\DRIVERS\rasl2tp.sys
Image name: rasl2tp.sys
Timestamp: Sat Jan 19 07:37:33 2008 (47919AAD)
CheckSum: 00024247
ImageSize: 00023000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12d8e000 fffffa60`12d9a000 ndistapi (deferred)
Image path: \SystemRoot\system32\DRIVERS\ndistapi.sys
Image name: ndistapi.sys
Timestamp: Sat Jan 19 07:37:22 2008 (47919AA2)
CheckSum: 0000CA62
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12d9a000 fffffa60`12dcb000 ndiswan (deferred)
Image path: \SystemRoot\system32\DRIVERS\ndiswan.sys
Image name: ndiswan.sys
Timestamp: Sat Jan 19 07:37:33 2008 (47919AAD)
CheckSum: 00032DAB
ImageSize: 00031000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12dcb000 fffffa60`12ddb000 raspppoe (deferred)
Image path: \SystemRoot\system32\DRIVERS\raspppoe.sys
Image name: raspppoe.sys
Timestamp: Sat Jan 19 07:37:30 2008 (47919AAA)
CheckSum: 00011662
ImageSize: 00010000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12ddb000 fffffa60`12df9000 raspptp (deferred)
Image path: \SystemRoot\system32\DRIVERS\raspptp.sys
Image name: raspptp.sys
Timestamp: Sat Jan 19 07:37:34 2008 (47919AAE)
CheckSum: 0001E8BF
ImageSize: 0001E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12e00000 fffffa60`12e9a000 rdpdr (deferred)
Image path: \SystemRoot\system32\DRIVERS\rdpdr.sys
Image name: rdpdr.sys
Timestamp: Sat Jan 19 07:43:38 2008 (47919C1A)
CheckSum: 0005CA26
ImageSize: 0009A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12e9a000 fffffa60`12eac000 termdd (deferred)
Image path: \SystemRoot\system32\DRIVERS\termdd.sys
Image name: termdd.sys
Timestamp: Sat Jan 19 07:42:03 2008 (47919BBB)
CheckSum: 00017FC1
ImageSize: 00012000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12eac000 fffffa60`12ead480 swenum (deferred)
Image path: \SystemRoot\system32\DRIVERS\swenum.sys
Image name: swenum.sys
Timestamp: Thu Nov 02 10:37:33 2006 (4549BC5D)
CheckSum: 0000447A
ImageSize: 00001480
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12eae000 fffffa60`12ee2000 ks (deferred)
Image path: \SystemRoot\system32\DRIVERS\ks.sys
Image name: ks.sys
Timestamp: Sat Jan 19 07:28:24 2008 (47919888)
CheckSum: 0003A13C
ImageSize: 00034000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.0 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ks.sys
OriginalFilename: ks.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Kernel CSA Library
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`12ee2000 fffffa60`12eed000 mssmbios (deferred)
Image path: \SystemRoot\system32\DRIVERS\mssmbios.sys
Image name: mssmbios.sys
Timestamp: Sat Jan 19 07:02:54 2008 (4791928E)
CheckSum: 0000EECB
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12eed000 fffffa60`12efd000 umbus (deferred)
Image path: \SystemRoot\system32\DRIVERS\umbus.sys
Image name: umbus.sys
Timestamp: Sat Jan 19 07:34:16 2008 (479199E8)
CheckSum: 0001333F
ImageSize: 00010000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12efd000 fffffa60`12f44000 usbhub (deferred)
Image path: \SystemRoot\system32\DRIVERS\usbhub.sys
Image name: usbhub.sys
Timestamp: Sat Jan 19 07:34:13 2008 (479199E5)
CheckSum: 00043573
ImageSize: 00047000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f44000 fffffa60`12f4e000 kbdhid (deferred)
Image path: \SystemRoot\system32\DRIVERS\kbdhid.sys
Image name: kbdhid.sys
Timestamp: Sat Jan 19 07:28:10 2008 (4791987A)
CheckSum: 0000B39B
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f4e000 fffffa60`12f71000 vdrv9000 (deferred)
Image path: \SystemRoot\system32\DRIVERS\vdrv9000.sys
Image name: vdrv9000.sys
Timestamp: Tue Mar 17 16:37:09 2009 (49BFC3A5)
CheckSum: 00021273
ImageSize: 00023000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f71000 fffffa60`12f7c000 mouhid (deferred)
Image path: \SystemRoot\system32\DRIVERS\mouhid.sys
Image name: mouhid.sys
Timestamp: Sat Jan 19 07:28:10 2008 (4791987A)
CheckSum: 0000DA7D
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f7c000 fffffa60`12f84000 wacommousefilter (deferred)
Image path: \SystemRoot\system32\DRIVERS\wacommousefilter.sys
Image name: wacommousefilter.sys
Timestamp: Fri Feb 16 19:12:17 2007 (45D5F401)
CheckSum: 00005ACE
ImageSize: 00008000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f84000 fffffa60`12f98000 NDProxy (deferred)
Image path: \SystemRoot\System32\Drivers\NDProxy.SYS
Image name: NDProxy.SYS
Timestamp: Sat Jan 19 07:37:26 2008 (47919AA6)
CheckSum: 0001366B
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12f98000 fffffa60`12fdc000 netbt (deferred)
Image path: \SystemRoot\System32\DRIVERS\netbt.sys
Image name: netbt.sys
Timestamp: Sat Jan 19 07:36:24 2008 (47919A68)
CheckSum: 0003D49E
ImageSize: 00044000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`12fdc000 fffffa60`12ffa000 pacer (deferred)
Image path: \SystemRoot\system32\DRIVERS\pacer.sys
Image name: pacer.sys
Timestamp: Sat Apr 05 03:55:46 2008 (47F6DC22)
CheckSum: 0001C364
ImageSize: 0001E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13a04000 fffffa60`13a84000 ADIHdAud (deferred)
Image path: \SystemRoot\system32\drivers\ADIHdAud.sys
Image name: ADIHdAud.sys
Timestamp: Fri Apr 11 20:37:49 2008 (47FFAFFD)
CheckSum: 00085931
ImageSize: 00080000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13a84000 fffffa60`13abf000 portcls (deferred)
Image path: \SystemRoot\system32\drivers\portcls.sys
Image name: portcls.sys
Timestamp: Sat Jan 19 07:33:58 2008 (479199D6)
CheckSum: 0004398B
ImageSize: 0003B000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.9 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: portcls.sys
OriginalFilename: portcls.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Port Class (Class Driver for Port/Miniport Devices)
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`13abf000 fffffa60`13ae2000 drmk (deferred)
Image path: \SystemRoot\system32\drivers\drmk.sys
Image name: drmk.sys
Timestamp: Sat Jan 19 08:20:04 2008 (4791A4A4)
CheckSum: 00022D56
ImageSize: 00023000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: drmk.sys
OriginalFilename: drmk.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Microsoft Kernel DRM Descrambler Filter
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`13ae2000 fffffa60`13ae7180 ksthunk (deferred)
Image path: \SystemRoot\system32\drivers\ksthunk.sys
Image name: ksthunk.sys
Timestamp: Sat Jan 19 07:28:14 2008 (4791987E)
CheckSum: 0000A913
ImageSize: 00005180
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13ae8000 fffffa60`13af6000 vga (deferred)
Image path: \SystemRoot\System32\drivers\vga.sys
Image name: vga.sys
Timestamp: Sat Jan 19 07:32:21 2008 (47919975)
CheckSum: 00007D47
ImageSize: 0000E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13af6000 fffffa60`13b1b000 VIDEOPRT (deferred)
Image path: \SystemRoot\System32\drivers\VIDEOPRT.SYS
Image name: VIDEOPRT.SYS
Timestamp: Sat Jan 19 07:32:25 2008 (47919979)
CheckSum: 00027AC2
ImageSize: 00025000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.4 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: videoprt.sys
OriginalFilename: videoprt.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Video Port Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`13b1b000 fffffa60`13b26000 Msfs (deferred)
Image path: \SystemRoot\System32\Drivers\Msfs.SYS
Image name: Msfs.SYS
Timestamp: Sat Jan 19 06:53:55 2008 (47919073)
CheckSum: 00008E66
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13b26000 fffffa60`13b37000 Npfs (deferred)
Image path: \SystemRoot\System32\Drivers\Npfs.SYS
Image name: Npfs.SYS
Timestamp: Sat Jan 19 06:53:57 2008 (47919075)
CheckSum: 00019013
ImageSize: 00011000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13b37000 fffffa60`13b40000 rasacd (deferred)
Image path: \SystemRoot\System32\DRIVERS\rasacd.sys
Image name: rasacd.sys
Timestamp: Sat Jan 19 07:37:30 2008 (47919AAA)
CheckSum: 0000DB26
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13b40000 fffffa60`13b5d000 tdx (deferred)
Image path: \SystemRoot\system32\DRIVERS\tdx.sys
Image name: tdx.sys
Timestamp: Sat Jan 19 07:36:53 2008 (47919A85)
CheckSum: 0001DEFA
ImageSize: 0001D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13b5d000 fffffa60`13b78000 smb (deferred)
Image path: \SystemRoot\system32\DRIVERS\smb.sys
Image name: smb.sys
Timestamp: Sat Jan 19 07:36:17 2008 (47919A61)
CheckSum: 000247F0
ImageSize: 0001B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13b78000 fffffa60`13be5000 afd (deferred)
Image path: \SystemRoot\system32\drivers\afd.sys
Image name: afd.sys
Timestamp: Sat Jan 19 07:38:15 2008 (47919AD7)
CheckSum: 000655C3
ImageSize: 0006D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13be5000 fffffa60`13bf4000 netbios (deferred)
Image path: \SystemRoot\system32\DRIVERS\netbios.sys
Image name: netbios.sys
Timestamp: Sat Jan 19 07:36:35 2008 (47919A73)
CheckSum: 00015AAA
ImageSize: 0000F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13c00000 fffffa60`13c09000 rdpencdd (deferred)
Image path: \SystemRoot\system32\drivers\rdpencdd.sys
Image name: rdpencdd.sys
Timestamp: Sat Jan 19 07:42:03 2008 (47919BBB)
CheckSum: 00003BDB
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13c0a000 fffffa60`13d46000 agrsm64 (deferred)
Image path: \SystemRoot\system32\DRIVERS\agrsm64.sys
Image name: agrsm64.sys
Timestamp: Fri Mar 21 17:47:11 2008 (47E3E68F)
CheckSum: 00138E65
ImageSize: 0013C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13d46000 fffffa60`13d55000 modem (deferred)
Image path: \SystemRoot\system32\drivers\modem.sys
Image name: modem.sys
Timestamp: Sat Jan 19 07:38:17 2008 (47919AD9)
CheckSum: 0000D95A
ImageSize: 0000F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13d55000 fffffa60`13d5e000 hidusb (deferred)
Image path: \SystemRoot\system32\DRIVERS\hidusb.sys
Image name: hidusb.sys
Timestamp: Sat Jan 19 07:33:54 2008 (479199D2)
CheckSum: 00004B9C
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13d5e000 fffffa60`13d6c000 BTHUSB (deferred)
Image path: \SystemRoot\System32\Drivers\BTHUSB.sys
Image name: BTHUSB.sys
Timestamp: Tue Apr 29 04:10:51 2008 (481683AB)
CheckSum: 0000C6A3
ImageSize: 0000E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13d6c000 fffffa60`13db5000 bthport (deferred)
Image path: \SystemRoot\System32\Drivers\bthport.sys
Image name: bthport.sys
Timestamp: Tue Apr 29 04:10:55 2008 (481683AF)
CheckSum: 0004BA0D
ImageSize: 00049000
File version: 6.0.6001.18064
Product version: 6.0.6001.18064
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: bthport.sys
OriginalFilename: bthport.sys
ProductVersion: 6.0.6001.18064
FileVersion: 6.0.6001.18064 (vistasp1_gdr.080428-1527)
FileDescription: Bluetooth Bus Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`13db5000 fffffa60`13dc1000 BthEnum (deferred)
Image path: \SystemRoot\system32\DRIVERS\BthEnum.sys
Image name: BthEnum.sys
Timestamp: Sat Jan 19 07:34:12 2008 (479199E4)
CheckSum: 000135A8
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13dc1000 fffffa60`13de0000 bthpan (deferred)
Image path: \SystemRoot\system32\DRIVERS\bthpan.sys
Image name: bthpan.sys
Timestamp: Sat Jan 19 07:34:19 2008 (479199EB)
CheckSum: 00022B90
ImageSize: 0001F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13de0000 fffffa60`13dea000 Fs_Rec (deferred)
Image path: \SystemRoot\System32\Drivers\Fs_Rec.SYS
Image name: Fs_Rec.SYS
Timestamp: Sat Jan 19 06:53:41 2008 (47919065)
CheckSum: 0000F90C
ImageSize: 0000A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13dea000 fffffa60`13df3000 Null (deferred)
Image path: \SystemRoot\System32\Drivers\Null.SYS
Image name: Null.SYS
Timestamp: Thu Nov 02 10:37:15 2006 (4549BC4B)
CheckSum: 0000B49D
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13df3000 fffffa60`13dfc000 RDPCDD (deferred)
Image path: \SystemRoot\System32\DRIVERS\RDPCDD.sys
Image name: RDPCDD.sys
Timestamp: Sat Jan 19 07:42:04 2008 (47919BBC)
CheckSum: 0000B335
ImageSize: 00009000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`13e02000 fffffa60`13fca480 snp2uvc (deferred)
Image path: \SystemRoot\system32\DRIVERS\snp2uvc.sys
Image name: snp2uvc.sys
Timestamp: Wed Oct 08 08:14:20 2008 (48EC4FBC)
CheckSum: 001C9F36
ImageSize: 001C8480
File version: 5.8.39008.0
Product version: 5.8.39008.0
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 3.0 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: © Microsoft Corporation. All rights reserved俘ﻖ߾
ProductName: HP Webcam
InternalName: HP Webcam
OriginalFilename: HP Webcam
ProductVersion: 5, 8, 39008, 0
FileVersion: 5, 8, 39008, 0
PrivateBuild: No I420, v2.0.0.2
SpecialBuild: Pure Version
FileDescription: UVC Camera Streaming Driver
LegalCopyright: Copyright 2004-2007
LegalTrademarks: Copyright 2004-2007
Comments: Copyright 2004-2007
fffffa60`13fcb000 fffffa60`13fdba80 STREAM (deferred)
Image path: \SystemRoot\system32\DRIVERS\STREAM.SYS
Image name: STREAM.SYS
Timestamp: Sat Jan 19 07:33:51 2008 (479199CF)
CheckSum: 0001D265
ImageSize: 00010A80
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: stream.sys
OriginalFilename: stream.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: WDM CODEC Class Device Driver 2.0
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`13fdc000 fffffa60`13fe4980 sncduvc (deferred)
Image path: \SystemRoot\system32\DRIVERS\sncduvc.SYS
Image name: sncduvc.SYS
Timestamp: Wed May 09 09:17:09 2007 (46417575)
CheckSum: 00018A43
ImageSize: 00008980
File version: 1.1.7.0
Product version: 1.1.7.0
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: © Microsoft Corporation. All rights reserved俘ﻖ߾
ProductName: USBCAMD for Sonix UVC
InternalName: USBCAMD for Sonix UVC
OriginalFilename: USBCAMD for Sonix UVC
ProductVersion: 1.1.7.0
FileVersion: 1.1.7.0
PrivateBuild: 1.1.7.0
SpecialBuild: 1.1.7.0
FileDescription: USBCAMD for Sonix UVC
LegalCopyright: Copyright 2004-2007
LegalTrademarks: Copyright 2004-2007
Comments: Copyright 2004-2007
fffffa60`13fe5000 fffffa60`13ff9000 rfcomm (deferred)
Image path: \SystemRoot\system32\DRIVERS\rfcomm.sys
Image name: rfcomm.sys
Timestamp: Sat Jan 19 07:34:13 2008 (479199E5)
CheckSum: 000166B4
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`14001000 fffffa60`1404f000 rdbss (deferred)
Image path: \SystemRoot\system32\DRIVERS\rdbss.sys
Image name: rdbss.sys
Timestamp: Sat Jan 19 06:55:09 2008 (479190BD)
CheckSum: 0004C836
ImageSize: 0004E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`1404f000 fffffa60`1405b000 nsiproxy (deferred)
Image path: \SystemRoot\system32\drivers\nsiproxy.sys
Image name: nsiproxy.sys
Timestamp: Sat Jan 19 07:36:45 2008 (47919A7D)
CheckSum: 00013617
ImageSize: 0000C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`1405b000 fffffa60`140d1000 csc (deferred)
Image path: \SystemRoot\system32\drivers\csc.sys
Image name: csc.sys
Timestamp: Sat Jan 19 06:55:39 2008 (479190DB)
CheckSum: 000747A5
ImageSize: 00076000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`140d1000 fffffa60`140ee000 dfsc (deferred)
Image path: \SystemRoot\System32\Drivers\dfsc.sys
Image name: dfsc.sys
Timestamp: Sat Jan 19 06:54:16 2008 (47919088)
CheckSum: 00020190
ImageSize: 0001D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`140ee000 fffffa60`1413c000 udfs (deferred)
Image path: \SystemRoot\system32\DRIVERS\udfs.sys
Image name: udfs.sys
Timestamp: Sat Jan 19 06:53:53 2008 (47919071)
CheckSum: 000550F3
ImageSize: 0004E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`1413c000 fffffa60`1414a000 crashdmp (deferred)
Image path: \SystemRoot\System32\Drivers\crashdmp.sys
Image name: crashdmp.sys
Timestamp: Sat Jan 19 07:28:59 2008 (479198AB)
CheckSum: 0001572C
ImageSize: 0000E000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: crashdmp.sys
OriginalFilename: crashdmp.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Crash Dump Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`1414a000 fffffa60`14156000 dump_dumpata (deferred)
Image path: \SystemRoot\System32\Drivers\dump_dumpata.sys
Image name: dump_dumpata.sys
Timestamp: Sat Jan 19 07:28:54 2008 (479198A6)
CheckSum: 000141AC
ImageSize: 0000C000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: dumpata.sys
OriginalFilename: dumpata.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: ATAPI Dump Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`14156000 fffffa60`14160000 dump_msahci (deferred)
Image path: \SystemRoot\System32\Drivers\dump_msahci.sys
Image name: dump_msahci.sys
Timestamp: Sat Jan 19 07:28:58 2008 (479198AA)
CheckSum: 00010AEA
ImageSize: 0000A000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: msahci.sys
OriginalFilename: msahci.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: MS AHCI 1.0 Standard Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`14160000 fffffa60`14173000 dump_dumpfve (deferred)
Image path: \SystemRoot\System32\Drivers\dump_dumpfve.sys
Image name: dump_dumpfve.sys
Timestamp: Sat Jan 19 06:52:25 2008 (47919019)
CheckSum: 00019561
ImageSize: 00013000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: dumpfve.sys
OriginalFilename: dumpfve.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: Bitlocker Drive Encryption Crashdump Filter
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`14173000 fffffa60`1417f000 Dxapi (deferred)
Image path: \SystemRoot\System32\drivers\Dxapi.sys
Image name: Dxapi.sys
Timestamp: Sat Jan 19 07:08:00 2008 (479193C0)
CheckSum: 00007785
ImageSize: 0000C000
File version: 6.0.6001.18000
Product version: 6.0.6001.18000
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: dxapi.sys
OriginalFilename: dxapi.sys
ProductVersion: 6.0.6001.18000
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
FileDescription: DirectX API Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`1417f000 fffffa60`14192000 monitor (deferred)
Image path: \SystemRoot\system32\DRIVERS\monitor.sys
Image name: monitor.sys
Timestamp: Sat Jan 19 07:32:34 2008 (47919982)
CheckSum: 0001BE53
ImageSize: 00013000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`14192000 fffffa60`141b4000 luafv (deferred)
Image path: \SystemRoot\system32\drivers\luafv.sys
Image name: luafv.sys
Timestamp: Sat Jan 19 06:59:06 2008 (479191AA)
CheckSum: 0001E74E
ImageSize: 00022000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`141b4000 fffffa60`141cf000 avgntflt (deferred)
Image path: \SystemRoot\system32\DRIVERS\avgntflt.sys
Image name: avgntflt.sys
Timestamp: Fri Nov 20 10:12:33 2009 (4B065D81)
CheckSum: 0001995F
ImageSize: 0001B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`141cf000 fffffa60`141e9000 mpsdrv (deferred)
Image path: \SystemRoot\System32\drivers\mpsdrv.sys
Image name: mpsdrv.sys
Timestamp: Sat Jan 19 07:35:28 2008 (47919A30)
CheckSum: 000167F0
ImageSize: 0001A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`1560e000 fffffa60`156a8000 spsys (deferred)
Image path: \SystemRoot\system32\drivers\spsys.sys
Image name: spsys.sys
Timestamp: Fri Jun 22 03:02:05 2007 (467B1F8D)
CheckSum: 00090ABB
ImageSize: 0009A000
File version: 6.0.6001.16606
Product version: 6.0.6001.16606
File flags: 8 (Mask 3F) Private
File OS: 40004 NT Win32
File type: 3.0 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: spsys.sys
OriginalFilename: spsys.sys
ProductVersion: 6.0.6001.16606
FileVersion: 6.0.6001.16606 (lh_security(sepbld-s).070621-1658)
FileDescription: security processor
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`156a8000 fffffa60`156bc000 lltdio (deferred)
Image path: \SystemRoot\system32\DRIVERS\lltdio.sys
Image name: lltdio.sys
Timestamp: Sat Jan 19 07:35:48 2008 (47919A44)
CheckSum: 000186DE
ImageSize: 00014000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`156bc000 fffffa60`156f0000 nwifi (deferred)
Image path: \SystemRoot\system32\DRIVERS\nwifi.sys
Image name: nwifi.sys
Timestamp: Tue May 20 04:33:46 2008 (4832388A)
CheckSum: 00037518
ImageSize: 00034000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`156f0000 fffffa60`156fb000 ndisuio (deferred)
Image path: \SystemRoot\system32\DRIVERS\ndisuio.sys
Image name: ndisuio.sys
Timestamp: Sat Jan 19 07:36:29 2008 (47919A6D)
CheckSum: 0001472B
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`156fb000 fffffa60`15713000 rspndr (deferred)
Image path: \SystemRoot\system32\DRIVERS\rspndr.sys
Image name: rspndr.sys
Timestamp: Sat Jan 19 07:35:48 2008 (47919A44)
CheckSum: 000132AD
ImageSize: 00018000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15713000 fffffa60`157b2000 HTTP (deferred)
Image path: \SystemRoot\system32\drivers\HTTP.sys
Image name: HTTP.sys
Timestamp: Mon Nov 09 12:31:49 2009 (4AF7FDA5)
CheckSum: 000981F5
ImageSize: 0009F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`157b2000 fffffa60`157da000 srvnet (deferred)
Image path: \SystemRoot\System32\DRIVERS\srvnet.sys
Image name: srvnet.sys
Timestamp: Sat Jan 19 06:56:38 2008 (47919116)
CheckSum: 00029BCB
ImageSize: 00028000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`157da000 fffffa60`157f8000 bowser (deferred)
Image path: \SystemRoot\system32\DRIVERS\bowser.sys
Image name: bowser.sys
Timestamp: Sat Jan 19 06:54:51 2008 (479190AB)
CheckSum: 00021CAB
ImageSize: 0001E000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15e00000 fffffa60`15e28000 mrxsmb (deferred)
Image path: \SystemRoot\system32\DRIVERS\mrxsmb.sys
Image name: mrxsmb.sys
Timestamp: Sat Jan 19 06:55:21 2008 (479190C9)
CheckSum: 0002781F
ImageSize: 00028000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15e28000 fffffa60`15e71000 mrxsmb10 (deferred)
Image path: \SystemRoot\system32\DRIVERS\mrxsmb10.sys
Image name: mrxsmb10.sys
Timestamp: Wed Aug 27 03:26:08 2008 (48B4AD30)
CheckSum: 0005060C
ImageSize: 00049000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15e71000 fffffa60`15e90000 mrxsmb20 (deferred)
Image path: \SystemRoot\system32\DRIVERS\mrxsmb20.sys
Image name: mrxsmb20.sys
Timestamp: Sat Jan 19 06:55:19 2008 (479190C7)
CheckSum: 00024B87
ImageSize: 0001F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15e90000 fffffa60`15ec2000 srv2 (deferred)
Image path: \SystemRoot\System32\DRIVERS\srv2.sys
Image name: srv2.sys
Timestamp: Mon Sep 14 12:00:18 2009 (4AAE1432)
CheckSum: 00030B51
ImageSize: 00032000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`15ec2000 fffffa60`15f56000 srv (deferred)
Image path: \SystemRoot\System32\DRIVERS\srv.sys
Image name: srv.sys
Timestamp: Tue Dec 16 04:42:00 2008 (49472388)
CheckSum: 0007C3C2
ImageSize: 00094000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`16208000 fffffa60`162be000 peauth (deferred)
Image path: \SystemRoot\system32\drivers\peauth.sys
Image name: peauth.sys
Timestamp: Mon Oct 23 13:57:00 2006 (453CAE0C)
CheckSum: 000AE0B2
ImageSize: 000B6000
File version: 6.0.5840.16385
Product version: 6.0.5840.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: PEAuth.sys
OriginalFilename: PEAuth.sys
ProductVersion: 6.0.5840.16385
FileVersion: 6.0.5840.16385 (VISTA_RTM_CLIENT_akaDMD.061022-1800)
FileDescription: Protected Environment Authentication and Authorization Export Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
fffffa60`162be000 fffffa60`162c9000 secdrv (deferred)
Image path: \SystemRoot\System32\Drivers\secdrv.SYS
Image name: secdrv.SYS
Timestamp: Wed Sep 13 15:18:38 2006 (4508052E)
CheckSum: 00010B40
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`162c9000 fffffa60`162d8000 tcpipreg (deferred)
Image path: \SystemRoot\System32\drivers\tcpipreg.sys
Image name: tcpipreg.sys
Timestamp: Sat Jan 19 07:37:01 2008 (47919A8D)
CheckSum: 000099A4
ImageSize: 0000F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
fffffa60`162d8000 fffffa60`162f4000 cdfs (deferred)
Image path: \SystemRoot\system32\DRIVERS\cdfs.sys
Image name: cdfs.sys
Timestamp: Sat Jan 19 06:53:45 2008 (47919069)
CheckSum: 0001CCC4
ImageSize: 0001C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4

Unloaded modules:
fffffa60`00fe4000 fffffa60`00ff2000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffffa60`00ff2000 fffffa60`00ffe000 dump_pciidex.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffffa60`00d6a000 fffffa60`00d74000 dump_msahci.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffffa60`00d74000 fffffa60`00d87000 dump_dumpfve.sys
Timestamp: unavailable (00000000)
Checksum: 00000000

Was ich daraus Erkennen konnte war das er Anscheinend Probleme mit der
ntkrnlmp.exe hat (irgend ein Treiber oder so).Meine Frage was ist das für ein Treiber und wie kann ich den fixen?

Danke für jede hilfe.
 
Das hört sich nach einem defekten Speicherbaustein an. Teste, wenn mehrere Riegekl vorhanden sind einen nach dem anderen durch.

Ebenfalls häufig, allerdings mehr von XP bekannt, ist ein Problem mit dem Powermanagement vor allem im Standby Modus. Auch verschiedene USB Geräte können zu diesem Fehler führen. In den meisten Fällen aber ist der Schuldige, leider, ein defekter RAM Baustein.
 
S.o.

einfach einen Rausnehmen, ausprobieren.
einfach nach testen des ersten anderen reintun ausprobieren.
Oder einfach mal bei starten gucken ob dein Mainboard 4096MB Ram anzeigt;)
 
Ich glaub das macht nur irgendwelche vergleiche es hat mir zumindest kein Fehler angezeigt und ich konnte auch nicht erkennen das er nach sowas gesucht hat.

Ihmo funktioniert ja alles bis auf das ich kein kompletten Systemcheck mit Avira machen kann. Eine halbe stunde hängt er bei 2.6% fest und denn kommt die Meldung Fehler Sicherheitsoptionen Dialogfeld. Drücke ich ok (wenigstes kein reset zwang mehr)Schalltet sich avira Inaktiv und ich kann es erst nach Neustart wieder Aktivieren. o_O

Edit: Als ich den Vorgang wiederholt habe Kam wieder ein Bluescreen Absturz danach habe ich die im Fehler angegebene minidump Datei Ausgelesen

Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\Mini021210-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0xfffff800`0265f000 PsLoadedModuleList = 0xfffff800`02823dd0
Debug session time: Fri Feb 12 18:03:04.947 2010 (GMT+1)
System Uptime: 0 days 0:40:11.788
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 7A, {fffff88009d4ca80, ffffffffc0000185, 2156a860, fffff960001c7dd0}

Unable to load image \SystemRoot\System32\win32k.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Probably caused by : win32k.sys ( win32k+147dd0 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KERNEL_DATA_INPAGE_ERROR (7a)
The requested page of kernel data could not be read in. Typically caused by
a bad block in the paging file or disk controller error. Also see
KERNEL_STACK_INPAGE_ERROR.
If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
it means the disk subsystem has experienced a failure.
If the error status is 0xC000009A, then it means the request failed because
a filesystem failed to make forward progress.
Arguments:
Arg1: fffff88009d4ca80, lock type that was held (value 1,2,3, or PTE address)
Arg2: ffffffffc0000185, error status (normally i/o status code)
Arg3: 000000002156a860, current process (virtual address for lock type 3, or PTE)
Arg4: fffff960001c7dd0, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************

ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: win32k

FAULTING_MODULE: fffff8000265f000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 0

ERROR_CODE: (NTSTATUS) 0xc0000185 - Das E/A-Ger t hat einen E/A-Fehler gemeldet.

DISK_HARDWARE_ERROR: There was error with disk hardware

BUGCHECK_STR: 0x7a_c0000185

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff800026734b4 to fffff800026b9450

STACK_TEXT:
fffffa60`14cee748 fffff800`026734b4 : 00000000`0000007a fffff880`09d4ca80 ffffffff`c0000185 00000000`2156a860 : nt+0x5a450
fffffa60`14cee750 00000000`0000007a : fffff880`09d4ca80 ffffffff`c0000185 00000000`2156a860 fffff960`001c7dd0 : nt+0x144b4
fffffa60`14cee758 fffff880`09d4ca80 : ffffffff`c0000185 00000000`2156a860 fffff960`001c7dd0 00000000`00000043 : 0x7a
fffffa60`14cee760 ffffffff`c0000185 : 00000000`2156a860 fffff960`001c7dd0 00000000`00000043 00000000`c0000185 : 0xfffff880`09d4ca80
fffffa60`14cee768 00000000`2156a860 : fffff960`001c7dd0 00000000`00000043 00000000`c0000185 fffffa80`049aab40 : 0xffffffff`c0000185
fffffa60`14cee770 fffff960`001c7dd0 : 00000000`00000043 00000000`c0000185 fffffa80`049aab40 fffff960`001c7dd0 : 0x2156a860
fffffa60`14cee778 00000000`00000043 : 00000000`c0000185 fffffa80`049aab40 fffff960`001c7dd0 fffffa80`049aab40 : win32k+0x147dd0
fffffa60`14cee780 00000000`c0000185 : fffffa80`049aab40 fffff960`001c7dd0 fffffa80`049aab40 fffffa80`09c05060 : 0x43
fffffa60`14cee788 fffffa80`049aab40 : fffff960`001c7dd0 fffffa80`049aab40 fffffa80`09c05060 fffff880`09d4ca80 : 0xc0000185
fffffa60`14cee790 fffff960`001c7dd0 : fffffa80`049aab40 fffffa80`09c05060 fffff880`09d4ca80 fffffa80`006403e0 : 0xfffffa80`049aab40
fffffa60`14cee798 fffffa80`049aab40 : fffffa80`09c05060 fffff880`09d4ca80 fffffa80`006403e0 00000000`00000204 : win32k+0x147dd0
fffffa60`14cee7a0 fffffa80`09c05060 : fffff880`09d4ca80 fffffa80`006403e0 00000000`00000204 fffffa80`04e871d0 : 0xfffffa80`049aab40
fffffa60`14cee7a8 fffff880`09d4ca80 : fffffa80`006403e0 00000000`00000204 fffffa80`04e871d0 fffff960`001c7dd0 : 0xfffffa80`09c05060
fffffa60`14cee7b0 fffffa80`006403e0 : 00000000`00000204 fffffa80`04e871d0 fffff960`001c7dd0 fffff880`09d4ca80 : 0xfffff880`09d4ca80
fffffa60`14cee7b8 00000000`00000204 : fffffa80`04e871d0 fffff960`001c7dd0 fffff880`09d4ca80 fffff880`09d4ca80 : 0xfffffa80`006403e0
fffffa60`14cee7c0 fffffa80`04e871d0 : fffff960`001c7dd0 fffff880`09d4ca80 fffff880`09d4ca80 fffffa80`09998b20 : 0x204
fffffa60`14cee7c8 fffff960`001c7dd0 : fffff880`09d4ca80 fffff880`09d4ca80 fffffa80`09998b20 ffffffff`ffffffff : 0xfffffa80`04e871d0
fffffa60`14cee7d0 fffff880`09d4ca80 : fffff880`09d4ca80 fffffa80`09998b20 ffffffff`ffffffff fffff6fc`b0000e38 : win32k+0x147dd0
fffffa60`14cee7d8 fffff880`09d4ca80 : fffffa80`09998b20 ffffffff`ffffffff fffff6fc`b0000e38 fffffa60`13ab3c00 : 0xfffff880`09d4ca80
fffffa60`14cee7e0 fffffa80`09998b20 : ffffffff`ffffffff fffff6fc`b0000e38 fffffa60`13ab3c00 fffffa80`049aaa50 : 0xfffff880`09d4ca80
fffffa60`14cee7e8 ffffffff`ffffffff : fffff6fc`b0000e38 fffffa60`13ab3c00 fffffa80`049aaa50 fffff800`026d2901 : 0xfffffa80`09998b20
fffffa60`14cee7f0 fffff6fc`b0000e38 : fffffa60`13ab3c00 fffffa80`049aaa50 fffff800`026d2901 fffffa80`049aaa50 : 0xffffffff`ffffffff
fffffa60`14cee7f8 fffffa60`13ab3c00 : fffffa80`049aaa50 fffff800`026d2901 fffffa80`049aaa50 fffffa60`14cee890 : 0xfffff6fc`b0000e38
fffffa60`14cee800 fffffa80`049aaa50 : fffff800`026d2901 fffffa80`049aaa50 fffffa60`14cee890 fffffa60`13ab3c00 : 0xfffffa60`13ab3c00
fffffa60`14cee808 fffff800`026d2901 : fffffa80`049aaa50 fffffa60`14cee890 fffffa60`13ab3c00 fffffa60`13ab3c00 : 0xfffffa80`049aaa50
fffffa60`14cee810 fffffa80`049aaa50 : fffffa60`14cee890 fffffa60`13ab3c00 fffffa60`13ab3c00 fffffa80`049aaaa0 : nt+0x73901
fffffa60`14cee818 fffffa60`14cee890 : fffffa60`13ab3c00 fffffa60`13ab3c00 fffffa80`049aaaa0 fffffa80`09c05060 : 0xfffffa80`049aaa50
fffffa60`14cee820 fffffa60`13ab3c00 : fffffa60`13ab3c00 fffffa80`049aaaa0 fffffa80`09c05060 fffffa60`14ceea50 : 0xfffffa60`14cee890
fffffa60`14cee828 fffffa60`13ab3c00 : fffffa80`049aaaa0 fffffa80`09c05060 fffffa60`14ceea50 fffffa60`14cee858 : 0xfffffa60`13ab3c00
fffffa60`14cee830 fffffa80`049aaaa0 : fffffa80`09c05060 fffffa60`14ceea50 fffffa60`14cee858 fffffa80`03cbf080 : 0xfffffa60`13ab3c00
fffffa60`14cee838 fffffa80`09c05060 : fffffa60`14ceea50 fffffa60`14cee858 fffffa80`03cbf080 fffffa80`049aaa50 : 0xfffffa80`049aaaa0
fffffa60`14cee840 fffffa60`14ceea50 : fffffa60`14cee858 fffffa80`03cbf080 fffffa80`049aaa50 00000000`00000000 : 0xfffffa80`09c05060
fffffa60`14cee848 fffffa60`14cee858 : fffffa80`03cbf080 fffffa80`049aaa50 00000000`00000000 00000000`00000000 : 0xfffffa60`14ceea50
fffffa60`14cee850 fffffa80`03cbf080 : fffffa80`049aaa50 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa60`14cee858
fffffa60`14cee858 fffffa80`049aaa50 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa60`14ceea50 : 0xfffffa80`03cbf080
fffffa60`14cee860 00000000`00000000 : 00000000`00000000 00000000`00000000 fffffa60`14ceea50 00000000`00000000 : 0xfffffa80`049aaa50


STACK_COMMAND: kb

FOLLOWUP_IP:
win32k+147dd0
fffff960`001c7dd0 ?? ???

SYMBOL_STACK_INDEX: 6

SYMBOL_NAME: win32k+147dd0

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: win32k.sys

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

da wird diesmal die win32k.sys angegeben

Iwie passiert das immer wenn Avira in meinem Adobe CS3 Rumsucht. Werde das Progi ma Deinstallieren und gucken was bei raus kommt.
 
Zuletzt bearbeitet:
Ich würde dir mal empfehlen dir die Ultimate Boot CD runterzuladen und dann mal mit den Programmen die da drauf sind deinen Arbeitsspeicher und deine Festplatte zu überprüfen.

Edit: BlueScreenView ist auch ganz nützlich, das wertet die Dumpfiles aus und zeigt dir direkt an welche Dateien bzw. Dlls ärger machen.
 
Zuletzt bearbeitet:
  • Like
Reaktionen: Orios das Auge