Event viewer says "The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xb6a26070, 0x00000001, 0x804da12e, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP."
Main Topics
Browse All TopicsBSOD "page fault in nonpaged area" on a Toshiba G30 laptop with 1G ram. XP SP2. Event viewer says "The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xb6a26070, 0x00000001, 0x804da12e, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP." Can't get any further than safe mode. No new hardware / software etc. Please help asap.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
have a look in this : http://www.techspot.com/vb
Take a look in the red line and try the solution:
http://support.microsoft.c
Hope this help ....
Hi,
If you have access to another pc to download a file.
Try running this tool in safe mode.
Download SDFix and save it to your desktop.
http://downloads.andymanch
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
Or, this one maybe, or a Hijackthis log
Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforu
http://download.bleepingco
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Please upload that dmp file to www.ee-stuff.com for us to analyze
Regards
Sometimes the error you describe is related to the swap file (page file). One possible test as part of the troubleshooting, is to remove the swap file and then re-create one, using a (not too big) fixed size for it. That will probably cause it to use other parts of disk surface and it may help. A thorough hard drive test, as suggested already, is of course of the essence. Chkdsk is not the right tool for this; AFAIK. It checks the file system but not the surface, I think.
/RID
A hard drive test is normally done with the use of a bootable media and each HD manufacturer will probably have a utility for download - for free. The "Ultimate Boot CD" incorporates several tools for testing HDs. That's a bootable CD that you make yourself after downloading (for free) an image file (.iso); see this site: http://www.ultimatebootcd.
/RID
http://www.hitachigst.com/
http://www.maxtor.com/en/s
http://www.fcpa.fujitsu.co
http://www.samsung.com/Pro
http://www.seagate.com/sup
http://support.wdc.com/dow
http://www.hgst.com/hdd/su
You can have a try for that software provided by the manufacturer (base on your HD manufacturer) .... hope that help ...... And make sure you backup those important files before you test it out.
Is that all? that doesn't seem right, even if it didn't find anything that report is awfully short and looks incomplete, :)
You've ruled-out hardware/software or driver issues?
Can you try and run another tool?
Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforu
http://download.bleepingco
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:18:27 a.m., on 7/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
C:\WINDOWS\system32\ctfmon
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepa
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-2
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-7
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-2
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.ex
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THot
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\Touc
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Kraidman] C:\Program Files\TOSHIBA\TOSHIBA RAID\Console\Kraidman.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\Z
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\i
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKLM\..\RunOnce: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\tos
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcg
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\C
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAM
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\E
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: TOSHIBA RAID Service (kraidsvc) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\kraidsvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\R
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServi
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
combofix
ComboFix 07-08-04.3 - "Rod" 2007-08-07 8:04:35.1 [GMT 12:00] - NTFS [SAFE MODE]
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.
((((((((((((((((((((((((( Files Created from 2007-07-06 to 2007-08-06 ))))))))))))))))))))))))))
2007-08-07 08:04 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-06 15:20 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-03 08:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI
2007-08-03 08:06 <DIR> d-------- C:\Program Files\VideoCAM Eye
2007-08-03 08:06 <DIR> d-------- C:\Program Files\Common Files\VCAMEye
2007-08-03 08:04 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-08-02 14:18 <DIR> d--hs---- C:\WINDOWS\CSC
2007-08-01 17:00 7,077,888 --a------ C:\DOCUME~1\Rod\ntuser.dat
2007-07-31 15:15 <DIR> d-------- C:\Program Files\iTunes
2007-07-31 15:13 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-31 15:07 <DIR> d-------- C:\Program Files\QuickTime
2007-07-12 22:08 98,304 --a------ C:\WINDOWS\system32\rsnpst
2007-07-12 22:08 61,440 --a------ C:\WINDOWS\system32\csnpst
2007-07-12 22:08 53,248 --a------ C:\WINDOWS\system32\dsnpst
2007-07-12 22:08 390,912 --a------ C:\WINDOWS\system32\driver
2007-07-12 22:08 36,864 --a------ C:\WINDOWS\system32\vsnpst
2007-07-12 22:08 286,720 --a------ C:\WINDOWS\vsnpstd.exe
2007-07-12 22:08 <DIR> d-------- C:\WINDOWS\Album
2007-07-08 03:09 1,100 --a------ C:\WINDOWS\system32\d3d8ca
((((((((((((((((((((((((((
2007-08-07 00:14 --------- d-------- C:\DOCUME~1\Rod\SendTo\APP
2007-08-04 00:27 --------- d-------- C:\Program Files\e-Sword
2007-08-03 08:06 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-31 19:33 --------- d-------- C:\DOCUME~1\Rod\SendTo\APP
2007-07-31 15:15 --------- d-------- C:\Program Files\iPod
2007-07-26 20:20 --------- d-------- C:\DOCUME~1\Rod\SendTo\APP
2007-07-17 11:13 --------- d-------- C:\Program Files\Norton Internet Security
2007-07-13 11:13 43520 --a------ C:\WINDOWS\system32\CmdLin
2007-07-12 22:08 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-05 15:41 --------- d-------- C:\Program Files\EA GAMES
2007-06-18 00:40 4581246 --a------ C:\WINDOWS\Screensaver-Sli
2007-06-17 14:36 --------- d-------- C:\Program Files\Smart PDF Converter
2007-06-16 15:20 --------- d-------- C:\DOCUME~1\Rod\SendTo\APP
2007-06-16 14:05 --------- d-------- C:\Program Files\SolidDocuments
2007-06-16 01:08 --------- d-------- C:\Program Files\VeryPDF PDF2Word v3.0
2007-06-13 11:36 --------- d-------- C:\Program Files\FLVPlayer
2007-06-13 11:30 --------- d-------- C:\Program Files\FLV Player
2007-05-17 03:12 86528 -----c--- C:\WINDOWS\system32\dllcac
2007-05-17 03:12 85504 -----c--- C:\WINDOWS\system32\dllcac
2007-05-17 03:12 683520 --a------ C:\WINDOWS\system32\inetco
2007-05-17 03:12 683520 -----c--- C:\WINDOWS\system32\dllcac
2007-05-17 03:12 510976 -----c--- C:\WINDOWS\system32\dllcac
2007-05-17 03:12 1314816 -----c--- C:\WINDOWS\system32\dllcac
2006-08-02 14:25 2327233 --a------ C:\Program Files\audacity-win-1.2.4b.
2006-05-26 20:22 45511810 --a------ C:\Program Files\NIS06910AP_2YR.exe
2006-05-12 00:01 2719485 --a------ C:\Program Files\amp.exe
2003-07-25 11:38 132096 --a------ C:\Program Files\Common Files\PCSBoff.exe
((((((((((((((((((((((((((
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA
"ehTray"="C:\WINDOWS\ehome
"00THotkey"="C:\WINDOWS\sy
"000StTHK"="000StTHK.exe" [2001-06-24 00:28 C:\WINDOWS\system32\000StT
"TFNF5"="TFNF5.exe" [2005-12-09 13:36 C:\WINDOWS\system32\TFNF5.
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 12:13]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\Touc
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2005-05-18 07:42]
"NDSTray.exe"="NDSTray.exe
"TPSMain"="TPSMain.exe" [2005-12-06 20:25 C:\WINDOWS\system32\TPSMai
"TPSODDCtl"="TPSODDCtl.exe
"TFncKy"="TFncKy.exe" []
"Kraidman"="C:\Program Files\TOSHIBA\TOSHIBA RAID\Console\Kraidman.exe"
"DLA"="C:\WINDOWS\System32
"PSQLLauncher"="C:\Program
"NvCplDaemon"="C:\WINDOWS\
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynT
"IntelZeroConfig"="C:\Prog
"IntelWireless"="C:\Progra
"NeroFilterCheck"="C:\WIND
"Synchronization Manager"="C:\WINDOWS\syste
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\reals
"Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 06:29 C:\WINDOWS\agrsmmsg.exe]
"SigmatelSysTrayApp"="stsy
"McDiags AutoLaunch"="" []
"snpstd"="C:\WINDOWS\vsnps
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe
"iTunesHelper"="C:\Program
"SDFix"="C:\SDFix\RunThis.
[HKEY_CURRENT_USER\SOFTWAR
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\tos
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe
"Skype"="C:\Program Files\Skype\Phone\Skype.ex
"swg"="C:\Program Files\Google\GoogleToolbar
"ctfmon.exe"="C:\WINDOWS\s
[HKEY_LOCAL_MACHINE\softwa
"SDFix"=C:\SDFix\RunThis.b
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Ad
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-12-08 10:01:32]
RAMASST.lnk - C:\WINDOWS\system32\RAMASS
[HKEY_LOCAL_MACHINE\softwa
"InstallVisualStyle"=C:\WI
"InstallTheme"=C:\WINDOWS\
[HKEY_LOCAL_MACHINE\softwa
psqlpwd.dll 2005-12-22 17:42 40448 C:\WINDOWS\system32\psqlpw
[HKEY_LOCAL_MACHINE\system
"Notification Packages"= scecli psqlpwd
R0 KR10N;KR10N;C:\WINDOWS\sys
R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\system32\dri
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\system32\dri
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\system32
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32
R0 Vax347b;Vax347b;C:\WINDOWS
R0 Vax347s;Vax347s;C:\WINDOWS
R1 meiudf;meiudf;C:\WINDOWS\s
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver;C:\WINDOWS\system32
R3 Iviaspi;IVI ASPI Shell;C:\WINDOWS\system32\
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32
R3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system3
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver;C:\WINDOWS\system32
S1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\system32\dri
S1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA;C:\WINDOWS\system3
S2 FdRedir;FdRedir;\??\C:\Pro
S2 FileDisk2;FileDisk Protector Kernel Driver;\??\C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys
S2 Netdevio;TOSHIBA Network Device Usermode I/O Protocol;C:\WINDOWS\system
S2 s24trans;WLAN Transport;C:\WINDOWS\syste
S2 smihlp;SMI helper driver;\??\C:\Program Files\Protector Suite QL\smihlp.sys
S2 TOS_SPS;TOSHIBA SPS Driver;\??\C:\Program Files\TOSHIBA\TMP2VDec\TOS
S3 CE3;Xircom Ethernet Adapter 10/100 Service;C:\WINDOWS\system3
S3 E100B;Intel(R) PRO Network Connection Driver;C:\WINDOWS\system32
S3 lredbooo;lredbooo;\??\C:\D
S3 MHN;MHN;C:\WINDOWS\System3
S3 MHNDRV;MHN driver;C:\WINDOWS\system32
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32
S3 sdbus;sdbus;C:\WINDOWS\sys
S3 STHDA;SigmaTel High Definition Audio CODEC;C:\WINDOWS\system32\
S3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32
S3 tifm21;tifm21;C:\WINDOWS\s
S3 toshidpt;TOSHIBA Bluetooth HID port driver;C:\WINDOWS\system32
S3 tosporte;Bluetooth Port Driver from Toshiba;C:\WINDOWS\system3
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA;C:\WINDOWS\system3
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA;C:\WINDOWS\system3
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA;C:\WINDOWS\system3
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA;C:\WINDOWS\system3
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA;C:\WINDOWS\system3
S3 Tosrfusb;Bluetooth USB Controller;C:\WINDOWS\syst
S3 ttv300x;TOSHIBA PCI TV Tuner;C:\WINDOWS\system32\
S3 ttv400x;TOSHIBA PCI DVB-T/Analog Hybrid Tuner;C:\WINDOWS\system32\
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-31 03:03:04 C:\WINDOWS\Tasks\AppleSoft
2007-07-20 09:06:14 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Rod.job - C:\PROGRA~1\NORTON~1\NORTO
**************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 08:07:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWA
"DisplayName"="Alcohol 120"
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
Completion time: 2007-08-07 8:07:35
OK, I'm a bit rabid when it comes to autostarting items, which is what those entries are. My view may not be representative of the normal view among windows users. However, the principle is that you identify the crucial processes (for a laptop, that would in my view include the touchpad driver (SyntpEnh), the wireless driver if you are on wireless network, and the antivirus) and then you delete the rest of the keys.
However, messing with the registry may cause odd effects; if something important is removed from here, some functions you like may disappear. I can't expand on this until later today, so perhaps someone with a more sensible view on autostart may be able to helt you before that.
Cheers
/RID
Pagefault in nonpaged area, means a page fault in memory (RAM). This excludes the harddrive. Spyware or other malware is a possibility. But more ovius it the possibilty of RAM failure. If you have more than one RAM module installed try to remove one and see if the failure is persistant. mIf so try to switch the modules arround. This kind of problem could also come fro a overheating problem try cleaning fans and air outlets of the computer.
Business Accounts
Answer for Membership
by: sparkmakerPosted on 2007-08-04 at 04:09:18ID: 19630521
If you are able to get into safe mode then it is probably a buggy or malicious(read virus or trojan) driver causing the issue.
p.php#0x50
While in safe mode check the event viewer in the control panel-->administrative tools for indications of what may be implicated. Post any recent events marked red, here.
Here are some 0x50 troubleshooting guidelines. http://www.aumha.org/a/sto