Question

Windows XP repeated blue screen

Asked by: Mike_D56

Windows XP continually blue screens with the error message something along the lines of "windows is shutting down to prevent system damage".  It then says, if problem persists remove any new hardware.  This error has just recently cropped up and I have not installed any new hard-ware for a long while, the last such thing being my modem around 3 months ago.  Any help in this matter would be greatly appreciated.  Thanks in adavance.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2003-09-06 at 11:36:00ID20731036
Tags

blue

,

screen

Topic

Windows XP Operating System

Participating Experts
3
Points
0
Comments
28

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. NT freezes at the blue screen with a modem installed
    I just bought a new computer and it came with Windows NT and Win 95 installed on it. It did not come with a modem so I pulled my modem out of my old computer and put it in the new one. The computer also came with a TV card, and when I tried to use the modem in Win 95, it w...
  2. modem
    i have a cpi 14.4 voice modem in canon p133/1.6g/16meg/factory config. the modem recently failed to respond to dial tone & refuses to dial out. i can hear thru sound card if someone is on line and cable/line work ok for separate fax machine.also changed cables. worked ok ...
  3. Modem installing, IRQ issues
    I have a problem installing my modem under Win98. It is being detected, but the system crashes to a blue screen each time I turn it on with the modem "installed". I think it has to do with some IRQ conflicts. I need to know more about IRQs, especially on a PCI bus. ...
  4. Cropping a layer?
    Hi there, Can anybody give me any guidance on how to crop a layer/layers? I know how to crop an image with the crop tool but my image consist of many layers, actually it is 3 linked layers I am concerned about.. They are just a little too big.. So I wanted to crop just thos...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: LeeTutorPosted on 2003-09-06 at 12:14:26ID: 9302268

Was your error message like this:

A problem has been detected and Windows has been shutdown to prevent damage to your computer.

UNMOUNTABLE_BOOT_VOLUME

If this is the first time you've seen this stop error screen,
restart your computer. If this screen appears again, follow
these steps.

Check to make sure any new hardware or software is properly
installed. If this is a new installation, ask your hardware
or software manufacturer for any Windows Updates you might
need.

If problems continue, disable or remove any newly installed
hardware or software. Disable BIOS memory options such as
Caching or Shadowing. If you need to use Safe Mode to remove
or disable components, restart your computer, press F8 to
select Advanced Startup Options, and then select Safe Mode.

Technical information:

*** STOP: 0x000000ED (0x81F59E30,0xC0000032,0x00000000,0x00000000)

If so, then this Microsoft Knowledge Base article applies:

http://support.microsoft.com/default.aspx?scid=kb;en-us;297185
"STOP 0x000000ED UNMOUNTABLE_BOOT_VOLUME" Error Message When You Restart Your Computer or Upgrade to Windows XP


By the way, another MSKB article on STOP 0xED says a corresponding problem was fixed in Service Pack 1.  Have you downloaded SP1 yet?

 

by: Mike_D56Posted on 2003-09-06 at 12:17:52ID: 9302280

No I haven't got SP1 yet.

The error message is similar to the above with exception to "UNMOUNTABLE_BOOT_VOLUME",  it says "DRIVER_IRQL_NOT_LESS_OR_EQUAL" whatever that means...

 

by: LeeTutorPosted on 2003-09-06 at 12:24:20ID: 9302301

All right.  Take a look at this site.  Then in the left pane of the window, search out the STOP error message with a code of D1 and click on that link.  It will take you to several possibly relevant MSKB articles:

http://aumha.org/win5/kbestop.htm

 

by: Mike_D56Posted on 2003-09-06 at 12:29:44ID: 9302307

None of these articles seem relevant.

The blue screen error just happened again, and seems to occur when I try to download large files from KaZaA.  This screen pops up, does something called "Dumping Memory" Then restarts the system.

 

by: LeeTutorPosted on 2003-09-06 at 12:37:22ID: 9302316

Uh, oh, KaZaA.  You can get viruses, trojans, spyware, and all that good stuff by using that.  If you can, try to do the following:

You may have problems with viruses or trojans.  You could try the free online virus tool at http://housecall.antivirus.com    I find that it isn't always able to CURE every virus it detects, but it is good at detecting and identifying them.  

A couple of other free online virus scanners:

http://security2.norton.com/ssc/vc_about.asp?langid=us&venid=sym&plfid=22&pkj=RKNYPJUIYCZRWEJGSSK

http://www.pcpitstop.com/antivirus/default.asp

http://www.pandasoftware.com/activescan/com/activescan_principal.htm

http://download.com.com/3000-2144-10194058.html?tag=lst-0-1

Spybot - Search & Destroy can detect and remove a multitude of adware files and modules from your computer. Spybot can also clean program and Web usage tracks from your system, which is especially useful if you share your computer with other users. Modules chosen for removal can be sent directly to the included file shredder, ensuring complete elimination from your system. And for advanced users, it allows you to fix Registry inconsistencies related to adware or malicious program installations. The handy online update feature ensures that Spybot always has the most current and complete listing of adware, dialers, and other uninvited system residents.
Version 1.2 adds a variety of new and updated features, including an immunization option that allows you to block many spyware downloads before they get to your computer, and improved detection mechanisms for morphing files.

 

by: LeeTutorPosted on 2003-09-06 at 12:39:40ID: 9302323

If you got a Memory Dump, you might be able to troubleshoot using this article:

http://support.microsoft.com/default.aspx?scid=kb;en-us;314084
How to Gather Information After a Memory Dump in Windows XP

 

by: Mike_D56Posted on 2003-09-06 at 12:39:43ID: 9302324

I have Norton installed, I'll run a system check see if it picks anything up. This answer does seem to be feasable, though it will take some time to determine if it does indeed, fix the problem.

 

by: LeeTutorPosted on 2003-09-06 at 12:45:05ID: 9302333

Antivirus programs normally don't check for spyware and some trojans and other malware. I would highly recommend you use SpyBot to see if it can determine any problems.  I use it, as well as LavaSoft's AdAware, on all my Windows systems (I multiboot Win98se, WinME, and WinXP.)

 

by: raju_rangarajanPosted on 2003-09-06 at 13:32:15ID: 9302443

Hi! is your motherboard chipset VIA and processor, AMD?? VIA drivers have the problem . so locate the latest drivers for the chipset and video card from http://viaarena.com/ website.

 

by: raju_rangarajanPosted on 2003-09-06 at 13:37:55ID: 9302459

Also run the signature verification toll to find unsigned drivers on the system. You can refer this link:

http://support.microsoft.com/support/ kb/articles/q308/5/14.asp

After locating the drivers, disable them or update the drivers from your manufacturer's web site.

 

by: Mike_D56Posted on 2003-09-06 at 14:00:22ID: 9302565

I ran a system check and found 2, torjans called VerifierBug but am unsure as to whether these were the source of the problem, I will download the SpyBoy thing and see if this works.  Thanks for your continued help so far.

 

by: gemartiPosted on 2003-09-06 at 14:44:41ID: 9302826

Mike_D56 Comment: >>does something called "Dumping Memory" Then restarts the system

Post that log! It'll give lots of good information.
Small Memory Dump records the smallest amount of information that will help identify the problem. This option requires a paging file of at least 2 MB on the boot volume of your computer and specifies that Windows will create a new file each time the system stops unexpectedly.
A history of these files is stored in the directory listed under Small Dump Directory.


Kernel Memory Dump records only kernel memory, which speeds up the process of recording information in a log when the system stops unexpectedly. Depending on the amount of RAM in your computer, you must have 50 MB to 800 MB available for the paging file on the boot volume.
The file is stored in the directory listed under Dump File.
 
Complete Memory Dump records the entire contents of system memory when the system stops unexpectedly. If you choose this option you must have a paging file on the boot volume large enough to hold all of the physical RAM plus one megabyte (MB). The file is stored in the directory listed under Dump File.

 

by: Mike_D56Posted on 2003-09-07 at 06:21:28ID: 9304644

You couldn't dumb that down a shade could you? My computer knowledge is limited to turning it on and off...

 

by: gemartiPosted on 2003-09-07 at 06:38:02ID: 9304676

:)

So the suggestions above and the clean up of the files you found didn't work?
Look at these instructions.
How to Use Dumpchk.exe to Check a Memory Dump File
http://support.microsoft.com/default.aspx?scid=kb;EN-US;315271

 

by: gemartiPosted on 2003-09-07 at 06:39:39ID: 9304682

Once you have extracted that information post it and we'll go from there. STOP errors can sometimes be very difficult to fix.

 

by: Mike_D56Posted on 2003-09-07 at 13:30:50ID: 9305916

Dumpchk dont appear to work. I followed instruction but it just opens black dos box, then closes it...help?!

 

by: gemartiPosted on 2003-09-07 at 13:53:42ID: 9305976

please post the command you entered with the switches used: i.e.

dumpchk -v c:\windows\minidump\mini122202-01.dmp

Do a search for .dmp files to find the location they are getting dumped to.

 

by: Mike_D56Posted on 2003-09-07 at 15:40:25ID: 9306286

I'm typing this "dumpchk -v D:\WINDOWS\Minidump.Mini080103-01.dmp"  but it still opens and closes too quickly to see the result. I've updated to SP1 too see if this fixes problem now also.

 

by: gemartiPosted on 2003-09-07 at 17:12:23ID: 9306596

Okay. Looks like we need to do some configuring.

START | RUN | SYSDM.CPL
Click the ADVANCED tab
Click the SETTINGS button in the START UP AND RECOVERY panel
You'll see a drop down box beneath the panel title "Write Debugging Information" Select Complete Memory Dump

Now, next time the machine blue screens on you open that file using the command you are using above.

I'm the command requires quotations around the filename at least most command line tools do. Try it both ways.
SO:

C:\>dumpchk -v "c:\windows\minidump\filename.dmp"

 

 

by: Mike_D56Posted on 2003-09-08 at 11:27:23ID: 9311031

Still opening too quickly.  Am I right to think I should be typing these commands in the "Run" box?  It opens and there's a flash of text, followed by a long set of text whizzing by, before it closes.  I'm still having the problem after updating to SP1 and it seems to be linked to downloaded large files with KaZaA.  It Blue Screens, dumps memory then restarts.  I also managed to copy this before it closed, dunno if it's relevant:

alcan5wn.sys - Address FA0F2FD... FA0EC000, Datestamp...

I'll try and get more when it happens next time.

Thanks for your continued help in the matter.

 

by: gemartiPosted on 2003-09-08 at 12:27:06ID: 9311512

No.

START | RUN | CMD

in the command window:

c:\>dumpchck -v "c:\windows\minidump\filename.dmp"

 

by: Mike_D56Posted on 2003-09-08 at 14:28:04ID: 9312528

DUMP_HEADER32:
MajorVersion        0000000f
MinorVersion        00000a28
DirectoryTableBase  00039000
PfnDataBase         81000000
PsLoadedModuleList  80543530
PsActiveProcessHead 80545578
MachineImageType    0000014c
NumberProcessors    00000001
BugCheckCode        000000d1
BugCheckParameter1  ff083000
BugCheckParameter2  00000002
BugCheckParameter3  00000000
BugCheckParameter4  fa0f2f2d
PaeEnabled          00000000
KdDebuggerDataBlock 805353e0

Physical Memory Description:
Number of runs: 3
          FileOffset  Start Address  Length
           00001000     00001000     0009e000
           0009f000     00100000     00eff000
           00f9e000     01000000     0cff0000
Last Page: 0df8d000     0dfef000

KiProcessorBlock at 80542480
  1 KiProcessorBlock entries:
  ffdff120


Windows XP Kernel Version 2600 (Service Pack 1) UP Free x86 compatible
Built by: 2600.xpsp2.030422-1633
Kernel base = 0x804d4000 PsLoadedModuleList = 0x80543530
Debug session time: Mon Sep 08 19:15:14 2003
System Uptime: 0 days 7:24:58
start    end        module name
804d4000 806aa280   nt             Checksum: 001E311B  Timestamp: Thu Apr 24 08:
57:43 2003 (3EA80977)

Unloaded modules:
f1f0b000 f1f32000   kmixer.sys    Timestamp: Mon Sep 08 12:52:21 2003 (3F5CDDF5)

f2072000 f2099000   kmixer.sys    Timestamp: Mon Sep 08 12:40:12 2003 (3F5CDB1C)

f25f1000 f2618000   kmixer.sys    Timestamp: Mon Sep 08 11:51:19 2003 (3F5CCFA7)

fa482000 fa483000   drmkaud.sys    Timestamp: Mon Sep 08 11:51:14 2003 (3F5CCFA2
)
f285f000 f286c000   DMusic.sys    Timestamp: Mon Sep 08 11:51:14 2003 (3F5CCFA2)

f286f000 f287d000   swmidi.sys    Timestamp: Mon Sep 08 11:51:14 2003 (3F5CCFA2)

f2653000 f2676000   aec.sys     Timestamp: Mon Sep 08 11:51:14 2003 (3F5CCFA2)
fa442000 fa444000   splitter.sys    Timestamp: Mon Sep 08 11:51:14 2003 (3F5CCFA
2)
fa1ac000 fa1b1000   Cdaudio.SYS    Timestamp: Mon Sep 08 11:50:36 2003 (3F5CCF7C
)
fa394000 fa397000   Sfloppy.SYS    Timestamp: Mon Sep 08 11:50:36 2003 (3F5CCF7C
)

Finished dump check.


Any ideas...?

 

by: gemartiPosted on 2003-09-08 at 15:02:38ID: 9312803

Okay we are getting somewhere now. What I need you to do is run another program from the command prompt:

pstat.exe > c:\memoryadr.txt

This will give me memory address information. Post this information also.


It is looking like your problem is with your Audio drivers. Does the machine crash while playing music?

 

by: Mike_D56Posted on 2003-09-09 at 10:07:29ID: 9322217

Yeah I think, now you mention it, I am playing music usually when it happens.  It's just that KaZaA is on also when it happens.  Maybe a combination of both?  Here's the memoryadr.txt:

PageFile: \??\D:\pagefile.sys
      Current Size: 344064 kb  Total Used:  33944 kb   Peak Used  46892 kb

 Memory: 228848K Avail:  54440K  TotalWs: 214884K InRam Kernel: 2964K P:23284K
 Commit: 181608K/ 127424K Limit: 560624K Peak: 188100K  Pool N: 5116K P:23360K

    User Time   Kernel Time    Ws   Faults  Commit Pri Hnd Thd Pid Name
                            63512   243076                         File Cache
  0:00:00.000   0:21:04.057    20        1       0  0    0   1   0 Idle Process
  0:00:00.000   0:00:09.002   216     4917      32  8  297  52   4 System
  0:00:00.010   0:00:00.020   464      237     172 11   21   3 532 SMSS.EXE
  0:00:00.951   0:00:06.228  3836     2752    1568 13  492  11 616 CSRSS.EXE
  0:00:00.670   0:00:00.951  2908     7750    5956 13  519  19 640 WINLOGON.EXE
  0:00:00.400   0:00:01.392  3168     1137    1344  9  295  15 684 SERVICES.EXE
  0:00:00.630   0:00:00.650  1120     4635    3300  9  313  20 696 LSASS.EXE
  0:00:00.220   0:00:00.240  3240      933    1132  8  302   9 856 SVCHOST.EXE
  0:00:02.633   0:00:02.884 22372    12761   15480  8 1393  80 880 SVCHOST.EXE
  0:00:00.100   0:00:00.100  2108      645     652  8   64   6 968 SVCHOST.EXE
  0:00:00.050   0:00:00.080  3832      997    1184  8  136  15 1036 SVCHOST.EXE
  0:00:00.070   0:00:00.260  4124     1559    2604  8  137  12 1172 SPOOLSV.EXE
  0:00:00.010   0:00:00.060  4228     1088    1060  8  115   5 1272 ALG.EXE
  0:00:10.565   0:00:13.329  4348    26593    3544  8  327  21 1284 CCEVTMGR.EXE
  0:00:00.460   0:00:00.480  1304     6954    1148  8  103   9 1344 NAVAPSVC.EXE
  0:00:00.240   0:00:00.090  4376     1322    1160  8  104   4 1368 NISUM.EXE
  0:00:00.070   0:00:00.080  3348      907     784  8   99   5 1512 SVCHOST.EXE
  0:00:08.352   0:00:09.984  7588    20744    5180  8  289  14 1872 CCPXYSVC.EXE
  0:00:02.974   0:00:19.327 18460    16004   11524  8  278  11 584 EXPLORER.EXE
  0:00:05.177   0:00:07.090 14248    15258    8568  8  459  31 912 CCAPP.EXE
  0:00:00.030   0:00:00.060  2688      724     616  8   23   1 964 MsgPlus.exe
  0:00:00.650   0:00:00.680  2596      658     600  8   22   3 1008 DRAGDIAG.EXE
  0:00:00.250   0:00:00.600  8720     2743    6144  8  158   5 1016 QTTASK.EXE
  0:00:00.030   0:00:00.070   128     2610     756  8   46   3 1028 realsched.exe
  0:00:00.981   0:00:01.522  5976     7768   17356  8  404  20 1092 MSMSGS.EXE
  0:00:08.051   0:00:18.146  6128    85791   17572  8  425  13 1952 MSNMSGR.EXE
  0:00:00.811   0:00:01.952  5528     8506    8628  8  396  19 3324 msimn.exe
  0:00:00.741   0:00:02.052 11692     7839    7600  8  356  14 3484 IEXPLORE.EXE
  0:00:00.020   0:00:00.060  1492      384    1428  8   21   1 3640 CMD.exe
  0:00:00.010   0:00:00.040  1116      277     332  8   13   1 3724 pstat.exe

pid:  0 pri: 0 Hnd:    0 Pf:      1 Ws:     20K Idle Process
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
   0   0    157801 00000000  0:00:00.000  0:21:04.057 Running

pid:  4 pri: 8 Hnd:  297 Pf:   4917 Ws:    216K System
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
   8   0      4878 8065F838  0:00:00.000  0:00:02.193 Ready
  10  13      2340 805257F0  0:00:00.000  0:00:00.060 Wait:EventPairLow
  14  13       873 805257F0  0:00:00.000  0:00:00.020 Wait:EventPairLow
  18  13      2193 805257F0  0:00:00.000  0:00:00.040 Wait:EventPairLow
  1c  14         5 805257F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
  20  13      2076 805257F0  0:00:00.000  0:00:00.040 Wait:EventPairLow
  24  12         1 805257F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
  28  12         2 805257F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
  2c  12        28 805257F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
  30  12     19417 805257F0  0:00:00.000  0:00:01.392 Wait:Executive
  34  13     21640 805257F0  0:00:00.000  0:00:02.433 Wait:EventPairLow
  38  13      1472 805257F0  0:00:00.000  0:00:00.170 Wait:EventPairLow
  3c  13       470 805257F0  0:00:00.000  0:00:01.011 Wait:EventPairLow
  40  15       771 805257F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
  44  14      1461 805E9E08  0:00:00.000  0:00:00.000 Wait:Executive
  48  18      1050 805022EC  0:00:00.000  0:00:00.040 Wait:VirtualMemory
  4c  17      1412 8062319E  0:00:00.000  0:00:00.050 Wait:FreePage
  50  16      7907 8052C2B8  0:00:00.000  0:00:00.020 Wait:Executive
  54  23      8068 8052C590  0:00:00.000  0:00:00.010 Wait:Executive
  58  16         1 804E8CDC  0:00:00.000  0:00:00.000 Wait:EventPairLow
  5c  17         1 804E8CDC  0:00:00.000  0:00:00.000 Wait:EventPairLow
  60   8       713 F9E6EDBE  0:00:00.000  0:00:00.020 Wait:Executive
  64  17       147 80503A9A  0:00:00.000  0:00:00.000 Wait:VirtualMemory
  68   8         1 F9E25D86  0:00:00.000  0:00:00.000 Wait:Executive
  6c   8       128 F9D99600  0:00:00.000  0:00:00.010 Wait:EventPairLow
  74  16         3 F9F71D30  0:00:00.000  0:00:00.000 Wait:Executive
  78  16         3 F9F71D30  0:00:00.000  0:00:00.000 Wait:Executive
  84   8         2 F9B74636  0:00:00.000  0:00:00.000 Wait:EventPairLow
  88   8         1 F9B74636  0:00:00.000  0:00:00.000 Wait:EventPairLow
  8c   8         1 F9B74636  0:00:00.000  0:00:00.000 Wait:EventPairLow
  90   8        25 F9B5F06A  0:00:00.000  0:00:00.000 Wait:Executive
  98   8         2 F9FC4A41  0:00:00.000  0:00:00.000 Wait:Executive
  9c   8         1 F9FC4BBA  0:00:00.000  0:00:00.000 Wait:Executive
 128   9     20415 F9BFE1B0  0:00:00.000  0:00:00.610 Wait:Suspended
 144   9      2828 F9BFE1B0  0:00:00.000  0:00:00.010 Wait:Suspended
 148   9      2825 F9BFE1B0  0:00:00.000  0:00:00.000 Wait:Suspended
 150   8       288 F9BEA2EE  0:00:00.000  0:00:00.000 Wait:Executive
 154   8         1 FA399038  0:00:00.000  0:00:00.000 Wait:Executive
 200   8         1 F78023F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
 204   8        48 F78023F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
 208   8         1 F78023F0  0:00:00.000  0:00:00.000 Wait:EventPairLow
 20c   8        24 F77EF717  0:00:00.000  0:00:00.000 Wait:Executive
 210   9        17 805D0CBE  0:00:00.000  0:00:00.000 Wait:LpcReceive
 23c   8     12296 F775DA92  0:00:00.000  0:00:00.110 Wait:Executive
 4d0   8         1 F2C53498  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4d4   8         1 F2C53498  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4d8   8         1 F2C53498  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4dc   8        24 F2C364CC  0:00:00.000  0:00:00.000 Wait:Executive
 4e8   8         9 F2C33C94  0:00:00.000  0:00:00.000 Wait:Executive
 580   9         1 F2AE79C8  0:00:00.000  0:00:00.000 Wait:EventPairLow
 594   9         1 F2AE79C8  0:00:00.000  0:00:00.000 Wait:EventPairLow
 118   8      5389 F9BF3854  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:214 pri:11 Hnd:   21 Pf:    237 Ws:    464K SMSS.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 218  11       101 48589A26  0:00:00.000  0:00:00.040 Wait:UserRequest
 21c  12         7 485887B8  0:00:00.000  0:00:00.000 Wait:LpcReceive
 220  12         3 485887B8  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:268 pri:13 Hnd:  492 Pf:   2752 Ws:   3836K CSRSS.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 270  15        10 75B7234A  0:00:00.000  0:00:00.000 Wait:LpcReply
 274  14         7 75B69FD5  0:00:00.000  0:00:00.010 Wait:UserRequest
 278  14      2614 75B441F0  0:00:00.270  0:00:00.280 Wait:LpcReceive
 27c  14         3 75B437E2  0:00:00.000  0:00:00.000 Wait:LpcReceive
 288  14      2596 75B441F0  0:00:00.330  0:00:00.250 Wait:LpcReceive
 28c  15    124337 75B6E8AD  0:00:00.000  0:00:00.771 Wait:UserRequest
 290  15     38895 75B6E8AD  0:00:00.000  0:00:03.895 Wait:UserRequest
 2c0  14         3 75B6E8AD  0:00:00.000  0:00:00.000 Wait:UserRequest
 13c  15         1 75B73114  0:00:00.000  0:00:00.000 Wait:UserRequest
 468  13      2007 75B441F0  0:00:00.230  0:00:00.110 Wait:LpcReceive
 e40  15      1282 75B77697  0:00:00.040  0:00:00.210 Wait:UserRequest

pid:280 pri:13 Hnd:  519 Pf:   7750 Ws:   2908K WINLOGON.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 284  15      2219 0103C559  0:00:00.530  0:00:00.721 Wait:UserRequest
 29c  13         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 2a0  13         3 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 2a4  13       102 77E7D342  0:00:00.050  0:00:00.020 Wait:EventPairLow
 2a8  14        41 77E7D342  0:00:00.000  0:00:00.010 Wait:EventPairLow
 2b4  14        14 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 2dc  15       111 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3e4  15        11 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3ec  11         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 510  14         6 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 514  14        36 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 518  13         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 51c  14         5 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 520   1         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 7c8  13         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 1b4   1         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 1e4  13         8 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 22c  15         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 14c  15        33 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest

pid:2ac pri: 9 Hnd:  295 Pf:   1137 Ws:   3168K SERVICES.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 2c4   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 314   9        82 77E7D342  0:00:00.010  0:00:00.000 Wait:DelayExecution
 318   9        65 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 324   9        46 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 338  10      3259 77E7D342  0:00:00.120  0:00:00.871 Wait:DelayExecution
 33c  11       244 77E7D342  0:00:00.010  0:00:00.030 Wait:DelayExecution
 340   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 34c  10        14 77E7D342  0:00:00.000  0:00:00.010 Wait:Executive
 354   9         4 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 3b0   9       463 77E7D342  0:00:00.000  0:00:00.000 Wait:Executive
 3b4   9        20 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 3e8   9        38 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 548  10      5771 77E7D342  0:00:00.190  0:00:00.380 Wait:EventPairLow
  d8  10         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  dc  10        16 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:2b8 pri: 9 Hnd:  313 Pf:   4635 Ws:   1120K LSASS.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 2c8  10        18 77E7D342  0:00:00.000  0:00:00.000 Wait:Executive
 2cc   9        42 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 2d0   9       124 77E7D342  0:00:00.060  0:00:00.010 Wait:EventPairLow
 2d4   9        42 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 2d8  10         2 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 2ec   9        45 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 2f4  10      4909 77E7D342  0:00:00.160  0:00:00.270 Wait:EventPairLow
 2f8   9         9 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 2fc  10       533 77E7D342  0:00:00.020  0:00:00.000 Wait:LpcReceive
 308  10        44 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 30c   9         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 31c  10       309 77E7D342  0:00:00.050  0:00:00.100 Wait:LpcReceive
 438  10       321 77E7D342  0:00:00.080  0:00:00.090 Wait:LpcReceive
 4c8  10         9 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5ac  10        38 77E7D342  0:00:00.060  0:00:00.010 Wait:UserRequest
 5b4  11         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5b8   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5bc   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5c0   9         3 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 3c0   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:358 pri: 8 Hnd:  302 Pf:    933 Ws:   3240K SVCHOST.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 35c   8        12 77E8149F  0:00:00.000  0:00:00.000 Wait:Executive
 360   8        82 77E7D342  0:00:00.000  0:00:00.030 Wait:DelayExecution
 368   8        15 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 36c   9        43 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  d4   8       122 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 550   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 738   8       408 77E7D342  0:00:00.030  0:00:00.020 Wait:LpcReceive
 a4c   9       199 77E7D342  0:00:00.010  0:00:00.000 Wait:LpcReceive
 da4   9        30 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:370 pri: 8 Hnd: 1393 Pf:  12761 Ws:  22372K SVCHOST.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 374   9       361 77E8149F  0:00:00.000  0:00:00.030 Wait:Executive
 37c   9       189 77E7D342  0:00:00.010  0:00:00.000 Wait:LpcReceive
 380   8       176 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 38c   8       514 77E7D342  0:00:00.090  0:00:00.110 Wait:EventPairLow
 394   8        33 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 3a4   8        10 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3a8   8       120 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 458   8       238 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 46c   8        12 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 470   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 474   9       374 77E7D342  0:00:00.010  0:00:00.010 Wait:UserRequest
 478   9       750 77E7D342  0:00:00.040  0:00:00.050 Wait:LpcReceive
 47c   8       103 77E7D342  0:00:00.000  0:00:00.030 Wait:UserRequest
 480   8        69 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 488  10      1507 77E7D342  0:00:00.030  0:00:00.030 Wait:EventPairLow
 48c  10        67 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 490   8        50 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 49c   8       869 77E7D342  0:00:00.300  0:00:00.400 Wait:UserRequest
 4a4   9       274 77E7D342  0:00:00.040  0:00:00.030 Wait:LpcReceive
 4c0   8       367 77E7D342  0:00:00.010  0:00:00.000 Wait:LpcReceive
 4cc   8        54 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 530   9        12 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 538   9        16 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 53c   8        65 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 578   8         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 598  10        12 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 604   9       103 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 608   9         8 77E7D342  0:00:00.000  0:00:00.000 Wait:Executive
 60c   9        80 77E7D342  0:00:00.000  0:00:00.030 Wait:UserRequest
 610  10        31 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 614   9       157 77E7D342  0:00:00.010  0:00:00.030 Wait:LpcReceive
 618   9        58 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 61c   8       671 77E7D342  0:00:00.070  0:00:00.020 Wait:LpcReceive
 620  10        76 77E7D342  0:00:00.000  0:00:00.020 Wait:EventPairLow
 628   9         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 62c  15        17 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 630   8         8 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 64c  10       196 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 674   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 678   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 67c  10        41 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 680   9       257 77E7D342  0:00:00.060  0:00:00.020 Wait:LpcReceive
 694   8        11 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 698   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 69c   8         7 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 6a0   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 6a4  10        48 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 6a8   9        22 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 700   8       118 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 704   8      1369 77E7D342  0:00:00.010  0:00:00.020 Wait:UserRequest
 734   9       158 77E7D342  0:00:00.000  0:00:00.040 Wait:UserRequest
 7d0   8      2368 77E7D342  0:00:00.560  0:00:00.590 Wait:UserRequest
 7d4   9        37 77E7D342  0:00:00.010  0:00:00.020 Wait:UserRequest
 7d8   8        33 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 7e8   9         9 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 7ec   9        11 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 7f0   8         7 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 7f4   8         1 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 7f8   9         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 7fc   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  94   8       227 77E7D342  0:00:00.000  0:00:00.020 Wait:LpcReceive
  c8   9        26 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  a4   8         7 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  cc   8         7 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  d0   9         8 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest
 160   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 164   8       169 77E7D342  0:00:00.020  0:00:00.050 Wait:EventPairLow
 168   9         4 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 16c   9     37316 77E7D342  0:00:00.741  0:00:00.771 Wait:EventPairLow
 188  10        35 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 240   6        21 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 5d0  10         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 6e4   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReply
 c90   8        30 77E7D342  0:00:00.000  0:00:00.010 Wait:LpcReceive
 c94   8        26 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 d80   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 d90   9        28 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 d98   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 e44   9        43 77E7D342  0:00:00.020  0:00:00.000 Wait:LpcReceive
 e68   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:3c8 pri: 8 Hnd:   64 Pf:    645 Ws:   2108K SVCHOST.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 3cc   9        16 77E8149F  0:00:00.010  0:00:00.010 Wait:Executive
 408   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 414   9         7 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 418   9       814 77E7D342  0:00:00.000  0:00:00.020 Wait:LpcReceive
 72c   9       825 77E7D342  0:00:00.050  0:00:00.050 Wait:LpcReceive
 8c8  10       675 77E7D342  0:00:00.020  0:00:00.020 Wait:LpcReceive

pid:40c pri: 8 Hnd:  136 Pf:    997 Ws:   3832K SVCHOST.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 410   9        45 77E8149F  0:00:00.000  0:00:00.010 Wait:Executive
 420   8        10 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 428   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 4ec   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4f0   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4f4   8        26 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 454  10        91 77E7D342  0:00:00.030  0:00:00.040 Wait:UserRequest
 464   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 424   8        72 77E7D342  0:00:00.000  0:00:00.010 Wait:EventPairLow
 4bc   8        11 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 2e4   8         9 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3e0   9         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 534  10        12 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 6b4   8         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 ae8   8         4 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow

pid:494 pri: 8 Hnd:  137 Pf:   1559 Ws:   4124K SPOOLSV.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 498   9        17 77E8149F  0:00:00.000  0:00:00.000 Wait:Executive
 4a8   9         8 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 4ac   8         7 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 4b0   8        36 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 4b8   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:Executive
  e8   9       269 77E7D342  0:00:00.060  0:00:00.220 Wait:UserRequest
  f4   9         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  f8   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  fc   8        38 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 100   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 10c   8         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 e24   8        13 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:4f8 pri: 8 Hnd:  115 Pf:   1088 Ws:   4228K ALG.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 4fc   9        18 77E8149F  0:00:00.000  0:00:00.010 Wait:Executive
 500   9        35 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 50c   8        31 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 73c   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 744   8        36 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow

pid:504 pri: 8 Hnd:  327 Pf:  26593 Ws:   4348K CCEVTMGR.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 508   8        43 77E8149F  0:00:00.030  0:00:00.030 Wait:Executive
 524   9       477 77E7D342  0:00:00.110  0:00:00.160 Wait:UserRequest
 568   8        12 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 59c   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5c8   8     25662 77E7D342  0:00:01.682  0:00:00.721 Wait:UserRequest
 5cc   8      8102 77E7D342  0:00:00.210  0:00:00.290 Wait:UserRequest
 634   8         8 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 63c   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 640   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 650  10        47 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 654   8         5 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 65c   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 660   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 668   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 710  13      1596 77E7D342  0:00:00.020  0:00:00.030 Wait:UserRequest
 730   8        30 77E7D342  0:00:00.020  0:00:00.040 Wait:UserRequest
 740   8         8 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 748   9        14 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 74c   8     22626 77E7D342  0:00:02.753  0:00:03.935 Wait:LpcReceive
 330   8     22568 77E7D342  0:00:02.663  0:00:04.196 Wait:LpcReceive
 3a0   8     22342 77E7D342  0:00:03.054  0:00:03.905 Wait:LpcReceive

pid:540 pri: 8 Hnd:  103 Pf:   6954 Ws:   1304K NAVAPSVC.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 544   9        17 77E8149F  0:00:00.000  0:00:00.010 Wait:Executive
 54c   8       144 77E7D342  0:00:00.020  0:00:00.090 Wait:UserRequest
 560   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 584   9         5 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 588   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 58c   8       336 77E7D342  0:00:00.420  0:00:00.320 Wait:UserRequest
 590   8       233 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 79c   9         6 77E7D342  0:00:00.000  0:00:00.000 Wait:Executive
 138   9        14 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:558 pri: 8 Hnd:  104 Pf:   1322 Ws:   4376K NISUM.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 55c   9       100 77E8149F  0:00:00.040  0:00:00.030 Wait:Executive
 5a0   9         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 5a4  10      3179 77E7D342  0:00:00.170  0:00:00.050 Wait:UserRequest
 bc8   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:5e8 pri: 8 Hnd:   99 Pf:    907 Ws:   3348K SVCHOST.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 5ec   8        13 77E8149F  0:00:00.000  0:00:00.000 Wait:Executive
 5f4   9      1104 77E7D342  0:00:00.030  0:00:00.030 Wait:UserRequest
 638   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 798   9         6 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 c04   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:750 pri: 8 Hnd:  289 Pf:  20744 Ws:   7588K CCPXYSVC.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 754   9        20 77E8149F  0:00:00.010  0:00:00.000 Wait:Executive
 758   8       142 77E7D342  0:00:00.190  0:00:00.160 Wait:UserRequest
 760   8        35 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 764   9         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 768   8       120 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 76c   9      4991 77E7D342  0:00:00.721  0:00:00.370 Wait:UserRequest
 770   8     15107 77E7D342  0:00:01.982  0:00:02.753 Wait:LpcReceive
 780   8       827 77E7D342  0:00:00.160  0:00:00.120 Wait:UserRequest
 78c  10     14774 77E7D342  0:00:00.090  0:00:00.090 Wait:UserRequest
 230   8     15084 77E7D342  0:00:01.912  0:00:02.503 Wait:LpcReceive
 820   9     15143 77E7D342  0:00:02.183  0:00:02.964 Wait:LpcReceive
 874  10      5204 77E7D342  0:00:00.000  0:00:00.030 Wait:UserRequest
 980  10      4734 77E7D342  0:00:00.030  0:00:00.040 Wait:UserRequest
 ce0   9       540 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest

pid:248 pri: 8 Hnd:  278 Pf:  16004 Ws:  18460K EXPLORER.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 24c  10      2812 77E8149F  0:00:00.260  0:00:01.762 Wait:UserRequest
 264   8       111 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 260  11     18554 77E7D342  0:00:01.271  0:00:11.706 Wait:UserRequest
 258   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 26c   8      4289 77E7D342  0:00:00.610  0:00:04.155 Wait:EventPairLow
 294   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 2bc   8       577 77E7D342  0:00:00.030  0:00:00.040 Wait:UserRequest
 6fc   9     19625 77E7D342  0:00:00.660  0:00:01.291 Wait:UserRequest
 c84   8        52 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 db4   8        13 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 db8   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution

pid:390 pri: 8 Hnd:  459 Pf:  15258 Ws:  14248K CCAPP.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 3b8  10       940 77E8149F  0:00:00.130  0:00:00.440 Wait:UserRequest
 4e0   8         6 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 7e4   9         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  80  11       299 77E7D342  0:00:00.050  0:00:00.070 Wait:UserRequest
 434  10        88 77E7D342  0:00:00.010  0:00:00.020 Wait:UserRequest
 2e8   8      5445 77E7D342  0:00:00.360  0:00:00.090 Wait:UserRequest
 7dc   8       292 77E7D342  0:00:00.030  0:00:00.020 Wait:UserRequest
 7e0   8     11598 77E7D342  0:00:01.301  0:00:01.852 Wait:LpcReceive
  e0   8         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
  b8   8     11729 77E7D342  0:00:01.261  0:00:02.072 Wait:LpcReceive
 4b4  10       274 77E7D342  0:00:00.040  0:00:00.080 Wait:UserRequest
  ec   8         5 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 108  13      7635 77E7D342  0:00:00.090  0:00:00.120 Wait:UserRequest
 11c   8         4 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 104  10      1342 77E7D342  0:00:00.170  0:00:00.170 Wait:UserRequest
 124   9         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 12c   8       159 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 2e0   8       156 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 1c0   8       146 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 1e8  10         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 1d8   8        70 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 228  11        40 77E7D342  0:00:00.030  0:00:00.010 Wait:UserRequest
 174   8      3843 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 198   8         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 194   8      1272 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 350  10       177 77E7D342  0:00:00.020  0:00:00.040 Wait:UserRequest
 41c   8      2587 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3d8   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 234  11        29 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 238  10        74 77E7D342  0:00:00.040  0:00:00.000 Wait:UserRequest
 5a8   8     11491 77E7D342  0:00:01.522  0:00:01.872 Wait:LpcReceive

pid:3c4 pri: 8 Hnd:   23 Pf:    724 Ws:   2688K MsgPlus.exe
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 3f4   8       952 77E8149F  0:00:00.020  0:00:00.050 Wait:UserRequest

pid:3f0 pri: 8 Hnd:   22 Pf:    658 Ws:   2596K DRAGDIAG.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 3dc   9      4702 77E8149F  0:00:00.640  0:00:00.680 Wait:UserRequest
 5c4   8       338 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 5dc   8       329 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:3f8 pri: 8 Hnd:  158 Pf:   2743 Ws:   8720K QTTASK.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 400  10      1013 77E8149F  0:00:00.240  0:00:00.610 Wait:UserRequest
 56c   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 658  10         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 75c   9         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 3d0   8         9 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest

pid:404 pri: 8 Hnd:   46 Pf:   2610 Ws:    128K realsched.exe
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 440  10       359 77E8149F  0:00:00.020  0:00:00.070 Wait:UserRequest
 6d8   8         8 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 6dc   9         9 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest

pid:444 pri: 8 Hnd:  404 Pf:   7768 Ws:   5976K MSMSGS.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 448   8     12109 77E8149F  0:00:00.781  0:00:01.371 Wait:UserRequest
 7b8   8      2601 77E7D342  0:00:00.010  0:00:00.010 Wait:LpcReceive
 7bc   9        47 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 724   9        55 77E7D342  0:00:00.020  0:00:00.010 Wait:UserRequest
 720  15         1 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest
 7a4   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 320   8       171 77E7D342  0:00:00.070  0:00:00.040 Wait:EventPairLow
 450   8        13 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 484  10        20 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 564   8       579 77E7D342  0:00:00.030  0:00:00.070 Wait:UserRequest
 778  10        81 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 848  10        20 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 84c   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 87c   7       225 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 880   6       214 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 88c   8      1283 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 898  10         9 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 89c  12        48 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 8a8   9      1048 77E7D342  0:00:00.010  0:00:00.000 Wait:LpcReceive
 d20   9        34 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive

pid:7a0 pri: 8 Hnd:  425 Pf:  85791 Ws:   6128K MSNMSGR.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 7a8   9     55038 77E8149F  0:00:07.741  0:00:17.955 Wait:UserRequest
 170  10        21 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 1cc   7       237 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 1d0   6       186 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 1e0   8      1302 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 4c4  13      1112 77E7D342  0:00:00.010  0:00:00.000 Wait:EventPairLow
 6d4  12       250 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest
 6b0   8         2 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 5e0  10       753 77E7D342  0:00:00.120  0:00:00.040 Wait:EventPairLow
 3bc  10        15 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 77c   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 670  15         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 7ac  10       300 77E7D342  0:00:00.010  0:00:00.150 Wait:UserRequest

pid:cfc pri: 8 Hnd:  396 Pf:   8506 Ws:   5528K msimn.exe
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 d00  10      2771 77E8149F  0:00:00.620  0:00:01.772 Wait:UserRequest
 d0c  10      1206 77E7D342  0:00:00.090  0:00:00.140 Wait:UserRequest
 d10  10        24 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d14   8        63 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 d18  11        38 77E7D342  0:00:00.010  0:00:00.000 Wait:LpcReceive
 d1c  10         6 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 d24   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d28  12        35 77E7D342  0:00:00.000  0:00:00.020 Wait:UserRequest
 d2c  10         3 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 d34  11        13 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest
 d40   8         5 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d44   9         3 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d48   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d4c   9        27 77E7D342  0:00:00.020  0:00:00.000 Wait:UserRequest
 d54  11       155 77E7D342  0:00:00.010  0:00:00.010 Wait:EventPairLow
 d78  15         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d7c  12        24 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 d8c  11        17 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 e20   8       111 77E7D342  0:00:00.020  0:00:00.010 Wait:UserRequest

pid:d9c pri: 8 Hnd:  356 Pf:   7839 Ws:  11692K IEXPLORE.EXE
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 da0  12       553 77E8149F  0:00:00.110  0:00:00.330 Wait:UserRequest
 da8  11        41 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 dac  11        35 77E7D342  0:00:00.000  0:00:00.010 Wait:LpcReceive
 db0   9         4 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 dbc  11        18 77E7D342  0:00:00.000  0:00:00.000 Wait:LpcReceive
 dc0  10      3047 77E7D342  0:00:00.550  0:00:01.612 Wait:UserRequest
 dc4   9       129 77E7D342  0:00:00.000  0:00:00.010 Wait:UserRequest
 dc8  10         4 77E7D342  0:00:00.000  0:00:00.000 Wait:DelayExecution
 dd0  11        21 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest
 dd4   9        16 77E7D342  0:00:00.000  0:00:00.000 Wait:EventPairLow
 de4  10        13 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 de8   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 dec   8         1 77E7D342  0:00:00.000  0:00:00.000 Wait:UserRequest
 df0   9       107 77E7D342  0:00:00.010  0:00:00.000 Wait:UserRequest

pid:e38 pri: 8 Hnd:   21 Pf:    384 Ws:   1492K CMD.exe
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 e3c   8       263 77E8149F  0:00:00.010  0:00:00.060 Wait:UserRequest

pid:e8c pri: 8 Hnd:   13 Pf:    277 Ws:   1116K pstat.exe
 tid pri Ctx Swtch StrtAddr    User Time  Kernel Time  State
 e90   8        24 77E8149F  0:00:00.000  0:00:00.040 Running

  ModuleName Load Addr   Code    Data   Paged           LinkDate
------------------------------------------------------------------------------
ntoskrnl.exe 804D4000  396160   76160 1094784 Thu Apr 24 08:57:43 2003
     hal.dll 806AB000   27008    6272   23936 Thu Aug 29 01:05:02 2002
   KDCOM.DLL FA3AC000    2560     256    1280 Fri Aug 17 13:49:10 2001
 BOOTVID.dll FA2BC000    5632    3584       0 Fri Aug 17 13:49:09 2001
    ACPI.sys F9E5F000  103936   11008   40192 Thu Aug 29 01:09:03 2002
  WMILIB.SYS FA3AE000     512       0    1280 Fri Aug 17 14:07:23 2001
     pci.sys F9EAC000   14464    1664   30976 Thu Aug 29 01:09:10 2002
  isapnp.sys F9EBC000    8704     768   18688 Fri Aug 17 13:58:01 2001
  viaide.sys FA3B0000    2432       0       0 Thu Aug 29 01:27:48 2002
 PCIIDEX.SYS FA12C000    5120     512   12288 Thu Aug 29 01:27:47 2002
MountMgr.sys F9ECC000    1280     128   29696 Fri Aug 17 13:47:36 2001
  ftdisk.sys F9E40000    5888     128  102400 Fri Aug 17 13:52:41 2001
  dmload.sys FA3B2000    2560     128       0 Fri Aug 17 13:58:15 2001
    dmio.sys F9E1C000  114432   15104    1152 Fri Aug 17 13:58:27 2001
 PartMgr.sys FA134000    1920     128   11136 Fri Aug 17 18:32:23 2001
 VolSnap.sys F9EDC000    2304     128   32512 Fri Aug 17 13:53:19 2001
   atapi.sys F9E06000   41472    3584   25984 Thu Aug 29 01:27:48 2002
    disk.sys F9EEC000    7808     256   16256 Thu Aug 29 01:27:56 2002
CLASSPNP.SYS F9EFC000   23424     128   14336 Thu Aug 29 02:08:42 2002
      sr.sys F9DF5000    1792    1152   51200 Thu Aug 29 01:17:56 2002
 Fastfat.sys F9DD1000    8704     768  116864 Thu Aug 29 02:12:45 2002
  KSecDD.sys F9DBD000    9216    6784   53504 Fri Aug 17 13:50:01 2001
    NDIS.sys F9D94000   18560    1024  122368 Thu Aug 29 02:09:23 2002
  viaagp.sys FA13C000    8192     128   13568 Fri Aug 17 13:58:00 2001
     Mup.sys F9D7A000   13824    6144   70272 Thu Aug 29 02:12:53 2002
processr.sys FA154000    7552    1408    9216 Thu Aug 29 01:05:03 2002
  s3gnbm.sys F9D0B000  109056   20608   19584 Wed Nov 06 21:38:46 2002
VIDEOPRT.SYS F9CF9000    9984     384   43008 Thu Aug 29 01:32:03 2002
HCF_MSFT.sys F9C1B000  557440  272576   36416 Fri Jun 08 00:01:44 2001
   Modem.SYS FA15C000    1280     128   19968 Fri Aug 17 13:57:35 2001
 usbuhci.sys FA164000   15744     384       0 Thu Aug 29 01:32:48 2002
 USBPORT.SYS F9BF9000  113024    1024   10752 Thu Aug 29 01:32:49 2002
i8042prt.sys F9F2C000   11648     256   22016 Thu Aug 29 02:06:37 2002
mouclass.sys FA16C000    5888     896    5504 Thu Aug 29 01:27:00 2002
kbdclass.sys FA174000    6528     896    6144 Thu Aug 29 01:26:59 2002
     fdc.sys FA17C000   18176     256     384 Fri Aug 17 13:51:22 2001
  serial.sys F9F3C000   11392     256   29312 Thu Aug 29 02:08:27 2002
 serenum.sys FA340000    2688     128    7552 Fri Aug 17 13:50:13 2001
 parport.sys F9BE6000   63232    1280     256 Thu Aug 29 01:27:29 2002
gameenum.sys FA344000    1152       0    5120 Thu Aug 29 01:32:42 2002
msmpu401.sys FA49E000     128       0     384 Fri Aug 17 13:59:59 2001
 portcls.sys F9BC5000   39168   10496   60032 Thu Aug 29 02:00:58 2002
    drmk.sys F9F4C000    5120    1280   45824 Thu Aug 29 01:32:30 2002
      ks.sys F9BA5000   28800     128   79744 Wed Dec 04 09:09:38 2002
   cdrom.sys F9F5C000   31872     128    5632 Thu Aug 29 01:27:55 2002
 redbook.sys F9F6C000    6400    1152   36096 Thu Aug 29 01:27:45 2002
   Imapi.SYS F9F7C000   10240     256   19328 Thu Aug 29 01:28:05 2002
 viaudio.sys F9F8C000   22784    4608   24704 Thu Sep 12 01:32:14 2002
  fetnd5.sys FA184000   18432     512       0 Fri Jul 20 04:40:24 2001
 audstub.sys FA49F000     128       0     512 Fri Aug 17 13:59:40 2001
 rasl2tp.sys F9F9C000   41984     512       0 Thu Aug 29 02:06:36 2002
ndistapi.sys FA350000    5248     128       0 Fri Aug 17 13:55:29 2001
 ndiswan.sys F9B8F000   68352    2432       0 Thu Aug 29 01:58:38 2002
raspppoe.sys F9FAC000   29056    4608       0 Fri Aug 17 13:55:33 2001
 raspptp.sys F9FBC000   38016     896       0 Tue Oct 01 17:52:28 2002
     TDI.SYS FA354000    9472     512     256 Fri Aug 17 13:57:25 2001
  psched.sys F9B7E000   49792    2048    3968 Thu Aug 29 01:35:54 2002
   msgpc.sys F9FCC000   27264    1408     512 Fri Aug 17 13:54:19 2001
 ptilink.sys FA18C000   12928     256       0 Fri Aug 17 13:49:53 2001
  raspti.sys FA194000   11008     640       0 Fri Aug 17 13:55:32 2001
   rdpdr.sys F9B51000   67840    4608   86400 Thu Aug 29 01:06:34 2002
  termdd.sys F9FDC000   25216     768    2304 Thu Aug 29 01:40:32 2002
  swenum.sys FA4A5000     384     128     640 Wed Dec 04 09:10:07 2002
  update.sys F9B07000    2048     768  129792 Fri Aug 17 20:53:56 2001
 NDProxy.SYS FA00C000   29184    2176       0 Fri Aug 17 13:55:30 2001
  usbhub.sys FA04C000   23552     768   20736 Thu Aug 29 01:32:49 2002
    USBD.SYS FA3D6000     256       0     896 Fri Aug 17 14:02:58 2001
flpydisk.sys FA1A4000    1920    1280   11392 Thu Aug 29 01:27:43 2002
  Fs_Rec.SYS FA3D8000     128     128    3584 Fri Aug 17 13:49:37 2001
    Null.SYS FA4AE000       0     128     384 Fri Aug 17 13:47:39 2001
    Beep.SYS FA3DA000    1152       0       0 Fri Aug 17 13:47:33 2001
     vga.sys FA1B4000     768     128   14848 Thu Aug 29 01:32:03 2002
   mnmdd.SYS FA3DC000       0       0    1792 Fri Aug 17 13:57:28 2001
  RDPCDD.sys FA3DE000       0       0    1792 Fri Aug 17 13:46:56 2001
    Msfs.SYS FA1BC000     896     128   11264 Fri Aug 17 13:50:02 2001
    Npfs.SYS FA1C4000    1664     256   20352 Fri Aug 17 13:50:03 2001
  rasacd.sys FA398000    3840     128     512 Fri Aug 17 13:55:39 2001
   ipsec.sys FA06C000   46976    1792    2432 Thu Aug 29 02:07:19 2002
   tcpip.sys F7964000  234496   39168   21376 Thu Aug 29 01:58:10 2002
  SYMTDI.SYS F792B000  177984   36384    4160 Fri Jun 06 17:25:24 2003
SYMEVENT.SYS F791A000   57280    1920       0 Tue May 13 22:45:43 2003
SYMREDRV.SYS FA3A0000    5888    1440       0 Fri Jun 06 17:25:40 2003
  SYMDNS.SYS FA3E0000    3232     160       0 Fri Jun 06 17:25:26 2003
 SYMNDIS.SYS FA07C000   37120    2240       0 Fri Jun 06 17:25:33 2003
   SYMFW.SYS F78F9000  103648   21056       0 Fri Jun 06 17:25:38 2003
  wanarp.sys FA08C000   21632     896    3328 Fri Aug 17 13:55:23 2001
  SYMIDS.SYS FA09C000   26592    4416       0 Fri Jun 06 17:25:46 2003
SYMIDSCO.SYS F783C000   97856   13216       0 Thu Aug 21 19:38:24 2003
   netbt.sys F7817000   99456    1664   30720 Tue Jul 08 16:48:51 2003
 netbios.sys FA0AC000   14336     768   11648 Thu Aug 29 01:35:45 2002
   rdbss.sys F77EF000   33024    2816  103936 Thu Aug 29 01:58:48 2002
  mrxsmb.sys F778F000   98304   18944  236160 Mon Nov 18 11:27:37 2002
    Fips.SYS FA0BC000   22016     768    3584 Fri Aug 17 18:31:49 2001
 BANTExt.sys FA4BB000    1088       0       0 Wed May 27 19:43:29 1998
alcaudsl.sys F76D8000  577408      64       0 Wed Oct 03 01:09:55 2001
  alcawh.sys FA3E4000    1088       0       0 Wed Oct 03 01:09:42 2001
  alcacr.sys FA508000    1024       0       0 Wed Oct 03 01:09:49 2001
    Cdfs.SYS FA0DC000    6528     640   42880 Thu Aug 29 01:58:50 2002
alcan5wn.sys FA0EC000   36416    9376       0 Wed Oct 03 01:10:09 2001
dump_atapi.sys F76A0000       0       0       0
dump_WMILIB.SYS FA3E6000       0       0       0
  win32k.sys BF800000 1449728   79232       0 Wed Oct 23 09:54:58 2002
watchdog.sys F9B3D000    2816     128    8320 Thu Aug 29 01:32:20 2002
   Dxapi.sys F9B39000    6272     384     640 Fri Aug 17 13:53:19 2001
     dxg.sys BFF80000   59520     896       0 Thu Aug 29 03:40:42 2002
  dxgthk.sys FA4F5000     128       0       0 Fri Aug 17 13:53:12 2001
   s3gnb.dll BF99E000  333184   24960       0 Wed Nov 06 21:38:39 2002
     afd.sys F2E3E000    3840    2048  105984 Thu Aug 29 02:01:13 2002
 ndisuio.sys F2EC7000    6912     128     640 Thu Aug 29 01:35:40 2002
  mrxdav.sys F2C33000   25088    5504  122240 Fri Aug 17 13:50:20 2001
  ParVdm.SYS FA3F0000    1408     128       0 Fri Aug 17 13:49:49 2001
     srv.sys F2ACC000   52096    8320  227712 Fri Mar 28 11:54:53 2003
SAVRTPEL.SYS F2A93000    4096   12288   32768 Thu Jul 25 22:10:31 2002
   ipnat.sys F28C7000   63744    4096     512 Thu Aug 29 01:36:12 2002
  NAVENG.Sys F2933000       0       0       0
 NavEx15.Sys F2756000       0       0       0
   SAVRT.SYS F2716000    4096   12288  212992 Thu Jul 25 22:10:27 2002
sysaudio.sys F2B73000    2560     128   44160 Thu Aug 29 02:01:17 2002
  kmixer.sys F2604000   12032   35840   94208 Thu Aug 29 01:32:28 2002
  wdmaud.sys F25F1000    7936    2048   60160 Thu Aug 29 02:00:46 2002
   ATMFD.DLL BFFA0000  203648   34176       0 Fri Aug 17 14:55:56 2001
   ntdll.dll 77F50000  458752   24576       0 Thu May 01 16:56:10 2003
------------------------------------------------------------------------------
       Total          6778976  884704 4054144


This is for the D:/ Drive, since this is the one WinXP is on.  Hope you make more out of those numbers that I do.

 

by: Mike_D56Posted on 2003-09-11 at 11:30:54ID: 9339071

I think I fixed it by downloading some new drivers for my Alcatel modem.  I sent off a report to Windows and they came back saying it was my Speedtouch modem causing the problems.  I downloaded new updates from the site and the problem has not occured since.  Thanks for everyones continued help in the matter, sorry the points went to waste.  The question can now be closed.

 

by: LeeTutorPosted on 2003-09-11 at 11:35:10ID: 9339108

Glad you got the problem fixed.  Sounds like you fixed it yourself.  You should click on the link for Community Support on the left side of the page and post a zero point question to have this question deleted so your points can be returned to you.  Make sure to include the reason for the deletion and the url of this question in your Community Support question.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...