I have a Toshiba laptop that was infected with viruses and spyware. After performing scans and removing everything, it now blue screens about three minutes after logging in.
Looking in the task manager, I found a svchost.exe SYSTEM process that continually uses up memory until it blue screens. If I shut down the process before it gets to about 25K, everything is fine.
The dumpchk file has pointed the finger at several different drivers, specifically related to nVidia (nv_mini.sys) and Intel (e100b325.sys). I have renamed these to filename.old and tried restarting, but it still blue screened.
Finally, I narrowed it down to a service causing the problem, because when I enabled only basic services and drivers to load, it wouldn't crash. From there I decided to disable 5 services at a time until it, hopefully, the problem disappeared. Well, it turned out that by disabling Automatic Updates, Windows no longer blue screened. I tested this loading Windows several times with Automatic updates enabled and disabled.
Now the problem is where to go from here. Below in the dumpchk file, it says 'Unable to load image ntoskrnl.exe, win32 error 2 WARNING: Unable to verify timestamp'. I need to find a way to determine if the Automatic Updates blue screen is a symptom of a problem with ntoskrnl.exe, or if I need to repair Automatic Updates (I have no idea how).
To summarize, I have basically 3 questions.
1. Is the 'Unable to verify timestamp for ntoskrnl.exe' something to worry about, or is this a common error?
2. What can be done if the ntoskrnl.exe file is damaged in some way?
3. Or if questions 1 & 2 don't apply, how to you repair the Automatic Updates service?
Thanks
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\program files\Debugging Tools for Windows>dumpchk !analyze -v -y c:\windows\s
ymbols c:\windows\minidump\mini11
2106-10.dm
p
Loading dump file c:\windows\minidump\mini11
2106-10.dm
p
Microsoft (R) Windows Debugger Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [c:\windows\minidump\mini1
12106-10.d
mp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: c:\windows\symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055a420
Debug session time: Tue Nov 21 21:04:28.925 2006 (GMT-8)
System Uptime: 0 days 0:03:04.525
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
..........................
..........
..........
..........
..........
..........
....
..........................
..
Loading User Symbols
Loading unloaded module list
..........
**************************
**********
**********
**********
**********
**********
***
* *
* Bugcheck Analysis *
* *
**************************
**********
**********
**********
**********
**********
***
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, f85bc80e, f71f8a20, 0}
*** WARNING: Unable to verify timestamp for nv4_mini.sys
Probably caused by : nv4_mini.sys ( nv4_mini!Legacy_dacTVConne
ctStatus+4
d0 )
Followup: MachineOwner
---------
----- 32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
KdSecondaryVersion 00000000
DirectoryTableBase 0390a000
PfnDataBase 81000000
PsLoadedModuleList 8055a420
PsActiveProcessHead 805604d8
MachineImageType 0000014c
NumberProcessors 00000001
BugCheckCode 1000008e
BugCheckParameter1 c0000005
BugCheckParameter2 f85bc80e
BugCheckParameter3 f71f8a20
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 8054c060
SecondaryDataState 00000000
ProductType 00000001
SuiteMask 00000310
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 000005d0
DriverListOffset 000031e0
DriverCount 0000006d
StringPoolOffset 00005240
StringPoolSize 00000ed8
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack f71f8a30
DebuggerDataOffset 00002f50
DebuggerDataSize 00000290
DataBlocksOffset 00006118
DataBlocksCount 00000006
c0000000 - c0000fff at offset 00006178
f85bc000 - f85bcfff at offset 00007178
f71f8000 - f71f8fff at offset 00008178
f85c2000 - f85c2fff at offset 00009178
0101c000 - 0101cfff at offset 0000a178
804dd000 - 804ddfff at offset 0000b178
Max offset c178, 9e88 from end of file
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055a420
Debug session time: Tue Nov 21 21:04:28.925 2006 (GMT-8)
System Uptime: 0 days 0:03:04.525
start end module name
804d7000 806eb100 nt Tue Mar 01 16:59:37 2005 (42250FF9)
806ec000 806ffd80 hal Tue Aug 03 22:59:04 2004 (41107B28)
bac07000 bac17e00 psched Tue Aug 03 23:04:16 2004 (41107C60)
bac18000 bac2e680 ndiswan Tue Aug 03 23:14:30 2004 (41107EC6)
bac2f000 bac52980 portcls Tue Aug 03 23:15:47 2004 (41107F13)
bac53000 bac84880 yacxgc Thu Jul 18 21:25:56 2002 (3D3794D4)
bac85000 baca7680 ks Tue Aug 03 23:15:20 2004 (41107EF8)
baca8000 bacbb900 parport Tue Aug 03 22:59:04 2004 (41107B28)
bacbc000 bacd9400 e100b325 Fri Nov 16 14:07:28 2001 (3BF58E20)
bacda000 bacfce80 USBPORT Tue Aug 03 23:08:34 2004 (41107D62)
bacfd000 bad10780 VIDEOPRT Tue Aug 03 23:07:04 2004 (41107D08)
bad11000 bade58c0 nv4_mini Fri Apr 19 14:44:04 2002 (3CC08FA4)
bae2e000 bae48580 Mup Tue Aug 03 23:15:20 2004 (41107EF8)
bae49000 bae75a80 NDIS Tue Aug 03 23:14:27 2004 (41107EC3)
bae76000 baf02480 Ntfs Tue Aug 03 23:15:06 2004 (41107EEA)
baf03000 baf19780 KSecDD Tue Aug 03 22:59:45 2004 (41107B51)
baf1a000 baf2bf00 sr Tue Aug 03 23:06:22 2004 (41107CDE)
baf2c000 baf2d000 fltmgr unavailable (00000000)
baf4b000 baf62480 atapi Tue Aug 03 22:59:41 2004 (41107B4D)
baf63000 baf81880 ftdisk Fri Aug 17 13:52:41 2001 (3B7D8419)
baf82000 baf9f480 pcmcia Tue Aug 03 23:07:45 2004 (41107D31)
bafa0000 bafb0a80 pci Tue Aug 03 23:07:45 2004 (41107D31)
bafb1000 bafded80 ACPI Tue Aug 03 23:07:35 2004 (41107D27)
bf800000 bf9c0500 win32k Tue Mar 01 17:06:42 2005 (422511A2)
bf9c1000 bf9d2580 dxg Tue Aug 03 23:00:51 2004 (41107B93)
bf9d3000 bfd09a80 nv4_disp Fri Apr 19 14:48:39 2002 (3CC090B7)
f6948000 f6988280 HTTP Thu Mar 16 16:33:09 2006 (441A03C5)
f6c89000 f6cda300 srv Mon May 09 17:17:49 2005 (427FFDAD)
f6df0000 f6e04400 wdmaud Tue Aug 03 23:15:03 2004 (41107EE7)
f6e2d000 f6e59400 mrxdav Tue Aug 03 23:00:49 2004 (41107B91)
f7073000 f7088580 irda Tue Aug 03 23:00:50 2004 (41107B92)
f7109000 f7117d80 sysaudio Tue Aug 03 23:15:54 2004 (41107F1A)
f71a5000 f71a8280 ndisuio Tue Aug 03 23:03:10 2004 (41107C1E)
f83ea000 f8401480 dump_atapi Tue Aug 03 22:59:41 2004 (41107B4D)
f842a000 f844af00 ipnat Wed Sep 29 15:28:36 2004 (415B3714)
f844b000 f84b9a00 mrxsmb Fri May 05 02:41:42 2006 (445B1DD6)
f84ba000 f84e4a00 rdbss Fri May 05 02:47:55 2006 (445B1F4B)
f84e5000 f8506d00 afd Tue Aug 03 23:14:13 2004 (41107EB5)
f8507000 f852ec00 netbt Tue Aug 03 23:14:36 2004 (41107ECC)
f852f000 f8586d80 tcpip Wed May 25 12:04:00 2005 (4294CC20)
f8587000 f8599400 ipsec Tue Aug 03 23:14:27 2004 (41107EC3)
f96af000 f96b1900 Dxapi Fri Aug 17 13:53:19 2001 (3B7D843F)
f96cb000 f96fe200 update Tue Aug 03 22:58:32 2004 (41107B08)
f96ff000 f9813b80 AGRSM Fri Jun 21 08:47:54 2002 (3D134AAA)
f9814000 f981cc00 isapnp Fri Aug 17 13:58:01 2001 (3B7D8559)
f9824000 f982e500 MountMgr Tue Aug 03 22:58:29 2004 (41107B05)
f9834000 f9840c80 VolSnap Tue Aug 03 23:00:14 2004 (41107B6E)
f9844000 f984ce00 disk Tue Aug 03 22:59:53 2004 (41107B59)
f9854000 f9860200 CLASSPNP Tue Aug 03 23:14:26 2004 (41107EC2)
f9864000 f986e580 agp440 Tue Aug 03 23:07:40 2004 (41107D2C)
f98b4000 f98bd480 NDProxy Fri Aug 17 13:55:30 2001 (3B7D84C2)
f98c4000 f98d2100 usbhub Tue Aug 03 23:08:40 2004 (41107D68)
f9924000 f992c700 netbios Tue Aug 03 23:03:19 2004 (41107C27)
f9944000 f994c880 Fips Fri Aug 17 18:31:49 2001 (3B7DC585)
f9954000 f995c700 wanarp Tue Aug 03 23:04:57 2004 (41107C89)
f9974000 f9983900 Cdfs Tue Aug 03 23:14:09 2004 (41107EB1)
f99e4000 f99ecd00 intelppm Tue Aug 03 22:59:19 2004 (41107B37)
f99f4000 f9a00e00 i8042prt Tue Aug 03 23:14:36 2004 (41107ECC)
f9a04000 f9a0e380 Imapi Tue Aug 03 23:00:12 2004 (41107B6C)
f9a14000 f9a20180 cdrom Tue Aug 03 22:59:52 2004 (41107B58)
f9a24000 f9a32080 redbook Tue Aug 03 22:59:34 2004 (41107B46)
f9a34000 f9a42b80 drmk Tue Aug 03 23:07:54 2004 (41107D3A)
f9a44000 f9a50880 rasl2tp Tue Aug 03 23:14:21 2004 (41107EBD)
f9a54000 f9a5e200 raspppoe Tue Aug 03 23:05:06 2004 (41107C92)
f9a64000 f9a6fd00 raspptp Tue Aug 03 23:14:26 2004 (41107EC2)
f9a74000 f9a7c900 msgpc Tue Aug 03 23:04:11 2004 (41107C5B)
f9a84000 f9a8df00 termdd Tue Aug 03 22:58:52 2004 (41107B1C)
f9a94000 f9a9a200 PCIIDEX Tue Aug 03 22:59:40 2004 (41107B4C)
f9a9c000 f9aa0900 PartMgr Fri Aug 17 18:32:23 2001 (3B7DC5A7)
f9aa4000 f9aa8080 PxHelp20 Fri Jan 03 14:10:17 2003 (3E160A49)
f9acc000 f9acd000 flpydisk unavailable (00000000)
f9ae4000 f9ae9200 vga Tue Aug 03 23:07:06 2004 (41107D0A)
f9aec000 f9af0a80 Msfs Tue Aug 03 23:00:37 2004 (41107B85)
f9af4000 f9afb880 Npfs Tue Aug 03 23:00:38 2004 (41107B86)
f9b0c000 f9b10500 watchdog Tue Aug 03 23:07:32 2004 (41107D24)
f9b44000 f9b49000 usbuhci Tue Aug 03 23:08:34 2004 (41107D62)
f9b4c000 f9b52000 kbdclass Tue Aug 03 22:58:32 2004 (41107B08)
f9b54000 f9b59a00 mouclass Tue Aug 03 22:58:32 2004 (41107B08)
f9b5c000 f9b5d000 fdc unavailable (00000000)
f9b64000 f9b6b580 Modem Tue Aug 03 23:08:04 2004 (41107D44)
f9b6c000 f9b70c80 rasirda Fri Aug 17 13:51:29 2001 (3B7D83D1)
f9b74000 f9b78880 TDI Tue Aug 03 23:07:47 2004 (41107D33)
f9b7c000 f9b80580 ptilink Fri Aug 17 13:49:53 2001 (3B7D8371)
f9b84000 f9b88080 raspti Fri Aug 17 13:55:32 2001 (3B7D84C4)
f9c24000 f9c27000 BOOTVID Fri Aug 17 13:49:09 2001 (3B7D8345)
f9c28000 f9c2a480 compbatt Fri Aug 17 13:57:58 2001 (3B7D8556)
f9c2c000 f9c2f700 BATTC Fri Aug 17 13:57:52 2001 (3B7D8550)
f9cc8000 f9cca280 rasacd Fri Aug 17 13:55:39 2001 (3B7D84CB)
f9ccc000 f9ccef00 ws2ifsl Fri Aug 17 13:55:58 2001 (3B7D84DE)
f9ce4000 f9ce6b80 IPFilter Thu Apr 11 11:47:22 2002 (3CB5DA3A)
f9cf4000 f9cf7700 CmBatt Tue Aug 03 23:07:39 2004 (41107D2B)
f9cfc000 f9cfe580 ndistapi Fri Aug 17 13:55:29 2001 (3B7D84C1)
f9d00000 f9d03c80 mssmbios Tue Aug 03 23:07:47 2004 (41107D33)
f9d14000 f9d15b80 kdcom Fri Aug 17 13:49:10 2001 (3B7D8346)
f9d16000 f9d17100 WMILIB Fri Aug 17 14:07:23 2001 (3B7D878B)
f9d18000 f9d19580 intelide Tue Aug 03 22:59:40 2004 (41107B4C)
f9d1a000 f9d1b4c0 TVALG Thu Sep 13 03:53:01 2001 (3BA0900D)
f9d1c000 f9d1d240 TVALD Thu Aug 16 22:23:56 2001 (3B7CAA6C)
f9d44000 f9d45100 swenum Tue Aug 03 22:58:41 2004 (41107B11)
f9d4c000 f9d4d000 ParVdm unavailable (00000000)
f9d54000 f9d55280 USBD Fri Aug 17 14:02:58 2001 (3B7D8682)
f9d6c000 f9d6d000 Fs_Rec unavailable (00000000)
f9d6e000 f9d6f080 Beep Fri Aug 17 13:47:33 2001 (3B7D82E5)
f9d70000 f9d71080 mnmdd Fri Aug 17 13:57:28 2001 (3B7D8538)
f9d72000 f9d73080 RDPCDD Fri Aug 17 13:46:56 2001 (3B7D82C0)
f9d78000 f9d79100 dump_WMILIB Fri Aug 17 14:07:23 2001 (3B7D878B)
f9e11000 f9e11c00 audstub Fri Aug 17 13:59:40 2001 (3B7D85BC)
f9e68000 f9e69000 Null unavailable (00000000)
f9ed9000 f9ed9d00 dxgthk Fri Aug 17 13:53:12 2001 (3B7D8438)
Unloaded modules:
f6d03000 f6d2d000 kmixer.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f9e07000 f9e08000 drmkaud.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f99b4000 f99c1000 DMusic.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f6dcd000 f6df0000 aec.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f729a000 f72a8000 swmidi.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f9d58000 f9d5a000 splitter.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f7159000 f7169000 Serial.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
f9934000 f993d000 processr.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
f9ad4000 f9ad9000 Cdaudio.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
f9cc4000 f9cc7000 Sfloppy.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
**************************
**********
**********
**********
**********
**********
***
* *
* Bugcheck Analysis *
* *
**************************
**********
**********
**********
**********
**********
***
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, f85bc80e, f71f8a20, 0}
Probably caused by : nv4_mini.sys ( nv4_mini!Legacy_dacTVConne
ctStatus+4
d0 )
Followup: MachineOwner
---------
Finished dump check
C:\program files\Debugging Tools for Windows>