LeonGarfield
asked on
BSOD 7F
After remove a lot of viruses I am receiving 2 different BSODs, 7F & 8E. Attached is a minidump file for the 7F BSOD.
The computer has WinXP SP2. I ran a memory test using Memtest86 and it didn't find any problems.
Can someone tell me what is causing the BSOD.
----- 32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 00039000
PfnDataBase 81b53000
PsLoadedModuleList 8055a620
PsActiveProcessHead 805606d8
MachineImageType 0000014c
NumberProcessors 00000001
BugCheckCode 0000007f
BugCheckParameter1 00000000
BugCheckParameter2 00000000
BugCheckParameter3 00000000
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 8054c260
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 0000047c
DriverListOffset 00003090
DriverCount 0000009f
StringPoolOffset 00005fc8
StringPoolSize 00001648
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack ed527b84
DebuggerDataOffset 00002e00
DebuggerDataSize 00000290
DataBlocksOffset 00007610
DataBlocksCount 00000004
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055a620
Debug session time: Sun Oct 14 12:40:16 2007
System Uptime: 0 days 0:31:14
start end module name
804d7000 806eb500 nt Checksum: 0021EF64 Timestamp: Wed Feb 28 01:10:41 2007 (45E54711)
Unloaded modules:
ec0ff000 ec112000 NAVENG.SYS Timestamp: unavailable (00000000)
ec112000 ec1e4000 NAVEX15.SYS Timestamp: unavailable (00000000)
ed909000 ed934000 SymIDSCo.sys Timestamp: unavailable (00000000)
f7a11000 f7a1b000 SRTSPX.SYS Timestamp: unavailable (00000000)
edb0c000 edb55000 SRTSP.SYS Timestamp: unavailable (00000000)
eda27000 eda3a000 NAVENG.SYS Timestamp: unavailable (00000000)
eda3a000 edb0c000 NAVEX15.SYS Timestamp: unavailable (00000000)
ec4d0000 ec4fb000 kmixer.sys Timestamp: unavailable (00000000)
ed8b9000 ed8c0000 DDMI2.sys Timestamp: unavailable (00000000)
ed8e1000 ed8e8000 DDMI2.sys Timestamp: unavailable (00000000)
ed8c1000 ed8c8000 DDMI2.sys Timestamp: unavailable (00000000)
f7b91000 f7b98000 DDMI2.sys Timestamp: unavailable (00000000)
f7b19000 f7b20000 DDMI2.sys Timestamp: unavailable (00000000)
ed8f9000 ed900000 DDMI2.sys Timestamp: unavailable (00000000)
ec4d0000 ec4fb000 kmixer.sys Timestamp: unavailable (00000000)
ecf1b000 ecf46000 kmixer.sys Timestamp: unavailable (00000000)
f7de2000 f7de3000 drmkaud.sys Timestamp: unavailable (00000000)
ed0e6000 ed0f3000 DMusic.sys Timestamp: unavailable (00000000)
ecf96000 ecfb9000 aec.sys Timestamp: unavailable (00000000)
ed0f6000 ed104000 swmidi.sys Timestamp: unavailable (00000000)
f7da7000 f7da9000 splitter.sys Timestamp: unavailable (00000000)
f7891000 f789b000 asc3550p.SYS Timestamp: unavailable (00000000)
f7a81000 f7a8a000 processr.sys Timestamp: unavailable (00000000)
f7a71000 f7a7c000 p3.sys Timestamp: unavailable (00000000)
f7cbd000 f7cc1000 kbdhid.sys Timestamp: unavailable (00000000)
f7c19000 f7c1e000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7ca5000 f7ca8000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
The computer has WinXP SP2. I ran a memory test using Memtest86 and it didn't find any problems.
Can someone tell me what is causing the BSOD.
----- 32 bit Kernel Mini Dump Analysis
DUMP_HEADER32:
MajorVersion 0000000f
MinorVersion 00000a28
DirectoryTableBase 00039000
PfnDataBase 81b53000
PsLoadedModuleList 8055a620
PsActiveProcessHead 805606d8
MachineImageType 0000014c
NumberProcessors 00000001
BugCheckCode 0000007f
BugCheckParameter1 00000000
BugCheckParameter2 00000000
BugCheckParameter3 00000000
BugCheckParameter4 00000000
PaeEnabled 00000000
KdDebuggerDataBlock 8054c260
MiniDumpFields 00000dff
TRIAGE_DUMP32:
ServicePackBuild 00000200
SizeOfDump 00010000
ValidOffset 0000fffc
ContextOffset 00000320
ExceptionOffset 000007d0
MmOffset 00001068
UnloadedDriversOffset 000010a0
PrcbOffset 00001878
ProcessOffset 000024c8
ThreadOffset 00002728
CallStackOffset 00002980
SizeOfCallStack 0000047c
DriverListOffset 00003090
DriverCount 0000009f
StringPoolOffset 00005fc8
StringPoolSize 00001648
BrokenDriverOffset 00000000
TriageOptions 00000041
TopOfStack ed527b84
DebuggerDataOffset 00002e00
DebuggerDataSize 00000290
DataBlocksOffset 00007610
DataBlocksCount 00000004
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055a620
Debug session time: Sun Oct 14 12:40:16 2007
System Uptime: 0 days 0:31:14
start end module name
804d7000 806eb500 nt Checksum: 0021EF64 Timestamp: Wed Feb 28 01:10:41 2007 (45E54711)
Unloaded modules:
ec0ff000 ec112000 NAVENG.SYS Timestamp: unavailable (00000000)
ec112000 ec1e4000 NAVEX15.SYS Timestamp: unavailable (00000000)
ed909000 ed934000 SymIDSCo.sys Timestamp: unavailable (00000000)
f7a11000 f7a1b000 SRTSPX.SYS Timestamp: unavailable (00000000)
edb0c000 edb55000 SRTSP.SYS Timestamp: unavailable (00000000)
eda27000 eda3a000 NAVENG.SYS Timestamp: unavailable (00000000)
eda3a000 edb0c000 NAVEX15.SYS Timestamp: unavailable (00000000)
ec4d0000 ec4fb000 kmixer.sys Timestamp: unavailable (00000000)
ed8b9000 ed8c0000 DDMI2.sys Timestamp: unavailable (00000000)
ed8e1000 ed8e8000 DDMI2.sys Timestamp: unavailable (00000000)
ed8c1000 ed8c8000 DDMI2.sys Timestamp: unavailable (00000000)
f7b91000 f7b98000 DDMI2.sys Timestamp: unavailable (00000000)
f7b19000 f7b20000 DDMI2.sys Timestamp: unavailable (00000000)
ed8f9000 ed900000 DDMI2.sys Timestamp: unavailable (00000000)
ec4d0000 ec4fb000 kmixer.sys Timestamp: unavailable (00000000)
ecf1b000 ecf46000 kmixer.sys Timestamp: unavailable (00000000)
f7de2000 f7de3000 drmkaud.sys Timestamp: unavailable (00000000)
ed0e6000 ed0f3000 DMusic.sys Timestamp: unavailable (00000000)
ecf96000 ecfb9000 aec.sys Timestamp: unavailable (00000000)
ed0f6000 ed104000 swmidi.sys Timestamp: unavailable (00000000)
f7da7000 f7da9000 splitter.sys Timestamp: unavailable (00000000)
f7891000 f789b000 asc3550p.SYS Timestamp: unavailable (00000000)
f7a81000 f7a8a000 processr.sys Timestamp: unavailable (00000000)
f7a71000 f7a7c000 p3.sys Timestamp: unavailable (00000000)
f7cbd000 f7cc1000 kbdhid.sys Timestamp: unavailable (00000000)
f7c19000 f7c1e000 Cdaudio.SYS Timestamp: unavailable (00000000)
f7ca5000 f7ca8000 Sfloppy.SYS Timestamp: unavailable (00000000)
Finished dump check
At what point are you getting the BSOD?
ASKER
when I am using the computer. No specific program is being used.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
0x0000007F: UNEXPECTED_KERNEL_MODE_TRA P
http://aumha.org/a/stop.htm
<Quote> One of three types of problems occurred in kernel-mode: (1) Hardware failures. (2) Software problems. (3) A bound trap (i.e., a condition that the kernel is not allowed to have or intercept). Hardware failures are the most common cause (many dozen KB articles exist for this error referencing specific hardware failures) and, of these, memory hardware failures are the most common <Unquote>
This is the present recommended RAM Tester, but no tester can guarantee confirming a RAM issue. Maybe you could consider exchanging (swopout) the RAM(s) >>
memtest86+ v1.70 :
http://www.memtest.org/
Or follow the advice in the "aumha" link.
http://aumha.org/a/stop.htm
<Quote> One of three types of problems occurred in kernel-mode: (1) Hardware failures. (2) Software problems. (3) A bound trap (i.e., a condition that the kernel is not allowed to have or intercept). Hardware failures are the most common cause (many dozen KB articles exist for this error referencing specific hardware failures) and, of these, memory hardware failures are the most common <Unquote>
This is the present recommended RAM Tester, but no tester can guarantee confirming a RAM issue. Maybe you could consider exchanging (swopout) the RAM(s) >>
memtest86+ v1.70 :
http://www.memtest.org/
Or follow the advice in the "aumha" link.
Oops .. some late post duplication ..
Actually - the best idea is to check with MemTest+ (as I stated) - then verify with the Windows Memory Diagnostic: http://oca.microsoft.com/en/windiag.asp
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I already ran memtest86 and it didn't report any errors. Supposedly before I removed the viruses there were not BSOD. Only after I cleaned up the computer did the BDOS start to appear. So I don't think it is a physical memory issue. But I will try running another memory test and I will try chkdsk.
I also already ran System File Checker to replace any corrupted system files..
I also already ran System File Checker to replace any corrupted system files..
If there is still malware on the computer - running a repair install is not recommended - and ultimately will not fix the problem.
If there IS still a virus problem, in addition you could try these two free virus scanners. No one scanner can guarantee finding & fixing everything ...
AVG Antivirus Free 7.5.488 >>
http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10645435.html
and ...
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
If you have a Trojan, please be aware that a number of scanners will detect a rootkit(a type of Trojan) but few will cleanly remove them.
The Sophos scanner comes with an excellent recommendation, you simply have to register (for a Home version) and it's free.
Certainly worth trying, it could neatly resolve your problem >
Sophos Anti-Rootkit Version 1.3.1
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
AVG Antivirus Free 7.5.488 >>
http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10645435.html
and ...
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
If you have a Trojan, please be aware that a number of scanners will detect a rootkit(a type of Trojan) but few will cleanly remove them.
The Sophos scanner comes with an excellent recommendation, you simply have to register (for a Home version) and it's free.
Certainly worth trying, it could neatly resolve your problem >
Sophos Anti-Rootkit Version 1.3.1
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
Another option if you are not comfortable registering the Sophos scanner above is ...
RootkitRevealer v1.71
http://www.microsoft.com/technet/sysinternals/utilities/RootKitRevealer.mspx
RootkitRevealer v1.71
http://www.microsoft.com/technet/sysinternals/utilities/RootKitRevealer.mspx
ASKER
The solution was to reinstall Windows. It seems that the viruses messed up Windows enough to require a fresh install.
Apologies that the solution wasn't ideal.
Thanks in any case.
Thanks in any case.