Solved

How can I test for conflicts between two programs causing BSOD?

Posted on 2008-10-26
5
656 Views
Last Modified: 2013-12-12
Using Vista Business SP1... HP 8710 Laptop 2 G RAM 2.2 CPU

Recently installed update to Zone Alarm Internet Security Suite and immediately started getting BSOD.  Contected tech support and they suggested disabling all programs in start menu and non ms services then enabling five at a time to pinpoint what program ZA is conflicting with.   I tried doing that and after a whole day of restarts without any problem finally got a BSOD.   So I disabled the last five services again and lo and behold BSOD again.  Doesn't make sense.  Problem is it might take an hour or two before the BSOD happens, sometime just 10 or 15 minutes so it's a long time consuming processs of elimination.

Is there another way I can find out what might be conflicting with ZA.  The WinDbg Mini Dump follows... I sent this to ZA support but I'm not sure if it points to anything that might help.

Another note.. if I close down ZA , no BSOD at all.   Any help appreciated.  Just not sure whether I should be pressing ZA support to resolve the issue or it's my responsibility.


Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Minidump\Mini102708-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: set _NT_SYMBOL_PATH=srv*C:\Users\Allan\Downloads\symstore*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008 Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18145.x86fre.vistasp1_gdr.080917-1612
Kernel base = 0x8203f000 PsLoadedModuleList = 0x82156c70
Debug session time: Mon Oct 27 09:25:02.361 2008 (GMT+13)
System Uptime: 0 days 1:13:27.513
Loading Kernel Symbols
...................................................................................................................................................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 4A, {82275a63, 2, 0, 0}

Probably caused by : ntkrpamp.exe ( nt!NtDeviceIoControlFile+0 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a)
Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL.
Arguments:
Arg1: 82275a63, Address of system function (system call routine)
Arg2: 00000002, Current IRQL
Arg3: 00000000, 0
Arg4: 00000000, 0

Debugging Details:
------------------


PROCESS_NAME:  vsmon.exe

BUGCHECK_STR:  RAISED_IRQL_FAULT

FAULTING_IP:
nt!NtDeviceIoControlFile+0
82275a63 8bff            mov     edi,edi

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 774d9a94 to 82096d6d

STACK_TEXT:  
9d1d1d64 774d9a94 badb0d00 03aeea08 00000000 nt!KiServiceExit2+0x154
WARNING: Frame IP not in any known module. Following frames may be wrong.
03aeea60 00000000 00000000 00000000 00000000 0x774d9a94


STACK_COMMAND:  kb

FOLLOWUP_IP:
nt!NtDeviceIoControlFile+0
82275a63 8bff            mov     edi,edi

SYMBOL_NAME:  nt!NtDeviceIoControlFile+0

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  48d1b7fa

FAILURE_BUCKET_ID:  RAISED_IRQL_FAULT_vsmon.exe_nt!NtDeviceIoControlFile+0

BUCKET_ID:  RAISED_IRQL_FAULT_vsmon.exe_nt!NtDeviceIoControlFile+0

Followup: MachineOwner
---------  
0
Comment
Question by:inajam
  • 3
  • 2
5 Comments
 
LVL 32

Expert Comment

by:willcomp
ID: 22809214
PROCESS_NAME:  vsmon.exe ---> vsmon.exe is part of Zone Alarm. First thing to try is disabling Zone Alarm.
0
 

Author Comment

by:inajam
ID: 22809391
As I said, all is ok if I shut down Zone Alarm but it's no good to me shut down.  Their tech support said it's conflicting with another program... how do I determine what that program is without having to go through disabling each one in a tiral and error approach?  
0
 
LVL 32

Accepted Solution

by:
willcomp earned 500 total points
ID: 22809406
My best guess is that ZA is causing an error all by itself and there is no other program except Vista involved.
0
 

Author Comment

by:inajam
ID: 22936008
I've sent a complete dump to Zone Alarm support and am awaiting their reply.  Will post back when I get some response from them.
0
 

Author Comment

by:inajam
ID: 23118601
Zone Alarm tech support suggested I download and try the latest beta but that caused the same problem.   I think I'll just have to give it up.   Installed latest Norton Internet Security and it's so much faster loading, best of all, no bluescreens.  Cheers willcomp for responding... it must be a ZA fault.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

This article covers general Notes 8.5 troubleshooting information including recreating the Notes\Data folder.
I annotated my article on ransomware somewhat extensively, but I keep adding new references and wanted to put a link to the reference library.  Despite all the reference tools I have on hand, it was not easy to find a way to do this easily. I finall…
Using Adobe Premiere Pro, the viewer will learn how to set up a sequence with proper settings, importing pictures, rendering, and exporting the finished product.
The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now