Bsod ws 8.1 irql not less or equal / kmode except

Philadelzia

New Member
Messages
3
Hello,

i built my computer, and since i got several differents bsod. Never the same

-KMODE EXCEPT
-IRQL NOT LESS OR EQUAL
-NTFS FILE SYSTEM

and some other ...

They can happend during a game (league of legend / watch_dogs), while skypping with friend or just when i'm browsing.

I already did a Memtest,ok OCCT test, temps are ok.

I joined the .zip of the debugger, i hope it'll help solving this annyoing problem.

Ask me if you need more information.


==================================================Dump File : 070714-4921-01.dmp
Crash Time : 07/07/2014 23:56:20
Bug Check String : NTFS_FILE_SYSTEM
Bug Check Code : 0x00000024
Parameter 1 : 000000b5`00190637
Parameter 2 : ffffd000`21dccef8
Parameter 3 : ffffd000`21dcc700
Parameter 4 : fffff800`ef0c6e79
Caused By Driver : Ntfs.sys
Caused By Address : Ntfs.sys+324b7
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1500a0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\070714-4921-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 9600
Dump File Size : 302 720
Dump File Time : 07/07/2014 23:56:54
==================================================


==================================================
Dump File : 070614-4859-01.dmp
Crash Time : 06/07/2014 22:06:58
Bug Check String : KMODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x0000001e
Parameter 1 : ffffffff`c0000005
Parameter 2 : fffff800`0276dd98
Parameter 3 : 00000000`00000000
Parameter 4 : ffffffff`ffffffff
Caused By Driver : Wdf01000.sys
Caused By Address : Wdf01000.sys+350d4
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1500a0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\070614-4859-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 9600
Dump File Size : 333 056
Dump File Time : 06/07/2014 22:07:31
==================================================


==================================================
Dump File : 070614-5421-01.dmp
Crash Time : 06/07/2014 19:26:43
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 00000000`00000057
Parameter 2 : 00000000`00000002
Parameter 3 : 00000000`00000000
Parameter 4 : fffff801`1c31057a
Caused By Driver : Wdf01000.sys
Caused By Address : Wdf01000.sys+6d43
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1500a0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\070614-5421-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 9600
Dump File Size : 302 648
Dump File Time : 06/07/2014 19:27:16
==================================================


==================================================
Dump File : 070614-8546-01.dmp
Crash Time : 06/07/2014 15:35:48
Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x000000d1
Parameter 1 : 000007fe`f64245f0
Parameter 2 : 00000000`00000002
Parameter 3 : 00000000`00000000
Parameter 4 : fffff800`00340413
Caused By Driver : Wdf01000.sys
Caused By Address : Wdf01000.sys+1b413
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1500a0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\070614-8546-01.dmp
Processors Count : 8
Major Version : 15
Minor Version : 9600
Dump File Size : 286 192
Dump File Time : 06/07/2014 15:36:20
==================================================
 

My Computer

System One

  • OS
    8.1
No Windows Updates installed. Most systems have 160 or more. Please visit Windows Update and get ALL available updates (it may take several trips to get them all).

Don't worry about the specific number, it's just important that you have checked and installed any updates that were available.

You have a Surf Wireless Micro USB Adapter:
I do not recommend using wireless USB network devices. Especially in Win8/8.1 systems.
These wireless USB devices have many issues with Win7 and later - using Vista drivers with them is almost sure to cause a BSOD.
Should you want to keep using these devices, be sure to have Win8/8.1 drivers - DO NOT use Vista drivers!!!
An installable wireless PCI/PCIe card that's plugged into your motherboard is much more robust, reliable, and powerful.

Of the 4 latest memory dumps, the only one to blame a 3rd party driver is the earliest one that blames rzudd.sys - a driver for your Razer Synapse. I would suggest:
- uninstalling the Razer drivers
- removing the Razer keyboard and mouse
- test with a regular keyboard and mouse

If you don't have another keyboard and mouse, please uninstall the Razer drivers and then download/install a fresh set from the Razer website.

If you have the Corsair Link software installed, please uninstall it. It's known to cause BSOD's on some Windows systems.

As there were random BSOD errors, it can also be a hardware problem. Please start with these free hardware diagnostics: Hardware Diagnostics

Please update these older drivers. Links are included to assist in looking up the source of the drivers. If unable to find an update, please remove (un-install) the program responsible for that driver. DO NOT manually delete/rename the driver as it may make the system unbootable! :

CAHS164.sys Thu Jun 16 03:10:06 2011 (4DF9AC4E)
C-Media Electronics USB Audio Driver
http://www.carrona.org/drivers/driver.php?id=CAHS164.sys

If all of this doesn't stop the BSOD's, please run Driver Verifier according to these instructions: Driver Verifier Settings



Analysis:
The following is for informational purposes only.
Code:
[font=lucida console]**************************Mon Jul  7 17:56:20.161 2014 (UTC - 4:00)**************************
Loading Dump File [C:\Users\John\SysnativeBSODApps\070714-4921-01.dmp]
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Built by: [B]9600[/B].16384.amd64fre.winblue_rtm.130821-1623
System Uptime:[B]1 days 1:48:53.517[/B]
Probably caused by :[B]memory_corruption ( nt!MiOffsetToProtos+99 )[/B]
BugCheck [B]24, {b500190637, ffffd00021dccef8, ffffd00021dcc700, fffff800ef0c6e79}[/B]
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x00000024]NTFS_FILE_SYSTEM (24)[/url]
Arguments: 
Arg1: 000000b500190637
Arg2: ffffd00021dccef8
Arg3: ffffd00021dcc700
Arg4: fffff800ef0c6e79
PROCESS_NAME:  svchost.exe
BUGCHECK_STR:  0x24
DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
FAILURE_BUCKET_ID: [B]0x24_nt!MiOffsetToProtos[/B]
CPUID:        "Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz"
MaxSpeed:     3500
CurrentSpeed: [B]3492[/B]
  BIOS Version                  F3
  BIOS Release Date             04/16/2013
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product Name                  Z87X-D3H
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Jul  6 16:06:58.910 2014 (UTC - 4:00)**************************
Loading Dump File [C:\Users\John\SysnativeBSODApps\070614-4859-01.dmp]
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Built by: [B]9600[/B].16384.amd64fre.winblue_rtm.130821-1623
System Uptime:[B]0 days 2:39:47.536[/B]
*** ERROR: Module load completed but symbols could not be loaded for USBXHCI.SYS
*** ERROR: Module load completed but symbols could not be loaded for Wdf01000.sys
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by :[B]USBXHCI.SYS ( USBXHCI+fd98 )[/B]
BugCheck [B]1E, {ffffffffc0000005, fffff8000276dd98, 0, ffffffffffffffff}[/B]
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000001E]KMODE_EXCEPTION_NOT_HANDLED (1e)[/url]
Arguments: 
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000276dd98, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
BUGCHECK_STR:  0x1E_c0000005_R
PROCESS_NAME:  System
FAILURE_BUCKET_ID: [B]0x1E_c0000005_R_USBXHCI+fd98[/B]
CPUID:        "Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz"
MaxSpeed:     3500
CurrentSpeed: [B]3492[/B]
  BIOS Version                  F3
  BIOS Release Date             04/16/2013
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product Name                  Z87X-D3H
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Jul  6 13:26:43.183 2014 (UTC - 4:00)**************************
Loading Dump File [C:\Users\John\SysnativeBSODApps\070614-5421-01.dmp]
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Built by: [B]9600[/B].16384.amd64fre.winblue_rtm.130821-1623
System Uptime:[B]0 days 2:24:36.412[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!KiRetireDpcList+54a )[/B]
BugCheck [B]A, {57, 2, 0, fffff8011c31057a}[/B]
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000000A]IRQL_NOT_LESS_OR_EQUAL (a)[/url]
Arguments: 
Arg1: 0000000000000057, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8011c31057a, address which referenced memory
BUGCHECK_STR:  AV
DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
PROCESS_NAME:  System
FAILURE_BUCKET_ID: [B]AV_nt!KiRetireDpcList[/B]
CPUID:        "Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz"
MaxSpeed:     3500
CurrentSpeed: [B]3492[/B]
  BIOS Version                  F3
  BIOS Release Date             04/16/2013
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product Name                  Z87X-D3H
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Jul  6 09:35:48.188 2014 (UTC - 4:00)**************************
Loading Dump File [C:\Users\John\SysnativeBSODApps\070614-8546-01.dmp]
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Built by: [B]9600[/B].16384.amd64fre.winblue_rtm.130821-1623
System Uptime:[B]0 days 0:19:05.821[/B]
*** ERROR: Module load completed but symbols could not be loaded for Wdf01000.sys
*** WARNING: Unable to verify timestamp for rzudd.sys
*** ERROR: Module load completed but symbols could not be loaded for rzudd.sys
Probably caused by :[B]rzudd.sys ( rzudd+7f10 )[/B]
BugCheck [B]D1, {7fef64245f0, 2, 0, fffff80000340413}[/B]
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x000000D1]DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)[/url]
Arguments: 
Arg1: 000007fef64245f0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff80000340413, address which referenced memory
BUGCHECK_STR:  AV
DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
PROCESS_NAME:  System
FAILURE_BUCKET_ID: [B]AV_rzudd+7f10[/B]
CPUID:        "Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz"
MaxSpeed:     3500
CurrentSpeed: [B]3492[/B]
  BIOS Version                  F3
  BIOS Release Date             04/16/2013
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product Name                  Z87X-D3H
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
[/font]

3rd Party Drivers:
The following is for information purposes only.
Any drivers in red should be updated or removed from your system. And should have been discussed in the body of my post.
Code:
[font=lucida console]**************************Mon Jul  7 17:56:20.161 2014 (UTC - 4:00)**************************
rtwlanu.sys                 Wed Jul 10 10:48:31 2013 (51DD743F)
intelppm.sys                Thu Aug 22 04:46:35 2013 (5215CFEB)
dump_storahci.sys           Thu Aug 22 07:40:39 2013 (5215F8B7)
TeeDriverx64.sys            Wed Nov 27 12:56:32 2013 (52963250)
nvhda64v.sys                Thu Nov 28 08:38:09 2013 (52974741)
corsveng2kamd64.sys         Mon Feb  3 13:42:16 2014 (52EFE308)
iwdbus.sys                  Thu Mar 13 17:59:14 2014 (53222A32)
e1d64x64.sys                Fri Mar 14 14:10:25 2014 (53234611)
nvvad64v.sys                Fri Mar 28 09:32:06 2014 (533579D6)
igdkmd64.sys                Sat May 17 00:17:35 2014 (5376E2DF)
rzudd.sys                   Mon May 19 02:43:44 2014 (5379A820)
rzvkeyboard.sys             Mon May 19 02:43:57 2014 (5379A82D)
rzdaendpt.sys               Mon May 19 02:44:07 2014 (5379A837)
nvlddmkm.sys                Mon May 19 19:08:44 2014 (537A8EFC)
NvStreamKms.sys             Thu May 22 12:43:14 2014 (537E2922)
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Jul  6 09:35:48.188 2014 (UTC - 4:00)**************************
[COLOR=RED][B]CAHS164.sys                 Thu Jun 16 03:10:06 2011 (4DF9AC4E)[/B][/COLOR]
e1i63x64.sys                Wed Mar 20 03:37:29 2013 (51496739)
NvStreamKms.sys             Tue Apr 29 20:59:44 2014 (53604B00)
[/font]
http://www.carrona.org/drivers/driver.php?id=rtwlanu.sys
http://www.carrona.org/drivers/driver.php?id=intelppm.sys
http://www.carrona.org/drivers/driver.php?id=dump_storahci.sys
http://www.carrona.org/drivers/driver.php?id=TeeDriverx64.sys
http://www.carrona.org/drivers/driver.php?id=nvhda64v.sys
corsveng2kamd64.sys - this driver hasn't been added to the DRT as of this run. Please search Google/Bing for the driver if additional information is needed.
http://www.carrona.org/drivers/driver.php?id=iwdbus.sys
http://www.carrona.org/drivers/driver.php?id=e1d64x64.sys
http://www.carrona.org/drivers/driver.php?id=nvvad64v.sys
http://www.carrona.org/drivers/driver.php?id=igdkmd64.sys
http://www.carrona.org/drivers/driver.php?id=rzudd.sys
http://www.carrona.org/drivers/driver.php?id=rzvkeyboard.sys
http://www.carrona.org/drivers/driver.php?id=rzdaendpt.sys
http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys
http://www.carrona.org/drivers/driver.php?id=NvStreamKms.sys
http://www.carrona.org/drivers/driver.php?id=CAHS164.sys
http://www.carrona.org/drivers/driver.php?id=e1i63x64.sys
http://www.carrona.org/drivers/driver.php?id=NvStreamKms.sys
 

My Computer

System One

  • OS
    Win8.1Pro - Finally!!!
    Computer type
    Laptop
    System Manufacturer/Model
    Samsung/NP780
    CPU
    Came with the laptop (i7 of some sort)
    Motherboard
    Pretty sure that it has one, but haven't checked inside the case!
    Memory
    upgraded to 12 gB from 8 gB
    Graphics Card(s)
    has switchable - Intel/ATI - Used wrong drivers, now ATI card is inop :( Will have to fix it soon!
    Sound Card
    I'm nearly deaf, so this isn't used often
    Monitor(s) Displays
    Touchscreen on laptop/32" Toshiba on HDMI (laid the Sharp TV on a mouse and cracked the screen!)
    Screen Resolution
    800x600
    Hard Drives
    One Samsung 1tB drive - 5400 rpm. Gonna switch to a 7200/10000 rpm or an SSD (if I can find $500 for a 1tB SSD!)
    - Switched to 500 gB Samsung 840 series SSD - WOW!!!
    PSU
    Why do we ask this for laptops?
    Case
    Silver with a neat Samsung logo
    Cooling
    sub-par, gotta get around to working on it soon Worked on it - still sub-par! :(
    Keyboard
    Microsoft Natural - the same one I've used since it orignally came out around 1995
    Mouse
    no Mouse - Trackball!!!!
    Internet Speed
    too slow when I'm waiting for a download to finish
    Browser
    Yes, I use this (Firefox mostly, w/IE next most)
    Antivirus
    Windows Defender and Windows Firewall
    Other Info
    I'm handsome and a snappy dresser :0)
Memory dump crashes my debugger. Please re-upload a fresh copy (or two if you can).

Late for work, gotta run......
 

My Computer

System One

  • OS
    Win8.1Pro - Finally!!!
    Computer type
    Laptop
    System Manufacturer/Model
    Samsung/NP780
    CPU
    Came with the laptop (i7 of some sort)
    Motherboard
    Pretty sure that it has one, but haven't checked inside the case!
    Memory
    upgraded to 12 gB from 8 gB
    Graphics Card(s)
    has switchable - Intel/ATI - Used wrong drivers, now ATI card is inop :( Will have to fix it soon!
    Sound Card
    I'm nearly deaf, so this isn't used often
    Monitor(s) Displays
    Touchscreen on laptop/32" Toshiba on HDMI (laid the Sharp TV on a mouse and cracked the screen!)
    Screen Resolution
    800x600
    Hard Drives
    One Samsung 1tB drive - 5400 rpm. Gonna switch to a 7200/10000 rpm or an SSD (if I can find $500 for a 1tB SSD!)
    - Switched to 500 gB Samsung 840 series SSD - WOW!!!
    PSU
    Why do we ask this for laptops?
    Case
    Silver with a neat Samsung logo
    Cooling
    sub-par, gotta get around to working on it soon Worked on it - still sub-par! :(
    Keyboard
    Microsoft Natural - the same one I've used since it orignally came out around 1995
    Mouse
    no Mouse - Trackball!!!!
    Internet Speed
    too slow when I'm waiting for a download to finish
    Browser
    Yes, I use this (Firefox mostly, w/IE next most)
    Antivirus
    Windows Defender and Windows Firewall
    Other Info
    I'm handsome and a snappy dresser :0)
I've looked into the memory dump that you've provided, FWIW - it's not a Driver Verifier enabled memory dump.
The only things that stand out are:
- presence of nVidia video drivers in the raw stack text
- presence of storage controller drivers (once) just prior to the nVidia drivers (Intel Rapid Storage Technology (RST) drivers) in the raw stack text. It has symbols problems and it's actually the dump_ version that's listed (this is the version that Windows makes when it boots - it is used during crashes)
- the presence of hal.dll in the raw stack text (may/may not be significant)
- one 2006 driver in the memory dump output (secdrv.sys) - this should have been updated to a 2013 version with the latest Windows Updates
- the presence of WinDivert.sys in the unloaded modules list. I mention it as I haven't seen it before. More info on it here: WinDivert 1.1: Windows Packet Divert

As Driver Verifier was running when this memory dump occurred, it's less likely that a 3rd party driver has caused this (although compatibility issues are different from driver issues - and may not be revealed by Driver Verifier).
That means that it's more likely that this is either a hardware problem, or a Windows problem.
But my gut says there's an incompatibility here.

So, in short, I'd:
- remove WinDivert and the program that's using it (there's a list near the bottom of the link I provided earlier)
- replace the current nVidia video drivers and the Intel RST drivers with the latest, Win8.1 versions
This means - download a fresh version, uninstall the current version, then install the freshly downloaded version
- ensure that you have ALL Windows Updates (in order to update the 2006 secdrv.sys driver)
- replace your Intel network adapter drivers (as they may be affected by the WinDivert stuff)
This means - download a fresh version, uninstall the current version, then install the freshly downloaded version

If that doesn't work, then it's either hardware diagnostics or a reinstall of Windows

Hardware Diagnostics:
- Hardware Diagnostics
- Hardware Stripdown Troubleshooting

Windows reinstall:
- try a RESET of Windows first
- Then try Canned Speeches
This was written for Win7, modify it as needed for Win8/8.1
The point here is to wipe the hard drive clean BEFORE reinstalling Windows - that way you're sure that everything on the hard drive is a new copy (and the old, corrupted stuff is wiped out).

This is the info from the debugger - it's FYI only:
Code:
Microsoft (R) Windows Debugger Version 6.3.9600.16384 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\John\SysnativeBSODApps\MEMORY.DMP]
Kernel Bitmap Dump File: Only kernel address space is available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Deferred                                       srv*c:\SymcachePublic*http://ctxsym.citrix.com/symbolsad/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols;srv*c:\SymcachePublic*http://ctxsym.citrix.com/symbolsad/symbols
Executable search path is: 
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17085.amd64fre.winblue_gdr.140330-1035
Machine Name:
Kernel base = 0xfffff801`f1a1a000 PsLoadedModuleList = 0xfffff801`f1ce42d0
Debug session time: Sat Aug  2 06:40:33.394 2014 (UTC - 4:00)
System Uptime: 0 days 12:29:10.199
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00007ff5`ffff8018).  Type ".hh dbgerr001" for details
Loading unloaded module list
..............
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff801f1e1d821, ffffd00020b62ee0, 0}

Probably caused by : memory_corruption ( nt!MmQueryVirtualMemory+715 )

Followup: MachineOwner
---------

6: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff801f1e1d821, Address of the instruction which caused the bugcheck
Arg3: ffffd00020b62ee0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
nt!MmQueryVirtualMemory+715
fffff801`f1e1d821 483910          cmp     qword ptr [rax],rdx

CONTEXT:  ffffd00020b62ee0 -- (.cxr 0xffffd00020b62ee0;r)
rax=fdffe00127ea9f80 rbx=0000000000000001 rcx=0000000000000000
rdx=ffffe00127e951a0 rsi=000000dbdccbcb00 rdi=ffffd00020b63aa8
rip=fffff801f1e1d821 rsp=ffffd00020b63910 rbp=ffffd00020b63b80
 r8=0000000000000160  r9=0000000000000162 r10=0000000000000160
r11=ffffd00057331900 r12=0000000000162000 r13=0000000000000030
r14=00007ffffffdffff r15=ffffe00127de0900
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!MmQueryVirtualMemory+0x715:
fffff801`f1e1d821 483910          cmp     qword ptr [rax],rdx ds:002b:fdffe001`27ea9f80=????????????????
Last set context:
rax=fdffe00127ea9f80 rbx=0000000000000001 rcx=0000000000000000
rdx=ffffe00127e951a0 rsi=000000dbdccbcb00 rdi=ffffd00020b63aa8
rip=fffff801f1e1d821 rsp=ffffd00020b63910 rbp=ffffd00020b63b80
 r8=0000000000000160  r9=0000000000000162 r10=0000000000000160
r11=ffffd00057331900 r12=0000000000162000 r13=0000000000000030
r14=00007ffffffdffff r15=ffffe00127de0900
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!MmQueryVirtualMemory+0x715:
fffff801`f1e1d821 483910          cmp     qword ptr [rax],rdx ds:002b:fdffe001`27ea9f80=????????????????
Resetting default scope

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  IPROSetMonitor

CURRENT_IRQL:  0

ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre

LAST_CONTROL_TRANSFER:  from fffff801f1e1d106 to fffff801f1e1d821

STACK_TEXT:  
ffffd000`20b63910 fffff801`f1e1d106 : 000000db`dd4d4500 fffff801`f1e07b8f ffffe001`29673580 000000db`dccbca38 : nt!MmQueryVirtualMemory+0x715
ffffd000`20b63a40 fffff801`f1b797b3 : ffffe001`2965e828 ffffd000`20b63ad8 fffff6fb`7dbed008 fffff6fb`7da01b78 : nt!NtQueryVirtualMemory+0x22
ffffd000`20b63a90 00007ffb`c87caf3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
000000db`dccbca98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`c87caf3a


FOLLOWUP_IP: 
nt!MmQueryVirtualMemory+715
fffff801`f1e1d821 483910          cmp     qword ptr [rax],rdx

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!MmQueryVirtualMemory+715

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  53388e13

STACK_COMMAND:  .cxr 0xffffd00020b62ee0 ; kb

IMAGE_NAME:  memory_corruption

BUCKET_ID_FUNC_OFFSET:  715

FAILURE_BUCKET_ID:  0x3B_nt!MmQueryVirtualMemory

BUCKET_ID:  0x3B_nt!MmQueryVirtualMemory

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0x3b_nt!mmqueryvirtualmemory

FAILURE_ID_HASH:  {f6bf0ba7-772a-0671-b2f8-836197d9931a}

Followup: MachineOwner
---------

6: kd> !niemiro.rawstack
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
0xffffd000`20b60a88  0xfffff801`822de3d3 nvlddmkm!+0x1ed3d3
0xffffd000`20b60a98  0xfffff801`8230374e nvlddmkm+0x21274e
0xffffd000`20b60ab8  0xfffff801`822de3d3 nvlddmkm+0x1ed3d3
0xffffd000`20b60ac8  0xfffff801`8230374e nvlddmkm+0x21274e
0xffffd000`20b60af8  0xfffff801`822de7ba nvlddmkm+0x1ed7ba
0xffffd000`20b60b28  0xfffff801`82304b67 nvlddmkm+0x213b67
0xffffd000`20b60b68  0xfffff801`822bcdf0 nvlddmkm+0x1cbdf0
0xffffd000`20b60b98  0xfffff801`82309fcd nvlddmkm+0x218fcd
0xffffd000`20b60c08  0xfffff801`8243a1c3 nvlddmkm+0x3491c3
0xffffd000`20b60c48  0xfffff801`8243a29e nvlddmkm+0x34929e
0xffffd000`20b60c78  0xfffff801`822de3d3 nvlddmkm+0x1ed3d3
0xffffd000`20b60c88  0xfffff801`8230374e nvlddmkm+0x21274e
0xffffd000`20b60ca8  0xfffff801`822de3d3 nvlddmkm+0x1ed3d3
0xffffd000`20b60cb8  0xfffff801`8230374e nvlddmkm+0x21274e
0xffffd000`20b60ce8  0xfffff801`822de7ba nvlddmkm+0x1ed7ba
0xffffd000`20b60d18  0xfffff801`82304b67 nvlddmkm+0x213b67
0xffffd000`20b60d58  0xfffff801`822bcdf0 nvlddmkm+0x1cbdf0
0xffffd000`20b60d88  0xfffff801`82309fcd nvlddmkm+0x218fcd
0xffffd000`20b60df8  0xfffff801`8243a1c3 nvlddmkm+0x3491c3
0xffffd000`20b60e38  0xfffff801`8243a29e nvlddmkm+0x34929e
0xffffd000`20b60e78  0xfffff801`8256124c nvlddmkm+0x47024c
0xffffd000`20b60eb8  0xfffff801`82561551 nvlddmkm+0x470551
0xffffd000`20b60ef8  0xfffff801`823dd3cd nvlddmkm+0x2ec3cd
*** ERROR: Module load completed but symbols could not be loaded for dump_iaStorA.sys
0xffffd000`20b60f18  0xfffff801`816d1126 c0000005 Exception in niemiro.rawstack debugger extension.
      PC: 00000000`76bdc220  VA: 000000f2`3a5f2ffc  R/W: 0  Parameter: 00000000`00000000
6: kd> !procdumpext.dpx
=========================================================================================
 ProcDumpExt v6.4 - Copyright 2013 Andrew Richards
=========================================================================================
Start memory scan  : 0xffffd00020b62628 ($csp)
End memory scan    : 0xffffd00020b64000 (Stack Base)

               rsp : 0xffffd00020b62628 : 0xfffff801f1b79ae9 : nt!KiBugCheckDispatch+0x69
0xffffd00020b62628 : 0xfffff801f1b79ae9 : nt!KiBugCheckDispatch+0x69
0xffffd00020b62640 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b62708 : 0xfffff801f1e2486d : nt!CmpDeleteKeyObject+0x32d
0xffffd00020b62728 : 0xfffff801f1caf59e : nt!ExFreePoolWithTag+0x2be
0xffffd00020b62758 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b62768 : 0xfffff801f1b793fc : nt!KiSystemServiceHandler+0x7c
0xffffd00020b62770 : 0xffffd00020b62860 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b62778 : 0xfffff801f1b6a886 : nt!_GSHandlerCheck_SEH+0x76
0xffffd00020b627a0 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b627a8 : 0xfffff801f1b754ed : nt!RtlpExecuteHandlerForException+0xd
0xffffd00020b627d0 : 0xffffd00020b62860 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b627d8 : 0xfffff801f1aff105 : nt!RtlDispatchException+0x1a5
0xffffd00020b627e8 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62830 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62858 : 0xfffff801f1a80b8f : nt!ObfDereferenceObjectWithTag+0x8f
0xffffd00020b62860 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b62868 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62870 : 0xfffff801f1d30ec0 : "nt!BcpCursor <PERF> (nt+0x316ec0)"
0xffffd00020b62890 : 0xfffff801f1b79380 : nt!KiSystemServiceHandler
0xffffd00020b628f8 : 0xffffe001231fd550 :  !du "PCI\VEN_8086&DEV_8C26&SUBSYS_50061458&REV_04\3&11583659&0&E8"
0xffffd00020b62908 : 0xfffff801f1dee62b : nt!CmGetDeviceInstanceKeyPath+0xc7
0xffffd00020b62918 : 0xffffc0007ff35c32 :  !du "Enum\PCI\VEN_8086&DEV_8C26&SUBSYS_50061458&REV_04\3&11583659&0&E8"
0xffffd00020b62928 : 0xfffff801f1caed33 : nt!ExAllocatePoolWithTag+0x873
0xffffd00020b62978 : 0xfffff801f1dee0ca : nt!SysCtxRegOpenKey+0x3a
0xffffd00020b629b8 : 0xfffff801f1ac9d99 : nt!MiAllocateWsle+0x269
0xffffd00020b62a18 : 0xfffff801f1ac75c5 : nt!MiCompleteProtoPteFault+0x1e5
0xffffd00020b62a48 : 0xfffff801f1e3856c : nt!PsQueryStatisticsProcess+0x14c
0xffffd00020b62a58 : 0xfffff801f1decef1 : nt!CmOpenDeviceRegKey+0xfd
0xffffd00020b62a68 : 0xffffe001231fd550 :  !du "PCI\VEN_8086&DEV_8C26&SUBSYS_50061458&REV_04\3&11583659&0&E8"
0xffffd00020b62b78 : 0xfffff801f1ded196 : nt!PiPnpRtlCmActionCallback+0x116
0xffffd00020b62be8 : 0xfffff801f1de6df6 : nt!RtlpInheritAcl2+0x16e
0xffffd00020b62bf8 : 0xfffff801f1caf59e : nt!ExFreePoolWithTag+0x2be
0xffffd00020b62c88 : 0xfffff801f1ded080 : nt!PiPnpRtlCmActionCallback
0xffffd00020b62c90 : 0xffffe001231fd550 :  !du "PCI\VEN_8086&DEV_8C26&SUBSYS_50061458&REV_04\3&11583659&0&E8"
0xffffd00020b62ca8 : 0xfffff801f1ded05c : nt!CmGetDeviceRegProp+0x14c
0xffffd00020b62ce8 : 0xfffff801f1caf59e : nt!ExFreePoolWithTag+0x2be
0xffffd00020b62cf0 : 0xffffe001231fd550 :  !du "PCI\VEN_8086&DEV_8C26&SUBSYS_50061458&REV_04\3&11583659&0&E8"
0xffffd00020b62d78 : 0xfffff801f1afeb70 : nt!KiOpFetchBytes+0x30
0xffffd00020b62d88 : 0xfffff801f1b79500 : nt!KiSystemCall64
0xffffd00020b62d90 : 0xfffff801f1e1da4e : nt!MmQueryVirtualMemory+0x942
0xffffd00020b62d98 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62da0 : 0xfffff801f1d41a5c : "nt!BcpCursor <PERF> (nt+0x327a5c)"
0xffffd00020b62da8 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62db0 : 0xfffff801f1d41a50 : "nt!BcpCursor <PERF> (nt+0x327a50)"
0xffffd00020b62db8 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b62dc0 : 0xfffff801f1d30ec0 : "nt!BcpCursor <PERF> (nt+0x316ec0)"
0xffffd00020b62e08 : 0xfffff801f1afe144 : nt!KiPreprocessFault+0x9c
0xffffd00020b62e30 : 0xffffd00020b62e40 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b62e40 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b62e48 : 0xfffff801f1e1d823 : nt!MmQueryVirtualMemory+0x717
0xffffd00020b62ea8 : 0xfffff801f1afdfbf : nt!KiDispatchException+0x61f
0xffffd00020b62ed0 : 0xffffe00127b49d00 : 0xfffff801f1cc0600 : nt!PspSystemQuotaBlock
0xffffd00020b62ee8 : 0xfffff801f1acac14 : nt!MiSwapWslEntries+0x124
0xffffd00020b62f48 : 0xfffff801f1b13a9c : nt!KiInSwapSingleProcess+0x7c
0xffffd00020b62fd8 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b62fe8 : 0xfffff801f1ac9d99 : nt!MiAllocateWsle+0x269
0xffffd00020b63048 : 0xfffff801f1ac75c5 : nt!MiCompleteProtoPteFault+0x1e5
0xffffd00020b63078 : 0xfffff801f1e3856c : nt!PsQueryStatisticsProcess+0x14c
0xffffd00020b63198 : 0xfffff801f1ac53b4 : nt!MiDispatchFault+0x2c4
0xffffd00020b63208 : 0xfffff801f21a969a : hal!HalpApicRequestInterrupt+0xea
0xffffd00020b63278 : 0xfffff801f21a958f : hal!HalSendSoftwareInterrupt+0xc0
0xffffd00020b63288 : 0xfffff801f21a969a : hal!HalpApicRequestInterrupt+0xea
0xffffd00020b632f8 : 0xfffff801f21a958f : hal!HalSendSoftwareInterrupt+0xc0
0xffffd00020b63308 : 0xfffff801f1cbd200 : nt!ExNode0
0xffffd00020b63368 : 0xfffff801f1abb6ef : nt!KiDeferredReadyThread+0x2ef
0xffffd00020b63378 : 0xfffff801f1aa758b : nt!RtlGetExtendedContextLength+0x1f
0xffffd00020b633c8 : 0xfffff801f1cbd200 : nt!ExNode0
0xffffd00020b63460 : 0xfffff801f1a1a000 : "nt!_guard_check_icall_fptr <PERF> (nt+0x0)"
0xffffd00020b634b8 : 0xfffff801f1ababfd : nt!KeSetEvent+0x34d
0xffffd00020b63518 : 0xfffff801f1b13a9c : nt!KiInSwapSingleProcess+0x7c
0xffffd00020b63530 : 0xfffff801f1ceba08 : nt!KiSwapEvent+0x8
0xffffd00020b63598 : 0xfffff801f1b79bc2 : nt!KiExceptionDispatch+0xc2
0xffffd00020b635a8 : 0xfffff801f1e08203 : nt!MmCopyVirtualMemory+0x44f
0xffffd00020b63680 : 0xffffd00020b63698 : 0xfffff801f1b70e36 : nt!KiSwapContext+0x76
0xffffd00020b63698 : 0xfffff801f1b70e36 : nt!KiSwapContext+0x76
0xffffd00020b636e8 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b63778 : 0xfffff801f1b780fe : nt!KiGeneralProtectionFault+0xfe
0xffffd00020b63780 : 0xffffffffffffffff :  Trap @ ffffd00020b63780
0xffffd00020b63798 : 0xfffff801f1ac2497 : nt!MiQueryAddressState+0x257
0xffffd00020b63878 : 0xfffff801f1b13a9c : nt!KiInSwapSingleProcess+0x7c
0xffffd00020b63898 : 0xfffff801f1ac1fb7 : nt!MiQueryAddressSpan+0xe3
0xffffd00020b638b8 : 0xfffff801f1a7f274 : nt!KeStackAttachProcess+0x164
0xffffd00020b638e8 : 0xfffff801f1e1d821 : nt!MmQueryVirtualMemory+0x715
0xffffd00020b639e8 : 0xfffff801f1e15b01 : nt!ObReferenceObjectByHandleWithTag+0xa1
0xffffd00020b63a38 : 0xfffff801f1e1d106 : nt!NtQueryVirtualMemory+0x22
0xffffd00020b63a48 : 0xfffff801f1e07b8f : nt!NtReadVirtualMemory+0x1b
0xffffd00020b63a88 : 0xfffff801f1b797b3 : nt!KiSystemServiceCopyEnd+0x13
0xffffd00020b63af8 : 0xfffff801f1b78357 : nt!KiPageFault+0x257
0xffffd00020b63b00 : 0x0000000000000001 :  Trap @ ffffd00020b63b00

6: kd> LMTSMN
Unknown option 'T'
Unknown option 'S'
Browse full module list
start             end                 module name
6: kd> lmtsmn
start             end                 module name
fffff801`80200000 fffff801`8028a000   ACPI     ACPI.sys     Sat Feb 22 07:13:57 2014 (53089485)
fffff801`803d4000 fffff801`803ec000   acpiex   acpiex.sys   Thu Aug 22 07:37:47 2013 (5215F80B)
fffff801`81d21000 fffff801`81db3000   afd      afd.sys      Thu May 29 23:03:01 2014 (5387F4E5)
fffff801`81f69000 fffff801`81f80000   ahcache  ahcache.sys  Thu Aug 22 07:39:54 2013 (5215F88A)
fffff801`82e65000 fffff801`831e8000   athw8x   athw8x.sys   Wed Sep 19 03:15:18 2012 (50597106)
fffff960`00a1f000 fffff960`00a7e000   ATMFD    ATMFD.DLL    Thu Aug 22 07:40:37 2013 (5215F8B5)
fffff801`81c75000 fffff801`81c87000   BasicDisplay BasicDisplay.sys Thu Aug 22 07:39:31 2013 (5215F873)
fffff801`81999000 fffff801`819a7000   BasicRender BasicRender.sys Sat Feb 22 07:14:02 2014 (5308948A)
fffff801`81991000 fffff801`81999000   Beep     Beep.SYS     Thu Aug 22 07:40:24 2013 (5215F8A8)
fffff801`801e9000 fffff801`801f3000   BOOTVID  BOOTVID.dll  Thu Aug 22 07:40:26 2013 (5215F8AA)
fffff801`83db6000 fffff801`83dd6000   bowser   bowser.sys   Thu Aug 22 07:38:38 2013 (5215F83E)
fffff960`0081a000 fffff960`00855000   cdd      cdd.dll      Thu Mar 06 07:39:53 2014 (53186C99)
fffff801`80000000 fffff801`80088000   CI       CI.dll       Sat Feb 22 07:12:12 2014 (5308941C)
fffff801`8078a000 fffff801`807df000   CLASSPNP CLASSPNP.SYS Wed Apr 09 02:53:25 2014 (5344EE65)
fffff801`80151000 fffff801`801b2000   CLFS     CLFS.SYS     Wed Mar 19 04:12:20 2014 (53295164)
fffff801`80496000 fffff801`80522000   cng      cng.sys      Thu May 29 03:45:47 2014 (5386E5AB)
fffff801`81f80000 fffff801`81f8f000   CompositeBus CompositeBus.sys Thu Aug 22 07:38:48 2013 (5215F848)
fffff801`8412a000 fffff801`8413a000   condrv   condrv.sys   Thu Aug 22 07:40:17 2013 (5215F8A1)
fffff801`832b0000 fffff801`832c8e80   corsveng2kamd64 corsveng2kamd64.sys Mon Feb 03 13:42:16 2014 (52EFE308)
fffff801`80c00000 fffff801`80c15000   crashdmp crashdmp.sys Thu Aug 22 07:40:03 2013 (5215F893)
fffff801`81e7f000 fffff801`81f0d000   csc      csc.sys      Thu Aug 22 07:38:00 2013 (5215F818)
fffff801`81f33000 fffff801`81f59000   dfsc     dfsc.sys     Thu Mar 06 04:22:50 2014 (53183E6A)
fffff801`80fd8000 fffff801`80ff4000   disk     disk.sys     Thu Aug 22 07:39:47 2013 (5215F883)
fffff801`820b3000 fffff801`820cf000   drmk     drmk.sys     Thu Aug 22 07:39:24 2013 (5215F86C)
fffff801`837d2000 fffff801`837de000   dump_diskdump dump_diskdump.sys Thu Aug 22 07:40:18 2013 (5215F8A2)
fffff801`837de000 fffff801`837f4000   dump_dumpfve dump_dumpfve.sys Sat Feb 22 07:14:48 2014 (530894B8)
fffff801`8166a000 fffff801`81924000   dump_iaStorA dump_iaStorA.sys Thu Aug 01 21:39:52 2013 (51FB0DE8)
fffff801`81a81000 fffff801`81c02000   dxgkrnl  dxgkrnl.sys  Thu Mar 06 04:22:58 2014 (53183E72)
fffff801`81c14000 fffff801`81c75000   dxgmms1  dxgmms1.sys  Thu Mar 06 04:22:14 2014 (53183E46)
fffff801`8201d000 fffff801`8208e000   e1d64x64 e1d64x64.sys Fri Mar 14 14:10:25 2014 (53234611)
fffff801`8085f000 fffff801`80879000   EhStorClass EhStorClass.sys Thu Aug 22 07:38:15 2013 (5215F827)
fffff801`80ba4000 fffff801`80bba000   fileinfo fileinfo.sys Sat Feb 22 07:13:10 2014 (53089456)
fffff801`80879000 fffff801`808d5000   fltmgr   fltmgr.sys   Sun Apr 06 10:10:42 2014 (53416062)
fffff801`80e69000 fffff801`80e74000   Fs_Rec   Fs_Rec.sys   Thu Aug 22 04:46:33 2013 (5215CFE9)
fffff801`81000000 fffff801`81095000   fvevol   fvevol.sys   Mon Apr 07 18:25:31 2014 (534325DB)
fffff801`81320000 fffff801`8138c000   fwpkclnt fwpkclnt.sys Sun Mar 30 21:39:34 2014 (5338C756)
fffff801`f21a3000 fffff801`f2213000   hal      hal.dll      Sun Jun 01 18:49:12 2014 (538BADE8)
fffff801`82d55000 fffff801`82d6e000   HDAudBus HDAudBus.sys Tue Mar 18 04:19:14 2014 (53280182)
fffff801`83200000 fffff801`8321f000   HIDCLASS HIDCLASS.SYS Thu Mar 06 04:24:40 2014 (53183ED8)
fffff801`837ca000 fffff801`837d1f00   HIDPARSE HIDPARSE.SYS Thu Aug 22 07:40:26 2013 (5215F8AA)
fffff801`833dd000 fffff801`833eb000   hidusb   hidusb.sys   Thu Mar 06 04:24:14 2014 (53183EBE)
fffff801`83cbc000 fffff801`83db6000   HTTP     HTTP.sys     Mon Jan 27 14:48:02 2014 (52E6B7F2)
fffff801`808ea000 fffff801`80ba4000   iaStorA  iaStorA.sys  Thu Aug 01 21:39:52 2013 (51FB0DE8)
fffff801`82e00000 fffff801`82e0c000   ICCWDT   ICCWDT.sys   Wed Aug 18 04:27:45 2010 (4C6B9981)
fffff801`832f2000 fffff801`83365000   IntcDAud IntcDAud.sys Fri Feb 21 08:50:26 2014 (530759A2)
fffff801`80fbd000 fffff801`80fcc000   intelpep intelpep.sys Sat Nov 09 03:45:55 2013 (527DF643)
fffff801`82e3d000 fffff801`82e5b000   intelppm intelppm.sys Thu Aug 22 04:46:35 2013 (5215CFEB)
fffff801`820cf000 fffff801`820db000   iwdbus   iwdbus.sys   Thu Mar 13 17:59:14 2014 (53222A32)
fffff801`83274000 fffff801`83284000   kbdclass kbdclass.sys Thu Aug 22 07:39:23 2013 (5215F86B)
fffff801`83266000 fffff801`83274000   kbdhid   kbdhid.sys   Thu Aug 22 07:39:13 2013 (5215F861)
fffff801`f0d54000 fffff801`f0d5d000   kd       kd.dll       Thu Aug 22 07:40:43 2013 (5215F8BB)
fffff801`81f8f000 fffff801`81f9a000   kdnic    kdnic.sys    Thu Aug 22 07:38:26 2013 (5215F832)
fffff801`819a7000 fffff801`819f5000   ks       ks.sys       Thu May 08 19:06:38 2014 (536C0DFE)
fffff801`80e3d000 fffff801`80e59000   ksecdd   ksecdd.sys   Sat Sep 21 03:59:44 2013 (523D51F0)
fffff801`80f8c000 fffff801`80fbd000   ksecpkg  ksecpkg.sys  Sat Mar 08 04:24:07 2014 (531AE1B7)
fffff801`82e5b000 fffff801`82e60300   ksthunk  ksthunk.sys  Thu Aug 22 07:39:31 2013 (5215F873)
fffff801`833eb000 fffff801`833ff000   lltdio   lltdio.sys   Thu Aug 22 07:36:18 2013 (5215F7B2)
fffff801`832c9000 fffff801`832ed000   luafv    luafv.sys    Sat Feb 22 07:14:25 2014 (530894A1)
fffff801`800dd000 fffff801`80143000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Thu Aug 22 07:40:16 2013 (5215F8A0)
fffff801`83284000 fffff801`83292000   monitor  monitor.sys  Thu Aug 22 07:36:37 2013 (5215F7C5)
fffff801`8322c000 fffff801`8323c000   mouclass mouclass.sys Thu Aug 22 07:39:13 2013 (5215F861)
fffff801`8321f000 fffff801`8322c000   mouhid   mouhid.sys   Thu Aug 22 07:39:13 2013 (5215F861)
fffff801`80663000 fffff801`8067e000   mountmgr mountmgr.sys Thu Aug 22 07:40:04 2013 (5215F894)
fffff801`83dd6000 fffff801`83ded000   mpsdrv   mpsdrv.sys   Thu Aug 22 07:36:06 2013 (5215F7A6)
fffff801`83c00000 fffff801`83c6c000   mrxsmb   mrxsmb.sys   Wed Apr 30 02:41:44 2014 (53609B28)
fffff801`83910000 fffff801`8395b000   mrxsmb10 mrxsmb10.sys Thu Mar 06 04:19:36 2014 (53183DA8)
fffff801`83c6c000 fffff801`83ca5000   mrxsmb20 mrxsmb20.sys Sat May 31 02:27:45 2014 (53897661)
fffff801`81c9b000 fffff801`81ca7000   Msfs     Msfs.SYS     Thu Aug 22 07:40:24 2013 (5215F8A8)
fffff801`8052d000 fffff801`80537000   msisadrv msisadrv.sys Thu Aug 22 07:39:03 2013 (5215F857)
fffff801`80297000 fffff801`802f4000   msrpc    msrpc.sys    Thu Aug 22 07:39:22 2013 (5215F86A)
fffff801`81f27000 fffff801`81f33000   mssmbios mssmbios.sys Thu Aug 22 07:39:41 2013 (5215F87D)
fffff801`81095000 fffff801`810ac000   mup      mup.sys      Thu Aug 22 07:40:28 2013 (5215F8AC)
fffff801`80e74000 fffff801`80f8c000   ndis     ndis.sys     Sat Feb 22 07:12:58 2014 (5308944A)
fffff801`838d5000 fffff801`838e9000   ndisuio  ndisuio.sys  Thu Aug 22 07:37:34 2013 (5215F7FE)
fffff801`831f5000 fffff801`83200000   NdisVirtualBus NdisVirtualBus.sys Thu Aug 22 07:36:25 2013 (5215F7B9)
fffff801`8395b000 fffff801`83978000   Ndu      Ndu.sys      Thu Aug 22 07:35:42 2013 (5215F78E)
fffff801`81a00000 fffff801`81a11000   netbios  netbios.sys  Thu Aug 22 07:38:58 2013 (5215F852)
fffff801`81cd5000 fffff801`81d21000   netbt    netbt.sys    Thu Aug 22 07:37:01 2013 (5215F7DD)
fffff801`806c1000 fffff801`8073a000   NETIO    NETIO.SYS    Thu Aug 22 07:37:08 2013 (5215F7E4)
fffff801`81c87000 fffff801`81c9b000   Npfs     Npfs.SYS     Thu Aug 22 07:40:25 2013 (5215F8A9)
fffff801`81f1b000 fffff801`81f27000   npsvctrig npsvctrig.sys Thu Aug 22 07:38:22 2013 (5215F82E)
fffff801`81f0d000 fffff801`81f1b000   nsiproxy nsiproxy.sys Thu Aug 22 07:36:34 2013 (5215F7C2)
fffff801`f1a1a000 fffff801`f21a3000   nt       ntkrnlmp.exe Sun Mar 30 17:35:15 2014 (53388E13)
fffff801`80c47000 fffff801`80e3d000   Ntfs     Ntfs.sys     Tue Mar 18 23:58:52 2014 (532915FC)
fffff801`81988000 fffff801`81991000   Null     Null.SYS     Thu Aug 22 07:40:24 2013 (5215F8A8)
fffff801`805c0000 fffff801`805f4000   nvhda64v nvhda64v.sys Thu Nov 28 08:38:09 2013 (52974741)
fffff801`820f1000 fffff801`82d55000   nvlddmkm nvlddmkm.sys Mon May 19 19:08:44 2014 (537A8EFC)
fffff801`820a6000 fffff801`820b3000   nvvad64v nvvad64v.sys Fri Mar 28 09:32:06 2014 (533579D6)
fffff801`83862000 fffff801`838d5000   nwifi    nwifi.sys    Wed Mar 19 04:07:12 2014 (53295030)
fffff801`81db3000 fffff801`81ddd000   pacer    pacer.sys    Thu Aug 22 07:36:06 2013 (5215F7A6)
fffff801`805a8000 fffff801`805c0000   partmgr  partmgr.sys  Thu Aug 22 07:40:20 2013 (5215F8A4)
fffff801`80537000 fffff801`8057f000   pci      pci.sys      Sat Feb 22 07:12:41 2014 (53089439)
fffff801`80e59000 fffff801`80e69000   pcw      pcw.sys      Thu Aug 22 04:46:34 2013 (5215CFEA)
fffff801`8058c000 fffff801`805a8000   pdc      pdc.sys      Fri Nov 01 00:58:42 2013 (52733502)
fffff801`83e38000 fffff801`83ee1000   peauth   peauth.sys   Sat Feb 22 07:09:37 2014 (53089381)
fffff801`81fab000 fffff801`81ff2000   portcls  portcls.sys  Sat Feb 22 07:11:25 2014 (530893ED)
fffff801`801d4000 fffff801`801e9000   PSHED    PSHED.dll    Sat Sep 14 09:57:19 2013 (52346B3F)
fffff801`81a11000 fffff801`81a81000   rdbss    rdbss.sys    Tue Dec 17 02:21:22 2013 (52AFFB72)
fffff801`820db000 fffff801`820e6000   rdpbus   rdpbus.sys   Thu Aug 22 07:38:52 2013 (5215F84C)
fffff801`813b1000 fffff801`813f7000   rdyboost rdyboost.sys Sat Feb 22 07:13:40 2014 (53089474)
fffff801`838e9000 fffff801`83901000   rspndr   rspndr.sys   Thu Aug 22 07:36:34 2013 (5215F7C2)
fffff801`83404000 fffff801`837c9900   RTKVHD64 RTKVHD64.sys Wed May 14 06:28:52 2014 (53734564)
fffff801`83ee1000 fffff801`83eec000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff801`82e26000 fffff801`82e33000   serenum  serenum.sys  Thu Aug 22 07:40:17 2013 (5215F8A1)
fffff801`82e0c000 fffff801`82e26000   serial   serial.sys   Thu Aug 22 07:40:08 2013 (5215F898)
fffff801`80400000 fffff801`80461000   spaceport spaceport.sys Tue Apr 01 00:16:52 2014 (533A3DB4)
fffff801`84088000 fffff801`84120000   srv      srv.sys      Sat Oct 05 07:01:15 2013 (524FF17B)
fffff801`83f41000 fffff801`83fee000   srv2     srv2.sys     Wed Apr 02 22:53:54 2014 (533CCD42)
fffff801`83eec000 fffff801`83f2f000   srvnet   srvnet.sys   Thu Mar 27 02:16:13 2014 (5333C22D)
fffff801`80800000 fffff801`8085f000   storport storport.sys Sun Apr 06 10:08:55 2014 (53415FF7)
fffff801`82e61000 fffff801`82e62600   swenum   swenum.sys   Thu Aug 22 07:39:29 2013 (5215F871)
fffff801`810ac000 fffff801`81320000   tcpip    tcpip.sys    Tue May 27 09:19:14 2014 (538490D2)
fffff801`83f2f000 fffff801`83f41000   tcpipreg tcpipreg.sys Thu Mar 06 04:19:59 2014 (53183DBF)
fffff801`81cc7000 fffff801`81cd5000   TDI      TDI.SYS      Thu Aug 22 07:39:01 2013 (5215F855)
fffff801`81ca7000 fffff801`81cc7000   tdx      tdx.sys      Thu Aug 22 07:36:34 2013 (5215F7C2)
fffff801`82000000 fffff801`8201d000   TeeDriverx64 TeeDriverx64.sys Wed Nov 27 12:56:32 2013 (52963250)
fffff801`801b2000 fffff801`801d4000   tm       tm.sys       Thu Aug 22 07:39:33 2013 (5215F875)
fffff960`007db000 fffff960`007e4000   TSDDD    TSDDD.dll    Thu Aug 22 07:40:32 2013 (5215F8B0)
fffff801`8415b000 fffff801`84188000   tunnel   tunnel.sys   Thu Aug 22 07:35:45 2013 (5215F791)
fffff801`82dc3000 fffff801`82df5000   ucx01000 ucx01000.sys Sat Feb 22 07:11:33 2014 (530893F5)
fffff801`81f9a000 fffff801`81fab000   umbus    umbus.sys    Thu Aug 22 07:38:59 2013 (5215F853)
fffff801`83292000 fffff801`832af900   usbaudio usbaudio.sys Fri Dec 13 02:24:20 2013 (52AAB624)
fffff801`8323c000 fffff801`83266000   usbccgp  usbccgp.sys  Wed Oct 23 04:17:41 2013 (52678625)
fffff801`81ff2000 fffff801`81ffe000   USBD     USBD.SYS     Sat May 31 02:31:17 2014 (53897735)
fffff801`8208e000 fffff801`820a6000   usbehci  usbehci.sys  Sat May 31 02:29:54 2014 (538976E2)
fffff801`81600000 fffff801`8166a000   usbhub   usbhub.sys   Sat May 31 02:28:51 2014 (538976A3)
fffff801`83365000 fffff801`833dd000   UsbHub3  UsbHub3.sys  Sat May 31 02:26:56 2014 (53897630)
fffff801`81e00000 fffff801`81e6f000   USBPORT  USBPORT.SYS  Sat May 31 02:30:25 2014 (53897701)
fffff801`82d6e000 fffff801`82dc3000   USBXHCI  USBXHCI.SYS  Sat Feb 22 07:11:27 2014 (530893EF)
fffff801`8057f000 fffff801`8058c000   vdrvroot vdrvroot.sys Thu Aug 22 07:38:49 2013 (5215F849)
fffff801`80461000 fffff801`80476000   volmgr   volmgr.sys   Thu Aug 22 07:39:53 2013 (5215F889)
fffff801`80604000 fffff801`80663000   volmgrx  volmgrx.sys  Thu Aug 22 07:40:23 2013 (5215F8A7)
fffff801`8073a000 fffff801`8078a000   volsnap  volsnap.sys  Thu Mar 06 04:26:33 2014 (53183F49)
fffff801`831e8000 fffff801`831f5000   vwifibus vwifibus.sys Thu Aug 22 07:39:00 2013 (5215F854)
fffff801`81ddd000 fffff801`81df5000   vwififlt vwififlt.sys Wed Apr 30 02:43:46 2014 (53609BA2)
fffff801`83901000 fffff801`83910000   vwifimp  vwifimp.sys  Wed Apr 30 02:41:59 2014 (53609B37)
fffff801`81c02000 fffff801`81c14000   watchdog watchdog.sys Sat Feb 22 07:14:39 2014 (530894AF)
fffff801`802f4000 fffff801`803c3000   Wdf01000 Wdf01000.sys Thu Aug 22 07:38:56 2013 (5215F850)
fffff801`8067e000 fffff801`806c1000   WdFilter WdFilter.sys Fri Mar 21 15:54:18 2014 (532C98EA)
fffff801`803c3000 fffff801`803d4000   WDFLDR   WDFLDR.SYS   Thu Aug 22 07:39:03 2013 (5215F857)
fffff801`8413a000 fffff801`8415b000   WdNisDrv WdNisDrv.sys Fri Mar 21 15:55:14 2014 (532C9922)
fffff801`80143000 fffff801`80151000   werkernel werkernel.sys Thu Aug 22 07:40:24 2013 (5215F8A8)
fffff801`8138c000 fffff801`813b1000   wfplwfs  wfplwfs.sys  Sat Mar 08 04:22:45 2014 (531AE165)
fffff960`001aa000 fffff960`005c3000   win32k   win32k.sys   Fri Jun 06 10:19:07 2014 (5391CDDB)
fffff801`82e33000 fffff801`82e3d000   wmiacpi  wmiacpi.sys  Thu Aug 22 07:40:04 2013 (5215F894)
fffff801`8028a000 fffff801`80294000   WMILIB   WMILIB.SYS   Thu Aug 22 07:40:23 2013 (5215F8A7)
fffff801`80bba000 fffff801`80be5000   Wof      Wof.sys      Thu Mar 13 04:27:29 2014 (53216BF1)
fffff801`803ec000 fffff801`803f7000   WppRecorder WppRecorder.sys Thu Aug 22 07:39:40 2013 (5215F87C)

Unloaded modules:
fffff801`84188000 fffff801`84195000   WinDivert.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000D000
fffff801`84215000 fffff801`847e9000   iqvw64e.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  005D4000
fffff801`84200000 fffff801`8420c000   hiber_storport.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff801`848c2000 fffff801`84b7c000   hiber_iaStorA.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  002BA000
fffff801`84b7c000 fffff801`84b92000   hiber_dumpfve.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00016000
fffff801`84120000 fffff801`8412a000   NvStreamKms.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff801`847e9000 fffff801`847f6000   WinDivert.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000D000
fffff801`80c15000 fffff801`80c21000   dump_storport.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff801`8168a000 fffff801`81944000   dump_iaStorA.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  002BA000
fffff801`81944000 fffff801`8195a000   dump_dumpfve.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00016000
fffff801`81f59000 fffff801`81f69000   dam.sys 
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00010000
fffff801`8195a000 fffff801`81988000   cdrom.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002E000
fffff801`80522000 fffff801`8052d000   WdBoot.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff801`80fcc000 fffff801`80fd8000   hwpolicy.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
 

My Computer

System One

  • OS
    Win8.1Pro - Finally!!!
    Computer type
    Laptop
    System Manufacturer/Model
    Samsung/NP780
    CPU
    Came with the laptop (i7 of some sort)
    Motherboard
    Pretty sure that it has one, but haven't checked inside the case!
    Memory
    upgraded to 12 gB from 8 gB
    Graphics Card(s)
    has switchable - Intel/ATI - Used wrong drivers, now ATI card is inop :( Will have to fix it soon!
    Sound Card
    I'm nearly deaf, so this isn't used often
    Monitor(s) Displays
    Touchscreen on laptop/32" Toshiba on HDMI (laid the Sharp TV on a mouse and cracked the screen!)
    Screen Resolution
    800x600
    Hard Drives
    One Samsung 1tB drive - 5400 rpm. Gonna switch to a 7200/10000 rpm or an SSD (if I can find $500 for a 1tB SSD!)
    - Switched to 500 gB Samsung 840 series SSD - WOW!!!
    PSU
    Why do we ask this for laptops?
    Case
    Silver with a neat Samsung logo
    Cooling
    sub-par, gotta get around to working on it soon Worked on it - still sub-par! :(
    Keyboard
    Microsoft Natural - the same one I've used since it orignally came out around 1995
    Mouse
    no Mouse - Trackball!!!!
    Internet Speed
    too slow when I'm waiting for a download to finish
    Browser
    Yes, I use this (Firefox mostly, w/IE next most)
    Antivirus
    Windows Defender and Windows Firewall
    Other Info
    I'm handsome and a snappy dresser :0)
Back
Top