| Home | Forums | Reviews | Articles | Register |
![]() |
| Thread Tools | Rate Thread |
|
bobtabulous@yahoo.co.uk
Guest
Posts: n/a
|
Hi
I think i have a driver conflict that is intermittently causing the blue screen of death and giving the following error message: STOP 0x000000f4 (0x00000003, 0x89140910, 0x89140a84, 0x805d11f8). I have tried everything i can thing of to resolve this problem including re-installing the OS (XP Home) but to no avail. I have run the memory dump through winbdg in the hope that it would pinpoint some unsigned driver, however the debugger seems to suggest that the cause could be winsrv.dll. I am not particlularly sure how to interpret the output of windbg therefore I would be grateful if anyone could help interpret where the problem lies and any possible resolution. Many thanks -bob Output: Microsoft (R) Windows Debugger Version 6.7.0005.0 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Documents and Settings\bob\Desktop\MEMORY.DMP] Kernel Complete Dump File: Full address space is available ************************************************************ WARNING: Dump file has been truncated. Data may be missing. ************************************************************ Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/ download/symbols Executable search path is: Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 2600.xpsp_sp2_gdr.070227-2254 Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700 Debug session time: Fri Apr 27 08:58:10.468 2007 (GMT+1) System Uptime: 4 days 12:32:09.057 Loading Kernel Symbols ................................................................................................................................ Loading User Symbols ............ Loading unloaded module list .................................. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck F4, {3, 89140910, 89140a84, 805d11f8} Probably caused by : winsrv.dll ( winsrv!UserHardError+0 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* CRITICAL_OBJECT_TERMINATION (f4) A process or thread crucial to system operation has unexpectedly exited or been terminated. Several processes and threads are necessary for the operation of the system; when they are terminated (for any reason), the system can no longer function. Arguments: Arg1: 00000003, Process Arg2: 89140910, Terminating object Arg3: 89140a84, Process image file name Arg4: 805d11f8, Explanatory message (ascii) Debugging Details: ------------------ PROCESS_OBJECT: 89140910 IMAGE_NAME: winsrv.dll DEBUG_FLR_IMAGE_TIMESTAMP: 45fbf065 FAULTING_MODULE: 4a680000 csrss PROCESS_NAME: csrss.exe EXCEPTION_RECORD: a6e879d8 -- (.exr 0xffffffffa6e879d8) ExceptionAddress: 75b7b399 (winsrv!UserHardError) ExceptionCode: c0000006 (In-page I/O error) ExceptionFlags: 00000000 NumberParameters: 3 Parameter[0]: 00000008 Parameter[1]: 75b7b399 Parameter[2]: c000009a Inpage operation failed at 75b7b399, due to I/O error c000009a EXCEPTION_CODE: (NTSTATUS) 0xc000009a - Insufficient system resources exist to complete the API. DEFAULT_BUCKET_ID: DRIVER_FAULT ERROR_CODE: (NTSTATUS) 0xc0000006 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The required data was not placed into memory because of an I/O error status of "0x%08lx". IO_ERROR: (NTSTATUS) 0xc000009a - Insufficient system resources exist to complete the API. EXCEPTION_STR: 0xc0000006_c000009a FAULTING_IP: winsrv!UserHardError+0 75b7b399 ?? ??? BUGCHECK_STR: 0xF4_IOERR_C000009A STACK_TEXT: a6e87520 805d039f 000000f4 00000003 89140910 nt!KeBugCheckEx+0x1b a6e87544 805d12a3 805d11f8 89140910 89140a84 nt!PspCatchCriticalBreak +0x75 a6e87574 8054086c 89140b58 c0000006 a6e879b0 nt!NtTerminateProcess +0x7d a6e87574 80500679 89140b58 c0000006 a6e879b0 nt!KiFastCallEntry+0xfc a6e875f4 804fe6aa ffffffff c0000006 a6e879f8 nt!ZwTerminateProcess +0x11 a6e879b0 80501db7 a6e879d8 00000000 a6e87d64 nt!KiDispatchException +0x3a0 a6e87d34 80544137 0069fbe8 0069fc08 00000000 nt!KiRaiseException+0x175 a6e87d50 8054086c 0069fbe8 0069fc08 00000000 nt!NtRaiseException+0x33 a6e87d50 75b7b399 0069fbe8 0069fc08 00000000 nt!KiFastCallEntry+0xfc 0069fed0 75b447a0 00000000 0069feec 00000005 winsrv!UserHardError 0069fff4 00000000 00000000 00000000 00000000 CSRSRV!CsrApiRequestThread +0x18a STACK_COMMAND: kb FOLLOWUP_IP: winsrv!UserHardError+0 75b7b399 ?? ??? SYMBOL_NAME: winsrv!UserHardError+0 FOLLOWUP_NAME: MachineOwner MODULE_NAME: winsrv FAILURE_BUCKET_ID: 0xF4_IOERR_C000009A_winsrv!UserHardError+0 BUCKET_ID: 0xF4_IOERR_C000009A_winsrv!UserHardError+0 Followup: MachineOwner --------- 0: kd> lmv start end module name 4a680000 4a685000 csrss (deferred) Image path: \??\C:\WINDOWS\system32\csrss.exe Image name: csrss.exe Timestamp: Wed Aug 04 07:03:11 2004 (41107C1F) CheckSum: 0000FC16 ImageSize: 00005000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 75b40000 75b4b000 CSRSRV (pdb symbols) c:\symbols \csrsrv.pdb\B7F3643BB6774218BBA185BBCA5281BE1\csrsrv.pdb Loaded symbol image file: CSRSRV.dll Image path: C:\WINDOWS\system32\CSRSRV.dll Image name: CSRSRV.dll Timestamp: Wed Aug 04 08:56:10 2004 (4110969A) CheckSum: 0000F947 ImageSize: 0000B000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 75b50000 75b60000 basesrv (deferred) Image path: C:\WINDOWS\system32\basesrv.dll Image name: basesrv.dll Timestamp: Wed Aug 04 07:03:45 2004 (41107C41) CheckSum: 00013F57 ImageSize: 00010000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 75b60000 75bab000 winsrv (pdb symbols) c:\symbols \winsrv.pdb\439C1780ED41498BA4926507CF2C1B7D2\winsrv.pdb Loaded symbol image file: winsrv.dll Image path: C:\WINDOWS\system32\winsrv.dll Image name: winsrv.dll Timestamp: Sat Mar 17 13:43:01 2007 (45FBF065) CheckSum: 0004BFBE ImageSize: 0004B000 File version: 5.1.2600.3103 Product version: 5.1.2600.3103 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: winsrv OriginalFilename: winsrv.dll ProductVersion: 5.1.2600.3103 FileVersion: 5.1.2600.3103 (xpsp_sp2_gdr.070316-1309) FileDescription: Windows Server DLL LegalCopyright: © Microsoft Corporation. All rights reserved. 75e90000 75f40000 sxs (deferred) Image path: C:\WINDOWS\system32\sxs.dll Image name: sxs.dll Timestamp: Thu Oct 19 14:56:28 2006 (4537840C) CheckSum: 000BC949 ImageSize: 000B0000 File version: 5.1.2600.3019 Product version: 5.1.2600.3019 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: SXS.DLL OriginalFilename: SXS.DLL ProductVersion: 5.1.2600.3019 FileVersion: 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414) FileDescription: Fusion 2.5 LegalCopyright: © Microsoft Corporation. All rights reserved. 77dd0000 77e6b000 ADVAPI32 (deferred) Image path: C:\WINDOWS\system32\ADVAPI32.dll Image name: ADVAPI32.dll Timestamp: Wed Aug 04 08:56:23 2004 (411096A7) CheckSum: 000A0DE4 ImageSize: 0009B000 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: advapi32.dll OriginalFilename: advapi32.dll ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Advanced Windows 32 Base API LegalCopyright: © Microsoft Corporation. All rights reserved. 77e70000 77f01000 RPCRT4 (deferred) Image path: C:\WINDOWS\system32\RPCRT4.dll Image name: RPCRT4.dll Timestamp: Wed Aug 04 08:56:30 2004 (411096AE) CheckSum: 0009C482 ImageSize: 00091000 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: rpcrt4.dll OriginalFilename: rpcrt4.dll ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Remote Procedure Call Runtime LegalCopyright: © Microsoft Corporation. All rights reserved. 77f10000 77f57000 GDI32 (deferred) Image path: C:\WINDOWS\system32\GDI32.dll Image name: GDI32.dll Timestamp: Thu Mar 08 15:36:28 2007 (45F02D7C) CheckSum: 00047DA0 ImageSize: 00047000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 7c800000 7c8f4000 KERNEL32 (deferred) Image path: C:\WINDOWS\system32\KERNEL32.dll Image name: KERNEL32.dll Timestamp: Wed Jul 05 11:55:00 2006 (44AB9A84) CheckSum: 000F724D ImageSize: 000F4000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 7c900000 7c9b0000 ntdll (pdb symbols) c:\symbols \ntdll.pdb\36515FB5D04345E491F672FA2E2878C02\ntdll.pdb Loaded symbol image file: ntdll.dll Mapped memory image file: c:\symbols\ntdll.dll \411096B4b0000\ntdll.dll Image path: C:\WINDOWS\system32\ntdll.dll Image name: ntdll.dll Timestamp: Wed Aug 04 08:56:36 2004 (411096B4) CheckSum: 000AF2F7 ImageSize: 000B0000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 7e410000 7e4a0000 USER32 (deferred) Image path: C:\WINDOWS\system32\USER32.dll Image name: USER32.dll Timestamp: Thu Mar 08 15:36:28 2007 (45F02D7C) CheckSum: 000940E1 ImageSize: 00090000 File version: 5.1.2600.3099 Product version: 5.1.2600.3099 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: user32 OriginalFilename: user32 ProductVersion: 5.1.2600.3099 FileVersion: 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) FileDescription: Windows XP USER API Client DLL LegalCopyright: © Microsoft Corporation. All rights reserved. 804d7000 806e2000 nt (pdb symbols) c:\symbols \ntkrpamp.pdb\966DF78E558F483199141B029DF5A9D51\ntkrpamp.pdb Loaded symbol image file: ntkrpamp.exe Image path: ntkrpamp.exe Image name: ntkrpamp.exe Timestamp: Wed Feb 28 08:38:53 2007 (45E53F9D) CheckSum: 001F873F ImageSize: 0020B000 File version: 5.1.2600.3093 Product version: 5.1.2600.3093 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrpamp.exe OriginalFilename: ntkrpamp.exe ProductVersion: 5.1.2600.3093 FileVersion: 5.1.2600.3093 (xpsp_sp2_gdr.070227-2254) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved. 806e2000 80702d00 hal (pdb symbols) c:\symbols \halmacpi.pdb\94CADB0398C841C1BA445EB81891CD5C1\halmacpi.pdb Loaded symbol image file: halmacpi.dll Image path: halmacpi.dll Image name: halmacpi.dll Timestamp: Wed Aug 04 06:59:09 2004 (41107B2D) CheckSum: 000293A1 ImageSize: 00020D00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 9f43f000 9f469180 kmixer (deferred) Image path: \SystemRoot\system32\drivers\kmixer.sys Image name: kmixer.sys Timestamp: Wed Jun 14 09:47:45 2006 (448FCD31) CheckSum: 0002C363 ImageSize: 0002A180 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a3512000 a3552280 HTTP (deferred) Image path: \SystemRoot\System32\Drivers\HTTP.sys Image name: HTTP.sys Timestamp: Fri Mar 17 00:33:09 2006 (441A03C5) CheckSum: 00047848 ImageSize: 00040280 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a3a31000 a3a45400 wdmaud (deferred) Image path: \SystemRoot\system32\drivers\wdmaud.sys Image name: wdmaud.sys Timestamp: Wed Jun 14 10:00:44 2006 (448FD03C) CheckSum: 000171EC ImageSize: 00014400 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a435e000 a4379fc0 naiavf5x (deferred) Image path: \SystemRoot\system32\drivers\naiavf5x.sys Image name: naiavf5x.sys Timestamp: Tue Mar 29 20:32:47 2005 (4249AD5F) CheckSum: 0002B820 ImageSize: 0001BFC0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a456a000 a456c100 EntDrv51 (deferred) Image path: \??\C:\WINDOWS\system32\drivers\EntDrv51.sys Image name: EntDrv51.sys Timestamp: Mon Aug 08 19:27:07 2005 (42F7A3FB) CheckSum: 0000EFE1 ImageSize: 00002100 File version: 8.0.0.448 Product version: 8.0.0.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 0.0 Unknown File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Network Associates, Inc ProductName: Virus Scan Enterprise, Entercept InternalName: EntDrv OriginalFilename: EntDrv.sys ProductVersion: 8.0.0 FileVersion: 8.0.0.448 PrivateBuild: 8.0.0.448 SpecialBuild: 8.0.0.448 FileDescription: EntDrv LegalCopyright: Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved LegalTrademarks: Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved Comments: Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved a45d2000 a4623480 srv (deferred) Image path: \SystemRoot\system32\DRIVERS\srv.sys Image name: srv.sys Timestamp: Mon Aug 14 11:34:39 2006 (44E051BF) CheckSum: 00059B2B ImageSize: 00051480 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a464c000 a46c7000 CVPNDRVA (deferred) Image path: \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys Image name: CVPNDRVA.sys Timestamp: Fri Aug 27 15:30:37 2004 (412F458D) CheckSum: 0004DE83 ImageSize: 0007B000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a46ef000 a471b400 mrxdav (deferred) Image path: \SystemRoot\system32\DRIVERS\mrxdav.sys Image name: mrxdav.sys Timestamp: Wed Aug 04 07:00:49 2004 (41107B91) CheckSum: 000398F1 ImageSize: 0002C400 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a4f1c000 a4f313c0 DLAUDF_M (deferred) Image path: \SystemRoot\System32\DLA\DLAUDF_M.SYS Image name: DLAUDF_M.SYS Timestamp: Thu Sep 08 17:29:08 2005 (432066D4) CheckSum: 00021D02 ImageSize: 000153C0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a4f32000 a4f49040 DLAUDFAM (deferred) Image path: \SystemRoot\System32\DLA\DLAUDFAM.SYS Image name: DLAUDFAM.SYS Timestamp: Thu Sep 08 17:29:23 2005 (432066E3) CheckSum: 00022160 ImageSize: 00017040 File version: 5.20.8.0 Product version: 1.0.0.1 File flags: 0 (Mask 3F) File OS: 4 Unknown Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Sonic Solutions FileVersion: 5.20.08a FileDescription: Drive Letter Access Component LegalCopyright: Copyright © 2004 Sonic Solutions a4f4a000 a4f5f1c0 DLAIFS_M (deferred) Image path: \SystemRoot\System32\DLA\DLAIFS_M.SYS Image name: DLAIFS_M.SYS Timestamp: Thu Sep 08 17:29:02 2005 (432066CE) CheckSum: 00022529 ImageSize: 000151C0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a5b31000 a5c05e80 dump_iastor (deferred) Image path: \SystemRoot\System32\Drivers\dump_iastor.sys Image name: dump_iastor.sys Timestamp: Fri Jun 17 15:33:38 2005 (42B2DF42) CheckSum: 000E2430 ImageSize: 000D4E80 File version: 5.1.0.1022 Product version: 5.1.0.1022 File flags: 8 (Mask 3F) Private File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Intel Corporation ProductName: Intel Matrix Storage Manager driver InternalName: iaStor.sys OriginalFilename: iaStor.sys ProductVersion: 5.1.0.1022 FileVersion: 5.1.0.1022 PrivateBuild: 5.1.0.1022 SpecialBuild: 5.1.0.1022 FileDescription: Intel Matrix Storage Manager driver LegalCopyright: Copyright(C) Intel Corporation 1994-2005 LegalTrademarks: Copyright(C) Intel Corporation 1994-2005 Comments: Copyright(C) Intel Corporation 1994-2005 a6695000 a6695d00 dxgthk (deferred) Image path: \SystemRoot\System32\drivers\dxgthk.sys Image name: dxgthk.sys Timestamp: Fri Aug 17 21:53:12 2001 (3B7D8438) CheckSum: 000035E7 ImageSize: 00000D00 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: dxgthk.sys OriginalFilename: dxgthk.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: DirectX Graphics Driver Thunk LegalCopyright: © Microsoft Corporation. All rights reserved. a671a000 a67235a0 DRVNDDM (deferred) Image path: \SystemRoot\System32\Drivers\DRVNDDM.SYS Image name: DRVNDDM.SYS Timestamp: Fri Aug 12 21:21:43 2005 (42FD04D7) CheckSum: 00019371 ImageSize: 000095A0 File version: 3.0.0.0 Product version: 1.0.0.1 File flags: 0 (Mask 3F) File OS: 4 Unknown Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Sonic Solutions FileVersion: 5.20.00a FileDescription: Device Driver Manager LegalCopyright: Copyright © Sonic Solutions a68b8000 a68be3e0 DLABOIOM (deferred) Image path: \SystemRoot\System32\DLA\DLABOIOM.SYS Image name: DLABOIOM.SYS Timestamp: Thu Sep 08 17:29:37 2005 (432066F1) CheckSum: 0000B3D6 ImageSize: 000063E0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6bc7000 a6bc9900 Dxapi (deferred) Image path: \SystemRoot\System32\drivers\Dxapi.sys Image name: Dxapi.sys Timestamp: Fri Aug 17 21:53:19 2001 (3B7D843F) CheckSum: 0000ACC2 ImageSize: 00002900 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: dxapi.sys OriginalFilename: dxapi.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: DirectX API Driver LegalCopyright: © Microsoft Corporation. All rights reserved. a6cd5000 a6cd9500 watchdog (deferred) Image path: \SystemRoot\System32\watchdog.sys Image name: watchdog.sys Timestamp: Wed Aug 04 07:07:32 2004 (41107D24) CheckSum: 0000FEBA ImageSize: 00004500 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: watchdog.sys OriginalFilename: watchdog.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Watchdog Driver LegalCopyright: © Microsoft Corporation. All rights reserved. a6d15000 a6d1b780 USBSTOR (deferred) Image path: \SystemRoot\system32\DRIVERS\USBSTOR.SYS Image name: USBSTOR.SYS Timestamp: Wed Aug 04 07:08:44 2004 (41107D6C) CheckSum: 0001333B ImageSize: 00006780 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6e68000 a6e77900 Cdfs (deferred) Image path: \SystemRoot\System32\Drivers\Cdfs.SYS Image name: Cdfs.SYS Timestamp: Wed Aug 04 07:14:09 2004 (41107EB1) CheckSum: 0000FB67 ImageSize: 0000F900 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6e88000 a6e90d80 HIDCLASS (deferred) Image path: \SystemRoot\system32\DRIVERS\HIDCLASS.SYS Image name: HIDCLASS.SYS Timestamp: Wed Aug 04 07:08:18 2004 (41107D52) CheckSum: 0000AB52 ImageSize: 00008D80 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: hidclass.sys OriginalFilename: hidclass.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Hid Class Library LegalCopyright: © Microsoft Corporation. All rights reserved. a6f17000 a6f1aa00 kbdhid (deferred) Image path: \SystemRoot\system32\DRIVERS\kbdhid.sys Image name: kbdhid.sys Timestamp: Wed Aug 04 06:58:33 2004 (41107B09) CheckSum: 00008FEE ImageSize: 00003A00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6f1f000 a6f21f80 mouhid (deferred) Image path: \SystemRoot\system32\DRIVERS\mouhid.sys Image name: mouhid.sys Timestamp: Fri Aug 17 21:47:57 2001 (3B7D82FD) CheckSum: 0000C848 ImageSize: 00002F80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6f23000 a6f25580 hidusb (deferred) Image path: \SystemRoot\system32\DRIVERS\hidusb.sys Image name: hidusb.sys Timestamp: Fri Aug 17 22:02:16 2001 (3B7D8658) CheckSum: 0000D6C8 ImageSize: 00002580 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 a6fbb000 a6fbc8a0 DLAPoolM (deferred) Image path: \SystemRoot\System32\DLA\DLAPoolM.SYS Image name: DLAPoolM.SYS Timestamp: Thu Sep 08 17:29:03 2005 (432066CF) CheckSum: 0000C357 ImageSize: 000018A0 File version: 5.20.8.0 Product version: 1.0.0.1 File flags: 0 (Mask 3F) File OS: 4 Unknown Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Sonic Solutions FileVersion: 5.20.08a FileDescription: Drive Letter Access Component LegalCopyright: Copyright © 2004 Sonic Solutions ac0af000 ac11da00 mrxsmb (deferred) Image path: \SystemRoot\system32\DRIVERS\mrxsmb.sys Image name: mrxsmb.sys Timestamp: Fri May 05 10:41:42 2006 (445B1DD6) CheckSum: 0007CA79 ImageSize: 0006EA00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac146000 ac170a00 rdbss (deferred) Image path: \SystemRoot\system32\DRIVERS\rdbss.sys Image name: rdbss.sys Timestamp: Fri May 05 10:47:55 2006 (445B1F4B) CheckSum: 000345EF ImageSize: 0002AA00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac171000 ac192d00 afd (deferred) Image path: \SystemRoot\System32\drivers\afd.sys Image name: afd.sys Timestamp: Wed Aug 04 07:14:13 2004 (41107EB5) CheckSum: 0002DC47 ImageSize: 00021D00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac193000 ac1bac00 netbt (deferred) Image path: \SystemRoot\system32\DRIVERS\netbt.sys Image name: netbt.sys Timestamp: Wed Aug 04 07:14:36 2004 (41107ECC) CheckSum: 00033EE9 ImageSize: 00027C00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac1bb000 ac1dbf00 ipnat (deferred) Image path: \SystemRoot\system32\DRIVERS\ipnat.sys Image name: ipnat.sys Timestamp: Wed Sep 29 23:28:36 2004 (415B3714) CheckSum: 00024074 ImageSize: 00020F00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac1dc000 ac233d80 tcpip (deferred) Image path: \SystemRoot\system32\DRIVERS\tcpip.sys Image name: tcpip.sys Timestamp: Thu Apr 20 12:51:47 2006 (444775D3) CheckSum: 0005F865 ImageSize: 00057D80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ac234000 ac246400 ipsec (deferred) Image path: \SystemRoot\system32\DRIVERS\ipsec.sys Image name: ipsec.sys Timestamp: Wed Aug 04 07:14:27 2004 (41107EC3) CheckSum: 0001A264 ImageSize: 00012400 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ae38b000 ae38e920 DLAOPIOM (deferred) Image path: \SystemRoot\System32\DLA\DLAOPIOM.SYS Image name: DLAOPIOM.SYS Timestamp: Thu Sep 08 17:30:23 2005 (4320671F) CheckSum: 0001071E ImageSize: 00003920 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ae8c9000 ae8c9b80 Null (deferred) Image path: \SystemRoot\System32\Drivers\Null.SYS Image name: Null.SYS Timestamp: Fri Aug 17 21:47:39 2001 (3B7D82EB) CheckSum: 00008483 ImageSize: 00000B80 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: null.sys OriginalFilename: null.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: NULL Driver LegalCopyright: © Microsoft Corporation. All rights reserved. aec06000 aec06980 DLADResN (deferred) Image path: \SystemRoot\System32\DLA\DLADResN.SYS Image name: DLADResN.SYS Timestamp: Thu Sep 08 17:32:10 2005 (4320678A) CheckSum: 0000D5B8 ImageSize: 00000980 File version: 5.20.8.0 Product version: 1.0.0.1 File flags: 0 (Mask 3F) File OS: 4 Unknown Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Sonic Solutions FileVersion: 5.20.08a FileDescription: Drive Letter Access Component LegalCopyright: Copyright © 2004 Sonic Solutions aecad000 aecb5880 Fips (deferred) Image path: \SystemRoot\System32\Drivers\Fips.SYS Image name: Fips.SYS Timestamp: Sat Aug 18 02:31:49 2001 (3B7DC585) CheckSum: 0000AB1E ImageSize: 00008880 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 aeccd000 aecd5700 netbios (deferred) Image path: \SystemRoot\system32\DRIVERS\netbios.sys Image name: netbios.sys Timestamp: Wed Aug 04 07:03:19 2004 (41107C27) CheckSum: 0000E953 ImageSize: 00008700 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: NETBIOS.SYS OriginalFilename: NETBIOS.SYS ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: NetBIOS interface driver LegalCopyright: © Microsoft Corporation. All rights reserved. aecdd000 aece5700 wanarp (deferred) Image path: \SystemRoot\system32\DRIVERS\wanarp.sys Image name: wanarp.sys Timestamp: Wed Aug 04 07:04:57 2004 (41107C89) CheckSum: 0000EFA7 ImageSize: 00008700 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 aeced000 aecfb460 mvstdi5x (deferred) Image path: \SystemRoot\system32\drivers\mvstdi5x.sys Image name: mvstdi5x.sys Timestamp: Wed Feb 02 19:16:00 2005 (420126F0) CheckSum: 0001DADA ImageSize: 0000E460 File version: 8.0.0.301 Product version: 8.0.0.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Network Associates, Inc. ProductName: VirusScan ProductVersion: 8.0.0 FileVersion: 8.0.0.301 PrivateBuild: OAS_CMN.3.3.0.301 F1,F2,F3,F7 FileDescription: Anti-Virus Mini-Firewall Driver LegalCopyright: Copyright© 1995-2005 Networks Associates Technology, Inc. All Rights Reserved. aed8d000 aed9b100 usbhub (deferred) Image path: \SystemRoot\system32\DRIVERS\usbhub.sys Image name: usbhub.sys Timestamp: Wed Aug 04 07:08:40 2004 (41107D68) CheckSum: 00014269 ImageSize: 0000E100 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 aedad000 aedb6480 NDProxy (deferred) Image path: \SystemRoot\System32\Drivers\NDProxy.SYS Image name: NDProxy.SYS Timestamp: Fri Aug 17 21:55:30 2001 (3B7D84C2) CheckSum: 0000BAEF ImageSize: 00009480 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 af0c7000 af0ce880 Npfs (deferred) Image path: \SystemRoot\System32\Drivers\Npfs.SYS Image name: Npfs.SYS Timestamp: Wed Aug 04 07:00:38 2004 (41107B86) CheckSum: 000088F8 ImageSize: 00007880 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 af0cf000 af0d3a80 Msfs (deferred) Image path: \SystemRoot\System32\Drivers\Msfs.SYS Image name: Msfs.SYS Timestamp: Wed Aug 04 07:00:37 2004 (41107B85) CheckSum: 00008C73 ImageSize: 00004A80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 af0d7000 af0dc200 vga (deferred) Image path: \SystemRoot\System32\drivers\vga.sys Image name: vga.sys Timestamp: Wed Aug 04 07:07:06 2004 (41107D0A) CheckSum: 0001265E ImageSize: 00005200 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.4 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: vga.sys OriginalFilename: vga.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: VGA/Super VGA Video Driver LegalCopyright: © Microsoft Corporation. All rights reserved. af0df000 af0e5180 HIDPARSE (deferred) Image path: \SystemRoot\system32\DRIVERS\HIDPARSE.SYS Image name: HIDPARSE.SYS Timestamp: Wed Aug 04 07:08:15 2004 (41107D4F) CheckSum: 0000E653 ImageSize: 00006180 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: hidparse.sys OriginalFilename: hidparse.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Hid Parsing Library LegalCopyright: © Microsoft Corporation. All rights reserved. af32b000 af32c500 dsunidrv (deferred) Image path: \SystemRoot\system32\DRIVERS\dsunidrv.sys Image name: dsunidrv.sys Timestamp: Sun Feb 18 18:31:02 2007 (45D89B66) CheckSum: 000080FA ImageSize: 00001500 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 af72e000 af72fd40 ASCTRM (deferred) Image path: \SystemRoot\System32\Drivers\ASCTRM.SYS Image name: ASCTRM.SYS Timestamp: Mon Feb 05 17:50:30 2001 (3A7EE7E6) CheckSum: 0000BFE0 ImageSize: 00001D40 File version: 5.0.2195.1 Product version: 5.0.2195.1 File flags: 8 (Mask 3F) Private File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Windows (R) 2000 DDK provider ProductName: Windows (R) 2000 DDK driver InternalName: trm.sys OriginalFilename: trm.sys ProductVersion: 5.00.2195.1 FileVersion: 5.00.2195.1 FileDescription: TR Manager LegalCopyright: Copyright (C) Microsoft Corp. 1981-1999 afaac000 afaaf6a0 ckldrv (deferred) Image path: \SystemRoot\system32\ckldrv.sys Image name: ckldrv.sys Timestamp: Thu Feb 03 20:53:11 2000 (3899EAB7) CheckSum: 0000EC9E ImageSize: 000036A0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 afac4000 afac6280 rasacd (deferred) Image path: \SystemRoot\system32\DRIVERS\rasacd.sys Image name: rasacd.sys Timestamp: Fri Aug 17 21:55:39 2001 (3B7D84CB) CheckSum: 0000B2E7 ImageSize: 00002280 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: rasacd.sys OriginalFilename: rasacd.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: RAS Automatic Connection Driver LegalCopyright: © Microsoft Corporation. All rights reserved. b0a6a000 b0a6f860 DLARTL_N (deferred) Image path: \SystemRoot\System32\Drivers\DLARTL_N.SYS Image name: DLARTL_N.SYS Timestamp: Thu Aug 25 20:16:15 2005 (430E18FF) CheckSum: 00009677 ImageSize: 00005860 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b407b000 b4117000 ctac32k (deferred) Image path: \SystemRoot\system32\drivers\ctac32k.sys Image name: ctac32k.sys Timestamp: Tue Nov 08 12:14:40 2005 (437096B0) CheckSum: 00086764 ImageSize: 0009C000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b4117000 b413e000 ctsfm2k (deferred) Image path: \SystemRoot\system32\drivers\ctsfm2k.sys Image name: ctsfm2k.sys Timestamp: Tue Nov 08 12:14:46 2005 (437096B6) CheckSum: 0002D163 ImageSize: 00027000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b4532000 b455f000 emupia2k (deferred) Image path: \SystemRoot\system32\drivers\emupia2k.sys Image name: emupia2k.sys Timestamp: Tue Nov 08 12:14:45 2005 (437096B5) CheckSum: 000171A1 ImageSize: 0002D000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b455f000 b466f000 ha20x2k (deferred) Image path: \SystemRoot\system32\drivers\ha20x2k.sys Image name: ha20x2k.sys Timestamp: Wed Feb 15 06:40:14 2006 (43F2CCCE) CheckSum: 00117FE2 ImageSize: 00110000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b886f000 b88a2200 update (deferred) Image path: \SystemRoot\system32\DRIVERS\update.sys Image name: update.sys Timestamp: Wed Aug 04 06:58:32 2004 (41107B08) CheckSum: 0003A526 ImageSize: 00033200 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b88a3000 b88b3e00 psched (deferred) Image path: \SystemRoot\system32\DRIVERS\psched.sys Image name: psched.sys Timestamp: Wed Aug 04 07:04:16 2004 (41107C60) CheckSum: 0001B55A ImageSize: 00010E00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b88b4000 b88ca680 ndiswan (deferred) Image path: \SystemRoot\system32\DRIVERS\ndiswan.sys Image name: ndiswan.sys Timestamp: Wed Aug 04 07:14:30 2004 (41107EC6) CheckSum: 00016813 ImageSize: 00016680 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b88cb000 b88e5160 dne2000 (deferred) Image path: \SystemRoot\system32\DRIVERS\dne2000.sys Image name: dne2000.sys Timestamp: Fri Jul 25 03:55:48 2003 (3F209C34) CheckSum: 00026650 ImageSize: 0001A160 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b88e6000 b8918000 ctoss2k (deferred) Image path: \SystemRoot\system32\drivers\ctoss2k.sys Image name: ctoss2k.sys Timestamp: Tue Nov 08 12:14:55 2005 (437096BF) CheckSum: 0001CCDB ImageSize: 00032000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b8918000 b893a680 ks (deferred) Image path: \SystemRoot\system32\drivers\ks.sys Image name: ks.sys Timestamp: Wed Aug 04 07:15:20 2004 (41107EF8) CheckSum: 0002E05C ImageSize: 00022680 File version: 5.3.2600.2180 Product version: 5.3.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.0 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft(R) Windows(R) Operating System InternalName: ks.sys OriginalFilename: ks.sys ProductVersion: 5.3.2600.2180 FileVersion: 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Kernel CSA Library LegalCopyright: © Microsoft Corporation. All rights reserved. b893b000 b895e980 portcls (deferred) Image path: \SystemRoot\system32\drivers\portcls.sys Image name: portcls.sys Timestamp: Wed Aug 04 07:15:47 2004 (41107F13) CheckSum: 0002E05C ImageSize: 00023980 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.9 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: portcls.sys OriginalFilename: portcls.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Port Class (Class Driver for Port/Miniport Devices) LegalCopyright: © Microsoft Corporation. All rights reserved. b895f000 b89ca580 ctaud2k (deferred) Image path: \SystemRoot\system32\drivers\ctaud2k.sys Image name: ctaud2k.sys Timestamp: Tue Nov 08 12:15:35 2005 (437096E7) CheckSum: 0007556C ImageSize: 0006B580 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b89cb000 b89ede80 USBPORT (deferred) Image path: \SystemRoot\system32\DRIVERS\USBPORT.SYS Image name: USBPORT.SYS Timestamp: Wed Aug 04 07:08:34 2004 (41107D62) CheckSum: 0002F594 ImageSize: 00022E80 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: usbport.sys OriginalFilename: usbport.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: USB 1.1 & 2.0 Port Driver LegalCopyright: © Microsoft Corporation. All rights reserved. b89ee000 b8a1a200 e1e5132 (deferred) Image path: \SystemRoot\system32\DRIVERS\e1e5132.sys Image name: e1e5132.sys Timestamp: Fri Apr 01 01:04:51 2005 (424C9023) CheckSum: 00031789 ImageSize: 0002C200 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b8a1b000 b8a2e780 VIDEOPRT (deferred) Image path: \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS Image name: VIDEOPRT.SYS Timestamp: Wed Aug 04 07:07:04 2004 (41107D08) CheckSum: 0001B84C ImageSize: 00013780 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.4 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: videoprt.sys OriginalFilename: videoprt.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Video Port Driver LegalCopyright: © Microsoft Corporation. All rights reserved. b8a2f000 b8daa260 nv4_mini (deferred) Image path: \SystemRoot\system32\DRIVERS\nv4_mini.sys Image name: nv4_mini.sys Timestamp: Sat Apr 01 05:44:42 2006 (442E053A) CheckSum: 0037DC30 ImageSize: 0037B260 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b8dab000 b8db9d80 sysaudio (deferred) Image path: \SystemRoot\system32\drivers\sysaudio.sys Image name: sysaudio.sys Timestamp: Wed Aug 04 07:15:54 2004 (41107F1A) CheckSum: 00013320 ImageSize: 0000ED80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9cd3000 b9cd5580 ndistapi (deferred) Image path: \SystemRoot\system32\DRIVERS\ndistapi.sys Image name: ndistapi.sys Timestamp: Fri Aug 17 21:55:29 2001 (3B7D84C1) CheckSum: 0000554A ImageSize: 00002580 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9d28000 b9d42580 Mup (deferred) Image path: Mup.sys Image name: Mup.sys Timestamp: Wed Aug 04 07:15:20 2004 (41107EF8) CheckSum: 0001F5BD ImageSize: 0001A580 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9d43000 b9d6fa80 NDIS (deferred) Image path: NDIS.sys Image name: NDIS.sys Timestamp: Wed Aug 04 07:14:27 2004 (41107EC3) CheckSum: 0003996E ImageSize: 0002CA80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9d70000 b9dfc480 Ntfs (deferred) Image path: Ntfs.sys Image name: Ntfs.sys Timestamp: Wed Aug 04 07:15:06 2004 (41107EEA) CheckSum: 0009BF25 ImageSize: 0008C480 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9dfd000 b9e13780 KSecDD (deferred) Image path: KSecDD.sys Image name: KSecDD.sys Timestamp: Wed Aug 04 06:59:45 2004 (41107B51) CheckSum: 00025EE6 ImageSize: 00016780 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9e14000 b9e29440 DRVMCDB (deferred) Image path: DRVMCDB.SYS Image name: DRVMCDB.SYS Timestamp: Mon Sep 12 22:38:27 2005 (4325F553) CheckSum: 00022384 ImageSize: 00015440 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9e2a000 b9e3bf00 sr (deferred) Image path: sr.sys Image name: sr.sys Timestamp: Wed Aug 04 07:06:22 2004 (41107CDE) CheckSum: 00016006 ImageSize: 00011F00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9e3c000 b9e5b780 fltMgr (deferred) Image path: fltMgr.sys Image name: fltMgr.sys Timestamp: Mon Aug 21 10:14:57 2006 (44E97991) CheckSum: 000213F1 ImageSize: 0001F780 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9e5c000 b9f30e80 iastor (deferred) Image path: iastor.sys Image name: iastor.sys Timestamp: Fri Jun 17 15:33:38 2005 (42B2DF42) CheckSum: 000E2430 ImageSize: 000D4E80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9f31000 b9f48480 atapi (deferred) Image path: atapi.sys Image name: atapi.sys Timestamp: Wed Aug 04 06:59:41 2004 (41107B4D) CheckSum: 000208FA ImageSize: 00017480 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9f49000 b9f67880 ftdisk (deferred) Image path: ftdisk.sys Image name: ftdisk.sys Timestamp: Fri Aug 17 21:52:41 2001 (3B7D8419) CheckSum: 00021032 ImageSize: 0001E880 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 b9f68000 b9f78a80 pci (deferred) Image path: pci.sys Image name: pci.sys Timestamp: Wed Aug 04 07:07:45 2004 (41107D31) CheckSum: 0001D791 ImageSize: 00010A80 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: pci.sys OriginalFilename: pci.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: NT Plug and Play PCI Enumerator LegalCopyright: © Microsoft Corporation. All rights reserved. b9f79000 b9fa6d80 ACPI (deferred) Image path: ACPI.sys Image name: ACPI.sys Timestamp: Wed Aug 04 07:07:35 2004 (41107D27) CheckSum: 00033106 ImageSize: 0002DD80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba0a8000 ba0b0c00 isapnp (deferred) Image path: isapnp.sys Image name: isapnp.sys Timestamp: Fri Aug 17 21:58:01 2001 (3B7D8559) CheckSum: 0000BB35 ImageSize: 00008C00 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: isapnp.sys OriginalFilename: isapnp.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: PNP ISA Bus Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba0b8000 ba0c2500 MountMgr (deferred) Image path: MountMgr.sys Image name: MountMgr.sys Timestamp: Wed Aug 04 06:58:29 2004 (41107B05) CheckSum: 000187D6 ImageSize: 0000A500 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba0c8000 ba0d4c80 VolSnap (deferred) Image path: VolSnap.sys Image name: VolSnap.sys Timestamp: Wed Aug 04 07:00:14 2004 (41107B6E) CheckSum: 00017B61 ImageSize: 0000CC80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba0d8000 ba0e0e00 disk (deferred) Image path: disk.sys Image name: disk.sys Timestamp: Wed Aug 04 06:59:53 2004 (41107B59) CheckSum: 0000CE3F ImageSize: 00008E00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba0e8000 ba0f4200 CLASSPNP (deferred) Image path: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS Image name: CLASSPNP.SYS Timestamp: Wed Aug 04 07:14:26 2004 (41107EC2) CheckSum: 0000DA62 ImageSize: 0000C200 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba1f8000 ba200d00 intelppm (deferred) Image path: \SystemRoot\system32\DRIVERS\intelppm.sys Image name: intelppm.sys Timestamp: Wed Aug 04 06:59:19 2004 (41107B37) CheckSum: 0000B22F ImageSize: 00008D00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba208000 ba216b80 drmk (deferred) Image path: \SystemRoot\system32\drivers\drmk.sys Image name: drmk.sys Timestamp: Wed Aug 04 07:07:54 2004 (41107D3A) CheckSum: 000157DE ImageSize: 0000EB80 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: drmk.sys OriginalFilename: drmk.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Microsoft Kernel DRM Descrambler Filter LegalCopyright: © Microsoft Corporation. All rights reserved. ba218000 ba224180 cdrom (deferred) Image path: \SystemRoot\system32\DRIVERS\cdrom.sys Image name: cdrom.sys Timestamp: Wed Aug 04 06:59:52 2004 (41107B58) CheckSum: 0000E599 ImageSize: 0000C180 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba228000 ba236080 redbook (deferred) Image path: \SystemRoot\system32\DRIVERS\redbook.sys Image name: redbook.sys Timestamp: Wed Aug 04 06:59:34 2004 (41107B46) CheckSum: 00010495 ImageSize: 0000E080 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba238000 ba242380 imapi (deferred) Image path: \SystemRoot\system32\DRIVERS\imapi.sys Image name: imapi.sys Timestamp: Wed Aug 04 07:00:12 2004 (41107B6C) CheckSum: 00012AFC ImageSize: 0000A380 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba248000 ba254880 rasl2tp (deferred) Image path: \SystemRoot\system32\DRIVERS\rasl2tp.sys Image name: rasl2tp.sys Timestamp: Wed Aug 04 07:14:21 2004 (41107EBD) CheckSum: 00011D37 ImageSize: 0000C880 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba258000 ba262200 raspppoe (deferred) Image path: \SystemRoot\system32\DRIVERS\raspppoe.sys Image name: raspppoe.sys Timestamp: Wed Aug 04 07:05:06 2004 (41107C92) CheckSum: 00017254 ImageSize: 0000A200 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: raspppoe.sys OriginalFilename: raspppoe.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: RAS PPPoE mini-port/call-manager driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba268000 ba273d00 raspptp (deferred) Image path: \SystemRoot\system32\DRIVERS\raspptp.sys Image name: raspptp.sys Timestamp: Wed Aug 04 07:14:26 2004 (41107EC2) CheckSum: 00016284 ImageSize: 0000BD00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba278000 ba280900 msgpc (deferred) Image path: \SystemRoot\system32\DRIVERS\msgpc.sys Image name: msgpc.sys Timestamp: Wed Aug 04 07:04:11 2004 (41107C5B) CheckSum: 0000AE74 ImageSize: 00008900 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba288000 ba291f00 termdd (deferred) Image path: \SystemRoot\system32\DRIVERS\termdd.sys Image name: termdd.sys Timestamp: Wed Aug 04 06:58:52 2004 (41107B1C) CheckSum: 0000E051 ImageSize: 00009F00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba328000 ba32e200 PCIIDEX (deferred) Image path: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS Image name: PCIIDEX.SYS Timestamp: Wed Aug 04 06:59:40 2004 (41107B4C) CheckSum: 0000D978 ImageSize: 00006200 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: pciidex.sys OriginalFilename: pciidex.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: PCI IDE Bus Driver Extension LegalCopyright: © Microsoft Corporation. All rights reserved. ba330000 ba334900 PartMgr (deferred) Image path: PartMgr.sys Image name: PartMgr.sys Timestamp: Sat Aug 18 02:32:23 2001 (3B7DC5A7) CheckSum: 00012793 ImageSize: 00004900 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba338000 ba33ce20 PxHelp20 (deferred) Image path: PxHelp20.sys Image name: PxHelp20.sys Timestamp: Mon Apr 25 20:48:02 2005 (426D4972) CheckSum: 0000BF9D ImageSize: 00004E20 File version: 2.3.32.0 Product version: 2.0.0.0 File flags: 0 (Mask 3F) File OS: 4 Unknown Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Sonic Solutions ProductName: PxHelp20 InternalName: PxHelp20 OriginalFilename: PxHelp20.sys FileVersion: 2.03.32a FileDescription: Px Engine Device Driver for Windows 2000/XP LegalCopyright: Copyright © Sonic Solutions ba3d8000 ba3dd000 usbuhci (deferred) Image path: \SystemRoot\system32\DRIVERS\usbuhci.sys Image name: usbuhci.sys Timestamp: Wed Aug 04 07:08:34 2004 (41107D62) CheckSum: 00013083 ImageSize: 00005000 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: USBUHCI.sys OriginalFilename: USBUHCI.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: UHCI USB Miniport Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba3e0000 ba3e6800 usbehci (deferred) Image path: \SystemRoot\system32\DRIVERS\usbehci.sys Image name: usbehci.sys Timestamp: Wed Aug 04 07:08:34 2004 (41107D62) CheckSum: 0000E59A ImageSize: 00006800 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba3e8000 ba3f0000 ctprxy2k (deferred) Image path: \SystemRoot\system32\drivers\ctprxy2k.sys Image name: ctprxy2k.sys Timestamp: Tue Nov 08 12:15:38 2005 (437096EA) CheckSum: 0000C2B1 ImageSize: 00008000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba3f0000 ba3f7000 GEARAspiWDM (deferred) Image path: \SystemRoot\System32\Drivers\GEARAspiWDM.sys Image name: GEARAspiWDM.sys Timestamp: Wed Feb 02 05:19:49 2005 (420062F5) CheckSum: 00011395 ImageSize: 00007000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba3f8000 ba3fc880 TDI (deferred) Image path: \SystemRoot\system32\DRIVERS\TDI.SYS Image name: TDI.SYS Timestamp: Wed Aug 04 07:07:47 2004 (41107D33) CheckSum: 00012DBA ImageSize: 00004880 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: tdi.sys OriginalFilename: tdi.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: TDI Wrapper LegalCopyright: © Microsoft Corporation. All rights reserved. ba400000 ba404580 ptilink (deferred) Image path: \SystemRoot\system32\DRIVERS\ptilink.sys Image name: ptilink.sys Timestamp: Fri Aug 17 21:49:53 2001 (3B7D8371) CheckSum: 0000648C ImageSize: 00004580 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba408000 ba40c080 raspti (deferred) Image path: \SystemRoot\system32\DRIVERS\raspti.sys Image name: raspti.sys Timestamp: Fri Aug 17 21:55:32 2001 (3B7D84C4) CheckSum: 000114B1 ImageSize: 00004080 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: raspti.sys OriginalFilename: raspti.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: PTI DirectParallel(R) mini-port/call-manager driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba410000 ba416000 kbdclass (deferred) Image path: \SystemRoot\system32\DRIVERS\kbdclass.sys Image name: kbdclass.sys Timestamp: Wed Aug 04 06:58:32 2004 (41107B08) CheckSum: 00014798 ImageSize: 00006000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba418000 ba41da00 mouclass (deferred) Image path: \SystemRoot\system32\DRIVERS\mouclass.sys Image name: mouclass.sys Timestamp: Wed Aug 04 06:58:32 2004 (41107B08) CheckSum: 0000A4D1 ImageSize: 00005A00 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba4b8000 ba4bb000 BOOTVID (deferred) Image path: \WINDOWS\system32\BOOTVID.dll Image name: BOOTVID.dll Timestamp: Fri Aug 17 21:49:09 2001 (3B7D8345) CheckSum: 0000A36C ImageSize: 00003000 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.4 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: bootvid.dll OriginalFilename: bootvid.dll ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: VGA Boot Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba550000 ba553c80 mssmbios (pdb symbols) c:\symbols \mssmbios.pdb\CEAE494998B24A458588AE7866D1B9421\mssmbios.pdb Loaded symbol image file: mssmbios.sys Image path: \SystemRoot\system32\DRIVERS\mssmbios.sys Image name: mssmbios.sys Timestamp: Wed Aug 04 07:07:47 2004 (41107D33) CheckSum: 0001304A ImageSize: 00003C80 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba564000 ba567280 ndisuio (deferred) Image path: \SystemRoot\system32\DRIVERS\ndisuio.sys Image name: ndisuio.sys Timestamp: Wed Aug 04 07:03:10 2004 (41107C1E) CheckSum: 00003A23 ImageSize: 00003280 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: NDISUIO.SYS OriginalFilename: NDISUIO.SYS ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: NDIS User mode I/O Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba5a8000 ba5a9b80 kdcom (deferred) Image path: kdcom.dll Image name: kdcom.dll Timestamp: Fri Aug 17 21:49:10 2001 (3B7D8346) CheckSum: 00008311 ImageSize: 00001B80 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.A Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: kdcom.dll OriginalFilename: kdcom.dll ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: Kernel Debugger HW Extension DLL LegalCopyright: © Microsoft Corporation. All rights reserved. ba5aa000 ba5ab100 WMILIB (deferred) Image path: \WINDOWS\system32\DRIVERS\WMILIB.SYS Image name: WMILIB.SYS Timestamp: Fri Aug 17 22:07:23 2001 (3B7D878B) CheckSum: 0000D600 ImageSize: 00001100 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba5be000 ba5bf280 USBD (deferred) Image path: \SystemRoot\system32\DRIVERS\USBD.SYS Image name: USBD.SYS Timestamp: Fri Aug 17 22:02:58 2001 (3B7D8682) CheckSum: 000040AF ImageSize: 00001280 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 2.0 Dll File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: usbd.sys OriginalFilename: usbd.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: Universal Serial Bus Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba5c0000 ba5c2000 i2omgmt (deferred) Image path: \SystemRoot\System32\Drivers\i2omgmt.SYS Image name: i2omgmt.SYS Timestamp: Wed Aug 04 07:00:50 2004 (41107B92) CheckSum: 0000DF6D ImageSize: 00002000 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: i2ofltr.sys OriginalFilename: i2ofltr.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: I2O Utility Filter LegalCopyright: © Microsoft Corporation. All rights reserved. ba5c2000 ba5c3f00 Fs_Rec (deferred) Image path: \SystemRoot\System32\Drivers\Fs_Rec.SYS Image name: Fs_Rec.SYS Timestamp: Fri Aug 17 21:49:37 2001 (3B7D8361) CheckSum: 000079A7 ImageSize: 00001F00 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: fs_rec.sys OriginalFilename: fs_rec.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: File System Recognizer Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba5c4000 ba5c5080 Beep (deferred) Image path: \SystemRoot\System32\Drivers\Beep.SYS Image name: Beep.SYS Timestamp: Fri Aug 17 21:47:33 2001 (3B7D82E5) CheckSum: 0000C82C ImageSize: 00001080 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: beep.sys OriginalFilename: beep.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: BEEP Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba5c6000 ba5c7080 mnmdd (deferred) Image path: \SystemRoot\System32\Drivers\mnmdd.SYS Image name: mnmdd.SYS Timestamp: Fri Aug 17 21:57:28 2001 (3B7D8538) CheckSum: 0000F3F7 ImageSize: 00001080 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.4 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: videosim.sys OriginalFilename: videosim.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: Frame buffer simulator LegalCopyright: © Microsoft Corporation. All rights reserved. ba5c8000 ba5c9080 RDPCDD (deferred) Image path: \SystemRoot\System32\DRIVERS\RDPCDD.sys Image name: RDPCDD.sys Timestamp: Fri Aug 17 21:46:56 2001 (3B7D82C0) CheckSum: 0000E2B7 ImageSize: 00001080 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.4 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: RDPCDD.SYS OriginalFilename: RDPCDD.SYS ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (xpclient.010817-1148) FileDescription: RDP Miniport LegalCopyright: © Microsoft Corporation. All rights reserved. ba5e8000 ba5e95c0 DLACDBHM (deferred) Image path: \SystemRoot\System32\Drivers\DLACDBHM.SYS Image name: DLACDBHM.SYS Timestamp: Thu Aug 25 20:16:50 2005 (430E1922) CheckSum: 00001AB0 ImageSize: 000015C0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba5ea000 ba5eb100 swenum (deferred) Image path: \SystemRoot\system32\DRIVERS\swenum.sys Image name: swenum.sys Timestamp: Wed Aug 04 06:58:41 2004 (41107B11) CheckSum: 00006DB6 ImageSize: 00001100 File version: 5.3.2600.2180 Product version: 5.3.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.0 Driver File date: 00000000.00000000 Translations: 0000.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft(R) Windows(R) Operating System InternalName: swenum.sys OriginalFilename: swenum.sys ProductVersion: 5.3.2600.2180 FileVersion: 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: Plug and Play Software Device Enumerator LegalCopyright: © Microsoft Corporation. All rights reserved. ba604000 ba605280 DSproct (deferred) Image path: \??\C:\Program Files\DellSupport\GTAction\triggers \DSproct.sys Image name: DSproct.sys Timestamp: Thu Oct 05 15:02:50 2006 (4525108A) CheckSum: 00002FD2 ImageSize: 00001280 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 ba670000 ba670d00 pciide (deferred) Image path: pciide.sys Image name: pciide.sys Timestamp: Fri Aug 17 21:51:49 2001 (3B7D83E5) CheckSum: 0000213E ImageSize: 00000D00 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: pciide.sys OriginalFilename: pciide.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: Generic PCI IDE Bus Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ba742000 ba742c00 audstub (deferred) Image path: \SystemRoot\system32\DRIVERS\audstub.sys Image name: audstub.sys Timestamp: Fri Aug 17 21:59:40 2001 (3B7D85BC) CheckSum: 000105B1 ImageSize: 00000C00 File version: 5.1.2600.0 Product version: 5.1.2600.0 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: audstub.sys OriginalFilename: audstub.sys ProductVersion: 5.1.2600.0 FileVersion: 5.1.2600.0 (XPClient.010817-1148) FileDescription: AudStub Driver LegalCopyright: © Microsoft Corporation. All rights reserved. bf000000 bf011580 dxg (deferred) Image path: \SystemRoot\System32\drivers\dxg.sys Image name: dxg.sys Timestamp: Wed Aug 04 07:00:51 2004 (41107B93) CheckSum: 0001D181 ImageSize: 00011580 File version: 5.1.2600.2180 Product version: 5.1.2600.2180 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: dxg.sys OriginalFilename: dxg.sys ProductVersion: 5.1.2600.2180 FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) FileDescription: DirectX Graphics Driver LegalCopyright: © Microsoft Corporation. All rights reserved. bf012000 bf3dc600 nv4_disp (deferred) Image path: \SystemRoot\System32\nv4_disp.dll Image name: nv4_disp.dll Timestamp: Sat Apr 01 05:38:25 2006 (442E03C1) CheckSum: 003CCFD0 ImageSize: 003CA600 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 bf800000 bf9c2180 win32k (deferred) Image path: \SystemRoot\System32\win32k.sys Image name: win32k.sys Timestamp: Thu Mar 08 13:47:34 2007 (45F013F6) CheckSum: 001C4886 ImageSize: 001C2180 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 Unloaded modules: 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f43f000 9f46a000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f64a000 9f675000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 a712e000 a7130000 splitter.sys Timestamp: unavailable (00000000) Checksum: 00000000 9f64a000 9f675000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 a39e3000 a3a0e000 kmixer.sys Timestamp: unavailable (00000000) Checksum: 00000000 a6310000 a6311000 drmkaud.sys Timestamp: unavailable (00000000) Checksum: 00000000 ba198000 ba1a5000 DMusic.sys Timestamp: unavailable (00000000) Checksum: 00000000 a3a0e000 a3a31000 aec.sys Timestamp: unavailable (00000000) Checksum: 00000000 ba2d8000 ba2e6000 swmidi.sys Timestamp: unavailable (00000000) Checksum: 00000000 a7e9d000 a7e9f000 splitter.sys Timestamp: unavailable (00000000) Checksum: 00000000 aecbd000 aeccd000 serial.sys Timestamp: unavailable (00000000) Checksum: 00000000 aed7d000 aed8a000 i8042prt.sys Timestamp: unavailable (00000000) Checksum: 00000000 b17fe000 b1802000 kbdhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 b0a72000 b0a77000 Cdaudio.SYS Timestamp: unavailable (00000000) Checksum: 00000000 b1806000 b1809000 Sfloppy.SYS Timestamp: unavailable (00000000) Checksum: 00000000 37000000 37013000 EntApi.dll Timestamp: Mon Aug 08 19:26:18 2005 (42F7A3CA) Checksum: 00000000 5b860000 5b8b4000 NETAPI32.dll Timestamp: Thu Aug 17 13:28:27 2006 (44E460EB) Checksum: 000532B4 76bf0000 76bfb000 PSAPI.DLL Timestamp: Wed Aug 04 08:56:58 2004 (411096CA) Checksum: 0000A29B 77c10000 77c68000 MSVCRT.dll Timestamp: Wed Aug 04 08:59:14 2004 (41109752) Checksum: 00057CD3 |
|
||
|
||||
|
|
|
| |
|
=?Utf-8?B?UmV5IFNhbnRvcw==?=
Guest
Posts: n/a
|
See this page and help your self. Good luck.
http://www.aumha.org/win5/kbestop.htm and click on the "7A: Kernel Data Inpage" link in the left side column. -- Hope I could help. "(E-Mail Removed)" wrote: > Hi > > I think i have a driver conflict that is intermittently causing the > blue screen of death and giving the following error message: > > STOP 0x000000f4 (0x00000003, 0x89140910, 0x89140a84, 0x805d11f8). > > I have tried everything i can thing of to resolve this problem > including re-installing the OS (XP Home) but to no avail. > > I have run the memory dump through winbdg in the hope that it would > pinpoint some unsigned driver, however the debugger seems to suggest > that the cause could be winsrv.dll. I am not particlularly sure how to > interpret the output of windbg therefore I would be grateful if anyone > could help interpret where the problem lies and any possible > resolution. > > Many thanks > -bob > > Output: > > Microsoft (R) Windows Debugger Version 6.7.0005.0 > Copyright (c) Microsoft Corporation. All rights reserved. > > > Loading Dump File [C:\Documents and Settings\bob\Desktop\MEMORY.DMP] > Kernel Complete Dump File: Full address space is available > > ************************************************************ > WARNING: Dump file has been truncated. Data may be missing. > ************************************************************ > Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/ > download/symbols > Executable search path is: > Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 > compatible > Product: WinNt, suite: TerminalServer SingleUserTS Personal > Built by: 2600.xpsp_sp2_gdr.070227-2254 > Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700 > Debug session time: Fri Apr 27 08:58:10.468 2007 (GMT+1) > System Uptime: 4 days 12:32:09.057 > Loading Kernel Symbols > ................................................................................................................................ > Loading User Symbols > ............ > Loading unloaded module list > .................................. > ******************************************************************************* > * > * > * Bugcheck > Analysis * > * > * > ******************************************************************************* > > Use !analyze -v to get detailed debugging information. > > BugCheck F4, {3, 89140910, 89140a84, 805d11f8} > > Probably caused by : winsrv.dll ( winsrv!UserHardError+0 ) > > Followup: MachineOwner > --------- > > 0: kd> !analyze -v > ******************************************************************************* > * > * > * Bugcheck > Analysis * > * > * > ******************************************************************************* > > CRITICAL_OBJECT_TERMINATION (f4) > A process or thread crucial to system operation has unexpectedly > exited or been > terminated. > Several processes and threads are necessary for the operation of the > system; when they are terminated (for any reason), the system can no > longer function. > Arguments: > Arg1: 00000003, Process > Arg2: 89140910, Terminating object > Arg3: 89140a84, Process image file name > Arg4: 805d11f8, Explanatory message (ascii) > > Debugging Details: > ------------------ > > > PROCESS_OBJECT: 89140910 > > IMAGE_NAME: winsrv.dll > > DEBUG_FLR_IMAGE_TIMESTAMP: 45fbf065 > > FAULTING_MODULE: 4a680000 csrss > > PROCESS_NAME: csrss.exe > > EXCEPTION_RECORD: a6e879d8 -- (.exr 0xffffffffa6e879d8) > ExceptionAddress: 75b7b399 (winsrv!UserHardError) > ExceptionCode: c0000006 (In-page I/O error) > ExceptionFlags: 00000000 > NumberParameters: 3 > Parameter[0]: 00000008 > Parameter[1]: 75b7b399 > Parameter[2]: c000009a > Inpage operation failed at 75b7b399, due to I/O error c000009a > > EXCEPTION_CODE: (NTSTATUS) 0xc000009a - Insufficient system resources > exist to complete the API. > > DEFAULT_BUCKET_ID: DRIVER_FAULT > > ERROR_CODE: (NTSTATUS) 0xc0000006 - The instruction at "0x%08lx" > referenced memory at "0x%08lx". The required data was not placed into > memory because of an I/O error status of "0x%08lx". > > IO_ERROR: (NTSTATUS) 0xc000009a - Insufficient system resources exist > to complete the API. > > EXCEPTION_STR: 0xc0000006_c000009a > > FAULTING_IP: > winsrv!UserHardError+0 > 75b7b399 ?? ??? > > BUGCHECK_STR: 0xF4_IOERR_C000009A > > STACK_TEXT: > a6e87520 805d039f 000000f4 00000003 89140910 nt!KeBugCheckEx+0x1b > a6e87544 805d12a3 805d11f8 89140910 89140a84 nt!PspCatchCriticalBreak > +0x75 > a6e87574 8054086c 89140b58 c0000006 a6e879b0 nt!NtTerminateProcess > +0x7d > a6e87574 80500679 89140b58 c0000006 a6e879b0 nt!KiFastCallEntry+0xfc > a6e875f4 804fe6aa ffffffff c0000006 a6e879f8 nt!ZwTerminateProcess > +0x11 > a6e879b0 80501db7 a6e879d8 00000000 a6e87d64 nt!KiDispatchException > +0x3a0 > a6e87d34 80544137 0069fbe8 0069fc08 00000000 nt!KiRaiseException+0x175 > a6e87d50 8054086c 0069fbe8 0069fc08 00000000 nt!NtRaiseException+0x33 > a6e87d50 75b7b399 0069fbe8 0069fc08 00000000 nt!KiFastCallEntry+0xfc > 0069fed0 75b447a0 00000000 0069feec 00000005 winsrv!UserHardError > 0069fff4 00000000 00000000 00000000 00000000 CSRSRV!CsrApiRequestThread > +0x18a > > > STACK_COMMAND: kb > > FOLLOWUP_IP: > winsrv!UserHardError+0 > 75b7b399 ?? ??? > > SYMBOL_NAME: winsrv!UserHardError+0 > > FOLLOWUP_NAME: MachineOwner > > MODULE_NAME: winsrv > > FAILURE_BUCKET_ID: 0xF4_IOERR_C000009A_winsrv!UserHardError+0 > > BUCKET_ID: 0xF4_IOERR_C000009A_winsrv!UserHardError+0 > > Followup: MachineOwner > --------- > > 0: kd> lmv > start end module name > 4a680000 4a685000 csrss (deferred) > Image path: \??\C:\WINDOWS\system32\csrss.exe > Image name: csrss.exe > Timestamp: Wed Aug 04 07:03:11 2004 (41107C1F) > CheckSum: 0000FC16 > ImageSize: 00005000 > Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 > 75b40000 75b4b000 CSRSRV (pdb symbols) c:\symbols > \csrsrv.pdb\B7F3643BB6774218BBA185BBCA5281BE1\csrsrv.pdb > Loaded symbol image file: CSRSRV.dll > Image path: C:\WINDOWS\system32\CSRSRV.dll > Image name: CSRSRV.dll > Timestamp: Wed Aug 04 08:56:10 2004 (4110969A) > CheckSum: 0000F947 > ImageSize: 0000B000 > Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 > 75b50000 75b60000 basesrv (deferred) > Image path: C:\WINDOWS\system32\basesrv.dll > Image name: basesrv.dll > Timestamp: Wed Aug 04 07:03:45 2004 (41107C41) > CheckSum: 00013F57 > ImageSize: 00010000 > Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 > 75b60000 75bab000 winsrv (pdb symbols) c:\symbols > \winsrv.pdb\439C1780ED41498BA4926507CF2C1B7D2\winsrv.pdb > Loaded symbol image file: winsrv.dll > Image path: C:\WINDOWS\system32\winsrv.dll > Image name: winsrv.dll > Timestamp: Sat Mar 17 13:43:01 2007 (45FBF065) > CheckSum: 0004BFBE > ImageSize: 0004B000 > File version: 5.1.2600.3103 > Product version: 5.1.2600.3103 > File flags: 0 (Mask 3F) > File OS: 40004 NT Win32 > File type: 2.0 Dll > File date: 00000000.00000000 > Translations: 0409.04b0 > CompanyName: Microsoft Corporation > ProductName: Microsoft® Windows® Operating System > InternalName: winsrv > OriginalFilename: winsrv.dll > ProductVersion: 5.1.2600.3103 > FileVersion: 5.1.2600.3103 (xpsp_sp2_gdr.070316-1309) > FileDescription: Windows Server DLL > LegalCopyright: © Microsoft Corporation. All rights reserved. > 75e90000 75f40000 sxs (deferred) > Image path: C:\WINDOWS\system32\sxs.dll > Image name: sxs.dll > Timestamp: Thu Oct 19 14:56:28 2006 (4537840C) > CheckSum: 000BC949 > ImageSize: 000B0000 > File version: 5.1.2600.3019 > Product version: 5.1.2600.3019 > File flags: 0 (Mask 3F) > File OS: 40004 NT Win32 > File type: 2.0 Dll > File date: 00000000.00000000 > Translations: 0409.04b0 > CompanyName: Microsoft Corporation > ProductName: Microsoft® Windows® Operating System > InternalName: SXS.DLL > OriginalFilename: SXS.DLL > ProductVersion: 5.1.2600.3019 > FileVersion: 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414) > FileDescription: Fusion 2.5 > LegalCopyright: © Microsoft Corporation. All rights reserved. > 77dd0000 77e6b000 ADVAPI32 (deferred) > Image path: C:\WINDOWS\system32\ADVAPI32.dll > Image name: ADVAPI32.dll > Timestamp: Wed Aug 04 08:56:23 2004 (411096A7) > CheckSum: 000A0DE4 > ImageSize: 0009B000 > File version: 5.1.2600.2180 > Product version: 5.1.2600.2180 > File flags: 0 (Mask 3F) > File OS: 40004 NT Win32 > File type: 2.0 Dll > File date: 00000000.00000000 > Translations: 0409.04b0 > CompanyName: Microsoft Corporation > ProductName: Microsoft® Windows® Operating System > InternalName: advapi32.dll > OriginalFilename: advapi32.dll > ProductVersion: 5.1.2600.2180 > FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) > FileDescription: Advanced Windows 32 Base API > LegalCopyright: © Microsoft Corporation. All rights reserved. > 77e70000 77f01000 RPCRT4 (deferred) > Image path: C:\WINDOWS\system32\RPCRT4.dll > Image name: RPCRT4.dll > Timestamp: Wed Aug 04 08:56:30 2004 (411096AE) > CheckSum: 0009C482 > ImageSize: 00091000 > File version: 5.1.2600.2180 > Product version: 5.1.2600.2180 > File flags: 0 (Mask 3F) > File OS: 40004 NT Win32 > File type: 2.0 Dll > File date: 00000000.00000000 > Translations: 0409.04b0 > CompanyName: Microsoft Corporation > ProductName: Microsoft® Windows® Operating System > InternalName: rpcrt4.dll > OriginalFilename: rpcrt4.dll > ProductVersion: 5.1.2600.2180 > FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) > FileDescription: Remote Procedure Call Runtime > LegalCopyright: © Microsoft Corporation. All rights reserved. > 77f10000 77f57000 GDI32 (deferred) > Image path: C:\WINDOWS\system32\GDI32.dll > Image name: GDI32.dll > Timestamp: Thu Mar 08 15:36:28 2007 (45F02D7C) > CheckSum: 00047DA0 > ImageSize: 00047000 > Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 > 7c800000 7c8f4000 KERNEL32 (deferred) > Image path: C:\WINDOWS\system32\KERNEL32.dll > Image name: KERNEL32.dll > Timestamp: Wed Jul 05 11:55:00 2006 (44AB9A84) > CheckSum: 000F724D > ImageSize: 000F4000 > Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0 > 7c900000 7c9b0000 ntdll (pdb symbols) c:\symbols > \ntdll.pdb\36515FB5D04345E491F672FA2E2878C02\ntdll.pdb > Loaded symbol image file: ntdll.dll > Mapped memory image file: c:\symbols\ntdll.dll |
|
||
|
||||
|
bobtabulous@yahoo.co.uk
Guest
Posts: n/a
|
On 29 Apr, 14:18, Rey Santos <ReySan...@discussions.microsoft.com>
wrote: > See this page and help your self. Good luck.http://www.aumha.org/win5/kbestop.htmand click on the "7A: Kernel > Data Inpage" link in the left side column. > > -- > Hope I could help. > > Hi Thanks for the reply. Actually, I have come across that page before; however, I did not think it was relevant. Or am i missing something. -bob |
|
||
|
||||
|
|
|
| |
![]() |
| Thread Tools | |
| Rate This Thread | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Driver conflict? | chansman | Windows XP Help | 1 | 23rd Aug 2006 10:25 PM |
| driver conflict | =?Utf-8?B?a3Nxd3Jk?= | Windows XP General | 0 | 27th Feb 2005 12:07 AM |
| driver conflict | Bill Cunningham | Windows XP Help | 1 | 20th Oct 2004 03:05 AM |
| xp driver conflict. | anthony | Windows XP Hardware | 2 | 11th Jul 2004 04:44 AM |
| driver conflict with XP: possibly video? but certified.. exact conflict unknown | seth thomas rasmussen | Windows XP Drivers | 9 | 8th Dec 2003 10:26 PM |
Powered by vBulletin®. Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2010, Crawlability, Inc. |




