ginnolo
03-11-2006, 22:26
pc Shuttle XPC SK21G, 1 HD serial ata da 160 1 gb di ram un lettore dvd e basta, windows xp sp2 e un modem ethernet dlink, ho gia formattato, cambiata la ram , cambiato hd e aggiornati tutti i driver ma continuo ad avere questo errore ogni 4-5 giorni:
ho provato a fare anche la proceduta della microsoft ma quelle voci nel registro non ci sono, aiutatemi!!!!!
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000001d, The exception code that was not handled
Arg2: 80531937, The address that the exception occurred at
Arg3: f6e94a34, Trap Frame
Arg4: 00000000
Microsoft (R) Windows Debugger Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [c:\windows\minidump\mini110306-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Fri Nov 3 20:37:56.687 2006 (GMT+1)
System Uptime: 0 days 1:27:12.825
Loading Kernel Symbols
..........................................................................................................................................
Loading User Symbols
Loading unloaded module list
.................
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c000001d, 80531937, f6e94a34, 0}
Probably caused by : win32k.sys
Followup: MachineOwner
---------
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000001d, The exception code that was not handled
Arg2: 80531937, The address that the exception occurred at
Arg3: f6e94a34, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {ERRORE DI EXCEPTION} Istruzione non valida Si tentato di eseguire un'istruzione non valida.
FAULTING_IP:
nt!ExAcquireResourceExclusiveLite+3
80531937 8bec mov ebp,esp
TRAP_FRAME: f6e94a34 -- (.trap fffffffff6e94a34)
ErrCode = 00000000
eax=85c027f0 ebx=00000000 ecx=00000000 edx=80010031 esi=00000001 edi=804fd79c
eip=80531937 esp=f6e94aa8 ebp=f6e94ad4 iopl=0 nv up ei ng nz ac pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010296
nt!ExAcquireResourceExclusiveLite+0x3:
80531937 8bec mov ebp,esp
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf800b2e to 80531937
FAILED_INSTRUCTION_ADDRESS:
nt!ExAcquireResourceExclusiveLite+3
80531937 8bec mov ebp,esp
STACK_TEXT:
f6e94aa8 bf800b2e 85daaab8 00000001 bf8011a2 nt!ExAcquireResourceExclusiveLite+0x3
f6e94ab4 bf8011a2 804fd79c 00000001 00000000 win32k!EnterCrit+0x14
f6e94ad4 bf888d06 00000022 006dfff4 bf8010a7 win32k!TimersProc+0x10
f6e94d30 bf86d09c f6ea44a8 00000002 f6e94d54 win32k!RawInputThread+0x634
f6e94d40 bf8010ca f6ea44a8 f6e94d64 006dfff4 win32k!xxxCreateSystemThreads+0x60
f6e94d54 8053c808 00000000 00000022 00000000 win32k!NtUserCallOneParam+0x23
f6e94d54 7c91eb94 00000000 00000022 00000000 nt!KiFastCallEntry+0xf8
WARNING: Frame IP not in any known module. Following frames may be wrong.
00000000 00000000 00000000 00000000 00000000 0x7c91eb94
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!EnterCrit+14
bf800b2e ff15e0b298bf call dword ptr [win32k!_imp__PsGetCurrentThread (bf98b2e0)]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: win32k!EnterCrit+14
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 43446a58
FAILURE_BUCKET_ID: 0x8E_BAD_IP_win32k!EnterCrit+14
BUCKET_ID: 0x8E_BAD_IP_win32k!EnterCrit+14
Followup: MachineOwner
---------
GetPointerFromAddress: unable to read from 80557bb4
THREAD 85c027f0 Cid 02e8.0314 Teb: 7ffd8000 Win32Thread: e164ab68 RUNNING on processor 0
IRP List:
Unable to read nt!_IRP @ 85397150
Not impersonating
GetUlongFromAddress: unable to read from 80557bc4
Owning Process 85dfb688 Image: csrss.exe
ffdf0000: Unable to get shared data
Wait Start TickCount 334900
Context Switch Count 955171 LargeStack
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.0000
KernelTime 00:00:00.0000
Start Address 0x75b17cd7
Stack Init f6e95000 Current f6e94a58 Base f6e95000 Limit f6e92000 Call 0
Priority 13 BasePriority 13 PriorityDecrement 0 DecrementCount 16
ChildEBP RetAddr Args to Child
f6e94aa8 bf800b2e 85daaab8 00000001 bf8011a2 nt!ExAcquireResourceExclusiveLite+0x3 (FPO: [Non-Fpo])
f6e94ab4 bf8011a2 804fd79c 00000001 00000000 win32k!EnterCrit+0x14 (FPO: [0,0,0])
f6e94ad4 bf888d06 00000022 006dfff4 bf8010a7 win32k!TimersProc+0x10 (FPO: [Non-Fpo])
f6e94d30 bf86d09c f6ea44a8 00000002 f6e94d54 win32k!RawInputThread+0x634 (FPO: [Non-Fpo])
f6e94d40 bf8010ca f6ea44a8 f6e94d64 006dfff4 win32k!xxxCreateSystemThreads+0x60 (FPO: [Non-Fpo])
f6e94d54 8053c808 00000000 00000022 00000000 win32k!NtUserCallOneParam+0x23 (FPO: [Non-Fpo])
f6e94d54 7c91eb94 00000000 00000022 00000000 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f6e94d64)
WARNING: Frame IP not in any known module. Following frames may be wrong.
00000000 00000000 00000000 00000000 00000000 0x7c91eb94
start end module name
804d7000 806ce100 nt (pdb symbols) c:\symbols\ntkrnlpa.pdb\89C2A9EB56A74E2D8269AFD1D835BA331\ntkrnlpa.pdb
Loaded symbol image file: ntkrnlpa.exe
Mapped memory image file: c:\symbols\ntkrnlpa.exe\42250A1D1f7100\ntkrnlpa.exe
Image path: ntkrnlpa.exe
Image name: ntkrnlpa.exe
Timestamp: Wed Mar 02 01:34:37 2005 (42250A1D)
CheckSum: 001FF759
ImageSize: 001F7100
File version: 5.1.2600.2622
Product version: 5.1.2600.2622
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0410.04b0
CompanyName: Microsoft Corporation
ProductName: Sistema operativo Microsoft® Windows®
InternalName: ntkrnlpa.exe
OriginalFilename: ntkrnlpa.exe
ProductVersion: 5.1.2600.2622
FileVersion: 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)
FileDescription: Sistema e kernel NT
LegalCopyright: © Microsoft Corporation. Tutti i diritti riservati.
806cf000 806ef380 hal (deferred)
Mapped memory image file: c:\symbols\halaacpi.dll\41107B2920380\halaacpi.dll
Image path: halaacpi.dll
Image name: halaacpi.dll
Timestamp: Wed Aug 04 07:59:05 2004 (41107B29)
CheckSum: 0002CFD1
ImageSize: 00020380
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: halaacpi.dll
OriginalFilename: halaacpi.dll
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Hardware Abstraction Layer DLL
LegalCopyright: © Microsoft Corporation. All rights reserved.
bf800000 bf9c1180 win32k (pdb symbols) c:\symbols\win32k.pdb\D8788E4736B34ED5B8516DBB9D45E9942\win32k.pdb
Loaded symbol image file: win32k.sys
Mapped memory image file: c:\symbols\win32k.sys\43446A581c1180\win32k.sys
Image path: win32k.sys
Image name: win32k.sys
Timestamp: Thu Oct 06 02:05:44 2005 (43446A58)
CheckSum: 001CA9CB
ImageSize: 001C1180
File version: 5.1.2600.2770
Product version: 5.1.2600.2770
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: win32k.sys
OriginalFilename: win32k.sys
ProductVersion: 5.1.2600.2770
FileVersion: 5.1.2600.2770 (xpsp_sp2_gdr.051005-1513)
FileDescription: Win32-drivrutin för flera användare
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
bf9c2000 bf9d3580 dxg (deferred)
Mapped memory image file: c:\symbols\dxg.sys\41107B9311580\dxg.sys
Image path: dxg.sys
Image name: dxg.sys
Timestamp: Wed Aug 04 08:00:51 2004 (41107B93)
CheckSum: 0001D181
ImageSize: 00011580
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: dxg.sys
OriginalFilename: dxg.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: DirectX Graphics Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
bf9d4000 bfcf5a80 vtdisp (deferred)
Image path: vtdisp.dll
Image name: vtdisp.dll
Timestamp: Wed May 19 14:10:40 2004 (40AB4EC0)
CheckSum: 00330DCD
ImageSize: 00321A80
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
efefc000 eff26180 kmixer (deferred)
Mapped memory image file: c:\symbols\kmixer.sys\448FCD312a180\kmixer.sys
Image path: kmixer.sys
Image name: kmixer.sys
Timestamp: Wed Jun 14 10:47:45 2006 (448FCD31)
CheckSum: 0002C363
ImageSize: 0002A180
File version: 5.1.2600.2929
Product version: 5.1.2600.2929
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: kmixer.sys
OriginalFilename: kmixer.sys
ProductVersion: 5.1.2600.2929
FileVersion: 5.1.2600.2929 (xpsp_sp2_gdr.060613-2359)
FileDescription: Kernel Mode Audio Mixer
LegalCopyright: © Microsoft Corporation. All rights reserved.
eff27000 eff37280 Udfs (deferred)
Mapped memory image file: c:\symbols\Udfs.SYS\41107B7B10280\Udfs.SYS
Image path: Udfs.SYS
Image name: Udfs.SYS
Timestamp: Wed Aug 04 08:00:27 2004 (41107B7B)
CheckSum: 00018824
ImageSize: 00010280
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: udfs.sys
OriginalFilename: udfs.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: UDF File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f03a1000 f03e1280 HTTP (deferred)
Mapped memory image file: c:\symbols\HTTP.sys\441A03C540280\HTTP.sys
Image path: HTTP.sys
Image name: HTTP.sys
Timestamp: Fri Mar 17 01:33:09 2006 (441A03C5)
CheckSum: 00047848
ImageSize: 00040280
File version: 5.1.2600.2869
Product version: 5.1.2600.2869
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: http.sys
OriginalFilename: http.sys
ProductVersion: 5.1.2600.2869
FileVersion: 5.1.2600.2869 (xpsp_sp2_gdr.060316-1512)
FileDescription: HTTP Protocol Stack
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0af3000 f0b07400 wdmaud (deferred)
Mapped memory image file: c:\symbols\wdmaud.sys\448FD03C14400\wdmaud.sys
Image path: wdmaud.sys
Image name: wdmaud.sys
Timestamp: Wed Jun 14 11:00:44 2006 (448FD03C)
CheckSum: 000171EC
ImageSize: 00014400
File version: 5.1.2600.2929
Product version: 5.1.2600.2929
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: WDMAUD
OriginalFilename: WDMAUD.SYS
ProductVersion: 5.1.2600.2929
FileVersion: 5.1.2600.2929 (xpsp_sp2_gdr.060613-2359)
FileDescription: MMSYSTEM Wave/Midi API mapper
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0bd0000 f0c21480 srv (deferred)
Mapped memory image file: c:\symbols\srv.sys\44E051BF51480\srv.sys
Image path: srv.sys
Image name: srv.sys
Timestamp: Mon Aug 14 12:34:39 2006 (44E051BF)
CheckSum: 00059B2B
ImageSize: 00051480
File version: 5.1.2600.2974
Product version: 5.1.2600.2974
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: SRV.SYS
OriginalFilename: SRV.SYS
ProductVersion: 5.1.2600.2974
FileVersion: 5.1.2600.2974 (xpsp_sp2_gdr.060814-0101)
FileDescription: Server driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0dda000 f0e06400 mrxdav (deferred)
Mapped memory image file: c:\symbols\mrxdav.sys\41107B912c400\mrxdav.sys
Image path: mrxdav.sys
Image name: mrxdav.sys
Timestamp: Wed Aug 04 08:00:49 2004 (41107B91)
CheckSum: 000398F1
ImageSize: 0002C400
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: MRxDav.sys
OriginalFilename: MRxDAV.Sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Windows NT WebDav Minirdr
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0e37000 f0e39680 ElbyCDIO (deferred)
Image path: ElbyCDIO.sys
Image name: ElbyCDIO.sys
Timestamp: Wed Jul 21 23:45:25 2004 (40FEE3F5)
CheckSum: 0000329F
ImageSize: 00002680
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f0f0b000 f0f0eee0 Aspi32 (deferred)
Image path: Aspi32.SYS
Image name: Aspi32.SYS
Timestamp: Mon May 06 18:43:02 2002 (3CD6B296)
CheckSum: 00013DCE
ImageSize: 00003EE0
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f1093000 f1096280 ndisuio (deferred)
Mapped memory image file: c:\symbols\ndisuio.sys\41107C1E3280\ndisuio.sys
Image path: ndisuio.sys
Image name: ndisuio.sys
Timestamp: Wed Aug 04 08:03:10 2004 (41107C1E)
CheckSum: 00003A23
ImageSize: 00003280
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: NDISUIO.SYS
OriginalFilename: NDISUIO.SYS
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: NDIS User mode I/O Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f59ef000 f5a06480 dump_atapi (deferred)
Mapped memory image file: c:\symbols\atapi.sys\41107B4D17480\atapi.sys
Image path: dump_atapi.sys
Image name: dump_atapi.sys
Timestamp: Wed Aug 04 07:59:41 2004 (41107B4D)
CheckSum: 000208FA
ImageSize: 00017480
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: atapi.sys
OriginalFilename: atapi.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: IDE/ATAPI Port Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5aa7000 f5aca000 Fastfat (deferred)
Mapped memory image file: c:\symbols\Fastfat.SYS\41107EB723000\Fastfat.SYS
Image path: Fastfat.SYS
Image name: Fastfat.SYS
Timestamp: Wed Aug 04 08:14:15 2004 (41107EB7)
CheckSum: 00027EAA
ImageSize: 00023000
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: fastfat.sys
OriginalFilename: FastFAT.Sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Fast FAT File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5af2000 f5bb9620 avg7core (deferred)
Image path: avg7core.sys
Image name: avg7core.sys
Timestamp: Mon Oct 23 20:52:56 2006 (453D0F88)
CheckSum: 000CF836
ImageSize: 000C7620
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f5bba000 f5bdaf00 ipnat (deferred)
Mapped memory image file: c:\symbols\ipnat.sys\415B371420f00\ipnat.sys
Image path: ipnat.sys
Image name: ipnat.sys
Timestamp: Thu Sep 30 00:28:36 2004 (415B3714)
CheckSum: 00024074
ImageSize: 00020F00
File version: 5.1.2600.2524
Product version: 5.1.2600.2524
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: IPNAT.SYS
OriginalFilename: IPNAT.SYS
ProductVersion: 5.1.2600.2524
FileVersion: 5.1.2600.2524 (xpsp_sp2_gdr.040919-1056)
FileDescription: IP Network Address Translator
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5bdb000 f5c49a00 mrxsmb (deferred)
Mapped memory image file: c:\symbols\mrxsmb.sys\445B1DD66ea00\mrxsmb.sys
Image path: mrxsmb.sys
Image name: mrxsmb.sys
Timestamp: Fri May 05 11:41:42 2006 (445B1DD6)
CheckSum: 0007CA79
ImageSize: 0006EA00
File version: 5.1.2600.2902
Product version: 5.1.2600.2902
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: MRxSmb.sys
OriginalFilename: MRXSMB.Sys
ProductVersion: 5.1.2600.2902
FileVersion: 5.1.2600.2902 (xpsp_sp2_gdr.060505-0036)
FileDescription: Windows NT SMB Minirdr
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c4a000 f5c74a00 rdbss (deferred)
Mapped memory image file: c:\symbols\rdbss.sys\445B1F4B2aa00\rdbss.sys
Image path: rdbss.sys
Image name: rdbss.sys
Timestamp: Fri May 05 11:47:55 2006 (445B1F4B)
CheckSum: 000345EF
ImageSize: 0002AA00
File version: 5.1.2600.2902
Product version: 5.1.2600.2902
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: rdbss.sys
OriginalFilename: RDBSS.Sys
ProductVersion: 5.1.2600.2902
FileVersion: 5.1.2600.2902 (xpsp_sp2_gdr.060505-0036)
FileDescription: Redirected Drive Buffering SubSystem Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c75000 f5c96d00 afd (deferred)
Mapped memory image file: c:\symbols\afd.sys\41107EB521d00\afd.sys
Image path: afd.sys
Image name: afd.sys
Timestamp: Wed Aug 04 08:14:13 2004 (41107EB5)
CheckSum: 0002DC47
ImageSize: 00021D00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: afd.sys
OriginalFilename: afd.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Ancillary Function Driver for WinSock
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c97000 f5cbec00 netbt (deferred)
Mapped memory image file: c:\symbols\netbt.sys\41107ECC27c00\netbt.sys
Image path: netbt.sys
Image name: netbt.sys
Timestamp: Wed Aug 04 08:14:36 2004 (41107ECC)
CheckSum: 00033EE9
ImageSize: 00027C00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: netbt.sys
OriginalFilename: netbt.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: MBT Transport driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5cbf000 f5d16d80 tcpip (deferred)
Mapped memory image file: c:\symbols\tcpip.sys\444775D357d80\tcpip.sys
Image path: tcpip.sys
Image name: tcpip.sys
Timestamp: Thu Apr 20 13:51:47 2006 (444775D3)
CheckSum: 0005F959
ImageSize: 00057D80
File version: 5.1.2600.2892
Product version: 5.1.2600.2892
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: tcpip.sys
OriginalFilename: tcpip.sys
ProductVersion: 5.1.2600.2892
FileVersion: 5.1.2600.2892 (xpsp_sp2_gdr.060420-0254)
FileDescription: TCP/IP Protocol Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5d17000 f5d29400 ipsec (deferred)
Mapped memory image file: c:\symbols\ipsec.sys\41107EC312400\ipsec.sys
Image path: ipsec.sys
Image name: ipsec.sys
Timestamp: Wed Aug 04 08:14:27 2004 (41107EC3)
CheckSum: 0001A264
ImageSize: 00012400
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ipsec.sys
OriginalFilename: ipsec.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: IPSec Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5d56000 f5d58f80 mouhid (deferred)
Mapped memory image file: c:\symbols\mouhid.sys\3B7D82FD2f80\mouhid.sys
Image path: mouhid.sys
Image name: mouhid.sys
Timestamp: Fri Aug 17 22:47:57 2001 (3B7D82FD)
CheckSum: 00010628
ImageSize: 00002F80
File version: 5.1.2600.0
Product version: 5.1.2600.0
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: mouhid.sys
OriginalFilename: mouhid.sys
ProductVersion: 5.1.2600.0
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
FileDescription: Filterdrivrutin för HID-mus
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
f5d5a000 f5d5da00 kbdhid (deferred)
Mapped memory image file: c:\symbols\kbdhid.sys\41107B093a00\kbdhid.sys
Image path: kbdhid.sys
Image name: kbdhid.sys
Timestamp: Wed Aug 04 07:58:33 2004 (41107B09)
CheckSum: 000081CA
ImageSize: 00003A00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: kbdhid.sys
OriginalFilename: kbdhid.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Filterdrivrutin för HID-mus
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
f5d5e000 f5d60580 hidusb (deferred)
Mapped memory image file: c:\symbols\hidusb.sys\3B7D86582580\hidusb.sys
Image path: hidusb.sys
Image name: hidusb.sys
Timestamp: Fri Aug 17 23:02:16 2001 (3B7D8658)
CheckSum: 0000D6C8
ImageSize: 00002580
File version: 5.1.2600.0
Product version: 5.1.2600.0
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: HIDUSB.SYS
OriginalFilename: HIDUSB.SYS
ProductVersion: 5.1.2600.0
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
FileDescription: USB Miniport Driver for Input Devices
LegalCopyright: © Microsoft Corporation. All rights reserved.
f6d9a000 f6dc8000 MarvinBus
ho provato a fare anche la proceduta della microsoft ma quelle voci nel registro non ci sono, aiutatemi!!!!!
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000001d, The exception code that was not handled
Arg2: 80531937, The address that the exception occurred at
Arg3: f6e94a34, Trap Frame
Arg4: 00000000
Microsoft (R) Windows Debugger Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [c:\windows\minidump\mini110306-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Fri Nov 3 20:37:56.687 2006 (GMT+1)
System Uptime: 0 days 1:27:12.825
Loading Kernel Symbols
..........................................................................................................................................
Loading User Symbols
Loading unloaded module list
.................
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c000001d, 80531937, f6e94a34, 0}
Probably caused by : win32k.sys
Followup: MachineOwner
---------
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000001d, The exception code that was not handled
Arg2: 80531937, The address that the exception occurred at
Arg3: f6e94a34, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {ERRORE DI EXCEPTION} Istruzione non valida Si tentato di eseguire un'istruzione non valida.
FAULTING_IP:
nt!ExAcquireResourceExclusiveLite+3
80531937 8bec mov ebp,esp
TRAP_FRAME: f6e94a34 -- (.trap fffffffff6e94a34)
ErrCode = 00000000
eax=85c027f0 ebx=00000000 ecx=00000000 edx=80010031 esi=00000001 edi=804fd79c
eip=80531937 esp=f6e94aa8 ebp=f6e94ad4 iopl=0 nv up ei ng nz ac pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010296
nt!ExAcquireResourceExclusiveLite+0x3:
80531937 8bec mov ebp,esp
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf800b2e to 80531937
FAILED_INSTRUCTION_ADDRESS:
nt!ExAcquireResourceExclusiveLite+3
80531937 8bec mov ebp,esp
STACK_TEXT:
f6e94aa8 bf800b2e 85daaab8 00000001 bf8011a2 nt!ExAcquireResourceExclusiveLite+0x3
f6e94ab4 bf8011a2 804fd79c 00000001 00000000 win32k!EnterCrit+0x14
f6e94ad4 bf888d06 00000022 006dfff4 bf8010a7 win32k!TimersProc+0x10
f6e94d30 bf86d09c f6ea44a8 00000002 f6e94d54 win32k!RawInputThread+0x634
f6e94d40 bf8010ca f6ea44a8 f6e94d64 006dfff4 win32k!xxxCreateSystemThreads+0x60
f6e94d54 8053c808 00000000 00000022 00000000 win32k!NtUserCallOneParam+0x23
f6e94d54 7c91eb94 00000000 00000022 00000000 nt!KiFastCallEntry+0xf8
WARNING: Frame IP not in any known module. Following frames may be wrong.
00000000 00000000 00000000 00000000 00000000 0x7c91eb94
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!EnterCrit+14
bf800b2e ff15e0b298bf call dword ptr [win32k!_imp__PsGetCurrentThread (bf98b2e0)]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: win32k!EnterCrit+14
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 43446a58
FAILURE_BUCKET_ID: 0x8E_BAD_IP_win32k!EnterCrit+14
BUCKET_ID: 0x8E_BAD_IP_win32k!EnterCrit+14
Followup: MachineOwner
---------
GetPointerFromAddress: unable to read from 80557bb4
THREAD 85c027f0 Cid 02e8.0314 Teb: 7ffd8000 Win32Thread: e164ab68 RUNNING on processor 0
IRP List:
Unable to read nt!_IRP @ 85397150
Not impersonating
GetUlongFromAddress: unable to read from 80557bc4
Owning Process 85dfb688 Image: csrss.exe
ffdf0000: Unable to get shared data
Wait Start TickCount 334900
Context Switch Count 955171 LargeStack
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.0000
KernelTime 00:00:00.0000
Start Address 0x75b17cd7
Stack Init f6e95000 Current f6e94a58 Base f6e95000 Limit f6e92000 Call 0
Priority 13 BasePriority 13 PriorityDecrement 0 DecrementCount 16
ChildEBP RetAddr Args to Child
f6e94aa8 bf800b2e 85daaab8 00000001 bf8011a2 nt!ExAcquireResourceExclusiveLite+0x3 (FPO: [Non-Fpo])
f6e94ab4 bf8011a2 804fd79c 00000001 00000000 win32k!EnterCrit+0x14 (FPO: [0,0,0])
f6e94ad4 bf888d06 00000022 006dfff4 bf8010a7 win32k!TimersProc+0x10 (FPO: [Non-Fpo])
f6e94d30 bf86d09c f6ea44a8 00000002 f6e94d54 win32k!RawInputThread+0x634 (FPO: [Non-Fpo])
f6e94d40 bf8010ca f6ea44a8 f6e94d64 006dfff4 win32k!xxxCreateSystemThreads+0x60 (FPO: [Non-Fpo])
f6e94d54 8053c808 00000000 00000022 00000000 win32k!NtUserCallOneParam+0x23 (FPO: [Non-Fpo])
f6e94d54 7c91eb94 00000000 00000022 00000000 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f6e94d64)
WARNING: Frame IP not in any known module. Following frames may be wrong.
00000000 00000000 00000000 00000000 00000000 0x7c91eb94
start end module name
804d7000 806ce100 nt (pdb symbols) c:\symbols\ntkrnlpa.pdb\89C2A9EB56A74E2D8269AFD1D835BA331\ntkrnlpa.pdb
Loaded symbol image file: ntkrnlpa.exe
Mapped memory image file: c:\symbols\ntkrnlpa.exe\42250A1D1f7100\ntkrnlpa.exe
Image path: ntkrnlpa.exe
Image name: ntkrnlpa.exe
Timestamp: Wed Mar 02 01:34:37 2005 (42250A1D)
CheckSum: 001FF759
ImageSize: 001F7100
File version: 5.1.2600.2622
Product version: 5.1.2600.2622
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0410.04b0
CompanyName: Microsoft Corporation
ProductName: Sistema operativo Microsoft® Windows®
InternalName: ntkrnlpa.exe
OriginalFilename: ntkrnlpa.exe
ProductVersion: 5.1.2600.2622
FileVersion: 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)
FileDescription: Sistema e kernel NT
LegalCopyright: © Microsoft Corporation. Tutti i diritti riservati.
806cf000 806ef380 hal (deferred)
Mapped memory image file: c:\symbols\halaacpi.dll\41107B2920380\halaacpi.dll
Image path: halaacpi.dll
Image name: halaacpi.dll
Timestamp: Wed Aug 04 07:59:05 2004 (41107B29)
CheckSum: 0002CFD1
ImageSize: 00020380
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: halaacpi.dll
OriginalFilename: halaacpi.dll
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Hardware Abstraction Layer DLL
LegalCopyright: © Microsoft Corporation. All rights reserved.
bf800000 bf9c1180 win32k (pdb symbols) c:\symbols\win32k.pdb\D8788E4736B34ED5B8516DBB9D45E9942\win32k.pdb
Loaded symbol image file: win32k.sys
Mapped memory image file: c:\symbols\win32k.sys\43446A581c1180\win32k.sys
Image path: win32k.sys
Image name: win32k.sys
Timestamp: Thu Oct 06 02:05:44 2005 (43446A58)
CheckSum: 001CA9CB
ImageSize: 001C1180
File version: 5.1.2600.2770
Product version: 5.1.2600.2770
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: win32k.sys
OriginalFilename: win32k.sys
ProductVersion: 5.1.2600.2770
FileVersion: 5.1.2600.2770 (xpsp_sp2_gdr.051005-1513)
FileDescription: Win32-drivrutin för flera användare
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
bf9c2000 bf9d3580 dxg (deferred)
Mapped memory image file: c:\symbols\dxg.sys\41107B9311580\dxg.sys
Image path: dxg.sys
Image name: dxg.sys
Timestamp: Wed Aug 04 08:00:51 2004 (41107B93)
CheckSum: 0001D181
ImageSize: 00011580
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: dxg.sys
OriginalFilename: dxg.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: DirectX Graphics Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
bf9d4000 bfcf5a80 vtdisp (deferred)
Image path: vtdisp.dll
Image name: vtdisp.dll
Timestamp: Wed May 19 14:10:40 2004 (40AB4EC0)
CheckSum: 00330DCD
ImageSize: 00321A80
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
efefc000 eff26180 kmixer (deferred)
Mapped memory image file: c:\symbols\kmixer.sys\448FCD312a180\kmixer.sys
Image path: kmixer.sys
Image name: kmixer.sys
Timestamp: Wed Jun 14 10:47:45 2006 (448FCD31)
CheckSum: 0002C363
ImageSize: 0002A180
File version: 5.1.2600.2929
Product version: 5.1.2600.2929
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: kmixer.sys
OriginalFilename: kmixer.sys
ProductVersion: 5.1.2600.2929
FileVersion: 5.1.2600.2929 (xpsp_sp2_gdr.060613-2359)
FileDescription: Kernel Mode Audio Mixer
LegalCopyright: © Microsoft Corporation. All rights reserved.
eff27000 eff37280 Udfs (deferred)
Mapped memory image file: c:\symbols\Udfs.SYS\41107B7B10280\Udfs.SYS
Image path: Udfs.SYS
Image name: Udfs.SYS
Timestamp: Wed Aug 04 08:00:27 2004 (41107B7B)
CheckSum: 00018824
ImageSize: 00010280
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: udfs.sys
OriginalFilename: udfs.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: UDF File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f03a1000 f03e1280 HTTP (deferred)
Mapped memory image file: c:\symbols\HTTP.sys\441A03C540280\HTTP.sys
Image path: HTTP.sys
Image name: HTTP.sys
Timestamp: Fri Mar 17 01:33:09 2006 (441A03C5)
CheckSum: 00047848
ImageSize: 00040280
File version: 5.1.2600.2869
Product version: 5.1.2600.2869
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: http.sys
OriginalFilename: http.sys
ProductVersion: 5.1.2600.2869
FileVersion: 5.1.2600.2869 (xpsp_sp2_gdr.060316-1512)
FileDescription: HTTP Protocol Stack
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0af3000 f0b07400 wdmaud (deferred)
Mapped memory image file: c:\symbols\wdmaud.sys\448FD03C14400\wdmaud.sys
Image path: wdmaud.sys
Image name: wdmaud.sys
Timestamp: Wed Jun 14 11:00:44 2006 (448FD03C)
CheckSum: 000171EC
ImageSize: 00014400
File version: 5.1.2600.2929
Product version: 5.1.2600.2929
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: WDMAUD
OriginalFilename: WDMAUD.SYS
ProductVersion: 5.1.2600.2929
FileVersion: 5.1.2600.2929 (xpsp_sp2_gdr.060613-2359)
FileDescription: MMSYSTEM Wave/Midi API mapper
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0bd0000 f0c21480 srv (deferred)
Mapped memory image file: c:\symbols\srv.sys\44E051BF51480\srv.sys
Image path: srv.sys
Image name: srv.sys
Timestamp: Mon Aug 14 12:34:39 2006 (44E051BF)
CheckSum: 00059B2B
ImageSize: 00051480
File version: 5.1.2600.2974
Product version: 5.1.2600.2974
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: SRV.SYS
OriginalFilename: SRV.SYS
ProductVersion: 5.1.2600.2974
FileVersion: 5.1.2600.2974 (xpsp_sp2_gdr.060814-0101)
FileDescription: Server driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0dda000 f0e06400 mrxdav (deferred)
Mapped memory image file: c:\symbols\mrxdav.sys\41107B912c400\mrxdav.sys
Image path: mrxdav.sys
Image name: mrxdav.sys
Timestamp: Wed Aug 04 08:00:49 2004 (41107B91)
CheckSum: 000398F1
ImageSize: 0002C400
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: MRxDav.sys
OriginalFilename: MRxDAV.Sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Windows NT WebDav Minirdr
LegalCopyright: © Microsoft Corporation. All rights reserved.
f0e37000 f0e39680 ElbyCDIO (deferred)
Image path: ElbyCDIO.sys
Image name: ElbyCDIO.sys
Timestamp: Wed Jul 21 23:45:25 2004 (40FEE3F5)
CheckSum: 0000329F
ImageSize: 00002680
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f0f0b000 f0f0eee0 Aspi32 (deferred)
Image path: Aspi32.SYS
Image name: Aspi32.SYS
Timestamp: Mon May 06 18:43:02 2002 (3CD6B296)
CheckSum: 00013DCE
ImageSize: 00003EE0
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f1093000 f1096280 ndisuio (deferred)
Mapped memory image file: c:\symbols\ndisuio.sys\41107C1E3280\ndisuio.sys
Image path: ndisuio.sys
Image name: ndisuio.sys
Timestamp: Wed Aug 04 08:03:10 2004 (41107C1E)
CheckSum: 00003A23
ImageSize: 00003280
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: NDISUIO.SYS
OriginalFilename: NDISUIO.SYS
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: NDIS User mode I/O Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f59ef000 f5a06480 dump_atapi (deferred)
Mapped memory image file: c:\symbols\atapi.sys\41107B4D17480\atapi.sys
Image path: dump_atapi.sys
Image name: dump_atapi.sys
Timestamp: Wed Aug 04 07:59:41 2004 (41107B4D)
CheckSum: 000208FA
ImageSize: 00017480
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: atapi.sys
OriginalFilename: atapi.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: IDE/ATAPI Port Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5aa7000 f5aca000 Fastfat (deferred)
Mapped memory image file: c:\symbols\Fastfat.SYS\41107EB723000\Fastfat.SYS
Image path: Fastfat.SYS
Image name: Fastfat.SYS
Timestamp: Wed Aug 04 08:14:15 2004 (41107EB7)
CheckSum: 00027EAA
ImageSize: 00023000
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: fastfat.sys
OriginalFilename: FastFAT.Sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Fast FAT File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5af2000 f5bb9620 avg7core (deferred)
Image path: avg7core.sys
Image name: avg7core.sys
Timestamp: Mon Oct 23 20:52:56 2006 (453D0F88)
CheckSum: 000CF836
ImageSize: 000C7620
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
f5bba000 f5bdaf00 ipnat (deferred)
Mapped memory image file: c:\symbols\ipnat.sys\415B371420f00\ipnat.sys
Image path: ipnat.sys
Image name: ipnat.sys
Timestamp: Thu Sep 30 00:28:36 2004 (415B3714)
CheckSum: 00024074
ImageSize: 00020F00
File version: 5.1.2600.2524
Product version: 5.1.2600.2524
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: IPNAT.SYS
OriginalFilename: IPNAT.SYS
ProductVersion: 5.1.2600.2524
FileVersion: 5.1.2600.2524 (xpsp_sp2_gdr.040919-1056)
FileDescription: IP Network Address Translator
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5bdb000 f5c49a00 mrxsmb (deferred)
Mapped memory image file: c:\symbols\mrxsmb.sys\445B1DD66ea00\mrxsmb.sys
Image path: mrxsmb.sys
Image name: mrxsmb.sys
Timestamp: Fri May 05 11:41:42 2006 (445B1DD6)
CheckSum: 0007CA79
ImageSize: 0006EA00
File version: 5.1.2600.2902
Product version: 5.1.2600.2902
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: MRxSmb.sys
OriginalFilename: MRXSMB.Sys
ProductVersion: 5.1.2600.2902
FileVersion: 5.1.2600.2902 (xpsp_sp2_gdr.060505-0036)
FileDescription: Windows NT SMB Minirdr
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c4a000 f5c74a00 rdbss (deferred)
Mapped memory image file: c:\symbols\rdbss.sys\445B1F4B2aa00\rdbss.sys
Image path: rdbss.sys
Image name: rdbss.sys
Timestamp: Fri May 05 11:47:55 2006 (445B1F4B)
CheckSum: 000345EF
ImageSize: 0002AA00
File version: 5.1.2600.2902
Product version: 5.1.2600.2902
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: rdbss.sys
OriginalFilename: RDBSS.Sys
ProductVersion: 5.1.2600.2902
FileVersion: 5.1.2600.2902 (xpsp_sp2_gdr.060505-0036)
FileDescription: Redirected Drive Buffering SubSystem Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c75000 f5c96d00 afd (deferred)
Mapped memory image file: c:\symbols\afd.sys\41107EB521d00\afd.sys
Image path: afd.sys
Image name: afd.sys
Timestamp: Wed Aug 04 08:14:13 2004 (41107EB5)
CheckSum: 0002DC47
ImageSize: 00021D00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: afd.sys
OriginalFilename: afd.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Ancillary Function Driver for WinSock
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5c97000 f5cbec00 netbt (deferred)
Mapped memory image file: c:\symbols\netbt.sys\41107ECC27c00\netbt.sys
Image path: netbt.sys
Image name: netbt.sys
Timestamp: Wed Aug 04 08:14:36 2004 (41107ECC)
CheckSum: 00033EE9
ImageSize: 00027C00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: netbt.sys
OriginalFilename: netbt.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: MBT Transport driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5cbf000 f5d16d80 tcpip (deferred)
Mapped memory image file: c:\symbols\tcpip.sys\444775D357d80\tcpip.sys
Image path: tcpip.sys
Image name: tcpip.sys
Timestamp: Thu Apr 20 13:51:47 2006 (444775D3)
CheckSum: 0005F959
ImageSize: 00057D80
File version: 5.1.2600.2892
Product version: 5.1.2600.2892
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: tcpip.sys
OriginalFilename: tcpip.sys
ProductVersion: 5.1.2600.2892
FileVersion: 5.1.2600.2892 (xpsp_sp2_gdr.060420-0254)
FileDescription: TCP/IP Protocol Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5d17000 f5d29400 ipsec (deferred)
Mapped memory image file: c:\symbols\ipsec.sys\41107EC312400\ipsec.sys
Image path: ipsec.sys
Image name: ipsec.sys
Timestamp: Wed Aug 04 08:14:27 2004 (41107EC3)
CheckSum: 0001A264
ImageSize: 00012400
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ipsec.sys
OriginalFilename: ipsec.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: IPSec Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
f5d56000 f5d58f80 mouhid (deferred)
Mapped memory image file: c:\symbols\mouhid.sys\3B7D82FD2f80\mouhid.sys
Image path: mouhid.sys
Image name: mouhid.sys
Timestamp: Fri Aug 17 22:47:57 2001 (3B7D82FD)
CheckSum: 00010628
ImageSize: 00002F80
File version: 5.1.2600.0
Product version: 5.1.2600.0
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: mouhid.sys
OriginalFilename: mouhid.sys
ProductVersion: 5.1.2600.0
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
FileDescription: Filterdrivrutin för HID-mus
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
f5d5a000 f5d5da00 kbdhid (deferred)
Mapped memory image file: c:\symbols\kbdhid.sys\41107B093a00\kbdhid.sys
Image path: kbdhid.sys
Image name: kbdhid.sys
Timestamp: Wed Aug 04 07:58:33 2004 (41107B09)
CheckSum: 000081CA
ImageSize: 00003A00
File version: 5.1.2600.2180
Product version: 5.1.2600.2180
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 041d.04b0
CompanyName: Microsoft Corporation
ProductName: Operativsystemet Microsoft® Windows®
InternalName: kbdhid.sys
OriginalFilename: kbdhid.sys
ProductVersion: 5.1.2600.2180
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileDescription: Filterdrivrutin för HID-mus
LegalCopyright: © Microsoft Corporation. Med ensamrätt.
f5d5e000 f5d60580 hidusb (deferred)
Mapped memory image file: c:\symbols\hidusb.sys\3B7D86582580\hidusb.sys
Image path: hidusb.sys
Image name: hidusb.sys
Timestamp: Fri Aug 17 23:02:16 2001 (3B7D8658)
CheckSum: 0000D6C8
ImageSize: 00002580
File version: 5.1.2600.0
Product version: 5.1.2600.0
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: HIDUSB.SYS
OriginalFilename: HIDUSB.SYS
ProductVersion: 5.1.2600.0
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
FileDescription: USB Miniport Driver for Input Devices
LegalCopyright: © Microsoft Corporation. All rights reserved.
f6d9a000 f6dc8000 MarvinBus