Solved Random BSOD's ¦ Very Frequent

Discussion in 'Virus, Spyware and Malware Removal' started by herothing11, Aug 4, 2012.


Thread Status:
Not open for further replies.
  1. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,935
    Likes Received:
    3,672
    My System
    Loading...
    Hi,

    Please copy this page to a new Notepad file



    Code:
    Registry Editor Version 5.00
     
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\X6va009]
    Save it as Fix.reg to your desktop

    Double click it to run the fix.
  2. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    I got an error:

    Cannot import C:\Users\David.David-PC\Desktop\fix.reg: The specified file is not a registry script.
    You can only import binary registry files from within the registry editor.
  3. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,935
    Likes Received:
    3,672
    My System
    Loading...
    Are file extensions showing?

    Organize>File and Folder Options

    Show Extensions For Known Filetypes

    That will allow you to change the reg extension
  4. Google Advertisement

  5. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    Extensions are already showing. The file is definitely a reg file, it's just not allowing me to run it.
  6. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,935
    Likes Received:
    3,672
    My System
    Loading...
    Sorry there was a typo. I've edited the script
  7. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    I'm still getting the same error. :(
  8. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,935
    Likes Received:
    3,672
    My System
    Loading...
    The script should be

    Windows Registry Editor Version 5.00

    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\X6va009]

    Saved as Fix.reg

    If that doesn't work, we can manually delete it
  9. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    Ok. It worked that time.
  10. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,935
    Likes Received:
    3,672
    My System
    Loading...
    Ok give it a little time. The BSOD's should stop now
    mkey82 likes this.
  11. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    Ok. I'll keep you posted.
    Thanks!
  12. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,610
    Likes Received:
    362
    My System
    Loading...
    Well, they should, if they were x-file related :p

    BTW our little fiend was still present in the last dump.
    Crush likes this.
  13. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    Hi guys.
    I got another Blue screen today, however they do seem less noticeable in terms of frequency.
    The dmp is posted.

    Attached Files:

  14. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,610
    Likes Received:
    362
    My System
    Loading...
    Memory corruption.
    Code:
    081312-20046-01.log
    Debug session time: Mon Aug 13 22:14:29.390 2012 (UTC + 2:00)
    System Uptime: 0 days 11:16:07.951
    SYSTEM_SERVICE_EXCEPTION (3b)
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff800032c05da, Address of the instruction which caused the bugcheck
    Arg3: fffff8800a6c9c80, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    IMAGE_NAME:  memory_corruption
    PROCESS_NAME:  chrome.exe
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    FAILURE_BUCKET_ID:  X64_0x3B_nt!MiGetNextNode+2e
    fffff880`0a6ca668 fffff800`036222b0 : 00000000`00000000 fffffa80`043b7b50 00000000`00000080 00000000`00000001 : nt!MiGetNextNode+0x2e
    fffff880`0a6ca670 fffff800`034e1228 : fffffa80`066d3b30 fffff880`0a6ca740 00000000`00000000 00000000`000000d0 : nt!MmEnumerateAndReferenceImages+0x160
    fffff880`0a6ca6f0 fffff800`03540a0e : fffffa80`066d3b30 00000000`00000000 fffffa80`043b7b50 fffffa80`066d3c90 : nt! ?? ::NNGAKEGL::`string'+0x21519
    fffff880`0a6ca890 fffff800`0355f659 : 00000000`7efdb000 fffff880`0a6cabe0 00000000`00000000 00000000`00000000 : nt!PspExitProcess+0x4e
    fffff880`0a6ca8f0 fffff800`03542bdd : 00000000`00000000 00000000`00000001 00000000`7efdb000 00000000`00000000 : nt!PspExitThread+0x4e9
    fffff880`0a6ca9f0 fffff800`03280cda : 00000000`00000100 fffffa80`043b7c10 00000000`00000001 fffff800`03283ddd : nt!PsExitSpecialApc+0x1d
    fffff880`0a6caa20 fffff800`03281020 : 00000000`00200246 fffff880`0a6caaa0 fffff800`03542b50 00000000`00000001 : nt!KiDeliverApc+0x2ca
    fffff880`0a6caaa0 fffff800`0328d4f7 : fffffa80`043b7b50 00000000`0000014c fffff880`0a6cabb8 fffffa80`03f9b8a0 : nt!KiInitiateUserApc+0x70
    fffff880`0a6cabe0 00000000`73032e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
    00000000`000deb78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73032e09
    3rd party drivers
    Code:
    4601886A 2007 Mar 21 20:32:58 hcw99bda.sys
    46018879 2007 Mar 21 20:33:13 hcw99rc.sys
    495B9DE8 2008 Dec 31 17:29:28 evbda.sys *** Broadcom NetXtreme II 10 GigE VBD --> http://www.broadcom.com/support/ethernet_nic/netxtremeii.php
    4995F19F 2009 Feb 13 23:18:07 bxvbda.sys *** Broadcom NetXtreme II VBD GigE --> http://www.broadcom.com/support/ethernet_nic/downloaddrivers.php
    49DEC60C 2009 Apr 10 06:07:40 iPodDrv.sys *** doubleTwist iPod Driver --> http://support.doubletwist.com/doubletwist
    49F4422F 2009 Apr 26 13:14:55 b57nd60a.sys *** Broadcom NetXtreme Gigabit Ethernet --> http://www.broadcom.com/support/ethernet_nic/downloaddrivers.php
    4A1151C0 2009 May 18 14:17:04 GEARAspiWDM.sys *** CD-ROM Class Filter Driver by Gear Software Also comes with iTunes --> http://www.gearsoftware.com
    4A5BC0FD 2009 Jul 14 01:19:25 intelppm.sys *** Intel Processor driver --> http://downloadcenter.intel.com/Default.aspx also at 
    4A5BC113 2009 Jul 14 01:19:47 dump_atapi.sys *** driver created to provide disk access during crash dump file generation --> Windows Update or 3rd party driver manufacturer; depending on the source driver
    4A5BC113 2009 Jul 14 01:19:47 dump_ataport.sys *** driver created to provide disk access during crash dump file generation --> Windows Update or 3rd party driver manufacturer; depending on the source driver
    4A5BC114 2009 Jul 14 01:19:48 intelide.sys *** Intel IDE storage driver --> http://downloadcenter.intel.com/Default.aspx also at 
    4A5BC18F 2009 Jul 14 01:21:51 dump_dumpfve.sys *** driver created to provide disk access during crash dump file generation --> Windows Update or 3rd party driver manufacturer; depending on the source driver
    4A5BCC0C 2009 Jul 14 02:06:36 usbcir.sys *** ENE USB Consumer IR Driver for eHome --> OEM - none at http://www.ene.com.tw/en/index.asp
    4A5BCCCB 2009 Jul 14 02:09:47 RNDISMPX.SYS
    4AB07F83 2009 Sep 16 08:02:43 tap0901t.sys *** Google Earth --> http://www.google.com/earth/index.html
    4CE7C737 2010 Nov 20 14:03:51 mcupdate.dll
    4E147335 2011 Jul 06 16:37:41 idmwfp.sys *** Internet Download Manager --> http://www.internetdownloadmanager.com/
    4E16B53B 2011 Jul 08 09:43:55 VMNET.SYS *** VMware Virtual Network Driver --> http://www.vmware.com/support/
    4E16B53C 2011 Jul 08 09:43:56 vmnetadapter.sys *** VMware virtual network adapter driver --> http://www.vmware.com/support/
    4E16B56C 2011 Jul 08 09:44:44 vmnetbridge.sys *** VMware bridge driver --> http://www.vmware.com/support/
    4E2F7B01 2011 Jul 27 04:42:09 vmci.sys *** VMware --> http://www.vmware.com/support/
    4E5C7DAF 2011 Aug 30 08:05:35 hcmon.sys *** VMware USB monitor --> http://www.vmware.com/support/
    4F463154 2012 Feb 23 13:30:12 AtihdW76.sys *** ATI Function Driver for HD Audio Service --> http://support.amd.com/us/Pages/AMDSupportHub.aspx
    4F59FA45 2012 Mar 09 13:40:37 Rt64win7.sys *** Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC --> http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=13&PFid=5&Level=5&Conn=4&DownTypeID=3&GetDown=false
    4F68AAA0 2012 Mar 20 17:04:48 mbam.sys *** MBAMProtector --> http://www.malwarebytes.org/contact.php
    4F7181FE 2012 Mar 27 11:01:50 RTKVHD64.sys *** Realtek High Definition Audio Function Driver --> http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
    4F7E4294 2012 Apr 06 03:10:44 atikmpag.sys *** ATI Video driver (remove the Catalyst Control Center and only install the Display Driver) --> http://support.amd.com/us/Pages/AMDSupportHub.aspx
    4F7E4B69 2012 Apr 06 03:48:25 atikmdag.sys *** ATI Video driver (remove the Catalyst Control Center and only install the Display Driver) --> http://support.amd.com/us/Pages/AMDSupportHub.aspx
    4FD19A80 2012 Jun 08 08:24:00 X6va009
    4FD2F4AF 2012 Jun 09 09:01:03 VMparport.sys *** VMware --> http://www.vmware.com/support/
    4FD2FA87 2012 Jun 09 09:25:59 vmnetuserif.sys *** VMware network application interface driver --> http://www.vmware.com/support/
    4FD304E9 2012 Jun 09 10:10:17 VMkbd.sys *** VMware keyboard filter driver --> http://www.vmware.com/support/
    4FD311F5 2012 Jun 09 11:05:57 vmx86.sys *** VMware Virtualization Driver --> http://www.vmware.com/support/
    4FDD8C94 2012 Jun 17 09:51:48 SbieDrv.sys *** Sandboxie Kernel Mode Driver --> http://www.sandboxie.com/index.php?HelpTopics
    The file in question is still present in the dump.
    My suggestion is to disable all the drivers stamped prior to 2009. That will break some functionality, but the source of memory corruption has to be established.
  15. herothing11 Bronze Member

    Bronze
    Message Count:
    43
    Likes Received:
    0
    My System
    Loading...
    And how would I go about doing that?
  16. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,610
    Likes Received:
    362
    My System
    Loading...
    The process has already been discussed in post #35.
    You should disable at least hcw99bda.sys and hcw99rc.sys

Random BSOD's ¦ Very Frequent

Thread Status:
Not open for further replies.