Solved Frequent BSoDs

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  • Hello everyone We want to personally apologize to everyone for the downtime that we've experienced. We are working to get everything back up as quickly as possible. Due to the issues we've had, your password will need to be reset. Please click the button that says "Forgot Your Password" and change it. We are working to have things back to normal. Emails are fixed and should now send properly. Thank you all for your patience. Thanks, PCHF Management
Status
Not open for further replies.

ZephyrCorsair

PCHF Member
Sep 26, 2016
25
3
29
I very often get BSoD on my computer. Sometimes it happens when I'm playing games, mostly overwatch, sometimes when I'm not even by my computer.

I have no idea why this is the case, it's been like this for quite some time, I don't remember how it started. I've reinstalled windows, bought new RAM and a new hard drive. I originally thought it was my graphics card, but even though I updated the drivers nothing changed.

The error messages varies greatly, but commonly I see IRQL_NOT_EQUAL_OR_LESS or CRITICAL_PROCESS_FAILED.

TFog7KF.png


kxMF5YV.png


Anyone got the slightest clue? Seems to be related to ntoskrnl.exe.
 
Please download MINITOOLBOX and run it.

Checkmark following boxes:



Flush DNS
Reset FF proxy Settings
Reset Ie Proxy Settings
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)



Click Go post the result.




Download Autoruns and Autorunsc Unzip it to your desktop and then double click autoruns.exe
After the scan is finished then click on File>>>>>>>>>>>Save
The default name will be autoruns.arn make sure to save it as Autoruns.txt under the file type option.
in other words make sure it is a .txt file instead of .arn Attach the text in your next reply.



Please upload your minidump files. How to compress and upload Minidump files
 
Here you go.

MiniToolBox by Farbar Version: 17-06-2016
Ran by Zara (administrator) on 26-09-2016 at 21:29:01
Running from "C:\Users\Zara\Downloads"
Microsoft Windows 10 Home (X64)
Model: System Product Name Manufacturer: System manufacturer
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================
========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = Ethernet (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global
set interface interface="Anslutning till lokalt n„tverk* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : DESKTOP-ML68503
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Ethernet:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : F4-6D-04-0D-5C-3D
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::dc0:f990:9217:a18e%2(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.0.15(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : den 26 september 2016 20:21:36
Lease Expires . . . . . . . . . . : den 26 september 2016 22:21:38
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DHCPv6 IAID . . . . . . . . . . . : 66350340
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1F-26-1E-A1-F4-6D-04-0D-5C-3D
DNS Servers . . . . . . . . . . . : 193.150.193.150
83.255.245.11
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{0830FB1F-D105-4D46-A9BF-504A463F3DEF}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fb:402:39af:ac04:33f(Preferred)
Link-local IPv6 Address . . . . . : fe80::402:39af:ac04:33f%8(Preferred)
Default Gateway . . . . . . . . . : ::
DHCPv6 IAID . . . . . . . . . . . : 134217728
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1F-26-1E-A1-F4-6D-04-0D-5C-3D
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: resolver2.comhem.se
Address: 193.150.193.150

Name: google.com
Addresses: 2a00:1450:400f:804::200e
216.58.209.142


Pinging google.com [216.58.209.142] with 32 bytes of data:
Reply from 216.58.209.142: bytes=32 time=30ms TTL=56
Reply from 216.58.209.142: bytes=32 time=10ms TTL=56

Ping statistics for 216.58.209.142:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 10ms, Maximum = 30ms, Average = 20ms
Server: resolver2.comhem.se
Address: 193.150.193.150

Name: yahoo.com
Addresses: 2001:4998:44:204::a7
2001:4998:c:a06::2:4008
2001:4998:58:c02::a9
206.190.36.45
98.138.253.109
98.139.183.24


Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=187ms TTL=50
Reply from 206.190.36.45: bytes=32 time=187ms TTL=50

Ping statistics for 206.190.36.45:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 187ms, Maximum = 187ms, Average = 187ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
2...f4 6d 04 0d 5c 3d ......Realtek PCIe GBE Family Controller
1...........................Software Loopback Interface 1
3...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
8...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.15 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.0.0 255.255.255.0 On-link 192.168.0.15 276
192.168.0.15 255.255.255.255 On-link 192.168.0.15 276
192.168.0.255 255.255.255.255 On-link 192.168.0.15 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.0.15 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.0.15 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
8 306 ::/0 On-link
1 306 ::1/128 On-link
8 306 2001::/32 On-link
8 306 2001:0:5ef5:79fb:402:39af:ac04:33f/128
On-link
2 276 fe80::/64 On-link
8 306 fe80::/64 On-link
8 306 fe80::402:39af:ac04:33f/128
On-link
2 276 fe80::dc0:f990:9217:a18e/128
On-link
1 306 ff00::/8 On-link
2 276 ff00::/8 On-link
8 306 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [55808] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [23552] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [80896] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [31744] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (09/26/2016 08:21:35 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU PnP start/stop failed

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT instans)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.


System errors:
=============
Error: (09/26/2016 08:21:36 PM) (Source: BugCheck) (User: )
Description: 0x0000003b (0x00000000c0000005, 0xfffff801afe0e61a, 0xffffd00024ab8690, 0x0000000000000000)C:\Windows\MEMORY.DMP00000000-0000-0000-0000-000000000000

Error: (09/26/2016 08:21:36 PM) (Source: BugCheck) (User: )
Description:

Error: (09/26/2016 08:21:35 PM) (Source: EventLog) (User: )
Description: Den senaste avstängningen av datorn vid 20:10:14 den ‎2016-‎09-‎26 skedde oväntat.

Error: (09/26/2016 07:59:11 PM) (Source: DCOM) (User: DESKTOP-ML68503)
Description: datorstandardvärdeLokalAktivering{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-ML68503ZaraS-1-5-21-2170518956-1945488489-3297117706-1001LocalHost (med LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (09/26/2016 05:30:24 PM) (Source: DCOM) (User: DESKTOP-ML68503)
Description: datorstandardvärdeLokalAktivering{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-ML68503ZaraS-1-5-21-2170518956-1945488489-3297117706-1001LocalHost (med LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (09/26/2016 05:30:06 PM) (Source: BugCheck) (User: )
Description: 0x0000003b (0x00000000c0000005, 0xfffff8010c4894d8, 0xffffd00024393580, 0x0000000000000000)C:\Windows\MEMORY.DMP768cfe44-03b0-4cc8-9d5d-cefa16adf93b

Error: (09/26/2016 05:30:04 PM) (Source: EventLog) (User: )
Description: Den senaste avstängningen av datorn vid 16:53:11 den ‎2016-‎09-‎26 skedde oväntat.

Error: (09/21/2016 06:57:38 PM) (Source: Service Control Manager) (User: )
Description: Tjänsten Synkroniseringsvärd_26dd5 avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 10000 millisekunder: Starta om tjänsten.

Error: (09/21/2016 06:46:10 PM) (Source: DCOM) (User: DESKTOP-ML68503)
Description: datorstandardvärdeLokalAktivering{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-ML68503ZaraS-1-5-21-2170518956-1945488489-3297117706-1001LocalHost (med LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (09/21/2016 06:46:10 PM) (Source: DCOM) (User: DESKTOP-ML68503)
Description: datorstandardvärdeLokalAktivering{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-ML68503ZaraS-1-5-21-2170518956-1945488489-3297117706-1001LocalHost (med LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742


Microsoft Office Sessions:
=========================
Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: WmiApRplWmiApRpl8F2030000E5050000

Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000

Error: (09/26/2016 08:27:34 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: WmiApRplWmiApRpl8F2030000E5050000

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000

Error: (09/26/2016 08:24:40 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000

Error: (09/26/2016 08:21:35 PM) (Source: ATIeRecord)(User: )
Description:

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: WmiApRplWmiApRpl8F2030000E5050000

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000

Error: (09/26/2016 05:36:01 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT instans)
Description: Performance163707000000000000000000008F020000


CodeIntegrity Errors:
===================================
Date: 2016-09-15 20:59:23.874
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-14 14:30:37.987
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-13 16:56:37.403
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-01 21:17:00.213
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-08-11 22:40:21.628
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-08-10 23:00:26.949
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-31 12:45:19.620
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-30 18:24:13.670
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-29 23:40:03.068
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 09:16:50.349
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


=========================== Installed Programs ============================

7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov)
Ableton Live 8 (HKLM-x32\...\{962E75A9-6DA3-4C2A-A69D-7E98515A78F6}) (Version: 8.0.0.0 - Ableton)
AMD Catalyst Install Manager (HKLM\...\{66AFB595-BC05-2913-7696-6D58F9B733E1}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software)
BankID säkerhetsprogram (HKLM-x32\...\{77B5BCDC-5496-48DA-8B16-5EE2AF08CA31}) (Version: 7.2.1.1 - Finansiell ID-Teknik BID AB)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Discord (HKCU\...\Discord) (Version: 0.0.296 - Hammer & Chisel, Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 10.4.26 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.45.1 - Dropbox, Inc.) Hidden
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Google Chrome (HKLM-x32\...\{A58EE139-F99A-3991-B9D2-EBB6A6E2F9AE}) (Version: 52.0.2743.82 - Google, Inc.)
Google Drive (HKLM-x32\...\{459CE109-4E46-4340-92BC-054642BC3BC2}) (Version: 1.31.2873.2758 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.31.5 - Google Inc.) Hidden
Icecream Screen Recorder version 3.70 (HKLM-x32\...\{7ADEC622-3230-4C9A-9DCE-9BD462B74095}_is1) (Version: 3.70 - Icecream Apps)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
MSI Afterburner 4.3.0 Beta 14 (HKLM-x32\...\Afterburner) (Version: 4.3.0 Beta 14 - MSI Co., LTD)
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - )
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.15.4 - OBS Project)
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Overwatch Test (HKLM-x32\...\Overwatch Test) (Version: - Blizzard Entertainment)
qBittorrent 3.3.6 (HKLM-x32\...\qBittorrent) (Version: 3.3.6 - The qBittorrent project)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.15.707 - Razer Inc.)
RivaTuner Statistics Server 6.5.0 Beta 5 (HKLM-x32\...\RTSS) (Version: 6.5.0 Beta 5 - Unwinder)
SafeZone Stable 1.51.2220.62 (HKLM-x32\...\SafeZone 1.51.2220.62) (Version: 1.51.2220.62 - Avast Software) Hidden
Skype™ 7.28 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.28.101 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Spotify (HKCU\...\Spotify) (Version: 1.0.38.171.g5e1cd7b2 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
WebM Project Directshow Filters (HKCU\...\webmdshow) (Version: 1.0.4.1 - WebM Project)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 39%
Total physical RAM: 8173.4 MB
Available physical RAM: 4909.14 MB
Total Virtual: 9453.4 MB
Available Virtual: 5233.02 MB

========================= Partitions: =====================================

1 Drive c: (SSD Primär Hårddisk) (Fixed) (Total:232.4 GB) (Free:160.75 GB) NTFS
2 Drive d: (Extern Hårddisk) (Fixed) (Total:931.48 GB) (Free:895.51 GB) NTFS
4 Drive z: (Mekanisk Hårddisk) (Fixed) (Total:463.87 GB) (Free:463.03 GB) NTFS

========================= Users: ========================================

Anv„ndarkonton f”r \\DESKTOP-ML68503

Administrat”r DefaultAccount G„st
Zara
Kommandot har utf”rts.


**** End of log ****
 

Attachments

Last edited by a moderator:
Don't know what this is for, but sure.


"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" "" "" "" "2016-09-07 22:12" ""
+ "AvastUI.exe" "avast! Antivirus" "AVAST Software" "c:\program files\avast software\avast\avastui.exe" "2016-09-09 11:47" ""
+ "Dropbox" "Dropbox" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropbox.exe" "2016-08-24 06:40" ""
+ "Razer Synapse" "Razer Synapse" "Razer Inc." "c:\program files (x86)\razer\synapse\rzsynapse.exe" "2016-07-07 03:40" ""
+ "StartCCC" "Catalyst® Control Center Launcher" "Advanced Micro Devices, Inc." "c:\program files (x86)\amd\ati.ace\core-static\amd64\clistart.exe" "2015-08-04 06:13" ""
+ "SunJavaUpdateSched" "Java Update Scheduler" "Oracle Corporation" "c:\program files (x86)\common files\java\java update\jusched.exe" "2016-06-22 11:12" ""
"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" "" "2016-09-08 16:58" ""
+ "Icecream_Screen_Recorder_Prefetcher" "Icecream Screen Recorder" "Icecream" "c:\program files (x86)\icecream screen recorder\recorder.exe" "2016-07-22 15:19" ""
+ "OneDrive" "Microsoft OneDrive" "Microsoft Corporation" "c:\users\zara\appdata\local\microsoft\onedrive\onedrive.exe" "2016-08-09 20:30" ""
+ "Skype" "Skype " "Skype Technologies S.A." "c:\program files (x86)\skype\phone\skype.exe" "2016-09-12 19:52" ""
+ "Spotify" "Spotify" "Spotify Ltd" "c:\users\zara\appdata\roaming\spotify\spotify.exe" "2016-09-13 15:41" ""
+ "Spotify Web Helper" "SpotifyWebHelper" "Spotify Ltd" "c:\users\zara\appdata\roaming\spotify\spotifywebhelper.exe" "2016-09-13 15:40" ""
+ "Steam" "Steam Client Bootstrapper" "Valve Corporation" "c:\program files (x86)\steam\steam.exe" "2016-08-23 20:27" ""
"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" "" "2016-07-24 09:05" ""
+ "Google Chrome" "Google Chrome Installer" "Google Inc." "c:\program files (x86)\google\chrome\application\53.0.2785.116\installer\chrmstp.exe" "2016-09-14 04:09" ""
+ "Microsoft Windows" "Windows Mail" "Microsoft Corporation" "c:\program files\windows mail\winmail.exe" "2015-10-30 04:37" ""
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" "" "" "" "2015-10-30 09:25" ""
+ "Microsoft Windows" "Windows Mail" "Microsoft Corporation" "c:\program files (x86)\windows mail\winmail.exe" "2015-10-30 04:36" ""
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" "" "2016-09-15 21:13" ""
+ "7-Zip" "7-Zip Shell Extension" "Igor Pavlov" "c:\program files\7-zip\7-zip.dll" "2016-05-21 10:19" ""
+ "avast" "avast! Shell Extension" "AVAST Software" "c:\program files\avast software\avast\ashsha64.dll" "2016-08-18 16:32" ""
+ "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ "EPP" "Gränssnittstillägg för Microsoft Security Client" "Microsoft Corporation" "c:\program files\windows defender\shellext.dll" "2016-09-07 06:36" ""
+ "GDContextMenu" "Google Drive shell extension" "Google" "c:\program files (x86)\google\drive\contextmenu64.dll" "2016-07-29 17:55" ""
"HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers" "" "" "" "2015-10-30 09:26" ""
+ "EPP" "Gränssnittstillägg för Microsoft Security Client" "Microsoft Corporation" "c:\program files\windows defender\shellext.dll" "2016-09-07 06:36" ""
"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" "" "2016-07-24 09:08" ""
+ "00avast" "avast! Shell Extension" "AVAST Software" "c:\program files\avast software\avast\ashsha64.dll" "2016-08-18 16:32" ""
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes" "c:\program files (x86)\malwarebytes anti-malware\mbamext.dll" "2016-02-24 19:14" ""
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" "" "2016-09-15 21:13" ""
+ "7-Zip" "7-Zip Shell Extension" "Igor Pavlov" "c:\program files\7-zip\7-zip.dll" "2016-05-21 10:19" ""
+ "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ "EPP" "Gränssnittstillägg för Microsoft Security Client" "Microsoft Corporation" "c:\program files\windows defender\shellext.dll" "2016-09-07 06:36" ""
+ "GDContextMenu" "Google Drive shell extension" "Google" "c:\program files (x86)\google\drive\contextmenu64.dll" "2016-07-29 17:55" ""
"HKLM\Software\Classes\Directory\Shellex\DragDropHandlers" "" "" "" "2016-07-24 09:06" ""
+ "7-Zip" "7-Zip Shell Extension" "Igor Pavlov" "c:\program files\7-zip\7-zip.dll" "2016-05-21 10:19" ""
"HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers" "" "" "" "2016-09-15 21:13" ""
+ "DropboxCopyHook" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" "" "2016-09-15 21:13" ""
+ "ACE" "AMD Desktop Control Panel" "Advanced Micro Devices, Inc." "c:\program files (x86)\amd\ati.ace\core-static\atiacm64.dll" "2015-08-04 06:15" ""
+ "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" "" "2016-07-24 09:08" ""
+ "7-Zip" "7-Zip Shell Extension" "Igor Pavlov" "c:\program files\7-zip\7-zip.dll" "2016-05-21 10:19" ""
+ "avast" "avast! Shell Extension" "AVAST Software" "c:\program files\avast software\avast\ashsha64.dll" "2016-08-18 16:32" ""
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes" "c:\program files (x86)\malwarebytes anti-malware\mbamext.dll" "2016-02-24 19:14" ""
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" "" "2016-09-15 21:13" ""
+ " GoogleDriveBlacklisted" "Google Drive shell extension" "Google" "c:\program files (x86)\google\drive\googledrivesync64.dll" "2016-07-29 17:55" ""
+ " GoogleDriveSynced" "Google Drive shell extension" "Google" "c:\program files (x86)\google\drive\googledrivesync64.dll" "2016-07-29 17:55" ""
+ " GoogleDriveSyncing" "Google Drive shell extension" "Google" "c:\program files (x86)\google\drive\googledrivesync64.dll" "2016-07-29 17:55" ""
+ " DropboxExt1" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt10" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt2" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt3" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt4" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt5" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt6" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt7" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt8" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt9" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext64.43.dll" "2016-09-20 03:13" ""
+ "00avast" "avast! Shell Extension" "AVAST Software" "c:\program files\avast software\avast\ashsha64.dll" "2016-08-18 16:32" ""
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" "" "2016-09-15 21:13" ""
+ " DropboxExt1" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt10" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt2" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt3" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt4" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt5" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt6" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt7" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt8" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
+ " DropboxExt9" "Dropbox Shell Extension" "Dropbox, Inc." "c:\program files (x86)\dropbox\client\dropboxext.43.dll" "2016-09-20 03:13" ""
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "2016-07-24 09:06" ""
+ "Java(tm) Plug-In 2 SSV Helper" "Java(TM) Platform SE binary" "Oracle Corporation" "c:\program files\java\jre1.8.0_101\bin\jp2ssv.dll" "2016-06-22 11:04" ""
+ "Java(tm) Plug-In SSV Helper" "Java(TM) Platform SE binary" "Oracle Corporation" "c:\program files\java\jre1.8.0_101\bin\ssv.dll" "2016-06-22 11:04" ""
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "2016-07-24 09:05" ""
+ "Java(tm) Plug-In 2 SSV Helper" "Java(TM) Platform SE binary" "Oracle Corporation" "c:\program files (x86)\java\jre1.8.0_101\bin\jp2ssv.dll" "2016-06-22 10:46" ""
+ "Java(tm) Plug-In SSV Helper" "Java(TM) Platform SE binary" "Oracle Corporation" "c:\program files (x86)\java\jre1.8.0_101\bin\ssv.dll" "2016-06-22 10:46" ""
"Task Scheduler" "" "" "" "" ""
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo" "" "" "c:\windows\system32\gathernetworkinfo.vbs" "2015-10-30 09:17" ""
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary" "Konfigurationsprogram för nätverksdelning i Windows Media Player" "Microsoft Corporation" "c:\program files\windows media player\wmpnscfg.exe" "2015-10-30 04:10" ""
+ "\MSIAfterburner" "MSIAfterburner" "" "c:\program files (x86)\msi afterburner\msiafterburner.exe" "2016-08-28 17:48" ""
+ "\OneDrive Standalone Update Task" "Standalone Updater" "Microsoft Corporation" "c:\users\zara\appdata\local\microsoft\onedrive\17.3.6517.0809\onedrivestandaloneupdater.exe" "2016-08-09 20:20" ""
+ "\SafeZone scheduled Autoupdate 1473518978" "Avast SafeZone Browser" "Avast Software" "c:\program files\avast software\szbrowser\launcher.exe" "2016-08-29 11:10" ""
"HKLM\System\CurrentControlSet\Services" "" "" "" "2016-09-26 20:21" ""
+ "AMD External Events Utility" "AMD External Events Service Module" "AMD" "c:\windows\system32\atiesrxx.exe" "2015-08-04 04:06" ""
+ "avast! Antivirus" "Hanterar och implementerar Avast antivirus-tjänster för denna dator. Detta inkluderar realtidsskydden, viruskarantänen och schemaläggaren." "AVAST Software" "c:\program files\avast software\avast\avastsvc.exe" "2016-08-18 16:18" ""
+ "avast! Firewall" "Implements main functionality for avast! Firewall" "AVAST Software" "c:\program files\avast software\avast\afwserv.exe" "2016-08-18 16:24" ""
+ "dbupdate" "Håller din Dropbox-programvara uppdaterad. Om den här tjänsten inaktiveras eller stoppas hålls din Dropbox-programvara inte uppdaterad, vilket innebär att eventuella säkerhetsrisker inte kan åtgärdas och funktioner kanske inte fungerar. Denna tjänst avinstallerar sig själv när det inte finns någon Dropbox-programvara som använder den." "Dropbox, Inc." "c:\program files (x86)\dropbox\update\dropboxupdate.exe" "2015-10-21 20:52" ""
+ "dbupdatem" "Håller din Dropbox-programvara uppdaterad. Om den här tjänsten inaktiveras eller stoppas hålls din Dropbox-programvara inte uppdaterad, vilket innebär att eventuella säkerhetsrisker inte kan åtgärdas och funktioner kanske inte fungerar. Denna tjänst avinstallerar sig själv när det inte finns någon Dropbox-programvara som använder den." "Dropbox, Inc." "c:\program files (x86)\dropbox\update\dropboxupdate.exe" "2015-10-21 20:52" ""
+ "DbxSvc" "Dropbox Service" "Windows (R) Win 7 DDK provider" "c:\windows\system32\dbxsvc.exe" "2016-08-24 05:49" ""
+ "gupdate" "Ser till att programvaran från Google är uppdaterad. Om tjänsten inaktiveras eller stoppas uppdateras inte programvaran från Google. Det betyder att vissa funktioner kanske inte fungerar och att eventuella säkerhetsrisker inte kan åtgärdas. Tjänsten avinstalleras automatiskt om den inte används av någon programvara från Google." "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "2016-04-15 07:32" ""
+ "gupdatem" "Ser till att programvaran från Google är uppdaterad. Om tjänsten inaktiveras eller stoppas uppdateras inte programvaran från Google. Det betyder att vissa funktioner kanske inte fungerar och att eventuella säkerhetsrisker inte kan åtgärdas. Tjänsten avinstalleras automatiskt om den inte används av någon programvara från Google." "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "2016-04-15 07:32" ""
+ "MBAMService" "Malwarebytes Anti-Malware service" "Malwarebytes" "c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe" "2016-02-12 03:32" ""
+ "Razer Game Scanner Service" "GameScannerService" "" "c:\program files (x86)\razer\razer services\gss\gamescannerservice.exe" "2015-11-05 02:11" ""
+ "SkypeUpdate" "Enables the detection, download and installation of updates for Skype." "Skype Technologies" "c:\program files (x86)\skype\updater\updater.exe" "2016-07-25 13:32" ""
+ "Steam Client Service" "Steam Client Service monitors and updates Steam content" "Valve Corporation" "c:\program files (x86)\common files\steam\steamservice.exe" "2016-08-23 20:25" ""
+ "WdNisSvc" "Skyddar mot intrångsförsök riktade mot kända och nyupptäckta sårbarheter i nätverksprotokoll" "Microsoft Corporation" "c:\program files\windows defender\nissrv.exe" "2016-09-07 06:35" ""
+ "WinDefend" "Skyddar användarna från skadlig kod och annan oönskad programvara" "Microsoft Corporation" "c:\program files\windows defender\msmpeng.exe" "2016-09-07 06:46" ""
+ "WMPNetworkSvc" "Delar Windows Media Player-bibliotek med andra spelare och enheter i nätverket som använder Universal Plug and Play" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe" "2016-09-07 06:18" ""
"HKLM\System\CurrentControlSet\Services" "" "" "" "2016-09-26 20:21" ""
+ "3ware" "LSI 3ware SCSI Storport Driver" "LSI" "c:\windows\system32\drivers\3ware.sys" "2015-05-19 00:28" ""
+ "ADP80XX" "PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller" "PMC-Sierra" "c:\windows\system32\drivers\adp80xx.sys" "2015-04-09 22:49" ""
+ "amdkmafd" "AMD Audio Bus Lower Filter" "Advanced Micro Devices, Inc." "c:\windows\system32\drivers\amdkmafd.sys" "2015-05-20 01:26" ""
+ "amdkmdag" "ATI Radeon Kernel Mode Driver" "Advanced Micro Devices, Inc." "c:\windows\system32\drivers\atikmdag.sys" "2015-08-04 05:28" ""
+ "amdkmdap" "AMD multi-vendor Miniport Driver" "Advanced Micro Devices, Inc." "c:\windows\system32\drivers\atikmpag.sys" "2015-08-04 03:42" ""
+ "amdsata" "AHCI 1.3 Device Driver" "Advanced Micro Devices" "c:\windows\system32\drivers\amdsata.sys" "2015-05-14 14:14" ""
+ "amdsbs" "AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform" "AMD Technologies Inc." "c:\windows\system32\drivers\amdsbs.sys" "2012-12-11 23:21" ""
+ "amdxata" "Storage Filter Driver" "Advanced Micro Devices" "c:\windows\system32\drivers\amdxata.sys" "2015-05-01 02:55" ""
+ "arcsas" "Adaptec SAS RAID WS03 Driver" "PMC-Sierra, Inc." "c:\windows\system32\drivers\arcsas.sys" "2015-04-09 21:12" ""
+ "aswHwid" "avast! HardwareID" "AVAST Software" "c:\windows\system32\drivers\aswhwid.sys" "2016-08-18 16:12" ""
+ "aswKbd" "avast! keyboard filter driver (aswKbd)" "AVAST Software" "c:\windows\system32\drivers\aswkbd.sys" "2016-08-18 16:12" ""
+ "aswMonFlt" "avast! mini-filter driver (aswMonFlt)" "AVAST Software" "c:\windows\system32\drivers\aswmonflt.sys" "2016-08-18 16:30" ""
+ "aswNetSec" "Avast Firewall Driver" "AVAST Software" "c:\windows\system32\drivers\aswnetsec.sys" "2016-08-18 16:33" ""
+ "aswRdr" "avast! WFP Redirect driver" "AVAST Software" "c:\windows\system32\drivers\aswrdr2.sys" "2016-08-18 16:12" ""
+ "aswRvrt" "avast! Revert" "AVAST Software" "c:\windows\system32\drivers\aswrvrt.sys" "2016-08-18 16:12" ""
+ "aswSnx" "avast! virtualization driver (aswSnx)" "AVAST Software" "c:\windows\system32\drivers\aswsnx.sys" "2016-09-12 14:37" ""
+ "aswSP" "avast! Self Protection" "AVAST Software" "c:\windows\system32\drivers\aswsp.sys" "2016-09-12 14:59" ""
+ "aswStm" "avast! StreamFilter Callout Driver" "AVAST Software" "c:\windows\system32\drivers\aswstm.sys" "2016-08-18 16:36" ""
+ "aswVmm" "avast! VM Monitor" "AVAST Software" "c:\windows\system32\drivers\aswvmm.sys" "2016-08-18 16:30" ""
+ "AtiHDAudioService" "AMD High Definition Audio Function Driver" "Advanced Micro Devices" "c:\windows\system32\drivers\atihdwt6.sys" "2015-07-08 03:28" ""
+ "b06bdrv" "Broadcom NetXtreme II GigE VBD" "Broadcom Corporation" "c:\windows\system32\drivers\bxvbda.sys" "2013-02-04 21:47" ""
+ "bcmfn" "BCM Function 2 Device Driver" "Windows (R) Win 7 DDK provider" "c:\windows\system32\drivers\bcmfn.sys" "2015-06-08 10:32" ""
+ "bcmfn2" "BCM Function 2 Device Driver" "Windows (R) Win 7 DDK provider" "c:\windows\system32\drivers\bcmfn2.sys" "2014-03-16 12:07" ""
+ "dbx" "Dropbox Mini-Filter Driver" "" "File not found: system32\DRIVERS\dbx.sys" "" ""
+ "ebdrv" "QLogic 10 GigE VBD" "QLogic Corporation" "c:\windows\system32\drivers\evbda.sys" "2015-01-12 12:29" ""
+ "HpSAMD" "Smart Array SAS/SATA Controller Media Driver" "Hewlett-Packard Company" "c:\windows\system32\drivers\hpsamd.sys" "2013-03-26 23:36" ""
+ "iai2c" "Intel(R) Serial IO I2C Driver" "Intel(R) Corporation" "c:\windows\system32\drivers\iai2c.sys" "2015-09-22 08:53" ""
+ "iaLPSS2i_I2C" "Intel(R) Serial IO I2C Driver v2" "Intel Corporation" "c:\windows\system32\drivers\ialpss2i_i2c.sys" "2015-09-21 05:08" ""
+ "iaLPSSi_GPIO" "Intel(R) Serial IO GPIO Controller Driver" "Intel Corporation" "c:\windows\system32\drivers\ialpssi_gpio.sys" "2015-02-02 11:00" ""
+ "iaLPSSi_I2C" "Intel(R) Serial IO I2C Controller Driver" "Intel Corporation" "c:\windows\system32\drivers\ialpssi_i2c.sys" "2015-02-24 17:52" ""
+ "iaStorAV" "Intel(R) Rapid Storage Technology driver (inbox) - x64" "Intel Corporation" "c:\windows\system32\drivers\iastorav.sys" "2015-02-19 14:08" ""
+ "iaStorV" "Intel Matrix Storage Manager driver - x64" "Intel Corporation" "c:\windows\system32\drivers\iastorv.sys" "2011-04-11 20:48" ""
+ "ibbus" "InfiniBand Fabric Bus Driver" "Mellanox" "c:\windows\system32\drivers\ibbus.sys" "2015-07-27 22:59" ""
+ "LSI_SAS" "LSI Fusion-MPT SAS Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_sas.sys" "2015-03-25 21:36" ""
+ "LSI_SAS2i" "LSI SAS Gen2 Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_sas2i.sys" "2015-04-08 22:58" ""
+ "LSI_SAS3i" "Avago SAS Gen3 Driver (StorPort)" "Avago Technologies" "c:\windows\system32\drivers\lsi_sas3i.sys" "2015-04-09 20:07" ""
+ "LSI_SSS" "LSI SSS PCIe/Flash Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_sss.sys" "2013-03-16 01:39" ""
+ "MBAMProtector" "Malwarebytes Anti-Malware" "Malwarebytes" "c:\windows\system32\drivers\mbam.sys" "2015-08-11 19:35" ""
+ "MBAMWebAccessControl" "Malwarebytes Web Access Control" "Malwarebytes Corporation" "c:\windows\system32\drivers\mwac.sys" "2014-06-18 04:07" ""
+ "megasas" "MEGASAS RAID Controller Driver for Windows" "Avago Technologies" "c:\windows\system32\drivers\megasas.sys" "2015-03-05 04:36" ""
+ "megasr" "LSI MegaRAID Software RAID Driver" "LSI Corporation, Inc." "c:\windows\system32\drivers\megasr.sys" "2013-06-04 00:02" ""
+ "MEIx64" "Intel(R) Management Engine Interface" "Intel Corporation" "c:\windows\system32\drivers\teedriverw8x64.sys" "2016-03-28 20:59" ""
+ "mlx4_bus" "MLX4 Bus Driver" "Mellanox" "c:\windows\system32\drivers\mlx4_bus.sys" "2015-07-27 23:03" ""
+ "mvumis" "Marvell Flash Controller Driver" "Marvell Semiconductor, Inc." "c:\windows\system32\drivers\mvumis.sys" "2014-05-23 22:39" ""
+ "ndfltr" "NetworkDirect Support Filter Driver" "Mellanox" "c:\windows\system32\drivers\ndfltr.sys" "2015-07-27 22:59" ""
+ "nvraid" "NVIDIA® nForce(TM) RAID Driver" "NVIDIA Corporation" "c:\windows\system32\drivers\nvraid.sys" "2014-04-21 20:28" ""
+ "nvstor" "NVIDIA® nForce(TM) Sata Performance Driver" "NVIDIA Corporation" "c:\windows\system32\drivers\nvstor.sys" "2014-04-21 20:34" ""
+ "percsas2i" "MEGASAS RAID Controller Driver for Windows" "LSI Corporation" "c:\windows\system32\drivers\percsas2i.sys" "2015-02-06 00:51" ""
+ "percsas3i" "MEGASAS RAID Controller Driver for Windows" "Avago Technologies" "c:\windows\system32\drivers\percsas3i.sys" "2015-02-05 00:52" ""
+ "rt640x64" "Realtek 8136/8168/8169 NDIS 6.40 64-bit Driver " "Realtek " "c:\windows\system32\drivers\rt640x64.sys" "2015-10-07 17:03" ""
+ "rzdaendpt" "Razer RzEndPt" "Razer Inc" "c:\windows\system32\drivers\rzdaendpt.sys" "2015-08-11 13:14" ""
+ "rzpmgrk" "Razer Overlay Support" "Razer, Inc." "c:\windows\system32\drivers\rzpmgrk.sys" "2015-09-17 20:42" ""
+ "rzpnk" "Razer Overlay Support" "Razer, Inc." "c:\windows\system32\drivers\rzpnk.sys" "2015-09-17 02:16" ""
+ "rzudd" "Razer Rzudd Engine" "Razer Inc" "c:\windows\system32\drivers\rzudd.sys" "2015-08-11 13:13" ""
+ "rzvkeyboard" "Razer Keyboard Device" "Razer Inc" "c:\windows\system32\drivers\rzvkeyboard.sys" "2015-08-11 13:14" ""
+ "SiSRaid2" "SiS RAID Stor Miniport Driver" "Silicon Integrated Systems Corp." "c:\windows\system32\drivers\sisraid2.sys" "2008-09-24 20:28" ""
+ "SiSRaid4" "SiS AHCI Stor-Miniport Driver" "Silicon Integrated Systems" "c:\windows\system32\drivers\sisraid4.sys" "2008-10-01 23:56" ""
+ "stexstor" "Promise SuperTrak EX Series Driver for Windows x64" "Promise Technology, Inc." "c:\windows\system32\drivers\stexstor.sys" "2012-11-27 02:02" ""
+ "Tdsshbecr" "Handelsbanken card reader" "Todos Data System AB" "c:\windows\system32\drivers\shbecr.sys" "2008-05-30 14:28" ""
+ "vsmraid" "VIA RAID DRIVER FOR AMD-X86-64" "VIA Technologies Inc.,Ltd" "c:\windows\system32\drivers\vsmraid.sys" "2014-04-22 21:21" ""
+ "VSTXRAID" "VIA StorX RAID Controller Driver" "VIA Corporation" "c:\windows\system32\drivers\vstxraid.sys" "2013-01-21 21:00" ""
+ "WinMad" "Kernel WinMad" "Mellanox" "c:\windows\system32\drivers\winmad.sys" "2015-07-27 22:59" ""
+ "WinVerbs" "Kernel WinVerbs" "Mellanox" "c:\windows\system32\drivers\winverbs.sys" "2015-07-27 22:59" ""
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers" "" "" "" "2015-10-30 09:25" ""
+ "Adobe Type Manager" "Windows NT OpenType/Type 1 Font Driver" "Adobe Systems Incorporated" "c:\windows\system32\atmfd.dll" "2016-05-28 06:23" ""
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" "" "2016-09-26 15:45" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm" "2015-10-30 04:36" ""
+ "VIDC.RTV1" "" "" "c:\windows\system32\rtvcvfw64.dll" "2012-09-28 21:45" ""
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" "" "2016-09-26 15:45" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\syswow64\l3codeca.acm" "2015-10-30 04:34" ""
+ "vidc.cvid" "Cinepak®-codec" "Radius Inc." "c:\windows\syswow64\iccvid.dll" "2015-10-30 04:46" ""
+ "VIDC.RTV1" "" "" "c:\windows\syswow64\rtvcvfw32.dll" "2012-09-28 21:45" ""
"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" "" "2016-08-29 15:12" ""
+ "Theora Encode Filter" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsftheoraencoder.dll" "2011-01-12 02:56" ""
+ "WebM Muxer Filter" "WebM Multiplexer Filter" "Google" "c:\program files (x86)\xiph.org\open codecs\x64\webmmux.dll" "2011-01-12 02:57" ""
+ "WebM Splitter Filter" "Webm Splitter Filter" "Google" "c:\program files (x86)\xiph.org\open codecs\x64\webmsplit.dll" "2011-01-12 02:57" ""
+ "WebM VP8 Decoder Filter" "WebM VP8 Decoder Filter" "Google" "c:\program files (x86)\xiph.org\open codecs\x64\vp8decoder.dll" "2011-01-12 02:58" ""
+ "WebM VP8 Encoder Filter" "WebM VP8 Encoder Filter" "Google" "c:\program files (x86)\xiph.org\open codecs\x64\vp8encoder.dll" "2011-01-12 02:58" ""
+ "Xiph.Org FLAC Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfflacdecoder.dll" "2011-01-12 02:57" ""
+ "Xiph.Org FLAC Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfflacencoder.dll" "2011-01-12 02:57" ""
+ "Xiph.Org Native FLAC Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfnativeflacsource.dll" "2011-01-12 02:57" ""
+ "Xiph.Org Ogg Demuxer" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfoggdemux2.dll" "2011-01-12 02:56" ""
+ "Xiph.Org Ogg Muxer" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfoggmux.dll" "2011-01-12 02:57" ""
+ "Xiph.Org Speex Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfspeexdecoder.dll" "2011-01-12 02:56" ""
+ "Xiph.Org Speex Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfspeexencoder.dll" "2011-01-12 02:56" ""
+ "Xiph.Org Theora Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsftheoradecoder.dll" "2011-01-12 02:56" ""
+ "Xiph.Org Vorbis Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfvorbisdecoder.dll" "2011-01-12 02:56" ""
+ "Xiph.Org Vorbis Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\x64\dsfvorbisencoder.dll" "2011-01-12 02:56" ""
"HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" "" "2016-09-07 22:12" ""
+ "ATI Ticker" "" "" "c:\program files (x86)\amd\ati.ace\graphics-previews-common\ticker.ax" "2015-08-04 06:13" ""
+ "MMACE Deinterlace" "" "" "c:\program files (x86)\amd\ati.ace\graphics-previews-common\mmacefilters.dll" "2015-08-04 06:13" ""
+ "MMACE ProcAmp" "" "" "c:\program files (x86)\amd\ati.ace\graphics-previews-common\mmacefilters.dll" "2015-08-04 06:13" ""
+ "MMACE SoftEmu" "" "" "c:\program files (x86)\amd\ati.ace\graphics-previews-common\mmacefilters.dll" "2015-08-04 06:13" ""
+ "Theora Encode Filter" "" "" "c:\program files (x86)\xiph.org\open codecs\dsftheoraencoder.dll" "2011-01-12 02:51" ""
+ "WebM Color Conversion Filter" "WebM Color Conversion Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\webmcc.dll" "2015-01-30 21:20" ""
+ "WebM Muxer Filter" "WebM Multiplexer Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\webmmux.dll" "2015-01-30 21:20" ""
+ "WebM Source Filter" "WebM Source Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\webmsource.dll" "2015-01-30 21:20" ""
+ "WebM Splitter Filter" "Webm Splitter Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\webmsplit.dll" "2015-01-30 21:20" ""
+ "WebM Vorbis Decoder Filter" "WebM Vorbis Decoder" "" "c:\program files (x86)\common files\webm project\webmdshow\webmvorbisdecoder.dll" "2015-01-30 21:20" ""
+ "WebM VP8 Decoder Filter" "WebM VP8 Decoder Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\vp8decoder.dll" "2015-01-30 21:20" ""
+ "WebM VP8 Encoder Filter" "WebM VP8 Encoder Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\vp8encoder.dll" "2015-01-30 21:20" ""
+ "WebM VP9 Decoder Filter" "WebM VP9 Decoder Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\vp9decoder.dll" "2015-01-30 21:20" ""
+ "WebM VPx Decoder Filter" "WebM VPX Decoder Filter" "Google" "c:\program files (x86)\common files\webm project\webmdshow\vpxdecoder.dll" "2015-01-30 21:20" ""
+ "Xiph.Org FLAC Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfflacdecoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org FLAC Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfflacencoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Native FLAC Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfnativeflacsource.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Ogg Demuxer" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfoggdemux2.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Ogg Muxer" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfoggmux.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Speex Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfspeexdecoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Speex Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfspeexencoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Theora Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsftheoradecoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Vorbis Decoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfvorbisdecoder.dll" "2011-01-12 02:51" ""
+ "Xiph.Org Vorbis Encoder" "" "" "c:\program files (x86)\xiph.org\open codecs\dsfvorbisencoder.dll" "2011-01-12 02:51" ""
"HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)" "" "" "" "2016-04-26 22:27" ""
+ "C:\Program Files\Internet Explorer\iexplore.exe" "Internet Explorer" "Microsoft Corporation" "c:\program files\internet explorer\iexplore.exe" "2016-09-07 06:35" ""
"HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls" "" "" "" "2015-10-30 09:25" ""
+ "_Wow64" "" "" "File not found: C:\Windows\SysWOW64\Wow64.dll" "" ""
+ "_Wow64cpu" "" "" "File not found: C:\Windows\SysWOW64\Wow64cpu.dll" "" ""
+ "_Wow64win" "" "" "File not found: C:\Windows\SysWOW64\Wow64win.dll" "" ""
 

Attachments

Last edited by a moderator:
Ok, now we are going to need the minidump files to help you further. :)
 
Hit the start button, type or copy and paste C:/Windows/Minidump into the start search box. Click on the folder, then edit select all. Right click and cut the dumps, create a new folder on your desktop and paste them into it. Zip new folder up and attach it here or send it to sendspace.com and send us the link.
 
I have summoned a BSOD guy for you, now that all of the information is up you will get assistance ASAP. These logs take time to look over, thank you for your patience. :)
 
Hi Zephyr and welcome to PCHF :)

Before we can proceed, I ask that you remove:

Code:
qBittorrent 3.3.6 (HKLM-x32\...\qBittorrent) (Version: 3.3.6 - The qBittorrent project)

P2P software is against PCHF rules, and we are unable to provide assistance until they are removed. Please advise us upon post-removal.
 
Most of your logs are indicating an IRQL_NOT_LESS_OR_EQUAL or is referring to a fault in dxgmms1.sys, which indicates a hardware conflict. Can you post a log of Speccy for me so I can analyze your hardware configuration? :)
 
Speccy Scan.

  • Please go here and download Speccy.
  • Install and run the program.
  • Upon Completion:
  • Hit File
  • Publish Snap Shot
  • A link will appear, post that link.
 
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800100ae1f8, Address of the instruction which caused the bugcheck
Arg3: ffffd00024015780, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
nt!ExAllocatePoolWithTag+518
fffff800`100ae1f8 c9              leave

CONTEXT:  ffffd00024015780 -- (.cxr 0xffffd00024015780)
rax=0000000000000040 rbx=ffffc0017a2f9000 rcx=0000000000000000
rdx=ffffc0017a2f9c00 rsi=000000004b677844 rdi=0000000000000001
rip=fffff800100ae1f8 rsp=ffffd000240161a0 rbp=00000000000000c0
 r8=0000000000000001  r9=0000000000000001 r10=7ffff80010178668
r11=7ffffffffffffffc r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=ffffd00024016720
iopl=0         nv up ei pl nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010202
nt!ExAllocatePoolWithTag+0x518:
fffff800`100ae1f8 c9              leave
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  CODE_CORRUPTION

BUGCHECK_STR:  0x3B

PROCESS_NAME:  Battle.net Hel

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff80114c90974 to fffff800100ae1f8

STACK_TEXT: 
ffffd000`240161a0 fffff801`14c90974 : 00000000`00000000 00000000`00001000 ffffd000`240169e0 ffffc001`7a2f9c00 : nt!ExAllocatePoolWithTag+0x518
ffffd000`24016280 fffff801`14cb5957 : ffffe001`5a96e520 ffffd000`24016b80 00000000`00000000 ffffc001`6edaa400 : dxgkrnl!DXGDEVICE::CreateAllocation+0x854
ffffd000`24016950 fffff800`0ffca1a3 : ffffe001`5e1a9080 00000000`00fbe001 00000000`00000000 ffffc001`6edaa4c0 : dxgkrnl!DxgkCreateAllocation+0x697
ffffd000`24016b00 00000000`70f36d04 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00fbdfd8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x70f36d04


MODULE_NAME: memory_corruption

IMAGE_NAME:  memory_corruption

FOLLOWUP_NAME:  memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MEMORY_CORRUPTOR:  ONE_BIT

STACK_COMMAND:  .cxr 0xffffd00024015780 ; kb

FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT

BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT

Followup: memory_corruption
---------
 
  • Like
Reactions: jmarket
Status
Not open for further replies.