BullGuard
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Blue Screen of Death
   
BullGuard Antivirus Forum > BullGuard zone > BullGuard Customers > Blue Screen of Death  
Forum Quick Jump
 
New Topic Post reply to : Blue Screen of Death Printable version of : Blue Screen of Death
[ << Previous Thread | Next Thread >> ]

beeshu
Junior Member


Date Joined Oct 2007
Total Posts : 53
 
   Posted 3/24/2013 2:13 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
Hi,

I am getting the blue screen of death and can not start my computer. I can only login via safe mode.

Thanks
Brian
Back to Top
 

Robert Mateescu
Forum Moderator




Date Joined Sep 2011
Total Posts : 244
 
   Posted 3/24/2013 6:37 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
Here is the procedure you need to follow:

A.
1. Click Start >> right click My Computer >> Properties.
2. In the Computer Properties window go to the Advanced tab and click on the Settings button in the Startup and Recover section.
3. In the Startup and Recover window, select the Kernel Memory dump option you have in the drop down dialog from the Write debug information section. Eventually, feel free to uncheck the option Overwrite any existing file.

Restart the computer into normal mode and, when the blue screen occurs, allow the computer to finish the kernel memory dump. After that, restart the computer into Safe Mode with Networking. Once logged in, look for the memory.dmp file in the Minidump folder from your Windows folder.

Copy the memory.dmp file to your desktop and rename it to DMP_BG.dmp. Attach it to your next reply.

B.
Meantime, whilst in Safe Mode with Networking, go to Start and type cmd. Right click on cmd.exe ->Run as administrator.
Type sfc /scannow and press Enter. Allow the scan to run.

C.
Download Combofix from here and run it.
Attach the scanlog (located in C:\ and named Combofix.txt) to your reply.


Best wishes!


Robert Mateescu
Senior Support Technician EN
support@bullguard.com
www.bullguard.com

Download the Free Trial version of BullGuard Internet Security 12

You have a BullGuard related problem? Contact our Support team directly: www.bullguard.com/support.aspx!

Back to Top
 

beeshu
Junior Member


Date Joined Oct 2007
Total Posts : 53
 
   Posted 3/25/2013 3:45 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
Thanks Robert!

I attached the 1st minidump file. While running the scan and combofix, the blue screen of death appeared again. I attached the 2nd minidump file after this as well and named it #2.

I will try to scan again but I am anticipating the bsod will reappear.

Let me know how to proceed.

Thank you again for your help and continued support!

File Attachment :
DMP_BG.dmp   277KB (application/octet-stream)
This file has been downloaded 54 time(s).

File Attachment :
DMP_BG2.dmp   265KB (application/octet-stream)
This file has been downloaded 49 time(s).
Back to Top
 

beeshu
Junior Member


Date Joined Oct 2007
Total Posts : 53
 
   Posted 3/26/2013 5:35 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
Hi,

It wouldn't allow me to attach the file for step 3, but below is the scanlog combofix file. I get the error message * You cannot upload files that use MIME type : text/plain.

ComboFix 13-03-25.01 - bshu 03/25/2013 19:58:57.3.6 - x64 NETWORK
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.3122 [GMT -4:00]
Running from: c:\users\bshu\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\svchost.exe
.
---- Previous Run -------
.
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-02-26 to 2013-03-26 )))))))))))))))))))))))))))))))
.
.
2013-03-26 00:11 . 2013-03-26 00:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-03-26 00:11 . 2013-03-26 00:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-23 23:12 . 2013-03-06 22:33 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-03-23 23:12 . 2013-03-06 22:33 377920 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-03-23 23:12 . 2013-03-06 22:33 70992 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-03-23 23:11 . 2013-03-06 22:33 68920 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-03-23 23:11 . 2013-03-06 22:33 1025808 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-23 23:11 . 2013-03-06 22:33 178624 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-23 23:11 . 2013-03-06 22:33 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-23 23:11 . 2013-03-06 22:33 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-23 23:11 . 2013-03-06 22:32 41664 ----a-w- c:\windows\avastSS.scr
2013-03-23 22:53 . 2013-03-23 22:53 -------- d-----w- c:\program files\CCleaner
2013-03-23 21:41 . 2013-03-23 21:54 -------- d-----w- c:\users\bshu\AppData\Roaming\Mipony
2013-03-23 21:40 . 2013-03-23 21:40 -------- d-----w- c:\users\bshu\AppData\Roaming\DSite
2013-03-23 21:38 . 2013-03-23 21:38 -------- d-----w- c:\programdata\ErrorEND64
2013-03-23 19:59 . 2013-03-23 21:57 -------- d-----w- c:\users\bshu\AppData\Local\ElevatedDiagnostics
2013-03-23 03:36 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5725E9ED-AD1E-4DD3-9604-A347DED2E0D1}\mpengine.dll
2013-03-22 06:36 . 2013-03-22 06:36 -------- d-----w- c:\users\bshu\AppData\Local\Programs
2013-03-22 06:23 . 2013-03-23 19:37 -------- d-----w- C:\Game
2013-03-22 05:56 . 2013-03-23 15:51 -------- d-----w- c:\users\bshu\AppData\Local\WinRAR
2013-03-21 03:46 . 2012-11-29 02:07 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{40537EB4-83F7-413C-918F-D984E547E2FB}\gapaengine.dll
2013-03-21 03:46 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-16 14:52 . 2013-03-16 14:52 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-03-08 00:23 . 2013-03-08 00:23 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2013-03-08 00:22 . 2010-05-26 16:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-03-08 00:22 . 2010-05-26 16:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-03-08 00:01 . 2013-03-22 05:41 -------- d-----w- c:\program files (x86)\Origin Games
2013-03-08 00:01 . 2013-03-09 03:59 -------- d-----w- c:\users\bshu\AppData\Roaming\Origin
2013-03-07 23:57 . 2013-03-07 23:57 -------- d-----w- c:\users\bshu\AppData\Local\Origin
2013-03-07 23:55 . 2013-03-09 04:06 -------- d-----w- c:\programdata\Origin
2013-03-07 23:55 . 2013-03-08 00:40 -------- d-----w- c:\programdata\Electronic Arts
2013-03-07 23:55 . 2013-03-19 02:18 -------- d-----w- c:\program files (x86)\Origin
2013-03-04 02:33 . 2013-03-04 02:34 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-03-04 02:33 . 2013-03-04 02:34 -------- d-----w- c:\program files\iTunes
2013-03-04 02:33 . 2013-03-04 02:33 -------- d-----w- c:\program files\iPod
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 01:51 . 2012-04-10 23:18 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-13 01:51 . 2011-10-13 01:39 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-06 22:32 . 2011-03-18 04:33 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-01-30 10:53 . 2010-08-11 16:32 273840 ------w- c:\windows\system32\MpSigStub.exe
2013-01-20 20:59 . 2013-01-20 20:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 20:59 . 2011-04-27 20:25 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="c:\program files (x86)\AIM\aim.exe" [2012-05-30 4331392]
"{A2B5F32D-421F-430C-BA7E-CA44DB447E1F}"="c:\users\bshu\AppData\Local\{06744FB5-03C3-44D5-95AA-E56B403E8551}\{A2B5F32D-421F-430C-BA7E-CA44DB447E1F}\afbtxjo.dll" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-01-22 106496]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Del816119"="del" [X]
"GrpConv"="grpconv -o" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 aswSnx;aswSnx; [x]
R1 aswSP;aswSP; [x]
R2 aswFsBlk;aswFsBlk; [x]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-03-06 80816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 havasvc;Vulkano Service;c:\program files (x86)\Monsoon Multimedia\Vulkano\Common\havasvc.exe [2011-01-28 146432]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-01-31 3289208]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 FLASHSYS;FLASHSYS;c:\program files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [2008-02-15 15192]
R3 HAVATV;Hava Video Device;c:\windows\system32\DRIVERS\HAVATV.sys [2010-02-26 189568]
R3 HavaTV_10;Hava Remote Video Device;c:\windows\system32\DRIVERS\HavaTV_10.sys [2010-02-26 189568]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2010-04-29 32768]
R3 MSICDSetup;MSICDSetup;D:\CDriver64.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 OA002Afx;Provides a software interface to control audio effects of OA002 camera.;c:\windows\system32\Drivers\OA002Afx.sys [2007-06-08 219544]
R3 OA002Ufd;Creative Camera OA002 Upper Filter Driver;c:\windows\system32\DRIVERS\OA002Ufd.sys [2008-06-03 168864]
R3 OA002Vid;Creative Camera OA002 Function Driver;c:\windows\system32\DRIVERS\OA002Vid.sys [2008-08-01 306560]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-15 1255736]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S3 havabus;HAVA Bus Enumerator;c:\windows\system32\DRIVERS\havabus.sys [2010-02-26 45056]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-07-14 22408]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 77824]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-01-22 180224]
S3 rt61x64;Linksys Wireless-G PCI Adapter Driver;c:\windows\system32\DRIVERS\WMP54Gv41x64.sys [2010-04-07 446304]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 17:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-03-14 04:55 1629648 ----a-w- c:\program files (x86)\Google\Chrome\Application\25.0.1364.172\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-10 01:51]
.
2013-03-23 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-03-23 22:32]
.
2013-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 04:25]
.
2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 04:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.espn.com/
uDefault_Search_URL = hxxp://search.autocompletepro.com/?si=10214&bi=400
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\bshu\AppData\Roaming\Mozilla\Firefox\Profiles\l8hdr9jv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-customfirefoxright-chromesbox-en-us&tb_uuid=20120314003730143&tb_oid=14-03-2012&tb_mrud=18-06-2012
FF - prefs.js: browser.search.selectedEngine - ACPro
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://blekko.com/ws/?source={SourceID}&tbp=url&toolbarid=blekkotb_031&u=USERGUID&q=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-03-23 19:11; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.homepage.dontask, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Wow6432Node-HKLM-RunOnce-<NO NAME> - (no file)
Toolbar-10 - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\0c\01\13\04(\13?"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-03-25 22:30:46
ComboFix-quarantined-files.txt 2013-03-26 02:30
.
Pre-Run: 83,477,446,656 bytes free
Post-Run: 82,070,503,424 bytes free
.
- - End Of File - - E6FE7A7F0561855A954A372CAB528965

Thanks
Brian
Back to Top
 

beeshu
Junior Member


Date Joined Oct 2007
Total Posts : 53
 
   Posted 3/26/2013 5:52 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
For step 2 the scan only got to 8% and stated that there were corrupt files and couldn't finish
Back to Top
 

Robert Mateescu
Forum Moderator




Date Joined Sep 2011
Total Posts : 244
 
   Posted 3/28/2013 12:40 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
Hi Brian,


" FAULTING_MODULE: fffff80004618000 nt
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT"

The exception code is equivalent to BullGuard's "Step 5" error and means that the needed resources couldn't be accessed. The most common causes are HDD and RAM failures.


A.Check your hard disk for any errors:

Run Command Prompt as administrator and type: chkdsk /r [Enter]
Since the scan can not run now, schedule it after reboot (Press Y when prompted).
Note that the scan will take some time.


B. Check your RAM memory:

Download MemTest from here and run a scan with it
Note that the scan will take some time.


C. Try to run a scf scan again.


Best wishes!


Robert Mateescu
Senior Support Technician EN
support@bullguard.com
www.bullguard.com

Download the Free Trial version of BullGuard Internet Security 12

You have a BullGuard related problem? Contact our Support team directly: www.bullguard.com/support.aspx!

Back to Top
 

beeshu
Junior Member


Date Joined Oct 2007
Total Posts : 53
 
   Posted 4/2/2013 2:38 AM (GMT +3)    Quote: Blue Screen of DeathAlert an admin about: Blue Screen of Death
I bought a new harddrive and reinstalled windows and everything runs fine. There may be some error with the harddrive or files that may have been corrupted. I ran the chkdsk overnight and it restarted on me before i was able to see if there was any issue.

I ran the scandsk and it stalled at 8%. This time it didnt state that there were corrupted files.
Back to Top
 
New Topic Post reply to : Blue Screen of Death Printable version of : Blue Screen of Death
 
Forum Information
Currently it is Wednesday, April 16, 2014 10:35 PM (GMT +3)
There are a total of 60,351 posts in 13,272 threads.
In the last 3 days there were 1 new threads and 13 reply posts. View Active Threads
Who's Online
This forum has 35757 registered members. Please welcome our newest member, bill78759.
1 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Internet connection intermittent (1)4/16/2014 7:18:37 PM (Dickens)
Music Hanging when surfing net, stops when i turn off firewall! (3)4/16/2014 4:20:53 PM (MNH)
Computer running snail slow, virus maybe (26)4/16/2014 3:12:05 PM (KMB1999)
Google Redirect - trouble removing it (9)4/15/2014 9:42:12 PM (Sha2009)
Bullguard 2014 Internet Security: Firewall blocks internet connection at startup (5)4/15/2014 4:09:10 PM (wafu)