Jump to content

STOP 0x50 PAGE_FAULT_IN_NONPAGED_AREA


Lord_Gaav

Recommended Posts

Recently I have been receiving the 0x50 BSOD when downloading files with uTorrent. I have already analyzed the minidumps with windbg, and it shows that utorrent.exe and ntfs.sys are the cause of the crash. Attached is an HijackedThis log and a ProcExp log. I'm using Vista x64 Ultimate.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:34:32, on 5-3-2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Switcher\Switcher.exe
D:\Program Files\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\mIRC\mirc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\GNU\GnuPG\claws-mail.exe
C:\Command\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~2\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Switcher] "C:\Program Files (x86)\Switcher\Switcher.exe" /quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Steam] "d:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: UltraMon.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Doel van koppeling converteren naar Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Doel van koppeling toevoegen aan bestaande PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Toevoegen aan bestaande PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: DirMngr - Unknown owner - C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30007 (IISADMIN) - Unknown owner - C:\Windows\system32\inetsrv\inetinfo.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: FTP Publishing Service (MSFTPSVC) - Unknown owner - C:\Windows\system32\inetsrv\inetinfo.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10628 bytes

Process    PID    CPU    Description    Company Name
System Idle Process 0 71.54
Interrupts n/a 0.77 Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4
smss.exe 528
csrss.exe 672
wininit.exe 724
services.exe 772
svchost.exe 1008
ehmsas.exe 3980 Media Center Media Status Aggregator Service Microsoft Corporation
RTSHookInterop.exe 3144 RTSHookInterop Realtime Soft Ltd
nvvsvc.exe 340
rundll32.exe 2316
svchost.exe 396
svchost.exe 676
audiodg.exe 1060
svchost.exe 720
WUDFHost.exe 2252
dwm.exe 2748 Desktop Window Manager Microsoft Corporation
svchost.exe 996
taskeng.exe 1896
taskeng.exe 2524 Task Scheduler Engine Microsoft Corporation
svchost.exe 1084
SLsvc.exe 1128
svchost.exe 1188
svchost.exe 1296
ccSvcHst.exe 1376
spoolsv.exe 1600
svchost.exe 1624
mDNSResponder.exe 1868
DefWatch.exe 1884
dirmngr.exe 1920
inetinfo.exe 1952
svchost.exe 1288
svchost.exe 1536
Rtvscan.exe 1672
svchost.exe 2120
SearchIndexer.exe 2152
IAANTmon.exe 2348
wmpnetwk.exe 3408
SteamService.exe 4912
lsass.exe 784
lsm.exe 792
csrss.exe 732
winlogon.exe 876
explorer.exe 2956 Windows Explorer Microsoft Corporation
IAAnotif.exe 4020 Event Monitor User Notification Tool Intel Corporation
RAVCpl64.exe 4056 HD Audio Control Panel Realtek Semiconductor
TSVNCache.exe 4076 TortoiseSVN status cache http://tortoisesvn.net
LCDMon.exe 3780 Logitech LCD Manager Logitech Inc.
LCDClock.exe 3336 Logitech G-series LCD Clock Logitech Inc.
LCDCountdown.exe 2964 Logitech G-series LCD Countdown Timer Logitech Inc.
LCDMedia.exe 1820 Logitech G-series Media Display Logitech Inc.
LGDCore.exe 3788 Logitech G-series Profiler Logitech Inc.
rundll32.exe 3888 Windows host process (Rundll32) Microsoft Corporation
sidebar.exe 3824 Windows Sidebar Microsoft Corporation
sidebar.exe 1836 Windows Sidebar Microsoft Corporation
daemon.exe 3828 DAEMON Tools Lite DT Soft Ltd
ehtray.exe 3840 Media Center Tray Applet Microsoft Corporation
Switcher.exe 3848 Switcher Bao_Nguyen
Steam.exe 3860 Steam Valve Corporation
SetPoint.exe 3916 Logitech SetPoint Event Manager (UNICODE) Logitech, Inc.
SetPoint32.exe 2672
KHALMNPR.exe 2684 Logitech KHAL Main Process Logitech, Inc.
wmpnscfg.exe 3364 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
UltraMon.exe 3692 UltraMon Realtime Soft Ltd
UltraMonTaskbar.exe 3704 UltraMon Taskbar Realtime Soft Ltd
UltraMonUiAcc.exe 2280
mirc.exe 5096 mIRC mIRC Co. Ltd.
firefox.exe 3756 Firefox Mozilla Corporation
uTorrent.exe 2548 24.62 µTorrent BitTorrent, Inc.
procexp.exe 1068 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
procexp64.exe 5108 3.08 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
ccApp.exe 4004 Symantec User Session Symantec Corporation
VPTray.exe 4028 Symantec AntiVirus Symantec Corporation
jusched.exe 4036 Java(TM) Platform SE binary Sun Microsystems, Inc.
PDVD8Serv.exe 2492 PowerDVD RC Service CyberLink Corp.
brs.exe 2184 brs cyberlink

Process: uTorrent.exe Pid: 2548

Name Description Company Name Version
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000
CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000
dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000
dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000
DnsApi.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000
FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.00.6001.18000
GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18159
IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000
Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000
lgscroll.dll Logitech Scroll Enabler (UNICODE) Logitech, Inc. 4.70.0213.0000
locale.nls
locale.nls
LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000
mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001
MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000
msctf.dll.mui MSCTF Server DLL Microsoft Corporation 6.00.6000.16386
MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.00.50727.3053
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000
napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000
NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000
NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000
ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000
ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000
NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 6.00.6001.18000
ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000
oleaut32.dll Microsoft Corporation 6.00.6001.18000
pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000
PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051
rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.00.6001.18000
RTSUltraMonHookX32.dll Hook DLL for Realtime Soft UltraMon Realtime Soft Ltd 3.00.0003.0000
SAMLIB.dll SAM Library DLL Microsoft Corporation 6.00.6001.18000
Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18167
shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000
USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000
USERENV.dll Userenv Microsoft Corporation 6.00.6001.18000
USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000
uTorrent.exe µTorrent BitTorrent, Inc. 1.08.0002.14458
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000
VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.00.6001.18000
WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000
wow64.dll Win32 Emulation on NT64 Microsoft Corporation 6.00.6001.18000
wow64cpu.dll AMD64 Wow64 CPU Microsoft Corporation 6.00.6001.18000
wow64win.dll Wow64 Console and Win32 API Logging Microsoft Corporation 6.00.6001.18000
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000
wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000
wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...