Laptop Crashes After Resume From Hibernation

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

firefoxsilver9

Thread Starter
Joined
Aug 3, 2008
Messages
32
Hi. Sometimes when i close the lid on my laptop to hibernate or standby, it crashes when i try to resume. The crash led to a blue screen. It created a memory.dmp file, which i tried opening with Debugging tools for windows and i get this:







Microsoft (R) Windows Debugger Version 6.11.0001.402 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16481.x86fre.win7_gdr.091207-1941
Machine Name:
Kernel base = 0x82c46000 PsLoadedModuleList = 0x82d8e810
Debug session time: Wed Apr 7 23:17:13.646 2010 (GMT-5)
System Uptime: 3 days 8:30:07.457
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols

Loading unloaded module list
................
0: kd> .restart /f

Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16481.x86fre.win7_gdr.091207-1941
Machine Name:
Kernel base = 0x82c46000 PsLoadedModuleList = 0x82d8e810
Debug session time: Wed Apr 7 23:17:13.646 2010 (GMT-5)
System Uptime: 3 days 8:30:07.457
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols

Loading unloaded module list
................


I'm using Windows 7 Ultimate x86, Lenovo Y450 Laptop Core 2 duo processor, 3GB ram. thanks in advance.
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
Whats the Graphic Card?
Post a HiJack This Log.
Download it from the link in my signature.
DO NOT FIX ANYTHING
 

firefoxsilver9

Thread Starter
Joined
Aug 3, 2008
Messages
32
Graphics card is Mobile Intel(R) 4 Series Express Chipset Family



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:56 AM, on 4/8/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Lenovo\Lenovo OneKey Theater\OneKeyTheater.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarDriverAdapter_450vista.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Aerofoil\Aerofoil.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\MediaMonkey\MediaMonkey.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\explorer.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\explorer.exe
C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Paul Tolbert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Paul Tolbert\Documents\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [OneKey Theater] C:\PROGRA~1\Lenovo\LENOVO~1\ONEKEY~1.EXE
O4 - HKLM\..\Run: [Lenovo SlideNav] "C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe"
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKCU\..\Run: [Google Update] "C:\Users\Paul Tolbert\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Aerofoil.lnk = C:\Program Files\Aerofoil\Aerofoil.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

--
End of file - 10750 bytes
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
Checked the log and it seems you are infected.
Run a full scan using SAS and MalwareBytes and post the logs over here.
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
Also trying closing all of the applications before Hibernating
 

firefoxsilver9

Thread Starter
Joined
Aug 3, 2008
Messages
32
yeah i use chrome. had 2 windows with several tabs and extensions running. updating the graphics drivers now. i'm using Windows 7 ultimate x86. what infection do i have?
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
What about changing the power saving options?
They also are sometimes the reason behind hiebernation issues.
It seemed like an infection.
Do you use Windows Live?
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
Also facing the same problem.
The problem is 90% times caused by wrong or tweaked drivers.
Hope you will solve the problem soon!
 
Joined
Dec 9, 2000
Messages
45,855
Antech I am going to ask you to stop using a red or any unusual font for normal text.

Also if you think you see something amiss in a HijackThis scanlog -- point out exactly what. While there is nothing wrong with suggesting generic malware scans -- you are not otherwise here qualified to offer malware advice.

-----------------------------------------------

firefoxsilver9:

Are you able to upload the minidumps following these directions >> ?

1 > create a new folder on the desktop and call it "dumpcheck" or whatever you like
2 > navigate to c:\windows\minidump and copy the last few minidump files to that folder. *this assumes 'c' is your boot drive, if it is not, subsitute accordingly
3 > close the folder and right click on it and select Send to Compressed (zipped) Folder.
4 > use the "manage attachments" in the "advanced" reply window to upload that zip file here as an attachment.


If you do not see any minidumps, be sure you are not using any cache cleaner such as CCleaner. Also run sysdm.cpl and select Advanced > Startup and Recovery. Make sure "small memory dump" is the one chosen under "write debugging information" and the location should be %systemroot%\minidump

------------------------------------------------------------------

Also, since many of these "resume" type errors are associated with wireless drivers -- if you are using wireless -- do you have the latest available drivers for Win7?

Looking at your scanlog I would probably suspect this since it seems to involve power settings >> http://silentdevelopment.blogspot.com/2009/10/aerofoil-150-released.html
 

antech

Banned
Joined
Feb 23, 2010
Messages
1,427
Am I going to stop like that?
The answer is YES.
Thanks..Rollin Rog.
I will soon point out the suspicious entries.
This is my last post using RED Color
Bye


BTW, What about Blue?
Just a joke though
 

TerryNet

Terry
Moderator
Joined
Mar 23, 2005
Messages
81,423
BTW, What about Blue?
Just a joke though
IMO for requesting or giving help it is most effective to use the default font, size and color, and use color or bolding or size to emphasize whatever is really important or might be overlooked otherwise.
 
Joined
Dec 9, 2000
Messages
45,855
We may need more examples to sort this out. The nominal fault is in a Microsoft Networking driver. Typically this type fault would be associated with Non Windows firewalls (you don't have one), out of date networking drivers, (yours seem recent) or other programs which affect Networking and the Winsock stack.

You have Utorrent running when this BSOD occured and I would suspect that since it is involved in networking.

However Windows Live may also be a factor since it is present as an added Winsock protocol.

BugCheck 1000008E, {c0000005, 90611493, b0308994, 0}

Probably caused by : afd.sys ( afd!AfdTLReleaseIndications+20 )
PROCESS_NAME: uTorrent.exe


*Note that this one BSOD may not be the one you are getting on resume from standby.
 

Attachments

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top