My PC has been crashing at least 5 times a days! The blue screen of death! Please help!

kuber003

Honorable
Apr 22, 2014
53
0
10,640
hey,

i'm running windows 7 ultimate and my pc has been crashing at least 5 times a day. the blue screen errors read:

1. IRQL_GT_ZERO_AT_SYSTEM_SERVICE Stop: 0x0000004A
2. Driver_IRQL_NOT_LESS_OR_EQUAL Stop 0x000000D1 tcpip.sys

i don't know how to read the dump files so i've uploaded the files here:

https://www.wetransfer.com/downloads/273ec334ed136aa44a0822d73dd9c42e20160505192730/0f85052e46c4d2e1e190458aaf9bd55d20160505192730/792499

can someone please pinpoint the problem and tell me how to fix it? i won't be able to thank you enough!

please please please help!

kuber
 
Solution
most likely cause of the bugcheck would be
Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC
\SystemRoot\system32\DRIVERS\Rt64win7.sys Tue Sep 27 07:50:33 2011
it is very old and have various bugs:
new version:
http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=13&PFid=5&Level=5&Conn=4&DownTypeID=3&GetDown=false


or maybe \SystemRoot\system32\DRIVERS\AppleCharger.sys Wed Oct 24 17:51:02 2012
because of memory corruption bugs. look for a update at the gigabyte website.
(also update any motherboard drivers you can get, and BIOS if you have USB problems)
---------------
-looks like a fake version of windows Looks like the kernel has been replaced.
- you have a hidden OS driver installed...

Colif

Win 11 Master
Moderator
tcpip.sys is your internet connection, I would run an Anti virus scan as well as malwarebytes, to see if its a virus

Use a program like Driver Booster and check if you have latest drivers.

I can't read dumps either, that was just from what you posted.
 
most likely cause of the bugcheck would be
Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC
\SystemRoot\system32\DRIVERS\Rt64win7.sys Tue Sep 27 07:50:33 2011
it is very old and have various bugs:
new version:
http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=13&PFid=5&Level=5&Conn=4&DownTypeID=3&GetDown=false


or maybe \SystemRoot\system32\DRIVERS\AppleCharger.sys Wed Oct 24 17:51:02 2012
because of memory corruption bugs. look for a update at the gigabyte website.
(also update any motherboard drivers you can get, and BIOS if you have USB problems)
---------------
-looks like a fake version of windows Looks like the kernel has been replaced.
- you have a hidden OS driver installed:
\SystemRoot\System32\drivers\veracrypt.sys Sat Feb 13 23:54:15 2016
https://veracrypt.codeplex.com/wikipage?title=VeraCrypt%20Hidden%20Operating%20System

(just in case you did not know it was there)
the system crashed in networking code because the stack was corrupted.
second bugcheck shows a crash in the hacked kernel, again a corrupted stack.

-you have 3 drivers installed that look like randomly generated driver names,
(Malware/rootkits?)
-your windows files are out of date ( I would guess the updates are being blocked)

I would reinstall with a known clean copy of windows.

machine info:
BIOS Version F15
BIOS Starting Address Segment f000
BIOS Release Date 10/23/2013
Manufacturer Gigabyte Technology Co., Ltd.
Product B75M-D3H
Processor Version Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
Processor Voltage 89h - 0.9V
External Clock 100MHz
Max Speed 7000MHz
Current Speed 3000MHz



 
Solution
it is the first time I have come across a system with a hidden OS inside. I think that code may have made the changes that make it look like a pirate version. (as well as the key activator drivers)



 
D

Deleted member 217926

Guest
So the pirated Windows was so busy being malware and sending all his information to some hacker it broke itself? That's amazing. :lol:

How to fix. Buy a legal copy of Windows. Reinstall using said legal copy. That was easy. :p
 
you can not know if this version was pirated, it could be a legit version then you run the hidden OS program to hide your stuff. The hidden OS program renames the kernel and files and fakes activation. The process basically breaks the windows debugger and it looks like a pirate version because of the renamed/hacked windows files. It might work fine after the other problems are fixed.



 

Colif

Win 11 Master
Moderator
Someone else asked about Veracrypt in windows 10 forums yesterday, I don't know why you would want a hidden OS but i think it also just offers a way to have a hidden partition for the same purpose as bitlocker or a function Bitdefender has that hides your personal info away from hackers.
 
according to the docs, it offers Plausible Deniability. IE you can claim you did not know that it was there if you were forced to turn over your computer and later went to trial. (ie unlawful content, criminal activity being hidden, or you are just very protective of your data/activities) The police/investigators will still find it, might be able to decrypt it but you can still claim you did not know it was installed.



 

kuber003

Honorable
Apr 22, 2014
53
0
10,640
i ran a bitdefender system scan and a few suspicious files popped up and were automatically deleted.
 

kuber003

Honorable
Apr 22, 2014
53
0
10,640
johnbl, thank you so much for your detailed reply. as per your suggestion, i updated the ethernet drivers and as of now, my pc is running fine so fingers crossed. and, a few of my friends have access to my pc and they were trying to install a cracked software without my knowledge and i'm sure they messed up my machine. i will be re-installing a clean copy of windows 7 soon once i backup my stuff.

but is it possible for my pc to secretly send out my personal information to a hacker without my knowledge if the pc is running a pirated copy of windows? that's really spooky!

do let me know and thanks a ton again!
 

kuber003

Honorable
Apr 22, 2014
53
0
10,640
is that really possible?