Marthinus

[resolved In Bitdefender 2013] Bsod From Bdfndisf6.sys

22 posts in this topic

I have BitDefender Total Security 2012 installed on my pc and have recently been experiencing system crashes with blue screen of death.

Memory dumps are created and it is also noted during these memory dumps that the problem likely occurred in the file bdfndisf6.sys. Upon googling this filename I discovered the problem is likely a driver problem with BitDefender

Does anyone know how to properly fix this? The internet is loaded with 3rd party applications that claims to fix this but I'm not keen to pay money for these when BitDefender should not be crashing my system.

Many thanks

Share this post


Link to post
Share on other sites

Hi :)

Welcome to the forums.

Please follow the steps explained in the article below and send me via PM the generated log file:

http://forum.bitdefender.com/index.php?showtopic=29927

If the file is too big to attach it, upload it on

http://www.sendspace.com

or

http://www.mediafire.com

and send me a PM with the download link.

If you were already asked to generate the log file, disregard the message above and just post the ticket ID.

Have a nice day.

Share this post


Link to post
Share on other sites

I have the same problem...Bitdefender is causing my system to crash and have BSOD. Attached herewith are the analysis of WhoCrashed. I have also sent a PM to you regarding the link to the file generated by Bitdefender Supporttool.exe.. Please help. I am using BD Total Security 2012 x64

post-100956-1334075869_thumb.png

Share this post


Link to post
Share on other sites

Hi - I engaged with support staff and have logged a ticket, Nr Ticket ID:201203291020385 I have also uploaded MEMORY.DMP file to the ftp site (details provided via support staff)

They want to send me an exe file via email???

Do you have any other means of solving the problem, it is not possible to email exe or zipped exe files

I'm running:

Windows 7 Professional x64

BitDefender Total Security 2012

Having no joy :(

Hi :)

Welcome to the forums.

Please follow the steps explained in the article below and send me via PM the generated log file:

http://forum.bitdefender.com/index.php?showtopic=29927

If the file is too big to attach it, upload it on

http://www.sendspace.com

or

http://www.mediafire.com

and send me a PM with the download link.

If you were already asked to generate the log file, disregard the message above and just post the ticket ID.

Have a nice day.

Share this post


Link to post
Share on other sites

Hello :)

Welcome back.

I can see that ticket closed in the system. Is everything OK now?

Take care.

Share this post


Link to post
Share on other sites

i have the same problem i have read all the posts and i still couldn't solve the problem.i am keeping the firewall off and it works,the minute i turn it on BSOD.

Using Windosws 7 x64m and i have realtek soundcard.I have updated bitdefender and still getting the error pls help.

Share this post


Link to post
Share on other sites

Hello :)

Welcome back.

I have here a special patch that will reinstall the firewall components and drivers for Bitdefender 2012.

Download and save following file to your desktop.

http://www.mediafire.com/?tmyqwm68j8id5nd

Do not run it!

Now, please reboot in Safe Mode.

[How to restart in SAFE MODE With Networking]

- Restart the computer;

- Press the "F8" key several times before Microsoft Windows begins to load; you need to press "F8" until you will be displayed a text menu;

- Select "SAFE MODE With Networking"

If you have Windows Vista or 7, right click on the patch and choose Run as administrator. If not, just double click on it.

Wait for the process to finish and reboot the PC in Normal Mode.

Let me know if eve thing is OK now.

Thank you.

Share this post


Link to post
Share on other sites

Thank you for your help, but i can't do what you asked me to.When i start the computer in Safe Mode with Networking i can't connect to the internet because i get error 711 and error 1084.It's a network thing that i can't go around. It's because i don't have a router or something like that.Any other solutions?Please note that this is a fresh install of bitdefender.

Thank you

Hello :)

Welcome back.

I have here a special patch that will reinstall the firewall components and drivers for Bitdefender 2012.

Download and save following file to your desktop.

http://www.mediafire.com/?tmyqwm68j8id5nd

Do not run it!

Now, please reboot in Safe Mode.

[How to restart in SAFE MODE With Networking]

- Restart the computer;

- Press the "F8" key several times before Microsoft Windows begins to load; you need to press "F8" until you will be displayed a text menu;

- Select "SAFE MODE With Networking"

If you have Windows Vista or 7, right click on the patch and choose Run as administrator. If not, just double click on it.

Wait for the process to finish and reboot the PC in Normal Mode.

Let me know if eve thing is OK now.

Thank you.

Share this post


Link to post
Share on other sites

hello, I have had same problem with I S 2011 and continued with 2012. Can't use the patch because of ppoe internet connection not working in safe mode, error 748 as above in win 7 64bit pro. any ideea please?

Share this post


Link to post
Share on other sites

Hi :)

Please pack this folder C:\Windows\Minidump in archive with the password infected and upload it on

http://www.sendspace.com

or

http://www.mediafire.com

and send me a PM with the download link.

We will analyze the information you sent and then reply with a possible solution in the shortest time.

Have a nice day.

Share this post


Link to post
Share on other sites

Done. i have archived the folder and uploaded it you have the link in PM.

Hope this works out cause it's been almost 2 weeks without firewall :mellow:

Hi :)

Please pack this folder C:\Windows\Minidump in archive with the password infected and upload it on

http://www.sendspace.com

or

http://www.mediafire.com

and send me a PM with the download link.

We will analyze the information you sent and then reply with a possible solution in the shortest time.

Have a nice day.

Share this post


Link to post
Share on other sites

it's been a week since i sent the archive,uou could have sent me a notification that it was ok or something, instead nothing...

What's happening??? i have to race my programs to disable the firewall when my pc starts or else it restarts,what happened ??? i've been using Bitdefender for some time and i was very happy with it and actually recommended it to some friends and now this happens... sad

Share this post


Link to post
Share on other sites

Hello again, i followed the steps and updated my network card reinstalled bitdefender and it worked yesterday and most of this day but then i started getting the BSOD again.

guess there's no cure...

Hello :)

Sorry for the delayed reply.

For the current issue, please try this:

0. Update the driver from your network card and reboot your PC.

1. Reinstall Bitdefender by following these steps:

http://forum.bitdefender.com/index.php?sho...mp;#entry143091

Thank you!

Share this post


Link to post
Share on other sites

Hi :)

I think I have a solution for your case.

As the new Bitdefender 2013 product suite was released, we would like to inform you that you benefit from a FREE upgrade to the latest version.

Apart from the fact that the 2013 suite brings lots of new features and improvements, it will most likely solve any issues that you may have encountered with your previous Bitdefender product.

Please check out this announcement:

http://forum.bitdefender.com/index.php?act...f=241&id=42

After you install the new version, if needed, we will continue the conversation on the new area from here:

http://forum.bitdefender.com/index.php?showforum=293

Thank you.

Share this post


Link to post
Share on other sites

i can safely say that BitDefender 2013 DOES NOT fix the Bsod From Bdfndisf6.sys problem. Can you help, please?

Here is a download link for the generated log, using that bitdefender tool.

http://www.mediafire.com/?jhhxogk4l9j1ooz

i also copy pasted 2 dmp logs:

Microsoft ® Windows Debugger Version 6.12.0002.633 X86

Copyright © Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\New folder\071912-22171-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols

Executable search path is:

Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible

Product: WinNt, suite: TerminalServer SingleUserTS

Built by: 7601.17803.x86fre.win7sp1_gdr.120330-1504

Machine Name:

Kernel base = 0xe2c42000 PsLoadedModuleList = 0xe2d8b4d0

Debug session time: Thu Jul 19 02:37:29.128 2012 (UTC + 3:00)

System Uptime: 0 days 2:15:28.832

Loading Kernel Symbols

...............................................................

................................................................

.......................

Loading User Symbols

Loading unloaded module list

......

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {18, 2, 0, c95daeeb}

Unable to load image \??\c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys, Win32 error 0n2

*** WARNING: Unable to verify timestamp for bdfndisf6.sys

*** ERROR: Module load completed but symbols could not be loaded for bdfndisf6.sys

Probably caused by : bdfndisf6.sys ( bdfndisf6+beeb )

Followup: MachineOwner

---------

0: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If kernel debugger is available get stack backtrace.

Arguments:

Arg1: 00000018, memory referenced

Arg2: 00000002, IRQL

Arg3: 00000000, value 0 = read operation, 1 = write operation

Arg4: c95daeeb, address which referenced memory

Debugging Details:

------------------

READ_ADDRESS: GetPointerFromAddress: unable to read from e2dab848

Unable to read MiSystemVaType memory at e2d8ae20

00000018

CURRENT_IRQL: 2

FAULTING_IP:

bdfndisf6+beeb

c95daeeb a5 movs dword ptr es:[edi],dword ptr [esi]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: System

TRAP_FRAME: e2d69924 -- (.trap 0xffffffffe2d69924)

ErrCode = 00000000

eax=00000000 ebx=c4e62c90 ecx=00000000 edx=00000000 esi=00000018 edi=e2d699b8

eip=c95daeeb esp=e2d69998 ebp=e2d699cc iopl=0 nv up ei pl nz ac pe nc

cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010216

bdfndisf6+0xbeeb:

c95daeeb a5 movs dword ptr es:[edi],dword ptr [esi] es:0023:e2d699b8=00000000 ds:0023:00000018=????????

Resetting default scope

LAST_CONTROL_TRANSFER: from c95daeeb to e2c8365b

STACK_TEXT:

e2d69924 c95daeeb badb0d00 00000000 c38c20f0 nt!KiTrap0E+0x2cf

WARNING: Stack unwind information not available. Following frames may be wrong.

e2d699cc c95d3a50 c4e62c90 00000000 c4e62c90 bdfndisf6+0xbeeb

e2d699ec c95d3f9e c4af9638 00000000 c3f6d7c0 bdfndisf6+0x4a50

e2d69a10 c95d09de c3f6d7c0 c28dd3d8 00000000 bdfndisf6+0x4f9e

e2d69a50 c95d1101 c3f6d7c0 c28dd3d8 00000000 bdfndisf6+0x19de

e2d69ab4 c97a1e94 c3f6d7c0 c28dd3d8 00000000 bdfndisf6+0x2101

e2d69b00 d1d88776 02a280e0 e2d69b3c 00000001 ndis!ndisMIndicatePacketsToNetBufferLists+0xea

e2d69b40 d1d88a44 0295f2f8 00000028 c45d4044 ndiswan!IndicateRecvPacket+0x2b5

e2d69b74 d1d896f9 c295f2f8 c367b008 c2bd6844 ndiswan!ProcessPPPFrame+0x124

e2d69b94 d1d86d11 c2874a58 c367b008 c2bd6800 ndiswan!ReceivePPP+0xb3

e2d69bc4 c97645b5 c3f6bc60 0000002a 0000002a ndiswan!ProtoCoReceivePacket+0x226

e2d69bf4 c97c38a4 c4e0cf48 e2d69c34 00000001 ndis!ndisMCoIndicateReceiveNdisPacketToNdisPacket+0xda

e2d69c08 d1d9d60d c4e0cf48 e2d69c34 00000001 ndis!NdisMCoIndicateReceivePacket+0x15

e2d69c38 d1d9e176 c475b008 c3641f10 c475b2b0 raspppoe!MpIndicatePacketOnCall+0x1bb

e2d69c58 d1d96b2e c475b2b0 c475b024 00000000 raspppoe!MpIndicateReceivedPackets+0x8e

e2d69c78 e2cba1b5 d1d9a1a8 00000000 4b6aede6 raspppoe!TimerEvent+0x112

e2d69cd4 e2cba018 e2d6cd20 e2d76380 00000000 nt!KiExecuteAllDpcs+0xf9

e2d69d20 e2cb9e38 00000000 0000000e 00000000 nt!KiRetireDpcList+0xd5

e2d69d24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38

STACK_COMMAND: kb

FOLLOWUP_IP:

bdfndisf6+beeb

c95daeeb a5 movs dword ptr es:[edi],dword ptr [esi]

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: bdfndisf6+beeb

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: bdfndisf6

IMAGE_NAME: bdfndisf6.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4ec14cc6

FAILURE_BUCKET_ID: 0xD1_bdfndisf6+beeb

BUCKET_ID: 0xD1_bdfndisf6+beeb

Followup: MachineOwner

---------

Microsoft ® Windows Debugger Version 6.12.0002.633 X86

Copyright © Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\New folder\071912-15281-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols

Executable search path is:

Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible

Product: WinNt, suite: TerminalServer SingleUserTS

Built by: 7601.17803.x86fre.win7sp1_gdr.120330-1504

Machine Name:

Kernel base = 0xe2c05000 PsLoadedModuleList = 0xe2d4e4d0

Debug session time: Thu Jul 19 18:31:05.905 2012 (UTC + 3:00)

System Uptime: 0 days 0:13:20.608

Loading Kernel Symbols

...............................................................

................................................................

......................

Loading User Symbols

Loading unloaded module list

.........

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {18, 2, 0, c9a0beeb}

Unable to load image \??\c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys, Win32 error 0n2

*** WARNING: Unable to verify timestamp for bdfndisf6.sys

*** ERROR: Module load completed but symbols could not be loaded for bdfndisf6.sys

Probably caused by : bdfndisf6.sys ( bdfndisf6+beeb )

Followup: MachineOwner

---------

0: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If kernel debugger is available get stack backtrace.

Arguments:

Arg1: 00000018, memory referenced

Arg2: 00000002, IRQL

Arg3: 00000000, value 0 = read operation, 1 = write operation

Arg4: c9a0beeb, address which referenced memory

Debugging Details:

------------------

READ_ADDRESS: GetPointerFromAddress: unable to read from e2d6e848

Unable to read MiSystemVaType memory at e2d4de20

00000018

CURRENT_IRQL: 2

FAULTING_IP:

bdfndisf6+beeb

c9a0beeb a5 movs dword ptr es:[edi],dword ptr [esi]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: vsserv.exe

TRAP_FRAME: c9182bf4 -- (.trap 0xffffffffc9182bf4)

ErrCode = 00000000

eax=00000000 ebx=c4b4b6f0 ecx=00000000 edx=00000000 esi=00000018 edi=c9182c88

eip=c9a0beeb esp=c9182c68 ebp=c9182c9c iopl=0 nv up ei pl nz ac pe nc

cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010216

bdfndisf6+0xbeeb:

c9a0beeb a5 movs dword ptr es:[edi],dword ptr [esi] es:0023:c9182c88=00000000 ds:0023:00000018=????????

Resetting default scope

LAST_CONTROL_TRANSFER: from c9a0beeb to e2c4665b

STACK_TEXT:

c9182bf4 c9a0beeb badb0d00 00000000 00000000 nt!KiTrap0E+0x2cf

WARNING: Stack unwind information not available. Following frames may be wrong.

c9182c9c c9a04a50 c4b4b6f0 00000000 c4b4b6f0 bdfndisf6+0xbeeb

c9182cbc c9a04f9e c4d74588 00000000 c3f47608 bdfndisf6+0x4a50

c9182ce0 c9a019de c3f47608 c2b4df00 00000000 bdfndisf6+0x4f9e

c9182d20 c9a02101 c3f47608 c2b4df00 00000000 bdfndisf6+0x19de

c9182d84 c97b0e94 c3f47608 c2b4df00 00000000 bdfndisf6+0x2101

c9182dd0 d1f84776 029ac0e0 c9182e0c 00000001 ndis!ndisMIndicatePacketsToNetBufferLists+0xea

c9182e10 d1f84a44 02934868 00000028 eb403044 ndiswan!IndicateRecvPacket+0x2b5

c9182e44 d1f856f9 c3934868 c37f14c0 f28f6764 ndiswan!ProcessPPPFrame+0x124

c9182e64 d1f82d11 c27429a0 c37f14c0 f28f6720 ndiswan!ReceivePPP+0xb3

c9182e94 c97735b5 c3f4d130 0000002a 0000002a ndiswan!ProtoCoReceivePacket+0x226

c9182ec4 c97d28a4 c296d320 c9182f04 00000001 ndis!ndisMCoIndicateReceiveNdisPacketToNdisPacket+0xda

c9182ed8 d1f9960d c296d320 c9182f04 00000001 ndis!NdisMCoIndicateReceivePacket+0x15

c9182f08 d1f9a176 c3934460 c30fbd50 c3934708 raspppoe!MpIndicatePacketOnCall+0x1bb

c9182f28 d1f92b2e c3934708 c393447c 00000000 raspppoe!MpIndicateReceivedPackets+0x8e

c9182f48 e2c7d1b5 d1f961a8 00000000 834624be raspppoe!TimerEvent+0x112

c9182fa4 e2c7d018 e2d2fd20 c4d7abe0 00000000 nt!KiExecuteAllDpcs+0xf9

c9182ff4 e2c7c7dc e9607ce4 00000000 00000000 nt!KiRetireDpcList+0xd5

c9182ff8 e9607ce4 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x2c

e2c7c7dc 00000000 0000001a 00d6850f bb830000 0xe9607ce4

STACK_COMMAND: kb

FOLLOWUP_IP:

bdfndisf6+beeb

c9a0beeb a5 movs dword ptr es:[edi],dword ptr [esi]

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: bdfndisf6+beeb

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: bdfndisf6

IMAGE_NAME: bdfndisf6.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4ec14cc6

FAILURE_BUCKET_ID: 0xD1_bdfndisf6+beeb

BUCKET_ID: 0xD1_bdfndisf6+beeb

Followup: MachineOwner

---------

Share this post


Link to post
Share on other sites

Hello :)

Could you please pack all the files from this folder and upload them on the same file server?

C:\Windows\Minidump

Post here the download link.

Have a great weekend!

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.