Re: Code integrity error on tcpip.sys -- IS suspicious



"Luke Kaven" <Luke Kaven@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:7325F3C4-A2E9-4573-8D25-CA742962C93E@xxxxxxxxxxxxxxxx
Since installing Vista SP1 three weeks ago, I have had BSOD crashes that
immediately follow a CodeIntegrity violation error (event ID 3002) in the log
that cites TCPIP.SYS according to the OPs message. Over a hundred crashes.

Day after day, I've been over this problem with 1st and 2nd level Vista
support. I am now strongly suspicious that this driver is corrupt and is
causing these crashes. The version installed by SP1 currently on my system
reads as v6.0.6001.18000 and is dated 18-Jan-2008.

My driver was not patched so far as I know. The only third party software
installed after SP1 is Adobe CS4. Bone stock Dell Dimension E521. Lots of
systematic searches for driver updates, disabling unneeded devices, all to no
avail. The only constant is TCPIP.SYS and the error report that immediately
precedes each crash.

I do not know if I am a candidate for hotfix based on KB article #952709,
which carries TWO updates of this one file. [v6.0.6001.18063 and
v6.0.6001.22167 (both dated 26-Apr-2008). ]

Are you really sure this is okay?

What can I do? Install the hotfix listed above? Try SP2 BETA? Reverting
to pre SP1 isn't an option, because my Adobe CS4 won't run without SP1 or
higher.

Luke Kaven

""Darrell Gorter[MSFT]"" wrote:

Hello Mark,
Yes the file is OK.
This error happens when tcpip.sys is loaded in user mode, to check the
version information of the driver binary.
It loaded fine at boot time in kernel mode and was successfully verified or
you would have seen errors at boot time or tcpip.sys would not have loaded.

Thanks,
Darrell Gorter[MSFT]

This posting is provided "AS IS" with no warranties, and confers no rights
--------------------
| >From: "Mark Naughton" <MarkNaughton@xxxxxxxxxxx>
| >Subject: Code integrity error on tcpip.sys
| >Date: Wed, 10 Dec 2008 15:40:03 -0500
| >Lines: 38
| >Message-ID: <B11D7537-E874-4D0A-8DD9-5A1657251BBE@xxxxxxxxxxxxx>
| >MIME-Version: 1.0
| >Content-Type: text/plain;
| > format=flowed;
| > charset="utf-8";
| > reply-type=original
| >Content-Transfer-Encoding: 8bit
| >X-Priority: 3
| >X-MSMail-Priority: Normal
| >X-Newsreader: Microsoft Windows Mail 6.0.6001.18000
| >X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18049
| >X-MS-CommunityGroup-MessageCategory:
{E4FCE0A9-75B4-4168-BFF9-16C22D8747EC}
| >X-MS-CommunityGroup-PostID: {B11D7537-E874-4D0A-8DD9-5A1657251BBE}
| >Newsgroups: microsoft.public.windows.vista.security
| >Path: TK2MSFTNGHUB02.phx.gbl
| >Xref: TK2MSFTNGHUB02.phx.gbl
microsoft.public.windows.vista.security:19999
| >NNTP-Posting-Host: TK2MSFTNGHUB02.phx.gbl 127.0.0.1
| >X-Tomcat-NG: microsoft.public.windows.vista.security
| >
| >
| >
| >Sigcheck reports file as ok, sfc /scannow completes ok. Is this file ok?
| >Thanks Mark
| >
| >
| >Code integrity determined that the image hash of a file is not valid.
The
| >file could be corrupt due to unauthorized modification or the invalid
hash
| >could indicate a potential disk device error.
| >
| >File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
| >
| >
| >
| >
| >C:\Windows\System32\drivers>sigcheck -a -h -r tcpip.sys
| >
| >sigcheck v1.54 - sigcheck
| >Copyright (C) 2004-2008 Mark Russinovich
| >Sysinternals - www.sysinternals.com
| >
| >C:\Windows\System32\drivers\tcpip.sys:
| > Verified: Signed
| > Signing date: 7:33 PM 5/28/2008
| > Publisher: Microsoft Corporation
| > Description: TCP/IP Driver
| > Product: Microsoft« Windows« Operating System
| > Version: 6.0.6001.18063
| > File version: 6.0.6001.18063 (vistasp1_gdr.080425-1930)
| > Original Name: tcpip.sys
| > Internal Name: tcpip.sys
| > Copyright: ⌐ Microsoft Corporation. All rights reserved.
| > Comments: n/a
| > MD5: 82e266bee5f0167e41c6ecfdd2a79c02
| > SHA1: f633629656e43452aa08611f0f72d24a46e7441c
| > SHA256:
| >1f462e882a662b2a133df035c435001b2ef6364f49a9ed6a6d98bd643093b666
| >
| >

Check Dell's support site for a new device driver for the network interface hardware.

Mike.


.



Relevant Pages

  • Installation of XP SP1 - updating of Yamaha Sound System
    ... Ques - When I install full version of SP1, will it replace all the Win XP ... Instructions for installing Win XP SP1, indicate that Yamaha Sound System ... Download the latest Yamaha Sound System Driver, ...
    (microsoft.public.windowsxp.general)
  • Re: [opensuse] BCM4312 - How to get working
    ... wireless card does not seem to have a driver. ... I seem to recall that the 4312 doesn't have a working linux driver. ... I was able to install ndiswrapper and get the bcm4312 working again. ... I only updated from SP1 to SP2 ...
    (SuSE)
  • Re: The USB device can perform faster if you connect it to a High Speed USB 2.0 port
    ... service packs installed (ref to it being in SP1 ... and having to manually install it), ... it was connected to a high speed USB 2.0device. ... Driver and Update driver, and let it search ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: The USB device can perform faster if you connect it to a High Speed USB 2.0 port
    ... service packs installed (ref to it being in SP1 ... and having to manually install it), ... it was connected to a high speed USB 2.0device. ... Driver and Update driver, and let it search ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: SP1 Premium Edition - CEICW Error on NIC
    ... Just a guess but is the driver for the NIC up to date? ... > will have to do the 'Microsoft' Standard Tech Response, ... After I downloaded the SP1 Files from Microsoft, ... >>> Call to Validating hardware selection returned ok. ...
    (microsoft.public.windows.server.sbs)