Windows 7 BSOD at 08:30:27 on 27-April-2012 following first run of LiveUpdate definitions.
Windows minidump via BlueScreenView shows the problem was caused by driver navex15.sys
navex15.sys is located in …..
C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\VirusDefs\20120426.032\NAVEX15.SYS
I note that Program Data is holding an older engine version of Norton Internet Security.
Norton Internet Security engine installed is the latest 19.7.0.9 yet Program Data has version 19.5.1.2
Norton 2012 was originally cleanly installed after using the removal tool and the navex15.exe file shows that it was modified on 16-April-2012 and created today on 27-April-2012 at 08:21:31 so there does not seem to be a problem from that aspect.
It seems that the LiveUpdate session that shortly afterwards resulted in a crash did install as it has been recorded in history as completed at 08:22:54 although the actual crash took place just shortly after that at 08:30:27 and just a few seconds after the firewall updated the configuration with 116 rules at 08:30:21
However there is not currently an issue with LiveUpdates as they all seem to be installing without any further crashes.
Here is a summary report with the drivers that were found in the crash stack …..
Windows 7 Crash Report Extract Caused By Norton Driver NAVEX15.SYS
Dump File : 042712-27468-01.dmp
Crash Time : 27/04/2012 08:30:27
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x9e2af38a
Parameter 3 : 0x913fb288
Parameter 4 : 0x913fae60
Caused By Driver : NAVEX15.SYS
Caused By Address : NAVEX15.SYS+8338a
File Description :
Product Name :
Company :
File Version :
Processor : 32-bit
Crash Address : NAVEX15.SYS+8338a
Stack Address 1 : NAVEX15.SYS+83110
Stack Address 2 : NAVEX15.SYS+715cb
Stack Address 3 : NAVEX15.SYS+6f446
Computer Name :
Full Path : C:\Windows\Minidump\042712-27468-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 7601
Dump File Size : 161,445
==================================================
Filename : fltmgr.sys
Address In Stack : fltmgr.sys+7cb988c
From Address : 0x89742000
To Address : 0x89776000
Size : 0x00034000
Time Stamp : 0x4a5bbf11
Time String : 14/07/2009 00:11:13
Product Name : Microsoft® Windows® Operating System
File Description : Microsoft Filesystem Filter Manager
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Company : Microsoft Corporation
Full Path : C:\Windows\system32\drivers\fltmgr.sys
==================================================
Filename : NAVEX15.SYS
Address In Stack : NAVEX15.SYS+8338a
From Address : 0x9e22c000
To Address : 0x9e3ab300
Size : 0x0017f300
Time Stamp : 0x4e32a280
Time String : 29/07/2011 13:07:2
Product Name :
File Description :
File Version :
Company :
Full Path :
==================================================
Filename : ntoskrnl.exe
Address In Stack : ntoskrnl.exe+e7e4944
From Address : 0x82c17000
To Address : 0x8301a000
Size : 0x00403000
Time Stamp : 0x4f558413
Time String : 06/03/2012 04:27:15
Product Name : Microsoft® Windows® Operating System
File Description : NT Kernel & System
File Version : 6.1.7601.17790 (win7sp1_gdr.120305-1505)
Company : Microsoft Corporation
Full Path : C:\Windows\system32\ntoskrnl.exe
==================================================
Filename : SiWinAcc.sys
Address In Stack : SiWinAcc.sys+7afe94c
From Address : 0x898fd000
To Address : 0x89900100
Size : 0x00003100
Time Stamp : 0x4671d713
Time String : 15/06/2007 01:02:27
Product Name : SATALink Accelerator driver
File Description : Windows Accelerator Driver
File Version : 1.1.12.0
Company : Silicon Image, In
Full Path : C:\Windows\system32\drivers\SiWinAcc.sys
==================================================
Filename : SRTSP.SYS
Address In Stack : SRTSP.SYS+f4dea6c0
From Address : 0x9c611000
To Address : 0x9c6a5000
Size : 0x00094000
Time Stamp : 0x4f622f6d
Time String : 15/03/2012 19:05:33
Product Name :
File Description :
File Version :
Company :
Full Path :
==================================================