Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cronic BSOD on wake and other times - x64


  • Please log in to reply
3 replies to this topic

#1 guillemot

guillemot

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:20 AM

Posted 02 June 2009 - 09:03 AM

Hi all,
New here. This looks like a great and active forum. I hope you all might suggest a solution to my chronic BSOD problem.

Running Vista x64 ultimate on a custom built desktop. The guy who built it for me did tweak the BIOS some – I believe it's running about 10% above its baseline specs (processor ~ 3,0 Ghz, ram faster too). I use it for statistics and scientific computing.

The machine crashes with BSOD 100% of the time after going through sleep mode. To mix things up a bit, it very occasionally crashes at other unpredictable times. The first crash this morning when I started up gave a PFN_LIST_CORRUPT message, but the memory dump was overwritten by the next crash. I then installed Vista x64 SP 2 (after first crash). The three subsequent crashed this morning were all MEMORY_MANAGEMENT blue screen errors. I was unable (so far) to reproduce the PFN crash to post here.

Hardware is listed below, followed by the output from windows debugger from the first two MEMORY_MANAGEMENT crashes (sorry, didn't get the PFN crash). Thanks to usasma for the great post on how to extract crash dump information!

Because of this recurring problem, I never use sleep mode and just shut down every time I leave the computer for more than an hour or so. Any suggestions are appreciated!

Sorry for the very lengthy post.

Thank you,
Jeff

Part Numbers are all NewEgg
JPAC AQPS Black / Silver Steel ATX Mid Tower Computer Case 500W Power Supply -Retail
Item #: N82E16811217042

Seagate Barracuda 7200.11 ST3500320AS 500GB 7200 RPM SATA 3.0Gb/s Hard Drive -OEM
Item #: N82E16822148288

Patriot Viper 4GB (2 x 2GB) 240-Pin DDR2 SDRAM DDR2 1066 (PC2 8500) Dual Channel Kit Desktop Memory Model PVS24G8500ELKR2 - Retail
Item #: N82E16820220315

Intel Core 2 Duo E8200 Wolfdale 2.66GHz LGA 775 65W Dual-Core Processor Model BX80570E8200 - Retail
Item #: N82E16819115038

GIGABYTE GA-EP43-DS3L LGA 775 Intel P43 ATX Intel Motherboard - Retail
Item #: N82E16813128347

BFG NVIDIA GeForce 8400 GS 512MB PCIe
BFG Vid Card

Most frequently run sotware
Symantec Endpoint Protection
MS Office 2003
Endnote X
MATLAB 2008a
SAS 9.2
R (various versions)
Google Talk
Photoshop CS3
Acrobat 8.1.5 Pro


\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
Begin Crash Dump 1
\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/


Microsoft Windows Debugger Version 6.11.0001.404 AMD64
Copyright Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6002.18005.amd64fre.lh_sp2rtm.090410-1830
Machine Name:
Kernel base = 0xfffff800`01e5b000 PsLoadedModuleList = 0xfffff800`0201fdd0
Debug session time: Tue Jun 2 08:44:47.371 2009 (GMT-4)
System Uptime: 0 days 0:23:09.195
Loading Kernel Symbols
...............................................................
........................................................Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
...Page 884bc not present in the dump file. Type ".hh dbgerr004" for details
..Page 7cd3d not present in the dump file. Type ".hh dbgerr004" for details
...
....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffda018). Type ".hh dbgerr001" for details
Loading unloaded module list
..........
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {8884, fffffa80017fffd0, fffffa8001800000, 403}

Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 884bc not present in the dump file. Type ".hh dbgerr004" for details
Page 7cd3d not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffda018). Type ".hh dbgerr001" for details
Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 884bc not present in the dump file. Type ".hh dbgerr004" for details
Page 7cd3d not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffda018). Type ".hh dbgerr001" for details
Probably caused by : memory_corruption ( nt!MiRelinkStandbyPage+a2 )

Followup: MachineOwner
---------

0: kd> !analyze -v
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008884, The subtype of the bugcheck.
Arg2: fffffa80017fffd0
Arg3: fffffa8001800000
Arg4: 0000000000000403

Debugging Details:
------------------

Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 884bc not present in the dump file. Type ".hh dbgerr004" for details
Page 7cd3d not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffda018). Type ".hh dbgerr001" for details
Page 96e1c not present in the dump file. Type ".hh dbgerr004" for details
Page 884bc not present in the dump file. Type ".hh dbgerr004" for details
Page 7cd3d not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffda018). Type ".hh dbgerr001" for details

BUGCHECK_STR: 0x1a_8884

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 2

LAST_CONTROL_TRANSFER: from fffff80001f230d2 to fffff80001eb5450

STACK_TEXT:
fffffa60`085788c8 fffff800`01f230d2 : 00000000`0000001a 00000000`00008884 fffffa80`017fffd0 fffffa80`01800000 : nt!KeBugCheckEx
fffffa60`085788d0 fffff800`01f79b5d : fffffa80`07a64bb0 fffffa80`05419708 fffffa80`07a64bb0 fffffa80`05419708 : nt!MiRelinkStandbyPage+0xa2
fffffa60`08578910 fffff800`02248cd4 : 00000000`00000000 fffffa60`00000000 00000000`00000000 fffffa80`05418000 : nt!MmSetPfnListPriorities+0x28d
fffffa60`08578980 fffff800`02289092 : fffffa60`003e9a00 00000000`00000000 fffffa80`054bc000 00000000`00000001 : nt!PfpPfnPrioRequest+0x84
fffffa60`085789d0 fffff800`0229baa8 : 00000000`00000000 00000000`00000004 fffffa80`060cd000 00000000`00000001 : nt!PfSetSuperfetchInformation+0x191
fffffa60`08578ab0 fffff800`01eb4ef3 : fffffa80`07a64bb0 00000000`02d7ceb0 00000000`0742be01 00000000`00000000 : nt!NtSetSystemInformation+0x8fb
fffffa60`08578c20 00000000`7729838a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`017bed18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7729838a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiRelinkStandbyPage+a2
fffff800`01f230d2 cc int 3

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!MiRelinkStandbyPage+a2

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 49e0237f

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: X64_0x1a_8884_nt!MiRelinkStandbyPage+a2

BUCKET_ID: X64_0x1a_8884_nt!MiRelinkStandbyPage+a2

Followup: MachineOwner
---------


\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
Begin Crash Dump 2
\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/

Microsoft Windows Debugger Version 6.11.0001.404 AMD64
Copyright Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6002.18005.amd64fre.lh_sp2rtm.090410-1830
Machine Name:
Kernel base = 0xfffff800`01e0e000 PsLoadedModuleList = 0xfffff800`01fd2dd0
Debug session time: Tue Jun 2 09:17:45.177 2009 (GMT-4)
System Uptime: 0 days 0:31:52.070
Loading Kernel Symbols
...............................................................
....................................................Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
...Page 982bd not present in the dump file. Type ".hh dbgerr004" for details
..Page 913ec not present in the dump file. Type ".hh dbgerr004" for details
.......
....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Loading unloaded module list
..............
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {8884, fffffa80017ffd30, fffffa8001800090, 605}

Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 982bd not present in the dump file. Type ".hh dbgerr004" for details
Page 913ec not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 982bd not present in the dump file. Type ".hh dbgerr004" for details
Page 913ec not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Probably caused by : memory_corruption ( nt!MiRelinkStandbyPage+a2 )

Followup: MachineOwner
---------

1: kd> !analyze -v
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008884, The subtype of the bugcheck.
Arg2: fffffa80017ffd30
Arg3: fffffa8001800090
Arg4: 0000000000000605

Debugging Details:
------------------

Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 982bd not present in the dump file. Type ".hh dbgerr004" for details
Page 913ec not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Page 9a6c5 not present in the dump file. Type ".hh dbgerr004" for details
Page 982bd not present in the dump file. Type ".hh dbgerr004" for details
Page 913ec not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details

BUGCHECK_STR: 0x1a_8884

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 2

LAST_CONTROL_TRANSFER: from fffff80001ed60d2 to fffff80001e68450

STACK_TEXT:
fffffa60`08f268c8 fffff800`01ed60d2 : 00000000`0000001a 00000000`00008884 fffffa80`017ffd30 fffffa80`01800090 : nt!KeBugCheckEx
fffffa60`08f268d0 fffff800`01f2cb5d : fffffa80`08996bb0 fffffa80`05a205c8 fffffa80`08996bb0 fffffa80`05a205c8 : nt!MiRelinkStandbyPage+0xa2
fffffa60`08f26910 fffff800`021fbcd4 : 00000000`00000000 fffffa60`00000000 00000000`00000000 fffffa80`05a20000 : nt!MmSetPfnListPriorities+0x28d
fffffa60`08f26980 fffff800`0223c092 : fffffa60`00338c00 00000000`00000000 fffffa80`05a04000 00000000`00000001 : nt!PfpPfnPrioRequest+0x84
fffffa60`08f269d0 fffff800`0224eaa8 : 00000000`00000000 00000000`00000004 fffffa80`03a7d000 00000000`00000001 : nt!PfSetSuperfetchInformation+0x191
fffffa60`08f26ab0 fffff800`01e67ef3 : fffffa80`08996bb0 00000000`039dc100 fffffa80`04a16d01 00000000`00000000 : nt!NtSetSystemInformation+0x8fb
fffffa60`08f26c20 00000000`77cf838a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`01d7ef98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77cf838a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiRelinkStandbyPage+a2
fffff800`01ed60d2 cc int 3

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!MiRelinkStandbyPage+a2

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 49e0237f

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: X64_0x1a_8884_nt!MiRelinkStandbyPage+a2

BUCKET_ID: X64_0x1a_8884_nt!MiRelinkStandbyPage+a2

Followup: MachineOwner
---------


edited to renumber crash dump sequence

Edited by guillemot, 02 June 2009 - 09:04 AM.


BC AdBot (Login to Remove)

 


#2 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:20 AM

Posted 02 June 2009 - 07:12 PM

I would start by "untweaking" whatever your friend did in the BIOS by restoring default settings

Edited by garmanma, 02 June 2009 - 07:13 PM.

Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#3 guillemot

guillemot
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:20 AM

Posted 02 June 2009 - 08:48 PM

Thanks Mark,

I just went through the BIOS settings. Looks like everything was at the defaults (to my surprise). The only thing that was off that I saw was the Bus/Core ratio, which is supposed to be 9 according to the Intel spec sheet, but was set to 8.5 (is that underclocking?). This is beyond my area of expertise, though. Is the a way to easily grab the BIOS settings so I can post them?

I have had another, different crash. New variety this time. I went through sleep, then woke up system but didn't enter password. new crash results are below.

Thanks again.

Cheers,
Jeff

\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
Begin Crash Dump 4
\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/


Microsoft ® Windows Debugger Version 6.11.0001.404 AMD64
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6002.18005.amd64fre.lh_sp2rtm.090410-1830
Machine Name:
Kernel base = 0xfffff800`01e0e000 PsLoadedModuleList = 0xfffff800`01fd2dd0
Debug session time: Tue Jun 2 20:47:16.167 2009 (GMT-4)
System Uptime: 0 days 0:09:13.987
Loading Kernel Symbols
...............................................................
........................................................Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
...Page 96dcd not present in the dump file. Type ".hh dbgerr004" for details
..Page 92c21 not present in the dump file. Type ".hh dbgerr004" for details
...
....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type ".hh dbgerr001" for details
Loading unloaded module list
..........
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 24, {1904aa, fffffa6004793e98, fffffa6004793870, fffff80001e74eda}

Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 96dcd not present in the dump file. Type ".hh dbgerr004" for details
Page 92c21 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type ".hh dbgerr001" for details
Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 96dcd not present in the dump file. Type ".hh dbgerr004" for details
Page 92c21 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type ".hh dbgerr001" for details
Probably caused by : Ntfs.sys ( Ntfs!NtfsPrefetchFile+7a2 )

Followup: MachineOwner
---------

1: kd> !analyze -v
ERROR: FindPlugIns 8007007b
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904aa
Arg2: fffffa6004793e98
Arg3: fffffa6004793870
Arg4: fffff80001e74eda

Debugging Details:
------------------

Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 96dcd not present in the dump file. Type ".hh dbgerr004" for details
Page 92c21 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type ".hh dbgerr001" for details
Page 98dec not present in the dump file. Type ".hh dbgerr004" for details
Page 96dcd not present in the dump file. Type ".hh dbgerr004" for details
Page 92c21 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type ".hh dbgerr001" for details

EXCEPTION_RECORD: fffffa6004793e98 -- (.exr 0xfffffa6004793e98)
ExceptionAddress: fffff80001e74eda (nt!MiRemoveAnyPage+0x00000000000000fa)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: fffffa6004793870 -- (.cxr 0xfffffa6004793870)
rax=cc66cc12de241236 rbx=fffffa8001800000 rcx=2211220325060309
rdx=0000000000081cfb rsi=0000000000080000 rdi=0000000000000000
rip=fffff80001e74eda rsp=fffffa60047940d0 rbp=fffff80001f7fbf0
r8=fffffa8000000008 r9=0000000000000000 r10=0000000000000000
r11=fffffa80050ce720 r12=0000000000000000 r13=0000000000000002
r14=fffffa8000000000 r15=0000000000000000
iopl=0 ov up ei ng nz ac po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010a96
nt!MiRemoveAnyPage+0xfa:
fffff800`01e74eda 498914c6 mov qword ptr [r14+rax*8],rdx ds:002b:63365b16`f12091b0=????????????????
Resetting default scope

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 2

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: ffffffffffffffff

FOLLOWUP_IP:
Ntfs!NtfsPrefetchFile+7a2
fffffa60`0112a5d2 443be3 cmp r12d,ebx

FAULTING_IP:
nt!MiRemoveAnyPage+fa
fffff800`01e74eda 498914c6 mov qword ptr [r14+rax*8],rdx

BUGCHECK_STR: 0x24

LAST_CONTROL_TRANSFER: from fffff80001e2a028 to fffff80001e74eda

STACK_TEXT:
fffffa60`047940d0 fffff800`01e2a028 : fa80050c`e79004c0 fffffa80`0a458e90 00000000`00000001 00000000`00000000 : nt!MiRemoveAnyPage+0xfa
fffffa60`04794130 fffff800`02057433 : fffffa80`07d1ca70 fffffa80`00000000 fffffa80`00000000 00000000`0000003f : nt!MiPfPutPagesInTransition+0x348
fffffa60`04794230 fffffa60`0112a5d2 : 00000000`00000000 00000000`00000000 fffffa80`05084010 fffffa80`050ac9f0 : nt!MmPrefetchPages+0xef
fffffa60`04794280 fffffa60`010fd794 : fffffa80`050ac9f0 fffffa60`04794500 00000000`00000001 fffff880`13e97a60 : Ntfs!NtfsPrefetchFile+0x7a2
fffffa60`047943b0 fffffa60`010e2145 : fffffa80`050ac9f0 00000000`00000000 fffffa80`05084010 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x14b1a
fffffa60`047943f0 fffffa60`00a0ce91 : fffffa60`04794400 fffffa80`05084010 00000000`00000001 fffffa80`050ac9f0 : Ntfs!NtfsFsdFileSystemControl+0x145
fffffa60`047944a0 fffffa60`00a296e2 : fffffa80`05f53de0 fffffa80`050d60c0 fffffa80`05f53d00 00000000`00000000 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x211
fffffa60`04794510 fffff800`020cab1e : fffffa80`05084301 00000000`00000050 fffffa80`050843b0 fffffa80`050d6000 : fltmgr!FltpFsControl+0x102
fffffa60`04794570 fffff800`020dbb36 : 00000000`00100001 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x5be
fffffa60`047946a0 fffff800`02207de5 : fffff880`0f9a54a0 ffffffff`ffe91ca0 fffffa60`04794828 00000004`00000000 : nt!NtFsControlFile+0x56
fffffa60`04794710 fffff800`02208b25 : 00000000`00000000 00000000`00001290 fffff880`13ef3338 00000000`00000063 : nt!PfpPrefetchDirectoryStream+0x1e5
fffffa60`047947c0 fffff800`0223bb5e : fffff880`00000000 00000000`00000000 fffff880`00004021 00000000`00000000 : nt!PfpVolumePrefetchMetadata+0x3d5
fffffa60`047948c0 fffff800`0223be42 : 00000000`00000000 fffffa60`04794ca0 fffffa60`04794a08 fffff880`13ef2001 : nt!PfpPrefetchRequestPerform+0x2ce
fffffa60`04794960 fffff800`0223c0a6 : fffffa60`04794a08 fffff800`01e81b01 fffffa80`09554500 00000000`00000000 : nt!PfpPrefetchRequest+0x171
fffffa60`047949d0 fffff800`0224eaa8 : 00000000`00000000 00000000`00000004 fffffa80`03b52000 00000000`00000001 : nt!PfSetSuperfetchInformation+0x1a5
fffffa60`04794ab0 fffff800`01e67ef3 : fffffa80`0a202060 00000000`00000000 fffffa80`03dd2d01 00000000`10fd96b0 : nt!NtSetSystemInformation+0x8fb
fffffa60`04794c20 00000000`7796838a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0641f3e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7796838a


SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: Ntfs!NtfsPrefetchFile+7a2

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME: Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 49e022ca

STACK_COMMAND: .cxr 0xfffffa6004793870 ; kb

FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsPrefetchFile+7a2

BUCKET_ID: X64_0x24_Ntfs!NtfsPrefetchFile+7a2

Followup: MachineOwner
---------

#4 guillemot

guillemot
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:20 AM

Posted 06 June 2009 - 04:33 PM

bump.

anyone?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users