Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bluescreen on Windows 7


  • Please log in to reply
6 replies to this topic

#1 sheryl0036

sheryl0036

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:26 PM

Posted 25 April 2010 - 02:41 PM

Hi,

I am experiencing frequent blue screens (2x per day or more) that don't seem to correlate to anything in particular that I am doing at the time of the BS.

My specs are:
Custom-built Pentium 4, 3.0 GHz, running Windows 7 Ultimate 32-bit (Build 7600)
HD: 1 @ 500 GB, 1 @ 200 GB, 1 @ 500 GB-external
Video: NVidea GeForce 6200
Audio: Realtek AC'97
RAM: 1.5 GB - 1 @ 512 MB, 1 @ 1024 MB
Antivirus: Comodo Internet Security

I ran SFC and it did not find any integrity violations. I also ran MemTest, which also found no errors.

Here is the Windows Debugger File for the minidump...

Any suggestions would be appreciated!

Thanks.


Microsoft ® Windows Debugger Version 6.12.0002.633 X86
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\042510-30359-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x85003000 PsLoadedModuleList = 0x8514b810
Debug session time: Sun Apr 25 12:49:30.554 2010 (UTC - 4:00)
System Uptime: 0 days 0:32:47.414
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {77d378, 2, 0, 8503b0cb}

Probably caused by : memory_corruption ( nt!MiIdentifyPfn+1cf )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0077d378, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 8503b0cb, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 8516b718
Unable to read MiSystemVaType memory at 8514b160
0077d378

CURRENT_IRQL: 2

FAULTING_IP:
nt!MiIdentifyPfn+1cf
8503b0cb 8b38 mov edi,dword ptr [eax]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: svchost.exe

TRAP_FRAME: a320b6ec -- (.trap 0xffffffffa320b6ec)
ErrCode = 00000000
eax=0077d378 ebx=86f474f0 ecx=00000000 edx=0802bc9d esi=00000000 edi=a320b798
eip=8503b0cb esp=a320b760 ebp=a320b798 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiIdentifyPfn+0x1cf:
8503b0cb 8b38 mov edi,dword ptr [eax] ds:0023:0077d378=????????
Resetting default scope

LAST_CONTROL_TRANSFER: from 8503b0cb to 8504982b

STACK_TEXT:
a320b6ec 8503b0cb badb0d00 0802bc9d 00000002 nt!KiTrap0E+0x2cf
a320b798 8503b562 86f474f0 86f47000 a320b83c nt!MiIdentifyPfn+0x1cf
a320b7c0 8521f44a 00f47060 9064214e a320b850 nt!MmQueryPfnList+0xa6
a320b808 8523fe21 00000001 906421ce 00000000 nt!PfpPfnPrioRequest+0xde
a320b888 85238865 00000000 00000001 a320bcd0 nt!PfQuerySuperfetchInformation+0xea
a320bd00 852394cc 0000004f 00000000 00000000 nt!ExpQuerySystemInformation+0x24ce
a320bd1c 8504644a 0000004f 0167f210 00000014 nt!NtQuerySystemInformation+0x76
a320bd1c 77b364f4 0000004f 0167f210 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0167d0d0 00000000 00000000 00000000 00000000 0x77b364f4


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiIdentifyPfn+1cf
8503b0cb 8b38 mov edi,dword ptr [eax]

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!MiIdentifyPfn+1cf

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cacf

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: 0xA_nt!MiIdentifyPfn+1cf

BUCKET_ID: 0xA_nt!MiIdentifyPfn+1cf

Followup: MachineOwner

---------

And, here is the BlueScreenView Crash List for the last couple of days:

Dump File Crash Time Bug Check String Bug Check Code Parameter 1 Parameter 2 Parameter 3 Parameter 4 Caused By Driver Caused By Address File Description Product Name Company File Version Processor Computer Name Full Path Processors Count Major Version Minor Version
042510-36125-01.dmp 4/25/2010 1:20:53 PM IRQL_NOT_LESS_OR_EQUAL 0x0000000a 0x8cedee1a 0x00000002 0x00000000 0x850eeebe ndis.sys ndis.sys+1e837 NDIS 6.20 driver Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16385 (win7_rtm.090713-1255) 32-bit C:\Windows\Minidump\042510-36125-01.dmp 2 15 7600
042510-30359-01.dmp 4/25/2010 12:50:48 PM IRQL_NOT_LESS_OR_EQUAL 0x0000000a 0x0077d378 0x00000002 0x00000000 0x8503b0cb ntkrnlpa.exe ntkrnlpa.exe+4682b NT Kernel & System Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16539 (win7_gdr.100226-1909) 32-bit C:\Windows\Minidump\042510-30359-01.dmp 2 15 7600
042410-29218-01.dmp 4/24/2010 6:11:20 AM IRQL_NOT_LESS_OR_EQUAL 0x0000000a 0xc0663b30 0x00000000 0x00000000 0x85058146 ntkrnlpa.exe ntkrnlpa.exe+4682b NT Kernel & System Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16539 (win7_gdr.100226-1909) 32-bit C:\Windows\Minidump\042410-29218-01.dmp 2 15 7600
042410-29062-01.dmp 4/24/2010 5:40:46 AM PAGE_FAULT_IN_NONPAGED_AREA 0x00000050 0xb2fcaaea 0x00000000 0x8509de04 0x00000000 ntkrnlpa.exe ntkrnlpa.exe+85903 NT Kernel & System Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16539 (win7_gdr.100226-1909) 32-bit C:\Windows\Minidump\042410-29062-01.dmp 2 15 7600
042410-35984-01.dmp 4/24/2010 2:57:24 AM MEMORY_MANAGEMENT 0x0000001a 0x00000403 0xc0021ae8 0x01218835 0x05a86218 ntkrnlpa.exe ntkrnlpa.exe+a7590 NT Kernel & System Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16539 (win7_gdr.100226-1909) 32-bit C:\Windows\Minidump\042410-35984-01.dmp 2 15 7600
042410-36046-01.dmp 4/24/2010 1:16:26 AM KERNEL_MODE_EXCEPTION_NOT_HANDLED 0x1000008e 0xc0000005 0x850d9dfa 0xa2823744 0x00000000 halmacpi.dll halmacpi.dll+3479 Hardware Abstraction Layer DLL Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16385 (win7_rtm.090713-1255) 32-bit C:\Windows\Minidump\042410-36046-01.dmp 2 15 7600
042210-30625-01.dmp 4/22/2010 9:17:15 PM KERNEL_MODE_EXCEPTION_NOT_HANDLED 0x1000008e 0xc0000005 0x82e70bb0 0xa3433b5c 0x00000000 fltmgr.sys fltmgr.sys+5f33 Microsoft Filesystem Filter Manager Microsoft® Windows® Operating System Microsoft Corporation 6.1.7600.16385 (win7_rtm.090713-1255) 32-bit C:\Windows\Minidump\042210-30625-01.dmp 2 15 7600

Edited by sheryl0036, 25 April 2010 - 02:57 PM.


BC AdBot (Login to Remove)

 


#2 computerxpds

computerxpds

    Bleepin' Comp


  • Moderator
  • 4,457 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:26 PM

Posted 25 April 2010 - 03:05 PM

when you ran memtest did you test each stick of ram separately? also you should think about swapping out the one 512 mb ram card for a 1 gb because windows 7 has a recommended ram of 2 GB total ram.

Also i see your a new member :huh: to BC. :huh:

Edited by computerxpds, 25 April 2010 - 03:06 PM.

sigcomp.png 
If I have replied to a topic and you reply and I haven't gotten back to you within 48 hours (2 days) then send me a P.M.
Some important links: BC Forum Rules | Misplaced Malware Logs | BC Tutorials | BC Downloads |
Follow BleepingComputer on: Facebook! | Twitter! | Google+| Come join us on the BleepingComputer Live Chat too! |


#3 Jacee

Jacee

    Bleeping around


  • Malware Response Team
  • 3,716 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:26 PM

Posted 25 April 2010 - 03:26 PM

Have you updated all drivers?

MS_MVP.gif
MS MVP Windows-Security 2006-2016
Member of UNITE, the Unified Network of Instructors and Trusted Eliminators

Admin PC Pitstop


#4 keyboardNinja

keyboardNinja

    Bleepin' Ninja


  • BC Advisor
  • 4,815 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:teh interwebz
  • Local time:04:26 PM

Posted 25 April 2010 - 04:25 PM

also you should think about swapping out the one 512 mb ram card for a 1 gb because windows 7 has a recommended ram of 2 GB total ram.

Yes, I believe having mismatched memory configurations can cause trouble on some systems.


sheryl0036,

Download BlueScreenView
No installation required.
Double click on BlueScreenView.exe file to run the program.
When scanning is done, go Edit>Select All.
Go File>Save Selected Items, and save the report as BSOD.txt.
Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.

How long has this been happening? Any new programs or hardware? What anti-virus do you use?
PICNIC - Problem In Chair, Not In Computer

Posted Image Posted Image

20 Things I Learned About Browsers and the Web

#5 sheryl0036

sheryl0036
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:26 PM

Posted 25 April 2010 - 06:24 PM

also you should think about swapping out the one 512 mb ram card for a 1 gb because windows 7 has a recommended ram of 2 GB total ram.

Yes, I believe having mismatched memory configurations can cause trouble on some systems.


sheryl0036,

Download BlueScreenView
No installation required.
Double click on BlueScreenView.exe file to run the program.
When scanning is done, go Edit>Select All.
Go File>Save Selected Items, and save the report as BSOD.txt.
Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.

How long has this been happening? Any new programs or hardware? What anti-virus do you use?


The problem has been ongoing pretty much since I upgraded to Windows 7, but more frequently over the past few months. I haven't installed any new programs recently and no new hardware. I did run the BlueScreenView.exe and it came up with no integrity violations, but I will attach the text from BSOD.txt below. I am running Comodo Internet Security. Thanks for your help.

==================================================
Dump File : 042510-36125-01.dmp
Crash Time : 4/25/2010 1:20:53 PM
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 0x8cedee1a
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0x850eeebe
Caused By Driver : ndis.sys
Caused By Address : ndis.sys+1e837
File Description : NDIS 6.20 driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042510-36125-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042510-30359-01.dmp
Crash Time : 4/25/2010 12:50:48 PM
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 0x0077d378
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0x8503b0cb
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+4682b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16539 (win7_gdr.100226-1909)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042510-30359-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042410-29218-01.dmp
Crash Time : 4/24/2010 6:11:20 AM
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 0xc0663b30
Parameter 2 : 0x00000000
Parameter 3 : 0x00000000
Parameter 4 : 0x85058146
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+4682b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16539 (win7_gdr.100226-1909)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042410-29218-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042410-29062-01.dmp
Crash Time : 4/24/2010 5:40:46 AM
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xb2fcaaea
Parameter 2 : 0x00000000
Parameter 3 : 0x8509de04
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85903
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16539 (win7_gdr.100226-1909)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042410-29062-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042410-35984-01.dmp
Crash Time : 4/24/2010 2:57:24 AM
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00000403
Parameter 2 : 0xc0021ae8
Parameter 3 : 0x01218835
Parameter 4 : 0x05a86218
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+a7590
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16539 (win7_gdr.100226-1909)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042410-35984-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042410-36046-01.dmp
Crash Time : 4/24/2010 1:16:26 AM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x850d9dfa
Parameter 3 : 0xa2823744
Parameter 4 : 0x00000000
Caused By Driver : halmacpi.dll
Caused By Address : halmacpi.dll+3479
File Description : Hardware Abstraction Layer DLL
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042410-36046-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042210-30625-01.dmp
Crash Time : 4/22/2010 9:17:15 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x82e70bb0
Parameter 3 : 0xa3433b5c
Parameter 4 : 0x00000000
Caused By Driver : fltmgr.sys
Caused By Address : fltmgr.sys+5f33
File Description : Microsoft Filesystem Filter Manager
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042210-30625-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

==================================================
Dump File : 042210-33890-01.dmp
Crash Time : 4/22/2010 9:42:21 AM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x850acdfa
Parameter 3 : 0x8bd232b8
Parameter 4 : 0x00000000
Caused By Driver : tcpip.sys
Caused By Address : tcpip.sys+804e1
File Description : TCP/IP Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Computer Name :
Full Path : C:\Windows\Minidump\042210-33890-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
==================================================

Edited by sheryl0036, 26 April 2010 - 06:02 PM.


#6 sheryl0036

sheryl0036
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:26 PM

Posted 25 April 2010 - 06:26 PM

when you ran memtest did you test each stick of ram separately? also you should think about swapping out the one 512 mb ram card for a 1 gb because windows 7 has a recommended ram of 2 GB total ram.

Also i see your a new member :huh: to BC. :huh:


I haven't tried running MemTest on each stick separately, I will do that. Also, I am going to get rid of the 512 stick and put 2 @ 1 Gb sticks in instead.
Thanks for your help.

S

#7 keyboardNinja

keyboardNinja

    Bleepin' Ninja


  • BC Advisor
  • 4,815 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:teh interwebz
  • Local time:04:26 PM

Posted 25 April 2010 - 11:09 PM

I am going to get rid of the 512 stick and put 2 @ 1 Gb sticks in instead.

I would also highly recommend doing this.

If that doesn't stop the BSOD'ing (although I'm pretty sure it will), we'll move on to other possibilities. :huh:
PICNIC - Problem In Chair, Not In Computer

Posted Image Posted Image

20 Things I Learned About Browsers and the Web




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users