Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

BSOD during logoff or shutdown


  • Please log in to reply
4 replies to this topic

#1 Tedsi

Tedsi

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:00 PM

Posted 08 May 2010 - 04:11 PM

I have a Dell E510 running XP HE. All MS updates are applied. It runs fine, until I logoff or shutdown. Then it gives me a BSOD. Multiple security tools find no problems. I ran the MS Debugging Tools for Windows. Results follow. Can anyone shed some light on my problem?

WARNING: Whitespace at end of path element

Microsoft ® Windows Debugger Version 6.12.0002.633 AMD64
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [H:\Woods BSOD.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

WARNING: Whitespace at end of path element
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols;SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 2600.xpsp_sp3_gdr.100216-1514
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat May 8 12:50:05.095 2010 (UTC - 7:00)
System Uptime: 1 days 15:46:30.858
Loading Kernel Symbols
...............................................................
................................................................
....
Loading User Symbols
Loading unloaded module list
..................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000008E, {c0000005, 80637625, ba257a90, 0}

Probably caused by : ntkrpamp.exe ( nt!HvpGetCellMapped+5f )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 80637625, The address that the exception occurred at
Arg3: ba257a90, Trap Frame
Arg4: 00000000

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP:
nt!HvpGetCellMapped+5f
80637625 8b4304 mov eax,dword ptr [ebx+4]

TRAP_FRAME: ba257a90 -- (.trap 0xffffffffba257a90)
ErrCode = 00000000
eax=00012418 ebx=00012418 ecx=8a462268 edx=000003ff esi=e2d65008 edi=00000fff
eip=80637625 esp=ba257b04 ebp=ba257b4c iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!HvpGetCellMapped+0x5f:
80637625 8b4304 mov eax,dword ptr [ebx+4] ds:0023:0001241c=????????
Resetting default scope

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x8E

PROCESS_NAME: winlogon.exe

LAST_CONTROL_TRANSFER: from 80638bbe to 80637625

STACK_TEXT:
ba257b4c 80638bbe e2d65008 ffffffff e108c008 nt!HvpGetCellMapped+0x5f
ba257b68 80638fae e2d65008 ffffffff e108c008 nt!CmpCopyCell+0x12
ba257b9c 806395b7 01d65008 00166090 0004b020 nt!CmpCopyValue+0xc0
ba257be4 80639a6e e2d65008 00135480 0004a3d0 nt!CmpCopyKeyPartial+0x16f
ba257c24 80639b7b e1152000 00000400 00000003 nt!CmpCopySyncTree2+0x25a
ba257c54 80635564 e2d65008 00000020 e108c008 nt!CmpCopySyncTree+0x4f
ba257c88 80625373 00000020 80000850 00000003 nt!CmSaveKey+0xde
ba257cb0 8054163c e3dec9d0 80000850 ba257d54 nt!NtSaveKey+0xcf
ba257cb0 80500d79 e3dec9d0 80000850 ba257d54 nt!KiFastCallEntry+0xfc
ba257d30 80625328 8000083c 80000850 ba257d64 nt!ZwSaveKey+0x11
ba257d54 8054163c 00000090 00000674 0006f8ac nt!NtSaveKey+0x84
ba257d54 7c90e514 00000090 00000674 0006f8ac nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0006f8ac 00000000 00000000 00000000 00000000 0x7c90e514


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!HvpGetCellMapped+5f
80637625 8b4304 mov eax,dword ptr [ebx+4]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!HvpGetCellMapped+5f

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4b7a9cac

FAILURE_BUCKET_ID: 0x8E_nt!HvpGetCellMapped+5f

BUCKET_ID: 0x8E_nt!HvpGetCellMapped+5f

Followup: MachineOwner
---------

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 56,295 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:09:00 PM

Posted 08 May 2010 - 05:12 PM

Good info...but I'd like to try something else.

Download/install BlueScreenView, http://www.nirsoft.net/utils/blue_screen_view.html.

Double-click BlueScreenView.exe file.

When scanning is done, Edit/Select All...then File/Save Selected Items. Save the report as BSOD.txt. If the reported date for errors is not in chronological order (most recent at top), then you may want to sort that column to make it so...before saving the file.

Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.

Thanks :thumbsup:.

Louis

#3 Tedsi

Tedsi
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:00 PM

Posted 19 May 2010 - 07:13 PM

Nirsoft reports:
==================================================
Dump File : Mini051910-01.dmp
Crash Time : 5/19/2010 4:46:19 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637738
Parameter 3 : 0xa97f1a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160738
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini051910-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini051010-01.dmp
Crash Time : 5/10/2010 10:56:35 AM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba327a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini051010-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050910-01.dmp
Crash Time : 5/9/2010 4:27:43 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637738
Parameter 3 : 0xa97e1a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160738
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050910-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-06.dmp
Crash Time : 5/8/2010 9:36:47 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba317a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-06.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-05.dmp
Crash Time : 5/8/2010 1:58:40 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba247a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-05.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-04.dmp
Crash Time : 5/8/2010 1:24:44 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba237a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-04.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-03.dmp
Crash Time : 5/8/2010 1:22:06 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba297a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-03.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-02.dmp
Crash Time : 5/8/2010 1:14:48 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x8062bf31
Parameter 3 : 0xba237a7c
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+154f31
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-02.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050810-01.dmp
Crash Time : 5/8/2010 12:50:54 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba257a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050810-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050610-04.dmp
Crash Time : 5/6/2010 9:03:52 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xba2e7a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050610-04.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050610-03.dmp
Crash Time : 5/6/2010 8:33:34 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637738
Parameter 3 : 0xba217a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160738
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050610-03.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050610-02.dmp
Crash Time : 5/6/2010 5:25:57 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xb9726a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050610-02.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

==================================================
Dump File : Mini050610-01.dmp
Crash Time : 5/6/2010 5:02:57 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x80637625
Parameter 3 : 0xb9825a90
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+160625
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050610-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================

#4 hamluis

hamluis

    Moderator


  • Moderator
  • 56,295 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:09:00 PM

Posted 19 May 2010 - 08:01 PM

Well...nothing I see that makes any sense to me.

8E STOP errors are common as shutdown issues, usually because of a driver issue. But these can be hardware, software, O/S-related.

From http://www.aumha.org/win5/a/shtdwnxp.php:

"One approach to these problems: Restart the computer. Press F8 during the restart and select “ Last Known Good Configuration.” If you catch the problem when it first occurs (meaning you likely have installed only one or two drivers or new service), this will return you to a previous working condition. System Restore provides an alternate approach, especially if you need to go back further than the last known good configuration, and Device Manager provides a tool for rolling back to an earlier driver."

Me...I would check Event Viewer for known errors which surface approximating your shutdown times. The fact that shutdown issues can be caused by so many things...would force me to look at EV for assistance.

Louis

Edited by hamluis, 21 May 2010 - 08:44 PM.


#5 Tedsi

Tedsi
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:00 PM

Posted 21 May 2010 - 07:24 PM

Thanks. Been there, done all that. My guess is this problem occurred when the user tried to renew his Norton license, got hosed up, and then ran the Norton Removal Tool. It's just a guess. I appreciate your attention. Thanks again.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users