Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Lots of BSOD problems!


  • Please log in to reply
24 replies to this topic

#1 prawnking

prawnking

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 06 September 2014 - 03:16 PM

Hi, I've been having fairly regular BSODs with the 0x0000003B error code for a few months now, recently I did a massive Windows Update, I think I've updated all my drivers, but still keep getting it now and again. It seems to be triggered by playing videos or sound files, although it's not every time.

 

Someone recommended getting rid of Avast Anti-Virus, which I replaced with MSE, but it still keeps happening. I'm now getting different BSODs too: 'IRQL_NOT_LESS_OR_EQUAL' 0x0000000A, 'REGISTRY ERROR' 0X00000051, 'BAD_POOL_ERROR'?!?

 

(My laptop used to shut down which I assumed was due to overheating of the fan, although now I prop it up with books, so that doesn't happen anymore, but thought it maybe relevant?)

 

Also my browser keeps crashing, which it never used to. It was Firefox, so I moved over to IE, which doesn't do it as often, but still crashes occasionally.

At my wits end and don't know where to look anymore...grateful for any help!

 

 

 

Computer type Laptop
System Manufacturer/Model Number Acer
OS Windows 7 Home Premium 64bit
CPU Aspire 5742
Motherboard Intel Core i3 CPU 2.53 Ghz
Memory 4.00 GB
Graphics Card Intel HD Graphics
 

 

Hard Drives 283 GB
Antivirus MSE

Browser IE

Edited by prawnking, 06 September 2014 - 03:17 PM.


BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,405 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:02:57 AM

Posted 06 September 2014 - 03:28 PM

Please download MiniToolBox  , save it to your desktop and run it.
 
Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory size.
 
Click Go and paste the content into your next post.
 
Also...please Publish a Snapshot using Speccy - http://www.bleepingcomputer.com/forums/topic323892.html/page__p__1797792#entry1797792 , taking care to post the link of the snapshot in your next post.
 
Louis



#3 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 06 September 2014 - 03:33 PM

Could you upload the dump files to a file sharing site such as onedrive then post the download link for analysis.



#4 prawnking

prawnking
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 06 September 2014 - 03:42 PM

http://speccy.piriform.com/results/YxNv3TsjYwroc3N2Wfu3Mol

 

MiniToolBox by Farbar  Version: 21-07-2014
Ran by Ad (administrator) on 06-09-2014 at 21:36:50
Running from "C:\Users\Ad\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

 

========================= Event log errors: ===============================

 

Application errors:
==================
Error: (09/06/2014 07:55:32 PM) (Source: Application Error) (User: )
Description: Faulting application name: TrustedInstaller.exe, version: 6.1.7601.17514, time stamp: 0x4ce7989b
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeb033f
Exception code: 0xc0000005
Fault offset: 0x00000000000033f1
Faulting process id: 0x1928
Faulting application start time: 0xTrustedInstaller.exe0
Faulting application path: TrustedInstaller.exe1
Faulting module path: TrustedInstaller.exe2
Report Id: TrustedInstaller.exe3

 

Error: (09/06/2014 07:12:14 PM) (Source: Application Error) (User: )
Description: Faulting application name: SearchIndexer.exe, version: 7.0.7601.17610, time stamp: 0x4dc0d019
Faulting module name: TQUERY.DLL, version: 7.0.7601.17610, time stamp: 0x4dc0e17a
Exception code: 0xc0000005
Fault offset: 0x000000000002ea08
Faulting process id: 0xe98
Faulting application start time: 0xSearchIndexer.exe0
Faulting application path: SearchIndexer.exe1
Faulting module path: SearchIndexer.exe2
Report Id: SearchIndexer.exe3

 

Error: (09/06/2014 07:10:21 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: Flash32_14_0_0_176.ocx, version: 14.0.0.176, time stamp: 0x53d80ad2
Exception code: 0xc0000005
Fault offset: 0x005e0ec2
Faulting process id: 0x17f0
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

 

Error: (09/06/2014 06:46:10 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0x538
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

 

Error: (09/06/2014 06:43:53 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: jscript9.dll, version: 11.0.9600.17207, time stamp: 0x53a217f1
Exception code: 0xc0000005
Fault offset: 0x0008dc2a
Faulting process id: 0x8b8
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

 

Error: (09/06/2014 06:43:20 PM) (Source: Application Error) (User: )
Description: Faulting application name: MsMpEng.exe, version: 4.5.216.0, time stamp: 0x531f64e3
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000047f0051
Faulting process id: 0x2398
Faulting application start time: 0xMsMpEng.exe0
Faulting application path: MsMpEng.exe1
Faulting module path: MsMpEng.exe2
Report Id: MsMpEng.exe3

 

Error: (09/06/2014 06:38:19 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1056) SUS20ClientDataStore: The database page read from the file "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb" at offset 7471104 (0x0000000000720000) (database page wuaueng.dll0) for 32768 (0x00008000) bytes failed verification due to a page checksum mismatch.  The expected checksum was [4b7cb48377788e3f:be5841a7be50008d:4b8e4b8e3e2600b5:b861479e7f8100c4] and the actual checksum was [b5dfb5df587b7dc3:b25bb25b9d50008d:4b8e4b8e3e2600b5:b861479e7f8100c4].  The read operation will fail with error -1018 (0xfffffc06).  If this condition persists then please restore the database from a previous backup.  This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

 

Error: (09/06/2014 06:37:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1056) SUS20ClientDataStore: The database page read from the file "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb" at offset 8978432 (0x0000000000890000) (database page wuaueng.dll0) for 32768 (0x00008000) bytes failed verification due to a page checksum mismatch.  The expected checksum was [e75de65daec6a457:fff920068e05fd8c:6f0e660e5c39778f:f086f9868f5817f8] and the actual checksum was [6c1d93e284c6a457:dff920068e05fd8c:660e660e5c39778f:f986f9868f5817f8].  The read operation will fail with error -1018 (0xfffffc06).  If this condition persists then please restore the database from a previous backup.  This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

 

Error: (09/06/2014 06:37:27 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1056) SUS20ClientDataStore: The database page read from the file "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb" at offset 10452992 (0x00000000009f8000) (database page wuaueng.dll0) for 32768 (0x00008000) bytes failed verification due to a page checksum mismatch.  The expected checksum was [dd1122ee2beed892:75dd8a220c600103:08bd08bdda000106:8c7b8c7b7fc60118] and the actual checksum was [dd1322ec15ecec90:75dd8a220c600103:08bd08bdda000106:b879b87975c60118].  The read operation will fail with error -1018 (0xfffffc06).  If this condition persists then please restore the database from a previous backup.  This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

 

Error: (09/06/2014 06:37:21 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: jscript9.dll, version: 11.0.9600.17207, time stamp: 0x53a217f1
Exception code: 0xc0000005
Fault offset: 0x001173b9
Faulting process id: 0x414
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

 

System errors:
=============
Error: (09/06/2014 08:01:56 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 0.0.0.0

 Update Source: %NT AUTHORITY59

 Update Stage: 4.5.0216.00

 Source Path: 4.5.0216.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\SYSTEM

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

 

Error: (09/06/2014 08:01:39 PM) (Source: ipnathlp) (User: )
Description: 192.168.0.7192.168.137.0255.255.255.0

 

Error: (09/06/2014 08:01:39 PM) (Source: ipnathlp) (User: )
Description:

 

Error: (09/06/2014 08:00:09 PM) (Source: Service Control Manager) (User: )
Description: The SupportSoft RemoteAssist service failed to start due to the following error:
%%2

 

Error: (09/06/2014 07:59:58 PM) (Source: BugCheck) (User: )
Description: 0x00000051 (0x0000000000000001, 0xfffff8a011ef7010, 0x000000002520d000, 0x0000000000000465)C:\Windows\MEMORY.DMP090614-45021-01

 

Error: (09/06/2014 07:59:49 PM) (Source: Microsoft Antimalware) (User: )
Description: %60 has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.

 Signatures Attempted: %24

 Error Code: 0x8050800c

 Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.

 Signature version: 1.183.1819.0;1.183.1819.0

 Engine version: %600

 

Error: (09/06/2014 07:59:39 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 19:57:38 on ‎06/‎09/‎2014 was unexpected.

Error: (09/06/2014 07:55:39 PM) (Source: Service Control Manager) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

 

Error: (09/06/2014 07:21:27 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 0.0.0.0

 Update Source: %NT AUTHORITY59

 Update Stage: 4.5.0216.00

 Source Path: 4.5.0216.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\SYSTEM

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

 

Error: (09/06/2014 07:12:16 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

 

Microsoft Office Sessions:
=========================
Error: (09/06/2014 07:55:32 PM) (Source: Application Error)(User: )
Description: TrustedInstaller.exe6.1.7601.175144ce7989bmsvcrt.dll7.0.7601.177444eeb033fc000000500000000000033f1192801cfca0374b2e821C:\Windows\servicing\TrustedInstaller.exeC:\Windows\system32\msvcrt.dll607affbc-35f7-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 07:12:14 PM) (Source: Application Error)(User: )
Description: SearchIndexer.exe7.0.7601.176104dc0d019TQUERY.DLL7.0.7601.176104dc0e17ac0000005000000000002ea08e9801cfc9bf3dd22ffbC:\Windows\system32\SearchIndexer.exeC:\Windows\system32\TQUERY.DLL5368b480-35f1-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 07:10:21 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50Flash32_14_0_0_176.ocx14.0.0.17653d80ad2c0000005005e0ec217f001cfc9fd193db322C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\Macromed\Flash\Flash32_14_0_0_176.ocx10515863-35f1-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 06:46:10 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50ntdll.dll6.1.7601.18247521ea8e7c0000374000ce75353801cfc9fa68cc3c2aC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\ntdll.dllaf7366cb-35ed-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 06:43:53 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50jscript9.dll11.0.9600.1720753a217f1c00000050008dc2a8b801cfc9f937b9be4eC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll5d7dfa14-35ed-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 06:43:20 PM) (Source: Application Error)(User: )
Description: MsMpEng.exe4.5.216.0531f64e3unknown0.0.0.000000000c000000500000000047f0051239801cfc9f9204b52aac:\Program Files\Microsoft Security Client\MsMpEng.exeunknown4a2525fe-35ed-11e4-b334-c7fd536eeb50

 

Error: (09/06/2014 06:38:19 PM) (Source: ESENT)(User: )
Description: wuaueng.dll1056SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb7471104 (0x0000000000720000)32768 (0x00008000)-1018 (0xfffffc06)[4b7cb48377788e3f:be5841a7be50008d:4b8e4b8e3e2600b5:b861479e7f8100c4][b5dfb5df587b7dc3:b25bb25b9d50008d:4b8e4b8e3e2600b5:b861479e7f8100c4]227 (0xE3)

 

Error: (09/06/2014 06:37:47 PM) (Source: ESENT)(User: )
Description: wuaueng.dll1056SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb8978432 (0x0000000000890000)32768 (0x00008000)-1018 (0xfffffc06)[e75de65daec6a457:fff920068e05fd8c:6f0e660e5c39778f:f086f9868f5817f8][6c1d93e284c6a457:dff920068e05fd8c:660e660e5c39778f:f986f9868f5817f8]273 (0x111)

 

Error: (09/06/2014 06:37:27 PM) (Source: ESENT)(User: )
Description: wuaueng.dll1056SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb10452992 (0x00000000009f8000)32768 (0x00008000)-1018 (0xfffffc06)[dd1122ee2beed892:75dd8a220c600103:08bd08bdda000106:8c7b8c7b7fc60118][dd1322ec15ecec90:75dd8a220c600103:08bd08bdda000106:b879b87975c60118]318 (0x13E)

 

Error: (09/06/2014 06:37:21 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50jscript9.dll11.0.9600.1720753a217f1c0000005001173b941401cfc9f75247d1f4C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll746eaec7-35ec-11e4-b334-c7fd536eeb50

 

=========================== Installed Programs ============================
Ace Stream Media 2.2.10-next (HKCU\...\AceStream) (Version: 2.2.10-next - Ace Stream Media)
Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems)
Acer Crystal Eye Webcam (HKLM-x32\...\{7760D94E-B1B5-40A0-9AA0-ABF942108755}) (Version: 5.3.36.1 - Suyin Optronics Corp)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated)
Acer GameZone Console (HKLM-x32\...\{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1) (Version: 6.1.0.9 - Oberon Media, Inc.)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0707.2010 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 14.0.0.178 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.176 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.04) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Airport Mania First Flight (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}) (Version:  - Oberon Media)
Amazon MP3 Downloader 1.0.18 (HKCU\...\Amazon MP3 Downloader) (Version: 1.0.18 - Amazon Services LLC)
Amazonia (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}) (Version:  - Oberon Media)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Assessment and Deployment Kit (HKLM-x32\...\{fc46d1b2-9557-4c1f-baac-04af4d2db7e4}) (Version: 8.59.25584 - Microsoft Corporation)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden
Baldur's Gate -  The Original Saga (HKLM-x32\...\GOGPACKBALDURSGATE1_is1) (Version: 2.0.0.20 - GOG.com)
Baldur's Gate II (HKLM-x32\...\Baldur's Gate II_is1) (Version:  - GOG.com)
BBC iPlayer Downloads (HKLM-x32\...\{198DFB43-9C28-4204-93ED-1545E3E467B8}) (Version: 1.0.2 - BBC)
BitTorrent (HKCU\...\BitTorrent) (Version: 7.9.2.32128 - BitTorrent Inc.)
Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 14.0.2.3 - Broadcom Corporation)
Budget Tracker 3.1 (HKCU\...\Budget Tracker 3.1) (Version:  - )
Cake Mania (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}) (Version:  - Oberon Media)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
Celestia 1.6.1 (HKLM-x32\...\Celestia_is1) (Version:  - Shatters Software)
CyberLink PowerDVD 9 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.3216.50 - CyberLink Corp.)
CyberLink PowerDVD 9 (x32 Version: 9.0.3216.50 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DFX (HKLM-x32\...\DFX) (Version: 11.105.0.0 - Power Technology)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.28 - DivX, LLC)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version:  - Oberon Media)
ETDWare PS/2-x64 7.0.6.5_WHQL (HKLM\...\Elantech) (Version: 7.0.6.5 - ELAN Microelectronics Corp.)
Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version:  - Oberon Media)
FileHippo.com Update Checker (HKLM-x32\...\FileHippo.com) (Version:  - )
Final Draft (HKLM-x32\...\{E8FDC52C-83F4-4A0F-AA65-D0E8C0F3302F}) (Version: 9.0.0.163 - Final Draft, Inc.)
foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski)
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version:  - Oberon Media)
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
GOG.com Downloader version 3.5.6 (HKLM-x32\...\{456A5815-604D-4D72-94DF-346D2B978A59}_is1) (Version: 3.5.6 - GOG.com)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version:  - Oberon Media)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
IMinent Toolbar (HKLM-x32\...\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}) (Version: 3.26.0 - IMinent)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2993 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kits Configuration Installer (x32 Version: 8.59.25584 - Microsoft) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LatencyMon 5.00 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.14 - Acer Inc.)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.)
Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version:  - Oberon Media)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Performance Toolkit (HKLM\...\{24190661-2122-40D1-9F7C-8FDEA5AE4197}) (Version: 4.6.0 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden
Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden
Nero MediaHome 4 (x32 Version: 4.5.9.4 - Nero AG) Hidden
Nero MediaHome 4 Essentials (HKLM-x32\...\{915d5a61-2e6c-43d2-aac9-0729145d5f26}) (Version:  - Nero AG)
Nero MediaHome 4 Help (x32 Version: 4.5.5.0 - Nero AG) Hidden
Nero Online Upgrade (x32 Version: 1.3.0.0 - Nero AG) Hidden
NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8939 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8939 - NTI Corporation) Hidden
OpenOffice.org 3.3 (HKLM-x32\...\{82AF3E91-57E1-4754-84D0-40A46E2479AB}) (Version: 3.3.9567 - OpenOffice.org)
Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version:  - Oberon Media)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version:  - )
Rapport (x32 Version: 3.5.1403.78 - Trusteer) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6839 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.)
Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden
SopCast 3.4.0 (HKLM-x32\...\SopCast) (Version: 3.4.0 - www.sopcast.com)
Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version:  - Oberon Media)
Spotify (HKCU\...\Spotify) (Version: 0.8.3.222.g317ab79d - Spotify AB)
Spotify (HKLM-x32\...\Spotify) (Version: 0.5.2 - )
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1108 - SUPERAntiSpyware.com)
System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC)
Toolkit Documentation (x32 Version: 8.59.25584 - Microsoft) Hidden
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1403.78 - Trusteer)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2836939v3) (Version: 3 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.18 - Veetle, Inc)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3007 - Acer Incorporated)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows Phone app for desktop (HKLM-x32\...\{E786AE85-8A30-4CF2-BF70-57404A5CD684}) (Version: 1.0.1720.1 - Microsoft Corporation)
WinPatrol (HKLM\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 32.0.2014.5 - Ruiware)
WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
WPT Redistributables (x32 Version: 8.59.25584 - Microsoft) Hidden
WPTx64 (x32 Version: 8.59.25584 - Microsoft) Hidden

 

========================= Memory info: ===================================

Percentage of memory in use: 46%
Total physical RAM: 3766.71 MB
Available physical RAM: 2000.11 MB
Total Pagefile: 7531.6 MB
Available Pagefile: 5356.34 MB
Total Virtual: 4095.88 MB
Available Virtual: 3972.82 MB

 

========================= Partitions: =====================================

1 Drive c: (Acer) (Fixed) (Total:283.99 GB) (Free:41.46 GB) NTFS

 

========================= Users: ========================================

User accounts for \\AD-PC

Ad                       Administrator            Guest                   
NeroMediaHomeUser.4     

**** End of log ****


Edited by hamluis, 06 September 2014 - 04:33 PM.


#5 prawnking

prawnking
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 06 September 2014 - 04:14 PM

Dump files:

 

https://onedrive.live.com/redir?resid=759BC6BC21BB1281%214569



#6 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 06 September 2014 - 04:44 PM

Hang on, I was looking at the wrong thread sorry... :crazy:

I'll analyse your files in a minute.


Edited by Jared44, 06 September 2014 - 04:46 PM.


#7 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 06 September 2014 - 05:16 PM

Okay, I downloaded six dump files and they're all the same pretty much which is good.

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80004567013, Address of the instruction which caused the bugcheck
Arg3: fffff88008e98140, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

We have an access violation which means memory was referenced which the CPU couldn't address because it was read only memory or it didn't exist.

2: kd> .cxr 0xfffff88008e98140;r
rax=fffff88004528d20 rbx=00000000012789f0 rcx=00000000003f0000
rdx=fffff88004528d20 rsi=0000000000000000 rdi=0000000020786e53
rip=fffff80004567013 rsp=fffff88008e98b20 rbp=00000000000004cc
 r8=0000000000000001  r9=0000000000000008 r10=0000000000000018
r11=fffff88008e98b40 r12=000000000021fd30 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!RtlCompareUnicodeString+0xb:
fffff800`04567013 0fb711          movzx   edx,word ptr [rcx] ds:002b:00000000`003f0000=????

We can see a movzx instruction occurred (move with zero extend) which moves a byte value to a word value.

It moved the contents from the edx register to the rcx register, this results in a memory write to 0x3f0000,

 

Because of the conistency we can see a bad instruction pointer being used by a program.

fffff880`08e98b20 fffff880`0447831a : 00000000`012789f0 00000000`00000000 00000000`20786e53 00000000`0021fd30 : nt!RtlCompareUnicodeString+0xb
fffff880`08e98b60 00000000`012789f0 : 00000000`00000000 00000000`20786e53 00000000`0021fd30 00000000`00000000 : aswSnx+0x2c31a
fffff880`08e98b68 00000000`00000000 : 00000000`20786e53 00000000`0021fd30 00000000`00000000 00000000`00000004 : 0x12789f0

Avast is causing the problems here, although you said you removed it.

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffffa80040e09d0, the pool entry being checked.
Arg3: f2fffa80040e09d0, the read back flink freelist value (should be the same as 2).
Arg4: f2fffa80040e09d0, the read back blink freelist value (should be the same as 2).

It's causing corruption in the pool freelist, I believe it's caused when a driver doesn't free the pool properly and caused an inconsistency within the linked list that tracks all free pages.

 

 

Download and run the removal tool from here:

 

http://www.avast.com/en-gb/uninstall-utility

 

I've just checked your other dump files and I they seem to be a similar cause.

igdkmd64	fffff880`05811000	fffff880`063cf160	Wed Jan 30 23:37:23 2013 (5109aeb3)	00bc4413		igdkmd64.sys

Your display driver is outdated, it seems to be the cause of one of the bugchecks.

STACK_TEXT:  
fffff880`0356af58 fffff880`01419f15 : 00000000`00000024 00000000`000c08a5 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`0356af60 fffff880`01419b68 : 00000001`00000000 00000000`00000000 00000000`00000000 00000250`00000000 : Ntfs!NtfsPagingFileIo+0x155
fffff880`0356b060 fffff880`01349bcf : fffffa80`08152fb8 fffffa80`08152c60 fffffa80`083b2850 00000000`00000001 : Ntfs! ?? ::FNODOBFM::`string'+0x7d59
fffff880`0356b110 fffff880`013486df : fffffa80`07033a30 fffffa80`08a0e701 fffffa80`07033a00 fffffa80`08152c60 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`0356b1a0 fffff800`042b4e15 : fffffa80`08152c80 fffffa80`074c9ca0 fffffa80`08b0a820 fffff880`009e9180 : fltmgr!FltpDispatch+0xcf
fffff880`0356b200 fffff800`042b48e9 : 00000000`00000000 00000000`00000000 fffffa80`08b0a760 fffffa80`08b0a760 : nt!IoPageRead+0x255
fffff880`0356b290 fffff800`0429b28a : 00000000`00000000 00000000`00000000 ffffffff`ffffffff 00000000`00000000 : nt!MiIssueHardFault+0x255
fffff880`0356b360 fffff800`0428bcee : 00000000`00000000 00000000`2abf7000 00000000`00000000 ffffffff`ffffffff : nt!MmAccessFault+0x146a
fffff880`0356b4c0 fffff800`042a9798 : fffff8a0`00000000 00000000`000019c0 00000000`00000000 fffff800`043c1e80 : nt!KiPageFault+0x16e
fffff880`0356b650 fffff880`04b5cba1 : fffffa80`04a4f000 00000000`00000000 fffff880`00000002 00000000`2aa00000 : nt!MmProbeAndLockPages+0x118
fffff880`0356b760 fffff880`04b5bd0d : fffffa80`08a0e380 fffff8a0`1166e010 fffffa80`00000178 00000000`00331000 : dxgmms1!VIDMM_SEGMENT::SafeProbeAndLockPages+0x229
fffff880`0356b7f0 fffff880`04b567d8 : fffff8a0`1166e010 fffff8a0`1166e010 fffffa80`00000000 00000000`0000003f : dxgmms1!VIDMM_SEGMENT::LockAllocationBackingStore+0x8d
fffff880`0356b860 fffff880`04b4ac2b : fffffa80`08a622a0 fffffa80`08a1e000 fffffa80`08a1e000 fffff880`04b4a820 : dxgmms1!VIDMM_APERTURE_SEGMENT::CommitResource+0x1c4
fffff880`0356b8b0 fffff880`04b47887 : 00000000`00000000 fffffa80`0924e000 00000000`00000000 fffffa80`04320690 : dxgmms1!VIDMM_GLOBAL::PageInAllocations+0xbb
fffff880`0356b910 fffff880`04b617d9 : 00000000`00000000 fffff8a0`0d66d010 fffffa80`00000000 fffffa80`04ab2770 : dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+0xccf
fffff880`0356bae0 fffff880`04b61514 : fffff880`031d7f40 fffff880`04b60f00 fffffa80`00000000 fffffa80`00000000 : dxgmms1!VidSchiSubmitRenderCommand+0x241
fffff880`0356bcd0 fffff880`04b61012 : 00000000`00000000 fffffa80`095d8760 00000000`00000080 fffffa80`089f2010 : dxgmms1!VidSchiSubmitQueueCommand+0x50
fffff880`0356bd00 fffff800`0452973a : 00000000`02da5965 fffffa80`08a0e760 fffffa80`04151040 fffffa80`08a0e760 : dxgmms1!VidSchiWorkerThread+0xd6
fffff880`0356bd40 fffff800`0427e8e6 : fffff880`031d3180 fffffa80`08a0e760 fffff880`031ddfc0 fffff880`0356be40 : nt!PspSystemThreadStartup+0x5a
fffff880`0356bd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16

A lot of DirectXMMS routines, it seems to be trying to lock the wrong pages into memory which can be caused by a bad instruction pointer.

An update to your display driver should solve that.

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffa800bd6f010, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
	bit 0 : value 0 = read operation, 1 = write operation
	bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80004380cb6, address which referenced memory

Here we have our IRQL too high when accessing pageable or invalid memory.

fffff880`08bd8f38 fffff800`042c3169 : 00000000`0000000a fffffa80`0bd6f010 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`08bd8f40 fffff800`042c1de0 : 00000000`00000008 fffff880`08bd9100 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`08bd9080 fffff800`04380cb6 : 00000000`00000000 00000000`00000000 fffffa80`0734ed00 00000000`00000000 : nt!KiPageFault+0x260
fffff880`08bd9210 fffff800`0433a3bc : 25000000`00000000 fffff680`00135000 fffff680`00135000 000fffff`00000005 : nt!MiReleaseConfirmedPageFileSpace+0x86
fffff880`08bd9290 fffff800`042b0142 : 000007fe`00000001 00000000`0000acb8 fffffa80`08b608d0 fffffa80`08b60c68 : nt! ?? ::FNODOBFM::`string'+0x3ad16
fffff880`08bd9b20 fffff800`042c2e53 : ffffffff`ffffffff 00000000`038bf118 00000000`038bf110 00000000`00004000 : nt!NtFreeVirtualMemory+0x382
fffff880`08bd9c20 00000000`770e149a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`038bf0d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x770e149a

So an attempt to release pages within the page file occurred when the IRQL was at DPC/Dispatch level, this incurred a page fault and hence the bugcheck.

 

Looking further into your loaded modules I see you have Super Antispyware on your computer as well, this with Avast is a big no no.

You cannot have more than one AV on your PC at once.

 

In fact you have at least 3, Rapport Trusteer internet security,

 

Remove all anti virus software and replace it with Microsoft Security Essentials and we'll go from there.

 

http://windows.microsoft.com/en-GB/windows/security-essentials-download



#8 rockysosua

rockysosua

  • Members
  • 772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Caribbean
  • Local time:03:57 AM

Posted 06 September 2014 - 05:32 PM

Superantispyware is a malware scanner program, not AV.

As much as I hate the Rapport/Trusteer program for the resources that it hogs and the inability to turn it off when you don't need it, the fact remains that my clients insist on keeping it, as they are obliged to have it by certain banking houses, otherwise they cannot make transactions.


All is well in Paradise.

#9 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 06 September 2014 - 05:36 PM

Ah yes, sorry about that.
The OP still remove it for testing purposes.

#10 prawnking

prawnking
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 06 September 2014 - 05:39 PM

Brilliant Jared44, thanks for looking into that, I'll get on with all that straight away.

 

One thing, hate to ask, but when you say 'An update to your display driver should solve that', what exactly do you mean by 'display driver'? Is it my graphics driver? Sorry, I'm a bit crap with this kind of thing!



#11 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 06 September 2014 - 05:40 PM

It's alright.
That's exactly what I mean.

#12 prawnking

prawnking
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 06 September 2014 - 06:31 PM

Done everything suggested: only got MSE as my antivirus/security program, checked my graphics driver and I have the latest version possible for my computer, made sure Avast was completely removed, rebooted and when I started up IE I blue screened with a code 24!

 

I've attached the minidump file from that on the OneDrive link above.

 

Any further help is appreciated!



#13 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 07 September 2014 - 05:02 AM

We have a 0x24 bugcheck again which isn't showing much.

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88007edaa38
Arg3: fffff88007eda290
Arg4: fffff800043b9147

So lets look at the context record for the instruction that caused the crash.

2: kd> .cxr 0xfffff88007eda290;r
rax=d3fff8a00d596b40 rbx=fffffa80040e2b00 rcx=fffff8a00d592b40
rdx=0000000000000004 rsi=000000000000004d rdi=0000000000000011
rip=fffff800043b9147 rsp=fffff88007edac70 rbp=0000000000001000
 r8=0000000000000001  r9=fffffa80040e2b00 r10=fffffa80040e2508
r11=0000000000000004 r12=fffffa80040e2500 r13=0000000000000000
r14=fffffa8008c96060 r15=000000006666744e
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
nt!ExAllocatePoolWithTag+0x537:
fffff800`043b9147 48895808        mov     qword ptr [rax+8],rbx ds:002b:d3fff8a0`0d596b48=????????????????

We just have a move instruction from rbx to an address calculated by adding the contents of the rax register with 8.

This results in a memory write to d3fff8a0`0d596b48

2: kd> !pte d3fff8a0`0d596b48
                                           VA d3fff8a00d596b48
PXE at FFFFF6FB7DBEDF88    PPE at FFFFF6FB7DBF1400    PDE at FFFFF6FB7E280350    PTE at FFFFF6FC5006ACB0
Unable to get PXE FFFFF6FB7DBEDF88
WARNING: noncanonical VA, accesses will fault !

So we tried to allocate memory at an address which is reserved, any accessing of this address will fail.

This is most likely a driver using bad pointers.

 

Could I have a Kernel memory dump as this minidump file isn't showing much.

 

Go the Start
Right click My Computer
Select Properties
Click Advanced system settings
Click on the Advanced tab
Select Settings under Startup and Recovery
Then under Write debugging information select Kernel memory dump.

Once a dump is created go to:
 

C:/Windows/memory.dmp

Copy the file to the desktop, zip it up and upload it to a file sharing site like Onedrive. After the upload is done post the download link in your next reply.


Edited by Jared44, 07 September 2014 - 05:03 AM.


#14 hamluis

hamluis

    Moderator


  • Moderator
  • 55,405 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:02:57 AM

Posted 07 September 2014 - 10:03 AM

STOP 24 Error

 

These errors are not that straightforward...the problem may be the file named itself...or the NTFS file system...or the hard drive.

 

Assuming the most easily corrected...try running the chkdsk /r command from the command prompt.

 

Chkdsk From Command Prompt, Win 7 - http://www.bleepingcomputer.com/forums/t/496613/contextmenu-is-causing-explorerexe-to-crash/?p=3067880

 

If the chkdsk /r cannot complete and displays an onscreen error message indicating that it cannot overcome whatever is wrong...then we move on to the other possibilities.

 

Louis



#15 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:07:57 AM

Posted 07 September 2014 - 10:06 AM

I have a very strong idea on what the cause is but I'd like some more information as I normally don't like to ask people to uninstall lots of programs until the problem is resolved.

It's not really troubleshooting...

 

Alright the anti virus programs were an exception as they can conflict and even cause problems on their own.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users