Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Frequent BSOD Error


  • Please log in to reply
15 replies to this topic

#1 johueshua

johueshua

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 02:26 PM

Hello,

 

I've been having frequent BSOD Errors on my PC that I build about 7 months ago. Is there anyway to check if their is a defective component in my system? Or uninstalled driver?

 

speccy:

http://speccy.piriform.com/results/VGguSTUPm51zornnoVz4TIc

 

minidump files:

https://www.sendspace.com/file/gucpsb

 

Thank you,

johueshua

 



BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 56,395 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:09:14 PM

Posted 23 September 2014 - 04:19 PM

Please download MiniToolBox  , save it to your desktop and run it.
 
Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory size.
 
Click Go and paste the content into your next post.
 

Louis



#3 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 04:56 PM

 

MiniToolBox by Farbar  Version: 21-07-2014
Ran by Joshua (administrator) on 23-09-2014 at 17:56:49
Running from "C:\Users\Joshua\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (09/23/2014 02:17:12 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (09/23/2014 00:55:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/23/2014 00:10:58 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (09/23/2014 11:48:17 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/22/2014 05:25:19 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (09/22/2014 05:25:18 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (09/22/2014 04:23:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 03:44:52 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 03:22:47 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 02:15:53 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005


System errors:
=============
Error: (09/23/2014 00:53:30 PM) (Source: BugCheck) (User: )
Description: 0x0000007e (0xffffffffc0000005, 0xfffff8000368425b, 0xfffff88003dd37c8, 0xfffff88003dd3020)C:\Windows\MEMORY.DMP092314-23790-01

Error: (09/23/2014 00:53:29 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 12:51:30 PM on ‎9/‎23/‎2014 was unexpected.

Error: (09/21/2014 03:43:17 PM) (Source: BugCheck) (User: )
Description: 0x0000003b (0x00000000c0000005, 0xfffff800039d2b0f, 0xfffff8800a8a0970, 0x0000000000000000)C:\Windows\MEMORY.DMP092114-23899-01

Error: (09/21/2014 03:43:16 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 3:42:01 PM on ‎9/‎21/‎2014 was unexpected.

Error: (09/21/2014 03:23:18 PM) (Source: Service Control Manager) (User: )
Description: The Symantec Iron Driver service failed to start due to the following error:
%%31

Error: (09/21/2014 03:21:12 PM) (Source: BugCheck) (User: )
Description: 0x00000019 (0x0000000000000020, 0xfffff8a01de02c50, 0xfffff8a01de02eb0, 0x0000000005260206)C:\Windows\MEMORY.DMP092114-23868-01

Error: (09/21/2014 03:21:11 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 3:19:09 PM on ‎9/‎21/‎2014 was unexpected.

Error: (09/20/2014 09:17:02 PM) (Source: BugCheck) (User: )
Description: 0x0000001e (0xffffffffc0000005, 0xfffff9600010db41, 0x0000000000000000, 0xffffffffffffffff)C:\Windows\MEMORY.DMP092014-22167-01

Error: (09/20/2014 09:17:01 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 9:15:13 PM on ‎9/‎20/‎2014 was unexpected.

Error: (09/18/2014 06:58:54 PM) (Source: Tcpip) (User: )
Description: The system detected an address conflict for IP address 0.0.0.0 with the system
having network hardware address 88-43-E1-CA-FB-7F. Network operations on this system may
be disrupted as a result.


Microsoft Office Sessions:
=========================
Error: (09/23/2014 02:17:12 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (09/23/2014 00:55:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/23/2014 00:10:58 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (09/23/2014 11:48:17 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/22/2014 05:25:19 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (09/22/2014 05:25:18 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (09/22/2014 04:23:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 03:44:52 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 03:22:47 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/21/2014 02:15:53 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005



=========================== Installed Programs ============================
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.0.8.4990 - Adobe Systems Inc.) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version:  - Amazon)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.2.8.000 - Asmedia Technology)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock eXtreme Tuner v0.1.337.3 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version:  - )
ASRock InstantBoot v1.29 (HKLM-x32\...\ASRock InstantBoot_is1) (Version:  - )
ASRock XFast RAM v2.0.28 (HKLM\...\ASRock XFast RAM_is1) (Version:  - ASRock Inc.)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4765 - AVG Technologies)
AVG 2014 (Version: 14.0.4025 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4765 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 3.2.0.15 - AVG Technologies)
Broadcom NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.5.1 - Broadcom Corporation)
calibre (HKLM-x32\...\{AB116F72-C91A-40F2-A25A-949B5D065EBB}) (Version: 2.3.0 - Kovid Goyal)
CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1611_37043 - CyberLink Corp.)
CyberLink MediaEspresso (x32 Version: 6.5.1611_37043 - CyberLink Corp.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel® Rapid Storage Technology enterprise (HKLM-x32\...\{8B313BF5-9BD5-42a3-94C1-A28AF3AA51CC}) (Version: 3.5.0.1092 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.0) (Version: 3.0.0 - Riot Games)
League of Legends (x32 Version: 3.0.0 - Riot Games) Hidden
MATLAB R2014a (HKLM\...\Matlab R2014a) (Version: 8.3 - The MathWorks, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (Version: 2.3.188.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 32.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 32.0.2 (x86 en-US)) (Version: 32.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.5.0.28 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Control Panel 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 2.1.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.160.1244 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Update 15.3.36 (Version: 15.3.36 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 15.3.36 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden
Python 2.7.8 (HKLM-x32\...\{61121B12-88BD-4261-A6EE-AB32610A56DD}) (Version: 2.7.8150 - Python Software Foundation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6468 - Realtek Semiconductor Corp.)
SecureW2 Enterprise Client 3.5.12 (HKLM-x32\...\SecureW2 Enterprise Client) (Version:  - )
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.26 - Piriform)
Spotify (HKCU\...\Spotify) (Version: 0.9.13.24.g5dbb3103 - Spotify AB)
TI USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{3AF095EF-23B3-4C6A-BBA1-4C1EB663DAF8}) (Version: 1.12.9.0 - Texas Instruments Inc.)
TI USB3 Host Driver (x32 Version: 1.12.9.0 - Texas Instruments Inc.) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows 7 Upgrade Advisor (HKLM-x32\...\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
XFast LAN v6.61 (HKLM\...\XFast LAN) (Version: 6.61 - cFos Software GmbH, Bonn)
XFastUSB (HKLM-x32\...\XFastUSB) (Version: 3.02.31 - ASRock Inc.)

========================= Memory info: ===================================

Percentage of memory in use: 37%
Total physical RAM: 16384 MB
Available physical RAM: 10311.2 MB
Total Pagefile: 32766.18 MB
Available Pagefile: 26686.57 MB
Total Virtual: 4095.88 MB
Available Virtual: 3985.01 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:232.37 GB) (Free:141.83 GB) NTFS
2 Drive d: (13-881-99-1) (CDROM) (Total:1.29 GB) (Free:0 GB) CDFS
3 Drive e: (New Volume) (Fixed) (Total:931.51 GB) (Free:927.84 GB) NTFS

========================= Users: ========================================

User accounts for \\JOSHUA-PC

Administrator            Guest                    Joshua                   


**** End of log ****
 



#4 hamluis

hamluis

    Moderator


  • Moderator
  • 56,395 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:09:14 PM

Posted 23 September 2014 - 06:23 PM

You reflect both NIS and AVG 2014 as installs, this has been known to result in system problems.

 

I suggest removing one or the other, all components.  I would also uninstall AVG Web Tuneup since this is an optimizer program and is a beta (not-ready-for-primetime) version.

 

I would then run the chkdsk /r command

 

SecureW2 appears to be a product not designed for consumer or free use, IMO. 

 

Louis



#5 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 07:15 PM

Thank you for your reply. But I do have a question: What is NIS?



#6 sflatechguy

sflatechguy

  • BC Advisor
  • 2,255 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:14 PM

Posted 23 September 2014 - 07:45 PM

You've had blue screens indicating there may be hardware incompatibilities or faulty drivers (0x1E), another indicating a faulty driver (0x19), a third that could be the result of your graphics driver passing corrupt data to the kernel (0x3B), and another that could be either faulty hardware, faulty drivers, problems with the video card or even BIOS issues (0x7E).

http://msdn.microsoft.com/en-us/library/windows/hardware/ff557408%28v=vs.85%29.aspx

http://msdn.microsoft.com/en-us/library/windows/hardware/ff557389%28v=vs.85%29.aspx

http://msdn.microsoft.com/en-us/library/windows/hardware/ff558949%28v=vs.85%29.aspx

http://msdn.microsoft.com/en-us/library/windows/hardware/ff559239%28v=vs.85%29.aspx

 

You've zipped the minidumps, but it would be more convenient (and safer -- I'm not a big fan of downloading .zip files from folks I don't exactly know) if you could run those minidumps through Blue Screen View or Debugging Tools for Windows, and copy and paste those reports here. That would help to pinpoint the hardware and/or drivers that are causing the issues. A third alternative is to upload the minidumps to this website http://www.osronline.com/page.cfm?name=analyze , and then copy and paste the reports here.



#7 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 07:55 PM

 

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`03c18000 PsLoadedModuleList = 0xfffff800`03e5b890
Debug session time: Sat Aug 30 22:43:31.340 2014 (UTC - 4:00)
System Uptime: 0 days 7:13:32.183
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffffffffffff0, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffffa8014699360, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000000, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80003ec5100
GetUlongFromAddress: unable to read from fffff80003ec51c0
fffffffffffffff0

FAULTING_IP:
+0
fffffa80`14699360 0850f0 or byte ptr [rax-10h],dl

MM_INTERNAL_CODE: 0

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: System

CURRENT_IRQL: 0

TRAP_FRAME: fffff88003f4e7d0 -- (.trap 0xfffff88003f4e7d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8014699000
rdx=0000000000000036 rsi=0000000000000000 rdi=0000000000000000
rip=fffffa8014699360 rsp=fffff88003f4e968 rbp=fffffa800ce31000
r8=0000000000000000 r9=0000000000000000 r10=fffff8800fd7637c
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
fffffa80`14699360 0850f0 or byte ptr [rax-10h],dl ds:ffffffff`fffffff0=??
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80003d0bbf0 to fffff80003c8dbc0

STACK_TEXT:
fffff880`03f4e668 fffff800`03d0bbf0 : 00000000`00000050 ffffffff`fffffff0 00000000`00000001 fffff880`03f4e7d0 : nt!KeBugCheckEx
fffff880`03f4e670 fffff800`03c8bcee : 00000000`00000001 ffffffff`fffffff0 fffff880`03f4e800 fffff880`03f4e9f0 : nt! ?? ::FNODOBFM::`string'+0x4518f
fffff880`03f4e7d0 fffffa80`14699360 : fffff880`0fc8b375 fffff880`03f4e9f0 fffffa80`0ce31000 00000000`00000119 : nt!KiPageFault+0x16e
fffff880`03f4e968 fffff880`0fc8b375 : fffff880`03f4e9f0 fffffa80`0ce31000 00000000`00000119 138f5848`0f189300 : 0xfffffa80`14699360
fffff880`03f4e970 fffff880`03f4e9f0 : fffffa80`0ce31000 00000000`00000119 138f5848`0f189300 00000000`00000000 : nvlddmkm+0x22c375
fffff880`03f4e978 fffffa80`0ce31000 : 00000000`00000119 138f5848`0f189300 00000000`00000000 fffff880`0fc8b59e : 0xfffff880`03f4e9f0
fffff880`03f4e980 00000000`00000119 : 138f5848`0f189300 00000000`00000000 fffff880`0fc8b59e fffffa80`14699000 : 0xfffffa80`0ce31000
fffff880`03f4e988 138f5848`0f189300 : 00000000`00000000 fffff880`0fc8b59e fffffa80`14699000 fffffa80`0ce31000 : 0x119
fffff880`03f4e990 00000000`00000000 : fffff880`0fc8b59e fffffa80`14699000 fffffa80`0ce31000 fffff880`0ff034a0 : 0x138f5848`0f189300


STACK_COMMAND: kb

FOLLOWUP_IP:
nvlddmkm+22c375
fffff880`0fc8b375 ?? ???

SYMBOL_STACK_INDEX: 4

SYMBOL_NAME: nvlddmkm+22c375

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nvlddmkm

IMAGE_NAME: nvlddmkm.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 52676afe

FAILURE_BUCKET_ID: X64_0x50_nvlddmkm+22c375

BUCKET_ID: X64_0x50_nvlddmkm+22c375

Followup: MachineOwner
---------



#8 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 07:56 PM

Sorry, I will be posting these seperately!:

 

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`03c5f000 PsLoadedModuleList = 0xfffff800`03ea2890
Debug session time: Sun Aug 31 14:53:50.172 2014 (UTC - 4:00)
System Uptime: 0 days 0:00:44.000
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 0000000000000000, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (Win32) 0 (0) - The operation completed successfully.

FAULTING_IP:
+0
00000000`00000000 ?? ???

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000000000

ERROR_CODE: (NTSTATUS) 0 - STATUS_WAIT_0

BUGCHECK_STR: 0x1e_0

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 2

EXCEPTION_RECORD: fffff80004407168 -- (.exr 0xfffff80004407168)
ExceptionAddress: fffff88001d3706e (NETIO!RtlGetNextExpiredTimerWheelEntry+0x000000000000005e)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

TRAP_FRAME: fffff80004407210 -- (.trap 0xfffff80004407210)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa801396c9e8 rbx=0000000000000000 rcx=000000000000a712
rdx=f7fffa801396c9e8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001d3706e rsp=fffff800044073a8 rbp=00000000000001f4
r8=00000000fffffa24 r9=fffffa801396b000 r10=fffffa801396c9e8
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
NETIO!RtlGetNextExpiredTimerWheelEntry+0x5e:
fffff880`01d3706e 8b4210 mov eax,dword ptr [rdx+10h] ds:f7fffa80`1396c9f8=????????
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80003ccc5be to fffff80003cd4b90

STACK_TEXT:
fffff800`04406248 fffff800`03ccc5be : ffffffff`ffffffff 00000000`0000000e fffff800`044069c0 fffff800`03cffa90 : nt!KeBugCheck
fffff800`04406250 fffff800`03cff75d : fffff800`03ee3380 fffff800`03e20260 fffff800`03c5f000 fffff800`04407168 : nt!KiKernelCalloutExceptionHandler+0xe
fffff800`04406280 fffff800`03cfe535 : fffff800`03e24038 fffff800`044062f8 fffff800`04407168 fffff800`03c5f000 : nt!RtlpExecuteHandlerForException+0xd
fffff800`044062b0 fffff800`03d0f4c1 : fffff800`04407168 fffff800`044069c0 fffff800`00000000 00000000`00000000 : nt!RtlDispatchException+0x415
fffff800`04406990 fffff800`03cd4242 : fffff800`04407168 00000000`0000010e fffff800`04407210 00000000`000003e8 : nt!KiDispatchException+0x135
fffff800`04407030 fffff800`03cd2b4a : fffffa80`16119ac0 fffffa80`14fee050 00000000`77485353 00000000`77485353 : nt!KiExceptionDispatch+0xc2
fffff800`04407210 fffff880`01d3706e : fffff880`020010cc 00000000`0000abe0 fffff780`00000008 00000000`000003e8 : nt!KiGeneralProtectionFault+0x10a
fffff800`044073a8 fffff880`020010cc : 00000000`0000abe0 fffff780`00000008 00000000`000003e8 fffff880`0fa2daae : NETIO!RtlGetNextExpiredTimerWheelEntry+0x5e
fffff800`044073b0 fffff800`03cdf85c : fffff800`04407538 00000000`00000000 00000000`00000002 00000000`00000555 : afd!AfdTimerWheelHandler+0xbc
fffff800`04407430 fffff800`03cdf6f6 : fffff800`03edb900 00000000`00000b04 00000000`00000000 00000000`00000000 : nt!KiProcessTimerDpcTable+0x6c
fffff800`044074a0 fffff800`03cdf5de : 00000000`1a39eea8 fffff800`04407b18 00000000`00000b04 fffff800`03e52308 : nt!KiProcessExpiredTimerList+0xc6
fffff800`04407af0 fffff800`03cdf3c7 : 00000000`084e44c7 00000000`00000b04 00000000`084e4498 00000000`00000004 : nt!KiTimerExpiration+0x1be
fffff800`04407b90 fffff800`03ccc8ca : fffff800`03e4fe80 fffff800`03e5dcc0 00000000`00000001 fffff800`00000000 : nt!KiRetireDpcList+0x277
fffff800`04407c40 00000000`00000000 : fffff800`04408000 fffff800`04402000 fffff800`04407c00 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND: kb

FOLLOWUP_IP:
NETIO!RtlGetNextExpiredTimerWheelEntry+5e
fffff880`01d3706e 8b4210 mov eax,dword ptr [rdx+10h]

SYMBOL_STACK_INDEX: 7

SYMBOL_NAME: NETIO!RtlGetNextExpiredTimerWheelEntry+5e

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: NETIO

IMAGE_NAME: NETIO.SYS

DEBUG_FLR_IMAGE_TIMESTAMP: 5294760d

FAILURE_BUCKET_ID: X64_0x1e_0_NETIO!RtlGetNextExpiredTimerWheelEntry+5e

BUCKET_ID: X64_0x1e_0_NETIO!RtlGetNextExpiredTimerWheelEntry+5e

Followup: MachineOwner
---------



#9 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:00 PM

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`03c0a000 PsLoadedModuleList = 0xfffff800`03e4d890
Debug session time: Tue Sep 2 17:30:46.173 2014 (UTC - 4:00)
System Uptime: 0 days 4:29:02.000
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80003c9b184, The address that the exception occurred at
Arg3: fffff88003d557b8, Exception Record Address
Arg4: fffff88003d55010, Context Record Address

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
nt!KeReleaseSemaphore+94
fffff800`03c9b184 488b6d00 mov rbp,qword ptr [rbp]

EXCEPTION_RECORD: fffff88003d557b8 -- (.exr 0xfffff88003d557b8)
ExceptionAddress: fffff80003c9b184 (nt!KeReleaseSemaphore+0x0000000000000094)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: ffffffffffffffff
Parameter[1]: 0000000000000000
Attempt to execute non-executable address 0000000000000000

CONTEXT: fffff88003d55010 -- (.cxr 0xfffff88003d55010)
rax=0000000000000001 rbx=fffffa8013f1add0 rcx=fffffa8013f1add0
rdx=0000000000000010 rsi=f7fffa8013f1add8 rdi=0000000000000001
rip=fffff80003c9b184 rsp=fffff88003d559f0 rbp=f7fffa8013f1add8
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff88003a5e180 r12=0000000000000000 r13=fffff88003a5e180
r14=0000000000000000 r15=fffffa8013f1add8
iopl=0 nv up ei ng nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010287
nt!KeReleaseSemaphore+0x94:
fffff800`03c9b184 488b6d00 mov rbp,qword ptr [rbp] ss:0018:f7fffa80`13f1add8=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: NULL_DEREFERENCE

PROCESS_NAME: System

CURRENT_IRQL: 2

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

EXCEPTION_PARAMETER1: ffffffffffffffff

EXCEPTION_PARAMETER2: 0000000000000000

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80003eb7100
GetUlongFromAddress: unable to read from fffff80003eb71c0
0000000000000000 Nonpaged pool

FOLLOWUP_IP:
usbhub!Usbh_SSH_HubActive+ca
fffff880`060f759a 488b6c2438 mov rbp,qword ptr [rsp+38h]

BUGCHECK_STR: 0x7E

LAST_CONTROL_TRANSFER: from fffff880060f759a to fffff80003c9b184

STACK_TEXT:
fffff880`03d559f0 fffff880`060f759a : 00000000`00000000 00000000`00000010 fffff880`03a5e180 fffff800`03e25200 : nt!KeReleaseSemaphore+0x94
fffff880`03d55a70 fffff880`060f74ab : 00000000`00000001 00000000`00000001 fffffa80`13f1a050 00000000`00000000 : usbhub!Usbh_SSH_HubActive+0xca
fffff880`03d55aa0 fffff880`060f8375 : fffffa80`13f1a1a0 fffff800`03e252d8 fffffa80`13f1a050 fffffa80`13f1a9c8 : usbhub!Usbh_SSH_Event+0x147
fffff880`03d55ad0 fffff880`060c473f : fffffa80`13f1a1a0 fffffa80`13f1a050 fffffa80`16b67bd0 00000000`00000000 : usbhub!UsbhHubSSH_Worker+0x2d
fffff880`03d55b00 fffff800`03f76c93 : fffffa80`13f1a050 fffffa80`0ce3a660 fffffa80`16b67bd0 fffffa80`0ce3a660 : usbhub!UsbhHubWorker+0x63
fffff880`03d55b40 fffff800`03c89261 : fffff800`03e25200 fffff800`03f76c01 fffffa80`0ce3a600 fffffa80`0ce3a660 : nt!IopProcessWorkItem+0x23
fffff880`03d55b70 fffff800`03f1b73a : 00000000`00000000 fffffa80`0ce3a660 00000000`00000080 fffffa80`0cdff890 : nt!ExpWorkerThread+0x111
fffff880`03d55c00 fffff800`03c708e6 : fffff880`03b42180 fffffa80`0ce3a660 fffff880`03b4d1c0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`03d55c40 00000000`00000000 : fffff880`03d56000 fffff880`03d50000 fffff880`03d558a0 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: usbhub!Usbh_SSH_HubActive+ca

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: usbhub

IMAGE_NAME: usbhub.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 52954dd0

STACK_COMMAND: .cxr 0xfffff88003d55010 ; kb

FAILURE_BUCKET_ID: X64_0x7E_usbhub!Usbh_SSH_HubActive+ca

BUCKET_ID: X64_0x7E_usbhub!Usbh_SSH_HubActive+ca

Followup: MachineOwner
---------



#10 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:02 PM

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`03610000 PsLoadedModuleList = 0xfffff800`03853890
Debug session time: Sat Sep 20 21:15:36.369 2014 (UTC - 4:00)
System Uptime: 0 days 10:43:35.600
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff9600010db41, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
win32k!xxxRealSleepThread+291
fffff960`0010db41 c3 ret

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800038bd100
GetUlongFromAddress: unable to read from fffff800038bd1c0
ffffffffffffffff

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

BUGCHECK_STR: 0x1e_c0000005

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

PROCESS_NAME: LolClient.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff800036d0738 to fffff80003685bc0

CONTEXT: 246c894808245c89 -- (.cxr 0x246c894808245c89)
Unable to read context, Win32 error 0n30

STACK_TEXT:
fffff880`0dcc8ed8 fffff800`036d0738 : 00000000`0000001e ffffffff`c0000005 fffff960`0010db41 00000000`00000000 : nt!KeBugCheckEx
fffff880`0dcc8ee0 fffff800`03685242 : fffff880`0dcc96b8 00000000`000025ff fffff880`0dcc9760 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x487ed
fffff880`0dcc9580 fffff800`03683b4a : 00000000`00000000 fffff880`037e6100 fffff880`037e6180 fffffa80`18d1fc58 : nt!KiExceptionDispatch+0xc2
fffff880`0dcc9760 fffff960`0010db41 : f7fff960`0010dba1 00000000`00000000 00000000`00000000 00000000`00000001 : nt!KiGeneralProtectionFault+0x10a
fffff880`0dcc98f8 f7fff960`0010dba1 : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`00000000 : win32k!xxxRealSleepThread+0x291
fffff880`0dcc9900 00000000`00000000 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : 0xf7fff960`0010dba1


FOLLOWUP_IP:
win32k!xxxRealSleepThread+291
fffff960`0010db41 c3 ret

SYMBOL_STACK_INDEX: 4

SYMBOL_NAME: win32k!xxxRealSleepThread+291

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: win32k

IMAGE_NAME: win32k.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 53f7e73f

STACK_COMMAND: .cxr 0x246c894808245c89 ; kb

FAILURE_BUCKET_ID: X64_0x1e_c0000005_win32k!xxxRealSleepThread+291

BUCKET_ID: X64_0x1e_c0000005_win32k!xxxRealSleepThread+291

Followup: MachineOwner



#11 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:03 PM

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`0365a000 PsLoadedModuleList = 0xfffff800`0389d890
Debug session time: Sun Sep 21 15:20:06.388 2014 (UTC - 4:00)
System Uptime: 0 days 2:59:09.620
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000020, a pool block header size is corrupt.
Arg2: fffff8a01de02c50, The pool entry we were looking for within the page.
Arg3: fffff8a01de02eb0, The next pool entry.
Arg4: 0000000005260206, (reserved)

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

BUGCHECK_STR: 0x19_20

POOL_ADDRESS: GetPointerFromAddress: unable to read from fffff80003907100
GetUlongFromAddress: unable to read from fffff800039071c0
fffff8a01de02c50 Paged pool

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

PROCESS_NAME: NvBackend.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff80003802cae to fffff800036cfbc0

STACK_TEXT:
fffff880`04f7a678 fffff800`03802cae : 00000000`00000019 00000000`00000020 fffff8a0`1de02c50 fffff8a0`1de02eb0 : nt!KeBugCheckEx
fffff880`04f7a680 fffff880`104f9523 : fffff8a0`1de02c60 00000000`00000000 fffff880`4b677844 00000000`00000003 : nt!ExDeferredFreePool+0x12da
fffff880`04f7a730 fffff960`001a22f2 : 00000000`3c010834 fffffa80`1483db50 00000000`7efaa000 00000000`00000020 : dxgkrnl!DxgkEscape+0xc3f
fffff880`04f7aab0 fffff800`036cee53 : fffffa80`1483db50 fffff880`00000000 00000000`00000000 00000000`00000000 : win32k!NtGdiDdDDIEscape+0x12
fffff880`04f7aae0 00000000`7559148a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0275e728 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7559148a


STACK_COMMAND: kb

FOLLOWUP_IP:
dxgkrnl!DxgkEscape+c3f
fffff880`104f9523 488d8c24a0000000 lea rcx,[rsp+0A0h]

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: dxgkrnl!DxgkEscape+c3f

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: dxgkrnl

IMAGE_NAME: dxgkrnl.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 539e411c

FAILURE_BUCKET_ID: X64_0x19_20_dxgkrnl!DxgkEscape+c3f

BUCKET_ID: X64_0x19_20_dxgkrnl!DxgkEscape+c3f

Followup: MachineOwner
---------



#12 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:05 PM

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`03666000 PsLoadedModuleList = 0xfffff800`038a9890
Debug session time: Sun Sep 21 15:42:13.628 2014 (UTC - 4:00)
System Uptime: 0 days 0:21:26.456
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800039d2b0f, Address of the instruction which caused the bugcheck
Arg3: fffff8800a8a0970, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
nt!ObpWaitForMultipleObjects+379
fffff800`039d2b0f 41ff401c inc dword ptr [r8+1Ch]

CONTEXT: fffff8800a8a0970 -- (.cxr 0xfffff8800a8a0970)
rax=0000000000000001 rbx=fffff8800a8a15e0 rcx=fffffa8016c3acd0
rdx=0000000000000000 rsi=0000000000000000 rdi=000000000000000b
rip=fffff800039d2b0f rsp=fffff8800a8a1350 rbp=fffff8800a8a1b60
r8=f7fffa800ce72c40 r9=0000000000000000 r10=fffffffffffffeff
r11=0000000000000246 r12=fffffa8014c40630 r13=fffff8a01066df20
r14=000000000000000c r15=000000000000000c
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!ObpWaitForMultipleObjects+0x379:
fffff800`039d2b0f 41ff401c inc dword ptr [r8+1Ch] ds:002b:f7fffa80`0ce72c5c=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

BUGCHECK_STR: 0x3B

PROCESS_NAME: FlashPlayerPlu

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800039d2b0f

STACK_TEXT:
fffff880`0a8a1350 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpWaitForMultipleObjects+0x379


FOLLOWUP_IP:
nt!ObpWaitForMultipleObjects+379
fffff800`039d2b0f 41ff401c inc dword ptr [r8+1Ch]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ObpWaitForMultipleObjects+379

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 531590fb

STACK_COMMAND: .cxr 0xfffff8800a8a0970 ; kb

FAILURE_BUCKET_ID: X64_0x3B_nt!ObpWaitForMultipleObjects+379

BUCKET_ID: X64_0x3B_nt!ObpWaitForMultipleObjects+379

Followup: MachineOwner



#13 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:08 PM

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`0361a000 PsLoadedModuleList = 0xfffff800`0385d890
Debug session time: Tue Sep 23 12:52:29.572 2014 (UTC - 4:00)
System Uptime: 0 days 1:06:12.400
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000368425b, The address that the exception occurred at
Arg3: fffff88003dd37c8, Exception Record Address
Arg4: fffff88003dd3020, Context Record Address

Debugging Details:
------------------

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
nt!ExpScanGeneralLookasideList+a0
fffff800`0368425b 418b40d8 mov eax,dword ptr [r8-28h]

EXCEPTION_RECORD: fffff88003dd37c8 -- (.exr 0xfffff88003dd37c8)
ExceptionAddress: fffff8000368425b (nt!ExpScanGeneralLookasideList+0x00000000000000a0)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: fffff88003dd3020 -- (.cxr 0xfffff88003dd3020)
rax=0000000000000005 rbx=fffff80003835440 rcx=0000000000000000
rdx=0000000000000000 rsi=fffffa800cdfe890 rdi=000000000000ffff
rip=fffff8000368425b rsp=fffff88003dd3a00 rbp=0000000000000001
r8=f7fff88002012440 r9=0000000000000004 r10=0000000000000000
r11=0000000000000100 r12=0000000000000000 r13=fffff80003835430
r14=0000000000000000 r15=fffff880037eb140
iopl=0 nv up ei ng nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010287
nt!ExpScanGeneralLookasideList+0xa0:
fffff800`0368425b 418b40d8 mov eax,dword ptr [r8-28h] ds:002b:f7fff880`02012418=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 2

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800038c7100
GetUlongFromAddress: unable to read from fffff800038c71c0
ffffffffffffffff

FOLLOWUP_IP:
nt!ExpScanGeneralLookasideList+a0
fffff800`0368425b 418b40d8 mov eax,dword ptr [r8-28h]

BUGCHECK_STR: 0x7E

LAST_CONTROL_TRANSFER: from fffff80003679a60 to fffff8000368425b

STACK_TEXT:
fffff880`03dd3a00 fffff800`03679a60 : 00000000`00000001 00000000`00000008 00000000`00000001 fffff800`038c7c40 : nt!ExpScanGeneralLookasideList+0xa0
fffff880`03dd3a60 fffff800`03679fae : 00000000`00000008 fffff880`03dd3ad0 00000000`00000001 fffffa80`00000000 : nt!ExAdjustLookasideDepth+0x40
fffff880`03dd3a90 fffff800`0392b73a : fffffa80`0ce4d750 00000000`00000080 fffffa80`0cdfe890 00000000`00000001 : nt!KeBalanceSetManager+0x1be
fffff880`03dd3c00 fffff800`036808e6 : fffff880`037e6180 fffffa80`0ce4d750 fffff880`037f11c0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`03dd3c40 00000000`00000000 : fffff880`03dd4000 fffff880`03dce000 fffff880`03dd35c0 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExpScanGeneralLookasideList+a0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 531590fb

STACK_COMMAND: .cxr 0xfffff88003dd3020 ; kb

FAILURE_BUCKET_ID: X64_0x7E_nt!ExpScanGeneralLookasideList+a0

BUCKET_ID: X64_0x7E_nt!ExpScanGeneralLookasideList+a0

Followup: MachineOwner



#14 sflatechguy

sflatechguy

  • BC Advisor
  • 2,255 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:14 PM

Posted 23 September 2014 - 08:35 PM

There are numerous issues with your graphics drivers and applications: nvlddmkm.sys is the Nvidia display driver; netio.sys is the Nvidia network access manager program; and the NvBackend.exe program, another Nvidia driver, is causing the dxgkrnl.sys graphics kernel subsystem to crash. You may want to reinstall the Nvidia driver and other Nvidia programs you have installed.

 

The usbhub.sys is the system driver for your USB ports. Try running sfc /scannow to address that issue, and make sure your Windows Updates are up to date.

 

It appears your League of Legends installation (LoLclient.exe) is causing issues, as is your Flash player. Uninstall and reinstall them.

 

That final minidump isn't giving us much info as to what caused that particular blue screen, other than that it happened at the kernel level. We may have to come back and revisit that one later.

 

Report back if there are other issues.



#15 johueshua

johueshua
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 23 September 2014 - 08:53 PM

Ok, will do. I've been flooded with assignments so I will get back to reinstalling these drivers and applications later in the week. I will keep this posted if anything does come up. Also I have already ran sfc /scannow and no errors showed up.

 

Thank you






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users