Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

BSOD RTWLANE.SYS WINDOWS 8.1 BRAND NEW HELP


  • Please log in to reply
9 replies to this topic

#1 MikeHunt

MikeHunt

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 03 October 2014 - 07:12 PM

Ive seen some posts all with different answers. Help me fix this please. 

crashes when goes into hibernate mode and comes back on with non paged errror rtwlane.sys

 

tell me what you need to see from the event viewer and ill post it here thank you..

 



BC AdBot (Login to Remove)

 


#2 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 03 October 2014 - 07:28 PM

am i looking for warnings or errors

cant open the minidmp file. tried take ownership. still access denied. I am the admin. 

finally got access to the garbage after all the mis information on the net. 

for everyone else. 

JUST OPEN THE YOUR C: WINDOWS/ MINIDMP/ RIGHT CLICK ON YOUR LATEST MINI DMP FILE, PROPERTIES/ ADVANCED 

CHANGE/ SELECT PRINCIPLE AT THE TOP/ THEN ADD YOUR USERNAME / FOR YOUR COMPUTER. IF YOU NAMED IT/ THEN APPLY ETC. HOPEFULLY THIS WILL SAVE YOU TONS OF TIME. 

 
Use !analyze -v to get detailed debugging information.
 
BugCheck 50, {ffffe001cf400960, 0, fffff80043b66323, 2}
 
*** WARNING: Unable to verify timestamp for rtwlane.sys
*** ERROR: Module load completed but symbols could not be loaded for rtwlane.sys
 
Could not read faulting driver name
Probably caused by : rtwlane.sys ( rtwlane+114323 )
 
Followup: MachineOwner
---------

Edited by MikeHunt, 03 October 2014 - 09:35 PM.


#3 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:10:49 AM

Posted 04 October 2014 - 04:45 AM

Can you upload the dump files for analysis.

Go to

C:\Windows\minidump

Upload all those files by copying (Make sure you copy the files otherwise you will get access denied, even if you're an administrator) them to the desktop and compressing them in a single .zip folder.

Or even better, upload a Kernel memory dump.

Go the Start
Right click My Computer
Select Properties
Click Advanced system settings
Click on the Advanced tab
Select Settings under Startup and Recovery
Then under Write debugging information select Kernel memory dump.

Once a dump is created go to:

C:\Windows\memory.dmp

Copy the file to the desktop, zip it up and upload it to a file sharing site like Onedrive. After the upload is done post the download link in your next reply.

#4 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 04 October 2014 - 09:30 AM

OK It came back so i got the kernel zipped up. See what you can do with this

 

thanks for your help. 

https://onedrive.live.com/redir?resid=F988B2B42A55729B!149&authkey=!AGgaobKb58zUdQs&ithint=file%2czip


Edited by MikeHunt, 04 October 2014 - 10:58 AM.


#5 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 04 October 2014 - 11:31 AM

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffe0007b800960, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800b5bbe323, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
 
Debugging Details:
------------------
 
 
Could not read faulting driver name
 
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff8026a571138
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSizeOfNonPagedPoolInBytes
 ffffe0007b800960 
 
FAULTING_IP: 
rtwlane+114323
fffff800`b5bbe323 440fb78860090000 movzx   r9d,word ptr [rax+960h]
 
MM_INTERNAL_CODE:  2
 
CUSTOMER_CRASH_COUNT:  1
 
DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
 
BUGCHECK_STR:  AV
 
PROCESS_NAME:  System
 
CURRENT_IRQL:  0
 
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre
 
TRAP_FRAME:  ffffd0009c145860 -- (.trap 0xffffd0009c145860)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe0007b800000 rbx=0000000000000000 rcx=fffff800b5dcec20
rdx=ffffe0007f600002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800b5bbe323 rsp=ffffd0009c1459f0 rbp=ffffd0009c145a50
 r8=ffffe0007f600001  r9=ffffe0007960d4c0 r10=0000000000000001
r11=ffffd0009c1459e8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
rtwlane+0x114323:
fffff800`b5bbe323 440fb78860090000 movzx   r9d,word ptr [rax+960h] ds:ffffe000`7b800960=????
Resetting default scope
 
LAST_CONTROL_TRANSFER:  from fffff8026a3a224a to fffff8026a370fa0
 
STACK_TEXT:  
ffffd000`9c145678 fffff802`6a3a224a : 00000000`00000050 ffffe000`7b800960 00000000`00000000 ffffd000`9c145860 : nt!KeBugCheckEx
ffffd000`9c145680 fffff802`6a2849c9 : 00000000`00000000 ffffe000`7acb4880 ffffd000`9c145860 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x20d9a
ffffd000`9c145720 fffff802`6a37b22f : 00000000`00000000 00000000`00000000 00000000`00000000 ffffd000`9c145860 : nt!MmAccessFault+0x7a9
ffffd000`9c145860 fffff800`b5bbe323 : ffffe000`7f200000 00000000`00000001 ffffd000`9c145a50 ffffe000`7f200000 : nt!KiPageFault+0x12f
ffffd000`9c1459f0 ffffe000`7f200000 : 00000000`00000001 ffffd000`9c145a50 ffffe000`7f200000 00000000`00000000 : rtwlane+0x114323
ffffd000`9c1459f8 00000000`00000001 : ffffd000`9c145a50 ffffe000`7f200000 00000000`00000000 fffff800`b5bf2f16 : 0xffffe000`7f200000
ffffd000`9c145a00 ffffd000`9c145a50 : ffffe000`7f200000 00000000`00000000 fffff800`b5bf2f16 00000000`00000000 : 0x1
ffffd000`9c145a08 ffffe000`7f200000 : 00000000`00000000 fffff800`b5bf2f16 00000000`00000000 ffffe000`7a0d2004 : 0xffffd000`9c145a50
ffffd000`9c145a10 00000000`00000000 : fffff800`b5bf2f16 00000000`00000000 ffffe000`7a0d2004 ffffe000`7a0d2004 : 0xffffe000`7f200000
 
 
STACK_COMMAND:  kb
 
FOLLOWUP_IP: 
rtwlane+114323
fffff800`b5bbe323 440fb78860090000 movzx   r9d,word ptr [rax+960h]
 
SYMBOL_STACK_INDEX:  4
 
SYMBOL_NAME:  rtwlane+114323
 
FOLLOWUP_NAME:  MachineOwner
 
MODULE_NAME: rtwlane
 
IMAGE_NAME:  rtwlane.sys
 
DEBUG_FLR_IMAGE_TIMESTAMP:  532c4587
 
FAILURE_BUCKET_ID:  AV_rtwlane+114323
 
BUCKET_ID:  AV_rtwlane+114323
 
ANALYSIS_SOURCE:  KM
 
FAILURE_ID_HASH_STRING:  km:av_rtwlane+114323
 
FAILURE_ID_HASH:  {c76fdf6a-88d4-3768-29ff-d872c474d9bd}
 
Followup: MachineOwner
---------
 


#6 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 04 October 2014 - 08:38 PM

any ideas anyone



#7 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:10:49 AM

Posted 05 October 2014 - 02:40 AM

Sorry for the delay.

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffe0007b800960, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800b5bbe323, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 0000000000000002, (reserved)

Invalid system memory was read, this isn't allowed and will always result in a bugcheck.

3: kd> !pte ffffe000`7b800960
                                           VA ffffe0007b800960
PXE at FFFFF6FB7DBEDE00    PPE at FFFFF6FB7DBC0008    PDE at FFFFF6FB78001EE0    PTE at FFFFF6F0003DC000
contains 00000000001C1863  contains 0000000000800863  contains 0000000000000000
GetUlongFromAddress: unable to read from fffff8026a571104
pfn 1c1       ---DA--KWEV  pfn 800       ---DA--KWEV  not valid // Invalid as pointed here

So lets look at the callstack to find the culprit.

ffffd000`9c145678 fffff802`6a3a224a : 00000000`00000050 ffffe000`7b800960 00000000`00000000 ffffd000`9c145860 : nt!KeBugCheckEx // The system must crash as the invalid memory reference cannot be ignored
ffffd000`9c145680 fffff802`6a2849c9 : 00000000`00000000 ffffe000`7acb4880 ffffd000`9c145860 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x20d9a
ffffd000`9c145720 fffff802`6a37b22f : 00000000`00000000 00000000`00000000 00000000`00000000 ffffd000`9c145860 : nt!MmAccessFault+0x7a9 //access fault, it can't bring the memory back from disk as it's invalid
ffffd000`9c145860 fffff800`b5bbe323 : ffffe000`7f200000 00000000`00000001 ffffd000`9c145a50 ffffe000`7f200000 : nt!KiPageFault+0x12f //calls into a pagefault
ffffd000`9c1459f0 ffffe000`7f200000 : 00000000`00000001 ffffd000`9c145a50 ffffe000`7f200000 00000000`00000000 : rtwlane+0x114323 // Realtek LAN NIC driver
ffffd000`9c1459f8 00000000`00000001 : ffffd000`9c145a50 ffffe000`7f200000 00000000`00000000 fffff800`b5bf2f16 : 0xffffe000`7f200000 // "
ffffd000`9c145a00 ffffd000`9c145a50 : ffffe000`7f200000 00000000`00000000 fffff800`b5bf2f16 00000000`00000000 : 0x1 // "
ffffd000`9c145a08 ffffe000`7f200000 : 00000000`00000000 fffff800`b5bf2f16 00000000`00000000 ffffe000`7a0d2004 : 0xffffd000`9c145a50 // "
ffffd000`9c145a10 00000000`00000000 : fffff800`b5bf2f16 00000000`00000000 ffffe000`7a0d2004 ffffe000`7a0d2004 : 0xffffe000`7f200000 // User Mode address not visible in a Minidump or Kernel mode dump

So rtwlane is the culprit.

What can we do?

3: kd> lmvm rtwlane
start             end                 module name
fffff800`b5aaa000 fffff800`b5dfb000   rtwlane  T (no symbols)           
    Loaded symbol image file: rtwlane.sys
    Image path: \SystemRoot\system32\DRIVERS\rtwlane.sys
    Image name: rtwlane.sys
    Timestamp:        Fri Mar 21 13:58:31 2014 (532C4587)
    CheckSum:         003466B8
    ImageSize:        00351000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4

The driver is fairly new, it the driver for your Realtek PCI-E Wireless LAN NIC NDIS card.

I would try to update it here

 

http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=13&PFid=21&Level=4&Conn=3

 

If there is no update then try an older driver,



#8 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 05 October 2014 - 07:16 PM

how do i get an older driver and why should i have this problem with a brand new computer. some one owes me a discount then huh. 

 

Realtek RTL8188EE 802.11 b/g/n Wi-Fi Adapter
driver update says its up to date

Edited by MikeHunt, 05 October 2014 - 07:26 PM.


#9 Jared44

Jared44

  • BSOD Kernel Dump Expert
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dronfield
  • Local time:10:49 AM

Posted 06 October 2014 - 02:44 PM

It can happen to anyone, there are many reasons it can happen, most likely conflict or incompatibility; this doesn't mean it's a problem on your end but rather a problem in the programming in the driver.

 

To roll back you can either download the eariler driver onto the desktop, uninstall your current driver then install the eariler one.

Or you can choose the role back driver via the device manager (not as reliable).



#10 MikeHunt

MikeHunt
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 06 October 2014 - 06:22 PM

thanks can you find me the earlier driver. id hate to delete this one and not be able to get back online. 

i tried to search for it for this card and couldnt find it. other than it sayings its up to date. 

 

device manager i didnt see the option to roll back. i dont wanna dig out my lan cable if i get pounded in the @hole on this one. 

can you find me the correct roll back if you think that will work? 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users