BSOD caused by e22win7x64.sys
Hey all,
recently I have some issues related with e22win7x64.sys. I believe this BSOD is caused by Killer network manager.
I have checked all possible solutions like uninstall Killer network, and only install the drivers.
Unfortunately, it doesn't help me much. I still have BSOD problems.
Does anyone know if there exist another network adapter that can replace Killer network?
My motherboard is X99S Gaming 9 ACK
Memorary: G.SKILL Ripjaws 4 series 32GB (4 x 8GB) 288-Pin DDR4 SDRAM DDR4 2666
GPU: MSI GTX 980 GAMING 4G GeForce GTX 980 4GB
CPU: I7-5960X
which killed driver version you are using?
Similar Messages
-
T410 NVIDIA BSOD caused by nvlddmkm.sys
Hi all,
I have lot of BSOD (1/week at least) caused by nvlddmkm.sys
I have the latest driver according to lenovo update.
I'm on Win7 x64.
This is not caused by overheating I'm not running any game or 3d application,
GPU idles ~60C.
Could someone help me what to do?
(Some time ago I tried the driver from NVIDIA page, but had the same experience, now I'm back on the Lenovo "official" driver.)hey nuri,
could you try the following ?
- uninstall the current driver you have installed
- -restart your system and let Win7 install its generic driver
- check if it happens again
WW Social Media
Important Note: If you need help, post your question in the forum, and include your system type, model number and OS. Do not post your serial number.
Did someone help you today? Press the star on the left to thank them with a Kudo!
If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!
Follow @LenovoForums on Twitter!
Have you checked out the Community Knowledgebase yet?!
How to send a private message? --> Check out this article. -
MOVED: BSOD caused by nvlddmkm.sys in Vista Ultimate x64
This topic has been moved to Vista problems.
https://forum-en.msi.com/index.php?topic=121723.0hey nuri,
could you try the following ?
- uninstall the current driver you have installed
- -restart your system and let Win7 install its generic driver
- check if it happens again
WW Social Media
Important Note: If you need help, post your question in the forum, and include your system type, model number and OS. Do not post your serial number.
Did someone help you today? Press the star on the left to thank them with a Kudo!
If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!
Follow @LenovoForums on Twitter!
Have you checked out the Community Knowledgebase yet?!
How to send a private message? --> Check out this article. -
Hi Guys,
Has anyone come across this BSOD error and found a fix, as I'm at a lost as to what is causing the BSOD
Please see Windows Debugger output below:-
Microsoft (R) Windows Debugger Version 6.2.9200.16384 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Transfer\Minidumps\Mini051414-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (8 procs) Free x64
Product: Server, suite: Enterprise TerminalServer
Built by: 6002.23154.amd64fre.vistasp2_ldr.130707-1535
Machine Name:
Kernel base = 0xfffff800`01c18000 PsLoadedModuleList = 0xfffff800`01dd7e30
Debug session time: Wed May 14 12:01:16.178 2014 (UTC + 1:00)
System Uptime: 3 days 7:15:01.532
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff9600030271e, fffffa603d967ec0, 0}
Probably caused by : win32k.sys ( win32k!PFFOBJ::pPvtDataMatch+12 )
Followup: MachineOwner
7: kd> !analyze -v
* Bugcheck Analysis
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff9600030271e, Address of the instruction which caused the bugcheck
Arg3: fffffa603d967ec0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!PFFOBJ::pPvtDataMatch+12
fffff960`0030271e f6430804 test byte ptr [rbx+8],4
CONTEXT: fffffa603d967ec0 -- (.cxr 0xfffffa603d967ec0)
rax=fffff900c277dd10 rbx=6364735523080013 rcx=fffffa603d968790
rdx=fffff900c2cc92a0 rsi=fffff900c2ade350 rdi=fffffa80369f6680
rip=fffff9600030271e rsp=fffffa603d968720 rbp=0000000000000000
r8=0000000000000000 r9=fffffa80369f6680 r10=fffffa803b6cdc48
r11=fffffa603d9687c8 r12=fffffa603d968810 r13=0000000000000000
r14=000000000000301f r15=0000000000000001
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
win32k!PFFOBJ::pPvtDataMatch+0x12:
fffff960`0030271e f6430804 test byte ptr [rbx+8],4 ds:002b:63647355`2308001b=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT_SERVER
BUGCHECK_STR: 0x3B
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960003009b1 to fffff9600030271e
STACK_TEXT:
fffffa60`3d968720 fffff960`003009b1 : 00000000`0000301f 00000000`00004fbc 00000000`00000000 fffffa80`3b6cdbb0 : win32k!PFFOBJ::pPvtDataMatch+0x12
fffffa60`3d968750 fffff960`001aacb6 : fffff900`c2ade350 fffff900`c3fa59e0 00000000`00000000 fffffa80`369f6680 : win32k!PFTOBJ::bUnloadWorkhorse+0x55
fffffa60`3d9687d0 fffff960`001ab8d8 : fffff900`c2ade2d0 00000000`00000000 00000000`00000001 00000000`00000001 : win32k!vCleanupPrivateFonts+0x72
fffffa60`3d968810 fffff960`0019fbc0 : 00000000`00000000 fffff800`01ebfe00 fffff900`c277dd10 fffffa80`38d5b800 : win32k!NtGdiCloseProcess+0x4a8
fffffa60`3d968870 fffff960`0019f423 : 00000000`00000000 fffff900`c277dd10 00000000`00000000 fffff800`01ebfe48 : win32k!GdiProcessCallout+0x1f4
fffffa60`3d9688f0 fffff800`01ecc924 : 00000000`00000000 00000000`00000000 fffff800`01db6ec0 00000000`00000000 : win32k!W32pProcessCallout+0x6f
fffffa60`3d968920 fffff800`01ebfe65 : fffffa60`00000000 fffff800`01c89701 fffffa80`57c73810 00000000`78457350 : nt!PspExitThread+0x41c
fffffa60`3d968a10 fffff800`01c89881 : fffffa60`3d968ad8 00000000`00000000 fffffa80`382fe430 00000000`00000000 : nt!PsExitSpecialApc+0x1d
fffffa60`3d968a40 fffff800`01c8d935 : fffffa60`3d968ca0 fffffa60`3d968ae0 fffff800`01ebfe74 00000000`00000001 : nt!KiDeliverApc+0x441
fffffa60`3d968ae0 fffff800`01c6721d : fffffa80`3b6cdbb0 00000000`0038f2f4 fffffa60`3d968bf8 fffffa80`597301e0 : nt!KiInitiateUserApc+0x75
fffffa60`3d968c20 00000000`74c93d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0xa2
00000000`000eebd8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x74c93d09
FOLLOWUP_IP:
win32k!PFFOBJ::pPvtDataMatch+12
fffff960`0030271e f6430804 test byte ptr [rbx+8],4
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!PFFOBJ::pPvtDataMatch+12
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 52f4cf4d
STACK_COMMAND: .cxr 0xfffffa603d967ec0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!PFFOBJ::pPvtDataMatch+12
BUCKET_ID: X64_0x3B_win32k!PFFOBJ::pPvtDataMatch+12
Followup: MachineOwner
7: kd> lmvm win32k
start end module name
fffff960`000e0000 fffff960`0039a000 win32k (pdb symbols) c:\symbols\win32k.pdb\E3E9D4C3813E470A90F52FAEC6461A252\win32k.pdb
Loaded symbol image file: win32k.sys
Mapped memory image file: c:\symbols\win32k.sys\52F4CF4D2ba000\win32k.sys
Image path: win32k.sys
Image name: win32k.sys
Timestamp: Fri Feb 07 12:19:25 2014 (52F4CF4D)
CheckSum: 002AD344
ImageSize: 002BA000
File version: 6.0.6002.23325
Product version: 6.0.6002.23325
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: win32k.sys
OriginalFilename: win32k.sys
ProductVersion: 6.0.6002.23325
FileVersion: 6.0.6002.23325 (vistasp2_ldr.140207-0038)
FileDescription: Multi-User Win32 Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
7: kd> .cxr 0xfffffa603d967ec0
rax=fffff900c277dd10 rbx=6364735523080013 rcx=fffffa603d968790
rdx=fffff900c2cc92a0 rsi=fffff900c2ade350 rdi=fffffa80369f6680
rip=fffff9600030271e rsp=fffffa603d968720 rbp=0000000000000000
r8=0000000000000000 r9=fffffa80369f6680 r10=fffffa803b6cdc48
r11=fffffa603d9687c8 r12=fffffa603d968810 r13=0000000000000000
r14=000000000000301f r15=0000000000000001
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
win32k!PFFOBJ::pPvtDataMatch+0x12:
fffff960`0030271e f6430804 test byte ptr [rbx+8],4 ds:002b:63647355`2308001b=??
Thanks
JTGetting BSOD's pointing to this dll also. Started at around the same date as Jitinder's post. Maybe a new issue introduced has been introduced?
7: kd> !analyze -v
* Bugcheck Analysis *
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff9600011fda0, Address of the instruction which caused the bugcheck
Arg3: fffffa6027acd1d0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
"kernel32.dll" was not found in the image list.
Debugger will attempt to load "kernel32.dll" at given base 00000000`00000000.
Please provide the full image name, including the extension (i.e. kernel32.dll)
for more reliable results.Base address and size overrides can be given as
.reload <image.ext>=<base>,<size>.
Unable to add module at 00000000`00000000
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!PFEOBJ::vFreepfdg+e8
fffff960`0011fda0 0fba60300f bt dword ptr [rax+30h],0Fh
CONTEXT: fffffa6027acd1d0 -- (.cxr 0xfffffa6027acd1d0)
rax=00000000014c0000 rbx=0000000000000000 rcx=fffff900c009c2a0
rdx=fffffa802735ab80 rsi=fffff900c0b9b010 rdi=fffffa6027acda80
rip=fffff9600011fda0 rsp=fffffa6027acda30 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=fffffa802800a288
r11=fffffa802800a060 r12=0000000000000000 r13=0000000000000000
r14=000000001539ed50 r15=0000000000000001
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010207
win32k!PFEOBJ::vFreepfdg+0xe8:
fffff960`0011fda0 0fba60300f bt dword ptr [rax+30h],0Fh ds:002b:00000000`014c0030=????????
Resetting default scope
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: iexplore.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960002e66d4 to fffff9600011fda0
STACK_TEXT:
fffffa60`27acda30 fffff960`002e66d4 : 00000000`00000000 fffffa80`2735ab50 00000000`00000001 00000000`746e6647 : win32k!PFEOBJ::vFreepfdg+0xe8
fffffa60`27acda60 fffff960`002f0cb7 : 00000000`00000000 fffff900`c008f000 fffff900`c0010000 00000000`00000000 : win32k!RFONTOBJ::vDeleteRFONT+0x210
fffffa60`27acdac0 fffff960`002f0926 : 00000000`00000000 fffff900`c2bfcca0 fffff900`c0ae4010 00000000`00000000 : win32k!vRestartKillRFONTList+0xab
fffffa60`27acdb10 fffff960`00275c79 : 00000000`00000000 00000000`00000001 fffffa80`235762b0 fffff900`00000002 : win32k!PFTOBJ::bUnloadWorkhorse+0x196
fffffa60`27acdb90 fffff960`002978e2 : fffffa80`2800a060 fffff900`c0b932a0 fffffa60`27acdca0 00000000`7457c444 : win32k!GreRemoveFontMemResourceEx+0xad
fffffa60`27acdbf0 fffff800`01a64173 : fffffa80`2800a060 fffffa60`27acdca0 00000000`7ee9f000 fffffa80`25803040 : win32k!NtGdiRemoveFontMemResourceEx+0x12
fffffa60`27acdc20 00000000`74513d09 : 00000000`74513cc5 00000023`77300682 00000000`00000023 00000000`00000202 : nt!KiSystemServiceCopyEnd+0x13
00000000`1539ed48 00000000`74513cc5 : 00000023`77300682 00000000`00000023 00000000`00000202 00000000`1767d5e0 : wow64cpu!CpupSyscallStub+0x9
00000000`1539ed50 00000000`7457ab36 : 00000000`77120000 00000000`1539fd20 00000000`60c8f022 00000000`1539f450 : wow64cpu!Thunk0Arg+0x5
00000000`1539edc0 00000000`7457a13a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : wow64!RunCpuSimulation+0xa
00000000`1539edf0 00000000`771847c8 : 00000000`00000000 00000000`00000000 00000000`7efdf000 00000000`00000000 : wow64!Wow64LdrpInitialize+0x4b6
00000000`1539f350 00000000`771461be : 00000000`1539f450 00000000`00000000 00000000`7efdf000 00000000`00000000 : ntdll! ?? ::FNODOBFM::`string'+0x1fba1
00000000`1539f400 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrInitializeThunk+0xe
FOLLOWUP_IP:
win32k!PFEOBJ::vFreepfdg+e8
fffff960`0011fda0 0fba60300f bt dword ptr [rax+30h],0Fh
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!PFEOBJ::vFreepfdg+e8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 5202fc4d
STACK_COMMAND: .cxr 0xfffffa6027acd1d0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!PFEOBJ::vFreepfdg+e8
BUCKET_ID: X64_0x3B_win32k!PFEOBJ::vFreepfdg+e8
Followup: MachineOwner
7: kd> lmv m win32k
start end module name
fffff960`000d0000 fffff960`00389000 win32k (pdb symbols) c:\symcache\win32k.pdb\54B8C53009264F08A9D8CF1B4B56BCDC2\win32k.pdb
Loaded symbol image file: win32k.sys
Image path: \SystemRoot\System32\win32k.sys
Image name: win32k.sys
Timestamp: Thu Aug 08 04:02:53 2013 (5202FC4D)
CheckSum: 002B126B
ImageSize: 002B9000
File version: 6.0.6002.18912
Product version: 6.0.6002.18912
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: win32k.sys
OriginalFilename: win32k.sys
ProductVersion: 6.0.6002.18912
FileVersion: 6.0.6002.18912 (vistasp2_gdr.130807-1537)
FileDescription: Multi-User Win32 Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
7: kd> .cxr 0xfffffa6027acd1d0
rax=00000000014c0000 rbx=0000000000000000 rcx=fffff900c009c2a0
rdx=fffffa802735ab80 rsi=fffff900c0b9b010 rdi=fffffa6027acda80
rip=fffff9600011fda0 rsp=fffffa6027acda30 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=fffffa802800a288
r11=fffffa802800a060 r12=0000000000000000 r13=0000000000000000
r14=000000001539ed50 r15=0000000000000001
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010207
win32k!PFEOBJ::vFreepfdg+0xe8:
fffff960`0011fda0 0fba60300f bt dword ptr [rax+30h],0Fh ds:002b:00000000`014c0030=???????? -
Last night 1 of our 2008r2 sp1 Enterprise crashed and auto rebooted. With the debugger tool I checked the minidump and at the bottom it states:
Probably caused by : srv2.sys ( srv2+212e )
This is the SMB driver. There is a KB that acknowledges that there is a bug in this driver and a hot fix is available. However.. the date of the driver in the hotfix is older than the date of the driver in use by the server. Get my point? Should I install
the "older" hotfix or not.
This is the KB: http://support.microsoft.com/kb/2394911
I contacted MS SA support in the Netherlands and the literally stated that the server is now up and running so there is no problem hence they can not support this. Ridiculous. I told him that we have a server running that we can't rely on. They did not care..
I asked they guy to ask his manager and they just refuse to support me. Instead they sad I should contact a MS Partner because the question was about "implementation ".
Can you imagine that I not impressed at all by this...Hello,
So it is a BSOD.
Please start by that:
Update all possible drivers
Uninstall all unused programs
Run chkdsk /r /f and sfc /scannow
Perform a clean boot: http://support.microsoft.com/kb/929135
Disable temporary all security softwares you have
Run memtest86+ to check your RAM. If an error was detected then replace the faulty RAM or contact your manufacturer Technical Support for assistance
Once done, check results. If this does not help then use Microsoft Skydrive to upload dump files. Once done, post a link here.
You can also contact Microsoft CSS for assistance.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft
Student Partner 2010 / 2011
Microsoft
Certified Professional
Microsoft
Certified Systems Administrator: Security
Microsoft
Certified Systems Engineer: Security
Microsoft
Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft Certified IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer -
Tracing complete, solution required bsod due to ACPI.sys
hi, hassaan here
i got a bsod today and i debugged it, the result i got, is you can find at:
https://skydrive.live.com/redir?resid=F80746862BC199FD!155&authkey=!AExsDmGkIac7haY&ithint=file%2c.txt
the main cause is ACpi.sys and showing reason, VISTA_DRIVER_FAULT;
i really required help, what is the cause and what solution is required.
awaiting for reply.
thanks.Hi,
Please upload the source file to Skydrive, and then share to us.
Meanwhile, update all your drivers and then run sfc /scannow command:
Use the System File Checker tool to repair missing or corrupted system files
http://support.microsoft.com/kb/929833
Karen Hu
TechNet Community Support -
Probably caused by : atikmdag.sys ( atikmdag+127f8 )
I just purchased a new HP ProLiant MicroServer G7 N54L
Here is a short history:
I replaced the 4GB ECC memory to 8GN non-ECC
I originally used a 25ft VGA cable on the on-board VGA port, but had a blue tinge, couldn't recognize the monitor properly, and a bluescreen shutdown, so I removed it.
There is nothing connected to the VGA port now
I now connect using RDP only
The computer freezes randomly and seems to happen when I launch the chrome browser (through RDP)
The dump files are at: https://onedrive.live.com/redir?resid=A19E045098FB769C!1399&authkey=!APLz-efriDf5wAs&ithint=file%2czip
According to my limited knowledge, it seems that the dump files indicate a video problem, but I am not completely sure. Can this be a problem with the motherboard?
Any help is greatly appreciated.GG
These were related to your 5 year old video driver and may simply need a driver update. It is called a BCC116 and is either the driver or perhaps heat. I would start by removing the current driver and installing the newest driver available.
"It's not a true crash, in the sense that the Blue Screen was initiated only because the combination of video driver and video hardware was being unresponsive, and not because of any synchronous processing exception".
Since Vista, the "Timeout Detection and Recovery" (TDR) components of the OS video subsystem have been capable of doing some truly impressive things to try to recover from issues which would have caused earlier OS's like XP to crash.
As a last resort, the TDR subsystem sends the video driver a "please restart yourself now!" command and waits a few seconds.
If there's no response, the OS concludes that the video driver/hardware combo has truly collapsed in a heap, and it fires off that stop 0x116 BSOD.
If playing with video driver versions hasn't helped, make sure the box is not overheating.
Try removing a side panel and aiming a big mains fan straight at the motherboard and GPU.
Run it like that for a few hours or days - long enough to ascertain whether cooler temperatures make a difference.
If so, it might be as simple as dust buildup and subsequently inadequate cooling.
I would download cpu-z and gpu-z (both free) and keep an eye on the video temps
For more information please read this blog http://captaindbg.com/bug-check-0x116-video_tdr_error-troubleshooting-tips/
http://msdn.microsoft.com/en-us/library/windows/hardware/ff557263%28v=vs.85%29.aspx
Microsoft (R) Windows Debugger Version 6.3.9600.17029 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Ken\Desktop\082614-25833-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred srv*C:\Symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: srv*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`0280a000 PsLoadedModuleList = 0xfffff800`02a4d890
Debug session time: Tue Aug 26 23:27:25.092 2014 (UTC - 4:00)
System Uptime: 8 days 2:58:31.684
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
* Bugcheck Analysis *
Use !analyze -v to get detailed debugging information.
BugCheck 116, {fffffa80093cd4e0, fffff88004cc57f8, 0, 2}
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
Probably caused by : atikmdag.sys ( atikmdag+127f8 )
Followup: MachineOwner
0: kd> !analyze -v
* Bugcheck Analysis *
VIDEO_TDR_FAILURE (116)
Attempt to reset the display driver and recover from timeout failed.
Arguments:
Arg1: fffffa80093cd4e0, Optional pointer to internal TDR recovery context (TDR_RECOVERY_CONTEXT).
Arg2: fffff88004cc57f8, The pointer into responsible device driver module (e.g. owner tag).
Arg3: 0000000000000000, Optional error code (NTSTATUS) of the last failed operation.
Arg4: 0000000000000002, Optional internal context dependent data.
Debugging Details:
FAULTING_IP:
atikmdag+127f8
fffff880`04cc57f8 48895c2408 mov qword ptr [rsp+8],rbx
DEFAULT_BUCKET_ID: GRAPHICS_DRIVER_TDR_FAULT
CUSTOMER_CRASH_COUNT: 1
BUGCHECK_STR: 0x116
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre
STACK_TEXT:
fffff880`05a5f9c8 fffff880`05327134 : 00000000`00000116 fffffa80`093cd4e0 fffff880`04cc57f8 00000000`00000000 : nt!KeBugCheckEx
fffff880`05a5f9d0 fffff880`05326e3e : fffff880`04cc57f8 fffffa80`093cd4e0 fffffa80`0841cc00 fffffa80`085ce010 : dxgkrnl!TdrBugcheckOnTimeout+0xec
fffff880`05a5fa10 fffff880`04c0ff13 : fffffa80`093cd4e0 00000000`00000000 fffffa80`0841cc00 fffffa80`085ce010 : dxgkrnl!TdrIsRecoveryRequired+0x1a2
fffff880`05a5fa40 fffff880`04c39cf1 : 00000000`ffffffff 00000000`02ae8b02 00000000`00000000 00000000`00000002 : dxgmms1!VidSchiReportHwHang+0x40b
fffff880`05a5fb20 fffff880`04c38437 : 00000000`00000102 00000000`00000000 00000000`02ae8b02 00000000`00000000 : dxgmms1!VidSchiCheckHwProgress+0x71
fffff880`05a5fb50 fffff880`04c0b2d2 : ffffffff`ff676980 fffffa80`085ce010 00000000`00000000 00000000`00000000 : dxgmms1!VidSchiWaitForSchedulerEvents+0x1fb
fffff880`05a5fbf0 fffff880`04c37ff6 : 00000000`00000000 fffffa80`08641830 00000000`00000080 fffffa80`085ce010 : dxgmms1!VidSchiScheduleCommandToRun+0x1da
fffff880`05a5fd00 fffff800`02b1b73a : 00000000`fffffc32 fffffa80`085cf610 fffffa80`06702040 fffffa80`085cf610 : dxgmms1!VidSchiWorkerThread+0xba
fffff880`05a5fd40 fffff800`028708e6 : fffff800`029fae80 fffffa80`085cf610 fffff800`02a08cc0 fffff880`031b5801 : nt!PspSystemThreadStartup+0x5a
fffff880`05a5fd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: .bugcheck ; kb
FOLLOWUP_IP:
atikmdag+127f8
fffff880`04cc57f8 48895c2408 mov qword ptr [rsp+8],rbx
SYMBOL_NAME: atikmdag+127f8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: atikmdag
IMAGE_NAME: atikmdag.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a8a1a8b
FAILURE_BUCKET_ID: X64_0x116_IMAGE_atikmdag.sys
BUCKET_ID: X64_0x116_IMAGE_atikmdag.sys
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x116_image_atikmdag.sys
FAILURE_ID_HASH: {7527b2fa-489f-c504-9452-1a10bd154401}
Followup: MachineOwner
Wanikiya and Dyami--Team Zigzag -
0x7_8 stop error caused by NTFS.SYS , please help with dump file analysis
My 2003 server rebooted unexpected twice today and yesterday.
I've run Windbg to analysis the dump file, but i really don't know what to do next to resolve my problem.
Can any one give some suggestion? thanks in advance.
Resetting default scope
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: csrss.exe
FAILURE_BUCKET_ID: 0x7f_8_Ntfs+5f74
BUCKET_ID: 0x7f_8_Ntfs+5f74
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\temp\ads02 memory dump 20140218\MEMORY_20140217.DMP]
Kernel Summary Dump File: Only kernel address space is available
WARNING: Whitespace at end of path element
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols.sympath
Executable search path is:
Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (4 procs) Free x86 compatible
Product: LanManNt, suite: TerminalServer SingleUserTS
Built by: 3790.srv03_sp2_qfe.130703-1535
Machine Name:
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a8ee8
Debug session time: Mon Feb 17 08:37:34.653 2014 (UTC + 8:00)
System Uptime: 1 days 2:57:43.093
WARNING: Process directory table base BFF9C6C0 doesn't match CR3 005F2000
WARNING: Unable to reset page directories
Loading Kernel Symbols
Loading User Symbols
WARNING: Process directory table base BFF9C6C0 doesn't match CR3 005F2000
Unable to get PEB pointer
Loading unloaded module list
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 7F, {8, 80042000, 0, 0}
*** WARNING: Unable to verify timestamp for mssmbios.sys
*** ERROR: Module load completed but symbols could not be loaded for mssmbios.sys
*** WARNING: Unable to verify timestamp for Ntfs.sys
*** ERROR: Module load completed but symbols could not be loaded for Ntfs.sys
Unable to read selector for PCR for processor 1
Unable to read selector for PCR for processor 2
Unable to read selector for PCR for processor 3
Unable to read selector for PCR for processor 1
Unable to read selector for PCR for processor 2
Unable to read selector for PCR for processor 3
Probably caused by : Ntfs.sys ( Ntfs+5f74 )
Followup: MachineOwner
0: kd> !analyze -v
* Bugcheck Analysis
UNEXPECTED_KERNEL_MODE_TRAP (7f)
This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault). The first number in the
bugcheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
use .trap on that value
Else
.trap on the appropriate frame will show where the trap was taken
(on x86, this will be the ebp that goes with the procedure KiTrap)
Endif
kb will then show the corrected stack.
Arguments:
Arg1: 00000008, EXCEPTION_DOUBLE_FAULT
Arg2: 80042000
Arg3: 00000000
Arg4: 00000000
Debugging Details:
Unable to read selector for PCR for processor 1
Unable to read selector for PCR for processor 2
Unable to read selector for PCR for processor 3
Unable to read selector for PCR for processor 1
Unable to read selector for PCR for processor 2
Unable to read selector for PCR for processor 3
BUGCHECK_STR: 0x7f_8
TSS: 00000028 -- (.tss 0x28)
eax=00000000 ebx=8b4f1100 ecx=8ac87d03 edx=8687ddc0 esi=b83481a0 edi=b8348028
eip=f7addf74 esp=b8348000 ebp=b8348014 iopl=0 nv up ei pl nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
Ntfs+0x5f74:
f7addf74 0000 add byte ptr [eax],al ds:0023:00000000=??
Resetting default scope
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 1
LAST_CONTROL_TRANSFER: from 00000000 to f7addf74
STACK_TEXT:
b8348014 00000000 00000000 00000000 00000000 Ntfs+0x5f74
STACK_COMMAND: .tss 0x28 ; kb
FOLLOWUP_IP:
Ntfs+5f74
f7addf74 0000 add byte ptr [eax],al
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs+5f74
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAILURE_BUCKET_ID: 0x7f_8_Ntfs+5f74
BUCKET_ID: 0x7f_8_Ntfs+5f74
Followup: MachineOwnerAccording to your post bug check 0x7F is recorded. Bug check 0x7F typically occurs after you install a faulty or mismatched hardware (especially memory) or if installed hardware fails.
I suggest you check below link and troubleshoot it accordingly.
Bug Check 0x7F
Regards, Ravikumar P -
Where is the form / forum to submit BSOD caused by Photoshop CS4 to the technical support ?
But if it will make you feel better, the bug report form is here:
http://www.adobe.com/cfusion/mmform/index.cfm?name=wishform
As Bob said, though, this is generally a hardware/driver issue of some sort. I've just seen a case where some malware was causing BSOD when trying to run or install a scanner. When I got the malware off the machine the BSOD problem was instantly cured. -
we run several Windows Server 2008r2 SP1 Enterprise as VM on two Stratus Avance xenserver based VM hosts. On both hosts we run a VM as file-server, RDS server including a little bit of DFS traffic. the underling physical machines are Intel based S5520UR
with plenty full of needed resources, running since 2012 more or less without problems.
Recently we on both physical hosts the STOP error 0x0000001e (0xffffffffc0000005, 0xfffff8800a07d7f0, 0x0000000000000000, 0x0000000000000000).
This has happended now twice and we have no clue or idea why the Stop error arrives now were the VM is running for month without such an error.
We have tried to analyze the problem with WnDbg and the result reported: Probably caused by : mrxsmb10.sys ( mrxsmb10!MRxSmbDeferredCreate+18a )
We have searched for a solution and have identified some hotfixes which could be related to our problem
Hotfix http://support.microsoft.com/kb/2521220/en-us
and / or
Hotfix http://support.microsoft.com/kb/2764302/en-us
The latter one matches the typical use of the VMs in question, file-server function and a flat file based database system with corresponding file I/O. (However, no dramatic system load and approx. 20 concurrent users on the system.)
The file NTFS.sys in the folder System32 are with a newer date and version as the version from the hotfix and we are not sure if this would be a good idea to replace it with the hotfix version.
As we are a small cap company we could not test the outcome of such a change of essential OS files and we tend to stay away from this approach. On the other hand we have a high pressure to solve this issue as we have to rely on the function of this core
system.
WinDbg points us towards mrxsmb10.sys as a possible root cause, but my believe is limited and we have not the knowledge to understand the output of the memory dump file. (mrxsmb was over the last 15 years always a difficult “thing”!)
Would someone so kind to point us to some useful steps or direct us to any helpful advise?
Thank you!1. Share your minidump file - someone may see content and help.
2. Consider this
http://support.microsoft.com/kb/2521220
3. Error description
http://msdn.microsoft.com/en-us/library/windows/hardware/ff557408(v=vs.85).aspx
Regards
Milos -
Windows Server 2008 R2 SP1 BSOD 0x1a with CLFS.sys
Hello,
I've got a BSOD on a Windows Server 2008 R2 with SP1 installed. Analyzed the dump and could
see a Bug-check of 0x1a which means "MEMORY_MANAGEMENT".
Further analysis on this dump shows me, that this probably is caused by the CLFS.sys, which
is the Common Log File System Driver. This CLFS.sys is installed with date:
Tue Jul 14 01:19:57 2009
I have now searched trough MS Support pages and resources and also the Internet, but I found no
information about an update for this or a newer version. It's nearby impossible to find newer versions
for specific files in i.e. Hot-fixes.
Do you know this issue with the 0x1a BSOD and CLFS.sys and/or do you know a newer version ?
Any help would be very appreciated!
Thanks and regards plus have a nice day !
TinoHi Tino,
Regarding to Bug Check 0x1A, please refer to following article.
Bug Check 0x1A: MEMORY_MANAGEMENT
Did you install any third-party application in this problematic server? Would you please let me know whether
the BSOD issue occurred regularly? Or just occurred suddenly? If the BSOD issue occurred regularly, please
perform a clean boot and check if this BSOD issue still exists.
In addition, please check if necessary updates need to be installed and drivers need to be updated. Please
run sfc /scannow command to scan all protected system files and check if find errors.
As you know, troubleshoot this kind of kernel crash issue, we need to analyze the crash dump file to narrow down the root cause of the issue. Actually, it is not effective
for us to debug the crash dump file here in the forum. If this issues is a state of emergency for you. Please contact Microsoft Customer Service and Support (CSS) via telephone so that a dedicated Support Professional can assist with your request.
To obtain the phone numbers for specific technology request, please refer to the web site listed below:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;OfferProPhone#faq607
àThis CLFS.sys is installed with date: Tue Jul 14 01:19:57 2009
àor do you know a newer version?
By the way, I checked the CLFS.sys in a Windows Server 2008 R2 in my Lab environment. It also created in July
2009.
Hope this helps.
Best regards,
Justin Gu -
Randomly BSODs caused by ntoskrnl.exe
I have random BSODs, this is the dump file... any ideas? I tried to update all drivers, but I solved nothing.
Microsoft (R) Windows Debugger Version 6.3.9600.17029 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Program Files (x86)\Windows Kits\8.1\Debuggers\x86\061114-29937-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Error: Attempts to access '061114-29937-01.dmp' failed: 0x0 - The operation completed successfully.
************* Symbol Path validation summary **************
Response Time (ms) Location
Error 061114-29937-01.dmp
Symbol search path is: 061114-29937-01.dmp
Executable search path is:
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17085.amd64fre.winblue_gdr.140330-1035
Machine Name:
Kernel base = 0xfffff800`6e28e000 PsLoadedModuleList = 0xfffff800`6e5582d0
Debug session time: Wed Jun 11 20:29:12.062 2014 (UTC + 2:00)
System Uptime: 0 days 0:22:21.219
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
************* Symbol Loading Error Summary **************
Module name Error
ntoskrnl The system cannot find the file specified
You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
You should also verify that your symbol search path (.sympath) is correct.
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 133, {1, 1e00, 0, 0}
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work.
*** Type referenced: nt!_KPRCB
5 times more...
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work.
*** Type referenced: nt!_KPRCB
Probably caused by : ntoskrnl.exe ( nt+153fa0 )
Followup: MachineOwner
Systeminfo:
OS Name: Microsoft Windows 8.1 Pro
OS Version: 6.3.9600 N/A Build 9600
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Workstation
OS Build Type: Multiprocessor Free
Original Install Date: 30/10/2013, 13:43:05
System Boot Time: 11/06/2014, 20:29:52
System Manufacturer: TOSHIBA
System Model: Satellite L500
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: Intel64 Family 6 Model 37 Stepping 2 GenuineIntel ~2261 Mhz
BIOS Version: TOSHIBA 2.10, 17/05/2011
Windows Directory: C:\WINDOWS
System Directory: C:\WINDOWS\system32
Boot Device: \Device\HarddiskVolume2
Total Physical Memory: 3.958 MB
Available Physical Memory: 1.792 MB
Virtual Memory: Max Size: 7.926 MB
Virtual Memory: Available: 5.492 MB
Virtual Memory: In Use: 2.434 MB
Page File Location(s): C:\pagefile.sys
Domain: WORKGROUP
Logon Server:
\\MicrosoftAccount
Hotfix(s): 56 Hotfix(s) Installed.
[01]: KB2899189_Microsoft-Windows-CameraCodec-Package
[02]: KB2843630
[03]: KB2868626
[04]: KB2883200
[05]: KB2887595
[06]: KB2889543
[07]: KB2891214
[08]: KB2893294
[09]: KB2894029
[10]: KB2894179
[11]: KB2898868
[12]: KB2900986
[13]: KB2901125
[14]: KB2901128
[15]: KB2903939
[16]: KB2904440
[17]: KB2911106
[18]: KB2912390
[19]: KB2913152
[20]: KB2916036
[21]: KB2919355
[22]: KB2919394
[23]: KB2919442
[24]: KB2920189
[25]: KB2923528
[26]: KB2923768
[27]: KB2926765
[28]: KB2928680
[29]: KB2931358
[30]: KB2931366
[31]: KB2939153
[32]: KB2939576
[33]: KB2950153
[34]: KB2953522
[35]: KB2954879
[36]: KB2955164
[37]: KB2956575
[38]: KB2957151
[39]: KB2957189
[40]: KB2957689
[41]: KB2958262
[42]: KB2959977
[43]: KB2961908
[44]: KB2962140
[45]: KB2964718
[46]: KB2964736
[47]: KB2965065
[48]: KB2965142
[49]: KB2965500
[50]: KB2965699
[51]: KB2965788
[52]: KB2966072
[53]: KB2966407
[54]: KB2966804
[55]: KB2969817
[56]: KB976002
Network Card(s): 10 NIC(s) Installed.
[01]: Realtek PCIe FE Family Controller
Connection Name: Ethernet
DHCP Enabled: Yes
DHCP Server: N/A
IP address(es)
[02]: Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
Connection Name: Wi-Fi
Status: Hardware
not present
[03]: Hyper-V Virtual Ethernet Adapter
Connection Name: Ethernet 6
Status: Media
disconnected
[04]: Hyper-V Virtual Ethernet Adapter
Connection Name: Ethernet 3
Status: Media
disconnected
[05]: Hyper-V Virtual Ethernet Adapter
Connection Name: Ethernet 5
DHCP Enabled: Yes
DHCP Server: 192.168.1.1
IP address(es)
[01]: 192.168.1.129
[02]: fe80::1513:f368:3c1e:c173
[06]: Hyper-V Virtual Ethernet Adapter
Connection Name: Ethernet 4
DHCP Enabled: No
IP address(es)
[01]: 169.254.80.80
[02]: fe80::4892:9cb3:7a80:2057
[07]: VMware Virtual Ethernet Adapter for VMnet1
Connection Name: VMware Network Adapter VMnet1
DHCP Enabled: No
IP address(es)
[01]: 192.168.223.1
[02]: fe80::a11c:f4d5:c02f:9fcf
[08]: VMware Virtual Ethernet Adapter for VMnet8
Connection Name: VMware Network Adapter VMnet8
DHCP Enabled: No
IP address(es)
[01]: 192.168.132.1
[02]: fe80::fc9a:9075:a71e:776c
[09]: TAP-Windows Adapter V9
Connection Name: Local Area Connection 3
Status: Media
disconnected
[10]: Hyper-V Virtual Ethernet Adapter
Connection Name: vEthernet (TAP-Windows Adapter V9 Virtual Switch)
Status: Media
disconnected
Hyper-V Requirements: A hypervisor has been detected. Features required for Hyper-V will not be displayed.Hi,
In order to assist you, we will need the .DMP files to analyze what exactly occurred at the time of the crash, etc.
If you don't know where .DMP files are located, here's how to get to them:
1. Navigate to the %systemroot%\Minidump folder.
2. Copy any and all DMP files in the Minidump folder to your Desktop and then zip up these files.
3. Upload the zip containing the .DMP files to Onedrive or a hosting site of your choice and paste in your reply. Preferred sites: Onedrive, Mediafire, Dropbox, etc. Nothing with wait-timers, download managers, etc.
4 (optional): The type of .DMP files located in the Minidump folder are known as Small Memory Dumps. In %systemroot% there will be what is known as a Kernel-Dump (if your system is set to generate). It is labeled MEMORY.DMP. The difference
between Small Memory Dumps and Kernel-Dumps in the simplest definition is a Kernel-Dump contains
much more information at the time of the crash, therefore allowing further debugging of your issue. If your upload speed permits it, and you aren't going against any strict bandwidth and/or usage caps, etc, the Kernel-Dump is the best
choice. Do note that Kernel-Dumps are much larger in size due to containing much more info, which is why I mentioned upload speed, etc.
If you are going to use Onedrive but don't know how to upload to it, please visit the following:
Upload photos and files to Onedrive.
After doing that, to learn how to share the link to the file if you are unaware, please visit the following link -
Share files and folders and change permissions and view 'Get a link'.
Please note that any "cleaner" programs such as TuneUpUtilities, CCleaner, etc, by default will delete .DMP files upon use. With this said, if you've run such software, you will need to allow the system to crash once again to generate a crash dump.
If your computer is not generating .DMP files, please do the following:
1. Start > type %systemroot% which should show the Windows folder, click on it. Once inside that folder, ensure there is a Minidump folder created. If not, CTRL-SHIFT-N to make a New Folder and name it Minidump.
2. Windows key + Pause key. This should bring up System. Click Advanced System Settings on the left > Advanced > Performance > Settings > Advanced > Ensure there's a check-mark for 'Automatically manage paging file size for all
drives'.
3. Windows key + Pause key. This should bring up System. Click Advanced System Settings on the left > Advanced > Startup and Recovery > Settings > System Failure > ensure there is a check mark next to 'Write an event to the system
log'.
Ensure Small Memory Dump is selected and ensure the path is %systemroot%\Minidump.
4. Double check that the WERS is ENABLED:
Start > Search > type services.msc > Under the name tab, find Windows Error Reporting Service > If the status of the service is not Started then right click it and select Start. Also ensure that under Startup Type it is set to Automatic rather than
Manual. You can do this by right clicking it, selecting properties, and under General selecting startup type to 'Automatic', and then click Apply.
If you cannot get into normal mode to do any of this, please do this via Safe Mode.
Regards,
Patrick
“Be kind whenever possible. It is always possible.” - Dalai Lama -
BSOD caused by ntkrnlmp.exe
Hello,
One of our clients has an annoying problem with BSODS almost daily cause by ntkrnlmp.exe and I couldn't manage to find what REALLY was the cause. Symbols were properly configure and still no clear infos. If someone can have a look over the Minidumps and/or
Memory.DMP here are both:
https://onedrive.live.com/?cid=E0FCDAC93086F976&id=E0FCDAC93086F976%21123
Thank you,
CozminHi Cozmin V,
This is excessive paged pool usage, this error may occur due to user-mode graphics driver crossing over and passing bad data to the kernel code.
1: kd> !analyze -v
* Bugcheck Analysis
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800030a5aae, Address of the instruction which caused the bugcheck
Arg3: fffff8800864c790, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+26
fffff800`030a5aae f00fba3100 lock btr dword ptr [rcx],0
CONTEXT: fffff8800864c790 -- (.cxr 0xfffff8800864c790)
rax=fffffa80082d63c0 rbx=0000000000000000 rcx=0000000000000000
rdx=fffffa80082d63c0 rsi=00000000ffffffff rdi=fffffa80082d63c0
rip=fffff800030a5aae rsp=fffff8800864d170 rbp=0000000000000001
r8=0000000000000000 r9=fffff96000365ab8 r10=000000000002fcc7
r11=fffff8800864d1c0 r12=0000000000000000 r13=0000000000000001
r14=0000000000000000 r15=fffff900caf4dd30
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+0x26:
fffff800`030a5aae f00fba3100 lock btr dword ptr [rcx],0 ds:002b:00000000`00000000=????????
Resetting default scope
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff9600060dce0 to fffff800030a5aae
STACK_TEXT:
fffff880`0864d170 fffff960`0060dce0 : 00000000`00000000 000001c4`00000000 0000feed`52052bed 00001f80`00000000 : nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+0x26
fffff880`0864d1a0 fffff960`00177748 : 00000000`00000001 fffff900`c00b7010 00000000`00000001 fffff900`caf3c370 : cdd!CddBitmapHw::Release+0xc0
fffff880`0864d1e0 fffff960`002b86b4 : 00000000`00000000 00000000`00000000 fffff900`caf3c370 00000000`00000000 : win32k!SURFACE::bDeleteSurface+0x358
fffff880`0864d330 fffff960`002b8757 : fffff900`c00b7010 00000000`00000001 fffff900`c00b7010 00000000`00000001 : win32k!vDynamicConvertNewSurfaceDCs+0xd8
fffff880`0864d360 fffff960`002b8ff2 : fffff900`c00b7010 00000000`00000001 fffff900`c8e35280 fffff900`c00b7010 : win32k!bDynamicRemoveAllDriverRealizations+0x6f
FOLLOWUP_IP:
cdd!CddBitmapHw::Release+c0
fffff960`0060dce0 488b4738 mov rax,qword ptr [rdi+38h]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: cdd!CddBitmapHw::Release+c0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: cdd
IMAGE_NAME: cdd.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7c546
STACK_COMMAND: .cxr 0xfffff8800864c790 ; kb
FAILURE_BUCKET_ID: X64_0x3B_cdd!CddBitmapHw::Release+c0
BUCKET_ID: X64_0x3B_cdd!CddBitmapHw::Release+c0
Followup: MachineOwner
1: kd> lmvm cdd
start end module name
fffff960`00600000 fffff960`00627000 cdd (pdb symbols) c:\symbols\cdd.pdb\88BFB882815849F88656925A7675F2BA1\cdd.pdb
Loaded symbol image file: cdd.dll
Mapped memory image file: c:\symbols\cdd.dll\4CE7C54627000\cdd.dll
Image path: \SystemRoot\System32\cdd.dll
Image name: cdd.dll
Timestamp: Sat Nov 20 20:55:34 2010 (4CE7C546)
CheckSum: 0002D4F0
ImageSize: 00027000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
1: kd> lmtsmn
start end module name
fffff880`00f18000 fffff880`00f6f000 ACPI ACPI.sys Sat Nov 20 17:19:16 2010 (4CE79294)
fffff880`068fd000 fffff880`0697d000 ADIHdAud ADIHdAud.sys Wed Jun 16 03:36:52 2010 (4C17D654)
fffff880`048df000 fffff880`04968000 afd afd.sys Sat Nov 20 17:23:27 2010 (4CE7938F)
fffff880`04a39000 fffff880`04a4f000 AgileVpn AgileVpn.sys Tue Jul 14 08:10:24 2009 (4A5BCCF0)
fffff880`02ec4000 fffff880`02ed7180 aksdf aksdf.sys Mon Nov 21 19:09:56 2011 (4ECA3184)
fffff880`032da000 fffff880`032fae00 aksfridge aksfridge.sys Tue Aug 07 18:34:40 2012 (5020EF40)
fffff880`017f2000 fffff880`017fd000 amdxata amdxata.sys Sat Mar 20 00:18:18 2010 (4BA3A3CA)
fffff880`01e50000 fffff880`01e65000 appid appid.sys Sat Nov 20 18:14:37 2010 (4CE79F8D)
fffff880`078fb000 fffff880`07906000 asyncmac asyncmac.sys Tue Jul 14 08:10:13 2009 (4A5BCCE5)
fffff880`013b2000 fffff880`013bb000 atapi atapi.sys Tue Jul 14 07:19:47 2009 (4A5BC113)
fffff880`013bb000 fffff880`013e5000 ataport ataport.SYS Sat Nov 20 17:19:15 2010 (4CE79293)
fffff960`00870000 fffff960`008d1000 ATMFD ATMFD.DLL Sat Nov 20 17:49:28 2010 (4CE799A8)
fffff880`00fe0000 fffff880`00fec000 BATTC BATTC.SYS Tue Jul 14 07:31:01 2009 (4A5BC3B5)
fffff880`04409000 fffff880`04410000 Beep Beep.SYS Tue Jul 14 08:00:13 2009 (4A5BCA8D)
fffff880`04b76000 fffff880`04b87000 blbdrive blbdrive.sys Tue Jul 14 07:35:59 2009 (4A5BC4DF)
fffff880`02fb1000 fffff880`02fcf000 bowser bowser.sys Wed Feb 23 12:55:04 2011 (4D649328)
fffff960`00600000 fffff960`00627000 cdd cdd.dll Sat Nov 20 20:55:34 2010 (4CE7C546)
Unloaded modules:
fffff880`078b6000 fffff880`078c4000 monitor.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`078a8000 fffff880`078b6000 monitor.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`0789a000 fffff880`078a8000 monitor.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`0788c000 fffff880`0789a000 monitor.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`0787e000 fffff880`0788c000 monitor.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
By checking your DMP file, we also found it related to cdd.dll which is the Canonical Display Driver from Microsoft, it's a system file. You could refer to this link for more information about cdd and bitmap
http://answers.microsoft.com/en-us/windows/forum/windows_7-system/bluescreen-error-when-alttabbing-out-of-full/267be931-70b1-482f-8164-c3cd8084def0
We suggest you replace your graphic/display driver and keep them up to date, then check the issue again.
Also you have a lot of outdated drivers on your system including cdd.dll. Please update these drivers for good measure.
If you're still crashing after all of the above, enable Driver Verifier to look for further corruption:
Driver Verifier:
What is Driver Verifier?
Driver Verifier is included in Windows 8, 7, Windows Server 2008 R2, Windows Vista, Windows Server 2008, Windows 2000, Windows XP, and Windows Server 2003 to promote stability and reliability; you can use this tool to troubleshoot driver issues. Windows
kernel-mode components can cause system corruption or system failures as a result of an improperly written driver, such as an earlier version of a Windows Driver Model (WDM) driver.
Essentially, if there's a 3rd party driver believed to be at issue, enabling Driver Verifier will help flush out the rogue driver if it detects a violation.
Note: Before enabling Driver Verifier, it is recommended to create a System Restore Point
For more information about Driver Verifier
https://msdn.microsoft.com/en-us/library/windows/hardware/ff545448(v=vs.85).aspx -
indows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (12 procs) Free x64
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Built by: 6002.18327.amd64fre.vistasp2_gdr.101014-0432
Machine Name:
Kernel base = 0xfffff800`01847000 PsLoadedModuleList = 0xfffff800`01a0bdd0
Debug session time: Mon Nov 3 05:27:34.976 2014 (UTC - 5:00)
System Uptime: 81 days 16:48:21.023
* Bugcheck Analysis *
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff9600007f200, Address of the instruction which caused the bugcheck
Arg3: fffffa60155fff70, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
win32k!PFEOBJ::vFreepfdg+e8
fffff960`0007f200 0fba60300f bt dword ptr [rax+30h],0Fh
CONTEXT: fffffa60155fff70 -- (.cxr 0xfffffa60155fff70)
rax=000000000002f6bc rbx=0000000000000000 rcx=fffff900c1fad250
rdx=fffffa82bc20a330 rsi=fffff900c327a940 rdi=fffffa6015600820
rip=fffff9600007f200 rsp=fffffa60156007d0 rbp=0000000000000000
r8=0000000000000000 r9=000000000003fb36 r10=0000000000000000
r11=fffffa82aa1d6bb0 r12=0000000000000000 r13=0000000000000000
r14=000000000000491f r15=0000000000000001
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010203
win32k!PFEOBJ::vFreepfdg+0xe8:
fffff960`0007f200 0fba60300f bt dword ptr [rax+30h],0Fh ds:002b:00000000`0002f6ec=????????
Resetting default scope
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT_SERVER
BUGCHECK_STR: 0x3B
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff96000244030 to fffff9600007f200
STACK_TEXT:
fffffa60`156007d0 fffff960`00244030 : 00000000`00000000 fffffa82`bc20a300 00000000`00000001 00000000`0000491f : win32k!PFEOBJ::vFreepfdg+0xe8
fffffa60`15600800 fffff960`0024e647 : 00000000`00000000 fffff900`c0092000 fffff900`c0010000 00000000`00000000 : win32k!RFONTOBJ::vDeleteRFONT+0x210
fffffa60`15600860 fffff960`0024e2ba : 00000000`00000000 fffff900`c1eb4010 fffff900`c1eb4010 fffff900`c2c773a0 : win32k!vRestartKillRFONTList+0xab
fffffa60`156008b0 fffff960`000f9bc2 : fffff900`c08ac998 fffff900`c2685350 00000000`00000000 fffff900`00000001 : win32k!PFTOBJ::bUnloadWorkhorse+0x196
fffffa60`15600930 fffff960`000fa7a1 : fffff900`c08ac910 00000000`00000000 00000000`00000001 00000000`00000001 : win32k!vCleanupPrivateFonts+0x72
fffffa60`15600970 fffff960`000eebc4 : 00000000`00000000 00000000`00000000 fffff900`c2621180 00000000`ffffffff : win32k!NtGdiCloseProcess+0x479
fffffa60`156009d0 fffff960`000ee42b : 00000000`00000000 fffff900`c2621180 00000000`00000000 00000000`00000000 : win32k!GdiProcessCallout+0x1f4
fffffa60`15600a50 fffff800`01afa77c : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa82`aa1d6bb0 : win32k!W32pProcessCallout+0x6f
fffffa60`15600a80 fffff800`01afcc7d : 00000000`00000000 fffffa82`aa1d6b01 00000000`00000000 00000000`00000000 : nt!PspExitThread+0x41c
fffffa60`15600b70 fffff800`01aed942 : 00000000`00000000 00000000`0000000c 00000000`fffdd000 fffff880`0000000c : nt!PspTerminateThreadByPointer+0x4d
fffffa60`15600bc0 fffff800`018a0f33 : fffffa82`ab4eac10 fffffa82`aa1d6bb0 fffffa60`15600ca0 00000000`fffdd000 : nt!NtTerminateProcess+0xfa
fffffa60`15600c20 00000000`779d6e5a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0007ded8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x779d6e5a
FOLLOWUP_IP:
win32k!PFEOBJ::vFreepfdg+e8
fffff960`0007f200 0fba60300f bt dword ptr [rax+30h],0Fh
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!PFEOBJ::vFreepfdg+e8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4de794fc
STACK_COMMAND: .cxr 0xfffffa60155fff70 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!PFEOBJ::vFreepfdg+e8
BUCKET_ID: X64_0x3B_win32k!PFEOBJ::vFreepfdg+e8
Followup: MachineOwnerHi,
Would you please let me know whether had done any change before this issue occurred? For examples, install
any third-party application (chrome.exe) or any other? Meanwhile, would you please let me confirm whether this issue occurred regularly?
For Bug Check 0x3B, it indicates that an exception happened while executing a routine that transitions from
non-privileged code to privileged code. For more details, please refer to following article and check if can help you.
Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION
Please update drivers and install all necessary Windows Updates, then monitor the result. If this issue still
exists, please perform a
clean boot. Any difference?
By the way, it may be not effective for us to debug the crash dump file here in the forum. If this issues is a state of emergency for you. Please contact Microsoft Customer
Service and Support (CSS) via telephone so that a dedicated Support Professional can assist with your request.
To obtain the phone numbers for specific technology request, please refer to the web site listed below:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;OfferProPhone#faq607
Hope this helps.
Best regards,
Justin Gu -
Touchsmart 310-1110uk - BSoD caused by ntoskrnl.exe
I have had seemingly random Blue Screens of Death when shutting down on my HP Touchsmart 310-1110uk over the last few months. Sometimes when shutting down, the "Shutting down..." message is displayed for a long time and then the BSoD appears. This only happens occasionally and most of the time it shuts down fine. The blue screen only ever appears when shutting down.
It seemed to happen when Connectify was running but after looking into Connectify BSoD problems it seems that this bug was fixed after version 3, and I am running 3.3.0.23104 Pro. Therefore I don't think Connectify is the problem.
I have uploaded the a .zip of the dump files from "C:\Windows\Minidumps" to Dropbox here:
http://dl.dropbox.com/u/9154836/Minidump.zip
I have also downloaded BlueScreenView to try and analyse the error logs. Most of the crashes seem to be the same with the following:
Bug Check String: DRIVER_POWER_STATE_FAILURE
Bug Check Code: 0x0000009f
Caused By Driver: ntoskrnl.exe
Caused By Address: [mostly "ntoskrnl.exe+7cd40" or "ntoskrnl.exe+7cc40"]
I have uploaded the full HTML BlueScreenView report here:
http://dl.dropbox.com/u/9154836/report.html
I haven't installed many programs which might have caused the problem. This has been happening since November 2011 and the only thing I installed around then was Connectify.
From what I can tell it seems to be a driver issue, but because this only happens occasionally (at seemingly random times when shutting down) it's almost impossible to troubleshoot by disabling individual drivers (i.e. trial and error).
I would appreciate some help on this, if you could provide some guidance on fixing this or ask for more specific information.I have had seemingly random Blue Screens of Death when shutting down on my HP Touchsmart 310-1110uk over the last few months. Sometimes when shutting down, the "Shutting down..." message is displayed for a long time and then the BSoD appears. This only happens occasionally and most of the time it shuts down fine. The blue screen only ever appears when shutting down.
It seemed to happen when Connectify was running but after looking into Connectify BSoD problems it seems that this bug was fixed after version 3, and I am running 3.3.0.23104 Pro. Therefore I don't think Connectify is the problem.
I have uploaded the a .zip of the dump files from "C:\Windows\Minidumps" to Dropbox here:
http://dl.dropbox.com/u/9154836/Minidump.zip
I have also downloaded BlueScreenView to try and analyse the error logs. Most of the crashes seem to be the same with the following:
Bug Check String: DRIVER_POWER_STATE_FAILURE
Bug Check Code: 0x0000009f
Caused By Driver: ntoskrnl.exe
Caused By Address: [mostly "ntoskrnl.exe+7cd40" or "ntoskrnl.exe+7cc40"]
I have uploaded the full HTML BlueScreenView report here:
http://dl.dropbox.com/u/9154836/report.html
I haven't installed many programs which might have caused the problem. This has been happening since November 2011 and the only thing I installed around then was Connectify.
From what I can tell it seems to be a driver issue, but because this only happens occasionally (at seemingly random times when shutting down) it's almost impossible to troubleshoot by disabling individual drivers (i.e. trial and error).
I would appreciate some help on this, if you could provide some guidance on fixing this or ask for more specific information.
Maybe you are looking for
-
Improving the performance of Crystal Reports for Eclipse 2.0
Hi, I am having some performance issues with displaying reports where it can take upto 30 seconds per user for each new session for the report to display. If we run this directly from the client (through Crystal 2008) it takes about 2 seconds. The pr
-
Clean install on ext hard drive
I have a new 21" iMac arriving and plan on using external drives rather than the internal one. It's my first time installing OS X from the App Store to a new hard drive so I want to make sure I have the procedure correct. From what I've read I can bo
-
How do I make iOS 5 photo edits permanent?
In iOS5 on the iPhone 4 when I edit my photos (crop, adjust color, etc) with the built-in photo editing tools, the photos look fine on the iphone, but when I upload them to my PC, they are not edited... they are the original uncropped, unmodified pho
-
Ipod nano and photos acting all weird ?
i have an ipod nano im having trouble with the photos...ok i know how to put them on and all...i wont to be able to put a photo on my ipod then be able to delet it off my pc and still be on my nano but its not....???? it delets the photos from my nan
-
I am unable to access my iBooks library from my iPad through the iBooks App. Recent changes to the app says I require IOS 5.0 which I don't have because I have the original IOS that came with my iPad (the original released version) I have an extensiv