Computer has reboots itself
Since installing Mavericks about 10 days ago, I have had two instances where my computer has reboot by itself.
Anyone else having this problem? Working on a 27in iMac Late 2009
Sounds like kernel panics.
See: OS X: When your computer spontaneously restarts or displays "Your computer restarted because of a problem."
Similar Messages
-
Hello,
A terminal server rebooted itself out of nowhere and I see the following error in the eventviewer:
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date:
11-9-2014 9:25:38
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SERVERNAME
Description:
The computer has rebooted from a bugcheck. The bugcheck was:
0x000000f4
(0x0000000000000003, 0xfffffa800a9f4130, 0xfffffa800a9f4410,
0xfffff80001be0270). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id:
091114-107781-01.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-09-11T07:25:38.000000000Z" />
<EventRecordID>450694</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>TERM-LYSIAS-02</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x000000f4 (0x0000000000000003, 0xfffffa800a9f4130, 0xfffffa800a9f4410, 0xfffff80001be0270)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">091114-107781-01</Data>
</EventData>
</Event>
Anyone who can help out here?
Thanks, RenseI analyzed the errors with BlueScreenViewer and noticed that the driver ntoskrnl.exe causes the server to reboot. A normal chkdsk or sfc /scannow couldn't find anything.
Using chkdsk /r /f gave me the following log:
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.
So I can't check if this solved the problem, but I hope it did.
Rense -
I have Windows 7 Ultimate 32bit ,and reboot several times in a day by itself .The event log show this:
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 2/11/2011 19:46:03
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: V_M-PC
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x80741004, 0x00000002, 0x00000001, 0x82acc4a8). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 021111-24102-01.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-02-11T18:46:03.000000000Z" />
<EventRecordID>84158</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>V_M-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x0000000a (0x80741004, 0x00000002, 0x00000001, 0x82acc4a8)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">021111-24102-01</Data>
</EventData>
</Event>
what is wrong ?? what a need to do ??I'm getting a similar problem...
Number 1
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-02-11T10:03:17.000000000Z" />
<EventRecordID>66460</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>V2SATIRE</Computer>
<Security />
</System>
- <EventData>
<Data Name="param1">0x0000000a (0x80741004, 0x00000002, 0x00000001, 0x82d094a8)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">021111-28126-01</Data>
</EventData>
</Event>
Number 2
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-02-13T10:03:32.000000000Z" />
<EventRecordID>67228</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>v2Satire</Computer>
<Security />
</System>
- <EventData>
<Data Name="param1">0x0000000a (0x80741004, 0x00000002, 0x00000001, 0x82cc64a8)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">021311-21340-01</Data>
</EventData>
</Event> -
Hi All
I formatted and installed Win8.1 (64-bit) recently on my PC but have constantly had BSOD with faults like:
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 27/11/2014 09:40:21
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: PC1
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff8025714c975, 0xffffd001186a85f0, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112714-32125-01.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-11-27T09:40:21.000000000Z" />
<EventRecordID>8488</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>PC1</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x0000003b (0x00000000c0000005, 0xfffff8025714c975, 0xffffd001186a85f0, 0x0000000000000000)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">112714-32125-01</Data>
</EventData>
</Event>
I've had others but this is the most recent. I ran the Nvidia scanner and loaded the video drivers it recommends (340.52). I've got two GeForce 8800GTX cards connected with SLI cable. I've tried turning SLI off as well. I also removed and re-seated the cards.
I also just replaced the RAM with another 4GB brand new from a supplier (240pin DDR2 DIMM UNBUFF.PC2 - 6400 CL6).
It crashed about once a day, totally randomly, sometimes when idle.
I zipped a copy of the DUMP file and MSINFO32 file to my OneDrive but I don't know if I need / how to share it (please advise if necessary).
I would be very grateful for a solution.
Regards
MarkOk, here is what I think. The MEMORY.DMP you provided was older and basically less helpful than what was recorded in the MSIinfo file. You are on the right track in your thinking that the crashes are related to
GeForce 8800GTX cards, so I am going to suggest an uninstall and "clean" reinstall of the current driver.
If no joy, try an older driver.
btw, apologies for the voluminous post...
25/11/2014 12:31 Windows Error Reporting Fault bucket
AV_nvlddmkm!CNvLChannelNonLegacy::pipelineGPFifoBlit, type 0
Event Name:
BlueScreen
Response:
http://wer.microsoft.com/responses/resredir.aspx?sid=10&Bucket=AV_nvlddmkm!CNvLChannelNonLegacy::pipelineGPFifoBlit&State=1&ID=e2e8a1cf-86d8-4a37-806c-7d971c8a16d6
Cab Id: e2e8a1cf-86d8-4a37-806c-7d971c8a16d6

Problem
signature:
P1: d1
P2: fffffffffffffff1
P3: 2
P4: 1
P5: fffff801ca3d1440
P6: 6_3_9600
P7: 0_0
P8:
768_1
P9: 
P10: 

Attached files:
C:\Windows\Minidump\112514-33906-01.dmp
C:\Users\Mark\AppData\Local\Temp\WER-95625-0.sysdata.xml
C:\Windows\MEMORY.DMP
C:\Users\Mark\AppData\Local\Temp\WERCED4.tmp.WERInternalMetadata.xml

These
files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_d1_a7d30b578e595ab79ff817b74f971d37c1e8e_00000000_cab_10a9e058

Analysis symbol: 
Rechecking
for solution: 0
Report ID: 112514-33906-01
Report Status: 0
Hashed bucket:
24/11/2014 17:22 Windows Error Reporting Fault bucket AV_nvlddmkm!vblankCallback, type 0
Event Name: BlueScreen
Response:
http://wer.microsoft.com/responses/resredir.aspx?sid=10&Bucket=AV_nvlddmkm!vblankCallback&State=1&ID=f616ba0f-2c01-41f5-bfc4-82489997cecc
Cab Id: f616ba0f-2c01-41f5-bfc4-82489997cecc

Problem
signature:
P1: d1
P2: 5e
P3: 6
P4: 1
P5: fffff80075721912
P6: 6_3_9600
P7: 0_0
P8:
768_1
P9: 
P10: 

Attached files:
C:\Windows\Minidump\112314-37250-01.dmp
C:\Users\Mark\AppData\Local\Temp\WER-86718-0.sysdata.xml
C:\Windows\MEMORY.DMP
C:\Users\Mark\AppData\Local\Temp\WER684A.tmp.WERInternalMetadata.xml

These
files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_d1_79675c223622dece3b44f5ae297e5b3f6af5349_00000000_cab_04d8b9c0

Analysis symbol: 
Rechecking
for solution: 0
Report ID: 112314-37250-01
Report Status: 0
Hashed bucket:
23/11/2014 18:03 Windows Error Reporting Fault bucket , type 0
Event Name:
BlueScreen
Response: Not available
Cab Id: 0

Problem signature:
P1: d1
P2: 5e
P3:
6
P4: 1
P5: fffff80075721912
P6: 6_3_9600
P7: 0_0
P8: 768_1
P9: 
P10: 

Attached
files:
C:\Windows\Minidump\112314-37250-01.dmp
C:\Users\Mark\AppData\Local\Temp\WER-86718-0.sysdata.xml
C:\Windows\MEMORY.DMP
C:\Users\Mark\AppData\Local\Temp\WER684A.tmp.WERInternalMetadata.xml

These
files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_d1_79675c223622dece3b44f5ae297e5b3f6af5349_00000000_cab_0d89e73e

Analysis symbol: 
Rechecking
for solution: 0
Report ID: 112314-37250-01
Report Status: 100
Hashed bucket:
24/11/2014 17:22 Windows Error Reporting Fault bucket -421640870, type 5
Event Name:
PnPDeviceProblemCode
Response: Not available
Cab Id: 0

Problem signature:
P1: x64
P2:
PCI\VEN_10DE&DEV_0191&SUBSYS_22501682&REV_A2
P3: {4d36e968-e325-11ce-bfc1-08002be10318}
P4: 0000001F
P5: BasicDisplay.sys
P6: 6.3.9600.16384
P7:
08-22-2013
P8: 
P9: 
P10: 

Attached files:
C:\Windows\Temp\DMID706.tmp.log.xml
C:\Windows\Temp\LOGD727.tmp
C:\Windows\Inf\display.inf

These
files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_24eb8c9ed87f37eac11320981cbf81446b69288_00000000_cab_0764d745

Analysis symbol: 
Rechecking
for solution: 0
Report ID: 54413262-6e57-11e4-824e-c58295c96ec1
Report Status: 8
Hashed bucket: adb5d63b7478974f8d85c5ec03d74566
Sorted by: Device ID
Device Id
Chip Description
Vendor Id
Vendor Name
0x0191
SIS191
0x1039
Silicon Integrated Systems
0x0191
NVIDIA GeForce 8800 GTX
0x10DE
NVIDIA
0x0660
HD Audio
0x10EC
Realtek Semiconductor Corp
0x0191
CMI 8738 8CH Sound Card
0x13F6
C-Media Electronics Inc. -
Hi,
I have an issue in my with my one of my Windows 2012 Failover node. One server was rebooted unexpectedly and i found the event id 1001 BugChecks
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000009e (0xfffffa8036f00980, 0x000000000000003c, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 092614-45458-01.
Any solution ?
Regards
KrisHi Lotusnotes,
Please also refer to following article and check if can help you.
Why
is my Failover Clustering node blue screening with a Stop 0x0000009E?
In addition, troubleshoot this kind of kernel crash issue, we need to analyze the crash dump file to narrow down the root cause of the issue. You can refer to following articles
and check if can help you to analyze dump files.
Analyzing a Kernel-Mode Dump File
How to read the small memory dump file that is created by Windows if a crash occurs
Meanwhile, if this issues is a state of emergency for you. Please contact Microsoft Customer Service and Support (CSS) via telephone so that a dedicated Support Professional
can assist with your request.
To obtain the phone numbers for specific technology request, please refer to the web site listed below:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;OfferProPhone#faq607
If any update, please feel free to let us know.
Hope this helps.
Best regards,
Justin Gu -
The computer has rebooted from a bugcheck. The bugcheck was: 0x0bad1001
I would like to know how to troubleshoot this issue.
The computer has rebooted from a bugcheck. The bugcheck was: 0x0bad1001 (0x00000000000d04fd, 0xffffd00022fb6388, 0xffffd00022fb5b90, 0xfffff803552f9916). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 070114-140796-01.
I'm not able to upload C:\WINDOWS\MEMORY.DMP because the file size is too big 1.41 GB
Any idea what is causing this proplem?
Thank in advance.Hi,
The dump file shows the message as below:
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck BAD1001, {d04fd, ffffd00022fb6388, ffffd00022fb5b90, fffff803552f9916}
Probably caused by : klvfs.sys ( klvfs+6044 )
Followup: MachineOwner
the klvfs.sys file is responsible for this, the file means a Kaspersky software is installed on your computer, in this case I suggest to remove this software to see the result, meanwhile I suggest to turn to Kaspersky for the compatibility with Windows 8
at:
http://support.kaspersky.com/
Regards
Wade Liu
TechNet Community Support -
I have a Virtual server that reboots several times a day with the following event:
Bugcheck Error:
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xfffff880009b8180, 0x0000000000000001). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 061714-74859-01.
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider
Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck"
/>
<EventID
Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated
SystemTime="2014-06-17T07:05:57.000000000Z" />
<EventRecordID>53764</EventRecordID>
<Correlation
/>
<Execution
ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>CLOUDBOX17812</Computer>
<Security
/>
</System>
- <EventData>
<Data Name="param1">0x00000101 (0x0000000000000030,
0x0000000000000000, 0xfffff880009b8180, 0x0000000000000001)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">061714-74859-01</Data>
</EventData>
</Event>
Critical Kernel-Power:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider
Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated
SystemTime="2014-06-17T07:04:13.937500000Z" />
<EventRecordID>53765</EventRecordID>
<Correlation
/>
<Execution
ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>CLOUDBOX17812</Computer>
<Security
UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="BugcheckCode">257</Data>
<Data Name="BugcheckParameter1">0x30</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0xfffff880009b8180</Data>
<Data Name="BugcheckParameter4">0x1</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event>
I searched on Google and most answers are about a HotFix for servers with a specific Intel Processor and Hyper-V installed, but this is a Virtual Server so Hyper-V is not installed obviously.
Any help is appreciated.
Regards,
Paul Ruedisueli
A.i Automatisering B.V.
The NetherlandsHi,
Thanks for your posting.
It seems to be system crash issue and we need to analyze the crash dump file to narrow down the root cause of the issue. Unfortunately, it is not effective for us to debug the crash dump file here in the forum.
I think you have read this kb article?
http://support.microsoft.com/kb/975530/en-au
Regards.
Vivian Wang -
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116
Every once in a while my computer will randomly hard restart its self in the middle of a game and when i check the event viewer it gives me this
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 3/18/2014 12:06:10 AM
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer:
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116 (0xfffffa800d777250, 0xfffff88006d7f694, 0xffffffffc000009a, 0x0000000000000004). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 031814-15381-01.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-03-18T04:06:10.000000000Z" />
<EventRecordID>131951</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>GUARDIANTC-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x00000116 (0xfffffa800d777250, 0xfffff88006d7f694, 0xffffffffc000009a, 0x0000000000000004)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">031814-15381-01</Data>
</EventData>
</Event>Unfortunately your post is off topic here, in the TechNet Site Feedback forum, because it is not Feedback about the TechNet Website or Subscription. This is a standard response I’ve written up in advance to help many people (thousands, really.)
who post their question in this forum in error, but please don’t ignore it. The links I share below I’ve collected to help you get right where you need to go with your issue.
For technical issues with Microsoft products that you would run into as an
end user of those products, one great source of info and help is
http://answers.microsoft.com, which has sections for Windows, Hotmail, Office, IE, and other products. Office related forums are also here:
http://office.microsoft.com/en-us/support/contact-us-FX103894077.aspx
For Technical issues with Microsoft products that you might have as an
IT professional (like technical installation issues, or other IT issues), you should head to the TechNet Discussion forums at
http://social.technet.microsoft.com/forums/en-us, and search for your product name.
For issues with products you might have as a Developer (like how to talk to APIs, what version of software do what, or other developer issues), you should head to the MSDN discussion forums at
http://social.msdn.microsoft.com/forums/en-us, and search for your product or issue.
If you’re asking a question particularly about one of the Microsoft Dynamics products, a great place to start is here:
http://community.dynamics.com/
If you really think your issue is related to the subscription or the TechNet Website, and I screwed up, I apologize! Please repost your question to the discussion forum and include much more detail about your problem, that could include screenshots
of the issue (do not include subscription information or product keys in your screenshots!), and/or links to the problem you’re seeing.
If you really had no idea where to post this question but you still posted it here, you still shouldn’t have because we have a forum just for you! It’s called the Where is the forum for…? forum and it’s here:
http://social.msdn.microsoft.com/forums/en-us/whatforum/
Moving to off topic.
Thanks, Mike
MSDN and TechNet Subscriptions Support <br/> Read the Subscriptions <a href="http://blogs.msdn.com/msdnsubscriptions">Blog! </a> -
The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1
The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x0000000000000000, 0x0000000000000002, 0x0000000000000000, 0xfffff80003cf33f7). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041715-27750-01.
https://drive.google.com/file/d/0BzDs1bdKVqlAcU9CZ3BMY2M3Wnk5eVV0WkhFWG9kYmRsaEtz/view?usp=sharingMH
This was related to the NETwbw02.sys Intel® Wireless WiFi Link Driver from Intel Corporation. I would remove the current driver and install the newest driver available
If you continue to crash I would remove Kaspersky and use the built in defender.
Microsoft (R) Windows Debugger Version 6.3.9600.17298 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\zigza\Desktop\041715-27750-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*D:\Symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*D:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.16384.amd64fre.winblue_rtm.130821-1623
Machine Name:
Kernel base = 0xfffff800`b7871000 PsLoadedModuleList = 0xfffff800`b7b389b0
Debug session time: Fri Apr 17 16:30:22.174 2015 (UTC - 4:00)
System Uptime: 0 days 0:00:10.822
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
* Bugcheck Analysis *
Use !analyze -v to get detailed debugging information.
BugCheck D1, {0, 2, 0, fffff80003cf33f7}
*** WARNING: Unable to verify timestamp for NETwbw02.sys
*** ERROR: Module load completed but symbols could not be loaded for NETwbw02.sys
Probably caused by : NETwbw02.sys ( NETwbw02+993f7 )
Followup: MachineOwner
0: kd> !analyze -v
* Bugcheck Analysis *
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000000, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff80003cf33f7, address which referenced memory
Debugging Details:
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800b7bc1150
GetUlongFromAddress: unable to read from fffff800b7bc1208
0000000000000000 Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
NETwbw02+993f7
fffff800`03cf33f7 488b09 mov rcx,qword ptr [rcx]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
DPC_STACK_BASE: FFFFF800B9C46FB0
TRAP_FRAME: fffff800b9c3f6b0 -- (.trap 0xfffff800b9c3f6b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe00004f2ed70 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003cf33f7 rsp=fffff800b9c3f840 rbp=ffffe00004fd9890
r8=fffff800b9c3f890 r9=0000000000000000 r10=fffff800b7b62180
r11=fffff800b9c3f870 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
NETwbw02+0x993f7:
fffff800`03cf33f7 488b09 mov rcx,qword ptr [rcx] ds:00000000`00000000=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800b79ccbe9 to fffff800b79c10a0
STACK_TEXT:
fffff800`b9c3f568 fffff800`b79ccbe9 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`b9c3f570 fffff800`b79cb43a : 00000000`00000000 00000000`00000000 ffff4ce4`1dc3da00 fffff800`b9c3f6b0 : nt!KiBugCheckDispatch+0x69
fffff800`b9c3f6b0 fffff800`03cf33f7 : 00000000`00000285 00000000`00000000 00000000`00000000 ffffe000`05be4ca0 : nt!KiPageFault+0x23a
fffff800`b9c3f840 00000000`00000285 : 00000000`00000000 00000000`00000000 ffffe000`05be4ca0 fffff800`03e62df0 : NETwbw02+0x993f7
fffff800`b9c3f848 00000000`00000000 : 00000000`00000000 ffffe000`05be4ca0 fffff800`03e62df0 ffffe000`04fd9540 : 0x285
STACK_COMMAND: kb
FOLLOWUP_IP:
NETwbw02+993f7
fffff800`03cf33f7 488b09 mov rcx,qword ptr [rcx]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: NETwbw02+993f7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETwbw02
IMAGE_NAME: NETwbw02.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 52a09c3a
FAILURE_BUCKET_ID: AV_NETwbw02+993f7
BUCKET_ID: AV_NETwbw02+993f7
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_netwbw02+993f7
FAILURE_ID_HASH: {1e0ec353-2360-690e-9374-7a77832276f2}
Followup: MachineOwner
Wanikiya and Dyami--Team Zigzag -
I had the following issue on Windows Server 2008 R2 Enterprise. I want to know if it's relarted with a specific driver in orider to avoid this happend again.
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffff80000003, 0xfffff80001a8d016, 0xfffff880029eb788, 0xfffff880029eafe0). A dump was saved
in: C:WindowsMEMORY.DMP. Report Id: .
The dump is uploaded to the following skydrive link:
https://skydrive.live.com/?cid=FE2E04A1A3CB9D1D&id=FE2E04A1A3CB9D1D%21150
Please Could someone help me to know to witch is related?
Regards.
Juan.thanks a lot for the answer!
the expeption code of the bugcheck is the following:
0x80000002: STATUS_DATATYPE_MISALIGNMENT indicates an unaligned data reference was encountered
I'm checking the drivers...maybe is related with some drivers installed in the system.
Is there any way to check the dump and confirm to witch driver is related?
Regards.
Juan. -
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050
I would like to know how to troubleshoot this issue.
I did the firmware/driver/patch updates for multiple Hyper-V cluster just before the Christmas break. We have all HP DL580 boxes. All went well however, in observed issues with two nodes on a cluster. These two servers are getting BSOD every seven days.
I am observing the pattern and happening almost same time every seven days.
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8a1227fd6a4, 0x0000000000000000, 0xfffff88001e8587a, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 011614-56799-01.
I am contacting HP for support, however any tips will be appreciated !
For every expert, there is an equal and opposite expert. - Becker's Law
My blog on Virtualization - InsideVirtualization.comHi Shabarinath,
Regarding to the BugCheck 0x50, please refer to the following articles. Then follow the resolution there and check if fix the issue.
Bug Check 0x50: PAGE_FAULT_IN_NONPAGED_AREA
http://msdn.microsoft.com/en-us/library/ff559023(v=vs.85).aspx
Based on your description, those two servers get BSOD every seven days. Would you please check if BSOD occurred at same time-point (occurred at same hour every
seven days)?
Meanwhile, I can find that you have got the Dump files. So, please refer to the following KB and use the Windows Debugger (WinDbg.exe) tool to analyze those dump
files. It will help you to narrow down this issue.
How to read the small memory dump file that is created by Windows if a crash occurs
http://support.microsoft.com/kb/315263/en-us
You also can upload those dump files to
SkyDrive,
then post the link here. We will be able to get dump files.Please note, the dump files that upload to SkyDrive will be public.
If this issues is a state of emergency for you. I suggest you should contact Microsoft Customer Service and Support (CSS) via telephone, so that a dedicated Support
Professional can assist with your request. Since, it is not effective for us to debug the crash dump file here in the forum. Thanks for your understanding.
To obtain the phone numbers for specific technology request, please refer to the web site listed below:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;OfferProPhone#faq607
Hope this helps.
Best regards,
Justin Gu -
The computer has rebooted from a bugcheck
Dear all,
One of our server is rebooting and giving these 2 errors. Kindly help on how to fix it.
Event ID: 1001
Level: Error
Source: BugCheck
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0xffffffff80000002, 0xe0000106532832e4, 0xe0000106544c9d70, 0x0000000000000000). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 062214-41630-01.
The other error comes with above error is
Event ID: 41
Level: Critical
Source: Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
The Server OS is Windows Server 2008 R2 for Itanium based Systems, it's HP blade server Model IA64
Kindly help!
Best regards,Dear Milos
Thanks for your response, can you share the link for downloading these tools ?
WinDbg (or at least view it with Nirsoft BSOD viewer
best regards,
Aqeel -
Computer has rebooted from a bugcheck windows 8.1
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe001ad9b05d8, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\021715-15656-01.dmp. Report Id: 021715-15656-01.
My computer is rebooting and that's the error I'm getting in the event viewer. A link to the dump can be found below. Please help and thank you.Patrick
Better and no worries it happens
These are called BCC124 and are related to hardware. Read how to diagnose and hopefully to fix them read this
wiki
Since they refer to "authentic AMD" I would start by running a CPU stress test
Microsoft (R) Windows Debugger Version 6.3.9600.17298 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Ken\Desktop\021715-15656-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
WARNING: Whitespace at start of path element
WARNING: Whitespace at end of path element
Error: Empty Path.
Symbol search path is:
SRV*e:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 9600.17328.amd64fre.winblue_r3.140827-1500
Machine Name:
Kernel base = 0xfffff802`cca1a000 PsLoadedModuleList = 0xfffff802`cccf0370
Debug session time: Tue Feb 17 08:37:15.708 2015 (UTC - 5:00)
System Uptime: 0 days 0:00:06.408
Loading Kernel Symbols
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
Loading User Symbols
Mini Kernel Dump does not contain unloaded driver list
* Bugcheck Analysis *
Use !analyze -v to get detailed debugging information.
BugCheck 124, {0, ffffe001ad9b05d8, 0, 0}
Probably caused by : AuthenticAMD
Followup: MachineOwner
0: kd> !analyze -v
* Bugcheck Analysis *
WHEA_UNCORRECTABLE_ERROR (124)
A fatal hardware error has occurred. Parameter 1 identifies the type of error
source that reported the error. Parameter 2 holds the address of the
WHEA_ERROR_RECORD structure that describes the error conditon.
Arguments:
Arg1: 0000000000000000, Machine Check Exception
Arg2: ffffe001ad9b05d8, Address of the WHEA_ERROR_RECORD structure.
Arg3: 0000000000000000, High order 32-bits of the MCi_STATUS value.
Arg4: 0000000000000000, Low order 32-bits of the MCi_STATUS value.
Debugging Details:
BUGCHECK_STR: 0x124_AuthenticAMD
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
STACK_TEXT:
ffffd000`e116f500 fffff802`ccd9ffd0 : ffffd000`e5950180 ffffe001`ad9b05b0 fffff802`cccff800 fffff802`cca9a339 : nt!WheapCreateLiveTriageDump+0x81
ffffd000`e116fa30 fffff802`ccbde454 : ffffe001`ad9b05b0 ffffd000`e116fb50 fffff802`cccff8e0 ffffe001`ab557880 : nt!WheapCreateTriageDumpFromPreviousSession+0x44
ffffd000`e116fa60 fffff802`ccbdf271 : fffff802`cccff8e0 ffffd000`e116fb50 fffff802`cccff8e0 ffffd000`e116fb50 : nt!WheapProcessWorkQueueItem+0x48
ffffd000`e116faa0 fffff802`cca895e3 : fffff802`ccf2ed20 fffff802`ccbdf24c ffffc001`7f38d280 ffffe001`ab557880 : nt!WheapWorkQueueWorkerRoutine+0x25
ffffd000`e116fad0 fffff802`ccb18e70 : 00000000`00000000 ffffe001`ab557880 ffffe001`ab557880 ffffe001`ab4ac040 : nt!ExpWorkerThread+0x293
ffffd000`e116fb80 fffff802`ccb6f7c6 : fffff802`ccd1a180 ffffe001`ab557880 fffff802`ccd73a00 00000000`00000000 : nt!PspSystemThreadStartup+0x58
ffffd000`e116fbe0 00000000`00000000 : ffffd000`e1170000 ffffd000`e1169000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: AuthenticAMD
IMAGE_NAME: AuthenticAMD
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION:
FAILURE_BUCKET_ID: 0x124_AuthenticAMD_PROCESSOR_BUS_PRV
BUCKET_ID: 0x124_AuthenticAMD_PROCESSOR_BUS_PRV
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x124_authenticamd_processor_bus_prv
FAILURE_ID_HASH: {6fd7875b-9a1b-9e09-d6d6-816026a875c8}
Followup: MachineOwner
Wanikiya and Dyami--Team Zigzag -
The computer has rebooted from a bugcheck, constant crash.
My newly built PC rebooted constantly and its driving me nuts, can anyone point me the reason? The errors are like this:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8000db1f0c0, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112114-8000-01.
I ve uploaded the most recent .dmp files here
http://1drv.ms/1xWeDon
if it helps. Will gladly upload anything you request, I just want to know if its my faulty hardware or software issue. If this is the wrong section, please move it where appropriate.
Thank you.KP
These were Related to ndisrd.sys NDISRD helper driver from NT Kernel Resources. This may be a part of the OS or it may be malware. I would run a system file check and malwarebytes
Please run a system file check (SFC)
All instructions are in our Wiki article below...
Should you have any questions please ask us.
System file check (SFC) Scan and Repair System Files
Please download the free version of Malwarebytes.
Update it immediately.
Do a full system scan
Let us know the results at the end.
http://www.malwarebytes.org/products
Microsoft (R) Windows Debugger Version 6.3.9600.17237 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Ken\Desktop\New folder\112214-29468-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred srv*C:\Symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: srv*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17328.amd64fre.winblue_r3.140827-1500
Machine Name:
Kernel base = 0xfffff802`d307c000 PsLoadedModuleList = 0xfffff802`d3352370
Debug session time: Fri Nov 21 20:45:57.058 2014 (UTC - 5:00)
System Uptime: 0 days 0:00:15.828
Loading Kernel Symbols
Loading User Symbols
Loading unloaded module list
* Bugcheck Analysis *
Use !analyze -v to get detailed debugging information.
BugCheck C4, {40, 0, ffffcf80f31fcc10, 0}
*** WARNING: Unable to verify timestamp for ndisrd.sys
*** ERROR: Module load completed but symbols could not be loaded for ndisrd.sys
Probably caused by : ndisrd.sys ( ndisrd+2716 )
Followup: MachineOwner
0: kd> !analyze -v
* Bugcheck Analysis *
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 0000000000000040, Acquiring a spinlock at IRQL < DISPATCH_LEVEL.
Arg2: 0000000000000000, Current IRQL
Arg3: ffffcf80f31fcc10, Spinlock address
Arg4: 0000000000000000
Debugging Details:
BUGCHECK_STR: 0xc4_40
CURRENT_IRQL: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: NetworkGenie.e
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre
LAST_CONTROL_TRANSFER: from fffff802d36fe6b0 to fffff802d31cb1a0
STACK_TEXT:
ffffd000`20efd778 fffff802`d36fe6b0 : 00000000`000000c4 00000000`00000040 00000000`00000000 ffffcf80`f31fcc10 : nt!KeBugCheckEx
ffffd000`20efd780 fffff802`d37048e7 : fffff800`4cd921b0 ffffcf80`f3f24f70 ffffd000`20efd800 fffff802`00000000 : nt!VerifierBugCheckIfAppropriate+0x3c
ffffd000`20efd7c0 fffff800`4cd8e716 : ffffcf80`f31fcbc0 ffffd000`20efd868 00000000`00000000 fffff802`00000001 : nt!VerifierKeAcquireSpinLockAtDpcLevel+0x9b
ffffd000`20efd800 ffffcf80`f31fcbc0 : ffffd000`20efd868 00000000`00000000 fffff802`00000001 00000000`00000000 : ndisrd+0x2716
ffffd000`20efd808 ffffd000`20efd868 : 00000000`00000000 fffff802`00000001 00000000`00000000 fffff800`4cd8fb99 : 0xffffcf80`f31fcbc0
ffffd000`20efd810 00000000`00000000 : fffff802`00000001 00000000`00000000 fffff800`4cd8fb99 00000000`00010001 : 0xffffd000`20efd868
STACK_COMMAND: kb
FOLLOWUP_IP:
ndisrd+2716
fffff800`4cd8e716 ?? ???
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: ndisrd+2716
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ndisrd
IMAGE_NAME: ndisrd.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4e707f81
FAILURE_BUCKET_ID: 0xc4_40_VRF_ndisrd+2716
BUCKET_ID: 0xc4_40_VRF_ndisrd+2716
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc4_40_vrf_ndisrd+2716
FAILURE_ID_HASH: {df7c0baf-f4d9-83e3-c876-e372e7f0e706}
Followup: MachineOwner
Wanikiya and Dyami--Team Zigzag -
The computer has rebooted from a bugcheck. Please help to explain what the error is
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88803e62ff8, 0x0000000000000001, 0xfffff8800452dbf3, 0x0000000000000002). A dump was saved in: C:\WINDOWS\Minidump\041214-52484-01.dmp. Report Id: 041214-52484-01.
We do need the actual DMP file as they contain the only record of the sequence of events leading up to the crash, what drivers were loaded, and what was responsible.
We prefer at least 2 DMP files to spot trends and confirm the cause.
Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here
If you have any questions about the procedure please ask
If you are using Blue screen view, who crashed, or a similar application don't. They are wrong at least as often as they are correct
Wanikiya and Dyami--Team Zigzag
Maybe you are looking for
-
It pops up once and a while when I close a tab/window.
-
Problems with DDIC tables in a Function's signature
Hi, We're on SAP Basis 702, support pack 7. I am trying to add a (DDIC) table to the signature of a Function in BRF+, but I have encountered 2 problems: 1. BRF+ asks me to specify the 'Table Line Type' of the table, but it refuses to recognize the st
-
Setting background color for a region
Hi, I am using apex 4.0. I am trying to set a background color to the report region and i tried different options and did not work for me. Can someone help me with this one in setting up a background color inside a region. Thanks, Rik Edited by: Rik2
-
Where do i download flash MSI?
I am trying to download the msi for flash and can not find where to do it. Any help would be appreciated. Thank you
-
Hi, we are havning devserver and prdserver.then what is the use of solution manager its a seperate server we have to install.can any one clarify my doubt. Thanku