Windows 8.1 rebooting overnight with a bug check

Windows 8.1 is rebooting overnight with a bug check in the system logs.
Event files saved:
https://onedrive.live.com/redir?resid=7DE1274A30A8AE63!1788&authkey=!AGhpLBq-8hDqCok&ithint=file%2c.zip
I also tried verifier to check out device drivers but could not figure out how to use it.  I got it configured and started, but did not know what to do once the computer rebooted....   Sounds like I need to download a windows debugger and
so I thought I would start with the event log files.  Any link on how to interpret the even logs, dump or mini dump files?
Thanks,
Ross

Hi,
According to the Event Log:
Session "ReadyBoot" stopped due to the following error: 0xC0000188
After that:
The previous system shutdown at 7:07:39 PM on ‎6/‎3/‎2014 was unexpected.
This problem probably caused by ReadyBoot problem, While you needn't worry about it,
The logging of this error will not affect the operation of your computer.  ReadyBoot is used by the ReadyBoost service that optimizes the boot time of your computer to a minimum.
You can refer to the link below for more details about this error:
http://support.microsoft.com/kb/2001347
In addition, I found another error message in your event log:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000019 (0x0000000000000020, 0xffffc0016d9657f0, 0xffffc0016d966040, 0x000000000585000a). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060314-18953-01.
If you still need assistance about this problem, please upload the memory.dmp file and share with us. We would help you try to analysize this log to find further reason of this problem.
Roger Lu
TechNet Community Support

Similar Messages

  • Need hotfix for BUG Check reboots for 2012R2

    I have 5 Node cluster of 2012R2 which will go to production in next few days, but am struck with the Bug check issue, which reboots atleast 3 nodes frequently. Am aware of this bug check and know the hotfixes for 2012 and 2008. However am not able to find
    the hotfix  or steps to resolve this issue on 2012r2.
    Need assistance to fix this problem.
    Thanks in advance, below the debug report.
    3: kd> !analyze -v
    *                        Bugcheck Analysis                                   
    USER_MODE_HEALTH_MONITOR (9e)
    One or more critical user mode components failed to satisfy a health check.
    Hardware mechanisms such as watchdog timers can detect that basic kernel
    services are not executing. However, resource starvation issues, including
    memory leaks, lock contention, and scheduling priority misconfiguration,
    may block critical user mode components without blocking DPCs or
    draining the nonpaged pool.
    Kernel components can extend watchdog timer functionality to user mode
    by periodically monitoring critical applications. This bugcheck indicates
    that a user mode health check failed in a manner such that graceful
    shutdown is unlikely to succeed. It restores critical services by
    rebooting and/or allowing application failover to other servers.
    Arguments:
    Arg1: ffffe8010a271900, Process that failed to satisfy a health check within the
     configured timeout
    Arg2: 00000000000004b0, Health monitoring timeout (seconds)
    Arg3: 0000000000000005
    Arg4: 0000000000000000
    Debugging Details:
    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
    ***    Either you specified an unqualified symbol, or your debugger   ***
    ***    doesn't have full symbol information.  Unqualified symbol      ***
    ***    resolution is turned off by default. Please either specify a   ***
    ***    fully qualified symbol module!symbolname, or enable resolution ***
    ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
    ***    enabling unqualified symbol resolution with network symbol     ***
    ***    server shares in the symbol path may cause the debugger to     ***
    ***    appear to hang for long periods of time when an incorrect      ***
    ***    symbol name is typed or the network symbol server is down.     ***
    ***    For some commands to work properly, your symbol path           ***
    ***    must point to .pdb files that have full type information.      ***
    ***    Certain .pdb files (such as the public OS symbols) do not      ***
    ***    contain the required information.  Contact the group that      ***
    ***    provided you with these symbols if you need this command to    ***
    ***    work.                                                         
    ***    Type referenced: nt!_KPRCB                                    
    ***    Either you specified an unqualified symbol, or your debugger   ***
    ***    doesn't have full symbol information.  Unqualified symbol      ***
    ***    resolution is turned off by default. Please either specify a   ***
    ***    fully qualified symbol module!symbolname, or enable resolution ***
    ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
    ***    enabling unqualified symbol resolution with network symbol     ***
    ***    server shares in the symbol path may cause the debugger to     ***
    ***    appear to hang for long periods of time when an incorrect      ***
    ***    symbol name is typed or the network symbol server is down.     ***
    ***    For some commands to work properly, your symbol path           ***
    ***    must point to .pdb files that have full type information.      ***
    ***    Certain .pdb files (such as the public OS symbols) do not      ***
    ***    contain the required information.  Contact the group that      ***
    ***    provided you with these symbols if you need this command to    ***
    ***    work.                                                         
    ***    Type referenced: nt!_KPRCB                                    
    ***    Either you specified an unqualified symbol, or your debugger   ***
    ***    doesn't have full symbol information.  Unqualified symbol      ***
    ***    resolution is turned off by default. Please either specify a   ***
    ***    fully qualified symbol module!symbolname, or enable resolution ***
    ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
    ***    enabling unqualified symbol resolution with network symbol     ***
    ***    server shares in the symbol path may cause the debugger to     ***
    ***    appear to hang for long periods of time when an incorrect      ***
    ***    symbol name is typed or the network symbol server is down.     ***
    ***    For some commands to work properly, your symbol path           ***
    ***    must point to .pdb files that have full type information.      ***
    ***    Certain .pdb files (such as the public OS symbols) do not      ***
    ***    contain the required information.  Contact the group that      ***
    ***    provided you with these symbols if you need this command to    ***
    ***    work.                                                         
    ***    Type referenced: nt!_KPRCB                                    
    ADDITIONAL_DEBUG_TEXT: 
    You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
    MODULE_NAME: netft
    FAULTING_MODULE: fffff80021089000 nt
    DEBUG_FLR_IMAGE_TIMESTAMP:  5215f788
    PROCESS_OBJECT: ffffe8010a271900
    DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
    BUGCHECK_STR:  0x9E
    CURRENT_IRQL:  0
    ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) x86fre
    LAST_CONTROL_TRANSFER:  from fffff800a291ac08 to fffff800211dcfa0
    STACK_TEXT: 
    ffffd001`d60c6938 fffff800`a291ac08 : 00000000`0000009e ffffe801`0a271900 00000000`000004b0 00000000`00000005 : nt!KeBugCheckEx
    ffffd001`d60c6940 fffff800`a291a892 : 00000000`00000000 00000000`00000000 ffffd001`d601c180 ffffe001`1f716ec8 : netft+0x2c08
    ffffd001`d60c6980 fffff800`210e2810 : ffffd001`d60c6b00 ffffe001`1f716ec8 ffffe001`24e7d220 ffffd001`d601c180 : netft+0x2892
    ffffd001`d60c69b0 fffff800`211e0aea : ffffd001`d601c180 ffffd001`d601c180 ffffd001`d6028dc0 ffffe001`24e7d080 : nt!KeRemoveQueueEx+0x3b80
    ffffd001`d60c6c60 00000000`00000000 : ffffd001`d60c7000 ffffd001`d60c1000 00000000`00000000 00000000`00000000 : nt!KeSynchronizeExecution+0x2efa
    STACK_COMMAND:  kb
    FOLLOWUP_IP:
    netft+2c08
    fffff800`a291ac08 cc              int     3
    SYMBOL_STACK_INDEX:  1
    SYMBOL_NAME:  netft+2c08
    FOLLOWUP_NAME:  MachineOwner
    IMAGE_NAME:  netft.sys
    BUCKET_ID:  WRONG_SYMBOLS
    FAILURE_BUCKET_ID:  WRONG_SYMBOLS
    ANALYSIS_SOURCE:  KM
    FAILURE_ID_HASH_STRING:  km:wrong_symbols
    FAILURE_ID_HASH:  {70b057e8-2462-896f-28e7-ac72d4d365f8}
    Followup: MachineOwner
    ndraj

    Hi, 
    Try to install all recommended cluster hot-fixes to stop further BSODs. Bug check ID 0x9E is recorded for this shutdown & image name netft.sys cause of server shutdown.
    As suggested in
    similar kind of thread netft.sys is driver of MS Cluster Virtual Adapter. Try to to update firmware/drivers of NICs.
    Here is another useful link for your reference 
    Regards, Ravikumar P

  • Windows rebooted from a bug check..

    The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000048, 0x0000000000000002, 0x0000000000000001, 0xfffff8026303b73e).
    Hello! I've been having bluescreens for about 2 months now. I thought it was my graphic card so I bought a new one and that did not work. I've formatted 4 times - running Windows 8.1 w/ all updates. Any deciphering of the bug check would be great, thanks
    for your time.

    KMODE_EXCEPTION_NOT_HANDLED (1e)
    This indicates that a kernel-mode program generated an exception which the error handler did not catch.
    BugCheck 1E, {ffffffffc0000005, fffff80307127fd8, 0, ffffffffffffffff}
    1: kd> ln fffff80307127fd8
    (fffff803`07127ad0) nt!MiResolveProtoPteFault+0x508 | (fffff803`071283e0) nt!MiCompleteProtoPteFault
    The exception occurred in nt!MiResolveProtoPteFault+0x508.
    1: kd> kv
    Child-SP RetAddr : Args to Child : Call Site
    ffffd000`22e9ed88 fffff803`07219d47 : 00000000`0000001e ffffffff`c0000005 fffff803`07127fd8 00000000`00000000 : nt!KeBugCheckEx
    ffffd000`22e9ed90 fffff803`071dabc2 : 00000000`c64430c0 fffff803`07332420 00000000`0000007d ffffe000`c5ada638 : nt! ?? ::FNODOBFM::`string'+0x3a897
    ffffd000`22e9f480 fffff803`071d90fe : 00000000`0000043d 00007ffb`890e3001 ffff0000`00000001 0000ffff`fffff000 : nt!KiExceptionDispatch+0xc2
    ffffd000`22e9f660 fffff803`07127fd8 : ffffe000`c9361dd8 00007ffb`890e3e88 00000001`60c4f021 ffffe000`c9361dd8 : nt!KiGeneralProtectionFault+0xfe (TrapFrame @ ffffd000`22e9f660)
    ffffd000`22e9f7f0 fffff803`0712638d : fffff6e0`00da6610 00007ffb`8901a13c fffff6bf`fdc480d0 ffffe000`c9361dd8 : nt!MiResolveProtoPteFault+0x508
    ffffd000`22e9f890 fffff803`070e258a : ffffe000`c94b1880 00007ffb`8901a13c ffffe000`c94b1880 ffffe000`00000000 : nt!MiDispatchFault+0x29d
    ffffd000`22e9f9c0 fffff803`071d922f : 00000000`00000008 00000000`037cfb30 ffffe000`c94b1801 ffffd000`22e9fb00 : nt!MmAccessFault+0x36a
    ffffd000`22e9fb00 00007ffb`8901a13c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x12f (TrapFrame @ ffffd000`22e9fb00)
    00000000`206fda78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`8901a13c
    1: kd> .trap ffffd000`22e9f660
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000073752860 rbx=0000000000000000 rcx=e000c93bf5780460
    rdx=0000000000165396 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff80307127fd8 rsp=ffffd00022e9f7f0 rbp=0000000000000000
    r8=0000058000000000 r9=ffffe000c9361dd8 r10=ffffd00022e9fb00
    r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0 nv up ei pl zr na po nc
    nt!MiResolveProtoPteFault+0x508:
    fffff803`07127fd8 488b3f mov rdi,qword ptr [rdi] ds:00000000`00000000=????????????????
    1: kd> u @rip
    nt!MiResolveProtoPteFault+0x508:
    fffff803`07127fd8 488b3f mov rdi,qword ptr [rdi]
    fffff803`07127fdb 4885ff test rdi,rdi
    fffff803`07127fde 0f841efcffff je nt!MiResolveProtoPteFault+0x132 (fffff803`07127c02)
    fffff803`07127fe4 488bc7 mov rax,rdi
    fffff803`07127fe7 4883e0f8 and rax,0FFFFFFFFFFFFFFF8h
    fffff803`07127feb 4883f808 cmp rax,8
    fffff803`07127fef 0f840dfcffff je nt!MiResolveProtoPteFault+0x132 (fffff803`07127c02)
    fffff803`07127ff5 400fb6c7 movzx eax,dil
    fffff803`07127d12 0f84f0020000 je nt!MiResolveProtoPteFault+0x538 (fffff803`07128008)
    fffff803`07127d18 480fbae708 bt rdi,8
    fffff803`07127d1d 0f82f0020000 jb nt!MiResolveProtoPteFault+0x543 (fffff803`07128013)
    fffff803`07127d23 4c8bc3 mov r8,rbx
    fffff803`07127d26 49c1e805 shr r8,5
    fffff803`07127d2a 4183e01f and r8d,1Fh
    fffff803`07127d2e 4184d9 test r9b,bl
    fffff803`07127d31 0f857c370e00 jne nt! ?? ::FNODOBFM::`string'+0x2c003 (fffff803`0720b4b3)
    fffff803`07127d37 488b442448 mov rax,qword ptr [rsp+48h]
    fffff803`07127d3c 488d0dade1f5ff lea rcx,[nt!MiReadWrite (fffff803`07085ef0)]
    Verify Flags Level 0x0002092b
    STANDARD FLAGS:
    [X] (0x00000000) Automatic Checks
    [X] (0x00000001) Special pool
    [X] (0x00000002) Force IRQL checking
    [X] (0x00000008) Pool tracking
    [ ] (0x00000010) I/O verification
    [X] (0x00000020) Deadlock detection
    [ ] (0x00000080) DMA checking
    [X] (0x00000100) Security checks
    [X] (0x00000800) Miscellaneous checks
    [X] (0x00020000) DDI compliance checking
    We have Driver Verifier enabled at the time of the crash, yet we have a ton of memory related stuff going on, and an exception occurring in one as well. Although Memtest failed, at this point I am going to say we're either not catching a problematic low-level
    driver causing corruption, or we have a RAM/motherboard problem despite Memtest passing.
    1. Uninstall any/all Asus bloatware (AI Suite, PC Probe, etc... whatever you have).
    2. Uninstall/disable the nVidia Streaming Service ASAP.
    3. If the above fails, faulty RAM and/or motherboard. Although before definitely concluding this, I'd try a BIOS update if available.
    Regards,
    Patrick
    “Be kind whenever possible. It is always possible.” - Dalai Lama

  • When closing 2 windows(with multiple tabs each), system restore does not properly restore the second window's tabs. Is this a bug in the new update/any ideas to fix?

    I regularly use 2 windows with multiple tabs each and session restore would work to get them all back, but after this latest update the second window does not restore properly, with the first tab not visible on top(only in drop down menu) and the add a tab button now on the left(instead of right). The add a tab button is not really concerning other than it indicates other problems with the tabs on tab of the 2nd window. Not having the 1st tab visible is frustrating, because I can not move it or as easily navigate. Also, the tabs on top of the 2nd window that are visible no longer have the "x" to close visible unless that tab is selected. I'm assuming this is a problem with the new release/update, since this is the first time I've ever encountered the problem, and I've shut down and restored Firefox a few times to make sure this was a recurring problem and not a one-time deal. Any ideas on how to fix would be welcome(other than perhaps cramming my tabs onto one window or sucking it up XD).

    Hi,
    You can try to '''Reset toolbars and controls:''' and '''Make Changes and Restart''' in the [https://support.mozilla.org/en-US/kb/Safe%20Mode Safe Mode] start screen.
    If the problem persists, please try a [https://support.mozilla.org/en-US/kb/Managing-profiles?s=profile&r=0&e=sph&as=s new profile]. You can later copy [https://support.mozilla.org/en-US/kb/Backing%20up%20your%20information?s=backup&r=1&e=sph&as=s needed data] from the old profile to this.
    [http://kb.mozillazine.org/Profile_folder_-_Firefox Firefox Profile Folder & Files]

  • Event ID 1001 Bug check Occurred, After updation of Kaspersky Windows 7

    Hi, 
    Recently I have updated my Anti Virus Kaspersky 10 on my Windows 7 Ultimate System 32 bit. After that it restart automatically  again and again. Then i restore it on Last known good configuration. It resolve the issue. In event viewr i found out the
    Error 1001 Bug check .. 
    I exactly want to know that what happened to my system . For this How can i send my dmp files to support team . 
    I have face the problem non my multiple systems but not all .. . 
    Please guide me asap . 

    The following log occurred 
    The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000c9 (0x0000024d, 0x9047b25a, 0x8d5ed0b8, 0x00000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041714-22230-01.
    when i run verifier.exe 
    and select " Create standard Setting"  then select "Automatically select drivers build for older version of windows" and press Next
    it display the Kl1.sys driver 
    what does it means .. is there any problem with this file?

  • Windows Server 2008 black screen with mouse *PLEASE HELP*

    Hello fellow techs,
    I have been tearing my hair out for the past 12hrs on this issue.
    About 3 weeks ago, one of our clients reported that they were experiencing
    issues on the network so one of the staff went into the server room and noticed
    the screen was black with only the cursor. As they couldn't reboot, they
    decided to hold the power button to power it off. When they powered it back
    up, it went passed the windows loading
    splash screen, and again the screen is black with
    the mouse pointer in the center of the screen.
    I am diagnosing the server and find that at the black screen, I’m able to move
    the cursor and beyond that nothing happened. I started in safe mode with the
    exact same results.
    I have been trying many different solutions from posts that I have found in
    Google but no change.
    From other machines you can type \\servername in
    the run box and see the shared folders, as well as ping it.
    This is a very urgent request as I need to have the Server back up and running
    by tomorrow.
    I am quiet willing to pay for phone support with anyone that can assist as soon
    as possible. I am happy to transfer founds via Paypal.<o:p></o:p>
    PLEASE HELP!

    Hi,
    I agree with sm, you should give us more details. Also you should use sfc  /scannow
    command to scans the integrity of all protected system files and repairs files with problems when possible. For more details, please refer to the following article.
    Sfc
    http://technet.microsoft.com/en-us/library/ff950779.aspx
    Before going further, would you please let me know whether there were any changes on the affected server? Has windows update or any new device been added? Please also check your shadow copies.
    The Windows Server black screen may be caused by them.
    In addition, there are similar questions, please refer to.
    Windows Server 2008 black screen
    http://social.technet.microsoft.com/Forums/en-US/463b529b-26a6-4d5d-88f5-7d8b3460d165/black-screen-windows-2008-r2
    Windows Server 2008 and the Black Screen of Waiting
    http://projectdream.org/wordpress/2009/03/03/windows-server-2008-and-the-black-screen-of-waiting/
    By a way, you also can be able to boot into last know good configuration to solve the trouble. You can refer to the following similar question that provide the detailed operations.
    Windows Server 2008 black screen with only the mouse pointer showing
    http://social.technet.microsoft.com/Forums/en-US/5c878af8-78f2-430d-9530-a0e5ad73ff03/windows-server-2008-black-screen-with-only-the-mouse-pointer-showing
    Hope this helps.
    Best regards,
    Justin Gu

  • Windows 7 Blue Screen Issues With Alt-tabbing From WoW

    As the title says, lately I've been having blue screens which are mostly caused by wow.
    Previously I've had the occasional bsod (once a month or so) when alt tabbing, but it was pretty rare. However recently, I've had something more like 1 a day, usually caused by alt tabbing out of wow. It seems the longer I'm alt tabbed the more likely it
    is to happen. I haven't experienced the same problem with any other game, although the occasional monthly ones usually happen when I'm changing my music as I alt tab out of League of Legends.
    I downloaded bluescreenview and it appears the cause is some combination of win32k.sys as well as ntoskrnl.exe             Based off the fact that it is happening more with a more demanding game, I'm guessing the problem is
    most likely due to a bad stick of ram, but I'd like a second opinion.
    I'll attach a few of the most recent dump files (the one today is slightly different than the ones last week which seems slightly odd).
    http://puu.sh/8lVuH     http://puu.sh/8lVtT      http://puu.sh/8lVse
    Thanks in advance for any help, and I hope image files are okay :)

    Thanks, and it's not, no. You can't exactly debug pictures :')
    We have two consistent bug checks:
    SYSTEM_SERVICE_EXCEPTION (3b)
    This indicates that an exception happened while executing a routine that transitions from non-privileged code to privileged code.
    This error has been linked to excessive paged pool usage and may occur due to user-mode graphics drivers crossing over and passing bad data to the kernel code.
    BugCheck 3B, {c0000005, fffff80002e5301e, fffff88008945c70, 0}
    0: kd> ln fffff80002e5301e
    (fffff800`02e52ff8) nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe+0x26 | (fffff800`02e53040) nt!PsIsProtectedProcess
    ^^ The exception occurred in nt!ExEnterCriticalRegionAndAcquireFastMutexUnsafe. This is a routine that first enters a critical region, and then acquires the specified fast mutex for the calling thread.
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    This indicates that invalid system memory has been referenced.
    Bug check 0x50 usually occurs after the installation of faulty hardware or in the event of failure of installed hardware (usually related to defective RAM, be it main memory, L2 RAM cache, or video RAM).
    Another common cause is the installation of a faulty system service.
    Antivirus software can also trigger this error, as can a corrupted NTFS volume.
    BugCheck 50, {fffff900c25efcf0, 0, fffff9600032c69d, 0}
    ^^ Address fffff900c25efcf0 was written to by the instruction at address
    fffff9600032c69d.
    1: kd> r cr2
    Last set context:
    cr2=fffff900c25efcf0
    ^^ The 1st parameter address was stored in cr2 prior to calling the page fault handler.
    1: kd> !pte fffff900c25efcf0
    VA fffff900c25efcf0
    PXE at FFFFF6FB7DBEDF90 PPE at FFFFF6FB7DBF2018 PDE at FFFFF6FB7E403090 PTE at FFFFF6FC80612F78
    Unable to get PXE FFFFF6FB7DBEDF90
    ^^ Can't see whether or not it's valid/non-valid.
    1: kd> .trap fffff880`073858e0
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000011 rbx=0000000000000000 rcx=fffff900c376ae40
    rdx=00000000701215e6 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff9600032c69d rsp=fffff88007385a70 rbp=0000000000000001
    r8=0000000000000000 r9=0000000000000410 r10=fffff80002e4e000
    r11=0000000000000022 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0 nv up ei pl zr na po nc
    win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+0x2d:
    fffff960`0032c69d 488b4f20 mov rcx,qword ptr [rdi+20h] ds:00000000`00000020=??????????
    ^^ On the instruction we failed on, address fffff960`0032c69d deferenced
    rdi+20h where rdi is 0000000000000000. All of this would result in a memory write to the address
    00000000`00000020.
    1: kd> dd 00000000`00000020
    00000000`00000020 ???????? ???????? ???????? ????????
    00000000`00000030 ???????? ???????? ???????? ????????
    00000000`00000040 ???????? ???????? ???????? ????????
    00000000`00000050 ???????? ???????? ???????? ????????
    00000000`00000060 ???????? ???????? ???????? ????????
    00000000`00000070 ???????? ???????? ???????? ????????
    00000000`00000080 ???????? ???????? ???????? ????????
    00000000`00000090 ???????? ???????? ???????? ????????
    Right, so the code wanted to write to 00000000`00000020 which as we can see above is a completely invalid address. The 1st parameter and cr2 however note we failed writing to address
    fffff900c25efcf0. This does not make sense, and is essentially not logically possible.
    The hardware was told to write to 00000000`00000020, and the hardware came back and said 'I cannot write to
    fffff900c25efcf0'. Another way to think about it is if you kindly asked the waiter of your table for more water, he writes it down, but comes back and says 'I'm sorry, but we're all out of coffee'.
    1. Uninstall any/all installed Asus bloatware, I for example see Asus PC Probe, and AI Suite.
    2. Remove and replace avast! with Microsoft Security Essentials for temporary troubleshooting purposes as it may be causing conflicts:
    avast! removal -
    http://www.avast.com/uninstall-utility
    MSE - 
    http://windows.microsoft.com/en-us/windows/security-essentials-download
    3. If the above fails, you have faulty RAM.
    Regards,
    Patrick
    “Be kind whenever possible. It is always possible.” - Dalai Lama

  • Windows Overlay Filter (wof.sys), file in Windows 8.1, is associated with BSOD in Windows 10 bld 9879

    BSOD in Win 10 build 9879 is with bug check 0x1e. Wof.sys is a file that is in Win 8.1. HP g7-1310us (refurbished) laptop has been having BSOD's even when it had Win 7 installed. Checked RAM, hardware, and SATA disk but there is no specific lead to why BSOD's
    happen routinely. Interestingly, there were no problems while this laptop was running Ubuntu 14. Any details on what Windows Overlay Filter driver named wof.sys does? Also, could this error be caused by faulty CPU? It has an Intel i3-2350M CPU @2.3Ghz, x64
    based processor.
    ==================================================
    Dump File         : 121114-22984-01.dmp
    Crash Time        : 12/11/2014 5:23:05 PM
    Bug Check String  : KMODE_EXCEPTION_NOT_HANDLED
    Bug Check Code    : 0x0000001e
    Parameter 1       : ffffffff`c0000005
    Parameter 2       : 00000000`00000000
    Parameter 3       : 00000000`00000008
    Parameter 4       : 00000000`00000000
    Caused By Driver  : Wof.sys
    Caused By Address : Wof.sys+1e40
    File Description  : Windows Overlay Filter
    Product Name      : Microsoft® Windows® Operating System
    Company           : Microsoft Corporation
    File Version      : 6.4.9879.0 (fbl_release.141103-1722)
    Processor         : x64
    Crash Address     : ntoskrnl.exe+161109
    Stack Address 1   :
    Stack Address 2   :
    Stack Address 3   :
    Computer Name     :
    Full Path         : C:\Windows\Minidump\121114-22984-01.dmp
    Processors Count  : 4
    Major Version     : 15
    Minor Version     : 9879
    Dump File Size    : 282,776
    Dump File Time    : 12/11/2014 5:26:16 PM
    ==================================================
    Gilda Sanchez

    Here is the CPU data:
    Intel(R) Processor Identification Utility
    Version: 5.01.20140910
    Time Stamp: 2014/12/11 19:28:20
    Operating System: 6.2-9200-
    Number of processors in system: 1
    Current processor: #1
    Active cores per processor: 2
    Disabled cores per processor: 0
    Processor Name: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
    Type: 0
    Family: 6
    Model: 2A
    Stepping: 7
    Revision: 29
    Maximum CPUID Level: D
    L1 Instruction Cache: 2 x 32 KB
    L1 Data Cache: 2 x 32 KB
    L2 Cache: 2 x 256 KB
    L3 Cache: 3 MB
    Packaging: µPGA/BGA
    Enhanced Intel SpeedStep(R) Technology: Yes
    MMX(TM): Yes
    Intel(R) SSE: Yes
    Intel(R) SSE2: Yes
    Intel(R) SSE3: Yes
    Intel(R) SSE4: Yes
    Intel(R) AES-NI: No
    Intel(R) AVX: Yes
    Enhanced Halt State: Yes
    Execute Disable Bit: Yes
    Gilda Sanchez

  • Outlook2013 email message goes behind main Outlook window when opening PDF attachment with Reader 11

    Problem statement: Outlook 2013 email message goes behind main Outlook window when opening PDF attachment with Adobe Reader 11.0.3
    Environment: Windows 8 x64; Office 2013; Adobe Reader 11.0.3
    Steps to reproduce bug:
    1. Open Outlook 2013
    2. Open email message with PDF attachment
    3. Open PDF attachment (with Adobe Reader as default PDF viewer)
    4. Close Adobe Reader
    Results: Original email message with PDF attacment now sits behind the main Outlook window
    Expected results: Original email message should be on top of main Outlook window as it was when opening the PDF attachment
    Note: Adobe Acrobat Profession performs as expected - the original email is on top of the main Outlook window - This only seems to be a problem with Adobe Reader.
    Has anyone else experience this problem?  If so, have you found a work-around?
    Thanks,
    Mike

    From: new window opens behind existing window - how to modify?
    I had this problem happening in Outlook.
    If I tried to open an email, it would open behind the main Outlook window.
    The same happened if I opened a link in the email - it would open behind the mail.
    The fix that was suggested to me was so simple that I still don't believe it.
    Right click on the task bar and unlock the taskbar, then lock it again.
    Close down Outlook and re-start it.
    Problem solved! Just dont know how  or why.
    Proposed as answer byalfreelandTuesday, January 08, 2013 4:52 PM
    It worked for me with Win 7 and OL 2003. Why? Who cares ... It is working.
    Liviu 2014-09-17

  • Windows 2003 Memory Dump - Bug check Analysis attached

    Hi all
    I recently have had a Windows 2003 Standard with SP2 server crash with a memory dump
     I have used WinDBG to read the file and output below
    can anyone shed any light on the faults, or point me in the right direction?
    *                        Bugcheck Analysis                                   
    KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e)
    This is a very common bugcheck.  Usually the exception address pinpoints
    the driver/function that caused the problem.  Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003.  This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG.  This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG.  This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: 8081c630, The address that the exception occurred at
    Arg3: b7487c30, Trap Frame
    Arg4: 00000000
    Debugging Details:
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    FAULTING_IP:
    nt!IoGetAttachedDevice+c
    8081c630 8b4810          mov     ecx,dword ptr [eax+10h]
    TRAP_FRAME:  b7487c30 -- (.trap 0xffffffffb7487c30)
    ErrCode = 00000000
    eax=000007f6 ebx=85e76068 ecx=000007f6 edx=00000000 esi=85e76068 edi=89d42020
    eip=8081c630 esp=b7487ca4 ebp=b7487ca4 iopl=0         nv up ei pl nz na pe nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010206
    nt!IoGetAttachedDevice+0xc:
    8081c630 8b4810          mov     ecx,dword ptr [eax+10h] ds:0023:00000806=????????
    Resetting default scope
    DEFAULT_BUCKET_ID:  DRIVER_FAULT
    BUGCHECK_STR:  0x8E
    PROCESS_NAME:  DocTransport.ex
    CURRENT_IRQL:  0
    ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) x86fre
    LAST_CONTROL_TRANSFER:  from 8082db20 to 80827f7d
    STACK_TEXT: 
    b74877fc 8082db20 0000008e c0000005 8081c630 nt!KeBugCheckEx+0x1b
    b7487bc0 8088c12a b7487bdc 00000000 b7487c30 nt!KiDispatchException+0x3a2
    b7487c28 8088c0de b7487ca4 8081c630 badb0d00 nt!CommonDispatchException+0x4a
    b7487ca4 8081c7e1 89d42020 b7487d64 00000000 nt!KiExceptionExit+0x186
    b7487cb8 808f44c7 85e76068 b7487d64 08a9ea50 nt!IoGetRelatedDeviceObject+0x63
    b7487d38 8088b658 00001e20 00000000 00000000 nt!NtReadFile+0x55
    b7487d38 7c82845c 00001e20 00000000 00000000 nt!KiSystemServicePostCall
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    08a9ea8c 00000000 00000000 00000000 00000000 0x7c82845c
    STACK_COMMAND:  kb
    FOLLOWUP_IP:
    nt!IoGetAttachedDevice+c
    8081c630 8b4810          mov     ecx,dword ptr [eax+10h]
    SYMBOL_STACK_INDEX:  0
    SYMBOL_NAME:  nt!IoGetAttachedDevice+c
    FOLLOWUP_NAME:  MachineOwner
    MODULE_NAME: nt
    IMAGE_NAME:  ntkrpamp.exe
    DEBUG_FLR_IMAGE_TIMESTAMP:  51d4c567
    IMAGE_VERSION:  5.2.3790.5190
    FAILURE_BUCKET_ID:  0x8E_nt!IoGetAttachedDevice+c
    BUCKET_ID:  0x8E_nt!IoGetAttachedDevice+c
    ANALYSIS_SOURCE:  KM
    FAILURE_ID_HASH_STRING:  km:0x8e_nt!iogetattacheddevice+c
    FAILURE_ID_HASH:  {22c1c728-5bf3-efb9-fff4-40d5ae0d47e2}
    Followup: MachineOwner

    Hi,
    For Bug Check 0x8E, it
    indicates that a kernel-mode application generated an exception that the error handler did not catch. For more details, please refer to following article and check if can help you.
    Bug Check 0x8E: KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Did you remember that which operation (or any change) you do before this issue occurred? Or just the server
    crashed suddenly?
    Please check if all necessary updates were installed and drivers were updated.
    à
    PROCESS_NAME: 
    DocTransport.exe
    Did you install any third-party application on the server? Please
    perform a clean boot and monitor the result.
    By the way, as you know, troubleshoot this kind of kernel crash issue, we need to analyze the crash dump file to narrow down the root cause of the issue. However, it is not
    effective for us to debug the crash dump file here in the forum. If this issues is a state of emergency for you. Please contact Microsoft Customer Service and Support (CSS) via telephone so that a dedicated Support Professional can assist with your request.
    To obtain the phone numbers for specific technology request, please refer to the web site listed below:
    http://support.microsoft.com/default.aspx?scid=fh;EN-US;OfferProPhone#faq607
    Hope this helps.
    Best regards,
    Justin Gu

  • Problems with RH 8 and Windows 2008 64-bit servers with IIS7?

    I have been informed that my company's servers are being upgraded to Windows 2008 64-bit servers with IIS7, from Windows 2003 & IIS6. Probably will be online in April 2011.
    I have a project created using WebHelp, RoboHelp HTML v5. I have RoboHelp HTML v8 (haven't had a chance to use it yet). We are currently using IE7 on XP. Does anyone have any info on issues with RoboHelp v8 WebHelp projects running on Windows 2008 64-bit servers & IIS7 that I need to be concerned about? I thought I should convert the project developed using RH 5 to and RH 8 project, then FTP it to the new server when it becomes available.
    Any helpful info would be much appreciated.
    Thanks,
    Alden

    Acrobat 8 is not certified for Win7, particularly the x64 version. If you got the installation to go, the first step is to update AA8 to at least AA8.2. The x64 with XP required at least AA8.2 and I suspect that has not changed. I would suggest updating to the latest, either from the help menu (until no more updates are available) or by downloading the updates from the adobe.com>downloads page. For the latter, download ALL updates after your current version and install them in ORDER. They are not cummulative in most cases. You only need to reboot after the final update. The updates may get you going. If not, you may simply have to upgrade to AA9 or search for what others have been able to do in your situation.

  • Windows 2008 R2 SP1 BSOD Bug Check 0x0000003b

    Hi,
    I have a Win 2k8 R2 SP1 VM that keeps crashing every night for the past 2 days. Every time is the same bug check code 0x0000003b. I looked around and found 2 KBs for this specific code: 
    http://support.microsoft.com/kb/980932/en-gb - does not apply to my system
    http://support.microsoft.com/kb/2836373/en-gb - installed the hotfix yesterday but got another crash today
    The server has 30 printers installed on it and during the night only one is used so I tend to think that it is causing the crash. The printer has the latest driver installed (Konica Minolta Universal Printing Driver v2.4).
    I looked through the dump files generated by every BSOD but I cannot find anything that would point me in the right direction... or I might have missed it. 
    Here is a bit more info on the server:
    Windows 2008 R2 Standard SP1
    System is a VM
    IIS role installed
    30 printers installed - all drivers are up to date
    I have stored the dump files here: http://1drv.ms/1kpL9vh
    Any help with this would be greatly appreciated. 
    Thanks

    Hi gogu2008,
    First , please keep the VM and Host up-to-date then check if the issue persists .
    What is the Host OS ?
    How much RAM does the VM have ?
    If the VM is using dynamic memory , for troubleshooting you may try to configure  fixed RAM for the VM.
    As for the DUMP , you can change the "mini dump  " to  "kernel memory dump " then analysis the file after BSOD .
    Hope it helps
    Best Regards
    Elton Ji
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Windows 8.1 + IEnumShellItems + protected OS files = BUG!

    IEnumShellItems is flaky on windows 8.1. Even when one manually turns OFF the "hide protected OS files" setting from folder options (control panel), the enumerated items do NOT contain "super hidden" files (those that have both S and
    H attributes)
    In older windows it behaves correctly, so this is a windows 8.1 quirk
    on a side note, since IEnumShellItems is the "new and improved" way to enumerate folders, shouldn't it offer some override flag like SHCONTF_INCLUDESUPERHIDDEN?
    thanks, nikos
    www.zabkat.com

    IEnumShellItems is flaky on windows 8.1. Even when one manually turns OFF the "hide protected OS files" setting from folder options (control panel), the enumerated items do NOT contain "super hidden" files (those that have both S and
    H attributes)
    In older windows it behaves correctly, so this is a windows 8.1 quirk
    Nikos,
    From what you say this sounds like an inconsistency introduced with
    Windows 8.1.
    I suggest that you write a simple stand-alone console program that
    anyone can use to see the difference between the OS's, and submit it
    with a bug report on the VS connect site:
    https://connect.microsoft.com/VisualStudio/
    If you note that you think it's an OS bug rather than VS, hopefully
    someone will be able to forward it on.
    If you need more immediate feedback on this issue, you may need to
    take out a phone support call with MS.
    Dave

  • Windows 7 Backup is Failing with error 0x81000101

    Hello,
    My windows 7 backup is failing with the following message "Error Code: 0x81000101". I searched the internet but didn't find any good solution.
    Can you please tell me what should I do?

    If none of the above worked read this next
    Did your computer come with a Recovery Partition on the drive? (Check the computers documentation)
    If it did, you cannot have any backup software or System Restore set to backup or monitor that drive.
    Go to Control Panel.
    Click on Classic View in the Task Pane.
    Double click System.
    Select Advanced System Settings in the Tasks Pane.
    Click the System Protection Tab.
    In the Available Disks section, make sure that the backup partition is not selected. If it is, remove the check mark.
    After this is done or if this does not work, go to Start/All Programs/Accessories/System Tools and click on Disk Cleanup.
    In the Options dialog, select 'Files from all users on this computer'. Click the C: system drive. When the scan is completed, click the 'More Options' Tab. In the 'System Restore and Shadow Copies' section, click the 'Cleanup' button. In the 'Are you sure......' popup, click Delete. Click OK.
    Wait for the Disk Cleanup to complete.
    Now, go back into Disk Cleanup and follow the same procedure for any other drives that appear in the drop down menu where you selected the C: drive the first time.
    Exit everything and reboot the computer.
    After the computer reboots, check System Restore again. If System Restore is still not working, go back into System Protection and turn off System Restore for all drives and reboot the computer again. This will delete all restore points on all drives.
    After the reboot, go back and enable System Restore for the C: volume only. Create a new restore point for that drive.
    Let me know the results.
    MCSE, MCSA, MCDST
    [If this post helps to resolve your issue, please click the "Mark as Answer" or "Helpful" button at the top of this message. By marking a post as Answered, or Helpful you help others find the answer faster.]

  • Windows failed to reboot after installing PC Suite

    Hi everyone,
    I hope you can help me with my problem. I have an old pc suite version installed in my old laptop(about 6 years old - OS Windows Vista Home Basic) but today i decided to upgrade to the latest one(i think it's version 7). I was able to successfully install it. when i launched the application, it worked fine but when i connected my phone(Nokia X2) via USB cable that was when i started to have troubles. When i inserted the usb cable that came with the phone to my laptop, a prompt appeared that my machine was installing the drivers for my device. After about 5 minutes, the installation was complete and it prompted me to reboot my computer and so i did. Before it powered off, the machine said it was completing the updates first, then done. When it came back on, Windows failed to load and reboot my computer. The complete error msg was: "Windows failed to start. A recent hardware or software change might be the cause. To fix the problem:
    1. Insert your windows installation disc & restart your computer.
    2. Choose language settings, and then click 'Next.'
    3. Click "Repair your computer."
    If you do not have this disc, contact your system administrator or computer manufacturer for assistance.
    File: ntoskrnl.exe
    Status: 0xc0000098
    Info: Windows failed to load because a required file is missing, or corrupt."
    I already followed the instructions since i have the disc with me but my laptop is still not working. I already did Startup Repair and System Restore but it didn't solve the problem. Please help me. Thank you so much!

    mu5ik3r0 wrote:
    Hi everyone,
    I hope you can help me with my problem. I have an old pc suite version installed in my old laptop(about 6 years old - OS Windows Vista Home Basic) but today i decided to upgrade to the latest one(i think it's version 7). I was able to successfully install it. when i launched the application, it worked fine but when i connected my phone(Nokia X2) via USB cable that was when i started to have troubles. When i inserted the usb cable that came with the phone to my laptop, a prompt appeared that my machine was installing the drivers for my device. After about 5 minutes, the installation was complete and it prompted me to reboot my computer and so i did. Before it powered off, the machine said it was completing the updates first, then done. When it came back on, Windows failed to load and reboot my computer. The complete error msg was: "Windows failed to start. A recent hardware or software change might be the cause. To fix the problem:
    1. Insert your windows installation disc & restart your computer.
    2. Choose language settings, and then click 'Next.'
    3. Click "Repair your computer."
    If you do not have this disc, contact your system administrator or computer manufacturer for assistance.
    File: ntoskrnl.exe
    Status: 0xc0000098
    Info: Windows failed to load because a required file is missing, or corrupt."
    I already followed the instructions since i have the disc with me but my laptop is still not working. I already did Startup Repair and System Restore but it didn't solve the problem. Please help me. Thank you so much!
    Ntoskrnl.exe is a driver in Windows\ System 32. Replace with Windows\ Driver Cache\ i386\ ntoskrnl.exe in safe mode. If that doesn't work, you've to reinstall W7 as suggested earlier and make a backup with Macrium Reflect. It's not sure that your problem is related to PC Suite. Your PC or laptop might be to old for W7. Reinstall PC or OVI Suite as administrator in XP mode.
    http://www.macrium.com/reflectfree.asp
    http://europe.nokia.com/support/download-software/nokia-ovi-suite
    ‡Thank you for hitting the Blue/Green Star button‡
    N8-00 RM 596 V:111.030.0609; E71-1(05) RM 346 V: 500.21.009

Maybe you are looking for

  • Problems with image and audio in Premiere

    Hi! I'm using Premiere Elements 9, but there's no synchronization with imagen and audio because the image is slower than audio and it's causing problems when I'm editing. Why can I do? It's there a poblem that can I fix in "Preferences" or is my lapt

  • HT4236 how to delete photos from photo libarby

    how to delete photos from photo album

  • Sales order replication (missing partner information in modifications)

    Hi, I configured a sales order to be replicated from R/3 into CRM. When the order is created in R/3, it gets replicated into CRM with all the information and without any error. But when I change some information in the R/3 sales order, the new BDoc m

  • Tabs and tab groups are lost

    Closing Firefox and restarting it, invariably all my tab groups seem to have lost their tabs. Reopening hibernated groups or closed groups (using tab group manager add-on) will not help. This did not happen on my previous install but since having upg

  • Problem installing OSX Mountain Lion on MacPro

    Hi, i'm trying to install the new OSX on my macpro but it fails when should reboot for install... I'm starting from the latest Snow Leopard version and the MacPro isa a MacPro4,1 Quad-Core Intel Xeon 2.26Ghz. I have already installed on my macbookpro