1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Random BSOD's Debuglogs Attached

Discussion in 'Windows XP' started by Ross1308, 2007/10/21.

  1. 2007/10/21
    Ross1308

    Ross1308 Inactive Thread Starter

    Joined:
    2007/10/21
    Messages:
    3
    Likes Received:
    0
    Hey guys the title says it all really its not a physical memory dump its a BSOD one of thos ones where you cant see the code to anyway here is what the Debug log says

    ...................................................................................
    This dump file has an exception of interest stored in it.
    The stored exception information can be accessed via .ecxr.
    (964.8a0): Access violation - code c0000005 (first/second chance not available)
    eax=575c3a43 ebx=00270000 ecx=4f444e49 edx=02fc3b20 esi=02fc3b18 edi=00000007
    eip=7c91142e esp=0012d6b0 ebp=0012d8d0 iopl=0 nv up ei ng nz na pe cy
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200287
    ntdll!RtlAllocateHeap+0x653:
    7c91142e 8b39 mov edi,dword ptr [ecx] ds:0023:4f444e49=????????
    0:000> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Exception Analysis *
    * *
    *******************************************************************************

    Unable to load image C:\Program Files\Mozilla Firefox\nspr4.dll, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for nspr4.dll
    *** ERROR: Module load completed but symbols could not be loaded for nspr4.dll
    *** WARNING: Unable to verify timestamp for xpcom_core.dll
    *** ERROR: Module load completed but symbols could not be loaded for xpcom_core.dll
    *** WARNING: Unable to verify timestamp for firefox.exe
    *** ERROR: Module load completed but symbols could not be loaded for firefox.exe
    *** WARNING: Unable to verify timestamp for nss3.dll
    *** ERROR: Module load completed but symbols could not be loaded for nss3.dll
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for shell32.dll -
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: kernel32!pNlsUserInfo ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: kernel32!pNlsUserInfo ***
    *** ***
    *************************************************************************

    FAULTING_IP:
    ntdll!RtlAllocateHeap+653
    7c91142e 8b39 mov edi,dword ptr [ecx]

    EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff)
    .exr 0xffffffffffffffff
    ExceptionAddress: 7c91142e (ntdll!RtlAllocateHeap+0x00000653)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 4f444e49
    Attempt to read from address 4f444e49

    DEFAULT_BUCKET_ID: HEAP_CORRUPTION

    PROCESS_NAME: firefox.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: 4f444e49

    LAST_CONTROL_TRANSFER: from 77c2c3c9 to 7c91142e

    STACK_TEXT:
    0012d8d0 77c2c3c9 00270000 00000000 0000002f ntdll!RtlAllocateHeap+0x653
    0012d910 77c2c3e7 0000002f 0012d92c 77c2c42e msvcrt!_heap_alloc+0xe0
    0012d91c 77c2c42e 0000002f 00000000 0012d93c msvcrt!_nh_malloc+0x13
    0012d92c 77c46147 0000002f 30000000 0012ddd8 msvcrt!malloc+0x27
    0012d93c 601a7393 0012d96c 02fc3b20 7c8360dd msvcrt!_strdup+0x22
    WARNING: Stack unwind information not available. Following frames may be wrong.
    0012de44 7c910732 00000042 002712e8 00270000 nspr4+0x7393
    0012de64 0012e18f 02c8d928 603a3f1b 00000038 ntdll!RtlpAllocateFromHeapLookaside+0x42
    0012de6c 603a3f1b 00000038 0012e15c 0012e1b4 0x12e18f
    0012de70 00000000 0012e15c 0012e1b4 603a1131 xpcom_core+0x43f1b


    STACK_COMMAND: ~0s; .ecxr ; kb

    ADDITIONAL_DEBUG_TEXT: Enable Pageheap/AutoVerifer

    FAULTING_THREAD: 000008a0

    PRIMARY_PROBLEM_CLASS: HEAP_CORRUPTION

    BUGCHECK_STR: APPLICATION_FAULT_HEAP_CORRUPTION_STRING_DEREFERENCE_INVALID_POINTER_READ

    SYMBOL_NAME: heap_corruption!heap_corruption

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: heap_corruption

    IMAGE_NAME: heap_corruption

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    FAILURE_BUCKET_ID: heap_corruption!heap_corruption_c0000005_HEAP_CORRUPTION

    BUCKET_ID: APPLICATION_FAULT_HEAP_CORRUPTION_STRING_DEREFERENCE_INVALID_POINTER_READ_heap_corruption!heap_corruption

    Followup: MachineOwner
    ---------

    eax=575c3a43 ebx=00270000 ecx=4f444e49 edx=02fc3b20 esi=02fc3b18 edi=00000007
    eip=7c91142e esp=0012d6b0 ebp=0012d8d0 iopl=0 nv up ei ng nz na pe cy
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200287
    ntdll!RtlAllocateHeap+0x653:
    7c91142e 8b39 mov edi,dword ptr [ecx] ds:0023:4f444e49=????????
    ChildEBP RetAddr Args to Child
    0012d8d0 77c2c3c9 00270000 00000000 0000002f ntdll!RtlAllocateHeap+0x653 (FPO: [Non-Fpo])
    0012d910 77c2c3e7 0000002f 0012d92c 77c2c42e msvcrt!_heap_alloc+0xe0 (FPO: [Non-Fpo])
    0012d91c 77c2c42e 0000002f 00000000 0012d93c msvcrt!_nh_malloc+0x13 (FPO: [Non-Fpo])
    0012d92c 77c46147 0000002f 30000000 0012ddd8 msvcrt!malloc+0x27 (FPO: [Non-Fpo])
    0012d93c 601a7393 0012d96c 02fc3b20 7c8360dd msvcrt!_strdup+0x22 (FPO: [Non-Fpo])
    WARNING: Stack unwind information not available. Following frames may be wrong.
    0012de44 7c910732 00000042 002712e8 00270000 nspr4+0x7393
    0012de64 0012e18f 02c8d928 603a3f1b 00000038 ntdll!RtlpAllocateFromHeapLookaside+0x42 (FPO: [Non-Fpo])
    0012de6c 603a3f1b 00000038 0012e15c 0012e1b4 0x12e18f
    0012de70 00000000 0012e15c 0012e1b4 603a1131 xpcom_core+0x43f1b
    start end module name
    00400000 00b5f000 firefox firefox.exe Sat Sep 15 02:07:02 2007 (46EB3036)
    015a0000 015c3000 nvappfilter nvappfilter.dll Fri Sep 08 21:13:01 2006 (4501CECD)
    10000000 100c3000 xfire_toucan_28220 xfire_toucan_28220.dll Wed Oct 03 00:50:33 2007 (4702D949)
    10100000 1010f000 lgscroll lgscroll.dll Tue Apr 24 02:41:39 2007 (462D6053)
    10d00000 10d0f000 GameHook GameHook.dll Tue Apr 24 02:40:27 2007 (462D600B)
    20000000 202c5000 xpsp2res xpsp2res.dll Wed Aug 04 08:56:41 2004 (411096B9)
    20b00000 20b4b000 imon imon.dll Fri May 11 07:30:49 2007 (46440D99)
    30000000 302ca000 NPSWF32 NPSWF32.dll Mon Jun 11 21:34:25 2007 (466DB1D1)
    5ad70000 5ada8000 uxtheme uxtheme.dll Wed Aug 04 08:56:43 2004 (411096BB)
    5b860000 5b8b4000 netapi32 netapi32.dll Thu Aug 17 13:28:27 2006 (44E460EB)
    60010000 60022000 jar50 jar50.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60040000 6004a000 myspell myspell.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60050000 6005e000 spellchk spellchk.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60090000 600c1000 freebl3 freebl3.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    600d0000 60141000 js3250 js3250.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    601a0000 601c7000 nspr4 nspr4.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    601d0000 6022b000 nss3 nss3.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60230000 60271000 nssckbi nssckbi.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60280000 60287000 plc4 plc4.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60290000 60296000 plds4 plds4.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    602a0000 602a8000 npnul32 npnul32.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    602b0000 602ca000 smime3 smime3.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    602d0000 6030f000 softokn3 softokn3.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60310000 60330000 ssl3 ssl3.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60340000 60354000 xpcom_compat xpcom_compat.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    60360000 603ca000 xpcom_core xpcom_core.dll Sat Sep 15 02:12:59 2007 (46EB319B)
    662b0000 66308000 hnetcfg hnetcfg.dll Wed Aug 04 08:56:16 2004 (411096A0)
    71a50000 71a8f000 mswsock mswsock.dll Wed Aug 04 08:59:20 2004 (41109758)
    71a90000 71a98000 wshtcpip wshtcpip.dll Wed Aug 04 08:57:49 2004 (411096FD)
    71aa0000 71aa8000 ws2help ws2help.dll Wed Aug 04 08:57:39 2004 (411096F3)
    71ab0000 71ac7000 ws2_32 ws2_32.dll Wed Aug 04 08:57:38 2004 (411096F2)
    71ad0000 71ad9000 wsock32 wsock32.dll Wed Aug 04 08:57:51 2004 (411096FF)
    71bf0000 71c03000 samlib samlib.dll Wed Aug 04 08:56:29 2004 (411096AD)
    72d10000 72d18000 msacm32_72d10000 msacm32.drv Sat Aug 18 06:33:30 2001 (3B7DFE2A)
    72d20000 72d29000 wdmaud wdmaud.drv Wed Aug 04 08:56:54 2004 (411096C6)
    73000000 73026000 winspool winspool.drv Wed Aug 04 08:56:38 2004 (411096B6)
    73b50000 73b67000 avifil32 avifil32.dll Wed Aug 04 08:57:07 2004 (411096D3)
    746f0000 7471a000 MSIMTF MSIMTF.dll Wed Aug 04 08:58:33 2004 (41109729)
    74720000 7476b000 MSCTF MSCTF.dll Wed Aug 04 08:57:30 2004 (411096EA)
    75a70000 75a91000 msvfw32 msvfw32.dll Wed Aug 04 08:59:15 2004 (41109753)
    75cf0000 75d81000 mlang mlang.dll Wed Aug 04 08:56:29 2004 (411096AD)
    75e90000 75f40000 sxs sxs.dll Thu Oct 19 14:56:28 2006 (4537840C)
    76380000 76385000 msimg32 msimg32.dll Wed Aug 04 08:58:31 2004 (41109727)
    76390000 763ad000 imm32 imm32.dll Wed Aug 04 08:56:30 2004 (411096AE)
    763b0000 763f9000 comdlg32 comdlg32.dll Wed Aug 04 08:56:32 2004 (411096B0)
    767f0000 76817000 schannel schannel.dll Wed Apr 25 15:21:15 2007 (462F63DB)
    769c0000 76a73000 userenv userenv.dll Wed Aug 04 08:56:41 2004 (411096B9)
    76b40000 76b6d000 winmm winmm.dll Wed Aug 04 08:57:10 2004 (411096D6)
    76bf0000 76bfb000 psapi psapi.dll Wed Aug 04 08:56:58 2004 (411096CA)
    76c30000 76c5e000 wintrust wintrust.dll Wed Aug 04 08:56:41 2004 (411096B9)
    76c90000 76cb8000 imagehlp imagehlp.dll Wed Aug 04 08:56:25 2004 (411096A9)
    76d60000 76d79000 iphlpapi iphlpapi.dll Fri May 19 13:59:41 2006 (446DC13D)
    76f20000 76f47000 dnsapi dnsapi.dll Mon Jun 26 18:37:10 2006 (44A01B46)
    76f60000 76f8c000 wldap32 wldap32.dll Wed Aug 04 08:56:43 2004 (411096BB)
    76fb0000 76fb8000 winrnr winrnr.dll Wed Aug 04 08:56:35 2004 (411096B3)
    76fc0000 76fc6000 rasadhlp rasadhlp.dll Mon Jun 26 18:37:10 2006 (44A01B46)
    76fd0000 7704f000 clbcatq clbcatq.dll Tue Jul 26 05:39:44 2005 (42E5BE90)
    77050000 77115000 comres comres.dll Wed Aug 04 08:56:36 2004 (411096B4)
    77120000 771ab000 oleaut32 oleaut32.dll Thu May 17 12:28:05 2007 (464C3C45)
    771b0000 77256000 wininet wininet.dll Wed Aug 22 14:12:18 2007 (46CC3632)
    773d0000 774d3000 comctl32 comctl32.dll Fri Aug 25 16:45:55 2006 (44EF1B33)
    774e0000 7761d000 ole32 ole32.dll Tue Jul 26 05:39:47 2005 (42E5BE93)
    77690000 776b1000 ntmarta ntmarta.dll Wed Aug 04 08:57:02 2004 (411096CE)
    77920000 77a13000 setupapi setupapi.dll Wed Aug 04 08:56:32 2004 (411096B0)
    77a80000 77b14000 crypt32 crypt32.dll Wed Aug 04 08:56:01 2004 (41109691)
    77b20000 77b32000 msasn1 msasn1.dll Wed Aug 04 08:57:23 2004 (411096E3)
    77b40000 77b62000 apphelp apphelp.dll Wed Aug 04 08:56:36 2004 (411096B4)
    77bd0000 77bd7000 midimap midimap.dll Wed Aug 04 08:56:25 2004 (411096A9)
    77be0000 77bf5000 msacm32 msacm32.dll Wed Aug 04 08:57:03 2004 (411096CF)
    77c00000 77c08000 version version.dll Wed Aug 04 08:56:39 2004 (411096B7)
    77c10000 77c68000 msvcrt msvcrt.dll Wed Aug 04 08:59:14 2004 (41109752)
    77dd0000 77e6b000 advapi32 advapi32.dll Wed Aug 04 08:56:23 2004 (411096A7)
    77e70000 77f02000 rpcrt4 rpcrt4.dll Mon Jul 09 14:09:42 2007 (46923396)
    77f10000 77f57000 gdi32 gdi32.dll Tue Jun 19 14:31:19 2007 (4677DAA7)
    77f60000 77fd6000 shlwapi shlwapi.dll Wed Aug 22 14:12:17 2007 (46CC3631)
    77fe0000 77ff1000 secur32 secur32.dll Wed Aug 04 08:56:49 2004 (411096C1)
    78130000 781cb000 msvcr80 msvcr80.dll Mon Jun 05 22:10:49 2006 (44849DD9)
    7c340000 7c396000 msvcr71 msvcr71.dll Fri Feb 21 12:42:20 2003 (3E561EAC)
    7c420000 7c4a7000 msvcp80 msvcp80.dll Mon Jun 05 22:13:37 2006 (44849E81)
    7c800000 7c8f5000 kernel32 kernel32.dll Mon Apr 16 16:52:53 2007 (46239BD5)
    7c900000 7c9b0000 ntdll ntdll.dll Wed Aug 04 08:56:36 2004 (411096B4)
    7c9c0000 7d1d5000 shell32 shell32.dll Tue Dec 19 21:52:11 2006 (45885F0B)
    7e410000 7e4a0000 user32 user32.dll Thu Mar 08 15:36:28 2007 (45F02D7C)
    Closing open log file c:\debuglog.txt
     
  2. 2007/10/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Ross1308 - Welcome to the Board :)

    Your debug log has a symbol problem - I suggest you run the memory dump through our Dump Data Collection Tool .....

    http://www.windowsbbs.com/showthread.php?t=33471

    And a footnote ....

    Unfortunately these logs require expert knowledge to analyze and there are only 2 members (who occasionally visit WindowsBBS.com) that have the depth of knowledge necessary. Other members can make observations and suggestions as to how you might proceed toward finding the cause ....
     

  3. to hide this advert.

  4. 2007/10/21
    Ross1308

    Ross1308 Inactive Thread Starter

    Joined:
    2007/10/21
    Messages:
    3
    Likes Received:
    0
    Hmmm it seems to be the program i use to configure my logitech mouse, also i debugged my other to logs and the one is caused by a Program i use called Webcammax and another is caused by my logitech webcam, is there a way of fixing these errors

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.8.0004.0 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini101707-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700
    Debug session time: Wed Oct 17 23:31:11.671 2007 (GMT+1)
    System Uptime: 0 days 5:37:02.438
    Loading Kernel Symbols
    .......................................................................................................................
    Loading User Symbols
    Loading unloaded module list
    ........................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 19, {20, e1ddc6f8, e1ddc708, 1c020601}



    Probably caused by : KHALMNPR.exe

    Followup: MachineOwner
    ---------

    1: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    BAD_POOL_HEADER (19)
    The pool is already corrupt at the time of the current request.
    This may or may not be due to the caller.
    The internal pool links must be walked to figure out a possible cause of
    the problem, and then special pool applied to the suspect tags or the driver
    verifier to a suspect driver.
    Arguments:
    Arg1: 00000020, a pool block header size is corrupt.
    Arg2: e1ddc6f8, The pool entry we were looking for within the page.
    Arg3: e1ddc708, The next pool entry.
    Arg4: 1c020601, (reserved)

    Debugging Details:
    ------------------




    BUGCHECK_STR: 0x19_20

    POOL_ADDRESS: e1ddc6f8

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    PROCESS_NAME: KHALMNPR.exe

    LAST_CONTROL_TRANSFER: from 8054a583 to 804f9deb

    STACK_TEXT:
    b5a16c38 8054a583 00000019 00000020 e1ddc6f8 nt!KeBugCheckEx+0x1b
    b5a16c88 805d0cac e1ddc700 f0547350 89a6e958 nt!ExFreePoolWithTag+0x2a3
    b5a16d14 805d1150 00000000 00000000 89a6e958 nt!PspExitThread+0x340
    b5a16d34 805d1490 89a6e958 00000000 b5a16d64 nt!PspTerminateThreadByPointer+0x52
    b5a16d54 8054086c 00000000 00000000 00c4ffb0 nt!NtTerminateThread+0x70
    b5a16d54 7c90eb94 00000000 00000000 00c4ffb0 nt!KiFastCallEntry+0xfc
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00c4ffb0 00000000 00000000 00000000 00000000 0x7c90eb94


    STACK_COMMAND: kb

    PROCESS_OBJECT: 89a506e0

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: KHALMNPR

    IMAGE_NAME: KHALMNPR.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    FAILURE_BUCKET_ID: 0x19_20_IMAGE_KHALMNPR.exe

    BUCKET_ID: 0x19_20_IMAGE_KHALMNPR.exe

    Followup: MachineOwner
    ---------

    eax=bab4013c ebx=e1ddc6f8 ecx=00000000 edx=00000000 esi=e1ddc6f8 edi=89a506e0
    eip=804f9deb esp=b5a16c20 ebp=b5a16c38 iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f9deb 5d pop ebp
     
    Last edited: 2007/10/21
  5. 2007/10/22
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  6. 2007/10/22
    Ross1308

    Ross1308 Inactive Thread Starter

    Joined:
    2007/10/21
    Messages:
    3
    Likes Received:
    0
    Hey Pete thanks for your help i looked in the Eventviewer and there seems to be no errors on my System or anything else only 3 errors in the Applications section but they dont say anything about logitech so i guess ill search further that google link was useful i am updatiing all the drivers for all my logitech stuff, Keyboard (Logitech G15) Mouse (Logitech G5) Webcam (Logitech Quick Cam Connect) Headset ( Logitech USB 350 Premium
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.