1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Windows XP BSOD

Discussion in 'Windows XP' started by nimrods, 2007/05/02.

  1. 2007/05/02
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    Hi All

    I have repeating BSOD on my machine - the reason (according to the windbg) is different every time - hardware/ntkrnl/memory_corruption/Pool_Corruption.

    I already tried running memtest on both memory sticks separately, and also reinstalled windows. I suspect the video card (NVIDIA GEFORCE FX5500), but I'm not sure. I already installed the latest drivers for the video card.

    I also started verifier on all non-microsoft drivers on the system, but didn't get any result yet.


    Here are some of the dump analysis:


    Microsoft (R) Windows Debugger Version 6.7.0005.0
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [D:\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: *** Invalid ***
    ****************************************************************************
    * Symbol loading may be unreliable without a symbol search path. *
    * Use .symfix to have the debugger choose a symbol path. *
    * After setting your symbol path, use .reload to refresh symbol locations. *
    ****************************************************************************
    Executable search path is:
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805533a0
    Debug session time: Wed May 2 21:04:25.593 2007 (GMT+3)
    System Uptime: 0 days 3:07:39.167
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Loading Kernel Symbols
    ....................................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
    Loading unloaded module list
    ...........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 4E, {99, 3ffbf, 0, 0}

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *** ERROR: Symbol file could not be found. Defaulted to export symbols for win32k.sys -
    Probably caused by : memory_corruption ( nt!MmTrimAllSystemPagableMemory+9796 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PFN_LIST_CORRUPT (4e)
    Typically caused by drivers passing bad memory descriptor lists (ie: calling
    MmUnlockPages twice with the same list, etc). If a kernel debugger is
    available get the stack trace.
    Arguments:
    Arg1: 00000099, A PTE or PFN is corrupt
    Arg2: 0003ffbf, page frame number
    Arg3: 00000000, current page state
    Arg4: 00000000, 0

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    MODULE_NAME: nt

    FAULTING_MODULE: 804d7000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 45e53f9c

    BUGCHECK_STR: 0x4E_99

    DEFAULT_BUCKET_ID: WRONG_SYMBOLS

    LAST_CONTROL_TRANSFER: from 8051f08e to 804f8aef

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b95065dc 8051f08e 0000004e 00000099 0003ffbf nt!KeBugCheckEx+0x1b
    b9506620 8050d336 c0605428 c0a85000 00000000 nt!MmTrimAllSystemPagableMemory+0x9796
    b95066d4 8050fa26 c0605420 01605420 c0607000 nt!MmFlushImageSection+0x208e
    b9506718 805c74d4 00d8e1f0 860f2828 40010004 nt!MmGrowKernelStack+0x21f8
    b95067c0 805c75b7 40010004 b950681c 804fd287 nt!PsGetProcessExitTime+0x7d0
    b95067cc 804fd287 860f2828 b9506818 b950680c nt!PsGetProcessExitTime+0x8b3
    b950681c 8053ca91 00000001 00000000 b9506834 nt!KiDeliverApc+0x1af
    b9506840 8053ca28 000200f0 0000003b 00000009 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb7d
    b9506900 80595e6b 00001f80 80595ed3 b9506990 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    b9506968 bf800b0b 00000000 0012fd50 0012fd28 nt!KeUserModeCallback+0x87
    b95069a8 bf800b0b 85f557f0 bf8136d8 bbe81a40 win32k+0xb0b
    b9506a20 bf813825 bbe81a40 00000006 00000001 win32k+0xb0b
    b9506a4c 804fa943 860f2828 85f557f0 85f55824 win32k!EngDeleteSurface+0x3d6f
    b9506a6c 805c75ff 860f2828 860f2828 00000001 nt!KeInsertQueueApc+0x4b
    b9506a8c 804fd1fc 40010004 860f2828 804fd2b8 nt!PsGetProcessExitTime+0x8fb
    b9506aec 80595e6b b9506bb0 b9506ba8 b9506b9c nt!KiDeliverApc+0x124
    b9506b30 804f8f2b b9506bc0 80535230 804d8fd8 nt!KeUserModeCallback+0x87
    b9506b48 bf89ed5f 0000002f b9506b70 00000030 nt!KeSetEventBoostPriority+0xaf
    b9506bd0 bf8bd4bc 00030000 00000001 b9506d18 win32k!EngGradientFill+0x2299
    b9506c10 bf83f2f5 74730de9 00000000 00000001 win32k!FONTOBJ_pxoGetXform+0xc35c
    b9506c88 bf83f4c8 03e69d70 00000000 00000001 win32k!EngUnmapFontFileFD+0x4f42
    b9506ca4 bf801afc 00000000 00000001 00000000 win32k!EngUnmapFontFileFD+0x5115
    b9506cec bf819fc8 b9506d18 000025ff 00000000 win32k+0x1afc
    b9506d4c 8053ca28 0012fd98 00000000 00000000 win32k!EngQueryPerformanceCounter+0x5af
    b9506d64 7c90eb94 badb0d00 0012fd58 00000000 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    b9506d68 badb0d00 0012fd58 00000000 00000000 0x7c90eb94
    b9506d6c 0012fd58 00000000 00000000 00000000 0xbadb0d00
    b9506d70 00000000 00000000 00000000 00000000 0x12fd58


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!MmTrimAllSystemPagableMemory+9796
    8051f08e 8b5008 mov edx,dword ptr [eax+8]

    SYMBOL_STACK_INDEX: 1

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!MmTrimAllSystemPagableMemory+9796

    IMAGE_NAME: memory_corruption

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner
    ---------



    _________________________________________________________________


    Microsoft (R) Windows Debugger Version 6.7.0005.0
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [D:\MEMORY_hardware.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: *** Invalid ***
    ****************************************************************************
    * Symbol loading may be unreliable without a symbol search path. *
    * Use .symfix to have the debugger choose a symbol path. *
    * After setting your symbol path, use .reload to refresh symbol locations. *
    ****************************************************************************
    Executable search path is:
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805533a0
    Debug session time: Thu Apr 26 08:53:33.312 2007 (GMT+3)
    System Uptime: 0 days 0:23:36.879
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Loading Kernel Symbols
    .................................................................................................................
    Loading User Symbols

    Loading unloaded module list
    ...........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 7E, {c000001d, f6f3efde, f5388cb0, f53889ac}

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ks.sys -
    Probably caused by : hardware ( ks!KsGenerateEvent+3a1 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: c000001d, The exception code that was not handled
    Arg2: f6f3efde, The address that the exception occurred at
    Arg3: f5388cb0, Exception Record Address
    Arg4: f53889ac, Context Record Address

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    FAULTING_MODULE: 804d7000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.

    FAULTING_IP:
    ks!KsGenerateEvent+3a1
    f6f3efde ff ???

    EXCEPTION_RECORD: f5388cb0 -- (.exr 0xfffffffff5388cb0)
    ExceptionAddress: f6f3efde (ks!KsGenerateEvent+0x000003a1)
    ExceptionCode: c000001d (Illegal instruction)
    ExceptionFlags: 00000000
    NumberParameters: 0

    CONTEXT: f53889ac -- (.cxr 0xfffffffff53889ac)
    eax=f6f3efda ebx=860c23d8 ecx=86142980 edx=80010031 esi=8055a3c0 edi=86142980
    eip=f6f3efde esp=f5388d78 ebp=f5388dac iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
    ks!KsGenerateEvent+0x3a1:
    f6f3efde ff ???
    Resetting default scope

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x7E

    MISALIGNED_IP:
    ks!KsGenerateEvent+3a1
    f6f3efde ff ???

    LAST_CONTROL_TRANSFER: from 805c4cce to f6f3efde

    FAILED_INSTRUCTION_ADDRESS:
    ks!KsGenerateEvent+3a1
    f6f3efde ff ???

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f5388dac 805c4cce 86142980 00000000 00000000 ks!KsGenerateEvent+0x3a1
    f5388ddc 805411c2 80533ee6 80000000 00000000 nt!PsRemoveCreateThreadNotifyRoutine+0x21e
    00000000 00000000 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x5a2


    FOLLOWUP_IP:
    ks!KsGenerateEvent+3a1
    f6f3efde ff ???

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: ks!KsGenerateEvent+3a1

    FOLLOWUP_NAME: MachineOwner

    STACK_COMMAND: .cxr 0xfffffffff53889ac ; kb

    MODULE_NAME: hardware

    IMAGE_NAME: hardware

    FAILURE_BUCKET_ID: IP_MISALIGNED_ks.sys

    BUCKET_ID: IP_MISALIGNED_ks.sys

    Followup: MachineOwner
    ---------

    _________________________________________________________________


    Loading Dump File [D:\MEMORY_ntkrnl.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: *** Invalid ***
    ****************************************************************************
    * Symbol loading may be unreliable without a symbol search path. *
    * Use .symfix to have the debugger choose a symbol path. *
    * After setting your symbol path, use .reload to refresh symbol locations. *
    ****************************************************************************
    Executable search path is:
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805533a0
    Debug session time: Thu Apr 26 20:15:17.141 2007 (GMT+3)
    System Uptime: 0 days 11:18:45.731
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Loading Kernel Symbols
    ...................................................................................................................
    Loading User Symbols

    Loading unloaded module list
    ....................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 7E, {c0000005, 805d7160, f7a3fc84, f7a3f980}

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    Probably caused by : ntkrnlpa.exe ( nt!RtlUnicodeStringToAnsiString+20 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: 805d7160, The address that the exception occurred at
    Arg3: f7a3fc84, Exception Record Address
    Arg4: f7a3f980, Context Record Address

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    MODULE_NAME: nt

    FAULTING_MODULE: 804d7000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 45e53f9c

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    nt!RtlUnicodeStringToAnsiString+20
    805d7160 0fb707 movzx eax,word ptr [edi]

    EXCEPTION_RECORD: f7a3fc84 -- (.exr 0xfffffffff7a3fc84)
    ExceptionAddress: 805d7160 (nt!RtlUnicodeStringToAnsiString+0x00000020)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 00000030
    Attempt to read from address 00000030

    CONTEXT: f7a3f980 -- (.cxr 0xfffffffff7a3f980)
    eax=f7a3fd78 ebx=00000000 ecx=00000000 edx=00000000 esi=806d02d0 edi=00000030
    eip=805d7160 esp=f7a3fd4c ebp=f7a3fd58 iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    nt!RtlUnicodeStringToAnsiString+0x20:
    805d7160 0fb707 movzx eax,word ptr [edi] ds:0023:00000030=????
    Resetting default scope

    DEFAULT_BUCKET_ID: WRONG_SYMBOLS

    BUGCHECK_STR: 0x7E

    LAST_CONTROL_TRANSFER: from 805072ed to 805d7160

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f7a3fd58 805072ed f7a3fd78 00000030 00000001 nt!RtlUnicodeStringToAnsiString+0x20
    f7a3fd8c 80508af6 e208bc88 00000000 865c23f8 nt!MmProbeAndLockSelectedPages+0x8c9
    f7a3fdac 805c4cce 00000000 00000000 00000000 nt!MmCanFileBeTruncated+0xab2
    f7a3fddc 805411c2 80508a58 00000000 00000000 nt!PsRemoveCreateThreadNotifyRoutine+0x21e
    00000000 00000000 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x5a2


    FOLLOWUP_IP:
    nt!RtlUnicodeStringToAnsiString+20
    805d7160 0fb707 movzx eax,word ptr [edi]

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    IMAGE_NAME: ntkrnlpa.exe

    SYMBOL_NAME: nt!RtlUnicodeStringToAnsiString+20

    STACK_COMMAND: .cxr 0xfffffffff7a3f980 ; kb

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner
    ---------

    _________________________________________________________________

    Any suggestions?

    Thanks
     
  2. 2007/05/03
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    You'll need to fix your symbols.

    More info on how to post a Dump Data Log.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2007/05/04
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    need some help with the symbol files...

    I've installed the full package of windows XP symbols from microsoft under d:\localsymbols I run the following commands on the debugger:

    .sympath d:\localsymbols
    !analyze -v

    and get the following box (with the debugging)

    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_MMPTE ***
    *** ***
    *************************************************************************
    Any suggestions?
     
  5. 2007/05/04
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    Ok, I used the debugWiz to analyze and here is what I got:

    first dump:


    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805533a0
    Debug session time: Thu Apr 26 20:15:17.141 2007 (GMT+3)
    System Uptime: 0 days 11:18:45.731
    Loading Kernel Symbols
    ...................................................................................................................
    Loading User Symbols

    Loading unloaded module list

    Use !analyze -v to get detailed debugging information.

    BugCheck 7E, {c0000005, 805d7160, f7a3fc84, f7a3f980}

    Probably caused by : ntkrnlpa.exe ( nt!RtlUnicodeStringToAnsiString+20 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q

    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: 805d7160, The address that the exception occurred at
    Arg3: f7a3fc84, Exception Record Address
    Arg4: f7a3f980, Context Record Address

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    nt!RtlUnicodeStringToAnsiString+20
    805d7160 0fb707 movzx eax,word ptr [edi]

    EXCEPTION_RECORD: f7a3fc84 -- (.exr 0xfffffffff7a3fc84)
    .exr 0xfffffffff7a3fc84
    ExceptionAddress: 805d7160 (nt!RtlUnicodeStringToAnsiString+0x00000020)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 00000030
    Attempt to read from address 00000030

    CONTEXT: f7a3f980 -- (.cxr 0xfffffffff7a3f980)
    .cxr 0xfffffffff7a3f980
    eax=f7a3fd78 ebx=00000000 ecx=00000000 edx=00000000 esi=806d02d0 edi=00000030
    eip=805d7160 esp=f7a3fd4c ebp=f7a3fd58 iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    nt!RtlUnicodeStringToAnsiString+0x20:
    805d7160 0fb707 movzx eax,word ptr [edi] ds:0023:00000030=????
    .cxr
    Resetting default scope

    PROCESS_NAME: System

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: 00000030

    BUGCHECK_STR: 0x7E

    DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE

    LAST_CONTROL_TRANSFER: from 805072ed to 805d7160

    STACK_TEXT:
    f7a3fd58 805072ed f7a3fd78 00000030 00000001 nt!RtlUnicodeStringToAnsiString+0x20
    f7a3fd8c 80508af6 e208bc88 00000000 865c23f8 nt!MiSegmentDelete+0x77
    f7a3fdac 805c4cce 00000000 00000000 00000000 nt!MiDereferenceSegmentThread+0x9e
    f7a3fddc 805411c2 80508a58 00000000 00000000 nt!PspSystemThreadStartup+0x34
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


    FOLLOWUP_IP:
    nt!RtlUnicodeStringToAnsiString+20
    805d7160 0fb707 movzx eax,word ptr [edi]

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlpa.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 45e53f9c

    SYMBOL_NAME: nt!RtlUnicodeStringToAnsiString+20

    STACK_COMMAND: .cxr 0xfffffffff7a3f980 ; kb

    FAILURE_BUCKET_ID: 0x7E_nt!RtlUnicodeStringToAnsiString+20

    BUCKET_ID: 0x7E_nt!RtlUnicodeStringToAnsiString+20

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=805d7160 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
    eip=804f8aef esp=f7a3f774 ebp=f7a3f78c iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8aef 5d pop ebp
    ChildEBP RetAddr Args to Child
    f7a3f78c 805c4c94 0000007e c0000005 805d7160 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    f7a3f7a8 805c4cf4 f7a3f7d0 80535291 f7a3f7d8 nt!PspUnhandledExceptionInSystemThread+0x1a (FPO: [Non-Fpo])
    f7a3fddc 805411c2 80508a58 00000000 00000000 nt!PspSystemThreadStartup+0x5a (FPO: [Non-Fpo])
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
    start end module name
    804d7000 806cd580 nt ntkrnlpa.exe Wed Feb 28 10:38:52 2007 (45E53F9C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 08:59:05 2004 (41107B29)
    bf000000 bf011580 dxg dxg.sys Wed Aug 04 09:00:51 2004 (41107B93)
    bf012000 bf3dc300 nv4_disp nv4_disp.dll Thu Feb 24 18:08:56 2005 (421DFC18)
    bf800000 bf9c2180 win32k win32k.sys Thu Mar 08 15:47:34 2007 (45F013F6)
    bff50000 bff52f00 TSDDD TSDDD.dll Wed Aug 04 10:57:02 2004 (411096CE)
    eb15d000 eb187180 kmixer kmixer.sys Wed Jun 14 11:47:45 2006 (448FCD31)
    ec6fc000 ec6ff800 asyncmac asyncmac.sys Wed Aug 04 09:05:02 2004 (41107C8E)
    ef459000 ef499280 HTTP HTTP.sys Fri Mar 17 02:33:09 2006 (441A03C5)
    ef76a000 ef7bb480 srv srv.sys Mon Aug 14 13:34:39 2006 (44E051BF)
    ef80c000 ef838400 mrxdav mrxdav.sys Wed Aug 04 09:00:49 2004 (41107B91)
    ef8af000 ef8c3400 wdmaud wdmaud.sys Wed Jun 14 12:00:44 2006 (448FD03C)
    f1f02000 f1f03a80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
    f1f9b000 f1fa9d80 sysaudio sysaudio.sys Wed Aug 04 09:15:54 2004 (41107F1A)
    f1feb000 f1ff9e00 dump_viamraid dump_viamraid.sys Thu Apr 07 08:59:10 2005 (4254CC2E)
    f1ffb000 f20076a0 HPZid412 HPZid412.sys Wed Sep 29 08:41:41 2004 (415A5925)
    f200b000 f2013d80 HIDCLASS HIDCLASS.SYS Wed Aug 04 09:08:18 2004 (41107D52)
    f201b000 f202a900 Cdfs Cdfs.SYS Wed Aug 04 09:14:09 2004 (41107EB1)
    f207e000 f2080900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    f2092000 f2095780 dump_diskdump dump_diskdump.sys Wed Aug 04 08:59:51 2004 (41107B57)
    f2096000 f2099f60 HPZipr12 HPZipr12.sys Wed Sep 29 08:41:44 2004 (415A5928)
    f209a000 f209cf80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001 (3B7D82FD)
    f209e000 f20a1b00 usbscan usbscan.sys Wed Aug 04 08:58:44 2004 (41107B14)
    f20a2000 f20a4580 hidusb hidusb.sys Sat Aug 18 00:02:16 2001 (3B7D8658)
    f27c7000 f27cb500 watchdog watchdog.sys Wed Aug 04 09:07:32 2004 (41107D24)
    f27d7000 f27dc3e0 HPZius12 HPZius12.sys Wed Sep 29 08:40:14 2004 (415A58CE)
    f27df000 f27e5500 usbprint usbprint.sys Wed Aug 04 09:01:23 2004 (41107BB3)
    f27e7000 f27ed180 HIDPARSE HIDPARSE.SYS Wed Aug 04 09:08:15 2004 (41107D4F)
    f27ef000 f27f6b80 usbccgp usbccgp.sys Wed Aug 04 09:08:45 2004 (41107D6D)
    f2d21000 f2d41f00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f2d42000 f2db0a00 mrxsmb mrxsmb.sys Fri May 05 12:41:42 2006 (445B1DD6)
    f2dd0000 f2dfaa00 rdbss rdbss.sys Fri May 05 12:47:55 2006 (445B1F4B)
    f2dfb000 f2e1cd00 afd afd.sys Wed Aug 04 09:14:13 2004 (41107EB5)
    f2e1d000 f2e44c00 netbt netbt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f2e45000 f2e9cd80 tcpip tcpip.sys Thu Apr 20 14:51:47 2006 (444775D3)
    f2e9d000 f2eaf400 ipsec ipsec.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f35b1000 f35b3280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f5652000 f5685200 update update.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f5686000 f56b6100 rdpdr rdpdr.sys Wed Aug 04 09:01:10 2004 (41107BA6)
    f6376000 f637e700 netbios netbios.sys Wed Aug 04 09:03:19 2004 (41107C27)
    f6c55000 f6c58280 ndisuio ndisuio.sys Wed Aug 04 09:03:10 2004 (41107C1E)
    f6df9000 f6e09e00 psched psched.sys Wed Aug 04 09:04:16 2004 (41107C60)
    f6e0a000 f6e20680 ndiswan ndiswan.sys Wed Aug 04 09:14:30 2004 (41107EC6)
    f6e21000 f6e44980 portcls portcls.sys Wed Aug 04 09:15:47 2004 (41107F13)
    f6e45000 f6ed2340 smwdm smwdm.sys Tue Jul 15 22:59:58 2003 (3F145D3E)
    f6ed3000 f6ee6900 parport parport.sys Wed Aug 04 08:59:04 2004 (41107B28)
    f6f1b000 f6f3de80 USBPORT USBPORT.SYS Wed Aug 04 09:08:34 2004 (41107D62)
    f6f3e000 f6f60680 ks ks.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    f6f61000 f6f74780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 09:07:04 2004 (41107D08)
    f6f75000 f72c04c0 nv4_mini nv4_mini.sys Thu Feb 24 18:13:44 2005 (421DFD38)
    f7309000 f7323580 Mup Mup.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    f7324000 f7350a80 NDIS NDIS.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f7351000 f73dd480 Ntfs Ntfs.sys Wed Aug 04 09:15:06 2004 (41107EEA)
    f73de000 f73f4780 KSecDD KSecDD.sys Wed Aug 04 08:59:45 2004 (41107B51)
    f73f5000 f7406f00 sr sr.sys Wed Aug 04 09:06:22 2004 (41107CDE)
    f7407000 f7426780 fltMgr fltMgr.sys Mon Aug 21 12:14:57 2006 (44E97991)
    f7427000 f743e800 SCSIPORT SCSIPORT.SYS Wed Aug 04 08:59:39 2004 (41107B4B)
    f743f000 f7456480 atapi atapi.sys Wed Aug 04 08:59:41 2004 (41107B4D)
    f7457000 f747c700 dmio dmio.sys Wed Aug 04 09:07:13 2004 (41107D11)
    f747d000 f749b880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    f749c000 f74aca80 pci pci.sys Wed Aug 04 09:07:45 2004 (41107D31)
    f74ad000 f74dad80 ACPI ACPI.sys Wed Aug 04 09:07:35 2004 (41107D27)
    f75dc000 f75e4c00 isapnp isapnp.sys Fri Aug 17 23:58:01 2001 (3B7D8559)
    f75ec000 f75f6500 MountMgr MountMgr.sys Wed Aug 04 08:58:29 2004 (41107B05)
    f75fc000 f7608c80 VolSnap VolSnap.sys Wed Aug 04 09:00:14 2004 (41107B6E)
    f760c000 f761ae00 viamraid viamraid.sys Thu Apr 07 08:59:10 2005 (4254CC2E)
    f761c000 f7624e00 disk disk.sys Wed Aug 04 08:59:53 2004 (41107B59)
    f762c000 f7638200 CLASSPNP CLASSPNP.SYS Wed Aug 04 09:14:26 2004 (41107EC2)
    f763c000 f7647580 gagp30kx gagp30kx.sys Wed Aug 04 09:07:43 2004 (41107D2F)
    f76dc000 f76e5f00 termdd termdd.sys Wed Aug 04 08:58:52 2004 (41107B1C)
    f770c000 f771a100 usbhub usbhub.sys Wed Aug 04 09:08:40 2004 (41107D68)
    f771c000 f7726380 imapi imapi.sys Wed Aug 04 09:00:12 2004 (41107B6C)
    f772c000 f7738180 cdrom cdrom.sys Wed Aug 04 08:59:52 2004 (41107B58)
    f773c000 f774a080 redbook redbook.sys Wed Aug 04 08:59:34 2004 (41107B46)
    f774c000 f7758e00 i8042prt i8042prt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f775c000 f776bd80 serial serial.sys Wed Aug 04 09:15:51 2004 (41107F17)
    f776c000 f777ab80 drmk drmk.sys Wed Aug 04 09:07:54 2004 (41107D3A)
    f777c000 f7786600 fetnd5bv fetnd5bv.sys Thu Dec 16 07:36:28 2004 (41C11EDC)
    f778c000 f7794a00 processr processr.sys Wed Aug 04 08:59:14 2004 (41107B32)
    f779c000 f77a8880 rasl2tp rasl2tp.sys Wed Aug 04 09:14:21 2004 (41107EBD)
    f77ac000 f77b6200 raspppoe raspppoe.sys Wed Aug 04 09:05:06 2004 (41107C92)
    f77bc000 f77c7d00 raspptp raspptp.sys Wed Aug 04 09:14:26 2004 (41107EC2)
    f77cc000 f77d4900 msgpc msgpc.sys Wed Aug 04 09:04:11 2004 (41107C5B)
    f77ec000 f77f5480 NDProxy NDProxy.SYS Fri Aug 17 23:55:30 2001 (3B7D84C2)
    f783c000 f7844880 Fips Fips.SYS Sat Aug 18 04:31:49 2001 (3B7DC585)
    f784c000 f7854700 wanarp wanarp.sys Wed Aug 04 09:04:57 2004 (41107C89)
    f785c000 f7862200 PCIIDEX PCIIDEX.SYS Wed Aug 04 08:59:40 2004 (41107B4C)
    f7864000 f7868900 PartMgr PartMgr.sys Sat Aug 18 04:32:23 2001 (3B7DC5A7)
    f7884000 f7889a00 mouclass mouclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f7894000 f7898080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f78ec000 f78f1200 vga vga.sys Wed Aug 04 09:07:06 2004 (41107D0A)
    f78f4000 f78f8a80 Msfs Msfs.SYS Wed Aug 04 09:00:37 2004 (41107B85)
    f791c000 f7923880 Npfs Npfs.SYS Wed Aug 04 09:00:38 2004 (41107B86)
    f79a4000 f79a9000 usbuhci usbuhci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f79ac000 f79b2800 usbehci usbehci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f79b4000 f79b8580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f79bc000 f79c2000 kbdclass kbdclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f79c4000 f79c8880 TDI TDI.SYS Wed Aug 04 09:07:47 2004 (41107D33)
    f79ec000 f79ef000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f7a90000 f7a93c80 mssmbios mssmbios.sys Wed Aug 04 09:07:47 2004 (41107D33)
    f7aa0000 f7aa3c80 serenum serenum.sys Wed Aug 04 08:59:06 2004 (41107B2A)
    f7aa4000 f7aa6580 ndistapi ndistapi.sys Fri Aug 17 23:55:29 2001 (3B7D84C1)
    f7adc000 f7addb80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f7ade000 f7adf100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f7ae0000 f7ae1500 viaide viaide.sys Wed Aug 04 08:59:42 2004 (41107B4E)
    f7ae2000 f7ae3700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
    f7afa000 f7afb120 aeaudio aeaudio.sys Mon Apr 01 17:39:14 2002 (3CA87112)
    f7b00000 f7b01100 swenum swenum.sys Wed Aug 04 08:58:41 2004 (41107B11)
    f7b06000 f7b07280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f7b5c000 f7b5df00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f7b5e000 f7b5f080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
    f7b60000 f7b61080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f7b62000 f7b63080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f7c5c000 f7c5cb80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f7ca1000 f7ca1c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)
    f7ced000 f7cedd00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)

    Unloaded modules:
    eb15d000 eb188000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb15d000 eb188000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb15d000 eb188000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb471000 eb49c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb471000 eb49c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb53c000 eb567000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb63a000 eb665000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb63a000 eb665000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eb63a000 eb665000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ebebf000 ebeea000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ee803000 ee82e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ee803000 ee82e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef861000 ef88c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef88c000 ef8af000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7cbb000 f7cbc000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6146000 f6153000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6ba5000 f6bb3000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b1a000 f7b1c000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f792c000 f7931000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f656c000 f656f000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt



    second dump:

    Opened log file 'c:\debuglog.txt'



    Loading Dump File [D:\MEMORY_memory_corruption.DMP]
    Kernel Summary Dump File: Only kernel address space is available


    ....................................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
    Loading unloaded module list

    Use !analyze -v to get detailed debugging information.

    BugCheck 4E, {99, 3ffbf, 0, 0}

    Probably caused by : memory_corruption ( nt!MiDeletePte+43e )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q

    PFN_LIST_CORRUPT (4e)
    Typically caused by drivers passing bad memory descriptor lists (ie: calling
    MmUnlockPages twice with the same list, etc). If a kernel debugger is
    available get the stack trace.
    Arguments:
    Arg1: 00000099, A PTE or PFN is corrupt
    Arg2: 0003ffbf, page frame number
    Arg3: 00000000, current page state
    Arg4: 00000000, 0

    Debugging Details:
    ------------------


    BUGCHECK_STR: 0x4E_99

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    PROCESS_NAME: hpqtra08.exe

    LAST_CONTROL_TRANSFER: from 8051f08e to 804f8aef

    STACK_TEXT:
    b95065dc 8051f08e 0000004e 00000099 0003ffbf nt!KeBugCheckEx+0x1b
    b9506620 8050d336 c0605428 c0a85000 00000000 nt!MiDeletePte+0x43e
    b95066d4 8050fa26 c0605420 01605420 c0607000 nt!MiDeletePteRange+0x9c
    b9506718 805c74d4 00d8e1f0 860f2828 40010004 nt!MmCleanProcessAddressSpace+0x1ae
    b95067c0 805c75b7 40010004 b950681c 804fd287 nt!PspExitThread+0x680
    b95067cc 804fd287 860f2828 b9506818 b950680c nt!PsExitSpecialApc+0x23
    b950681c 8053ca91 00000001 00000000 b9506834 nt!KiDeliverApc+0x1af
    b950681c 7c90ead0 00000001 00000000 b9506834 nt!KiServiceExit+0x58
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fd74 00000000 00000000 00000000 00000000 0x7c90ead0


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!MiDeletePte+43e
    8051f08e 8b5008 mov edx,dword ptr [eax+8]

    SYMBOL_STACK_INDEX: 1

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 45e53f9c

    SYMBOL_NAME: nt!MiDeletePte+43e

    IMAGE_NAME: memory_corruption

    FAILURE_BUCKET_ID: 0x4E_99_VRF_nt!MiDeletePte+43e

    BUCKET_ID: 0x4E_99_VRF_nt!MiDeletePte+43e

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=0003ffbf ecx=00000000 edx=816ff8e4 esi=816f4a70 edi=03ffffff
    eip=804f8aef esp=b95065c4 ebp=b95065dc iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8aef 5d pop ebp
    ChildEBP RetAddr Args to Child
    b95065dc 8051f08e 0000004e 00000099 0003ffbf nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    b9506620 8050d336 c0605428 c0a85000 00000000 nt!MiDeletePte+0x43e (FPO: [Non-Fpo])
    b95066d4 8050fa26 c0605420 01605420 c0607000 nt!MiDeletePteRange+0x9c (FPO: [Non-Fpo])
    b9506718 805c74d4 00d8e1f0 860f2828 40010004 nt!MmCleanProcessAddressSpace+0x1ae (FPO: [Non-Fpo])
    b95067c0 805c75b7 40010004 b950681c 804fd287 nt!PspExitThread+0x680 (FPO: [Non-Fpo])
    b95067cc 804fd287 860f2828 b9506818 b950680c nt!PsExitSpecialApc+0x23 (FPO: [Non-Fpo])
    b950681c 8053ca91 00000001 00000000 b9506834 nt!KiDeliverApc+0x1af (FPO: [Non-Fpo])
    b950681c 7c90ead0 00000001 00000000 b9506834 nt!KiServiceExit+0x58 (FPO: [0,0] TrapFrame @ b9506834)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fd74 00000000 00000000 00000000 00000000 0x7c90ead0
    start end module name
    804d7000 806cd580 nt ntkrnlpa.exe Wed Feb 28 10:38:52 2007 (45E53F9C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 08:59:05 2004 (41107B29)
    b6e8e000 b6eb8180 kmixer kmixer.sys Wed Jun 14 11:47:45 2006 (448FCD31)
    b9336000 b9376280 HTTP HTTP.sys Fri Mar 17 02:33:09 2006 (441A03C5)
    b9563000 b9566800 asyncmac asyncmac.sys Wed Aug 04 09:05:02 2004 (41107C8E)
    b961f000 b9670480 srv srv.sys Mon Aug 14 13:34:39 2006 (44E051BF)
    b96c1000 b96ed400 mrxdav mrxdav.sys Wed Aug 04 09:00:49 2004 (41107B91)
    b98fc000 b9910400 wdmaud wdmaud.sys Wed Jun 14 12:00:44 2006 (448FD03C)
    ba405000 ba428980 portcls portcls.sys Wed Aug 04 09:15:47 2004 (41107F13)
    ba429000 ba43c900 parport parport.sys Wed Aug 04 08:59:04 2004 (41107B28)
    ba43d000 ba45fe80 USBPORT USBPORT.SYS Wed Aug 04 09:08:34 2004 (41107D62)
    ba460000 ba482680 ks ks.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    ba483000 ba496780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 09:07:04 2004 (41107D08)
    ba499000 ba49c280 ndisuio ndisuio.sys Wed Aug 04 09:03:10 2004 (41107C1E)
    ba4d3000 ba4d5900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    ba513000 ba52d580 Mup Mup.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    ba52e000 ba55aa80 NDIS NDIS.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    ba55b000 ba5e7480 Ntfs Ntfs.sys Wed Aug 04 09:15:06 2004 (41107EEA)
    ba5e8000 ba5fe780 KSecDD KSecDD.sys Wed Aug 04 08:59:45 2004 (41107B51)
    ba5ff000 ba610f00 sr sr.sys Wed Aug 04 09:06:22 2004 (41107CDE)
    ba611000 ba630780 fltMgr fltMgr.sys Mon Aug 21 12:14:57 2006 (44E97991)
    ba631000 ba648800 SCSIPORT SCSIPORT.SYS Wed Aug 04 08:59:39 2004 (41107B4B)
    ba649000 ba662200 viamraid viamraid.sys Wed Nov 08 08:23:49 2006 (455177F5)
    ba663000 ba67a480 atapi atapi.sys Wed Aug 04 08:59:41 2004 (41107B4D)
    ba67b000 ba6a0700 dmio dmio.sys Wed Aug 04 09:07:13 2004 (41107D11)
    ba6a1000 ba6bf880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    ba6c0000 ba6d0a80 pci pci.sys Wed Aug 04 09:07:45 2004 (41107D31)
    ba6d1000 ba6fed80 ACPI ACPI.sys Wed Aug 04 09:07:35 2004 (41107D27)
    bf000000 bf011580 dxg dxg.sys Wed Aug 04 09:00:51 2004 (41107B93)
    bf012000 bf463580 nv4_disp nv4_disp.dll Sun Oct 22 23:02:50 2006 (453BDC7A)
    bf800000 bf9c2180 win32k win32k.sys Thu Mar 08 15:47:34 2007 (45F013F6)
    bff50000 bff52f00 TSDDD TSDDD.dll Wed Aug 04 10:57:02 2004 (411096CE)
    f2d46000 f2d5f200 dump_viamraid dump_viamraid.sys Wed Nov 08 08:23:49 2006 (455177F5)
    f2d60000 f2d80f00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f2d81000 f2defa00 mrxsmb mrxsmb.sys Fri May 05 12:41:42 2006 (445B1DD6)
    f2df0000 f2e1aa00 rdbss rdbss.sys Fri May 05 12:47:55 2006 (445B1F4B)
    f2e1b000 f2e3cd00 afd afd.sys Wed Aug 04 09:14:13 2004 (41107EB5)
    f2e3d000 f2e64c00 netbt netbt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f2e65000 f2ebcd80 tcpip tcpip.sys Thu Apr 20 14:51:47 2006 (444775D3)
    f2ebd000 f2ecf400 ipsec ipsec.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f4068000 f409b200 update update.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f409c000 f40cc100 rdpdr rdpdr.sys Wed Aug 04 09:01:10 2004 (41107BA6)
    f40f5000 f40f9500 watchdog watchdog.sys Wed Aug 04 09:07:32 2004 (41107D24)
    f4115000 f411a3e0 HPZius12 HPZius12.sys Wed Sep 29 08:40:14 2004 (415A58CE)
    f4505000 f4507280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f4583000 f4589180 HIDPARSE HIDPARSE.SYS Wed Aug 04 09:08:15 2004 (41107D4F)
    f458b000 f4592b80 usbccgp usbccgp.sys Wed Aug 04 09:08:45 2004 (41107D6D)
    f45a3000 f45aa880 Npfs Npfs.SYS Wed Aug 04 09:00:38 2004 (41107B86)
    f46a0000 f46ac6a0 HPZid412 HPZid412.sys Wed Sep 29 08:41:41 2004 (415A5925)
    f46b0000 f46b8d80 HIDCLASS HIDCLASS.SYS Wed Aug 04 09:08:18 2004 (41107D52)
    f47e6000 f47e6b80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f48bf000 f48c2c80 mssmbios mssmbios.sys Wed Aug 04 09:07:47 2004 (41107D33)
    f4a30000 f4a34a80 Msfs Msfs.SYS Wed Aug 04 09:00:37 2004 (41107B85)
    f4a38000 f4a3d200 vga vga.sys Wed Aug 04 09:07:06 2004 (41107D0A)
    f4a68000 f4a6da00 mouclass mouclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f4a70000 f4a74080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f4a78000 f4a7c580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f696b000 f6979d80 sysaudio sysaudio.sys Wed Aug 04 09:15:54 2004 (41107F1A)
    f697b000 f6983880 Fips Fips.SYS Sat Aug 18 04:31:49 2001 (3B7DC585)
    f699b000 f69a3700 wanarp wanarp.sys Wed Aug 04 09:04:57 2004 (41107C89)
    f69bb000 f69c4f00 termdd termdd.sys Wed Aug 04 08:58:52 2004 (41107B1C)
    f6dcb000 f6dd4480 NDProxy NDProxy.SYS Fri Aug 17 23:55:30 2001 (3B7D84C2)
    f6e7b000 f6e7df80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001 (3B7D82FD)
    f6e7f000 f6e82b00 usbscan usbscan.sys Wed Aug 04 08:58:44 2004 (41107B14)
    f6fe0000 f6ff0e00 psched psched.sys Wed Aug 04 09:04:16 2004 (41107C60)
    f6ff1000 f7007680 ndiswan ndiswan.sys Wed Aug 04 09:14:30 2004 (41107EC6)
    f7029000 f70b6340 smwdm smwdm.sys Tue Jul 15 22:59:58 2003 (3F145D3E)
    f70b7000 f7486400 nv4_mini nv4_mini.sys Sun Oct 22 23:08:02 2006 (453BDDB2)
    f7487000 f748fc00 isapnp isapnp.sys Fri Aug 17 23:58:01 2001 (3B7D8559)
    f7497000 f74a1500 MountMgr MountMgr.sys Wed Aug 04 08:58:29 2004 (41107B05)
    f74a7000 f74b3c80 VolSnap VolSnap.sys Wed Aug 04 09:00:14 2004 (41107B6E)
    f74b7000 f74bfe00 disk disk.sys Wed Aug 04 08:59:53 2004 (41107B59)
    f74c7000 f74d3200 CLASSPNP CLASSPNP.SYS Wed Aug 04 09:14:26 2004 (41107EC2)
    f74d7000 f74e2580 gagp30kx gagp30kx.sys Wed Aug 04 09:07:43 2004 (41107D2F)
    f7597000 f75a1380 imapi imapi.sys Wed Aug 04 09:00:12 2004 (41107B6C)
    f75a7000 f75b3180 cdrom cdrom.sys Wed Aug 04 08:59:52 2004 (41107B58)
    f75b7000 f75c5080 redbook redbook.sys Wed Aug 04 08:59:34 2004 (41107B46)
    f75c7000 f75d3e00 i8042prt i8042prt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f75d7000 f75e6d80 serial serial.sys Wed Aug 04 09:15:51 2004 (41107F17)
    f75e7000 f75f5b80 drmk drmk.sys Wed Aug 04 09:07:54 2004 (41107D3A)
    f75f7000 f7601600 fetnd5bv fetnd5bv.sys Thu Dec 16 07:36:28 2004 (41C11EDC)
    f7607000 f7616000 AmdK8 AmdK8.sys Fri Jul 30 00:20:24 2004 (41096A18)
    f7617000 f7623880 rasl2tp rasl2tp.sys Wed Aug 04 09:14:21 2004 (41107EBD)
    f7627000 f7631200 raspppoe raspppoe.sys Wed Aug 04 09:05:06 2004 (41107C92)
    f7637000 f7642d00 raspptp raspptp.sys Wed Aug 04 09:14:26 2004 (41107EC2)
    f7647000 f764f900 msgpc msgpc.sys Wed Aug 04 09:04:11 2004 (41107C5B)
    f7667000 f766f700 netbios netbios.sys Wed Aug 04 09:03:19 2004 (41107C27)
    f7687000 f7695100 usbhub usbhub.sys Wed Aug 04 09:08:40 2004 (41107D68)
    f76a7000 f76b6900 Cdfs Cdfs.SYS Wed Aug 04 09:14:09 2004 (41107EB1)
    f7707000 f770d200 PCIIDEX PCIIDEX.SYS Wed Aug 04 08:59:40 2004 (41107B4C)
    f770f000 f7713900 PartMgr PartMgr.sys Sat Aug 18 04:32:23 2001 (3B7DC5A7)
    f7717000 f771f000 videX32 videX32.sys Tue Oct 17 14:22:24 2006 (4534CB00)
    f7737000 f773d800 usbehci usbehci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f773f000 f7745000 kbdclass kbdclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f7747000 f774b880 TDI TDI.SYS Wed Aug 04 09:07:47 2004 (41107D33)
    f781f000 f7825500 usbprint usbprint.sys Wed Aug 04 09:01:23 2004 (41107BB3)
    f788f000 f7894000 usbuhci usbuhci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f7897000 f789a000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f794f000 f7951580 hidusb hidusb.sys Sat Aug 18 00:02:16 2001 (3B7D8658)
    f795b000 f795ec80 serenum serenum.sys Wed Aug 04 08:59:06 2004 (41107B2A)
    f795f000 f7961580 ndistapi ndistapi.sys Fri Aug 17 23:55:29 2001 (3B7D84C1)
    f7977000 f797af60 HPZipr12 HPZipr12.sys Wed Sep 29 08:41:44 2004 (415A5928)
    f797b000 f797e780 dump_diskdump dump_diskdump.sys Wed Aug 04 08:59:51 2004 (41107B57)
    f7987000 f7988b80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f7989000 f798a100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f798b000 f798c500 viaide viaide.sys Wed Aug 04 08:59:42 2004 (41107B4E)
    f798d000 f798e700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
    f7993000 f7994a80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
    f79b5000 f79b6120 aeaudio aeaudio.sys Mon Apr 01 17:39:14 2002 (3CA87112)
    f7a21000 f7a22100 swenum swenum.sys Wed Aug 04 08:58:41 2004 (41107B11)
    f7a29000 f7a2a280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f7a37000 f7a38f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f7a39000 f7a3a080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
    f7a3b000 f7a3c080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f7a3d000 f7a3e080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f7a64000 f7a64d00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)
    f7bca000 f7bcac00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)

    Unloaded modules:
    b768f000 b76ba000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b83e3000 b840e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b98ae000 b98d9000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b77000 f7b78000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f68fb000 f6909000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b98d9000 b98fc000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f682b000 f6838000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f79f7000 f79f9000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7677000 f7680000 processr.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4a40000 f4a45000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4509000 f450c000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  6. 2007/05/04
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    and even more dumps...

    Third dump:


    kd> !analyze -v;r;kv;lmtn;.logclose;q

    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: c000001d, The exception code that was not handled
    Arg2: f6f3efde, The address that the exception occurred at
    Arg3: f5388cb0, Exception Record Address
    Arg4: f53889ac, Context Record Address

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.

    FAULTING_IP:
    ks!PerformLockedOperation+ae
    f6f3efde ff ???

    EXCEPTION_RECORD: f5388cb0 -- (.exr 0xfffffffff5388cb0)
    .exr 0xfffffffff5388cb0
    ExceptionAddress: f6f3efde (ks!PerformLockedOperation+0x000000ae)
    ExceptionCode: c000001d (Illegal instruction)
    ExceptionFlags: 00000000
    NumberParameters: 0

    CONTEXT: f53889ac -- (.cxr 0xfffffffff53889ac)
    .cxr 0xfffffffff53889ac
    eax=f6f3efda ebx=860c23d8 ecx=86142980 edx=80010031 esi=8055a3c0 edi=86142980
    eip=f6f3efde esp=f5388d78 ebp=f5388dac iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
    ks!PerformLockedOperation+0xae:
    f6f3efde ff ???
    .cxr
    Resetting default scope

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x7E

    PROCESS_NAME: System

    ERROR_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.

    MISALIGNED_IP:
    ks!PerformLockedOperation+ae
    f6f3efde ff ???

    LAST_CONTROL_TRANSFER: from 805c4cce to f6f3efde

    FAILED_INSTRUCTION_ADDRESS:
    ks!PerformLockedOperation+ae
    f6f3efde ff ???

    STACK_TEXT:
    f5388dac 805c4cce 86142980 00000000 00000000 ks!PerformLockedOperation+0xae
    f5388ddc 805411c2 80533ee6 80000000 00000000 nt!PspSystemThreadStartup+0x34
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


    FOLLOWUP_IP:
    ks!PerformLockedOperation+ae
    f6f3efde ff ???

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: ks!PerformLockedOperation+ae

    FOLLOWUP_NAME: MachineOwner

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    STACK_COMMAND: .cxr 0xfffffffff53889ac ; kb

    MODULE_NAME: hardware

    IMAGE_NAME: hardware

    FAILURE_BUCKET_ID: IP_MISALIGNED_ks.sys

    BUCKET_ID: IP_MISALIGNED_ks.sys

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=f6f3efde ecx=00000000 edx=00000000 esi=00000000 edi=00000000
    eip=804f8aef esp=f53887a0 ebp=f53887b8 iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8aef 5d pop ebp
    ChildEBP RetAddr Args to Child
    f53887b8 805c4c94 0000007e c000001d f6f3efde nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    f53887d4 805c4cf4 f53887fc 80535291 f5388804 nt!PspUnhandledExceptionInSystemThread+0x1a (FPO: [Non-Fpo])
    f5388ddc 805411c2 80533ee6 80000000 00000000 nt!PspSystemThreadStartup+0x5a (FPO: [Non-Fpo])
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
    start end module name
    804d7000 806cd580 nt ntkrnlpa.exe Wed Feb 28 10:38:52 2007 (45E53F9C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 08:59:05 2004 (41107B29)
    bf000000 bf011580 dxg dxg.sys Wed Aug 04 09:00:51 2004 (41107B93)
    bf012000 bf3dc300 nv4_disp nv4_disp.dll Thu Feb 24 18:08:56 2005 (421DFC18)
    bf800000 bf9c2180 win32k win32k.sys Thu Mar 08 15:47:34 2007 (45F013F6)
    ee5cc000 ee5f6180 kmixer kmixer.sys Wed Jun 14 11:47:45 2006 (448FCD31)
    ef331000 ef371280 HTTP HTTP.sys Fri Mar 17 02:33:09 2006 (441A03C5)
    ef552000 ef5a3480 srv srv.sys Mon Aug 14 13:34:39 2006 (44E051BF)
    ef5f4000 ef620400 mrxdav mrxdav.sys Wed Aug 04 09:00:49 2004 (41107B91)
    ef78f000 ef7a3400 wdmaud wdmaud.sys Wed Jun 14 12:00:44 2006 (448FD03C)
    f0e77000 f0ee5a00 mrxsmb mrxsmb.sys Fri May 05 12:41:42 2006 (445B1DD6)
    f0ee6000 f0f06f00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f0f07000 f0f31a00 rdbss rdbss.sys Fri May 05 12:47:55 2006 (445B1F4B)
    f100b000 f100f500 watchdog watchdog.sys Wed Aug 04 09:07:32 2004 (41107D24)
    f1209000 f1217d80 sysaudio sysaudio.sys Wed Aug 04 09:15:54 2004 (41107F1A)
    f1279000 f1287e00 dump_viamraid dump_viamraid.sys Thu Apr 07 08:59:10 2005 (4254CC2E)
    f1289000 f12956a0 HPZid412 HPZid412.sys Wed Sep 29 08:41:41 2004 (415A5925)
    f1847000 f184a780 dump_diskdump dump_diskdump.sys Wed Aug 04 08:59:51 2004 (41107B57)
    f184b000 f184ef60 HPZipr12 HPZipr12.sys Wed Sep 29 08:41:44 2004 (415A5928)
    f185b000 f185df80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001 (3B7D82FD)
    f185f000 f1862b00 usbscan usbscan.sys Wed Aug 04 08:58:44 2004 (41107B14)
    f1863000 f1865580 hidusb hidusb.sys Sat Aug 18 00:02:16 2001 (3B7D8658)
    f211e000 f213fd00 afd afd.sys Wed Aug 04 09:14:13 2004 (41107EB5)
    f2140000 f2167c00 netbt netbt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f2168000 f21bfd80 tcpip tcpip.sys Thu Apr 20 14:51:47 2006 (444775D3)
    f21c0000 f21d2400 ipsec ipsec.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f21f3000 f21f6280 ndisuio ndisuio.sys Wed Aug 04 09:03:10 2004 (41107C1E)
    f285d000 f285f280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f4bbb000 f4bee200 update update.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f4bef000 f4c1f100 rdpdr rdpdr.sys Wed Aug 04 09:01:10 2004 (41107BA6)
    f4c28000 f4c29080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f4c2a000 f4c2b080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f4c2c000 f4c2d080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
    f4c2e000 f4c2ff00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f4d0e000 f4d10900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    f4d93000 f4da1100 usbhub usbhub.sys Wed Aug 04 09:08:40 2004 (41107D68)
    f4dc3000 f4dcb880 Fips Fips.SYS Sat Aug 18 04:31:49 2001 (3B7DC585)
    f4e78000 f4e80700 wanarp wanarp.sys Wed Aug 04 09:04:57 2004 (41107C89)
    f4e98000 f4ea1480 NDProxy NDProxy.SYS Fri Aug 17 23:55:30 2001 (3B7D84C2)
    f4ef8000 f4f01f00 termdd termdd.sys Wed Aug 04 08:58:52 2004 (41107B1C)
    f4f4e000 f4f4eb80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f4fc6000 f4fcc180 HIDPARSE HIDPARSE.SYS Wed Aug 04 09:08:15 2004 (41107D4F)
    f4fce000 f4fd4500 usbprint usbprint.sys Wed Aug 04 09:01:23 2004 (41107BB3)
    f4fde000 f4fe5b80 usbccgp usbccgp.sys Wed Aug 04 09:08:45 2004 (41107D6D)
    f55cb000 f55d0a00 mouclass mouclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f55d3000 f55d7080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f55db000 f55df580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f5693000 f569b700 netbios netbios.sys Wed Aug 04 09:03:19 2004 (41107C27)
    f56fb000 f56fec80 mssmbios mssmbios.sys Wed Aug 04 09:07:47 2004 (41107D33)
    f67eb000 f67f3d80 HIDCLASS HIDCLASS.SYS Wed Aug 04 09:08:18 2004 (41107D52)
    f67fb000 f680a900 Cdfs Cdfs.SYS Wed Aug 04 09:14:09 2004 (41107EB1)
    f6df9000 f6e09e00 psched psched.sys Wed Aug 04 09:04:16 2004 (41107C60)
    f6e0a000 f6e20680 ndiswan ndiswan.sys Wed Aug 04 09:14:30 2004 (41107EC6)
    f6e21000 f6e44980 portcls portcls.sys Wed Aug 04 09:15:47 2004 (41107F13)
    f6e45000 f6ed2340 smwdm smwdm.sys Tue Jul 15 22:59:58 2003 (3F145D3E)
    f6ed3000 f6ee6900 parport parport.sys Wed Aug 04 08:59:04 2004 (41107B28)
    f6f1b000 f6f3de80 USBPORT USBPORT.SYS Wed Aug 04 09:08:34 2004 (41107D62)
    f6f3e000 f6f60680 ks ks.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    f6f61000 f6f74780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 09:07:04 2004 (41107D08)
    f6f75000 f72c04c0 nv4_mini nv4_mini.sys Thu Feb 24 18:13:44 2005 (421DFD38)
    f7309000 f7323580 Mup Mup.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    f7324000 f7350a80 NDIS NDIS.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f7351000 f73dd480 Ntfs Ntfs.sys Wed Aug 04 09:15:06 2004 (41107EEA)
    f73de000 f73f4780 KSecDD KSecDD.sys Wed Aug 04 08:59:45 2004 (41107B51)
    f73f5000 f7406f00 sr sr.sys Wed Aug 04 09:06:22 2004 (41107CDE)
    f7407000 f7426780 fltMgr fltMgr.sys Mon Aug 21 12:14:57 2006 (44E97991)
    f7427000 f743e800 SCSIPORT SCSIPORT.SYS Wed Aug 04 08:59:39 2004 (41107B4B)
    f743f000 f7456480 atapi atapi.sys Wed Aug 04 08:59:41 2004 (41107B4D)
    f7457000 f747c700 dmio dmio.sys Wed Aug 04 09:07:13 2004 (41107D11)
    f747d000 f749b880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    f749c000 f74aca80 pci pci.sys Wed Aug 04 09:07:45 2004 (41107D31)
    f74ad000 f74dad80 ACPI ACPI.sys Wed Aug 04 09:07:35 2004 (41107D27)
    f75dc000 f75e4c00 isapnp isapnp.sys Fri Aug 17 23:58:01 2001 (3B7D8559)
    f75ec000 f75f6500 MountMgr MountMgr.sys Wed Aug 04 08:58:29 2004 (41107B05)
    f75fc000 f7608c80 VolSnap VolSnap.sys Wed Aug 04 09:00:14 2004 (41107B6E)
    f760c000 f761ae00 viamraid viamraid.sys Thu Apr 07 08:59:10 2005 (4254CC2E)
    f761c000 f7624e00 disk disk.sys Wed Aug 04 08:59:53 2004 (41107B59)
    f762c000 f7638200 CLASSPNP CLASSPNP.SYS Wed Aug 04 09:14:26 2004 (41107EC2)
    f763c000 f7647580 gagp30kx gagp30kx.sys Wed Aug 04 09:07:43 2004 (41107D2F)
    f772c000 f7736380 imapi imapi.sys Wed Aug 04 09:00:12 2004 (41107B6C)
    f773c000 f7748180 cdrom cdrom.sys Wed Aug 04 08:59:52 2004 (41107B58)
    f774c000 f775a080 redbook redbook.sys Wed Aug 04 08:59:34 2004 (41107B46)
    f775c000 f7768e00 i8042prt i8042prt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f776c000 f777bd80 serial serial.sys Wed Aug 04 09:15:51 2004 (41107F17)
    f777c000 f778ab80 drmk drmk.sys Wed Aug 04 09:07:54 2004 (41107D3A)
    f778c000 f7796600 fetnd5bv fetnd5bv.sys Thu Dec 16 07:36:28 2004 (41C11EDC)
    f779c000 f77a4a00 processr processr.sys Wed Aug 04 08:59:14 2004 (41107B32)
    f77ac000 f77b8880 rasl2tp rasl2tp.sys Wed Aug 04 09:14:21 2004 (41107EBD)
    f77bc000 f77c6200 raspppoe raspppoe.sys Wed Aug 04 09:05:06 2004 (41107C92)
    f77cc000 f77d7d00 raspptp raspptp.sys Wed Aug 04 09:14:26 2004 (41107EC2)
    f77dc000 f77e4900 msgpc msgpc.sys Wed Aug 04 09:04:11 2004 (41107C5B)
    f785c000 f7862200 PCIIDEX PCIIDEX.SYS Wed Aug 04 08:59:40 2004 (41107B4C)
    f7864000 f7868900 PartMgr PartMgr.sys Sat Aug 18 04:32:23 2001 (3B7DC5A7)
    f789c000 f78a13e0 HPZius12 HPZius12.sys Wed Sep 29 08:40:14 2004 (415A58CE)
    f79a4000 f79a9000 usbuhci usbuhci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f79ac000 f79b1200 vga vga.sys Wed Aug 04 09:07:06 2004 (41107D0A)
    f79b4000 f79ba800 usbehci usbehci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f79bc000 f79c2000 kbdclass kbdclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f79c4000 f79c8880 TDI TDI.SYS Wed Aug 04 09:07:47 2004 (41107D33)
    f79d4000 f79d8a80 Msfs Msfs.SYS Wed Aug 04 09:00:37 2004 (41107B85)
    f79dc000 f79e3880 Npfs Npfs.SYS Wed Aug 04 09:00:38 2004 (41107B86)
    f79ec000 f79ef000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f7a9c000 f7a9fc80 serenum serenum.sys Wed Aug 04 08:59:06 2004 (41107B2A)
    f7aa0000 f7aa2580 ndistapi ndistapi.sys Fri Aug 17 23:55:29 2001 (3B7D84C1)
    f7adc000 f7addb80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f7ade000 f7adf100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f7ae0000 f7ae1500 viaide viaide.sys Wed Aug 04 08:59:42 2004 (41107B4E)
    f7ae2000 f7ae3700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
    f7afa000 f7afb120 aeaudio aeaudio.sys Mon Apr 01 17:39:14 2002 (3CA87112)
    f7b06000 f7b07a80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
    f7b16000 f7b17280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f7b28000 f7b29100 swenum swenum.sys Wed Aug 04 08:58:41 2004 (41107B11)
    f7c68000 f7c68c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)
    f7cb9000 f7cb9d00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)

    Unloaded modules:
    ee5cc000 ee5f7000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ee77b000 ee7a6000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ee77b000 ee7a6000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef719000 ef744000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7cbb000 f7cbc000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f77ec000 f77f9000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef744000 ef767000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f67db000 f67e9000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b46000 f7b48000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f789c000 f78a1000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f2865000 f2868000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000



    fourth dump:

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_gdr.070227-2254
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805533a0
    Debug session time: Sat May 5 02:11:50.187 2007 (GMT+3)
    System Uptime: 0 days 0:03:38.758
    Loading Kernel Symbols
    .................................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
    Loading unloaded module list


    BugCheck 24, {1902fe, b9294328, b9294024, 80528e72}

    Probably caused by : Ntfs.sys ( Ntfs!NtfsCreateNewFile+319 )

    Followup: MachineOwner


    kd> !analyze -v;r;kv;lmtn;.logclose;q

    NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
    Arguments:
    Arg1: 001902fe
    Arg2: b9294328
    Arg3: b9294024
    Arg4: 80528e72

    Debugging Details:
    ------------------


    EXCEPTION_RECORD: b9294328 -- (.exr 0xffffffffb9294328)
    .exr 0xffffffffb9294328
    ExceptionAddress: 80528e72 (nt!RtlDelete+0x0000005c)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 00000024
    Attempt to read from address 00000024

    CONTEXT: b9294024 -- (.cxr 0xffffffffb9294024)
    .cxr 0xffffffffb9294024
    eax=00530309 ebx=b929443b ecx=00000020 edx=00000024 esi=e27bbfd0 edi=e27bbfd0
    eip=80528e72 esp=b92943f0 ebp=b92943f4 iopl=0 nv up ei pl nz na pe cy
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010207
    nt!RtlDelete+0x5c:
    80528e72 3932 cmp dword ptr [edx],esi ds:0023:00000024=????????
    .cxr
    Resetting default scope

    PROCESS_NAME: symbols.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: 00000024

    BUGCHECK_STR: 0x24

    DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE

    LAST_CONTROL_TRANSFER: from 804e79e3 to 80528e72

    STACK_TEXT:
    b92943f4 804e79e3 e27bbfd0 01c78ea1 86266e88 nt!RtlDelete+0x5c
    b929440c 8055f620 86266e64 e27bbfd0 b9294458 nt!FsRtlRemoveNodeFromTunnel+0x1d
    b929443c 8055f8e0 86266e64 b9294458 85e25d78 nt!FsRtlPruneTunnelCache+0x60
    b9294480 ba5907d7 86266e64 00011af6 00050000 nt!FsRtlFindInTunnelCache+0x3e
    b9294674 ba583c37 85e25d78 86d2ae70 86d2afb8 Ntfs!NtfsCreateNewFile+0x319
    b92948c8 ba580f64 85e25d78 86d2ae70 b9294920 Ntfs!NtfsCommonCreate+0x12ce
    b92949a8 804edfe3 86266770 86d2ae70 806d02e8 Ntfs!NtfsFsdCreate+0x1ec
    b92949b8 8064b8a8 86d2afd4 8617be88 86d2ae70 nt!IopfCallDriver+0x31
    b92949dc ba60490e 8617bdd0 865716e0 85df5900 nt!IovCallDriver+0xa0
    b9294a28 804edfe3 8617be88 00000002 806d02e8 sr!SrCreate+0x1e8
    b9294a38 8064b8a8 86d2ae80 86d2ae70 85df5908 nt!IopfCallDriver+0x31
    b9294a5c 80577672 86571e18 861197b4 b9294c04 nt!IovCallDriver+0xa0
    b9294b3c 805b390a 86571e30 00000000 86119710 nt!IopParseDevice+0xa12
    b9294bc4 805afdeb 00000000 b9294c04 00000040 nt!ObpLookupObjectName+0x56a
    b9294c18 8056a3b1 00000000 00000000 294c8401 nt!ObOpenObjectByName+0xeb
    b9294c94 8056ad28 0006cd08 80100080 0006cca8 nt!IopCreateFile+0x407
    b9294cf0 8056d3fa 0006cd08 80100080 0006cca8 nt!IoCreateFile+0x8e
    b9294d30 8053ca28 0006cd08 80100080 0006cca8 nt!NtCreateFile+0x30
    b9294d30 7c90eb94 0006cd08 80100080 0006cca8 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0006cd00 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    Ntfs!NtfsCreateNewFile+319
    ba5907d7 84c0 test al,al

    SYMBOL_STACK_INDEX: 4

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: Ntfs

    IMAGE_NAME: Ntfs.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107eea

    SYMBOL_NAME: Ntfs!NtfsCreateNewFile+319

    STACK_COMMAND: .cxr 0xffffffffb9294024 ; kb

    FAILURE_BUCKET_ID: 0x24_VRF_Ntfs!NtfsCreateNewFile+319

    BUCKET_ID: 0x24_VRF_Ntfs!NtfsCreateNewFile+319

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=b9294328 ecx=00000000 edx=00000000 esi=85e25d78 edi=c0000005
    eip=804f8aef esp=b9293e00 ebp=b9293e18 iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8aef 5d pop ebp
    ChildEBP RetAddr Args to Child
    b9293e18 ba569051 00000024 001902fe b9294328 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    b9293e48 ba59437b 85e25d78 b9293e74 80535291 Ntfs!NtfsExceptionFilter+0x1cd (FPO: [Non-Fpo])
    b9293e54 80535291 b9293e7c 00000000 b9293e7c Ntfs!NtfsFsdCreate+0x208 (FPO: [Non-Fpo])
    b9293e7c 80541d12 b9294328 b9294998 b9294024 nt!_except_handler3+0x61 (FPO: [Uses EBP] [3,0,7])
    b9293ea0 80541ce4 b9294328 b9294998 b9294024 nt!ExecuteHandler2+0x26
    b9293f50 804fc8cc b9294328 b9294024 00000024 nt!ExecuteHandler+0x24
    b929430c 8053d471 b9294328 00000000 b929437c nt!KiDispatchException+0x13e (FPO: [Non-Fpo])
    b9294374 8053d422 b92943f4 80528e72 badb0d00 nt!CommonDispatchException+0x4d (FPO: [0,20,0])
    b92943f4 804e79e3 e27bbfd0 01c78ea1 86266e88 nt!Kei386EoiHelper+0x18a
    b92943f4 804e79e3 e27bbfd0 01c78ea1 86266e88 nt!FsRtlRemoveNodeFromTunnel+0x1d (FPO: [Non-Fpo])
    b929440c 8055f620 86266e64 e27bbfd0 b9294458 nt!FsRtlRemoveNodeFromTunnel+0x1d (FPO: [Non-Fpo])
    b929443c 8055f8e0 86266e64 b9294458 85e25d78 nt!FsRtlPruneTunnelCache+0x60 (FPO: [Non-Fpo])
    b9294480 ba5907d7 86266e64 00011af6 00050000 nt!FsRtlFindInTunnelCache+0x3e (FPO: [Non-Fpo])
    b9294674 ba583c37 85e25d78 86d2ae70 86d2afb8 Ntfs!NtfsCreateNewFile+0x319 (FPO: [Non-Fpo])
    b92948c8 ba580f64 85e25d78 86d2ae70 b9294920 Ntfs!NtfsCommonCreate+0x12ce (FPO: [Non-Fpo])
    b92949a8 804edfe3 86266770 86d2ae70 806d02e8 Ntfs!NtfsFsdCreate+0x1ec (FPO: [Non-Fpo])
    b92949b8 8064b8a8 86d2afd4 8617be88 86d2ae70 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    b92949dc ba60490e 8617bdd0 865716e0 85df5900 nt!IovCallDriver+0xa0 (FPO: [Non-Fpo])
    b9294a28 804edfe3 8617be88 00000002 806d02e8 sr!SrCreate+0x1e8 (FPO: [Non-Fpo])
    b9294a38 8064b8a8 86d2ae80 86d2ae70 85df5908 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    start end module name
    804d7000 806cd580 nt ntkrnlpa.exe Wed Feb 28 10:38:52 2007 (45E53F9C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 08:59:05 2004 (41107B29)
    b9335000 b9375280 HTTP HTTP.sys Fri Mar 17 02:33:09 2006 (441A03C5)
    b961e000 b966f480 srv srv.sys Mon Aug 14 13:34:39 2006 (44E051BF)
    b96c0000 b96ec400 mrxdav mrxdav.sys Wed Aug 04 09:00:49 2004 (41107B91)
    b98fb000 b990f400 wdmaud wdmaud.sys Wed Jun 14 12:00:44 2006 (448FD03C)
    ba408000 ba41b900 parport parport.sys Wed Aug 04 08:59:04 2004 (41107B28)
    ba428000 ba42b780 dump_diskdump dump_diskdump.sys Wed Aug 04 08:59:51 2004 (41107B57)
    ba43d000 ba45fe80 USBPORT USBPORT.SYS Wed Aug 04 09:08:34 2004 (41107D62)
    ba460000 ba482680 ks ks.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    ba483000 ba496780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 09:07:04 2004 (41107D08)
    ba4cf000 ba4d2f60 HPZipr12 HPZipr12.sys Wed Sep 29 08:41:44 2004 (415A5928)
    ba4db000 ba4de280 ndisuio ndisuio.sys Wed Aug 04 09:03:10 2004 (41107C1E)
    ba513000 ba52d580 Mup Mup.sys Wed Aug 04 09:15:20 2004 (41107EF8)
    ba52e000 ba55aa80 NDIS NDIS.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    ba55b000 ba5e7480 Ntfs Ntfs.sys Wed Aug 04 09:15:06 2004 (41107EEA)
    ba5e8000 ba5fe780 KSecDD KSecDD.sys Wed Aug 04 08:59:45 2004 (41107B51)
    ba5ff000 ba610f00 sr sr.sys Wed Aug 04 09:06:22 2004 (41107CDE)
    ba611000 ba630780 fltMgr fltMgr.sys Mon Aug 21 12:14:57 2006 (44E97991)
    ba631000 ba648800 SCSIPORT SCSIPORT.SYS Wed Aug 04 08:59:39 2004 (41107B4B)
    ba649000 ba662200 viamraid viamraid.sys Wed Nov 08 08:23:49 2006 (455177F5)
    ba663000 ba67a480 atapi atapi.sys Wed Aug 04 08:59:41 2004 (41107B4D)
    ba67b000 ba6a0700 dmio dmio.sys Wed Aug 04 09:07:13 2004 (41107D11)
    ba6a1000 ba6bf880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    ba6c0000 ba6d0a80 pci pci.sys Wed Aug 04 09:07:45 2004 (41107D31)
    ba6d1000 ba6fed80 ACPI ACPI.sys Wed Aug 04 09:07:35 2004 (41107D27)
    bf000000 bf011580 dxg dxg.sys Wed Aug 04 09:00:51 2004 (41107B93)
    bf012000 bf463580 nv4_disp nv4_disp.dll Sun Oct 22 23:02:50 2006 (453BDC7A)
    bf800000 bf9c2180 win32k win32k.sys Thu Mar 08 15:47:34 2007 (45F013F6)
    f2d26000 f2d3f200 dump_viamraid dump_viamraid.sys Wed Nov 08 08:23:49 2006 (455177F5)
    f2d40000 f2d60f00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f2d61000 f2dcfa00 mrxsmb mrxsmb.sys Fri May 05 12:41:42 2006 (445B1DD6)
    f2dd0000 f2dfaa00 rdbss rdbss.sys Fri May 05 12:47:55 2006 (445B1F4B)
    f2dfb000 f2e1cd00 afd afd.sys Wed Aug 04 09:14:13 2004 (41107EB5)
    f2e1d000 f2e44c00 netbt netbt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f2e45000 f2e9cd80 tcpip tcpip.sys Thu Apr 20 14:51:47 2006 (444775D3)
    f2e9d000 f2eaf400 ipsec ipsec.sys Wed Aug 04 09:14:27 2004 (41107EC3)
    f402f000 f4062200 update update.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f4063000 f4093100 rdpdr rdpdr.sys Wed Aug 04 09:01:10 2004 (41107BA6)
    f4112000 f4118180 HIDPARSE HIDPARSE.SYS Wed Aug 04 09:08:15 2004 (41107D4F)
    f411a000 f4121b80 usbccgp usbccgp.sys Wed Aug 04 09:08:45 2004 (41107D6D)
    f4132000 f4139880 Npfs Npfs.SYS Wed Aug 04 09:00:38 2004 (41107B86)
    f413a000 f413ea80 Msfs Msfs.SYS Wed Aug 04 09:00:37 2004 (41107B85)
    f4142000 f4147200 vga vga.sys Wed Aug 04 09:07:06 2004 (41107D0A)
    f4191000 f4199700 wanarp wanarp.sys Wed Aug 04 09:04:57 2004 (41107C89)
    f41a1000 f41a9880 Fips Fips.SYS Sat Aug 18 04:31:49 2001 (3B7DC585)
    f41c1000 f41c9700 netbios netbios.sys Wed Aug 04 09:03:19 2004 (41107C27)
    f4201000 f420f100 usbhub usbhub.sys Wed Aug 04 09:08:40 2004 (41107D68)
    f4581000 f4586a00 mouclass mouclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f4589000 f458d080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f4591000 f4595580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f4636000 f4639c80 mssmbios mssmbios.sys Wed Aug 04 09:07:47 2004 (41107D33)
    f6a94000 f6aa2d80 sysaudio sysaudio.sys Wed Aug 04 09:15:54 2004 (41107F1A)
    f6b58000 f6b5a900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    f6b5c000 f6b5ef80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001 (3B7D82FD)
    f6b60000 f6b63b00 usbscan usbscan.sys Wed Aug 04 08:58:44 2004 (41107B14)
    f6d5d000 f6d6c900 Cdfs Cdfs.SYS Wed Aug 04 09:14:09 2004 (41107EB1)
    f6e01000 f6e03280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f6ed7000 f6ee7e00 psched psched.sys Wed Aug 04 09:04:16 2004 (41107C60)
    f6ee8000 f6efe680 ndiswan ndiswan.sys Wed Aug 04 09:14:30 2004 (41107EC6)
    f6f10000 f6f33980 portcls portcls.sys Wed Aug 04 09:15:47 2004 (41107F13)
    f6f34000 f6fc1340 smwdm smwdm.sys Tue Jul 15 22:59:58 2003 (3F145D3E)
    f6fc2000 f7391400 nv4_mini nv4_mini.sys Sun Oct 22 23:08:02 2006 (453BDDB2)
    f73d2000 f73de6a0 HPZid412 HPZid412.sys Wed Sep 29 08:41:41 2004 (415A5925)
    f73e2000 f73ead80 HIDCLASS HIDCLASS.SYS Wed Aug 04 09:08:18 2004 (41107D52)
    f7412000 f741b480 NDProxy NDProxy.SYS Fri Aug 17 23:55:30 2001 (3B7D84C2)
    f7422000 f742bf00 termdd termdd.sys Wed Aug 04 08:58:52 2004 (41107B1C)
    f7487000 f748fc00 isapnp isapnp.sys Fri Aug 17 23:58:01 2001 (3B7D8559)
    f7497000 f74a1500 MountMgr MountMgr.sys Wed Aug 04 08:58:29 2004 (41107B05)
    f74a7000 f74b3c80 VolSnap VolSnap.sys Wed Aug 04 09:00:14 2004 (41107B6E)
    f74b7000 f74bfe00 disk disk.sys Wed Aug 04 08:59:53 2004 (41107B59)
    f74c7000 f74d3200 CLASSPNP CLASSPNP.SYS Wed Aug 04 09:14:26 2004 (41107EC2)
    f74d7000 f74e2580 gagp30kx gagp30kx.sys Wed Aug 04 09:07:43 2004 (41107D2F)
    f7597000 f75a1380 imapi imapi.sys Wed Aug 04 09:00:12 2004 (41107B6C)
    f75a7000 f75b3180 cdrom cdrom.sys Wed Aug 04 08:59:52 2004 (41107B58)
    f75b7000 f75c5080 redbook redbook.sys Wed Aug 04 08:59:34 2004 (41107B46)
    f75c7000 f75d3e00 i8042prt i8042prt.sys Wed Aug 04 09:14:36 2004 (41107ECC)
    f75d7000 f75e6d80 serial serial.sys Wed Aug 04 09:15:51 2004 (41107F17)
    f75e7000 f75f5b80 drmk drmk.sys Wed Aug 04 09:07:54 2004 (41107D3A)
    f75f7000 f7601600 fetnd5bv fetnd5bv.sys Thu Dec 16 07:36:28 2004 (41C11EDC)
    f7607000 f7616000 AmdK8 AmdK8.sys Fri Jul 30 00:20:24 2004 (41096A18)
    f7617000 f7623880 rasl2tp rasl2tp.sys Wed Aug 04 09:14:21 2004 (41107EBD)
    f7627000 f7631200 raspppoe raspppoe.sys Wed Aug 04 09:05:06 2004 (41107C92)
    f7637000 f7642d00 raspptp raspptp.sys Wed Aug 04 09:14:26 2004 (41107EC2)
    f7647000 f764f900 msgpc msgpc.sys Wed Aug 04 09:04:11 2004 (41107C5B)
    f7707000 f770d200 PCIIDEX PCIIDEX.SYS Wed Aug 04 08:59:40 2004 (41107B4C)
    f770f000 f7713900 PartMgr PartMgr.sys Sat Aug 18 04:32:23 2001 (3B7DC5A7)
    f7717000 f771f000 videX32 videX32.sys Tue Oct 17 14:22:24 2006 (4534CB00)
    f7737000 f773b880 TDI TDI.SYS Wed Aug 04 09:07:47 2004 (41107D33)
    f7767000 f776d500 usbprint usbprint.sys Wed Aug 04 09:01:23 2004 (41107BB3)
    f781f000 f78243e0 HPZius12 HPZius12.sys Wed Sep 29 08:40:14 2004 (415A58CE)
    f7867000 f786b500 watchdog watchdog.sys Wed Aug 04 09:07:32 2004 (41107D24)
    f787f000 f7884000 usbuhci usbuhci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f7887000 f788d800 usbehci usbehci.sys Wed Aug 04 09:08:34 2004 (41107D62)
    f788f000 f7895000 kbdclass kbdclass.sys Wed Aug 04 08:58:32 2004 (41107B08)
    f7897000 f789a000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f7957000 f795ac80 serenum serenum.sys Wed Aug 04 08:59:06 2004 (41107B2A)
    f795b000 f795d580 ndistapi ndistapi.sys Fri Aug 17 23:55:29 2001 (3B7D84C1)
    f7977000 f7979580 hidusb hidusb.sys Sat Aug 18 00:02:16 2001 (3B7D8658)
    f7987000 f7988b80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f7989000 f798a100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f798b000 f798c500 viaide viaide.sys Wed Aug 04 08:59:42 2004 (41107B4E)
    f798d000 f798e700 dmload dmload.sys Fri Aug 17 23:58:15 2001 (3B7D8567)
    f79a3000 f79a4120 aeaudio aeaudio.sys Mon Apr 01 17:39:14 2002 (3CA87112)
    f79e5000 f79e6100 swenum swenum.sys Wed Aug 04 08:58:41 2004 (41107B11)
    f79e7000 f79e8280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f79e9000 f79ea080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f79f1000 f79f2f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f79f3000 f79f4080 Beep Beep.SYS Fri Aug 17 23:47:33 2001 (3B7D82E5)
    f79f5000 f79f6080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f7a4d000 f7a4ea80 ParVdm ParVdm.SYS Fri Aug 17 23:49:49 2001 (3B7D836D)
    f7aeb000 f7aebb80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f7b52000 f7b52c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)
    f7b7f000 f7b7fd00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)

    Unloaded modules:
    b91ca000 b91f5000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b98ad000 b98d8000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b98d8000 b98fb000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7af7000 f7af8000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6984000 f6991000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6a14000 f6a22000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7a25000 f7a27000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f41b1000 f41ba000 processr.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f414a000 f414f000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7917000 f791a000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000


    Thanks again for all your help!!
     
  7. 2007/05/04
    tynta

    tynta Inactive

    Joined:
    2007/03/25
    Messages:
    2
    Likes Received:
    0
    for me it was not stable memmory (PQI DDR2-800), BSOD when a lot of memmory in use, like games, apps etc., i also tried a memtest, separatly memsticks passes tests, in dual mode test hangs. then i trried chenge the voltage from (by default) 1.8v to 2.0 ......... yeehaa, working like charm :D
    no more B.S.O.D.
     
  8. 2007/05/05
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #7
  9. 2007/05/06
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    memory testing...

    Already ran both, with no conclusive results - most of the time the tests ran just fine, on other times it got stuck after some time, but it didn't point to any error...

    Regarding the changing voltage idea... I have asus k8v-x se - should I set the voltage to any specific value (I can do it through the bios, can't I?)

    Thanks
     
  10. 2007/05/06
    tynta

    tynta Inactive

    Joined:
    2007/03/25
    Messages:
    2
    Likes Received:
    0
    ...on other times it got stuck after some time, but it didn't point to any error...

    yap it is memm\motherboard (hardware) problem, find out what type and vendor memmory you use, in motherboard manual are list of memmory supported and tested for it,... memmory tweaks are risky there is no guaranty
     
  11. 2007/05/11
    nimrods

    nimrods Inactive Thread Starter

    Joined:
    2007/05/02
    Messages:
    6
    Likes Received:
    0
    Seems to be working fine now...

    I updated the bios and the mother board drivers, and didn't get any blue screen for the last 5 days... we'll see if it keeps up this way...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.