1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

DUMP DATA - BSOD 0xA at random times

Discussion in 'Windows XP' started by Thonolan, 2005/01/06.

Thread Status:
Not open for further replies.
  1. 2005/01/06
    Thonolan

    Thonolan Inactive Thread Starter

    Joined:
    2005/01/06
    Messages:
    3
    Likes Received:
    0
    Hello,

    I suffer already quite a while with random stop error 0xA. It has always the same parameters:

    Bugcheck code 0000000A
    Arguments fffff5c4 0000001c 00000001 804e3880

    The first two lines in the stack trace are always the same, but the others are always different:
    f6c99b8c 804e3880 badb0d00 fe6a8b68 f6c99bb4 nt!KiTrap0E+0x233
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143

    I already disabled a lot of drivers to find the cause, but it doesn't seem to help a lot...

    Below you find the dump data
    Thanks,
    T.

    ==================================
    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0004.4
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [H:\WIN\MEMORY.DMP]
    Kernel Complete Dump File: Full address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: H:\WIN;H:\WIN\system32;H:\WIN\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
    Debug session time: Wed Jan 5 23:42:13.658 2005 (GMT+1)
    System Uptime: 4 days 12:36:30.230
    Loading Kernel Symbols
    .............................................................................................................
    Loading unloaded module list
    ..........
    Loading User Symbols
    UserMode Module List Address is NULL (Addr= 00241e9c)
    This is usually caused by being in the wrong process
    context or by paging
    The call to LoadLibrary(ext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    The call to LoadLibrary(kext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    The call to LoadLibrary(ext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    The call to LoadLibrary(kext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************
    .bugcheck
    Bugcheck code 0000000A
    Arguments fffff5c4 0000001c 00000001 804e3880

    kb
    ChildEBP RetAddr Args to Child
    f6c99b8c 804e3880 badb0d00 fe6a8b68 f6c99bb4 nt!KiTrap0E+0x233
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143
    f6c99c7c bf802ed2 e2169950 00000200 e2169950 win32k!SleepInputIdle+0x4a
    f6c99ca8 bf801aa8 000025ff 00000000 00000001 win32k!xxxSleepThread+0x1b8
    f6c99cec bf80f106 f6c99d18 000025ff 00000000 win32k!xxxRealInternalGetMessage+0x418
    f6c99d4c 804df06b 0012fe78 00000000 00000000 win32k!NtUserGetMessage+0x27
    f6c99d4c 7c90ebab 0012fe78 00000000 00000000 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fc14 0040c406 0012fe78 00000000 00000000 0x7c90ebab
    0040f619 7835ff00 680041f8 0041e7cc 414c7068 0x40c406
    4113db68 00000000 00000000 00000000 00000000 0x7835ff00

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    The call to LoadLibrary(ext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    The call to LoadLibrary(kext) failed, Win32 error 2
    "The system cannot find the file specified. "
    Please check your debugger configuration and/or network access.
    No export analyze found
    eax=ffdff13c ebx=0000001c ecx=00000000 edx=40000000 esi=804e3880 edi=fffff5c4
    eip=804e2158 esp=f6c99b74 ebp=f6c99b8c iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KiTrap0E+0x233:
    804e2158 f7457000000200 test dword ptr [ebp+0x70],0x20000 ss:0010:f6c99bfc=00010202
    ChildEBP RetAddr Args to Child
    f6c99b8c 804e3880 badb0d00 fe6a8b68 f6c99bb4 nt!KiTrap0E+0x233 (FPO: [0,0] TrapFrame @ f6c99b8c)
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143 (FPO: [0,2] TrapFrame @ f6c99c08)
    f6c99c7c bf802ed2 e2169950 00000200 e2169950 win32k!SleepInputIdle+0x4a (FPO: [Non-Fpo])
    f6c99ca8 bf801aa8 000025ff 00000000 00000001 win32k!xxxSleepThread+0x1b8 (FPO: [Non-Fpo])
    f6c99cec bf80f106 f6c99d18 000025ff 00000000 win32k!xxxRealInternalGetMessage+0x418 (FPO: [Non-Fpo])
    f6c99d4c 804df06b 0012fe78 00000000 00000000 win32k!NtUserGetMessage+0x27 (FPO: [Non-Fpo])
    f6c99d4c 7c90ebab 0012fe78 00000000 00000000 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f6c99d64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fc14 0040c406 0012fe78 00000000 00000000 0x7c90ebab
    0040f619 7835ff00 680041f8 0041e7cc 414c7068 0x40c406
    4113db68 00000000 00000000 00000000 00000000 0x7835ff00
    start end module name
    804d7000 806eb780 nt ntoskrnl.exe Wed Aug 04 08:19:48 2004 (41108004)
    806ec000 806ffd80 hal halacpi.dll Wed Aug 04 07:59:04 2004 (41107B28)
    bac0c000 bac2b160 ptserial ptserial.sys Wed Aug 09 22:45:21 2000 (3991C2E1)
    bac2c000 bac4ee80 USBPORT USBPORT.SYS Wed Aug 04 08:08:34 2004 (41107D62)
    bac4f000 bac71680 ks ks.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    bac72000 bac85780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 08:07:04 2004 (41107D08)
    bac86000 bacbc480 trid3dm trid3dm.sys Thu May 17 23:15:16 2001 (3B043F64)
    bacc2000 bacd2e00 psched psched.sys Wed Aug 04 08:04:16 2004 (41107C60)
    bacd3000 bace9680 ndiswan ndiswan.sys Wed Aug 04 08:14:30 2004 (41107EC6)
    bacea000 bacfb300 Rtlnicxp Rtlnicxp.sys Fri Jul 16 08:19:52 2004 (40F77388)
    bad44000 bad5e580 Mup Mup.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    bad5f000 badbefa0 vpctcom vpctcom.sys Thu Aug 17 04:53:52 2000 (399B53C0)
    badbf000 bae40cc0 VMODEM VMODEM.SYS Thu Aug 17 02:11:47 2000 (399B2DC3)
    bae41000 bae6da80 NDIS NDIS.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    bae6e000 baefa480 Ntfs Ntfs.sys Wed Aug 04 08:15:06 2004 (41107EEA)
    baefb000 baf11780 KSecDD KSecDD.sys Wed Aug 04 07:59:45 2004 (41107B51)
    baf12000 baf23f00 sr sr.sys Wed Aug 04 08:06:22 2004 (41107CDE)
    baf24000 baf43000 fltmgr fltmgr.sys unavailable (FFFFFFFE)
    baf43000 baf5a480 atapi atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    baf5b000 baf80700 dmio dmio.sys Wed Aug 04 08:07:13 2004 (41107D11)
    baf81000 baf9f880 ftdisk ftdisk.sys Fri Aug 17 22:52:41 2001 (3B7D8419)
    bafa0000 bafb0a80 pci pci.sys Wed Aug 04 08:07:45 2004 (41107D31)
    bafb1000 bafded80 ACPI ACPI.sys Wed Aug 04 08:07:35 2004 (41107D27)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 08:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 08:00:51 2004 (41107B93)
    bf9d3000 bf9d5f00 TSDDD TSDDD.dll Wed Aug 04 09:57:02 2004 (411096CE)
    bff10000 bff5d080 trid3d trid3d.dll Fri Aug 17 23:56:04 2001 (3B7D92F4)
    f6a12000 f6a26440 naiavf5x naiavf5x.sys Tue Aug 05 03:08:00 2003 (3F2F0370)
    f6a27000 f6a67380 HTTP HTTP.sys Wed Aug 04 08:00:09 2004 (41107B69)
    f6ae0000 f6b02000 RDPWD RDPWD.SYS Wed Aug 04 07:59:01 2004 (41107B25)
    f6eca000 f6ecc780 secdrv secdrv.sys Mon Apr 08 10:50:52 2002 (3CB159EC)
    f6eea000 f6f3c180 srv srv.sys Wed Aug 04 08:14:44 2004 (41107ED4)
    f7055000 f7081400 mrxdav mrxdav.sys Wed Aug 04 08:00:49 2004 (41107B91)
    f737a000 f738a280 Udfs Udfs.SYS Wed Aug 04 08:00:27 2004 (41107B7B)
    f73a3000 f73a6280 ndisuio ndisuio.sys Wed Aug 04 08:03:10 2004 (41107C1E)
    f73db000 f741fc00 BsUDF BsUDF.SYS Tue Jul 10 08:15:40 2001 (3B4A9D8C)
    f8160000 f8177480 dump_atapi dump_atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    f8178000 f819b000 Fastfat Fastfat.SYS Wed Aug 04 08:14:15 2004 (41107EB7)
    f819b000 f81bbf00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f81bc000 f8229680 mrxsmb mrxsmb.sys Thu Oct 28 03:14:16 2004 (418047E8)
    f822a000 f8254a00 rdbss rdbss.sys Thu Oct 28 03:13:57 2004 (418047D5)
    f8255000 f8276d00 afd afd.sys Wed Aug 04 08:14:13 2004 (41107EB5)
    f8277000 f829ec00 netbt netbt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    f829f000 f82f6a80 tcpip tcpip.sys Wed Aug 04 08:14:39 2004 (41107ECF)
    f82f7000 f8309400 ipsec ipsec.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    f8353000 f8355900 Dxapi Dxapi.sys Fri Aug 17 22:53:19 2001 (3B7D843F)
    f93ab000 f93de200 update update.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f93df000 f93ee900 Cdfs Cdfs.SYS Wed Aug 04 08:14:09 2004 (41107EB1)
    f9497000 f94c7100 rdpdr rdpdr.sys Wed Aug 04 08:01:10 2004 (41107BA6)
    f94c8000 f958c000 dmboot dmboot.sys unavailable (FFFFFFFE)
    f958c000 f9594c00 isapnp isapnp.sys Fri Aug 17 22:58:01 2001 (3B7D8559)
    f959c000 f95a6500 MountMgr MountMgr.sys Wed Aug 04 07:58:29 2004 (41107B05)
    f95ac000 f95b8c80 VolSnap VolSnap.sys Wed Aug 04 08:00:14 2004 (41107B6E)
    f95bc000 f95c4e00 disk disk.sys Wed Aug 04 07:59:53 2004 (41107B59)
    f95cc000 f95d8200 CLASSPNP CLASSPNP.SYS Wed Aug 04 08:14:26 2004 (41107EC2)
    f95ec000 f95f6500 viaagp viaagp.sys Wed Aug 04 08:07:42 2004 (41107D2E)
    f961c000 f9624700 netbios netbios.sys Wed Aug 04 08:03:19 2004 (41107C27)
    f962c000 f9634880 Fips Fips.SYS Sat Aug 18 03:31:49 2001 (3B7DC585)
    f963c000 f9644700 wanarp wanarp.sys Wed Aug 04 08:04:57 2004 (41107C89)
    f96fc000 f9704a00 processr processr.sys Wed Aug 04 07:59:14 2004 (41107B32)
    f970c000 f9716380 imapi imapi.sys Wed Aug 04 08:00:12 2004 (41107B6C)
    f971c000 f9728180 cdrom cdrom.sys Wed Aug 04 07:59:52 2004 (41107B58)
    f972c000 f973a080 redbook redbook.sys Wed Aug 04 07:59:34 2004 (41107B46)
    f974c000 f975ba80 VVOICE VVOICE.SYS Tue Jul 25 03:06:19 2000 (397CE80B)
    f975c000 f976bd80 serial serial.sys Wed Aug 04 08:15:51 2004 (41107F17)
    f976c000 f9778e00 i8042prt i8042prt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    f977c000 f9788880 rasl2tp rasl2tp.sys Wed Aug 04 08:14:21 2004 (41107EBD)
    f978c000 f9796200 raspppoe raspppoe.sys Wed Aug 04 08:05:06 2004 (41107C92)
    f979c000 f97a7d00 raspptp raspptp.sys Wed Aug 04 08:14:26 2004 (41107EC2)
    f97ac000 f97b4900 msgpc msgpc.sys Wed Aug 04 08:04:11 2004 (41107C5B)
    f97bc000 f97c5f00 termdd termdd.sys Wed Aug 04 07:58:52 2004 (41107B1C)
    f97dc000 f97e5480 NDProxy NDProxy.SYS Fri Aug 17 22:55:30 2001 (3B7D84C2)
    f97fc000 f980a100 usbhub usbhub.sys Wed Aug 04 08:08:40 2004 (41107D68)
    f980c000 f9812200 PCIIDEX PCIIDEX.SYS Wed Aug 04 07:59:40 2004 (41107B4C)
    f9814000 f9818900 PartMgr PartMgr.sys Sat Aug 18 03:32:23 2001 (3B7DC5A7)
    f981c000 f9820bc0 PxHelp20 PxHelp20.sys Tue Oct 28 19:25:49 2003 (3F9EB4AD)
    f9864000 f9869500 TDTCP TDTCP.SYS Wed Aug 04 07:58:52 2004 (41107B1C)
    f98b4000 f98b9000 usbuhci usbuhci.sys Wed Aug 04 08:08:34 2004 (41107D62)
    f98bc000 f98c3580 Modem Modem.SYS Wed Aug 04 08:08:04 2004 (41107D44)
    f98c4000 f98cab00 fdc fdc.sys Wed Aug 04 07:59:25 2004 (41107B3D)
    f98cc000 f98d1a00 mouclass mouclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f98d4000 f98da000 kbdclass kbdclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f98dc000 f98e0880 TDI TDI.SYS Wed Aug 04 08:07:47 2004 (41107D33)
    f98e4000 f98e8580 ptilink ptilink.sys Fri Aug 17 22:49:53 2001 (3B7D8371)
    f98ec000 f98f0080 raspti raspti.sys Fri Aug 17 22:55:32 2001 (3B7D84C4)
    f9904000 f9909000 flpydisk flpydisk.sys Wed Aug 04 07:59:24 2004 (41107B3C)
    f9914000 f9919200 vga vga.sys Wed Aug 04 08:07:06 2004 (41107D0A)
    f991c000 f9920a80 Msfs Msfs.SYS Wed Aug 04 08:00:37 2004 (41107B85)
    f9924000 f992b880 Npfs Npfs.SYS Wed Aug 04 08:00:38 2004 (41107B86)
    f9944000 f9948500 watchdog watchdog.sys Wed Aug 04 08:07:32 2004 (41107D24)
    f999c000 f999f000 BOOTVID BOOTVID.dll Fri Aug 17 22:49:09 2001 (3B7D8345)
    f9a1c000 f9a1e280 rasacd rasacd.sys Fri Aug 17 22:55:39 2001 (3B7D84CB)
    f9a48000 f9a4bc80 serenum serenum.sys Wed Aug 04 07:59:06 2004 (41107B2A)
    f9a4c000 f9a4e580 ndistapi ndistapi.sys Fri Aug 17 22:55:29 2001 (3B7D84C1)
    f9a68000 f9a6bc80 mssmbios mssmbios.sys Wed Aug 04 08:07:47 2004 (41107D33)
    f9a8c000 f9a8db80 kdcom kdcom.dll Fri Aug 17 22:49:10 2001 (3B7D8346)
    f9a8e000 f9a8f100 WMILIB WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9a90000 f9a91500 viaide viaide.sys Wed Aug 04 07:59:42 2004 (41107B4E)
    f9a92000 f9a94000 dmload dmload.sys unavailable (FFFFFFFE)
    f9a9e000 f9a9f100 swenum swenum.sys Wed Aug 04 07:58:41 2004 (41107B11)
    f9aaa000 f9aab280 USBD USBD.SYS Fri Aug 17 23:02:58 2001 (3B7D8682)
    f9aba000 f9abc000 Fs_Rec Fs_Rec.SYS unavailable (FFFFFFFE)
    f9abc000 f9abd080 Beep Beep.SYS Fri Aug 17 22:47:33 2001 (3B7D82E5)
    f9abe000 f9abf080 mnmdd mnmdd.SYS Fri Aug 17 22:57:28 2001 (3B7D8538)
    f9ac0000 f9ac1080 RDPCDD RDPCDD.sys Fri Aug 17 22:46:56 2001 (3B7D82C0)
    f9ad2000 f9ad3100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9b36000 f9b37100 hiber_WMILIB hiber_WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9b99000 f9b99d00 dxgthk dxgthk.sys Fri Aug 17 22:53:12 2001 (3B7D8438)
    f9ba6000 f9ba6c00 audstub audstub.sys Fri Aug 17 22:59:40 2001 (3B7D85BC)
    f9c51000 f9c52000 Null Null.SYS unavailable (FFFFFFFE)

    Unloaded modules:
    f24c2000 f24da000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f3d8a000 f3da2000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4a2a000 f4a42000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4c32000 f4c4a000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f9c60000 f9c61000 BANTExt.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f990c000 f9911000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f9a18000 f9a1b000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bad5f000 bade1000 vmodem.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bade1000 bae41000 vpctcom.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f95dc000 f95ec000 vvoice.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  2. 2005/01/06
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    Your debugger install is broken. We need the !analyze output to crack the trap frames for this one. That tool uses the registry key created when you install the debuggers to figure out where to go get the debugging tools. This is incorrect, or your debugger install was not successful.

    Please install the debugging tools and try again. If you see these errors, it didnt work:
    The call to LoadLibrary(ext) failed, Win32 error 2
    "The system cannot find the file specified. "

    If you cannot resolve this problem, you will need to use the advanced option in that tool to do it the hard way or open the dump in the debugger by hand and do some commands. Let us know, and we can tell you how to do that.
     

  3. to hide this advert.

  4. 2005/01/07
    Thonolan

    Thonolan Inactive Thread Starter

    Joined:
    2005/01/06
    Messages:
    3
    Likes Received:
    0
    OK, I installed another version of the debugging tools and it seems to give me more info now (see below)
    What I learn from the trace is the following:
    Probably caused by : win32k.sys ( win32k!SleepInputIdle+4a )
    I guess he gets this info from the stack trace, but as I said before only the first lines of the stack trace are always the same, but the third one (now win32k!SleepInputIdle+4a ) is always different. So I am not convinced that the error is in win32k.sys.

    Thanks,
    T.


    ===========================
    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0004.4
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [H:\WIN\MEMORY.DMP]
    Kernel Complete Dump File: Full address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: H:\WIN;H:\WIN\system32;H:\WIN\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
    Debug session time: Wed Jan 5 23:42:13.658 2005 (GMT+1)
    System Uptime: 4 days 12:36:30.230
    Loading Kernel Symbols
    .............................................................................................................
    Loading unloaded module list
    ..........
    Loading User Symbols
    UserMode Module List Address is NULL (Addr= 00241e9c)
    This is usually caused by being in the wrong process
    context or by paging
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {fffff5c4, 1c, 1, 804e3880}

    Probably caused by : win32k.sys ( win32k!SleepInputIdle+4a )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: fffff5c4, memory referenced
    Arg2: 0000001c, IRQL
    Arg3: 00000001, value 0 = read operation, 1 = write operation
    Arg4: 804e3880, address which referenced memory

    Debugging Details:
    ------------------


    WRITE_ADDRESS: fffff5c4 Nonpaged pool expansion

    CURRENT_IRQL: 1c

    FAULTING_IP:
    nt!KeUpdateSystemTime+143
    804e3880 ff05c4f5dfff inc dword ptr [ffdff5c4]

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xA

    LAST_CONTROL_TRANSFER: from bf802453 to 804e3880

    TRAP_FRAME: f6c99b8c -- (.trap fffffffff6c99b8c)
    .trap fffffffff6c99b8c
    ErrCode = 00000002
    eax=000000f1 ebx=0253bef1 ecx=8055a388 edx=fe6a8b68 esi=0000038e edi=58568380
    eip=804e3880 esp=f6c99c00 ebp=f6c99c08 iopl=0 nv up ei pl nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
    nt!KeUpdateSystemTime+0x143:
    804e3880 ff05c4f5dfff inc dword ptr [ffdff5c4] ds:0023:ffdff5c4=06d7befe
    .trap
    Resetting default scope

    STACK_TEXT:
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143
    f6c99c7c bf802ed2 e2169950 00000200 e2169950 win32k!SleepInputIdle+0x4a
    f6c99ca8 bf801aa8 000025ff 00000000 00000001 win32k!xxxSleepThread+0x1b8
    f6c99cec bf80f106 f6c99d18 000025ff 00000000 win32k!xxxRealInternalGetMessage+0x418
    f6c99d4c 804df06b 0012fe78 00000000 00000000 win32k!NtUserGetMessage+0x27
    f6c99d4c 7c90ebab 0012fe78 00000000 00000000 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fc14 0040c406 0012fe78 00000000 00000000 0x7c90ebab
    0040f619 7835ff00 680041f8 0041e7cc 414c7068 0x40c406
    4113db68 00000000 00000000 00000000 00000000 0x7835ff00


    FOLLOWUP_IP:
    win32k!SleepInputIdle+4a
    bf802453 83f9ff cmp ecx,0xffffffff

    SYMBOL_STACK_INDEX: 1

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: win32k!SleepInputIdle+4a

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107f7a

    STACK_COMMAND: .trap fffffffff6c99b8c ; kb

    BUCKET_ID: 0xA_W_win32k!SleepInputIdle+4a

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=0000001c ecx=00000000 edx=40000000 esi=804e3880 edi=fffff5c4
    eip=804e2158 esp=f6c99b74 ebp=f6c99b8c iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KiTrap0E+0x233:
    804e2158 f7457000000200 test dword ptr [ebp+0x70],0x20000 ss:0010:f6c99bfc=00010202
    ChildEBP RetAddr Args to Child
    f6c99b8c 804e3880 badb0d00 fe6a8b68 f6c99bb4 nt!KiTrap0E+0x233 (FPO: [0,0] TrapFrame @ f6c99b8c)
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143 (FPO: [0,2] TrapFrame @ f6c99c08)
    f6c99c7c bf802ed2 e2169950 00000200 e2169950 win32k!SleepInputIdle+0x4a (FPO: [Non-Fpo])
    f6c99ca8 bf801aa8 000025ff 00000000 00000001 win32k!xxxSleepThread+0x1b8 (FPO: [Non-Fpo])
    f6c99cec bf80f106 f6c99d18 000025ff 00000000 win32k!xxxRealInternalGetMessage+0x418 (FPO: [Non-Fpo])
    f6c99d4c 804df06b 0012fe78 00000000 00000000 win32k!NtUserGetMessage+0x27 (FPO: [Non-Fpo])
    f6c99d4c 7c90ebab 0012fe78 00000000 00000000 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f6c99d64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0012fc14 0040c406 0012fe78 00000000 00000000 0x7c90ebab
    0040f619 7835ff00 680041f8 0041e7cc 414c7068 0x40c406
    4113db68 00000000 00000000 00000000 00000000 0x7835ff00
    start end module name
    804d7000 806eb780 nt ntoskrnl.exe Wed Aug 04 08:19:48 2004 (41108004)
    806ec000 806ffd80 hal halacpi.dll Wed Aug 04 07:59:04 2004 (41107B28)
    bac0c000 bac2b160 ptserial ptserial.sys Wed Aug 09 22:45:21 2000 (3991C2E1)
    bac2c000 bac4ee80 USBPORT USBPORT.SYS Wed Aug 04 08:08:34 2004 (41107D62)
    bac4f000 bac71680 ks ks.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    bac72000 bac85780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 08:07:04 2004 (41107D08)
    bac86000 bacbc480 trid3dm trid3dm.sys Thu May 17 23:15:16 2001 (3B043F64)
    bacc2000 bacd2e00 psched psched.sys Wed Aug 04 08:04:16 2004 (41107C60)
    bacd3000 bace9680 ndiswan ndiswan.sys Wed Aug 04 08:14:30 2004 (41107EC6)
    bacea000 bacfb300 Rtlnicxp Rtlnicxp.sys Fri Jul 16 08:19:52 2004 (40F77388)
    bad44000 bad5e580 Mup Mup.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    bad5f000 badbefa0 vpctcom vpctcom.sys Thu Aug 17 04:53:52 2000 (399B53C0)
    badbf000 bae40cc0 VMODEM VMODEM.SYS Thu Aug 17 02:11:47 2000 (399B2DC3)
    bae41000 bae6da80 NDIS NDIS.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    bae6e000 baefa480 Ntfs Ntfs.sys Wed Aug 04 08:15:06 2004 (41107EEA)
    baefb000 baf11780 KSecDD KSecDD.sys Wed Aug 04 07:59:45 2004 (41107B51)
    baf12000 baf23f00 sr sr.sys Wed Aug 04 08:06:22 2004 (41107CDE)
    baf24000 baf43000 fltmgr fltmgr.sys unavailable (FFFFFFFE)
    baf43000 baf5a480 atapi atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    baf5b000 baf80700 dmio dmio.sys Wed Aug 04 08:07:13 2004 (41107D11)
    baf81000 baf9f880 ftdisk ftdisk.sys Fri Aug 17 22:52:41 2001 (3B7D8419)
    bafa0000 bafb0a80 pci pci.sys Wed Aug 04 08:07:45 2004 (41107D31)
    bafb1000 bafded80 ACPI ACPI.sys Wed Aug 04 08:07:35 2004 (41107D27)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 08:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 08:00:51 2004 (41107B93)
    bf9d3000 bf9d5f00 TSDDD TSDDD.dll Wed Aug 04 09:57:02 2004 (411096CE)
    bff10000 bff5d080 trid3d trid3d.dll Fri Aug 17 23:56:04 2001 (3B7D92F4)
    f6a12000 f6a26440 naiavf5x naiavf5x.sys Tue Aug 05 03:08:00 2003 (3F2F0370)
    f6a27000 f6a67380 HTTP HTTP.sys Wed Aug 04 08:00:09 2004 (41107B69)
    f6ae0000 f6b02000 RDPWD RDPWD.SYS Wed Aug 04 07:59:01 2004 (41107B25)
    f6eca000 f6ecc780 secdrv secdrv.sys Mon Apr 08 10:50:52 2002 (3CB159EC)
    f6eea000 f6f3c180 srv srv.sys Wed Aug 04 08:14:44 2004 (41107ED4)
    f7055000 f7081400 mrxdav mrxdav.sys Wed Aug 04 08:00:49 2004 (41107B91)
    f737a000 f738a280 Udfs Udfs.SYS Wed Aug 04 08:00:27 2004 (41107B7B)
    f73a3000 f73a6280 ndisuio ndisuio.sys Wed Aug 04 08:03:10 2004 (41107C1E)
    f73db000 f741fc00 BsUDF BsUDF.SYS Tue Jul 10 08:15:40 2001 (3B4A9D8C)
    f8160000 f8177480 dump_atapi dump_atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    f8178000 f819b000 Fastfat Fastfat.SYS Wed Aug 04 08:14:15 2004 (41107EB7)
    f819b000 f81bbf00 ipnat ipnat.sys Thu Sep 30 00:28:36 2004 (415B3714)
    f81bc000 f8229680 mrxsmb mrxsmb.sys Thu Oct 28 03:14:16 2004 (418047E8)
    f822a000 f8254a00 rdbss rdbss.sys Thu Oct 28 03:13:57 2004 (418047D5)
    f8255000 f8276d00 afd afd.sys Wed Aug 04 08:14:13 2004 (41107EB5)
    f8277000 f829ec00 netbt netbt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    f829f000 f82f6a80 tcpip tcpip.sys Wed Aug 04 08:14:39 2004 (41107ECF)
    f82f7000 f8309400 ipsec ipsec.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    f8353000 f8355900 Dxapi Dxapi.sys Fri Aug 17 22:53:19 2001 (3B7D843F)
    f93ab000 f93de200 update update.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f93df000 f93ee900 Cdfs Cdfs.SYS Wed Aug 04 08:14:09 2004 (41107EB1)
    f9497000 f94c7100 rdpdr rdpdr.sys Wed Aug 04 08:01:10 2004 (41107BA6)
    f94c8000 f958c000 dmboot dmboot.sys unavailable (FFFFFFFE)
    f958c000 f9594c00 isapnp isapnp.sys Fri Aug 17 22:58:01 2001 (3B7D8559)
    f959c000 f95a6500 MountMgr MountMgr.sys Wed Aug 04 07:58:29 2004 (41107B05)
    f95ac000 f95b8c80 VolSnap VolSnap.sys Wed Aug 04 08:00:14 2004 (41107B6E)
    f95bc000 f95c4e00 disk disk.sys Wed Aug 04 07:59:53 2004 (41107B59)
    f95cc000 f95d8200 CLASSPNP CLASSPNP.SYS Wed Aug 04 08:14:26 2004 (41107EC2)
    f95ec000 f95f6500 viaagp viaagp.sys Wed Aug 04 08:07:42 2004 (41107D2E)
    f961c000 f9624700 netbios netbios.sys Wed Aug 04 08:03:19 2004 (41107C27)
    f962c000 f9634880 Fips Fips.SYS Sat Aug 18 03:31:49 2001 (3B7DC585)
    f963c000 f9644700 wanarp wanarp.sys Wed Aug 04 08:04:57 2004 (41107C89)
    f96fc000 f9704a00 processr processr.sys Wed Aug 04 07:59:14 2004 (41107B32)
    f970c000 f9716380 imapi imapi.sys Wed Aug 04 08:00:12 2004 (41107B6C)
    f971c000 f9728180 cdrom cdrom.sys Wed Aug 04 07:59:52 2004 (41107B58)
    f972c000 f973a080 redbook redbook.sys Wed Aug 04 07:59:34 2004 (41107B46)
    f974c000 f975ba80 VVOICE VVOICE.SYS Tue Jul 25 03:06:19 2000 (397CE80B)
    f975c000 f976bd80 serial serial.sys Wed Aug 04 08:15:51 2004 (41107F17)
    f976c000 f9778e00 i8042prt i8042prt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    f977c000 f9788880 rasl2tp rasl2tp.sys Wed Aug 04 08:14:21 2004 (41107EBD)
    f978c000 f9796200 raspppoe raspppoe.sys Wed Aug 04 08:05:06 2004 (41107C92)
    f979c000 f97a7d00 raspptp raspptp.sys Wed Aug 04 08:14:26 2004 (41107EC2)
    f97ac000 f97b4900 msgpc msgpc.sys Wed Aug 04 08:04:11 2004 (41107C5B)
    f97bc000 f97c5f00 termdd termdd.sys Wed Aug 04 07:58:52 2004 (41107B1C)
    f97dc000 f97e5480 NDProxy NDProxy.SYS Fri Aug 17 22:55:30 2001 (3B7D84C2)
    f97fc000 f980a100 usbhub usbhub.sys Wed Aug 04 08:08:40 2004 (41107D68)
    f980c000 f9812200 PCIIDEX PCIIDEX.SYS Wed Aug 04 07:59:40 2004 (41107B4C)
    f9814000 f9818900 PartMgr PartMgr.sys Sat Aug 18 03:32:23 2001 (3B7DC5A7)
    f981c000 f9820bc0 PxHelp20 PxHelp20.sys Tue Oct 28 19:25:49 2003 (3F9EB4AD)
    f9864000 f9869500 TDTCP TDTCP.SYS Wed Aug 04 07:58:52 2004 (41107B1C)
    f98b4000 f98b9000 usbuhci usbuhci.sys Wed Aug 04 08:08:34 2004 (41107D62)
    f98bc000 f98c3580 Modem Modem.SYS Wed Aug 04 08:08:04 2004 (41107D44)
    f98c4000 f98cab00 fdc fdc.sys Wed Aug 04 07:59:25 2004 (41107B3D)
    f98cc000 f98d1a00 mouclass mouclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f98d4000 f98da000 kbdclass kbdclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f98dc000 f98e0880 TDI TDI.SYS Wed Aug 04 08:07:47 2004 (41107D33)
    f98e4000 f98e8580 ptilink ptilink.sys Fri Aug 17 22:49:53 2001 (3B7D8371)
    f98ec000 f98f0080 raspti raspti.sys Fri Aug 17 22:55:32 2001 (3B7D84C4)
    f9904000 f9909000 flpydisk flpydisk.sys Wed Aug 04 07:59:24 2004 (41107B3C)
    f9914000 f9919200 vga vga.sys Wed Aug 04 08:07:06 2004 (41107D0A)
    f991c000 f9920a80 Msfs Msfs.SYS Wed Aug 04 08:00:37 2004 (41107B85)
    f9924000 f992b880 Npfs Npfs.SYS Wed Aug 04 08:00:38 2004 (41107B86)
    f9944000 f9948500 watchdog watchdog.sys Wed Aug 04 08:07:32 2004 (41107D24)
    f999c000 f999f000 BOOTVID BOOTVID.dll Fri Aug 17 22:49:09 2001 (3B7D8345)
    f9a1c000 f9a1e280 rasacd rasacd.sys Fri Aug 17 22:55:39 2001 (3B7D84CB)
    f9a48000 f9a4bc80 serenum serenum.sys Wed Aug 04 07:59:06 2004 (41107B2A)
    f9a4c000 f9a4e580 ndistapi ndistapi.sys Fri Aug 17 22:55:29 2001 (3B7D84C1)
    f9a68000 f9a6bc80 mssmbios mssmbios.sys Wed Aug 04 08:07:47 2004 (41107D33)
    f9a8c000 f9a8db80 kdcom kdcom.dll Fri Aug 17 22:49:10 2001 (3B7D8346)
    f9a8e000 f9a8f100 WMILIB WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9a90000 f9a91500 viaide viaide.sys Wed Aug 04 07:59:42 2004 (41107B4E)
    f9a92000 f9a94000 dmload dmload.sys unavailable (FFFFFFFE)
    f9a9e000 f9a9f100 swenum swenum.sys Wed Aug 04 07:58:41 2004 (41107B11)
    f9aaa000 f9aab280 USBD USBD.SYS Fri Aug 17 23:02:58 2001 (3B7D8682)
    f9aba000 f9abc000 Fs_Rec Fs_Rec.SYS unavailable (FFFFFFFE)
    f9abc000 f9abd080 Beep Beep.SYS Fri Aug 17 22:47:33 2001 (3B7D82E5)
    f9abe000 f9abf080 mnmdd mnmdd.SYS Fri Aug 17 22:57:28 2001 (3B7D8538)
    f9ac0000 f9ac1080 RDPCDD RDPCDD.sys Fri Aug 17 22:46:56 2001 (3B7D82C0)
    f9ad2000 f9ad3100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9b36000 f9b37100 hiber_WMILIB hiber_WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f9b99000 f9b99d00 dxgthk dxgthk.sys Fri Aug 17 22:53:12 2001 (3B7D8438)
    f9ba6000 f9ba6c00 audstub audstub.sys Fri Aug 17 22:59:40 2001 (3B7D85BC)
    f9c51000 f9c52000 Null Null.SYS unavailable (FFFFFFFE)

    Unloaded modules:
    f24c2000 f24da000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f3d8a000 f3da2000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4a2a000 f4a42000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f4c32000 f4c4a000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f9c60000 f9c61000 BANTExt.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f990c000 f9911000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f9a18000 f9a1b000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bad5f000 bade1000 vmodem.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bade1000 bae41000 vpctcom.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f95dc000 f95ec000 vvoice.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  5. 2005/01/07
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    Code:
    eax=000000f1 ebx=0253bef1 ecx=8055a388 edx=fe6a8b68 esi=0000038e edi=58568380
    eip=804e3880 esp=f6c99c00 ebp=f6c99c08 iopl=0 nv up ei pl nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
    nt!KeUpdateSystemTime+0x143:
    804e3880 ff05c4f5dfff inc dword ptr [ffdff5c4] ds:0023:ffdff5c4=06d7befe
    
    STACK_TEXT: 
    f6c99c08 bf802453 badb0d00 80010031 f6c99c68 nt!KeUpdateSystemTime+0x143
    This is 'the juice' of your dump log. The registers in state at the exact time of the crash, and the stack in the correct trap frame.

    if you have many dumps in this routine like this, there is something afoot. This is the routine that updates the system time, does dpc processing, IPI, etc.. Ill need to check into it to make sure that eip is valid and lines up, and then look at a know good machine to see whats in that pointer.

    If i had to use a crystal ball, you have a hardware driver that is doing some nonsense with dpcs, or that EIP is off a bit or 2. i'll post back later after i check out a known good.
     
  6. 2005/01/07
    BenMcDonald[MS]

    BenMcDonald[MS] Inactive

    Joined:
    2004/12/14
    Messages:
    228
    Likes Received:
    0
    a bitflip!
    Look at the memory it tried to read:
    Now, look at the instruction it was SUPPOSED to be exectuting
    0:000> .formats ffdff5c4
    Binary: 11111111 11011111 11110101 11000100
    0:000> .formats fffff5c4
    Binary: 11111111 11111111 11110101 11000100

    Now the trick is How in the world did that happen. The code said do something, and a bit flipped either while reading the instruction from RAM, or while actually processing the instruction. The image is not corrupt, otherwise the debug log wouldnt look like that (hrm, maybe thats an assumption).

    Heres my guesses in order of likelyhood:
    1) bad proc
    2) bad motherboard
    3) bad ram

    Since you arent getting any other crashes, i highly doubt its bad ram. Since its crashing in EXACTLY the same place every time, i dont think its a bad motherboard. It is my GUESS that the proc, when given that SPECIFIC instruction, ff05c4f5dfff, is flipping a bit sometimes.

    My recommendation to you is to a) update your BIOS to latest availbile (to get any microcode updates b) make sure you are current with windows update (another vehicle for microcode updates) c) update all drivers for your motherboard from the vendor and d) if none of that works, start replacing components, in the order i've recommended. I realize the proc is not a cheap replacement component, so I encourage you to research my response before opening your wallet. I'm basing this on a single point of data, and making a lot of assumptions.
     
  7. 2005/01/07
    Thonolan

    Thonolan Inactive Thread Starter

    Joined:
    2005/01/06
    Messages:
    3
    Likes Received:
    0
    I know my motherboard is a cheap thing, it's a M787CLR from PCCHIPS, specs can be found at http://www.mcsmicro.com/mcs_index_files/promotion/M787CLR.htm

    I already searched a new BIOS on the web but didn't really find one for my mobo... pcchips is not responding to my mails. I requested an upgraded bios at esupport.com, but they want to charge me 30$ for it. I didn't buy it yet because I wanted to be sure that it could solve my problem.
    I already tested my ram with memtest and my windows is up-to-date.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.