1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

New Build - BSOD - Dump Data

Discussion in 'Windows XP' started by spotta, 2005/04/13.

Thread Status:
Not open for further replies.
  1. 2005/04/13
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Hi All.

    I have a newly built machine here, I installed XP home and started getting random lock-ups. reformatted and tried again, and still having problems :confused:

    I gather it's a driver fault - but i was wondering if someone who knows how to read dump data could point me in the right direction.

    I would like to learn more about troubleshooting memory dumps but do not know where to go to do this.

    dump data as follows

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini041205-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Tue Apr 12 07:05:10.484 2005 (GMT-7)
    System Uptime: 0 days 1:46:57.062
    Loading Kernel Symbols
    .............................................................................................................
    Loading unloaded module list
    .............
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 6, {0, 0, 0, 0}

    Probably caused by : ntkrnlpa.exe ( nt!KeUnstackDetachProcess+10d )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    INVALID_PROCESS_DETACH_ATTEMPT (6)
    Arguments:
    Arg1: 00000000
    Arg2: 00000000
    Arg3: 00000000
    Arg4: 00000000

    Debugging Details:
    ------------------


    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x6

    LAST_CONTROL_TRANSFER: from 804f73d9 to 804f8900

    STACK_TEXT:
    b6e2ebb0 804f73d9 00000006 8999a2b8 7ffa9000 nt!KeBugCheck+0x14
    b6e2ebd8 805c41df b6e2ebf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d
    b6e2ec34 805c07fd 8999a2b8 00000000 b6e2ed64 nt!PsAssignImpersonationToken+0x123
    b6e2ed4c 8053c808 fffffffe 00000005 00c5fc88 nt!NtSetInformationThread+0x207
    b6e2ed4c 7c90eb94 fffffffe 00000005 00c5fc88 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00c5fc6c 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    nt!KeUnstackDetachProcess+10d
    804f73d9 cc int 3

    SYMBOL_STACK_INDEX: 1

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!KeUnstackDetachProcess+10d

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlpa.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107b0c

    STACK_COMMAND: kb

    FAILURE_BUCKET_ID: 0x6_nt!KeUnstackDetachProcess+10d

    BUCKET_ID: 0x6_nt!KeUnstackDetachProcess+10d

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00000000 ecx=00000000 edx=00000000 esi=8999a2b8 edi=8999a2b8
    eip=804f8900 esp=b6e2eb98 ebp=b6e2ebb0 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheck+0x14:
    804f8900 5d pop ebp
    ChildEBP RetAddr Args to Child
    b6e2ebb0 804f73d9 00000006 8999a2b8 7ffa9000 nt!KeBugCheck+0x14 (FPO: [Non-Fpo])
    b6e2ebd8 805c41df b6e2ebf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d (FPO: [Non-Fpo])
    b6e2ec34 805c07fd 8999a2b8 00000000 b6e2ed64 nt!PsAssignImpersonationToken+0x123 (FPO: [Non-Fpo])
    b6e2ed4c 8053c808 fffffffe 00000005 00c5fc88 nt!NtSetInformationThread+0x207 (FPO: [Non-Fpo])
    b6e2ed4c 7c90eb94 fffffffe 00000005 00c5fc88 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ b6e2ed64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00c5fc6c 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Tue Aug 03 22:58:36 2004 (41107B0C)
    806ce000 806ee380 hal halaacpi.dll Tue Aug 03 22:59:05 2004 (41107B29)
    b65c6000 b6611d80 mrv8ka51 mrv8ka51.sys Wed Jan 05 19:18:38 2005 (41DCAE0E)
    b6612000 b6648b00 yk51x86 yk51x86.sys Thu Nov 25 23:42:27 2004 (41A6DE63)
    b6649000 b666c000 Fastfat Fastfat.SYS Tue Aug 03 23:14:15 2004 (41107EB7)
    b6a7d000 b6a91400 wdmaud wdmaud.sys Tue Aug 03 23:15:03 2004 (41107EE7)
    b6aba000 b6afa100 HTTP HTTP.sys Fri Oct 08 16:48:20 2004 (41672744)
    b6b7b000 b6b89d80 sysaudio sysaudio.sys Tue Aug 03 23:15:54 2004 (41107F1A)
    b6d03000 b6d55180 srv srv.sys Tue Aug 03 23:14:44 2004 (41107ED4)
    b6da6000 b6dd2400 mrxdav mrxdav.sys Tue Aug 03 23:00:49 2004 (41107B91)
    b6efb000 b6efe280 ndisuio ndisuio.sys Tue Aug 03 23:03:10 2004 (41107C1E)
    b7313000 b7381400 mrxsmb mrxsmb.sys Tue Jan 18 20:26:50 2005 (41EDE18A)
    b7382000 b73a2f00 ipnat ipnat.sys Wed Sep 29 15:28:36 2004 (415B3714)
    b73a3000 b73cda00 rdbss rdbss.sys Wed Oct 27 18:13:57 2004 (418047D5)
    b73ce000 b73efd00 afd afd.sys Tue Aug 03 23:14:13 2004 (41107EB5)
    b73f0000 b7417c00 netbt netbt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    b7418000 b746fa80 tcpip tcpip.sys Tue Aug 03 23:14:39 2004 (41107ECF)
    b7470000 b7482400 ipsec ipsec.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    b74a3000 b74b6780 VIDEOPRT VIDEOPRT.SYS Tue Aug 03 23:07:04 2004 (41107D08)
    b74cb000 b74cd900 Dxapi Dxapi.sys Fri Aug 17 13:53:19 2001 (3B7D843F)
    b792e000 b793cd00 dump_viamraid dump_viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    b793e000 b794d900 Cdfs Cdfs.SYS Tue Aug 03 23:14:09 2004 (41107EB1)
    b7a50000 b7a53780 dump_scsiport dump_scsiport.sys Tue Aug 03 22:59:51 2004 (41107B57)
    b7d3e000 b7d4cd80 arp1394 arp1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    b7d4e000 b7d56880 Fips Fips.SYS Fri Aug 17 18:31:49 2001 (3B7DC585)
    b7d5e000 b7d66700 wanarp wanarp.sys Tue Aug 03 23:04:57 2004 (41107C89)
    b7d6e000 b7d76700 netbios netbios.sys Tue Aug 03 23:03:19 2004 (41107C27)
    b818b000 b818d280 rasacd rasacd.sys Fri Aug 17 13:55:39 2001 (3B7D84CB)
    b87f0000 b8823200 update update.sys Tue Aug 03 22:58:32 2004 (41107B08)
    ba1db000 ba1ebe00 psched psched.sys Tue Aug 03 23:04:16 2004 (41107C60)
    ba28c000 ba2a2680 ndiswan ndiswan.sys Tue Aug 03 23:14:30 2004 (41107EC6)
    ba2c4000 ba2d7900 parport parport.sys Tue Aug 03 22:59:04 2004 (41107B28)
    ba2d8000 ba2fb980 portcls portcls.sys Tue Aug 03 23:15:47 2004 (41107F13)
    ba2fc000 ba529d40 ALCXWDM ALCXWDM.SYS Tue Oct 26 22:57:33 2004 (417F38CD)
    ba541000 ba563e80 USBPORT USBPORT.SYS Tue Aug 03 23:08:34 2004 (41107D62)
    ba564000 ba586680 ks ks.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    ba5fc000 ba616580 Mup Mup.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    ba617000 ba643a80 NDIS NDIS.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    ba644000 ba6d0480 Ntfs Ntfs.sys Tue Aug 03 23:15:06 2004 (41107EEA)
    ba6d1000 ba6e7780 KSecDD KSecDD.sys Tue Aug 03 22:59:45 2004 (41107B51)
    ba6e8000 ba6f9f00 sr sr.sys Tue Aug 03 23:06:22 2004 (41107CDE)
    ba6fa000 ba718780 fltMgr fltMgr.sys Tue Aug 03 23:01:17 2004 (41107BAD)
    ba719000 ba730800 SCSIPORT SCSIPORT.SYS Tue Aug 03 22:59:39 2004 (41107B4B)
    ba731000 ba748480 atapi atapi.sys Tue Aug 03 22:59:41 2004 (41107B4D)
    ba749000 ba767880 ftdisk ftdisk.sys Fri Aug 17 13:52:41 2001 (3B7D8419)
    ba768000 ba778a80 pci pci.sys Tue Aug 03 23:07:45 2004 (41107D31)
    ba779000 ba7a6d80 ACPI ACPI.sys Tue Aug 03 23:07:35 2004 (41107D27)
    ba8a8000 ba8b0c00 isapnp isapnp.sys Fri Aug 17 13:58:01 2001 (3B7D8559)
    ba8b8000 ba8c6e80 ohci1394 ohci1394.sys Tue Aug 03 23:10:05 2004 (41107DBD)
    ba8c8000 ba8d5000 1394BUS 1394BUS.SYS Tue Aug 03 23:10:03 2004 (41107DBB)
    ba8d8000 ba8e2500 MountMgr MountMgr.sys Tue Aug 03 22:58:29 2004 (41107B05)
    ba8e8000 ba8f4c80 VolSnap VolSnap.sys Tue Aug 03 23:00:14 2004 (41107B6E)
    ba8f8000 ba906d00 viamraid viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    ba908000 ba910e00 disk disk.sys Tue Aug 03 22:59:53 2004 (41107B59)
    ba918000 ba924200 CLASSPNP CLASSPNP.SYS Tue Aug 03 23:14:26 2004 (41107EC2)
    ba928000 ba933580 gagp30kx gagp30kx.sys Tue Aug 03 23:07:43 2004 (41107D2F)
    ba958000 ba964180 cdrom cdrom.sys Tue Aug 03 22:59:52 2004 (41107B58)
    ba968000 ba976080 redbook redbook.sys Tue Aug 03 22:59:34 2004 (41107B46)
    ba978000 ba986b80 drmk drmk.sys Tue Aug 03 23:07:54 2004 (41107D3A)
    ba988000 ba997d80 serial serial.sys Tue Aug 03 23:15:51 2004 (41107F17)
    ba998000 ba9a4e00 i8042prt i8042prt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    ba9a8000 ba9b4880 rasl2tp rasl2tp.sys Tue Aug 03 23:14:21 2004 (41107EBD)
    ba9b8000 ba9c2200 raspppoe raspppoe.sys Tue Aug 03 23:05:06 2004 (41107C92)
    ba9c8000 ba9d3d00 raspptp raspptp.sys Tue Aug 03 23:14:26 2004 (41107EC2)
    ba9e8000 ba9f7180 nic1394 nic1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    ba9f8000 baa00900 msgpc msgpc.sys Tue Aug 03 23:04:11 2004 (41107C5B)
    baa28000 baa31f00 termdd termdd.sys Tue Aug 03 22:58:52 2004 (41107B1C)
    baa38000 baa41480 NDProxy NDProxy.SYS Fri Aug 17 13:55:30 2001 (3B7D84C2)
    baa68000 baa76100 usbhub usbhub.sys Tue Aug 03 23:08:40 2004 (41107D68)
    bab08000 bab10a00 processr processr.sys Tue Aug 03 22:59:14 2004 (41107B32)
    bab18000 bab22380 imapi imapi.sys Tue Aug 03 23:00:12 2004 (41107B6C)
    bab28000 bab2e200 PCIIDEX PCIIDEX.SYS Tue Aug 03 22:59:40 2004 (41107B4C)
    bab30000 bab34900 PartMgr PartMgr.sys Fri Aug 17 18:32:23 2001 (3B7DC5A7)
    bab58000 bab5c880 TDI TDI.SYS Tue Aug 03 23:07:47 2004 (41107D33)
    bab80000 bab85000 flpydisk flpydisk.sys Tue Aug 03 22:59:24 2004 (41107B3C)
    babf0000 babf5200 vga vga.sys Tue Aug 03 23:07:06 2004 (41107D0A)
    babf8000 babfca80 Msfs Msfs.SYS Tue Aug 03 23:00:37 2004 (41107B85)
    bac00000 bac07880 Npfs Npfs.SYS Tue Aug 03 23:00:38 2004 (41107B86)
    bac28000 bac2c080 raspti raspti.sys Fri Aug 17 13:55:32 2001 (3B7D84C4)
    bac60000 bac64580 ptilink ptilink.sys Fri Aug 17 13:49:53 2001 (3B7D8371)
    bac70000 bac74500 watchdog watchdog.sys Tue Aug 03 23:07:32 2004 (41107D24)
    bac90000 bac95000 usbuhci usbuhci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    bac98000 bac9e800 usbehci usbehci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    baca0000 baca1000 fdc fdc.sys unavailable (00000000)
    baca8000 bacada00 mouclass mouclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    bacb0000 bacb6000 kbdclass kbdclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    bacb8000 bacbb000 BOOTVID BOOTVID.dll Fri Aug 17 13:49:09 2001 (3B7D8345)
    bad40000 bad43c80 mssmbios mssmbios.sys Tue Aug 03 23:07:47 2004 (41107D33)
    bad60000 bad63c80 serenum serenum.sys Tue Aug 03 22:59:06 2004 (41107B2A)
    bad64000 bad66980 gameenum gameenum.sys Tue Aug 03 23:08:20 2004 (41107D54)
    bad68000 bad6a580 ndistapi ndistapi.sys Fri Aug 17 13:55:29 2001 (3B7D84C1)
    bada8000 bada9b80 kdcom kdcom.dll Fri Aug 17 13:49:10 2001 (3B7D8346)
    badaa000 badab100 WMILIB WMILIB.SYS Fri Aug 17 14:07:23 2001 (3B7D878B)
    badac000 badad500 viaide viaide.sys Tue Aug 03 22:59:42 2004 (41107B4E)
    badae000 badaf080 mnmdd mnmdd.SYS Fri Aug 17 13:57:28 2001 (3B7D8538)
    badb0000 badb1080 RDPCDD RDPCDD.sys Fri Aug 17 13:46:56 2001 (3B7D82C0)
    badbe000 badbf420 ASACPI ASACPI.sys Thu Aug 12 19:52:52 2004 (411C2D04)
    bae0a000 bae0b100 swenum swenum.sys Tue Aug 03 22:58:41 2004 (41107B11)
    bae0e000 bae0f280 USBD USBD.SYS Fri Aug 17 14:02:58 2001 (3B7D8682)
    bae12000 bae13a80 ParVdm ParVdm.SYS Fri Aug 17 13:49:49 2001 (3B7D836D)
    bae6c000 bae6df00 Fs_Rec Fs_Rec.SYS Fri Aug 17 13:49:37 2001 (3B7D8361)
    bae6e000 bae6f080 Beep Beep.SYS Fri Aug 17 13:47:33 2001 (3B7D82E5)
    bae70000 bae70d00 pciide pciide.sys Fri Aug 17 13:51:49 2001 (3B7D83E5)
    bae9c000 bae9cb80 Null Null.SYS Fri Aug 17 13:47:39 2001 (3B7D82EB)
    baef6000 baef6d00 dxgthk dxgthk.sys Fri Aug 17 13:53:12 2001 (3B7D8438)
    bafca000 bafcab80 msmpu401 msmpu401.sys Fri Aug 17 13:59:59 2001 (3B7D85CF)
    bafcb000 bafcbc00 audstub audstub.sys Fri Aug 17 13:59:40 2001 (3B7D85BC)
    bf800000 bf9c0380 win32k win32k.sys Tue Aug 03 23:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Tue Aug 03 23:00:51 2004 (41107B93)
    bff50000 bff52480 framebuf framebuf.dll Wed Aug 04 00:56:31 2004 (411096AF)

    Unloaded modules:
    b64fc000 b6526000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b64fc000 b6526000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b64fc000 b6526000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba587000 ba5b4000 yk51x86.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b67ac000 b67d6000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b6990000 b69ba000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    baf58000 baf59000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b6a5a000 b6a7d000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b6b4b000 b6b58000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b6b5b000 b6b69000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bade6000 bade8000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    babe8000 babed000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b818f000 b8192000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt


    Many thanks
     
  2. 2005/04/13
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    I left the machine on overnight and in the morning i had another BSOD

    Dump data as follows

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini041205-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 2600.xpsp_sp2_gdr.050301-1519
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Tue Apr 12 17:22:12.953 2005 (GMT-7)
    System Uptime: 0 days 5:25:48.552
    Loading Kernel Symbols
    ............................................................................................................................
    Loading unloaded module list
    ..................
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000000A, {96864f28, 2, 0, 8051ead2}

    Probably caused by : memory_corruption ( nt!MiDeletePte+4e )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: 96864f28, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: 8051ead2, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: 96864f28

    CURRENT_IRQL: 2

    FAULTING_IP:
    nt!MiDeletePte+4e
    8051ead2 8b16 mov edx,[esi]

    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xA

    LAST_CONTROL_TRANSFER: from 8051f090 to 8051ead2

    STACK_TEXT:
    b3fd9bc4 8051f090 c00f3f10 1e7e2000 00000000 nt!MiDeletePte+0x4e
    b3fd9c88 80516641 00073d90 5ad0cfff 00000000 nt!MiDeleteVirtualAddresses+0x164
    b3fd9ca4 805a72ec 10030000 5ad0cfff b3fd9d64 nt!MiDeleteFreeVm+0x1d
    b3fd9d4c 8053c808 ffffffff 00ccfcec 00ccfd04 nt!NtFreeVirtualMemory+0x42e
    b3fd9d4c 7c90eb94 ffffffff 00ccfcec 00ccfd04 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00ccfc24 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    nt!MiDeletePte+4e
    8051ead2 8b16 mov edx,[esi]

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!MiDeletePte+4e

    MODULE_NAME: nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 42250a1d

    STACK_COMMAND: kb

    IMAGE_NAME: memory_corruption

    FAILURE_BUCKET_ID: 0xA_nt!MiDeletePte+4e

    BUCKET_ID: 0xA_nt!MiDeletePte+4e

    Followup: MachineOwner
    ---------

    eax=81086000 ebx=c00f3f10 ecx=00c47f66 edx=00000000 esi=96864f28 edi=03ffffff
    eip=8051ead2 esp=b3fd9b9c ebp=b3fd9bc4 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
    nt!MiDeletePte+0x4e:
    8051ead2 8b16 mov edx,[esi] ds:0023:96864f28=????????
    ChildEBP RetAddr Args to Child
    b3fd9bc4 8051f090 c00f3f10 1e7e2000 00000000 nt!MiDeletePte+0x4e (FPO: [Non-Fpo])
    b3fd9c88 80516641 00073d90 5ad0cfff 00000000 nt!MiDeleteVirtualAddresses+0x164 (FPO: [Non-Fpo])
    b3fd9ca4 805a72ec 10030000 5ad0cfff b3fd9d64 nt!MiDeleteFreeVm+0x1d (FPO: [Non-Fpo])
    b3fd9d4c 8053c808 ffffffff 00ccfcec 00ccfd04 nt!NtFreeVirtualMemory+0x42e (FPO: [Non-Fpo])
    b3fd9d4c 7c90eb94 ffffffff 00ccfcec 00ccfd04 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ b3fd9d64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00ccfc24 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Tue Mar 01 16:34:37 2005 (42250A1D)
    806ce000 806ee380 hal halaacpi.dll Tue Aug 03 22:59:05 2004 (41107B29)
    ae051000 ae061960 NAVENG NAVENG.Sys Thu Dec 30 13:46:10 2004 (41D47722)
    ae062000 ae0faa60 NavEx15 NavEx15.Sys Thu Dec 30 13:45:19 2004 (41D476EF)
    ae69b000 ae6db100 HTTP HTTP.sys Fri Oct 08 16:48:20 2004 (41672744)
    ae9fc000 aea4e180 srv srv.sys Tue Aug 03 23:14:44 2004 (41107ED4)
    aea9f000 aeacb400 mrxdav mrxdav.sys Tue Aug 03 23:00:49 2004 (41107B91)
    aecd3000 aece7400 wdmaud wdmaud.sys Tue Aug 03 23:15:03 2004 (41107EE7)
    aed60000 aed83000 Fastfat Fastfat.SYS Tue Aug 03 23:14:15 2004 (41107EB7)
    b04a4000 b0512400 mrxsmb mrxsmb.sys Tue Jan 18 20:26:50 2005 (41EDE18A)
    b0513000 b053da00 rdbss rdbss.sys Wed Oct 27 18:13:57 2004 (418047D5)
    b053e000 b055fd00 afd afd.sys Tue Aug 03 23:14:13 2004 (41107EB5)
    b0560000 b0587c00 netbt netbt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    b0588000 b05ce460 symidsco symidsco.sys Thu Mar 03 18:55:44 2005 (4227CE30)
    b05cf000 b05eff00 ipnat ipnat.sys Wed Sep 29 15:28:36 2004 (415B3714)
    b05f0000 b06189e0 SYMFW SYMFW.SYS Fri Jan 21 21:57:51 2005 (41F1EB5F)
    b0619000 b0658da0 SYMTDI SYMTDI.SYS Fri Jan 21 21:55:40 2005 (41F1EADC)
    b0659000 b06b0d80 tcpip tcpip.sys Sun Mar 13 16:55:05 2005 (4234E0E9)
    b06b1000 b06c3400 ipsec ipsec.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    b078e000 b07a7a80 SYMEVENT SYMEVENT.SYS Tue Oct 19 14:18:08 2004 (41758490)
    b07b4000 b07b7780 dump_scsiport dump_scsiport.sys Tue Aug 03 22:59:51 2004 (41107B57)
    b2e79000 b2ec9000 SAVRT SAVRT.SYS Tue Jan 25 21:38:55 2005 (41F72CEF)
    b2ff1000 b2ff81e0 SYMIDS SYMIDS.SYS Fri Jan 21 21:59:16 2005 (41F1EBB4)
    b39c7000 b39cc200 vga vga.sys Tue Aug 03 23:07:06 2004 (41107D0A)
    b7391000 b73c4200 update update.sys Tue Aug 03 22:58:32 2004 (41107B08)
    b73f5000 b7403100 usbhub usbhub.sys Tue Aug 03 23:08:40 2004 (41107D68)
    b7700000 b7709480 NDProxy NDProxy.SYS Fri Aug 17 13:55:30 2001 (3B7D84C2)
    b7b54000 b7b59000 flpydisk flpydisk.sys Tue Aug 03 22:59:24 2004 (41107B3C)
    b7c01000 b7c0af00 termdd termdd.sys Tue Aug 03 22:58:52 2004 (41107B1C)
    b7c2a000 b7c2e500 watchdog watchdog.sys Tue Aug 03 23:07:32 2004 (41107D24)
    b7c5a000 b7c5e080 raspti raspti.sys Fri Aug 17 13:55:32 2001 (3B7D84C4)
    b7c62000 b7c66580 ptilink ptilink.sys Fri Aug 17 13:49:53 2001 (3B7D8371)
    b867f000 b8689000 SYMNDIS SYMNDIS.SYS Fri Jan 21 21:57:07 2005 (41F1EB33)
    b868f000 b869f000 SAVRTPEL SAVRTPEL.SYS Tue Jan 25 21:38:57 2005 (41F72CF1)
    b8a06000 b8a09c80 mssmbios mssmbios.sys Tue Aug 03 23:07:47 2004 (41107D33)
    b8a0a000 b8a0c900 Dxapi Dxapi.sys Fri Aug 17 13:53:19 2001 (3B7D843F)
    b8a9f000 b8aa7700 wanarp wanarp.sys Tue Aug 03 23:04:57 2004 (41107C89)
    b8adf000 b8aedd80 sysaudio sysaudio.sys Tue Aug 03 23:15:54 2004 (41107F1A)
    b8bec000 b8bf4880 Fips Fips.SYS Fri Aug 17 18:31:49 2001 (3B7DC585)
    b8bfc000 b8c04700 netbios netbios.sys Tue Aug 03 23:03:19 2004 (41107C27)
    b8c0c000 b8c1ad80 arp1394 arp1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    b8f36000 b8f46e00 psched psched.sys Tue Aug 03 23:04:16 2004 (41107C60)
    b8f47000 b8f5d680 ndiswan ndiswan.sys Tue Aug 03 23:14:30 2004 (41107EC6)
    b8f5e000 b8f71900 parport parport.sys Tue Aug 03 22:59:04 2004 (41107B28)
    b8f98000 b8fbb980 portcls portcls.sys Tue Aug 03 23:15:47 2004 (41107F13)
    b8fbc000 b91e9d40 ALCXWDM ALCXWDM.SYS Tue Oct 26 22:57:33 2004 (417F38CD)
    b91ea000 b920ce80 USBPORT USBPORT.SYS Tue Aug 03 23:08:34 2004 (41107D62)
    b920d000 b922f680 ks ks.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    b9230000 b927bd80 mrv8ka51 mrv8ka51.sys Wed Jan 05 19:18:38 2005 (41DCAE0E)
    b927c000 b92b2b00 yk51x86 yk51x86.sys Thu Nov 25 23:42:27 2004 (41A6DE63)
    b92f8000 b930b780 VIDEOPRT VIDEOPRT.SYS Tue Aug 03 23:07:04 2004 (41107D08)
    b930c000 b964be40 nv4_mini nv4_mini.sys Thu Jan 27 00:47:35 2005 (41F8AAA7)
    b966c000 b96746e0 NPDRIVER NPDRIVER.SYS Tue Aug 13 23:39:06 2002 (3D59FB0A)
    b967c000 b968a080 redbook redbook.sys Tue Aug 03 22:59:34 2004 (41107B46)
    b968c000 b9698180 cdrom cdrom.sys Tue Aug 03 22:59:52 2004 (41107B58)
    b969c000 b96a6380 imapi imapi.sys Tue Aug 03 23:00:12 2004 (41107B6C)
    b96bc000 b96c4a00 processr processr.sys Tue Aug 03 22:59:14 2004 (41107B32)
    ba5cc000 ba5ce280 rasacd rasacd.sys Fri Aug 17 13:55:39 2001 (3B7D84CB)
    ba5fc000 ba616580 Mup Mup.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    ba617000 ba643a80 NDIS NDIS.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    ba644000 ba6d0480 Ntfs Ntfs.sys Tue Aug 03 23:15:06 2004 (41107EEA)
    ba6d1000 ba6e7780 KSecDD KSecDD.sys Tue Aug 03 22:59:45 2004 (41107B51)
    ba6e8000 ba6f9f00 sr sr.sys Tue Aug 03 23:06:22 2004 (41107CDE)
    ba6fa000 ba718780 fltMgr fltMgr.sys Tue Aug 03 23:01:17 2004 (41107BAD)
    ba719000 ba730800 SCSIPORT SCSIPORT.SYS Tue Aug 03 22:59:39 2004 (41107B4B)
    ba731000 ba748480 atapi atapi.sys Tue Aug 03 22:59:41 2004 (41107B4D)
    ba749000 ba767880 ftdisk ftdisk.sys Fri Aug 17 13:52:41 2001 (3B7D8419)
    ba768000 ba778a80 pci pci.sys Tue Aug 03 23:07:45 2004 (41107D31)
    ba779000 ba7a6d80 ACPI ACPI.sys Tue Aug 03 23:07:35 2004 (41107D27)
    ba8a8000 ba8b0c00 isapnp isapnp.sys Fri Aug 17 13:58:01 2001 (3B7D8559)
    ba8b8000 ba8c6e80 ohci1394 ohci1394.sys Tue Aug 03 23:10:05 2004 (41107DBD)
    ba8c8000 ba8d5000 1394BUS 1394BUS.SYS Tue Aug 03 23:10:03 2004 (41107DBB)
    ba8d8000 ba8e2500 MountMgr MountMgr.sys Tue Aug 03 22:58:29 2004 (41107B05)
    ba8e8000 ba8f4c80 VolSnap VolSnap.sys Tue Aug 03 23:00:14 2004 (41107B6E)
    ba8f8000 ba906d00 viamraid viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    ba908000 ba910e00 disk disk.sys Tue Aug 03 22:59:53 2004 (41107B59)
    ba918000 ba924200 CLASSPNP CLASSPNP.SYS Tue Aug 03 23:14:26 2004 (41107EC2)
    ba928000 ba933580 gagp30kx gagp30kx.sys Tue Aug 03 23:07:43 2004 (41107D2F)
    ba958000 ba964880 rasl2tp rasl2tp.sys Tue Aug 03 23:14:21 2004 (41107EBD)
    ba968000 ba972200 raspppoe raspppoe.sys Tue Aug 03 23:05:06 2004 (41107C92)
    ba978000 ba983d00 raspptp raspptp.sys Tue Aug 03 23:14:26 2004 (41107EC2)
    ba988000 ba990900 msgpc msgpc.sys Tue Aug 03 23:04:11 2004 (41107C5B)
    baa38000 baa47180 nic1394 nic1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    baaa8000 baab7900 Cdfs Cdfs.SYS Tue Aug 03 23:14:09 2004 (41107EB1)
    baac8000 baad6d00 dump_viamraid dump_viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    baae8000 baaf6b80 drmk drmk.sys Tue Aug 03 23:07:54 2004 (41107D3A)
    baaf8000 bab07d80 serial serial.sys Tue Aug 03 23:15:51 2004 (41107F17)
    bab08000 bab14e00 i8042prt i8042prt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    bab28000 bab2e200 PCIIDEX PCIIDEX.SYS Tue Aug 03 22:59:40 2004 (41107B4C)
    bab30000 bab34900 PartMgr PartMgr.sys Fri Aug 17 18:32:23 2001 (3B7DC5A7)
    babe8000 babed000 usbuhci usbuhci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    babf0000 babf6800 usbehci usbehci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    bac08000 bac09000 fdc fdc.sys unavailable (00000000)
    bac10000 bac15a00 mouclass mouclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    bac18000 bac1e000 kbdclass kbdclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    bac28000 bac2c880 TDI TDI.SYS Tue Aug 03 23:07:47 2004 (41107D33)
    bac38000 bac3ca80 Msfs Msfs.SYS Tue Aug 03 23:00:37 2004 (41107B85)
    bac40000 bac47880 Npfs Npfs.SYS Tue Aug 03 23:00:38 2004 (41107B86)
    bac48000 bac4d060 SYMREDRV SYMREDRV.SYS Fri Jan 21 21:58:32 2005 (41F1EB88)
    bacb8000 bacbb000 BOOTVID BOOTVID.dll Fri Aug 17 13:49:09 2001 (3B7D8345)
    bad54000 bad57280 ndisuio ndisuio.sys Tue Aug 03 23:03:10 2004 (41107C1E)
    bad94000 bad97c80 serenum serenum.sys Tue Aug 03 22:59:06 2004 (41107B2A)
    bad98000 bad9a980 gameenum gameenum.sys Tue Aug 03 23:08:20 2004 (41107D54)
    bad9c000 bad9e580 ndistapi ndistapi.sys Fri Aug 17 13:55:29 2001 (3B7D84C1)
    bada8000 bada9b80 kdcom kdcom.dll Fri Aug 17 13:49:10 2001 (3B7D8346)
    badaa000 badab100 WMILIB WMILIB.SYS Fri Aug 17 14:07:23 2001 (3B7D878B)
    badac000 badad500 viaide viaide.sys Tue Aug 03 22:59:42 2004 (41107B4E)
    badc6000 badc7420 ASACPI ASACPI.sys Thu Aug 12 19:52:52 2004 (411C2D04)
    badde000 baddf100 swenum swenum.sys Tue Aug 03 22:58:41 2004 (41107B11)
    badf2000 badf3280 USBD USBD.SYS Fri Aug 17 14:02:58 2001 (3B7D8682)
    badf6000 badf7f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 13:49:37 2001 (3B7D8361)
    badfa000 badfb080 RDPCDD RDPCDD.sys Fri Aug 17 13:46:56 2001 (3B7D82C0)
    badfc000 badfd080 Beep Beep.SYS Fri Aug 17 13:47:33 2001 (3B7D82E5)
    badfe000 badff080 mnmdd mnmdd.SYS Fri Aug 17 13:57:28 2001 (3B7D8538)
    bae00000 bae01640 SYMDNS SYMDNS.SYS Fri Jan 21 21:56:20 2005 (41F1EB04)
    bae56000 bae57a80 ParVdm ParVdm.SYS Fri Aug 17 13:49:49 2001 (3B7D836D)
    bae70000 bae70d00 pciide pciide.sys Fri Aug 17 13:51:49 2001 (3B7D83E5)
    baee5000 baee5b80 msmpu401 msmpu401.sys Fri Aug 17 13:59:59 2001 (3B7D85CF)
    baee6000 baee6c00 audstub audstub.sys Fri Aug 17 13:59:40 2001 (3B7D85BC)
    baefe000 baefeb80 Null Null.SYS Fri Aug 17 13:47:39 2001 (3B7D82EB)
    bafba000 bafba7a0 symlcbrd symlcbrd.sys Tue Oct 15 23:50:27 2002 (3DAD0C33)
    baff2000 baff2d00 dxgthk dxgthk.sys Fri Aug 17 13:53:12 2001 (3B7D8438)
    bf800000 bf9c0500 win32k win32k.sys Tue Mar 01 17:06:42 2005 (422511A2)
    bf9c1000 bf9d2580 dxg dxg.sys Tue Aug 03 23:00:51 2004 (41107B93)
    bf9d3000 bfdc0380 nv4_disp nv4_disp.dll Thu Jan 27 00:42:39 2005 (41F8A97F)

    Unloaded modules:
    ad7fd000 ad827000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad7fd000 ad827000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad7fd000 ad827000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae027000 ae051000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae051000 ae062000 NAVENG.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae062000 ae0fb000 NavEx15.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae051000 ae062000 NAVENG.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae062000 ae0fb000 NavEx15.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b06e4000 b06f5000 NAVENG.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b06f5000 b078e000 NavEx15.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aec86000 aecb0000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    baea9000 baeaa000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    baa88000 baa95000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aecb0000 aecd3000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b96cc000 b96da000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bae5e000 bae60000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b42a4000 b42a9000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b4959000 b495c000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     

  3. to hide this advert.

  4. 2005/04/13
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Hi Spotta

    Analysing these dump files is a specialist task - unfortunately we have temporarily lost the services of the one member capable of doing this due to work commitments.

    However, there is always a clue .....

    From your first log Probably caused by :
    ntkrnlpa.exe would appear to be a worm. From your second log
    See this thead for something very similar - memory or driver.

    HTH - good luck!
     
  5. 2005/04/13
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    one foot out the door... im not gone yet, still lurkin around till i get these other dump threads closed out.

    ntkrnlpa.exe would appear to be a worm.
    There are some malware that use this as a disguise, but thats also the name of the "kernel" NTOSKRNL.EXE has become these four names, depending on uni/multiproc and pae. In this case, i would say we have no reason to be suspect of the file and can safely assume it is as it appears at face value.


    Spotta, if i was giving out Tshirts, you'd win one for posting a Stop 6. I've been looking at windows dumps since they shipped it back in `95, and I've never seen one of those. Accordingly, i have no idea what causes them. I'll have to look it up at work.
    heh.

    The StopA looks like memory corruption, specificly looks like a PTE went south. Have you run any mem testers against this new machine to make sure your subsystem is relitively stable?
     
  6. 2005/04/13
    debugnt

    debugnt Inactive

    Joined:
    2004/08/05
    Messages:
    13
    Likes Received:
    0
    This is a very interesting Stop message in that it should only occur if strange things are afoot like still having pending APC's during the detach process. But like my buddy Joe said, this is very rare. (If this stop can be reproduced it would interesting to dig in.)

    So the first think I would look for is to validate all of the structures and find where the machine didn't do what it was supposed to do which falls in line with suspected memory corruption and the stop A.

    However, I would beg the question on why the machine is running PAE in the first place. The machine will run with PAE enabled if it's a new fancy AMD with NX technology or it was configured to run PAE so you can take advantage of more than 4GB of memory which isn't too common - yet.

    So, as a another troubleshooting step, I would boot up with PAE disabled, by changing the boot.ini options and getting rid of /NOEXECUTE or taking out /PAE.

    Boot.ini explained.
    http://www.sysinternals.com/ntw2k/info/bootini.shtml

    Explanation of DEP and method to disable via the GUI
    http://support.microsoft.com/kb/875352

    Let us know how it goes and if that pesky Stop 6 just won't go away.

    Thanks,

    DebugNT
     
  7. 2005/04/13
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Hi

    PeteC.
    Thanks for the reply, I have ruled out a virus after three online scans and norton 2004 (installed) failed to find anything - I would have hoped they would have picked up a worm from 2003.

    JoeHobart
    Thank you for your reply, I'll let you know where to post the Tee!
    I have had two of these stop 6 INVALID_PROCESS_DETACH_ATTEMPT BSOD's now - one after the first installation and this one after a format (low level) and re-install.
    The Stop A error occured overnight while running Prime95 and I have run memtest86 and the MS memory test - both returning no fault...

    debugnt.
    - I have no idea what PAE is, but the machine is a new 64bit AMD (3000) fitted with 2Gb of Ram. I have taken your advice and removed the /NOEXECUTE from boot.ini - there was no mention of PAE.

    Can anyone suggest a good way of 'stressing' this machine in a way that might be able to either repeat the fault or see if these few tweaks have stopped it?

    Many thanks

    Spotta
     
  8. 2005/04/13
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Within 10 mins of running Prime95 I got this
    - Another error code I am unfamiliar with, I've googled it but am none the wiser as to the best place to start looking for the fault.


    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini041305-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 2600.xpsp_sp2_gdr.050301-1519
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Wed Apr 13 14:28:44.609 2005 (GMT-7)
    System Uptime: 0 days 0:09:19.203
    Loading Kernel Symbols
    .............................................................................................................................
    Loading unloaded module list
    ............
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 4E, {99, 41f00, 1, 0}

    Probably caused by : memory_corruption ( nt!MiDeletePte+43e )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PFN_LIST_CORRUPT (4e)
    Typically caused by drivers passing bad memory descriptor lists (ie: calling
    MmUnlockPages twice with the same list, etc). If a kernel debugger is
    available get the stack trace.
    Arguments:
    Arg1: 00000099, A PTE or PFN is corrupt
    Arg2: 00041f00, page frame number
    Arg3: 00000001, current page state
    Arg4: 00000000, 0

    Debugging Details:
    ------------------


    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x4E

    LAST_CONTROL_TRANSFER: from 8051eec2 to 804f8925

    STACK_TEXT:
    ad8c8b80 8051eec2 0000004e 00000099 00041f00 nt!KeBugCheckEx+0x1b
    ad8c8bc4 8051f090 c00b5770 16aee000 00000000 nt!MiDeletePte+0x43e
    ad8c8c88 80516641 000355f0 5ad0cfff 00000000 nt!MiDeleteVirtualAddresses+0x164
    ad8c8ca4 805a72ec 10030000 5ad0cfff ad8c8d64 nt!MiDeleteFreeVm+0x1d
    ad8c8d4c 8053c808 ffffffff 00ccfcec 00ccfd04 nt!NtFreeVirtualMemory+0x42e
    ad8c8d4c 7c90eb94 ffffffff 00ccfcec 00ccfd04 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00ccfc24 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    nt!MiDeletePte+43e
    8051eec2 8b5008 mov edx,[eax+0x8]

    SYMBOL_STACK_INDEX: 1

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!MiDeletePte+43e

    MODULE_NAME: nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 42250a1d

    STACK_COMMAND: kb

    IMAGE_NAME: memory_corruption

    FAILURE_BUCKET_ID: 0x4E_nt!MiDeletePte+43e

    BUCKET_ID: 0x4E_nt!MiDeletePte+43e

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00041f00 ecx=00000000 edx=817bc400 esi=817c1f1c edi=03ffffff
    eip=804f8925 esp=ad8c8b68 ebp=ad8c8b80 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x1b:
    804f8925 5d pop ebp
    ChildEBP RetAddr Args to Child
    ad8c8b80 8051eec2 0000004e 00000099 00041f00 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    ad8c8bc4 8051f090 c00b5770 16aee000 00000000 nt!MiDeletePte+0x43e (FPO: [Non-Fpo])
    ad8c8c88 80516641 000355f0 5ad0cfff 00000000 nt!MiDeleteVirtualAddresses+0x164 (FPO: [Non-Fpo])
    ad8c8ca4 805a72ec 10030000 5ad0cfff ad8c8d64 nt!MiDeleteFreeVm+0x1d (FPO: [Non-Fpo])
    ad8c8d4c 8053c808 ffffffff 00ccfcec 00ccfd04 nt!NtFreeVirtualMemory+0x42e (FPO: [Non-Fpo])
    ad8c8d4c 7c90eb94 ffffffff 00ccfcec 00ccfd04 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ ad8c8d64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00ccfc24 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Tue Mar 01 16:34:37 2005 (42250A1D)
    806ce000 806ee380 hal halaacpi.dll Tue Aug 03 22:59:05 2004 (41107B29)
    ad673000 ad69cf00 kmixer kmixer.sys Tue Aug 03 23:07:46 2004 (41107D32)
    ad69d000 ad6ad960 NAVENG NAVENG.Sys Thu Dec 30 13:46:10 2004 (41D47722)
    ad6ae000 ad746a60 NavEx15 NavEx15.Sys Thu Dec 30 13:45:19 2004 (41D476EF)
    adbd1000 adc11100 HTTP HTTP.sys Fri Oct 08 16:48:20 2004 (41672744)
    adeea000 adef26e0 NPDRIVER NPDRIVER.SYS Tue Aug 13 23:39:06 2002 (3D59FB0A)
    ae072000 ae0c4180 srv srv.sys Tue Aug 03 23:14:44 2004 (41107ED4)
    ae115000 ae141400 mrxdav mrxdav.sys Tue Aug 03 23:00:49 2004 (41107B91)
    ae22f000 ae243400 wdmaud wdmaud.sys Tue Aug 03 23:15:03 2004 (41107EE7)
    ae384000 ae3a7000 Fastfat Fastfat.SYS Tue Aug 03 23:14:15 2004 (41107EB7)
    afac8000 afae8f00 ipnat ipnat.sys Wed Sep 29 15:28:36 2004 (415B3714)
    afae9000 afb57400 mrxsmb mrxsmb.sys Tue Jan 18 20:26:50 2005 (41EDE18A)
    afb58000 afb82a00 rdbss rdbss.sys Wed Oct 27 18:13:57 2004 (418047D5)
    afb83000 afba4d00 afd afd.sys Tue Aug 03 23:14:13 2004 (41107EB5)
    afba5000 afbccc00 netbt netbt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    afbcd000 afc13460 symidsco symidsco.sys Thu Mar 03 18:55:44 2005 (4227CE30)
    afc14000 afc3c9e0 SYMFW SYMFW.SYS Fri Jan 21 21:57:51 2005 (41F1EB5F)
    afc3d000 afc7cda0 SYMTDI SYMTDI.SYS Fri Jan 21 21:55:40 2005 (41F1EADC)
    afc7d000 afcd4d80 tcpip tcpip.sys Sun Mar 13 16:55:05 2005 (4234E0E9)
    afcd5000 afce7400 ipsec ipsec.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    affcf000 affd1900 Dxapi Dxapi.sys Fri Aug 17 13:53:19 2001 (3B7D843F)
    affe7000 affea780 dump_scsiport dump_scsiport.sys Tue Aug 03 22:59:51 2004 (41107B57)
    b0059000 b005d500 watchdog watchdog.sys Tue Aug 03 23:07:32 2004 (41107D24)
    b033c000 b034ad00 dump_viamraid dump_viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    b034c000 b035b900 Cdfs Cdfs.SYS Tue Aug 03 23:14:09 2004 (41107EB1)
    b03bc000 b03cad80 arp1394 arp1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    b04f9000 b05001e0 SYMIDS SYMIDS.SYS Fri Jan 21 21:59:16 2005 (41F1EBB4)
    b0501000 b0506060 SYMREDRV SYMREDRV.SYS Fri Jan 21 21:58:32 2005 (41F1EB88)
    b0509000 b0510880 Npfs Npfs.SYS Tue Aug 03 23:00:38 2004 (41107B86)
    b0511000 b0515a80 Msfs Msfs.SYS Tue Aug 03 23:00:37 2004 (41107B85)
    b0519000 b051e200 vga vga.sys Tue Aug 03 23:07:06 2004 (41107D0A)
    b0587000 b0587b80 Null Null.SYS Fri Aug 17 13:47:39 2001 (3B7D82EB)
    b0635000 b063d700 netbios netbios.sys Tue Aug 03 23:03:19 2004 (41107C27)
    b0665000 b066f000 SYMNDIS SYMNDIS.SYS Fri Jan 21 21:57:07 2005 (41F1EB33)
    b087c000 b087da80 ParVdm ParVdm.SYS Fri Aug 17 13:49:49 2001 (3B7D836D)
    b2d9a000 b2da2880 Fips Fips.SYS Fri Aug 17 18:31:49 2001 (3B7DC585)
    b3089000 b3097d80 sysaudio sysaudio.sys Tue Aug 03 23:15:54 2004 (41107F1A)
    b3423000 b343ca80 SYMEVENT SYMEVENT.SYS Tue Oct 19 14:18:08 2004 (41758490)
    b343d000 b348d000 SAVRT SAVRT.SYS Tue Jan 25 21:38:55 2005 (41F72CEF)
    b3491000 b3494280 ndisuio ndisuio.sys Tue Aug 03 23:03:10 2004 (41107C1E)
    b464f000 b465f000 SAVRTPEL SAVRTPEL.SYS Tue Jan 25 21:38:57 2005 (41F72CF1)
    b76f5000 b7728200 update update.sys Tue Aug 03 22:58:32 2004 (41107B08)
    b77d0000 b77d5000 flpydisk flpydisk.sys Tue Aug 03 22:59:24 2004 (41107B3C)
    b7808000 b7816100 usbhub usbhub.sys Tue Aug 03 23:08:40 2004 (41107D68)
    b7888000 b7891480 NDProxy NDProxy.SYS Fri Aug 17 13:55:30 2001 (3B7D84C2)
    b7f83000 b7f8cf00 termdd termdd.sys Tue Aug 03 22:58:52 2004 (41107B1C)
    b7ff3000 b7ff7080 raspti raspti.sys Fri Aug 17 13:55:32 2001 (3B7D84C4)
    b7ffb000 b7fff580 ptilink ptilink.sys Fri Aug 17 13:49:53 2001 (3B7D8371)
    b807d000 b807f280 rasacd rasacd.sys Fri Aug 17 13:55:39 2001 (3B7D84CB)
    b90a4000 b90b4e00 psched psched.sys Tue Aug 03 23:04:16 2004 (41107C60)
    b90b5000 b90cb680 ndiswan ndiswan.sys Tue Aug 03 23:14:30 2004 (41107EC6)
    b90f0000 b9103900 parport parport.sys Tue Aug 03 22:59:04 2004 (41107B28)
    b9104000 b9127980 portcls portcls.sys Tue Aug 03 23:15:47 2004 (41107F13)
    b913f000 b936cd40 ALCXWDM ALCXWDM.SYS Tue Oct 26 22:57:33 2004 (417F38CD)
    b93a9000 b93cbe80 USBPORT USBPORT.SYS Tue Aug 03 23:08:34 2004 (41107D62)
    b93e2000 b9404680 ks ks.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    b9405000 b9450d80 mrv8ka51 mrv8ka51.sys Wed Jan 05 19:18:38 2005 (41DCAE0E)
    b9451000 b9487b00 yk51x86 yk51x86.sys Thu Nov 25 23:42:27 2004 (41A6DE63)
    b9488000 b949b780 VIDEOPRT VIDEOPRT.SYS Tue Aug 03 23:07:04 2004 (41107D08)
    b949c000 b97dbe40 nv4_mini nv4_mini.sys Thu Jan 27 00:47:35 2005 (41F8AAA7)
    b9903000 b990f880 rasl2tp rasl2tp.sys Tue Aug 03 23:14:21 2004 (41107EBD)
    b9913000 b991fe00 i8042prt i8042prt.sys Tue Aug 03 23:14:36 2004 (41107ECC)
    b9923000 b9932d80 serial serial.sys Tue Aug 03 23:15:51 2004 (41107F17)
    b9933000 b9941b80 drmk drmk.sys Tue Aug 03 23:07:54 2004 (41107D3A)
    b9953000 b9961080 redbook redbook.sys Tue Aug 03 22:59:34 2004 (41107B46)
    b9963000 b996f180 cdrom cdrom.sys Tue Aug 03 22:59:52 2004 (41107B58)
    b9973000 b997d380 imapi imapi.sys Tue Aug 03 23:00:12 2004 (41107B6C)
    b9ac1000 b9ac9a00 processr processr.sys Tue Aug 03 22:59:14 2004 (41107B32)
    ba5d0000 ba5d2580 ndistapi ndistapi.sys Fri Aug 17 13:55:29 2001 (3B7D84C1)
    ba5d4000 ba5d6980 gameenum gameenum.sys Tue Aug 03 23:08:20 2004 (41107D54)
    ba5d8000 ba5dbc80 serenum serenum.sys Tue Aug 03 22:59:06 2004 (41107B2A)
    ba5fc000 ba616580 Mup Mup.sys Tue Aug 03 23:15:20 2004 (41107EF8)
    ba617000 ba643a80 NDIS NDIS.sys Tue Aug 03 23:14:27 2004 (41107EC3)
    ba644000 ba6d0480 Ntfs Ntfs.sys Tue Aug 03 23:15:06 2004 (41107EEA)
    ba6d1000 ba6e7780 KSecDD KSecDD.sys Tue Aug 03 22:59:45 2004 (41107B51)
    ba6e8000 ba6f9f00 sr sr.sys Tue Aug 03 23:06:22 2004 (41107CDE)
    ba6fa000 ba718780 fltMgr fltMgr.sys Tue Aug 03 23:01:17 2004 (41107BAD)
    ba719000 ba730800 SCSIPORT SCSIPORT.SYS Tue Aug 03 22:59:39 2004 (41107B4B)
    ba731000 ba748480 atapi atapi.sys Tue Aug 03 22:59:41 2004 (41107B4D)
    ba749000 ba767880 ftdisk ftdisk.sys Fri Aug 17 13:52:41 2001 (3B7D8419)
    ba768000 ba778a80 pci pci.sys Tue Aug 03 23:07:45 2004 (41107D31)
    ba779000 ba7a6d80 ACPI ACPI.sys Tue Aug 03 23:07:35 2004 (41107D27)
    ba8a8000 ba8b0c00 isapnp isapnp.sys Fri Aug 17 13:58:01 2001 (3B7D8559)
    ba8b8000 ba8c6e80 ohci1394 ohci1394.sys Tue Aug 03 23:10:05 2004 (41107DBD)
    ba8c8000 ba8d5000 1394BUS 1394BUS.SYS Tue Aug 03 23:10:03 2004 (41107DBB)
    ba8d8000 ba8e2500 MountMgr MountMgr.sys Tue Aug 03 22:58:29 2004 (41107B05)
    ba8e8000 ba8f4c80 VolSnap VolSnap.sys Tue Aug 03 23:00:14 2004 (41107B6E)
    ba8f8000 ba906d00 viamraid viamraid.sys Sun Jul 04 18:52:59 2004 (40E8B47B)
    ba908000 ba910e00 disk disk.sys Tue Aug 03 22:59:53 2004 (41107B59)
    ba918000 ba924200 CLASSPNP CLASSPNP.SYS Tue Aug 03 23:14:26 2004 (41107EC2)
    ba928000 ba933580 gagp30kx gagp30kx.sys Tue Aug 03 23:07:43 2004 (41107D2F)
    ba978000 ba980700 wanarp wanarp.sys Tue Aug 03 23:04:57 2004 (41107C89)
    ba9c8000 ba9d2200 raspppoe raspppoe.sys Tue Aug 03 23:05:06 2004 (41107C92)
    ba9e8000 ba9f3d00 raspptp raspptp.sys Tue Aug 03 23:14:26 2004 (41107EC2)
    ba9f8000 baa00900 msgpc msgpc.sys Tue Aug 03 23:04:11 2004 (41107C5B)
    baa48000 baa57180 nic1394 nic1394.sys Tue Aug 03 22:58:28 2004 (41107B04)
    bab28000 bab2e200 PCIIDEX PCIIDEX.SYS Tue Aug 03 22:59:40 2004 (41107B4C)
    bab30000 bab34900 PartMgr PartMgr.sys Fri Aug 17 18:32:23 2001 (3B7DC5A7)
    babf8000 babfd000 usbuhci usbuhci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    bac08000 bac0e800 usbehci usbehci.sys Tue Aug 03 23:08:34 2004 (41107D62)
    bac10000 bac11000 fdc fdc.sys unavailable (00000000)
    bac18000 bac1da00 mouclass mouclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    bac28000 bac2e000 kbdclass kbdclass.sys Tue Aug 03 22:58:32 2004 (41107B08)
    baca0000 baca4880 TDI TDI.SYS Tue Aug 03 23:07:47 2004 (41107D33)
    bacb8000 bacbb000 BOOTVID BOOTVID.dll Fri Aug 17 13:49:09 2001 (3B7D8345)
    bad98000 bad9bc80 mssmbios mssmbios.sys Tue Aug 03 23:07:47 2004 (41107D33)
    bada8000 bada9b80 kdcom kdcom.dll Fri Aug 17 13:49:10 2001 (3B7D8346)
    badaa000 badab100 WMILIB WMILIB.SYS Fri Aug 17 14:07:23 2001 (3B7D878B)
    badac000 badad500 viaide viaide.sys Tue Aug 03 22:59:42 2004 (41107B4E)
    badc6000 badc7420 ASACPI ASACPI.sys Thu Aug 12 19:52:52 2004 (411C2D04)
    bade0000 bade1100 swenum swenum.sys Tue Aug 03 22:58:41 2004 (41107B11)
    badee000 badef280 USBD USBD.SYS Fri Aug 17 14:02:58 2001 (3B7D8682)
    bae34000 bae35080 RDPCDD RDPCDD.sys Fri Aug 17 13:46:56 2001 (3B7D82C0)
    bae36000 bae37f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 13:49:37 2001 (3B7D8361)
    bae38000 bae39080 Beep Beep.SYS Fri Aug 17 13:47:33 2001 (3B7D82E5)
    bae3a000 bae3b080 mnmdd mnmdd.SYS Fri Aug 17 13:57:28 2001 (3B7D8538)
    bae3c000 bae3d640 SYMDNS SYMDNS.SYS Fri Jan 21 21:56:20 2005 (41F1EB04)
    bae70000 bae70d00 pciide pciide.sys Fri Aug 17 13:51:49 2001 (3B7D83E5)
    baeb9000 baeb9b80 msmpu401 msmpu401.sys Fri Aug 17 13:59:59 2001 (3B7D85CF)
    baeba000 baebac00 audstub audstub.sys Fri Aug 17 13:59:40 2001 (3B7D85BC)
    baf0f000 baf0f7a0 symlcbrd symlcbrd.sys Tue Oct 15 23:50:27 2002 (3DAD0C33)
    bafaf000 bafafd00 dxgthk dxgthk.sys Fri Aug 17 13:53:12 2001 (3B7D8438)
    bf800000 bf9c0500 win32k win32k.sys Tue Mar 01 17:06:42 2005 (422511A2)
    bf9c1000 bf9d2580 dxg dxg.sys Tue Aug 03 23:00:51 2004 (41107B93)
    bf9d3000 bfdc0380 nv4_disp nv4_disp.dll Thu Jan 27 00:42:39 2005 (41F8A97F)

    Unloaded modules:
    ad673000 ad69d000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    afd08000 afd19000 NAVENG.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    afd19000 afdb2000 NavEx15.Sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad76f000 ad799000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae1e2000 ae20c000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b10a3000 b10a4000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b83d0000 b83dd000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae20c000 ae22f000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8fc0000 b8fce000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b0886000 b0888000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b0521000 b0526000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b54d2000 b54d5000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  9. 2005/04/14
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Stop 0x00000006 dump data

    Carrying in on from here.

    Admin: Should have been posted to that same thread... merging - Sorry :)

    Reformated hard drive

    performed clean install of Win XP home -
    no additional drivers installed
    Within 30 mins BSOD

    dump data below
    The machine is not yet online - hence symbols problem
    would it helpful to get it online and re-run debugwiz?

    Many thanks

    Spotta


    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini041405-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Thu Apr 14 13:42:46.765 2005 (GMT+1)
    System Uptime: 0 days 0:27:45.359
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Loading Kernel Symbols
    ...............................................................................................
    Loading unloaded module list
    ....
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 6, {0, 0, 0, 0}

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    INVALID_PROCESS_DETACH_ATTEMPT (6)
    Arguments:
    Arg1: 00000000
    Arg2: 00000000
    Arg3: 00000000
    Arg4: 00000000

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    MODULE_NAME: nt

    FAULTING_MODULE: 804d7000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107b0c

    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x6

    LAST_CONTROL_TRANSFER: from 804f73d9 to 804f8900

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b9b96bb0 804f73d9 00000006 89948660 7ffdb000 nt!KeBugCheck+0x14
    b9b96bd8 805c41df b9b96bf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d
    b9b96c34 805c07fd 89948660 00000000 b9b96d64 nt!PsAssignImpersonationToken+0x123
    b9b96d4c 8053c808 fffffffe 00000005 00eafce4 nt!NtSetInformationThread+0x207
    b9b96d64 7c90eb94 badb0d00 00eafcd4 002257d5 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    00eafce8 00000000 00000000 00000000 00000000 0x7c90eb94


    STACK_COMMAND: .bugcheck ; kb

    FOLLOWUP_NAME: MachineOwner

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00000000 ecx=00000000 edx=00000000 esi=89948660 edi=89948660
    eip=804f8900 esp=b9b96b98 ebp=b9b96bb0 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheck+0x14:
    804f8900 5d pop ebp
    ChildEBP RetAddr Args to Child
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b9b96bb0 804f73d9 00000006 89948660 7ffdb000 nt!KeBugCheck+0x14
    b9b96bd8 805c41df b9b96bf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d
    b9b96c34 805c07fd 89948660 00000000 b9b96d64 nt!PsAssignImpersonationToken+0x123
    b9b96d4c 8053c808 fffffffe 00000005 00eafce4 nt!NtSetInformationThread+0x207
    b9b96d64 7c90eb94 badb0d00 00eafcd4 002257d5 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    00eafce8 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Wed Aug 04 06:58:36 2004 (41107B0C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 06:59:05 2004 (41107B29)
    b96f6000 b9736380 HTTP HTTP.sys Wed Aug 04 07:00:09 2004 (41107B69)
    b99df000 b9a31180 srv srv.sys Wed Aug 04 07:14:44 2004 (41107ED4)
    b9a82000 b9aae400 mrxdav mrxdav.sys Wed Aug 04 07:00:49 2004 (41107B91)
    b9d13000 b9d16280 ndisuio ndisuio.sys Wed Aug 04 07:03:10 2004 (41107C1E)
    ba21f000 ba236480 dump_atapi dump_atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    ba237000 ba257f00 ipnat ipnat.sys Wed Aug 04 07:04:48 2004 (41107C80)
    ba258000 ba2c6380 mrxsmb mrxsmb.sys Wed Aug 04 07:15:14 2004 (41107EF2)
    ba2ef000 ba31a180 rdbss rdbss.sys Wed Aug 04 07:20:05 2004 (41108015)
    ba31b000 ba33cd00 afd afd.sys Wed Aug 04 07:14:13 2004 (41107EB5)
    ba33d000 ba364c00 netbt netbt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    ba365000 ba3bca80 tcpip tcpip.sys Wed Aug 04 07:14:39 2004 (41107ECF)
    ba3bd000 ba3cf400 ipsec ipsec.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    ba3f0000 ba403780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 07:07:04 2004 (41107D08)
    ba43d000 ba470200 update update.sys Wed Aug 04 06:58:32 2004 (41107B08)
    ba533000 ba543e00 psched psched.sys Wed Aug 04 07:04:16 2004 (41107C60)
    ba544000 ba55a680 ndiswan ndiswan.sys Wed Aug 04 07:14:30 2004 (41107EC6)
    ba55b000 ba56e900 parport parport.sys Wed Aug 04 06:59:04 2004 (41107B28)
    ba56f000 ba591e80 USBPORT USBPORT.SYS Wed Aug 04 07:08:34 2004 (41107D62)
    ba592000 ba5b4680 ks ks.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    ba5ec000 ba5ee280 rasacd rasacd.sys Fri Aug 17 21:55:39 2001 (3B7D84CB)
    ba614000 ba62e580 Mup Mup.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    ba62f000 ba65ba80 NDIS NDIS.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    ba65c000 ba6e8480 Ntfs Ntfs.sys Wed Aug 04 07:15:06 2004 (41107EEA)
    ba6e9000 ba6ff780 KSecDD KSecDD.sys Wed Aug 04 06:59:45 2004 (41107B51)
    ba700000 ba711f00 sr sr.sys Wed Aug 04 07:06:22 2004 (41107CDE)
    ba712000 ba730780 fltMgr fltMgr.sys Wed Aug 04 07:01:17 2004 (41107BAD)
    ba731000 ba748480 atapi atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    ba749000 ba767880 ftdisk ftdisk.sys Fri Aug 17 21:52:41 2001 (3B7D8419)
    ba768000 ba778a80 pci pci.sys Wed Aug 04 07:07:45 2004 (41107D31)
    ba779000 ba7a6d80 ACPI ACPI.sys Wed Aug 04 07:07:35 2004 (41107D27)
    ba8a8000 ba8b0c00 isapnp isapnp.sys Fri Aug 17 21:58:01 2001 (3B7D8559)
    ba8b8000 ba8c6e80 ohci1394 ohci1394.sys Wed Aug 04 07:10:05 2004 (41107DBD)
    ba8c8000 ba8d5000 1394BUS 1394BUS.SYS Wed Aug 04 07:10:03 2004 (41107DBB)
    ba8d8000 ba8e2500 MountMgr MountMgr.sys Wed Aug 04 06:58:29 2004 (41107B05)
    ba8e8000 ba8f4c80 VolSnap VolSnap.sys Wed Aug 04 07:00:14 2004 (41107B6E)
    ba8f8000 ba900e00 disk disk.sys Wed Aug 04 06:59:53 2004 (41107B59)
    ba908000 ba914200 CLASSPNP CLASSPNP.SYS Wed Aug 04 07:14:26 2004 (41107EC2)
    ba918000 ba923580 gagp30kx gagp30kx.sys Wed Aug 04 07:07:43 2004 (41107D2F)
    ba948000 ba950900 msgpc msgpc.sys Wed Aug 04 07:04:11 2004 (41107C5B)
    ba958000 ba961f00 termdd termdd.sys Wed Aug 04 06:58:52 2004 (41107B1C)
    ba968000 ba971480 NDProxy NDProxy.SYS Fri Aug 17 21:55:30 2001 (3B7D84C2)
    ba978000 ba986100 usbhub usbhub.sys Wed Aug 04 07:08:40 2004 (41107D68)
    ba988000 ba990700 netbios netbios.sys Wed Aug 04 07:03:19 2004 (41107C27)
    ba998000 ba9a0880 Fips Fips.SYS Sat Aug 18 02:31:49 2001 (3B7DC585)
    ba9a8000 ba9b0700 wanarp wanarp.sys Wed Aug 04 07:04:57 2004 (41107C89)
    ba9b8000 ba9c6d80 arp1394 arp1394.sys Wed Aug 04 06:58:28 2004 (41107B04)
    ba9d8000 ba9e7900 Cdfs Cdfs.SYS Wed Aug 04 07:14:09 2004 (41107EB1)
    baa78000 baa87180 nic1394 nic1394.sys Wed Aug 04 06:58:28 2004 (41107B04)
    baa98000 baaa0a00 processr processr.sys Wed Aug 04 06:59:14 2004 (41107B32)
    baaa8000 baab2380 imapi imapi.sys Wed Aug 04 07:00:12 2004 (41107B6C)
    baab8000 baac4180 cdrom cdrom.sys Wed Aug 04 06:59:52 2004 (41107B58)
    baac8000 baad6080 redbook redbook.sys Wed Aug 04 06:59:34 2004 (41107B46)
    baad8000 baae7d80 serial serial.sys Wed Aug 04 07:15:51 2004 (41107F17)
    baae8000 baaf4e00 i8042prt i8042prt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    baaf8000 bab04880 rasl2tp rasl2tp.sys Wed Aug 04 07:14:21 2004 (41107EBD)
    bab08000 bab12200 raspppoe raspppoe.sys Wed Aug 04 07:05:06 2004 (41107C92)
    bab18000 bab23d00 raspptp raspptp.sys Wed Aug 04 07:14:26 2004 (41107EC2)
    bab28000 bab2e200 PCIIDEX PCIIDEX.SYS Wed Aug 04 06:59:40 2004 (41107B4C)
    bab30000 bab34900 PartMgr PartMgr.sys Sat Aug 18 02:32:23 2001 (3B7DC5A7)
    bab80000 bab85000 usbuhci usbuhci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    bab88000 bab8e800 usbehci usbehci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    bab90000 bab95a00 mouclass mouclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    bab98000 bab9e000 kbdclass kbdclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    baba0000 baba4880 TDI TDI.SYS Wed Aug 04 07:07:47 2004 (41107D33)
    baba8000 babac580 ptilink ptilink.sys Fri Aug 17 21:49:53 2001 (3B7D8371)
    babb0000 babb4080 raspti raspti.sys Fri Aug 17 21:55:32 2001 (3B7D84C4)
    babd0000 babd5200 vga vga.sys Wed Aug 04 07:07:06 2004 (41107D0A)
    babd8000 babdca80 Msfs Msfs.SYS Wed Aug 04 07:00:37 2004 (41107B85)
    babe0000 babe7880 Npfs Npfs.SYS Wed Aug 04 07:00:38 2004 (41107B86)
    babf8000 babfc500 watchdog watchdog.sys Wed Aug 04 07:07:32 2004 (41107D24)
    bacb8000 bacbb000 BOOTVID BOOTVID.dll Fri Aug 17 21:49:09 2001 (3B7D8345)
    bad44000 bad46900 Dxapi Dxapi.sys Fri Aug 17 21:53:19 2001 (3B7D843F)
    bad68000 bad6bc80 serenum serenum.sys Wed Aug 04 06:59:06 2004 (41107B2A)
    bad6c000 bad6e980 gameenum gameenum.sys Wed Aug 04 07:08:20 2004 (41107D54)
    bad70000 bad72580 ndistapi ndistapi.sys Fri Aug 17 21:55:29 2001 (3B7D84C1)
    bad80000 bad83c80 mssmbios mssmbios.sys Wed Aug 04 07:07:47 2004 (41107D33)
    bada8000 bada9b80 kdcom kdcom.dll Fri Aug 17 21:49:10 2001 (3B7D8346)
    badaa000 badab100 WMILIB WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    badac000 badad500 viaide viaide.sys Wed Aug 04 06:59:42 2004 (41107B4E)
    badb4000 badb5100 swenum swenum.sys Wed Aug 04 06:58:41 2004 (41107B11)
    badb6000 badb7280 USBD USBD.SYS Fri Aug 17 22:02:58 2001 (3B7D8682)
    badb8000 badb9f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 21:49:37 2001 (3B7D8361)
    badba000 badbb080 Beep Beep.SYS Fri Aug 17 21:47:33 2001 (3B7D82E5)
    badbc000 badbd080 mnmdd mnmdd.SYS Fri Aug 17 21:57:28 2001 (3B7D8538)
    badbe000 badbf080 RDPCDD RDPCDD.sys Fri Aug 17 21:46:56 2001 (3B7D82C0)
    badc0000 badc1100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    badda000 baddba80 ParVdm ParVdm.SYS Fri Aug 17 21:49:49 2001 (3B7D836D)
    bae70000 bae70d00 pciide pciide.sys Fri Aug 17 21:51:49 2001 (3B7D83E5)
    baea3000 baea3d00 dxgthk dxgthk.sys Fri Aug 17 21:53:12 2001 (3B7D8438)
    baf58000 baf58c00 audstub audstub.sys Fri Aug 17 21:59:40 2001 (3B7D85BC)
    bafd2000 bafd2b80 Null Null.SYS Fri Aug 17 21:47:39 2001 (3B7D82EB)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 07:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 07:00:51 2004 (41107B93)
    bff50000 bff52480 framebuf framebuf.dll Wed Aug 04 08:56:31 2004 (411096AF)

    Unloaded modules:
    babc8000 babcd000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba5f0000 ba5f3000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    babc0000 babc5000 Flpydisk.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    babb8000 babbf000 Fdc.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
    Last edited: 2005/04/14
  10. 2005/04/14
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    Will need to research it. no need to rerun the wiz.
     
  11. 2005/04/14
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Many thanks

    Spotta
     
  12. 2005/04/14
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Another one - if it helps


    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini041405-03.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
    Debug session time: Thu Apr 14 21:25:06.875 2005 (GMT+1)
    System Uptime: 0 days 1:20:53.468
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlpa.exe -
    Loading Kernel Symbols
    ...................................................................................................................
    Loading unloaded module list
    ......
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 6, {0, 0, 0, 0}

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *** ERROR: Module load completed but symbols could not be loaded for mssmbios.sys

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    INVALID_PROCESS_DETACH_ATTEMPT (6)
    Arguments:
    Arg1: 00000000
    Arg2: 00000000
    Arg3: 00000000
    Arg4: 00000000

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.


    MODULE_NAME: nt

    FAULTING_MODULE: 804d7000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107b0c

    CUSTOMER_CRASH_COUNT: 3

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x6

    LAST_CONTROL_TRANSFER: from 804f73d9 to 804f8900

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b9950bb0 804f73d9 00000006 893c9da8 7ffaf000 nt!KeBugCheck+0x14
    b9950bd8 805c41df b9950bf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d
    b9950c34 805c07fd 893c9da8 00000000 b9950d64 nt!PsAssignImpersonationToken+0x123
    b9950d4c 8053c808 fffffffe 00000005 008cfcdc nt!NtSetInformationThread+0x207
    b9950d64 7c90eb94 badb0d00 008cfccc b9950d98 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    008cfce0 00000000 00000000 00000000 00000000 0x7c90eb94


    STACK_COMMAND: .bugcheck ; kb

    FOLLOWUP_NAME: MachineOwner

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00000000 ecx=00000000 edx=00000000 esi=893c9da8 edi=893c9da8
    eip=804f8900 esp=b9950b98 ebp=b9950bb0 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheck+0x14:
    804f8900 5d pop ebp
    ChildEBP RetAddr Args to Child
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b9950bb0 804f73d9 00000006 893c9da8 7ffaf000 nt!KeBugCheck+0x14
    b9950bd8 805c41df b9950bf0 00000002 00000000 nt!KeUnstackDetachProcess+0x10d
    b9950c34 805c07fd 893c9da8 00000000 b9950d64 nt!PsAssignImpersonationToken+0x123
    b9950d4c 8053c808 fffffffe 00000005 008cfcdc nt!NtSetInformationThread+0x207
    b9950d64 7c90eb94 badb0d00 008cfccc b9950d98 nt!KeReleaseInStackQueuedSpinLockFromDpcLevel+0xb14
    008cfce0 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806cd280 nt ntkrnlpa.exe Wed Aug 04 06:58:36 2004 (41107B0C)
    806ce000 806ee380 hal halaacpi.dll Wed Aug 04 06:59:05 2004 (41107B29)
    b8973000 b8983980 NAVENG NAVENG.Sys Tue Mar 15 20:35:44 2005 (42374720)
    b8984000 b8a1ce20 NavEx15 NavEx15.Sys Tue Mar 15 20:51:30 2005 (42374AD2)
    b8b35000 b8b75380 HTTP HTTP.sys Wed Aug 04 07:00:09 2004 (41107B69)
    b936e000 b93c0180 srv srv.sys Wed Aug 04 07:14:44 2004 (41107ED4)
    b9411000 b943d400 mrxdav mrxdav.sys Wed Aug 04 07:00:49 2004 (41107B91)
    b95ae000 b95b66e0 NPDRIVER NPDRIVER.SYS Wed Aug 14 07:39:06 2002 (3D59FB0A)
    b975e000 b9781000 Fastfat Fastfat.SYS Wed Aug 04 07:14:15 2004 (41107EB7)
    b9911000 b9914280 ndisuio ndisuio.sys Wed Aug 04 07:03:10 2004 (41107C1E)
    b9e29000 b9e40480 dump_atapi dump_atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    b9e41000 b9e61f00 ipnat ipnat.sys Wed Aug 04 07:04:48 2004 (41107C80)
    b9e62000 b9ed0380 mrxsmb mrxsmb.sys Wed Aug 04 07:15:14 2004 (41107EF2)
    b9ed1000 b9efc180 rdbss rdbss.sys Wed Aug 04 07:20:05 2004 (41108015)
    b9efd000 b9f1ed00 afd afd.sys Wed Aug 04 07:14:13 2004 (41107EB5)
    b9f1f000 b9f46c00 netbt netbt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    b9f47000 b9f63c60 SYMIDSCO SYMIDSCO.SYS Mon Sep 01 05:20:11 2003 (3F52C8FB)
    ba004000 ba02adc0 SYMFW SYMFW.SYS Mon Sep 01 05:19:55 2003 (3F52C8EB)
    ba02b000 ba069f40 SYMTDI SYMTDI.SYS Mon Sep 01 05:19:41 2003 (3F52C8DD)
    ba092000 ba0e9a80 tcpip tcpip.sys Wed Aug 04 07:14:39 2004 (41107ECF)
    ba0ea000 ba0fc400 ipsec ipsec.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    ba11d000 ba130780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 07:07:04 2004 (41107D08)
    ba1b2000 ba1c4c20 SYMEVENT SYMEVENT.SYS Thu Aug 07 02:32:39 2003 (3F31AC37)
    ba1c5000 ba213000 SAVRT SAVRT.SYS Tue Aug 05 04:40:55 2003 (3F2F2747)
    ba213000 ba246200 update update.sys Wed Aug 04 06:58:32 2004 (41107B08)
    ba267000 ba269900 Dxapi Dxapi.sys Fri Aug 17 21:53:19 2001 (3B7D843F)
    ba26f000 ba27fe00 psched psched.sys Wed Aug 04 07:04:16 2004 (41107C60)
    ba280000 ba296680 ndiswan ndiswan.sys Wed Aug 04 07:14:30 2004 (41107EC6)
    ba317000 ba326900 Cdfs Cdfs.SYS Wed Aug 04 07:14:09 2004 (41107EB1)
    ba337000 ba34a900 parport parport.sys Wed Aug 04 06:59:04 2004 (41107B28)
    ba34b000 ba36de80 USBPORT USBPORT.SYS Wed Aug 04 07:08:34 2004 (41107D62)
    ba36e000 ba390680 ks ks.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    ba391000 ba3d0200 mrv8ka51 mrv8ka51.sys Thu May 20 12:47:20 2004 (40AC9AC8)
    ba571000 ba59d100 yk51x86 yk51x86.sys Wed Jun 16 14:45:16 2004 (40D04EEC)
    ba614000 ba62e580 Mup Mup.sys Wed Aug 04 07:15:20 2004 (41107EF8)
    ba62f000 ba65ba80 NDIS NDIS.sys Wed Aug 04 07:14:27 2004 (41107EC3)
    ba65c000 ba6e8480 Ntfs Ntfs.sys Wed Aug 04 07:15:06 2004 (41107EEA)
    ba6e9000 ba6ff780 KSecDD KSecDD.sys Wed Aug 04 06:59:45 2004 (41107B51)
    ba700000 ba711f00 sr sr.sys Wed Aug 04 07:06:22 2004 (41107CDE)
    ba712000 ba730780 fltMgr fltMgr.sys Wed Aug 04 07:01:17 2004 (41107BAD)
    ba731000 ba748480 atapi atapi.sys Wed Aug 04 06:59:41 2004 (41107B4D)
    ba749000 ba767880 ftdisk ftdisk.sys Fri Aug 17 21:52:41 2001 (3B7D8419)
    ba768000 ba778a80 pci pci.sys Wed Aug 04 07:07:45 2004 (41107D31)
    ba779000 ba7a6d80 ACPI ACPI.sys Wed Aug 04 07:07:35 2004 (41107D27)
    ba8a8000 ba8b0c00 isapnp isapnp.sys Fri Aug 17 21:58:01 2001 (3B7D8559)
    ba8b8000 ba8c6e80 ohci1394 ohci1394.sys Wed Aug 04 07:10:05 2004 (41107DBD)
    ba8c8000 ba8d5000 1394BUS 1394BUS.SYS Wed Aug 04 07:10:03 2004 (41107DBB)
    ba8d8000 ba8e2500 MountMgr MountMgr.sys Wed Aug 04 06:58:29 2004 (41107B05)
    ba8e8000 ba8f4c80 VolSnap VolSnap.sys Wed Aug 04 07:00:14 2004 (41107B6E)
    ba8f8000 ba900e00 disk disk.sys Wed Aug 04 06:59:53 2004 (41107B59)
    ba908000 ba914200 CLASSPNP CLASSPNP.SYS Wed Aug 04 07:14:26 2004 (41107EC2)
    ba918000 ba923580 gagp30kx gagp30kx.sys Wed Aug 04 07:07:43 2004 (41107D2F)
    ba948000 ba950880 Fips Fips.SYS Sat Aug 18 02:31:49 2001 (3B7DC585)
    ba958000 ba960700 wanarp wanarp.sys Wed Aug 04 07:04:57 2004 (41107C89)
    ba968000 ba976d80 arp1394 arp1394.sys Wed Aug 04 06:58:28 2004 (41107B04)
    ba978000 ba987180 nic1394 nic1394.sys Wed Aug 04 06:58:28 2004 (41107B04)
    ba988000 ba990a00 processr processr.sys Wed Aug 04 06:59:14 2004 (41107B32)
    ba9d8000 ba9e2380 imapi imapi.sys Wed Aug 04 07:00:12 2004 (41107B6C)
    ba9e8000 ba9f4180 cdrom cdrom.sys Wed Aug 04 06:59:52 2004 (41107B58)
    ba9f8000 baa06080 redbook redbook.sys Wed Aug 04 06:59:34 2004 (41107B46)
    baa08000 baa17d80 serial serial.sys Wed Aug 04 07:15:51 2004 (41107F17)
    baa18000 baa24e00 i8042prt i8042prt.sys Wed Aug 04 07:14:36 2004 (41107ECC)
    baa28000 baa34880 rasl2tp rasl2tp.sys Wed Aug 04 07:14:21 2004 (41107EBD)
    baa38000 baa42200 raspppoe raspppoe.sys Wed Aug 04 07:05:06 2004 (41107C92)
    baa48000 baa53d00 raspptp raspptp.sys Wed Aug 04 07:14:26 2004 (41107EC2)
    baa58000 baa60900 msgpc msgpc.sys Wed Aug 04 07:04:11 2004 (41107C5B)
    baa68000 baa71f00 termdd termdd.sys Wed Aug 04 06:58:52 2004 (41107B1C)
    baa88000 baa91480 NDProxy NDProxy.SYS Fri Aug 17 21:55:30 2001 (3B7D84C2)
    baab8000 baac6100 usbhub usbhub.sys Wed Aug 04 07:08:40 2004 (41107D68)
    baad8000 baae7000 SAVRTPEL SAVRTPEL.SYS Tue Aug 05 04:41:00 2003 (3F2F274C)
    baaf8000 bab03460 SYMNDIS SYMNDIS.SYS Mon Sep 01 05:19:49 2003 (3F52C8E5)
    bab08000 bab12020 SYMIDS SYMIDS.SYS Mon Sep 01 05:20:04 2003 (3F52C8F4)
    bab18000 bab20700 netbios netbios.sys Wed Aug 04 07:03:19 2004 (41107C27)
    bab28000 bab2e200 PCIIDEX PCIIDEX.SYS Wed Aug 04 06:59:40 2004 (41107B4C)
    bab30000 bab34900 PartMgr PartMgr.sys Sat Aug 18 02:32:23 2001 (3B7DC5A7)
    bab90000 bab95000 usbuhci usbuhci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    bab98000 bab9e800 usbehci usbehci.sys Wed Aug 04 07:08:34 2004 (41107D62)
    baba0000 baba6b00 fdc fdc.sys Wed Aug 04 06:59:25 2004 (41107B3D)
    baba8000 babada00 mouclass mouclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    babb0000 babb6000 kbdclass kbdclass.sys Wed Aug 04 06:58:32 2004 (41107B08)
    babb8000 babbc880 TDI TDI.SYS Wed Aug 04 07:07:47 2004 (41107D33)
    babc0000 babc4580 ptilink ptilink.sys Fri Aug 17 21:49:53 2001 (3B7D8371)
    babc8000 babcc080 raspti raspti.sys Fri Aug 17 21:55:32 2001 (3B7D84C4)
    babd0000 babd5000 flpydisk flpydisk.sys Wed Aug 04 06:59:24 2004 (41107B3C)
    babe0000 babe5200 vga vga.sys Wed Aug 04 07:07:06 2004 (41107D0A)
    babe8000 babeca80 Msfs Msfs.SYS Wed Aug 04 07:00:37 2004 (41107B85)
    babf0000 babf7880 Npfs Npfs.SYS Wed Aug 04 07:00:38 2004 (41107B86)
    bac00000 bac04500 watchdog watchdog.sys Wed Aug 04 07:07:32 2004 (41107D24)
    bacb8000 bacbb000 BOOTVID BOOTVID.dll Fri Aug 17 21:49:09 2001 (3B7D8345)
    bad48000 bad4bc80 serenum serenum.sys Wed Aug 04 06:59:06 2004 (41107B2A)
    bad4c000 bad4e980 gameenum gameenum.sys Wed Aug 04 07:08:20 2004 (41107D54)
    bad50000 bad52580 ndistapi ndistapi.sys Fri Aug 17 21:55:29 2001 (3B7D84C1)
    bad60000 bad63c80 mssmbios mssmbios.sys Wed Aug 04 07:07:47 2004 (41107D33)
    bad90000 bad92280 rasacd rasacd.sys Fri Aug 17 21:55:39 2001 (3B7D84CB)
    bad98000 bad9aac0 SYMREDRV SYMREDRV.SYS Mon Sep 01 05:19:58 2003 (3F52C8EE)
    bada8000 bada9b80 kdcom kdcom.dll Fri Aug 17 21:49:10 2001 (3B7D8346)
    badaa000 badab100 WMILIB WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    badac000 badad500 viaide viaide.sys Wed Aug 04 06:59:42 2004 (41107B4E)
    badb2000 badb3420 ASACPI ASACPI.sys Fri Aug 13 03:52:52 2004 (411C2D04)
    badb4000 badb5100 swenum swenum.sys Wed Aug 04 06:58:41 2004 (41107B11)
    badb6000 badb7280 USBD USBD.SYS Fri Aug 17 22:02:58 2001 (3B7D8682)
    badb8000 badb9f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 21:49:37 2001 (3B7D8361)
    badba000 badbb080 Beep Beep.SYS Fri Aug 17 21:47:33 2001 (3B7D82E5)
    badbc000 badbd080 mnmdd mnmdd.SYS Fri Aug 17 21:57:28 2001 (3B7D8538)
    badbe000 badbf080 RDPCDD RDPCDD.sys Fri Aug 17 21:46:56 2001 (3B7D82C0)
    badc0000 badc14e0 SYMDNS SYMDNS.SYS Mon Sep 01 05:19:43 2003 (3F52C8DF)
    badd4000 badd5100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 22:07:23 2001 (3B7D878B)
    bae5c000 bae5da80 ParVdm ParVdm.SYS Fri Aug 17 21:49:49 2001 (3B7D836D)
    bae70000 bae70d00 pciide pciide.sys Fri Aug 17 21:51:49 2001 (3B7D83E5)
    baf3d000 baf3db80 Null Null.SYS Fri Aug 17 21:47:39 2001 (3B7D82EB)
    baf43000 baf437a0 symlcbrd symlcbrd.sys Wed Oct 16 07:50:27 2002 (3DAD0C33)
    bafe4000 bafe4c00 audstub audstub.sys Fri Aug 17 21:59:40 2001 (3B7D85BC)
    bafeb000 bafebd00 dxgthk dxgthk.sys Fri Aug 17 21:53:12 2001 (3B7D8438)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 07:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 07:00:51 2004 (41107B93)
    bff50000 bff52480 framebuf framebuf.dll Wed Aug 04 08:56:31 2004 (411096AF)

    Unloaded modules:
    b903e000 b904e000 NAVENG.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b899c000 b8a1d000 NAVEX15.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    baae8000 baaf8000 NAVENG.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba131000 ba1b2000 NAVEX15.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    babd8000 babdd000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bad8c000 bad8f000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  13. 2005/04/15
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    I have now update BIOS and drivers to latest manufacturer releases,
    I have tried disabling /NOEXECUTE in boot.ini but that gives me stop 0x0000008E error messages (dump data available if needed) and causes a lot of crashes in IE and Windows Explorer

    Should I start thinking of getting a RMA for the board?

    Regards

    Spotta
     
  14. 2005/04/15
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    OK, so to crack the cause of a Stop 6 takes at least a kernel memory dump, not a mini, and some intensive debugging.

    Several vectors for it, some of which can be driver related, others hardware problems.

    I can't say for sure whats going on on your machine to cause this problem. I think theres a 50/50 chance at this point that its a hardware problem (ram/mb/cpu) vs a driver problem.

    You could setup for a big dump and call microsoft for analysis, they should be able to debug it down to what error condition caused the fault. Based on that being bad data or a bitflip or something, you should be able to get better confidence about the problem.
     
  15. 2005/04/18
    debugnt

    debugnt Inactive

    Joined:
    2004/08/05
    Messages:
    13
    Likes Received:
    0
    I believe the chances are even greater than 50/50 that his is a hardware problem. I got my hands on another minidump with this same stack and found that the computer didn't do what it was supposed to do.

    This is the call stack leading to the BugCheck aka crash/blue screen
    kd> k
    ChildEBP RetAddr
    b7ba8bb0 804f73d9 nt!KeBugCheck+0x14
    b7ba8bd8 805c41df nt!KeUnstackDetachProcess+0x10d
    b7ba8c34 805c07fd nt!PsAssignImpersonationToken+0x123
    b7ba8d4c 8053c808 nt!NtSetInformationThread+0x207
    b7ba8d4c 7c90eb94 nt!KiFastCallEntry+0xf8
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    0110f6e4 00000000 0x7c90eb94

    Unassemble the instructions leading to the call to KeUnstackDetachProcess

    805c41ba 8b65e8 mov esp,[ebp-0x18]
    805c41bd 834dfcff or dword ptr [ebp-0x4],0xffffffff
    805c41c1 33db xor ebx,ebx
    805c41c3 8b7d08 mov edi,[ebp+0x8]
    805c41c6 8d8f34020000 lea ecx,[edi+0x234]
    805c41cc e845d20300 call nt!ExReleaseRundownProtection (80601416)
    805c41d1 385de7 cmp [ebp-0x19],bl
    805c41d4 7409 jz nt!PsAssignImpersonationToken+0x123 (805c41df)
    805c41d6 8d45bc lea eax,[ebp-0x44]
    805c41d9 50 push eax
    805c41da e8ed30f3ff call nt!KeUnstackDetachProcess (804f72cc)

    Examine the logic and determine that the value stored at [ebx-0x19] must be non-zero in order to call KeUnstackDetachProcess.

    Dump the value of [ebb-0x19] which is on the local kernel stack.

    kd> db b7ba8c34-19 l1
    b7ba8c1b 00

    It's zero, which means the machine should have executed the following statement, which would have returned without calling KeUnstackDetachProcess.

    jz nt!PsAssignImpersonationToken+0x123 (805c41df)

    805c41df 8b45e0 mov eax,[ebp-0x20]
    805c41e2 e8342ff7ff call nt!__SEH_epilog (8053711b)
    805c41e7 c20800 ret 0x8
    805c41ea cc int 3

    Note that earlier in the disassembly, if KeStackAttachProcess is called, [ebx-0x19] is set to 1.

    805c4171 e8c234f3ff call nt!KeStackAttachProcess (804f7638)
    805c4176 c645e701 mov byte ptr [ebp-0x19],0x1

    Per my earlier post the APC state doesn't look proper, but in this case it isn't proper because the system never called KeStackAttachProcess.

    So why would this machine and seemingly a lot of other machines crash in the same spot due to bad hardware? This is a very common code path, and hardware, like software, malfunction for logical reasons.

    John
     
  16. 2005/04/21
    spotta

    spotta Inactive Thread Starter

    Joined:
    2002/12/04
    Messages:
    182
    Likes Received:
    0
    Turned out to be memory / motherboard problems.
    They just didn't like each other - the memory works fine in another machine

    Thanks for the help

    Spotta
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.