1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BSOD Error code 00000024 win xp pro sp2

Discussion in 'Windows XP' started by enjoyfreestyle, 2006/10/30.

  1. 2006/10/30
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
    Hello everybody... i'm new and i'm italian so excuse me for my bad english!

    I've an hp nx6325 with turion 64 x2 TL 60...

    Often but not always i get BSOD while booting windows xp sp2...

    I'm not sure but i think that they are due to processor or acpi driver...

    If i use amd drivers i get bsod (IRQL_DRIVER... or PAGE_FAULT_IN_NONPAGED_AREA)at startup, instead if use procssr.sys i get bsod using windows...

    I paste the result of windebug in the first case and then one of the second case:

    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini103006-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols_cache*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.051011-1528
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
    Debug session time: Mon Oct 30 09:36:39.296 2006 (GMT+1)
    System Uptime: 0 days 0:00:36.984
    Loading Kernel Symbols
    .............................................................................................................................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 24, {1902fe, f6b48e00, f6b48afc, f750dc73}

    *** WARNING: Unable to verify timestamp for SYMEVENT.SYS
    *** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
    Probably caused by : Ntfs.sys ( Ntfs!NtfsFindPrefixHashEntry+2a6 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
    Arguments:
    Arg1: 001902fe
    Arg2: f6b48e00
    Arg3: f6b48afc
    Arg4: f750dc73

    Debugging Details:
    ------------------


    EXCEPTION_RECORD: f6b48e00 -- (.exr fffffffff6b48e00)
    ExceptionAddress: f750dc73 (Ntfs!NtfsFindPrefixHashEntry+0x000002a6)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 00500041
    Attempt to read from address 00500041

    CONTEXT: f6b48afc -- (.cxr fffffffff6b48afc)
    eax=00000044 ebx=f6b49018 ecx=00000011 edx=e17beb38 esi=00500041 edi=e17beb3a
    eip=f750dc73 esp=f6b48ec8 ebp=f6b48ee8 iopl=0 nv up ei pl nz ac pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010216
    Ntfs!NtfsFindPrefixHashEntry+0x2a6:
    f750dc73 f3a5 rep movs dword ptr es:[edi],dword ptr [esi] es:0023:e17beb3a=???????? ds:0023:00500041=????????
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    PROCESS_NAME: smss.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: 00500041

    BUGCHECK_STR: 0x24

    DEFAULT_BUCKET_ID: STRING_DEREFERENCE

    LAST_CONTROL_TRANSFER: from f750cf73 to f750dc73

    STACK_TEXT:
    f6b48ee8 f750cf73 84b165a8 00000044 e14c49e0 Ntfs!NtfsFindPrefixHashEntry+0x2a6
    f6b49054 f750ef64 84b165a8 842e8008 f6b490ac Ntfs!NtfsCommonCreate+0xb39
    f6b49134 804e13c9 84b0b020 842e8008 84a671c0 Ntfs!NtfsFsdCreate+0x1ec
    f6b49144 f75a8876 842e8198 84b119d0 f6b49200 nt!IopfCallDriver+0x31
    f6b49190 804e13c9 84b1b598 00000001 842e81bc sr!SrCreate+0x150
    f6b491a0 ee6e7841 842e8198 842e81bc f6b49200 nt!IopfCallDriver+0x31
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f6b491c8 ee6ee7f0 84b1b4e0 842e8018 f6b49200 SYMEVENT+0x7841
    f6b491e4 ee6e78b9 f6b49200 804e9420 ee6e797a SYMEVENT+0xe7f0
    f6b49220 804e13c9 84523b50 842e8008 842e8008 SYMEVENT+0x78b9
    f6b49230 8057ccc7 84b0b9c8 8490f0ac f6b493c8 nt!IopfCallDriver+0x31
    f6b49310 8056c063 84b0b9e0 00000000 8490f008 nt!IopParseDevice+0xa58
    f6b49388 8056f2a8 00000000 f6b493c8 00000240 nt!ObpLookupObjectName+0x53c
    f6b493dc 8057d2d3 00000000 00000000 4d6f6000 nt!ObOpenObjectByName+0xea
    f6b49458 8057d3a2 f6b496fc 00000020 f6b4969c nt!IopCreateFile+0x407
    f6b494b4 8057d550 f6b496fc 00000020 f6b4969c nt!IoCreateFile+0x8e
    f6b494f4 804dd98f f6b496fc 00000020 f6b4969c nt!NtOpenFile+0x27
    f6b494f4 804e3b93 f6b496fc 00000020 f6b4969c nt!KiFastCallEntry+0xfc
    f6b49584 805a3b34 f6b496fc 00000020 f6b4969c nt!ZwOpenFile+0x11
    f6b49734 805b6d8a f6b49778 00000000 00000000 nt!MmLoadSystemImage+0x266
    f6b497c8 805a3ead bf800000 f6b4991c 00000000 nt!MiResolveImageReferences+0x45d
    f6b49978 805b76c7 f6b49b00 00000000 00000000 nt!MmLoadSystemImage+0x8c8
    f6b49b28 804dd98f 00000026 f6b49d28 00000008 nt!NtSetSystemInformation+0x37c
    f6b49b28 804e4543 00000026 f6b49d28 00000008 nt!KiFastCallEntry+0xfc
    f6b49bac 805b7694 00000026 f6b49d28 00000008 nt!ZwSetSystemInformation+0x11
    f6b49d50 804dd98f 00000026 0015fe34 00000008 nt!NtSetSystemInformation+0x31a
    f6b49d50 7c90eb94 00000026 0015fe34 00000008 nt!KiFastCallEntry+0xfc
    0015fe4c 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    Ntfs!NtfsFindPrefixHashEntry+2a6
    f750dc73 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: Ntfs

    IMAGE_NAME: Ntfs.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107eea

    SYMBOL_NAME: Ntfs!NtfsFindPrefixHashEntry+2a6

    STACK_COMMAND: .cxr 0xfffffffff6b48afc ; kb

    FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsFindPrefixHashEntry+2a6

    BUCKET_ID: 0x24_Ntfs!NtfsFindPrefixHashEntry+2a6

    Followup: MachineOwner
    ---------

    0: kd> lmvm Ntfs
    start end module name
    f74e9000 f7575480 Ntfs (pdb symbols) c:\symbols_cache\ntfs.pdb\CF3F539EE3B2408887756DD42D7E53442\ntfs.pdb
    Loaded symbol image file: Ntfs.sys
    Mapped memory image file: c:\symbols_cache\Ntfs.sys\41107EEA8c480\Ntfs.sys
    Image path: Ntfs.sys
    Image name: Ntfs.sys
    Timestamp: Wed Aug 04 08:15:06 2004 (41107EEA)
    CheckSum: 0009BF25
    ImageSize: 0008C480
    File version: 5.1.2600.2180
    Product version: 5.1.2600.2180
    File flags: 0 (Mask 3F)
    File OS: 40004 NT Win32
    File type: 3.7 Driver
    File date: 00000000.00000000
    Translations: 0409.04b0
    CompanyName: Microsoft Corporation
    ProductName: Microsoft® Windows® Operating System
    InternalName: ntfs.sys
    OriginalFilename: ntfs.sys
    ProductVersion: 5.1.2600.2180
    FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    FileDescription: NT File System Driver
    LegalCopyright: © Microsoft Corporation. All rights reserved.

    Second case:

    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini102806-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols_cache*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x805644a0
    Debug session time: Sat Oct 28 15:54:30.843 2006 (GMT+1)
    System Uptime: 0 days 0:42:44.531
    Loading Kernel Symbols
    ...............................................................................................................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, 1, ec4ee0bc, 0}

    Probably caused by : ntkrnlmp.exe ( nt!KiFastCallEntry+fc )

    Followup: MachineOwner
    ---------

    1: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: 00000001, The address that the exception occurred at
    Arg3: ec4ee0bc, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    FAULTING_IP:
    +1
    00000001 ?? ???

    TRAP_FRAME: ec4ee0bc -- (.trap ffffffffec4ee0bc)
    ErrCode = 00000000
    eax=0188000b ebx=180104b3 ecx=00000000 edx=00000000 esi=0397f1f4 edi=ec4ee154
    eip=00000001 esp=ec4ee130 ebp=4f0801fd iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
    00000001 ?? ???
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: setup.exe

    LAST_CONTROL_TRANSFER: from 180104b3 to 00000001

    STACK_TEXT:
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    ec4ee12c 180104b3 4f0801fd 00000000 0397f1f4 0x1
    ec4ee140 804ddf0f 180104b3 4f0801fd 00000000 0x180104b3
    ec4ee140 7c90eb94 180104b3 4f0801fd 00000000 nt!KiFastCallEntry+0xfc
    0397f1dc 77f1831b 77f18305 180104b3 4f0801fd 0x7c90eb94
    0397f1f8 4fc2bb18 180104b3 4f0801fd 00000000 0x77f1831b
    0397f230 4fc3ad66 00000138 180104b3 00060204 0x4fc2bb18
    0397f254 4fc1d823 000a01ae 00000138 180104b3 0x4fc3ad66
    0397f2a4 4fc37168 02846de0 00000138 180104b3 0x4fc1d823
    0397f2c4 77d48709 02846de0 00000138 180104b3 0x4fc37168
    0397f2f0 77d54ca6 02d23958 000a01ae 00000138 0x77d48709
    0397f35c 77d54af2 00000000 02d23958 000a01ae 0x77d54ca6
    0397f3a4 77d4b3b4 00000000 00000138 180104b3 0x77d54af2
    0397f3cc 7c90eae3 0397f3dc 00000018 00618a28 0x77d4b3b4
    0397f48c 77d574ee 0cd23970 180104b3 00000001 0x7c90eae3
    0397f4a8 77d572a6 02d23970 00000000 00000000 0x77d574ee
    0397f520 77d4dcd1 00618c80 0000000c 00000000 0x77d572a6
    0397f550 7c90eae3 0397f560 000000fc 000000fc 0x77d4dcd1
    0397f678 4f0c8d4c 0397f69c 00000000 00000000 0x7c90eae3
    0397ffb4 7c80b50b 00c41ff8 00000000 00000000 0x4f0c8d4c
    0397ffec 00000000 4f0c7ecd 00c41ff8 00000000 0x7c80b50b


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!KiFastCallEntry+fc
    804ddf0f 8be5 mov esp,ebp

    SYMBOL_STACK_INDEX: 2

    SYMBOL_NAME: nt!KiFastCallEntry+fc

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107faa

    FAILURE_BUCKET_ID: 0x8E_nt!KiFastCallEntry+fc

    BUCKET_ID: 0x8E_nt!KiFastCallEntry+fc

    Followup: MachineOwner
    ---------

    1: kd> lmvm nt
    start end module name
    804d7000 80701000 nt # (pdb symbols) c:\symbols_cache\ntkrnlmp.pdb\7DE39A3E89DA4B378B95A09FA3A6398C2\ntkrnlmp.pdb
    Loaded symbol image file: ntkrnlmp.exe
    Mapped memory image file: c:\symbols_cache\ntkrnlmp.exe\41107FAA22a000\ntkrnlmp.exe
    Image path: ntkrnlmp.exe
    Image name: ntkrnlmp.exe
    Timestamp: Wed Aug 04 08:18:18 2004 (41107FAA)
    CheckSum: 0021C534
    ImageSize: 0022A000
    File version: 5.1.2600.2180
    Product version: 5.1.2600.2180
    File flags: 0 (Mask 3F)
    File OS: 40004 NT Win32
    File type: 1.0 App
    File date: 00000000.00000000
    Translations: 041d.04b0
    CompanyName: Microsoft Corporation
    ProductName: Operativsystemet Microsoft® Windows®
    InternalName: ntkrnlmp.exe
    OriginalFilename: ntkrnlmp.exe
    ProductVersion: 5.1.2600.2180
    FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    FileDescription: NT:s kernel och system
    LegalCopyright: © Microsoft Corporation. Med ensamrätt.


    thak you very much for your time!!!

    bye

    diego
     
  2. 2006/10/30
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #2

  3. to hide this advert.

  4. 2006/10/31
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
    I've already tried memtest86... no errors...
    I'll try also the other one...

    thank you
    bye
     
  5. 2006/10/31
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
    today, while my laptop was waking up from hibernation i got a different BSOD...

    this is what the win debugger said:

    0: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: 00000000, memory referenced
    Arg2: 0000001c, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: 804e1627, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: 00000000

    CURRENT_IRQL: 1c

    FAULTING_IP:
    nt!KiUnlinkThread+7
    804e1627 8b10 mov edx,dword ptr [eax]

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xA

    PROCESS_NAME: System

    LAST_CONTROL_TRANSFER: from 804e1680 to 804e1627

    STACK_TEXT:
    f7ad6e54 804e1680 84bc4598 84bc45a0 00000102 nt!KiUnlinkThread+0x7
    f7ad6e68 804e177c 00000000 f7ad6e84 00000000 nt!KiUnwaitThread+0x12
    f7ad6e94 804e2af0 f999e3ce 0000006c f7ad6fbc nt!KiWaitTest+0xab
    f7ad6fa0 804e206d f99969bc ffdff9c0 ffdff000 nt!KiTimerListExpire+0x7a
    f7ad6fcc 804dcd12 80561300 00000000 0007f56b nt!KiTimerExpiration+0xb1
    f7ad6ff4 804dc87d f7b0e43c 00000000 00000000 nt!KiRetireDpcList+0x61
    f7ad6ff8 f7b0e43c 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x2b
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    804dc87d 00000000 00000009 0081850f bb830000 0xf7b0e43c


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!KiUnlinkThread+7
    804e1627 8b10 mov edx,dword ptr [eax]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt!KiUnlinkThread+7

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 434c5639

    FAILURE_BUCKET_ID: 0xA_nt!KiUnlinkThread+7

    BUCKET_ID: 0xA_nt!KiUnlinkThread+7

    Followup: MachineOwner
    ---------

    0: kd> lmvm nt
    start end module name
    804d7000 806fd000 nt # (pdb symbols) c:\symbols_cache\ntkrnlmp.pdb\C5C5A2CF44924714BD7B4B42F2B227422\ntkrnlmp.pdb
    Loaded symbol image file: ntkrnlmp.exe
    Mapped memory image file: c:\symbols_cache\ntkrnlmp.exe\434C5639226000\ntkrnlmp.exe
    Image path: ntkrnlmp.exe
    Image name: ntkrnlmp.exe
    Timestamp: Wed Oct 12 02:18:01 2005 (434C5639)
    CheckSum: 00212E39
    ImageSize: 00226000
    File version: 5.1.2600.2774
    Product version: 5.1.2600.2774
    File flags: 0 (Mask 3F)
    File OS: 40004 NT Win32
    File type: 1.0 App
    File date: 00000000.00000000
    Translations: 0804.04b0
    CompanyName: Microsoft Corporation
    ProductName: Microsoft(R) Windows(R) Operating System
    InternalName: ntkrnlmp.exe
    OriginalFilename: ntkrnlmp.exe
    ProductVersion: 5.1.2600.2774
    FileVersion: 5.1.2600.2774 (xpsp.051011-1528)
    FileDescription: NT Kernel & System
    LegalCopyright: (C) Microsoft Corporation. All rights reserved.


    bye

    diego
     
  6. 2006/10/31
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
  7. 2006/10/31
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
  8. 2006/10/31
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Doubtfull...

     
    Arie,
    #7
  9. 2006/11/01
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
  10. 2006/11/01
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
    i've just tried also the OCA test with the same result: no error!! :confused:
     
  11. 2006/11/01
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
    A problem occurred within NTFS.SYS, the driver file that allows the system to read and write to NTFS file system drives. There may be a physical problem with the disk, or an Interrupt Request Packet (IRP) may be corrupted. Other common causes include heavy hard drive fragmentation, heavy file I/O, problems with some types of drive-mirroring software, or some antivirus software. I suggest running ChkDsk ; then disable all file system filters such as virus scanners, firewall software, or backup utilities. Update all disk, tape backup, CD-ROM, or removable device drivers to the most current versions.

    (AUMHA on 0x24 errors)

    Steps to take for an 0x24 error in Win2k or XP:
    http://support.microsoft.com/?kbid=228888&sd=RMVP
     
  12. 2006/11/01
    enjoyfreestyle

    enjoyfreestyle Inactive Thread Starter

    Joined:
    2006/10/30
    Messages:
    6
    Likes Received:
    0
    i formatted the system partition this week end and reinstalled windows... and nothing changed...

    i don't understand why i get this stop only at startup... if windows can boot then it run perfectly!

    i'll soon contact hp assistance...

    thak you

    bye
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.