1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BSOD 0x000000f4

Discussion in 'Windows XP' started by undertaker, 2006/12/21.

  1. 2006/12/21
    undertaker

    undertaker Inactive Thread Starter

    Joined:
    2006/12/21
    Messages:
    3
    Likes Received:
    0
    Hi, everyone..
    Old system had many problem..
    i made fresh install of windows xp, formating disk C..
    Everything works great, except, when i try to update windows through Autopatcher for XP, nov2006, i get BSOD while installing some security patch. This happens every time i try to update..

    i tried many testing tools, memtester, burnin, CPU stab test,.. everything works normal..

    thanx in advance,
    Undertaker

    p.s. i have some strange motherboard SVX400 i think from Syntax.. i had to download drivers for soundcard, chipset and agp from VIA homepage..

    here is my dump:

    Opened log file 'c:\debuglog.txt'
    kd> .sympath srv*c:\symbols*http://msdl.microsoft.com/download/symbols
    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
    kd> .reload;!analyze -v;r;kv;lmnt;.logclose;q
    Loading Kernel Symbols
    ......................................................................................................................
    Loading User Symbols
    Loading unloaded module list
    .........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    CRITICAL_OBJECT_TERMINATION (f4)
    A process or thread crucial to system operation has unexpectedly exited or been
    terminated.
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arguments:
    Arg1: 00000003, Process
    Arg2: 8207f4e0, Terminating object
    Arg3: 8207f654, Process image file name
    Arg4: 805fa7a8, Explanatory message (ascii)

    Debugging Details:
    ------------------


    PROCESS_OBJECT: 8207f4e0

    IMAGE_NAME: csrss.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    MODULE_NAME: csrss

    FAULTING_MODULE: 00000000

    PROCESS_NAME: csrss.exe

    EXCEPTION_RECORD: f85c4d10 -- (.exr fffffffff85c4d10)
    .exr fffffffff85c4d10
    ExceptionAddress: 7c90eb94
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000001
    Parameter[1]: 00582498
    Attempt to write to address 00582498

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    WRITE_ADDRESS: 00582498

    BUGCHECK_STR: 0xF4_C0000005

    STACK_TEXT:
    f85c4864 8062ca73 000000f4 00000003 8207f4e0 nt!KeBugCheckEx+0x1b
    f85c4888 805fa766 805fa7a8 8207f4e0 8207f654 nt!PspCatchCriticalBreak+0x75
    f85c48b8 804df06b 8207f728 c0000005 f85c4cf4 nt!NtTerminateProcess+0x7d
    f85c48b8 804de310 8207f728 c0000005 f85c4cf4 nt!KiFastCallEntry+0xf8
    f85c4938 8051de95 ffffffff c0000005 00582498 nt!ZwTerminateProcess+0x11
    f85c4cf4 804dfada f85c4d10 00000000 f85c4d64 nt!KiDispatchException+0x3a0
    f85c4d5c 804dfa86 0057fff4 7c90eb94 badb0d00 nt!CommonDispatchException+0x4d
    f85c4ddc 804fa477 805bcbff 00000001 00000000 nt!Kei386EoiHelper+0x18a
    f85c4de0 805bcbfe 00000001 00000000 0000027f nt!KiThreadStartup+0x16
    f85c4de4 00000000 00000000 0000027f 00000000 nt!CmpCreatePerfKeys+0x12e


    STACK_COMMAND: kb

    FOLLOWUP_NAME: MachineOwner

    FAILURE_BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe

    BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=8207f4e0 ecx=00000000 edx=8207f4c8 esi=8207f4e0 edi=82080b08
    eip=805339ae esp=f85c484c ebp=f85c4864 iopl=3 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00003286
    nt!KeBugCheckEx+0x1b:
    805339ae 5d pop ebp
    ChildEBP RetAddr Args to Child
    f85c4864 8062ca73 000000f4 00000003 8207f4e0 nt!KeBugCheckEx+0x1b (FPO: [Non-Fpo])
    f85c4888 805fa766 805fa7a8 8207f4e0 8207f654 nt!PspCatchCriticalBreak+0x75 (FPO: [Non-Fpo])
    f85c48b8 804df06b 8207f728 c0000005 f85c4cf4 nt!NtTerminateProcess+0x7d (FPO: [Non-Fpo])
    f85c48b8 804de310 8207f728 c0000005 f85c4cf4 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f85c48c8)
    f85c4938 8051de95 ffffffff c0000005 00582498 nt!ZwTerminateProcess+0x11 (FPO: [2,0,0])
    f85c4cf4 804dfada f85c4d10 00000000 f85c4d64 nt!KiDispatchException+0x3a0 (FPO: [Non-Fpo])
    f85c4d5c 804dfa86 0057fff4 7c90eb94 badb0d00 nt!CommonDispatchException+0x4d (FPO: [0,20,0])
    f85c4ddc 804fa477 805bcbff 00000001 00000000 nt!Kei386EoiHelper+0x18a
    f85c4de0 805bcbfe 00000001 00000000 0000027f nt!KiThreadStartup+0x16
    f85c4de4 00000000 00000000 0000027f 00000000 nt!CmpCreatePerfKeys+0x12e
    start end module name
    804d7000 806eb780 nt ntoskrnl.exe Wed Aug 04 08:19:48 2004 (41108004)
    806ec000 8070c380 hal halaacpi.dll Wed Aug 04 07:59:05 2004 (41107B29)
    b841f000 b845f100 HTTP HTTP.sys Sat Oct 09 01:48:20 2004 (41672744)
    b85a0000 b85c7800 mfehidk mfehidk.sys Wed Nov 22 23:53:25 2006 (4564D4E5)
    b8758000 b87aa180 srv srv.sys Wed Aug 04 08:14:44 2004 (41107ED4)
    b87cb000 b87daf00 mfeavfk mfeavfk.sys Wed Nov 22 23:55:05 2006 (4564D549)
    b88c3000 b88ef400 mrxdav mrxdav.sys Wed Aug 04 08:00:49 2004 (41107B91)
    b8acd000 b8ae1400 wdmaud wdmaud.sys Wed Aug 04 08:15:03 2004 (41107EE7)
    bad8a000 bada1480 dump_atapi dump_atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    bae6a000 baed7680 mrxsmb mrxsmb.sys Thu Oct 28 03:14:16 2004 (418047E8)
    baed8000 baf02a00 rdbss rdbss.sys Thu Oct 28 03:13:57 2004 (418047D5)
    baf03000 baf24d00 afd afd.sys Wed Aug 04 08:14:13 2004 (41107EB5)
    baf25000 baf4cc00 netbt netbt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    baf4d000 bafa4a80 tcpip tcpip.sys Sat Aug 14 00:50:41 2004 (411D45C1)
    bafa5000 bafb7400 ipsec ipsec.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 08:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 08:00:51 2004 (41107B93)
    bf9d3000 bfa16000 ati2dvag ati2dvag.dll Wed May 03 18:51:00 2006 (4458DF74)
    bfa16000 bfa5b000 ati2cqag ati2cqag.dll Wed May 03 18:09:20 2006 (4458D5B0)
    bfa5b000 bfa91000 atikvmag atikvmag.dll Wed May 03 18:15:58 2006 (4458D73E)
    bfa91000 bfd228a0 ati3duag ati3duag.dll Wed May 03 18:35:24 2006 (4458DBCC)
    bfd23000 bfe7ac00 ativvaxx ativvaxx.dll Wed May 03 18:29:13 2006 (4458DA59)
    f7f73000 f7fa6200 update update.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f7fe7000 f7ff5020 mfeapfk mfeapfk.sys Wed Nov 22 23:54:19 2006 (4564D51B)
    f8047000 f8049900 Dxapi Dxapi.sys Fri Aug 17 22:53:19 2001 (3B7D843F)
    f806f000 f809f100 rdpdr rdpdr.sys Wed Aug 04 08:01:10 2004 (41107BA6)
    f80a0000 f80b0e00 psched psched.sys Wed Aug 04 08:04:16 2004 (41107C60)
    f80b1000 f80c7680 ndiswan ndiswan.sys Wed Aug 04 08:14:30 2004 (41107EC6)
    f80c8000 f80db900 parport parport.sys Wed Aug 04 07:59:04 2004 (41107B28)
    f80dc000 f80ff980 portcls portcls.sys Wed Aug 04 08:15:47 2004 (41107F13)
    f8100000 f8131b80 vinyl97 vinyl97.sys Mon Oct 09 06:58:46 2006 (4529D706)
    f8132000 f8154680 ks ks.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    f8155000 f8177e80 USBPORT USBPORT.SYS Wed Aug 04 08:08:34 2004 (41107D62)
    f8178000 f818b780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 08:07:04 2004 (41107D08)
    f8194000 f8196280 rasacd rasacd.sys Fri Aug 17 22:55:39 2001 (3B7D84CB)
    f81b4000 f833b000 ati2mtag ati2mtag.sys Wed May 03 18:50:42 2006 (4458DF62)
    f835b000 f8375580 Mup Mup.sys Wed Aug 04 08:15:20 2004 (41107EF8)
    f8376000 f83a2a80 NDIS NDIS.sys Wed Aug 04 08:14:27 2004 (41107EC3)
    f83a3000 f842f480 Ntfs Ntfs.sys Wed Aug 04 08:15:06 2004 (41107EEA)
    f8430000 f8446780 KSecDD KSecDD.sys Wed Aug 04 07:59:45 2004 (41107B51)
    f8447000 f8458f00 sr sr.sys Wed Aug 04 08:06:22 2004 (41107CDE)
    f8459000 f8477780 fltMgr fltMgr.sys Wed Aug 04 08:01:17 2004 (41107BAD)
    f8478000 f848f480 atapi atapi.sys Wed Aug 04 07:59:41 2004 (41107B4D)
    f8490000 f84b5700 dmio dmio.sys Wed Aug 04 08:07:13 2004 (41107D11)
    f84b6000 f84d4880 ftdisk ftdisk.sys Fri Aug 17 22:52:41 2001 (3B7D8419)
    f84d5000 f84e5a80 pci pci.sys Wed Aug 04 08:07:45 2004 (41107D31)
    f84e6000 f8513d80 ACPI ACPI.sys Wed Aug 04 08:07:35 2004 (41107D27)
    f8535000 f853dc00 isapnp isapnp.sys Fri Aug 17 22:58:01 2001 (3B7D8559)
    f8545000 f854f500 MountMgr MountMgr.sys Wed Aug 04 07:58:29 2004 (41107B05)
    f8555000 f8561c80 VolSnap VolSnap.sys Wed Aug 04 08:00:14 2004 (41107B6E)
    f8565000 f856de00 disk disk.sys Wed Aug 04 07:59:53 2004 (41107B59)
    f8575000 f8581200 CLASSPNP CLASSPNP.SYS Wed Aug 04 08:14:26 2004 (41107EC2)
    f8585000 f858db40 PxHelp20 PxHelp20.sys Tue Jun 06 22:08:29 2006 (4485E0BD)
    f85d5000 f85ddd00 intelppm intelppm.sys Wed Aug 04 07:59:19 2004 (41107B37)
    f85e5000 f85f1180 cdrom cdrom.sys Wed Aug 04 07:59:52 2004 (41107B58)
    f85f5000 f8603080 redbook redbook.sys Wed Aug 04 07:59:34 2004 (41107B46)
    f8605000 f860f380 imapi imapi.sys Wed Aug 04 08:00:12 2004 (41107B6C)
    f8615000 f8623b80 drmk drmk.sys Wed Aug 04 08:07:54 2004 (41107D3A)
    f8625000 f862f800 fetnd5bv fetnd5bv.sys Wed Mar 15 03:51:51 2006 (44178147)
    f8635000 f8644d80 serial serial.sys Wed Aug 04 08:15:51 2004 (41107F17)
    f8645000 f8651e00 i8042prt i8042prt.sys Wed Aug 04 08:14:36 2004 (41107ECC)
    f8655000 f8661880 rasl2tp rasl2tp.sys Wed Aug 04 08:14:21 2004 (41107EBD)
    f8665000 f866f200 raspppoe raspppoe.sys Wed Aug 04 08:05:06 2004 (41107C92)
    f8675000 f8680d00 raspptp raspptp.sys Wed Aug 04 08:14:26 2004 (41107EC2)
    f8685000 f868d900 msgpc msgpc.sys Wed Aug 04 08:04:11 2004 (41107C5B)
    f8695000 f869ef00 termdd termdd.sys Wed Aug 04 07:58:52 2004 (41107B1C)
    f86c5000 f86ce480 NDProxy NDProxy.SYS Fri Aug 17 22:55:30 2001 (3B7D84C2)
    f86d5000 f86e3100 usbhub usbhub.sys Wed Aug 04 08:08:40 2004 (41107D68)
    f86f5000 f8700060 mfetdik mfetdik.sys Wed Nov 22 23:54:10 2006 (4564D512)
    f8705000 f870d700 wanarp wanarp.sys Wed Aug 04 08:04:57 2004 (41107C89)
    f8715000 f871d700 netbios netbios.sys Wed Aug 04 08:03:19 2004 (41107C27)
    f8725000 f872dd80 HIDCLASS HIDCLASS.SYS Wed Aug 04 08:08:18 2004 (41107D52)
    f8735000 f873d880 Fips Fips.SYS Sat Aug 18 03:31:49 2001 (3B7DC585)
    f8755000 f8764900 Cdfs Cdfs.SYS Wed Aug 04 08:14:09 2004 (41107EB1)
    f8765000 f8773d80 sysaudio sysaudio.sys Wed Aug 04 08:15:54 2004 (41107F1A)
    f87b5000 f87bb200 PCIIDEX PCIIDEX.SYS Wed Aug 04 07:59:40 2004 (41107B4C)
    f87bd000 f87c1900 PartMgr PartMgr.sys Sat Aug 18 03:32:23 2001 (3B7DC5A7)
    f87c5000 f87cd000 videX32 videX32.sys Wed Feb 22 11:10:28 2006 (43FC3894)
    f87cd000 f87d3d00 viaagp1 viaagp1.sys Wed Jul 02 12:08:01 2003 (3F02AF01)
    f8805000 f880a000 usbuhci usbuhci.sys Wed Aug 04 08:08:34 2004 (41107D62)
    f880d000 f8813800 usbehci usbehci.sys Wed Aug 04 08:08:34 2004 (41107D62)
    f8835000 f8836000 fdc fdc.sys unavailable (00000000)
    f8845000 f884b000 kbdclass kbdclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f8865000 f8869880 TDI TDI.SYS Wed Aug 04 08:07:47 2004 (41107D33)
    f8875000 f8879580 ptilink ptilink.sys Fri Aug 17 22:49:53 2001 (3B7D8371)
    f8885000 f8889080 raspti raspti.sys Fri Aug 17 22:55:32 2001 (3B7D84C4)
    f888d000 f8892a00 mouclass mouclass.sys Wed Aug 04 07:58:32 2004 (41107B08)
    f889d000 f88a2000 flpydisk flpydisk.sys Wed Aug 04 07:59:24 2004 (41107B3C)
    f88b5000 f88ba200 vga vga.sys Wed Aug 04 08:07:06 2004 (41107D0A)
    f88c5000 f88c9a80 Msfs Msfs.SYS Wed Aug 04 08:00:37 2004 (41107B85)
    f88d5000 f88dc880 Npfs Npfs.SYS Wed Aug 04 08:00:38 2004 (41107B86)
    f88fd000 f8903180 mferkdk mferkdk.sys Wed Nov 22 23:55:49 2006 (4564D575)
    f890d000 f8913180 HIDPARSE HIDPARSE.SYS Wed Aug 04 08:08:15 2004 (41107D4F)
    f892d000 f8933a20 mfebopk mfebopk.sys Wed Nov 22 23:55:32 2006 (4564D564)
    f893d000 f8941500 watchdog watchdog.sys Wed Aug 04 08:07:32 2004 (41107D24)
    f8945000 f8948000 BOOTVID BOOTVID.dll Fri Aug 17 22:49:09 2001 (3B7D8345)
    f89cd000 f89cf880 pfc pfc.sys Fri Apr 16 23:57:56 2004 (408056E4)
    f89dd000 f89df580 hidusb hidusb.sys Fri Aug 17 23:02:16 2001 (3B7D8658)
    f89e5000 f89e8c80 serenum serenum.sys Wed Aug 04 07:59:06 2004 (41107B2A)
    f89ed000 f89eff80 mouhid mouhid.sys Fri Aug 17 22:47:57 2001 (3B7D82FD)
    f89f1000 f89f3980 gameenum gameenum.sys Wed Aug 04 08:08:20 2004 (41107D54)
    f89f9000 f89fb580 ndistapi ndistapi.sys Fri Aug 17 22:55:29 2001 (3B7D84C1)
    f8a1d000 f8a20c80 mssmbios mssmbios.sys Wed Aug 04 08:07:47 2004 (41107D33)
    f8a35000 f8a36b80 kdcom kdcom.dll Fri Aug 17 22:49:10 2001 (3B7D8346)
    f8a37000 f8a38100 WMILIB WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f8a39000 f8a3a500 viaide viaide.sys Wed Aug 04 07:59:42 2004 (41107B4E)
    f8a3b000 f8a3c700 dmload dmload.sys Fri Aug 17 22:58:15 2001 (3B7D8567)
    f8a4b000 f8a4c100 swenum swenum.sys Wed Aug 04 07:58:41 2004 (41107B11)
    f8a51000 f8a52280 USBD USBD.SYS Fri Aug 17 23:02:58 2001 (3B7D8682)
    f8a55000 f8a56f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 22:49:37 2001 (3B7D8361)
    f8a59000 f8a5a080 Beep Beep.SYS Fri Aug 17 22:47:33 2001 (3B7D82E5)
    f8a5d000 f8a5e080 mnmdd mnmdd.SYS Fri Aug 17 22:57:28 2001 (3B7D8538)
    f8a61000 f8a62080 RDPCDD RDPCDD.sys Fri Aug 17 22:46:56 2001 (3B7D82C0)
    f8a69000 f8a6a100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 23:07:23 2001 (3B7D878B)
    f8acf000 f8ad0a80 ParVdm ParVdm.SYS Fri Aug 17 22:49:49 2001 (3B7D836D)
    f8b3b000 f8b3bb80 msmpu401 msmpu401.sys Fri Aug 17 22:59:59 2001 (3B7D85CF)
    f8b3e000 f8b3ec00 audstub audstub.sys Fri Aug 17 22:59:40 2001 (3B7D85BC)
    f8b72000 f8b72b80 Null Null.SYS Fri Aug 17 22:47:39 2001 (3B7D82EB)
    f8c50000 f8c50d00 dxgthk dxgthk.sys Fri Aug 17 22:53:12 2001 (3B7D8438)

    Unloaded modules:
    b823d000 b8267000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f8b77000 f8b78000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b89e0000 b8a0a000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8d0a000 b8d17000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8aaa000 b8acd000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b8d1a000 b8d28000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f8aa3000 f8aa5000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f88ad000 f88b2000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f819c000 f819f000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  2. 2006/12/22
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Does the crash also happens when you use Windows Update instead of a 3rd party program?

    Also, check your PC for the location of csrss.exe. Should only be in \Windows\System32\ (and possibly C:\WINDOWS\$NtServicePackUninstall$ and C:\WINDOWS\ServicePackFiles\i386). In other locations it is likely to be malware.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2006/12/22
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
    You can pretty much ignore the Dump, as any violation in Csrss.exe is going to cause a BSOD error. Not the trace though. The reference to Csrss.exe as a process in this instance is nonsensical and bogus.

    Nor do I see in your results a RAM error, although anything is possible.

    Member "Aries" suggestion of malware as responsible seems to me very reasonable.

    But I would be happier if you told us why you did a clean install of XP to start this whole mess.

    My guess: your hard disk is failing.

    I suggest this only because it has explained other 0xF4 BSODs, where RAM and malware were removed as possible issues.

    But I assure you that the debug session pointing at Csrss.exe is likely of no help in your instance.

    So, why did you do a clean install of XP?
     
  5. 2006/12/28
    undertaker

    undertaker Inactive Thread Starter

    Joined:
    2006/12/21
    Messages:
    3
    Likes Received:
    0
    thnx for replay,..
    i had to give computer back to friend, at the moment it's working fine, ..

    i didn't use windows update, since it takes time to update through internet, and i had no problems with autopatcher(more than 20 updated computers with this version)

    location of file was fine and clean, tested with mcafee virusscan, nod32, adaware, spysweeper..

    clean install(format) was made because system was crashed(could not run .exe and some other extensions)

    and i don't know about hard disk, since i had no other problems, and got same bsod after defrag and runing autopatcher again...

    we'll see :)

    again thank you both..
     
  6. 2006/12/28
    usasma

    usasma Inactive

    Joined:
    2006/12/17
    Messages:
    225
    Likes Received:
    4
    Try running the free diagnostic tools from the hard drive manufacturer's website - this'll give you an idea if it's the hard drive.
     
  7. 2006/12/28
    undertaker

    undertaker Inactive Thread Starter

    Joined:
    2006/12/21
    Messages:
    3
    Likes Received:
    0
    i'll try this next time i get this comp in my hands ..

    thnx
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.