1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BSOD STOP 0x000000BE. Seems NDIS.SYS as culprit

Discussion in 'Windows XP' started by bsp43, 2007/04/14.

  1. 2007/04/14
    bsp43

    bsp43 Inactive Thread Starter

    Joined:
    2007/04/09
    Messages:
    1
    Likes Received:
    0
    New to Forum. Could not download Microsoft debugging tools on offending system (get BSOD) so downloaded on another working Windows XP system and ran debugger on working system on Minidump file saved from offending system. Here is the dump data. Appreciate any help/pointers.

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [D:\Mini041407-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp2_rtm.040803-2158
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
    Debug session time: Sat Apr 14 20:24:58.468 2007 (GMT-4)
    System Uptime: 0 days 0:03:48.968
    Loading Kernel Symbols
    ....................................................................................................
    Loading User Symbols
    Unable to load image NDIS.SYS, Win32 error 2
    *** WARNING: Unable to verify timestamp for NDIS.SYS
    *** ERROR: Module load completed but symbols could not be loaded for NDIS.SYS
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 100000BE, {f803859d, 3a86161, f7850ba0, b}

    Probably caused by : NDIS.SYS

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
    An attempt was made to write to readonly memory. The guilty driver is on the
    stack trace (and is typically the current instruction pointer).
    When possible, the guilty driver's name (Unicode string) is printed on
    the bugcheck screen and saved in KiBugCheckDriver.
    Arguments:
    Arg1: f803859d, Virtual address for the attempted write.
    Arg2: 03a86161, PTE contents.
    Arg3: f7850ba0, (reserved)
    Arg4: 0000000b, (reserved)

    Debugging Details:
    ------------------


    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: CODE_CORRUPTION

    BUGCHECK_STR: 0xBE

    PROCESS_NAME: explorer.exe

    LAST_CONTROL_TRANSFER: from f84ab15d to f84abcc0

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f7850c20 f84ab15d 81ce3230 82303ab8 81da0868 NDIS+0x2acc0
    f7850c34 804e3d77 82303950 80551980 806ee2d0 NDIS+0x2a15d
    f7850c3c 80551980 806ee2d0 8056a9ab 81da08d8 nt!IopfCallDriver+0x31
    f7850c58 8057d9f7 82303950 81da0868 81dd9de0 nt!KeTickCount
    f7850d00 8057fbfa 000007b0 00000000 00000000 nt!IopXxxControlFile+0x611
    f7850d34 804df06b 000007b0 00000000 00000000 nt!NtDeviceIoControlFile+0x2a
    f7850d34 7c90eb94 000007b0 00000000 00000000 nt!KiFastCallEntry+0xf8
    01ded620 00000000 00000000 00000000 00000000 0x7c90eb94


    STACK_COMMAND: kb

    CHKIMG_EXTENSION: !chkimg -lo 50 -d !tcpip
    !chkimg -lo 50 -d !tcpip
    f803859c-f80385a0 5 bytes - tcpip!TCPDispatchInternalDeviceControl

    [ 8b ff 55 8b ec:e9 cf 2f 47 00 ]
    5 errors : !tcpip (f803859c-f80385a0)

    MODULE_NAME: NDIS

    IMAGE_NAME: NDIS.SYS

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107ec3

    FOLLOWUP_NAME: MachineOwner

    MEMORY_CORRUPTOR: PATCH_NDIS

    FAILURE_BUCKET_ID: MEMORY_CORRUPTION_PATCH_NDIS

    BUCKET_ID: MEMORY_CORRUPTION_PATCH_NDIS

    Followup: MachineOwner
    ---------

    eax=f803859c ebx=81e34e50 ecx=00472fcf edx=81da0868 esi=81da0868 edi=00000009
    eip=f84abcc0 esp=f7850c14 ebp=f7850c20 iopl=0 nv up ei pl nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
    NDIS+0x2acc0:
    f84abcc0 894801 mov dword ptr [eax+1],ecx ds:0023:f803859d=00472fcf
    ChildEBP RetAddr Args to Child
    WARNING: Stack unwind information not available. Following frames may be wrong.
    f7850c20 f84ab15d 81ce3230 82303ab8 81da0868 NDIS+0x2acc0
    f7850c34 804e3d77 82303950 80551980 806ee2d0 NDIS+0x2a15d
    f7850c3c 80551980 806ee2d0 8056a9ab 81da08d8 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
    f7850c58 8057d9f7 82303950 81da0868 81dd9de0 nt!KeTickCount
    f7850d00 8057fbfa 000007b0 00000000 00000000 nt!IopXxxControlFile+0x611 (FPO: [Non-Fpo])
    f7850d34 804df06b 000007b0 00000000 00000000 nt!NtDeviceIoControlFile+0x2a (FPO: [Non-Fpo])
    f7850d34 7c90eb94 000007b0 00000000 00000000 nt!KiFastCallEntry+0xf8 (FPO: [0,0] TrapFrame @ f7850d64)
    01ded620 00000000 00000000 00000000 00000000 0x7c90eb94
    start end module name
    804d7000 806eb780 nt ntoskrnl.exe Wed Aug 04 02:19:48 2004 (41108004)
    806ec000 8070c380 hal halaacpi.dll Wed Aug 04 01:59:05 2004 (41107B29)
    bf800000 bf9c0380 win32k win32k.sys Wed Aug 04 02:17:30 2004 (41107F7A)
    bf9c1000 bf9d2580 dxg dxg.sys Wed Aug 04 02:00:51 2004 (41107B93)
    bff50000 bff52480 framebuf framebuf.dll Wed Aug 04 03:56:31 2004 (411096AF)
    f78b5000 f7907180 srv srv.sys Wed Aug 04 02:14:44 2004 (41107ED4)
    f79d0000 f79f3000 Fastfat Fastfat.SYS Wed Aug 04 02:14:15 2004 (41107EB7)
    f7bb3000 f7bb6280 ndisuio ndisuio.sys Wed Aug 04 02:03:10 2004 (41107C1E)
    f7e9b000 f7eb2480 dump_atapi dump_atapi.sys Wed Aug 04 01:59:41 2004 (41107B4D)
    f7edb000 f7f49380 mrxsmb mrxsmb.sys Wed Aug 04 02:15:14 2004 (41107EF2)
    f7f4a000 f7f75180 rdbss rdbss.sys Wed Aug 04 02:20:05 2004 (41108015)
    f7f76000 f7f97d00 afd afd.sys Wed Aug 04 02:14:13 2004 (41107EB5)
    f7f98000 f7fbfc00 netbt netbt.sys Wed Aug 04 02:14:36 2004 (41107ECC)
    f7fc0000 f7fe0f00 ipnat ipnat.sys Wed Aug 04 02:04:48 2004 (41107C80)
    f801c000 f8073a80 tcpip tcpip.sys Wed Aug 04 02:14:39 2004 (41107ECF)
    f8074000 f8086400 ipsec ipsec.sys Wed Aug 04 02:14:27 2004 (41107EC3)
    f80a7000 f80ba780 VIDEOPRT VIDEOPRT.SYS Wed Aug 04 02:07:04 2004 (41107D08)
    f80eb000 f80ed900 Dxapi Dxapi.sys Fri Aug 17 16:53:19 2001 (3B7D843F)
    f8107000 f8109580 hidusb hidusb.sys Fri Aug 17 17:02:16 2001 (3B7D8658)
    f810b000 f813e200 update update.sys Wed Aug 04 01:58:32 2004 (41107B08)
    f81df000 f820f100 rdpdr rdpdr.sys Wed Aug 04 02:01:10 2004 (41107BA6)
    f8210000 f8220e00 psched psched.sys Wed Aug 04 02:04:16 2004 (41107C60)
    f8221000 f8237680 ndiswan ndiswan.sys Wed Aug 04 02:14:30 2004 (41107EC6)
    f8238000 f8260180 abvpn2k abvpn2k.sys Thu Jun 03 15:31:11 2004 (40BF7C7F)
    f8281000 f8283280 rasacd rasacd.sys Fri Aug 17 16:55:39 2001 (3B7D84CB)
    f8289000 f82ab680 ks ks.sys Wed Aug 04 02:15:20 2004 (41107EF8)
    f82ac000 f82f0800 MRV8335XP MRV8335XP.sys Mon Aug 22 03:04:13 2005 (430978ED)
    f82f1000 f8313e80 USBPORT USBPORT.SYS Wed Aug 04 02:08:34 2004 (41107D62)
    f8334000 f834e580 Mup Mup.sys Wed Aug 04 02:15:20 2004 (41107EF8)
    f834f000 f83db480 Ntfs Ntfs.sys Wed Aug 04 02:15:06 2004 (41107EEA)
    f83dc000 f83f2780 KSecDD KSecDD.sys Wed Aug 04 01:59:45 2004 (41107B51)
    f83f3000 f8404f00 sr sr.sys Wed Aug 04 02:06:22 2004 (41107CDE)
    f8405000 f8423780 fltMgr fltMgr.sys Wed Aug 04 02:01:17 2004 (41107BAD)
    f8424000 f843b480 atapi atapi.sys Wed Aug 04 01:59:41 2004 (41107B4D)
    f843c000 f8461700 dmio dmio.sys Wed Aug 04 02:07:13 2004 (41107D11)
    f8462000 f8480880 ftdisk ftdisk.sys Fri Aug 17 16:52:41 2001 (3B7D8419)
    f8481000 f84afd70 NDIS NDIS.SYS Wed Aug 04 02:14:27 2004 (41107EC3)
    f84b0000 f84d7000 SSIDRV SSIDRV.SYS Thu Jan 25 23:56:48 2007 (45B98A10)
    f84d7000 f84e7a80 pci pci.sys Wed Aug 04 02:07:45 2004 (41107D31)
    f84e8000 f8515d80 ACPI ACPI.sys Wed Aug 04 02:07:35 2004 (41107D27)
    f8537000 f853fc00 isapnp isapnp.sys Fri Aug 17 16:58:01 2001 (3B7D8559)
    f8547000 f8550000 SSHRMD SSHRMD.SYS Thu Jan 25 23:56:54 2007 (45B98A16)
    f8557000 f8560000 SSFS0509 SSFS0509.SYS Thu Jan 25 23:56:51 2007 (45B98A13)
    f8567000 f8571500 MountMgr MountMgr.sys Wed Aug 04 01:58:29 2004 (41107B05)
    f8577000 f8583c80 VolSnap VolSnap.sys Wed Aug 04 02:00:14 2004 (41107B6E)
    f8587000 f858fe00 disk disk.sys Wed Aug 04 01:59:53 2004 (41107B59)
    f8597000 f85a3200 CLASSPNP CLASSPNP.SYS Wed Aug 04 02:14:26 2004 (41107EC2)
    f85a7000 f85b1580 agp440 agp440.sys Wed Aug 04 02:07:40 2004 (41107D2C)
    f85e7000 f85efd80 AN983 AN983.sys Thu Oct 25 02:42:09 2001 (3BD7B441)
    f85f7000 f8603e00 i8042prt i8042prt.sys Wed Aug 04 02:14:36 2004 (41107ECC)
    f8607000 f8613000 sskbfd sskbfd.sys Thu Jan 25 23:56:52 2007 (45B98A14)
    f8617000 f8621380 imapi imapi.sys Wed Aug 04 02:00:12 2004 (41107B6C)
    f8627000 f8633180 cdrom cdrom.sys Wed Aug 04 01:59:52 2004 (41107B58)
    f8637000 f8645080 redbook redbook.sys Wed Aug 04 01:59:34 2004 (41107B46)
    f8647000 f8653880 rasl2tp rasl2tp.sys Wed Aug 04 02:14:21 2004 (41107EBD)
    f8657000 f8661200 raspppoe raspppoe.sys Wed Aug 04 02:05:06 2004 (41107C92)
    f8667000 f8672d00 raspptp raspptp.sys Wed Aug 04 02:14:26 2004 (41107EC2)
    f8677000 f867f900 msgpc msgpc.sys Wed Aug 04 02:04:11 2004 (41107C5B)
    f8687000 f8690f00 termdd termdd.sys Wed Aug 04 01:58:52 2004 (41107B1C)
    f8697000 f86a5100 usbhub usbhub.sys Wed Aug 04 02:08:40 2004 (41107D68)
    f86a7000 f86b0480 NDProxy NDProxy.SYS Fri Aug 17 16:55:30 2001 (3B7D84C2)
    f86e7000 f86ef700 netbios netbios.sys Wed Aug 04 02:03:19 2004 (41107C27)
    f8707000 f870fd80 HIDCLASS HIDCLASS.SYS Wed Aug 04 02:08:18 2004 (41107D52)
    f8717000 f8726900 Cdfs Cdfs.SYS Wed Aug 04 02:14:09 2004 (41107EB1)
    f87b7000 f87bb880 TDI TDI.SYS Wed Aug 04 02:07:47 2004 (41107D33)
    f87bf000 f87c5200 PCIIDEX PCIIDEX.SYS Wed Aug 04 01:59:40 2004 (41107B4C)
    f87c7000 f87cb900 PartMgr PartMgr.sys Fri Aug 17 21:32:23 2001 (3B7DC5A7)
    f87e7000 f87ec000 usbuhci usbuhci.sys Wed Aug 04 02:08:34 2004 (41107D62)
    f87ef000 f87f5800 usbehci usbehci.sys Wed Aug 04 02:08:34 2004 (41107D62)
    f87f7000 f87fc200 RTL8139 RTL8139.SYS Fri Jun 13 01:29:46 2003 (3EE9614A)
    f8807000 f8808000 fdc fdc.sys unavailable (00000000)
    f8817000 f881d000 kbdclass kbdclass.sys Wed Aug 04 01:58:32 2004 (41107B08)
    f881f000 f8824a00 mouclass mouclass.sys Wed Aug 04 01:58:32 2004 (41107B08)
    f884f000 f8853580 ptilink ptilink.sys Fri Aug 17 16:49:53 2001 (3B7D8371)
    f885f000 f8863080 raspti raspti.sys Fri Aug 17 16:55:32 2001 (3B7D84C4)
    f886f000 f8874000 flpydisk flpydisk.sys Wed Aug 04 01:59:24 2004 (41107B3C)
    f8887000 f888c200 vga vga.sys Wed Aug 04 02:07:06 2004 (41107D0A)
    f8897000 f889ba80 Msfs Msfs.SYS Wed Aug 04 02:00:37 2004 (41107B85)
    f88a7000 f88ae880 Npfs Npfs.SYS Wed Aug 04 02:00:38 2004 (41107B86)
    f88cf000 f88d6b80 usbccgp usbccgp.sys Wed Aug 04 02:08:45 2004 (41107D6D)
    f88e7000 f88ed500 usbprint usbprint.sys Wed Aug 04 02:01:23 2004 (41107BB3)
    f88f7000 f88fd180 HIDPARSE HIDPARSE.SYS Wed Aug 04 02:08:15 2004 (41107D4F)
    f8917000 f891b500 watchdog watchdog.sys Wed Aug 04 02:07:32 2004 (41107D24)
    f8947000 f894a000 BOOTVID BOOTVID.dll Fri Aug 17 16:49:09 2001 (3B7D8345)
    f89df000 f89e1580 ndistapi ndistapi.sys Fri Aug 17 16:55:29 2001 (3B7D84C1)
    f89ef000 f89f2680 avpnnic avpnnic.sys Wed Mar 19 16:44:26 2003 (3E78D6AA)
    f8a03000 f8a06c80 mssmbios mssmbios.sys Wed Aug 04 02:07:47 2004 (41107D33)
    f8a37000 f8a38b80 kdcom kdcom.dll Fri Aug 17 16:49:10 2001 (3B7D8346)
    f8a39000 f8a3a100 WMILIB WMILIB.SYS Fri Aug 17 17:07:23 2001 (3B7D878B)
    f8a3b000 f8a3c580 intelide intelide.sys Wed Aug 04 01:59:40 2004 (41107B4C)
    f8a3d000 f8a3e700 dmload dmload.sys Fri Aug 17 16:58:15 2001 (3B7D8567)
    f8a45000 f8a46100 swenum swenum.sys Wed Aug 04 01:58:41 2004 (41107B11)
    f8a49000 f8a4a280 USBD USBD.SYS Fri Aug 17 17:02:58 2001 (3B7D8682)
    f8a4f000 f8a50f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 16:49:37 2001 (3B7D8361)
    f8a53000 f8a54080 Beep Beep.SYS Fri Aug 17 16:47:33 2001 (3B7D82E5)
    f8a57000 f8a58080 RDPCDD RDPCDD.sys Fri Aug 17 16:46:56 2001 (3B7D82C0)
    f8a61000 f8a62100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 17:07:23 2001 (3B7D878B)
    f8aff000 f8affd00 PCIIde PCIIde.sys Fri Aug 17 16:51:49 2001 (3B7D83E5)
    f8b74000 f8b74d00 dxgthk dxgthk.sys Fri Aug 17 16:53:12 2001 (3B7D8438)
    f8c27000 f8c27b80 Null Null.SYS Fri Aug 17 16:47:39 2001 (3B7D82EB)
    f8c2a000 f8c2af80 AvgAsCln AvgAsCln.sys Tue Sep 05 12:03:16 2006 (44FD9FC4)
    Closing open log file c:\debuglog.txt
     
    Last edited: 2007/04/14
  2. 2007/04/15
    cpc2004

    cpc2004 Inactive

    Joined:
    2005/07/08
    Messages:
    366
    Likes Received:
    0

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.