1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BSOD - Page fault in non paging area

Discussion in 'Windows XP' started by McMood, 2008/07/04.

  1. 2008/07/04
    McMood

    McMood Inactive Thread Starter

    Joined:
    2008/07/04
    Messages:
    4
    Likes Received:
    0
    Hi everyone,

    I gotta problem with my lappy and would appreciate your experience in helping me solve it. I have a dell inspiron 9400/e1705. I recently upgraded the processor to a T7600 and upgraded it from 2Gig of ram to 4 Gig on winXP MCE 2005. I also uprgraded shortly after my budget ATI X1400 128MB graphics card to a NVIDIA Quadro fx2500 512MB following some popular tutorials I found online. A week ago around 1 month after installing everything and everything seemingly running ok. Suddenly my screen went black or almost black even when I restarted. Eventually I realised it was the graphics card and so I returned my old ATI card back into its slot and it was back to normal (I didnt install any drivers etc, it just worked, i guess drivers were already in the windows repository?) Anyway all was fine...but then every now and then I was getting these BSOD and its getting a little too common like once a day. Generally if not always now with this Paging fault error thingie...

    I installed the debug wiz and the tools and I got these results, if someone can please decipher the log for me I would greatly appreciate it, Thanks in advance!

    ===========================================

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini070508-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Kernel base = 0xe0ba3000 PsLoadedModuleList = 0xe0c29720
    Debug session time: Sat Jul 5 01:01:29.062 2008 (GMT+3)
    System Uptime: 0 days 8:39:56.791
    Loading Kernel Symbols
    ............................................................................................................................................................
    Loading User Symbols
    Loading unloaded module list
    ..................................................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 10000050, {e7856000, 1, e0d0c16f, 1}


    Could not read faulting driver name
    Probably caused by : ntkrpamp.exe ( nt!CmpGetValueKeyFromCache+89 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced. This cannot be protected by try-except,
    it must be protected by a Probe. Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: e7856000, memory referenced.
    Arg2: 00000001, value 0 = read operation, 1 = write operation.
    Arg3: e0d0c16f, If non-zero, the instruction address which referenced the bad memory
    address.
    Arg4: 00000001, (reserved)

    Debugging Details:
    ------------------


    Could not read faulting driver name

    WRITE_ADDRESS: e7856000

    FAULTING_IP:
    nt!CmpGetValueKeyFromCache+89
    e0d0c16f f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    MM_INTERNAL_CODE: 1

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x50

    PROCESS_NAME: avgscanx.exe

    LAST_CONTROL_TRANSFER: from e0cfd2d3 to e0d0c16f

    STACK_TEXT:
    f00f7c4c e0cfd2d3 e2225758 e64d300c 00000014 nt!CmpGetValueKeyFromCache+0x89
    f00f7cb4 e0cf041a e79d93c8 00000014 00000001 nt!CmEnumerateValueKey+0xc1
    f00f7d44 e0c0d61c 000003f0 00000014 00000001 nt!NtEnumerateValueKey+0x1ea
    f00f7d44 7c90e4f4 000003f0 00000014 00000001 nt!KiFastCallEntry+0xfc
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00000014 00000000 00000000 00000000 00000000 0x7c90e4f4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!CmpGetValueKeyFromCache+89
    e0d0c16f f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt!CmpGetValueKeyFromCache+89

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrpamp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 4802516a

    FAILURE_BUCKET_ID: 0x50_W_nt!CmpGetValueKeyFromCache+89

    BUCKET_ID: 0x50_W_nt!CmpGetValueKeyFromCache+89

    Followup: MachineOwner
    ---------

    eax=e7854210 ebx=e64d305c ecx=3ffff884 edx=fffffffc esi=c49a51a8 edi=e7856000
    eip=e0d0c16f esp=f00f7c40 ebp=f00f7c4c iopl=0 nv up ei pl nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
    nt!CmpGetValueKeyFromCache+0x89:
    e0d0c16f f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
    ChildEBP RetAddr Args to Child
    f00f7c4c e0cfd2d3 e2225758 e64d300c 00000014 nt!CmpGetValueKeyFromCache+0x89 (FPO: [Non-Fpo])
    f00f7cb4 e0cf041a e79d93c8 00000014 00000001 nt!CmEnumerateValueKey+0xc1 (FPO: [Non-Fpo])
    f00f7d44 e0c0d61c 000003f0 00000014 00000001 nt!NtEnumerateValueKey+0x1ea (FPO: [Non-Fpo])
    f00f7d44 7c90e4f4 000003f0 00000014 00000001 nt!KiFastCallEntry+0xfc (FPO: [0,0] TrapFrame @ f00f7d64)
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    00000014 00000000 00000000 00000000 00000000 0x7c90e4f4
    start end module name
    dd600000 dd7c2980 win32k win32k.sys Sun Apr 13 22:29:46 2008 (48025F2A)
    dd7c3000 dd7d4600 dxg dxg.sys Sun Apr 13 21:38:27 2008 (48025323)
    dd7d5000 dd817000 ati2dvag ati2dvag.dll Wed Feb 08 22:06:12 2006 (43EA4124)
    dd817000 dd851000 ati2cqag ati2cqag.dll Wed Feb 08 21:31:25 2006 (43EA38FD)
    dd851000 dd887000 atikvmag atikvmag.dll Wed Feb 08 21:36:18 2006 (43EA3A22)
    dd887000 ddaedca0 ati3duag ati3duag.dll Wed Feb 08 21:53:06 2006 (43EA3E12)
    ddaee000 ddbc0a00 ativvaxx ativvaxx.dll Wed Feb 08 21:47:48 2006 (43EA3CD4)
    ddbc1000 ddc06c00 ATMFD ATMFD.DLL Mon Apr 14 03:09:55 2008 (4802A0D3)
    e0b82000 e0ba2d00 hal halmacpi.dll Sun Apr 13 21:31:27 2008 (4802517F)
    e0ba3000 e0db0000 nt ntkrpamp.exe Sun Apr 13 21:31:06 2008 (4802516A)
    ed5ba000 ed5e4180 kmixer kmixer.sys Sun Apr 13 21:45:07 2008 (480254B3)
    ed6b0000 ed6c8000 tosrfbd tosrfbd.sys Mon Jan 17 07:13:26 2005 (41EB3B66)
    ed896000 ed8a2380 Tosrfhid Tosrfhid.sys Mon Nov 15 16:51:52 2004 (4198B478)
    eedf4000 eedfc3a0 tosrfbnp tosrfbnp.sys Thu Jul 08 11:07:33 2004 (40ED00C5)
    ef50c000 ef516000 secdrv secdrv.sys Wed Sep 13 16:18:32 2006 (45080528)
    ef584000 ef5d5c00 srv srv.sys Sun Apr 13 22:15:08 2008 (48025BBC)
    ef65e000 ef667900 LMIRfsDriver LMIRfsDriver.sys Thu Mar 06 20:38:19 2008 (47D02C0B)
    ef6fa000 ef6fd100 mdmxsdk mdmxsdk.sys Thu Oct 06 02:58:05 2005 (4344688D)
    ef70a000 ef70cf80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001 (3B7D82FD)
    ef7be000 ef7c1900 kbdhid kbdhid.sys Sun Apr 13 21:39:47 2008 (48025373)
    ef87e000 ef8bea80 HTTP HTTP.sys Sun Apr 13 21:53:48 2008 (480256BC)
    efb17000 efb27c00 avgtdix avgtdix.sys Wed Mar 12 14:46:16 2008 (47D7C288)
    efb50000 efb7c180 mrxdav mrxdav.sys Sun Apr 13 21:32:42 2008 (480251CA)
    effbb000 effcf480 wdmaud wdmaud.sys Sun Apr 13 22:17:18 2008 (48025C3E)
    f00d8000 f00e6d80 sysaudio sysaudio.sys Sun Apr 13 22:15:55 2008 (48025BEB)
    f0368000 f03808c0 tfsnudfa tfsnudfa.sys Tue Dec 07 05:05:15 2004 (41B50FDB)
    f0381000 f0399160 tfsnudf tfsnudf.sys Tue Dec 07 05:04:33 2004 (41B50FB1)
    f039a000 f03af200 tfsnifs tfsnifs.sys Tue Dec 07 05:04:27 2004 (41B50FAB)
    f03e4000 f03e7900 ndisuio ndisuio.sys Sun Apr 13 21:55:57 2008 (4802573D)
    f0440000 f0443b40 tfsnopio tfsnopio.sys Tue Dec 07 05:04:51 2004 (41B50FC3)
    f1120000 f1124460 tosrfnds tosrfnds.sys Thu Jan 06 07:42:41 2005 (41DCC1C1)
    f1168000 f117f900 dump_atapi dump_atapi.sys Sun Apr 13 21:40:29 2008 (4802539D)
    f11f0000 f11f2900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001 (3B7D843F)
    f1228000 f122bf00 APPDRV APPDRV.SYS Wed Jun 30 18:39:34 2004 (40E2DEB6)
    f122c000 f122fe60 ASPI32 ASPI32.SYS Wed Jul 17 18:53:00 2002 (3D3592DC)
    f1258000 f12607e0 tfsncofs tfsncofs.sys Tue Dec 07 05:04:46 2004 (41B50FBE)
    f1268000 f1271560 drvnddm drvnddm.sys Wed Nov 24 08:47:25 2004 (41A4206D)
    f12d8000 f12edf00 avgldx86 avgldx86.sys Thu Jan 31 20:38:23 2008 (47A2078F)
    f12ee000 f135d780 mrxsmb mrxsmb.sys Sun Apr 13 22:16:58 2008 (48025C2A)
    f135e000 f1388e80 rdbss rdbss.sys Sun Apr 13 22:28:38 2008 (48025EE6)
    f13b1000 f13d2b80 afd afd.sys Sun Apr 13 22:19:22 2008 (48025CBA)
    f13d3000 f13f8500 ipnat ipnat.sys Sun Apr 13 21:57:10 2008 (48025786)
    f13f9000 f1420c00 netbt netbt.sys Sun Apr 13 22:20:59 2008 (48025D1B)
    f1421000 f1479380 tcpip tcpip.sys Sun Apr 13 22:20:12 2008 (48025CEC)
    f147a000 f148c600 ipsec ipsec.sys Sun Apr 13 22:19:42 2008 (48025CCE)
    f1557000 f160d000 HSX_CNXT HSX_CNXT.sys Fri Dec 02 04:40:05 2005 (438FA5F5)
    f160d000 f1704000 HSX_DPV HSX_DPV.sys Fri Dec 02 04:40:52 2005 (438FA624)
    f1704000 f173e000 HSXHWAZL HSXHWAZL.sys Fri Dec 02 04:40:10 2005 (438FA5FA)
    f173e000 f1761a80 portcls portcls.sys Sun Apr 13 22:19:40 2008 (48025CCC)
    f1762000 f18595e0 sthda sthda.sys Wed Nov 16 22:47:30 2005 (437B8CD2)
    f4b39000 f4b96f00 update update.sys Sun Apr 13 21:39:46 2008 (48025372)
    f4b97000 f4bb9700 ks ks.sys Sun Apr 13 22:16:34 2008 (48025C12)
    f4bba000 f4be9e80 rdpdr rdpdr.sys Sun Apr 13 21:32:50 2008 (480251D2)
    f4bea000 f4bfae00 psched psched.sys Sun Apr 13 21:56:36 2008 (48025764)
    f4bfb000 f4c11580 ndiswan ndiswan.sys Sun Apr 13 22:20:41 2008 (48025D09)
    f4c12000 f4c40dc0 SynTP SynTP.sys Tue Nov 29 23:36:56 2005 (438CBBE8)
    f4c41000 f4c8c300 rixdptsk rixdptsk.sys Thu Jul 14 11:28:37 2005 (42D62235)
    f4c8d000 f4ca0580 sdbus sdbus.sys Sun Apr 13 21:36:44 2008 (480252BC)
    f4ca1000 f4cc4200 USBPORT USBPORT.SYS Sun Apr 13 21:45:34 2008 (480254CE)
    f4cc5000 f4e21a80 w39n51 w39n51.sys Mon Dec 05 11:55:28 2005 (43940080)
    f4e22000 f4e4a000 HDAudBus HDAudBus.sys Thu May 26 18:46:29 2005 (4295EF55)
    f4e4a000 f4e5df00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 21:44:39 2008 (48025497)
    f4e5e000 f4fc7000 ati2mtag ati2mtag.sys Wed Feb 08 22:05:55 2006 (43EA4113)
    f561f000 f5628e80 NDProxy NDProxy.SYS Sun Apr 13 21:57:28 2008 (48025798)
    f562f000 f563aee0 tosporte tosporte.sys Fri Jan 07 19:15:38 2005 (41DEB5AA)
    f563f000 f5648f00 termdd termdd.sys Sun Apr 13 21:38:36 2008 (4802532C)
    f564f000 f5657900 msgpc msgpc.sys Sun Apr 13 21:56:32 2008 (48025760)
    f565f000 f566ad00 raspptp raspptp.sys Sun Apr 13 22:19:47 2008 (48025CD3)
    f566f000 f5679200 raspppoe raspppoe.sys Sun Apr 13 21:57:31 2008 (4802579B)
    f567f000 f568b880 rasl2tp rasl2tp.sys Sun Apr 13 22:19:43 2008 (48025CCF)
    f5ab5000 f5ab8c80 mssmbios mssmbios.sys Sun Apr 13 21:36:45 2008 (480252BD)
    f5ad1000 f5ad3780 ndistapi ndistapi.sys Sun Apr 13 21:57:27 2008 (48025797)
    f5af9000 f5b12b80 Mup Mup.sys Sun Apr 13 22:17:05 2008 (48025C31)
    f5b13000 f5b3f980 NDIS NDIS.sys Sun Apr 13 22:20:35 2008 (48025D03)
    f5b40000 f5bcc600 Ntfs Ntfs.sys Sun Apr 13 22:15:49 2008 (48025BE5)
    f5bcd000 f5be3880 KSecDD KSecDD.sys Sun Apr 13 21:31:40 2008 (4802518C)
    f5be4000 f5bf8d60 drvmcdb drvmcdb.sys Wed Dec 01 20:32:07 2004 (41AE0017)
    f5bf9000 f5c0af00 sr sr.sys Sun Apr 13 21:36:50 2008 (480252C2)
    f5c0b000 f5c2ab00 fltmgr fltmgr.sys Sun Apr 13 21:32:58 2008 (480251DA)
    f5c2b000 f5c42900 atapi atapi.sys Sun Apr 13 21:40:29 2008 (4802539D)
    f5c43000 f5c68700 dmio dmio.sys Sun Apr 13 21:44:45 2008 (4802549D)
    f5c69000 f5c87880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001 (3B7D8419)
    f5c88000 f5c98a80 pci pci.sys Sun Apr 13 21:36:43 2008 (480252BB)
    f5c99000 f5cc6d80 ACPI ACPI.sys Sun Apr 13 21:36:33 2008 (480252B1)
    f5dc8000 f5dd1180 isapnp isapnp.sys Sun Apr 13 21:36:40 2008 (480252B8)
    f5dd8000 f5de2580 MountMgr MountMgr.sys Sun Apr 13 21:39:45 2008 (48025371)
    f5de8000 f5df4c80 VolSnap VolSnap.sys Sun Apr 13 21:41:00 2008 (480253BC)
    f5df8000 f5e00e00 disk disk.sys Sun Apr 13 21:40:46 2008 (480253AE)
    f5e08000 f5e14180 CLASSPNP CLASSPNP.SYS Sun Apr 13 22:16:21 2008 (48025C05)
    f5e18000 f5e20b80 PxHelp20 PxHelp20.sys Sat Feb 03 00:23:57 2007 (45C3ABED)
    f5e28000 f5e32b80 sbp2port sbp2port.sys Sun Apr 13 21:40:47 2008 (480253AF)
    f5e38000 f5e47100 ohci1394 ohci1394.sys Sun Apr 13 21:46:18 2008 (480254FA)
    f5e48000 f5e55080 1394BUS 1394BUS.SYS Sun Apr 13 21:46:18 2008 (480254FA)
    f5e68000 f5e77180 nic1394 nic1394.sys Sun Apr 13 21:51:22 2008 (4802562A)
    f5e88000 f5e96b00 drmk drmk.sys Sun Apr 13 21:45:12 2008 (480254B8)
    f5ea8000 f5eb6880 usbhub usbhub.sys Sun Apr 13 21:45:36 2008 (480254D0)
    f5ec8000 f5ed0780 netbios netbios.sys Sun Apr 13 21:56:01 2008 (48025741)
    f5f08000 f5f12e00 Fips Fips.SYS Sun Apr 13 21:33:27 2008 (480251F7)
    f5f18000 f5f20700 wanarp wanarp.sys Sun Apr 13 21:57:20 2008 (48025790)
    f5f28000 f5f36d80 arp1394 arp1394.sys Sun Apr 13 21:51:22 2008 (4802562A)
    f5f38000 f5f40800 tosrfusb tosrfusb.sys Tue Dec 21 05:38:11 2004 (41C78C93)
    f5f88000 f5f91000 HIDCLASS HIDCLASS.SYS Sun Apr 13 21:45:25 2008 (480254C5)
    f5fb8000 f5fc0e00 intelppm intelppm.sys Sun Apr 13 21:31:31 2008 (48025183)
    f5fc8000 f5fd3100 bcm4sbxp bcm4sbxp.sys Fri Aug 05 21:32:15 2005 (42F3B0AF)
    f5fd8000 f5fe4880 rimsptsk rimsptsk.sys Tue Jul 12 13:00:27 2005 (42D394BB)
    f5fe8000 f5ff4d00 i8042prt i8042prt.sys Sun Apr 13 22:17:59 2008 (48025C67)
    f5ff8000 f6006680 tosrfcom tosrfcom.sys Mon Oct 04 04:33:01 2004 (4160A84D)
    f6048000 f604e180 PCIIDEX PCIIDEX.SYS Sun Apr 13 21:40:29 2008 (4802539D)
    f6050000 f6054d00 PartMgr PartMgr.sys Sun Apr 13 21:40:48 2008 (480253B0)
    f6090000 f6095bc0 ssrtln ssrtln.sys Wed Jul 14 21:28:48 2004 (40F57B60)
    f6098000 f609e180 HIDPARSE HIDPARSE.SYS Sun Apr 13 21:45:22 2008 (480254C2)
    f60a0000 f60a5200 vga vga.sys Sun Apr 13 21:44:40 2008 (48025498)
    f60a8000 f60aca80 Msfs Msfs.SYS Sun Apr 13 21:32:38 2008 (480251C6)
    f60b0000 f60b7880 Npfs Npfs.SYS Sun Apr 13 21:32:38 2008 (480251C6)
    f60b8000 f60bef00 SCDEmu SCDEmu.SYS Sat Jul 29 14:11:23 2006 (44CB425B)
    f60c0000 f60c4c40 avgmfx86 avgmfx86.sys Thu Jan 10 20:05:15 2008 (4786504B)
    f60d0000 f60d4500 watchdog watchdog.sys Sun Apr 13 21:44:59 2008 (480254AB)
    f60e8000 f60ee4e0 tfsnboio tfsnboio.sys Tue Dec 07 05:04:34 2004 (41B50FB2)
    f6168000 f616d080 usbuhci usbuhci.sys Sun Apr 13 21:45:34 2008 (480254CE)
    f6170000 f6177600 usbehci usbehci.sys Sun Apr 13 21:45:34 2008 (480254CE)
    f6178000 f617ef80 rimmptsk rimmptsk.sys Thu Jul 14 12:58:13 2005 (42D63735)
    f6180000 f6185a00 mouclass mouclass.sys Sun Apr 13 21:39:47 2008 (48025373)
    f6188000 f618e000 kbdclass kbdclass.sys Sun Apr 13 21:39:46 2008 (48025372)
    f6190000 f6194a80 TDI TDI.SYS Sun Apr 13 22:00:04 2008 (48025834)
    f6198000 f619c580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001 (3B7D8371)
    f61a0000 f61a4080 raspti raspti.sys Fri Aug 17 23:55:32 2001 (3B7D84C4)
    f61a8000 f61ac2c0 omci omci.sys Fri Feb 13 19:45:58 2004 (402CFF46)
    f61b0000 f61b7580 Modem Modem.SYS Sun Apr 13 22:00:18 2008 (48025842)
    f61d8000 f61db000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09 2001 (3B7D8345)
    f61dc000 f61de800 compbatt compbatt.sys Sun Apr 13 21:36:36 2008 (480252B4)
    f61e0000 f61e3780 BATTC BATTC.SYS Sun Apr 13 21:36:32 2008 (480252B0)
    f6294000 f6296180 i2omgmt i2omgmt.SYS Sun Apr 13 21:41:22 2008 (480253D2)
    f629c000 f629e280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001 (3B7D84CB)
    f62a8000 f62aa180 VCdRom VCdRom.sys Wed Dec 19 22:44:58 2001 (3C20EE3A)
    f62b8000 f62ba280 wmiacpi wmiacpi.sys Sun Apr 13 21:36:37 2008 (480252B5)
    f62bc000 f62bf680 CmBatt CmBatt.sys Sun Apr 13 21:36:36 2008 (480252B4)
    f62c8000 f62c9b80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001 (3B7D8346)
    f62ca000 f62cb100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f62f4000 f62f5280 USBD USBD.SYS Sat Aug 18 00:02:58 2001 (3B7D8682)
    f62f6000 f62f7100 swenum swenum.sys Sun Apr 13 21:39:52 2008 (48025378)
    f6304000 f63055c0 sscdbhk5 sscdbhk5.sys Wed Jul 14 21:29:02 2004 (40F57B6E)
    f6306000 f6307f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001 (3B7D8361)
    f630a000 f630b080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001 (3B7D8538)
    f630c000 f630d080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56 2001 (3B7D82C0)
    f631c000 f631d100 dump_WMILIB dump_WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f6322000 f63238a0 tfsnpool tfsnpool.sys Tue Dec 07 05:04:29 2004 (41B50FAD)
    f633a000 f633b100 hiber_WMILIB hiber_WMILIB.SYS Sat Aug 18 00:07:23 2001 (3B7D878B)
    f6384000 f6385800 RaInfo RaInfo.sys Fri Jan 04 21:57:12 2008 (477E8188)
    f6390000 f6390d00 pciide pciide.sys Fri Aug 17 23:51:49 2001 (3B7D83E5)
    f63c0000 f63c0880 tfsndres tfsndres.sys Tue Dec 07 05:05:20 2004 (41B50FE0)
    f63c1000 f63c1fe0 tfsndrct tfsndrct.sys Tue Dec 07 05:04:50 2004 (41B50FC2)
    f63d4000 f63d4c80 lmimirr lmimirr.sys Wed Apr 11 01:32:11 2007 (461C106B)
    f63d5000 f63d5c00 audstub audstub.sys Fri Aug 17 23:59:40 2001 (3B7D85BC)
    f642d000 f642db80 Null Null.SYS Fri Aug 17 23:47:39 2001 (3B7D82EB)
    f643b000 f643ba80 PQNTDrv PQNTDrv.SYS Thu May 06 06:48:39 2004 (4099B597)
    f64da000 f64dad00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001 (3B7D8438)
    f64de000 f64de960 Toshidpt Toshidpt.sys Wed Oct 16 15:55:47 2002 (3DAD61D3)

    Unloaded modules:
    efc35000 efc40000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed685000 ed6b0000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed753000 ed75e000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6c8000 ed6f3000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6b0000 ed6c8000 hiber_atapi.
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f5f68000 f5f73000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6c8000 ed6f3000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed936000 ed93f000 HIDCLASS.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f64ec000 f64ed000 Toshidpt.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed926000 ed92f000 tosrfbnp.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eedb4000 eedc1000 Tosrfhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed793000 ed7ab000 tosrfbd.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f60f8000 f60fd000 tosrfnds.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f11e0000 f11e4000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    efa23000 efa26000 mouhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eedf4000 eedff000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6c8000 ed6f3000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef90f000 ef91a000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6c8000 ed6f3000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed986000 ed991000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed6c8000 ed6f3000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed783000 ed78e000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed83b000 ed866000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eefb4000 eefbd000 HIDCLASS.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f645e000 f645f000 Toshidpt.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed936000 ed93f000 tosrfbnp.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed926000 ed933000 Tosrfhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed823000 ed83b000 tosrfbd.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1128000 f112d000 tosrfnds.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    efaeb000 efaef000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef7c2000 ef7c5000 mouhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ef274000 ef27f000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f5f88000 f5f91000 HIDCLASS.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f64e5000 f64e6000 Toshidpt.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f5f78000 f5f81000 tosrfbnp.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f5f68000 f5f75000 Tosrfhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f11f8000 f1210000 tosrfbd.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f60c8000 f60cd000 tosrfnds.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1389000 f138d000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1234000 f1237000 mouhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed83b000 ed866000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    efd7d000 efd88000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ed83b000 ed866000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f633a000 f633c000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f12b8000 f12c3000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    efc15000 efc20000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eeb86000 eebb1000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f6312000 f6314000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f12b8000 f12c3000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    eefb4000 eefbf000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  2. 2008/07/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    McMood - Welcome to the Board :)

    First a rider ....
    However ....

    A single dump log is generally not enough - it is often necessary to establish a trend, so debug a few more and examine them. Is the probable cause always ntkrpamp.exe ?

    In this log I see that the AVG scanner was running - avgscanx.exe. Which version of AVG? - some people have experienced problems with AVG 8. Is the computer setup for a daily scan?

    If further logs also note avgscanx.exe I would be inclined to uninstall AVG and use Avira for a few days - you might even like it better :)
     

  3. to hide this advert.

  4. 2008/07/05
    McMood

    McMood Inactive Thread Starter

    Joined:
    2008/07/04
    Messages:
    4
    Likes Received:
    0
    BSOD - More debug logs and info

    Hi Pete,

    Ok, surprisingly this BSOD happened again this morning not too long after the last BSOD a few hours before. But it was not the same fault, this time it was a win32K.sys error.

    Note, I have AVG 8 and it does a daily scan.

    One more thing I need to point out, for about 4 months, when I load up my Win XP, at the beginning I get AVG finding a beep.sys Trojan from the Windows directory, which I ask to be removed every time. A few seconds later I get a Winlogon error which says it needs to close down that file. But after that there are no problems etc. after closing these 2 windows. I was intending to do a fresh install but just one thing after the other and I have over 100 Gigs of info to backup and I just got round to it yet. I am not sure if this is related as the BSODs only began in the last 2 weeks or so.

    Anyway I do have 2 other Mini Dump logs in my directory, I will post those two after the latest one I just got:

    Thanks again in advance...ermmm, sorry this post is long!

    ================================
    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini070508-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is:

    SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:

    C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free

    x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
    Debug session time: Sat Jul 5 09:50:32.406 2008 (GMT+3)
    System Uptime: 0 days 8:48:02.113
    Loading Kernel Symbols
    .................................................................................................................

    ...........................................
    Loading User Symbols
    Loading unloaded module list
    ..................................................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, bf806895, ad17cb38, 0}

    Probably caused by : win32k.sys ( win32k!XDCOBJ::bCleanDC+11 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
    This is a very common bugcheck. Usually the exception address

    pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means

    a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should

    never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: bf806895, The address that the exception occurred at
    Arg3: ad17cb38, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at

    "0x%08lx" referenced memory at "0x%08lx ". The memory could not be

    "%s ".

    FAULTING_IP:
    win32k!XDCOBJ::bCleanDC+11
    bf806895 8b7004 mov esi,dword ptr [eax+4]

    TRAP_FRAME: ad17cb38 -- (.trap 0xffffffffad17cb38)
    .trap 0xffffffffad17cb38
    ErrCode = 00000000
    eax=02050910 ebx=ad17cbe0 ecx=e42679c8 edx=00000438

    esi=00000000 edi=00000438
    eip=bf806895 esp=ad17cbac ebp=ad17cbd0 iopl=0 nv up ei ng nz

    ac pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000

    efl=00010296
    win32k!XDCOBJ::bCleanDC+0x11:
    bf806895 8b7004 mov esi,dword ptr [eax+4]

    ds:0023:02050914=????????
    .trap
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: winlogon.exe

    LAST_CONTROL_TRANSFER: from bf80d0cf to bf806895

    STACK_TEXT:
    ad17cbd0 bf80d0cf 08010727 00000001 e42679c8 win32k!

    XDCOBJ::bCleanDC+0x11
    ad17cbe4 bf8c1205 08010727 00000001 00000001 win32k!

    bDeleteDCInternal+0x26
    ad17cbfc bf8c10c9 00000438 e4249e68 00000000 win32k!

    vCleanupDCs+0x28
    ad17cc18 bf8bf7a9 e4249e68 00000000 00000000 win32k!

    NtGdiCloseProcess+0x1a
    ad17cc30 bf8bc955 e4249e68 00000000 8a0506a8 win32k!

    GdiProcessCallout+0x102
    ad17cc4c 805d248f 8b3f7800 00000000 8b923e30 win32k!

    W32pProcessCallout+0x5c
    ad17ccf0 805d27e9 40010004 ad17cd4c 804ff93f nt!

    PspExitThread+0x409
    ad17ccfc 804ff93f 8b923e30 ad17cd48 ad17cd3c nt!

    PsExitSpecialApc+0x23
    ad17cd4c 80541687 00000001 00000000 ad17cd64 nt!

    KiDeliverApc+0x1af
    ad17cd4c 7c90e4f4 00000001 00000000 ad17cd64 nt!

    KiServiceExit+0x59
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    0262f81c 00000000 00000000 00000000 00000000 0x7c90e4f4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    win32k!XDCOBJ::bCleanDC+11
    bf806895 8b7004 mov esi,dword ptr [eax+4]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: win32k!XDCOBJ::bCleanDC+11

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 48025f2a

    FAILURE_BUCKET_ID: 0x8E_win32k!XDCOBJ::bCleanDC+11

    BUCKET_ID: 0x8E_win32k!XDCOBJ::bCleanDC+11

    Followup: MachineOwner
    ---------

    eax=02050910 ebx=ad17cbe0 ecx=e42679c8 edx=00000438

    esi=00000000 edi=00000438
    eip=bf806895 esp=ad17cbac ebp=ad17cbd0 iopl=0 nv up ei ng nz

    ac pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000

    efl=00010296
    win32k!XDCOBJ::bCleanDC+0x11:
    bf806895 8b7004 mov esi,dword ptr [eax+4]

    ds:0023:02050914=????????
    ChildEBP RetAddr Args to Child
    ad17cbd0 bf80d0cf 08010727 00000001 e42679c8 win32k!

    XDCOBJ::bCleanDC+0x11 (FPO: [Non-Fpo])
    ad17cbe4 bf8c1205 08010727 00000001 00000001 win32k!

    bDeleteDCInternal+0x26 (FPO: [Non-Fpo])
    ad17cbfc bf8c10c9 00000438 e4249e68 00000000 win32k!

    vCleanupDCs+0x28 (FPO: [Non-Fpo])
    ad17cc18 bf8bf7a9 e4249e68 00000000 00000000 win32k!

    NtGdiCloseProcess+0x1a (FPO: [Non-Fpo])
    ad17cc30 bf8bc955 e4249e68 00000000 8a0506a8 win32k!

    GdiProcessCallout+0x102 (FPO: [Non-Fpo])
    ad17cc4c 805d248f 8b3f7800 00000000 8b923e30 win32k!

    W32pProcessCallout+0x5c (FPO: [Non-Fpo])
    ad17ccf0 805d27e9 40010004 ad17cd4c 804ff93f nt!

    PspExitThread+0x409 (FPO: [Non-Fpo])
    ad17ccfc 804ff93f 8b923e30 ad17cd48 ad17cd3c nt!

    PsExitSpecialApc+0x23 (FPO: [Non-Fpo])
    ad17cd4c 80541687 00000001 00000000 ad17cd64 nt!

    KiDeliverApc+0x1af (FPO: [Non-Fpo])
    ad17cd4c 7c90e4f4 00000001 00000000 ad17cd64 nt!

    KiServiceExit+0x59 (FPO: [0,0] TrapFrame @ ad17cd64)
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    0262f81c 00000000 00000000 00000000 00000000 0x7c90e4f4
    start end module name
    804d7000 806e4000 nt ntkrpamp.exe Sun Apr 13 21:31:06 2008

    (4802516A)
    806e4000 80704d00 hal halmacpi.dll Sun Apr 13 21:31:27 2008

    (4802517F)
    aca03000 aca2d180 kmixer kmixer.sys Sun Apr 13 21:45:07 2008

    (480254B3)
    ad641000 ad64b000 secdrv secdrv.sys Wed Sep 13 16:18:32 2006

    (45080528)
    ad74c000 ad79dc00 srv srv.sys Sun Apr 13 22:15:08 2008

    (48025BBC)
    ad7ba000 ad7bd100 mdmxsdk mdmxsdk.sys Thu Oct 06 02:58:05

    2005 (4344688D)
    ad816000 ad81f900 LMIRfsDriver LMIRfsDriver.sys Thu Mar 06

    20:38:19 2008 (47D02C0B)
    ad8b6000 ad8f6a80 HTTP HTTP.sys Sun Apr 13 21:53:48 2008

    (480256BC)
    adb77000 adb87c00 avgtdix avgtdix.sys Wed Mar 12 14:46:16 2008

    (47D7C288)
    add18000 add44180 mrxdav mrxdav.sys Sun Apr 13 21:32:42 2008

    (480251CA)
    ae093000 ae0a7480 wdmaud wdmaud.sys Sun Apr 13 22:17:18

    2008 (48025C3E)
    ae130000 ae13ed80 sysaudio sysaudio.sys Sun Apr 13 22:15:55

    2008 (48025BEB)
    ae3a0000 ae3b88c0 tfsnudfa tfsnudfa.sys Tue Dec 07 05:05:15 2004

    (41B50FDB)
    ae3b9000 ae3d1160 tfsnudf tfsnudf.sys Tue Dec 07 05:04:33 2004

    (41B50FB1)
    ae3fa000 ae40f200 tfsnifs tfsnifs.sys Tue Dec 07 05:04:27 2004

    (41B50FAB)
    ae42c000 ae42f900 ndisuio ndisuio.sys Sun Apr 13 21:55:57 2008

    (4802573D)
    ae47c000 ae47fb40 tfsnopio tfsnopio.sys Tue Dec 07 05:04:51 2004

    (41B50FC3)
    b0550000 b0567900 dump_atapi dump_atapi.sys Sun Apr 13 21:40:29

    2008 (4802539D)
    b05e4000 b05e6900 Dxapi Dxapi.sys Fri Aug 17 23:53:19 2001

    (3B7D843F)
    b0600000 b0603f00 APPDRV APPDRV.SYS Wed Jun 30 18:39:34

    2004 (40E2DEB6)
    b0604000 b0607e60 ASPI32 ASPI32.SYS Wed Jul 17 18:53:00

    2002 (3D3592DC)
    b0608000 b0620000 tosrfbd tosrfbd.sys Mon Jan 17 07:13:26 2005

    (41EB3B66)
    b0650000 b06587e0 tfsncofs tfsncofs.sys Tue Dec 07 05:04:46 2004

    (41B50FBE)
    b0660000 b0669560 drvnddm drvnddm.sys Wed Nov 24 08:47:25

    2004 (41A4206D)
    b06c0000 b06d5f00 avgldx86 avgldx86.sys Thu Jan 31 20:38:23 2008

    (47A2078F)
    b06d6000 b0745780 mrxsmb mrxsmb.sys Sun Apr 13 22:16:58 2008

    (48025C2A)
    b074e000 b0750f80 mouhid mouhid.sys Fri Aug 17 23:47:57 2001

    (3B7D82FD)
    b0752000 b0755900 kbdhid kbdhid.sys Sun Apr 13 21:39:47 2008

    (48025373)
    b076e000 b0798e80 rdbss rdbss.sys Sun Apr 13 22:28:38 2008

    (48025EE6)
    b0799000 b07bab80 afd afd.sys Sun Apr 13 22:19:22 2008

    (48025CBA)
    b07bb000 b07e0500 ipnat ipnat.sys Sun Apr 13 21:57:10 2008

    (48025786)
    b07e1000 b0808c00 netbt netbt.sys Sun Apr 13 22:20:59 2008

    (48025D1B)
    b0831000 b0889380 tcpip tcpip.sys Sun Apr 13 22:20:12 2008

    (48025CEC)
    b088a000 b089c600 ipsec ipsec.sys Sun Apr 13 22:19:42 2008

    (48025CCE)
    b08e5000 b099b000 HSX_CNXT HSX_CNXT.sys Fri Dec 02 04:40:05

    2005 (438FA5F5)
    b099b000 b0a92000 HSX_DPV HSX_DPV.sys Fri Dec 02 04:40:52

    2005 (438FA624)
    b0a92000 b0acc000 HSXHWAZL HSXHWAZL.sys Fri Dec 02

    04:40:10 2005 (438FA5FA)
    b0acc000 b0aefa80 portcls portcls.sys Sun Apr 13 22:19:40 2008

    (48025CCC)
    b0af0000 b0be75e0 sthda sthda.sys Wed Nov 16 22:47:30 2005

    (437B8CD2)
    b8e8b000 b8ee8f00 update update.sys Sun Apr 13 21:39:46 2008

    (48025372)
    b8ee9000 b8f0b700 ks ks.sys Sun Apr 13 22:16:34 2008

    (48025C12)
    b8f0c000 b8f3be80 rdpdr rdpdr.sys Sun Apr 13 21:32:50 2008

    (480251D2)
    b8f3c000 b8f4ce00 psched psched.sys Sun Apr 13 21:56:36 2008

    (48025764)
    b8f4d000 b8f63580 ndiswan ndiswan.sys Sun Apr 13 22:20:41 2008

    (48025D09)
    b8f64000 b8f92dc0 SynTP SynTP.sys Tue Nov 29 23:36:56 2005

    (438CBBE8)
    b8f93000 b8fde300 rixdptsk rixdptsk.sys Thu Jul 14 11:28:37 2005

    (42D62235)
    b8fdf000 b8ff2580 sdbus sdbus.sys Sun Apr 13 21:36:44 2008

    (480252BC)
    b8ff3000 b9016200 USBPORT USBPORT.SYS Sun Apr 13 21:45:34

    2008 (480254CE)
    b9017000 b9173a80 w39n51 w39n51.sys Mon Dec 05 11:55:28

    2005 (43940080)
    b9174000 b919c000 HDAudBus HDAudBus.sys Thu May 26 18:46:29

    2005 (4295EF55)
    b919c000 b91aff00 VIDEOPRT VIDEOPRT.SYS Sun Apr 13 21:44:39

    2008 (48025497)
    b91b0000 b9319000 ati2mtag ati2mtag.sys Wed Feb 08 22:05:55

    2006 (43EA4113)
    b9331000 b9334c80 mssmbios mssmbios.sys Sun Apr 13 21:36:45

    2008 (480252BD)
    b98f1000 b98ffb00 drmk drmk.sys Sun Apr 13 21:45:12 2008

    (480254B8)
    b9931000 b993ae80 NDProxy NDProxy.SYS Sun Apr 13 21:57:28

    2008 (48025798)
    b9941000 b994cee0 tosporte tosporte.sys Fri Jan 07 19:15:38 2005

    (41DEB5AA)
    b9951000 b995af00 termdd termdd.sys Sun Apr 13 21:38:36 2008

    (4802532C)
    b9961000 b9969900 msgpc msgpc.sys Sun Apr 13 21:56:32 2008

    (48025760)
    b9971000 b997cd00 raspptp raspptp.sys Sun Apr 13 22:19:47 2008

    (48025CD3)
    b9981000 b998b200 raspppoe raspppoe.sys Sun Apr 13 21:57:31

    2008 (4802579B)
    b9d95000 b9d97780 ndistapi ndistapi.sys Sun Apr 13 21:57:27 2008

    (48025797)
    b9da5000 b9da8680 CmBatt CmBatt.sys Sun Apr 13 21:36:36 2008

    (480252B4)
    b9da9000 b9dab280 wmiacpi wmiacpi.sys Sun Apr 13 21:36:37 2008

    (480252B5)
    b9dd9000 b9df2b80 Mup Mup.sys Sun Apr 13 22:17:05 2008

    (48025C31)
    b9df3000 b9e1f980 NDIS NDIS.sys Sun Apr 13 22:20:35 2008

    (48025D03)
    b9e20000 b9eac600 Ntfs Ntfs.sys Sun Apr 13 22:15:49 2008

    (48025BE5)
    b9ead000 b9ec3880 KSecDD KSecDD.sys Sun Apr 13 21:31:40

    2008 (4802518C)
    b9ec4000 b9ed8d60 drvmcdb drvmcdb.sys Wed Dec 01 20:32:07

    2004 (41AE0017)
    b9ed9000 b9eeaf00 sr sr.sys Sun Apr 13 21:36:50 2008

    (480252C2)
    b9eeb000 b9f0ab00 fltmgr fltmgr.sys Sun Apr 13 21:32:58 2008

    (480251DA)
    b9f0b000 b9f22900 atapi atapi.sys Sun Apr 13 21:40:29 2008

    (4802539D)
    b9f23000 b9f48700 dmio dmio.sys Sun Apr 13 21:44:45 2008

    (4802549D)
    b9f49000 b9f67880 ftdisk ftdisk.sys Fri Aug 17 23:52:41 2001

    (3B7D8419)
    b9f68000 b9f78a80 pci pci.sys Sun Apr 13 21:36:43 2008

    (480252BB)
    b9f79000 b9fa6d80 ACPI ACPI.sys Sun Apr 13 21:36:33 2008

    (480252B1)
    ba0a8000 ba0b1180 isapnp isapnp.sys Sun Apr 13 21:36:40 2008

    (480252B8)
    ba0b8000 ba0c2580 MountMgr MountMgr.sys Sun Apr 13 21:39:45

    2008 (48025371)
    ba0c8000 ba0d4c80 VolSnap VolSnap.sys Sun Apr 13 21:41:00 2008

    (480253BC)
    ba0d8000 ba0e0e00 disk disk.sys Sun Apr 13 21:40:46 2008

    (480253AE)
    ba0e8000 ba0f4180 CLASSPNP CLASSPNP.SYS Sun Apr 13

    22:16:21 2008 (48025C05)
    ba0f8000 ba100b80 PxHelp20 PxHelp20.sys Sat Feb 03 00:23:57

    2007 (45C3ABED)
    ba108000 ba112b80 sbp2port sbp2port.sys Sun Apr 13 21:40:47 2008

    (480253AF)
    ba118000 ba127100 ohci1394 ohci1394.sys Sun Apr 13 21:46:18

    2008 (480254FA)
    ba128000 ba135080 1394BUS 1394BUS.SYS Sun Apr 13 21:46:18

    2008 (480254FA)
    ba148000 ba157180 nic1394 nic1394.sys Sun Apr 13 21:51:22 2008

    (4802562A)
    ba158000 ba166880 usbhub usbhub.sys Sun Apr 13 21:45:36 2008

    (480254D0)
    ba178000 ba180780 netbios netbios.sys Sun Apr 13 21:56:01 2008

    (48025741)
    ba1b8000 ba1c2e00 Fips Fips.SYS Sun Apr 13 21:33:27 2008

    (480251F7)
    ba1c8000 ba1d0700 wanarp wanarp.sys Sun Apr 13 21:57:20 2008

    (48025790)
    ba1d8000 ba1e6d80 arp1394 arp1394.sys Sun Apr 13 21:51:22 2008

    (4802562A)
    ba1e8000 ba1f0800 tosrfusb tosrfusb.sys Tue Dec 21 05:38:11 2004

    (41C78C93)
    ba1f8000 ba204380 Tosrfhid Tosrfhid.sys Mon Nov 15 16:51:52 2004

    (4198B478)
    ba208000 ba2103a0 tosrfbnp tosrfbnp.sys Thu Jul 08 11:07:33 2004

    (40ED00C5)
    ba218000 ba221000 HIDCLASS HIDCLASS.SYS Sun Apr 13 21:45:25

    2008 (480254C5)
    ba268000 ba270e00 intelppm intelppm.sys Sun Apr 13 21:31:31 2008

    (48025183)
    ba278000 ba283100 bcm4sbxp bcm4sbxp.sys Fri Aug 05 21:32:15

    2005 (42F3B0AF)
    ba288000 ba294880 rimsptsk rimsptsk.sys Tue Jul 12 13:00:27 2005

    (42D394BB)
    ba298000 ba2a4d00 i8042prt i8042prt.sys Sun Apr 13 22:17:59 2008

    (48025C67)
    ba2a8000 ba2b6680 tosrfcom tosrfcom.sys Mon Oct 04 04:33:01

    2004 (4160A84D)
    ba318000 ba324880 rasl2tp rasl2tp.sys Sun Apr 13 22:19:43 2008

    (48025CCF)
    ba328000 ba32e180 PCIIDEX PCIIDEX.SYS Sun Apr 13 21:40:29

    2008 (4802539D)
    ba330000 ba334d00 PartMgr PartMgr.sys Sun Apr 13 21:40:48 2008

    (480253B0)
    ba340000 ba347880 Npfs Npfs.SYS Sun Apr 13 21:32:38 2008

    (480251C6)
    ba360000 ba366f00 SCDEmu SCDEmu.SYS Sat Jul 29 14:11:23

    2006 (44CB425B)
    ba368000 ba36cc40 avgmfx86 avgmfx86.sys Thu Jan 10 20:05:15

    2008 (4786504B)
    ba370000 ba374460 tosrfnds tosrfnds.sys Thu Jan 06 07:42:41 2005

    (41DCC1C1)
    ba378000 ba37c500 watchdog watchdog.sys Sun Apr 13 21:44:59

    2008 (480254AB)
    ba388000 ba38e4e0 tfsnboio tfsnboio.sys Tue Dec 07 05:04:34 2004

    (41B50FB2)
    ba440000 ba445080 usbuhci usbuhci.sys Sun Apr 13 21:45:34 2008

    (480254CE)
    ba448000 ba44f600 usbehci usbehci.sys Sun Apr 13 21:45:34 2008

    (480254CE)
    ba450000 ba456f80 rimmptsk rimmptsk.sys Thu Jul 14 12:58:13 2005

    (42D63735)
    ba458000 ba45da00 mouclass mouclass.sys Sun Apr 13 21:39:47

    2008 (48025373)
    ba460000 ba466000 kbdclass kbdclass.sys Sun Apr 13 21:39:46 2008

    (48025372)
    ba468000 ba46ca80 TDI TDI.SYS Sun Apr 13 22:00:04 2008

    (48025834)
    ba470000 ba474580 ptilink ptilink.sys Fri Aug 17 23:49:53 2001

    (3B7D8371)
    ba478000 ba47c080 raspti raspti.sys Fri Aug 17 23:55:32 2001

    (3B7D84C4)
    ba480000 ba4842c0 omci omci.sys Fri Feb 13 19:45:58 2004

    (402CFF46)
    ba488000 ba48f580 Modem Modem.SYS Sun Apr 13 22:00:18

    2008 (48025842)
    ba498000 ba49dbc0 ssrtln ssrtln.sys Wed Jul 14 21:28:48 2004

    (40F57B60)
    ba4a0000 ba4a6180 HIDPARSE HIDPARSE.SYS Sun Apr 13 21:45:22

    2008 (480254C2)
    ba4a8000 ba4ad200 vga vga.sys Sun Apr 13 21:44:40 2008

    (48025498)
    ba4b0000 ba4b4a80 Msfs Msfs.SYS Sun Apr 13 21:32:38 2008

    (480251C6)
    ba4b8000 ba4bb000 BOOTVID BOOTVID.dll Fri Aug 17 23:49:09

    2001 (3B7D8345)
    ba4bc000 ba4be800 compbatt compbatt.sys Sun Apr 13 21:36:36

    2008 (480252B4)
    ba4c0000 ba4c3780 BATTC BATTC.SYS Sun Apr 13 21:36:32

    2008 (480252B0)
    ba580000 ba582180 i2omgmt i2omgmt.SYS Sun Apr 13 21:41:22

    2008 (480253D2)
    ba588000 ba58a280 rasacd rasacd.sys Fri Aug 17 23:55:39 2001

    (3B7D84CB)
    ba594000 ba596180 VCdRom VCdRom.sys Wed Dec 19 22:44:58

    2001 (3C20EE3A)
    ba5a8000 ba5a9b80 kdcom kdcom.dll Fri Aug 17 23:49:10 2001

    (3B7D8346)
    ba5aa000 ba5ab100 WMILIB WMILIB.SYS Sat Aug 18 00:07:23

    2001 (3B7D878B)
    ba5e6000 ba5e7280 USBD USBD.SYS Sat Aug 18 00:02:58

    2001 (3B7D8682)
    ba5e8000 ba5e9100 swenum swenum.sys Sun Apr 13 21:39:52

    2008 (48025378)
    ba5f6000 ba5f75c0 sscdbhk5 sscdbhk5.sys Wed Jul 14 21:29:02 2004

    (40F57B6E)
    ba5f8000 ba5f9f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 23:49:37 2001

    (3B7D8361)
    ba5fc000 ba5fd080 mnmdd mnmdd.SYS Fri Aug 17 23:57:28 2001

    (3B7D8538)
    ba5fe000 ba5ff080 RDPCDD RDPCDD.sys Fri Aug 17 23:46:56

    2001 (3B7D82C0)
    ba60c000 ba60d9e0 Beep Beep.SYS Mon Mar 10 13:03:42 2008

    (47D5077E)
    ba618000 ba619100 dump_WMILIB dump_WMILIB.SYS Sat Aug 18

    00:07:23 2001 (3B7D878B)
    ba61e000 ba61f8a0 tfsnpool tfsnpool.sys Tue Dec 07 05:04:29 2004

    (41B50FAD)
    ba656000 ba657800 RaInfo RaInfo.sys Fri Jan 04 21:57:12 2008

    (477E8188)
    ba670000 ba670d00 pciide pciide.sys Fri Aug 17 23:51:49 2001

    (3B7D83E5)
    ba68b000 ba68bfe0 tfsndrct tfsndrct.sys Tue Dec 07 05:04:50 2004

    (41B50FC2)
    ba6a8000 ba6a8880 tfsndres tfsndres.sys Tue Dec 07 05:05:20 2004

    (41B50FE0)
    ba6e8000 ba6e8b80 Null Null.SYS Fri Aug 17 23:47:39 2001

    (3B7D82EB)
    ba6fa000 ba6faa80 PQNTDrv PQNTDrv.SYS Thu May 06 06:48:39

    2004 (4099B597)
    ba785000 ba785d00 dxgthk dxgthk.sys Fri Aug 17 23:53:12 2001

    (3B7D8438)
    ba7a8000 ba7a8960 Toshidpt Toshidpt.sys Wed Oct 16 15:55:47

    2002 (3DAD61D3)
    ba7fe000 ba7fec80 lmimirr lmimirr.sys Wed Apr 11 01:32:11 2007

    (461C106B)
    ba7ff000 ba7ffc00 audstub audstub.sys Fri Aug 17 23:59:40 2001

    (3B7D85BC)
    bf000000 bf011600 dxg dxg.sys Sun Apr 13 21:38:27 2008

    (48025323)
    bf012000 bf054000 ati2dvag ati2dvag.dll Wed Feb 08 22:06:12 2006

    (43EA4124)
    bf054000 bf08e000 ati2cqag ati2cqag.dll Wed Feb 08 21:31:25 2006

    (43EA38FD)
    bf08e000 bf0c4000 atikvmag atikvmag.dll Wed Feb 08 21:36:18 2006

    (43EA3A22)
    bf0c4000 bf32aca0 ati3duag ati3duag.dll Wed Feb 08 21:53:06 2006

    (43EA3E12)
    bf32b000 bf3fda00 ativvaxx ativvaxx.dll Wed Feb 08 21:47:48 2006

    (43EA3CD4)
    bf800000 bf9c2980 win32k win32k.sys Sun Apr 13 22:29:46 2008

    (48025F2A)
    bffa0000 bffe5c00 ATMFD ATMFD.DLL Mon Apr 14 03:09:55 2008

    (4802A0D3)

    Unloaded modules:
    add45000 add50000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    add75000 add80000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae000000 ae00b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b0670000 b067b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca3e000 aca49000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad251000 ad25c000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad826000 ad831000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    aca03000 aca2e000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    add45000 add50000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    acb1e000 acb49000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    acbf9000 acc04000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad7f6000 ad803000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad826000 ad834000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad689000 ad6ac000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba5b2000 ba5b4000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    adfa5000 adfd0000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad806000 ad811000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad836000 ad841000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    adc70000 adc7b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ad957000 ad962000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba7c8000 ba7c9000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae0d0000 ae0dd000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae0f0000 ae0fe000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae070000 ae093000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba652000 ba654000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba5fa000 ba5fc000 Beep.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae390000 ae39b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b06b0000 b06bb000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae0e0000 ae0eb000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae100000 ae10b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae110000 ae11b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae120000 ae12b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae140000 ae14b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ae150000 ae15b000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba1a8000 ba1b3000 imapi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba198000 ba1a7000 redbook.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba188000 ba198000 serial.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba584000 ba588000 kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba490000 ba495000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba168000 ba178000 cdrom.sys
    Timestamp: unavailable (00000000)

    Checksum: 00000000
    b9901000 b990c000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba308000 ba313000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba2f8000 ba303000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ba2e8000 ba2f3000 lvusbsta.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  5. 2008/07/05
    McMood

    McMood Inactive Thread Starter

    Joined:
    2008/07/04
    Messages:
    4
    Likes Received:
    0
    The other Debug logs from the BSODS

    ==========================Number 2=======

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini070208-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is:

    SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:

    C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free

    x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Kernel base = 0xe0ba3000 PsLoadedModuleList = 0xe0c29720
    Debug session time: Wed Jul 2 23:53:38.093 2008 (GMT+3)
    System Uptime: 1 days 14:46:05.959
    Loading Kernel Symbols
    .................................................................................................................

    ............................................
    Loading User Symbols
    Loading unloaded module list
    ..................................................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, dd6e5e56, f038f868, 0}

    Probably caused by : win32k.sys ( win32k!

    UserGetRedirectedWindowOrigin+28 )

    Followup: MachineOwner
    ---------

    1: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
    This is a very common bugcheck. Usually the exception address

    pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means

    a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should

    never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: dd6e5e56, The address that the exception occurred at
    Arg3: f038f868, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at

    "0x%08lx" referenced memory at "0x%08lx ". The memory could not be

    "%s ".

    FAULTING_IP:
    win32k!UserGetRedirectedWindowOrigin+28
    dd6e5e56 8b5040 mov edx,dword ptr [eax+40h]

    TRAP_FRAME: f038f868 -- (.trap 0xfffffffff038f868)
    .trap 0xfffffffff038f868
    ErrCode = 00000000
    eax=00000000 ebx=00000001 ecx=00000b20 edx=0000000b

    esi=e270c6d0 edi=00000005
    eip=dd6e5e56 esp=f038f8dc ebp=f038f8dc iopl=0 nv up ei pl zr na

    pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000

    efl=00010246
    win32k!UserGetRedirectedWindowOrigin+0x28:
    dd6e5e56 8b5040 mov edx,dword ptr [eax+40h]

    ds:0023:00000040=????????
    .trap
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: Audition.exe

    LAST_CONTROL_TRANSFER: from dd6160d8 to dd6e5e56

    STACK_TEXT:
    f038f8dc dd6160d8 b60129d5 f038f910 0013df2c win32k!

    UserGetRedirectedWindowOrigin+0x28
    f038f920 e0c0d61c b60129d5 e270c6d0 00000004 win32k!


    GreGetRandomRgn+0xde
    f038f920 7c90e4f4 b60129d5 e270c6d0 00000004 nt!

    KiFastCallEntry+0xfc
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    0013df44 00000000 00000000 00000000 00000000 0x7c90e4f4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    win32k!UserGetRedirectedWindowOrigin+28
    dd6e5e56 8b5040 mov edx,dword ptr [eax+40h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: win32k!UserGetRedirectedWindowOrigin+28

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 48025f2a

    FAILURE_BUCKET_ID: 0x8E_win32k!

    UserGetRedirectedWindowOrigin+28

    BUCKET_ID: 0x8E_win32k!UserGetRedirectedWindowOrigin+28

    Followup: MachineOwner
    ---------

    eax=00000000 ebx=00000001 ecx=00000b20 edx=0000000b

    esi=e270c6d0 edi=00000005
    eip=dd6e5e56 esp=f038f8dc ebp=f038f8dc iopl=0 nv up ei pl zr na

    pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000

    efl=00010246
    win32k!UserGetRedirectedWindowOrigin+0x28:
    dd6e5e56 8b5040 mov edx,dword ptr [eax+40h]

    ds:0023:00000040=????????
    ChildEBP RetAddr Args to Child
    f038f8dc dd6160d8 b60129d5 f038f910 0013df2c win32k!

    UserGetRedirectedWindowOrigin+0x28 (FPO: [Non-Fpo])
    f038f920 e0c0d61c b60129d5 e270c6d0 00000004 win32k!

    GreGetRandomRgn+0xde (FPO: [Non-Fpo])
    f038f920 7c90e4f4 b60129d5 e270c6d0 00000004 nt!

    KiFastCallEntry+0xfc (FPO: [0,0] TrapFrame @ f038f934)
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    0013df44 00000000 00000000 00000000 00000000 0x7c90e4f4
    start end module name
    dd600000 dd7c2980 win32k win32k.sys Sun Apr 13 22:29:46 2008

    <SNIP> (no need for repeated info)
     
  6. 2008/07/05
    McMood

    McMood Inactive Thread Starter

    Joined:
    2008/07/04
    Messages:
    4
    Likes Received:
    0
    More debug logs for BSOD...

    =======================Finally Number 3!!=====

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini070408-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is:

    SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:

    C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free

    x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Kernel base = 0xe0ba3000 PsLoadedModuleList = 0xe0c29720
    Debug session time: Fri Jul 4 01:01:21.968 2008 (GMT+3)
    System Uptime: 0 days 8:32:59.917
    Loading Kernel Symbols
    .................................................................................................................

    ....................................................
    Loading User Symbols
    Loading unloaded module list
    ..................................................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 10000050, {e5e62e24, 0, e0d033f1, 1}


    Could not read faulting driver name
    Probably caused by : ntkrpamp.exe ( nt!HvpGetCellMapped+5f )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced. This cannot be protected by try

    -except,
    it must be protected by a Probe. Typically the address is just plain bad

    or it
    is pointing at freed memory.
    Arguments:
    Arg1: e5e62e24, memory referenced.
    Arg2: 00000000, value 0 = read operation, 1 = write operation.
    Arg3: e0d033f1, If non-zero, the instruction address which referenced

    the bad memory
    address.
    Arg4: 00000001, (reserved)

    Debugging Details:
    ------------------


    Could not read faulting driver name

    READ_ADDRESS: e5e62e24

    FAULTING_IP:
    nt!HvpGetCellMapped+5f
    e0d033f1 8b4304 mov eax,dword ptr [ebx+4]

    MM_INTERNAL_CODE: 1

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x50

    PROCESS_NAME: avgscanx.exe

    LAST_CONTROL_TRANSFER: from e0d0c133 to e0d033f1

    STACK_TEXT:
    ebfd7c30 e0d0c133 e2225758 fc9cd620 e616c3c8 nt!

    HvpGetCellMapped+0x5f
    ebfd7c4c e0cfd2d3 e2225758 e616500c 00000000 nt!

    CmpGetValueKeyFromCache+0x4d
    ebfd7cb4 e0cf041a e616c3c8 00000000 00000001 nt!

    CmEnumerateValueKey+0xc1
    ebfd7d44 e0c0d61c 000003f4 00000000 00000001 nt!

    NtEnumerateValueKey+0x1ea
    ebfd7d44 7c90e4f4 000003f4 00000000 00000001 nt!

    KiFastCallEntry+0xfc
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    00000000 00000000 00000000 00000000 00000000 0x7c90e4f4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!HvpGetCellMapped+5f
    e0d033f1 8b4304 mov eax,dword ptr [ebx+4]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt!HvpGetCellMapped+5f

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrpamp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 4802516a

    FAILURE_BUCKET_ID: 0x50_nt!HvpGetCellMapped+5f

    BUCKET_ID: 0x50_nt!HvpGetCellMapped+5f

    Followup: MachineOwner
    ---------

    eax=e5e62e20 ebx=e5e62e20 ecx=fccd90c0 edx=000003e4

    esi=e2225758 edi=00000620
    eip=e0d033f1 esp=ebfd7be8 ebp=ebfd7c30 iopl=0 nv up ei pl zr na

    pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000

    efl=00010246
    nt!HvpGetCellMapped+0x5f:
    e0d033f1 8b4304 mov eax,dword ptr [ebx+4]

    ds:0023:e5e62e24=????????
    ChildEBP RetAddr Args to Child
    ebfd7c30 e0d0c133 e2225758 fc9cd620 e616c3c8 nt!

    HvpGetCellMapped+0x5f (FPO: [Non-Fpo])
    ebfd7c4c e0cfd2d3 e2225758 e616500c 00000000 nt!

    CmpGetValueKeyFromCache+0x4d (FPO: [Non-Fpo])
    ebfd7cb4 e0cf041a e616c3c8 00000000 00000001 nt!

    CmEnumerateValueKey+0xc1 (FPO: [Non-Fpo])
    ebfd7d44 e0c0d61c 000003f4 00000000 00000001 nt!

    NtEnumerateValueKey+0x1ea (FPO: [Non-Fpo])
    ebfd7d44 7c90e4f4 000003f4 00000000 00000001 nt!

    KiFastCallEntry+0xfc (FPO: [0,0] TrapFrame @ ebfd7d64)
    WARNING: Frame IP not in any known module. Following frames may be

    wrong.
    00000000 00000000 00000000 00000000 00000000 0x7c90e4f4
    start end module name
    dd600000 dd7c2980 win32k win32k.sys Sun Apr 13 22:29:46 2008

    <SNIP> (no need for repeated info)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.