1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Random Blue Screen of Death - DUMP DATA

Discussion in 'PC Hardware' started by jonesy, 2006/11/03.

  1. 2006/11/03
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    Hey there. Nice forum so hopefully you can help me out a bit.

    We've been having blue screen of deaths and crashes today, and has happened about 4 times so far. I cannot see any hardware problems in device manager, but after reading another thread, ive downloaded the debug tools and have ran them, and created a log file/dump data. I could only do this for user.dmp and not the memory.dmp as this was not present. heres the log, any ideas please?


    ####################################

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Documents and Settings\All Users\Documents\DrWatson\user.dmp]
    User Dump File: Only application data is available

    Windows 2000 Version 2195 UP Free x86 compatible
    Product: LanManNt, suite: TerminalServer SingleUserTS
    Debug session time: Fri Oct 20 02:02:54.375 2006 (GMT+0)
    System Uptime: 0 days 0:02:44.188
    Process Uptime: not available
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINNT;C:\WINNT\system32;C:\WINNT\system32\drivers
    ......................................
    (a78.af0): Access violation - code c0000005 (!!! second chance !!!)
    eax=00000000 ebx=00000000 ecx=0109da58 edx=00000124 esi=0109da48 edi=00000000
    eip=77f8f281 esp=015bfea4 ebp=015bff04 iopl=0 nv up ei pl zr na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
    ntdll!RtlpWaitForCriticalSection+0x8a:
    77f8f281 ff4010 inc dword ptr [eax+10h] ds:0023:00000010=????????
    0:005> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Exception Analysis *
    * *
    *******************************************************************************

    *** ERROR: Module load completed but symbols could not be loaded for FXSSVC.exe
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: ntdll!_PEB ***
    *** ***
    *************************************************************************
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for FXSROUTE.dll -
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_RTL_CRITICAL_SECTION ***
    *** ***
    *************************************************************************

    FAULTING_IP:
    ntdll!RtlpWaitForCriticalSection+8a
    77f8f281 ff4010 inc dword ptr [eax+10h]

    EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
    .exr ffffffffffffffff
    ExceptionAddress: 77f8f281 (ntdll!RtlpWaitForCriticalSection+0x0000008a)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000001
    Parameter[1]: 00000010
    Attempt to write to address 00000010

    FAULTING_THREAD: 00000af0

    PROCESS_NAME: FXSSVC.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    WRITE_ADDRESS: 00000010

    BUGCHECK_STR: ACCESS_VIOLATION

    DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE

    CRITICAL_SECTION: 0109da48 (!cs -s 0109da48)

    LAST_CONTROL_TRANSFER: from 77f87f26 to 77f8f281

    STACK_TEXT:
    015bff04 77f87f26 0109da00 010742ff 0109da48 ntdll!RtlpWaitForCriticalSection+0x8a
    015bff0c 010742ff 0109da48 77fcb8af 77fcba2b ntdll!RtlEnterCriticalSection+0x46
    WARNING: Stack unwind information not available. Following frames may be wrong.
    015bff5c 01074c49 00e6e160 00000038 00e6e1b8 FXSSVC+0x742ff
    015bffb4 7c57b396 00000000 77fcb8af 77fcba2b FXSSVC+0x74c49
    015bffec 00000000 01074bb0 00000000 00000000 KERNEL32!BaseThreadStart+0x52


    FOLLOWUP_IP:
    FXSSVC+742ff
    010742ff c745fc00000000 mov dword ptr [ebp-4],0

    SYMBOL_STACK_INDEX: 2

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: FXSSVC

    IMAGE_NAME: FXSSVC.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 3a3c8d7f

    SYMBOL_NAME: FXSSVC+742ff

    STACK_COMMAND: ~5s ; kb

    FAILURE_BUCKET_ID: ACCESS_VIOLATION_FXSSVC+742ff

    BUCKET_ID: ACCESS_VIOLATION_FXSSVC+742ff

    Followup: MachineOwner
    ---------

    eax=00000000 ebx=00000000 ecx=0109da58 edx=00000124 esi=0109da48 edi=00000000
    eip=77f8f281 esp=015bfea4 ebp=015bff04 iopl=0 nv up ei pl zr na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
    ntdll!RtlpWaitForCriticalSection+0x8a:
    77f8f281 ff4010 inc dword ptr [eax+10h] ds:0023:00000010=????????
    ChildEBP RetAddr Args to Child
    015bff04 77f87f26 0109da00 010742ff 0109da48 ntdll!RtlpWaitForCriticalSection+0x8a (FPO: [Non-Fpo])
    015bff0c 010742ff 0109da48 77fcb8af 77fcba2b ntdll!RtlEnterCriticalSection+0x46 (FPO: [1,0,0])
    WARNING: Stack unwind information not available. Following frames may be wrong.
    015bff5c 01074c49 00e6e160 00000038 00e6e1b8 FXSSVC+0x742ff
    015bffb4 7c57b396 00000000 77fcb8af 77fcba2b FXSSVC+0x74c49
    015bffec 00000000 01074bb0 00000000 00000000 KERNEL32!BaseThreadStart+0x52 (FPO: [Non-Fpo])
    start end module name
    00400000 00487000 FXSAPI FXSAPI.dll Sun Dec 17 09:54:51 2000 (3A3C8D6B)
    01000000 010a4000 FXSSVC FXSSVC.exe Sun Dec 17 09:55:11 2000 (3A3C8D7F)
    63180000 631cc000 SHLWAPI SHLWAPI.dll Fri Jun 13 00:23:56 2003 (3EE90B8C)
    644c0000 64510000 FXST30 FXST30.dll Sun Dec 17 09:56:10 2000 (3A3C8DBA)
    64700000 6476a000 FXSTIFF FXSTIFF.dll Sun Dec 17 09:54:24 2000 (3A3C8D50)
    64800000 64814000 FXSROUTE FXSROUTE.dll Sun Dec 17 09:55:03 2000 (3A3C8D77)
    648c0000 648d1000 FXSEVENT FXSEVENT.dll Sun Dec 17 09:54:59 2000 (3A3C8D73)
    64fc0000 64fca000 FXSUTIL FXSUTIL.dll Sun Dec 17 09:54:49 2000 (3A3C8D69)
    69bf0000 69c0d000 NTMARTA NTMARTA.DLL Fri Jun 20 03:44:11 2003 (3EF274FB)
    716f0000 7177a000 COMCTL32 COMCTL32.dll Tue Jul 24 03:12:20 2001 (3B5CD984)
    75020000 75028000 WS2HELP WS2HELP.DLL Tue Nov 30 09:31:09 1999 (3843995D)
    75030000 75044000 WS2_32 WS2_32.DLL Fri Jun 20 03:44:22 2003 (3EF27506)
    75050000 75058000 WSOCK32 WSOCK32.dll Fri Jun 20 03:44:22 2003 (3EF27506)
    75150000 75160000 SAMLIB SAMLIB.dll Fri Apr 08 12:54:35 2005 (425670FB)
    751c0000 751c6000 NETRAP NETRAP.dll Tue Nov 30 09:31:07 1999 (3843995B)
    759b0000 759b6000 LZ32 LZ32.DLL Fri Jun 20 03:43:46 2003 (3EF274E2)
    76620000 76630000 MPR MPR.DLL Wed Jun 21 07:52:14 2006 (4498EC9E)
    77430000 77441000 MSASN1 MSASN1.dll Fri Apr 08 12:54:30 2005 (425670F6)
    77530000 77552000 TAPI32 TAPI32.dll Fri Jun 20 03:43:42 2003 (3EF274DE)
    77800000 7781e000 WINSPOOL WINSPOOL.DRV Fri Jun 20 03:43:41 2003 (3EF274DD)
    77820000 77827000 VERSION VERSION.dll Fri Jun 20 03:43:41 2003 (3EF274DD)
    77950000 7797b000 WLDAP32 WLDAP32.DLL Fri Apr 08 12:54:29 2005 (425670F5)
    77980000 779a4000 DNSAPI DNSAPI.DLL Thu Jul 06 12:45:31 2006 (44ACF7DB)
    779b0000 77a4b000 OLEAUT32 OLEAUT32.dll Fri Jun 20 03:43:41 2003 (3EF274DD)
    77bf0000 77c01000 NTDSAPI NTDSAPI.dll Fri Jun 20 03:43:41 2003 (3EF274DD)
    77d30000 77d9f000 RPCRT4 RPCRT4.dll Thu Apr 13 06:17:06 2006 (443DDED2)
    77e10000 77e79000 USER32 USER32.dll Thu Apr 21 09:08:41 2005 (42675F89)
    77f40000 77f7c000 GDI32 GDI32.dll Thu Dec 29 13:15:55 2005 (43B3E18B)
    77f80000 77ffc000 ntdll ntdll.dll Thu Jan 13 10:09:36 2005 (41E648E0)
    78000000 78045000 MSVCRT MSVCRT.dll Tue Mar 11 18:55:17 2003 (3E6E3115)
    780c0000 7814d000 MSVCP50 MSVCP50.dll Wed Aug 20 06:13:22 1997 (33FA7CF2)
    7c2d0000 7c335000 ADVAPI32 ADVAPI32.dll Thu Apr 21 09:08:42 2005 (42675F8A)
    7c340000 7c34f000 Secur32 Secur32.dll Fri Jun 20 03:43:41 2003 (3EF274DD)
    7c570000 7c624000 KERNEL32 KERNEL32.dll Wed Jun 21 07:52:14 2006 (4498EC9E)
    7c740000 7c7cc000 CRYPT32 CRYPT32.dll Fri Apr 08 12:54:30 2005 (425670F6)
    7cdc0000 7ce10000 NETAPI32 NETAPI32.dll Fri Jul 14 14:54:58 2006 (44B7A232)
    7ce20000 7cf0f000 ole32 ole32.dll Mon Sep 05 09:18:45 2005 (431BFF65)
    7cf30000 7d176000 SHELL32 SHELL32.dll Thu Jul 13 08:09:22 2006 (44B5F1A2)
    Closing open log file c:\debuglog.txt

    ################


    thanks for the help

    Regards
     
  2. 2006/11/03
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #2

  3. to hide this advert.

  4. 2006/11/03
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    I shall try and run the memory test asap, once everyones off the system. Its just bluescreened again, this time i managed to get some of the details written down, it said:


    STOP 0x00000050 (0xE5B34000, 0x00000001, 0xB2A4BDBB, 0x00000001)

    Address B2A4BDBB base at B2A49000, DateStamp 43a0639f-C0-Mon.sys


    does that clarify anything, or what does that mean?
     
  5. 2006/11/03
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    Its now just bluescreened again.

    saying:

    BAD_POOL_CALLER
    STOP 0x000000C2 (0x00000007, 0x00000B8A, 0x87BA90C0, 0x87BA90CB)

    Whats that mean :s
     
  6. 2006/11/03
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    erm, lol, and again:

    STOP 0x00000050 (0xB4137C44, 0x00000001, 0x8044277A, 0x00000003)

    PAGE_FAULT_IN_NONPAGED_AREA

    Address 8044277A base at 80400000, Datestamp 45069e6e - ntokrnl.exe

    :s isnt looking very good
     
  7. 2006/11/03
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Is there any more info in your System log? To check your System log, go to Start > Run and type eventvwr.msc, click OK.

    Check your System log for errors.

    You can double click on any error for more details, and there is also a button to copy the error to your clipboard for easy copying & pasting.
     
    Arie,
    #6
  8. 2006/11/05
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    back in work today :( and same/more problems.

    i replaced the motherboard on friday, and similar problems are occuring. Its running more stable, and am only getting blue screen of deaths if i try and restart the server.

    Checked the Event Logs and keep seeing a similar occurence:

    "Service Control Manager - The Portable Media Serial Numbe Service terminated Unexpectedly "


    ran that debug program again, this time its come up with:

    ###################################

    qOpened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Documents and Settings\All Users\Documents\DrWatson\user.dmp]
    User Dump File: Only application data is available

    Windows 2000 Version 2195 UP Free x86 compatible
    Product: LanManNt, suite: TerminalServer SingleUserTS
    Debug session time: Sun Nov 5 12:13:58.406 2006 (GMT+0)
    System Uptime: 0 days 0:04:41.219
    Process Uptime: not available
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINNT;C:\WINNT\system32;C:\WINNT\system32\drivers
    .........
    (138c.1388): Access violation - code c0000005 (!!! second chance !!!)
    eax=00000000 ebx=00c00178 ecx=fffffff8 edx=000000d4 esi=00c01aa8 edi=00c00000
    eip=77fcb8f1 esp=0012fdfc ebp=0012fe90 iopl=0 nv up ei pl nz na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
    ntdll!RtlFreeHeap+0x227:
    77fcb8f1 663b11 cmp dx,word ptr [ecx] ds:0023:fffffff8=????
    0:000> !analyze -v;r;kv;lmtn;.logclose;q
    *** WARNING: Unable to verify checksum for Ati2evxx.exe
    *** ERROR: Module load completed but symbols could not be loaded for Ati2evxx.exe
    *******************************************************************************
    * *
    * Exception Analysis *
    * *
    *******************************************************************************

    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: ntdll!_PEB ***
    *** ***
    *************************************************************************

    FAULTING_IP:
    ntdll!RtlFreeHeap+227
    77fcb8f1 663b11 cmp dx,word ptr [ecx]

    EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
    .exr ffffffffffffffff
    ExceptionAddress: 77fcb8f1 (ntdll!RtlFreeHeap+0x00000227)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: fffffff8
    Attempt to read from address fffffff8

    FAULTING_THREAD: 00001388

    PROCESS_NAME: Ati2evxx.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: fffffff8

    BUGCHECK_STR: ACCESS_VIOLATION

    LAST_CONTROL_TRANSFER: from 00434389 to 77fcb8f1

    STACK_TEXT:
    0012fe90 00434389 00c00000 00000001 00c01ab0 ntdll!RtlFreeHeap+0x227
    WARNING: Stack unwind information not available. Following frames may be wrong.
    0012fea8 0042d2d3 00c01ab0 000001cc 00433c4f Ati2evxx+0x34389
    0012fee4 004269e0 0045bdbc 000001cc 00000000 Ati2evxx+0x2d2d3
    0012ff18 00435f06 00000000 0012ff38 00435f62 Ati2evxx+0x269e0
    00000000 00000000 00000000 00000000 00000000 Ati2evxx+0x35f06


    ADDITIONAL_DEBUG_TEXT: Enable Pageheap/AutoVerifer

    DEFAULT_BUCKET_ID: STACK_CORRUPTION

    PRIMARY_PROBLEM_CLASS: STACK_CORRUPTION

    FOLLOWUP_IP:
    Ati2evxx+34389
    00434389 5e pop esi

    SYMBOL_STACK_INDEX: 1

    SYMBOL_NAME: Ati2evxx+34389

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: Ati2evxx

    IMAGE_NAME: Ati2evxx.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 42f18561

    STACK_COMMAND: ~0s ; kb

    FAILURE_BUCKET_ID: ACCESS_VIOLATION_Ati2evxx+34389

    BUCKET_ID: ACCESS_VIOLATION_Ati2evxx+34389

    Followup: MachineOwner
    ---------

    eax=00000000 ebx=00c00178 ecx=fffffff8 edx=000000d4 esi=00c01aa8 edi=00c00000
    eip=77fcb8f1 esp=0012fdfc ebp=0012fe90 iopl=0 nv up ei pl nz na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
    ntdll!RtlFreeHeap+0x227:
    77fcb8f1 663b11 cmp dx,word ptr [ecx] ds:0023:fffffff8=????
    ChildEBP RetAddr Args to Child
    0012fe90 00434389 00c00000 00000001 00c01ab0 ntdll!RtlFreeHeap+0x227 (FPO: [Non-Fpo])
    WARNING: Stack unwind information not available. Following frames may be wrong.
    0012fea8 0042d2d3 00c01ab0 000001cc 00433c4f Ati2evxx+0x34389
    0012fee4 004269e0 0045bdbc 000001cc 00000000 Ati2evxx+0x2d2d3
    0012ff18 00435f06 00000000 0012ff38 00435f62 Ati2evxx+0x269e0
    00000000 00000000 00000000 00000000 00000000 Ati2evxx+0x35f06
    start end module name
    00400000 00462000 Ati2evxx Ati2evxx.exe Thu Aug 04 04:02:57 2005 (42F18561)
    779b0000 77a4b000 OLEAUT32 OLEAUT32.dll Fri Jun 20 03:43:41 2003 (3EF274DD)
    77d30000 77d9f000 RPCRT4 RPCRT4.dll Thu Apr 13 06:17:06 2006 (443DDED2)
    77e10000 77e79000 USER32 USER32.dll Thu Apr 21 09:08:41 2005 (42675F89)
    77f40000 77f7c000 GDI32 GDI32.dll Thu Dec 29 13:15:55 2005 (43B3E18B)
    77f80000 77ffc000 ntdll ntdll.dll Thu Jan 13 10:09:36 2005 (41E648E0)
    7c2d0000 7c335000 ADVAPI32 ADVAPI32.dll Thu Apr 21 09:08:42 2005 (42675F8A)
    7c570000 7c624000 KERNEL32 KERNEL32.dll Wed Jun 21 07:52:14 2006 (4498EC9E)
    7ce20000 7cf0f000 ole32 ole32.dll Mon Sep 05 09:18:45 2005 (431BFF65)
    Closing open log file c:\debuglog.txt


    ###################################
     
  9. 2006/11/05
    mattman

    mattman Inactive Alumni

    Joined:
    2002/06/10
    Messages:
    8,198
    Likes Received:
    63
    ERROR_CODE is the same in both debuglog reports:
    http://support.microsoft.com/kb/220946/en-us
    "Get the latest Service Pack "

    I suggest you update or reinstall the motherboard/chipset drivers, then the graphics drivers.

    Matt
     
  10. 2006/11/06
    jonesy

    jonesy Inactive Thread Starter

    Joined:
    2006/11/03
    Messages:
    6
    Likes Received:
    0
    thanks for all the help so far. I did reinstall the chipset drivers when i added the new motherboard, will do this again, and will update the ati graphics drivers too.

    checking event log keeps showing the same message on System:

    "Service Control Manager - The Portable Media Serial Numbe Service terminated Unexpectedly "

    Any ideas what thats about?

    Cheers
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.