I am getting the following errors - possibly others.
STOP: 0x0000007E (0xFFFFFFFF0000005, 0xFFFFF800020d2d69, 0xFFFFFA6000
5AFA08, 0XFFFFFA60005AF3E0)
Stop: 0X00000050 (0XFFFFF800221C591C, 0X0000000000000000,
0XFFFFF80002319C81, 0X0000000000000002)
STOP: 0X0000001E (0XFFFFFFFFc000...5, 0XFFFFF80002094D69,
0X0000000000000000, 0XFFFFFFFFFFFFFFFF)
Sometimes the computers runs for hours, othertimes minutes.
I have run the HD diagnostics and they are ok.
I have run the built in vista memory check and on the basic and
intermediate settings it was fine. On the third level it sat for over
30 minutes on 21% and I will run it overnight.
I have the latest video drivers and all the windows updates.
Any ideas or am I up for a total reinstall?
Mark77
1: kd> !analyze -v
* Bugcheck Analysis
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffffa60010f3064, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffffa60010f3064, address which referenced memory
Debugging Details:
READ_ADDRESS: fffffa60010f3064
CURRENT_IRQL: 2
FAULTING_IP:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
CUSTOMER_CRASH_COUNT: 10
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: svchost.exe
TRAP_FRAME: fffffa6008f477e0 -- (.trap 0xfffffa6008f477e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa60010f3064 rbx=0000000000000000 rcx=fffffa6008f479b0
rdx=fffffa6008f48790 rsi=0000000000000000 rdi=0000000000000000
rip=fffffa60010f3064 rsp=fffffa6008f47978 rbp=fffffa6008f47ab0
r8=fffffa6008f481d0 r9=fffffa6008f47ab0 r10=fffffa6008f48130
r11=fffffa6008f479e8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
Ntfs!NtfsCopyReadA+0x390:
fffffa60`010f3064 53 push rbx
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020a40ee to fffff800020a4350
FAILED_INSTRUCTION_ADDRESS:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
STACK_TEXT:
fffffa60`08f47698 fffff800`020a40ee : 00000000`0000000a
fffffa60`010f3064 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffffa60`08f476a0 fffff800`020a2fcb : 00000000`00000008
fffffa60`08f48790 00000000`00000000 fffffa60`01054784 :
nt!KiBugCheckDispatch+0x6e
fffffa60`08f477e0 fffffa60`010f3064 : fffff800`020b77d8
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiPageFault+0x20b
fffffa60`08f47978 fffff800`020b77d8 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
Ntfs!NtfsCopyReadA+0x390
fffffa60`08f47980 fffff800`020b76bd : fffffa60`08f48790
fffffa60`08f48790 fffffa60`08f48130 fffffa60`010c1136 :
nt!_C_specific_handler+0x8c
fffffa60`08f479f0 fffff800`020becff : fffffa60`00000001
00000000`00000000 00000000`00000000 fffffa60`08f48790 :
nt!RtlpExecuteHandlerForException+0xd
fffffa60`08f47a20 fffff800`020bcb7e : fffffa60`08f48130
fffffa60`08f481d0 fffffa80`00000001 fffff6fc`c0014b00 :
nt!RtlDispatchException+0x22f
fffffa60`08f48110 fffff800`02317144 : 00000000`00000000
fffffa80`0a524160 00000000`00000002 00000000`01081000 :
nt!RtlRaiseStatus+0x4e
fffffa60`08f486b0 fffffa60`010c1136 : fffffa80`0a5209d0
00000000`00000000 00000000`00010000 00000000`01091000 :
nt!CcFastCopyRead+0x2e4
fffffa60`08f48790 fffffa60`00a07248 : 00000000`00000010
fffffa60`08f487f0 00000000`00010000 fffffa80`0a520a01 :
Ntfs!NtfsCopyReadA+0x1e6
fffffa60`08f48980 fffffa60`00a0a1d5 : fffffa60`08f48a60
00000000`00000000 fffffa80`0a520903 fffffa80`00000000 :
fltmgr!FltpPerformFastIoCall+0x88
fffffa60`08f489e0 fffffa60`00a24599 : 00000000`00000000
00000000`00446640 00000000`00000000 00000000`00000000 :
fltmgr!FltpPassThroughFastIo+0xb5
fffffa60`08f48a30 fffff800`0230dfba : fffffa80`0a5209d0
fffff800`00000001 fffffa80`066fd080 fffffa80`0a5209d0 :
fltmgr!FltpFastIoRead+0x1a9
fffffa60`08f48ad0 fffff800`020a3df3 : 00000000`00000228
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!NtReadFile+0x3f8
fffffa60`08f48bb0 00000000`77175ada : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`000fe9c8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x77175ada
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!NtfsCopyReadA+390
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 479190d1
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!NtfsCopyReadA+390
BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!NtfsCopyReadA+390
Followup: MachineOwner
Mark77
* Bugcheck Analysis
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffffa60010f3064, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffffa60010f3064, address which referenced memory
Debugging Details:
READ_ADDRESS: fffffa60010f3064
CURRENT_IRQL: 2
FAULTING_IP:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
CUSTOMER_CRASH_COUNT: 10
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: svchost.exe
TRAP_FRAME: fffffa6008f477e0 -- (.trap 0xfffffa6008f477e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa60010f3064 rbx=0000000000000000 rcx=fffffa6008f479b0
rdx=fffffa6008f48790 rsi=0000000000000000 rdi=0000000000000000
rip=fffffa60010f3064 rsp=fffffa6008f47978 rbp=fffffa6008f47ab0
r8=fffffa6008f481d0 r9=fffffa6008f47ab0 r10=fffffa6008f48130
r11=fffffa6008f479e8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
Ntfs!NtfsCopyReadA+0x390:
fffffa60`010f3064 53 push rbx
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020a40ee to fffff800020a4350
FAILED_INSTRUCTION_ADDRESS:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
STACK_TEXT:
fffffa60`08f47698 fffff800`020a40ee : 00000000`0000000a
fffffa60`010f3064 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffffa60`08f476a0 fffff800`020a2fcb : 00000000`00000008
fffffa60`08f48790 00000000`00000000 fffffa60`01054784 :
nt!KiBugCheckDispatch+0x6e
fffffa60`08f477e0 fffffa60`010f3064 : fffff800`020b77d8
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiPageFault+0x20b
fffffa60`08f47978 fffff800`020b77d8 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
Ntfs!NtfsCopyReadA+0x390
fffffa60`08f47980 fffff800`020b76bd : fffffa60`08f48790
fffffa60`08f48790 fffffa60`08f48130 fffffa60`010c1136 :
nt!_C_specific_handler+0x8c
fffffa60`08f479f0 fffff800`020becff : fffffa60`00000001
00000000`00000000 00000000`00000000 fffffa60`08f48790 :
nt!RtlpExecuteHandlerForException+0xd
fffffa60`08f47a20 fffff800`020bcb7e : fffffa60`08f48130
fffffa60`08f481d0 fffffa80`00000001 fffff6fc`c0014b00 :
nt!RtlDispatchException+0x22f
fffffa60`08f48110 fffff800`02317144 : 00000000`00000000
fffffa80`0a524160 00000000`00000002 00000000`01081000 :
nt!RtlRaiseStatus+0x4e
fffffa60`08f486b0 fffffa60`010c1136 : fffffa80`0a5209d0
00000000`00000000 00000000`00010000 00000000`01091000 :
nt!CcFastCopyRead+0x2e4
fffffa60`08f48790 fffffa60`00a07248 : 00000000`00000010
fffffa60`08f487f0 00000000`00010000 fffffa80`0a520a01 :
Ntfs!NtfsCopyReadA+0x1e6
fffffa60`08f48980 fffffa60`00a0a1d5 : fffffa60`08f48a60
00000000`00000000 fffffa80`0a520903 fffffa80`00000000 :
fltmgr!FltpPerformFastIoCall+0x88
fffffa60`08f489e0 fffffa60`00a24599 : 00000000`00000000
00000000`00446640 00000000`00000000 00000000`00000000 :
fltmgr!FltpPassThroughFastIo+0xb5
fffffa60`08f48a30 fffff800`0230dfba : fffffa80`0a5209d0
fffff800`00000001 fffffa80`066fd080 fffffa80`0a5209d0 :
fltmgr!FltpFastIoRead+0x1a9
fffffa60`08f48ad0 fffff800`020a3df3 : 00000000`00000228
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!NtReadFile+0x3f8
fffffa60`08f48bb0 00000000`77175ada : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`000fe9c8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x77175ada
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsCopyReadA+390
fffffa60`010f3064 53 push rbx
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!NtfsCopyReadA+390
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 479190d1
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!NtfsCopyReadA+390
BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!NtfsCopyReadA+390
Followup: MachineOwner
Mark77
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff800020d2d69,
fffffa60005afa08, fffffa60005af3e0}
Probably caused by : memory_corruption ( nt!MiUnlinkFreeOrZeroedPage+89
)
Followup: MachineOwner
2: kd> !analyze -v
* Bugcheck Analysis
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address
pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this
address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never
have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800020d2d69, The address that the exception occurred at
Arg3: fffffa60005afa08, Exception Record Address
Arg4: fffffa60005af3e0, Context Record Address
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiUnlinkFreeOrZeroedPage+89
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
EXCEPTION_RECORD: fffffa60005afa08 -- (.exr 0xfffffa60005afa08)
ExceptionAddress: fffff800020d2d69
(nt!MiUnlinkFreeOrZeroedPage+0x0000000000000089)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffffa60005af3e0 -- (.cxr 0xfffffa60005af3e0)
rax=00c00000008ce8fc rbx=fffffa8001212780 rcx=00000000001b0f69
rdx=0020000000177c2a rsi=0000000000060628 rdi=fffff800021cdbc0
rip=fffff800020d2d69 rsp=fffffa60005afc40 rbp=0000000000000001
r8=fffffa8000000008 r9=fffffa8006600000 r10=0000fffffffff000
r11=2aaaaaaaaaaaaaab r12=fffff8000205b000 r13=0000058000000000
r14=fffffa8006600600 r15=0000000000000040
iopl=0 nv up ei pl nz ac po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b
efl=00010216
nt!MiUnlinkFreeOrZeroedPage+0x89:
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
ds:002b:05fffa80`046747e8=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 9
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002284080
ffffffffffffffff
FOLLOWUP_IP:
nt!MiUnlinkFreeOrZeroedPage+89
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff800020a4356 to fffff800020d2d69
STACK_TEXT:
fffffa60`005afc40 fffff800`020a4356 : 00000000`00000028
00000000`0000003f 00000000`00000000 fffff800`0081da40 :
nt!MiUnlinkFreeOrZeroedPage+0x89
fffffa60`005afc80 fffff800`0249cb1e : 01c85e33`00000000
fffffa80`00000000 00000000`00000000 fffff800`024eb000 :
nt!MmZeroPageThread+0x276
fffffa60`005afd20 fffff800`022d2ff3 : 002e0070`00630061
fffff800`020ea539 00000000`00000010 00000000`00000286 :
nt!Phase1Initialization+0xe
fffffa60`005afd50 fffff800`020ea546 : fffff800`021cf680
fffffa80`066c24c0 fffff800`021d4b80 fffff800`0081da40 :
nt!PspSystemThreadStartup+0x57
fffffa60`005afd80 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiUnlinkFreeOrZeroedPage+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
STACK_COMMAND: .cxr 0xfffffa60005af3e0 ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x7E_nt!MiUnlinkFreeOrZeroedPage+89
BUCKET_ID: X64_0x7E_nt!MiUnlinkFreeOrZeroedPage+89
Followup: MachineOwner
Mark77
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff800020d2d69,
fffffa60005afa08, fffffa60005af3e0}
Probably caused by : memory_corruption ( nt!MiUnlinkFreeOrZeroedPage+89
)
Followup: MachineOwner
2: kd> !analyze -v
* Bugcheck Analysis
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address
pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this
address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never
have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800020d2d69, The address that the exception occurred at
Arg3: fffffa60005afa08, Exception Record Address
Arg4: fffffa60005af3e0, Context Record Address
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiUnlinkFreeOrZeroedPage+89
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
EXCEPTION_RECORD: fffffa60005afa08 -- (.exr 0xfffffa60005afa08)
ExceptionAddress: fffff800020d2d69
(nt!MiUnlinkFreeOrZeroedPage+0x0000000000000089)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffffa60005af3e0 -- (.cxr 0xfffffa60005af3e0)
rax=00c00000008ce8fc rbx=fffffa8001212780 rcx=00000000001b0f69
rdx=0020000000177c2a rsi=0000000000060628 rdi=fffff800021cdbc0
rip=fffff800020d2d69 rsp=fffffa60005afc40 rbp=0000000000000001
r8=fffffa8000000008 r9=fffffa8006600000 r10=0000fffffffff000
r11=2aaaaaaaaaaaaaab r12=fffff8000205b000 r13=0000058000000000
r14=fffffa8006600600 r15=0000000000000040
iopl=0 nv up ei pl nz ac po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b
efl=00010216
nt!MiUnlinkFreeOrZeroedPage+0x89:
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
ds:002b:05fffa80`046747e8=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 9
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002284080
ffffffffffffffff
FOLLOWUP_IP:
nt!MiUnlinkFreeOrZeroedPage+89
fffff800`020d2d69 49890cc0 mov qword ptr [r8+rax*8],rcx
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff800020a4356 to fffff800020d2d69
STACK_TEXT:
fffffa60`005afc40 fffff800`020a4356 : 00000000`00000028
00000000`0000003f 00000000`00000000 fffff800`0081da40 :
nt!MiUnlinkFreeOrZeroedPage+0x89
fffffa60`005afc80 fffff800`0249cb1e : 01c85e33`00000000
fffffa80`00000000 00000000`00000000 fffff800`024eb000 :
nt!MmZeroPageThread+0x276
fffffa60`005afd20 fffff800`022d2ff3 : 002e0070`00630061
fffff800`020ea539 00000000`00000010 00000000`00000286 :
nt!Phase1Initialization+0xe
fffffa60`005afd50 fffff800`020ea546 : fffff800`021cf680
fffffa80`066c24c0 fffff800`021d4b80 fffff800`0081da40 :
nt!PspSystemThreadStartup+0x57
fffffa60`005afd80 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiUnlinkFreeOrZeroedPage+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
STACK_COMMAND: .cxr 0xfffffa60005af3e0 ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x7E_nt!MiUnlinkFreeOrZeroedPage+89
BUCKET_ID: X64_0x7E_nt!MiUnlinkFreeOrZeroedPage+89
Followup: MachineOwner
Mark77
1E
2: kd> !analyze -v
* Bugcheck Analysis
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address
pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this
address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800020dcdf2, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiUnlinkFreeOrZeroedPage+112
fffff800`020dcdf2 4c095028 or qword ptr [rax+28h],r10
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff8000228e080
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 3
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002093e47 to fffff800020ba350
STACK_TEXT:
fffffa60`0935e128 fffff800`02093e47 : 00000000`0000001e
ffffffff`c0000005 fffff800`020dcdf2 00000000`00000000 : nt!KeBugCheckEx
fffffa60`0935e130 fffff800`020ba1a9 : fffffa60`0935e868
fffffa80`01031400 fffffa60`0935e910 00000000`000565c0 : nt! ??
::FNODOBFM::`string'+0x29317
fffffa60`0935e730 fffff800`020b8d8d : 00000000`0723aa00
00000000`00000000 00000000`00000000 fffff700`01080000 :
nt!KiExceptionDispatch+0xa9
fffffa60`0935e910 fffff800`020dcdf2 : fffffa80`0a23c928
fffff700`01080000 fffffa60`0935eba0 fffff800`020edf4e :
nt!KiGeneralProtectionFault+0xcd
fffffa60`0935eaa0 fffff800`020dcaca : 00000000`00000000
00000000`00000000 00000000`00000000 fffff700`01080000 :
nt!MiUnlinkFreeOrZeroedPage+0x112
fffffa60`0935eae0 fffff800`020ca4cb : fffffa80`0a247060
00000000`00000000 fffff680`00043938 fffffa80`0a247060 :
nt!MiRemoveAnyPage+0xda
fffffa60`0935eb30 fffff800`020b8ed9 : 00000000`00000001
fffffa60`0935eca0 fffffa60`0935ea01 00000000`00000000 :
nt!MmAccessFault+0x24db
fffffa60`0935ec20 000007fe`fe1713da : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiPageFault+0x119
00000000`0311d368 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fe1713da
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkFreeOrZeroedPage+112
fffff800`020dcdf2 4c095028 or qword ptr [rax+28h],r10
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MiUnlinkFreeOrZeroedPage+112
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!MiUnlinkFreeOrZeroedPage+112
BUCKET_ID: X64_0x1E_nt!MiUnlinkFreeOrZeroedPage+112
Followup: MachineOwner
Mark77
2: kd> !analyze -v
* Bugcheck Analysis
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address
pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this
address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800020dcdf2, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx
referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiUnlinkFreeOrZeroedPage+112
fffff800`020dcdf2 4c095028 or qword ptr [rax+28h],r10
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff8000228e080
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 3
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002093e47 to fffff800020ba350
STACK_TEXT:
fffffa60`0935e128 fffff800`02093e47 : 00000000`0000001e
ffffffff`c0000005 fffff800`020dcdf2 00000000`00000000 : nt!KeBugCheckEx
fffffa60`0935e130 fffff800`020ba1a9 : fffffa60`0935e868
fffffa80`01031400 fffffa60`0935e910 00000000`000565c0 : nt! ??
::FNODOBFM::`string'+0x29317
fffffa60`0935e730 fffff800`020b8d8d : 00000000`0723aa00
00000000`00000000 00000000`00000000 fffff700`01080000 :
nt!KiExceptionDispatch+0xa9
fffffa60`0935e910 fffff800`020dcdf2 : fffffa80`0a23c928
fffff700`01080000 fffffa60`0935eba0 fffff800`020edf4e :
nt!KiGeneralProtectionFault+0xcd
fffffa60`0935eaa0 fffff800`020dcaca : 00000000`00000000
00000000`00000000 00000000`00000000 fffff700`01080000 :
nt!MiUnlinkFreeOrZeroedPage+0x112
fffffa60`0935eae0 fffff800`020ca4cb : fffffa80`0a247060
00000000`00000000 fffff680`00043938 fffffa80`0a247060 :
nt!MiRemoveAnyPage+0xda
fffffa60`0935eb30 fffff800`020b8ed9 : 00000000`00000001
fffffa60`0935eca0 fffffa60`0935ea01 00000000`00000000 :
nt!MmAccessFault+0x24db
fffffa60`0935ec20 000007fe`fe1713da : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiPageFault+0x119
00000000`0311d368 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fe1713da
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkFreeOrZeroedPage+112
fffff800`020dcdf2 4c095028 or qword ptr [rax+28h],r10
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MiUnlinkFreeOrZeroedPage+112
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!MiUnlinkFreeOrZeroedPage+112
BUCKET_ID: X64_0x1E_nt!MiUnlinkFreeOrZeroedPage+112
Followup: MachineOwner
Mark77
PAGE_FAULT_IN_NONPAGED_AREA (50)
........
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff800221c591c, 0, fffff80002319c81, 2}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt!NtQuerySystemInformation+441 )
Followup: MachineOwner
1: kd> !analyze -v
* Bugcheck Analysis
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain
bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff800221c591c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002319c81, If non-zero, the instruction address which
referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002278080
fffff800221c591c
FAULTING_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 6
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: OIS.EXE
CURRENT_IRQL: 0
TRAP_FRAME: fffffa600b6817d0 -- (.trap 0xfffffa600b6817d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000001 rcx=fffff800021c3680
rdx=fffff80002278640 rsi=0000000075813380 rdi=fffff800023397a7
rip=fffff80002319c81 rsp=fffffa600b681960 rbp=fffffa600b681ca0
r8=0000000000000000 r9=000000000079ee63 r10=0000000000001a16
r11=00000000000c6bb6 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!NtQuerySystemInformation+0x441:
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
ds:4c10:fffff800`021c591c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020b2524 to fffff800020a4350
STACK_TEXT:
fffffa60`0b6816d8 fffff800`020b2524 : 00000000`00000050
fffff800`221c591c 00000000`00000000 fffffa60`0b6817d0 : nt!KeBugCheckEx
fffffa60`0b6816e0 fffff800`020a2ed9 : 00000000`00000000
fffffa60`0b681940 fffffa60`0b681800 00000000`00000000 :
nt!MmAccessFault+0x534
fffffa60`0b6817d0 fffff800`02319c81 : 00000000`00000001
00000000`00000001 00000000`00000001 fffffa60`0b681c01 :
nt!KiPageFault+0x119
fffffa60`0b681960 fffff800`020a3df3 : fffffa80`08197720
00000000`00000000 00000000`0007e558 00000000`0007e578 :
nt!NtQuerySystemInformation+0x441
fffffa60`0b681c20 00000000`776b5dda : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`0007e4e8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x776b5dda
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!NtQuerySystemInformation+441
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
Followup: MachineOwner
Mark77
........
* Bugcheck Analysis
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff800221c591c, 0, fffff80002319c81, 2}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt!NtQuerySystemInformation+441 )
Followup: MachineOwner
1: kd> !analyze -v
* Bugcheck Analysis
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain
bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff800221c591c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002319c81, If non-zero, the instruction address which
referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002278080
fffff800221c591c
FAULTING_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 6
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: OIS.EXE
CURRENT_IRQL: 0
TRAP_FRAME: fffffa600b6817d0 -- (.trap 0xfffffa600b6817d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000001 rcx=fffff800021c3680
rdx=fffff80002278640 rsi=0000000075813380 rdi=fffff800023397a7
rip=fffff80002319c81 rsp=fffffa600b681960 rbp=fffffa600b681ca0
r8=0000000000000000 r9=000000000079ee63 r10=0000000000001a16
r11=00000000000c6bb6 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!NtQuerySystemInformation+0x441:
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
ds:4c10:fffff800`021c591c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020b2524 to fffff800020a4350
STACK_TEXT:
fffffa60`0b6816d8 fffff800`020b2524 : 00000000`00000050
fffff800`221c591c 00000000`00000000 fffffa60`0b6817d0 : nt!KeBugCheckEx
fffffa60`0b6816e0 fffff800`020a2ed9 : 00000000`00000000
fffffa60`0b681940 fffffa60`0b681800 00000000`00000000 :
nt!MmAccessFault+0x534
fffffa60`0b6817d0 fffff800`02319c81 : 00000000`00000001
00000000`00000001 00000000`00000001 fffffa60`0b681c01 :
nt!KiPageFault+0x119
fffffa60`0b681960 fffff800`020a3df3 : fffffa80`08197720
00000000`00000000 00000000`0007e558 00000000`0007e578 :
nt!NtQuerySystemInformation+0x441
fffffa60`0b681c20 00000000`776b5dda : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`0007e4e8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x776b5dda
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!NtQuerySystemInformation+441
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
Followup: MachineOwner
Mark77
PAGE_FAULT_IN_NONPAGED_AREA (50)
1: kd> !analyze -v
* Bugcheck Analysis
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain
bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff800221c591c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002319c81, If non-zero, the instruction address which
referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002278080
fffff800221c591c
FAULTING_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 6
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: OIS.EXE
CURRENT_IRQL: 0
TRAP_FRAME: fffffa600b6817d0 -- (.trap 0xfffffa600b6817d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000001 rcx=fffff800021c3680
rdx=fffff80002278640 rsi=0000000075813380 rdi=fffff800023397a7
rip=fffff80002319c81 rsp=fffffa600b681960 rbp=fffffa600b681ca0
r8=0000000000000000 r9=000000000079ee63 r10=0000000000001a16
r11=00000000000c6bb6 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!NtQuerySystemInformation+0x441:
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
ds:4c10:fffff800`021c591c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020b2524 to fffff800020a4350
STACK_TEXT:
fffffa60`0b6816d8 fffff800`020b2524 : 00000000`00000050
fffff800`221c591c 00000000`00000000 fffffa60`0b6817d0 : nt!KeBugCheckEx
fffffa60`0b6816e0 fffff800`020a2ed9 : 00000000`00000000
fffffa60`0b681940 fffffa60`0b681800 00000000`00000000 :
nt!MmAccessFault+0x534
fffffa60`0b6817d0 fffff800`02319c81 : 00000000`00000001
00000000`00000001 00000000`00000001 fffffa60`0b681c01 :
nt!KiPageFault+0x119
fffffa60`0b681960 fffff800`020a3df3 : fffffa80`08197720
00000000`00000000 00000000`0007e558 00000000`0007e578 :
nt!NtQuerySystemInformation+0x441
fffffa60`0b681c20 00000000`776b5dda : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`0007e4e8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x776b5dda
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!NtQuerySystemInformation+441
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
Followup: MachineOwner
Mark77
1: kd> !analyze -v
* Bugcheck Analysis
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain
bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff800221c591c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002319c81, If non-zero, the instruction address which
referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from
fffff80002278080
fffff800221c591c
FAULTING_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 6
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: OIS.EXE
CURRENT_IRQL: 0
TRAP_FRAME: fffffa600b6817d0 -- (.trap 0xfffffa600b6817d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000001 rcx=fffff800021c3680
rdx=fffff80002278640 rsi=0000000075813380 rdi=fffff800023397a7
rip=fffff80002319c81 rsp=fffffa600b681960 rbp=fffffa600b681ca0
r8=0000000000000000 r9=000000000079ee63 r10=0000000000001a16
r11=00000000000c6bb6 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!NtQuerySystemInformation+0x441:
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
ds:4c10:fffff800`021c591c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800020b2524 to fffff800020a4350
STACK_TEXT:
fffffa60`0b6816d8 fffff800`020b2524 : 00000000`00000050
fffff800`221c591c 00000000`00000000 fffffa60`0b6817d0 : nt!KeBugCheckEx
fffffa60`0b6816e0 fffff800`020a2ed9 : 00000000`00000000
fffffa60`0b681940 fffffa60`0b681800 00000000`00000000 :
nt!MmAccessFault+0x534
fffffa60`0b6817d0 fffff800`02319c81 : 00000000`00000001
00000000`00000001 00000000`00000001 fffffa60`0b681c01 :
nt!KiPageFault+0x119
fffffa60`0b681960 fffff800`020a3df3 : fffffa80`08197720
00000000`00000000 00000000`0007e558 00000000`0007e578 :
nt!NtQuerySystemInformation+0x441
fffffa60`0b681c20 00000000`776b5dda : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSystemServiceCopyEnd+0x13
00000000`0007e4e8 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 : 0x776b5dda
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!NtQuerySystemInformation+441
fffff800`02319c81 8b819c220000 mov eax,dword ptr [rcx+229Ch]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!NtQuerySystemInformation+441
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
BUCKET_ID: X64_0x50_nt!NtQuerySystemInformation+441
Followup: MachineOwner
Mark77
- Windows XP
Replies: 8
09-29-2009 06:09 PM
vBulletin, Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.3.1 © 2009, Crawlability, Inc.
LinkBacks Enabled by vBSEO 3.3.1 © 2009, Crawlability, Inc.
©2009 TechAsk.com, All Rights Reserved.



None



