Answered by:
BSOD IRQL_NOT_EQUAL_OR_LESS_THAN

Question
-
I have a Dell Studio 1555 laptop running Win 7 home premium.
Within the last month I've been getting the BSOD IRQL_NOT_EQUAL_OR_LESS_THAN with various system files and sometimes with no file mentioned. Since November, 2009 the laptop has run flawlessly. This problems seems to have started around the 3rd of March with a Windows Update - could be a coincidence however.
I've attached a rar with several minidumps from the 16th. I am uploading the memdump to google docs for sharing should it be necessary.
Please have a look and help me with this !%cking problem!
I have SP1 installed and have used AVG 2011 boot CD to scan for root problems and virusses in general.
Thanks,
Hank
Friday, March 18, 2011 3:41 AM
Answers
-
one dumps shows AVG as possible cause. Do you use the latest AVG version?
"A programmer is just a tool which converts caffeine into code"
Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221- Marked as answer by Magon LiuModerator Wednesday, March 30, 2011 3:08 AM
Monday, March 21, 2011 9:17 PM
All replies
-
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000001236, The subtype of the bugcheck.fffff880`0395e778 fffff800`02dd505b nt!KeBugCheckEx
fffff880`0395e780 fffff880`018f9eb2 nt!MmFreePagesFromMdl+0x31b
fffff880`0395e7e0 fffff880`018f97df rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+0x4e
fffff880`0395e840 fffff880`018f84ce rdyboost!ST_STORE<SMD_TRAITS>::StDmCleanup+0x183
fffff880`0395e880 fffff880`018f7a27 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStCleanup+0x7a
fffff880`0395e8c0 fffff880`018f798a rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmStoreMgrCallback+0x4b
fffff880`0395e900 fffff880`0191e4b8 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmCleanup+0x9a
fffff880`0395e930 fffff880`018ffb26 rdyboost!SmdRBContextShutdown+0x94
fffff880`0395e970 fffff800`02ffff97 rdyboost!SmdDispatchDeviceControl+0x3ce
fffff880`0395e9d0 fffff800`030007f6 nt!IopXxxControlFile+0x607
fffff880`0395eb00 fffff800`02ce48d3 nt!NtDeviceIoControlFile+0x56
fffff880`0395eb70 00000000`76eb138a nt!KiSystemServiceCopyEnd+0x13PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Could not read faulting driver namefffff880`0274bc18 fffff800`0207e2ac nt!KeBugCheckEx
fffff880`0274bc20 fffff800`020d076e nt! ?? ::FNODOBFM::`string'+0x4621f
fffff880`0274bd80 fffff800`02121d9e nt!KiPageFault+0x16e
fffff880`0274bf18 fffff800`024d47de nt!wcsstr+0x56
fffff880`0274bf20 fffff800`024d4840 nt!SiIsWinPEBoot+0x4e
fffff880`0274bf60 fffff800`024d7942 nt!SiCheckForUfdWinpeBoot+0x30
fffff880`0274c040 fffff800`024d7a0d nt!SiCheckForAlternateSystemDisk+0x12
fffff880`0274c070 fffff800`024d978e nt!SiGetBiosSystemDisk+0x9d
fffff880`0274c0f0 fffff800`024ef457 nt!SiGetBiosSystemPartition+0x2e
fffff880`0274c140 fffff800`024d4b3a nt!SiGetSystemPartition+0x27
fffff880`0274c170 fffff800`0245a41d nt!SiGetSystemDeviceName+0x3a
fffff880`0274c1d0 fffff800`024da1f7 nt!IopRetrieveSystemDeviceName+0xac
fffff880`0274c230 fffff800`02430c99 nt!IoQuerySystemDeviceName+0x37
fffff880`0274c270 fffff800`023dc949 nt! ?? ::NNGAKEGL::`string'+0x59cdc
fffff880`0274c620 fffff800`020d18d3 nt!NtQuerySystemInformation+0x4d
fffff880`0274c660 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
fffff880`0274c7f8 fffff800`024d4aaa nt!KiServiceLinkage
fffff880`0274c800 fffff800`024d990c nt!SiQuerySystemPartitionInformation+0x7a
fffff880`0274c840 fffff800`024d9960 nt!SyspartGetSystemPartition+0x1c
fffff880`0274c870 fffff800`0253f852 nt!BiGetSystemPartition+0x20
fffff880`0274c8a0 fffff800`02550dc1 nt!BiGetSystemStorePath+0x52
fffff880`0274c8e0 fffff800`02550fb1 nt!BiLoadSystemStore+0x21
fffff880`0274c920 fffff800`02551770 nt!BiOpenSystemStore+0x101
fffff880`0274c970 fffff800`0232b8eb nt!PoInitHiberServices+0x20
fffff880`0274c9a0 fffff800`020d18d3 nt!NtInitializeRegistry+0x1ab
fffff880`0274c9f0 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
fffff880`0274cb88 fffff800`0232b7af nt!KiServiceLinkage
fffff880`0274cb90 fffff800`020d18d3 nt!NtInitializeRegistry+0x6fBAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.Child-SP RetAddr Call Site
fffff880`02fe0658 fffff800`02df74b3 nt!KeBugCheckEx
fffff880`02fe0660 fffff800`02cdf5c1 nt!ExDeferredFreePool+0xa53
fffff880`02fe0750 fffff800`030840e6 nt!IopAllocateIrpPrivate+0x241
fffff880`02fe07b0 fffff800`030844ea nt!PnpAsynchronousCall+0x36
fffff880`02fe07f0 fffff800`03086837 nt!PnpQueryDeviceRelations+0xfa
fffff880`02fe08b0 fffff800`030b6e1c nt!PipEnumerateDevice+0x117
fffff880`02fe0910 fffff800`030b7428 nt!PipProcessDevNodeTree+0x21c
fffff880`02fe0b80 fffff800`02dc6b97 nt!PiProcessReenumeration+0x98
fffff880`02fe0bd0 fffff800`02cd7a21 nt!PnpDeviceActionWorker+0x327
fffff880`02fe0c70 fffff800`02f6acce nt!ExpWorkerThread+0x111
fffff880`02fe0d00 fffff800`02cbefe6 nt!PspSystemThreadStartup+0x5a
fffff880`02fe0d40 00000000`00000000 nt!KxStartSystemThread+0x16MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a53IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx
fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69
fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260
fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5
fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7
fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25
fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a
fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd
fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13fffff800`0705b4c8 fffff800`02ce5be9 nt!KeBugCheckEx
fffff800`0705b4d0 fffff800`02ce4860 nt!KiBugCheckDispatch+0x69
fffff800`0705b610 fffff800`02cd8e99 nt!KiPageFault+0x260
fffff800`0705b7a0 fffff800`02cc7d64 nt!KiInsertQueueApc+0x1e9
fffff800`0705b7d0 fffff800`02cea29c nt!KeInsertQueueApc+0x80
fffff800`0705b830 fffff880`00dcd41a nt!IopfCompleteRequest+0xbbc
fffff800`0705b910 fffff880`00dcd242 ataport!IdeCompleteScsiIrp+0x62
fffff800`0705b940 fffff880`00dc7e32 ataport!IdeCommonCrbCompletion+0x5a
fffff800`0705b970 fffff880`00dd0805 ataport!IdeTranslateCompletedRequest+0x236
fffff800`0705baa0 fffff880`00dd0104 ataport!IdeProcessCompletedRequests+0x4d5
fffff800`0705bbd0 fffff800`02cf1b1c ataport!IdePortCompletionDpc+0x1a8
fffff800`0705bc90 fffff800`02cde36a nt!KiRetireDpcList+0x1bc
fffff800`0705bd40 00000000`00000000 nt!KiIdleLoop+0x5a
based on the dumps you have some hardware issue. Either the HDD or the RAM. So chdck the HDDs/drives you use with chkdsk /r /f and download memtest86+ [1], burn a new bootable CD (use a CD-RW if possible) from the ISO (download and use ImgBurn [2][3] to do this or make double click on the ISO in Windows 7), reboot your PC and scan your RAM 4-5hours for errors. If memtest86+ detects errors, test each module its own and replace the faulty RAM.
If the memtest tells no error, please download CPU-Z [4], look in the memory and SPD tab and verify that the current RAM Speed and the Timings match to the values that you see in the SPD tab. If your RAM run at CR (Command Rate) 1T, change the value into 2T in the BIOS.
André
[1] http://www.memtest.org/download/4.20/memtest86+-4.20.iso.zip
[2] http://www.imgburn.com/index.php?act=download
[3] http://forum.imgburn.com/index.php?showtopic=61
[4] http://www.cpuid.com/softwares/cpu-z.html
"A programmer is just a tool which converts caffeine into code"
Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221Friday, March 18, 2011 2:21 PM -
Thanks Andre.
I forgot to mention that I had run memtest.
I will check speed and post.
Update: don't trust AVG 2011. After running the boot to cd version and finding nothing more than tracking cookies, I found a file on the root of C drive called 19792079 and started digging. I then downloaded the AVG W32/Bamital. One of the things this virus does is add new memory space:
There were new memory pages created in the address space of the system process(es):
Process Name Process Filename Allocated Size spoolsv.exe %System%\spoolsv.exe 999,424 bytes spoolsv.exe %System%\spoolsv.exe 999,424 bytes After I manually removed it I ran MS Security Essentials - it found two more trojans that AVG 2011 did not find.
I'm on the previously inoperable machine typing this now. I'll go ahead with the mem speed check as suggested, but I'm pretty sure this was all virus related.
BTW, that nasty virus also turns off system restore - I had been looking for system restore points from February as a fallback and could find ZERO. It was also preventing the uninstall of applications.
The other trojans/virus that AVG 2011 missed, but MS Security Essentials discovered were Wimad.gen!I, Aluereon.DX & Clagent.B
I hope the symptoms and solution help others with this issue.
Hank
Friday, March 18, 2011 11:01 PM -
Ram check was perfect.
Hank
Friday, March 18, 2011 11:28 PM -
Well, it ran fine for a couple of hours! I just received 2 BSODs in a row and will post the minidump.
I also ran an SFC /SCANNOW and see that there are damaged files which cannot be repaired by SFC. Corrupted by the virusses? I'll post CBS.log as well.
It will take a few minutes as I'm running chkdsk /R /F - step 4 of 5 and no errors thus far.
Best,
Hank
Saturday, March 19, 2011 1:16 AM -
Minidumps from this morning:
CBS log from SFC /SCANNOW:
Thanks,
Hank
Saturday, March 19, 2011 2:45 AM -
Hi Hank,
this is the only damaged file:Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"tcpmon.ini"; source file in store is also corrupted
so replace the tcpmon.ini with the file from your Windows DVD [1].
The crash shows again HDD/IDE issues:
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.fffff800`00b9c7b8 fffff800`02c98be9 nt!KeBugCheckEx
fffff800`00b9c7c0 fffff800`02c97860 nt!KiBugCheckDispatch+0x69
fffff800`00b9c900 fffff880`00eb50e4 nt!KiPageFault+0x260
fffff800`00b9ca98 fffff880`00eae4bd ataport!memmove+0x64
fffff800`00b9caa0 fffff880`00eae104 ataport!IdeProcessCompletedRequests+0x18d
fffff800`00b9cbd0 fffff800`02ca4b1c ataport!IdePortCompletionDpc+0x1a8
fffff800`00b9cc90 fffff800`02c9136a nt!KiRetireDpcList+0x1bc
fffff800`00b9cd40 00000000`00000000 nt!KiIdleLoop+0x5a
Child-SP RetAddr Call Site
fffff880`047f6118 fffff800`02082be9 nt!KeBugCheckEx
fffff880`047f6120 fffff800`02081860 nt!KiBugCheckDispatch+0x69
fffff880`047f6260 fffff800`02080000 nt!KiPageFault+0x260
fffff880`047f63f0 00000000`00000000 nt!KiInterruptDispatchNoEOI+0x2b0
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
Check if the cables are damaged or have kinks.
André
"A programmer is just a tool which converts caffeine into code"
Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221Saturday, March 19, 2011 2:48 PM -
Andre,
Two issues with this as the real problem.
One, the hard drive connector is on the motherboard and mounted to the chassis with the HD held in place by 4 screws. As a possible resolution I have taken the HD out and put it back to reseat the connection.
Two, if I boot to a CD, such as the AVG 2011 solution running linux, the laptop will run all day without issue (it took hours to complete the full scan).
Was this the output for both minidumps? I thought one heppend in conjunction with ATAPORT.sys and one happened with no system file.
This is getting frustrating...
Sunday, March 20, 2011 6:39 AM -
this as the output from both dumps. both have the same crash type (0xD1). Have you made a memtest?
André
"A programmer is just a tool which converts caffeine into code"
Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221Sunday, March 20, 2011 2:19 PM -
I have performed memtest and 12 hours of disk checks. No issues.
I have seen a references in the event viewer to onboard controller error, memory allocation attempt at invalid page errors, cannot validate timestamp on mssmbios.sys, memory page fault "probably caused by" atapi.sys, ataport.sys, ntkrnlmp and corrupt tcpmon.iniWhat a mess (the last two you have already seen). MINIDUMPS over the last 4 days (none in 14 hours however and many fewer since removing the 4 virusses):
Loading Dump File [C:\Windows\Minidump\031611-37596-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c65000 PsLoadedModuleList = 0xfffff800`02eaae90
Debug session time: Wed Mar 16 18:21:10.299 2011 (UTC + 8:00)
System Uptime: 0 days 0:03:05.031
Loading Kernel Symbols
...............................................................
................................................................
........................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {1236, fffffa8006132b70, fffffa8006132be8, 0}
Probably caused by : rdyboost.sys ( rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+4e )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`0395e778 fffff800`02dd505b nt!KeBugCheckEx
fffff880`0395e780 fffff880`018f9eb2 nt!MmFreePagesFromMdl+0x31b
fffff880`0395e7e0 fffff880`018f97df rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+0x4e
fffff880`0395e840 fffff880`018f84ce rdyboost!ST_STORE<SMD_TRAITS>::StDmCleanup+0x183
fffff880`0395e880 fffff880`018f7a27 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStCleanup+0x7a
fffff880`0395e8c0 fffff880`018f798a rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmStoreMgrCallback+0x4b
fffff880`0395e900 fffff880`0191e4b8 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmCleanup+0x9a
fffff880`0395e930 fffff880`018ffb26 rdyboost!SmdRBContextShutdown+0x94
fffff880`0395e970 fffff800`02ffff97 rdyboost!SmdDispatchDeviceControl+0x3ce
fffff880`0395e9d0 fffff800`030007f6 nt!IopXxxControlFile+0x607
fffff880`0395eb00 fffff800`02ce48d3 nt!NtDeviceIoControlFile+0x56
fffff880`0395eb70 00000000`76eb138a nt!KiSystemServiceCopyEnd+0x13
00000000`01abe948 00000000`00000000 0x76eb138a
Loading Dump File [C:\Windows\Minidump\031611-39764-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02052000 PsLoadedModuleList = 0xfffff800`02297e90
Debug session time: Wed Mar 16 18:35:58.664 2011 (UTC + 8:00)
System Uptime: 0 days 0:00:14.305
Loading Kernel Symbols
...............................................................
..........
Loading User Symbols
Loading unloaded module list
.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff8a000628000, 0, fffff80002121d9e, 0}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt!wcsstr+56 )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`0274bc18 fffff800`0207e2ac nt!KeBugCheckEx
fffff880`0274bc20 fffff800`020d076e nt! ?? ::FNODOBFM::`string'+0x4621f
fffff880`0274bd80 fffff800`02121d9e nt!KiPageFault+0x16e
fffff880`0274bf18 fffff800`024d47de nt!wcsstr+0x56
fffff880`0274bf20 fffff800`024d4840 nt!SiIsWinPEBoot+0x4e
fffff880`0274bf60 fffff800`024d7942 nt!SiCheckForUfdWinpeBoot+0x30
fffff880`0274c040 fffff800`024d7a0d nt!SiCheckForAlternateSystemDisk+0x12
fffff880`0274c070 fffff800`024d978e nt!SiGetBiosSystemDisk+0x9d
fffff880`0274c0f0 fffff800`024ef457 nt!SiGetBiosSystemPartition+0x2e
fffff880`0274c140 fffff800`024d4b3a nt!SiGetSystemPartition+0x27
fffff880`0274c170 fffff800`0245a41d nt!SiGetSystemDeviceName+0x3a
fffff880`0274c1d0 fffff800`024da1f7 nt!IopRetrieveSystemDeviceName+0xac
fffff880`0274c230 fffff800`02430c99 nt!IoQuerySystemDeviceName+0x37
fffff880`0274c270 fffff800`023dc949 nt! ?? ::NNGAKEGL::`string'+0x59cdc
fffff880`0274c620 fffff800`020d18d3 nt!NtQuerySystemInformation+0x4d
fffff880`0274c660 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
fffff880`0274c7f8 fffff800`024d4aaa nt!KiServiceLinkage
fffff880`0274c800 fffff800`024d990c nt!SiQuerySystemPartitionInformation+0x7a
fffff880`0274c840 fffff800`024d9960 nt!SyspartGetSystemPartition+0x1c
fffff880`0274c870 fffff800`0253f852 nt!BiGetSystemPartition+0x20
fffff880`0274c8a0 fffff800`02550dc1 nt!BiGetSystemStorePath+0x52
fffff880`0274c8e0 fffff800`02550fb1 nt!BiLoadSystemStore+0x21
fffff880`0274c920 fffff800`02551770 nt!BiOpenSystemStore+0x101
fffff880`0274c970 fffff800`0232b8eb nt!PoInitHiberServices+0x20
fffff880`0274c9a0 fffff800`020d18d3 nt!NtInitializeRegistry+0x1ab
fffff880`0274c9f0 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
fffff880`0274cb88 fffff800`0232b7af nt!KiServiceLinkage
fffff880`0274cb90 fffff800`020d18d3 nt!NtInitializeRegistry+0x6f
fffff880`0274cbe0 00000000`00000000 nt!KiSystemServiceCopyEnd+0x13
Loading Dump File [C:\Windows\Minidump\031611-43461-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c4d000 PsLoadedModuleList = 0xfffff800`02e92e90
Debug session time: Wed Mar 16 03:00:19.190 2011 (UTC + 8:00)
System Uptime: 0 days 5:58:04.923
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {3, fffff80002e54c80, fffff80002e6a670, fffff80002e54c80}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+a53 )
Followup: Pool_corruption
---------
0: kd> k
Child-SP RetAddr Call Site
fffff880`02fe0658 fffff800`02df74b3 nt!KeBugCheckEx
fffff880`02fe0660 fffff800`02cdf5c1 nt!ExDeferredFreePool+0xa53
fffff880`02fe0750 fffff800`030840e6 nt!IopAllocateIrpPrivate+0x241
fffff880`02fe07b0 fffff800`030844ea nt!PnpAsynchronousCall+0x36
fffff880`02fe07f0 fffff800`03086837 nt!PnpQueryDeviceRelations+0xfa
fffff880`02fe08b0 fffff800`030b6e1c nt!PipEnumerateDevice+0x117
fffff880`02fe0910 fffff800`030b7428 nt!PipProcessDevNodeTree+0x21c
fffff880`02fe0b80 fffff800`02dc6b97 nt!PiProcessReenumeration+0x98
fffff880`02fe0bd0 fffff800`02cd7a21 nt!PnpDeviceActionWorker+0x327
fffff880`02fe0c70 fffff800`02f6acce nt!ExpWorkerThread+0x111
fffff880`02fe0d00 fffff800`02cbefe6 nt!PspSystemThreadStartup+0x5a
fffff880`02fe0d40 00000000`00000000 nt!KxStartSystemThread+0x16
Loading Dump File [C:\Windows\Minidump\031611-47985-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c5f000 PsLoadedModuleList = 0xfffff800`02ea4e90
Debug session time: Wed Mar 16 12:17:57.977 2011 (UTC + 8:00)
System Uptime: 0 days 0:02:41.709
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002cf5015}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx
fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69
fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260
fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5
fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7
fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25
fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a
fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd
fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13
00000000`000adf28 00000000`00000000 0x7777159a
Loading Dump File [C:\Windows\Minidump\031611-49733-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c55000 PsLoadedModuleList = 0xfffff800`02e9ae90
Debug session time: Wed Mar 16 17:14:00.103 2011 (UTC + 8:00)
System Uptime: 0 days 0:02:50.835
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002ceb1a6, fffff88006fea1c0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiDeliverApc+1c7 )
Followup: MachineOwner
---------
0: kd> k
Child-SP RetAddr Call Site
fffff880`06fe98f8 fffff800`02cd4be9 nt!KeBugCheckEx
fffff880`06fe9900 fffff800`02cd453c nt!KiBugCheckDispatch+0x69
fffff880`06fe9a40 fffff800`02d00f6d nt!KiSystemServiceHandler+0x7c
fffff880`06fe9a80 fffff800`02cffd45 nt!RtlpExecuteHandlerForException+0xd
fffff880`06fe9ab0 fffff800`02d10dc1 nt!RtlDispatchException+0x415
fffff880`06fea190 fffff800`02cd4cc2 nt!KiDispatchException+0x135
fffff880`06fea830 fffff800`02cd35ca nt!KiExceptionDispatch+0xc2
fffff880`06feaa10 fffff800`02ceb1a6 nt!KiGeneralProtectionFault+0x10a
fffff880`06feaba0 fffff800`02cc8cf7 nt!IopCompleteRequest+0xc76
fffff880`06feac70 fffff800`02cdab9d nt!KiDeliverApc+0x1c7
fffff880`06feacf0 fffff800`02cd9eaa nt!KiCommitThreadWait+0x3dd
fffff880`06fead80 00000000`00000000 nt!KeWaitForMultipleObjects+0x272
Loading Dump File [C:\Windows\Minidump\031611-51012-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c55000 PsLoadedModuleList = 0xfffff800`02e9ae90
Debug session time: Wed Mar 16 12:01:24.074 2011 (UTC + 8:00)
System Uptime: 0 days 0:26:46.807
Loading Kernel Symbols
...............................................................
................................................................
.................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002ceb015}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
0: kd> k
Child-SP RetAddr Call Site
fffff880`0833f558 fffff800`02cd4be9 nt!KeBugCheckEx
fffff880`0833f560 fffff800`02cd3860 nt!KiBugCheckDispatch+0x69
fffff880`0833f6a0 fffff800`02ceb015 nt!KiPageFault+0x260
fffff880`0833f830 fffff800`02cc8cf7 nt!IopCompleteRequest+0xae5
fffff880`0833f900 fffff800`02c827d5 nt!KiDeliverApc+0x1c7
fffff880`0833f980 fffff800`02f2197a nt!KiCheckForKernelApcDelivery+0x25
fffff880`0833f9b0 fffff800`02feec9e nt! ?? ::NNGAKEGL::`string'+0x2af6a
fffff880`0833faa0 fffff800`02cd48d3 nt!NtMapViewOfSection+0x2bd
fffff880`0833fb70 00000000`7756159a nt!KiSystemServiceCopyEnd+0x13
00000000`001cdb78 00000000`00000000 0x7756159a
Loading Dump File [C:\Windows\Minidump\031611-51183-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c66000 PsLoadedModuleList = 0xfffff800`02eabe90
Debug session time: Wed Mar 16 17:04:18.316 2011 (UTC + 8:00)
System Uptime: 0 days 0:13:08.048
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002cfc015}
Unable to load image \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for AVGIDSDriver.Sys
*** ERROR: Module load completed but symbols could not be loaded for AVGIDSDriver.Sys
Probably caused by : AVGIDSDriver.Sys ( AVGIDSDriver+96dc )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`0868a078 fffff800`02ce5be9 nt!KeBugCheckEx
fffff880`0868a080 fffff800`02ce4860 nt!KiBugCheckDispatch+0x69
fffff880`0868a1c0 fffff800`02cfc015 nt!KiPageFault+0x260
fffff880`0868a350 fffff800`02cd9cf7 nt!IopCompleteRequest+0xae5
fffff880`0868a420 fffff800`02ca1701 nt!KiDeliverApc+0x1c7
fffff880`0868a4a0 fffff880`055a66dc nt! ?? ::FNODOBFM::`string'+0xfd25
fffff880`0868a550 00000000`00000000 AVGIDSDriver+0x96dc
Loading Dump File [C:\Windows\Minidump\031611-51683-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c1d000 PsLoadedModuleList = 0xfffff800`02e62e90
Debug session time: Wed Mar 16 17:10:07.263 2011 (UTC + 8:00)
System Uptime: 0 days 0:04:12.996
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002cb3015}
Unable to load image \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for AVGIDSDriver.Sys
*** ERROR: Module load completed but symbols could not be loaded for AVGIDSDriver.Sys
Probably caused by : AVGIDSDriver.Sys ( AVGIDSDriver+9644 )
Followup: MachineOwner
---------
0: kd> k
Child-SP RetAddr Call Site
fffff880`0720cff8 fffff800`02c9cbe9 nt!KeBugCheckEx
fffff880`0720d000 fffff800`02c9b860 nt!KiBugCheckDispatch+0x69
fffff880`0720d140 fffff800`02cb3015 nt!KiPageFault+0x260
fffff880`0720d2d0 fffff800`02c90cf7 nt!IopCompleteRequest+0xae5
fffff880`0720d3a0 fffff800`02ca2b9d nt!KiDeliverApc+0x1c7
fffff880`0720d420 fffff800`02ca51af nt!KiCommitThreadWait+0x3dd
fffff880`0720d4b0 fffff880`063ae644 nt!KeWaitForSingleObject+0x19f
fffff880`0720d550 00000000`00000000 AVGIDSDriver+0x9644
Loading Dump File [C:\Windows\Minidump\031611-67798-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c18000 PsLoadedModuleList = 0xfffff800`02e5de90
Debug session time: Wed Mar 16 12:53:40.685 2011 (UTC + 8:00)
System Uptime: 0 days 0:34:10.417
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff88006da7738, 2, 1, fffff880010cb0e4}
Probably caused by : ataport.SYS ( ataport!memmove+64 )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`03122a28 fffff800`02c97be9 nt!KeBugCheckEx
fffff880`03122a30 fffff800`02c96860 nt!KiBugCheckDispatch+0x69
fffff880`03122b70 fffff880`010cb0e4 nt!KiPageFault+0x260
fffff880`03122d08 fffff880`010c44bd ataport!memmove+0x64
fffff880`03122d10 fffff880`010c4104 ataport!IdeProcessCompletedRequests+0x18d
fffff880`03122e40 fffff800`02ca3b1c ataport!IdePortCompletionDpc+0x1a8
fffff880`03122f00 fffff800`02c9b165 nt!KiRetireDpcList+0x1bc
fffff880`03122fb0 fffff800`02c9af7c nt!KxRetireDpcList+0x5
fffff880`08a41ba0 00000000`00000000 nt!KiDispatchInterruptContinue
Loading Dump File [C:\Windows\Minidump\031611-47985-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c5f000 PsLoadedModuleList = 0xfffff800`02ea4e90
Debug session time: Wed Mar 16 12:17:57.977 2011 (UTC + 8:00)
System Uptime: 0 days 0:02:41.709
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002cf5015}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
1: kd> k
Child-SP RetAddr Call Site
fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx
fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69
fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260
fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5
fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7
fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25
fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a
fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd
fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13
00000000`000adf28 00000000`00000000 0x7777159a
Loading Dump File [C:\Windows\Minidump\031811-31980-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02013000 PsLoadedModuleList = 0xfffff800`02258e90
Debug session time: Fri Mar 18 11:02:51.117 2011 (UTC + 8:00)
System Uptime: 0 days 0:10:48.742
Loading Kernel Symbols
...............................................................
.............................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff88004dd6738, 2, 1, fffff88000e130e4}
Probably caused by : ataport.SYS ( ataport!memmove+64 )
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\031811-49124-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c53000 PsLoadedModuleList = 0xfffff800`02e98e90
Debug session time: Fri Mar 18 19:38:04.179 2011 (UTC + 8:00)
System Uptime: 0 days 1:32:44.911
Loading Kernel Symbols
...............................................................
................................................................
.........................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff8800746e3d8, 2, 1, fffff88000e130e4}
Probably caused by : ataport.SYS ( ataport!memmove+64 )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-23587-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c59000 PsLoadedModuleList = 0xfffff800`02e9ee90
Debug session time: Sat Mar 19 11:31:12.038 2011 (UTC + 8:00)
System Uptime: 0 days 0:03:12.646
Loading Kernel Symbols
...............................................................
................................................................
.........................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 1, fffff80002cef1a6}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-24024-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02061000 PsLoadedModuleList = 0xfffff800`022a6e90
Debug session time: Sat Mar 19 11:26:31.068 2011 (UTC + 8:00)
System Uptime: 0 days 0:10:40.708
Loading Kernel Symbols
...............................................................
.............................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff880044276e8, 2, 1, fffff88000c360e4}
Probably caused by : ataport.SYS ( ataport!memmove+64 )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-24320-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c15000 PsLoadedModuleList = 0xfffff800`02e5ae90
Debug session time: Sat Mar 19 11:10:01.110 2011 (UTC + 8:00)
System Uptime: 0 days 0:47:44.843
Loading Kernel Symbols
...............................................................
................................................................
.........................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, 0, 8, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4987d )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-24960-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02066000 PsLoadedModuleList = 0xfffff800`022abe90
Debug session time: Sat Mar 19 11:14:49.824 2011 (UTC + 8:00)
System Uptime: 0 days 0:01:10.449
Loading Kernel Symbols
...............................................................
............................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88004c0d4c8, fffff88004c0cd20, fffff880012c0000}
Probably caused by : hardware ( Ntfs!NtfsRemoveHashEntry+fc )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-25755-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02003000 PsLoadedModuleList = 0xfffff800`02248e90
Debug session time: Sat Mar 19 07:45:46.799 2011 (UTC + 8:00)
System Uptime: 0 days 0:00:37.440
Loading Kernel Symbols
...............................................................
.......................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {ffffffffffffffe0, 2, 0, fffff80002080000}
Probably caused by : hardware ( nt!KiInterruptDispatchNoEOI+2b0 )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-27814-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c19000 PsLoadedModuleList = 0xfffff800`02e5ee90
Debug session time: Sat Mar 19 07:41:33.308 2011 (UTC + 8:00)
System Uptime: 0 days 1:21:32.040
Loading Kernel Symbols
...............................................................
................................................................
.........................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff880076196e8, 2, 1, fffff88000eb50e4}
Probably caused by : ataport.SYS ( ataport!memmove+64 )
Followup: MachineOwner
---------
Loading Dump File [C:\Windows\Minidump\031911-31059-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: c:\windows\minidump
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02c1b000 PsLoadedModuleList = 0xfffff800`02e60e90
Debug session time: Sat Mar 19 11:12:33.542 2011 (UTC + 8:00)
System Uptime: 0 days 0:01:22.274
Loading Kernel Symbols
...............................................................
................................................................
.......................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {0, 2, 0, fffff80002cb1015}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
Monday, March 21, 2011 4:08 AM -
one dumps shows AVG as possible cause. Do you use the latest AVG version?
"A programmer is just a tool which converts caffeine into code"
Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221- Marked as answer by Magon LiuModerator Wednesday, March 30, 2011 3:08 AM
Monday, March 21, 2011 9:17 PM