locked
BSOD IRQL_NOT_EQUAL_OR_LESS_THAN RRS feed

  • Question

  • I have a Dell Studio 1555 laptop running Win 7 home premium.

    Within the last month I've been getting the BSOD IRQL_NOT_EQUAL_OR_LESS_THAN with various system files and sometimes with no file mentioned.  Since November, 2009 the laptop has run flawlessly.  This problems seems to have started around the 3rd of March with a Windows Update - could be a coincidence however.

    I've attached a rar with several minidumps from the 16th.  I am uploading the memdump to google docs for sharing should it be necessary.

    https://docs.google.com/leaf?id=0BzEX5z5JHeHoZmU0ZmQwYmQtZjllZS00NzUzLWEyODktZmUxMDIzZWZjNmEx&hl=en&authkey=CLOi7vkO

    Please have a look and help me with this !%cking problem! 

    I have SP1 installed and have used AVG 2011 boot CD to scan for root problems and virusses in general.

    Thanks,

    Hank


    Friday, March 18, 2011 3:41 AM

Answers

  • one dumps shows AVG as possible cause. Do you use the latest AVG version?

    "A programmer is just a tool which converts caffeine into code"

    Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221
    Monday, March 21, 2011 9:17 PM

All replies

  • MEMORY_MANAGEMENT (1a)
        # Any other values for parameter 1 must be individually examined.
    Arguments:
    Arg1: 0000000000001236, The subtype of the bugcheck.

    fffff880`0395e778 fffff800`02dd505b nt!KeBugCheckEx
    fffff880`0395e780 fffff880`018f9eb2 nt!MmFreePagesFromMdl+0x31b
    fffff880`0395e7e0 fffff880`018f97df rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+0x4e
    fffff880`0395e840 fffff880`018f84ce rdyboost!ST_STORE<SMD_TRAITS>::StDmCleanup+0x183
    fffff880`0395e880 fffff880`018f7a27 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStCleanup+0x7a
    fffff880`0395e8c0 fffff880`018f798a rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmStoreMgrCallback+0x4b
    fffff880`0395e900 fffff880`0191e4b8 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmCleanup+0x9a
    fffff880`0395e930 fffff880`018ffb26 rdyboost!SmdRBContextShutdown+0x94
    fffff880`0395e970 fffff800`02ffff97 rdyboost!SmdDispatchDeviceControl+0x3ce
    fffff880`0395e9d0 fffff800`030007f6 nt!IopXxxControlFile+0x607
    fffff880`0395eb00 fffff800`02ce48d3 nt!NtDeviceIoControlFile+0x56
    fffff880`0395eb70 00000000`76eb138a nt!KiSystemServiceCopyEnd+0x13

    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except,
    it must be protected by a Probe.  Typically the address is just plain bad or it
    is pointing at freed memory.

    Could not read faulting driver name

    fffff880`0274bc18 fffff800`0207e2ac nt!KeBugCheckEx
    fffff880`0274bc20 fffff800`020d076e nt! ?? ::FNODOBFM::`string'+0x4621f
    fffff880`0274bd80 fffff800`02121d9e nt!KiPageFault+0x16e
    fffff880`0274bf18 fffff800`024d47de nt!wcsstr+0x56
    fffff880`0274bf20 fffff800`024d4840 nt!SiIsWinPEBoot+0x4e
    fffff880`0274bf60 fffff800`024d7942 nt!SiCheckForUfdWinpeBoot+0x30
    fffff880`0274c040 fffff800`024d7a0d nt!SiCheckForAlternateSystemDisk+0x12
    fffff880`0274c070 fffff800`024d978e nt!SiGetBiosSystemDisk+0x9d
    fffff880`0274c0f0 fffff800`024ef457 nt!SiGetBiosSystemPartition+0x2e
    fffff880`0274c140 fffff800`024d4b3a nt!SiGetSystemPartition+0x27
    fffff880`0274c170 fffff800`0245a41d nt!SiGetSystemDeviceName+0x3a
    fffff880`0274c1d0 fffff800`024da1f7 nt!IopRetrieveSystemDeviceName+0xac
    fffff880`0274c230 fffff800`02430c99 nt!IoQuerySystemDeviceName+0x37
    fffff880`0274c270 fffff800`023dc949 nt! ?? ::NNGAKEGL::`string'+0x59cdc
    fffff880`0274c620 fffff800`020d18d3 nt!NtQuerySystemInformation+0x4d
    fffff880`0274c660 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
    fffff880`0274c7f8 fffff800`024d4aaa nt!KiServiceLinkage
    fffff880`0274c800 fffff800`024d990c nt!SiQuerySystemPartitionInformation+0x7a
    fffff880`0274c840 fffff800`024d9960 nt!SyspartGetSystemPartition+0x1c
    fffff880`0274c870 fffff800`0253f852 nt!BiGetSystemPartition+0x20
    fffff880`0274c8a0 fffff800`02550dc1 nt!BiGetSystemStorePath+0x52
    fffff880`0274c8e0 fffff800`02550fb1 nt!BiLoadSystemStore+0x21
    fffff880`0274c920 fffff800`02551770 nt!BiOpenSystemStore+0x101
    fffff880`0274c970 fffff800`0232b8eb nt!PoInitHiberServices+0x20
    fffff880`0274c9a0 fffff800`020d18d3 nt!NtInitializeRegistry+0x1ab
    fffff880`0274c9f0 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13
    fffff880`0274cb88 fffff800`0232b7af nt!KiServiceLinkage
    fffff880`0274cb90 fffff800`020d18d3 nt!NtInitializeRegistry+0x6f

    BAD_POOL_HEADER (19)
    The pool is already corrupt at the time of the current request.
    This may or may not be due to the caller.
    The internal pool links must be walked to figure out a possible cause of
    the problem, and then special pool applied to the suspect tags or the driver
    verifier to a suspect driver.
    Arguments:
    Arg1: 0000000000000003, the pool freelist is corrupt.

    Child-SP          RetAddr           Call Site
    fffff880`02fe0658 fffff800`02df74b3 nt!KeBugCheckEx
    fffff880`02fe0660 fffff800`02cdf5c1 nt!ExDeferredFreePool+0xa53
    fffff880`02fe0750 fffff800`030840e6 nt!IopAllocateIrpPrivate+0x241
    fffff880`02fe07b0 fffff800`030844ea nt!PnpAsynchronousCall+0x36
    fffff880`02fe07f0 fffff800`03086837 nt!PnpQueryDeviceRelations+0xfa
    fffff880`02fe08b0 fffff800`030b6e1c nt!PipEnumerateDevice+0x117
    fffff880`02fe0910 fffff800`030b7428 nt!PipProcessDevNodeTree+0x21c
    fffff880`02fe0b80 fffff800`02dc6b97 nt!PiProcessReenumeration+0x98
    fffff880`02fe0bd0 fffff800`02cd7a21 nt!PnpDeviceActionWorker+0x327
    fffff880`02fe0c70 fffff800`02f6acce nt!ExpWorkerThread+0x111
    fffff880`02fe0d00 fffff800`02cbefe6 nt!PspSystemThreadStartup+0x5a
    fffff880`02fe0d40 00000000`00000000 nt!KxStartSystemThread+0x16

    MODULE_NAME: Pool_Corruption

    FAILURE_BUCKET_ID:  X64_0x19_3_nt!ExDeferredFreePool+a53

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.

    fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx
    fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69
    fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260
    fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5
    fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7
    fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25
    fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a
    fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd
    fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13

    fffff800`0705b4c8 fffff800`02ce5be9 nt!KeBugCheckEx
    fffff800`0705b4d0 fffff800`02ce4860 nt!KiBugCheckDispatch+0x69
    fffff800`0705b610 fffff800`02cd8e99 nt!KiPageFault+0x260
    fffff800`0705b7a0 fffff800`02cc7d64 nt!KiInsertQueueApc+0x1e9
    fffff800`0705b7d0 fffff800`02cea29c nt!KeInsertQueueApc+0x80
    fffff800`0705b830 fffff880`00dcd41a nt!IopfCompleteRequest+0xbbc
    fffff800`0705b910 fffff880`00dcd242 ataport!IdeCompleteScsiIrp+0x62
    fffff800`0705b940 fffff880`00dc7e32 ataport!IdeCommonCrbCompletion+0x5a
    fffff800`0705b970 fffff880`00dd0805 ataport!IdeTranslateCompletedRequest+0x236
    fffff800`0705baa0 fffff880`00dd0104 ataport!IdeProcessCompletedRequests+0x4d5
    fffff800`0705bbd0 fffff800`02cf1b1c ataport!IdePortCompletionDpc+0x1a8
    fffff800`0705bc90 fffff800`02cde36a nt!KiRetireDpcList+0x1bc
    fffff800`0705bd40 00000000`00000000 nt!KiIdleLoop+0x5a

    based on the dumps you have some hardware issue. Either the HDD or the RAM. So chdck the HDDs/drives you use with chkdsk /r /f and download memtest86+ [1], burn a new bootable CD (use a CD-RW if possible) from the ISO (download and use ImgBurn [2][3] to do this or make double click on the ISO in Windows 7), reboot your PC and scan your RAM 4-5hours for errors. If memtest86+ detects errors, test each module its own and replace the faulty RAM.

    If the memtest tells no error, please download CPU-Z [4], look in the memory and SPD tab and verify that the current RAM Speed and the Timings match to the values that you see in the SPD tab. If your RAM run at CR (Command Rate) 1T, change the value into 2T in the BIOS.

    André

    [1] http://www.memtest.org/download/4.20/memtest86+-4.20.iso.zip
    [2] http://www.imgburn.com/index.php?act=download
    [3] http://forum.imgburn.com/index.php?showtopic=61
    [4] http://www.cpuid.com/softwares/cpu-z.html


    "A programmer is just a tool which converts caffeine into code"

    Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221
    Friday, March 18, 2011 2:21 PM
  • Thanks Andre.

    I forgot to mention that I had run memtest.

    I will check speed and post. 

    Update: don't trust AVG 2011.  After running the boot to cd version and finding nothing more than tracking cookies, I found a file on the root of C drive called 19792079 and started digging.  I then downloaded the AVG W32/Bamital.  One of the things this virus does is add new memory space:

     

    There were new memory pages created in the address space of the system process(es):

    Process Name Process Filename Allocated Size
    spoolsv.exe %System%\spoolsv.exe 999,424 bytes
    spoolsv.exe %System%\spoolsv.exe 999,424 bytes

    After I manually removed it I ran MS Security Essentials - it found two more trojans that AVG 2011 did not find.

    I'm on the previously inoperable machine typing this now.  I'll go ahead with the mem speed check as suggested, but I'm pretty sure this was all virus related.

    BTW, that nasty virus also turns off system restore - I had been looking for system restore points from February as a fallback and could find ZERO.  It was also preventing the uninstall of applications.

    The other trojans/virus that AVG 2011 missed, but MS Security Essentials discovered were Wimad.gen!I, Aluereon.DX & Clagent.B

    I hope the symptoms and solution help others with this issue.

    Hank

    Friday, March 18, 2011 11:01 PM
  • Ram check was perfect.

    Hank

    Friday, March 18, 2011 11:28 PM
  • Well, it ran fine for a couple of hours!  I just received 2 BSODs in a row and will post the minidump.

    I also ran an SFC /SCANNOW and see that there are damaged files which cannot be repaired by SFC.  Corrupted by the virusses?  I'll post CBS.log as well.

    It will take a few minutes as I'm running chkdsk /R /F - step 4 of 5 and no errors thus far.

    Best,

    Hank

    Saturday, March 19, 2011 1:16 AM
  • Hi Hank,

    this is the only damaged file:

    Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"tcpmon.ini"; source file in store is also corrupted

    so replace the tcpmon.ini with the file from your Windows DVD [1].

    The crash shows again HDD/IDE issues:

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.

    fffff800`00b9c7b8 fffff800`02c98be9 nt!KeBugCheckEx
    fffff800`00b9c7c0 fffff800`02c97860 nt!KiBugCheckDispatch+0x69
    fffff800`00b9c900 fffff880`00eb50e4 nt!KiPageFault+0x260
    fffff800`00b9ca98 fffff880`00eae4bd ataport!memmove+0x64
    fffff800`00b9caa0 fffff880`00eae104 ataport!IdeProcessCompletedRequests+0x18d
    fffff800`00b9cbd0 fffff800`02ca4b1c ataport!IdePortCompletionDpc+0x1a8
    fffff800`00b9cc90 fffff800`02c9136a nt!KiRetireDpcList+0x1bc
    fffff800`00b9cd40 00000000`00000000 nt!KiIdleLoop+0x5a

    Child-SP          RetAddr           Call Site
    fffff880`047f6118 fffff800`02082be9 nt!KeBugCheckEx
    fffff880`047f6120 fffff800`02081860 nt!KiBugCheckDispatch+0x69
    fffff880`047f6260 fffff800`02080000 nt!KiPageFault+0x260
    fffff880`047f63f0 00000000`00000000 nt!KiInterruptDispatchNoEOI+0x2b0

    MODULE_NAME: hardware

    FAILURE_BUCKET_ID:  X64_IP_MISALIGNED

    Check if the cables are damaged or have kinks.

    André

    [1] http://blog.nirsoft.net/2009/09/17/how-to-extract-missing-system-files-from-the-dvd-of-windows-7vista/


    "A programmer is just a tool which converts caffeine into code"

    Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221
    Saturday, March 19, 2011 2:48 PM
  • Andre,

    Two issues with this as the real problem. 

    One, the hard drive connector is on the motherboard and mounted to the chassis with the HD held in place by 4 screws.  As a possible resolution I have taken the HD out and put it back to reseat the connection.

    Two, if I boot to a CD, such as the AVG 2011 solution running linux, the laptop will run all day without issue (it took hours to complete the full scan).

    Was this the output for both minidumps?  I thought one heppend in conjunction with ATAPORT.sys and one happened with no system file.

    This is getting frustrating...

    Sunday, March 20, 2011 6:39 AM
  • this as the output from both dumps. both have the same crash type (0xD1). Have you made a memtest?

    André

    "A programmer is just a tool which converts caffeine into code"

    Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221
    Sunday, March 20, 2011 2:19 PM
  • I have performed memtest and 12 hours of disk checks.  No issues.

    I have seen a references in the event viewer to onboard controller error, memory allocation attempt at invalid page errors, cannot validate timestamp on mssmbios.sys, memory page fault "probably caused by" atapi.sys, ataport.sys, ntkrnlmp and corrupt tcpmon.ini

    What a mess (the last two you have already seen).  MINIDUMPS over the last 4 days (none in 14 hours however and many fewer since removing the 4 virusses):

    Loading Dump File [C:\Windows\Minidump\031611-37596-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c65000 PsLoadedModuleList = 0xfffff800`02eaae90

    Debug session time: Wed Mar 16 18:21:10.299 2011 (UTC + 8:00)

    System Uptime: 0 days 0:03:05.031

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ........................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1A, {1236, fffffa8006132b70, fffffa8006132be8, 0}

    Probably caused by : rdyboost.sys ( rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+4e )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`0395e778 fffff800`02dd505b nt!KeBugCheckEx

    fffff880`0395e780 fffff880`018f9eb2 nt!MmFreePagesFromMdl+0x31b

    fffff880`0395e7e0 fffff880`018f97df rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+0x4e

    fffff880`0395e840 fffff880`018f84ce rdyboost!ST_STORE<SMD_TRAITS>::StDmCleanup+0x183

    fffff880`0395e880 fffff880`018f7a27 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStCleanup+0x7a

    fffff880`0395e8c0 fffff880`018f798a rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmStoreMgrCallback+0x4b

    fffff880`0395e900 fffff880`0191e4b8 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmCleanup+0x9a

    fffff880`0395e930 fffff880`018ffb26 rdyboost!SmdRBContextShutdown+0x94

    fffff880`0395e970 fffff800`02ffff97 rdyboost!SmdDispatchDeviceControl+0x3ce

    fffff880`0395e9d0 fffff800`030007f6 nt!IopXxxControlFile+0x607

    fffff880`0395eb00 fffff800`02ce48d3 nt!NtDeviceIoControlFile+0x56

    fffff880`0395eb70 00000000`76eb138a nt!KiSystemServiceCopyEnd+0x13

    00000000`01abe948 00000000`00000000 0x76eb138a

     

     

     

    Loading Dump File [C:\Windows\Minidump\031611-39764-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02052000 PsLoadedModuleList = 0xfffff800`02297e90

    Debug session time: Wed Mar 16 18:35:58.664 2011 (UTC + 8:00)

    System Uptime: 0 days 0:00:14.305

    Loading Kernel Symbols

    ...............................................................

    ..........

    Loading User Symbols

    Loading unloaded module list

    .

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 50, {fffff8a000628000, 0, fffff80002121d9e, 0}

     

    Could not read faulting driver name

    Probably caused by : ntkrnlmp.exe ( nt!wcsstr+56 )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`0274bc18 fffff800`0207e2ac nt!KeBugCheckEx

    fffff880`0274bc20 fffff800`020d076e nt! ?? ::FNODOBFM::`string'+0x4621f

    fffff880`0274bd80 fffff800`02121d9e nt!KiPageFault+0x16e

    fffff880`0274bf18 fffff800`024d47de nt!wcsstr+0x56

    fffff880`0274bf20 fffff800`024d4840 nt!SiIsWinPEBoot+0x4e

    fffff880`0274bf60 fffff800`024d7942 nt!SiCheckForUfdWinpeBoot+0x30

    fffff880`0274c040 fffff800`024d7a0d nt!SiCheckForAlternateSystemDisk+0x12

    fffff880`0274c070 fffff800`024d978e nt!SiGetBiosSystemDisk+0x9d

    fffff880`0274c0f0 fffff800`024ef457 nt!SiGetBiosSystemPartition+0x2e

    fffff880`0274c140 fffff800`024d4b3a nt!SiGetSystemPartition+0x27

    fffff880`0274c170 fffff800`0245a41d nt!SiGetSystemDeviceName+0x3a

    fffff880`0274c1d0 fffff800`024da1f7 nt!IopRetrieveSystemDeviceName+0xac

    fffff880`0274c230 fffff800`02430c99 nt!IoQuerySystemDeviceName+0x37

    fffff880`0274c270 fffff800`023dc949 nt! ?? ::NNGAKEGL::`string'+0x59cdc

    fffff880`0274c620 fffff800`020d18d3 nt!NtQuerySystemInformation+0x4d

    fffff880`0274c660 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13

    fffff880`0274c7f8 fffff800`024d4aaa nt!KiServiceLinkage

    fffff880`0274c800 fffff800`024d990c nt!SiQuerySystemPartitionInformation+0x7a

    fffff880`0274c840 fffff800`024d9960 nt!SyspartGetSystemPartition+0x1c

    fffff880`0274c870 fffff800`0253f852 nt!BiGetSystemPartition+0x20

    fffff880`0274c8a0 fffff800`02550dc1 nt!BiGetSystemStorePath+0x52

    fffff880`0274c8e0 fffff800`02550fb1 nt!BiLoadSystemStore+0x21

    fffff880`0274c920 fffff800`02551770 nt!BiOpenSystemStore+0x101

    fffff880`0274c970 fffff800`0232b8eb nt!PoInitHiberServices+0x20

    fffff880`0274c9a0 fffff800`020d18d3 nt!NtInitializeRegistry+0x1ab

    fffff880`0274c9f0 fffff800`020cde70 nt!KiSystemServiceCopyEnd+0x13

    fffff880`0274cb88 fffff800`0232b7af nt!KiServiceLinkage

    fffff880`0274cb90 fffff800`020d18d3 nt!NtInitializeRegistry+0x6f

    fffff880`0274cbe0 00000000`00000000 nt!KiSystemServiceCopyEnd+0x13

     

    Loading Dump File [C:\Windows\Minidump\031611-43461-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c4d000 PsLoadedModuleList = 0xfffff800`02e92e90

    Debug session time: Wed Mar 16 03:00:19.190 2011 (UTC + 8:00)

    System Uptime: 0 days 5:58:04.923

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ...............................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 19, {3, fffff80002e54c80, fffff80002e6a670, fffff80002e54c80}

    Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+a53 )

    Followup: Pool_corruption

    ---------

    0: kd> k

    Child-SP RetAddr Call Site

    fffff880`02fe0658 fffff800`02df74b3 nt!KeBugCheckEx

    fffff880`02fe0660 fffff800`02cdf5c1 nt!ExDeferredFreePool+0xa53

    fffff880`02fe0750 fffff800`030840e6 nt!IopAllocateIrpPrivate+0x241

    fffff880`02fe07b0 fffff800`030844ea nt!PnpAsynchronousCall+0x36

    fffff880`02fe07f0 fffff800`03086837 nt!PnpQueryDeviceRelations+0xfa

    fffff880`02fe08b0 fffff800`030b6e1c nt!PipEnumerateDevice+0x117

    fffff880`02fe0910 fffff800`030b7428 nt!PipProcessDevNodeTree+0x21c

    fffff880`02fe0b80 fffff800`02dc6b97 nt!PiProcessReenumeration+0x98

    fffff880`02fe0bd0 fffff800`02cd7a21 nt!PnpDeviceActionWorker+0x327

    fffff880`02fe0c70 fffff800`02f6acce nt!ExpWorkerThread+0x111

    fffff880`02fe0d00 fffff800`02cbefe6 nt!PspSystemThreadStartup+0x5a

    fffff880`02fe0d40 00000000`00000000 nt!KxStartSystemThread+0x16

     

     

     

    Loading Dump File [C:\Windows\Minidump\031611-47985-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c5f000 PsLoadedModuleList = 0xfffff800`02ea4e90

    Debug session time: Wed Mar 16 12:17:57.977 2011 (UTC + 8:00)

    System Uptime: 0 days 0:02:41.709

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ..............................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002cf5015}

    Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx

    fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69

    fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260

    fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5

    fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7

    fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25

    fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a

    fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd

    fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13

    00000000`000adf28 00000000`00000000 0x7777159a

     

     

    Loading Dump File [C:\Windows\Minidump\031611-49733-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c55000 PsLoadedModuleList = 0xfffff800`02e9ae90

    Debug session time: Wed Mar 16 17:14:00.103 2011 (UTC + 8:00)

    System Uptime: 0 days 0:02:50.835

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ...............................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 3B, {c0000005, fffff80002ceb1a6, fffff88006fea1c0, 0}

    Probably caused by : ntkrnlmp.exe ( nt!KiDeliverApc+1c7 )

    Followup: MachineOwner

    ---------

    0: kd> k

    Child-SP RetAddr Call Site

    fffff880`06fe98f8 fffff800`02cd4be9 nt!KeBugCheckEx

    fffff880`06fe9900 fffff800`02cd453c nt!KiBugCheckDispatch+0x69

    fffff880`06fe9a40 fffff800`02d00f6d nt!KiSystemServiceHandler+0x7c

    fffff880`06fe9a80 fffff800`02cffd45 nt!RtlpExecuteHandlerForException+0xd

    fffff880`06fe9ab0 fffff800`02d10dc1 nt!RtlDispatchException+0x415

    fffff880`06fea190 fffff800`02cd4cc2 nt!KiDispatchException+0x135

    fffff880`06fea830 fffff800`02cd35ca nt!KiExceptionDispatch+0xc2

    fffff880`06feaa10 fffff800`02ceb1a6 nt!KiGeneralProtectionFault+0x10a

    fffff880`06feaba0 fffff800`02cc8cf7 nt!IopCompleteRequest+0xc76

    fffff880`06feac70 fffff800`02cdab9d nt!KiDeliverApc+0x1c7

    fffff880`06feacf0 fffff800`02cd9eaa nt!KiCommitThreadWait+0x3dd

    fffff880`06fead80 00000000`00000000 nt!KeWaitForMultipleObjects+0x272

     

     

    Loading Dump File [C:\Windows\Minidump\031611-51012-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c55000 PsLoadedModuleList = 0xfffff800`02e9ae90

    Debug session time: Wed Mar 16 12:01:24.074 2011 (UTC + 8:00)

    System Uptime: 0 days 0:26:46.807

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .................................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002ceb015}

    Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

    Followup: MachineOwner

    ---------

    0: kd> k

    Child-SP RetAddr Call Site

    fffff880`0833f558 fffff800`02cd4be9 nt!KeBugCheckEx

    fffff880`0833f560 fffff800`02cd3860 nt!KiBugCheckDispatch+0x69

    fffff880`0833f6a0 fffff800`02ceb015 nt!KiPageFault+0x260

    fffff880`0833f830 fffff800`02cc8cf7 nt!IopCompleteRequest+0xae5

    fffff880`0833f900 fffff800`02c827d5 nt!KiDeliverApc+0x1c7

    fffff880`0833f980 fffff800`02f2197a nt!KiCheckForKernelApcDelivery+0x25

    fffff880`0833f9b0 fffff800`02feec9e nt! ?? ::NNGAKEGL::`string'+0x2af6a

    fffff880`0833faa0 fffff800`02cd48d3 nt!NtMapViewOfSection+0x2bd

    fffff880`0833fb70 00000000`7756159a nt!KiSystemServiceCopyEnd+0x13

    00000000`001cdb78 00000000`00000000 0x7756159a

     

     

    Loading Dump File [C:\Windows\Minidump\031611-51183-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c66000 PsLoadedModuleList = 0xfffff800`02eabe90

    Debug session time: Wed Mar 16 17:04:18.316 2011 (UTC + 8:00)

    System Uptime: 0 days 0:13:08.048

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ...............................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002cfc015}

    Unable to load image \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for AVGIDSDriver.Sys

    *** ERROR: Module load completed but symbols could not be loaded for AVGIDSDriver.Sys

    Probably caused by : AVGIDSDriver.Sys ( AVGIDSDriver+96dc )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`0868a078 fffff800`02ce5be9 nt!KeBugCheckEx

    fffff880`0868a080 fffff800`02ce4860 nt!KiBugCheckDispatch+0x69

    fffff880`0868a1c0 fffff800`02cfc015 nt!KiPageFault+0x260

    fffff880`0868a350 fffff800`02cd9cf7 nt!IopCompleteRequest+0xae5

    fffff880`0868a420 fffff800`02ca1701 nt!KiDeliverApc+0x1c7

    fffff880`0868a4a0 fffff880`055a66dc nt! ?? ::FNODOBFM::`string'+0xfd25

    fffff880`0868a550 00000000`00000000 AVGIDSDriver+0x96dc

     

     

    Loading Dump File [C:\Windows\Minidump\031611-51683-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c1d000 PsLoadedModuleList = 0xfffff800`02e62e90

    Debug session time: Wed Mar 16 17:10:07.263 2011 (UTC + 8:00)

    System Uptime: 0 days 0:04:12.996

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ...............................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002cb3015}

    Unable to load image \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for AVGIDSDriver.Sys

    *** ERROR: Module load completed but symbols could not be loaded for AVGIDSDriver.Sys

    Probably caused by : AVGIDSDriver.Sys ( AVGIDSDriver+9644 )

    Followup: MachineOwner

    ---------

    0: kd> k

    Child-SP RetAddr Call Site

    fffff880`0720cff8 fffff800`02c9cbe9 nt!KeBugCheckEx

    fffff880`0720d000 fffff800`02c9b860 nt!KiBugCheckDispatch+0x69

    fffff880`0720d140 fffff800`02cb3015 nt!KiPageFault+0x260

    fffff880`0720d2d0 fffff800`02c90cf7 nt!IopCompleteRequest+0xae5

    fffff880`0720d3a0 fffff800`02ca2b9d nt!KiDeliverApc+0x1c7

    fffff880`0720d420 fffff800`02ca51af nt!KiCommitThreadWait+0x3dd

    fffff880`0720d4b0 fffff880`063ae644 nt!KeWaitForSingleObject+0x19f

    fffff880`0720d550 00000000`00000000 AVGIDSDriver+0x9644

     

     

     

    Loading Dump File [C:\Windows\Minidump\031611-67798-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c18000 PsLoadedModuleList = 0xfffff800`02e5de90

    Debug session time: Wed Mar 16 12:53:40.685 2011 (UTC + 8:00)

    System Uptime: 0 days 0:34:10.417

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ..............................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {fffff88006da7738, 2, 1, fffff880010cb0e4}

    Probably caused by : ataport.SYS ( ataport!memmove+64 )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`03122a28 fffff800`02c97be9 nt!KeBugCheckEx

    fffff880`03122a30 fffff800`02c96860 nt!KiBugCheckDispatch+0x69

    fffff880`03122b70 fffff880`010cb0e4 nt!KiPageFault+0x260

    fffff880`03122d08 fffff880`010c44bd ataport!memmove+0x64

    fffff880`03122d10 fffff880`010c4104 ataport!IdeProcessCompletedRequests+0x18d

    fffff880`03122e40 fffff800`02ca3b1c ataport!IdePortCompletionDpc+0x1a8

    fffff880`03122f00 fffff800`02c9b165 nt!KiRetireDpcList+0x1bc

    fffff880`03122fb0 fffff800`02c9af7c nt!KxRetireDpcList+0x5

    fffff880`08a41ba0 00000000`00000000 nt!KiDispatchInterruptContinue

     

     

     

    Loading Dump File [C:\Windows\Minidump\031611-47985-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c5f000 PsLoadedModuleList = 0xfffff800`02ea4e90

    Debug session time: Wed Mar 16 12:17:57.977 2011 (UTC + 8:00)

    System Uptime: 0 days 0:02:41.709

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ..............................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002cf5015}

    Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

    Followup: MachineOwner

    ---------

    1: kd> k

    Child-SP RetAddr Call Site

    fffff880`06f53558 fffff800`02cdebe9 nt!KeBugCheckEx

    fffff880`06f53560 fffff800`02cdd860 nt!KiBugCheckDispatch+0x69

    fffff880`06f536a0 fffff800`02cf5015 nt!KiPageFault+0x260

    fffff880`06f53830 fffff800`02cd2cf7 nt!IopCompleteRequest+0xae5

    fffff880`06f53900 fffff800`02c8c7d5 nt!KiDeliverApc+0x1c7

    fffff880`06f53980 fffff800`02f2b97a nt!KiCheckForKernelApcDelivery+0x25

    fffff880`06f539b0 fffff800`02ff8c9e nt! ?? ::NNGAKEGL::`string'+0x2af6a

    fffff880`06f53aa0 fffff800`02cde8d3 nt!NtMapViewOfSection+0x2bd

    fffff880`06f53b70 00000000`7777159a nt!KiSystemServiceCopyEnd+0x13

    00000000`000adf28 00000000`00000000 0x7777159a

     

     

    Loading Dump File [C:\Windows\Minidump\031811-31980-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02013000 PsLoadedModuleList = 0xfffff800`02258e90

    Debug session time: Fri Mar 18 11:02:51.117 2011 (UTC + 8:00)

    System Uptime: 0 days 0:10:48.742

    Loading Kernel Symbols

    ...............................................................

    .............................................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {fffff88004dd6738, 2, 1, fffff88000e130e4}

    Probably caused by : ataport.SYS ( ataport!memmove+64 )

    Followup: MachineOwner

    ---------

     

     

     

    Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64

    Copyright (c) Microsoft Corporation. All rights reserved.

     

    Loading Dump File [C:\Windows\Minidump\031811-49124-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c53000 PsLoadedModuleList = 0xfffff800`02e98e90

    Debug session time: Fri Mar 18 19:38:04.179 2011 (UTC + 8:00)

    System Uptime: 0 days 1:32:44.911

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .........................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {fffff8800746e3d8, 2, 1, fffff88000e130e4}

    Probably caused by : ataport.SYS ( ataport!memmove+64 )

    Followup: MachineOwner

    ---------

     

    Loading Dump File [C:\Windows\Minidump\031911-23587-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c59000 PsLoadedModuleList = 0xfffff800`02e9ee90

    Debug session time: Sat Mar 19 11:31:12.038 2011 (UTC + 8:00)

    System Uptime: 0 days 0:03:12.646

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .........................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 1, fffff80002cef1a6}

    Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

    Followup: MachineOwner

    ---------

    Loading Dump File [C:\Windows\Minidump\031911-24024-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02061000 PsLoadedModuleList = 0xfffff800`022a6e90

    Debug session time: Sat Mar 19 11:26:31.068 2011 (UTC + 8:00)

    System Uptime: 0 days 0:10:40.708

    Loading Kernel Symbols

    ...............................................................

    .............................................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {fffff880044276e8, 2, 1, fffff88000c360e4}

    Probably caused by : ataport.SYS ( ataport!memmove+64 )

    Followup: MachineOwner

    ---------

     

    Loading Dump File [C:\Windows\Minidump\031911-24320-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c15000 PsLoadedModuleList = 0xfffff800`02e5ae90

    Debug session time: Sat Mar 19 11:10:01.110 2011 (UTC + 8:00)

    System Uptime: 0 days 0:47:44.843

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .........................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1E, {ffffffffc0000005, 0, 8, 0}

    Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4987d )

    Followup: MachineOwner

    ---------

     

     

    Loading Dump File [C:\Windows\Minidump\031911-24960-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02066000 PsLoadedModuleList = 0xfffff800`022abe90

    Debug session time: Sat Mar 19 11:14:49.824 2011 (UTC + 8:00)

    System Uptime: 0 days 0:01:10.449

    Loading Kernel Symbols

    ...............................................................

    ............................................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 24, {1904fb, fffff88004c0d4c8, fffff88004c0cd20, fffff880012c0000}

    Probably caused by : hardware ( Ntfs!NtfsRemoveHashEntry+fc )

    Followup: MachineOwner

    ---------

     

    Loading Dump File [C:\Windows\Minidump\031911-25755-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02003000 PsLoadedModuleList = 0xfffff800`02248e90

    Debug session time: Sat Mar 19 07:45:46.799 2011 (UTC + 8:00)

    System Uptime: 0 days 0:00:37.440

    Loading Kernel Symbols

    ...............................................................

    .......................................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {ffffffffffffffe0, 2, 0, fffff80002080000}

    Probably caused by : hardware ( nt!KiInterruptDispatchNoEOI+2b0 )

    Followup: MachineOwner

    ---------

     

    Loading Dump File [C:\Windows\Minidump\031911-27814-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c19000 PsLoadedModuleList = 0xfffff800`02e5ee90

    Debug session time: Sat Mar 19 07:41:33.308 2011 (UTC + 8:00)

    System Uptime: 0 days 1:21:32.040

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .........................................

    Loading User Symbols

    Loading unloaded module list

    ......

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {fffff880076196e8, 2, 1, fffff88000eb50e4}

    Probably caused by : ataport.SYS ( ataport!memmove+64 )

    Followup: MachineOwner

    ---------

     

    Loading Dump File [C:\Windows\Minidump\031911-31059-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols

    Executable search path is: c:\windows\minidump

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS Personal

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff800`02c1b000 PsLoadedModuleList = 0xfffff800`02e60e90

    Debug session time: Sat Mar 19 11:12:33.542 2011 (UTC + 8:00)

    System Uptime: 0 days 0:01:22.274

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .......................................

    Loading User Symbols

    Loading unloaded module list

    ....

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {0, 2, 0, fffff80002cb1015}

    Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

    Followup: MachineOwner

    ---------

    Monday, March 21, 2011 4:08 AM
  • one dumps shows AVG as possible cause. Do you use the latest AVG version?

    "A programmer is just a tool which converts caffeine into code"

    Want to install RSAT on Windows 7 Sp1? Check my HowTo: http://www.msfn.org/board/index.php?showtopic=150221
    Monday, March 21, 2011 9:17 PM