locked
blue screen RRS feed

  • Question

  • hi, i just had a few blue screens im my laptop in the last days and i can´t find the reason...

    Nome do registo:System
    Origem:        Microsoft-Windows-Kernel-Power
    Data:          04-01-2012 00:25:19
    ID do evento:  41
    Categoria de Tarefa:(63)
    Nível:         Crítico
    Palavras-chave:(2)
    Utilizador:    SYSTEM
    Computador:    BrunoPalma-PC
    Descrição:
    O sistema foi reiniciado sem primeiro ter sido encerrado de forma correcta. Este erro poderá ser provocado por o sistema ter parado de responder, ter sofrido uma falha ou ter perdido a alimentação de forma inesperada.
    Evento Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
        <EventID>41</EventID>
        <Version>2</Version>
        <Level>1</Level>
        <Task>63</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000002</Keywords>
        <TimeCreated SystemTime="2012-01-04T00:25:19.970814900Z" />
        <EventRecordID>8132</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="8" />
        <Channel>System</Channel>
        <Computer>BrunoPalma-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="BugcheckCode">244</Data>
        <Data Name="BugcheckParameter1">0x3</Data>
        <Data Name="BugcheckParameter2">0xfffffa800619bb30</Data>
        <Data Name="BugcheckParameter3">0xfffffa800619be10</Data>
        <Data Name="BugcheckParameter4">0xfffff80002fdca00</Data>
        <Data Name="SleepInProgress">false</Data>
        <Data Name="PowerButtonTimestamp">0</Data>
      </EventData>
    </Event>

    hope somebody could help me

    thanks

     

     

    Wednesday, January 4, 2012 1:45 AM

Answers

  • The system crashed due to an IO error affecting wininit.exe. The next
    steps to troubleshoot are going to be:
     
    - Check the memory for errors
     
     
    - Check the hard drive for errors
     
     
    - Perform an offline system integrity verification
     
     
    0: kd>  !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
     
    CRITICAL_OBJECT_TERMINATION (f4)
    A process or thread crucial to system operation has unexpectedly exited or been
    terminated.
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arguments:
    Arg1: 0000000000000003, Process
    Arg2: fffffa80063acb30, Terminating object
    Arg3: fffffa80063ace10, Process image file name
    Arg4: fffff80002f80a00, Explanatory message (ascii)
     
    Debugging Details:
    ------------------
     PROCESS_OBJECT: fffffa80063acb30
     
    IMAGE_NAME:  wininit.exe
     
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
     
    MODULE_NAME: wininit
     
    FAULTING_MODULE: 0000000000000000
     
    PROCESS_NAME:  wininit.exe
     
    EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
     
    BUGCHECK_STR:  0xF4_IOERR
     
    CUSTOMER_CRASH_COUNT:  1
     
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
     
    CURRENT_IRQL:  0
     
    STACK_TEXT:
    fffff880`0a3f10a8 fffff800`03007622 : 00000000`000000f4 00000000`00000003 fffffa80`063acb30 fffffa80`063ace10 : nt!KeBugCheckEx
    fffff880`0a3f10b0 fffff800`02fb4bab : ffffffff`ffffffff fffffa80`06068660 fffffa80`063acb30 fffffa80`063acb30 : nt!PspCatchCriticalBreak+0x92
    fffff880`0a3f10f0 fffff800`02f34598 : ffffffff`ffffffff 00000000`00000001 fffffa80`063acb30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x176c6
    fffff880`0a3f1140 fffff800`02c7bf13 : fffffa80`063acb30 fffff800`c0000006 fffffa80`06068660 00000000`02920d10 : nt!NtTerminateProcess+0xf4
    fffff880`0a3f11c0 fffff800`02c784b0 : fffff800`02cc867f fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 : nt!KiSystemServiceCopyEnd+0x13
    fffff880`0a3f1358 fffff800`02cc867f : fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 00000000`76cef9d8 : nt!KiServiceLinkage
    fffff880`0a3f1360 fffff800`02c7c302 : fffff880`0a3f1b38 00000000`029a0000 fffff880`0a3f1be0 00000000`76cfbd40 : nt! ?? ::FNODOBFM::`string'+0x49874
    fffff880`0a3f1a00 fffff800`02c7ae7a : 00000000`00000000 00000000`76cb0a34 00000000`76e7e701 00000000`029a0000 : nt!KiExceptionDispatch+0xc2
    fffff880`0a3f1be0 00000000`76d78e05 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
    00000000`029212d0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76d78e05
     STACK_COMMAND:  kb
     
    FOLLOWUP_NAME:  MachineOwner
     
    FAILURE_BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
     
    BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
     
    Followup: MachineOwner
    ---------
     
    0: kd>  !process fffffa80063acb30 3
    GetPointerFromAddress: unable to read from fffff80002eaf000
    PROCESS fffffa80063acb30
        SessionId: none  Cid: 02c4    Peb: 7fffffd4000  ParentCid: 0270
        DirBase: 88224000  ObjectTable: fffff8a0021e2690  HandleCount:<Data Not Accessible>
        Image: wininit.exe
        VadRoot fffffa80051f3130 Vads 68 Clone 0 Private 420. Modified 10. Locked 2.
        DeviceMap fffff8a000008bb0
        Token                             fffff8a0021e3060
        ReadMemory error: Cannot get nt!KeMaximumIncrement value.
    fffff78000000000: Unable to get shared data
        ElapsedTime                       00:00:00.000
        UserTime                          00:00:00.000
        KernelTime                        00:00:00.000
        QuotaPoolUsage[PagedPool]         0
        QuotaPoolUsage[NonPagedPool]      0
        Working Set Sizes (now,min,max)  (1349, 50, 345) (5396KB, 200KB, 1380KB)
        PeakWorkingSetSize                1349
        VirtualSize                       49 Mb
        PeakVirtualSize                   53 Mb
        PageFaultCount                    1596
        MemoryPriority                    BACKGROUND
        BasePriority                      13
        CommitCharge                      522
             *** Error in reading nt!_ETHREAD @ fffffa8006399a50
     
    0: kd>  da fffff80002f80a00
    fffff800`02f80a00  "Terminating critical process 0x%"
    fffff800`02f80a20  "p (%s)."
     
     

    -- Mike Burr
    Technology
    • Marked as answer by Leo Huang Wednesday, January 11, 2012 2:13 AM
    Wednesday, January 4, 2012 1:15 PM

All replies

  • This is 0xF4 CRITICAL_OBJECT_TERMINATION,
     
     
    Please upload the files in c:\windows\minidump for further analysis
     
     

    -- Mike Burr
    Technology
    Wednesday, January 4, 2012 3:29 AM
  • this is the file on minidump, i just have one because yesterday a ran tuneup utilities

     

    https://skydrive.live.com/redir.aspx?cid=ce7397b3ba903da1&resid=CE7397B3BA903DA1!173&parid=CE7397B3BA903DA1!172&authkey=!ALhx1t0TdqmaTko

    Bruno Palma

    Wednesday, January 4, 2012 12:08 PM
  • this is the file on minidump, i just have one because yesterday a ran tuneup utilities

     

    https://skydrive.live.com/redir.aspx?cid=ce7397b3ba903da1&resid=CE7397B3BA903DA1!173&parid=CE7397B3BA903DA1!172&authkey=!ALhx1t0TdqmaTko

    Bruno Palma

    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    CRITICAL_OBJECT_TERMINATION (f4)
    A process or thread crucial to system operation has unexpectedly exited or been
    terminated.
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arguments:
    Arg1: 0000000000000003, Process
    Arg2: fffffa80063acb30, Terminating object
    Arg3: fffffa80063ace10, Process image file name
    Arg4: fffff80002f80a00, Explanatory message (ascii)
    Debugging Details:
    ------------------
    PROCESS_OBJECT: fffffa80063acb30
    IMAGE_NAME:  wininit.exe
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
    MODULE_NAME: wininit
    FAULTING_MODULE: 0000000000000000 
    PROCESS_NAME:  wininit.exe
    EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
    BUGCHECK_STR:  0xF4_IOERR
    CUSTOMER_CRASH_COUNT:  1
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    CURRENT_IRQL:  0
    STACK_TEXT:  
    fffff880`0a3f10a8 fffff800`03007622 : 00000000`000000f4 00000000`00000003 fffffa80`063acb30 fffffa80`063ace10 : nt!KeBugCheckEx
    fffff880`0a3f10b0 fffff800`02fb4bab : ffffffff`ffffffff fffffa80`06068660 fffffa80`063acb30 fffffa80`063acb30 : nt!PspCatchCriticalBreak+0x92
    fffff880`0a3f10f0 fffff800`02f34598 : ffffffff`ffffffff 00000000`00000001 fffffa80`063acb30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x176c6
    fffff880`0a3f1140 fffff800`02c7bf13 : fffffa80`063acb30 fffff800`c0000006 fffffa80`06068660 00000000`02920d10 : nt!NtTerminateProcess+0xf4
    fffff880`0a3f11c0 fffff800`02c784b0 : fffff800`02cc867f fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 : nt!KiSystemServiceCopyEnd+0x13
    fffff880`0a3f1358 fffff800`02cc867f : fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 00000000`76cef9d8 : nt!KiServiceLinkage
    fffff880`0a3f1360 fffff800`02c7c302 : fffff880`0a3f1b38 00000000`029a0000 fffff880`0a3f1be0 00000000`76cfbd40 : nt! ?? ::FNODOBFM::`string'+0x49874
    fffff880`0a3f1a00 fffff800`02c7ae7a : 00000000`00000000 00000000`76cb0a34 00000000`76e7e701 00000000`029a0000 : nt!KiExceptionDispatch+0xc2
    fffff880`0a3f1be0 00000000`76d78e05 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
    00000000`029212d0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76d78e05
    STACK_COMMAND:  kb
    FOLLOWUP_NAME:  MachineOwner
    FAILURE_BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
    BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
    Followup: MachineOwner
    ----------------------------------------------------------------------------------------------------------------------------------------------------------
    Please disconnect recently added hardware components and uninstall their drivers.
    Also, proceed like that:
       1- Run msconfig and disable all startup items / services except Microsoft ones
       2- Uninstall all unused programs
    Regards,


     

    MCP ✦ MCTS ✦ MCITP

    Wednesday, January 4, 2012 1:06 PM
  • The system crashed due to an IO error affecting wininit.exe. The next
    steps to troubleshoot are going to be:
     
    - Check the memory for errors
     
     
    - Check the hard drive for errors
     
     
    - Perform an offline system integrity verification
     
     
    0: kd>  !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
     
    CRITICAL_OBJECT_TERMINATION (f4)
    A process or thread crucial to system operation has unexpectedly exited or been
    terminated.
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arguments:
    Arg1: 0000000000000003, Process
    Arg2: fffffa80063acb30, Terminating object
    Arg3: fffffa80063ace10, Process image file name
    Arg4: fffff80002f80a00, Explanatory message (ascii)
     
    Debugging Details:
    ------------------
     PROCESS_OBJECT: fffffa80063acb30
     
    IMAGE_NAME:  wininit.exe
     
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
     
    MODULE_NAME: wininit
     
    FAULTING_MODULE: 0000000000000000
     
    PROCESS_NAME:  wininit.exe
     
    EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
     
    BUGCHECK_STR:  0xF4_IOERR
     
    CUSTOMER_CRASH_COUNT:  1
     
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
     
    CURRENT_IRQL:  0
     
    STACK_TEXT:
    fffff880`0a3f10a8 fffff800`03007622 : 00000000`000000f4 00000000`00000003 fffffa80`063acb30 fffffa80`063ace10 : nt!KeBugCheckEx
    fffff880`0a3f10b0 fffff800`02fb4bab : ffffffff`ffffffff fffffa80`06068660 fffffa80`063acb30 fffffa80`063acb30 : nt!PspCatchCriticalBreak+0x92
    fffff880`0a3f10f0 fffff800`02f34598 : ffffffff`ffffffff 00000000`00000001 fffffa80`063acb30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x176c6
    fffff880`0a3f1140 fffff800`02c7bf13 : fffffa80`063acb30 fffff800`c0000006 fffffa80`06068660 00000000`02920d10 : nt!NtTerminateProcess+0xf4
    fffff880`0a3f11c0 fffff800`02c784b0 : fffff800`02cc867f fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 : nt!KiSystemServiceCopyEnd+0x13
    fffff880`0a3f1358 fffff800`02cc867f : fffff880`0a3f1b38 fffff880`0a3f1890 fffff880`0a3f1be0 00000000`76cef9d8 : nt!KiServiceLinkage
    fffff880`0a3f1360 fffff800`02c7c302 : fffff880`0a3f1b38 00000000`029a0000 fffff880`0a3f1be0 00000000`76cfbd40 : nt! ?? ::FNODOBFM::`string'+0x49874
    fffff880`0a3f1a00 fffff800`02c7ae7a : 00000000`00000000 00000000`76cb0a34 00000000`76e7e701 00000000`029a0000 : nt!KiExceptionDispatch+0xc2
    fffff880`0a3f1be0 00000000`76d78e05 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
    00000000`029212d0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76d78e05
     STACK_COMMAND:  kb
     
    FOLLOWUP_NAME:  MachineOwner
     
    FAILURE_BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
     
    BUCKET_ID:  X64_0xF4_IOERR_IMAGE_wininit.exe
     
    Followup: MachineOwner
    ---------
     
    0: kd>  !process fffffa80063acb30 3
    GetPointerFromAddress: unable to read from fffff80002eaf000
    PROCESS fffffa80063acb30
        SessionId: none  Cid: 02c4    Peb: 7fffffd4000  ParentCid: 0270
        DirBase: 88224000  ObjectTable: fffff8a0021e2690  HandleCount:<Data Not Accessible>
        Image: wininit.exe
        VadRoot fffffa80051f3130 Vads 68 Clone 0 Private 420. Modified 10. Locked 2.
        DeviceMap fffff8a000008bb0
        Token                             fffff8a0021e3060
        ReadMemory error: Cannot get nt!KeMaximumIncrement value.
    fffff78000000000: Unable to get shared data
        ElapsedTime                       00:00:00.000
        UserTime                          00:00:00.000
        KernelTime                        00:00:00.000
        QuotaPoolUsage[PagedPool]         0
        QuotaPoolUsage[NonPagedPool]      0
        Working Set Sizes (now,min,max)  (1349, 50, 345) (5396KB, 200KB, 1380KB)
        PeakWorkingSetSize                1349
        VirtualSize                       49 Mb
        PeakVirtualSize                   53 Mb
        PageFaultCount                    1596
        MemoryPriority                    BACKGROUND
        BasePriority                      13
        CommitCharge                      522
             *** Error in reading nt!_ETHREAD @ fffffa8006399a50
     
    0: kd>  da fffff80002f80a00
    fffff800`02f80a00  "Terminating critical process 0x%"
    fffff800`02f80a20  "p (%s)."
     
     

    -- Mike Burr
    Technology
    • Marked as answer by Leo Huang Wednesday, January 11, 2012 2:13 AM
    Wednesday, January 4, 2012 1:15 PM