locked
Need urgent help!!! RRS feed

  • Question

  • Hello, I am writing in this forum again because isnot any other forum who can provide me support on this. I have previously posted my problems in this forum:

    http://social.technet.microsoft.com/Forums/en-US/w7itproperf/thread/cdf1136d-2dd9-4479-8283-0ae287426f80

    and my problem didnt go away it became worse.

    Isnt there anyway to help me in this forum? I am losing valuable data for this BSODs. Here are the latest problems:

    https://skydrive.live.com/#!/?cid=01923c48eef0ea71&sc=documents&uc=5&id=1923C48EEF0EA71%21103

    Tuesday, October 18, 2011 4:00 PM

All replies

  • *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except,
    it must be protected by a Probe.  Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: fffff88009812528, memory referenced.
    Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
    Arg3: fffff880012f35d2, If non-zero, the instruction address which referenced the bad memory
    address.
    Arg4: 0000000000000002, (reserved)
    Debugging Details:
    ------------------
    Could not read faulting driver name
    *** WARNING: Unable to verify timestamp for win32k.sys
    *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
    READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800034cd100
     fffff88009812528 
    FAULTING_IP: 
    Ntfs!NtfsCommonCreate+209b
    fffff880`012f35d2 f6838800000210  test    byte ptr [rbx+2000088h],10h
    MM_INTERNAL_CODE:  2
    CUSTOMER_CRASH_COUNT:  1
    DEFAULT_BUCKET_ID:  CODE_CORRUPTION
    BUGCHECK_STR:  0x50
    PROCESS_NAME:  hsswd.exe
    CURRENT_IRQL:  0
    TRAP_FRAME:  fffff88007811f60 -- (.trap 0xfffff88007811f60)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=fffff8a002e9b390 rbx=0000000000000000 rcx=fffff8a002e08010
    rdx=7fffffffffffffff rsi=0000000000000000 rdi=0000000000000000
    rip=fffff880012f35d2 rsp=fffff880078120f0 rbp=fffffa8004987c10
     r8=fffffa80048c0ea8  r9=0000000000000000 r10=0000000000000000
    r11=fffff880078120d0 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei pl nz na po nc
    Ntfs!NtfsCommonCreate+0x209b:
    fffff880`012f35d2 f6838800000210  test    byte ptr [rbx+2000088h],10h ds:00000000`02000088=??
    Resetting default scope
    LAST_CONTROL_TRANSFER:  from fffff800032453f0 to fffff8000329ac40
    STACK_TEXT:  
    fffff880`07811df8 fffff800`032453f0 : 00000000`00000050 fffff880`09812528 00000000`00000000 fffff880`07811f60 : nt!KeBugCheckEx
    fffff880`07811e00 fffff800`03298d6e : 00000000`00000000 fffff880`09812528 fffff880`07811f00 fffff880`078124a0 : nt! ?? ::FNODOBFM::`string'+0x447c6
    fffff880`07811f60 fffff880`012f35d2 : fffffa80`048c0d50 fffff880`078124a0 fffff880`078124a0 fffffa80`048c0d50 : nt!KiPageFault+0x16e
    fffff880`078120f0 fffff880`0125aa3d : fffffa80`048c0d50 fffffa80`04987c10 fffff880`078124a0 00000000`00000000 : Ntfs!NtfsCommonCreate+0x209b
    fffff880`078122d0 fffff800`032a7618 : fffff880`07812410 00000000`00000000 fffff8a0`0b9df750 00000000`00000170 : Ntfs!NtfsCommonCreateCallout+0x1d
    fffff880`07812300 fffff880`0125b1bf : fffff880`0125aa20 fffff880`0125a020 00000000`00000000 fffff880`012fbf00 : nt!KeExpandKernelStackAndCalloutEx+0xd8
    fffff880`078123e0 fffff880`012f499c : 00000000`00000000 00000000`00000000 fffff880`07812640 fffffa80`04987c10 : Ntfs!NtfsCommonCreateOnNewStack+0x4f
    fffff880`07812440 fffff880`010e6bcf : fffffa80`04e9b030 fffffa80`04987c10 00000000`00000000 fffffa80`04d0a060 : Ntfs!NtfsFsdCreate+0x1ac
    fffff880`078125f0 fffff880`011062b9 : fffffa80`04987c10 fffffa80`04ea7800 fffffa80`04987c00 fffffa80`04d0a060 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
    fffff880`07812680 fffff800`03598f95 : 00000000`00000005 fffffa80`0419a1c8 fffffa80`07d75010 00000000`00000000 : fltmgr!FltpCreate+0x2a9
    fffff880`07812730 fffff800`03595838 : fffffa80`04a83cd0 fffff800`00000000 fffffa80`0419a010 fffffa80`00000001 : nt!IopParseDevice+0x5a5
    fffff880`078128c0 fffff800`03596a56 : 00000000`00000000 fffffa80`0419a010 fffff8a0`00000000 fffffa80`03bce290 : nt!ObpLookupObjectName+0x588
    fffff880`078129b0 fffff800`0359835c : 00000000`00000400 00000000`00000000 fffff880`07812b01 fffff880`00000001 : nt!ObOpenObjectByName+0x306
    fffff880`07812a80 fffff800`03583be4 : 00000000`0022e548 fffff880`00100001 00000000`0022eda0 00000000`0022e4e8 : nt!IopCreateFile+0x2bc
    fffff880`07812b20 fffff800`03299ed3 : fffffa80`05746060 00000000`0022ee18 fffff880`07812bc8 fffff800`035924f4 : nt!NtOpenFile+0x58
    fffff880`07812bb0 00000000`7799164a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`0022e4a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7799164a
    STACK_COMMAND:  kb
    CHKIMG_EXTENSION: !chkimg -lo 50 -db !Ntfs
    3 errors : !Ntfs (fffff880012f32c7-fffff880012f36d7)
    fffff880012f32c0  02  66  89  42  58  48  8b *c3  30  48  8b  48  60  44  0f  b7 .f.BXH..0H.H`D..
    ...
    fffff880012f35d0  04  01  f6  83  88  00  00 *02  10  0f  85  2f  a3  05  00  4c .........../...L
    ...
    fffff880012f36d0  70  85  ff  41  0f  99  c5 *46  89  6c  24  20  41  b1  01  44 p..A...F.l$ A..D
    MODULE_NAME: memory_corruption
    IMAGE_NAME:  memory_corruption
    FOLLOWUP_NAME:  memory_corruption
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
    MEMORY_CORRUPTOR:  STRIDE
    FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_STRIDE
    BUCKET_ID:  X64_MEMORY_CORRUPTION_STRIDE
    Followup: memory_corruption
    ---------
    -------------------------------------------------------------------
    Run chkdsk /r /f and check results. More in the article I gave.
    The BSOD occured when hostspot shield was running: http://www.whatisexe.com/process/hsswd.exe.html
    Please uninstall it and check again.

    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

    Microsoft Student Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator: Security
    Microsoft Certified Systems Engineer: Security
    Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows 7, Configuring
    Microsoft Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

    Tuesday, October 18, 2011 11:15 PM
  • Here are the latest log files seems like the previous issues were solved but got new issues again:

    https://skydrive.live.com/#!/?cid=01923c48eef0ea71&sc=documents&uc=5&id=1923C48EEF0EA71%21103

    Friday, October 21, 2011 10:23 PM
  • For the last dump, it occued when gom.exe was running: http://www.processlibrary.com/directory/files/gom/405696/

    Please uninstall it and check results.

    Also, update all possible drivers and run memtest86+ to check there is a problem with your RAM. If an error was detected then replace your faulty RAM or contact your manufacturer Technical Support.

     


    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

    Microsoft Student Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator: Security
    Microsoft Certified Systems Engineer: Security
    Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows 7, Configuring
    Microsoft Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

    • Proposed as answer by zhen tan Monday, October 24, 2011 2:15 AM
    Saturday, October 22, 2011 1:52 PM
  • https://skydrive.live.com/?cid=01923c48eef0ea71&sc=documents&uc=5&id=1923C48EEF0EA71%21103#

    what is the file that is causing the error this time?
    Wednesday, October 26, 2011 4:54 PM
  • *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    KMODE_EXCEPTION_NOT_HANDLED (1e)
    This is a very common bugcheck.  Usually the exception address pinpoints
    the driver/function that caused the problem.  Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: ffffffffc000001d, The exception code that was not handled
    Arg2: fffff88001356c31, The address that the exception occurred at
    Arg3: 0000000000000000, Parameter 0 of the exception
    Arg4: 000000002d8a0000, Parameter 1 of the exception
    Debugging Details:
    ------------------
    EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION}  Illegal Instruction  An attempt was made to execute an illegal instruction.
    FAULTING_IP: 
    Ntfs!NtfsMoveLinkToNewDir+201
    fffff880`01356c31 ff              ???
    EXCEPTION_PARAMETER1:  0000000000000000
    EXCEPTION_PARAMETER2:  000000002d8a0000
    ERROR_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION}  Illegal Instruction  An attempt was made to execute an illegal instruction.
    BUGCHECK_STR:  0x1E_c000001d
    CUSTOMER_CRASH_COUNT:  1
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    PROCESS_NAME:  explorer.exe
    CURRENT_IRQL:  0
    LAST_CONTROL_TRANSFER:  from fffff8000331c588 to fffff800032d0c40
    FAILED_INSTRUCTION_ADDRESS: 
    Ntfs!NtfsMoveLinkToNewDir+201
    fffff880`01356c31 ff              ???
    STACK_TEXT:  
    fffff880`08328a28 fffff800`0331c588 : 00000000`0000001e ffffffff`c000001d fffff880`01356c31 00000000`00000000 : nt!KeBugCheckEx
    fffff880`08328a30 fffff800`032d02c2 : fffff880`08329208 fffff8a0`09b75010 fffff880`083292b0 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4977d
    fffff880`083290d0 fffff800`032ce41f : fffff880`083292b0 fffff980`11223c00 fffff980`11223c00 fffff980`00000000 : nt!KiExceptionDispatch+0xc2
    fffff880`083292b0 fffff880`01356c31 : fffffa80`047159d0 fffff880`012a7cda fffffa80`04715901 fffff8a0`03f7aef0 : nt!KiInvalidOpcodeFault+0x11f
    fffff880`08329440 fffff8a0`09b753a8 : 00000000`00000001 fffffa80`04994180 00000000`00000000 fffff8a0`018ae750 : Ntfs!NtfsMoveLinkToNewDir+0x201
    fffff880`08329570 00000000`00000001 : fffffa80`04994180 00000000`00000000 fffff8a0`018ae750 00000000`00000000 : 0xfffff8a0`09b753a8
    fffff880`08329578 fffffa80`04994180 : 00000000`00000000 fffff8a0`018ae750 00000000`00000000 00000000`00000000 : 0x1
    fffff880`08329580 00000000`00000000 : fffff8a0`018ae750 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa80`04994180
    STACK_COMMAND:  kb
    FOLLOWUP_IP: 
    Ntfs!NtfsMoveLinkToNewDir+201
    fffff880`01356c31 ff              ???
    SYMBOL_STACK_INDEX:  4
    SYMBOL_NAME:  Ntfs!NtfsMoveLinkToNewDir+201
    FOLLOWUP_NAME:  MachineOwner
    MODULE_NAME: Ntfs
    IMAGE_NAME:  Ntfs.sys
    DEBUG_FLR_IMAGE_TIMESTAMP:  4d79997b
    FAILURE_BUCKET_ID:  X64_0x1E_c000001d_BAD_IP_Ntfs!NtfsMoveLinkToNewDir+201
    BUCKET_ID:  X64_0x1E_c000001d_BAD_IP_Ntfs!NtfsMoveLinkToNewDir+201
    Followup: MachineOwner
    ---------
    2: kd> lmvm Ntfs
    start             end                 module name
    fffff880`0122f000 fffff880`013d2000   Ntfs       (pdb symbols)          c:\symbols\ntfs.pdb\D51347AE03CB4523A2844EA865BA0BE92\ntfs.pdb
        Loaded symbol image file: Ntfs.sys
        Mapped memory image file: c:\symbols\Ntfs.sys\4D79997B1a3000\Ntfs.sys
        Image path: \SystemRoot\System32\Drivers\Ntfs.sys
        Image name: Ntfs.sys
        Timestamp:        Fri Mar 11 04:39:39 2011 (4D79997B)
        CheckSum:         0019968A
        ImageSize:        001A3000
        File version:     6.1.7601.17577
        Product version:  6.1.7601.17577
        File flags:       0 (Mask 3F)
        File OS:          40004 NT Win32
        File type:        3.7 Driver
        File date:        00000000.00000000
        Translations:     0409.04b0
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     ntfs.sys
        OriginalFilename: ntfs.sys
        ProductVersion:   6.1.7601.17577
        FileVersion:      6.1.7601.17577 (win7sp1_gdr.110310-1504)
        FileDescription:  NT File System Driver
        LegalCopyright:   © Microsoft Corporation. All rights reserved.
    -------------------------------------------------------------------------
    Please run chkdsk /r /f and check results. If this does not help then possible that you have problems with your disk. Please also check your RAM and contact your manufacturer Technical Support.

    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

    Microsoft Student Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator: Security
    Microsoft Certified Systems Engineer: Security
    Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows 7, Configuring
    Microsoft Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

    Wednesday, October 26, 2011 10:14 PM
  • Hello again!! Sorry but I cant seem to analyze these latest reports and can you help me solve this in more detail please?

    https://skydrive.live.com/?cid=01923c48eef0ea71&sc=documents&uc=5&id=1923C48EEF0EA71%21103#

    Sunday, November 6, 2011 5:59 PM