locked
Window 7 Home Premium - 64 bit - Crashes due to ntoskrnl.exe RRS feed

  • Question

  • Hello guys,

    I searched a lot about this prolem seems very common problem lot of other users also suffer from this problem.

     

    Well In a day more than 10-12 times my Laptop restarts , Crashes sometime happen after every 5 -10 mints an sometime after 3-4 hours no particular time between two crashes.

     

    I have dump files regarding this. and i tries to analysis using whocrashed it shows the couse ntoskrnl.exe file.

     

    one of the analysis:

     

     

    On Sun 11/21/2010 9:27:45 AM your computer crashed
    This was likely caused by the following module: ntoskrnl.exe
    Bugcheck code: 0x19 (0x3, 0xFFFFF80003268670, 0xFFFFF8000326866F, 0xFFFFF80003268670)
    Error: BAD_POOL_HEADER
    Dump file: C:\Windows\Minidump\112110-79264-01.dmp
    file path: C:\Windows\system32\ntoskrnl.exe
    product: Microsoft® Windows® Operating System
    company: Microsoft Corporation
    description: NT Kernel & System
    The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit is in another driver on your system which cannot be identified at this time. 
    
    

     

    Attaching Dump.zip file, Kindly tell me the analysis of recent crash name if the crash file is "112110-79264-01".

    here is the attachment

    http://cid-f296bb1451d2e0cb.office.live.com/self.aspx/.Documents/dumps.zip

     

    Thanks,

    M.S.

    Sunday, November 21, 2010 10:18 AM

Answers

  • DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) - An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high.

    STACK_TEXT:  
    nt!KeBugCheckEx
    nt!KiBugCheckDispatch+0x69
    nt!KiPageFault+0x260
    kl1 +0x37940

    BAD_POOL_HEADER (19)
    The pool is already corrupt at the time of the current request.
    This may or may not be due to the caller.
    The internal pool links must be walked to figure out a possible cause of
    the problem, and then special pool applied to the suspect tags or the driver
    verifier to a suspect driver.
    Arguments:
    Arg1: 0000000000000003, the pool freelist is corrupt.

    STACK_TEXT: 
    nt!KeBugCheckEx
    nt!ExDeferredFreePool+0xa56
    kl1 +0x489c6

    As you can see both have Kaspersky involved.


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    • Marked as answer by Leo Huang Thursday, November 25, 2010 8:18 AM
    Monday, November 22, 2010 12:12 PM

All replies

  • Bug Check 0x19: BAD_POOL_HEADER

    The BAD_POOL_HEADER bug check has a value of 0x00000019. This indicates that a pool header is corrupt.

    http://msdn.microsoft.com/en-us/library/ff557389%28VS.85%29.aspx


    Hi,

    it maybe a RAM issue:

    MODULE_NAME: Pool_Corruption

    FAILURE_BUCKET_ID:  nt!ExDeferredFreePool +a56

    So check your RAM for errors wit memtest86+ (http://memtest.org/).

    If memtest86+ doesn't detect errors, enable Driver verifier to get the causing driver:

    http://www.sevenforums.com/tutorials/101379-driver-verifier-enable-disable.html

    http://support.microsoft.com/?kbid=244617

    when you get a new BSOD, boot to safe mode, disable driver verifier, reboot to normal mode and upload the newest dmp file from the folder C:\Windows\Minidump to your public SkyDrive [1] folder and post the link here.

    André

    [1] http://social.technet.microsoft.com/Forums/en-US/w7itproui/thread/4fc10639-02db-4665-993a-08d865088d65


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    Sunday, November 21, 2010 11:47 AM
  • can i check ram errors with in built facility in DELL STUDIO 1558 ?
    www.LogicMatters.org www.LMTutorials.com
    Sunday, November 21, 2010 12:17 PM
  • Windows has a memory test but this is not the best program.

    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    Sunday, November 21, 2010 12:37 PM
  • I downloaded Download (Pre-built & ISOs) from  Memtest 86+ , its iso i tried to create virtual drive (iso mounted) and in virtual drive there is again .img iso that is unable to open even after mount.

     

    Is not this is a simple program to test or require some special steps for installing and analysis ? or i need a disc and then write the iso on it then only it works during start up of computer.

     

    I just enabled driver verifier. lets see what it covers next time it reboot i will post dump here.

     

    can u tell me all my previous dump contains same cause(information) i mean reason why it reboot .  some time it reboot due to kaspersky driver crases also. but that very rare like if 14 times due to ntoskrnl.exe then 2 times due to kaspersky drivers.

     

     


    www.LogicMatters.org www.LMTutorials.com
    Sunday, November 21, 2010 1:00 PM
  • here are new dumps with driver verifier on:

    zip files contain 2 files one happens due to Kaspersky and other due to ntoskrnl.exe

    kindly give me detail analysis of both files.

    here is link : http://cid-f296bb1451d2e0cb.office.live.com/self.aspx/.Documents/new%20dump.zip

    www.LogicMatters.org www.LMTutorials.com
    Sunday, November 21, 2010 4:37 PM
  • The new dumps, show the driver kl1.sys as cause:

        Image path: \SystemRoot\system32\DRIVERS\kl1.sys
        Image name: kl1.sys
        Timestamp:        Tue Sep 01 13:29:21 2009

    So update Kaspersky, please.


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    Sunday, November 21, 2010 5:19 PM
  • hey andre

     

    I know new dump shows kl1.sys  thats why i told you it contains 2 files , one cause is kaspersky and other cause is something else.

     

    kindly do analysis of other file. and also i complete that memory86+ test its successful.

     

    and also kaspersky is update already :) i regularly u[pdate it. even when kaspersky is not activated then also this randomly shut down occur.

     

    kidly tell me result of other file. that why i already post in my previous post.

     


    www.LogicMatters.org www.LMTutorials.com
    Sunday, November 21, 2010 5:55 PM
  • Hey can u please post the analysis of other file ???

    www.LogicMatters.org www.LMTutorials.com
    Monday, November 22, 2010 6:34 AM
  • DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) - An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high.

    STACK_TEXT:  
    nt!KeBugCheckEx
    nt!KiBugCheckDispatch+0x69
    nt!KiPageFault+0x260
    kl1 +0x37940

    BAD_POOL_HEADER (19)
    The pool is already corrupt at the time of the current request.
    This may or may not be due to the caller.
    The internal pool links must be walked to figure out a possible cause of
    the problem, and then special pool applied to the suspect tags or the driver
    verifier to a suspect driver.
    Arguments:
    Arg1: 0000000000000003, the pool freelist is corrupt.

    STACK_TEXT: 
    nt!KeBugCheckEx
    nt!ExDeferredFreePool+0xa56
    kl1 +0x489c6

    As you can see both have Kaspersky involved.


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    • Marked as answer by Leo Huang Thursday, November 25, 2010 8:18 AM
    Monday, November 22, 2010 12:12 PM
  • hey andre,

     

    can u tell me please which software you use for analysis  or which method you guys uses ???

     

    thanks

    Wednesday, December 8, 2010 11:33 AM
  • I'm using the Debuging tools for Windows :

    http://www.microsoft.com/whdc/devtools/debugging/default.mspx


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    Wednesday, December 8, 2010 3:49 PM