Windows 7 Blue screens
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000335ee6e, Address of the instruction which caused the bugcheck
Arg3: fffff880029e0720, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
CONTEXT: fffff880029e0720 -- (.cxr 0xfffff880029e0720)
rax=0000000000000006 rbx=0000000000000000 rcx=0000000000000417
rdx=000000000000015d rsi=fffff880029e1328 rdi=0000000046a10b0a
rip=fffff8000335ee6e rsp=fffff880029e1100 rbp=fffff8a009473410
r8=0000000000000009 r9=0000000000000000 r10=0000000000000009
r11=fffff880029e12b0 r12=fffff8a009a21380 r13=fff7f8a0099e4ba8
r14=fffff880029e1330 r15=fffff8a009bcdcc0
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!CmpKcbCacheLookup+0x1de:
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch] ds:002b:fff7f8a0`099e4b9c=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: TrustedInstall
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000335ee6e
STACK_TEXT:
fffff880`029e1100 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmpKcbCacheLookup+0x1de
FOLLOWUP_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKcbCacheLookup+1de
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff880029e0720 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
Followup: MachineOwner
---------
------------------------------------------------------------------------
There is no much information to extract from minidumps.
Please proceed like that:
Update all possible drivers Uninstall all unused programs Disable all security softwares Run msconfig and disable all startup items / services except Microsoft ones
Run memtest86+ to check that all is okay with your RAM. If an error was reported then replace the faulty RAM or contact your manufacturer Technical Support.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft Student
Partner 2010 / 2011
Microsoft Certified
Professional
Microsoft Certified
Systems Administrator: Security
Microsoft Certified
Systems Engineer: Security
Microsoft Certified
Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft Certified
Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft Certified
Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft Certified
IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer
November 25th, 2011 12:00am
Hi,
Read this:
http://www.computerhope.com/issues/ch001142.htm
Also this:
http://vrajput.hubpages.com/hub/Resolving-Windows-BAD_POOL_HEADER-Error
Perform the following steps;
1. Start Registry Editor (Regedt32.exe).
2. Locate the UpperFilters value under the following key in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
3. On the Edit menu, click Delete, and then click OK.
4. Locate the LowerFilters value under the same key in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
5. On the Edit menu, click Delete, and then click OK.
6. Quit Registry Editor.NOTE: After you remove the Upperfilters value and the Lowerfilters value, if you notice lost functionality in a particular program, such as CD recording software, you may need to reinstall that software. If the problem recurs, consult
with the software vendor for assistance.
7. Restart your computer.
This fixed the problem and I was able to do this from the "safe" mode.
Source Code:
http://forum.parallels.com/showthread.php?t=12387Founder of SharePoint CookBook: http://www.GokanOzcifci.be
Microsoft Certified Technology Specialist: SharePoint 2010, Configuring
Microsoft Certified Personal
Free Windows Admin Tool Kit Click here and download it now
November 25th, 2011 7:25am
Thanks both of you. I'm gonna try this steps, and let you know if it worked, or not.
But what should I do with the other BSOD's? (API_INDEX_MISMATCH, CACHE_MANAGER, etc.)
November 25th, 2011 9:03am
Sir, please go to c:\Windows\minidump and Upload all Files into
SkyDrive
Regards,
MCP | MCTS | MCITP
Free Windows Admin Tool Kit Click here and download it now
November 25th, 2011 9:09am
Here are all the dumps: https://skydrive.live.com/self.aspx/Minidumps/minidumps.zip?cid=8c1792eefdaed745&sc=documents
November 25th, 2011 9:20am
Sir, i Analyzed all dmp Files i got Three Different Result was caused the Blue Screen :
(1)
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000335ee6e, Address of the instruction which caused the bugcheck
Arg3: fffff880029e0720, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
CONTEXT: fffff880029e0720 -- (.cxr 0xfffff880029e0720)
rax=0000000000000006 rbx=0000000000000000 rcx=0000000000000417
rdx=000000000000015d rsi=fffff880029e1328 rdi=0000000046a10b0a
rip=fffff8000335ee6e rsp=fffff880029e1100 rbp=fffff8a009473410
r8=0000000000000009 r9=0000000000000000 r10=0000000000000009
r11=fffff880029e12b0 r12=fffff8a009a21380 r13=fff7f8a0099e4ba8
r14=fffff880029e1330 r15=fffff8a009bcdcc0
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!CmpKcbCacheLookup+0x1de:
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch] ds:002b:fff7f8a0`099e4b9c=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: TrustedInstall
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000335ee6e
STACK_TEXT:
fffff880`029e1100 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmpKcbCacheLookup+0x1de
FOLLOWUP_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKcbCacheLookup+1de
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff880029e0720 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
Followup: MachineOwner
----------------------------------------------------------------------------------------------------------------------
Bug Check 0X3B : http://msdn.microsoft.com/en-us/library/ff558949(v=vs.85).aspx
(2)
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800033c67e5, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObpWaitForMultipleObjects+2ff
fffff800`033c67e5 c3 ret
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003302100
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0x1E_c0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff8000311b588 to fffff800030cfc40
STACK_TEXT:
fffff880`09f08f38 fffff800`0311b588 : 00000000`0000001e ffffffff`c0000005 fffff800`033c67e5 00000000`00000000 : nt!KeBugCheckEx
fffff880`09f08f40 fffff800`030cf2c2 : fffff880`09f09718 00000000`00000001 fffff880`09f097c0 00000000`02aef098 : nt! ?? ::FNODOBFM::`string'+0x4977d
fffff880`09f095e0 fffff800`030cdbca : fffff880`02fd4180 fffffa80`05827380 fffff8a0`00000001 fffff800`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`09f097c0 fffff800`033c67e5 : fff7f800`033f34cd 00000000`c0000001 00000000`00000000 00000000`00000001 : nt!KiGeneralProtectionFault+0x10a
fffff880`09f09958 fff7f800`033f34cd : 00000000`c0000001 00000000`00000000 00000000`00000001 00000000`00000000 : nt!ObpWaitForMultipleObjects+0x2ff
fffff880`09f09960 00000000`c0000001 : 00000000`00000000 00000000`00000001 00000000`00000000 fffff880`09f09998 : 0xfff7f800`033f34cd
fffff880`09f09968 00000000`00000000 : 00000000`00000001 00000000`00000000 fffff880`09f09998 00000000`00000050 : 0xc0000001
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ObpWaitForMultipleObjects+2ff
fffff800`033c67e5 c3 ret
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!ObpWaitForMultipleObjects+2ff
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!ObpWaitForMultipleObjects+2ff
BUCKET_ID: X64_0x1E_c0000005_nt!ObpWaitForMultipleObjects+2ff
Followup: MachineOwner
------------------------------------------------------------------------------------------
Bug Check 0X1E : http://msdn.microsoft.com/en-us/library/ff557408(v=vs.85).aspx
(3)
100311-10374-01.dmp
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
APC_INDEX_MISMATCH (1)
This is a kernel internal error. The most common reason to see this
bugcheck is when a filesystem or a driver has a mismatched number of
calls to disable and re-enable APCs. The key data item is the
Thread->KernelApcDisable field. A negative value indicates that a driver
has disabled APC calls without re-enabling them. A positive value indicates
that the reverse is true. This check is made on exit from a system call.
Arguments:
Arg1: 0000000077591eaa, address of system function (system call)
Arg2: 0000000000000000, Thread->ApcStateIndex << 8 | Previous ApcStateIndex
Arg3: 000000000000ffff, Thread->KernelApcDisable
Arg4: fffff88005fe4ca0, Previous KernelApcDisable
Debugging Details:
------------------
FAULTING_IP:
+3231333437363436
00000000`77591eaa ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800030d51e9 to fffff800030d5c40
STACK_TEXT:
fffff880`05fe4ad8 fffff800`030d51e9 : 00000000`00000001 00000000`77591eaa 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
fffff880`05fe4ae0 fffff800`030d5120 : 00000000`000005b0 000007fe`fd4c1000 00000000`02acb000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`05fe4c20 00000000`77591eaa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`00bff508 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77591eaa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`030d5120 4883ec50 sub rsp,50h
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceExit+245
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1_SysCallNum_b6_nt!KiSystemServiceExit+245
BUCKET_ID: X64_0x1_SysCallNum_b6_nt!KiSystemServiceExit+245
Followup: MachineOwner
----------------------------------------------------------------------------------------------------------------------------------------------
Bug Check 0X1 : http://msdn.microsoft.com/en-us/library/ff557419(v=vs.85).aspx
** So I want you to make Sure your Graphic Card , Audio ,..etc Drivers are Up to date , also Stop all startup Service by :
Start
à Run…
à Msconfig
-à Startup
à Disbale
All à ok
à Restart
your Computer.
Regards,
MCP | MCTS | MCITP
Free Windows Admin Tool Kit Click here and download it now
November 25th, 2011 12:28pm
Recently I build a computer for a customer. After a few days, it begin to giving blue screens. I'm very bad at blue screens, so I hope that anyone can help me with it. I already reinstalled windows (7, 64 bit, home edition) and also checked the memory with
MemTest86.
Some other pics of bluescreens:
http://i39.tinypic.com/6giib6.jpg
http://i40.tinypic.com/1z1wp5d.jpg
November 25th, 2011 12:36pm
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000335ee6e, Address of the instruction which caused the bugcheck
Arg3: fffff880029e0720, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
CONTEXT: fffff880029e0720 -- (.cxr 0xfffff880029e0720)
rax=0000000000000006 rbx=0000000000000000 rcx=0000000000000417
rdx=000000000000015d rsi=fffff880029e1328 rdi=0000000046a10b0a
rip=fffff8000335ee6e rsp=fffff880029e1100 rbp=fffff8a009473410
r8=0000000000000009 r9=0000000000000000 r10=0000000000000009
r11=fffff880029e12b0 r12=fffff8a009a21380 r13=fff7f8a0099e4ba8
r14=fffff880029e1330 r15=fffff8a009bcdcc0
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!CmpKcbCacheLookup+0x1de:
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch] ds:002b:fff7f8a0`099e4b9c=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: TrustedInstall
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000335ee6e
STACK_TEXT:
fffff880`029e1100 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmpKcbCacheLookup+0x1de
FOLLOWUP_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0335ee6e 418b45f4 mov eax,dword ptr [r13-0Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKcbCacheLookup+1de
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff880029e0720 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1de
Followup: MachineOwner
---------
------------------------------------------------------------------------
There is no much information to extract from minidumps.
Please proceed like that:
Update all possible drivers Uninstall all unused programs Disable all security softwares Run msconfig and disable all startup items / services except Microsoft ones
Run memtest86+ to check that all is okay with your RAM. If an error was reported then replace the faulty RAM or contact your manufacturer Technical Support.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft Student
Partner 2010 / 2011
Microsoft Certified
Professional
Microsoft Certified
Systems Administrator: Security
Microsoft Certified
Systems Engineer: Security
Microsoft Certified
Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft Certified
Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft Certified
Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft Certified
IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer
Free Windows Admin Tool Kit Click here and download it now
November 25th, 2011 3:21pm
Hello,
Bug Check Code 0x19: http://msdn.microsoft.com/en-us/library/ff557389(v=VS.85).aspx
See the cause and the resolution in the article.
Start by:
updating all possible drivers Uninstalling all unused programs Running msconfig and disabling all startup items / services except Microsoft ones
Disabling all security softwares
Once done check again.
You can also use Microsoft Skydrive to upload dump files (c:\windows\minidumps). Once done, post a link here.
You can also contact Microsoft CSS.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft
Student Partner 2010 / 2011
Microsoft
Certified Professional
Microsoft
Certified Systems Administrator: Security
Microsoft
Certified Systems Engineer: Security
Microsoft
Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft
Certified IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer
November 25th, 2011 4:35pm