stan baker

New Member
Joined
Mar 19, 2014
Messages
2
The attached minidump resulted from listening to iTunes internet music. I was sleeping when the crash occurred, so I don't know how long after starting iTunes that it happened. I have had the same result after a few hours of listening to the SecurityNow podcast on twit.tv, so I'm guessing that the problem has something to do with audio. Machine configuration details are in the attached in the sysinfo.nfo file. Any provided help is sincerely appreciated.



Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\031914-35755-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*Link Removed
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18113.amd64fre.win7sp1_gdr.130318-1533
Machine Name:
Kernel base = 0xfffff800`0501b000 PsLoadedModuleList = 0xfffff800`0525e670
Debug session time: Wed Mar 19 10:44:36.289 2014 (UTC - 4:00)
System Uptime: 0 days 9:34:33.006
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa800d245b30, fffffa800d245e10, fffff80005397350}
Probably caused by : csrss.exe
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa800d245b30, Terminating object
Arg3: fffffa800d245e10, Process image file name
Arg4: fffff80005397350, Explanatory message (ascii)
Debugging Details:
------------------

PROCESS_OBJECT: fffffa800d245b30
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0xF4_C0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
fffff880`044940a8 fffff800`0541ed22 : 00000000`000000f4 00000000`00000003 fffffa80`0d245b30 fffffa80`0d245e10 : nt!KeBugCheckEx
fffff880`044940b0 fffff800`053cb08b : ffffffff`ffffffff fffffa80`0d44db50 fffffa80`0d245b30 fffffa80`0d245b30 : nt!PspCatchCriticalBreak+0x92
fffff880`044940f0 fffff800`0534b144 : ffffffff`ffffffff 00000000`00000001 fffffa80`0d245b30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17486
fffff880`04494140 fffff800`0508fe93 : fffffa80`0d245b30 fffff800`c0000005 fffffa80`0d44db50 00000000`00c80a20 : nt!NtTerminateProcess+0xf4
fffff880`044941c0 fffff800`0508c450 : fffff800`050db81f fffff880`04494b38 fffff880`04494890 fffff880`04494be0 : nt!KiSystemServiceCopyEnd+0x13
fffff880`04494358 fffff800`050db81f : fffff880`04494b38 fffff880`04494890 fffff880`04494be0 00000000`77419c12 : nt!KiServiceLinkage
fffff880`04494360 fffff800`05090282 : fffff880`04494b38 00000000`00000000 fffff880`04494be0 00000000`00c81128 : nt! ?? ::FNODOBFM::`string'+0x488e4
fffff880`04494a00 fffff800`0508edfa : 00000000`00000001 00000000`00c80fd8 00000000`00c8b701 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`04494be0 00000000`77419ac6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
00000000`00c80fe0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77419ac6

STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
Followup: MachineOwner
---------
 


Attachments

Solution
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck F4, {3, fffffa800d245b30, fffffa800d245e10, fffff80005397350}

----- ETW minidump data unavailable-----
Probably caused by : csrss.exe

Followup: MachineOwner

Hi Stan,
Stan the more dump files you send the better as it makes our job easier in spotting faults and linking...
Hello and welcome to the forums.

First make sure your machine is configured properly to facilitate the collection of .dmp files.

Go to Start and type in sysdm.cpl and press Enter

Click on the Advanced tab

Click on the Startup and Recovery Settings button

Ensure that Automatically restart is unchecked

Under the Write Debugging Information header select Small memory dump (256 kB) in the dropdown box

Ensure that the Small Dump Directory is listed as %systemroot%\Minidump << where your .dmp files can be
found later.

Click OK twice to exit the dialogs, then reboot for the changes to take effect.


Then please read the first post in this sticky thread here Link Removed
Do your best to accumulate the data required.
Run the SF Diagnostic tool (download and right click the executable and choose run as administrator)
Download and run CPUz. Use the Windows snipping tool to gather images from all tabs including all slots populated with memory under the SPD tab.Likewise RAMMon. Export the html report, put everything into a desktop folder that you've created for this purpose, zip it up and attach it to your next post (right click it and choose send to, compressed (zipped) folder.
 


Thanks for the prompt reply and posting instructions. The attached w7f.zip file contains all of the requested diagnostic information.
 


Attachments

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck F4, {3, fffffa800d245b30, fffffa800d245e10, fffff80005397350}

----- ETW minidump data unavailable-----
Probably caused by : csrss.exe

Followup: MachineOwner

Hi Stan,
Stan the more dump files you send the better as it makes our job easier in spotting faults and linking trends. crss.exe is either a Trojan or an essential part of the windows subsystem and something made it crash.

BiosVersion = NBG4310H.86A.0106.2010.0512.1722
BiosReleaseDate = 05/12/2010
You also have a bios update pending, please update:
Link Removed

The dump file also mentioned memory. Please test your RAM using this app:
http://www.memtest.org/
You'll need to download the iso, burn to disk and then boot from it to test RAM outside of windows. Run for a few passes.

Check windows hasn't become corrupt by running the system file checker. Look in the start menu for command prompt, right click on it, choose properties and then run as admin. Type:
sfc /scannow
Press enter and await results.

AtihdW76.sys Fri Jul 05 19:10:37 2013
atikmdag.sys Wed Jul 24 01:03:16 2013: AMD GPU driver, please use this app to remove:
Link Removed
Then install latest version:
Link Removed

e1y62x64.sys Thu Oct 20 19:20:55 2011: Intel 82567V-2 Gigabit Network Connection Ethernet driver please update:
Link Removed

gfibto.sys Fri Sep 02 02:31:28 2011: Possibly a VIPRE Antivirus driver. Please remove and install MSE. This creates a known environment:
Link Removed

Please run the Intel update utility:
Link Removed

mv91xx.sys Thu Jun 07 04:10:27 2012: Marvel SATA drivers please update:
Link Removed

psi_mf_amd64.sys Thu Feb 07 09:28:21 2013: Secunia Personal Software Inspector driver. Please remove as specified above. You can always re-install later.

Try this download for your Realtek ALC Audio driver:
http://drivers.softpedia.com/downloadTag/Realtek+ALC+Audio+Driver

Post any new dump files.
 


Solution
Back
Top