- Thread Author
- #1
Hi
I am having big issues with blue screens. The pc is pretty new, I build it myself, and I put windows 7 Pro.
I am geting blue screens almost every day, I am getting crazy about this.
I have installed windows debugger but it seems all crashes are comming from window 7 itself and I don't really know how to solve this.
All crivers are ok and working, I hade AVG but I uninstalled thinking this was the problem so I have Microsoft Security Essential, even the system crashes during antivirus run. My PC is not over clocked.
Here is one crash report:
Loading Dump File [C:\Users\Gus\Desktop\080312-10420-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`0320f000 PsLoadedModuleList = 0xfffff800`03453670
Debug session time: Fri Aug 3 20:18:16.139 2012 (UTC + 2:00)
System Uptime: 0 days 0:20:07.933
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800033ba9bc, fffff88003f07fc0, 0}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+100 )
Followup: Pool_corruption
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800033ba9bc, Address of the instruction which caused the bugcheck
Arg3: fffff88003f07fc0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExDeferredFreePool+100
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx]
CONTEXT: fffff88003f07fc0 -- (.cxr 0xfffff88003f07fc0)
rax=fffff8a015264010 rbx=0000000000000002 rcx=fffffa800ca0bdf0
rdx=ffdff8a015263010 rsi=fffff8a015265000 rdi=fffff8a015264010
rip=fffff800033ba9bc rsp=fffff88003f089a0 rbp=0000000000000001
r8=ffdff8a015263010 r9=fffff8a0152635c0 r10=0000000000000001
r11=0000000000000000 r12=fffffa800ca0b280 r13=0000000000000000
r14=0000000000000008 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ExDeferredFreePool+0x100:
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx] ds:002b:ffdff8a0`15263010=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800033ba9bc
STACK_TEXT:
fffff880`03f089a0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExDeferredFreePool+0x100
FOLLOWUP_IP:
nt!ExDeferredFreePool+100
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExDeferredFreePool+100
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
STACK_COMMAND: .cxr 0xfffff88003f07fc0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
Followup: Pool_corruption
---------
and a #2 report:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Gus\Desktop\080312-9282-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`0320b000 PsLoadedModuleList = 0xfffff800`0344f670
Debug session time: Fri Aug 3 19:16:33.618 2012 (UTC + 2:00)
System Uptime: 0 days 4:30:28.788
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff8000329332c, fffff88006c09a50, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceHandler+7c )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000329332c, Address of the instruction which caused the bugcheck
Arg3: fffff88006c09a50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObfDereferenceObject+2c
fffff800`0329332c f0480fc11f lock xadd qword ptr [rdi],rbx
CONTEXT: fffff88006c09a50 -- (.cxr 0xfffff88006c09a50)
rax=0000000000000002 rbx=ffffffffffffffff rcx=ffdffa800ca83060
rdx=00000000000007ff rsi=ffdffa800ca83060 rdi=ffdffa800ca83030
rip=fffff8000329332c rsp=fffff88006c0a430 rbp=fffff88006c0aca0
r8=fffffa800f8b40e8 r9=0000000000000000 r10=fffffffffffffffd
r11=0000000000000000 r12=0000000000000000 r13=fffff8a0013f5ca0
r14=0000000000000002 r15=0000000000000002
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ObfDereferenceObject+0x2c:
fffff800`0329332c f0480fc11f lock xadd qword ptr [rdi],rbx ds:002b:ffdffa80`0ca83030=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000329332c
STACK_TEXT:
fffff880`06c09188 fffff800`03289769 : 00000000`0000003b 00000000`c0000005 fffff800`0329332c fffff880`06c09a50 : nt!KeBugCheckEx
fffff880`06c09190 fffff800`032890bc : fffff880`06c0a1f8 fffff880`06c09a50 00000000`00000000 fffff800`032b5320 : nt!KiBugCheckDispatch+0x69
fffff880`06c092d0 fffff800`032b4e2d : fffff800`034a469c 00000000`00000000 fffff800`0320b000 fffff880`06c0a1f8 : nt!KiSystemServiceHandler+0x7c
fffff880`06c09310 fffff800`032b3c05 : fffff800`033d1638 fffff880`06c09388 fffff880`06c0a1f8 fffff800`0320b000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`06c09340 fffff800`032c4b81 : fffff880`06c0a1f8 fffff880`06c09a50 fffff880`00000000 ffdffa80`0ca83030 : nt!RtlDispatchException+0x415
fffff880`06c09a20 fffff800`03289842 : fffff880`06c0a1f8 ffffffff`ffffffff fffff880`06c0a2a0 ffdffa80`0ca83060 : nt!KiDispatchException+0x135
fffff880`06c0a0c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceHandler+7c
fffff800`032890bc b801000000 mov eax,1
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceHandler+7c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4fa390f3
FAILURE_BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
Followup: MachineOwner
I really appreciate any possible help.
I start to regret I moved from XP pro to W7 :-(
Thanks
/Gustavo
I am having big issues with blue screens. The pc is pretty new, I build it myself, and I put windows 7 Pro.
I am geting blue screens almost every day, I am getting crazy about this.
I have installed windows debugger but it seems all crashes are comming from window 7 itself and I don't really know how to solve this.
All crivers are ok and working, I hade AVG but I uninstalled thinking this was the problem so I have Microsoft Security Essential, even the system crashes during antivirus run. My PC is not over clocked.
Here is one crash report:
Loading Dump File [C:\Users\Gus\Desktop\080312-10420-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`0320f000 PsLoadedModuleList = 0xfffff800`03453670
Debug session time: Fri Aug 3 20:18:16.139 2012 (UTC + 2:00)
System Uptime: 0 days 0:20:07.933
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800033ba9bc, fffff88003f07fc0, 0}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+100 )
Followup: Pool_corruption
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800033ba9bc, Address of the instruction which caused the bugcheck
Arg3: fffff88003f07fc0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExDeferredFreePool+100
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx]
CONTEXT: fffff88003f07fc0 -- (.cxr 0xfffff88003f07fc0)
rax=fffff8a015264010 rbx=0000000000000002 rcx=fffffa800ca0bdf0
rdx=ffdff8a015263010 rsi=fffff8a015265000 rdi=fffff8a015264010
rip=fffff800033ba9bc rsp=fffff88003f089a0 rbp=0000000000000001
r8=ffdff8a015263010 r9=fffff8a0152635c0 r10=0000000000000001
r11=0000000000000000 r12=fffffa800ca0b280 r13=0000000000000000
r14=0000000000000008 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ExDeferredFreePool+0x100:
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx] ds:002b:ffdff8a0`15263010=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800033ba9bc
STACK_TEXT:
fffff880`03f089a0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExDeferredFreePool+0x100
FOLLOWUP_IP:
nt!ExDeferredFreePool+100
fffff800`033ba9bc 4c8b02 mov r8,qword ptr [rdx]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExDeferredFreePool+100
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
STACK_COMMAND: .cxr 0xfffff88003f07fc0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
Followup: Pool_corruption
---------
and a #2 report:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Gus\Desktop\080312-9282-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`0320b000 PsLoadedModuleList = 0xfffff800`0344f670
Debug session time: Fri Aug 3 19:16:33.618 2012 (UTC + 2:00)
System Uptime: 0 days 4:30:28.788
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff8000329332c, fffff88006c09a50, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceHandler+7c )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000329332c, Address of the instruction which caused the bugcheck
Arg3: fffff88006c09a50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObfDereferenceObject+2c
fffff800`0329332c f0480fc11f lock xadd qword ptr [rdi],rbx
CONTEXT: fffff88006c09a50 -- (.cxr 0xfffff88006c09a50)
rax=0000000000000002 rbx=ffffffffffffffff rcx=ffdffa800ca83060
rdx=00000000000007ff rsi=ffdffa800ca83060 rdi=ffdffa800ca83030
rip=fffff8000329332c rsp=fffff88006c0a430 rbp=fffff88006c0aca0
r8=fffffa800f8b40e8 r9=0000000000000000 r10=fffffffffffffffd
r11=0000000000000000 r12=0000000000000000 r13=fffff8a0013f5ca0
r14=0000000000000002 r15=0000000000000002
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ObfDereferenceObject+0x2c:
fffff800`0329332c f0480fc11f lock xadd qword ptr [rdi],rbx ds:002b:ffdffa80`0ca83030=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000329332c
STACK_TEXT:
fffff880`06c09188 fffff800`03289769 : 00000000`0000003b 00000000`c0000005 fffff800`0329332c fffff880`06c09a50 : nt!KeBugCheckEx
fffff880`06c09190 fffff800`032890bc : fffff880`06c0a1f8 fffff880`06c09a50 00000000`00000000 fffff800`032b5320 : nt!KiBugCheckDispatch+0x69
fffff880`06c092d0 fffff800`032b4e2d : fffff800`034a469c 00000000`00000000 fffff800`0320b000 fffff880`06c0a1f8 : nt!KiSystemServiceHandler+0x7c
fffff880`06c09310 fffff800`032b3c05 : fffff800`033d1638 fffff880`06c09388 fffff880`06c0a1f8 fffff800`0320b000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`06c09340 fffff800`032c4b81 : fffff880`06c0a1f8 fffff880`06c09a50 fffff880`00000000 ffdffa80`0ca83030 : nt!RtlDispatchException+0x415
fffff880`06c09a20 fffff800`03289842 : fffff880`06c0a1f8 ffffffff`ffffffff fffff880`06c0a2a0 ffdffa80`0ca83060 : nt!KiDispatchException+0x135
fffff880`06c0a0c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceHandler+7c
fffff800`032890bc b801000000 mov eax,1
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceHandler+7c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4fa390f3
FAILURE_BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
BUCKET_ID: X64_0x3B_nt!KiSystemServiceHandler+7c
Followup: MachineOwner
I really appreciate any possible help.
I start to regret I moved from XP pro to W7 :-(
Thanks
/Gustavo