Windows 7 Windows 7 crashes with blue screen

Arif Hussain

New Member
Joined
Dec 11, 2012
Messages
2
i m having windows 7 which restart with below error.
SYSTEM SERVICE EXCEPTION
PAGE FAULT IN NON PAGE AREA
KMOD EXCEPTION NOT HANDLED
IRQL NOT LESS OR EQUAL
DRIVER IRQL NOT LESS OR EQUAL.
Kindly help to get rid of this unwanted auto restart
attached dmp file..and snaps.




Link RemovedLink RemovedLink RemovedLink RemovedLink RemovedLink RemovedLink RemovedLink RemovedLink RemovedLink Removed
 
Solution
SP1 isn't installed, please do the following:

Please provide this information so we can provide a complete analysis: Link Removed

More to follow once the memory dumps finish running......
 
SP1 isn't installed, please do the following:

Daemon Tools (and Alcohol % software) are known to cause BSOD's on some Win7 systems (mostly due to the sptd.sys driver, although I have seen dtsoftbus01.sys blamed on several occasions).

Also, remove HotSpotShield - it's known to cause BSOD's in some Win7 systems.

Please update these older drivers. Links are included to assist in looking up the source of the drivers. If unable to find an update, please remove (un-install) the program responsible for that driver. DO NOT manually delete/rename the driver as it may make the system unbootable! :

Get from HP or remove it:
HpqKbFiltr.sys Mon Jun 18 18:13:11 2007 (46770377)
HP Quick Launch Buttons HpqKbFiltr Keyboard Filter driver
Link Removed

Remove according to the instructions above:
dtsoftbus01.sys Fri Jan 13 08:45:46 2012 (4F10358A)
Daemon Tools driver [br] Possible BSOD issues in Win7
Link Removed

Un-install this one:
hssdrv6.sys Wed Nov 14 20:32:58 2012 (50A4464A)
Hotspot Shield Routing Driver [br] Possible BSOD cause seen in mid-2012
Link Removed



Analysis:
The following is for informational purposes only.
Code:
[FONT=lucida console]**************************Sun Dec  2 16:57:01.475 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\120312-16941-01.dmp]
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
[B]Missing Windows 7 Service Pack 1[/B]
Built by: [B]7600[/B].16385.amd64fre.win7_rtm.090713-1255
System Uptime:[B]0 days 0:13:18.171[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!ExFreePoolWithTag+43 )[/B]
BugCheck [B]1E, {ffffffffc0000005, fffff80002fbe0f3, 0, f2}[/B]
BugCheck Info: [B]Link Removed[/B]
Arguments: 
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002fbe0f3, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 00000000000000f2, Parameter 1 of the exception
BUGCHECK_STR:  0x1E_c0000005_R
PROCESS_NAME: [B]hsssrv.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1E_c0000005_R_nt!ExFreePoolWithTag+43[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Wed Dec  5 03:30:57.182 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\120512-19110-01.dmp]
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
[B]Missing Windows 7 Service Pack 1[/B]
Built by: [B]7600[/B].16385.amd64fre.win7_rtm.090713-1255
System Uptime:[B]0 days 0:00:13.759[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!KiSystemServiceHandler+7c )[/B]
BugCheck [B]3B, {c0000005, fffffa80055921d0, fffff8800895ba20, 0}[/B]
BugCheck Info: [B]Link Removed[/B]
Arguments: 
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffffa80055921d0, Address of the instruction which caused the bugcheck
Arg3: fffff8800895ba20, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
BUGCHECK_STR:  0x3B
DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT
PROCESS_NAME: [B]csrss.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x3B_nt!KiSystemServiceHandler+7c[/B]
CPUID:        "Intel(R) Core(TM) i3 CPU       M 350  @ 2.27GHz"
MaxSpeed:     2270
CurrentSpeed: [B]2261[/B]
  BIOS Version                  V1.09
  BIOS Release Date             06/08/2010
  Manufacturer                  Gateway         
  Product Name                  NV59C           
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Mon Dec  3 02:46:20.233 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\120312-19531-01.dmp]
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
[B]Missing Windows 7 Service Pack 1[/B]
Built by: [B]7600[/B].16385.amd64fre.win7_rtm.090713-1255
System Uptime:[B]0 days 0:27:29.420[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!KeWaitForMultipleObjects+4c6 )[/B]
BugCheck [B]A, {4, 2, 0, fffff80002ed07a0}[/B]
BugCheck Info: [B]Link Removed[/B]
Arguments: 
Arg1: 0000000000000004, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002ed07a0, address which referenced memory
BUGCHECK_STR:  0xA
DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT
PROCESS_NAME: [B]chrome.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0xA_nt!KeWaitForMultipleObjects+4c6[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Mon Dec  3 04:37:45.881 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\120312-17612-01.dmp]
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
[B]Missing Windows 7 Service Pack 1[/B]
Built by: [B]7600[/B].16385.amd64fre.win7_rtm.090713-1255
System Uptime:[B]0 days 1:51:03.067[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!KiPageFault+260 )[/B]
BugCheck [B]D1, {0, 2, 1, fffffa80071196b0}[/B]
BugCheck Info: [B]Link Removed[/B]
Arguments: 
Arg1: 0000000000000000, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffffa80071196b0, address which referenced memory
BUGCHECK_STR:  0xD1
DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT
PROCESS_NAME: [B]System[/B]
FAILURE_BUCKET_ID: [B]X64_0xD1_nt!KiPageFault+260[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
[/FONT]

3rd Party Drivers:
The following is for information purposes only.
Any drivers in red should be updated or removed from your system. And should have been discussed in the body of my post.
Code:
[FONT=lucida console]**************************Sun Dec  2 16:57:01.475 2012 (UTC - 5:00)**************************
[B]HpqKbFiltr.sys              Mon Jun 18 18:13:11 2007 (46770377)[/B]
GEARAspiWDM.sys             Mon May 18 08:17:04 2009 (4A1151C0)
amdxata.sys                 Tue May 19 13:56:59 2009 (4A12F2EB)
intelppm.sys                Mon Jul 13 19:19:25 2009 (4A5BC0FD)
HECIx64.sys                 Thu Sep 17 15:54:16 2009 (4AB293E8)
RTKVHD64.sys                Wed Oct 21 10:27:48 2009 (4ADF1A64)
Impcd.sys                   Fri Feb 26 18:32:11 2010 (4B8859FB)
athwx.sys                   Fri Nov  5 19:50:35 2010 (4CD4984B)
k57nd60a.sys                Mon Feb 14 23:19:05 2011 (4D59FEB9)
iaStor.sys                  Fri May 20 12:52:24 2011 (4DD69C48)
epfwwfpr.sys                Tue Jun 28 03:30:09 2011 (4E098301)
ehdrv.sys                   Tue Jun 28 03:34:38 2011 (4E09840E)
VMNET.SYS                   Fri Jul  8 03:43:55 2011 (4E16B53B)
vmnetbridge.sys             Fri Jul  8 03:44:44 2011 (4E16B56C)
vmci.sys                    Tue Jul 26 22:42:09 2011 (4E2F7B01)
eamonm.sys                  Tue Aug  2 05:33:29 2011 (4E37C469)
hcmon.sys                   Mon Aug 22 02:05:57 2011 (4E51F1C5)
vmnetuserif.sys             Mon Aug 22 18:35:59 2011 (4E52D9CF)
vmx86.sys                   Mon Aug 22 19:57:51 2011 (4E52ECFF)
IntcDAud.sys                Tue Aug 23 09:12:57 2011 (4E53A759)
igdkmd64.sys                Fri Oct 21 13:29:55 2011 (4EA1AC13)
[B]dtsoftbus01.sys             Fri Jan 13 08:45:46 2012 (4F10358A)[/B]
SCDEmu.SYS                  Fri Aug 17 00:19:38 2012 (502DC65A)
avgtpx64.sys                Tue Aug 21 10:16:24 2012 (50339838)
[B]hssdrv6.sys                 Wed Nov 14 20:32:58 2012 (50A4464A)[/B]
taphss6.sys                 Wed Nov 14 20:38:02 2012 (50A4477A)
[/FONT]
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
Link Removed
 
Last edited:
Solution