00000000c 0000005 System_service_exception

Hello, got BSoD after playing Overwatch for about a minute, don't have not installed/changed anything, he played well for about 2 weeks before.

Dump downloaded file

Result of WinDbg:

Bugcheck 3B {c0000005, fffff8000368b423, fffff8800c6a0c10, 0}

Probably caused by: Unknown_Image (nt! EtwpFindGuidEntryByGuid + 72)

Problem solved.

Installed Windows 10

Previous Windows 7 was about 4 years old

Tags: Windows

Similar Questions

  • Screen blue error - 3B (00000000C 0000005, FFFFFA60036E0C36, FFFFFA60091D3E60, 0000000000000000)

    Signature of the problem:

    Problem event name: BlueScreen

    OS version: 6.0.6002.2.2.0.256.6

    Locale ID: 1033

    More information about the problem:

    BCCode: 3B

    BCP1: 00000000C 0000005

    BCP2: FFFFFA60036E0C36

    BCP3: FFFFFA60091D3E60

    BCP4: 0000000000000000

    OS version: 6_0_6002

    Service Pack: 2_0

    Product: 256_1

    Files helping to describe the problem:

    C:\Windows\Minidump\Mini071411-02.dmp

    C:\Users\Thomas Allen\AppData\Local\Temp\WER-207574-0.sysdata.xml

    C:\Users\Thomas Allen\AppData\Local\Temp\WER2E9E.tmp.version.txt

    It gives me this error when I try to start windows, if I boot in safe mode, it works very well. Only randomly, it started when I started my computer today. Any ideas on what could be the cause?

    Hello

    ·         Did you make any changes before the show?

    Method 1:

    Start in safe mode and put the computer to boot and check if that helps:

    How to troubleshoot a problem by performing a clean boot in Windows Vista or Windows 7:

    http://support.Microsoft.com/kb/929135

    Note: After a repair, be sure to set the computer to start as usual as mentioned in step 7 in the above article.

    Method 2:

    You can also follow the steps in the link below and check if it helps:

    http://support.Microsoft.com/kb/958233

  • BSOD System_Service_Exception and Driver_Verifier_Detection on HP m9520f PC

    Hello

    I recently re-formatted and re-installed Windows 7 Ultimate x 64 on my HP Pavilion Elite m9520f PC.

    I met the BSOD crashes several times a day to have the "System_Service_Exception 0x0000003B" and DRIVER_VERIFIER_DETECTED_VIOLATION 0x000000c4 error. The system automatically reboots when the BSOD occurs.

    I installed the latest update driver NVIDIA GeForce 9600 GS, to see if it solves the problem, but nothing has been resolved. Also, I went to the Advanced Boot Options and did the last known good configuration option but did not work. More information on how to solve this problem would be sincerely appreciated.

    Here is both the problem signatures:

    Signature of the problem:
    Problem event name: BlueScreen
    OS version: 6.1.7601.2.1.0.256.1
    Locale ID: 1033

    More information about the problem:
    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: FFFFF880016537E7
    BCP3: FFFFF88006810E70
    BCP4: 0000000000000000
    OS version: 6_1_7601
    Service Pack: 1_0
    Product: 256_1

    AND

    Signature of the problem:
    Problem event name: BlueScreen
    OS version: 6.1.7601.2.1.0.256.1
    Locale ID: 1033

    More information about the problem:
    BCCode: c4
    BCP1: 0000000000000091
    BCP2: 0000000000000002
    BCP3: FFFFFA800A8D9710
    BCP4: 0000000000000000
    OS version: 6_1_7601
    Service Pack: 1_0
    Product: 256_1

    Unplug the PC from the domestic sector.

    Remove the memory modules.

    Put only one memory card in the nearest location of the CPU.

    Once this is done, you can plug the PC back to see if it starts up.

    If it does not start, then disconnect the PC.  Remove the memory module and put the other module in its place, plug the PC and try to start again at the top.

  • System_service_exception (3B) - rdpdr! CTransportVC::CloseChannels + 18

    Hi team,

    The system was unexpected reboot, bugcheck 3B. System_service_exception (3B)

    Can someone help me find the problem here please?

    KD >! analyze - v
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************

    System_service_exception (3B)
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffff8800bd49e54, the address of the instruction that caused the error checking
    Arg3: fffff8800efc6c00, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.

    Debugging information:
    ------------------

    Page c27021 not present in the dump file. Type ".hh dbgerr004" for more details
    Page 89ef9c not present in the dump file. Type ".hh dbgerr004" for more details

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - the instruction at 0 x % lx 08 referenced memory at 0 x % 08 lx. The memory could not be %s.

    FAULTING_IP:
    Rdpdr! CTransportVC::CloseChannels + 18
    fffff880'0bd49e54 488b 4148 mov rax, qword ptr [rcx + 48 h]

    CONTEXT: fffff8800efc6c00-(.cxr 0xfffff8800efc6c00)
    Rax = 0000000000000001 rbx = 0000000000000000 rcx = 0000000000000000
    RDX = 0000000000000001 rsi = 0000000000000000 rdi = fffffab025d60010
    RIP = fffff8800bd49e54 rsp = fffff8800efc75e0 rbp = 0000000000000001
    R8 = 0000000000000000 r9 = 0000000000000000 r10 = 002 005000440052 d
    R11 = fffff8800efc7740 r12 = 0000000000000004 = 0000000000000000 r13
    R14 = r15 0000000000000004 = 0000000000000003
    iopl = 0 nv in pe of na EI ng nz nc
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010282
    Rdpdr! CTransportVC::CloseChannels + 0x18:
    fffff880'0bd49e54 488b 4148 mov rax, qword ptr [rcx + 48 h] b ds:002: 00000000'00000048 =?
    Reset the default scope
    DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

    BUGCHECK_STR: 0X3B

    Nom_processus: svchost.exe

    CURRENT_IRQL: 0

    LAST_CONTROL_TRANSFER: from fffff8800bd46d7b to fffff8800bd49e54

    STACK_TEXT:
    fffff880 '0efc75e0 fffff880' 0bd46d7b: fffff880 00000000'00000000 00000000'00000001 00000000'00000000 ' 0bd466d5: rdpdr! CTransportVC::CloseChannels + 0x18
    "fffff880 '0efc7620 fffff880' 0bd465c9: 00000000 ' fffffab0 00000000 ' 3029df50 00000000'00000000 00000000'00000004: rdpdr! CVCSession: disconnect + 0x7b
    fffff880 '0efc7670 fffff880' 0bd4643b: 00000000 00000000' fffff880 ' 0efc7740 fffffab0 25 d 60010 fffffab0 ' 3029df50: rdpdr! CDynVC::NotifySessionDisconnected + 0 x 71
    fffff880 '0efc76a0 fffff880' 0bd480fc: 00000000'00000634 fffffab0 '2fcffd90 00000000' 0218e140 fffffab0' 24d8a1c8: rdpdr! CDynVC::NotifySessionConnected + 0 x 47
    "fffff880 '0efc76f0 fffff880' 0bd46020: 00000000 ' fffff8a0 00000620 '101b525e fffffab0' 249882f0 fffff880 ' 0efc77e0: rdpdr! CFileVC::DeviceIoControl + 0x15c
    fffff880 '0efc77d0 fffff880' 0bd35a19: fffffab0'249882f0 fffff8a0 '101b 5250 00000000 00000000' fffffab0' 203dbb40: rdpdr! DYNVC_Dispatch + 0 x 70
    "fffff880 '0efc7800 fffff800' 023e01cb: 00000000'00000002 00000000'00000002 fffffab0 ' 20645 c 30 fffffab0 ' 249882f0: rdpdr! DrPeekDispatch + 0x61
    fffff880 '0efc7850 fffff800' 023f433a: fffffab0 ' 20645c 30 '20645 c 30 fffffab0' fffffab0 20645c 30 fffff880' 024d 7180: nt! IopSynchronousServiceTail + 0xfb
    fffff880 '0efc78c0 fffff800' 023f43d6: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! IopXxxControlFile + 0xc27
    fffff880'0efc7a00 fffff800'020 d 3613: 00000000'00000018 00000000' 0218e910 00000000' 0218e630 00000000' 00aa1810: nt! NtDeviceIoControlFile + 0 x 56
    fffff880 '0efc7a70 00000000' 76f1bbaa: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSystemServiceCopyEnd + 0x13
    00000000' 0218dfb8 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: 0x76f1bbaa

    FOLLOWUP_IP:
    Rdpdr! CTransportVC::CloseChannels + 18
    fffff880'0bd49e54 488b 4148 mov rax, qword ptr [rcx + 48 h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: rdpdr! CTransportVC::CloseChannels + 18

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: rdpdr

    Nom_image: rdpdr.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7abc1

    STACK_COMMAND: .cxr 0xfffff8800efc6c00; Ko

    FAILURE_BUCKET_ID: X64_0x3B_rdpdr! CTransportVC::CloseChannels + 18

    BUCKET_ID: X64_0x3B_rdpdr! CTransportVC::CloseChannels + 18

    Follow-up: MachineOwner

    =================================================================

    KD > kv
    Child-SP RetAddr: Args to child: call Site
    fffff880'0efc6338 fffff800'020 d 3929: 00000000' 0000003b 00000000' c0000005 fffff880 '0bd49e54 fffff880' 0efc6c00: nt! KeBugCheckEx
    fffff880 '0efc6340 fffff800' 020d327c: fffff880'0efc73a8 fffff880 '0efc6c00 00000000 00000000' fffff800' 020ffc28: nt! KiBugCheckDispatch + 0 x 69
    fffff880 '0efc6480 fffff800' 020ff72d: fffff800 '022fbc24 fffff800 ' 02221880 fffff800' 02064000 fffff880' 0efc73a8: nt! KiSystemServiceHandler + 0x7c
    fffff880 '0efc64c0 fffff800' 020fe505: fffff800 ' 02228158 fffff880 '0efc6538 fffff880' 0efc73a8 fffff800' 02064000: nt! RtlpExecuteHandlerForException + 0xd
    fffff880 '0efc64f0 fffff800' 0210fa31: fffff880 '0efc73a8 fffff880' 0efc6c00 fffff880 'fffffab0 00000000' 00000007: nt! RtlDispatchException + 0 x 415
    fffff880 '0efc6bd0 fffff800' 020d3a02: fffff880 '0efc73a8 00000000 00000000' fffff880' 0efc7450 00000000' 00000000: nt! KiDispatchException + 0 x 135
    fffff880 '0efc7270 fffff800' 020d257a: fffffab0 00000000'00000000 00000000'00000048 ' 24988200 00000000 00000000': nt! KiExceptionDispatch + 0xc2
    "fffff880 '0efc7450 fffff880' 0bd49e54: 00000000 ' 00000004 fffff880 ' 0bd29583 00000000'00000003 00000000'00000004: nt! KiPageFault + 0x23a (TrapFrame @ fffff880'0efc7450)
    fffff880 '0efc75e0 fffff880' 0bd46d7b: fffff880 00000000'00000000 00000000'00000001 00000000'00000000 ' 0bd466d5: rdpdr! CTransportVC::CloseChannels + 0x18
    "fffff880 '0efc7620 fffff880' 0bd465c9: 00000000 ' fffffab0 00000000 ' 3029df50 00000000'00000000 00000000'00000004: rdpdr! CVCSession: disconnect + 0x7b
    fffff880 '0efc7670 fffff880' 0bd4643b: 00000000 00000000' fffff880 ' 0efc7740 fffffab0 25 d 60010 fffffab0 ' 3029df50: rdpdr! CDynVC::NotifySessionDisconnected + 0 x 71
    fffff880 '0efc76a0 fffff880' 0bd480fc: 00000000'00000634 fffffab0 '2fcffd90 00000000' 0218e140 fffffab0' 24d8a1c8: rdpdr! CDynVC::NotifySessionConnected + 0 x 47
    "fffff880 '0efc76f0 fffff880' 0bd46020: 00000000 ' fffff8a0 00000620 '101b525e fffffab0' 249882f0 fffff880 ' 0efc77e0: rdpdr! CFileVC::DeviceIoControl + 0x15c
    fffff880 '0efc77d0 fffff880' 0bd35a19: fffffab0'249882f0 fffff8a0 '101b 5250 00000000 00000000' fffffab0' 203dbb40: rdpdr! DYNVC_Dispatch + 0 x 70
    "fffff880 '0efc7800 fffff800' 023e01cb: 00000000'00000002 00000000'00000002 fffffab0 ' 20645 c 30 fffffab0 ' 249882f0: rdpdr! DrPeekDispatch + 0x61
    fffff880 '0efc7850 fffff800' 023f433a: fffffab0 ' 20645c 30 '20645 c 30 fffffab0' fffffab0 20645c 30 fffff880' 024d 7180: nt! IopSynchronousServiceTail + 0xfb
    fffff880 '0efc78c0 fffff800' 023f43d6: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! IopXxxControlFile + 0xc27
    fffff880'0efc7a00 fffff800'020 d 3613: 00000000'00000018 00000000' 0218e910 00000000' 0218e630 00000000' 00aa1810: nt! NtDeviceIoControlFile + 0 x 56
    fffff880 '0efc7a70 00000000' 76f1bbaa: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSystemServiceCopyEnd + 0 x 13 (TrapFrame @ fffff880'0efc7ae0)
    00000000' 0218dfb8 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: 0x76f1bbaa

    ===========================================

    KD > .trap fffff880'0efc7450
    NOTE: The frame trap does contain not all registers.
    Some registry values can be set to zero or incorrect.
    Rax = 0000000000000001 rbx = 0000000000000000 rcx = 0000000000000000
    RDX = 0000000000000001 rsi = 0000000000000000 rdi = 0000000000000000
    RIP = fffff8800bd49e54 rsp = fffff8800efc75e0 rbp = 0000000000000001
    R8 = 0000000000000000 r9 = 0000000000000000 r10 = 002 005000440052 d
    R11 = fffff8800efc7740 r12 = 0000000000000000 r13 = 0000000000000000
    R14 = 0000000000000000 r15 = 0000000000000000
    iopl = 0 nv in pe of na EI ng nz nc
    Rdpdr! CTransportVC::CloseChannels + 0x18:
    fffff880 '0bd49e54 488b 4148 mov rax, qword ptr [rcx + 48 h] ds:00000000' 00000048 =?

    3: kd > u @rip
    Rdpdr! CTransportVC::CloseChannels + 0x18:
    fffff880'0bd49e54 488b 4148 mov rax, qword ptr [rcx + 48 h]
    fffff880'0bd49e58 488bf1 mov rsi, rcx
    fffff880'0bd49e5b 4883c 148 Add rcx, 48 h
    fffff880'0bd49e5f 4533ed xor r13d, r13d
    fffff880'0bd49e62 ff5018 call qword ptr [rax + 18 h]
    fffff880'0bd49e65 4c39aed0000000 cmp qword ptr [rsi + 0D0h], r13
    fffff880'0bd49e6c 7473 I rdpdr! CTransportVC::CloseChannels + 0xa5 (fffff880'0bd49ee1)
    fffff880'0bd49e6e 4533e4 xor r12d, r12d

    3: kd >! thread fffff880'0bd49ee1
    fffff8800bd49ee1 is not a thread object, interpreting as stack value...
    Page 126fa90 not present in the dump file. Type ".hh dbgerr004" for more details
    TYPE mismatch for the object thread at fffff8800bd49ee1
    3: kd >! thread fffff880'0bd49e6c
    fffff8800bd49e6c is not a thread object, interpreting as stack value...
    Page 126fa90 not present in the dump file. Type ".hh dbgerr004" for more details
    TYPE mismatch for the object thread at fffff8800bd49e6c
    3: kd > dt_DEVICE_OBJECT fffff880'0bd46d7b
    NT! _DEVICE_OBJECT
    + 0 x 000 type: 0n-29368
    + 0 x 002 size: 0xf08f
    + 0 x 004 ReferenceCount: 0n1157627905
    + 0 x 008 DriverObject: 0x15fff08b'd233c033 _DRIVER_OBJECT
    + 0 x 010 NextDevice: 0x609f8b4c'fffe3451 _DEVICE_OBJECT
    + 0 x 018 AttachedDevice: 0x01608f8d'48000001 _DEVICE_OBJECT
    + 0 x 020 CurrentIrp: 0xed852053'ff410000 _IRP
    + 0 x 028 timer: 0x8b485278'f6855674 _IO_TIMER
    + 0 x 030 indicators: 0xd09f
    + 0 x 034 features: 0xdb854800
    + 0 x 038 Vpb: 0 x 76307339'f6334674 _VPB
    + 0 x 040 DeviceExtension: 0x00d0938b' empty 48ed333d
    + 0 x 048 DeviceType: 0x7c830000
    + 0x04c StackSize: 42 ' *'
    + 0 x 050 queued:
    + 0 x 098 AlignmentRequirement: 0x186f8d4c
    + 0x0a0 DeviceQueue: _KDEVICE_QUEUE
    + 0x0c8 CPD: _KDPC
    + 0 x 108 ActiveThreadCount: 0x247c8b48
    + 0 x 110 SecurityDescriptor: 0x30c48348'6024748 b vacuum
    + 0x118 DeviceLock: _KEVENT
    + 0 x 130 SectorSize: 0 x 5741
    + 0 x 132 Spare1: 0 8348 x
    + 0 x 138 DeviceObjectExtension: 0x08b93944'e98b48ff _DEVOBJ_EXTENSION
    + 0 x 140 reserved: 0 x 00064384' empty 0f000002
    3: kd >! devobj 0x15fff08b'd233c033
    15fff08bd233c033: could not read the device object or _DEVICE_OBJECT not found
    3: kd >! devobj 0x609f8b4c'fffe345
    609f8b4cfffe345: could not read the device object or _DEVICE_OBJECT not found
    3: kd >! devobj 0x01608f8d'48000001
    1608f8d48000001: could not read the device object or _DEVICE_OBJECT not found

    ===========================================================

    KD >! thread
    WIRE fffffab024cb1b50 Teb 0c50.3e40 Cid: 000007fffffae000 Win32Thread: 0000000000000000 PROCESSOR 3
    The IRP list:
    fffffab0249882f0: (0006,0118) flags: 00060000 Mdl: 00000000
    Borrow not identity
    DeviceMap fffff8a0022058d0
    Own fffffab02fc2c9c0 Image process: svchost.exe
    Joint process s/o Image: n/a
    Wait start TickCount 66109057 ticks: 0
    Context switch count IdealProcessor 79: 3
    Get_user_time 00:00:00.015
    KernelTime 00:00:00.000
    0x0000000076eef5d0 Win32 start address
    Stack Init fffff8800efc7c70 current fffff8800efc74b0
    Basic fffff8800efc8000 limit fffff8800efc2000 dial 0
    Priority 9 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
    Child-SP RetAddr: Args to child: call Site
    fffff880'0efc6338 fffff800'020 d 3929: 00000000' 0000003b 00000000' c0000005 fffff880 '0bd49e54 fffff880' 0efc6c00: nt! KeBugCheckEx
    fffff880 '0efc6340 fffff800' 020d327c: fffff880'0efc73a8 fffff880 '0efc6c00 00000000 00000000' fffff800' 020ffc28: nt! KiBugCheckDispatch + 0 x 69
    fffff880 '0efc6480 fffff800' 020ff72d: fffff800 '022fbc24 fffff800 ' 02221880 fffff800' 02064000 fffff880' 0efc73a8: nt! KiSystemServiceHandler + 0x7c
    fffff880 '0efc64c0 fffff800' 020fe505: fffff800 ' 02228158 fffff880 '0efc6538 fffff880' 0efc73a8 fffff800' 02064000: nt! RtlpExecuteHandlerForException + 0xd
    fffff880 '0efc64f0 fffff800' 0210fa31: fffff880 '0efc73a8 fffff880' 0efc6c00 fffff880 'fffffab0 00000000' 00000007: nt! RtlDispatchException + 0 x 415
    fffff880 '0efc6bd0 fffff800' 020d3a02: fffff880 '0efc73a8 00000000 00000000' fffff880' 0efc7450 00000000' 00000000: nt! KiDispatchException + 0 x 135
    fffff880 '0efc7270 fffff800' 020d257a: fffffab0 00000000'00000000 00000000'00000048 ' 24988200 00000000 00000000': nt! KiExceptionDispatch + 0xc2
    "fffff880 '0efc7450 fffff880' 0bd49e54: 00000000 ' 00000004 fffff880 ' 0bd29583 00000000'00000003 00000000'00000004: nt! KiPageFault + 0x23a (TrapFrame @ fffff880'0efc7450)
    fffff880 '0efc75e0 fffff880' 0bd46d7b: fffff880 00000000'00000000 00000000'00000001 00000000'00000000 ' 0bd466d5: rdpdr! CTransportVC::CloseChannels + 0x18
    "fffff880 '0efc7620 fffff880' 0bd465c9: 00000000 ' fffffab0 00000000 ' 3029df50 00000000'00000000 00000000'00000004: rdpdr! CVCSession: disconnect + 0x7b
    fffff880 '0efc7670 fffff880' 0bd4643b: 00000000 00000000' fffff880 ' 0efc7740 fffffab0 25 d 60010 fffffab0 ' 3029df50: rdpdr! CDynVC::NotifySessionDisconnected + 0 x 71
    fffff880 '0efc76a0 fffff880' 0bd480fc: 00000000'00000634 fffffab0 '2fcffd90 00000000' 0218e140 fffffab0' 24d8a1c8: rdpdr! CDynVC::NotifySessionConnected + 0 x 47
    "fffff880 '0efc76f0 fffff880' 0bd46020: 00000000 ' fffff8a0 00000620 '101b525e fffffab0' 249882f0 fffff880 ' 0efc77e0: rdpdr! CFileVC::DeviceIoControl + 0x15c
    fffff880 '0efc77d0 fffff880' 0bd35a19: fffffab0'249882f0 fffff8a0 '101b 5250 00000000 00000000' fffffab0' 203dbb40: rdpdr! DYNVC_Dispatch + 0 x 70
    "fffff880 '0efc7800 fffff800' 023e01cb: 00000000'00000002 00000000'00000002 fffffab0 ' 20645 c 30 fffffab0 ' 249882f0: rdpdr! DrPeekDispatch + 0x61
    fffff880 '0efc7850 fffff800' 023f433a: fffffab0 ' 20645c 30 '20645 c 30 fffffab0' fffffab0 20645c 30 fffff880' 024d 7180: nt! IopSynchronousServiceTail + 0xfb
    fffff880 '0efc78c0 fffff800' 023f43d6: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! IopXxxControlFile + 0xc27
    fffff880'0efc7a00 fffff800'020 d 3613: 00000000'00000018 00000000' 0218e910 00000000' 0218e630 00000000' 00aa1810: nt! NtDeviceIoControlFile + 0 x 56
    fffff880 '0efc7a70 00000000' 76f1bbaa: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSystemServiceCopyEnd + 0 x 13 (TrapFrame @ fffff880'0efc7ae0)
    00000000' 0218dfb8 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: 0x76f1bbaa

    3: kd >! PRI fffffab0249882f0
    IRP is active with 1 1 batteries is current (= 0xfffffab0249883c0)
    No Mdl: No system buffer only: thread fffffab024cb1b50: Irp stack trace.
    cmd flg cl device file completion-context
    > [0 e] 5 0 fffffab02fcffd90 fffffab020645c30 00000000-00000000
    \Driver\RDPDR
    Args: 00000000 00000052 00388403 0218e140
    3: kd >! thread fffffab024cb1b50
    WIRE fffffab024cb1b50 Teb 0c50.3e40 Cid: 000007fffffae000 Win32Thread: 0000000000000000 PROCESSOR 3
    The IRP list:
    fffffab0249882f0: (0006,0118) flags: 00060000 Mdl: 00000000
    Borrow not identity
    DeviceMap fffff8a0022058d0
    Own fffffab02fc2c9c0 Image process: svchost.exe
    Joint process s/o Image: n/a
    Wait start TickCount 66109057 ticks: 0
    Context switch count IdealProcessor 79: 3
    Get_user_time 00:00:00.015
    KernelTime 00:00:00.000
    0x0000000076eef5d0 Win32 start address
    Stack Init fffff8800efc7c70 current fffff8800efc74b0
    Basic fffff8800efc8000 limit fffff8800efc2000 dial 0
    Priority 9 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
    Child-SP RetAddr: Args to child: call Site
    fffff880'0efc6338 fffff800'020 d 3929: 00000000' 0000003b 00000000' c0000005 fffff880 '0bd49e54 fffff880' 0efc6c00: nt! KeBugCheckEx
    fffff880 '0efc6340 fffff800' 020d327c: fffff880'0efc73a8 fffff880 '0efc6c00 00000000 00000000' fffff800' 020ffc28: nt! KiBugCheckDispatch + 0 x 69
    fffff880 '0efc6480 fffff800' 020ff72d: fffff800 '022fbc24 fffff800 ' 02221880 fffff800' 02064000 fffff880' 0efc73a8: nt! KiSystemServiceHandler + 0x7c
    fffff880 '0efc64c0 fffff800' 020fe505: fffff800 ' 02228158 fffff880 '0efc6538 fffff880' 0efc73a8 fffff800' 02064000: nt! RtlpExecuteHandlerForException + 0xd
    fffff880 '0efc64f0 fffff800' 0210fa31: fffff880 '0efc73a8 fffff880' 0efc6c00 fffff880 'fffffab0 00000000' 00000007: nt! RtlDispatchException + 0 x 415
    fffff880 '0efc6bd0 fffff800' 020d3a02: fffff880 '0efc73a8 00000000 00000000' fffff880' 0efc7450 00000000' 00000000: nt! KiDispatchException + 0 x 135
    fffff880 '0efc7270 fffff800' 020d257a: fffffab0 00000000'00000000 00000000'00000048 ' 24988200 00000000 00000000': nt! KiExceptionDispatch + 0xc2
    "fffff880 '0efc7450 fffff880' 0bd49e54: 00000000 ' 00000004 fffff880 ' 0bd29583 00000000'00000003 00000000'00000004: nt! KiPageFault + 0x23a (TrapFrame @ fffff880'0efc7450)
    fffff880 '0efc75e0 fffff880' 0bd46d7b: fffff880 00000000'00000000 00000000'00000001 00000000'00000000 ' 0bd466d5: rdpdr! CTransportVC::CloseChannels + 0x18
    "fffff880 '0efc7620 fffff880' 0bd465c9: 00000000 ' fffffab0 00000000 ' 3029df50 00000000'00000000 00000000'00000004: rdpdr! CVCSession: disconnect + 0x7b
    fffff880 '0efc7670 fffff880' 0bd4643b: 00000000 00000000' fffff880 ' 0efc7740 fffffab0 25 d 60010 fffffab0 ' 3029df50: rdpdr! CDynVC::NotifySessionDisconnected + 0 x 71
    fffff880 '0efc76a0 fffff880' 0bd480fc: 00000000'00000634 fffffab0 '2fcffd90 00000000' 0218e140 fffffab0' 24d8a1c8: rdpdr! CDynVC::NotifySessionConnected + 0 x 47
    "fffff880 '0efc76f0 fffff880' 0bd46020: 00000000 ' fffff8a0 00000620 '101b525e fffffab0' 249882f0 fffff880 ' 0efc77e0: rdpdr! CFileVC::DeviceIoControl + 0x15c
    fffff880 '0efc77d0 fffff880' 0bd35a19: fffffab0'249882f0 fffff8a0 '101b 5250 00000000 00000000' fffffab0' 203dbb40: rdpdr! DYNVC_Dispatch + 0 x 70
    "fffff880 '0efc7800 fffff800' 023e01cb: 00000000'00000002 00000000'00000002 fffffab0 ' 20645 c 30 fffffab0 ' 249882f0: rdpdr! DrPeekDispatch + 0x61
    fffff880 '0efc7850 fffff800' 023f433a: fffffab0 ' 20645c 30 '20645 c 30 fffffab0' fffffab0 20645c 30 fffff880' 024d 7180: nt! IopSynchronousServiceTail + 0xfb
    fffff880 '0efc78c0 fffff800' 023f43d6: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! IopXxxControlFile + 0xc27
    fffff880'0efc7a00 fffff800'020 d 3613: 00000000'00000018 00000000' 0218e910 00000000' 0218e630 00000000' 00aa1810: nt! NtDeviceIoControlFile + 0 x 56
    fffff880 '0efc7a70 00000000' 76f1bbaa: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSystemServiceCopyEnd + 0 x 13 (TrapFrame @ fffff880'0efc7ae0)
    00000000' 0218dfb8 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: 0x76f1bbaa

    Kind regards

    Raji

    Hi all

    Did some research on Microsoft Website and found this fix to solve this problem.

    https://support.Microsoft.com/en-us/KB/2780102

    stop "0x0000003B" error when Remote Desktop Connection Broker and a Windows Server 2008 R2 SP1 or Windows 7 SP1 computer are in a farm RDS.

    This problem is caused by a race condition that occurs in dynamic virtual channels. Therefore, the rdpdr! Function CTransportVC::CloseChannels in the file Rdpdr.sys crashes.

    Kind regards

    Raji

  • TrackMania United is developing BlueScreen, System_Service_Exception

    I got TrackMania United Forever, which I played on my old computer which has Vista. A month ago I got a new computer (HP Pavilion p6202f) with Windows 7, 4 GB of RAM and a 64-bit operating system and NIVIDIA GeForce 9100. I installed TMUF and plays without any problems. However, when I quit the game, I get a blue screen and my computer shuts down. I uninstalled the game and then downloaded again with the same results. Can anyone help?  Thank you and happy new year!

    Signature of the problem:

    Problem event name: BlueScreen
    OS version: 6.1.7600.2.0.0.768.3
    Locale ID: 1033

    More information about the problem:

    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: FFFFF80002D22E1F
    BCP3: FFFFF8800838FA50
    BCP4: 0000000000000000

    OS version: 6_1_7600
    Service Pack: 0_0
    Product: 768_1

    Files helping to describe the problem:

    C:\Windows\Minidump\010110-19780-01.dmp
    C:\Users\Owner\AppData\Local\Temp\WER-44429-0.SysData.XML

    Hi Arona,

    I opened another game that is preloaded on my HP p6202f and he did the same thing (blue screen) when I stopped the game.  I found the following on the HP website.

    The following error message appears when changing user or disconnect:
    System service exception stop 0x0000003b
    This error can occur when a remote control with HP support session has not completely closed.
    To avoid these errors, remove the device "Driver of HP RC mirror" as follows:
    1. Click Start , and in the search box, type Device Manager.
    2. Open the Device Manager .
    3. If a user account control window opens, click Yes .
    4. Double-click display adapters .
    5. Click OK .
    6. HP RC mirror driver right click and select Uninstall and select delete the driver for this device (if present).
    7. Uninstall all instances of HP RC driver mirror if more of a figure.
    8. Close Device Manager, and then restart the computer.

      It worked and now my game is back.

      Thank you
      Vic77

  • Satellite C870D - blue screen / reboot randomly

    Hi all

    I recently bought a satellite c870d (uk) and the last week or so from time to time, usually when browsing the internet or do I change the window I look (for example flicking of internet explorer on the desktop) the computer to crash and bring up the blue screen of death saying your computer has encountered a problem and it says system service exception.

    wondering if anyone knows how I can solve this problem?
    All drivers are up-to-date of which I'm aware, but im tired of constantly losing my job now that she saves nothing before the crash

    Signature of the problem
    Problem event name: BlueScreen
    OS version: 6.2.9200.2.0.0.768.101
    Locale ID: 2057

    Additional information about the problem
    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: 000000015D 505000
    BCP3: FFFFF8801CE2EFC0
    BCP4: 0000000000000000
    OS version: 6_2_9200
    Service Pack: 0_0
    Product: 768_1
    Bucket ID: 0x3B_win32k! SURFACE::bDeleteSurface

    Post edited by: markhamilton

    just updated display drivers but had the same problem again after 10 minutes of general use, had opened internet Explorer and / or chrome and is going to change the window, I watched and it crashed

    Post edited by: markhamilton

    Hello

    BSOD (blue screen of death) is primarily a result of software or hardware problems.
    It could be a software compatibility issue or just one of the hardware components (RAM, motherboard) could be faulty.

    I found some info on the BSOD * BCCode: 3B *.

    + Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION +.
    + Bug SYSTEM_SERVICE_EXCEPTION control has a value of 0x0000003B. +
    + Which indicates that an exception happened during execution of a routine that passes from non-preferred to the privileged code code. +

    _Cause_
    + This error has been linked to the excessive use of expanded memory and resulting from user mode graphics drivers enjambment and passing data incorrect of the kernel code. +

    So, it seems that 0x3B errors are usually caused by a defective video card drivers.

  • Server 2008 help crash dump

    Hello
    I need help analyzing the dump file. My server crashed during the night (yet) and I can't identify the reason why. This produced about every two weeks.
    Microsoft (R) Windows debug 6.12.0002.633 AMD64 Version
    Copyright (c) Microsoft Corporation. All rights reserved.
    Loading dump file [C:\Windows\Minidump\070913-25084-01.dmp]
    The mini kernel dump file: only registers and the trace of the stack are available
    Symbol search path is: SRV * C:\Symbols* http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) free x 64
    Product: LanManNt, suite: TerminalServer SingleUserTS
    By: 7601.17944.amd64fre.win7sp1_gdr.120830 - 0333
    Computer name:
    Kernel base = 0xfffff800 '01816000 PsLoadedModuleList = 0xfffff800' 01a5a670
    The debugging session: Wed Jul 9 23:03:51.081 2013 (UTC + 02:00)
    Adding system: 19 days 22:55:13.717
    Loading the kernel symbols
    ...............................................................
    ................................................................
    ..................
    Loading user symbols
    Loading unloaded module list
    ...........
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************
    Use! analyze - v to obtain detailed debugging information.
    Bugcheck 3B {c0000005, fffff88005dd19a1, fffff8800969cb30, 0}
    Probably caused by: zaccess.sys (zaccess + 1d9a1)
    Follow-up: MachineOwner
    ---------
    5: kd >! analyze - v
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************
    System_service_exception (3B)
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffff88005dd19a1, the address of the instruction that caused the error checking
    Arg3: fffff8800969cb30, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.
    Debugging information:
    ------------------
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - the instruction at 0 x % lx 08 referenced memory at 0 x % 08 lx. The memory could not be %s.
    FAULTING_IP:
    zaccess + 1d9a1
    fffff880'05dd19a1 0fbe494c movsx ecx, byte ptr [rcx + 4Ch]
    CONTEXT: fffff8800969cb30-(.cxr 0xfffff8800969cb30)
    Rax = 000000000000000a rbx = 0000000000000005 rcx = 0000000000000000
    RDX = fffffa80135c04c0 rsi = rdi = fffff8800969d580 fffffa8014dba340
    RIP = fffff88005dd19a1 rsp = fffff8800969d510 rbp = fffffa80133e0968
    R8 = fffffa800f903e70 r9 = 0000000000000000 r10 = 005 007300780073
    R11 = 0000000000000022 r12 = fffffa80135c04c0 r13 = fffffa801b651c00
    R14 = 0000000000000000 r15 = fffffa800f773060
    iopl = 0 nv up ei pl nz na po nc
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010206
    zaccess + 0x1d9a1:
    fffff880'05dd19a1 0fbe494c movsx ecx, byte ptr [rcx + 4Ch] b ds:002: 00000000'0000004 c =?
    ?
    Reset the default scope
    CUSTOMER_CRASH_COUNT: 1
    DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP
    BUGCHECK_STR: 0X3B
    Nom_processus: caagstart.exe
    CURRENT_IRQL: 0
    LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff88005dd19a1
    STACK_TEXT:
    fffff880'0969 d 510 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: zaccess + 0x1d9a1
    FOLLOWUP_IP:
    zaccess + 1d9a1
    fffff880'05dd19a1 0fbe494c movsx ecx, byte ptr [rcx + 4Ch]
    SYMBOL_STACK_INDEX: 0
    SYMBOL_NAME: zaccess + 1d9a1
    FOLLOWUP_NAME: MachineOwner
    MODULE_NAME: zaccess
    Nom_image: zaccess.sys
    DEBUG_FLR_IMAGE_TIMESTAMP: 5146f52f
    STACK_COMMAND: .cxr 0xfffff8800969cb30; Ko
    FAILURE_BUCKET_ID: X64_0x3B_zaccess + 1d9a1
    BUCKET_ID: X64_0x3B_zaccess + 1d9a1
    Follow-up: MachineOwner
    ---------
    5: kd > lmvm zaccess
    start end module name
    fffff880 '05db4000 fffff880' 05dfb000 zaccess T (no symbol)
    Loaded symbol image file: zaccess.sys
    Image path: \SystemRoot\SYSWOW64\Drivers\zaccess.sys
    Image name: zaccess.sys
    Timestamp: Mon Mar 18 12:06:23 2013 (5146F52F)
    CheckSum: 0004C1F3
    ImageSize: 00047000
    Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4

    Please repost under Server blog and you can get the best exposure for viable solutions

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

  • BSOD Vista KS.sys

    Just started getting the BSOD with the ks.sys BSOD error. I am attaching the .dmp files as I do not understand what is the cause.

    Signature of the problem:
    Problem event name: BlueScreen
    The system version: 6.0.6001.2.1.0.768.3
    Locale ID: 2057
    More information about the problem:
    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: FFFFFA600421A0FE
    BCP3: FFFFFA60051F3E40
    BCP4: 0000000000000000
    OS version: 6_0_6001
    Service Pack: 1_0
    Product: 768_1

    Hello AndrewMenzies,

    I took a look in the dump that you file sent and it seems that ks.sys may actually be the victim here.

    Before ks.sys, atihdLH6.sys appears in the stack.  Since it is a minidump, I can't read the dismount, but we generally see a third-party driver sending an invalid parameter to the top of the stack.

    The atihdLH6 driver is fairly new - March 2011.  We check with ATI to see if they have an update for it.  If this isn't the case, then we could revisit the driver that came out before this iteration.

    Here is my analysis of the discharge.  My comments are in "BOLD":

    The mini kernel dump file: only registers and the trace of the stack are available

    Symbol search path is: SRV * c:\websymbols* http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (4 procs) free x 64
    Product: WinNt, suite: TerminalServer personal TerminalServer
    By: 6001.18538.amd64fre.vistasp1_gdr.101014 - 0432
    Computer name:
    Kernel base = 0xfffff800' 01b 59000 PsLoadedModuleList = 0xfffff800'01e1edb0
    The debugging session: 11:43:14.656 Wed Jul 20 2011 (UTC - 05:00)
    System Uptime: 0 days 0:00:23.825

    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************

    Use! analyze - v to obtain detailed debugging information.

    Bugcheck 3B {c0000005, fffffa600421a0fe, fffffa60051f3e40, 0}

    Probably caused by: ks.sys (ks! KspPinPropertyHandler + 17 (a)<-- debugger="" blames="" ks.sys-="" but="" it="" looks="" like="" it="">
    Follow-up: MachineOwner actually the victim here.
    ---------

    2: kd >! analyze - v
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************

    System_service_exception (3B)<-- stop="" code="" and="">
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffffa600421a0fe, the address of the instruction that caused the error checking
    Arg3: fffffa60051f3e40, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.

    Debugging information:
    ------------------

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - the instruction at 0 x % lx 08 referenced memory at 0 x % 08 lx. The memory could not be %s.

    FAULTING_IP:
    Msg KspPinPropertyHandler + 17
    fffffa60'0421a0fe 448b0a mov r9d, dword ptr [rdx]<-- this="" could="" very="" well="" be="" from="" a="" bad="" parameter="" that="">
    CONTEXT: fffffa60051f3e40-(.cxr 0xfffffa60051f3e40) spent on top of the stack.
    Rax = fffffa80071324e8 rbx = 0000000000000000 rcx = 0000000000000000
    RDX = 0000000000000000 rsi = rdi fffffa80071322b0 = 0000000000000008
    RIP = fffffa600421a0fe rsp = fffffa60051f46a0 rbp = 0000000000000001
    R8 = 0000000000000001 r9 = 0000000000000002 r10 = fffff8800096e140
    R11 = 00000000fffffff8 r12 = r13 0000000000000008 = fffff8800096e140
    R14 = 00000000ffffffff r15 = 0000000000000001
    iopl = 0 nv in pe of na EI pl nz nc
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010202
    MSG KspPinPropertyHandler + 0x17a:
    fffffa60'0421a0fe 448b0a mov r9d, dword ptr [rdx] b ds:002: 00000000'00000000 =?
    Reset the default scope

    2: kd > .cxr 0xfffffa60051f3e40<-- getting="" context="">
    Rax = fffffa80071324e8 rbx = 0000000000000000 rcx = 0000000000000000
    RDX = 0000000000000000 rsi = rdi fffffa80071322b0 = 0000000000000008
    RIP = fffffa600421a0fe rsp = fffffa60051f46a0 rbp = 0000000000000001
    R8 = 0000000000000001 r9 = 0000000000000002 r10 = fffff8800096e140
    R11 = 00000000fffffff8 r12 = r13 0000000000000008 = fffff8800096e140
    R14 = 00000000ffffffff r15 = 0000000000000001
    iopl = 0 nv in pe of na EI pl nz nc
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010202
    MSG KspPinPropertyHandler + 0x17a:
    fffffa60'0421a0fe 448b0a mov r9d, dword ptr [rdx] b ds:002: 00000000'00000000 =?
    2: kd > kv
    Resets to the last context set-.thread/.cxr stack trace it
    Child-SP RetAddr: Args to child: call Site
    "fffffa60 '051f46a0 fffffa60' 0422001b: fffffa80 '071322b 0 fffffa80 ' 07189460 fffffa80' 071322b 0 fffff880 ' 009a 8880: ks! KspPinPropertyHandler + 0x17a
    "fffffa60 '051f46f0 fffffa60' 042f4f32: 00000000' 7070534b fffffa80 ' 07189460 fffff880 ' 009a57e0 00000000'00000020: ks! KsPinPropertyHandler + 0x1b
    fffffa60 '051f4730 fffffa60' 042172ab: fffffa80 '071322b 0 fffffa80' 066f53f0 00000000'00000000 00000000'00000003: portcls! PcPinPropertyHandler + 0 x 152
    fffffa60 '051f4770 fffffa60' 0422059b: 00000000 '00000000 fffff880' fffffa60 00000003 '051f4880 fffff880' 009a8ab0: ks. KspPropertyHandler + 0x6cb
    fffffa60 '051f47d0 fffffa60' 042f5904: fffffa60 ' 051f4880 fffff880 '009a8ab0 fffffa80' 071322b 0 fffffa80 ' 0675dcc0: ks. KsPropertyHandler + 0x1b
    "fffffa60'051f4820 fffffa60'0430869 c: 00000000 ' 00000001 fffffa80 ' 071322b 0 fffffa80 '066f5540 fffffa60' 042d90cb: portcls! PcHandlePropertyWithTable + 0 x 64
    fffffa60 '051f4850 fffffa60' 042f4b01: fffffa80 ' 071322b 0 fffffa80 '066f53f0 fffffa80' 066f5540 fffffa60 ' 051f4a88: portcls! CPortFilterWaveRT::DeviceIoControl + 0 x 144
    fffffa60'051f48b0 fffffa60'042176 8 d: 00000000' c000000d fffffa80 '071324e8 fffffa80' 066f53f0 00000000'60000000: portcls! DispatchDeviceIoControl + 0 x 79
    fffffa60 '051f48e0 fffffa60' 042f406c: fffffa60'051f4a18 11cf51ad '134960 0000 8 c 101' 00000001 f8948a87 c' 00000003: ks! KsDispatchIrp + 0xd8
    fffffa60'051f4910 fffffa60'042 d 3765: 00000000 ' 00000001 fffffa80' 07132530 fffffa60 '051f4a00 fffffa60' 04336a 87: portcls! PcDispatchIrp + 0x5c

    "fffffa60'051f4940 00000000 00000001': fffffa80 ' 07132530 '051f4a00 fffffa60' fffffa60 04336a 87 fffffa80 ' 071322b 0: AtihdLH6 + 0x1b765<-- 3rd="" party="">

    fffffa60'051f4948 fffffa80'07132530: fffffa60'051f4a00 fffffa60 '04336-87 fffffa80' 071322b 0 00000000 00000000': 0 x 1
    fffffa60 '051f4950 fffffa60' 051f4a00: fffffa60'04336 has 87 fffffa80 '071322b 0 00000000 00000000' fffffa80' 0675dcc0: 0xfffffa80'07132530
    fffffa60 '051f4958 fffffa60' 04336a 87: fffffa80' 071322b 0 00000000 00000000' fffffa80 '0675dcc0 fffffa80' 071322b 0: 0xfffffa60'051f4a00
    "" fffffa60 '051f4960 fffffa60' 043367dd: 00000000 ' 00000001 fffffa80 ' 071324e8 fffffa80 ' 07132530 fffffa80 ' 071322b 0: ksthunk! CKSThunkDevice::DispatchIoctl + 0xcf
    fffffa60 '051f4990 fffff800' 01f31a6a: fffffa80 '0675dcc0 fffffa60' 051f4ca0 00000000'00000000 00000000'00000001: ksthunk! CKernelFilterDevice::DispatchIrp + 0x11d
    fffffa60 '051f49f0 fffff800' 01f4a966: fffffa80'06e87c10 00000000'00000000 00000000'00000000 00000000'00000000: nt! IopXxxControlFile + 0x5da
    fffffa60 '051f4b40 fffff800' 01cadeb3: fffff880'0aea91e0 fffffa80 '06ebd700 00000000'00000300 fffff800' 01f2a634: nt! NtDeviceIoControlFile + 0 x 56
    fffffa60 '051f4bb0 00000000' 7739507a: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSystemServiceCopyEnd + 0 x 13 (TrapFrame @ fffffa60'051f4c20)
    00000000' 0160f3a8 00000000'00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: 0x7739507a
    2: kd > lmvm AtihdLH6
    start end module name
    fffffa60'042 b 8000 fffffa60'042 d 8000 AtihdLH6 T (no symbol)
    Loaded symbol image file: AtihdLH6.sys
    Image path: \SystemRoot\system32\drivers\AtihdLH6.sys
    Image name: AtihdLH6.sys
    Timestamp: Kills Mar 31 02:15:13 2011 (4D942A01)<-- driver="" is="" fairly="" new. ="" we="" should="" check="" for="" an="" update="" for="" it="" or="" revert="" to="" earlier="">

    Let us know if you have any questions.

    Best regards

    Matthew_Ha

  • RESTART THE COMPUTER AFTER BLUE SCREEN

    I use windows 7 64 bit peacefully at the moment sometimes until a few weeks before. My computer reboots intermittently then it display message windows recovery shows the details of the error. Signature of the problem:
    Problem event name: BlueScreen
    The system version: 6.1.7600.2.0.0.256.1
    Locale ID: 1033

    More information about the problem:
    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: FFFFF9600010E309
    BCP3: FFFFF88007522060
    BCP4: 0000000000000000
    OS version: 6_1_7600
    Service Pack: 0_0
    Product: 256_1

    Above are the details of the error. Please help me.

    I've also posted the dump file on my skydrive. This is the link http://cid-6bce03f6d07a7c2a.skydrive.live.com/self.aspx/blue%20screen

    Hello

    Generally, this error is caused by video drivers so use the methods in the driver section below to
    update your drivers manually. Using device update management drivers one or even a scanner
    on the site of the manufacturer of the device will not get the job done correctly. Other possible influences are antivirus.
    programs of antispyware/security including firewall part 3 - which ones do you use and which
    already have on the computer?

    Also update the BIOS if available.

    If necessary the BlueScreenViewer allows you to validate the information in a message here that will allow
    all this to see the info without having to download it and for them to download. Its a small and very
    easy to use utility which is free.

    BCCode: 3B 0x0000003b

    Cause

    This error has been linked to the excessive use of expanded memory and can occur due to user mode
    graphics drivers enjambment and pass incorrect data of the kernel code.

    BCCode: 3B 0x0000003b
    http://www.faultwire.com/solutions-fatal_error/system-service-exception-0x0000003B-* 1074.html

    =============================================

    If you need to do more troubleshooting.

    Look in the Event Viewer to see if something is reported on those.
    http://www.computerperformance.co.UK/Vista/vista_event_viewer.htm

    MyEventViewer - free - a simple alternative in the standard Windows Event Viewer.
    TIP - Options - Advanced filter allows you to see a period of time instead of the entire file.

    http://www.NirSoft.NET/utils/my_event_viewer.html

    It is an excellent tool for displaying the blue screen error information

    BlueScreenView scans all your minidump files created during 'blue screen of death '.
    hangs and displays information about all accidents of a table - free

    http://www.NirSoft.NET/utils/blue_screen_view.html

    The output of BlueScreenView can be seen and recorded in several formats such as:
    (The default display in the program itself is excellent and can be changed in many
    views, including the page of blue screen of XP style as necessary)

    Dump file: 031210-27892 - 01.dmp
    Crash time: 2010-03-17 08:52:05
    Bug Check String: SYSTEM_SERVICE_EXCEPTION
    Bug check code: 0x0000003b
    Parameter 1: 00000000' c0000005
    Parameter 2: fffff960'0010e309
    Parameter 3: fffff880'07522060
    Parameter 4: 00000000'00000000
    Caused by the driver: win32k.sys
    Caused by the address: win32k.sys + ce309
    Description of the file: multi-user Win32 Driver
    Product name: Microsoft® Windows® Operating System
    Company: Microsoft Corporation
    File version: 6.0.6000.16386 (vista_rtm.061101 - 2205)
    CPU: x 64
    Computer name:
    Full path: C:\Windows\minidump\031210-27892-01.dmp
    Number of processors: 4
    Main version: 15
    Minor Version: 7600

    and:

    031210-27892 - 01.dmp 17/03/2010-08:52:05 SYSTEM_SERVICE_EXCEPTION 0x0000003b
    00000000' c0000005 fffff960'0010e309 fffff880'07522060 00000000 00000000' win32k.sys
    Win32k.sys + ce309 Multi-User Win32 Driver Microsoft® Windows® operating system from Microsoft
    Company 6.0.6000.16386 (vista_rtm.061101 - 2205) x 64
    C:\Windows\minidump\031210-27892-01.dmp 4 15 7600

    ============================

    It's my generic how updates of appropriate driver: (mainly updated BIOS and video well)
    others would not hurt because you are using a new OS)

    This utility, it is easy see which versions are loaded:

    -Free - DriverView utility displays the list of all device drivers currently loaded on your system.
    For each driver in the list, additional useful information is displayed: load address of the driver,
    Description, version, product name, company that created the driver and more.
    http://www.NirSoft.NET/utils/DriverView.html

    For drivers, visit manufacturer of emergency system and of the manufacturer of the device that are the most common.
    Control Panel - device - Graphics Manager - note the brand and complete model
    your video card - double - tab of the driver - write version information. Now, click on update
    Driver (this can do nothing as MS is far behind the certification of drivers) - then right-click.
    Uninstall - REBOOT it will refresh the driver stack.

    Repeat this for network - card (NIC), Wifi network, sound, mouse, and keyboard if 3rd party
    with their own software and drivers and all other main drivers that you have.

    Now in the system manufacturer (Dell, HP, Toshiba as examples) site (in a restaurant), peripheral
    Site of the manufacturer (Realtek, Intel, Nvidia, ATI, for example) and get their latest versions. (Look for
    BIOS, Chipset and software updates on the site of the manufacturer of the system here.)

    Download - SAVE - go to where you put them - right click - RUN AD ADMIN - REBOOT after
    each installation.

    Always check in the Device Manager - drivers tab to be sure the version you actually install
    presents itself. This is because some restore drivers before the most recent is installed (sound card drivers
    in particular that) so to install a driver - reboot - check that it is installed and repeat as
    necessary.

    Repeat to the manufacturers - BTW in the DO NOT RUN THEIR SCANNER device - check
    manually by model.

    Look at the sites of the manufacturer for drivers - and the manufacturer of the device manually.
    http://pcsupport.about.com/od/driverssupport/HT/driverdlmfgr.htm

    How to install a device driver in Vista Device Manager
    http://www.Vistax64.com/tutorials/193584-Device-Manager-install-driver.html

    If you update the drivers manually, then it's a good idea to disable the facilities of driver under Windows
    Updates, that leaves about Windows updates but it will not install the drivers that will be generally
    older and cause problems. If updates offers a new driver and then HIDE it (right click on it), then
    get new manually if you wish.

    How to disable automatic driver Installation in Windows Vista - drivers
    http://www.AddictiveTips.com/Windows-Tips/how-to-disable-automatic-driver-installation-in-Windows-Vista/
    http://TechNet.Microsoft.com/en-us/library/cc730606 (WS.10) .aspx

    Hope these helps.

    Rob - bicycle - Mark Twain said it is good.

  • W2K3 64bits

    Where can you get support for 64-bit Win 2003 Server?  Event ID - 1001 error checking and
    Event ID = 1003 system error.  I can't find any help with my codes.  Does anyone know where I can get help with this?

    Event ID 1001

    Error checking

    code 0x0000003b (0x00000000C00000005, 0xfffffadf29209ec4, 0xfffffadf25367e50, ox0000000000000000)

    Event ID = 1003 system error

    000000000000003b, parameter1 00000000c 0000005, fffffadf29208ec4, fffffadf25367e50, parameter3, parameter4 0000000000000000 parameter 2

    Windows Server 2003: http://technet.microsoft.com/en-gb/windowsserver/bb512919

    Windows Server-Forum: http://social.technet.microsoft.com/Forums/en-US/category/windowsserver

    Bug Check information from the debugging tools:

     
    Debugging tools for Windows

    Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION

    The SYSTEM_SERVICE_EXCEPTION bug control has a value of 0x0000003B. This indicates that an exception happened during execution of a routine that passes from non-preferred to the privileged code code.

    Parameters

    The following settings are displayed on the blue screen.

    Parameter Description
    1 The exception that caused the bug control
    2 The address of the exception record for the exception that caused the bug control
    3 The address of the context record to the exception that caused the bug control
    4 0

    Cause

    This error has been linked to the excessive use of expanded memory and resulting from user mode graphics drivers enjambment and passing data incorrect of the kernel code.


    © 2009 Microsoft Corporation
    Send your comments to this topic
    Debugging tools for Windows
    January 17, 2009
    Build machine: CAPEBUILD
  • I get blue screen whenever I download anything

    Hi, I get a blue screen. It seems to only happen when I download or just after. I just had my hard drive replaced by dell and had geek team look at to this problem, and they are.

    This is the info I have beem able to find

    I'm not too good with computers, I only know the basics and don't really have the money to take it anywhere else for help.

    Signature of the problem:

    Problem event name: BlueScreen

    The system version: 6.0.6002.2.2.0.768.3

    Locale ID: 1033

    More information about the problem:

    BCCode: 3B

    BCP1: 00000000C 0000005

    BCP2: FFFFF80001AFCFAA

    BCP3: FFFFFA6015630F60

    BCP4: 0000000000000000

    OS version: 6_0_6002

    Service Pack: 2_0

    Product: 768_1

    Files helping to describe the problem:

    C:\Windows\Minidump\Mini012111-01.dmp

    C:\Users\Owner\AppData\Local\Temp\WER-63305-0.SysData.XML

    C:\Users\Owner\AppData\Local\Temp\WERFE0C.tmp.version.txt

    Read our privacy statement:

    Hello

    Resolve errors stop (blue screen) in Windows 7 - has a section for if you can or cannot start Windows.
    http://Windows.Microsoft.com/en-us/Windows7/resolving-stop-blue-screen-errors-in-Windows-7

    Check this item thead for more information on using BlueScreenView, MyEventViewer and other methods of
    Troubleshooting BlueSceens - answers top 3 (+ 1 more).

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-system/sometimes-i-get-a-blue-screen-when-using-IE-8/c675b7b8-795f-474d-a1c4-6b77b3fcd990

    We can analyze the minidumps if make you it available to the SkyDrive or another file
    sharing sites (such as MediaFire). If you have problems to download the copy of minidumps
    for the office or in the Documents folder and download them from there.

    ZIP or download the content of the C:\Windows\minidump

    Use SkyDrive to upload collected files.
    http://social.technet.Microsoft.com/forums/en-us/w7itproui/thread/4fc10639-02dB-4665-993a-08d865088d65

    -------------------------------------------------------------------------

    Also this, so you can see the probable bluescreens.

    Windows Vista restarts automatically if your computer encounters an error that requires him to plant.
    (also Windows 7)
    http://www.winvistatips.com/disable-automatic-restart-T84.html

    -----------------------------------------------------------------------------------------------------------

    BCCode: 3B 0x0000003b

    Try to remove and replace the cards memory and cables (both ends where possible)-in fact
    delete and replace - not just in the warm (on a PC) and clean the dust bunnies and vents. On
    a laptop on everything that can be done is to reinstall the memory and clean the vents. (Of course delete
    ALL power before opening the case).

    Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION

    The SYSTEM_SERVICE_EXCEPTION bug control has a value of 0x0000003B. This indicates that an exception happened during execution of a routine that passes from non-preferred to the privileged code code.

    Important info if you received a STOP Code

    If you received a blue error screen, or a stop code, the computer stopped abruptly to protect against data loss. A hardware device, its driver or software might have caused this error. If your copy of Windows is shipped with your computer, contact your computer manufacturer. If you purchased Windows separately from your computer, Microsoft provides support. To find contact information for Microsoft or the manufacturer of your computer, Contact Support.

    If you have experience with computers and try to recover from this error, follow the steps in the Microsoft article solution STOP (blue screen) errors in Windows.

    These actions could prevent a mistake like this does not happen:

    1. Download and install updates for your computer from Windows Update device drivers.
    2. Scan your computer for computer viruses.
    3. Check your hard drive for errors.

    System_service_exception parameters

    The following settings are displayed on the blue screen.

    Parameter Description

    1

    The exception that caused the bug control

    2

    The address of the exception record for the exception that caused the bug control

    3

    The address of the context record to the exception that caused the bug control

    4

    0


    Cause

    This error has been linked to the excessive use of expanded memory and resulting from user mode graphics drivers enjambment and passing data incorrect of the kernel code.

    BCCode: 3B 0x0000003b<-- read="" this="">
    http://www.faultwire.com/solutions-fatal_error/system-service-exception-0x0000003B-* 1074.html

    ============================================================

    Vista and Windows 7 updated drivers love then here's how update the most important.

    References to Vista also apply to Windows 7.

    It's my generic how updates of appropriate driver: (updating the video/display driver and BIOS)

    This utility, it is easy see which versions are loaded:

    -Free - DriverView utility displays the list of all device drivers currently loaded on your system.
    For each driver in the list, additional useful information is displayed: load address of the driver,
    Description, version, product name, company that created the driver and more.
    http://www.NirSoft.NET/utils/DriverView.html

    For drivers, visit manufacturer of emergency system and of the manufacturer of the device that are the most common.
    Control Panel - device - Graphics Manager - note the brand and complete model
    your video card - double - tab of the driver - write version information. Now, click on update
    Driver (this can do nothing as MS is far behind the certification of drivers) - then right-click.
    Uninstall - REBOOT it will refresh the driver stack.

    Repeat this for network - card (NIC), Wifi network, sound, mouse, and keyboard if 3rd party
    with their own software and drivers and all other main drivers that you have.

    Now in the system manufacturer (Dell, HP, Toshiba as examples) site (in a restaurant), peripheral
    Site of the manufacturer (Realtek, Intel, Nvidia, ATI, for example) and get their latest versions. (Look for
    BIOS, Chipset and software updates on the site of the manufacturer of the system here.)

    Download - SAVE - go to where you put them - right click - RUN AD ADMIN - REBOOT after
    each installation.

    Always check in the Device Manager - drivers tab to be sure the version you actually install
    presents itself. This is because some restore drivers before the most recent is installed (sound card drivers
    in particular that) so to install a driver - reboot - check that it is installed and repeat as
    necessary.

    Repeat to the manufacturers - BTW in the DO NOT RUN THEIR SCANNER device - check
    manually by model.

    Look at the sites of the manufacturer for drivers - and the manufacturer of the device manually.
    http://pcsupport.about.com/od/driverssupport/HT/driverdlmfgr.htm

    Installation and update of drivers under Windows 7 (updated drivers manually using the methods above
    It is preferable to ensure that the latest drivers from the manufacturer of system and device manufacturers are located)
    http://www.SevenForums.com/tutorials/43216-installing-updating-drivers-7-a.html

    If you update the drivers manually, then it's a good idea to disable the facilities of driver under Windows
    Updates, that leaves about Windows updates but it will not install the drivers that will be generally
    older and cause problems. If updates offers a new driver and then HIDE it (right click on it) and
    Then, get new ones manually if you wish.

    How to stop Windows 7 automatically install drivers
    http://support.Microsoft.com/kb/2500967

    ----------------------------------------------------------------------------------------

    Tests of memory intercept all errors such as memory do not match (possible even for sticks
    seemingly identical) and when the faster memory is placed in system behind the slower memory.
    So it is best to Exchange also sticks in and out to check for those, even if all the tests of memory do not
    show a problem.

    To test the RAM here control - run 4 + hours or so.<-- best="">
    www.memtest.org

    For the Windows Memory Diagnostic tool.

    Start - type in the search-> memory box - find top - click - right Memory Diagnostics tool
    RUN AS ADMIN follow the instructions

    Windows Vista: How to scan / test your memory with Windows Vista memory or RAM
    Diagnostic tool
    http://www.shivaranjan.com/2007/11/01/Windows-Vista-how-to-scan-test-your-RAM-or-memory-with-Windows-Vista-memory-diagnostic-tool/

    How to run the diagnostic tool memory in Windows 7
    http://www.SevenForums.com/tutorials/715-memory-diagnostics-tool.html

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle=""><- mark="" twain="" said="" it="">

  • BSOD after replacing hard drive

    Hey. I replaced my hard drive lately after many accidents and eventually unable to run any OS.

    With the new, after installing some drivers I get BSOD with the following Minidump file:

    Microsoft (R) Windows debug 6.3.9600.17336 AMD64 Version
    Copyright (c) Microsoft Corporation. All rights reserved.
    Loading dump file [C:\Windows\Minidump\080216-
    The mini kernel dump file: only registers and the trace of the stack are available
    Symbol of validation of the path summary *.
    Location of response time (ms)
    Deferred SRV * C:\Windows\symbol_cache*ht
    Symbol search path is: SRV * C:\Windows\symbol_cache*ht
    Executable search path is:
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) free x 64
    Product: WinNt, suite: TerminalServer SingleUserTS
    By: 7601.17514.amd64fre.win7sp1_
    Computer name:
    Kernel base = 0xfffff800 '02864000 PsLoadedModuleList = 0xfffff800' 02aa9e90
    The debugging session: killed Aug 2 18:39:04.990 2016 (UTC + 03:00)
    System Uptime: 0 days 0:08:09.473
    Loading the kernel symbols
    ..............................
    ..............................
    ............................
    Loading user symbols
    Loading unloaded module list
    ....
    ******************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    ******************************
    Use! analyze - v to obtain detailed debugging information.
    Bugcheck 3B {c0000005, fffff80002b9a640, fffff880067aec70, 0}
    Probably caused by: ntkrnlmp.exe (nt! RtlUpcaseUnicodeString + 54)
    Follow-up: MachineOwner
    ---------
    0: kd >! analyze - v
    ******************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    ******************************
    System_service_exception (3B)
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffff80002b9a640, the address of the instruction that caused the error checking
    Arg3: fffff880067aec70, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.
    Debugging information:
    ------------------
    EXCEPTION_CODE: (NTSTATUS) 0XC0000005 -.
    FAULTING_IP:
    NT! RtlUpcaseUnicodeString + 54
    fffff800'02b9a640 420fb70c48 movzx ecx, word ptr [rax + r9 * 2]
    BACKGROUND: fffff880067aec70--(.cxr 0xfffff880067aec70; r)
    Rax = 0000000000000000 rbx = fffff880067af700 rcx = fffff880067af700
    RDX = fffff880067af8a0 rsi = fffff880067af8a0 rdi = 0000000000000000
    RIP = fffff80002b9a640 rsp = fffff880067af650 rbp = 0000000000000000
    R8 = 000000000000002e r9 = 0000000000000000 r10 = fffff98000020654
    R11 = fffff880067af650 r12 = 0000000000000000 r13 = fffff880067af8a0
    R14 = fffff880067af800 r15 = fffff880067af7d8
    iopl = 0 nv up ei ng nz po cy ca
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010297
    NT
    ! RtlUpcaseUnicodeString +.
    fffff800'02b9a640 420fb70c48 movzx ecx, word ptr [rax + r9 * 2] b ds:002: 00000000'00000000 =?
    ?
    Last set context:
    Rax = 0000000000000000 rbx = fffff880067af700 rcx = fffff880067af700
    RDX = fffff880067af8a0 rsi = fffff880067af8a0 rdi = 0000000000000000
    RIP = fffff80002b9a640 rsp = fffff880067af650 rbp = 0000000000000000
    R8 = 000000000000002e r9 = 0000000000000000 r10 = fffff98000020654
    R11 = fffff880067af650 r12 = 0000000000000000 r13 = fffff880067af8a0
    R14 = fffff880067af800 r15 = fffff880067af7d8
    iopl = 0 nv up ei ng nz po cy ca
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010297
    NT! RtlUpcaseUnicodeString +.
    fffff800'02b9a640 420fb70c48 movzx ecx, word ptr [rax + r9 * 2] b ds:002: 00000000'00000000 =?
    Reset the default scope
    CUSTOMER_CRASH_COUNT: 1
    DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_
    BUGCHECK_STR: 0X3B
    NOM_PROCESSUS: BCMWLTRY. EXE
    CURRENT_IRQL: 0
    ANALYSIS_VERSION: 6.3.9600.17336 (debuggers (dbg). 150226-1500) amd64fre
    LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002b9a640
    STACK_TEXT:
    fffff880 '067af650 00000000' 00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! RtlUpcaseUnicodeString + 0 x 54
    FOLLOWUP_IP:
    NT! RtlUpcaseUnicodeString + 54
    fffff800'02b9a640 420fb70c48 movzx ecx, word ptr [rax + r9 * 2]
    SYMBOL_STACK_INDEX: 0
    SYMBOL_NAME: nt! RtlUpcaseUnicodeString + 54
    FOLLOWUP_NAME: MachineOwner
    MODULE_NAME: nt
    Nom_image: ntkrnlmp.exe
    DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7951a
    IMAGE_VERSION: 6.1.7601.17514
    STACK_COMMAND: .cxr 0xfffff880067aec70; Ko
    FAILURE_BUCKET_ID: X64_0x3B_VRF_nt!
    BUCKET_ID: X64_0x3B_VRF_nt!
    ANALYSIS_SOURCE: KM
    FAILURE_ID_HASH_STRING: km:x64_0x3b_vrf_nt!
    FAILURE_ID_HASH: {e9e5c339-1aaa-402 a - 04 b 7 -
    Follow-up: MachineOwner
    ---------

    Your system is holding to the memory of the night before and it releases is not memory free . You can force the release by restarting your computer, but often it is not very practical. Another way to force the release of standby memory is available using the RAM (freeware from Microsoft) card:
    http://TechNet.Microsoft.com/en-GB/Sysinternals/ff700229.aspx

    Download and install and create a shortcut on your desktop for RAMMap and / or PIN to the taskbar. When you sense the system becomes unresponsive, use Ctrl + Shift + Esc to access the Task Manager. Click the performance tab and the resource monitor button. Click the memory tab and check if free is close to zero, or is equal to zero. If it is, open RAMMap, click on empty on the menu bar and the empty queue. This action restores instantly free memory.

    The procedure using RAMMap is an effective workaround, but the real solution lies in the discovery of the source of the problem. Know the source, you may be able to solve the problem by contacting the provider of the software and / or update the software.

    The solution lies in the identification of the software which is access to many files, to search for malware or index to facilitate the search of Windows. If you find out which files are accessed unnecessarily you can exclude routine analyses. The first image below illustrates the problem. The second image identifies the folders / files. In the example Microsoft Security Essentials was scan my G drive, which I excluded from future scans.

    Investigate what made up the figure of Eve may not be easy. How I discovered what was the cause of this computer has been reached by following the procedure detailed below.

    RAMMap open when your Standby figure is too high and click on the file summary tab, click the column heading of Eve to sort the numbers as in the image below to determine the really big held in standby mode files, see the image below. If you click the path heading, you can sort and see what partitions are being accessed. It is important to remember that these files have been consulted since the computer was started. You ask then what program could have access to the file and it really need to? Programs with scheduled scans are potential candidates.

    In my case, I found a very large download of Windows 7 that I had used for a repair installation I had not deleted after use. I also found a large number of files on a non-related system partition for backup copies created by Windows backup utility. I decided to see if these have been regularly analyzed by Microsoft Security Essentials and them excluded from the analyses. You should also check if you are indexing more than what you need as this will increase the impact of the execution of Windows Search.

  • Windows 7 BSOD

    We have recently started getting BSOD on Dell XPS8700 with 16G of Ram, processor I7, Windows 7 Professional.

    The error is caused by ntkrnlmp.exe, process name: audiodg.exe and (sometimes) can be triggered by her disconnect and reconnect the speaker/headphone cable or line-in cable.

    Some of the information from the Minidump is listed below, and zipped Minidump and MSInfo files have been downloaded on this link OneDrive:

    https://onedrive.live.com/redir?RESID=685745AE9B3E889E! 106 & authkey =! AOCyTvAkAsOQbVc & ithint = % 2czip

    You can provide any help will be greatly appreciated.

    Thank you!

    Bugcheck 3B {c0000005, fffff800034c2a3e, fffff8800f35ec30, 0}

    Probably caused by: ntkrnlmp.exe (nt! KiSignalSynchronizationObject + 4th)

    System_service_exception (3B)
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffff800034c2a3e, the address of the instruction that caused the error checking
    Arg3: fffff8800f35ec30, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.

    DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

    BUGCHECK_STR: 0X3B

    Nom_processus: audiodg.exe

    CURRENT_IRQL: 2

    ANALYSIS_SESSION_HOST: LAPTOP_2

    ANALYSIS_SESSION_TIME: 12/05/2016 00:17:05.0764

    ANALYSIS_VERSION: 10.0.10586.567 amd64fre

    LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800034c2a3e

    STACK_TEXT:
    fffff880 '0f35f610 00000000' 00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: nt! KiSignalSynchronizationObject + 0x4e

    Update the driver Realtek Audio version 6.0.1.7525:

    http://downloads.Dell.com/FOLDER03113490M/1/XPS-8700_Audio_Driver_MN0T2_WN32_6.0.1.7525_A00.exe

    This file automatically installs automatically after downloading. Reboot required.

    Update Intel AMT HECI driver to version 11.0.0.1153:

    http://downloads.Dell.com/FOLDER03130113M/1/XPS-8700_Chipset_Driver_VJ54R_WN32_11.0.0.1153_A00.exe

    Installation

    1. navigate to the location where you downloaded the file, and then double-click the new file.

    2. read the information about the version presented in the dialogue window.

    3. download and install all of the components required in the dialogue window before proceeding.

    4. click on the button to install.

    5. follow the remaining prompts to perform the update

    Update the Chipset Intel version 10.1.1.7:

    http://downloads.Dell.com/FOLDER03130099M/1/XPS-8700_Chipset_Driver_CR5PJ_WN32_10.1.1.7_A00.exe

    This file automatically installs automatically after downloading. Reboot required.

    The 7260 Intel Wireless Driver version 17.1.0 update:

    http://www.Dell.com/support/home/us/en/19/drivers/DriversDetails?driverId=VXCDN&FILEID=3493199299&osCode=W764&ProductCode=XPS-8700&LanguageCode=en&CategoryID=NI

    Intel rapid storage technology driver update to version 14.5.0.1081:

    http://downloads.Dell.com/FOLDER03127021M/1/XPS-8700_Serial-ATA_Driver_C2JM0_WN32_14.5.0.1081_A00.exe

    This file automatically installs automatically after downloading. Reboot required.

    Updated the Realtek network driver 8111E to version 10.1.505.2015:

    http://downloads.Dell.com/FOLDER03184762M/1/XPS-8700_Network_Driver_5Y97W_WN64_10.1.505.2015_A01.exe

    Update the Nvidia graphics driver to version 10.18.13.5324:

    http://downloads.Dell.com/FOLDER03102665M/1/Video_Driver_086XM_WN32_10.18.13.5324_A00.exe

  • Intermittent BSOD with 0X000000D1

    Hello

    I have a Lenovo X 250 meeting BSOD with 0X000000D1 driver_irql_not_less_or_equal.

    Igdkmd64.sys addresses FFFFF880051AE27B, FFFFF880050EF000, Datestamp 546C13B9...

    Anyone encounter this before?

    Your support "COMPUTING" is wrong on several levels.  First of all, you have a driver of November 2014 and there are at least 3 more recent.  Secondly even though he was the most recent driver that does not mean it is not corrupt.

    Still related to the video driver

    Microsoft (R) Windows debug 10.0.10563.566 AMD64 Version
    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading dump file [C:\Users\zigza\Desktop\minidump\102115-14679-01.dmp]
    The mini kernel dump file: only registers and the trace of the stack are available

    Symbol of validation of the path summary *.
    Location of response time (ms)
    Deferred SRV * E:\symbols* http://msdl.microsoft.com/download/symbols
    Symbol search path is: SRV * E:\symbols* http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) free x 64
    Product: WinNt, suite: TerminalServer SingleUserTS
    By: 7601.23223.amd64fre.win7sp1_ldr.150928 - 0600
    Computer name:
    Kernel base = 0xfffff800 '03a 67000 PsLoadedModuleList = 0xfffff800' 03ca 9730
    The debugging session: Wed 21 Oct 2015 06:57:27.681 (UTC - 04:00)
    System Uptime: 0 days 9:58:54.618
    Loading the kernel symbols
    ...............................................................
    ................................................................
    ..........................................................
    Loading user symbols
    Loading unloaded module list
    ...........
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************

    Use! analyze - v to obtain detailed debugging information.

    Bugcheck 3B {c0000005, fffff8800513927b, fffff8802080dc20, 0}

    Probably caused by: igdkmd64.sys (igdkmd64 + bf27b)

    Follow-up: MachineOwner
    ---------

    0: kd >! analyze - v
    *******************************************************************************
    *                                                                             *
    * Bugcheck analysis *.
    *                                                                             *
    *******************************************************************************

    System_service_exception (3B)
    An exception occurred during the execution of a system service routine.
    Arguments:
    Arg1: 00000000c 0000005, Exception that caused the error checking code
    Arg2: fffff8800513927b, the address of the instruction that caused the error checking
    Arg3: fffff8802080dc20, address of the context record to the exception that caused the error checking
    Arg4: 0000000000000000, zero.

    Debugging information:
    ------------------

    SYSTEM_SKU: LENOVO_MT_20CL_BU_Think_FM_ThinkPad X 250

    SYSTEM_VERSION: ThinkPad X 250

    BIOS_DATE: 06/04/2015

    BASEBOARD_PRODUCT: 20CLCTO1WW

    BASEBOARD_VERSION: 0B 98417 WIN

    BUGCHECK_P1: c0000005

    BUGCHECK_P2: fffff8800513927b

    BUGCHECK_P3: fffff8802080dc20

    BUGCHECK_P4: 0

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - the instruction at 0 x %p memory referenced to 0 x %p. The memory could not be %s.

    FAULTING_IP:
    Igdkmd64 + bf27b
    fffff880'0513927 b 488b1b mov rbx, qword ptr [rbx]

    CONTEXT: fffff8802080dc20-(.cxr 0xfffff8802080dc20)
    Rax = 0000000006ea28f0 rbx = ffff0000004c004c rcx = 00000001062f8000
    RDX = fffffa8006ea28d0 rsi = 0000000000000060 rdi = 0000000105b 00000
    RIP = fffff8800513927b rsp = fffff8802080e600 rbp = fffffa8006ea28d0
    R8 = 0000000105b 00000 r9 = 00000000007f8000 r10 = fffff80003c56820
    R11 = fffffa800e09c6d0 r12 = fffffa800a557000 r13 = 0000000000000002
    R14 = 00000000007f8000 r15 = fffffa800a557000
    iopl = 0 nv up ei ng nz na po nc
    CS = 0010 ss = 0018 ds = 002 b're = 002 b fs = 0053 gs = 002 b efl = 00010286
    Igdkmd64 + 0xbf27b:
    fffff880 ' 0513927b 488b1b mov rbx, qword ptr [rbx] b ds:002: ffff0000 ' 004c004c =?
    Reset the default scope

    CPU_COUNT: 4

    CPU_MHZ: 892

    CPU_VENDOR: GenuineIntel

    CPU_FAMILY: 6

    CPU_MODEL: 3D

    CPU_STEPPING: 4

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

    BUGCHECK_STR: 0X3B

    NOM_PROCESSUS: EXCEL. EXE

    CURRENT_IRQL: 2

    ANALYSIS_VERSION: 10.0.10563.566 amd64fre

    LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8800513927b

    STACK_TEXT:
    fffff880 '2080e600 00000000' 00000000: 00000000'00000000 00000000'00000000 00000000'00000000 00000000'00000000: igdkmd64 + 0xbf27b

    FOLLOWUP_IP:
    Igdkmd64 + bf27b
    fffff880'0513927 b 488b1b mov rbx, qword ptr [rbx]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: igdkmd64 + bf27b

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: igdkmd64

    Nom_image: igdkmd64.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 546c13b9

    STACK_COMMAND: .cxr 0xfffff8802080dc20; Ko

    FAILURE_BUCKET_ID: X64_0x3B_igdkmd64 + bf27b

    BUCKET_ID: X64_0x3B_igdkmd64 + bf27b

    PRIMARY_PROBLEM_CLASS: X64_0x3B_igdkmd64 + bf27b

    ANALYSIS_SOURCE: KM

    FAILURE_ID_HASH_STRING: km:x64_0x3b_igdkmd64 + bf27b

    FAILURE_ID_HASH: {a103711e-7d13-3c9e-b714-f34fb1cf841a}

    Follow-up: MachineOwner
    ---------

    0: kd > lmvm igdkmd64
    Browse the full list of module
    start end module name
    fffff880'0507 has 000 fffff880'05521000 T igdkmd64 (no symbol)
    Loaded symbol image file: igdkmd64.sys
    Image path: \SystemRoot\system32\DRIVERS\igdkmd64.sys
    Image name: igdkmd64.sys
    Browse all global symbols data functions
    Timestamp: Kills Nov 18 22:51:21 2014 (546C13B9)
    CheckSum: 0049668E
    ImageSize: 004A 7000
    Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4

  • Windows 7 x 64 BlueScreen BCCode: 3B

    Signature of the problem:
    Problem event name: BlueScreen
    OS version: 6.1.7601.2.1.0.768.2
    Locale ID: 2052

    More information about the problem:
    BCCode: 3B
    BCP1: 00000000C 0000005
    BCP2: FFFFF80005F2EFF7
    BCP3: FFFFF880056B6B50
    BCP4: 0000000000000000
    OS version: 6_1_7601
    Service Pack: 1_0
    Product: 768_1

    Mini dump file:

    http://1drv.Ms/1G0RIgx

    SysData.XML:

    http://1drv.Ms/1G0RHco

    He appears several times. Please help me! Thank you!

    Hello

    Bugcheck 3B {c0000005, fffff80005f2eff7, fffff880056b6b50, 0}

    Probably caused by: memory_corruption (nt! MiIdentifyPfn + 317)

    No other real help in the minidump.

    BiosVersion = K46CM.204
    BiosReleaseDate = 06/07/2012
    SystemManufacturer = ASUSTeK COMPUTER INC..
    SystemProductName = K46CM
    SystemSKU = ASUS-NotebookSKU
    BaseBoardManufacturer = ASUSTeK COMPUTER INC..
    BaseBoardProduct = K46CM
    BaseBoardVersion = 1.0

    1. check with ASUStek support, their drivers and documentation online and ask for their
    Forums about known problems. Update the BIOS, drivers from the chipset of low level and the major
    device drivers embedded and separated (see methods of updating driver below).

    ASUS - Service<-- includes="" live="">
    http://www.service.ASUS.com/

    ASUStek support
    http://support.ASUS.com/

    ASUStek Forums
    http://VIP.ASUS.com/forum/default.aspx?SLanguage=en-us

    ASUStek drivers
    http://support.ASUS.com/download/download.aspx?SLanguage=en-us

    2 check memory very carefully (see memory test methods below).

    3 the problem could be linked to the 360 Antivirus you are using. Try uninstalling and
    Use MSE - free to see if it makes a difference.

    MSE - free
    http://Windows.Microsoft.com/en-us/Windows/Security-Essentials-download

    4 use ALL methods in the troubleshooters below if necessary.

    5 if necessary execute DriverVerifier to see if it can indicate a CAUSE (see methods of DriverVerifier
    below).

    =============================================================

    Resolution in Windows 7 stop errors (blue screen) - has a section for if you can or cannot start Windows.
    http://Windows.Microsoft.com/en-us/Windows7/resolving-stop-blue-screen-errors-in-Windows-7

    Check this item thead for more information on using BlueScreenView, MyEventViewer and other methods of
    Troubleshooting BlueSceens - answers top 3 (+ 1 more).

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-system/sometimes-i-get-a-blue-screen-when-using-IE-8/c675b7b8-795f-474d-a1c4-6b77b3fcd990

    -----------------------------------------------------------------------------------------------------------

    BCCode: 3B 0x0000003b

    Try to remove and replace the cards memory and cables (both ends where possible)-in fact
    delete and replace - not just in the warm (on a PC) and clean the dust bunnies and vents. On
    a laptop on everything that can be done is to reinstall the memory and clean the vents. (Of course delete
    ALL power before opening the case).

    Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION

    The SYSTEM_SERVICE_EXCEPTION bug control has a value of 0x0000003B. This indicates that an exception happened during execution of a routine that passes from non-preferred to the privileged code code.

    Important info if you received a STOP Code

    If you received a blue error screen, or a stop code, the computer stopped abruptly to protect against data loss. A hardware device, its driver or software might have caused this error. If your copy of Windows is shipped with your computer, contact your computer manufacturer. If you purchased Windows separately from your computer, Microsoft provides support. To find contact information for Microsoft or the manufacturer of your computer, Contact Support.

    If you have experience with computers and try to recover from this error, follow the steps in the Microsoft article solution STOP (blue screen) errors in Windows.

    These actions could prevent a mistake like this does not happen:

    1. Download and install updates for your computer from Windows Update device drivers.
    2. Scan your computer for computer viruses.
    3. Check your hard drive for errors.

    System_service_exception parameters

    The following settings are displayed on the blue screen.

    Parameter Description

    1

    The exception that caused the bug control

    2

    The address of the exception record for the exception that caused the bug control

    3

    The address of the context record to the exception that caused the bug control

    4

    0


    Cause

    This error has been linked to the excessive use of expanded memory and resulting from user mode graphics drivers enjambment and passing data incorrect of the kernel code.

    BCCode: 3B 0x0000003b<-- read="" this="">
    http://www.faultwire.com/solutions-fatal_error/system-service-exception-0x0000003B-* 1074.html

    ============================================================

    Vista and Windows 7 updated drivers love then here's how update the most important.

    References to Vista also apply to Windows 7.

    It's my generic how updates of appropriate driver: (updating the video/display driver and BIOS)

    This utility, it is easy see which versions are loaded: run DriverView - see
    Hide Microsoft drivers - updated those without drain in their names. (Also update the BIOS
    and chipset drivers)

    -Free - DriverView utility displays the list of all device drivers currently loaded on your system.
    For each driver in the list, additional useful information is displayed: load address of the driver,
    Description, version, product name, company that created the driver and more.
    http://www.NirSoft.NET/utils/DriverView.html

    For drivers, visit manufacturer of emergency system and of the manufacturer of the device that are the most common.
    Control Panel - device - Graphics Manager - note the brand and complete model
    your video card - double - tab of the driver - write version information. Now, click on update
    Driver (this can do nothing as MS is far behind the certification of drivers) - then right-click.
    Uninstall - REBOOT it will refresh the driver stack.

    Repeat this for network - card (NIC), Wifi network, sound, mouse, and keyboard if 3rd party
    with their own software and drivers and all other main drivers that you have.

    Now in the system manufacturer (Dell, HP, Toshiba as examples) site (in a restaurant), peripheral
    Site of the manufacturer (Realtek, Intel, Nvidia, ATI, for example) and get their latest versions. (Look for
    BIOS, Chipset and software updates on the site of the manufacturer of the system here.)

    Download - SAVE - go to where you put them - right click - RUN AD ADMIN - REBOOT after
    each installation.

    Always check in the Device Manager - drivers tab to be sure the version you actually install
    presents itself. This is because some restore drivers before the most recent is installed (sound card drivers
    in particular that) so to install a driver - reboot - check that it is installed and repeat as
    necessary.

    Repeat to the manufacturers - BTW in the DO NOT RUN THEIR SCANNER device - check
    manually by model.

    Look at the sites of the manufacturer for drivers - and the manufacturer of the device manually.
    http://pcsupport.about.com/od/driverssupport/HT/driverdlmfgr.htm

    Installation and update of drivers under Windows 7 (updated drivers manually using the methods above
    It is preferable to ensure that the latest drivers from the manufacturer of system and device manufacturers are located)
    http://www.SevenForums.com/tutorials/43216-installing-updating-drivers-7-a.html

    If you update the drivers manually, then it's a good idea to disable the facilities of driver under Windows
    Updates, that leaves about Windows updates but it will not install the drivers that will be generally
    older and cause problems. If updates offers a new driver and then HIDE it (right click on it) and
    Then, get new ones manually if you wish.

    How to stop Windows 7 automatically install drivers
    http://support.Microsoft.com/kb/2500967

    ----------------------------------------------------------------------------------------

    Tests of memory intercept all errors such as memory do not match (possible even for sticks
    seemingly identical) and when the faster memory is placed in system behind the slower memory.
    So it is best to Exchange also sticks in and out to check for those, even if all the tests of memory do not
    show a problem.

    To test the RAM here control - run 4 + hours or so.<-- best="">
    www.memtest.org

    For the Windows Memory Diagnostic tool.

    Start - type in the search-> memory box - find top - click - right Memory Diagnostics tool
    RUN AS ADMIN follow the instructions

    Windows Vista: How to scan / test your memory with Windows Vista memory or RAM
    Diagnostic tool
    http://www.shivaranjan.com/2007/11/01/Windows-Vista-how-to-scan-test-your-RAM-or-memory-with-Windows-Vista-memory-diagnostic-tool/

    How to run the diagnostic tool memory in Windows 7
    http://www.SevenForums.com/tutorials/715-memory-diagnostics-tool.html

    ==========================================================

    Driver Verifier can help find some BSOD problems:

    Using Driver Verifier to identify issues with Windows drivers for users advanced
    http://support.Microsoft.com/kb/244617

    How to solve the problems of driver in Windows Vista or 7.
    http://www.WinVistaClub.com/T79.html

    Using Driver Verifier
    http://msdn.Microsoft.com/en-us/library/ff554113 (v = VS. 85) .aspx

    How to use the Windows Driver Verifier Manager to troubleshoot and identify questionshttp://www.youtube.com/watch?v=_VwIDD9xngM Driver

    Driver Verifier
    http://www.techsupportforum.com/2110308-POST3.html

    Using Driver Verifier
    http://www.faultwire.com/solutions/using_driver_verifier.php

    How to use Windows drivers check Manager to solve problems and identify the Driver questions
    http://www.YouTube.com/watch?v=_VwIDD9xngM

    You can disable the driver verifier
    http://support.Microsoft.com/kb/244617

    Start - type in the box search-> auditor/Reset hit enter to disable

    BlueScreenView lets you know if there is a driver specified in the error message. Also check with
    MyEventViewer at the blue screen.

    If DriverVerifier creates a minidump upload it and post the link here so we can analyze.

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle=""><- mark="" twain="" said="" it="">

Maybe you are looking for

  • Google Chrome Favorites

    I just replaced my hard drive with an SSD, then Restore'd using Time Machine. Alas, all my favorites for Google Chrome (value years!) disappeared! I looked in the TM files to ~/Library/Application Support/Google/Chrome /. But the only element in this

  • PowerAmp

    Has anyone with a used Xoom sucsessfully poweramp? My droid I have the paid version and love it, am hopeing it works with 3.0 SC -Patrick

  • HP Envy TS - 15 - J146TX: lost Recovery manager

    Since I updated to windows 10 he deleted all my apps hp as hp simplepass, assistant manager of hp recovery hp, support etc. He has also deleted my beats audio app and I can not still the volume pls help.

  • make a local administrator, a domain user

    How can I give a user in the domain of administrative rights workstation local in a Windows Server 2003 domain and using Windows XP on the local computer?

  • PlayerListener problems

    I am new to Java and to JDE BB, so I don't know that it is a stupid problem that I have.  I'm trying to use a PlayerListener in my application, but I get the following compilation error: incompatible types found : javax.microedition.media.Player requ