TechSpot

BugCheck STOP errors 1E, 0A, D1

By artm
May 30, 2007
  1. system: Compaq DL380 G2, 2GB RAM, SA5304 controller in RAID6, Win2K, SP3
    recent additions: Adaptec Duoconnect USB2/Firewire PCI card, Canon 8600F USB2 scanner (connected to Adaptec), generic USB1.0 audio card (connected to server USB1 port.


    Been getting flaky errors where Compaq's ASR (autorecovery) kicks in and server reboots.

    Compaq Integrated Management Log shows:

    STOP 0x000000D1 {0x0000016C, 0x00000002, 0x00000000, 0xF642041C} 05/30/07, 10:54AM
    STOP 0x0000000A {0xBAD0B0E4, 0x00000002, 0x00000001, 0x8006543A} 05/29/07, 5:46PM
    STOP 0x0000000A {0xBAD0B0E4, 0x00000002, 0x00000001, 0x8006543A} 05/28/07, 9:37AM
    STOP 0x0000001E {0xC0000005, 0xF674A876, 0x00000001, 0x00000024} 05/18/07, 4:58PM

    ====================================================================

    The corresponding Event Log entries offer little info:

    Event Type: Error
    Event Source: CimNotify
    Event Category: (1)
    Event ID: 5
    Date: 5/30/2007
    Time: 10:57:46 AM
    User: N/A
    Computer: MAIL
    Description:
    The description for Event ID ( 5 ) in Source ( CimNotify ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: Server Agents: ASR Reboot Completed.

    ====================================================================

    Another quirk: after installing Adobe Acrobat 4.0 and Reader 5.0, printing to Adobe driver produces an error:

    Event Type: Error
    Event Source: Print
    Event Category: None
    Event ID: 61
    Date: 5/29/2007
    Time: 3:47:17 PM
    User: MAIL\Administrator
    Computer: MAIL
    Description:
    The document vista audio i84 owned by Administrator failed to print. Win32 error code returned by the print processor: 63 (0x3f).


    ...and a popup asking to cancel the print job or retry. I select cancel. The job always prints correctly though.

    ====================================================================

    Hijack This shows the following entries, none of which are problematic:

    Logfile of HijackThis v1.99.1
    Scan saved at 3:39:28 PM, on 5/30/2007
    Platform: Windows 2000 SP3 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\CIMntfy\cimntfy.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\hidserv.exe
    E:\prog\Internet\KeepMePosted\KMPServ.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\snmp.exe
    C:\WINNT\System32\snmptrap.exe
    C:\WINNT\system32\stisvc.exe
    C:\hp\hpsmh\bin\smhstart.exe
    C:\WINNT\system32\ZONELABS\vsmon.exe
    C:\hp\hpsmh\bin\hpsmhd.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    E:\prog\Internet\VNC4\WinVNC4.exe
    C:\WINNT\System32\CPQNiMgt\cpqnimgt.exe
    C:\WINNT\System32\CPQMgmt\CqMgServ\cqmgserv.exe
    C:\WINNT\System32\CPQMgmt\CqMgStor\cqmgstor.exe
    C:\WINNT\System32\sysdown.exe
    C:\hp\hpsmh\bin\rotatelogs.exe
    C:\hp\hpsmh\bin\rotatelogs.exe
    C:\WINNT\System32\CPQMgmt\CqMgHost\cqmghost.exe
    C:\hp\hpsmh\bin\hpsmhd.exe
    C:\hp\hpsmh\bin\rotatelogs.exe
    C:\hp\hpsmh\bin\rotatelogs.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\cpqteam.exe
    E:\prog\Internet\ZoneAlarm\zlclient.exe
    E:\prog\Uti\VirtuaWin\VirtuaWin.exe
    E:\prog\Internet\CookiePal\CPal.exe
    E:\prog\Internet\DUMeter\DUMeter.exe
    E:\prog\Uti\VirtuaWin\modules\WinList.exe
    E:\prog\WinFax\wfxctl32.exe
    E:\prog\WinFax\WFXMOD32.EXE
    C:\Program Files\Compaq\INSIGHT MANAGER\cim.EXE
    C:\WINNT\system32\mmc.exe
    E:\prog\Internet\Mozilla1.5\firefox.exe
    E:\Prog\Internet\Eudora\Eudora.exe
    E:\prog\Internet\Prospector3\Prospector.exe
    C:\WINNT\system32\notepad.exe
    E:\prog\Uti\TextPad4\TextPad.exe
    E:\prog\Uti\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\prog\uti\acrobat5\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\prog\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: ExplorerWatch Class - {D4E7C68D-37FD-11D4-9D32-0000A00B0B0B} - E:\prog\Internet\CookiePal\CPBrHelp.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [CPQTEAM] cpqteam.exe
    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    O4 - HKLM\..\Run: [Zone Labs Client] E:\prog\Internet\ZoneAlarm\zlclient.exe
    O4 - Global Startup: VirtuaWin.lnk = E:\prog\Uti\VirtuaWin\VirtuaWin.exe
    O4 - Global Startup: Cookie Pal.lnk = E:\prog\Internet\CookiePal\CPal.exe
    O4 - Global Startup: Keep Me Posted.lnk = E:\prog\Internet\KeepMePosted\KMPServ.exe
    O4 - Global Startup: DU Meter.lnk = E:\prog\Internet\DUMeter\DUMeter.exe
    O4 - Global Startup: WinFax PRO Controller.lnk = E:\prog\WinFax\wfxctl32.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\prog\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\prog\Java\jre1.5.0_06\bin\ssv.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{43E24E7C-FEB8-4763-9FF5-CE61E0745BAA}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9C7DFE23-4C8B-42E1-AA8E-08238520BB7B}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CS1\Services\Tcpip\..\{43E24E7C-FEB8-4763-9FF5-CE61E0745BAA}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CS2\Services\Tcpip\..\{43E24E7C-FEB8-4763-9FF5-CE61E0745BAA}: NameServer = 208.67.222.222,208.67.220.220
    O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\hpadu\Bin\hpapp.dll
    O23 - Service: HP Insight Event Notifier (CIMnotify) - Hewlett-Packard Company - C:\WINNT\System32\CIMntfy\cimntfy.exe
    O23 - Service: HP Insight NIC Agent (CpqNicMgmt) - Hewlett-Packard Company - C:\WINNT\System32\CPQNiMgt\cpqnimgt.exe
    O23 - Service: HP Insight Foundation Agents (CqMgHost) - Hewlett-Packard Company - C:\WINNT\System32\CPQMgmt\CqMgHost\cqmghost.exe
    O23 - Service: HP Insight Server Agents (CqMgServ) - Hewlett-Packard Company - C:\WINNT\System32\CPQMgmt\CqMgServ\cqmgserv.exe
    O23 - Service: HP Insight Storage Agents (CqMgStor) - Hewlett-Packard Company - C:\WINNT\System32\CPQMgmt\CqMgStor\cqmgstor.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Keep Me Posted (KMPService) - Elegant Logic Ltd. - E:\prog\Internet\KeepMePosted\KMPServ.exe
    O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Compaq Computer Corporation - C:\WINNT\System32\sysdown.exe
    O23 - Service: HP System Management Homepage (SysMgmtHp) - Hewlett-Packard Company - C:\hp\hpsmh\bin\smhstart.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - E:\prog\Internet\VNC4\WinVNC4.exe" -service (file missing)

    ====================================================================


    The last four minidumps are attached.

    Of course, any help greatly appreciated.
     
  2. artm

    artm TS Rookie Topic Starter

    Got a BSOD today (again) for hal.dll, two weeks or so after the last one, with the minidump below and in the next reply.

    Any help appreciated.



    ****************************************************************
    **
    ** Windows 2000 Crash Dump Analysis
    **
    ****************************************************************
    *
    Filename . . . . . . .mini061207-01.dmp
    Signature. . . . . . .PAGE
    ValidDump. . . . . . .DUMP
    MajorVersion . . . . .free system
    MinorVersion . . . . .2195
    DirectoryTableBase . .0x00030000
    PfnDataBase. . . . . .0x89096000
    PsLoadedModuleList . .0x80483de0
    PsActiveProcessHead. .0x80485528
    MachineImageType . . .i386
    NumberProcessors . . .2
    BugCheckCode . . . . .0x0000000a
    BugCheckParameter1 . .0xbad0b0e4
    BugCheckParameter2 . .0x00000002
    BugCheckParameter3 . .0x00000001
    BugCheckParameter4 . .0x8006543a

    ExceptionCode. . . . .0x80000003
    ExceptionFlags . . . .0x00000001
    ExceptionAddress . . .0x8046923c


    **** could not load kernel debugger extenion dll [ kdextx86.dll ]

    ****************************************************************
    ** Symbol File Load Log
    ****************************************************************

    Module CheckSum
    ntoskrnl.exe 001A98AE
    hal.dll 00014D9F
    BOOTVID.dll 0000D8A2
    ACPI.sys 00036141
    WMILIB.SYS 00008BFD
    pci.sys 000187F5
    isapnp.sys 0001ADB1
    pciide.sys 0000E66F
    PCIIDEX.SYS 0000DE8C
    MountMgr.sys 00014162
    ftdisk.sys 0001D3BC
    Diskperf.sys 00006CE8
    dmload.sys 0000B8B0
    dmio.sys 0002DA3B
    PartMgr.sys 0000DF75
    atapi.sys 00021BAE
    cpqcissm.sys 000124F0
    SCSIPORT.SYS 000219D4
    disk.sys 0000F20D
    CLASSPNP.SYS 0000BDD7
    Fastfat.sys 0002B0BB
    KSecDD.sys 0001A350
    NDIS.sys 00034BC1
    ohci1394.sys 00010BDC
    1394BUS.SYS 00012134
    Mup.sys 00025138
    **** Error: overlapping image conflict. Invalid dump file.
    CPQCISSE.sys 00014BB9
    VIDEOPRT.SYS 0001C29A
    ati2mpad.sys 00056AFC
    cpqasm.sys 0004C864
    i8042prt.sys 00012F94
    kbdclass.sys 00014DB7
    mouclass.sys 0000D72E
    serial.sys 0001D024
    serenum.sys 0000F5FE
    fdc.sys 0001553C
    cdrom.sys 00011B4B
    USBD.SYS 00009E7E
    openhci.sys 0000BBCE
    aehcd.sys 0000DD20
    ausbd.sys 0000F1E2
    audstub.sys 00008EF7
    rasl2tp.sys 00014A34
    ndistapi.sys 0000B34D
    ndiswan.sys 0001E9B7
    TDI.SYS 000122D0
    raspptp.sys 000146EE
    ptilink.sys 0000D9AF
    raspti.sys 0000FED0
    ks.sys 0001D383
    swenum.sys 00004A92
    update.sys 0002B70C
    flpydisk.sys 00009D83
    usbhub.sys 00010A0B
    NDProxy.SYS 000121C3
    ser2pl.sys 00010FAA
    USBSTOR.SYS 00014A68
    Modem.SYS 00014BE8
    HIDPARSE.SYS 00008144
    HIDCLASS.SYS 0000CB43
    hidusb.sys 0000C106
    STREAM.SYS 00011E33
    usbaudio.sys 0001748F
    Fs_Rec.SYS 0001057D
    Null.SYS 000023CE
    Beep.SYS 0000C54F
    vga.sys 0001047D
    mnmdd.SYS 0000F6C2
    Msfs.SYS 0000E5FA
    Npfs.SYS 00017E60
    rasacd.sys 0000F369
    tcpip.sys 00056B95
    msgpc.sys 000122E3
    wanarp.sys 00015051
    netbt.sys 0003179C
    vsdatant.sys 0004CFD5
    netbios.sys 0000B5C1
    rdbss.sys 0003159B
    PQNTDrv.SYS 0000CFD3
    mrxsmb.sys 000615C2
    **** Error Loading Image
    Module: dump_scsiport.sys
    Image File: None
    Debug File: None
    CheckSum: 84D3
    Error: Could not find image

    dump_cpqcissm.sys 000124F0
    win32k.sys 001B4369
    ati2drad.dll 0005FAF6
    afd.sys 000240A6
    Fips.SYS 0001050B
    srv.sys 0004948E
    sysmgmt.sys 00003BC6
    Cdfs.SYS 0000F059
    wdmaud.sys 00018FA8
    sysaudio.sys 000169FE
    ipsec.sys 00018D23
    ATMFD.DLL 00046C82
    PDFKD.DLL 0000C54B
    asyncmac.sys 0000EC2B
    n100nt5.sys 000346A1
    qdfsdrv.sys 0000B9E5
    **** Error Loading Image
    Module: PROCEXP.SYS
    Image File: None
    Debug File: None
    CheckSum: 84F1
    Error: Could not find image

    kmixer.sys 00025DD2

    ****************************************************************
    ** drivers
    ****************************************************************

    Base Size CheckSum Image Name
    80400000 0019c000 001a98ae ntoskrnl.exe
    80062000 00014420 00014d9f hal.dll
    f6810000 00002a20 0000d8a2 BOOTVID.dll
    bffd8000 00027c40 00036141 ACPI.sys
    f69c8000 00000f80 00008bfd WMILIB.SYS
    f6400000 0000e640 000187f5 pci.sys
    f6410000 0000b680 0001adb1 isapnp.sys
    f69c9000 00000b00 0000e66f pciide.sys
    f6680000 00005500 0000de8c PCIIDEX.SYS
    f6688000 00007180 00014162 MountMgr.sys
    bffbb000 0001c1a0 0001d3bc ftdisk.sys
    f6900000 00001d20 00006ce8 Diskperf.sys
    f6902000 00001b80 0000b8b0 dmload.sys
    bff99000 000219c0 0002da3b dmio.sys
    f6814000 00002d00 0000df75 PartMgr.sys
    bff83000 000151a0 00021bae atapi.sys
    f6690000 00004080 000124f0 cpqcissm.sys
    bff71000 00011d60 000219d4 SCSIPORT.SYS
    f6698000 000073c0 0000f20d disk.sys
    f6420000 00008560 0000bdd7 CLASSPNP.SYS
    bff4e000 000223c0 0002b0bb Fastfat.sys
    bff3c000 00011460 0001a350 KSecDD.sys
    bff13000 00028ca0 00034bc1 NDIS.sys
    f6430000 00009240 00010bdc ohci1394.sys
    f6440000 0000a160 00012134 1394BUS.SYS
    bfefd000 000152e0 00025138 Mup.sys
    bfee3000 0001a000 0001d797 CPQPHP.SYS
    f6450000 0000e580 00014bb9 CPQCISSE.sys
    f6460000 0000c4c0 0001c29a VIDEOPRT.SYS
    bfc77000 00055600 00056afc ati2mpad.sys
    bfc2a000 0004c300 0004c864 cpqasm.sys
    f6520000 0000b6a0 00012f94 i8042prt.sys
    f66d8000 00005e40 00014db7 kbdclass.sys
    f66e8000 00005380 0000d72e mouclass.sys
    f6530000 0000f320 0001d024 serial.sys
    f6894000 00003560 0000f5fe serenum.sys
    f6700000 00007000 0001553c fdc.sys
    f6710000 00006c20 00011b4b cdrom.sys
    f6738000 00004f80 00009e7e USBD.SYS
    f6720000 00005fa0 0000bbce openhci.sys
    f6540000 0000a500 0000dd20 aehcd.sys
    f6748000 00005900 0000f1e2 ausbd.sys
    f69e2000 00000a40 00008ef7 audstub.sys
    f6550000 0000ca80 00014a34 rasl2tp.sys
    f68a4000 000022c0 0000b34d ndistapi.sys
    bfc13000 00016aa0 0001e9b7 ndiswan.sys
    f68b0000 00003e60 000122d0 TDI.SYS
    f6560000 0000ba00 000146ee raspptp.sys
    f6768000 00004400 0000d9af ptilink.sys
    f6778000 000040e0 0000fed0 raspti.sys
    bfbf7000 0001bb00 0001d383 ks.sys
    f69e3000 00000d80 00004a92 swenum.sys
    bfbd4000 000222a0 0002b70c update.sys
    f6790000 00004a60 00009d83 flpydisk.sys
    f6580000 00009ba0 00010a0b usbhub.sys
    f6590000 00009ce0 000121c3 NDProxy.SYS
    f65a0000 0000a880 00010faa ser2pl.sys
    f66a0000 00005320 00014a68 USBSTOR.SYS
    f66b0000 000070e0 00014be8 Modem.SYS
    f66e0000 00005900 00008144 HIDPARSE.SYS
    f66c0000 00005fa0 0000cb43 HIDCLASS.SYS
    bfe4f000 00003540 0000c106 hidusb.sys
    f65b0000 00009f20 00011e33 STREAM.SYS
    bf181000 00010c20 0001748f usbaudio.sys
    f690e000 00001ca0 0001057d Fs_Rec.SYS
    f69ee000 000009e0 000023ce Null.SYS
    f69ef000 00000ee0 0000c54f Beep.SYS
    bfe3b000 00003580 0001047d vga.sys
    f69f0000 00000f80 0000f6c2 mnmdd.SYS
    f6718000 00005240 0000e5fa Msfs.SYS
    f65c0000 00008fa0 00017e60 Npfs.SYS
    f6916000 00001e40 0000f369 rasacd.sys
    bf110000 000505e0 00056b95 tcpip.sys
    f65d0000 000086c0 000122e3 msgpc.sys
    f6740000 00007d00 00015051 wanarp.sys
    bf0c3000 00024500 0003179c netbt.sys
    bf080000 00042e40 0004cfd5 vsdatant.sys
    f65e0000 000081a0 0000b5c1 netbios.sys
    bf05e000 00021920 0003159b rdbss.sys
    f69f1000 00000740 0000cfd3 PQNTDrv.SYS
    befee000 0005d8a0 000615c2 mrxsmb.sys
    bf29a000 00003660 000084d3 dump_scsiport.sys
    bf1b2000 00004080 000124f0 dump_cpqcissm.sys
    a0000000 001a6580 001b4369 win32k.sys
    bef6f000 00057000 0005faf6 ati2drad.dll
    bee39000 0001dd40 000240a6 afd.sys
    f65f0000 00008240 0001050b Fips.SYS
    bebf5000 0003b560 0004948e srv.sys
    bf1da000 00007000 00003bc6 sysmgmt.sys
    bec69000 0000eda0 0000f059 Cdfs.SYS
    bea2a000 00012060 00018fa8 wdmaud.sys
    beb9d000 0000ba80 000169fe sysaudio.sys
    bea8d000 0000f9c0 00018d23 ipsec.sys
    bd3b7000 00047000 00046c82 ATMFD.DLL
    be2ac000 000036c0 0000c54b PDFKD.DLL
    f66b8000 00004060 0000ec2b asyncmac.sys
    bd2cc000 00025200 000346a1 n100nt5.sys
    bdce5000 000020a0 0000b9e5 qdfsdrv.sys
    f6974000 00001620 000084f1 PROCEXP.SYS
    bc79c000 00024220 00025dd2 kmixer.sys
     
  3. artm

    artm TS Rookie Topic Starter

    ****************************************************************
    ** Process
    ****************************************************************

    PROCESS: SessionId: 0 Cid: 0008 Peb: 00000000 ParentCid: 0000
    DirBase: 00030000 ObjectTable: 890950a8 TableSize: 0.
    Image: System
    VadRoot 8905d3e8 Clone 0 Private 4. Modified 3422047. Locked 0.
    DeviceMap 89061008
    Token e1000a90
    QuotaPoolUsage[PagedPool] 0
    QuotaPoolUsage[NonPagedPool] 0
    Working Set Sizes (now,min,max) (57, 0, 345) (228KB, 0KB, 1380KB)
    PeakWorkingSetSize 161
    VirtualSize 1 Mb
    PeakVirtualSize 1 Mb
    PageFaultCount 33496
    MemoryPriority BACKGROUND
    BasePriority 8
    CommitCharge 6


    ****************************************************************
    ** Thread
    ****************************************************************

    THREAD Cid 8.10 Teb: 00000000 Win32Thread: 00000000 RUNNING
    Owning Process 890685e0
    WaitTime (seconds) 71322427
    Context Switch Count 2066234
    Start Address ExQueueWorkItem
    Stack Init f6830000 Current f682fd34 Base f6830000 Limit f682d000 Call 0
    Priority 13 BasePriority 13 PriorityDecrement 0 DecrementCount 0


    ****************************************************************
    ** Register Dump For Processor #0
    ****************************************************************

    eax=ffdff13c ebx=0000000a ecx=00000001 edx=40000000 esi=8006543a edi=bad0b0e4
    eip=8046923c esp=f682fca8 ebp=f682fcbc iopl=0 nv up di pl nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    cr0=8001003b cr2=bad0b0e4 cr3=00030000 dr0=00000000 dr1=00000000 dr2=00000000
    dr3=00000000 dr6=ffff0ff0 dr7=00000400 cr4=000006d1
    gdtr=80036000 gdtl=03ff idtr=80036400 idtl=07ff tr=0028 ldtr=0000


    ****************************************************************
    ** Stack Trace
    ****************************************************************

    ChildEBP RetAddr Args to Child
    f682fcbc 00000004 86b07220 86af3000 8805a958 NTOSKRNL!Kei386EoiHelper+0x2ae4
     
  4. N3051M

    N3051M TS Evangelist Posts: 2,115

    first off, please just post these as attached .txt files where possible.. (especially the hjt log). I don't have the symbol pack for NT so i can't check your minidumps, so probably someone will do so for you..

    if you're having crashes, why don't you start with removing the recently added devices to your system? it does seem to point to hardware related symptoms..
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...