Hi guys, i have a problem with a computer sporadically rebooting.
The errors are different in the event viewer, however i took two of the minidumps to compare, it seems as though both problems occur around a certain memory block, can anyone shed any light on this for me please.
thanks in advance
chris
minidump1
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 80573e2a, The address that the exception occurred at
Arg3: eb8b3a98, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!RtlpCoalesceFreeBlocks+2cd
80573e2a 8b12 mov edx,dword ptr [edx]
TRAP_FRAME: eb8b3a98 -- (.trap ffffffffeb8b3a98)
.trap ffffffffeb8b3a98
ErrCode = 00000000
eax=000002b5 ebx=bc630000 ecx=bc640500 edx=00000000 esi=bc6404f8 edi=bc6404f0
eip=80573e2a esp=eb8b3b0c ebp=eb8b3b18 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!RtlpCoalesceFreeBlocks+0x2cd:
80573e2a 8b12 mov edx,dword ptr [edx] ds:0023:00000000=????????
.trap
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: fmstart.exe
LAST_CONTROL_TRANSFER: from 80573f28 to 80573e2a
STACK_TEXT:
eb8b3b18 80573f28 bc630000 bc6404f0 eb8b3b80 nt!RtlpCoalesceFreeBlocks+0x2cd
eb8b3ba0 bf80cc0e bc630000 00000000 bc6404f8 nt!RtlFreeHeap+0xa1
eb8b3bb4 bf81fb6d bc630000 bc6404f8 eb8b3be0 win32k!Win32HeapFree+0x13
eb8b3bc4 bf81fc34 82833b68 bc6404f8 e11c6648 win32k!ClassFree+0x1e
eb8b3be0 bf8c0919 e11c6648 829f23b8 e11bc110 win32k!DestroyClass+0xb2
eb8b3bf4 bf8209ea e11c65c0 828547d8 00000000 win32k!DestroyProcessesClasses+0x2b
eb8b3c1c bf819e30 00000001 eb8b3c44 bf819ef4 win32k!xxxDestroyThreadInfo+0x21d
eb8b3c28 bf819ef4 828547d8 00000001 00000000 win32k!UserThreadCallout+0x4b
eb8b3c44 8056a0cf 828547d8 00000001 828545d0 win32k!W32pThreadCallout+0x3d
eb8b3cf0 80584c64 40010004 eb8b3d4c 804e60e9 nt!PspExitThread+0x40b
eb8b3cfc 804e60e9 828545d0 eb8b3d48 eb8b3d3c nt!PsExitSpecialApc+0x22
eb8b3d4c 804de855 00000001 00000000 eb8b3d64 nt!KiDeliverApc+0x1af
eb8b3d4c 7c90eb94 00000001 00000000 eb8b3d64 nt!KiServiceExit+0x58
WARNING: Frame IP not in any known module. Following frames may be wrong.
0012fe94 00000000 00000000 00000000 00000000 0x7c90eb94
Minidump 2:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8054b02d, The address that the exception occurred at
Arg3: eb903844, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!ExAllocatePoolWithTag+66c
8054b02d 8b08 mov ecx,dword ptr [eax]
TRAP_FRAME: eb903844 -- (.trap ffffffffeb903844)
.trap ffffffffeb903844
ErrCode = 00000000
eax=0481023d ebx=82bef028 ecx=82bf1098 edx=00000001 esi=82bef410 edi=000001ff
eip=8054b02d esp=eb9038b8 ebp=eb90390c iopl=0 ov up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010a87
nt!ExAllocatePoolWithTag+0x66c:
8054b02d 8b08 mov ecx,dword ptr [eax] ds:0023:0481023d=????????
.trap
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from 805647f7 to 8054b02d
STACK_TEXT:
eb90390c 805647f7 00000001 00000001 e56b6f54 nt!ExAllocatePoolWithTag+0x66c
eb903930 8056495d 829da2c8 00000000 00000000 nt!ObpAllocateObject+0xc8
eb903964 80575aed 00000000 82bed238 eb9039d8 nt!ObCreateObject+0x12a
eb9039a8 80578cab e2193030 eb9039d8 7ffde200 nt!SepDuplicateToken+0xff
eb903a60 804de7ec fffffffe 00020008 00000001 nt!NtOpenThreadTokenEx+0x17f
eb903a60 804dd0f5 fffffffe 00020008 00000001 nt!KiFastCallEntry+0xf8
eb903aec 805812b8 fffffffe 00020008 00000001 nt!ZwOpenThreadTokenEx+0x11
eb903b7c 80581231 eb903ba8 80580df2 00f2fde6 nt!RtlFormatCurrentUserKeyPath+0x2f
eb903bb4 80580c6d 02000000 eb903c0c 00000000 nt!RtlOpenCurrentUser+0x13
eb903d14 80580dd7 80580df2 00f2fde6 00000001 nt!ExpGetCurrentUserUILanguage+0x2d
eb903d58 804de7ec 00f2fde6 00f2fe80 7c90eb94 nt!NtQueryDefaultUILanguage+0x49
eb903d58 7c90eb94 00f2fde6 00f2fe80 7c90eb94 nt!KiFastCallEntry+0xf8
WARNING: Frame IP not in any known module. Following frames may be wrong.
00f2fe80 00000000 00000000 00000000 00000000 0x7c90eb94
The errors are different in the event viewer, however i took two of the minidumps to compare, it seems as though both problems occur around a certain memory block, can anyone shed any light on this for me please.
thanks in advance
chris
minidump1
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 80573e2a, The address that the exception occurred at
Arg3: eb8b3a98, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!RtlpCoalesceFreeBlocks+2cd
80573e2a 8b12 mov edx,dword ptr [edx]
TRAP_FRAME: eb8b3a98 -- (.trap ffffffffeb8b3a98)
.trap ffffffffeb8b3a98
ErrCode = 00000000
eax=000002b5 ebx=bc630000 ecx=bc640500 edx=00000000 esi=bc6404f8 edi=bc6404f0
eip=80573e2a esp=eb8b3b0c ebp=eb8b3b18 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!RtlpCoalesceFreeBlocks+0x2cd:
80573e2a 8b12 mov edx,dword ptr [edx] ds:0023:00000000=????????
.trap
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: fmstart.exe
LAST_CONTROL_TRANSFER: from 80573f28 to 80573e2a
STACK_TEXT:
eb8b3b18 80573f28 bc630000 bc6404f0 eb8b3b80 nt!RtlpCoalesceFreeBlocks+0x2cd
eb8b3ba0 bf80cc0e bc630000 00000000 bc6404f8 nt!RtlFreeHeap+0xa1
eb8b3bb4 bf81fb6d bc630000 bc6404f8 eb8b3be0 win32k!Win32HeapFree+0x13
eb8b3bc4 bf81fc34 82833b68 bc6404f8 e11c6648 win32k!ClassFree+0x1e
eb8b3be0 bf8c0919 e11c6648 829f23b8 e11bc110 win32k!DestroyClass+0xb2
eb8b3bf4 bf8209ea e11c65c0 828547d8 00000000 win32k!DestroyProcessesClasses+0x2b
eb8b3c1c bf819e30 00000001 eb8b3c44 bf819ef4 win32k!xxxDestroyThreadInfo+0x21d
eb8b3c28 bf819ef4 828547d8 00000001 00000000 win32k!UserThreadCallout+0x4b
eb8b3c44 8056a0cf 828547d8 00000001 828545d0 win32k!W32pThreadCallout+0x3d
eb8b3cf0 80584c64 40010004 eb8b3d4c 804e60e9 nt!PspExitThread+0x40b
eb8b3cfc 804e60e9 828545d0 eb8b3d48 eb8b3d3c nt!PsExitSpecialApc+0x22
eb8b3d4c 804de855 00000001 00000000 eb8b3d64 nt!KiDeliverApc+0x1af
eb8b3d4c 7c90eb94 00000001 00000000 eb8b3d64 nt!KiServiceExit+0x58
WARNING: Frame IP not in any known module. Following frames may be wrong.
0012fe94 00000000 00000000 00000000 00000000 0x7c90eb94
Minidump 2:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8054b02d, The address that the exception occurred at
Arg3: eb903844, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!ExAllocatePoolWithTag+66c
8054b02d 8b08 mov ecx,dword ptr [eax]
TRAP_FRAME: eb903844 -- (.trap ffffffffeb903844)
.trap ffffffffeb903844
ErrCode = 00000000
eax=0481023d ebx=82bef028 ecx=82bf1098 edx=00000001 esi=82bef410 edi=000001ff
eip=8054b02d esp=eb9038b8 ebp=eb90390c iopl=0 ov up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010a87
nt!ExAllocatePoolWithTag+0x66c:
8054b02d 8b08 mov ecx,dword ptr [eax] ds:0023:0481023d=????????
.trap
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from 805647f7 to 8054b02d
STACK_TEXT:
eb90390c 805647f7 00000001 00000001 e56b6f54 nt!ExAllocatePoolWithTag+0x66c
eb903930 8056495d 829da2c8 00000000 00000000 nt!ObpAllocateObject+0xc8
eb903964 80575aed 00000000 82bed238 eb9039d8 nt!ObCreateObject+0x12a
eb9039a8 80578cab e2193030 eb9039d8 7ffde200 nt!SepDuplicateToken+0xff
eb903a60 804de7ec fffffffe 00020008 00000001 nt!NtOpenThreadTokenEx+0x17f
eb903a60 804dd0f5 fffffffe 00020008 00000001 nt!KiFastCallEntry+0xf8
eb903aec 805812b8 fffffffe 00020008 00000001 nt!ZwOpenThreadTokenEx+0x11
eb903b7c 80581231 eb903ba8 80580df2 00f2fde6 nt!RtlFormatCurrentUserKeyPath+0x2f
eb903bb4 80580c6d 02000000 eb903c0c 00000000 nt!RtlOpenCurrentUser+0x13
eb903d14 80580dd7 80580df2 00f2fde6 00000001 nt!ExpGetCurrentUserUILanguage+0x2d
eb903d58 804de7ec 00f2fde6 00f2fe80 7c90eb94 nt!NtQueryDefaultUILanguage+0x49
eb903d58 7c90eb94 00f2fde6 00f2fe80 7c90eb94 nt!KiFastCallEntry+0xf8
WARNING: Frame IP not in any known module. Following frames may be wrong.
00f2fe80 00000000 00000000 00000000 00000000 0x7c90eb94