Jump to content

Windows 7 Crash Dump Help


Recommended Posts

I have Windows 7 and I keep gettings the BSOD and the error are never the same, I have downloaded the debugger and I think I may have some bad RAM, I have copied my dump analisis for anyone who can understand it better than I.

Loading Dump File [C:\Windows\MEMORY.DMP]

Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: C:\Symbols

Executable search path is:

Windows 7 Kernel Version 7100 MP (2 procs) Free x64

Product: WinNt, suite: TerminalServer SingleUserTS

Built by: 7100.0.amd64fre.winmain_win7rc.090421-1700

Machine Name:

Kernel base = 0xfffff800`02e01000 PsLoadedModuleList = 0xfffff800`0303ae90

Debug session time: Tue Jun 9 15:36:50.692 2009 (GMT-7)

System Uptime: 0 days 0:00:41.300

Loading Kernel Symbols

...............................................................

................................................................

............................

Loading User Symbols

PEB is paged out (Peb.Ldr = 000007ff`fffd9018). Type ".hh dbgerr001" for details

Loading unloaded module list

.......

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 50, {fffff880017ffb78, 0, fffff8800143b340, 0}

*** ERROR: Module load completed but symbols could not be loaded for SiWinAcc.sys

PEB is paged out (Peb.Ldr = 000007ff`fffd9018). Type ".hh dbgerr001" for details

PEB is paged out (Peb.Ldr = 000007ff`fffd9018). Type ".hh dbgerr001" for details

Probably caused by : SiWinAcc.sys ( SiWinAcc+1a75 )

Followup: MachineOwner

---------

1: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)

Invalid system memory was referenced. This cannot be protected by try-except,

it must be protected by a Probe. Typically the address is just plain bad or it

is pointing at freed memory.

Arguments:

Arg1: fffff880017ffb78, memory referenced.

Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.

Arg3: fffff8800143b340, If non-zero, the instruction address which referenced the bad memory

address.

Arg4: 0000000000000000, (reserved)

Debugging Details:

------------------

PEB is paged out (Peb.Ldr = 000007ff`fffd9018). Type ".hh dbgerr001" for details

PEB is paged out (Peb.Ldr = 000007ff`fffd9018). Type ".hh dbgerr001" for details

READ_ADDRESS: fffff880017ffb78

FAULTING_IP:

Ntfs!NtfsFinishIoAtEof+0

fffff880`0143b340 488b5158 mov rdx,qword ptr [rcx+58h]

MM_INTERNAL_CODE: 0

IMAGE_NAME: SiWinAcc.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41868d31

FAULTING_MODULE: fffff88001433000 Ntfs

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 1

TRAP_FRAME: fffff88002105530 -- (.trap 0xfffff88002105530)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=0000000000000000 rbx=0000000000000000 rcx=fffff880017ffb20

rdx=fffffa8005d43650 rsi=0000000000000000 rdi=0000000000000000

rip=fffff8800143b340 rsp=fffff880021056c8 rbp=fffff88002105b00

r8=0000000000010000 r9=fffffa8005eaf180 r10=0000000000000000

r11=fffffa8005d435e8 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0 nv up ei ng nz na po nc

Ntfs!NtfsFinishIoAtEof:

fffff880`0143b340 488b5158 mov rdx,qword ptr [rcx+58h] ds:fffff880`017ffb78=????????????????

Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002ee95f8 to fffff80002e7ff80

STACK_TEXT:

fffff880`021053c8 fffff800`02ee95f8 : 00000000`00000050 fffff880`017ffb78 00000000`00000000 fffff880`02105530 : nt!KeBugCheckEx

fffff880`021053d0 fffff800`02e7e06e : 00000000`00000000 00000000`00000001 fffffa80`05eaf000 fffff800`03074190 : nt! ?? ::FNODOBFM::`string'+0x3f7b3

fffff880`02105530 fffff880`0143b340 : fffff880`015245f9 00000000`00000001 00000000`00000000 fffffa80`00010000 : nt!KiPageFault+0x16e

fffff880`021056c8 fffff880`015245f9 : 00000000`00000001 00000000`00000000 fffffa80`00010000 fffffa80`05f66201 : Ntfs!NtfsFinishIoAtEof

fffff880`021056d0 fffff880`01348098 : fffffa80`05f662b0 fffffa80`05d435e8 00000000`00000000 fffffa80`04393001 : Ntfs!NtfsCopyReadA+0x269

fffff880`021058a0 fffff880`0134befa : fffff880`02105970 fffffa80`05f66203 00000000`02997000 fffffa80`05f66200 : fltmgr!FltpPerformFastIoCall+0x88

fffff880`02105900 fffff880`013685f0 : fffffa80`05f662b0 00000000`00000000 fffff880`02105b08 00000000`00010000 : fltmgr!FltpPassThroughFastIo+0x9a

fffff880`02105940 fffff880`013a7a75 : 00000000`00000580 fffff700`01080000 00000000`00000000 fffffa80`05f66200 : fltmgr!FltpFastIoRead+0x1d0

fffff880`021059e0 fffff800`0311f32b : fffffa80`05f662b0 fffffa80`00000001 fffffa80`018d89f0 ffffffff`ffffff01 : SiWinAcc+0x1a75

fffff880`02105a80 fffff800`02e7f1d3 : ffffffff`ffffffff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x429

fffff880`02105bb0 00000000`778ce53a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13

00000000`018adb38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778ce53a

STACK_COMMAND: kb

FOLLOWUP_IP:

SiWinAcc+1a75

fffff880`013a7a75 0fb6d8 movzx ebx,al

SYMBOL_STACK_INDEX: 8

SYMBOL_NAME: SiWinAcc+1a75

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: SiWinAcc

FAILURE_BUCKET_ID: X64_0x50_SiWinAcc+1a75

BUCKET_ID: X64_0x50_SiWinAcc+1a75

Followup: MachineOwner

---------

Link to comment
Share on other sites

Welcome to the Windows Forum.

While someone may or may not help you with the general problem (PAGE_FAULT_IN_NONPAGED_AREA), please keep in mind that Windows 7 is still a pre-release, and there is no full support for it. For more details see this post.

SiWinAcc.sys seems to be a SATA driver failing; is this a Windows 7 driver?

Link to comment
Share on other sites

BETA programs are used at your own risk, and are meant only for those capable of testing them and helping the vendor with any such problems. Personally, I would reinstall XP Vista, whichever was installed before. :D

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy