Solved BSOD - ntoskrnl.exe. Help please!

Discussion in 'Win 7/Vista BSOD' started by s10, Aug 8, 2012.


Thread Status:
Not open for further replies.
  1. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Hi, PCHF! I receive BSOD since a few days. The computer works fine in Safe Mode.
    From BlueScreenView I can see that the ntoskrnl.exe is causing me problems.
    I had one year ago a problem with the overheating, when my pc had 80 grade Celsius and I was getting BSOD's, so I thought it is the same thing now, because my pc it's running slow but when i ran the SpeedFan it shows 50 grades, and after making out room for the C drive, the pc it's moving a little bit better.
    Tell me if I can give you more informations.
    Thank you,
    Simon.

    Attached Files:

  2. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
  3. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Here it is.

    Attached Files:

  4. Google Advertisement

  5. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
    I have reviewed your latest 4 memory dumps
    Code:
    080112-159339-01.log
    Debug session time: Wed Aug  1 22:10:18.065 2012 (UTC + 2:00)
    System Uptime: 0 days 0:52:12.110
    BAD_POOL_HEADER (19)
    Arg1: 00000003, the pool freelist is corrupt.
    Arg2: 9e180e68, the pool entry being checked.
    Arg3: 9e180e68, the read back flink freelist value (should be the same as 2).
    Arg4: 00000000, the read back blink freelist value (should be the same as 2).
    IMAGE_NAME:  Pool_Corruption
    PROCESS_NAME:  System
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    FAILURE_BUCKET_ID:  0x19_3_nt!ExDeferredFreePool+312
    80e3ba74 83565902 00000019 00000003 9e180e68 nt!KeBugCheckEx+0x1e
    80e3bac8 835652e5 85435140 9e180e60 aa8e2a60 nt!ExDeferredFreePool+0x312
    80e3bb30 89ddd26e a2ebeb68 00000000 9e16c570 nt!ExFreePoolWithTag+0x848
    80e3bb44 89d4809a 00000000 80e3bb64 093571f2 Ntfs!NtfsFullDeleteLcb+0xe0
    80e3bb94 89dc422c 8595be28 862920d8 9e16c2d8 Ntfs!NtfsTeardownFromLcb+0x141
    80e3bbe4 89d40c1c 8595be28 9e16c3c8 0116c570 Ntfs!NtfsTeardownStructures+0xf3
    80e3bc0c 89dc062a 8595be28 9e16c3c8 9e16c570 Ntfs!NtfsDecrementCloseCounts+0xaf
    80e3bc6c 89ddf593 8595be28 9e16c3c8 9e16c2d8 Ntfs!NtfsCommonClose+0x4f2
    80e3bd00 834a7f83 00000000 00000000 854bd020 Ntfs!NtfsFspClose+0x118
    80e3bd50 83634ee8 00000000 a14b902c 00000000 nt!ExpWorkerThread+0x10d
    80e3bd90 834d6089 834a7e76 00000000 00000000 nt!PspSystemThreadStartup+0x9e
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
    ~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~
     
    080312-18954-01.log
    Debug session time: Fri Aug  3 19:07:31.758 2012 (UTC + 2:00)
    System Uptime: 0 days 6:14:49.678
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Arg1: dc10cbd6, memory referenced.
    Arg2: 00000000, value 0 = read operation, 1 = write operation.
    Arg3: 836cddba, If non-zero, the instruction address which referenced the bad memory
    Arg4: 00000002, (reserved)
    IMAGE_NAME:  memory_corruption
    PROCESS_NAME:  System
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    FAILURE_BUCKET_ID:  0x50_nt!MiFreeRelocations+17
    80e6bc14 8347e948 00000000 dc10cbd6 00000000 nt!MmAccessFault+0xbf
    80e6bc14 836cddba 00000000 dc10cbd6 00000000 nt!KiTrap0E+0xdc
    80e6bca0 83669102 a6ebfcd0 a6ebfcf8 835a76c0 nt!MiFreeRelocations+0x17
    80e6bccc 835013d5 a6ebfcd0 00000000 00000000 nt!MiSegmentDelete+0xc8
    80e6bd28 8346402a 854c1d48 00000000 00000000 nt!MiProcessDereferenceList+0xdb
    80e6bd50 8362dee8 00000000 a14cff2e 00000000 nt!MiDereferenceSegmentThread+0xc5
    80e6bd90 834cf089 83463f63 00000000 00000000 nt!PspSystemThreadStartup+0x9e
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
    ~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~
     
    080312-32791-01.log
    Debug session time: Fri Aug  3 22:18:50.697 2012 (UTC + 2:00)
    System Uptime: 0 days 0:22:57.741
    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
    Arg1: c0000005, The exception code that was not handled
    Arg2: 83698dba, The address that the exception occurred at
    Arg3: 80e6bbd8, Exception Record Address
    Arg4: 80e6b7b0, Context Record Address
    IMAGE_NAME:  memory_corruption
    PROCESS_NAME:  System
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    FAILURE_BUCKET_ID:  0x7E_nt!MiFreeRelocations+17
    80e6bca0 83634102 85547820 85547848 835726c0 nt!MiFreeRelocations+0x17
    80e6bccc 834cc3d5 85547820 00000000 00000000 nt!MiSegmentDelete+0xc8
    80e6bd28 8342f02a 854c1d48 00000000 00000000 nt!MiProcessDereferenceList+0xdb
    80e6bd50 835f8ee8 00000000 a14cb14d 00000000 nt!MiDereferenceSegmentThread+0xc5
    80e6bd90 8349a089 8342ef63 00000000 00000000 nt!PspSystemThreadStartup+0x9e
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
    ~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~¤~
     
    080712-32339-01.log
    Debug session time: Tue Aug  7 11:10:09.285 2012 (UTC + 2:00)
    System Uptime: 0 days 0:29:09.329
    CRITICAL_OBJECT_TERMINATION (f4)
    Arg1: 00000003, Process
    Arg2: 96d2ed40, Terminating object
    Arg3: 96d2eeac, Process image file name
    Arg4: 8363dac0, Explanatory message (ascii)
    IMAGE_NAME:  csrss.exe
    PROCESS_NAME:  csrss.exe
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    FAILURE_BUCKET_ID:  0xF4_C0000005_IMAGE_csrss.exe
    80e1e448 8371ef13 000000f4 00000003 96d2ed40 nt!KeBugCheckEx+0x1e
    80e1e46c 836725c2 8363dac0 96d2eeac 96d2efb0 nt!PspCatchCriticalBreak+0x71
    80e1e49c 8366502b 96d2ed40 827c7260 c0000005 nt!PspTerminateAllThreads+0x2d
    80e1e4d0 8348175a ffffffff c0000005 80e1e964 nt!NtTerminateProcess+0x1a2
    80e1e4d0 834809b9 ffffffff c0000005 80e1e964 nt!KiFastCallEntry+0x12a
    80e1e550 834f3b0e ffffffff c0000005 0001003f nt!ZwTerminateProcess+0x11
    80e1e964 8347843d 80e1ec7c 00000000 80e1ed34 nt!KiDispatchException+0x497
    80e1ed04 834852f7 80e1ec7c 013ff500 00000000 nt!KiRaiseException+0x185
    80e1ed20 8348175a 013ff4e4 013ff500 00000000 nt!NtRaiseException+0x33
    80e1ed20 5925a4fc 013ff4e4 013ff500 00000000 nt!KiFastCallEntry+0x12a
    013ffa48 00000000 00000000 00000000 00000000 0x5925a4fc
    These point to a general memory corruption problem, possibly being caused by drivers or defective RAM. Sadly, no drivers are being pointed in the dumps, but on your 3rd party drivers list there are a few suspicious files.
    Code:
    316334F5 1996 Apr 04 04:33:25 giveio.sys *** ADC Analyzer/SwiftForth/Disspy - ?SpeedFan? --> Info only (
    411C2D04 2004 Aug 13 04:52:52 ASACPI.sys *** Asus ATK0110 ACPI Utility (a known BSOD maker in Win7).  Also a part of the Asus PCProbe and AISuite Utilities --> http://support.asus.com/download/download.aspx
    45103E2F 2006 Sep 19 20:59:59 ADIHdAud.sys *** SoundMAX Digital HD Audio Driver --> OEM - none at http://www.analog.com/en/index.html
    4649177E 2007 May 15 04:14:22 usbVM303.sys
    467CB396 2007 Jun 23 07:45:58 vvftav303.sys
    4F103595 2012 Jan 13 14:45:57 dtsoftbus01.sys *** Daemon Tools driver --> http://www.daemon-tools.cc/eng/downloads
    - Update or uninstall the speedfan application.
    - the problem with your motherboard is that it doesn't have official support for windows 7 http://www.asus.com/Motherboards/Intel_Socket_775/P5LD2_SE/#download The sound device driver is rather old and it should be updated, but Asus doesn't offer any newer files for it
    - you seem to have some Vimicro video capture device installed, it uses some very old drivers which need to be updated or the device has to be uninstalled
    - uninstall the daemon tools application
    - go to
    Code:
    c:\windows\system32\drivers
    and rename ASACPI.sys to ASACPI.bak
    Reboot the machine to take effect.
  6. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Thank you, mkey82. Before receiving this reply I set Windows Firewall off and uninstalled AvnSoft Audio Driver (because the main audio driver is SoundMax), and now I don't receive the BSOD any more. I will come with feedback after a few days. Thanks for helping!
  7. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
    You're very welcome.
  8. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Hi again! I had another crash today when I was shut downing my computer. I signed out from YMessenger, and when the application was closing I rushed and I pressed shut down, and then it happened. :)

    Vimicro it's the driver from my web-camera.
    I uninstalled Daemon Tools before the today's crash; and SpeedFan just now.

    Attached Files:

  9. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
    I see you haven't disabled the ASACPI.sys driver as we have discussed above.

    Code:
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    CRITICAL_OBJECT_TERMINATION (f4)
    A process or thread crucial to system operation has unexpectedly exited or been
    terminated.
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arguments:
    Arg1: 00000003, Process
    Arg2: 86a8f0d0, Terminating object
    Arg3: 86a8f23c, Process image file name
    Arg4: 83609ac0, Explanatory message (ascii)
    This type of bugcheck warrant a system files scan.

    Insert the windows installation DVD and reboot the PC. Right after the PC restarts tap the F12 key several times to toggle the boot menu. Once it appears, select your DVD drive from the list and boot from the windows DVD. On the first menu choose the language and keyboard layout, press next. On the second screen click "Repair your computer". On the third screen choose your windows installation, probably only one on the list, and click next.

    On the following screen choose the "command prompt." Once you have input, enter "diskpart" and follow it by "list volume". You should see at least two ntfs partitions. The small partition is the boot partition, note the drive letter. Based on its size, you should be able to determine the windows installation partition, note that as well. Type "exit" and press enter to exit the diskpart console.

    Finally input this
    Code:
    sfc /SCANNOW /OFFBOOTDIR=c:\ /OFFWINDIR=d:\Windows
    here we assume that c: is the boot partition, d: is the windows installation partition, you may need to change the drive letters accordingly. If there is no dedicated boot partition, use letter c in both cases.
  10. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Hi, mkey82! Last night when I was working in Photoshop with a large psd file for a flyer the computer freezed (was not responding) and then I shut down. This morning when I opened the computer it's the same as last night (freezed), and I can't do a thing.
    Also I have received a BSOD this morning saying something about win32k.sys, but I cannot find the crash (.dmp file) in the Minidump folder.

    It's working fine in Safe Mode, so I disabled the ASACPI.sys and tried to make the system files scan, but I got an error. (You can see the photo attached).
    Thanks for your help,
    Simon.

    Attached Files:

  11. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Another crash!

    Attached Files:

  12. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
    Go to
    Code:
    c:\windows\logs\CBS
    zip up cbs.log file and attach it here.

    Go to
    Code:
    c:\windows\system32\drivers
    and rename the following drivers to *.bak
    Code:
    ADIHdAud.sys
    usbVM303.sys
    vvftav303.sys
    Reboot to take effect. This will break some functionality on your system (like the sound) but we have to disable these old, probably very leaky drivers.
    To restore drivers you only need to rename them back to *.sys and reboot once again, so any changes you introduce are not permanent.
  13. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Hi, mkey82! I cannot use my computer anymore. It's restarting either in normal mode or safe mode.
    For normal mode it goes to Starting Windows and then it's restarting.
    For safe mode it's restarting after loading all the drivers.

    You can see the CBS.log attached in my post above.

    CPU Temperature 57.5*C
    MB Temperature 42*C

    CPU Fan Speed 2986 RPM

    VCORE Voltage 1.376V
    3.3V Voltage 3.264V
    5V Voltage 5.043V
    12V Voltage 12.302V
  14. mkey82 Je ne sais quois

    Tech Member
    Message Count:
    4,596
    Likes Received:
    359
    My System
    Loading...
    Go to the bios setup and load safe default values. Save and exit.

    Insert your windows setup dvd, follow the above procedure to boot from it, however once on the screen where you can choose to start the command prompt, choose "startup repair" and allow the process to complete.

    A BIOS flash could be warranted. Please note that every flashing procedure involves some risk and it may lead to a bricked motherboard. The risk is minimal, but you should keep that in mind.
    The procedure
    1) Insert a USB flash drive and make it bootable according to this http://rufus.akeo.ie/
    2) Download this http://dlcdnet.asus.com/pub/ASUS/mb/socket775/P5LD2 SE/LDSE1301.zip and extract the three files to the USB flash drive we prepared in step one.
    3) Reboot your system, go to BIOS setup and load safe defaults, save and exit.
    4) Once at the post screen, keep tapping F12, F9 or F8 key to toggle the boot menu, the correct key is probably written somewhere on the bottom of the screen. Once the menu shows up, choose your USB flash drive from the list.
    5) According to the manual http://dlcdnet.asus.com/pub/ASUS/mb/socket775/P5LD2 SE/e2705_p5ld2_se.pdf at page 4-2 you should now land on a command prompt. Input
    Code:
    afudos /iLDSE1301.ROM
    /i is the switch, LDSE1301.ROM is the bios update name, there are no spaces in between.
    6) Wait until the process completes, it will ask you to reboot. Again, consult the manual.
    7) After the reboot, go immediately to the bios setup and load safe default. Once again save and exit.

    There may be a simpler procedure for this, if you have a floppy drive and some diskettes. Consult the manual on page 4-7.

    If none of this works, open up the case, take both memory modules out, make sure memory slots are clean and insert only memory module 1 into slot 1. If the machine still crashes, take out module 1 and insert module 2 into slot 1. If it still crashes, repeat the same procedure on slot 2.
  15. s10 Bronze Member

    Bronze
    Message Count:
    11
    Likes Received:
    0
    My System
    Loading...
    Thanks for you help!
    Today when I came home I tried the computer to see if it works and I don't know how, but the computer it's booting normally and I can use my computer. :)
    I went to drivers and disabled the ones from the post above.
    I will come with news soon. ;)

    Thanks so far,
    Simon.
  16. madmonkey Site Manager

    Manager
    PCHF Staff
    Message Count:
    18,863
    Likes Received:
    759
    My System
    Loading...
    Hi Simon, any update?





    -----
    [IMG] Thread marked [Pending]...

BSOD - ntoskrnl.exe. Help please!

Thread Status:
Not open for further replies.