• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

BSODs galore

BulletHole24

Weaksauce
Joined
Apr 22, 2005
Messages
109
I wasn't sure where else to put this so I figured I would go with the CPU.

For many weeks now my machine has been giving me Blue Screens of Death. At first, I didn't have any mini dumps, but I was able to narrow it down to the wireless adapter giving problems. I bought a new one, plugged it in and everything was fine for a couple of weeks. Then suddenly the blue screens started popping up again (multiple times per day). I figured this may have been due to the old adapter's drivers conflicting with the new adapter so I made sure both were uninstalled and installed the latest drivers for the new adapter (it's a Netgear WG111v3). Everything was fine for a couple of days and lo and behold, more blue screens. I ran Memtest for 9 passes and no errors were found. I ran a HDD check via the Windows System Tools, did a disk/registry cleanup via CCleaner and then ran a Defrag. The blue screens persisted. So at this point I tried to be clever and ran an ethernet cable across the hallway from the router to the computer. My problem was solved; there were no more blue screens... at least for about a week. Then, another blue screen, this time from a different driver than any of the other blue screens. At this point, I have no idea what else to do with this thing. Keep in mind this machine is very, very old and the core of it was built in 2005 with many of the other parts dating some year prior to 2003. I ran a virus/malware/spyware check and only a low threat Trojan was detected that I removed. Here are the specs:

Antec TruePower 480W PS (2005)
Asus A8V Deluxe MOBO (2005)
AMD 64 3500+ clocked @ 2.2GHz (2005)
2GB Corsair RAM (2005)
NVIDIA GeForce 6600GT GPU (2005)
40GB IDE HDD (prior to 2003)
80GB IDE HDD (prior to 2003)
DVD-ROM/CD R/W combo (prior to 2003)
Floppy Disk Drive (prior to 2003)
Viewsonic CRT Monitor (2005)
Windows XP Professional SP3

Nothing is overclocked. I will post all of my (distinct) minidumps one at a time to make this thread a bit easier on the eyes. I am at my wits end with this thing. At this point I'm thinking it is a hardware problem (CPU overheating? PSU overheating? RAM not being refreshed enough?). This is my mother's computer and unfortunately I am leaving in a couple of days for 10 weeks so I won't be able to do the usual, pain in the butt hardware checks (using the comp with one stick of RAM at a time, etc.) and she thinks she might break something if she does it herself. Keep in mind she just about never reboots this thing as I have been telling her she should be doing. The most obvious guess would be faulty USB ports, I don't have a PS/2 mouse to fully test this and my mother doesn't know how to use a computer with only a keyboard.
 
Last edited:
May 14, 2010:

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffff60, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 80522b31, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

READ_ADDRESS: ffffff60

FAULTING_IP:
nt!ObReferenceObjectSafe+d
80522b31 8b3e mov edi,dword ptr [esi]

MM_INTERNAL_CODE: 0

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: System

LAST_CONTROL_TRANSFER: from 805cdda7 to 80522b31

STACK_TEXT:
b5db4a54 805cdda7 ba71d9e8 00000000 88ab6bc8 nt!ObReferenceObjectSafe+0xd
b5db4a6c 80534734 88ab6bc8 00001000 b5db4d54 nt!PsGetNextProcess+0x4d
b5db4af4 8060833a 85fc3000 00001000 b5db4d20 nt!ExpGetProcessInformation+0x2d6
b5db4d3c 8899cecd 00000005 85fc3000 00001000 nt!NtQuerySystemInformation+0x748
WARNING: Frame IP not in any known module. Following frames may be wrong.
b5db4dac 805c61e0 00000000 00000000 00000000 0x8899cecd
b5db4ddc 80541e02 8897be7b 00000000 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!ObReferenceObjectSafe+d
80522b31 8b3e mov edi,dword ptr [esi]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ObReferenceObjectSafe+d

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlpa.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4b7a9cac

FAILURE_BUCKET_ID: 0x50_nt!ObReferenceObjectSafe+d

BUCKET_ID: 0x50_nt!ObReferenceObjectSafe+d

Followup: MachineOwner
---------
 
May 14, 2010:

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, value 0 = read operation, 1 = write operation
Arg4: ba1ea9cc, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: 00000004

CURRENT_IRQL: 2

FAULTING_IP:
HIDCLASS!DequeueInterruptReport+1a
ba1ea9cc 894a04 mov dword ptr [edx+4],ecx

CUSTOMER_CRASH_COUNT: 2

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: System

LAST_CONTROL_TRANSFER: from ba1ea736 to ba1ea9cc

STACK_TEXT:
ba4efbdc ba1ea736 88757368 00000004 00002000 HIDCLASS!DequeueInterruptReport+0x1a
ba4efc18 ba1e993c 00000000 005fe008 ba4efc4c HIDCLASS!HidpIrpMajorRead+0x1e6
ba4efc28 804ee129 89673308 875fe008 b63a1e5c HIDCLASS!HidpMajorHandler+0x3a
ba4efc38 b635615c 77204c38 771f3340 88dfb501 nt!IopfCallDriver+0x31
ba4efc4c ba3a18c3 00000005 88e0ccb8 89888258 Wdf01000!imp_WdfRequestSend+0x3b7
WARNING: Stack unwind information not available. Following frames may be wrong.
ba4efc78 b63701b2 771f3340 76777da0 ba4efc9c NuidFltr+0x18c3
ba4efcc4 b6370253 b63a1a08 89888258 88e0ccb8 Wdf01000!FxRequestBase::CompleteSubmittedNoContext+0x63
ba4efcdc b63475d3 875fe12f 89888258 00000000 Wdf01000!FxRequestBase::CompleteSubmitted+0x97
ba4efcf8 b634768d 01e0ccb8 888099d8 ba4efd24 Wdf01000!FxIoTarget::RequestCompletionRoutine+0x195
ba4efd08 804ef74f 8963fa00 875fe008 88e0ccb8 Wdf01000!FxIoTarget::_RequestCompletionRoutine+0x35
ba4efd24 804f06ae 8963fa00 875fe008 888099d8 nt!IopUnloadSafeCompletion+0x1d
ba4efd54 ba1ea40e 89673308 ba4efd74 8056bd37 nt!IopfCompleteRequest+0xa2
ba4efd60 8056bd37 89673308 898d3af8 8055b17c HIDCLASS!WorkItemCallback_CompleteIrpAsynchronously+0x14
ba4efd74 80534c1a 882708b0 00000000 8ab00b30 nt!IopProcessWorkItem+0x13
ba4efdac 805c61e0 882708b0 00000000 00000000 nt!ExpWorkerThread+0x100
ba4efddc 80541e02 80534b1a 00000001 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: kb

FOLLOWUP_IP:
HIDCLASS!DequeueInterruptReport+1a
ba1ea9cc 894a04 mov dword ptr [edx+4],ecx

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: HIDCLASS!DequeueInterruptReport+1a

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: HIDCLASS

IMAGE_NAME: HIDCLASS.SYS

DEBUG_FLR_IMAGE_TIMESTAMP: 480254c5

FAILURE_BUCKET_ID: 0xD1_HIDCLASS!DequeueInterruptReport+1a

BUCKET_ID: 0xD1_HIDCLASS!DequeueInterruptReport+1a

Followup: MachineOwner
---------
 
May 14, 2010:

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 93db2a48, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, value 0 = read operation, 1 = write operation
Arg4: ba3a90f3, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: 93db2a48

CURRENT_IRQL: 2

FAULTING_IP:
AegisP+10f3
ba3a90f3 893b mov dword ptr [ebx],edi

CUSTOMER_CRASH_COUNT: 3

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: System

LAST_CONTROL_TRANSFER: from ba3ab6cc to ba3a90f3

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
b50c3ce4 ba3ab6cc 93db2a48 000005b8 b50c3d08 AegisP+0x10f3
b50c3d0c ba3a9961 b9dbdcd8 00000000 b50c3d2c AegisP+0x36cc
b50c3d98 b9dbcbaa 8a29d110 00000000 8a67ab10 AegisP+0x1961
b50c3dac 805c61e0 8a29d190 00000000 00000000 NDIS!ndisWorkerThread+0x75
b50c3ddc 80541e02 b9dbcb85 8a29d190 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: kb

FOLLOWUP_IP:
AegisP+10f3
ba3a90f3 893b mov dword ptr [ebx],edi

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: AegisP+10f3

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: AegisP

IMAGE_NAME: AegisP.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 42a9a3e0

FAILURE_BUCKET_ID: 0xD1_AegisP+10f3

BUCKET_ID: 0xD1_AegisP+10f3

Followup: MachineOwner
---------
 
May 21, 2010:

KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 804ec827, The address that the exception occurred at
Arg3: b4dc275c, Trap Frame
Arg4: 00000000

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
nt!FsRtlLookupPerStreamContextInternal+4b
804ec827 395008 cmp dword ptr [eax+8],edx

TRAP_FRAME: b4dc275c -- (.trap 0xffffffffb4dc275c)
ErrCode = 00000000
eax=00000000 ebx=b4dc2978 ecx=e26c7dbc edx=88ebc008 esi=e26c7d90 edi=00000000
eip=804ec827 esp=b4dc27d0 ebp=b4dc27dc iopl=0 nv up ei pl nz ac pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010217
nt!FsRtlLookupPerStreamContextInternal+0x4b:
804ec827 395008 cmp dword ptr [eax+8],edx ds:0023:00000008=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 2

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x8E

PROCESS_NAME: jqs.exe

LAST_CONTROL_TRANSFER: from b9e9ff56 to 804ec827

STACK_TEXT:
b4dc27dc b9e9ff56 e26c7d90 88ebc008 00000000 nt!FsRtlLookupPerStreamContextInternal+0x4b
b4dc2840 b9e9abc4 88ebc008 87c29bb0 00000000 fltmgr!FltpGetStreamListCtrl+0x5a
b4dc285c b5e3c749 88ebce10 87c29bb0 b4dc2910 fltmgr!FltGetStreamContext+0x1a
WARNING: Stack unwind information not available. Following frames may be wrong.
b4dc292c b5e3d9bb 87f8d064 b4dc2978 00000040 MpFilter+0x9749
b4dc2954 b9e99ef3 87f8d064 b4dc2978 00000040 MpFilter+0xa9bb
b4dc29bc b9e9c338 00f8d008 00000000 87f8d008 fltmgr!FltpPerformPostCallbacks+0x1c5
b4dc29d0 b9e9c867 87f8d008 87b53008 b4dc2a10 fltmgr!FltpProcessIoCompletion+0x10
b4dc29e0 b9e9cef9 8938fb70 87b53008 87f8d008 fltmgr!FltpPassThroughCompletion+0x89
b4dc2a10 b9ea9754 b4dc2a30 00000000 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x269
b4dc2a4c 804ee129 8938fb70 87b53008 87b53008 fltmgr!FltpCreate+0x26a
b4dc2a5c 80578688 8aa5c350 8966067c b4dc2c04 nt!IopfCallDriver+0x31
b4dc2b3c 805b4d3c 8aa5c368 00000000 896605d8 nt!IopParseDevice+0xa12
b4dc2bc4 805b10e5 00000000 b4dc2c04 00000040 nt!ObpLookupObjectName+0x56a
b4dc2c18 8056b295 00000000 00000000 5b6a6f01 nt!ObOpenObjectByName+0xeb
b4dc2c94 8056bc0c 00adfc30 80100080 00adfbd0 nt!IopCreateFile+0x407
b4dc2cf0 8056e31e 00adfc30 80100080 00adfbd0 nt!IoCreateFile+0x8e
b4dc2d30 8053d658 00adfc30 80100080 00adfbd0 nt!NtCreateFile+0x30
b4dc2d30 7c90e514 00adfc30 80100080 00adfbd0 nt!KiFastCallEntry+0xf8
00adfc28 00000000 00000000 00000000 00000000 0x7c90e514


STACK_COMMAND: kb

FOLLOWUP_IP:
MpFilter+9749
b5e3c749 ?? ???

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: MpFilter+9749

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: MpFilter

IMAGE_NAME: MpFilter.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4b0732b2

FAILURE_BUCKET_ID: 0x8E_MpFilter+9749

BUCKET_ID: 0x8E_MpFilter+9749

Followup: MachineOwner
---------
 
May 28, 2010 (this is the one after using the ethernet for internet for a week):

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 804fff0a, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: 00000004

CURRENT_IRQL: 2

FAULTING_IP:
nt!KiInsertTimerTable+4e
804fff0a 894204 mov dword ptr [edx+4],eax

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: firefox.exe

LAST_CONTROL_TRANSFER: from 804fffdf to 804fff0a

STACK_TEXT:
ba4c7e04 804fffdf ffb15267 ffffffff d1f4168e nt!KiInsertTimerTable+0x4e
ba4c7e20 804f8e57 ffb15267 ffffffff 898ec3b0 nt!KiInsertTreeTimer+0x7d
ba4c7e40 804f8efe 008ec730 ffb15267 ffffffff nt!KeSetTimerEx+0x4b
ba4c7e5c b88598e9 898ec730 ffb15267 ffffffff nt!KeSetTimer+0x18
ba4c7e88 804ffd98 898ec70c 898ec028 432f097e USBPORT!USBPORT_DM_TimerDpc+0x20d
ba4c7fa4 804ffeaf d1f4168e 000000d5 ffdff000 nt!KiTimerListExpire+0x122
ba4c7fd0 80541bbd 80552e20 00000000 0059aec2 nt!KiTimerExpiration+0xaf
ba4c7ff4 8054188a b44bcd44 00000000 00000000 nt!KiRetireDpcList+0x46
ba4c7ff8 b44bcd44 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x2a
WARNING: Frame IP not in any known module. Following frames may be wrong.
8054188a 00000000 00000009 bb835675 00000128 0xb44bcd44


STACK_COMMAND: kb

FOLLOWUP_IP:
USBPORT!USBPORT_DM_TimerDpc+20d
b88598e9 6a01 push 1

SYMBOL_STACK_INDEX: 4

SYMBOL_NAME: USBPORT!USBPORT_DM_TimerDpc+20d

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: USBPORT

IMAGE_NAME: USBPORT.SYS

DEBUG_FLR_IMAGE_TIMESTAMP: 480254ce

FAILURE_BUCKET_ID: 0xA_USBPORT!USBPORT_DM_TimerDpc+20d

BUCKET_ID: 0xA_USBPORT!USBPORT_DM_TimerDpc+20d

Followup: MachineOwner
---------
 
Reformat and reinstall. See what happens then.

Though my hunch is the mobo with the PSU being a close second.
 
Back
Top