I have been getting regular blue screen errors for the last couple of weeks since Upgrading my BIOS from Dell.
I have re-installed Norton Internet Security 2006 (many times), I have booted my machine in safe mode and edited MSConfig to only allow the vital apps ie Symantec Firewall and Dr Watson Spyware. I have checked the physical memory using the Dell Memory Checking Utilities but I still keep getting blue screens!
The original problems occured when I left my machine running with Outlook only. Since this time I have change my memory settings so that Windows controls this and added Cacheing.
I then left my machine alone for a while and came back to see that the same error occured except it was Explorer that had caused the fault this time.
Please find the MiniDump below and let me know if anyone else is experiencing this problem..thanks...
Microsoft (R) Windows Debugger Version 6.8.0004.0 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini1
21207-02.d
mp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\Program Files\Debugging Tools for Windows\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700
Debug session time: Wed Dec 12 21:50:09.859 2007 (GMT+0)
System Uptime: 0 days 0:36:42.550
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
..........................
..........
..........
..........
..........
..........
..........
..........
..........
..........
..........
..........
..........
..........
.........
Loading User Symbols
Loading unloaded module list
.......................
**************************
**********
**********
**********
**********
**********
***
* *
* Bugcheck Analysis *
* *
**************************
**********
**********
**********
**********
**********
***
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c000009a, 804ef2ce, 9595a4a8, 0}
Unable to load image SAVRT.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for SAVRT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SAVRT.SYS
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
*** WARNING: Unable to verify timestamp for fltMgr.sys
Probably caused by : SAVRT.SYS ( SAVRT+16c1d )
Followup: MachineOwner
---------
0: kd> !analyze -v
**************************
**********
**********
**********
**********
**********
***
* *
* Bugcheck Analysis *
* *
**************************
**********
**********
**********
**********
**********
***
KERNEL_MODE_EXCEPTION_NOT_
HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000009a, The exception code that was not handled
Arg2: 804ef2ce, The address that the exception occurred at
Arg3: 9595a4a8, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000009a - Insufficient system resources exist to complete the API.
FAULTING_IP:
nt!`string'+7a
804ef2ce 8b7d08 mov edi,dword ptr [ebp+8]
TRAP_FRAME: 9595a4a8 -- (.trap 0xffffffff9595a4a8)
ESP EDITED! New esp=9595a858
ErrCode = 00000000
eax=00000000 ebx=00000000 ecx=00000000 edx=00000000 esi=8a5d8a80 edi=c000009a
eip=804ef2ce esp=9595a51c ebp=9595a884 iopl=0 nv up ei pl zr na pe nc
cs=0000 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000246
nt!`string'+0x7a:
804ef2ce 8b7d08 mov edi,dword ptr [ebp+8] ss:0010:9595a88c=e51e08a0
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: explorer.exe
LAST_CONTROL_TRANSFER: from 80575098 to 804ef2ce
STACK_TEXT:
9595a884 80575098 e51e08a0 00000000 00000000 nt!`string'+0x7a
9595a898 95881c1d f89ed028 00000000 e7050a28 nt!FsRtlIsNameInExpression
Private+0x
2c7
WARNING: Stack unwind information not available. Following frames may be wrong.
9595a948 9bcc1d2a e5214bc8 e167d6d0 e5214bc0 SAVRT+0x16c1d
9595a968 9bcc1ed7 e5214bc0 9595a9c8 e167d6f0 SYMEVENT+0x11d2a
9595a97c 9bcb61da 9595a9c8 e204d00c e167d6f0 SYMEVENT+0x11ed7
9595a990 9bcc0d31 9595a9c8 00000000 9595a9c8 SYMEVENT+0x61da
9595a9ac 9bcb791b 9595a9c8 804f0028 9bcb79e3 SYMEVENT+0x10d31
9595a9ec 804ef163 897684d0 fb4f9de0 fb4f9de0 SYMEVENT+0x791b
9595aa20 b9e25448 9595aa40 8966eee8 00000000 nt!RtlFindClearBits+0x211
9595aa5c 804ef163 8966eee8 fb4f9de0 fb4f9de0 fltMgr!FltpInitFrameLookas
ideLists+0
xe6
9595ab4c 805bdf06 8a5d8a80 00000000 87613b10 nt!RtlFindClearBits+0x211
9595abc4 805ba58e 00000000 9595ac04 00000040 nt!NtCreatePagingFile+0x67
a
9595ac18 80574f33 00000000 00000000 ac3c0c01 nt!CcPfParametersRead+0x29
3
9595ac94 805758aa 00f6f7f8 80100080 00f6f798 nt!FsRtlIsNameInExpression
Private+0x
226
9595acf0 80577f76 00f6f7f8 80100080 00f6f798 nt!HvMarkDirty+0x1de
9595ad30 805409ac 00f6f7f8 80100080 00f6f798 nt!RtlMapGenericMask+0x4d
9595ad64 7c90eb94 badb0d00 00f6f720 00000000 nt!RtlIpv6StringToAddressW
+0xe9
9595ad74 00000000 00000000 00000000 00000000 0x7c90eb94
STACK_COMMAND: kb
FOLLOWUP_IP:
SAVRT+16c1d
95881c1d ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: SAVRT+16c1d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SAVRT
IMAGE_NAME: SAVRT.SYS
DEBUG_FLR_IMAGE_TIMESTAMP:
430f857b
FAILURE_BUCKET_ID: 0x8E_SAVRT+16c1d
BUCKET_ID: 0x8E_SAVRT+16c1d
Followup: MachineOwner
---------
0: kd> lmvm SAVRT
start end module name
9586b000 958c3000 SAVRT T (no symbols)
Loaded symbol image file: SAVRT.SYS
Image path: SAVRT.SYS
Image name: SAVRT.SYS
Timestamp: Fri Aug 26 22:11:23 2005 (430F857B)
CheckSum: 0005FAE7
ImageSize: 00058000
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
0: kd> .trap 0xffffffff9595a4a8
ESP EDITED! New esp=9595a858
ErrCode = 00000000
eax=00000000 ebx=00000000 ecx=00000000 edx=00000000 esi=8a5d8a80 edi=c000009a
eip=804ef2ce esp=9595a51c ebp=9595a884 iopl=0 nv up ei pl zr na pe nc
cs=0000 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000246
nt!`string'+0x7a:
804ef2ce 8b7d08 mov edi,dword ptr [ebp+8] ss:0010:9595a88c=e51e08a0
0: kd> lmvm SAVRT
start end module name
9586b000 958c3000 SAVRT T (no symbols)
Loaded symbol image file: SAVRT.SYS
Image path: SAVRT.SYS
Image name: SAVRT.SYS
Timestamp: Fri Aug 26 22:11:23 2005 (430F857B)
CheckSum: 0005FAE7
ImageSize: 00058000
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
0: kd> .trap 0xffffffff9595a4a8
ESP EDITED! New esp=9595a858
ErrCode = 00000000
eax=00000000 ebx=00000000 ecx=00000000 edx=00000000 esi=8a5d8a80 edi=c000009a
eip=804ef2ce esp=9595a51c ebp=9595a884 iopl=0 nv up ei pl zr na pe nc
cs=0000 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000246
nt!`string'+0x7a:
804ef2ce 8b7d08 mov edi,dword ptr [ebp+8] ss:0010:9595a88c=e51e08a0
0: kd> lmvm SAVRT
start end module name
9586b000 958c3000 SAVRT T (no symbols)
Loaded symbol image file: SAVRT.SYS
Image path: SAVRT.SYS
Image name: SAVRT.SYS
Timestamp: Fri Aug 26 22:11:23 2005 (430F857B)
CheckSum: 0005FAE7
ImageSize: 00058000
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
Start Free Trial