XP crashes when Outlook is opened

I run windows XP on a dell optiplex. When I open windows outlook the system crashes and reboots with a message about a serious error. I have reported to MS and get a message telling me of a violation and a possible driver problem.
I also get a message on bootup telling me that HP OfficeJet Com device objects has encountered problems and needs to close.
I can't find any file referring to HP OfficeJet. My only HP printer is a PSC 750 that has worked for years without trouble.
I use Norton Security in case this is relevant.
I have tried a system restore to a week earlier but it makes no difference.

Kieran O'Brien
KJOBrienAsked:
Who is Participating?
 
cpc2004Commented:
You haven't fixed the bad paging space problem. Run chkdsk /r to perform the hard disk health check.
0
 
venom96737Commented:
maybe your printer drivers ahve gone back try uninstalling them and reinstalling them.
0
 
cpc2004Commented:

Your RAM is good but it must be compatible to your motherboard.

The crash may be caused by faulty ram or device driver error (ie video, sound card, modem and etc). The system event log and the minidump has the most useful diagnostic information. When Windows crashes with blue screen, it writes a system event 1001 or 1003 and a minidump to the folder \windows\minidump. Check system event 1001 and 1003 and it has the detail of the blue screen.

Event ID: 1001
Source: Save Dump
Description:
The computer has rebooted from a bugcheck.The bugcheck was : 0xc000000a (0xe1270188, 0x00000002, 0x00000000, 0x804032100).
Microsoft Windows..... A dump was saved in: .......

Event Source: System Error
Event Category: (102)
Event ID: 1003
Description:
Error code 1000007f, parameter1 0000000d, parameter2 00000000, parameter3 00000000, parameter4 00000000

Control Panel -> Adminstrative Tools -> Event Viewer -> System -> Event 1001/1003. Copy the content and paste it back here

Zip 5 to 6 minidumps to a zip file and attach it at any webspace. I will study the dump and find out the culprit. If you can't provide the minidumps, run memtest to stress test the ram. Make sure that your windows is not infected with spyware, adware adn chkdsk /r.
http://www.memtest86.com/.

Get public webspace
Use a free service like rapidshare to attach the minidumps and post the url of the mimidumps at this thread.
http://www.rapidshare.de/
0
Cloud Class® Course: C++ 11 Fundamentals

This course will introduce you to C++ 11 and teach you about syntax fundamentals.

 
KJOBrienAuthor Commented:
Minidumps posted to following links:

http://rapidshare.de/files/20193821/mini050506-01.dmp.html
http://rapidshare.de/files/20194019/mini051106-01.dmp.html
http://rapidshare.de/files/20194106/mini051106-02.dmp.html
http://rapidshare.de/files/20194258/mini051106-03.dmp.html
http://rapidshare.de/files/20194318/mini051106-04.dmp.html
http://rapidshare.de/files/20194366/mini051106-05.dmp.html
http://rapidshare.de/files/20194445/mini051106-06.dmp.html


Content of error events 1001/1003

Event Type:      Error
Event Source:      System Error
Event Category:      (102)
Event ID:      1003
Date:            11/05/2006
Time:            15:04:56
User:            N/A
Computer:      MAINSERVER
Description:
Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3 00000000, parameter4 00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 53 79 73 74 65 6d 20 45   System E
0008: 72 72 6f 72 20 20 45 72   rror  Er
0010: 72 6f 72 20 63 6f 64 65   ror code
0018: 20 31 30 30 30 30 30 37    1000007
0020: 66 20 20 50 61 72 61 6d   f  Param
0028: 65 74 65 72 73 20 30 30   eters 00
0030: 30 30 30 30 30 38 2c 20   000008,
0038: 38 30 30 34 32 30 30 30   80042000
0040: 2c 20 30 30 30 30 30 30   , 000000
0048: 30 30 2c 20 30 30 30 30   00, 0000
0050: 30 30 30 30               0000    




Event Type:      Information
Event Source:      Save Dump
Event Category:      None
Event ID:      1001
Date:            11/05/2006
Time:            15:03:33
User:            N/A
Computer:      MAINSERVER
Description:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x1000007f (0x00000008, 0x80042000, 0x00000000, 0x00000000). A dump was saved in: C:\WINDOWS\Minidump\Mini051106-06.dmp.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.






Event Type:      Error
Event Source:      System Error
Event Category:      (102)
Event ID:      1003
Date:            11/05/2006
Time:            14:39:42
User:            N/A
Computer:      MAINSERVER
Description:
Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3 00000000, parameter4 00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 53 79 73 74 65 6d 20 45   System E
0008: 72 72 6f 72 20 20 45 72   rror  Er
0010: 72 6f 72 20 63 6f 64 65   ror code
0018: 20 31 30 30 30 30 30 37    1000007
0020: 66 20 20 50 61 72 61 6d   f  Param
0028: 65 74 65 72 73 20 30 30   eters 00
0030: 30 30 30 30 30 38 2c 20   000008,
0038: 38 30 30 34 32 30 30 30   80042000
0040: 2c 20 30 30 30 30 30 30   , 000000
0048: 30 30 2c 20 30 30 30 30   00, 0000
0050: 30 30 30 30               0000    


I hope this helps

Kieran


0
 
KJOBrienAuthor Commented:
Link for zipped file as requested

http://rapidshare.de/files/20198892/FreeZip.zip.html 

Kieran
0
 
cpc2004Commented:
All of the minidumps are crashed with stack overflow and it is known problem of Norton AV. Extend the size of the stack trace will resolve the problem.

Refer the following webpage
http://support.microsoft.com/?kbid=822789



Mini050506-01.dmp
BugCheck 1000007F, {8, 80042000, 0, 0}

GetPointerFromAddress: unable to read from 8055ee34
THREAD 829633b0  Cid 0a88.0be4  Teb: 7ffdd000 Win32Thread: 00000000 RUNNING on processor 0
IRP List:
    Unable to read nt!_IRP @ 82345008
Not impersonating
GetUlongFromAddress: unable to read from 8055ee44
Owning Process            82954178       Image:         OUTLOOK.EXE
ffdf0000: Unable to get shared data
Wait Start TickCount      168940      
Context Switch Count      421            
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime                  00:00:00.0000
KernelTime                00:00:00.0000
Start Address 0x7c810867
Win32 Start Address 0x3000106c
Stack Init ecd62000 Current ecd5fa74 Base ecd62000 Limit ecd5f000 Call 0
Priority 9 BasePriority 8 PriorityDecrement 0 DecrementCount 0
ChildEBP RetAddr  Args to Child              
ecd5effc f85e6f47 82953338 00000001 ecd5f190 Ntfs!NtfsInitializeIrpContext+0x2 (FPO: [Non-Fpo])
ecd5f1ac 804e37f7 8335e520 82953338 833cfbf8 Ntfs!NtfsFsdRead+0x74 (FPO: [Non-Fpo])
ecd5f1bc f8688459 ecd5f1e8 804e37f7 8335edd0 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
ecd5f1c4 804e37f7 8335edd0 82953338 829534ec sr!SrPassThrough+0x31 (FPO: [Non-Fpo])
ecd5f1d4 efdbd9e1 829534ec 82fd9f38 829534ec nt!IopfCallDriver+0x31 (FPO: [0,0,0])
WARNING: Stack unwind information not available. Following frames may be wrong.
ecd5f1e8 804e37f7 82ff33e8 82953338 82953510 SYMEVENT+0x79e1
ecd5f1f0 82953338 82953510 ef9fb9ad 832afcf8 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
ecd5f63c ef9fbbd5 0061a800 82953338 804e37f7 0x82953338
ecd5f66c 804f552f 8261a820 825dde0a 825dde48 FILESPY+0x1bd5
ecd5f68c 804f5194 832afcf8 825dde68 825dde48 nt!IoPageRead+0x1b (FPO: [Non-Fpo])
ecd5f700 804ebace 0bd2b860 f86494a1 c03e1924 nt!MiDispatchFault+0x274 (FPO: [Non-Fpo])
ecd5f750 804e1718 00000000 f86494a1 00000000 nt!MmAccessFault+0x5bc (FPO: [Non-Fpo])
ecd5f750 f86494a1 00000000 f86494a1 00000000 nt!KiTrap0E+0xcc (FPO: [0,0] TrapFrame @ ecd5f768)
ecd5f7d8 804e264c ecd5f840 804e25b1 ffffffff Ntfs!NtfsWalkUpTree+0x241 (FPO: [Non-Fpo])
ecd5f7fc 804e2565 ecd60348 ffffffff ecd5f828 nt!_NLG_Return2 (FPO: [2,0,3])
ecd5f828 804db49a ecd5f898 ecd60348 ecd5f944 nt!_except_handler3+0xd5 (FPO: [Uses EBP] [3,0,7])
ecd5f84c 804db46b ecd5f898 ecd60348 ecd5f944 nt!ExecuteHandler2+0x26
ecd5fc14 804e25a9 ecd604a4 804e25a9 00000000 nt!ExecuteHandler+0x24
ecd5fc3c 804e2505 ecd604a4 ecd5fc60 00000000 nt!_global_unwind2+0x18
ecd5fc60 804db49a ecd6010c ecd604a4 ecd5fe08 nt!_except_handler3+0x75 (FPO: [Uses EBP] [3,0,7])
ecd5fc84 804db46b ecd6010c ecd604a4 ecd5fe08 nt!ExecuteHandler2+0x26
ecd5fd34 80513486 ecd6010c ecd5fe08 c00002e8 nt!ExecuteHandler+0x24
ecd600f0 804df235 ecd6010c 00000000 ecd60160 nt!KiDispatchException+0x13e (FPO: [Non-Fpo])
ecd60158 804e1825 ecd60220 8056ae04 badb0d00 nt!CommonDispatchException+0x4d (FPO: [0,20,0])
ecd60158 8056ae04 ecd60220 8056ae04 badb0d00 nt!KiTrap0E+0x1d9 (FPO: [0,0] TrapFrame @ ecd60160)
ecd60220 f860a7cb 82790348 ecd60250 000003a0 nt!CcMapData+0xef (FPO: [Non-Fpo])
ecd60240 f862af07 ecd604c8 82360ac8 00000000 Ntfs!NtfsMapStream+0x46 (FPO: [Non-Fpo])
ecd60278 f860dd2c ecd604c8 e30dbcc8 ecd6030c Ntfs!NtfsMapAttributeValue+0x9b (FPO: [Non-Fpo])
ecd602ac f8626b15 ecd604c8 e30dbcc8 dede6898 Ntfs!NtfsLookupInFileRecord+0xf5 (FPO: [Non-Fpo])
ecd60358 f8626bf7 ecd604c8 e30dbcc8 f8626c2a Ntfs!NtfsWalkUpTree+0x79 (FPO: [Non-Fpo])
ecd603b4 f86108c1 ecd604c8 e30dbcc8 00000000 Ntfs!NtfsBuildNormalizedName+0x44 (FPO: [Non-Fpo])
ecd603e0 f860be10 ecd604c8 82790348 82360ac8 Ntfs!NtfsQueryNameInfo+0x4b (FPO: [Non-Fpo])
ecd60450 f860a4b4 ecd604c8 823f3588 823f3718 Ntfs!NtfsCommonQueryInformation+0x28c (FPO: [Non-Fpo])
ecd604b4 f860a4ed ecd604c8 823f3588 00000001 Ntfs!NtfsFsdDispatchSwitch+0x12a (FPO: [Non-Fpo])
ecd605d8 804e37f7 8335e520 823f3588 833cfbf8 Ntfs!NtfsFsdDispatchWait+0x1c (FPO: [Non-Fpo])
ecd605e8 f8688459 ecd60618 804e37f7 8335edd0 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
ecd605f0 804e37f7 8335edd0 823f3588 804e8a39 sr!SrPassThrough+0x31 (FPO: [Non-Fpo])
ecd60600 efdbd752 823f3718 823f373c ecd60650 nt!IopfCallDriver+0x31 (FPO: [0,0,0])
ecd60618 efdc4800 8335edd0 82ff33e8 ecd60650 SYMEVENT+0x7752
ecd60634 efdbd8b9 ecd60650 804e8a39 efdbd97a SYMEVENT+0xe800
0
 
cpc2004Commented:
Your windows is crashed with double fault. The first fault is In-page I/O error and the second fault is stack overflow. The In-page I/O error is usually caused by the corrupted paging space. Run chkdsk /r and re-allocate the paging space.

BUGCHECK_STR:  0x7f_8
CUSTOMER_CRASH_COUNT:  1
DEFAULT_BUCKET_ID:  DRIVER_FAULT

EXCEPTION_RECORD:  ecd6010c -- (.exr ffffffffecd6010c)
.exr ffffffffecd6010c
ExceptionAddress: 8056ae04 (nt!CcMapData+0x000000ef)
   ExceptionCode: c0000006 (In-page I/O error)
  ExceptionFlags: 00000000
NumberParameters: 3
   Parameter[0]: 00000000
   Parameter[1]: c3580000
   Parameter[2]: c00002e8
Inpage operation failed at c3580000, due to I/O error c00002e8
0
 
KJOBrienAuthor Commented:
I have followed instructions via links through MS and Symantec.

Symantec instructions for setting KStackMinFree parameter are as follows:

To modify the registry by adding the KStackMinFree value in Symantec AntiVirus 9.x or later
In the Registry Editor, go to the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan


Right-click the RealTimeScan key, and then click New > DWORD Value.
Type KStackMinFree for the name of the new value.
Right-click the KStackMinFree value, and then click Modify.
Set the Base to Hexadecimal, and then type 2200 in the Value field.
Click OK.
Restart the computer.



I have expanded the registry as far as HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\  but I can't locate a LANDesk parameter.
My version of antivirus is 12.1.0.20

Can you help?

Kieran

0
 
KJOBrienAuthor Commented:
I found another reference on the Symantec web site and downloaded a programme to add KStackMinFree=2200. Ran the programme and received confirmation that KStackMinFree added to registry.

Also ran ChkDsk as suggested.

PC now operates ok (although error re HP officeJet Com is still comes up on boot)

Thanks for your help. I consider question closed.

Kieran
0
 
KJOBrienAuthor Commented:
How do I close the question?

Afraid I'm a newbie.

Kieran
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.