Solved

PAGE_FAULT_IN_NON_PAGED_AREA

Posted on 2009-05-20
8
302 Views
Last Modified: 2012-05-07
Okay thats the error I get when starting a customers pc.

I dont understand how to get the event logs so I went into view event viewer and copied it to a .txt file. Please find them attached and in the code snippet section.

I understand that DWord means Int does it not?

Anyhow I tried a chkdsk, memory test, HDD test, spyware test.

It works in safe mode which leads me to believe it to be a Driver fault.

I went into safe mode with networking plugged in my ethernet cable wouldnt connect to the internet.

I then looked at the Network Connections to check the TCP/IP connections but it said it couldnt view the network connections? Strange error I have never came accross before which then resulted in me scanning for virus's and spyware/malware using MalwareBytes and KIS online scanner (Kaspersky).

Any help appreciated.
Event Type:	Error

Event Source:	LoadPerf

Event Category:	None

Event ID:	3001

Date:		20/05/2009

Time:		17:32:19

User:		N/A

Computer:	BACKBUSINESS

Description:

The performance counter name string value in the registry is incorrectly formatted. The bogus string is 4454, the bogus index value is the first DWORD in Data section while the last valid index values are the second and third DWORD in Data section.
 

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Data:

0000: 66 11 00 00 64 11 00 00   f...d...

0008: 65 11 00 00 cf 01 00 00   e...Ï...
 
 

Event Type:	Error

Event Source:	LoadPerf

Event Category:	None

Event ID:	3011

Date:		20/05/2009

Time:		17:32:19

User:		N/A

Computer:	BACKBUSINESS

Description:

Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The Error code is the first DWORD in Data section.
 

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Data:

0000: f2 03 00 00 3b 07 00 00   ò...;...
 
 

Event Type:	Warning

Event Source:	LoadPerf

Event Category:	None

Event ID:	2006

Date:		20/05/2009

Time:		17:32:22

User:		N/A

Computer:	BACKBUSINESS

Description:

LastCounter and LastHelp values of performance registry is corrupted and needs to be updated. The first and second DWORDs in Data Section are the original values while the third and forth DWORDs in Data Section are the updated new values.
 

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Data:

0000: 64 11 00 00 65 11 00 00   d...e...

0008: 70 11 00 00 71 11 00 00   p...q...
 
 

Event Type:	Error

Event Source:	LoadPerf

Event Category:	None

Event ID:	3001

Date:		20/05/2009

Time:		17:32:23

User:		N/A

Computer:	BACKBUSINESS

Description:

The performance counter name string value in the registry is incorrectly formatted. The bogus string is 4454, the bogus index value is the first DWORD in Data section while the last valid index values are the second and third DWORD in Data section.
 

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Data:

0000: 66 11 00 00 64 11 00 00   f...d...

0008: 65 11 00 00 97 02 00 00   e...—...

Open in new window

events.txt
0
Comment
Question by:squirrel_force
  • 5
  • 2
8 Comments
 
LVL 11

Assisted Solution

by:NaturaTek
NaturaTek earned 250 total points
ID: 24433715
Hey squirrel

When you turn the client's pc on and you see the blue screen can you see quickly if you can catch the stop 0x00.. code if you can
And further down you might see it reference a file like win2k.sys or some type of file. I'll look thru your attachment in a sec.
0
 
LVL 8

Accepted Solution

by:
eXpeLLeD_4RM_heLL earned 250 total points
ID: 24433886
Once in safe mode locate the folder C.:windows\minidumps and post the last five files located therin.  Zip the files and post it here. Also in safe mode, networking is disabled disabled, however if you choose safe mode with networking you will be able to access the Internet
0
 
LVL 11

Assisted Solution

by:NaturaTek
NaturaTek earned 250 total points
ID: 24434098
By anychance do you have Norton/Symantec installed or had it previously installed?
0
 

Author Comment

by:squirrel_force
ID: 24438956
The Customer has AVG installed (yes I know its shit but he refuses to pay and its better than nothing.)
I am unsure of his other Anti-Virus if he had any before.

I will do what eXpeLLeD 4RM heLL has said.

And the 0x00 thing ends in 50 I know that. (unsure of the amount of 0's)
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:squirrel_force
ID: 24439157
Attached the .zip for you....

It wouldnt let me keep the .dmp extension so I just removed it but its still the correct last 5 entries.
Dumps.zip
0
 

Author Comment

by:squirrel_force
ID: 24439810
A list of things I tried:

ControlPanel => System => Advanced => The physical Memory thing.

Memory Caching

Tested memory no problems.

Replaced memory same problem. (Removed added new same problem).

Could it be caused by AVG as on there forums someone has the same problem.
0
 

Author Comment

by:squirrel_force
ID: 24440033
Found out the problem to be caused by AVG, went through the registry searching for every detail of AVG, deleted all.

NOTE: NO UNEXPERIENCED PC USERS SHOULD DO THAT.

Thanks for all your help guys.
0
 

Author Closing Comment

by:squirrel_force
ID: 31583547
Thanks for your help guys.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
Migration of Exchange mailbox can be done with the ExProfre.exe tool. But at times, when the ExProfre.exe tool migrates the Exchange Server user profile, it results in numerous synchronization problems. Synchronization error messages appear in the e…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now