Solved

PAGE_FAULT_IN_NON_PAGED_AREA

Posted on 2009-05-20
8
304 Views
Last Modified: 2012-05-07
Okay thats the error I get when starting a customers pc.

I dont understand how to get the event logs so I went into view event viewer and copied it to a .txt file. Please find them attached and in the code snippet section.

I understand that DWord means Int does it not?

Anyhow I tried a chkdsk, memory test, HDD test, spyware test.

It works in safe mode which leads me to believe it to be a Driver fault.

I went into safe mode with networking plugged in my ethernet cable wouldnt connect to the internet.

I then looked at the Network Connections to check the TCP/IP connections but it said it couldnt view the network connections? Strange error I have never came accross before which then resulted in me scanning for virus's and spyware/malware using MalwareBytes and KIS online scanner (Kaspersky).

Any help appreciated.
Event Type:	Error
Event Source:	LoadPerf
Event Category:	None
Event ID:	3001
Date:		20/05/2009
Time:		17:32:19
User:		N/A
Computer:	BACKBUSINESS
Description:
The performance counter name string value in the registry is incorrectly formatted. The bogus string is 4454, the bogus index value is the first DWORD in Data section while the last valid index values are the second and third DWORD in Data section.
 
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 66 11 00 00 64 11 00 00   f...d...
0008: 65 11 00 00 cf 01 00 00   e...Ï...
 
 
Event Type:	Error
Event Source:	LoadPerf
Event Category:	None
Event ID:	3011
Date:		20/05/2009
Time:		17:32:19
User:		N/A
Computer:	BACKBUSINESS
Description:
Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The Error code is the first DWORD in Data section.
 
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: f2 03 00 00 3b 07 00 00   ò...;...
 
 
Event Type:	Warning
Event Source:	LoadPerf
Event Category:	None
Event ID:	2006
Date:		20/05/2009
Time:		17:32:22
User:		N/A
Computer:	BACKBUSINESS
Description:
LastCounter and LastHelp values of performance registry is corrupted and needs to be updated. The first and second DWORDs in Data Section are the original values while the third and forth DWORDs in Data Section are the updated new values.
 
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 64 11 00 00 65 11 00 00   d...e...
0008: 70 11 00 00 71 11 00 00   p...q...
 
 
Event Type:	Error
Event Source:	LoadPerf
Event Category:	None
Event ID:	3001
Date:		20/05/2009
Time:		17:32:23
User:		N/A
Computer:	BACKBUSINESS
Description:
The performance counter name string value in the registry is incorrectly formatted. The bogus string is 4454, the bogus index value is the first DWORD in Data section while the last valid index values are the second and third DWORD in Data section.
 
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 66 11 00 00 64 11 00 00   f...d...
0008: 65 11 00 00 97 02 00 00   e...—...

Open in new window

events.txt
0
Comment
Question by:squirrel_force
  • 5
  • 2
8 Comments
 
LVL 11

Assisted Solution

by:NaturaTek
NaturaTek earned 250 total points
ID: 24433715
Hey squirrel

When you turn the client's pc on and you see the blue screen can you see quickly if you can catch the stop 0x00.. code if you can
And further down you might see it reference a file like win2k.sys or some type of file. I'll look thru your attachment in a sec.
0
 
LVL 8

Accepted Solution

by:
eXpeLLeD_4RM_heLL earned 250 total points
ID: 24433886
Once in safe mode locate the folder C.:windows\minidumps and post the last five files located therin.  Zip the files and post it here. Also in safe mode, networking is disabled disabled, however if you choose safe mode with networking you will be able to access the Internet
0
 
LVL 11

Assisted Solution

by:NaturaTek
NaturaTek earned 250 total points
ID: 24434098
By anychance do you have Norton/Symantec installed or had it previously installed?
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 

Author Comment

by:squirrel_force
ID: 24438956
The Customer has AVG installed (yes I know its shit but he refuses to pay and its better than nothing.)
I am unsure of his other Anti-Virus if he had any before.

I will do what eXpeLLeD 4RM heLL has said.

And the 0x00 thing ends in 50 I know that. (unsure of the amount of 0's)
0
 

Author Comment

by:squirrel_force
ID: 24439157
Attached the .zip for you....

It wouldnt let me keep the .dmp extension so I just removed it but its still the correct last 5 entries.
Dumps.zip
0
 

Author Comment

by:squirrel_force
ID: 24439810
A list of things I tried:

ControlPanel => System => Advanced => The physical Memory thing.

Memory Caching

Tested memory no problems.

Replaced memory same problem. (Removed added new same problem).

Could it be caused by AVG as on there forums someone has the same problem.
0
 

Author Comment

by:squirrel_force
ID: 24440033
Found out the problem to be caused by AVG, went through the registry searching for every detail of AVG, deleted all.

NOTE: NO UNEXPERIENCED PC USERS SHOULD DO THAT.

Thanks for all your help guys.
0
 

Author Closing Comment

by:squirrel_force
ID: 31583547
Thanks for your help guys.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your system is showing symptoms of browser hijacks or 'google search redirects' check out my other article (http://rdsrc.us/u3GP7A) first and run the tool TDSSKiller (http://rdsrc.us/GDBBs4) to get rid of the infection. Once done, and if the …
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question