Bij het draaien van quickpar (heb de nieuwste versie), crasht het systeem telkens bij het repareren van grote bestanden (zoals dvd's), waarbij je reparatieblokken nodig hebt van in totaal meer dan 100mb. Dan volgt er een BSOD waarin er een memory dump wordt gemaakt (mini-dump).
Ook bij het draaien van Memtest 3.1 krijg ik zo'n BSOD.
Nu heb ik met een debug tool informatie weten te halen uit de dumpfile, maar ikzelf begrijp daar niks van. Misschien dat iemand van jullie er wel wijs uit kan en mij kan vertellen wat het probleem is?
Zou trouwens wel merkwaardig zijn als het geheugen niet goed blijkt te zijn. Die is namelijk erg nieuw en van topkwaliteit (Corsair 2x512mb TwinX Matched Memory Pair 2-2-2-5 latency).
Dit alles op een Asus P4P800 Deluxe mobo en Pentium 4 2,8Ghz cpu met HT.
Hier de debug info:
WARNING: Inaccessible path: 'C:\Program Files\Debugging Tools for Windows\symbols*http://msdl.microsoft.com/download/symbols'
Loading Dump File [C:\WINDOWS\Minidump\Mini042005-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Program Files\Debugging Tools for Windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp2.030422-1633
Kernel base = 0x804d4000 PsLoadedModuleList = 0x8054a230
Debug session time: Wed Apr 20 01:53:36.093 2005 (GMT+2)
System Uptime: 0 days 0:19:13.775
Loading Kernel Symbols
................................................................................................................................
Loading unloaded module list
........
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 805cea9a, eb033a80, 0}
Unable to load image a347bus.sys, Win32 error 2
*** WARNING: Unable to verify timestamp for a347bus.sys
*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 805cea9a, The address that the exception occurred at
Arg3: eb033a80, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - De instructie op 0x%08lx verwijst naar geheugen op 0x%08lx. De lees- of schrijfbewerking ("%s") op het geheugen is mislukt.
FAULTING_IP:
nt!SeCreateAccessState+60
805cea9a 108943188d43 adc [ecx+0x438d1843],cl
TRAP_FRAME: eb033a80 -- (.trap ffffffffeb033a80)
ErrCode = 00000002
eax=00000001 ebx=851d0ee9 ecx=00000005 edx=e1002a84 esi=851d0f9c edi=e1002a80
eip=805cea9a esp=eb033af4 ebp=eb033b00 iopl=0 nv up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010283
nt!SeCreateAccessState+0x60:
805cea9a 108943188d43 adc [ecx+0x438d1843],cl ds:0023:438d1848=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x8E
LAST_CONTROL_TRANSFER: from 8059da27 to 805cea9a
STACK_TEXT:
eb033b00 8059da27 851d0ee8 851d0f9c 00000009 nt!SeCreateAccessState+0x60
eb033b38 8055b4b3 00000000 00000000 80534800 nt!ObOpenObjectByName+0x8d
eb033bb4 8055bc2e eb033d68 00000080 eb033d40 nt!IopCreateFile+0x407
eb033bfc 8055f14b eb033d68 00000080 eb033d40 nt!IoCreateFile+0x36
eb033c3c f781bc2b eb033d68 00000080 eb033d40 nt!NtOpenFile+0x25
WARNING: Stack unwind information not available. Following frames may be wrong.
eb033d68 00000080 eb033da8 eb033da4 00000000 a347bus+0x1c2b
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
805cea95 - nt!SeCreateAccessState+5b
[ 8b:83 ]
1 error : !nt (805cea95)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BIT
STACK_COMMAND: .trap ffffffffeb033a80 ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------
Ook bij het draaien van Memtest 3.1 krijg ik zo'n BSOD.
Nu heb ik met een debug tool informatie weten te halen uit de dumpfile, maar ikzelf begrijp daar niks van. Misschien dat iemand van jullie er wel wijs uit kan en mij kan vertellen wat het probleem is?
Zou trouwens wel merkwaardig zijn als het geheugen niet goed blijkt te zijn. Die is namelijk erg nieuw en van topkwaliteit (Corsair 2x512mb TwinX Matched Memory Pair 2-2-2-5 latency).
Dit alles op een Asus P4P800 Deluxe mobo en Pentium 4 2,8Ghz cpu met HT.
Hier de debug info:
WARNING: Inaccessible path: 'C:\Program Files\Debugging Tools for Windows\symbols*http://msdl.microsoft.com/download/symbols'
Loading Dump File [C:\WINDOWS\Minidump\Mini042005-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Program Files\Debugging Tools for Windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp2.030422-1633
Kernel base = 0x804d4000 PsLoadedModuleList = 0x8054a230
Debug session time: Wed Apr 20 01:53:36.093 2005 (GMT+2)
System Uptime: 0 days 0:19:13.775
Loading Kernel Symbols
................................................................................................................................
Loading unloaded module list
........
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 805cea9a, eb033a80, 0}
Unable to load image a347bus.sys, Win32 error 2
*** WARNING: Unable to verify timestamp for a347bus.sys
*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 805cea9a, The address that the exception occurred at
Arg3: eb033a80, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - De instructie op 0x%08lx verwijst naar geheugen op 0x%08lx. De lees- of schrijfbewerking ("%s") op het geheugen is mislukt.
FAULTING_IP:
nt!SeCreateAccessState+60
805cea9a 108943188d43 adc [ecx+0x438d1843],cl
TRAP_FRAME: eb033a80 -- (.trap ffffffffeb033a80)
ErrCode = 00000002
eax=00000001 ebx=851d0ee9 ecx=00000005 edx=e1002a84 esi=851d0f9c edi=e1002a80
eip=805cea9a esp=eb033af4 ebp=eb033b00 iopl=0 nv up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010283
nt!SeCreateAccessState+0x60:
805cea9a 108943188d43 adc [ecx+0x438d1843],cl ds:0023:438d1848=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x8E
LAST_CONTROL_TRANSFER: from 8059da27 to 805cea9a
STACK_TEXT:
eb033b00 8059da27 851d0ee8 851d0f9c 00000009 nt!SeCreateAccessState+0x60
eb033b38 8055b4b3 00000000 00000000 80534800 nt!ObOpenObjectByName+0x8d
eb033bb4 8055bc2e eb033d68 00000080 eb033d40 nt!IopCreateFile+0x407
eb033bfc 8055f14b eb033d68 00000080 eb033d40 nt!IoCreateFile+0x36
eb033c3c f781bc2b eb033d68 00000080 eb033d40 nt!NtOpenFile+0x25
WARNING: Stack unwind information not available. Following frames may be wrong.
eb033d68 00000080 eb033da8 eb033da4 00000000 a347bus+0x1c2b
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
805cea95 - nt!SeCreateAccessState+5b
[ 8b:83 ]
1 error : !nt (805cea95)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BIT
STACK_COMMAND: .trap ffffffffeb033a80 ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------