ntoskernel error and bluescreen

G

Guest

I ran debugger on memory dump file and got the following:

*******************************************************************************
*
*
* Bugcheck Analysis
*
*

*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000204, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8041153d, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: 00000204 Paged pool

CURRENT_IRQL: 2

FAULTING_IP:
nt!CcFindBcb+a7
8041153d 8b00 mov eax,[eax]

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from 8041153d to 804690f3

STACK_TEXT:
bb83359c 8041153d 80416602 817c0988 bb8336e8 nt!KiTrap13+0xe8
bb833620 8040ed24 817c0988 bb8336e8 bb83367c nt!CcFindBcb+0xa7
bb8336a4 8041403b 817c5b78 bb8336e8 00000400 nt!CcPinFileData+0x14b
bb833718 bfea684f 817c5b78 bb83374c 00000400 nt!CcPinMappedData+0x79
bb83373c bfebe376 bb833ac0 817c5cc8 075d0400 Ntfs!NtfsCommonCreate+0x687
bb833808 bfe9bdf7 bb833ac0 e36750d8 e36750f8
Ntfs!NtfsCreateNonresidentWithValue+0x68
bb833a78 bfe9d0df bb833ac0 860f46c8 817c3020 Ntfs!NtfsCreateNewFile+0x7a4
bb833bf0 8041fbbb 817c3020 860f46c8 817c4438 Ntfs!NtfsCommonCleanup+0x1f00
bb833c78 804950ff f9f15760 ffa6cd00 00120196 nt!IoCancelIrp+0x86
bb833ca4 8044ffe5 f9f15760 f9df8094 f9df80a8 nt!NtReleaseMutant+0x10a
bb833d58 80465b91 00000908 00000000 00000000 nt!NtQuerySecurityObject+0x102
bb833d58 77f828d3 00000908 00000000 00000000 nt!KiGetTickCount+0xe1
0980f7a8 7c573d85 00000908 0980f920 630150a4
ntdll!RtlSetSaclSecurityDescriptor+0x53
0980f7b4 630150a4 00000908 00000000 02406dc0
KERNEL32!BaseGetVdmConfigInfo+0xcb
0980f920 6301504a 0245d510 0245d508 0245d518
WININET!CFsm_HttpReadData::`vftable'
0980fa6c 63013e41 00000055 0239e9b0 023f84a8 WININET!`string'+0x22
00000001 00000000 00000000 00000000 00000000
WININET!InternetTimeFromSystemTimeA+0x6e


FOLLOWUP_IP:
nt!CcFindBcb+a7
8041153d 8b00 mov eax,[eax]

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: nt!CcFindBcb+a7

MODULE_NAME: nt

IMAGE_NAME: ntoskrnl.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4047db83

STACK_COMMAND: kb

BUCKET_ID: 0xA_VFL_VRF_nt!CcFindBcb+a7

Followup: MachineOwner
 
G

Guest

Someone said there is a hotfix for this problem. Can someone e-mail it to me?

Tony said:
I ran debugger on memory dump file and got the following:

*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000204, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8041153d, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: 00000204 Paged pool

CURRENT_IRQL: 2

FAULTING_IP:
nt!CcFindBcb+a7
8041153d 8b00 mov eax,[eax]

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from 8041153d to 804690f3

STACK_TEXT:
bb83359c 8041153d 80416602 817c0988 bb8336e8 nt!KiTrap13+0xe8
bb833620 8040ed24 817c0988 bb8336e8 bb83367c nt!CcFindBcb+0xa7
bb8336a4 8041403b 817c5b78 bb8336e8 00000400 nt!CcPinFileData+0x14b
bb833718 bfea684f 817c5b78 bb83374c 00000400 nt!CcPinMappedData+0x79
bb83373c bfebe376 bb833ac0 817c5cc8 075d0400 Ntfs!NtfsCommonCreate+0x687
bb833808 bfe9bdf7 bb833ac0 e36750d8 e36750f8
Ntfs!NtfsCreateNonresidentWithValue+0x68
bb833a78 bfe9d0df bb833ac0 860f46c8 817c3020 Ntfs!NtfsCreateNewFile+0x7a4
bb833bf0 8041fbbb 817c3020 860f46c8 817c4438 Ntfs!NtfsCommonCleanup+0x1f00
bb833c78 804950ff f9f15760 ffa6cd00 00120196 nt!IoCancelIrp+0x86
bb833ca4 8044ffe5 f9f15760 f9df8094 f9df80a8 nt!NtReleaseMutant+0x10a
bb833d58 80465b91 00000908 00000000 00000000 nt!NtQuerySecurityObject+0x102
bb833d58 77f828d3 00000908 00000000 00000000 nt!KiGetTickCount+0xe1
0980f7a8 7c573d85 00000908 0980f920 630150a4
ntdll!RtlSetSaclSecurityDescriptor+0x53
0980f7b4 630150a4 00000908 00000000 02406dc0
KERNEL32!BaseGetVdmConfigInfo+0xcb
0980f920 6301504a 0245d510 0245d508 0245d518
WININET!CFsm_HttpReadData::`vftable'
0980fa6c 63013e41 00000055 0239e9b0 023f84a8 WININET!`string'+0x22
00000001 00000000 00000000 00000000 00000000
WININET!InternetTimeFromSystemTimeA+0x6e


FOLLOWUP_IP:
nt!CcFindBcb+a7
8041153d 8b00 mov eax,[eax]

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: nt!CcFindBcb+a7

MODULE_NAME: nt

IMAGE_NAME: ntoskrnl.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4047db83

STACK_COMMAND: kb

BUCKET_ID: 0xA_VFL_VRF_nt!CcFindBcb+a7

Followup: MachineOwner
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

BSOD and random restarts 1
Windows XP Win2k3 stop error 0xa 1

Top