memory corruption

Associate
Joined
17 Jul 2011
Posts
18
Hi Again,

Not sure what topic to put this under so I will try here.

I have been trying to do some work in excel and word but it crashes after a few seconds and after a few tries a blue screen of death pops up. I put some team group 16gig memory in a few days ago but everything has been running fine apart from a virus that I had on the pc that I got rid of. not sure if anyone can help but this is what the dump file says.


Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Debug\022812-18782-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03218000 PsLoadedModuleList = 0xfffff800`0345d670
Debug session time: Tue Feb 28 10:12:18.141 2012 (UTC + 0:00)
System Uptime: 0 days 0:02:39.922
Loading Kernel Symbols
...............................................................
................................................................
...........................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff960000a3464, fffff880090d70f0, 0}

Probably caused by : memory_corruption

Followup: memory_corruption
---------

6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx

CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: CODE_CORRUPTION

BUGCHECK_STR: 0x3B

PROCESS_NAME: explorer.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464

STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba


CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)

MODULE_NAME: memory_corruption

IMAGE_NAME: memory_corruption

FOLLOWUP_NAME: memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MEMORY_CORRUPTOR: LARGE

STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb

FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

Followup: memory_corruption
---------

6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx

CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: CODE_CORRUPTION

BUGCHECK_STR: 0x3B

PROCESS_NAME: explorer.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464

STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba


CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)

MODULE_NAME: memory_corruption

IMAGE_NAME: memory_corruption

FOLLOWUP_NAME: memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MEMORY_CORRUPTOR: LARGE

STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb

FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

Followup: memory_corruption
---------


Update: just ran 2 passes on memtest86 with 0 errors. also I had prim95 running this morning for about 4 hours and no crashes during that time.

Update2: just reinstalled office and i think its fixed (touch wood!) maybe it was a office file that got infected.

OR NOT! excel just crashed again.
 
Last edited:
run a memory test...

go to start > type in "memory" and choose memory Diag tool... restart and let windows do its thing.. once you log back in, go to event manager by start > event manager and the results should appear in there.

depending on your specs... run the test on one stick of memory at a time.
 
Back
Top Bottom