Hi Again,
Not sure what topic to put this under so I will try here.
I have been trying to do some work in excel and word but it crashes after a few seconds and after a few tries a blue screen of death pops up. I put some team group 16gig memory in a few days ago but everything has been running fine apart from a virus that I had on the pc that I got rid of. not sure if anyone can help but this is what the dump file says.
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Debug\022812-18782-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03218000 PsLoadedModuleList = 0xfffff800`0345d670
Debug session time: Tue Feb 28 10:12:18.141 2012 (UTC + 0:00)
System Uptime: 0 days 0:02:39.922
Loading Kernel Symbols
...............................................................
................................................................
...........................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960000a3464, fffff880090d70f0, 0}
Probably caused by : memory_corruption
Followup: memory_corruption
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx
CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x3B
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464
STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba
CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: LARGE
STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
Followup: memory_corruption
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx
CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x3B
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464
STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba
CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: LARGE
STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
Followup: memory_corruption
---------
Update: just ran 2 passes on memtest86 with 0 errors. also I had prim95 running this morning for about 4 hours and no crashes during that time.
Update2: just reinstalled office and i think its fixed (touch wood!) maybe it was a office file that got infected.
OR NOT! excel just crashed again.
Not sure what topic to put this under so I will try here.
I have been trying to do some work in excel and word but it crashes after a few seconds and after a few tries a blue screen of death pops up. I put some team group 16gig memory in a few days ago but everything has been running fine apart from a virus that I had on the pc that I got rid of. not sure if anyone can help but this is what the dump file says.
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Debug\022812-18782-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03218000 PsLoadedModuleList = 0xfffff800`0345d670
Debug session time: Tue Feb 28 10:12:18.141 2012 (UTC + 0:00)
System Uptime: 0 days 0:02:39.922
Loading Kernel Symbols
...............................................................
................................................................
...........................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960000a3464, fffff880090d70f0, 0}
Probably caused by : memory_corruption
Followup: memory_corruption
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx
CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x3B
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464
STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba
CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: LARGE
STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
Followup: memory_corruption
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000a3464, Address of the instruction which caused the bugcheck
Arg3: fffff880090d70f0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!NtUserGetForegroundWindow+0
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx
CONTEXT: fffff880090d70f0 -- (.cxr 0xfffff880090d70f0)
rax=0000000000000000 rbx=fffffa8011c51a10 rcx=00000000000301fc
rdx=00000000000301fc rsi=0000000000000000 rdi=0000000000000020
rip=fffff960000a3464 rsp=fffff880090d7ad8 rbp=fffff880090d7b60
r8=0000000000000200 r9=0000000000000000 r10=fffff960000a3464
r11=000007fffffde000 r12=000000000426045e r13=00000000000301fc
r14=0000000000000000 r15=00000000fffffffe
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!NtUserGetForegroundWindow:
fffff960`000a3464 48895c2008 mov qword ptr [rax+8],rbx ds:002b:00000000`00000008=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x3B
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80003293ed3 to fffff960000a3464
STACK_TEXT:
fffff880`090d7ad8 fffff800`03293ed3 : fffffa80`11c51a10 fffff880`090d7b60 00000000`00000000 00000000`06fa35b0 : win32k!NtUserGetForegroundWindow
fffff880`090d7ae0 00000000`77605aba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023e6e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77605aba
CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
fffff960000a3467 - win32k!NtUserGetForegroundWindow+3
[ 24:20 ]
fffff960000a3688-fffff960000a368f 8 bytes - win32k!RegisterUserApiHook+4 (+0x221)
[ 90 90 90 90 90 90 90 90:24 ac 0b 03 80 f8 ff ff ]
9 errors : !win32k (fffff960000a3467-fffff960000a368f)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: LARGE
STACK_COMMAND: .cxr 0xfffff880090d70f0 ; kb
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
Followup: memory_corruption
---------
Update: just ran 2 passes on memtest86 with 0 errors. also I had prim95 running this morning for about 4 hours and no crashes during that time.
Update2: just reinstalled office and i think its fixed (touch wood!) maybe it was a office file that got infected.
OR NOT! excel just crashed again.
Last edited: