getting blue screen error 3b!


  1. Posts : 88
    windows7 64 bit
       #1

    getting blue screen error 3b!


    hi!

    I am getting a series of blue screen errors.The latest being a

    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.1.7601.2.1.0.768.2
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 3b
    BCP1: 00000000C0000005
    BCP2: FFFFF88003E48900
    BCP3: FFFFF88007445640
    BCP4: 0000000000000000
    OS Version: 6_1_7601
    Service Pack: 1_0
    Product: 768_1

    Files that help describe the problem:
    C:\Windows\Minidump\061111-27970-01.dmp
    C:\Users\mahesh\AppData\Local\Temp\WER-44975-0.sysdata.xml.

    Can you tell me what caused the problem.Could it be a memory problem?
    I have uploaded the memory dump file.
    Please tell me as to what could be the problem.
      My Computer


  2. Posts : 28,845
    Win 8 Release candidate 8400
       #2

    Maheshputt said:
    hi!

    I am getting a series of blue screen errors.The latest being a

    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.1.7601.2.1.0.768.2
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 3b
    BCP1: 00000000C0000005
    BCP2: FFFFF88003E48900
    BCP3: FFFFF88007445640
    BCP4: 0000000000000000
    OS Version: 6_1_7601
    Service Pack: 1_0
    Product: 768_1

    Files that help describe the problem:
    C:\Windows\Minidump\061111-27970-01.dmp
    C:\Users\mahesh\AppData\Local\Temp\WER-44975-0.sysdata.xml.

    Can you tell me what caused the problem.Could it be a memory problem?
    I have uploaded the memory dump file.
    Please tell me as to what could be the problem.
    Easy, your McAfee. Remove and replace with Microsoft security essentials

    How to uninstall or reinstall supported McAfee consumer products using the McAfee Consumer Products Removal tool (MCPR.exe)

    Virus, Spyware & Malware Protection | Microsoft Security Essentials

    Code:
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [C:\Users\K\Desktop\061111-27970-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
    *http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 7601.17592.amd64fre.win7sp1_gdr.110408-1631
    Machine Name:
    Kernel base = 0xfffff800`03253000 PsLoadedModuleList = 0xfffff800`03498650
    Debug session time: Sat Jun 11 07:29:39.364 2011 (GMT-4)
    System Uptime: 0 days 0:01:19.956
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 3B, {c0000005, fffff88003e48900, fffff88007445640, 0}
    
    Probably caused by : mfefirek.sys ( mfefirek+48900 )
    
    Followup: MachineOwner
    ---------
    
    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff88003e48900, Address of the exception record for the exception that caused the bugcheck
    Arg3: fffff88007445640, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    FAULTING_IP: 
    mfefirek+48900
    fffff880`03e48900 41ff5120        call    qword ptr [r9+20h]
    
    CONTEXT:  fffff88007445640 -- (.cxr 0xfffff88007445640)
    rax=fffffa8006effd4f rbx=fffffa8006effd4f rcx=fffffa8006effd4f
    rdx=fffff880074461c0 rsi=fffff880074461c0 rdi=fffffa8003995c30
    rip=fffff88003e48900 rsp=fffff88007446020 rbp=0000000000000001
     r8=0000000000000001  r9=fff88003e5a97000 r10=00520054005f0044
    r11=fffffa80064bcdc8 r12=fffffa8006e93190 r13=fffffa800530b001
    r14=fffffa800530b4f0 r15=fffff88007446530
    iopl=0         nv up ei ng nz na pe nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
    mfefirek+0x48900:
    fffff880`03e48900 41ff5120        call    qword ptr [r9+20h] ds:002b:fff88003`e5a97020=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x3B
    
    PROCESS_NAME:  McSvHost.exe
    
    CURRENT_IRQL:  2
    
    LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff88003e48900
    
    STACK_TEXT:  
    fffff880`07446020 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : mfefirek+0x48900
    
    
    FOLLOWUP_IP: 
    mfefirek+48900
    fffff880`03e48900 41ff5120        call    qword ptr [r9+20h]
    
    SYMBOL_STACK_INDEX:  0
    
    SYMBOL_NAME:  mfefirek+48900
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: mfefirek
    
    IMAGE_NAME:  mfefirek.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4d6edb33
    
    STACK_COMMAND:  .cxr 0xfffff88007445640 ; kb
    
    FAILURE_BUCKET_ID:  X64_0x3B_mfefirek+48900
    
    BUCKET_ID:  X64_0x3B_mfefirek+48900
    
    Followup: MachineOwner
    ---------
      My Computer


  3. Posts : 88
    windows7 64 bit
    Thread Starter
       #3

    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************
    SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: ffffffffc0000005, The exception code that was not handled
    Arg2: fffff800032c9d01, The address that the exception occurred at
    Arg3: fffff88002ffc5c8, Exception Record Address
    Arg4: fffff88002ffbe20, Context Record Address
    Debugging Details:
    ------------------
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    FAULTING_IP:
    nt!MiGetNextNode+25
    fffff800`032c9d01 488b4808 mov rcx,qword ptr [rax+8]
    EXCEPTION_RECORD: fffff88002ffc5c8 -- (.exr 0xfffff88002ffc5c8)
    ExceptionAddress: fffff800032c9d01 (nt!MiGetNextNode+0x0000000000000025)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 0000000000000000
    Parameter[1]: 0000000100000007
    Attempt to read from address 0000000100000007
    CONTEXT: fffff88002ffbe20 -- (.cxr 0xfffff88002ffbe20)
    rax=00000000ffffffff rbx=fffffa80039dfb60 rcx=fffffa8003994c20
    rdx=fffffa8004cc2c54 rsi=fffffa8003c18278 rdi=fffffa8003994c20
    rip=fffff800032c9d01 rsp=fffff88002ffc808 rbp=fffffa8004cc5620
    r8=0000000000000005 r9=00000000000007ff r10=0000000000000801
    r11=0000000000000000 r12=fffff8a005887000 r13=0000000000000000
    r14=fffff8a005887028 r15=0000000000000000
    iopl=0 nv up ei pl nz na po nc
    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
    nt!MiGetNextNode+0x25:
    fffff800`032c9d01 488b4808 mov rcx,qword ptr [rax+8] ds:002b:00000001`00000007=????????????????
    Resetting default scope
    CUSTOMER_CRASH_COUNT: 1
    DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
    PROCESS_NAME: chrome.exe
    CURRENT_IRQL: 0
    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    EXCEPTION_PARAMETER1: 0000000000000000
    EXCEPTION_PARAMETER2: 0000000100000007
    READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800034c6100
    0000000100000007
    FOLLOWUP_IP:
    nt!MiGetNextNode+25
    fffff800`032c9d01 488b4808 mov rcx,qword ptr [rax+8]
    BUGCHECK_STR: 0x7E
    LAST_CONTROL_TRANSFER: from fffff8000362b1f0 to fffff800032c9d01
    STACK_TEXT:
    fffff880`02ffc808 fffff800`0362b1f0 : fffff880`02ffc830 fffffa80`039dfb60 fffff880`00000006 fffff8a0`057b7710 : nt!MiGetNextNode+0x25
    fffff880`02ffc810 fffff800`0366f9b1 : fffffa80`03c18060 00000000`00001404 fffffa80`03dd7000 00000000`00000002 : nt!MmEnumerateAndReferenceImages+0x160
    fffff880`02ffc890 fffff800`0366fc24 : fffffa80`03c18060 fffff800`00000048 fffff800`0366fa00 fffff880`02ffc9b0 : nt!EtwpEnumerateImages+0x51
    fffff880`02ffc8e0 fffff800`03626af6 : fffffa80`03b0f060 fffffa80`03c18060 fffff800`0366fa50 fffff880`02ffc9b0 : nt!EtwpProcessEnumCallback+0x1d4
    fffff880`02ffc960 fffff800`0366fd71 : fffff880`02ffca98 fffffa80`04356801 fffffa80`04356500 fffffa80`04356500 : nt!PsEnumProcesses+0x26
    fffff880`02ffc990 fffff800`0366fdc7 : 00000000`00000000 00000000`00000002 fffff800`03433120 fffffa80`04356580 : nt!EtwpProcessThreadImageRundown+0x51
    fffff880`02ffc9e0 fffff800`036dba6c : 00000000`00401802 fffffa80`04356828 fffffa80`04356580 fffff800`033c2fbd : nt!EtwpKernelTraceRundown+0x47
    fffff880`02ffca10 fffff800`036dbb6f : fffffa80`04356580 00000000`00000002 fffff8a0`0499b930 00000000`00000000 : nt!EtwpUpdateLoggerGroupMasks+0x22c
    fffff880`02ffcb10 fffff800`034eb129 : 00000000`00000000 fffff8a0`0499b930 00000000`00000000 fffff800`032aab06 : nt!EtwpStopLoggerInstance+0x4f
    fffff880`02ffcb50 fffff800`034eaea0 : 00000000`00000000 00000000`00000002 fffffa80`04356580 ffffffff`88ca6c00 : nt!EtwpStopTrace+0x129
    fffff880`02ffcbc0 fffff800`03702f35 : ffffffff`ffffffff 00000000`00000001 ffffffff`000000b4 00000000`00000001 : nt! ?? ::NNGAKEGL::`string'+0x59edc
    fffff880`02ffcc30 fffff800`032a1021 : fffff800`03434200 fffff800`03702d70 fffff800`034342b8 fffffa80`039dfb60 : nt!PerfDiagpProxyWorker+0x1c5
    fffff880`02ffcc70 fffff800`0353332e : ffdfffff`bfffefdf fffffa80`039dfb60 00000000`00000080 fffffa80`039ce040 : nt!ExpWorkerThread+0x111
    fffff880`02ffcd00 fffff800`03288666 : fffff880`009e6180 fffffa80`039dfb60 fffff880`009f0f40 fdffffff`fefdffff : nt!PspSystemThreadStartup+0x5a
    fffff880`02ffcd40 00000000`00000000 : fffff880`02ffd000 fffff880`02ff7000 fffff880`02ffc0d0 00000000`00000000 : nt!KiStartSystemThread+0x16
    SYMBOL_STACK_INDEX: 0
    SYMBOL_NAME: nt!MiGetNextNode+25
    FOLLOWUP_NAME: MachineOwner
    MODULE_NAME: nt
    DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd5b
    STACK_COMMAND: .cxr 0xfffff88002ffbe20 ; kb
    IMAGE_NAME: memory_corruption
    FAILURE_BUCKET_ID: X64_0x7E_nt!MiGetNextNode+25
    BUCKET_ID: X64_0x7E_nt!MiGetNextNode+25
    Followup: MachineOwner

    also getting error 0*0000007E

    can you tell me what caused the problem?
      My Computer


  4. Posts : 88
    windows7 64 bit
    Thread Starter
       #4

    can any one help me with this error?
      My Computer


  5. Posts : 8,383
    Windows 10 Pro x64, Arch Linux
       #5

    Maheshputt said:
    can any one help me with this error?
    Remove McAfee and upload the latest dump files
      My Computer


  6. Posts : 88
    windows7 64 bit
    Thread Starter
       #6

    okay thanks
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:08.
Find Us