BSOD after waking computer from sleep mode

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 11,269
    Windows 7 Home Premium 64 Bit
       #11

    You may have to replace it in Safe Mode or if that will not work, do it from Advanced Boot Options -> Repair Your Computer -> System Recovery Options choosing command prompt.

    There are methods for changing the permissions/ownership on files, but I avoid this as much as possible as it can cause system conflicts in some cases later on.
      My Computer


  2. Posts : 15
    windows 7 home premium 64bit
    Thread Starter
       #12

    ok i ran the sfc scan 4 times and it said it had no integrity issues what should i do now
      My Computer


  3. Posts : 11,269
    Windows 7 Home Premium 64 Bit
       #13

    How is the system running?
      My Computer


  4. Posts : 15
    windows 7 home premium 64bit
    Thread Starter
       #14

    fine as far as i can see it usually only had an issue when i closed the lid and then opened it back up
      My Computer


  5. Posts : 11,269
    Windows 7 Home Premium 64 Bit
       #15

    Do your normal routine and post back if you have further problems.
      My Computer


  6. Posts : 15
    windows 7 home premium 64bit
    Thread Starter
       #16

    ok ig got another bsod screen again this is plain old ridiculous well i'm uploading the file again that i just ran so it does have the old info in it
      My Computer


  7. Posts : 11,269
    Windows 7 Home Premium 64 Bit
       #17

    Code:
    
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [G:\Kingston\BSODDmpFiles\midna34704\Windows_NT6_BSOD_jcgriff2\020212-29920-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7601 (Service Pack 1) UP Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
    Machine Name:
    Kernel base = 0xfffff800`02c49000 PsLoadedModuleList = 0xfffff800`02e8e670
    Debug session time: Thu Feb  2 10:41:40.694 2012 (GMT-7)
    System Uptime: 0 days 0:23:35.318
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...................................
    Loading User Symbols
    Loading unloaded module list
    ......
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 1E, {ffffffffc0000005, fffff80002fbea9a, 1, 18}
    
    Probably caused by : ntkrnlmp.exe ( nt!ObpCreateHandle+29a )
    
    Followup: MachineOwner
    ---------
    
    kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    KMODE_EXCEPTION_NOT_HANDLED (1e)
    This is a very common bugcheck.  Usually the exception address pinpoints
    the driver/function that caused the problem.  Always note this address
    as well as the link date of the driver/image that contains this address.
    Arguments:
    Arg1: ffffffffc0000005, The exception code that was not handled
    Arg2: fffff80002fbea9a, The address that the exception occurred at
    Arg3: 0000000000000001, Parameter 0 of the exception
    Arg4: 0000000000000018, Parameter 1 of the exception
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    FAULTING_IP: 
    nt!ObpCreateHandle+29a
    fffff800`02fbea9a f0480fba6f1800  lock bts qword ptr [rdi+18h],0
    
    EXCEPTION_PARAMETER1:  0000000000000001
    
    EXCEPTION_PARAMETER2:  0000000000000018
    
    WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef8100
     0000000000000018 
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x1E
    
    PROCESS_NAME:  Pen_TouchUser.
    
    CURRENT_IRQL:  0
    
    TRAP_FRAME:  fffff8800355b300 -- (.trap 0xfffff8800355b300)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8002407680
    rdx=00000000000f001f rsi=0000000000000000 rdi=0000000000000000
    rip=fffff80002fbea9a rsp=fffff8800355b490 rbp=0000000000000000
     r8=fffff8a00d00f720  r9=00000000000000e8 r10=0000000000000000
    r11=fffff8a00d00f6d0 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei ng nz ac po nc
    nt!ObpCreateHandle+0x29a:
    fffff800`02fbea9a f0480fba6f1800  lock bts qword ptr [rdi+18h],0 ds:00000000`00000018=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002d11588 to fffff80002cc5c40
    
    STACK_TEXT:  
    fffff880`0355aa78 fffff800`02d11588 : 00000000`0000001e ffffffff`c0000005 fffff800`02fbea9a 00000000`00000001 : nt!KeBugCheckEx
    fffff880`0355aa80 fffff800`02cc52c2 : fffff880`0355b258 00000000`00000000 fffff880`0355b300 fffffa80`02407680 : nt! ?? ::FNODOBFM::`string'+0x4977d
    fffff880`0355b120 fffff800`02cc3e3a : 00000000`00000001 00000000`00000018 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
    fffff880`0355b300 fffff800`02fbea9a : fffff880`00000000 fffff880`0355b4e0 fffffa80`030a3b30 fffff8a0`0d00f720 : nt!KiPageFault+0x23a
    fffff880`0355b490 fffff800`02fb027e : fffffa80`00000000 fffff8a0`0d00f720 fffff8a0`000f001f 00000000`00000000 : nt!ObpCreateHandle+0x29a
    fffff880`0355b5a0 fffff800`02fa1623 : fffffa80`05c3cd70 fffff880`0355b960 fffffa80`02731ad0 00000000`08000000 : nt!ObInsertObjectEx+0xde
    fffff880`0355b7f0 fffff800`02cc4ed3 : fffffa80`02407680 fffff880`0355ba98 fffff880`0355b888 fffffa80`06502010 : nt!NtCreateSection+0x1fe
    fffff880`0355b870 fffff800`02cc1470 : fffffa80`054c9a76 fffff880`0355bb80 00000000`00000000 fffffa80`054cd250 : nt!KiSystemServiceCopyEnd+0x13
    fffff880`0355ba78 fffffa80`054c9a76 : fffff880`0355bb80 00000000`00000000 fffffa80`054cd250 fffffa80`054d0540 : nt!KiServiceLinkage
    fffff880`0355ba80 fffff880`0355bb80 : 00000000`00000000 fffffa80`054cd250 fffffa80`054d0540 fffffa80`00000002 : 0xfffffa80`054c9a76
    fffff880`0355ba88 00000000`00000000 : fffffa80`054cd250 fffffa80`054d0540 fffffa80`00000002 00000000`08000000 : 0xfffff880`0355bb80
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt!ObpCreateHandle+29a
    fffff800`02fbea9a f0480fba6f1800  lock bts qword ptr [rdi+18h],0
    
    SYMBOL_STACK_INDEX:  4
    
    SYMBOL_NAME:  nt!ObpCreateHandle+29a
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4e02aaa3
    
    FAILURE_BUCKET_ID:  X64_0x1E_nt!ObpCreateHandle+29a
    
    BUCKET_ID:  X64_0x1E_nt!ObpCreateHandle+29a
    
    Followup: MachineOwner
    ---------
    Your tablet/pen touch driver is still in need of updating.
    Code:
    wacommousefilter	fffff880`04936000	fffff880`0493e000	Fri Feb 16 11:12:17 2007 (45d5f401)	00005ace		wacommousefilter.sys
    You could also try re-installing its software in case the software has corrupted files.
      My Computer


  8. Posts : 15
    windows 7 home premium 64bit
    Thread Starter
       #18

    got another bsod today this one was different than the other ones and im not sure what to make of it
      My Computer


  9. Posts : 11,269
    Windows 7 Home Premium 64 Bit
       #19

    Code:
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    
    Loading Dump File [G:\Kingston\BSODDmpFiles\midna34704\Windows_NT6_BSOD_jcgriff2\020312-28594-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7601 (Service Pack 1) UP Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
    Machine Name:
    Kernel base = 0xfffff800`02c4f000 PsLoadedModuleList = 0xfffff800`02e94670
    Debug session time: Fri Feb  3 14:46:16.197 2012 (GMT-7)
    System Uptime: 0 days 4:57:57.836
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ....................................
    Loading User Symbols
    Loading unloaded module list
    .........
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck F7, {fffff8800319faf0, 153d98de654a, ffffeac267219ab5, 0}
    
    Probably caused by : ntkrnlmp.exe ( nt!_report_gsfailure+25 )
    
    Followup: MachineOwner
    ---------
    
    kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    DRIVER_OVERRAN_STACK_BUFFER (f7)
    A driver has overrun a stack-based buffer.  This overrun could potentially
    allow a malicious user to gain control of this machine.
    DESCRIPTION
    A driver overran a stack-based buffer (or local variable) in a way that would
    have overwritten the function's return address and jumped back to an arbitrary
    address when the function returned.  This is the classic "buffer overrun"
    hacking attack and the system has been brought down to prevent a malicious user
    from gaining complete control of it.
    Do a kb to get a stack backtrace -- the last routine on the stack before the
    buffer overrun handlers and bugcheck call is the one that overran its local
    variable(s).
    Arguments:
    Arg1: fffff8800319faf0, Actual security check cookie from the stack
    Arg2: 0000153d98de654a, Expected security check cookie
    Arg3: ffffeac267219ab5, Complement of the expected security check cookie
    Arg4: 0000000000000000, zero
    
    Debugging Details:
    ------------------
    
    
    DEFAULT_BUCKET_ID:  GS_FALSE_POSITIVE_MISSING_GSFRAME
    
    SECURITY_COOKIE:  Expected 0000153d98de654a found fffff8800319faf0
    
    CUSTOMER_CRASH_COUNT:  1
    
    BUGCHECK_STR:  0xF7
    
    PROCESS_NAME:  Pen_TouchUser.
    
    CURRENT_IRQL:  0
    
    EXCEPTION_RECORD:  fffff8800319f258 -- (.exr 0xfffff8800319f258)
    ExceptionAddress: fffff80002fc4a9a (nt!ObpCreateHandle+0x000000000000029a)
       ExceptionCode: c0000005 (Access violation)
      ExceptionFlags: 00000000
    NumberParameters: 2
       Parameter[0]: 0000000000000001
       Parameter[1]: 0000000000000018
    Attempt to write to address 0000000000000018
    
    TRAP_FRAME:  fffff8800319f300 -- (.trap 0xfffff8800319f300)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8002b9bb60
    rdx=00000000000f001f rsi=0000000000000000 rdi=0000000000000000
    rip=fffff80002fc4a9a rsp=fffff8800319f490 rbp=0000000000000000
     r8=fffff8a00eb7d560  r9=00000000000000e8 r10=0000000000000000
    r11=fffff8a00eb7d510 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei ng nz ac po nc
    nt!ObpCreateHandle+0x29a:
    fffff800`02fc4a9a f0480fba6f1800  lock bts qword ptr [rdi+18h],0 ds:00000000`00000018=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002d59e35 to fffff80002ccbc40
    
    STACK_TEXT:  
    fffff880`0319e2f8 fffff800`02d59e35 : 00000000`000000f7 fffff880`0319faf0 0000153d`98de654a ffffeac2`67219ab5 : nt!KeBugCheckEx
    fffff880`0319e300 fffff800`02d1bb47 : 00000000`00000000 fffff800`02cf79f0 fffff800`02ee8ba4 fffff800`02fa7623 : nt!_report_gsfailure+0x25
    fffff880`0319e340 fffff800`02cf74fd : fffff800`02ed4c54 fffff800`02e14f20 fffff800`02c4f000 fffff880`0319f258 : nt!_GSHandlerCheck+0x13
    fffff880`0319e370 fffff800`02cf62d5 : fffff800`02e12144 fffff880`0319e3e8 fffff880`0319f258 fffff800`02c4f000 : nt!RtlpExecuteHandlerForException+0xd
    fffff880`0319e3a0 fffff800`02d07361 : fffff880`0319f258 fffff880`0319eab0 fffff880`00000000 00000000`00000000 : nt!RtlDispatchException+0x415
    fffff880`0319ea80 fffff800`02ccb2c2 : fffff880`0319f258 00000000`00000000 fffff880`0319f300 fffffa80`02b9bb60 : nt!KiDispatchException+0x135
    fffff880`0319f120 fffff800`02cc9e3a : 00000000`00000001 00000000`00000018 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
    fffff880`0319f300 fffff800`02fc4a9a : fffff880`00000000 fffff880`0319f4e0 fffffa80`02feeb30 fffff8a0`0eb7d560 : nt!KiPageFault+0x23a
    fffff880`0319f490 fffff800`02fb627e : fffffa80`00000000 fffff8a0`0eb7d560 fffff8a0`000f001f 00000000`00000000 : nt!ObpCreateHandle+0x29a
    fffff880`0319f5a0 fffff800`02fa7623 : fffffa80`029953c0 fffff880`0319f960 fffffa80`078c9250 00000000`08000000 : nt!ObInsertObjectEx+0xde
    fffff880`0319f7f0 fffff800`02ccaed3 : fffffa80`02b9bb60 fffff880`0319fa98 fffff880`0319f888 fffffa80`02b19860 : nt!NtCreateSection+0x1fe
    fffff880`0319f870 fffff800`02cc7470 : fffffa80`0548da76 fffff880`0319fb80 00000000`00000000 fffffa80`05491250 : nt!KiSystemServiceCopyEnd+0x13
    fffff880`0319fa78 fffffa80`0548da76 : fffff880`0319fb80 00000000`00000000 fffffa80`05491250 fffffa80`05494540 : nt!KiServiceLinkage
    fffff880`0319fa80 fffff880`0319fb80 : 00000000`00000000 fffffa80`05491250 fffffa80`05494540 fffffa80`00000002 : 0xfffffa80`0548da76
    fffff880`0319fa88 00000000`00000000 : fffffa80`05491250 fffffa80`05494540 fffffa80`00000002 00000000`08000000 : 0xfffff880`0319fb80
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt!_report_gsfailure+25
    fffff800`02d59e35 cc              int     3
    
    SYMBOL_STACK_INDEX:  1
    
    SYMBOL_NAME:  nt!_report_gsfailure+25
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4e02aaa3
    
    FAILURE_BUCKET_ID:  X64_0xF7_MISSING_GSFRAME_nt!_report_gsfailure+25
    
    BUCKET_ID:  X64_0xF7_MISSING_GSFRAME_nt!_report_gsfailure+25
    
    Followup: MachineOwner
    ---------
    PROCESS_NAME: Pen_TouchUser.

    Did you re-install the pen software? I am wondering if this continues to be blamed just because it is always on... Might have to try other steps.
      My Computer


  10. Posts : 15
    windows 7 home premium 64bit
    Thread Starter
       #20

    i did reinstall it
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:02.
Find Us