Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: BSOD - any time :/

09 Jul 2013   #1
TesterFromTest

Windows 7 Ultimate x64
 
 
BSOD - any time :/

Hello,

I had computer which we use for CCTV. Sometimes it has BSOD. We formated him, reinstalled all software and we add card for analog cameras.

It was still in BSOD. So we take it to our office turn it on and nothing in two days. So we take them without analog CCTV card again to gatehouse. When it start again BSOD. Restart and again.




My System SpecsSystem Spec
09 Jul 2013   #2
Capt.Jack Sparrow

Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
 
 

Hi there!

Seems like it might the drivers related to the analog CCTV card. But since the dump file didn't report it let run the Driver Verifier to conform it. Using Driver Verifier to identify issues with Drivers

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: 96c40000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 82e9dd54, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 82da084c
Unable to read MiSystemVaType memory at 82d7fe20
 96c40000 

FAULTING_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

MM_INTERNAL_CODE:  0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0x50

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

TRAP_FRAME:  9f58da0c -- (.trap 0xffffffff9f58da0c)
ErrCode = 00000000
eax=aa000000 ebx=9f58dab4 ecx=005e032d edx=ab780cb8 esi=9e9846e8 edi=954bf34c
eip=82e9dd54 esp=9f58da80 ebp=9f58da88 iopl=0         nv up ei pl nz na pe cy
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
nt!CmpGetValueListFromCache+0x95:
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4] ds:0023:96c40000=????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from 82c77a88 to 82cc4861

STACK_TEXT:  
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!CmpGetValueListFromCache+95

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  51871b70

FAILURE_BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

Followup: MachineOwner
---------

0: kd> !thread;!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck;
GetPointerFromAddress: unable to read from 82da0850
THREAD 858ba030  Cid 09b4.0898  Teb: 7ffaf000 Win32Thread: 00000000 RUNNING on processor 0
Not impersonating
GetUlongFromAddress: unable to read from 82d604dc
Owning Process            87d94be8       Image:         svchost.exe
Attached Process          N/A            Image:         N/A
ffdf0000: Unable to get shared data
Wait Start TickCount      2671194      
Context Switch Count      84651          IdealProcessor: 3             
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime                  00:00:00.000
KernelTime                00:00:00.000
Win32 Start Address 0x771d03e9
Stack Init 9f58ded0 Current 9f58d9ac Base 9f58e000 Limit 9f58b000 Call 0
Priority 8 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
ChildEBP RetAddr  Args to Child              
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc (FPO: [0,0] TrapFrame @ 9f58da0c)
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall (FPO: [0,3] TrapFrame @ 9f58dc34)
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094

*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: 96c40000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 82e9dd54, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 82da084c
Unable to read MiSystemVaType memory at 82d7fe20
 96c40000 

FAULTING_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

MM_INTERNAL_CODE:  0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0x50

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

TRAP_FRAME:  9f58da0c -- (.trap 0xffffffff9f58da0c)
ErrCode = 00000000
eax=aa000000 ebx=9f58dab4 ecx=005e032d edx=ab780cb8 esi=9e9846e8 edi=954bf34c
eip=82e9dd54 esp=9f58da80 ebp=9f58da88 iopl=0         nv up ei pl nz na pe cy
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
nt!CmpGetValueListFromCache+0x95:
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4] ds:0023:96c40000=????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from 82c77a88 to 82cc4861

STACK_TEXT:  
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!CmpGetValueListFromCache+95

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  51871b70

FAILURE_BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

Followup: MachineOwner
My System SpecsSystem Spec
10 Jul 2013   #3
TesterFromTest

Windows 7 Ultimate x64
 
 

Thanks for quick response.
Dumps are enclosed.
My System SpecsSystem Spec
10 Jul 2013   #4
Capt.Jack Sparrow

Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
 
 

Hi there!

Yes we guessed correct it's CapSV.sys i.e. Capture card driver. Uninstall the drivers completely How to Uninstall Drivers in Windows | PCWorld and reboot and try to install it again. See if you can get an updated version of the drivers.

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_VERIFIER_IOMANAGER_VIOLATION (c9)
The IO manager has caught a misbehaving driver.
Arguments:
Arg1: 0000021f, A driver has not filled out a dispatch routine for a required IRP major function.
Arg2: 8d4952a0, The address in the driver's code where the error was detected.
Arg3: 935a6f00, IRP address.
Arg4: 00000000

Debugging Details:
------------------


BUGCHECK_STR:  0xc9_21f

DRIVER_VERIFIER_IO_VIOLATION_TYPE:  21f

FAULTING_IP: 
CapSV+382a0
8d4952a0 6a00            push    0

FOLLOWUP_IP: 
CapSV+382a0
8d4952a0 6a00            push    0

IRP_ADDRESS:  935a6f00

DEVICE_OBJECT: 8c1880b8

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VERIFIER_ENABLED_VISTA_MINIDUMP

PROCESS_NAME:  System

CURRENT_IRQL:  2

LOCK_ADDRESS:  82d6dbe0 -- (!locks 82d6dbe0)

Resource @ nt!PiEngineLock (0x82d6dbe0)    Available

WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.


WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.

1 total locks

PNP_TRIAGE: 
	Lock address  : 0x82d6dbe0
	Thread Count  : 0
	Thread address: 0x00000000
	Thread wait   : 0x0

LAST_CONTROL_TRANSFER:  from 82f3df03 to 82ce5bf0

STACK_TEXT:  
881856dc 82f3df03 000000c9 0000021f 8d4952a0 nt!KeBugCheckEx+0x1e
881856fc 82f402cd 8d4952a0 88185734 8d4952a0 nt!VerifierBugCheckIfAppropriate+0x30
88185714 82f4032a 0000021f 8d4952a0 00000000 nt!ViErrorFinishReport+0xc9
88185768 82f473f0 0000021f 935a6f00 935a6fb8 nt!VfErrorReport1+0x4d
88185784 82f3fedb 935a6fdc 935a6fb8 8b1fb170 nt!VfWmiVerifyIrpStackDownward+0x4d
881857a0 82f3e426 8c1a2948 8c0a0dc8 935a6fdc nt!VfMajorVerifyIrpStackDownward+0x3e
88185804 82f3dd33 8c03f910 935a6f00 88185834 nt!IovpCallDriver1+0x468
88185814 82f38670 8c0a0dc8 935a6fd4 8c0a0dc8 nt!VfBeforeCallDriver+0xe7
88185834 82c3dbd5 935a6fb8 935a6ff8 8c0a0dc8 nt!IovCallDriver+0x206
88185848 82f4a4d0 8adaef90 935a6f00 8c1880b8 nt!IofCallDriver+0x1b
88185860 82f386c3 8c188170 935a6f00 935a7000 nt!ViFilterDispatchGeneric+0x5e
88185884 82c3dbd5 00000000 8818590c 8c1880b8 nt!IovCallDriver+0x258
88185898 82f3dbcc 00000004 00000017 00000000 nt!IofCallDriver+0x1b
881858c4 82f474f7 8a878b58 881858e8 00000001 nt!VfIrpSendSynchronousIrp+0xa5
88185910 82f4011f 8a86f880 8818599c 82db87f5 nt!VfWmiTestStartedPdoStack+0x48
8818591c 82db87f5 8a878b58 8a86f880 00000000 nt!VfMajorTestStartedPdoStack+0x48
8818599c 82dc4057 00000001 00000000 8b9d5d00 nt!PipProcessStartPhase3+0x427
88185b94 82d8fe62 86fb6700 8b9d5d00 88185bc8 nt!PipProcessDevNodeTree+0x2e6
88185bd4 82c1bd09 8b9d5d00 82d6bb00 86e68d48 nt!PiProcessStartSystemDevices+0x6d
88185c00 82c840fb 00000000 00000000 86e68d48 nt!PnpDeviceActionWorker+0x241
88185c50 82e1012f 00000001 a5166ff8 00000000 nt!ExpWorkerThread+0x10d
88185c90 82cb7559 82c83fee 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


STACK_COMMAND:  .bugcheck ; kb

SYMBOL_NAME:  CapSV+382a0

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: CapSV

IMAGE_NAME:  CapSV.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4b0244c3

FAILURE_BUCKET_ID:  0xc9_21f_VRF_CapSV+382a0

BUCKET_ID:  0xc9_21f_VRF_CapSV+382a0

Followup: MachineOwner
---------

3: kd> lmvm CapSV
start    end        module name
8d45d000 8d4d4c00   CapSV    T (no symbols)           
    Loaded symbol image file: CapSV.sys
    Image path: \SystemRoot\system32\drivers\CapSV.sys
    Image name: CapSV.sys
    Timestamp:        Tue Nov 17 12:07:55 2009 (4B0244C3)
    CheckSum:         0007E10B
    ImageSize:        00077C00
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
My System SpecsSystem Spec
10 Jul 2013   #5
TesterFromTest

Windows 7 Ultimate x64
 
 

I've contacted with driver producer. They add this driver to instalation software.

I uninstalled the driver and did the repair install windows during which he informed me that he could not confirm the source of the driver.

After installing the Driver Verifier done again BSOD appeared.
I attach the dump.
My System SpecsSystem Spec
10 Jul 2013   #6
Capt.Jack Sparrow

Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
 
 

Quote   Quote: Originally Posted by TesterFromTest View Post
I've contacted with driver producer. They add this driver to instalation software.

I uninstalled the driver and did the repair install windows during which he informed me that he could not confirm the source of the driver.

After installing the Driver Verifier done again BSOD appeared.
I attach the dump.
Sorry it's showing the same drivers again. Once you reinstall the driver disable the Driver Verifier

Code:
BugCheck C9, {21f, 8ce8f2a0, 8f992f00, 0}

Unable to load image \SystemRoot\system32\drivers\CapSV.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for CapSV.sys
*** ERROR: Module load completed but symbols could not be loaded for CapSV.sys
Probably caused by : CapSV.sys ( CapSV+382a0 )
My System SpecsSystem Spec
Reply

 BSOD - any time :/




Thread Tools




Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 08:34 AM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App