random bsod

dbaic

New member
i had 3 bsod's today, im using windows 7 64 bit
2 of them were caused by ntoskrnl.exe, 1 was caused by atapi.sys
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
Hello there!

Seems like the crashes all are generic so we have to start with basics. Run Hardware Diagnostic (RAM, GPU and Hard drive) : Hardware Diagnostic | Captain Debugger

Download a update version of Network drivers and Remove you Network drivers and install the new one.

Uninstall Sophos Anti-Rootkit and Spybot and install Microsoft Security essentials. Use Malwarebytes and run a complete scan. Then run SFC SCANNOW to make sure all the OS files are intact.


Code:
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002f95fda, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000000000018, Parameter 1 of the exception

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP: 
nt!ObpCreateHandle+29a
fffff800`02f95fda f0480fba6f1800  lock bts qword ptr [rdi+18h],0

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  0000000000000018

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ece0e8
 0000000000000018 

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x1E

PROCESS_NAME:  chrome.exe

CURRENT_IRQL:  0

TRAP_FRAME:  fffff88002ff5340 -- (.trap 0xfffff88002ff5340)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa80036de680
rdx=00000000000f001f rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002f95fda rsp=fffff88002ff54d0 rbp=0000000000000000
 r8=fffff8a009ef9670  r9=00000000000000e8 r10=0000000000000000
r11=fffff8a009ef9620 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz ac po nc
nt!ObpCreateHandle+0x29a:
fffff800`02f95fda f0480fba6f1800  lock bts qword ptr [rdi+18h],0 ds:00000000`00000018=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002ce9028 to fffff80002c9d640

STACK_TEXT:  
fffff880`02ff4ab8 fffff800`02ce9028 : 00000000`0000001e ffffffff`c0000005 fffff800`02f95fda 00000000`00000001 : nt!KeBugCheckEx
fffff880`02ff4ac0 fffff800`02c9ccc2 : fffff880`02ff5298 00000000`00000000 fffff880`02ff5340 fffffa80`036de680 : nt! ?? ::FNODOBFM::`string'+0x4987d
fffff880`02ff5160 fffff800`02c9b83a : 00000000`00000001 00000000`00000018 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`02ff5340 fffff800`02f95fda : fffff880`00000000 fffff880`02ff5520 fffffa80`03aceb30 fffff8a0`09ef9670 : nt!KiPageFault+0x23a
fffff880`02ff54d0 fffff800`02f877ce : fffffa80`00000000 fffff8a0`09ef9670 fffff8a0`000f001f 00000000`00000000 : nt!ObpCreateHandle+0x29a
fffff880`02ff55e0 fffff800`02f78baf : fffffa80`06404d10 fffff880`02ff59a0 fffffa80`06c39190 00000000`08000000 : nt!ObInsertObjectEx+0xde
fffff880`02ff5830 fffff800`02c9c8d3 : fffffa80`036de680 fffff880`02ff5ad8 fffff880`02ff58c8 fffffa80`04a42970 : nt!NtCreateSection+0x1fe
fffff880`02ff58b0 fffff800`02c98e70 : fffffa80`045fbb72 fffff880`02ff5bc0 00000000`00000000 fffffa80`04600250 : nt!KiSystemServiceCopyEnd+0x13
fffff880`02ff5ab8 fffffa80`045fbb72 : fffff880`02ff5bc0 00000000`00000000 fffffa80`04600250 fffffa80`046045d0 : nt!KiServiceLinkage
fffff880`02ff5ac0 fffff880`02ff5bc0 : 00000000`00000000 fffffa80`04600250 fffffa80`046045d0 fffffa80`00000002 : 0xfffffa80`045fbb72
fffff880`02ff5ac8 00000000`00000000 : fffffa80`04600250 fffffa80`046045d0 fffffa80`00000002 00000000`08000000 : 0xfffff880`02ff5bc0


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!ObpCreateHandle+29a
fffff800`02f95fda f0480fba6f1800  lock bts qword ptr [rdi+18h],0

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  nt!ObpCreateHandle+29a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

FAILURE_BUCKET_ID:  X64_0x1E_nt!ObpCreateHandle+29a

BUCKET_ID:  X64_0x1E_nt!ObpCreateHandle+29a

Followup: MachineOwner
---------
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
thanks for the reply

i ran hardware diagnostic and sfc scannnow, there were no problems.
all drivers are updated
i removed anti rootkit and spybot.
i ran malwarebytes before and it removed all threats
microsoft security essentials also removed all threats, but every 5 minutes it detects and removes win32/coinminer
here is screenshot
i1dtnm.png
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
coinminer may be an trojan, its for generating bitcoins. If you dont know know anything about bitcoins im pretty sure someone uses your pc to generate coins for them. Update virusscanner security patches for ie flash windows firefox etc and try mcaffee stinger and spybot search and destroy.
 

My Computer

OS
windows 7 Ultimate x64
CPU
AMD Phenom X6 Black Edition
Motherboard
Aus Crosshair 4 Formula
Memory
16gb Kingston
Graphics Card(s)
Powercolor ATI 6870 HD X2
Sound Card
Onboard, Xfi chip
Monitor(s) Displays
Viewsonic VA2626wm
Hard Drives
Corsair Force 129 GB ssd
Case
Sharkoon Rebel

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
im writing from another computer, i followed that article and after restart i cant get into windows, it says: DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
im writing from another computer, i followed that article and after restart i cant get into windows, it says: DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER

Go into your BIOS and check the boot order make sure your Hard disk is choosed as primary boot device. Unplug the USB devices while booting.
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
i did that and it doesnt work. should i try to use recovery disk?
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
Disk boot failure may be related to driver verifier.

You 'll want to boot the DVD Repair console or System Repair CD, accept any offered repair.

If this fails to start Win7, boot back into DVD/CD System Recovery Options
run System Restore to before Driver Verifier was enabled.

If this fail, run Startup Repair repeatedly, report back results.
 
startup repair fixed the problem, but my D partition is gone, i had a lot of data there, how can i get it back?
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
Boot free Partition Wizard bootable CD, rightclick on D to Explore for files.

If there is no partition remaining or files are missing from within one, run the Partition Recovery Wizard from the Wizards tab on the HD. It will scan and find any missing partitions which have not been secure erased. You can then select the correct missing partition and it will reinstate it if possible.

If this fails which is rare next run Recuva data recovery: Recuva - Features

There is no way the missing partition could be caused by running Startup Repair, but it could be caused by infection which may still exist on HD. For this reason, I would first install, update and run a full scan using Malwarebytes, in Safe Mode if necessary.

If for some reason it doesn't run download and burn to CD or write to flash stick Microsoft Standalone System Sweeper, boot it, allow it to update via wired connection then scan the HD.

If infection isn't responsible, then you can continue troubleshooting your BSOD where you left off. Set a Restore Point recoverable via DVD/Repair console before each step.
 
thanks, i got partition back, now back to bsod, here is the latest dump file
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
Back up your files now, wait for Captain Jack to continue with BSOD troubleshooting as I'm an Installer called in to consult by him and not a BSOD specialist.

Have you completed the steps he gave in the beginning yet?
 
yes i did everything
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel E8400 3.0 ghz
Motherboard
Gygabite GA-EP31-DS3L
Memory
2x2gb Kingston DDR2-800
Graphics Card(s)
Gygabite Nvidia 9600GT
Hard Drives
WD 400 GB
PSU
Xilence 500w
Mouse
Logitech MX518 Gaming Grade
Thanks for helping out Greg!

Seems like the crash is pointing to HIDCLASS.SYS which is related to your USB driver related files. Do you have any USB devices connected to your machine? If so reinstall the drivers. Try to disconnect the device and see if it crash. It includes external HDD, USB drive, USB Mouse, USB Keyboard, Gaming Pad etc.

Also refer your Motherboard Manual and RAM manually and check the RAM timings in the BIOS make sure it's set correctly.

Code:
DRIVER_VERIFIER_IOMANAGER_VIOLATION (c9)
The IO manager has caught a misbehaving driver.
Arguments:
Arg1: 000000000000023b, The caller has changed the status field of an IRP it does not understand.
Arg2: fffff88004e1c710, The address in the driver's code where the error was detected.
Arg3: fffff9800fa10dc0, IRP address.
Arg4: 0000000000000000

Debugging Details:
------------------


BUGCHECK_STR:  0xc9_23b

DRIVER_VERIFIER_IO_VIOLATION_TYPE:  23b

FAULTING_IP: 
HIDCLASS!HidpMajorHandler+0
fffff880`04e1c710 48895c2410      mov     qword ptr [rsp+10h],rbx

FOLLOWUP_IP: 
HIDCLASS!HidpMajorHandler+0
fffff880`04e1c710 48895c2410      mov     qword ptr [rsp+10h],rbx

IRP_ADDRESS:  fffff9800fa10dc0

DEVICE_OBJECT: fffffa80071e6b80

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VERIFIER_ENABLED_VISTA_MINIDUMP

PROCESS_NAME:  System

CURRENT_IRQL:  2

LOCK_ADDRESS:  fffff80002e8b440 -- (!locks fffff80002e8b440)

Resource @ nt!PiEngineLock (0xfffff80002e8b440)    Available

WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.


WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.

1 total locks

PNP_TRIAGE: 
    Lock address  : 0xfffff80002e8b440
    Thread Count  : 0
    Thread address: 0x0000000000000000
    Thread wait   : 0x0

LAST_CONTROL_TRANSFER:  from fffff800031163dc to fffff80002c8f640

STACK_TEXT:  
fffff880`031fd0f8 fffff800`031163dc : 00000000`000000c9 00000000`0000023b fffff880`04e1c710 fffff980`0fa10dc0 : nt!KeBugCheckEx
fffff880`031fd100 fffff800`0312047a : fffff800`031149f0 fffff880`04e1c710 fffff980`0fa10dc0 00000000`00000000 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`031fd140 fffff800`03121483 : 00000000`0000023b 00000000`c0000010 fffff980`0fa10dc0 00000000`ffffffff : nt!ViErrorFinishReport+0xda
fffff880`031fd190 fffff800`03121b42 : fffff980`0fa10f20 fffff880`04e1c710 00000000`00000000 00000000`000001f1 : nt!VfErrorReport1+0x63
fffff880`031fd230 fffff800`03116071 : fffffa80`05c47788 00000000`00000001 00000000`00000000 fffff980`0fa10f20 : nt!ViGenericVerifyIrpStackUpward+0x62
fffff880`031fd260 fffff800`03122b2d : fffffa80`07144680 fffffa80`05c475d0 fffff980`0fa10dc0 fffff980`0fa10dc0 : nt!VfMajorVerifyIrpStackUpward+0x91
fffff880`031fd2a0 fffff800`0313450d : fffff980`0fa10f20 fffff880`031fd480 00000000`c0000010 fffff980`0fa10f20 : nt!IovpCompleteRequest2+0xad
fffff880`031fd310 fffff800`02c92a91 : fffff980`0fa10f23 fffff800`00000000 00000000`000000ff fffff880`00000005 : nt!IovpLocalCompletionRoutine+0x9d
fffff880`031fd370 fffff800`0312c19f : fffff980`0fa10dc0 fffff880`04e26400 fffffa80`071e6c00 00000000`00000000 : nt!IopfCompleteRequest+0x3b1
fffff880`031fd450 fffff800`02c751ea : fffff880`00000013 fffff880`031fd578 fffff980`0fa10f20 fffffa80`071e6cd0 : nt!IovCompleteRequest+0x19f
fffff880`031fd520 fffff880`04e1ca0f : 00000000`00000000 fffffa80`071e6cd0 00000000`00000001 00000000`00000017 : nt!IopInvalidDeviceRequest+0x16
fffff880`031fd550 fffff880`04e1c7fb : 00000000`00000000 fffffa80`071e6cd0 fffff980`0fa10dc0 fffff880`031fd600 : HIDCLASS!HidpIrpMajorDefault+0x8b
fffff880`031fd590 fffff800`03132c16 : fffff980`00000002 fffff980`0fa10dc0 00000000`00000002 fffff800`0312e37e : HIDCLASS!HidpMajorHandler+0xeb
fffff880`031fd600 fffff800`03131c42 : fffff980`0fa10f68 00000000`00000002 fffffa80`071e6a70 fffffa80`067e6e00 : nt!IovCallDriver+0x566
fffff880`031fd660 fffff800`03132c16 : fffff980`0fa10dc0 00000000`00000002 fffffa80`071e6920 00000000`00000000 : nt!ViFilterDispatchGeneric+0x62
fffff880`031fd690 fffff800`03131d58 : fffff980`0fa10dc0 fffffa80`071e6920 00000000`00000000 fffffa80`06eb6810 : nt!IovCallDriver+0x566
fffff880`031fd6f0 fffff800`03131e42 : fffffa80`071eda60 fffffa80`03758010 fffffa80`071eda60 00000000`00000017 : nt!VfIrpSendSynchronousIrp+0xe8
fffff880`031fd760 fffff800`0311efaf : fffffa80`071ee010 00000000`000007ff fffff800`02dc55b8 fffff800`03022ca9 : nt!VfWmiTestStartedPdoStack+0x72
fffff880`031fd800 fffff800`02d38c92 : fffffa80`071ee010 00000000`00000000 00000000`00000000 00000000`00000000 : nt!VfMajorTestStartedPdoStack+0x5f
fffff880`031fd830 fffff800`0307726c : fffffa80`071ee010 fffffa80`03758010 00000000`00000001 00000000`00000000 : nt!PpvUtilTestStartedPdoStack+0x12
fffff880`031fd860 fffff800`03078e64 : fffffa80`071ee010 fffffa80`071ee010 fffffa80`03758010 00000000`00000001 : nt!PipProcessStartPhase3+0x55c
fffff880`031fd950 fffff800`03079428 : fffff800`02e88dc0 00000000`00000000 00000000`00000010 fffff800`03079390 : nt!PipProcessDevNodeTree+0x264
fffff880`031fdbc0 fffff800`02d88b97 : 00000001`00000003 00000000`00000000 00000000`00000001 00000000`00000000 : nt!PiProcessReenumeration+0x98
fffff880`031fdc10 fffff800`02c99a21 : fffff800`02d88870 fffffa80`03727001 00000000`00000000 fffffa80`00000657 : nt!PnpDeviceActionWorker+0x327
fffff880`031fdcb0 fffff800`02f2ccce : 00000000`00000000 fffffa80`03727040 00000000`00000080 fffffa80`03709040 : nt!ExpWorkerThread+0x111
fffff880`031fdd40 fffff800`02c80fe6 : fffff880`009e5180 fffffa80`03727040 fffff880`009eff40 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`031fdd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16


STACK_COMMAND:  .bugcheck ; kb

SYMBOL_NAME:  HIDCLASS!HidpMajorHandler+0

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: HIDCLASS

IMAGE_NAME:  HIDCLASS.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7a665

FAILURE_BUCKET_ID:  X64_0xc9_23b_VRF_HIDCLASS!HidpMajorHandler+0

BUCKET_ID:  X64_0xc9_23b_VRF_HIDCLASS!HidpMajorHandler+0

Followup: MachineOwner
---------
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
Back
Top