Logoff causes restart

Page 1 of 3 123 LastLast

  1. Posts : 14
    Windows 7 Professional 64 bit
       #1

    Logoff causes restart


    Wheneven I logoff of the system it does a restart. I have tried it with no programs loaded and all services turned off but the same thing happens.

    The only indication I get from the event log is "The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff80002d2481f, 0xfffff8800207f880, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP.

    Thanks for any help
    Last edited by tecinc; 08 Jul 2011 at 08:08. Reason: Uploaded files
      My Computer


  2. Posts : 1,808
    Windows 7 64b Ultimate
       #2

    Hello tecinc, welcome to SF!

    A 3b could mean a lot of thngs... could you please upload your info as per these instructions? There a some experts at looking into crashes here.... but they need the right information to do so...
    https://www.sevenforums.com/crashes-d...tructions.html
      My Computer


  3. Posts : 14
    Windows 7 Professional 64 bit
    Thread Starter
       #3

    Thanks:

    I think I did it right. If not please let me know.
      My Computer


  4. Posts : 1,808
    Windows 7 64b Ultimate
       #4

    You did fine, thanks...
    You have many dmp files and a lot going on... it'll take some time to look at them...

    Your last dmp points to csrss.sys which should be a normal windows driver. However, sometimes it is misused by malware and what worries me is you have two csrss processes going on... I'll have to check with others here to see what they think about that....

    Meanwhile it wouldn't hurt to do a full system scan of your AV with updated info and perform a Malware check: Malwarebytes : Free anti-malware, anti-virus and spyware removal download

    HTML Code:
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff80002d2481f, Address of the instruction which caused the bugcheck
    Arg3: fffff8800207f880, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - De instructie op 0x%08lx verwijst naar geheugen op 0x%08lx. Een lees- of schrijfbewerking op het geheugen is mislukt: %s.
    
    FAULTING_IP: 
    nt!MiUnsecureVirtualMemory+15f
    fffff800`02d2481f 488b0f          mov     rcx,qword ptr [rdi]
    
    CONTEXT:  fffff8800207f880 -- (.cxr 0xfffff8800207f880)
    rax=0000000000000001 rbx=fffffa80058f0b60 rcx=0000000000000000
    rdx=0000000000000000 rsi=fffffa8005838b30 rdi=0000000000000000
    rip=fffff80002d2481f rsp=fffff88002080260 rbp=0000000022050768
     r8=0000000000000070  r9=0000000000000000 r10=0000000000000000
    r11=fffff8800207fd40 r12=fffffa8005838d48 r13=0000000000000000
    r14=0000000000000001 r15=0000000000000000
    iopl=0         nv up ei pl zr na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
    nt!MiUnsecureVirtualMemory+0x15f:
    fffff800`02d2481f 488b0f          mov     rcx,qword ptr [rdi] ds:002b:00000000`00000000=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x3B
    
    PROCESS_NAME:  csrss.exe
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff80002d2481f
    
    STACK_TEXT:  
    fffff880`02080260 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiUnsecureVirtualMemory+0x15f
    
    
    FOLLOWUP_IP: 
    nt!MiUnsecureVirtualMemory+15f
    fffff800`02d2481f 488b0f          mov     rcx,qword ptr [rdi]
    
    SYMBOL_STACK_INDEX:  0
    
    SYMBOL_NAME:  nt!MiUnsecureVirtualMemory+15f
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4d9fdd5b
    
    STACK_COMMAND:  .cxr 0xfffff8800207f880 ; kb
    
    IMAGE_NAME:  memory_corruption
    
    FAILURE_BUCKET_ID:  X64_0x3B_nt!MiUnsecureVirtualMemory+15f
    
    BUCKET_ID:  X64_0x3B_nt!MiUnsecureVirtualMemory+15f
    
    Followup: MachineOwner
    ---------
    
    2: kd> lmvm nt
    start             end                 module name
    fffff800`02a03000 fffff800`02fec000   nt         (pdb symbols)          c:\symcache\ntkrnlmp.pdb\962458112DE04DEBBFB6761B710924452\ntkrnlmp.pdb
        Loaded symbol image file: ntkrnlmp.exe
        Mapped memory image file: c:\symcache\ntoskrnl.exe\4D9FDD5B5e9000\ntoskrnl.exe
        Image path: ntkrnlmp.exe
        Image name: ntkrnlmp.exe
        Timestamp:        Sat Apr 09 06:15:23 2011 (4D9FDD5B)
        CheckSum:         0054E319
        ImageSize:        005E9000
        File version:     6.1.7601.17592
        Product version:  6.1.7601.17592
        File flags:       0 (Mask 3F)
        File OS:          40004 NT Win32
        File type:        1.0 App
        File date:        00000000.00000000
        Translations:     0409.04b0
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     ntkrnlmp.exe
        OriginalFilename: ntkrnlmp.exe
        ProductVersion:   6.1.7601.17592
        FileVersion:      6.1.7601.17592 (win7sp1_gdr.110408-1631)
        FileDescription:  NT Kernel & System
        LegalCopyright:   © Microsoft Corporation. All rights reserved.
      My Computer


  5. Posts : 14
    Windows 7 Professional 64 bit
    Thread Starter
       #5

    Will do thanks. I am running Microsoft Essentials and Spy bot but will try the one you recommend also.

    Thanks
      My Computer


  6. Posts : 1,808
    Windows 7 64b Ultimate
       #6

    tecinc said:
    Will do thanks. I am running Microsoft Essentials and Spy bot but will try the one you recommend also.

    Thanks
    Could it be that your also running windows defender? I see a lot of MpTelemetry faults (bsods). Normally, Id expect Defender to be off if you use MSE...
    Please check that Defender is off, if it isn't please de-install MSE and reinstall it from Microsoft and then check Defender is off as it should be?
      My Computer


  7. Posts : 14
    Windows 7 Professional 64 bit
    Thread Starter
       #7

    I am not using defender to my knowledge. Doesn't show up anywhere that I can see. I ran ARO and it didn't find any security issues.

    Thanks
      My Computer


  8. Posts : 1,808
    Windows 7 64b Ultimate
       #8

    tecinc said:
    I am not using defender to my knowledge. Doesn't show up anywhere that I can see. I ran ARO and it didn't find any security issues.

    Thanks
    I'd follow that advise anyway... for sure MpTelemetry is causing problems:

    Attachment 163873
      My Computer


  9. Posts : 14
    Windows 7 Professional 64 bit
    Thread Starter
       #9

    OK, I'm not real clear on how I check to see that defender is off.

    Thanks
      My Computer


  10. Posts : 1,808
    Windows 7 64b Ultimate
       #10

    tecinc said:
    OK, I'm not real clear on how I check to see that defender is off.

    Thanks
    You should be able to see it in Action Center: Action Center - Change Message Settings

    If it is off there... then maybe soemthing in MSE is corrupted, please de-install and dowlnoad the latest to re-install anyway...
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:12.
Find Us