New
#1
BSOD 0x0000000A
BSOD 0x0000000A
Constantly getting this on a machine
CPU: Q6600
RAM 2GB
VGA - Nvidia 8400GS
MB: foxconn G31Mx-K
Win 7
Any one able to help?
BSOD 0x0000000A
Constantly getting this on a machine
CPU: Q6600
RAM 2GB
VGA - Nvidia 8400GS
MB: foxconn G31Mx-K
Win 7
Any one able to help?
Hi and welcome
I took a look at 3 of the dumps. They all point to mfehidk.sys. It is a part of the Macaffee av. It is likely goven the dates on the below drivers that you should
Upgrade all the older drivers listed below. Upgrade or remove macaffe first
then I would also recommend running a system file check to verify and repair system files
type cmd in search>right click and run as admin>type SFC /SCANNOW
let us know the results
Hope this helps and if more bsod's upload them
Ken J++
mdmxsdk.sys 0x97f5d000 0x97f60180 0x00003180 0x449716a3 6/19/2006 4:26:59 PM
secdrv.SYS 0x97e00000 0x97e0a000 0x0000a000 0x45080528 9/13/2006 8:18:32 AM
PxHelp20.sys 0x88a00000 0x88a08de0 0x00008de0 0x4679a978 6/20/2007 5:26:00 PM
RTKVHDA.sys 0x81e25000 0x81ffdc40 0x001d8c40 0x46bbfc51 8/10/2007 12:49:05 AM
irsir.sys 0x8e745000 0x8e750000 0x0000b000 0x479190c9 1/19/2008 12:55:21 AM
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\111309-30669-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*Symbol information
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x82e51000 PsLoadedModuleList = 0x82f99810
Debug session time: Fri Nov 13 02:30:38.592 2009 (GMT-5)
System Uptime: 0 days 0:07:35.278
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {8154, 2, 1, 82ee0791}
*** WARNING: Unable to verify timestamp for mfehidk.sys
*** ERROR: Module load completed but symbols could not be loaded for mfehidk.sys
Probably caused by : mfehidk.sys ( mfehidk+1c194 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00008154, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 82ee0791, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from 82fb9718
Unable to read MiSystemVaType memory at 82f99160
00008154
CURRENT_IRQL: 2
FAULTING_IP:
nt!CcFlushCache+a6
82ee0791 ff8654010000 inc dword ptr [esi+154h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: mcods.exe
TRAP_FRAME: aafd980c -- (.trap 0xffffffffaafd980c)
ErrCode = 00000002
eax=00000000 ebx=00000005 ecx=84d52fa8 edx=00000000 esi=00008000 edi=aafd992c
eip=82ee0791 esp=aafd9880 ebp=aafd9904 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!CcFlushCache+0xa6:
82ee0791 ff8654010000 inc dword ptr [esi+154h] ds:0023:00008154=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 82ee0791 to 82e977eb
STACK_TEXT:
aafd980c 82ee0791 badb0d00 00000000 00000000 nt!KiTrap0E+0x2cf
aafd9904 88cb9f62 84d52fa8 00000000 00000000 nt!CcFlushCache+0xa6
aafd9958 88cac72c 015dc640 ad5d7d78 00000000 Ntfs!NtfsFlushUserStream+0x93
aafd99f8 88c5bc8a 875dc640 858f60d8 00000001 Ntfs!NtfsFlushVolume+0x281
aafd9a50 88c4f74b 875dc640 84df5330 858fd008 Ntfs!NtfsVolumeDasdIo+0xf2
aafd9b24 88c53bae 875dc640 84df5330 223a014c Ntfs!NtfsCommonRead+0x3ac
aafd9b94 82e8d4bc 858f6020 84df5330 84df5330 Ntfs!NtfsFsdRead+0x279
aafd9bac 889a320c 858e4ed8 84df5330 00000000 nt!IofCallDriver+0x63
aafd9bd0 889a33cb aafd9bf0 858e4ed8 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2aa
aafd9c08 82e8d4bc 858e4ed8 84df5330 84df5330 fltmgr!FltpDispatch+0xc5
aafd9c20 8e1d0194 86a64cf0 86a64cf0 858e4ed8 nt!IofCallDriver+0x63
WARNING: Stack unwind information not available. Following frames may be wrong.
aafd9c44 82e8d4bc 86a64cf0 84df5330 84df5330 mfehidk+0x1c194
aafd9c5c 8308eeee 84df5330 84df552c 84bcdac8 nt!IofCallDriver+0x63
aafd9c7c 830a0ea6 86a64cf0 84bcdac8 00000001 nt!IopSynchronousServiceTail+0x1f8
aafd9d08 82e9442a 86a64cf0 84df5330 00000000 nt!NtReadFile+0x644
aafd9d08 774164f4 86a64cf0 84df5330 00000000 nt!KiFastCallEntry+0x12a
039cebe4 00000000 00000000 00000000 00000000 0x774164f4
STACK_COMMAND: kb
FOLLOWUP_IP:
mfehidk+1c194
8e1d0194 ?? ???
SYMBOL_STACK_INDEX: b
SYMBOL_NAME: mfehidk+1c194
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: mfehidk
IMAGE_NAME: mfehidk.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a73694c
FAILURE_BUCKET_ID: 0xA_mfehidk+1c194
BUCKET_ID: 0xA_mfehidk+1c194
Followup: MachineOwner
Good luck
---------
thank you very much for your help.
I will get back to your shortly after the removal and the SFC scan.
Kind Regards,
Robbie
Hi All!
I have experienced 30 crashes with following explanation from "WhoCrashed":
On Mon 6/21/2010 11:34:36 AM your computer crashed
This was likely caused by the following module: ntoskrnl.exe
Bugcheck code: 0xA (0x48, 0x2, 0x1, 0xFFFFF80002D41A5F)
Error: IRQL_NOT_LESS_OR_EQUAL
Dump file: C:\Windows\Minidump\062110-16785-01.dmp
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit is in another driver on your system which cannot be identified at this time.
On Mon 6/21/2010 12:03:35 AM your computer crashed
This was likely caused by the following module: ntoskrnl.exe
Bugcheck code: 0xA (0x48, 0x2, 0x1, 0xFFFFF80002C6619D)
Error: IRQL_NOT_LESS_OR_EQUAL
Dump file: C:\Windows\Minidump\062110-18330-01.dmp
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit is in another driver on your system which cannot be identified at this time.
If anybody can help, I will appreciate desperately!!!
Thanks Dalibor
DELL Inspiron 1464
CPU Intel Core i5 M520 2,40GHz
4GB RAM
Windows 7, 64 bit