New
#1
BSOD on Windows7 2-3 times per week
I am getting BSOD at various times. Sometimes at start-up from sleep and other times just using internet. Any help will be very appreciated. Attached mini dump file:
I am getting BSOD at various times. Sometimes at start-up from sleep and other times just using internet. Any help will be very appreciated. Attached mini dump file:
The problem file seems to be "Probably caused by : fltmgr.sys ( fltmgr!TreeUnlinkNoBalance+6 "
From what I have read it's a windows file but the cause is mostly blamed on symantic or Norton. I'am not sure if you are running Norton or not but the fix seems to be delating the old Norton version and installing the new one.
Hi matt and welcome
this dmp was probably caused by fltmgr.sys. it is a legacy driver form vista. I would suspect you did not do a clean install
I would
Run system file check to verify and repair your system files. to do so type cmd in search>right click and run as admin> SFC /SCANNOW
Let us know the results as you may nee to run it more than once.
other things
If you are overclocking stop
if you have a raid update its driver
If your are the cautious type downlaod and run memtestx86 for at least several hours as i suspect some memory/heat issues.
As usual if you get more crashes upload the dmp files to us.
Hope this helps
Ken J++
Code:Microsoft (R) Windows Debugger Version 6.11.0001.404 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\K\Desktop\120609-27003-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*d:\symbols*Symbol information Executable search path is: Windows 7 Kernel Version 7600 MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 7600.16385.amd64fre.win7_rtm.090713-1255 Machine Name: Kernel base = 0xfffff800`02e5f000 PsLoadedModuleList = 0xfffff800`0309ce50 Debug session time: Sun Dec 6 16:18:44.912 2009 (GMT-5) System Uptime: 0 days 0:13:01.206 Loading Kernel Symbols ............................................................... ................................................................ ...................................... Loading User Symbols Loading unloaded module list ....... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff88001092366, fffff8800ab94e10, 0} Probably caused by : fltmgr.sys ( fltmgr!TreeUnlinkNoBalance+6 ) Followup: MachineOwner --------- 3: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff88001092366, Address of the exception record for the exception that caused the bugcheck Arg3: fffff8800ab94e10, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. FAULTING_IP: fltmgr!TreeUnlinkNoBalance+6 fffff880`01092366 488b5118 mov rdx,qword ptr [rcx+18h] CONTEXT: fffff8800ab94e10 -- (.cxr 0xfffff8800ab94e10) rax=fffffa80047a7b60 rbx=0800000000000000 rcx=0800000000000000 rdx=ffffffffffffffff rsi=fffffa8008c6b330 rdi=0000000000000000 rip=fffff88001092366 rsp=fffff8800ab957f0 rbp=fffffa8008c6b338 r8=ffffffffffffffff r9=ffffffffffffffff r10=fffff80002e5f000 r11=00000000000004b6 r12=ffffffffffffffff r13=fffffa8004e23bf4 r14=0000000000004000 r15=fffff8800ab95a50 iopl=0 nv up ei ng nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286 fltmgr!TreeUnlinkNoBalance+0x6: fffff880`01092366 488b5118 mov rdx,qword ptr [rcx+18h] ds:002b:08000000`00000018=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B p CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff8800108e238 to fffff88001092366 STACK_TEXT: fffff880`0ab957f0 fffff880`0108e238 : fffff8a0`0af11000 fffffa80`042e0630 fffff880`0ab95a50 00000000`00008000 : fltmgr!TreeUnlinkNoBalance+0x6 fffff880`0ab95820 fffff880`010ac46f : ffffffff`ffffffff fffff800`02edcb50 00000000`6e664d46 00000000`00000246 : fltmgr!TreeUnlinkMulti+0x148 fffff880`0ab95870 fffff880`010ace19 : ffffffff`ffffffff fffffa80`08aa6a70 fffffa80`04e23580 fffffa80`08c6b2a0 : fltmgr!DeleteNameCacheNodes+0x9f fffff880`0ab958b0 fffff880`010bc2af : fffffa80`08aa6a70 fffffa80`08c6b2a0 00000000`00000000 00000000`00000000 : fltmgr!PurgeStreamNameCache+0xa9 fffff880`0ab958f0 fffff880`010b3a30 : fffffa80`03d71630 fffffa80`04e23580 00000000`00000000 00000000`04000001 : fltmgr!FltpPurgeVolumeNameCache+0x7f fffff880`0ab95930 fffff880`010acd4b : fffffa80`04e23580 fffff880`0ab959e0 fffffa80`04e08350 00000000`00000000 : fltmgr! ?? ::NNGAKEGL::`string'+0x1a04 fffff880`0ab95970 fffff880`0109377b : fffffa80`045a6ab0 fffffa80`049cc010 fffffa80`042e0630 fffff880`0ab95948 : fltmgr!FltpReinstateNameCachingAllFrames+0x4b fffff880`0ab959a0 fffff880`0108a6df : fffffa80`064ac2c0 fffffa80`045a6710 fffffa80`064ac200 fffffa80`045a6710 : fltmgr! ?? ::FNODOBFM::`string'+0x2cb2 fffff880`0ab95a30 fffff800`031b149d : 00000000`0000009c fffff880`0ab95ca0 00000000`00000000 fffffa80`04d972b0 : fltmgr!FltpDispatch+0xcf fffff880`0ab95a90 fffff800`02ed0153 : 00000000`00000594 fffffa80`047a7b60 00000000`00b6e6b8 0000007f`0000009c : nt!NtSetInformationFile+0x909 fffff880`0ab95bb0 00000000`774d012a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`00b6e698 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x774d012a FOLLOWUP_IP: fltmgr!TreeUnlinkNoBalance+6 fffff880`01092366 488b5118 mov rdx,qword ptr [rcx+18h] SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: fltmgr!TreeUnlinkNoBalance+6 FOLLOWUP_NAME: MachineOwner MODULE_NAME: fltmgr IMAGE_NAME: fltmgr.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc11f STACK_COMMAND: .cxr 0xfffff8800ab94e10 ; kb FAILURE_BUCKET_ID: X64_0x3B_fltmgr!TreeUnlinkNoBalance+6 BUCKET_ID: X64_0x3B_fltmgr!TreeUnlinkNoBalance+6 Followup: MachineOwner ---------
I ran the sfc/scannow 2 times and got: Windows Resource Protection did not find any integrity violations. And yes i have Norton 360 installed. Think thats the problem??
Please help, 4th BSOD today. Here is dump file:
Wow, that's awfully nice of you for the OP.
This latest dump he posted was much easier than the original to figure things out. That was cool how you did it only with the first one:
Code:BugCheck 1000007E, {ffffffffc0000005, fffff88003f0840c, fffff880031b6718, fffff880031b5f70} Probably caused by : IDSvia64.sys ( IDSvia64+3240c )
Just contacted Norton support. They remotely uninstalled Norton 360 and reinstalled the newest version of 360.Hope this cures the problem. Thanks guys for all of your help I really appreciate it.