BSOD - any time :/

TesterFromTest

New member
Local time
4:29 PM
Messages
5
Hello,

I had computer which we use for CCTV. Sometimes it has BSOD. We formated him, reinstalled all software and we add card for analog cameras.

It was still in BSOD. So we take it to our office turn it on and nothing in two days. So we take them without analog CCTV card again to gatehouse. When it start again BSOD. Restart and again.

:sarc:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Vostro 3500
OS
Windows 7 Ultimate x64
CPU
i5
Memory
8GB
Graphics Card(s)
NVudia 310
Antivirus
Kaspersky Endpoint Security
Hi there!

Seems like it might the drivers related to the analog CCTV card. But since the dump file didn't report it let run the Driver Verifier to conform it. http://www.sevenforums.com/crash-lo...-driver-verifier-identify-issues-drivers.html

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: 96c40000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 82e9dd54, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 82da084c
Unable to read MiSystemVaType memory at 82d7fe20
 96c40000 

FAULTING_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

MM_INTERNAL_CODE:  0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0x50

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

TRAP_FRAME:  9f58da0c -- (.trap 0xffffffff9f58da0c)
ErrCode = 00000000
eax=aa000000 ebx=9f58dab4 ecx=005e032d edx=ab780cb8 esi=9e9846e8 edi=954bf34c
eip=82e9dd54 esp=9f58da80 ebp=9f58da88 iopl=0         nv up ei pl nz na pe cy
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
nt!CmpGetValueListFromCache+0x95:
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4] ds:0023:96c40000=????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from 82c77a88 to 82cc4861

STACK_TEXT:  
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!CmpGetValueListFromCache+95

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  51871b70

FAILURE_BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

Followup: MachineOwner
---------

0: kd> !thread;!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck;
GetPointerFromAddress: unable to read from 82da0850
THREAD 858ba030  Cid 09b4.0898  Teb: 7ffaf000 Win32Thread: 00000000 RUNNING on processor 0
Not impersonating
GetUlongFromAddress: unable to read from 82d604dc
Owning Process            87d94be8       Image:         svchost.exe
Attached Process          N/A            Image:         N/A
ffdf0000: Unable to get shared data
Wait Start TickCount      2671194      
Context Switch Count      84651          IdealProcessor: 3             
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime                  00:00:00.000
KernelTime                00:00:00.000
Win32 Start Address 0x771d03e9
Stack Init 9f58ded0 Current 9f58d9ac Base 9f58e000 Limit 9f58b000 Call 0
Priority 8 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
ChildEBP RetAddr  Args to Child              
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc (FPO: [0,0] TrapFrame @ 9f58da0c)
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall (FPO: [0,3] TrapFrame @ 9f58dc34)
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094

*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: 96c40000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 82e9dd54, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 82da084c
Unable to read MiSystemVaType memory at 82d7fe20
 96c40000 

FAULTING_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

MM_INTERNAL_CODE:  0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0x50

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

TRAP_FRAME:  9f58da0c -- (.trap 0xffffffff9f58da0c)
ErrCode = 00000000
eax=aa000000 ebx=9f58dab4 ecx=005e032d edx=ab780cb8 esi=9e9846e8 edi=954bf34c
eip=82e9dd54 esp=9f58da80 ebp=9f58da88 iopl=0         nv up ei pl nz na pe cy
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
nt!CmpGetValueListFromCache+0x95:
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4] ds:0023:96c40000=????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from 82c77a88 to 82cc4861

STACK_TEXT:  
9f58d9f4 82c77a88 00000000 96c40000 00000000 nt!MmAccessFault+0x104
9f58d9f4 82e9dd54 00000000 96c40000 00000000 nt!KiTrap0E+0xdc
9f58da88 82e832c3 010c8348 9f58dac8 9f58dac4 nt!CmpGetValueListFromCache+0x95
9f58daec 82e82480 9f58db7c 9f58db2c 9f58db28 nt!CmpFindValueByNameFromCache+0x47
9f58db60 82e829a8 a48d63b0 00000002 011de80c nt!CmQueryValueKey+0x350
9f58dc14 82c748a6 000005e0 011de8d0 00000002 nt!NtQueryValueKey+0x312
9f58dc14 771e7094 000005e0 011de8d0 00000002 nt!KiSystemServicePostCall
WARNING: Frame IP not in any known module. Following frames may be wrong.
011de8a0 00000000 00000000 00000000 00000000 0x771e7094


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!CmpGetValueListFromCache+95
82e9dd54 8b3c8f          mov     edi,dword ptr [edi+ecx*4]

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!CmpGetValueListFromCache+95

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrpamp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  51871b70

FAILURE_BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

BUCKET_ID:  0x50_nt!CmpGetValueListFromCache+95

Followup: MachineOwner
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
Thanks for quick response.
Dumps are enclosed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Vostro 3500
OS
Windows 7 Ultimate x64
CPU
i5
Memory
8GB
Graphics Card(s)
NVudia 310
Antivirus
Kaspersky Endpoint Security
Hi there!

Yes we guessed correct it's CapSV.sys i.e. Capture card driver. Uninstall the drivers completely How to Uninstall Drivers in Windows | PCWorld and reboot and try to install it again. See if you can get an updated version of the drivers.

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_VERIFIER_IOMANAGER_VIOLATION (c9)
The IO manager has caught a misbehaving driver.
Arguments:
Arg1: 0000021f, A driver has not filled out a dispatch routine for a required IRP major function.
Arg2: 8d4952a0, The address in the driver's code where the error was detected.
Arg3: 935a6f00, IRP address.
Arg4: 00000000

Debugging Details:
------------------


BUGCHECK_STR:  0xc9_21f

DRIVER_VERIFIER_IO_VIOLATION_TYPE:  21f

FAULTING_IP: 
CapSV+382a0
8d4952a0 6a00            push    0

FOLLOWUP_IP: 
CapSV+382a0
8d4952a0 6a00            push    0

IRP_ADDRESS:  935a6f00

DEVICE_OBJECT: 8c1880b8

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VERIFIER_ENABLED_VISTA_MINIDUMP

PROCESS_NAME:  System

CURRENT_IRQL:  2

LOCK_ADDRESS:  82d6dbe0 -- (!locks 82d6dbe0)

Resource @ nt!PiEngineLock (0x82d6dbe0)    Available

WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.


WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.

1 total locks

PNP_TRIAGE: 
	Lock address  : 0x82d6dbe0
	Thread Count  : 0
	Thread address: 0x00000000
	Thread wait   : 0x0

LAST_CONTROL_TRANSFER:  from 82f3df03 to 82ce5bf0

STACK_TEXT:  
881856dc 82f3df03 000000c9 0000021f 8d4952a0 nt!KeBugCheckEx+0x1e
881856fc 82f402cd 8d4952a0 88185734 8d4952a0 nt!VerifierBugCheckIfAppropriate+0x30
88185714 82f4032a 0000021f 8d4952a0 00000000 nt!ViErrorFinishReport+0xc9
88185768 82f473f0 0000021f 935a6f00 935a6fb8 nt!VfErrorReport1+0x4d
88185784 82f3fedb 935a6fdc 935a6fb8 8b1fb170 nt!VfWmiVerifyIrpStackDownward+0x4d
881857a0 82f3e426 8c1a2948 8c0a0dc8 935a6fdc nt!VfMajorVerifyIrpStackDownward+0x3e
88185804 82f3dd33 8c03f910 935a6f00 88185834 nt!IovpCallDriver1+0x468
88185814 82f38670 8c0a0dc8 935a6fd4 8c0a0dc8 nt!VfBeforeCallDriver+0xe7
88185834 82c3dbd5 935a6fb8 935a6ff8 8c0a0dc8 nt!IovCallDriver+0x206
88185848 82f4a4d0 8adaef90 935a6f00 8c1880b8 nt!IofCallDriver+0x1b
88185860 82f386c3 8c188170 935a6f00 935a7000 nt!ViFilterDispatchGeneric+0x5e
88185884 82c3dbd5 00000000 8818590c 8c1880b8 nt!IovCallDriver+0x258
88185898 82f3dbcc 00000004 00000017 00000000 nt!IofCallDriver+0x1b
881858c4 82f474f7 8a878b58 881858e8 00000001 nt!VfIrpSendSynchronousIrp+0xa5
88185910 82f4011f 8a86f880 8818599c 82db87f5 nt!VfWmiTestStartedPdoStack+0x48
8818591c 82db87f5 8a878b58 8a86f880 00000000 nt!VfMajorTestStartedPdoStack+0x48
8818599c 82dc4057 00000001 00000000 8b9d5d00 nt!PipProcessStartPhase3+0x427
88185b94 82d8fe62 86fb6700 8b9d5d00 88185bc8 nt!PipProcessDevNodeTree+0x2e6
88185bd4 82c1bd09 8b9d5d00 82d6bb00 86e68d48 nt!PiProcessStartSystemDevices+0x6d
88185c00 82c840fb 00000000 00000000 86e68d48 nt!PnpDeviceActionWorker+0x241
88185c50 82e1012f 00000001 a5166ff8 00000000 nt!ExpWorkerThread+0x10d
88185c90 82cb7559 82c83fee 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


STACK_COMMAND:  .bugcheck ; kb

SYMBOL_NAME:  CapSV+382a0

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: CapSV

IMAGE_NAME:  CapSV.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4b0244c3

FAILURE_BUCKET_ID:  0xc9_21f_VRF_CapSV+382a0

BUCKET_ID:  0xc9_21f_VRF_CapSV+382a0

Followup: MachineOwner
---------

3: kd> lmvm CapSV
start    end        module name
8d45d000 8d4d4c00   CapSV    T (no symbols)           
    Loaded symbol image file: CapSV.sys
    Image path: \SystemRoot\system32\drivers\CapSV.sys
    Image name: CapSV.sys
    Timestamp:        Tue Nov 17 12:07:55 2009 (4B0244C3)
    CheckSum:         0007E10B
    ImageSize:        00077C00
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
I've contacted with driver producer. They add this driver to instalation software.

I uninstalled the driver and did the repair install windows during which he informed me that he could not confirm the source of the driver.

After installing the Driver Verifier done again BSOD appeared.
I attach the dump.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Vostro 3500
OS
Windows 7 Ultimate x64
CPU
i5
Memory
8GB
Graphics Card(s)
NVudia 310
Antivirus
Kaspersky Endpoint Security
I've contacted with driver producer. They add this driver to instalation software.

I uninstalled the driver and did the repair install windows during which he informed me that he could not confirm the source of the driver.

After installing the Driver Verifier done again BSOD appeared.
I attach the dump.

Sorry it's showing the same drivers again. Once you reinstall the driver disable the Driver Verifier

Code:
BugCheck C9, {21f, 8ce8f2a0, 8f992f00, 0}

Unable to load image \SystemRoot\system32\drivers\CapSV.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for CapSV.sys
*** ERROR: Module load completed but symbols could not be loaded for CapSV.sys
Probably caused by : CapSV.sys ( CapSV+382a0 )
 

My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
Back
Top