Event Type: Warning
Event Source: USER32
Event Category: None
Event ID: 1076
Date: 2003-08-09
Time: 17:12:54
User: ALEBORG-WIN-2\Anders
Computer: ALEBORG-WIN-2
Description:
The reason supplied by user ALEBORG-WIN-2\Anders for the last unexpected shutdown of this computer is: Power Failure: Environment
Reason Code: 0x806000c
Bug ID:
Bugcheck String:
Comment:
Information
Produkt: Windows Operating System
ID: 106
Källa: WMIxWDM
Version: 5.2
Symboliskt namn: MCA_WARNING_UNKNOWN_NO_CPU
Meddelande: Machine Check Event reported is a corrected error.
Förklaring
A hardware error was resolved by your system. The type of error cannot be determined because the error record returned by the firmware is not in the required format. For detailed information about the hardware that caused the problem, refer to the event log.
**Bug Check 0x50:**PAGE_FAULT_IN_NONPAGED_AREA
The PAGE_FAULT_IN_NONPAGED_AREA bug check has a value of 0x00000050. This indicates that invalid system memory has been referenced.
Cause
Bug check 0x50 usually occurs after the installation of faulty hardware or in the event of failure of installed hardware (usually related to defective RAM, be it main memory, L2 RAM cache, or video RAM).
Another common cause is the installation of a faulty system service.
Antivirus software can also trigger this error, as can a corrupted NTFS volume.
En sak mindre... För övrigt, den andra minnesdumpfilen var korrupt. Har du fler?
Man borde se några olika dumpfiler och jämföra. Är det helt olika områden varje gång ligger ju hårdvarufel nära till hands.
Samtidigt känns svårt att utesluta att det beror på en dålig drivrutin till nätverkskortet som trashar kernelminne. Har du testat att plocka ur externa nätverkskort *samt disablat inbyggda kortet*? (Titta i device managern så inget kort finns)
Din dator ser ju ut att ha hyperthreading, och det gör ju uppgiften för den som skriver drivrutinen något svårare. Finns kortet på WHQL för ditt OS?
Finns det något samband i när den dyker? Hur ofta händer det? Är det när du kör hög last eller räcker med att den står och vilar i ett nätverk utan trafik?
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: e58744f8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 804ef5b0, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000002, (reserved)
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt.
***** Followup with Debugger team
"nt.*" was not found in the image list.
Debugger will attempt to load "nt.*" at given base 00000000.
Please provide the full image name, including the extension (i.e. kernel32.dll)
for more reliable results. Base address and size overrides can be given as
.reload <image.ext>=<base>,<size>.
Unable to load image nt.*, Win32 error 2
Unable to add module at 00000000
READ_ADDRESS: unable to get nt!MmPoolCodeEnd
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPagedPoolEnd
unable to get nt!MmNonPagedPoolEnd
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSpecialPoolStart
unable to get nt!MmPagedPoolStart
unable to get nt!MiSessionPoolStart
unable to get nt!MiSessionPoolEnd
unable to get nt!MmNonPagedPoolExpansionStart
unable to get nt!MmPoolCodeStart
e58744f8
FAULTING_IP:
+ffffffff804ef5b0
804ef5b0 ?? ???
MM_INTERNAL_CODE: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP
BUGCHECK_STR: 0x50
LAST_CONTROL_TRANSFER: from 00000000 to 8053eec8
STACK_TEXT:
f78beb80 00000000 00000000 00000000 00000000 0x8053eec8
FOLLOWUP_IP:
+ffffffff8053eec8
8053eec8 5d pop ebp
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: kb
BUCKET_ID: CORRUPT_MODULELIST
Followup: MachineOwner
---------
samt
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000001a, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: f6ea8eb8, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: 0000001a
CURRENT_IRQL: 2
FAULTING_IP:
tcpip!MdpFree+18
f6ea8eb8 0fb6471b movzx eax,byte ptr [edi+0x1b]
DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP
BUGCHECK_STR: 0xD1
TRAP_FRAME: f789ed14 -- (.trap fffffffff789ed14)
ErrCode = 00000000
eax=8401e0d8 ebx=84c37f30 ecx=0000003c edx=8401e0d8 esi=8401e000 edi=ffffffff
eip=f6ea8eb8 esp=f789ed88 ebp=f789ed98 iopl=0 nv up ei ng nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
tcpip!MdpFree+0x18:
f6ea8eb8 0fb6471b movzx eax,byte ptr [edi+0x1b] ds:0023:0000001a=??
Resetting default scope
LAST_CONTROL_TRANSFER: from f6eb534c to f6ea8eb8
STACK_TEXT:
f789ed98 f6eb534c 8401e0d8 f6eb5202 8401e0d8 tcpip!MdpFree+0x18
f789eda0 f6eb5202 8401e0d8 00000000 84bc7c20 tcpip!FreeDGHeader+0x1c
f789eddc f6ea88b9 84c37f30 8401e0d8 00000000 tcpip!DGSendComplete+0x9f
f789ee14 f6ea8a83 84ceb1c0 00bc7c20 00000000 tcpip!IPSendComplete+0x124
f789ee38 f72a4b23 84b8f008 84bc7c20 c001000c tcpip!ARPSendComplete+0xf4
f789ee7c f72a4baf 00000000 84d12988 84d12958 NDIS!ndisMAbortPackets+0x1a3
f789ee90 f72a513a 84d12958 00000000 00000000 NDIS!ndisMResetCompleteStage1+0x1f
f789eeb0 f70fb53d 02d12958 00000000 00000000 NDIS!NdisMResetComplete+0x6a
f789eecc f72a0567 00000000 0000786d 00000000 el90xbc5!NICTimer+0x6f
f789eef0 804ecd84 84b6a2f8 f70fb4ce 047ee3dc NDIS!ndisMTimerDpc+0x108
f789efa4 804e40f8 00000000 00000000 02003d08 nt!KiTimerExpiration+0x205
f789eff4 804e48eb f6269940 00000000 00000000 nt!KiRetireDpcList+0x63
FOLLOWUP_IP:
el90xbc5!NICTimer+6f
f70fb53d 80667c00 and byte ptr [esi+0x7c],0x0
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: el90xbc5!NICTimer+6f
MODULE_NAME: el90xbc5
IMAGE_NAME: el90xbc5.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 3c9648cb
STACK_COMMAND: .trap fffffffff789ed14 ; kb
BUCKET_ID: 0xD1_el90xbc5!NICTimer+6f
Followup: MachineOwner
---------