Tech Support Forum banner
Status
Not open for further replies.

BSOD whilst running gmer.exe

4.7K views 32 replies 3 participants last post by  BazzaFiggy  
#1 ·
perfmon /report
I was denied from running it
**************************************
An error occured while attempting to generate the report.
The operator or administrator has refused the request.
**************************************
· OS - WIN 8.1
· x64
· What was original installed OS on system? win7 to Vista to Win8
· Is the OS an OEM version (came pre-installed on system) or full retail version (YOU purchased it from retailer)? - OEM
· Age of system (hardware) 3 years
· Age of OS installation - have you re-installed the OS? 2 years, No


· System Manufacturer - ASROCK
· Exact model number H67M

Laptop or Desktop? DESKTOP


Was trying to run gmer.exe as per http://www.techsupportforum.com/for.../new-instructions-read-this-before-posting-for-malware-removal-help-305963.html

trying to come at my consistent problem from another angle.
I dont have original install for 8.1 as original is win 7 - upgraded from there.
 

Attachments

#2 ·
Verifier enabled dumps showing unknown images and Windows system files almost always means hardware faults.
Code:
BugCheck 109, {a3a01f589b2c38bd, b3b72bdeedac39d4, fffff8021969d080, 2}
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
BugCheck 1A, {411, fffff6e000018670, afb0000154287882, fffff6e000014b71}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+204cf )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
BugCheck 1A, {41287, 5d70, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+99d3 )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
BugCheck 1000007E, {ffffffffc0000005, fffff801bc92d686, ffffd000207a94f8, ffffd000207a8d00}
Probably caused by : memory_corruption ( nt!MiDemoteCombinedPte+42 )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
BugCheck 1A, {41287, 3970000397a0, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+99d3 )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
BugCheck A, {15c0002fffa0, 2, 0, fffff80325505bd4}
Probably caused by : memory_corruption ( nt!MiPfPutPagesInTransition+320 )
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Lets start by testing the ram with memtest86+
D/L Memtest+ > How to perform a MemTest86+ Test | Tech Support Forum


Code:
Debug session time: Fri Mar 28 21:50:40.701 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032914-23656-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 1:03:42.430
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
BugCheck 109, {a3a01f589b2c38bd, b3b72bdeedac39d4, fffff8021969d080, 2}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x00000109]CRITICAL_STRUCTURE_CORRUPTION (109)[/url]
Bugcheck code 00000109
Arguments: 
Arg1: a3a01f589b2c38bd, Reserved
Arg2: b3b72bdeedac39d4, Reserved
Arg3: fffff8021969d080, Failure type dependent information
Arg4: 0000000000000002, Type of corrupted region, can be
	0 : A generic data region
	1 : Modification of a function or .pdata
	2 : A processor IDT
	3 : A processor GDT
	4 : Type 1 process list corruption
	5 : Type 2 process list corruption
	6 : Debug routine modification
	7 : Critical MSR modification
BUGCHECK_STR:  0x109
PROCESS_NAME:  System
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Debug session time: Fri Mar 28 20:46:19.551 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032914-25453-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 0:15:34.279
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+204cf )
BugCheck 1A, {411, fffff6e000018670, afb0000154287882, fffff6e000014b71}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000001A]MEMORY_MANAGEMENT (1a)[/url]
Bugcheck code 0000001A
Arguments: 
Arg1: 0000000000000411, The subtype of the bugcheck.
Arg2: fffff6e000018670
Arg3: afb0000154287882
Arg4: fffff6e000014b71
BUGCHECK_STR:  0x1a_411
PROCESS_NAME:  svchost.exe
FAILURE_BUCKET_ID:  X64_0x1a_411_VRF_nt!_??_::FNODOBFM::_string_+204cf
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Debug session time: Tue Mar 25 01:46:20.240 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032514-37203-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 1:21:43.927
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+99d3 )
BugCheck 1A, {41287, 5d70, 0, 0}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000001A]MEMORY_MANAGEMENT (1a)[/url]
Bugcheck code 0000001A
Arguments: 
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000005d70
Arg3: 0000000000000000
Arg4: 0000000000000000
BUGCHECK_STR:  0x1a_41287
PROCESS_NAME:  OINSIGHT.exe
FAILURE_BUCKET_ID:  X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+99d3
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Debug session time: Tue Mar 25 00:23:57.680 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032514-34140-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 0:02:37.367
Probably caused by : memory_corruption ( nt!MiDemoteCombinedPte+42 )
BugCheck 1000007E, {ffffffffc0000005, fffff801bc92d686, ffffd000207a94f8, ffffd000207a8d00}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x1000007E]SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)[/url]
Bugcheck code 1000007E
Arguments: 
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff801bc92d686, The address that the exception occurred at
Arg3: ffffd000207a94f8, Exception Record Address
Arg4: ffffd000207a8d00, Context Record Address
PROCESS_NAME:  svchost.exe
BUGCHECK_STR:  0x7E
DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
FAILURE_BUCKET_ID:  X64_0x7E_nt!MiDemoteCombinedPte+42
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Debug session time: Tue Mar 25 00:20:30.821 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032514-36062-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 4:34:37.688
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+99d3 )
BugCheck 1A, {41287, 3970000397a0, 0, 0}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000001A]MEMORY_MANAGEMENT (1a)[/url]
Bugcheck code 0000001A
Arguments: 
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 00003970000397a0
Arg3: 0000000000000000
Arg4: 0000000000000000
BUGCHECK_STR:  0x1a_41287
PROCESS_NAME:  OINSIGHT.exe
FAILURE_BUCKET_ID:  X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+99d3
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Debug session time: Mon Mar 24 10:22:53.402 2014 (UTC - 4:00)
Loading Dump File [C:\Users\Owner\Bsodapps\SysnativeBSODApps\032514-33359-01.dmp]
Built by: 9600.16452.amd64fre.winblue_gdr.131030-1505
System Uptime: 0 days 8:32:36.090
Probably caused by : memory_corruption ( nt!MiPfPutPagesInTransition+320 )
BugCheck A, {15c0002fffa0, 2, 0, fffff80325505bd4}
BugCheck Info: [url=http://www.carrona.org/bsodindx.html#0x0000000A]IRQL_NOT_LESS_OR_EQUAL (a)[/url]
Bugcheck code 0000000A
Arguments: 
Arg1: 000015c0002fffa0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
	bit 0 : value 0 = read operation, 1 = write operation
	bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80325505bd4, address which referenced memory
BUGCHECK_STR:  0xA
DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
PROCESS_NAME:  System
FAILURE_BUCKET_ID:  X64_0xA_nt!MiPfPutPagesInTransition+320
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``




		***   3rd PARTY DRIVER LIST   *** 
		***   3rd PARTY DRIVER LIST   *** 




ElbyCDIO.sys                Mon Mar  4 04:21:51 2013 (513467AF)
GEARAspiWDM.sys             Thu May  3 15:56:17 2012 (4FA2E2E1)
HWiNFO64A.SYS               Sun Aug 18 13:21:57 2013 (521102B5)
ICCWDT.sys                  Wed Aug 18 04:27:45 2010 (4C6B9981)
PulseUsb.sys                Mon Apr 12 12:27:15 2010 (4BC349E3)
RTKVHD64.sys                Tue Dec  3 07:26:10 2013 (529DCDE2)
Rt630x64.sys                Tue Nov 26 02:32:54 2013 (52944EA6)
TeeDriverx64.sys            Tue Apr 23 13:36:39 2013 (5176C6A7)
avgdiska.sys                Mon Nov 25 15:47:16 2013 (5293B754)
avgidsdrivera.sys           Mon Nov 25 15:47:17 2013 (5293B755)
avgidsha.sys                Mon Nov 25 15:47:18 2013 (5293B756)
avgldx64.sys                Thu Oct 31 18:00:14 2013 (5272D2EE)
avgloga.sys                 Thu Oct 31 17:49:41 2013 (5272D075)
avgmfx64.sys                Mon Sep 30 18:49:53 2013 (524A0011)
avgrkx64.sys                Mon Sep  9 18:42:59 2013 (522E4EF3)
avgwfpa.sys                 Mon Oct 21 16:28:13 2013 (52658E5D)
bdfndisf6.sys               Tue Aug 28 10:25:03 2012 (503CD4BF)
bdfwfpf.sys                 Mon Oct 29 08:23:28 2012 (508E7540)
dc3d.sys                    Fri Apr 12 08:15:46 2013 (5167FAF2)
dump_iaStorA.sys            Thu Aug  1 21:39:52 2013 (51FB0DE8)
iaStorA.sys                 Thu Aug  1 21:39:52 2013 (51FB0DE8)
idmwfp.sys                  Wed Nov 27 09:24:10 2013 (5296008A)
igdkmd64.sys                Thu Oct 31 14:28:01 2013 (5272A131)
intelppm.sys                Thu Aug 22 04:46:35 2013 (5215CFEB)
point64.sys                 Fri Apr 12 08:15:29 2013 (5167FAE1)
pxldqpoc.sys                Sun Apr  7 13:19:48 2013 (5161AAB4)
speedfan.sys                Sat Dec 29 15:59:35 2012 (50DF59B7)
 
#3 ·
Thank you.
I ran memtest as I normally have, with no errors. I then noticed the cores were 1 of 1, which was incorrect as i have 4. Googled and found you press F3 on start. (was then I noticed the F2 msg).

Anyway, It froze @ 73% in test #7. Core #3 shows W.

This has obviously been the cause of all my problems the last month (yes, other bsod problems reported, with now I assume red herring solutions)
Do you know if that is bad cpu or bad memory.

Thank you very much for finding my problem.
 
#8 ·
Ok, have done 12 passes and not a dicky bird....all OK.

What now.

I feel I have a corruption in the Win8.1 system somewhere, but I cant do a repair as I do not have a Win8.1 install disk, only the original Win7 one.
There a re a few strange quirky things happening, I will document them as they happen.

What is the best registry checker/fixer, straw clutching here.?

I assume that if not hardware problem then BSOD could be caused by a corrupt/missing windows file somewhere?
 
#9 ·
btw:
I have a cd that is labeled 'Repair disc Windows 8 64-bit', but if i go thru Recovery->Refresh it says 'the media inserted is not valid'. I also have a usb stick one, same msg.
The disk is readable and view-able.
Is there anything I can check or do differently.

The repair function said to needed to get some missing files.!
 
#10 · (Edited)
It's not valid because it's Win 8 and you now have 8.1.

See this for the official procedure> How to refresh, reset, or restore your PC - Microsoft Windows Help

It's one place where MS dropped the ball with the 8.1 update.
The only way I done it successfully is to roll the system back to 8 by using a restore point when or before the 8.1 update was installed.
 
#11 ·
Back again,
You will need to point me to the correct support area I think.
Downloaded Win 8.1 install iso.
Tried repair every which way, but keep getting. "this option is not supported on the operating system you have selected" and also "the media inserted is not valid'

I ran a sfc /scannow as admin and got the errors as attached in the cbs.log

If you can 'tell me where to go" that would actually be great.
[and dont ask how old I am<s>]
 

Attachments

#15 ·
You are the greatest.
Thanks I will try that now.

PS: I used key finder to get my OS key and it definitively matches the one I gave the install disc setup. So there is something strange going on. Last resort I get a SSD as a new C: and have current C: as second drive and then just copy over the setting etc and my OpenInsight development stuff.
 
#24 ·
Now got a bsod memory_management and now windows 8.1 appears to have re installed itself and a msg flashed up about temporary profile. Desktop appears to have all the app shortcuts that were there but not any of the folders. I have a Temp that has been created in \users today. I still have my original 'Barry' in users. I thought it must have been the 8.1 rel 1 upgrade that was happening but I say not (Well hope not cause a lot of people will be in strife)

Can you point me to where I can fix this.
 
Status
Not open for further replies.
You have insufficient privileges to reply here.