If interested please analyze these .dmp files and advise as to how to correct the issues.
Please refer to this:
http://msdn.microsoft.com/en-us/library/ff560177(v=vs.85).aspx
The error occurs in a user-mode process, therefore, I suggest you
Clean Boot the computer and see the result.
Or remove recently installed new applications. Maybe the last known good configuration could help you.
Regards,
Miya
Miya Yao
TechNet Community Support
February 21st, 2012 9:01am
There are five .dmp files listed below. Please advise on possible causes and resolutions.
Thank You,
Respectfully,
Rambo0865
#1
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17713.x86fre.win7sp1_gdr.111025-1505
Machine Name:
Kernel base = 0x82e1e000 PsLoadedModuleList = 0x82f674d0
Debug session time: Mon Feb 13 07:51:13.607 2012 (UTC - 5:00)
System Uptime: 1 days 19:50:03.747
Loading Kernel Symbols
...............................................................
................................................................
...............
Loading User Symbols
Loading unloaded module list
...............
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: 9ee28988, String that identifies the problem.
Arg2: c0000006, Error Code.
Arg3: 74f6d1af
Arg4: 00c3f474
Debugging Details:
------------------
ERROR_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_PARAMETER1: 9ee28988
EXCEPTION_PARAMETER2: c0000006
EXCEPTION_PARAMETER3: 74f6d1af
EXCEPTION_PARAMETER4: c3f474
ADDITIONAL_DEBUG_TEXT: Windows SubSystem
BUGCHECK_STR: 0xc000021a_csrss.exe_c0000006
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 830f72df to 82efcef4
STACK_TEXT:
97cca8e4 830f72df 0000004c c000021a 97cca96c nt!KeBugCheckEx+0x1e
97cca934 83149949 00000001 0000004c c000021a nt!PoShutdownBugCheck+0x81
97ccaaf4 82ff6d66 c000021a 00000004 00000001 nt!ExpSystemErrorHandler+0x567
97ccaca4 82ff61c6 c000021a 00000004 00000001 nt!ExpRaiseHardError+0xbf
97ccad14 82e5c21a c000021a 00000004 00000001 nt!NtRaiseHardError+0x11a
97ccad14 76e37094 c000021a 00000004 00000001 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
00c3f324 00000000 00000000 00000000 00000000 0x76e37094
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiFastCallEntry+12a
82e5c21a f6456c01 test byte ptr [ebp+6Ch],1
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: nt!KiFastCallEntry+12a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4ea76eb4
FAILURE_BUCKET_ID: 0xc000021a_csrss.exe_c0000006_nt!KiFastCallEntry+12a
BUCKET_ID: 0xc000021a_csrss.exe_c0000006_nt!KiFastCallEntry+12a
Followup: MachineOwner
---------
1: kd> g
^ No runnable debuggees error in 'g'
#2
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17713.x86fre.win7sp1_gdr.111025-1505
Machine Name:
Kernel base = 0x82e48000 PsLoadedModuleList = 0x82f914d0
Debug session time: Fri Feb 10 12:00:11.966 2012 (UTC - 5:00)
System Uptime: 0 days 1:23:16.104
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
.................
0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 878334e8, Terminating object
Arg3: 87833654, Process image file name
Arg4: 83060d60, Explanatory message (ascii)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for mfehidk.sys
*** ERROR: Module load completed but symbols could not be loaded for mfehidk.sys
PROCESS_OBJECT: 878334e8
IMAGE_NAME: hardware_disk
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAULTING_MODULE: 00000000
PROCESS_NAME: wininit.exe
EXCEPTION_RECORD: 97aabc7c -- (.exr 0xffffffff97aabc7c)
ExceptionAddress: 00ef0083
ExceptionCode: c0000006 (In-page I/O error)
ExceptionFlags: 00000000
NumberParameters: 3
Parameter[0]: 00000008
Parameter[1]: 00ef0083
Parameter[2]: c000000e
Inpage operation failed at 00ef0083, due to I/O error c000000e
EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
EXCEPTION_PARAMETER1: 00000008
EXCEPTION_PARAMETER2: 00ef0083
EXCEPTION_PARAMETER3: c000000e
IO_ERROR: (NTSTATUS) 0xc000000e - A device which does not exist was specified.
EXCEPTION_STR: 0xc0000006_c000000e
FAULTING_IP:
+12a
00ef0083 ?? ???
BUGCHECK_STR: 0xF4_IOERR_C000000E
STACK_TEXT:
97aab428 83126159 000000f4 00000003 878334e8 nt!KeBugCheckEx+0x1e
97aab44c 830a3cdc 83060d60 87833654 87833758 nt!PspCatchCriticalBreak+0x71
97aab47c 830a3c1f 878334e8 85933890 c0000006 nt!PspTerminateAllThreads+0x2d
97aab4b0 8c85ac6c ffffffff c0000006 97aab4e0 nt!NtTerminateProcess+0x1a2
WARNING: Stack unwind information not available. Following frames may be wrong.
97aab4d0 82e8621a ffffffff c0000006 97aab964 mfehidk+0x39c6c
97aab4d0 82e8546d ffffffff c0000006 97aab964 nt!KiFastCallEntry+0x12a
97aab550 82efd359 ffffffff c0000006 0001003f nt!ZwTerminateProcess+0x11
97aab964 82e74fe7 97aabc7c 00000000 97aabd34 nt!KiDispatchException+0x497
97aabd04 82e89db7 97aabc7c 002fe9bc 00000000 nt!KiRaiseException+0x18a
97aabd20 82e8621a 002fe99c 002fe9bc 00000000 nt!NtRaiseException+0x33
97aabd20 00ef0083 002fe99c 002fe9bc 00000000 nt!KiFastCallEntry+0x12a
002fed24 00000000 00000000 00000000 00000000 0xef0083
STACK_COMMAND: kb
FOLLOWUP_IP:
+12a
00ef0083 ?? ???
SYMBOL_STACK_INDEX: b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware_disk
SYMBOL_NAME: +12a
FAILURE_BUCKET_ID: 0xF4_IOERR_C000000E_+12a
BUCKET_ID: 0xF4_IOERR_C000000E_+12a
Followup: MachineOwner
#3
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17713.x86fre.win7sp1_gdr.111025-1505
Machine Name:
Kernel base = 0x82e1b000 PsLoadedModuleList = 0x82f644d0
Debug session time: Fri Feb 10 08:21:40.139 2012 (UTC - 5:00)
System Uptime: 0 days 15:39:47.546
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
.............
2: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 86b393a0, Terminating object
Arg3: 86b3950c, Process image file name
Arg4: 83033d60, Explanatory message (ascii)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for mfehidk.sys
*** ERROR: Module load completed but symbols could not be loaded for mfehidk.sys
PROCESS_OBJECT: 86b393a0
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 00000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
BUGCHECK_STR: 0xF4_IOERR
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
a14c5c7c 830f9159 000000f4 00000003 86b393a0 nt!KeBugCheckEx+0x1e
a14c5ca0 83076cdc 83033d60 86b3950c 86b39610 nt!PspCatchCriticalBreak+0x71
a14c5cd0 83076c1f 86b393a0 862d4030 c0000006 nt!PspTerminateAllThreads+0x2d
a14c5d04 8c892c6c ffffffff c0000006 ffffffff nt!NtTerminateProcess+0x1a2
WARNING: Stack unwind information not available. Following frames may be wrong.
a14c5d24 82e5921a ffffffff c0000006 02cdf538 mfehidk+0x39c6c
a14c5d24 77437094 ffffffff c0000006 02cdf538 nt!KiFastCallEntry+0x12a
02cdf538 00000000 00000000 00000000 00000000 0x77437094
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: 0xF4_IOERR_IMAGE_csrss.exe
BUCKET_ID: 0xF4_IOERR_IMAGE_csrss.exe
Followup: MachineOwner
#4
Loading Dump File [C:\Users\klarson\Downloads\rebootupinfo\021112-15490-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17713.x86fre.win7sp1_gdr.111025-1505
Machine Name:
Kernel base = 0x82e42000 PsLoadedModuleList = 0x82f8b4d0
Debug session time: Sat Feb 11 12:00:11.529 2012 (UTC - 5:00)
System Uptime: 0 days 23:39:46.785
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
Loading unloaded module list
...............
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: aa6085b0, String that identifies the problem.
Arg2: c0000006, Error Code.
Arg3: 778bc1ec
Arg4: 00b2efe0
Debugging Details:
------------------
ERROR_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_PARAMETER1: aa6085b0
EXCEPTION_PARAMETER2: c0000006
EXCEPTION_PARAMETER3: 778bc1ec
EXCEPTION_PARAMETER4: b2efe0
ADDITIONAL_DEBUG_TEXT: Windows SubSystem
BUGCHECK_STR: 0xc000021a_csrss.exe_c0000006
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 8311b2df to 82f20ef4
STACK_TEXT:
974938e4 8311b2df 0000004c c000021a 9749396c nt!KeBugCheckEx+0x1e
97493934 8316d949 00000001 0000004c c000021a nt!PoShutdownBugCheck+0x81
97493af4 8301ad66 c000021a 00000004 00000001 nt!ExpSystemErrorHandler+0x567
97493ca4 8301a1c6 c000021a 00000004 00000001 nt!ExpRaiseHardError+0xbf
97493d14 82e8021a c000021a 00000004 00000001 nt!NtRaiseHardError+0x11a
97493d14 778d7094 c000021a 00000004 00000001 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
00b2ee90 00000000 00000000 00000000 00000000 0x778d7094
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiFastCallEntry+12a
82e8021a f6456c01 test byte ptr [ebp+6Ch],1
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: nt!KiFastCallEntry+12a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4ea76eb4
FAILURE_BUCKET_ID: 0xc000021a_csrss.exe_c0000006_nt!KiFastCallEntry+12a
BUCKET_ID: 0xc000021a_csrss.exe_c0000006_nt!KiFastCallEntry+12a
Followup: MachineOwner
---------
#5
Loading Dump File [C:\Users\klarson\Downloads\rebootupinfo\021412-15381-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17713.x86fre.win7sp1_gdr.111025-1505
Machine Name:
Kernel base = 0x82e17000 PsLoadedModuleList = 0x82f604d0
Debug session time: Tue Feb 14 07:55:10.560 2012 (UTC - 5:00)
System Uptime: 1 days 0:03:00.885
Loading Kernel Symbols
...............................................................
................................................................
...............
Loading User Symbols
Loading unloaded module list
...............
2: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis *
*
*
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 85b36528, Terminating object
Arg3: 85b36694, Process image file name
Arg4: 8302fd60, Explanatory message (ascii)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for mfehidk.sys
*** ERROR: Module load completed but symbols could not be loaded for mfehidk.sys
PROCESS_OBJECT: 85b36528
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 00000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
BUGCHECK_STR: 0xF4_IOERR
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
a0e83c7c 830f5159 000000f4 00000003 85b36528 nt!KeBugCheckEx+0x1e
a0e83ca0 83072cdc 8302fd60 85b36694 85b36798 nt!PspCatchCriticalBreak+0x71
a0e83cd0 83072c1f 85b36528 87bc8d48 c0000006 nt!PspTerminateAllThreads+0x2d
a0e83d04 8c83fc6c ffffffff c0000006 ffffffff nt!NtTerminateProcess+0x1a2
WARNING: Stack unwind information not available. Following frames may be wrong.
a0e83d24 82e5521a ffffffff c0000006 0090f934 mfehidk+0x39c6c
a0e83d24 777f7094 ffffffff c0000006 0090f934 nt!KiFastCallEntry+0x12a
0090f934 00000000 00000000 00000000 00000000 0x777f7094
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: 0xF4_IOERR_IMAGE_csrss.exe
BUCKET_ID: 0xF4_IOERR_IMAGE_csrss.exe
Followup: MachineOwner
Free Windows Admin Tool Kit Click here and download it now
March 3rd, 2012 11:00am
Please refer to this:
http://msdn.microsoft.com/en-us/library/ff560177(v=vs.85).aspx
The error occurs in a user-mode process, therefore, I suggest you
Clean Boot the computer and see the result.
Or remove recently installed new applications. Maybe the last known good configuration could help you.
Regards,
Miya
Miya Yao
TechNet Community Support
March 4th, 2012 12:54am