System reboot with Bug check
Event Type: InformationEvent Source: Save DumpEvent Category: NoneEvent ID: 1001Date: 12/27/2010Time: 2:47:35 PMUser: N/ADescription:The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000b8c, 0x0000001c, 0x00000000, 0x804ffa24). A dump was saved in: C:\WINDOWS\MEMORY.DMP.For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.1 person needs an answerI do too
December 27th, 2010 5:40am

There are many reasons for a 0x0000000A type report, so we need to know more information to efficiently solve the problem.Please provide additional information about your system:What is your system make and model?What is your XP Version and Service Pack?Describe your current antivirus and anti malware situation: McAfee, Symantec, Norton, Spybot, AVG, Avira!, MSE, Panda, Trend Micro, CA, Defender, ZoneAlarm, PC Tools, Comodo, etc.Was the issue preceded by a power interruption, aborted restart, or improper shutdown? (this includes plug pulling, power buttons, removing the battery, etc.)Does the afflicted system have a working CD/DVD drive?Do you have a genuine bootable XP installation CD (this is not the same as any Recovery CDs that came with your system)?Can you make the system crash any time you want? For example, would you say that there is any particular system activity that coincides with the crashes (like watching videos, playing games, etc.).Fill in the blank: My system was working fine until: ____________________________________________.The next time your system crashes, provide more information about what you see.Here is a BSOD example showing information you need to provide:http://techrepublic.com.com/i/tr/downloads/images/bsod_a.jpgSend the information pointed to with the red arrows (3-4 lines total). Send the entire *** STOP message line since there are clues in the 4 parameters.If there is a file name listed under the STOP message, be sure to include that information too.Skip the boring text unless it looks important to you. We know what a BSOD looks like, we need to know what your BSOD looks like.Now provide more information about your most recent crashes.Download BlueScreenView from here:http://www.nirsoft.net/utils/blue_screen_view.htmlUnzip and run it (BSV installs nothing) and let it finish scanning all your crash dump files. If you double click on of the dumps, you will get some information about it (including the Caused By Driver field) and you may be able to spot the problem right away - especially if you see a pattern in the dumps where the Caused by Driver field is the same (start with that driver).Select (highlight) one or more of the most recent dump files by clicking them and holding down the Ctrl key to select multiples files. Try to select just the most recent ones that relate to your issue (maybe five or so dump files to get started).Click File, Save Selected Items and save the information from the dumps to a text file on your desktop called BSOD.txt. Open BSOD.txt with a text editor, copy all the text and paste it into your next reply.Here is an example of the BSV report from a single BSOD that I initiated on purpose that shows the cause of the crash as the i8042prt.sys driver belonging to Microsoft Corporation:==================================================Dump File : Memory.dmpCrash Time : 6/21/2010 11:51:31 AMBug Check String : MANUALLY_INITIATED_CRASHBug Check Code : 0x000000e2Parameter 1 : 0x00000000Parameter 2 : 0x00000000Parameter 3 : 0x00000000Parameter 4 : 0x00000000Caused By Driver : i8042prt.sysCaused By Address : i8042prt.sys+27fbFile Description : i8042 Port DriverProduct Name : Microsoft® Windows® Operating SystemCompany : Microsoft CorporationFile Version : 5.1.2600.5512 (xpsp.080413-2108)Processor : 32-bitComputer Name : Full Path : C:\WINDOWS\minidump\Mini062110-01.dmp==================================================Send the information from the last 5 memory dumps.Do, or do not. There is no try.I decided to save up points for a new puppy instead of a pony!
Free Windows Admin Tool Kit Click here and download it now
December 27th, 2010 6:26am

OS Name: Microsoft Windows XP ProfessionalOS Version: 5.1.2600 Service Pack 3 Build 2600System Manufacturer: Hewlett-PackardSystem Model: Compaq 420System type: X86-based PCProcessor(s): 1 Processor(s) Installed. [01]: x86 Family 6 Model 23 Stepping 10 GenuineIntel ~2094 Mhz I have McCafe virusscan enterprise+antiSpyware 8.7.0Iand Cisco Security agent. also running spybot search and destroyI got a BSOD while starting the machine, I had similar issue before and I see total of 10 system log entries of save dump in event viewer.after the last BSOD i removed some items from startup and BSOD never happened.
December 28th, 2010 4:33am

================================================== Dump File : Mini122410-03.dmp Crash Time : 12/25/2010 3:27:36 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x00000804 Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122410-03.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini122410-02.dmp Crash Time : 12/25/2010 12:44:02 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x00000a5c Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122410-02.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini122310-01.dmp Crash Time : 12/24/2010 10:46:48 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x0000019c Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122310-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini122210-02.dmp Crash Time : 12/22/2010 7:20:54 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x00000744 Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122210-02.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini122210-01.dmp Crash Time : 12/22/2010 6:51:36 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x000008ac Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122210-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini121610-01.dmp Crash Time : 12/16/2010 4:13:04 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x000008d4 Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini121610-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini121510-02.dmp Crash Time : 12/15/2010 6:01:59 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x000008d4 Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini121510-02.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini121510-01.dmp Crash Time : 12/15/2010 5:59:09 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x0000076c Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini121510-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini121310-01.dmp Crash Time : 12/14/2010 2:29:19 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x00000794 Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini121310-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini120910-01.dmp Crash Time : 12/10/2010 8:19:46 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x00000a8c Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini120910-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini120610-01.dmp Crash Time : 12/7/2010 3:08:59 AM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x1000000a Parameter 1 : 0x000008ac Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+28a24 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini120610-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini122710-01.dmp Crash Time : 12/27/2010 2:47:35 PM Bug Check String : IRQL_NOT_LESS_OR_EQUAL Bug Check Code : 0x0000000a Parameter 1 : 0x00000b8c Parameter 2 : 0x0000001c Parameter 3 : 0x00000000 Parameter 4 : 0x804ffa24 Caused By Driver : ntkrnlpa.exe Caused By Address : ntkrnlpa.exe+6d728 File Description : NT Kernel & System Product Name : Microsoft Windows Operating System Company : Microsoft Corporation File Version : 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122710-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 65,536 ================================================== ================================================== Dump File : Mini122410-01.dmp Crash Time : 12/25/2010 12:29:17 AM Bug Check String : BAD_POOL_CALLER Bug Check Code : 0x000000c2 Parameter 1 : 0x00000007 Parameter 2 : 0x00000cd4 Parameter 3 : 0x85c5d608 Parameter 4 : 0x9c91ac5c Caused By Driver : ihrubjxi.sys Caused By Address : ihrubjxi.sys+39f4 File Description : Product Name : Company : File Version : Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini122410-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 106,496 ================================================== ================================================== Dump File : Mini120410-01.dmp Crash Time : 12/5/2010 12:00:21 AM Bug Check String : THREAD_STUCK_IN_DEVICE_DRIVER Bug Check Code : 0x000000ea Parameter 1 : 0x852e77d8 Parameter 2 : 0x889744f0 Parameter 3 : 0x88375360 Parameter 4 : 0x00000001 Caused By Driver : igxpdv32.DLL Caused By Address : igxpdv32.DLL+f1bf File Description : Component GHAL Driver Product Name : Intel Graphics Accelerator Drivers for Windows XP(R) Company : Intel Corporation File Version : 6.14.10.5225 Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini120410-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 2600 Dump File Size : 69,908 ==================================================
Free Windows Admin Tool Kit Click here and download it now
December 28th, 2010 4:37am

Information related to Bug Check Code 0xAhttp://msdn.microsoft.com/en-us/library/ff560129(v=VS.85).aspxigxpdv32.DLL is an Intel driver related to graphics.Ah!ihrubjxi.sys gets no results from a Google search!I would starting checking for malware. Hope this helps, Gerry Cornell
December 28th, 2010 5:41am

Loading Dump File [C:\WINDOWS\MEMORY.DMP]Kernel Summary Dump File: Only kernel address space is availableSymbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbolsExecutable search path is: Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSBuilt by: 2600.xpsp_sp3_gdr.100427-1636Machine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Tue Dec 28 18:09:27.203 2010 (UTC + 5:30)System Uptime: 0 days 0:00:27.875Loading Kernel Symbols................................................................................................................................Loading User SymbolsLoading unloaded module list...******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck A, {19c, 1c, 0, 804ffa24}Probably caused by : ntkrpamp.exe ( nt!KiInsertQueueApc+6c )Followup: MachineOwner---------0: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 0000019c, memory referencedArg2: 0000001c, IRQLArg3: 00000000, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 804ffa24, address which referenced memoryDebugging Details:------------------READ_ADDRESS: 0000019c CURRENT_IRQL: 1cFAULTING_IP: nt!KiInsertQueueApc+6c804ffa24 8b5f04 mov ebx,dword ptr [edi+4]DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: SystemTRAP_FRAME: a3217cb4 -- (.trap 0xffffffffa3217cb4)ErrCode = 00000000eax=896e8ad8 ebx=00000001 ecx=8757ff84 edx=00000001 esi=8757ff84 edi=00000198eip=804ffa24 esp=a3217d28 ebp=a3217d38 iopl=0 nv up ei pl nz ac pe nccs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010216nt!KiInsertQueueApc+0x6c:804ffa24 8b5f04 mov ebx,dword ptr [edi+4] ds:0023:0000019c=????????Resetting default scopeLAST_CONTROL_TRANSFER: from 804ffa24 to 80544728STACK_TEXT: a3217cb4 804ffa24 badb0d00 00000001 00000008 nt!KiTrap0E+0x238a3217d38 804fc4db 00000000 8a54ada8 00000000 nt!KiInsertQueueApc+0x6ca3217d58 876a940b 896e8ad8 00000000 00000000 nt!KeInsertQueueApc+0x51WARNING: Frame IP not in any known module. Following frames may be wrong.a3217dac 805cff62 00000000 00000000 00000000 0x876a940ba3217ddc 8054612e 876a9180 00000000 00000000 nt!PspSystemThreadStartup+0x3400000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16STACK_COMMAND: kbFOLLOWUP_IP: nt!KiInsertQueueApc+6c804ffa24 8b5f04 mov ebx,dword ptr [edi+4]SYMBOL_STACK_INDEX: 1SYMBOL_NAME: nt!KiInsertQueueApc+6cFOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntkrpamp.exeDEBUG_FLR_IMAGE_TIMESTAMP: 4bd6e0e8FAILURE_BUCKET_ID: 0xA_nt!KiInsertQueueApc+6cBUCKET_ID: 0xA_nt!KiInsertQueueApc+6cFollowup: MachineOwner---------0: kd> lmvm ntstart end module name804d7000 806e4000 nt (pdb symbols) c:\symbols\ntkrpamp.pdb\140D20ABBC1B433EA7BF82B979B6BF9D1\ntkrpamp.pdb Loaded symbol image file: ntkrpamp.exe Image path: ntkrpamp.exe Image name: ntkrpamp.exe Timestamp: Tue Apr 27 18:34:40 2010 (4BD6E0E8) CheckSum: 001FBA25 ImageSize: 0020D000 File version: 5.1.2600.5973 Product version: 5.1.2600.5973 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrpamp.exe OriginalFilename: ntkrpamp.exe ProductVersion: 5.1.2600.5973 FileVersion: 5.1.2600.5973 (xpsp_sp3_gdr.100427-1636) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved.0: kd> .trap 0xffffffffa3217cb4ErrCode = 00000000eax=896e8ad8 ebx=00000001 ecx=8757ff84 edx=00000001 esi=8757ff84 edi=00000198eip=804ffa24 esp=a3217d28 ebp=a3217d38 iopl=0 nv up ei pl nz ac pe nccs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010216nt!KiInsertQueueApc+0x6c:
Free Windows Admin Tool Kit Click here and download it now
December 28th, 2010 8:54am

Still its creating mini dumps. Is it any driver failure or RAM failure ?
December 29th, 2010 3:18pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics