Need BSOD help

Joined
May 7, 2010
Messages
1,279
Reaction score
141
I'm running Windows 7 Professional x64 and need help with a BSOD that happened while running a scan with SUPERAntiSpyware.I couldn't write down the error message as my pen ran out of ink. I attached the memory dump and msinfo32 files.
 

Attachments

Joined
Nov 30, 2009
Messages
1,752
Reaction score
396
1) Uninstall AMD Overdrive.

2) Uninstall Super-Antispyware as it is junk and caused your crash.

Reboot and install MSE.

Code:
NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800a0110f8
Arg3: fffff8800a010960
Arg4: fffff80002c9cfcb

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff8800a0110f8 -- (.exr 0xfffff8800a0110f8)
ExceptionAddress: fffff80002c9cfcb (nt!MmMapViewInSystemCache+0x000000000000021b)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000001
   Parameter[1]: 0000000000000098
Attempt to write to address 0000000000000098

CONTEXT:  fffff8800a010960 -- (.cxr 0xfffff8800a010960)
rax=0000000000000000 rbx=fffff68000000000 rcx=0000000000000000
rdx=0000000000000040 rsi=fffff8a0038f7838 rdi=fffff8a0038f7830
rip=fffff80002c9cfcb rsp=fffff8800a011330 rbp=fffff68000000200
 r8=fffffa8000000020  r9=0000000000000265 r10=00000000000007ff
r11=0000000000000265 r12=fffffa8006e02c10 r13=0000000000000080
r14=fffffa8006a04a50 r15=fffffa8006e02c90
iopl=0         nv up ei pl nz na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
nt!MmMapViewInSystemCache+0x21b:
fffff800`02c9cfcb 4d897d18        mov     qword ptr [r13+18h],r15 ds:002b:00000000`00000098=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  SUPERAntiSpywa

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  0000000000000098

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eab0e0
 0000000000000098 

FOLLOWUP_IP: 
Ntfs!NtfsCachedRead+180
fffff880`0123bd50 84c0            test    al,al

FAULTING_IP: 
nt!MmMapViewInSystemCache+21b
fffff800`02c9cfcb 4d897d18        mov     qword ptr [r13+18h],r15

BUGCHECK_STR:  0x24

DEFAULT_BUCKET_ID:  NULL_CLASS_PTR_DEREFERENCE

LAST_CONTROL_TRANSFER:  from fffff80002c9c407 to fffff80002c9cfcb
--------

When done, open an elevated command prompt. Run this command from it:

chkdsk /r
 
Joined
May 7, 2010
Messages
1,279
Reaction score
141
Already have MSE

I'm uninstallung SUPERAntiSpyware and AMD Overdrive after I post this reply. I already use MSE. Thanks TorrentG. P.s> I also updated ShockWave as Adobe put a update out for it today.
1) Uninstall AMD Overdrive.

2) Uninstall Super-Antispyware as it is junk and caused your crash.

Reboot and install MSE.

Code:
NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800a0110f8
Arg3: fffff8800a010960
Arg4: fffff80002c9cfcb
 
Debugging Details:
------------------
 
 
EXCEPTION_RECORD:  fffff8800a0110f8 -- (.exr 0xfffff8800a0110f8)
ExceptionAddress: fffff80002c9cfcb (nt!MmMapViewInSystemCache+0x000000000000021b)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000001
   Parameter[1]: 0000000000000098
Attempt to write to address 0000000000000098
 
CONTEXT:  fffff8800a010960 -- (.cxr 0xfffff8800a010960)
rax=0000000000000000 rbx=fffff68000000000 rcx=0000000000000000
rdx=0000000000000040 rsi=fffff8a0038f7838 rdi=fffff8a0038f7830
rip=fffff80002c9cfcb rsp=fffff8800a011330 rbp=fffff68000000200
 r8=fffffa8000000020  r9=0000000000000265 r10=00000000000007ff
r11=0000000000000265 r12=fffffa8006e02c10 r13=0000000000000080
r14=fffffa8006a04a50 r15=fffffa8006e02c90
iopl=0         nv up ei pl nz na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
nt!MmMapViewInSystemCache+0x21b:
fffff800`02c9cfcb 4d897d18        mov     qword ptr [r13+18h],r15 ds:002b:00000000`00000098=????????????????
Resetting default scope
 
CUSTOMER_CRASH_COUNT:  1
 
PROCESS_NAME:  SUPERAntiSpywa
 
CURRENT_IRQL:  0
 
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
 
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
 
EXCEPTION_PARAMETER1:  0000000000000001
 
EXCEPTION_PARAMETER2:  0000000000000098
 
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eab0e0
 0000000000000098 
 
FOLLOWUP_IP: 
Ntfs!NtfsCachedRead+180
fffff880`0123bd50 84c0            test    al,al
 
FAULTING_IP: 
nt!MmMapViewInSystemCache+21b
fffff800`02c9cfcb 4d897d18        mov     qword ptr [r13+18h],r15
 
BUGCHECK_STR:  0x24
 
DEFAULT_BUCKET_ID:  NULL_CLASS_PTR_DEREFERENCE
 
LAST_CONTROL_TRANSFER:  from fffff80002c9c407 to fffff80002c9cfcb
--------

When done, open an elevated command prompt. Run this command from it:

chkdsk /r
 
Joined
Nov 30, 2009
Messages
1,752
Reaction score
396
Get rid of SpywareBlaster. Another unnecessary software...

Code:
CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  spywareblaster

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff800029fb0bf
Post new crashes if they happen.

-------

I'd also remove all of the other junk spyware/malware scanners you have. Leave only MSE and Malwarebytes.

pctgntdi64 pctgntdi64.sys Wed Jan 06 19:59:33 2010
pctNdis64 pctNdis64.sys Wed Jan 06 19:21:38 2010
PctWfpFilter64 PctWfpFilter64.sys Wed Jan 06 20:07:09 2010

ImageSize: 00008000
fffff880`010a5000 fffff880`010b6000 TfSysMon.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00011000
fffff880`01091000 fffff880`010a5000 TfFsMon.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00014000
 
Last edited:

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top