F5F Stay Refreshed Hardware Desktop Error screen with dump file included.

Error screen with dump file included.

Error screen with dump file included.

C
Chito25
Member
57
05-13-2023, 12:13 PM
#1
Trying to figure out why I BSOD on my PC startup. Typing this now from the PC as it started up the second time but want to get to the root of the issue. Had some crashing issues a few months ago. The crashes were during attempted shutdowns. Don't recall what from. Believe I did an in place install which resolved the issue. Now I'm encountering a BSOD at startup. Here is my dump file. Any advice would be appreciated. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* ATTEMPTED_WRITE_TO_READONLY_MEMORY (be) An attempt was made to write to readonly memory. The guilty driver is on the stack trace (and is typically the current instruction pointer). When possible, the guilty driver's name (Unicode string) is printed on the BugCheck screen and saved in KiBugCheckDriver. Arguments: Arg1: ffff8d000640ced8, Virtual address for the attempted write. Arg2: 8a00000000200121, PTE contents. Arg3: ffffae03b61246e0, (reserved) Arg4: 000000000000000a, (reserved) Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 780 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 4191 Key : Analysis.IO.Other.Mb Value: 15 Key : Analysis.IO.Read.Mb Value: 0 Key : Analysis.IO.Write.Mb Value: 32 Key : Analysis.Init.CPU.mSec Value: 483 Key : Analysis.Init.Elapsed.mSec Value: 26675 Key : Analysis.Memory.CommitPeak.Mb Value: 103 Key : Bugcheck.Code.DumpHeader Value: 0xbe Key : Bugcheck.Code.KiBugCheckData Value: 0xbe Key : Bugcheck.Code.Register Value: 0xbe Key : WER.OS.Branch Value: ni_release Key : WER.OS.Timestamp Value: 2022-05-06T12:50:00Z Key : WER.OS.Version Value: 10.0.22621.1 FILE_IN_CAB: MEMORY.DMP BUGCHECK_CODE: be BUGCHECK_P1: ffff8d000640ced8 BUGCHECK_P2: 8a00000000200121 BUGCHECK_P3: ffffae03b61246e0 BUGCHECK_P4: a BLACKBOXBSD: 1 ( !blackboxbsd ) BLACKBOXNTFS: 1 ( !blackboxntfs ) BLACKBOXPNP: 1 ( !blackboxpnp ) BLACKBOXWINLOGON: 1 PROCESS_NAME: svchost.exe TRAP_FRAME: ffffae03b61246e0 -- (.trap 0xffffae03b61246e0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000200000 rbx=0000000000000000 rcx=0000000000600000 rdx=3fffffffffffffff rsi=0000000000000000 rdi=0000000000000000 rip=fffff8074184f39b rsp=ffffae03b6124870 rbp=ffffae03b6124969 r8=ffffb002d08f18c0 r9=ffff8d000640cee8 r10=ffff840000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na po cy nt!MiBuildForkPte+0x577: fffff807`4184f39b f0480fba2b3f lock bts qword ptr [rbx],3Fh ds:00000000`00000000=???????????????? Resetting default scope STACK_TEXT: ffffae03`b6124568 fffff807`416c00f2 : 00000000`000000be ffff8d00`0640ced8 8a000000`00200121 ffffae03`b61246e0 : nt!KeBugCheckEx ffffae03`b6124570 fffff807`4145777f : 8a000000`00200121 00000000`00000003 ffffae03`b6124679 00000000`00000000 : nt!MiRaisedIrqlFault+0x15f422 ffffae03`b61245c0 fffff807`4163a029 : 00000000`00000eff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x3af ffffae03`b61246e0 fffff807`4184f39b : 81008002`159a4867 ffffae03`00000000 9b8a1a8c`3aa00408 ffffb002`c7410000 : nt!KiPageFault+0x369 ffffae03`b6124870 fffff807`41850350 : ffffb002`d21da080 ffffb002`e1acc0c0 ffff8400`98791288 ffff8b80`05d70fb0 : nt!MiBuildForkPte+0x577 ffffae03`b61249b0 fffff807`41c3b21d : ffffb002`d21da080 ffffae03`b6124cb9 ffffb002`e1acc0c0 ffffb002`00000001 : nt!MiCloneVads+0x4b4 ffffae03`b6124c40 fffff807`41add736 : 00000000`00000000 ffffb002`d21da080 00000000`00000000 ffffb002`e1acc0c0 : nt!MiCloneProcessAddressSpace+0x271 ffffae03`b6124d20 fffff807`41ade069 : 00000000`0042ac1c ffffae03`b6125b60 00000000`00000000 ffffb002`d21da080 : nt!MmInitializeProcessAddressSpace+0x191aa6 ffffae03`b6124f10 fffff807`41a69c8e : ffffb002`dbcb9001 00000000`00000080 ffffb002`c1c94560 00000000`00000001 : nt!PspAllocateProcess+0x190731 ffffae03`b6125740 fffff807`41ba35c5 : ffff2dd5`d94a6c17 0000021e`cc010000 00000000`00000000 00000000`00000000 : nt!PspCreateProcess+0x23a ffffae03`b6125a10 fffff807`4163e1e8 : ffffb002`c1c94560 00000000`00000000 00000000`77566d4d ffffae03`b6125a00 : nt!NtCreateProcessEx+0x85 ffffae03`b6125a70 00007ff8`6322f5f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 00000082`ea5cf368 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`6322f5f4 SYMBOL_NAME: nt!MiRaisedIrqlFault+15f422 MODULE_NAME: nt STACK_COMMAND: .cxr; .ecxr ; kb IMAGE_NAME: ntkrnlmp.exe BUCKET_ID_FUNC_OFFSET: 15f422 FAILURE_BUCKET_ID: AV_nt!MiRaisedIrqlFault OS_VERSION: 10.0.22621.1 BUILDLAB_STR: ni_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 FAILURE_ID_HASH: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5} Followup: MachineOwner ---------
C
Chito25
05-13-2023, 12:13 PM #1

Trying to figure out why I BSOD on my PC startup. Typing this now from the PC as it started up the second time but want to get to the root of the issue. Had some crashing issues a few months ago. The crashes were during attempted shutdowns. Don't recall what from. Believe I did an in place install which resolved the issue. Now I'm encountering a BSOD at startup. Here is my dump file. Any advice would be appreciated. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* ATTEMPTED_WRITE_TO_READONLY_MEMORY (be) An attempt was made to write to readonly memory. The guilty driver is on the stack trace (and is typically the current instruction pointer). When possible, the guilty driver's name (Unicode string) is printed on the BugCheck screen and saved in KiBugCheckDriver. Arguments: Arg1: ffff8d000640ced8, Virtual address for the attempted write. Arg2: 8a00000000200121, PTE contents. Arg3: ffffae03b61246e0, (reserved) Arg4: 000000000000000a, (reserved) Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 780 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 4191 Key : Analysis.IO.Other.Mb Value: 15 Key : Analysis.IO.Read.Mb Value: 0 Key : Analysis.IO.Write.Mb Value: 32 Key : Analysis.Init.CPU.mSec Value: 483 Key : Analysis.Init.Elapsed.mSec Value: 26675 Key : Analysis.Memory.CommitPeak.Mb Value: 103 Key : Bugcheck.Code.DumpHeader Value: 0xbe Key : Bugcheck.Code.KiBugCheckData Value: 0xbe Key : Bugcheck.Code.Register Value: 0xbe Key : WER.OS.Branch Value: ni_release Key : WER.OS.Timestamp Value: 2022-05-06T12:50:00Z Key : WER.OS.Version Value: 10.0.22621.1 FILE_IN_CAB: MEMORY.DMP BUGCHECK_CODE: be BUGCHECK_P1: ffff8d000640ced8 BUGCHECK_P2: 8a00000000200121 BUGCHECK_P3: ffffae03b61246e0 BUGCHECK_P4: a BLACKBOXBSD: 1 ( !blackboxbsd ) BLACKBOXNTFS: 1 ( !blackboxntfs ) BLACKBOXPNP: 1 ( !blackboxpnp ) BLACKBOXWINLOGON: 1 PROCESS_NAME: svchost.exe TRAP_FRAME: ffffae03b61246e0 -- (.trap 0xffffae03b61246e0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000200000 rbx=0000000000000000 rcx=0000000000600000 rdx=3fffffffffffffff rsi=0000000000000000 rdi=0000000000000000 rip=fffff8074184f39b rsp=ffffae03b6124870 rbp=ffffae03b6124969 r8=ffffb002d08f18c0 r9=ffff8d000640cee8 r10=ffff840000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na po cy nt!MiBuildForkPte+0x577: fffff807`4184f39b f0480fba2b3f lock bts qword ptr [rbx],3Fh ds:00000000`00000000=???????????????? Resetting default scope STACK_TEXT: ffffae03`b6124568 fffff807`416c00f2 : 00000000`000000be ffff8d00`0640ced8 8a000000`00200121 ffffae03`b61246e0 : nt!KeBugCheckEx ffffae03`b6124570 fffff807`4145777f : 8a000000`00200121 00000000`00000003 ffffae03`b6124679 00000000`00000000 : nt!MiRaisedIrqlFault+0x15f422 ffffae03`b61245c0 fffff807`4163a029 : 00000000`00000eff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x3af ffffae03`b61246e0 fffff807`4184f39b : 81008002`159a4867 ffffae03`00000000 9b8a1a8c`3aa00408 ffffb002`c7410000 : nt!KiPageFault+0x369 ffffae03`b6124870 fffff807`41850350 : ffffb002`d21da080 ffffb002`e1acc0c0 ffff8400`98791288 ffff8b80`05d70fb0 : nt!MiBuildForkPte+0x577 ffffae03`b61249b0 fffff807`41c3b21d : ffffb002`d21da080 ffffae03`b6124cb9 ffffb002`e1acc0c0 ffffb002`00000001 : nt!MiCloneVads+0x4b4 ffffae03`b6124c40 fffff807`41add736 : 00000000`00000000 ffffb002`d21da080 00000000`00000000 ffffb002`e1acc0c0 : nt!MiCloneProcessAddressSpace+0x271 ffffae03`b6124d20 fffff807`41ade069 : 00000000`0042ac1c ffffae03`b6125b60 00000000`00000000 ffffb002`d21da080 : nt!MmInitializeProcessAddressSpace+0x191aa6 ffffae03`b6124f10 fffff807`41a69c8e : ffffb002`dbcb9001 00000000`00000080 ffffb002`c1c94560 00000000`00000001 : nt!PspAllocateProcess+0x190731 ffffae03`b6125740 fffff807`41ba35c5 : ffff2dd5`d94a6c17 0000021e`cc010000 00000000`00000000 00000000`00000000 : nt!PspCreateProcess+0x23a ffffae03`b6125a10 fffff807`4163e1e8 : ffffb002`c1c94560 00000000`00000000 00000000`77566d4d ffffae03`b6125a00 : nt!NtCreateProcessEx+0x85 ffffae03`b6125a70 00007ff8`6322f5f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 00000082`ea5cf368 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`6322f5f4 SYMBOL_NAME: nt!MiRaisedIrqlFault+15f422 MODULE_NAME: nt STACK_COMMAND: .cxr; .ecxr ; kb IMAGE_NAME: ntkrnlmp.exe BUCKET_ID_FUNC_OFFSET: 15f422 FAILURE_BUCKET_ID: AV_nt!MiRaisedIrqlFault OS_VERSION: 10.0.22621.1 BUILDLAB_STR: ni_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 FAILURE_ID_HASH: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5} Followup: MachineOwner ---------

L
LegoLover202
Junior Member
40
05-13-2023, 12:13 PM
#2
Review the dump files and logs to identify the problematic device or driver. Examine the analysis results to pinpoint the source of the issue. Further investigation is required.
L
LegoLover202
05-13-2023, 12:13 PM #2

Review the dump files and logs to identify the problematic device or driver. Examine the analysis results to pinpoint the source of the issue. Further investigation is required.

T
Tedix1
Member
59
05-13-2023, 12:13 PM
#3
It appears you're being directed to focus on svchost.exe as the problem source. You're wondering if your interpretation might be incorrect, especially since a driver issue wouldn't typically involve an executable file.
T
Tedix1
05-13-2023, 12:13 PM #3

It appears you're being directed to focus on svchost.exe as the problem source. You're wondering if your interpretation might be incorrect, especially since a driver issue wouldn't typically involve an executable file.