Share via

New computer BSOD

Anonymous
2023-11-28T13:59:52+00:00

I put together a new computer last week and I have been getting blue screens almost everyday. At first it looked liked like it was always in a game my daughter was playing. I uninstalled it and it seemed to stop but it looks like maybe they were just less frequent.

I have the dumps from the last two crashes. Thank you in advance for your time and any input.

Microsoft (R) Windows Debugger Version 10.0.22621.2428 AMD64

Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\audre\OneDrive\Desktop\dumps\112623-6468-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*

Executable search path is:

Windows 10 Kernel Version 22621 MP (16 procs) Free x64

Product: WinNt, suite: TerminalServer SingleUserTS

Edition build lab: 22621.1.amd64fre.ni_release.220506-1250

Machine Name:

Kernel base = 0xfffff8002ba00000 PsLoadedModuleList = 0xfffff8002c6134a0

Debug session time: Sun Nov 26 18:35:19.397 2023 (UTC - 5:00)

System Uptime: 0 days 0:17:50.125

Loading Kernel Symbols

...............................................................

................................................................

................................................................

.

Loading User Symbols

Loading unloaded module list

.........

For analysis of this file, run !analyze -v

6: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)

An attempt was made to write to readonly memory. The guilty driver is on the

stack trace (and is typically the current instruction pointer).

When possible, the guilty driver's name (Unicode string) is printed on

the BugCheck screen and saved in KiBugCheckDriver.

Arguments:

Arg1: ffff98830a080168, Virtual address for the attempted write.

Arg2: 8a0000007be00121, PTE contents.

Arg3: fffff60ee1c59f20, (reserved)

Arg4: 000000000000000a, (reserved)

Debugging Details:


KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec 

Value: 1000 

Key  : Analysis.DebugAnalysisManager 

Value: Create 

Key  : Analysis.Elapsed.mSec 

Value: 1005 

Key  : Analysis.Init.CPU.mSec 

Value: 342 

Key  : Analysis.Init.Elapsed.mSec 

Value: 35623 

Key  : Analysis.Memory.CommitPeak.Mb 

Value: 92 

Key  : WER.OS.Branch 

Value: ni\_release 

Key  : WER.OS.Timestamp 

Value: 2022-05-06T12:50:00Z 

Key  : WER.OS.Version 

Value: 10.0.22621.1 

FILE_IN_CAB: 112623-6468-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b

BUGCHECK_CODE: be

BUGCHECK_P1: ffff98830a080168

BUGCHECK_P2: 8a0000007be00121

BUGCHECK_P3: fffff60ee1c59f20

BUGCHECK_P4: a

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: System

TRAP_FRAME: fffff60ee1c59f20 -- (.trap 0xfffff60ee1c59f20)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=ffff988000000000 rbx=0000000000000000 rcx=ffff98830a080150

rdx=ffffa47ffffe8f90 rsi=0000000000000000 rdi=0000000000000000

rip=fffff8002bc955f2 rsp=fffff60ee1c5a0b0 rbp=0000000000000000

r8=0000000010358007 r9=0000003ffffff853 r10=0000000000000001

r11=ffff988000000000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0 nv up ei ng nz na po cy

nt!MiAcquirePageListLock+0x152:

fffff8002bc955f2 f0480fba69183f lock bts qword ptr [rcx+18h],3Fh ds:ffff98830a080168=????????????????

Resetting default scope

STACK_TEXT:

fffff60ee1c59da8 fffff8002bec5842 : 00000000000000be ffff98830a080168 8a0000007be00121 fffff60ee1c59f20 : nt!KeBugCheckEx

fffff60ee1c59db0 fffff8002bc62e53 : 8a0000007be00121 0000000000000003 fffff60ee1c59eb9 0000000000000000 : nt!MiRaisedIrqlFault+0x1811f2

fffff60ee1c59e00 fffff8002be27529 : 0000000000000000 0000000000000001 0000000000000000 0000000000000000 : nt!MmAccessFault+0x363

fffff60ee1c59f20 fffff8002bc955f2 : fffff60ee1c5a280 fffff8002bc49a7b ffffa47ffffe8f60 fffff8002bc9c7d0 : nt!KiPageFault+0x369

fffff60ee1c5a0b0 fffff8002bc94953 : fffff8002c66bd38 0000000000000000 ffff988000000001 0000000000000004 : nt!MiAcquirePageListLock+0x152

fffff60ee1c5a150 fffff8002bc88890 : 0000000000000000 fffff8002c66bd58 fffff8002c66b008 0000000000000000 : nt!MiUnlinkPageFromListEx+0x223

fffff60ee1c5a330 fffff8002bc892b5 : ffff988017364180 0000000000000000 fffff80000000000 ffffab0581167040 : nt!MiRelinkStandbyPage+0x20

fffff60ee1c5a360 fffff8002bd1ee89 : fffff8002c66b000 0000000000000002 fffff8002c66b000 ffffab058105c2a0 : nt!MiEmptyDecayClusterTimers+0x285

fffff60ee1c5a3c0 fffff8002bd921b0 : 0000000000000003 0000000000000003 00000000ffffffff fffff8002bd92060 : nt!MiWorkingSetManager+0x89

fffff60ee1c5a480 fffff8002bd07287 : ffffab0581156040 0000000000000080 fffff8002c66b000 0000000000000000 : nt!KeBalanceSetManager+0x150

fffff60ee1c5a570 fffff8002be1b8e4 : fffff80025e3a180 ffffab0581156040 fffff8002bd07230 0000000000000000 : nt!PspSystemThreadStartup+0x57

fffff60ee1c5a5c0 0000000000000000 : fffff60ee1c5b000 fffff60ee1c54000 0000000000000000 0000000000000000 : nt!KiStartSystemThread+0x34

SYMBOL_NAME: nt!MiRaisedIrqlFault+1811f2

MODULE_NAME: nt

IMAGE_VERSION: 10.0.22621.2715

STACK_COMMAND: .cxr; .ecxr ; kb

IMAGE_NAME: ntkrnlmp.exe

BUCKET_ID_FUNC_OFFSET: 1811f2

FAILURE_BUCKET_ID: AV_nt!MiRaisedIrqlFault

OS_VERSION: 10.0.22621.1

BUILDLAB_STR: ni_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}

Followup: MachineOwner



Microsoft (R) Windows Debugger Version 10.0.22621.2428 AMD64

Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\audre\Desktop\dumps\112723-6296-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*

Executable search path is:

Windows 10 Kernel Version 22621 MP (16 procs) Free x64

Product: WinNt, suite: TerminalServer SingleUserTS

Edition build lab: 22621.1.amd64fre.ni_release.220506-1250

Machine Name:

Kernel base = 0xfffff8060dc00000 PsLoadedModuleList = 0xfffff8060e8134a0

Debug session time: Mon Nov 27 18:42:09.177 2023 (UTC - 5:00)

System Uptime: 0 days 0:09:42.957

Loading Kernel Symbols

...............................................................

................................................................

................................................................

.

Loading User Symbols

Loading unloaded module list

..........

For analysis of this file, run !analyze -v

13: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If a kernel debugger is available get the stack backtrace.

Arguments:

Arg1: ffff988fd3d55378, memory referenced

Arg2: 0000000000000002, IRQL

Arg3: 0000000000000000, bitfield :

bit 0 : value 0 = read operation, 1 = write operation

bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)

Arg4: fffff8060de341e9, address which referenced memory

Debugging Details:


KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec 

Value: 1171 

Key  : Analysis.DebugAnalysisManager 

Value: Create 

Key  : Analysis.Elapsed.mSec 

Value: 2664 

Key  : Analysis.Init.CPU.mSec 

Value: 327 

Key  : Analysis.Init.Elapsed.mSec 

Value: 208928 

Key  : Analysis.Memory.CommitPeak.Mb 

Value: 94 

Key  : WER.OS.Branch 

Value: ni\_release 

Key  : WER.OS.Timestamp 

Value: 2022-05-06T12:50:00Z 

Key  : WER.OS.Version 

Value: 10.0.22621.1 

FILE_IN_CAB: 112723-6296-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b

BUGCHECK_CODE: a

BUGCHECK_P1: ffff988fd3d55378

BUGCHECK_P2: 2

BUGCHECK_P3: 0

BUGCHECK_P4: fffff8060de341e9

READ_ADDRESS: fffff8060e91d470: Unable to get MiVisibleState

Unable to get NonPagedPoolStart

Unable to get NonPagedPoolEnd

Unable to get PagedPoolStart

Unable to get PagedPoolEnd

unable to get nt!MmSpecialPagesInUse

ffff988fd3d55378

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

TRAP_FRAME: ffff958dc1b6f0c0 -- (.trap 0xffff958dc1b6f0c0)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=ffff988fd3d55378 rbx=0000000000000000 rcx=ffff988fbdc520c0

rdx=ffff988fba9d43b8 rsi=0000000000000000 rdi=0000000000000000

rip=fffff8060de341e9 rsp=ffff958dc1b6f250 rbp=ffff988fbdc520c0

r8=0000000000000001 r9=0000000000000000 r10=0000fffff8060d00

r11=ffffbb7f10000000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0 nv up ei pl zr na po nc

nt!MiAcquirePageListLock+0x152+0xad:

fffff8060de341e9 483930 cmp qword ptr [rax],rsi ds:ffff988fd3d55378=????????????????

Resetting default scope

STACK_TEXT:

ffff958dc1b6ef78 fffff8060e02bfa9 : 000000000000000a ffff988fd3d55378 0000000000000002 0000000000000000 : nt!KeBugCheckEx

ffff958dc1b6ef80 fffff8060e027634 : 0000000000002000 000000e27a4e2000 0000000000007ef5 fffff8060e308ed9 : nt!KiBugCheckDispatch+0x69

ffff958dc1b6f0c0 fffff8060de341e9 : ffff988fbaaa7080 ffff988fbaaa7080 8000000000000000 01da218b563bc46b : nt!KiPageFault+0x474

ffff958dc1b6f250 fffff8060e2dc517 : ffff988fbaaa7508 0000000000000000 ffff988fbaaa7508 0000000000000001 : nt!KeTerminateThread+0xad

ffff958dc1b6f2d0 fffff8060e370633 : 0000000000000000 0000000000000000 ffff988fbaaa70f4 000000e27a4e2000 : nt!PspExitThread+0x4c3

ffff958dc1b6f3d0 fffff8060e3705ba : 0000000000000000 0000000000000000 ffff988fbaaa7080 fffff8060e3403c9 : nt!PspTerminateThreadByPointer+0x53

ffff958dc1b6f410 fffff8060e02b6e8 : 0000000000000000 ffff988fbaaa7080 ffff958dc1b6f4e0 ffff988f00000000 : nt!NtTerminateThread+0x4a

ffff958dc1b6f460 00007ffc009afdd4 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x28

000000e2008ff808 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffc`009afdd4

SYMBOL_NAME: nt!KeTerminateThread+ad

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.2715

STACK_COMMAND: .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET: ad

FAILURE_BUCKET_ID: AV_nt!KeTerminateThread

OS_VERSION: 10.0.22621.1

BUILDLAB_STR: ni_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {e9aa2360-26b8-46e4-6467-1da7154b7f5a}

Followup: MachineOwner


Windows for home | Windows 11 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-28T17:35:29+00:00

    Here is a link to the dump files. I included a screenshot as a sanity check on the windows version.

    Thanks again!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-11-28T14:39:14+00:00

    I can upload the dump files later tonight but I assure you it is windows 11 installed on the computer. But I do see what you mean when you say it indicates windows 10. That confuses me.

    Thank you

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-28T14:32:00+00:00

    The content you have shown doesnt say anything usefull other than say that its win 10 and you have posted to a win11 group.

    You would need to upload the dmp file to a file sharing site, and post the link here, in a post

    Was this answer helpful?

    0 comments No comments