BSOD's Posting Mini Dumps

Hashwagon

Honorable
Apr 24, 2012
120
0
10,710
Hello,

I have laptop I've been working on that keeps blue screening. A month or so ago I decided to reinstall Windows and the BSOD's came right back. To rule out it wasn't a HDD I swapped another in an through Windows on it and wham, the same thing. I have the mini dumps from the OS on the old HDD and the new and both are pointing to csrss.exe. I'm not very new at these dump files so I'm seeing if anyone here can chime in an help out if possible. Any help would be greatly appreciated.

System Specs:
Asus G73J ROG Laptop
Windows 7 Home Premium 64 bit

This mini dump is from the fresh install on a new HDD. It happened after the 1st restart in Windows if I recall.

Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`0285d000 PsLoadedModuleList = 0xfffff800`02aa2e90
Debug session time: Thu Dec 12 21:54:42.997 2013 (UTC - 7:00)
System Uptime: 0 days 0:02:46.012
Loading Kernel Symbols
...............................................................
................................................................
.......
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck F4, {3, fffffa8006f7b540, fffffa8006f7b820, fffff80002be0db0}

----- ETW minidump data unavailable-----
Probably caused by : csrss.exe

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa8006f7b540, Terminating object
Arg3: fffffa8006f7b820, Process image file name
Arg4: fffff80002be0db0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: fffffa8006f7b540

IMAGE_NAME: csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MODULE_NAME: csrss

FAULTING_MODULE: 0000000000000000

PROCESS_NAME: csrss.exe

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

BUGCHECK_STR: 0xF4_c0000005

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

CURRENT_IRQL: 0

STACK_TEXT:
fffff880`0507b0e8 fffff800`02c65982 : 00000000`000000f4 00000000`00000003 fffffa80`06f7b540 fffffa80`06f7b820 : nt!KeBugCheckEx
fffff880`0507b0f0 fffff800`02c130ab : ffffffff`ffffffff fffffa80`06d38b60 fffffa80`06f7b540 fffffa80`06f7b540 : nt!PspCatchCriticalBreak+0x92
fffff880`0507b130 fffff800`02b96698 : ffffffff`ffffffff 00000000`00000001 fffffa80`06f7b540 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17ad6
fffff880`0507b180 fffff800`028dc8d3 : fffffa80`06f7b540 fffff800`c0000005 fffffa80`06d38b60 00000000`007c09e0 : nt!NtTerminateProcess+0xf4
fffff880`0507b200 fffff800`028d8e70 : fffff800`0292911f fffff880`0507bb78 fffff880`0507b8d0 fffff880`0507bc20 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0507b398 fffff800`0292911f : fffff880`0507bb78 fffff880`0507b8d0 fffff880`0507bc20 00000000`77909c12 : nt!KiServiceLinkage
fffff880`0507b3a0 fffff800`028dccc2 : fffff880`0507bb78 00000000`00000000 fffff880`0507bc20 00000000`007c10e8 : nt! ?? ::FNODOBFM::`string'+0x49974
fffff880`0507ba40 fffff800`028db83a : 00000000`00000001 00000000`007c0f98 00000000`00000001 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`0507bc20 00000000`77909ac6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
00000000`007c0fa0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77909ac6


STACK_COMMAND: kb

FOLLOWUP_NAME: MachineOwner

FAILURE_BUCKET_ID: X64_0xF4_c0000005_IMAGE_csrss.exe

BUCKET_ID: X64_0xF4_c0000005_IMAGE_csrss.exe

Followup: MachineOwner
---------
 

Hashwagon

Honorable
Apr 24, 2012
120
0
10,710
Here's a random one from his old HDD. Each one I've checked mentions csrss.exe.

Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532
Machine Name:
Kernel base = 0xfffff800`02c59000 PsLoadedModuleList = 0xfffff800`02e9c6d0
Debug session time: Sat Dec 7 17:21:37.970 2013 (UTC - 7:00)
System Uptime: 0 days 0:01:28.016
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck F4, {3, fffffa8006c8c720, fffffa8006c8ca00, fffff80002fd37b0}

----- ETW minidump data unavailable-----
Probably caused by : csrss.exe

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa8006c8c720, Terminating object
Arg3: fffffa8006c8ca00, Process image file name
Arg4: fffff80002fd37b0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: fffffa8006c8c720

IMAGE_NAME: csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MODULE_NAME: csrss

FAULTING_MODULE: 0000000000000000

PROCESS_NAME: csrss.exe

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

BUGCHECK_STR: 0xF4_c0000005

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

CURRENT_IRQL: 0

STACK_TEXT:
fffff880`03e120e8 fffff800`0305cab2 : 00000000`000000f4 00000000`00000003 fffffa80`06c8c720 fffffa80`06c8ca00 : nt!KeBugCheckEx
fffff880`03e120f0 fffff800`03007abb : ffffffff`ffffffff fffffa80`079d6060 fffffa80`06c8c720 fffffa80`06c8c720 : nt!PspCatchCriticalBreak+0x92
fffff880`03e12130 fffff800`02f87674 : ffffffff`ffffffff 00000000`00000001 fffffa80`06c8c720 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17486
fffff880`03e12180 fffff800`02ccde53 : fffffa80`06c8c720 fffff800`c0000005 fffffa80`079d6060 00000000`00aa0890 : nt!NtTerminateProcess+0xf4
fffff880`03e12200 fffff800`02cca410 : fffff800`02d1982f fffff880`03e12b78 fffff880`03e128d0 fffff880`03e12c20 : nt!KiSystemServiceCopyEnd+0x13
fffff880`03e12398 fffff800`02d1982f : fffff880`03e12b78 fffff880`03e128d0 fffff880`03e12c20 00000000`00aa20d0 : nt!KiServiceLinkage
fffff880`03e123a0 fffff800`02cce242 : fffff880`03e12b78 00000000`00013600 fffff880`03e12c20 00000000`00aa1ba8 : nt! ?? ::FNODOBFM::`string'+0x488e4
fffff880`03e12a40 fffff800`02cccdba : 00000000`00000001 00000000`00aa0e48 00000000`76f4ff01 00000000`00013600 : nt!KiExceptionDispatch+0xc2
fffff880`03e12c20 00000000`76e48e5d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
00000000`00aa0e50 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76e48e5d


STACK_COMMAND: kb

FOLLOWUP_NAME: MachineOwner

FAILURE_BUCKET_ID: X64_0xF4_c0000005_IMAGE_csrss.exe

BUCKET_ID: X64_0xF4_c0000005_IMAGE_csrss.exe

Followup: MachineOwner
---------