I'm running XP sp3. When I search HKEY_USER, I get a BSOD Page_Fault in Non-paged area (0x00000050) error. Here's what I've done so far:
Logged on in Safe Mode
Logged on as another user
Swapped out memory
Disconnected everything but the primary drive
Bought a new hard drive (!) and cloned it
Put the original hard drive in a different computer (so it's not hardware related)
Used one of those registry analyzers
Booted from UBCD and ran a remote registry program to search that key.
None of the above worked. Every single time, it crashes. The dump is below my signature. They're all the same, and I can reproduce it easily by doing a search. It only affects that one key.
BTW - I can't run certain programs, like Old Timer File Cleaner, Driver Verifier or GMER. I'm thinking it's all connected, but don't know how or why. Malwarebytes and Avast come up clean, so it's probably not a virus/spyware.
Thanks very much for your attention,
- Russ
BugCheck 10000050, {fffffbf8, 0, 8054b51a, 0}
Could not read faulting driver name
Probably caused by : ntkrpamp.exe ( nt!ExFreePoolWithTag+23a )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffbf8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8054b51a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: fffffbf8
FAULTING_IP:
nt!ExFreePoolWithTag+23a
8054b51a 668b4efa mov cx,word ptr [esi-6]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 6
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: regedit.exe
LAST_CONTROL_TRANSFER: from 806339d3 to 8054b51a
STACK_TEXT:
a3b2ac3c 806339d3 fffffbfe 00000000 e297c008 nt!ExFreePoolWithTag+0x23a
a3b2ac58 80634001 e29757d8 e297c008 e102daa4 nt!CmpCleanUpKcbValueCache+0x51
a3b2ac6c 8063c6bc e29757d8 e2fa4b60 8063c7d8 nt!CmpCleanUpKcbCacheWithLock+0x19
a3b2ac78 8063c7d8 a3b2ac8c 80634106 e297c008 nt!CmpGetDelayedCloseIndex+0x16
a3b2ac80 80634106 e297c008 a3b2ac98 80634548 nt!CmpAddToDelayedClose+0xa
a3b2ac8c 80634548 e297c008 a3b2acb0 80636fda nt!CmpDereferenceKeyControlBlockWithLock+0x48
a3b2ac98 80636fda e297c008 e3348700 e3348710 nt!CmpDereferenceKeyControlBlock+0x12
a3b2acb0 805bb466 e3348728 00000000 e3348710 nt!CmpDeleteKeyObject+0x92
a3b2accc 805266ca e3348728 00000000 000000ec nt!ObpRemoveObjectRoutine+0xe0
a3b2ace4 805bc33b 897d8348 e16703c8 898a2030 nt!ObfDereferenceObject+0x4c
a3b2acfc 805bc3d1 e16703c8 e3348728 000000ec nt!ObpCloseHandleTableEntry+0x155
a3b2ad44 805bc509 000000ec 00000001 00000000 nt!ObpCloseHandle+0x87
a3b2ad58 8054161c 000000ec 0007f440 7c90e4f4 nt!NtClose+0x1d
a3b2ad58 7c90e4f4 000000ec 0007f440 7c90e4f4 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0007f440 00000000 00000000 00000000 00000000 0x7c90e4f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExFreePoolWithTag+23a
8054b51a 668b4efa mov cx,word ptr [esi-6]
SYMBOL_STACK_INDEX: 0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4802516a
SYMBOL_NAME: nt!ExFreePoolWithTag+23a
FAILURE_BUCKET_ID: 0x50_nt!ExFreePoolWithTag+23a
BUCKET_ID: 0x50_nt!ExFreePoolWithTag+23a
Followup: MachineOwner
---------