Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Getting BSOD very often lately on Windows 7!


  • Please log in to reply

#61
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts

0x0000001E: KMODE_EXCEPTION_NOT_HANDLED
The Windows kernel detected an illegal or unknown processor instruction. A Stop 0x1E condition can be caused by invalid memory and access violations similar to those that generate Stop 0xA errors. This default Windows error handler typically intercepts these problems if error-handling routines are not present in the code itself.



OK this is pointing toward Windows again as the culprit so I now need to see a Event log.

Please follow the steps below to enter the Event Viewer program in Vista\Win7. This will give me more information into what is causing your issue. You can get to Event viewer two ways and I will post both for you.


" Go to
" Start
" In the Search box type in Event Viewer in the search box and press Enter
" From this point you can follow from step four from the below method as they will be the same.
Method Two
" Go to Start
" Right click on the Computer Icon and select Manage
" Navigate to the Event Viewer, You will be prompted to accept the action you are going to perform. Click continue
" On the left window pane click on Local and then expand the Windows entry. This will allow you to see every error for the past 24 hours as well as the last 7 days in the right window pane.
" Look for the ones that correspond to the times that your issue occurred.
" If any are found please double click and expand the error. This will open and give you more information on the error.
" Please include that in your next reply.

  • 0

Advertisements


#62
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

0x0000001E: KMODE_EXCEPTION_NOT_HANDLED
The Windows kernel detected an illegal or unknown processor instruction. A Stop 0x1E condition can be caused by invalid memory and access violations similar to those that generate Stop 0xA errors. This default Windows error handler typically intercepts these problems if error-handling routines are not present in the code itself.



OK this is pointing toward Windows again as the culprit so I now need to see a Event log.

Please follow the steps below to enter the Event Viewer program in Vista\Win7. This will give me more information into what is causing your issue. You can get to Event viewer two ways and I will post both for you.


" Go to
" Start
" In the Search box type in Event Viewer in the search box and press Enter
" From this point you can follow from step four from the below method as they will be the same.Method Two
" Go to Start
" Right click on the Computer Icon and select Manage
" Navigate to the Event Viewer, You will be prompted to accept the action you are going to perform. Click continue
" On the left window pane click on Local and then expand the Windows entry. This will allow you to see every error for the past 24 hours as well as the last 7 days in the right window pane.
" Look for the ones that correspond to the times that your issue occurred.
" If any are found please double click and expand the error. This will open and give you more information on the error.
" Please include that in your next reply.




Under which tab Application, Security, Setup, System, Forwarded Events?
  • 0

#63
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
" On the left window pane click on Local and then expand the Windows entry. This will allow you to see every error for the past 24 hours as well as the last 7 days in the right window pane.
" Look for the ones that correspond to the times that your issue occurred.
" If any are found please double click and expand the error. This will open and give you more information on the error.
" Please include that in your next reply.


I'm mostly interested in system and application.
  • 0

#64
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

" On the left window pane click on Local and then expand the Windows entry. This will allow you to see every error for the past 24 hours as well as the last 7 days in the right window pane.
" Look for the ones that correspond to the times that your issue occurred.
" If any are found please double click and expand the error. This will open and give you more information on the error.
" Please include that in your next reply.


I'm mostly interested in system and application.


Ok, under system tab the error log at time of BSOD says:



Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 7/31/2013 1:08:29 AM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (2)
User: SYSTEM
Computer: Ricky-PC
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2013-07-31T05:08:29.515217600Z" />
<EventRecordID>439413</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Ricky-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">30</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event>


Another one under that is:



Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 7/31/2013 1:08:42 AM
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: RICKY-PC
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 073113-18236-01.
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-07-31T05:08:42.000000000Z" />
<EventRecordID>439410</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>RICKY-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000)</Data>
<Data Name="param2">C:\Windows\MEMORY.DMP</Data>
<Data Name="param3">073113-18236-01</Data>
</EventData>
</Event>


Under the application tab there actually isn't anything for that time.
  • 0

#65
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
Just had another BSOD a few minutes ago, looks like the same as usual except this time ndis.sys was there instead of tcpip.sys.


080113-20623-01.dmp 8/1/2013 12:50:04 AM KMODE_EXCEPTION_NOT_HANDLED 0x0000001e 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000
ndis.sys ndis.sys+878d4 x64 ntoskrnl.exe+75bd0
C:\Windows\Minidump\080113-20623-01.dmp8157601262,144



WHO CRASHED LOG:




Crash Dump Analysis
Crash dump directory: C:\Windows\Minidump

Crash dumps are enabled on your computer.

On Thu 8/1/2013 4:48:33 AM GMT your computer crashed
crash dump file: C:\Windows\Minidump\080113-20623-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x75BD0)
Bugcheck code: 0x1E (0x0, 0x0, 0x0, 0x0)
Error: KMODE_EXCEPTION_NOT_HANDLED
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Thu 8/1/2013 4:48:33 AM GMT your computer crashed
crash dump file: C:\Windows\memory.dmp
This was probably caused by the following module: ntkrnlmp.exe (nt!KeBugCheck+0x0)
Bugcheck code: 0x1E (0x0, 0x0, 0x0, 0x0)
Error: KMODE_EXCEPTION_NOT_HANDLED
file path: C:\Windows\system32\ntkrnlmp.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Wed 7/31/2013 5:07:00 AM GMT your computer crashed
crash dump file: C:\Windows\Minidump\073113-18236-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x75BD0)
Bugcheck code: 0x1E (0x0, 0x0, 0x0, 0x0)
Error: KMODE_EXCEPTION_NOT_HANDLED
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



Conclusion
3 crash dumps have been found and analyzed. No offending third party drivers have been found. Consider configuring your system to produce a full memory dump for better analysis.





EVENT VIEWER LOGS ASSOCIATED WITH BSOD:





Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 8/1/2013 12:49:54 AM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (2)
User: SYSTEM
Computer: Ricky-PC
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2013-08-01T04:49:54.574421200Z" />
<EventRecordID>439930</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Ricky-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">30</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event>






Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 8/1/2013 12:51:59 AM
Event ID: 10016
Task Category: None
Level: Error
Keywords: Classic
User: SYSTEM
Computer: Ricky-PC
Description:
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}
and APPID
{344ED43D-D086-4961-86A6-1106F4ACAD9B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="49152">10016</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-08-01T04:51:59.000000000Z" />
<EventRecordID>440023</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>Ricky-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="param1">application-specific</Data>
<Data Name="param2">Local</Data>
<Data Name="param3">Launch</Data>
<Data Name="param4">{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}</Data>
<Data Name="param5">{344ED43D-D086-4961-86A6-1106F4ACAD9B}</Data>
<Data Name="param6">NT AUTHORITY</Data>
<Data Name="param7">SYSTEM</Data>
<Data Name="param8">S-1-5-18</Data>
<Data Name="param9">LocalHost (Using LRPC)</Data>
</EventData>
</Event>






Log Name: System
Source: Service Control Manager
Date: 8/1/2013 12:50:17 AM
Event ID: 7023
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Ricky-PC
Description:
The Computer Browser service terminated with the following error:
The specified service does not exist as an installed service.
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7023</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2013-08-01T04:50:17.628387600Z" />
<EventRecordID>440010</EventRecordID>
<Correlation />
<Execution ProcessID="720" ThreadID="876" />
<Channel>System</Channel>
<Computer>Ricky-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">Computer Browser</Data>
<Data Name="param2">%%1060</Data>
</EventData>
</Event>

Edited by sour11, 31 July 2013 - 10:59 PM.

  • 0

#66
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
Again this is pointing to the same error as before.
Back at the beginning of all this I had you run in Safe Mode for a few days and you had no problems at all. That tells me it is a driver or a service being loaded in normal mode causing this.
So I want to redo some steps to double check everything.

Lets see what you have in your startup
Please click on

Start and then on Run
Type in msconfig and then press Enter
Now click on Startup
Next click on your Print Screen on your keyboard. It is normally the key above your number pad between the F12 key and the Scroll Lock key. Make sure you get everything even if you have to take more then one picture of the list.
Now go to Start
All Programs
Accessories
Paint

In the empty white area click and hold the CTRL key and then click the V
Go to the File option at the top and click on Save As
Save as file type JPEG and save it to your desktop
In your next reply attach the screenshot.
  • 0

#67
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

Again this is pointing to the same error as before.
Back at the beginning of all this I had you run in Safe Mode for a few days and you had no problems at all. That tells me it is a driver or a service being loaded in normal mode causing this.
So I want to redo some steps to double check everything.

Lets see what you have in your startup
Please click on
Start and then on Run
Type in msconfig and then press Enter
Now click on Startup
Next click on your Print Screen on your keyboard. It is normally the key above your number pad between the F12 key and the Scroll Lock key. Make sure you get everything even if you have to take more then one picture of the list.
Now go to Start
All Programs
Accessories
Paint

In the empty white area click and hold the CTRL key and then click the V
Go to the File option at the top and click on Save As
Save as file type JPEG and save it to your desktop
In your next reply attach the screenshot.


I don't have anything selected in that startup menu, but here are the SS's you requested:


Posted Image



Posted Image



Posted Image



Posted Image



Posted Image

Edited by sour11, 01 August 2013 - 02:56 PM.

  • 0

#68
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
OK first turn on all the Microsoft stuff for me. That may be part of the problem. Then reopen the startup but stretch it out so I can see the actual names please.
  • 0

#69
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

OK first turn on all the Microsoft stuff for me. That may be part of the problem. Then reopen the startup but stretch it out so I can see the actual names please.


I can't stretch the whole box out for some reason, but I got the full names of the programs, I hope thats what you need.

Posted Image


Posted Image


Posted Image



Posted Image



Posted Image

  • 0

#70
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
OK that all looks good for now. A lot of those things in the list are not needed to auto start at all. At this point it is a personal preference if you want something to auto start or not. In fact one of the errors mentioned a Microsoft service that may have been having a problem. Lets do this for the services and see what we have now.

Lets see what you have in your startup services area

Please click on
Start and then to Run
Type in msconfig and press Enter
Now click on Services
Let me know once you get to this above if you see any Service from Microsoft not clicked. DO NOT click anything till you let me know.
Click on the Hide All Microsoft Services
Then uncheck everything and restart.
If system boots correctly and is running smoothly and faster then we have a startup problem
Post back with the results
  • 0

Advertisements


#71
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

OK that all looks good for now. A lot of those things in the list are not needed to auto start at all. At this point it is a personal preference if you want something to auto start or not. In fact one of the errors mentioned a Microsoft service that may have been having a problem. Lets do this for the services and see what we have now.

Lets see what you have in your startup services area

Please click on
Start and then to Run
Type in msconfig and press Enter
Now click on Services
Let me know once you get to this above if you see any Service from Microsoft not clicked. DO NOT click anything till you let me know.
Click on the Hide All Microsoft Services
Then uncheck everything and restart.
If system boots correctly and is running smoothly and faster then we have a startup problem
Post back with the results



Every service from Microsoft is checked off. After reboot the PC is running fine. Can't say its any "faster" so to speak, but I had no problems.

Edited by sour11, 01 August 2013 - 05:40 PM.

  • 0

#72
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
I didn't know there was a speed issue. I thought this was all about the BSOD's?
  • 0

#73
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

I didn't know there was a speed issue. I thought this was all about the BSOD's?


No there was never a speed issue. I thought you when you said If system boots correctly and is running smoothly and faster then we have a startup problem, you wanted me to post if it was running faster with those things unchecked. I read it wrong sorry, just ignore that.

Edited by sour11, 01 August 2013 - 09:38 PM.

  • 0

#74
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
No problem and I'm sorry for the confusion. Any BSOD's since the changes were made?
  • 0

#75
sour11

sour11

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts

No problem and I'm sorry for the confusion. Any BSOD's since the changes were made?


So far so good! But my PC is known to go for a week with no problems then BAM BSOD lol. I hope that its finally fixed though! I'll post back here if I get a BSOD. As always thank you for your help Posted Image!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP