Windows 10: BSOD StopCode Page Fault in Nonpaged Areas Solved

Page 1 of 4 123 ... LastLast

  1. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
       02 Dec 2017 #1

    BSOD StopCode Page Fault in Nonpaged Areas


    Last night I suffered two Stopcodes in quick succession, however I did not get the details, so I shut down and had a beer. This morning again I got two Stopcodes, but managed to photograph the event:

    Click image for larger version. 

Name:	IMG_01301.jpg 
Views:	1 
Size:	751.5 KB 
ID:	166440

    I then opened a CMD window as an administrator, then typed: chkdsk /f /r, had to restart, it paused a long time (minutes) at 14% then off to 100%.
    Then again opened a CMD window as an administrator, then typed sfc /scannow, so now its a waiting game to see if it crashes again.
      My ComputersSystem Spec


  2. Posts : 5,660
    Windows 10 Pro X64 16299.192
       02 Dec 2017 #2

    Please read and follow the instructions here: Blue Screen of Death (BSOD) Posting Instructions
      My ComputersSystem Spec


  3. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
    Thread Starter
       03 Dec 2017 #3

    @Ztruker, many thanks:

    Hopefully Zip attached.
    BSOD StopCode Page Fault in Nonpaged Areas Attached Files
      My ComputersSystem Spec


  4. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
    Thread Starter
       03 Dec 2017 #4

    Point to note:
    When running the script to create the zip, at the end it informed me it was on my desktop, however it wasn't, it was in an "alternative". After thinking about this for a while I deleted this "alternative" desktop, and ran the script again, and it script create this alternative desktop:
    Click image for larger version. 

Name:	image.png 
Views:	1 
Size:	53.7 KB 
ID:	166538

    The second desktop was created after deletion of the previous second desktop, as you will see from the properties

    Click image for larger version. 

Name:	image.png 
Views:	30 
Size:	10.6 KB 
ID:	166539
      My ComputersSystem Spec


  5. Posts : 5,660
    Windows 10 Pro X64 16299.192
       03 Dec 2017 #5

    The script creates the zip based on where %userprofile% environment variable points. This is the folder associated with the jim account it looks like.

    The dump from 12/3 at 8:35Am indicates a problem with RPCRT4.dll.
    Code:
    BugCheck EF, {ffffab0cef7495c0, 0, 0, 0}
    Probably caused by : RPCRT4.dll
    The Rpcrt4.dll file is a file associated with the Remote Procedure Call program, and is used by a number of Windows applications for network and Internet connections

    The file is located here: C:\Windows\System32\rpcrt4.dll. It's properties should be:
    Click image for larger version. 

Name:	rpcrt4.dll Properties.jpg 
Views:	29 
Size:	34.1 KB 
ID:	166679

    The dumps from 12/3 at 8:31 and 8:59Am indicate a problem with BFE.DLL.
    Code:
    BugCheck EF, {ffff8f0a50fd65c0, 0, 0, 0}
    Probably caused by : bfe.dll
    The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering.

    The file is located here: C:\Windows\System32\BFE.DLL. It's properties should be:
    Click image for larger version. 

Name:	BFE.DLL Properties.jpg 
Views:	29 
Size:	30.8 KB 
ID:	166680

    The first thing to do is run a full scan with your anti-virus software. If you have Malwarebytes Anti-malware installed, run a full scan with that too.

    Next run the following commands in sequence as shown from a Administrator Command Prompt:

    Dism /Online /Cleanup-Image /StartComponentCleanup
    Dism /Online /Cleanup-Image /RestoreHealth
    SFC /scannow


    Also noticed this in the event log.

    Code:
    Event[7058]:
      Log Name: System
      Source: Microsoft-Windows-WMPNSS-Service
      Date: 2017-12-03T08:34:10.855
      Event ID: 14210
      Task: N/A
      Level: Information
      Opcode: N/A
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: JimmyB-Win10
      Description: 
    The monitored folders on media server 'jim@jimmyb.org.uk' changed.  Windows Media Player is updating security permissions for any included folders to enable media sharing.
    
    Event[7059]:
      Log Name: System
      Source: Microsoft-Windows-Kernel-General
      Date: 2017-12-03T08:35:31.697
      Event ID: 12
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: JimmyB-Win10
      Description: 
    The operating system started at system time ?2017?-?12?-?03T08:35:31.493164700Z.
    Networking and security which are what the dumps indicate as problematic. Have you changed anything in your media server setup?
      My ComputersSystem Spec


  6. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
    Thread Starter
       04 Dec 2017 #6

    Rich, many thanks:

    Currently not at home, however when I get in, as advised I will be running the anti-virus full scan, followed by the scripts as detailed.
    As to the media server, not changed anything, after re-installing 1709 in October everything has stayed the same except for updates.

    One point is yesterday the machine crashed twice whilst in "idle" i.e. started the machine, logged in and then nothing else (other homely tasks called), when I came back I new it had restarted, and the event log confirmed this!!
      My ComputersSystem Spec


  7. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
    Thread Starter
       05 Dec 2017 #7

    Rich,

    Struggling to carry out Full Scan due to crashes, managed to get 75% through, will try in safe mode:

    A copy of my BFE.DLL properties, shows a couple of differences:

    Click image for larger version. 

Name:	image.png 
Views:	22 
Size:	36.3 KB 
ID:	166824

    Date and time, but I think this is down to format and time zones; however the File Version number is different???

    rpcrt4.dll properties are identical.
      My ComputersSystem Spec


  8. Posts : 14,213
    windows 10 professional version 1607 build 14393.969 64 bit
       05 Dec 2017 #8

    The BSOD bugchecks in the logs were:
    50 Page fault in nonpaged area
    EF Critical process died
    7E System thread exception not handled

    Open administrative command prompt and type or copy and paste:
    1) sfc /scannow
    2) dism /online /cleanup-image /restorehealth
    3) chkdsk /scan
    When these have completed > right click on the top bar or title bar of the administrative command prompt box > left click on edit then select all > right click on the top bar again > left click on edit then copy > paste into the thread
    4) post into the thread the memory dump file: %SystemRoot%\MEMORY.DMP or C:\Windows\MEMORY.DMP
    Use file explorer > this PC > local C: drive > right upper corner search enter each of the above to find results > post into the thread using one drive or drop box share links.
    5) post a new zip into the thread:
    BSOD - Posting Instructions - Windows 10 Forums
    6) In the left lower corner search type: system > open system control panel > on the left pane click advanced system settings > on the advanced tab under startup and recovery click settings > post an image into the thread
    7) Un-check automatic restart
    8) Which AV products are you using. Which one has completed and which one needs to be rerun becouse it was interrupted by a bsod?

    Code:
    26/10/2017 14:03    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 1000007e
    P2: ffffffffc0000005
    P3: fffff80135332e1e
    P4: ffffc98e86296bf8
    P5: ffffc98e86296440
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\102617-5437-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11046-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F89.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F99.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FB9.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1000007e_eff42b0e34feb612e78111874bdd1620b7438e_00000000_cab_03543fb8
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: a2aa35a4-26c7-4d6e-a69b-0b407283e3d7
    Report Status: 4
    Hashed bucket:02/12/2017 11:22    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 50
    P2: ffffb083ca19ab20
    P3: 0
    P4: fffff80ed460bf9d
    P5: 2
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120217-8000-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-14875-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5091.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50B0.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50D0.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_50_632b9f3120b278b4d9727aaf2e29dd211be724_00000000_cab_039450cf
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 0ce4c818-1ca5-4c68-9d07-e0c9e80985d3
    Report Status: 4
    Hashed bucket:
    02/12/2017 11:05    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffff8808bad865c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120217-4750-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11390-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43B0.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43CF.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43EF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_dac9cb43f75f5f2df85d4a32a952611413b29_00000000_cab_038c43ee
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fec35604-ddeb-4dc3-a845-26d21469be4d
    Report Status: 4
    Hashed bucket:
    03/12/2017 08:59    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffff8f0a50fd65c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4203-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-6625-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3D95.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3DA5.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3DC5.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_297e4a36b7239bb2d5093b27ea26695f1c958b1_00000000_cab_037c3dd4
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 8c6b3296-0bb3-4bf1-959c-c521f0e870ec
    Report Status: 4
    Hashed bucket:
    01/12/2017 17:37    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffffa3056b4c75c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120117-4500-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-7015-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4110.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER412F.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER414F.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_3f295cf273b1e568dd7e8fc0e8453cacbfea5_00000000_cab_0390414e
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: b88a0567-60f5-47fe-9dce-3bcbfdb0b838
    Report Status: 4
    Hashed bucket:
    03/12/2017 08:35    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffffab0cef7495c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4875-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11890-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4611.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4621.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4641.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_ddcd247a48ae3acb21d768ac9774f76f9dfc40_00000000_cab_03844650
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 3c252447-3486-42d8-821f-a1f07e8955e6
    Report Status: 4
    Hashed bucket:
    03/12/2017 08:31    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffffc78419acb5c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4187-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11671-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43FE.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER441D.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER443D.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_5707a86b6acaf21fc0c0a8ab94b66edd566e1_00000000_cab_0384443c
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: b9eb2d1d-aa4a-458d-9dc8-b452dd82bd85
    Report Status: 4
    Hashed bucket:
    01/12/2017 17:50    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: ef
    P2: ffffcb83e3a4a5c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120117-4968-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-15406-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50BF.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50DF.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50FF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_ee304fc888ecdce2b1183aba7eb831b2af9ffd92_00000000_cab_0390510e
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 34a704a3-ea7d-4781-8e08-60aad896960e
    Report Status: 4
    Hashed bucket:
    03/12/2017 08:32    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 41483307-5a84-47b8-b87e-87cb4ae0897d
    
    Problem signature:
    P1: ef
    P2: ffffc78419acb5c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4187-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11671-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43FE.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER441D.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER443D.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_5707a86b6acaf21fc0c0a8ab94b66edd566e1_00000000_cab_0384443c
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: b9eb2d1d-aa4a-458d-9dc8-b452dd82bd85
    Report Status: 4
    Hashed bucket:
    03/12/2017 08:59    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: dceaa1c1-70d3-4fc4-98c9-3c43c176dcd7
    
    Problem signature:
    P1: ef
    P2: ffff8f0a50fd65c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4203-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-6625-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3D95.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3DA5.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3DC5.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_ef_297e4a36b7239bb2d5093b27ea26695f1c958b1_00000000_cab_037c3dd4
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 8c6b3296-0bb3-4bf1-959c-c521f0e870ec
    Report Status: 4
    Hashed bucket:
    02/12/2017 11:13    Windows Error Reporting    Fault bucket , type 0
    Event Name: ScriptedDiagFailure
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: Microsoft Corporation.BlueScreenDiagnostic.1.1
    P2: Default
    P3: 1.0.0.0
    P4: Default
    P5: 
    P6: 
    P7: 
    P8: 
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\Users\jim\AppData\Local\Temp\msdtadmin\_47B419C6-D81C-47B2-838D-10034198FCD6_\PkgF2C7.cab
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2F7.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF3F0.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF420.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_da15eef057dffa683da5341c73ad0cfb08a39b4_00000000_cab_09a9f41f
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 0d2196c8-a4a5-44ac-8b35-3a9ca07d6e93
    Report Status: 4
    Hashed bucket:
    02/12/2017 11:17    Windows Error Reporting    Fault bucket , type 0
    Event Name: ScriptedDiagFailure
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: Microsoft Corporation.DeviceDiagnostic.4.1
    P2: Default
    P3: 1.0.0.0
    P4: Default
    P5: 
    P6: 
    P7: 
    P8: 
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\Users\jim\AppData\Local\Temp\msdtadmin\_2660C2C4-ADE7-4528-AA74-1F71E45D7532_\Pkg2D12.cab
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D42.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D53.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D83.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_9749799e43fa96145ba63edd5f5ba8d696ad389_00000000_cab_32192d80
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 4999c6c4-51d5-4e04-a842-62a1c8e2adde
    Report Status: 4
    Hashed bucket:
    Code:
    03/12/2017 08:35    Windows Error Reporting    Fault bucket 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_c0000005_bfe.dll!BfeObjectFindById_IMAGE_bfe.dll, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 41483307-5a84-47b8-b87e-87cb4ae0897d
    
    Problem signature:
    P1: ef
    P2: ffffc78419acb5c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4187-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11671-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43FE.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER441D.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER443D.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_ef_5707a86b6acaf21fc0c0a8ab94b66edd566e1_00000000_cab_0a184ae3
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: b9eb2d1d-aa4a-458d-9dc8-b452dd82bd85
    Report Status: 268435460
    Hashed bucket:01/12/2017 17:38    Windows Error Reporting    Fault bucket 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_c0000005_bfe.dll!BfeObjectFindById_IMAGE_bfe.dll, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 9138a5e4-dca0-43c1-a17f-325fe6178829
    
    Problem signature:
    P1: ef
    P2: ffffa3056b4c75c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120117-4500-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-7015-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4110.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER412F.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER414F.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_ef_3f295cf273b1e568dd7e8fc0e8453cacbfea5_00000000_cab_132887dd
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: b88a0567-60f5-47fe-9dce-3bcbfdb0b838
    Report Status: 268435456
    Hashed bucket:
    01/12/2017 17:50    Windows Error Reporting    Fault bucket 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_c0000005_bfe.dll!BfeObjectFindById_IMAGE_bfe.dll, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 97505988-57a4-49f9-9b82-8414802641ae
    
    Problem signature:
    P1: ef
    P2: ffffcb83e3a4a5c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120117-4968-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-15406-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50BF.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50DF.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50FF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_ef_ee304fc888ecdce2b1183aba7eb831b2af9ffd92_00000000_cab_09f0687e
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 34a704a3-ea7d-4781-8e08-60aad896960e
    Report Status: 268435456
    Hashed bucket:
    02/12/2017 11:05    Windows Error Reporting    Fault bucket 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_c0000005_bfe.dll!BfeObjectFindById_IMAGE_bfe.dll, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: deec8dcf-f456-4117-9fd1-f8e6c37d5ad1
    
    Problem signature:
    P1: ef
    P2: ffff8808bad865c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120217-4750-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11390-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43B0.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43CF.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER43EF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_ef_dac9cb43f75f5f2df85d4a32a952611413b29_00000000_cab_09f46ddd
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fec35604-ddeb-4dc3-a845-26d21469be4d
    Report Status: 268435456
    Hashed bucket:
    03/12/2017 08:36    Windows Error Reporting    Fault bucket 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_c0000005_RPCRT4.dll!NdrpConformantStringMarshall_IMAGE_RPCRT4.dll, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 9b3c646e-f662-44ae-924a-1983269a30af
    
    Problem signature:
    P1: ef
    P2: ffffab0cef7495c0
    P3: 0
    P4: 0
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120317-4875-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11890-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4611.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4621.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4641.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_ef_ddcd247a48ae3acb21d768ac9774f76f9dfc40_00000000_cab_0a18786c
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 3c252447-3486-42d8-821f-a1f07e8955e6
    Report Status: 268435456
    Hashed bucket:
    Code:
    02/12/2017 11:13    Windows Error Reporting    Fault bucket 127915145080, type 5
    Event Name: ScriptedDiagFailure
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: Microsoft Corporation.BlueScreenDiagnostic.1.1
    P2: Default
    P3: 1.0.0.0
    P4: Default
    P5: 
    P6: 
    P7: 
    P8: 
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\Users\jim\AppData\Local\Temp\msdtadmin\_47B419C6-D81C-47B2-838D-10034198FCD6_\PkgF2C7.cab
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2F7.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF3F0.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF420.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft Corpor_da15eef057dffa683da5341c73ad0cfb08a39b4_00000000_31d5f8c2
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 0d2196c8-a4a5-44ac-8b35-3a9ca07d6e93
    Report Status: 268435456
    Hashed bucket: 6c3ebb8d12cafe7a1d859b3e218ee0c6
    Code:
    26/10/2017 14:03    Windows Error Reporting    Fault bucket AV_nt!MiAgePte, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: b50994ef-68aa-4005-b1d2-1170b7235720
    
    Problem signature:
    P1: 1000007e
    P2: ffffffffc0000005
    P3: fffff80135332e1e
    P4: ffffc98e86296bf8
    P5: ffffc98e86296440
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\102617-5437-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11046-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F89.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F99.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FB9.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000007e_eff42b0e34feb612e78111874bdd1620b7438e_00000000_cab_18247d9c
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: a2aa35a4-26c7-4d6e-a69b-0b407283e3d7
    Report Status: 268435456
    Hashed bucket:02/12/2017 11:22    Windows Error Reporting    Fault bucket AV_R_INVALID_ntfs!NtfsFcbTableCompare, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 24256c7c-7a8e-4754-9218-8950882bf63d
    
    Problem signature:
    P1: 50
    P2: ffffb083ca19ab20
    P3: 0
    P4: fffff80ed460bf9d
    P5: 2
    P6: 10_0_16299
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120217-8000-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-14875-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5091.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50B0.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER50D0.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_50_632b9f3120b278b4d9727aaf2e29dd211be724_00000000_cab_17e08cde
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 0ce4c818-1ca5-4c68-9d07-e0c9e80985d3
    Report Status: 268435456
    Hashed bucket:
    Code:
    Event[364]:  Log Name: System
      Source: Display
      Date: 2017-10-19T13:54:27.418
      Event ID: 4101
      Task: N/A
      Level: Warning
      Opcode: Info
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: JimmyB-Win10
      Description: 
    Display driver nvlddmkm stopped responding and has successfully recovered.
    Code:
    Event[1741]:  Log Name: System
      Source: Display
      Date: 2017-10-27T17:14:53.426
      Event ID: 4101
      Task: N/A
      Level: Warning
      Opcode: Info
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: JimmyB-Win10
      Description: 
    Display driver nvlddmkm stopped responding and has successfully recovered.
    Last edited by zbook; 05 Dec 2017 at 03:28.
      My ComputerSystem Spec


  9. Posts : 86
    Microsoft Windows 10 Home 64-bit/Windows 7 dual boot
    Thread Starter
       05 Dec 2017 #9

    @zbook many thanks; here are the above items in order:

    1)
    Microsoft Windows [Version 10.0.16299.98]

    (c) 2017 Microsoft Corporation. All rights reserved.
    C:\WINDOWS\system32>sfc /scannow
    Beginning system scan. This process will take some time.
    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection did not find any integrity violations.

    2)
    Microsoft Windows [Version 10.0.16299.98]
    (c) 2017 Microsoft Corporation. All rights reserved.
    C:\WINDOWS\system32>dism /online /cleanup-image /restorehealth
    Deployment Image Servicing and Management tool
    Version: 10.0.16299.15
    Image Version: 10.0.16299.98
    [==========================100.0%==========================] The restore operation completed successfully.
    The operation completed successfully.

    3)
    Microsoft Windows [Version 10.0.16299.98]

    (c) 2017 Microsoft Corporation. All rights reserved.
    C:\WINDOWS\system32>chkdsk /scan
    The type of the file system is NTFS.
    Volume label is Windows 10.
    Stage 1: Examining basic file system structure ...
    404224 file records processed.
    File verification completed.
    5324 large file records processed.
    0 bad file records processed.
    Stage 2: Examining file name linkage ...
    1667 reparse records processed.
    484020 index entries processed.
    Index verification completed.
    0 unindexed files scanned.
    0 unindexed files recovered to lost and found.
    1667 reparse records processed.
    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    39899 data files processed.
    CHKDSK is verifying Usn Journal...
    35743728 USN bytes processed.
    Usn Journal verification completed.
    Windows has scanned the file system and found no problems.
    No further action is required.
    153599999 KB total disk space.
    73234724 KB in 219192 files.
    146236 KB in 39900 indexes.
    0 KB in bad sectors.
    514083 KB in use by the system.
    65536 KB occupied by the log file.
    79704956 KB available on disk.
    4096 bytes in each allocation unit.
    38399999 total allocation units on disk.
    19926239 allocation units available on disk.

    4) Not shared onedrive hope this works!

    https://1drv.ms/u/s!Ao4RFa_AhzC3h2a4WGVawZX8q0LM

    5)

    6) Didn't understand this instruction Now found Doh!!
    7) Ergo this could not be carried out done

    8) I use McAfee, and i tried to carry out a full scan and after 2 hour gave up due to crashes.

    P.S. though is crashed during item 2) above, it has not crashed in 30 minutes now!!

    BSOD StopCode Page Fault in Nonpaged Areas Attached Files
    Last edited by Jimmyb; 05 Dec 2017 at 04:23. Reason: Found 6)
      My ComputersSystem Spec


  10. Posts : 14,213
    windows 10 professional version 1607 build 14393.969 64 bit
       05 Dec 2017 #10

    The latest 2 mini dumps were also bugcheck EF.
    When debugged they did not display a misbehaving driver.
    The memory dump may take a while to download so the debugging will be done later in the day.

    Run Memtest86+ version 5.01 for 8 or more passes.
    Memtest86+ - Advanced Memory Diagnostic Tool
    Memtest86+ - Advanced Memory Diagnostic Tool

    It can be run overnight.
    The test is not run by time but by passes.
    The greater the number of passes the better the test.
    Running Memtest86 + version 5.01 takes approximately 1 -2 hours / GB RAM
    The computer has 8 GB RAM.
    If the test is started in the evening it should have completed 8 or more passes within 16 hours.
    Just 1 error is a fail and you can abort testing.
    If there is an error then it will be necessary to differentiate good from bad RAM and problems with DIMM or motherboard.
    To do this 1 RAM module would be tested in the same DIMM for 8 or more passes.
    When the test has completed 8 or more passes use a camera or smart phone camera to take a picture and post an image into the thread.
    If there is any problem posting an image please use a one drive or drop box share link.
      My ComputerSystem Spec


 
Page 1 of 4 123 ... LastLast

Related Threads
BSOD Page fault in nonpaged area (uTorrent) in BSOD Crashes and Debugging
Hi everyone, so this issue recently started and am not sure whats causing this issue. Whenever i attempt to download someone using the uTorrent application, my laptop just crashes after 2 minutes. Would like to receive some help. :confused:
Bsod: Page fault in nonpaged area in BSOD Crashes and Debugging
Hello. I've been having a problem for few days now. Quite often my laptop will just restart to BSOD with stop code:PAGE FAULT IN NONPAGED AREA. So far no luck finding the answer.
Page Fault In Nonpaged Area BSOD in BSOD Crashes and Debugging
Hello Friends, I've been having some BSODs both on startup and while running some programs. Most recently I got a Page Fault in Nonpaged Area while using Firefox. While running Diablo 3 last month I got a Memory Management BSOD. On boot last...
Please help. My laptop is crashing on a frequent basis, with the appearance of the BSOD and the error message PAGE FAULT IN NONPAGED AREA. I've spent a lot of time googling ways to solve this issue, but nothing has worked. Also, there doesn't seem...
Hello, I just bought an Asus Laptop, and ever since I bought it, its been having the same issue, BSOD PAGE_FAULT_IN_NONPAGED_AREA, but it only happens while torrenting. At first, I thought it was faulty RAM, so I asked for a new PC (same model)...
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 12:18.
Find Us