Hi! Sorry for my English.
I have on my pc CCleaner ver. 2.21. Then I used 1)page "Cleaner"->button"Analyze"->button"Run Cleaner"; 2)page "Regisrtry"->button"Scan for Issues"->button"Fix selected issues..." and after that do standard restart of operation system I have system error "0x0000008e" without any parametrs. In begin I think about RAM, but test of RAM was good/no errors. I tested my RAM with Memtest86+. And I had this BSOD two times after work of CCleaner. I had this bsod with this version of Ccleaner and with version 2.03.
My config is: MB - Gigabyte EP43DS-3L, CPU - Intel Core 2 Duo E8400 3000MHz, RAM - 2Gb SAMSUNG PC6400 DDR II 800 MHz CL6 x2 modules (4Gb summary), Video - Gigabyte nVidia GeForce 9800GT, HDD - WD640Gb, internal audio and LAN, LAN ADSL modem D-link.
My system is MS Windows XP Pro SP3 Rus, corporate licence, my browser is IE8 Rus.
Please, give me answer. Help!
Ccleaner 2.21 and bsod error 0x0000008e
Started by goilia, Jun 30 2009 10:01 AM
3 replies to this topic
#1 OFFLINE
Posted 30 June 2009 - 10:01 AM
#2 OFFLINE
Posted 30 June 2009 - 06:18 PM
You could try running CCleaner using the debug option, then post your debug log which will be saved in the CCleaner installed folder into this topic for the developers too see.
How to run CCleaner in debug mode:
How to run CCleaner in debug mode:
"C:\Program Files\CCleaner\CCleaner.exe" /debug
#3 OFFLINE
Posted 01 July 2009 - 05:02 AM
Thanks, Andavari!
I shall start СCleaner in debug mode later one of these days and then I shall write about result, because a computer of the house at the my sister.
Yesterday, standard start of Ccleaner and standart restart of system after its work bsod has not caused.
I have checked up 2 times. Any floating bug (!?).
As I have lead the analysis mini dump by utility of Microsoft (file's name is Mini062909-01.dmp). File Memory.dmp in folder Windows was not. Result of the analysis mini dump below. Probably it will help to find the reason. I ask, briefly state your ideas. Thanks. Wait your post.
I shall start СCleaner in debug mode later one of these days and then I shall write about result, because a computer of the house at the my sister.
Yesterday, standard start of Ccleaner and standart restart of system after its work bsod has not caused.
I have checked up 2 times. Any floating bug (!?).
As I have lead the analysis mini dump by utility of Microsoft (file's name is Mini062909-01.dmp). File Memory.dmp in folder Windows was not. Result of the analysis mini dump below. Probably it will help to find the reason. I ask, briefly state your ideas. Thanks. Wait your post.
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Dmp\n\Mini062909-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp.080413-2111
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Mon Jun 29 18:31:16.781 2009 (GMT+4)
System Uptime: 0 days 4:01:52.515
Loading Kernel Symbols
...............................................................
...........................................................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 8064ce4d, b65afb14, 0}
Unable to load image sfc.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for sfc.SYS
*** ERROR: Module load completed but symbols could not be loaded for sfc.SYS
Probably caused by : sfc.SYS ( sfc+11aa )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8064ce4d, The address that the exception occurred at
Arg3: b65afb14, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
nt!MiUnmapLockedPagesInUserSpace+1f
8064ce4d 8b4818 mov ecx,dword ptr [eax+18h]
TRAP_FRAME: b65afb14 -- (.trap 0xffffffffb65afb14)
ErrCode = 00000000
eax=00000000 ebx=00000000 ecx=0000001c edx=00000081 esi=8937f820 edi=8989f8b0
eip=8064ce4d esp=b65afb88 ebp=b65afbb4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!MiUnmapLockedPagesInUserSpace+0x1f:
8064ce4d 8b4818 mov ecx,dword ptr [eax+18h] ds:0023:00000018=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: explorer.exe
LAST_CONTROL_TRANSFER: from 80509499 to 8064ce4d
STACK_TEXT:
b65afbb4 80509499 00000000 00000000 b65afb56 nt!MiUnmapLockedPagesInUserSpace+0x1f
b65afbc8 b63741aa 00000000 00000000 8989f8b0 nt!MmUnmapLockedPages+0x7b
WARNING: Stack unwind information not available. Following frames may be wrong.
b65afbfc b6375691 000002a4 8989f8b0 80563a50 sfc+0x11aa
b65afc28 805d1b22 000001c0 000002a4 00000000 sfc+0x2691
b65afc4c 805d2634 00000001 00000004 897de548 nt!PspExitProcess+0x5e
b65afcf0 805d27e9 40010004 b65afd4c 804ff93f nt!PspExitThread+0x5ae
b65afcfc 804ff93f 897de548 b65afd48 b65afd3c nt!PsExitSpecialApc+0x23
b65afd4c 80541687 00000001 00000000 b65afd64 nt!KiDeliverApc+0x1af
b65afd4c 7c90e4f4 00000001 00000000 b65afd64 nt!KiServiceExit+0x59
035bff6c 00000000 00000000 00000000 00000000 0x7c90e4f4
STACK_COMMAND: kb
FOLLOWUP_IP:
sfc+11aa
b63741aa ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: sfc+11aa
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: sfc
IMAGE_NAME: sfc.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4a393a95
FAILURE_BUCKET_ID: 0x8E_sfc+11aa
BUCKET_ID: 0x8E_sfc+11aa
Followup: MachineOwner
---------
0: kd> lmvm sfc
start end module name
b6373000 b63760c0 sfc T (no symbols)
Loaded symbol image file: sfc.SYS
Image path: sfc.SYS
Image name: sfc.SYS
Timestamp: Wed Jun 17 22:48:53 2009 (4A393A95)
CheckSum: 0000A52D
ImageSize: 000030C0
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Attached Files
#4 OFFLINE
Posted 06 July 2009 - 06:08 AM
My problem was in a virus. Its name Trojan.Win.Spy with any number in name, has not remembered. The infected file c:\windows\system32\sfcfiles.dll and generated by it c:\windows\system32\drivers\sfc.sys which caused bsod, that has confirmed the analysis mini-dump, have been found out and removed by free utility CureIt! of Dr. Web Company. The removed file sfcfiles.dll has been replaced same from other computer by me. CCleaner above suspicion. All thanks. It's ok.












