Bluescreen im Rythmus


Der Erste:
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000338b5ec, Address of the instruction which caused the bugcheck
Arg3: fffff880079c2f60, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

CONTEXT:  fffff880079c2f60 -- (.cxr 0xfffff880079c2f60)
rax=fffefa80073862e3 rbx=fffff8a0046d2f30 rcx=fffefa80073862e2
rdx=0000000000000000 rsi=fffff8a000db94e0 rdi=fffffa800a66cb60
rip=fffff8000338b5ec rsp=fffff880079c3940 rbp=fffefa80073862e0
 r8=fffff8a000e31000  r9=0000000000000020 r10=fffff800033b07a0
r11=fffff880079c3b38 r12=0000000000000000 r13=00000000000013cc
r14=0000000000000001 r15=fffffa800a139930
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!ObReferenceObjectByHandleWithTag+0x10c:
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h] ss:0018:fffefa80`073862f8=??
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  AvastSvc.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8000338b5ec

STACK_TEXT:  
fffff880`079c3940 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObReferenceObjectByHandleWithTag+0x10c


FOLLOWUP_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!ObReferenceObjectByHandleWithTag+10c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

STACK_COMMAND:  .cxr 0xfffff880079c2f60 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

Followup: MachineOwner
---------
Der Zweite:
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000338b5ec, Address of the instruction which caused the bugcheck
Arg3: fffff880079c2f60, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

CONTEXT:  fffff880079c2f60 -- (.cxr 0xfffff880079c2f60)
rax=fffefa80073862e3 rbx=fffff8a0046d2f30 rcx=fffefa80073862e2
rdx=0000000000000000 rsi=fffff8a000db94e0 rdi=fffffa800a66cb60
rip=fffff8000338b5ec rsp=fffff880079c3940 rbp=fffefa80073862e0
 r8=fffff8a000e31000  r9=0000000000000020 r10=fffff800033b07a0
r11=fffff880079c3b38 r12=0000000000000000 r13=00000000000013cc
r14=0000000000000001 r15=fffffa800a139930
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!ObReferenceObjectByHandleWithTag+0x10c:
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h] ss:0018:fffefa80`073862f8=??
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  AvastSvc.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8000338b5ec

STACK_TEXT:  
fffff880`079c3940 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObReferenceObjectByHandleWithTag+0x10c


FOLLOWUP_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!ObReferenceObjectByHandleWithTag+10c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

STACK_COMMAND:  .cxr 0xfffff880079c2f60 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

Followup: MachineOwner
---------
Und der Dritte:
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000338b5ec, Address of the instruction which caused the bugcheck
Arg3: fffff880079c2f60, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

CONTEXT:  fffff880079c2f60 -- (.cxr 0xfffff880079c2f60)
rax=fffefa80073862e3 rbx=fffff8a0046d2f30 rcx=fffefa80073862e2
rdx=0000000000000000 rsi=fffff8a000db94e0 rdi=fffffa800a66cb60
rip=fffff8000338b5ec rsp=fffff880079c3940 rbp=fffefa80073862e0
 r8=fffff8a000e31000  r9=0000000000000020 r10=fffff800033b07a0
r11=fffff880079c3b38 r12=0000000000000000 r13=00000000000013cc
r14=0000000000000001 r15=fffffa800a139930
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!ObReferenceObjectByHandleWithTag+0x10c:
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h] ss:0018:fffefa80`073862f8=??
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  AvastSvc.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8000338b5ec

STACK_TEXT:  
fffff880`079c3940 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObReferenceObjectByHandleWithTag+0x10c


FOLLOWUP_IP: 
nt!ObReferenceObjectByHandleWithTag+10c
fffff800`0338b5ec 0fb64518        movzx   eax,byte ptr [rbp+18h]

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!ObReferenceObjectByHandleWithTag+10c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

STACK_COMMAND:  .cxr 0xfffff880079c2f60 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

BUCKET_ID:  X64_0x3B_nt!ObReferenceObjectByHandleWithTag+10c

Followup: MachineOwner
---------
 
Weil die BS durch einen Prozess "avastsvc.exe" ausgelöst wird. Schmeiß mal den avast runter und nimm Antivir.

Könnte auch ein Trojaner sein, glaub ich aber nicht.
 
Öhm, Avast schmeiß ich gern runter, aber Antivir kommt mir nicht mehr auf die Kiste. ;)
Ich hab jetzt die 30-Tage Trial von Kaspersky drauf gemacht.
Mal schaun... Ich berichte dann ob es daran lag. ;)

Edit: Sorry wegen dem Doppelpost.

Update #1 (der nächste Bluescreen):
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800d2ee3f8
Arg3: fffff8800d2edc50
Arg4: fffff880014b63e7

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff8800d2ee3f8 -- (.exr 0xfffff8800d2ee3f8)
ExceptionAddress: fffff880014b63e7 (Ntfs!NtfsOpenAttribute+0x00000000000003a7)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff8800d2edc50 -- (.cxr 0xfffff8800d2edc50)
rax=fffef8a004bdce98 rbx=fffffa800aae6700 rcx=fffff8a004bdcf68
rdx=0000000000000000 rsi=fffffa800b30b368 rdi=fffff8a004bdced8
rip=fffff880014b63e7 rsp=fffff8800d2ee630 rbp=0000000000000000
 r8=fffffa800718b018  r9=0000000000000000 r10=fffff88001467380
r11=fffff8a00b13b198 r12=fffff8800e198510 r13=fffff8a004bdcb40
r14=fffff8800e198518 r15=fffff8800e1984a0
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
Ntfs!NtfsOpenAttribute+0x3a7:
fffff880`014b63e7 4c8918          mov     qword ptr [rax],r11 ds:002b:fffef8a0`04bdce98=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  avp.exe

CURRENT_IRQL:  1

ERROR_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b90e8
 ffffffffffffffff 

FOLLOWUP_IP: 
Ntfs!NtfsOpenAttribute+3a7
fffff880`014b63e7 4c8918          mov     qword ptr [rax],r11

FAULTING_IP: 
Ntfs!NtfsOpenAttribute+3a7
fffff880`014b63e7 4c8918          mov     qword ptr [rax],r11

BUGCHECK_STR:  0x24

LAST_CONTROL_TRANSFER:  from fffff880014a4fe5 to fffff880014b63e7

STACK_TEXT:  
fffff880`0d2ee630 fffff880`014a4fe5 : fffffa80`0b42cbe0 fffffa80`0b30b368 fffffa80`078ad180 fffff8a0`04bdced8 : Ntfs!NtfsOpenAttribute+0x3a7
fffff880`0d2ee740 fffff880`014a0e3b : fffff880`0e1984a0 fffffa80`0b42cbe0 fffff8a0`04bdced8 fffff8a0`0000004e : Ntfs!NtfsOpenExistingAttr+0x145
fffff880`0d2ee800 fffff880`014a409f : fffffa80`0b42cbe0 fffffa80`0b30b010 fffff8a0`04bdced8 fffff880`0000004e : Ntfs!NtfsOpenAttributeInExistingFile+0x5ab
fffff880`0d2ee990 fffff880`014b4166 : fffffa80`0b42cbe0 fffffa80`0b30b010 fffff8a0`04bdced8 00000000`00000701 : Ntfs!NtfsOpenExistingPrefixFcb+0x1ef
fffff880`0d2eea80 fffff880`014b1911 : fffffa80`0b42cbe0 fffffa80`0b30b010 fffff880`0d2eec50 fffff880`0d2eeca0 : Ntfs!NtfsFindStartingNode+0x5e6
fffff880`0d2eeb50 fffff880`0141aa3d : fffffa80`0b42cbe0 fffffa80`0b30b010 fffff880`0e1984a0 fffffa80`0aeeeb00 : Ntfs!NtfsCommonCreate+0x3e1
fffff880`0d2eed30 fffff800`03080157 : fffff880`0e198410 00000000`000007e1 00000000`7ef68000 00000000`08b4ff3c : Ntfs!NtfsCommonCreateCallout+0x1d
fffff880`0d2eed60 fffff800`03080111 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxSwitchKernelStackCallout+0x27
fffff880`0e1982e0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  Ntfs!NtfsOpenAttribute+3a7

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce792f9

STACK_COMMAND:  .cxr 0xfffff8800d2edc50 ; kb

FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsOpenAttribute+3a7

BUCKET_ID:  X64_0x24_Ntfs!NtfsOpenAttribute+3a7

Followup: MachineOwner
---------

Update #2 (schon wieder...):
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff88010764eea, Address of the instruction which caused the bugcheck
Arg3: fffff88007dae470, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`10764eea f00fc14308      lock xadd dword ptr [rbx+8],eax

CONTEXT:  fffff88007dae470 -- (.cxr 0xfffff88007dae470)
rax=0000000000000001 rbx=fffefa800aa7aac0 rcx=fffefa800aa7aac0
rdx=fffffa800989d000 rsi=0000000000000001 rdi=fffffa80098c7000
rip=fffff88010764eea rsp=fffff88007daee50 rbp=0000000000000001
 r8=fffffa80098c83e0  r9=0000000000000001 r10=0000000000000038
r11=fffff88007daee60 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=fffff8a00aad6c40
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00210282
dxgmms1!DXGFASTMUTEX::Acquire+0x1a:
fffff880`10764eea f00fc14308      lock xadd dword ptr [rbx+8],eax ds:002b:fffefa80`0aa7aac8=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  firefox.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff8801077a4ff to fffff88010764eea

STACK_TEXT:  
fffff880`07daee50 fffff880`1077a4ff : fffffa80`0a22ce60 fffffa80`0a22ce60 fffff8a0`04d09e50 00000000`00000001 : dxgmms1!DXGFASTMUTEX::Acquire+0x1a
fffff880`07daee90 fffff880`10760ecc : fffff8a0`00000000 fffff8a0`00000000 00000000`00000000 00000000`00000000 : dxgmms1!VIDMM_GLOBAL::CloseOneAllocation+0x177
fffff880`07daef60 fffff880`0fa37ccc : 00000000`00000000 fffff8a0`0adfa000 fffff8a0`0adfa000 00000000`00000001 : dxgmms1!VidMmCloseAllocation+0x44
fffff880`07daef90 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : dxgkrnl!DXGDEVICE::DestroyAllocations+0x248


FOLLOWUP_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`10764eea f00fc14308      lock xadd dword ptr [rbx+8],eax

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::Acquire+1a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

STACK_COMMAND:  .cxr 0xfffff88007dae470 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

Followup: MachineOwner
---------
 
Zuletzt bearbeitet:
Komisch. avp.exe gehört zu Kaspersky und der 2. BS hängt mit firefox zusammen :huh:

memtest86+ hast Du schon laufen lassen?

Ansonsten müsstest Du mal auf Simpel1970 warten, der hat bestimmt noch ein paar Ideen ;)
 
Tritt der Fehler auch mit nur einem RAM-Riegel auf? Hast Du die Riegel einzeln mindestens ein paar Stunden mit memtest86+ getestet?
 
Dann kann es immer noch ein Treibersalat oder ähnliches sein. Welche Programme hast Du bisher installiert?

Du kannst entweder Windows mal neu aufsetzen, oder auf Simpel1970 warten, der weiß vielleicht Rat :)
 
Hab Windows schon mehrfach neu installiert.
Jetzt aber erstmal die neusten Bluescreens:

Der Erste
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff9600015535c, Address of the instruction which caused the bugcheck
Arg3: fffff8800bce1370, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
win32k+c535c
fffff960`0015535c 6644396f0c      cmp     word ptr [rdi+0Ch],r13w

CONTEXT:  fffff8800bce1370 -- (.cxr 0xfffff8800bce1370)
rax=fffff900c0001012 rbx=0000000000000000 rcx=fffff900c000dfd0
rdx=fffff900c0226f70 rsi=fffff900c0226f70 rdi=fffef900c39e2930
rip=fffff9600015535c rsp=fffff8800bce1d50 rbp=fffff900c0226f70
 r8=0000000000000001  r9=00000000000019fa r10=0000000000004dee
r11=000000000000003e r12=00000000000019fa r13=0000000000000000
r14=0000000000000001 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
win32k+0xc535c:
fffff960`0015535c 6644396f0c      cmp     word ptr [rdi+0Ch],r13w ds:002b:fffef900`c39e293c=????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  VDeck.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000f50 to fffff9600015535c

STACK_TEXT:  
fffff880`0bce1d50 00000000`00000f50 : 00000000`00000000 fffff900`c0226f70 00000000`00010bde 00000000`00000000 : win32k+0xc535c
fffff880`0bce1d58 00000000`00000000 : fffff900`c0226f70 00000000`00010bde 00000000`00000000 fffff900`c39db820 : 0xf50


FOLLOWUP_IP: 
win32k+c535c
fffff960`0015535c 6644396f0c      cmp     word ptr [rdi+0Ch],r13w

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  win32k+c535c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: win32k

IMAGE_NAME:  win32k.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4df2dbd2

STACK_COMMAND:  .cxr 0xfffff8800bce1370 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_win32k+c535c

BUCKET_ID:  X64_0x3B_win32k+c535c

Followup: MachineOwner
---------

Und der Zweite
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88008506968
Arg3: fffff880085061c0
Arg4: fffff880013013e7

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff88008506968 -- (.exr 0xfffff88008506968)
ExceptionAddress: fffff880013013e7 (Ntfs!NtfsOpenAttribute+0x00000000000003a7)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff880085061c0 -- (.cxr 0xfffff880085061c0)
rax=fffef8a00d12ee98 rbx=fffffa800a5e5070 rcx=fffff8a00d12ef68
rdx=0000000000000000 rsi=fffffa800a42e788 rdi=fffff8a00d12eed8
rip=fffff880013013e7 rsp=fffff88008506ba0 rbp=0000000000000000
 r8=fffffa800a9bb7c8  r9=0000000000000000 r10=fffff880012b2380
r11=fffff8a00dbed6a8 r12=fffff88008507510 r13=fffff8a00d12eb40
r14=fffff88008507518 r15=fffff880085074a0
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
Ntfs!NtfsOpenAttribute+0x3a7:
fffff880`013013e7 4c8918          mov     qword ptr [rax],r11 ds:002b:fffef8a0`0d12ee98=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  chrome.exe

CURRENT_IRQL:  1

ERROR_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032fd0e8
 ffffffffffffffff 

FOLLOWUP_IP: 
Ntfs!NtfsOpenAttribute+3a7
fffff880`013013e7 4c8918          mov     qword ptr [rax],r11

FAULTING_IP: 
Ntfs!NtfsOpenAttribute+3a7
fffff880`013013e7 4c8918          mov     qword ptr [rax],r11

BUGCHECK_STR:  0x24

LAST_CONTROL_TRANSFER:  from fffff880012effe5 to fffff880013013e7

STACK_TEXT:  
fffff880`08506ba0 fffff880`012effe5 : fffffa80`0a79de40 fffffa80`0a42e788 fffffa80`078cb180 fffff8a0`0d12eed8 : Ntfs!NtfsOpenAttribute+0x3a7
fffff880`08506cb0 fffff880`012ebe3b : fffff880`085074a0 fffffa80`0a79de40 fffff8a0`0d12eed8 fffff8a0`00000098 : Ntfs!NtfsOpenExistingAttr+0x145
fffff880`08506d70 fffff880`012d90e5 : fffffa80`0a79de40 fffffa80`0a42e430 fffff8a0`0d12eed8 00100000`00000098 : Ntfs!NtfsOpenAttributeInExistingFile+0x5ab
fffff880`08506f00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsOpenFile+0x525


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  Ntfs!NtfsOpenAttribute+3a7

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce792f9

STACK_COMMAND:  .cxr 0xfffff880085061c0 ; kb

FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsOpenAttribute+3a7

BUCKET_ID:  X64_0x24_Ntfs!NtfsOpenAttribute+3a7

Followup: MachineOwner
---------

Edit: Mal schaun ob ich das auch schon kann...
Der erste wurde durch die Audiotreiber ausgelöst, der zweite durch Chrome...
 
Zurück