BlueScreen wie jetzt weiter

Das ganze tritt auch ohne Übertaktung auf? Mache bitte noch ein paar Screenshots von CPU-Z (Reiter Mainboard, Memory und SPD).
 
Bitte schön, ich hoffe ihr könnt mir wiedermal helfen. ;)
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff8800f205eea, fffff880093f98d0, 0}

Probably caused by : dxgmms1.sys ( dxgmms1!DXGFASTMUTEX::Acquire+1a )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8800f205eea, Address of the instruction which caused the bugcheck
Arg3: fffff880093f98d0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

CONTEXT:  fffff880093f98d0 -- (.cxr 0xfffff880093f98d0)
rax=0000000000000001 rbx=fffefa8006a15160 rcx=fffefa8006a15160
rdx=fffffa8009d31000 rsi=0000000000000001 rdi=fffffa8009d3b000
rip=fffff8800f205eea rsp=fffff880093fa2b0 rbp=0000000000000001
 r8=fffffa8009d3c3e0  r9=0000000000000001 r10=0000000000000038
r11=fffff880093fa2c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=fffff8a001f98db0
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
dxgmms1!DXGFASTMUTEX::Acquire+0x1a:
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax ds:002b:fffefa80`06a15168=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  dwm.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8800f205eea

STACK_TEXT:  
fffff880`093fa2b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : dxgmms1!DXGFASTMUTEX::Acquire+0x1a


FOLLOWUP_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::Acquire+1a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

STACK_COMMAND:  .cxr 0xfffff880093f98d0 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8800f205eea, Address of the instruction which caused the bugcheck
Arg3: fffff880093f98d0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

CONTEXT:  fffff880093f98d0 -- (.cxr 0xfffff880093f98d0)
rax=0000000000000001 rbx=fffefa8006a15160 rcx=fffefa8006a15160
rdx=fffffa8009d31000 rsi=0000000000000001 rdi=fffffa8009d3b000
rip=fffff8800f205eea rsp=fffff880093fa2b0 rbp=0000000000000001
 r8=fffffa8009d3c3e0  r9=0000000000000001 r10=0000000000000038
r11=fffff880093fa2c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=fffff8a001f98db0
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
dxgmms1!DXGFASTMUTEX::Acquire+0x1a:
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax ds:002b:fffefa80`06a15168=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  dwm.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8800f205eea

STACK_TEXT:  
fffff880`093fa2b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : dxgmms1!DXGFASTMUTEX::Acquire+0x1a


FOLLOWUP_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::Acquire+1a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

STACK_COMMAND:  .cxr 0xfffff880093f98d0 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8800f205eea, Address of the instruction which caused the bugcheck
Arg3: fffff880093f98d0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

CONTEXT:  fffff880093f98d0 -- (.cxr 0xfffff880093f98d0)
rax=0000000000000001 rbx=fffefa8006a15160 rcx=fffefa8006a15160
rdx=fffffa8009d31000 rsi=0000000000000001 rdi=fffffa8009d3b000
rip=fffff8800f205eea rsp=fffff880093fa2b0 rbp=0000000000000001
 r8=fffffa8009d3c3e0  r9=0000000000000001 r10=0000000000000038
r11=fffff880093fa2c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=fffff8a001f98db0
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
dxgmms1!DXGFASTMUTEX::Acquire+0x1a:
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax ds:002b:fffefa80`06a15168=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  dwm.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8800f205eea

STACK_TEXT:  
fffff880`093fa2b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : dxgmms1!DXGFASTMUTEX::Acquire+0x1a


FOLLOWUP_IP: 
dxgmms1!DXGFASTMUTEX::Acquire+1a
fffff880`0f205eea f00fc14308      lock xadd dword ptr [rbx+8],eax

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::Acquire+1a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce799c1

STACK_COMMAND:  .cxr 0xfffff880093f98d0 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

BUCKET_ID:  X64_0x3B_dxgmms1!DXGFASTMUTEX::Acquire+1a

Followup: MachineOwner
---------
 
Hi Kev95,

bei dem Bluescreen trat eine Speicherzugriffsverletzung durch die DirectX Komponente auf.
Wenn die Bluescreens häufiger auftreten, mache bitte noch Auswertungen von den anderen Bluescreens. Evtl, kann damit eine gewisse Richtung nachvollzogen werden (Speicherzugriffsprobleme können u.a. durch CPU, RAM, VRAM ausgelöst werden).
 
Hi Kev95,

bei dem Bluescreen trat eine Speicherzugriffsverletzung durch die DirectX Komponente auf.
Wenn die Bluescreens häufiger auftreten, mache bitte noch Auswertungen von den anderen Bluescreens. Evtl, kann damit eine gewisse Richtung nachvollzogen werden (Speicherzugriffsprobleme können u.a. durch CPU, RAM, VRAM ausgelöst werden).
Hast schon ne PN, mit nem neuen Bluescreen.

Heute Mittag habe ich mein System wieder auf nen alten Punkt gesetzt.
In der Hoffnung alles funktioniert wieder, dem ist aber nicht so...
Leider habe ich die alten Minidumps jetzt nichmehr.
 
Damit alle mitlesen können, hier die zweite:
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: fffff683ff7a6001
Arg3: 000000000000075d
Arg4: fffff70001080000

Debugging Details:
------------------


BUGCHECK_STR:  0x1a_41284

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff80002f3d767 to fffff80002ee6640

STACK_TEXT:  
fffff880`0ba8f698 fffff800`02f3d767 : 00000000`0000001a 00000000`00041284 fffff683`ff7a6001 00000000`0000075d : nt!KeBugCheckEx
fffff880`0ba8f6a0 fffff800`02f007c9 : fffffa80`06b10e48 00000000`00000000 00000000`00000000 00000000`00000002 : nt! ?? ::FNODOBFM::`string'+0x4ac3
fffff880`0ba8f6e0 fffff800`02f1a5ea : fffffa80`03ae4bf0 fffffa80`06b10ab0 00000000`00000000 fffff683`ff7a6e80 : nt!MiTerminateWsle+0x29
fffff880`0ba8f720 fffff800`02f18b2a : fffffa80`06b10ab0 00000000`00000000 00000000`00000000 cc300001`3cf3a025 : nt!MiDeletePageTableHierarchy+0xca
fffff880`0ba8f830 fffff800`02f19fd9 : 00000000`00000000 000007fe`f4dd0fff fffffa80`00000000 fffff880`00961000 : nt!MiDeleteVirtualAddresses+0x929
fffff880`0ba8f9f0 fffff800`031fd731 : fffffa80`06b8a160 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0ba8fb10 fffff800`031fdb33 : 0000007f`00000000 000007fe`f45a0000 fffffa80`00000001 fffffa80`07052730 : nt!MiUnmapViewOfSection+0x1b1
fffff880`0ba8fbd0 fffff800`02ee58d3 : 00000000`00000000 00000000`779b500c fffffa80`06b10ab0 00000000`779b5000 : nt!NtUnmapViewOfSection+0x5f
fffff880`0ba8fc20 00000000`778315ba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`005ff828 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778315ba


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt! ?? ::FNODOBFM::`string'+4ac3
fffff800`02f3d767 cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+4ac3

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7951a

FAILURE_BUCKET_ID:  X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4ac3

BUCKET_ID:  X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4ac3

Followup: MachineOwner
---------
Hoffentlich is nich die CPU kaputt, die Grafikkarte ginge ja noch...
 
Der Memory Management Fehler ist nun wieder zu allgemein, um eine bestimmte Hardware ausmachen zu können.

Die letzten beiden hätten in Richtung Grafikkarte gedeutet, aber so wird es etwas schwammiger.

Mache bitte ein paar Screenshots von CPU-Z (Reiter Mainboard, CPU, Memory und SPD) und einer von CrystalDiskInfo.
 
Hallo, ich habe seit kurzem eine neue Grafikkarte. GTX 560 2GB DDR5

Nun wollte ich mal ausprobieren ob die auch richtig funktioniert und mal Black Ops angeworfen. Nach 10 bis 15 Min spielen kommt dann Bluescreen mit dem Fehlercode 0x00000124

Hier nun die Fehler Analyse mit dem Debugging Tool:



Wo liegt der Fehler?

Hi,

mach bitte einen eigenen Thread auf. Sonst gibt das hier ganz schnell ein Durcheinander. Danke :daumen:
 
Guten Tag,

ich habe meine CPU (i7 860) ein wenig übertaktet und zwar nach diesem guide:
Hardwareoverclock.com | Test: Intel Core i7 860 Overclocking Guide Anleitung

ich habe mir dafür sogar extra 2000er ram von corsair gekauft, damit das auch alles funktioniert und nun bekomme ich einen Bluescreen. Ich habe ihn schon ausgewertet und hoffe, dass ihr mehr damit anfangen könnt als ich es tu!

Vielen Dank schon Mal!


Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\091811-8205-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02a1b000 PsLoadedModuleList = 0xfffff800`02c60670
Debug session time: Sun Sep 18 12:47:48.049 2011 (UTC + 2:00)
System Uptime: 0 days 0:28:14.923
Loading Kernel Symbols
...............................................................
................................................................
.............
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {80, 2, 0, fffff80002aa3442}

Probably caused by : ntkrnlmp.exe ( nt!KiProcessExpiredTimerList+72 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000080, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002aa3442, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cca100
0000000000000080

CURRENT_IRQL: 2

FAULTING_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: hl.exe

TRAP_FRAME: fffff80000ba2680 -- (.trap 0xfffff80000ba2680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000080 rbx=0000000000000000 rcx=fffffa8006507c00
rdx=0000000000000102 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002aa3442 rsp=fffff80000ba2810 rbp=000000000001a868
r8=fffff80002c10001 r9=0000000000000004 r10=0000000000000068
r11=fffffa8006473380 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!KiProcessExpiredTimerList+0x72:
fffff800`02aa3442 803818 cmp byte ptr [rax],18h ds:0001:00000000`00000080=??
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002a971e9 to fffff80002a97c40

STACK_TEXT:
fffff800`00ba2538 fffff800`02a971e9 : 00000000`0000000a 00000000`00000080 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00ba2540 fffff800`02a95e60 : fffffa80`059bd2b8 fffffa80`05f5c700 00000000`00000000 fffffa80`06507c20 : nt!KiBugCheckDispatch+0x69
fffff800`00ba2680 fffff800`02aa3442 : fffffa80`06507c20 fffffa80`06507c68 00000000`00000000 00000000`00000102 : nt!KiPageFault+0x260
fffff800`00ba2810 fffff800`02aa337e : 00000003`f240def7 fffff800`00ba2e88 00000000`0001a868 fffff800`02c10f88 : nt!KiProcessExpiredTimerList+0x72
fffff800`00ba2e60 fffff800`02aa3167 : fffffa80`05e653c3 fffffa80`0001a868 00000000`00000000 00000000`00000068 : nt!KiTimerExpiration+0x1be
fffff800`00ba2f00 fffff800`02a9a765 : 00000000`00000000 fffffa80`0694d060 00000000`00000000 fffff880`0148ba00 : nt!KiRetireDpcList+0x277
fffff800`00ba2fb0 fffff800`02a9a57c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KyRetireDpcList+0x5
fffff880`0788dbe0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!KiProcessExpiredTimerList+72

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000080, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002aa3442, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: 0000000000000080

CURRENT_IRQL: 2

FAULTING_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: hl.exe

TRAP_FRAME: fffff80000ba2680 -- (.trap 0xfffff80000ba2680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000080 rbx=0000000000000000 rcx=fffffa8006507c00
rdx=0000000000000102 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002aa3442 rsp=fffff80000ba2810 rbp=000000000001a868
r8=fffff80002c10001 r9=0000000000000004 r10=0000000000000068
r11=fffffa8006473380 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!KiProcessExpiredTimerList+0x72:
fffff800`02aa3442 803818 cmp byte ptr [rax],18h ds:0001:00000000`00000080=??
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002a971e9 to fffff80002a97c40

STACK_TEXT:
fffff800`00ba2538 fffff800`02a971e9 : 00000000`0000000a 00000000`00000080 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00ba2540 fffff800`02a95e60 : fffffa80`059bd2b8 fffffa80`05f5c700 00000000`00000000 fffffa80`06507c20 : nt!KiBugCheckDispatch+0x69
fffff800`00ba2680 fffff800`02aa3442 : fffffa80`06507c20 fffffa80`06507c68 00000000`00000000 00000000`00000102 : nt!KiPageFault+0x260
fffff800`00ba2810 fffff800`02aa337e : 00000003`f240def7 fffff800`00ba2e88 00000000`0001a868 fffff800`02c10f88 : nt!KiProcessExpiredTimerList+0x72
fffff800`00ba2e60 fffff800`02aa3167 : fffffa80`05e653c3 fffffa80`0001a868 00000000`00000000 00000000`00000068 : nt!KiTimerExpiration+0x1be
fffff800`00ba2f00 fffff800`02a9a765 : 00000000`00000000 fffffa80`0694d060 00000000`00000000 fffff880`0148ba00 : nt!KiRetireDpcList+0x277
fffff800`00ba2fb0 fffff800`02a9a57c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KyRetireDpcList+0x5
fffff880`0788dbe0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!KiProcessExpiredTimerList+72

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000080, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002aa3442, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: 0000000000000080

CURRENT_IRQL: 2

FAULTING_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: hl.exe

TRAP_FRAME: fffff80000ba2680 -- (.trap 0xfffff80000ba2680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000080 rbx=0000000000000000 rcx=fffffa8006507c00
rdx=0000000000000102 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002aa3442 rsp=fffff80000ba2810 rbp=000000000001a868
r8=fffff80002c10001 r9=0000000000000004 r10=0000000000000068
r11=fffffa8006473380 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!KiProcessExpiredTimerList+0x72:
fffff800`02aa3442 803818 cmp byte ptr [rax],18h ds:0001:00000000`00000080=??
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002a971e9 to fffff80002a97c40

STACK_TEXT:
fffff800`00ba2538 fffff800`02a971e9 : 00000000`0000000a 00000000`00000080 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00ba2540 fffff800`02a95e60 : fffffa80`059bd2b8 fffffa80`05f5c700 00000000`00000000 fffffa80`06507c20 : nt!KiBugCheckDispatch+0x69
fffff800`00ba2680 fffff800`02aa3442 : fffffa80`06507c20 fffffa80`06507c68 00000000`00000000 00000000`00000102 : nt!KiPageFault+0x260
fffff800`00ba2810 fffff800`02aa337e : 00000003`f240def7 fffff800`00ba2e88 00000000`0001a868 fffff800`02c10f88 : nt!KiProcessExpiredTimerList+0x72
fffff800`00ba2e60 fffff800`02aa3167 : fffffa80`05e653c3 fffffa80`0001a868 00000000`00000000 00000000`00000068 : nt!KiTimerExpiration+0x1be
fffff800`00ba2f00 fffff800`02a9a765 : 00000000`00000000 fffffa80`0694d060 00000000`00000000 fffff880`0148ba00 : nt!KiRetireDpcList+0x277
fffff800`00ba2fb0 fffff800`02a9a57c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KyRetireDpcList+0x5
fffff880`0788dbe0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiProcessExpiredTimerList+72
fffff800`02aa3442 803818 cmp byte ptr [rax],18h

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!KiProcessExpiredTimerList+72

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+72

Followup: MachineOwner
---------
 
Hi,

ich bekomm beim ausm ruhezustand gehn immer nen bluescreen und würd gern wissen woran des liegt

Viele Grüße und danke scho mal für die hilfe,

Surf-Chiller



0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffa98095efa8b, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800030e5137, address which referenced memory

Debugging Details:
------------------

Page 2b8280 not present in the dump file. Type ".hh dbgerr004" for details

READ_ADDRESS: fffffa98095efa8b

CURRENT_IRQL: 2

FAULTING_IP:
nt!MiUnlinkPageFromLockedList+167
fffff800`030e5137 410fb6511b movzx edx,byte ptr [r9+1Bh]

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: DTLite.exe

TRAP_FRAME: fffff8800c239d90 -- (.trap 0xfffff8800c239d90)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000008031fa8d rbx=0000000000000000 rcx=ffffffffffffffff
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800030e5137 rsp=fffff8800c239f20 rbp=fffff80003309d28
r8=0000000000000000 r9=fffffa98095efa70 r10=fffffa800cc763f8
r11=fffff8800c239fa8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
nt!MiUnlinkPageFromLockedList+0x167:
fffff800`030e5137 410fb6511b movzx edx,byte ptr [r9+1Bh] ds:fffffa98`095efa8b=??
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff800030d31e9 to fffff800030d3c40

STACK_TEXT:
fffff880`0c239c48 fffff800`030d31e9 : 00000000`0000000a fffffa98`095efa8b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0c239c50 fffff800`030d1e60 : fffffa80`095edcd0 fffff880`0c239e10 2aaaaaaa`aaaaaaab fffffa80`095efa10 : nt!KiBugCheckDispatch+0x69
fffff880`0c239d90 fffff800`030e5137 : 00000000`00000000 fffffa80`09c015b0 fffff8a0`1ef43000 fffff880`0c23a0a8 : nt!KiPageFault+0x260
fffff880`0c239f20 fffff800`030a1bad : 00000000`002514bd 00000580`00000000 fffffa80`00000001 00000000`002514bd : nt!MiUnlinkPageFromLockedList+0x167
fffff880`0c239fb0 fffff800`030a2532 : 00000000`00000000 fffff8a0`17162e00 00000000`00000000 00000072`00000000 : nt!MmPurgeSection+0x4bd
fffff880`0c23a0a0 fffff880`0c1a4619 : fffffa80`1088f018 00000000`00000000 fffff880`00000000 fffff8a0`00000000 : nt!CcPurgeCacheSection+0x172
fffff880`0c23a110 fffff880`0c1a3dff : 00000000`00000000 fffff8a0`17b2b120 00000000`00000001 00000000`00000000 : cdfs!CdPurgeVolume+0x111
fffff880`0c23a170 fffff880`0c19ec03 : 00000000`00000000 00000000`00000000 fffffa80`0ede1a90 fffffa80`0f04d270 : cdfs!CdVerifyVolume+0x50f
fffff880`0c23a2c0 fffff880`0c195481 : fffffa80`0ede1a90 fffffa80`0f04d270 fffff880`0c23a3a0 fffffa80`0f29b2ee : cdfs!CdCommonFsControl+0x37
fffff880`0c23a2f0 fffff880`01364bcf : fffffa80`0f04d4a8 fffffa80`0f04d270 fffff880`0c23a401 fffffa80`0dafb4d0 : cdfs!CdFsdDispatch+0x381
fffff880`0c23a360 fffff880`0138495e : fffffa80`0fd065d0 fffffa80`0f04d270 fffffa80`0fd06500 fffffa80`0f04d270 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`0c23a3f0 fffff800`034c30f6 : fffffa80`0c2a19c0 fffffa80`0dfad510 fffffa80`0f04d270 fffffa80`0fd065d0 : fltmgr!FltpFsControl+0xee
fffff880`0c23a450 fffff880`0c19616c : fffffa80`0efcd660 fffffa80`0c2a19c0 00000000`00000000 fffffa80`0dfad510 : nt!IoVerifyVolume+0x106
fffff880`0c23a4e0 fffff880`0c195f9d : fffffa80`0f200a00 fffffa80`0eb75c60 fffffa80`0c2a19c0 fffffa80`0eb75c60 : cdfs!CdPerformVerify+0x94
fffff880`0c23a540 fffff880`0c1954a1 : fffffa80`0f200a00 fffffa80`0eb75c60 fffffa80`80000016 fffffa80`0f200a00 : cdfs!CdProcessException+0x1ad
fffff880`0c23a580 fffff880`01364bcf : fffffa80`0eb75e98 fffffa80`0eb75c60 00000000`00000001 fffffa80`0f32b9f0 : cdfs!CdFsdDispatch+0x3a1
fffff880`0c23a5f0 fffff880`013842b9 : fffffa80`0eb75c60 fffffa80`0e739010 fffffa80`0eb75c00 fffffa80`0fd065d0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`0c23a680 fffff800`033d1f95 : 00000000`00000025 fffffa80`09f4b3f8 fffffa80`0dfbab10 00000000`00000000 : fltmgr!FltpCreate+0x2a9
fffff880`0c23a730 fffff800`033ce838 : fffffa80`0c2a19c0 00000000`00000000 fffffa80`09f4b240 fffff800`00000001 : nt!IopParseDevice+0x5a5
fffff880`0c23a8c0 fffff800`033cfa56 : 00000000`00000000 fffffa80`09f4b240 00000000`00000000 fffffa80`09de22a0 : nt!ObpLookupObjectName+0x588
fffff880`0c23a9b0 fffff800`033d135c : fffff880`0c23aa80 00000000`00000000 00000000`66626301 00000000`00000001 : nt!ObOpenObjectByName+0x306
fffff880`0c23aa80 fffff800`033dbf78 : 00000000`0299e7d8 fffff8a0`80100080 00000000`0299f0a0 00000000`0299e7f0 : nt!IopCreateFile+0x2bc
fffff880`0c23ab20 fffff800`030d2ed3 : ffffffff`ffffffff 00000000`00000001 00000000`0299f0a0 fffff800`00000024 : nt!NtCreateFile+0x78
fffff880`0c23abb0 00000000`76e8186a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0299e768 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76e8186a


STACK_COMMAND: kb

FOLLOWUP_IP:
cdfs!CdPurgeVolume+111
fffff880`0c1a4619 84c0 test al,al

SYMBOL_STACK_INDEX: 6

SYMBOL_NAME: cdfs!CdPurgeVolume+111

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: cdfs

IMAGE_NAME: cdfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc112

FAILURE_BUCKET_ID: X64_0xA_cdfs!CdPurgeVolume+111

BUCKET_ID: X64_0xA_cdfs!CdPurgeVolume+111

Followup: MachineOwner
 
Bitte um Hilfe bei der Auswertung meines Bluescreens Memory Management

hier das dumpfiles welches ich mit debugging tool ausgelesen habe

DANKESCHÖN

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\110511-24164-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03418000 PsLoadedModuleList = 0xfffff800`0365d670
Debug session time: Sat Nov 5 21:02:19.952 2011 (UTC + 1:00)
System Uptime: 6 days 23:58:33.840
Loading Kernel Symbols
...............................................................
................................................................
.......................................
Loading User Symbols
Loading unloaded module list
..................................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 30, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+46485 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000030
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------

BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: consent.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800a4c65e0 -- (.trap 0xfffff8800a4c65e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8008ec9940 rbx=0000000000000000 rcx=fffff8800a4c6950
rdx=00000780f59a8710 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000348b7c1 rsp=fffff8800a4c6778 rbp=fffff8800a4c6ca0
r8=0000000000000062 r9=00000000ffe6f000 r10=0000000000000001
r11=fffff8800a4c68f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!memcpy+0x1d1:
fffff800`0348b7c1 668b040a mov ax,word ptr [rdx+rcx] ds:0001:00000000`ffe6f060=????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003427d7e to fffff80003494c40
STACK_TEXT:
fffff880`0a4c5ea8 fffff800`03427d7e : 00000000`0000001a 00000000`00041287 00000000`00000030 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a4c5eb0 fffff800`03492d6e : 00000000`00000000 00000000`00000030 fffffa80`08ec9900 00000000`fffff8a0 : nt! ?? ::FNODOBFM::`string'+0x46485
fffff880`0a4c6010 fffff800`03572bc5 : fffff8a0`00000078 00000000`ffffffff fffff8a0`19ef2380 00000000`00000170 : nt!KiPageFault+0x16e
fffff880`0a4c61a0 fffff800`035071f8 : 00000000`ffe6f060 fffff8a0`00000078 fffffa80`0b4d2bf8 00000000`00000000 : nt!MiResolvePageFileFault+0x1115
fffff880`0a4c62e0 fffff800`034b2053 : 00000000`00003ca6 00000000`ffe6f060 fffff680`007ff378 fffffa80`0b4d2bf8 : nt! ?? ::FNODOBFM::`string'+0x394e7
fffff880`0a4c6370 fffff800`034a1f19 : 00000000`00000000 00000000`ffe6f060 00000000`00001f80 00000000`00000000 : nt!MiDispatchFault+0x1c3
fffff880`0a4c6480 fffff800`03492d6e : 00000000`00000000 00000000`ffe6f060 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x359
fffff880`0a4c65e0 fffff800`0348b7c1 : fffff800`03739fc3 fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 : nt!KiPageFault+0x16e
fffff880`0a4c6778 fffff800`03739fc3 : fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 00000000`00000000 : nt!memcpy+0x1d1
fffff880`0a4c6780 fffff800`03739ddb : fffffa80`0b4d2860 00000000`ffe6f000 fffffa80`08ef9b30 00000000`0246e940 : nt!MmCopyVirtualMemory+0x17b
fffff880`0a4c6b30 fffff800`03493ed3 : fffffa80`08ec9940 00000000`0246e4c8 fffff880`0a4c6bc8 00000000`00000062 : nt!NtReadVirtualMemory+0xff
fffff880`0a4c6bb0 00000000`77a6170a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0246e4a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a6170a

STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+46485
fffff800`03427d7e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+46485
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000030
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------

BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: consent.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800a4c65e0 -- (.trap 0xfffff8800a4c65e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8008ec9940 rbx=0000000000000000 rcx=fffff8800a4c6950
rdx=00000780f59a8710 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000348b7c1 rsp=fffff8800a4c6778 rbp=fffff8800a4c6ca0
r8=0000000000000062 r9=00000000ffe6f000 r10=0000000000000001
r11=fffff8800a4c68f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!memcpy+0x1d1:
fffff800`0348b7c1 668b040a mov ax,word ptr [rdx+rcx] ds:0001:00000000`ffe6f060=????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003427d7e to fffff80003494c40
STACK_TEXT:
fffff880`0a4c5ea8 fffff800`03427d7e : 00000000`0000001a 00000000`00041287 00000000`00000030 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a4c5eb0 fffff800`03492d6e : 00000000`00000000 00000000`00000030 fffffa80`08ec9900 00000000`fffff8a0 : nt! ?? ::FNODOBFM::`string'+0x46485
fffff880`0a4c6010 fffff800`03572bc5 : fffff8a0`00000078 00000000`ffffffff fffff8a0`19ef2380 00000000`00000170 : nt!KiPageFault+0x16e
fffff880`0a4c61a0 fffff800`035071f8 : 00000000`ffe6f060 fffff8a0`00000078 fffffa80`0b4d2bf8 00000000`00000000 : nt!MiResolvePageFileFault+0x1115
fffff880`0a4c62e0 fffff800`034b2053 : 00000000`00003ca6 00000000`ffe6f060 fffff680`007ff378 fffffa80`0b4d2bf8 : nt! ?? ::FNODOBFM::`string'+0x394e7
fffff880`0a4c6370 fffff800`034a1f19 : 00000000`00000000 00000000`ffe6f060 00000000`00001f80 00000000`00000000 : nt!MiDispatchFault+0x1c3
fffff880`0a4c6480 fffff800`03492d6e : 00000000`00000000 00000000`ffe6f060 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x359
fffff880`0a4c65e0 fffff800`0348b7c1 : fffff800`03739fc3 fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 : nt!KiPageFault+0x16e
fffff880`0a4c6778 fffff800`03739fc3 : fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 00000000`00000000 : nt!memcpy+0x1d1
fffff880`0a4c6780 fffff800`03739ddb : fffffa80`0b4d2860 00000000`ffe6f000 fffffa80`08ef9b30 00000000`0246e940 : nt!MmCopyVirtualMemory+0x17b
fffff880`0a4c6b30 fffff800`03493ed3 : fffffa80`08ec9940 00000000`0246e4c8 fffff880`0a4c6bc8 00000000`00000062 : nt!NtReadVirtualMemory+0xff
fffff880`0a4c6bb0 00000000`77a6170a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0246e4a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a6170a

STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+46485
fffff800`03427d7e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+46485
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000030
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------

BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: consent.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800a4c65e0 -- (.trap 0xfffff8800a4c65e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8008ec9940 rbx=0000000000000000 rcx=fffff8800a4c6950
rdx=00000780f59a8710 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000348b7c1 rsp=fffff8800a4c6778 rbp=fffff8800a4c6ca0
r8=0000000000000062 r9=00000000ffe6f000 r10=0000000000000001
r11=fffff8800a4c68f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!memcpy+0x1d1:
fffff800`0348b7c1 668b040a mov ax,word ptr [rdx+rcx] ds:0001:00000000`ffe6f060=????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003427d7e to fffff80003494c40
STACK_TEXT:
fffff880`0a4c5ea8 fffff800`03427d7e : 00000000`0000001a 00000000`00041287 00000000`00000030 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a4c5eb0 fffff800`03492d6e : 00000000`00000000 00000000`00000030 fffffa80`08ec9900 00000000`fffff8a0 : nt! ?? ::FNODOBFM::`string'+0x46485
fffff880`0a4c6010 fffff800`03572bc5 : fffff8a0`00000078 00000000`ffffffff fffff8a0`19ef2380 00000000`00000170 : nt!KiPageFault+0x16e
fffff880`0a4c61a0 fffff800`035071f8 : 00000000`ffe6f060 fffff8a0`00000078 fffffa80`0b4d2bf8 00000000`00000000 : nt!MiResolvePageFileFault+0x1115
fffff880`0a4c62e0 fffff800`034b2053 : 00000000`00003ca6 00000000`ffe6f060 fffff680`007ff378 fffffa80`0b4d2bf8 : nt! ?? ::FNODOBFM::`string'+0x394e7
fffff880`0a4c6370 fffff800`034a1f19 : 00000000`00000000 00000000`ffe6f060 00000000`00001f80 00000000`00000000 : nt!MiDispatchFault+0x1c3
fffff880`0a4c6480 fffff800`03492d6e : 00000000`00000000 00000000`ffe6f060 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x359
fffff880`0a4c65e0 fffff800`0348b7c1 : fffff800`03739fc3 fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 : nt!KiPageFault+0x16e
fffff880`0a4c6778 fffff800`03739fc3 : fffff880`0a4c6ca0 00000000`00000000 00000000`00000008 00000000`00000000 : nt!memcpy+0x1d1
fffff880`0a4c6780 fffff800`03739ddb : fffffa80`0b4d2860 00000000`ffe6f000 fffffa80`08ef9b30 00000000`0246e940 : nt!MmCopyVirtualMemory+0x17b
fffff880`0a4c6b30 fffff800`03493ed3 : fffffa80`08ec9940 00000000`0246e4c8 fffff880`0a4c6bc8 00000000`00000062 : nt!NtReadVirtualMemory+0xff
fffff880`0a4c6bb0 00000000`77a6170a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0246e4a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a6170a

STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+46485
fffff800`03427d7e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+46485
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
Followup: MachineOwner
---------
 
Zuletzt bearbeitet:
Wie der Bluescreen Name schon sagt: "Memory Management". Der Absturz trat durch beschädigte Speichermanagement Strukturen auf (Arg1: 0000000000041287). Speicher i.d.S. kann insbes. RAM, VRAM, CPU-Cache oder Festplatte sein.

Hast du die RAM schon mit Memtest86+ auf Fehler überprüft? Ist es immer der gleiche Stopfehlercode, der bei den Bluescreens angezeigt wird?
 
Hallo liebe Com,

ich habe ebenfalls Probleme mit einem ständig wiederkehrenden Bluescreen. Ich gebe mal soweit alles an:

Code:
Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\120111-19936-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c50000 PsLoadedModuleList = 0xfffff800`02e95670
Debug session time: Thu Dec  1 16:19:15.811 2011 (GMT+1)
System Uptime: 0 days 0:02:13.013
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff80002fd7c53, fffff88006f71020, 0}

Probably caused by : ntkrnlmp.exe ( nt!AlpcpSendMessage+7b1 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002fd7c53, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88006f71020, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP: 
nt!AlpcpSendMessage+7b1
fffff800`02fd7c53 f00fc141f4      lock xadd dword ptr [rcx-0Ch],eax

CONTEXT:  fffff88006f71020 -- (.cxr 0xfffff88006f71020)
rax=00000000ffffffff rbx=0000000000000000 rcx=dffff8a0098559c0
rdx=00000000ffffffff rsi=fffff8a00712a750 rdi=fffff8a00712a7c8
rip=fffff80002fd7c53 rsp=fffff88006f71a00 rbp=00000000012df5b0
 r8=fffff8a000085000  r9=0000000000000290 r10=fffffa8009292410
r11=fffff88006f719f8 r12=0000000000010000 r13=fffff88006f71b58
r14=00000000012df5b0 r15=0000000000010000
iopl=0         nv up ei ng nz na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010286
nt!AlpcpSendMessage+0x7b1:
fffff800`02fd7c53 f00fc141f4      lock xadd dword ptr [rcx-0Ch],eax ds:002b:dffff8a0`098559b4=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from fffff80002fda279 to fffff80002fd7c53

STACK_TEXT:  
fffff880`06f71a00 fffff800`02fda279 : 00000000`012d6d00 00000000`00000001 00000000`00000000 fffffa80`09292401 : nt!AlpcpSendMessage+0x7b1
fffff880`06f71b00 fffff800`02ccbed3 : fffffa80`0a130870 fffff880`06f71ca0 00000000`0236e918 00000000`0236f598 : nt!NtAlpcSendWaitReceivePort+0xb9
fffff880`06f71bb0 00000000`77461b6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0236e8f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77461b6a


FOLLOWUP_IP: 
nt!AlpcpSendMessage+7b1
fffff800`02fd7c53 f00fc141f4      lock xadd dword ptr [rcx-0Ch],eax

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!AlpcpSendMessage+7b1

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4e02aaa3

STACK_COMMAND:  .cxr 0xfffff88006f71020 ; kb

FAILURE_BUCKET_ID:  X64_0x3B_nt!AlpcpSendMessage+7b1

BUCKET_ID:  X64_0x3B_nt!AlpcpSendMessage+7b1

Followup: MachineOwner
---------
Hier noch die Daten von CPUZ

CPUZ.jpg

Hoffentlich könnt Ihr damit etwas anfangen und mir unter die Arme greifen.

Mfg
 
Hi Obscures,

tausche als Erstes das Datenkabel der Festplatte aus (hoher UDMA CRC Fehler Wert). Stelle zudem die RAM Timings im Bios lockerer ein. Die laufen im XMP Profil (der Subtiming Wert so gar noch etwas straffer als vorgesehen), das stellt bei Vollbestückung eine mögliche Fehlerquelle dar.

Stelle die RAM Timings auf 9-9-9-25-34.

Mache auch noch eine RAM Prüfung mit Memtest86+.
 
Zuletzt bearbeitet:
Zurück