AW: Bluescreens und Abstürze im neuen pc
gerade ein weiterer bluescreen:
Problemsignatur:
Problemereignisname: BlueScreen
Betriebsystemversion: 6.1.7600.2.0.0.256.28
Gebietsschema-ID: 1031
Zusatzinformationen zum Problem:
BCCode: 27
BCP1: 00000000BAAD0073
BCP2: FFFFF88005C4C868
BCP3: FFFFF88005C4C0D0
BCP4: FFFFF80003089021
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1
Dateien, die bei der Beschreibung des Problems hilfreich sind:
C:\Windows\Minidump\121510-22058-01.dmp
C:\Users\Nico\AppData\Local\Temp\WER-40622-0.sysdata.xml
Lesen Sie unsere Datenschutzbestimmungen online:
Windows 7 Privacy Statement - Microsoft Windows
Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline:
C:\Windows\system32\de-DE\erofflps.txt
Mit debugging tool kam folgender text heraus:
Microsoft (R) Windows Debugger Version 6.10.0003.233 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\121510-22058-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*
Symbol information
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0300d000 PsLoadedModuleList = 0xfffff800`0324ae50
Debug session time: Wed Dec 15 16:41:02.621 2010 (GMT+1)
System Uptime: 0 days 0:20:37.384
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 27, {baad0073, fffff88005c4c868, fffff88005c4c0d0, fffff80003089021}
Probably caused by : csc.sys ( csc!CscCheckTokenMembership+6c )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
RDR_FILE_SYSTEM (27)
If you see RxExceptionFilter on the stack then the 2nd and 3rd parameters are the
exception record and context record. Do a .cxr on the 3rd parameter and then kb to
obtain a more informative stack trace.
The high 16 bits of the first parameter is the RDBSS bugcheck code, which is defined
as follows:
RDBSS_BUG_CHECK_CACHESUP = 0xca550000,
RDBSS_BUG_CHECK_CLEANUP = 0xc1ee0000,
RDBSS_BUG_CHECK_CLOSE = 0xc10e0000,
RDBSS_BUG_CHECK_NTEXCEPT = 0xbaad0000,
Arguments:
Arg1: 00000000baad0073
Arg2: fffff88005c4c868
Arg3: fffff88005c4c0d0
Arg4: fffff80003089021
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88005c4c868 -- (.exr 0xfffff88005c4c868)
ExceptionAddress: fffff80003089021 (nt!RtlSidHashLookup+0x0000000000000031)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88005c4c0d0 -- (.cxr 0xfffff88005c4c0d0)
rax=fffff88005c4cae8 rbx=0000000000000000 rcx=fffff8a0011627d0
rdx=10fffa801196eb40 rsi=fffff8a0011626f0 rdi=0000000000000001
rip=fffff80003089021 rsp=fffff88005c4caa0 rbp=fffffa8003c12b30
r8=0000000000020000 r9=0000000000100000 r10=0000000000000000
r11=fffff88005c4cae8 r12=fffff8a0011627d0 r13=fffff8a0004807b0
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
nt!RtlSidHashLookup+0x31:
fffff800`03089021 440fb72a movzx r13d,word ptr [rdx] ds:002b:10fffa80`1196eb40=????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b50e0
ffffffffffffffff
FOLLOWUP_IP:
csc!CscCheckTokenMembership+6c
fffff880`03f22b94 8ad8 mov bl,al
BUGCHECK_STR: 0x27
LAST_CONTROL_TRANSFER: from fffff80003082cca to fffff80003089021
STACK_TEXT:
fffff880`05c4caa0 fffff800`03082cca : fffffa80`03c12b30 00000000`00000000 fffffa80`03c12b30 fffff8a0`011626f0 : nt!RtlSidHashLookup+0x31
fffff880`05c4caf0 fffff800`0308ac3e : fffff8a0`004807b0 fffff8a0`0123e988 00000000`00000000 00000000`00000000 : nt!SeAccessCheckWithHint+0x23a
fffff880`05c4cbd0 fffff880`03f22b94 : 00000000`00000000 00000000`00000000 fffff8a0`0123e988 fffff8a0`02340ff8 : nt!SeAccessCheck+0x5e
fffff880`05c4cc40 fffff880`03f25380 : 00000000`0000054e 00000000`00000000 00000000`00000000 00000000`00000000 : csc!CscCheckTokenMembership+0x6c
fffff880`05c4ccc0 fffff880`03f25d4b : fffff800`03079100 fffff8a0`0123e830 00000000`00001000 fffff8a0`0217a340 : csc!CscCreateSlashDotOpen+0x360
fffff880`05c4cd80 fffff880`03e92a1c : fffffa80`064b99c0 00000000`00000000 00000000`00000000 fffffa80`064b9900 : csc!CscCreate+0x56f
fffff880`05c4cf90 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : rdbss!RxCollapseOrCreateSrvOpen+0x4dc
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: csc!CscCheckTokenMembership+6c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: csc
IMAGE_NAME: csc.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc22a
STACK_COMMAND: .cxr 0xfffff88005c4c0d0 ; kb
FAILURE_BUCKET_ID: X64_0x27_csc!CscCheckTokenMembership+6c
BUCKET_ID: X64_0x27_csc!CscCheckTokenMembership+6c
Followup: MachineOwner
---------
Weiß keiner Rat??
