hi du
so hab das nochmal gemacht nach deiner Anleitung . gib dir jetzt das dump file aus
Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: SRV*C:\symbols*
Symbol information
Executable search path is:
Windows Longhorn Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Kernel base = 0xfffff800`02a1b000 PsLoadedModuleList = 0xfffff800`02c58e50
Debug session time: Thu Dec 16 16:42:33.222 2010 (GMT+1)
System Uptime: 0 days 1:28:25.252
Loading Kernel Symbols
...........................................................................................................................................................
Loading unloaded module list
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`7efdf018). Type ".hh dbgerr001" for details
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8000827b50, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339c8 )
Followup: MachineOwner
---------
1: kd> .reload
Loading Kernel Symbols
...........................................................................................................................................................
Loading unloaded module list
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`7efdf018). Type ".hh dbgerr001" for details
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8000827b50
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
OVERLAPPED_MODULE:
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: DRIVER_FAULT
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002aff058 to fffff80002a8b740
STACK_TEXT:
fffff880`097e01d8 fffff800`02aff058 : 00000000`0000001a 00000000`00041790 fffffa80`00827b50 00000000`0000ffff : nt!KeBugCheckEx
fffff880`097e01e0 fffff800`02a5e68a : fffffa80`06a61420 fffffa80`00000000 00000000`000005e4 fffff800`00000000 : nt! ?? ::FNODOBFM::`string'+0x339c8
fffff880`097e0a90 fffff800`02d70dcf : fffff8a0`09691060 00000000`00000001 00000000`00000000 fffffa80`0669fb60 : nt!MmCleanProcessAddressSpace+0x96
fffff880`097e0ae0 fffff800`02d4885b : 00000000`00000000 00000000`00000001 00000000`7efdb000 00000000`00000000 : nt!PspExitThread+0x92f
fffff880`097e0ba0 fffff800`02a8a993 : fffffa80`06a61420 00000000`00000000 00000000`7efdb001 fffffa80`0669fb60 : nt!NtTerminateProcess+0x25b
fffff880`097e0c20 00000000`770d001a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`000cdde8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x770d001a
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+339c8
fffff800`02aff058 cc int 3
SYMBOL_STACK_INDEX: 1
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+339c8
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: kb
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339c8
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339c8
Followup: MachineOwner
---------
weitere Bluescreens mit folgender Fehlermeldung: Memory Managment und Page fualt in nonpaged area. heute am abend 18.50