AW: WINDBG will nicht .dmp file debuggen (Anfänger) Vorher: Windows BSOD: Memory_Management
Upsala, hatte ich ganz vergessen, das hat sich hier teilweise auf zwei Threads verlagert, hier sind die Minidumps mit meinen unqualifizierten Bemerkungen:
Okay, also, die Crashes, die mir am meisten Sorge machen, sind die beiden MEMORY_CORRUPTION_ONE_BIT
Nummero 1:
Loading Dump File [C:\Windows\Minidump\041015-6375-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17668.amd64fre.winblue_r8.150127-1500
Machine Name:
Kernel base = 0xfffff801`d0c7b000 PsLoadedModuleList = 0xfffff801`d0f54250
Debug session time: Fri Apr 10 22:35:00.595 2015 (UTC + 2:00)
System Uptime: 0 days 3:24:17.294
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
..........................
Loading User Symbols
Loading unloaded module list
...........
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41792, fffff68000377000, 8000000, 0}
Probably caused by : memory_corruption ( ONE_BIT )
Followup: MachineOwner
---------
0: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: fffff68000377000
Arg3: 0000000008000000
Arg4: 0000000000000000
Debugging Details:
------------------
MEMORY_CORRUPTOR: ONE_BIT
BUGCHECK_STR: 0x1a_41792
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: NvBackend.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
STACK_TEXT:
ffffd000`3301d308 fffff801`d0df8d78 : 00000000`0000001a 00000000`00041792 fffff680`00377000 00000000`08000000 : nt!KeBugCheckEx
ffffd000`3301d310 fffff801`d0cde223 : ffffe000`ac988080 ffffe000`aa9389a8 00000000`00000000 ffffe000`00000009 : nt! ?? ::FNODOBFM::`string'+0x1cec8
ffffd000`3301d5a0 fffff801`d1017272 : ffffe000`ac7e39b0 ffffe000`ac7e39b0 ffffe000`00000000 ffffe000`00000000 : nt!MiDeleteVad+0x233
ffffd000`3301d6a0 fffff801`d10ce2f4 : 00000000`00040000 ffffd000`3301d800 00000000`00000000 fffff801`d109b02e : nt!MmCleanProcessAddressSpace+0xe2
ffffd000`3301d700 fffff801`d1053c1f : ffffe000`ac7484c0 ffffc000`98363950 ffffd000`3301d800 00000000`00000000 : nt!PspRundownSingleProcess+0xac
ffffd000`3301d790 fffff801`d111e640 : 00000000`40010004 ffffe000`ac988080 ffffd000`3301db00 ffffe000`ac988128 : nt!PspExitThread+0x573
ffffd000`3301d8a0 fffff801`d0d12aea : 00000000`00000000 ffffe000`ac9863d0 00000000`00000001 00000000`00000000 : nt!KiSchedulerApcTerminate+0x18
ffffd000`3301d8d0 fffff801`d0dd08c0 : 00000000`0749ee70 ffffd000`3301d950 fffff801`d0d11d54 00000000`00000000 : nt!KiDeliverApc+0x2fa
ffffd000`3301d950 fffff801`d0dd725a : 00000000`00000488 00000000`0749ee70 00000000`00000010 00000000`0759fc98 : nt!KiInitiateUserApc+0x70
ffffd000`3301da90 00007fff`fe61287a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
00000000`0749e758 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`fe61287a
STACK_COMMAND: kb
SYMBOL_NAME: ONE_BIT
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION:
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Followup: MachineOwner
---------
Numero 2:
Loading Dump File [C:\Windows\Minidump\041015-7015-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17668.amd64fre.winblue_r8.150127-1500
Machine Name:
Kernel base = 0xfffff801`b8c19000 PsLoadedModuleList = 0xfffff801`b8ef2250
Debug session time: Fri Apr 10 19:10:20.556 2015 (UTC + 2:00)
System Uptime: 15 days 0:11:07.505
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
............................
Loading User Symbols
Loading unloaded module list
..................................................
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41792, fffff680003ab7b8, 10000000000000, 0}
Probably caused by : memory_corruption ( ONE_BIT )
Followup: MachineOwner
---------
2: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: fffff680003ab7b8
Arg3: 0010000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
MEMORY_CORRUPTOR: ONE_BIT
BUGCHECK_STR: 0x1a_41792
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
STACK_TEXT:
ffffd000`348da378 fffff801`b8d96d78 : 00000000`0000001a 00000000`00041792 fffff680`003ab7b8 00100000`00000000 : nt!KeBugCheckEx
ffffd000`348da380 fffff801`b8c7c223 : ffffe000`516f0080 ffffe000`4d7f1ce8 00000000`00000000 ffffe000`00000009 : nt! ?? ::FNODOBFM::`string'+0x1cec8
ffffd000`348da610 fffff801`b8fb5272 : ffffe000`53b1a640 ffffe000`53b1a640 ffffe000`00000000 ffffe000`00000000 : nt!MiDeleteVad+0x233
ffffd000`348da710 fffff801`b906c2f4 : 00000000`00040000 ffffd000`348da840 00000000`00000000 00000000`00000000 : nt!MmCleanProcessAddressSpace+0xe2
ffffd000`348da770 fffff801`b8ff1c1f : ffffe000`5070f880 ffffc000`4e8bb1b0 ffffd000`348da840 00000000`00000000 : nt!PspRundownSingleProcess+0xac
ffffd000`348da800 fffff801`b90bc640 : ffffe000`00000000 ffffe000`516f0080 ffffd000`348dab00 ffffe000`516f0128 : nt!PspExitThread+0x573
ffffd000`348da910 fffff801`b8cb0aea : ffffe000`516f0180 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSchedulerApcTerminate+0x18
ffffd000`348da940 fffff801`b8d6e8c0 : 00000000`00000324 ffffd000`348da9c0 fffff801`b8cafd54 00000000`00000000 : nt!KiDeliverApc+0x2fa
ffffd000`348da9c0 fffff801`b8d7525a : ffffe000`516f0080 00000000`00000000 00000000`00000000 ffffe000`4b9f3420 : nt!KiInitiateUserApc+0x70
ffffd000`348dab00 00000000`77782352 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
00000000`054ff0e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77782352
STACK_COMMAND: kb
SYMBOL_NAME: ONE_BIT
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION:
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Followup: MachineOwner
---------
Man sieht, dass ab
ffffd000`3301da90 00007fff`fe61287a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
der Verlauf gleich ist. Es wurden allerdings die beiden Crashes von verschiedenen Programmen verursacht, also ist es Windows oder meine HW.
Dann habe ich einen Crash, bei dem ein Befehl nicht auf den Speicher (RAM?) angewendet werden konnte:
Loading Dump File [C:\Windows\Minidump\041415-7375-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17668.amd64fre.winblue_r8.150127-1500
Machine Name:
Kernel base = 0xfffff800`44e08000 PsLoadedModuleList = 0xfffff800`450e1250
Debug session time: Tue Apr 14 22:40:59.455 2015 (UTC + 2:00)
System Uptime: 3 days 10:12:18.189
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
.............................
Loading User Symbols
Loading unloaded module list
..................................
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800c0a857b1, ffffd000344aab10, 0}
Probably caused by : dxgmms1.sys ( dxgmms1!VIDMM_LINEAR_POOL::Free+81 )
Followup: MachineOwner
---------
2: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800c0a857b1, Address of the instruction which caused the bugcheck
Arg3: ffffd000344aab10, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
dxgmms1!VIDMM_LINEAR_POOL::Free+81
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3
CONTEXT: ffffd000344aab10 -- (.cxr 0xffffd000344aab10;r)
rax=ffffc000d20157e0 rbx=ffffc000d1f5fc40 rcx=feffc000e1b6b740
rdx=ffffe001367e4218 rsi=ffffc000d8c9cb10 rdi=ffffc000cfab8210
rip=fffff800c0a857b1 rsp=ffffd000344ab540 rbp=ffffe001367e41d0
r8=00000000001f5d41 r9=fffff80044e08000 r10=ffffd000d4978d00
r11=ffffe0013ca1ce10 r12=0000000000000000 r13=ffffc000e39c6010
r14=ffffc000cfab8230 r15=ffffffffffffffff
iopl=0 nv up ei ng nz ac pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010293
dxgmms1!VIDMM_LINEAR_POOL::Free+0x81:
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3 ds:002b:feffc000`e1b6b710=????????
Last set context:
rax=ffffc000d20157e0 rbx=ffffc000d1f5fc40 rcx=feffc000e1b6b740
rdx=ffffe001367e4218 rsi=ffffc000d8c9cb10 rdi=ffffc000cfab8210
rip=fffff800c0a857b1 rsp=ffffd000344ab540 rbp=ffffe001367e41d0
r8=00000000001f5d41 r9=fffff80044e08000 r10=ffffd000d4978d00
r11=ffffe0013ca1ce10 r12=0000000000000000 r13=ffffc000e39c6010
r14=ffffc000cfab8230 r15=ffffffffffffffff
iopl=0 nv up ei ng nz ac pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010293
dxgmms1!VIDMM_LINEAR_POOL::Free+0x81:
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3 ds:002b:feffc000`e1b6b710=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff800c0a844fb to fffff800c0a857b1
STACK_TEXT:
ffffd000`344ab540 fffff800`c0a844fb : ffffc000`d1cd8770 ffffd000`344ab609 ffffc000`cf8f80d0 00000000`00000000 : dxgmms1!VIDMM_LINEAR_POOL::Free+0x81
ffffd000`344ab580 fffff800`c0a83e14 : ffffe001`39fce000 ffffe001`00000001 00000000`00000001 ffffe001`00000000 : dxgmms1!VIDMM_GLOBAL::CloseLocalAllocation+0x18b
ffffd000`344ab670 fffff800`c0a83c32 : ffffc000`dcf25530 fffff800`00000000 ffffe001`00000000 00000000`00000000 : dxgmms1!VIDMM_GLOBAL::CloseOneAllocation+0x194
ffffd000`344ab7f0 fffff800`c0927712 : ffffc000`dd4801c0 ffffd000`344ab9c0 ffffc000`dd90a580 00000000`00000002 : dxgmms1!VIDMM_GLOBAL::CloseAllocation+0x52
ffffd000`344ab830 fffff800`c0921212 : ffffc000`dcf25530 00000000`00000000 ffffc000`00000000 ffffc000`dd4801c0 : dxgkrnl!DXGDEVICE:estroyAllocations+0x172
ffffd000`344ab930 fffff800`44f641b3 : ffffe001`3b5e6080 00000000`009bdb20 ffffe001`3681d701 00000000`00000000 : dxgkrnl!DxgkPresent+0x682
ffffd000`344abb00 00000000`7721773a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`009bdad8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7721773a
FOLLOWUP_IP:
dxgmms1!VIDMM_LINEAR_POOL::Free+81
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: dxgmms1!VIDMM_LINEAR_POOL::Free+81
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: dxgmms1
IMAGE_NAME: dxgmms1.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 54505506
IMAGE_VERSION: 6.3.9600.17415
STACK_COMMAND: .cxr 0xffffd000344aab10 ; kb
BUCKET_ID_FUNC_OFFSET: 81
FAILURE_BUCKET_ID: 0x3B_dxgmms1!VIDMM_LINEAR_POOL::Free
BUCKET_ID: 0x3B_dxgmms1!VIDMM_LINEAR_POOL::Free
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x3b_dxgmms1!vidmm_linear_pool::free
FAILURE_ID_HASH: {cb8f5010-66bf-3e5f-cd6f-dd5b5360e495}
Followup: MachineOwner
---------
Dann habe ich ein Adressierungsproblem:
Loading Dump File [C:\Windows\Minidump\041915-7781-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17736.amd64fre.winblue_r9.150322-1500
Machine Name:
Kernel base = 0xfffff803`7f274000 PsLoadedModuleList = 0xfffff803`7f54d850
Debug session time: Sun Apr 19 14:12:25.881 2015 (UTC + 2:00)
System Uptime: 2 days 22:14:15.565
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
.....................................
Loading User Symbols
Loading unloaded module list
......................................
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {20, 2, 1, fffff8037f2da84b}
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : nvlddmkm.sys ( nvlddmkm+19597c )
Followup: MachineOwner
---------
0: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000020, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8037f2da84b, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff8037f5d7138
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSizeOfNonPagedPoolInBytes
0000000000000020
CURRENT_IRQL: 2
FAULTING_IP:
nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+1b
fffff803`7f2da84b 488711 xchg rdx,qword ptr [rcx]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
TRAP_FRAME: ffffd0002516c840 -- (.trap 0xffffd0002516c840)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=02200000000bb76e rbx=0000000000000000 rcx=0000000000000020
rdx=ffffd0002516ca18 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8037f2da84b rsp=ffffd0002516c9d8 rbp=ffffd0002516ca48
r8=ffffd0002516ca18 r9=fffff8037f274000 r10=0000000000000003
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+0x1b:
fffff803`7f2da84b 488711 xchg rdx,qword ptr [rcx] ds:00000000`00000020=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8037f3d07e9 to fffff8037f3c4ca0
STACK_TEXT:
ffffd000`2516c6f8 fffff803`7f3d07e9 : 00000000`0000000a 00000000`00000020 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd000`2516c700 fffff803`7f3cf03a : 00000000`00000001 fffffa80`03abf660 00000000`00000000 00000000`00000001 : nt!KiBugCheckDispatch+0x69
ffffd000`2516c840 fffff803`7f2da84b : fffff803`7f3395d2 00000000`80000000 ffffe001`0f717d98 000000a4`16107000 : nt!KiPageFault+0x23a
ffffd000`2516c9d8 fffff803`7f3395d2 : 00000000`80000000 ffffe001`0f717d98 000000a4`16107000 fffff580`10804000 : nt!KeAcquireInStackQueuedSpinLockAtDpcLevel+0x1b
ffffd000`2516c9e0 fffff803`7f2c4800 : fffff803`7f577180 fffff680`520b0840 ffffd000`00000000 00000000`00000005 : nt!MiUnlinkPageFromLockedList+0x892
ffffd000`2516ca70 fffff803`7f2c761f : ffffe001`0f717d98 00000000`00000000 00000000`00000000 ffffd000`2516cc30 : nt!MiDispatchFault+0x590
ffffd000`2516cbb0 fffff803`7f31dc91 : 00000000`00000001 ffffffff`ffffffff 00000000`ffffff00 ffffffff`ffffffff : nt!MmAccessFault+0x54f
ffffd000`2516cd70 fffff803`7f31d321 : ffffd000`00000001 00000000`00000002 ffffd000`00000001 00000000`00000002 : nt!MiProbeLeafFrame+0x3d1
ffffd000`2516cea0 fffff801`d6a8d97c : 00000000`000029b7 fffff801`d6c45c00 ffffe001`00000002 ffffe001`12cf6990 : nt!MmProbeAndLockPages+0x241
ffffd000`2516cf80 00000000`000029b7 : fffff801`d6c45c00 ffffe001`00000002 ffffe001`12cf6990 00000000`00000000 : nvlddmkm+0x19597c
ffffd000`2516cf88 fffff801`d6c45c00 : ffffe001`00000002 ffffe001`12cf6990 00000000`00000000 00000000`00000000 : 0x29b7
ffffd000`2516cf90 ffffe001`00000002 : ffffe001`12cf6990 00000000`00000000 00000000`00000000 ffffd000`2516cff0 : nvlddmkm+0x34dc00
ffffd000`2516cf98 ffffe001`12cf6990 : 00000000`00000000 00000000`00000000 ffffd000`2516cff0 00000000`00000002 : 0xffffe001`00000002
ffffd000`2516cfa0 00000000`00000000 : 00000000`00000000 ffffd000`2516cff0 00000000`00000002 ffffe001`00000000 : 0xffffe001`12cf6990
STACK_COMMAND: kb
FOLLOWUP_IP:
nvlddmkm+19597c
fffff801`d6a8d97c ?? ???
SYMBOL_STACK_INDEX: 9
SYMBOL_NAME: nvlddmkm+19597c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nvlddmkm
IMAGE_NAME: nvlddmkm.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 550304cc
FAILURE_BUCKET_ID: AV_nvlddmkm+19597c
BUCKET_ID: AV_nvlddmkm+19597c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_nvlddmkm+19597c
FAILURE_ID_HASH: {b9e8e40e-4420-1356-a3a1-6dc80e526639}
Followup: MachineOwner
---------
Dann habe ich nochmal das selbe, dass ein Befehl nicht auf den Speicher angewendet werden konnte, ist der selbe Befehl:
Loading Dump File [C:\Windows\Minidump\041415-7375-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17668.amd64fre.winblue_r8.150127-1500
Machine Name:
Kernel base = 0xfffff800`44e08000 PsLoadedModuleList = 0xfffff800`450e1250
Debug session time: Tue Apr 14 22:40:59.455 2015 (UTC + 2:00)
System Uptime: 3 days 10:12:18.189
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
.............................
Loading User Symbols
Loading unloaded module list
..................................
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800c0a857b1, ffffd000344aab10, 0}
Probably caused by : dxgmms1.sys ( dxgmms1!VIDMM_LINEAR_POOL::Free+81 )
Followup: MachineOwner
---------
2: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800c0a857b1, Address of the instruction which caused the bugcheck
Arg3: ffffd000344aab10, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
dxgmms1!VIDMM_LINEAR_POOL::Free+81
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3
CONTEXT: ffffd000344aab10 -- (.cxr 0xffffd000344aab10;r)
rax=ffffc000d20157e0 rbx=ffffc000d1f5fc40 rcx=feffc000e1b6b740
rdx=ffffe001367e4218 rsi=ffffc000d8c9cb10 rdi=ffffc000cfab8210
rip=fffff800c0a857b1 rsp=ffffd000344ab540 rbp=ffffe001367e41d0
r8=00000000001f5d41 r9=fffff80044e08000 r10=ffffd000d4978d00
r11=ffffe0013ca1ce10 r12=0000000000000000 r13=ffffc000e39c6010
r14=ffffc000cfab8230 r15=ffffffffffffffff
iopl=0 nv up ei ng nz ac pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010293
dxgmms1!VIDMM_LINEAR_POOL::Free+0x81:
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3 ds:002b:feffc000`e1b6b710=????????
Last set context:
rax=ffffc000d20157e0 rbx=ffffc000d1f5fc40 rcx=feffc000e1b6b740
rdx=ffffe001367e4218 rsi=ffffc000d8c9cb10 rdi=ffffc000cfab8210
rip=fffff800c0a857b1 rsp=ffffd000344ab540 rbp=ffffe001367e41d0
r8=00000000001f5d41 r9=fffff80044e08000 r10=ffffd000d4978d00
r11=ffffe0013ca1ce10 r12=0000000000000000 r13=ffffc000e39c6010
r14=ffffc000cfab8230 r15=ffffffffffffffff
iopl=0 nv up ei ng nz ac pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010293
dxgmms1!VIDMM_LINEAR_POOL::Free+0x81:
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3 ds:002b:feffc000`e1b6b710=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff800c0a844fb to fffff800c0a857b1
STACK_TEXT:
ffffd000`344ab540 fffff800`c0a844fb : ffffc000`d1cd8770 ffffd000`344ab609 ffffc000`cf8f80d0 00000000`00000000 : dxgmms1!VIDMM_LINEAR_POOL::Free+0x81
ffffd000`344ab580 fffff800`c0a83e14 : ffffe001`39fce000 ffffe001`00000001 00000000`00000001 ffffe001`00000000 : dxgmms1!VIDMM_GLOBAL::CloseLocalAllocation+0x18b
ffffd000`344ab670 fffff800`c0a83c32 : ffffc000`dcf25530 fffff800`00000000 ffffe001`00000000 00000000`00000000 : dxgmms1!VIDMM_GLOBAL::CloseOneAllocation+0x194
ffffd000`344ab7f0 fffff800`c0927712 : ffffc000`dd4801c0 ffffd000`344ab9c0 ffffc000`dd90a580 00000000`00000002 : dxgmms1!VIDMM_GLOBAL::CloseAllocation+0x52
ffffd000`344ab830 fffff800`c0921212 : ffffc000`dcf25530 00000000`00000000 ffffc000`00000000 ffffc000`dd4801c0 : dxgkrnl!DXGDEVICE:estroyAllocations+0x172
ffffd000`344ab930 fffff800`44f641b3 : ffffe001`3b5e6080 00000000`009bdb20 ffffe001`3681d701 00000000`00000000 : dxgkrnl!DxgkPresent+0x682
ffffd000`344abb00 00000000`7721773a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`009bdad8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7721773a
FOLLOWUP_IP:
dxgmms1!VIDMM_LINEAR_POOL::Free+81
fffff800`c0a857b1 8379d003 cmp dword ptr [rcx-30h],3
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: dxgmms1!VIDMM_LINEAR_POOL::Free+81
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: dxgmms1
IMAGE_NAME: dxgmms1.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 54505506
IMAGE_VERSION: 6.3.9600.17415
STACK_COMMAND: .cxr 0xffffd000344aab10 ; kb
BUCKET_ID_FUNC_OFFSET: 81
FAILURE_BUCKET_ID: 0x3B_dxgmms1!VIDMM_LINEAR_POOL::Free
BUCKET_ID: 0x3B_dxgmms1!VIDMM_LINEAR_POOL::Free
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x3b_dxgmms1!vidmm_linear_pool::free
FAILURE_ID_HASH: {cb8f5010-66bf-3e5f-cd6f-dd5b5360e495}
Followup: MachineOwner
---------
Dann aus diesem hier werde ich wenig schlau:
Loading Dump File [C:\Windows\Minidump\041915-6296-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17736.amd64fre.winblue_r9.150322-1500
Machine Name:
Kernel base = 0xfffff803`88a07000 PsLoadedModuleList = 0xfffff803`88ce0850
Debug session time: Sun Apr 19 20:40:40.560 2015 (UTC + 2:00)
System Uptime: 0 days 6:27:51.245
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
...................................
Loading User Symbols
Loading unloaded module list
.........
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41284, 1f673000, 0, fffff58010804000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+11313 )
Followup: MachineOwner
---------
3: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: 000000001f673000
Arg3: 0000000000000000
Arg4: fffff58010804000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: chrome.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff80388b794d3 to fffff80388b57ca0
STACK_TEXT:
ffffd000`34988008 fffff803`88b794d3 : 00000000`0000001a 00000000`00041284 00000000`1f673000 00000000`00000000 : nt!KeBugCheckEx
ffffd000`34988010 fffff803`88a5450d : 80000000`00000867 ffffd000`34988160 ffffffff`ffffffff fffff580`10804000 : nt! ?? ::FNODOBFM::`string'+0x11313
ffffd000`34988060 fffff803`88a4b240 : ffffe001`75fc5210 00000000`00000000 ffffe001`00000000 00000000`00000000 : nt!MiDecommitPages+0x36d
ffffd000`349889a0 fffff803`88b634b3 : 00000000`00000001 00000000`00000000 00000000`00000001 ffffe001`00000000 : nt!NtFreeVirtualMemory+0x650
ffffd000`34988b00 00007ffc`3d0013aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0040e468 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`3d0013aa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+11313
fffff803`88b794d3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+11313
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 550f41a6
IMAGE_VERSION: 6.3.9600.17736
BUCKET_ID_FUNC_OFFSET: 11313
FAILURE_BUCKET_ID: 0x1a_41284_nt!_??_::FNODOBFM::_string_
BUCKET_ID: 0x1a_41284_nt!_??_::FNODOBFM::_string_
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x1a_41284_nt!_??_::fnodobfm::_string_
FAILURE_ID_HASH: {c39d115f-eaa3-aeb6-09bd-1a63e83e1077}
Followup: MachineOwner
---------
Dann habe ich ein weiteres Adressierungsproblem (Overlap):
Loading Dump File [C:\Windows\Minidump\042215-15000-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17736.amd64fre.winblue_r9.150322-1500
Machine Name:
Kernel base = 0xfffff802`e1813000 PsLoadedModuleList = 0xfffff802`e1aec850
Debug session time: Wed Apr 22 14:19:12.691 2015 (UTC + 2:00)
System Uptime: 0 days 20:02:19.376
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.................................................. ............
.................................................. ..............
.................................
Loading User Symbols
Loading unloaded module list
..................................................
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck FC, {ffffe000fc23a630, 8000000000459963, ffffd001e8ae8e70, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4cd28 )
Followup: MachineOwner
---------
0: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY (fc)
An attempt was made to execute non-executable memory. The guilty driver
is on the stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: ffffe000fc23a630, Virtual address for the attempted execute.
Arg2: 8000000000459963, PTE contents.
Arg3: ffffd001e8ae8e70, (reserved)
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'WUDFRd' and 'EhStorClass.' overlap
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xFC
PROCESS_NAME: Steam.exe
CURRENT_IRQL: 2
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
TRAP_FRAME: ffffd001e8ae8e70 -- (.trap 0xffffd001e8ae8e70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=000000021c127000 rsi=0000000000000000 rdi=0000000000000000
rip=ffffe000fc23a630 rsp=ffffd001e8ae9000 rbp=00000000001a6fc0
r8=000000000029fd9a r9=0000000000000000 r10=0000000000000000
r11=fffff802e197088f r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl zr na pe nc
ffffe000`fc23a630 0100 add dword ptr [rax],eax ds:00000000`00000000=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff802e19c0ee8 to fffff802e1963ca0
STACK_TEXT:
ffffd001`e8ae8c28 fffff802`e19c0ee8 : 00000000`000000fc ffffe000`fc23a630 80000000`00459963 ffffd001`e8ae8e70 : nt!KeBugCheckEx
ffffd001`e8ae8c30 fffff802`e1a11e4e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4cd28
ffffd001`e8ae8c70 fffff802`e1986a11 : fffff802`e1b16180 ffffd001`e8ae8d00 ffffe000`ffdc9880 00000000`00000000 : nt!MiRaisedIrqlFault+0x152
ffffd001`e8ae8cb0 fffff802`e196df2f : 00000000`00000008 fffff802`e1b16180 00000000`80000300 fffff800`ef6a4000 : nt! ?? ::FNODOBFM::`string'+0x12851
ffffd001`e8ae8e70 ffffe000`fc23a630 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x12f
ffffd001`e8ae9000 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffffe000`fc23a630
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4cd28
fffff802`e19c0ee8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4cd28
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 550f41a6
IMAGE_VERSION: 6.3.9600.17736
BUCKET_ID_FUNC_OFFSET: 4cd28
FAILURE_BUCKET_ID: 0xFC_nt!_??_::FNODOBFM::_string_
BUCKET_ID: 0xFC_nt!_??_::FNODOBFM::_string_
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xfc_nt!_??_::fnodobfm::_string_
FAILURE_ID_HASH: {a715e467-86e4-97ce-e0a9-37223e080980}
Followup: MachineOwner
---------
Für mich seht es nach einem RAM Problem aus, blöd, dass ich den Heatsink runtergemacht habe, damit mein CPU Kühler drüber passt Damit habe ich wohl meine Garantie verloren