BlueScreens

motsch_

Lt. Commander
Registriert
Okt. 2010
Beiträge
1.137
Guten Abend,

ich hatte zwar schon mal einen Thread, aber ich will ihn nicht immer wieder noch oben holen...und der ist inzwischen ziemlich unübersichtlich (auch für andere) geworden.

https://www.computerbase.de/forum/threads/staendig-bluescreens.944283/

So nun zu meinem Problem:

Ich habe erst gestern den PC neu aufgesetzt, d.h. ich habe Windows 7 64 bit neu installiert, und alle Festplattenpartitionen gelöscht!
Doch dann kam ziemlich schnell schon der erste BlueScreen!

Hier der Windbg log:

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\110211-20202-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e1c000 PsLoadedModuleList = 0xfffff800`03061670
Debug session time: Wed Nov 2 21:44:35.978 2011 (UTC + 1:00)
System Uptime: 0 days 0:42:20.149
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {fffff8002e2d866a, 2, 1, fffff80002ec8663}

Probably caused by : hardware ( nt!MiWaitForInPageComplete+767 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff8002e2d866a, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002ec8663, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030cb100
fffff8002e2d866a

CURRENT_IRQL: 2

FAULTING_IP:
nt!MiWaitForInPageComplete+767
fffff800`02ec8663 80050000412bc0 add byte ptr [fffff800`2e2d866a],0C0h

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: System

TRAP_FRAME: fffff880070e88a0 -- (.trap 0xfffff880070e88a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000000060ec rbx=0000000000000000 rcx=00000000000122c4
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ec8663 rsp=fffff880070e8a30 rbp=fffff90000001ed8
r8=fffff800030ce180 r9=fffffa8007086000 r10=0000000000010000
r11=fffff880070e8b00 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiWaitForInPageComplete+0x767:
fffff800`02ec8663 80050000412bc0 add byte ptr [fffff800`2e2d866a],0C0h ds:ccf9:fffff800`2e2d866a=??
Resetting default scope

MISALIGNED_IP:
nt!MiWaitForInPageComplete+767
fffff800`02ec8663 80050000412bc0 add byte ptr [fffff800`2e2d866a],0C0h

LAST_CONTROL_TRANSFER: from fffff80002e981e9 to fffff80002e98c40

STACK_TEXT:
fffff880`070e8758 fffff800`02e981e9 : 00000000`0000000a fffff800`2e2d866a 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`070e8760 fffff800`02e96e60 : 00000000`00000000 00000000`00000000 00000000`00000000 000067ee`af4b0705 : nt!KiBugCheckDispatch+0x69
fffff880`070e88a0 fffff800`02ec8663 : fffff880`070e8ae8 fffff800`03020d80 fffff880`070e8b30 00000000`0000000f : nt!KiPageFault+0x260
fffff880`070e8a30 00000000`00000000 : 00000000`00000010 fffff800`032e8dae fffffa80`087ff000 fffffa80`08d1b1d8 : nt!MiWaitForInPageComplete+0x767


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiWaitForInPageComplete+767
fffff800`02ec8663 80050000412bc0 add byte ptr [fffff800`2e2d866a],0C0h

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!MiWaitForInPageComplete+767

FOLLOWUP_NAME: MachineOwner

DEBUG_FLR_IMAGE_TIMESTAMP: 0

IMAGE_NAME: hardware

MODULE_NAME: hardware

FAILURE_BUCKET_ID: X64_IP_MISALIGNED

BUCKET_ID: X64_IP_MISALIGNED

Followup: MachineOwner
---------
 
RAM habe ich schon geprüft, hdd aber nicht!
Wie jetzt Treiber Problem...habe das System erst neu aufgesetzt, und die Motherboard Treiber alle installiert!
 
AHCI oder IDE im Bios eingestellt
 
IDE!
Habe vorher der Neuinstallation von W7 aml auf AHCI umgestellt, jedoch tauchten die Bluescreens schon viel fürher auf!
 
So heute hatte ich wieder 2 BlueScreens während F1 2011!

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\110611-19640-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03012000 PsLoadedModuleList = 0xfffff800`03257670
Debug session time: Sun Nov 6 14:57:46.475 2011 (UTC + 1:00)
System Uptime: 0 days 1:06:59.666
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1, {778f178a, 0, ffff, fffff880088c2320}

Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceExit+245 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

APC_INDEX_MISMATCH (1)
This is a kernel internal error. The most common reason to see this
bugcheck is when a filesystem or a driver has a mismatched number of
calls to disable and re-enable APCs. The key data item is the
Thread->KernelApcDisable field. A negative value indicates that a driver
has disabled APC calls without re-enabling them. A positive value indicates
that the reverse is true. This check is made on exit from a system call.
Arguments:
Arg1: 00000000778f178a, address of system function (system call)
Arg2: 0000000000000000, Thread->ApcStateIndex << 8 | Previous ApcStateIndex
Arg3: 000000000000ffff, Thread->KernelApcDisable
Arg4: fffff880088c2320, Previous KernelApcDisable

Debugging Details:
------------------


FAULTING_IP:
+6231336365626435
00000000`778f178a ?? ???

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x1

PROCESS_NAME: LogonUI.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff8000308e1e9 to fffff8000308ec40

STACK_TEXT:
fffff880`088c2158 fffff800`0308e1e9 : 00000000`00000001 00000000`778f178a 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
fffff880`088c2160 fffff800`0308e120 : fffffa80`0907a060 00000000`0013eec0 00000000`779d2501 000007fe`f2e18240 : nt!KiBugCheckDispatch+0x69
fffff880`088c22a0 00000000`778f178a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`0013ee88 fffff800`03086210 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778f178a
fffff880`088c26b0 00000009`5c348c68 : fffff800`0309674f 00000000`008a0000 fffff8a0`07f1b552 00000000`000000a5 : nt!KiCallUserMode
fffff880`088c26b8 fffff800`0309674f : 00000000`008a0000 fffff8a0`07f1b552 00000000`000000a5 fffff880`088c2db0 : 0x9`5c348c68
fffff880`088c26c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeWaitForSingleObject+0x19f


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`0308e120 4883ec50 sub rsp,50h

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: nt!KiSystemServiceExit+245

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0x1_SysCallNum_44_nt!KiSystemServiceExit+245

BUCKET_ID: X64_0x1_SysCallNum_44_nt!KiSystemServiceExit+245

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

APC_INDEX_MISMATCH (1)
This is a kernel internal error. The most common reason to see this
bugcheck is when a filesystem or a driver has a mismatched number of
calls to disable and re-enable APCs. The key data item is the
Thread->KernelApcDisable field. A negative value indicates that a driver
has disabled APC calls without re-enabling them. A positive value indicates
that the reverse is true. This check is made on exit from a system call.
Arguments:
Arg1: 00000000778f178a, address of system function (system call)
Arg2: 0000000000000000, Thread->ApcStateIndex << 8 | Previous ApcStateIndex
Arg3: 000000000000ffff, Thread->KernelApcDisable
Arg4: fffff880088c2320, Previous KernelApcDisable

Debugging Details:
------------------


FAULTING_IP:
+6231336365626435
00000000`778f178a ?? ???

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x1

PROCESS_NAME: LogonUI.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff8000308e1e9 to fffff8000308ec40

STACK_TEXT:
fffff880`088c2158 fffff800`0308e1e9 : 00000000`00000001 00000000`778f178a 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
fffff880`088c2160 fffff800`0308e120 : fffffa80`0907a060 00000000`0013eec0 00000000`779d2501 000007fe`f2e18240 : nt!KiBugCheckDispatch+0x69
fffff880`088c22a0 00000000`778f178a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`0013ee88 fffff800`03086210 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778f178a
fffff880`088c26b0 00000009`5c348c68 : fffff800`0309674f 00000000`008a0000 fffff8a0`07f1b552 00000000`000000a5 : nt!KiCallUserMode
fffff880`088c26b8 fffff800`0309674f : 00000000`008a0000 fffff8a0`07f1b552 00000000`000000a5 fffff880`088c2db0 : 0x9`5c348c68
fffff880`088c26c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeWaitForSingleObject+0x19f


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`0308e120 4883ec50 sub rsp,50h

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: nt!KiSystemServiceExit+245

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0x1_SysCallNum_44_nt!KiSystemServiceExit+245

BUCKET_ID: X64_0x1_SysCallNum_44_nt!KiSystemServiceExit+245

Followup: MachineOwner
---------

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\110611-19890-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`0305c000 PsLoadedModuleList = 0xfffff800`032a1670
Debug session time: Sun Nov 6 15:08:21.563 2011 (UTC + 1:00)
System Uptime: 0 days 0:09:55.374
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {fffff7fffb0decc0, 2, 8, fffff7fffb0decc0}

Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff7fffb0decc0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffff7fffb0decc0, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff8000330b100
fffff7fffb0decc0

CURRENT_IRQL: 2

FAULTING_IP:
+6637643738393465
fffff7ff`fb0decc0 ?? ???

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: csrss.exe

TRAP_FRAME: fffff88008054780 -- (.trap 0xfffff88008054780)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000003 rbx=0000000000000000 rcx=fffffa8006b58b60
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff7fffb0decc0 rsp=fffff88008054918 rbp=fffffa8006b58c68
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff8a002a7d930 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
fffff7ff`fb0decc0 ?? ???
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff800030d81e9 to fffff800030d8c40

FAILED_INSTRUCTION_ADDRESS:
+6637643738393465
fffff7ff`fb0decc0 ?? ???

STACK_TEXT:
fffff880`08054638 fffff800`030d81e9 : 00000000`0000000a fffff7ff`fb0decc0 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff880`08054640 fffff800`030d6e60 : fffffa80`07a2d060 fffffa80`069abc10 fffff880`08054a30 fffffa80`06b58b60 : nt!KiBugCheckDispatch+0x69
fffff880`08054780 fffff7ff`fb0decc0 : fffff800`030f4e78 fffffa80`08c73a60 fffff800`033d0556 00000000`00000474 : nt!KiPageFault+0x260
fffff880`08054918 fffff800`030f4e78 : fffffa80`08c73a60 fffff800`033d0556 00000000`00000474 fffffa80`094d3660 : 0xfffff7ff`fb0decc0
fffff880`08054920 fffff800`033e66c6 : fffff8a0`00000000 00000000`00000001 fffffa80`08cf0540 fffff8a0`02a7d800 : nt!KeReleaseSemaphore+0x228
fffff880`080549a0 fffff800`033e3ad0 : 00000000`0402f920 fffffa80`094d3660 fffffa80`06b58b60 00000000`0402f920 : nt!AlpcpDispatchReplyToWaitingThread+0x2d6
fffff880`08054a00 fffff800`033e6279 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000001 : nt!AlpcpSendMessage+0x62e
fffff880`08054b00 fffff800`030d7ed3 : fffffa80`094d3660 fffff880`08054ca0 00000000`0402f878 00000000`0402f968 : nt!NtAlpcSendWaitReceivePort+0xb9
fffff880`08054bb0 00000000`77781b6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0402f858 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77781b6a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiPageFault+260
fffff800`030d6e60 440f20c0 mov rax,cr8

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: nt!KiPageFault+260

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3

FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260

BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260

Followup: MachineOwner
---------
 
Zurück
Oben