- Registriert
- Feb. 2011
- Beiträge
- 28
So hier mal das Ergebnis.....das sind die Bluescreens die öfter vorkommen bei mir.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002ccdaa6, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!SwapContext_PatchXRstor+c0
fffff800`02ccdaa6 c3 ret
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eff0e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: CurseClient.ex
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff8800d548dc8 -- (.exr 0xfffff8800d548dc8)
ExceptionAddress: fffff80002ccdaa6 (nt!SwapContext_PatchXRstor+0x00000000000000c0)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff8800d548e70 -- (.trap 0xfffff8800d548e70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000007fffffd3000 rbx=0000000000000000 rcx=00000000c0000102
rdx=00000000000007ff rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ccdaa6 rsp=fffff8800d549008 rbp=fffffa8004f1eb60
r8=fffffa80058dabb8 r9=0000000000000000 r10=fffffffffffffffd
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!SwapContext_PatchXRstor+0xc0:
fffff800`02ccdaa6 c3 ret
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002d01a39 to fffff80002cc7740
STACK_TEXT:
fffff880`0d5485f8 fffff800`02d01a39 : 00000000`0000001e ffffffff`c0000005 fffff800`02ccdaa6 00000000`00000000 : nt!KeBugCheckEx
fffff880`0d548600 fffff800`02cc6d82 : fffff880`0d548dc8 fffff880`009ea180 fffff880`0d548e70 fffffa80`04f1eb60 : nt!KiDispatchException+0x1b9
fffff880`0d548c90 fffff800`02cc568a : 00000000`00000000 00000000`00000002 00000000`5f6d0000 fffffa80`058dabb8 : nt!KiExceptionDispatch+0xc2
fffff880`0d548e70 fffff800`02ccdaa6 : fffff800`02ccd5da 00000000`00000000 ffffffff`fffffffd 00000000`002f7a00 : nt!KiGeneralProtectionFault+0x10a
fffff880`0d549008 fffff800`02ccd5da : 00000000`00000000 ffffffff`fffffffd 00000000`002f7a00 00000000`00000000 : nt!SwapContext_PatchXRstor+0xc0
fffff880`0d549010 fffff800`02cce992 : fffffa80`00000000 fffffa80`04f1eb60 fffffa80`00000000 fffff880`0000000a : nt!KiSwapContext+0x7a
fffff880`0d549150 fffff800`02ccad4b : 00000000`00000008 fffffa80`05d998d0 00000000`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x1d2
fffff880`0d5491e0 fffff800`02fc0fef : fffff880`0000001f fffff880`0d549520 00000000`00000001 fffffa80`00000006 : nt!KeWaitForMultipleObjects+0x271
fffff880`0d549490 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpWaitForMultipleObjects+0x294
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!SwapContext_PatchXRstor+c0
fffff800`02ccdaa6 c3 ret
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!SwapContext_PatchXRstor+c0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
FAILURE_BUCKET_ID: X64_0x1E_nt!SwapContext_PatchXRstor+c0
BUCKET_ID: X64_0x1E_nt!SwapContext_PatchXRstor+c0
Followup: MachineOwner
---------
1: kd> dt Feb
Symbol not found at address 0000000000000feb.
--------------------------------------------------------------------------------------------------------------------
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {AUSNAHME} Ung ltige Anweisung Es wurde versucht, eine ung ltige Anweisung auszuf hren.
FAULTING_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
CONTEXT: fffff88002850fb0 -- (.cxr 0xfffff88002850fb0)
rax=0000000000000002 rbx=fffffa8007653100 rcx=fffffa8007a61f91
rdx=fffffa8007653111 rsi=0000000000000080 rdi=0000000000000000
rip=fffff80002df951a rsp=fffff88002851980 rbp=fffff80002e54880
r8=fffffa8007653110 r9=fffff80002c55000 r10=fffff88002f63ca0
r11=fffff88002851aa0 r12=0000000000000008 r13=0000000000000000
r14=0000000000000002 r15=000000006e657645
iopl=0 nv up ei pl zr na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010247
nt!ExAllocatePoolWithTag+0x14a:
fffff800`02df951a ff ???
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: audiodg.exe
CURRENT_IRQL: 0
MISALIGNED_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002df951a
STACK_TEXT:
fffff880`02851980 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x14a
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExAllocatePoolWithTag+14a
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .cxr 0xfffff88002850fb0 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
BUCKET_ID: X64_IP_MISALIGNED
Followup: MachineOwner
---------
--------------------------------------------------------------------------------------------------------------------
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c82905, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff8800b15ab90, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02c82905 498b08 mov rcx,qword ptr [r8]
CONTEXT: fffff8800b15ab90 -- (.cxr 0xfffff8800b15ab90)
rax=0000000002cc0002 rbx=0000000000000000 rcx=fffffa8003906120
rdx=bffffa80004a1361 rsi=fffff80002e0bb40 rdi=0000000000000000
rip=fffff80002c82905 rsp=fffff8800b15b560 rbp=fffff8800b15b5c0
r8=bffffa80004a1360 r9=fffff6fc50058b30 r10=fffffa8003906120
r11=fffff6fb7e2802c0 r12=0000000000000000 r13=0000000000000012
r14=0000000000000004 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExpInterlockedPopEntrySListFault16:
fffff800`02c82905 498b08 mov rcx,qword ptr [r8] ds:002b:bffffa80`004a1360=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: TuneUpUtilitie
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c82905
STACK_TEXT:
fffff880`0b15b560 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExpInterlockedPopEntrySListFault16
FOLLOWUP_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02c82905 498b08 mov rcx,qword ptr [r8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExpInterlockedPopEntrySListFault16+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
STACK_COMMAND: .cxr 0xfffff8800b15ab90 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExpInterlockedPopEntrySListFault16+0
BUCKET_ID: X64_0x3B_nt!ExpInterlockedPopEntrySListFault16+0
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002ccdaa6, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!SwapContext_PatchXRstor+c0
fffff800`02ccdaa6 c3 ret
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eff0e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: CurseClient.ex
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff8800d548dc8 -- (.exr 0xfffff8800d548dc8)
ExceptionAddress: fffff80002ccdaa6 (nt!SwapContext_PatchXRstor+0x00000000000000c0)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff8800d548e70 -- (.trap 0xfffff8800d548e70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000007fffffd3000 rbx=0000000000000000 rcx=00000000c0000102
rdx=00000000000007ff rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ccdaa6 rsp=fffff8800d549008 rbp=fffffa8004f1eb60
r8=fffffa80058dabb8 r9=0000000000000000 r10=fffffffffffffffd
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!SwapContext_PatchXRstor+0xc0:
fffff800`02ccdaa6 c3 ret
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002d01a39 to fffff80002cc7740
STACK_TEXT:
fffff880`0d5485f8 fffff800`02d01a39 : 00000000`0000001e ffffffff`c0000005 fffff800`02ccdaa6 00000000`00000000 : nt!KeBugCheckEx
fffff880`0d548600 fffff800`02cc6d82 : fffff880`0d548dc8 fffff880`009ea180 fffff880`0d548e70 fffffa80`04f1eb60 : nt!KiDispatchException+0x1b9
fffff880`0d548c90 fffff800`02cc568a : 00000000`00000000 00000000`00000002 00000000`5f6d0000 fffffa80`058dabb8 : nt!KiExceptionDispatch+0xc2
fffff880`0d548e70 fffff800`02ccdaa6 : fffff800`02ccd5da 00000000`00000000 ffffffff`fffffffd 00000000`002f7a00 : nt!KiGeneralProtectionFault+0x10a
fffff880`0d549008 fffff800`02ccd5da : 00000000`00000000 ffffffff`fffffffd 00000000`002f7a00 00000000`00000000 : nt!SwapContext_PatchXRstor+0xc0
fffff880`0d549010 fffff800`02cce992 : fffffa80`00000000 fffffa80`04f1eb60 fffffa80`00000000 fffff880`0000000a : nt!KiSwapContext+0x7a
fffff880`0d549150 fffff800`02ccad4b : 00000000`00000008 fffffa80`05d998d0 00000000`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x1d2
fffff880`0d5491e0 fffff800`02fc0fef : fffff880`0000001f fffff880`0d549520 00000000`00000001 fffffa80`00000006 : nt!KeWaitForMultipleObjects+0x271
fffff880`0d549490 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpWaitForMultipleObjects+0x294
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!SwapContext_PatchXRstor+c0
fffff800`02ccdaa6 c3 ret
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!SwapContext_PatchXRstor+c0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
FAILURE_BUCKET_ID: X64_0x1E_nt!SwapContext_PatchXRstor+c0
BUCKET_ID: X64_0x1E_nt!SwapContext_PatchXRstor+c0
Followup: MachineOwner
---------
1: kd> dt Feb
Symbol not found at address 0000000000000feb.
--------------------------------------------------------------------------------------------------------------------
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {AUSNAHME} Ung ltige Anweisung Es wurde versucht, eine ung ltige Anweisung auszuf hren.
FAULTING_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
CONTEXT: fffff88002850fb0 -- (.cxr 0xfffff88002850fb0)
rax=0000000000000002 rbx=fffffa8007653100 rcx=fffffa8007a61f91
rdx=fffffa8007653111 rsi=0000000000000080 rdi=0000000000000000
rip=fffff80002df951a rsp=fffff88002851980 rbp=fffff80002e54880
r8=fffffa8007653110 r9=fffff80002c55000 r10=fffff88002f63ca0
r11=fffff88002851aa0 r12=0000000000000008 r13=0000000000000000
r14=0000000000000002 r15=000000006e657645
iopl=0 nv up ei pl zr na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010247
nt!ExAllocatePoolWithTag+0x14a:
fffff800`02df951a ff ???
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: audiodg.exe
CURRENT_IRQL: 0
MISALIGNED_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002df951a
STACK_TEXT:
fffff880`02851980 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x14a
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+14a
fffff800`02df951a ff ???
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExAllocatePoolWithTag+14a
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .cxr 0xfffff88002850fb0 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
BUCKET_ID: X64_IP_MISALIGNED
Followup: MachineOwner
---------
--------------------------------------------------------------------------------------------------------------------
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c82905, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff8800b15ab90, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02c82905 498b08 mov rcx,qword ptr [r8]
CONTEXT: fffff8800b15ab90 -- (.cxr 0xfffff8800b15ab90)
rax=0000000002cc0002 rbx=0000000000000000 rcx=fffffa8003906120
rdx=bffffa80004a1361 rsi=fffff80002e0bb40 rdi=0000000000000000
rip=fffff80002c82905 rsp=fffff8800b15b560 rbp=fffff8800b15b5c0
r8=bffffa80004a1360 r9=fffff6fc50058b30 r10=fffffa8003906120
r11=fffff6fb7e2802c0 r12=0000000000000000 r13=0000000000000012
r14=0000000000000004 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExpInterlockedPopEntrySListFault16:
fffff800`02c82905 498b08 mov rcx,qword ptr [r8] ds:002b:bffffa80`004a1360=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: TuneUpUtilitie
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c82905
STACK_TEXT:
fffff880`0b15b560 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExpInterlockedPopEntrySListFault16
FOLLOWUP_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02c82905 498b08 mov rcx,qword ptr [r8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExpInterlockedPopEntrySListFault16+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
STACK_COMMAND: .cxr 0xfffff8800b15ab90 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExpInterlockedPopEntrySListFault16+0
BUCKET_ID: X64_0x3B_nt!ExpInterlockedPopEntrySListFault16+0
Followup: MachineOwner
---------