Hallo @all,
Ich benötige mal eure Hilfe. Seit kurzer Zeit habe ich ab und zu Abstürze mit Bluescreen wenn ich mit Qutlook 2007 Sp2 arbeite, Entweder Bluescreen beim öffnen oder einfach während dem Arbeiten mit Qutlook oder beim schließen von Qutlook. Ich habe mal ein Speicherabbild gemacht und angehängt. Kann mir einer bei der Auswertung behilflich sein?
Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini122811-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b240
Debug session time: Wed Dec 28 17:10:38.337 2011 (GMT+1)
System Uptime: 0 days 0:05:38.907
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
.............................................................................................................................
Loading unloaded module list
........
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 10000050, {ffffeff8, 0, 8054b632, 0}
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffeff8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8054b632, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
MODULE_NAME: nt
FAULTING_MODULE: 804d7000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4d00dbda
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
unable to get nt!MiSessionPoolStart
unable to get nt!MiSessionPoolEnd
ffffeff8
FAULTING_IP:
nt+74632
8054b632 668b4efa mov cx,[esi-0x6]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x50
LAST_CONTROL_TRANSFER: from 80591975 to 8054b632
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
a9fb8c24 80591975 ffffeffe 00000000 e2ef8058 nt+0x74632
a9fb8c40 80591d4e e2ef8058 e11e57d8 e102a5d4 nt+0xba975
a9fb8c54 80591607 e323bc38 e1a51b60 805690f5 nt+0xbad4e
a9fb8c68 80568f27 e11e57d8 e11e57d8 00000001 nt+0xba607
a9fb8c80 80568f43 e11e57d8 a9fb8ca4 8056ab6a nt+0x91f27
a9fb8c8c 8056ab6a e11e57d8 00000000 e2962e28 nt+0x91f43
a9fb8ca4 805647f7 e2962e40 e2962e28 00000000 nt+0x93b6a
a9fb8cc0 804e36e5 e2962e40 00000000 00000286 nt+0x8d7f7
a9fb8ce4 80567a57 888d7990 e2b46ef0 88896020 nt+0xc6e5
a9fb8cfc 80567ac0 e2b46ef0 e2962e40 00000286 nt+0x90a57
a9fb8d44 80567b0a 00000286 00000001 00000000 nt+0x90ac0
a9fb8d58 804de7ec 00000286 00ebf7f8 7c91e514 nt+0x90b0a
a9fb8d64 7c91e514 badb0d00 00ebf7f0 00000000 nt+0x77ec
00ebf7f8 00000000 00000000 00000000 00000000 0x7c91e514
STACK_COMMAND: .bugcheck ; kb
FOLLOWUP_NAME: MachineOwner
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
gruß
dk1000
Ich benötige mal eure Hilfe. Seit kurzer Zeit habe ich ab und zu Abstürze mit Bluescreen wenn ich mit Qutlook 2007 Sp2 arbeite, Entweder Bluescreen beim öffnen oder einfach während dem Arbeiten mit Qutlook oder beim schließen von Qutlook. Ich habe mal ein Speicherabbild gemacht und angehängt. Kann mir einer bei der Auswertung behilflich sein?
Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini122811-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b240
Debug session time: Wed Dec 28 17:10:38.337 2011 (GMT+1)
System Uptime: 0 days 0:05:38.907
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
.............................................................................................................................
Loading unloaded module list
........
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 10000050, {ffffeff8, 0, 8054b632, 0}
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffeff8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8054b632, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
MODULE_NAME: nt
FAULTING_MODULE: 804d7000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4d00dbda
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
unable to get nt!MiSessionPoolStart
unable to get nt!MiSessionPoolEnd
ffffeff8
FAULTING_IP:
nt+74632
8054b632 668b4efa mov cx,[esi-0x6]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x50
LAST_CONTROL_TRANSFER: from 80591975 to 8054b632
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
a9fb8c24 80591975 ffffeffe 00000000 e2ef8058 nt+0x74632
a9fb8c40 80591d4e e2ef8058 e11e57d8 e102a5d4 nt+0xba975
a9fb8c54 80591607 e323bc38 e1a51b60 805690f5 nt+0xbad4e
a9fb8c68 80568f27 e11e57d8 e11e57d8 00000001 nt+0xba607
a9fb8c80 80568f43 e11e57d8 a9fb8ca4 8056ab6a nt+0x91f27
a9fb8c8c 8056ab6a e11e57d8 00000000 e2962e28 nt+0x91f43
a9fb8ca4 805647f7 e2962e40 e2962e28 00000000 nt+0x93b6a
a9fb8cc0 804e36e5 e2962e40 00000000 00000286 nt+0x8d7f7
a9fb8ce4 80567a57 888d7990 e2b46ef0 88896020 nt+0xc6e5
a9fb8cfc 80567ac0 e2b46ef0 e2962e40 00000286 nt+0x90a57
a9fb8d44 80567b0a 00000286 00000001 00000000 nt+0x90ac0
a9fb8d58 804de7ec 00000286 00ebf7f8 7c91e514 nt+0x90b0a
a9fb8d64 7c91e514 badb0d00 00ebf7f0 00000000 nt+0x77ec
00ebf7f8 00000000 00000000 00000000 00000000 0x7c91e514
STACK_COMMAND: .bugcheck ; kb
FOLLOWUP_NAME: MachineOwner
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
gruß
dk1000