Bluescreens durch externe Festplatte am eSATA-Port

H

HuskyNET

Gast
[size=+1]Hallo liebes Forum,[/size]

ich habe seit längerem ein Problem mit meinem Notebook und bis jetzt selbst noch keine Lösung gefunden:

Seit etwa 3 Monaten betreibe ich am eSATA-Port eine externe Festplatte und seit der gleichen Zeit erhalte ich hin und wieder Bluescreens. Oft erscheint der Bluescreen ein paar Minuten (!) nachdem ich die Festplatte über "Hardware sicher entfernen" abgemeldet und anschließend ausgeschaltet habe. Seltener auch "einfach so" während des Betriebes mit und auch ohne angeschlossene Platte.

In letzter Zeit häufen sich die Fälle, in denen kein Bluescreen erscheint, sondern das Bild mit Mauszeiger einfach einfriert (ob hier ein Zusammenhang mit dem Bluescreen-Problem besteht, oder ob das ein ganz anderes, weiteres Problem ist, weiß ich nicht).

Wenn der Rechner bereits mit eingeschalteter Festplatte bootet und die Festplatte währenddessen auch nicht abgemeldet wird, läuft das System meistens (aber auch nicht immer) fehlerfrei. Die meisten Probleme gibt es beim An- oder Abstecken der Festplatte.

Modell: Alienware M15x
CPU: Intel Core i7 820QM
RAM: 2x2GB Samsung DDR3 M471B5673EH1-CH9 @ 1333 MHz
Festplatte: Samsung SSD PM800 256GB
Grafikkarte: nVidia GeForce GTX 260M
Betriebssystem: Windows 7 Professional 64-Bit mit SP1

[size=+1]Was ich schon getestet habe:[/size]

  1. Die Windows Speicherdiagnose lief fehlerfrei durch - ich denke nicht, dass das hier ein Speicherproblem ist, aber wenn gewünscht teste ich auch gerne noch einmal über mehrere Stunden mit Memtest86 :)
  2. Prime95 lief 4 Stunden fehlerfrei (CPU-Temperatur dabei um die 75°C, ansonsten ohne Last um die 45°C)

[size=+1]Zusammenfassung der letzten 3 Bluescreens:[/size]

Das sind die Infos, die "BlueScreenView" ausgibt. Die detaillierte Ausgabe von WinDbg werde ich im nächsten Post noch nachreichen.


Bug Check String: IRQL_NOT_LESS_OR_EQUAL
Bug Check Code: 0x0000000a

Parameter 1: ffffffff`ffffffd0
Parameter 2: 00000000`00000002
Parameter 3: 00000000`00000001
Parameter 4: fffff800`030886e0

Caused By Driver: ntoskrnl.exe
Caused By Address: ntoskrnl.exe+70740

Drivers Found In Stack: ntoskrnl.exe
Bug Check String: IRQL_NOT_LESS_OR_EQUAL
Bug Check Code: 0x0000000a

Parameter 1: ffffffff`ffffffd0
Parameter 2: 00000000`00000002
Parameter 3: 00000000`00000001
Parameter 4: fffff800`0309ef10

Caused By Driver: rimspx64.sys
Caused By Address: rimspx64.sys+fe943cf8

Drivers Found In Stack: ntoskrnl.exe, rimspx64.sys
Bug Check String: IRQL_NOT_LESS_OR_EQUAL
Bug Check Code: 0x0000000a

Parameter 1: ffffffff`ffffffd0
Parameter 2: 00000000`00000002
Parameter 3: 00000000`00000001
Parameter 4: fffff800`030d5f10

Caused By Driver: itecir.sys
Caused By Address: itecir.sys+ffdd4b60

Drivers Found In Stack: itecir.sys, ntoskrnl.exe


[size=+1]Und:[/size]

Das ist die komplette Liste aller Zeitpunkte aus der Windows Ereignisanzeige, an denen Bluescreens auftraten:

Kritisch 11.03.2011 17:22:09 Kernel-Power
Kritisch 03.03.2011 21:12:14 Kernel-Power
Kritisch 28.02.2011 07:54:18 Kernel-Power
Kritisch 25.02.2011 10:20:00 Kernel-Power
Kritisch 25.02.2011 10:10:07 Kernel-Power
Kritisch 25.02.2011 08:23:18 Kernel-Power
Kritisch 24.02.2011 06:43:47 Kernel-Power
Kritisch 16.02.2011 04:43:45 Kernel-Power
Kritisch 13.02.2011 09:58:38 Kernel-Power
Kritisch 12.02.2011 14:48:47 Kernel-Power
Kritisch 07.02.2011 06:31:59 Kernel-Power
Kritisch 07.02.2011 01:07:14 Kernel-Power
Kritisch 05.02.2011 04:18:02 Kernel-Power
Kritisch 30.01.2011 14:29:58 Kernel-Power
Kritisch 29.01.2011 16:58:15 Kernel-Power
Kritisch 24.01.2011 09:28:13 Kernel-Power
Kritisch 23.01.2011 15:36:20 Kernel-Power
Kritisch 22.01.2011 07:52:29 Kernel-Power
Kritisch 21.01.2011 06:05:45 Kernel-Power
Kritisch 16.01.2011 06:33:58 Kernel-Power
Kritisch 15.01.2011 22:20:41 Kernel-Power
Kritisch 12.01.2011 16:59:09 Kernel-Power
Kritisch 11.01.2011 12:25:55 Kernel-Power
Kritisch 03.01.2011 11:49:25 Kernel-Power
Kritisch 27.12.2010 06:29:55 Kernel-Power
Kritisch 19.11.2010 17:34:43 Kernel-Power
Kritisch 05.11.2010 14:44:47 Kernel-Power
Kritisch 29.10.2010 23:22:34 Kernel-Power
Kritisch 29.10.2010 19:49:36 Kernel-Power
Kritisch 29.10.2010 15:52:56 Kernel-Power
Kritisch 28.10.2010 09:10:01 Kernel-Power
Kritisch 26.10.2010 06:26:58 Kernel-Power
Kritisch 22.10.2010 23:19:04 Kernel-Power
Kritisch 21.10.2010 00:49:30 Kernel-Power
Kritisch 18.10.2010 01:11:37 Kernel-Power
Kritisch 16.10.2010 20:24:11 Kernel-Power
Kritisch 16.10.2010 18:34:24 Kernel-Power
Kritisch 14.10.2010 02:05:11 Kernel-Power
Kritisch 13.10.2010 10:34:50 Kernel-Power
Kritisch 13.10.2010 01:51:44 Kernel-Power
Kritisch 12.10.2010 21:33:58 Kernel-Power

Und nun ratet mal, wann ich meine externe Festplatte gekauft habe (ich habe auf der Rechnung nachgesehen): am 12.10.2010 - das ist auch der Tag des ersten Bluescreens... :)

Es scheint da also tatsächlich einen Zusammenhang zu geben. Ich tippe auf ein Treiberproblem, aber wie kann ich mehr darüber herausfinden und das beheben? Der verursachende Treiber ist laut Bluescreens angeblich immer ein anderer, wobei die ntoskrnl.exe immer mit eine Rolle spielt.

So ich hoffe ihr könnt damit erst mal was anfangen. Ich reiche gern noch Infos nach und bin dankbar, wenn ihr mir bei der Behebung des Problems behilflich seid :)
Ergänzung ()


Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\021311-13572-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Longhorn Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Kernel base = 0xfffff800`0300c000 PsLoadedModuleList = 0xfffff800`03249e50
Debug session time: Sun Feb 13 09:57:58.483 2011 (GMT+1)
System Uptime: 0 days 4:10:51.888
Loading Kernel Symbols
................................................................................................................................................................................................................
Loading unloaded module list
...................
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {ffffffffffffffd0, 2, 1, fffff800030886e0}

Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )

Followup: MachineOwner
---------

3: kd> .reload
Loading Kernel Symbols
................................................................................................................................................................................................................
Loading unloaded module list
...................
Loading User Symbols
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffffffffffffd0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff800030886e0, address which referenced memory

Debugging Details:
------------------


OVERLAPPED_MODULE: btwavdt

WRITE_ADDRESS: unable to get MiSystemVaType - probably bad symbols
ffffffffffffffd0

CURRENT_IRQL: 2

FAULTING_IP:
nt!ObfReferenceObject+20
fffff800`030886e0 f0480fc11f lock xadd [rdi],rbx

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from fffff8000307bca9 to fffff8000307c740

STACK_TEXT:
fffff880`0cda4908 fffff800`0307bca9 : 00000000`0000000a ffffffff`ffffffd0 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`0cda4910 fffff800`0307a920 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`0cda4a50 fffff800`030886e0 : fffffa80`000000fa 00000000`00000030 00000000`00000030 00000000`0000000b : nt!KiPageFault+0x260
fffff880`0cda4be0 fffff800`03166b1c : fffffa80`0485a938 fffffa80`0485a938 00000000`00000001 00000000`00000000 : nt!ObfReferenceObject+0x20
fffff880`0cda4c10 fffff800`032e529f : fffffa80`0485a938 00000000`00000001 00000000`00000000 00000000`00007534 : nt!IopDisassociateThreadIrp+0x9c
fffff880`0cda4c40 fffff800`0335f71b : 00000000`00000000 ffffffff`fffe7960 00000000`00000000 00000000`00000000 : nt! ?? ::NNGAKEGL::`string'+0x1e4ca
fffff880`0cda4c70 fffff800`0336341d : 00000000`00000000 fffff800`0331f700 fffffa80`0485a500 00000000`00000000 : nt!PspExitThread+0x58b
fffff880`0cda4d30 fffff800`0305ac26 : fffff880`03163180 00000000`00000080 fffffa80`0485a550 00000000`00000246 : nt!PspTerminateThreadByPointer+0x4d
fffff880`0cda4d80 00000000`00000000 : fffff880`0cda5000 fffff880`0cd9f000 fffff880`0cda49c0 00000000`00000000 : nt!KxStartSystemThread+0x16


FOLLOWUP_IP:
nt!KiPageFault+260
fffff800`0307a920 440f20c0 mov rax,cr8

SYMBOL_STACK_INDEX: 2

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: nt!KiPageFault+260

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd

STACK_COMMAND: kb

FAILURE_BUCKET_ID: X64_0xA_W_nt!KiPageFault+260

BUCKET_ID: X64_0xA_W_nt!KiPageFault+260

Followup: MachineOwner
---------

Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\031111-16489-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Windows Longhorn Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Kernel base = 0xfffff800`03049000 PsLoadedModuleList = 0xfffff800`0328ee90
Debug session time: Fri Mar 11 17:20:39.793 2011 (GMT+1)
System Uptime: 1 days 10:39:02.979
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Loading Kernel Symbols
....................................................................................................................................................................................................................
Loading unloaded module list
.....................................
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {ffffffffffffffd0, 2, 1, fffff800030d5f10}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************

Followup: MachineOwner
---------

4: kd> .reload
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Loading Kernel Symbols
....................................................................................................................................................................................................................
Loading unloaded module list
.....................................
Loading User Symbols
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffffffffffffd0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff800030d5f10, address which referenced memory

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************

MODULE_NAME: nt

FAULTING_MODULE: fffff80003049000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7951a

WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
unable to get nt!MiSessionPoolStart
unable to get nt!MiSessionPoolEnd
ffffffffffffffd0

CURRENT_IRQL: 2

FAULTING_IP:
nt!ObfReferenceObject+20
fffff800`030d5f10 f0480fc11f lock xadd [rdi],rbx

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from fffff800030c8be9 to fffff800030c9640

STACK_TEXT:
fffff880`041578c8 fffff800`030c8be9 : 00000000`0000000a ffffffff`ffffffd0 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`041578d0 fffff800`030c7860 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!KeSynchronizeExecution+0x3d59
fffff880`04157a10 fffff800`030d5f10 : 00000000`00000085 fffff800`030d01c2 00000000`00000000 00000000`0000000b : nt!KeSynchronizeExecution+0x29d0
fffff880`04157ba0 fffff800`031a69bc : fffffa80`04ad6f48 fffffa80`04ad6f48 00000000`00000001 00000000`00000000 : nt!ObfReferenceObject+0x20
fffff880`04157bd0 fffff800`0331a74e : fffffa80`04ad6f48 00000000`00000001 00000000`00000000 00000000`00007532 : nt!IoWriteErrorLogEntry+0x193c
fffff880`04157c00 fffff800`0339edd9 : 00000000`00000030 ffffffff`fffe7960 00000000`00000000 00000000`00000000 : nt!FsRtlNotifyCleanup+0xf8e
fffff880`04157c30 fffff800`0339f465 : 00000000`00000000 fffff800`03366c00 fffffa80`04ad6b00 00000000`00000000 : nt!RtlCopySidAndAttributesArray+0x1559
fffff880`04157d30 fffff800`030bafe6 : fffff880`009b1180 00000000`00000080 fffffa80`04ad6b60 00000000`00000000 : nt!RtlCopySidAndAttributesArray+0x1be5
fffff880`04157d80 00000000`00000000 : fffff880`04158000 fffff880`04152000 fffff880`04157980 00000000`00000000 : nt!KeInitializeSemaphore+0x24a


STACK_COMMAND: .bugcheck ; kb

FOLLOWUP_NAME: MachineOwner

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------
 
Esata Port im AHCI Mode? Windows oder Chipsatz Treiber werden benutzt für Sata /Esata?
 
Über welchen Chipsatz läuft der eSATA ?
Treiber aktuell ?
Was ist im BIOS eingestellt ? AHCI,IDE,RAID ?
Hat die Festplatte noch USB Anschluss ? Wenn ja, funktioniert das ?
 
Im BIOS ist unter "SATA operation" AHCI eingestellt - ich nehme an, dass das auch für den eSATA-Port gilt (eine separate Einstellung habe ich nicht gefunden).

Für SSD und externe Festplatte verwende ich momentan den Standard-Microsoft-Treiber. Bis vor zwei Monaten hatte ich noch den "Intel Rapid Storage Technology Driver 9.6.0.1014" installiert, aber da ich dachte, dass das Problem mit diesem zusammenhängen könnte, hatte ich ihn deinstalliert. Geändert hat das nichts - das Bluescreen-Problem besteht nach wie vor.

marcol1979 schrieb:
Hat die Festplatte noch USB Anschluss ? Wenn ja, funktioniert das ?

Ja, einmal habe ich darüber ein Backup angelegt. Es hat ewig gedauert, aber funktioniert hat es. Ausgiebig getestet habe ich das aber nicht, möglicherweise hatte ich da auch einfach nur Glück und keinen "Bluescreen-Moment" erwischt. Der eSATA-Port funktioniert die meiste Zeit über ja auch.

Gefühlsmäßig würde ich aber trotzdem behaupten wollen, dass das Problem mit eSATA zusammenhängt.

marcol1979 schrieb:
Treiber aktuell ?

Das aktuellste BIOS und die aktuellsten Treiber von der Dell-Webseite sind installiert. Windows-Updates sowie Sicherheitsupdates für alle relevanten Anwendungen sollten auch drauf sein. Norton Internet Security schiebt im Hintergrund Wache.

marcol1979 schrieb:
Über welchen Chipsatz läuft der eSATA ?

PM55
 
Also, ich hab mir deine sehr gute Dokumentation des Fehlers durchgelesen - dann mal bei Dell geschaut, was für ein Controller für die eSATA - Schnittstelle verbaut ist, und ich werd daraus ehrlich gesagt nicht wirklich schlau. Einzig, das eine kombinierte USB2.0/eSATA Schnittstelle benutzt wird finde ich bei Dell, nicht mal im Treiberbereich hab ich was gefunden. Das, und gewisse Erfahrungen mit den Eigenheiten von Dell Notebooks bringen mich zu der Empfehlung mit diesem Problem den Dell Service zu bemühen - mindestens ins Dell Forum zu gehn. ich trau mir jedenfalls nicht zu hier eine Analyse abzugeben.
 
Zurück
Oben