AW: Bluescreen!
so nach 2tagen ruhe, der nächste

aufm desk nur ts3 lief noch, war am quatschen unso.
so hier mal die komplette auswertung:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\032011-19156-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02a0e000 PsLoadedModuleList = 0xfffff800`02c4be50
Debug session time: Sun Mar 20 23:28:41.933 2011 (UTC + 1:00)
System Uptime: 0 days 8:41:16.003
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002a82597, fffff88008f60060, 0}
Probably caused by : ntkrnlmp.exe ( nt!PspReturnQuota+47 )
Followup: MachineOwner
---------
0: kd> !analyze -v!
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002a82597, Address of the instruction which caused the bugcheck
Arg3: fffff88008f60060, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!PspReturnQuota+47
fffff800`02a82597 488b5d00 mov rbx,qword ptr [rbp]
CONTEXT: fffff88008f60060 -- (.cxr 0xfffff88008f60060)
rax=fffff80002c2da00 rbx=fffffa8009bebeb0 rcx=00fff80002c0ca80
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000070
rip=fffff80002a82597 rsp=fffff88008f60a30 rbp=00fff80002c0ca80
r8=0000000000000000 r9=0000000000000070 r10=0000000000000000
r11=fffffa8005920060 r12=0000000000000000 r13=0000000000000000
r14=0000000000000005 r15=00fff80002c0ca80
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!PspReturnQuota+0x47:
fffff800`02a82597 488b5d00 mov rbx,qword ptr [rbp] ss:0018:00fff800`02c0ca80=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: SearchProtocol
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d78594 to fffff80002a82597
STACK_TEXT:
fffff880`08f60a30 fffff800`02d78594 : fffffa80`09bebeb0 00000000`00000070 00fff800`02c0ca80 00000000`00000000 : nt!PspReturnQuota+0x47
fffff880`08f60a90 fffff800`02a838bc : 00fff800`02c0ca80 00000000`00000000 fffffa80`07ca6060 fffffa80`039e0570 : nt!ObpFreeObject+0x224
fffff880`08f60ae0 fffff800`02d92354 : fffffa80`07ca6060 00000000`00000000 fffffa80`05920060 00000000`00000000 : nt!ObfDereferenceObject+0xdc
fffff880`08f60b40 fffff800`02d92254 : 00000000`00000260 fffffa80`07ca6060 fffff8a0`09999d90 00000000`00000260 : nt!ObpCloseHandleTableEntry+0xc4
fffff880`08f60bd0 fffff800`02a7d993 : fffffa80`05920060 fffff880`08f60ca0 00000000`00000000 fffffa80`03f948d0 : nt!ObpCloseHandle+0x94
fffff880`08f60c20 00000000`7773f7aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`001c6a08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7773f7aa
FOLLOWUP_IP:
nt!PspReturnQuota+47
fffff800`02a82597 488b5d00 mov rbx,qword ptr [rbp]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!PspReturnQuota+47
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
STACK_COMMAND: .cxr 0xfffff88008f60060 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!PspReturnQuota+47
BUCKET_ID: X64_0x3B_nt!PspReturnQuota+47
Followup: MachineOwner
---------