Probleme mit Windows 7

Nummer 1

*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c7b23b, Address of the instruction which caused the bugcheck
Arg3: fffff88008176e50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

CONTEXT: fffff88008176e50 -- (.cxr 0xfffff88008176e50)
rax=0000000002cb9de2 rbx=0000000000000000 rcx=00000db1000010fa
rdx=fffff8800817797c rsi=00000000000d9424 rdi=00000000097bf6a0
rip=fffff80002c7b23b rsp=fffff88008177830 rbp=fffff88008177ca0
r8=fffff88008177978 r9=fffff80002e5f720 r10=0000000000000005
r11=fffff8800817795c r12=0000000000000004 r13=00000000000265b1
r14=fffff80002ef2900 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010203
nt!ExQueryPoolUsage+0xe0:
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0 ds:002b:00000db1`000010de=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x3B

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c7b23b

STACK_TEXT:
fffff880`08177830 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExQueryPoolUsage+0xe0


FOLLOWUP_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExQueryPoolUsage+e0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

STACK_COMMAND: .cxr 0xfffff88008176e50 ; kb

FAILURE_BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c7b23b, Address of the instruction which caused the bugcheck
Arg3: fffff88008176e50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

CONTEXT: fffff88008176e50 -- (.cxr 0xfffff88008176e50)
rax=0000000002cb9de2 rbx=0000000000000000 rcx=00000db1000010fa
rdx=fffff8800817797c rsi=00000000000d9424 rdi=00000000097bf6a0
rip=fffff80002c7b23b rsp=fffff88008177830 rbp=fffff88008177ca0
r8=fffff88008177978 r9=fffff80002e5f720 r10=0000000000000005
r11=fffff8800817795c r12=0000000000000004 r13=00000000000265b1
r14=fffff80002ef2900 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010203
nt!ExQueryPoolUsage+0xe0:
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0 ds:002b:00000db1`000010de=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x3B

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c7b23b

STACK_TEXT:
fffff880`08177830 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExQueryPoolUsage+0xe0


FOLLOWUP_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExQueryPoolUsage+e0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

STACK_COMMAND: .cxr 0xfffff88008176e50 ; kb

FAILURE_BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c7b23b, Address of the instruction which caused the bugcheck
Arg3: fffff88008176e50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.

FAULTING_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

CONTEXT: fffff88008176e50 -- (.cxr 0xfffff88008176e50)
rax=0000000002cb9de2 rbx=0000000000000000 rcx=00000db1000010fa
rdx=fffff8800817797c rsi=00000000000d9424 rdi=00000000097bf6a0
rip=fffff80002c7b23b rsp=fffff88008177830 rbp=fffff88008177ca0
r8=fffff88008177978 r9=fffff80002e5f720 r10=0000000000000005
r11=fffff8800817795c r12=0000000000000004 r13=00000000000265b1
r14=fffff80002ef2900 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010203
nt!ExQueryPoolUsage+0xe0:
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0 ds:002b:00000db1`000010de=????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x3B

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c7b23b

STACK_TEXT:
fffff880`08177830 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExQueryPoolUsage+0xe0


FOLLOWUP_IP:
nt!ExQueryPoolUsage+e0
fffff800`02c7b23b 8379e400 cmp dword ptr [rcx-1Ch],0

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExQueryPoolUsage+e0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

STACK_COMMAND: .cxr 0xfffff88008176e50 ; kb

FAILURE_BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

BUCKET_ID: X64_0x3B_nt!ExQueryPoolUsage+e0

Followup: MachineOwner
---------

0: kd> !analyze-v
No export analyze-v found
 
Nummer 2


*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffa8046444064, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800021d714a, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800023050e0
fffffa8046444064

CURRENT_IRQL: 2

FAULTING_IP:
nt!EtwTraceContextSwap+a
fffff800`021d714a 4889742420 mov qword ptr [rsp+20h],rsi

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: smss.exe

TRAP_FRAME: fffff8800255f190 -- (.trap 0xfffff8800255f190)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffff880009c9fc0
rdx=fffffa8004ed2040 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800021d714a rsp=fffff8800255f328 rbp=fffff8800255fdb0
r8=fffffa8004ec40c8 r9=0000000000000000 r10=fffffffffffffffd
r11=fffffa800437db02 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!EtwTraceContextSwap+0xa:
fffff800`021d714a 4889742420 mov qword ptr [rsp+20h],rsi ss:0018:fffff880`0255f348=fffffa8004fd0780
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff800020ce469 to fffff800020cef00

STACK_TEXT:
fffff880`0255f048 fffff800`020ce469 : 00000000`0000000a fffffa80`46444064 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`0255f050 fffff800`020cd0e0 : fffff8a0`00145a98 fffff880`009bf180 00000000`00001400 fffffa80`04a06b10 : nt!KiBugCheckDispatch+0x69
fffff880`0255f190 fffff800`021d714a : fffff800`020d52e2 00000000`00000001 fffff880`009bf180 fffff880`0255fdb0 : nt!KiPageFault+0x260
fffff880`0255f328 fffff800`020d52e2 : 00000000`00000001 fffff880`009bf180 fffff880`0255fdb0 fffffa80`04fd0780 : nt!EtwTraceContextSwap+0xa
fffff880`0255f330 fffff800`020d4dda : 00000000`00000000 fffffa80`04900940 fffffa80`04e57640 00000000`00000001 : nt!SwapContext_PatchXRstor+0xfc
fffff880`0255f370 fffff800`020d6052 : fffffa80`04e27a30 fffffa80`04ed2040 fffffa80`00000000 fffffa80`04fd0780 : nt!KiSwapContext+0x7a
fffff880`0255f4b0 fffff800`020d81af : fffffa80`04fcf600 fffff880`010816df fffffa80`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x1d2
fffff880`0255f540 fffff800`0236effc : fffff880`0255f800 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeWaitForSingleObject+0x19f
fffff880`0255f5e0 fffff800`023708d1 : fffffa80`04fd0780 fffffa80`04f224a0 fffffa80`04f224a0 00000000`000007ff : nt!IopSynchronousApiServiceTail+0x74
fffff880`0255f620 fffff800`020ce153 : fffffa80`04ed2040 fffffa80`04fcf600 fffffa80`048ddb60 fffffa80`04fcf600 : nt!NtFlushBuffersFile+0x195
fffff880`0255f6b0 fffff800`020ca6f0 : fffff800`02532cf5 00000000`00002006 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0255f848 fffff800`02532cf5 : 00000000`00002006 00000000`00000000 00000000`00000000 fffffa80`04916c00 : nt!KiServiceLinkage
fffff880`0255f850 fffff800`02533107 : 00000000`00000000 ffffffff`800001a4 00000000`00000000 fffffa80`04fcf600 : nt!PopCreateHiberFile+0x365
fffff880`0255f970 fffff800`0254fea2 : 00000000`00000000 00000000`00000002 00000000`bff6e000 00000000`00000000 : nt!PopEnableHiberFile+0x207
fffff880`0255f9b0 fffff800`0232f34b : 00000000`00000001 00000000`0000000e ffffffff`800001a8 00000000`00000000 : nt!PoInitHiberServices+0xd2
fffff880`0255f9e0 fffff800`020ce153 : fffffa80`04ed2040 ffffffff`80000058 fffff880`0255fab0 00000000`00000001 : nt!NtInitializeRegistry+0x1ab
fffff880`0255fa30 fffff800`020ca6f0 : fffff800`0232f20f fffffa80`04eb30e0 0000007f`fffffff8 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0255fbc8 fffff800`0232f20f : fffffa80`04eb30e0 0000007f`fffffff8 00000000`00000000 fffffa80`04935b20 : nt!KiServiceLinkage
fffff880`0255fbd0 fffff800`020ce153 : fffffa80`04ed2040 fffffa80`04ec3460 fffff880`0255fca0 00000000`00000044 : nt!NtInitializeRegistry+0x6f
fffff880`0255fc20 00000000`77c30c5a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0029f1a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77c30c5a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!EtwTraceContextSwap+a
fffff800`021d714a 4889742420 mov qword ptr [rsp+20h],rsi

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!EtwTraceContextSwap+a

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

FAILURE_BUCKET_ID: X64_0xA_nt!EtwTraceContextSwap+a

BUCKET_ID: X64_0xA_nt!EtwTraceContextSwap+a

Followup: MachineOwner
---------
Ergänzung ()

Nummer 3


*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff88057b26361, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff80002f54c2c, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec70e0
fffff88057b26361

FAULTING_IP:
nt!MiVerifyImageHeader+74
fffff800`02f54c2c 4088795c mov byte ptr [rcx+5Ch],dil

MM_INTERNAL_CODE: 5

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: rundll32.exe

CURRENT_IRQL: 0

TRAP_FRAME: fffff88006290520 -- (.trap 0xfffff88006290520)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff880062906e8 rbx=0000000000000000 rcx=fffff88006290870
rdx=0000000000001000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002f54c2c rsp=fffff880062906b0 rbp=0000000000000001
r8=000000000000014c r9=0000000000004550 r10=0000000000001000
r11=0000000fffffffff r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!MiVerifyImageHeader+0x74:
fffff800`02f54c2c 4088795c mov byte ptr [rcx+5Ch],dil ds:fffff880`062908cc=00
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002d0eb91 to fffff80002c90f00

STACK_TEXT:
fffff880`062903b8 fffff800`02d0eb91 : 00000000`00000050 fffff880`57b26361 00000000`00000001 fffff880`06290520 : nt!KeBugCheckEx
fffff880`062903c0 fffff800`02c8efee : 00000000`00000001 fffff880`0d0d8100 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x40f5b
fffff880`06290520 fffff800`02f54c2c : 00000000`00000000 00000000`00000000 fffffa80`00330ff0 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`062906b0 fffff800`02f53ec8 : 00000000`00000000 00000000`00000001 00000000`00001000 00000000`00000100 : nt!MiVerifyImageHeader+0x74
fffff880`062906f0 fffff800`02f89555 : fffffa80`03b0da80 00000000`00000000 00000000`00000002 fffff880`062909a0 : nt!MiCreateImageFileMap+0x26c
fffff880`06290920 fffff800`02f7e893 : fffff880`06290b80 00000000`00000000 00000000`00000000 fffff880`06290b78 : nt!MmCreateSection+0x7a9
fffff880`06290b30 fffff800`02c90153 : fffffa80`079f9ac0 00000000`001dd0f8 fffff880`06290bc8 00000000`001dd230 : nt!NtCreateSection+0x162
fffff880`06290bb0 00000000`7712035a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`001dd0d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7712035a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiVerifyImageHeader+74
fffff800`02f54c2c 4088795c mov byte ptr [rcx+5Ch],dil

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!MiVerifyImageHeader+74

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: X64_0x50_nt!MiVerifyImageHeader+74

BUCKET_ID: X64_0x50_nt!MiVerifyImageHeader+74

Followup: MachineOwner
---------
 
Die Ramriegel scheinen jeder für sich alleine zu funktionieren.

Hier mal noch 3 Crashdumps:

Nr.1


DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff8800340bc80, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff88003e07517, address which referenced memory

Debugging Details:
------------------


WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef90e0
fffff8800340bc80

CURRENT_IRQL: 2

FAULTING_IP:
USBPORT!USBPORT_ProcessNeoStateChangeList+af
fffff880`03e07517 899c2480000000 mov dword ptr [rsp+80h],ebx

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: System

TRAP_FRAME: fffff88002ffba70 -- (.trap 0xfffff88002ffba70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000000000b400 rbx=0000000000000000 rcx=fffffa8004e63168
rdx=0000000000000002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88003e07517 rsp=fffff88002ffbc00 rbp=fffffa8004e62050
r8=fffffa8004e621a0 r9=0000000000000000 r10=0000000000018505
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
USBPORT!USBPORT_ProcessNeoStateChangeList+0xaf:
fffff880`03e07517 899c2480000000 mov dword ptr [rsp+80h],ebx ss:fffff880`02ffbc80=04e621a0
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002cc0c69 to fffff80002cc1700

STACK_TEXT:
fffff880`02ffb928 fffff800`02cc0c69 : 00000000`0000000a fffff880`0340bc80 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`02ffb930 fffff800`02cbf8e0 : fffffa80`04e621a0 00000000`0000b400 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`02ffba70 fffff880`03e07517 : fffffa80`04e621a0 fffffa80`04e62050 00000000`ffffffff 00000000`00000000 : nt!KiPageFault+0x260
fffff880`02ffbc00 fffff880`03e2d4ef : fffffa80`04e62102 00000000`00000201 fffffa80`04e621a0 fffffa80`04e621a0 : USBPORT!USBPORT_ProcessNeoStateChangeList+0xaf
fffff880`02ffbc70 fffff800`02cccc0c : fffff880`02fd3180 fffffa80`04e62050 fffffa80`04e63178 00000000`00000000 : USBPORT!USBPORT_IsrDpc+0x1f3
fffff880`02ffbcd0 fffff800`02cc9eea : fffff880`02fd3180 fffff880`02fddfc0 00000000`00000000 fffff880`03e2d2fc : nt!KiRetireDpcList+0x1bc
fffff880`02ffbd80 00000000`00000000 : fffff880`02ffc000 fffff880`02ff6000 fffff880`02ffbd40 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND: kb

FOLLOWUP_IP:
USBPORT!USBPORT_ProcessNeoStateChangeList+af
fffff880`03e07517 899c2480000000 mov dword ptr [rsp+80h],ebx

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: USBPORT!USBPORT_ProcessNeoStateChangeList+af

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: USBPORT

IMAGE_NAME: USBPORT.SYS

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bcc07

FAILURE_BUCKET_ID: X64_0xD1_USBPORT!USBPORT_ProcessNeoStateChangeList+af

BUCKET_ID: X64_0xD1_USBPORT!USBPORT_ProcessNeoStateChangeList+af

Followup: MachineOwner
---------

Nr. 2


PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffdb00e2153a11, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff960000ea7b1, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000007, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec50e0
ffffdb00e2153a11

FAULTING_IP:
win32k!vExpandAndCopyText+111
fffff960`000ea7b1 00448b41 add byte ptr [rbx+rcx*4+41h],al

MM_INTERNAL_CODE: 7

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: LCDMedia.exe

CURRENT_IRQL: 0

TRAP_FRAME: fffff88008824c60 -- (.trap 0xfffff88008824c60)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000c23ed041 rbx=0000000000000000 rcx=fffff88008824e70
rdx=fffff900c23ed010 rsi=0000000000000000 rdi=0000000000000000
rip=fffff960000ea7b1 rsp=fffff88008824df0 rbp=fffff88008825790
r8=fffff900c0081050 r9=fffff900c0081238 r10=0000000000000014
r11=000000000000002a r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
win32k!vExpandAndCopyText+0x111:
fffff960`000ea7b1 00448b41 add byte ptr [rbx+rcx*4+41h],al ds:ffffe200`22093a01=??
Resetting default scope

MISALIGNED_IP:
win32k!vExpandAndCopyText+111
fffff960`000ea7b1 00448b41 add byte ptr [rbx+rcx*4+41h],al

LAST_CONTROL_TRANSFER: from fffff80002d0c959 to fffff80002c8d700

STACK_TEXT:
fffff880`08824af8 fffff800`02d0c959 : 00000000`00000050 ffffdb00`e2153a11 00000000`00000001 fffff880`08824c60 : nt!KeBugCheckEx
fffff880`08824b00 fffff800`02c8b7ee : 00000000`00000001 fffff900`c00c0010 00000000`00000000 fffff800`02ca77c0 : nt! ?? ::FNODOBFM::`string'+0x40dcb
fffff880`08824c60 fffff960`000ea7b1 : 00000000`00000000 00000000`00000111 fffffa80`079b8060 00000000`00000001 : nt!KiPageFault+0x16e
fffff880`08824df0 fffff960`000c4e78 : 00000000`00000000 fffff900`c2595020 fffff900`c0081050 00000000`fffffffe : win32k!vExpandAndCopyText+0x111
fffff880`08825180 fffff960`000c3a65 : fffff900`00000014 fffff880`0000002a fffff900`c23ed010 fffff880`088256d0 : win32k!EngTextOut+0xe28
fffff880`08825510 fffff960`000c1ccf : fffff900`c21da738 00000000`0000002f 00000000`00000000 00000000`01011513 : win32k!GreExtTextOutWLocked+0x1d29
fffff880`08825930 fffff960`0028b751 : 00000000`00000000 fffff880`08825ca0 fffff900`c00812a8 fffff960`001547c2 : win32k!GreExtTextOutWInternal+0x10f
fffff880`088259e0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!NtGdiExtTextOutW+0x341


STACK_COMMAND: kb

FOLLOWUP_IP:
win32k!vExpandAndCopyText+111
fffff960`000ea7b1 00448b41 add byte ptr [rbx+rcx*4+41h],al

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: win32k!vExpandAndCopyText+111

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: hardware

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MODULE_NAME: hardware

FAILURE_BUCKET_ID: X64_IP_MISALIGNED

BUCKET_ID: X64_IP_MISALIGNED

Followup: MachineOwner
---------


Nr. 3


Could not read faulting driver name

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb30e0
fffff8810229ca18

FAULTING_IP:
nt!RtlpCopyAces+5b
fffff800`02f417ab 48898424e0000000 mov qword ptr [rsp+0E0h],rax

MM_INTERNAL_CODE: 5

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: CCC.exe

CURRENT_IRQL: 0

TRAP_FRAME: fffff880023906e0 -- (.trap 0xfffff880023906e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff88002390a18 rbx=0000000000000000 rcx=fffff88002390cf0
rdx=fffffa800396e9dc rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002f417ab rsp=fffff88002390870 rbp=fffff8a0038f9700
r8=0000000000000001 r9=fffffa8003961300 r10=fffff8a003848620
r11=fffff8a003848648 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!RtlpCopyAces+0x5b:
fffff800`02f417ab 48898424e0000000 mov qword ptr [rsp+0E0h],rax ss:0018:fffff880`02390950=fffff80002e0a9e0
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002cfa9d1 to fffff80002c7b700

STACK_TEXT:
fffff880`02390578 fffff800`02cfa9d1 : 00000000`00000050 fffff881`0229ca18 00000000`00000000 fffff880`023906e0 : nt!KeBugCheckEx
fffff880`02390580 fffff800`02c797ee : 00000000`00000000 00000000`00000000 00001f80`00100000 0053002b`002b0010 : nt! ?? ::FNODOBFM::`string'+0x40e4b
fffff880`023906e0 fffff800`02f417ab : fffff6fb`40000800 fffff800`02c957c0 fffff6fb`40000800 fffff880`02390900 : nt!KiPageFault+0x16e
fffff880`02390870 fffff800`02f8b61e : fffff6fb`40000800 fffffa80`07a41060 00000000`00000000 00000000`00000801 : nt!RtlpCopyAces+0x5b
fffff880`023909a0 fffff800`02f8af11 : 00000000`00000000 fffff880`02390c68 00000000`00000000 00000000`00000700 : nt!RtlpInheritAcl2+0x18e
fffff880`02390a60 fffff800`02f89eb1 : 00000000`00000003 00000000`00000000 00000000`000000c8 fffff8a0`0384869c : nt!RtlpInheritAcl+0x17d
fffff880`02390b20 fffff800`02f41422 : fffff880`02391280 00000000`00000000 fffffa80`0396e990 00000000`00000000 : nt!RtlpNewSecurityObject+0x8c1
fffff880`02390db0 fffff800`02f6af2e : 00000000`00000000 fffffa80`0778d5f0 00000000`00000000 00000000`00000000 : nt!ObpAssignSecurity+0x82
fffff880`02390e20 fffff800`02f446b0 : ffffffff`ffffffff fffffa80`07a41060 fffffa80`07a41060 00000000`00000000 : nt!ObInsertObjectEx+0x20e
fffff880`02391060 fffff800`02f48916 : fffffa80`0506b8e0 fffffa80`07a41060 fffff880`02391500 fffff880`02391240 : nt!PspInsertThread+0x3f0
fffff880`023911e0 fffff800`02f48c23 : 00000000`00000000 00000000`00000000 00000000`00000001 fffff880`02391a10 : nt!PspCreateThread+0x246
fffff880`02391460 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateThreadEx+0x243


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!RtlpCopyAces+5b
fffff800`02f417ab 48898424e0000000 mov qword ptr [rsp+0E0h],rax

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: nt!RtlpCopyAces+5b

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd34

FAILURE_BUCKET_ID: X64_0x50_nt!RtlpCopyAces+5b

BUCKET_ID: X64_0x50_nt!RtlpCopyAces+5b

Followup: MachineOwner
---------
 
Mein BIOS erlaubt es mir nicht die Spannung zu erhöhen bzw gibt es keine entsprechende Option.
 
Nein. Keine Probleme. Dann wirf es wohl das Mainboard sein oder?
 
Wenn es 1,5 Jahre einwandfrei lieg und jetzt auf einmal mit beiden RAM gleichzeitig nicht mehr, kann das viele Ursachen haben. Eine davon wäre (Stichwort Elektromigration) das Mainboard, eine andere der Memory Controller in der CPU, oder der RAM selbst. Schwer zu sagen, an welcher Komponente es liegt.

Da die Auswertung der Minidumps nur virtuelle Speicheradressen anzeigen, kann eine genaue Zuordnung nicht erfolgen. Du müsstest mit Ersatzhardware testen. Evtl. einen Bekannten, der z.B. mit anderem RAM aushelfen könnte?

Lade im Bios aber erst mal die "Setup Defaults" im Exit Menü (sofern noch nicht geschehen).
Welche Spannungen kannst du den überhaupt einstellen? Kannst du die RAM Frequenz oder Timings ändern?
 
Naja das Problem besteht schon länger. Wie lange weiß ich aber nicht genau. Ich muss mal nachschauen was ich einstellen kann.
Ergänzung ()

Ich finde auch das die Temperaturen ohne Belastung auch recht hoch sind. Und das Problem besteht echt schon lange :(
 

Anhänge

  • 1.jpg
    1.jpg
    72,6 KB · Aufrufe: 130
Lies die Temps mit der CPU mit Coretemp und die GPU mit GPU-Z aus. Bei GPU-Z auf den Reiter "Sensors" und unten einen Haken bei "continue refreshing this screen..." machen.

Beides unter Leerlauf und mit Last (Last für die CPU z.B. mit Prime95; für die GPU mit Furmark). Furmark liest die GPU Temp auch aus, was den Einsatz von GPU-Z unter Last eigentlich erübrigt.

Wenn das Problem schon länger besteht (evtl. seit Anfang an?) könnte auch ein Kompatibilitätsproblem (RAM - Mobo) vorliegen.
 
Hallo.
Ich hatte länger keine Zeit mich hier zu melden und bin auch nich nicht dazu gekommen die Temps unter Last nachzuschauen. Allerdings poste ich nochmal eine der vielen Minidumps, die ich gestern bekommen habe, da jetzt von einem Fatal Hardware Error die Rede ist. Das Eingenartige ist, dass der Rechner eine Weile problemlos läuft wenn ich die CPU runter nehme und wieder draufsetze. Er bleibt jetzt auch beim spielen hängen. In WoW aber zum Beispiel nur wenn ich mich z.B. aus einem Dungeon teleportieren falls dir das was sagt :) und das aber auch nur wenn derRechner schon eine Zeit läuft.

Hier die Minidump:


WHEA_UNCORRECTABLE_ERROR (124)
A fatal hardware error has occurred. Parameter 1 identifies the type of error
source that reported the error. Parameter 2 holds the address of the
WHEA_ERROR_RECORD structure that describes the error conditon.
Arguments:
Arg1: 0000000000000000, Machine Check Exception
Arg2: fffffa80049788f8, Address of the WHEA_ERROR_RECORD structure.
Arg3: 0000000000000000, High order 32-bits of the MCi_STATUS value.
Arg4: 0000000000000000, Low order 32-bits of the MCi_STATUS value.

Debugging Details:
------------------


BUGCHECK_STR: 0x124_AuthenticAMD

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 0

STACK_TEXT:
fffff880`02fb66f0 fffff800`02f1f979 : fffffa80`049788d0 fffffa80`03a03b60 fffff880`02fb6c38 00000000`00000018 : nt!WheapCreateLiveTriageDump+0x6c
fffff880`02fb6c10 fffff800`02e015c7 : fffffa80`049788d0 fffff800`02e7a5f8 fffffa80`03a03b60 00000002`00000005 : nt!WheapCreateTriageDumpFromPreviousSession+0x49
fffff880`02fb6c40 fffff800`02d69b55 : fffff800`02edc360 fffffa80`0491baa8 fffffa80`0491baa0 fffffa80`03a03b60 : nt!WheapProcessWorkQueueItem+0x57
fffff880`02fb6c80 fffff800`02ce2961 : fffff880`010b3e00 fffff800`02d69b30 fffffa80`03a03b60 00000000`00000000 : nt!WheapWorkQueueWorkerRoutine+0x25
fffff880`02fb6cb0 fffff800`02f78bc6 : 55415441`57084b89 fffffa80`03a03b60 00000000`00000080 fffffa80`03973890 : nt!ExpWorkerThread+0x111
fffff880`02fb6d40 fffff800`02cb3bc6 : fffff880`02d63180 fffffa80`03a03b60 fffff880`02d6dfc0 48088948`08408b49 : nt!PspSystemThreadStartup+0x5a
fffff880`02fb6d80 00000000`00000000 : fffff880`02fb7000 fffff880`02fb1000 fffff880`035d4590 00000000`00000000 : nt!KiStartSystemThread+0x16


STACK_COMMAND: kb

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: hardware

IMAGE_NAME: hardware

DEBUG_FLR_IMAGE_TIMESTAMP: 0

FAILURE_BUCKET_ID: X64_0x124_AuthenticAMD_PROCESSOR_CACHE_PRV

BUCKET_ID: X64_0x124_AuthenticAMD_PROCESSOR_CACHE_PRV

Followup: MachineOwner
---------
 
Wirf bitte noch einmal WinDbg an, stoß die Auswertung des 0x124 an und gib dann den Befehl !errrec ein Leerzeichen und die Adresse von Arg2 ein, also: !errrec fffffa80049788f8
Es sollte der Common Platform Error Record angezeigt werden.
 
Weiß nicht mehr welche Crashdump das war deswegen hier mit einer anderen:


Common Platform Error Record @ fffffa8004a1e028
-------------------------------------------------------------------------------
Record Id : 01cc43be8da8e0a1
Severity : Fatal (1)
Length : 928
Creator : Microsoft
Notify Type : Machine Check Exception
Timestamp : 7/16/2011 14:48:03
Flags : 0x00000000

===============================================================================
Section 0 : Processor Generic
-------------------------------------------------------------------------------
Descriptor @ fffffa8004a1e0a8
Section @ fffffa8004a1e180
Offset : 344
Length : 192
Flags : 0x00000001 Primary
Severity : Fatal

Proc. Type : x86/x64
Instr. Set : x64
Error Type : Cache error
Operation : Generic
Flags : 0x00
Level : 1
CPU Version : 0x0000000000100f42
Processor ID : 0x0000000000000003

===============================================================================
Section 1 : x86/x64 Processor Specific
-------------------------------------------------------------------------------
Descriptor @ fffffa8004a1e0f0
Section @ fffffa8004a1e240
Offset : 536
Length : 128
Flags : 0x00000000
Severity : Fatal

Local APIC Id : 0x0000000000000003
CPU Id : 42 0f 10 00 00 08 04 03 - 09 20 80 00 ff fb 8b 17
00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00

Proc. Info 0 @ fffffa8004a1e240

===============================================================================
Section 2 : x86/x64 MCA
-------------------------------------------------------------------------------
Descriptor @ fffffa8004a1e138
Section @ fffffa8004a1e2c0
Offset : 664
Length : 264
Flags : 0x00000000
Severity : Fatal

Error : DCACHEL1_EVICT_ERR (Proc 3 Bank 0)
Status : 0xb652400000000175
Address : 0x000000000399d660
Misc. : 0x0000000000000000


PS: Fakt ist: Wenn ich die CPU ein- und ausbaue geht er eine Zeit lang einwandfrei...
MfG
 
genetix1989 schrieb:
Fakt ist: Wenn ich die CPU ein- und ausbaue geht er eine Zeit lang einwandfrei...

Was für ein Kühler sitzt auf der CPU? Wie fest ist der angezogen?

Wie sieht es aus, wenn du den Rechner im liegen betreibst (evtl. leichte H-Risse im Board?) ...
 
Das es ein anderer Bugcheck war, sieht man an der Adresse des Error Record.

Der DCACHEL1_EVICT_ERR (Proc 3 Bank 0) zeigt an, das der L1 Cache des Prozessor 3 defekt ist.

Allerdings können auch fehlerhafter RAM, ein veraltetes BIOS oder korrupte Treiber als Ursachen in Betracht kommen; Werden diese durch Tests ausgeschloßen, und der Tipp von simpel1970 funktioniert nicht, bleibt nur die CPU als Verursacher übrig.
 
Zuletzt bearbeitet:
Also der Rechner wird momentan im Liegen betrieben und auch da fängt er irgendwann an rumzumacken. BIOS und Treiben können denke ich ausgeschlossen werden, da ich das BIOS vor kurzem erst geupdatet habe und ich das Windows des öfteren neu installiert habe und immer die neusten Treiber runtergeladen habe. Sollte ich mal eine andere CPU ausprobieren?

MfG
Ergänzung ()

Der PC fängt aber nicht an zu spinnen wenn ich am CPU Lüfter vorsichtig drücke oder ziehe. Kann ich damit die H-Risse ausschließen? Installiert ist der Boxed Lüfter.
 
Ich könnte eine vll eine AM3 CPU bekommen. Die müsste ja auf meinem AM2+ Board laufen. Pins sind alle in Ordnung.
 
Zurück
Oben