Windows 7 Bluecreens

benningmk

Cadet 3rd Year
Registriert
Aug. 2010
Beiträge
57
Hallo Leute...

ich habe auf meinem Rechner Windows 7 Ultimate X64 installiert. Es lief auch bisher super stabil, aber seit ein paar Tagen habe ich vermehrt BlueScreens, häufig beim kopieren von Daten.

Folgende Informationen zeigt Windows mir an:

Problemsignatur:
Problemereignisname: BlueScreen
Betriebsystemversion: 6.1.7600.2.0.0.256.1
Gebietsschema-ID: 1031

Zusatzinformationen zum Problem:
BCCode: 1e
BCP1: FFFFFFFFC0000046
BCP2: FFFFF80002EB4034
BCP3: 000000000002625A
BCP4: 0000000000000000
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1

Bitte um Hilfe !!!
 
Hey, hast Du was an deiner Hardware verändert?
Starte mal Windows mit gedrückter F8-Taste. Dann dort mal
nen Speichertest durchlaufen lassen.
 
Hey...
an meiner Hardware habe ich nichts geändert. Habe es gerade ausprobiert, Neustart mit F8.
Es gibt mehrere Punkte zum Anwählen aber Speichertest finde ich nicht.
MfG
Ergänzung ()

Habe soeben mit dem Debugging Tool für X64 mal eine Auswertung von meinem letzten Dump gemacht, evtl. sagt euch das ja mehr.


Use !analyze -v to get detailed debugging information.

BugCheck 1E, {ffffffffc0000046, fffff80002eb4034, 2625a, 0}

Probably caused by : ntkrnlmp.exe ( nt!RtlRaiseStatus+18 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000046, The exception code that was not handled
Arg2: fffff80002eb4034, The address that the exception occurred at
Arg3: 000000000002625a, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000046 - Ein Thread versuchte, ein Mutantobjekt freizugeben, ohne Besitzer des Objekts zu sein.

FAULTING_IP:
nt!RtlRaiseStatus+18
fffff800`02eb4034 488b8424b8010000 mov rax,qword ptr [rsp+1B8h]

EXCEPTION_PARAMETER1: 000000000002625a

EXCEPTION_PARAMETER2: 0000000000000000

ERROR_CODE: (NTSTATUS) 0xc0000046 - Ein Thread versuchte, ein Mutantobjekt freizugeben, ohne Besitzer des Objekts zu sein.

BUGCHECK_STR: 0x1E_c0000046

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 2

EXCEPTION_RECORD: fffff8800331adf0 -- (.exr 0xfffff8800331adf0)
ExceptionAddress: fffff80002eb4034 (nt!RtlRaiseStatus+0x0000000000000018)
ExceptionCode: c0000046
ExceptionFlags: 00000001
NumberParameters: 0

TRAP_FRAME: fffff8800331ac30 -- (.trap 0xfffff8800331ac30)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=fffff8800331ae90
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002eb4034 rsp=fffff8800331add0 rbp=0000000000000002
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff880009e8180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!RtlRaiseStatus+0x18:
fffff800`02eb4034 488b8424b8010000 mov rax,qword ptr [rsp+1B8h] ss:0018:fffff880`0331af88=fffff80002eb4034
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002ebfa39 to fffff80002e85740

STACK_TEXT:
fffff880`0331a328 fffff800`02ebfa39 : 00000000`0000001e ffffffff`c0000046 fffff800`02eb4034 00000000`0002625a : nt!KeBugCheckEx
fffff880`0331a330 fffff800`02f89459 : fffff880`0331adf0 fffff880`0331adf0 fffff880`0331ac30 fffff880`0331ae90 : nt!KiDispatchException+0x1b9
fffff880`0331a9c0 fffff800`02e873fb : fffff880`0331adf0 fffff880`009f2fc0 00000000`00000001 fffff880`03f8577a : nt!KiRaiseException+0x1b9
fffff880`0331aaf0 fffff800`02e84993 : 00000000`00000000 fffff880`031da199 fffffa80`03fb2030 fffffa80`04fe41a0 : nt!NtRaiseException+0x7b
fffff880`0331ac30 fffff800`02eb4034 : fffff880`0331adf0 fffff880`0331ae90 00000000`00000001 00000000`00000007 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0331add0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlRaiseStatus+0x18


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!RtlRaiseStatus+18
fffff800`02eb4034 488b8424b8010000 mov rax,qword ptr [rsp+1B8h]

SYMBOL_STACK_INDEX: 5

SYMBOL_NAME: nt!RtlRaiseStatus+18

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9

FAILURE_BUCKET_ID: X64_0x1E_c0000046_nt!RtlRaiseStatus+18

BUCKET_ID: X64_0x1E_c0000046_nt!RtlRaiseStatus+18

Followup: MachineOwner
---------
Ergänzung ()

Und das eine Auswertung von einem Dump von gestern:

Use !analyze -v to get detailed debugging information.

BugCheck 100000B8, {fffffa80039f91a0, fffff8800336dfc0, 0, 0}

Unable to load image \SystemRoot\system32\DRIVERS\snapman.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for snapman.sys
*** ERROR: Module load completed but symbols could not be loaded for snapman.sys
Probably caused by : snapman.sys ( snapman+18e71 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

ATTEMPTED_SWITCH_FROM_DPC (b8)
A wait operation, attach process, or yield was attempted from a DPC routine.
This is an illegal operation and the stack track will lead to the offending
code and original DPC routine.
Arguments:
Arg1: fffffa80039f91a0, Original thread which is the cause of the failure
Arg2: fffff8800336dfc0, New thread
Arg3: 0000000000000000, Stack address of the original thread
Arg4: 0000000000000000

Debugging Details:
------------------


FAULTING_THREAD: fffffa80039f91a0

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xB8

PROCESS_NAME: System

CURRENT_IRQL: 2

LAST_CONTROL_TRANSFER: from fffff80002ecb992 to fffff80002eca5da

STACK_TEXT:
fffff880`033923d0 fffff800`02ecb992 : fffff880`03392580 fffffa80`039f91a0 00000000`00000000 00000000`00000020 : nt!KiSwapContext+0x7a
fffff880`03392510 fffff800`02ecdcff : fffffa80`06d62402 00000000`00000000 0000000f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x1d2
fffff880`033925a0 fffff880`01db2e71 : fffff880`01dc5100 fffff880`00000000 00000000`00000000 fffff880`04c11500 : nt!KeWaitForSingleObject+0x19f
fffff880`03392640 fffff880`01dc5100 : fffff880`00000000 00000000`00000000 fffff880`04c11500 fffff880`03363180 : snapman+0x18e71
fffff880`03392648 fffff880`00000000 : 00000000`00000000 fffff880`04c11500 fffff880`03363180 fffff880`01dc5140 : snapman+0x2b100
fffff880`03392650 00000000`00000000 : fffff880`04c11500 fffff880`03363180 fffff880`01dc5140 fffffa80`04b022c0 : 0xfffff880`00000000


STACK_COMMAND: .thread 0xfffffa80039f91a0 ; kb

FOLLOWUP_IP:
snapman+18e71
fffff880`01db2e71 ?? ???

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: snapman+18e71

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: snapman

IMAGE_NAME: snapman.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 45265d99

FAILURE_BUCKET_ID: X64_0xB8_snapman+18e71

BUCKET_ID: X64_0xB8_snapman+18e71

Followup: MachineOwner
Ergänzung ()

Zu guter letzt noch eine Auswertung von meinem ersten Dump:

Use !analyze -v to get detailed debugging information.

BugCheck 100000B8, {fffffa8005391060, fffff80002e06c40, 0, 0}

Unable to load image \SystemRoot\system32\DRIVERS\snapman.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for snapman.sys
*** ERROR: Module load completed but symbols could not be loaded for snapman.sys
Probably caused by : snapman.sys ( snapman+18e71 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

ATTEMPTED_SWITCH_FROM_DPC (b8)
A wait operation, attach process, or yield was attempted from a DPC routine.
This is an illegal operation and the stack track will lead to the offending
code and original DPC routine.
Arguments:
Arg1: fffffa8005391060, Original thread which is the cause of the failure
Arg2: fffff80002e06c40, New thread
Arg3: 0000000000000000, Stack address of the original thread
Arg4: 0000000000000000

Debugging Details:
------------------


FAULTING_THREAD: fffffa8005391060

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xB8

PROCESS_NAME: firefox.exe

CURRENT_IRQL: 2

LAST_CONTROL_TRANSFER: from fffff80002c85992 to fffff80002c845da

STACK_TEXT:
fffff800`043c33d0 fffff800`02c85992 : 00000000`00002000 fffffa80`05391060 00000000`00000000 fffff880`053ddf14 : nt!KiSwapContext+0x7a
fffff800`043c3510 fffff800`02c87cff : 00000000`00000000 00000000`00011001 0000000f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x1d2
fffff800`043c35a0 fffff880`01c18e71 : fffff880`01c2b100 fffff880`00000000 00000000`00000000 fffff880`01876e00 : nt!KeWaitForSingleObject+0x19f
fffff800`043c3640 fffff880`01c2b100 : fffff880`00000000 00000000`00000000 fffff880`01876e00 fffff800`02df8e80 : snapman+0x18e71
fffff800`043c3648 fffff880`00000000 : 00000000`00000000 fffff880`01876e00 fffff800`02df8e80 fffff880`01c2b140 : snapman+0x2b100
fffff800`043c3650 00000000`00000000 : fffff880`01876e00 fffff800`02df8e80 fffff880`01c2b140 fffffa80`04b0d528 : 0xfffff880`00000000


STACK_COMMAND: .thread 0xfffffa8005391060 ; kb

FOLLOWUP_IP:
snapman+18e71
fffff880`01c18e71 ?? ???

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: snapman+18e71

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: snapman

IMAGE_NAME: snapman.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 45265d99

FAILURE_BUCKET_ID: X64_0xB8_snapman+18e71

BUCKET_ID: X64_0xB8_snapman+18e71

Followup: MachineOwner
 
Hm, also wenn Du schreibst, dass es beim kopieren von dateien auftritt, dann könnten es die hdds sein, muss aber nicht.

ich würde mit nem freeware tool mal die hdds auf fehler überprüfen. dann wie ich oben schon schrieb mit F8 den PC starten und meiner Meinung nach auf Computerreparaturoptionen gehen, dort kann man es glaube ich auswählen.

oder du guckst hier mal:

http://www.windowspower.de/Windows-...ene-Speichertestprogramm-überprüfen_1430.html
 
Die letzten beiden Bluescreens wurden durch die Datei snapman.sys verursacht. Diese Datei gehört zu einem Acronis oder Apricorn Produkt (z.B. Acronis True Image oder Seagate DiscWizard).
Hast du ein solches Produkt installiert? Wenn ja welches? Bleiben die Fehler aus, wenn du die Software deinstallierst?

Bei der ersten Auswertung ist es nicht so eindeutig, kann allerdings auch durch die Software bedingt sein.
 
Zurück
Oben