Widziałem sporo wątków o bluescreen, ale nie znalazłem podobnego do mojego (chyba, że źle szukałem).
Niemniej jednak, mój komputer resetuje się gdy gram, przeglądam internet, a nawet jeśli nic nie robię.
Poczytałem coś o plikach dmp, ale sam sobie z tym nie poradzę, więc proszę o pomoc.
Raport z WinDbg:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\081912-20155-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x8301e000 PsLoadedModuleList = 0x83166810
Debug session time: Sun Aug 19 21:12:24.094 2012 (GMT+2)
System Uptime: 0 days 0:06:22.951
Loading Kernel Symbols
...............................................................
................................................................
....................................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: b511e000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8320684a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
READ_ADDRESS: GetPointerFromAddress: unable to read from 83186718
Unable to read MiSystemVaType memory at 83166160
b511e000
FAULTING_IP:
nt!MiCompressRelocations+3d
8320684a 0fb731 movzx esi,word ptr [ecx]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: a5ac35b0 -- (.trap 0xffffffffa5ac35b0)
ErrCode = 00000000
eax=7ffffa5a ebx=00000000 ecx=b511e000 edx=00000000 esi=00000000 edi=b511d4b4
eip=8320684a esp=a5ac3624 ebp=a5ac3644 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiCompressRelocations+0x3d:
8320684a 0fb731 movzx esi,word ptr [ecx] ds:0023:b511e000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 830645f8 to 830a38e3
STACK_TEXT:
a5ac3598 830645f8 00000000 b511e000 00000000 nt!MmAccessFault+0x106
a5ac3598 8320684a 00000000 b511e000 00000000 nt!KiTrap0E+0xdc
a5ac3644 832266cd b5000000 00047e1c 00000008 nt!MiCompressRelocations+0x3d
a5ac36f4 832418a9 b4f48000 a5ac377c 00000003 nt!MiRelocateImage+0x430
a5ac3818 8324ee51 a5ac386c 0000000d a5ac38c0 nt!MmCreateSection+0x797
a5ac388c 83222c86 a5ac391c 0000000d a5ac38c0 nt!NtCreateSection+0x16e
a5ac3908 832226d4 a5ac39c8 b4606c30 00000001 nt!PfpFileBuildReadSupport+0xe4
a5ac399c 832240b4 00ac39c8 a5ac3b28 00000001 nt!PfpPrefetchFilesTrickle+0xdf
a5ac3a44 83223d71 b4600000 8af43df0 a5ac3b3c nt!PfpPrefetchRequestPerform+0x2a6
a5ac3a98 8323d97f a5ac3b28 83088701 8af43c34 nt!PfpPrefetchRequest+0x16e
a5ac3b5c 832a98f6 00b3f9f8 00000014 83088701 nt!PfSetSuperfetchInformation+0x182
a5ac3c94 9207a08f 0000004f 00000000 00000014 nt!NtSetSystemInformation+0xb00
WARNING: Stack unwind information not available. Following frames may be wrong.
a5ac3d20 8306142a 0000004f 00b3f9f8 00000014 SYMEVENT+0x1708f
a5ac3d20 00b3fb48 0000004f 00b3f9f8 00000014 nt!KiFastCallEntry+0x12a
ffffffff 00000000 00000000 00000000 00000000 0xb3fb48
STACK_COMMAND: kb
FOLLOWUP_IP:
SYMEVENT+1708f
9207a08f ?? ???
SYMBOL_STACK_INDEX: c
SYMBOL_NAME: SYMEVENT+1708f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SYMEVENT
IMAGE_NAME: SYMEVENT.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4ecbea42
FAILURE_BUCKET_ID: 0x50_SYMEVENT+1708f
BUCKET_ID: 0x50_SYMEVENT+1708f
Followup: MachineOwner
---------
1: kd> lmvm SYMEVENT
start end module name
92063000 9208d000 SYMEVENT T (no symbols)
Loaded symbol image file: SYMEVENT.SYS
Image path: \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
Image name: SYMEVENT.SYS
Timestamp: Tue Nov 22 19:30:26 2011 (4ECBEA42)
CheckSum: 00027540
ImageSize: 0002A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
BlueScreen SYMEVENT.SYS
- lewy
- Posty: 1462
- Rejestracja: 15 gru 2009, 11:10
BlueScreen SYMEVENT.SYS
A Masz jakieś oprogramowanie firmy Symantec bo to on tutaj spowodował wystąpienie bluescreena?
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
Mam Norton 360, ale używam go od kilku miesięcy.
Dlaczego teraz pojawił się problem?
Dlaczego teraz pojawił się problem?
- lewy
- Posty: 1462
- Rejestracja: 15 gru 2009, 11:10
BlueScreen SYMEVENT.SYS
Być może jakaś felerna aktualizacja albo coś się z nim pogryzło. Dla testu bym go na kilka dni odinstalował
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
OK, spróbuję, zobaczymy co będzie.
A jeśli okaże się, że to wina antywirusa, to czy potem możliwe będzie jego ponowne zainstalowanie?
A jeśli okaże się, że to wina antywirusa, to czy potem możliwe będzie jego ponowne zainstalowanie?
- seba86mu
- Posty: 9744
- Rejestracja: 13 lis 2008, 18:07
- Lokalizacja: Sosnowiec
BlueScreen SYMEVENT.SYS
Shacool pisze:A jeśli okaże się, że to wina antywirusa, to czy potem możliwe będzie jego ponowne zainstalowanie?
Tak, będziesz mógł zainstalować, jednak jeżeli on jest winowajcą problem może się powtarzać.
Możliwe również, że odinstalowanie antywirusa i jego ponowna instalacja rozwiąże problem.
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
Odinstalowanie nie pomogło. Próbowałem odnaleźć ten plik SYMEVENT.SYS i usunąć go ręcznie, ale okazuje się że go nie ma, a skoro go nie ma to jak może powodować problem? Macie jakieś propozycje?
- seba86mu
- Posty: 9744
- Rejestracja: 13 lis 2008, 18:07
- Lokalizacja: Sosnowiec
BlueScreen SYMEVENT.SYS
Nortona odinstaluj narzędziem Norton Removall Tool => ftp://ftp.symantec.com/public/english_u ... l_Tool.exe
Uruchom program => Dostępne tylko dla zarejestrowanych użytkowników => Analiza => Uruchom Cleaner
Dokonaj naprawy rejestru programem => Dostępne tylko dla zarejestrowanych użytkowników => Skanuj rejestr => Napraw rejestr
Uruchom program => Dostępne tylko dla zarejestrowanych użytkowników => Analiza => Uruchom Cleaner
Dokonaj naprawy rejestru programem => Dostępne tylko dla zarejestrowanych użytkowników => Skanuj rejestr => Napraw rejestr
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
Krok 1 i 2 przebiegły pomyślnie, ale przy 3 zanim zdążyłem kliknąć "Napraw rejestr" pojawił się BlueScreen. Po ponownym uruchomieniu komputera udało mi się włączyć skanowanie i naprawianie rejestru, no i chwilowo jest OK, zobaczymy co będzie za jakiś czas.
A oto raport przed naprawą rejestru, nieco inny od poprzedniego. Czy ten nowy raport oznacza nowy błąd?
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\082012-17659-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x8301e000 PsLoadedModuleList = 0x83166810
Debug session time: Mon Aug 20 10:52:02.823 2012 (GMT+2)
System Uptime: 0 days 0:06:20.665
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: aa91e000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8320684a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 83186718
Unable to read MiSystemVaType memory at 83166160
aa91e000
FAULTING_IP:
nt!MiCompressRelocations+3d
8320684a 0fb731 movzx esi,word ptr [ecx]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: a40bb640 -- (.trap 0xffffffffa40bb640)
ErrCode = 00000000
eax=7ffffa5a ebx=00000000 ecx=aa91e000 edx=00000000 esi=00000000 edi=aa91d4b4
eip=8320684a esp=a40bb6b4 ebp=a40bb6d4 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiCompressRelocations+0x3d:
8320684a 0fb731 movzx esi,word ptr [ecx] ds:0023:aa91e000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 830645f8 to 830a38e3
STACK_TEXT:
a40bb628 830645f8 00000000 aa91e000 00000000 nt!MmAccessFault+0x106
a40bb628 8320684a 00000000 aa91e000 00000000 nt!KiTrap0E+0xdc
a40bb6d4 832266cd aa800000 00047e1c 00000008 nt!MiCompressRelocations+0x3d
a40bb784 832418a9 aa4b2000 a40bb80c 00000003 nt!MiRelocateImage+0x430
a40bb8a8 8324ee51 a40bb8fc 0000000d a40bb950 nt!MmCreateSection+0x797
a40bb91c 83222c86 a40bb9ac 0000000d a40bb950 nt!NtCreateSection+0x16e
a40bb998 832226d4 a40bba58 aa222df0 00000001 nt!PfpFileBuildReadSupport+0xe4
a40bba2c 832240b4 000bba58 a40bbbb4 00000001 nt!PfpPrefetchFilesTrickle+0xdf
a40bbad0 83223d71 aa21d000 8b79c5b5 a40bbbc8 nt!PfpPrefetchRequestPerform+0x2a6
a40bbb24 8323d97f a40bbbb4 83433b01 8b79c579 nt!PfpPrefetchRequest+0x16e
a40bbbe8 832a98f6 0197f63c 00000014 83433b01 nt!PfSetSuperfetchInformation+0x182
a40bbd20 8306142a 0000004f 00000000 00000014 nt!NtSetSystemInformation+0xb00
a40bbd20 76fd64f4 0000004f 00000000 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0197f654 00000000 00000000 00000000 00000000 0x76fd64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCompressRelocations+3d
8320684a 0fb731 movzx esi,word ptr [ecx]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!MiCompressRelocations+3d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
Followup: MachineOwner
---------
1: kd> lmvm nt
start end module name
8301e000 8342e000 nt (pdb symbols) c:\symbols\ntkrpamp.pdb\5B308B4ED6464159B87117C711E7340C2\ntkrpamp.pdb
Loaded symbol image file: ntkrpamp.exe
Mapped memory image file: C:\symbols\ntkrpamp.exe\4A5BC007410000\ntkrpamp.exe
Image path: ntkrpamp.exe
Image name: ntkrpamp.exe
Timestamp: Tue Jul 14 01:15:19 2009 (4A5BC007)
CheckSum: 003C9503
ImageSize: 00410000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrpamp.exe
OriginalFilename: ntkrpamp.exe
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
A oto raport przed naprawą rejestru, nieco inny od poprzedniego. Czy ten nowy raport oznacza nowy błąd?
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\082012-17659-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x8301e000 PsLoadedModuleList = 0x83166810
Debug session time: Mon Aug 20 10:52:02.823 2012 (GMT+2)
System Uptime: 0 days 0:06:20.665
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: aa91e000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8320684a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 83186718
Unable to read MiSystemVaType memory at 83166160
aa91e000
FAULTING_IP:
nt!MiCompressRelocations+3d
8320684a 0fb731 movzx esi,word ptr [ecx]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: a40bb640 -- (.trap 0xffffffffa40bb640)
ErrCode = 00000000
eax=7ffffa5a ebx=00000000 ecx=aa91e000 edx=00000000 esi=00000000 edi=aa91d4b4
eip=8320684a esp=a40bb6b4 ebp=a40bb6d4 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiCompressRelocations+0x3d:
8320684a 0fb731 movzx esi,word ptr [ecx] ds:0023:aa91e000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 830645f8 to 830a38e3
STACK_TEXT:
a40bb628 830645f8 00000000 aa91e000 00000000 nt!MmAccessFault+0x106
a40bb628 8320684a 00000000 aa91e000 00000000 nt!KiTrap0E+0xdc
a40bb6d4 832266cd aa800000 00047e1c 00000008 nt!MiCompressRelocations+0x3d
a40bb784 832418a9 aa4b2000 a40bb80c 00000003 nt!MiRelocateImage+0x430
a40bb8a8 8324ee51 a40bb8fc 0000000d a40bb950 nt!MmCreateSection+0x797
a40bb91c 83222c86 a40bb9ac 0000000d a40bb950 nt!NtCreateSection+0x16e
a40bb998 832226d4 a40bba58 aa222df0 00000001 nt!PfpFileBuildReadSupport+0xe4
a40bba2c 832240b4 000bba58 a40bbbb4 00000001 nt!PfpPrefetchFilesTrickle+0xdf
a40bbad0 83223d71 aa21d000 8b79c5b5 a40bbbc8 nt!PfpPrefetchRequestPerform+0x2a6
a40bbb24 8323d97f a40bbbb4 83433b01 8b79c579 nt!PfpPrefetchRequest+0x16e
a40bbbe8 832a98f6 0197f63c 00000014 83433b01 nt!PfSetSuperfetchInformation+0x182
a40bbd20 8306142a 0000004f 00000000 00000014 nt!NtSetSystemInformation+0xb00
a40bbd20 76fd64f4 0000004f 00000000 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0197f654 00000000 00000000 00000000 00000000 0x76fd64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCompressRelocations+3d
8320684a 0fb731 movzx esi,word ptr [ecx]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!MiCompressRelocations+3d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
Followup: MachineOwner
---------
1: kd> lmvm nt
start end module name
8301e000 8342e000 nt (pdb symbols) c:\symbols\ntkrpamp.pdb\5B308B4ED6464159B87117C711E7340C2\ntkrpamp.pdb
Loaded symbol image file: ntkrpamp.exe
Mapped memory image file: C:\symbols\ntkrpamp.exe\4A5BC007410000\ntkrpamp.exe
Image path: ntkrpamp.exe
Image name: ntkrpamp.exe
Timestamp: Tue Jul 14 01:15:19 2009 (4A5BC007)
CheckSum: 003C9503
ImageSize: 00410000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrpamp.exe
OriginalFilename: ntkrpamp.exe
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
- seba86mu
- Posty: 9744
- Rejestracja: 13 lis 2008, 18:07
- Lokalizacja: Sosnowiec
BlueScreen SYMEVENT.SYS
Ostatni plik DMP nie wskazuje na nic konkretnego.
Od kiedy pojawiają się BSOD ?
Przypomnij sobie, może instalowałeś jakiś nowy program czy grę ?
Nie masz przypadkiem programu pcAnywhere ?
Od kiedy pojawiają się BSOD ?
Przypomnij sobie, może instalowałeś jakiś nowy program czy grę ?
Nie masz przypadkiem programu pcAnywhere ?
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
pcAnywhere nie mam, nawet nie wiem co to jest.
A co do błędów, to zaczęły się kilka dni temu. Możliwe że po tym jak mój młodszy brat przyniósł jakieś gry od znajomego. Ale jeśli byłaby to wina którejś gry, to dlaczego w raporcie wskazywało na Symantec?
A co do błędów, to zaczęły się kilka dni temu. Możliwe że po tym jak mój młodszy brat przyniósł jakieś gry od znajomego. Ale jeśli byłaby to wina którejś gry, to dlaczego w raporcie wskazywało na Symantec?
- seba86mu
- Posty: 9744
- Rejestracja: 13 lis 2008, 18:07
- Lokalizacja: Sosnowiec
BlueScreen SYMEVENT.SYS
Shacool pisze:Ale jeśli byłaby to wina którejś gry, to dlaczego w raporcie wskazywało na Symantec?
Może doszło do jakiegoś konfliktu Nortona z inną aplikacją i dlatego wskazało plik Nortona.
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
Odinstalowałem Nortona i wyczyściłem wszystko podanymi programami i na razie jest dobrze. Spróbuję później ponownie zainstalować Nortona i zobaczę czy problem wróci.
Póki co dziękuję za pomoc.
Póki co dziękuję za pomoc.
- cosik_ktosik
- Posty: 21416
- Rejestracja: 13 lis 2008, 01:17
- Lokalizacja: Szczecin
- Kontaktowanie:
-
- Posty: 8
- Rejestracja: 20 sie 2012, 00:43
BlueScreen SYMEVENT.SYS
Znowu to samo. Nie instalowałem jeszcze Nortona, a problem powrócił.
Wczoraj było OK, komputer działał przez kilka godzin bez żadnych awarii, a dziś powtórka z rozrywki.
Dzisiejszy raport wygląda tak:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Łukasz\Desktop\082112-17191-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x83002000 PsLoadedModuleList = 0x8314a810
Debug session time: Tue Aug 21 12:52:58.783 2012 (GMT+2)
System Uptime: 0 days 0:12:01.624
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.......
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ac1ae000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 831ea84a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 8316a718
Unable to read MiSystemVaType memory at 8314a160
ac1ae000
FAULTING_IP:
nt!MiCompressRelocations+3d
831ea84a 0fb731 movzx esi,word ptr [ecx]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
TRAP_FRAME: 8e227a30 -- (.trap 0xffffffff8e227a30)
ErrCode = 00000000
eax=7ffffa5a ebx=00000000 ecx=ac1ae000 edx=00000000 esi=00000000 edi=ac1ad4b4
eip=831ea84a esp=8e227aa4 ebp=8e227ac4 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiCompressRelocations+0x3d:
831ea84a 0fb731 movzx esi,word ptr [ecx] ds:0023:ac1ae000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 830485f8 to 830878e3
STACK_TEXT:
8e227a18 830485f8 00000000 ac1ae000 00000000 nt!MmAccessFault+0x106
8e227a18 831ea84a 00000000 ac1ae000 00000000 nt!KiTrap0E+0xdc
8e227ac4 8320a6cd ac090000 00047e1c 00000008 nt!MiCompressRelocations+0x3d
8e227b74 832258a9 ac000000 8e227bfc 00000003 nt!MiRelocateImage+0x430
8e227c9c 83232e51 8e227cf0 00000007 00000000 nt!MmCreateSection+0x797
8e227d10 8304542a 05bff148 00000007 00000000 nt!NtCreateSection+0x16e
8e227d10 774864f4 05bff148 00000007 00000000 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
05bff268 00000000 00000000 00000000 00000000 0x774864f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCompressRelocations+3d
831ea84a 0fb731 movzx esi,word ptr [ecx]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!MiCompressRelocations+3d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
Followup: MachineOwner
---------
0: kd> lmvm nt
start end module name
83002000 83412000 nt (pdb symbols) c:\symbols\ntkrpamp.pdb\5B308B4ED6464159B87117C711E7340C2\ntkrpamp.pdb
Loaded symbol image file: ntkrpamp.exe
Mapped memory image file: C:\symbols\ntkrpamp.exe\4A5BC007410000\ntkrpamp.exe
Image path: ntkrpamp.exe
Image name: ntkrpamp.exe
Timestamp: Tue Jul 14 01:15:19 2009 (4A5BC007)
CheckSum: 003C9503
ImageSize: 00410000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrpamp.exe
OriginalFilename: ntkrpamp.exe
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
Wczoraj było OK, komputer działał przez kilka godzin bez żadnych awarii, a dziś powtórka z rozrywki.
Dzisiejszy raport wygląda tak:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Łukasz\Desktop\082112-17191-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x83002000 PsLoadedModuleList = 0x8314a810
Debug session time: Tue Aug 21 12:52:58.783 2012 (GMT+2)
System Uptime: 0 days 0:12:01.624
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.......
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ac1ae000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 831ea84a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 8316a718
Unable to read MiSystemVaType memory at 8314a160
ac1ae000
FAULTING_IP:
nt!MiCompressRelocations+3d
831ea84a 0fb731 movzx esi,word ptr [ecx]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
TRAP_FRAME: 8e227a30 -- (.trap 0xffffffff8e227a30)
ErrCode = 00000000
eax=7ffffa5a ebx=00000000 ecx=ac1ae000 edx=00000000 esi=00000000 edi=ac1ad4b4
eip=831ea84a esp=8e227aa4 ebp=8e227ac4 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiCompressRelocations+0x3d:
831ea84a 0fb731 movzx esi,word ptr [ecx] ds:0023:ac1ae000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 830485f8 to 830878e3
STACK_TEXT:
8e227a18 830485f8 00000000 ac1ae000 00000000 nt!MmAccessFault+0x106
8e227a18 831ea84a 00000000 ac1ae000 00000000 nt!KiTrap0E+0xdc
8e227ac4 8320a6cd ac090000 00047e1c 00000008 nt!MiCompressRelocations+0x3d
8e227b74 832258a9 ac000000 8e227bfc 00000003 nt!MiRelocateImage+0x430
8e227c9c 83232e51 8e227cf0 00000007 00000000 nt!MmCreateSection+0x797
8e227d10 8304542a 05bff148 00000007 00000000 nt!NtCreateSection+0x16e
8e227d10 774864f4 05bff148 00000007 00000000 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
05bff268 00000000 00000000 00000000 00000000 0x774864f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCompressRelocations+3d
831ea84a 0fb731 movzx esi,word ptr [ecx]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!MiCompressRelocations+3d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
BUCKET_ID: 0x50_nt!MiCompressRelocations+3d
Followup: MachineOwner
---------
0: kd> lmvm nt
start end module name
83002000 83412000 nt (pdb symbols) c:\symbols\ntkrpamp.pdb\5B308B4ED6464159B87117C711E7340C2\ntkrpamp.pdb
Loaded symbol image file: ntkrpamp.exe
Mapped memory image file: C:\symbols\ntkrpamp.exe\4A5BC007410000\ntkrpamp.exe
Image path: ntkrpamp.exe
Image name: ntkrpamp.exe
Timestamp: Tue Jul 14 01:15:19 2009 (4A5BC007)
CheckSum: 003C9503
ImageSize: 00410000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrpamp.exe
OriginalFilename: ntkrpamp.exe
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
-
- Reklama
Kto jest online
Użytkownicy przeglądający to forum: Google [Bot], Google Adsense [Bot] i 224 gości