Hallo,
kann mir jemand zu der Auswertung was genaueres sagen?
Microsoft (R) Windows Debugger Version 6.3.9600.16384 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532
Machine Name:
Kernel base = 0xfffff800`0305a000 PsLoadedModuleList = 0xfffff800`0329d6d0
Debug session time: Sun Oct 27 11:22:18.871 2013 (UTC + 1:00)
System Uptime: 0 days 0:04:08.120
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffd5018). Type ".hh dbgerr001" for details
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8004313fa0, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35084 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8004313fa0
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: taskmgr.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
LAST_CONTROL_TRANSFER: from fffff80003140d50 to fffff800030cfbc0
STACK_TEXT:
fffff880`0381c6e8 fffff800`03140d50 : 00000000`0000001a 00000000`00041790 fffffa80`04313fa0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`0381c6f0 fffff800`031027d9 : 00000000`00000000 00000001`4073efff fffffa80`00000000 fffff880`00961000 : nt! ?? ::FNODOBFM::`string'+0x35084
fffff880`0381c8b0 fffff800`033e8631 : fffffa80`08fcfb50 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0381c9d0 fffff800`033e8a33 : 0000007f`00000000 00000001`40000000 fffffa80`00000001 fffffa80`091ba990 : nt!MiUnmapViewOfSection+0x1b1
fffff880`0381ca90 fffff800`030cee53 : 00000000`00000008 000007fe`fd8aa240 fffffa80`09653060 00000000`00000000 : nt!NtUnmapViewOfSection+0x5f
fffff880`0381cae0 00000000`779e155a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`04d1ec18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x779e155a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+35084
fffff800`03140d50 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+35084
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
IMAGE_VERSION: 6.1.7601.18247
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35084
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35084
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x1a_41790_nt!_??_::fnodobfm::_string_+35084
FAILURE_ID_HASH: {f6a6ed79-e275-9f8c-d5a4-3a37a32b0b4e}
Followup: MachineOwner
---------
1: kd> lmvm nt
start end module name
fffff800`0305a000 fffff800`0363f000 nt (pdb symbols) c:\symbols\ntkrnlmp.pdb\F69D000687EC491E87FC0425D4D378AC2\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Thu Aug 29 03:13:25 2013 (521EA035)
CheckSum: 0054CBB3
ImageSize: 005E5000
File version: 6.1.7601.18247
Product version: 6.1.7601.18247
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.1.7601.18247
FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
Edit vom 27.10.2013, 12:27 Uhr
Ich habe jetzt "spaßeshalber" mal die USB-Version von Memtest+ gezogen und ausgeführt. Ich musste keine 5-6 Stunden warten, weil es quasi direkt nach dem Start mit den roten Fehlermeldungen losging. Demnach kann man wohl davon ausgehen, dass einer oder beide RAM-Riegel defekt sind? Würde ja auch mit der Meldung "Memory-Management" im Bluescreen passen.
Ich habe aber beide Riegel drin gehabt, am besten nochmal einzeln testen oder? Der Rechner ist jetzt knappe 1,5 Jahre alt, vorher nie Probleme gehabt und jetzt innerhalb von 3 Tagen kam es dann ganz unwillkürlich und plötzlich. Kündigt sich auch nie wirklich an.
CPU: Intel Core i5-2400 @ 3.1GHz
MB: Asus P8H67-V Rev. 3.0
GPU: Gigabyte Geforce GTX 560 Ti 448 Cores
RAM: 8GB (2x 4GB) XMS3 DDR3-1333 CL9 von Corsair
AV: be quiet! 550W 80plus
OS: Win7 Home 64 Bit