Windows 7 stürzt regelmaßig ab: Suche der Fehlerursache


Okt. 2013

der Windows 7-PC eines Freundes stürzt ziemlich oft ab, deshalb versuche ich zu klären, woran das liegt.

In der Ereignisanzeige habe ich nach kritischen Ereignissen gesucht und dort wurde mir mehrmals das folgende angezeigt:

   <Event xmlns="[B]">[/B]
  [B]   <System>
     <Provider Name="[B]Microsoft-Windows-Kernel-Power[/B]" Guid="[B]{331C3B3A-2005-44C2-AC5E-77220C37D6B4}[/B]" /> 







    <TimeCreated SystemTime="[B]2015-11-28T14:02:12.268431200Z[/B]" /> 


    <Correlation />  

    <Execution ProcessID="[B]4[/B]" ThreadID="[B]8[/B]" />  



    <Security UserID="[B]S-1-5-18[/B]" /> 


     <Data Name="[B]BugcheckCode[/B]">159</Data> 

    <Data Name="[B]BugcheckParameter1[/B]">0x3</Data> 

    <Data Name="[B]BugcheckParameter2[/B]">0xfffffa8004700a10</Data>  

    <Data Name="[B]BugcheckParameter3[/B]">0xfffff80000b9a3d8</Data>  

    <Data Name="[B]BugcheckParameter4[/B]">0xfffffa800460f750</Data>  

    <Data Name="[B]SleepInProgress[/B]">true</Data> 

    <Data Name="[B]PowerButtonTimestamp[/B]">0</Data> 




Wisst Ihr, worum es sich handeln könnte?
Zuletzt bearbeitet:
Da steht nicht wirklich was drinnen, was eine konkrete Ursache für einen Abbruch bedeuten könnte; Du solltest mal das Ereignisprotokoll nach einem solchen Absturz mit Angabe der Urzeiten und der Ereignisse ausdrucken.

Im Übrigen wird das erfahrungsgemäss auch nicht weiterführen; vielmehr solltest erst mal versuchen, Du das System einmal reparieren oder neu aufsetzen.

Noch besser wäre es, gleich auf WIN10 upzugraden, das läuft jetzt seit Threshold (November Update) wie erste Sahne; hat bei mir auch funktioniert, nachdem mein 7 an allen Ecken und Enden gekrächzt hat und vielen nicht mehr ausführte, wie Systemwiederherstellung, komplette Datensicherung und vieles mehr.
Zuletzt bearbeitet:
Stürzt der PC zufälligerweise immer dann ab, wenn er in Standby geht?
Wie stürzt der PC denn ab. Mit einem Bluescreen?
Diesen schon mal ausgewertet z.B. mit dem Tool "Bluescreenview"?
Ich kann leider keine genauen Informationen zu den Abstürzen angeben, da ich nur den funktionierenden PC untersuchen konnte. Er hat mir erzählt, dass der PC oft abstürzt, ich war allerdings noch nicht dabei, als das passiert ist. Ob es einen Bluescreen gab oder ob er zuvor in den Standby-Modus wechseln wollte, kann ich leider nicht sagen.

Ich habe ihn allerdings gebeten, ab jetzt alle Informationen festzuhalten.
Endlich sind nähere Informationen verfügbar:

Problemereignisname: BlueScreen
Betriebsystemversion: 6.1.7601.
Gebietsschema-ID: 1031

Zusatzinformationen zum Problem:
BCCode: 9f
BCP1: 0000000000000003
BCP2: FFFFFA8004707060
BCP3: FFFFF80000B9A3D8
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1

Dateien, die bei der Beschreibung des Problems hilfreich sind:

Lesen Sie unsere Datenschutzbestimmungen online:

Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline:
Das ist genau das, was du schon in deinem 1. Post geschrieben hast, nur anders dargestellt.

shortrange schrieb:
Dateien, die bei der Beschreibung des Problems hilfreich sind:
Ich glaube diese Datei könnte bei der Suche nach dem Problem hilfreich sein.
Habe die Datei jetzt mit Bluescreenview untersucht in das Ereignis als HTML-Report extrahiert:

Created by using BlueScreenView

Dump FileCrash TimeBug Check StringBug Check CodeParameter 1Parameter 2Parameter 3Parameter 4Caused By DriverCaused By AddressFile DescriptionProduct NameCompanyFile VersionProcessorCrash AddressStack Address 1Stack Address 2Stack Address 3Full PathProcessors CountMajor VersionMinor VersionDump File SizeDump File Time

[TD="bgcolor: #FFFFFF"]120715-32307-01.dmp[/TD]
[TD="bgcolor: #FFFFFF"]07.12.2015 17:54:40[/TD]
[TD="bgcolor: #FFFFFF"]0x0000009f[/TD]
[TD="bgcolor: #FFFFFF"]00000000`00000003[/TD]
[TD="bgcolor: #FFFFFF"]fffffa80`04707060[/TD]
[TD="bgcolor: #FFFFFF"]fffff800`00b9a3d8[/TD]
[TD="bgcolor: #FFFFFF"]fffffa80`043fee50[/TD]
[TD="bgcolor: #FFFFFF"]ntoskrnl.exe[/TD]
[TD="bgcolor: #FFFFFF"]ntoskrnl.exe+73c40[/TD]
[TD="bgcolor: #FFFFFF"]NT Kernel & System[/TD]
[TD="bgcolor: #FFFFFF"]Microsoft® Windows® Operating System[/TD]
[TD="bgcolor: #FFFFFF"]Microsoft Corporation[/TD]
[TD="bgcolor: #FFFFFF"]6.1.7601.19045 (win7sp1_gdr.151019-1254)[/TD]
[TD="bgcolor: #FFFFFF"]x64[/TD]
[TD="bgcolor: #FFFFFF"]ntoskrnl.exe+73c40[/TD]
[TD="bgcolor: #FFFFFF"][/TD]
[TD="bgcolor: #FFFFFF"][/TD]
[TD="bgcolor: #FFFFFF"][/TD]
[TD="bgcolor: #FFFFFF"]C:\Windows\Minidump\120715-32307-01.dmp[/TD]
[TD="bgcolor: #FFFFFF"]4[/TD]
[TD="bgcolor: #FFFFFF"]15[/TD]
[TD="bgcolor: #FFFFFF"]7601[/TD]
[TD="bgcolor: #FFFFFF"]1.113.032[/TD]
[TD="bgcolor: #FFFFFF"]07.12.2015 18:37:58[/TD]

Ich hoffe, das hilft.
Nein, es ist extrem unwahrscheinlich, dass der Kernel selbst schuld ist.
Die Datei muss mit WinDbg analysiert werden, dort wird auch der Stacktrace angezeigt.
WinDbg mit !analyze -v sieht wie folgt aus:

Microsoft (R) Windows Debugger  Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\NameDesPCs\Desktop\120715-32307-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
**** AddRegion: Empty region being added.
**** AddRegion: Empty region being added.
**** AddRegion: Empty region being added.
**** AddRegion: Empty region being added.
**** AddRegion: Empty region being added.
**** AddRegion: Empty region being added.
Symbol search path is: *** Invalid ***
* Symbol loading may be unreliable without a symbol search path.           *
* Use .symfix to have the debugger choose a symbol path.                   *
* After setting your symbol path, use .reload to refresh symbol locations. *
Executable search path is: 
* Symbols can not be loaded because symbol path is not initialized. *
*                                                                   *
* The Symbol Path can be set by:                                    *
*   using the _NT_SYMBOL_PATH environment variable.                 *
*   using the -y <symbol_path> argument when starting the debugger. *
*   using .sympath and .sympath+                                    *
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows Longhorn Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.19045.amd64fre.win7sp1_gdr.151019-1254
Kernel base = 0xfffff800`03849000 PsLoadedModuleList = 0xfffff800`03a90730
Debug session time: Mon Dec  7 17:54:40.861 2015 (GMT+1)
System Uptime: 0 days 1:47:04.116
* Symbols can not be loaded because symbol path is not initialized. *
*                                                                   *
* The Symbol Path can be set by:                                    *
*   using the _NT_SYMBOL_PATH environment variable.                 *
*   using the -y <symbol_path> argument when starting the debugger. *
*   using .sympath and .sympath+                                    *
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
Loading unloaded module list
Loading User Symbols
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
Use !analyze -v to get detailed debugging information.
BugCheck 9F, {3, fffffa8004707060, fffff80000b9a3d8, fffffa80043fee50}
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_DRIVER_OBJECT                             ***
***                                                                   ***
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
*** WARNING: Unable to verify timestamp for hal.dll
*** ERROR: Module load completed but symbols could not be loaded for hal.dll
Unable to load image \SystemRoot\system32\mcupdate_GenuineIntel.dll, Win32 error 2
*** WARNING: Unable to verify timestamp for mcupdate_GenuineIntel.dll
*** ERROR: Module load completed but symbols could not be loaded for mcupdate_GenuineIntel.dll
Unable to load image \SystemRoot\system32\DRIVERS\tunnel.sys, Win32 error 2
*** WARNING: Unable to verify timestamp for tunnel.sys
*** ERROR: Module load completed but symbols could not be loaded for tunnel.sys
Probably caused by : tunnel.sys ( tunnel+1acf8 )
Followup: MachineOwner
0: kd> !analyze -v
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
A driver is causing an inconsistent power state.
Arg1: 0000000000000003, SubCode
Arg2: fffffa8004707060
Arg3: fffff80000b9a3d8
Arg4: fffffa80043fee50
Debugging Details:
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_DRIVER_OBJECT                             ***
***                                                                   ***
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
***                                                                   ***
***                                                                   ***
***    Your debugger is not using the correct symbols                 ***
***                                                                   ***
***    In order for this command to work properly, your symbol path   ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: nt!_KPRCB                                     ***
***                                                                   ***
MODULE_NAME:  tunnel
FAULTING_MODULE: fffff80003849000 nt
DRIVER_OBJECT:  fffffa80043fee50
DEVICE_OBJECT:  fffff80000b9a3d8
LAST_CONTROL_TRANSFER:  from fffff8000392c930 to fffff800038bcc40
fffff800`00b9a388 fffff800`0392c930 : 00000000`0000009f 00000000`00000003 fffffa80`04707060 fffff800`00b9a3d8 : nt+0x73c40
fffff800`00b9a390 00000000`0000009f : 00000000`00000003 fffffa80`04707060 fffff800`00b9a3d8 fffffa80`043fee50 : nt+0xe3930
fffff800`00b9a398 00000000`00000003 : fffffa80`04707060 fffff800`00b9a3d8 fffffa80`043fee50 00000000`c00000bb : 0x9f
fffff800`00b9a3a0 fffffa80`04707060 : fffff800`00b9a3d8 fffffa80`043fee50 00000000`c00000bb 00000000`00000000 : 0x3
fffff800`00b9a3a8 fffff800`00b9a3d8 : fffffa80`043fee50 00000000`c00000bb 00000000`00000000 fffff800`03a72be0 : 0xfffffa80`04707060
fffff800`00b9a3b0 fffffa80`043fee50 : 00000000`c00000bb 00000000`00000000 fffff800`03a72be0 00000000`00000002 : 0xfffff800`00b9a3d8
fffff800`00b9a3b8 00000000`c00000bb : 00000000`00000000 fffff800`03a72be0 00000000`00000002 00000000`00018000 : 0xfffffa80`043fee50
fffff800`00b9a3c0 00000000`00000000 : fffff800`03a72be0 00000000`00000002 00000000`00018000 fffff800`03a72bd0 : 0xc00000bb
fffff800`00b9a3c8 fffff800`03a72be0 : 00000000`00000002 00000000`00018000 fffff800`03a72bd0 fffff800`03a72520 : 0x0
fffff800`00b9a3d0 00000000`00000002 : 00000000`00018000 fffff800`03a72bd0 fffff800`03a72520 fffff800`03a672d8 : nt+0x229be0
fffff800`00b9a3d8 00000000`00018000 : fffff800`03a72bd0 fffff800`03a72520 fffff800`03a672d8 00000000`000644d6 : 0x2
fffff800`00b9a3e0 fffff800`03a72bd0 : fffff800`03a72520 fffff800`03a672d8 00000000`000644d6 fffff800`03a3ce80 : 0x18000
fffff800`00b9a3e8 fffff800`03a72520 : fffff800`03a672d8 00000000`000644d6 fffff800`03a3ce80 fffff800`03a4acc0 : nt+0x229bd0
fffff800`00b9a3f0 fffff800`03a672d8 : 00000000`000644d6 fffff800`03a3ce80 fffff800`03a4acc0 fffff800`00b9ab18 : nt+0x229520
fffff800`00b9a3f8 00000000`000644d6 : fffff800`03a3ce80 fffff800`03a4acc0 fffff800`00b9ab18 00000000`00000004 : nt+0x21e2d8
fffff800`00b9a400 fffff800`03a3ce80 : fffff800`03a4acc0 fffff800`00b9ab18 00000000`00000004 fffffa80`081dde00 : 0x644d6
fffff800`00b9a408 fffff800`03a4acc0 : fffff800`00b9ab18 00000000`00000004 fffffa80`081dde00 fffff800`038c816c : nt+0x1f3e80
fffff800`00b9a410 fffff800`00b9ab18 : 00000000`00000004 fffffa80`081dde00 fffff800`038c816c fffff800`00b9a4c0 : nt+0x201cc0
fffff800`00b9a418 00000000`00000004 : fffffa80`081dde00 fffff800`038c816c fffff800`00b9a4c0 fffff800`00b9a4c0 : 0xfffff800`00b9ab18
fffff800`00b9a420 fffffa80`081dde00 : fffff800`038c816c fffff800`00b9a4c0 fffff800`00b9a4c0 00000000`00000000 : 0x4
fffff800`00b9a428 fffff800`038c816c : fffff800`00b9a4c0 fffff800`00b9a4c0 00000000`00000000 00000000`00000001 : 0xfffffa80`081dde00
fffff800`00b9a430 fffff800`00b9a4c0 : fffff800`00b9a4c0 00000000`00000000 00000000`00000001 00000000`00000000 : nt+0x7f16c
fffff800`00b9a438 fffff800`00b9a4c0 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`0000000f : 0xfffff800`00b9a4c0
fffff800`00b9a440 00000000`00000000 : 00000000`00000001 00000000`00000000 00000000`0000000f 00000000`00000000 : 0xfffff800`00b9a4c0
fffff800`00b9a448 00000000`00000001 : 00000000`00000000 00000000`0000000f 00000000`00000000 ffffef5c`3df383c4 : 0x0
fffff800`00b9a450 00000000`00000000 : 00000000`0000000f 00000000`00000000 ffffef5c`3df383c4 fffff800`03a3ce80 : 0x1
fffff800`00b9a458 00000000`0000000f : 00000000`00000000 ffffef5c`3df383c4 fffff800`03a3ce80 00000000`00000001 : 0x0
fffff800`00b9a460 00000000`00000000 : ffffef5c`3df383c4 fffff800`03a3ce80 00000000`00000001 fffffa80`082ceb50 : 0xf
fffff800`00b9a468 ffffef5c`3df383c4 : fffff800`03a3ce80 00000000`00000001 fffffa80`082ceb50 00000000`00000004 : 0x0
fffff800`00b9a470 fffff800`03a3ce80 : 00000000`00000001 fffffa80`082ceb50 00000000`00000004 fffffa80`081dde60 : 0xffffef5c`3df383c4
fffff800`00b9a478 00000000`00000001 : fffffa80`082ceb50 00000000`00000004 fffffa80`081dde60 fffff800`038c8006 : nt+0x1f3e80
fffff800`00b9a480 fffffa80`082ceb50 : 00000000`00000004 fffffa80`081dde60 fffff800`038c8006 fffffa80`082cec58 : 0x1
fffff800`00b9a488 00000000`00000004 : fffffa80`081dde60 fffff800`038c8006 fffffa80`082cec58 fffffa80`082cec58 : 0xfffffa80`082ceb50
fffff800`00b9a490 fffffa80`081dde60 : fffff800`038c8006 fffffa80`082cec58 fffffa80`082cec58 00000000`00000000 : 0x4
fffff800`00b9a498 fffff800`038c8006 : fffffa80`082cec58 fffffa80`082cec58 00000000`00000000 00000000`00000000 : 0xfffffa80`081dde60
fffff800`00b9a4a0 fffffa80`082cec58 : fffffa80`082cec58 00000000`00000000 00000000`00000000 fffff800`03a72fa0 : nt+0x7f006
fffff800`00b9a4a8 fffffa80`082cec58 : 00000000`00000000 00000000`00000000 fffff800`03a72fa0 fffff800`03874a30 : 0xfffffa80`082cec58
fffff800`00b9a4b0 00000000`00000000 : 00000000`00000000 fffff800`03a72fa0 fffff800`03874a30 00000000`00000000 : 0xfffffa80`082cec58
fffff800`00b9a4b8 00000000`00000000 : fffff800`03a72fa0 fffff800`03874a30 00000000`00000000 fffff880`03716b50 : 0x0
fffff800`00b9a4c0 fffff800`03a72fa0 : fffff800`03874a30 00000000`00000000 fffff880`03716b50 fffff800`038c396c : 0x0
fffff800`00b9a4c8 fffff800`03874a30 : 00000000`00000000 fffff880`03716b50 fffff800`038c396c fffff880`03716ae0 : nt+0x229fa0
fffff800`00b9a4d0 00000000`00000000 : fffff880`03716b50 fffff800`038c396c fffff880`03716ae0 fffff800`03a63fc0 : nt+0x2ba30
fffff800`00b9a4d8 fffff880`03716b50 : fffff800`038c396c fffff880`03716ae0 fffff800`03a63fc0 fffff800`039b4930 : 0x0
fffff800`00b9a4e0 fffff800`038c396c : fffff880`03716ae0 fffff800`03a63fc0 fffff800`039b4930 00000000`00000000 : 0xfffff880`03716b50
fffff800`00b9a4e8 fffff880`03716ae0 : fffff800`03a63fc0 fffff800`039b4930 00000000`00000000 fffff880`0501acf8 : nt+0x7a96c
fffff800`00b9a4f0 fffff800`03a63fc0 : fffff800`039b4930 00000000`00000000 fffff880`0501acf8 fffff880`05003750 : 0xfffff880`03716ae0
fffff800`00b9a4f8 fffff800`039b4930 : 00000000`00000000 fffff880`0501acf8 fffff880`05003750 00000000`00000000 : nt+0x21afc0
fffff800`00b9a500 00000000`00000000 : fffff880`0501acf8 fffff880`05003750 00000000`00000000 fffffa80`0a6eb010 : nt+0x16b930
fffff800`00b9a508 fffff880`0501acf8 : fffff880`05003750 00000000`00000000 fffffa80`0a6eb010 fffff880`04841064 : 0x0
fffff800`00b9a510 fffff880`05003750 : 00000000`00000000 fffffa80`0a6eb010 fffff880`04841064 00000000`00000000 : tunnel+0x1acf8
fffff880`0501acf8 ??               ???
FOLLOWUP_NAME:  MachineOwner
SYMBOL_NAME:  tunnel+1acf8
IMAGE_NAME:  tunnel.sys
Followup: MachineOwner

Quelle von WinDbg:
und dann Punkt 3 (standalone tool set)
tunnel.sys gehört zum Teredo-Treiber. Den mal im Gerätemanager deaktivieren (vorher ausgeblendete Geräte anzeigen lassen).
Bleibt das Problem bestehen, wird es der Netzwerktreiber sein.
Den gleichnamigen Netzwerkadapter im Gerätemanager.
Aufgrund der Formulierung
simpel1970 schrieb:
Lade mal bitte die Minidump hier im Forum hoch
war ich davon ausgegangen, dass ich diese Datei C:\Windows\Minidump\Minidump.dmp hochladen soll.

Aber anscheinend meint ihr diese Datei
shortrange schrieb:

Ich werde mich bemühen, die Datei hochzuladen.
Danke für den Hinweis.
Werde ich am kommenden Montag machen, da ich dann wieder bei ihm sein werden.