2009-03-21, 06:45
#1
Hej.
Jag har ett problem som jag har haft nu sedan köp av en PC i delar. Jag får det fan inte att bli bra trots en massa åtgärder och undersökningar av drivrutiner och hårdvara. Jag har skapat en dumpfil som ni kan få se, tacksam för alla idéer som kan vara av någon nytta. Personligen så brukar jag kunna lösa det mesta själv men här går jag bet. =/ Bluescreen FTL!
***
BugCheck 1A, {8886, fffffa80019bfc30, fffffa8001800060, 200}
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+9078 )
Followup: MachineOwner
---------
3: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa80019bfc30
Arg3: fffffa8001800060
Arg4: 0000000000000200
Debugging Details:
------------------
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
BUGCHECK_STR: 0x1a_8886
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80001e280f8 to fffff80001e6b350
STACK_TEXT:
fffffa60`08de52d8 fffff800`01e280f8 : 00000000`0000001a 00000000`00008886 fffffa80`019bfc30 fffffa80`01800060 : nt!KeBugCheckEx
fffffa60`08de52e0 fffff800`01e57f9c : fffff880`0a38df38 00000000`00089541 fffffa80`019bfc30 fffffa80`017f1c00 : nt! ?? ::FNODOBFM::`string'+0x9078
fffffa60`08de5320 fffff800`020a6d41 : fffffa80`041fb010 fffff6fd`3004d658 fffff6fd`00000002 fffffa80`083c0b00 : nt!MiValidateImagePages+0x3fc
fffffa60`08de53c0 fffff800`020ba5e5 : ffffffff`ffffffff fffffa80`041fb010 fffff880`0a390000 fffff880`00000046 : nt!MiSwitchBaseAddress+0x61
fffffa60`08de5400 fffff800`020f26a5 : 00000000`00000004 fffffa80`041fb010 00000000`01000000 00000000`01000000 : nt!MiRelocateImageAgain+0xf5
fffffa60`08de5440 fffff800`020baad9 : fffffa60`08de5690 fffffa60`08de5908 fffffa60`08de5748 fffffa60`08de5688 : nt!MmCreateSection+0x5f5
fffffa60`08de5640 fffff800`02218b23 : 00000000`00000000 00000000`0000000d fffff880`0e08f5d8 fffffa80`00000000 : nt!NtCreateSection+0x170
fffffa60`08de56d0 fffff800`0221adc6 : 00000000`00000000 fffff880`0e08f5d8 fffff880`0e08e000 fffffa60`00000060 : nt!PfpFileBuildReadSupport+0x163
fffffa60`08de57c0 fffff800`022447a9 : fffff880`00000000 00000000`00000001 00000000`00000071 00000000`00000000 : nt!PfpPrefetchFilesTrickle+0x126
fffffa60`08de58c0 fffff800`02244a62 : 00000000`00000000 fffffa60`08de5ca0 fffffa60`08de5a08 fffff880`0e08e001 : nt!PfpPrefetchRequestPerform+0x2f9
fffffa60`08de5960 fffff800`02244cc6 : fffffa60`08de5a08 00000000`00000001 fffffa80`08436d40 00000000`00000000 : nt!PfpPrefetchRequest+0x171
fffffa60`08de59d0 fffff800`022573f8 : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`04a2ef01 : nt!PfSetSuperfetchInformation+0x1a5
fffffa60`08de5ab0 fffff800`01e6adf3 : fffffa80`083c0bb0 00000000`00000000 00000000`00000000 00000000`09aafe10 : nt!NtSetSystemInformation+0x8fb
fffffa60`08de5c20 00000000`76f470ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`04a2f738 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f470ea
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+9078
fffff800`01e280f8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+9078
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
Followup: MachineOwner
---------
3: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa80019bfc30
Arg3: fffffa8001800060
Arg4: 0000000000000200
Debugging Details:
------------------
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
BUGCHECK_STR: 0x1a_8886
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80001e280f8 to fffff80001e6b350
STACK_TEXT:
fffffa60`08de52d8 fffff800`01e280f8 : 00000000`0000001a 00000000`00008886 fffffa80`019bfc30 fffffa80`01800060 : nt!KeBugCheckEx
fffffa60`08de52e0 fffff800`01e57f9c : fffff880`0a38df38 00000000`00089541 fffffa80`019bfc30 fffffa80`017f1c00 : nt! ?? ::FNODOBFM::`string'+0x9078
fffffa60`08de5320 fffff800`020a6d41 : fffffa80`041fb010 fffff6fd`3004d658 fffff6fd`00000002 fffffa80`083c0b00 : nt!MiValidateImagePages+0x3fc
fffffa60`08de53c0 fffff800`020ba5e5 : ffffffff`ffffffff fffffa80`041fb010 fffff880`0a390000 fffff880`00000046 : nt!MiSwitchBaseAddress+0x61
fffffa60`08de5400 fffff800`020f26a5 : 00000000`00000004 fffffa80`041fb010 00000000`01000000 00000000`01000000 : nt!MiRelocateImageAgain+0xf5
fffffa60`08de5440 fffff800`020baad9 : fffffa60`08de5690 fffffa60`08de5908 fffffa60`08de5748 fffffa60`08de5688 : nt!MmCreateSection+0x5f5
fffffa60`08de5640 fffff800`02218b23 : 00000000`00000000 00000000`0000000d fffff880`0e08f5d8 fffffa80`00000000 : nt!NtCreateSection+0x170
fffffa60`08de56d0 fffff800`0221adc6 : 00000000`00000000 fffff880`0e08f5d8 fffff880`0e08e000 fffffa60`00000060 : nt!PfpFileBuildReadSupport+0x163
fffffa60`08de57c0 fffff800`022447a9 : fffff880`00000000 00000000`00000001 00000000`00000071 00000000`00000000 : nt!PfpPrefetchFilesTrickle+0x126
fffffa60`08de58c0 fffff800`02244a62 : 00000000`00000000 fffffa60`08de5ca0 fffffa60`08de5a08 fffff880`0e08e001 : nt!PfpPrefetchRequestPerform+0x2f9
fffffa60`08de5960 fffff800`02244cc6 : fffffa60`08de5a08 00000000`00000001 fffffa80`08436d40 00000000`00000000 : nt!PfpPrefetchRequest+0x171
fffffa60`08de59d0 fffff800`022573f8 : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`04a2ef01 : nt!PfSetSuperfetchInformation+0x1a5
fffffa60`08de5ab0 fffff800`01e6adf3 : fffffa80`083c0bb0 00000000`00000000 00000000`00000000 00000000`09aafe10 : nt!NtSetSystemInformation+0x8fb
fffffa60`08de5c20 00000000`76f470ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`04a2f738 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f470ea
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+9078
fffff800`01e280f8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+9078
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
Followup: MachineOwner
---------
3: kd> lmvm nt
start end module name
fffff800`01e16000 fffff800`0232e000 nt (pdb symbols) c:\symbolfiler\ntkrnlmp.pdb\149C563625CA49CEA2881C EDF5D55CCF2\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Thu Sep 18 04:17:25 2008 (48D1BA35)
CheckSum: 0047E2D2
ImageSize: 00518000
File version: 6.0.6001.18145
Product version: 6.0.6001.18145
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.0.6001.18145
FileVersion: 6.0.6001.18145 (vistasp1_gdr.080917-1612)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
***
Helt klart så verkar det ju vara en fil vid namn ntkrnlmp.exe som orsakar detta problem, eller har jag helt fel? Har sökt lite info om den inte riktigt hittat något annat än att det antagligen är någon drivrutin som måste uppdateras. Nu sitter jag med validerade och fungerade drivrutiner men får fortfarande Bluescreen. Har kört memtest där det inte hittades några fel.
Idéer?
*suck*
Jag har ett problem som jag har haft nu sedan köp av en PC i delar. Jag får det fan inte att bli bra trots en massa åtgärder och undersökningar av drivrutiner och hårdvara. Jag har skapat en dumpfil som ni kan få se, tacksam för alla idéer som kan vara av någon nytta. Personligen så brukar jag kunna lösa det mesta själv men här går jag bet. =/ Bluescreen FTL!
***
BugCheck 1A, {8886, fffffa80019bfc30, fffffa8001800060, 200}
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+9078 )
Followup: MachineOwner
---------
3: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa80019bfc30
Arg3: fffffa8001800060
Arg4: 0000000000000200
Debugging Details:
------------------
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
BUGCHECK_STR: 0x1a_8886
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80001e280f8 to fffff80001e6b350
STACK_TEXT:
fffffa60`08de52d8 fffff800`01e280f8 : 00000000`0000001a 00000000`00008886 fffffa80`019bfc30 fffffa80`01800060 : nt!KeBugCheckEx
fffffa60`08de52e0 fffff800`01e57f9c : fffff880`0a38df38 00000000`00089541 fffffa80`019bfc30 fffffa80`017f1c00 : nt! ?? ::FNODOBFM::`string'+0x9078
fffffa60`08de5320 fffff800`020a6d41 : fffffa80`041fb010 fffff6fd`3004d658 fffff6fd`00000002 fffffa80`083c0b00 : nt!MiValidateImagePages+0x3fc
fffffa60`08de53c0 fffff800`020ba5e5 : ffffffff`ffffffff fffffa80`041fb010 fffff880`0a390000 fffff880`00000046 : nt!MiSwitchBaseAddress+0x61
fffffa60`08de5400 fffff800`020f26a5 : 00000000`00000004 fffffa80`041fb010 00000000`01000000 00000000`01000000 : nt!MiRelocateImageAgain+0xf5
fffffa60`08de5440 fffff800`020baad9 : fffffa60`08de5690 fffffa60`08de5908 fffffa60`08de5748 fffffa60`08de5688 : nt!MmCreateSection+0x5f5
fffffa60`08de5640 fffff800`02218b23 : 00000000`00000000 00000000`0000000d fffff880`0e08f5d8 fffffa80`00000000 : nt!NtCreateSection+0x170
fffffa60`08de56d0 fffff800`0221adc6 : 00000000`00000000 fffff880`0e08f5d8 fffff880`0e08e000 fffffa60`00000060 : nt!PfpFileBuildReadSupport+0x163
fffffa60`08de57c0 fffff800`022447a9 : fffff880`00000000 00000000`00000001 00000000`00000071 00000000`00000000 : nt!PfpPrefetchFilesTrickle+0x126
fffffa60`08de58c0 fffff800`02244a62 : 00000000`00000000 fffffa60`08de5ca0 fffffa60`08de5a08 fffff880`0e08e001 : nt!PfpPrefetchRequestPerform+0x2f9
fffffa60`08de5960 fffff800`02244cc6 : fffffa60`08de5a08 00000000`00000001 fffffa80`08436d40 00000000`00000000 : nt!PfpPrefetchRequest+0x171
fffffa60`08de59d0 fffff800`022573f8 : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`04a2ef01 : nt!PfSetSuperfetchInformation+0x1a5
fffffa60`08de5ab0 fffff800`01e6adf3 : fffffa80`083c0bb0 00000000`00000000 00000000`00000000 00000000`09aafe10 : nt!NtSetSystemInformation+0x8fb
fffffa60`08de5c20 00000000`76f470ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`04a2f738 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f470ea
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+9078
fffff800`01e280f8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+9078
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
Followup: MachineOwner
---------
3: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa80019bfc30
Arg3: fffffa8001800060
Arg4: 0000000000000200
Debugging Details:
------------------
Page 9fad6 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
BUGCHECK_STR: 0x1a_8886
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80001e280f8 to fffff80001e6b350
STACK_TEXT:
fffffa60`08de52d8 fffff800`01e280f8 : 00000000`0000001a 00000000`00008886 fffffa80`019bfc30 fffffa80`01800060 : nt!KeBugCheckEx
fffffa60`08de52e0 fffff800`01e57f9c : fffff880`0a38df38 00000000`00089541 fffffa80`019bfc30 fffffa80`017f1c00 : nt! ?? ::FNODOBFM::`string'+0x9078
fffffa60`08de5320 fffff800`020a6d41 : fffffa80`041fb010 fffff6fd`3004d658 fffff6fd`00000002 fffffa80`083c0b00 : nt!MiValidateImagePages+0x3fc
fffffa60`08de53c0 fffff800`020ba5e5 : ffffffff`ffffffff fffffa80`041fb010 fffff880`0a390000 fffff880`00000046 : nt!MiSwitchBaseAddress+0x61
fffffa60`08de5400 fffff800`020f26a5 : 00000000`00000004 fffffa80`041fb010 00000000`01000000 00000000`01000000 : nt!MiRelocateImageAgain+0xf5
fffffa60`08de5440 fffff800`020baad9 : fffffa60`08de5690 fffffa60`08de5908 fffffa60`08de5748 fffffa60`08de5688 : nt!MmCreateSection+0x5f5
fffffa60`08de5640 fffff800`02218b23 : 00000000`00000000 00000000`0000000d fffff880`0e08f5d8 fffffa80`00000000 : nt!NtCreateSection+0x170
fffffa60`08de56d0 fffff800`0221adc6 : 00000000`00000000 fffff880`0e08f5d8 fffff880`0e08e000 fffffa60`00000060 : nt!PfpFileBuildReadSupport+0x163
fffffa60`08de57c0 fffff800`022447a9 : fffff880`00000000 00000000`00000001 00000000`00000071 00000000`00000000 : nt!PfpPrefetchFilesTrickle+0x126
fffffa60`08de58c0 fffff800`02244a62 : 00000000`00000000 fffffa60`08de5ca0 fffffa60`08de5a08 fffff880`0e08e001 : nt!PfpPrefetchRequestPerform+0x2f9
fffffa60`08de5960 fffff800`02244cc6 : fffffa60`08de5a08 00000000`00000001 fffffa80`08436d40 00000000`00000000 : nt!PfpPrefetchRequest+0x171
fffffa60`08de59d0 fffff800`022573f8 : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`04a2ef01 : nt!PfSetSuperfetchInformation+0x1a5
fffffa60`08de5ab0 fffff800`01e6adf3 : fffffa80`083c0bb0 00000000`00000000 00000000`00000000 00000000`09aafe10 : nt!NtSetSystemInformation+0x8fb
fffffa60`08de5c20 00000000`76f470ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`04a2f738 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f470ea
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+9078
fffff800`01e280f8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+9078
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35
FAILURE_BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
BUCKET_ID: X64_0x1a_8886_nt!_??_::FNODOBFM::_string_+9078
Followup: MachineOwner
---------
3: kd> lmvm nt
start end module name
fffff800`01e16000 fffff800`0232e000 nt (pdb symbols) c:\symbolfiler\ntkrnlmp.pdb\149C563625CA49CEA2881C EDF5D55CCF2\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Thu Sep 18 04:17:25 2008 (48D1BA35)
CheckSum: 0047E2D2
ImageSize: 00518000
File version: 6.0.6001.18145
Product version: 6.0.6001.18145
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.0.6001.18145
FileVersion: 6.0.6001.18145 (vistasp1_gdr.080917-1612)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
***
Helt klart så verkar det ju vara en fil vid namn ntkrnlmp.exe som orsakar detta problem, eller har jag helt fel? Har sökt lite info om den inte riktigt hittat något annat än att det antagligen är någon drivrutin som måste uppdateras. Nu sitter jag med validerade och fungerade drivrutiner men får fortfarande Bluescreen. Har kört memtest där det inte hittades några fel.
Idéer?
*suck*