Hallo BuZeMaNn,
Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Petra\Desktop\052912-31387-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17803.amd64fre.win7sp1_gdr.120330-1504
Machine Name:
Kernel base = 0xfffff800`03c4a000 PsLoadedModuleList = 0xfffff800`03e8e670
Debug session time: Tue May 29 22:08:18.941 2012 (UTC + 2:00)
System Uptime: 0 days 3:34:19.174
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa801c090828, 0, fffff80003c98ceb, 2}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiDeleteAddressesInWorkingSet+27f )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa801c090828, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80003c98ceb, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003ef8100
fffffa801c090828
FAULTING_IP:
nt!MiDeleteAddressesInWorkingSet+27f
fffff800`03c98ceb 488b4128 mov rax,qword ptr [rcx+28h]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: MsMpEng.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800893ccf0 -- (.trap 0xfffff8800893ccf0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000058000000000 rbx=0000000000000000 rcx=fffffa801c090800
rdx=00000000024b8009 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003c98ceb rsp=fffff8800893ce80 rbp=fffff700010eda98
r8=fffffa8006fe96e8 r9=0000000000000001 r10=00000000000025bf
r11=fffff70001080000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!MiDeleteAddressesInWorkingSet+0x27f:
fffff800`03c98ceb 488b4128 mov rax,qword ptr [rcx+28h] ds:c7be:fffffa80`1c090828=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003c6ff50 to fffff80003cc91c0
STACK_TEXT:
fffff880`0893cb88 fffff800`03c6ff50 : 00000000`00000050 fffffa80`1c090828 00000000`00000000 fffff880`0893ccf0 : nt!KeBugCheckEx
fffff880`0893cb90 fffff800`03cc72ee : 00000000`00000000 fffffa80`1c090828 00000000`00001000 ac200009`58580867 : nt! ?? ::FNODOBFM::`string'+0x43d86
fffff880`0893ccf0 fffff800`03c98ceb : 00000003`00000000 2bd00000`10166867 fffff700`010eda70 fffff680`000b4b38 : nt!KiPageFault+0x16e
fffff880`0893ce80 fffff800`03c99e42 : fffffa80`06fe9350 fffffa80`0000011f fffff8a0`000025bf fffff880`00000000 : nt!MiDeleteAddressesInWorkingSet+0x27f
fffff880`0893d730 fffff800`03f9a6da : fffff8a0`0cb38840 fffff880`0893dae0 00000000`00000000 fffffa80`07445b50 : nt!MmCleanProcessAddressSpace+0x96
fffff880`0893d780 fffff800`03f7dbdd : 00000000`000000ff fffff880`014d1701 000007ff`fff8a000 00000000`00000000 : nt!PspExitThread+0x56a
fffff880`0893d880 fffff800`03cbbd1a : fffffa80`140e51c8 fffffa80`09f18b20 fffffa80`09eb0a30 fffffa80`140e50d8 : nt!PsExitSpecialApc+0x1d
fffff880`0893d8b0 fffff800`03cbc060 : 00000000`0114dd10 fffff880`0893d930 fffff800`03f7db50 00000000`00000001 : nt!KiDeliverApc+0x2ca
fffff880`0893d930 fffff800`03cc84f7 : 00000000`000002e8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiInitiateUserApc+0x70
fffff880`0893da70 00000000`7744137a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`0114dae8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7744137a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiDeleteAddressesInWorkingSet+27f
fffff800`03c98ceb 488b4128 mov rax,qword ptr [rcx+28h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiDeleteAddressesInWorkingSet+27f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4f76721c
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiDeleteAddressesInWorkingSet+27f
BUCKET_ID: X64_0x50_nt!MiDeleteAddressesInWorkingSet+27f
Followup: MachineOwner
---------
Scheint also wie auch immer mit der Datei MsMpEng.exe zusammenzuhängen, die zu Windows Security Essentials gehört. Das bestätigt auch diese Fehlermeldung in den Ereignissen:
Code:
Error - 28.05.2012 08:28:15 | Computer Name = Adrian-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: MsMpEng.exe, Version: 4.0.1526.0,
Zeitstempel: 0x4f711b15 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
Zeitstempel: 0x4ec4aa8e Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005324e
ID des fehlerhaften Prozesses: 0x190 Startzeit der fehlerhaften Anwendung: 0x01cd3ccd17f470f9
Pfad der fehlerhaften Anwendung: c:\Program Files\Microsoft Security Client\MsMpEng.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll Berichtskennung: 98cf8841-a8c0-11e1-a0e7-8c89a58069c6
Machen wir erstmal folgendes:
===== Punkt 1 =====
Zunächst schlage ich vor, Microsoft Security Essentials einmal ganz zu installieren. Gehe wie folgt vor:
Lade die aktuelle Version herunter => http://windows.microsoft.com/de-DE/w...ity-essentials
Trenne den Rechner vom Netz.
Deinstalliere über Systemsteuerung => Programme die alte Version
Starte den Computer neu.
Installiere die neue Version.
Verbinde den Rechner wieder mit dem Netz.
Lasse die Signaturen aktualisieren und mache einen Komplettscan.
Wenn Funde gemacht werden, teile mir bitte die Details dazu mit, inkl. Pfad- und Dateiname.
Lesezeichen