Hi erstmal danke für die Antwort.
Ich hab ein Desktop Pc.
Hardware ist:
Mainboard GigaByte GA-870A-UD3
CPU AMD Phenom X6 1075T
Grafikkarte AMD HD 6950
RAM 8 GB (herstellername vergessen)
Einen Debugger habe ich grade installiert, nur blick ich da noch nicht so ganz durch.
Aufjedenfall scheint die ntkrnlmp.exe etwas damit zu tun zu haben.
Vielleicht hilft euch das ja mehr, das hier steht drinne:
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 4, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+42b65 )
Followup: MachineOwner
---------
2: kd> g
^ No runnable debuggees error in 'g'
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000004
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002c1eb9a to fffff80002c72700
STACK_TEXT:
fffff880`031e67e8 fffff800`02c1eb9a : 00000000`0000001a 00000000`00041287 00000000`00000004 00000000`00000000 : nt!KeBugCheckEx
fffff880`031e67f0 fffff800`02c707ee : 00000000`00000000 00000000`00000000 00000d4c`00000000 ffffde7a`00000006 : nt! ?? ::FNODOBFM::`string'+0x42b65
fffff880`031e6950 fffff800`02cf4b96 : fffffa80`0862c3f8 fffff880`00000001 00000000`00000001 fffff880`031e6bb0 : nt!KiPageFault+0x16e
fffff880`031e6ae0 fffff800`02c86ef2 : 00000000`00006a0b 00000000`00000000 fffffa80`00000000 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x496c5
fffff880`031e6b80 fffff800`02c87183 : 00000000`00000008 fffff880`031e6c10 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`031e6bd0 fffff800`02f15bc6 : fffffa80`06a27580 00000000`00000080 fffffa80`06a0c040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`031e6d40 fffff800`02c50bc6 : fffff880`02f64180 fffffa80`06a27580 fffff880`02f6f040 85119485`33665533 : nt!PspSystemThreadStartup+0x5a
fffff880`031e6d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+42b65
fffff800`02c1eb9a cc int 3
SYMBOL_STACK_INDEX: 1
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+42b65
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd34
STACK_COMMAND: kb
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+42b65
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+42b65
Followup: MachineOwner
---------
2: kd> !devnode 0 1
Error reading value of IopRootDeviceNode (0xfffff80002e76570)
2: kd> im v mntkrnlmp
^ Syntax error in 'im v mntkrnlmp'
2: kd> IM v mntkrnlmp
^ Syntax error in 'IM v mntkrnlmp'
2: kd> Im v mntkrnlmp
^ Syntax error in 'Im v mntkrnlmp'
2: kd> Im v mntkrnlmp.exe
^ Syntax error in 'Im v mntkrnlmp.exe'
2: kd> !thread
GetPointerFromAddress: unable to read from fffff80002eaa000
THREAD fffffa8006a27580 Cid 0004.0074 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 2
Not impersonating
GetUlongFromAddress: unable to read from fffff80002de8ba4
Owning Process fffffa800862c060 Image: lsass.exe
fffff78000000000: Unable to get shared data
Wait Start TickCount 1740053
Context Switch Count 30197
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.0000
KernelTime 00:00:00.0000
Start Address nt!KeBalanceSetManager (0xfffff80002c86fc0)
Win32 Start Address nt!KeBalanceSetManager (0xfffff80002c86fc0)
Stack Init fffff880031e6db0 Current fffff880031e6710
Base fffff880031e7000 Limit fffff880031e1000 Call 0
Priority 16 BasePriority 8 PriorityDecrement 0
Child-SP RetAddr : Args to Child : Call Site
fffff880`031e67e8 fffff800`02c1eb9a : 00000000`0000001a 00000000`00041287 00000000`00000004 00000000`00000000 : nt!KeBugCheckEx
fffff880`031e67f0 fffff800`02c707ee : 00000000`00000000 00000000`00000000 00000d4c`00000000 ffffde7a`00000006 : nt! ?? ::FNODOBFM::`string'+0x42b65
fffff880`031e6950 fffff800`02cf4b96 : fffffa80`0862c3f8 fffff880`00000001 00000000`00000001 fffff880`031e6bb0 : nt!KiPageFault+0x16e
fffff880`031e6ae0 fffff800`02c86ef2 : 00000000`00006a0b 00000000`00000000 fffffa80`00000000 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x496c5
fffff880`031e6b80 fffff800`02c87183 : 00000000`00000008 fffff880`031e6c10 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`031e6bd0 fffff800`02f15bc6 : fffffa80`06a27580 00000000`00000080 fffffa80`06a0c040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`031e6d40 fffff800`02c50bc6 : fffff880`02f64180 fffffa80`06a27580 fffff880`02f6f040 85119485`33665533 : nt!PspSystemThreadStartup+0x5a
fffff880`031e6d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
Mit freundlichen Grüßen
Narek