Blue screen of death

Colapsar
X
 
  • Filtrar
  • Tiempo
  • Mostrar
Limpiar Todo
nuevos mensajes

  • Blue screen of death

    Ultimamente me aparece la dichosa pantallita azul todo el tiempo o no me arranca el portatil y se queda la pantalla en negro. Ha empezado a pasarme hace unos dias, sin haber instalado ningun programa, driver o hardware.
    Gracias ha que tengo configurado el ordenador para hacer dumps de lo sucedido, he conseguido la siguiente informacion:

    Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini012613-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/s...wnload/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b1c0
    Debug session time: Sat Jan 26 18:42:15.787 2013 (UTC + 0:00)
    System Uptime: 0 days 1:33:51.357
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    .........
    Loading User Symbols
    Loading unloaded module list
    .............
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 100000BE, {b877dd24, 32406121, b8775c94, b}

    Probably caused by : memory_corruption

    Followup: memory_corruption
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
    An attempt was made to write to readonly memory. The guilty driver is on the
    stack trace (and is typically the current instruction pointer).
    When possible, the guilty driver's name (Unicode string) is printed on
    the bugcheck screen and saved in KiBugCheckDriver.
    Arguments:
    Arg1: b877dd24, Virtual address for the attempted write.
    Arg2: 32406121, PTE contents.
    Arg3: b8775c94, (reserved)
    Arg4: 0000000b, (reserved)

    Debugging Details:
    ------------------


    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: CODE_CORRUPTION

    BUGCHECK_STR: 0xBE

    PROCESS_NAME: winamp.exe

    LAST_CONTROL_TRANSFER: from 68107536 to 80566212

    STACK_TEXT:
    b877dd50 68107536 000002d0 77dc0c68 bbe850b8 nt!NtWaitForSingleObject+0x9c
    WARNING: Frame IP not in any known module. Following frames may be wrong.
    b877dd60 3bfffff4 5fdf75f7 c2c95b5e cccc0004 0x68107536
    b877dd64 5fdf75f7 c2c95b5e cccc0004 cccccccc 0x3bfffff4
    b877dd68 c2c95b5e cccc0004 cccccccc 8b55ff8b 0x5fdf75f7
    b877dd6c cccc0004 cccccccc 8b55ff8b 575653ec 0xc2c95b5e
    b877dd70 cccccccc 8b55ff8b 575653ec 0ad415ff 0xcccc0004
    b877dd74 8b55ff8b 575653ec 0ad415ff 053bb878 0xcccccccc
    b877dd78 575653ec 0ad415ff 053bb878 b8782ac4 0x8b55ff8b
    b877dd7c 0ad415ff 053bb878 b8782ac4 00d7850f 0x575653ec
    b877dd80 053bb878 b8782ac4 00d7850f 15ff0000 0xad415ff
    b877dd84 b8782ac4 00d7850f 15ff0000 b8780a0c 0x53bb878
    b877dd88 00d7850f 15ff0000 b8780a0c 850fc084 mrxdav!RxDispatcher+0x4
    b877dd8c 15ff0000 b8780a0c 850fc084 000000c9 0xd7850f
    b877dd90 b8780a0c 850fc084 000000c9 8d08758b 0x15ff0000
    b877dd94 850fc084 000000c9 8d08758b cb8b045e mrxdav!_imp__KeGetCurrentIrql
    b8780a0c 00029088 00029072 00000000 000290c0 0x850fc084
    b8780a10 00029072 00000000 000290c0 000290a6 0x29088
    b8780a14 00000000 000290c0 000290a6 00000000 0x29072


    STACK_COMMAND: kb

    CHKIMG_EXTENSION: !chkimg -lo 50 -d !mrxdav
    b877dd05 - mrxdav!RxTearDownWorkQueue+cf
    [ e8:68 ]
    1 error : !mrxdav (b877dd05)

    MODULE_NAME: memory_corruption

    IMAGE_NAME: memory_corruption

    FOLLOWUP_NAME: memory_corruption

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    MEMORY_CORRUPTOR: ONE_BIT

    FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

    BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

    Followup: memory_corruption
    ---------





    Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini012813-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b1c0
    Debug session time: Mon Jan 28 16:32:21.979 2013 (UTC + 0:00)
    System Uptime: 0 days 0:05:33.550
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ........
    Loading User Symbols
    Loading unloaded module list
    .............
    Unable to load image aswSnx.SYS, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for aswSnx.SYS
    *** ERROR: Module load completed but symbols could not be loaded for aswSnx.SYS
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, b9fbc663, b7aca748, 0}

    Unable to load image aswFsBlk.SYS, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for aswFsBlk.SYS
    *** ERROR: Module load completed but symbols could not be loaded for aswFsBlk.SYS
    *** WARNING: Unable to verify timestamp for aswMon2.SYS
    *** ERROR: Module load completed but symbols could not be loaded for aswMon2.SYS
    Probably caused by : aswSnx.SYS ( aswSnx+9663 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
    This is a very common bugcheck. Usually the exception address pinpoints
    the driver/function that caused the problem. Always note this address
    as well as the link date of the driver/image that contains this address.
    Some common problems are exception code 0x80000003. This means a hard
    coded breakpoint or assertion was hit, but this system was booted
    /NODEBUG. This is not supposed to happen as developers should never have
    hardcoded breakpoints in retail code, but ...
    If this happens, make sure a debugger gets connected, and the
    system is booted /DEBUG. This will let us see why this breakpoint is
    happening.
    Arguments:
    Arg1: c0000005, The exception code that was not handled
    Arg2: b9fbc663, The address that the exception occurred at
    Arg3: b7aca748, Trap Frame
    Arg4: 00000000

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

    FAULTING_IP:
    aswSnx+9663
    b9fbc663 8b4828 mov ecx,dword ptr [eax+28h]

    TRAP_FRAME: b7aca748 -- (.trap 0xffffffffb7aca74
    ErrCode = 00000000
    eax=000000a9 ebx=00000000 ecx=49bb000e edx=49ba000d esi=8536d5c8 edi=00000000
    eip=b9fbc663 esp=b7aca7bc ebp=b7aca7ec iopl=0 ov up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010a46
    aswSnx+0x9663:
    b9fbc663 8b4828 mov ecx,dword ptr [eax+28h] ds:0023:000000d1=????????
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x8E

    PROCESS_NAME: firefox.exe

    LAST_CONTROL_TRANSFER: from f7687c3f to b9fbc663

    STACK_TEXT:
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b7aca7ec f7687c3f 8653b178 85395160 85c8169c aswSnx+0x9663
    b7aca81c f768a18e 8536d5c8 00000000 8536d5c8 fltMgr!FltpCallOpenedFileNameHandler+0x45
    b7aca838 f768a76b 8536d5c8 00000000 000000fe fltMgr!FltpGetNormalizedFileNameWorker+0xc4
    b7aca850 f76882a2 8536d5c8 00000000 8536d5c8 fltMgr!FltpGetNormalizedFileName+0x19
    b7aca868 f7680365 80552000 8536d5c8 b7aca8a4 fltMgr!FltpCreateFileNameInformation+0x84
    b7aca878 f7678e0a 8536d5c8 85c8169c 00000000 fltMgr!FltEnumerateInstances+0x99
    b7aca8a4 f7679366 8536d5c8 b7aca8f4 b7aca938 fltMgr!FltpGetFileNameInformation+0xaa
    b7aca8cc b7f58b40 00c8169c 00000101 b7aca8f0 fltMgr!FltGetFileNameInformation+0x114
    b7aca914 b7f5875b b7aca964 85c8169c b7aca938 aswFsBlk+0x1b40
    b7aca944 f7674888 00120196 b7aca964 b7aca994 aswFsBlk+0x175b
    b7aca9a4 f76762a0 00aca9e8 85c81640 8661bfb4 fltMgr!FltpPerformPreCallbacks+0x2d4
    b7aca9b8 f7683217 b7aca9e8 f76816aa 00000000 fltMgr!FltpPassThroughInternal+0x32
    b7aca9d0 f7683742 b7aca9e8 856a9008 8661bfd8 fltMgr!FltpCreateInternal+0x63
    b7acaa04 804e37f7 865b7020 8661be00 8661bffc fltMgr!FltpCreate+0x258
    b7acaa14 b7bb6777 00000000 862e84f8 85395160 nt!IopfCallDriver+0x31
    b7acaa38 b7bafac7 86258560 8661be00 8661be10 aswMon2+0x7777
    b7acaa4c 804e37f7 86258560 8661be00 8661be00 aswMon2+0xac7
    b7acaa5c 8056c712 866d6578 85306804 b7acac04 nt!IopfCallDriver+0x31
    b7acab3c 80563fec 866d6590 00000000 85306760 nt!IopParseDevice+0xa12
    b7acabc4 805684da 00000000 b7acac04 00000040 nt!ObpLookupObjectName+0x56a
    b7acac18 8056cbeb 00000000 00000000 00000001 nt!ObOpenObjectByName+0xeb
    b7acac94 8056ccba 027ffeac 40100080 027ffe4c nt!IopCreateFile+0x407
    b7acacf0 8056cdf0 027ffeac 40100080 027ffe4c nt!IoCreateFile+0x8e
    b7acad30 804de7ec 027ffeac 40100080 027ffe4c nt!NtCreateFile+0x30
    b7acad30 7c90e4f4 027ffeac 40100080 027ffe4c nt!KiFastCallEntry+0xf8
    027ffea4 00000000 00000000 00000000 00000000 0x7c90e4f4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    aswSnx+9663
    b9fbc663 8b4828 mov ecx,dword ptr [eax+28h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: aswSnx+9663

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: aswSnx

    IMAGE_NAME: aswSnx.SYS

    DEBUG_FLR_IMAGE_TIMESTAMP: 5090582a

    FAILURE_BUCKET_ID: 0x8E_aswSnx+9663

    BUCKET_ID: 0x8E_aswSnx+9663

    Followup: MachineOwner
    ---------




    Loading Dump File [C:\WINDOWS\Minidump\Mini020413-02.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp.080413-2111
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b1c0
    Debug session time: Mon Feb 4 13:20:34.075 2013 (UTC + 0:00)
    System Uptime: 0 days 0:02:43.645
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ........
    Loading User Symbols
    Loading unloaded module list
    .............
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 10000050, {b7b7ecc0, 0, 804e4090, 3}


    Could not read faulting driver name
    Probably caused by : ntoskrnl.exe ( nt!KeRemoveQueue+308 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced. This cannot be protected by try-except,
    it must be protected by a Probe. Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: b7b7ecc0, memory referenced.
    Arg2: 00000000, value 0 = read operation, 1 = write operation.
    Arg3: 804e4090, If non-zero, the instruction address which referenced the bad memory
    address.
    Arg4: 00000003, (reserved)

    Debugging Details:
    ------------------


    Could not read faulting driver name

    READ_ADDRESS: b7b7ecc0

    FAULTING_IP:
    nt!KeRemoveQueue+308
    804e4090 c9 leave

    MM_INTERNAL_CODE: 3

    CUSTOMER_CRASH_COUNT: 2

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x50

    PROCESS_NAME: AvastSvc.exe

    LAST_CONTROL_TRANSFER: from 00000000 to 804e4090

    STACK_TEXT:
    b7b7ecc0 00000000 00000000 00000000 00000000 nt!KeRemoveQueue+0x308


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!KeRemoveQueue+308
    804e4090 c9 leave

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt!KeRemoveQueue+308

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntoskrnl.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 48025eab

    FAILURE_BUCKET_ID: 0x50_nt!KeRemoveQueue+308

    BUCKET_ID: 0x50_nt!KeRemoveQueue+308

    Followup: MachineOwner
    ---------

    La cosa es que no entiendo bien la informacion y no se como arreglarlo. Sabe alguien que es lo que pasa y como arreglarlo?

    Saludos

  • #2
    Re: Blue screen of death

    Siento haber puesto dos veces el mismo tema,pero es que me daba error y pense que no se habia enviado. Si alguien puede borrar uno de los dos, para que no se repita el tema, se lo agradeceria.

    Comentario

    Trabajando...
    X