Salve a tutti.........da 2 settimane circa mi appare la fatidica BSoD senza nessun motivo specifico....nell'ultimo periodo sopratutto quando riproduco file multimediali con WMP 11...vi allego i dump file ottenuti con Windows Debugger................AIUTATEMI!!!!
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini042011-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\WINDOWS\symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805540c0
Debug session time: Wed Apr 20 17:42:57.656 2011 (UTC + 2:00)
System Uptime: 0 days 0:29:16.238
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
.................................................. .............
.................................................. ..............
.......
Loading User Symbols
Loading unloaded module list
.........
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 77, {c0000185, c0000185, 0, 1b65000}
Probably caused by : ntoskrnl.exe ( nt!KeContextToKframes+1eb )
Followup: MachineOwner
---------
kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
KERNEL_STACK_INPAGE_ERROR (77)
The requested page of kernel data could not be read in. Caused by
bad block in paging file or disk controller error.
In the case when the first arguments is 0 or 1, the stack signature
in the kernel stack was not found. Again, bad hardware.
An I/O status of c000009c (STATUS_DEVICE_DATA_ERROR) or
C000016AL (STATUS_DISK_OPERATION_FAILED) normally indicates
the data could not be read from the disk due to a bad
block. Upon reboot autocheck will run and attempt to map out the bad
sector. If the status is C0000185 (STATUS_IO_DEVICE_ERROR) and the paging
file is on a SCSI disk device, then the cabling and termination should be
checked. See the knowledge base article on SCSI termination.
Arguments:
Arg1: c0000185, status code
Arg2: c0000185, i/o status code
Arg3: 00000000, page file number
Arg4: 01b65000, offset into page file
Debugging Details:
------------------
ERROR_CODE: (NTSTATUS) 0xc0000185 - La periferica di I/O ha riportato un errore di I/O.
DISK_HARDWARE_ERROR: There was error with disk hardware
BUGCHECK_STR: 0x77_c0000185
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: SYSTEM
LAST_CONTROL_TRANSFER: from 8050f19c to 804f8cc5
STACK_TEXT:
f7a4fcdc 8050f19c 00000077 c0000185 c0000185 nt!KeContextToKframes+0x1eb
f7a4fd50 8050fed6 c07bd3d8 0002eaf6 00000001 nt!`string'+0x10
f7a4fd8c 8053c154 006e3290 00000000 871bf8b8 nt!KiInitializeTSS+0x12
f7a4fda4 8053c62f 866e32f0 805c62c2 00000000 nt!MiWaitForForkToComplete+0x25
f7a4fddc 80541e82 8053c5a6 00000000 00000000 nt!MiDecrementCloneBlockReference+0xcc
f7a4fdf8 00000000 00000000 00000000 00001f80 nt!RtlpTraceDatabaseInternalAdd+0x130
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KeContextToKframes+1eb
804f8cc5 5d pop ebp
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!KeContextToKframes+1eb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntoskrnl.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4d00d46f
FAILURE_BUCKET_ID: 0x77_c0000185_nt!KeContextToKframes+1eb
BUCKET_ID: 0x77_c0000185_nt!KeContextToKframes+1eb
Followup: MachineOwner
---------
kd> lmvm nt
start end module name
804d7000 806d1200 nt M (pdb symbols) c:\windows\symbols\exe\ntoskrnl.pdb
Loaded symbol image file: ntoskrnl.exe
Image path: ntoskrnl.exe
Image name: ntoskrnl.exe
Timestamp: Thu Dec 09 14:06:55 2010 (4D00D46F)
CheckSum: 002039C8
ImageSize: 001FA200
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini041911-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\WINDOWS\symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805540c0
Debug session time: Tue Apr 19 11:18:33.390 2011 (UTC + 2:00)
System Uptime: 0 days 0:27:08.978
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
.................................................. .............
.................................................. ..............
.......
Loading User Symbols
Loading unloaded module list
.........
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, 86ff02c8, 86ff043c, 805c8d78}
unable to get nt!KiCurrentEtwBufferOffset
unable to get nt!KiCurrentEtwBufferBase
Probably caused by : csrss.exe
Followup: MachineOwner
---------
kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 86ff02c8, Terminating object
Arg3: 86ff043c, Process image file name
Arg4: 805c8d78, Explanatory message (ascii)
Debugging Details:
------------------
unable to get nt!KiCurrentEtwBufferOffset
unable to get nt!KiCurrentEtwBufferBase
PROCESS_OBJECT: 86ff02c8
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 00000000
PROCESS_NAME: csrss.exe
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xF4
STACK_TEXT:
f69d7520 805c7e65 000000f4 00000003 86ff02c8 nt!KeContextToKframes+0x1eb
f69d7544 805c8e23 805c8d78 86ff02c8 86ff043c nt!ArbFindSuitableRange+0x5b
f69d7574 8053d6d8 86ff0510 c0000006 f69d79b0 nt!IopFilterResourceRequirementsList+0x10d
f69d7584 804ff1cd badb0d00 f69d75fc 000c0000 nt!PoRegisterDeviceNotify+0x85
f69d79b0 8050045b f69d79d8 00000000 f69d7d64 nt!_output+0x3a4
f69d7d34 80540f31 0053fbe8 0053fc08 00000000 nt!IoCancelIrp+0x51
f69d7d50 8053d6d8 0053fbe8 0053fc08 00000000 nt!RtlIpv4StringToAddressExA+0xc6
f69d7d64 7c91e514 badb0d00 0053fbdc 00000000 nt!PoRegisterDeviceNotify+0x85
WARNING: Frame IP not in any known module. Following frames may be wrong.
f69d7d80 00000000 00000000 00000000 00000000 0x7c91e514
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: 0xF4_IMAGE_csrss.exe
BUCKET_ID: 0xF4_IMAGE_csrss.exe
Followup: MachineOwner
---------
kd> lmvm csrss
start end module name
kd> lmvm csrss
start end module name