|
|
|
![]() |
|
Strumenti |
![]() |
#21 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
Microsoft (R) Windows Debugger Version 6.8.0004.0 X86
Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Windows\Minidump\Mini031808-02.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 6000.16575.x86fre.vista_gdr.071009-1548 Kernel base = 0x81c00000 PsLoadedModuleList = 0x81d11e10 Debug session time: Tue Mar 18 13:30:32.633 2008 (GMT+1) System Uptime: 0 days 0:36:17.487 Loading Kernel Symbols ......................................................................................................................................................... Loading User Symbols Loading unloaded module list ..... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck D1, {3fe3058, 2, 0, 8b432bfd} Probably caused by : usbhub.sys ( usbhub!PdoExt+1f ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If kernel debugger is available get stack backtrace. Arguments: Arg1: 03fe3058, memory referenced Arg2: 00000002, IRQL Arg3: 00000000, value 0 = read operation, 1 = write operation Arg4: 8b432bfd, address which referenced memory Debugging Details: ------------------ OVERLAPPED_MODULE: Address regions for 'cdfs' and 'parport.sys' overlap READ_ADDRESS: GetPointerFromAddress: unable to read from 81d315ac Unable to read MiSystemVaType memory at 81d117e0 03fe3058 CURRENT_IRQL: 2 FAULTING_IP: usbhub!PdoExt+1f 8b432bfd 8b4028 mov eax,dword ptr [eax+28h] CUSTOMER_CRASH_COUNT: 2 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: System TRAP_FRAME: 880bcab8 -- (.trap 0xffffffff880bcab8) ErrCode = 00000000 eax=03fe3030 ebx=85ad5780 ecx=00000000 edx=31696e6f esi=865cc808 edi=00000100 eip=8b432bfd esp=880bcb2c ebp=880bcb2c iopl=0 nv up ei pl nz na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206 usbhub!PdoExt+0x1f: 8b432bfd 8b4028 mov eax,dword ptr [eax+28h] ds:0023:03fe3058=???????? Resetting default scope LAST_CONTROL_TRANSFER: from 8b432bfd to 81c8fd84 STACK_TEXT: 880bcab8 8b432bfd badb0d00 31696e6f 0000000f nt!KiTrap0E+0x2ac 880bcb2c 8b4389e4 03fe3030 85d81000 00000400 usbhub!PdoExt+0x1f 880bcb58 8b434c0e 85af7028 83ffd700 00000004 usbhub!UsbhDetectDuplicateDevice+0x67 880bcb90 8b43662d 00000001 00000000 83ffd700 usbhub!UsbhReset2Complete+0x1df 880bcbb4 8b435adc 85af7028 00000010 00000000 usbhub!UsbhEnumerate2+0x192 880bcbe4 8b43556c 85af7028 85d81019 83ffd700 usbhub!UsbhHubDispatchPortEvent+0x4a6 880bcc34 8b435d02 00000503 85d81000 85d81014 usbhub!UsbhHubRunPortChangeQueue+0x1b4 880bcc58 8b435124 85af7000 00000004 85d81014 usbhub!Usbh_PCE_wRun_Action+0x11b 880bcc78 8b436074 85af7028 85d81000 00000005 usbhub!UsbhDispatch_PortChangeQueueEventEx+0xb9 880bcca4 8b436047 85af7028 85d81000 00000005 usbhub!UsbhDispatch_PortChangeQueueEvent+0x24 880bccd4 8b43601d 85af7028 85d81000 00000005 usbhub!UsbhDispatch_PortChangeQueueNullEvent+0x20 880bccf0 8b435fbf 85af7028 85d81014 85d81000 usbhub!UsbhPCE_wRun+0x48 880bcd10 8b4327dc 85af7028 9f109c70 85d81014 usbhub!UsbhHubProcessChangeWorker+0x7c 880bcd30 81d8c85a 85af7028 83ee1420 8367c580 usbhub!UsbhHubWorker+0x50 880bcd44 81c78fa0 864c3f58 00000000 8367c580 nt!IopProcessWorkItem+0x23 880bcd7c 81e254e0 864c3f58 880b7680 00000000 nt!ExpWorkerThread+0xfd 880bcdc0 81c9159e 81c78ea3 00000001 00000000 nt!PspSystemThreadStartup+0x9d 00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16 STACK_COMMAND: kb FOLLOWUP_IP: usbhub!PdoExt+1f 8b432bfd 8b4028 mov eax,dword ptr [eax+28h] SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: usbhub!PdoExt+1f FOLLOWUP_NAME: MachineOwner MODULE_NAME: usbhub IMAGE_NAME: usbhub.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4549b278 FAILURE_BUCKET_ID: 0xD1_usbhub!PdoExt+1f BUCKET_ID: 0xD1_usbhub!PdoExt+1f Followup: MachineOwner - questo è quello dell'ultimo riavvio, è sempre la ram? |
![]() |
![]() |
![]() |
#22 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
non è la ram ma sembra un conflitto del driver usb.
Probabilmente si è verificata una concorrenza tra usbhub e parport (che si occupa della porta parallela)
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#23 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
mamma che casini che ha sto pc, da quando ho messo vista.
|
![]() |
![]() |
![]() |
#24 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
ora c'è scritto questo dp l'ultimo riavvio...
Microsoft (R) Windows Debugger Version 6.8.0004.0 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Windows\Minidump\Mini032008-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 6000.16575.x86fre.vista_gdr.071009-1548 Kernel base = 0x81c00000 PsLoadedModuleList = 0x81d11e10 Debug session time: Thu Mar 20 10:29:00.342 2008 (GMT+1) System Uptime: 0 days 0:06:23.094 Loading Kernel Symbols ............................................................................................................................................................ Loading User Symbols Loading unloaded module list ..... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck A, {63de900, 1b, 1, 81ca90b0} Probably caused by : ntkrpamp.exe ( nt!KiUnwaitThread+19 ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: 063de900, memory referenced Arg2: 0000001b, IRQL Arg3: 00000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status) Arg4: 81ca90b0, address which referenced memory Debugging Details: ------------------ OVERLAPPED_MODULE: Address regions for 'cdfs' and 'parport.sys' overlap WRITE_ADDRESS: GetPointerFromAddress: unable to read from 81d315ac Unable to read MiSystemVaType memory at 81d117e0 063de900 CURRENT_IRQL: 1b FAULTING_IP: nt!KiUnwaitThread+19 81ca90b0 890a mov dword ptr [edx],ecx CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xA PROCESS_NAME: wmpnetwk.exe IRP_ADDRESS: 00313b68 TRAP_FRAME: 989cfaa4 -- (.trap 0xffffffff989cfaa4) ErrCode = 00000002 eax=83f44808 ebx=8530ccd0 ecx=863de900 edx=063de900 esi=8520d030 edi=8530ccc8 eip=81ca90b0 esp=989cfb18 ebp=989cfb2c iopl=0 nv up ei pl nz na po nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202 nt!KiUnwaitThread+0x19: 81ca90b0 890a mov dword ptr [edx],ecx ds:0023:063de900=???????? Resetting default scope LAST_CONTROL_TRANSFER: from 81ca90b0 to 81c8fd84 STACK_TEXT: 989cfaa4 81ca90b0 badb0d00 063de900 864ba3b8 nt!KiTrap0E+0x2ac 989cfb2c 81cb0ec3 00000000 989c403c 85313ba8 nt!KiUnwaitThread+0x19 989cfb7c 81cb1302 00313ba8 989cfba8 989cfbb4 nt!IopCompleteRequest+0x51e 989cfbd4 81cac9ea 00000000 00000000 00000000 nt!KiDeliverApc+0xce 989cfc1c 81cad431 864ba3b8 989cfd08 866ac5f0 nt!KiSwapThread+0x3a4 989cfc68 81d8b982 85209d10 989cfc01 00000001 nt!KeRemoveQueueEx+0x568 989cfcc0 81c7a036 85209d10 989cfcf8 989cfd20 nt!IoRemoveIoCompletion+0x23 989cfd54 81c8caaa 000001e8 01b4fd48 01b4fdcc nt!NtWaitForWorkViaWorkerFactory+0x1a1 989cfd54 77ac0f34 000001e8 01b4fd48 01b4fdcc nt!KiFastCallEntry+0x12a WARNING: Frame IP not in any known module. Following frames may be wrong. 01b4fdcc 00000000 00000000 00000000 00000000 0x77ac0f34 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiUnwaitThread+19 81ca90b0 890a mov dword ptr [edx],ecx SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!KiUnwaitThread+19 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrpamp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 470c2f52 FAILURE_BUCKET_ID: 0xA_W_nt!KiUnwaitThread+19 BUCKET_ID: 0xA_W_nt!KiUnwaitThread+19 Followup: MachineOwner --------- |
![]() |
![]() |
![]() |
#25 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
il problema dovrebbe essere causato da wmpnetwk.exe che è un servizio installato con wmp11 che serve a condividere i file multimediali in una rete.
Puoi tranquillamente disabilitarlo cliccando sui start -> esegui: services.msc Fai doppio click su Servizio di condivisione in rete Windows Media Player, arresta il servizio e imposta il tipo di avvio su manuale o disabilitato. ![]()
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#26 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
caspita ma ogni problema si riavvia sto pc...
|
![]() |
![]() |
![]() |
#27 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
vuol dire che c'è dell'hw difettoso, la colpa non è di vista.
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#28 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
a sapere quale sia posso cambiarlo, da dove si puo vedere? ke test posso fare?se mi aiuti te ne sarò grato
|
![]() |
![]() |
![]() |
#29 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
se, ha avuto problemi windows media player, escludendo la ram, i primi indagati sono la scheda audio e quella video o anche qualche accessorio collegato a usb che sfrutti la multimedialità e che potrebbe creare un conflitto.
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#30 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
ma nn mi pare di aver avuto problemi con windows media player
|
![]() |
![]() |
![]() |
#31 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
intanto il processo dell'ultimo errore che hai postato era un processo di wmp, l'hai disabilitato come ti ho detto ?
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#32 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
ho messo avvio manuale come dicevi
|
![]() |
![]() |
![]() |
#33 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
altro riavvio...
Microsoft (R) Windows Debugger Version 6.8.0004.0 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Windows\Minidump\Mini032208-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 6000.16575.x86fre.vista_gdr.071009-1548 Kernel base = 0x81c00000 PsLoadedModuleList = 0x81d11e10 Debug session time: Sat Mar 22 09:54:01.494 2008 (GMT+1) System Uptime: 0 days 0:10:23.204 Loading Kernel Symbols ............................................................................................................................................................. Loading User Symbols Loading unloaded module list ..... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, b9abd8d, 8bfdb9c4, 0} Probably caused by : tdx.sys ( tdx!TdxDeactivateTransportAddress+137 ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Some common problems are exception code 0x80000003. This means a hard coded breakpoint or assertion was hit, but this system was booted /NODEBUG. This is not supposed to happen as developers should never have hardcoded breakpoints in retail code, but ... If this happens, make sure a debugger gets connected, and the system is booted /DEBUG. This will let us see why this breakpoint is happening. Arguments: Arg1: c0000005, The exception code that was not handled Arg2: 0b9abd8d, The address that the exception occurred at Arg3: 8bfdb9c4, Trap Frame Arg4: 00000000 Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: +b9abd8d 0b9abd8d ?? ??? TRAP_FRAME: 8bfdb9c4 -- (.trap 0xffffffff8bfdb9c4) ErrCode = 00000010 eax=841cc800 ebx=841cc800 ecx=00000000 edx=00000004 esi=841cc7c0 edi=00000000 eip=0b9abd8d esp=8bfdba38 ebp=8bfdba40 iopl=0 nv up ei pl zr na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246 0b9abd8d ?? ??? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x8E PROCESS_NAME: System CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from 8b9d00ea to 0b9abd8d STACK_TEXT: WARNING: Frame IP not in any known module. Following frames may be wrong. 8bfdba34 8b9d00ea 841cc7c0 8bfdba54 8b9abd82 0xb9abd8d 8bfdba40 8b9abd82 841cc800 841cc9a0 81c47827 tcpip!WfpAleDecrementWaitRef+0x65 8bfdba54 8b9a40ab 841cc7c0 83fbf090 00000000 tcpip!WfpAleEndpointTeardownHandler+0x7e 8bfdba6c 8b9a4169 841cc9e4 8bfdba88 8b9a4028 tcpip!TcpCleanupEndpointWorkQueueRoutine+0x77 8bfdba78 8b9a4028 841cc9a0 841cc9a0 8bfdba9c tcpip!TcpCleanupEndpoint+0x1e 8bfdba88 8b9a4243 841cc9a0 00000000 83fbf098 tcpip!TcpDereferenceEndpoint+0x1c 8bfdba9c 8b9a4d84 841cc9a0 8bfdbae8 8bfdbb04 tcpip!TcpCloseEndpoint+0xc1 8bfdbaac 8b93e319 841cc9a0 8bfdbae8 83fbf090 tcpip!TcpTlEndpointCloseEndpoint+0x10 8bfdbb04 8b93e559 83fbf090 00000000 863aacc8 tdx!TdxDeactivateTransportAddress+0x137 8bfdbb18 8b944c1d 83fbf090 85dc4008 863aacc8 tdx!TdxDeleteTransportAddress+0x23 8bfdbb30 81c27f83 85dba268 863aacc8 863aacd8 tdx!TdxTdiDispatchCleanup+0x43 8bfdbb48 81d94e62 83656ab0 8367fbf0 00000001 nt!IofCallDriver+0x63 8bfdbb8c 81df328b 83656ab0 83e7f128 0012019f nt!IopCloseFile+0x386 8bfdbbdc 81df1676 83656ab0 0067fbf0 0012019f nt!ObpDecrementHandleCount+0x14c 8bfdbc2c 81df1718 88200188 9ccf39e0 83656ab0 nt!ObpCloseHandleTableEntry+0x23a 8bfdbc5c 81df180a 83656ab0 00000000 00000000 nt!ObpCloseHandle+0x73 8bfdbc70 81c8caaa 80000cf0 8bfdbd00 81c7e081 nt!NtClose+0x20 8bfdbc70 81c7e081 80000cf0 8bfdbd00 81c7e081 nt!KiFastCallEntry+0x12a 8bfdbcec 8b8d02ff 80000cf0 8655fda8 8b8cef0c nt!ZwClose+0x11 8bfdbd00 8b8aeb54 8655fda8 8b8cef08 8655fdf4 netbt!NbtTdiCloseAddress+0x30 8bfdbd14 8b8ae5dd 00000000 8655fda8 00000000 netbt!DelayedWipeOutLowerconn+0x2a 8bfdbd44 81c78fa0 8b8cef1c 00000000 85213d78 netbt!NTExecuteWorker+0x6a 8bfdbd7c 81e254e0 8b8cef1c 8bfd0680 00000000 nt!ExpWorkerThread+0xfd 8bfdbdc0 81c9159e 81c78ea3 80000000 00000000 nt!PspSystemThreadStartup+0x9d 00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16 STACK_COMMAND: kb FOLLOWUP_IP: tdx!TdxDeactivateTransportAddress+137 8b93e319 3d03010000 cmp eax,103h SYMBOL_STACK_INDEX: 8 SYMBOL_NAME: tdx!TdxDeactivateTransportAddress+137 FOLLOWUP_NAME: MachineOwner MODULE_NAME: tdx IMAGE_NAME: tdx.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4549b2fe FAILURE_BUCKET_ID: 0x8E_tdx!TdxDeactivateTransportAddress+137 BUCKET_ID: 0x8E_tdx!TdxDeactivateTransportAddress+137 Followup: MachineOwner --------- |
![]() |
![]() |
![]() |
#34 |
Senior Member
Iscritto dal: Oct 2007
Città: Roma
Messaggi: 9797
|
io direi però di provare a vedere se levando un blocco di ram l'errore si presenta ancora oppure no... prova prima uno poi l'altro modulo.
|
![]() |
![]() |
![]() |
#35 |
Senior Member
Iscritto dal: Dec 2007
Messaggi: 4282
|
Il tuo sistema non sembra aggiornato con le ultime patch, perchè il numero di versione del kernel deve essere "Built by: 6000.16584" e non 16575 (c:\windows\system32\ntoskrnl.exe)
Ultima modifica di yeppala : 22-03-2008 alle 09:13. |
![]() |
![]() |
![]() |
#36 |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
ti direi di fare un controllo per verificare che non possa essere stato infettato da
rustock http://www.symantec.com/security_res...412-99&tabid=2 altrimenti è un problema di modem
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
![]() |
![]() |
![]() |
#37 |
Senior Member
Iscritto dal: Oct 2007
Città: Roma
Messaggi: 9797
|
ah ricorda che i modem usb a volte provocano schermate blu. se il modem che usi va anche col cavo ethernet usa quello al posto dell'usb, potrebbe già risolversi.
|
![]() |
![]() |
![]() |
#38 | |
Senior Member
Iscritto dal: Oct 2005
Città: Palermo
Messaggi: 2579
|
Quote:
![]() ![]()
__________________
Utente gran figlio di Jobs ed in via di ubuntizzazione Lippi, perchè non hai convocato loro ? |
|
![]() |
![]() |
![]() |
#39 |
Senior Member
Iscritto dal: Oct 2007
Città: Roma
Messaggi: 9797
|
|
![]() |
![]() |
![]() |
#40 |
Senior Member
Iscritto dal: Apr 2007
Messaggi: 2003
|
aspettate ragazzi, una cosa alla volta, il pc in questione è un notebook, quindi nn saprei proprio cm fare x levare una ram, seconda cosa windows update è sempre attivo e se faccio cerca agg non ne trova ora, terza cosa cosa bisogna fare x vedere se si è infetti da quel trojan?, quarta cosa uso un router e mi collego wifi a internet
|
![]() |
![]() |
![]() |
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 04:11.