Problema con pantallazo azul

30/10/2005 - 20:19 por Franco Castro | Informe spam
Tengo problemas con windows, tengo xp pro, y me da pantalazos azules a cada
rato, aqui tengo el dump de la memoria, no estoy seguro, pero parece ser que
es por culpa del mcafee,

Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\MEMORY2.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is:
SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86
compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Oct 30 06:11:27.250 2005 (GMT-7)
System Uptime: 0 days 3:59:10.723
Loading Kernel Symbols

Loading unloaded module list

Loading User Symbols

*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 50, {ffffffe8, 0, f76c2533, 0}

*** ERROR: Module load completed but symbols could not be loaded for
NaiFiltr.sys
*** WARNING: Unable to verify checksum for mcscan32.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
mcscan32.dll -
*** WARNING: Unable to verify checksum for mcvsctl.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
mcvsctl.dll -
Probably caused by : hardware ( NaiFiltr+3def )

Followup: MachineOwner


1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or
it
is pointing at freed memory.
Arguments:
Arg1: ffffffe8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: f76c2533, If non-zero, the instruction address which referenced the
bad memory
address.
Arg4: 00000000, (reserved)

Debugging Details:



READ_ADDRESS: ffffffe8

FAULTING_IP:
Ntfs!NtfsCommonQueryVolumeInfo+3d
f76c2533 0857e8 or [edi-0x18],dl

MM_INTERNAL_CODE: 0

IMAGE_NAME: hardware

DEBUG_FLR_IMAGE_TIMESTAMP: 0

FAULTING_MODULE: f769c000 Ntfs

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

LAST_CONTROL_TRANSFER: from f76c2656 to f76c2533

MISALIGNED_IP:
Ntfs!NtfsCommonQueryVolumeInfo+3d
f76c2533 0857e8 or [edi-0x18],dl

TRAP_FRAME: a894d9e4 -- (.trap ffffffffa894d9e4)
ErrCode = 00000000
eax…364550 ebx…57a958 ecx=a894da90 edx…626590 esi…626744 edi000000
eip=f76c2533 esp=a894da58 ebp=a894dab4 iopl=0 nv up ei ng nz ac pe nc
cs08 ss10 ds23 es23 fs30 gs00 efl010292
Ntfs!NtfsCommonQueryVolumeInfo+0x3d:
f76c2533 0857e8 or [edi-0x18],dl ds:0023:ffffffe8=??
Resetting default scope

STACK_TEXT:
a894dab4 f76c2656 a894db2c 85626590 85626744
Ntfs!NtfsCommonQueryVolumeInfo+0x3d
a894db18 f76c24ed a894db2c 85626590 00000001 Ntfs!NtfsFsdDispatchSwitch+0xc0
a894dc3c 804e13d9 8632c020 85626590 86377440 Ntfs!NtfsFsdDispatchWait+0x1c
a894dc4c f7740459 a894dc90 804e13d9 863c6020 nt!IopfCallDriver+0x31
a894dc54 804e13d9 863c6020 85626590 857d8e08 sr!SrPassThrough+0x31
a894dc64 f7c22def 857acfb8 85fa9d78 85626590 nt!IopfCallDriver+0x31
WARNING: Stack unwind information not available. Following frames may be
wrong.
a894dc90 f7c2335b 857d8e08 85626590 804e13d9 NaiFiltr+0x3def
a894dcc0 8057d8d0 857d8e08 85626590 85364550 NaiFiltr+0x435b
a894dd48 804dd99f 000075ac 02fce900 027cefa8
nt!NtQueryVolumeInformationFile+0x3b8
a894dd48 7c91eb94 000075ac 02fce900 027cefa8 nt!KiFastCallEntry+0xfc
02fce8bc 7c91e234 7c80fd4b 000075ac 02fce900 ntdll!KiFastSystemCallRet
02fce8c0 7c80fd4b 000075ac 02fce900 027cefa8
ntdll!NtQueryVolumeInformationFile+0xc
02fce954 7c82713b 7ffd7c00 001a4be8 000002d0
kernel32!GetVolumeInformationW+0x235
02fce9dc 12009091 02fceb78 02fcea10 00000168
kernel32!GetVolumeInformationA+0xf0
02fcefbc 12004ebf 03161770 031612f0 03161758
mcscan32!RetrieveSingleExtensionList+0x4971
02fcefe4 12008ee3 02fcf010 ffffffff 031612f0
mcscan32!RetrieveSingleExtensionList+0x79f
02fcf188 12008acf 031612f0 69686300 20736f76
mcscan32!RetrieveSingleExtensionList+0x47c3
02fcf2fc 12016e13 02fcfaf4 01a7ad18 01a790d8
mcscan32!RetrieveSingleExtensionList+0x43af
02fcf314 12016eeb 01a790b8 01a7aa30 0217d010
mcscan32!RetrieveSingleExtensionList+0x126f3
02fcf33c 12016eeb 01a790b8 01a7aba0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf364 12016eeb 01a790b8 01a7b160 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf38c 12016eeb 01a790b8 01a7b5c0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf3b4 12016eeb 01a790b8 01a79460 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf3dc 12016eeb 01a790b8 01a795d0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf404 12016eeb 01a790b8 01a79740 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf42c 12016eeb 01a790b8 01a79ba0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf454 12016eeb 01a790b8 01a780f0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf47c 12016eeb 01a790b8 01a78550 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf4a4 12016ca6 01a790b8 01a789b0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf64c 120125b8 01a790b8 0217d010 01a79120
mcscan32!RetrieveSingleExtensionList+0x12586
02fcf6dc 120044dc 01a79120 7c920732 7c9206ab
mcscan32!RetrieveSingleExtensionList+0xde98
02fcfee0 019b3084 01a37478 02fcff34 02fcff50 mcscan32!AVScanObject+0x57c
02fcfef4 019d7c66 01a02e44 02fcff34 02fcff50
mcvsctl!CEngineInstance::AVScanObject+0x25
02fcffa8 019d47a3 02fcffb0 02fcffec 7c80b50b mcvsctl!DllCanUnloadNow+0x2134
02fcffb4 7c80b50b 01a03728 7c920732 7c9206ab
mcvsctl!AddQuarantineItem2+0x1867f
02fcffec 00000000 019d4794 01a03728 00000000 kernel32!BaseThreadStart+0x37


FOLLOWUP_IP:
NaiFiltr+3def
f7c22def 5f pop edi

SYMBOL_STACK_INDEX: 6

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: NaiFiltr+3def

MODULE_NAME: hardware

STACK_COMMAND: .trap ffffffffa894d9e4 ; kb

FAILURE_BUCKET_ID: IP_MISALIGNED

BUCKET_ID: IP_MISALIGNED

Followup: MachineOwner



muchas gracias a todo =)

Preguntas similare

Leer las respuestas

#1 Enrique [MVP Windows]
30/10/2005 - 20:40 | Informe spam
¿Utilizas el antivirus y/o firewall de McAfee?



Saludos,
Enrique Cortés
Microsoft MVP - Windows - IE/OE
(quita la Z)

"Existe al menos un rincón del universo que con
toda seguridad puedes mejorar, y eres tú mismo".

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.
This posting is provided "AS IS" with no warranties, and confers no
rights.
________________________________________________________________________________
"Franco Castro" <Franco escribió en el
mensaje news:
Tengo problemas con windows, tengo xp pro, y me da pantalazos azules a
cada
rato, aqui tengo el dump de la memoria, no estoy seguro, pero parece ser
que
es por culpa del mcafee,

Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\MEMORY2.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is:
SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86
compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Sun Oct 30 06:11:27.250 2005 (GMT-7)
System Uptime: 0 days 3:59:10.723
Loading Kernel Symbols
...
Loading unloaded module list

Loading User Symbols
...
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 50, {ffffffe8, 0, f76c2533, 0}

*** ERROR: Module load completed but symbols could not be loaded for
NaiFiltr.sys
*** WARNING: Unable to verify checksum for mcscan32.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
mcscan32.dll -
*** WARNING: Unable to verify checksum for mcvsctl.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
mcvsctl.dll -
Probably caused by : hardware ( NaiFiltr+3def )

Followup: MachineOwner


1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain
bad or
it
is pointing at freed memory.
Arguments:
Arg1: ffffffe8, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: f76c2533, If non-zero, the instruction address which referenced
the
bad memory
address.
Arg4: 00000000, (reserved)

Debugging Details:



READ_ADDRESS: ffffffe8

FAULTING_IP:
Ntfs!NtfsCommonQueryVolumeInfo+3d
f76c2533 0857e8 or [edi-0x18],dl

MM_INTERNAL_CODE: 0

IMAGE_NAME: hardware

DEBUG_FLR_IMAGE_TIMESTAMP: 0

FAULTING_MODULE: f769c000 Ntfs

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

LAST_CONTROL_TRANSFER: from f76c2656 to f76c2533

MISALIGNED_IP:
Ntfs!NtfsCommonQueryVolumeInfo+3d
f76c2533 0857e8 or [edi-0x18],dl

TRAP_FRAME: a894d9e4 -- (.trap ffffffffa894d9e4)
ErrCode = 00000000
eax…364550 ebx…57a958 ecx¨94da90 edx…626590 esi…626744
edi000000
eip÷6c2533 esp¨94da58 ebp¨94dab4 iopl=0 nv up ei ng nz ac
pe nc
cs08 ss10 ds23 es23 fs30 gs00
efl010292
Ntfs!NtfsCommonQueryVolumeInfo+0x3d:
f76c2533 0857e8 or [edi-0x18],dl
ds:0023:ffffffe8=??
Resetting default scope

STACK_TEXT:
a894dab4 f76c2656 a894db2c 85626590 85626744
Ntfs!NtfsCommonQueryVolumeInfo+0x3d
a894db18 f76c24ed a894db2c 85626590 00000001
Ntfs!NtfsFsdDispatchSwitch+0xc0
a894dc3c 804e13d9 8632c020 85626590 86377440
Ntfs!NtfsFsdDispatchWait+0x1c
a894dc4c f7740459 a894dc90 804e13d9 863c6020 nt!IopfCallDriver+0x31
a894dc54 804e13d9 863c6020 85626590 857d8e08 sr!SrPassThrough+0x31
a894dc64 f7c22def 857acfb8 85fa9d78 85626590 nt!IopfCallDriver+0x31
WARNING: Stack unwind information not available. Following frames may be
wrong.
a894dc90 f7c2335b 857d8e08 85626590 804e13d9 NaiFiltr+0x3def
a894dcc0 8057d8d0 857d8e08 85626590 85364550 NaiFiltr+0x435b
a894dd48 804dd99f 000075ac 02fce900 027cefa8
nt!NtQueryVolumeInformationFile+0x3b8
a894dd48 7c91eb94 000075ac 02fce900 027cefa8 nt!KiFastCallEntry+0xfc
02fce8bc 7c91e234 7c80fd4b 000075ac 02fce900 ntdll!KiFastSystemCallRet
02fce8c0 7c80fd4b 000075ac 02fce900 027cefa8
ntdll!NtQueryVolumeInformationFile+0xc
02fce954 7c82713b 7ffd7c00 001a4be8 000002d0
kernel32!GetVolumeInformationW+0x235
02fce9dc 12009091 02fceb78 02fcea10 00000168
kernel32!GetVolumeInformationA+0xf0
02fcefbc 12004ebf 03161770 031612f0 03161758
mcscan32!RetrieveSingleExtensionList+0x4971
02fcefe4 12008ee3 02fcf010 ffffffff 031612f0
mcscan32!RetrieveSingleExtensionList+0x79f
02fcf188 12008acf 031612f0 69686300 20736f76
mcscan32!RetrieveSingleExtensionList+0x47c3
02fcf2fc 12016e13 02fcfaf4 01a7ad18 01a790d8
mcscan32!RetrieveSingleExtensionList+0x43af
02fcf314 12016eeb 01a790b8 01a7aa30 0217d010
mcscan32!RetrieveSingleExtensionList+0x126f3
02fcf33c 12016eeb 01a790b8 01a7aba0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf364 12016eeb 01a790b8 01a7b160 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf38c 12016eeb 01a790b8 01a7b5c0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf3b4 12016eeb 01a790b8 01a79460 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf3dc 12016eeb 01a790b8 01a795d0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf404 12016eeb 01a790b8 01a79740 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf42c 12016eeb 01a790b8 01a79ba0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf454 12016eeb 01a790b8 01a780f0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf47c 12016eeb 01a790b8 01a78550 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf4a4 12016ca6 01a790b8 01a789b0 0217d010
mcscan32!RetrieveSingleExtensionList+0x127cb
02fcf64c 120125b8 01a790b8 0217d010 01a79120
mcscan32!RetrieveSingleExtensionList+0x12586
02fcf6dc 120044dc 01a79120 7c920732 7c9206ab
mcscan32!RetrieveSingleExtensionList+0xde98
02fcfee0 019b3084 01a37478 02fcff34 02fcff50 mcscan32!AVScanObject+0x57c
02fcfef4 019d7c66 01a02e44 02fcff34 02fcff50
mcvsctl!CEngineInstance::AVScanObject+0x25
02fcffa8 019d47a3 02fcffb0 02fcffec 7c80b50b
mcvsctl!DllCanUnloadNow+0x2134
02fcffb4 7c80b50b 01a03728 7c920732 7c9206ab
mcvsctl!AddQuarantineItem2+0x1867f
02fcffec 00000000 019d4794 01a03728 00000000
kernel32!BaseThreadStart+0x37


FOLLOWUP_IP:
NaiFiltr+3def
f7c22def 5f pop edi

SYMBOL_STACK_INDEX: 6

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: NaiFiltr+3def

MODULE_NAME: hardware

STACK_COMMAND: .trap ffffffffa894d9e4 ; kb

FAILURE_BUCKET_ID: IP_MISALIGNED

BUCKET_ID: IP_MISALIGNED

Followup: MachineOwner



muchas gracias a todo =)
email Siga el debate Respuesta Responder a este mensaje
Ads by Google
Help Hacer una preguntaRespuesta Tengo una respuesta
Search Busqueda sugerida