Twitter iPhone pliant OnePlus 11 PS5 Disney+ Orange Livebox Windows 11

Vidage mémoire.

1 réponse
Avatar
Tintin
Bonjour.Mon ordinateur affiche un écran bleu et m'affiche vidage mémoire. on
m'a dit d'indiquer ce qu'il y avait Dans drwatson32 (il y en avait 4 comme
ça mais j'avais pas assez de
place))
Une exception d'application s'est produite :
App : C:\WINDOWS\system32\ntvdm.exe (pid=2856)
Lorsque : 05/05/2005 @ 12:22:20.781
Numéro d'exception : c0000005 (violation d'accès)

*----> Informations système <----*
Nom ordinateur : CHAMBRE
Nom utilisateur : Désio Valentin
ID de la session Terminal : 0
Nombre de processeurs : 1
Type de processeur : x86 Family 6 Model 10 Stepping 0
Version de Windows : 5.1
Numéro actuel : 2600
Service Pack : 2
Type actuel : Uniprocessor Free
Organisation enregistrée :
Propriétaire enregistré :

*----> Liste des tâches <----*
0 System Process
4 System
560 smss.exe
796 csrss.exe
820 winlogon.exe
864 services.exe
876 lsass.exe
1028 svchost.exe
1080 svchost.exe
1120 svchost.exe
1208 svchost.exe
1300 svchost.exe
1576 spoolsv.exe
1692 navapsvc.exe
1844 wlancfg.exe
404 alg.exe
1780 Explorer.EXE
840 RunDll32.exe
1356 navapw32.exe
284 Seticon.exe
640 wuauclt.exe
2856 ntvdm.exe
2768 wuauclt.exe
3072 dwwin.exe
3296 drwtsn32.exe

*----> Liste des modules <----*
(000000000f000000 - 000000000f0a7000: C:\WINDOWS\system32\ntvdm.exe
(000000000ffa0000 - 000000000ffa6000: C:\WINDOWS\system32\VCDEX.DLL
(0000000010000000 - 0000000010013000: C:\PROGRA~1\Symantec\S32EVNT1.DLL
(0000000058b50000 - 0000000058be7000: C:\WINDOWS\system32\comctl32.dll
(000000005f4d0000 - 000000005f4d7000: C:\WINDOWS\system32\NTVDMD.DLL
(0000000072c60000 - 0000000072c68000: C:\WINDOWS\system32\msacm32.drv
(0000000072c70000 - 0000000072c79000: C:\WINDOWS\system32\wdmaud.drv
(0000000076ae0000 - 0000000076b0f000: C:\WINDOWS\system32\WINMM.DLL
(0000000076be0000 - 0000000076c0e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c40000 - 0000000076c68000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000077390000 - 0000000077492000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000779e0000 - 0000000077a76000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077a80000 - 0000000077a92000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b50000 - 0000000077b72000: C:\WINDOWS\system32\Apphelp.dll
(0000000077ba0000 - 0000000077ba7000: C:\WINDOWS\system32\midimap.dll
(0000000077bb0000 - 0000000077bc5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d10000 - 0000000077da0000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e4c000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077ef0000 - 0000000077f36000: C:\WINDOWS\system32\GDI32.dll
(0000000077f40000 - 0000000077fb6000: C:\WINDOWS\system32\SHLWAPI.dll
(000000007c800000 - 000000007c904000: C:\WINDOWS\system32\kernel32.dll
(000000007c910000 - 000000007c9c7000: C:\WINDOWS\system32\ntdll.dll

*----> Vidage de l'état de la thread 0xb3c <----*

eax=02981000 ebx=0f077460 ecx=0205fdc8 edx=00001000 esi=027527c8 edi=00000046
eip=0f05060b esp=0205fdb0 ebp=0205fdc0 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntvdm.exe -
fonction : ntvdm!SetShadowDescriptorEntries
0f0505ee 50 push eax
0f0505ef 8d4508 lea eax,[ebp+0x8]
0f0505f2 50 push eax
0f0505f3 6a03 push 0x3
0f0505f5 e8d94c0000 call ntvdm!SetShadowDescriptorEntries+0x5630
(0f0552d3)
0f0505fa 85c0 test eax,eax
0f0505fc 747c jz ntvdm!SetShadowDescriptorEntries+0x9d7
(0f05067a)
0f0505fe 66833db8c0090f00 cmp word ptr [ntvdm!pDeviceChain+0x360
(0f09c0b8)],0x0
0f050606 8b4508 mov eax,[ebp+0x8]
0f050609 742e jz ntvdm!SetShadowDescriptorEntries+0x996
(0f050639)
FAUTE ->0f05060b 8978fc mov [eax-0x4],edi
ds:0023:02980ffc=????????
0f05060e 0fb786bc000000 movzx eax,word ptr [esi+0xbc]
0f050615 8b4d08 mov ecx,[ebp+0x8]
0f050618 8941f8 mov [ecx-0x8],eax
0f05061b 8b5508 mov edx,[ebp+0x8]
0f05061e 8d86b8000000 lea eax,[esi+0xb8]
0f050624 8b08 mov ecx,[eax]
0f050626 894af4 mov [edx-0xc],ecx
0f050629 8b4b04 mov ecx,[ebx+0x4]
0f05062c 8908 mov [eax],ecx
0f05062e 8b45fc mov eax,[ebp-0x4]

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0205fdc0 0f0546fd 02981000 00020000 027524f0
ntvdm!SetShadowDescriptorEntries+0x968
0205fdf8 0f004e7c 0f00534e 00000000 00003046
ntvdm!SetShadowDescriptorEntries+0x4a5a
0205fe18 0f054c30 00000003 027527c8 00000000 ntvdm!Sim32pGetVDMPointer+0x77
0205fe6c 0f051117 00003002 0f051645 00020000
ntvdm!SetShadowDescriptorEntries+0x4f8d
0205fea0 0f01a4bd 00000a28 0205fee4 0f00ccf5
ntvdm!SetShadowDescriptorEntries+0x1474
0205feac 0f00ccf5 00000003 02750b28 00000094 ntvdm!setCL+0xabf
0205fee4 0f00f4c2 00000003 02750b28 02750b68 ntvdm!setDI+0x180b
0205ffc0 7c816d4f 0069006c 00610063 7ffda000 ntvdm!IsCdRomFile+0x1103
0205fff0 00000000 0f00f34c 00000000 78746341
kernel32!RegisterWaitForInputIdle+0x49

*----> Vidage brut de la pile <----*
000000000205fdb0 08 00 00 00 f0 24 75 02 - 00 00 00 00 f4 0f 00 00
.....$u.........
000000000205fdc0 f8 fd 05 02 fd 46 05 0f - 00 10 98 02 00 00 02 00
.....F..........
000000000205fdd0 f0 24 75 02 00 00 00 00 - d1 80 00 00 12 09 00 00
.$u.............
000000000205fde0 1b 50 a7 00 a7 00 a7 00 - 00 00 00 00 a6 d8 00 00
.P..............
000000000205fdf0 d3 05 00 00 00 00 00 00 - 18 fe 05 02 7c 4e 00 0f
............|N..
000000000205fe00 4e 53 00 0f 00 00 00 00 - 46 30 00 00 c8 27 75 02
NS......F0...'u.
000000000205fe10 4e 4b 02 00 00 00 00 00 - 6c fe 05 02 30 4c 05 0f
NK......l...0L..
000000000205fe20 03 00 00 00 c8 27 75 02 - 00 00 00 00 02 03 00 00
.....'u.........
000000000205fe30 00 00 00 00 00 00 00 00 - af 01 00 00 54 4b 00 00
............TK..
000000000205fe40 88 00 01 00 4c 4e af 02 - 54 09 00 00 8c 4d 00 00
....LN..T....M..
000000000205fe50 46 30 00 00 67 02 7f 02 - 7f 01 af 01 00 00 7f 01
F0..g...........
000000000205fe60 8c 4d 00 00 00 00 00 00 - d4 ba 00 00 a0 fe 05 02
.M..............
000000000205fe70 17 11 05 0f 02 30 00 00 - 45 16 05 0f 00 00 02 00
.....0..E.......
000000000205fe80 f0 24 75 02 7c 4e 00 0f - 4e 53 00 0f 94 00 00 00
.$u.|N..NS......
000000000205fe90 28 0b 75 02 00 a0 fd 7f - d1 80 00 00 00 00 00 00
(.u.............
000000000205fea0 ac fe 05 02 bd a4 01 0f - 28 0a 00 00 e4 fe 05 02
........(.......
000000000205feb0 f5 cc 00 0f 03 00 00 00 - 28 0b 75 02 94 00 00 00
........(.u.....
000000000205fec0 28 0a 00 00 00 a0 fd 7f - ff ff ff ff bc fe 05 02
(...............
000000000205fed0 d4 f9 05 02 b0 ff 05 02 - f8 b5 01 0f 30 16 00 0f
............0...
000000000205fee0 00 00 00 00 c0 ff 05 02 - c2 f4 00 0f 03 00 00 00
................

*----> Vidage de l'état de la thread 0x4c8 <----*

eax=027aff18 ebx=00000000 ecx=00000000 edx=027aff28 esi=027aff14 edi=00000000
eip=7c91eb94 esp=027afeec ebp=027aff84 iopl=0 vif nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00080246

*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntdll.dll -
fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
027aff84 0f03b788 03010301 03010301 00000000 ntdll!KiFastSystemCallRet
027affb4 7c80b50b 00000000 03010301 03010301 ntvdm!host_simulate+0x61bd
027affec 00000000 0f03b759 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
00000000027afeec ab e9 91 7c f8 b5 03 0f - 02 00 00 00 78 ff 7a 02
...|........x.z.
00000000027afefc 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
................
00000000027aff0c 01 03 01 03 00 00 00 00 - 10 00 00 00 00 00 00 00
................
00000000027aff1c 00 00 00 00 00 00 00 00 - ab e9 91 7c 02 00 af 75
...........|...u
00000000027aff2c 4f 00 15 00 01 00 00 00 - 20 00 00 00 00 00 00 00
O....... .......
00000000027aff3c 08 00 d4 77 16 01 00 00 - 67 04 d4 77 e0 88 d1 77
...w....g..w...w
00000000027aff4c ff ff ff ff 08 00 d4 77 - 1f 01 00 00 67 04 d4 77
.......w....g..w
00000000027aff5c e0 88 d1 77 ff ff ff ff - 10 00 00 00 01 00 00 00
...w............
00000000027aff6c 00 00 00 00 00 00 00 00 - ab e9 91 7c 20 00 00 00
...........| ...
00000000027aff7c 50 00 00 00 01 00 00 00 - b4 ff 7a 02 88 b7 03 0f
P.........z.....
00000000027aff8c 01 03 01 03 01 03 01 03 - 00 00 00 00 ff ff ff ff
................
00000000027aff9c 8c ff 7a 02 81 a8 4f 80 - dc ff 7a 02 f8 b5 01 0f
..z...O...z.....
00000000027affac 20 25 00 0f 00 00 00 00 - ec ff 7a 02 0b b5 80 7c
%........z....|
00000000027affbc 00 00 00 00 01 03 01 03 - 01 03 01 03 00 00 00 00
................
00000000027affcc 00 e0 fd 7f 00 66 7c 81 - c0 ff 7a 02 e0 8e f6 80
.....f|...z.....
00000000027affdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
.......|...|....
00000000027affec 00 00 00 00 00 00 00 00 - 59 b7 03 0f 00 00 00 00
........Y.......
00000000027afffc 00 00 00 00 08 00 00 00 - 00 01 00 01 ee ff ee ff
................
00000000027b000c 00 00 00 00 00 00 75 02 - 00 d0 0a 00 00 00 7b 02
......u.......{.
00000000027b001c 00 01 00 00 40 00 7b 02 - 00 00 8b 02 ad 00 00 00
....@.{.........

*----> Vidage de l'état de la thread 0xe7c <----*

eax=ffffffff ebx=00000000 ecx=000006db edx=00000010 esi=7c91e99f edi=0f09b828
eip=7c91eb94 esp=028eff38 ebp=028eff68 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
028eff68 0f00dd18 0000bf1d 00000000 00000030 ntdll!KiFastSystemCallRet
028eff84 0f012046 00000000 00000030 00000000 ntvdm!setDL+0x8d
028effb4 7c80b50b 00000000 00000000 00000030 ntvdm!setAH+0x4cd
028effec 00000000 0f011fdf 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
00000000028eff38 ab e9 91 7c 0a 43 00 0f - 02 00 00 00 28 b8 09 0f
...|.C......(...
00000000028eff48 01 00 00 00 01 00 00 00 - 60 ff 8e 02 8d d6 00 00
........`.......
00000000028eff58 1d bf 00 00 00 00 00 00 - de 88 f8 ff ff ff ff ff
................
00000000028eff68 84 ff 8e 02 18 dd 00 0f - 1d bf 00 00 00 00 00 00
................
00000000028eff78 30 00 00 00 18 03 00 00 - c8 64 04 00 b4 ff 8e 02
0........d......
00000000028eff88 46 20 01 0f 00 00 00 00 - 30 00 00 00 00 00 00 00 F
......0.......
00000000028eff98 ff ff ff ff 8c ff 8e 02 - 81 a8 4f 80 dc ff 8e 02
..........O.....
00000000028effa8 f8 b5 01 0f e0 1f 00 0f - 00 00 00 00 ec ff 8e 02
................
00000000028effb8 0b b5 80 7c 00 00 00 00 - 00 00 00 00 30 00 00 00
...|........0...
00000000028effc8 00 00 00 00 00 d0 fd 7f - 00 66 7c 81 c0 ff 8e 02
.........f|.....
00000000028effd8 00 8f fc 80 ff ff ff ff - f3 99 83 7c 18 b5 80 7c
...........|...|
00000000028effe8 00 00 00 00 00 00 00 00 - 00 00 00 00 df 1f 01 0f
................
00000000028efff8 00 00 00 00 00 00 00 00 - c8 00 00 00 2a 01 00 00
............*...
00000000028f0008 ff ee ff ee 02 10 00 00 - 00 00 00 00 00 fe 00 00
................
00000000028f0018 00 00 10 00 00 20 00 00 - 00 02 00 00 00 20 00 00 .....
....... ..
00000000028f0028 41 00 00 00 ff ef fd 7f - 05 00 08 06 00 00 00 00
A...............
00000000028f0038 00 00 00 00 00 00 00 00 - 00 00 00 00 98 05 8f 02
................
00000000028f0048 0f 00 00 00 f8 ff ff ff - 50 00 8f 02 50 00 8f 02
........P...P...
00000000028f0058 40 06 8f 02 00 00 00 00 - 00 00 00 00 00 00 00 00
@...............
00000000028f0068 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................

*----> Vidage de l'état de la thread 0xfc0 <----*

eax=72c730e8 ebx=0317fef8 ecx=00000015 edx=02087188 esi=00000000 edi=7ffda000
eip=7c91eb94 esp=0317fed0 ebp=0317ff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
0317ff6c 7c809c86 00000002 0317ffa4 00000000 ntdll!KiFastSystemCallRet
0317ff88 72c7312a 00000002 0317ffa4 00000000
kernel32!WaitForMultipleObjects+0x18
0317ffb4 7c80b50b 00000000 00000000 02070000 wdmaud!midMessage+0x348
0317ffec 00000000 72c730e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
000000000317fed0 ab e9 91 7c f2 94 80 7c - 02 00 00 00 f8 fe 17 03
...|...|........
000000000317fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
000000000317fef0 00 00 00 00 00 00 00 00 - e0 00 00 00 dc 00 00 00
................
000000000317ff00 fe b5 01 00 bd da 4e 80 - f8 bb c7 f0 0c 86 3e c0
......N.......>.
000000000317ff10 be 47 00 00 ac b8 e8 80 - 14 00 00 00 01 00 00 00
.G..............
000000000317ff20 00 00 00 00 00 00 00 00 - 10 00 00 00 44 b7 e8 80
............D...
000000000317ff30 e1 a9 54 80 ea b5 57 80 - 00 a0 fd 7f 00 c0 fd 7f
..T...W.........
000000000317ff40 00 c0 fd 7f 00 00 00 00 - f8 fe 17 03 00 00 00 00
................
000000000317ff50 02 00 00 00 ec fe 17 03 - 00 00 00 00 dc ff 17 03
................
000000000317ff60 f3 99 83 7c 90 95 80 7c - 00 00 00 00 88 ff 17 03
...|...|........
000000000317ff70 86 9c 80 7c 02 00 00 00 - a4 ff 17 03 00 00 00 00
...|............
000000000317ff80 ff ff ff ff 00 00 00 00 - b4 ff 17 03 2a 31 c7 72
............*1.r
000000000317ff90 02 00 00 00 a4 ff 17 03 - 00 00 00 00 ff ff ff ff
................
000000000317ffa0 00 00 07 02 e0 00 00 00 - dc 00 00 00 00 00 00 00
................
000000000317ffb0 dc e2 91 7c ec ff 17 03 - 0b b5 80 7c 00 00 00 00
...|.......|....
000000000317ffc0 00 00 00 00 00 00 07 02 - 00 00 00 00 00 c0 fd 7f
................
000000000317ffd0 00 66 7c 81 c0 ff 17 03 - 20 38 72 81 ff ff ff ff
.f|..... 8r.....
000000000317ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
...|...|........
000000000317fff0 00 00 00 00 e8 30 c7 72 - 00 00 00 00 00 00 00 00
.....0.r........
0000000003180000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................

1 réponse

Avatar
le Claude
Salut Tintin,

Bien que ne sachant pas interpréter le message d'erreur, mais comme
depuis 2 jours, personne ne t'as apporté des conseils éclairés -:)) je vais
te donner quelques pistes.
Le processus défaillant ntvdm.exe est décrit ici :
http://www.commentcamarche.net/processus/ntvdm-exe.php3

Tu as plusieurs possibilités :

1-) le phénomène se produit rarement
et après ton PC retravaille normalement, c'est un logiciel (jeu, suite
bureautique etc...) qui surcharge le fonctionnement et produit un plantage ;
ce n'est en ce cas pas très grave, un augmentation de la RAM, la suppression
de certains programmes (ou leur démarrage automatique) peuvent régler le
problème.

2-) le phénomène se produit assez souvent
et là c'est plus grave, il te faut tout d'abord savoir si ce n'et pas un
programme ou un logiciel mal installé ou inadapté à XP (cf. : explications
sur NTVDM) qui est devenu "plantogène" (comme dirait JCB) ; essaye avec un
de ces 2 utilitaires qui te diront les programmes qui démarrent et à quoi
servent-ils :
Ekins : http://www.ekinox-team.com/ekinx.php
Autoruns : http://www.sysinternals.com/ntw2k/freeware/autoruns.shtml
Ensuite, partant du principe que l'écran bleu est souvent un problème de
mémoire RAM, fait un test avec l'utilitaire WinDiag de Microsoft, il est un
peu moins performant que Memtest mais est en français, avec une aide bien
faîte !
Windiag : https://oca.microsoft.com/fr/windiag.asp
Memtest : http://www.memtest.org/

Dans le cas de plantage avec écran bleu (BSOD), il se crée dans
C:Windows un fichier nommé Memory ayant la taille de ta RAM ; c'est lui qui
permet le redémarrage correct de XP, c'est dans lui que se vide la "mémoire
physique" tu peux l'effacer quand XP a redémarré.
Pendant l'écran bleu, il est important de laisser l'opération
s'effectuer jusqu'au bout si la mémoire physique n'est pas vidée à 100 %, tu
as risque d'un nouvel BSOD, donc interdiction de se servir du bouton [reset]
qui relance l'ordinateur.



Amicalement, Claude


"Tintin" a écrit dans le message de news:

Bonjour.Mon ordinateur affiche un écran bleu et m'affiche vidage mémoire.
on
m'a dit d'indiquer ce qu'il y avait Dans drwatson32 (il y en avait 4
comme
ça mais j'avais pas assez de
place))
Une exception d'application s'est produite :
App : C:WINDOWSsystem32ntvdm.exe (pid(56)
Lorsque : 05/05/2005 @ 12:22:20.781
Numéro d'exception : c0000005 (violation d'accès)

*----> Informations système <----*
Nom ordinateur : CHAMBRE
Nom utilisateur : Désio Valentin
ID de la session Terminal : 0
Nombre de processeurs : 1
Type de processeur : x86 Family 6 Model 10 Stepping 0
Version de Windows : 5.1
Numéro actuel : 2600
Service Pack : 2
Type actuel : Uniprocessor Free
Organisation enregistrée :
Propriétaire enregistré :

*----> Liste des tâches <----*
0 System Process
4 System
560 smss.exe
796 csrss.exe
820 winlogon.exe
864 services.exe
876 lsass.exe
1028 svchost.exe
1080 svchost.exe
1120 svchost.exe
1208 svchost.exe
1300 svchost.exe
1576 spoolsv.exe
1692 navapsvc.exe
1844 wlancfg.exe
404 alg.exe
1780 Explorer.EXE
840 RunDll32.exe
1356 navapw32.exe
284 Seticon.exe
640 wuauclt.exe
2856 ntvdm.exe
2768 wuauclt.exe
3072 dwwin.exe
3296 drwtsn32.exe

*----> Liste des modules <----*
(000000000f000000 - 000000000f0a7000: C:WINDOWSsystem32ntvdm.exe
(000000000ffa0000 - 000000000ffa6000: C:WINDOWSsystem32VCDEX.DLL
(0000000010000000 - 0000000010013000: C:PROGRA~1SymantecS32EVNT1.DLL
(0000000058b50000 - 0000000058be7000: C:WINDOWSsystem32comctl32.dll
(000000005f4d0000 - 000000005f4d7000: C:WINDOWSsystem32NTVDMD.DLL
(0000000072c60000 - 0000000072c68000: C:WINDOWSsystem32msacm32.drv
(0000000072c70000 - 0000000072c79000: C:WINDOWSsystem32wdmaud.drv
(0000000076ae0000 - 0000000076b0f000: C:WINDOWSsystem32WINMM.DLL
(0000000076be0000 - 0000000076c0e000: C:WINDOWSsystem32WINTRUST.dll
(0000000076c40000 - 0000000076c68000: C:WINDOWSsystem32IMAGEHLP.dll
(0000000077390000 - 0000000077492000:
C:WINDOWSWinSxSx86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9comctl32.dll
(00000000779e0000 - 0000000077a76000: C:WINDOWSsystem32CRYPT32.dll
(0000000077a80000 - 0000000077a92000: C:WINDOWSsystem32MSASN1.dll
(0000000077b50000 - 0000000077b72000: C:WINDOWSsystem32Apphelp.dll
(0000000077ba0000 - 0000000077ba7000: C:WINDOWSsystem32midimap.dll
(0000000077bb0000 - 0000000077bc5000: C:WINDOWSsystem32MSACM32.dll
(0000000077bd0000 - 0000000077bd8000: C:WINDOWSsystem32VERSION.dll
(0000000077be0000 - 0000000077c38000: C:WINDOWSsystem32msvcrt.dll
(0000000077d10000 - 0000000077da0000: C:WINDOWSsystem32USER32.dll
(0000000077da0000 - 0000000077e4c000: C:WINDOWSsystem32ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: C:WINDOWSsystem32RPCRT4.dll
(0000000077ef0000 - 0000000077f36000: C:WINDOWSsystem32GDI32.dll
(0000000077f40000 - 0000000077fb6000: C:WINDOWSsystem32SHLWAPI.dll
(000000007c800000 - 000000007c904000: C:WINDOWSsystem32kernel32.dll
(000000007c910000 - 000000007c9c7000: C:WINDOWSsystem32ntdll.dll

*----> Vidage de l'état de la thread 0xb3c <----*

eax981000 ebx077460 ecx05fdc8 edx001000 esi7527c8
edi000046
eip05060b esp05fdb0 ebp05fdc0 iopl=0 nv up ei pl nz na pe
nc
cs1b ss23 ds23 es23 fs3b gs00
efl000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:WINDOWSsystem32ntvdm.exe -
fonction : ntvdm!SetShadowDescriptorEntries
0f0505ee 50 push eax
0f0505ef 8d4508 lea eax,[ebp+0x8]
0f0505f2 50 push eax
0f0505f3 6a03 push 0x3
0f0505f5 e8d94c0000 call ntvdm!SetShadowDescriptorEntries+0x5630
(0f0552d3)
0f0505fa 85c0 test eax,eax
0f0505fc 747c jz ntvdm!SetShadowDescriptorEntries+0x9d7
(0f05067a)
0f0505fe 66833db8c0090f00 cmp word ptr [ntvdm!pDeviceChain+0x360
(0f09c0b8)],0x0
0f050606 8b4508 mov eax,[ebp+0x8]
0f050609 742e jz ntvdm!SetShadowDescriptorEntries+0x996
(0f050639)
FAUTE ->0f05060b 8978fc mov [eax-0x4],edi
ds:0023:02980ffc=????????
0f05060e 0fb786bc000000 movzx eax,word ptr [esi+0xbc]
0f050615 8b4d08 mov ecx,[ebp+0x8]
0f050618 8941f8 mov [ecx-0x8],eax
0f05061b 8b5508 mov edx,[ebp+0x8]
0f05061e 8d86b8000000 lea eax,[esi+0xb8]
0f050624 8b08 mov ecx,[eax]
0f050626 894af4 mov [edx-0xc],ecx
0f050629 8b4b04 mov ecx,[ebx+0x4]
0f05062c 8908 mov [eax],ecx
0f05062e 8b45fc mov eax,[ebp-0x4]

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:WINDOWSsystem32kernel32.dll -
ChildEBP RetAddr Args to Child
0205fdc0 0f0546fd 02981000 00020000 027524f0
ntvdm!SetShadowDescriptorEntries+0x968
0205fdf8 0f004e7c 0f00534e 00000000 00003046
ntvdm!SetShadowDescriptorEntries+0x4a5a
0205fe18 0f054c30 00000003 027527c8 00000000
ntvdm!Sim32pGetVDMPointer+0x77
0205fe6c 0f051117 00003002 0f051645 00020000
ntvdm!SetShadowDescriptorEntries+0x4f8d
0205fea0 0f01a4bd 00000a28 0205fee4 0f00ccf5
ntvdm!SetShadowDescriptorEntries+0x1474
0205feac 0f00ccf5 00000003 02750b28 00000094 ntvdm!setCL+0xabf
0205fee4 0f00f4c2 00000003 02750b28 02750b68 ntvdm!setDI+0x180b
0205ffc0 7c816d4f 0069006c 00610063 7ffda000 ntvdm!IsCdRomFile+0x1103
0205fff0 00000000 0f00f34c 00000000 78746341
kernel32!RegisterWaitForInputIdle+0x49

*----> Vidage brut de la pile <----*
000000000205fdb0 08 00 00 00 f0 24 75 02 - 00 00 00 00 f4 0f 00 00
.....$u.........
000000000205fdc0 f8 fd 05 02 fd 46 05 0f - 00 10 98 02 00 00 02 00
.....F..........
000000000205fdd0 f0 24 75 02 00 00 00 00 - d1 80 00 00 12 09 00 00
.$u.............
000000000205fde0 1b 50 a7 00 a7 00 a7 00 - 00 00 00 00 a6 d8 00 00
.P..............
000000000205fdf0 d3 05 00 00 00 00 00 00 - 18 fe 05 02 7c 4e 00 0f
............|N..
000000000205fe00 4e 53 00 0f 00 00 00 00 - 46 30 00 00 c8 27 75 02
NS......F0...'u.
000000000205fe10 4e 4b 02 00 00 00 00 00 - 6c fe 05 02 30 4c 05 0f
NK......l...0L..
000000000205fe20 03 00 00 00 c8 27 75 02 - 00 00 00 00 02 03 00 00
.....'u.........
000000000205fe30 00 00 00 00 00 00 00 00 - af 01 00 00 54 4b 00 00
............TK..
000000000205fe40 88 00 01 00 4c 4e af 02 - 54 09 00 00 8c 4d 00 00
....LN..T....M..
000000000205fe50 46 30 00 00 67 02 7f 02 - 7f 01 af 01 00 00 7f 01
F0..g...........
000000000205fe60 8c 4d 00 00 00 00 00 00 - d4 ba 00 00 a0 fe 05 02
.M..............
000000000205fe70 17 11 05 0f 02 30 00 00 - 45 16 05 0f 00 00 02 00
.....0..E.......
000000000205fe80 f0 24 75 02 7c 4e 00 0f - 4e 53 00 0f 94 00 00 00
.$u.|N..NS......
000000000205fe90 28 0b 75 02 00 a0 fd 7f - d1 80 00 00 00 00 00 00
(.u.............
000000000205fea0 ac fe 05 02 bd a4 01 0f - 28 0a 00 00 e4 fe 05 02
........(.......
000000000205feb0 f5 cc 00 0f 03 00 00 00 - 28 0b 75 02 94 00 00 00
........(.u.....
000000000205fec0 28 0a 00 00 00 a0 fd 7f - ff ff ff ff bc fe 05 02
(...............
000000000205fed0 d4 f9 05 02 b0 ff 05 02 - f8 b5 01 0f 30 16 00 0f
............0...
000000000205fee0 00 00 00 00 c0 ff 05 02 - c2 f4 00 0f 03 00 00 00
................

*----> Vidage de l'état de la thread 0x4c8 <----*

eax7aff18 ebx000000 ecx000000 edx7aff28 esi7aff14
edi000000
eip|91eb94 esp7afeec ebp7aff84 iopl=0 vif nv up ei pl zr na po
nc
cs1b ss23 ds23 es23 fs3b gs00
efl080246

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:WINDOWSsystem32ntdll.dll -
fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
027aff84 0f03b788 03010301 03010301 00000000 ntdll!KiFastSystemCallRet
027affb4 7c80b50b 00000000 03010301 03010301 ntvdm!host_simulate+0x61bd
027affec 00000000 0f03b759 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
00000000027afeec ab e9 91 7c f8 b5 03 0f - 02 00 00 00 78 ff 7a 02
...|........x.z.
00000000027afefc 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
................
00000000027aff0c 01 03 01 03 00 00 00 00 - 10 00 00 00 00 00 00 00
................
00000000027aff1c 00 00 00 00 00 00 00 00 - ab e9 91 7c 02 00 af 75
...........|...u
00000000027aff2c 4f 00 15 00 01 00 00 00 - 20 00 00 00 00 00 00 00
O....... .......
00000000027aff3c 08 00 d4 77 16 01 00 00 - 67 04 d4 77 e0 88 d1 77
...w....g..w...w
00000000027aff4c ff ff ff ff 08 00 d4 77 - 1f 01 00 00 67 04 d4 77
.......w....g..w
00000000027aff5c e0 88 d1 77 ff ff ff ff - 10 00 00 00 01 00 00 00
...w............
00000000027aff6c 00 00 00 00 00 00 00 00 - ab e9 91 7c 20 00 00 00
...........| ...
00000000027aff7c 50 00 00 00 01 00 00 00 - b4 ff 7a 02 88 b7 03 0f
P.........z.....
00000000027aff8c 01 03 01 03 01 03 01 03 - 00 00 00 00 ff ff ff ff
................
00000000027aff9c 8c ff 7a 02 81 a8 4f 80 - dc ff 7a 02 f8 b5 01 0f
..z...O...z.....
00000000027affac 20 25 00 0f 00 00 00 00 - ec ff 7a 02 0b b5 80 7c
%........z....|
00000000027affbc 00 00 00 00 01 03 01 03 - 01 03 01 03 00 00 00 00
................
00000000027affcc 00 e0 fd 7f 00 66 7c 81 - c0 ff 7a 02 e0 8e f6 80
.....f|...z.....
00000000027affdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
.......|...|....
00000000027affec 00 00 00 00 00 00 00 00 - 59 b7 03 0f 00 00 00 00
........Y.......
00000000027afffc 00 00 00 00 08 00 00 00 - 00 01 00 01 ee ff ee ff
................
00000000027b000c 00 00 00 00 00 00 75 02 - 00 d0 0a 00 00 00 7b 02
......u.......{.
00000000027b001c 00 01 00 00 40 00 7b 02 - 00 00 8b 02 ad 00 00 00
{.........

*----> Vidage de l'état de la thread 0xe7c <----*

eaxÿffffff ebx000000 ecx0006db edx000010 esi|91e99f
edi09b828
eip|91eb94 esp8eff38 ebp8eff68 iopl=0 nv up ei pl nz na pe
nc
cs1b ss23 ds23 es23 fs3b gs00
efl000202

fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
028eff68 0f00dd18 0000bf1d 00000000 00000030 ntdll!KiFastSystemCallRet
028eff84 0f012046 00000000 00000030 00000000 ntvdm!setDL+0x8d
028effb4 7c80b50b 00000000 00000000 00000030 ntvdm!setAH+0x4cd
028effec 00000000 0f011fdf 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
00000000028eff38 ab e9 91 7c 0a 43 00 0f - 02 00 00 00 28 b8 09 0f
...|.C......(...
00000000028eff48 01 00 00 00 01 00 00 00 - 60 ff 8e 02 8d d6 00 00
........`.......
00000000028eff58 1d bf 00 00 00 00 00 00 - de 88 f8 ff ff ff ff ff
................
00000000028eff68 84 ff 8e 02 18 dd 00 0f - 1d bf 00 00 00 00 00 00
................
00000000028eff78 30 00 00 00 18 03 00 00 - c8 64 04 00 b4 ff 8e 02
0........d......
00000000028eff88 46 20 01 0f 00 00 00 00 - 30 00 00 00 00 00 00 00 F
......0.......
00000000028eff98 ff ff ff ff 8c ff 8e 02 - 81 a8 4f 80 dc ff 8e 02
..........O.....
00000000028effa8 f8 b5 01 0f e0 1f 00 0f - 00 00 00 00 ec ff 8e 02
................
00000000028effb8 0b b5 80 7c 00 00 00 00 - 00 00 00 00 30 00 00 00
...|........0...
00000000028effc8 00 00 00 00 00 d0 fd 7f - 00 66 7c 81 c0 ff 8e 02
.........f|.....
00000000028effd8 00 8f fc 80 ff ff ff ff - f3 99 83 7c 18 b5 80 7c
...........|...|
00000000028effe8 00 00 00 00 00 00 00 00 - 00 00 00 00 df 1f 01 0f
................
00000000028efff8 00 00 00 00 00 00 00 00 - c8 00 00 00 2a 01 00 00
............*...
00000000028f0008 ff ee ff ee 02 10 00 00 - 00 00 00 00 00 fe 00 00
................
00000000028f0018 00 00 10 00 00 20 00 00 - 00 02 00 00 00 20 00 00 .....
....... ..
00000000028f0028 41 00 00 00 ff ef fd 7f - 05 00 08 06 00 00 00 00
A...............
00000000028f0038 00 00 00 00 00 00 00 00 - 00 00 00 00 98 05 8f 02
................
00000000028f0048 0f 00 00 00 f8 ff ff ff - 50 00 8f 02 50 00 8f 02
........P...P...
00000000028f0058 40 06 8f 02 00 00 00 00 - 00 00 00 00 00 00 00 00
@...............
00000000028f0068 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................

*----> Vidage de l'état de la thread 0xfc0 <----*

eaxrc730e8 ebx17fef8 ecx000015 edx087188 esi000000
edifda000
eip|91eb94 esp17fed0 ebp17ff6c iopl=0 nv up ei pl zr na po
nc
cs1b ss23 ds23 es23 fs3b gs00
efl000246

fonction : ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:WINDOWSsystem32wdmaud.drv -
ChildEBP RetAddr Args to Child
0317ff6c 7c809c86 00000002 0317ffa4 00000000 ntdll!KiFastSystemCallRet
0317ff88 72c7312a 00000002 0317ffa4 00000000
kernel32!WaitForMultipleObjects+0x18
0317ffb4 7c80b50b 00000000 00000000 02070000 wdmaud!midMessage+0x348
0317ffec 00000000 72c730e8 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Vidage brut de la pile <----*
000000000317fed0 ab e9 91 7c f2 94 80 7c - 02 00 00 00 f8 fe 17 03
...|...|........
000000000317fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
000000000317fef0 00 00 00 00 00 00 00 00 - e0 00 00 00 dc 00 00 00
................
000000000317ff00 fe b5 01 00 bd da 4e 80 - f8 bb c7 f0 0c 86 3e c0
......N.......>.
000000000317ff10 be 47 00 00 ac b8 e8 80 - 14 00 00 00 01 00 00 00
.G..............
000000000317ff20 00 00 00 00 00 00 00 00 - 10 00 00 00 44 b7 e8 80
............D...
000000000317ff30 e1 a9 54 80 ea b5 57 80 - 00 a0 fd 7f 00 c0 fd 7f
..T...W.........
000000000317ff40 00 c0 fd 7f 00 00 00 00 - f8 fe 17 03 00 00 00 00
................
000000000317ff50 02 00 00 00 ec fe 17 03 - 00 00 00 00 dc ff 17 03
................
000000000317ff60 f3 99 83 7c 90 95 80 7c - 00 00 00 00 88 ff 17 03
...|...|........
000000000317ff70 86 9c 80 7c 02 00 00 00 - a4 ff 17 03 00 00 00 00
...|............
000000000317ff80 ff ff ff ff 00 00 00 00 - b4 ff 17 03 2a 31 c7 72
............*1.r
000000000317ff90 02 00 00 00 a4 ff 17 03 - 00 00 00 00 ff ff ff ff
................
000000000317ffa0 00 00 07 02 e0 00 00 00 - dc 00 00 00 00 00 00 00
................
000000000317ffb0 dc e2 91 7c ec ff 17 03 - 0b b5 80 7c 00 00 00 00
...|.......|....
000000000317ffc0 00 00 00 00 00 00 07 02 - 00 00 00 00 00 c0 fd 7f
................
000000000317ffd0 00 66 7c 81 c0 ff 17 03 - 20 38 72 81 ff ff ff ff
.f|..... 8r.....
000000000317ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
...|...|........
000000000317fff0 00 00 00 00 e8 30 c7 72 - 00 00 00 00 00 00 00 00
.....0.r........
0000000003180000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................