系统蓝屏问题常规处理步骤

匿名
2010-02-21T00:25:15+00:00

出现蓝屏了怎么办

蓝屏(Blue Screen)错误可能是Windows系统中比较常见的一种错误。而且对于我们大多数人来说,发生蓝屏之后可能就束手无策了。这里介绍一些发生蓝屏错误时的一些办法。办法很多,但是今天这部分,主要介绍如何用Windows Debugging Tool,或者叫Windbg,结合微软的论坛来处理问题的办法。

首先,要用WinDBG处理蓝屏问题,要确保系统有生成内存转储文件。

确认存在内存转储文件

默认配置的Windows 7,生成的可能是核心转储文件(Kernal Memory Dump)或是小内存转储文件(Minidump)。如果是核心转储文件,默认会存为C:\Windows\Memory.dmp,如果是小内存转储文件,相关文件会保存在C:\Windows\MiniDump目录下面。

所以,出现蓝屏后,请检查系统中有没有C:\Windows\Memory.dmp这个文件,或者是C:\Windows\MiniDump目录下面按照日期命名的文件。比如,Mini010810-01.dmp就是2010年1月8日的第一个小内存转储文件。

如果没有相应的内存转储文件,请参考有关文档。

安装Windows Debugging Tool (WinDBG)

接下来,我们要安装Windbg了。WinDBG可以在微软网站下载,32位的地址是http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx ,64位的地址是http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx 。注意WinDBG只有英文版的。你只要到这两个地方找一个最新的版本下载安装就可以了。如果你不是很懂英语,那就直接到这两个地址下载:32位:http://msdl.microsoft.com/download/symbols/debuggers/dbg_x86_6.11.1.404.msi,64位:

http://msdl.microsoft.com/download/symbols/debuggers/dbg_amd64_6.11.1.404.msi

http://msdl.microsoft.com/download/symbols/debuggers/dbg_ia64_6.11.1.404.msi。然后一路Next安转就可以了。WinDBG安转文件大小,大概在15-30兆左右。

配置Windows Debugging Tool (WinDBG)

在用WinDBG分析内存转储文件之前,我们要配置一下WinDBG。

首先,选一个临时目录存放Symbol文件。比如,建立一个目录叫C:\Temp

然后,打开WinDBG,在File菜单-〉选择Symbol File Path。在打开的对话框里输入:

SRV*c:\temp*http://msdl.microsoft.com/download/symbols

选择OK确定。WinDBG就配置好了。

用Windows Debugging Tool (WinDBG)分析内存转储文件

在WinDBG里面,在File菜单,选择Open Crash Dump,然后找到前面说的那个核心内存转储文件或者小内存转储文件,选择打开。等待一会儿,如果需要从微软网站下载Symbole文件的话,时间可能会比较长。如果不出现大量Warning,就说明设置是成功的。如果出现Your debugger is not using the correct symbols                之类的信息,说明配置有问题,到上一步再仔细检查一下。

一直等到出现Use !analyze -v to get detailed debugging information.字样和0: kd>提示符。

按照提示,输入!analyze -v命令。等待命令执行完成。

分析Windows Debugging Tool(WinDBG)结果

如果你的英文有一定基础,!analyze -v命令可能就告诉你很多信息了。如果看的不是很明白,就把结果贴出来让热心的网友给你分析一下吧。

http://shower-thunder.spaces.live.com/blog/cns!250DE47BD119587C!131.entry

Windows 家庭版 | 以前的 Windows 版本 | Windows 更新

锁定的问题。 此问题已从 Microsoft 支持社区迁移。 你可投票决定它是否有用,但不能添加评论或回复,也不能关注问题。

0 个注释 无注释
问题作者接受的答案
匿名
2014-09-12T06:03:21+00:00

您好,

从您提供的蓝屏信息中可以查看到是由于EagleX64.sys、KartRider.exe文件导致的。

错误代码: 0x00000019,表示磁盘驱动器在磁盘找不到持定的扇区或磁道。

Eaglex64.sys 是安博士杀毒软件,可能是游戏自带的安全软件也有可能是您安装的该软件。

KartRider.exe是跑跑卡丁车这款游戏的进程,可能是该软件不兼容当前系统或与电脑上安装的应用软件存在冲突(特别是杀毒软件)。

建议您暂时卸载掉电脑上的安全防护类软件再确认问题(您安装了360和迅雷之类的应用了)。

此答案是否有帮助?

6 个人认为此答案很有帮助。
0 个注释 无注释

80 个其他答案

排序依据: 非常有帮助
  1. 匿名
    2011-09-16T02:41:00+00:00

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\WINDOWS\Minidump\Mini091511-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    WARNING: Whitespace at end of path element

    Symbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols

    Executable search path is:

    Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 2600.xpsp_sp3_gdr.090206-1234

    Machine Name:

    Kernel base = 0x80800000 PsLoadedModuleList = 0x8088c4c0

    Debug session time: Thu Sep 15 22:57:59.359 2011 (GMT+8)

    System Uptime: 0 days 0:30:15.080

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .................

    Loading User Symbols

    Loading unloaded module list

    ..................

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 77, {c0000185, c0000185, 0, c4b000}

    Probably caused by : memory_corruption ( nt!MiMakeOutswappedPageResident+37e )

    Followup: MachineOwner

    请求帮助啊

    此答案是否有帮助?

    0 个注释 无注释
  2. 匿名
    2011-07-12T09:34:42+00:00

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\Windows\Minidump\071211-22807-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols

    Executable search path is:

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7601.17592.x86fre.win7sp1_gdr.110408-1631

    Machine Name:

    Kernel base = 0x84041000 PsLoadedModuleList = 0x8418a4d0

    Debug session time: Tue Jul 12 13:34:21.340 2011 (GMT+8)

    System Uptime: 0 days 0:41:09.228

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    .............................................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000008E, {c0000005, 840ce933, a5827950, 0}

    Unable to load image \SystemRoot\system32\DRIVERS\klif.sys, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for klif.sys

    *** ERROR: Module load completed but symbols could not be loaded for klif.sys

    *** WARNING: Unable to verify timestamp for qutmdrv.sys

    *** ERROR: Module load completed but symbols could not be loaded for qutmdrv.sys

    Probably caused by : klif.sys ( klif+20278 )

    Followup: MachineOwner


    1: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)

    This is a very common bugcheck.  Usually the exception address pinpoints

    the driver/function that caused the problem.  Always note this address

    as well as the link date of the driver/image that contains this address.

    Some common problems are exception code 0x80000003.  This means a hard

    coded breakpoint or assertion was hit, but this system was booted

    /NODEBUG.  This is not supposed to happen as developers should never have

    hardcoded breakpoints in retail code, but ...

    If this happens, make sure a debugger gets connected, and the

    system is booted /DEBUG.  This will let us see why this breakpoint is

    happening.

    Arguments:

    Arg1: c0000005, The exception code that was not handled

    Arg2: 840ce933, The address that the exception occurred at

    Arg3: a5827950, Trap Frame

    Arg4: 00000000

    Debugging Details:


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

    FAULTING_IP:

    nt!FsRtlLookupPerStreamContextInternal+9a

    840ce933 395008          cmp     dword ptr [eax+8],edx

    TRAP_FRAME:  a5827950 -- (.trap 0xffffffffa5827950)

    ErrCode = 00000000

    eax=02000000 ebx=a5827a38 ecx=af79eda4 edx=8819d008 esi=00000000 edi=af79ed78

    eip=840ce933 esp=a58279c4 ebp=a58279d0 iopl=0         nv up ei pl nz ac pe cy

    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010217

    nt!FsRtlLookupPerStreamContextInternal+0x9a:

    840ce933 395008          cmp     dword ptr [eax+8],edx ds:0023:02000008=????????

    Resetting default scope

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    BUGCHECK_STR:  0x8E

    PROCESS_NAME:  avp.exe

    CURRENT_IRQL:  0

    LAST_CONTROL_TRANSFER:  from 84f2af3b to 840ce933

    STACK_TEXT: 

    a58279d0 84f2af3b 00000000 8819d008 00000000 nt!FsRtlLookupPerStreamContextInternal+0x9a

    a5827a14 84f2443a 8819d008 8702dce8 00000000 fltmgr!FltpGetStreamListCtrl+0x5b

    a5827a30 91123278 00000000 8702dce8 92677364 fltmgr!FltGetStreamHandleContext+0x1a

    WARNING: Stack unwind information not available. Following frames may be wrong.

    a5827aa0 84f23aeb 870f2e40 a5827ac0 a5827aec klif+0x20278

    a5827b0c 84f269f0 a5827b60 86be1378 86be1574 fltmgr!FltpPerformPreCallbacks+0x34d

    a5827b24 84f26f01 a5827b60 00000000 881bc230 fltmgr!FltpPassThroughInternal+0x40

    a5827b48 84f273ba 12827b60 881bc230 84fecb28 fltmgr!FltpPassThrough+0x203

    a5827b78 84078593 881bc230 86be1378 86be1378 fltmgr!FltpDispatch+0xb4

    a5827b90 84fd80c7 86be1378 88393cf0 00000000 nt!IofCallDriver+0x63

    a5827bf0 84078593 88393cf0 86be1378 8702dce8 qutmdrv+0xd0c7

    a5827c08 84273a04 86ad3c58 8702dcd0 00000001 nt!IofCallDriver+0x63

    a5827c48 84264eed 98661780 8702dce8 00000001 nt!IopCloseFile+0x2f3

    a5827c94 842862f2 98661780 9abedd40 870c1d48 nt!ObpDecrementHandleCount+0x139

    a5827cdc 84286032 9abedd40 ada3d3c0 98661780 nt!ObpCloseHandleTableEntry+0x203

    a5827d0c 842863cc 98661780 870c1d01 0ccbf3b0 nt!ObpCloseHandle+0x7f

    a5827d28 8407f1ea 000021e0 0ccbf3b4 77ae70b4 nt!NtClose+0x4e

    a5827d28 77ae70b4 000021e0 0ccbf3b4 77ae70b4 nt!KiFastCallEntry+0x12a

    0ccbf3b4 00000000 00000000 00000000 00000000 0x77ae70b4

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    klif+20278

    91123278 ??              ???

    SYMBOL_STACK_INDEX:  3

    SYMBOL_NAME:  klif+20278

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: klif

    IMAGE_NAME:  klif.sys

    DEBUG_FLR_IMAGE_TIMESTAMP:  4daeb73f

    FAILURE_BUCKET_ID:  0x8E_klif+20278

    BUCKET_ID:  0x8E_klif+20278

    Followup: MachineOwner

    ---------求解~~~这个是怎么回事?

    此答案是否有帮助?

    0 个注释 无注释
  3. 匿名
    2011-04-16T09:34:45+00:00

    0x0000007F

    蓝屏,求解

    此答案是否有帮助?

    0 个注释 无注释
  4. 匿名
    2011-04-14T13:57:19+00:00

    请高手帮我看下。

    1: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)

    This is a very common bugcheck.  Usually the exception address pinpoints

    the driver/function that caused the problem.  Always note this address

    as well as the link date of the driver/image that contains this address.

    Some common problems are exception code 0x80000003.  This means a hard

    coded breakpoint or assertion was hit, but this system was booted

    /NODEBUG.  This is not supposed to happen as developers should never have

    hardcoded breakpoints in retail code, but ...

    If this happens, make sure a debugger gets connected, and the

    system is booted /DEBUG.  This will let us see why this breakpoint is

    happening.

    Arguments:

    Arg1: c0000005, The exception code that was not handled

    Arg2: 00000000, The address that the exception occurred at

    Arg3: af59a968, Trap Frame

    Arg4: 00000000

    Debugging Details:


    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    Unable to open image file: C:\Program Files\Debugging Tools for Windows (x86)\sym\ntkrnlpa.exe\4CC78ED4410000\ntkrnlpa.exe

    ϵͳÕÒ²»µ½Ö¸¶¨µÄÎļþ¡£

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    ADDITIONAL_DEBUG_TEXT: 

    Use '!findthebuild' command to search for the target build information.

    If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

    FAULTING_MODULE: 83e43000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP:  4da0733b

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

    FAULTING_IP:

    +4343a

    00000000 ??              ???

    TRAP_FRAME:  af59a968 -- (.trap 0xffffffffaf59a968)

    ErrCode = 00000010

    eax=8782d928 ebx=867af1a0 ecx=00000000 edx=00000000 esi=867af130 edi=8782d928

    eip=00000000 esp=af59a9dc ebp=af59aa44 iopl=0         nv up ei ng nz na pe nc

    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010286

    00000000 ??              ???

    Resetting default scope

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    BUGCHECK_STR:  0x8E

    CURRENT_IRQL:  0

    LAST_CONTROL_TRANSFER:  from a83aaf8f to 00000000

    STACK_TEXT: 

    WARNING: Frame IP not in any known module. Following frames may be wrong.

    af59a9d8 a83aaf8f 00000000 867af130 8782d928 0x0

    af59aa44 83eabc53 00000000 867af130 8782d928 GamesGuardNet+0x5f8f

    af59aa8c 8eb71044 85cb6038 867af1a0 af59aab4 nt+0x68c53

    af59aa9c a83ab034 86d578b8 867af130 86d578b8 nsiproxy!NsippDispatch+0x92

    af59aab4 83e7f4ac 86d578b8 867af130 867af130 GamesGuardNet+0x6034

    af59aacc 840813be 85cb6038 867af130 867af1a0 nt+0x3c4ac

    af59aaec 8409e1af 86d578b8 85cb6038 00000000 nt+0x23e3be

    af59ab88 840a098a 86d578b8 867af130 00000000 nt+0x25b1af

    af59abbc a83aaa2b 00000258 000006ac 00000000 nt+0x25d98a

    af59ac10 84bc0a05 00000258 000006ac 00000000 GamesGuardNet+0x5a2b

    af59ad04 83e8643a 00000258 000006ac 00000000 Hookport+0x4a05

    af59ad34 77466344 badb0d00 0d21fd4c 00000000 nt+0x4343a

    af59ad38 badb0d00 0d21fd4c 00000000 00000000 0x77466344

    af59ad3c 0d21fd4c 00000000 00000000 00000000 0xbadb0d00

    af59ad40 00000000 00000000 00000000 00000000 0xd21fd4c

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    GamesGuardNet+5f8f

    a83aaf8f ??              ???

    SYMBOL_STACK_INDEX:  1

    SYMBOL_NAME:  GamesGuardNet+5f8f

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: GamesGuardNet

    IMAGE_NAME:  GamesGuardNet.dat

    BUCKET_ID:  WRONG_SYMBOLS

    Followup: MachineOwner


    此答案是否有帮助?

    0 个注释 无注释