系统蓝屏问题常规处理步骤

匿名
2010-02-21T00:25:15+00:00

出现蓝屏了怎么办

蓝屏(Blue Screen)错误可能是Windows系统中比较常见的一种错误。而且对于我们大多数人来说,发生蓝屏之后可能就束手无策了。这里介绍一些发生蓝屏错误时的一些办法。办法很多,但是今天这部分,主要介绍如何用Windows Debugging Tool,或者叫Windbg,结合微软的论坛来处理问题的办法。

首先,要用WinDBG处理蓝屏问题,要确保系统有生成内存转储文件。

确认存在内存转储文件

默认配置的Windows 7,生成的可能是核心转储文件(Kernal Memory Dump)或是小内存转储文件(Minidump)。如果是核心转储文件,默认会存为C:\Windows\Memory.dmp,如果是小内存转储文件,相关文件会保存在C:\Windows\MiniDump目录下面。

所以,出现蓝屏后,请检查系统中有没有C:\Windows\Memory.dmp这个文件,或者是C:\Windows\MiniDump目录下面按照日期命名的文件。比如,Mini010810-01.dmp就是2010年1月8日的第一个小内存转储文件。

如果没有相应的内存转储文件,请参考有关文档。

安装Windows Debugging Tool (WinDBG)

接下来,我们要安装Windbg了。WinDBG可以在微软网站下载,32位的地址是http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx ,64位的地址是http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx 。注意WinDBG只有英文版的。你只要到这两个地方找一个最新的版本下载安装就可以了。如果你不是很懂英语,那就直接到这两个地址下载:32位:http://msdl.microsoft.com/download/symbols/debuggers/dbg_x86_6.11.1.404.msi,64位:

http://msdl.microsoft.com/download/symbols/debuggers/dbg_amd64_6.11.1.404.msi

http://msdl.microsoft.com/download/symbols/debuggers/dbg_ia64_6.11.1.404.msi。然后一路Next安转就可以了。WinDBG安转文件大小,大概在15-30兆左右。

配置Windows Debugging Tool (WinDBG)

在用WinDBG分析内存转储文件之前,我们要配置一下WinDBG。

首先,选一个临时目录存放Symbol文件。比如,建立一个目录叫C:\Temp

然后,打开WinDBG,在File菜单-〉选择Symbol File Path。在打开的对话框里输入:

SRV*c:\temp*http://msdl.microsoft.com/download/symbols

选择OK确定。WinDBG就配置好了。

用Windows Debugging Tool (WinDBG)分析内存转储文件

在WinDBG里面,在File菜单,选择Open Crash Dump,然后找到前面说的那个核心内存转储文件或者小内存转储文件,选择打开。等待一会儿,如果需要从微软网站下载Symbole文件的话,时间可能会比较长。如果不出现大量Warning,就说明设置是成功的。如果出现Your debugger is not using the correct symbols                之类的信息,说明配置有问题,到上一步再仔细检查一下。

一直等到出现Use !analyze -v to get detailed debugging information.字样和0: kd>提示符。

按照提示,输入!analyze -v命令。等待命令执行完成。

分析Windows Debugging Tool(WinDBG)结果

如果你的英文有一定基础,!analyze -v命令可能就告诉你很多信息了。如果看的不是很明白,就把结果贴出来让热心的网友给你分析一下吧。

http://shower-thunder.spaces.live.com/blog/cns!250DE47BD119587C!131.entry

Windows 家庭版 | 以前的 Windows 版本 | Windows 更新

锁定的问题。 此问题已从 Microsoft 支持社区迁移。 你可投票决定它是否有用,但不能添加评论或回复,也不能关注问题。

0 个注释 无注释
问题作者接受的答案
匿名
2014-09-12T06:03:21+00:00

您好,

从您提供的蓝屏信息中可以查看到是由于EagleX64.sys、KartRider.exe文件导致的。

错误代码: 0x00000019,表示磁盘驱动器在磁盘找不到持定的扇区或磁道。

Eaglex64.sys 是安博士杀毒软件,可能是游戏自带的安全软件也有可能是您安装的该软件。

KartRider.exe是跑跑卡丁车这款游戏的进程,可能是该软件不兼容当前系统或与电脑上安装的应用软件存在冲突(特别是杀毒软件)。

建议您暂时卸载掉电脑上的安全防护类软件再确认问题(您安装了360和迅雷之类的应用了)。

此答案是否有帮助?

6 个人认为此答案很有帮助。
0 个注释 无注释

80 个其他答案

排序依据: 非常有帮助
  1. 匿名
    2012-03-18T06:10:23+00:00

    我的电脑出现蓝屏……上面显示的是……

    STOP:0X0000008E(0XC0000005,0X87ED3455,0XB4169768,0X00000000)

    还有一个是:

    STOP:0X0000008E(0XC0000005,0XBF81957F,0XB42ACEB8,0X00000000)

    WIN32K.SYS-ADDRESS BF81957F BASE AT BF800000, DATESTAMP ,4F2BA740

    还有一个是:

    STOP:0X0000008E(0XC0000005,0X87ED3455,0XB2A077A4,0X00000000)

    FLTMGR.SYS-ADDRESS B7ED3455 BASE AT B7ED3000,DATESTAMP,480251DA

    现在大概半小时就蓝屏一次……电脑修了几次换了个主板还有电源……不知道是怎么回事……

    版主麻烦帮我看一看

    此答案是否有帮助?

    0 个注释 无注释
  2. 匿名
    2012-03-08T07:45:46+00:00

    麻烦各位帮我看一下是什么原因引起的。

    0: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)

    This is a very common bugcheck.  Usually the exception address pinpoints

    the driver/function that caused the problem.  Always note this address

    as well as the link date of the driver/image that contains this address.

    Some common problems are exception code 0x80000003.  This means a hard

    coded breakpoint or assertion was hit, but this system was booted

    /NODEBUG.  This is not supposed to happen as developers should never have

    hardcoded breakpoints in retail code, but ...

    If this happens, make sure a debugger gets connected, and the

    system is booted /DEBUG.  This will let us see why this breakpoint is

    happening.

    Arguments:

    Arg1: c0000005, The exception code that was not handled

    Arg2: 80934490, The address that the exception occurred at

    Arg3: b910cba4, Trap Frame

    Arg4: 00000000

    Debugging Details:


    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    GetUlongFromAddress: unable to read from 808afb18

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - "0x%08lx"

    FAULTING_IP:

    nt!ObpCloseHandleTableEntry+16

    80934490 8b80a8000000    mov     eax,dword ptr [eax+0A8h]

    TRAP_FRAME:  b910cba4 -- (.trap 0xffffffffb910cba4)

    ErrCode = 00000000

    eax=543c2020 ebx=89e83d88 ecx=00000000 edx=8a9d3971 esi=8a9d3970 edi=e2004f58

    eip=80934490 esp=b910cc18 ebp=b910cc24 iopl=0         nv up ei ng nz na po nc

    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010282

    nt!ObpCloseHandleTableEntry+0x16:

    80934490 8b80a8000000    mov     eax,dword ptr [eax+0A8h] ds:0023:543c20c8=????????

    Resetting default scope

    CUSTOMER_CRASH_COUNT:  4

    DEFAULT_BUCKET_ID:  DRIVER_FAULT_SERVER_MINIDUMP

    BUGCHECK_STR:  0x8E

    CURRENT_IRQL:  0

    CORRUPTING_POOL_ADDRESS:  8a9d35f0

    CORRUPTING_POOL_TAG:  NDam

    LAST_CONTROL_TRANSFER:  from 8093b189 to 80934490

    STACK_TEXT:

    b910cc24 8093b189 e1ed7660 e2004f58 000007ac nt!ObpCloseHandleTableEntry+0x16

    b910cc40 8098a9c4 e2004f58 000007ac b910cc7c nt!ObpCloseHandleProcedure+0x1d

    b910cc5c 8093b388 e1ed7660 8093b16c b910cc7c nt!ExSweepHandleTable+0x28

    b910cc84 8094c583 89e83d01 89e86bd0 89e86e10 nt!ObKillProcess+0x66

    b910cd0c 8094c765 00000000 00000000 89e83d88 nt!PspExitThread+0x563

    b910cd24 8094c95f 89e86bd0 00000000 00000001 nt!PspTerminateThreadByPointer+0x4b

    b910cd54 808897ec 00000000 00000000 0013ff5c nt!NtTerminateProcess+0x125

    b910cd54 7c95845c 00000000 00000000 0013ff5c nt!KiFastCallEntry+0xfc

    WARNING: Frame IP not in any known module. Following frames may be wrong.

    0013ff5c 00000000 00000000 00000000 00000000 0x7c95845c

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    nt!ObpCloseHandleTableEntry+16

    80934490 8b80a8000000    mov     eax,dword ptr [eax+0A8h]

    SYMBOL_STACK_INDEX:  0

    SYMBOL_NAME:  nt!ObpCloseHandleTableEntry+16

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME:  ntkrpamp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP:  4ea6dacb

    FAILURE_BUCKET_ID:  CORRUPTING_POOLTAG_NDam

    BUCKET_ID:  CORRUPTING_POOLTAG_NDam

    Followup: MachineOwner

    此答案是否有帮助?

    0 个注释 无注释
  3. 匿名
    2012-02-29T06:09:12+00:00

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    BUGCODE_ID_DRIVER (40000080)

    This is the NDIS Driver Bugcheck for Windows 2000 and Windows XP.

    For Windows Server 2003 and later, see 0x7C, BUGCODE_NDIS_DRIVER.

    DESCRIPTION

    The meaning of the bug check parameters cannot be determined by examining the

    parameters alone.  You must also examine the text of a DbgPrint message.

    For details, see either the debugger documentation or the DDK documentation.

    Arguments:

    Arg1: 89b94ad0

    Arg2: 894e5828

    Arg3: 80552388

    Arg4: 00000001

    Debugging Details:


    CUSTOMER_CRASH_COUNT:  2

    DEFAULT_BUCKET_ID:  DRIVER_FAULT

    BUGCHECK_STR:  0x40000080

    PROCESS_NAME:  Idle

    LAST_CONTROL_TRANSFER:  from f71f2821 to 804faf43

    STACK_TEXT: 

    80552308 f71f2821 40000080 89b94ad0 894e5828 nt!KeBugCheckEx+0x1b

    80552368 f766d79e 89b94ad0 80552388 00000001 NDIS!ethFilterDprIndicateReceivePacket+0x5fe

    WARNING: Stack unwind information not available. Following frames may be wrong.

    805523f8 f7668231 00000001 89b94ad0 8955f258 SiSGbeXP+0x679e

    80552410 f71e7e99 8955f008 8055d0c0 ffdff9c0 SiSGbeXP+0x1231

    80552428 80546eef 8955f26c 8955f258 00000000 NDIS!ndisMDpcX+0x21

    80552450 80546dd4 00000000 0000000e 00000000 nt!KiRetireDpcList+0x61

    80552454 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x28

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    SiSGbeXP+679e

    f766d79e ??              ???

    SYMBOL_STACK_INDEX:  2

    SYMBOL_NAME:  SiSGbeXP+679e

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: SiSGbeXP

    IMAGE_NAME:  SiSGbeXP.sys

    DEBUG_FLR_IMAGE_TIMESTAMP:  47cba188

    FAILURE_BUCKET_ID:  0x40000080_SiSGbeXP+679e

    BUCKET_ID:  0x40000080_SiSGbeXP+679e

    Followup: MachineOwner


    这个是怎么回事

    此答案是否有帮助?

    0 个注释 无注释
  4. 匿名
    2012-01-06T11:25:15+00:00

    感请楼主或者路过的朋友帮忙分析一下,我用WinDbg检测出来的结果,看了几圈,看到了有关X64 CPU的 错误问题,

    这个CPU是原盒CPU,CPU上的序列号和包装盒上的一致,购买的时候就已验证。

    烦请各位朋友帮忙给看下,分析结果到底哪里有问题:   劳烦了……

    Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\Windows\Minidump\010612-13712-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\patch*http://msdl.microsoft.com/download/symbols

    Executable search path is:

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850

    Machine Name:

    Kernel base = 0xfffff80004457000 PsLoadedModuleList = 0xfffff8000469ce90

    Debug session time: Fri Jan  6 19:03:29.570 2012 (GMT+8)

    System Uptime: 0 days 0:00:06.333

    Loading Kernel Symbols

    .................................................

    Loading User Symbols

    Mini Kernel Dump does not contain unloaded driver list

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 124, {0, fffffa8004bda748, 0, 0}

    Probably caused by : hardware

    Followup: MachineOwner


    1: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    WHEA_UNCORRECTABLE_ERROR (124)

    A fatal hardware error has occurred. Parameter 1 identifies the type of error

    source that reported the error. Parameter 2 holds the address of the

    WHEA_ERROR_RECORD structure that describes the error conditon.

    Arguments:

    Arg1: 0000000000000000, Machine Check Exception

    Arg2: fffffa8004bda748, Address of the WHEA_ERROR_RECORD structure.

    Arg3: 0000000000000000, High order 32-bits of the MCi_STATUS value.

    Arg4: 0000000000000000, Low order 32-bits of the MCi_STATUS value.

    Debugging Details:


    BUGCHECK_STR:  0x124_AuthenticAMD

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    PROCESS_NAME:  System

    CURRENT_IRQL:  0

    STACK_TEXT:****

    fffff880047a86f0 fffff8000471ad29 : fffffa8004bda720 fffffa8003a06b60 0000000000000006 0000000000000000 : nt!WheapCreateLiveTriageDump+0x6c

    fffff880047a8c10 fffff800045fa217 : fffffa8004bda720 fffff80004674658 fffffa8003a06b60 0000000000000000 : nt!WheapCreateTriageDumpFromPreviousSession+0x49

    fffff880047a8c40 fffff80004561865 : fffff800046d63a0 0000000000000001 fffffa8004971fa0 fffffa8003a06b60 : nt!WheapProcessWorkQueueItem+0x57

    fffff880047a8c80 fffff800044e1a21 : fffff88001102e00 fffff80004561840 fffffa8003a06b00 08102608a253b0a8 : nt!WheapWorkQueueWorkerRoutine+0x25

    fffff880047a8cb0 fffff80004774cce : 64a50e15cac0101d fffffa8003a06b60 0000000000000080 fffffa800396d890 : nt!ExpWorkerThread+0x111

    fffff880047a8d40 fffff800044c8fe6 : fffff88004564180 fffffa8003a06b60 fffff8800456efc0 e44140286ac261cc : nt!PspSystemThreadStartup+0x5a

    fffff880047a8d80 0000000000000000 : fffff880047a9000 fffff880047a3000 fffff8800551b540 0000000000000000 : nt!KxStartSystemThread+0x16

    STACK_COMMAND:  kb

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: hardware

    IMAGE_NAME:  hardware

    DEBUG_FLR_IMAGE_TIMESTAMP:  0

    FAILURE_BUCKET_ID:  X64_0x124_AuthenticAMD_PROCESSOR_BUS_PRV

    BUCKET_ID:  X64_0x124_AuthenticAMD_PROCESSOR_BUS_PRV

    Followup: MachineOwner


    1: kd> lmvm hardware

    start             end                 module name

    Mini Kernel Dump does not contain unloaded driver list

    1: kd> .bugcheck

    Bugcheck code 00000124

    Arguments 0000000000000000 fffffa8004bda748 0000000000000000 0000000000000000

    此答案是否有帮助?

    0 个注释 无注释