系统蓝屏问题常规处理步骤

匿名
2010-02-21T00:25:15+00:00

出现蓝屏了怎么办

蓝屏(Blue Screen)错误可能是Windows系统中比较常见的一种错误。而且对于我们大多数人来说,发生蓝屏之后可能就束手无策了。这里介绍一些发生蓝屏错误时的一些办法。办法很多,但是今天这部分,主要介绍如何用Windows Debugging Tool,或者叫Windbg,结合微软的论坛来处理问题的办法。

首先,要用WinDBG处理蓝屏问题,要确保系统有生成内存转储文件。

确认存在内存转储文件

默认配置的Windows 7,生成的可能是核心转储文件(Kernal Memory Dump)或是小内存转储文件(Minidump)。如果是核心转储文件,默认会存为C:\Windows\Memory.dmp,如果是小内存转储文件,相关文件会保存在C:\Windows\MiniDump目录下面。

所以,出现蓝屏后,请检查系统中有没有C:\Windows\Memory.dmp这个文件,或者是C:\Windows\MiniDump目录下面按照日期命名的文件。比如,Mini010810-01.dmp就是2010年1月8日的第一个小内存转储文件。

如果没有相应的内存转储文件,请参考有关文档。

安装Windows Debugging Tool (WinDBG)

接下来,我们要安装Windbg了。WinDBG可以在微软网站下载,32位的地址是http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx ,64位的地址是http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx 。注意WinDBG只有英文版的。你只要到这两个地方找一个最新的版本下载安装就可以了。如果你不是很懂英语,那就直接到这两个地址下载:32位:http://msdl.microsoft.com/download/symbols/debuggers/dbg_x86_6.11.1.404.msi,64位:

http://msdl.microsoft.com/download/symbols/debuggers/dbg_amd64_6.11.1.404.msi

http://msdl.microsoft.com/download/symbols/debuggers/dbg_ia64_6.11.1.404.msi。然后一路Next安转就可以了。WinDBG安转文件大小,大概在15-30兆左右。

配置Windows Debugging Tool (WinDBG)

在用WinDBG分析内存转储文件之前,我们要配置一下WinDBG。

首先,选一个临时目录存放Symbol文件。比如,建立一个目录叫C:\Temp

然后,打开WinDBG,在File菜单-〉选择Symbol File Path。在打开的对话框里输入:

SRV*c:\temp*http://msdl.microsoft.com/download/symbols

选择OK确定。WinDBG就配置好了。

用Windows Debugging Tool (WinDBG)分析内存转储文件

在WinDBG里面,在File菜单,选择Open Crash Dump,然后找到前面说的那个核心内存转储文件或者小内存转储文件,选择打开。等待一会儿,如果需要从微软网站下载Symbole文件的话,时间可能会比较长。如果不出现大量Warning,就说明设置是成功的。如果出现Your debugger is not using the correct symbols                之类的信息,说明配置有问题,到上一步再仔细检查一下。

一直等到出现Use !analyze -v to get detailed debugging information.字样和0: kd>提示符。

按照提示,输入!analyze -v命令。等待命令执行完成。

分析Windows Debugging Tool(WinDBG)结果

如果你的英文有一定基础,!analyze -v命令可能就告诉你很多信息了。如果看的不是很明白,就把结果贴出来让热心的网友给你分析一下吧。

http://shower-thunder.spaces.live.com/blog/cns!250DE47BD119587C!131.entry

Windows 家庭版 | 以前的 Windows 版本 | Windows 更新

锁定的问题。 此问题已从 Microsoft 支持社区迁移。 你可投票决定它是否有用,但不能添加评论或回复,也不能关注问题。

0 个注释 无注释
问题作者接受的答案
匿名
2014-09-12T06:03:21+00:00

您好,

从您提供的蓝屏信息中可以查看到是由于EagleX64.sys、KartRider.exe文件导致的。

错误代码: 0x00000019,表示磁盘驱动器在磁盘找不到持定的扇区或磁道。

Eaglex64.sys 是安博士杀毒软件,可能是游戏自带的安全软件也有可能是您安装的该软件。

KartRider.exe是跑跑卡丁车这款游戏的进程,可能是该软件不兼容当前系统或与电脑上安装的应用软件存在冲突(特别是杀毒软件)。

建议您暂时卸载掉电脑上的安全防护类软件再确认问题(您安装了360和迅雷之类的应用了)。

此答案是否有帮助?

6 个人认为此答案很有帮助。
0 个注释 无注释

80 个其他答案

排序依据: 非常有帮助
  1. 匿名
    2010-07-18T09:53:35+00:00

    Microsoft (R) Windows Debugger Version 6.10.0003.233 X86

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\Windows\Minidump\071810-18423-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: *** Invalid ***

    ****************************************************************************

    * Symbol loading may be unreliable without a symbol search path.           *

    * Use .symfix to have the debugger choose a symbol path.                   *

    * After setting your symbol path, use .reload to refresh symbol locations. *

    ****************************************************************************

    Executable search path is:

    *********************************************************************

    * Symbols can not be loaded because symbol path is not initialized. *

    *                                                                   *

    * The Symbol Path can be set by:                                    *

    *   using the _NT_SYMBOL_PATH environment variable.                 *

    *   using the -y <symbol_path> argument when starting the debugger. *

    *   using .sympath and .sympath+                                    *

    *********************************************************************

    Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for ntkrnlpa.exe

    *** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe

    Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7600.16384.x86fre.win7_rtm.090710-1945

    Machine Name:

    Kernel base = 0x83e55000 PsLoadedModuleList = 0x83f9d810

    Debug session time: Sun Jul 18 17:14:21.804 2010 (GMT+8)

    System Uptime: 0 days 4:25:24.584

    *********************************************************************

    * Symbols can not be loaded because symbol path is not initialized. *

    *                                                                   *

    * The Symbol Path can be set by:                                    *

    *   using the _NT_SYMBOL_PATH environment variable.                 *

    *   using the -y <symbol_path> argument when starting the debugger. *

    *   using .sympath and .sympath+                                    *

    *********************************************************************

    Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for ntkrnlpa.exe

    *** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ..........

    Loading User Symbols

    Loading unloaded module list

    ................

    1: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    PAGE_FAULT_IN_NONPAGED_AREA (50)

    Invalid system memory was referenced.  This cannot be protected by try-except,

    it must be protected by a Probe.  Typically the address is just plain bad or it

    is pointing at freed memory.

    Arguments:

    Arg1: e8254680, memory referenced.

    Arg2: 00000000, value 0 = read operation, 1 = write operation.

    Arg3: 83ec6877, If non-zero, the instruction address which referenced the bad memory

     address.

    Arg4: 00000002, (reserved)

    Debugging Details:


    *** WARNING: Unable to verify timestamp for afd.sys

    *** ERROR: Module load completed but symbols could not be loaded for afd.sys

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    *************************************************************************

    ***                                                                   ***

    ***                                                                   ***

    ***    Your debugger is not using the correct symbols                 ***

    ***                                                                   ***

    ***    In order for this command to work properly, your symbol path   ***

    ***    must point to .pdb files that have full type information.      ***

    ***                                                                   ***

    ***    Certain .pdb files (such as the public OS symbols) do not      ***

    ***    contain the required information.  Contact the group that      ***

    ***    provided you with these symbols if you need this command to    ***

    ***    work.                                                          ***

    ***                                                                   ***

    ***    Type referenced: nt!_KPRCB                                     ***

    ***                                                                   ***

    *************************************************************************

    *********************************************************************

    * Symbols can not be loaded because symbol path is not initialized. *

    *                                                                   *

    * The Symbol Path can be set by:                                    *

    *   using the _NT_SYMBOL_PATH environment variable.                 *

    *   using the -y <symbol_path> argument when starting the debugger. *

    *   using .sympath and .sympath+                                    *

    *********************************************************************

    *********************************************************************

    * Symbols can not be loaded because symbol path is not initialized. *

    *                                                                   *

    * The Symbol Path can be set by:                                    *

    *   using the _NT_SYMBOL_PATH environment variable.                 *

    *   using the -y <symbol_path> argument when starting the debugger. *

    *   using .sympath and .sympath+                                    *

    *********************************************************************

    MODULE_NAME: afd

    FAULTING_MODULE: 83e55000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP:  4a582a6f

    READ_ADDRESS: unable to get nt!MmSpecialPoolStart

    unable to get nt!MmSpecialPoolEnd

    unable to get nt!MmPoolCodeStart

    unable to get nt!MmPoolCodeEnd

     e8254680

    FAULTING_IP:

    nt+71877

    83ec6877 8b3e            mov     edi,dword ptr [esi]

    MM_INTERNAL_CODE:  2

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  WRONG_SYMBOLS

    BUGCHECK_STR:  0x50

    CURRENT_IRQL:  0

    LAST_CONTROL_TRANSFER:  from 83e9b5f8 to 83eda8e3

    STACK_TEXT: 

    WARNING: Stack unwind information not available. Following frames may be wrong.

    9e173a0c 83e9b5f8 00000000 e8254680 00000000 nt+0x858e3

    9e173a24 83ec6877 badb0d00 00000000 00000006 nt+0x465f8

    9e173ab4 83f0eb4d e8254680 864a2030 00000000 nt+0x71877

    9e173acc 83f0cd20 864a2030 00000000 000000a0 nt+0xb9b4d

    9e173b48 8f64b0ae 864dde40 d0646641 85e2096c nt+0xb7d20

    9e173b60 8f64abf5 864dde40 00012024 8f64a478 afd+0x290ae

    9e173bec 8f643504 88348a48 86bf9460 9e173c14 afd+0x28bf5

    9e173bfc 83e914bc 86bf9460 886d2310 886d2310 afd+0x21504

    9e173c14 84092eee 88348a48 886d2310 886d23ec nt+0x3c4bc

    9e173c34 840afcd1 86bf9460 88348a48 00000000 nt+0x23deee

    9e173cd0 840b24ac 86bf9460 886d2310 00000000 nt+0x25acd1

    9e173d04 83e9842a 000008ec 00000900 00000000 nt+0x25d4ac

    9e173d34 77da64f4 badb0d00 0b39fa74 00000000 nt+0x4342a

    9e173d38 badb0d00 0b39fa74 00000000 00000000 0x77da64f4

    9e173d3c 0b39fa74 00000000 00000000 00000000 0xbadb0d00

    9e173d40 00000000 00000000 00000000 00000000 0xb39fa74

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    afd+290ae

    8f64b0ae ??              ???

    SYMBOL_STACK_INDEX:  5

    SYMBOL_NAME:  afd+290ae

    FOLLOWUP_NAME:  MachineOwner

    IMAGE_NAME:  afd.sys

    BUCKET_ID:  WRONG_SYMBOLS

    Followup: MachineOwner


    经常蓝屏,XP和WIN7都不行,中间还试着换过一条内存,求楼主帮忙!!

    此答案是否有帮助?

    0 个注释 无注释
  2. 匿名
    2010-07-18T01:34:25+00:00

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\Windows\MEMORY.DMP]

    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols

    Executable search path is:

    Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7600.16539.x86fre.win7_gdr.100226-1909

    Machine Name:

    Kernel base = 0x83c18000 PsLoadedModuleList = 0x83d60810

    Debug session time: Sun Jul 18 08:28:32.025 2010 (GMT+8)

    System Uptime: 0 days 0:22:22.351

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ..............................

    Loading User Symbols

    Loading unloaded module list

    ......

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 7F, {8, 801e5000, 0, 0}

    Probably caused by : tcpip.sys ( tcpip!Ipv4Global+a )

    Followup: MachineOwner


    0: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    UNEXPECTED_KERNEL_MODE_TRAP (7f)

    This means a trap occurred in kernel mode, and it's a trap of a kind

    that the kernel isn't allowed to have/catch (bound trap) or that

    is always instant death (double fault).  The first number in the

    bugcheck params is the number of the trap (8 = double fault, etc)

    Consult an Intel x86 family manual to learn more about what these

    traps are. Here is a *portion* of those codes:

    If kv shows a taskGate

            use .tss on the part before the colon, then kv.

    Else if kv shows a trapframe

            use .trap on that value

    Else

            .trap on the appropriate frame will show where the trap was taken

            (on x86, this will be the ebp that goes with the procedure KiTrap)

    Endif

    kb will then show the corrected stack.

    Arguments:

    Arg1: 00000008, EXCEPTION_DOUBLE_FAULT

    Arg2: 801e5000

    Arg3: 00000000

    Arg4: 00000000

    Debugging Details:


    BUGCHECK_STR:  0x7f_8

    TSS:  00000028 -- (.tss 0x28)

    eax=89f18dab ebx=86e4d54c ecx=86171300 edx=00000001 esi=8078ac84 edi=86e4d5e8

    eip=89f18da2 esp=8079ab25 ebp=8078ac4c iopl=0         ov up ei pl nz na pe nc

    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010a06

    tcpip!Ipv4Global+0xa:

    89f18da2 f1              ???

    Resetting default scope

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    PROCESS_NAME:  System

    CURRENT_IRQL:  2

    LAST_CONTROL_TRANSFER:  from 00000000 to 89f18da2

    UNALIGNED_STACK_POINTER:  8079ab25

    STACK_TEXT: 

    8078ac4c 00000000 00000000 00000007 89f18d98 tcpip!Ipv4Global+0xa

    STACK_COMMAND:  .tss 0x28 ; kb

    FOLLOWUP_IP:

    tcpip!Ipv4Global+a

    89f18da2 f1              ???

    SYMBOL_STACK_INDEX:  0

    SYMBOL_NAME:  tcpip!Ipv4Global+a

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: tcpip

    IMAGE_NAME:  tcpip.sys

    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bbf8e

    FAILURE_BUCKET_ID:  0x7f_8_tcpip!Ipv4Global+a

    BUCKET_ID:  0x7f_8_tcpip!Ipv4Global+a

    Followup: MachineOwner


    我的电脑经常蓝屏  试过xp win7都不行 现在用的是win7 请帮我分析一下 谢谢

    此答案是否有帮助?

    0 个注释 无注释
  3. 匿名
    2010-07-17T14:58:06+00:00

    stop:0x00000050(0xCE040000,0x00000000,ox805DD649,ox00000000) beginning dump of physcical memory. 上面说*50的属于非内存等的物理问题,可是,我这个也是*50的问题,但下面确显示了"physical memory" , 倒底是怎么的呢?请帮忙解答一下下. 最近我的电脑凡是正常启动,都会刚进入WINDOW 后就蓝屏了, 但在安全模下,却可以. 最近也没有装新的软件. 不知道为何?谢谢了! 小女子不太懂电脑,请高手帮帮忙!

    此答案是否有帮助?

    0 个注释 无注释
  4. 匿名
    2010-07-15T05:48:21+00:00

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86

    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [E:\Windows\Minidump\071510-90511-01.dmp]

    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*e:\temp*http://msdl.microsoft.com/download/symbols

    Executable search path is:

    Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7600.16539.x86fre.win7_gdr.100226-1909

    Machine Name:

    Kernel base = 0x8400a000 PsLoadedModuleList = 0x84152810

    Debug session time: Thu Jul 15 13:02:11.034 2010 (GMT+8)

    System Uptime: 0 days 3:33:32.766

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ...........................

    Loading User Symbols

    Loading unloaded module list

    .....

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 1000000A, {8433eed3, 2, 8, 8433eed3}

    Unable to load image splj.sys, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for splj.sys

    *** ERROR: Module load completed but symbols could not be loaded for splj.sys

    Probably caused by : CLASSPNP.SYS ( CLASSPNP!ClassCompleteRequest+11 )

    Followup: MachineOwner


    1: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)

    An attempt was made to access a pageable (or completely invalid) address at an

    interrupt request level (IRQL) that is too high.  This is usually

    caused by drivers using improper addresses.

    If a kernel debugger is available get the stack backtrace.

    Arguments:

    Arg1: 8433eed3, memory referenced

    Arg2: 00000002, IRQL

    Arg3: 00000008, bitfield :

     bit 0 : value 0 = read operation, 1 = write operation

     bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)

    Arg4: 8433eed3, address which referenced memory

    Debugging Details:


    READ_ADDRESS: GetPointerFromAddress: unable to read from 84172718

    Unable to read MiSystemVaType memory at 84152160

     8433eed3

    CURRENT_IRQL:  2

    FAULTING_IP:

    nt!VerifierBugCheckIfAppropriate+0

    8433eed3 8bff            mov     edi,edi

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    BUGCHECK_STR:  0xA

    PROCESS_NAME:  System

    LAST_CONTROL_TRANSFER:  from 840f9443 to 8433eed3

    FAILED_INSTRUCTION_ADDRESS:

    nt!VerifierBugCheckIfAppropriate+0

    8433eed3 8bff            mov     edi,edi

    STACK_TEXT: 

    807e1a34 840f9443 8719a500 8719a4f8 000001ff nt!VerifierBugCheckIfAppropriate

    807e1a48 84129544 8719a500 00000858 00000001 nt!VerifierFreeTrackedPool+0x24

    807e1abc 84f34492 8719a500 63694d46 00000000 nt!ExFreePoolWithTag+0x53e

    807e1ad8 84f385b4 8719a500 00000000 871441e3 fltmgr!FltpFreeIrpCtrl+0x128

    807e1af4 84f38b46 00000000 87144008 807e1b48 fltmgr!FltpProcessIoCompletion+0xb2

    807e1b04 84072b33 876a3c00 87144008 8719a500 fltmgr!FltpPassThroughCompletion+0x98

    807e1b48 8a591498 807e1b7c 8a591abd 875ff030 nt!IopfCompleteRequest+0x128

    807e1b50 8a591abd 875ff030 87144008 00000001 CLASSPNP!ClassCompleteRequest+0x11

    807e1b7c 84072b33 00000000 87b0f990 00b0fa98 CLASSPNP!TransferPktComplete+0x2e4

    807e1bc0 84ee59a5 873d15a8 807e1c04 84ef4a10 nt!IopfCompleteRequest+0x128

    807e1bcc 84ef4a10 87b0f990 00000001 00000000 storport!RaidCompleteRequestEx+0x1c

    807e1c04 84ee61d9 873d15a8 87331008 807e1c7c storport!RaidUnitCompleteRequest+0xac

    807e1c2c 84c22894 866db814 866db7a0 00000000 storport!RaidpAdapterDpcRoutine+0x51

    WARNING: Stack unwind information not available. Following frames may be wrong.

    807e1c78 840723b5 866db814 866db7a0 00000000 splj+0x11894

    807e1cd4 84072218 807c5120 807ca800 00000000 nt!KiExecuteAllDpcs+0xf9

    807e1d20 84072038 00000000 0000000e 00000000 nt!KiRetireDpcList+0xd5

    807e1d24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38

    STACK_COMMAND:  kb

    FOLLOWUP_IP:

    CLASSPNP!ClassCompleteRequest+11

    8a591498 5d              pop     ebp

    SYMBOL_STACK_INDEX:  7

    SYMBOL_NAME:  CLASSPNP!ClassCompleteRequest+11

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: CLASSPNP

    IMAGE_NAME:  CLASSPNP.SYS

    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bbf18

    FAILURE_BUCKET_ID:  0xA_CODE_AV_BAD_IP_CLASSPNP!ClassCompleteRequest+11

    BUCKET_ID:  0xA_CODE_AV_BAD_IP_CLASSPNP!ClassCompleteRequest+11

    Followup: MachineOwner


    希望楼主帮忙分析下!  还有我蓝屏后 ie8的 临时文件好像也丢失了!

    此答案是否有帮助?

    0 个注释 无注释