Microsoft (R) Windows Debugger Version 6.10.0003.233 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\071810-18423-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntkrnlpa.exe
*** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16384.x86fre.win7_rtm.090710-1945
Machine Name:
Kernel base = 0x83e55000 PsLoadedModuleList = 0x83f9d810
Debug session time: Sun Jul 18 17:14:21.804 2010 (GMT+8)
System Uptime: 0 days 4:25:24.584
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntkrnlpa.exe
*** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe
Loading Kernel Symbols
...............................................................
................................................................
..........
Loading User Symbols
Loading unloaded module list
................
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: e8254680, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 83ec6877, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000002, (reserved)
Debugging Details:
*** WARNING: Unable to verify timestamp for afd.sys
*** ERROR: Module load completed but symbols could not be loaded for afd.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
MODULE_NAME: afd
FAULTING_MODULE: 83e55000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a582a6f
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
e8254680
FAULTING_IP:
nt+71877
83ec6877 8b3e mov edi,dword ptr [esi]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
BUGCHECK_STR: 0x50
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 83e9b5f8 to 83eda8e3
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
9e173a0c 83e9b5f8 00000000 e8254680 00000000 nt+0x858e3
9e173a24 83ec6877 badb0d00 00000000 00000006 nt+0x465f8
9e173ab4 83f0eb4d e8254680 864a2030 00000000 nt+0x71877
9e173acc 83f0cd20 864a2030 00000000 000000a0 nt+0xb9b4d
9e173b48 8f64b0ae 864dde40 d0646641 85e2096c nt+0xb7d20
9e173b60 8f64abf5 864dde40 00012024 8f64a478 afd+0x290ae
9e173bec 8f643504 88348a48 86bf9460 9e173c14 afd+0x28bf5
9e173bfc 83e914bc 86bf9460 886d2310 886d2310 afd+0x21504
9e173c14 84092eee 88348a48 886d2310 886d23ec nt+0x3c4bc
9e173c34 840afcd1 86bf9460 88348a48 00000000 nt+0x23deee
9e173cd0 840b24ac 86bf9460 886d2310 00000000 nt+0x25acd1
9e173d04 83e9842a 000008ec 00000900 00000000 nt+0x25d4ac
9e173d34 77da64f4 badb0d00 0b39fa74 00000000 nt+0x4342a
9e173d38 badb0d00 0b39fa74 00000000 00000000 0x77da64f4
9e173d3c 0b39fa74 00000000 00000000 00000000 0xbadb0d00
9e173d40 00000000 00000000 00000000 00000000 0xb39fa74
STACK_COMMAND: kb
FOLLOWUP_IP:
afd+290ae
8f64b0ae ?? ???
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: afd+290ae
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: afd.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
经常蓝屏,XP和WIN7都不行,中间还试着换过一条内存,求楼主帮忙!!