江湖救急,感謝!
Windows 電腦藍屏, 請各位大牛幫忙分析, DUMP文件如附件
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\F1203783\Desktop\Windows日誌分析\MEMORY.DMP] Kernel Summary Dump File: Only kernel address space is available Symbol search path is: http://msdl.microsoft.com/download/symbols Executable search path is: Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7601.23403.amd64fre.win7sp1_ldr.160325-0600 Machine Name: Kernel base = 0xfffff8000461d000 PsLoadedModuleList = 0xfffff8000485f730 Debug session time: Wed Apr 20 00:05:21.019 2022 (UTC + 8:00) System Uptime: 0 days 5:27:14.237 Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1E, {ffffffffc0000005, fffffa80123d1009, 1, e2e2e2e2} Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::string'+40e2d ) Followup: MachineOwner --------- 0: kd> .reload Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... 0: kd> .restart /f Loading Dump File [C:\Users\F1203783\Desktop\Windows日誌分析\MEMORY.DMP] Kernel Summary Dump File: Only kernel address space is available Symbol search path is: [http://msdl.microsoft.com/download/symbols](http://msdl.microsoft.com/download/symbols) Executable search path is: Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7601.23403.amd64fre.win7sp1\_ldr.160325-0600 Machine Name: Kernel base = 0xfffff8000461d000 PsLoadedModuleList = 0xfffff8000485f730 Debug session time: Wed Apr 20 00:05:21.019 2022 (UTC + 8:00) System Uptime: 0 days 5:27:14.237 Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \* \* \* Bugcheck Analysis \* \* \* \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* Use !analyze -v to get detailed debugging information. BugCheck 1E, {ffffffffc0000005, fffffa80123d1009, 1, e2e2e2e2} Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::string'+40e2d ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d Followup: MachineOwner --------- 0: kd> .trap 0xfffff88004f706c0 NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? 0: kd> .trap 0xfffff88004f706c0 NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? 0: kd> .reload Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d Followup: MachineOwner --------- 0: kd> dfasd *** ERROR: Module load completed but symbols could not be loaded for spldr.sys *** ERROR: Module load completed but symbols could not be loaded for aksfridge.sys *** ERROR: Module load completed but symbols could not be loaded for aksdf.sys *** ERROR: Module load completed but symbols could not be loaded for cog8700.sys *** ERROR: Module load completed but symbols could not be loaded for hardlock.sys *** ERROR: Module load completed but symbols could not be loaded for peauth.sys *** ERROR: Module load completed but symbols could not be loaded for e1q62x64.sys *** ERROR: Module load completed but symbols could not be loaded for ebUniversalPro.sys *** ERROR: Module load completed but symbols could not be loaded for vncmirror.sys *** ERROR: Module load completed but symbols could not be loaded for Rt64win7.sys *** ERROR: Module load completed but symbols could not be loaded for GT800.sys *** ERROR: Module load completed but symbols could not be loaded for Smb_driver_Intel.sys *** ERROR: Symbol file could not be found. Defaulted to export symbols for igdkmd64.sys - *** ERROR: Module load completed but symbols could not be loaded for TeeDriverx64.sys *** ERROR: Module load completed but symbols could not be loaded for xtouch.sys *** ERROR: Module load completed but symbols could not be loaded for AppleUSBEthernet.sys *** ERROR: Symbol file could not be found. Defaulted to export symbols for spsys.sys - *** ERROR: Symbol file could not be found. Defaulted to export symbols for drmk.sys - *** ERROR: Module load completed but symbols could not be loaded for IntcDAud.sys *** ERROR: Module load completed but symbols could not be loaded for RTKVHD64.sys Couldn't resolve error at 'asd' 0: kd> 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d Followup: MachineOwner --------- 0: kd> .reload Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... 0: kd> .reload Loading Kernel Symbols ............................................................... ................................................................ ................. Loading User Symbols Loading unloaded module list .... 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!??::FNODOBFM::string+40e2d Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffffa80123d1009, The address that the exception occurred at Arg3: 0000000000000001, Parameter 0 of the exception Arg4: 00000000e2e2e2e2, Parameter 1 of the exception Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - FAULTING_IP: +3632363962373534 fffffa80123d1009 0000 add byte ptr [rax],al EXCEPTION\_PARAMETER1: 0000000000000001 EXCEPTION\_PARAMETER2: 00000000e2e2e2e2 WRITE\_ADDRESS: 00000000e2e2e2e2 ERROR\_CODE: (NTSTATUS) 0xc0000005 - BUGCHECK\_STR: 0x1E\_c0000005 DEFAULT\_BUCKET\_ID: VISTA\_DRIVER\_FAULT PROCESS\_NAME: System CURRENT\_IRQL: 0 TRAP\_FRAME: fffff88004f706c0 -- (.trap 0xfffff88004f706c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000e2e2e2e2 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000187540f3 rsi=0000000000000000 rdi=0000000000000000 rip=fffffa80123d1009 rsp=fffff88004f70858 rbp=fffffa8006bd7000 r8=0000000000012408 r9=00000000000007ff r10=000000000000074d r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc fffffa80123d1009 0000 add byte ptr [rax],al ds:e0a8:e2e2=?? Resetting default scope LAST_CONTROL_TRANSFER: from fffff8000470d512 to fffff8000468d380 STACK_TEXT: fffff88004f6fe38 fffff8000470d512 : 000000000000001e ffffffffc0000005 fffffa80123d1009 0000000000000001 : nt!KeBugCheckEx fffff88004f6fe40 fffff8000468ca02 : fffff88004f70618 000000000050f000 fffff88004f706c0 fffffa80123d1000 : nt! ?? ::FNODOBFM::string'+0x40e2d fffff88004f704e0 fffff8000468b57a : 0000000000000001 00000000e2e2e2e2 fffffa80093f9f00 000000000050f000 : nt!KiExceptionDispatch+0xc2 fffff88004f706c0 fffffa80123d1009 : fffffa8006bd717a 0000000000000000 000000000050f000 fffff88001952d20 : nt!KiPageFault+0x23a fffff88004f70858 fffffa8006bd717a : 0000000000000000 000000000050f000 fffff88001952d20 fffffa800a83f0e0 : 0xfffffa80123d1009 fffff88004f70860 0000000000000000 : 000000000050f000 fffff88001952d20 fffffa800a83f0e0 fffff8a000000002 : 0xfffffa8006bd717a STACK\_COMMAND: kb FOLLOWUP\_IP: nt! ?? ::FNODOBFM::string'+40e2d fffff8000470d512 cc int 3 SYMBOL\_STACK\_INDEX: 1 SYMBOL\_NAME: nt! ?? ::FNODOBFM::string'+40e2d FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 56f579f0 FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!_??_::FNODOBFM::_string_+40e2d BUCKET_ID: X64_0x1E_c0000005_nt!_??_::FNODOBFM::_string_+40e2d Followup: MachineOwner --------- 0: kd> 0: kd> !process PROCESS fffffa80066fc040 SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000 DirBase: 00187000 ObjectTable: fffff8a0000019f0 HandleCount: 1487. Image: System VadRoot fffffa80076ce930 Vads 16 Clone 0 Private 12. Modified 738425. Locked 64. DeviceMap fffff8a000008d80 Token fffff8a000004040 ElapsedTime 05:27:07.607 UserTime 00:00:00.000 KernelTime 00:00:03.463 QuotaPoolUsage[PagedPool] 0 QuotaPoolUsage[NonPagedPool] 0 Working Set Sizes (now,min,max) (512, 0, 0) (2048KB, 0KB, 0KB) PeakWorkingSetSize 1974 VirtualSize 5 Mb PeakVirtualSize 11 Mb PageFaultCount 21293 MemoryPriority BACKGROUND BasePriority 8 CommitCharge 34 THREAD fffffa80066fcab0 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrFreePage) KernelMode Non-Alertable fffff8000485ffa0 Gate THREAD fffffa8006761590 Cid 0004.000c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff80004841580 SynchronizationEvent THREAD fffffa8006776040 Cid 0004.0010 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff80004841ba0 Semaphore Limit 0x7fffffff THREAD fffffa800676f850 Cid 0004.0014 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff80004841ba0 Semaphore Limit 0x7fffffff THREAD fffffa800676f360 Cid 0004.0018 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80004836280 QueueObject THREAD fffffa800671ab50 Cid 0004.001c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80004836280 QueueObject THREAD fffffa800672cb50 Cid 0004.0020 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80004836280 QueueObject THREAD fffffa800672c660 Cid 0004.0024 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80004836280 QueueObject THREAD fffffa800672c170 Cid 0004.0028 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80004836280 QueueObject THREAD fffffa8006719040 Cid 0004.002c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006719b50 Cid 0004.0030 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006719660 Cid 0004.0034 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006718040 Cid 0004.0038 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006718b50 Cid 0004.003c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006718660 Cid 0004.0040 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006717040 Cid 0004.0044 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800048362d8 QueueObject THREAD fffffa8006717b50 Cid 0004.0048 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff80004836330 QueueObject THREAD fffffa8006717660 Cid 0004.004c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff880047d9bb0 NotificationTimer fffff80004836240 SynchronizationEvent fffff80004836220 SynchronizationEvent THREAD fffffa8006716760 Cid 0004.0050 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Suspended) KernelMode Non-Alertable fffff80004810280 Gate THREAD fffffa8006715040 Cid 0004.0054 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Suspended) KernelMode Non-Alertable fffff880009f0580 Gate THREAD fffffa8006715b50 Cid 0004.0058 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Suspended) KernelMode Non-Alertable
Windows 家庭版 | 以前的 Windows 版本 | Windows 更新
锁定的问题。 此问题已从 Microsoft 支持社区迁移。 你可投票决定它是否有用,但不能添加评论或回复,也不能关注问题。