新装的win10系统,安装完360后出现了几次蓝屏,不知是否与360有关。请帮忙看看,dmp文件太大了,现在附上windbg的分析结果。
Microsoft (R) Windows Debugger Version 10.0.17712.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 17134 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 17134.1.amd64fre.rs4_release.180410-1804
Machine Name:
Kernel base = 0xfffff803`cf606000 PsLoadedModuleList = 0xfffff803`cf9c01f0
Debug session time: Fri Jul 20 12:42:14.605 2018 (UTC + 8:00)
System Uptime: 0 days 0:17:43.633
Loading Kernel Symbols
...............................................................
...Page 9a8 not present in the dump file. Type \".hh dbgerr004\" for details
.............................................................
.......................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`002b6018). Type \".hh dbgerr001\" for details
Loading unloaded module list
..............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffad820ff18a40, 11, ffffad820ff18a40, c}
*** ERROR: Symbol file could not be found. Defaulted to export symbols for FLTMGR.SYS -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for win32k.sys -
Probably caused by : memory_corruption ( nt!MiSystemFault+14135d )
Followup: MachineOwner
---------
nt!KeBugCheckEx:
fffff803`cf79e330 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff8d06`366532b0=0000000000000050
7: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffad820ff18a40, memory referenced.
Arg2: 0000000000000011, value 0 = read operation, 1 = write operation.
Arg3: ffffad820ff18a40, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 000000000000000c, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804
SYSTEM_MANUFACTURER: BIOSTAR Group
SYSTEM_PRODUCT_NAME: Hi-Fi Z97Z7
SYSTEM_SKU: None
SYSTEM_VERSION: 5.0
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 4.6.5
BIOS_DATE: 09/12/2014
BASEBOARD_MANUFACTURER: BIOSTAR Group
BASEBOARD_PRODUCT: Hi-Fi Z97Z7
BASEBOARD_VERSION: 5.0
DUMP_TYPE: 1
BUGCHECK_P1: ffffad820ff18a40
BUGCHECK_P2: 11
BUGCHECK_P3: ffffad820ff18a40
BUGCHECK_P4: c
WRITE_ADDRESS: ffffad820ff18a40 Nonpaged pool
FAULTING_IP:
+0
ffffad82`0ff18a40 0300 add eax,dword ptr [rax]
MM_INTERNAL_CODE: c
CPU_COUNT: 8
CPU_MHZ: fb5
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3c
CPU_STEPPING: 3
CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 22\'00000000 (cache) 22\'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXPNP: 1 (!blackboxpnp)
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: 360rp.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-H9VQ6UU
ANALYSIS_SESSION_TIME: 07-20-2018 19:14:27.0075
ANALYSIS_VERSION: 10.0.17712.1000 amd64fre
TRAP_FRAME: ffff8d0636653560 -- (.trap 0xffff8d0636653560)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000c0000034 rbx=0000000000000000 rcx=ffffad8213810010
rdx=ffffad82108a22a0 rsi=0000000000000000 rdi=0000000000000000
rip=ffffad820ff18a40 rsp=ffff8d06366536f8 rbp=0000000000000000
r8=ffffad82108a22a0 r9=ffffd08139bb9180 r10=ffffad820f54fbf0
r11=ffffad8213810010 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
ffffad82`0ff18a40 0300 add eax,dword ptr [rax] ds:00000000`c0000034=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff803cf7f021d to fffff803cf79e330
STACK_TEXT:
ffff8d06`366532a8 fffff803`cf7f021d : 00000000`00000050 ffffad82`0ff18a40 00000000`00000011 ffff8d06`36653560 : nt!KeBugCheckEx
ffff8d06`366532b0 fffff803`cf6b33e8 : fffff803`cf69ef13 00000000`00000011 00000000`00000000 ffff8cc6`633198c8 : nt!MiSystemFault+0x14135d
ffff8d06`366533f0 fffff803`cf7ab9da : 00000000`0000001a ffffad82`11783630 ffffad82`1121cc01 00000000`00000000 : nt!MmAccessFault+0x1f8
ffff8d06`36653560 ffffad82`0ff18a40 : ffffad82`13810010 00000000`00060830 fffff802`00000000 ffff8d06`366537c0 : nt!KiPageFault+0x31a
ffff8d06`366536f8 ffffad82`13810010 : 00000000`00060830 fffff802`00000000 ffff8d06`366537c0 ffffad82`1121cc00 : 0xffffad82`0ff18a40
ffff8d06`36653700 00000000`00060830 : fffff802`00000000 ffff8d06`366537c0 ffffad82`1121cc00 ffffad82`1121cc0d : 0xffffad82`13810010
ffff8d06`36653708 fffff802`00000000 : ffff8d06`366537c0 ffffad82`1121cc00 ffffad82`1121cc0d fffff802`db207207 : 0x60830
ffff8d06`36653710 ffff8d06`366537c0 : ffffad82`1121cc00 ffffad82`1121cc0d fffff802`db207207 ffff8d06`366537c0 : 0xfffff802`00000000
ffff8d06`36653718 ffffad82`1121cc00 : ffffad82`1121cc0d fffff802`db207207 ffff8d06`366537c0 fffff802`db2053b4 : 0xffff8d06`366537c0
ffff8d06`36653720 ffffad82`1121cc0d : fffff802`db207207 ffff8d06`366537c0 fffff802`db2053b4 00000000`00000000 : 0xffffad82`1121cc00
ffff8d06`36653728 fffff802`db207207 : ffff8d06`366537c0 fffff802`db2053b4 00000000`00000000 00000000`0000000d : 0xffffad82`1121cc0d
ffff8d06`36653730 fffff802`db23aed0 : ffff8d06`366537c0 ffffad82`1121ccc0 00000000`00000001 ffffad82`142e2580 : FLTMGR!FltIsCallbackDataDirty+0x2e7
ffff8d06`366537a0 fffff803`cf68a189 : ffffad82`13810010 ffffad82`1121ccc0 00000000`00000001 00000000`20206f49 : FLTMGR!FltRemoveOpenReparseEntry+0x720
ffff8d06`36653800 fffff803`cfafd2eb : ffffad82`13810010 ffff8d06`36653b80 00000000`00000001 00000000`00000000 : nt!IofCallDriver+0x59
ffff8d06`36653840 fffff803`cfb0922f : ffffad82`00000000 ffffad82`1121cd10 00000000`00000000 ffff8d06`36653b80 : nt!IopSynchronousServiceTail+0x1ab
ffff8d06`366538f0 fffff803`cfba59f6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x66f
ffff8d06`36653a20 fffff803`cf7ae943 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`02950668 : nt!NtFsControlFile+0x56
ffff8d06`36653a90 00007ffd`3f6aa5d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0535fd78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`3f6aa5d4
THREAD_SHA1_HASH_MOD_FUNC: be1deabefa837a0eb905dd56f080994430bdaae4
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: a2b038835e9069fac0129ed60446ca569495cab3
THREAD_SHA1_HASH_MOD: 19e78fae6b2f26b89fd89904c1af1e92aae92f70
FOLLOWUP_IP:
nt!MiSystemFault+14135d
fffff803`cf7f021d cc int 3
FAULT_INSTR_CODE: b60f41cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiSystemFault+14135d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 5b1a4590
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 14135d
FAILURE_BUCKET_ID: AV_INVALID_nt!MiSystemFault
BUCKET_ID: AV_INVALID_nt!MiSystemFault
PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!MiSystemFault
TARGET_TIME: 2018-07-20T04:42:14.000Z
OSBUILD: 17134
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2018-06-08 17:00:00
BUILDDATESTAMP_STR: 180410-1804
BUILDLAB_STR: rs4_release
BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804
ANALYSIS_SESSION_ELAPSED_TIME: 138d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_invalid_nt!misystemfault
FAILURE_ID_HASH: {8a33c6b1-a9f1-4efe-025b-a861cc33d6e2}
Followup: MachineOwner
---------
|
|
|
|
评论
直达楼层