閱讀149 返回首頁    go 阿裏雲 go 技術社區[雲棲]


Win10 64位 係統藍屏 Probably caused by : ntkrnlmp.exe (


Microsoft (R) Windows Debugger Version 10.0.15063.468 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\071317-25781-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 14393 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 14393.1358.amd64fre.rs1_release.170602-2252
Machine Name:
Kernel base = 0xfffff800`6c882000 PsLoadedModuleList = 0xfffff800`6cb81000
Debug session time: Thu Jul 13 00:56:00.810 2017 (UTC + 9:00)
System Uptime: 2 days 2:39:48.446
Loading Kernel Symbols
..

Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.

.............................................................
................................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
.....................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {ffffffff00000009, 2, 0, fffff8006c91616b}

Probably caused by : ntkrnlmp.exe ( nt!IopSetLockOperationProcess+c3 )

Followup:     MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffffff00000009, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8006c91616b, address which referenced memory

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  14393.1358.amd64fre.rs1_release.170602-2252

SYSTEM_MANUFACTURER:  Alienware

SYSTEM_PRODUCT_NAME:  Alienware 17

SYSTEM_SKU:  Alienware 17

SYSTEM_VERSION:  A14

BIOS_VENDOR:  Alienware

BIOS_VERSION:  A14

BIOS_DATE:  09/24/2014

BASEBOARD_MANUFACTURER:  Alienware

BASEBOARD_PRODUCT:  04WT2G

BASEBOARD_VERSION:  A00

DUMP_TYPE:  2

DUMP_FILE_ATTRIBUTES: 0x8
  Kernel Generated Triage Dump

BUGCHECK_P1: ffffffff00000009

BUGCHECK_P2: 2

BUGCHECK_P3: 0

BUGCHECK_P4: fffff8006c91616b

READ_ADDRESS: fffff8006cc22338: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
 ffffffff00000009 

CURRENT_IRQL:  2

FAULTING_IP: 
nt!IopSetLockOperationProcess+c3
fffff800`6c91616b 4c396108        cmp     qword ptr [rcx+8],r12

CPU_COUNT: 8

CPU_MHZ: b4d

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 3c

CPU_STEPPING: 3

CPU_MICROCODE: 6,3c,3,0 (F,M,S,R)  SIG: 1E'00000000 (cache) 1E'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  svchost.exe

ANALYSIS_SESSION_HOST:  MIX-ALIENWARE

ANALYSIS_SESSION_TIME:  07-13-2017 01:26:48.0499

ANALYSIS_VERSION: 10.0.15063.468 amd64fre

TRAP_FRAME:  ffff878185d427d0 -- (.trap 0xffff878185d427d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffffff00000001
rdx=ffffb20e57419910 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8006c91616b rsp=ffff878185d42960 rbp=ffffb20e4461d001
 r8=ffff878180ee4000  r9=0000000000000000 r10=0000000000000801
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
nt!IopSetLockOperationProcess+0xc3:
fffff800`6c91616b 4c396108        cmp     qword ptr [rcx+8],r12 ds:ffffffff`00000009=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff8006c9dbe29 to fffff8006c9d0ce0

STACK_TEXT:  
ffff8781`85d42688 fffff800`6c9dbe29 : 00000000`0000000a ffffffff`00000009 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffff8781`85d42690 fffff800`6c9da407 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8781`85d427e8 : nt!KiBugCheckDispatch+0x69
ffff8781`85d427d0 fffff800`6c91616b : 00000000`00000200 00000000`00000010 00000000`00000000 fffff800`00000000 : nt!KiPageFault+0x247
ffff8781`85d42960 fffff800`6cccb424 : 00000000`00000000 ffffb20e`5a29e740 ffff8781`85d42b80 00000000`00000000 : nt!IopSetLockOperationProcess+0xc3
ffff8781`85d429c0 fffff800`6c9db993 : ffffb20e`43d10340 00000008`ca1fd6e8 00000000`00000000 00000008`ca1fd780 : nt!NtLockFile+0x1a8
ffff8781`85d42a90 00007ffd`39548084 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000008`ca1fd6c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`39548084


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  90904e2f252ffed626681a37ba48aab3042ef5bf

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  50db4cd51ea7926ac2c5ed066910b7a37207c8d4

THREAD_SHA1_HASH_MOD:  ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693

FOLLOWUP_IP: 
nt!IopSetLockOperationProcess+c3
fffff800`6c91616b 4c396108        cmp     qword ptr [rcx+8],r12

FAULT_INSTR_CODE:  861394c

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  nt!IopSetLockOperationProcess+c3

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  593278b1

IMAGE_VERSION:  10.0.14393.1358

BUCKET_ID_FUNC_OFFSET:  c3

FAILURE_BUCKET_ID:  AV_nt!IopSetLockOperationProcess

BUCKET_ID:  AV_nt!IopSetLockOperationProcess

PRIMARY_PROBLEM_CLASS:  AV_nt!IopSetLockOperationProcess

TARGET_TIME:  2017-07-12T15:56:00.000Z

OSBUILD:  14393

OSSERVICEPACK:  1358

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:  

USER_LCID:  0

OSBUILD_TIMESTAMP:  2017-06-03 17:52:01

BUILDDATESTAMP_STR:  170602-2252

BUILDLAB_STR:  rs1_release

BUILDOSVER_STR:  10.0.14393.1358.amd64fre.rs1_release.170602-2252

ANALYSIS_SESSION_ELAPSED_TIME:  399

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_nt!iopsetlockoperationprocess

FAILURE_ID_HASH:  {5f44213d-4444-49b1-e8cb-1d751a460a06}

Followup:     MachineOwner
---------

3: kd> !process
PROCESS ffffb20e5092b480
    SessionId: none  Cid: 0a40    Peb: 8af53f000  ParentCid: 0334
    DirBase: 3ba70d000  ObjectTable: ffff9e04b38e8040  HandleCount: <Data Not Accessible>
    Image: svchost.exe
    VadRoot ffffb20e565f28c0 Vads 150 Clone 0 Private 2293. Modified 9269. Locked 0.
    DeviceMap ffff9e04a7c15220
    Token                             ffff9e04b389f940
    ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
    ElapsedTime                       00:00:00.000
    UserTime                          00:00:00.000
    KernelTime                        00:00:00.000
    QuotaPoolUsage[PagedPool]         137328
    QuotaPoolUsage[NonPagedPool]      20776
    Working Set Sizes (now,min,max)  (4323, 50, 345) (17292KB, 200KB, 1380KB)
    PeakWorkingSetSize                7249
    VirtualSize                       2097371 Mb
    PeakVirtualSize                   2097386 Mb
    PageFaultCount                    220053
    MemoryPriority                    BACKGROUND
    BasePriority                      8
    CommitCharge                      2517

        *** Error in reading nt!_ETHREAD @ ffffb20e5092d100


最後更新:2017-07-13 07:27:47

  上一篇:go Windows10 藍屏問題 求幫忙 有DMP文件
  下一篇:go WIN10更新