服務器在已經屏蔽 445,135,137,138,139;69端口後依然由於bugcheck重啟
開始windows服務器收到永恒之藍攻擊event顯示由於bugcheck導致重啟,在服務器屏蔽 445,135,137,138,139;69端口後依然由於bugcheck重啟,懷疑是驅動問題,請幫忙分析一下memory.dmp.
system log:
The computer has rebooted from a bugcheck. The bugcheck was:
0x000000c5 (0x0000ffff, 0x00000002, 0x00000000, 808933b0).
A dump was saved in: F:\MEMORY.DMP.
memory dump debug:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\123\HBSM25BAP1B_MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: SRV*C:\DevLib\SymbolLocal*https://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (4 procs) Free x86 compatible
Product: LanManNt, suite: Enterprise TerminalServer SingleUserTS
Built by: 3790.srv03_sp2_gdr.120821-0338
Machine Name:
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
Debug session time: Tue May 16 03:02:50.986 2017 (UTC + 8:00)
System Uptime: 417 days 2:19:55.046
Loading Kernel Symbols
...............................................................
...............................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffd700c). Type ".hh dbgerr001" for details
Loading unloaded module list
............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C5, {ffff, d0000002, 0, 808933b0}
Probably caused by : ntkrpamp.exe ( nt!ExAllocatePoolWithTag+838 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000ffff, memory referenced
Arg2: d0000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 808933b0, address which referenced memory
Debugging Details:
------------------
BUGCHECK_STR: 0xC5_D0000002
CURRENT_IRQL: 2
FAULTING_IP:
nt!ExAllocatePoolWithTag+838
808933b0 8b07 mov eax,dword ptr [edi]
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: svchost.exe
TRAP_FRAME: b8f49a58 -- (.trap 0xffffffffb8f49a58)
ErrCode = 00000000
eax=00000000 ebx=808aeae0 ecx=808b4180 edx=f772f568 esi=808aed90 edi=0000ffff
eip=808933b0 esp=b8f49acc ebp=b8f49b08 iopl=0 nv up ei pl nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010207
nt!ExAllocatePoolWithTag+0x838:
808933b0 8b07 mov eax,dword ptr [edi] ds:0023:0000ffff=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 808933b0 to 8088ca3b
STACK_TEXT:
b8f49a58 808933b0 badb0d00 f772f568 e290f500 nt!KiTrap0E+0x2a7
b8f49b08 8093951b 00000000 00000000 e5726854 nt!ExAllocatePoolWithTag+0x838
b8f49b2c 80939c3b 87830468 88d83901 00000000 nt!ObpAllocateObject+0xc9
b8f49b60 80949e9f 88d83901 8b17fad0 00000000 nt!ObCreateObject+0x129
b8f49cc8 8094af23 01e7ef1c 001f03ff 00000000 nt!PspCreateThread+0xb9
b8f49d3c 8088983c 01e7ef1c 001f03ff 00000000 nt!NtCreateThread+0xdd
b8f49d3c 7c82845c 01e7ef1c 001f03ff 00000000 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
01e7f2c8 00000000 00000000 00000000 00000000 0x7c82845c
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+838
808933b0 8b07 mov eax,dword ptr [edi]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExAllocatePoolWithTag+838
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 503382ff
FAILURE_BUCKET_ID: 0xC5_D0000002_nt!ExAllocatePoolWithTag+838
BUCKET_ID: 0xC5_D0000002_nt!ExAllocatePoolWithTag+838
Followup: MachineOwner
---------
最後更新:2017-05-19 07:20:51
上一篇:
windows10更新之後屏幕右下角為什麼出現了一個評估副本的東西,並且好像有時間限製
下一篇:
win10更新卡死
wtg
bitlocker鎖定硬盤,無法用微軟提供的“恢複密鑰”解鎖,請問有什麼辦法可以解決該問
windows10創意者15063.138人名模式問題
點擊小娜語音後,小娜卡死,桌麵略微卡頓,任務欄出現一個小娜的文件夾
屏蔽win10 1703和1709版本升級,其他能正常更新的方法?
surface 的hello開機無法使用
windows live mail 導入 outlook express 6的郵件
Win10 安裝 Microsoft Visual C++ 2015 Redistributable
windows server 2012 支持網絡設備日誌或者安全設備的日誌收集嗎?
0xc1900101 安裝失敗
相關內容
你的設備已過期,並缺少重要的安全和質量更新,因此存在風險。讓我們帶你重回正軌,這樣
Microsoft store 無法聯網,顯示Microsoft Store需要聯網,你似乎沒有聯網
設備以遷移 由於僅部分匹配或匹配不明確,因此無法遷移設備
由於在創建轉儲期間出錯,創建轉儲文件失敗。
發生臨時 DNS 錯誤
應用商店,在我們這邊發生問題,無法使你登陸,錯誤代碼: 0xD000000D
照相機不可用,錯誤代碼:0xA00F4244(0xC00DABE0)
應用商店打開異常提示“清單中指定了未知的布局”
自定義掃描Windows defender裏麵的設備性能和運行狀況 黃色感歎號問題
windows預口體驗成員內口版本遇到問題需要重啟
熱門內容
windows10 點開此電腦後,有兩個顯示硬盤盤符的目錄是怎麼回事?
windows 10 專業版無法下載中文語言包
KB4056892
win10不能共享文件夾
在Surfacebook上用Windows to go 1703版本,更新後重啟藍屏,無法進入係統
windows10 1709版本更新失敗,錯誤0x8007001f
microdoft visual c++ 2015 redistributable
WIN10 Insider Preview 17025更新失敗,錯誤代碼0x80096004
計算機管理服務 出現一個內部錯誤(INVALID
關於控製麵板中的安全和維護內提示Windows defender 防病毒已關閉的問題