阅读673 返回首页    go 微软 go windows


win10蓝屏问题

昨天无故蓝屏,一起研究讨论下,这个蓝屏是由什么问题引起的。


Microsoft (R) Windows Debugger Version 10.0.15063.468 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Jink\Desktop\解码器问题描述与系统日志2017-8-14\系统日志2017-8-14\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 10586 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 10586.0.amd64fre.th2_release.151029-1700
Machine Name:
Kernel base = 0xfffff803`7468a000 PsLoadedModuleList = 0xfffff803`74968cb0
Debug session time: Mon Aug 14 14:06:22.498 2017 (UTC + 8:00)
System Uptime: 12 days 3:16:45.421
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
.............
Loading unloaded module list
..................................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck EF, {ffffe00056727840, 0, 0, 0}

*** WARNING: Unable to verify timestamp for winsrv.DLL
*** ERROR: Module load completed but symbols could not be loaded for winsrv.DLL
*** WARNING: Unable to verify timestamp for CSRSRV.dll
*** ERROR: Module load completed but symbols could not be loaded for CSRSRV.dll
Page e40 not present in the dump file. Type ".hh dbgerr004" for details
Page e40 not present in the dump file. Type ".hh dbgerr004" for details
Page e40 not present in the dump file. Type ".hh dbgerr004" for details
*** WARNING: Unable to verify timestamp for kernelbase.dll
*** ERROR: Module load completed but symbols could not be loaded for kernelbase.dll
Probably caused by : ntdll.dll ( ntdll!RtlLookupFunctionEntry+11a )

Followup:     MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_PROCESS_DIED (ef)
        A critical system process died
Arguments:
Arg1: ffffe00056727840, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------

Page e40 not present in the dump file. Type ".hh dbgerr004" for details
Page e40 not present in the dump file. Type ".hh dbgerr004" for details
Page e40 not present in the dump file. Type ".hh dbgerr004" for details

DUMP_CLASS: 1

DUMP_QUALIFIER: 401

BUILD_VERSION_STRING:  10586.0.amd64fre.th2_release.151029-1700

SYSTEM_MANUFACTURER:  Supermicro

SYSTEM_PRODUCT_NAME:  Super Server

SYSTEM_SKU:  To be filled by O.E.M.

SYSTEM_VERSION:  0123456789

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2.0a

BIOS_DATE:  03/30/2017

BASEBOARD_MANUFACTURER:  Supermicro

BASEBOARD_PRODUCT:  X11SAE

BASEBOARD_VERSION:  1.01

DUMP_TYPE:  1

BUGCHECK_P1: ffffe00056727840

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

PROCESS_NAME:  csrss.exe

CRITICAL_PROCESS:  csrss.exe

EXCEPTION_CODE: (NTSTATUS) 0x5c24a080 - <Unable to get error code text>

ERROR_CODE: (NTSTATUS) 0x5c24a080 - <Unable to get error code text>

CPU_COUNT: 4

CPU_MHZ: e70

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 5e

CPU_STEPPING: 3

CPU_MICROCODE: 6,5e,3,0 (F,M,S,R)  SIG: A6'00000000 (cache) A6'00000000 (init)

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  0xEF

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-QKM9K6D

ANALYSIS_SESSION_TIME:  08-15-2017 17:34:04.0975

ANALYSIS_VERSION: 10.0.15063.468 amd64fre

TRAP_FRAME:  ffffd000212ffa00 -- (.trap 0xffffd000212ffa00)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000001059 rbx=0000000000000000 rcx=0000000000004170
rdx=00007ffee051a164 rsi=0000000000000000 rdi=0000000000000000
rip=00007ffee3f85f3a rsp=000000e64eb013e0 rbp=000000e64eb01530
 r8=0000000000000574  r9=00007ffee04f0000 r10=00007ffee0516000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na po nc
ntdll!RtlLookupFunctionEntry+0x11a:
0033:00007ffe`e3f85f3a 418b0482        mov     eax,dword ptr [r10+rax*4] ds:00007ffe`e051a164=????????
Resetting default scope

CONTEXT:  00007ffee044aea1 -- (.cxr 0x7ffee044aea1)
Unable to read context, HRESULT 0x80004002

LAST_CONTROL_TRANSFER:  from fffff80374ccac10 to fffff803747cbf80

THREAD_SHA1_HASH_MOD_FUNC:  9655ca82c724c8a91077faeff7a204bf8764f1f0

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  2d7ab1799579c1e6bd7372f99e24d1173387af0f

THREAD_SHA1_HASH_MOD:  4cd436cd21764fb5ad0a5470b46d219ab44ba389

FOLLOWUP_IP: 
ntdll!RtlLookupFunctionEntry+11a
00007ffe`e3f85f3a 418b0482        mov     eax,dword ptr [r10+rax*4]

FAULT_INSTR_CODE:  82048b41

SYMBOL_STACK_INDEX:  a

SYMBOL_NAME:  ntdll!RtlLookupFunctionEntry+11a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: ntdll

IMAGE_NAME:  ntdll.dll

DEBUG_FLR_IMAGE_TIMESTAMP:  5632d193

STACK_COMMAND:  .cxr 0x7ffee044aea1 ; kb

BUCKET_ID_FUNC_OFFSET:  11a

FAILURE_BUCKET_ID:  0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_5c24a080_ntdll!RtlLookupFunctionEntry

BUCKET_ID:  0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_5c24a080_ntdll!RtlLookupFunctionEntry

PRIMARY_PROBLEM_CLASS:  0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_5c24a080_ntdll!RtlLookupFunctionEntry

TARGET_TIME:  2017-08-14T06:06:22.000Z

OSBUILD:  10586

OSSERVICEPACK:  0

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:  

USER_LCID:  0

OSBUILD_TIMESTAMP:  2015-10-30 10:15:45

BUILDDATESTAMP_STR:  151029-1700

BUILDLAB_STR:  th2_release

BUILDOSVER_STR:  10.0.10586.0.amd64fre.th2_release.151029-1700

ANALYSIS_SESSION_ELAPSED_TIME:  1835

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0xef_csrss.exe_bugcheck_critical_process_5c24a080_ntdll!rtllookupfunctionentry

FAILURE_ID_HASH:  {5d2f78b4-ca91-8ec3-8d01-d5e18cffafe1}

Followup:     MachineOwner
---------



最后更新:2017-08-16 11:02:26

  上一篇:go Win10
  下一篇:go 所有图片类应用程序,在“打开文件”对话框弹出后程序崩溃