服务器在已经屏蔽 445,135,137,138,139;69端口后依然由于bugcheck重启
开始windows服务器收到永恒之蓝攻击event显示由于bugcheck导致重启,在服务器屏蔽 445,135,137,138,139;69端口后依然由于bugcheck重启,怀疑是驱动问题,请帮忙分析一下memory.dmp.
system log:
The computer has rebooted from a bugcheck. The bugcheck was:
0x000000c5 (0x0000ffff, 0x00000002, 0x00000000, 808933b0).
A dump was saved in: F:\MEMORY.DMP.
memory dump debug:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\123\HBSM25BAP1B_MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: SRV*C:\DevLib\SymbolLocal*https://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (4 procs) Free x86 compatible
Product: LanManNt, suite: Enterprise TerminalServer SingleUserTS
Built by: 3790.srv03_sp2_gdr.120821-0338
Machine Name:
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
Debug session time: Tue May 16 03:02:50.986 2017 (UTC + 8:00)
System Uptime: 417 days 2:19:55.046
Loading Kernel Symbols
...............................................................
...............................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffd700c). Type ".hh dbgerr001" for details
Loading unloaded module list
............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C5, {ffff, d0000002, 0, 808933b0}
Probably caused by : ntkrpamp.exe ( nt!ExAllocatePoolWithTag+838 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000ffff, memory referenced
Arg2: d0000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 808933b0, address which referenced memory
Debugging Details:
------------------
BUGCHECK_STR: 0xC5_D0000002
CURRENT_IRQL: 2
FAULTING_IP:
nt!ExAllocatePoolWithTag+838
808933b0 8b07 mov eax,dword ptr [edi]
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: svchost.exe
TRAP_FRAME: b8f49a58 -- (.trap 0xffffffffb8f49a58)
ErrCode = 00000000
eax=00000000 ebx=808aeae0 ecx=808b4180 edx=f772f568 esi=808aed90 edi=0000ffff
eip=808933b0 esp=b8f49acc ebp=b8f49b08 iopl=0 nv up ei pl nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010207
nt!ExAllocatePoolWithTag+0x838:
808933b0 8b07 mov eax,dword ptr [edi] ds:0023:0000ffff=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 808933b0 to 8088ca3b
STACK_TEXT:
b8f49a58 808933b0 badb0d00 f772f568 e290f500 nt!KiTrap0E+0x2a7
b8f49b08 8093951b 00000000 00000000 e5726854 nt!ExAllocatePoolWithTag+0x838
b8f49b2c 80939c3b 87830468 88d83901 00000000 nt!ObpAllocateObject+0xc9
b8f49b60 80949e9f 88d83901 8b17fad0 00000000 nt!ObCreateObject+0x129
b8f49cc8 8094af23 01e7ef1c 001f03ff 00000000 nt!PspCreateThread+0xb9
b8f49d3c 8088983c 01e7ef1c 001f03ff 00000000 nt!NtCreateThread+0xdd
b8f49d3c 7c82845c 01e7ef1c 001f03ff 00000000 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
01e7f2c8 00000000 00000000 00000000 00000000 0x7c82845c
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+838
808933b0 8b07 mov eax,dword ptr [edi]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExAllocatePoolWithTag+838
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 503382ff
FAILURE_BUCKET_ID: 0xC5_D0000002_nt!ExAllocatePoolWithTag+838
BUCKET_ID: 0xC5_D0000002_nt!ExAllocatePoolWithTag+838
Followup: MachineOwner
---------
最后更新:2017-05-19 07:20:51
上一篇:
windows10更新之后屏幕右下角为什么出现了一个评估副本的东西,并且好像有时间限制
下一篇:
win10更新卡死
wtg
bitlocker锁定硬盘,无法用微软提供的“恢复密钥”解锁,请问有什么办法可以解决该问
windows10创意者15063.138人名模式问题
点击小娜语音后,小娜卡死,桌面略微卡顿,任务栏出现一个小娜的文件夹
屏蔽win10 1703和1709版本升级,其他能正常更新的方法?
surface 的hello开机无法使用
windows live mail 导入 outlook express 6的邮件
Win10 安装 Microsoft Visual C++ 2015 Redistributable
windows server 2012 支持网络设备日志或者安全设备的日志收集吗?
0xc1900101 安装失败
相关内容
你的设备已过期,并缺少重要的安全和质量更新,因此存在风险。让我们带你重回正轨,这样
Microsoft store 无法联网,显示Microsoft Store需要联网,你似乎没有联网
设备以迁移 由于仅部分匹配或匹配不明确,因此无法迁移设备
由于在创建转储期间出错,创建转储文件失败。
发生临时 DNS 错误
应用商店,在我们这边发生问题,无法使你登陆,错误代码: 0xD000000D
照相机不可用,错误代码:0xA00F4244(0xC00DABE0)
应用商店打开异常提示“清单中指定了未知的布局”
自定义扫描Windows defender里面的设备性能和运行状况 黄色感叹号问题
windows预口体验成员内口版本遇到问题需要重启
热门内容
windows10 点开此电脑后,有两个显示硬盘盘符的目录是怎么回事?
windows 10 专业版无法下载中文语言包
KB4056892
win10不能共享文件夹
在Surfacebook上用Windows to go 1703版本,更新后重启蓝屏,无法进入系统
windows10 1709版本更新失败,错误0x8007001f
microdoft visual c++ 2015 redistributable
WIN10 Insider Preview 17025更新失败,错误代码0x80096004
计算机管理服务 出现一个内部错误(INVALID
关于控制面板中的安全和维护内提示Windows defender 防病毒已关闭的问题