阅读506 返回首页    go 微软 go windows


频繁蓝屏 分析了dump文件看不懂 大神帮我看看


Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\jiaopengkang0228\Desktop\110817-16140-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 16299 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 16299.15.amd64fre.rs3_release.170928-1534
Machine Name:
Kernel base = 0xfffff803`67c01000 PsLoadedModuleList = 0xfffff803`67f62fd0
Debug session time: Wed Nov  8 07:38:29.736 2017 (GMT+8)
System Uptime: 1 days 0:35:49.444
Loading Kernel Symbols
...............................................................
................................................................
........................................................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {3f, 2a6ab, 12a67475, cd2b5ded}

*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption

Followup: memory_corruption
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 000000000000003f, The subtype of the bugcheck.
Arg2: 000000000002a6ab
Arg3: 0000000012a67475
Arg4: 00000000cd2b5ded

Debugging Details:
------------------


BUGCHECK_STR:  0x1a_3f

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  CODE_CORRUPTION

PROCESS_NAME:  MemCompression

CURRENT_IRQL:  2

LAST_CONTROL_TRANSFER:  from fffff80367e2b9f8 to fffff80367d64960

STACK_TEXT: 
ffffc304`d96ef338 fffff803`67e2b9f8 : 00000000`0000001a 00000000`0000003f 00000000`0002a6ab 00000000`12a67475 : nt!KeBugCheckEx
ffffc304`d96ef340 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiValidatePagefilePageHash+0x2c4


STACK_COMMAND:  kb

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
    fffff80367c8df08-fffff80367c8df09  2 bytes - nt!MmAccessFault+d68
 [ ff f6:7f fc ]
    fffff80367cad2d5-fffff80367cad2d6  2 bytes - nt!MiIssueHardFault+225 (+0x1f3cd)
 [ 80 f6:00 fc ]
    fffff80367cad698-fffff80367cad699  2 bytes - nt!MiDeleteCachedKernelStack+3c (+0x3c3)
 [ 80 f6:00 fc ]
    fffff80367e27024-fffff80367e27025  2 bytes - nt!MmStoreProbeAndLockPages+b0 (+0x17998c)
 [ 80 fa:00 94 ]
    fffff80367e2bab9-fffff80367e2baba  2 bytes - nt!MiWritePageFileHash+b9 (+0x4a95)
 [ 80 fa:00 94 ]
10 errors : !nt (fffff80367c8df08-fffff80367e2baba)

MODULE_NAME: memory_corruption

IMAGE_NAME:  memory_corruption

FOLLOWUP_NAME:  memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MEMORY_CORRUPTOR:  LARGE

FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_LARGE

BUCKET_ID:  X64_MEMORY_CORRUPTION_LARGE

Followup: memory_corruption
---------

 



最后更新:2017-11-10 18:04:22

  上一篇:go Windows10设置
  下一篇:go 如何了解win10更新中的新增功能