閱讀257 返回首頁    go 微軟 go windows


電腦老藍屏50那位大神看看謝謝了!

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\111517-51449-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*D:\Symbols*https://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.23915.amd64fre.win7sp1_ldr.170913-0600
Machine Name:
Kernel base = 0xfffff800`0460f000 PsLoadedModuleList = 0xfffff800`04851750
Debug session time: Wed Nov 15 07:59:44.192 2017 (UTC + 8:00)
System Uptime: 0 days 0:01:26.191
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 50, {fffff8a0039f6000, 0, fffff8000467698e, 0}


Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+3bdaf )

Followup: MachineOwner
---------

2: kd> 
2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8a0039f6000, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8000467698e, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800048bb100
 fffff8a0039f6000 

FAULTING_IP: 
nt!memmove+15e
fffff800`0467698e 4c8b4c0af0      mov     r9,qword ptr [rdx+rcx-10h]

MM_INTERNAL_CODE:  0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x50

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

TRAP_FRAME:  fffff88003883430 -- (.trap 0xfffff88003883430)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000001 rbx=0000000000000000 rcx=0000000009d70010
rdx=fffff89ff9c86000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000467698e rsp=fffff880038835c8 rbp=fffff88003883b60
 r8=000000006929752f  r9=0000001d0000001c r10=0000001f0000001e
r11=0000000009880010 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
nt!memmove+0x15e:
fffff800`0467698e 4c8b4c0af0      mov     r9,qword ptr [rdx+rcx-10h] ds:ff78:fffff8a0`039f6000=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff800046fc70e to fffff8000467fe00

STACK_TEXT:  
fffff880`038832c8 fffff800`046fc70e : 00000000`00000050 fffff8a0`039f6000 00000000`00000000 fffff880`03883430 : nt!KeBugCheckEx
fffff880`038832d0 fffff800`0467df2e : 00000000`00000000 fffff8a0`039f6000 fffff800`0480ff00 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x3bdaf
fffff880`03883430 fffff800`0467698e : fffff800`04ad11b7 0000007f`ffffff01 00000000`00000000 00000001`00000001 : nt!KiPageFault+0x16e
fffff880`038835c8 fffff800`04ad11b7 : 0000007f`ffffff01 00000000`00000000 00000001`00000001 00000000`0000000d : nt!memmove+0x15e
fffff880`038835d0 fffff800`049df871 : 00000000`09880010 fffff800`69788000 fffff880`03883730 fffff800`046a9001 : nt!PfGetCompletedTrace+0x307
fffff880`03883660 fffff800`04990923 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt! ?? ::NNGAKEGL::`string'+0x379c4
fffff880`038836f0 fffff800`04991199 : 00000000`00faec48 fffff880`03883b60 00000000`0002bff0 00000000`00faec48 : nt!ExpQuerySystemInformation+0x1193
fffff880`03883aa0 fffff800`0467f093 : 00000000`00000001 fffffa80`0ab12750 00000000`0002bff0 00000000`017b8ba0 : nt!NtQuerySystemInformation+0x4d
fffff880`03883ae0 00000000`76d6c09a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00faec08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76d6c09a


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt! ?? ::FNODOBFM::`string'+3bdaf
fffff800`046fc70e cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+3bdaf

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  59b946d1

FAILURE_BUCKET_ID:  X64_0x50_nt!_??_::FNODOBFM::_string_+3bdaf

BUCKET_ID:  X64_0x50_nt!_??_::FNODOBFM::_string_+3bdaf

Followup: MachineOwner
---------

2: kd> !process
GetPointerFromAddress: unable to read from fffff800048bb000
PROCESS fffffa800aafd060
    SessionId: none  Cid: 072c    Peb: 7fffffdb000  ParentCid: 02a0
    DirBase: 70161000  ObjectTable: fffff8a00188c830  HandleCount: <Data Not Accessible>
    Image: svchost.exe
    VadRoot fffffa800aafdf70 Vads 85 Clone 0 Private 458238. Modified 13. Locked 0.
    DeviceMap fffff8a000008bc0
    Token                             fffff8a001899c40
    ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
    ElapsedTime                       00:00:00.000
    UserTime                          00:00:00.000
    KernelTime                        00:00:00.000
    QuotaPoolUsage[PagedPool]         0
    QuotaPoolUsage[NonPagedPool]      0
    Working Set Sizes (now,min,max)  (459327, 50, 345) (1837308KB, 200KB, 1380KB)
    PeakWorkingSetSize                459327
    VirtualSize                       1850 Mb
    PeakVirtualSize                   1850 Mb
    PageFaultCount                    471830
    MemoryPriority                    BACKGROUND
    BasePriority                      8
    CommitCharge                      458495

        *** Error in reading nt!_ETHREAD @ fffffa800ab00b50


最後更新:2017-11-15 09:04:07

  上一篇:go 圖片另存為不能存C盤及D盤自動生成Documents文件夾的bug
  下一篇:go Windows hello無效。