查看: 4347|回复: 21
收起左侧

[已解决] 360 蓝屏

 关闭 [复制链接]
ccsfuture
发表于 2012-6-22 10:58:05 | 显示全部楼层 |阅读模式
本帖最后由 ccsfuture 于 2012-6-23 09:54 编辑



貌似是360的一个驱动,腾讯游戏那个保护模块,以及显卡的一个驱动冲突。最近老蓝屏,受不鸟了。

附上dmp
求高手具体看看啥情况。



这个帖子里的问题就当作素材让高手参考吧,呵呵。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jefffire
头像被屏蔽
发表于 2012-6-22 10:59:39 | 显示全部楼层
排个队,也有个蓝屏,求高手分析
http://yunpan.cn/lk/40t3dvrivc
-oAo-
发表于 2012-6-22 11:10:03 | 显示全部楼层
都与Q管组合?
§夢非夢§
发表于 2012-6-22 11:16:22 | 显示全部楼层
最好别配上Q管,另外请蓝屏的坛友说明360卫士+什么?
GiBson
发表于 2012-6-22 11:27:08 | 显示全部楼层
本帖最后由 GiBson 于 2012-6-22 11:28 编辑

  1. Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
  2. Copyright (c) Microsoft Corporation. All rights reserved.


  3. Loading Dump File [C:\Users\GiBson\Desktop\061812-19078-01.dmp]
  4. Mini Kernel Dump File: Only registers and stack trace are available

  5. WARNING: Whitespace at end of path element
  6. Symbol search path is: srv*c:\DownstreamStore*http://msdl.microsoft.com/download/symbols

  7. Executable search path is:
  8. Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
  9. Product: WinNt, suite: TerminalServer SingleUserTS
  10. Built by: 7601.17803.x86fre.win7sp1_gdr.120330-1504
  11. Machine Name:
  12. Kernel base = 0x84001000 PsLoadedModuleList = 0x8414a4d0
  13. Debug session time: Mon Jun 18 20:22:19.542 2012 (GMT+8)
  14. System Uptime: 0 days 3:41:55.087
  15. Loading Kernel Symbols
  16. ...............................................................
  17. ................................................................
  18. ..........................................
  19. Loading User Symbols
  20. Loading unloaded module list
  21. .........
  22. 2: kd> !analyze -v
  23. *******************************************************************************
  24. *                                                                             *
  25. *                        Bugcheck Analysis                                    *
  26. *                                                                             *
  27. *******************************************************************************

  28. PAGE_FAULT_IN_NONPAGED_AREA (50)
  29. Invalid system memory was referenced.  This cannot be protected by try-except,
  30. it must be protected by a Probe.  Typically the address is just plain bad or it
  31. is pointing at freed memory.
  32. Arguments:
  33. Arg1: bdea3000, memory referenced.
  34. Arg2: 00000000, value 0 = read operation, 1 = write operation.
  35. Arg3: c480d974, If non-zero, the instruction address which referenced the bad memory
  36.         address.
  37. Arg4: 00000000, (reserved)

  38. Debugging Details:
  39. ------------------

  40. Unable to load image \??\C:\Windows\system32\TesSafe.sys, Win32 error 0n2
  41. *** WARNING: Unable to verify timestamp for TesSafe.sys
  42. *** ERROR: Module load completed but symbols could not be loaded for TesSafe.sys
  43. *** WARNING: Unable to verify timestamp for Hookport.sys
  44. *** ERROR: Module load completed but symbols could not be loaded for Hookport.sys

  45. Could not read faulting driver name

  46. READ_ADDRESS: GetPointerFromAddress: unable to read from 8416a848
  47. Unable to read MiSystemVaType memory at 84149e20
  48. bdea3000

  49. FAULTING_IP:
  50. TesSafe+1974
  51. c480d974 a5              movs    dword ptr es:[edi],dword ptr [esi]

  52. MM_INTERNAL_CODE:  0

  53. CUSTOMER_CRASH_COUNT:  1

  54. DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

  55. BUGCHECK_STR:  0x50

  56. PROCESS_NAME:  crossfire.exe

  57. CURRENT_IRQL:  0

  58. TRAP_FRAME:  b612f510 -- (.trap 0xffffffffb612f510)
  59. ErrCode = 00000000
  60. eax=00002180 ebx=0000000f ecx=0000c000 edx=8da12000 esi=bdea3000 edi=8951df9c
  61. eip=c480d974 esp=b612f584 ebp=b612f598 iopl=0         nv up ei ng nz ac po nc
  62. cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010292
  63. TesSafe+0x1974:
  64. c480d974 a5              movs    dword ptr es:[edi],dword ptr [esi] es:0023:8951df9c=???????? ds:0023:bdea3000=????????
  65. Resetting default scope

  66. LAST_CONTROL_TRANSFER:  from 84042468 to 8408f3bf

  67. STACK_TEXT:  
  68. b612f4f8 84042468 00000000 bdea3000 00000000 nt!MmAccessFault+0x106
  69. b612f4f8 c480d974 00000000 bdea3000 00000000 nt!KiTrap0E+0xdc
  70. WARNING: Stack unwind information not available. Following frames may be wrong.
  71. b612f598 c480f76d 8951df94 8951c000 8951c000 TesSafe+0x1974
  72. b612f6d0 c4810ead c480d8ae 8951c000 b612fb08 TesSafe+0x376d
  73. b612f6e0 c4857721 8951c000 8354ea68 86958030 TesSafe+0x4ead
  74. b612fb08 840385be 86958030 8706ebf0 8706ebf0 TesSafe+0x4b721
  75. b612fb20 8422bb09 8354ea68 8706ebf0 8706ec60 nt!IofCallDriver+0x63
  76. b612fb40 8422ecdb 86958030 8354ea68 00000000 nt!IopSynchronousServiceTail+0x1f8
  77. b612fbdc 8427561b 86958030 8706ebf0 00000000 nt!IopXxxControlFile+0x6aa
  78. b612fc10 84d9af4f 0000126c 00000000 00000000 nt!NtDeviceIoControlFile+0x2a
  79. b612fd04 8403f27a 0000126c 00000000 00000000 Hookport+0x4f4f
  80. b612fd04 77427094 0000126c 00000000 00000000 nt!KiFastCallEntry+0x12a
  81. 0919fd5c 00000000 00000000 00000000 00000000 0x77427094


  82. STACK_COMMAND:  kb

  83. FOLLOWUP_IP:
  84. TesSafe+1974
  85. c480d974 a5              movs    dword ptr es:[edi],dword ptr [esi]

  86. SYMBOL_STACK_INDEX:  2

  87. SYMBOL_NAME:  TesSafe+1974

  88. FOLLOWUP_NAME:  MachineOwner

  89. MODULE_NAME: TesSafe

  90. IMAGE_NAME:  TesSafe.sys

  91. DEBUG_FLR_IMAGE_TIMESTAMP:  4edd7664

  92. FAILURE_BUCKET_ID:  0x50_TesSafe+1974

  93. BUCKET_ID:  0x50_TesSafe+1974

  94. Followup: MachineOwner
  95. ---------
复制代码
进程:crossfire.exe(穿越火线)
驱动: TesSafe.sys
好像是腾讯的问题吧。。。。
GiBson
发表于 2012-6-22 11:35:19 | 显示全部楼层
jefffire 发表于 2012-6-22 10:59
排个队,也有个蓝屏,求高手分析
http://yunpan.cn/lk/40t3dvrivc

062112-29811-01.dmp:
进程:System
驱动:NETwNs32.sys(我这里上不了百度,不知道这个是什么驱动
另外一个dump也是这个进程和驱动。。。。
小蚂蚁的梦想
发表于 2012-6-22 12:11:14 | 显示全部楼层
GiBson 发表于 2012-6-22 11:35
062112-29811-01.dmp:
进程:System
驱动:NETwNs32.sys(我这里上不了百度,不知道这个是什么驱动[:3 ...

网卡驱动问题 这个驱动
myzuzong
发表于 2012-6-22 13:11:52 | 显示全部楼层
to be honest, posting things that are automatically generated by windbg like "probably caused by xxx" really does't help. everybody understands what "probably caused by" means, everybody knows how to drag a file into windbg, and everybody can even read the stack backtrace. but not everybody know how to correctly debug a problem. that's why we need software engineer.
ccsfuture
 楼主| 发表于 2012-6-22 13:13:26 | 显示全部楼层
本帖最后由 ccsfuture 于 2012-6-22 13:14 编辑
-oAo- 发表于 2012-6-22 11:10
都与Q管组合?


家里的老爷机 q管不是杀毒管家2合一么,图省事。

不对啊 这是我笔记本的蓝屏记录,这台破电脑没蓝屏!!!!
ccsfuture
 楼主| 发表于 2012-6-22 13:15:45 | 显示全部楼层
GiBson 发表于 2012-6-22 11:27
进程:crossfire.exe(穿越火线)
驱动: TesSafe.sys
好像是腾讯的问题吧。。。。

一开机直接蓝 还没有运行任何程序呢?360和tx是不是对着干啊...........
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 03:52 , Processed in 0.132895 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表