我的电脑又蓝屏了,上次蓝屏的帖子是:http://bbs.kafan.cn/thread-1697508-1-1.html
这次的流程几乎是差不多的,插上电源,按下主机电源按钮,然后本来正常的应该出现“正在启动Windows”的画面之前,就蓝屏了。
经过上次蓝屏后,我已经升级更新BIOS到最新版本了,因为BIOS的更新历史上有“改善了内存的兼容性”、“改善了系统的稳定性”这样的字眼多次出现。所以就更新了,当然是更新成功了,过程中没发现异常,或者是我没发现吧。 但是进入BIOS显示是最新版本的了。
这次蓝屏文件在这里:http://pan.baidu.com/s/1i39iNzf
我用Windbg看过蓝屏文件,好像这一次的蓝屏文件是由微点引起的,不知道我有没有分析错了,貌似我因为蓝屏多次已经开始知道如何分析蓝屏文件了。
- Loading Dump File [D:\软件\蓝屏信息查看诊断\MEMORY.DMP]
- Kernel Summary Dump File: Only kernel address space is available
- Symbol search path is: SRV*C:\Program Files\Symbols*http://msdl.microsoft.com/download/symbols
- Executable search path is:
- Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 7601.17727.x86fre.win7sp1_gdr.111118-2330
- Machine Name:
- Kernel base = 0x8420a000 PsLoadedModuleList = 0x843534d0
- Debug session time: Thu Mar 27 10:30:14.044 2014 (UTC + 8:00)
- System Uptime: 0 days 0:00:13.027
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ..........
- Loading User Symbols
- PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
- Loading unloaded module list
- ....
- 3: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except,
- it must be protected by a Probe. Typically the address is just plain bad or it
- is pointing at freed memory.
- Arguments:
- Arg1: bf0b430d, memory referenced.
- Arg2: 00000000, value 0 = read operation, 1 = write operation.
- Arg3: 8445525d, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 00000002, (reserved)
- Debugging Details:
- ------------------
- *** ERROR: Symbol file could not be found. Defaulted to export symbols for mp110009.sys -
- READ_ADDRESS: bf0b430d
- FAULTING_IP:
- nt!CmQueryValueKey+27f
- 8445525d 8b0e mov ecx,dword ptr [esi]
- MM_INTERNAL_CODE: 2
- DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
- BUGCHECK_STR: 0x50
- PROCESS_NAME: MPSVC2.exe
- CURRENT_IRQL: 0
- TRAP_FRAME: 97f29a30 -- (.trap 0xffffffff97f29a30)
- ErrCode = 00000000
- eax=8f781148 ebx=8f781148 ecx=00000001 edx=8e41c024 esi=bf0b430d edi=97f29ad4
- eip=8445525d esp=97f29aa4 ebp=97f29af8 iopl=0 nv up ei pl zr ac pe cy
- cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010257
- nt!CmQueryValueKey+0x27f:
- 8445525d 8b0e mov ecx,dword ptr [esi] ds:0023:bf0b430d=????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from 8424b478 to 842983ff
- STACK_TEXT:
- 97f29a18 8424b478 00000000 bf0b430d 00000000 nt!MmAccessFault+0x106
- 97f29a18 8445525d 00000000 bf0b430d 00000000 nt!KiTrap0E+0xdc
- 97f29af8 8d203552 8f7e77e8 00000002 08b2dc6c nt!CmQueryValueKey+0x27f
- WARNING: Stack unwind information not available. Following frames may be wrong.
- 97f29bfc 8443dfa1 ffffffff 842c9ccd acdfbfc9 mp110009!f2006+0x1dc0
- 97f29c14 8424828a 000003ac 08b2dd38 00000002 nt!CmOpenKey+0x264
- 97f29c14 771c70b4 000003ac 08b2dd38 00000002 nt!KiFastCallEntry+0x12a
- 08b2dd00 00000000 00000000 00000000 00000000 0x771c70b4
- STACK_COMMAND: kb
- FOLLOWUP_IP:
- mp110009!f2006+1dc0
- 8d203552 8bd8 mov ebx,eax
- SYMBOL_STACK_INDEX: 3
- SYMBOL_NAME: mp110009!f2006+1dc0
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: mp110009
- IMAGE_NAME: mp110009.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 4fbef08f
- FAILURE_BUCKET_ID: 0x50_mp110009!f2006+1dc0
- BUCKET_ID: 0x50_mp110009!f2006+1dc0
- Followup: MachineOwner
- ---------
- 3: kd> !process
- PROCESS 8b228d40 SessionId: 0 Cid: 0478 Peb: 7ffda000 ParentCid: 03b4
- DirBase: cb5b01c0 ObjectTable: 9018b0e8 HandleCount: 239.
- Image: MPSVC2.exe
- VadRoot 8b272158 Vads 267 Clone 0 Private 22366. Modified 1705. Locked 8.
- DeviceMap 8e4089e8
- Token 90193928
- ElapsedTime 00:00:03.276
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- QuotaPoolUsage[PagedPool] 0
- QuotaPoolUsage[NonPagedPool] 0
- Working Set Sizes (now,min,max) (24364, 50, 345) (97456KB, 200KB, 1380KB)
- PeakWorkingSetSize 26268
- VirtualSize 197 Mb
- PeakVirtualSize 201 Mb
- PageFaultCount 44787
- MemoryPriority BACKGROUND
- BasePriority 10
- CommitCharge 23245
- THREAD 8b251030 Cid 0478.047c Teb: 7ffdf000 Win32Thread: fe96fb18 RUNNING on processor 1
- THREAD 8b2ae4e0 Cid 0478.04a0 Teb: 7ffde000 Win32Thread: 00000000 RUNNING on processor 0
- THREAD 89cd0d48 Cid 0478.04a4 Teb: 7ffdd000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Alertable
- 8999b200 SynchronizationTimer
- 89b87030 SynchronizationTimer
- 89b85030 SynchronizationTimer
- THREAD 8b2d2d48 Cid 0478.04ac Teb: 7ffdc000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2ca1a8 NotificationEvent
- 8b302898 SynchronizationEvent
- THREAD 89cfb630 Cid 0478.04b0 Teb: 7ffdb000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2d29e8 NotificationEvent
- THREAD 89cfbd48 Cid 0478.04b8 Teb: 7ffd8000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b0aa5a0 SynchronizationEvent
- THREAD 8b300d48 Cid 0478.04c0 Teb: 7ffd9000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2c6950 NotificationEvent
- THREAD 8b300a60 Cid 0478.04c4 Teb: 7ffd7000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2c3a88 NotificationEvent
- THREAD 8b304788 Cid 0478.04c8 Teb: 7ffd6000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 89cfa440 NotificationEvent
- THREAD 8b300778 Cid 0478.04cc Teb: 7ffd5000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b125bf8 SynchronizationEvent
- THREAD 8b10dcb8 Cid 0478.04d0 Teb: 7ffd4000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 97f25b38 Unknown
- THREAD 8b10d9d0 Cid 0478.04d4 Teb: 7ffd3000 Win32Thread: fe96f8e8 RUNNING on processor 3
- THREAD 8b10d6e8 Cid 0478.04d8 Teb: 7ff9f000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 97f2db38 Unknown
- THREAD 8b26fd48 Cid 0478.04dc Teb: 7ff9e000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 8b2b3180 NotificationEvent
- THREAD 8b26f370 Cid 0478.04e0 Teb: 7ff9d000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 8999b1c0 SynchronizationEvent
- THREAD 8b10d400 Cid 0478.04e4 Teb: 7ff9c000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 8b10d5c8 Semaphore Limit 0x2
- THREAD 89cfaa20 Cid 0478.04e8 Teb: 7ff9b000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 8999b1c0 SynchronizationEvent
- THREAD 8b269658 Cid 0478.04ec Teb: 7ff9a000 Win32Thread: 00000000 WAIT: (DelayExecution) UserMode Non-Alertable
- 8999b1c0 SynchronizationEvent
- THREAD 89aa5210 Cid 0478.04f0 Teb: 7ff99000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2c3e28 NotificationEvent
- THREAD 8b2c6d48 Cid 0478.04f4 Teb: 7ff98000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2cb410 SynchronizationEvent
- THREAD 8b2cb030 Cid 0478.04f8 Teb: 7ff97000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2cb320 SynchronizationEvent
- THREAD 8b3378c8 Cid 0478.04fc Teb: 7ff96000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b2cb558 SynchronizationEvent
- THREAD 8b3078a8 Cid 0478.0500 Teb: 7ff95000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b338870 SynchronizationEvent
- THREAD 8b33f030 Cid 0478.0508 Teb: 7ff94000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 89cee1b0 SynchronizationEvent
- THREAD 8b33f488 Cid 0478.050c Teb: 7ff93000 Win32Thread: 00000000 WAIT: (UserRequest) UserMode Non-Alertable
- 8b33f348 SynchronizationEvent
- THREAD 8b2eea60 Cid 0478.0514 Teb: 7ff91000 Win32Thread: 00000000 ????
复制代码
这次是真的因为微点引起的吗??@伊川书院 |