楼主: 88sad88
收起左侧

[系统] 蓝屏 求分析

[复制链接]
swq0503
发表于 2014-6-10 10:33:25 | 显示全部楼层
88sad88 发表于 2014-6-10 10:32
我也是用这个打开的啊 看到的信息很少啊

参考这个http://support.icafe8.com/technologynews/focus/932.html
需要输入命令
88sad88
 楼主| 发表于 2014-6-10 10:35:58 | 显示全部楼层
swq0503 发表于 2014-6-10 10:33
参考这个http://support.icafe8.com/technologynews/focus/932.html
需要输入命令

这样啊 3Q
swq0503
发表于 2014-6-10 10:38:04 | 显示全部楼层

3Q不是3RQ啊

评分

参与人数 1人气 +3 收起 理由
88sad88 + 3

查看全部评分

88sad88
 楼主| 发表于 2014-6-10 11:00:47 | 显示全部楼层

Symbol search path is: srv*c:\mss*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18205.x86fre.win7sp1_gdr.130708-1532
Machine Name:
Kernel base = 0x84400000 PsLoadedModuleList = 0x845494d0
Debug session time: Tue Jun 10 08:19:59.444 2014 (UTC + 8:00)
System Uptime: 0 days 0:24:18.568
Loading Kernel Symbols
...............................................................
................................................................
.........................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck F4, {3, 88a42910, 88a42a7c, 84618ea0}

----- ETW minidump data unavailable-----
Probably caused by : csrss.exe

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 88a42910, Terminating object
Arg3: 88a42a7c, Process image file name
Arg4: 84618ea0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: 88a42910

IMAGE_NAME:  csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MODULE_NAME: csrss

FAULTING_MODULE: 00000000

PROCESS_NAME:  csrss.exe

EXCEPTION_RECORD:  8f821be0 -- (.exr 0xffffffff8f821be0)
ExceptionAddress: 777f33b1
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000001
   Parameter[1]: 02930ffc
Attempt to write to address 02930ffc

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

EXCEPTION_PARAMETER1:  00000001

EXCEPTION_PARAMETER2:  02930ffc

WRITE_ADDRESS: GetPointerFromAddress: unable to read from 8456984c
Unable to read MiSystemVaType memory at 84548e20
02930ffc

FOLLOWUP_IP:
+0
777f33b1 ??              ???

FAULTING_IP:
+0
777f33b1 ??              ???

FAILED_INSTRUCTION_ADDRESS:
+0
777f33b1 ??              ???

BUGCHECK_STR:  0xF4_8f82141c

STACK_TEXT:  
8f821480 846de3fb 000000f4 00000003 88a42910 nt!KeBugCheckEx+0x1e
8f8214a4 8465bfd5 84618ea0 88a42a7c 88a42b80 nt!PspCatchCriticalBreak+0x71
8f8214d4 8465bf18 88a42910 89465798 c0000005 nt!PspTerminateAllThreads+0x2d
8f821528 8449afe3 00000000 8f82141c 00003fe9 nt!NtTerminateProcess+0x1a2
8f8215b0 8443d8c6 ffffffff c0000005 8f821bc4 nt!MiCheckVirtualAddress+0x4c
8f8215b0 8443caf9 ffffffff c0000005 8f821bc4 nt!KiSystemServicePostCall
8f821630 844b46bb ffffffff c0000005 0001007f nt!ZwTerminateProcess+0x11
8f821bc4 8443e4a6 8f821be0 00000000 8f821c34 nt!KiDispatchException+0x497
8f821c2c 8443e45a 02931040 777f33b1 badb0d00 nt!CommonDispatchException+0x4a
8f821c34 777f33b1 badb0d00 7787cc30 00000000 nt!Kei386EoiHelper+0x192
WARNING: Frame IP not in any known module. Following frames may be wrong.
8f821c38 badb0d00 7787cc30 00000000 00000000 0x777f33b1
8f821c3c 7787cc30 00000000 00000000 00000000 0xbadb0d00
8f821c40 00000000 00000000 00000000 00000000 0x7787cc30


STACK_COMMAND:  kb

FOLLOWUP_NAME:  MachineOwner

FAILURE_BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 88a42910, Terminating object
Arg3: 88a42a7c, Process image file name
Arg4: 84618ea0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: 88a42910

IMAGE_NAME:  csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MODULE_NAME: csrss

FAULTING_MODULE: 00000000

PROCESS_NAME:  csrss.exe

EXCEPTION_RECORD:  8f821be0 -- (.exr 0xffffffff8f821be0)
ExceptionAddress: 777f33b1
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000001
   Parameter[1]: 02930ffc
Attempt to write to address 02930ffc

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

EXCEPTION_PARAMETER1:  00000001

EXCEPTION_PARAMETER2:  02930ffc

WRITE_ADDRESS: GetPointerFromAddress: unable to read from 8456984c
Unable to read MiSystemVaType memory at 84548e20
02930ffc

FOLLOWUP_IP:
+0
777f33b1 ??              ???

FAULTING_IP:
+0
777f33b1 ??              ???

FAILED_INSTRUCTION_ADDRESS:
+0
777f33b1 ??              ???

BUGCHECK_STR:  0xF4_8f82141c

STACK_TEXT:  
8f821480 846de3fb 000000f4 00000003 88a42910 nt!KeBugCheckEx+0x1e
8f8214a4 8465bfd5 84618ea0 88a42a7c 88a42b80 nt!PspCatchCriticalBreak+0x71
8f8214d4 8465bf18 88a42910 89465798 c0000005 nt!PspTerminateAllThreads+0x2d
8f821528 8449afe3 00000000 8f82141c 00003fe9 nt!NtTerminateProcess+0x1a2
8f8215b0 8443d8c6 ffffffff c0000005 8f821bc4 nt!MiCheckVirtualAddress+0x4c
8f8215b0 8443caf9 ffffffff c0000005 8f821bc4 nt!KiSystemServicePostCall
8f821630 844b46bb ffffffff c0000005 0001007f nt!ZwTerminateProcess+0x11
8f821bc4 8443e4a6 8f821be0 00000000 8f821c34 nt!KiDispatchException+0x497
8f821c2c 8443e45a 02931040 777f33b1 badb0d00 nt!CommonDispatchException+0x4a
8f821c34 777f33b1 badb0d00 7787cc30 00000000 nt!Kei386EoiHelper+0x192
WARNING: Frame IP not in any known module. Following frames may be wrong.
8f821c38 badb0d00 7787cc30 00000000 00000000 0x777f33b1
8f821c3c 7787cc30 00000000 00000000 00000000 0xbadb0d00
8f821c40 00000000 00000000 00000000 00000000 0x7787cc30


STACK_COMMAND:  kb

FOLLOWUP_NAME:  MachineOwner

FAILURE_BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 88a42910, Terminating object
Arg3: 88a42a7c, Process image file name
Arg4: 84618ea0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: 88a42910

IMAGE_NAME:  csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MODULE_NAME: csrss

FAULTING_MODULE: 00000000

PROCESS_NAME:  csrss.exe

EXCEPTION_RECORD:  8f821be0 -- (.exr 0xffffffff8f821be0)
ExceptionAddress: 777f33b1
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000001
   Parameter[1]: 02930ffc
Attempt to write to address 02930ffc

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

EXCEPTION_PARAMETER1:  00000001

EXCEPTION_PARAMETER2:  02930ffc

WRITE_ADDRESS: GetPointerFromAddress: unable to read from 8456984c
Unable to read MiSystemVaType memory at 84548e20
02930ffc

FOLLOWUP_IP:
+0
777f33b1 ??              ???

FAULTING_IP:
+0
777f33b1 ??              ???

FAILED_INSTRUCTION_ADDRESS:
+0
777f33b1 ??              ???

BUGCHECK_STR:  0xF4_8f82141c

STACK_TEXT:  
8f821480 846de3fb 000000f4 00000003 88a42910 nt!KeBugCheckEx+0x1e
8f8214a4 8465bfd5 84618ea0 88a42a7c 88a42b80 nt!PspCatchCriticalBreak+0x71
8f8214d4 8465bf18 88a42910 89465798 c0000005 nt!PspTerminateAllThreads+0x2d
8f821528 8449afe3 00000000 8f82141c 00003fe9 nt!NtTerminateProcess+0x1a2
8f8215b0 8443d8c6 ffffffff c0000005 8f821bc4 nt!MiCheckVirtualAddress+0x4c
8f8215b0 8443caf9 ffffffff c0000005 8f821bc4 nt!KiSystemServicePostCall
8f821630 844b46bb ffffffff c0000005 0001007f nt!ZwTerminateProcess+0x11
8f821bc4 8443e4a6 8f821be0 00000000 8f821c34 nt!KiDispatchException+0x497
8f821c2c 8443e45a 02931040 777f33b1 badb0d00 nt!CommonDispatchException+0x4a
8f821c34 777f33b1 badb0d00 7787cc30 00000000 nt!Kei386EoiHelper+0x192
WARNING: Frame IP not in any known module. Following frames may be wrong.
8f821c38 badb0d00 7787cc30 00000000 00000000 0x777f33b1
8f821c3c 7787cc30 00000000 00000000 00000000 0xbadb0d00
8f821c40 00000000 00000000 00000000 00000000 0x7787cc30


STACK_COMMAND:  kb

FOLLOWUP_NAME:  MachineOwner

FAILURE_BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 88a42910, Terminating object
Arg3: 88a42a7c, Process image file name
Arg4: 84618ea0, Explanatory message (ascii)

Debugging Details:
------------------

----- ETW minidump data unavailable-----

PROCESS_OBJECT: 88a42910

IMAGE_NAME:  csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MODULE_NAME: csrss

FAULTING_MODULE: 00000000

PROCESS_NAME:  csrss.exe

EXCEPTION_RECORD:  8f821be0 -- (.exr 0xffffffff8f821be0)
ExceptionAddress: 777f33b1
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000001
   Parameter[1]: 02930ffc
Attempt to write to address 02930ffc

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

EXCEPTION_PARAMETER1:  00000001

EXCEPTION_PARAMETER2:  02930ffc

WRITE_ADDRESS: GetPointerFromAddress: unable to read from 8456984c
Unable to read MiSystemVaType memory at 84548e20
02930ffc

FOLLOWUP_IP:
+0
777f33b1 ??              ???

FAULTING_IP:
+0
777f33b1 ??              ???

FAILED_INSTRUCTION_ADDRESS:
+0
777f33b1 ??              ???

BUGCHECK_STR:  0xF4_8f82141c

STACK_TEXT:  
8f821480 846de3fb 000000f4 00000003 88a42910 nt!KeBugCheckEx+0x1e
8f8214a4 8465bfd5 84618ea0 88a42a7c 88a42b80 nt!PspCatchCriticalBreak+0x71
8f8214d4 8465bf18 88a42910 89465798 c0000005 nt!PspTerminateAllThreads+0x2d
8f821528 8449afe3 00000000 8f82141c 00003fe9 nt!NtTerminateProcess+0x1a2
8f8215b0 8443d8c6 ffffffff c0000005 8f821bc4 nt!MiCheckVirtualAddress+0x4c
8f8215b0 8443caf9 ffffffff c0000005 8f821bc4 nt!KiSystemServicePostCall
8f821630 844b46bb ffffffff c0000005 0001007f nt!ZwTerminateProcess+0x11
8f821bc4 8443e4a6 8f821be0 00000000 8f821c34 nt!KiDispatchException+0x497
8f821c2c 8443e45a 02931040 777f33b1 badb0d00 nt!CommonDispatchException+0x4a
8f821c34 777f33b1 badb0d00 7787cc30 00000000 nt!Kei386EoiHelper+0x192
WARNING: Frame IP not in any known module. Following frames may be wrong.
8f821c38 badb0d00 7787cc30 00000000 00000000 0x777f33b1
8f821c3c 7787cc30 00000000 00000000 00000000 0xbadb0d00
8f821c40 00000000 00000000 00000000 00000000 0x7787cc30


STACK_COMMAND:  kb

FOLLOWUP_NAME:  MachineOwner

FAILURE_BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

BUCKET_ID:  0xF4_8f82141c_IMAGE_csrss.exe

Followup: MachineOwner
---------


我这个显示 win7 驱动问题啊
swq0503
发表于 2014-6-10 11:06:52 | 显示全部楼层
88sad88 发表于 2014-6-10 11:00
Symbol search path is: srv*c:\mss*http://msdl.microsoft.com/download/symbols
Executable search pa ...

你有没有安装vista的驱动?我这这么显示的,一般品牌机官网都有相应驱动的
88sad88
 楼主| 发表于 2014-6-10 11:16:35 | 显示全部楼层
swq0503 发表于 2014-6-10 11:06
你有没有安装vista的驱动?我这这么显示的,一般品牌机官网都有相应驱动的

不是啊 我是win7系统
swq0503
发表于 2014-6-10 11:19:03 | 显示全部楼层
本帖最后由 swq0503 于 2014-6-10 11:20 编辑
88sad88 发表于 2014-6-10 11:16
不是啊 我是win7系统


我知道啊,我这边也显示了win7,但下面显示vista
从官网下载相应驱动试试
我这联想的这个样子 输入机箱上的字码 就出来对应型号和驱动了

应该是显卡驱动吧
88sad88
 楼主| 发表于 2014-6-10 11:23:50 | 显示全部楼层
swq0503 发表于 2014-6-10 11:19
我知道啊,我这边也显示了win7,但下面显示vista
从官网下载相应驱动试试
我这联想的这个样子 输入机 ...

不知道 机子不是我自己的
100lj
发表于 2014-6-10 11:35:21 | 显示全部楼层
88sad88 发表于 2014-6-10 11:00
Symbol search path is: srv*c:\mss*http://msdl.microsoft.com/download/symbols
Executable search pa ...

早说了不全,你还不信。
这个才是全的。
Probably caused by : csrss.exe

csrss.exe是系统文件,你检查下csrss.exe的签名和文件位置、大小是否正常。从相同版本正常系统在PE下复制替换该文件试试。
88sad88
 楼主| 发表于 2014-6-10 12:00:38 | 显示全部楼层
100lj 发表于 2014-6-10 11:35
早说了不全,你还不信。
这个才是全的。
Probably caused by : csrss.exe

好吧  我感觉 csrss.exe  应该一般不会出现问题吧  是不是偶然的问题
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-10 20:02 , Processed in 0.125501 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表