本帖最后由 扬帆起航 于 2014-9-14 13:23 编辑
以下是dump文件分析:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [G:\091314-28656-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*G:\symbols*D:\symbols;http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17085.amd64fre.winblue_gdr.140330-1035
Machine Name:
Kernel base = 0xfffff800`29481000 PsLoadedModuleList = 0xfffff800`2974b2d0
Debug session time: Sat Sep 13 21:38:07.627 2014 (UTC + 8:00)
System Uptime: 0 days 3:47:52.506
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 9F, {3, ffffe0003a7f1e40, fffff8002b11c930, ffffe0003f8748b0}
Probably caused by : ntkrnlmp
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_POWER_STATE_FAILURE (9f)
A driver is causing an inconsistent power state.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
Arg2: ffffe0003a7f1e40, Physical Device Object of the stack
Arg3: fffff8002b11c930, Functional Device Object of the stack
Arg4: ffffe0003f8748b0, The blocked IRP
Debugging Details:
------------------
DRVPOWERSTATE_SUBCODE: 3
IMAGE_NAME: ntkrnlmp
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAULTING_MODULE: fffff8019f85d000 tunnel
IRP_ADDRESS: ffffe0003f8748b0
DEVICE_OBJECT: ffffe0003d638050
DRIVER_OBJECT: ffffe0003e8674c0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: System
CURRENT_IRQL: 2
STACK_TEXT:
fffff800`2b11c8f8 fffff800`2967dc1e : 00000000`0000009f 00000000`00000003 ffffe000`3a7f1e40 fffff800`2b11c930 : nt!KeBugCheckEx
fffff800`2b11c900 fffff800`2967db3e : ffffe000`3a2e6510 00000000`ffffffff ffffe000`3a2e6550 fffff800`294de240 : nt!PopIrpWatchdogBugcheck+0xde
fffff800`2b11c960 fffff800`294da810 : 00000000`00000000 fffff800`2b11cab0 ffffe000`3a2e6548 fffff800`00000002 : nt!PopIrpWatchdog+0x32
fffff800`2b11c9b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiRetireDpcList+0x4f0
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ntkrnlmp
FAILURE_BUCKET_ID: X64_0x9F_3_IMAGE_ntkrnlmp
BUCKET_ID: X64_0x9F_3_IMAGE_ntkrnlmp
Followup: MachineOwner
---------
0: kd> lmvm ntkrnlmp
start end module name
0: kd> !process
GetPointerFromAddress: unable to read from fffff800297d5000
PROCESS ffffe00039594900
SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 001aa000 ObjectTable: ffffc000e9c03000 HandleCount: <Data Not Accessible>
Image: System
VadRoot ffffe00039e40660 Vads 1 Clone 0 Private 29664. Modified 6426712. Locked 416.
DeviceMap ffffc000e9c0c300
Token ffffc000e9c05600
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 0
QuotaPoolUsage[NonPagedPool] 0
Working Set Sizes (now,min,max) (1022, 50, 450) (4088KB, 200KB, 1800KB)
PeakWorkingSetSize 3948
VirtualSize 128 Mb
PeakVirtualSize 148 Mb
PageFaultCount 429452
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 29667
*** Error in reading nt!_ETHREAD @ ffffe000394f9040
蓝屏代码:0x9f
最近是否在关机 重启 待机 休眠等过程中出现问题(注意检查硬件,特别是电源,主板等,还要检查电源设置) |