查看: 2196|回复: 0
收起左侧

[系统] 蓝屏求助:win32k.sys,ntkrnlmp.exe

[复制链接]
雾以泪聚.
发表于 2018-6-14 22:56:55 | 显示全部楼层 |阅读模式
这几天疯狂蓝屏两天大概有十七八次的样子

而且大多找不到dmp文件,只有最近的一次找到了minidump,打开这个minidump的时候windbg提示发现memory.dmp问我是否打开,我选是结果来了个打开失败,再找又找不到了


这个是windbg的:

  1. Microsoft (R) Windows Debugger Version 10.0.17674.1000 AMD64
  2. Copyright (c) Microsoft Corporation. All rights reserved.


  3. Loading Dump File [C:\Windows\Minidump\061418-18390-01.dmp]
  4. Mini Kernel Dump File: Only registers and stack trace are available

  5. Symbol search path is: srv*
  6. Executable search path is:
  7. Windows 10 Kernel Version 17134 MP (4 procs) Free x64
  8. Product: WinNt, suite: TerminalServer SingleUserTS Personal
  9. Built by: 17134.1.amd64fre.rs4_release.180410-1804
  10. Machine Name:
  11. Kernel base = 0xfffff800`3ac09000 PsLoadedModuleList = 0xfffff800`3afc62f0
  12. Debug session time: Thu Jun 14 18:47:05.194 2018 (UTC + 8:00)
  13. System Uptime: 0 days 0:07:01.168
  14. Loading Kernel Symbols
  15. .

  16. Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
  17. Run !sym noisy before .reload to track down problems loading symbols.

  18. ..............................................................
  19. ................................................................
  20. ................................................................
  21. ...............
  22. Loading User Symbols
  23. Loading unloaded module list
  24. ...........
  25. *******************************************************************************
  26. *                                                                             *
  27. *                        Bugcheck Analysis                                    *
  28. *                                                                             *
  29. *******************************************************************************

  30. Use !analyze -v to get detailed debugging information.

  31. BugCheck 3B, {c0000006, fffff8003b0dc292, fffff20e03d86c90, 0}

  32. *** WARNING: Unable to verify timestamp for win32k.sys
  33. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  34. Probably caused by : ntkrnlmp.exe ( nt!HvpGetCellPaged+a2 )

  35. Followup:     MachineOwner
  36. ---------

  37. nt!KeBugCheckEx:
  38. fffff800`3ada0680 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:fffff20e`03d863c0=000000000000003b

  39. 2: kd>  !analyze -v
  40. *******************************************************************************
  41. *                                                                             *
  42. *                        Bugcheck Analysis                                    *
  43. *                                                                             *
  44. *******************************************************************************

  45. SYSTEM_SERVICE_EXCEPTION (3b)
  46. An exception happened while executing a system service routine.
  47. Arguments:
  48. Arg1: 00000000c0000006, Exception code that caused the bugcheck
  49. Arg2: fffff8003b0dc292, Address of the instruction which caused the bugcheck
  50. Arg3: fffff20e03d86c90, Address of the context record for the exception that caused the bugcheck
  51. Arg4: 0000000000000000, zero.

  52. Debugging Details:
  53. ------------------


  54. KEY_VALUES_STRING: 1


  55. STACKHASH_ANALYSIS: 1

  56. TIMELINE_ANALYSIS: 1


  57. DUMP_CLASS: 1

  58. DUMP_QUALIFIER: 400

  59. BUILD_VERSION_STRING:  17134.1.amd64fre.rs4_release.180410-1804

  60. SYSTEM_MANUFACTURER:  Dell Inc.

  61. SYSTEM_PRODUCT_NAME:  Inspiron 7560

  62. SYSTEM_SKU:  0782

  63. BIOS_VENDOR:  Dell Inc.

  64. BIOS_VERSION:  1.5.4

  65. BIOS_DATE:  01/31/2018

  66. BASEBOARD_MANUFACTURER:  Dell Inc.

  67. BASEBOARD_PRODUCT:  036R0F

  68. BASEBOARD_VERSION:  A00

  69. DUMP_TYPE:  2

  70. BUGCHECK_P1: c0000006

  71. BUGCHECK_P2: fffff8003b0dc292

  72. BUGCHECK_P3: fffff20e03d86c90

  73. BUGCHECK_P4: 0

  74. EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - <Unable to get error code text>

  75. FAULTING_IP:
  76. nt!HvpGetCellPaged+a2
  77. fffff800`3b0dc292 418b02          mov     eax,dword ptr [r10]

  78. CONTEXT:  fffff20e03d86c90 -- (.cxr 0xfffff20e03d86c90)
  79. rax=0000000000000000 rbx=fffff20e03d876d8 rcx=0000000000000007
  80. rdx=00000000030b9020 rsi=ffffb00b82e4be48 rdi=ffffb00b839f5000
  81. rip=fffff8003b0dc292 rsp=fffff20e03d87688 rbp=fffff20e03d87751
  82. r8=000000000000001c  r9=ffffc4898455f080 r10=00000000030da020
  83. r11=0000000000000020 r12=0000000000000000 r13=0000000000000000
  84. r14=00000000030b9020 r15=0000000000000000
  85. iopl=0         nv up ei pl nz na pe nc
  86. cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010202
  87. nt!HvpGetCellPaged+0xa2:
  88. fffff800`3b0dc292 418b02          mov     eax,dword ptr [r10] ds:002b:00000000`030da020=????????
  89. Resetting default scope

  90. CPU_COUNT: 4

  91. CPU_MHZ: a98

  92. CPU_VENDOR:  GenuineIntel

  93. CPU_FAMILY: 6

  94. CPU_MODEL: 8e

  95. CPU_STEPPING: 9

  96. CPU_MICROCODE: 6,8e,9,0 (F,M,S,R)  SIG: 84'00000000 (cache) 84'00000000 (init)

  97. BLACKBOXBSD: 1 (!blackboxbsd)


  98. BLACKBOXPNP: 1 (!blackboxpnp)


  99. CUSTOMER_CRASH_COUNT:  1

  100. DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

  101. BUGCHECK_STR:  0x3B

  102. PROCESS_NAME:  Registry

  103. CURRENT_IRQL:  0

  104. ANALYSIS_SESSION_HOST:  NORTHWORD-DELL

  105. ANALYSIS_SESSION_TIME:  06-14-2018 22:32:45.0949

  106. ANALYSIS_VERSION: 10.0.17674.1000 amd64fre

  107. LAST_CONTROL_TRANSFER:  from fffff8003b0d6350 to fffff8003b0dc292

  108. STACK_TEXT:  
  109. fffff20e`03d87688 fffff800`3b0d6350 : ffffb00b`839f5000 00000000`00000000 00000000`00000358 00000000`00000000 : nt!HvpGetCellPaged+0xa2
  110. fffff20e`03d87690 fffff800`3b0d5efa : 00000000`00000005 fffff20e`03d87880 00000000`00000001 00000000`00000000 : nt!CmEnumerateKey+0x1c0
  111. fffff20e`03d877a0 fffff800`3adb3223 : ffffb00b`858b59d0 fffff800`3b0e599d 00000000`00000000 00000000`00000000 : nt!NtEnumerateKey+0x2ea
  112. fffff20e`03d87990 00007ff8`968ea5d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  113. 0000003c`63dfed38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`968ea5d4


  114. THREAD_SHA1_HASH_MOD_FUNC:  e9711201a136cc12bc8c3d158cdcfbec0855aeb1

  115. THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  941e50129cefbc90d68ac27c0ee3cad5dc2e13f6

  116. THREAD_SHA1_HASH_MOD:  d084f7dfa548ce4e51810e4fd5914176ebc66791

  117. FOLLOWUP_IP:
  118. nt!HvpGetCellPaged+a2
  119. fffff800`3b0dc292 418b02          mov     eax,dword ptr [r10]

  120. FAULT_INSTR_CODE:  41028b41

  121. SYMBOL_STACK_INDEX:  0

  122. SYMBOL_NAME:  nt!HvpGetCellPaged+a2

  123. FOLLOWUP_NAME:  MachineOwner

  124. MODULE_NAME: nt

  125. IMAGE_NAME:  ntkrnlmp.exe

  126. DEBUG_FLR_IMAGE_TIMESTAMP:  5b015ac2

  127. IMAGE_VERSION:  10.0.17134.81

  128. STACK_COMMAND:  .cxr 0xfffff20e03d86c90 ; kb

  129. BUCKET_ID_FUNC_OFFSET:  a2

  130. FAILURE_BUCKET_ID:  0x3B_nt!HvpGetCellPaged

  131. BUCKET_ID:  0x3B_nt!HvpGetCellPaged

  132. PRIMARY_PROBLEM_CLASS:  0x3B_nt!HvpGetCellPaged

  133. TARGET_TIME:  2018-06-14T10:47:05.000Z

  134. OSBUILD:  17134

  135. OSSERVICEPACK:  81

  136. SERVICEPACK_NUMBER: 0

  137. OS_REVISION: 0

  138. SUITE_MASK:  784

  139. PRODUCT_TYPE:  1

  140. OSPLATFORM_TYPE:  x64

  141. OSNAME:  Windows 10

  142. OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS Personal

  143. OS_LOCALE:  

  144. USER_LCID:  0

  145. OSBUILD_TIMESTAMP:  2018-05-20 19:23:46

  146. BUILDDATESTAMP_STR:  180410-1804

  147. BUILDLAB_STR:  rs4_release

  148. BUILDOSVER_STR:  10.0.17134.1.amd64fre.rs4_release.180410-1804

  149. ANALYSIS_SESSION_ELAPSED_TIME:  528b

  150. ANALYSIS_SOURCE:  KM

  151. FAILURE_ID_HASH_STRING:  km:0x3b_nt!hvpgetcellpaged

  152. FAILURE_ID_HASH:  {3f4270b8-7b0a-894a-9742-49f2b066180b}

  153. Followup:     MachineOwner
  154. ---------



  155. 2: kd> !process
  156. PROCESS ffffc4897d2d5040
  157.     SessionId: none  Cid: 0060    Peb: 00000000  ParentCid: 0004
  158.     DirBase: 78c30002  ObjectTable: ffffb00b82828280  HandleCount: <Data Not Accessible>
  159.     Image: Registry
  160.     VadRoot ffffc48982ea7d00 Vads 83 Clone 0 Private 1014. Modified 24537. Locked 0.
  161.     DeviceMap ffffb00b82818b00
  162.     Token                             ffffb00b82823950
  163.     ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  164. fffff78000000000: Unable to get shared data
  165.     ElapsedTime                       00:00:00.000
  166.     UserTime                          00:00:00.000
  167.     KernelTime                        00:00:00.000
  168.     QuotaPoolUsage[PagedPool]         267232
  169.     QuotaPoolUsage[NonPagedPool]      11288
  170.     Working Set Sizes (now,min,max)  (6074, 50, 345) (24296KB, 200KB, 1380KB)
  171.     PeakWorkingSetSize                24606
  172.     VirtualSize                       128 Mb
  173.     PeakVirtualSize                   135 Mb
  174.     PageFaultCount                    45674
  175.     MemoryPriority                    BACKGROUND
  176.     BasePriority                      8
  177.     CommitCharge                      1029

  178.         *** Error in reading nt!_ETHREAD [url=home.php?mod=space&uid=340]@[/url] ffffc4897d30c040
复制代码


我百度了win32k.sys和ntkrnlmp.exe,都是些我不敢动的东西,想知道有没有不重装系统可以解决以后可能的蓝屏
还看到了这个www.cnblogs.com/ae6623/p/5029628.html  我感觉我温度不是很高的样子,就用用word上上网的也不耗资源

这个是dmp文件和dbg出来的文件


求大神告诉一下该怎么解决

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-25 12:35 , Processed in 0.137419 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表