windbg分析dmp蓝屏文件_莫名其妙的蓝屏分析

v2-cdc6ba89dff5e3be606b97a65ebbe883_1440w.jpg?source=172ae18b

大量设备升级Win10 后经常出现蓝屏重启。重装系统正常,安装软件后即随机蓝屏。

使用windbg进行蓝屏原因分析。软件地址:

Download Debugging Tools for Windows - WinDbg - Windows drivers​docs.microsoft.com
v2-fa769ba2fd25c9bdd269a736e0942218_ipico.jpg

安装后:

  1. 打开File菜单,选择 Symbol Path.
  2. Symbol Search Path 写入如下代码:srv*c:cache*http://msdl.microsoft.com/download/symbols;

在:kd> 后输入.symfix;.reload 来载入symbol

小内存转储文件的默认路径为“%SystemRoot%Minidump”,即“C:windowsMinidump”文件夹中,文件后缀为dmp。 核心内存转储文件的默认路径为“%SystemRoot%MEMORY.DMP”,即“C:windowsMEMORY.DMP

导入 dump文件,

在:kd>后输入 !analyze -v 开始分析。

Debugging Details:
------------------

Unable to load image HV1351UM.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for HV1351UM.sys
*** ERROR: Module load completed but symbols could not be loaded for HV1351UM.sys

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

FAULTING_IP: 
HV1351UM+35ba
8cfd25ba ??              ???

EXCEPTION_RECORD:  8ef349f8 -- (.exr 0xffffffff8ef349f8)
ExceptionAddress: 8cfd25ba (HV1351UM+0x000035ba)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000000
   Parameter[1]: 0000000c
Attempt to read from address 0000000c

CONTEXT:  8ef345d0 -- (.cxr 0xffffffff8ef345d0)
eax=00000000 ebx=00000000 ecx=8ef34a94 edx=00000000 esi=89820910 edi=89820858
eip=8cfd25ba esp=8ef34ac0 ebp=8ef34acc iopl=0         nv up ei pl zr na pe nc
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010246
HV1351UM+0x35ba:
8cfd25ba ??              ???
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  System

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_PARAMETER1:  00000000

EXCEPTION_PARAMETER2:  0000000c

READ_ADDRESS: GetPointerFromAddress: unable to read from 82fb1850
Unable to read MiSystemVaType memory at 82f90780
 0000000c 

FOLLOWUP_IP: 
HV1351UM+35ba
8cfd25ba ??              ???

BUGCHECK_STR:  0x7E

LAST_CONTROL_TRANSFER:  from 85ed6778 to 8cfd25ba

STACK_TEXT:  
WARNING: Stack unwind information not available. Following frames may be wrong.
8ef34abc 85ed6778 00000002 89820858 8ef34ae8 HV1351UM+0x35ba
8ef34acc 8cfd1de5 89820858 85ed6778 85ed6950 0x85ed6778
8ef34ae8 82e7b129 8982091c 85ed6778 8ef34b8c HV1351UM+0x2de5
8ef34b00 83021108 863c26a8 85e9d690 863c26a8 nt!IofCallDriver+0x63
8ef34b34 83110068 863c26a8 8ef34b68 00000000 nt!IopSynchronousCall+0xba
8ef34b90 82f210c2 863c26a8 00000002 c5783678 nt!IopRemoveDevice+0xd5
8ef34bbc 83107db3 0000000a c5783678 00000000 nt!PnpRemoveLockedDeviceNode+0x16c
8ef34bd0 83108067 00000002 0000000a 00000000 nt!PnpDeleteLockedDeviceNode+0x2d
8ef34c04 8310ba3f 863c26a8 c5783678 00000002 nt!PnpDeleteLockedDeviceNodes+0x4c
8ef34cc4 82ff937f 8ef34cf4 00000000 ccacef10 nt!PnpProcessQueryRemoveAndEject+0x946
8ef34cdc 8300748c 00000000 894240e8 85d11648 nt!PnpProcessTargetDeviceEvent+0x38
8ef34d00 82ec237b 894240e8 00000000 85d11648 nt!PnpDeviceEventWorker+0x216
8ef34d50 830514ef 00000001 aeb27142 00000000 nt!ExpWorkerThread+0x10d
8ef34d90 82ef5a19 82ec226e 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  HV1351UM+35ba

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: HV1351UM

IMAGE_NAME:  HV1351UM.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4ba9c3dc

STACK_COMMAND:  .cxr 0xffffffff8ef345d0 ; kb

FAILURE_BUCKET_ID:  0x7E_HV1351UM+35ba

BUCKET_ID:  0x7E_HV1351UM+35ba

Followup: MachineOwner
---------

分析结束,发现是HV1351UM.sys和内核有冲突,分析结束。

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值