WackenSS Skrevet 11. juli 2014 Del Skrevet 11. juli 2014 Prøvde og lese en .dmp fil i Windbg, men som forventet så er det ikke noe jeg forstår noe av, vet ikke om det er feil i loggen eller om loggen har fått de "symbolfilene" den skal. Noen som kan ta meg et steg videre? Pc specs: AMD phenom 9650 Quad core 2.30ghz Fabrikant ASUSTeK Computer INC. Modell M2N32-SLI DELUXE Versjon 1.XX Serienummer 123456789000 Bro Nordbro NVIDIA SPP190 (C51XE) Revision A2 Sørbro NVIDIA nForce 590 SLI Revision A2 CPU Navn AMD Phenom 9650 Quad-Core Processor Cpu kontakt Socket AM2+ (940) Max CPU hastighet 3700MHz Minne sum Reported by BIOS Minne type DDR2 Installed Memory 4096 MBytes Available Memory 4095 MBytes Channels Dual Maksimum kapasitet 16384 MBytes Maksimum minne modul størrelse 4096 MBytes Minne porter 4 Feil retting Ingen System spor ISA 0 PCI 6 AGP 0 VL-BUS 0 EISA 0 PCMCIA 0 ExpressCard 0 MCA 0 Win 7 Ultimate sp1 Video Adapter NVIDIA GeForce 6200SE TurboCache Grafikkprosessor GeForce 6200SE TurboCache Adapter DAC Type Integrated RAMDAC PCI ID 0x10DE / 0x0162 - NVIDIA Corporation / GeForce 6200SE TurboCache PCI sub ID 0x1043 / 0x0345 - ASUSTeK Computer Inc Minne 64 MBytes Dedicated Video Memory 57 MB (60805120) Dedicated System Memory 0 MB (0) Shared System Memory 1007 MB (1056374784) Adapter BIOS String Version 5.44.02.37.06 Adapter BIOS Date 07/21/05 PnP Device Id PCI\VEN_10DE&DEV_0162&SUBSYS_03451043&REV_A1\4&2AD12F4B&0&0020 Video Mode Description 1280 x 1024 x 4294967296 colors Driverversjon 9.18.13.783 Driver Dato 2013-01-31 00:00:00 DirectX DirectX 11 Driver Name nvd3dum.dll Driver Description NVIDIA GeForce 6200SE TurboCache Denne maskinen står og server 6-8 disker og står kjølig uten skjerm og tastatur. Bruker kun teamwiever for og vedlikeholde/flytte filer. Derfor har jeg satt i et enkelt skjermkort for det dekker behovet.. BSOD kommer alltid vis jeg flytter filer, men det kan ta alt fra 2 min till 60 min før blåskjerm. Microsoft ® Windows Debugger Version 6.3.9600.17029 AMD64 Copyright © Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\SERVER\Desktop\071114-24102-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred srv*c:\symboler*http://msdl.microsoft.com/download/symbols ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred srv*c:\symboler*http://msdl.microsoft.com/download/symbols Symbol search path is: srv*c:\symboler*http://msdl.microsoft.com/download/symbols Executable search path is: srv*c:\symboler*http://msdl.microsoft.com/download/symbols Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532 Machine Name: Kernel base = 0xfffff800`02a61000 PsLoadedModuleList = 0xfffff800`02ca46d0 Debug session time: Fri Jul 11 02:44:51.103 2014 (UTC + 2:00) System Uptime: 0 days 5:11:46.976 Loading Kernel Symbols . Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long. Run !sym noisy before .reload to track down problems loading symbols. .............................................................. ................................................................ ................................ Loading User Symbols Loading unloaded module list ...... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1E, {0, 0, 0, 0} ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* Probably caused by : ntkrnlmp.exe ( nt!KiKernelCalloutExceptionHandler+e ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: 0000000000000000, The exception code that was not handled Arg2: 0000000000000000, The address that the exception occurred at Arg3: 0000000000000000, Parameter 0 of the exception Arg4: 0000000000000000, Parameter 1 of the exception Debugging Details: ------------------ ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: System CURRENT_IRQL: 0 ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre DPC_STACK_BASE: FFFFF80000BA2FB0 EXCEPTION_RECORD: fffff80000b9ca18 -- (.exr 0xfffff80000b9ca18) ExceptionAddress: fffff80002a484f8 (hal!HalpKInterruptHeap+0x00000000000004f8) ExceptionCode: c000001d (Illegal instruction) ExceptionFlags: 00000000 NumberParameters: 0 TRAP_FRAME: fffff80000b9cac0 -- (.trap 0xfffff80000b9cac0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffffffffffe7bf rbx=0000000000000000 rcx=fffffa8005072a90 rdx=fffffa80050776a8 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80002a484f8 rsp=fffff80000b9cc58 rbp=0000000000000000 r8=0000000000000000 r9=0000000a94a0f5fc r10=000000000001c392 r11=fffff80002c51e80 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up di ng nz na pe nc hal!HalpKInterruptHeap+0x4f8: fffff800`02a484f8 ?? ??? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002ace5be to fffff80002ad6b90 STACK_TEXT: fffff800`00b9baf8 fffff800`02ace5be : fffff800`00b9bb18 00000000`00000028 fffff800`00b9c270 fffff800`02b01a90 : nt!KeBugCheck fffff800`00b9bb00 fffff800`02b0175d : fffff800`02ce50ec fffff800`02c23a80 fffff800`02a61000 fffff800`00b9ca18 : nt!KiKernelCalloutExceptionHandler+0xe fffff800`00b9bb30 fffff800`02b00535 : fffff800`02c26038 fffff800`00b9bba8 fffff800`00b9ca18 fffff800`02a61000 : nt!RtlpExecuteHandlerForException+0xd fffff800`00b9bb60 fffff800`02b114c1 : fffff800`00b9ca18 fffff800`00b9c270 fffff800`00000000 00000000`00000001 : nt!RtlDispatchException+0x415 fffff800`00b9c240 fffff800`02ad6242 : fffff800`00b9ca18 00000000`00000000 fffff800`00b9cac0 fffff800`02c51e80 : nt!KiDispatchException+0x135 fffff800`00b9c8e0 fffff800`02ad439f : fffff800`00b9cac0 fffff800`02a22800 fffff800`02a48400 fffff800`00000000 : nt!KiExceptionDispatch+0xc2 fffff800`00b9cac0 fffff800`02a484f8 : 00000000`00000000 00000000`0001e296 fffff880`048297f2 00000000`00000010 : nt!KiInvalidOpcodeFault+0x11f fffff800`00b9cc58 00000000`00000000 : 00000000`0001e296 fffff880`048297f2 00000000`00000010 00000000`00000246 : hal!HalpKInterruptHeap+0x4f8 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiKernelCalloutExceptionHandler+e fffff800`02ace5be 90 nop SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035 IMAGE_VERSION: 6.1.7601.18247 FAILURE_BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:x64_0x1e_nt!kikernelcalloutexceptionhandler+e FAILURE_ID_HASH: {31b31670-23d4-78dd-b3a6-d5566ed846e6} Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: 0000000000000000, The exception code that was not handled Arg2: 0000000000000000, The address that the exception occurred at Arg3: 0000000000000000, Parameter 0 of the exception Arg4: 0000000000000000, Parameter 1 of the exception Debugging Details: ------------------ ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: System CURRENT_IRQL: 0 ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre DPC_STACK_BASE: FFFFF80000BA2FB0 EXCEPTION_RECORD: fffff80000b9ca18 -- (.exr 0xfffff80000b9ca18) ExceptionAddress: fffff80002a484f8 (hal!HalpKInterruptHeap+0x00000000000004f8) ExceptionCode: c000001d (Illegal instruction) ExceptionFlags: 00000000 NumberParameters: 0 TRAP_FRAME: fffff80000b9cac0 -- (.trap 0xfffff80000b9cac0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffffffffffe7bf rbx=0000000000000000 rcx=fffffa8005072a90 rdx=fffffa80050776a8 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80002a484f8 rsp=fffff80000b9cc58 rbp=0000000000000000 r8=0000000000000000 r9=0000000a94a0f5fc r10=000000000001c392 r11=fffff80002c51e80 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up di ng nz na pe nc hal!HalpKInterruptHeap+0x4f8: fffff800`02a484f8 ?? ??? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002ace5be to fffff80002ad6b90 STACK_TEXT: fffff800`00b9baf8 fffff800`02ace5be : fffff800`00b9bb18 00000000`00000028 fffff800`00b9c270 fffff800`02b01a90 : nt!KeBugCheck fffff800`00b9bb00 fffff800`02b0175d : fffff800`02ce50ec fffff800`02c23a80 fffff800`02a61000 fffff800`00b9ca18 : nt!KiKernelCalloutExceptionHandler+0xe fffff800`00b9bb30 fffff800`02b00535 : fffff800`02c26038 fffff800`00b9bba8 fffff800`00b9ca18 fffff800`02a61000 : nt!RtlpExecuteHandlerForException+0xd fffff800`00b9bb60 fffff800`02b114c1 : fffff800`00b9ca18 fffff800`00b9c270 fffff800`00000000 00000000`00000001 : nt!RtlDispatchException+0x415 fffff800`00b9c240 fffff800`02ad6242 : fffff800`00b9ca18 00000000`00000000 fffff800`00b9cac0 fffff800`02c51e80 : nt!KiDispatchException+0x135 fffff800`00b9c8e0 fffff800`02ad439f : fffff800`00b9cac0 fffff800`02a22800 fffff800`02a48400 fffff800`00000000 : nt!KiExceptionDispatch+0xc2 fffff800`00b9cac0 fffff800`02a484f8 : 00000000`00000000 00000000`0001e296 fffff880`048297f2 00000000`00000010 : nt!KiInvalidOpcodeFault+0x11f fffff800`00b9cc58 00000000`00000000 : 00000000`0001e296 fffff880`048297f2 00000000`00000010 00000000`00000246 : hal!HalpKInterruptHeap+0x4f8 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiKernelCalloutExceptionHandler+e fffff800`02ace5be 90 nop SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035 IMAGE_VERSION: 6.1.7601.18247 FAILURE_BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:x64_0x1e_nt!kikernelcalloutexceptionhandler+e FAILURE_ID_HASH: {31b31670-23d4-78dd-b3a6-d5566ed846e6} Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: 0000000000000000, The exception code that was not handled Arg2: 0000000000000000, The address that the exception occurred at Arg3: 0000000000000000, Parameter 0 of the exception Arg4: 0000000000000000, Parameter 1 of the exception Debugging Details: ------------------ ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** ************************************************************************* CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT BUGCHECK_STR: 0x1E PROCESS_NAME: System CURRENT_IRQL: 0 ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre DPC_STACK_BASE: FFFFF80000BA2FB0 EXCEPTION_RECORD: fffff80000b9ca18 -- (.exr 0xfffff80000b9ca18) ExceptionAddress: fffff80002a484f8 (hal!HalpKInterruptHeap+0x00000000000004f8) ExceptionCode: c000001d (Illegal instruction) ExceptionFlags: 00000000 NumberParameters: 0 TRAP_FRAME: fffff80000b9cac0 -- (.trap 0xfffff80000b9cac0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffffffffffe7bf rbx=0000000000000000 rcx=fffffa8005072a90 rdx=fffffa80050776a8 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80002a484f8 rsp=fffff80000b9cc58 rbp=0000000000000000 r8=0000000000000000 r9=0000000a94a0f5fc r10=000000000001c392 r11=fffff80002c51e80 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up di ng nz na pe nc hal!HalpKInterruptHeap+0x4f8: fffff800`02a484f8 ?? ??? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80002ace5be to fffff80002ad6b90 STACK_TEXT: fffff800`00b9baf8 fffff800`02ace5be : fffff800`00b9bb18 00000000`00000028 fffff800`00b9c270 fffff800`02b01a90 : nt!KeBugCheck fffff800`00b9bb00 fffff800`02b0175d : fffff800`02ce50ec fffff800`02c23a80 fffff800`02a61000 fffff800`00b9ca18 : nt!KiKernelCalloutExceptionHandler+0xe fffff800`00b9bb30 fffff800`02b00535 : fffff800`02c26038 fffff800`00b9bba8 fffff800`00b9ca18 fffff800`02a61000 : nt!RtlpExecuteHandlerForException+0xd fffff800`00b9bb60 fffff800`02b114c1 : fffff800`00b9ca18 fffff800`00b9c270 fffff800`00000000 00000000`00000001 : nt!RtlDispatchException+0x415 fffff800`00b9c240 fffff800`02ad6242 : fffff800`00b9ca18 00000000`00000000 fffff800`00b9cac0 fffff800`02c51e80 : nt!KiDispatchException+0x135 fffff800`00b9c8e0 fffff800`02ad439f : fffff800`00b9cac0 fffff800`02a22800 fffff800`02a48400 fffff800`00000000 : nt!KiExceptionDispatch+0xc2 fffff800`00b9cac0 fffff800`02a484f8 : 00000000`00000000 00000000`0001e296 fffff880`048297f2 00000000`00000010 : nt!KiInvalidOpcodeFault+0x11f fffff800`00b9cc58 00000000`00000000 : 00000000`0001e296 fffff880`048297f2 00000000`00000010 00000000`00000246 : hal!HalpKInterruptHeap+0x4f8 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiKernelCalloutExceptionHandler+e fffff800`02ace5be 90 nop SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035 IMAGE_VERSION: 6.1.7601.18247 FAILURE_BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:x64_0x1e_nt!kikernelcalloutexceptionhandler+e FAILURE_ID_HASH: {31b31670-23d4-78dd-b3a6-d5566ed846e6} Followup: MachineOwner --------- Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå