locked
系统老是蓝屏 RRS feed

  • 问题

  • 这个问题 已经出现过好几次了

    蓝屏代码是:stop:0x0000034

     

    在网上实在是找不到问题处在呢个地方了,希望各位大侠给帮忙指点一二

    这个是我的dmp文件

    https://cid-56aea1d4bb59d2a4.office.live.com/self.aspx/%e5%85%b1%e4%ba%ab/060811-21699-01.dmp

    https://cid-56aea1d4bb59d2a4.office.live.com/self.aspx/%e5%85%b1%e4%ba%ab/060811-23478-01.dmp

    我不会分析,还希望各位帮忙看看……

    对不起哦,我刚才有仔细的看了一下dmp文件,发现了这样一个问题Image path: \??\C:\Program Files\IObit\Password Folder\pffilter.sys


    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Windows\Minidump\060811-23478-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7601.17592.x86fre.win7sp1_gdr.110408-1631
    Machine Name:
    Kernel base = 0x8424f000 PsLoadedModuleList = 0x843984d0
    Debug session time: Wed Jun  8 08:04:39.188 2011 (GMT+8)
    System Uptime: 0 days 0:01:46.359
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    .....................................
    Loading User Symbols
    Loading unloaded module list
    ......
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    CACHE_MANAGER (34)
        See the comment for FAT_FILE_SYSTEM (0x23)
    Arguments:
    Arg1: 00050853
    Arg2: 8d5735f4
    Arg3: 8d5731d0
    Arg4: 844b6eee

    Debugging Details:
    ------------------


    EXCEPTION_RECORD:  8d5735f4 -- (.exr 0xffffffff8d5735f4)
    ExceptionAddress: 844b6eee (nt!RtlPrefixUnicodeString+0x000000f7)
       ExceptionCode: c0000005 (Access violation)
      ExceptionFlags: 00000000
    NumberParameters: 2
       Parameter[0]: 00000000
       Parameter[1]: 00000000
    Attempt to read from address 00000000

    CONTEXT:  8d5731d0 -- (.cxr 0xffffffff8d5731d0)
    eax=0000005c ebx=86713890 ecx=000000d8 edx=88d50840 esi=772af7c0 edi=88d508b6
    eip=844b6eee esp=8d5736bc ebp=8d5736c8 iopl=0         nv up ei pl nz na pe cy
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
    nt!RtlPrefixUnicodeString+0xf7:
    844b6eee 663b0416        cmp     ax,word ptr [esi+edx]    ds:0023:00000000=????
    Resetting default scope

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  NULL_DEREFERENCE

    PROCESS_NAME:  System

    CURRENT_IRQL:  0

    ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx

    EXCEPTION_PARAMETER1:  00000000

    EXCEPTION_PARAMETER2:  00000000

    READ_ADDRESS: GetPointerFromAddress: unable to read from 843b8848
    Unable to read MiSystemVaType memory at 84397e20
     00000000

    FOLLOWUP_IP:
    pffilter+3022
    83c29022 ??              ???

    FAULTING_IP:
    nt!RtlPrefixUnicodeString+f7
    844b6eee 663b0416        cmp     ax,word ptr [esi+edx]

    BUGCHECK_STR:  0x34

    LAST_CONTROL_TRANSFER:  from 83c29022 to 844b6eee

    STACK_TEXT: 
    8d5736c8 83c29022 88d508b6 867112fc 00000000 nt!RtlPrefixUnicodeString+0xf7
    WARNING: Stack unwind information not available. Following frames may be wrong.
    8d5736e4 83c290e0 88d50620 88d50838 867112fc pffilter+0x3022
    8d5736fc 83c29193 88d505f0 867112fc 00000002 pffilter+0x30e0
    8d573720 83c293ae 867112fc 00000010 02080000 pffilter+0x3193
    8d573948 83c2835d 866cad40 00000002 89457570 pffilter+0x33ae
    8d573b78 84286593 88d524d0 866f0d50 866f0d50 pffilter+0x235d
    8d573b90 84313a24 86713891 894db180 866cad42 nt!IofCallDriver+0x63
    8d573bac 844cfb4b 866cad40 86473d48 894db1b8 nt!IoPageRead+0x1f5
    8d573be0 844cfe5d 866d54c0 00000001 0001f000 nt!MiPfExecuteReadList+0x10c
    8d573c08 842851e4 00001000 00000000 0001f000 nt!MmPrefetchForCacheManager+0xa4
    8d573ca8 842e9354 866cad40 adb0d55c 86463388 nt!CcPerformReadAhead+0x1ab
    8d573d00 842ccaab 86463388 00000000 86473d48 nt!CcWorkerThread+0x18d
    8d573d50 84457f64 00000000 adb0d5cc 00000000 nt!ExpWorkerThread+0x10d
    8d573d90 84300219 842cc99e 00000000 00000000 nt!PspSystemThreadStartup+0x9e
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


    SYMBOL_STACK_INDEX:  1

    SYMBOL_NAME:  pffilter+3022

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: pffilter

    IMAGE_NAME:  pffilter.sys

    DEBUG_FLR_IMAGE_TIMESTAMP:  4ce796dd

    STACK_COMMAND:  .cxr 0xffffffff8d5731d0 ; kb

    FAILURE_BUCKET_ID:  0x34_pffilter+3022

    BUCKET_ID:  0x34_pffilter+3022

    Followup: MachineOwner
    ---------

    1: kd> lmvm pffilter
    start    end        module name
    83c26000 83c50000   pffilter T (no symbols)          
        Loaded symbol image file: pffilter.sys
        Image path: \??\C:\Program Files\IObit\Password Folder\pffilter.sys
        Image name: pffilter.sys
        Timestamp:        Sat Nov 20 17:37:33 2010 (4CE796DD)
        CheckSum:         00013A4B
        ImageSize:        0002A000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    1: kd> .cxr 0xffffffff8d5731d0
    eax=0000005c ebx=86713890 ecx=000000d8 edx=88d50840 esi=772af7c0 edi=88d508b6
    eip=844b6eee esp=8d5736bc ebp=8d5736c8 iopl=0         nv up ei pl nz na pe cy
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010207
    nt!RtlPrefixUnicodeString+0xf7:
    844b6eee 663b0416        cmp     ax,word ptr [esi+edx]    ds:0023:00000000=????
    1: kd> .exr 0xffffffff8d5735f4
    ExceptionAddress: 844b6eee (nt!RtlPrefixUnicodeString+0x000000f7)
       ExceptionCode: c0000005 (Access violation)
      ExceptionFlags: 00000000
    NumberParameters: 2
       Parameter[0]: 00000000
       Parameter[1]: 00000000
    Attempt to read from address 00000000


    一直在淡定,从未被超越……


    2011年6月8日 2:59

答案

  • 你好,

     

    pffilter.sys 是指IObit Information Technology公司的Password Folder filter driver. 请问你有没有装过该公司的相关软件,如果有的话,尝试重新安装检查。

     

    Alex Zhao


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    2011年6月10日 9:42
    版主