伊克路西安 发表于 2022-4-25 17:29

刚刚win10蓝屏了,运行了下windbg,求帮忙解析

本帖最后由 伊克路西安 于 2022-4-25 18:54 编辑

Loading Dump File
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.


************* Path validation summary **************
Response                         Time (ms)   Location
Deferred                                       SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 10 Kernel Version 19041 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff801`40a00000 PsLoadedModuleList = 0xfffff801`4162a230
Debug session time: Mon Apr 25 17:03:34.033 2022 (UTC + 8:00)
System Uptime: 0 days 8:24:07.825
Loading Kernel Symbols
...............................................................
..............Page 802fe9 not present in the dump file. Type ".hh dbgerr004" for details
..................................................
................................................................
................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 0000007c`984ef018).Type ".hh dbgerr001" for details
Loading unloaded module list
..................................................
For analysis of this file, run !analyze -v
6: kd> !analyze -v
*******************************************************************************
*                                                                           *
*                        Bugcheck Analysis                                    *
*                                                                           *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041791, The subtype of the bugcheck.
Arg2: ffff980016b581d0
Arg3: ffffe280d993b7e8
Arg4: 0000000000010001

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key: Analysis.CPU.mSec
    Value: 3249

    Key: Analysis.DebugAnalysisManager
    Value: Create

    Key: Analysis.Elapsed.mSec
    Value: 16389

    Key: Analysis.Init.CPU.mSec
    Value: 2124

    Key: Analysis.Init.Elapsed.mSec
    Value: 53902

    Key: Analysis.Memory.CommitPeak.Mb
    Value: 143

    Key: WER.OS.Branch
    Value: vb_release

    Key: WER.OS.Timestamp
    Value: 2019-12-06T14:06:00Z

    Key: WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:1a

BUGCHECK_P1: 41791

BUGCHECK_P2: ffff980016b581d0

BUGCHECK_P3: ffffe280d993b7e8

BUGCHECK_P4: 10001

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

PROCESS_NAME:Photoshop.exe

STACK_TEXT:
fffff908`1a1481b8 fffff801`40c5e341   : 00000000`0000001a 00000000`00041791 ffff9800`16b581d0 ffffe280`d993b7e8 : nt!KeBugCheckEx
fffff908`1a1481c0 fffff801`40c83e17   : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiUnlockPageTableCharges+0x235
fffff908`1a148230 fffff801`40c8551e   : ffffbf81`8133f010 fffff908`1a140102 00000000`00000002 00000000`00000000 : nt!MmUnlockPages+0x477
fffff908`1a148320 fffff801`40c84ed7   : 7fffffff`ffffffff 00000000`00000001 00000000`00000000 ffffbf81`90375a60 : nt!IopfCompleteRequest+0x62e
fffff908`1a148410 fffff801`44204bd8   : ffffbf81`a0ff3c00 00000000`00000001 ffffbf81`a0ff3ce8 00000000`00000000 : nt!IofCompleteRequest+0x17
fffff908`1a148440 fffff801`44218938   : 00000000`00000000 00000000`00000000 00000000`00000001 fffff908`1a148700 : Ntfs!NtfsExtendedCompleteRequestInternal+0x178
fffff908`1a1484a0 fffff801`442177c3   : ffffbf81`a0ff3ce8 ffffbf81`90375a60 fffff908`1a148740 00000000`00000000 : Ntfs!NtfsCommonWrite+0xd08
fffff908`1a1486d0 fffff801`40c8f835   : ffffbf81`99844b20 ffffbf81`90375a60 ffffbf81`90375a60 ffffbf81`852f18d0 : Ntfs!NtfsFsdWrite+0x1d3
fffff908`1a1487a0 fffff801`3e036fcf   : ffffe481`49ce0006 00000000`00000000 ffffbf81`93551080 00000000`00000000 : nt!IofCallDriver+0x55
fffff908`1a1487e0 fffff801`3e034663   : fffff908`1a148870 00000000`00000000 00000000`00000000 ffffbf81`94421c40 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
fffff908`1a148850 fffff801`40c8f835   : ffffbf81`90375a60 fffff801`40c0827e ffffbf81`93551118 ffffbf81`a1fa5cf0 : FLTMGR!FltpDispatch+0xa3
fffff908`1a1488b0 fffff801`41077428   : 00000000`00000001 ffffbf81`a1fa5cf0 00000000`00000001 ffffbf81`90375f20 : nt!IofCallDriver+0x55
fffff908`1a1488f0 fffff801`4108d6ef   : ffffbf81`00000000 fffff908`1a148b80 00000000`00000000 fffff908`1a148b80 : nt!IopSynchronousServiceTail+0x1a8
fffff908`1a148990 fffff801`40e092b8   : 00000000`00000c84 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtWriteFile+0x66f
fffff908`1a148a90 00007ff8`5850ce74   : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000007c`98fff718 00000000`00000000   : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`5850ce74


SYMBOL_NAME:nt!MiUnlockPageTableCharges+235

MODULE_NAME: nt

STACK_COMMAND:.thread ; .cxr ; kb

IMAGE_NAME:ntkrnlmp.exe

BUCKET_ID_FUNC_OFFSET:235

FAILURE_BUCKET_ID:0x1a_41791_nt!MiUnlockPageTableCharges

OS_VERSION:10.0.19041.1

BUILDLAB_STR:vb_release

OSPLATFORM_TYPE:x64

OSNAME:Windows 10

FAILURE_ID_HASH:{0b63eca1-f09f-4462-b984-8ed48733803f}

Followup:   MachineOwner
---------

6: kd> lmvm nt
Browse full module list
start             end               module name
fffff801`40a00000 fffff801`41a46000   nt         (pdb symbols)          c:\symbols\ntkrnlmp.pdb\725DA593BDE0B421BA4B8CA28AA67A421\ntkrnlmp.pdb
    Loaded symbol image file: ntkrnlmp.exe
    Mapped memory image file: c:\symbols\ntoskrnl.exe\06E352931046000\ntoskrnl.exe
    Image path: ntkrnlmp.exe
    Image name: ntkrnlmp.exe
    Browse all global symbolsfunctionsdata
    Image was built with /Brepro flag.
    Timestamp:      06E35293 (This is a reproducible build file hash, not a timestamp)
    CheckSum:         00A683D9
    ImageSize:      01046000
    Translations:   0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Information from resource tables:


照着网上的教程运行了下windbg,但是结果完全看不懂
用vposy的破解版adobe ps的时候突然蓝屏的,但是也开了很多其他软件

以前也有不少次自动重启,不过都是whea-18核心错误,没有蓝屏提示,这次有蓝屏,而且下半屏都花屏了
https://p.sda1.dev/5/0493ac82c687dfe362492438e2e5cdf4/image.png

kjcm150 发表于 2022-4-25 17:42

本帖最后由 kjcm150 于 2022-4-25 17:44 编辑

bugcheck code 1a 对应 MEMORY_MANAGEMENT
1号参数 0x41791 查了微软的文档,没有 0x41790 和 0x41792 都有

whea18是amd的问题吧?不太懂

tsubasa9 发表于 2022-4-25 18:01

whea18
联系售后换cpu

magpte 发表于 2022-4-25 19:35

超频要降频或者换cpu

—— 来自 Xiaomi M2006J10C, Android 12上的 S1Next-鹅版 v2.5.2-play

囧囧囧 发表于 2022-4-25 19:39

whea 18 cpu核心不稳 ;whea 19 fclk过高

伊克路西安 发表于 2022-4-25 19:52

我知道whea18是CPU的问题啦,我这次问的是蓝屏是什么原因= =

kjcm150 发表于 2022-4-26 10:12

伊克路西安 发表于 2022-4-25 19:52
我知道whea18是CPU的问题啦,我这次问的是蓝屏是什么原因= =

肯定跟内存有关啦,跑个内存测试看看

囧囧囧 发表于 2022-4-26 13:31

不换u就试试加电压
页: [1]
查看完整版本: 刚刚win10蓝屏了,运行了下windbg,求帮忙解析