积极答复者
关闭outlook2010,系统就死机

问题
-
今天出现关闭outlook2010,系统就死机,是怎么回事呢?
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\062810-58905-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`04218000 PsLoadedModuleList = 0xfffff800`04455e50
Debug session time: Mon Jun 28 21:59:55.491 2010 (GMT+8)
System Uptime: 0 days 0:12:20.395
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************Use !analyze -v to get detailed debugging information.
BugCheck C5, {8, 2, 0, fffff800043bc0bf}
Unable to load image SYMTDIV.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for SYMTDIV.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMTDIV.SYS
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+233 )Followup: Pool_corruption
---------1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff800043bc0bf, address which referenced memoryDebugging Details:
------------------
BUGCHECK_STR: 0xC5_2CURRENT_IRQL: 2
FAULTING_IP:
nt!ExDeferredFreePool+233
fffff800`043bc0bf 4c395008 cmp qword ptr [rax+8],r10CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: OUTLOOK.EXE
TRAP_FRAME: fffff8800a9bc230 -- (.trap 0xfffff8800a9bc230)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffff80004417b10
rdx=fffff880049fdaf0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800043bc0bf rsp=fffff8800a9bc3c0 rbp=0000000000000000
r8=0000000000000000 r9=fffff880049fdaf0 r10=fffff880049fdb00
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
nt!ExDeferredFreePool+0x233:
fffff800`043bc0bf 4c395008 cmp qword ptr [rax+8],r10 ds:490b:00000000`00000008=????????????????
Resetting default scopeLAST_CONTROL_TRANSFER: from fffff80004287b69 to fffff80004288600
STACK_TEXT:
fffff880`0a9bc0e8 fffff800`04287b69 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a9bc0f0 fffff800`042867e0 : 00000000`00000000 00000000`000000af 0000d3a5`0a9b0010 00000014`016a0006 : nt!KiBugCheckDispatch+0x69
fffff880`0a9bc230 fffff800`043bc0bf : fffffa80`09f67930 00000000`00000014 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x260
fffff880`0a9bc3c0 fffff800`043bd4c1 : 00000000`00000000 fffffa80`04d83000 00000000`00000000 fffffa80`0487f4a0 : nt!ExDeferredFreePool+0x233
fffff880`0a9bc450 fffff880`01c676d6 : 80000004`00000000 fffffa80`04829db0 00000000`45706354 fffff8a0`00000000 : nt!ExFreePoolWithTag+0x411
fffff880`0a9bc500 fffff880`01c68204 : fffff880`0a9ac000 fffff880`0a9bc790 fffffa80`04d83010 fffff880`0a9bc800 : tcpip!TcpCleanupTcbWorkQueueRoutine+0x236
fffff880`0a9bc5a0 fffff880`01c68245 : 00000000`b83eaea5 fffff880`0a9bc790 00000000`00000001 fffff880`0a9ac000 : tcpip!TcpCloseTcb+0x84
fffff880`0a9bc650 fffff800`04297d4a : 00000000`00000000 fffff880`0100931a ffff0000`0b4db085 fffffa80`08fd7010 : tcpip!TcpTlConnectionCloseEndpointCalloutRoutine+0x15
fffff880`0a9bc680 fffff880`01c68460 : fffff880`01c68230 fffff880`0a9bc790 fffffa80`08eeb000 00000000`00000000 : nt!KeExpandKernelStackAndCalloutEx+0xda
fffff880`0a9bc760 fffff880`00de8b4d : fffffa80`0487f4a0 00000000`00000103 00000000`00000000 00000000`00000103 : tcpip!TcpTlConnectionCloseEndpoint+0xa0
fffff880`0a9bc7d0 fffff880`00de8e8f : fffffa80`0487f4a0 00000000`00000000 00000000`00000103 fffffa80`0487f4a0 : tdx!TdxShutdownEndpointConnection+0xcd
fffff880`0a9bc820 fffff880`00deaaa7 : fffffa80`0487f4a0 00000000`00000103 00000000`00000000 fffffa80`114347f0 : tdx!TdxDecrementTlEndpointReference+0x2f
fffff880`0a9bc850 fffff880`00ddf7df : fffffa80`114347f0 00000000`00000103 00000000`00000002 fffffa80`0923a5a4 : tdx!TdxDisconnectConnection+0x417
fffff880`0a9bc960 fffff880`0585d3dd : fffffa80`04b94500 00000000`00000103 00000000`00000002 fffffa80`0923a5a4 : tdx! ?? ::FNODOBFM::`string'+0x8f9
fffff880`0a9bc990 fffffa80`04b94500 : 00000000`00000103 00000000`00000002 fffffa80`0923a5a4 00000000`00000001 : SYMTDIV+0x143dd
fffff880`0a9bc998 00000000`00000103 : 00000000`00000002 fffffa80`0923a5a4 00000000`00000001 fffffa80`090ba890 : 0xfffffa80`04b94500
fffff880`0a9bc9a0 00000000`00000002 : fffffa80`0923a5a4 00000000`00000001 fffffa80`090ba890 00000000`00000000 : 0x103
fffff880`0a9bc9a8 fffffa80`0923a5a4 : 00000000`00000001 fffffa80`090ba890 00000000`00000000 fffff880`0585d37d : 0x2
fffff880`0a9bc9b0 00000000`00000001 : fffffa80`090ba890 00000000`00000000 fffff880`0585d37d fffffa80`04b94500 : 0xfffffa80`0923a5a4
fffff880`0a9bc9b8 fffffa80`090ba890 : 00000000`00000000 fffff880`0585d37d fffffa80`04b94500 00000000`00000002 : 0x1
fffff880`0a9bc9c0 00000000`00000000 : fffff880`0585d37d fffffa80`04b94500 00000000`00000002 fffffa80`04b94500 : 0xfffffa80`090ba890
STACK_COMMAND: kbFOLLOWUP_IP:
nt!ExDeferredFreePool+233
fffff800`043bc0bf 4c395008 cmp qword ptr [rax+8],r10SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExDeferredFreePool+233
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0xC5_2_nt!ExDeferredFreePool+233
BUCKET_ID: X64_0xC5_2_nt!ExDeferredFreePool+233
Followup: Pool_corruption
答案
-
是否安装了Symantec 的杀毒或者防火墙软件?请暂时删除然后看看是否还有问题。
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.- 已标记为答案 Sean Zhu -Moderator 2010年7月9日 0:51
全部回复
-
是否安装了Symantec 的杀毒或者防火墙软件?请暂时删除然后看看是否还有问题。
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.- 已标记为答案 Sean Zhu -Moderator 2010年7月9日 0:51
-
0x000000C5 错误一般是硬件兼容性问题或者硬件设备驱动程序不正确引起,包括虚拟设备驱动。如果卸载 NIS 后可以解决,可能是它添加了某些虚拟设备驱动引起的问题。--Alexis Zhanghttps://mvp.support.microsoft.com/profile/jiehttp://blogs.itecn.net/blogs/alexishttp://social.technet.microsoft.com/Forums/zh-CN/categories微软中文技术论坛Windows 系统组/微软硬件组 版主本帖是回复帖,原帖作者是楼上的 "无聊的蜗牛"今天出现关闭outlook2010,系统就死机,是怎么回事呢?Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
-
删除了NIS,没有问题了,可是不能没有杀毒软件啊?
我从dump的信息里面看到是因为NIS的文件导致的蓝屏。杀毒软件根据个人需要,可以使用微软的免费杀毒软件MSE http://www.microsoft.com/security_essentials/,或者其他品牌。
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.