积极答复者
系统蓝屏

问题
-
这个问题 已经出现过好几次了
蓝屏代码是:stop:0x0000034
在网上实在是找不到问题处在呢个地方了,希望各位大侠给帮忙指点一二
这个是我的dmp文件
https://cid-56aea1d4bb59d2a4.office.live.com/self.aspx/%e5%85%b1%e4%ba%ab/060811-21699-01.dmp
https://cid-56aea1d4bb59d2a4.office.live.com/self.aspx/%e5%85%b1%e4%ba%ab/060811-23478-01.dmp
我不会分析,还希望各位帮忙看看……
一直在淡定,从未被超越……
答案
-
请检查 Program Files 是否存在 \IObit\Password Folder 文件夹,如果有则应该是安装了 Password Folder,尝试将其卸载看看还有没有问题。--Alexis Zhanghttp://mvp.support.microsoft.com/profile/jiehttp://blogs.itecn.net/blogs/alexis推荐以 NNTP Bridge 桥接新闻组方式访问论坛以获取最佳用户体验。本帖是回复帖,原帖作者是楼上的 "烂泥"SYMBOL_STACK_INDEX: 1SYMBOL_NAME: pffilter+3022
- 已标记为答案 烂泥行天下 2011年6月10日 5:26
全部回复
-
0x00000034 错误表示 Windows 执行程序代码错误,这个错误并不常见,通常是设备驱动程序有问题引起的。Crash Dump 没有提供什么有用的信息。请问这个错误一般是在什么情况下会出现,包括执行什么特定的操作或修改什么特定的设置?最后一次正常运行的时候有没有添加或修改过任何新硬件或驱动程序?--Alexis Zhanghttp://mvp.support.microsoft.com/profile/jiehttp://blogs.itecn.net/blogs/alexis推荐以 NNTP Bridge 桥接新闻组方式访问论坛以获取最佳用户体验。本帖是回复帖,原帖作者是楼上的 "烂泥"蓝屏代码是:stop:0x0000034在网上实在是找不到问题处在呢个地方了,希望各位大侠给帮忙指点一二
-
这个是我刚刚打开dmp文件看到的
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\060811-23478-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17592.x86fre.win7sp1_gdr.110408-1631
Machine Name:
Kernel base = 0x8424f000 PsLoadedModuleList = 0x843984d0
Debug session time: Wed Jun 8 08:04:39.188 2011 (GMT+8)
System Uptime: 0 days 0:01:46.359
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************CACHE_MANAGER (34)
See the comment for FAT_FILE_SYSTEM (0x23)
Arguments:
Arg1: 00050853
Arg2: 8d5735f4
Arg3: 8d5731d0
Arg4: 844b6eeeDebugging Details:
------------------
EXCEPTION_RECORD: 8d5735f4 -- (.exr 0xffffffff8d5735f4)
ExceptionAddress: 844b6eee (nt!RtlPrefixUnicodeString+0x000000f7)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000000
Attempt to read from address 00000000CONTEXT: 8d5731d0 -- (.cxr 0xffffffff8d5731d0)
eax=0000005c ebx=86713890 ecx=000000d8 edx=88d50840 esi=772af7c0 edi=88d508b6
eip=844b6eee esp=8d5736bc ebp=8d5736c8 iopl=0 nv up ei pl nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010207
nt!RtlPrefixUnicodeString+0xf7:
844b6eee 663b0416 cmp ax,word ptr [esi+edx] ds:0023:00000000=????
Resetting default scopeCUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00000000
READ_ADDRESS: GetPointerFromAddress: unable to read from 843b8848
Unable to read MiSystemVaType memory at 84397e20
00000000FOLLOWUP_IP:
pffilter+3022
83c29022 ?? ???FAULTING_IP:
nt!RtlPrefixUnicodeString+f7
844b6eee 663b0416 cmp ax,word ptr [esi+edx]BUGCHECK_STR: 0x34
LAST_CONTROL_TRANSFER: from 83c29022 to 844b6eee
STACK_TEXT:
8d5736c8 83c29022 88d508b6 867112fc 00000000 nt!RtlPrefixUnicodeString+0xf7
WARNING: Stack unwind information not available. Following frames may be wrong.
8d5736e4 83c290e0 88d50620 88d50838 867112fc pffilter+0x3022
8d5736fc 83c29193 88d505f0 867112fc 00000002 pffilter+0x30e0
8d573720 83c293ae 867112fc 00000010 02080000 pffilter+0x3193
8d573948 83c2835d 866cad40 00000002 89457570 pffilter+0x33ae
8d573b78 84286593 88d524d0 866f0d50 866f0d50 pffilter+0x235d
8d573b90 84313a24 86713891 894db180 866cad42 nt!IofCallDriver+0x63
8d573bac 844cfb4b 866cad40 86473d48 894db1b8 nt!IoPageRead+0x1f5
8d573be0 844cfe5d 866d54c0 00000001 0001f000 nt!MiPfExecuteReadList+0x10c
8d573c08 842851e4 00001000 00000000 0001f000 nt!MmPrefetchForCacheManager+0xa4
8d573ca8 842e9354 866cad40 adb0d55c 86463388 nt!CcPerformReadAhead+0x1ab
8d573d00 842ccaab 86463388 00000000 86473d48 nt!CcWorkerThread+0x18d
8d573d50 84457f64 00000000 adb0d5cc 00000000 nt!ExpWorkerThread+0x10d
8d573d90 84300219 842cc99e 00000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 1SYMBOL_NAME: pffilter+3022
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: pffilter
IMAGE_NAME: pffilter.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce796dd
STACK_COMMAND: .cxr 0xffffffff8d5731d0 ; kb
FAILURE_BUCKET_ID: 0x34_pffilter+3022
BUCKET_ID: 0x34_pffilter+3022
Followup: MachineOwner
---------1: kd> lmvm pffilter
start end module name
83c26000 83c50000 pffilter T (no symbols)
Loaded symbol image file: pffilter.sys
Image path: \??\C:\Program Files\IObit\Password Folder\pffilter.sys
Image name: pffilter.sys
Timestamp: Sat Nov 20 17:37:33 2010 (4CE796DD)
CheckSum: 00013A4B
ImageSize: 0002A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
1: kd> .cxr 0xffffffff8d5731d0
eax=0000005c ebx=86713890 ecx=000000d8 edx=88d50840 esi=772af7c0 edi=88d508b6
eip=844b6eee esp=8d5736bc ebp=8d5736c8 iopl=0 nv up ei pl nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010207
nt!RtlPrefixUnicodeString+0xf7:
844b6eee 663b0416 cmp ax,word ptr [esi+edx] ds:0023:00000000=????
1: kd> .exr 0xffffffff8d5735f4
ExceptionAddress: 844b6eee (nt!RtlPrefixUnicodeString+0x000000f7)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000000
Attempt to read from address 00000000
一直在淡定,从未被超越…… -
请检查 Program Files 是否存在 \IObit\Password Folder 文件夹,如果有则应该是安装了 Password Folder,尝试将其卸载看看还有没有问题。--Alexis Zhanghttp://mvp.support.microsoft.com/profile/jiehttp://blogs.itecn.net/blogs/alexis推荐以 NNTP Bridge 桥接新闻组方式访问论坛以获取最佳用户体验。本帖是回复帖,原帖作者是楼上的 "烂泥"SYMBOL_STACK_INDEX: 1SYMBOL_NAME: pffilter+3022
- 已标记为答案 烂泥行天下 2011年6月10日 5:26