none
[求救]WIN10下,打开outlook邮件附件中的word或者excel文件出现蓝屏的情况 RRS feed

  • 问题

  • 本人新装的WIN10,安装的是OFFICE2013,目前出现一个问题,只要一打开outlook邮件附件中的word或者excel文件,就会出现蓝屏的情况,错误提示为REFERENCE_BY_POINTER。即使我把文件保存的桌面上,再打开还是会出现蓝屏。

    刚装的系统啊。

    dump文件已经上传到共享:http://1drv.ms/1FU1PH2
    请各位大牛帮忙看看是什么问题,该如何解决。

    2015年10月8日 3:38

答案

  • Quince_QY 您好,

    这里有一篇英文文档,里面解释了这个蓝屏发生的原因:

    https://msdn.microsoft.com/zh-cn/library/windows/hardware/ff557386%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396

    以下是dump文件的解析:

    ******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 18, {0, ffffe000702b5e80, 7, ffffffdf}
    
    Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+183ee )
    
    Followup: MachineOwner
    ---------
    
    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    REFERENCE_BY_POINTER (18)
    Arguments:
    Arg1: 0000000000000000, Object type of the object whose reference count is being lowered
    Arg2: ffffe000702b5e80, Object whose reference count is being lowered
    Arg3: 0000000000000007, Reserved
    Arg4: 00000000ffffffdf, Reserved
    	The reference count of an object is illegal for the current state of the object.
    	Each time a driver uses a pointer to an object the driver calls a kernel routine
    	to increment the reference count of the object. When the driver is done with the
    	pointer the driver calls another kernel routine to decrement the reference count.
    	Drivers must match calls to the increment and decrement routines. This bugcheck
    	can occur because an object's reference count goes to zero while there are still
    	open handles to the object, in which case the fourth parameter indicates the number
    	of opened handles. It may also occur when the object’s reference count drops below zero
    	whether or not there are open handles to the object, and in that case the fourth parameter
    	contains the actual value of the pointer references count.
    
    Debugging Details:
    ------------------
    
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
    
    BUGCHECK_STR:  0x18
    
    PROCESS_NAME:  WINWORD.EXE
    
    CURRENT_IRQL:  0
    
    ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
    
    LAST_CONTROL_TRANSFER:  from fffff803d1de61ee to fffff803d1dbf240
    
    STACK_TEXT:  
    ffffd000`231d73d8 fffff803`d1de61ee : 00000000`00000018 00000000`00000000 ffffe000`702b5e80 00000000`00000007 : nt!KeBugCheckEx
    ffffd000`231d73e0 fffff803`d209d504 : 00000000`00000005 ffffd000`231d7701 00000000`00000000 ffffe000`702b5e80 : nt! ?? ::FNODOBFM::`string'+0x183ee
    ffffd000`231d7420 fffff803`d218452a : 00000000`00000cd8 ffffe000`6f924760 00000000`00000000 ffffe000`765f76a0 : nt!IopParseDevice+0x644
    ffffd000`231d7630 fffff803`d20989d1 : 00000000`00000cd8 ffffd000`231d7790 ffffe000`765f7670 fffff803`d2184474 : nt!IopParseFile+0xb6
    ffffd000`231d7690 fffff803`d20f738c : ffffe000`76c23b01 ffffd000`231d78b8 00000000`00000040 ffffe000`6e9dbdc0 : nt!ObpLookupObjectName+0x711
    ffffd000`231d7830 fffff803`d20f369c : 00000000`00000001 ffffe000`6f924760 00000000`0f3fee30 00000000`0f3fe580 : nt!ObOpenObjectByName+0x1ec
    ffffd000`231d7960 fffff803`d20f32e9 : 00000000`0f3fe568 00000000`00000001 00000000`0f3fee30 00000000`0f3fe580 : nt!IopCreateFile+0x38c
    ffffd000`231d7a00 fffff803`d1dc9863 : ffffe000`769a0800 00000000`0f3fe1e8 ffffd000`231d7aa8 00000000`00000000 : nt!NtCreateFile+0x79
    ffffd000`231d7a90 00007ff9`90ea3a4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`0f3fe4f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`90ea3a4a
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt! ?? ::FNODOBFM::`string'+183ee
    fffff803`d1de61ee cc              int     3
    
    SYMBOL_STACK_INDEX:  1
    
    SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+183ee
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  55fa569b
    
    IMAGE_VERSION:  10.0.10240.16515
    
    BUCKET_ID_FUNC_OFFSET:  183ee
    
    FAILURE_BUCKET_ID:  0x18_nt!_??_::FNODOBFM::_string_
    
    BUCKET_ID:  0x18_nt!_??_::FNODOBFM::_string_
    
    ANALYSIS_SOURCE:  KM
    
    FAILURE_ID_HASH_STRING:  km:0x18_nt!_??_::fnodobfm::_string_
    
    FAILURE_ID_HASH:  {23944209-42f8-342c-4e58-b3422a5fb0a5}
    
    Followup: MachineOwner
    ---------
    
    0: kd> !object ffffe000702b5e80
    GetUlongFromAddress: unable to read from fffff803d20361c8
    Could not read ObjectType address
    0: kd> !object 702b5e80
    GetUlongFromAddress: unable to read from fffff803d20361c8

    奇怪的是我这边读不出来具体的指针信息。

    另外,请尝试在干净启动下面打开,看看是不是还是会出现蓝屏:

    https://support.microsoft.com/zh-cn/kb/929135


    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    2015年10月9日 8:35
    版主