请教: 系统blue screen后, 如何使用windebug分析dump文件?
我的机器出现Blue screen问题后,用windebug工具分析得出下面所列信息:
请教高手: 如何看其中的信息来判断问题所在呢?多谢指教!
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8224c639, The address that the exception occurred at
Arg3: 8cd03c04, Exception Record Address
Arg4: 8cd03900, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
iaStor+42639
8224c639 8b01 mov eax,dword ptr [ecx]
EXCEPTION_RECORD: 8cd03c04 -- (.exr 0xffffffff8cd03c04)
ExceptionAddress: 8224c639 (iaStor+0x00042639)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000000
Attempt to read from address 00000000
CONTEXT: 8cd03900 -- (.cxr 0xffffffff8cd03900)
eax=8534b300 ebx=8534b2a8 ecx=00000000 edx=8534b168 esi=8534b2a8 edi=00000002
eip=8224c639 esp=8cd03ccc ebp=8cd03cd4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
iaStor+0x42639:
8224c639 8b01 mov eax,dword ptr [ecx] ds:0023:00000000=????????
Resetting default scope
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
READ_ADDRESS: 00000000
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from 8224c79c to 8224c639
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
8cd03cd4 8224c79c 00000002 8534b2a0 8534b168 iaStor+0x42639
8cd03cfc 8224cd48 81d1e13c 88b34c78 84ef5f68 iaStor+0x4279c
8cd03d14 82213bb4 8534b2ac 8cd03d30 82242059 iaStor+0x42d48
8cd03d20 82242059 85348a20 852c65e8 8cd03d44 iaStor+0x9bb4
8cd03d30 81e3823b 852c65e8 88b34c78 8848d270 iaStor+0x38059
8cd03d44 81c5441d 84ef5f68 00000000 8848d270 nt!IopProcessWorkItem+0x23
8cd03d7c 81df1a1c 84ef5f68 2f479c07 00000000 nt!ExpWorkerThread+0xfd
8cd03dc0 81c4aa3e 81c54320 80000001 00000000 nt!PspSystemThreadStartup+0x9d
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
FOLLOWUP_IP:
iaStor+42639
8224c639 8b01 mov eax,dword ptr [ecx]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: iaStor+42639
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: iaStor
IMAGE_NAME: iaStor.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4865ac6e
STACK_COMMAND: .cxr 0xffffffff8cd03900 ; kb
FAILURE_BUCKET_ID: 0x7E_iaStor+42639
BUCKET_ID: 0x7E_iaStor+42639
Followup: MachineOwner
---------