瑞星卡卡安全论坛个人产品讨论区瑞星杀毒软件瑞星杀毒软件2011 RavMonD.exe引起win2003系统经常蓝屏(已传附件)

1   1  /  1  页   跳转

RavMonD.exe引起win2003系统经常蓝屏(已传附件)

RavMonD.exe引起win2003系统经常蓝屏(已传附件)

这段时间经常出现蓝屏,分析dump文件有如下结果:



Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\WINDOWS\Minidump\Mini052408-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\WINDOWS\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows Server 2003 Kernel Version 3790 (Service Pack 2) UP Free x86 compatible
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a8e48
Debug session time: Sat May 24 18:41:28.146 2008 (GMT+8)
System Uptime: 0 days 1:24:13.756
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
.............................................................................................................................
Loading User Symbols
Loading unloaded module list
............
*******************************************************************************
*                                                                            *
*                        Bugcheck Analysis                                    *
*                                                                            *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000000A, {4, 2, 0, 8083e3cc}
Probably caused by : memory_corruption ( nt!MiRemovePageByColor+7e )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
*                                                                            *
*                        Bugcheck Analysis                                    *
*                                                                            *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 8083e3cc, address which referenced memory
Debugging Details:
------------------

READ_ADDRESS:  00000004
CURRENT_IRQL:  2
FAULTING_IP:
nt!MiRemovePageByColor+7e
8083e3cc 8b4a04          mov    ecx,dword ptr [edx+4]
CUSTOMER_CRASH_COUNT:  1
DEFAULT_BUCKET_ID:  DRIVER_FAULT_SERVER_MINIDUMP
BUGCHECK_STR:  0xA
PROCESS_NAME:  RavMonD.exe
LAST_CONTROL_TRANSFER:  from 80845d3c to 8083e3cc
STACK_TEXT: 
f60ebd10 80845d3c 0686a000 06540f78 00000000 nt!MiRemovePageByColor+0x7e
f60ebd4c 808264ca 00000001 0686a000 00000001 nt!MmAccessFault+0xbdb
f60ebd4c 05ddc749 00000001 0686a000 00000001 nt!KiTrap0E+0x118
WARNING: Frame IP not in any known module. Following frames may be wrong.
00000000 00000000 00000000 00000000 00000000 0x5ddc749

STACK_COMMAND:  kb
FOLLOWUP_IP:
nt!MiRemovePageByColor+7e
8083e3cc 8b4a04          mov    ecx,dword ptr [edx+4]
SYMBOL_STACK_INDEX:  0
SYMBOL_NAME:  nt!MiRemovePageByColor+7e
FOLLOWUP_NAME:  MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP:  45ec146a
IMAGE_NAME:  memory_corruption
FAILURE_BUCKET_ID:  0xA_nt!MiRemovePageByColor+7e
BUCKET_ID:  0xA_nt!MiRemovePageByColor+7e
Followup: MachineOwner
---------

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; MyIE2; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)

附件附件:

文件名:Minidump.rar
下载次数:172
文件类型:application/octet-stream
文件大小:
上传时间:2008-5-25 1:07:34
描述:rar

最后编辑新鱼 最后编辑于 2008-05-25 01:07:34
分享到:
gototop
 

回复:win2003系统经常蓝屏

请到系统区发帖
谢谢合作
gototop
 

回复: win2003系统经常蓝屏



引用:
原帖由 aaccbbdd 于 2008-5-24 19:52:00 发表
请到系统区发帖
谢谢合作


但是里面的分析显示,蓝屏可能是 RavMonD.exe引起的,又不是系统的问题!
gototop
 

回复:RavMonD.exe引起win2003系统经常蓝屏

把dump文件作为附件上传!
gototop
 
gototop
 

回复: RavMonD.exe引起win2003系统经常蓝屏(已传附件)



引用:
原帖由 lqqk7 于 2008-5-24 22:57:00 发表
把dump文件作为附件上传!


附件已经上传啦!
帮我看看是什么问题,谢谢!
gototop
 

回复:RavMonD.exe引起win2003系统经常蓝屏(已传附件)

分析了minidump,已有的信息不够。请Lz做如下操作:

右击我的电脑点属性/高级/启动和故障回复/设置,将“写入调试信息”改为“内存转储文件",再次蓝屏时会生成MEMORY.DMP,将此文件压缩后上传,同时将蓝屏之前所进行的操作以及瑞星的版本都贴上来。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT