Many new process was blocked at nt!KiStartUserThread

SwimmingPool 121 Reputation points
2020-10-02T13:27:12.303+00:00

Windows 7. It is accidental but happened many times. When the desktop was appeared, There were so many appearances just below.

  1. the mouse was circling always.
  2. shutdown or restart key at start menu could be clicked, but there was nothing happend.
  3. I type cmd.exe, notepad.exe, regedit in win+r. the word typed was good,but there was nothing happened.
  4. Ctrl+alt+del, but nothing happened.
  5. ctrl+shift+esc, but nothing happened.
  6. right click the desktop or taskbar, there was an menu.
  7. I could browered any files from the explorer.
  8. I had to ctrl_r+scrollock+scrollock to get a bluescreen dmp. 下载 button is it. https://pan.ruijie.com.cn/share/17de1afc797949cf7559d516f6
  9. It seemed that those process had created, but some of them such as notepad, cmd was blocked at nt!KiStartUserThread. And explorer called CreateProcessW to Win+r,but it was blocked at KiSwapContent.
    Could you tell me what's wrong with these Windows?

Thank you very much!

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,734 questions
0 comments No comments
{count} votes

Accepted answer
  1. SwimmingPool 121 Reputation points
    2020-12-09T01:50:00.497+00:00

    It seemed that PsSetCreateProcessNotifyRoutine was called first. Then, when any process was created, the child would be blocked until the parent process ran some function.


1 additional answer

Sort by: Most helpful
  1. Carl Fan 6,836 Reputation points
    2020-10-05T09:55:56.61+00:00

    Hi,
    The memory dump provided some information about kbdhid.sys and usb.sys. You need to update your USB driver, mainboard driver, keyboard driver from manufacturer's official website.
    Restart to Safe Mode to check if the issue still insists.
    Then Perform a clean boot and disable security software temporarily.
    Could you open cmd window, right click and run as admin. Type the command below:
    sfc /scannow
    DISM /Online /Cleanup-Image /RestoreHealth
    Best Regards,
    Carl