Share via

BSOD problem (蓝屏问题)

Anonymous
2022-07-03T05:42:21+00:00

unable to get nt!MmSpecialPagesInUse

0000000000000000

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  WeChat.exe

IRP_ADDRESS: 8000000308a49788

TRAP_FRAME:  ffffbf8641e1e8f0 -- (.trap 0xffffbf8641e1e8f0)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=0000000000000000 rbx=0000000000000000 rcx=ffffbf8641e1e5a8

rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000

rip=fffff805374454a2 rsp=ffffbf8641e1ea80 rbp=ffff88807b3ed180

 r8=0000000000000000  r9=ffff88807b1eb000 r10=fffff80537e59100

r11=ffffaf8cf7acba10 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0         nv up ei pl nz na po cy

nt!KeSetEvent+0x92:

fffff805374454a2 498b4500        mov     rax,qword ptr [r13] ds:0000000000000000=????????????????

Resetting default scope

STACK_TEXT:  

ffffbf8641e1e7a8 fffff80537609d69     : 000000000000000a 0000000000000000 0000000000000002 0000000000000000 : nt!KeBugCheckEx

ffffbf8641e1e7b0 fffff80537606069     : 00000001ffffffff fffff80537405c41 ffffaf8ceed8f3b0 0000000000000000 : nt!KiBugCheckDispatch+0x69

ffffbf8641e1e8f0 fffff805374454a2     : ffffbf8641e1e5a8 0000000000000000 3d30e439f76e0e7a 3d30e439f76e0e7a : nt!KiPageFault+0x469

ffffbf8641e1ea80 fffff80537444bd9     : 0000000000000000 ffffbf8641e1ec50 0000000100000000 ffffe1087c3c0000 : nt!KeSetEvent+0x92

ffffbf8641e1eb10 fffff80537457540     : 8000000308a49800 ffffaf8c00000000 ffffaf8cf2674000 ffffaf8cf41dc080 : nt!IopCompleteRequest+0x389

ffffbf8641e1ebd0 fffff805375fc130     : 0000000000000000 0000000000000000 af8cfa1200000000 0000000000000000 : nt!KiDeliverApc+0x1b0

ffffbf8641e1ec80 fffff805374a6791     : 0000000000000114 0000000000000000 ffffe1087c3c0000 0000000000000000 : nt!KiApcInterrupt+0x2f0

ffffbf8641e1ee10 fffff8053747c49b     : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!MmAccessFault+0x231

ffffbf8641e1efb0 fffff8053746be25     : 0000000000000000 0000000000000000 ffffbf8641e1f1f0 ffffbf8641e1f1d4 : nt!MmCheckCachedPageStates+0x17eb

ffffbf8641e1f180 fffff8053746adaa     : ffffaf8cf0892a20 00000000119b2360 ffffbf8641e1f378 ffffaf8c00000000 : nt!CcMapAndCopyInToCache+0x605

ffffbf8641e1f320 fffff8053d9763b7     : 0000000000000000 ffffbf8641e1f600 ffffaf8cf498ea28 0000000000000000 : nt!CcCopyWriteEx+0xea

ffffbf8641e1f3a0 fffff8053d972063     : ffffaf8cf498ea28 ffffaf8cf7ae4010 ffffbf8641e1f640 0000000000000000 : Ntfs!NtfsCommonWrite+0x3ee7

ffffbf8641e1f5d0 fffff8053744e565     : ffffaf8cf41ee8a0 ffffaf8cf7ae4010 ffffaf8cf7ae4010 ffffaf8ce4dd8c20 : Ntfs!NtfsFsdWrite+0x1d3

ffffbf8641e1f6a0 fffff80536c572af     : ffffbf8641e20000 0000000000000000 ffffbf8641e1f790 fffff80536c572af : nt!IofCallDriver+0x55

ffffbf8641e1f6e0 fffff80536c54b33     : ffffbf8641e1f770 0000000000000000 0000000000000000 fffff80537450b6e : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f

ffffbf8641e1f750 fffff8053744e565     : ffffaf8cf7ae4010 0000000000000204 ffffaf8cf6045760 fffff8053744e565 : FLTMGR!FltpDispatch+0xa3

ffffbf8641e1f7b0 fffff8053780db18     : 0000000000000001 ffffaf8cf6062130 0000000000000001 ffffaf8cf7ae4440 : nt!IofCallDriver+0x55

ffffbf8641e1f7f0 fffff805377fc99f     : ffffaf8c00000000 ffffbf8641e1fa80 000000001409e408 ffffbf8641e1fa80 : nt!IopSynchronousServiceTail+0x1a8

ffffbf8641e1f890 fffff805376097b5     : ffffaf8cf41dc080 0000000000001824 0000000000000000 0000000011a15534 : nt!NtWriteFile+0x66f

ffffbf8641e1f990 0000000077141cfc     : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x25

00000000103ff268 0000000000000000     : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x77141cfc

SYMBOL_NAME:  nt!KeSetEvent+92

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.1766

STACK_COMMAND:  .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET:  92

FAILURE_BUCKET_ID:  AV_nt!KeSetEvent

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {c42bf4ac-5ef0-4bd6-418f-0d54b7c20876}

Followup:     MachineOwner


Windows for home | Windows 10 | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

4 answers

Sort by: Most helpful
  1. DYARI BARHAM 34,936 Reputation points Independent Advisor
    2022-07-04T09:36:11+00:00

    Hi Yujie,

    Thanks for sharing the minidump files.

    The minidump file did not name any driver only indicates ntkrnlmp.exe which is a Windows component that means something else drove the system to a fault or it could be a memory corruption that usually happens due to driver incompatibility.

    To troubleshoot this issue, kindly try the steps below:

    1-Check for updates:

    Go to Settings > Update and Security > Check for update > install all the pending updates

    2-Uninstall the graphics card driver completely using the DDU free tool:

    https://www.guru3d.com/files-details/display-dr...

    Then, install the latest driver provided on the manufacturer's website.

    3-Uninstall any third-party security software and scan for viruses & malware with the free Malwarebytes:

    https://www.malwarebytes.com/mwb-download

    4-Run Command Prompt as administrator. Type this command and hit enter:

    dism.exe /online /cleanup-image /restorehealth

    Then, type this command and hit enter:

    sfc /scannow

    5-If you are overclocking your PC, try running everything (CPU, GPU, system memory) at their stock speeds. See if the issue is still reproducible. Or, turn off XMP profile or set it to Auto.

    6-Download then install the latest version of BIOS & Chipset drivers from the manufacturer's website.

    7-Test the RAM with the free utility MemTest86, then run a full 8 pass scan to test your RAM for physical errors:

    https://www.tenforums.com/tutorials/14201-memte...

    8-Run the Windows Memory Diagnostic:

    https://www.howtogeek.com/260813/how-to-test-yo...

    Run Hard Drive Diagnostic:

    https://www.lifewire.com/free-hard-drive-testin...

    9-If you are comfortable of doing so, take all the system memory sticks out, examine them for any obvious defects, and then reseat them into the sockets. Make sure that they are seated properly in their slots. If you have multiple sticks of system memory installed and you suspect one is faulty, one thing to try is to reproduce the issue with only one stick of memory module at a time. This will help you to isolate the faulty module.

    10-If the issue still persists after the steps above, enable the driver verifier and let the computer crash 4 times then disable it and share the newly created minidump file:

    https://www.tenforums.com/tutorials/5470-enable...

    Please do not hesitate to ask if you need further assistance.

    Stay safe

    ____________________________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2022-07-03T22:47:31+00:00
    1. Please run the V2 log collector and post a share link into this thread using one drive, drop box, or google drive.

    https://www.tenforums.com/bsod-crashes-debugging/2198-bsod-posting-instructions.html

    https://www.elevenforum.com/t/bsod-posting-instructions.103/

    Modify the default language to English so that log files can be scanned and read.

    https://www.tenforums.com/tutorials/3813-add-remove-change-display-language-windows-10-a.html

    https://www.tenforums.com/tutorials/136792-change-display-language-windows-10-a.html

    1. The BIOS: Version 1.11 2016

    Upgrade the BIOS: 1.11 -----------> 1.45 2022

    https://pcsupport.lenovo.com/ie/en/products/laptops-and-netbooks/thinkpad-t-series-laptops/thinkpad-t460/downloads/ds112122-bios-update-utility-bootable-cd-for-windows-10-81-7-64-bit-7-32-bit-thinkpad-t460?category=BIOS%2FUEFI

    1. Read this link on Windows Driver Verifier (WDV): https://www.tenforums.com/tutorials/5470-enable-disable-driver-verifier-windows-10-a.html

    The tool will stress test drivers.

    Misbehaving drivers will create BSOD and if available dump files.

    Learn the methods to recover from using the tool by booting to safe mode then opening administrative command prompt and typing:

    verifier /reset

    or

    verifier /bootmode resetonbootfail

    Test on non-Microsoft drivers.

    Test no Microsoft drivers.

    Start with the 3 customized tests displayed in the Ten Forums link.

    The customized tests will be modified during the troubleshooting.

    If there is no immediate BSOD then open administrative command prompt and type or copy and paste: verifier /querysettings

    Post a share link into this thread using one drive, drop box, or google drive.

    For any BSOD run the V2 log collector and post a share link into the newest post.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-07-03T18:33:53+00:00

    https://drive.google.com/file/d/1BJ9XJOFO2wDqz34ijk5YLnLysctdnlYL/view?usp=sharing thank you for your reply, please see the following link

    Was this answer helpful?

    0 comments No comments
  4. DYARI BARHAM 34,936 Reputation points Independent Advisor
    2022-07-03T06:14:35+00:00

    Hi Yujie,

    I'm Dyari. Thanks for reaching out. I will be happy to assist you in this regard.

    Kindly check C:\Windows\Minidump and copy available minidump files to the desktop then share them via One Drive or Google Drive in order to be analyzed and indicate which file is causing the crash.

    Regards,

    你好 Yujie,

    我是迪亚里。 感谢您伸出援手。 我很乐意在这方面为您提供帮助。

    请检查 C:\Windows\Minidump 并将可用的 minidump 文件复制到桌面,然后通过 One Drive 或 Google Drive 共享它们,以便分析并指出导致崩溃的文件。

    问候,

    Was this answer helpful?

    0 comments No comments