Potrzebuję pomocy odnośnie uporczywych blue screenów, windbg pokazuje błąd związany z ntkrnlmp.exe, pamięć ram była kilkukrotnie sprawdzana memtestem i narzędziem diagnostycznym windows, dyski były formatowane, system stawiany na nowo i bios aktualizowany, bluescreeny dalej się pojawiają
Analiza błędu:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff8077e2023ce, Address of the instruction which caused the BugCheck
Arg3: ffffc00589a668b0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 6718
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 78067
Key : Analysis.Init.CPU.mSec
Value: 687
Key : Analysis.Init.Elapsed.mSec
Value: 345323
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8077e2023ce
BUGCHECK_P3: ffffc00589a668b0
BUGCHECK_P4: 0
CONTEXT: ffffc00589a668b0 -- (.cxr 0xffffc00589a668b0)
rax=0000000000000001 rbx=ffffd60e8c3fb6d0 rcx=ffffd60e8c3fb6d0
rdx=0000000000000000 rsi=ffffc00589a67350 rdi=fffff8077ec43dc8
rip=fffff8077e2023ce rsp=ffffc00589a672b8 rbp=0000000000000001
r8=ffffd60e8c3fb6d0 r9=0000000000000001 r10=0000000000000000
r11=ffffc00589a67290 r12=0000000000000000 r13=fffff8077e0011c0
r14=ffffc00589a67344 r15=fffff8077e26ba30
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050202
nt!RealSuccessor+0xe:
fffff807`7e2023ce 488b4808 mov rcx,qword ptr [rax+8] ds:002b:00000000`00000009=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
PROCESS_NAME: explorer.exe
LOCK_ADDRESS: fffff8077ec44ba0 -- (!locks fffff8077ec44ba0)
Resource @ nt!PiEngineLock (0xfffff8077ec44ba0) Available
Contention Count = 44
1 total locks
PNP_TRIAGE_DATA:
Lock address : 0xfffff8077ec44ba0
Thread Count : 0
Thread address: 0x0000000000000000
Thread wait : 0x0
STACK_TEXT:
ffffc005`89a672b8 fffff807`7e20230f : 00000000`00000000 fffff807`7ec43d60 fffff807`7ec43d60 00000000`00000001 : nt!RealSuccessor+0xe
ffffc005`89a672c0 fffff807`7e5d8ba6 : ffffd60e`8c3f9600 ffffc005`89a673b9 fffff807`7ec43d60 00000000`00000000 : nt!RtlEnumerateGenericTableLikeADirectory+0x6f
ffffc005`89a67300 fffff807`7e5d1f90 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`c0000001 : nt!PiDmEnumObjectsWithCallback+0x16e
ffffc005`89a67420 fffff807`7e5d2d4e : 00000000`00000000 fffff807`00000000 00000000`00000016 00000000`00000000 : nt!PiDqObjectManagerEnumerateAndRegisterQuery+0x314
ffffc005`89a67560 fffff807`7e5d1548 : ffffc282`ebdb0f10 00000000`00000000 00000000`00000000 ffffc005`89a676a0 : nt!PiDqQuerySerializeActionQueue+0x9e
ffffc005`89a675f0 fffff807`7e5d2297 : ffffc282`e05fa400 fffff807`7e3fe601 fffff807`00000000 00000000`00000000 : nt!PiDqIrpQueryGetResult+0x154
ffffc005`89a67690 fffff807`7e6ee61d : ffffc282`e05fa400 ffffc282`d4ec8d80 fffff807`7e006590 00000000`00000000 : nt!PiDqDispatch+0x1c7
ffffc005`89a676d0 fffff807`7e28f6f5 : ffffc282`e05fa400 00000000`00000002 00000000`00000000 00000000`00000001 : nt!PiDaDispatch+0x4d
ffffc005`89a67700 fffff807`7e6758f8 : ffffc282`e05fa400 00000000`00000000 ffffc282`e05fa400 00000000`00000000 : nt!IofCallDriver+0x55
ffffc005`89a67740 fffff807`7e6751c5 : 00000000`00000000 ffffc005`89a67a80 00000000`00000000 ffffc005`89a67a80 : nt!IopSynchronousServiceTail+0x1a8
ffffc005`89a677e0 fffff807`7e674bc6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`0f77c0a8 : nt!IopXxxControlFile+0x5e5
ffffc005`89a67920 fffff807`7e408bb5 : 00000000`00000000 ffffc282`e02f88d0 00000000`00000000 00000000`00bebc20 : nt!NtDeviceIoControlFile+0x56
ffffc005`89a67990 00007ffc`c808ce54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0bf3f878 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`c808ce54
SYMBOL_NAME: nt!RealSuccessor+e
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
STACK_COMMAND: .cxr 0xffffc00589a668b0 ; kb
BUCKET_ID_FUNC_OFFSET: e
FAILURE_BUCKET_ID: 0x3B_c0000005_nt!RealSuccessor
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {20525b36-f8b4-81a9-f1f4-2c7fd06a5a57}
Followup: MachineOwner
---------
w wątkach jeszcze jest wyróżniony:
[0x1048] = nt!KiSwapContext+0x76 (fffff807`7e3fdf36)
Bardzo proszę o pomoc