Your dump file shows a blue screen caused by the PhotoShop program.
The method I found for you is to delete the CRWindowsClientService.exe file under the PhotoShop directory (preferably cut it to another place), you can try it.
Sorry for the late reply
I try with your solution, but, it still is not working. The desktop show bluescreen periodically.
Yesterday, 01 July 2021 It occurred again.
Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64 <br><br>Copyright (c) Microsoft Corporation. All rights reserved. <br><br> <br><br> <br><br>Loading Dump File [C:\Users\salap\OneDrive\เดสก์ท็อป\MEMORY.DMP] <br><br>Kernel Bitmap Dump File: Full address space is available <br><br> <br><br>Symbol search path is: srv* <br><br>Executable search path is: <br><br>Windows 10 Kernel Version 19041 MP (6 procs) Free x64 <br><br>Product: WinNt, suite: TerminalServer SingleUserTS <br><br>Built by: 19041.1.amd64fre.vb_release.191206-1406 <br><br>Machine Name: <br><br>Kernel base = 0xfffff80153c00000 PsLoadedModuleList = 0xfffff8015482a230 <br><br>Debug session time: Thu Jul 1 12:57:24.137 2021 (UTC + 7:00) <br><br>System Uptime: 0 days 3:41:44.065 <br><br>Loading Kernel Symbols <br><br>............................................................... <br><br>................................................................ <br><br>.............................................................. <br><br>Loading User Symbols <br><br>..... <br><br>Loading unloaded module list <br><br>...... <br><br>Loading Wow64 Symbols <br><br>................................................................ <br><br>. <br><br>For analysis of this file, run !analyze -v <br><br>1: kd> !analyze -v <br><br>******************************************************************************* <br><br>* * <br><br>* Bugcheck Analysis * <br><br>* * <br><br>******************************************************************************* <br><br> <br><br>PAGE_FAULT_IN_NONPAGED_AREA (50) <br><br>Invalid system memory was referenced. This cannot be protected by try-except. <br><br>Typically the address is just plain bad or it is pointing at freed memory. <br><br>Arguments: <br><br>Arg1: ffffffffffffffe8, memory referenced. <br><br>Arg2: 0000000000000000, value 0 = read operation, 1 = write operation. <br><br>Arg3: fffff801542d6411, If non-zero, the instruction address which referenced the bad memory <br><br> address. <br><br>Arg4: 0000000000000002, (reserved) <br><br> <br><br>Debugging Details: <br><br>------------------ <br><br> <br><br> <br><br>"C:\WINDOWS\System32\KERNELBASE.dll" was not found in the image list. <br><br>Debugger will attempt to load "C:\WINDOWS\System32\KERNELBASE.dll" at given base 0000000000000000. <br><br> <br><br>Please provide the full image name, including the extension (i.e. kernel32.dll) <br><br>for more reliable results.Base address and size overrides can be given as <br><br>.reload <image.ext>=<base>,<size>. <br><br> <br><br>KEY\_VALUES\_STRING: 1 <br><br> <br><br> Key : Analysis.CPU.Sec <br><br> Value: 4 <br><br> <br><br> Key : Analysis.DebugAnalysisProvider.CPP <br><br> Value: Create: 8007007e on LAPTOP-JJR4EDEO <br><br> <br><br> Key : Analysis.DebugData <br><br> Value: CreateObject <br><br> <br><br> Key : Analysis.DebugModel <br><br> Value: CreateObject <br><br> <br><br> Key : Analysis.Elapsed.Sec <br><br> Value: 19 <br><br> <br><br> Key : Analysis.Memory.CommitPeak.Mb <br><br> Value: 77 <br><br> <br><br> Key : Analysis.System <br><br> Value: CreateObject <br><br> <br><br> <br><br>BUGCHECK\_CODE: 50 <br><br> <br><br>BUGCHECK\_P1: ffffffffffffffe8 <br><br> <br><br>BUGCHECK\_P2: 0 <br><br> <br><br>BUGCHECK\_P3: fffff801542d6411 <br><br> <br><br>BUGCHECK\_P4: 2 <br><br> <br><br>READ\_ADDRESS: ffffffffffffffe8 <br><br> <br><br>MM\_INTERNAL\_CODE: 2 <br><br> <br><br>BLACKBOXBSD: 1 (!blackboxbsd) <br><br> <br><br> <br><br>BLACKBOXNTFS: 1 (!blackboxntfs) <br><br> <br><br> <br><br>BLACKBOXWINLOGON: 1 <br><br> <br><br>PROCESS\_NAME: remoting\_host.exe <br><br> <br><br>TRAP\_FRAME: fffff208ef5cb6c0 -- (.trap 0xfffff208ef5cb6c0) <br><br>NOTE: The trap frame does not contain all registers. <br><br>Some register values may be zeroed or incorrect. <br><br>rax=fffff208ef5cb910 rbx=0000000000000000 rcx=ffff880f79acb960 <br><br>rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000 <br><br>rip=fffff801542d6411 rsp=fffff208ef5cb850 rbp=fffff208ef5cba39 <br><br> r8=0000000000000000 r9=0000000000000000 r10=0000000000000000 <br><br>r11=ffffd07ed9e00000 r12=0000000000000000 r13=0000000000000000 <br><br>r14=0000000000000000 r15=0000000000000000 <br><br>iopl=0 nv up ei ng nz na pe cy <br><br>nt!SeDefaultObjectMethod+0xb1: <br><br>fffff801542d6411 488b4708 mov rax,qword ptr [rdi+8] ds:0000000000000008=???????????????? <br><br>Resetting default scope <br><br> <br><br>STACK\_TEXT: <br><br>fffff208ef5cb418 fffff8015408dd7d : 0000000000000050 ffffffffffffffe8 0000000000000000 fffff208ef5cb6c0 : nt!KeBugCheckEx <br><br>fffff208ef5cb420 fffff80153f28210 : 0000000000000000 0000000000000000 fffff208ef5cb740 0000000000000000 : nt!MiSystemFault+0x147cbd <br><br>fffff208ef5cb520 fffff80154004d5e : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!MmAccessFault+0x400 <br><br>fffff208ef5cb6c0 fffff801542d6411 : ffff880f75bc20c0 0000000000007000 00000000000041d7 fffff801541f9d01 : nt!KiPageFault+0x35e <br><br>fffff208ef5cb850 fffff801542e0176 : ffff880f79acb930 fffff208ef5cba39 0000000000000000 fffff801541f9cbc : nt!SeDefaultObjectMethod+0xb1 <br><br>fffff208ef5cb8b0 fffff80153e08357 : 0000000000000000 0000000000000000 fffff208ef5cba39 ffff880f79acb960 : nt!ObpRemoveObjectRoutine+0xd6 <br><br>fffff208ef5cb910 fffff801541f372e : ffff880f6ace7220 0000000000000001 ffffffffffffffff ffffb90ba5f77670 : nt!ObfDereferenceObjectWithTag+0xc7 <br><br>fffff208ef5cb950 fffff801541f73ac : 000000000000059c fffff801541f8b45 fffff20800000000 ffff880f7654abe0 : nt!ObCloseHandleTableEntry+0x29e <br><br>fffff208ef5cba90 fffff801540085b8 : 0000000046cbc000 00007fffffed4890 fffff208ef5cbb80 0000000000000000 : nt!NtClose+0xec <br><br>fffff208ef5cbb00 00000000771c1cfc : 00000000771c1cbb 0000002377242bbc 0000000000000023 0000000000000000 : nt!KiSystemServiceCopyEnd+0x28 <br><br>000000000690ed18 00000000771c1cbb : 0000002377242bbc 0000000000000023 0000000000000000 0000000006a0e784 : wow64cpu!CpupSyscallStub+0xc <br><br>000000000690ed20 00000000771c11b9 : 0000000006a0f6f8 00007fffffec39b4 0000000000000000 00007fffffec3aaf : wow64cpu!Thunk0Arg+0x5 <br><br>000000000690edd0 00007fffffec38c9 : 0000000046ca0500 0000000000000000 0000000000000000 000000000690f210 : wow64cpu!BTCpuSimulate+0x9 <br><br>000000000690ee10 00007fffffec32bd : 0000000000000000 0000000000000001 0000000000000000 0000000000000000 : wow64!RunCpuSimulation+0xd <br><br>000000000690ee40 00007ff800fa4f89 : 0000000000000000 0000000000000000 0000000000000001 0000000000000000 : wow64!Wow64LdrpInitialize+0x12d <br><br>000000000690f0f0 00007ff800fa4b73 : 0000000000000000 00007ff800f30000 0000000000000000 00000000049ce000 : ntdll!LdrpInitialize+0x3fd <br><br>000000000690f190 00007ff800fa4b1e : 000000000690f210 0000000000000000 0000000000000000 0000000000000000 : ntdll!LdrpInitialize+0x3b <br><br>000000000690f1c0 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 00000000`00000000 : ntdll!LdrInitializeThunk+0xe <br><br> <br><br> <br><br>SYMBOL_NAME: nt!SeDefaultObjectMethod+b1 <br><br> <br><br>MODULE_NAME: nt <br><br> <br><br>IMAGE_NAME: ntkrnlmp.exe <br><br> <br><br>STACK_COMMAND: .thread ; .cxr ; kb <br><br> <br><br>BUCKET_ID_FUNC_OFFSET: b1 <br><br> <br><br>FAILURE_BUCKET_ID: AV_R_INVALID_nt!SeDefaultObjectMethod <br><br> <br><br>OS_VERSION: 10.0.19041.1 <br><br> <br><br>BUILDLAB_STR: vb_release <br><br> <br><br>OSPLATFORM_TYPE: x64 <br><br> <br><br>OSNAME: Windows 10 <br><br> <br><br>FAILURE_ID_HASH: {8bff512c-58e1-d26a-5bbd-ae3d1ad0e774} <br><br> <br><br>Followup: MachineOwner |
|---|