每天第一次启动Windows都会出现相同情况的MEMORY_MANAGEMENT蓝屏,但后续启动却无法复现,等待机器完全关闭30分钟后才可复现
dump文件已上传百度网盘:
链接:https://pan.baidu.com/s/1SHbsEMyUCIFNCrNadqQf7Q?pwd=f3xi 提取码:f3xi
使用BlueScreenView查看为ntoskrnl.exe的问题。
使用WinDbg分析为以下内容
************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : false
AllowNugetExeUpdate : false
AllowNugetMSCredentialProviderInstall : false
AllowParallelInitializationOfLocalRepositories : true
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.031 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 36
Microsoft (R) Windows Debugger Version 10.0.25877.1004 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\113023-9984-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (16 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff8022e400000 PsLoadedModuleList = 0xfffff8022f02a6d0
Debug session time: Thu Nov 30 08:00:20.831 2023 (UTC + 8:00)
System Uptime: 0 days 0:00:58.560
Loading Kernel Symbols
...............................................................
................................................................
................................................................
............................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 0000000b`53d7e018). Type ".hh dbgerr001" for details
Loading unloaded module list
.............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff8022e7fd730 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff8185ad536fd0=000000000000001a
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: fffff73ffd4ddd30
Arg3: 0200000000000000
Arg4: 0000000000000000
Debugging Details:
*** WARNING: Check Image - Checksum mismatch - Dump: 0x3afaf5, File: 0x3a7fda - C:\ProgramData\Dbg\sym\dxgkrnl.sys\C7D99C703aa000\dxgkrnl.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 4249
Key : Analysis.Elapsed.mSec
Value: 6742
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 484
Key : Analysis.Init.Elapsed.mSec
Value: 8855
Key : Analysis.Memory.CommitPeak.Mb
Value: 90
Key : Bugcheck.Code.LegacyAPI
Value: 0x1a
Key : Failure.Bucket
Value: MEMORY_CORRUPTION_ONE_BIT
Key : Failure.Hash
Value: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Key : MemoryManagement.PFN
Value: 0
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 1a
BUGCHECK_P1: 41792
BUGCHECK_P2: fffff73ffd4ddd30
BUGCHECK_P3: 200000000000000
BUGCHECK_P4: 0
FILE_IN_CAB: 113023-9984-01.dmp
MEMORY_CORRUPTOR: ONE_BIT
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: WerFault.exe
STACK_TEXT:
ffff8185ad536fc8 fffff8022e68b7ba : 000000000000001a 0000000000041792 fffff73ffd4ddd30 0200000000000000 : nt!KeBugCheckEx
ffff8185ad536fd0 fffff8022e6236e6 : 0000000000000000 0000000000000000 0000000000000015 fffff73ffd4ddd30 : nt!MiDeleteVa+0x153a
ffff8185ad5370d0 fffff8022e6237fb : fffff77b00000000 ffffb28023ee9700 ffff818500000000 ffff8185ad537540 : nt!MiWalkPageTablesRecursively+0x776
ffff8185ad537170 fffff8022e6237fb : fffff77bbdcfff50 ffffb28023ee9700 ffff818500000001 ffff8185ad537550 : nt!MiWalkPageTablesRecursively+0x88b
ffff8185ad537210 fffff8022e6237fb : fffff77bbdcff000 ffffb28023ee9700 ffff818500000002 ffff8185ad537560 : nt!MiWalkPageTablesRecursively+0x88b
ffff8185ad5372b0 fffff8022e6207fb : ffffb043bf9bee54 ffffb28023ee9700 ffff818500000003 ffff8185ad537570 : nt!MiWalkPageTablesRecursively+0x88b
ffff8185ad537350 fffff8022e68a051 : ffff8185ad5374f0 ffffb28000000000 fffff77b00000002 ffffffff00000000 : nt!MiWalkPageTables+0x36b
ffff8185ad537450 fffff8022e633920 : 0000000000000001 ffff818500000000 ffffb28023ee9550 ffffb280240d1080 : nt!MiDeletePagablePteRange+0x4f1
ffff8185ad537760 fffff8022ea8f149 : ffffb2801aaecc40 0000000000000000 0000000000000000 ffffb28000000000 : nt!MiDeleteVad+0x360
ffff8185ad537870 fffff8022ea8ef22 : ffffb28024109ba0 00007ffa9bb90000 ffffb28023ee9080 0000000000000000 : nt!MiUnmapVad+0x49
ffff8185ad5378a0 fffff8022ea8ed99 : ffffb280240d1080 fffff8022e810ef5 0000000000000000 0000000000000000 : nt!MiUnmapViewOfSection+0x152
ffff8185ad537980 fffff8022ea8ea3c : ffffb280240d1080 0000010cd6cc0410 0000000000000001 ffffb28023ee9080 : nt!NtUnmapViewOfSectionEx+0x99
ffff8185ad5379d0 fffff8022e810ef5 : ffffb280240d1080 0000000000000010 ffff818500000001 ffffb28000000000 : nt!NtUnmapViewOfSection+0xc
ffff8185ad537a00 00007ffaa6a8d524 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x25
0000000b53aef1c8 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffa`a6a8d524
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
STACK_COMMAND: .cxr; .ecxr ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Followup: MachineOwner