질문과 답변
안녕하세요 w2k3 r2 덤프분석좀 부탁드려요..
2009.07.29 10:02
안녕하세요 시스템이 불규칙하게 재부팅이 되어버립니다..
덤프분석좀 부탁드릴게요.. windbg 돌렸으나 도통 뭔소린지 모르겠네요 ㅠㅠ
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {f74db97c, 3fe85121, f794abdc, b}
Probably caused by : ntkrpamp.exe ( nt!KiTrap0E+dc )
Followup: MachineOwner
---------
9: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: f74db97c, Virtual address for the attempted write.
Arg2: 3fe85121, PTE contents.
Arg3: f794abdc, (reserved)
Arg4: 0000000b, (reserved)
Debugging Details:
------------------
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: System
CURRENT_IRQL: 2
TRAP_FRAME: f794abdc -- (.trap 0xfffffffff794abdc)
ErrCode = 00000003
eax=f74d0005 ebx=808aeae0 ecx=f74db978 edx=0000e8cd esi=000001ff edi=6b576343
eip=808930e3 esp=f794ac50 ebp=f794ac8c iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!ExAllocatePoolWithTag+0x56b:
808930e3 897904 mov dword ptr [ecx+4],edi ds:0023:f74db97c=ffffe0b0
Resetting default scope
LAST_CONTROL_TRANSFER: from 8085ed19 to 80827c83
STACK_TEXT:
f794ab4c 8085ed19 000000be f74db97c 3fe85121 nt!KeBugCheckEx+0x1b
f794abc4 8088c7c8 00000001 f74db97c 00000000 nt!MmAccessFault+0xb25
f794abc4 808930e3 00000001 f74db97c 00000000 nt!KiTrap0E+0xdc
f794ac8c 808124de 00000000 f776f120 6b576343 nt!ExAllocatePoolWithTag+0x56b
f794ad40 808127a8 97a8a660 808ae5c0 97a5ee40 nt!CcLazyWriteScan+0x2cc
f794ad80 80880469 97a5ee40 00000000 97a8a660 nt!CcWorkerThread+0x140
f794adac 80949b7c 97a5ee40 00000000 00000000 nt!ExpWorkerThread+0xeb
f794addc 8088e092 8088037e 00000000 00000000 nt!PspSystemThreadStartup+0x2e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiTrap0E+dc
8088c7c8 85c0 test eax,eax
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiTrap0E+dc
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 49c21e56
FAILURE_BUCKET_ID: 0xBE_nt!KiTrap0E+dc
BUCKET_ID: 0xBE_nt!KiTrap0E+dc
Followup: MachineOwner
---------
덤프분석좀 부탁드릴게요.. windbg 돌렸으나 도통 뭔소린지 모르겠네요 ㅠㅠ
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {f74db97c, 3fe85121, f794abdc, b}
Probably caused by : ntkrpamp.exe ( nt!KiTrap0E+dc )
Followup: MachineOwner
---------
9: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: f74db97c, Virtual address for the attempted write.
Arg2: 3fe85121, PTE contents.
Arg3: f794abdc, (reserved)
Arg4: 0000000b, (reserved)
Debugging Details:
------------------
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: System
CURRENT_IRQL: 2
TRAP_FRAME: f794abdc -- (.trap 0xfffffffff794abdc)
ErrCode = 00000003
eax=f74d0005 ebx=808aeae0 ecx=f74db978 edx=0000e8cd esi=000001ff edi=6b576343
eip=808930e3 esp=f794ac50 ebp=f794ac8c iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!ExAllocatePoolWithTag+0x56b:
808930e3 897904 mov dword ptr [ecx+4],edi ds:0023:f74db97c=ffffe0b0
Resetting default scope
LAST_CONTROL_TRANSFER: from 8085ed19 to 80827c83
STACK_TEXT:
f794ab4c 8085ed19 000000be f74db97c 3fe85121 nt!KeBugCheckEx+0x1b
f794abc4 8088c7c8 00000001 f74db97c 00000000 nt!MmAccessFault+0xb25
f794abc4 808930e3 00000001 f74db97c 00000000 nt!KiTrap0E+0xdc
f794ac8c 808124de 00000000 f776f120 6b576343 nt!ExAllocatePoolWithTag+0x56b
f794ad40 808127a8 97a8a660 808ae5c0 97a5ee40 nt!CcLazyWriteScan+0x2cc
f794ad80 80880469 97a5ee40 00000000 97a8a660 nt!CcWorkerThread+0x140
f794adac 80949b7c 97a5ee40 00000000 00000000 nt!ExpWorkerThread+0xeb
f794addc 8088e092 8088037e 00000000 00000000 nt!PspSystemThreadStartup+0x2e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiTrap0E+dc
8088c7c8 85c0 test eax,eax
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiTrap0E+dc
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 49c21e56
FAILURE_BUCKET_ID: 0xBE_nt!KiTrap0E+dc
BUCKET_ID: 0xBE_nt!KiTrap0E+dc
Followup: MachineOwner
---------
댓글 [0]
번호 | 제목 | 글쓴이 | 조회 | 등록일 |
---|---|---|---|---|
[공지] | 질문과 답변 게시판 이용간 유의사항 | gooddew | - | - |
10571 | 윈 도 우| A.I인증시 인터넷에 연결되야 하나요? [2] | incom10 | 2503 | 12-15 |
10570 | 윈 도 우| MW님이 올리신 AI자동인증 버젼 윈도우7 질문입니다. [2] | 팬더곰 | 3023 | 12-15 |
10569 | 윈 도 우| IE8 보안수준 최소화 방법은 없는건가요? [10] | Star★Bros | 19683 | 12-15 |
10568 | 하드웨어| 넷북이나 노트북 구입하려는데... 어떤것이 괜찮을까요? [3] | less | 2262 | 12-15 |
10567 | 하드웨어| ideebee 같은 무료웹하드 추천 좀 해주시면 감사하겠습니당 [7] | 오마르 | 2881 | 12-15 |
10566 | 윈 도 우| A.I 인증 라이선스 상태 질문드려요. [10] | 뉴탑 | 3283 | 12-15 |
10565 | 윈 도 우| 파티션설정에서 동적파티션 [5] | 어린오리 | 4600 | 12-15 |
10564 | 하드웨어| 한컴 오피스 2007 홈에디션 정품 인증 방식 질문입니다. [6] | 슬픔의언덕 | 11408 | 12-15 |
10563 | 윈 도 우| 익스플로러를 켜면 자꾸 복구하라고 합니다..... [2] | 윈도우77 | 2357 | 12-15 |
10562 | 하드웨어| MKV동영상 펜4에서 무리 인가요? [9] | 현민수 | 3741 | 12-15 |
10561 | 윈 도 우| win7 설치후 부팅속도가 떨어집니다 [10] | 가난한사람 | 3992 | 12-15 |
10560 | 하드웨어| 소리가 안 납니다. [6] | 한승훈 | 2389 | 12-15 |
10559 | 하드웨어| 트루이미지로 백업을 했는데 파일은 없고 용량만 잡아먹어요. [4] | 신념이 | 2406 | 12-15 |
10558 | 윈 도 우| 부팅관리자 창 - 이전버전의 windows [3] | 한냐 | 4315 | 12-15 |
10557 | 윈 도 우| 윈도우 Tiny7 rev02 버전이 도는 것 같은데요.. [3] | Chris | 4272 | 12-15 |
10556 | 윈 도 우| 리알람 다들 적용되시나요~? [7] | 명후이 | 2493 | 12-15 |
10555 | 윈 도 우| 윈도우7을 두개를 설치했는데 이전걸 복구할수는 없나요? [3] | 신념이 | 2759 | 12-15 |
10554 | 윈 도 우| 윈도우7 처음사용자버전 정품인증에 대해 궁금한게 있는데요 [2] | 겨울언제오니 | 3606 | 12-15 |
10553 | 윈 도 우| Kmplayer(32비트)와 리얼텍 사운드드라이버 64비트 와 32비... [2] | 제임스 딘 | 3044 | 12-15 |
10552 | 윈 도 우| 윈도우7 시작메뉴 우측 그림자..관련.. [1] | 아현동마님 | 2566 | 12-15 |