各位老大,帮忙看下,指点下解决思路,在此谢过!!!
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
INVALID_PROCESS_ATTACH_ATTEMPT (5)
Arguments:
Arg1: 8bf45950
Arg2: 8a1b5c10
Arg3: 00000001
Arg4: 00000001
Debugging Details:
------------------
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x5
PROCESS_NAME: System
CURRENT_IRQL: 2
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) x86fre
LAST_CONTROL_TRANSFER: from 818f2e8a to 8190eb0d
STACK_TEXT:
819369cc 818f2e8a 00000005 8bf45950 8a1b5c10 nt!KeBugCheckEx+0x1e
81936a00 81ac2b89 8bf45950 81936a20 5afa4feb nt!KeStackAttachProcess+0x41
81936a58 8cbca4c8 8be3b0e8 8bf45950 00000001 nt!MmProbeAndLockProcessPages+0x32
81936b10 98ba0d37 81936ab8 8be677c0 8bf22588 fltmgr!FltSendMessage+0x1dc
81936b50 98ba1035 98ba306c 8bf22588 8be3be98 fnotify!NotifyFileEvent+0x25d
81936b6c 8cbc50f3 8be3be40 81936b90 9c48fa70 fnotify!fltPostOperationCallback+0x1d1
81936bd0 8cbc8090 00e3bde0 8ac84aab 8be3bde0 fltmgr!FltpPerformPostCallbacks+0x1f1
81936be4 8cbc85c6 8be3bde0 8ac84960 81936c28 fltmgr!FltpProcessIoCompletion+0x10
81936bf4 818e81fb 8a4d0628 8ac84960 8be3bde0 fltmgr!FltpPassThroughCompletion+0x94
81936c28 8cf7dd5f 81936c5c 8cf7d3ee 8a611678 nt!IopfCompleteRequest+0x11d
81936c30 8cf7d3ee 8a611678 8ac84960 00000001 CLASSPNP!ClassCompleteRequest+0x11
81936c5c 818e81fb 00000000 8a9fcb48 009fcd28 CLASSPNP!TransferPktComplete+0x2b6
81936c94 8cb79047 8a9fcdd4 81936cd8 8cb7c658 nt!IopfCompleteRequest+0x11d
81936ca0 8cb7c658 8a9fcb48 00000001 00000000 storport!RaidCompleteRequestEx+0x1c
81936cd8 8cb7931f 8adac008 8193b300 81936d50 storport!RaidUnitCompleteRequest+0x8f
81936ce8 818eb6a2 8a5609cc 8a560958 00000000 storport!RaidpAdapterDpcRoutine+0x28
81936d50 818e987d 00000000 0000000e 00000000 nt!KiRetireDpcList+0x147
81936d54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x49
STACK_COMMAND: kb
FOLLOWUP_IP:
NotifyFileEvent+25d
98ba0d37 685352676d push 6D675253h
FAULTING_SOURCE_LINE:
FAULTING_SOURCE_FILE:
FAULTING_SOURCE_LINE_NUMBER: 1832
FAULTING_SOURCE_CODE:
1831: FltSendMessage(serviceData.Filter,&serviceData.Agent.ClientPort,msgbuffer,AllocSize,NULL,NULL,&timeout);
> 1832: ExFreePoolWithTag(msgbuffer,FCNOTIFY_MESSAGE_TAG);
SYMBOL_STACK_INDEX: 4
FOLLOWUP_NAME: MachineOwner
DEBUG_FLR_IMAGE_TIMESTAMP: 55dd78ad
FAILURE_BUCKET_ID: fnotify!NotifyFileEvent+25d
BUCKET_ID: fnotify!NotifyFileEvent+25d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:fnotify!notifyfileevent+25d
FAILURE_ID_HASH: {3781bde5-e624-f862-9b50-70d03a11160f}
Followup: MachineOwner
---------
server 2008 32位虚拟机中抓的dmp,文件较大,放在网盘上:https://pan.baidu.com/s/1o7Nyjge
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)