请大神帮忙分析一个问题呢。windbg信息如下:
INVALID_PROCESS_ATTACH_ATTEMPT (5)
Arguments:
Arg1: ffffe000a664e900
Arg2: ffffe000a36c8900
Arg3: 0000000000000001
Arg4: 0000000000000001
Debugging Details:
------------------
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 9600.17936.amd64fre.winblue_ltsb.150715-0840
SYSTEM_MANUFACTURER: VMware, Inc.
VIRTUAL_MACHINE: VMware
SYSTEM_PRODUCT_NAME: VMware Virtual Platform
SYSTEM_VERSION: None
BIOS_VENDOR: Phoenix Technologies LTD
BIOS_VERSION: 6.00
BIOS_DATE: 09/21/2015
BASEBOARD_MANUFACTURER: Intel Corporation
BASEBOARD_PRODUCT: 440BX Desktop Reference Platform
BASEBOARD_VERSION: None
DUMP_TYPE: 1
BUGCHECK_P1: ffffe000a664e900
BUGCHECK_P2: ffffe000a36c8900
BUGCHECK_P3: 1
BUGCHECK_P4: 1
CPU_COUNT: c
CPU_MHZ: 898
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 4f
CPU_STEPPING: 1
CPU_MICROCODE: 6,4f,1,0 (F,M,S,R) SIG: B00001E'00000000 (cache) B00001E'00000000 (init)
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x5
PROCESS_NAME: System
CURRENT_IRQL: 1
ANALYSIS_SESSION_HOST: DESKTOP-BNLMI0B
ANALYSIS_SESSION_TIME: 04-01-2017 16:21:18.0112
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
LAST_CONTROL_TRANSFER: from fffff803fa017240 to fffff803f9fd39a0
STACK_TEXT:
fffff803`fb8dacc8 fffff803`fa017240 : 00000000`00000005 ffffe000`a664e900 ffffe000`a36c8900 00000000`00000001 : nt!KeBugCheckEx
fffff803`fb8dacd0 fffff803`fa2aecaa : 00000000`00000001 ffffe000`a655df00 ffffe000`a74eaf40 fffff803`fb8dae18 : nt! ?? ::FNODOBFM::`string'+0x33380
fffff803`fb8dad20 fffff801`ac0f126a : ffffe000`a59d7ee0 00000000`00000000 00000000`00000000 00000000`00000f01 : nt!MmProbeAndLockProcessPages+0x56
fffff803`fb8dada0 fffff801`ae801097 : ffffe000`a69a29c8 ffffe000`a751c74a fffff803`fb8dafc0 fffff801`00000438 : fltmgr!FltSendMessage+0x24a
fffff803`fb8daee0 fffff801`ae8100f7 : fffff803`fb8dafc0 ffffe000`00000438 00000000`00000000 fffff803`fb8dafa0 : HiveMiniFilter!MyFltSendMessage+0x87 [g:\hive\hivefilecontrol\hiveminifilter\operation.c @ 1228]
fffff803`fb8daf40 fffff801`ac0ebe8b : ffffe000`a69a29c8 fffff803`fb8db478 00000000`00000000 fffff801`00000000 : HiveMiniFilter!WritePostOperation+0x467 [g:\hive\hivefilecontrol\hiveminifilter\operation.c @ 852]
fffff803`fb8db430 fffff801`ac0ec5ad : 00000000`00000000 00000000`00000000 ffffe000`a74ccf40 ffffe000`a74f5cf0 : fltmgr!FltpPerformPostCallbacks+0x34b
fffff803`fb8db500 fffff803`f9f1253e : ffffe000`a74f5cf0 00000000`00000000 ffffe000`a74f5e53 ffffe000`a7310dd4 : fltmgr!FltpPassThroughCompletionWorker+0x7d
fffff803`fb8db570 fffff801`ad2d4ac5 : ffffe000`a74f5cf0 00000000`00000001 00000000`00000000 00000000`00000000 : nt!IopfCompleteRequest+0x2ee
fffff803`fb8db6b0 fffff801`ad2d72db : 00000000`00000000 ffffe000`a71b7ca0 fffff801`ad2f8010 ffffe000`a44ee801 : rdbss!RxCompleteRequestEx+0x1f5
fffff803`fb8db760 fffff801`ad2d911f : ffffe000`a549c030 00000000`00000000 00000000`00000000 fffff801`ac197010 : rdbss!RxLowIoCompletionTail+0xab
fffff803`fb8db7a0 fffff801`ac1d62ad : ffffe000`a549c030 ffffe000`a7351de8 ffffe000`a7351ed0 ffffe000`a66e4920 : rdbss!RxLowIoCompletion+0x3f
fffff803`fb8db7e0 fffff801`ac1606c1 : ffffe000`00000000 00000000`00000000 ffffe000`a71b7ca0 ffffe000`a549c030 : mrxsmb20!Smb2Write_Finalize+0x1cd
fffff803`fb8db850 fffff801`ac161dd9 : ffffe000`a7311db0 ffffe000`a7351ed0 00000000`00005701 00000000`00000001 : mrxsmb!SmbCeSendCompleteInd+0x451
fffff803`fb8db8f0 fffff803`f9f1253e : ffffe000`a65c0b90 fffff803`fb8dba40 00000000`00000000 ffffe000`a65c0c63 : mrxsmb!SmbWskSendComplete+0xc9
fffff803`fb8db940 fffff801`ad402dd2 : ffffe000`a65c0b90 ffff1be1`2956af02 ffffe000`a41f410c 00000000`00000000 : nt!IopfCompleteRequest+0x2ee
fffff803`fb8dba80 fffff801`acaa35a1 : 00000000`00000000 ffffe000`a526f0d0 fffff803`fb8dbbe0 fffff803`fb8dbdc8 : afd!WskProTLSendOrDisconnectComplete+0x72
fffff803`fb8dbae0 fffff801`acaa8ce0 : 00000000`00000001 fffff801`aca787e0 00000000`00000000 ffffe000`a3d29150 : tcpip!TcpTcbReceive+0x311
fffff803`fb8dbc30 fffff801`acaa86f5 : ffffe000`a44d382c 00000000`00000000 00000000`00000000 ffffe000`a3dcf0e0 : tcpip!TcpMatchReceive+0x1f0
fffff803`fb8dbdc0 fffff801`acaeb990 : ffffe000`a3de65c0 00000000`00000000 00000000`00006cc0 ffffe000`a52cd000 : tcpip!TcpPreValidatedReceive+0x385
fffff803`fb8dbec0 fffff801`aca789d2 : ffffe000`a45b4770 fffff801`aca787e0 fffff801`aca70006 00000000`00000006 : tcpip!IpFlcReceivePreValidatedPackets+0x650
fffff803`fb8dc080 fffff803`f9f3efa3 : fffffff6`0000000c 00000000`00000000 ffffe000`a3daee10 fffff803`fb8d7000 : tcpip!FlReceiveNetBufferListChainCalloutRoutine+0x102
fffff803`fb8dc1b0 fffff801`aca78b26 : fffff801`aca788d0 fffff803`fb8dc2d0 ffffe000`a43b2c10 00000000`00000000 : nt!KeExpandKernelStackAndCalloutInternal+0xf3
fffff803`fb8dc2a0 fffff801`abe02903 : 00000000`00000000 fffff803`fb8dc381 ffffe000`00000001 ffffe000`a6a24b60 : tcpip!FlReceiveNetBufferListChain+0xb6
fffff803`fb8dc320 fffff801`abe0308a : 00000000`ffffff01 ffffe000`a6a20008 00000000`00000000 ffffe000`00000001 : NDIS!ndisMIndicateNetBufferListsToOpen+0x123
fffff803`fb8dc3e0 fffff801`ae2461c4 : ffffe000`a4319000 fffff801`ae246efc ffffe000`a4319e00 ffffe000`a44ee8a0 : NDIS!NdisMIndicateReceiveNetBufferLists+0x32a
fffff803`fb8dc5c0 fffff801`ae246a9d : 00000000`00000001 ffffe000`a44ee8a0 ffffe000`a4319000 00000000`00000001 : e1i63x64!RECEIVE::RxIndicateNBLs+0xd4
fffff803`fb8dc600 fffff801`ae239150 : 00000000`00000000 ffffe000`a3bc84c0 00000000`00000000 ffff0001`00000000 : e1i63x64!RECEIVE::RxProcessInterrupts+0x19d
fffff803`fb8dc680 fffff801`ae23957e : ffffe000`a3bc84c0 ffffe000`a4319000 ffff0001`00000000 ffff0001`00000000 : e1i63x64!INTERRUPT::MsgIntDpcTxRxProcessing+0x1c0
fffff803`fb8dc6f0 fffff801`ae238b78 : fffff803`fb8dc829 ffff0001`00000000 fffff801`ae238af0 ffffe000`a43b5000 : e1i63x64!INTERRUPT::MsgIntMessageInterruptDPC+0x13e
fffff803`fb8dc750 fffff801`abe04005 : fffff803`fa185f00 fffff803`f9f78f50 ffffe000`a3cefb50 fffff801`aca74db3 : e1i63x64!INTERRUPT::MiniportMessageInterruptDPC+0x28
fffff803`fb8dc790 fffff803`f9f061e0 : fffff803`fb8dcb20 fffff803`fa183180 00000000`00000002 fffff803`f9e1a58f : NDIS!ndisInterruptDpc+0x1b5
fffff803`fb8dc890 fffff803`f9f05527 : 00000000`00000000 ffffe000`a6c23080 fffff803`fa183180 fffff803`00000001 : nt!KiExecuteAllDpcs+0x1b0
fffff803`fb8dc9e0 fffff803`f9fd74ea : fffff803`fa183180 fffff803`fa183180 fffff803`fa1dca00 ffffe000`a74b2080 : nt!KiRetireDpcList+0xd7
fffff803`fb8dcc60 00000000`00000000 : fffff803`fb8dd000 fffff803`fb8d7000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
THREAD_SHA1_HASH_MOD_FUNC: d2981fe6e73ec9f0b84eb44b493f49f89a00e201
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 34d50751ba9b5b2fbee71d6ef497f0cbba7c72b6
THREAD_SHA1_HASH_MOD: 9fc1487c4bae9e906abf2f35ff2f82eaf67cfcde
FOLLOWUP_IP:
HiveMiniFilter!MyFltSendMessage+87 [g:\hive\hivefilecontrol\hiveminifilter\operation.c @ 1228]
fffff801`ae801097 89442444 mov dword ptr [rsp+44h],eax
FAULT_INSTR_CODE: 44244489
FAULTING_SOURCE_LINE: g:\hive\hivefilecontrol\hiveminifilter\operation.c
FAULTING_SOURCE_FILE: g:\hive\hivefilecontrol\hiveminifilter\operation.c
FAULTING_SOURCE_LINE_NUMBER: 1228
FAULTING_SOURCE_CODE:
1224: {
1225: KeLowerIrql(APC_LEVEL);
1226: bLower = TRUE;
1227: }
> 1228: status = FltSendMessage(gFilterData.Filter, &gFilterData.ClientPort, SenderBuffer, SenderBufferLength, ReplyBuffer, ReplyLength, Timeout);
1229: if (bLower)
1230: {
1231: KfRaiseIrql(irqlTemp);
1232: }
1233: return status;
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: HiveMiniFilter!MyFltSendMessage+87
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: HiveMiniFilter
IMAGE_NAME: HiveMiniFilter.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 58df58ff
BUCKET_ID_FUNC_OFFSET: 87
FAILURE_BUCKET_ID: 0x5_HiveMiniFilter!MyFltSendMessage
BUCKET_ID: 0x5_HiveMiniFilter!MyFltSendMessage
PRIMARY_PROBLEM_CLASS: 0x5_HiveMiniFilter!MyFltSendMessage
TARGET_TIME: 2017-04-01T07:53:11.000Z
OSBUILD: 9600
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 3
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
OSEDITION: Windows 8.1 Server TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2015-07-16 00:37:58
BUILDDATESTAMP_STR: 150715-0840
BUILDLAB_STR: winblue_ltsb
BUILDOSVER_STR: 6.3.9600.17936.amd64fre.winblue_ltsb.150715-0840
ANALYSIS_SESSION_ELAPSED_TIME: 12ec
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x5_hiveminifilter!myfltsendmessage
FAILURE_ID_HASH: {a6e529d2-2eaf-b55f-5301-2b165c167fba}
Followup: MachineOwner
开始报异常,是因为函数不晓得什么原因运行在DISPATCH_LEVEL 等级,降级后,就这样蓝屏了。
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课