Имя пользователя:
Пароль:  
Помощь | Регистрация | Забыли пароль?  

Показать сообщение отдельно

Ветеран


Сообщения: 865
Благодарности: 213

Профиль | Отправить PM | Цитировать


Jake153
Информация к размышлению
REFERENCE_BY_POINTER (18)
Arguments:
Arg1: fffffa80066e7570, Object type of the object whose reference count is being lowered
Arg2: fffffa8006cc1820, Object whose reference count is being lowered
Arg3: 0000000000000001, Reserved
Arg4: 0000000000000001, Reserved
The reference count of an object is illegal for the current state of the object.
Each time a driver uses a pointer to an object the driver calls a kernel routine
to increment the reference count of the object. When the driver is done with the
pointer the driver calls another kernel routine to decrement the reference count.
Drivers must match calls to the increment and decrement routines. This bugcheck
can occur because an object's reference count goes to zero while there are still
open handles to the object, in which case the fourth parameter indicates the number
of opened handles. It may also occur when the object?s reference count drops below zero
whether or not there are open handles to the object, and in that case the fourth parameter
contains the actual value of the pointer references count.

Как видим подозреваемый виновник разный.
fffff880`02f1bb08 fffff880`04209e85Unable to load image atikmpag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmpag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmpag.sys
atikmpag+0x9e85

fffff880`02f1b1d8 fffff880`04ed126bUnable to load image iusb3hub.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for iusb3hub.sys
*** ERROR: Module load completed but symbols could not be loaded for iusb3hub.sys
iusb3hub+0x1726b

fffff880`02f1b178 fffff880`1057d9e3Unable to load image iusb3xhc.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for iusb3xhc.sys
*** ERROR: Module load completed but symbols could not be loaded for iusb3xhc.sys
iusb3xhc+0x509e3

fffff880`02f1a688 fffff880`0f081329Unable to load image atikmdag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
atikmdag+0x5e329

fffff880`02f19ec8 fffff880`0f006c87Unable to load image L1C62x64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for L1C62x64.sys
*** ERROR: Module load completed but symbols could not be loaded for L1C62x64.sys
L1C62x64+0x6c87


Смотрим аргумент 1. fffffa80066e7570
GetUlongFromAddress: unable to read from fffff800034b5010
Could not read ObjectType address

Смотрим аргумент 2. fffffa8009c07690
GetUlongFromAddress: unable to read from fffff800034b5010
Could not read ObjectType address

Смотрим память по этому адресу: fffff800034b5010
fffff800`034b5010 ???????? ???????? ???????? ???????? ????????????????
fffff800`034b5020 ???????? ???????? ???????? ???????? ????????????????
fffff800`034b5030 ???????? ???????? ???????? ???????? ????????????????
fffff800`034b5040 ???????? ???????? ???????? ???????? ????????????????
fffff800`034b5050 ???????? ???????? ???????? ???????? ????????????????
fffff800`034b5060 ???????? ???????? 00000000 ???????? ????????....????
fffff800`034b5070 ???????? 00000000 ???????? ???????? ????....????????
fffff800`034b5080 ???????? ???????? ???????? ???????? ????????????????

В последних дампах синий экран появлялся во время процесса chrome.exe
GetPointerFromAddress: unable to read from fffff800034c5000
PROCESS fffffa800921a700
SessionId: none Cid: 1848 Peb: fffdf000 ParentCid: 1250
DirBase: b2980000 ObjectTable: fffff8a002e51ab0 HandleCount: <Data Not Accessible>
Image: chrome.exe
VadRoot fffffa8007ad9e70 Vads 357 Clone 0 Private 84521. Modified 37087. Locked 0.
DeviceMap fffff8a0013054f0
Token fffff8a009f33060
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 466472
QuotaPoolUsage[NonPagedPool] 43064
Working Set Sizes (now,min,max) (109059, 50, 345) (436236KB, 200KB, 1380KB)
PeakWorkingSetSize 111594
VirtualSize 647 Mb
PeakVirtualSize 660 Mb
PageFaultCount 581689
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 89748
Job fffffa8008905b30

*** Error in reading nt!_ETHREAD @ fffffa8008e9a3b0


В В майском дампе синий экран появлялся во время процесса BlackDesert64, в это время еще atikmpag.sys был старой версии
GetPointerFromAddress: unable to read from fffff80003500000
PROCESS fffffa8007b7bb30
SessionId: none Cid: 1394 Peb: 7fffffde000 ParentCid: 1290
DirBase: 55faf000 ObjectTable: fffff8a008f54b40 HandleCount: <Data Not Accessible>
Image: BlackDesert64.
VadRoot fffffa8008afffc0 Vads 448 Clone 0 Private 378664. Modified 11606. Locked 16155.
DeviceMap fffff8a002da5e40
Token fffff8a00b299a90
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 1252952
QuotaPoolUsage[NonPagedPool] 62152
Working Set Sizes (now,min,max) (383907, 50, 345) (1535628KB, 200KB, 1380KB)
PeakWorkingSetSize 385773
VirtualSize 1815 Mb
PeakVirtualSize 1824 Mb
PageFaultCount 2857490
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 410570
Job fffffa80070b1e30

*** Error in reading nt!_ETHREAD @ fffffa8007b74b60

1. Скачайте программу по удалению Avira AntiVir и удалите этот антивирус
avgntflt.sys Thu Jul 02 12:44:38 2015 Avira AntiVir

2. Почему не делаете системные обновления или ститаете, что достаточно обновить только драйвер видео?
dxgkrnl.sys Sat Nov 20 12:50:50 2010 DirectX Graphics Kernel
dxgmms1.sys Sat Nov 20 12:49:53 2010 DirectX Graphics MMS

3. Neo_0068.sys Fri May 29 20:23:30 2015 WindowexeAllkiller Давайте тоже удалим эту программу

Жду Ваших сообщений.

Отправлено: 15:21, 28-10-2015 | #2024