询问者
电脑蓝屏 A critical system process died

问题
-
各位大神好,
现在发现一台新装的三星笔记本频繁出现蓝屏问题,代码是A critical system process died,系统是WIN10 64 PRO.
现在我已经做的操作是:1:WIN10 UPDATE 更新到最新 2:三星官方自带的驱动软件Samsung update,BIOS和驱动更新到最新 3:SFC \scannow 和 CHKDSK没有问题。
WINDBG Log如下:
Microsoft (R) Windows Debugger Version 10.0.18362.1 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
************* Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 10 Kernel Version 18362 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base = 0xfffff804`4f000000 PsLoadedModuleList = 0xfffff804`4f446490
Debug session time: Thu Aug 29 17:52:24.913 2019 (UTC + 8:00)
System Uptime: 0 days 0:04:57.681
Loading Kernel Symbols
.....................................Page 20015015e too large to be in the dump file.
Page 2001fd55d too large to be in the dump file.
..........................
................................................................
................................................................
...............
Loading User Symbols
................................................................
...................................
Loading unloaded module list
...............
For analysis of this file, run !analyze -v
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffa78f50ece080, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
Page 20015015e too large to be in the dump file.
Page 2001fd55d too large to be in the dump file.
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: SAMSUNG ELECTRONICS CO., LTD.
SYSTEM_PRODUCT_NAME: 900X3L
SYSTEM_SKU: ATIV A5A5-A5A5-A5A5-A5A5-A5A5-PAFN
SYSTEM_VERSION: P10AFN
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P10AFN.046.180605.KS
BIOS_DATE: 06/05/2018
BASEBOARD_MANUFACTURER: SAMSUNG ELECTRONICS CO., LTD.
BASEBOARD_PRODUCT: NP900X3L-EG1CN
BASEBOARD_VERSION: SGL8830A0H-C01-G001-S0002+10.0.14393
DUMP_TYPE: 1
BUGCHECK_P1: ffffa78f50ece080
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: svchost.exe
CRITICAL_PROCESS: svchost.exe
EXCEPTION_RECORD: ffffa78f50ece640 -- (.exr 0xffffa78f50ece640)
ExceptionAddress: 0000000000000000
ExceptionCode: 00000000
ExceptionFlags: 00000000
NumberParameters: 0
EXCEPTION_CODE: (NTSTATUS) 0x54e5b080 - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0x54e5b080 - <Unable to get error code text>
CPU_COUNT: 4
CPU_MHZ: a20
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 4e
CPU_STEPPING: 3
CPU_MICROCODE: 6,4e,3,0 (F,M,S,R) SIG: C6'00000000 (cache) C6'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: CN31LCLI
ANALYSIS_SESSION_TIME: 09-11-2019 11:09:14.0935
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8044f8c9b99 to fffff8044f1bfcc0
THREAD_SHA1_HASH_MOD_FUNC: 06aab4c21fb1981b10bcb51fdea16d51dac0db36
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e275b956c879ffc910b0a64023ce631a0decae24
THREAD_SHA1_HASH_MOD: 560a0dc4c571037edf944f23e2b5cb3a54ebf676
FOLLOWUP_IP:
ntdll!RtlLookupFunctionEntry+82
00007ffc`8449e322 448b1c87 mov r11d,dword ptr [rdi+rax*4]
FAULT_INSTR_CODE: 871c8b44
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: ntdll!RtlLookupFunctionEntry+82
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ntdll
IMAGE_NAME: ntdll.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 82
FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_54e5b080_ntdll!RtlLookupFunctionEntry
BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_54e5b080_ntdll!RtlLookupFunctionEntry
PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_54e5b080_ntdll!RtlLookupFunctionEntry
TARGET_TIME: 2019-08-29T09:52:24.000Z
OSBUILD: 18362
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1998-05-31 05:12:57
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 988b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_54e5b080_ntdll!rtllookupfunctionentry
FAILURE_ID_HASH: {0748a5d3-45e5-7c4c-71dd-dd5f4328a3ec}
Followup: MachineOwner
---------
3: kd>
ExceptionAddress: 0000000000000000
ExceptionCode: 00000000
ExceptionFlags: 00000000
NumberParameters: 0
3: kd> !process
PROCESS ffffa78f50ece080
SessionId: 0 Cid: 037c Peb: f936fa2000 ParentCid: 02c4
DirBase: 218add002 ObjectTable: ffffd68257f7c380 HandleCount: 1173.
Image: svchost.exe
VadRoot ffffa78f50e93f10 Vads 182 Clone 0 Private 4318. Modified 196. Locked 1.
DeviceMap ffffd68253a138a0
Token ffffd68257ea7560
ElapsedTime 00:04:52.249
UserTime 00:00:00.062
KernelTime 00:00:00.093
QuotaPoolUsage[PagedPool] 785912
QuotaPoolUsage[NonPagedPool] 27880
Working Set Sizes (now,min,max) (9267, 50, 345) (37068KB, 200KB, 1380KB)
PeakWorkingSetSize 9129
VirtualSize 2101410 Mb
PeakVirtualSize 2101410 Mb
PageFaultCount 11018
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 4992
THREAD ffffa78f50ecf080 Cid 037c.0380 Teb: 000000f936fa3000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f50e6d460 SynchronizationEvent
THREAD ffffa78f50f0d080 Cid 037c.03c0 Teb: 000000f936faf000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
00007ffc7f351440 Unknown
THREAD ffffa78f50f0e040 Cid 037c.03c4 Teb: 000000f936fb1000 Win32Thread: ffffa78f52e72760 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
00007ffc7f351440 Unknown
THREAD ffffa78f50f11080 Cid 037c.03d4 Teb: 000000f936fb5000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50f1a640 QueueObject
THREAD ffffa78f526cd080 Cid 037c.04bc Teb: 000000f936fc1000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f52650e60 SynchronizationEvent
ffffa78f5264fb60 SynchronizationEvent
THREAD ffffa78f52713080 Cid 037c.04d0 Teb: 000000f936fc5000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f526db580 QueueObject
THREAD ffffa78f5270d080 Cid 037c.04ec Teb: 000000f936fc7000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f492a46a0 NotificationEvent
ffffa78f52663be0 SynchronizationEvent
ffffa78f52661560 SynchronizationEvent
THREAD ffffa78f5270c080 Cid 037c.04f0 Teb: 000000f936fc9000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
0000026b70e299b8 Unknown
THREAD ffffa78f52782080 Cid 037c.0648 Teb: 000000f936fcd000 Win32Thread: 0000000000000000 WAIT: (Executive) UserMode Non-Alertable
ffffa78f492a40a0 NotificationEvent
THREAD ffffa78f52b82080 Cid 037c.1970 Teb: 000000f936fd7000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50eef700 QueueObject
THREAD ffffa78f52ba0080 Cid 037c.1a90 Teb: 000000f936fd9000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50eef700 QueueObject
THREAD ffffa78f52e30080 Cid 037c.1ad4 Teb: 000000f936fdb000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50eef700 QueueObject
THREAD ffffa78f52f8d080 Cid 037c.1a0c Teb: 000000f936fdd000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f492a4520 NotificationEvent
ffffa78f53cf0130 NotificationEvent
THREAD ffffa78f53c3c080 Cid 037c.0600 Teb: 000000f936fdf000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f55310260 NotificationEvent
THREAD ffffa78f53493300 Cid 037c.0d54 Teb: 000000f936fe1000 Win32Thread: 0000000000000000 WAIT: (Executive) UserMode Non-Alertable
ffffa78f492a40a0 NotificationEvent
THREAD ffffa78f53b64080 Cid 037c.1210 Teb: 000000f936fe3000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f536fa0d0 SynchronizationTimer
THREAD ffffa78f543ca080 Cid 037c.1238 Teb: 000000f936fe5000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f528e2b80 QueueObject
THREAD ffffa78f54690040 Cid 037c.0190 Teb: 000000f936fe7000 Win32Thread: 0000000000000000 WAIT: (Executive) UserMode Non-Alertable
ffffa78f492a40a0 NotificationEvent
THREAD ffffa78f53e94080 Cid 037c.1eb8 Teb: 000000f936fe9000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f54c54540 QueueObject
THREAD ffffa78f54e5b080 Cid 037c.1f24 Teb: 000000f936feb000 Win32Thread: 0000000000000000 RUNNING on processor 3
THREAD ffffa78f54e4d080 Cid 037c.1f6c Teb: 000000f936fed000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f54c5ae40 QueueObject
THREAD ffffa78f54f36080 Cid 037c.1554 Teb: 000000f936fef000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
00007ffc7f351440 Unknown
THREAD ffffa78f55098080 Cid 037c.20cc Teb: 000000f936ff1000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f526db580 QueueObject
THREAD ffffa78f5523e080 Cid 037c.2298 Teb: 000000f936ff3000 Win32Thread: 0000000000000000 WAIT: (Executive) UserMode Non-Alertable
ffffa78f492a40a0 NotificationEvent
THREAD ffffa78f5521e080 Cid 037c.2374 Teb: 000000f936ff5000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f526db580 QueueObject
THREAD ffffa78f4eeb2080 Cid 037c.1f84 Teb: 000000f936ff7000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f526db580 QueueObject
THREAD ffffa78f5488f080 Cid 037c.2284 Teb: 000000f936ff9000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
0000026b70e299b8 Unknown
THREAD ffffa78f5488e080 Cid 037c.15bc Teb: 000000f936ffb000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f55302760 NotificationEvent
THREAD ffffa78f54def040 Cid 037c.2334 Teb: 000000f936ffd000 Win32Thread: 0000000000000000 WAIT: (Executive) UserMode Non-Alertable
ffffa78f492a40a0 NotificationEvent
THREAD ffffa78f50fee080 Cid 037c.0234 Teb: 000000f936e00000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable
ffffa78f553028e0 NotificationEvent
THREAD ffffa78f52860080 Cid 037c.18cc Teb: 000000f936e02000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
00007ffc7f351440 Unknown
THREAD ffffa78f52908080 Cid 037c.2120 Teb: 000000f936e04000 Win32Thread: 0000000000000000 WAIT: (WrAlertByThreadId) UserMode Non-Alertable
0000026b70e299b8 Unknown
THREAD ffffa78f550fa040 Cid 037c.1e50 Teb: 000000f936e06000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50e91e00 QueueObject
THREAD ffffa78f55231080 Cid 037c.170c Teb: 000000f936e08000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50e91e00 QueueObject
THREAD ffffa78f550d3080 Cid 037c.1354 Teb: 000000f936e0a000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50e91e00 QueueObject
THREAD ffffa78f550d4080 Cid 037c.06c4 Teb: 000000f936e0c000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffa78f50e91e00 QueueObject