C盘驱动里有一堆类似06mHQFi5.sys、8fbnfpVS.sys、3A3LrDZZ.sys等等这样的文件,
查看这些驱动文件,有的有签名有的没,有签名的签名都是Microsoft Windows,
这些驱动文件详细信息文件说明里,都是下列这些的其中一个:
Serial Device Drive
Kernel Security Support Provider Interface
PnP Disk Driver
Network Driver Interface Specification (NDIS)
ATAPI IDE Miniport Drivel
Performance Counters for Windows Driver
NT Plug and Play PCI Enumerato
最后是dbg结果:
Microsoft (R) Windows Debugger Version 10.0.22621.3233 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [Z:\360Downloads\bluescreen\1\MEMORY.DMP]
Kernel Bitmap Dump File: Full address space is available
************* Path valIDAtion summary **************
Response Time (ms) Location
Deferred srv*C:\APP\windbgsymbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: srv*C:\APP\windbgsymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 10 Kernel Version 22621 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 22621.1.amd64fre.ni_release.220506-1250
Machine Name:
Kernel base = 0xfffff802`06000000 PsLoadedModuleList = 0xfffff802`06c13110
Debug session time: Mon Apr 22 11:34:24.222 2024 (UTC + 8:00)
System Uptime: 0 days 0:00:49.025
Loading Kernel Symbols
...............................................................
................................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
..........
For analysis of this file, run !analyze -v
10: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffff80191ce376d, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80208724499, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Unable to load image \SystemRoot\system32\drivers\05tBA8ph.sys, Win32 error 0n2
TRAP_FRAME: ffffa2870ef622f0 -- (.trap 0xffffa2870ef622f0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000005867 rbx=0000000000000000 rcx=ffffffff8b4978c2
rdx=0000000000005867 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80208724499 rsp=ffffa2870ef62480 rbp=ffffa2870ef625e0
r8=0000000000005867 r9=fffff80191cddf06 r10=fffff80206c75640
r11=ffffb58a178e4db0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po nc
05tBA8ph+0x14499:
fffff802`08724499 4a630c08 movsxd rcx,dword ptr [rax+r9] ds:fffff801`91ce376d=????????
Resetting default scope