9176324 / Shark

Turn off PatchGuard in real time for win7 (7600) ~ later
MIT License
986 stars 303 forks source link

sometime BSOD - SYSTEM_THREAD_EXCEPTION_NOT_HANDLED #13

Closed YangKi1902 closed 3 years ago

YangKi1902 commented 5 years ago

hello, sometime i got BSOD with SYSTEM_THREAD_EXCEPTION_NOT_HANDLED code, same with windows 7 and windows 10 64 bit, here the log :

`***

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc000001d, The exception code that was not handled Arg2: ffffa981810a2a54, The address that the exception occurred at Arg3: ffff8c095bacf7a8, Exception Record Address Arg4: ffff8c095baceff0, Context Record Address

Debugging Details:

KEY_VALUES_STRING: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

DUMP_CLASS: 1

DUMP_QUALIFIER: 401

BUILD_VERSION_STRING: 17763.1.amd64fre.rs5_release.180914-1434

SYSTEM_MANUFACTURER: Razer

SYSTEM_PRODUCT_NAME: Blade Stealth

SYSTEM_SKU: RZ09-02393E31

SYSTEM_VERSION: 4.06

BIOS_VENDOR: Razer

BIOS_VERSION: 3.02

BIOS_DATE: 02/22/2018

BASEBOARD_MANUFACTURER: Razer

BASEBOARD_PRODUCT: Blade Stealth

DUMP_TYPE: 1

BUGCHECK_P1: ffffffffc000001d

BUGCHECK_P2: ffffa981810a2a54

BUGCHECK_P3: ffff8c095bacf7a8

BUGCHECK_P4: ffff8c095baceff0

EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.

FAULTING_IP: +0 ffffa981`810a2a54 c7 ???

EXCEPTION_RECORD: ffff8c095bacf7a8 -- (.exr 0xffff8c095bacf7a8) ExceptionAddress: ffffa981810a2a54 ExceptionCode: c000001d (Illegal instruction) ExceptionFlags: 00000000 NumberParameters: 0

CONTEXT: ffff8c095baceff0 -- (.cxr 0xffff8c095baceff0) rax=ffffa981810bb31f rbx=ffffa981810bb31f rcx=ffffa981810a02d9 rdx=0000000000000000 rsi=ffffa981810a0a59 rdi=ffffa981810a02d9 rip=ffffa981810a2a54 rsp=ffff8c095bacf9e0 rbp=fffff801419af7d0 r8=0000000000000023 r9=0000000000000000 r10=fffff801419af7d0 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=ffffa9817ec7fc1a r15=fffff80141d72240 iopl=0 nv up ei ng nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286 ffffa981`810a2a54 c7 ??? Resetting default scope

CPU_COUNT: 8

CPU_MHZ: 7c8

CPU_VENDOR: GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 8e

CPU_STEPPING: a

CPU_MICROCODE: 6,8e,a,0 (F,M,S,R) SIG: 84'00000000 (cache) 84'00000000 (init)

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXPNP: 1 (!blackboxpnp)

DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT

BUGCHECK_STR: AV

PROCESS_NAME: System

CURRENT_IRQL: 0

ERROR_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.

EXCEPTION_CODE_STR: c000001d

ANALYSIS_SESSION_HOST: DESKTOP-QPBMC3H

ANALYSIS_SESSION_TIME: 04-22-2019 22:26:49.0234

ANALYSIS_VERSION: 10.0.17763.132 amd64fre

LAST_CONTROL_TRANSFER: from 000000007e7cf03d to ffffa981810a2a54

FAILED_INSTRUCTION_ADDRESS: +0 ffffa981`810a2a54 c7 ???

STACK_TEXT:
ffff8c095bace788 fffff801419e01b1 : 000000000000007e ffffffffc000001d ffffa981810a2a54 ffff8c095bacf7a8 : nt!KeBugCheckEx ffff8c095bace790 fffff801419a346f : 0000000000000003 ffff8c095bacfb10 ffff8c095bac9000 ffff8c095bad0000 : nt!PspSystemThreadStartup$filt$0+0x44 ffff8c095bace7d0 fffff801419d121f : ffff8c095bacfb10 ffff8c095bacedb0 ffff8c095bacee90 000000000010001f : nt!_C_specific_handler+0x9f ffff8c095bace840 fffff8014192a240 : ffff8c095bacee90 0000000000000000 ffff8c095bacedb0 0000000000000000 : nt!RtlpExecuteHandlerForException+0xf ffff8c095bace870 fffff80141837ac4 : ffff8c095bacf7a8 ffff8c095bacf4f0 ffff8c095bacf7a8 ffffa981810a02d9 : nt!RtlDispatchException+0x430 ffff8c095bacefc0 fffff801419d9f42 : 0000000000000000 0000000000000000 0000000000000000 fffff80141817e22 : nt!KiDispatchException+0x144 ffff8c095bacf670 fffff801419d478e : ffffbe002b9d8200 0000000000000001 ffffa9818c5e33c0 0000000000000000 : nt!KiExceptionDispatch+0xc2 ffff8c095bacf850 ffffa981810a2a54 : 000000007e7cf03d ffffa981810bb328 ffffa98100000000 ffffa9817eca8680 : nt!KiInvalidOpcodeFault+0x30e ffff8c095bacf9e0 000000007e7cf03d : ffffa981810bb328 ffffa98100000000 ffffa9817eca8680 ffffe78c00000000 : 0xffffa981810a2a54 ffff8c095bacf9e8 ffffa981810bb328 : ffffa98100000000 ffffa9817eca8680 ffffe78c00000000 0000000000000000 : 0x7e7cf03d ffff8c095bacf9f0 ffffa98100000000 : ffffa9817eca8680 ffffe78c00000000 0000000000000000 ffffa9817eca8680 : 0xffffa981810bb328 ffff8c095bacf9f8 ffffa9817eca8680 : ffffe78c00000000 0000000000000000 ffffa9817eca8680 fffff801558fd50c : 0xffffa98100000000 ffff8c095bacfa00 ffffe78c00000000 : 0000000000000000 ffffa9817eca8680 fffff801558fd50c ffffa9818fe2f640 : 0xffffa9817eca8680 ffff8c095bacfa08 0000000000000000 : ffffa9817eca8680 fffff801558fd50c ffffa9818fe2f640 fffff80141d72240 : 0xffffe78c`00000000

THREAD_SHA1_HASH_MOD_FUNC: 0305f1688681aebed0adad04f2a1f9bbfa632561

THREAD_SHA1_HASH_MOD_FUNC_OFFSET: d02f21f1f7e352aab835030d8af9e02e0e8a177a

THREAD_SHA1_HASH_MOD: cb5f414824c2521bcc505eaa03e92fa10922dad8

FOLLOWUP_IP: nt!PspSystemThreadStartup$filt$0+44 fffff801`419e01b1 90 nop

FAULT_INSTR_CODE: c4834890

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!PspSystemThreadStartup$filt$0+44

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 438ffec3

STACK_COMMAND: .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET: 44

FAILURE_BUCKET_ID: AV_BAD_IP_nt!PspSystemThreadStartup$filt$0

BUCKET_ID: AV_BAD_IP_nt!PspSystemThreadStartup$filt$0

PRIMARY_PROBLEM_CLASS: AV_BAD_IP_nt!PspSystemThreadStartup$filt$0

TARGET_TIME: 2019-04-22T15:08:01.000Z

OSBUILD: 17763

OSSERVICEPACK: 0

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 784

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal

OS_LOCALE:

USER_LCID: 0

OSBUILD_TIMESTAMP: 2005-12-02 14:58:59

BUILDDATESTAMP_STR: 180914-1434

BUILDLAB_STR: rs5_release

BUILDOSVER_STR: 10.0.17763.1.amd64fre.rs5_release.180914-1434

ANALYSIS_SESSION_ELAPSED_TIME: 4e6

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:av_bad_ip_nt!pspsystemthreadstartup$filt$0

FAILURE_ID_HASH: {32e528d8-24a5-3b2e-58ad-3857d4ab6660}

Followup: MachineOwner ---------`

9176324 commented 5 years ago

应该是 重新启动 ExpWorkerThread 的时候 环境出了问题 可以选择直接干掉线程

YangKi1902 commented 5 years ago

hello, can you tech me a snippet for it ?

hzqst commented 5 years ago

hello, can you tech me a snippet for it ?

should be fixed now.

YangKi1902 commented 5 years ago

hello, can you tech me a snippet for it ?

should be fixed now.

thanks, i will try to test.