用windbg 的!analyze -v命令分析后的结果:
FAULTING_MODULE: 84849000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bbf28
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx
FAULTING_IP:
Wdf01000+40018
8b67b018 8b700c mov esi,dword ptr [eax+0Ch]
TRAP_FRAME: c60fd9a8 -- (.trap ffffffffc60fd9a8)
ErrCode = 00000000
eax=fffffff8 ebx=90a5d610 ecx=00000000 edx=00000000 esi=870335d8 edi=00000000
eip=8b67b018 esp=c60fda1c ebp=c60fda28 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
Wdf01000+0x40018:
8b67b018 8b700c mov esi,dword ptr [eax+0Ch] ds:0023:00000004=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
BUGCHECK_STR: 0x8E
LAST_CONTROL_TRANSFER: from c5a9de96 to 8b67b018
STACK_COMMAND: kb
FOLLOWUP_IP:
Wdf01000+40018
8b67b018 8b700c mov esi,dword ptr [eax+0Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Wdf01000+40018
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Wdf01000
IMAGE_NAME: Wdf01000.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
0: kd> lmvm Wdf01000
start end module name
8b63b000 8b6ac000 Wdf01000 T (no symbols)
Loaded symbol image file: Wdf01000.sys
Image path: \SystemRoot\system32\drivers\Wdf01000.sys
Image name: Wdf01000.sys
Timestamp: Tue Jul 14 07:11:36 2009 (4A5BBF28)
CheckSum: 000717B7
ImageSize: 00071000
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0