Geçen günlerde bilgisayarım açılırken hiç yoktan mavi ekran hatası aldım. Normal CRITICAL_PROCESS_DIED gibi yazı olan hata kodu yerine 0xc000021a yazıyordu, ayrıyeten sistemde hiçbir değişiklik yapmadım ve virüs olmadığından eminim. Dump dosyası analizi:
[CODE title="Windbg analizi"]*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffff8d0dd844e6b0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001b07e920000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 6
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on MINT
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 5
Key : Analysis.Memory.CommitPeak.Mb
Value: 80
Key : Analysis.System
Value: CreateObject
ERROR_CODE: (NTSTATUS) 0xc000021a - { nemli Sistem Hatas } %hs sistem i lemi, 0x
EXCEPTION_CODE_STR: c000021a
EXCEPTION_PARAMETER1: ffff8d0dd844e6b0
EXCEPTION_PARAMETER2: ffffffffc0000428
EXCEPTION_PARAMETER3: 0000000000000000
EXCEPTION_PARAMETER4: 1b07e920000
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
BUGCHECK_CODE: c000021a
BUGCHECK_P1: ffff8d0dd844e6b0
BUGCHECK_P2: ffffffffc0000428
BUGCHECK_P3: 0
BUGCHECK_P4: 1b07e920000
PROCESS_NAME: smss.exe
ADDITIONAL_DEBUG_TEXT: initial session process or
IMAGE_NAME: ntkrnlmp.exe
MODULE_NAME: nt
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
CUSTOMER_CRASH_COUNT: 1
STACK_TEXT:
ffff880b`51e5a6d8 fffff802`3a3af55a : 00000000`0000004c 00000000`c000021a ffff880b`52564530 ffffc389`102fcd90 : nt!KeBugCheckEx
ffff880b`51e5a6e0 fffff802`3a3a0f8b : ffff880b`51e5a800 ffff880b`51e5a7a0 ffff880b`51e5a800 ffff880b`51e5a7a0 : nt!PopGracefulShutdown+0x29a
ffff880b`51e5a720 fffff802`3a3966fc : 00000000`00000001 00000000`00000006 00000000`00000005 fffff802`00000000 : nt!PopTransitionSystemPowerStateEx+0x11c9b
ffff880b`51e5a7e0 fffff802`39e088b5 : ffff880b`51e5a9d8 ffffeae7`763cf00e 00000000`00000000 fffff802`3a178645 : nt!NtSetSystemPowerState+0x4c
ffff880b`51e5a9c0 fffff802`39dfad80 : fffff802`3a243919 00000000`00000014 ffffffff`ffffff00 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
ffff880b`51e5ab58 fffff802`3a243919 : 00000000`00000014 ffffffff`ffffff00 00000000`00000000 fffff802`3a623bc0 : nt!KiServiceLinkage
ffff880b`51e5ab60 fffff802`3a1627d9 : 00000000`00000000 ffffc388`faedb8c0 00000000`00000000 00000000`00000000 : nt!PopIssueActionRequest+0xe1021
ffff880b`51e5ac00 fffff802`39d53784 : 00000000`00000001 00000000`00000000 ffffffff`ffffffff fffff802`3a623b00 : nt!PopPolicyWorkerAction+0x79
ffff880b`51e5ac70 fffff802`39cb8515 : ffffc388`00000001 ffffc388`fafc5140 fffff802`39d536f0 ffffc389`00000000 : nt!PopPolicyWorkerThread+0x94
ffff880b`51e5acb0 fffff802`39d55875 : ffffc388`fafc5140 00000000`00000080 ffffc388`fae7e040 00000000`00000000 : nt!ExpWorkerThread+0x105
ffff880b`51e5ad50 fffff802`39dfe578 : fffff802`32fa0180 ffffc388`fafc5140 fffff802`39d55820 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff880b`51e5ada0 00000000`00000000 : ffff880b`51e5b000 ffff880b`51e55000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11c9b
IMAGE_VERSION: 10.0.19041.1110
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 11c9b
FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {11c026a4-042b-4c24-02dc-2da456397475}
Followup: MachineOwner
---------
[/CODE]