İbrahim Kerem AKGÜL
Hectopat
- Katılım
- 30 Aralık 2019
- Mesajlar
- 4
Aynı sorunla ben de karşı karşıyayım. Minidump dosyalarını yükledim. Bakarsanız sevinirim.
Minidump dosyaları
Minidump dosyaları
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and bugcheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffffd0016aa38b10, Actual security check cookie from the stack
Arg2: 00003ca28c15cf2c, Expected security check cookie
Arg3: ffffc35d73ea30d3, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff802e15cd308
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 9600.19478.amd64fre.winblue_ltsb.190831-0600
SYSTEM_MANUFACTURER: LENOVO
SYSTEM_PRODUCT_NAME: 20221
SYSTEM_SKU: LENOVO_MT_20221
SYSTEM_VERSION: Lenovo IdeaPad Z500 Touch
BIOS_VENDOR: LENOVO
BIOS_VERSION: 71CN51WW(V1.21)
BIOS_DATE: 07/12/2013
BASEBOARD_MANUFACTURER: LENOVO
BASEBOARD_PRODUCT: INVALID
BASEBOARD_VERSION: 31900004Std
DUMP_TYPE: 2
BUGCHECK_P1: ffffd0016aa38b10
BUGCHECK_P2: 3ca28c15cf2c
BUGCHECK_P3: ffffc35d73ea30d3
BUGCHECK_P4: 0
SECURITY_COOKIE: Expected 00003ca28c15cf2c found ffffd0016aa38b10
CPU_COUNT: 8
CPU_MHZ: 82f
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 1B'00000000 (cache) 1B'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xF7
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-VJAA6DJ
ANALYSIS_SESSION_TIME: 01-02-2020 14:05:13.0692
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff802e1414545 to fffff802e13bf3a0
STACK_TEXT:
ffffd001`6aa38ac8 fffff802`e1414545 : 00000000`000000f7 ffffd001`6aa38b10 00003ca2`8c15cf2c ffffc35d`73ea30d3 : nt!KeBugCheckEx
ffffd001`6aa38ad0 fffff802`e12dc6f2 : ffffd001`6ab33180 ffffd001`6aa38b4c ffffd001`6aa38b50 ffffd001`6aa38b58 : nt!_report_gsfailure+0x25
ffffd001`6aa38b10 fffff802`e13c308c : ffffd001`6ab33180 ffffd001`6ab33180 ffffd001`6ab43480 00000000`0000cb5e : nt!PoIdle+0x332
ffffd001`6aa38c60 00000000`00000000 : ffffd001`6aa39000 ffffd001`6aa33000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c
THREAD_SHA1_HASH_MOD_FUNC: 61eab8069b813e60188d222dba8f1722fde04615
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 947dbced409278ae5002f0d0179eb38f63e0f62b
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!_report_gsfailure+25
fffff802`e1414545 cc int 3
FAULT_INSTR_CODE: 48cccccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!_report_gsfailure+25
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5d6a8d07
IMAGE_VERSION: 6.3.9600.19478
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 25
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
PRIMARY_PROBLEM_CLASS: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
TARGET_TIME: 2019-12-30T14:08:41.000Z
OSBUILD: 9600
OSSERVICEPACK: 19478
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
OSEDITION: Windows 8.1 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-08-31 18:06:47
BUILDDATESTAMP_STR: 190831-0600
BUILDLAB_STR: winblue_ltsb
BUILDOSVER_STR: 6.3.9600.19478.amd64fre.winblue_ltsb.190831-0600
ANALYSIS_SESSION_ELAPSED_TIME: c40
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xf7_missing_gsframe_nt!_report_gsfailure
FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
Followup: MachineOwner
Bu sitenin çalışmasını sağlamak için gerekli çerezleri ve deneyiminizi iyileştirmek için isteğe bağlı çerezleri kullanıyoruz.