Prophet2047
Kilopat
- Katılım
- 9 Ağustos 2015
- Mesajlar
- 513
- Çözümler
- 1
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff82043eb873b0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff82043eb87308, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 2
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1LCNFAR
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 23
Key : Analysis.Memory.CommitPeak.Mb
Value: 69
Key : Analysis.System
Value: CreateObject
ADDITIONAL_XML: 1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff82043eb873b0
BUGCHECK_P3: ffff82043eb87308
BUGCHECK_P4: 0
TRAP_FRAME: ffff82043eb873b0 -- (.trap 0xffff82043eb873b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff8808af8a63e0 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80336b213d0 rsp=ffff82043eb87540 rbp=ffff8808abd26040
r8=0000000000000001 r9=0000000000000002 r10=ffff8808a51f9a00
r11=fffff80333d20180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
nt!KiExitDispatcher+0x160:
fffff803`36b213d0 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff82043eb87308 -- (.exr 0xffff82043eb87308)
ExceptionAddress: fffff80336b213d0 (nt!KiExitDispatcher+0x0000000000000160)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff8204`3eb87088 fffff803`36bd41e9 : 00000000`00000139 00000000`00000003 ffff8204`3eb873b0 ffff8204`3eb87308 : nt!KeBugCheckEx
ffff8204`3eb87090 fffff803`36bd4610 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff8204`3eb871d0 fffff803`36bd29a3 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8204`3eb87520 : nt!KiFastFailDispatch+0xd0
ffff8204`3eb873b0 fffff803`36b213d0 : 00000000`00000000 ffff8204`3eb875e1 fffff803`33d20180 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
ffff8204`3eb87540 fffff803`36b36a6d : ffff8808`af8a63d8 00000000`00000200 fffff803`33d20101 fffff803`36d6f08d : nt!KiExitDispatcher+0x160
ffff8204`3eb875a0 fffff803`7ed0dd3e : 00000000`00000500 ffff8808`ad104278 00000000`0000006c ffff8808`00000002 : nt!KeInsertQueueApc+0x14d
ffff8204`3eb87640 00000000`00000500 : ffff8808`ad104278 00000000`0000006c ffff8808`00000002 00000000`00000000 : BEDaisy+0x2ddd3e
ffff8204`3eb87648 ffff8808`ad104278 : 00000000`0000006c ffff8808`00000002 00000000`00000000 00000000`00000000 : 0x500
ffff8204`3eb87650 00000000`0000006c : ffff8808`00000002 00000000`00000000 00000000`00000000 ffff403f`90f90f00 : 0xffff8808`ad104278
ffff8204`3eb87658 ffff8808`00000002 : 00000000`00000000 00000000`00000000 ffff403f`90f90f00 00000000`00000000 : 0x6c
ffff8204`3eb87660 00000000`00000000 : 00000000`00000000 ffff403f`90f90f00 00000000`00000000 00000000`00000001 : 0xffff8808`00000002
SYMBOL_NAME: BEDaisy+2ddd3e
MODULE_NAME: BEDaisy
IMAGE_NAME: BEDaisy.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 2ddd3e
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_BEDaisy!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {59d8eb10-b2e4-7df6-f6a5-49968226dbb8}
Followup: MachineOwner
---------
start end module name
fffff803`7ea30000 fffff803`7ed16000 BEDaisy T (no symbols)
Loaded symbol image file: BEDaisy.sys
Image path: \??\C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
Image name: BEDaisy.sys
Browse all global symbols functions data
Timestamp: Wed Mar 25 17:47:09 2020 (5E7B6EED)
CheckSum: 002F1F01
ImageSize: 002E6000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff82043eb873b0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff82043eb87308, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 2
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1LCNFAR
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 23
Key : Analysis.Memory.CommitPeak.Mb
Value: 69
Key : Analysis.System
Value: CreateObject
ADDITIONAL_XML: 1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff82043eb873b0
BUGCHECK_P3: ffff82043eb87308
BUGCHECK_P4: 0
TRAP_FRAME: ffff82043eb873b0 -- (.trap 0xffff82043eb873b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff8808af8a63e0 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80336b213d0 rsp=ffff82043eb87540 rbp=ffff8808abd26040
r8=0000000000000001 r9=0000000000000002 r10=ffff8808a51f9a00
r11=fffff80333d20180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
nt!KiExitDispatcher+0x160:
fffff803`36b213d0 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff82043eb87308 -- (.exr 0xffff82043eb87308)
ExceptionAddress: fffff80336b213d0 (nt!KiExitDispatcher+0x0000000000000160)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff8204`3eb87088 fffff803`36bd41e9 : 00000000`00000139 00000000`00000003 ffff8204`3eb873b0 ffff8204`3eb87308 : nt!KeBugCheckEx
ffff8204`3eb87090 fffff803`36bd4610 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff8204`3eb871d0 fffff803`36bd29a3 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8204`3eb87520 : nt!KiFastFailDispatch+0xd0
ffff8204`3eb873b0 fffff803`36b213d0 : 00000000`00000000 ffff8204`3eb875e1 fffff803`33d20180 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
ffff8204`3eb87540 fffff803`36b36a6d : ffff8808`af8a63d8 00000000`00000200 fffff803`33d20101 fffff803`36d6f08d : nt!KiExitDispatcher+0x160
ffff8204`3eb875a0 fffff803`7ed0dd3e : 00000000`00000500 ffff8808`ad104278 00000000`0000006c ffff8808`00000002 : nt!KeInsertQueueApc+0x14d
ffff8204`3eb87640 00000000`00000500 : ffff8808`ad104278 00000000`0000006c ffff8808`00000002 00000000`00000000 : BEDaisy+0x2ddd3e
ffff8204`3eb87648 ffff8808`ad104278 : 00000000`0000006c ffff8808`00000002 00000000`00000000 00000000`00000000 : 0x500
ffff8204`3eb87650 00000000`0000006c : ffff8808`00000002 00000000`00000000 00000000`00000000 ffff403f`90f90f00 : 0xffff8808`ad104278
ffff8204`3eb87658 ffff8808`00000002 : 00000000`00000000 00000000`00000000 ffff403f`90f90f00 00000000`00000000 : 0x6c
ffff8204`3eb87660 00000000`00000000 : 00000000`00000000 ffff403f`90f90f00 00000000`00000000 00000000`00000001 : 0xffff8808`00000002
SYMBOL_NAME: BEDaisy+2ddd3e
MODULE_NAME: BEDaisy
IMAGE_NAME: BEDaisy.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 2ddd3e
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_BEDaisy!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {59d8eb10-b2e4-7df6-f6a5-49968226dbb8}
Followup: MachineOwner
---------
start end module name
fffff803`7ea30000 fffff803`7ed16000 BEDaisy T (no symbols)
Loaded symbol image file: BEDaisy.sys
Image path: \??\C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
Image name: BEDaisy.sys
Browse all global symbols functions data
Timestamp: Wed Mar 25 17:47:09 2020 (5E7B6EED)
CheckSum: 002F1F01
ImageSize: 002E6000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Bu sitenin çalışmasını sağlamak için gerekli çerezleri ve deneyiminizi iyileştirmek için isteğe bağlı çerezleri kullanıyoruz.