- Katılım
- 19 Ekim 2018
- Mesajlar
- 12.735
- Makaleler
- 7
- Çözümler
- 113
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 00000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ce5bfba0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ce5bfad0, Address of the exception record for the exception that caused the bugcheck
Arg4: 00000000, Reserved
Debugging Details:
------------------KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 11249
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-J7A11VA
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 60351
Key : Analysis.Memory.CommitPeak.Mb
Value: 92
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffffffffce5bfba0
BUGCHECK_P3: ffffffffce5bfad0
BUGCHECK_P4: 0
TRAP_FRAME: ce5bfba0 -- (.trap 0xffffffffce5bfba0)
ErrCode = 00000000
eax=804c95d8 ebx=ce5bfd08 ecx=00000003 edx=9c9939f8 esi=804c95d8 edi=00000090
eip=9c8311e7 esp=ce5bfc14 ebp=ce5bfc18 iopl=0 nv up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000287
win32kbase!FreeThreadBufferWithTag+0x57:
9c8311e7 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ce5bfad0 -- (.exr 0xffffffffce5bfad0)
ExceptionAddress: 9c8311e7 (win32kbase!FreeThreadBufferWithTag+0x00000057)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 00000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: winlogon.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 00000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ce5bfab0 81df2cf8 00000139 00000003 ce5bfba0 nt!KiBugCheck2
ce5bfab0 9c8311e7 (T) 00000139 00000003 ce5bfba0 nt!KiRaiseSecurityCheckFailure+0x2d8
ce5bfc18 9ce4e8f5 (T) 804c95e8 99dc00b0 ce5bfd08 win32kbase!FreeThreadBufferWithTag+0x57
ce5bfc34 9cdef138 a4e72a50 99dc00b0 99dc0000 win32kfull!EXLATEOBJ::vAddToCache+0x4d
ce5bfc80 9cdea52a 00000000 00000000 a4e72a50 win32kfull!EXLATEOBJ::bInitXlateObj+0x188
ce5bfe54 9cde9a5f 00000000 00000020 00000040 win32kfull!NtGdiBitBltInternal+0xaba
ce5bfe80 91ba1ccb 0e01064e 00000000 00000000 win32kfull!NtGdiBitBlt+0x2f
WARNING: Stack unwind information not available. Following frames may be wrong.
ce5bfeb8 90b311d2 0e01064e 00000000 00000000 klgse+0x21ccb
ce5bfef4 90b41b70 91ba1c70 ce5bff28 0000002c klhk+0x11d2
ce5bff08 90b3118f 95b1ada0 ce5bff28 ce5bff1c klhk+0x11b70
ce5bff20 81df268b 0e01064e 00000000 00000000 klhk+0x118f
ce5bff20 76f814f0 (T) 0e01064e 00000000 00000000 nt!KiSystemServicePostCall
0309e674 00000000 (T) 00000000 00000000 00000000 0x76f814f0
SYMBOL_NAME: win32kbase!FreeThreadBufferWithTag+57
MODULE_NAME: win32kbase
IMAGE_NAME: win32kbase.sys
IMAGE_VERSION: 10.0.19041.388
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 57
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_win32kbase!FreeThreadBufferWithTag
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x86
OSNAME: Windows 10
FAILURE_ID_HASH: {45e5baba-8cff-c812-0b0b-8de6fc5bd0b0}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 00000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ce5bfba0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ce5bfad0, Address of the exception record for the exception that caused the bugcheck
Arg4: 00000000, Reserved
Debugging Details:
------------------KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 11249
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-J7A11VA
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 60351
Key : Analysis.Memory.CommitPeak.Mb
Value: 92
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffffffffce5bfba0
BUGCHECK_P3: ffffffffce5bfad0
BUGCHECK_P4: 0
TRAP_FRAME: ce5bfba0 -- (.trap 0xffffffffce5bfba0)
ErrCode = 00000000
eax=804c95d8 ebx=ce5bfd08 ecx=00000003 edx=9c9939f8 esi=804c95d8 edi=00000090
eip=9c8311e7 esp=ce5bfc14 ebp=ce5bfc18 iopl=0 nv up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000287
win32kbase!FreeThreadBufferWithTag+0x57:
9c8311e7 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ce5bfad0 -- (.exr 0xffffffffce5bfad0)
ExceptionAddress: 9c8311e7 (win32kbase!FreeThreadBufferWithTag+0x00000057)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 00000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: winlogon.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 00000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ce5bfab0 81df2cf8 00000139 00000003 ce5bfba0 nt!KiBugCheck2
ce5bfab0 9c8311e7 (T) 00000139 00000003 ce5bfba0 nt!KiRaiseSecurityCheckFailure+0x2d8
ce5bfc18 9ce4e8f5 (T) 804c95e8 99dc00b0 ce5bfd08 win32kbase!FreeThreadBufferWithTag+0x57
ce5bfc34 9cdef138 a4e72a50 99dc00b0 99dc0000 win32kfull!EXLATEOBJ::vAddToCache+0x4d
ce5bfc80 9cdea52a 00000000 00000000 a4e72a50 win32kfull!EXLATEOBJ::bInitXlateObj+0x188
ce5bfe54 9cde9a5f 00000000 00000020 00000040 win32kfull!NtGdiBitBltInternal+0xaba
ce5bfe80 91ba1ccb 0e01064e 00000000 00000000 win32kfull!NtGdiBitBlt+0x2f
WARNING: Stack unwind information not available. Following frames may be wrong.
ce5bfeb8 90b311d2 0e01064e 00000000 00000000 klgse+0x21ccb
ce5bfef4 90b41b70 91ba1c70 ce5bff28 0000002c klhk+0x11d2
ce5bff08 90b3118f 95b1ada0 ce5bff28 ce5bff1c klhk+0x11b70
ce5bff20 81df268b 0e01064e 00000000 00000000 klhk+0x118f
ce5bff20 76f814f0 (T) 0e01064e 00000000 00000000 nt!KiSystemServicePostCall
0309e674 00000000 (T) 00000000 00000000 00000000 0x76f814f0
SYMBOL_NAME: win32kbase!FreeThreadBufferWithTag+57
MODULE_NAME: win32kbase
IMAGE_NAME: win32kbase.sys
IMAGE_VERSION: 10.0.19041.388
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 57
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_win32kbase!FreeThreadBufferWithTag
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x86
OSNAME: Windows 10
FAILURE_ID_HASH: {45e5baba-8cff-c812-0b0b-8de6fc5bd0b0}
Followup: MachineOwner
---------
Bu sitenin çalışmasını sağlamak için gerekli çerezleri ve deneyiminizi iyileştirmek için isteğe bağlı çerezleri kullanıyoruz.