- Katılım
- 8 Aralık 2017
- Mesajlar
- 4.402
- Çözümler
- 25
@Enes3078 @Murat5038 @claus hocalarım, mavi ekran hatası aldım az önce. BattleEye sebep olmuş sanırım ancak siz daha bilgilisinizdir. Kolaylık olsun diye kod olarak bıraktım ancak isterseniz minidump olarak da yükleyebilirim. İlgilenebilir misiniz? Teşekkür ederim şimdiden.
Kod:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: fffffa8b2496b380, Address of the trap frame for the exception that caused the bugcheck
Arg3: fffffa8b2496b2d8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for BEDaisy.sys
*** WARNING: Unable to verify checksum for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 4468
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 81167
Key : Analysis.Init.CPU.mSec
Value: 890
Key : Analysis.Init.Elapsed.mSec
Value: 256663
Key : Analysis.Memory.CommitPeak.Mb
Value: 80
Key : FailFast.Name
Value: CORRUPT_LIST_ENTRY
Key : FailFast.Type
Value: 3
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: fffffa8b2496b380
BUGCHECK_P3: fffffa8b2496b2d8
BUGCHECK_P4: 0
TRAP_FRAME: fffffa8b2496b380 -- (.trap 0xfffffa8b2496b380)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff9b8a1e755e30 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8043024a8fd rsp=fffffa8b2496b510 rbp=ffff9b8a2040f040
r8=0000000000000001 r9=0000000000000002 r10=ffff9b8a1bcec200
r11=fffff8042d977180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!KiExitDispatcher+0x1ad:
fffff804`3024a8fd cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: fffffa8b2496b2d8 -- (.exr 0xfffffa8b2496b2d8)
ExceptionAddress: fffff8043024a8fd (nt!KiExitDispatcher+0x00000000000001ad)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
fffffa8b`2496b058 fffff804`30407d69 : 00000000`00000139 00000000`00000003 fffffa8b`2496b380 fffffa8b`2496b2d8 : nt!KeBugCheckEx
fffffa8b`2496b060 fffff804`30408190 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffffa8b`2496b1a0 fffff804`30406523 : 00000000`0000000f 00000000`00000000 00000000`00000000 55555555`55555555 : nt!KiFastFailDispatch+0xd0
fffffa8b`2496b380 fffff804`3024a8fd : 00000000`00000000 fffffa8b`2496b5c1 ffff9b8a`26ce7000 fffff804`30264623 : nt!KiRaiseSecurityCheckFailure+0x323
fffffa8b`2496b510 fffff804`30357711 : fffff804`2d977180 00000000`00000000 fffff804`2d977101 fffff804`309b1094 : nt!KiExitDispatcher+0x1ad
fffffa8b`2496b580 fffff804`334b207a : 00000000`00000200 ffff9b8a`28fa80a8 ffff8a88`252795e0 00001f80`00000002 : nt!KeInsertQueueApc+0x151
fffffa8b`2496b620 00000000`00000200 : ffff9b8a`28fa80a8 ffff8a88`252795e0 00001f80`00000002 00000000`00000000 : BEDaisy+0x33207a
fffffa8b`2496b628 ffff9b8a`28fa80a8 : ffff8a88`252795e0 00001f80`00000002 00000000`00000000 00000000`00000000 : 0x200
fffffa8b`2496b630 ffff8a88`252795e0 : 00001f80`00000002 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff9b8a`28fa80a8
fffffa8b`2496b638 00001f80`00000002 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff8a88`252795e0
fffffa8b`2496b640 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : 0x00001f80`00000002
SYMBOL_NAME: BEDaisy+33207a
MODULE_NAME: BEDaisy
IMAGE_NAME: BEDaisy.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 33207a
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_BEDaisy!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {59d8eb10-b2e4-7df6-f6a5-49968226dbb8}
Followup: MachineOwner
---------