SFC /scannow
ve DISM işlemlerini uyguladım şu anda herhangi bir hata bulunumadı. İşlemler sıkınıtısız bir şekilde tamamlanmış gözüküyor. Herkese yardımları için teşekkür ederim.Hocam bu arada size zahmet minidump dosyalarının içeriğini buraya atabilir misiniz ben telefondayım da.
Hocam bayağı önce (sanrım 2 yıl önce) oldu.
Hocam bu arada size zahmet minidump dosyalarının içeriğini buraya atabilir misiniz ben telefondayım da.
Hocam minidump dosyları:
1 Minidump.rar
drive.google.com
Tamamdır. Saat 1 de analiz edip size geri dönüş yapacağım.
Yeni formatlanmış bir sistemde virüs olma ihtimali çok düşük. Olsa bile normal Kaspersky'ı yükleyip tarar. Rescue diske ihtiyacı yok.
Hocam ama sonuçta virüs virüstür en azından virüsten mi olup olmadığını anlarız (ama dediğin gibi zahmetli olabilir)
Döküm burada. Yeni dosyaları attım sadece. Diğerleri de zaten disk kaynaklı.Hocam o zaman birisi analiz edip atsa olur mu? (ben saat 1 de bakabilirim de.)
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffff8d8191d44350, String that identifies the problem.
Arg2: ffffffffc0000006, Error Code.
Arg3: ffff8d818de3c410
Arg4: 0000000000000000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 8453
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 17463
Key : Analysis.Init.CPU.mSec
Value: 749
Key : Analysis.Init.Elapsed.mSec
Value: 6116
Key : Analysis.Memory.CommitPeak.Mb
Value: 72
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ERROR_CODE: (NTSTATUS) 0xc000021a - { nemli Sistem Hatas } %hs sistem i lemi, 0x
EXCEPTION_CODE_STR: c000021a
EXCEPTION_PARAMETER1: ffff8d8191d44350
EXCEPTION_PARAMETER2: ffffffffc0000006
EXCEPTION_PARAMETER3: ffff8d818de3c410
EXCEPTION_PARAMETER4: 0
BUGCHECK_CODE: c000021a
BUGCHECK_P1: ffff8d8191d44350
BUGCHECK_P2: ffffffffc0000006
BUGCHECK_P3: ffff8d818de3c410
BUGCHECK_P4: 0
PROCESS_NAME: smss.exe
ADDITIONAL_DEBUG_TEXT: Verification of a KnownDLL failed.
IMAGE_NAME: ntkrnlmp.exe
MODULE_NAME: nt
CUSTOMER_CRASH_COUNT: 1
STACK_TEXT:
ffff870e`9678c598 fffff804`7cfad52a : 00000000`0000004c 00000000`c000021a ffff870e`96b103f0 ffffe08f`5f70f450 : nt!KeBugCheckEx
ffff870e`9678c5a0 fffff804`7cf9f36d : ffff870e`9678c6c0 ffff870e`9678c660 ffff870e`9678c6c0 ffff870e`9678c660 : nt!PopGracefulShutdown+0x29a
ffff870e`9678c5e0 fffff804`7cf947ec : 00000000`00000001 fffff804`00000006 00000000`00000004 00000000`00000000 : nt!PopTransitionSystemPowerStateEx+0x11885
ffff870e`9678c6a0 fffff804`7ca077b8 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!NtSetSystemPowerState+0x4c
ffff870e`9678c880 fffff804`7c9f9ca0 : fffff804`7ce3c54b 00000000`00000014 ffffffff`ffffff00 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffff870e`9678ca18 fffff804`7ce3c54b : 00000000`00000014 ffffffff`ffffff00 00000000`00000000 fffff804`7d223d40 : nt!KiServiceLinkage
ffff870e`9678ca20 fffff804`7cd61a49 : 00000000`00000000 ffffe08f`5aa90ce0 00000000`00000000 00000000`00000000 : nt!PopIssueActionRequest+0xda9e3
ffff870e`9678cac0 fffff804`7c9159c4 : 00000000`00000001 00000000`00000000 ffffffff`ffffffff fffff804`7d223c00 : nt!PopPolicyWorkerAction+0x79
ffff870e`9678cb30 fffff804`7c825975 : ffffe08f`00000001 ffffe08f`5ab40080 fffff804`7c915930 ffffe08f`00000000 : nt!PopPolicyWorkerThread+0x94
ffff870e`9678cb70 fffff804`7c917e85 : ffffe08f`5ab40080 00000000`00000080 ffffe08f`5aa7b1c0 00000000`00000000 : nt!ExpWorkerThread+0x105
ffff870e`9678cc10 fffff804`7c9fd498 : ffffcb01`8cbdb180 ffffe08f`5ab40080 fffff804`7c917e30 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff870e`9678cc60 00000000`00000000 : ffff870e`9678d000 ffff870e`96787000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11885
IMAGE_VERSION: 10.0.19041.928
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 11885
FAILURE_BUCKET_ID: 0xc000021a_SmpInitializeKnownDlls_c0000006_IN_PAGE_ERROR_kernelbase.dll_nt!PopTransitionSystemPowerStateEx
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {33399a12-0874-ae4e-87b0-395fe0161aaa}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffb98dbd244350, String that identifies the problem.
Arg2: ffffffffc0000006, Error Code.
Arg3: ffffb98dbcfc2310
Arg4: 0000000000000000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 8906
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 16667
Key : Analysis.Init.CPU.mSec
Value: 811
Key : Analysis.Init.Elapsed.mSec
Value: 8934
Key : Analysis.Memory.CommitPeak.Mb
Value: 73
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ERROR_CODE: (NTSTATUS) 0xc000021a - { nemli Sistem Hatas } %hs sistem i lemi, 0x
EXCEPTION_CODE_STR: c000021a
EXCEPTION_PARAMETER1: ffffb98dbd244350
EXCEPTION_PARAMETER2: ffffffffc0000006
EXCEPTION_PARAMETER3: ffffb98dbcfc2310
EXCEPTION_PARAMETER4: 0
BUGCHECK_CODE: c000021a
BUGCHECK_P1: ffffb98dbd244350
BUGCHECK_P2: ffffffffc0000006
BUGCHECK_P3: ffffb98dbcfc2310
BUGCHECK_P4: 0
PROCESS_NAME: smss.exe
ADDITIONAL_DEBUG_TEXT: Verification of a KnownDLL failed.
IMAGE_NAME: ntkrnlmp.exe
MODULE_NAME: nt
CUSTOMER_CRASH_COUNT: 1
STACK_TEXT:
fffffe8c`97484598 fffff802`109ad52a : 00000000`0000004c 00000000`c000021a fffffe8c`975c43f0 ffffdb8a`c17f5610 : nt!KeBugCheckEx
fffffe8c`974845a0 fffff802`1099f36d : fffffe8c`974846c0 fffffe8c`97484660 fffffe8c`974846c0 fffffe8c`97484660 : nt!PopGracefulShutdown+0x29a
fffffe8c`974845e0 fffff802`109947ec : 00000000`00000001 fffff802`00000006 00000000`00000004 00000000`00000000 : nt!PopTransitionSystemPowerStateEx+0x11885
fffffe8c`974846a0 fffff802`104077b8 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!NtSetSystemPowerState+0x4c
fffffe8c`97484880 fffff802`103f9ca0 : fffff802`1083c54b 00000000`00000014 ffffffff`ffffff00 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
fffffe8c`97484a18 fffff802`1083c54b : 00000000`00000014 ffffffff`ffffff00 00000000`00000000 fffff802`10c23d40 : nt!KiServiceLinkage
fffffe8c`97484a20 fffff802`10761a49 : 00000000`00000000 ffffdb8a`bd0a0cc0 00000000`00000000 00000000`00000000 : nt!PopIssueActionRequest+0xda9e3
fffffe8c`97484ac0 fffff802`103159c4 : 00000000`00000001 00000000`00000000 ffffffff`ffffffff fffff802`10c23c00 : nt!PopPolicyWorkerAction+0x79
fffffe8c`97484b30 fffff802`10225975 : ffffdb8a`00000001 ffffdb8a`bdcf8040 fffff802`10315930 ffffdb8a`00000000 : nt!PopPolicyWorkerThread+0x94
fffffe8c`97484b70 fffff802`10317e85 : ffffdb8a`bdcf8040 00000000`00000080 ffffdb8a`bd093180 000fa425`b59bbfff : nt!ExpWorkerThread+0x105
fffffe8c`97484c10 fffff802`103fd498 : ffffa501`3f963180 ffffdb8a`bdcf8040 fffff802`10317e30 00000000`00000000 : nt!PspSystemThreadStartup+0x55
fffffe8c`97484c60 00000000`00000000 : fffffe8c`97485000 fffffe8c`9747f000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11885
IMAGE_VERSION: 10.0.19041.928
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 11885
FAILURE_BUCKET_ID: 0xc000021a_SmpInitializeKnownDlls_c0000006_IN_PAGE_ERROR_combase.dll_nt!PopTransitionSystemPowerStateEx
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f1ed6f85-62d4-44a3-ff24-3820e7f621e6}
Followup: MachineOwner
---------
Hocam ama sonuçta virüs virüstür en azından virüsten mi olup olmadığını anlarız (ama dediğin gibi zahmetli olabilir)
Çok teşekkür ederim. Bu arada Rufus ve kasperksy ISO'su indi.
Bu sitenin çalışmasını sağlamak için gerekli çerezleri ve deneyiminizi iyileştirmek için isteğe bağlı çerezleri kullanıyoruz.