大贤者
精华
|
战斗力 鹅
|
回帖 0
注册时间 2013-11-11
|
本帖最后由 litel 于 2018-10-10 22:14 编辑
我也也不会看栈啊什么的,只会简单的用windbg跑下自动分析。
其实最可疑的是 WiseTDIFw64.sys 这个第三方网络过滤驱动。
speedpan.exe 应该是在使用某些网络方面的东西,跟这个网络过滤驱动一起,产生了某些问题,
然后导致win10蓝屏。
搜到 WiseTDIFw64.sys 是个什么 WiseCleaner.com 的系统清理的什么工具。。。建议卸载,重启,检查是否还有 WiseTDIFw64.sys 这个第三方驱动。
然后 speedpan.exe 这个百度下载工具也别用了,建议换 proxyee-down 或者 pandownload.com
- Microsoft (R) Windows Debugger Version 10.0.18239.1000 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\minidump\100618-5812-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 17134 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 17134.1.amd64fre.rs4_release.180410-1804
- Machine Name:
- Kernel base = 0xfffff802`2c8a2000 PsLoadedModuleList = 0xfffff802`2cc502d0
- Debug session time: Sat Oct 6 21:15:51.894 2018 (UTC + 8:00)
- System Uptime: 0 days 19:19:47.733
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ...........................................................
- Loading User Symbols
- Loading unloaded module list
- .................
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck 139, {3, ffff9a09bb256a10, ffff9a09bb256968, 0}
- *** WARNING: Unable to verify timestamp for WiseTDIFw64.sys
- *** ERROR: Module load completed but symbols could not be loaded for WiseTDIFw64.sys
- Probably caused by : tdx.sys ( tdx!TdxTdiDispatchCreate+10b )
- Followup: MachineOwner
- ---------
- nt!KeBugCheckEx:
- fffff802`2ca4b490 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9a09`bb2566f0=0000000000000139
- 0: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- KERNEL_SECURITY_CHECK_FAILURE (139)
- A kernel component has corrupted a critical data structure. The corruption
- could potentially allow a malicious user to gain control of this machine.
- Arguments:
- Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
- Arg2: ffff9a09bb256a10, Address of the trap frame for the exception that caused the bugcheck
- Arg3: ffff9a09bb256968, Address of the exception record for the exception that caused the bugcheck
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- STACKHASH_ANALYSIS: 1
- TIMELINE_ANALYSIS: 1
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804
- SYSTEM_MANUFACTURER: System manufacturer
- SYSTEM_PRODUCT_NAME: System Product Name
- SYSTEM_SKU: ASUS_MB_CNL
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 0803
- BIOS_DATE: 06/20/2018
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: TUF B360M-PLUS GAMING
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- BUGCHECK_P1: 3
- BUGCHECK_P2: ffff9a09bb256a10
- BUGCHECK_P3: ffff9a09bb256968
- BUGCHECK_P4: 0
- TRAP_FRAME: ffff9a09bb256a10 -- (.trap 0xffff9a09bb256a10)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffff8888eda02ca0 rbx=0000000000000000 rcx=0000000000000003
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8022cb8de55 rsp=ffff9a09bb256ba0 rbp=ffff9a09bb256c29
- r8=0000000000000000 r9=0000000000000000 r10=0000000000000001
- r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na pe cy
- nt!ExAllocatePoolWithTag+0x1a45:
- fffff802`2cb8de55 cd29 int 29h
- Resetting default scope
- EXCEPTION_RECORD: ffff9a09bb256968 -- (.exr 0xffff9a09bb256968)
- ExceptionAddress: fffff8022cb8de55 (nt!ExAllocatePoolWithTag+0x0000000000001a45)
- ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
- ExceptionFlags: 00000001
- NumberParameters: 1
- Parameter[0]: 0000000000000003
- Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
- CPU_COUNT: 4
- CPU_MHZ: e10
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: b
- CPU_MICROCODE: 6,9e,b,0 (F,M,S,R) SIG: 8E'00000000 (cache) 8E'00000000 (init)
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXPNP: 1 (!blackboxpnp)
- CUSTOMER_CRASH_COUNT: 1
- BUGCHECK_STR: 0x139
- PROCESS_NAME: SpeedPan.exe
- CURRENT_IRQL: 2
- DEFAULT_BUCKET_ID: FAIL_FAST_CORRUPT_LIST_ENTRY
- ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
- EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
- EXCEPTION_CODE_STR: c0000409
- EXCEPTION_PARAMETER1: 0000000000000003
- ANALYSIS_SESSION_HOST:
- ANALYSIS_SESSION_TIME: 10-10-2018 22:07:13.0413
- ANALYSIS_VERSION: 10.0.18239.1000 amd64fre
- LAST_CONTROL_TRANSFER: from fffff8022ca5c069 to fffff8022ca4b490
- STACK_TEXT:
- ffff9a09`bb2566e8 fffff802`2ca5c069 : 00000000`00000139 00000000`00000003 ffff9a09`bb256a10 ffff9a09`bb256968 : nt!KeBugCheckEx
- ffff9a09`bb2566f0 fffff802`2ca5c410 : 00000000`00000000 ffff9a09`bb256ba0 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff9a09`bb256830 fffff802`2ca5aa1f : ffff8888`e5d51c10 ffff8888`ebd27128 fffff80b`b07a2c90 ffff8888`e5d5b980 : nt!KiFastFailDispatch+0xd0
- ffff9a09`bb256a10 fffff802`2cb8de55 : ffff8888`e5400000 00000000`00000000 fffff802`2cc86b08 00000000`00000100 : nt!KiRaiseSecurityCheckFailure+0x2df
- ffff9a09`bb256ba0 fffff80b`b0765a6b : 00000000`00000000 00000000`00001000 00000000`43786454 fffff80b`00000000 : nt!ExAllocatePoolWithTag+0x1a45
- ffff9a09`bb256c90 fffff802`2c8dcef9 : ffff8888`00000030 ffff9a09`bb256d58 ffff8888`ebd27010 ffff8888`ebd27128 : tdx!TdxTdiDispatchCreate+0x10b
- ffff9a09`bb256d20 fffff80b`b07a39ff : ffff8888`e5d51c10 00000103`00000030 00000000`00000000 00000000`00000000 : nt!IofCallDriver+0x59
- ffff9a09`bb256d60 ffff8888`e5d51c10 : 00000103`00000030 00000000`00000000 00000000`00000000 00000000`00000000 : WiseTDIFw64+0x39ff
- ffff9a09`bb256d68 00000103`00000030 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8888`ebd27010 : 0xffff8888`e5d51c10
- ffff9a09`bb256d70 00000000`00000000 : 00000000`00000000 00000000`00000000 ffff8888`ebd27010 ffff8888`e5d51c10 : 0x00000103`00000030
- THREAD_SHA1_HASH_MOD_FUNC: 70ae0703cb534a15e25f808273c4ee9de0109dcf
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e4862eb0c86ba6e3ca3bcf3c0fc61b24eac9d603
- THREAD_SHA1_HASH_MOD: ab22e84fc9001c14a0cb7a5c588437560d86b2db
- FOLLOWUP_IP:
- tdx!TdxTdiDispatchCreate+10b
- fffff80b`b0765a6b 488bd8 mov rbx,rax
- FAULT_INSTR_CODE: 48d88b48
- SYMBOL_STACK_INDEX: 5
- SYMBOL_NAME: tdx!TdxTdiDispatchCreate+10b
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: tdx
- IMAGE_NAME: tdx.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.17134.165
- STACK_COMMAND: .thread ; .cxr ; kb
- BUCKET_ID_FUNC_OFFSET: 10b
- FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_tdx!TdxTdiDispatchCreate
- BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_tdx!TdxTdiDispatchCreate
- PRIMARY_PROBLEM_CLASS: 0x139_3_CORRUPT_LIST_ENTRY_tdx!TdxTdiDispatchCreate
- TARGET_TIME: 2018-10-06T13:15:51.000Z
- OSBUILD: 17134
- OSSERVICEPACK: 320
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- OS_LOCALE:
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2018-09-21 11:40:27
- BUILDDATESTAMP_STR: 180410-1804
- BUILDLAB_STR: rs4_release
- BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804
- ANALYSIS_SESSION_ELAPSED_TIME: 2ecc
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0x139_3_corrupt_list_entry_tdx!tdxtdidispatchcreate
- FAILURE_ID_HASH: {e78434f0-6468-411a-f9ac-bd600228d03f}
- Followup: MachineOwner
- ---------
复制代码
|
评分
-
查看全部评分
|