Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 22000 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 22000.1.amd64fre.co_release.210604-1628
Machine Name:
Kernel base = 0xfffff803`54400000 PsLoadedModuleList = 0xfffff803`55029650
Debug session time: Tue Jul 19 18:02:42.323 2022 (UTC + 3:00)
System Uptime: 0 days 0:13:47.014
Loading Kernel Symbols
...............................................................
................................................................
..............................................................
Loading User Symbols
Loading unloaded module list
...................
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff803`54817d00 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffa709`a975eff0=0000000000000139
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffa709a975f310, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffa709a975f268, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
Unable to load image \SystemRoot\System32\drivers\athurx.sys, Win32 error 0n2
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x1800
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffffa709a975f310
BUGCHECK_P3: ffffa709a975f268
BUGCHECK_P4: 0
TRAP_FRAME: ffffa709a975f310 -- (.trap 0xffffa709a975f310)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffc10b81fe6515 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffc10b7a566c48 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80354718bc2 rsp=ffffa709a975f4a0 rbp=ffffab802c385180
r8=0000000000000010 r9=0000000000000000 r10=fffff803546f5a90
r11=00000001a3fbcc39 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl nz na pe nc
nt!ExInterlockedRemoveHeadList+0x102:
fffff803`54718bc2 cd29 int 29h
Resetting default scope
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
Minidump dosyaları, bilgisayarınız mavi ekran verdiğinde belleğin ufak bir dökümünü barındıran dosyalardır. Bunları analiz ederek mavi ekran hatalarının nedenini öğrenebiliriz. Minidump dosyaları C:\Windows\Minidump klasöründe bulunur ve DMP uzantılıdır. Bu dosyaları sizden istediğimizde...