Vedo

Uzman
Katılım
30 Mayıs 2024
Mesajlar
7
Beğeniler
2
  • Anakart: Asus TUF B550M-PLUS Wifi 2
  • İşlemci: 5800x3d
  • Ekran Kartı: 6800XT
  • İşletim Sistemi: Windows 11 Pro 23H2

Herkese merhaba;

2 gündür ara ara mavi ekran alıyorum. Sistem yükteyken falan olmuyor. Normal internette gezinirken vs oluyor. 8-10 saat oyun açık olduğu durumlarda bile hiç mavi ekran almadım. WinDbg programım dosyaları açmıyor. Sisteme yakın zamanda hiç bir şey kurduğumu hatırlamıyorum. Hata aldığım zamana en yakın windows güncellemesini de ekledim. Alakasız bir şeye benziyor ama Windows bu, sürprizlerle dolu :) Kontrol edip çözüm önerisi sunabilir misiniz?


Minidump Dosyası
 

Dosya Ekleri

  • Update.webp
    Update.webp
    63 KB · Görüntüleme: 83
Sanırım RAM'lerde problem var. TestMem5 veya MemTest86 yazılımları ile RAM'leri test eder misin? Yaptığın testlerde 1 tane bile hata alırsan RAM'lerde sorun var demektir.

Ayrıca muhtemelen RAM'lerini XMP açık olarak kullanıyorsundur. RAM testini öncelikle mevcut haliyle, yani XMP açıkken yap. Eğer hata alırsan bir de XMP kapalı iken RAM'leri test et. XMP kapalı iken hata almazsan demek ki sorun XMP ayarlarında.

Sorunun XMP ayarlarında olduğu senaryoda ise bu sorunu çözmek için öncelikle bir BIOS güncelle. Güncelledikten sonra XMP açıp bilgisayarı test et. Hala mavi ekran hatası alıyorsan ya bir daha XMP kullanmayacaksın ya XMP açmadan manuel overclock yapıp stabil bir ayar tutturacaksın ya da hayatına başka RAM'ler ile devam edeceksin.

Analizleri de aşağıda paylaşıyorum.

3: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80557bbe5c9, Address of the instruction which caused the BugCheck
Arg3: ffffd808a0a2e8a0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

*** WARNING: Check Image - Checksum mismatch - Dump: 0x208038, File: 0x2080c6 - C:\ProgramData\Dbg\sym\BTHport.sys\2AFD096C202000\BTHport.sys

KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 2125

Key : Analysis.Elapsed.mSec
Value: 21826

Key : Analysis.IO.Other.Mb
Value: 24

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 33

Key : Analysis.Init.CPU.mSec
Value: 203

Key : Analysis.Init.Elapsed.mSec
Value: 228684

Key : Analysis.Memory.CommitPeak.Mb
Value: 151

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x3b

Key : Bugcheck.Code.TargetModel
Value: 0x3b

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 3b

BUGCHECK_P1: c0000005

BUGCHECK_P2: fffff80557bbe5c9

BUGCHECK_P3: ffffd808a0a2e8a0

BUGCHECK_P4: 0

FILE_IN_CAB: 092224-12406-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffffd90016f9d080

CONTEXT: ffffd808a0a2e8a0 -- (.cxr 0xffffd808a0a2e8a0)
rax=0000000000000800 rbx=ffff810258d14150 rcx=0000000000000010
rdx=000000000000006e rsi=0000000000000400 rdi=ffff810259445d60
rip=fffff80557bbe5c9 rsp=ffffd808a0a2f2c0 rbp=ffffd808a0a2f3d0
r8=ffff8102594450ca r9=0000000000000002 r10=0000000000000000
r11=0000000000000d50 r12=ffffd90046ca406c r13=0000000000000000
r14=ffff810258d14150 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff805`57bbe5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: GoogleDriveFS.

STACK_TEXT:
ffffd808`a0a2f2c0 fffff805`5770fe2e : 00000000`00000000 00000000`00000000 00000000`00000100 ffffd808`a0a2f6e8 : nt!RtlpNewSecurityObject+0xe39
ffffd808`a0a2f600 fffff805`57bbba08 : ffffd90f`fc6cf900 ffffd808`a0a2f760 ffffd900`1a4daa60 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
ffffd808`a0a2f660 fffff805`57adaddc : 00000000`00000004 00000036`388feba0 00000000`00000000 00000000`00000000 : nt!ObInsertObjectEx+0x248
ffffd808`a0a2f910 fffff805`5782b608 : ffffd900`16f9d080 00000036`388feb78 00000000`00000000 00000000`00000000 : nt!NtDuplicateToken+0x28c
ffffd808`a0a2fa30 00007ff9`88070974 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000036`388feb58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`88070974


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xffffd808a0a2e8a0 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8040c1be5c9, The address that the exception occurred at
Arg3: fffffd0996bb6248, Exception Record Address
Arg4: fffffd0996bb5a60, Context Record Address

Debugging Details:
------------------


KEY_VALUES_STRING: 1

Key : AV.Fault
Value: Read

Key : Analysis.CPU.mSec
Value: 1984

Key : Analysis.Elapsed.mSec
Value: 85873

Key : Analysis.IO.Other.Mb
Value: 8

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 11

Key : Analysis.Init.CPU.mSec
Value: 234

Key : Analysis.Init.Elapsed.mSec
Value: 6707

Key : Analysis.Memory.CommitPeak.Mb
Value: 159

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e

Key : Bugcheck.Code.TargetModel
Value: 0x1000007e

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 7e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8040c1be5c9

BUGCHECK_P3: fffffd0996bb6248

BUGCHECK_P4: fffffd0996bb5a60

FILE_IN_CAB: 092024-12281-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffffe50d2dbb0040

EXCEPTION_RECORD: fffffd0996bb6248 -- (.exr 0xfffffd0996bb6248)
ExceptionAddress: fffff8040c1be5c9 (nt!RtlpNewSecurityObject+0x0000000000000e39)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000045e91344
Attempt to read from address 0000000045e91344

CONTEXT: fffffd0996bb5a60 -- (.cxr 0xfffffd0996bb5a60)
rax=0000000000000800 rbx=ffffbd0ed22a8800 rcx=0000000000000010
rdx=00000000000000ef rsi=0000000000000400 rdi=ffffbd0edc86d1a0
rip=fffff8040c1be5c9 rsp=fffffd0996bb6480 rbp=fffffd0996bb6590
r8=ffffbd0edc8680d4 r9=000000000000000c r10=0000000000000000
r11=0000000000005190 r12=ffffe50d4b40addc r13=0000000000000000
r14=ffffbd0ed22a8800 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff804`0c1be5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: System

READ_ADDRESS: fffff8040c71d470: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000045e91344

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000045e91344

EXCEPTION_STR: 0xc0000005

STACK_TEXT:
fffffd09`96bb6480 fffff804`0bd0fe2e : 00000000`00000000 00000000`00000000 00000000`00000300 fffffd09`96bb68a8 : nt!RtlpNewSecurityObject+0xe39
fffffd09`96bb67c0 fffff804`0c1bba08 : ffffe50d`2dacb6c0 fffffd09`96bb6920 ffffe50d`53883b50 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
fffffd09`96bb6820 fffff804`0c0b130e : ffffffff`ffffffff fffffd09`96bb6cb0 00000000`00000000 ffffffff`ffffffff : nt!ObInsertObjectEx+0x248
fffffd09`96bb6ad0 fffff804`0c0b1ba5 : ffffe50d`4f591040 ffffe50d`3dc4f080 fffffd09`96bb73d0 fffffd09`96bb6c18 : nt!PspInsertThread+0x3be
fffffd09`96bb6bb0 fffff804`0c1eed8b : ffffe50d`3dc4f080 fffffd09`96bb7960 ffffe50d`3dc4f080 00000000`00000000 : nt!PspCreateThread+0x29d
fffffd09`96bb6e60 fffff804`0be2b608 : ffff8001`97edf180 fffff804`0be1fb37 004fe07f`b4bbbdff 00000000`00000000 : nt!NtCreateThreadEx+0x28b
fffffd09`96bb76f0 fffff804`0be1baf0 : fffff804`0c1f0ccd 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 : nt!KiSystemServiceCopyEnd+0x28
fffffd09`96bb78f8 fffff804`0c1f0ccd : 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 00000000`00c50001 : nt!KiServiceLinkage
fffffd09`96bb7900 fffff804`0bd67ad9 : ffffe50d`3dbf3d00 ffffffff`ffffffff ffffe50d`3dbf3d00 00000000`00000001 : nt!RtlpCreateUserThreadEx+0x151
fffffd09`96bb7a40 fffff804`0bd40ecd : 00000000`00000000 ffffe50d`3dbf3e98 ffffe50d`3dbf3d00 fffff804`0bce93b7 : nt!ExpWorkerFactoryCreateThread+0x10d
fffffd09`96bb7b00 fffff804`0bd8ab29 : ffffe50d`3dbf3d00 00000000`00000080 00000000`00000000 ffffe50d`3dbf3f68 : nt!ExpWorkerFactoryCheckCreate+0x20d
fffffd09`96bb7b60 fffff804`0bd54d47 : ffffe50d`2dbb0040 fffff804`0bd8aa00 00000000`00000000 00000000`00000000 : nt!ExpWorkerFactoryManagerThread+0x129
fffffd09`96bb7bb0 fffff804`0be1b174 : ffff8001`97e51180 ffffe50d`2dbb0040 fffff804`0bd54cf0 00000000`00000000 : nt!PspSystemThreadStartup+0x57
fffffd09`96bb7c00 00000000`00000000 : fffffd09`96bb8000 fffffd09`96bb1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xfffffd0996bb5a60 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------

: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80561dbe5c9, Address of the instruction which caused the BugCheck
Arg3: fffff002756018a0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

*** WARNING: Check Image - Checksum mismatch - Dump: 0x208038, File: 0x2080c6 - C:\ProgramData\Dbg\sym\BTHport.sys\2AFD096C202000\BTHport.sys

KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 2000

Key : Analysis.Elapsed.mSec
Value: 6451

Key : Analysis.IO.Other.Mb
Value: 0

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 0

Key : Analysis.Init.CPU.mSec
Value: 296

Key : Analysis.Init.Elapsed.mSec
Value: 11753

Key : Analysis.Memory.CommitPeak.Mb
Value: 151

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x3b

Key : Bugcheck.Code.TargetModel
Value: 0x3b

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 3b

BUGCHECK_P1: c0000005

BUGCHECK_P2: fffff80561dbe5c9

BUGCHECK_P3: fffff002756018a0

BUGCHECK_P4: 0

FILE_IN_CAB: 092024-11578-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffff80096cc230c0

CONTEXT: fffff002756018a0 -- (.cxr 0xfffff002756018a0)
rax=0000000000000800 rbx=ffffa1828c5d9d40 rcx=0000000000000010
rdx=0000000000000002 rsi=0000000000000400 rdi=ffffa18267f1cb90
rip=fffff80561dbe5c9 rsp=fffff002756022c0 rbp=fffff002756023d0
r8=ffffa18267f13094 r9=0000000000000014 r10=0000000000000000
r11=0000000000009b80 r12=ffff800955d627cc r13=0000000000000000
r14=ffffa1828c5d9d40 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff805`61dbe5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: GoogleDriveFS.

STACK_TEXT:
fffff002`756022c0 fffff805`6190fe2e : 00000000`00000000 00000000`00000000 00000000`00000100 fffff002`756026e8 : nt!RtlpNewSecurityObject+0xe39
fffff002`75602600 fffff805`61dbba08 : ffff8009`4cace380 fffff002`75602760 ffff8009`6d1bcb60 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
fffff002`75602660 fffff805`61cdaddc : 00000000`00000004 000000f1`db1feb10 00000000`00000000 00000000`00000000 : nt!ObInsertObjectEx+0x248
fffff002`75602910 fffff805`61a2b608 : ffff8009`6cc230c0 000000f1`db1feae8 00000000`00000000 00000000`00000000 : nt!NtDuplicateToken+0x28c
fffff002`75602a30 00007ff9`36ef0974 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000f1`db1feac8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`36ef0974


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xfffff002756018a0 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------
 
Sanırım RAM'lerde problem var. TestMem5 veya MemTest86 yazılımları ile RAM'leri test eder misin? Yaptığın testlerde 1 tane bile hata alırsan RAM'lerde sorun var demektir.

Ayrıca muhtemelen RAM'lerini XMP açık olarak kullanıyorsundur. RAM testini öncelikle mevcut haliyle, yani XMP açıkken yap. Eğer hata alırsan bir de XMP kapalı iken RAM'leri test et. XMP kapalı iken hata almazsan demek ki sorun XMP ayarlarında.

Sorunun XMP ayarlarında olduğu senaryoda ise bu sorunu çözmek için öncelikle bir BIOS güncelle. Güncelledikten sonra XMP açıp bilgisayarı test et. Hala mavi ekran hatası alıyorsan ya bir daha XMP kullanmayacaksın ya XMP açmadan manuel overclock yapıp stabil bir ayar tutturacaksın ya da hayatına başka RAM'ler ile devam edeceksin.

Analizleri de aşağıda paylaşıyorum.

3: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80557bbe5c9, Address of the instruction which caused the BugCheck
Arg3: ffffd808a0a2e8a0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

*** WARNING: Check Image - Checksum mismatch - Dump: 0x208038, File: 0x2080c6 - C:\ProgramData\Dbg\sym\BTHport.sys\2AFD096C202000\BTHport.sys

KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 2125

Key : Analysis.Elapsed.mSec
Value: 21826

Key : Analysis.IO.Other.Mb
Value: 24

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 33

Key : Analysis.Init.CPU.mSec
Value: 203

Key : Analysis.Init.Elapsed.mSec
Value: 228684

Key : Analysis.Memory.CommitPeak.Mb
Value: 151

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x3b

Key : Bugcheck.Code.TargetModel
Value: 0x3b

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 3b

BUGCHECK_P1: c0000005

BUGCHECK_P2: fffff80557bbe5c9

BUGCHECK_P3: ffffd808a0a2e8a0

BUGCHECK_P4: 0

FILE_IN_CAB: 092224-12406-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffffd90016f9d080

CONTEXT: ffffd808a0a2e8a0 -- (.cxr 0xffffd808a0a2e8a0)
rax=0000000000000800 rbx=ffff810258d14150 rcx=0000000000000010
rdx=000000000000006e rsi=0000000000000400 rdi=ffff810259445d60
rip=fffff80557bbe5c9 rsp=ffffd808a0a2f2c0 rbp=ffffd808a0a2f3d0
r8=ffff8102594450ca r9=0000000000000002 r10=0000000000000000
r11=0000000000000d50 r12=ffffd90046ca406c r13=0000000000000000
r14=ffff810258d14150 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff805`57bbe5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: GoogleDriveFS.

STACK_TEXT:
ffffd808`a0a2f2c0 fffff805`5770fe2e : 00000000`00000000 00000000`00000000 00000000`00000100 ffffd808`a0a2f6e8 : nt!RtlpNewSecurityObject+0xe39
ffffd808`a0a2f600 fffff805`57bbba08 : ffffd90f`fc6cf900 ffffd808`a0a2f760 ffffd900`1a4daa60 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
ffffd808`a0a2f660 fffff805`57adaddc : 00000000`00000004 00000036`388feba0 00000000`00000000 00000000`00000000 : nt!ObInsertObjectEx+0x248
ffffd808`a0a2f910 fffff805`5782b608 : ffffd900`16f9d080 00000036`388feb78 00000000`00000000 00000000`00000000 : nt!NtDuplicateToken+0x28c
ffffd808`a0a2fa30 00007ff9`88070974 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000036`388feb58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`88070974


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xffffd808a0a2e8a0 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8040c1be5c9, The address that the exception occurred at
Arg3: fffffd0996bb6248, Exception Record Address
Arg4: fffffd0996bb5a60, Context Record Address

Debugging Details:
------------------


KEY_VALUES_STRING: 1

Key : AV.Fault
Value: Read

Key : Analysis.CPU.mSec
Value: 1984

Key : Analysis.Elapsed.mSec
Value: 85873

Key : Analysis.IO.Other.Mb
Value: 8

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 11

Key : Analysis.Init.CPU.mSec
Value: 234

Key : Analysis.Init.Elapsed.mSec
Value: 6707

Key : Analysis.Memory.CommitPeak.Mb
Value: 159

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e

Key : Bugcheck.Code.TargetModel
Value: 0x1000007e

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 7e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8040c1be5c9

BUGCHECK_P3: fffffd0996bb6248

BUGCHECK_P4: fffffd0996bb5a60

FILE_IN_CAB: 092024-12281-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffffe50d2dbb0040

EXCEPTION_RECORD: fffffd0996bb6248 -- (.exr 0xfffffd0996bb6248)
ExceptionAddress: fffff8040c1be5c9 (nt!RtlpNewSecurityObject+0x0000000000000e39)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000045e91344
Attempt to read from address 0000000045e91344

CONTEXT: fffffd0996bb5a60 -- (.cxr 0xfffffd0996bb5a60)
rax=0000000000000800 rbx=ffffbd0ed22a8800 rcx=0000000000000010
rdx=00000000000000ef rsi=0000000000000400 rdi=ffffbd0edc86d1a0
rip=fffff8040c1be5c9 rsp=fffffd0996bb6480 rbp=fffffd0996bb6590
r8=ffffbd0edc8680d4 r9=000000000000000c r10=0000000000000000
r11=0000000000005190 r12=ffffe50d4b40addc r13=0000000000000000
r14=ffffbd0ed22a8800 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff804`0c1be5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: System

READ_ADDRESS: fffff8040c71d470: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000045e91344

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000045e91344

EXCEPTION_STR: 0xc0000005

STACK_TEXT:
fffffd09`96bb6480 fffff804`0bd0fe2e : 00000000`00000000 00000000`00000000 00000000`00000300 fffffd09`96bb68a8 : nt!RtlpNewSecurityObject+0xe39
fffffd09`96bb67c0 fffff804`0c1bba08 : ffffe50d`2dacb6c0 fffffd09`96bb6920 ffffe50d`53883b50 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
fffffd09`96bb6820 fffff804`0c0b130e : ffffffff`ffffffff fffffd09`96bb6cb0 00000000`00000000 ffffffff`ffffffff : nt!ObInsertObjectEx+0x248
fffffd09`96bb6ad0 fffff804`0c0b1ba5 : ffffe50d`4f591040 ffffe50d`3dc4f080 fffffd09`96bb73d0 fffffd09`96bb6c18 : nt!PspInsertThread+0x3be
fffffd09`96bb6bb0 fffff804`0c1eed8b : ffffe50d`3dc4f080 fffffd09`96bb7960 ffffe50d`3dc4f080 00000000`00000000 : nt!PspCreateThread+0x29d
fffffd09`96bb6e60 fffff804`0be2b608 : ffff8001`97edf180 fffff804`0be1fb37 004fe07f`b4bbbdff 00000000`00000000 : nt!NtCreateThreadEx+0x28b
fffffd09`96bb76f0 fffff804`0be1baf0 : fffff804`0c1f0ccd 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 : nt!KiSystemServiceCopyEnd+0x28
fffffd09`96bb78f8 fffff804`0c1f0ccd : 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 00000000`00c50001 : nt!KiServiceLinkage
fffffd09`96bb7900 fffff804`0bd67ad9 : ffffe50d`3dbf3d00 ffffffff`ffffffff ffffe50d`3dbf3d00 00000000`00000001 : nt!RtlpCreateUserThreadEx+0x151
fffffd09`96bb7a40 fffff804`0bd40ecd : 00000000`00000000 ffffe50d`3dbf3e98 ffffe50d`3dbf3d00 fffff804`0bce93b7 : nt!ExpWorkerFactoryCreateThread+0x10d
fffffd09`96bb7b00 fffff804`0bd8ab29 : ffffe50d`3dbf3d00 00000000`00000080 00000000`00000000 ffffe50d`3dbf3f68 : nt!ExpWorkerFactoryCheckCreate+0x20d
fffffd09`96bb7b60 fffff804`0bd54d47 : ffffe50d`2dbb0040 fffff804`0bd8aa00 00000000`00000000 00000000`00000000 : nt!ExpWorkerFactoryManagerThread+0x129
fffffd09`96bb7bb0 fffff804`0be1b174 : ffff8001`97e51180 ffffe50d`2dbb0040 fffff804`0bd54cf0 00000000`00000000 : nt!PspSystemThreadStartup+0x57
fffffd09`96bb7c00 00000000`00000000 : fffffd09`96bb8000 fffffd09`96bb1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xfffffd0996bb5a60 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------

: kd> !analyze -v
*******************************************************************************
  • *
  • Bugcheck Analysis *
  • *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80561dbe5c9, Address of the instruction which caused the BugCheck
Arg3: fffff002756018a0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

*** WARNING: Check Image - Checksum mismatch - Dump: 0x208038, File: 0x2080c6 - C:\ProgramData\Dbg\sym\BTHport.sys\2AFD096C202000\BTHport.sys

KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 2000

Key : Analysis.Elapsed.mSec
Value: 6451

Key : Analysis.IO.Other.Mb
Value: 0

Key : Analysis.IO.Read.Mb
Value: 0

Key : Analysis.IO.Write.Mb
Value: 0

Key : Analysis.Init.CPU.mSec
Value: 296

Key : Analysis.Init.Elapsed.mSec
Value: 11753

Key : Analysis.Memory.CommitPeak.Mb
Value: 151

Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001

Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre

Key : Analysis.Version.Ext
Value: 1.2408.27.1

Key : Bugcheck.Code.LegacyAPI
Value: 0x3b

Key : Bugcheck.Code.TargetModel
Value: 0x3b

Key : Dump.Attributes.AsUlong
Value: 1008

Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key : Dump.Attributes.ErrorCode
Value: 0

Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key : Dump.Attributes.ProgressPercentage
Value: 0

Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject

Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}


BUGCHECK_CODE: 3b

BUGCHECK_P1: c0000005

BUGCHECK_P2: fffff80561dbe5c9

BUGCHECK_P3: fffff002756018a0

BUGCHECK_P4: 0

FILE_IN_CAB: 092024-11578-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump

FAULTING_THREAD: ffff80096cc230c0

CONTEXT: fffff002756018a0 -- (.cxr 0xfffff002756018a0)
rax=0000000000000800 rbx=ffffa1828c5d9d40 rcx=0000000000000010
rdx=0000000000000002 rsi=0000000000000400 rdi=ffffa18267f1cb90
rip=fffff80561dbe5c9 rsp=fffff002756022c0 rbp=fffff002756023d0
r8=ffffa18267f13094 r9=0000000000000014 r10=0000000000000000
r11=0000000000009b80 r12=ffff800955d627cc r13=0000000000000000
r14=ffffa1828c5d9d40 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff805`61dbe5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: GoogleDriveFS.

STACK_TEXT:
fffff002`756022c0 fffff805`6190fe2e : 00000000`00000000 00000000`00000000 00000000`00000100 fffff002`756026e8 : nt!RtlpNewSecurityObject+0xe39
fffff002`75602600 fffff805`61dbba08 : ffff8009`4cace380 fffff002`75602760 ffff8009`6d1bcb60 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
fffff002`75602660 fffff805`61cdaddc : 00000000`00000004 000000f1`db1feb10 00000000`00000000 00000000`00000000 : nt!ObInsertObjectEx+0x248
fffff002`75602910 fffff805`61a2b608 : ffff8009`6cc230c0 000000f1`db1feae8 00000000`00000000 00000000`00000000 : nt!NtDuplicateToken+0x28c
fffff002`75602a30 00007ff9`36ef0974 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000f1`db1feac8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`36ef0974


SYMBOL_NAME: nt!RtlpNewSecurityObject+e39

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.4169

STACK_COMMAND: .cxr 0xfffff002756018a0 ; kb

BUCKET_ID_FUNC_OFFSET: e39

FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}

Followup: MachineOwner
---------
Yatmadan teste bırakayım bakalım. Umarım bozuk çıkar da başka şeylerle uğraşmam :)