Mavi ekran hata analizi (2024)

  • 10 Haziran 2023
  • #8

* 16 Mayıs: AMD entegre grafik sürücüleri kaynaklı. Ama bir çakışma olmuş da olabilir. Kaspersky yüklü görünüyor, virüs olsa da engellemiştir diye düşünüyorum. Ama 3 mavi ekranda da entegre grafik sürücünüz Eylül 2022'den kalma.

Rich (BB code):

fffff807`dd5a0000 fffff807`e22af000 amdkmdag (deferred) Image path: amdkmdag.sys Image name: amdkmdag.sys Browse all global symbols functions data Timestamp: Thu Sep 29 05:35:21 2022 (63350469)

* 24 Mayıs: Bariz olarak mtkwl6ex.sys yani MediaTek Wi-Fi sürücüsünden kaynaklanmış. Yüklü sürüm bilgileri:

Rich (BB code):

fffff806`c4930000 fffff806`c4b71000 mtkwl6ex T (no symbols) Loaded symbol image file: mtkwl6ex.sys Image path: mtkwl6ex.sys Image name: mtkwl6ex.sys Browse all global symbols functions data Timestamp: Tue Nov 1 08:34:50 2022 (6360AFFA)

Sürücüyü güncelleyebilirsiniz, şu anki durum ne bilmiyorum.

* 2 Haziran: Bunun tam olarak neyden kaynaklandığı belli olmuyor. Genelde driver kaynaklı denmiş Microsoft'un sitesinde. KERNEL_SECURITY_CHECK_FAILURE (139)

* Virüs olsaydı bu tarz problemlere sebep olabilir miydi? Evet, sağa sola atlayıp sürücülerin çalışmasını, Windows'un genel işleyişini bozabilirdi ama burada sürücülerin eski olmaları sebebiyle alınan mavi ekran ihtimali daha kuvvetli sanki.

Sistem dosyalarının etkilenme riskine karşı aşağıdaki komutları sırayla girebiliriniz CMD'yi yönetici olarak çalıştırıp.

SFC /scannow
DISM /Online /Cleanup-Image /RestoreHealth

Üsttekiler tamamlandıktan sonra aşağıdakini de girip gelen soruya Y dedikten sonra PC'yi yeniden başlatın. Tarama yapsın belki bir şeyler düzeltir.

chkdsk /f /r

* Kaspersky'ı silin dememin sebebi ise mavi ekran sürecindeki şüphelileri mümkün olduğunca elimine etmek sıra sıra. Kaspersky zaman zaman mavi ekranlara sebebiyet verebiliyor. Ama güncelleyip kullanılabilir.

Kod:

******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************SYSTEM_SERVICE_EXCEPTION (3b)An exception happened while executing a system service routine.Arguments:Arg1: 00000000c0000005, Exception code that caused the BugCheckArg2: fffff8077dc20082, Address of the instruction which caused the BugCheckArg3: ffff95857ebe1a30, Address of the context record for the exception that caused the BugCheckArg4: 0000000000000000, zero.Debugging Details:------------------KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 1437 Key : Analysis.Elapsed.mSec Value: 3598 Key : Analysis.IO.Other.Mb Value: 0 Key : Analysis.IO.Read.Mb Value: 0 Key : Analysis.IO.Write.Mb Value: 0 Key : Analysis.Init.CPU.mSec Value: 140 Key : Analysis.Init.Elapsed.mSec Value: 33178 Key : Analysis.Memory.CommitPeak.Mb Value: 146 Key : Bugcheck.Code.LegacyAPI Value: 0x3b Key : Dump.Attributes.AsUlong Value: 8 Key : Dump.Attributes.KernelGeneratedTriageDump Value: 1 Key : Failure.Bucket Value: IP_MISALIGNED_AuthenticAMD.sys Key : Failure.Hash Value: {716d112a-8330-4bbb-160c-ec98297019d2}BUGCHECK_CODE: 3bBUGCHECK_P1: c0000005BUGCHECK_P2: fffff8077dc20082BUGCHECK_P3: ffff95857ebe1a30BUGCHECK_P4: 0FILE_IN_CAB: 051623-16468-01.dmpDUMP_FILE_ATTRIBUTES: 0x8 Kernel Generated Triage DumpCONTEXT: ffff95857ebe1a30 -- (.cxr 0xffff95857ebe1a30)rax=0000000000000000 rbx=ffff850f826621e0 rcx=fffff8077c0794a0rdx=ffff850f841f5080 rsi=ffff850f83c22260 rdi=ffff95857ebe24e0rip=fffff8077dc20082 rsp=ffff95857ebe2430 rbp=0000000000000000 r8=00000000ffffffff r9=7fffad8e273091b8 r10=7ffffffffffffffcr11=ffffc7ff03400000 r12=ffff95857ebe2538 r13=ffff95857ebe27b0r14=ffff850f6f7f8260 r15=0000000000000000iopl=0 nv up ei pl zr na po nccs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246nt!FsRtlLookupPerStreamContextInternal+0x32:fffff807`7dc20082 0000 add byte ptr [rax],al ds:002b:00000000`00000000=??Resetting default scopeCUSTOMER_CRASH_COUNT: 1PROCESS_NAME: explorer.exeMISALIGNED_IP:nt!FsRtlLookupPerStreamContextInternal+32fffff807`7dc20082 0000 add byte ptr [rax],alSTACK_TEXT:ffff9585`7ebe2430 ffff850f`7da74090 : ffff850f`7da74010 ffff850f`7da742a0 00000000`00000000 fffff807`7c053c0c : nt!FsRtlLookupPerStreamContextInternal+0x32ffff9585`7ebe2460 ffff850f`7da74010 : ffff850f`7da742a0 00000000`00000000 fffff807`7c053c0c ffff9585`7ebe2628 : 0xffff850f`7da74090ffff9585`7ebe2468 ffff850f`7da742a0 : 00000000`00000000 fffff807`7c053c0c ffff9585`7ebe2628 00000000`00000000 : 0xffff850f`7da74010ffff9585`7ebe2470 00000000`00000000 : fffff807`7c053c0c ffff9585`7ebe2628 00000000`00000000 ffff9585`7ebe2529 : 0xffff850f`7da742a0SYMBOL_NAME: nt!FsRtlLookupPerStreamContextInternal+32IMAGE_VERSION: 10.0.19041.2965STACK_COMMAND: .cxr 0xffff95857ebe1a30 ; kbMODULE_NAME: AuthenticAMDIMAGE_NAME: AuthenticAMD.sysFAILURE_BUCKET_ID: IP_MISALIGNED_AuthenticAMD.sysOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {716d112a-8330-4bbb-160c-ec98297019d2}Followup: MachineOwner---------******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)This is a very common BugCheck. Usually the exception address pinpointsthe driver/function that caused the problem. Always note this addressas well as the link date of the driver/image that contains this address.Arguments:Arg1: ffffffffc0000005, The exception code that was not handledArg2: fffff806c493e113, The address that the exception occurred atArg3: ffff8b08c0c224e8, Exception Record AddressArg4: ffff8b08c0c21d20, Context Record AddressDebugging Details:------------------KEY_VALUES_STRING: 1 Key : AV.Dereference Value: NullClassPtr Key : AV.Fault Value: Read Key : Analysis.CPU.mSec Value: 1281 Key : Analysis.Elapsed.mSec Value: 1981 Key : Analysis.IO.Other.Mb Value: 0 Key : Analysis.IO.Read.Mb Value: 0 Key : Analysis.IO.Write.Mb Value: 0 Key : Analysis.Init.CPU.mSec Value: 186 Key : Analysis.Init.Elapsed.mSec Value: 24702 Key : Analysis.Memory.CommitPeak.Mb Value: 141 Key : Bugcheck.Code.LegacyAPI Value: 0x1000007e Key : Dump.Attributes.AsUlong Value: 8 Key : Dump.Attributes.KernelGeneratedTriageDump Value: 1 Key : Failure.Bucket Value: AV_mtkwl6ex!unknown_function Key : Failure.Hash Value: {7fbea1c0-2ec4-7d26-2ed6-cb151c611289}BUGCHECK_CODE: 7eBUGCHECK_P1: ffffffffc0000005BUGCHECK_P2: fffff806c493e113BUGCHECK_P3: ffff8b08c0c224e8BUGCHECK_P4: ffff8b08c0c21d20FILE_IN_CAB: 052423-10734-01.dmpDUMP_FILE_ATTRIBUTES: 0x8 Kernel Generated Triage DumpEXCEPTION_RECORD: ffff8b08c0c224e8 -- (.exr 0xffff8b08c0c224e8)ExceptionAddress: fffff806c493e113 (mtkwl6ex+0x000000000000e113) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: 0000000000000018Attempt to read from address 0000000000000018CONTEXT: ffff8b08c0c21d20 -- (.cxr 0xffff8b08c0c21d20)rax=0000000000000000 rbx=ffffb48af3a10000 rcx=fffff806c4b66380rdx=0000000000000000 rsi=0000000000000001 rdi=000000000000ffffrip=fffff806c493e113 rsp=ffff8b08c0c22720 rbp=0000000000000000 r8=0000000000000000 r9=ffff8b08c0c222d8 r10=0000000000000028r11=ffffb77a8900004c r12=00000000c0000001 r13=fffff806c4a4b000r14=0000000000000001 r15=00000000c023002fiopl=0 nv up ei pl zr na po nccs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246mtkwl6ex+0xe113:fffff806`c493e113 8b5518 mov edx,dword ptr [rbp+18h] ss:0018:00000000`00000018=????????Resetting default scopeCUSTOMER_CRASH_COUNT: 1PROCESS_NAME: SystemREAD_ADDRESS: fffff8065e2fb390: Unable to get MiVisibleStateUnable to get NonPagedPoolStartUnable to get NonPagedPoolEndUnable to get PagedPoolStartUnable to get PagedPoolEndunable to get nt!MmSpecialPagesInUse 0000000000000018ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.EXCEPTION_CODE_STR: c0000005EXCEPTION_PARAMETER1: 0000000000000000EXCEPTION_PARAMETER2: 0000000000000018EXCEPTION_STR: 0xc0000005STACK_TEXT:ffff8b08`c0c22720 ffffb48a`f3a10000 : 00000000`0000ffff 00000000`00000004 fffff806`c493a4d6 ffffb48a`f3a10000 : mtkwl6ex+0xe113ffff8b08`c0c22728 00000000`0000ffff : 00000000`00000004 fffff806`c493a4d6 ffffb48a`f3a10000 00000000`00000000 : 0xffffb48a`f3a10000ffff8b08`c0c22730 00000000`00000004 : fffff806`c493a4d6 ffffb48a`f3a10000 00000000`00000000 fffff806`c4a6a000 : 0xffffffff8b08`c0c22738 fffff806`c493a4d6 : ffffb48a`f3a10000 00000000`00000000 fffff806`c4a6a000 fffff806`c4a58bc0 : 0x4ffff8b08`c0c22740 ffffb48a`f3a10000 : 00000000`00000000 fffff806`c4a6a000 fffff806`c4a58bc0 ffffb48a`f3a10000 : mtkwl6ex+0xa4d6ffff8b08`c0c22748 00000000`00000000 : fffff806`c4a6a000 fffff806`c4a58bc0 ffffb48a`f3a10000 fffff806`c494c26d : 0xffffb48a`f3a10000SYMBOL_NAME: mtkwl6ex+e113MODULE_NAME: mtkwl6exIMAGE_NAME: mtkwl6ex.sysSTACK_COMMAND: .cxr 0xffff8b08c0c21d20 ; kbBUCKET_ID_FUNC_OFFSET: e113FAILURE_BUCKET_ID: AV_mtkwl6ex!unknown_functionOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {7fbea1c0-2ec4-7d26-2ed6-cb151c611289}Followup: MachineOwner---------******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************KERNEL_SECURITY_CHECK_FAILURE (139)A kernel component has corrupted a critical data structure. The corruptioncould potentially allow a malicious user to gain control of this machine.Arguments:Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).Arg2: fffff887d7e99600, Address of the trap frame for the exception that caused the BugCheckArg3: fffff887d7e99558, Address of the exception record for the exception that caused the BugCheckArg4: 0000000000000000, ReservedDebugging Details:------------------KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 1436 Key : Analysis.Elapsed.mSec Value: 1576 Key : Analysis.IO.Other.Mb Value: 0 Key : Analysis.IO.Read.Mb Value: 0 Key : Analysis.IO.Write.Mb Value: 0 Key : Analysis.Init.CPU.mSec Value: 140 Key : Analysis.Init.Elapsed.mSec Value: 54832 Key : Analysis.Memory.CommitPeak.Mb Value: 146 Key : Bugcheck.Code.LegacyAPI Value: 0x139 Key : Dump.Attributes.AsUlong Value: 8 Key : Dump.Attributes.KernelGeneratedTriageDump Value: 1 Key : FailFast.Name Value: CORRUPT_LIST_ENTRY Key : FailFast.Type Value: 3 Key : Failure.Bucket Value: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiCommitThreadWait Key : Failure.Hash Value: {369b7001-cfef-011b-6243-985c04f34d42}BUGCHECK_CODE: 139BUGCHECK_P1: 3BUGCHECK_P2: fffff887d7e99600BUGCHECK_P3: fffff887d7e99558BUGCHECK_P4: 0FILE_IN_CAB: 060223-12843-01.dmpDUMP_FILE_ATTRIBUTES: 0x8 Kernel Generated Triage DumpTRAP_FRAME: fffff887d7e99600 -- (.trap 0xfffff887d7e99600)NOTE: The trap frame does not contain all registers.Some register values may be zeroed or incorrect.rax=fffff80016125440 rbx=0000000000000000 rcx=0000000000000003rdx=ffffc580e159c180 rsi=0000000000000000 rdi=0000000000000000rip=fffff8001561c363 rsp=fffff887d7e99790 rbp=0000000000000001 r8=ffff9a889343b400 r9=000000000000ffff r10=0000000067888440r11=0000000000000000 r12=0000000000000000 r13=0000000000000000r14=0000000000000000 r15=0000000000000000iopl=0 nv up ei pl nz na pe cynt!KiCommitThreadWait+0x5c3:fffff800`1561c363 cd29 int 29hResetting default scopeEXCEPTION_RECORD: fffff887d7e99558 -- (.exr 0xfffff887d7e99558)ExceptionAddress: fffff8001561c363 (nt!KiCommitThreadWait+0x00000000000005c3) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001NumberParameters: 1 Parameter[0]: 0000000000000003Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRYBLACKBOXBSD: 1 (!blackboxbsd)BLACKBOXNTFS: 1 (!blackboxntfs)BLACKBOXPNP: 1 (!blackboxpnp)BLACKBOXWINLOGON: 1CUSTOMER_CRASH_COUNT: 1PROCESS_NAME: FIFA22.exeERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.EXCEPTION_CODE_STR: c0000409EXCEPTION_PARAMETER1: 0000000000000003EXCEPTION_STR: 0xc0000409STACK_TEXT:fffff887`d7e992d8 fffff800`1580fd29 : 00000000`00000139 00000000`00000003 fffff887`d7e99600 fffff887`d7e99558 : nt!KeBugCheckExfffff887`d7e992e0 fffff800`15810290 : 00000000`00000000 fffff887`d7e99470 00000000`00000001 ffff9a88`7daca000 : nt!KiBugCheckDispatch+0x69fffff887`d7e99420 fffff800`1580e25d : 00000000`00000000 00000000`00000000 ffffc580`e159c180 fffff800`156df5dd : nt!KiFastFailDispatch+0xd0fffff887`d7e99600 fffff800`1561c363 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x31dfffff887`d7e99790 ffff9a88`9343b080 : ffff9a88`86fce080 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x5c3fffff887`d7e99830 ffff9a88`86fce080 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff9a88`9343b080fffff887`d7e99838 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff9a88`86fce080SYMBOL_NAME: nt!KiCommitThreadWait+5c3MODULE_NAME: ntIMAGE_NAME: ntkrnlmp.exeIMAGE_VERSION: 10.0.19041.2965STACK_COMMAND: .cxr; .ecxr ; kbBUCKET_ID_FUNC_OFFSET: 5c3FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiCommitThreadWaitOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {369b7001-cfef-011b-6243-985c04f34d42}Followup: MachineOwner---------

Artı0Eksi

Mavi ekran hata analizi (2024)
Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 5990

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.