Hallo
Lade den Dmp bitte auf One Drive hoch teile ihn und gib ihn frei und poste den Link davon hier
Dann kann man sich das runterladen und analysieren
Liebe grüße UWE
Dieser Browser wird nicht mehr unterstützt.
Führen Sie ein Upgrade auf Microsoft Edge durch, um die neuesten Features, Sicherheitsupdates und den technischen Support zu nutzen.
Hallo, ich habe an der Hardware nichts verändert, auch keine neue Software installiert. Der BS trat auf als ich gerade World of Warcraft spielte.
-----------------------------------------------------------------------
Microsoft (R) Windows Debugger Version 10.0.25200.1003 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff801`18600000 PsLoadedModuleList = 0xfffff801`1922a2b0
Debug session time: Thu Dec 1 14:45:23.715 2022 (UTC + 1:00)
System Uptime: 0 days 0:39:38.393
Loading Kernel Symbols
...............................................................
................................................................
.........................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 0000008f`da8c6018). Type ".hh dbgerr001" for details
Loading unloaded module list
........
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`189f92d0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff8509`fa2301c0=0000000000000139
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000002, Stack cookie instrumentation code detected a stack-based
buffer overrun.
Arg2: ffff8509fa2304e0, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff8509fa230438, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
Page 180109 not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
Page 20b2da not present in the dump file. Type ".hh dbgerr004" for details
..................
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 6265
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 6440
Key : Analysis.IO.Other.Mb
Value: 29
Key : Analysis.IO.Read.Mb
Value: 2
Key : Analysis.IO.Write.Mb
Value: 36
Key : Analysis.Init.CPU.mSec
Value: 952
Key : Analysis.Init.Elapsed.mSec
Value: 103313
Key : Analysis.Memory.CommitPeak.Mb
Value: 110
Key : Bugcheck.Code.DumpHeader
Value: 0x139
Key : Bugcheck.Code.KiBugCheckData
Value: 0x139
Key : Bugcheck.Code.Register
Value: 0x139
Key : FailFast.Name
Value: STACK_COOKIE_CHECK_FAILURE
Key : FailFast.Type
Value: 2
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
FILE_IN_CAB: MEMORY.DMP
BUGCHECK_CODE: 139
BUGCHECK_P1: 2
BUGCHECK_P2: ffff8509fa2304e0
BUGCHECK_P3: ffff8509fa230438
BUGCHECK_P4: 0
TRAP_FRAME: ffff8509fa2304e0 -- (.trap 0xffff8509fa2304e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000003 rbx=0000000000000000 rcx=0000000000000002
rdx=000000000000000b rsi=0000000000000000 rdi=0000000000000000
rip=ffffecd9fbecd5e5 rsp=ffff8509fa230678 rbp=ffff8509fa230780
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=ffff8c8352a52dd0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
win32kbase!_report_gsfailure+0x5:
ffffecd9`fbecd5e5 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff8509fa230438 -- (.exr 0xffff8509fa230438)
ExceptionAddress: ffffecd9fbecd5e5 (win32kbase!_report_gsfailure+0x0000000000000005)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000002
Subcode: 0x2 FAST_FAIL_STACK_COOKIE_CHECK_FAILURE
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: csrss.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Das System hat in dieser Anwendung den berlauf eines stapelbasierten Puffers ermittelt. Dieser berlauf k nnte einem b sartigen Benutzer erm glichen, die Steuerung der Anwendung zu bernehmen.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000002
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff8509`fa2301b8 fffff801`18a0d329 : 00000000`00000139 00000000`00000002 ffff8509`fa2304e0 ffff8509`fa230438 : nt!KeBugCheckEx
ffff8509`fa2301c0 fffff801`18a0d890 : ffff8509`fa2303d1 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff8509`fa230300 fffff801`18a0b85d : ffff8509`fa230610 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffff8509`fa2304e0 ffffecd9`fbecd5e5 : ffffecd9`fbe23163 ffffecd9`fc04d210 ffff8c83`52dd9cf0 00000000`00000001 : nt!KiRaiseSecurityCheckFailure+0x31d
ffff8509`fa230678 ffffecd9`fbe23163 : ffffecd9`fc04d210 ffff8c83`52dd9cf0 00000000`00000001 ffffec8b`40665800 : win32kbase!_report_gsfailure+0x5
ffff8509`fa230680 ffffecd9`fc5e906f : 00000000`00000000 00000000`00000001 00002000`00000000 00000000`00000004 : win32kbase!LegacyInputDispatcher::WaitAndDispatch+0xd3
ffff8509`fa2307b0 ffffecd9`fbe79aa3 : ffff8c83`515350c0 ffff8c83`515350c0 00000000`00000000 00000000`00000005 : win32kfull!RawInputThread+0x7bf
ffff8509`fa230970 ffffecd9`fc58fcf0 : ffff8c83`515350c0 00000000`00000000 00000000`00000005 00000000`00000005 : win32kbase!xxxCreateSystemThreads+0xc3
ffff8509`fa230aa0 ffffecd9`fc13474d : ffff8c83`515350c0 ffff8c83`515350c0 00000000`00000000 00000000`00000000 : win32kfull!NtUserCallNoParam+0x70
ffff8509`fa230ad0 fffff801`18a0caf8 : ffff8c83`00000005 00000000`00000005 00000191`4a004330 00000000`000003b8 : win32k!NtUserCallNoParam+0x15
ffff8509`fa230b00 00007fff`9fa310e4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000008f`dabbfcb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`9fa310e4
SYMBOL_NAME: win32kbase!_report_gsfailure+5
MODULE_NAME: win32kbase
IMAGE_NAME: win32kbase.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 5
FAILURE_BUCKET_ID: 0x139_MISSING_GSFRAME_win32kbase!_report_gsfailure
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f22c2e43-4b0d-a5dc-7d6c-399075f6e217}
Followup: MachineOwner
---------
Gesperrte Frage. Diese Frage wurde aus der Microsoft-Support-Community migriert. Sie können darüber abstimmen, ob sie hilfreich ist, aber Sie können keine Kommentare oder Antworten hinzufügen oder der Frage folgen.
Hallo
Lade den Dmp bitte auf One Drive hoch teile ihn und gib ihn frei und poste den Link davon hier
Dann kann man sich das runterladen und analysieren
Liebe grüße UWE