Blue Screen usually while forcing pc

Hi,

112216-46437-01.dmp

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000096, Exception code that caused the bugcheck
Arg2: fffff80319b6789e, Address of the instruction which caused the bugcheck
Arg3: ffffab8117e31d00, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.


privileged escalation
Mem problem


pretty rare this failure
FAULTING_IP:
nt!SwapContext+2be
fffff803`19b6789e 0f30 wrmsr

112216-40937-01.dmp

DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.

Arguments:
Arg1: 8000c148c4b88bbc, Actual security check cookie from the stack
Arg2: 0000c148c4b88bbc, Expected security check cookie
Arg3: ffff3eb73b477443, Complement of the expected security check cookie
Arg4: 0000000000000000, zero

BUGCHECK_STR: 0xF7_ONE_BIT

a nice one too

112216-32390-01.dmp

Probably caused by : memory_corruption

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff8010bebdd7d - nt!MiDeleteSystemPagableVm+5fd
[ f6:fd ]
fffff8010bebdd98 - nt!MiDeleteSystemPagableVm+618 (+0x1b)
[ f6:fd ]
fffff8010bebe331 - nt!MiDeleteValidSystemPage+251 (+0x599)
[ f6:fd ]
fffff8010bebe34d-fffff8010bebe34e 2 bytes - nt!MiDeleteValidSystemPage+26d (+0x1c)
[ 80 fa:00 eb ]
fffff8010beec602-fffff8010beec604 3 bytes - nt!MiPfnShareCountIsZero+192 (+0x2e2b5)
[ 40 fb f6:c0 fe fd ]
fffff8010beec627 - nt!MiPfnShareCountIsZero+1b7 (+0x25)
[ f6:fd ]
fffff8010beec646-fffff8010beec647 2 bytes - nt!MiPfnShareCountIsZero+1d6 (+0x1f)
[ a0 7d:60 ff ]
fffff8010bf17e6d-fffff8010bf17e6e 2 bytes - nt!MiPurgeZeroList+6d (+0x2b827)
[ 80 fa:00 eb ]
fffff8010c056387-fffff8010c056389 3 bytes - nt!ExFreePoolWithTag+387
[ 40 fb f6:c0 fe fd ]
16 errors : !nt (fffff8010bebdd7d-fffff8010c056389)
.
so a memory test is a good option, checking the harddisk as well.

Memtest86+ - Advanced Memory Diagnostic Tool
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top