360fans_n5sXOG 发表于 2026-8-3 16:49

360把我系统杀了,还有360内置的反馈功能炸了


打cod打的好好的忽然蓝屏了,把日志导出来扔windbg里:
************* Path validation summary **************
Response                         Time (ms)   Location
Deferred                                       srv*
************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.015 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 46
Microsoft (R) Windows Debugger Version 10.0.29617.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response                         Time (ms)   Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 22621 MP (16 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`4d000000 PsLoadedModuleList = 0xfffff800`4dc135a0
Debug session time: Mon Aug3 15:57:41.325 2026 (UTC + 8:00)
System Uptime: 0 days 1:49:08.049
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`4d41e230 48894c2408      mov   qword ptr ,rcx ss:0018:ffffcf05`ad357090=00000000000000ef
0: kd> !analyze -v
Loading Kernel Symbols
..
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.............................................................
................................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
*                                                                           *
*                        Bugcheck Analysis                                    *
*                                                                           *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
      A critical system process died
Arguments:
Arg1: ffffd50da8008080, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: ffffd50dadfde0c0, The process object that initiated the termination.
Arg4: 0000000000000000, Additional triage data.
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for 360Hvm64.sys
KEY_VALUES_STRING: 1
    Key: Analysis.CPU.mSec
    Value: 1203
    Key: Analysis.Elapsed.mSec
    Value: 1627
    Key: Analysis.IO.Other.Mb
    Value: 0
    Key: Analysis.IO.Read.Mb
    Value: 1
    Key: Analysis.IO.Write.Mb
    Value: 0
    Key: Analysis.Init.CPU.mSec
    Value: 265
    Key: Analysis.Init.Elapsed.mSec
    Value: 18795
    Key: Analysis.Memory.CommitPeak.Mb
    Value: 80
    Key: Analysis.Version.DbgEng
    Value: 10.0.29617.1000
    Key: Analysis.Version.Description
    Value: 10.2604.29.1 amd64fre
    Key: Analysis.Version.Ext
    Value: 1.2604.29.1
    Key: Bugcheck.Code.LegacyAPI
    Value: 0xef
    Key: Bugcheck.Code.TargetModel
    Value: 0xef
    Key: CriticalProcessDied.Process
    Value: LsaIso.exe
    Key: Dump.Attributes.AsUlong
    Value: 0x1808
    Key: Dump.Attributes.DiagDataWrittenToHeader
    Value: 1
    Key: Dump.Attributes.ErrorCode
    Value: 0x0
    Key: Dump.Attributes.KernelGeneratedTriageDump
    Value: 1
    Key: Dump.Attributes.LastLine
    Value: Dump completed successfully.
    Key: Dump.Attributes.ProgressPercentage
    Value: 0
    Key: Failure.Bucket
    Value: 0xEF_LsaIso.exe_IMAGE_LsaIso.exe
    Key: Failure.Hash
    Value: {04bd134c-2395-d458-fc7d-1fb87d130a2e}
    Key: Hypervisor.Enlightenments.ValueHex
    Value: 0x1417df84
    Key: Hypervisor.Flags.AnyHypervisorPresent
    Value: 1
    Key: Hypervisor.Flags.ApicEnlightened
    Value: 0
    Key: Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1
    Key: Hypervisor.Flags.AsyncMemoryHint
    Value: 0
    Key: Hypervisor.Flags.CoreSchedulerRequested
    Value: 0
    Key: Hypervisor.Flags.CpuManager
    Value: 1
    Key: Hypervisor.Flags.DeprecateAutoEoi
    Value: 1
    Key: Hypervisor.Flags.DynamicCpuDisabled
    Value: 1
    Key: Hypervisor.Flags.Epf
    Value: 0
    Key: Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1
    Key: Hypervisor.Flags.HardwareMbecAvailable
    Value: 1
    Key: Hypervisor.Flags.MaxBankNumber
    Value: 0
    Key: Hypervisor.Flags.MemoryZeroingControl
    Value: 0
    Key: Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0
    Key: Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1
    Key: Hypervisor.Flags.Phase0InitDone
    Value: 1
    Key: Hypervisor.Flags.PowerSchedulerQos
    Value: 0
    Key: Hypervisor.Flags.RootScheduler
    Value: 0
    Key: Hypervisor.Flags.SynicAvailable
    Value: 1
    Key: Hypervisor.Flags.UseQpcBias
    Value: 0
    Key: Hypervisor.Flags.Value
    Value: 21631230
    Key: Hypervisor.Flags.ValueHex
    Value: 0x14a10fe
    Key: Hypervisor.Flags.VpAssistPage
    Value: 1
    Key: Hypervisor.Flags.VsmAvailable
    Value: 1
    Key: Hypervisor.RootFlags.AccessStats
    Value: 1
    Key: Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1
    Key: Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1
    Key: Hypervisor.RootFlags.DisableHyperthreading
    Value: 0
    Key: Hypervisor.RootFlags.HostTimelineSync
    Value: 1
    Key: Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0
    Key: Hypervisor.RootFlags.IsHyperV
    Value: 1
    Key: Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1
    Key: Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1
    Key: Hypervisor.RootFlags.MceEnlightened
    Value: 1
    Key: Hypervisor.RootFlags.Nested
    Value: 0
    Key: Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1
    Key: Hypervisor.RootFlags.Value
    Value: 1015
    Key: Hypervisor.RootFlags.ValueHex
    Value: 0x3f7
    Key: WER.System.BIOSRevision
    Value: 1.47.0.0
BUGCHECK_CODE:ef
BUGCHECK_P1: ffffd50da8008080
BUGCHECK_P2: 0
BUGCHECK_P3: ffffd50dadfde0c0
BUGCHECK_P4: 0
FILE_IN_CAB:080326-29218-01.dmp
DUMP_FILE_ATTRIBUTES: 0x1808
Kernel Generated Triage Dump
FAULTING_THREAD:ffffd50dabed9080
PROCESS_NAME:LsaIso.exe
CRITICAL_PROCESS:LsaIso.exe
IMAGE_NAME:LsaIso.exe
MODULE_NAME: LsaIso
FAULTING_MODULE: 0000000000000000
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)
CUSTOMER_CRASH_COUNT:1
STACK_TEXT:
ffffcf05`ad357088 fffff800`4d9b3b2b   : 00000000`000000ef ffffd50d`a8008080 00000000`00000000 ffffd50d`adfde0c0 : nt!KeBugCheckEx
ffffcf05`ad357090 fffff800`4d8e17e9   : ffffd50d`a8008080 fffff800`4d204ff5 00000000`00000000 fffff800`4d204847 : nt!PspCatchCriticalBreak+0x11b
ffffcf05`ad357120 fffff800`4d683abb   : ffffd50d`a8008080 00000000`00000001 ffffd50d`a8008080 00000000`00000000 : nt!PspTerminateAllThreads+0x174329
ffffcf05`ad357190 fffff800`4d683891   : ffffffff`ffffffff ffffd50d`adfde0c0 ffffd50d`abed9080 ffffd50d`a8008080 : nt!PspTerminateProcess+0xe7
ffffcf05`ad3571d0 fffff800`6aa19a2e   : ffffd50d`00000520 00000000`00000000 ffffd50d`a8008080 00000000`00000f33 : nt!NtTerminateProcess+0xb1
ffffcf05`ad357250 ffffd50d`00000520   : 00000000`00000000 ffffd50d`a8008080 00000000`00000f33 ffffcf05`ad357290 : 360Hvm64+0x19a2e
ffffcf05`ad357258 00000000`00000000   : ffffd50d`a8008080 00000000`00000f33 ffffcf05`ad357290 ffffcf05`ad3573a0 : 0xffffd50d`00000520
STACK_COMMAND: .process /r /p 0xffffd50dadfde0c0; .thread /r /p 0xffffd50dabed9080 ; kb
FAILURE_BUCKET_ID:0xEF_LsaIso.exe_IMAGE_LsaIso.exe
OSPLATFORM_TYPE:x64
OSNAME:Windows 10
FAILURE_ID_HASH:{04bd134c-2395-d458-fc7d-1fb87d130a2e}
Followup:   MachineOwner
---------
0: kd> k
# Child-SP          RetAddr               Call Site
00 ffffcf05`ad357088 fffff800`4d9b3b2b   nt!KeBugCheckEx
01 ffffcf05`ad357090 fffff800`4d8e17e9   nt!PspCatchCriticalBreak+0x11b
02 ffffcf05`ad357120 fffff800`4d683abb   nt!PspTerminateAllThreads+0x174329
03 ffffcf05`ad357190 fffff800`4d683891   nt!PspTerminateProcess+0xe7
04 ffffcf05`ad3571d0 fffff800`6aa19a2e   nt!NtTerminateProcess+0xb1
05 ffffcf05`ad357250 ffffd50d`00000520   360Hvm64+0x19a2e
06 ffffcf05`ad357258 00000000`00000000   0xffffd50d`00000520
0: kd> !process
PROCESS ffffd50da8008080
    SessionId: noneCid: 0520    Peb: decb384000ParentCid: 04a0
    DirBase: 110cff002ObjectTable: ffffbe8342f88b40HandleCount:<Data Not Accessible>
    Image: LsaIso.exe
    VadRoot ffffd50da5f24bf0 Vads 45 Clone 0 Private 224. Modified 4. Locked 0.
    DeviceMap ffffbe833d489b50
    Token                           ffffbe83423ec060
    ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
    ElapsedTime                     00:00:00.000
    UserTime                        00:00:00.000
    KernelTime                        00:00:00.000
    QuotaPoolUsage         29408
    QuotaPoolUsage      6384
    Working Set Sizes (now,min,max)(1057, 50, 345) (4228KB, 200KB, 1380KB)
    PeakWorkingSetSize                1043
    VirtualSize                     4145 Mb
    PeakVirtualSize                   4146 Mb
    PageFaultCount                  1757
    MemoryPriority                  BACKGROUND
    BasePriority                      8
    CommitCharge                      279
      *** Error in reading nt!_ETHREAD @ ffffd50da8007240


分析结果里看到了系统的LsaIso.exe和一个360
扔给deepseek这么说


根据您提供的Windows调试器(WinDbg)分析输出,这个蓝屏错误(Bug Check 0xEF: CRITICAL_PROCESS_DIED)的原因和关键信息已明确。以下是对问题的详细解析和解决方案。


---
### 核心问题分析
1. **错误类型**:`CRITICAL_PROCESS_DIED (ef)`
   - 系统检测到一个关键的系统进程意外终止,导致系统认为无法继续安全运行,从而触发蓝屏。
2. **终止的进程**:`LsaIso.exe`
   - 这是 **Credential Guard** 和 **Key Isolation** 的核心进程,负责隔离和保护身份验证凭据(如智能卡、Windows Hello等)。它是Windows安全模型的重要组成部分。
3. **终止来源**:堆栈跟踪显示,终止操作最终是由 **`360Hvm64.sys`** 发起的。
   - 这是 **360安全软件(如360安全卫士、360杀毒)的虚拟化/防护驱动**。该驱动调用了 `NtTerminateProcess`,强制终止了 `LsaIso.exe`。
4. **直接原因**:
   - 360的驱动程序拦截或误判了 `LsaIso.exe` 的行为(可能是将其视为威胁或冲突),然后主动调用了终止进程的API。这一操作触发了系统保护机制,导致蓝屏。
---
### 详细堆栈解读(关键部分)
```
STACK_TEXT:
...
nt!PspTerminateProcess+0xe7
nt!NtTerminateProcess+0xb1
360Hvm64+0x19a2e<-- 关键:360驱动调用终止进程
...
```
- 堆栈清楚地显示了调用链:从360的驱动模块直接发起了对 `LsaIso.exe` 的终止操作,随后系统内核执行了进程终止并触发了错误检查。
---
### 解决方案建议
由于问题明确指向 **360安全软件** 与 **Windows Credential Guard** 的冲突,请按以下步骤处理:
#### 1. 临时快速修复(如能进入系统或安全模式)
- **卸载或禁用360系列软件**(安全卫士、杀毒、浏览器等所有360产品),重启计算机。这可以立即消除冲突源。
- 如果无法正常进入系统,请尝试进入 **安全模式** 进行卸载。
#### 2. 长期解决方案(如需保留360软件)
- **更新360软件**:访问360官方网站,下载并安装最新版本,看是否已修复此兼容性问题。
- **调整360防护设置**:在360的“防护中心”或“设置”中,尝试**关闭“主动防御”**或**“内核级防护”**相关选项,特别是与“虚拟化”或“系统加固”相关的功能。
- **向360官方反馈**:将此蓝屏分析结果(特别是 `360Hvm64.sys` 和 `LsaIso.exe` 冲突信息)提交给360技术支持,请求协助。
#### 3. 彻底解决(如果更新无效)
- **永久卸载360软件**,更换为其他兼容性更好的安全软件(如Windows Defender本身已足够强大),并确保Windows Defender实时保护已启用。
#### 4. 验证系统完整性(可选)
卸载冲突软件后,建议在管理员命令提示符中运行以下命令修复可能的系统文件损坏:
```cmd
sfc /scannow
```
---
### 关于“无法验证360Hvm64.sys时间戳”
- 这通常意味着该驱动文件的数字签名或版本信息可能已过期或损坏,也印证了版本兼容性问题是主要诱因。
### 总结
**本次蓝屏的直接原因是360安全驱动(360Hvm64.sys)误终止了关键系统进程LsaIso.exe。** 最直接有效的解决方法是卸载360软件或更新至兼容版本。此问题与硬件无关,无需更换硬件。
如果按照上述步骤操作后问题依然存在,请考虑提供新的转储文件进行进一步分析。


360自带的反馈还炸了,文字难以表达,发了个视频放哔哩哔哩了,bv码和网址不给发贴子里,稍后发评论
































































































































360fans_n5sXOG 发表于 2026-8-3 16:51

没招了不给发url链接,又不给帖子里上传视频真神了

leo0205 发表于 2026-8-3 17:43

您好,您关闭核晶防护看看正常吗,如果正常的话,您加下我的微信,我帮您看下


页: [1]
查看完整版本: 360把我系统杀了,还有360内置的反馈功能炸了