请使用手机微信扫码安全登录

切换账号密码登录

绑定手机号

应国家法规对于账号实名的要求,请您在进行下一步操作前,需要先完成手机绑定 (若绑定失败,请重新登录绑定)。了解更多

不绑定绑定手机号

360官网 | 360商城

推荐论坛版块360粉丝商城360用户活动常见问题

打cod打的好好的忽然蓝屏了,把日志导出来扔windbg里:
************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.015 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 46
Microsoft (R) Windows Debugger Version 10.0.29617.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\19065\Desktop\080326-29218-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 22621 MP (16 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`4d000000 PsLoadedModuleList = 0xfffff800`4dc135a0
Debug session time: Mon Aug  3 15:57:41.325 2026 (UTC + 8:00)
System Uptime: 0 days 1:49:08.049
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`4d41e230 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffcf05`ad357090=00000000000000ef
0: kd> !analyze -v
Loading Kernel Symbols
..
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.............................................................
................................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
        A critical system process died
Arguments:
Arg1: ffffd50da8008080, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: ffffd50dadfde0c0, The process object that initiated the termination.
Arg4: 0000000000000000, Additional triage data.
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for 360Hvm64.sys
KEY_VALUES_STRING: 1
    Key  : Analysis.CPU.mSec
    Value: 1203
    Key  : Analysis.Elapsed.mSec
    Value: 1627
    Key  : Analysis.IO.Other.Mb
    Value: 0
    Key  : Analysis.IO.Read.Mb
    Value: 1
    Key  : Analysis.IO.Write.Mb
    Value: 0
    Key  : Analysis.Init.CPU.mSec
    Value: 265
    Key  : Analysis.Init.Elapsed.mSec
    Value: 18795
    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 80
    Key  : Analysis.Version.DbgEng
    Value: 10.0.29617.1000
    Key  : Analysis.Version.Description
    Value: 10.2604.29.1 amd64fre
    Key  : Analysis.Version.Ext
    Value: 1.2604.29.1
    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xef
    Key  : Bugcheck.Code.TargetModel
    Value: 0xef
    Key  : CriticalProcessDied.Process
    Value: LsaIso.exe
    Key  : Dump.Attributes.AsUlong
    Value: 0x1808
    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1
    Key  : Dump.Attributes.ErrorCode
    Value: 0x0
    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1
    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.
    Key  : Dump.Attributes.ProgressPercentage
    Value: 0
    Key  : Failure.Bucket
    Value: 0xEF_LsaIso.exe_IMAGE_LsaIso.exe
    Key  : Failure.Hash
    Value: {04bd134c-2395-d458-fc7d-1fb87d130a2e}
    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x1417df84
    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1
    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0
    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1
    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0
    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0
    Key  : Hypervisor.Flags.CpuManager
    Value: 1
    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 1
    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 1
    Key  : Hypervisor.Flags.Epf
    Value: 0
    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1
    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1
    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0
    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0
    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0
    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1
    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1
    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0
    Key  : Hypervisor.Flags.RootScheduler
    Value: 0
    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1
    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0
    Key  : Hypervisor.Flags.Value
    Value: 21631230
    Key  : Hypervisor.Flags.ValueHex
    Value: 0x14a10fe
    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1
    Key  : Hypervisor.Flags.VsmAvailable
    Value: 1
    Key  : Hypervisor.RootFlags.AccessStats
    Value: 1
    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1
    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1
    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0
    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 1
    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0
    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 1
    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1
    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1
    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 1
    Key  : Hypervisor.RootFlags.Nested
    Value: 0
    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1
    Key  : Hypervisor.RootFlags.Value
    Value: 1015
    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x3f7
    Key  : WER.System.BIOSRevision
    Value: 1.47.0.0
BUGCHECK_CODE:  ef
BUGCHECK_P1: ffffd50da8008080
BUGCHECK_P2: 0
BUGCHECK_P3: ffffd50dadfde0c0
BUGCHECK_P4: 0
FILE_IN_CAB:  080326-29218-01.dmp
DUMP_FILE_ATTRIBUTES: 0x1808
  Kernel Generated Triage Dump
FAULTING_THREAD:  ffffd50dabed9080
PROCESS_NAME:  LsaIso.exe
CRITICAL_PROCESS:  LsaIso.exe
IMAGE_NAME:  LsaIso.exe
MODULE_NAME: LsaIso
FAULTING_MODULE: 0000000000000000
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)
CUSTOMER_CRASH_COUNT:  1
STACK_TEXT:  
ffffcf05`ad357088 fffff800`4d9b3b2b     : 00000000`000000ef ffffd50d`a8008080 00000000`00000000 ffffd50d`adfde0c0 : nt!KeBugCheckEx
ffffcf05`ad357090 fffff800`4d8e17e9     : ffffd50d`a8008080 fffff800`4d204ff5 00000000`00000000 fffff800`4d204847 : nt!PspCatchCriticalBreak+0x11b
ffffcf05`ad357120 fffff800`4d683abb     : ffffd50d`a8008080 00000000`00000001 ffffd50d`a8008080 00000000`00000000 : nt!PspTerminateAllThreads+0x174329
ffffcf05`ad357190 fffff800`4d683891     : ffffffff`ffffffff ffffd50d`adfde0c0 ffffd50d`abed9080 ffffd50d`a8008080 : nt!PspTerminateProcess+0xe7
ffffcf05`ad3571d0 fffff800`6aa19a2e     : ffffd50d`00000520 00000000`00000000 ffffd50d`a8008080 00000000`00000f33 : nt!NtTerminateProcess+0xb1
ffffcf05`ad357250 ffffd50d`00000520     : 00000000`00000000 ffffd50d`a8008080 00000000`00000f33 ffffcf05`ad357290 : 360Hvm64+0x19a2e
ffffcf05`ad357258 00000000`00000000     : ffffd50d`a8008080 00000000`00000f33 ffffcf05`ad357290 ffffcf05`ad3573a0 : 0xffffd50d`00000520
STACK_COMMAND: .process /r /p 0xffffd50dadfde0c0; .thread /r /p 0xffffd50dabed9080 ; kb
FAILURE_BUCKET_ID:  0xEF_LsaIso.exe_IMAGE_LsaIso.exe
OSPLATFORM_TYPE:  x64
OSNAME:  Windows 10
FAILURE_ID_HASH:  {04bd134c-2395-d458-fc7d-1fb87d130a2e}
Followup:     MachineOwner
---------
0: kd> k
# Child-SP          RetAddr               Call Site
00 ffffcf05`ad357088 fffff800`4d9b3b2b     nt!KeBugCheckEx
01 ffffcf05`ad357090 fffff800`4d8e17e9     nt!PspCatchCriticalBreak+0x11b
02 ffffcf05`ad357120 fffff800`4d683abb     nt!PspTerminateAllThreads+0x174329
03 ffffcf05`ad357190 fffff800`4d683891     nt!PspTerminateProcess+0xe7
04 ffffcf05`ad3571d0 fffff800`6aa19a2e     nt!NtTerminateProcess+0xb1
05 ffffcf05`ad357250 ffffd50d`00000520     360Hvm64+0x19a2e
06 ffffcf05`ad357258 00000000`00000000     0xffffd50d`00000520
0: kd> !process
PROCESS ffffd50da8008080
    SessionId: none  Cid: 0520    Peb: decb384000  ParentCid: 04a0
    DirBase: 110cff002  ObjectTable: ffffbe8342f88b40  HandleCount:<Data Not Accessible>
    Image: LsaIso.exe
    VadRoot ffffd50da5f24bf0 Vads 45 Clone 0 Private 224. Modified 4. Locked 0.
    DeviceMap ffffbe833d489b50
    Token                             ffffbe83423ec060
    ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
    ElapsedTime                       00:00:00.000
    UserTime                          00:00:00.000
    KernelTime                        00:00:00.000
    QuotaPoolUsage[PagedPool]         29408
    QuotaPoolUsage[NonPagedPool]      6384
    Working Set Sizes (now,min,max)  (1057, 50, 345) (4228KB, 200KB, 1380KB)
    PeakWorkingSetSize                1043
    VirtualSize                       4145 Mb
    PeakVirtualSize                   4146 Mb
    PageFaultCount                    1757
    MemoryPriority                    BACKGROUND
    BasePriority                      8
    CommitCharge                      279
        *** Error in reading nt!_ETHREAD @ ffffd50da8007240


分析结果里看到了系统的LsaIso.exe和一个360
扔给deepseek这么说


根据您提供的Windows调试器(WinDbg)分析输出,这个蓝屏错误(Bug Check 0xEF: CRITICAL_PROCESS_DIED)的原因和关键信息已明确。以下是对问题的详细解析和解决方案。


---
### 核心问题分析
1. **错误类型**:`CRITICAL_PROCESS_DIED (ef)`
   - 系统检测到一个关键的系统进程意外终止,导致系统认为无法继续安全运行,从而触发蓝屏。
2. **终止的进程**:`LsaIso.exe`
   - 这是 **Credential Guard** 和 **Key Isolation** 的核心进程,负责隔离和保护身份验证凭据(如智能卡、Windows Hello等)。它是Windows安全模型的重要组成部分。
3. **终止来源**:堆栈跟踪显示,终止操作最终是由 **`360Hvm64.sys`** 发起的。
   - 这是 **360安全软件(如360安全卫士、360杀毒)的虚拟化/防护驱动**。该驱动调用了 `NtTerminateProcess`,强制终止了 `LsaIso.exe`。
4. **直接原因**:
   - 360的驱动程序拦截或误判了 `LsaIso.exe` 的行为(可能是将其视为威胁或冲突),然后主动调用了终止进程的API。这一操作触发了系统保护机制,导致蓝屏。
---
### 详细堆栈解读(关键部分)
```
STACK_TEXT:
...
nt!PspTerminateProcess+0xe7
nt!NtTerminateProcess+0xb1
360Hvm64+0x19a2e<-- 关键:360驱动调用终止进程
...
```
- 堆栈清楚地显示了调用链:从360的驱动模块直接发起了对 `LsaIso.exe` 的终止操作,随后系统内核执行了进程终止并触发了错误检查。
---
### 解决方案建议
由于问题明确指向 **360安全软件** 与 **Windows Credential Guard** 的冲突,请按以下步骤处理:
#### 1. 临时快速修复(如能进入系统或安全模式)
- **卸载或禁用360系列软件**(安全卫士、杀毒、浏览器等所有360产品),重启计算机。这可以立即消除冲突源。
- 如果无法正常进入系统,请尝试进入 **安全模式** 进行卸载。
#### 2. 长期解决方案(如需保留360软件)
- **更新360软件**:访问360官方网站,下载并安装最新版本,看是否已修复此兼容性问题。
- **调整360防护设置**:在360的“防护中心”或“设置”中,尝试**关闭“主动防御”**或**“内核级防护”**相关选项,特别是与“虚拟化”或“系统加固”相关的功能。
- **向360官方反馈**:将此蓝屏分析结果(特别是 `360Hvm64.sys` 和 `LsaIso.exe` 冲突信息)提交给360技术支持,请求协助。
#### 3. 彻底解决(如果更新无效)
- **永久卸载360软件**,更换为其他兼容性更好的安全软件(如Windows Defender本身已足够强大),并确保Windows Defender实时保护已启用。
#### 4. 验证系统完整性(可选)
卸载冲突软件后,建议在管理员命令提示符中运行以下命令修复可能的系统文件损坏:
```cmd
sfc /scannow
```
---
### 关于“无法验证360Hvm64.sys时间戳”
- 这通常意味着该驱动文件的数字签名或版本信息可能已过期或损坏,也印证了版本兼容性问题是主要诱因。
### 总结
**本次蓝屏的直接原因是360安全驱动(360Hvm64.sys)误终止了关键系统进程LsaIso.exe。** 最直接有效的解决方法是卸载360软件或更新至兼容版本。此问题与硬件无关,无需更换硬件。
如果按照上述步骤操作后问题依然存在,请考虑提供新的转储文件进行进一步分析。


360自带的反馈还炸了,文字难以表达,发了个视频放哔哩哔哩了,bv码和网址不给发贴子里,稍后发评论
































































































































共 2 个关于360把我系统杀了,还有360内置的反馈功能炸了的回复 最后回复于 2026-8-3 17:43

评论

直达楼层

沙发
360fans_n5sXOG LV1.上等兵 楼主 发表于 2026-8-3 16:51 | 只看该作者 | 私信

IP属地: 广东省

没招了不给发url链接,又不给帖子里上传视频真神了
板凳
leo0205 产品答疑师 发表于 2026-8-3 17:43 | 只看该作者 | 私信

IP属地: 未知

您好,您关闭核晶防护看看正常吗,如果正常的话,您加下我的微信,我帮您看下


您需要登录后才可以回帖 登录 | 注册

本版积分规则

360fans_n5sXOG LV1.上等兵

粉丝:0 关注:0 积分:1

精华:0 金币:8 经验:4

IP属地: 局域网

最后登录时间:2026-8-3

私信 加好友

最新活动

粽叶飘香·共度端午 |360社区端午节活动上

排行榜

热度排行 查看排行
本月
    本月

      扫码添加360粉丝团助手有超多福利等你来哦

      快速回复 返回顶部 返回列表