360fans_MEOMCw 发表于 2026-9-5 15:30

0x18 REFERENCE_BY_POINTER蓝屏,系统win1125h2,360极速版版本15.0.3.1005

本帖最后由 360fans_MEOMCw 于 2026-9-5 15:32 编辑


链接不让填,附件也传不上去,发图片里了
版本      Windows 11 专业工作站版
版本号      25H2
安装日期      ‎2026/‎7/‎6
操作系统版本      26200.9168
功能包      Windows 功能体验包 1000.26100.344.0
4: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
................................................................
.................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`00ec9018).Type .hh dbgerr001 for details
Loading unloaded module list
.............................................
*******************************************************************************
*                                                                           *
*                        Bugcheck Analysis                                    *
*                                                                           *
*******************************************************************************

REFERENCE_BY_POINTER (18)
Arguments:
Arg1: ffffa08abd7d1e30, Object type of the object whose reference count is being lowered
Arg2: ffffa08b29d458b0, Object whose reference count is being lowered
Arg3: 0000000000000001, Reserved
Arg4: 0000000000000001, Reserved
The reference count of an object is illegal for the current state of the object.
Each time a driver uses a pointer to an object the driver calls a kernel routine
to increment the reference count of the object. When the driver is done with the
pointer the driver calls another kernel routine to decrement the reference count.
Drivers must match calls to the increment and decrement routines. This BugCheck
can occur because an object's reference count goes to zero while there are still
open handles to the object, in which case the fourth parameter indicates the number
of opened handles. It may also occur when the object's reference count drops below zero
whether or not there are open handles to the object, and in that case the fourth parameter
contains the actual value of the pointer references count.

Debugging Details:
------------------

Unable to load image \SystemRoot\system32\DRIVERS\360FsFlt.sys, Win32 error 0n2
Unable to load image \SystemRoot\System32\Drivers\360Hvm64.sys, Win32 error 0n2

KEY_VALUES_STRING: 1

    Key: Analysis.CPU.mSec
    Value: 1906

    Key: Analysis.Elapsed.mSec
    Value: 5711

    Key: Analysis.IO.Other.Mb
    Value: 0

    Key: Analysis.IO.Read.Mb
    Value: 1

    Key: Analysis.IO.Write.Mb
    Value: 0

    Key: Analysis.Init.CPU.mSec
    Value: 468

    Key: Analysis.Init.Elapsed.mSec
    Value: 1755

    Key: Analysis.Memory.CommitPeak.Mb
    Value: 94

    Key: Analysis.Version.DbgEng
    Value: 10.0.29617.1000

    Key: Analysis.Version.Deion
    Value: 10.2604.29.1 amd64fre

    Key: Analysis.Version.Ext
    Value: 1.2604.29.1

    Key: Bugcheck.Code.KiBugCheckData
    Value: 0x18

    Key: Bugcheck.Code.LegacyAPI
    Value: 0x18

    Key: Bugcheck.Code.TargetModel
    Value: 0x18

    Key: Dump.Attributes.AsUlong
    Value: 0x21800

    Key: Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key: Dump.Attributes.ErrorCode
    Value: 0x0

    Key: Dump.Attributes.LastLine
    Value: Dumping physical memory to disk:100%


    Key: Dump.Attributes.ProgressPercentage
    Value: 100

    Key: Failure.Bucket
    Value: 0x18_EXCESS_HANDLE_COUNT_360FsFlt!unknown_function

    Key: Failure.Hash
    Value: {9f7775c7-8acd-a51e-f75b-ed85eacd86d6}

    Key: Hypervisor.Enlightenments.ValueHex
    Value: 0x7417df84

    Key: Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key: Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key: Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1

    Key: Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key: Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key: Hypervisor.Flags.CpuManager
    Value: 1

    Key: Hypervisor.Flags.DeprecateAutoEoi
    Value: 1

    Key: Hypervisor.Flags.DynamicCpuDisabled
    Value: 1

    Key: Hypervisor.Flags.Epf
    Value: 0

    Key: Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1

    Key: Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key: Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key: Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key: Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key: Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1

    Key: Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key: Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key: Hypervisor.Flags.RootScheduler
    Value: 0

    Key: Hypervisor.Flags.SynicAvailable
    Value: 1

    Key: Hypervisor.Flags.UseQpcBias
    Value: 0

    Key: Hypervisor.Flags.Value
    Value: 55185662

    Key: Hypervisor.Flags.ValueHex
    Value: 0x34a10fe

    Key: Hypervisor.Flags.VpAssistPage
    Value: 1

    Key: Hypervisor.Flags.VsmAvailable
    Value: 1

    Key: Hypervisor.RootFlags.AccessStats
    Value: 1

    Key: Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1

    Key: Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1

    Key: Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key: Hypervisor.RootFlags.HostTimelineSync
    Value: 1

    Key: Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key: Hypervisor.RootFlags.IsHyperV
    Value: 1

    Key: Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1

    Key: Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1

    Key: Hypervisor.RootFlags.MceEnlightened
    Value: 1

    Key: Hypervisor.RootFlags.Nested
    Value: 0

    Key: Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1

    Key: Hypervisor.RootFlags.Value
    Value: 1015

    Key: Hypervisor.RootFlags.ValueHex
    Value: 0x3f7

    Key: SecureKernel.HalpHvciEnabled
    Value: 0

    Key: WER.OS.Branch
    Value: ge_release

    Key: WER.OS.Version
    Value: 10.0.26100.1

    Key: WER.System.BIOSRevision
    Value: 5.27.0.0


BUGCHECK_CODE:18

BUGCHECK_P1: ffffa08abd7d1e30

BUGCHECK_P2: ffffa08b29d458b0

BUGCHECK_P3: 1

BUGCHECK_P4: 1

FILE_IN_CAB:MEMORY.DMP

DUMP_FILE_ATTRIBUTES: 0x21800

FAULTING_THREAD:ffffa08b27be60c0

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


PROCESS_NAME:CodeSetup-stable-a44adf7f53e00964ab890f9f8758a334f1fc15bc.tmp

STACK_TEXT:
fffffa09`f9547198 fffff802`b68c38bc   : 00000000`00000018 ffffa08a`bd7d1e30 ffffa08b`29d458b0 00000000`00000001 : nt!KeBugCheckEx
fffffa09`f95471a0 fffff802`b6e49551   : 00000000`00000001 00000000`00000001 00000000`00000001 ffffa08b`29d45880 : nt!ObfDereferenceObjectWithTag+0xbc
fffffa09`f95471e0 fffff802`b6e47ce9   : ffff4400`d39cb8a5 fffffa09`f9547409 00000000`c0000022 fffff802`b6cc041f : nt!ObCloseHandleTableEntry+0x3b1
fffffa09`f9547330 fffff802`b6cc0441   : 00000000`00000000 00000000`00000000 ffffa08b`27be60c0 00000000`00000000 : nt!NtClose+0xe9
fffffa09`f95473a0 fffff802`b6cae050   : fffff802`4b61a70d 00000000`00000000 fffffa09`f9547678 fffffa09`f95475c0 : nt!KiSystemServiceExitPico+0x496
fffffa09`f9547538 fffff802`4b61a70d   : 00000000`00000000 fffffa09`f9547678 fffffa09`f95475c0 ffffb20d`855c72a0 : nt!KiServiceLinkage
fffffa09`f9547540 fffff802`4b61b1f9   : 00000000`00003660 00000000`00003660 fffffa09`f95476a0 00000000`00100862 : 360FsFlt+0x1a70d
fffffa09`f9547640 fffff802`4b631f81   : ffffa08a`f653e420 ffffb20d`e7c3f650 00000000`00003660 00000000`000101e0 : 360FsFlt+0x1b1f9
fffffa09`f9547670 fffff802`4b63214b   : 00000000`00000000 fffffa09`f9547a20 fffffa09`f9547a01 fffffa09`f95478f0 : 360FsFlt+0x31f81
fffffa09`f95476f0 fffff802`4bfbad8e   : 00000000`00000000 fffffa09`f9547988 00000000`0000000d fffffa09`f95479a0 : 360FsFlt+0x3214b
fffffa09`f9547860 fffff802`4bfcb7d5   : fffff802`b75c72c0 00000000`0000002c fffffa09`f95478f0 fffff802`b6ebfa70 : 360Hvm64+0xad8e
fffffa09`f95478c0 fffff802`b6cc0441   : ffffa08b`00000000 ffffa08b`27be60c0 fffffa09`f9547aa0 00000000`0000c57d : 360Hvm64+0x1b7d5
fffffa09`f9547a20 00007ffc`b236cc64   : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x496
00000000`0103dde8 00000000`00000000   : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`b236cc64


SYMBOL_NAME:360FsFlt+1a70d

MODULE_NAME: 360FsFlt

IMAGE_NAME:360FsFlt.sys

STACK_COMMAND: .process /r /p 0xffffa08b2bae30c0; .thread /r /p 0xffffa08b27be60c0 ; kb

BUCKET_ID_FUNC_OFFSET:1a70d

FAILURE_BUCKET_ID:0x18_EXCESS_HANDLE_COUNT_360FsFlt!unknown_function

OS_VERSION:10.0.26100.1

BUILDLAB_STR:ge_release

OSPLATFORM_TYPE:x64

OSNAME:Windows 10

FAILURE_ID_HASH:{9f7775c7-8acd-a51e-f75b-ed85eacd86d6}

Followup:   MachineOwner
---------

360fans_MEOMCw 发表于 2026-9-5 16:16

更新vscode时蓝屏

leo0205 发表于 2026-9-5 16:48

我们提交分析一下此问题

360fans_22602395 发表于 2026-9-13 09:31

好家伙,下载你的附件,网盘还要收费1元……
360fsflt.sys是360安全软件中木马防火墙模块的驱动文件,用于实时监控系统文件操作以防御恶意攻击。






该驱动文件可能导致Windows蓝屏,常见错误包括:

PAGE_FAULT_IN_NONPAGED_AREA
KMODE_EXCEPTION_NOT_HANDLED
KERNEL_DATA_INPAGE_ERROR
SYSTEM_SERVICE_EXCEPTION
蓝屏通常与以下因素有关:
驱动冲突:系统中存在多款安全软件时,底层驱动可能互相干扰 。
软件兼容性问题:360安全软件版本与Windows系统不兼容。
系统文件损坏或硬件问题:如磁盘或内存异常 。

解决方法
卸载冲突软件:如果系统中安装了多款杀毒软件(如360安全卫士、腾讯电脑管家、卡巴斯基等),建议只保留一款,并重启系统 。
更新或重装360软件:通过360官网下载最新版本覆盖安装,确保与系统兼容。
安全模式操作:
开机按F8(部分设备需Shift+F8)进入安全模式。
在设备管理器中找到360fsflt.sys相关驱动并卸载。
系统文件修复:使用命令提示符运行sfc /scannow扫描并修复系统文件 。
系统还原:若近期安装软件或更新导致问题,可通过控制面板恢复至正常状态。
检查硬件:如蓝屏仍频繁出现,可排查磁盘、内存或主板问题
页: [1]
查看完整版本: 0x18 REFERENCE_BY_POINTER蓝屏,系统win1125h2,360极速版版本15.0.3.1005