- 软件版本
Windows 7 Ultimate Service Pack 1 [Build 6.1.7601]
电脑管家 12.0.18066.222 DF6E0633A4681CE829E344A5B83C2573
- 测试条件
针对 “清理垃圾” 功能点,制作了视频文件在下载目录下,导致清理垃圾量很大 >50gb
每次断开电脑管理会接着上次的清理进度 ok
- 测试步骤
1)在清理过程中,反复对电脑管理模式切换,产生句柄 crash
轻巧模式->经典模式->循环多次->轻巧模式出现截图情况,假死后几秒后出现 crash
抽取有用 log 如下
CallStack:
0X75D00000[C41F] KERNELBASE.dll: (-529697949,1,3,222946936)
0X756E0000[28E89] MSVCR80.dll: (222946964,1970689860,1970565352,1970562144)
0X756E0000[30E7C] MSVCR80.dll: (516,222947064,2011673370,2011673395)
0X75780000[9FAA] MSVCP80.dll: (258,0,1970310871,222949116)
0X75780000[F568] MSVCP80.dll: (257,0,222949224,257)
0X75780000[F5FE] MSVCP80.dll: (222949224,0,-1,1970883376)
0X75780000[11EE0] MSVCP80.dll: (222949416,222949360,2129475584,1902648616)
0X6E820000[20DA8] GarbageCleaner.dll: (72808276,1902648336,72808276,2129475296)
0X6E820000[1F65C] GarbageCleaner.dll: (222950264,222950236,212186880,222950236)
0X6E820000[1FD81] GarbageCleaner.dll: (222950264,222950236,2129475296,212186880)
0X6E820000[12585] GarbageCleaner.dll: (2129475296,1902648484,212186528,212186732)
0X6E820000[11DE4] GarbageCleaner.dll: (222951604,212186732,1,212186528)
0X6E820000[113F1] GarbageCleaner.dll: (222951604,212186732,1,1902647196)
0X6E820000[10ED3] GarbageCleaner.dll: (1902646452,190050568,72748848,72748872)
0X6E820000[38A0F] GarbageCleaner.dll: (1976965840,32769,1854257881,0)
0X6E820000[3BB4F] GarbageCleaner.dll: (5639984,1853874792,0,0)
0X756E0000[29BB] MSVCR80.dll: (0,1976972138,189895952,222952708)
0X756E0000[2A47] MSVCR80.dll: (189895952,2061794042,0,0)
0X77E20000[39F72] ntdll.dll: (1970153953,189895952,0,0)
0X77E20000[39F45] ntdll.dll: (1970153953,189895952,0,0)
Regs:
EAX=0D49E5FC, EBX=7578F552, ECX=00000003, EDX=00000000
ESI=7577451C, EDI=0D49EEFC, EBP=0D49E64C, ESP=0D49E5FC, EIP=75D0C41F
Bytes at CS:EIP:
C9 C2 10 00 CC CC CC CC CC 8B FF 55 8B EC 56 8B 75 08 83 FE F4 72 18 83 FE F6 77 13 8D 45 08 50
pid=6872 init_tid=6876 crashtid=6288
Bytes at teb:
24 DD 49 0D 00 00 4A 0D 00 E0 48 0D 00 00 00 00 00 1E 00 00 00 00 00 00 00 80 F1 7E 00 00 00 00 D8 1A 00 00 90 18 00 00
Modules:
<这里回避敏感去掉,都是我本地的>
这段证实是面向的软件,省略了部分
HWND:00100636 Title: Class:TXGuiFoundation WndProc:0 UserData:0
HWND:00190304 Title: Class:TXGuiFoundation WndProc:0 UserData:0
HWND:000703FE Title: Class:TXGFLayerMask WndProc:0 UserData:6879128
HWND:00020640 Title: Class:TXGuiFoundation WndProc:0 UserData:0
HWND:00020644 Title: Class:AtlAxWin80 WndProc:0 UserData:71760980
HWND:0006041E Title:电脑管家 Class:TXGuiFoundation WndProc:0 UserData:6879128
HWND:000804D2 Title: Class:TXGuiFoundation WndProc:0 UserData:0
HWND:00040624 Title:GarbageClean.regeditclean Class:CSysHPAdapterGarbageClean WndProc:0 UserData:72774528
HWND:000B04CC Title:GarbageClean.garbageclean Class:CSysHPAdapterGarbageClean WndProc:0 UserData:72567648
HWND:00130412 Title:{19A85DED-0447-45af-AD64-1484AC003CB3} Class:Static WndProc:0 UserData:6529088
HWND:00090406 Title: Class:Static WndProc:0 UserData:0
HWND_MESSAGE children begin
Crash Signature: 5768EE37EE42B7CF5E6E7B70811E92F9
CommondLine: bugreport /buginfo:000009E4:00000D00:0055B4D8:6872 /ext1:00000000
Mini Dump Errcode: 0x00000006
GUID: fa8219521a57b47b20b3216708f4a115
WorkingSetSize[1957228544] VirtualSize[2093137920] PagefileUsage[1834291200]
Boot Time: 2016-11-01 21:53:36
Current Time: 2016-11-01 23:40:07
还有一份 dmp 如果用 windbg 可以看出更多问题,这里就不上传了。
- 测试步骤
第二种方式,如图轻巧模式切换到当前模式,整理比较久清理垃圾时,当点击红圈区域
业务上这个红圈区域正在检查中,几秒后,这个恶意软件检查 pass 会向上自动消除的,时间由硬件运行效率有浮动
按道理应该是点击这块区域任意是无响应的,但目前点击后有 1 个小小的 loading,然后 crash 了
这个产生的 log 和上面信息一致。