KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff92811ccdf400, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff92811ccdf358, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 890
Key : Analysis.Elapsed.mSec
Value: 12858
Key : Analysis.IO.Other.Mb
Value: 1
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 8
Key : Analysis.Init.CPU.mSec
Value: 312
Key : Analysis.Init.Elapsed.mSec
Value: 958
Key : Analysis.Memory.CommitPeak.Mb
Value: 92
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : FailFast.Name
Value: CORRUPT_LIST_ENTRY
Key : FailFast.Type
Value: 3
Key : Failure.Bucket
Value: 0x139_3_CORRUPT_LIST_ENTRY_win32kfull!DecTimerCountAndClearReadyFlag
Key : Failure.Exception.Code
Value: 0xc0000409
Key : Failure.Exception.Record
Value: 0xffff92811ccdf358
Key : Failure.Hash
Value: {5b5491b4-7ff3-f096-5cb8-b29d3dba7440}
Key : WER.OS.Branch
Value: ge_release
Key : WER.OS.Version
Value: 10.0.26100.1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff92811ccdf400
BUGCHECK_P3: ffff92811ccdf358
BUGCHECK_P4: 0
FILE_IN_CAB: 042825-6281-01.dmp
FAULTING_THREAD: ffffb00b4ca98080
TRAP_FRAME: ffff92811ccdf400 -- (.trap 0xffff92811ccdf400)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000001 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000108 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8069180e0b0 rsp=ffff92811ccdf590 rbp=ffffe504588f4010
r8=0000000000000000 r9=0000000000000000 r10=fffff806ea927630
r11=ffff92811ccdf590 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
win32kfull!DecTimerCountAndClearReadyFlag+0x90:
fffff806`9180e0b0 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff92811ccdf358 -- (.exr 0xffff92811ccdf358)
ExceptionAddress: fffff8069180e0b0 (win32kfull!DecTimerCountAndClearReadyFlag+0x0000000000000090)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: Setup.tmp
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff9281`1ccdf0d8 fffff806`eacb8fe9 : 00000000`00000139 00000000`00000003 ffff9281`1ccdf400 ffff9281`1ccdf358 : nt!KeBugCheckEx
ffff9281`1ccdf0e0 fffff806`eacb95f2 : ffff9281`1ccdf300 ffff9281`1ccdf4c0 ffffffff`80003658 fffff806`eae4ac8e : nt!KiBugCheckDispatch+0x69
ffff9281`1ccdf220 fffff806`eacb7228 : 00000000`00000000 fffff806`9159372b ffffe504`3c17a8a0 fffff806`7c405490 : nt!KiFastFailDispatch+0xb2
ffff9281`1ccdf400 fffff806`9180e0b0 : 00000000`00000000 ffffe504`588f4550 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x368
ffff9281`1ccdf590 fffff806`917d164d : 00000000`00000057 ffffe504`58297498 ffffe504`588f4010 ffffe504`588f4010 : win32kfull!DecTimerCountAndClearReadyFlag+0x90
ffff9281`1ccdf5c0 fffff806`915ddcf0 : ffffe504`588f4010 00000000`00000001 00000000`00000000 ffff9281`1ccdf980 : win32kfull!DoTimer+0x21d
ffff9281`1ccdf660 fffff806`915dcf56 : ffff9281`1ccdf980 fffff806`913b389b ffffe504`00000000 00000000`00000000 : win32kfull!xxxRealInternalGetMessage+0xc30
ffff9281`1ccdf8f0 fffff806`915dce3d : 00000000`00000000 00000000`0009e490 00000000`00000000 00000000`00000000 : win32kfull!xxxInternalGetMessage+0x76
ffff9281`1ccdf930 fffff806`7c3f1077 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00355000 : win32kfull!NtUserPeekMessage+0xfd
ffff9281`1ccdf9e0 fffff806`eacb8658 : ffffb00b`4ca98080 ffff9281`1ccdfb20 00000000`0009e478 00000000`00355000 : win32k!NtUserPeekMessage+0x67
ffff9281`1ccdfa30 00007fff`cf5dc104 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000000`0009e458 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`cf5dc104
SYMBOL_NAME: win32kfull!DecTimerCountAndClearReadyFlag+90
MODULE_NAME: win32kfull
IMAGE_NAME: win32kfull.sys
IMAGE_VERSION: 10.0.26100.3912
STACK_COMMAND: .process /r /p 0xffffb00b4ca97080; .thread 0xffffb00b4ca98080 ; kb
BUCKET_ID_FUNC_OFFSET: 90
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_win32kfull!DecTimerCountAndClearReadyFlag
OS_VERSION: 10.0.26100.1
BUILDLAB_STR: ge_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {5b5491b4-7ff3-f096-5cb8-b29d3dba7440}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133903255116441388
PnpEventInformation: 3
PnpEventInProgress : 0
PnpProblemCode : 24
PnpVetoType : 0
DeviceId : USB\VID_046D&PID_C21D\9D1B2E7D
VetoString :
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000039, The subtype of the BugCheck.
Arg2: 0000000000000000
Arg3: 00000000000004ce
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 859
Key : Analysis.Elapsed.mSec
Value: 862
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 250
Key : Analysis.Init.Elapsed.mSec
Value: 945
Key : Analysis.Memory.CommitPeak.Mb
Value: 80
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1a
Key : Bugcheck.Code.TargetModel
Value: 0x1a
Key : Failure.Bucket
Value: PAGE_HASH_ERRORS_0x1a_39
Key : Failure.Hash
Value: {d1a10898-8495-4d08-b385-22aea5adadcc}
Key : Memory.System.Errors.PageHashErrors
Value: 1
Key : WER.OS.Branch
Value: ge_release
Key : WER.OS.Version
Value: 10.0.26100.1
BUGCHECK_CODE: 1a
BUGCHECK_P1: 39
BUGCHECK_P2: 0
BUGCHECK_P3: 4ce
BUGCHECK_P4: 0
FILE_IN_CAB: 042825-5312-01.dmp
FAULTING_THREAD: ffffb60bc9e020c0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
PAGE_HASH_ERRORS_DETECTED: 1
STACK_TEXT:
fffff604`fc6174e8 fffff807`a128bb77 : 00000000`0000001a 00000000`00000039 00000000`00000000 00000000`000004ce : nt!KeBugCheckEx
fffff604`fc6174f0 fffff807`a12d43d6 : 00000000`00000000 00000000`00000001 fffff604`fc6175f0 ffff9801`f0061102 : nt!MiPageHashBugCheck+0x4f
fffff604`fc617530 fffff807`a0f476da : ffffe680`091401f0 00000000`00000000 00000000`00000000 ffffb60b`cc4b12d0 : nt!MiArePagefileContentsCorrupted+0x38cbbe
fffff604`fc6175b0 fffff807`a0f503fa : ffffb60b`cc4b11b0 ffffb60b`cc4b11e0 fffff604`fc6177c9 ffffb60b`cc4b1190 : nt!MiValidatePagefilePageHash+0x19a
fffff604`fc617730 fffff807`a0f4f945 : fffff604`00000000 00000000`00000000 fffff604`fc6178e0 00000000`00000000 : nt!MiWaitForInPageComplete+0x2a2
fffff604`fc617830 fffff807`a0ea8b72 : ffff8000`00000000 00007df4`0d754400 00000000`c0033333 00000000`00000001 : nt!MiIssueHardFault+0x2ad
fffff604`fc617930 fffff807`a12b41cb : ffffb60b`c9e00000 00007ffe`574af9c8 00000000`00000005 00000000`00004c24 : nt!MmAccessFault+0x402
fffff604`fc617aa0 00007ffe`574476ef : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x38b
000000a2`c35be938 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`574476ef
SYMBOL_NAME: PAGE_HASH_ERRORS
MODULE_NAME: hardware
IMAGE_NAME: hardware
STACK_COMMAND: .process /r /p 0xffffb60bca6f8140; .thread 0xffffb60bc9e020c0 ; kb
FAILURE_BUCKET_ID: PAGE_HASH_ERRORS_0x1a_39
OS_VERSION: 10.0.26100.1
BUILDLAB_STR: ge_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {d1a10898-8495-4d08-b385-22aea5adadcc}
Followup: MachineOwner
---------
*** Memory manager detected 1 instance(s) of corrupted pagefile page(s) while performing in-page operations.
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133903278239153806
PnpEventInformation: 3
PnpEventInProgress : 0
PnpProblemCode : 24
PnpVetoType : 0
DeviceId : SWD\XvddEnum\XvddRootDevice_Instance
VetoString :