KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: fffff88399c3f9c0, Address of the trap frame for the exception that caused the BugCheck
Arg3: fffff88399c3f918, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1077
Key : Analysis.Elapsed.mSec
Value: 3775
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 296
Key : Analysis.Init.Elapsed.mSec
Value: 1665
Key : Analysis.Memory.CommitPeak.Mb
Value: 86
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : FailFast.Name
Value: CORRUPT_LIST_ENTRY
Key : FailFast.Type
Value: 3
Key : Failure.Bucket
Value: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiProcessExpiredTimerList
Key : Failure.Hash
Value: {9db7945b-255d-24a1-9f2c-82344e883ab8}
Key : WER.OS.Branch
Value: ni_release
Key : WER.OS.Version
Value: 10.0.22621.1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: fffff88399c3f9c0
BUGCHECK_P3: fffff88399c3f918
BUGCHECK_P4: 0
FILE_IN_CAB: 081124-6859-01.dmp
FAULTING_THREAD: ffffcc8a704f8080
TRAP_FRAME: fffff88399c3f9c0 -- (.trap 0xfffff88399c3f9c0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffcc8a68a76e78 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8010705098e rsp=fffff88399c3fb50 rbp=ffffcc8a5f411c00
r8=0000000000000001 r9=fffff88399c3f830 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
nt!KiProcessThreadWaitList+0x9e:
fffff801`0705098e cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: fffff88399c3f918 -- (.exr 0xfffff88399c3f918)
ExceptionAddress: fffff8010705098e (nt!KiProcessThreadWaitList+0x000000000000009e)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: Cities.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
DPC_STACK_BASE: FFFFF88399C3FFB0
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
fffff883`99c3f698 fffff801`0722b729 : 00000000`00000139 00000000`00000003 fffff883`99c3f9c0 fffff883`99c3f918 : nt!KeBugCheckEx
fffff883`99c3f6a0 fffff801`0722bcf2 : 00000000`00000000 00000002`00000002 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff883`99c3f7e0 fffff801`072299db : fffff801`046ac180 fffff801`07b4b040 ffffcc8a`67746080 ffffcc8a`67746080 : nt!KiFastFailDispatch+0xb2
fffff883`99c3f9c0 fffff801`0705098e : 00000000`00000000 ffffcc8a`6bcd2158 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x35b
fffff883`99c3fb50 fffff801`07051aa3 : ffffcc8a`00000003 00000000`00000001 fffff883`00000000 00000000`00000002 : nt!KiProcessThreadWaitList+0x9e
fffff883`99c3fbd0 fffff801`07052cd9 : 00000001`00000148 ffffba81`d8423180 00000000`00000001 fffff801`046b33c8 : nt!KiProcessExpiredTimerList+0x343
fffff883`99c3fd00 fffff801`0721f095 : 00000000`00000000 00000000`00000000 ffffba81`d8423180 00000000`00000000 : nt!KiRetireDpcList+0xaf9
fffff883`99c3ffb0 fffff801`0721f03f : fffff883`a14a7949 fffff801`07055e75 00000000`00000000 00000000`00000000 : nt!KxSwapStacksAndRetireDpcList+0x5
fffff883`a14a78b0 fffff801`07055e75 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPlatformSwapStacksAndCallReturn
fffff883`a14a78c0 fffff801`0721e7cb : 00000000`00000000 00000000`005bf7f0 00000000`005bf8f0 00000000`00000000 : nt!KiDispatchInterrupt+0xd5
fffff883`a14a79b0 fffff801`07218371 : 00000000`c8ef7340 00000000`027b34c0 00000000`00000000 ffffcc8a`00000000 : nt!KiDpcInterruptBypass+0x1b
fffff883`a14a79e0 00007ff7`4861b3c4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiInterruptDispatchNoLockNoEtw+0xb1
00000000`005bf920 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff7`4861b3c4
SYMBOL_NAME: nt!KiProcessExpiredTimerList+343
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.22621.3958
STACK_COMMAND: .process /r /p 0xffffcc8a730320c0; .thread 0xffffcc8a704f8080 ; kb
BUCKET_ID_FUNC_OFFSET: 343
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiProcessExpiredTimerList
OS_VERSION: 10.0.22621.1
BUILDLAB_STR: ni_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {9db7945b-255d-24a1-9f2c-82344e883ab8}
Followup: MachineOwner
---------
[SMBIOS Data Tables v3.0]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 4298 bytes]
[BIOS Information (Type 0) - Length 24 - Handle 0000h]
Vendor American Megatrends Inc.
BIOS Version 3004
BIOS Starting Address Segment f000
BIOS Release Date 07/12/2021
BIOS ROM Size 1000000
BIOS Characteristics
07: - PCI Supported
10: - APM Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
27: - Keyboard Services Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Enable Targeted Content Distribution
11: - UEFI Specification Supported
BIOS Major Revision 5
BIOS Minor Revision 12
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer System manufacturer
Product Name System Product Name
Version System Version
Serial Number System Serial Number
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber SKU
Family To be filled by O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer ASUSTeK COMPUTER INC.
Product ROG STRIX Z370-F GAMING
Version Rev X.0x
Serial Number 180117812701670
Asset Tag
Feature Flags 09h
00: - Motherboard
03: - Replaceable
Location Default string
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
Manufacturer Default string
Chassis Type Desktop
Version Default string
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 0
Contained Element Size 3
[Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
Note: The On Board Device Information (Type 10) struct is obsolete as of SMBIOs spec v2.6 Number of Devices 1
01: Type Video [enabled]
01: Description To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0027h]
Number of Strings 8
1 Default string
2 Default string
3 DYORAK
4 Default string
5 FFFFFFFFFFFFF
6 FFFFFFFFFFFFF
7 FFFFFFFFFFFFF
8 Default string
[System Configuration Options (Type 12) - Length 5 - Handle 0028h]
[ (Type 256) - Length 32 - Handle 003fh]
[ (Type 256) - Length 11 - Handle 0040h]
[ (Type 256) - Length 11 - Handle 0041h]
[ (Type 256) - Length 11 - Handle 0042h]
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: ffffcd640ffb0825, Address of the instruction which caused the BugCheck
Arg3: ffff960db8fb6b50, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
*** WARNING: Check Image - Checksum mismatch - Dump: 0x14371, File: 0x14467 - C:\ProgramData\Dbg\sym\WIN32KSGD.SYS\C2E961BBc000\WIN32KSGD.SYS
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1296
Key : Analysis.Elapsed.mSec
Value: 15010
Key : Analysis.IO.Other.Mb
Value: 1
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 9
Key : Analysis.Init.CPU.mSec
Value: 312
Key : Analysis.Init.Elapsed.mSec
Value: 710
Key : Analysis.Memory.CommitPeak.Mb
Value: 103
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: AV_win32kfull!StoreQMessage
Key : Failure.Hash
Value: {12d45148-6af6-e881-2cd0-6ef33ce8ca01}
Key : WER.OS.Branch
Value: ni_release
Key : WER.OS.Version
Value: 10.0.22621.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: ffffcd640ffb0825
BUGCHECK_P3: ffff960db8fb6b50
BUGCHECK_P4: 0
FILE_IN_CAB: 081224-6906-01.dmp
FAULTING_THREAD: ffff808e666800c0
CONTEXT: ffff960db8fb6b50 -- (.cxr 0xffff960db8fb6b50)
rax=0000000000000000 rbx=ffffbd0f67823710 rcx=ffffbd0f67823710
rdx=fffff806b082a930 rsi=ffffbd0f579756a0 rdi=0000000000000000
rip=ffffcd640ffb0825 rsp=ffff960db8fb7578 rbp=ffff960db8fb7a60
r8=0000000000000113 r9=0000000000000000 r10=fffff806b082a930
r11=ffff960db8fb7570 r12=0000000000000000 r13=ffffbd0f579756a0
r14=ffffbd0f5d198518 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
win32kfull!StoreQMessage+0x5:
ffffcd64`0ffb0825 48896c2410 mov qword ptr [rsp+10h],rbp ss:0018:ffff960d`b8fb7588=ffff960db8fb7a60
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: NVIDIA Share.exe
STACK_TEXT:
ffff960d`b8fb7578 ffffcd64`0ffd816d : ffffbd0f`67823710 ffff960d`b8fb7a60 ffffbd0f`579756a0 ffffbd0f`579759c8 : win32kfull!StoreQMessage+0x5
ffff960d`b8fb7580 ffffcd64`0ffd6eba : 00000000`00000000 00000000`00000000 00000000`00000000 fffff806`b23b12c9 : win32kfull!xxxRealInternalGetMessage+0x11ad
ffff960d`b8fb7870 ffffcd64`108f802a : ffff808e`666800c0 00000003`1913fb98 ffff960d`b8fb7988 00000000`00000000 : win32kfull!NtUserPeekMessage+0xaa
ffff960d`b8fb7920 fffff806`7e22ae05 : 00000003`1913f000 ffffbd0f`57975828 00000000`00000000 00000003`1913f101 : win32k!NtUserPeekMessage+0x2a
ffff960d`b8fb7970 00007ff8`3cf414d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000003`1913fb78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`3cf414d4
SYMBOL_NAME: win32kfull!StoreQMessage+5
MODULE_NAME: win32kfull
IMAGE_NAME: win32kfull.sys
IMAGE_VERSION: 10.0.22621.4034
STACK_COMMAND: .cxr 0xffff960db8fb6b50 ; kb
BUCKET_ID_FUNC_OFFSET: 5
FAILURE_BUCKET_ID: AV_win32kfull!StoreQMessage
OS_VERSION: 10.0.22621.1
BUILDLAB_STR: ni_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {12d45148-6af6-e881-2cd0-6ef33ce8ca01}
Followup: MachineOwner
---------