KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffd888d95f03d0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffd888d95f0328, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 3
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-NG9H4F5
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 15
Key : Analysis.Memory.CommitPeak.Mb
Value: 69
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffffd888d95f03d0
BUGCHECK_P3: ffffd888d95f0328
BUGCHECK_P4: 0
TRAP_FRAME: ffffd888d95f03d0 -- (.trap 0xffffd888d95f03d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffa2067d990340 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80512e48b10 rsp=ffffd888d95f0560 rbp=ffffa2067ee95040
r8=0000000000000001 r9=0000000000000002 r10=ffffa2067cdf3f00
r11=ffffb4008bb60180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!KiExitDispatcher+0x160:
fffff805`12e48b10 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffffd888d95f0328 -- (.exr 0xffffd888d95f0328)
ExceptionAddress: fffff80512e48b10 (nt!KiExitDispatcher+0x0000000000000160)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffffd888`d95f00a8 fffff805`12fd32e9 : 00000000`00000139 00000000`00000003 ffffd888`d95f03d0 ffffd888`d95f0328 : nt!KeBugCheckEx
ffffd888`d95f00b0 fffff805`12fd3710 : 00000000`00000000 fffff805`12fc7910 00000000`00000000 ffffa206`7cc40000 : nt!KiBugCheckDispatch+0x69
ffffd888`d95f01f0 fffff805`12fd1aa5 : 00000000`00000000 00000000`00000000 00000000`00000000 ffffd888`d95f0540 : nt!KiFastFailDispatch+0xd0
ffffd888`d95f03d0 fffff805`12e48b10 : 00000000`00000000 ffffd888`d95f0601 ffffb400`8bb60180 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x325
ffffd888`d95f0560 fffff805`12ea597d : ffffa206`7d990338 00000000`00000200 ffffb400`8bb60101 fffff805`1316f06d : nt!KiExitDispatcher+0x160
ffffd888`d95f05c0 fffff805`253d07f8 : 00000000`00000100 ffffa206`9a4bd0a8 00000000`00000001 00000000`00000002 : nt!KeInsertQueueApc+0x14d
ffffd888`d95f0660 00000000`00000100 : ffffa206`9a4bd0a8 00000000`00000001 00000000`00000002 00000000`00000000 : BEDaisy+0x2b07f8
ffffd888`d95f0668 ffffa206`9a4bd0a8 : 00000000`00000001 00000000`00000002 00000000`00000000 00000000`00000000 : 0x100
ffffd888`d95f0670 00000000`00000001 : 00000000`00000002 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffffa206`9a4bd0a8
ffffd888`d95f0678 00000000`00000002 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x1
ffffd888`d95f0680 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`c0000001 : 0x2
SYMBOL_NAME: BEDaisy+2b07f8
MODULE_NAME: BEDaisy
IMAGE_NAME: BEDaisy.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 2b07f8
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_BEDaisy!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {59d8eb10-b2e4-7df6-f6a5-49968226dbb8}
Followup: MachineOwner
---------
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff9e8d663173d0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff9e8d66317328, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 4
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-NG9H4F5
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 9
Key : Analysis.Memory.CommitPeak.Mb
Value: 69
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff9e8d663173d0
BUGCHECK_P3: ffff9e8d66317328
BUGCHECK_P4: 0
TRAP_FRAME: ffff9e8d663173d0 -- (.trap 0xffff9e8d663173d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe18a22990340 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8020b048ad0 rsp=ffff9e8d66317560 rbp=ffffe18a238bb080
r8=0000000000000001 r9=0000000000000002 r10=ffffe18a208e8100
r11=ffffca8028760180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!KiExitDispatcher+0x160:
fffff802`0b048ad0 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff9e8d66317328 -- (.exr 0xffff9e8d66317328)
ExceptionAddress: fffff8020b048ad0 (nt!KiExitDispatcher+0x0000000000000160)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff9e8d`663170a8 fffff802`0b1d30e9 : 00000000`00000139 00000000`00000003 ffff9e8d`663173d0 ffff9e8d`66317328 : nt!KeBugCheckEx
ffff9e8d`663170b0 fffff802`0b1d3510 : 00000000`00000001 00000000`00000000 00000000`00000000 ffffe18a`207d7000 : nt!KiBugCheckDispatch+0x69
ffff9e8d`663171f0 fffff802`0b1d18a5 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff9e8d`66317540 : nt!KiFastFailDispatch+0xd0
ffff9e8d`663173d0 fffff802`0b048ad0 : 00000000`00000000 ffff9e8d`66317601 ffffca80`28760180 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x325
ffff9e8d`66317560 fffff802`0b0a592d : ffffe18a`22990338 00000000`00000200 ffffca80`28760101 fffff802`0b36f06d : nt!KiExitDispatcher+0x160
ffff9e8d`663175c0 fffff802`0cbf07f8 : 00000000`00000100 ffffe18a`3aa5a0a8 00000000`00000001 00000000`00000002 : nt!KeInsertQueueApc+0x14d
ffff9e8d`66317660 00000000`00000100 : ffffe18a`3aa5a0a8 00000000`00000001 00000000`00000002 00000000`00000000 : BEDaisy+0x2b07f8
ffff9e8d`66317668 ffffe18a`3aa5a0a8 : 00000000`00000001 00000000`00000002 00000000`00000000 00000000`00000000 : 0x100
ffff9e8d`66317670 00000000`00000001 : 00000000`00000002 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffffe18a`3aa5a0a8
ffff9e8d`66317678 00000000`00000002 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x1
ffff9e8d`66317680 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff700`00000301 : 0x2
SYMBOL_NAME: BEDaisy+2b07f8
MODULE_NAME: BEDaisy
IMAGE_NAME: BEDaisy.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 2b07f8
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_BEDaisy!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {59d8eb10-b2e4-7df6-f6a5-49968226dbb8}
Followup: MachineOwner
---------
1: kd> lmvm BEDaisy
start end module name
fffff802`0c940000 fffff802`0cbf8000 BEDaisy T (no symbols)
Loaded symbol image file: BEDaisy.sys
Image path: \??\C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
Image name: BEDaisy.sys
Timestamp: Thu Oct 10 23:33:36 2019 (5D9F95A0)
CheckSum: 002BD711
ImageSize: 002B8000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables: