KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff8300caa2ff60, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff8300caa2feb8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
DUMP_TYPE: 2
BUGCHECK_P1: 3
BUGCHECK_P2: ffff8300caa2ff60
BUGCHECK_P3: ffff8300caa2feb8
BUGCHECK_P4: 0
TRAP_FRAME: ffff8300caa2ff60 -- (.trap 0xffff8300caa2ff60)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff890409603c98 rbx=0000000000000000 rcx=0000000000000003
rdx=ffff8904118ab000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80377bf514b rsp=ffff8300caa300f0 rbp=ffff8300caa301f0
r8=ffff890409603c88 r9=ffff890409603c98 r10=ffff890410f4f000
r11=ffff890409602780 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
fffff803`77bf514b ?? ???
Resetting default scope
EXCEPTION_RECORD: ffff8300caa2feb8 -- (.exr 0xffff8300caa2feb8)
ExceptionAddress: fffff80377bf514b
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CUSTOMER_CRASH_COUNT: 1
BUGCHECK_STR: 0x139
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:28.0700
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80377bd32e9 to fffff80377bc14e0
STACK_TEXT:
ffff8300`caa300f0 ffff8300`caa30708 : ffff8300`caa30170 00000000`00000000 00000000`ffffffff ffff8300`caa30110 : 0xfffff803`77bf514b
ffff8300`caa300f8 ffff8300`caa30170 : 00000000`00000000 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 : 0xffff8300`caa30708
ffff8300`caa30100 00000000`00000000 : 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 00000000`00380038 : 0xffff8300`caa30170
STACK_COMMAND: .trap 0xffff8300caa2ff60 ; kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: CORRUPT_MODULELIST_0x139
DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x139
PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST_0x139
FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x139
TARGET_TIME: 2019-12-20T14:23:40.000Z
OSBUILD: 18362
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
ANALYSIS_SESSION_ELAPSED_TIME: 1f
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x139
FAILURE_ID_HASH: {bec1bc00-1c8a-a417-55b2-9f8b67cbb1c5}
Followup: MachineOwner
---------
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffc60b55ee9280, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffc60b55ee91d8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
DUMP_TYPE: 2
BUGCHECK_P1: 3
BUGCHECK_P2: ffffc60b55ee9280
BUGCHECK_P3: ffffc60b55ee91d8
BUGCHECK_P4: 0
TRAP_FRAME: ffffc60b55ee9280 -- (.trap 0xffffc60b55ee9280)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffb58f8e259a50 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffb58f8e259b50 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80268fe24e1 rsp=ffffc60b55ee9410 rbp=0000000000000000
r8=00000000ffffffff r9=7fffb58f85d57400 r10=fffff80268e0a970
r11=ffffccfb38800000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!ExDeleteResourceLite+0x1d7b71:
fffff802`68fe24e1 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffffc60b55ee91d8 -- (.exr 0xffffc60b55ee91d8)
ExceptionAddress: fffff80268fe24e1 (nt!ExDeleteResourceLite+0x00000000001d7b71)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
BUGCHECK_STR: 0x139
PROCESS_NAME: System
CURRENT_IRQL: 2
DEFAULT_BUCKET_ID: FAIL_FAST_CORRUPT_LIST_ENTRY
ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:39.0892
ANALYSIS_VERSION: 10.0.18362.1 x86fre
STACK_TEXT:
ffffc60b`55ee8f58 fffff802`68fd32e9 : 00000000`00000139 00000000`00000003 ffffc60b`55ee9280 ffffc60b`55ee91d8 : nt!KeBugCheckEx
ffffc60b`55ee8f60 fffff802`68fd3710 : ffffc60b`55ee92ff ffffc60b`55ee9230 00000000`00000000 fffff802`68e957ea : nt!KiBugCheckDispatch+0x69
ffffc60b`55ee90a0 fffff802`68fd1aa5 : 00000000`00000000 00000000`00000000 ffffa502`31200100 00000000`00000003 : nt!KiFastFailDispatch+0xd0
ffffc60b`55ee9280 fffff802`68fe24e1 : 00000000`00000705 01000000`00100000 ffffa502`3d7edc90 fffff802`6ba24985 : nt!KiRaiseSecurityCheckFailure+0x325
ffffc60b`55ee9410 fffff802`6ba26ec9 : 00000000`00000745 00000000`00000000 ffffb58f`8e25a910 ffffc60b`55ee98f0 : nt!ExDeleteResourceLite+0x1d7b71
ffffc60b`55ee9460 fffff802`6baefdf4 : 00000000`00000745 ffffb58f`8e25a910 ffffa502`3e0ad660 ffffc60b`55ee98f0 : Ntfs!NtfsFreeNonpagedIndexFcb+0x19
ffffc60b`55ee9490 fffff802`6ba14507 : ffffc60b`55ee98f0 ffffa502`34049800 ffffa502`3e0ad660 ffffb58f`00000000 : Ntfs!NtfsDeleteFcb+0x5c4
ffffc60b`55ee9510 fffff802`6baef4fe : ffffc60b`55ee98f0 ffffb58f`85d57180 ffffa502`3e0ad660 ffffa502`3e0adb78 : Ntfs!NtfsTeardownFromLcb+0x267
ffffc60b`55ee95b0 fffff802`6ba1892a : ffffc60b`55ee98f0 ffffc60b`55ee96b1 00000000`00000000 ffffc60b`55ee98f0 : Ntfs!NtfsTeardownStructures+0xee
ffffc60b`55ee9630 fffff802`6bb10cec : ffffc60b`55ee9700 ffffa502`3e0ad660 ffffc60b`55ee98f0 ffffc60b`55ee98f0 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffffc60b`55ee9670 fffff802`6bb0fc31 : ffffc60b`55ee98f0 ffffa502`3e0ad7c0 ffffa502`3e0ad660 ffffb58f`85d57180 : Ntfs!NtfsCommonClose+0x45c
ffffc60b`55ee9750 fffff802`6bb454d8 : 00000000`0000001c fffff802`6938f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffffc60b`55ee98b0 fffff802`68ebd095 : ffffb58f`850abcc0 ffffb58f`850abc00 ffffb58f`850abc00 ffffb58f`8ab106c0 : Ntfs!NtfsFspClose+0x88
ffffc60b`55ee9b70 fffff802`68f2a7a5 : ffffb58f`8c815040 00000000`00000080 ffffb58f`8506c080 005c003a`0043003b : nt!ExpWorkerThread+0x105
ffffc60b`55ee9c10 fffff802`68fc8b2a : fffff802`64862180 ffffb58f`8c815040 fffff802`68f2a750 0043003b`005c0074 : nt!PspSystemThreadStartup+0x55
ffffc60b`55ee9c60 00000000`00000000 : ffffc60b`55eea000 ffffc60b`55ee4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 17fa4a8e3fd9e775c947d1d7121599e329fc6a6b
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f52d99ada7558168a3abfd0cf619a361dd14b77e
THREAD_SHA1_HASH_MOD: baf72ea6dc105da5d0f2fb8a45027cf1bace7247
FOLLOWUP_NAME: memory_corruption
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
PRIMARY_PROBLEM_CLASS: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
TARGET_TIME: 2019-12-13T17:52:33.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 57b8
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x139_3_corrupt_list_entry_image_memory_corruption
FAILURE_ID_HASH: {6b711939-e5de-38cb-287e-eb7d8c867a90}
Followup: memory_corruption
---------
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffb909486fdef0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001589fcf0000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
ERROR_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text>
EXCEPTION_CODE_STR: c000021a
EXCEPTION_PARAMETER1: ffffb909486fdef0
EXCEPTION_PARAMETER2: ffffffffc0000428
EXCEPTION_PARAMETER3: 0000000000000000
EXCEPTION_PARAMETER4: 1589fcf0000
DUMP_TYPE: 2
BUGCHECK_P1: ffffb909486fdef0
BUGCHECK_P2: ffffffffc0000428
BUGCHECK_P3: 0
BUGCHECK_P4: 1589fcf0000
PROCESS_NAME: smss.exe
ADDITIONAL_DEBUG_TEXT: initial session process or
BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428
IMAGE_NAME: ntkrnlmp.exe
MODULE_NAME: nt
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:30.0788
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff806039aeaea to fffff806035c14e0
STACK_TEXT:
ffffe081`5d1e85a8 fffff806`039aeaea : 00000000`0000004c 00000000`c000021a ffffe081`5d3fe3f8 ffff968f`5a067690 : nt!KeBugCheckEx
ffffe081`5d1e85b0 fffff806`03999fad : 00000000`00000000 ffffe081`5d1e8670 00000000`00000000 ffffe081`5d1e8670 : nt!PopGracefulShutdown+0x29a
ffffe081`5d1e85f0 fffff806`0399f14c : ffffb909`42f66001 fffff806`00000006 00000000`00000004 ffffb909`4729e030 : nt!PopTransitionSystemPowerStateEx+0x11f1
ffffe081`5d1e86b0 fffff806`035d2d18 : 00000000`00000000 fffff806`0344109b 00000000`00000010 00000000`00000086 : nt!NtSetSystemPowerState+0x4c
ffffe081`5d1e8890 fffff806`035c5320 : fffff806`03b9ca3d 00000000`c0000004 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffffe081`5d1e8a28 fffff806`03b9ca3d : 00000000`c0000004 00000000`00000000 00000000`00000000 fffff806`03845820 : nt!KiServiceLinkage
ffffe081`5d1e8a30 fffff806`03b22269 : ffff968f`56285080 fffff806`034bd54c fffff806`08c1e7e0 ffff968f`00000000 : nt!PopIssueActionRequest+0x7a6b1
ffffe081`5d1e8ad0 fffff806`0352890f : 00000000`00000001 00000000`00000002 00000000`00000000 fffff806`03845800 : nt!PopPolicyWorkerAction+0x79
ffffe081`5d1e8b40 fffff806`034bd095 : ffff968f`00000001 ffff968f`56285080 fffff806`03528880 ffff968f`563139e0 : nt!PopPolicyWorkerThread+0x8f
ffffe081`5d1e8b70 fffff806`0352a7a5 : ffff968f`56285080 00000000`00000080 ffff968f`5626c080 00000404`b59bbfff : nt!ExpWorkerThread+0x105
ffffe081`5d1e8c10 fffff806`035c8b2a : ffffcf80`9f480180 ffff968f`56285080 fffff806`0352a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffe081`5d1e8c60 00000000`00000000 : ffffe081`5d1e9000 ffffe081`5d1e3000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 53fc5ecb280b3e5cc6b5dde02f8439c4d5c2f83b
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e7c93c1aa367bf54af0e27c579d634451cfabf2e
THREAD_SHA1_HASH_MOD: dc844b1b94baa204d070855e43bbbd27eee98b94
FOLLOWUP_IP:
nt!PopTransitionSystemPowerStateEx+11f1
fffff806`03999fad cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11f1
FOLLOWUP_NAME: MachineOwner
DEBUG_FLR_IMAGE_TIMESTAMP: 12dcb470
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 11f1
FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
PRIMARY_PROBLEM_CLASS: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
TARGET_TIME: 2019-12-22T14:45:57.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 4872
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc000021a_smpdestroycontrolblock_smss.exe_terminated_c0000428_nt!poptransitionsystempowerstateex
FAILURE_ID_HASH: {11c026a4-042b-4c24-02dc-2da456397475}
Followup: MachineOwner
---------
BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 0000000000000046, Attempt to free an invalid pool address
Arg2: 0000000000010000, Starting address
Arg3: 0000000000000000, 0
Arg4: 0000000000000000, 0
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
DUMP_TYPE: 2
BUGCHECK_P1: 46
BUGCHECK_P2: 10000
BUGCHECK_P3: 0
BUGCHECK_P4: 0
FAULTING_IP:
Ntfs!EfsCloseEncryptOnCloseFile+41
fffff803`3bc59d71 48832600 and qword ptr [rsi],0
BUGCHECK_STR: 0xc2_46
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: Monitor.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:43.0532
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8033851ac63 to fffff803383c14e0
STACK_TEXT:
ffffb604`f3c75cf8 fffff803`3851ac63 : 00000000`000000c2 00000000`00000046 00000000`00010000 00000000`00000000 : nt!KeBugCheckEx
ffffb604`f3c75d00 fffff803`3851acd8 : 00000000`00000016 00000000`00000000 00000000`00010000 fffff803`3866e118 : nt!RtlpHeapHandleError+0x2b
ffffb604`f3c75d40 fffff803`3851a901 : ffffb604`f3c75e10 fffff803`3866e118 00000000`00000000 00000008`00000100 : nt!RtlpHpHeapHandleError+0x58
ffffb604`f3c75d70 fffff803`382ea787 : ffffb604`f3c75e10 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpLogHeapFailure+0x45
ffffb604`f3c75da0 fffff803`382ea700 : ffffb604`f3c75ed0 ffffb604`f3c75f70 00000000`00000000 00000000`00000000 : nt!RtlpHpVaMgrCtxQuery+0x4b
ffffb604`f3c75de0 fffff803`38246389 : 00000000`00000000 00000000`00010000 a2e64ead`a2e64ead 00000000`00000000 : nt!RtlpHpQueryVA+0x54
ffffb604`f3c75e40 fffff803`3856f0a9 : 00000000`00000705 00000000`00000000 ffffe306`299be1c8 fffff803`3829e930 : nt!ExFreeHeapPool+0x809
ffffb604`f3c75f60 fffff803`3bc59d71 : 00000000`00000200 00000000`00000002 ffffe306`299be458 00000000`00000000 : nt!ExFreePool+0x9
ffffb604`f3c75f90 fffff803`3bb20a68 : ffffe306`299be170 00000000`00000000 00000000`00000000 ffffe306`299be458 : Ntfs!EfsCloseEncryptOnCloseFile+0x41
ffffb604`f3c75fc0 fffff803`3bb1ab9d : 00000000`00000000 00000000`00000258 00000000`00000000 ffffb604`f3c76480 : Ntfs!NtfsCommonCleanup+0x5a58
ffffb604`f3c76410 fffff803`38231f79 : ffffbb85`d100b010 fffff803`3af145a0 ffffbb85`d1b943f8 ffffbb85`d10b2000 : Ntfs!NtfsFsdCleanup+0x1ad
ffffb604`f3c76760 fffff803`3af155de : ffffbb85`d1b94010 ffffb604`f3c76840 ffffbb85`d1b94010 ffffb604`f3c76850 : nt!IofCallDriver+0x59
ffffb604`f3c767a0 fffff803`3af13f16 : ffffb604`f3c76840 00000000`00000001 00000000`00000001 ffffbb85`d10b2080 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffb604`f3c76820 fffff803`38231f79 : ffffbb85`d484f6c0 fffff803`38231e5d ffffbb85`ca6ce6c0 ffffb604`f3c76a39 : FLTMGR!FltpDispatch+0xb6
ffffb604`f3c76880 fffff803`387e42b8 : 00000000`00000000 ffffbb85`d484f6c0 00000000`00000000 ffffbb85`d1b94010 : nt!IofCallDriver+0x59
ffffb604`f3c768c0 fffff803`387ec408 : 00000000`00000000 00000000`00000001 ffffbb85`00000000 00000000`00007ffd : nt!IopCloseFile+0x188
ffffb604`f3c76950 fffff803`387f174e : 00000000`00000b80 00000000`00990000 00000000`00000000 fffff803`387c76fa : nt!ObCloseHandleTableEntry+0x278
ffffb604`f3c76a90 fffff803`383d2d18 : ffffbb85`d0a1a080 00007ffe`17ba4901 ffffb604`f3c76b80 ffffbb85`d10b2080 : nt!NtClose+0xde
ffffb604`f3c76b00 00000000`777e1cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000000`0009eec8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777e1cbc
THREAD_SHA1_HASH_MOD_FUNC: 4523f3cab0a62567943bb72de2e1ab2b13c58b95
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: df4d630fd6f156ec2609f83d4dfc091a58316b09
THREAD_SHA1_HASH_MOD: 13371c36d8e7d2598a30c6397adec97d20874fdc
FOLLOWUP_IP:
Ntfs!EfsCloseEncryptOnCloseFile+41
fffff803`3bc59d71 48832600 and qword ptr [rsi],0
FAULT_INSTR_CODE: 268348
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: Ntfs!EfsCloseEncryptOnCloseFile+41
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 41
FAILURE_BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
PRIMARY_PROBLEM_CLASS: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
TARGET_TIME: 2019-12-13T12:27:18.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 573b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc2_46_ntfs!efscloseencryptonclosefile
FAILURE_ID_HASH: {6c0dbbce-3bf4-6674-181d-24e090eaf7df}
Followup: MachineOwner
---------