KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff8300caa2ff60, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff8300caa2feb8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
DUMP_TYPE: 2
BUGCHECK_P1: 3
BUGCHECK_P2: ffff8300caa2ff60
BUGCHECK_P3: ffff8300caa2feb8
BUGCHECK_P4: 0
TRAP_FRAME: ffff8300caa2ff60 -- (.trap 0xffff8300caa2ff60)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff890409603c98 rbx=0000000000000000 rcx=0000000000000003
rdx=ffff8904118ab000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80377bf514b rsp=ffff8300caa300f0 rbp=ffff8300caa301f0
r8=ffff890409603c88 r9=ffff890409603c98 r10=ffff890410f4f000
r11=ffff890409602780 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
fffff803`77bf514b ?? ???
Resetting default scope
EXCEPTION_RECORD: ffff8300caa2feb8 -- (.exr 0xffff8300caa2feb8)
ExceptionAddress: fffff80377bf514b
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CUSTOMER_CRASH_COUNT: 1
BUGCHECK_STR: 0x139
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:28.0700
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80377bd32e9 to fffff80377bc14e0
STACK_TEXT:
ffff8300`caa300f0 ffff8300`caa30708 : ffff8300`caa30170 00000000`00000000 00000000`ffffffff ffff8300`caa30110 : 0xfffff803`77bf514b
ffff8300`caa300f8 ffff8300`caa30170 : 00000000`00000000 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 : 0xffff8300`caa30708
ffff8300`caa30100 00000000`00000000 : 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 00000000`00380038 : 0xffff8300`caa30170
STACK_COMMAND: .trap 0xffff8300caa2ff60 ; kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: CORRUPT_MODULELIST_0x139
DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x139
PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST_0x139
FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x139
TARGET_TIME: 2019-12-20T14:23:40.000Z
OSBUILD: 18362
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
ANALYSIS_SESSION_ELAPSED_TIME: 1f
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x139
FAILURE_ID_HASH: {bec1bc00-1c8a-a417-55b2-9f8b67cbb1c5}
Followup: MachineOwner
---------
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffc60b55ee9280, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffc60b55ee91d8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
DUMP_TYPE: 2
BUGCHECK_P1: 3
BUGCHECK_P2: ffffc60b55ee9280
BUGCHECK_P3: ffffc60b55ee91d8
BUGCHECK_P4: 0
TRAP_FRAME: ffffc60b55ee9280 -- (.trap 0xffffc60b55ee9280)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffb58f8e259a50 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffb58f8e259b50 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80268fe24e1 rsp=ffffc60b55ee9410 rbp=0000000000000000
r8=00000000ffffffff r9=7fffb58f85d57400 r10=fffff80268e0a970
r11=ffffccfb38800000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!ExDeleteResourceLite+0x1d7b71:
fffff802`68fe24e1 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffffc60b55ee91d8 -- (.exr 0xffffc60b55ee91d8)
ExceptionAddress: fffff80268fe24e1 (nt!ExDeleteResourceLite+0x00000000001d7b71)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
BUGCHECK_STR: 0x139
PROCESS_NAME: System
CURRENT_IRQL: 2
DEFAULT_BUCKET_ID: FAIL_FAST_CORRUPT_LIST_ENTRY
ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:39.0892
ANALYSIS_VERSION: 10.0.18362.1 x86fre
STACK_TEXT:
ffffc60b`55ee8f58 fffff802`68fd32e9 : 00000000`00000139 00000000`00000003 ffffc60b`55ee9280 ffffc60b`55ee91d8 : nt!KeBugCheckEx
ffffc60b`55ee8f60 fffff802`68fd3710 : ffffc60b`55ee92ff ffffc60b`55ee9230 00000000`00000000 fffff802`68e957ea : nt!KiBugCheckDispatch+0x69
ffffc60b`55ee90a0 fffff802`68fd1aa5 : 00000000`00000000 00000000`00000000 ffffa502`31200100 00000000`00000003 : nt!KiFastFailDispatch+0xd0
ffffc60b`55ee9280 fffff802`68fe24e1 : 00000000`00000705 01000000`00100000 ffffa502`3d7edc90 fffff802`6ba24985 : nt!KiRaiseSecurityCheckFailure+0x325
ffffc60b`55ee9410 fffff802`6ba26ec9 : 00000000`00000745 00000000`00000000 ffffb58f`8e25a910 ffffc60b`55ee98f0 : nt!ExDeleteResourceLite+0x1d7b71
ffffc60b`55ee9460 fffff802`6baefdf4 : 00000000`00000745 ffffb58f`8e25a910 ffffa502`3e0ad660 ffffc60b`55ee98f0 : Ntfs!NtfsFreeNonpagedIndexFcb+0x19
ffffc60b`55ee9490 fffff802`6ba14507 : ffffc60b`55ee98f0 ffffa502`34049800 ffffa502`3e0ad660 ffffb58f`00000000 : Ntfs!NtfsDeleteFcb+0x5c4
ffffc60b`55ee9510 fffff802`6baef4fe : ffffc60b`55ee98f0 ffffb58f`85d57180 ffffa502`3e0ad660 ffffa502`3e0adb78 : Ntfs!NtfsTeardownFromLcb+0x267
ffffc60b`55ee95b0 fffff802`6ba1892a : ffffc60b`55ee98f0 ffffc60b`55ee96b1 00000000`00000000 ffffc60b`55ee98f0 : Ntfs!NtfsTeardownStructures+0xee
ffffc60b`55ee9630 fffff802`6bb10cec : ffffc60b`55ee9700 ffffa502`3e0ad660 ffffc60b`55ee98f0 ffffc60b`55ee98f0 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffffc60b`55ee9670 fffff802`6bb0fc31 : ffffc60b`55ee98f0 ffffa502`3e0ad7c0 ffffa502`3e0ad660 ffffb58f`85d57180 : Ntfs!NtfsCommonClose+0x45c
ffffc60b`55ee9750 fffff802`6bb454d8 : 00000000`0000001c fffff802`6938f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffffc60b`55ee98b0 fffff802`68ebd095 : ffffb58f`850abcc0 ffffb58f`850abc00 ffffb58f`850abc00 ffffb58f`8ab106c0 : Ntfs!NtfsFspClose+0x88
ffffc60b`55ee9b70 fffff802`68f2a7a5 : ffffb58f`8c815040 00000000`00000080 ffffb58f`8506c080 005c003a`0043003b : nt!ExpWorkerThread+0x105
ffffc60b`55ee9c10 fffff802`68fc8b2a : fffff802`64862180 ffffb58f`8c815040 fffff802`68f2a750 0043003b`005c0074 : nt!PspSystemThreadStartup+0x55
ffffc60b`55ee9c60 00000000`00000000 : ffffc60b`55eea000 ffffc60b`55ee4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 17fa4a8e3fd9e775c947d1d7121599e329fc6a6b
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f52d99ada7558168a3abfd0cf619a361dd14b77e
THREAD_SHA1_HASH_MOD: baf72ea6dc105da5d0f2fb8a45027cf1bace7247
FOLLOWUP_NAME: memory_corruption
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
PRIMARY_PROBLEM_CLASS: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption
TARGET_TIME: 2019-12-13T17:52:33.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 57b8
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x139_3_corrupt_list_entry_image_memory_corruption
FAILURE_ID_HASH: {6b711939-e5de-38cb-287e-eb7d8c867a90}
Followup: memory_corruption
---------
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffb909486fdef0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001589fcf0000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
ERROR_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text>
EXCEPTION_CODE_STR: c000021a
EXCEPTION_PARAMETER1: ffffb909486fdef0
EXCEPTION_PARAMETER2: ffffffffc0000428
EXCEPTION_PARAMETER3: 0000000000000000
EXCEPTION_PARAMETER4: 1589fcf0000
DUMP_TYPE: 2
BUGCHECK_P1: ffffb909486fdef0
BUGCHECK_P2: ffffffffc0000428
BUGCHECK_P3: 0
BUGCHECK_P4: 1589fcf0000
PROCESS_NAME: smss.exe
ADDITIONAL_DEBUG_TEXT: initial session process or
BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428
IMAGE_NAME: ntkrnlmp.exe
MODULE_NAME: nt
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:30.0788
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff806039aeaea to fffff806035c14e0
STACK_TEXT:
ffffe081`5d1e85a8 fffff806`039aeaea : 00000000`0000004c 00000000`c000021a ffffe081`5d3fe3f8 ffff968f`5a067690 : nt!KeBugCheckEx
ffffe081`5d1e85b0 fffff806`03999fad : 00000000`00000000 ffffe081`5d1e8670 00000000`00000000 ffffe081`5d1e8670 : nt!PopGracefulShutdown+0x29a
ffffe081`5d1e85f0 fffff806`0399f14c : ffffb909`42f66001 fffff806`00000006 00000000`00000004 ffffb909`4729e030 : nt!PopTransitionSystemPowerStateEx+0x11f1
ffffe081`5d1e86b0 fffff806`035d2d18 : 00000000`00000000 fffff806`0344109b 00000000`00000010 00000000`00000086 : nt!NtSetSystemPowerState+0x4c
ffffe081`5d1e8890 fffff806`035c5320 : fffff806`03b9ca3d 00000000`c0000004 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffffe081`5d1e8a28 fffff806`03b9ca3d : 00000000`c0000004 00000000`00000000 00000000`00000000 fffff806`03845820 : nt!KiServiceLinkage
ffffe081`5d1e8a30 fffff806`03b22269 : ffff968f`56285080 fffff806`034bd54c fffff806`08c1e7e0 ffff968f`00000000 : nt!PopIssueActionRequest+0x7a6b1
ffffe081`5d1e8ad0 fffff806`0352890f : 00000000`00000001 00000000`00000002 00000000`00000000 fffff806`03845800 : nt!PopPolicyWorkerAction+0x79
ffffe081`5d1e8b40 fffff806`034bd095 : ffff968f`00000001 ffff968f`56285080 fffff806`03528880 ffff968f`563139e0 : nt!PopPolicyWorkerThread+0x8f
ffffe081`5d1e8b70 fffff806`0352a7a5 : ffff968f`56285080 00000000`00000080 ffff968f`5626c080 00000404`b59bbfff : nt!ExpWorkerThread+0x105
ffffe081`5d1e8c10 fffff806`035c8b2a : ffffcf80`9f480180 ffff968f`56285080 fffff806`0352a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffe081`5d1e8c60 00000000`00000000 : ffffe081`5d1e9000 ffffe081`5d1e3000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 53fc5ecb280b3e5cc6b5dde02f8439c4d5c2f83b
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e7c93c1aa367bf54af0e27c579d634451cfabf2e
THREAD_SHA1_HASH_MOD: dc844b1b94baa204d070855e43bbbd27eee98b94
FOLLOWUP_IP:
nt!PopTransitionSystemPowerStateEx+11f1
fffff806`03999fad cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11f1
FOLLOWUP_NAME: MachineOwner
DEBUG_FLR_IMAGE_TIMESTAMP: 12dcb470
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 11f1
FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
PRIMARY_PROBLEM_CLASS: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx
TARGET_TIME: 2019-12-22T14:45:57.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 4872
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc000021a_smpdestroycontrolblock_smss.exe_terminated_c0000428_nt!poptransitionsystempowerstateex
FAILURE_ID_HASH: {11c026a4-042b-4c24-02dc-2da456397475}
Followup: MachineOwner
---------
BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 0000000000000046, Attempt to free an invalid pool address
Arg2: 0000000000010000, Starting address
Arg3: 0000000000000000, 0
Arg4: 0000000000000000, 0
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: To be filled by O.E.M.
SYSTEM_SKU: To be filled by O.E.M.
SYSTEM_VERSION: To be filled by O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F2
BIOS_DATE: 08/30/2013
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: H61M-DS2 4.0
BASEBOARD_VERSION: To be filled by O.E.M.
DUMP_TYPE: 2
BUGCHECK_P1: 46
BUGCHECK_P2: 10000
BUGCHECK_P3: 0
BUGCHECK_P4: 0
FAULTING_IP:
Ntfs!EfsCloseEncryptOnCloseFile+41
fffff803`3bc59d71 48832600 and qword ptr [rsi],0
BUGCHECK_STR: 0xc2_46
CPU_COUNT: 4
CPU_MHZ: d40
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: Monitor.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-22-2019 18:09:43.0532
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8033851ac63 to fffff803383c14e0
STACK_TEXT:
ffffb604`f3c75cf8 fffff803`3851ac63 : 00000000`000000c2 00000000`00000046 00000000`00010000 00000000`00000000 : nt!KeBugCheckEx
ffffb604`f3c75d00 fffff803`3851acd8 : 00000000`00000016 00000000`00000000 00000000`00010000 fffff803`3866e118 : nt!RtlpHeapHandleError+0x2b
ffffb604`f3c75d40 fffff803`3851a901 : ffffb604`f3c75e10 fffff803`3866e118 00000000`00000000 00000008`00000100 : nt!RtlpHpHeapHandleError+0x58
ffffb604`f3c75d70 fffff803`382ea787 : ffffb604`f3c75e10 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpLogHeapFailure+0x45
ffffb604`f3c75da0 fffff803`382ea700 : ffffb604`f3c75ed0 ffffb604`f3c75f70 00000000`00000000 00000000`00000000 : nt!RtlpHpVaMgrCtxQuery+0x4b
ffffb604`f3c75de0 fffff803`38246389 : 00000000`00000000 00000000`00010000 a2e64ead`a2e64ead 00000000`00000000 : nt!RtlpHpQueryVA+0x54
ffffb604`f3c75e40 fffff803`3856f0a9 : 00000000`00000705 00000000`00000000 ffffe306`299be1c8 fffff803`3829e930 : nt!ExFreeHeapPool+0x809
ffffb604`f3c75f60 fffff803`3bc59d71 : 00000000`00000200 00000000`00000002 ffffe306`299be458 00000000`00000000 : nt!ExFreePool+0x9
ffffb604`f3c75f90 fffff803`3bb20a68 : ffffe306`299be170 00000000`00000000 00000000`00000000 ffffe306`299be458 : Ntfs!EfsCloseEncryptOnCloseFile+0x41
ffffb604`f3c75fc0 fffff803`3bb1ab9d : 00000000`00000000 00000000`00000258 00000000`00000000 ffffb604`f3c76480 : Ntfs!NtfsCommonCleanup+0x5a58
ffffb604`f3c76410 fffff803`38231f79 : ffffbb85`d100b010 fffff803`3af145a0 ffffbb85`d1b943f8 ffffbb85`d10b2000 : Ntfs!NtfsFsdCleanup+0x1ad
ffffb604`f3c76760 fffff803`3af155de : ffffbb85`d1b94010 ffffb604`f3c76840 ffffbb85`d1b94010 ffffb604`f3c76850 : nt!IofCallDriver+0x59
ffffb604`f3c767a0 fffff803`3af13f16 : ffffb604`f3c76840 00000000`00000001 00000000`00000001 ffffbb85`d10b2080 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffb604`f3c76820 fffff803`38231f79 : ffffbb85`d484f6c0 fffff803`38231e5d ffffbb85`ca6ce6c0 ffffb604`f3c76a39 : FLTMGR!FltpDispatch+0xb6
ffffb604`f3c76880 fffff803`387e42b8 : 00000000`00000000 ffffbb85`d484f6c0 00000000`00000000 ffffbb85`d1b94010 : nt!IofCallDriver+0x59
ffffb604`f3c768c0 fffff803`387ec408 : 00000000`00000000 00000000`00000001 ffffbb85`00000000 00000000`00007ffd : nt!IopCloseFile+0x188
ffffb604`f3c76950 fffff803`387f174e : 00000000`00000b80 00000000`00990000 00000000`00000000 fffff803`387c76fa : nt!ObCloseHandleTableEntry+0x278
ffffb604`f3c76a90 fffff803`383d2d18 : ffffbb85`d0a1a080 00007ffe`17ba4901 ffffb604`f3c76b80 ffffbb85`d10b2080 : nt!NtClose+0xde
ffffb604`f3c76b00 00000000`777e1cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000000`0009eec8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777e1cbc
THREAD_SHA1_HASH_MOD_FUNC: 4523f3cab0a62567943bb72de2e1ab2b13c58b95
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: df4d630fd6f156ec2609f83d4dfc091a58316b09
THREAD_SHA1_HASH_MOD: 13371c36d8e7d2598a30c6397adec97d20874fdc
FOLLOWUP_IP:
Ntfs!EfsCloseEncryptOnCloseFile+41
fffff803`3bc59d71 48832600 and qword ptr [rsi],0
FAULT_INSTR_CODE: 268348
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: Ntfs!EfsCloseEncryptOnCloseFile+41
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 41
FAILURE_BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
PRIMARY_PROBLEM_CLASS: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile
TARGET_TIME: 2019-12-13T12:27:18.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 573b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc2_46_ntfs!efscloseencryptonclosefile
FAILURE_ID_HASH: {6c0dbbce-3bf4-6674-181d-24e090eaf7df}
Followup: MachineOwner
---------
Hata raporlarına baktım, görünen hatalarının hepsinde donanım kaynaklı hafıza ve dosya sistemi hatası bildiriyor. Muhtemel sebep RAM'de bozulma var. Bu da belleğe alınan dosyaları ve dosya sistemini sekteye uğratıyor. Farklı bir RAM ile bir kaç gün test edip hatanın devam edip etmediğini kontrol et. Hata giderildi ise RAM değişimi yaparsın. Devam ediyorsa anakart slotlarında sıkıntı olabilir. Duruma göre farklı çözümlere gidersin.
Evet denedim değişen birşey yokTekrar silgi yöntemi denedin mi?
İşlemci pinleri iyi.belleğim bozuldu sanırım.Yeni parçalar alacağım artık.Bellek hataları, Memtest86 testi yap, eğer silgi yöntemi işe yaramıyorsa bellekler veya anakartın yuvaları arızalıdır, ayrıca işlemcinin altındaki pinleri kontrol et eğik bükük olmasın.
Kod:KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine. Arguments: Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove). Arg2: ffff8300caa2ff60, Address of the trap frame for the exception that caused the bugcheck Arg3: ffff8300caa2feb8, Address of the exception record for the exception that caused the bugcheck Arg4: 0000000000000000, Reserved Debugging Details: ------------------ ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057. KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 DUMP_TYPE: 2 BUGCHECK_P1: 3 BUGCHECK_P2: ffff8300caa2ff60 BUGCHECK_P3: ffff8300caa2feb8 BUGCHECK_P4: 0 TRAP_FRAME: ffff8300caa2ff60 -- (.trap 0xffff8300caa2ff60) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffff890409603c98 rbx=0000000000000000 rcx=0000000000000003 rdx=ffff8904118ab000 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80377bf514b rsp=ffff8300caa300f0 rbp=ffff8300caa301f0 r8=ffff890409603c88 r9=ffff890409603c98 r10=ffff890410f4f000 r11=ffff890409602780 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na po cy fffff803`77bf514b ?? ??? Resetting default scope EXCEPTION_RECORD: ffff8300caa2feb8 -- (.exr 0xffff8300caa2feb8) ExceptionAddress: fffff80377bf514b ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000003 Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY CPU_COUNT: 4 CPU_MHZ: d40 CPU_VENDOR: GenuineIntel CPU_FAMILY: 6 CPU_MODEL: 3a CPU_STEPPING: 9 CUSTOMER_CRASH_COUNT: 1 BUGCHECK_STR: 0x139 CURRENT_IRQL: 0 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 12-22-2019 18:09:28.0700 ANALYSIS_VERSION: 10.0.18362.1 x86fre LAST_CONTROL_TRANSFER: from fffff80377bd32e9 to fffff80377bc14e0 STACK_TEXT: ffff8300`caa300f0 ffff8300`caa30708 : ffff8300`caa30170 00000000`00000000 00000000`ffffffff ffff8300`caa30110 : 0xfffff803`77bf514b ffff8300`caa300f8 ffff8300`caa30170 : 00000000`00000000 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 : 0xffff8300`caa30708 ffff8300`caa30100 00000000`00000000 : 00000000`ffffffff ffff8300`caa30110 ffff8300`caa30110 00000000`00380038 : 0xffff8300`caa30170 STACK_COMMAND: .trap 0xffff8300caa2ff60 ; kb SYMBOL_NAME: ANALYSIS_INCONCLUSIVE FOLLOWUP_NAME: MachineOwner MODULE_NAME: Unknown_Module IMAGE_NAME: Unknown_Image DEBUG_FLR_IMAGE_TIMESTAMP: 0 BUCKET_ID: CORRUPT_MODULELIST_0x139 DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x139 PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST_0x139 FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x139 TARGET_TIME: 2019-12-20T14:23:40.000Z OSBUILD: 18362 OSSERVICEPACK: 0 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: unknown_date ANALYSIS_SESSION_ELAPSED_TIME: 1f ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x139 FAILURE_ID_HASH: {bec1bc00-1c8a-a417-55b2-9f8b67cbb1c5} Followup: MachineOwner --------- KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine. Arguments: Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove). Arg2: ffffc60b55ee9280, Address of the trap frame for the exception that caused the bugcheck Arg3: ffffc60b55ee91d8, Address of the exception record for the exception that caused the bugcheck Arg4: 0000000000000000, Reserved Debugging Details: ------------------ *** WARNING: Unable to verify timestamp for win32k.sys KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd. SYSTEM_PRODUCT_NAME: To be filled by O.E.M. SYSTEM_SKU: To be filled by O.E.M. SYSTEM_VERSION: To be filled by O.E.M. BIOS_VENDOR: American Megatrends Inc. BIOS_VERSION: F2 BIOS_DATE: 08/30/2013 BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd. BASEBOARD_PRODUCT: H61M-DS2 4.0 BASEBOARD_VERSION: To be filled by O.E.M. DUMP_TYPE: 2 BUGCHECK_P1: 3 BUGCHECK_P2: ffffc60b55ee9280 BUGCHECK_P3: ffffc60b55ee91d8 BUGCHECK_P4: 0 TRAP_FRAME: ffffc60b55ee9280 -- (.trap 0xffffc60b55ee9280) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffb58f8e259a50 rbx=0000000000000000 rcx=0000000000000003 rdx=ffffb58f8e259b50 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80268fe24e1 rsp=ffffc60b55ee9410 rbp=0000000000000000 r8=00000000ffffffff r9=7fffb58f85d57400 r10=fffff80268e0a970 r11=ffffccfb38800000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe cy nt!ExDeleteResourceLite+0x1d7b71: fffff802`68fe24e1 cd29 int 29h Resetting default scope EXCEPTION_RECORD: ffffc60b55ee91d8 -- (.exr 0xffffc60b55ee91d8) ExceptionAddress: fffff80268fe24e1 (nt!ExDeleteResourceLite+0x00000000001d7b71) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000003 Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY CPU_COUNT: 4 CPU_MHZ: d40 CPU_VENDOR: GenuineIntel CPU_FAMILY: 6 CPU_MODEL: 3a CPU_STEPPING: 9 CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init) BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXPNP: 1 (!blackboxpnp) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 BUGCHECK_STR: 0x139 PROCESS_NAME: System CURRENT_IRQL: 2 DEFAULT_BUCKET_ID: FAIL_FAST_CORRUPT_LIST_ENTRY ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text> EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text> EXCEPTION_CODE_STR: c0000409 EXCEPTION_PARAMETER1: 0000000000000003 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 12-22-2019 18:09:39.0892 ANALYSIS_VERSION: 10.0.18362.1 x86fre STACK_TEXT: ffffc60b`55ee8f58 fffff802`68fd32e9 : 00000000`00000139 00000000`00000003 ffffc60b`55ee9280 ffffc60b`55ee91d8 : nt!KeBugCheckEx ffffc60b`55ee8f60 fffff802`68fd3710 : ffffc60b`55ee92ff ffffc60b`55ee9230 00000000`00000000 fffff802`68e957ea : nt!KiBugCheckDispatch+0x69 ffffc60b`55ee90a0 fffff802`68fd1aa5 : 00000000`00000000 00000000`00000000 ffffa502`31200100 00000000`00000003 : nt!KiFastFailDispatch+0xd0 ffffc60b`55ee9280 fffff802`68fe24e1 : 00000000`00000705 01000000`00100000 ffffa502`3d7edc90 fffff802`6ba24985 : nt!KiRaiseSecurityCheckFailure+0x325 ffffc60b`55ee9410 fffff802`6ba26ec9 : 00000000`00000745 00000000`00000000 ffffb58f`8e25a910 ffffc60b`55ee98f0 : nt!ExDeleteResourceLite+0x1d7b71 ffffc60b`55ee9460 fffff802`6baefdf4 : 00000000`00000745 ffffb58f`8e25a910 ffffa502`3e0ad660 ffffc60b`55ee98f0 : Ntfs!NtfsFreeNonpagedIndexFcb+0x19 ffffc60b`55ee9490 fffff802`6ba14507 : ffffc60b`55ee98f0 ffffa502`34049800 ffffa502`3e0ad660 ffffb58f`00000000 : Ntfs!NtfsDeleteFcb+0x5c4 ffffc60b`55ee9510 fffff802`6baef4fe : ffffc60b`55ee98f0 ffffb58f`85d57180 ffffa502`3e0ad660 ffffa502`3e0adb78 : Ntfs!NtfsTeardownFromLcb+0x267 ffffc60b`55ee95b0 fffff802`6ba1892a : ffffc60b`55ee98f0 ffffc60b`55ee96b1 00000000`00000000 ffffc60b`55ee98f0 : Ntfs!NtfsTeardownStructures+0xee ffffc60b`55ee9630 fffff802`6bb10cec : ffffc60b`55ee9700 ffffa502`3e0ad660 ffffc60b`55ee98f0 ffffc60b`55ee98f0 : Ntfs!NtfsDecrementCloseCounts+0xaa ffffc60b`55ee9670 fffff802`6bb0fc31 : ffffc60b`55ee98f0 ffffa502`3e0ad7c0 ffffa502`3e0ad660 ffffb58f`85d57180 : Ntfs!NtfsCommonClose+0x45c ffffc60b`55ee9750 fffff802`6bb454d8 : 00000000`0000001c fffff802`6938f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241 ffffc60b`55ee98b0 fffff802`68ebd095 : ffffb58f`850abcc0 ffffb58f`850abc00 ffffb58f`850abc00 ffffb58f`8ab106c0 : Ntfs!NtfsFspClose+0x88 ffffc60b`55ee9b70 fffff802`68f2a7a5 : ffffb58f`8c815040 00000000`00000080 ffffb58f`8506c080 005c003a`0043003b : nt!ExpWorkerThread+0x105 ffffc60b`55ee9c10 fffff802`68fc8b2a : fffff802`64862180 ffffb58f`8c815040 fffff802`68f2a750 0043003b`005c0074 : nt!PspSystemThreadStartup+0x55 ffffc60b`55ee9c60 00000000`00000000 : ffffc60b`55eea000 ffffc60b`55ee4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a THREAD_SHA1_HASH_MOD_FUNC: 17fa4a8e3fd9e775c947d1d7121599e329fc6a6b THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f52d99ada7558168a3abfd0cf619a361dd14b77e THREAD_SHA1_HASH_MOD: baf72ea6dc105da5d0f2fb8a45027cf1bace7247 FOLLOWUP_NAME: memory_corruption MODULE_NAME: memory_corruption IMAGE_NAME: memory_corruption DEBUG_FLR_IMAGE_TIMESTAMP: 0 STACK_COMMAND: .thread ; .cxr ; kb FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption PRIMARY_PROBLEM_CLASS: 0x139_3_CORRUPT_LIST_ENTRY_IMAGE_memory_corruption TARGET_TIME: 2019-12-13T17:52:33.000Z OSBUILD: 18362 OSSERVICEPACK: 535 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: 1980-01-11 18:53:20 BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 57b8 ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0x139_3_corrupt_list_entry_image_memory_corruption FAILURE_ID_HASH: {6b711939-e5de-38cb-287e-eb7d8c867a90} Followup: memory_corruption --------- WINLOGON_FATAL_ERROR (c000021a) The Winlogon process terminated unexpectedly. Arguments: Arg1: ffffb909486fdef0, String that identifies the problem. Arg2: ffffffffc0000428, Error Code. Arg3: 0000000000000000 Arg4: 000001589fcf0000 Debugging Details: ------------------ ETW minidump data unavailable KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd. SYSTEM_PRODUCT_NAME: To be filled by O.E.M. SYSTEM_SKU: To be filled by O.E.M. SYSTEM_VERSION: To be filled by O.E.M. BIOS_VENDOR: American Megatrends Inc. BIOS_VERSION: F2 BIOS_DATE: 08/30/2013 BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd. BASEBOARD_PRODUCT: H61M-DS2 4.0 BASEBOARD_VERSION: To be filled by O.E.M. ERROR_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text> EXCEPTION_CODE: (NTSTATUS) 0xc000021a - <Unable to get error code text> EXCEPTION_CODE_STR: c000021a EXCEPTION_PARAMETER1: ffffb909486fdef0 EXCEPTION_PARAMETER2: ffffffffc0000428 EXCEPTION_PARAMETER3: 0000000000000000 EXCEPTION_PARAMETER4: 1589fcf0000 DUMP_TYPE: 2 BUGCHECK_P1: ffffb909486fdef0 BUGCHECK_P2: ffffffffc0000428 BUGCHECK_P3: 0 BUGCHECK_P4: 1589fcf0000 PROCESS_NAME: smss.exe ADDITIONAL_DEBUG_TEXT: initial session process or BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428 IMAGE_NAME: ntkrnlmp.exe MODULE_NAME: nt CPU_COUNT: 4 CPU_MHZ: d40 CPU_VENDOR: GenuineIntel CPU_FAMILY: 6 CPU_MODEL: 3a CPU_STEPPING: 9 CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init) BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT CURRENT_IRQL: 0 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 12-22-2019 18:09:30.0788 ANALYSIS_VERSION: 10.0.18362.1 x86fre LAST_CONTROL_TRANSFER: from fffff806039aeaea to fffff806035c14e0 STACK_TEXT: ffffe081`5d1e85a8 fffff806`039aeaea : 00000000`0000004c 00000000`c000021a ffffe081`5d3fe3f8 ffff968f`5a067690 : nt!KeBugCheckEx ffffe081`5d1e85b0 fffff806`03999fad : 00000000`00000000 ffffe081`5d1e8670 00000000`00000000 ffffe081`5d1e8670 : nt!PopGracefulShutdown+0x29a ffffe081`5d1e85f0 fffff806`0399f14c : ffffb909`42f66001 fffff806`00000006 00000000`00000004 ffffb909`4729e030 : nt!PopTransitionSystemPowerStateEx+0x11f1 ffffe081`5d1e86b0 fffff806`035d2d18 : 00000000`00000000 fffff806`0344109b 00000000`00000010 00000000`00000086 : nt!NtSetSystemPowerState+0x4c ffffe081`5d1e8890 fffff806`035c5320 : fffff806`03b9ca3d 00000000`c0000004 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 ffffe081`5d1e8a28 fffff806`03b9ca3d : 00000000`c0000004 00000000`00000000 00000000`00000000 fffff806`03845820 : nt!KiServiceLinkage ffffe081`5d1e8a30 fffff806`03b22269 : ffff968f`56285080 fffff806`034bd54c fffff806`08c1e7e0 ffff968f`00000000 : nt!PopIssueActionRequest+0x7a6b1 ffffe081`5d1e8ad0 fffff806`0352890f : 00000000`00000001 00000000`00000002 00000000`00000000 fffff806`03845800 : nt!PopPolicyWorkerAction+0x79 ffffe081`5d1e8b40 fffff806`034bd095 : ffff968f`00000001 ffff968f`56285080 fffff806`03528880 ffff968f`563139e0 : nt!PopPolicyWorkerThread+0x8f ffffe081`5d1e8b70 fffff806`0352a7a5 : ffff968f`56285080 00000000`00000080 ffff968f`5626c080 00000404`b59bbfff : nt!ExpWorkerThread+0x105 ffffe081`5d1e8c10 fffff806`035c8b2a : ffffcf80`9f480180 ffff968f`56285080 fffff806`0352a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55 ffffe081`5d1e8c60 00000000`00000000 : ffffe081`5d1e9000 ffffe081`5d1e3000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a THREAD_SHA1_HASH_MOD_FUNC: 53fc5ecb280b3e5cc6b5dde02f8439c4d5c2f83b THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e7c93c1aa367bf54af0e27c579d634451cfabf2e THREAD_SHA1_HASH_MOD: dc844b1b94baa204d070855e43bbbd27eee98b94 FOLLOWUP_IP: nt!PopTransitionSystemPowerStateEx+11f1 fffff806`03999fad cc int 3 FAULT_INSTR_CODE: cccccccc SYMBOL_STACK_INDEX: 2 SYMBOL_NAME: nt!PopTransitionSystemPowerStateEx+11f1 FOLLOWUP_NAME: MachineOwner DEBUG_FLR_IMAGE_TIMESTAMP: 12dcb470 IMAGE_VERSION: 10.0.18362.535 STACK_COMMAND: .thread ; .cxr ; kb BUCKET_ID_FUNC_OFFSET: 11f1 FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx PRIMARY_PROBLEM_CLASS: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!PopTransitionSystemPowerStateEx TARGET_TIME: 2019-12-22T14:45:57.000Z OSBUILD: 18362 OSSERVICEPACK: 535 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: 1980-01-11 18:53:20 BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 4872 ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0xc000021a_smpdestroycontrolblock_smss.exe_terminated_c0000428_nt!poptransitionsystempowerstateex FAILURE_ID_HASH: {11c026a4-042b-4c24-02dc-2da456397475} Followup: MachineOwner --------- BAD_POOL_CALLER (c2) The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc. Arguments: Arg1: 0000000000000046, Attempt to free an invalid pool address Arg2: 0000000000010000, Starting address Arg3: 0000000000000000, 0 Arg4: 0000000000000000, 0 Debugging Details: ------------------ KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd. SYSTEM_PRODUCT_NAME: To be filled by O.E.M. SYSTEM_SKU: To be filled by O.E.M. SYSTEM_VERSION: To be filled by O.E.M. BIOS_VENDOR: American Megatrends Inc. BIOS_VERSION: F2 BIOS_DATE: 08/30/2013 BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd. BASEBOARD_PRODUCT: H61M-DS2 4.0 BASEBOARD_VERSION: To be filled by O.E.M. DUMP_TYPE: 2 BUGCHECK_P1: 46 BUGCHECK_P2: 10000 BUGCHECK_P3: 0 BUGCHECK_P4: 0 FAULTING_IP: Ntfs!EfsCloseEncryptOnCloseFile+41 fffff803`3bc59d71 48832600 and qword ptr [rsi],0 BUGCHECK_STR: 0xc2_46 CPU_COUNT: 4 CPU_MHZ: d40 CPU_VENDOR: GenuineIntel CPU_FAMILY: 6 CPU_MODEL: 3a CPU_STEPPING: 9 CPU_MICROCODE: 6,3a,9,0 (F,M,S,R) SIG: 20'00000000 (cache) 20'00000000 (init) BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXPNP: 1 (!blackboxpnp) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT PROCESS_NAME: Monitor.exe CURRENT_IRQL: 0 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 12-22-2019 18:09:43.0532 ANALYSIS_VERSION: 10.0.18362.1 x86fre LAST_CONTROL_TRANSFER: from fffff8033851ac63 to fffff803383c14e0 STACK_TEXT: ffffb604`f3c75cf8 fffff803`3851ac63 : 00000000`000000c2 00000000`00000046 00000000`00010000 00000000`00000000 : nt!KeBugCheckEx ffffb604`f3c75d00 fffff803`3851acd8 : 00000000`00000016 00000000`00000000 00000000`00010000 fffff803`3866e118 : nt!RtlpHeapHandleError+0x2b ffffb604`f3c75d40 fffff803`3851a901 : ffffb604`f3c75e10 fffff803`3866e118 00000000`00000000 00000008`00000100 : nt!RtlpHpHeapHandleError+0x58 ffffb604`f3c75d70 fffff803`382ea787 : ffffb604`f3c75e10 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpLogHeapFailure+0x45 ffffb604`f3c75da0 fffff803`382ea700 : ffffb604`f3c75ed0 ffffb604`f3c75f70 00000000`00000000 00000000`00000000 : nt!RtlpHpVaMgrCtxQuery+0x4b ffffb604`f3c75de0 fffff803`38246389 : 00000000`00000000 00000000`00010000 a2e64ead`a2e64ead 00000000`00000000 : nt!RtlpHpQueryVA+0x54 ffffb604`f3c75e40 fffff803`3856f0a9 : 00000000`00000705 00000000`00000000 ffffe306`299be1c8 fffff803`3829e930 : nt!ExFreeHeapPool+0x809 ffffb604`f3c75f60 fffff803`3bc59d71 : 00000000`00000200 00000000`00000002 ffffe306`299be458 00000000`00000000 : nt!ExFreePool+0x9 ffffb604`f3c75f90 fffff803`3bb20a68 : ffffe306`299be170 00000000`00000000 00000000`00000000 ffffe306`299be458 : Ntfs!EfsCloseEncryptOnCloseFile+0x41 ffffb604`f3c75fc0 fffff803`3bb1ab9d : 00000000`00000000 00000000`00000258 00000000`00000000 ffffb604`f3c76480 : Ntfs!NtfsCommonCleanup+0x5a58 ffffb604`f3c76410 fffff803`38231f79 : ffffbb85`d100b010 fffff803`3af145a0 ffffbb85`d1b943f8 ffffbb85`d10b2000 : Ntfs!NtfsFsdCleanup+0x1ad ffffb604`f3c76760 fffff803`3af155de : ffffbb85`d1b94010 ffffb604`f3c76840 ffffbb85`d1b94010 ffffb604`f3c76850 : nt!IofCallDriver+0x59 ffffb604`f3c767a0 fffff803`3af13f16 : ffffb604`f3c76840 00000000`00000001 00000000`00000001 ffffbb85`d10b2080 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e ffffb604`f3c76820 fffff803`38231f79 : ffffbb85`d484f6c0 fffff803`38231e5d ffffbb85`ca6ce6c0 ffffb604`f3c76a39 : FLTMGR!FltpDispatch+0xb6 ffffb604`f3c76880 fffff803`387e42b8 : 00000000`00000000 ffffbb85`d484f6c0 00000000`00000000 ffffbb85`d1b94010 : nt!IofCallDriver+0x59 ffffb604`f3c768c0 fffff803`387ec408 : 00000000`00000000 00000000`00000001 ffffbb85`00000000 00000000`00007ffd : nt!IopCloseFile+0x188 ffffb604`f3c76950 fffff803`387f174e : 00000000`00000b80 00000000`00990000 00000000`00000000 fffff803`387c76fa : nt!ObCloseHandleTableEntry+0x278 ffffb604`f3c76a90 fffff803`383d2d18 : ffffbb85`d0a1a080 00007ffe`17ba4901 ffffb604`f3c76b80 ffffbb85`d10b2080 : nt!NtClose+0xde ffffb604`f3c76b00 00000000`777e1cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 00000000`0009eec8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777e1cbc THREAD_SHA1_HASH_MOD_FUNC: 4523f3cab0a62567943bb72de2e1ab2b13c58b95 THREAD_SHA1_HASH_MOD_FUNC_OFFSET: df4d630fd6f156ec2609f83d4dfc091a58316b09 THREAD_SHA1_HASH_MOD: 13371c36d8e7d2598a30c6397adec97d20874fdc FOLLOWUP_IP: Ntfs!EfsCloseEncryptOnCloseFile+41 fffff803`3bc59d71 48832600 and qword ptr [rsi],0 FAULT_INSTR_CODE: 268348 SYMBOL_STACK_INDEX: 8 SYMBOL_NAME: Ntfs!EfsCloseEncryptOnCloseFile+41 FOLLOWUP_NAME: MachineOwner MODULE_NAME: Ntfs IMAGE_NAME: Ntfs.sys DEBUG_FLR_IMAGE_TIMESTAMP: 0 IMAGE_VERSION: 10.0.18362.535 STACK_COMMAND: .thread ; .cxr ; kb BUCKET_ID_FUNC_OFFSET: 41 FAILURE_BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile BUCKET_ID: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile PRIMARY_PROBLEM_CLASS: 0xc2_46_Ntfs!EfsCloseEncryptOnCloseFile TARGET_TIME: 2019-12-13T12:27:18.000Z OSBUILD: 18362 OSSERVICEPACK: 535 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: 1980-01-11 18:53:20 BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 573b ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0xc2_46_ntfs!efscloseencryptonclosefile FAILURE_ID_HASH: {6c0dbbce-3bf4-6674-181d-24e090eaf7df} Followup: MachineOwner ---------
Elimde fazladan RAM yok.Yeni bir PC topluyordum.Sadece işlemci ve ekran kartı eksikti.Onları alacağım.Bir sorum daha var mavi ekran hatası SSD'me zarar verir mi?Şuan kullandığım SSD'yi yeni kasada da kullanacağım.Hata raporlarına baktım, görünen hatalarının hepsinde donanım kaynaklı hafıza ve dosya sistemi hatası bildiriyor. Muhtemel sebep RAM'de bozulma var. Bu da belleğe alınan dosyaları ve dosya sistemini sekteye uğratıyor. Farklı bir RAM ile bir kaç gün test edip hatanın devam edip etmediğini kontrol et. Hata giderildi ise RAM değişimi yaparsın. Devam ediyorsa anakart slotlarında sıkıntı olabilir. Duruma göre farklı çözümlere gidersin.
Zarar vereceğini sanmıyorum.SSD'me zarar verir mi? Şuan kullandığım SSD'yi yeni kasada da kullanacağım.