Windows 10 Memory Dump help

  • Thread starter Thread starter MarkCaya1
  • Start date Start date
M

MarkCaya1

Enclosed is my memory dump output. I am running OBS, TrackIR, Tobii, GoXLR, AsusTweak II, Discord, ElgatoStream deck and lights, VoiceAttack, Restream.io chat, Edge Browser. I can stream all day with nothing bad happening, then out of the blue I get a BSOD. Previous blue screens I believe were caused by AsusTweak II component so I removed it and it stopped crashing because of that. This time it just says hardware failure in the reliability windows tool. KERNEL_SECURITY_CHECK_FAILURE (139)is the result of this crash. Also recently installed razer central. This is a fresh install of windows. Thank you for any help.






Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
For analysis of this file, run
!analyze -v
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139

Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Can't set dump file contexts
MachineInfo::SetContext failed - Thread: 00000187A3924B90 Handle: 30 Id: 30 - Error == 0x8000FFFF

************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139
||1:47: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000000, A stack-based buffer has been overrun.
Arg2: 0000000000000000, Address of the trap frame for the exception that caused the bugcheck
Arg3: 0000000000000000, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000020, Reserved

Debugging Details:
------------------


KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 4405

Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-KKAKIP1

Key : Analysis.DebugData
Value: CreateObject

Key : Analysis.DebugModel
Value: CreateObject

Key : Analysis.Elapsed.mSec
Value: 4399

Key : Analysis.Memory.CommitPeak.Mb
Value: 124

Key : Analysis.System
Value: CreateObject

Key : WER.OS.Branch
Value: vb_release

Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z

Key : WER.OS.Version
Value: 10.0.19041.1


ADDITIONAL_XML: 1

OS_BUILD_LAYERS: 1

BUGCHECK_CODE: 139

BUGCHECK_P1: 0

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 20

TRAP_FRAME: 0000000000000000 --
(.trap 0x0)

EXCEPTION_RECORD: 0000000000000000 -- (.exr 0x0)
Cannot read Exception record @ 0000000000000000

BLACKBOXBSD: 1 (
!blackboxbsd)


BLACKBOXNTFS: 1 (
!blackboxntfs)


BLACKBOXPNP: 1 (
!blackboxpnp)


BLACKBOXWINLOGON: 1

PROCESS_NAME: System

STACK_TEXT:
ffff9485`6b4ae6b8 fffff806`45bfe28b : 00000000`00000139 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffff9485`6b4ae6c0 fffff806`45b92375 : ffffffff`ffffffff 00000000`00989600 0000011d`1690084e 00000000`00000000 : nt!guard_icall_bugcheck+0x1b
ffff9485`6b4ae6f0 fffff806`45a701e5 : 00000000`00000000 00001f80`00000009 00000000`00000000 00000000`00000000 : nt!PpmIdleSelectStates+0x415
ffff9485`6b4aeaf0 fffff806`45bf92a4 : ffffffff`00000000 ffffb380`e23f7040 ffffa303`1b90a080 00000000`00001cb6 : nt!PoIdle+0x405
ffff9485`6b4aec60 00000000`00000000 : ffff9485`6b4af000 ffff9485`6b4a9000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x54


SYMBOL_NAME: nt!guard_icall_bugcheck+1b

MODULE_NAME:
nt

IMAGE_NAME: ntkrnlmp.exe

STACK_COMMAND: .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET: 1b

FAILURE_BUCKET_ID: 0x139_0_LEGACY_GS_VIOLATION_nt!guard_icall_bugcheck

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {9bee41a7-2ef9-07ca-7e59-7d5a0c6e2d05}

Followup: MachineOwner
---------

NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'

Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.


************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
For analysis of this file, run
!analyze -v
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139

Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Can't set dump file contexts
MachineInfo::SetContext failed - Thread: 0000020ABE359010 Handle: 30 Id: 30 - Error == 0x8000FFFF

************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2007.6001.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'

Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.


************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
For analysis of this file, run
!analyze -v
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139

Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Can't set dump file contexts
MachineInfo::SetContext failed - Thread: 000001F12096F600 Handle: 30 Id: 30 - Error == 0x8000FFFF

************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (64 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff806`45800000 PsLoadedModuleList = 0xfffff806`4642a2b0
Debug session time: Sat Dec 19 17:22:27.484 2020 (UTC - 7:00)
System Uptime: 1 days 10:00:44.421
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...............
Loading User Symbols

Loading unloaded module list
...........................
nt!KeBugCheckEx:
fffff806`45bf5780 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9485`6b4ae6c0=0000000000000139


Continue reading...
 
Back
Top