Windows 10 Recurrent crashes

  • Thread starter Thread starter PJ B
  • Start date Start date
P

PJ B

I have noticed that my PC crashes every now and then. This is the latest .dmp from last night's crash:



[COLOR=rgba(30, 30, 30, 1)]Microsoft (R) Windows Debugger Version 10.0.21306.1007 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\032821-9562-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff805`32c00000 PsLoadedModuleList = 0xfffff805`3382a490
Debug session time: Sun Mar 28 10:23:47.836 2021 (UTC + 1:00)
System Uptime: 3 days 10:28:39.640
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.......................................................
Loading User Symbols
Loading unloaded module list
..................................................
For analysis of this file, run [/COLOR][COLOR=rgba(0, 0, 255, 1)]!analyze -v
[/COLOR][COLOR=rgba(30, 30, 30, 1)]nt!KeBugCheckEx:
fffff805`32ff5c50 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff830a`5f09f590=0000000000000139
8: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 000000000000001d, Type of memory safety violation
Arg2: ffff830a5f09f8b0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff830a5f09f808, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------

*** WARNING: Unable to verify checksum for win32k.sys

KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 3624

Key : Analysis.DebugAnalysisManager
Value: Create

Key : Analysis.Elapsed.mSec
Value: 15647

Key : Analysis.Init.CPU.mSec
Value: 530

Key : Analysis.Init.Elapsed.mSec
Value: 61624

Key : Analysis.Memory.CommitPeak.Mb
Value: 83

Key : FailFast.Name
Value: INVALID_BALANCED_TREE

Key : FailFast.Type
Value: 29

Key : WER.OS.Branch
Value: vb_release

Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z

Key : WER.OS.Version
Value: 10.0.19041.1


BUGCHECK_CODE: 139

BUGCHECK_P1: 1d

BUGCHECK_P2: ffff830a5f09f8b0

BUGCHECK_P3: ffff830a5f09f808

BUGCHECK_P4: 0

TRAP_FRAME: ffff830a5f09f8b0 -- [/COLOR][COLOR=rgba(0, 0, 255, 1)](.trap 0xffff830a5f09f8b0)
[/COLOR][COLOR=rgba(30, 30, 30, 1)]NOTE: The trap frame does not contain all registers.
[/COLOR][COLOR=rgba(0, 0, 255, 1)]Some register values may be zeroed or incorrect.
[/COLOR][COLOR=rgba(30, 30, 30, 1)]rax=fffff80533812440 rbx=0000000000000000 rcx=000000000000001d
rdx=fffff805338196a0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8053302d71f rsp=ffff830a5f09fa40 rbp=0000000000000001
r8=fffff80533831880 r9=fffff80533812440 r10=fffff805338ec1c0
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di ng nz na po cy
nt!RtlRbInsertNodeEx+0x1ddf2f:
fffff805`3302d71f cd29 int 29h
Resetting default scope

EXCEPTION_RECORD: ffff830a5f09f808 -- [/COLOR][COLOR=rgba(0, 0, 255, 1)](.exr 0xffff830a5f09f808)
[/COLOR][COLOR=rgba(30, 30, 30, 1)]ExceptionAddress: fffff8053302d71f (nt!RtlRbInsertNodeEx+0x00000000001ddf2f)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 000000000000001d
Subcode: 0x1d FAST_FAIL_INVALID_BALANCED_TREE

BLACKBOXBSD: 1 ([/COLOR][COLOR=rgba(0, 0, 255, 1)]!blackboxbsd[/COLOR][COLOR=rgba(30, 30, 30, 1)])


BLACKBOXNTFS: 1 ([/COLOR][COLOR=rgba(0, 0, 255, 1)]!blackboxntfs[/COLOR][COLOR=rgba(30, 30, 30, 1)])


BLACKBOXPNP: 1 ([/COLOR][COLOR=rgba(0, 0, 255, 1)]!blackboxpnp[/COLOR][COLOR=rgba(30, 30, 30, 1)])


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: ciscowebexstart.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR: c0000409

EXCEPTION_PARAMETER1: 000000000000001d

EXCEPTION_STR: 0xc0000409

BAD_STACK_POINTER: ffff830a5f09f588

STACK_TEXT:
ffff830a`5f09f588 fffff805`33007b69 : 00000000`00000139 00000000`0000001d ffff830a`5f09f8b0 ffff830a`5f09f808 : nt!KeBugCheckEx
ffff830a`5f09f590 fffff805`33007f90 : 00000000`00000000 00000000`00989680 00000000`00000002 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff830a`5f09f6d0 fffff805`33006323 : 00000000`00000000 ffff830a`5f09fa31 ffff830a`5f09fa58 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffff830a`5f09f8b0 fffff805`3302d71f : ffff8883`ad89b040 fffff805`32f0e66f fffff805`33812440 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
ffff830a`5f09fa40 fffff805`32f0e66f : fffff805`33812440 00000000`00000000 fffff805`338ec1c0 00000000`00002710 : nt!RtlRbInsertNodeEx+0x1ddf2f
ffff830a`5f09fa50 fffff805`3311ad3a : 00000000`00000002 00000000`0000000f 00000000`00000201 00000000`00000000 : nt!KiSetClockInterval+0xa3
ffff830a`5f09fa80 fffff805`33119171 : 00000000`00000100 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSetVirtualHeteroClockIntervalRequest+0xc6
ffff830a`5f09fab0 fffff805`33118857 : 00000000`00000001 00000000`00000000 00000000`00000201 ffffdb00`e311b180 : nt!KeUpdatePendingQosRequest+0x31
ffff830a`5f09faf0 fffff805`32ffcd6b : ffffdb00`e311b180 000fa5ef`bd9bbfff ffff8883`cb2ea080 ffffdb00`e3126340 : nt!KeCheckAndApplyBamQos+0xd7
ffff830a`5f09fb20 fffff805`32ff9896 : ffffffff`00000000 ffffdb00`e3126340 ffff8883`c22db280 00000000`000002ee : nt!SwapContext+0xbb
ffff830a`5f09fb60 00000000`00000000 : ffff830a`5f0a0000 ffff830a`5f099000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x176


SYMBOL_NAME: nt!KiFastFailDispatch+d0

MODULE_NAME: [/COLOR][COLOR=rgba(0, 0, 255, 1)]nt

[/COLOR][COLOR=rgba(30, 30, 30, 1)]IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.19041.867

STACK_COMMAND: .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET: d0

FAILURE_BUCKET_ID: 0x139_1d_INVALID_BALANCED_TREE_STACKPTR_ERROR_nt!KiFastFailDispatch

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {8d15ffb8-3c9e-c4ac-5734-3b1c29688025}

Followup: MachineOwner
---------


Any suggestions?[/COLOR]

Continue reading...
 
Back
Top