pastebin - collaborative debugging tool
nrubsig.kpaste.net RSS


Windows crash with home dir/profile dir on network share
Posted by Anonymous on Wed 10th Sep 2025 12:54
raw | new post

  1. #
  2. # Windows crash with home dir/profile dir on network share
  3. #
  4. Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64
  5. Copyright (c) Microsoft Corporation. All rights reserved.
  6.  
  7.  
  8. Loading Dump File [C:\Users\roland_mainz\MEMORY.DMP]
  9. Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
  10.  
  11. Symbol search path is: srv*
  12. Executable search path is:
  13. Windows 10 Kernel Version 19041 MP (2 procs) Free x86 compatible
  14. Product: WinNt, suite: TerminalServer SingleUserTS
  15. Built by: 19041.1.x86fre.vb_release.191206-1406
  16. Machine Name:
  17. Kernel base = 0x8220a000 PsLoadedModuleList = 0x824d0d58
  18. Debug session time: Wed Sep 10 13:44:31.237 2025 (UTC + 2:00)
  19. System Uptime: 0 days 1:13:47.018
  20. Loading Kernel Symbols
  21. ...............................................................
  22. ................................................................
  23. .............Page 100b1 not present in the dump file. Type ".hh dbgerr004" for details
  24. ..........................................
  25. Loading User Symbols
  26. PEB is paged out (Peb.Ldr = 00b4900c).  Type ".hh dbgerr001" for details
  27. Loading unloaded module list
  28. ........
  29. For analysis of this file, run !analyze -v
  30. 0: kd> !analyze -v
  31. *******************************************************************************
  32. *                                                                             *
  33. *                        Bugcheck Analysis                                    *
  34. *                                                                             *
  35. *******************************************************************************
  36.  
  37. KERNEL_SECURITY_CHECK_FAILURE (139)
  38. A kernel component has corrupted a critical data structure.  The corruption
  39. could potentially allow a malicious user to gain control of this machine.
  40. Arguments:
  41. Arg1: 00000003, A LIST_ENTRY has been corrupted (i.e. double remove).
  42. Arg2: 8404acbc, Address of the trap frame for the exception that caused the bugcheck
  43. Arg3: 8404abe0, Address of the exception record for the exception that caused the bugcheck
  44. Arg4: 00000000, Reserved
  45.  
  46. Debugging Details:
  47. ------------------
  48.  
  49.  
  50. KEY_VALUES_STRING: 1
  51.  
  52.     Key  : Analysis.CPU.Sec
  53.     Value: 4
  54.  
  55.     Key  : Analysis.DebugAnalysisProvider.CPP
  56.     Value: Create: 8007007e on WINGRENDEL02
  57.  
  58.     Key  : Analysis.DebugData
  59.     Value: CreateObject
  60.  
  61.     Key  : Analysis.DebugModel
  62.     Value: CreateObject
  63.  
  64.     Key  : Analysis.Elapsed.Sec
  65.     Value: 4
  66.  
  67.     Key  : Analysis.Memory.CommitPeak.Mb
  68.     Value: 69
  69.  
  70.     Key  : Analysis.System
  71.     Value: CreateObject
  72.  
  73.  
  74. VIRTUAL_MACHINE:  VMware
  75.  
  76. BUGCHECK_CODE:  139
  77.  
  78. BUGCHECK_P1: 3
  79.  
  80. BUGCHECK_P2: ffffffff8404acbc
  81.  
  82. BUGCHECK_P3: ffffffff8404abe0
  83.  
  84. BUGCHECK_P4: 0
  85.  
  86. TRAP_FRAME:  8404acbc -- (.trap 0xffffffff8404acbc)
  87. ErrCode = 00000000
  88. eax=b2f719ec ebx=9b21b800 ecx=00000003 edx=00000001 esi=9b21b8e0 edi=9b21b8f8
  89. eip=82256887 esp=8404ad30 ebp=8404ad50 iopl=0         nv up ei pl nz na pe nc
  90. cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00000206
  91. nt!KiProcessThreadWaitList+0x77:
  92. 82256887 cd29            int     29h
  93. Resetting default scope
  94.  
  95. EXCEPTION_RECORD:  8404abe0 -- (.exr 0xffffffff8404abe0)
  96. ExceptionAddress: 82256887 (nt!KiProcessThreadWaitList+0x00000077)
  97.    ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  98.   ExceptionFlags: 00000001
  99. NumberParameters: 1
  100.    Parameter[0]: 00000003
  101. Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
  102.  
  103. BLACKBOXBSD: 1 (!blackboxbsd)
  104.  
  105.  
  106. BLACKBOXNTFS: 1 (!blackboxntfs)
  107.  
  108.  
  109. BLACKBOXPNP: 1 (!blackboxpnp)
  110.  
  111.  
  112. BLACKBOXWINLOGON: 1
  113.  
  114. PROCESS_NAME:  svchost.exe
  115.  
  116. ERROR_CODE: (NTSTATUS) 0xc0000409 - Das System hat in dieser Anwendung den  berlauf eines stapelbasierten Puffers ermittelt. Dieser  berlauf k nnte einem b sartigen Benutzer erm glichen, die Steuerung der Anwendung zu  bernehmen.
  117.  
  118. EXCEPTION_CODE_STR:  c0000409
  119.  
  120. EXCEPTION_PARAMETER1:  00000003
  121.  
  122. DPC_STACK_BASE:  FFFFFFFF8404B000
  123.  
  124. EXCEPTION_STR:  0xc0000409
  125.  
  126. STACK_TEXT:  
  127. 8404abc0 823a4240 00000139 00000003 8404acbc nt!KiBugCheck2
  128. 8404abc0 82256887 00000139 00000003 8404acbc nt!KiRaiseSecurityCheckFailure+0x2dc
  129. 8404ad50 82255cbf 00000000 00000002 811e65f8 nt!KiProcessThreadWaitList+0x77
  130. 8404ade0 82255b6d 811e5380 00000003 000293ad nt!KiProcessExpiredTimerList+0xdf
  131. 8404ae2c 82255950 c00293ad 00000003 000000c5 nt!KiExpireTimerTable+0x17d
  132. 8404aea0 82292788 4eb5590b 0000000a 000293ad nt!KiTimerExpiration+0x100
  133. 8404aff4 823abc8e a3747b3c 00000000 00000000 nt!KiRetireDpcList+0x558
  134. a3747b5c 8299c1eb a3747c14 9f9f0680 a3747c14 nt!KiDispatchInterrupt+0x2e
  135. a3747b6c 82988e88 00000001 a3747c14 823a516c hal!HalpInterruptCheckForSoftwareInterrupt+0x28
  136. a3747b78 823a516c 829cb140 a3747c14 0001ae00 hal!HalEndSystemInterrupt+0x78
  137. a3747b78 7791ecda 829cb140 a3747c14 0001ae00 nt!KiUnexpectedInterruptTail+0x41d
  138. WARNING: Frame IP not in any known module. Following frames may be wrong.
  139. 0423f5d4 00000000 00000000 00000000 00000000 0x7791ecda
  140.  
  141.  
  142. SYMBOL_NAME:  nt!KiProcessExpiredTimerList+df
  143.  
  144. MODULE_NAME: nt
  145.  
  146. IMAGE_NAME:  ntkrpamp.exe
  147.  
  148. STACK_COMMAND:  .thread ; .cxr ; kb
  149.  
  150. BUCKET_ID_FUNC_OFFSET:  df
  151.  
  152. FAILURE_BUCKET_ID:  0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiProcessExpiredTimerList
  153.  
  154. OS_VERSION:  10.0.19041.1
  155.  
  156. BUILDLAB_STR:  vb_release
  157.  
  158. OSPLATFORM_TYPE:  x86
  159.  
  160. OSNAME:  Windows 10
  161.  
  162. FAILURE_ID_HASH:  {9db7945b-255d-24a1-9f2c-82344e883ab8}
  163.  
  164. Followup:     MachineOwner
  165. ---------
  166.  
  167. 0: kd>

Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.

Syntax highlighting:

To highlight particular lines, prefix each line with {%HIGHLIGHT}




All content is user-submitted.
The administrators of this site (kpaste.net) are not responsible for their content.
Abuse reports should be emailed to us at