BSOD due to ntoskrnl.exe+1509a0

tomgeo

New Member
Messages
2
Hi,

I'm getting BSOD after upgrading to Windows 8.1. I believe all the drivers are installed.

I checked minidumps with nirsoft's BlueScreenView and got that those BSODs are caused by the same ntoskrnl.exe error 0xc0000139. I have noticed that this happens when I play a video (usually a Mkv file, but not all mkv files)

I have attached the required files to this post. It would be a great help if anybody can help me to resolve this issue.

Best Regards
Tom
 

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    PC/Desktop
Update: Analysis ouptut from WinDbg

Microsoft (R) Windows Debugger Version 6.3.9600.17298 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Only kernel address space is available


************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9600.17415.amd64fre.winblue_r4.141028-1500
Machine Name:
Kernel base = 0xfffff803`e3e07000 PsLoadedModuleList = 0xfffff803`e40e0250
Debug session time: Sun Nov 30 21:40:09.854 2014 (UTC - 5:00)
System Uptime: 0 days 4:45:14.501
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols

Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 139, {3, ffffd00092974680, ffffd000929745d8, 0}

Probably caused by : ntkrnlmp.exe ( nt!KiFastFailDispatch+d0 )

Followup: MachineOwner
---------

2: kd> analyze -v
Couldn't resolve error at 'nalyze -v'
2: kd> analyze -v
Couldn't resolve error at 'nalyze -v'
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffd00092974680, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffd000929745d8, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------


TRAP_FRAME: ffffd00092974680 -- (.trap 0xffffd00092974680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff803e46278b0 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffe00079f58400 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803e3f8f659 rsp=ffffd00092974810 rbp=ffffd00092974860
r8=fffff803e40e78b0 r9=fffff803e46278b0 r10=fffff803e40e78b0
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt! ?? ::FNODOBFM::`string'+0x277a9:
fffff803`e3f8f659 cd29 int 29h
Resetting default scope

EXCEPTION_RECORD: ffffd000929745d8 -- (.exr 0xffffd000929745d8)
ExceptionAddress: fffff803e3f8f659 (nt! ?? ::FNODOBFM::`string'+0x00000000000277a9)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003

DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT

BUGCHECK_STR: 0x139

PROCESS_NAME: System

CURRENT_IRQL: 2

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_PARAMETER1: 0000000000000003

ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre

DPC_STACK_BASE: FFFFD0009297BFB0

LAST_CONTROL_TRANSFER: from fffff803e3f634e9 to fffff803e3f579a0

STACK_TEXT:
ffffd000`92974358 fffff803`e3f634e9 : 00000000`00000139 00000000`00000003 ffffd000`92974680 ffffd000`929745d8 : nt!KeBugCheckEx
ffffd000`92974360 fffff803`e3f63810 : 00000000`000085b5 fffff800`3e71bdac ffffe000`7777b180 003158cd`00000001 : nt!KiBugCheckDispatch+0x69
ffffd000`929744a0 fffff803`e3f62a34 : ffffd000`92974698 00000000`00000002 fffffff6`00000008 00000001`ffffffff : nt!KiFastFailDispatch+0xd0
ffffd000`92974680 fffff803`e3f8f659 : ffffd000`92974b01 fffff803`e40c1660 00000000`00000000 fffff803`e3e30f45 : nt!KiRaiseSecurityCheckFailure+0xf4
ffffd000`92974810 fffff803`e3ed1cd0 : ffffd000`9294cf00 ffffd000`92974b60 fffff803`e40e7830 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x277a9
ffffd000`92974890 fffff803`e3ed0f87 : 00000000`00000001 ffffd000`92974b40 ffffd000`9294a180 00000000`00000001 : nt!KiExecuteAllDpcs+0x1b0
ffffd000`929749e0 fffff803`e3f5b4ea : ffffd000`9294a180 ffffd000`9294a180 ffffd000`929563c0 ffffe000`7a7db880 : nt!KiRetireDpcList+0xd7
ffffd000`92974c60 00000000`00000000 : ffffd000`92975000 ffffd000`9296f000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!KiFastFailDispatch+d0
fffff803`e3f63810 c644242000 mov byte ptr [rsp+20h],0

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: nt!KiFastFailDispatch+d0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 54503718

BUCKET_ID_FUNC_OFFSET: d0

FAILURE_BUCKET_ID: 0x139_3_nt!KiFastFailDispatch

BUCKET_ID: 0x139_3_nt!KiFastFailDispatch

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:0x139_3_nt!kifastfaildispatch

FAILURE_ID_HASH: {36173680-6f08-995f-065a-3d368c996911}

Followup: MachineOwner
---------
 

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    PC/Desktop
Update the drivers highlighted in red
Code:
[COLOR=red][B]lirsgt.sys Sun Jan 29 12:13:28 2006 (43DCA358)[/B][/COLOR]  
part of a Copy Protection platform developed by Tages SA 
[URL="http://www.carrona.org/drivers/driver.php?id=lirsgt.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]lirsgt.sys[/COLOR][/B][/URL] 

[COLOR=red][B]atksgt.sys Sat  Sep 16 17:03:49 2006 (450C1255)[/B][/COLOR] 
part of a Copy Protection  platform developed by Tages SA 
[URL="http://www.carrona.org/drivers/driver.php?id=atksgt.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]atksgt.sys[/COLOR][/B][/URL] 

[COLOR=red][B]wdcsam64.sys Wed  Apr 16 10:39:08 2008 (4805BB2C)[/B][/COLOR] 

[COLOR=#777777][COLOR=#4b0082]wdcsam64.sys[/COLOR] - this driver hasn't been added to the DRT as  of this run. Please search Google/Bing for the driver if additional information  is needed.[/COLOR] 

[COLOR=red][B]AsUpIO.sys Tue Aug 3 04:47:59 2010  (4C57835F)[/B][/COLOR] 
ASUS hardware monitoring software related 
[URL="http://www.carrona.org/drivers/driver.php?id=AsUpIO.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]AsUpIO.sys[/COLOR][/B][/URL] 

AsIO.sys Wed Aug 22 11:54:47 2012  (5034AC67) 
Asus PCProbe Utility 
[URL="http://www.carrona.org/drivers/driver.php?id=AsIO.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]AsIO.sys[/COLOR][/B][/URL] 

vstor2-mntapi20-shared.sys Fri Feb 22  12:27:11 2013 (5127560F) 

[COLOR=#777777][COLOR=#4b0082]vstor2-mntapi20-shared.sys[/COLOR] - this driver hasn't been added  to the DRT as of this run. Please search Google/Bing for the driver if  additional information is needed.[/COLOR] 

ElbyCDIO.sys Mon Mar 4 10:21:51  2013 (513467AF) 
CDRTools/ElbyCDIO/DVD Region Killer/VirtualCloneDrive (elby  CloneDVD™ 2)/AnyDVD 
[URL="http://www.carrona.org/drivers/driver.php?id=ElbyCDIO.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]ElbyCDIO.sys[/COLOR][/B][/URL] 

e1i63x64.sys Wed Mar 20 08:37:29  2013 (51496739) 
Intel(R) Gigabit Adapter 
[URL="http://www.carrona.org/drivers/driver.php?id=e1i63x64.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]e1i63x64.sys[/COLOR][/B][/URL] 

vmci.sys Sat May 18 03:19:18 2013  (5196D716) 
VMware 
[URL="http://www.carrona.org/drivers/driver.php?id=vmci.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vmci.sys[/COLOR][/B][/URL] 

VMNET.SYS Thu Jul 18 21:42:50 2013  (51E8453A) 
VMware Virtual Network Driver 
[URL="http://www.carrona.org/drivers/driver.php?id=VMNET.SYS"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]VMNET.SYS[/COLOR][/B][/URL] 

vmnetadapter.sys Thu Jul 18 21:43:00  2013 (51E84544) 
VMware virtual network adapter driver 
[URL="http://www.carrona.org/drivers/driver.php?id=vmnetadapter.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vmnetadapter.sys[/COLOR][/B][/URL] 

vmnetbridge.sys Thu Jul 18  21:43:47 2013 (51E84573) 
VMware bridge driver 
[URL="http://www.carrona.org/drivers/driver.php?id=vmnetbridge.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vmnetbridge.sys[/COLOR][/B][/URL] 

VClone.sys Wed Jul 24 17:02:55  2013 (51EFEC9F) 
VirtualCloneCD Driver by Elaborate Bytes AG 
[URL="http://www.carrona.org/drivers/driver.php?id=VClone.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]VClone.sys[/COLOR][/B][/URL] 

vsock.sys Thu Aug 1 04:46:10 2013  (51F9CBF2) 
VMware vSockets Service 
[URL="http://www.carrona.org/drivers/driver.php?id=vsock.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vsock.sys[/COLOR][/B][/URL] 

TeeDriverx64.sys Mon Aug 19 19:23:31  2013 (52125493) 
Intel Management Engine Interface driver 
[URL="http://www.carrona.org/drivers/driver.php?id=TeeDriverx64.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]TeeDriverx64.sys[/COLOR][/B][/URL] 

intelppm.sys Thu Aug 22  10:46:35 2013 (5215CFEB) 
Intel Processor driver 
[URL="http://www.carrona.org/drivers/driver.php?id=intelppm.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]intelppm.sys[/COLOR][/B][/URL] 

dump_storahci.sys Thu Aug 22  13:40:39 2013 (5215F8B7) 
driver created to provide disk access during crash  dump file generation 
[URL="http://www.carrona.org/drivers/driver.php?id=dump_storahci.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]dump_storahci.sys[/COLOR][/B][/URL] 

avkmgr.sys Mon Sep 16  13:14:23 2013 (5236E80F) 
Avira GmbH Manager Driver 
[URL="http://www.carrona.org/drivers/driver.php?id=avkmgr.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]avkmgr.sys[/COLOR][/B][/URL] 

SCDEmu.SYS Mon Feb 3 07:36:42 2014  (52EF38FA) 

[COLOR=#777777][COLOR=#4b0082]SCDEmu.SYS[/COLOR] -  this driver hasn't been added to the DRT as of this run. Please search  Google/Bing for the driver if additional information is needed.[/COLOR]  

hcmon.sys Fri Feb 28 03:40:28 2014 (530FF71C) 
VMware USB monitor  
[URL="http://www.carrona.org/drivers/driver.php?id=hcmon.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]hcmon.sys[/COLOR][/B][/URL] 

vmnetuserif.sys Tue Apr 15 00:07:57  2014 (534C5C3D) 
VMware network application interface driver 
[URL="http://www.carrona.org/drivers/driver.php?id=vmnetuserif.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vmnetuserif.sys[/COLOR][/B][/URL] 

VMkbd.sys Tue Apr 15 00:42:54  2014 (534C646E) 
VMware keyboard filter driver 
[URL="http://www.carrona.org/drivers/driver.php?id=VMkbd.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]VMkbd.sys[/COLOR][/B][/URL] 

vmx86.sys Tue Apr 15 01:31:39 2014  (534C6FDB) 
VMware Virtualization Driver 
[URL="http://www.carrona.org/drivers/driver.php?id=vmx86.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]vmx86.sys[/COLOR][/B][/URL] 

avgntflt.sys Fri Jul 11 17:46:47  2014 (53C006E7) 
Avira AntiVir 
[URL="http://www.carrona.org/drivers/driver.php?id=avgntflt.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]avgntflt.sys[/COLOR][/B][/URL] 

nvhda64v.sys Mon Jul 21 16:17:53  2014 (53CD2111) 
nVidia HDMI Audio Device (nForce chipset driver) 
[URL="http://www.carrona.org/drivers/driver.php?id=nvhda64v.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]nvhda64v.sys[/COLOR][/B][/URL] 

avipbb.sys Wed Aug 6 09:31:29  2014 (53E1D9D1) 
Avira AntiVir 
[URL="http://www.carrona.org/drivers/driver.php?id=avipbb.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]avipbb.sys[/COLOR][/B][/URL] 

nvvad64v.sys Thu Sep 25 17:39:23  2014 (5424372B) 
NVIDIA Virtual Audio Driver 
[URL="http://www.carrona.org/drivers/driver.php?id=nvvad64v.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]nvvad64v.sys[/COLOR][/B][/URL] 

idmwfp.sys Thu Sep 25 17:44:24  2014 (54243858) 
Internet Download Manager 
[URL="http://www.carrona.org/drivers/driver.php?id=idmwfp.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]idmwfp.sys[/COLOR][/B][/URL] 

[COLOR=red][B]NvStreamKms.sys  Sat Nov 1 00:04:56 2014 (54541598)[/B][/COLOR] 
nVidia Streaming Kernel  service - may cause [COLOR=red]BSOD[/COLOR] in Win8.1 systems (found in May  2014). Date/TimeStamp: Tue Apr 29 20:59:44 2014 (53604B00) [B]MAY NOT BE A  PROBLEM, this is a tenative posting - Appears that April 29 driver is a problem,  July 2014 drivers seem OK[/B] 
[URL="http://www.carrona.org/drivers/driver.php?id=NvStreamKms.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]NvStreamKms.sys[/COLOR][/B][/URL] 

nvlddmkm.sys Wed Nov 12  21:51:31 2014 (5463C853) 
nVidia Video drivers 
[URL="http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys"]http://www.carrona.org/drivers/driver.php?id=[B][COLOR=blue]nvlddmkm.sys[/COLOR][/B][/URL] 



Debug session time: Mon  Dec 1 03:40:09.854 2014 (UTC + 1:00) 
Loading Dump File  [C:\Users\Mihael\SysnativeBSODApps\113014-24625-01.dmp] 
Built by:  9600.17415.amd64fre.winblue_r4.141028-1500 
System Uptime: 0 days 4:45:14.501  
Probably caused by : ntkrnlmp.exe ( nt!KiFastFailDispatch+d0 ) 
BugCheck  139, {3, ffffd00092974680, ffffd000929745d8, 0} 
BugCheck Info: [URL="http://www.carrona.org/bsodindx.html#0x00000139"]KERNEL_SECURITY_CHECK_FAILURE  (139)[/URL] 
Bugcheck code 00000139 
Arguments: 
Arg1: 0000000000000003,  A LIST_ENTRY has been corrupted (i.e. double remove). 
Arg2:  ffffd00092974680, Address of the trap frame for the exception that caused the  bugcheck 
Arg3: ffffd000929745d8, Address of the exception record for the  exception that caused the bugcheck 
Arg4: 0000000000000000, Reserved  
BUGCHECK_STR: 0x139 
DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT  
PROCESS_NAME: System 
FAILURE_BUCKET_ID: 0x139_3_nt!KiFastFailDispatch  
MaxSpeed: 3500 
CurrentSpeed: 3498 
BiosVersion = 2004  
BiosReleaseDate = 06/03/2014 
SystemManufacturer = ASUS  
SystemProductName = All Series  
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``  




--- E O J --- 2014 Dec 01 06:34:38 AM _88-dbug Copyright  2012 Sysnative Forums 
--- E O J --- 2014 Dec 01 06:34:38 AM _88-dbug  Copyright 2012 Sysnative Forums 
--- E O J --- 2014 Dec 01 06:34:38 AM  _88-dbug Copyright 2012 Sysnative Forums
 

My Computer

System One

  • OS
    Windows 10 Pro x64
    Computer type
    PC/Desktop
    CPU
    INTEL Core i7-2700K 3.5GHz
    Motherboard
    ASROCK Fatal1ty P67 Main Board
    Memory
    HyperX Blu 8GB (2 x 4GB) DDR3 1600
    Graphics Card(s)
    Gigabyte GTX 980 Ti G1 Gaming
    Sound Card
    On-board
    Monitor(s) Displays
    Philips Brilliance BDM4065UC
    Screen Resolution
    3840x2160
    Hard Drives
    SSD: Samsung EVO 250 GB
    Internal HDD: WD Black 1TB
    External: 2x2TB MyBook drives
    1x4TB MyBook
    1x1TB Seagate Freeagent drive
    PSU
    Corsair GS 700W
    Case
    Silverstone Kublai KL04
    Cooling
    Artic Cooling Freezer Pro
    Keyboard
    Logitech G710+
    Mouse
    Razer Mamba Elite 2012
    Internet Speed
    10/0.75
    Browser
    FF 39.0.3, Microsoft Edge, Chrome 44
    Antivirus
    Avast 10.0
Back
Top