Windows 8 and 8.1 Forums


BSOD due to ntoskrnl.exe+1509a0

  1. #1


    Posts : 2
    Windows 8.1

    BSOD due to ntoskrnl.exe+1509a0


    Hi,

    I'm getting BSOD after upgrading to Windows 8.1. I believe all the drivers are installed.

    I checked minidumps with nirsoft's BlueScreenView and got that those BSODs are caused by the same ntoskrnl.exe error 0xc0000139. I have noticed that this happens when I play a video (usually a Mkv file, but not all mkv files)

    I have attached the required files to this post. It would be a great help if anybody can help me to resolve this issue.

    Best Regards
    Tom

      My System SpecsSystem Spec

  2. #2


    Posts : 2
    Windows 8.1

    Update: Analysis ouptut from WinDbg


    Microsoft (R) Windows Debugger Version 6.3.9600.17298 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Windows\MEMORY.DMP]
    Kernel Bitmap Dump File: Only kernel address space is available


    ************* Symbol Path validation summary **************
    Response Time (ms) Location
    Deferred SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
    Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows 8 Kernel Version 9600 MP (8 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 9600.17415.amd64fre.winblue_r4.141028-1500
    Machine Name:
    Kernel base = 0xfffff803`e3e07000 PsLoadedModuleList = 0xfffff803`e40e0250
    Debug session time: Sun Nov 30 21:40:09.854 2014 (UTC - 5:00)
    System Uptime: 0 days 4:45:14.501
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..................................
    Loading User Symbols

    Loading unloaded module list
    ..........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 139, {3, ffffd00092974680, ffffd000929745d8, 0}

    Probably caused by : ntkrnlmp.exe ( nt!KiFastFailDispatch+d0 )

    Followup: MachineOwner
    ---------

    2: kd> analyze -v
    Couldn't resolve error at 'nalyze -v'
    2: kd> analyze -v
    Couldn't resolve error at 'nalyze -v'
    2: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    KERNEL_SECURITY_CHECK_FAILURE (139)
    A kernel component has corrupted a critical data structure. The corruption
    could potentially allow a malicious user to gain control of this machine.
    Arguments:
    Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
    Arg2: ffffd00092974680, Address of the trap frame for the exception that caused the bugcheck
    Arg3: ffffd000929745d8, Address of the exception record for the exception that caused the bugcheck
    Arg4: 0000000000000000, Reserved

    Debugging Details:
    ------------------


    TRAP_FRAME: ffffd00092974680 -- (.trap 0xffffd00092974680)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=fffff803e46278b0 rbx=0000000000000000 rcx=0000000000000003
    rdx=ffffe00079f58400 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff803e3f8f659 rsp=ffffd00092974810 rbp=ffffd00092974860
    r8=fffff803e40e78b0 r9=fffff803e46278b0 r10=fffff803e40e78b0
    r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0 nv up ei pl nz na pe cy
    nt! ?? ::FNODOBFM::`string'+0x277a9:
    fffff803`e3f8f659 cd29 int 29h
    Resetting default scope

    EXCEPTION_RECORD: ffffd000929745d8 -- (.exr 0xffffd000929745d8)
    ExceptionAddress: fffff803e3f8f659 (nt! ?? ::FNODOBFM::`string'+0x00000000000277a9)
    ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
    ExceptionFlags: 00000001
    NumberParameters: 1
    Parameter[0]: 0000000000000003

    DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT

    BUGCHECK_STR: 0x139

    PROCESS_NAME: System

    CURRENT_IRQL: 2

    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_PARAMETER1: 0000000000000003

    ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre

    DPC_STACK_BASE: FFFFD0009297BFB0

    LAST_CONTROL_TRANSFER: from fffff803e3f634e9 to fffff803e3f579a0

    STACK_TEXT:
    ffffd000`92974358 fffff803`e3f634e9 : 00000000`00000139 00000000`00000003 ffffd000`92974680 ffffd000`929745d8 : nt!KeBugCheckEx
    ffffd000`92974360 fffff803`e3f63810 : 00000000`000085b5 fffff800`3e71bdac ffffe000`7777b180 003158cd`00000001 : nt!KiBugCheckDispatch+0x69
    ffffd000`929744a0 fffff803`e3f62a34 : ffffd000`92974698 00000000`00000002 fffffff6`00000008 00000001`ffffffff : nt!KiFastFailDispatch+0xd0
    ffffd000`92974680 fffff803`e3f8f659 : ffffd000`92974b01 fffff803`e40c1660 00000000`00000000 fffff803`e3e30f45 : nt!KiRaiseSecurityCheckFailure+0xf4
    ffffd000`92974810 fffff803`e3ed1cd0 : ffffd000`9294cf00 ffffd000`92974b60 fffff803`e40e7830 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x277a9
    ffffd000`92974890 fffff803`e3ed0f87 : 00000000`00000001 ffffd000`92974b40 ffffd000`9294a180 00000000`00000001 : nt!KiExecuteAllDpcs+0x1b0
    ffffd000`929749e0 fffff803`e3f5b4ea : ffffd000`9294a180 ffffd000`9294a180 ffffd000`929563c0 ffffe000`7a7db880 : nt!KiRetireDpcList+0xd7
    ffffd000`92974c60 00000000`00000000 : ffffd000`92975000 ffffd000`9296f000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nt!KiFastFailDispatch+d0
    fffff803`e3f63810 c644242000 mov byte ptr [rsp+20h],0

    SYMBOL_STACK_INDEX: 2

    SYMBOL_NAME: nt!KiFastFailDispatch+d0

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 54503718

    BUCKET_ID_FUNC_OFFSET: d0

    FAILURE_BUCKET_ID: 0x139_3_nt!KiFastFailDispatch

    BUCKET_ID: 0x139_3_nt!KiFastFailDispatch

    ANALYSIS_SOURCE: KM

    FAILURE_ID_HASH_STRING: km:0x139_3_nt!kifastfaildispatch

    FAILURE_ID_HASH: {36173680-6f08-995f-065a-3d368c996911}

    Followup: MachineOwner
    ---------
      My System SpecsSystem Spec

  3. #3


    Posts : 2,480
    Windows 10 Pro x64


    Update the drivers highlighted in red
    Code:
    lirsgt.sys Sun Jan 29 12:13:28 2006 (43DCA358)  
    part of a Copy Protection platform developed by Tages SA 
    http://www.carrona.org/drivers/driver.php?id=lirsgt.sys 
    
    atksgt.sys Sat  Sep 16 17:03:49 2006 (450C1255) 
    part of a Copy Protection  platform developed by Tages SA 
    http://www.carrona.org/drivers/driver.php?id=atksgt.sys 
    
    wdcsam64.sys Wed  Apr 16 10:39:08 2008 (4805BB2C) 
    
    wdcsam64.sys - this driver hasn't been added to the DRT as  of this run. Please search Google/Bing for the driver if additional information  is needed. 
    
    AsUpIO.sys Tue Aug 3 04:47:59 2010  (4C57835F) 
    ASUS hardware monitoring software related 
    http://www.carrona.org/drivers/driver.php?id=AsUpIO.sys 
    
    AsIO.sys Wed Aug 22 11:54:47 2012  (5034AC67) 
    Asus PCProbe Utility 
    http://www.carrona.org/drivers/driver.php?id=AsIO.sys 
    
    vstor2-mntapi20-shared.sys Fri Feb 22  12:27:11 2013 (5127560F) 
    
    vstor2-mntapi20-shared.sys - this driver hasn't been added  to the DRT as of this run. Please search Google/Bing for the driver if  additional information is needed. 
    
    ElbyCDIO.sys Mon Mar 4 10:21:51  2013 (513467AF) 
    CDRTools/ElbyCDIO/DVD Region Killer/VirtualCloneDrive (elby  CloneDVD™ 2)/AnyDVD 
    http://www.carrona.org/drivers/driver.php?id=ElbyCDIO.sys 
    
    e1i63x64.sys Wed Mar 20 08:37:29  2013 (51496739) 
    Intel(R) Gigabit Adapter 
    http://www.carrona.org/drivers/driver.php?id=e1i63x64.sys 
    
    vmci.sys Sat May 18 03:19:18 2013  (5196D716) 
    VMware 
    http://www.carrona.org/drivers/driver.php?id=vmci.sys 
    
    VMNET.SYS Thu Jul 18 21:42:50 2013  (51E8453A) 
    VMware Virtual Network Driver 
    http://www.carrona.org/drivers/driver.php?id=VMNET.SYS 
    
    vmnetadapter.sys Thu Jul 18 21:43:00  2013 (51E84544) 
    VMware virtual network adapter driver 
    http://www.carrona.org/drivers/driver.php?id=vmnetadapter.sys 
    
    vmnetbridge.sys Thu Jul 18  21:43:47 2013 (51E84573) 
    VMware bridge driver 
    http://www.carrona.org/drivers/driver.php?id=vmnetbridge.sys 
    
    VClone.sys Wed Jul 24 17:02:55  2013 (51EFEC9F) 
    VirtualCloneCD Driver by Elaborate Bytes AG 
    http://www.carrona.org/drivers/driver.php?id=VClone.sys 
    
    vsock.sys Thu Aug 1 04:46:10 2013  (51F9CBF2) 
    VMware vSockets Service 
    http://www.carrona.org/drivers/driver.php?id=vsock.sys 
    
    TeeDriverx64.sys Mon Aug 19 19:23:31  2013 (52125493) 
    Intel Management Engine Interface driver 
    http://www.carrona.org/drivers/driver.php?id=TeeDriverx64.sys 
    
    intelppm.sys Thu Aug 22  10:46:35 2013 (5215CFEB) 
    Intel Processor driver 
    http://www.carrona.org/drivers/driver.php?id=intelppm.sys 
    
    dump_storahci.sys Thu Aug 22  13:40:39 2013 (5215F8B7) 
    driver created to provide disk access during crash  dump file generation 
    http://www.carrona.org/drivers/driver.php?id=dump_storahci.sys 
    
    avkmgr.sys Mon Sep 16  13:14:23 2013 (5236E80F) 
    Avira GmbH Manager Driver 
    http://www.carrona.org/drivers/driver.php?id=avkmgr.sys 
    
    SCDEmu.SYS Mon Feb 3 07:36:42 2014  (52EF38FA) 
    
    SCDEmu.SYS -  this driver hasn't been added to the DRT as of this run. Please search  Google/Bing for the driver if additional information is needed.  
    
    hcmon.sys Fri Feb 28 03:40:28 2014 (530FF71C) 
    VMware USB monitor  
    http://www.carrona.org/drivers/driver.php?id=hcmon.sys 
    
    vmnetuserif.sys Tue Apr 15 00:07:57  2014 (534C5C3D) 
    VMware network application interface driver 
    http://www.carrona.org/drivers/driver.php?id=vmnetuserif.sys 
    
    VMkbd.sys Tue Apr 15 00:42:54  2014 (534C646E) 
    VMware keyboard filter driver 
    http://www.carrona.org/drivers/driver.php?id=VMkbd.sys 
    
    vmx86.sys Tue Apr 15 01:31:39 2014  (534C6FDB) 
    VMware Virtualization Driver 
    http://www.carrona.org/drivers/driver.php?id=vmx86.sys 
    
    avgntflt.sys Fri Jul 11 17:46:47  2014 (53C006E7) 
    Avira AntiVir 
    http://www.carrona.org/drivers/driver.php?id=avgntflt.sys 
    
    nvhda64v.sys Mon Jul 21 16:17:53  2014 (53CD2111) 
    nVidia HDMI Audio Device (nForce chipset driver) 
    http://www.carrona.org/drivers/driver.php?id=nvhda64v.sys 
    
    avipbb.sys Wed Aug 6 09:31:29  2014 (53E1D9D1) 
    Avira AntiVir 
    http://www.carrona.org/drivers/driver.php?id=avipbb.sys 
    
    nvvad64v.sys Thu Sep 25 17:39:23  2014 (5424372B) 
    NVIDIA Virtual Audio Driver 
    http://www.carrona.org/drivers/driver.php?id=nvvad64v.sys 
    
    idmwfp.sys Thu Sep 25 17:44:24  2014 (54243858) 
    Internet Download Manager 
    http://www.carrona.org/drivers/driver.php?id=idmwfp.sys 
    
    NvStreamKms.sys  Sat Nov 1 00:04:56 2014 (54541598) 
    nVidia Streaming Kernel  service - may cause BSOD in Win8.1 systems (found in May  2014). Date/TimeStamp: Tue Apr 29 20:59:44 2014 (53604B00) MAY NOT BE A  PROBLEM, this is a tenative posting - Appears that April 29 driver is a problem,  July 2014 drivers seem OK 
    http://www.carrona.org/drivers/driver.php?id=NvStreamKms.sys 
    
    nvlddmkm.sys Wed Nov 12  21:51:31 2014 (5463C853) 
    nVidia Video drivers 
    http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys 
    
    
    
    Debug session time: Mon  Dec 1 03:40:09.854 2014 (UTC + 1:00) 
    Loading Dump File  [C:\Users\Mihael\SysnativeBSODApps\113014-24625-01.dmp] 
    Built by:  9600.17415.amd64fre.winblue_r4.141028-1500 
    System Uptime: 0 days 4:45:14.501  
    Probably caused by : ntkrnlmp.exe ( nt!KiFastFailDispatch+d0 ) 
    BugCheck  139, {3, ffffd00092974680, ffffd000929745d8, 0} 
    BugCheck Info: KERNEL_SECURITY_CHECK_FAILURE  (139) 
    Bugcheck code 00000139 
    Arguments: 
    Arg1: 0000000000000003,  A LIST_ENTRY has been corrupted (i.e. double remove). 
    Arg2:  ffffd00092974680, Address of the trap frame for the exception that caused the  bugcheck 
    Arg3: ffffd000929745d8, Address of the exception record for the  exception that caused the bugcheck 
    Arg4: 0000000000000000, Reserved  
    BUGCHECK_STR: 0x139 
    DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT  
    PROCESS_NAME: System 
    FAILURE_BUCKET_ID: 0x139_3_nt!KiFastFailDispatch  
    MaxSpeed: 3500 
    CurrentSpeed: 3498 
    BiosVersion = 2004  
    BiosReleaseDate = 06/03/2014 
    SystemManufacturer = ASUS  
    SystemProductName = All Series  
    ииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииииии``  
    
    
    
    
    --- E O J --- 2014 Dec 01 06:34:38 AM _88-dbug Copyright  2012 Sysnative Forums 
    --- E O J --- 2014 Dec 01 06:34:38 AM _88-dbug  Copyright 2012 Sysnative Forums 
    --- E O J --- 2014 Dec 01 06:34:38 AM  _88-dbug Copyright 2012 Sysnative Forums
      My System SpecsSystem Spec

BSOD due to ntoskrnl.exe+1509a0
Related Threads
BSOD due to ntoskrnl.exe+1509a0 in BSOD Crashes and Debugging
Guys, I had this BSOD due to ntoskrnl.exe+1509a0. I am using Windows 8.1 Pro 64 bits. PC is new, i7 4770 and according to AMD all video card drivers (R7 265) were updated. Using Zone Alarm as firewall. At the moment, the computer was downloading/uploading too much, don't know if this is...
Solved BSOD, Ntoskrnl. in BSOD Crashes and Debugging
Hi guys, My laptop crashes showing this BSOD, sometimes it is so frequent may reach 5 times/day sometimes the day passes clearly http://www.sevenforums.com/images/smilies/biggrin.gif Sometimes during browsing and working on it, sometimes when I leave it free/on lockscreen !!...
BSOD sometimes, ntoskrnl.exe in BSOD Crashes and Debugging
Hi! Everytime I shutdown the Laptop, computer close all programs and windows start to shutdown and after that screen goes black, computer still running. May be after 5-30 min will computer completely. Short summary: Computer: HP Probook 4530s OS: Windows 8.1 Event view and...
Solved BSOD with ntoskrnl.exe in BSOD Crashes and Debugging
Hi! :) For a couple of weeks now I'm using Windows 8.1 (upgraded from a Win 8 installation). Everything went fine until yesterday when I got my first BSOD on Win 8.1. Today it happened again. The causes seem to be the same but I hope for your analysis and help! Thanks in advance :)
BSOD on ntoskrnl.exe in BSOD Crashes and Debugging
Hi, I'm getting frequent blue screens which apparently occur from ntoskrnl.exe. Please see attached zip file from SF Diagnostic Tool Thanks in advance
Solved Ntoskrnl.exe bsod in BSOD Crashes and Debugging
Hello, i have a Problem with my Lenovo S205 in irregular times. In the attachment have I add my Minidump. I hope somebody can help me. I doesnt understand the dump Thanks
BSOD 133 (hal.dll and ntoskrnl.exe) in BSOD Crashes and Debugging
I just built this PC with Windows 8 Pro but have been getting random BSODs (watchdog) that typically occur when the system has to restart after installing new software or drivers. BlueScreenView tells me that the problem files are hal.dll and ntoskrnl.exe (and usbport.sys in one other dump), but...
Eight Forums Android App Eight Forums IOS App Follow us on Facebook