Share via

Need help with BSOD - multiple different errors.

Anonymous
2025-05-19T20:43:12+00:00

Hello,

A year and a while back my laptop began to crash once a day, and all of a sudden began crashing 2-3 times a day, later on it became hysterical from every 2 hours to 30 mins.

Problem is I keep getting different errors everytime. I sent it to some professionals here in Egypt, their final analysis is the motherboard is bad, which I don't believe tbh.

Now I tried to fix it with another shop who could not really fix it yet, we are in the testing phase. However I started troubleshooting on my own. Sometimes I would think I got the fix and others not. I regret buying a laptop with Ryzen processor, I feel the AMD is the issue here.

MY PC:

Processor AMD Ryzen 7 4800H with Radeon Graphics 2.90 GHz

Installed RAM 16.0 GB (15.4 GB usable)

Device ID B35B1B55-6E7B-4EA1-9B90-CF367E437104

Product ID 00327-30926-80177-AAOEM

System type 64-bit operating system, x64-based processor

Pen and touch No pen or touch input is available for this display

However I want help to fix this. Currently From the last crash I got the following DUMP:

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.016 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.062 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 44

Microsoft (R) Windows Debugger Version 10.0.27829.1001 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\051925-12625-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 22621 MP (16 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 22621.1.amd64fre.ni_release.220506-1250
Kernel base = 0xfffff804`0e800000 PsLoadedModuleList = 0xfffff804`0f413510
Debug session time: Mon May 19 23:02:42.571 2025 (UTC + 3:00)
System Uptime: 0 days 0:24:36.381
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...........
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000cd`b8eff018).  Type ".hh dbgerr001" for details
Loading unloaded module list
........
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff804`0ec17ba0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffc201`4da67ed0=0000000000000139
4: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...........
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000cd`b8eff018).  Type ".hh dbgerr001" for details
Loading unloaded module list
........
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000002, Stack cookie instrumentation code detected a stack-based
buffer overrun.
Arg2: ffffc2014da681f0, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffc2014da68148, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 3109

    Key  : Analysis.Elapsed.mSec
    Value: 8540

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 968

    Key  : Analysis.Init.Elapsed.mSec
    Value: 5018

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 120

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27829.1001

    Key  : Analysis.Version.Description
    Value: 10.2503.24.01 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2503.24.1

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x139

    Key  : Bugcheck.Code.TargetModel
    Value: 0x139

    Key  : FailFast.Name
    Value: STACK_COOKIE_CHECK_FAILURE

    Key  : FailFast.Type
    Value: 2

    Key  : Failure.Bucket
    Value: 0x139_MISSING_GSFRAME_dxgkrnl!_report_gsfailure

    Key  : Failure.Exception.Code
    Value: 0xc0000409

    Key  : Failure.Exception.Record
    Value: 0xffffc2014da68148

    Key  : Failure.Hash
    Value: {1685fa82-f4b9-d129-b6b1-78c3bba339a9}

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x1497cf94

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 1

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 0

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 1

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 0

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 1

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 4853999

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x4a10ef

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 1

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 1

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 1

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 1

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.Value
    Value: 1015

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x3f7

    Key  : WER.OS.Branch
    Value: ni_release

    Key  : WER.OS.Version
    Value: 10.0.22621.1

BUGCHECK_CODE:  139

BUGCHECK_P1: 2

BUGCHECK_P2: ffffc2014da681f0

BUGCHECK_P3: ffffc2014da68148

BUGCHECK_P4: 0

FILE_IN_CAB:  051925-12625-01.dmp

TAG_NOT_DEFINED_202b:  *** Unknown TAG in analysis list 202b

FAULTING_THREAD:  ffffad89f20760c0

TRAP_FRAME:  ffffc2014da681f0 -- (.trap 0xffffc2014da681f0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff804218d43a5 rsp=ffffc2014da68388 rbp=ffffc2014da68490
 r8=ffffc2014da68480  r9=ffffad89f29d5470 r10=fffff8040eacfcf0
r11=ffffc2014da68440 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
dxgkrnl!_report_gsfailure+0x5:
fffff804`218d43a5 cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  ffffc2014da68148 -- (.exr 0xffffc2014da68148)
ExceptionAddress: fffff804218d43a5 (dxgkrnl!_report_gsfailure+0x0000000000000005)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000002
Subcode: 0x2 FAST_FAIL_STACK_COOKIE_CHECK_FAILURE 

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  chrome.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000002

EXCEPTION_STR:  0xc0000409

STACK_TEXT:  
ffffc201`4da67ec8 fffff804`0ec2db29     : 00000000`00000139 00000000`00000002 ffffc201`4da681f0 ffffc201`4da68148 : nt!KeBugCheckEx
ffffc201`4da67ed0 fffff804`0ec2e0f2     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffc201`4da68010 fffff804`0ec2bddb     : ffffad89`ed579000 ffffad89`f3348010 00000000`0000000d fffff804`34b0866e : nt!KiFastFailDispatch+0xb2
ffffc201`4da681f0 fffff804`218d43a5     : fffff804`218d5258 ffffad89`e06750a0 00000000`00000018 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x35b
ffffc201`4da68388 fffff804`218d5258     : ffffad89`e06750a0 00000000`00000018 00000000`00000000 00000000`00000000 : dxgkrnl!_report_gsfailure+0x5
ffffc201`4da68390 fffff804`21a437ac     : 00000000`00000000 00000000`00000000 00000000`00000001 ffffc201`4da68638 : dxgkrnl!DXGCONTEXT::ReleaseReference+0x110
ffffc201`4da684b0 fffff804`21a40f54     : ffffad89`f20760c0 00000000`00000000 00000000`00000000 00000000`00000000 : dxgkrnl!SignalSynchronizationObjectInternal+0xf3c
ffffc201`4da68930 fffff804`21a4085b     : 00000000`00000000 00000207`1cc3b0d0 ffffad89`f20760c0 ffff6fff`26400000 : dxgkrnl!DxgkSignalSynchronizationObjectFromGpu2Impl+0x6e4
ffffc201`4da68ab0 fffff804`0ec2d208     : ffffad89`f20760c0 ffffc201`4da68b60 00000207`0abef750 ffffffff`ff676980 : dxgkrnl!DxgkSignalSynchronizationObjectFromGpu2+0xb
ffffc201`4da68ae0 00007ff9`51766004     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000cd`b97fc878 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`51766004

SYMBOL_NAME:  dxgkrnl!_report_gsfailure+5

MODULE_NAME: dxgkrnl

IMAGE_NAME:  dxgkrnl.sys

IMAGE_VERSION:  10.0.22621.5331

STACK_COMMAND: .process /r /p 0xffffad89f1e870c0; .thread 0xffffad89f20760c0 ; kb

BUCKET_ID_FUNC_OFFSET:  5

FAILURE_BUCKET_ID:  0x139_MISSING_GSFRAME_dxgkrnl!_report_gsfailure

OS_VERSION:  10.0.22621.1

BUILDLAB_STR:  ni_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {1685fa82-f4b9-d129-b6b1-78c3bba339a9}

Followup:     MachineOwner
---------
Windows for home | Windows 11 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

23 answers

Sort by: Most helpful
  1. Anonymous
    2025-05-22T11:09:28+00:00

    I wanted your opinion, what do you think of attempting to set this laptop to factory settings ?

    I found a digital media (set to factory settings) on Lenovos website.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-05-21T21:09:19+00:00

    Please reinstall these drivers from the Lenovo website:

    Realtek Wireless: rtwlane.sys

    Realtek Audio: rtkvhd64.sys

    Restart WDV with all customized tests except > run for 24 hrs

    [ ] 0x00000004 Randomized low resources simulation.
    

    If there is no immediate BSOD then open administrative command prompt and copy and paste:

    verifier /querysettings

    Post a share link.

    For any BSOD post a new V2 share link into the newest post:

    BSOD - Posting Instructions - Windows 10 Forums

    BSOD - Posting Instructions | Windows 11 Forum (elevenforum.com)

    https://www.tenforums.com/tutorials/3813-language-add-remove-change-windows-10-a.html

    https://www.tenforums.com/tutorials/136792-change-display-language-windows-10-a.html#option1

    After WDV testing has completed:

    Lenovo has various hardware diagnostic tests.

    a) https://download.lenovo.com/pccbbs/thinkvantage_en/ldiag_v04.39.000_bootable_uefi_x64.zip https://download.lenovo.com/pccbbs/thinkvantage_en/ldiag_v04.39.000_bootable_uefi_x64_ug.pdf

    b) Windows Custom scan > 112 min test

    Plan to run them > extensive > overnight while sleeping > take pictures > post images or share links displaying the tests performed with results

    RTKVHD64.sys Tue May 19 04:48:47 2020 (5EC3AB7F)

    rtwlane.sys Tue Nov 3 23:53:47 2020 (5FA241EB)

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-05-21T17:07:29+00:00

    Was this answer helpful?

    0 comments No comments
  4. Jonathan Deives 73,715 Reputation points Independent Advisor
    2025-05-20T18:24:23+00:00

    The minidump files do not indicate any driver or hardware causes.

    Try forcing Windows to show failed drivers and produce minidump files, enable Driver Verifier for this;

    https://answers.microsoft.com/en-us/windows/for...

    Let the BSOD happen 3 times and then see if the files were created.

    Before running Driver Verifier, create a new system restore point.


    If you have problems starting Windows after enabling Driver Verifier, follow these steps:

    Start your PC, as soon as Windows tries to load (spinning dots appear), press and hold the power button for 5 to 10 seconds to perform a forced shutdown

    Do this two or three times.

    Windows will boot into the Recovery Environment.

    Go to Troubleshoot > Advanced Option > Startup Settings and click Restart.

    When restarting, press 4 to enter safe mode.

    Open command prompt as administrator, run these two commands and restart your PC.

    verifier /reset

    verifier /bootmode resetonbootfail

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-05-20T11:07:21+00:00

    Hey Jonathan,

    Unfortunately it crashed again after these changes.

    The following is 2 minidumps when it first the first crash:

    https://drive.google.com/file/d/1GmLQ8Rjbi79Sok_CWy3dqzJwxqL-DTWC/view?usp=sharing

    This is from the last Memory Dump:

    Primary dump contents written successfully
    
    Symbol search path is: srv*
    Executable search path is: 
    Windows 10 Kernel Version 22621 MP (16 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Edition build lab: 22621.1.amd64fre.ni_release.220506-1250
    Kernel base = 0xfffff801`33000000 PsLoadedModuleList = 0xfffff801`33c13510
    Debug session time: Tue May 20 13:48:05.185 2025 (UTC + 3:00)
    System Uptime: 0 days 0:11:11.996
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ................................................................
    ...
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 0000001c`2e33c018).  Type ".hh dbgerr001" for details
    Loading unloaded module list
    .......
    For analysis of this file, run !analyze -v
    nt!KeBugCheckEx:
    fffff801`33417ba0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffff8109`2d452160=0000000000000050
    4: kd> !analyze -v
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ................................................................
    ...
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 0000001c`2e33c018).  Type ".hh dbgerr001" for details
    Loading unloaded module list
    .......
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except.
    Typically the address is just plain bad or it is pointing at freed memory.
    Arguments:
    Arg1: ffffe706e6d00010, memory referenced.
    Arg2: 0000000000000000, X64: bit 0 set if the fault was due to a not-present PTE.
    bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the processor decided the fault was due to a corrupted PTE.
    bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
    - ARM64: bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
    Arg3: fffff8013324b888, If non-zero, the instruction address which referenced the bad memory
    address.
    Arg4: 0000000000000002, (reserved)
    
    Debugging Details:
    ------------------
    
    KEY_VALUES_STRING: 1
    
        Key  : AV.Type
        Value: Read
    
        Key  : Analysis.CPU.mSec
        Value: 1640
    
        Key  : Analysis.Elapsed.mSec
        Value: 4930
    
        Key  : Analysis.IO.Other.Mb
        Value: 1
    
        Key  : Analysis.IO.Read.Mb
        Value: 1
    
        Key  : Analysis.IO.Write.Mb
        Value: 1
    
        Key  : Analysis.Init.CPU.mSec
        Value: 468
    
        Key  : Analysis.Init.Elapsed.mSec
        Value: 2684
    
        Key  : Analysis.Memory.CommitPeak.Mb
        Value: 113
    
        Key  : Analysis.Version.DbgEng
        Value: 10.0.27829.1001
    
        Key  : Analysis.Version.Description
        Value: 10.2503.24.01 amd64fre
    
        Key  : Analysis.Version.Ext
        Value: 1.2503.24.1
    
        Key  : Bugcheck.Code.KiBugCheckData
        Value: 0x50
    
        Key  : Bugcheck.Code.LegacyAPI
        Value: 0x50
    
        Key  : Bugcheck.Code.TargetModel
        Value: 0x50
    
        Key  : Dump.Attributes.AsUlong
        Value: 0x1800
    
        Key  : Dump.Attributes.DiagDataWrittenToHeader
        Value: 1
    
        Key  : Dump.Attributes.ErrorCode
        Value: 0x0
    
        Key  : Dump.Attributes.LastLine
        Value: Dumping physical memory to disk:  100% 
    
        Key  : Dump.Attributes.ProgressPercentage
        Value: 100
    
        Key  : Failure.Bucket
        Value: AV_R_(null)_CI!CiLogSIPolicyGetPolicyNameAndID
    
        Key  : Failure.Exception.IP.Address
        Value: 0xfffff8013324b888
    
        Key  : Failure.Exception.IP.Module
        Value: nt
    
        Key  : Failure.Exception.IP.Offset
        Value: 0x24b888
    
        Key  : Failure.Hash
        Value: {052e62ca-89a6-31b5-f8a9-770f8c758573}
    
        Key  : Hypervisor.Enlightenments.ValueHex
        Value: 0x1497cf94
    
        Key  : Hypervisor.Flags.AnyHypervisorPresent
        Value: 1
    
        Key  : Hypervisor.Flags.ApicEnlightened
        Value: 1
    
        Key  : Hypervisor.Flags.ApicVirtualizationAvailable
        Value: 0
    
        Key  : Hypervisor.Flags.AsyncMemoryHint
        Value: 0
    
        Key  : Hypervisor.Flags.CoreSchedulerRequested
        Value: 0
    
        Key  : Hypervisor.Flags.CpuManager
        Value: 1
    
        Key  : Hypervisor.Flags.DeprecateAutoEoi
        Value: 0
    
        Key  : Hypervisor.Flags.DynamicCpuDisabled
        Value: 1
    
        Key  : Hypervisor.Flags.Epf
        Value: 0
    
        Key  : Hypervisor.Flags.ExtendedProcessorMasks
        Value: 1
    
        Key  : Hypervisor.Flags.HardwareMbecAvailable
        Value: 1
    
        Key  : Hypervisor.Flags.MaxBankNumber
        Value: 0
    
        Key  : Hypervisor.Flags.MemoryZeroingControl
        Value: 0
    
        Key  : Hypervisor.Flags.NoExtendedRangeFlush
        Value: 0
    
        Key  : Hypervisor.Flags.NoNonArchCoreSharing
        Value: 1
    
        Key  : Hypervisor.Flags.Phase0InitDone
        Value: 1
    
        Key  : Hypervisor.Flags.PowerSchedulerQos
        Value: 0
    
        Key  : Hypervisor.Flags.RootScheduler
        Value: 0
    
        Key  : Hypervisor.Flags.SynicAvailable
        Value: 1
    
        Key  : Hypervisor.Flags.UseQpcBias
        Value: 0
    
        Key  : Hypervisor.Flags.Value
        Value: 4853999
    
        Key  : Hypervisor.Flags.ValueHex
        Value: 0x4a10ef
    
        Key  : Hypervisor.Flags.VpAssistPage
        Value: 1
    
        Key  : Hypervisor.Flags.VsmAvailable
        Value: 1
    
        Key  : Hypervisor.RootFlags.AccessStats
        Value: 1
    
        Key  : Hypervisor.RootFlags.CrashdumpEnlightened
        Value: 1
    
        Key  : Hypervisor.RootFlags.CreateVirtualProcessor
        Value: 1
    
        Key  : Hypervisor.RootFlags.DisableHyperthreading
        Value: 0
    
        Key  : Hypervisor.RootFlags.HostTimelineSync
        Value: 1
    
        Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
        Value: 0
    
        Key  : Hypervisor.RootFlags.IsHyperV
        Value: 1
    
        Key  : Hypervisor.RootFlags.LivedumpEnlightened
        Value: 1
    
        Key  : Hypervisor.RootFlags.MapDeviceInterrupt
        Value: 1
    
        Key  : Hypervisor.RootFlags.MceEnlightened
        Value: 1
    
        Key  : Hypervisor.RootFlags.Nested
        Value: 0
    
        Key  : Hypervisor.RootFlags.StartLogicalProcessor
        Value: 1
    
        Key  : Hypervisor.RootFlags.Value
        Value: 1015
    
        Key  : Hypervisor.RootFlags.ValueHex
        Value: 0x3f7
    
        Key  : SecureKernel.HalpHvciEnabled
        Value: 1
    
        Key  : WER.OS.Branch
        Value: ni_release
    
        Key  : WER.OS.Version
        Value: 10.0.22621.1
    
    BUGCHECK_CODE:  50
    
    BUGCHECK_P1: ffffe706e6d00010
    
    BUGCHECK_P2: 0
    
    BUGCHECK_P3: fffff8013324b888
    
    BUGCHECK_P4: 2
    
    FILE_IN_CAB:  MEMORY.DMP
    
    TAG_NOT_DEFINED_202b:  *** Unknown TAG in analysis list 202b
    
    DUMP_FILE_ATTRIBUTES: 0x1800
    
    FAULTING_THREAD:  ffffc205fbe09080
    
    READ_ADDRESS: unable to get nt!PspSessionIdBitmap
     ffffe706e6d00010 Paged pool
    
    MM_INTERNAL_CODE:  2
    
    PROCESS_NAME:  sppsvc.exe
    
    STACK_TEXT:  
    ffff8109`2d452158 fffff801`3348c5d6     : 00000000`00000050 ffffe706`e6d00010 00000000`00000000 ffff8109`2d452380 : nt!KeBugCheckEx
    ffff8109`2d452160 fffff801`3322375c     : 00000000`00000038 00000000`00000000 00000000`00000000 ffffe706`e6d00010 : nt!MiSystemFault+0x205806
    ffff8109`2d452260 fffff801`33428e7e     : ffffe706`b3a5a090 00000000`00000000 00000000`00000060 00000000`00000004 : nt!MmAccessFault+0x29c
    ffff8109`2d452380 fffff801`3324b888     : 00000000`332346af fffff801`332e90ef ffffe706`b3b89000 fffff801`00000001 : nt!KiPageFault+0x37e
    ffff8109`2d452510 fffff801`3321d1d3     : ffffffff`ffffffff ffffe706`b3b89000 ffffe706`b3b89000 ffffe706`b3b89000 : nt!RtlpHpSegLfhVsCommit+0x28
    ffff8109`2d452550 fffff801`3321c08f     : ffffe706`a9600380 ffffe706`a9600cc0 00000000`00000000 00000000`00000060 : nt!RtlpHpLfhSlotAllocate+0xa13
    ffff8109`2d452660 fffff801`3321bdaf     : ffff8109`00000000 ffff8109`2d452990 ffffe706`63734943 00000000`00000002 : nt!ExAllocateHeapPool+0x2af
    ffff8109`2d452780 fffff801`33aae36d     : 00000000`00000102 00000000`00000001 00000000`00000001 ffffe706`00000000 : nt!ExpAllocatePoolWithTagFromNode+0x5f
    ffff8109`2d4527d0 fffff801`34865dc9     : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe706`a9f68c00 : nt!ExAllocatePool2+0xdd
    ffff8109`2d452880 fffff801`34865656     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000003 : CI!CiLogSIPolicyGetPolicyNameAndID+0x119
    ffff8109`2d452940 fffff801`3486af77     : 00000000`00000000 ffff8109`2d452bd0 00000000`00000000 ffffe706`ffffffff : CI!CiLogSIPolicySmartlockerEvent+0xc2
    ffff8109`2d452ad0 fffff801`34872803     : 00000000`00000000 00000000`00000000 ffffd89e`08000002 00000000`0000100c : CI!CipApplySiPolicyEx+0x7ef
    ffff8109`2d452c90 fffff801`34872615     : 00000000`00000000 ffff8109`2d452d68 ffffe706`b3a5a0b0 ffff8109`2d452ea0 : CI!CiEvaluatePolicyInfo+0x13f
    ffff8109`2d452cf0 fffff801`3485730a     : ffffe706`b3a5a900 00000000`08000002 fffff801`424e000c 00000000`00000000 : CI!CiVerifyPageHashSignedFile+0x155
    ffff8109`2d452db0 fffff801`34858796     : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe706`b3a5a090 : CI!CipGetPageHashesForFile+0x3d2
    ffff8109`2d452ee0 fffff801`34857b64     : ffffe706`b3a5a090 ffffc205`fbb6d320 ffffc205`fbb32080 ffffe706`b56ff000 : CI!CipValidatePageHash+0x2c6
    ffff8109`2d452fd0 fffff801`34855b21     : 00000000`00000002 00000000`00000000 00000000`0000000c ffffe706`b56ff000 : CI!CipValidateImageHash+0x108
    ffff8109`2d453110 fffff801`336c9b55     : 00000000`68496d4d fffff801`3321bdaf 00000000`00000401 ffffe706`b56ff000 : CI!CiValidateImageHeader+0x8b1
    ffff8109`2d4532c0 fffff801`336c9675     : ffffe706`b4031000 00000000`00000000 00000000`00000000 00000000`00000002 : nt!SeValidateImageHeader+0xe9
    ffff8109`2d453370 fffff801`336cb78b     : 00000000`00000000 00000000`00000000 ffffffff`ffffffff 00000000`00000000 : nt!MiValidateSectionCreate+0x62d
    ffff8109`2d453590 fffff801`336cb504     : ffff8109`2d453820 00000000`00000002 ffffe706`b08e66cf 00000000`00000000 : nt!MiValidateSectionSigningPolicy+0xc7
    ffff8109`2d453600 fffff801`336caea4     : 00000000`00000002 ffff8109`2d453820 ffffc205`fbb6d320 ffffe706`b08e66c0 : nt!MiValidateExistingImage+0xf8
    ffff8109`2d453680 fffff801`336b46ab     : 00000000`00000000 ffff8109`2d453820 00000000`00000002 00000000`00000000 : nt!MiShareExistingControlArea+0xcc
    ffff8109`2d4536b0 fffff801`336b38f4     : ffffc205`f98f1bf0 00000000`00000000 ffffc205`fbb6d320 00000000`00000000 : nt!MiCreateImageOrDataSection+0x1cb
    ffff8109`2d4537a0 fffff801`336b4c75     : 00000000`01000000 ffff8109`2d453b60 00000000`00000001 00000000`00000001 : nt!MiCreateSection+0xf4
    ffff8109`2d453920 fffff801`336b37ec     : 0000001c`2e6fd188 00000000`0000000d 00000000`00000000 00000000`00000001 : nt!MiCreateSectionCommon+0x255
    ffff8109`2d453a00 fffff801`3342d208     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateSection+0x5c
    ffff8109`2d453a70 00007ffe`f92716c4     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
    0000001c`2e6fd138 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`f92716c4
    
    SYMBOL_NAME:  CI!CiLogSIPolicyGetPolicyNameAndID+119
    
    MODULE_NAME: CI
    
    IMAGE_NAME:  CI.dll
    
    STACK_COMMAND: .process /r /p 0xffffc205fbb32080; .thread 0xffffc205fbe09080 ; kb
    
    BUCKET_ID_FUNC_OFFSET:  119
    
    FAILURE_BUCKET_ID:  AV_R_(null)_CI!CiLogSIPolicyGetPolicyNameAndID
    
    OS_VERSION:  10.0.22621.1
    
    BUILDLAB_STR:  ni_release
    
    OSPLATFORM_TYPE:  x64
    
    OSNAME:  Windows 10
    
    FAILURE_ID_HASH:  {052e62ca-89a6-31b5-f8a9-770f8c758573}
    
    Followup:     MachineOwner
    ---------
    

    Was this answer helpful?

    0 comments No comments