Hello,
I have a HP pavilion TP01-3700 desktop. Since the July updates, every morning my computer automatically restarts and opens a black screen stating, "Your device ran into problem and needs to restart" "KERNEL_SECURITY_CHECK _FAILURE (0x139).
Please help me solve this issue, I have extensively researched but nothing worked so-far. Below is the debug log.
Thanks in advance.
<DmlText>
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.032 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 46
Microsoft (R) Windows Debugger Version 10.0.29617.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\apopk\Desktop\072626-11656-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
WARNING: TriageDumpDataExtArray.HeaderSize is 0
WARNING: Failed to read dump data exension data
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 26100 MP (20 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Kernel base = 0xfffff804caa00000 PsLoadedModuleList = 0xfffff804cb8f5350
Debug session time: Sun Jul 26 07:54:03.104 2026 (UTC - 4:00)
System Uptime: 0 days 23:35:01.717
Loading Kernel Symbols
...............................................................
................................................................
................................................................
....................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000a5`35414018). Type ".hh dbgerr001" for details
Loading unloaded module list
...........
For analysis of this file, run <link alt="!analyze -v" cmd="!analyze -v"><u>!analyze -v</u></link>
nt!KeBugCheckEx:
fffff804caef9250 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff89849de76330=0000000000000139
6: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
....................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000a5`35414018). Type ".hh dbgerr001" for details
Loading unloaded module list
...........
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 000000000000001d, An RTL_BALANCED_NODE RBTree entry has been corrupted.
Arg2: ffff89849de76650, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff89849de765a8, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
*** WARNING: Unable to verify timestamp for nllArDisk.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1328
Key : Analysis.Elapsed.mSec
Value: 3600
Key : Analysis.IO.Other.Mb
Value: 4
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 10
Key : Analysis.Init.CPU.mSec
Value: 750
Key : Analysis.Init.Elapsed.mSec
Value: 54501
Key : Analysis.Memory.CommitPeak.Mb
Value: 108
Key : Analysis.Version.DbgEng
Value: 10.0.29617.1000
Key : Analysis.Version.Description
Value: 10.2604.29.1 amd64fre
Key : Analysis.Version.Ext
Value: 1.2604.29.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : FailFast.Name
Value: INVALID_BALANCED_TREE
Key : FailFast.Type
Value: 29
Key : Failure.Bucket
Value: 0x139_1d_INVALID_BALANCED_TREE_disk!DiskDeviceControl
Key : Failure.Exception.Code
Value: 0xc0000409
Key : Failure.Exception.Record
Value: 0xffff89849de765a8
Key : Failure.Hash
Value: {473901a9-9560-cf0c-f607-a5ab50412cfd}
BUGCHECK_CODE: 139
BUGCHECK_P1: 1d
BUGCHECK_P2: ffff89849de76650
BUGCHECK_P3: ffff89849de765a8
BUGCHECK_P4: 0
FILE_IN_CAB: 072626-11656-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: <link alt=".thread /r /p ffffe40fb3bdc080" cmd=".thread /r /p ffffe40fb3bdc080"><u>ffffe40fb3bdc080</u></link>
TRAP_FRAME: ffff89849de76650 -- <link alt=".trap 0xffff89849de76650" cmd=".trap 0xffff89849de76650"><u>(.trap 0xffff89849de76650)</u></link>
NOTE: The trap frame does not contain all registers.
<col fg="emphfg">Some register values may be zeroed or incorrect.</col>
rax=0000000000000000 rbx=0000000000000000 rcx=000000000000001d
rdx=00000000000000a8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff804cad659a3 rsp=ffff89849de767e0 rbp=ffff89849de769c9
r8=0000000000000000 r9=ffffe40fbf5e0058 r10=ffffe40fbf5de048
r11=ffffe40f7610cb90 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac pe cy
nt!RtlRbRemoveNode+0x133:
fffff804`cad659a3 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff89849de765a8 -- <link alt=".exr 0xffff89849de765a8" cmd=".exr 0xffff89849de765a8"><u>(.exr 0xffff89849de765a8)</u></link>
ExceptionAddress: fffff804cad659a3 (nt!RtlRbRemoveNode+0x0000000000000133)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 000000000000001d
Subcode: 0x1d FAST_FAIL_INVALID_BALANCED_TREE
BLACKBOXBSD: 1 (<link alt="!blackboxbsd" cmd="!blackboxbsd"><u>!blackboxbsd</u></link>)
BLACKBOXNTFS: 1 (<link alt="!blackboxntfs" cmd="!blackboxntfs"><u>!blackboxntfs</u></link>)
BLACKBOXPNP: 1 (<link alt="!blackboxpnp" cmd="!blackboxpnp"><u>!blackboxpnp</u></link>)
BLACKBOXWINLOGON: 1 (<link alt="!blackboxwinlogon" cmd="!blackboxwinlogon"><u>!blackboxwinlogon</u></link>) (<link alt="!blackboxwinlogonnotify" cmd="!blackboxwinlogonnotify"><u>!blackboxwinlogonnotify</u></link>)
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: hp-plugin-exec
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 000000000000001d
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff89849de76328 fffff804cb0bfbe9 : 0000000000000139 000000000000001d ffff89849de76650 ffff89849de765a8 : nt!KeBugCheckEx
ffff89849de76330 fffff804cb0c01f2 : ffff89849de76530 fffff804caca3315 fffff8045dd337a0 fffff8045dd46e7b : nt!KiBugCheckDispatch+0x69
ffff89849de76470 fffff804cb0bde28 : 0000000000000000 0000000000000000 fffff804cb8376a8 0000000000000001 : nt!KiFastFailDispatch+0xb2
ffff89849de76650 fffff804cad659a3 : ffffe40fbf5dc000 ffffe40fbf5de040 ffffe40f761002c0 0000000000000107 : nt!KiRaiseSecurityCheckFailure+0x368
ffff89849de767e0 fffff804cad64680 : ffffc30004349a00 ffffe40fbf5defe0 ffff89849de769c9 0000010600fa0000 : nt!RtlRbRemoveNode+0x133
ffff89849de76810 fffff804cad5c248 : ffff898400000000 ffffe40f7610cb80 ffffe40f761002c0 ffffe40f761002c0 : nt!RtlpHpVsChunkFree+0xb0
ffff89849de76880 fffff804cad5bc35 : 0000000000000000 ffffe40f761002c0 ffffe40fbf5defe0 0000000000000000 : nt!RtlpHpVsSlotFreeList+0x178
ffff89849de768f0 fffff804cb5754e9 : 0000000000000000 ffffe40f76100140 fffff804caa00000 ffffe40fbf5dc000 : nt!RtlpHpVsContextFree+0x155
ffff89849de76930 fffff8045dd2ebef : ffffe40fbf5df000 0000000000001000 ffffe40f76100000 ffff898400001050 : nt!ExFreePoolWithTag+0xc79
ffff89849de76a30 fffff8045dee0f8a : ffffe40fb8e922b0 ffffe40fb333e2d0 ffffe40fb8e922b0 fffff804cacd575b : storport!RaUnitStorageQueryDeviceProtocolSpecificPropertyIoctl+0x30b
ffff89849de76b90 fffff8045dd4ec2f : 0000000000000000 0000008000000001 ffffe40f01000080 ffffe40f76100340 : storport!RaUnitStorageQueryPropertyIoctl+0x3ca
ffff89849de76c50 fffff8045dd4c9bc : 0000000000000040 ffffe40f76100000 ffffe40fb8e922b0 0000000000000600 : storport!RaUnitDeviceControlIrp+0xf6f
ffff89849de76d30 fffff804cac5cabb : ffffe40fb8e922b0 ffffe40fb8e924a0 ffffe40f7d06b4a0 0000000000000000 : storport!RaDriverDeviceControlIrp+0x8c
ffff89849de76d70 fffff804cac5ca33 : ffffe40f7d06b4a0 fffff804cadcd41f ffffe40f7db800a0 0000000000000000 : nt!IopfCallDriver+0x5b
ffff89849de76db0 fffff8045d11b34d : ffffe40f7d06b4a0 0000000000000068 0000000000000000 0000000000000001 : nt!IofCallDriver+0x13
ffff89849de76de0 fffff804cac5cabb : 0000000000000007 ffffe40fb8e922b0 ffff89849de76fd0 0000000000000000 : ACPI!ACPIDispatchIrp+0x56d
ffff89849de76e60 fffff804cac5ca33 : 0000000000000000 ffffe40fbe6e0090 0000000000000000 0000000000000000 : nt!IopfCallDriver+0x5b
ffff89849de76ea0 fffff8045efc8a18 : ffffe40fbe6e0090 ffffe40fb8e922b0 ffffe40f76100000 0000000000000000 : nt!IofCallDriver+0x13
ffff89849de76ed0 fffff8045ef823e4 : ffffe40fbf5dd000 0000000000000000 ffffe40fb8e924e8 0000000000000002 : CLASSPNP!ClassDeviceControl+0xa98
ffff89849de77070 fffff8045efc1841 : 0000000000000000 ffffe40f00000000 ffffe40fb8e922b0 ffff89849de771f0 : disk!DiskDeviceControl+0xf4
ffff89849de77100 fffff8045efc017a : 0000000000000000 0000000000000002 ffffe40fb8e922b0 0000000000000000 : CLASSPNP!ClassDeviceControlDispatch+0x91
ffff89849de771a0 fffff804cac5cabb : 0000000100000002 0000000200000003 000000dd00000000 fffff804000001ff : CLASSPNP!ClassGlobalDispatch+0x3a
ffff89849de771d0 fffff804cac5ca33 : ffffe40f761002c0 ffffe40fbf5dc000 ffffe40f761002c5 0000000000000000 : nt!IopfCallDriver+0x5b
ffff89849de77210 fffff8045d925a25 : 0000000000000001 0000000000000001 ffffe40fbf5dc000 ffffe40f7610cb80 : nt!IofCallDriver+0x13
ffff89849de77240 fffff8045d90b00a : ffffe40f761002c0 ffffe40f7da188d0 ffffe40fb8e924e8 0000000000000000 : partmgr!PmIoctlQueryProperty+0x55
ffff89849de77270 fffff8045d902479 : ffffe40f7da18a20 ffffe40fb8e922b0 ffffe40f7da188d0 0000000000000000 : partmgr!PmFilterDeviceControlLegacy+0x35a
ffff89849de772c0 fffff804cac5cabb : 0000000000000000 ffffe40f7da19a20 ffffe40f7610cb80 ffff89849de773c0 : partmgr!PmGlobalDispatch+0xb9
ffff89849de772f0 fffff804cac5ca33 : ffffe40fbf5ec000 ffffe40f7610cb80 ffffe40f00000000 0000000000000001 : nt!IopfCallDriver+0x5b
ffff89849de77330 fffff8045ef0161d : 0000000000001040 0000000000000000 ffffe40fb8e922b0 ffffe40f7da19a20 : nt!IofCallDriver+0x13
ffff89849de77360 0000000000001040 : 0000000000000000 ffffe40fb8e922b0 ffffe40f7da19a20 ffffe40f00000020 : nllArDisk+0x161d
ffff89849de77368 0000000000000000 : ffffe40fb8e922b0 ffffe40f7da19a20 ffffe40f00000020 fffff804cad6795d : 0x1040
SYMBOL_NAME: disk!DiskDeviceControl+f4
MODULE_NAME: <link alt="lmvm disk" cmd="lmvm disk"><u>disk</u></link>
IMAGE_NAME: disk.sys
IMAGE_VERSION: 10.0.26100.8521
STACK_COMMAND: <link alt=".process /r /p 0xffffe40fb8dc8080; .thread /r /p 0xffffe40fb3bdc080 ; kb" cmd=".process /r /p 0xffffe40fb8dc8080; .thread /r /p 0xffffe40fb3bdc080 ; kb"><u>.process /r /p 0xffffe40fb8dc8080; .thread /r /p 0xffffe40fb3bdc080 ; kb</u></link>
BUCKET_ID_FUNC_OFFSET: f4
FAILURE_BUCKET_ID: 0x139_1d_INVALID_BALANCED_TREE_disk!DiskDeviceControl
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {473901a9-9560-cf0c-f607-a5ab50412cfd}
Followup: MachineOwner
6: kd> .process /r /p 0xffffe40fb8dc8080; .thread /r /p 0xffffe40fb3bdc080 ; kb
Implicit process is now ffffe40f`b8dc8080
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000a5`35414018). Type ".hh dbgerr001" for details
Implicit thread is now ffffe40f`b3bdc080
Implicit process is now ffffe40f`b8dc8080
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000a5`35414018). Type ".hh dbgerr001" for details
*** Stack trace for last set context - .thread/.cxr resets it
RetAddr : Args to Child : Call Site
<link alt=".frame 0n0;dv /t /v" cmd=".frame 0n0;dv /t /v"><u>00</u></link> fffff804cb0bfbe9 : 0000000000000139 000000000000001d ffff89849de76650 ffff8984`9de765a8 : nt!KeBugCheckEx
<link alt=".frame 0n1;dv /t /v" cmd=".frame 0n1;dv /t /v"><u>01</u></link> fffff804cb0c01f2 : ffff89849de76530 fffff804caca3315 fffff8045dd337a0 fffff804`5dd46e7b : nt!KiBugCheckDispatch+0x69
<link alt=".frame 0n2;dv /t /v" cmd=".frame 0n2;dv /t /v"><u>02</u></link> fffff804cb0bde28 : 0000000000000000 0000000000000000 fffff804cb8376a8 00000000`00000001 : nt!KiFastFailDispatch+0xb2
<link alt=".frame 0n3;dv /t /v" cmd=".frame 0n3;dv /t /v"><u>03</u></link> fffff804cad659a3 : ffffe40fbf5dc000 ffffe40fbf5de040 ffffe40f761002c0 00000000`00000107 : nt!KiRaiseSecurityCheckFailure+0x368
<link alt=".frame 0n4;dv /t /v" cmd=".frame 0n4;dv /t /v"><u>04</u></link> fffff804cad64680 : ffffc30004349a00 ffffe40fbf5defe0 ffff89849de769c9 00000106`00fa0000 : nt!RtlRbRemoveNode+0x133
<link alt=".frame 0n5;dv /t /v" cmd=".frame 0n5;dv /t /v"><u>05</u></link> fffff804cad5c248 : ffff898400000000 ffffe40f7610cb80 ffffe40f761002c0 ffffe40f`761002c0 : nt!RtlpHpVsChunkFree+0xb0
<link alt=".frame 0n6;dv /t /v" cmd=".frame 0n6;dv /t /v"><u>06</u></link> fffff804cad5bc35 : 0000000000000000 ffffe40f761002c0 ffffe40fbf5defe0 00000000`00000000 : nt!RtlpHpVsSlotFreeList+0x178
<link alt=".frame 0n7;dv /t /v" cmd=".frame 0n7;dv /t /v"><u>07</u></link> fffff804cb5754e9 : 0000000000000000 ffffe40f76100140 fffff804caa00000 ffffe40f`bf5dc000 : nt!RtlpHpVsContextFree+0x155
<link alt=".frame 0n8;dv /t /v" cmd=".frame 0n8;dv /t /v"><u>08</u></link> fffff8045dd2ebef : ffffe40fbf5df000 0000000000001000 ffffe40f76100000 ffff8984`00001050 : nt!ExFreePoolWithTag+0xc79
<link alt=".frame 0n9;dv /t /v" cmd=".frame 0n9;dv /t /v"><u>09</u></link> fffff8045dee0f8a : ffffe40fb8e922b0 ffffe40fb333e2d0 ffffe40fb8e922b0 fffff804`cacd575b : storport!RaUnitStorageQueryDeviceProtocolSpecificPropertyIoctl+0x30b
<link alt=".frame 0n10;dv /t /v" cmd=".frame 0n10;dv /t /v"><u>0a</u></link> fffff8045dd4ec2f : 0000000000000000 0000008000000001 ffffe40f01000080 ffffe40f`76100340 : storport!RaUnitStorageQueryPropertyIoctl+0x3ca
<link alt=".frame 0n11;dv /t /v" cmd=".frame 0n11;dv /t /v"><u>0b</u></link> fffff8045dd4c9bc : 0000000000000040 ffffe40f76100000 ffffe40fb8e922b0 00000000`00000600 : storport!RaUnitDeviceControlIrp+0xf6f
<link alt=".frame 0n12;dv /t /v" cmd=".frame 0n12;dv /t /v"><u>0c</u></link> fffff804cac5cabb : ffffe40fb8e922b0 ffffe40fb8e924a0 ffffe40f7d06b4a0 00000000`00000000 : storport!RaDriverDeviceControlIrp+0x8c
<link alt=".frame 0n13;dv /t /v" cmd=".frame 0n13;dv /t /v"><u>0d</u></link> fffff804cac5ca33 : ffffe40f7d06b4a0 fffff804cadcd41f ffffe40f7db800a0 00000000`00000000 : nt!IopfCallDriver+0x5b
<link alt=".frame 0n14;dv /t /v" cmd=".frame 0n14;dv /t /v"><u>0e</u></link> fffff8045d11b34d : ffffe40f7d06b4a0 0000000000000068 0000000000000000 00000000`00000001 : nt!IofCallDriver+0x13
<link alt=".frame 0n15;dv /t /v" cmd=".frame 0n15;dv /t /v"><u>0f</u></link> fffff804cac5cabb : 0000000000000007 ffffe40fb8e922b0 ffff89849de76fd0 00000000`00000000 : ACPI!ACPIDispatchIrp+0x56d
<link alt=".frame 0n16;dv /t /v" cmd=".frame 0n16;dv /t /v"><u>10</u></link> fffff804cac5ca33 : 0000000000000000 ffffe40fbe6e0090 0000000000000000 00000000`00000000 : nt!IopfCallDriver+0x5b
<link alt=".frame 0n17;dv /t /v" cmd=".frame 0n17;dv /t /v"><u>11</u></link> fffff8045efc8a18 : ffffe40fbe6e0090 ffffe40fb8e922b0 ffffe40f76100000 00000000`00000000 : nt!IofCallDriver+0x13
<link alt=".frame 0n18;dv /t /v" cmd=".frame 0n18;dv /t /v"><u>12</u></link> fffff8045ef823e4 : ffffe40fbf5dd000 0000000000000000 ffffe40fb8e924e8 00000000`00000002 : CLASSPNP!ClassDeviceControl+0xa98
<link alt=".frame 0n19;dv /t /v" cmd=".frame 0n19;dv /t /v"><u>13</u></link> fffff8045efc1841 : 0000000000000000 ffffe40f00000000 ffffe40fb8e922b0 ffff8984`9de771f0 : disk!DiskDeviceControl+0xf4
<link alt=".frame 0n20;dv /t /v" cmd=".frame 0n20;dv /t /v"><u>14</u></link> fffff8045efc017a : 0000000000000000 0000000000000002 ffffe40fb8e922b0 00000000`00000000 : CLASSPNP!ClassDeviceControlDispatch+0x91
<link alt=".frame 0n21;dv /t /v" cmd=".frame 0n21;dv /t /v"><u>15</u></link> fffff804cac5cabb : 0000000100000002 0000000200000003 000000dd00000000 fffff804`000001ff : CLASSPNP!ClassGlobalDispatch+0x3a
<link alt=".frame 0n22;dv /t /v" cmd=".frame 0n22;dv /t /v"><u>16</u></link> fffff804cac5ca33 : ffffe40f761002c0 ffffe40fbf5dc000 ffffe40f761002c5 00000000`00000000 : nt!IopfCallDriver+0x5b
<link alt=".frame 0n23;dv /t /v" cmd=".frame 0n23;dv /t /v"><u>17</u></link> fffff8045d925a25 : 0000000000000001 0000000000000001 ffffe40fbf5dc000 ffffe40f`7610cb80 : nt!IofCallDriver+0x13
<link alt=".frame 0n24;dv /t /v" cmd=".frame 0n24;dv /t /v"><u>18</u></link> fffff8045d90b00a : ffffe40f761002c0 ffffe40f7da188d0 ffffe40fb8e924e8 00000000`00000000 : partmgr!PmIoctlQueryProperty+0x55
<link alt=".frame 0n25;dv /t /v" cmd=".frame 0n25;dv /t /v"><u>19</u></link> fffff8045d902479 : ffffe40f7da18a20 ffffe40fb8e922b0 ffffe40f7da188d0 00000000`00000000 : partmgr!PmFilterDeviceControlLegacy+0x35a
<link alt=".frame 0n26;dv /t /v" cmd=".frame 0n26;dv /t /v"><u>1a</u></link> fffff804cac5cabb : 0000000000000000 ffffe40f7da19a20 ffffe40f7610cb80 ffff8984`9de773c0 : partmgr!PmGlobalDispatch+0xb9
<link alt=".frame 0n27;dv /t /v" cmd=".frame 0n27;dv /t /v"><u>1b</u></link> fffff804cac5ca33 : ffffe40fbf5ec000 ffffe40f7610cb80 ffffe40f00000000 00000000`00000001 : nt!IopfCallDriver+0x5b
<link alt=".frame 0n28;dv /t /v" cmd=".frame 0n28;dv /t /v"><u>1c</u></link> fffff8045ef0161d : 0000000000001040 0000000000000000 ffffe40fb8e922b0 ffffe40f`7da19a20 : nt!IofCallDriver+0x13
<link alt=".frame 0n29;dv /t /v" cmd=".frame 0n29;dv /t /v"><u>1d</u></link> 0000000000001040 : 0000000000000000 ffffe40fb8e922b0 ffffe40f7da19a20 ffffe40f`00000020 : nllArDisk+0x161d
<link alt=".frame 0n30;dv /t /v" cmd=".frame 0n30;dv /t /v"><u>1e</u></link> 0000000000000000 : ffffe40fb8e922b0 ffffe40f7da19a20 ffffe40f00000020 fffff804`cad6795d : 0x1040
6: kd> !blackboxwinlogon
ThreadName : WluiReleaseUI
IsOperationPending : 0
</DmlText>