Unsolved
3 Posts
0
1640
February 27th, 2021 09:00
XPS 8920, random blue screen after new RAM installed
Hi all!
Our XPS 8920 has been going into bluescreen randomly since we installed new RAM sticks. Error codes are different every time. It happens randomly between minutes and hours.
The 4 RAM sticks are all the same model from Crucial (https://www.crucial.com/memory/ddr4/ct2k16g4dfd832a).
We thought if the cause was not the new RAMs, then it might be the mobo that is becoming unstable. I would like to show you one of the most recent WinDbg log below and would love to get some advise from you, what should we try out first: replacing the mobo or the RAM, or reinstalling Windows?
Thank you for your help!
Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 18362 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base = 0xfffff803`51000000 PsLoadedModuleList = 0xfffff803`51445e90
Debug session time: Sun Feb 28 01:43:05.747 2021 (UTC + 9:00)
System Uptime: 0 days 0:02:11.620
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.................................................
Loading User Symbols
Loading unloaded module list
....................
For analysis of this file, run !analyze -vnt!KeBugCheckEx:
fffff803`511c3a90 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9280`6883f390=0000000000000139
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff92806883f6b0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff92806883f608, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 4874
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-S240J4S
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 13328
Key : Analysis.Memory.CommitPeak.Mb
Value: 84
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff92806883f6b0
BUGCHECK_P3: ffff92806883f608
BUGCHECK_P4: 0
TRAP_FRAME: ffff92806883f6b0 -- (.trap 0xffff92806883f6b0)NOTE: The trap frame does not contain all registers.Some register values may be zeroed or incorrect.rax=ffffde0482118268 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000005 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803510c67e4 rsp=ffff92806883f840 rbp=ffffde048346c250
r8=0000000000000102 r9=0000000000000000 r10=fffff8035113e4e0
r11=ffff92806883f820 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!KiProcessExpiredTimerList+0x234:
fffff803`510c67e4 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff92806883f608 -- (.exr 0xffff92806883f608)ExceptionAddress: fffff803510c67e4 (nt!KiProcessExpiredTimerList+0x0000000000000234)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff9280`6883f388 fffff803`511d5929 : 00000000`00000139 00000000`00000003 ffff9280`6883f6b0 ffff9280`6883f608 : nt!KeBugCheckEx
ffff9280`6883f390 fffff803`511d5d50 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff9280`6883f4d0 fffff803`511d40e3 : 00000000`00001000 00000000`00000002 00000000`00000000 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffff9280`6883f6b0 fffff803`510c67e4 : ffffde04`8346c220 00000000`00000002 00000000`00000080 ffffde04`00000002 : nt!KiRaiseSecurityCheckFailure+0x323
ffff9280`6883f840 fffff803`510c5479 : 00000000`00000012 00000000`00989680 00000000`0000139c 00000000`000000b4 : nt!KiProcessExpiredTimerList+0x234
ffff9280`6883f930 fffff803`511c75be : ffffffff`00000000 ffffca80`90379180 ffffca80`9038a240 ffffde04`8ad3d080 : nt!KiRetireDpcList+0x4e9
ffff9280`6883fb60 00000000`00000000 : ffff9280`68840000 ffff9280`68839000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e
SYMBOL_NAME: nt!KiProcessExpiredTimerList+234
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 234
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiProcessExpiredTimerList
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {9db7945b-255d-24a1-9f2c-82344e883ab8}
Followup: MachineOwner
---------
No Events found!


redxps630
11 Legend
•
16K Posts
•
82K Points
1
February 27th, 2021 09:00
Re: what should we try out first: replacing the mobo or the RAM, or reinstalling Windows
these new crucial ram guaranteed to work for 8920 according to vendor.
try remove all new ram and install old ram. If system is rock stable, one or more of new ram is incompatible. Remove all ram, install only one new ram in DIMM1, test for stability. Chances are 1/4 new ram may be corrupted. By testing individually you isolate the bad apple. It doesn’t sound like you need to replace mobo or reinstall OS at this point.
Vic384
6 Operator
•
3.2K Posts
1
February 27th, 2021 10:00
@lambchie You could try running Memtest86. Memtest86 boots from a USB flash drive and operates independently of the operating system.
r72019
8 Professor
•
5.3K Posts
1
February 27th, 2021 11:00
Memtest is a good idea. Your PC might also have a built-in (streamlined) RAM test similar to memtest if you hit F12 on boot, and look for the ePSA hardware test option.
r72019
8 Professor
•
5.3K Posts
1
February 27th, 2021 11:00
But yeah, I would definitely test/troubleshoot the RAM new and old, before reinstalling the OS or replacing the mobo, especially since this issue came up right after you installed new RAM.
lambchie
3 Posts
0
March 1st, 2021 02:00
Thank you all for your replies. Sorry for the late update but testing all 4 RAMs took some time.
Turns out that all the 4 new RAMs behaves totally stable when used singly. However as soon as I put 2 of them in slot 1 & 3, errors show up in Memtest.
Just to make sure it's not some of the slots that are faulty I tried putting only one RAM in slot 3, no error at all.
Anyone had the same experience before? What log / info should I provide here? What can we do to investigate further?
Vic384
6 Operator
•
3.2K Posts
0
March 1st, 2021 04:00
@lambchie I don't think there is much more to investigate. I think you need to contact Crucial and tell them your problem. Perhaps you should have purchased this RAM: https://www.crucial.com/memory/ddr4/ct2k16g4dfra266/ct18793863
I don't think you could not use the extra speed of the RAM you purchased in the XPS 8920.
lambchie
3 Posts
0
March 1st, 2021 04:00
@Vic384 I see your point. The reason I bought the 3200 version is because it's somehow cheaper than the other ones like 2666 version here in Japan. If in someway down tuning the RAM would solve the problem I would love to try out first.
For further update, I just tried out the other pair of the new RAMs and it's a bluescreen again.
In short, my 4 new Crucial 16GB RAMs can all run singly, but they give my random bluescreen when going in dual channel. All 4 RAMs have been tested singly with no issue. The 2 old 8GB RAMs that came with the XPS 8920 machine make no trouble however.
speedstep
11 Legend
•
47K Posts
0
March 1st, 2021 04:00
The SPD chip on the ram can have malware
You arent using windows 10 20H2
Windows 10 Insider Preview 10.0.18362.1 (19H1_RELEASE)
There isn't support for that here.
Rootkits are un detectable. There isn’t a simple, updated virus definition file or all-encompassing antivirus tool to guard against fileless malware attacks.
Fileless malware can remain undetected because it’s memory-based, not file-based. The SPD rom is a rom it doesnt lose data from power loss or removal. The key is that fileless malware isn’t written to disk like traditional malware. Rather, fileless malware is written directly to ROM/RAM/UEFI partition memory — which is not accessable by user and doesn’t leave behind those traditional traces of its existence.
KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine.
Vic384
6 Operator
•
3.2K Posts
0
March 1st, 2021 06:00
If there is malware, the malware runs independently of Windows because Memtest 86 does not require Windows to run and the RAM is failing Memtest86.
speedstep
11 Legend
•
47K Posts
0
March 1st, 2021 07:00
REPAIR UPGRADE to 20H2 might fix except in the case of non file malware hiding in Rootkit or ROM or SPD or UEFI partition.
How to: Perform a Repair Upgrade Using the Windows 10 ISO file
https://www.microsoft.com/en-us/software-download/windows10ISO
http://answers.microsoft.com/en-us/insider/wiki/insider_wintp-insider_install/how-to-perform-a-repair-upgrade-using-the-windows/35160fbe-9352-4e70-9887-f40096ec3085