Unsolved

3 Posts

1640

February 27th, 2021 09:00

XPS 8920, random blue screen after new RAM installed

Hi all!

Our XPS 8920 has been going into bluescreen randomly since we installed new RAM sticks. Error codes are different every time. It happens randomly between minutes and hours.

The 4 RAM sticks are all the same model from Crucial (https://www.crucial.com/memory/ddr4/ct2k16g4dfd832a).

We thought if the cause was not the new RAMs, then it might be the mobo that is becoming unstable. I would like to show you one of the most recent WinDbg log below and would love to get some advise from you, what should we try out first: replacing the mobo or the RAM, or reinstalling Windows?

Thank you for your help!

Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 18362 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base = 0xfffff803`51000000 PsLoadedModuleList = 0xfffff803`51445e90
Debug session time: Sun Feb 28 01:43:05.747 2021 (UTC + 9:00)
System Uptime: 0 days 0:02:11.620
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.................................................
Loading User Symbols

Loading unloaded module list
....................
For analysis of this file, run !analyze -vnt!KeBugCheckEx:
fffff803`511c3a90 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffff9280`6883f390=0000000000000139
2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff92806883f6b0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff92806883f608, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 4874

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-S240J4S

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.mSec
    Value: 13328

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 84

    Key  : Analysis.System
    Value: CreateObject

    Key  : WER.OS.Branch
    Value: 19h1_release

    Key  : WER.OS.Timestamp
    Value: 2019-03-18T12:02:00Z

    Key  : WER.OS.Version
    Value: 10.0.18362.1


ADDITIONAL_XML: 1

OS_BUILD_LAYERS: 1

BUGCHECK_CODE:  139

BUGCHECK_P1: 3

BUGCHECK_P2: ffff92806883f6b0

BUGCHECK_P3: ffff92806883f608

BUGCHECK_P4: 0

TRAP_FRAME:  ffff92806883f6b0 -- (.trap 0xffff92806883f6b0)NOTE: The trap frame does not contain all registers.Some register values may be zeroed or incorrect.rax=ffffde0482118268 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000005 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803510c67e4 rsp=ffff92806883f840 rbp=ffffde048346c250
 r8=0000000000000102  r9=0000000000000000 r10=fffff8035113e4e0
r11=ffff92806883f820 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe cy
nt!KiProcessExpiredTimerList+0x234:
fffff803`510c67e4 cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  ffff92806883f608 -- (.exr 0xffff92806883f608)ExceptionAddress: fffff803510c67e4 (nt!KiProcessExpiredTimerList+0x0000000000000234)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY 

PROCESS_NAME:  System

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000003

EXCEPTION_STR:  0xc0000409

STACK_TEXT:  
ffff9280`6883f388 fffff803`511d5929     : 00000000`00000139 00000000`00000003 ffff9280`6883f6b0 ffff9280`6883f608 : nt!KeBugCheckEx
ffff9280`6883f390 fffff803`511d5d50     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffff9280`6883f4d0 fffff803`511d40e3     : 00000000`00001000 00000000`00000002 00000000`00000000 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffff9280`6883f6b0 fffff803`510c67e4     : ffffde04`8346c220 00000000`00000002 00000000`00000080 ffffde04`00000002 : nt!KiRaiseSecurityCheckFailure+0x323
ffff9280`6883f840 fffff803`510c5479     : 00000000`00000012 00000000`00989680 00000000`0000139c 00000000`000000b4 : nt!KiProcessExpiredTimerList+0x234
ffff9280`6883f930 fffff803`511c75be     : ffffffff`00000000 ffffca80`90379180 ffffca80`9038a240 ffffde04`8ad3d080 : nt!KiRetireDpcList+0x4e9
ffff9280`6883fb60 00000000`00000000     : ffff9280`68840000 ffff9280`68839000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e


SYMBOL_NAME:  nt!KiProcessExpiredTimerList+234

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  234

FAILURE_BUCKET_ID:  0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiProcessExpiredTimerList

OS_VERSION:  10.0.18362.1

BUILDLAB_STR:  19h1_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {9db7945b-255d-24a1-9f2c-82344e883ab8}

Followup:     MachineOwner
---------

 

11 Legend

 • 

16K Posts

 • 

82K Points

February 27th, 2021 09:00

Re: what should we try out first: replacing the mobo or the RAM, or reinstalling Windows

these new crucial ram guaranteed to work for 8920 according to vendor.

try remove all new ram and install old ram. If system is rock stable, one or more of new ram is incompatible. Remove all ram, install only one new ram in DIMM1, test for stability.  Chances are 1/4 new ram may be corrupted.  By testing individually you isolate the bad apple.  It doesn’t sound like you need to replace mobo or reinstall OS at this point.

6 Operator

 • 

3.2K Posts

February 27th, 2021 10:00

@lambchie You could try running Memtest86. Memtest86 boots from a USB flash drive and operates independently of the operating system. 

8 Professor

 • 

5.3K Posts

February 27th, 2021 11:00

Memtest is a good idea.  Your PC might also have a built-in (streamlined) RAM test similar to memtest if you hit F12 on boot, and look for the ePSA hardware test option.

8 Professor

 • 

5.3K Posts

February 27th, 2021 11:00

But yeah, I would definitely test/troubleshoot the RAM new and old, before reinstalling the OS or replacing the mobo, especially since this issue came up right after you installed new RAM.

3 Posts

March 1st, 2021 02:00

Thank you all for your replies. Sorry for the late update but testing all 4 RAMs took some time.

Turns out that all the 4 new RAMs behaves totally stable when used singly. However as soon as I put 2 of them in slot 1 & 3, errors show up in Memtest.

Just to make sure it's not some of the slots that are faulty I tried putting only one RAM in slot 3, no error at all.

Anyone had the same experience before? What log / info should I provide here? What can we do to investigate further?

6 Operator

 • 

3.2K Posts

March 1st, 2021 04:00

@lambchie I don't think there is much more to investigate. I think you need to contact Crucial and tell them your problem. Perhaps you should have purchased this RAM: https://www.crucial.com/memory/ddr4/ct2k16g4dfra266/ct18793863

I don't think you could not use the extra speed of the RAM you purchased in the XPS 8920.

3 Posts

March 1st, 2021 04:00

@Vic384 I see your point. The reason I bought the 3200 version is because it's somehow cheaper than the other ones like 2666 version here in Japan. If in someway down tuning the RAM would solve the problem I would love to try out first.

For further update, I just tried out the other pair of the new RAMs and it's a bluescreen again.

In short, my 4 new Crucial 16GB RAMs can all run singly, but they give my random bluescreen when going in dual channel. All 4 RAMs have been tested singly with no issue. The 2 old 8GB RAMs that came with the XPS 8920 machine make no trouble however.

 

11 Legend

 • 

47K Posts

March 1st, 2021 04:00

The SPD chip on the ram can have malware

You arent using windows 10 20H2

Windows 10 Insider Preview 10.0.18362.1 (19H1_RELEASE)

There isn't support for that here.

Rootkits are un detectable. There isn’t a simple, updated virus definition file or all-encompassing antivirus tool to guard against fileless malware attacks.

Fileless malware can remain undetected because it’s memory-based, not file-based. The SPD rom is a rom it doesnt lose data from power loss or removal. The key is that fileless malware isn’t written to disk like traditional malware. Rather, fileless malware is written directly to ROM/RAM/UEFI partition memory — which is not accessable by user and doesn’t leave behind those traditional traces of its existence.

KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine.

 

6 Operator

 • 

3.2K Posts

March 1st, 2021 06:00

If there is malware, the malware runs independently of Windows because Memtest 86 does not require Windows to run and the RAM is failing Memtest86.

11 Legend

 • 

47K Posts

March 1st, 2021 07:00

REPAIR UPGRADE to 20H2 might fix except in the case of non file malware hiding in Rootkit or ROM or SPD or UEFI partition.

How to: Perform a Repair Upgrade Using the Windows 10 ISO file

https://www.microsoft.com/en-us/software-download/windows10ISO

 

http://answers.microsoft.com/en-us/insider/wiki/insider_wintp-insider_install/how-to-perform-a-repair-upgrade-using-the-windows/35160fbe-9352-4e70-9887-f40096ec3085

 

No Events found!

Top