Location:
State:
Carrier
Country
Status

BSOD at non-specific times, KERNEL_SECURITY_CHECK_FAILURE


Code:
KERNEL_SECURITY_CHECK_FAILURE (139)  A kernel component has corrupted a critical data structure.  The corruption  could potentially allow a malicious user to gain control of this machine.  Arguments:  Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).  Arg2: ffffd001c37db0f0, Address of the trap frame for the exception that caused the bugcheck  Arg3: ffffd001c37db048, Address of the exception record for the exception that caused the bugcheck  Arg4: 0000000000000000, Reserved    Debugging Details:  ------      TRAP_FRAME:  ffffd001c37db0f0 -- (.trap 0xffffd001c37db0f0)  NOTE: The trap frame does not contain all registers.  Some register values may be zeroed or incorrect.  rax=ffffe0007cecb311 rbx=0000000000000000 rcx=0000000000000003  rdx=ffffe0007cecb3c4 rsi=0000000000000000 rdi=0000000000000000  rip=fffff801bb7c469c rsp=ffffd001c37db280 rbp=0000000000000000   r8=ffffe0007d8d6c48  r9=0000000000000000 r10=00000000fffffff8  r11=0000000000000000 r12=0000000000000000 r13=0000000000000000  r14=0000000000000000 r15=0000000000000000  iopl=0         nv up di ng nz ac pe cy  nt! ?? ::FNODOBFM::`string'+0x5679c:  fffff801`bb7c469c cd29            int     29h  Resetting default scope    EXCEPTION_RECORD:  ffffd001c37db048 -- (.exr 0xffffd001c37db048)  ExceptionAddress: fffff801bb7c469c (nt! ?? ::FNODOBFM::`string'+0x000000000005679c)     ExceptionCode: c0000409 (Security check failure or stack buffer overrun)    ExceptionFlags: 00000001  NumberParameters: 1     Parameter[0]: 0000000000000003    DEFAULT_BUCKET_ID:  LIST_ENTRY_CORRUPT    BUGCHECK_STR:  0x139    PROCESS_NAME:  System    CURRENT_IRQL:  1    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.    EXCEPTION_PARAMETER1:  0000000000000003    ANALYSIS_VERSION: 6.3.9600.17336 (debuggers(dbg).150226-1500) x86fre    LAST_CONTROL_TRANSFER:  from fffff801bb769ca9 to fffff801bb75f2e0    STACK_TEXT:    ffffd001`c37dadc8 fffff801`bb769ca9 : 00000000`00000139 00000000`00000003 ffffd001`c37db0f0 ffffd001`c37db048 : nt!KeBugCheckEx  ffffd001`c37dadd0 fffff801`bb769fd0 : 00000000`00000001 ffffe000`7dd491b0 ffffe000`7d2d5c10 ffffe000`7dd49060 : nt!KiBugCheckDispatch+0x69  ffffd001`c37daf10 fffff801`bb7691f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiFastFailDispatch+0xd0  ffffd001`c37db0f0 fffff801`bb7c469c : 00000000`00000000 ffffe000`7d7ac0e8 ffffd001`c31df180 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0xf4  ffffd001`c37db280 fffff801`e62d54f1 : 00000000`00000000 00000000`00000000 ffffe000`7dd35050 ffffd001`c37db6b8 : nt! ?? ::FNODOBFM::`string'+0x5679c  ffffd001`c37db2c0 fffff801`e62fa610 : ffffe000`7d8c4030 ffffe000`7cecb3c4 ffffe000`7cecb3c4 ffffe000`7cfaa060 : ts_arnusbx+0x54f1  ffffd001`c37db2f0 fffff801`e638df8e : ffffe000`7cecb3f4 00000000`00000000 00000000`00000000 ffffd001`c37db6b8 : ts_arnusbx+0x2a610  ffffd001`c37db330 fffff801`e63a80b3 : ffffe000`7cecb3f4 fffff801`e4e9a740 00000000`00000000 ffffe000`7dd35050 : ts_arnusbx+0xbdf8e  ffffd001`c37db360 fffff801`e638f153 : ffffe000`7cecb3f4 00000000`00000000 ffffe000`00000000 ffffffff`fd050f80 : ts_arnusbx+0xd80b3  ffffd001`c37db390 fffff801`e638eccc : ffffe000`7cecb3f4 00000000`99f6e581 00000000`00000000 fffff780`00000008 : ts_arnusbx+0xbf153  ffffd001`c37db3c0 fffff801`e6377365 : ffffe000`7cfaa030 fffff801`00000017 ffffd001`c37db464 fffff801`00000004 : ts_arnusbx+0xbeccc  ffffd001`c37db420 fffff801`e637709b : ffffe000`7d7dd030 fffff801`0000a258 ffffe000`7d7dd030 ffffe000`0000a258 : ts_arnusbx+0xa7365  ffffd001`c37db480 fffff801`e6406acd : ffffe000`7d7dd030 ffffe000`0000a258 ffffe000`0ccb5380 00000000`00000003 : ts_arnusbx+0xa709b  ffffd001`c37db4c0 fffff801`e640706b : ffffe000`7d7dd030 ffffe000`7d7e9140 ffffe000`7d7de9c8 ffffd001`c37db658 : ts_arnusbx+0x136acd  ffffd001`c37db610 fffff801`e63ee07b : ffffe000`7d7dd030 ffffe000`7d7e9140 ffffe000`7d7de9c8 fffff801`e63700f2 : ts_arnusbx+0x13706b  ffffd001`c37db6e0 fffff801`e63fb064 : ffffe000`7d7dd030 ffffe000`7d7e9140 ffffe000`7d7de9c8 fffff801`000000f2 : ts_arnusbx+0x11e07b  ffffd001`c37db740 fffff801`e63fa00f : ffffe000`7d7dd030 ffffd001`c37db9f0 ffffe000`7d7de9c8 fffff801`00000000 : ts_arnusbx+0x12b064  ffffd001`c37db7c0 fffff801`e6399095 : ffffe000`7d7dd030 ffffe000`00000001 ffffd001`c37db9f0 ffffe000`00000000 : ts_arnusbx+0x12a00f  ffffd001`c37db850 fffff801`e639a745 : ffffe000`7d7d8030 ffffd001`c37db9f0 ffffe000`00000000 ffffe000`7d7d8030 : ts_arnusbx+0xc9095  ffffd001`c37db930 fffff801`e637dd3e : ffffe000`7d7d8030 ffffd001`c37db9f0 ffffd001`c37dbb80 fffff801`e6387900 : ts_arnusbx+0xca745  ffffd001`c37db9c0 fffff801`e63274a2 : ffffe000`7cfb0030 00000000`00000000 00000000`0003dd61 00000000`00000000 : ts_arnusbx+0xadd3e  ffffd001`c37dba20 fffff801`e63373ae : ffffe000`7cfb0030 ffffe000`7cfb0880 00000000`00000a20 00000000`00000000 : ts_arnusbx+0x574a2  ffffd001`c37dba60 fffff801`e63749a1 : ffffe000`7ddf8030 fffff801`e648c888 ffffe000`7d944da0 fffff801`e6487110 : ts_arnusbx+0x673ae  ffffd001`c37dbab0 fffff801`e6337063 : ffffe000`7d944da0 00000000`00000003 ffffe000`7bbfd180 ffffe000`7bbfd140 : ts_arnusbx+0xa49a1  ffffd001`c37dbb10 fffff801`e63746db : ffffe000`7ddf8030 fffff801`e6480002 ffffe000`7d940000 00000000`00000000 : ts_arnusbx+0x67063  ffffd001`c37dbb70 fffff801`e637375c : ffffe000`7d944da0 fffff801`e4a10002 00000000`00000000 00000000`00000000 : ts_arnusbx+0xa46db  ffffd001`c37dbbc0 fffff801`e63738a6 : ffffe000`7d944e08 ffffe000`00000002 00000000`00000000 ffffe000`7bbfd180 : ts_arnusbx+0xa375c  ffffd001`c37dbc00 fffff801`bb68b6c4 : ffffe000`7d944e08 ffffe000`7d9309f0 fffff801`00046000 00000000`00000000 : ts_arnusbx+0xa38a6  ffffd001`c37dbc40 fffff801`bb68add9 : fffff801`bb9ea340 ffffe000`7bbfd040 fffff801`bb68b5d0 fffff801`00046000 : nt!IopProcessWorkItem+0xf4  ffffd001`c37dbcb0 fffff801`bb6f7558 : ffffe000`7ac95480 00000000`00000080 fffff801`bb9ea340 ffffe000`7bbfd040 : nt!ExpWorkerThread+0xe9  ffffd001`c37dbd40 fffff801`bb7643c6 : fffff801`bb974180 ffffe000`7bbfd040 fffff801`bb9ea740 00000000`00000000 : nt!PspSystemThreadStartup+0x58  ffffd001`c37dbda0 00000000`00000000 : ffffd001`c37dc000 ffffd001`c37d6000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16      STACK_COMMAND:  kb    FOLLOWUP_IP:   ts_arnusbx+54f1  fffff801`e62d54f1 4883c428        add     rsp,28h    SYMBOL_STACK_INDEX:  5    SYMBOL_NAME:  ts_arnusbx+54f1    FOLLOWUP_NAME:  MachineOwner    MODULE_NAME: ts_arnusbx    IMAGE_NAME:  ts_arnusbx.sys    DEBUG_FLR_IMAGE_TIMESTAMP:  51ed677f    FAILURE_BUCKET_ID:  0x139_3_ts_arnusbx+54f1    BUCKET_ID:  0x139_3_ts_arnusbx+54f1    ANALYSIS_  KM    FAILURE_ID_HASH_STRING:  km:0x139_3_ts_arnusbx+54f1    FAILURE_ID_HASH:  {c5b7c09d-ff5f-1b00-2738-89553309d60c}    Followup: MachineOwner  ---

Hi KarmaPoliceman,

Welcome to the 10blog.

I do not know where the driver ts_arnusbx.sys is used for unfortunately, so please read BSOD Posting Instructions & How to upload files

BSOD at non-specific times, KERNEL_SECURITY_CHECK_FAILURE