• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

@gr999,

 

No problem -and the screenshot explains what is happening.

 

It looks like your account currently does not have the attachment option in the Community editor, and the forum is also explicitly rejecting the .zip file as an unsupported file type. So, my previous instructions about simply attaching a ZIP were too optimistic -sorry about that.

 

Please don't email the dump to an address posted publicly on the forum. A minidump can contain system information that shouldn't be shared through an unknown or unofficial address.

 

We have a couple of alternatives.

 

Option 1 — OneDrive:

 

The easiest solution would be to put the ZIP containing: 081226-25609-01.dmpin your OneDrive and create a sharing link that allows anyone with the link to view/download the file. You can then post the OneDrive link in your HP Community reply.

 

If you do this, please make sure the link points specifically to the ZIP containing the minidump rather than giving access to your entire OneDrive folder.

 

Option 2 — We can continue without the dump:

 

The dump would be very useful, but we don't necessarily have to stop here.

 

The 0x139 / parameter 0x1D bugcheck already establishes that Windows detected corruption of a kernel data structure. The next useful question is whether this is happening repeatedly with the same failure pattern.

If you have another crash, please provide the corresponding BugCheck Event 1001 details and, if another minidump is created, its filename.

 

Also, the fact that Windows subsequently installed:

 

HP Inc. SoftwareComponent Driver Update — 1.87.4769.0 is worth recording, but I would not assume that update caused or fixed the problem. It occurred after the crash and could simply have been an unrelated Windows Update/HP driver delivery.

 

For now, I would leave the BIOS at F.35 and avoid changing Secure Boot settings whilst we investigate the actual crash.

 

If you can provide a OneDrive link to the minidump, however, that would be my preferred next step. A debugger analysis of the actual .dmp file could potentially tell us considerably more than Event Viewer alone.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Thank you for looking at this,

 

- System

- Provider

[ Name] Microsoft-Windows-WER-SystemErrorReporting
[ Guid] {abce23e7-de45-4366-8631-84fa6c525952}

EventID 1001

Version 1

Level 2

Task 0

Opcode 0

Keywords 0x8000000000000000

- TimeCreated

[ SystemTime] 2026-08-14T11:00:24.0778091Z

EventRecordID 219047

Correlation

- Execution

[ ProcessID] 1552
[ ThreadID] 1556

Channel System

Computer HPS01

- Security

[ UserID] S-1-5-18

- EventData

param1 0x00000139 (0x000000000000001d, 0xfffffd0cc4acb330, 0xfffffd0cc4acb288, 0x0000000000000000)
param2 C:\windows\Minidump\081426-24875-01.dmp
param3 b46e6966-4385-4204-a076-62dd2b92e3c2

HP Recommended

@gr999,

 

I apologize for the delays -I am assisting here in this Community as a volunteer, but obviously I have other responsibilities and places to go so to speak.

 

Anyways, this was excellent — this is exactly the Event Viewer entry I was hoping you would find. It confirms that Windows generated a kernel crash dump and gives us the BugCheck details.

 

The crash is 0x139, KERNEL_SECURITY_CHECK_FAILURE, with parameter 1 = 0x1D, which indicates that Windows detected corruption involving a kernel LIST_ENTRY structure. That often points toward a kernel-mode driver or other low-level software, although the BugCheck itself does not identify the culprit.

 

More importantly, Windows confirms that the actual minidump is:

 

C:\Windows\Minidump\081426-24875-01.dmp

 

Please upload that exact .dmp file to OneDrive (or another file-sharing service) and post the share link here.

 

Please don't compress it unless necessary, and make sure the link permits downloading the file.

 

The dump itself is what I'd like to examine next. With WinDbg, we can potentially determine the crash stack, the thread that detected the corruption, loaded modules/drivers, and whether there is a particular third-party driver that deserves suspicion. That should give us considerably more actionable information than Event Viewer alone.

 

One caution: please don't delete or overwrite 081426-24875-01.dmp before uploading it. That is the artifact we need.

 

How to upload the dump to OneDrive:

 

If you're not familiar with OneDrive, no problem. Please do the following:

 

  1. Open File Explorer.
  2. Copy and paste this into the address bar:

    C:\Windows\Minidump

  3. Press Enter. You should see a file named:

    081426-24875-01.dmp

  4. Right-click that file and select Copy.
  5. Open your OneDrive folder in File Explorer.
  6. Right-click inside the OneDrive folder and select Paste.
  7. Wait for the file to finish uploading/synchronizing to OneDrive. Depending on your connection, this may take a little while.

 

Then:

 

  1. Right-click 081426-24875-01.dmp in OneDrive.
  2. Select Share.
  3. Choose the option to Copy link.
  4. Make sure the link is accessible to people who have the link (rather than requiring your Microsoft account to sign in).
  5. Paste that OneDrive link into your reply here.

 

Please don't open, modify, rename, or delete the .dmp file. I need the original file as Windows created it.

 

If OneDrive isn't available on your system, that's also fine — another file-sharing service can be used. The important thing is that I can download the actual 081426-24875-01.dmp file.

 

Once I have the dump, I can analyze the crash stack and loaded drivers with a debugger. That has a much better chance of identifying what actually caused the 0x139 crash than the Event Viewer entry alone.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Hello,

ran windbg on 3 files, unable to upload .txt  file either.

 

==================================================================================

FILE_IN_CAB: 081426-24875-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
Kernel Generated Triage Dump

FAULTING_THREAD: ffffcb0faba650c0

TRAP_FRAME: fffffd0cc4acb330 -- (.trap 0xfffffd0cc4acb330)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffcb0fd521c058 rbx=0000000000000000 rcx=000000000000001d
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80098b5b1c3 rsp=fffffd0cc4acb4c0 rbp=0000000000000001
r8=0000000000000000 r9=ffffcb0fcf886fc8 r10=ffffcb0fcba33048
r11=ffffcb0f86109510 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac pe cy
nt!RtlRbRemoveNode+0x133:
fffff800`98b5b1c3 cd29 int 29h
Resetting default scope

EXCEPTION_RECORD: fffffd0cc4acb288 -- (.exr 0xfffffd0cc4acb288)
ExceptionAddress: fffff80098b5b1c3 (nt!RtlRbRemoveNode+0x0000000000000133)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 000000000000001d
Subcode: 0x1d FAST_FAIL_INVALID_BALANCED_TREE

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: hp-plugin-exec

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR: c0000409

EXCEPTION_PARAMETER1: 000000000000001d

IRP_ADDRESS: ffffcb0fae2b2010

EXCEPTION_STR: 0xc0000409

 

================================================================================

FILE_IN_CAB: 081626-25265-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
Kernel Generated Triage Dump

FAULTING_THREAD: ffffb4853c4cd080

CORRUPTING_POOL_ADDRESS: fffff800b79c54d8: Unable to get MiVisibleState
ffffb4855199c000

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: Taskmgr.exe

DPC_STACK_BASE: FFFFE50C66227FB0

 

=========================================================================

FILE_IN_CAB: 081726-24968-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
Kernel Generated Triage Dump

FAULTING_THREAD: ffff9a86e3637080

CONTEXT: ffff940232f6ec60 -- (.cxr 0xffff940232f6ec60)
rax=520e09a72a576b87 rbx=0000000000000000 rcx=0000000000000011
rdx=0000000000000000 rsi=ffff9a86928ce6c0 rdi=ffffbd8bcb3081d0
rip=fffff80276c39dc8 rsp=ffff940232f6f690 rbp=ffff940232f6f790
r8=0000000000000000 r9=0000000000000000 r10=ffffbd8bcb3081d0
r11=0000000c5c1492a8 r12=ffff9a86928ce000 r13=0000000000000000
r14=ffff9a86928ce6f0 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050203
nt!EtwpRegisterUMProvider+0x138:
fffff802`76c39dc8 482b4328 sub rax,qword ptr [rbx+28h] ds:002b:00000000`00000028=????????????????
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: hp-plugin-exec

IP_IN_PAGED_CODE:
nt!EtwpRegisterUMProvider+138
fffff802`76c39dc8 482b4328 sub rax,qword ptr [rbx+28h]

 

 

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->