SECURITY_SYSTEM

Code: 0x29 (41)

As HRESULT:As NTSTATUS:

Description

The SECURITY_SYSTEM bug check has a value of 0x00000029.

This bug check appears very infrequently.

Important

This article is for programmers. If you're a customer who has received a blue screen error code while using your computer, see Troubleshoot blue screen errors.

Resolution

The !analyze debug extension displays information about the bug check and can be helpful in determining the root cause.

Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.

Associated Modules

ModuleCodeFound inDescription
EhStorAuthn.exe0x297Configuration error. Verify the device is configured correctly and the required certificates are available on the system.
EventCreate.exe0x2978.11011%1
cipher.exe0x2978.11011Your .PFX file was created successfully.
compact.exe0x291011Skipping virtual file %1
dsreg.dll0x291011Unable to remove account %2 from group %1. Error: %3
dssec.dll0x2978.11011Peek computer journal
ehepgres.dll0x297%1
hvloader.dll0x2911Hypervisor launch failed; Either VMX not present or not enabled in BIOS.
hvservice.sys0x2910Hypervisor launch failed; Either VMX not present or not enabled in BIOS.
nslookup.exe0x2978.11011*** Can't find server name for address %1: %2
pshed.dll0x291011A processs was terminated due to an uncorrected hardware error. Process ID: %1 Image name: %2
reagentc.exe0x298.11011%1: Invalid index.
sc.exe0x2978.11011[SC] Tag = %1
w32time.dll0x291011The time service has been configured to use one or more input providers, however, none of the input providers are still running. The time service has no source of accurate time.
webservices.dll0x2978.11011The URL matching options '%1' were invalid.
wecutil.exe0x2978.11011Create a remote subscription. Usage: wecutil { cs | create-subscription } CONFIGURATION_FILE [/OPTION:VALUE [/OPTION:VALUE] ...] CONFIGURATION_FILE String that specifies the path to the XML file that contains subscription configuration. The path can be absolute or relative to the current directory. Options: You can use either the short (i.e. /cun) or long (i.e. /CommonUserName) version of the option names. Options and their values are case-insensitive. /cun:USERNAME (CommonUserName) Sets shared user credential to be used for event sources that do not have their own user credentials. This option applies to collector initiated subscriptions only. Note: if this option is specified, UserName/UserPassword settings for individual event sources from the configuration file are ignored. If you want to use different credential for a specific event source, use ss (set-subscription) command to set it for the event source. /cup:PASSWORD (CommonUserPassword) Sets the user password for the shared user credential. When PASSWORD is set to * (asterisk), the password is read from the console. This option is only valid when /cun (CommonUserName) option is specified. Example: Create a collector initiated subscription to forward events from the Application event log of a remote computer mySource.myDomain.com to ForwardedEvents log. wecutil cs ci_subscription.xml Content of ci_subscription.xml: SampleCISubscription CollectorInitiated Collector Initiated Subscription Sample true http://schemas.microsoft.com/wbem/wsman/1/windows/EventLog Custom 20 60000 thisMachine.myDomain.com 2010-01-01T00:00:00.000Z ]]> false http RenderedText ForwardedEvents Default
mySource.myDomain.com
myUserName
Example: Create a source initiated subscription to forward events from the Application event log of a remote computer mySource.myDomain.com to ForwardedEvents log. wecutil cs si_subscription.xml Content of si_subscription.xml: SampleSISubscription SourceInitiated Source Initiated Subscription Sample true http://schemas.microsoft.com/wbem/wsman/1/windows/EventLog Custom 1 1000 2018-01-01T00:00:00.000Z ]]> true http RenderedText ForwardedEvents O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS) Note, that when creating a source initiated subscription, if AllowedSourceDomainComputers, AllowedSourceNonDomainComputers/AllowedIssuerCAList, AllowedSubjectList, and DeniedSubjectList are all empty, then a default will be provided for AllowedSourceDomainComputers - O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS). This SDDL default grants members of the Domain Computers domain group, as well as the local Network Service group (for local forwarder), the ability to raise events for this subscription.
wevtutil.exe0x2978.11011Failed to open channel enumeration.
whealogr.dll0x2971011A corrected hardware error has occurred. Component: %5 Error Source: %1 The details view of this entry contains further information.
win32k.sys0x2978.1TitleText
win32kbase.sys0x291011TitleText
20 entries