Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x00000001

APC_INDEX_MISMATCH 0x00000001 and WIN32K_CRITICAL_FAILURE 0x00000164 crashes

14 min read Updated October 5, 2026 Windows Crashes & Boot Recovery

Fix it now

0x00000001 is a thread returning from kernel mode with its APC disable count unbalanced: something disabled asynchronous procedure calls and never re-enabled them. 0x00000164 is win32k failing one of its own consistency checks. Both usually point at third-party code hooking the windowing or print path.

Run these in an elevated Command Prompt: the first shows whether Driver Verifier is already switched on, the second opens Print Server Properties on the Drivers page

verifier /querysettings
rundll32 printui.dll PrintUIEntry /s /t2
  1. Work out whether the crash is tied to an action. Printing, opening one particular application, screen sharing and remote-control sessions are the four that matter, because they all cross win32k.
  2. Install every outstanding Windows update and reboot before you remove anything. Several crashes in this family have been fixed on the Windows side, and patching is quicker than diagnosing.
  3. List the software that hooks the interface: security suites with a browser or window shield, screen recorders, remote-control agents, dock and window-manager utilities, vendor printer software. Uninstall the most likely one with the vendor’s own removal tool, reboot, and repeat the action that crashed the machine.
  4. If printing is the trigger, remove the print driver and its package from the Drivers page you opened above, then reinstall the printer with an in-box or current vendor driver.
  5. Open the System log in Event Viewer and read the BugCheck entry. It records the stop code and its four parameters, which is what the next section teaches you to read.

Driver Verifier crashes the machine deliberately when it catches a violation. Run it out of hours, set verifier /bootmode resetonbootfail first so a failed boot disables it, and know how to reach Safe Mode to run verifier /reset.

If the crashes stop after patching or after removing one product, you are done. If not, the next section explains what the four parameters in the dump are telling you.

Why it happens

Asynchronous procedure calls are how the kernel interrupts a thread to run work in that thread’s context. Code that must not be interrupted that way enters a critical or guarded region, which increments a per-thread counter, and leaves it again, which decrements it. The pairing is strict. When a thread is about to return to user mode the kernel checks the counter is back where it started, and if it is not, it stops the machine.

Microsoft publishes exactly what to read. Parameter 3 of 0x00000001 is the thread’s CombinedApcDisable field, which is two 16-bit halves packed together: SpecialApcDisable in the high half and KernelApcDisable in the low half. A negative value in either half means a driver disabled that class of APC and never re-enabled it. A positive value means it enabled them too many times. Parameter 4 is the call type: 0 for a system call, 1 for a worker routine. That last one matters, because a worker routine tells you the imbalance happened on a system thread rather than on a thread your user was driving.

0x00000164 comes from a different mechanism reaching the same place. Rather than the dispatcher noticing an imbalance, win32k itself detects that its internal state is wrong and stops. Parameter 1 names the subtype, and the published list is specific enough to be useful: a region out of surface bounds, a missing critical APISET extension, a GDI sprite shape deleted without deleting the sprite, a failure to open the pointer device, a failed SAS key registration. Graphics, printing and input each have their own entry, so the parameter tells you which subsystem to look at before you touch anything.

The other three codes in this family are frequently listed together and are frequently described as interchangeable. They are not. 0x0000013C is INVALID_IO_BOOST_STATE, a thread that exited with a non-zero I/O boost state when it should have been zero. 0x00000160 is WIN32K_ATOMIC_CHECK_FAILURE, a win32k function violating an atomic check, with parameter 1 counting the functions on the stack inside that atomic operation. 0x00000197 is WIN32K_SECURITY_FAILURE, and its only published subtype is an object handle entry that did not point back to its object.

Something is hooking win32k

You have this one if The dump names a security, monitoring or remote-access driver, and the crashes follow interface work rather than disk or network load.

  1. Uninstall the product with the vendor’s own removal tool and reboot. Turning a shield off inside the product usually leaves its driver loaded, so removal is the only test that proves the point.
  2. Repeat the action that used to crash the machine before you reinstall anything.
  3. If the product is needed, install the vendor’s current build rather than the one that was on the machine.
  4. Where two products both hook the interface, keep one. Two window shields on one machine is a configuration nobody supports.

Printing is the trigger

You have this one if The machine is stable until a job is submitted, a printer is added, or the printer properties dialog is opened.

  1. Open Print Server Properties with rundll32 printui.dll PrintUIEntry /s /t2 and read the installed drivers.
  2. Remove the driver and its package for the printer involved, then reboot.
  3. Reinstall using an in-box driver or the vendor’s current package, not one carried forward from a previous machine.
  4. For printers shared from a server, check whether the server is still offering an old driver to clients and replace it there.

Print-path crashes in this family have been both caused and fixed by Windows updates in the past. Patch before you spend an afternoon on drivers.

The machine is months behind on updates

You have this one if The crash appears on a build that has not been patched in a long time, and nothing about the machine’s software changed.

  1. Install all pending cumulative updates and reboot.
  2. Update the display driver from the hardware vendor at the same time.
  3. Retest before removing any software. This ends the investigation often enough to be worth doing first.
  4. If updates will not install, fix that before anything else. You cannot rule the platform out while it is unpatched.

A display driver and win32k disagree

You have this one if 0x00000164 with a graphics module named in the dump, usually after a driver update or a change of monitor or dock.

  1. Roll the display driver back to the previous version in Device Manager and test.
  2. If rolling back helps, install the vendor’s current release rather than staying on the old one.
  3. Remove overlay and capture utilities that install their own graphics filters.
  4. Test with the dock or the second monitor disconnected, to isolate which path is involved.

A handle no longer matches its object

You have this one if 0x00000197 with parameter 1 of 0x1, which is the published subtype for a handle entry that does not point back to its object.

  1. Treat this as memory or state corruption rather than a configuration problem, and stop looking for a setting to change.
  2. Run Driver Verifier’s standard settings against the third-party drivers only: verifier /standard /driver name.sys.
  3. Test the machine’s memory, because a bit flip produces exactly this class of failure.
  4. Once you have a driver name, clear the settings with verifier /reset and take the driver to its vendor.

Full reference

Reading the parameters rather than guessing at the code

The BugCheck entry in the System log carries all four parameters. For 0x00000001 they are published as follows, and the third is the one that identifies the fault.

Parameter What it holds
1 The address of the system function or worker routine
2 The thread’s ApcStateIndex field
3 The thread’s CombinedApcDisable field: SpecialApcDisable in the high 16 bits, KernelApcDisable in the low 16
4 Call type: 0 for a system call, 1 for a worker routine

For 0x00000164 the first parameter is a failure type rather than an address, and Microsoft publishes the list. Match yours against it before you assume the crash is a graphics problem.

Parameter 1 Documented failure
0x1 Region is out of surface bounds
0x2 Operator new used to allocate memory
0x3 A critical extension APISET API is missing
0x4 A GDI sprite’s shape is being deleted without deleting the sprite
0x5 Failed to open the pointer device
0x8 A public device context holds a pointer to an object owned by a specific process
0xA / 0xB / 0xC An invalid function table index in TTFD, ATMFD or a palette
0x10 SAS key registration failed

The three codes that get filed under this one

Code Published name What it says
0x0000013C INVALID_IO_BOOST_STATE A thread exited with a non-zero I/O boost state. Parameter 1 is the thread, parameter 2 the boost state or throttle count
0x00000160 WIN32K_ATOMIC_CHECK_FAILURE A win32k function violated an ATOMICCHECK. Parameter 1 counts the functions on the stack inside the atomic operation
0x00000197 WIN32K_SECURITY_FAILURE A security failure in win32k. Subtype 0x1 is a handle entry that did not point back to its object; parameters 2 to 4 give the object type, the handle entry and the expected object

None of these three is a synonym for the other two, and none of them is a general-purpose ‘graphics crashed’ code. If your dump carries one of them, read its own parameters rather than treating it as another face of 0x00000001.

Driver Verifier without losing the machine

Driver Verifier does not find faults by watching. It applies stricter rules to the drivers you name and crashes the machine on purpose the moment one breaks a rule. That is the point, and it is why it belongs in a maintenance window.

Command What it does
verifier /standard /driver name.sys Applies the standard checks to the named drivers after the next boot. Separate several names with spaces; wildcards are not supported
verifier /querysettings Shows what will be verified after the next boot
verifier /query Shows a summary of what Driver Verifier is doing now
verifier /bootmode resetonbootfail Disables Driver Verifier on subsequent reboots if the system failed to start
verifier /reset Clears every Driver Verifier setting; nothing is verified after the next boot
verifier /volatile /flags <n> Changes settings without a reboot, taking effect immediately

Never turn Driver Verifier on for all drivers on a production machine. Name the third-party drivers you actually suspect. Verifying everything at once slows the machine badly and gives you a crash you cannot attribute.

Where the evidence lives

  • The System log in Event Viewer records a BugCheck entry with the stop code and all four parameters. This is enough to identify the subtype without a debugger.
  • Windows Error Reporting entries alongside it frequently name a module, which is usually the fastest route to a suspect.
  • The memory dump under the Windows folder holds the stack. !analyze in a debugger reads it, and Microsoft points at !apc for inspecting the APCs on the thread.
  • Print Server Properties, opened with rundll32 printui.dll PrintUIEntry /s /t2, lists every print driver installed and lets you remove a driver package rather than just the printer.

When the obvious suspects are all clear

  • Check whether the machine has two products doing the same job. A second window or browser shield is the most common overlooked cause on managed desktops.
  • Check the parameter 4 value on 0x00000001. A worker routine puts the fault on a system thread, which shifts suspicion away from anything the user was doing at the time.
  • Check the graphics driver against the vendor’s list for the exact Windows build. A driver that was fine before a feature update is a plausible suspect after one.
  • Test the memory. Handle and state corruption codes such as 0x00000197 come from bad memory as readily as from bad drivers.
  • If the machine is a virtual desktop, check the hypervisor’s own graphics and input drivers. They hook the same path as anything else.

When a licence is the actual fix

If the product hooking win32k is a consumer security suite on a business machine, or an agent nobody is licensed for any more, the durable answer is to standardise on one managed platform rather than layering another. Microsoft Defender Antivirus is already in Windows at no extra cost, so removing the offending product on its own is a legitimate outcome. Microsoft Defender for Business adds central management, policy and reporting on top of what is already there, which is a licence for management rather than for another driver stack. Arco can quote it against your device count and tell you what you already hold.

Every code this article covers

Code What it points at Source
0x00000001 APC_INDEX_MISMATCH: a thread reached the end of a system call or worker routine with its kernel APC disable count unbalanced. Parameter 3 shows which half is wrong Microsoft Learn
0x00000164 WIN32K_CRITICAL_FAILURE: win32k hit a critical failure. Parameter 1 names the subtype, from region validation through sprite deletion to pointer device failure Microsoft Learn
0x0000013C INVALID_IO_BOOST_STATE: a thread exited with an invalid I/O boost state, which should be zero at exit Microsoft Learn
0x00000160 WIN32K_ATOMIC_CHECK_FAILURE: a win32k function violated an ATOMICCHECK. Parameter 1 counts the functions on the stack inside the atomic operation Microsoft Learn
0x00000197 WIN32K_SECURITY_FAILURE: a security failure detected in win32k. Subtype 0x1 is an object handle entry that did not point back to its object Microsoft Learn

Confirm the fix worked

  1. Repeat the exact action that used to crash the machine, several times, over a working day.
  2. Check the System log and confirm no new BugCheck entries since the change.
  3. Confirm Windows Update reports the machine as up to date, so the platform is genuinely ruled out.
  4. Run verifier /querysettings and confirm no drivers are left under verification.
  5. If you removed a print driver, print to that device again and open its properties dialog.

Questions people ask about this

Is this a Windows bug or a third-party bug?

It can be either, which is why patching comes first. Windows has shipped fixes for crashes in this family, particularly around printing. Once the machine is fully patched and still crashing, the remaining suspects are the drivers hooking the same path.

Can I read the dump without installing a debugger?

You can get most of the value from Event Viewer. The BugCheck entry in the System log records the stop code and all four parameters, and Windows Error Reporting entries often name a module. For 0x00000164 the first parameter alone tells you which win32k subsystem failed, which is usually enough to pick a suspect.

Do these five codes all mean the same thing?

No, and treating them as interchangeable is how people end up chasing the wrong subsystem. 0x00000001 is an APC counter imbalance, 0x00000164 is a win32k consistency check, 0x0000013C is an I/O boost state left non-zero at thread exit, 0x00000160 is an atomic check violation and 0x00000197 is a handle that no longer matches its object.

Do I need to buy anything?

No. Updates, driver removals and print driver replacement are all free. A licence only enters the conversation if you decide to consolidate several security agents into one managed product, which is a management decision rather than a fix for this stop code.

Will a repair install fix it?

Only if damaged system files are the cause, which is unusual here. It also reinstalls the third-party software that is the more likely culprit, so remove the hooking product first and keep the repair install as a later step.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Windows RE update fails with 0x80070643 – recovery partition too small License Error RESOURCE_OWNER_POINTER_INVALID 0x00000132 and lock ownership crashes License Error SYSTEM_THREAD_EXCEPTION_NOT_HANDLED 0x0000007E on Windows 10 and 11 License Error There was a problem resetting your PC – error 0x80070003 in Reset This PC
โ† Back to Knowledge Base