Fix it now
These four stops are lock accounting failures: an invalid resource owner pointer, a resource released by a thread that never owned it, a thread terminated with AutoBoost lock entries still held, or a thread that exited with an asynchronous procedure call pending. On a virtualisation host the culprit is nearly always a file system filter driver.
fltmc filters
verifier /querysettings
- Confirm the host is keeping dumps. In System Properties, Advanced, Startup and Recovery, set debugging information to Automatic or Kernel memory dump.
- Open the newest dump in the Windows debugger and run
!analyze -v. Note the module it names; that name is the whole point of the exercise. - Match every third-party filter in the
fltmc filtersoutput to a product you know is installed. Antivirus, backup, encryption and data loss prevention agents all appear here. - Check the named driver against its vendor’s supported platform list for the exact Windows Server build you are running, and update it.
- Where two products provide overlapping filters, remove one with the vendor’s own uninstaller, reboot, and confirm with
fltmc filtersthat the filter has actually gone.
For 0x00000020 read parameter 2, the thread’s APC disable count. Microsoft states that a negative value means a driver disabled APCs without re-enabling them and a positive value means the reverse, which is the fastest route to the offending code path.
If the host is stable after updating or removing the driver the dump named, you are done. If it is not, the next section explains what the kernel was checking and which of the four codes you have.
Why it happens
Windows uses executive resources to arbitrate shared access to kernel structures. A resource records which thread owns it, whether that ownership is shared or exclusive, and who is waiting. Alongside them the kernel runs AutoBoost, which tracks lock ownership so that a thread holding a lock can be given a temporary priority lift when something more important is waiting on it. Both mechanisms depend on ownership records that describe reality.
Each of these four stops is the moment a record stopped describing reality. 0x00000132 says an invalid resource owner pointer was supplied, and its parameters hand you the resource, its owner table, the current thread and the pointer that was wrong. 0x000000E3 is blunter: a thread tried to release a resource it did not own. 0x00000153 says a thread was terminated before it had freed all its AutoBoost lock entries, which the documentation attributes to a thread relying on another thread to release its lock, or to inconsistent flags passed to the lock package. 0x00000020 says an asynchronous procedure call was still pending when a thread exited.
The kernel cannot carry on from any of them. Ownership records are what guarantee two pieces of code are not modifying the same structure at once, so continuing on records known to be wrong is worse than stopping. That is why there is no repair to apply on the machine: the fix is always to identify the driver that broke the pairing.
They cluster on virtualisation hosts for a structural reason. A host runs very few applications but a great many filter drivers, all intercepting file and storage operations at high volume against cluster shared volumes and multi-terabyte virtual disk files. That is a workload most vendors test less thoroughly than a file server, and it is where the bugs surface.
A filter driver that predates the Windows build
You have this one if The analysis names a third-party driver older than the Windows Server release on the host, or the host was upgraded recently and the agent was not.
- Find the driver’s version from the .sys file’s properties and its vendor from the filter name in
fltmc filters. - Check the vendor’s compatibility statement for your exact Windows Server release and build.
- Upgrade the agent to a version the vendor supports on that build.
- Where the vendor does not support the build at all, that is your answer. No configuration bridges that gap.
Two products competing in the same path
You have this one if fltmc filters lists two antivirus minifilters, or an antivirus and a backup filter at adjacent altitudes, and the stops began when the second product was deployed.
- Decide which product owns which job on this host and remove the other properly, with its own removal tool.
- Apply both vendors’ documented exclusions for virtualisation: cluster shared volume paths, virtual disk and checkpoint files, and the cluster database.
- Retest through a full backup cycle before declaring it fixed.
Two real-time scanning engines is not twice the protection. It is two sets of filters interleaving in a path neither vendor tested against the other.
Changed block tracking or snapshot handling in a backup agent
You have this one if Stops line up with backup jobs, snapshot creation or snapshot removal, and stop when backups are paused.
- Correlate the crash timestamps with the backup schedule. If they match, you have your candidate.
- Update the backup agent including its kernel components, which some products ship separately from the management agent.
- As a diagnostic, disable changed block tracking and run a full backup to see whether the host stays up.
- Send the dump to the backup vendor. A lock ownership fault in their driver is theirs to fix.
A hardware driver or a genuine Windows defect
You have this one if The analysis names a storage, RAID or multipath driver, or only Microsoft binaries appear on a fully patched host with third-party agents removed.
- For a hardware driver, match firmware and driver to the vendor’s tested combination and apply it identically on every node.
- For Microsoft binaries, install the latest cumulative update. Faults of this kind are often fixed quietly in servicing.
- Then open a support case with the dump. This is the one branch where you should stop changing things and hand it over.
Full reference
Reading the four codes apart
| Stop code | Name | What it states |
|---|---|---|
| 0x00000132 | RESOURCE_OWNER_POINTER_INVALID | An invalid resource owner pointer was supplied. Parameters: the resource, its owner table, the current thread, the owner pointer |
| 0x000000E3 | RESOURCE_NOT_OWNED | A thread tried to release a resource it did not own. Parameters: the resource address, the thread address, the owner table |
| 0x00000153 | KERNEL_LOCK_ENTRY_LEAKED_ON_THREAD_TERMINATION | A thread was terminated before freeing all its AutoBoost lock entries. Parameter 3 says how the entry was wrong, including a residual boost |
| 0x00000020 | KERNEL_APC_PENDING_DURING_EXIT | An APC was still pending when a thread exited. Parameter 2 is the APC disable count, parameter 3 the IRQL |
Parameter 2 of 0x00000020 is the one to read first on any of these. The count is decremented when a driver calls KeEnterCriticalRegion, FsRtlEnterFileSystem or acquires a mutex, and incremented when it calls the matching KeLeaveCriticalRegion, KeReleaseMutex or FsRtlExitFileSystem. Because those calls should always pair, the count should be zero at thread exit. A non-zero value tells you which half of the pair a driver skipped.
Working out which filters are loaded
| Command | Purpose |
|---|---|
fltmc filters |
Lists the loaded file system minifilters with their altitudes |
!analyze -v |
The debugger command that performs the initial bugcheck analysis and names the faulting module |
verifier /standard /driver a.sys b.sys |
Enables the standard verification options against a named list of drivers, from the next boot |
verifier /querysettings |
Shows what will be verified after the next boot |
verifier /reset |
Clears all Driver Verifier settings so nothing is verified after the next boot |
Driver Verifier deliberately bugchecks the machine on the first violation it finds. Enable it for a small, named set of third-party drivers only, out of hours, and be certain you can reach Safe Mode to run verifier /reset before you start.
Removing an agent properly
- Take the host out of service and drain its virtual machines first. A stop during removal is not unusual.
- Use the vendor’s dedicated removal utility rather than Programs and Features. A normal uninstall commonly leaves the minifilter registered.
- Reboot, then run
fltmc filtersand confirm the filter is absent rather than merely idle. - Only then install whatever is replacing it, and confirm the replacement’s filter appears where you expect.
When the filter list is clean and it still stops
- Check the storage path. A multipath, RAID or host bus adapter driver mismatched against its firmware produces exactly this class of fault under load, and the dump names the module.
- Apply the latest cumulative update to the host before opening a case. Lock accounting defects are routinely fixed in servicing without a public note.
- Compare nodes. If one node in a cluster stops and the others do not, diff their driver versions before you diff anything else.
- Keep every dump. A single dump gives you one module name; three dumps that all name the same module give you a support case the vendor cannot deflect.
When a licence is the actual fix
Where the dump names an endpoint or backup driver that the vendor no longer builds for your Windows Server version, no configuration change will fix it. You need an agent still developed and tested against the build in front of you, and very often that is a newer version of what you already own, at no cost. Microsoft Defender Antivirus is included with Windows Server and is supported on host operating systems, so if central policy and reporting are not requirements, removing the failing product and leaving Defender in place is a legitimate outcome. Where you do need managed policy, tuned exclusions and reporting across several hosts, Bitdefender GravityZone Business Security is one of the products we supply, and we will check its current supported platform list against your Windows Server version and roles before you commit. Be clear about what the licence does: getting onto a supported, maintained agent is what removes this class of fault, and the licence is only the means.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x00000132 |
RESOURCE_OWNER_POINTER_INVALID: an invalid resource owner pointer was supplied | Microsoft Learn |
0x000000E3 |
RESOURCE_NOT_OWNED: a thread tried to release a resource it did not own | Microsoft Learn |
0x00000153 |
KERNEL_LOCK_ENTRY_LEAKED_ON_THREAD_TERMINATION: a thread was terminated before it had freed all its AutoBoost lock entries | Microsoft Learn |
0x00000020 |
KERNEL_APC_PENDING_DURING_EXIT: an asynchronous procedure call was still pending when a thread exited | Microsoft Learn |
Confirm the fix worked
- Run the host through a complete backup cycle and a full business day without a stop.
- Run
fltmc filtersand confirm the filter set is what you intended, with no leftovers from a removed product. - Confirm the agent you updated reports its new version in its own management console.
- Confirm no new dump has appeared in the Windows folder or its Minidump subfolder since the change.
- Run
verifier /querysettingsand confirm nothing is left under verification.
Questions people ask about this
Do I need special tools to read the dump?
The Windows debugger is a free download from Microsoft and !analyze -v is a single command. You only need the module name it reports. Most endpoint and backup vendors will also read a dump for you as part of a support case.
Should I just uninstall the antivirus and leave it off?
Not as a permanent answer, but removing it as a diagnostic step is entirely reasonable. Microsoft Defender Antivirus is present on Windows Server and provides real protection, so removing a third-party agent leaves the host covered rather than exposed.
Why does only the host stop and never the guests?
Filter drivers on the host run in the parent partition and see every operation against the virtual disks. The guests have their own stacks and never touch the failing driver. That asymmetry is itself a clue about where to look.
Is 0x00000153 different from the other three?
Slightly. It is specifically about AutoBoost lock entries not being freed before a thread ended, and Microsoft names two causes: a thread relying on another thread to release its lock, or inconsistent flags passed to the lock package. Both are driver bugs, but it narrows the search to code using AutoBoost-tracked locks.
Will buying a different security product fix this?
Only if the current one is genuinely unsupported on your build and cannot be updated. Read the dump first and find out which case you are in, because very often the fix is a newer version of what you already have.
