*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
INTERNAL_POWER_ERROR (a0)
The power policy manager experienced a fatal error.
Arguments:
Arg1: 000000000000010e, The disk subsystem returned corrupt data while reading from the
hibernation file.
Arg2: 000000000000000a
Arg3: 000000000000729b, Incorrect checksum
Arg4: 00000000000006c8, Previous disk read's checksum
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 10.0.18362.476 (WinBuild.160101.0800)
DUMP_FILE_ATTRIBUTES: 0x9
Hiber Crash Dump
Kernel Generated Triage Dump
DUMP_TYPE: 2
BUGCHECK_P1: 10e
BUGCHECK_P2: a
BUGCHECK_P3: 729b
BUGCHECK_P4: 6c8
BUGCHECK_STR: 0xa0_10e
CPU_COUNT: 10
CPU_MHZ: 1018
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
CURRENT_IRQL: f
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-01-2019 13:05:14.0204
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8042dda6faa to fffff8042d9c14e0
STACK_TEXT:
ffff8781`529c9648 fffff804`2dda6faa : 00000000`000000a0 00000000`0000010e 00000000`0000000a 00000000`0000729b : nt!KeBugCheckEx
ffff8781`529c9650 fffff804`2ddaf1a4 : 00000000`00000001 ffffad0a`eacfcc70 00000002`12daa000 ffffad0b`0279b000 : nt!PopHiberChecksumHiberFileData+0xaa2a
ffff8781`529c96b0 fffff804`2dda64a5 : 00000001`8f78f000 ffffbe81`dc131f38 00000000`00000001 00000000`00000001 : nt!PopRequestRead+0x78
ffff8781`529c9720 fffff804`2dd9af9e : 0000e0eb`be7aafa4 ffffbe81`dc131f38 00000000`00000000 fffff804`2e2b7848 : nt!PopRestoreHiberContext+0xb165
ffff8781`529c97b0 fffff804`2dd9acea : fffff804`2dc69fd0 ffff8781`529c9930 fffff804`2dc69fd0 ffffad0a`eacfcc70 : nt!PopHandleNextState+0x20e
ffff8781`529c9800 fffff804`2dd9aa5f : 00000000`00000100 00000000`00989680 ffffad0a`eacfcc70 ffffad0a`eacfcc70 : nt!PopIssueNextState+0x1a
ffff8781`529c9830 fffff804`2dd9b2ec : 00000000`0000000c fffff600`000077c0 00000000`00000000 fffff804`2d893474 : nt!PopInvokeSystemStateHandler+0x35b
ffff8781`529c9a30 fffff804`2dd9f6aa : ffffffff`ffffffff ffffffff`ffffffff 00000000`00000014 00000000`00000000 : nt!PopEndMirroring+0x1ec
ffff8781`529c9af0 fffff804`2dd9f3e5 : 00000000`00000000 00000000`00000000 00000013`00000001 00000000`00000001 : nt!MmDuplicateMemory+0x26e
ffff8781`529c9b80 fffff804`2d92a7a5 : ffffad0a`f8f2c000 ffffad0a`f8f2c040 fffff804`2dd9f2c0 00000000`00000001 : nt!PopTransitionToSleep+0x125
ffff8781`529c9c10 fffff804`2d9c8b2a : ffff9c80`c17c9180 ffffad0a`f8f2c040 fffff804`2d92a750 00000000`00000400 : nt!PspSystemThreadStartup+0x55
ffff8781`529c9c60 00000000`00000000 : ffff8781`529ca000 ffff8781`529c4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 337d1299c6890b7c6d65ceb358b93db026da4cb1
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 0fca91e4a12cdd0050f5e17d8e04102a11d16bfb
THREAD_SHA1_HASH_MOD: dc844b1b94baa204d070855e43bbbd27eee98b94
FOLLOWUP_IP:
nt!PopHiberChecksumHiberFileData+aa2a
fffff804`2dda6faa cc int 3
FAULT_INSTR_CODE: 3840cccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PopHiberChecksumHiberFileData+aa2a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: aa2a
FAILURE_BUCKET_ID: 0xa0_10e_nt!PopHiberChecksumHiberFileData
BUCKET_ID: 0xa0_10e_nt!PopHiberChecksumHiberFileData
PRIMARY_PROBLEM_CLASS: 0xa0_10e_nt!PopHiberChecksumHiberFileData
TARGET_TIME: 2019-11-30T23:38:40.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 160101.0800
BUILDLAB_STR: WinBuild
BUILDOSVER_STR: 10.0.18362.476
ANALYSIS_SESSION_ELAPSED_TIME: b08
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xa0_10e_nt!pophiberchecksumhiberfiledata
FAILURE_ID_HASH: {28ba2091-a476-6f77-2dec-6241bccd4685}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff840d78870078, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80779279b47, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: System manufacturer
SYSTEM_PRODUCT_NAME: System Product Name
SYSTEM_SKU: SKU
SYSTEM_VERSION: System Version
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 2901
BIOS_DATE: 10/16/2019
BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
BASEBOARD_PRODUCT: ROG STRIX B450-I GAMING
BASEBOARD_VERSION: Rev 1.xx
DUMP_TYPE: 2
BUGCHECK_P1: ffff840d78870078
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80779279b47
BUGCHECK_P4: 2
READ_ADDRESS: fffff80777b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffff840d78870078
FAULTING_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68 mov rcx,qword ptr [rsi+68h]
MM_INTERNAL_CODE: 2
CPU_COUNT: 10
CPU_MHZ: e6d
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-01-2019 13:05:10.0439
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffa408944f43b0 -- (.trap 0xffffa408944f43b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000150
rdx=ffffa60f47480180 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80779279b47 rsp=ffffa408944f4540 rbp=ffffa60f4743d7a0
r8=ffffa60f471bf070 r9=0000000000000000 r10=fffff8077763e6e0
r11=ffffc97c26800000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
Ntfs!NtfsFsdClose+0xf7:
fffff807`79279b47 488b4e68 mov rcx,qword ptr [rsi+68h] ds:00000000`00000068=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff807777e35d6 to fffff807777c14e0
STACK_TEXT:
ffffa408`944f4108 fffff807`777e35d6 : 00000000`00000050 ffff840d`78870078 00000000`00000000 ffffa408`944f43b0 : nt!KeBugCheckEx
ffffa408`944f4110 fffff807`77672eef : 00000000`00001000 00000000`00000000 00000000`00000000 ffff840d`78870078 : nt!MiSystemFault+0x1d6866
ffffa408`944f4210 fffff807`777cf520 : 00000000`c0000225 fffff807`786e815c 00000000`00000001 ffffa408`00000000 : nt!MmAccessFault+0x34f
ffffa408`944f43b0 fffff807`79279b47 : ffffa408`944f45f9 fffff807`786e4fc9 ffffa60f`5766f260 ffffa60f`00000000 : nt!KiPageFault+0x360
ffffa408`944f4540 fffff807`77631f79 : ffffa60f`471e2d01 ffffa60f`54518380 ffffa408`944f4730 00000000`00000002 : Ntfs!NtfsFsdClose+0xf7
ffffa408`944f4650 fffff807`786e55de : ffffa60f`54518380 ffffa408`944f4730 ffffa60f`54518380 ffffa408`944f4740 : nt!IofCallDriver+0x59
ffffa408`944f4690 fffff807`786e3f16 : ffffa408`944f4730 ffffa60f`471e2d60 00000000`00000001 ffffa60f`433fe280 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffa408`944f4710 fffff807`77631f79 : ffffa60f`56102500 fffff807`77701ef0 00000000`000037c1 00000000`00000000 : FLTMGR!FltpDispatch+0xb6
ffffa408`944f4770 fffff807`77be74cd : ffffa60f`56102500 ffffa60f`4743d7a0 ffffa60f`471e2d60 ffffa60f`54518380 : nt!IofCallDriver+0x59
ffffa408`944f47b0 fffff807`77bfa0e0 : ffff840d`721e6690 00000000`00000000 ffffa60f`3f6f76c0 fffff807`777077ff : nt!IopDeleteFile+0x12d
ffffa408`944f4830 fffff807`776390c4 : 00000000`00000000 00000000`00000000 ffff840d`721e6690 ffffa60f`56102500 : nt!ObpRemoveObjectRoutine+0x80
ffffa408`944f4890 fffff807`77bfc378 : 00000000`00000000 ffffa60f`576833d0 ffff840d`721e6690 ffffa60f`50872010 : nt!ObfDereferenceObject+0xa4
ffffa408`944f48d0 fffff807`777626d7 : fffff807`00000001 fffff807`77a6a400 ffffa408`944f49a0 ffffa60f`576833d8 : nt!MiSegmentDelete+0x154
ffffa408`944f4920 fffff807`7778f279 : 00000000`00000000 fffff807`00000001 00000000`00000000 fffff807`77a6a400 : nt!MiProcessDereferenceList+0xc3
ffffa408`944f49e0 fffff807`7772a7a5 : ffffa60f`473d4080 ffffa60f`473d4080 00000000`00000080 fffff807`7778f150 : nt!MiDereferenceSegmentThread+0x129
ffffa408`944f4c10 fffff807`777c8b2a : ffffd981`99c80180 ffffa60f`473d4080 fffff807`7772a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffa408`944f4c60 00000000`00000000 : ffffa408`944f5000 ffffa408`944ef000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 8c30faa9d8ac2b59394fc0d42256e9f619d7381d
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f95d1ca8699e828c538b821c41d8dbb6175892b2
THREAD_SHA1_HASH_MOD: 2c7ea0025fdc68207e0d2ea581806bf3fb0411b0
FOLLOWUP_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68 mov rcx,qword ptr [rsi+68h]
FAULT_INSTR_CODE: 684e8b48
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: Ntfs!NtfsFsdClose+f7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 18633ece
IMAGE_VERSION: 10.0.18362.449
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: f7
FAILURE_BUCKET_ID: AV_R_INVALID_Ntfs!NtfsFsdClose
BUCKET_ID: AV_R_INVALID_Ntfs!NtfsFsdClose
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_Ntfs!NtfsFsdClose
TARGET_TIME: 2019-11-29T15:05:48.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 4114
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_ntfs!ntfsfsdclose
FAILURE_ID_HASH: {2f10441a-beec-4e13-d39a-66f0294a8a16}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffe18f6904eb08, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff803450ac8e0, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: System manufacturer
SYSTEM_PRODUCT_NAME: System Product Name
SYSTEM_SKU: SKU
SYSTEM_VERSION: System Version
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 2901
BIOS_DATE: 10/16/2019
BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
BASEBOARD_PRODUCT: ROG STRIX B450-I GAMING
BASEBOARD_VERSION: Rev 1.xx
DUMP_TYPE: 2
BUGCHECK_P1: ffffe18f6904eb08
BUGCHECK_P2: 0
BUGCHECK_P3: fffff803450ac8e0
BUGCHECK_P4: 2
READ_ADDRESS: fffff80342b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffe18f6904eb08
FAULTING_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908 cmp qword ptr [rcx+8],rbx
MM_INTERNAL_CODE: 2
CPU_COUNT: 10
CPU_MHZ: e6d
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-01-2019 13:05:08.0205
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffff908caf6d1120 -- (.trap 0xffff908caf6d1120)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffe18f6904eb00
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803450ac8e0 rsp=ffff908caf6d12b0 rbp=ffff808bb393c500
r8=0000000000000000 r9=0000000000000000 r10=fffff803426d5f50
r11=ffffc07bc7200000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
fileinfo!FIStreamCleanup+0x50:
fffff803`450ac8e0 48395908 cmp qword ptr [rcx+8],rbx ds:ffffe18f`6904eb08=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff803427e35d6 to fffff803427c14e0
STACK_TEXT:
ffff908c`af6d0e78 fffff803`427e35d6 : 00000000`00000050 ffffe18f`6904eb08 00000000`00000000 ffff908c`af6d1120 : nt!KeBugCheckEx
ffff908c`af6d0e80 fffff803`42672eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe18f`6904eb08 : nt!MiSystemFault+0x1d6866
ffff908c`af6d0f80 fffff803`427cf520 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x34f
ffff908c`af6d1120 fffff803`450ac8e0 : ffff808b`b393c500 00000000`00000000 ffff808b`a34d9210 ffff808b`a34d9150 : nt!KiPageFault+0x360
ffff908c`af6d12b0 fffff803`446e86f2 : ffffe18f`4904e260 ffff808b`a34d9150 00000000`00000705 ffffffff`ffffffff : fileinfo!FIStreamCleanup+0x50
ffff908c`af6d1310 fffff803`4471dbbb : ffff808b`b393c528 00000000`00000000 ffffe18f`4904e278 ffffffff`ffffffff : FLTMGR!DoReleaseContext+0x82
ffff908c`af6d1350 fffff803`4471d6a7 : ffff808b`b393c4e0 00000000`00000706 ffff808b`b393c4e8 fffff803`42636a8f : FLTMGR!FltpDeleteContextList+0xab
ffff908c`af6d1380 fffff803`4471efaa : ffff808b`b393c4e0 ffff808b`a38ba190 ffff808b`b393c4e0 ffff808b`b393c4e0 : FLTMGR!CleanupStreamListCtrl+0x47
ffff908c`af6d1400 fffff803`42c70adb : ffffe18f`4824a170 ffff808b`b393c4e8 ffffe18f`00000000 ffff908c`af6d18f0 : FLTMGR!DeleteStreamListCtrlCallback+0xba
ffff908c`af6d1440 fffff803`4524ee26 : ffffe18f`4824a170 ffff908c`af6d1578 ffff908c`af6d18f0 00000000`00000705 : nt!FsRtlTeardownPerStreamContexts+0xcb
ffff908c`af6d1480 fffff803`4524f772 : ffffe18f`4824a170 fffff803`42645ed7 ffffe18f`32200340 ffffe18f`000000ff : Ntfs!NtfsDeleteScb+0x166
ffff908c`af6d1510 fffff803`45174225 : ffffe18f`4824a050 ffffe18f`4824a170 ffffe18f`4824a010 ffffe18f`4824a170 : Ntfs!NtfsRemoveScb+0xba
ffff908c`af6d1570 fffff803`4524f4b0 : ffff908c`af6d18f0 fffff803`452a5450 ffffe18f`4824a010 ffffe18f`4824a400 : Ntfs!NtfsPrepareFcbForRemoval+0x75
ffff908c`af6d15b0 fffff803`4517892a : ffff908c`af6d18f0 ffff908c`af6d16b1 ffffe18f`4824a458 ffff908c`af6d18f0 : Ntfs!NtfsTeardownStructures+0xa0
ffff908c`af6d1630 fffff803`45270cec : ffff908c`af6d1700 ffffe18f`00000000 ffff908c`00000000 ffff908c`af6d18f0 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffff908c`af6d1670 fffff803`4526fc31 : ffff908c`af6d18f0 ffffe18f`4824a170 ffffe18f`4824a010 ffff808b`a38bf180 : Ntfs!NtfsCommonClose+0x45c
ffff908c`af6d1750 fffff803`452a54d8 : 00000000`0000001c fffff803`42b8f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffff908c`af6d18b0 fffff803`426bd4b5 : ffff808b`9ba94b80 fffff803`42a68200 00000000`00000000 fffff803`4c873830 : Ntfs!NtfsFspClose+0x88
ffff908c`af6d1b70 fffff803`4272a7a5 : ffff808b`aa53b040 00000000`00000080 ffff808b`9ba90040 6e726177`00000001 : nt!ExpWorkerThread+0x105
ffff908c`af6d1c10 fffff803`427c8b2a : ffffd080`18479180 ffff808b`aa53b040 fffff803`4272a750 74726f70`70757302 : nt!PspSystemThreadStartup+0x55
ffff908c`af6d1c60 00000000`00000000 : ffff908c`af6d2000 ffff908c`af6cc000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 8af332adc128204de9b4fd929a43821801049a41
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 90bb67ce4b28a96d58ad1a519aa3a84eb4d74388
THREAD_SHA1_HASH_MOD: f68501f3e6a4e6ec4bdbfbfbda765ad69e024213
FOLLOWUP_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908 cmp qword ptr [rcx+8],rbx
FAULT_INSTR_CODE: 8593948
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: fileinfo!FIStreamCleanup+50
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 24bbed20
IMAGE_VERSION: 10.0.18362.1216
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 50
FAILURE_BUCKET_ID: AV_R_INVALID_fileinfo!FIStreamCleanup
BUCKET_ID: AV_R_INVALID_fileinfo!FIStreamCleanup
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_fileinfo!FIStreamCleanup
TARGET_TIME: 2019-11-28T15:10:08.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 5440
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_fileinfo!fistreamcleanup
FAILURE_ID_HASH: {740f90e9-6aa2-7571-b946-cc541647de7d}
Followup: MachineOwner
---------