SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80345ba1eb8, The address that the exception occurred at
Arg3: ffffaf08a32bbe98, Exception Record Address
Arg4: ffffaf08a32bb6d0, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify checksum for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullClassPtr
Key : AV.Fault
Value: Write
Key : Analysis.CPU.mSec
Value: 4389
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-JO5OOR3
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 22163
Key : Analysis.Memory.CommitPeak.Mb
Value: 99
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80345ba1eb8
BUGCHECK_P3: ffffaf08a32bbe98
BUGCHECK_P4: ffffaf08a32bb6d0
EXCEPTION_RECORD: ffffaf08a32bbe98 -- (.exr 0xffffaf08a32bbe98)
ExceptionAddress: fffff80345ba1eb8 (Ntfs!NtfsSetupUsnJournal+0x0000000000000168)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 00000000000001f0
Attempt to write to address 00000000000001f0
CONTEXT: ffffaf08a32bb6d0 -- (.cxr 0xffffaf08a32bb6d0)
rax=00000000000001f0 rbx=ffffb00842219010 rcx=ffffaf08a32bc138
rdx=ffffaf08a32bc001 rsi=ffff9e8e882cb180 rdi=0000000000000000
rip=fffff80345ba1eb8 rsp=ffffaf08a32bc0d0 rbp=ffffaf08a32bc9c9
r8=0000000000000000 r9=0000000000000000 r10=fffff803410639b0
r11=ffffaf08a32bc0a0 r12=0000000000000001 r13=0000000000000000
r14=0000000000000000 r15=ffff9e8e89bc45a8
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050286
Ntfs!NtfsSetupUsnJournal+0x168:
fffff803`45ba1eb8 440920 or dword ptr [rax],r12d ds:002b:00000000`000001f0=????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
WRITE_ADDRESS: fffff803416fa388: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8034160f2a8: Unable to get Flags value from nt!KdVersionBlock
fffff8034160f2a8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
00000000000001f0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 00000000000001f0
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffffaf08`a32bc0d0 fffff803`45ba0ef3 : ffffb008`42219010 ffffaf08`a32bc9c9 ffff9e8e`89bc45a8 00000000`00000000 : Ntfs!NtfsSetupUsnJournal+0x168
ffffaf08`a32bc450 fffff803`45b81644 : ffff9e8e`89bc45a8 ffff9e8e`882cb180 ffff9e8e`882cb101 ffffb008`00000020 : Ntfs!NtfsInitializeUsnJournal+0x10b
ffffaf08`a32bc4f0 fffff803`45ad9403 : ffffdd01`eb340100 ffff9e8e`7fa3b040 00000000`8471d000 00000000`00000000 : Ntfs!NtfsMountVolume+0x2624
ffffaf08`a32bc960 fffff803`45a08722 : ffff9e8e`89bc45a8 fffff803`45a08390 00000000`00000000 ffff9e8e`89bc45a8 : Ntfs!NtfsCommonFileSystemControl+0xcf
ffffaf08`a32bca30 fffff803`40c33f25 : ffff9e8e`8471d040 ffff9e8e`8471d040 ffff9e8e`7cc6da20 ffff9e8e`00000000 : Ntfs!NtfsFspDispatch+0x392
ffffaf08`a32bcb70 fffff803`40d46715 : ffff9e8e`8471d040 00000000`00000080 ffff9e8e`7cc92040 00000000`00000000 : nt!ExpWorkerThread+0x105
ffffaf08`a32bcc10 fffff803`40de5078 : ffffdd01`eabe8180 ffff9e8e`8471d040 fffff803`40d466c0 00000000`00e9be00 : nt!PspSystemThreadStartup+0x55
ffffaf08`a32bcc60 00000000`00000000 : ffffaf08`a32bd000 ffffaf08`a32b7000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: Ntfs!NtfsSetupUsnJournal+168
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
IMAGE_VERSION: 10.0.19041.208
STACK_COMMAND: .cxr 0xffffaf08a32bb6d0 ; kb
BUCKET_ID_FUNC_OFFSET: 168
FAILURE_BUCKET_ID: AV_Ntfs!NtfsSetupUsnJournal
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {cc862901-0a21-70a5-daa7-dc2d180005d2}
Followup: MachineOwner
---------