*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8070a38c078, The address that the exception occurred at
Arg3: ffffa50833f773b8, Exception Record Address
Arg4: ffffa50833f76bf0, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 9468
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-70T822T
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 16832
Key : Analysis.Memory.CommitPeak.Mb
Value: 87
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8070a38c078
BUGCHECK_P3: ffffa50833f773b8
BUGCHECK_P4: ffffa50833f76bf0
EXCEPTION_RECORD: ffffa50833f773b8 -- (.exr 0xffffa50833f773b8)
ExceptionAddress: fffff8070a38c078 (Ntfs!NtfsAcquireExclusiveFcb+0x0000000000000078)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000010078
Attempt to read from address 0000000000010078
CONTEXT: ffffa50833f76bf0 -- (.cxr 0xffffa50833f76bf0)
rax=0000000000100041 rbx=ffffb882428be010 rcx=0000000000010010
rdx=ffffb882428be010 rsi=0000000000000702 rdi=0000000000000009
rip=fffff8070a38c078 rsp=ffffa50833f775f0 rbp=fffff8070a4c7930
r8=0000000000000000 r9=0000000000000009 r10=0000000000000000
r11=ffffa50833f77600 r12=0000000000000000 r13=0000000000000001
r14=0000000000000000 r15=ffffb882428be101
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050202
Ntfs!NtfsAcquireExclusiveFcb+0x78:
fffff807`0a38c078 488b4968 mov rcx,qword ptr [rcx+68h] ds:002b:00000000`00010078=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff807046fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8070460f340: Unable to get Flags value from nt!KdVersionBlock
fffff8070460f340: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
0000000000010078
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000010078
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffffa508`33f775f0 fffff807`0a4ab139 : ffffa508`33f778f0 ffffb882`428be010 00000000`00000000 fffff807`00000001 : Ntfs!NtfsAcquireExclusiveFcb+0x78
ffffa508`33f77670 fffff807`0a4a7ff1 : ffffa508`33f778f0 ffffb882`428be170 ffffb882`428be010 ffff9401`dd37b180 : Ntfs!NtfsCommonClose+0xc9
ffffa508`33f77750 fffff807`0a4c79b8 : 00000000`0000001c fffff807`04725440 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffffa508`33f778b0 fffff807`03d034b5 : ffff9401`db57f080 fffff807`0a4c7930 ffff9401`db535a60 fffff807`00000000 : Ntfs!NtfsFspClose+0x88
ffffa508`33f77b70 fffff807`03ca29a5 : ffff9401`db57f080 00000000`00000080 ffff9401`db467040 00000000`00000000 : nt!ExpWorkerThread+0x105
ffffa508`33f77c10 fffff807`03dfc868 : ffffa701`e7fec180 ffff9401`db57f080 fffff807`03ca2950 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffa508`33f77c60 00000000`00000000 : ffffa508`33f78000 ffffa508`33f72000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: Ntfs!NtfsAcquireExclusiveFcb+78
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
IMAGE_VERSION: 10.0.19041.602
STACK_COMMAND: .cxr 0xffffa50833f76bf0 ; kb
BUCKET_ID_FUNC_OFFSET: 78
FAILURE_BUCKET_ID: AV_Ntfs!NtfsAcquireExclusiveFcb
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {fc3e4f4d-f198-64f4-3243-291a9f2b62a9}
Followup: MachineOwner
---------