REFERENCE_BY_POINTER (18)
Arguments:
Arg1: 0000000000000000, Object type of the object whose reference count is being lowered
Arg2: fffff88002849000, Object whose reference count is being lowered
Arg3: 0000000000000004, Reserved
Arg4: ffffffffffffffff, Reserved
The reference count of an object is illegal for the current state of the object.
Each time a driver uses a pointer to an object the driver calls a kernel routine
to increment the reference count of the object. When the driver is done with the
pointer the driver calls another kernel routine to decrement the reference count.
Drivers must match calls to the increment and decrement routines. This bugcheck
can occur because an object's reference count goes to zero while there are still
open handles to the object, in which case the fourth parameter indicates the number
of opened handles. It may also occur when the object's reference count drops below zero
whether or not there are open handles to the object, and in that case the fourth parameter
contains the actual value of the pointer references count.
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff80002eec300
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24540.amd64fre.win7sp1_ldr_escrow.191127-1706
SYSTEM_MANUFACTURER: Packard Bell
SYSTEM_PRODUCT_NAME: EasyNote TE69HW
SYSTEM_SKU: EasyNote TE69HW_0776_V2.13
SYSTEM_VERSION: V2.13
BIOS_VENDOR: Insyde Corp.
BIOS_VERSION: V2.13
BIOS_DATE: 11/21/2013
BASEBOARD_MANUFACTURER: Packard Bell
BASEBOARD_PRODUCT: EG50_HW
BASEBOARD_VERSION: V2.13
DUMP_TYPE: 2
BUGCHECK_P1: 0
BUGCHECK_P2: fffff88002849000
BUGCHECK_P3: 4
BUGCHECK_P4: ffffffffffffffff
CPU_COUNT: 4
CPU_MHZ: 8f6
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 45
CPU_STEPPING: 1
CPU_MICROCODE: 6,45,1,0 (F,M,S,R) SIG: 17'00000000 (cache) 17'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x18
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-20-2019 20:53:40.0804
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80002d08881 to fffff80002ce2ea0
STACK_TEXT:
fffff880`07ebe798 fffff800`02d08881 : 00000000`00000018 00000000`00000000 fffff880`02849000 00000000`00000004 : nt!KeBugCheckEx
fffff880`07ebe7a0 fffff800`02d08f6c : fffffa80`077cdf50 00000000`00000705 fffffa80`0459c010 fffff8a0`0b5938b0 : nt! ?? ::FNODOBFM::`string'+0x12f81
fffff880`07ebe7e0 fffff880`012cdebc : fffff880`07ebe8b0 00000000`00000745 fffffa80`077cdf10 fffffa80`0459c010 : nt! ?? ::FNODOBFM::`string'+0x1366c
fffff880`07ebe820 fffff880`0124a212 : fffff800`02e5f7a0 fffff880`07ebea01 fffff880`07ebe8a1 fffff8a0`0ae57010 : Ntfs!NtfsDeleteFcb+0x10c
fffff880`07ebe880 fffff880`012cfb0c : fffffa80`0459c010 fffffa80`05259180 fffff8a0`0ae57010 fffff8a0`0ae573a8 : Ntfs!NtfsTeardownFromLcb+0x1e2
fffff880`07ebe910 fffff880`01252b82 : fffffa80`0459c010 fffffa80`0459c010 fffff8a0`0ae57010 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`07ebe990 fffff880`012df403 : fffffa80`0459c010 fffff800`02e5f7a0 fffff8a0`0ae57010 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`07ebe9d0 fffff880`01332772 : fffffa80`0459c010 fffff8a0`0ae57140 fffff8a0`0ae57010 fffffa80`05259180 : Ntfs!NtfsCommonClose+0x353
fffff880`07ebeaa0 fffff800`02c92dc9 : 00000000`00000000 fffff800`02f58b01 fffff800`02ec1f00 00000000`00000002 : Ntfs!NtfsFspCloseInternal+0x186
fffff880`07ebeb70 fffff800`02f8e2e8 : fffffa80`051dc010 fffff800`02e33180 00000000`00000080 00000000`00000001 : nt!ExpWorkerThread+0x111
fffff880`07ebec00 fffff800`02ce8ec6 : fffff800`02e33180 fffffa80`07b76b50 fffff800`02e431c0 00000000`00000000 : nt!PspSystemThreadStartup+0x194
fffff880`07ebec40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
THREAD_SHA1_HASH_MOD_FUNC: 882a8ef5a0d7cfce0f1ee37ddf1a526eb90598a7
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: c9c2d7c210e40661e3504d81b0f6e8884a9a4928
THREAD_SHA1_HASH_MOD: 65df2ad12d51e89f5a17fd652f220cce94c78715
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+12f81
fffff800`02d08881 cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+12f81
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5ddf3671
IMAGE_VERSION: 6.1.7601.24540
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: X64_0x18_nt!_??_::FNODOBFM::_string_+12f81
BUCKET_ID: X64_0x18_nt!_??_::FNODOBFM::_string_+12f81
PRIMARY_PROBLEM_CLASS: X64_0x18_nt!_??_::FNODOBFM::_string_+12f81
TARGET_TIME: 2019-12-20T17:14:06.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-11-28 05:52:33
BUILDDATESTAMP_STR: 191127-1706
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24540.amd64fre.win7sp1_ldr_escrow.191127-1706
ANALYSIS_SESSION_ELAPSED_TIME: 93f0
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x18_nt!_??_::fnodobfm::_string_+12f81
FAILURE_ID_HASH: {ae9031ae-c030-d636-b1f5-e40b7b4a1e52}
Followup: MachineOwner
---------