Critical process died mavi ekran

chuztr

Hectopat
Katılım
18 Kasım 2019
Mesajlar
25

Bilgisayarı ilk açtığımda, mavi ekranla karşılaşıyorum, her seferinde olmuyor arada sırada oluyor, resetlenerek tekrar açılıyor, ama bunun nedenini öğrenmek istiyorum ki çözüme kavuşturabileyim. Anlayan arkadaşlar yardımcı olursa sevinirim. Minidump dosyasını rar'layarak paylaştım.
 
Hala bellek hatası görüyorum, sistemde kaç bellek takılı? Chipseti siz mi yüklediniz?

Kod:
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003.  This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG.  This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG.  This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8030b13f321, The address that the exception occurred at
Arg3: ffff9c8ed5f92d38, Exception Record Address
Arg4: fffff8030fe7c930, Context Record Address

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8030b13f321

BUGCHECK_P3: ffff9c8ed5f92d38

BUGCHECK_P4: fffff8030fe7c930

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

FAULTING_IP:
nt!MiDemoteCombinedPte+51
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1

EXCEPTION_RECORD:  ffff9c8ed5f92d38 -- (.exr 0xffff9c8ed5f92d38)
ExceptionAddress: fffff8030b13f321 (nt!MiDemoteCombinedPte+0x0000000000000051)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff8030fe7c930 -- (.cxr 0xfffff8030fe7c930)
rax=ffffdc6e371b8000 rbx=3d450227b3050233 rcx=ffffe40546830580
rdx=ffffdc3fff1b1008 rsi=ffffdc3fff1b1008 rdi=ffffdc3fff1b1008
rip=fffff8030b13f321 rsp=ffff9c8ed5f92f70 rbp=ffffdf0677190f00
r8=8000000000000000  r9=0000000fffffffff r10=0000000000000000
r11=ffffb7fe7ca00000 r12=ffffdc6e371b87f8 r13=ffffdf0000000000
r14=8000000000000000 r15=ffffe40546830580
iopl=0         nv up ei ng nz na pe cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00050283
nt!MiDemoteCombinedPte+0x51:
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1 ds:002b:7fffffff`fffffff0=????????????????
Resetting default scope

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

PROCESS_NAME:  NVDispl

CURRENT_IRQL:  2

FOLLOWUP_IP:
nt!MiDemoteCombinedPte+51
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1

BUGCHECK_STR:  AV

READ_ADDRESS: fffff8030b5733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffffffffffffff

ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:03.0589

ANALYSIS_VERSION: 10.0.18362.1 x86fre

BAD_STACK_POINTER:  fffff8030fe7c0c8

LAST_CONTROL_TRANSFER:  from fffff8030b26aae1 to fffff8030b13f321

STACK_TEXT:
ffff9c8e`d5f92f70 fffff803`0b26aae1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000003 : nt!MiDemoteCombinedPte+0x51
ffff9c8e`d5f93040 fffff803`0b0ace07 : 3d450227`b3050233 00000000`00000000 00000000`00000000 ffff9c8e`d5f934e0 : nt!MiResetAccessBitPte+0xf39a1
ffff9c8e`d5f930a0 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`1fff8d88 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x1e7
ffff9c8e`d5f93160 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`370fffc0 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f93220 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`371b87f8 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f932e0 fffff803`0b0aca4c : ffff9c8e`d5f934e0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f933a0 fffff803`0b17b071 : ffff9c8e`d5f934e0 fffff803`00000002 ffff9c8e`00000001 fffff803`00000000 : nt!MiWalkPageTables+0x36c
ffff9c8e`d5f934a0 fffff803`0b0ac01b : ffffe405`3e294080 fffff803`00000000 ffffe405`46830580 00000000`00000000 : nt!MiCaptureAndResetWorkingSetAccessBits+0x109
ffff9c8e`d5f93790 fffff803`0b0ab52a : ffffe405`46830580 ffff9c8e`d5f93a50 00000000`00000000 00000000`00000000 : nt!MiTrimOrAgeWorkingSet+0x7bb
ffff9c8e`d5f93880 fffff803`0b0a9180 : fffff803`0b46a400 00000000`ffffffff fffff803`0b46a400 ffffe405`37444010 : nt!MiProcessWorkingSets+0x1fa
ffff9c8e`d5f93a30 fffff803`0b2ca1b6 : fffff803`0b46a400 00000000`00000004 00000000`ffffffff 00000000`00000001 : nt!MiWorkingSetManager+0xc8
ffff9c8e`d5f93af0 fffff803`0b18bcb7 : 00000000`00000005 00000000`ffffffff 00000000`00000004 00000000`000005c8 : nt!MmWorkingSetManager+0x12
ffff9c8e`d5f93b20 fffff803`0b12a7a5 : ffffe405`37524080 00000000`00000080 fffff803`0b18ba10 00000000`00000000 : nt!KeBalanceSetManager+0x2a7
ffff9c8e`d5f93c10 fffff803`0b1c8b2a : ffffc800`77080180 ffffe405`37524080 fffff803`0b12a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff9c8e`d5f93c60 00000000`00000000 : ffff9c8e`d5f94000 ffff9c8e`d5f8e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  ac200141e9a7adc5cb469bc451e8d40a01618cc0

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  57b9d753037a95f8e1bcaaa3a5fdf3da4f1f1a34

THREAD_SHA1_HASH_MOD:  38bc5fec3f0409c265cf5c87da6f8f8859d0711c

FAULT_INSTR_CODE:  f0788349

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!MiDemoteCombinedPte+51

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4efcf7a9

IMAGE_VERSION:  10.0.18362.476

STACK_COMMAND:  .cxr 0xfffff8030fe7c930 ; kb

IMAGE_NAME:  memory_corruption

BUCKET_ID_FUNC_OFFSET:  51

FAILURE_BUCKET_ID:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

BUCKET_ID:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

PRIMARY_PROBLEM_CLASS:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

TARGET_TIME:  2019-11-27T14:55:43.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  3c35

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_stackptr_error_nt!midemotecombinedpte

FAILURE_ID_HASH:  {51bd6656-a4b2-8d9b-1231-94678dd83b3a}

Followup:     MachineOwner
---------

INTERNAL_POWER_ERROR (a0)
The power policy manager experienced a fatal error.
Arguments:
Arg1: 000000000000010e, The disk subsystem returned corrupt data while reading from the
    hibernation file.
Arg2: 000000000000000a
Arg3: 000000000000bd73, Incorrect checksum
Arg4: 000000000000c968, Previous disk read's checksum

Debugging Details:
------------------


KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  10.0.18362.476 (WinBuild.160101.0800)

DUMP_FILE_ATTRIBUTES: 0x9
  Hiber Crash Dump
  Kernel Generated Triage Dump

DUMP_TYPE:  2

BUGCHECK_P1: 10e

BUGCHECK_P2: a

BUGCHECK_P3: bd73

BUGCHECK_P4: c968

BUGCHECK_STR:  0xa0_10e

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

CURRENT_IRQL:  f

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:06.0765

ANALYSIS_VERSION: 10.0.18362.1 x86fre

LAST_CONTROL_TRANSFER:  from fffff80519fa6faa to fffff80519bc14e0

STACK_TEXT:
fffff20c`92956648 fffff805`19fa6faa : 00000000`000000a0 00000000`0000010e 00000000`0000000a 00000000`0000bd73 : nt!KeBugCheckEx
fffff20c`92956650 fffff805`19faf1a4 : 00000000`00000001 ffffb70f`23d3d9b0 00000003`7c5fd000 ffffb70f`39e1b000 : nt!PopHiberChecksumHiberFileData+0xaa2a
fffff20c`929566b0 fffff805`19fa64a5 : 00000001`9060f000 ffffa70c`46131f38 00000000`00000001 00000000`00000001 : nt!PopRequestRead+0x78
fffff20c`92956720 fffff805`19f9af9e : 00004167`b19d78ad ffffa70c`46131f38 00000000`00000000 fffff805`1995e848 : nt!PopRestoreHiberContext+0xb165
fffff20c`929567b0 fffff805`19f9acea : fffff805`19e69fd0 fffff20c`92956930 fffff805`19e69fd0 ffffb70f`23d3d9b0 : nt!PopHandleNextState+0x20e
fffff20c`92956800 fffff805`19f9aa5f : 00000000`00000100 00000000`00989680 ffffb70f`23d3d9b0 ffffb70f`23d3d9b0 : nt!PopIssueNextState+0x1a
fffff20c`92956830 fffff805`19f9b2ec : 00000000`0000000c ffff9d00`000077c0 00000000`00000000 fffff805`19a93474 : nt!PopInvokeSystemStateHandler+0x35b
fffff20c`92956a30 fffff805`19f9f6aa : ffffffff`ffffffff ffffffff`ffffffff 00000000`00000014 00000000`00000000 : nt!PopEndMirroring+0x1ec
fffff20c`92956af0 fffff805`19f9f3e5 : 00000000`00000000 00000000`00000000 0000001e`00000001 00000000`00000001 : nt!MmDuplicateMemory+0x26e
fffff20c`92956b80 fffff805`19b2a7a5 : ffffb70f`2cbde000 ffffb70f`2cbde040 fffff805`19f9f2c0 ffff73fa`00000001 : nt!PopTransitionToSleep+0x125
fffff20c`92956c10 fffff805`19bc8b2a : ffff8400`50284180 ffffb70f`2cbde040 fffff805`19b2a750 fffff20c`92956d89 : nt!PspSystemThreadStartup+0x55
fffff20c`92956c60 00000000`00000000 : fffff20c`92957000 fffff20c`92951000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  337d1299c6890b7c6d65ceb358b93db026da4cb1

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  0fca91e4a12cdd0050f5e17d8e04102a11d16bfb

THREAD_SHA1_HASH_MOD:  dc844b1b94baa204d070855e43bbbd27eee98b94

FOLLOWUP_IP:
nt!PopHiberChecksumHiberFileData+aa2a
fffff805`19fa6faa cc              int     3

FAULT_INSTR_CODE:  3840cccc

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!PopHiberChecksumHiberFileData+aa2a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4efcf7a9

IMAGE_VERSION:  10.0.18362.476

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  aa2a

FAILURE_BUCKET_ID:  0xa0_10e_nt!PopHiberChecksumHiberFileData

BUCKET_ID:  0xa0_10e_nt!PopHiberChecksumHiberFileData

PRIMARY_PROBLEM_CLASS:  0xa0_10e_nt!PopHiberChecksumHiberFileData

TARGET_TIME:  2019-11-25T20:56:36.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  160101.0800

BUILDLAB_STR:  WinBuild

BUILDOSVER_STR:  10.0.18362.476

ANALYSIS_SESSION_ELAPSED_TIME:  af8

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0xa0_10e_nt!pophiberchecksumhiberfiledata

FAILURE_ID_HASH:  {28ba2091-a476-6f77-2dec-6241bccd4685}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffe18f6904eb08, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff803450ac8e0, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys

KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffffe18f6904eb08

BUGCHECK_P2: 0

BUGCHECK_P3: fffff803450ac8e0

BUGCHECK_P4: 2

READ_ADDRESS: fffff80342b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffe18f6904eb08

FAULTING_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx

MM_INTERNAL_CODE:  2

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:10.0348

ANALYSIS_VERSION: 10.0.18362.1 x86fre

TRAP_FRAME:  ffff908caf6d1120 -- (.trap 0xffff908caf6d1120)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffe18f6904eb00
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803450ac8e0 rsp=ffff908caf6d12b0 rbp=ffff808bb393c500
r8=0000000000000000  r9=0000000000000000 r10=fffff803426d5f50
r11=ffffc07bc7200000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po nc
fileinfo!FIStreamCleanup+0x50:
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx ds:ffffe18f`6904eb08=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff803427e35d6 to fffff803427c14e0

STACK_TEXT:
ffff908c`af6d0e78 fffff803`427e35d6 : 00000000`00000050 ffffe18f`6904eb08 00000000`00000000 ffff908c`af6d1120 : nt!KeBugCheckEx
ffff908c`af6d0e80 fffff803`42672eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe18f`6904eb08 : nt!MiSystemFault+0x1d6866
ffff908c`af6d0f80 fffff803`427cf520 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x34f
ffff908c`af6d1120 fffff803`450ac8e0 : ffff808b`b393c500 00000000`00000000 ffff808b`a34d9210 ffff808b`a34d9150 : nt!KiPageFault+0x360
ffff908c`af6d12b0 fffff803`446e86f2 : ffffe18f`4904e260 ffff808b`a34d9150 00000000`00000705 ffffffff`ffffffff : fileinfo!FIStreamCleanup+0x50
ffff908c`af6d1310 fffff803`4471dbbb : ffff808b`b393c528 00000000`00000000 ffffe18f`4904e278 ffffffff`ffffffff : FLTMGR!DoReleaseContext+0x82
ffff908c`af6d1350 fffff803`4471d6a7 : ffff808b`b393c4e0 00000000`00000706 ffff808b`b393c4e8 fffff803`42636a8f : FLTMGR!FltpDeleteContextList+0xab
ffff908c`af6d1380 fffff803`4471efaa : ffff808b`b393c4e0 ffff808b`a38ba190 ffff808b`b393c4e0 ffff808b`b393c4e0 : FLTMGR!CleanupStreamListCtrl+0x47
ffff908c`af6d1400 fffff803`42c70adb : ffffe18f`4824a170 ffff808b`b393c4e8 ffffe18f`00000000 ffff908c`af6d18f0 : FLTMGR!DeleteStreamListCtrlCallback+0xba
ffff908c`af6d1440 fffff803`4524ee26 : ffffe18f`4824a170 ffff908c`af6d1578 ffff908c`af6d18f0 00000000`00000705 : nt!FsRtlTeardownPerStreamContexts+0xcb
ffff908c`af6d1480 fffff803`4524f772 : ffffe18f`4824a170 fffff803`42645ed7 ffffe18f`32200340 ffffe18f`000000ff : Ntfs!NtfsDeleteScb+0x166
ffff908c`af6d1510 fffff803`45174225 : ffffe18f`4824a050 ffffe18f`4824a170 ffffe18f`4824a010 ffffe18f`4824a170 : Ntfs!NtfsRemoveScb+0xba
ffff908c`af6d1570 fffff803`4524f4b0 : ffff908c`af6d18f0 fffff803`452a5450 ffffe18f`4824a010 ffffe18f`4824a400 : Ntfs!NtfsPrepareFcbForRemoval+0x75
ffff908c`af6d15b0 fffff803`4517892a : ffff908c`af6d18f0 ffff908c`af6d16b1 ffffe18f`4824a458 ffff908c`af6d18f0 : Ntfs!NtfsTeardownStructures+0xa0
ffff908c`af6d1630 fffff803`45270cec : ffff908c`af6d1700 ffffe18f`00000000 ffff908c`00000000 ffff908c`af6d18f0 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffff908c`af6d1670 fffff803`4526fc31 : ffff908c`af6d18f0 ffffe18f`4824a170 ffffe18f`4824a010 ffff808b`a38bf180 : Ntfs!NtfsCommonClose+0x45c
ffff908c`af6d1750 fffff803`452a54d8 : 00000000`0000001c fffff803`42b8f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffff908c`af6d18b0 fffff803`426bd4b5 : ffff808b`9ba94b80 fffff803`42a68200 00000000`00000000 fffff803`4c873830 : Ntfs!NtfsFspClose+0x88
ffff908c`af6d1b70 fffff803`4272a7a5 : ffff808b`aa53b040 00000000`00000080 ffff808b`9ba90040 6e726177`00000001 : nt!ExpWorkerThread+0x105
ffff908c`af6d1c10 fffff803`427c8b2a : ffffd080`18479180 ffff808b`aa53b040 fffff803`4272a750 74726f70`70757302 : nt!PspSystemThreadStartup+0x55
ffff908c`af6d1c60 00000000`00000000 : ffff908c`af6d2000 ffff908c`af6cc000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  8af332adc128204de9b4fd929a43821801049a41

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  90bb67ce4b28a96d58ad1a519aa3a84eb4d74388

THREAD_SHA1_HASH_MOD:  f68501f3e6a4e6ec4bdbfbfbda765ad69e024213

FOLLOWUP_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx

FAULT_INSTR_CODE:  8593948

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  fileinfo!FIStreamCleanup+50

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: fileinfo

IMAGE_NAME:  fileinfo.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  24bbed20

IMAGE_VERSION:  10.0.18362.1216

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  50

FAILURE_BUCKET_ID:  AV_R_INVALID_fileinfo!FIStreamCleanup

BUCKET_ID:  AV_R_INVALID_fileinfo!FIStreamCleanup

PRIMARY_PROBLEM_CLASS:  AV_R_INVALID_fileinfo!FIStreamCleanup

TARGET_TIME:  2019-11-28T15:10:08.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  5ecc

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_r_invalid_fileinfo!fistreamcleanup

FAILURE_ID_HASH:  {740f90e9-6aa2-7571-b946-cc541647de7d}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff840d78870078, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80779279b47, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys

KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffff840d78870078

BUGCHECK_P2: 0

BUGCHECK_P3: fffff80779279b47

BUGCHECK_P4: 2

READ_ADDRESS: fffff80777b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffff840d78870078

FAULTING_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h]

MM_INTERNAL_CODE:  2

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:14.0002

ANALYSIS_VERSION: 10.0.18362.1 x86fre

TRAP_FRAME:  ffffa408944f43b0 -- (.trap 0xffffa408944f43b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000150
rdx=ffffa60f47480180 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80779279b47 rsp=ffffa408944f4540 rbp=ffffa60f4743d7a0
r8=ffffa60f471bf070  r9=0000000000000000 r10=fffff8077763e6e0
r11=ffffc97c26800000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
Ntfs!NtfsFsdClose+0xf7:
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h] ds:00000000`00000068=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff807777e35d6 to fffff807777c14e0

STACK_TEXT:
ffffa408`944f4108 fffff807`777e35d6 : 00000000`00000050 ffff840d`78870078 00000000`00000000 ffffa408`944f43b0 : nt!KeBugCheckEx
ffffa408`944f4110 fffff807`77672eef : 00000000`00001000 00000000`00000000 00000000`00000000 ffff840d`78870078 : nt!MiSystemFault+0x1d6866
ffffa408`944f4210 fffff807`777cf520 : 00000000`c0000225 fffff807`786e815c 00000000`00000001 ffffa408`00000000 : nt!MmAccessFault+0x34f
ffffa408`944f43b0 fffff807`79279b47 : ffffa408`944f45f9 fffff807`786e4fc9 ffffa60f`5766f260 ffffa60f`00000000 : nt!KiPageFault+0x360
ffffa408`944f4540 fffff807`77631f79 : ffffa60f`471e2d01 ffffa60f`54518380 ffffa408`944f4730 00000000`00000002 : Ntfs!NtfsFsdClose+0xf7
ffffa408`944f4650 fffff807`786e55de : ffffa60f`54518380 ffffa408`944f4730 ffffa60f`54518380 ffffa408`944f4740 : nt!IofCallDriver+0x59
ffffa408`944f4690 fffff807`786e3f16 : ffffa408`944f4730 ffffa60f`471e2d60 00000000`00000001 ffffa60f`433fe280 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffa408`944f4710 fffff807`77631f79 : ffffa60f`56102500 fffff807`77701ef0 00000000`000037c1 00000000`00000000 : FLTMGR!FltpDispatch+0xb6
ffffa408`944f4770 fffff807`77be74cd : ffffa60f`56102500 ffffa60f`4743d7a0 ffffa60f`471e2d60 ffffa60f`54518380 : nt!IofCallDriver+0x59
ffffa408`944f47b0 fffff807`77bfa0e0 : ffff840d`721e6690 00000000`00000000 ffffa60f`3f6f76c0 fffff807`777077ff : nt!IopDeleteFile+0x12d
ffffa408`944f4830 fffff807`776390c4 : 00000000`00000000 00000000`00000000 ffff840d`721e6690 ffffa60f`56102500 : nt!ObpRemoveObjectRoutine+0x80
ffffa408`944f4890 fffff807`77bfc378 : 00000000`00000000 ffffa60f`576833d0 ffff840d`721e6690 ffffa60f`50872010 : nt!ObfDereferenceObject+0xa4
ffffa408`944f48d0 fffff807`777626d7 : fffff807`00000001 fffff807`77a6a400 ffffa408`944f49a0 ffffa60f`576833d8 : nt!MiSegmentDelete+0x154
ffffa408`944f4920 fffff807`7778f279 : 00000000`00000000 fffff807`00000001 00000000`00000000 fffff807`77a6a400 : nt!MiProcessDereferenceList+0xc3
ffffa408`944f49e0 fffff807`7772a7a5 : ffffa60f`473d4080 ffffa60f`473d4080 00000000`00000080 fffff807`7778f150 : nt!MiDereferenceSegmentThread+0x129
ffffa408`944f4c10 fffff807`777c8b2a : ffffd981`99c80180 ffffa60f`473d4080 fffff807`7772a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffa408`944f4c60 00000000`00000000 : ffffa408`944f5000 ffffa408`944ef000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  8c30faa9d8ac2b59394fc0d42256e9f619d7381d

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  f95d1ca8699e828c538b821c41d8dbb6175892b2

THREAD_SHA1_HASH_MOD:  2c7ea0025fdc68207e0d2ea581806bf3fb0411b0

FOLLOWUP_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h]

FAULT_INSTR_CODE:  684e8b48

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  Ntfs!NtfsFsdClose+f7

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  18633ece

IMAGE_VERSION:  10.0.18362.449

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  f7

FAILURE_BUCKET_ID:  AV_R_INVALID_Ntfs!NtfsFsdClose

BUCKET_ID:  AV_R_INVALID_Ntfs!NtfsFsdClose

PRIMARY_PROBLEM_CLASS:  AV_R_INVALID_Ntfs!NtfsFsdClose

TARGET_TIME:  2019-11-29T15:05:48.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  4145

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_r_invalid_ntfs!ntfsfsdclose

FAILURE_ID_HASH:  {2f10441a-beec-4e13-d39a-66f0294a8a16}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a0046528c9b5a5, Reserved
Arg2: 0000000000000000, Reserved
Arg3: 86351c84ffb74618, Failure type dependent information
Arg4: 0000000000000101, Type of corrupted region, can be
    0   : A generic data region
    1   : Modification of a function or .pdata
    2   : A processor IDT
    3   : A processor GDT
    4   : Type 1 process list corruption
    5   : Type 2 process list corruption
    6   : Debug routine modification
    7   : Critical MSR modification
    8   : Object type
    9   : A processor IVT
    a   : Modification of a system service function
    b   : A generic session data region
    c   : Modification of a session function or .pdata
    d   : Modification of an import table
    e   : Modification of a session import table
    f   : Ps Win32 callout modification
    10  : Debug switch routine modification
    11  : IRP allocator modification
    12  : Driver call dispatcher modification
    13  : IRP completion dispatcher modification
    14  : IRP deallocator modification
    15  : A processor control register
    16  : Critical floating point control register modification
    17  : Local APIC modification
    18  : Kernel notification callout modification
    19  : Loaded module list modification
    1a  : Type 3 process list corruption
    1b  : Type 4 process list corruption
    1c  : Driver object corruption
    1d  : Executive callback object modification
    1e  : Modification of module padding
    1f  : Modification of a protected process
    20  : A generic data region
    21  : A page hash mismatch
    22  : A session page hash mismatch
    23  : Load config directory modification
    24  : Inverted function table modification
    25  : Session configuration modification
    26  : An extended processor control register
    27  : Type 1 pool corruption
    28  : Type 2 pool corruption
    29  : Type 3 pool corruption
    2a  : Type 4 pool corruption
    2b  : Modification of a function or .pdata
    2c  : Image integrity corruption
    2d  : Processor misconfiguration
    2e  : Type 5 process list corruption
    2f  : Process shadow corruption
    30  : Retpoline code page corruption
    101 : General pool corruption
    102 : Modification of win32k.sys

Debugging Details:
------------------


KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: a3a0046528c9b5a5

BUGCHECK_P2: 0

BUGCHECK_P3: 86351c84ffb74618

BUGCHECK_P4: 101

PG_MISMATCH:  10045308000210

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  BAD_STACK_0x109

BUGCHECK_STR:  0x109

PROCESS_NAME:  csrss.exe

CURRENT_IRQL:  2

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:53:59.0806

ANALYSIS_VERSION: 10.0.18362.1 x86fre

STACK_TEXT:
ffffbf85`54bc5e98 00000000`00000000 : 00000000`00000109 a3a00465`28c9b5a5 00000000`00000000 86351c84`ffb74618 : nt!KeBugCheckEx


THREAD_SHA1_HASH_MOD_FUNC:  81a83ae0317433a47fcc36991983df3b6e638b71

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  6e16edd8c7dd677734fdbcd2397a2e35e9fae964

THREAD_SHA1_HASH_MOD:  76cd06466d098060a9eb26e5fd2a25cb1f3fe0a3

SYMBOL_NAME:  ANALYSIS_INCONCLUSIVE

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Unknown_Module

IMAGE_NAME:  Unknown_Image

DEBUG_FLR_IMAGE_TIMESTAMP:  0

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID:  BAD_STACK_0x109

PRIMARY_PROBLEM_CLASS:  BAD_STACK_0x109

FAILURE_BUCKET_ID:  BAD_STACK_0x109

TARGET_TIME:  2019-11-25T15:16:11.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  1f64

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:bad_stack_0x109

FAILURE_ID_HASH:  {b4d7023a-05c3-49b2-3ea4-6240fe57d90e}

Followup:     MachineOwner
---------
 
Hala bellek hatası görüyorum, sistemde kaç bellek takılı? Chipseti siz mi yüklediniz?

Kod:
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003.  This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG.  This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG.  This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8030b13f321, The address that the exception occurred at
Arg3: ffff9c8ed5f92d38, Exception Record Address
Arg4: fffff8030fe7c930, Context Record Address

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8030b13f321

BUGCHECK_P3: ffff9c8ed5f92d38

BUGCHECK_P4: fffff8030fe7c930

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

FAULTING_IP:
nt!MiDemoteCombinedPte+51
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1

EXCEPTION_RECORD:  ffff9c8ed5f92d38 -- (.exr 0xffff9c8ed5f92d38)
ExceptionAddress: fffff8030b13f321 (nt!MiDemoteCombinedPte+0x0000000000000051)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff8030fe7c930 -- (.cxr 0xfffff8030fe7c930)
rax=ffffdc6e371b8000 rbx=3d450227b3050233 rcx=ffffe40546830580
rdx=ffffdc3fff1b1008 rsi=ffffdc3fff1b1008 rdi=ffffdc3fff1b1008
rip=fffff8030b13f321 rsp=ffff9c8ed5f92f70 rbp=ffffdf0677190f00
r8=8000000000000000  r9=0000000fffffffff r10=0000000000000000
r11=ffffb7fe7ca00000 r12=ffffdc6e371b87f8 r13=ffffdf0000000000
r14=8000000000000000 r15=ffffe40546830580
iopl=0         nv up ei ng nz na pe cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00050283
nt!MiDemoteCombinedPte+0x51:
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1 ds:002b:7fffffff`fffffff0=????????????????
Resetting default scope

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

PROCESS_NAME:  NVDispl

CURRENT_IRQL:  2

FOLLOWUP_IP:
nt!MiDemoteCombinedPte+51
fffff803`0b13f321 498378f001      cmp     qword ptr [r8-10h],1

BUGCHECK_STR:  AV

READ_ADDRESS: fffff8030b5733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffffffffffffff

ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:03.0589

ANALYSIS_VERSION: 10.0.18362.1 x86fre

BAD_STACK_POINTER:  fffff8030fe7c0c8

LAST_CONTROL_TRANSFER:  from fffff8030b26aae1 to fffff8030b13f321

STACK_TEXT:
ffff9c8e`d5f92f70 fffff803`0b26aae1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000003 : nt!MiDemoteCombinedPte+0x51
ffff9c8e`d5f93040 fffff803`0b0ace07 : 3d450227`b3050233 00000000`00000000 00000000`00000000 ffff9c8e`d5f934e0 : nt!MiResetAccessBitPte+0xf39a1
ffff9c8e`d5f930a0 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`1fff8d88 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x1e7
ffff9c8e`d5f93160 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`370fffc0 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f93220 fffff803`0b0ad2c1 : ffff9c8e`d5f934e0 ffffdc6e`371b87f8 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f932e0 fffff803`0b0aca4c : ffff9c8e`d5f934e0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x6a1
ffff9c8e`d5f933a0 fffff803`0b17b071 : ffff9c8e`d5f934e0 fffff803`00000002 ffff9c8e`00000001 fffff803`00000000 : nt!MiWalkPageTables+0x36c
ffff9c8e`d5f934a0 fffff803`0b0ac01b : ffffe405`3e294080 fffff803`00000000 ffffe405`46830580 00000000`00000000 : nt!MiCaptureAndResetWorkingSetAccessBits+0x109
ffff9c8e`d5f93790 fffff803`0b0ab52a : ffffe405`46830580 ffff9c8e`d5f93a50 00000000`00000000 00000000`00000000 : nt!MiTrimOrAgeWorkingSet+0x7bb
ffff9c8e`d5f93880 fffff803`0b0a9180 : fffff803`0b46a400 00000000`ffffffff fffff803`0b46a400 ffffe405`37444010 : nt!MiProcessWorkingSets+0x1fa
ffff9c8e`d5f93a30 fffff803`0b2ca1b6 : fffff803`0b46a400 00000000`00000004 00000000`ffffffff 00000000`00000001 : nt!MiWorkingSetManager+0xc8
ffff9c8e`d5f93af0 fffff803`0b18bcb7 : 00000000`00000005 00000000`ffffffff 00000000`00000004 00000000`000005c8 : nt!MmWorkingSetManager+0x12
ffff9c8e`d5f93b20 fffff803`0b12a7a5 : ffffe405`37524080 00000000`00000080 fffff803`0b18ba10 00000000`00000000 : nt!KeBalanceSetManager+0x2a7
ffff9c8e`d5f93c10 fffff803`0b1c8b2a : ffffc800`77080180 ffffe405`37524080 fffff803`0b12a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff9c8e`d5f93c60 00000000`00000000 : ffff9c8e`d5f94000 ffff9c8e`d5f8e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  ac200141e9a7adc5cb469bc451e8d40a01618cc0

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  57b9d753037a95f8e1bcaaa3a5fdf3da4f1f1a34

THREAD_SHA1_HASH_MOD:  38bc5fec3f0409c265cf5c87da6f8f8859d0711c

FAULT_INSTR_CODE:  f0788349

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  nt!MiDemoteCombinedPte+51

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4efcf7a9

IMAGE_VERSION:  10.0.18362.476

STACK_COMMAND:  .cxr 0xfffff8030fe7c930 ; kb

IMAGE_NAME:  memory_corruption

BUCKET_ID_FUNC_OFFSET:  51

FAILURE_BUCKET_ID:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

BUCKET_ID:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

PRIMARY_PROBLEM_CLASS:  AV_STACKPTR_ERROR_nt!MiDemoteCombinedPte

TARGET_TIME:  2019-11-27T14:55:43.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  3c35

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_stackptr_error_nt!midemotecombinedpte

FAILURE_ID_HASH:  {51bd6656-a4b2-8d9b-1231-94678dd83b3a}

Followup:     MachineOwner
---------

INTERNAL_POWER_ERROR (a0)
The power policy manager experienced a fatal error.
Arguments:
Arg1: 000000000000010e, The disk subsystem returned corrupt data while reading from the
    hibernation file.
Arg2: 000000000000000a
Arg3: 000000000000bd73, Incorrect checksum
Arg4: 000000000000c968, Previous disk read's checksum

Debugging Details:
------------------


KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  10.0.18362.476 (WinBuild.160101.0800)

DUMP_FILE_ATTRIBUTES: 0x9
  Hiber Crash Dump
  Kernel Generated Triage Dump

DUMP_TYPE:  2

BUGCHECK_P1: 10e

BUGCHECK_P2: a

BUGCHECK_P3: bd73

BUGCHECK_P4: c968

BUGCHECK_STR:  0xa0_10e

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

CURRENT_IRQL:  f

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:06.0765

ANALYSIS_VERSION: 10.0.18362.1 x86fre

LAST_CONTROL_TRANSFER:  from fffff80519fa6faa to fffff80519bc14e0

STACK_TEXT:
fffff20c`92956648 fffff805`19fa6faa : 00000000`000000a0 00000000`0000010e 00000000`0000000a 00000000`0000bd73 : nt!KeBugCheckEx
fffff20c`92956650 fffff805`19faf1a4 : 00000000`00000001 ffffb70f`23d3d9b0 00000003`7c5fd000 ffffb70f`39e1b000 : nt!PopHiberChecksumHiberFileData+0xaa2a
fffff20c`929566b0 fffff805`19fa64a5 : 00000001`9060f000 ffffa70c`46131f38 00000000`00000001 00000000`00000001 : nt!PopRequestRead+0x78
fffff20c`92956720 fffff805`19f9af9e : 00004167`b19d78ad ffffa70c`46131f38 00000000`00000000 fffff805`1995e848 : nt!PopRestoreHiberContext+0xb165
fffff20c`929567b0 fffff805`19f9acea : fffff805`19e69fd0 fffff20c`92956930 fffff805`19e69fd0 ffffb70f`23d3d9b0 : nt!PopHandleNextState+0x20e
fffff20c`92956800 fffff805`19f9aa5f : 00000000`00000100 00000000`00989680 ffffb70f`23d3d9b0 ffffb70f`23d3d9b0 : nt!PopIssueNextState+0x1a
fffff20c`92956830 fffff805`19f9b2ec : 00000000`0000000c ffff9d00`000077c0 00000000`00000000 fffff805`19a93474 : nt!PopInvokeSystemStateHandler+0x35b
fffff20c`92956a30 fffff805`19f9f6aa : ffffffff`ffffffff ffffffff`ffffffff 00000000`00000014 00000000`00000000 : nt!PopEndMirroring+0x1ec
fffff20c`92956af0 fffff805`19f9f3e5 : 00000000`00000000 00000000`00000000 0000001e`00000001 00000000`00000001 : nt!MmDuplicateMemory+0x26e
fffff20c`92956b80 fffff805`19b2a7a5 : ffffb70f`2cbde000 ffffb70f`2cbde040 fffff805`19f9f2c0 ffff73fa`00000001 : nt!PopTransitionToSleep+0x125
fffff20c`92956c10 fffff805`19bc8b2a : ffff8400`50284180 ffffb70f`2cbde040 fffff805`19b2a750 fffff20c`92956d89 : nt!PspSystemThreadStartup+0x55
fffff20c`92956c60 00000000`00000000 : fffff20c`92957000 fffff20c`92951000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  337d1299c6890b7c6d65ceb358b93db026da4cb1

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  0fca91e4a12cdd0050f5e17d8e04102a11d16bfb

THREAD_SHA1_HASH_MOD:  dc844b1b94baa204d070855e43bbbd27eee98b94

FOLLOWUP_IP:
nt!PopHiberChecksumHiberFileData+aa2a
fffff805`19fa6faa cc              int     3

FAULT_INSTR_CODE:  3840cccc

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!PopHiberChecksumHiberFileData+aa2a

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4efcf7a9

IMAGE_VERSION:  10.0.18362.476

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  aa2a

FAILURE_BUCKET_ID:  0xa0_10e_nt!PopHiberChecksumHiberFileData

BUCKET_ID:  0xa0_10e_nt!PopHiberChecksumHiberFileData

PRIMARY_PROBLEM_CLASS:  0xa0_10e_nt!PopHiberChecksumHiberFileData

TARGET_TIME:  2019-11-25T20:56:36.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  160101.0800

BUILDLAB_STR:  WinBuild

BUILDOSVER_STR:  10.0.18362.476

ANALYSIS_SESSION_ELAPSED_TIME:  af8

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0xa0_10e_nt!pophiberchecksumhiberfiledata

FAILURE_ID_HASH:  {28ba2091-a476-6f77-2dec-6241bccd4685}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffe18f6904eb08, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff803450ac8e0, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys

KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffffe18f6904eb08

BUGCHECK_P2: 0

BUGCHECK_P3: fffff803450ac8e0

BUGCHECK_P4: 2

READ_ADDRESS: fffff80342b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffe18f6904eb08

FAULTING_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx

MM_INTERNAL_CODE:  2

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:10.0348

ANALYSIS_VERSION: 10.0.18362.1 x86fre

TRAP_FRAME:  ffff908caf6d1120 -- (.trap 0xffff908caf6d1120)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffe18f6904eb00
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803450ac8e0 rsp=ffff908caf6d12b0 rbp=ffff808bb393c500
r8=0000000000000000  r9=0000000000000000 r10=fffff803426d5f50
r11=ffffc07bc7200000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po nc
fileinfo!FIStreamCleanup+0x50:
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx ds:ffffe18f`6904eb08=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff803427e35d6 to fffff803427c14e0

STACK_TEXT:
ffff908c`af6d0e78 fffff803`427e35d6 : 00000000`00000050 ffffe18f`6904eb08 00000000`00000000 ffff908c`af6d1120 : nt!KeBugCheckEx
ffff908c`af6d0e80 fffff803`42672eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe18f`6904eb08 : nt!MiSystemFault+0x1d6866
ffff908c`af6d0f80 fffff803`427cf520 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x34f
ffff908c`af6d1120 fffff803`450ac8e0 : ffff808b`b393c500 00000000`00000000 ffff808b`a34d9210 ffff808b`a34d9150 : nt!KiPageFault+0x360
ffff908c`af6d12b0 fffff803`446e86f2 : ffffe18f`4904e260 ffff808b`a34d9150 00000000`00000705 ffffffff`ffffffff : fileinfo!FIStreamCleanup+0x50
ffff908c`af6d1310 fffff803`4471dbbb : ffff808b`b393c528 00000000`00000000 ffffe18f`4904e278 ffffffff`ffffffff : FLTMGR!DoReleaseContext+0x82
ffff908c`af6d1350 fffff803`4471d6a7 : ffff808b`b393c4e0 00000000`00000706 ffff808b`b393c4e8 fffff803`42636a8f : FLTMGR!FltpDeleteContextList+0xab
ffff908c`af6d1380 fffff803`4471efaa : ffff808b`b393c4e0 ffff808b`a38ba190 ffff808b`b393c4e0 ffff808b`b393c4e0 : FLTMGR!CleanupStreamListCtrl+0x47
ffff908c`af6d1400 fffff803`42c70adb : ffffe18f`4824a170 ffff808b`b393c4e8 ffffe18f`00000000 ffff908c`af6d18f0 : FLTMGR!DeleteStreamListCtrlCallback+0xba
ffff908c`af6d1440 fffff803`4524ee26 : ffffe18f`4824a170 ffff908c`af6d1578 ffff908c`af6d18f0 00000000`00000705 : nt!FsRtlTeardownPerStreamContexts+0xcb
ffff908c`af6d1480 fffff803`4524f772 : ffffe18f`4824a170 fffff803`42645ed7 ffffe18f`32200340 ffffe18f`000000ff : Ntfs!NtfsDeleteScb+0x166
ffff908c`af6d1510 fffff803`45174225 : ffffe18f`4824a050 ffffe18f`4824a170 ffffe18f`4824a010 ffffe18f`4824a170 : Ntfs!NtfsRemoveScb+0xba
ffff908c`af6d1570 fffff803`4524f4b0 : ffff908c`af6d18f0 fffff803`452a5450 ffffe18f`4824a010 ffffe18f`4824a400 : Ntfs!NtfsPrepareFcbForRemoval+0x75
ffff908c`af6d15b0 fffff803`4517892a : ffff908c`af6d18f0 ffff908c`af6d16b1 ffffe18f`4824a458 ffff908c`af6d18f0 : Ntfs!NtfsTeardownStructures+0xa0
ffff908c`af6d1630 fffff803`45270cec : ffff908c`af6d1700 ffffe18f`00000000 ffff908c`00000000 ffff908c`af6d18f0 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffff908c`af6d1670 fffff803`4526fc31 : ffff908c`af6d18f0 ffffe18f`4824a170 ffffe18f`4824a010 ffff808b`a38bf180 : Ntfs!NtfsCommonClose+0x45c
ffff908c`af6d1750 fffff803`452a54d8 : 00000000`0000001c fffff803`42b8f240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffff908c`af6d18b0 fffff803`426bd4b5 : ffff808b`9ba94b80 fffff803`42a68200 00000000`00000000 fffff803`4c873830 : Ntfs!NtfsFspClose+0x88
ffff908c`af6d1b70 fffff803`4272a7a5 : ffff808b`aa53b040 00000000`00000080 ffff808b`9ba90040 6e726177`00000001 : nt!ExpWorkerThread+0x105
ffff908c`af6d1c10 fffff803`427c8b2a : ffffd080`18479180 ffff808b`aa53b040 fffff803`4272a750 74726f70`70757302 : nt!PspSystemThreadStartup+0x55
ffff908c`af6d1c60 00000000`00000000 : ffff908c`af6d2000 ffff908c`af6cc000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  8af332adc128204de9b4fd929a43821801049a41

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  90bb67ce4b28a96d58ad1a519aa3a84eb4d74388

THREAD_SHA1_HASH_MOD:  f68501f3e6a4e6ec4bdbfbfbda765ad69e024213

FOLLOWUP_IP:
fileinfo!FIStreamCleanup+50
fffff803`450ac8e0 48395908        cmp     qword ptr [rcx+8],rbx

FAULT_INSTR_CODE:  8593948

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  fileinfo!FIStreamCleanup+50

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: fileinfo

IMAGE_NAME:  fileinfo.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  24bbed20

IMAGE_VERSION:  10.0.18362.1216

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  50

FAILURE_BUCKET_ID:  AV_R_INVALID_fileinfo!FIStreamCleanup

BUCKET_ID:  AV_R_INVALID_fileinfo!FIStreamCleanup

PRIMARY_PROBLEM_CLASS:  AV_R_INVALID_fileinfo!FIStreamCleanup

TARGET_TIME:  2019-11-28T15:10:08.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  5ecc

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_r_invalid_fileinfo!fistreamcleanup

FAILURE_ID_HASH:  {740f90e9-6aa2-7571-b946-cc541647de7d}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff840d78870078, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80779279b47, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys

KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: ffff840d78870078

BUGCHECK_P2: 0

BUGCHECK_P3: fffff80779279b47

BUGCHECK_P4: 2

READ_ADDRESS: fffff80777b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffff840d78870078

FAULTING_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h]

MM_INTERNAL_CODE:  2

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:54:14.0002

ANALYSIS_VERSION: 10.0.18362.1 x86fre

TRAP_FRAME:  ffffa408944f43b0 -- (.trap 0xffffa408944f43b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000150
rdx=ffffa60f47480180 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80779279b47 rsp=ffffa408944f4540 rbp=ffffa60f4743d7a0
r8=ffffa60f471bf070  r9=0000000000000000 r10=fffff8077763e6e0
r11=ffffc97c26800000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
Ntfs!NtfsFsdClose+0xf7:
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h] ds:00000000`00000068=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff807777e35d6 to fffff807777c14e0

STACK_TEXT:
ffffa408`944f4108 fffff807`777e35d6 : 00000000`00000050 ffff840d`78870078 00000000`00000000 ffffa408`944f43b0 : nt!KeBugCheckEx
ffffa408`944f4110 fffff807`77672eef : 00000000`00001000 00000000`00000000 00000000`00000000 ffff840d`78870078 : nt!MiSystemFault+0x1d6866
ffffa408`944f4210 fffff807`777cf520 : 00000000`c0000225 fffff807`786e815c 00000000`00000001 ffffa408`00000000 : nt!MmAccessFault+0x34f
ffffa408`944f43b0 fffff807`79279b47 : ffffa408`944f45f9 fffff807`786e4fc9 ffffa60f`5766f260 ffffa60f`00000000 : nt!KiPageFault+0x360
ffffa408`944f4540 fffff807`77631f79 : ffffa60f`471e2d01 ffffa60f`54518380 ffffa408`944f4730 00000000`00000002 : Ntfs!NtfsFsdClose+0xf7
ffffa408`944f4650 fffff807`786e55de : ffffa60f`54518380 ffffa408`944f4730 ffffa60f`54518380 ffffa408`944f4740 : nt!IofCallDriver+0x59
ffffa408`944f4690 fffff807`786e3f16 : ffffa408`944f4730 ffffa60f`471e2d60 00000000`00000001 ffffa60f`433fe280 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffa408`944f4710 fffff807`77631f79 : ffffa60f`56102500 fffff807`77701ef0 00000000`000037c1 00000000`00000000 : FLTMGR!FltpDispatch+0xb6
ffffa408`944f4770 fffff807`77be74cd : ffffa60f`56102500 ffffa60f`4743d7a0 ffffa60f`471e2d60 ffffa60f`54518380 : nt!IofCallDriver+0x59
ffffa408`944f47b0 fffff807`77bfa0e0 : ffff840d`721e6690 00000000`00000000 ffffa60f`3f6f76c0 fffff807`777077ff : nt!IopDeleteFile+0x12d
ffffa408`944f4830 fffff807`776390c4 : 00000000`00000000 00000000`00000000 ffff840d`721e6690 ffffa60f`56102500 : nt!ObpRemoveObjectRoutine+0x80
ffffa408`944f4890 fffff807`77bfc378 : 00000000`00000000 ffffa60f`576833d0 ffff840d`721e6690 ffffa60f`50872010 : nt!ObfDereferenceObject+0xa4
ffffa408`944f48d0 fffff807`777626d7 : fffff807`00000001 fffff807`77a6a400 ffffa408`944f49a0 ffffa60f`576833d8 : nt!MiSegmentDelete+0x154
ffffa408`944f4920 fffff807`7778f279 : 00000000`00000000 fffff807`00000001 00000000`00000000 fffff807`77a6a400 : nt!MiProcessDereferenceList+0xc3
ffffa408`944f49e0 fffff807`7772a7a5 : ffffa60f`473d4080 ffffa60f`473d4080 00000000`00000080 fffff807`7778f150 : nt!MiDereferenceSegmentThread+0x129
ffffa408`944f4c10 fffff807`777c8b2a : ffffd981`99c80180 ffffa60f`473d4080 fffff807`7772a750 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffa408`944f4c60 00000000`00000000 : ffffa408`944f5000 ffffa408`944ef000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a


THREAD_SHA1_HASH_MOD_FUNC:  8c30faa9d8ac2b59394fc0d42256e9f619d7381d

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  f95d1ca8699e828c538b821c41d8dbb6175892b2

THREAD_SHA1_HASH_MOD:  2c7ea0025fdc68207e0d2ea581806bf3fb0411b0

FOLLOWUP_IP:
Ntfs!NtfsFsdClose+f7
fffff807`79279b47 488b4e68        mov     rcx,qword ptr [rsi+68h]

FAULT_INSTR_CODE:  684e8b48

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  Ntfs!NtfsFsdClose+f7

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  18633ece

IMAGE_VERSION:  10.0.18362.449

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  f7

FAILURE_BUCKET_ID:  AV_R_INVALID_Ntfs!NtfsFsdClose

BUCKET_ID:  AV_R_INVALID_Ntfs!NtfsFsdClose

PRIMARY_PROBLEM_CLASS:  AV_R_INVALID_Ntfs!NtfsFsdClose

TARGET_TIME:  2019-11-29T15:05:48.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  4145

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_r_invalid_ntfs!ntfsfsdclose

FAILURE_ID_HASH:  {2f10441a-beec-4e13-d39a-66f0294a8a16}

Followup:     MachineOwner
---------
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a0046528c9b5a5, Reserved
Arg2: 0000000000000000, Reserved
Arg3: 86351c84ffb74618, Failure type dependent information
Arg4: 0000000000000101, Type of corrupted region, can be
    0   : A generic data region
    1   : Modification of a function or .pdata
    2   : A processor IDT
    3   : A processor GDT
    4   : Type 1 process list corruption
    5   : Type 2 process list corruption
    6   : Debug routine modification
    7   : Critical MSR modification
    8   : Object type
    9   : A processor IVT
    a   : Modification of a system service function
    b   : A generic session data region
    c   : Modification of a session function or .pdata
    d   : Modification of an import table
    e   : Modification of a session import table
    f   : Ps Win32 callout modification
    10  : Debug switch routine modification
    11  : IRP allocator modification
    12  : Driver call dispatcher modification
    13  : IRP completion dispatcher modification
    14  : IRP deallocator modification
    15  : A processor control register
    16  : Critical floating point control register modification
    17  : Local APIC modification
    18  : Kernel notification callout modification
    19  : Loaded module list modification
    1a  : Type 3 process list corruption
    1b  : Type 4 process list corruption
    1c  : Driver object corruption
    1d  : Executive callback object modification
    1e  : Modification of module padding
    1f  : Modification of a protected process
    20  : A generic data region
    21  : A page hash mismatch
    22  : A session page hash mismatch
    23  : Load config directory modification
    24  : Inverted function table modification
    25  : Session configuration modification
    26  : An extended processor control register
    27  : Type 1 pool corruption
    28  : Type 2 pool corruption
    29  : Type 3 pool corruption
    2a  : Type 4 pool corruption
    2b  : Modification of a function or .pdata
    2c  : Image integrity corruption
    2d  : Processor misconfiguration
    2e  : Type 5 process list corruption
    2f  : Process shadow corruption
    30  : Retpoline code page corruption
    101 : General pool corruption
    102 : Modification of win32k.sys

Debugging Details:
------------------


KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  System manufacturer

SYSTEM_PRODUCT_NAME:  System Product Name

SYSTEM_SKU:  SKU

SYSTEM_VERSION:  System Version

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  2901

BIOS_DATE:  10/16/2019

BASEBOARD_MANUFACTURER:  ASUSTeK COMPUTER INC.

BASEBOARD_PRODUCT:  ROG STRIX B450-I GAMING

BASEBOARD_VERSION:  Rev 1.xx

DUMP_TYPE:  2

BUGCHECK_P1: a3a0046528c9b5a5

BUGCHECK_P2: 0

BUGCHECK_P3: 86351c84ffb74618

BUGCHECK_P4: 101

PG_MISMATCH:  10045308000210

CPU_COUNT: 10

CPU_MHZ: e6d

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 8

CPU_STEPPING: 2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  BAD_STACK_0x109

BUGCHECK_STR:  0x109

PROCESS_NAME:  csrss.exe

CURRENT_IRQL:  2

ANALYSIS_SESSION_HOST:  DESKTOP-18V31A3

ANALYSIS_SESSION_TIME:  11-29-2019 22:53:59.0806

ANALYSIS_VERSION: 10.0.18362.1 x86fre

STACK_TEXT:
ffffbf85`54bc5e98 00000000`00000000 : 00000000`00000109 a3a00465`28c9b5a5 00000000`00000000 86351c84`ffb74618 : nt!KeBugCheckEx


THREAD_SHA1_HASH_MOD_FUNC:  81a83ae0317433a47fcc36991983df3b6e638b71

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  6e16edd8c7dd677734fdbcd2397a2e35e9fae964

THREAD_SHA1_HASH_MOD:  76cd06466d098060a9eb26e5fd2a25cb1f3fe0a3

SYMBOL_NAME:  ANALYSIS_INCONCLUSIVE

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Unknown_Module

IMAGE_NAME:  Unknown_Image

DEBUG_FLR_IMAGE_TIMESTAMP:  0

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID:  BAD_STACK_0x109

PRIMARY_PROBLEM_CLASS:  BAD_STACK_0x109

FAILURE_BUCKET_ID:  BAD_STACK_0x109

TARGET_TIME:  2019-11-25T15:16:11.000Z

OSBUILD:  18362

OSSERVICEPACK:  476

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2011-12-30 02:28:41

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  1f64

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:bad_stack_0x109

FAILURE_ID_HASH:  {b4d7023a-05c3-49b2-3ea4-6240fe57d90e}

Followup:     MachineOwner
---------
2 ram yuvası var 2 ram takılı.. memtestte neden hata gözükmemiştir sizce
 
Uyarı! Bu konu 5 yıl önce açıldı.
Muhtemelen daha fazla tartışma gerekli değildir ki bu durumda yeni bir konu başlatmayı öneririz. Eğer yine de cevabınızın gerekli olduğunu düşünüyorsanız buna rağmen cevap verebilirsiniz.

Yeni konular

Geri
Yukarı