SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff804402158f7, The address that the exception occurred at
Arg3: ffff8988fef55918, Exception Record Address
Arg4: ffff8988fef55150, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 4312
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on TEKNOBUS
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 5491
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff804402158f7
BUGCHECK_P3: ffff8988fef55918
BUGCHECK_P4: ffff8988fef55150
EXCEPTION_RECORD: ffff8988fef55918 -- (.exr 0xffff8988fef55918)
ExceptionAddress: fffff804402158f7 (CI+0x00000000000258f7)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 000000004f00e978
Attempt to read from address 000000004f00e978
CONTEXT: ffff8988fef55150 -- (.cxr 0xffff8988fef55150)
rax=4ad638288c23ad2c rbx=9b6e465f9fe87b92 rcx=ffff9e01d2f2e220
rdx=ba9e10daa559fb72 rsi=dd3f029ec1654d5d rdi=ffff9e01d2f2e2a0
rip=fffff804402158f7 rsp=ffff8988fef55b58 rbp=5bf592ad03fb8fc9
r8=ffff9e01d2f2e3a0 r9=0000000000000002 r10=242ddacd02e94cde
r11=d23ec29d43844dc4 r12=3ecd7de1fc7e6cc1 r13=1bd4507933229288
r14=c78da89b72886dc9 r15=2cc36fb9c113a831
iopl=0 ov up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050a02
CI+0x258f7:
fffff804`402158f7 c4e2fbf65910 mulx rbx,rax,qword ptr [rcx+10h] ds:002b:ffff9e01`d2f2e230=ecf4ca502d547799
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff8043befa390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8043be0f2f0: Unable to get Flags value from nt!KdVersionBlock
fffff8043be0f2f0: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
000000004f00e978
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 000000004f00e978
EXCEPTION_STR: 0xc0000005
LOCK_ADDRESS: fffff8043be44b40 -- (!locks fffff8043be44b40)
Resource @ nt!PiEngineLock (0xfffff8043be44b40) Exclusively owned
Contention Count = 1
NumberOfExclusiveWaiters = 1
Threads: ffff8d8fc62eb040-01<*>
Threads Waiting On Exclusive Access:
ffff8d8fd1f06040
1 total locks
PNP_TRIAGE_DATA:
Lock address : 0xfffff8043be44b40
Thread Count : 1
Thread address: 0xffff8d8fc62eb040
Thread wait : 0x163
STACK_TEXT:
ffff8988`fef55b58 fffff804`40208109 : ffff9e01`d2f2e220 00000004`00000004 ffff9e01`d2f2e320 ffff9e01`d2f2e320 : CI+0x258f7
ffff8988`fef55ba0 fffff804`402091a7 : ffff9e01`cf7d10c0 00000000`00004440 00000000`00000100 fffff804`40207e4c : CI+0x18109
ffff8988`fef55bd0 fffff804`40200ff2 : 00000000`00000000 ffff9e01`cf7d1000 ffff9e01`d2f2e020 ffff9e01`d2f2e020 : CI+0x191a7
ffff8988`fef55c30 fffff804`40201920 : 00000000`00000000 ffff9e01`d2f2e020 ffff9e01`d2f2e020 ffff9e01`d2f2806b : CI+0x10ff2
ffff8988`fef55c80 fffff804`40201a7b : ffff9e01`d2eea020 00000000`000004c0 ffff9e01`d2eea020 ffff9e01`d2f2e020 : CI+0x11920
ffff8988`fef55dc0 fffff804`402a9c2f : 00000000`00000000 ffff9e01`cf7d1000 ffff9e01`cf7d1000 ffff9e01`d2f2806b : CI+0x11a7b
ffff8988`fef55e40 fffff804`40257570 : 00000000`00002400 ffff9e01`d2ed3aa0 00000000`00000020 ffff9e01`cf4ba410 : CI!CiSetTrustedOriginClaimId+0x59bbf
ffff8988`fef55ef0 fffff804`40255b5f : 00000000`00000000 ffff9e01`cf7cc138 00000000`00000000 ffff9e01`d2ed3970 : CI!CiSetTrustedOriginClaimId+0x7500
ffff8988`fef56040 fffff804`4025777a : ffff8988`fef56250 ffff9e01`cf7cc7e0 00000000`00000000 fffff804`00000000 : CI!CiSetTrustedOriginClaimId+0x5aef
ffff8988`fef56160 fffff804`4023a143 : 00000000`fffffffe ffff9e01`cfcf5c10 00000000`00000000 00000000`00000000 : CI!CiSetTrustedOriginClaimId+0x770a
ffff8988`fef56210 fffff804`40251a2a : 00000000`00000001 00000000`00000001 ffff8988`fef563f0 ffff8988`fef56348 : CI!CiFreePolicyInfo+0x56b3
ffff8988`fef562f0 fffff804`40240928 : ffff9e01`cf7cc7e0 00000000`c0000428 fffff804`54ee0110 fffff804`402427fd : CI!CiSetTrustedOriginClaimId+0x19ba
ffff8988`fef56440 fffff804`40241c79 : 00000000`00000000 ffff8988`fef56771 00000000`00000000 00000000`00000000 : CI!CiFreePolicyInfo+0xbe98
ffff8988`fef565a0 fffff804`402415ac : ffff9e01`cf7cc010 ffff8d8f`d11b8a40 ffff8d8f`c60df080 fffff804`54ee0000 : CI!CiFreePolicyInfo+0xd1e9
ffff8988`fef56680 fffff804`4023f9e2 : 00000000`00000088 00000000`00000000 ffff8d8f`d11b8a40 fffff804`54ee0000 : CI!CiFreePolicyInfo+0xcb1c
ffff8988`fef567c0 fffff804`3b84a97d : ffff8988`fef56a00 fffff804`54ee0000 00000000`0000000f fffff804`54ee0000 : CI!CiFreePolicyInfo+0xaf52
ffff8988`fef56940 fffff804`3b84a4d8 : 00000000`00000000 ffff8d8f`d1457a60 00000000`00000000 00000000`00016000 : nt!SeValidateImageHeader+0xd9
ffff8988`fef569f0 fffff804`3b8483e3 : ffff8988`fef56f00 00000000`00000000 00000000`00000000 ffffffff`80000594 : nt!MiValidateSectionCreate+0x438
ffff8988`fef56bd0 fffff804`3b8d2102 : ffff8988`fef56f10 ffff8988`fef56f10 ffff8988`fef56d30 00000000`00000000 : nt!MiValidateSectionSigningPolicy+0xab
ffff8988`fef56c30 fffff804`3b86e1cb : ffff8d8f`d11b8a40 ffff8988`fef56f10 ffff8988`fef56f10 00000000`00000000 : nt!MiCreateNewSection+0x66e
ffff8988`fef56da0 fffff804`3b86d814 : ffff8988`fef56dd0 ffff9e01`d2eaaab0 ffff8d8f`d11b8a40 00000000`00000000 : nt!MiCreateImageOrDataSection+0x2db
ffff8988`fef56e90 fffff804`3b55d838 : 00000000`00000000 00000000`ffffffff ffffffff`80000520 fffff804`3b444c59 : nt!MiCreateSection+0xf4
ffff8988`fef57010 fffff804`3b94e7a2 : 00000000`00000000 ffff8988`fef57129 ffffffff`80000520 00000000`00000000 : nt!MiCreateSystemSection+0xa4
ffff8988`fef570b0 fffff804`3b94c07e : fffff804`3be2a2f0 ffffffff`80000520 ffff8988`fef57248 00000000`00000000 : nt!MiCreateSectionForDriver+0x126
ffff8988`fef57190 fffff804`3b94b8d2 : 00000000`00000000 ffff8988`fef572e0 00000000`00000000 00000000`000009c8 : nt!MiObtainSectionForDriver+0xa6
ffff8988`fef571e0 fffff804`3b94b766 : ffff8988`fef57418 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmLoadSystemImageEx+0x156
ffff8988`fef57380 fffff804`3b92ba54 : ffff8988`fef574c0 00000000`00000000 fffff804`3be45880 00000000`00000000 : nt!MmLoadSystemImage+0x26
ffff8988`fef573c0 fffff804`3b92d686 : 00000000`00000000 00000000`00000000 00000000`00000004 ffff8988`00000004 : nt!IopLoadDriver+0x23c
ffff8988`fef57590 fffff804`3b92d396 : fffff804`3b20a101 00000000`00000000 ffff8d8f`d1dbf320 ffffffff`80000628 : nt!PipCallDriverAddDeviceQueryRoutine+0x1be
ffff8988`fef57620 fffff804`3b92cd54 : 00000000`00000000 ffff8988`fef57730 00000000`6e657050 fffff804`00000024 : nt!PnpCallDriverQueryServiceHelper+0xda
ffff8988`fef576d0 fffff804`3b92c4e7 : ffff8d8f`d19e52d0 ffff8988`fef57911 ffff8d8f`d19e52d0 00000000`00000000 : nt!PipCallDriverAddDevice+0x41c
ffff8988`fef57890 fffff804`3b9c32ac : ffff8d8f`d0cfa400 ffff8988`fef57a01 ffff8988`fef579b0 fffff804`00000000 : nt!PipProcessDevNodeTree+0x333
ffff8988`fef57960 fffff804`3b55bd7c : 00000001`00000003 ffff8d8f`d0cfa460 00000000`00000000 ffff8d8f`d0cfa460 : nt!PiProcessStartSystemDevices+0x60
ffff8988`fef579b0 fffff804`3b433f45 : ffff8d8f`c62eb040 ffff8d8f`c6102a60 fffff804`3be43480 ffff8d8f`00000000 : nt!PnpDeviceActionWorker+0x4cc
ffff8988`fef57a70 fffff804`3b546745 : ffff8d8f`c62eb040 00000000`00000080 ffff8d8f`c60df080 00000000`00000000 : nt!ExpWorkerThread+0x105
ffff8988`fef57b10 fffff804`3b5e5598 : ffffb081`d4647180 ffff8d8f`c62eb040 fffff804`3b5466f0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff8988`fef57b60 00000000`00000000 : ffff8988`fef58000 ffff8988`fef51000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: CI+258f7
MODULE_NAME: CI
IMAGE_NAME: CI.dll
IMAGE_VERSION: 10.0.19041.450
STACK_COMMAND: .cxr 0xffff8988fef55150 ; kb
BUCKET_ID_FUNC_OFFSET: 258f7
FAILURE_BUCKET_ID: AV_CI!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {fd26e961-fe42-67bc-8b39-afa3c1dac45e}
Followup: MachineOwner
---------
8: kd> lmvm CI
Browse full module list
start end module name
fffff804`401f0000 fffff804`402d3000 CI # (export symbols) CI.dll
Loaded symbol image file: CI.dll
Mapped memory image file: C:\ProgramData\Dbg\sym\CI.dll\40A75AC0e3000\CI.dll
Image path: \SystemRoot\system32\CI.dll
Image name: CI.dll
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 40A75AC0 (This is a reproducible build file hash, not a timestamp)
CheckSum: 000E6A98
ImageSize: 000E3000
File version: 10.0.19041.450
Product version: 10.0.19041.450
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ci.dll
OriginalFilename: ci.dll
ProductVersion: 10.0.19041.450
FileVersion: 10.0.19041.450 (WinBuild.160101.0800)
FileDescription: Code Integrity Module
LegalCopyright: © Microsoft Corporation. All rights reserved.
8: kd> !blackboxbsd
Stream size mismatch (expected = 192, read = 168)