SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff807316f3acc, The address that the exception occurred at
Arg3: ffff848c6a74ef98, Exception Record Address
Arg4: ffff848c6a74e7d0, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify checksum for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Write
Key : Analysis.CPU.mSec
Value: 5968
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 14932
Key : Analysis.Init.CPU.mSec
Value: 1186
Key : Analysis.Init.Elapsed.mSec
Value: 40793
Key : Analysis.Memory.CommitPeak.Mb
Value: 92
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff807316f3acc
BUGCHECK_P3: ffff848c6a74ef98
BUGCHECK_P4: ffff848c6a74e7d0
EXCEPTION_RECORD: ffff848c6a74ef98 -- (.exr 0xffff848c6a74ef98)
ExceptionAddress: fffff807316f3acc (nt!RtlDeleteNoSplay+0x000000000000004c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000002000
Attempt to write to address 0000000000002000
CONTEXT: ffff848c6a74e7d0 -- (.cxr 0xffff848c6a74e7d0)
rax=ffffc7067b674808 rbx=ffffc7067b674808 rcx=0000000000002000
rdx=ffffa48a9f8a5260 rsi=ffffffffffffffff rdi=ffffa48a9f8a5260
rip=fffff807316f3acc rsp=ffff848c6a74f1d0 rbp=ffffffffffffffff
r8=ffffffffffffffff r9=ffffffffffffffff r10=fffff807316f3a80
r11=0000000000000544 r12=0000000000008000 r13=ffff848c6a74f7f0
r14=ffffa48a9f8a5260 r15=00000000ffff7fff
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
nt!RtlDeleteNoSplay+0x4c:
fffff807`316f3acc 488909 mov qword ptr [rcx],rcx ds:002b:00000000`00002000=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
WRITE_ADDRESS: fffff807320fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000002000
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000002000
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffff848c`6a74f1d0 fffff807`359b86c0 : ffffc706`79037678 fffff807`31660ace ffffa48a`9bd3b040 ffffa48a`9f8a5248 : nt!RtlDeleteNoSplay+0x4c
ffff848c`6a74f200 fffff807`359ec6d1 : ffffa48a`9f8a51e0 ffffffff`00000000 ffffc706`00000000 ffffffff`ffffffff : FLTMGR!TreeUnlinkMulti+0x90
ffff848c`6a74f250 fffff807`359ec858 : ffffa48a`9f8a51e0 ffffa48a`902870a0 00000000`00000705 ffffffff`ffffffff : FLTMGR!DeleteNameCacheNodes+0xa1
ffff848c`6a74f2b0 fffff807`359ecd8a : ffffa48a`9f8a51e0 ffffa48a`9f8a51e8 ffffa48a`9f8a51e0 ffffa48a`9f8a51e0 : FLTMGR!CleanupStreamListCtrl+0x80
ffff848c`6a74f2f0 fffff807`31ab9609 : ffffc706`757491a8 ffffa48a`9f8a51e8 00000000`00000000 ffff848c`6a74f7f0 : FLTMGR!DeleteStreamListCtrlCallback+0xba
ffff848c`6a74f330 fffff807`36620bbb : ffffc706`75749170 ffff848c`6a74f478 ffff848c`6a74f7f0 00000000`00000705 : nt!FsRtlTeardownPerStreamContexts+0xc9
ffff848c`6a74f370 fffff807`36620946 : ffffc706`75749170 ffffc706`74886200 ffffc706`000005cf fffff807`365057f2 : Ntfs!NtfsDeleteScb+0x17b
ffff848c`6a74f410 fffff807`36515425 : 00000000`00000000 ffffc706`75749170 ffffc706`7574b9f8 00000000`00000000 : Ntfs!NtfsRemoveScb+0x66
ffff848c`6a74f470 fffff807`366206dc : ffff848c`6a74f7f0 fffff807`3665ab20 ffffc706`75749010 ffffc706`75749400 : Ntfs!NtfsPrepareFcbForRemoval+0x75
ffff848c`6a74f4b0 fffff807`365039f0 : ffff848c`6a74f7f0 ffff848c`6a74f5b2 ffffc706`75749468 ffffc706`75749010 : Ntfs!NtfsTeardownStructures+0x9c
ffff848c`6a74f530 fffff807`365e6527 : ffff848c`6a74f600 ffffc706`00000000 00000000`00000000 ffffc706`75749000 : Ntfs!NtfsDecrementCloseCounts+0xb0
ffff848c`6a74f570 fffff807`365e3041 : ffff848c`6a74f7f0 ffffc706`75749170 ffffc706`75749010 ffffa48a`90290180 : Ntfs!NtfsCommonClose+0x467
ffff848c`6a74f650 fffff807`3665aba8 : 00000000`0000001c fffff807`32125440 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffff848c`6a74f7b0 fffff807`31625975 : ffffa48a`9bd3b040 fffff807`505dad50 ffffa48a`8bab0a20 ffffa48a`00000000 : Ntfs!NtfsFspClose+0x88
ffff848c`6a74fa70 fffff807`31717e85 : ffffa48a`9bd3b040 00000000`00000080 ffffa48a`8bab8040 00000000`0000081c : nt!ExpWorkerThread+0x105
ffff848c`6a74fb10 fffff807`317fd2a8 : ffffb601`24b28180 ffffa48a`9bd3b040 fffff807`31717e30 00000000`000018f4 : nt!PspSystemThreadStartup+0x55
ffff848c`6a74fb60 00000000`00000000 : ffff848c`6a750000 ffff848c`6a749000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!RtlDeleteNoSplay+4c
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.870
STACK_COMMAND: .cxr 0xffff848c6a74e7d0 ; kb
BUCKET_ID_FUNC_OFFSET: 4c
FAILURE_BUCKET_ID: AV_nt!RtlDeleteNoSplay
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {bebce8cf-2824-8195-e433-1ad6c75dc3f0}
Followup: MachineOwner
---------
5: kd> !sysinfo machineid
Machine ID Information [From Smbios 3.2, DMIVersion 0, Size=4436]
BiosMajorRelease = 5
BiosMinorRelease = 17
BiosVendor = American Megatrends Inc.
BiosVersion = 1.80
BiosReleaseDate = 11/16/2020
SystemManufacturer = Micro-Star International Co., Ltd.
SystemProductName = MS-7C89
SystemFamily = Default string
SystemVersion = 1.0
SystemSKU = Default string
BaseBoardManufacturer = Micro-Star International Co., Ltd.
BaseBoardProduct = H410M-A PRO (MS-7C89)
BaseBoardVersion = 1.0