FAT_FILE_SYSTEM (23)
If you see FatExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000000e0121
Arg2: ffffe205ad1fd518
Arg3: ffffe205ad1fcd60
Arg4: fffff8017fe9f2eb
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullClassPtr
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: e0121
BUGCHECK_P2: ffffe205ad1fd518
BUGCHECK_P3: ffffe205ad1fcd60
BUGCHECK_P4: fffff8017fe9f2eb
EXCEPTION_RECORD: ffffe205ad1fd518 -- (.exr 0xffffe205ad1fd518)
ExceptionAddress: fffff8017fe9f2eb (volmgr!VmpQueryUniqueIdInternal+0x0000000000000037)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000040
Attempt to read from address 0000000000000040
CONTEXT: ffffe205ad1fcd60 -- (.cxr 0xffffe205ad1fcd60)
rax=0000000000000000 rbx=ffffcf04fb6ed6a0 rcx=ffffcf04fb6ed600
rdx=0000000000000000 rsi=ffffcf04f7af45c0 rdi=0000000000000000
rip=fffff8017fe9f2eb rsp=ffffe205ad1fd750 rbp=ffffe205ad1fd809
r8=ffffe205ad1fd802 r9=ffffcf04fb6ed6a0 r10=00000000ffffffff
r11=ffffe205ad1fd760 r12=fffff80182c2f001 r13=ffffcf04f1190ca0
r14=ffffe205ad1fd800 r15=ffffe205ad1fd802
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
volmgr!VmpQueryUniqueIdInternal+0x37:
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h] ds:002b:00000000`00000040=????????????????
Resetting default scope
CPU_COUNT: c
CPU_MHZ: d48
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
FOLLOWUP_IP:
volmgr!VmpQueryUniqueIdInternal+37
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h]
FAULTING_IP:
volmgr!VmpQueryUniqueIdInternal+37
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h]
BUGCHECK_STR: 0x23
READ_ADDRESS: fffff8017bf733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000000000040
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000040
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-16-2020 15:49:40.0093
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8017fea02ce to fffff8017fe9f2eb
STACK_TEXT:
ffffe205`ad1fd750 fffff801`7fea02ce : ffffcf04`fb6ed6a0 ffffcf04`f7af45c0 00000000`0fb00000 ffffcf04`f1190c01 : volmgr!VmpQueryUniqueIdInternal+0x37
ffffe205`ad1fd780 fffff801`7fea078f : ffffcf04`faf9df40 ffffcf04`f7af45c0 00000000`00000000 000000a0`00000000 : volmgr!VmpSetPartitionInformation+0x2c0e
ffffe205`ad1fd870 fffff801`7fe918eb : ffffcf04`fb6ed6a0 ffffe205`ad1fd8f0 00000000`00000000 ffffcf04`faf9d960 : volmgr!VmpGetPartitionInfoEx+0x4627
ffffe205`ad1fd8b0 fffff801`7ba31f79 : ffffcf04`faf9d960 ffffcf04`faf9d960 ffffffff`ffffffff ffffffff`ffffffff : volmgr!VmDeviceControl+0x2bb
ffffe205`ad1fd920 fffff801`7bb21b7e : ffffcf04`ee013640 00000000`000000a0 00000000`00000000 00000000`00000680 : nt!IofCallDriver+0x59
ffffe205`ad1fd960 fffff801`7c0ce841 : ffffe480`20400000 00000000`20206f49 00000000`00000000 00000000`000000e0 : nt!IoSynchronousCallDriver+0x4e
ffffe205`ad1fd9c0 fffff801`82c7439e : 00000000`00000000 ffffffff`ffffffff ffffe205`ad1fdb10 fffff801`7ba33294 : nt!IoForwardIrpSynchronously+0x41
ffffe205`ad1fd9f0 fffff801`82c13d77 : ffffcf04`faf9d960 ffffcf04`fa68c801 ffffcf04`faf39180 00000000`00000000 : fvevol!IoctlDiskQuery+0x7a
ffffe205`ad1fdae0 fffff801`7ba31f79 : 00000000`00000000 00000000`00000000 ffffcf04`fa68c8a0 00000000`00000000 : fvevol!FveFilterDeviceControl+0x207
ffffe205`ad1fdbe0 fffff801`803e1033 : ffffe205`ad1fddb8 fffff801`7ba2a2af 00000000`00070048 ffffcf04`faf9d960 : nt!IofCallDriver+0x59
ffffe205`ad1fdc20 fffff801`7ba31f79 : ffffe205`ad1fddf0 fffff801`00000090 ffffcf04`fba93c00 ffffe205`ad1fdcf0 : volume!VolumePassThrough+0x23
ffffe205`ad1fdc50 fffff801`8bc71ec6 : 00000000`00000000 ffffcf04`fba93c68 00000000`00000000 00000000`00000000 : nt!IofCallDriver+0x59
ffffe205`ad1fdc90 fffff801`8bc82f8c : ffffcf04`fa68cf01 ffffcf04`f50f6800 00000000`00000000 ffffcf04`fa68cf10 : fastfat!FatPerformDevIoCtrl+0xca
ffffe205`ad1fdd20 fffff801`8bc820d4 : ffffcf04`f141a560 ffffcf04`f5e48760 ffffcf04`fa68c8a0 ffffcf04`fb9779e0 : fastfat!FatVerifyVolume+0x190
ffffe205`ad1fdf00 fffff801`8bc82032 : ffffcf04`fa68c8a0 ffffcf04`fa68cf01 ffffcf04`fa68cf01 ffffcf04`fb871d00 : fastfat!FatCommonFileSystemControl+0x44
ffffe205`ad1fdf30 fffff801`7ba31f79 : ffffcf04`fb6839b0 ffffcf04`fa68c8a0 ffffe205`ad1fe000 ffffcf04`fa68cf58 : fastfat!FatFsdFileSystemControl+0xb2
ffffe205`ad1fdf70 fffff801`7f6e55de : 00000000`00000000 ffffcf04`fb6ed500 ffffcf04`fa68c8a0 ffffe205`ad1fe060 : nt!IofCallDriver+0x59
ffffe205`ad1fdfb0 fffff801`7f71c190 : ffffe205`ad1fe050 00000000`00000700 00000000`00000001 fffff801`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffe205`ad1fe030 fffff801`7ba31f79 : ffffcf04`fb6ed550 ffffe205`ad1fe130 ffffcf04`fa68c8a0 ffffe205`ad1fe100 : FLTMGR!FltpFsControl+0x110
ffffe205`ad1fe090 fffff801`7c25810b : ffffe205`ad1fe130 ffffcf04`fb6ed550 ffffcf04`fa68c8a0 ffffcf04`fb871d70 : nt!IofCallDriver+0x59
ffffe205`ad1fe0d0 fffff801`8bc8d037 : ffffcf04`f50f6800 ffffcf04`fbabca20 ffffcf04`fba93870 00000000`00000000 : nt!IoVerifyVolume+0x12b
ffffe205`ad1fe170 fffff801`8bc7c65b : ffffcf04`f10e5c80 ffffcf04`f9e488a0 ffffcf04`fb6ed550 00000000`00000002 : fastfat!FatPerformVerify+0x93
ffffe205`ad1fe1e0 fffff801`8bc6a192 : ffffcf04`f10e5c80 ffffcf04`f9e488a0 ffffcf04`80000016 ffffcf04`00000001 : fastfat!FatProcessException+0x3e3
ffffe205`ad1fe260 fffff801`7ba31f79 : ffffcf04`fba93870 ffffcf04`f9e488a0 ffffcf04`f141a501 ffffcf04`fb884010 : fastfat!FatFsdCreate+0x132
ffffe205`ad1fe2f0 fffff801`7f6e55de : ffffcf04`f9e488a0 ffffcf04`f9e48f00 ffffcf04`f9e488a0 ffffcf04`fd204da0 : nt!IofCallDriver+0x59
ffffe205`ad1fe330 fffff801`7f71cd27 : ffffe205`ad1fe3f0 00000000`00000000 00000000`00000001 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffe205`ad1fe3b0 fffff801`7ba31f79 : ffffcf04`fd204d00 fffff801`7bfe5b25 00000000`00000000 00000000`00000030 : FLTMGR!FltpCreate+0x307
ffffe205`ad1fe460 fffff801`7ba31024 : 00000000`00000000 ffffcf04`f50f6800 ffffcf04`f9e48fa0 fffff801`7ba317e3 : nt!IofCallDriver+0x59
ffffe205`ad1fe4a0 fffff801`7bfe61eb : ffffe205`ad1fe760 fffff801`7bfe5b25 ffffe205`ad1fe6d0 ffffcf04`ef289520 : nt!IoCallDriverWithTracing+0x34
ffffe205`ad1fe4f0 fffff801`7bfed1bf : ffffcf04`fb6ed550 ffffcf04`fb6ed525 ffffcf04`fb20a4c0 ffffbc0c`48e0ae01 : nt!IopParseDevice+0x62b
ffffe205`ad1fe660 fffff801`7bfeb621 : ffffcf04`fb20a400 ffffe205`ad1fe8a8 00000000`00000040 ffffcf04`edcf4d20 : nt!ObpLookupObjectName+0x78f
ffffe205`ad1fe820 fffff801`7c030df0 : ffffcf04`00000001 0000008e`34a7e5f8 00000000`00000001 00000000`00000000 : nt!ObOpenObjectByNameEx+0x201
ffffe205`ad1fe960 fffff801`7c0305b9 : 0000008e`34a7e5a0 00000000`80100080 0000008e`34a7e5f8 0000008e`34a7e5b8 : nt!IopCreateFile+0x820
ffffe205`ad1fea00 fffff801`7bbd2d18 : 00000000`000002f4 00000000`00400004 00000000`00000000 000001e7`2511e0c0 : nt!NtCreateFile+0x79
ffffe205`ad1fea90 00007fff`ec53cb64 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000008e`34a7e528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`ec53cb64
THREAD_SHA1_HASH_MOD_FUNC: c59bac712340d40778e7452ded139852d421e393
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f414499de867805ed9dfbc8bc07d1519579b58db
THREAD_SHA1_HASH_MOD: 6f9201a36e99e0303f196d6d14f07d17f43be59c
FAULT_INSTR_CODE: 40508b48
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: volmgr!VmpQueryUniqueIdInternal+37
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: volmgr
IMAGE_NAME: volmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 211cef76
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .cxr 0xffffe205ad1fcd60 ; kb
BUCKET_ID_FUNC_OFFSET: 37
FAILURE_BUCKET_ID: 0x23_volmgr!VmpQueryUniqueIdInternal
BUCKET_ID: 0x23_volmgr!VmpQueryUniqueIdInternal
PRIMARY_PROBLEM_CLASS: 0x23_volmgr!VmpQueryUniqueIdInternal
TARGET_TIME: 2020-01-16T12:36:30.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 9948
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x23_volmgr!vmpqueryuniqueidinternal
FAILURE_ID_HASH: {d0e2cbbb-f6c9-659f-dade-4145ab43ee0a}
Followup: MachineOwner
---------
Hocam sizce AMD 20.1.1 güncellemesiyle hataları gidermiş midir?Minidump paylaşın.
Bence daha kötü oldu.Hocam sizce AMD 20.1.1 güncellemesiyle hataları gidermişmidir?
Windows memory taraması sonuçlarını mı paylaşayım hocam? Tam anlayamadım kusura bakmayın.Minidump paylaşın.
011020-27625-01.rar Buyur abi geç oldu kusura bakma yeni öğrendim minidump olayını.Minidump paylaşın.
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffffffffffffd0, memory referenced.
Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.
Arg3: fffff80333004584, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for FACEIT.sys
Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffffffffd0
BUGCHECK_P2: 2
BUGCHECK_P3: fffff80333004584
BUGCHECK_P4: 2
READ_ADDRESS: fffff803335733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffffffffffffd0
FAULTING_IP:
nt!ObfReferenceObjectWithTag+24
fffff803`33004584 f0480fc15ed0 lock xadd qword ptr [rsi-30h],rbx
MM_INTERNAL_CODE: 2
CPU_COUNT: c
CPU_MHZ: d48
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-16-2020 01:58:33.0818
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffe9016c78e3a0 -- (.trap 0xffffe9016c78e3a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000008000 rbx=0000000000000000 rcx=0000000000000000
rdx=00000000746c6644 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80333004584 rsp=ffffe9016c78e530 rbp=fffff803877cb1bc
r8=ffff88811b9b8d20 r9=ffff88811b9b8d20 r10=ffff888119202000
r11=ffffe9016c78e4f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ObfReferenceObjectWithTag+0x24:
fffff803`33004584 f0480fc15ed0 lock xadd qword ptr [rsi-30h],rbx ds:ffffffff`ffffffd0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff803331e35d6 to fffff803331c14e0
STACK_TEXT:
ffffe901`6c78e0f8 fffff803`331e35d6 : 00000000`00000050 ffffffff`ffffffd0 00000000`00000002 ffffe901`6c78e3a0 : nt!KeBugCheckEx
ffffe901`6c78e100 fffff803`33072eef : 00000000`00000000 00000000`00000002 00000000`00000000 ffffffff`ffffffd0 : nt!MiSystemFault+0x1d6866
ffffe901`6c78e200 fffff803`331cf520 : 00000000`00000001 00000000`00000070 ffff8881`2bd48dd0 ffff8881`18010000 : nt!MmAccessFault+0x34f
ffffe901`6c78e3a0 fffff803`33004584 : 00000000`00000000 00000000`00000058 00000000`00000000 fffff803`3336f06d : nt!KiPageFault+0x360
ffffe901`6c78e530 fffff803`330d2206 : ffff8881`2a7e8b00 ffff8881`1b9b8d20 ffff8881`280f6040 00000000`00000000 : nt!ObfReferenceObjectWithTag+0x24
ffffe901`6c78e570 fffff803`330d1d05 : fffff803`00000000 00000000`00000001 ffffe901`6c78e680 ffff8881`1b9b8d20 : nt!IopQueueWorkItemProlog+0x52
ffffe901`6c78e5a0 fffff803`88825a38 : ffff8881`1b9b78e0 00000000`00000000 00000000`00000000 ffff8881`1b9b78e0 : nt!IoQueueWorkItem+0x15
ffffe901`6c78e5d0 ffff8881`1b9b78e0 : 00000000`00000000 00000000`00000000 ffff8881`1b9b78e0 ffffe901`6c78e5b0 : FACEIT+0x1065a38
ffffe901`6c78e5d8 00000000`00000000 : 00000000`00000000 ffff8881`1b9b78e0 ffffe901`6c78e5b0 00000000`00000038 : 0xffff8881`1b9b78e0
THREAD_SHA1_HASH_MOD_FUNC: 34852ae56a881c7330b4cf4720e201e7f2dbf97c
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6d2703c4691137d5e146b31bdfba5fb941937219
THREAD_SHA1_HASH_MOD: a74cd514b2e0f22229ac9a51240214a38c96fede
FOLLOWUP_IP:
FACEIT+1065a38
fffff803`88825a38 e910000000 jmp FACEIT+0x1065a4d (fffff803`88825a4d)
FAULT_INSTR_CODE: 10e9
SYMBOL_STACK_INDEX: 7
SYMBOL_NAME: FACEIT+1065a38
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: FACEIT
IMAGE_NAME: FACEIT.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 5e188842
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 1065a38
FAILURE_BUCKET_ID: AV_INVALID_FACEIT!unknown_function
BUCKET_ID: AV_INVALID_FACEIT!unknown_function
PRIMARY_PROBLEM_CLASS: AV_INVALID_FACEIT!unknown_function
TARGET_TIME: 2020-01-10T17:15:00.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 6e4d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_invalid_faceit!unknown_function
FAILURE_ID_HASH: {c16d4f0e-c865-34f7-3c81-3d50019d3ee7}
Followup: MachineOwner
Hocam teşekkürler yanıt verdiğiniz için.FACEIT adlı anti hile sistemi sıkıntı çıkarıyor, fakat sistem bellek hatası veriyor, Windows bellek tanılama aracı ile değil Memtest86 ile test yapar mısın?
Ayrıca diğer dosyaları da gönder.
Kod:PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: ffffffffffffffd0, memory referenced. Arg2: 0000000000000002, value 0 = read operation, 1 = write operation. Arg3: fffff80333004584, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000002, (reserved) Debugging Details: ------------------ *** WARNING: Unable to verify timestamp for FACEIT.sys Could not read faulting driver name *** WARNING: Unable to verify timestamp for win32k.sys KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 DUMP_TYPE: 2 BUGCHECK_P1: ffffffffffffffd0 BUGCHECK_P2: 2 BUGCHECK_P3: fffff80333004584 BUGCHECK_P4: 2 READ_ADDRESS: fffff803335733b8: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd ffffffffffffffd0 FAULTING_IP: nt!ObfReferenceObjectWithTag+24 fffff803`33004584 f0480fc15ed0 lock xadd qword ptr [rsi-30h],rbx MM_INTERNAL_CODE: 2 CPU_COUNT: c CPU_MHZ: d48 CPU_VENDOR: AuthenticAMD CPU_FAMILY: 17 CPU_MODEL: 8 CPU_STEPPING: 2 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT BUGCHECK_STR: AV PROCESS_NAME: System CURRENT_IRQL: 0 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 01-16-2020 01:58:33.0818 ANALYSIS_VERSION: 10.0.18362.1 x86fre TRAP_FRAME: ffffe9016c78e3a0 -- (.trap 0xffffe9016c78e3a0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000008000 rbx=0000000000000000 rcx=0000000000000000 rdx=00000000746c6644 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80333004584 rsp=ffffe9016c78e530 rbp=fffff803877cb1bc r8=ffff88811b9b8d20 r9=ffff88811b9b8d20 r10=ffff888119202000 r11=ffffe9016c78e4f0 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc nt!ObfReferenceObjectWithTag+0x24: fffff803`33004584 f0480fc15ed0 lock xadd qword ptr [rsi-30h],rbx ds:ffffffff`ffffffd0=???????????????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff803331e35d6 to fffff803331c14e0 STACK_TEXT: ffffe901`6c78e0f8 fffff803`331e35d6 : 00000000`00000050 ffffffff`ffffffd0 00000000`00000002 ffffe901`6c78e3a0 : nt!KeBugCheckEx ffffe901`6c78e100 fffff803`33072eef : 00000000`00000000 00000000`00000002 00000000`00000000 ffffffff`ffffffd0 : nt!MiSystemFault+0x1d6866 ffffe901`6c78e200 fffff803`331cf520 : 00000000`00000001 00000000`00000070 ffff8881`2bd48dd0 ffff8881`18010000 : nt!MmAccessFault+0x34f ffffe901`6c78e3a0 fffff803`33004584 : 00000000`00000000 00000000`00000058 00000000`00000000 fffff803`3336f06d : nt!KiPageFault+0x360 ffffe901`6c78e530 fffff803`330d2206 : ffff8881`2a7e8b00 ffff8881`1b9b8d20 ffff8881`280f6040 00000000`00000000 : nt!ObfReferenceObjectWithTag+0x24 ffffe901`6c78e570 fffff803`330d1d05 : fffff803`00000000 00000000`00000001 ffffe901`6c78e680 ffff8881`1b9b8d20 : nt!IopQueueWorkItemProlog+0x52 ffffe901`6c78e5a0 fffff803`88825a38 : ffff8881`1b9b78e0 00000000`00000000 00000000`00000000 ffff8881`1b9b78e0 : nt!IoQueueWorkItem+0x15 ffffe901`6c78e5d0 ffff8881`1b9b78e0 : 00000000`00000000 00000000`00000000 ffff8881`1b9b78e0 ffffe901`6c78e5b0 : FACEIT+0x1065a38 ffffe901`6c78e5d8 00000000`00000000 : 00000000`00000000 ffff8881`1b9b78e0 ffffe901`6c78e5b0 00000000`00000038 : 0xffff8881`1b9b78e0 THREAD_SHA1_HASH_MOD_FUNC: 34852ae56a881c7330b4cf4720e201e7f2dbf97c THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6d2703c4691137d5e146b31bdfba5fb941937219 THREAD_SHA1_HASH_MOD: a74cd514b2e0f22229ac9a51240214a38c96fede FOLLOWUP_IP: FACEIT+1065a38 fffff803`88825a38 e910000000 jmp FACEIT+0x1065a4d (fffff803`88825a4d) FAULT_INSTR_CODE: 10e9 SYMBOL_STACK_INDEX: 7 SYMBOL_NAME: FACEIT+1065a38 FOLLOWUP_NAME: MachineOwner MODULE_NAME: FACEIT IMAGE_NAME: FACEIT.sys DEBUG_FLR_IMAGE_TIMESTAMP: 5e188842 STACK_COMMAND: .thread ; .cxr ; kb BUCKET_ID_FUNC_OFFSET: 1065a38 FAILURE_BUCKET_ID: AV_INVALID_FACEIT!unknown_function BUCKET_ID: AV_INVALID_FACEIT!unknown_function PRIMARY_PROBLEM_CLASS: AV_INVALID_FACEIT!unknown_function TARGET_TIME: 2020-01-10T17:15:00.000Z OSBUILD: 18362 OSSERVICEPACK: 535 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: 1980-01-11 18:53:20 BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 6e4d ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:av_invalid_faceit!unknown_function FAILURE_ID_HASH: {c16d4f0e-c865-34f7-3c81-3d50019d3ee7} Followup: MachineOwner
Hocam hiçbir antivürün porgramı kullanmıyorum. Zaten yeni format attım direkt Driver Booster, sofware updater falan kurup her şeyi hallettikten sonra oyunları falan indirdim zaten. Ayrıca şimdi bilgisayarı açarken USB üstünde kalmış otomatik Memtest86 açılmış yine. İptal edip restart atınca tekrar açılışta mavi ekran hatası aldım onu da şöyle paylaşayım: 011620-29812-01.rarAntivirüs veya temizlik yazılımları kullanıyorsan kaldır tekrar dene, eğer olmaz ise temiz kurulum yap sürücüleri yükle tekrar dene, farklı bir program yükleme, bir program ile çakışıyor veya dosyaları siliniyor olabilir.
FAT_FILE_SYSTEM (23)
If you see FatExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000000e0121
Arg2: ffffe205ad1fd518
Arg3: ffffe205ad1fcd60
Arg4: fffff8017fe9f2eb
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullClassPtr
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: e0121
BUGCHECK_P2: ffffe205ad1fd518
BUGCHECK_P3: ffffe205ad1fcd60
BUGCHECK_P4: fffff8017fe9f2eb
EXCEPTION_RECORD: ffffe205ad1fd518 -- (.exr 0xffffe205ad1fd518)
ExceptionAddress: fffff8017fe9f2eb (volmgr!VmpQueryUniqueIdInternal+0x0000000000000037)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000040
Attempt to read from address 0000000000000040
CONTEXT: ffffe205ad1fcd60 -- (.cxr 0xffffe205ad1fcd60)
rax=0000000000000000 rbx=ffffcf04fb6ed6a0 rcx=ffffcf04fb6ed600
rdx=0000000000000000 rsi=ffffcf04f7af45c0 rdi=0000000000000000
rip=fffff8017fe9f2eb rsp=ffffe205ad1fd750 rbp=ffffe205ad1fd809
r8=ffffe205ad1fd802 r9=ffffcf04fb6ed6a0 r10=00000000ffffffff
r11=ffffe205ad1fd760 r12=fffff80182c2f001 r13=ffffcf04f1190ca0
r14=ffffe205ad1fd800 r15=ffffe205ad1fd802
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
volmgr!VmpQueryUniqueIdInternal+0x37:
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h] ds:002b:00000000`00000040=????????????????
Resetting default scope
CPU_COUNT: c
CPU_MHZ: d48
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
FOLLOWUP_IP:
volmgr!VmpQueryUniqueIdInternal+37
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h]
FAULTING_IP:
volmgr!VmpQueryUniqueIdInternal+37
fffff801`7fe9f2eb 488b5040 mov rdx,qword ptr [rax+40h]
BUGCHECK_STR: 0x23
READ_ADDRESS: fffff8017bf733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000000000040
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000040
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-16-2020 15:49:40.0093
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8017fea02ce to fffff8017fe9f2eb
STACK_TEXT:
ffffe205`ad1fd750 fffff801`7fea02ce : ffffcf04`fb6ed6a0 ffffcf04`f7af45c0 00000000`0fb00000 ffffcf04`f1190c01 : volmgr!VmpQueryUniqueIdInternal+0x37
ffffe205`ad1fd780 fffff801`7fea078f : ffffcf04`faf9df40 ffffcf04`f7af45c0 00000000`00000000 000000a0`00000000 : volmgr!VmpSetPartitionInformation+0x2c0e
ffffe205`ad1fd870 fffff801`7fe918eb : ffffcf04`fb6ed6a0 ffffe205`ad1fd8f0 00000000`00000000 ffffcf04`faf9d960 : volmgr!VmpGetPartitionInfoEx+0x4627
ffffe205`ad1fd8b0 fffff801`7ba31f79 : ffffcf04`faf9d960 ffffcf04`faf9d960 ffffffff`ffffffff ffffffff`ffffffff : volmgr!VmDeviceControl+0x2bb
ffffe205`ad1fd920 fffff801`7bb21b7e : ffffcf04`ee013640 00000000`000000a0 00000000`00000000 00000000`00000680 : nt!IofCallDriver+0x59
ffffe205`ad1fd960 fffff801`7c0ce841 : ffffe480`20400000 00000000`20206f49 00000000`00000000 00000000`000000e0 : nt!IoSynchronousCallDriver+0x4e
ffffe205`ad1fd9c0 fffff801`82c7439e : 00000000`00000000 ffffffff`ffffffff ffffe205`ad1fdb10 fffff801`7ba33294 : nt!IoForwardIrpSynchronously+0x41
ffffe205`ad1fd9f0 fffff801`82c13d77 : ffffcf04`faf9d960 ffffcf04`fa68c801 ffffcf04`faf39180 00000000`00000000 : fvevol!IoctlDiskQuery+0x7a
ffffe205`ad1fdae0 fffff801`7ba31f79 : 00000000`00000000 00000000`00000000 ffffcf04`fa68c8a0 00000000`00000000 : fvevol!FveFilterDeviceControl+0x207
ffffe205`ad1fdbe0 fffff801`803e1033 : ffffe205`ad1fddb8 fffff801`7ba2a2af 00000000`00070048 ffffcf04`faf9d960 : nt!IofCallDriver+0x59
ffffe205`ad1fdc20 fffff801`7ba31f79 : ffffe205`ad1fddf0 fffff801`00000090 ffffcf04`fba93c00 ffffe205`ad1fdcf0 : volume!VolumePassThrough+0x23
ffffe205`ad1fdc50 fffff801`8bc71ec6 : 00000000`00000000 ffffcf04`fba93c68 00000000`00000000 00000000`00000000 : nt!IofCallDriver+0x59
ffffe205`ad1fdc90 fffff801`8bc82f8c : ffffcf04`fa68cf01 ffffcf04`f50f6800 00000000`00000000 ffffcf04`fa68cf10 : fastfat!FatPerformDevIoCtrl+0xca
ffffe205`ad1fdd20 fffff801`8bc820d4 : ffffcf04`f141a560 ffffcf04`f5e48760 ffffcf04`fa68c8a0 ffffcf04`fb9779e0 : fastfat!FatVerifyVolume+0x190
ffffe205`ad1fdf00 fffff801`8bc82032 : ffffcf04`fa68c8a0 ffffcf04`fa68cf01 ffffcf04`fa68cf01 ffffcf04`fb871d00 : fastfat!FatCommonFileSystemControl+0x44
ffffe205`ad1fdf30 fffff801`7ba31f79 : ffffcf04`fb6839b0 ffffcf04`fa68c8a0 ffffe205`ad1fe000 ffffcf04`fa68cf58 : fastfat!FatFsdFileSystemControl+0xb2
ffffe205`ad1fdf70 fffff801`7f6e55de : 00000000`00000000 ffffcf04`fb6ed500 ffffcf04`fa68c8a0 ffffe205`ad1fe060 : nt!IofCallDriver+0x59
ffffe205`ad1fdfb0 fffff801`7f71c190 : ffffe205`ad1fe050 00000000`00000700 00000000`00000001 fffff801`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffe205`ad1fe030 fffff801`7ba31f79 : ffffcf04`fb6ed550 ffffe205`ad1fe130 ffffcf04`fa68c8a0 ffffe205`ad1fe100 : FLTMGR!FltpFsControl+0x110
ffffe205`ad1fe090 fffff801`7c25810b : ffffe205`ad1fe130 ffffcf04`fb6ed550 ffffcf04`fa68c8a0 ffffcf04`fb871d70 : nt!IofCallDriver+0x59
ffffe205`ad1fe0d0 fffff801`8bc8d037 : ffffcf04`f50f6800 ffffcf04`fbabca20 ffffcf04`fba93870 00000000`00000000 : nt!IoVerifyVolume+0x12b
ffffe205`ad1fe170 fffff801`8bc7c65b : ffffcf04`f10e5c80 ffffcf04`f9e488a0 ffffcf04`fb6ed550 00000000`00000002 : fastfat!FatPerformVerify+0x93
ffffe205`ad1fe1e0 fffff801`8bc6a192 : ffffcf04`f10e5c80 ffffcf04`f9e488a0 ffffcf04`80000016 ffffcf04`00000001 : fastfat!FatProcessException+0x3e3
ffffe205`ad1fe260 fffff801`7ba31f79 : ffffcf04`fba93870 ffffcf04`f9e488a0 ffffcf04`f141a501 ffffcf04`fb884010 : fastfat!FatFsdCreate+0x132
ffffe205`ad1fe2f0 fffff801`7f6e55de : ffffcf04`f9e488a0 ffffcf04`f9e48f00 ffffcf04`f9e488a0 ffffcf04`fd204da0 : nt!IofCallDriver+0x59
ffffe205`ad1fe330 fffff801`7f71cd27 : ffffe205`ad1fe3f0 00000000`00000000 00000000`00000001 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
ffffe205`ad1fe3b0 fffff801`7ba31f79 : ffffcf04`fd204d00 fffff801`7bfe5b25 00000000`00000000 00000000`00000030 : FLTMGR!FltpCreate+0x307
ffffe205`ad1fe460 fffff801`7ba31024 : 00000000`00000000 ffffcf04`f50f6800 ffffcf04`f9e48fa0 fffff801`7ba317e3 : nt!IofCallDriver+0x59
ffffe205`ad1fe4a0 fffff801`7bfe61eb : ffffe205`ad1fe760 fffff801`7bfe5b25 ffffe205`ad1fe6d0 ffffcf04`ef289520 : nt!IoCallDriverWithTracing+0x34
ffffe205`ad1fe4f0 fffff801`7bfed1bf : ffffcf04`fb6ed550 ffffcf04`fb6ed525 ffffcf04`fb20a4c0 ffffbc0c`48e0ae01 : nt!IopParseDevice+0x62b
ffffe205`ad1fe660 fffff801`7bfeb621 : ffffcf04`fb20a400 ffffe205`ad1fe8a8 00000000`00000040 ffffcf04`edcf4d20 : nt!ObpLookupObjectName+0x78f
ffffe205`ad1fe820 fffff801`7c030df0 : ffffcf04`00000001 0000008e`34a7e5f8 00000000`00000001 00000000`00000000 : nt!ObOpenObjectByNameEx+0x201
ffffe205`ad1fe960 fffff801`7c0305b9 : 0000008e`34a7e5a0 00000000`80100080 0000008e`34a7e5f8 0000008e`34a7e5b8 : nt!IopCreateFile+0x820
ffffe205`ad1fea00 fffff801`7bbd2d18 : 00000000`000002f4 00000000`00400004 00000000`00000000 000001e7`2511e0c0 : nt!NtCreateFile+0x79
ffffe205`ad1fea90 00007fff`ec53cb64 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000008e`34a7e528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`ec53cb64
THREAD_SHA1_HASH_MOD_FUNC: c59bac712340d40778e7452ded139852d421e393
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f414499de867805ed9dfbc8bc07d1519579b58db
THREAD_SHA1_HASH_MOD: 6f9201a36e99e0303f196d6d14f07d17f43be59c
FAULT_INSTR_CODE: 40508b48
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: volmgr!VmpQueryUniqueIdInternal+37
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: volmgr
IMAGE_NAME: volmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 211cef76
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .cxr 0xffffe205ad1fcd60 ; kb
BUCKET_ID_FUNC_OFFSET: 37
FAILURE_BUCKET_ID: 0x23_volmgr!VmpQueryUniqueIdInternal
BUCKET_ID: 0x23_volmgr!VmpQueryUniqueIdInternal
PRIMARY_PROBLEM_CLASS: 0x23_volmgr!VmpQueryUniqueIdInternal
TARGET_TIME: 2020-01-16T12:36:30.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 9948
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x23_volmgr!vmpqueryuniqueidinternal
FAILURE_ID_HASH: {d0e2cbbb-f6c9-659f-dade-4145ab43ee0a}
Followup: MachineOwner
---------