MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 000000000000003f, An inpage operation failed with a CRC error. Parameter 2 contains
the pagefile offset. Parameter 3 contains the page CRC value.
Parameter 4 contains the expected CRC value.
Arg2: 000000000009dfae
Arg3: 00000000d3ac79d8
Arg4: 00000000d3aa79d8
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2858
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1IBQR0U
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 11532
Key : Analysis.Memory.CommitPeak.Mb
Value: 74
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 1a
BUGCHECK_P1: 3f
BUGCHECK_P2: 9dfae
BUGCHECK_P3: d3ac79d8
BUGCHECK_P4: d3aa79d8
ADDITIONAL_DEBUG_TEXT: Memory Manager detected corruption of a pagefile page while performing an in-page operation.
The data read from storage does not match the original data written.
This indicates the data was corrupted by the storage stack, or device hardware.
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: csgo.exe
PAGE_HASH_ERRORS_DETECTED: 1
STACK_TEXT:
ffffb084`c2ec37a8 fffff801`68e634ca : 00000000`0000001a 00000000`0000003f 00000000`0009dfae 00000000`d3ac79d8 : nt!KeBugCheckEx
ffffb084`c2ec37b0 fffff801`68c0b902 : ffffe60a`a81f8340 ffffffff`ffffffff 00000000`00000000 ffffe60a`a81f8430 : nt!MiValidatePagefilePageHash+0x10589e
ffffb084`c2ec3890 fffff801`68c0a83d : 00000000`00000002 ffffb084`00000000 ffffb084`c2ec3a48 fffff801`00000000 : nt!MiWaitForInPageComplete+0x472
ffffb084`c2ec39a0 fffff801`68cc929b : 00000000`c0033333 00000000`00000001 00000000`231e7dc4 fffff801`68dc391f : nt!MiIssueHardFault+0x1ad
ffffb084`c2ec3aa0 fffff801`68dca69a : 00000000`28217172 ffffb084`c2ec3cc0 00000000`009c3000 00000000`00000000 : nt!MmAccessFault+0x40b
ffffb084`c2ec3c40 00000000`55c34468 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35a
00000000`1eacf4a4 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x55c34468
SYMBOL_NAME: PAGE_HASH_ERRORS_INPAGE
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: PAGE_HASH_ERRORS_0x1a_3f
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {6a2d4548-0eec-578d-e8f1-9e2239aa9a00}
Followup: MachineOwner
---------
*** Memory manager detected 1 instance(s) of corrupted pagefilepage(s) while performing in-page operations.
2: kd> !sysinfo machineid
Machine ID Information [From Smbios 2.5, DMIVersion 0, Size=2165]
BiosMajorRelease = 8
BiosMinorRelease = 15
BiosVendor = American Megatrends Inc.
BiosVersion = 0803
BiosReleaseDate = 11/21/2011
SystemManufacturer = System manufacturer
SystemProductName = System Product Name
SystemFamily = To Be Filled By O.E.M.
SystemVersion = System Version
SystemSKU = To Be Filled By O.E.M.
BaseBoardManufacturer = ASUSTeK Computer INC.
BaseBoardProduct = M5A87
BaseBoardVersion = Rev X.0x
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80155715be3, The address that the exception occurred at
Arg3: ffff848790132fc8, Parameter 0 of the exception
Arg4: ffff848790132810, Parameter 1 of the exception
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2843
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1IBQR0U
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 15074
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 1e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80155715be3
BUGCHECK_P3: ffff848790132fc8
BUGCHECK_P4: ffff848790132810
WRITE_ADDRESS: fffff80155b6e3b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff80155a253c8: Unable to get Flags value from nt!KdVersionBlock
fffff80155a253c8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
ffff848790132810
EXCEPTION_PARAMETER1: ffff848790132fc8
EXCEPTION_PARAMETER2: ffff848790132810
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
DEVICE_OBJECT: ffffe38600000000
STACK_TEXT:
ffff8487`90131f68 fffff801`558a3827 : 00000000`0000001e ffffffff`c0000005 fffff801`55715be3 ffff8487`90132fc8 : nt!KeBugCheckEx
ffff8487`90131f70 fffff801`557d48f6 : fffff801`55715be3 fffff801`5571d4eb ffff8487`90133208 ffff8487`90132810 : nt!KiFatalFilter+0x1f
ffff8487`90131fb0 fffff801`557990f9 : ffff8487`00000002 ffff8487`90133480 ffff8487`9012e000 ffff8487`90134000 : nt!KeExpandKernelStackAndCalloutInternal$filt$0+0x16
ffff8487`90131ff0 fffff801`557c550f : ffff8487`90133480 ffff8487`901325d0 00000000`00000000 00000000`00000000 : nt!_C_specific_handler+0xa9
ffff8487`90132060 fffff801`556b4745 : 00000000`00000000 00000000`00000000 ffff8487`901325d0 00007fff`ffff0000 : nt!RtlpExecuteHandlerForException+0xf
ffff8487`90132090 fffff801`556b865e : ffff8487`90132fc8 ffff8487`90132d10 ffff8487`90132fc8 ffffe386`c5751180 : nt!RtlDispatchException+0x4a5
ffff8487`901327e0 fffff801`557ce59d : ffff870b`6a7be000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x16e
ffff8487`90132e90 fffff801`557ca31c : ffffe386`cb186408 fffff801`58cb87ed 00000000`00000002 ffffe386`cb1862f8 : nt!KiExceptionDispatch+0x11d
ffff8487`90133070 fffff801`55715be3 : fffff801`58ded03b ffffe386`cb1862f8 ffffe386`00000000 ffff870b`00000001 : nt!KiGeneralProtectionFault+0x31c
ffff8487`90133208 fffff801`58ded03b : ffffe386`cb1862f8 ffffe386`00000000 ffff870b`00000001 ffff870b`6d4fba10 : nt!RtlEnumerateGenericTableWithoutSplayingAvl+0x43
ffff8487`90133210 fffff801`58d63e36 : ffffe386`cb1862f8 ffff870b`6a7208b0 ffffe386`cb1862f8 ffff870b`6a7208b0 : Ntfs!NtfsFlushVolume+0x27b
ffff8487`90133330 fffff801`58d63549 : ffffe386`cb1862f8 ffffe386`cc480010 fffff801`58d63501 ffff8487`90133560 : Ntfs!NtfsCommonFlushBuffers+0x8a6
ffff8487`90133450 fffff801`556c0118 : ffff8487`90133560 ffffe386`cb1862f8 ffffe386`c3a7d040 00000000`00000000 : Ntfs!NtfsCommonFlushBuffersCallout+0x19
ffff8487`90133480 fffff801`556c008d : fffff801`58d63530 ffff8487`90133560 00000000`00000000 fffff801`582e4be5 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff8487`901334f0 fffff801`58ddb889 : ffff8487`90134000 00000000`00000000 ffff8487`90133550 00000000`00000000 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff8487`90133530 fffff801`58ddb7bd : 00000000`00000000 ffffe386`cc480010 ffffe386`cb1862f8 ffff8487`901335c8 : Ntfs!NtfsCommonFlushBuffersOnNewStack+0x61
ffff8487`901335a0 fffff801`55627da9 : ffffe386`cb40d9e0 ffffe386`cc480010 ffffe386`cb1862f8 ffff8487`901335c8 : Ntfs!NtfsFsdFlushBuffers+0xdd
ffff8487`90133610 fffff801`582e55d9 : 00000000`00000000 ffff8487`901336f0 ffffe386`cc480010 ffff8487`90133700 : nt!IofCallDriver+0x59
ffff8487`90133650 fffff801`582e3f16 : ffff8487`901336f0 00000000`00000000 00000000`00000001 ffffe386`c54b2980 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x159
ffff8487`901336d0 fffff801`55627da9 : ffffe386`cc480010 ffffe386`c3a7d000 fffff801`55b93ea0 00000000`00000000 : FLTMGR!FltpDispatch+0xb6
ffff8487`90133730 fffff801`55c15dd5 : ffff8487`90133960 ffffe386`cc480010 00000000`00000001 ffffe386`ce651ab0 : nt!IofCallDriver+0x59
ffff8487`90133770 fffff801`55cc02dc : ffffe386`00000000 00000000`00000000 ffffe386`ce651ab0 ffff8487`90133960 : nt!IopSynchronousServiceTail+0x1a5
ffff8487`90133810 fffff801`55cc00c6 : ffffe386`cb59e500 fffff801`55b93ea0 ffffe386`c552fda0 ffff8487`90133ae8 : nt!NtFlushBuffersFileEx+0x1fc
ffff8487`901338a0 fffff801`557ce3ce : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtFlushBuffersFile+0x16
ffff8487`901338e0 fffff801`557c05c0 : fffff801`55b94029 ffff8487`91c1b6c0 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x2b9
ffff8487`90133a78 fffff801`55b94029 : ffff8487`91c1b6c0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffff8487`90133a80 fffff801`55730925 : ffffe386`cb59e500 ffffe386`cb59e500 ffff8487`91c1b6c0 00000000`000003bf : nt!PopFlushVolumeWorker+0x189
ffff8487`90133d50 fffff801`557c3d5a : ffffbc80`1d620180 ffffe386`cb59e500 fffff801`557308d0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff8487`90133da0 00000000`00000000 : ffff8487`90134000 ffff8487`9012e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
SYMBOL_NAME: nt!RtlEnumerateGenericTableWithoutSplayingAvl+43
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.18362.30
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 43
FAILURE_BUCKET_ID: 0x1E_c0000005_nt!RtlEnumerateGenericTableWithoutSplayingAvl
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3b7d8e53-d7c8-ec1f-fd55-728f3892a0cf}
Followup: MachineOwner
---------
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8032483505c, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2515
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1IBQR0U
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 13309
Key : Analysis.Memory.CommitPeak.Mb
Value: 75
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 1e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8032483505c
BUGCHECK_P3: 0
BUGCHECK_P4: ffffffffffffffff
READ_ADDRESS: fffff8032476e3b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff803246253c8: Unable to get Flags value from nt!KdVersionBlock
fffff803246253c8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
ffffffffffffffff
EXCEPTION_PARAMETER2: ffffffffffffffff
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
STACK_TEXT:
ffffeb0c`ad54ef08 fffff803`24422453 : 00000000`0000001e ffffffff`c0000005 fffff803`2483505c 00000000`00000000 : nt!KeBugCheckEx
ffffeb0c`ad54ef10 fffff803`243ce59d : ffff998d`00000000 00000000`00000001 00000000`00000000 ffff998d`6a186040 : nt!KiDispatchException+0x169f63
ffffeb0c`ad54f5c0 fffff803`243ca31c : ffffb10d`7acf4100 00000000`7acf4200 00000000`00000000 ffff998d`6c34b180 : nt!KiExceptionDispatch+0x11d
ffffeb0c`ad54f7a0 fffff803`2483505c : ffbff803`24834cf5 ffffeb0c`ad54fbf8 00000000`00000000 00000000`00000000 : nt!KiGeneralProtectionFault+0x31c
ffffeb0c`ad54f938 ffbff803`24834cf5 : ffffeb0c`ad54fbf8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObWaitForMultipleObjects+0x32c
ffffeb0c`ad54f940 ffffeb0c`ad54fbf8 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8000`55780001 : 0xffbff803`24834cf5
ffffeb0c`ad54f948 00000000`00000000 : 00000000`00000000 00000000`00000000 ffff8000`55780001 00000000`00100001 : 0xffffeb0c`ad54fbf8
SYMBOL_NAME: nt!ObWaitForMultipleObjects+32c
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.18362.30
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 32c
FAILURE_BUCKET_ID: 0x1E_c0000005_R_nt!ObWaitForMultipleObjects
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {39558743-4312-db4e-4f6c-98e5ba7b3072}
Followup: MachineOwner
---------
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8054f0b2a42, The address that the exception occurred at
Arg3: ffffcc83927fe358, Exception Record Address
Arg4: ffffcc83927fdba0, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Write
Key : Analysis.CPU.mSec
Value: 2843
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-1IBQR0U
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 22924
Key : Analysis.Memory.CommitPeak.Mb
Value: 79
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8054f0b2a42
BUGCHECK_P3: ffffcc83927fe358
BUGCHECK_P4: ffffcc83927fdba0
EXCEPTION_RECORD: ffffcc83927fe358 -- (.exr 0xffffcc83927fe358)
ExceptionAddress: fffff8054f0b2a42 (Ntfs!DeleteNodeFromTree+0x00000000000000ba)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000004000
Attempt to write to address 0000000000004000
CONTEXT: ffffcc83927fdba0 -- (.cxr 0xffffcc83927fdba0)
rax=ffffd38c158f09d8 rbx=ffffd38c158f09d8 rcx=0000000000004000
rdx=ffffd38c15ecea01 rsi=0000000000000000 rdi=ffffd38c15ecea40
rip=fffff8054f0b2a42 rsp=ffffcc83927fe590 rbp=fffff8054f1e3f20
r8=0000000000000000 r9=ffffd38c15ecea40 r10=ffffd38c158f09d8
r11=ffffcc83927fe620 r12=0000000000000000 r13=0000000000000000
r14=ffffcc83927fe701 r15=ffffd38c158f0740
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00010207
Ntfs!DeleteNodeFromTree+0xba:
fffff805`4f0b2a42 488901 mov qword ptr [rcx],rax ds:002b:00000000`00004000=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
WRITE_ADDRESS: fffff8054cb6e3b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8054ca253c8: Unable to get Flags value from nt!KdVersionBlock
fffff8054ca253c8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
0000000000004000
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000004000
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffffcc83`927fe590 fffff805`4f0b2979 : ffffd38c`158f09d8 00000000`00000000 ffffe60f`22076040 ffffe60f`2335f818 : Ntfs!DeleteNodeFromTree+0xba
ffffcc83`927fe5c0 fffff805`4f174f7e : ffffd38c`15ece9e8 ffffd38c`00000000 ffffcc83`00000001 00000000`00000000 : Ntfs!FsLibRemoveElementGenericTableAvlEx+0x11
ffffcc83`927fe5f0 fffff805`4f174d5d : ffffd38c`15ece9e8 fffff805`4f1e3f20 ffffd38c`15ece5a0 00000000`00000000 : Ntfs!NtfsRemovePrefix+0x4e
ffffcc83`927fe620 fffff805`4f0b2253 : ffffcc83`927fea30 ffffd38c`15ece5a0 ffffd38c`15ece5a0 ffffd38c`00000000 : Ntfs!NtfsFullDeleteLcb+0x2d
ffffcc83`927fe650 fffff805`4f1731de : ffffcc83`927fea30 ffffe60f`1d14f180 ffffd38c`15ece5a0 ffffd38c`15ece9e8 : Ntfs!NtfsTeardownFromLcb+0x1a3
ffffcc83`927fe6f0 fffff805`4f0b669a : ffffcc83`927fea30 ffffcc83`927fe7f1 ffffd38c`15ece9e8 ffffcc83`927fea30 : Ntfs!NtfsTeardownStructures+0xee
ffffcc83`927fe770 fffff805`4f1949cc : ffffcc83`927fe900 ffffd38c`00000000 ffffcc83`00000000 ffffcc83`927fea30 : Ntfs!NtfsDecrementCloseCounts+0xaa
ffffcc83`927fe7b0 fffff805`4f193911 : ffffcc83`927fea30 ffffd38c`15ece700 ffffd38c`15ece5a0 ffffe60f`1d14f180 : Ntfs!NtfsCommonClose+0x45c
ffffcc83`927fe890 fffff805`4f1e3fa8 : 00000000`0000001c fffff805`4cb8a240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
ffffcc83`927fe9f0 fffff805`4c6ae835 : ffffe60f`1a46bad0 ffffe60f`00002000 ffffe60f`00000000 ffffe60f`00002000 : Ntfs!NtfsFspClose+0x88
ffffcc83`927fecb0 fffff805`4c730925 : ffffe60f`22076040 00000000`00000080 ffffe60f`1a483040 fffff805`00501802 : nt!ExpWorkerThread+0x105
ffffcc83`927fed50 fffff805`4c7c3d5a : ffff8a01`59620180 ffffe60f`22076040 fffff805`4c7308d0 fffff6e9`00501802 : nt!PspSystemThreadStartup+0x55
ffffcc83`927feda0 00000000`00000000 : ffffcc83`927ff000 ffffcc83`927f9000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
SYMBOL_NAME: Ntfs!DeleteNodeFromTree+ba
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
IMAGE_VERSION: 10.0.18362.1040
STACK_COMMAND: .cxr 0xffffcc83927fdba0 ; kb
BUCKET_ID_FUNC_OFFSET: ba
FAILURE_BUCKET_ID: AV_Ntfs!DeleteNodeFromTree
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {4f879dd2-24e8-c9e2-0f1d-4a199bccac01}
Followup: MachineOwner
---------