SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc000001d, The exception code that was not handled
Arg2: fffff80256d87532, The address that the exception occurred at
Arg3: ffffd000a6a4f0e8, Exception Record Address
Arg4: ffffbb0049b3f920, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for rt640x64.sys
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2234
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 11870
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 234
Key : Analysis.Init.Elapsed.mSec
Value: 1423
Key : Analysis.Memory.CommitPeak.Mb
Value: 95
Key : Bugcheck.Code.DumpHeader
Value: 0x1000007e
Key : Bugcheck.Code.Register
Value: 0x7e
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
FILE_IN_CAB: 031521-26203-01.dmp
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc000001d
BUGCHECK_P2: fffff80256d87532
BUGCHECK_P3: ffffd000a6a4f0e8
BUGCHECK_P4: ffffbb0049b3f920
EXCEPTION_RECORD: ffffd000a6a4f0e8 -- (.exr 0xffffd000a6a4f0e8)
ExceptionAddress: fffff80256d87532 (ndis!ndisFilterIndicateReceiveNetBufferLists+0x00000000000000c2)
ExceptionCode: c000001d (Illegal instruction)
ExceptionFlags: 00000000
NumberParameters: 0
CONTEXT: ffffbb0049b3f920 -- (.cxr 0xffffbb0049b3f920)
rax=0000000000000002 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000001 rsi=ffff828ab05218a0 rdi=0000000000000020
rip=fffff80256d87532 rsp=ffffd000a6a4f320 rbp=0000000000000001
r8=0000000000000082 r9=0000000000000000 r10=0000000000000001
r11=ffff828aaab7fba1 r12=ffff828ab051ba70 r13=ffff828ab05218a0
r14=ffff828ab022fc60 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050297
ndis!ndisFilterIndicateReceiveNetBufferLists+0xc2:
fffff802`56d87532 0f8daebf0300 jge ndis!ndisFilterIndicateReceiveNetBufferLists+0x3c076 (fffff802`56dc34e6) [br=0]
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc000001d - { ZEL DURUM} Ge ersiz Y nerge Ge ersiz bir y nerge y r t lmeye al ld .
EXCEPTION_CODE_STR: c000001d
EXCEPTION_STR: 0xc000001d
FAILED_INSTRUCTION_ADDRESS:
ndis!ndisFilterIndicateReceiveNetBufferLists+c2
fffff802`56d87532 0f8daebf0300 jge ndis!ndisFilterIndicateReceiveNetBufferLists+0x3c076 (fffff802`56dc34e6)
STACK_TEXT:
ffffd000`a6a4f320 fffff802`56d8804e : ffff828a`b05218a0 00000000`00000000 ffff828a`00000000 00000000`00000001 : ndis!ndisFilterIndicateReceiveNetBufferLists+0xc2
ffffd000`a6a4f3d0 fffff802`5734131c : ffff828a`a655b260 00000000`00000001 00000000`00000001 00000000`00000001 : ndis!NdisFIndicateReceiveNetBufferLists+0x6e
ffffd000`a6a4f410 fffff802`56d87ef1 : ffff828a`00000001 ffff828a`b022fc60 ffff828a`a655b260 fffff802`53a58901 : wfplwfs!LwfLowerRecvNetBufferLists+0x17c
ffffd000`a6a4f4d0 fffff802`56dbde4c : ffff828a`b051ba40 ffffd000`a6a4f5a1 ffffd000`a6a4f568 fffff802`538c1180 : ndis!ndisCallReceiveHandler+0x61
ffffd000`a6a4f520 fffff802`56d84a94 : 00000000`00780d3c 00000000`00000001 ffff828a`aa8b11a0 00000000`00000001 : ndis!ndisInvokeNextReceiveHandler+0x148
ffffd000`a6a4f5f0 fffff802`705e6a78 : ffff828a`aa9c6000 ffff828a`aa9c6000 00000000`00000002 00000000`00000000 : ndis!NdisMIndicateReceiveNetBufferLists+0x104
ffffd000`a6a4f680 ffff828a`aa9c6000 : ffff828a`aa9c6000 00000000`00000002 00000000`00000000 00000048`00000001 : rt640x64+0x26a78
ffffd000`a6a4f688 ffff828a`aa9c6000 : 00000000`00000002 00000000`00000000 00000048`00000001 00000000`00000004 : 0xffff828a`aa9c6000
ffffd000`a6a4f690 00000000`00000002 : 00000000`00000000 00000048`00000001 00000000`00000004 00000002`ffff0001 : 0xffff828a`aa9c6000
ffffd000`a6a4f698 00000000`00000000 : 00000048`00000001 00000000`00000004 00000002`ffff0001 80000000`00000001 : 0x2
SYMBOL_NAME: wfplwfs!LwfLowerRecvNetBufferLists+17c
MODULE_NAME: wfplwfs
IMAGE_NAME: wfplwfs.sys
IMAGE_VERSION: 10.0.19041.508
STACK_COMMAND: .cxr 0xffffbb0049b3f920 ; kb
BUCKET_ID_FUNC_OFFSET: 17c
FAILURE_BUCKET_ID: 0x7E_C000001D_BAD_IP_wfplwfs!LwfLowerRecvNetBufferLists
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {11020c20-b059-9cd7-b171-e0798bf13285}
Followup: MachineOwner
---------
4: kd> lmvm wfplwfs
Browse full module list
start end module name
fffff802`57340000 fffff802`57370000 wfplwfs # (pdb symbols) C:\ProgramData\Dbg\sym\wfplwfs.pdb\0D6CC29202502BB995AE4D09F1F784601\wfplwfs.pdb
Loaded symbol image file: wfplwfs.sys
Mapped memory image file: C:\ProgramData\Dbg\sym\wfplwfs.sys\3340819A30000\wfplwfs.sys
Image path: \SystemRoot\System32\drivers\wfplwfs.sys
Image name: wfplwfs.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 3340819A (This is a reproducible build file hash, not a timestamp)
CheckSum: 000352F4
ImageSize: 00030000
File version: 10.0.19041.508
Product version: 10.0.19041.508
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0000.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: WFPLWFS.SYS
OriginalFilename: WFPLWFS.SYS
ProductVersion: 10.0.19041.508
FileVersion: 10.0.19041.508 (WinBuild.160101.0800)
FileDescription: WFP NDIS 6.30 Lightweight Filter Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.