SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80666f4668f, The address that the exception occurred at
Arg3: fffff582bd7fe3f8, Exception Record Address
Arg4: fffff582bd7fdc40, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: System manufacturer
SYSTEM_PRODUCT_NAME: System Product Name
SYSTEM_SKU: SKU
SYSTEM_VERSION: System Version
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 2006
BIOS_DATE: 11/13/2019
BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
BASEBOARD_PRODUCT: PRIME B450M-K
BASEBOARD_VERSION: Rev X.0x
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80666f4668f
BUGCHECK_P3: fffff582bd7fe3f8
BUGCHECK_P4: fffff582bd7fdc40
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
Ntfs!TxfDeleteTxfFo+13
fffff806`66f4668f 8b4204 mov eax,dword ptr [rdx+4]
EXCEPTION_RECORD: fffff582bd7fe3f8 -- (.exr 0xfffff582bd7fe3f8)
ExceptionAddress: fffff80666f4668f (Ntfs!TxfDeleteTxfFo+0x0000000000000013)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000800000004
Attempt to read from address 0000000800000004
CONTEXT: fffff582bd7fdc40 -- (.cxr 0xfffff582bd7fdc40)
rax=000000000000003f rbx=0000000800000000 rcx=ffffc000ba6e7000
rdx=0000000800000000 rsi=fffff582bd7fe8f0 rdi=ffffc000d1294010
rip=fffff80666f4668f rsp=fffff582bd7fe630 rbp=fffff80666f45310
r8=00000000ffffffff r9=7fffb00404d75518 r10=7ffffffffffffffc
r11=fffff582bd7fe640 r12=0000000000000000 r13=ffffb003f32c6180
r14=ffffc000d1294170 r15=fffff582bd7fe7f8
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
Ntfs!TxfDeleteTxfFo+0x13:
fffff806`66f4668f 8b4204 mov eax,dword ptr [rdx+4] ds:002b:00000008`00000004=????????
Resetting default scope
CPU_COUNT: c
CPU_MHZ: e09
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 71
CPU_STEPPING: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: System
CURRENT_IRQL: 0
FOLLOWUP_IP:
Ntfs!TxfDeleteTxfFo+13
fffff806`66f4668f 8b4204 mov eax,dword ptr [rdx+4]
BUGCHECK_STR: AV
READ_ADDRESS: fffff806657823b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000800000004
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000800000004
ANALYSIS_SESSION_HOST: DESKTOP-GULEPCP
ANALYSIS_SESSION_TIME: 05-30-2020 09:01:26.0774
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff80666f110cc to fffff80666f4668f
STACK_TEXT:
fffff582`bd7fe630 fffff806`66f110cc : fffff582`bd7fe7f8 00000000`00000000 fffff582`00000000 fffff582`bd7fe8f0 : Ntfs!TxfDeleteTxfFo+0x13
fffff582`bd7fe670 fffff806`66f0faf1 : fffff582`bd7fe8f0 ffffc000`d1294170 ffffc000`d1294010 ffffb003`f32c6180 : Ntfs!NtfsCommonClose+0x97c
fffff582`bd7fe750 fffff806`66f45398 : 00000000`0000001c fffff806`6579e240 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x241
fffff582`bd7fe8b0 fffff806`653033b5 : ffffb003`ecb35c50 fffff806`65806000 ffffb003`ecb35c00 ffffb003`ecb35c50 : Ntfs!NtfsFspClose+0x88
fffff582`bd7feb70 fffff806`6527acd5 : ffffb003`fc3ba040 00000000`00000080 ffffb003`ecab8040 00000000`00000000 : nt!ExpWorkerThread+0x105
fffff582`bd7fec10 fffff806`653d8998 : ffff9c81`b5380180 ffffb003`fc3ba040 fffff806`6527ac80 00000000`00000246 : nt!PspSystemThreadStartup+0x55
fffff582`bd7fec60 00000000`00000000 : fffff582`bd7ff000 fffff582`bd7f9000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
THREAD_SHA1_HASH_MOD_FUNC: 2b6f300186f6cc2602807fcbc4a2ff28dce56c48
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 983144b3d1ecf492e58a7c77e28e4714bac17332
THREAD_SHA1_HASH_MOD: 7676a52ccb40e8f35ecd8de90472ed5f968f3455
FAULT_INSTR_CODE: a804428b
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!TxfDeleteTxfFo+13
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.719
STACK_COMMAND: .cxr 0xfffff582bd7fdc40 ; kb
BUCKET_ID_FUNC_OFFSET: 13
FAILURE_BUCKET_ID: AV_VRF_Ntfs!TxfDeleteTxfFo
BUCKET_ID: AV_VRF_Ntfs!TxfDeleteTxfFo
PRIMARY_PROBLEM_CLASS: AV_VRF_Ntfs!TxfDeleteTxfFo
TARGET_TIME: 2020-05-25T15:15:29.000Z
OSBUILD: 18362
OSSERVICEPACK: 836
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 9c50
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_vrf_ntfs!txfdeletetxffo
FAILURE_ID_HASH: {42ad579e-ccec-82bf-c4e4-a3079843667c}
Followup: MachineOwner