NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800338c678
Arg3: fffff8800338bed0
Arg4: fffff8800102a0fe
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.Sec
Value: 2
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-I8FA0KP
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 8
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 24
BUGCHECK_P1: 1904fb
BUGCHECK_P2: fffff8800338c678
BUGCHECK_P3: fffff8800338bed0
BUGCHECK_P4: fffff8800102a0fe
EXCEPTION_RECORD: fffff8800338c678 -- (.exr 0xfffff8800338c678)
ExceptionAddress: fffff8800102a0fe (fltmgr! ?? ::NNGAKEGL::`string'+0x0000000000001087)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff8800338bed0 -- (.cxr 0xfffff8800338bed0)
rax=7ffffa800c81ed80 rbx=fffffa80101506c8 rcx=0000000000000000
rdx=fffffa80101503b0 rsi=0000000000000000 rdi=fffff8a02c92bcc8
rip=fffff8800102a0fe rsp=fffff8800338c8b0 rbp=fffff88001000000
r8=ffffffffffffffff r9=ffffffffffffffff r10=fffff80003213300
r11=fffffa80101506c8 r12=0000000000000705 r13=0000000000000000
r14=fffffa8010150368 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
fltmgr! ?? ::NNGAKEGL::`string'+0x1087:
fffff880`0102a0fe 0fb74818 movzx ecx,word ptr [rax+18h] ds:002b:7ffffa80`0c81ed98=????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff80003208068: Unable to get Flags value from nt!KdVersionBlock
fffff80003208068: Unable to get Flags value from nt!KdVersionBlock
fffff80003208068: Unable to get Flags value from nt!KdVersionBlock
Unable to get MmSystemRangeStart
GetUlongPtrFromAddress: unable to read from fffff800032c8280
GetUlongPtrFromAddress: unable to read from fffff800032c8408
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
fffff880`0338c8b0 fffff880`01025311 : fffffa80`097bc800 00000000`00000130 fffff8a0`2cc6fc70 00000000`00000000 : fltmgr! ?? ::NNGAKEGL::`string'+0x1087
fffff880`0338c8e0 fffff880`010253fb : fffffa80`097bc800 00000000`00000000 fffffa80`097bc800 fffff800`0307fa1e : fltmgr!CleanupStreamListCtrl+0x21
fffff880`0338c920 fffff800`03351b62 : 00000000`00000001 fffff880`012a50d8 fffff8a0`2cc6fda0 fffff880`01221f49 : fltmgr!DeleteStreamListCtrlCallback+0x6b
fffff880`0338c950 fffff880`012a4bac : fffff8a0`2cc6fc70 fffffa80`097ed9e0 fffff880`0338ca28 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`0338c9a0 fffff880`012a9cc1 : 00000000`01000000 00000000`00000000 fffff800`03234600 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`0338c9e0 fffff880`0122285c : fffff8a0`2cc6fb70 fffff8a0`2cc6fc70 fffff800`03234600 fffff880`0338cb52 : Ntfs!NtfsRemoveScb+0x61
fffff880`0338ca20 fffff880`012a764c : fffff8a0`2cc6fb40 fffff800`03234600 fffff880`0338cb52 fffffa80`100d9010 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`0338ca50 fffff880`012290e2 : fffffa80`100d9010 fffffa80`100d9010 fffff8a0`2cc6fb40 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`0338cad0 fffff880`012b7193 : fffffa80`100d9010 fffff800`03234600 fffff8a0`2cc6fb40 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`0338cb10 fffff880`012a6357 : fffffa80`100d9010 fffff8a0`2cc6fc70 fffff8a0`2cc6fb40 fffffa80`0ab0b180 : Ntfs!NtfsCommonClose+0x353
fffff880`0338cbe0 fffff800`030a1a21 : 00000000`00000000 fffff800`0338df00 fffff800`03296100 fffffa80`00000005 : Ntfs!NtfsFspClose+0x15f
fffff880`0338ccb0 fffff800`03334cce : 00000000`00000000 fffffa80`097ed9e0 00000000`00000080 fffffa80`09758040 : nt!ExpWorkerThread+0x111
fffff880`0338cd40 fffff800`03088fe6 : fffff880`03164180 fffffa80`097ed9e0 fffff880`0316efc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0338cd80 00000000`00000000 : fffff880`0338d000 fffff880`03387000 fffff880`0338c9e0 00000000`00000000 : nt!KiStartSystemThread+0x16
SYMBOL_NAME: fltmgr! ?? ::NNGAKEGL::`string'+1087
MODULE_NAME: fltmgr
IMAGE_NAME: fltmgr.sys
IMAGE_VERSION: 6.1.7601.17514
STACK_COMMAND: .cxr 0xfffff8800338bed0 ; kb
FAILURE_BUCKET_ID: X64_0x24_fltmgr!_??_::NNGAKEGL::_string_+1087
OS_VERSION: 7.1.7601.17514
BUILDLAB_STR: win7sp1_rtm
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
FAILURE_ID_HASH: {6137c2a6-bb1d-430b-fff6-0f3bae75c8fb}
Followup: MachineOwner