PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffce80725ff0a8, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80120fec22d, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffce80725ff0a8
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80120fec22d
BUGCHECK_P4: 0
READ_ADDRESS: fffff80120f733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffce80725ff0a8
FAULTING_IP:
nt!ObCloseHandleTableEntry+9d
fffff801`20fec22d 4c8b97a8000000 mov r10,qword ptr [rdi+0A8h]
MM_INTERNAL_CODE: 0
CPU_COUNT: c
CPU_MHZ: d48
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: RuntimeBroker.exe
CURRENT_IRQL: 2
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-26-2020 21:52:15.0416
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffb10f84c14310 -- (.trap 0xffffb10f84c14310)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff80120a00000 rbx=0000000000000000 rcx=0000000000000001
rdx=ffff820037df2e20 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80120fec22d rsp=ffffb10f84c144a0 rbp=ffffb10f84c14589
r8=ffffdf0b7fec7080 r9=ffffdf0b7fec7080 r10=00000000ffffffff
r11=00000000000000fe r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!ObCloseHandleTableEntry+0x9d:
fffff801`20fec22d 4c8b97a8000000 mov r10,qword ptr [rdi+0A8h] ds:00000000`000000a8=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80120be3863 to fffff80120bc14e0
STACK_TEXT:
ffffb10f`84c14068 fffff801`20be3863 : 00000000`00000050 ffffce80`725ff0a8 00000000`00000000 ffffb10f`84c14310 : nt!KeBugCheckEx
ffffb10f`84c14070 fffff801`20a72eef : ffff8200`352ea170 00000000`00000000 00000000`00000000 ffffce80`725ff0a8 : nt!MiSystemFault+0x1d6af3
ffffb10f`84c14170 fffff801`20bcf520 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000180 : nt!MmAccessFault+0x34f
ffffb10f`84c14310 fffff801`20fec22d : 00000000`ffff8001 ffffdf0b`8791ae90 ffff8200`00000000 00000000`00007fff : nt!KiPageFault+0x360
ffffb10f`84c144a0 fffff801`210385a5 : ffffdf0b`7fe80098 fffff801`20a36a8f 00000000`00000000 ffffdf0b`7de0d080 : nt!ObCloseHandleTableEntry+0x9d
ffffb10f`84c145e0 fffff801`21038241 : ffffdf0b`7fe80060 ffffdf0b`7de0d080 ffffffff`ffffff01 ffffdf0b`7fec7380 : nt!ExSweepHandleTable+0xd5
ffffb10f`84c14690 fffff801`21038769 : ffffffff`ffffffff ffffdf0b`7fec7080 ffffb10f`84c146e0 ffffdf0b`00000000 : nt!ObKillProcess+0x35
ffffb10f`84c146c0 fffff801`2105e6d3 : ffffdf0b`7fec7080 ffff8200`501590a0 ffffb10f`84c148e9 00000000`00000000 : nt!PspRundownSingleProcess+0x131
ffffb10f`84c14740 fffff801`210cd143 : ffffdf0b`00000000 00000116`ee269e01 00000013`e908a000 ffffb10f`84c14934 : nt!PspExitThread+0x60b
ffffb10f`84c14850 fffff801`20a3e551 : 00000013`e95ff694 00000000`00000010 ffffdf0b`836d7590 00000000`00000001 : nt!KiSchedulerApcTerminate+0x33
ffffb10f`84c14890 fffff801`20bc5a60 : ffffdf0b`7e82a001 ffffb10f`84c14950 ffffdf0b`836d7590 00000000`00000000 : nt!KiDeliverApc+0x481
ffffb10f`84c14950 fffff801`20bd2dbf : 00000000`00000000 ffffb10f`84c14b80 ffffdf0b`80a68160 fffff801`210b077d : nt!KiInitiateUserApc+0x70
ffffb10f`84c14a90 00007ffc`cf25fa54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
00000013`e95ff638 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`cf25fa54
THREAD_SHA1_HASH_MOD_FUNC: ea31686cc5250db4674571504a7879bb4c861bf3
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: a99d43fbaf0824e89ffc99b57ef92f8f72e7caa2
THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
FOLLOWUP_IP:
nt!ObCloseHandleTableEntry+9d
fffff801`20fec22d 4c8b97a8000000 mov r10,qword ptr [rdi+0A8h]
FAULT_INSTR_CODE: a8978b4c
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!ObCloseHandleTableEntry+9d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4f6eba0
IMAGE_VERSION: 10.0.18362.592
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 9d
FAILURE_BUCKET_ID: AV_R_INVALID_nt!ObCloseHandleTableEntry
BUCKET_ID: AV_R_INVALID_nt!ObCloseHandleTableEntry
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!ObCloseHandleTableEntry
TARGET_TIME: 2020-01-26T18:47:53.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 30c6
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!obclosehandletableentry
FAILURE_ID_HASH: {a0bb740f-7614-5514-dcd3-4233dfea6108}
Followup: MachineOwner
---------