after bios update bsods didnt appear
BSODs caused by ntkrnlmp.exe
WinDBG analysis:
6: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.........................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8062307809d, The address that the exception occurred at
Arg3: fffffe80e459eb68, Exception Record Address
Arg4: fffffe80e459e3a0, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Type
Value: Read
Key : Analysis.CPU.mSec
Value: 1312
Key : Analysis.Elapsed.mSec
Value: 13892
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 265
Key : Analysis.Init.Elapsed.mSec
Value: 6615
Key : Analysis.Memory.CommitPeak.Mb
Value: 96
Key : Analysis.Version.DbgEng
Value: 10.0.29547.1002
Key : Analysis.Version.Description
Value: 10.2602.27.2 amd64fre
Key : Analysis.Version.Ext
Value: 1.2602.27.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_nt!ExReinitializeResourceLite
Key : Failure.Exception.Code
Value: 0xc0000005
Key : Failure.Exception.IP.Address
Value: 0xfffff8062307809d
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x27809d
Key : Failure.Exception.Record
Value: 0xfffffe80e459eb68
Key : Failure.Hash
Value: {d46532d4-a1d4-e059-087f-428af1b2ce29}
Key : Faulting.IP.Type
Value: Paged
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
Key : WER.System.BIOSRevision
Value: 5.32.0.0
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8062307809d
BUGCHECK_P3: fffffe80e459eb68
BUGCHECK_P4: fffffe80e459e3a0
FILE_IN_CAB: 051626-9000-01.dmp
FAULTING_THREAD: ffff83063aef2040
EXCEPTION_RECORD: fffffe80e459eb68 -- (.exr 0xfffffe80e459eb68)
ExceptionAddress: fffff8062307809d (nt!ExReinitializeResourceLite+0x00000000000000fd)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffffe80e459e3a0 -- (.cxr 0xfffffe80e459e3a0)
rax=ffff830638826410 rbx=ffff830638826450 rcx=ffff830638826450
rdx=ffffe107ffc61010 rsi=0066006f0073006f rdi=0000000000000000
rip=fffff8062307809d rsp=fffffe80e459eda0 rbp=0000000000000000
r8=00000000ffffffff r9=7fff830624a96410 r10=fffff80623077fa0
r11=0000000000000243 r12=0000000000000000 r13=fffffe80e459f201
r14=0000000000000000 r15=ffffe107ffc61010
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!ExReinitializeResourceLite+0xfd:
fffff806`2307809d 8b6e08 mov ebp,dword ptr [rsi+8] ds:002b:0066006f`00730077=????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff80623afb390: Unable to get MiVisibleState
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p 0x%p. %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
EXCEPTION_STR: 0xc0000005
IP_IN_PAGED_CODE:
nt!ExReinitializeResourceLite+fd
fffff806`2307809d 8b6e08 mov ebp,dword ptr [rsi+8]
STACK_TEXT:
fffffe80`e459eda0 fffff806`26b0dc2f : 00000000`00000000 ffff8306`38826410 00000000`00000000 ffff8306`24a96410 : nt!ExReinitializeResourceLite+0xfd
fffffe80`e459ee00 fffff806`26a142c2 : fffffe80`e459f270 ffffe108`08e03200 ffffe108`08e03170 ffff8306`00000000 : Ntfs!NtfsDeleteFcb+0x1df
fffffe80`e459ee80 fffff806`26b0e29a : fffffe80`e459f270 ffff8306`24a96180 ffffe107`ffc61010 ffffe107`ffc61528 : Ntfs!NtfsTeardownFromLcb+0x272
fffffe80`e459ef20 fffff806`26a13616 : fffffe80`e459f270 ffffe107`ffc61170 00000000`00000000 ffffe107`ffc61010 : Ntfs!NtfsTeardownStructures+0xea
fffffe80`e459efa0 fffff806`26b0c1a2 : fffffe80`e459f270 fffff806`26b5a480 00000000`00000000 ffffe107`ffc61000 : Ntfs!NtfsDecrementCloseCounts+0xf6
fffffe80`e459f000 fffff806`26b0d5b4 : fffffe80`e459f270 ffffe107`ffc61170 ffffe107`ffc61010 ffff8306`24a96180 : Ntfs!NtfsCommonClose+0xac2
fffffe80`e459f0d0 fffff806`26b5a508 : 00000000`0000001c fffff806`23b25440 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x244
fffffe80`e459f230 fffff806`230418f5 : ffff8306`3aef2040 fffff806`23073870 ffff8306`1c910cb0 ffff8306`00000000 : Ntfs!NtfsFspClose+0x88
fffffe80`e459f4f0 fffff806`2315d6e5 : ffff8306`3aef2040 00000000`00000080 ffff8306`1c94a080 00000000`00000000 : nt!ExpWorkerThread+0x105
fffffe80`e459f590 fffff806`232065c8 : ffffa401`82700180 ffff8306`3aef2040 fffff806`2315d690 00000000`00000246 : nt!PspSystemThreadStartup+0x55
fffffe80`e459f5e0 00000000`00000000 : fffffe80`e45a0000 fffffe80`e4599000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!ExReinitializeResourceLite+fd
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.6456
STACK_COMMAND: .cxr 0xfffffe80e459e3a0 ; kb
BUCKET_ID_FUNC_OFFSET: fd
FAILURE_BUCKET_ID: AV_nt!ExReinitializeResourceLite
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {d46532d4-a1d4-e059-087f-428af1b2ce29}
Followup: MachineOwner
---------
Dumps:
https://mega.nz/folder/3GgQxJxA#TVcwS_yxyY0hxfP4pB3LBg
On that moment i updated Intel ax210 wifi adapter, unintalled and installed gpu drivers and passed memtestx86
Windows for home | Windows 10 | Performance and system failures
Answer recommended by moderator
2 additional answers
Sort by: Most helpful
-
Sakiko 39,230 Reputation points Independent Advisor2026-05-16T13:12:53.0533333+00:00 Hi, the information you have provided indicates a problem with the system kernel, usually caused by a driver, which we need to verify further. Please first create a restore point for your system, then please refer to this article: https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier to enable driver verifier. In the third step select "Automatically select all drivers installed on this computer", wait for a couple of new blue screens and then collect 2-3 new dump files and share the new dump files with me.
If the computer has any automatic overclocking features enabled (including XMP, EXPO, etc.) or manual overclocking, please restore the defaults first.
Driver verifier puts heavy pressure on the drivers in your system to troubleshoot drivers that are in poor condition or misbehaving. It is normal for your computer to run slowly after driver verifier is turned on. The computer will also crash more frequently and generate dump files during this process.
If your system fails to boot after driver verifier is turned on or enough dump files are generated, please restore via the restore point.
-
AI answer
2026-05-16T11:58:23.6033333+00:00 The bugcheck is 0x1000007E (SYSTEM_THREAD_EXCEPTION_NOT_HANDLED) with an access violation (0xC0000005) in nt!ExReinitializeResourceLite while NTFS is tearing down file control blocks (FCBs). The stack shows only ntkrnlmp.exe and Ntfs.sys, which means the kernel detected memory corruption while NTFS was closing a file object; ntkrnlmp.exe is the victim, not the root cause.
From the stack:
- Ntfs!NtfsDeleteFcb / NtfsTeardownFromLcb / NtfsTeardownStructures / NtfsDecrementCloseCounts / NtfsCommonClose / NtfsFspClose
- Then nt!ExReinitializeResourceLite dereferences an invalid pointer (RSI points to garbage), causing the AV.
This pattern typically indicates one of the following:
- A third‑party filter or file system driver (AV, backup, encryption, disk filter, etc.) has corrupted NTFS structures or a resource object.
- Underlying storage issues (SSD/HDD, controller, or cabling) causing NTFS metadata corruption.
- Less commonly, bad RAM corrupting kernel structures.
Because the context only shows the kernel and NTFS, the next steps are:
- Check for known NTFS/kernel issues
- Ensure Windows 10 is fully updated (the kernel version 10.0.19041.6456 indicates a patched 2004/20H2/21H1 line). Install any pending cumulative updates.
- If the crashes started after a specific update, check reliability history and Event Viewer for NTFS or disk errors around the same time.
- Inspect storage and NTFS
- Run
chkdsk /scanon all NTFS volumes from an elevated command prompt. If errors are reported, schedulechkdsk /fon the system volume and reboot. - In Event Viewer → Windows Logs → System, look for Disk, Ntfs, or StorPort events (warnings/errors) around the time of the bugchecks.
- If there are repeated disk or NTFS errors, suspect the drive or controller.
- Remove or test third‑party filter drivers
- Temporarily uninstall or disable:
- Third‑party antivirus/endpoint security
- Backup/snapshot tools
- Disk encryption, defragmentation, or “tuning” utilities
- Any filesystem filter drivers (e.g., cloud sync clients that install drivers)
- After removal, test stability. If BSODs stop, reintroduce components one by one.
- Hardware validation
- Run vendor diagnostics on the system drive (SSD/HDD) and controller.
- Run a memory test (e.g., Windows Memory Diagnostic extended test). Intermittent RAM errors can corrupt kernel structures and manifest as NTFS/ntkrnlmp faults.
- Additional dump analysis
- For each dump, compare stacks to see if NTFS close/teardown is always involved.
- Use
!threadand!processin WinDbg on the faulting thread to see what component initiated the I/O. - If a third‑party driver appears consistently in other frames or in loaded modules, focus on updating or removing that driver.
If, after updates, disk checks, and removal of all non‑Microsoft filter drivers, the system still shows the same 0x7E in Ntfs/nt!ExReinitializeResourceLite, treat it as likely hardware (storage or RAM) and proceed with replacement testing.
References:
- Stop error 0x0000007E in Windows 7 or Windows Server 2008 R2
- !cxr
- Secondary dump data is limited to 256 MB in Windows 7 and Windows Server 2008 R2
- "0x0000008E" Stop error in Windows 7 or in Windows Server 2008 R2
- Evaluate controlled folder access
- Application crashing faulting module MSVC100.DLL - Microsoft Q&A
- WinSxS Corruptions Despite Numerous Formats to Windows, Silent Corruption and Deletion of Windows Update Files - Microsoft Q&A
- Trying to figure out this Windows Error Reporting 1001 event (Event Name: Bluescreen) - Microsoft Q&A
- Constant BSOD - Microsoft Q&A
- PROBLEMAS COM ATUALIZAÇÃO 02/10/2025 WIN - Microsoft Q&A
AI-generated content may be incorrect. Read our transparency notes for more information.