Share via

BSODs caused by ntkrnlmp.exe

gkhjkfkkjghjkg 0 Reputation points
2026-05-16T11:57:59.6566667+00:00

WinDBG analysis:

6: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.........................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8062307809d, The address that the exception occurred at
Arg3: fffffe80e459eb68, Exception Record Address
Arg4: fffffe80e459e3a0, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
    Key  : AV.Type
    Value: Read
    Key  : Analysis.CPU.mSec
    Value: 1312
    Key  : Analysis.Elapsed.mSec
    Value: 13892
    Key  : Analysis.IO.Other.Mb
    Value: 0
    Key  : Analysis.IO.Read.Mb
    Value: 1
    Key  : Analysis.IO.Write.Mb
    Value: 1
    Key  : Analysis.Init.CPU.mSec
    Value: 265
    Key  : Analysis.Init.Elapsed.mSec
    Value: 6615
    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 96
    Key  : Analysis.Version.DbgEng
    Value: 10.0.29547.1002
    Key  : Analysis.Version.Description
    Value: 10.2602.27.2 amd64fre
    Key  : Analysis.Version.Ext
    Value: 1.2602.27.2
    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1000007e
    Key  : Bugcheck.Code.TargetModel
    Value: 0x1000007e
    Key  : Failure.Bucket
    Value: AV_nt!ExReinitializeResourceLite
    Key  : Failure.Exception.Code
    Value: 0xc0000005
    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8062307809d
    Key  : Failure.Exception.IP.Module
    Value: nt
    Key  : Failure.Exception.IP.Offset
    Value: 0x27809d
    Key  : Failure.Exception.Record
    Value: 0xfffffe80e459eb68
    Key  : Failure.Hash
    Value: {d46532d4-a1d4-e059-087f-428af1b2ce29}
    Key  : Faulting.IP.Type
    Value: Paged
    Key  : WER.OS.Branch
    Value: vb_release
    Key  : WER.OS.Version
    Value: 10.0.19041.1
    Key  : WER.System.BIOSRevision
    Value: 5.32.0.0
BUGCHECK_CODE:  7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8062307809d
BUGCHECK_P3: fffffe80e459eb68
BUGCHECK_P4: fffffe80e459e3a0
FILE_IN_CAB:  051626-9000-01.dmp
FAULTING_THREAD:  ffff83063aef2040
EXCEPTION_RECORD:  fffffe80e459eb68 -- (.exr 0xfffffe80e459eb68)
ExceptionAddress: fffff8062307809d (nt!ExReinitializeResourceLite+0x00000000000000fd)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT:  fffffe80e459e3a0 -- (.cxr 0xfffffe80e459e3a0)
rax=ffff830638826410 rbx=ffff830638826450 rcx=ffff830638826450
rdx=ffffe107ffc61010 rsi=0066006f0073006f rdi=0000000000000000
rip=fffff8062307809d rsp=fffffe80e459eda0 rbp=0000000000000000
 r8=00000000ffffffff  r9=7fff830624a96410 r10=fffff80623077fa0
r11=0000000000000243 r12=0000000000000000 r13=fffffe80e459f201
r14=0000000000000000 r15=ffffe107ffc61010
iopl=0         nv up ei pl nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00050206
nt!ExReinitializeResourceLite+0xfd:
fffff806`2307809d 8b6e08          mov     ebp,dword ptr [rsi+8] ds:002b:0066006f`00730077=????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)
CUSTOMER_CRASH_COUNT:  1
PROCESS_NAME:  System
READ_ADDRESS: fffff80623afb390: Unable to get MiVisibleState
 ffffffffffffffff 
ERROR_CODE: (NTSTATUS) 0xc0000005 -                      0x%p                               0x%p.                      %s.
EXCEPTION_CODE_STR:  c0000005
EXCEPTION_PARAMETER1:  0000000000000000
EXCEPTION_PARAMETER2:  ffffffffffffffff
EXCEPTION_STR:  0xc0000005
IP_IN_PAGED_CODE: 
nt!ExReinitializeResourceLite+fd
fffff806`2307809d 8b6e08          mov     ebp,dword ptr [rsi+8]
STACK_TEXT:  
fffffe80`e459eda0 fffff806`26b0dc2f     : 00000000`00000000 ffff8306`38826410 00000000`00000000 ffff8306`24a96410 : nt!ExReinitializeResourceLite+0xfd
fffffe80`e459ee00 fffff806`26a142c2     : fffffe80`e459f270 ffffe108`08e03200 ffffe108`08e03170 ffff8306`00000000 : Ntfs!NtfsDeleteFcb+0x1df
fffffe80`e459ee80 fffff806`26b0e29a     : fffffe80`e459f270 ffff8306`24a96180 ffffe107`ffc61010 ffffe107`ffc61528 : Ntfs!NtfsTeardownFromLcb+0x272
fffffe80`e459ef20 fffff806`26a13616     : fffffe80`e459f270 ffffe107`ffc61170 00000000`00000000 ffffe107`ffc61010 : Ntfs!NtfsTeardownStructures+0xea
fffffe80`e459efa0 fffff806`26b0c1a2     : fffffe80`e459f270 fffff806`26b5a480 00000000`00000000 ffffe107`ffc61000 : Ntfs!NtfsDecrementCloseCounts+0xf6
fffffe80`e459f000 fffff806`26b0d5b4     : fffffe80`e459f270 ffffe107`ffc61170 ffffe107`ffc61010 ffff8306`24a96180 : Ntfs!NtfsCommonClose+0xac2
fffffe80`e459f0d0 fffff806`26b5a508     : 00000000`0000001c fffff806`23b25440 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspCloseInternal+0x244
fffffe80`e459f230 fffff806`230418f5     : ffff8306`3aef2040 fffff806`23073870 ffff8306`1c910cb0 ffff8306`00000000 : Ntfs!NtfsFspClose+0x88
fffffe80`e459f4f0 fffff806`2315d6e5     : ffff8306`3aef2040 00000000`00000080 ffff8306`1c94a080 00000000`00000000 : nt!ExpWorkerThread+0x105
fffffe80`e459f590 fffff806`232065c8     : ffffa401`82700180 ffff8306`3aef2040 fffff806`2315d690 00000000`00000246 : nt!PspSystemThreadStartup+0x55
fffffe80`e459f5e0 00000000`00000000     : fffffe80`e45a0000 fffffe80`e4599000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME:  nt!ExReinitializeResourceLite+fd
MODULE_NAME: nt
IMAGE_NAME:  ntkrnlmp.exe
IMAGE_VERSION:  10.0.19041.6456
STACK_COMMAND: .cxr 0xfffffe80e459e3a0 ; kb
BUCKET_ID_FUNC_OFFSET:  fd
FAILURE_BUCKET_ID:  AV_nt!ExReinitializeResourceLite
OS_VERSION:  10.0.19041.1
BUILDLAB_STR:  vb_release
OSPLATFORM_TYPE:  x64
OSNAME:  Windows 10
FAILURE_ID_HASH:  {d46532d4-a1d4-e059-087f-428af1b2ce29}
Followup:     MachineOwner
---------

Dumps:

https://mega.nz/folder/3GgQxJxA#TVcwS_yxyY0hxfP4pB3LBg

On that moment i updated Intel ax210 wifi adapter, unintalled and installed gpu drivers and passed memtestx86

Windows for home | Windows 10 | Performance and system failures
0 comments No comments

Answer recommended by moderator

gkhjkfkkjghjkg 0 Reputation points
2026-05-20T12:56:59.7833333+00:00

after bios update bsods didnt appear

Was this answer helpful?

0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Sakiko 39,230 Reputation points Independent Advisor
    2026-05-16T13:12:53.0533333+00:00

    Hi, the information you have provided indicates a problem with the system kernel, usually caused by a driver, which we need to verify further. Please first create a restore point for your system, then please refer to this article: https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier to enable driver verifier. In the third step select "Automatically select all drivers installed on this computer", wait for a couple of new blue screens and then collect 2-3 new dump files and share the new dump files with me.

    If the computer has any automatic overclocking features enabled (including XMP, EXPO, etc.) or manual overclocking, please restore the defaults first.

    Driver verifier puts heavy pressure on the drivers in your system to troubleshoot drivers that are in poor condition or misbehaving. It is normal for your computer to run slowly after driver verifier is turned on. The computer will also crash more frequently and generate dump files during this process.

    If your system fails to boot after driver verifier is turned on or enough dump files are generated, please restore via the restore point.

    Was this answer helpful?


  2. AI answer

    2026-05-16T11:58:23.6033333+00:00

    The bugcheck is 0x1000007E (SYSTEM_THREAD_EXCEPTION_NOT_HANDLED) with an access violation (0xC0000005) in nt!ExReinitializeResourceLite while NTFS is tearing down file control blocks (FCBs). The stack shows only ntkrnlmp.exe and Ntfs.sys, which means the kernel detected memory corruption while NTFS was closing a file object; ntkrnlmp.exe is the victim, not the root cause.

    From the stack:

    • Ntfs!NtfsDeleteFcb / NtfsTeardownFromLcb / NtfsTeardownStructures / NtfsDecrementCloseCounts / NtfsCommonClose / NtfsFspClose
    • Then nt!ExReinitializeResourceLite dereferences an invalid pointer (RSI points to garbage), causing the AV.

    This pattern typically indicates one of the following:

    • A third‑party filter or file system driver (AV, backup, encryption, disk filter, etc.) has corrupted NTFS structures or a resource object.
    • Underlying storage issues (SSD/HDD, controller, or cabling) causing NTFS metadata corruption.
    • Less commonly, bad RAM corrupting kernel structures.

    Because the context only shows the kernel and NTFS, the next steps are:

    1. Check for known NTFS/kernel issues
    • Ensure Windows 10 is fully updated (the kernel version 10.0.19041.6456 indicates a patched 2004/20H2/21H1 line). Install any pending cumulative updates.
    • If the crashes started after a specific update, check reliability history and Event Viewer for NTFS or disk errors around the same time.
    1. Inspect storage and NTFS
    • Run chkdsk /scan on all NTFS volumes from an elevated command prompt. If errors are reported, schedule chkdsk /f on the system volume and reboot.
    • In Event Viewer → Windows Logs → System, look for Disk, Ntfs, or StorPort events (warnings/errors) around the time of the bugchecks.
    • If there are repeated disk or NTFS errors, suspect the drive or controller.
    1. Remove or test third‑party filter drivers
    • Temporarily uninstall or disable:
      • Third‑party antivirus/endpoint security
      • Backup/snapshot tools
      • Disk encryption, defragmentation, or “tuning” utilities
      • Any filesystem filter drivers (e.g., cloud sync clients that install drivers)
    • After removal, test stability. If BSODs stop, reintroduce components one by one.
    1. Hardware validation
    • Run vendor diagnostics on the system drive (SSD/HDD) and controller.
    • Run a memory test (e.g., Windows Memory Diagnostic extended test). Intermittent RAM errors can corrupt kernel structures and manifest as NTFS/ntkrnlmp faults.
    1. Additional dump analysis
    • For each dump, compare stacks to see if NTFS close/teardown is always involved.
    • Use !thread and !process in WinDbg on the faulting thread to see what component initiated the I/O.
    • If a third‑party driver appears consistently in other frames or in loaded modules, focus on updating or removing that driver.

    If, after updates, disk checks, and removal of all non‑Microsoft filter drivers, the system still shows the same 0x7E in Ntfs/nt!ExReinitializeResourceLite, treat it as likely hardware (storage or RAM) and proceed with replacement testing.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.