Share via

BSOD PAGE_FAULT_IN_NONPAGED_AREA (50) ntkrnlmp.exe Windows 10

Anonymous
2019-08-14T22:04:01+00:00

Hi guys facing this issue in my PC, clean installation of Windows 10 and drivers, attached data from the memory dump

Gigabyte B450M-DS3H Bios F42b

Ryzen 7 3700X

RAM HyperX @ 2666 MHz 2 X 8GB

Nvidia RTX 2060

*No overclocking

*******************************************************************************

*                                                                             *

*                        Bugcheck Analysis                                    *

*                                                                             *

*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)

Invalid system memory was referenced.  This cannot be protected by try-except.

Typically the address is just plain bad or it is pointing at freed memory.

Arguments:

Arg1: ffffc20874ebc000, memory referenced.

Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.

Arg3: fffff8063ace23da, If non-zero, the instruction address which referenced the bad memory

address.

Arg4: 0000000000000000, (reserved)

Debugging Details:


Could not read faulting driver name

KEY_VALUES_STRING: 1

PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

DUMP_TYPE:  2

BUGCHECK_P1: ffffc20874ebc000

BUGCHECK_P2: 2

BUGCHECK_P3: fffff8063ace23da

BUGCHECK_P4: 0

READ_ADDRESS: fffff8063b1713b8: Unable to get MiVisibleState

Unable to get NonPagedPoolStart

Unable to get NonPagedPoolEnd

Unable to get PagedPoolStart

Unable to get PagedPoolEnd

 ffffc20874ebc000 

FAULTING_IP: 

nt!RtlDecompressBufferXpressHuff+3aa

fffff806`3ace23da f3a4            rep movs byte ptr [rdi],byte ptr [rsi]

MM_INTERNAL_CODE:  0

CPU_COUNT: 10

CPU_MHZ: e09

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 71

CPU_STEPPING: 0

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  RuntimeBroker.exe

CURRENT_IRQL:  2

ANALYSIS_SESSION_HOST:  DESKTOP-V3CS05D

ANALYSIS_SESSION_TIME:  08-14-2019 15:49:51.0162

ANALYSIS_VERSION: 10.0.18362.1 amd64fre

TRAP_FRAME:  ffff948f5f2221f0 -- (.trap 0xffff948f5f2221f0)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=ffffc20874e9f465 rbx=0000000000000000 rcx=0000000000004465

rdx=0000000000000100 rsi=0000000000000000 rdi=0000000000000000

rip=fffff8063ace23da rsp=ffff948f5f222380 rbp=ffffc2087372e000

 r8=0000000000000000  r9=0000000000000000 r10=0000000000004502

r11=0000000000008000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0         nv up ei ng nz ac pe cy

nt!RtlDecompressBufferXpressHuff+0x3aa:

fffff806`3ace23da f3a4            rep movs byte ptr [rdi],byte ptr [rsi]

Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff8063ade21c1 to fffff8063adbfcc0

STACK_TEXT:  

ffff948f5f221f48 fffff8063ade21c1 : 0000000000000050 ffffc20874ebc000 0000000000000002 ffff948f5f2221f0 : nt!KeBugCheckEx

ffff948f5f221f50 fffff8063ac729df : 0000000000000111 0000000000000002 0000000000000000 ffffc20874ebc000 : nt!MiSystemFault+0x1d5601

ffff948f5f222050 fffff8063adcdd20 : 0000002d0000002d ffffc2087372dfe0 ffffc20874e6b000 0000000000000000 : nt!MmAccessFault+0x34f

ffff948f5f2221f0 fffff8063ace23da : ffffc2087372e000 ffffc20874ebb4c8 ffffc20874e51d60 ffffc20874e8b000 : nt!KiPageFault+0x360

ffff948f5f222380 fffff8063ac5caf0 : 000000000000cd94 ffffc20874e6b000 00000000000504c8 fffff8063b2e2116 : nt!RtlDecompressBufferXpressHuff+0x3aa

ffff948f5f2223d0 fffff8063ac5ca1f : 0000000000000000 ffffab0f9095b560 0000000000000000 0000000000000000 : nt!RtlDecompressBufferEx+0x60

ffff948f5f222420 fffff8063b1fe0ab : 0000000000001429 0000000000000000 ffff948f5f222510 ffff948f5f222520 : nt!SmDecompressBuffer+0xff

ffff948f5f2224c0 fffff8063b1ffe7d : 0000000000000000 0000000000000003 ffffab0f903723a0 fffff8063ac3967d : nt!PfSnGetPrefetchInstructions+0x257

ffff948f5f222600 fffff8063b201509 : ffffab0f907f34c0 ffff948f5f222710 ffff948f00000000 0000000000000000 : nt!PfSnBeginScenario+0x1f5

ffff948f5f2226a0 fffff8063b201365 : 0000000000000000 ffffab0f907f34c0 ffffe780fbeca180 ffffab0f907f34c0 : nt!PfSnBeginAppLaunch+0x169

ffff948f5f2228a0 fffff8063b20335a : ffffe780fbeca180 0000000000000000 ffffab0f90372080 0000000000000000 : nt!PfProcessCreateNotification+0x5d

ffff948f5f2228d0 fffff8063adc767a : ffffe780fbeca180 ffffab0f90372080 ffffe780fbedb440 0000000000000000 : nt!PspUserThreadStartup+0x14a

ffff948f5f2229c0 fffff8063adc75e0 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiStartUserThread+0x2a

ffff948f5f222b00 00007ffa069cce50 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiStartUserThreadReturn

00000059937cf8d8 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffa`069cce50

THREAD_SHA1_HASH_MOD_FUNC:  4c1150ec55a6abdd5d2266612f84de0bcbbd1145

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  aed3012a5c9cfbcf931004eed3f2b59f427427ba

THREAD_SHA1_HASH_MOD:  7f608ac2fbce9034a3386b1d51652e4911d30234

FOLLOWUP_IP: 

nt!RtlDecompressBufferXpressHuff+3aa

fffff806`3ace23da f3a4            rep movs byte ptr [rdi],byte ptr [rsi]

FAULT_INSTR_CODE:  8b48a4f3

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  nt!RtlDecompressBufferXpressHuff+3aa

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  35707659

IMAGE_VERSION:  10.0.18362.295

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  3aa

FAILURE_BUCKET_ID:  AV_INVALID_nt!RtlDecompressBufferXpressHuff

BUCKET_ID:  AV_INVALID_nt!RtlDecompressBufferXpressHuff

PRIMARY_PROBLEM_CLASS:  AV_INVALID_nt!RtlDecompressBufferXpressHuff

TARGET_TIME:  2019-08-14T18:21:45.000Z

OSBUILD:  18362

OSSERVICEPACK:  295

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:  

USER_LCID:  0

OSBUILD_TIMESTAMP:  1998-05-30 15:12:57

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  1e1a

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_invalid_nt!rtldecompressbufferxpresshuff

FAILURE_ID_HASH:  {aa7b5878-1a5d-6544-4200-7ccaffe918b5}

Followup:     MachineOwner

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2019-08-20T00:40:30+00:00

    All right, I understand, here are the new dump files along with the system logs

    https://1drv.ms/u/s!AmFj6ylHkhFHgb45tIilcB-mOHdqag?e=oVFgtT

    Thanks for the help

    Was this answer helpful?

    0 comments No comments
  2. Sumit D - IA 171.1K Reputation points Independent Advisor
    2019-08-17T05:29:58+00:00

    No real help, unfortunately.

    To better understand the issue, Please see the article below on how to share System logs.

    http://www.yourwindowsguide.com/2017/12/how-to-...

    Content on the above blog is written by a Microsoft MVP so it is safe. However, do watch out for the ads.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-08-16T17:26:33+00:00

    Here is the dump files: 

    https://1drv.ms/u/s!AmFj6ylHkhFHgb0hMrDKjymSwUsgQg?e=xSDGjI

    thanks for the help

    Was this answer helpful?

    0 comments No comments
  4. Sumit D - IA 171.1K Reputation points Independent Advisor
    2019-08-15T01:56:47+00:00

    Hi,

    I am Sumit, an Independent Advisor and a 2-Year Windows Insider MVP here to help.

    The dump you attached blamed memory corruption as a cause. Can you share the verifier one as well for better analysis?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-08-14T23:46:04+00:00

    Here is the dump files: 

    https://1drv.ms/u/s!AmFj6ylHkhFHgb0hMrDKjymSwUsgQg?e=xSDGjI

    I have run driver verifier and the last dump file is different and contains...

    *** WARNING: Unable to verify timestamp for win32kfull.sys

    Could not read faulting driver name

    *** WARNING: Unable to verify timestamp for win32k.sys

    I hope someone can help me.

    Was this answer helpful?

    0 comments No comments