In a windows dump that shows that NTFS received an invalid pointer for a delete, I need to see which piece of code issued the delete, and would like to see what filesystem filters are running, can someone point me at some documentation for this?

Nichols, Alan 0 Reputation points
2024-03-07T09:57:12.3+00:00

It is a full memory dump and there is NOTHING TO SEE AT ALL IN THE WINDOWS EVENT LOG , only the restart is visible in the event log.

How, in a windows dump do I follow the chain of events leading up to the illegal NTFS delete (the supplied pointer was invalid)

The operating system is windows server 2022.

Filesystem "filters" are active and a couple of applications, but this system was hardly being used at all, I need to eliminate my application ;-) ...

Is there some self training available for windows dump reading ? How would you proceed ?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.