I have a computer that has random BSOD happening sometimes daily and sometimes only a few days a week. A few weeks ago I ran chkdsk, sfc scannow and DISM. The issue seemed to stop for a week or so and now has come back again. The two crash dumps are below if anyone could help determine what may be causing it.
1st one
************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
EnableRedirectToChakraJsProvider : false
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.063 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 42
Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\jcutler\Downloads\082024-9500-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff805`40000000 PsLoadedModuleList = 0xfffff805`40c2a830
Debug session time: Tue Aug 20 11:18:03.827 2024 (UTC - 4:00)
System Uptime: 0 days 0:40:47.366
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`008c9018). Type ".hh dbgerr001" for details
Loading unloaded module list
.............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff805`403fe2a0 48894c2408 mov qword ptr [rsp+8],rcx ss:ffff800b`aadb6700=000000000000000a
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffb1081bed24f4, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8054031dd21, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 546
Key : Analysis.Elapsed.mSec
Value: 7267
Key : Analysis.IO.Other.Mb
Value: 12
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 26
Key : Analysis.Init.CPU.mSec
Value: 281
Key : Analysis.Init.Elapsed.mSec
Value: 94414
Key : Analysis.Memory.CommitPeak.Mb
Value: 93
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: AV_win32kfull!xxxRemoveQueueCompletion
Key : Failure.Hash
Value: {cb7d5ed8-2741-f0d2-c30b-7712b3d17105}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: a
BUGCHECK_P1: ffffb1081bed24f4
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff8054031dd21
FILE_IN_CAB: 082024-9500-01.dmp
FAULTING_THREAD: ffffb107c4dd0080
WRITE_ADDRESS: fffff80540cfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffb1081bed24f4
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: NinjaRMMAgent.exe
STACK_TEXT:
ffff800b`aadb66f8 fffff805`40412aa9 : 00000000`0000000a ffffb108`1bed24f4 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffff800b`aadb6700 fffff805`4040e478 : 00000000`00000000 ffffa081`ff1ca180 ffffa081`ff1ca180 fffff805`402e6d96 : nt!KiBugCheckDispatch+0x69
ffff800b`aadb6840 fffff805`4031dd21 : fffff805`4022e974 ffffb107`c4dd0080 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x478
ffff800b`aadb69d8 fffff805`4022e974 : ffffb107`c4dd0080 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchQueue+0x5
ffff800b`aadb69e0 fffff805`4022e098 : ffffb107`c49bb6c0 00000000`00000000 00000000`00000000 00000000`00000001 : nt!KeRemoveQueueEx+0x574
ffff800b`aadb6a80 fffff805`4060622e : 00000000`00000000 ffff800b`aadb6c61 ffffb107`c4dd0080 fffff805`40255163 : nt!IoRemoveIoCompletion+0x98
ffff800b`aadb6bb0 fffff805`40412205 : ffffb107`bf840bf0 ffffffff`ffb3b4c0 ffffb107`c4dd0080 00000000`00000004 : nt!NtRemoveIoCompletionEx+0xfe
ffff800b`aadb6cf0 fffff805`40403090 : fffff011`d4975207 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
ffff800b`aadb6ef8 fffff011`d4975207 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffff800b`aadb6f00 fffff011`d4ac1292 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32kfull!xxxRemoveQueueCompletion+0x57
ffff800b`aadb6f70 fffff011`d4a1794e : 00000000`00000000 fffff03a`044e3410 00000000`ffffffff 00000000`00001cff : win32kfull!xxxMsgWaitForMultipleObjectsEx+0x126
ffff800b`aadb7020 fffff011`d3966fd0 : 00000000`00001cff 00000000`00000000 00000000`ffffffff 00000000`00001cff : win32kfull!NtUserMsgWaitForMultipleObjectsEx+0x3fe
ffff800b`aadb7950 fffff805`40412205 : ffffb107`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : win32k!NtUserMsgWaitForMultipleObjectsEx+0x20
ffff800b`aadb7990 00007fff`835f9044 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0763e4d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`835f9044
SYMBOL_NAME: win32kfull!xxxRemoveQueueCompletion+57
MODULE_NAME: win32kfull
IMAGE_NAME: win32kfull.sys
IMAGE_VERSION: 10.0.19041.4717
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 57
FAILURE_BUCKET_ID: AV_win32kfull!xxxRemoveQueueCompletion
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {cb7d5ed8-2741-f0d2-c30b-7712b3d17105}
Followup: MachineOwner
---------
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'
2nd one
************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
EnableRedirectToChakraJsProvider : false
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.032 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 42
Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\jcutler\Downloads\082024-9765-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff801`67200000 PsLoadedModuleList = 0xfffff801`67e2a830
Debug session time: Tue Aug 20 10:36:38.975 2024 (UTC - 4:00)
System Uptime: 1 days 1:17:35.888
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`675fe2a0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffbd81`99eff0f0=000000000000007e
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80167456b30, The address that the exception occurred at
Arg3: ffffce0f8eea7658, Exception Record Address
Arg4: ffffbd8199eff920, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 875
Key : Analysis.Elapsed.mSec
Value: 7375
Key : Analysis.IO.Other.Mb
Value: 3
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 11
Key : Analysis.Init.CPU.mSec
Value: 62
Key : Analysis.Init.Elapsed.mSec
Value: 3524
Key : Analysis.Memory.CommitPeak.Mb
Value: 91
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_nt!KiSearchForNewThreadOnProcessor
Key : Failure.Hash
Value: {f6898590-0a2f-456e-2101-8929228989d1}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80167456b30
BUGCHECK_P3: ffffce0f8eea7658
BUGCHECK_P4: ffffbd8199eff920
FILE_IN_CAB: 082024-9765-01.dmp
FAULTING_THREAD: ffffe60954728040
EXCEPTION_RECORD: ffffce0f8eea7658 -- (.exr 0xffffce0f8eea7658)
ExceptionAddress: fffff80167456b30 (nt!KiSearchForNewThreadOnProcessor)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: ffffbd8199eff920 -- (.cxr 0xffffbd8199eff920)
rax=c3ffffffffffffff rbx=ffffbd8199ea5180 rcx=ffffbd8199ea5180
rdx=0000000000000000 rsi=ffffe60954728040 rdi=0000000000000000
rip=fffff80167456b30 rsp=ffffce0f8eea7898 rbp=0000000000000000
r8=fffff80161a61a00 r9=0000000000000000 r10=0000000000000006
r11=0000000000000000 r12=00000000000000ff r13=0000000000000001
r14=00000000000000bf r15=fffff80167f25440
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
nt!KiSearchForNewThreadOnProcessor:
fffff801`67456b30 48895c2408 mov qword ptr [rsp+8],rbx ss:0018:ffffce0f`8eea78a0=ffffe609fffffffe
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff80167efb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
EXCEPTION_STR: 0xc0000005
IP_IN_FREE_BLOCK: 0
STACK_TEXT:
ffffce0f`8eea7898 fffff801`6745647c : ffffe609`fffffffe ffffce0f`ffffffff 00000000`00000000 fffff801`67428ae8 : nt!KiSearchForNewThreadOnProcessor
ffffce0f`8eea78a0 fffff801`674558bf : 00000000`00000006 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x5ec
ffffce0f`8eea7950 fffff801`67422917 : ffffe609`00000000 fffff801`00000000 ffffce0f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x14f
ffffce0f`8eea79f0 fffff801`674224c0 : ffffe609`54728040 fffff801`677f3f40 ffffe609`2828ace0 00000000`00000000 : nt!KeRemovePriQueue+0x1a7
ffffce0f`8eea7a70 fffff801`675299a5 : ffffe609`54728040 00000000`00000080 ffffe609`282c4080 00000000`00000000 : nt!ExpWorkerThread+0xa0
ffffce0f`8eea7b10 fffff801`676072a8 : ffffbd81`995cf180 ffffe609`54728040 fffff801`67529950 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffce0f`8eea7b60 00000000`00000000 : ffffce0f`8eea8000 ffffce0f`8eea1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!KiSearchForNewThreadOnProcessor+0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.4780
STACK_COMMAND: .cxr 0xffffbd8199eff920 ; kb
BUCKET_ID_FUNC_OFFSET: 0
FAILURE_BUCKET_ID: AV_nt!KiSearchForNewThreadOnProcessor
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f6898590-0a2f-456e-2101-8929228989d1}
Followup: MachineOwner
---------
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'
************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
EnableRedirectToChakraJsProvider : false
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.016 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 42
Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\jcutler\Downloads\082024-9765-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff801`67200000 PsLoadedModuleList = 0xfffff801`67e2a830
Debug session time: Tue Aug 20 10:36:38.975 2024 (UTC - 4:00)
System Uptime: 1 days 1:17:35.888
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`675fe2a0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffbd81`99eff0f0=000000000000007e
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80167456b30, The address that the exception occurred at
Arg3: ffffce0f8eea7658, Exception Record Address
Arg4: ffffbd8199eff920, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 671
Key : Analysis.Elapsed.mSec
Value: 2417
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 452
Key : Analysis.Init.Elapsed.mSec
Value: 12120
Key : Analysis.Memory.CommitPeak.Mb
Value: 95
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_nt!KiSearchForNewThreadOnProcessor
Key : Failure.Hash
Value: {f6898590-0a2f-456e-2101-8929228989d1}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80167456b30
BUGCHECK_P3: ffffce0f8eea7658
BUGCHECK_P4: ffffbd8199eff920
FILE_IN_CAB: 082024-9765-01.dmp
FAULTING_THREAD: ffffe60954728040
EXCEPTION_RECORD: ffffce0f8eea7658 -- (.exr 0xffffce0f8eea7658)
ExceptionAddress: fffff80167456b30 (nt!KiSearchForNewThreadOnProcessor)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: ffffbd8199eff920 -- (.cxr 0xffffbd8199eff920)
rax=c3ffffffffffffff rbx=ffffbd8199ea5180 rcx=ffffbd8199ea5180
rdx=0000000000000000 rsi=ffffe60954728040 rdi=0000000000000000
rip=fffff80167456b30 rsp=ffffce0f8eea7898 rbp=0000000000000000
r8=fffff80161a61a00 r9=0000000000000000 r10=0000000000000006
r11=0000000000000000 r12=00000000000000ff r13=0000000000000001
r14=00000000000000bf r15=fffff80167f25440
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
nt!KiSearchForNewThreadOnProcessor:
fffff801`67456b30 48895c2408 mov qword ptr [rsp+8],rbx ss:0018:ffffce0f`8eea78a0=ffffe609fffffffe
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff80167efb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
EXCEPTION_STR: 0xc0000005
IP_IN_FREE_BLOCK: 0
STACK_TEXT:
ffffce0f`8eea7898 fffff801`6745647c : ffffe609`fffffffe ffffce0f`ffffffff 00000000`00000000 fffff801`67428ae8 : nt!KiSearchForNewThreadOnProcessor
ffffce0f`8eea78a0 fffff801`674558bf : 00000000`00000006 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x5ec
ffffce0f`8eea7950 fffff801`67422917 : ffffe609`00000000 fffff801`00000000 ffffce0f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x14f
ffffce0f`8eea79f0 fffff801`674224c0 : ffffe609`54728040 fffff801`677f3f40 ffffe609`2828ace0 00000000`00000000 : nt!KeRemovePriQueue+0x1a7
ffffce0f`8eea7a70 fffff801`675299a5 : ffffe609`54728040 00000000`00000080 ffffe609`282c4080 00000000`00000000 : nt!ExpWorkerThread+0xa0
ffffce0f`8eea7b10 fffff801`676072a8 : ffffbd81`995cf180 ffffe609`54728040 fffff801`67529950 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffce0f`8eea7b60 00000000`00000000 : ffffce0f`8eea8000 ffffce0f`8eea1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!KiSearchForNewThreadOnProcessor+0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.4780
STACK_COMMAND: .cxr 0xffffbd8199eff920 ; kb
BUCKET_ID_FUNC_OFFSET: 0
FAILURE_BUCKET_ID: AV_nt!KiSearchForNewThreadOnProcessor
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f6898590-0a2f-456e-2101-8929228989d1}
Followup: MachineOwner
---------