Share via

Random BSOD SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e) and IRQL_NOT_LESS_OR_EQUAL (a)

Anonymous
2024-08-20T16:30:57+00:00

I have a computer that has random BSOD happening sometimes daily and sometimes only a few days a week. A few weeks ago I ran chkdsk, sfc scannow and DISM. The issue seemed to stop for a week or so and now has come back again. The two crash dumps are below if anyone could help determine what may be causing it.

1st one

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.063 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 42

Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\jcutler\Downloads\082024-9500-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff805`40000000 PsLoadedModuleList = 0xfffff805`40c2a830
Debug session time: Tue Aug 20 11:18:03.827 2024 (UTC - 4:00)
System Uptime: 0 days 0:40:47.366
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`008c9018).  Type ".hh dbgerr001" for details
Loading unloaded module list
.............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff805`403fe2a0 48894c2408      mov     qword ptr [rsp+8],rcx ss:ffff800b`aadb6700=000000000000000a
1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffb1081bed24f4, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8054031dd21, address which referenced memory

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 546

    Key  : Analysis.Elapsed.mSec
    Value: 7267

    Key  : Analysis.IO.Other.Mb
    Value: 12

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 26

    Key  : Analysis.Init.CPU.mSec
    Value: 281

    Key  : Analysis.Init.Elapsed.mSec
    Value: 94414

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 93

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xa

    Key  : Bugcheck.Code.TargetModel
    Value: 0xa

    Key  : Failure.Bucket
    Value: AV_win32kfull!xxxRemoveQueueCompletion

    Key  : Failure.Hash
    Value: {cb7d5ed8-2741-f0d2-c30b-7712b3d17105}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1

BUGCHECK_CODE:  a

BUGCHECK_P1: ffffb1081bed24f4

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff8054031dd21

FILE_IN_CAB:  082024-9500-01.dmp

FAULTING_THREAD:  ffffb107c4dd0080

WRITE_ADDRESS: fffff80540cfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffffb1081bed24f4 

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  NinjaRMMAgent.exe

STACK_TEXT:  
ffff800b`aadb66f8 fffff805`40412aa9     : 00000000`0000000a ffffb108`1bed24f4 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffff800b`aadb6700 fffff805`4040e478     : 00000000`00000000 ffffa081`ff1ca180 ffffa081`ff1ca180 fffff805`402e6d96 : nt!KiBugCheckDispatch+0x69
ffff800b`aadb6840 fffff805`4031dd21     : fffff805`4022e974 ffffb107`c4dd0080 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x478
ffff800b`aadb69d8 fffff805`4022e974     : ffffb107`c4dd0080 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchQueue+0x5
ffff800b`aadb69e0 fffff805`4022e098     : ffffb107`c49bb6c0 00000000`00000000 00000000`00000000 00000000`00000001 : nt!KeRemoveQueueEx+0x574
ffff800b`aadb6a80 fffff805`4060622e     : 00000000`00000000 ffff800b`aadb6c61 ffffb107`c4dd0080 fffff805`40255163 : nt!IoRemoveIoCompletion+0x98
ffff800b`aadb6bb0 fffff805`40412205     : ffffb107`bf840bf0 ffffffff`ffb3b4c0 ffffb107`c4dd0080 00000000`00000004 : nt!NtRemoveIoCompletionEx+0xfe
ffff800b`aadb6cf0 fffff805`40403090     : fffff011`d4975207 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
ffff800b`aadb6ef8 fffff011`d4975207     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffff800b`aadb6f00 fffff011`d4ac1292     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32kfull!xxxRemoveQueueCompletion+0x57
ffff800b`aadb6f70 fffff011`d4a1794e     : 00000000`00000000 fffff03a`044e3410 00000000`ffffffff 00000000`00001cff : win32kfull!xxxMsgWaitForMultipleObjectsEx+0x126
ffff800b`aadb7020 fffff011`d3966fd0     : 00000000`00001cff 00000000`00000000 00000000`ffffffff 00000000`00001cff : win32kfull!NtUserMsgWaitForMultipleObjectsEx+0x3fe
ffff800b`aadb7950 fffff805`40412205     : ffffb107`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : win32k!NtUserMsgWaitForMultipleObjectsEx+0x20
ffff800b`aadb7990 00007fff`835f9044     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0763e4d8 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`835f9044

SYMBOL_NAME:  win32kfull!xxxRemoveQueueCompletion+57

MODULE_NAME: win32kfull

IMAGE_NAME:  win32kfull.sys

IMAGE_VERSION:  10.0.19041.4717

STACK_COMMAND:  .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET:  57

FAILURE_BUCKET_ID:  AV_win32kfull!xxxRemoveQueueCompletion

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {cb7d5ed8-2741-f0d2-c30b-7712b3d17105}

Followup:     MachineOwner
---------

NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'

2nd one

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.032 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 42

Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\jcutler\Downloads\082024-9765-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff801`67200000 PsLoadedModuleList = 0xfffff801`67e2a830
Debug session time: Tue Aug 20 10:36:38.975 2024 (UTC - 4:00)
System Uptime: 1 days 1:17:35.888
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols

Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`675fe2a0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffbd81`99eff0f0=000000000000007e
6: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80167456b30, The address that the exception occurred at
Arg3: ffffce0f8eea7658, Exception Record Address
Arg4: ffffbd8199eff920, Context Record Address

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read

    Key  : Analysis.CPU.mSec
    Value: 875

    Key  : Analysis.Elapsed.mSec
    Value: 7375

    Key  : Analysis.IO.Other.Mb
    Value: 3

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 11

    Key  : Analysis.Init.CPU.mSec
    Value: 62

    Key  : Analysis.Init.Elapsed.mSec
    Value: 3524

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 91

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1000007e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1000007e

    Key  : Failure.Bucket
    Value: AV_nt!KiSearchForNewThreadOnProcessor

    Key  : Failure.Hash
    Value: {f6898590-0a2f-456e-2101-8929228989d1}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1

BUGCHECK_CODE:  7e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff80167456b30

BUGCHECK_P3: ffffce0f8eea7658

BUGCHECK_P4: ffffbd8199eff920

FILE_IN_CAB:  082024-9765-01.dmp

FAULTING_THREAD:  ffffe60954728040

EXCEPTION_RECORD:  ffffce0f8eea7658 -- (.exr 0xffffce0f8eea7658)
ExceptionAddress: fffff80167456b30 (nt!KiSearchForNewThreadOnProcessor)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  ffffbd8199eff920 -- (.cxr 0xffffbd8199eff920)
rax=c3ffffffffffffff rbx=ffffbd8199ea5180 rcx=ffffbd8199ea5180
rdx=0000000000000000 rsi=ffffe60954728040 rdi=0000000000000000
rip=fffff80167456b30 rsp=ffffce0f8eea7898 rbp=0000000000000000
 r8=fffff80161a61a00  r9=0000000000000000 r10=0000000000000006
r11=0000000000000000 r12=00000000000000ff r13=0000000000000001
r14=00000000000000bf r15=fffff80167f25440
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00050246
nt!KiSearchForNewThreadOnProcessor:
fffff801`67456b30 48895c2408      mov     qword ptr [rsp+8],rbx ss:0018:ffffce0f`8eea78a0=ffffe609fffffffe
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

READ_ADDRESS: fffff80167efb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffffffffffffffff 

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

EXCEPTION_STR:  0xc0000005

IP_IN_FREE_BLOCK: 0

STACK_TEXT:  
ffffce0f`8eea7898 fffff801`6745647c     : ffffe609`fffffffe ffffce0f`ffffffff 00000000`00000000 fffff801`67428ae8 : nt!KiSearchForNewThreadOnProcessor
ffffce0f`8eea78a0 fffff801`674558bf     : 00000000`00000006 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x5ec
ffffce0f`8eea7950 fffff801`67422917     : ffffe609`00000000 fffff801`00000000 ffffce0f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x14f
ffffce0f`8eea79f0 fffff801`674224c0     : ffffe609`54728040 fffff801`677f3f40 ffffe609`2828ace0 00000000`00000000 : nt!KeRemovePriQueue+0x1a7
ffffce0f`8eea7a70 fffff801`675299a5     : ffffe609`54728040 00000000`00000080 ffffe609`282c4080 00000000`00000000 : nt!ExpWorkerThread+0xa0
ffffce0f`8eea7b10 fffff801`676072a8     : ffffbd81`995cf180 ffffe609`54728040 fffff801`67529950 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffce0f`8eea7b60 00000000`00000000     : ffffce0f`8eea8000 ffffce0f`8eea1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28

SYMBOL_NAME:  nt!KiSearchForNewThreadOnProcessor+0

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.4780

STACK_COMMAND:  .cxr 0xffffbd8199eff920 ; kb

BUCKET_ID_FUNC_OFFSET:  0

FAILURE_BUCKET_ID:  AV_nt!KiSearchForNewThreadOnProcessor

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {f6898590-0a2f-456e-2101-8929228989d1}

Followup:     MachineOwner
---------

NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2407.24003.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.016 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 42

Microsoft (R) Windows Debugger Version 10.0.27668.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\jcutler\Downloads\082024-9765-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 19041 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff801`67200000 PsLoadedModuleList = 0xfffff801`67e2a830
Debug session time: Tue Aug 20 10:36:38.975 2024 (UTC - 4:00)
System Uptime: 1 days 1:17:35.888
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols

Loading unloaded module list
..............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`675fe2a0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffbd81`99eff0f0=000000000000007e
6: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80167456b30, The address that the exception occurred at
Arg3: ffffce0f8eea7658, Exception Record Address
Arg4: ffffbd8199eff920, Context Record Address

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read

    Key  : Analysis.CPU.mSec
    Value: 671

    Key  : Analysis.Elapsed.mSec
    Value: 2417

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 452

    Key  : Analysis.Init.Elapsed.mSec
    Value: 12120

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 95

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1000007e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1000007e

    Key  : Failure.Bucket
    Value: AV_nt!KiSearchForNewThreadOnProcessor

    Key  : Failure.Hash
    Value: {f6898590-0a2f-456e-2101-8929228989d1}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1

BUGCHECK_CODE:  7e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff80167456b30

BUGCHECK_P3: ffffce0f8eea7658

BUGCHECK_P4: ffffbd8199eff920

FILE_IN_CAB:  082024-9765-01.dmp

FAULTING_THREAD:  ffffe60954728040

EXCEPTION_RECORD:  ffffce0f8eea7658 -- (.exr 0xffffce0f8eea7658)
ExceptionAddress: fffff80167456b30 (nt!KiSearchForNewThreadOnProcessor)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  ffffbd8199eff920 -- (.cxr 0xffffbd8199eff920)
rax=c3ffffffffffffff rbx=ffffbd8199ea5180 rcx=ffffbd8199ea5180
rdx=0000000000000000 rsi=ffffe60954728040 rdi=0000000000000000
rip=fffff80167456b30 rsp=ffffce0f8eea7898 rbp=0000000000000000
 r8=fffff80161a61a00  r9=0000000000000000 r10=0000000000000006
r11=0000000000000000 r12=00000000000000ff r13=0000000000000001
r14=00000000000000bf r15=fffff80167f25440
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00050246
nt!KiSearchForNewThreadOnProcessor:
fffff801`67456b30 48895c2408      mov     qword ptr [rsp+8],rbx ss:0018:ffffce0f`8eea78a0=ffffe609fffffffe
Resetting default scope

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

READ_ADDRESS: fffff80167efb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffffffffffffffff 

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

EXCEPTION_STR:  0xc0000005

IP_IN_FREE_BLOCK: 0

STACK_TEXT:  
ffffce0f`8eea7898 fffff801`6745647c     : ffffe609`fffffffe ffffce0f`ffffffff 00000000`00000000 fffff801`67428ae8 : nt!KiSearchForNewThreadOnProcessor
ffffce0f`8eea78a0 fffff801`674558bf     : 00000000`00000006 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x5ec
ffffce0f`8eea7950 fffff801`67422917     : ffffe609`00000000 fffff801`00000000 ffffce0f`00000000 00000000`00000000 : nt!KiCommitThreadWait+0x14f
ffffce0f`8eea79f0 fffff801`674224c0     : ffffe609`54728040 fffff801`677f3f40 ffffe609`2828ace0 00000000`00000000 : nt!KeRemovePriQueue+0x1a7
ffffce0f`8eea7a70 fffff801`675299a5     : ffffe609`54728040 00000000`00000080 ffffe609`282c4080 00000000`00000000 : nt!ExpWorkerThread+0xa0
ffffce0f`8eea7b10 fffff801`676072a8     : ffffbd81`995cf180 ffffe609`54728040 fffff801`67529950 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffce0f`8eea7b60 00000000`00000000     : ffffce0f`8eea8000 ffffce0f`8eea1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28

SYMBOL_NAME:  nt!KiSearchForNewThreadOnProcessor+0

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.4780

STACK_COMMAND:  .cxr 0xffffbd8199eff920 ; kb

BUCKET_ID_FUNC_OFFSET:  0

FAILURE_BUCKET_ID:  AV_nt!KiSearchForNewThreadOnProcessor

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {f6898590-0a2f-456e-2101-8929228989d1}

Followup:     MachineOwner
---------
Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-08-21T07:14:03+00:00

    Dear Justin Cutler!

    Welcome to the Microsoft Community!

    According to the blue screen crash information provided, the first blue screen log shows that this problem seems to be related to the kernel mode driver of Windows 10. The specific error code is "0xA", which usually indicates that the driver attempts to access an invalid memory address or a driver conflict occurs. The second blue screen log shows that this problem may be caused by the Windows kernel mode driver ntkrnlmp.exe.

    Here are some key information from the blue screen crash log:

    • BUGCHECK_CODE: 0xA
    • FAULTING_THREAD: ffffb107c4dd0080
    • WRITE_ADDRESS: fffff80540cfb390
    • PROCESS_NAME: NinjaRMMAgent.exe
    • MODULE_NAME: win32kfull
    • IMAGE_NAME: win32kfull.sys

    This problem may be caused by the process named "NinjaRMMAgent.exe", which may conflict with the "win32kfull.sys" driver. Here are the recommended steps to fix this problem:

    1. Update drivers:
    • Make sure your system drivers are up to date. Especially the graphics card driver, as "win32kfull.sys" is related to the graphics subsystem.
    1. Uninstall NinjaRMMAgent:
    • If "NinjaRMMAgent.exe" is not a program you must use, try uninstalling it and see if that solves the problem.
    1. Boot to Safe Mode:
    • Try booting to Safe Mode to determine if the problem is caused by a third-party application or driver.
    1. System Restore:
    • If you have recently made system changes (such as installing new software or drivers) and you have previously set a system restore point, you can try to restore the system to a previous state.
    1. Run the Memory Diagnostic Tool:
    • Use the Windows Memory Diagnostic Tool to check if there are any problems with the memory.
    1. Seek professional help:
    • If the above steps do not solve the problem, you may need to seek professional technical support.

    Please make sure to back up important data before making any changes to prevent data loss. If you are not familiar with any of the above steps, it is recommended to seek professional technical support.

    Best regards

    Yang.Z - MSFT | Microsoft Community Support Specialist

    Was this answer helpful?

    0 comments No comments