Share via

BSOD AV_FBNetFlt!unknown_function help!

Anonymous
2022-05-21T15:52:59+00:00

Hello there. Yesterday while I was playing I got a BSOD (to provide more context, chrome and wps office were also opened). It was the first time since I bought my laptop (which is 5 months old). I'm worried it could occur again so I checked the details on the event viewer. It shows three critical events.

1-

Origen

Windows

Resumen

Shut down unexpectedly

Fecha

‎20/‎5/‎2022 18:58

Estado

Informe enviado

Firma del problema

Nombre de evento de problema: BlueScreen

Code: d1

Parameter 1: ffffdd8a402a4000

Parameter 2: 2

Parameter 3: 0

Parameter 4: fffff804c5272690

OS version: 10_0_19044

Service Pack: 0_0

Product: 768_1

OS Version: 10.0.19044.2.0.0.768.101

Locale ID: 1033

Información adicional sobre el problema

Id. de depósito: AV_FBNetFlt!unknown_function

2-

The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xffffdd8a402a4000, 0x0000000000000002, 0x0000000000000000, 0xfffff804c5272690). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 77c3fe2f-89a2-4c3a-8f47-733063b7bbd4.

3-

The previous system shutdown at 6:52:07 PM on ‎5/‎20/‎2022 was unexpected.

Windbg displays this:

Microsoft (R) Windows Debugger Version 10.0.22549.1000 AMD64

Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\MEMORY.DMP]

Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Symbol search path is: srv*

Executable search path is:

Windows 10 Kernel Version 19041 MP (16 procs) Free x64

Product: WinNt, suite: TerminalServer SingleUserTS Personal

Edition build lab: 19041.1.amd64fre.vb_release.191206-1406

Machine Name:

Kernel base = 0xfffff80462000000 PsLoadedModuleList = 0xfffff80462c2a2b0

Debug session time: Fri May 20 18:57:41.041 2022 (UTC - 4:00)

System Uptime: 3 days 10:51:15.671

Loading Kernel Symbols

...............................................................

.....Page aa07b not present in the dump file. Type ".hh dbgerr004" for details

.......Page 1bb5ec not present in the dump file. Type ".hh dbgerr004" for details

....................................................

................................................................

.........................

Loading User Symbols

PEB is paged out (Peb.Ldr = 000000f9`1fc3d018). Type ".hh dbgerr001" for details

Loading unloaded module list

..................................................

For analysis of this file, run !analyze -v

nt!KeBugCheckEx:

fffff804623f7d60 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff80891630e8a0=000000000000000a

7: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If kernel debugger is available get stack backtrace.

Arguments:

Arg1: ffffdd8a402a4000, memory referenced

Arg2: 0000000000000002, IRQL

Arg3: 0000000000000000, value 0 = read operation, 1 = write operation

Arg4: fffff804c5272690, address which referenced memory

Debugging Details:


KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec 

Value: 12687 

Key  : Analysis.DebugAnalysisManager 

Value: Create 

Key  : Analysis.Elapsed.mSec 

Value: 24930 

Key  : Analysis.Init.CPU.mSec 

Value: 3140 

Key  : Analysis.Init.Elapsed.mSec 

Value: 212668 

Key  : Analysis.Memory.CommitPeak.Mb 

Value: 95 

Key  : WER.OS.Branch 

Value: vb\_release 

Key  : WER.OS.Timestamp 

Value: 2019-12-06T14:06:00Z 

Key  : WER.OS.Version 

Value: 10.0.19041.1 

FILE_IN_CAB: MEMORY.DMP

BUGCHECK_CODE: d1

BUGCHECK_P1: ffffdd8a402a4000

BUGCHECK_P2: 2

BUGCHECK_P3: 0

BUGCHECK_P4: fffff804c5272690

READ_ADDRESS: ffffdd8a402a4000 Nonpaged pool

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

PROCESS_NAME: chrome.exe

TRAP_FRAME: ffff80891630e9e0 -- (.trap 0xffff80891630e9e0)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=ffffdd8a402a3f90 rbx=0000000000000000 rcx=ffffdd8a211fe220

rdx=ffffdd8a402a3f90 rsi=0000000000000000 rdi=0000000000000000

rip=fffff804c5272690 rsp=ffff80891630eb70 rbp=ffff80891630ec59

r8=ffffdd8a402a4000 r9=0000000000000000 r10=0000000066626e66

r11=ffffdd8a402a3f90 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0 nv up ei pl nz na pe nc

FBNetFlt+0x2690:

fffff804c5272690 664183385c cmp word ptr [r8],5Ch ds:ffffdd8a402a4000=????

Resetting default scope

STACK_TEXT:

ffff80891630e898 fffff80462409c69 : 000000000000000a ffffdd8a402a4000 0000000000000002 0000000000000000 : nt!KeBugCheckEx

ffff80891630e8a0 fffff80462405f69 : 0000000000000000 ffffcb80a20c1180 000000000000048c 0000000000000000 : nt!KiBugCheckDispatch+0x69

ffff80891630e9e0 fffff804c5272690 : ffffdd8a211fe23e ffff80891630ec59 0000000000000000 ffffdd8a2a4df76e : nt!KiPageFault+0x469

ffff80891630eb70 fffff804c5273d1b : ffffdd8a211fe220 ffff80891630ec59 ffffdd8a211fe248 ffff80891630ec59 : FBNetFlt+0x2690

ffff80891630eba0 fffff804626735cf : ffff80891630ec30 ffffdd8a37dc2430 ffffdd8a211fe220 ffffdd8a343b6080 : FBNetFlt+0x3d1b

ffff80891630ebf0 fffff80462643712 : ffffffff00000000 ffff80891630f9d0 ffff80891630f301 ffffdd8a2aea3450 : nt!PspCallProcessNotifyRoutines+0x213

ffff80891630ecc0 fffff804626ffb20 : ffffdd8a2b78a080 ffffdd8a343b6080 ffff80891630f450 ffff80891630f31c : nt!PspInsertThread+0x68e

ffff80891630ed80 fffff804624096b8 : 0000000000000002 0000000000000001 0000000000000000 00000250677e6920 : nt!NtCreateUserProcess+0xde0

ffff80891630fa50 00007ff958dee634 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x28

000000f93a5fcfb8 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ff9`58dee634

SYMBOL_NAME: FBNetFlt+2690

MODULE_NAME: FBNetFlt

IMAGE_NAME: FBNetFlt.sys

STACK_COMMAND: .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET: 2690

FAILURE_BUCKET_ID: AV_FBNetFlt!unknown_function

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {a930455f-6e65-8e8c-d1b4-40f3e912c54d}

Followup: MachineOwner


I'd appreciate a lot any help to find out what the issue is and how to fix it!

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2022-05-21T16:42:37+00:00

Hi TeVb,

I'm Paul and I'm here to help you with your concern.

The file "FBnetFLT.sys" is the Lenovo Network Throttling driver.

Can you open the Lenovo Vantage app? Check the Network boost, and make sure that it is disabled.

I hope this helps. Feel free to ask back any questions and keep me posted.

Was this answer helpful?

5 people found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-05-21T17:52:04+00:00

    That's good to know. I'm glad that I could help you. If you have any other questions don't hesitate to ask again. Also, feel free to choose a rating.

    Stay safe always and have a great day.

    Thanks.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2022-05-21T17:23:42+00:00

    Thank you! I just did what you recommended. If it ever happens again, I'll let you know!

    Was this answer helpful?

    0 comments No comments