New
#1
Random BSODs related to ntfs.sys and system kernel
I've had several bsods a day for about a week now. They mostly occur when the system is left alone for even a few minutes, but also when i'm playing a game (mostly DooM 3). Sometimes they are caused by ntfs.sys, sometimes the system kernel itself (ntkrnlmp.exe) crashes. I've attached all the dump files from c:\windows\minidump here.
I've recently updated my pc, and before the upgrade it was running fine and stable. I'm guessing it has something to do with the parts i upgraded, which were my graphics card (from VTX3D Radeon HD 5670 to XFX Radeon HD 6850) and my memory (from two A-Data AD2800E001GOU to fourA-DATA AD2U800B2G6-B model sticks)
System specs:
System: Windows 7 Home Premium 64-bit
Motherboard: ASUS M2N
Processor: AMD Athlon X2 4200+
Memory: 4x A-DATA AD2U800B2G6-B 2GB DDR2 800MHz
Graphics Card: XFX Radeon HD 6850 Black Edition
HDD: Samsung Spinpoint F3 3,5" 1TB 7200RPM SATA2
Also, here is what windbg found out about my latest ntfs.sys related bsod:
Code:MODULE_NAME: Ntfs FAULTING_MODULE: fffff80003066000 nt DEBUG_FLR_IMAGE_TIMESTAMP: 4d79996d EXCEPTION_RECORD: fffff880061ea088 -- (.exr 0xfffff880061ea088) ExceptionAddress: fffff8800141b11d (Ntfs+0x000000000000d11d) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: ffffffffffffffff Attempt to read from address ffffffffffffffff CONTEXT: fffff880061e98f0 -- (.cxr 0xfffff880061e98f0) rax=0000000000000000 rbx=0000000000000000 rcx=ffdff8a012d477c0 rdx=0000000000000000 rsi=0000000000000000 rdi=fffff8a012d476f0 rip=fffff8800141b11d rsp=fffff880061ea2c0 rbp=fffff880061ea660 r8=0000000000000000 r9=0000000000000000 r10=0000000000000000 r11=0000000000000010 r12=fffffa800b8c1e40 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr ac po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010256 Ntfs+0xd11d: fffff880`0141b11d 48393408 cmp qword ptr [rax+rcx],rsi ds:002b:ffdff8a0`12d477c0=???????????????? Resetting default scope DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x24 CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff88001414b68 to fffff8800141b11d STACK_TEXT: fffff880`061ea2c0 fffff880`01414b68 : fffffa80`0b8c1e40 fffff8a0`12d476f0 00000000`00000000 fffff880`061ea4f0 : Ntfs+0xd11d fffff880`061ea430 fffff880`0141a092 : fffffa80`0b8c1e40 fffffa80`0aa8d430 fffff8a0`12d476f0 00000000`00000000 : Ntfs+0x6b68 fffff880`061ea5c0 fffff880`0141d2a6 : fffffa80`0b8c1e40 fffffa80`0aa8d430 fffff8a0`12d476f0 fffff8a0`12d475c0 : Ntfs+0xc092 fffff880`061ea790 fffff880`0141fcf8 : fffffa80`0b8c1e40 fffffa80`0aa8d430 fffff880`061ea901 fffffa80`079b4801 : Ntfs+0xf2a6 fffff880`061ea930 fffff880`012cb23f : fffffa80`0aa8d7d0 fffffa80`0aa8d430 fffffa80`079b48d0 00000000`00000000 : Ntfs+0x11cf8 fffff880`061ea9e0 fffff880`012c96df : fffffa80`091e42c0 fffffa80`0aa8d430 fffffa80`091e4200 fffffa80`0aa8d430 : fltmgr!FltIsCallbackDataDirty+0xa2f fffff880`061eaa70 fffff800`030c80c2 : fffffa80`0aa8d450 fffffa80`0b883f20 00000000`00000403 fffff880`009e8180 : fltmgr+0x16df fffff880`061eaad0 fffff800`03372e37 : fffffa80`0a869000 fffffa80`0a869000 fffffa80`0a8690d1 fffffa80`0a869010 : nt!IoPageRead+0x252 fffff880`061eab60 fffff800`03372f31 : fffffa80`0b8645c0 fffffa80`0aa86760 fffff880`061eac98 00000000`00000004 : nt!RtlCompareUnicodeString+0x677 fffff880`061eabc0 fffff800`0311abed : fffffa80`0b8645c0 00000000`00000000 00000000`00001000 00000000`00000000 : nt!RtlCompareUnicodeString+0x771 fffff880`061eac10 fffff800`033f07fb : 00000000`00000000 00000000`00000000 fffffa80`0b883f20 fffffa80`0b95f5d0 : nt!IoGetAttachedDevice+0x19d fffff880`061eac70 fffff880`01418d50 : fffff8a0`00000000 fffff800`00000004 fffffa80`00040000 fffff880`0146b001 : nt!CcCopyRead+0x16b fffff880`061ead30 fffff880`0141d083 : 00000000`00000000 fffff8a0`12d476f0 fffff880`061eaf60 00000000`00000000 : Ntfs+0xad50 fffff880`061ead90 fffff880`0141fcf8 : fffffa80`0b8c7e40 fffffa80`0b32a410 fffff880`061eaf01 fffffa80`0aa85c00 : Ntfs+0xf083 fffff880`061eaf30 fffff880`012cb23f : fffffa80`0b32a7b0 fffffa80`0b32a410 fffffa80`0aa85c30 00000000`00000000 : Ntfs+0x11cf8 fffff880`061eafe0 fffff880`012cd94a : 00000000`00000000 00000000`00000000 fffffa80`09ad1700 fffffa80`0aa85c30 : fltmgr!FltIsCallbackDataDirty+0xa2f fffff880`061eb070 fffff880`012da204 : fffffa80`084e1c10 00000000`00000019 fffffa80`07cd7510 00000000`00000000 : fltmgr!FltPerformSynchronousIo+0x2ca fffff880`061eb110 fffff880`06362e25 : 00000000`00000000 fffffa80`07cd7510 00000000`00000000 00000000`00000000 : fltmgr!FltReadFile+0x334 fffff880`061eb1f0 fffff880`063621f0 : fffffa80`09ad1700 fffffa80`0aa85c30 00000007`00000010 00000002`00000004 : aswMonFlt+0x2e25 fffff880`061eb330 fffff880`0639636d : 00000000`00000000 fffffa80`0782fae0 fffff880`061eb458 fffff880`00000000 : aswMonFlt+0x21f0 fffff880`061eb400 fffff880`012cc242 : 00000000`00000000 00000000`00000000 fffffa80`0b8247d0 00000000`00000000 : aswMonFlt+0x3636d fffff880`061eb530 fffff880`012cb38b : fffffa80`07cc1030 fffffa80`0782fb80 fffffa80`09ad17b0 fffffa80`09ad19d0 : fltmgr!FltIsCallbackDataDirty+0x1a32 fffff880`061eb600 fffff880`012ea2b9 : fffffa80`0b824430 fffffa80`07cd7510 fffffa80`0b824400 fffffa80`091e42c0 : fltmgr!FltIsCallbackDataDirty+0xb7b fffff880`061eb690 fffff800`033d6537 : 00000000`00000005 fffff800`033d5f90 fffffa80`0b606a10 00000000`00000000 : fltmgr!FltReadFile+0x103e9 fffff880`061eb740 fffff800`033ccba4 : fffffa80`07c9fad0 00000000`00000000 fffffa80`0b89ab10 00000000`00000701 : nt!SeUnlockSubjectContext+0x647 fffff880`061eb8d0 fffff800`033d1b7d : fffffa80`0b89ab10 fffff880`061eba30 fffffa80`00000040 fffffa80`06d22080 : nt!SeQueryInformationToken+0x2104 fffff880`061eb9d0 fffff800`033d8647 : fffffa80`0add1cd0 00000000`00000001 fffffa80`0b1ab001 fffffa80`099f7570 : nt!ObOpenObjectByName+0x1cd fffff880`061eba80 fffff800`033e2398 : 00000000`02cd85e8 00000000`00100081 fffffa80`0aa86760 00000000`02cd85f8 : nt!SeUnlockSubjectContext+0x2757 fffff880`061ebb20 fffff800`030d5813 : 00000000`00000000 fffff800`033f0000 fffff880`061ebca0 00000000`00000000 : nt!NtCreateFile+0x78 fffff880`061ebbb0 00000000`777ffc0a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeSynchronizeExecution+0x3a43 00000000`02cd8568 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777ffc0a FOLLOWUP_IP: Ntfs+d11d fffff880`0141b11d 48393408 cmp qword ptr [rax+rcx],rsi SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: Ntfs+d11d FOLLOWUP_NAME: MachineOwner IMAGE_NAME: Ntfs.sys STACK_COMMAND: .cxr 0xfffff880061e98f0 ; kb BUCKET_ID: WRONG_SYMBOLS Followup: MachineOwner --------- 1: kd> .exr 0xfffff880061ea088 ExceptionAddress: fffff8800141b11d (Ntfs+0x000000000000d11d) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: ffffffffffffffff Attempt to read from address ffffffffffffffff 1: kd> lmvm Ntfs start end module name fffff880`0140e000 fffff880`015b0000 Ntfs (no symbols) Loaded symbol image file: Ntfs.sys Image path: \SystemRoot\System32\Drivers\Ntfs.sys Image name: Ntfs.sys Timestamp: Fri Mar 11 05:39:25 2011 (4D79996D) CheckSum: 00199985 ImageSize: 001A2000 File version: 6.1.7600.16778 Product version: 6.1.7600.16778 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntfs.sys OriginalFilename: ntfs.sys ProductVersion: 6.1.7600.16778 FileVersion: 6.1.7600.16778 (win7_gdr.110310-1506) FileDescription: NT File System Driver LegalCopyright: © Microsoft Corporation. All rights reserved.
Help is much appreciated, I'm getting tired of solving this alone.