New
#1
BSOD on user PC after 3-5 minutes, no applications running
I have already debugged the dump file will paste info:
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000000c08a5
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x24
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre
LAST_CONTROL_TRANSFER: from fffff8800144ebd5 to fffff80002a89bc0
STACK_TEXT:
fffff880`03cd95b8 fffff880`0144ebd5 : 00000000`00000024 00000000`000c08a5 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`03cd95c0 fffff880`01473008 : 00000001`00000000 00000000`00000000 00000000`00000000 00000a80`00000000 : Ntfs!NtfsPagingFileIo+0x155
fffff880`03cd96c0 fffff880`01045bcf : fffffa80`03914b28 fffffa80`039147d0 fffffa80`0383abb0 00000000`00000000 : Ntfs! ?? ::FNODOBFM::`string'+0x71b9
fffff880`03cd9770 fffff880`010446df : fffffa80`04618950 fffffa80`07713001 fffffa80`04618900 fffffa80`039147d0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`03cd9800 fffff800`02ab0e15 : fffffa80`039147f0 fffffa80`04c40070 fffffa80`0378ea60 fffff880`02f65180 : fltmgr!FltpDispatch+0xcf
fffff880`03cd9860 fffff800`02ab08e9 : fffff880`03cd9901 fffff880`03cd9901 fffffa80`0378e9a0 00000000`00000000 : nt!IoPageRead+0x255
fffff880`03cd98f0 fffff800`02a9728a : 00000000`00000000 00000000`00000000 ffffffff`ffffffff 00000000`000e0000 : nt!MiIssueHardFault+0x255
fffff880`03cd9980 fffff800`02a87cee : 00000000`00000001 00000000`002b0008 00000000`000cee01 00000000`002b2000 : nt!MmAccessFault+0x146a
fffff880`03cd9ae0 00000000`7710d8ae : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`000cedc0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7710d8ae
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsPagingFileIo+155
fffff880`0144ebd5 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs!NtfsPagingFileIo+155
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 52e1be8a
IMAGE_VERSION: 6.1.7601.18378
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsPagingFileIo+155
BUCKET_ID: X64_0x24_Ntfs!NtfsPagingFileIo+155
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x24_ntfs!ntfspagingfileio+155
FAILURE_ID_HASH: {8018ac65-4151-0b56-5f0b-cec86356850c}
Followup: MachineOwner