*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88008402e58, fffff880084026b0, fffff800032ed58f}
Probably caused by : Ntfs.sys ( Ntfs! ?? ::FNODOBFM::`string'+299d )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88008402e58
Arg3: fffff880084026b0
Arg4: fffff800032ed58f
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88008402e58 -- (.exr 0xfffff88008402e58)
ExceptionAddress: fffff800032ed58f (nt!IoGetRelatedDeviceObject+0x000000000000005f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff880084026b0 -- (.cxr 0xfffff880084026b0;r)
rax=fffffa8003f7d030 rbx=0000000000000000 rcx=fffffa8003c75870
rdx=0065007400610064 rsi=0000000000000000 rdi=fffffa800b86b2f0
rip=fffff800032ed58f rsp=fffff88008403098 rbp=fffffa800b86b190
r8=fffffa800bd876b0 r9=fffff80003459e00 r10=0000000000000000
r11=0000000000000000 r12=fffff880084030d0 r13=fffffa800b86b2f0
r14=fffffa8005b36000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
nt!IoGetRelatedDeviceObject+0x5f:
fffff800`032ed58f 488b12 mov rdx,qword ptr [rdx] ds:002b:00650074`00610064=????????????????
Last set context:
rax=fffffa8003f7d030 rbx=0000000000000000 rcx=fffffa8003c75870
rdx=0065007400610064 rsi=0000000000000000 rdi=fffffa800b86b2f0
rip=fffff800032ed58f rsp=fffff88008403098 rbp=fffffa800b86b190
r8=fffffa800bd876b0 r9=fffff80003459e00 r10=0000000000000000
r11=0000000000000000 r12=fffff880084030d0 r13=fffffa800b86b2f0
r14=fffffa8005b36000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
nt!IoGetRelatedDeviceObject+0x5f:
fffff800`032ed58f 488b12 mov rdx,qword ptr [rdx] ds:002b:00650074`00610064=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B][COLOR=red] nis.exe[/COLOR][/B]
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003516100
GetUlongFromAddress: unable to read from fffff800035161c0
ffffffffffffffff
FOLLOWUP_IP:
Ntfs! ?? ::FNODOBFM::`string'+299d
fffff880`0121a211 cc int 3
FAULTING_IP:
nt!IoGetRelatedDeviceObject+5f
fffff800`032ed58f 488b12 mov rdx,qword ptr [rdx]
BUGCHECK_STR: 0x24
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800032ed58f
STACK_TEXT:
fffff880`08401e88 fffff880`0121a211 : 00000000`00000024 00000000`001904fb fffff880`08402e58 fffff880`084026b0 : nt!KeBugCheckEx
fffff880`08401e90 fffff880`0130b96b : fffff880`01268d48 fffff880`08403790 fffff880`08403790 00000000`00000001 : Ntfs! ?? ::FNODOBFM::`string'+0x299d
fffff880`08401ed0 fffff800`0330589c : fffff880`08401fc8 fffff880`08401fc8 fffffa80`0439ff68 fffffa80`03af47d0 : Ntfs! ?? ::NNGAKEGL::`string'+0x84a8
fffff880`08401f00 fffff800`0330531d : fffff880`01268d3c fffff880`08403790 00000000`00000000 fffff880`01216000 : nt!_C_specific_handler+0x8c
fffff880`08401f70 fffff800`033040f5 : fffff880`01268d3c fffff880`08401fe8 fffff880`08402e58 fffff880`01216000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`08401fa0 fffff800`03315081 : fffff880`08402e58 fffff880`084026b0 fffff880`00000000 fffffa80`0b86b2f0 : nt!RtlDispatchException+0x415
fffff880`08402680 fffff800`032d90c2 : fffff880`08402e58 00000000`00000000 fffff880`08402f00 00000000`00000000 : nt!KiDispatchException+0x135
fffff880`08402d20 fffff800`032d79ca : 00000000`00000000 00000000`00000000 fffffa80`08709350 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`08402f00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiGeneralProtectionFault+0x10a
STACK_COMMAND: kb
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs! ?? ::FNODOBFM::`string'+299d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 52e1be8a
IMAGE_VERSION: 6.1.7601.18378
FAILURE_BUCKET_ID: X64_0x24_Ntfs!_??_::FNODOBFM::_string_+299d
BUCKET_ID: X64_0x24_Ntfs!_??_::FNODOBFM::_string_+299d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x24_ntfs!_??_::fnodobfm::_string_+299d
FAILURE_ID_HASH: {2d01d825-ac05-cdc8-87bc-650cf3d30c26}
Followup: MachineOwner
---------