Windows 10: BSOD NTFS.sys MEMORY.dmp analysis included

Discus and support BSOD NTFS.sys MEMORY.dmp analysis included in Windows 10 BSOD Crashes and Debugging to solve the problem; I've been getting crashes seemingly at random. I've found no pattern yet. I've tried both dism /online /cleanup-image /restorehealth and chkdsk c: /f... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by MatthiasKunnen, Jul 28, 2020.

  1. BSOD NTFS.sys MEMORY.dmp analysis included


    I've been getting crashes seemingly at random. I've found no pattern yet.


    I've tried both dism /online /cleanup-image /restorehealth and chkdsk c: /f


    I've found no errors related to this in the event viewer.

    My system is a dual boot system and in Linux Ubuntu I have yet to see any crashes/problems.


    MEMORY.dmp analysis:



    Microsoft R Windows Debugger Version 10.0.20153.1000 AMD64Copyright c Microsoft Corporation. All rights reserved.Loading Dump File [C:\Windows\MEMORY.DMP]Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.Symbol search path is: srv*Executable search path is: Windows 10 Kernel Version 19041 MP 24 procs Free x64Product: WinNt, suite: TerminalServer SingleUserTSEdition build lab: 19041.1.amd64fre.vb_release.191206-1406Machine Name:Kernel base = 0xfffff807`66400000 PsLoadedModuleList = 0xfffff807`6702a310Debug session time: Tue Jul 28 22:08:32.252 2020 UTC + 2:00System Uptime: 1 days 0:31:32.886Loading Kernel Symbols............................................................................................................................................................................................Loading User SymbolsPEB is paged out Peb.Ldr = 00000007`52db9018. Type ".hh dbgerr001" for detailsLoading unloaded module list.........................For analysis of this file, run !analyze -vnt!KeBugCheckEx:fffff807`667ddb60 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff858b`b80c2e00=000000000000010915: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************CRITICAL_STRUCTURE_CORRUPTION 109This bugcheck is generated when the kernel detects that critical kernel code ordata have been corrupted. There are generally three causes for a corruption:1 A driver has inadvertently or deliberately modified critical kernel code or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx2 A developer attempted to set a normal kernel breakpoint using a kernel debugger that was not attached when the system was booted. Normal breakpoints, "bp", can only be set if the debugger is attached at boot time. Hardware breakpoints, "ba", can be set at any time.3 A hardware corruption occurred, e.g. failing RAM holding kernel code or data.Arguments:Arg1: a3a01be719e0658e, ReservedArg2: b3b7286d6c61e3ca, ReservedArg3: fffff80768a00000, Failure type dependent informationArg4: 000000000000002c, Type of corrupted region, can be 0 : A generic data region 1 : Modification of a function or .pdata 2 : A processor IDT 3 : A processor GDT 4 : Type 1 process list corruption 5 : Type 2 process list corruption 6 : Debug routine modification 7 : Critical MSR modification 8 : Object type 9 : A processor IVT a : Modification of a system service function b : A generic session data region c : Modification of a session function or .pdata d : Modification of an import table e : Modification of a session import table f : Ps Win32 callout modification 10 : Debug switch routine modification 11 : IRP allocator modification 12 : Driver call dispatcher modification 13 : IRP completion dispatcher modification 14 : IRP deallocator modification 15 : A processor control register 16 : Critical floating point control register modification 17 : Local APIC modification 18 : Kernel notification callout modification 19 : Loaded module list modification 1a : Type 3 process list corruption 1b : Type 4 process list corruption 1c : Driver object corruption 1d : Executive callback object modification 1e : Modification of module padding 1f : Modification of a protected process 20 : A generic data region 21 : A page hash mismatch 22 : A session page hash mismatch 23 : Load config directory modification 24 : Inverted function table modification 25 : Session configuration modification 26 : An extended processor control register 27 : Type 1 pool corruption 28 : Type 2 pool corruption 29 : Type 3 pool corruption 2a : Type 4 pool corruption 2b : Modification of a function or .pdata 2c : Image integrity corruption 2d : Processor misconfiguration 2e : Type 5 process list corruption 2f : Process shadow corruption 30 : Retpoline code page corruption 101 : General pool corruption 102 : Modification of win32k.sysDebugging Details:------------------Unable to load image \SystemRoot\System32\Drivers\Ntfs.sys, Win32 error 0n2*** WARNING: Unable to verify timestamp for Ntfs.sysKEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 2625 Key : Analysis.DebugAnalysisProvider.CPP Value: Create: 8007007e on MATTHIAS-DESKTO Key : Analysis.DebugData Value: CreateObject Key : Analysis.DebugModel Value: CreateObject Key : Analysis.Elapsed.mSec Value: 3353 Key : Analysis.Memory.CommitPeak.Mb Value: 89 Key : Analysis.System Value: CreateObject Key : WER.OS.Branch Value: vb_release Key : WER.OS.Timestamp Value: 2019-12-06T14:06:00Z Key : WER.OS.Version Value: 10.0.19041.1ADDITIONAL_XML: 1OS_BUILD_LAYERS: 1BUGCHECK_CODE: 109BUGCHECK_P1: a3a01be719e0658eBUGCHECK_P2: b3b7286d6c61e3caBUGCHECK_P3: fffff80768a00000BUGCHECK_P4: 2cBLACKBOXBSD: 1 !blackboxbsdBLACKBOXNTFS: 1 !blackboxntfsBLACKBOXPNP: 1 !blackboxpnpBLACKBOXWINLOGON: 1PROCESS_NAME: csrss.exeSTACK_TEXT: ffff858b`b80c2df8 00000000`00000000 : 00000000`00000109 a3a01be7`19e0658e b3b7286d`6c61e3ca fffff807`68a00000 : nt!KeBugCheckExMODULE_NAME: NtfsIMAGE_NAME: Ntfs.sysSTACK_COMMAND: .thread ; .cxr ; kbFAILURE_BUCKET_ID: 0x109_2c_IMAGE_Ntfs.sysOS_VERSION: 10.0.19041.1BUILDLAB_STR: vb_releaseOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {1ac1cef4-57d0-75db-be0a-7f8b6ff55cb8}Followup: MachineOwner---------

    Boot drive status NVME drive


    C:\Program Files\smartmontools\bin>smartctl.exe -A /dev/sdf -H
    smartctl 7.1 2019-12-30 r5022 [x86_64-w64-mingw32-w10-b19041] sf-7.1-1
    Copyright C 2002-19, Bruce Allen, Christian Franke, www.smartmontools.org

    === START OF SMART DATA SECTION ===
    SMART overall-health self-assessment test result: PASSED

    SMART/Health Information NVMe Log 0x02
    Critical Warning: 0x00
    Temperature: 68 Celsius
    Available Spare: 100%
    Available Spare Threshold: 10%
    Percentage Used: 1%
    Data Units Read: 10 605 657 [5.43 TB]
    Data Units Written: 55 245 869 [28.2 TB]
    Host Read Commands: 375 597 942
    Host Write Commands: 344 010 063
    Controller Busy Time: 1 593
    Power Cycles: 635
    Power On Hours: 1 662
    Unsafe Shutdowns: 49
    Media and Data Integrity Errors: 0
    Error Information Log Entries: 802
    Warning Comp. Temperature Time: 0
    Critical Comp. Temperature Time: 0
    Temperature Sensor 1: 68 Celsius
    Temperature Sensor 2: 76 Celsius

    :)
     
    MatthiasKunnen, Jul 28, 2020
    #1

  2. Bsod with Vista64

    Well i finally found a site where it tells the average computer user , step by step how to open a minidump through windbg . I was shocked to see the first one had at the Image name Ntfs.sys can this really be making problems?, the second was with video driver and the third is with tcpip.sys *Frown BSOD NTFS.sys MEMORY.dmp analysis included :( .
     
    Patrauleac, Jul 28, 2020
    #2
  3. BSOD - ntfs.sys

    Is anyone able to review
    this
    dmp file to get further information about the cause? BSOD happening every 5 minutes and reporting error in ntfs.sys. Started happening after installation of Sophos Safeguard but 100's of other machines using same OS image / SSCM deployment of Sophos
    with no issues.
     
    Richard S_1234, Jul 28, 2020
    #3
  4. BSOD NTFS.sys MEMORY.dmp analysis included

    BSOD crash with : kmode_Exception_not_handled (Ntfs.sys) , systemthread_Exception_not_handled (Ntfs.sys), systemthread_Exception_not_handled (with no reason)

    Paste 2 months I have had around 8 BSOD crashes.

    I have a Dell Inspiron 3670 (12th Dec)

    After kmode_Exception_not_handled (Ntfs.sys) , systemthread_Exception_not_handled (Ntfs.sys):

    I have run chkdsk scan, memory diagnostic scan, updated my drivers, cannot uninstall software (as started since the pc was bought), run Dell support software, no certain program (or acting) used while crashing and have had different anti-viruses used during
    the crashes.

    After these, I got the crash stop code "systemthread_Exception_not_handled" but without it mentioning Ntfs.sys

    This is the link to latest dump file: Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.

    Any help or advice would be much appreciated.
     
    Gwon Yueng, Jul 28, 2020
    #4
Thema:

BSOD NTFS.sys MEMORY.dmp analysis included

Loading...
  1. BSOD NTFS.sys MEMORY.dmp analysis included - Similar Threads - BSOD NTFS sys

  2. BSOD - memory dump analysis

    in Windows 10 BSOD Crashes and Debugging
    BSOD - memory dump analysis: I've been getting BSOD, for a few times now in the last few months. The debugging showed same issue every time. Can someone help me figure out the exact root cause of the issue ?Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.Sec Value: 3 Key :...
  3. BSOD - memory dump analysis

    in Windows 10 Gaming
    BSOD - memory dump analysis: I've been getting BSOD, for a few times now in the last few months. The debugging showed same issue every time. Can someone help me figure out the exact root cause of the issue ?Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.Sec Value: 3 Key :...
  4. BSOD - memory dump analysis

    in Windows 10 Software and Apps
    BSOD - memory dump analysis: I've been getting BSOD, for a few times now in the last few months. The debugging showed same issue every time. Can someone help me figure out the exact root cause of the issue ?Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.Sec Value: 3 Key :...
  5. IRQL_not_less_or_equal dmp analysis

    in Windows 10 BSOD Crashes and Debugging
    IRQL_not_less_or_equal dmp analysis: Hello, here are all the minidump files that I've retrieved from the past week on the frequent BSODs my PC has been experiencing. Would appreciate any analysis/solution on these problems. Thanks!https://www.dropbox.com/sh/fbkv5pt5q8tlvvz/AACxCmNIkSnFnamst6AWKtc_a?dl=0...
  6. BSOD Help DMP included

    in Windows 10 BSOD Crashes and Debugging
    BSOD Help DMP included: So I have this dmp file of my recent crash I was wondering if anyone could help me figure out what may be the problem?Intel i7-7700HQ cpu @2.80GHz16GB RAMNVIDIA GEFORCE GTX1070https://1drv.ms/u/s!AkYymB8ktKw9gwek17l-5rmT8e87?e=gh5NCt...
  7. BSOD dmp. file analysis

    in Windows 10 BSOD Crashes and Debugging
    BSOD dmp. file analysis: Hello world, I've had overwhelming number of bsods in the last year. But today it has cost me time and money, so I decided to ask you, tech saavys, to help me analyse the dmp file from the BSOD. Thank you for help Here it is: Microsoft R Windows Debugger Version...
  8. DMP file analysis

    in Windows 10 BSOD Crashes and Debugging
    DMP file analysis: Hey, I have been getting BSOD with the error code video memory management. Could you please help me analyze the dmp files and tell me what is wrong? https://1drv.ms/u/s!At-WwvuKYLHrpFfT3__1b47fSHZ-?e=qBk8en Thank you!...
  9. BSOD issues - Looking for help and DMP analysis

    in Windows 10 BSOD Crashes and Debugging
    BSOD issues - Looking for help and DMP analysis: Issues usually occur after playing video games, any of them, for a few hours, immediately restarting the PC and the game after BSOD typically results in another BSOD, but waiting a while, such as overnight, tends to allow me to play for an hour or two again before BSOD occurs...
  10. Looking for dmp analysis.

    in Windows 10 BSOD Crashes and Debugging
    Looking for dmp analysis.: Hi Guys Continuing to have problems with bsods, they are becoming far more frequent as well. I uploaded some dmp files last week, analysis showed that it was a particular driver causing the issue which has since been uninstalled. However I have crashed three times so far...