PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffff9c0419c94a38, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
[COLOR="#FF0000"]Arg3: fffff803f56b4eaf, If non-zero, the instruction address which referenced the bad memory
address.[/COLOR]
Arg4: 0000000000000002, (reserved)
..........
Could not read faulting driver name
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPagedPoolEnd
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSizeOfNonPagedPoolInBytes
......
[COLOR="#FF0000"]FAULTING_IP: NTFS!NtfsDeleteScb[/COLOR]+2f fffff803`f56b4eaf 483901 cmp qword ptr [rcx],rax
TRAP_FRAME: ffffc5005c762530 -- (.trap 0xffffc5005c762530)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff9c8419c94bd8 rbx=0000000000000000 rcx=ffff9c0419c94a38
rdx=ffff9c8419c94a38 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803f56b4eaf rsp=ffffc5005c7626c0 rbp=ffff9c8419c94a00
r8=ffffae85e09f8018 r9=0000000000000000 r10=ffff9c8419c94a00
r11=7ffffffffffffffc r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
[COLOR="#FF0000"]NTFS!NtfsDeleteScb[/COLOR]+0x2f:
fffff803`f56b4eaf 483901 cmp qword ptr [rcx],rax ds:ffff9c04`19c94a38=????????????????
....
STACK_TEXT:
ffffc500`5c762238 fffff801`3b214c56 : 00000000`00000050 ffff9c04`19c94a38 00000000`00000000 ffffc500`5c762530 : nt!KeBugCheckEx
ffffc500`5c762240 fffff801`3b1215da : 00000000`00000000 00000000`00000000 ffffc500`5c762530 ffffc36c`84977c00 : nt! ?? ::FNODOBFM::`string'+0x422b6
ffffc500`5c762330 fffff801`3b1ccafc : 9c840466`7fc00400 9c840466`7fc80400 9c840466`7fd00400 9c840466`7fd80400 : nt!MmAccessFault+0x9ca
ffffc500`5c762530 fffff803`f56b4eaf : 00000000`00000000 ffffae85`e0084d00 00000000`00000025 00000000`00000250 : nt!KiPageFault+0x13c
[COLOR="#FF0000"]ffffc500`5c7626c0 fffff803`f56b4daf : ffff9c84`00000000 ffff9c84`19c94a00 ffff9c84`19c94a00 ffff9c84`19c94b40 : NTFS!NtfsDeleteScb+0x2f[/COLOR]
[COLOR="#008000"]NTFS soll einen Eintrag löschen. Dabei wird der Pagefault-Fehler ausgelöst[/COLOR]
ffffc500`5c762750 fffff803`f56056f3 : ffff9c84`19c94a00 ffff9c84`19c94b40 ffff9c84`19c94b40 fffff801`3b2c6e17 : NTFS!NtfsRemoveScb+0x5f
ffffc500`5c7627a0 fffff803`f56b4b30 : ffff9c84`19c94a00 ffffc500`5c762a00 ffffae85`e0e7f018 00000000`00000001 : NTFS!NtfsPrepareFcbForRemoval+0x63
ffffc500`5c7627e0 fffff803`f561ede0 : ffffae85`e0e7f018 ffffc500`5c7628e3 ffff9c84`19c94ed8 ffff9c84`19c94a00 : NTFS!NtfsTeardownStructures+0x90
ffffc500`5c762860 fffff803`f56fe6cb : ffffc500`5c762a38 ffffc500`5c762a38 ffffc500`5c762a00 ffff9c84`19c94a00 : NTFS!NtfsDecrementCloseCounts+0xd0
ffffc500`5c7628a0 fffff803`f5708b8e : ffffae85`e0e7f018 ffff9c84`19c94b40 ffff9c84`19c94a00 ffffae85`d7e44180 : NTFS!NtfsCommonClose+0x40b
ffffc500`5c762970 fffff801`3b10ffd9 : fffff801`3b436100 ffffae85`dfcf4040 ffffae85`00000000 fffff801`3b436280 : NTFS!NtfsFspCloseInternal+0x1a2
ffffc500`5c762b00 fffff801`3b07b729 : d276a0c4`0aff6424 00000000`00000080 ffffae85`d7e956c0 ffffae85`dfcf4040 : nt!ExpWorkerThread+0xe9
ffffc500`5c762b90 fffff801`3b1c89d6 : ffffc500`58441180 ffffae85`dfcf4040 fffff801`3b07b6e8 b42c86b0`389d7718 : nt!PspSystemThreadStartup+0x41
ffffc500`5c762be0 00000000`00000000 : ffffc500`5c763000 ffffc500`5c75c000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
.......
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff8013b12b75e-fffff8013b12b75f 2 bytes - [COLOR="#FF0000"]nt!MmUnmapViewInSystemCache[/COLOR]+83e
[COLOR="#FF0000"][ 80 fa:00 90 ][/COLOR]
2 errors : !nt (fffff8013b12b75e-fffff8013b12b75f)
[COLOR="#008000"]Der MemoryManager soll auf den SystemCache zugreifen. Der Ausdruck in der [ ] zeigt den Fehler.
Der Wert vor dem ":" wird erwartet und der nach dem ":" wird vorgefunden.
Das deutet auf beschädigte Werte in der Pagefile.sys hin.[/COLOR]
.....
BUCKET_ID: MEMORY_CORRUPTION_LARGE
[COLOR="#FF0000"]FAILURE_ID_HASH_STRING: km:memory_corruption_large[/COLOR]