My driver carshed on win10 pro,I don’t know how to solve it
Notepad.exe load a txt file,win 10 crash.
fffff800`142d6728 41f7470400000002 test dword ptr [r15+4],2000000h
the object is null.
windbg info
!analyze -v
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800142d6728, Address of the instruction which caused the bugcheck
Arg3: ffffd001d4bf6980, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
DUMP_CLASS: 1
DUMP_QUALIFIER: 0
BUILD_VERSION_STRING: 10586.1176.amd64fre.th2_release_sec.170913-1848
DUMP_TYPE: 0
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff800142d6728
BUGCHECK_P3: ffffd001d4bf6980
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 -
FAULTING_IP:
NTFS!NtfsFilterCallbackAcquireForCreateSection+a8
fffff800142d6728 41f7470400000002 test dword ptr [r15+4],2000000h<br><br>CONTEXT: ffffd001d4bf6980 -- (.cxr 0xffffd001d4bf6980)<br>rax=0000000000000000 rbx=ffffcf80d3556d70 rcx=0000000100000001<br>rdx=0000000000000000 rsi=ffffd001d4bf7518 rdi=0000000000000000<br>rip=fffff800142d6728 rsp=ffffd001d4bf73a0 rbp=ffffd001d4bf73e0<br> r8=fffff800142d6680 r9=0000000000000000 r10=000000000000ffff<br>r11=ffffe001512a1500 r12=0000000000000000 r13=ffffe00151a03280<br>r14=ffffd001d4bf7500 r15=0000000000000000<br>iopl=0 nv up ei pl zr na po nc<br>cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246<br>NTFS!NtfsFilterCallbackAcquireForCreateSection+0xa8:<br>fffff800
142d6728 41f7470400000002 test dword ptr [r15+4],2000000h ds:002b:0000000000000004=????????<br>Resetting default scope<br><br>CPU_COUNT: 4<br><br>CPU_MHZ: bb8<br><br>CPU_VENDOR: GenuineIntel<br><br>CPU_FAMILY: 6<br><br>CPU_MODEL: 9e<br><br>CPU_STEPPING: 9<br><br>CPU_MICROCODE: 0,0,0,0 (F,M,S,R) SIG: 48'00000000 (cache) 0'00000000 (init)<br><br>DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT<br><br>BUGCHECK_STR: 0x3B<br><br>CURRENT_IRQL: 0<br><br>ANALYSIS_SESSION_HOST: ENMING-DESKTOP<br><br>ANALYSIS_SESSION_TIME: 10-28-2017 16:14:41.0527<br><br>ANALYSIS_VERSION: 10.0.16299.15 x86fre<br><br>LAST_CONTROL_TRANSFER: from fffff800f3d621a8 to fffff800142d6728<br><br>STACK_TEXT: <br>ffffd001
d4bf73a0 fffff800f3d621a8 : ffffd001
d4bf7518 ffffe00152986030 ffffd001
d4bf7518 0000000000000000 : NTFS!NtfsFilterCallbackAcquireForCreateSection+0xa8<br>ffffd001
d4bf7480 fffff800f412de02 : 00000000
00000001 ffffe00154e0fcc0 ffffe001
52320bf0 0000000000000001 : nt!FsFilterPerformCallbacks+0x138<br>ffffd001
d4bf74d0 fffff800f412daae : 00000000
00000001 ffffd001d4bf7920 00000000
00000000 fffff800f41170c5 : nt!FsRtlAcquireFileExclusiveCommon+0xf2<br>ffffd001
d4bf77b0 fffff800f412e7ed : 00000000
00000000 0000000000000000 00000000
00000000 00000000ffffffff : nt!FsRtlAcquireToCreateMappedSection+0x56<br>ffffd001
d4bf7820 fffff800f412e059 : ffffd001
d4bf7a60 0000000000000000 00000000
00000000 ffffd001d4bf7a58 : nt!MiCreateSection+0x56d<br>ffffd001
d4bf79f0 fffff800f3dc91a3 : ffffe001
512a1500 000000d74b8deae8 ffffd001
d4bf7aa8 0000000000000000 : nt!NtCreateSection+0x1c9<br>ffffd001
d4bf7a90 00007fff8dd75a14 : 00007fff
8a4bb08d 0000000000000002 00000104
00000010 000000d74b8deb51 : nt!KiSystemServiceCopyEnd+0x13<br>000000d7
4b8deac8 00007fff8a4bb08d : 00000000
00000002 0000010400000010 000000d7
4b8deb51 0000000000000000 : ntdll!NtCreateSection+0x14<br>000000d7
4b8dead0 00007fff8a4b9c70 : 00000000
00000003 0000000000000000 00000000
00000000 0000000000000000 : KERNELBASE!CreateFileMappingNumaW+0xed<br>000000d7
4b8deba0 00007ff724545dd6 : 00000000
00000001 000002630000002a 00000000
00000058 0000000000000000 : KERNELBASE!CreateFileMappingW+0x20<br>000000d7
4b8debf0 00007ff724542ed1 : 00000263
a91c0088 00000263a91c0088 00007ff7
24563520 00007fff8a5125a1 : NOTEPAD!LoadFile+0x336<br>000000d7
4b8df590 00007ff7245437cc : 00000000
00000000 0000000000000001 00000000
00000000 0000000000000000 : NOTEPAD!doDrop+0xb1<br>000000d7
4b8df5e0 00007fff8b4f1169 : 00000000
00000000 000000d74b8df829 00000000
00000001 0000000000000000 : NOTEPAD!NPWndProc+0x42c<br>000000d7
4b8df620 00007fff8b4f0c97 : 00000263
a7db96b0 00007ff7245433a0 00000000
0003046e 000000d74bbe8800 : USER32!UserCallWinProcCheckWow+0x1f9<br>000000d7
4b8df710 00007ff724543ba1 : 00000263
00000004 00000000001103b1 00007ff7
24540000 00000263a7741b6c : USER32!DispatchMessageWorker+0x1a7<br>000000d7
4b8df790 00007ff7245590b5 : 00000263
a7742a30 00000263a7742a32 00000000
00000000 00007ff724559490 : NOTEPAD!WinMain+0x269<br>000000d7
4b8df890 00007fff8b188102 : 00007ff7
24558ef0 000000d74bbe7000 000000d7
4bbe7000 0000000000000000 : NOTEPAD!WinMainCRTStartup+0x1c5<br>000000d7
4b8df950 00007fff8dd2c5b4 : 00007fff
8b1880e0 0000000000000000 00000000
00000000 0000000000000000 : KERNEL32!BaseThreadInitThunk+0x22<br>000000d7
4b8df980 0000000000000000 : 00000000
00000000 0000000000000000 00000000
00000000 0000000000000000 : ntdll!RtlUserThreadStart+0x34<br><br>THREAD_SHA1_HASH_MOD_FUNC: 0f20ec7de272744588b5d567f97d2aeb92d9f156<br><br>THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 8ff565dbf7fd4db3618f74a30c508963fea52612<br><br>THREAD_SHA1_HASH_MOD: 3801d63ce91bc0758d78b5f4d8cc03818909bab3<br><br>FOLLOWUP_IP: <br>NTFS!NtfsFilterCallbackAcquireForCreateSection+a8<br>fffff800
142d6728 41f7470400000002 test dword ptr [r15+4],2000000h
FAULT_INSTR_CODE: 447f741
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: NTFS!NtfsFilterCallbackAcquireForCreateSection+a8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NTFS
IMAGE_NAME: NTFS.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 59ba144e
IMAGE_VERSION: 10.0.10586.1176
STACK_COMMAND: .cxr 0xffffd001d4bf6980 ; kb
BUCKET_ID_FUNC_OFFSET: a8
FAILURE_BUCKET_ID: 0x3B_VRF_NTFS!NtfsFilterCallbackAcquireForCreateSection
BUCKET_ID: 0x3B_VRF_NTFS!NtfsFilterCallbackAcquireForCreateSection
PRIMARY_PROBLEM_CLASS: 0x3B_VRF_NTFS!NtfsFilterCallbackAcquireForCreateSection
TARGET_TIME: 2017-10-28T08:05:01.000Z
OSBUILD: 10586
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2017-09-14 13:39:31
BUILDDATESTAMP_STR: 170913-1848
BUILDLAB_STR: th2_release_sec
BUILDOSVER_STR: 10.0.10586.1176.amd64fre.th2_release_sec.170913-1848
ANALYSIS_SESSION_ELAPSED_TIME: 2703
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x3b_vrf_ntfs!ntfsfiltercallbackacquireforcreatesection
FAILURE_ID_HASH: {4617c119-a987-07fb-1f13-a1c651814fd4}
Followup: MachineOwner
NtfsFilterCallbackAcquireForCreateSection without any infomation in msdn. This driver runs normally on Windows 7