Full Diagnostic Tree & Step-by-Step Overview
What specific error detail or driver file name is displayed on the blue screen during the boot loop?
- BSOD explicitly specifies a display driver module (e.g., nvlddmkm.sys, amdkmdag.sys, or igdkmd64.sys).
- BSOD specifies a network or Wi-Fi driver module (e.g., Netwtw10.sys, rt640x64.sys, or e2f68.sys).
- BSOD specifies an antivirus, security filter, or anti-cheat file (e.g., epfw.sys, vgk.sys, or EasyAntiCheat_KM.sys).
- BSOD shows NO driver filename (shows only SYSTEM_THREAD_EXCEPTION_NOT_HANDLED or 0x0000007E).
Display Driver Kernel Crash (0x7E). How far into the boot sequence does the crash occur?
- Crash occurs during Windows loading dots animation before reaching the user logon screen.
- Windows boots into Safe Mode normally, but crashes instantly when attempting standard normal boot.
- Crash occurs after installing a recent Windows Update or automated GPU driver update.
- Crash started immediately after enabling PCIe Resizable BAR (ReBAR) or modifying GPU hardware states.
Graphics Driver Ring-0 Exception (`nvlddmkm.sys` / `amdkmdag.sys` Boot Lock)
Solution:
Root Cause: Kernel Mode Unhandled Exception in Graphics Subsystem Driver
The SYSTEM_THREAD_EXCEPTION_NOT_HANDLED bug check (Stop Code 0x0000007E or 0xC0000005 STATUS_ACCESS_VIOLATION) occurs when a system thread created by a kernel-mode driver generates an exception that the error handler fails to catch. When the faulting driver is a graphics binary (nvlddmkm.sys for NVIDIA, amdkmdag.sys for AMD, or igdkmd64.sys for Intel), the display driver attempts an illegal memory access or issues an invalid opcode during early Direct3D hardware-acceleration initialization (dxgkrnl.sys). Because this occurs during early kernel initialization, Windows enters an endless boot loop.
# Diagnostic Verification:
1. Boot the PC into Windows Recovery Environment (WinRE) (Force power-off twice during boot animation).
2. Navigate to Troubleshoot > Advanced options > Command Prompt.
3. Determine your Windows drive letter (e.g., D: or C:):
dir C:
dir D:
4. Inspect recent crash dump details using the Windows DISM log or parsing SrtTrail:
type D:\Windows\System32\LogFiles\Srt\SrtTrail.txt
5. Search for entries naming nvlddmkm.sys, amdkmdag.sys, or dxgkrnl.sys.
# Step-by-Step Fix:
1. Disable the Faulting Driver via Offline Registry Hive in WinRE:
Open Command Prompt in WinRE.Load the offline SYSTEM registry hive: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Navigate to the active ControlSet service entries (typically ControlSet001): reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\nvlddmkm" /v Start /t REG_DWORD /d 4 /f
*(Use amdkmdag for AMD GPUs or igfx for Intel GPUs)*
Unload the offline registry hive: reg unload HKLM\OFFLINE_SYS
Close Command Prompt and click Continue to Windows 11/10.2. Boot into Safe Mode to Perform Clean Driver Removal:
Once Windows boots past the boot loop using basic display fallback, press Win + R, type msconfig -> Boot tab -> check Safe boot (Minimal) -> restart.In Safe Mode, run Display Driver Uninstaller (DDU) to completely purge corrupted GPU driver files and registry keys.3. Reinstall Fresh WHQL Display Drivers:
Boot back into normal mode and download the official WHQL display driver package directly from NVIDIA or AMD.# Prevention & Long-Term Monitoring:
Disable automatic driver updates via Windows Update for GPU hardware using Group Policy or device installation settings.
D3D / Hardware Acceleration Hook Failure in Safe Mode vs Normal Boot
Solution:
Root Cause: Secondary Driver Filter Hook Desynchronization
When a system successfully boots into Safe Mode but repeatedly crashes with SYSTEM_THREAD_EXCEPTION_NOT_HANDLED during normal boot, the core operating system kernel is intact. The crash is triggered when normal boot loads secondary filter drivers (such as GPU tuning utilities, frame overlays, or virtual display drivers) that register high-priority callbacks. When dxgkrnl.sys initializes, these filter hooks attempt to query unallocated memory addresses, causing an unhandled system thread exception.
# Diagnostic Verification:
1. Boot into Safe Mode (WinRE > Startup Settings > Enable Safe Mode).
2. Press Win + R, type eventvwr.msc, and hit Enter.
3. Navigate to Windows Logs > System.
4. Filter for Error events with Source BugCheck (Event ID 1001) to identify associated secondary binaries.
# Step-by-Step Fix:
1. Clean Boot Configuration in Safe Mode:
In Safe Mode, press Win + R, type msconfig, hit Enter.On the General tab, select Selective startup and uncheck Load startup items.Switch to the Services tab, check Hide all Microsoft services, and click Disable all.2. Disable Non-Essential Display Filter Drivers:
Launch regedit in Safe Mode and navigate to: HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}
Inspect UpperFilters and LowerFilters. Remove third-party entries (such as mup, nvppbr, or custom remote desktop mirror drivers) leaving only standard Windows drivers.3. Restart System Normally:
Reboot the PC to confirm successful normal boot.# Prevention & Long-Term Monitoring:
Avoid installing multiple third-party GPU overclocking or display capture utilities simultaneously.
Corrupted Windows Update Driver Package Staging
Solution:
Root Cause: Incomplete Servicing Stack Package Staging
When Windows Update delivers an incomplete or corrupted driver package, the driver binary is staged in C:\Windows\System32\DriverStore\FileRepository. During early boot execution, the Plug and Play (PnP) manager attempts to bind the newly staged driver to the hardware object. If the package manifest is incomplete, the driver initialization routine throws an unhandled exception, causing an infinite boot loop.
# Diagnostic Verification:
1. Boot into WinRE Command Prompt.
2. Identify your Windows partition drive letter (D:).
3. Query installed third-party drivers in the offline driver store:
dism /Image:D:\ /Get-Drivers
4. Identify driver packages with recent installation dates matching your GPU or display adapter.
# Step-by-Step Fix:
1. Enumerate and Identify Published Driver Names in WinRE:
Run DISM driver query in WinRE Command Prompt: dism /Image:D:\ /Get-Drivers /Format:Table
Locate the Published Name (e.g., oem12.inf, oem25.inf) corresponding to the problematic graphics driver.2. Remove Corrupted Driver Package Offline:
Execute the DISM driver removal command: dism /Image:D:\ /Remove-Driver /Driver:oem12.inf
3. Clear Windows Update Staging Cache:
Delete pending update transactions: del /f /q D:\Windows\SoftwareDistribution\Download\*.*
del /f /q D:\Windows\System32\config\txr\*.*
4. Reboot System:
Exit Command Prompt and click Continue.# Prevention & Long-Term Monitoring:
Always download display drivers directly from official hardware vendor portals rather than relying on Windows Update routine patches.
PCIe Resizable BAR / Base Address Register Allocation Crash
Solution:
Root Cause: PCIe Base Address Register (BAR) Memory Mapping Allocation Failure
Enabling Resizable BAR (ReBAR) in BIOS allows the CPU to access the entire GPU VRAM frame buffer at once. However, if the operating system kernel is installed under legacy CSM/MBR partition schemes, or if the graphics driver fails to parse 64-bit BAR address space during early boot, the memory manager allocates overlapping memory addresses. When dxgkrnl.sys executes its first DMA request, a hardware memory access exception is raised at IRQL 2, crashing the system before display output initializes.
# Diagnostic Verification:
1. Confirm whether ReBAR / Above 4G Decoding was recently enabled in BIOS.
2. If system crashes immediately after motherboard logo screen, PCIe BAR mapping collision is present.
# Step-by-Step Fix:
1. Disable ReBAR / Above 4G Decoding in System BIOS:
Power on PC and enter BIOS setup (F2 or Delete).Navigate to Advanced > PCIe Subsystem Settings.Set Above 4G Decoding and Re-Size BAR Support to Disabled.Save settings (F10) and restart.2. Verify UEFI Partition Scheme in Windows:
Once booted into Windows, verify system partition layout using Disk Management or PowerShell: Get-Disk | Select-Object Number, PartitionStyle
If PartitionStyle is MBR, ReBAR cannot be used safely.3. Convert MBR to GPT for Native UEFI Compatibility (If ReBAR is required):
Convert disk without data loss using administrative Command Prompt: mbr2gpt /validate /allowFullOS
mbr2gpt /convert /allowFullOS
Re-enter BIOS, switch boot mode to Pure UEFI (CSM Disabled), and re-enable ReBAR.# Prevention & Long-Term Monitoring:
Ensure CSM (Compatibility Support Module) is strictly disabled in BIOS before enabling Resizable BAR.
Network / Wi-Fi Driver Crash (0x7E). What specific network hardware or environment is involved?
- BSOD specifies Intel Wi-Fi driver (Netwtw10.sys or Netwtw08.sys) during boot.
- BSOD specifies Realtek LAN driver (rt640x64.sys) or Killer Networking driver.
- Crash occurs after connecting to a new Wi-Fi 6E/7 network or dynamic IP handoff.
- Virtual network adapter (VPN TAP/TUN driver or Hyper-V virtual switch) crashing during boot.
Intel Wireless Driver (`Netwtw10.sys`) Offline Neutralization
Solution:
Root Cause: Intel Wireless Stack Driver Interrupt Exception
During early system boot, the Network Driver Interface Specification (NDIS.sys) initializes wireless network adapters. If the Intel Wi-Fi driver (Netwtw10.sys) encounters corrupted registry state in HKLM\SYSTEM\CurrentControlSet\Services\Netwtw10 or an invalid dynamic memory pointer during firmware handshake, an unhandled exception occurs on the NDIS system thread, triggering Stop Code 0x0000007E.
# Diagnostic Verification:
1. WinRE Command Prompt or crash screen explicitly names Netwtw10.sys or Netwtw08.sys.
# Step-by-Step Fix:
1. Disable Wireless Adapter Driver Service via Offline Registry in WinRE:
Open WinRE Command Prompt.Load offline SYSTEM hive: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Disable Intel Wi-Fi service start type: reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\Netwtw10" /v Start /t REG_DWORD /d 4 /f
Unload hive: reg unload HKLM\OFFLINE_SYS
2. Boot into Windows and Clean Install Official Wi-Fi Drivers:
Restart the PC (Windows will boot into desktop without initializing the Wi-Fi card).Open Device Manager > expand Network adapters.Right-click Intel Wi-Fi 6/6E/7 Controller > Uninstall device > check Attempt to remove the driver for this device.3. Install Updated Intel Driver Suite:
Install official driver package downloaded directly from Intel or motherboard manufacturer.# Prevention & Long-Term Monitoring:
Keep wireless drivers updated directly from chip manufacturer portals.
Realtek / Killer LAN Intermediate Filter Driver Hook Exception
Solution:
Root Cause: Third-Party Network Prioritization Filter Driver Collision
OEM network utility suites (such as Killer Control Center or ASUS ROG GameFirst) install intermediate NDIS filter drivers (e.g., KNetKb.sys or rt640x64.sys) between the network card and the Windows network stack. If these filter drivers fail to parse network buffer descriptors during early boot service start, an exception is thrown in the NDIS system thread.
# Diagnostic Verification:
1. Crash minidump cites rt640x64.sys, KNetKb.sys, or NDIS.sys.
# Step-by-Step Fix:
1. Disable Network Filter Service via WinRE Registry:
Open WinRE Command Prompt.Load offline registry hive: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Disable Killer/Realtek filter drivers: reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\KNetKb" /v Start /t REG_DWORD /d 4 /f
reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\rt640x64" /v Start /t REG_DWORD /d 4 /f
Unload hive: reg unload HKLM\OFFLINE_SYS2. Boot Windows and Uninstall Network Prioritization Software:
Restart into Windows desktop.Open Settings > Apps > Installed apps > uninstall Killer Control Center or GameFirst.3. Install Bare WHQL Driver Only:
Install driver-only INF files without accompanying OEM utility software.# Prevention & Long-Term Monitoring:
Avoid installing OEM network optimization software suites; native Windows NDIS queuing handles throughput efficiently.
Wi-Fi 6E/7 Fast Roaming & WPA3 Authentication State Lock
Solution:
Root Cause: WPA3 / 6GHz Frequency Handshake Exception in Wireless Stack
When connecting to high-speed Wi-Fi 6E or Wi-Fi 7 access points utilizing WPA3 SAE encryption, the wireless driver saves profile state to %ProgramData%\Microsoft\WlanSvc. If this state file becomes corrupted during an improper shutdown, the driver thread fails to parse the cached WPA3 security key on boot, causing an unhandled pointer exception inside wlansec.dll / Netwtw10.sys.
# Diagnostic Verification:
1. System crashes only when booting within range of a specific Wi-Fi network.
# Step-by-Step Fix:
1. Clear Cached Wireless Profiles via WinRE Command Prompt:
Boot into WinRE Command Prompt.Navigate to the WLAN service directory: del /f /q D:\ProgramData\Microsoft\WlanSvc\Profiles\Interfaces\*.*
2. Reset Windows Networking Stack Offline:
Rename network configuration hives to force rebuild: ren D:\Windows\System32\config\netlogon netlogon.old
3. Reboot and Re-connect to Wi-Fi:
Boot into Windows normally, select your Wi-Fi network, and re-enter network credentials.# Prevention & Long-Term Monitoring:
Ensure router firmware and client Wi-Fi drivers are kept updated to maintain matching WPA3 SAE standards.
Virtual VPN / Hyper-V Virtual Switch Bridge Driver Crash
Solution:
Root Cause: Virtual Network Adapter Protocol Bridge Deadlock
Virtual network adapters created by Hyper-V Virtual Switches, Docker, or VPN tools (e.g., OpenVPN TAP-Windows, WireGuard, or Citrix Virtual Adapter) register kernel-mode virtual network interfaces (vmswitch.sys or tap0901.sys). During boot, if the virtual interface fails to bind to its assigned physical NIC bridge, the virtual switch driver throws an unhandled exception.
# Diagnostic Verification:
1. Minidump specifies vmswitch.sys, tap0901.sys, or wireguard.sys.
# Step-by-Step Fix:
1. Disable Virtual Network Adapter Services in WinRE:
Open WinRE Command Prompt and load offline registry: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Disable Hyper-V Virtual Switch and TAP drivers: reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\vmswitch" /v Start /t REG_DWORD /d 4 /f
reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\tap0901" /v Start /t REG_DWORD /d 4 /f
Unload hive: reg unload HKLM\OFFLINE_SYS2. Re-bind Virtual Networks in Windows:
Boot into Windows, open Hyper-V Manager or your VPN client, and delete/recreate the virtual switch or adapter interface.# Prevention & Long-Term Monitoring:
Remove obsolete VPN or virtualization virtual adapters before installing major Windows updates.
Security / Antivirus Filter Crash (0x7E). What security driver or software was installed?
- Third-party Antivirus driver (e.g., epfw.sys, bdntwrk.sys, or avgbkup.sys) named in crash log.
- Kernel Anti-Cheat driver (e.g., vgk.sys, EasyAntiCheat_KM.sys, or BEDaisy.sys) named in crash log.
- Windows Defender Core Isolation / HVCI (Hypervisor-Protected Code Integrity) conflict.
- Full Disk Encryption driver (e.g., BitLocker filter or VeraCrypt driver) failing validation.
Third-Party Antivirus Kernel Filter Driver (`epfw.sys` / `bdntwrk.sys`) Offline Removal
Solution:
Root Cause: Kernel Security Filter Driver Memory Access Violation
Third-party antivirus applications (e.g., ESET, Bitdefender, Avast) install early-launch kernel-mode filter drivers that intercept file system and network operations. If an operating system update modifies internal kernel structures before the antivirus vendor updates their filter driver hooks, the filter driver executes an invalid memory access during boot, generating SYSTEM_THREAD_EXCEPTION_NOT_HANDLED.
# Diagnostic Verification:
1. WinRE Command Prompt or BlueScreen log names antivirus drivers such as epfw.sys, bdntwrk.sys, or tmcomm.sys.
# Step-by-Step Fix:
1. Disable Antivirus Driver Services via WinRE Command Prompt:
Boot into WinRE Command Prompt and load offline registry: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Locate and disable the specific antivirus service (e.g., ESET epfw): reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\epfw" /v Start /t REG_DWORD /d 4 /f
reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\ehttpsrv" /v Start /t REG_DWORD /d 4 /f
Unload hive: reg unload HKLM\OFFLINE_SYS2. Boot into Windows and Completely Uninstall Antivirus Software:
Reboot into Windows desktop.Download and run the official vendor uninstall cleanup tool (e.g., ESET Uninstaller, Bitdefender Uninstall Tool) to remove remaining driver hooks.3. Re-enable Windows Defender Security:
Ensure native Windows Defender Antivirus initializes cleanly.# Prevention & Long-Term Monitoring:
Rely on native Windows Defender or ensure third-party security software is fully updated prior to applying major Windows feature upgrades.
Kernel Anti-Cheat Driver Hook Exception (`vgk.sys` / `EasyAntiCheat_KM.sys`)
Solution:
Root Cause: Ring-0 Anti-Cheat Service Initialization Deadlock
Kernel-level anti-cheat engines (such as Riot Vanguard vgk.sys, Easy Anti-Cheat EasyAntiCheat_KM.sys, or BattEye BEDaisy.sys) execute at Ring 0 during boot to ensure system integrity. If these drivers encounter unauthorized memory hooks, outdated system microcode, or conflicts with debugging utilities, the anti-cheat driver deliberately issues an unhandled kernel exception to block system startup.
# Diagnostic Verification:
1. Minidump or BSOD error screen names vgk.sys, EasyAntiCheat_KM.sys, or BEDaisy.sys.
# Step-by-Step Fix:
1. Disable Anti-Cheat Service in WinRE:
Open WinRE Command Prompt.Load offline registry: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Disable the anti-cheat driver service: reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\vgk" /v Start /t REG_DWORD /d 4 /f
reg add "HKLM\OFFLINE_SYS\ControlSet001\Services\EasyAntiCheat_KM" /v Start /t REG_DWORD /d 4 /f
Unload hive: reg unload HKLM\OFFLINE_SYS2. Uninstall and Reinstall Anti-Cheat Engine in Windows:
Boot into Windows normally.Go to Settings > Apps > Installed apps > uninstall Riot Vanguard or the specific game launcher.Relaunch the game client (e.g., Valorant or Fortnite) to trigger a fresh download and installation of the signed anti-cheat driver.# Prevention & Long-Term Monitoring:
Ensure TPM 2.0 and Secure Boot are properly enabled in BIOS, as modern kernel anti-cheat engines require these security features.
HVCI / Memory Integrity Incompatible Driver Execution Trap
Solution:
Root Cause: Hypervisor-Protected Code Integrity (HVCI) Unsigned Driver Block
Hypervisor-Protected Code Integrity (HVCI / Memory Integrity) uses hardware virtualization to prevent malicious code from injecting into high-security kernel pools. If an older driver lacking valid HVCI code signing certificates attempts to execute inside the kernel space during boot, the hypervisor intercepts the driver thread and issues a 0x7E exception.
# Diagnostic Verification:
1. System crashes during boot after enabling Memory Integrity / Core Isolation in Windows Security.
# Step-by-Step Fix:
1. Disable HVCI via Offline Registry in WinRE:
Open WinRE Command Prompt.Load offline SYSTEM hive: reg load HKLM\OFFLINE_SYS D:\Windows\System32\config\SYSTEM
Turn off Hypervisor Code Integrity: reg add "HKLM\OFFLINE_SYS\ControlSet001\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v Enabled /t REG_DWORD /d 0 /f
Unload hive: reg unload HKLM\OFFLINE_SYS2. Boot Windows and Identify Incompatible Drivers:
Reboot into Windows.Open Windows Security > Device security > Core isolation details.Check for listed incompatible drivers and update or remove them.# Prevention & Long-Term Monitoring:
Only use modern, WHQL-certified drivers verified for Windows 11 HVCI compliance.
Full Disk Encryption (VeraCrypt / BitLocker) Filter Driver Invalidation
Solution:
Root Cause: Encryption Volume Filter Driver (veracrypt.sys / rdbss.sys) Decryption Fault
Full disk encryption software uses low-level volume filter drivers to decrypt storage blocks in real-time. If the encryption volume headers or filter driver binaries (veracrypt.sys) are modified or disrupted by an incomplete OS update, the driver fails to decrypt required system executables during boot, leading to a system thread access violation.
# Diagnostic Verification:
1. Crash occurs immediately after entering the disk encryption password at boot loader prompt.
# Step-by-Step Fix:
1. Boot using Official Encryption Recovery Media:
Boot from a prepared VeraCrypt / Rescue Disk or BitLocker Recovery Environment.2. Decrypt OS Volume or Restore Backup Volume Header:
In VeraCrypt Rescue Disk menu, select Restore volume header or Permanently decrypt system partition.For BitLocker, enter your 48-digit BitLocker Recovery Key in WinRE.3. Repair Windows Boot Configuration:
Once decrypted, open Command Prompt in WinRE and repair boot files: bcdboot D:\Windows /s C: /f ALL
# Prevention & Long-Term Monitoring:
Always retain a backup copy of disk encryption recovery keys and rescue disks in a secure external location.
No Driver Filename Specified (0x7E / 0xC0000005). What system recovery or file condition is present?
- System File Store (CBS/WinSxS) or system registry hives (`SOFTWARE`/`SYSTEM`) are corrupted.
- Boot Configuration Data (BCD) or Master Boot Record / EFI boot files are corrupted.
- Physical RAM memory modules or CPU cache experiencing bit-flips (Memory hardware fault).
- System partition is out of free storage space (0 bytes free on Drive C:).
Corrupted Component Store & Registry Hive Corruption (Offline SFC / DISM)
Solution:
Root Cause: Core Operating System Binary and Servicing Store Degradation
When SYSTEM_THREAD_EXCEPTION_NOT_HANDLED occurs without naming a specific driver file, the crash is caused by core Windows kernel DLLs (ntoskrnl.exe, hal.dll, or pshed.dll) encountering corrupted instructions inside the Component Store (WinSxS). This structural corruption typically stems from improper power cutoffs during active updates.
# Diagnostic Verification:
1. Open WinRE Command Prompt.
2. Check file system integrity using SFC:
sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows
3. Output reports corrupted files that could not be repaired offline.
# Step-by-Step Fix:
1. Execute Offline DISM Servicing Repair in WinRE:
Open WinRE Command Prompt.Run DISM targeting the offline Windows installation: dism /Image:D:\Windows /Cleanup-Image /RestoreHealth
If source files are missing, mount a Windows installation ISO (e.g., drive E:) and point to install.wim: dism /Image:D:\Windows /Cleanup-Image /RestoreHealth /Source:wim:E:\sources\install.wim:1 /LimitAccess
2. Re-run Offline SFC Scan:
Execute: sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows
3. Restore Clean Registry Hives from RegBack (If Registry is Corrupted):
Check if clean registry backups exist: copy D:\Windows\System32\config\RegBack\SYSTEM D:\Windows\System32\config\SYSTEM
4. Reboot System:
Exit Command Prompt and restart normal boot.# Prevention & Long-Term Monitoring:
Run sfc /scannow and dism /Online /Cleanup-Image /RestoreHealth periodically after resolving improper system shutdowns.
Corrupted Boot Configuration Data (BCD) & EFI Boot Loader Rebuild
Solution:
Root Cause: Boot Configuration Data (BCD) Pointer Invalidation
If the Boot Configuration Data (BCD) store contains invalid kernel execution flags (such as corrupted noexecute, pae, or safeboot settings), the Windows Boot Manager (bootmgr) passes invalid memory execution parameters to winload.efi. As soon as kernel threads initialize, an exception is thrown before driver logging begins.
# Diagnostic Verification:
1. Open WinRE Command Prompt.
2. Query BCD store configuration:
bcdedit /enum
3. If command returns *The boot configuration data store could not be opened*, BCD corruption is present.
# Step-by-Step Fix:
1. Mount Hidden EFI System Partition in WinRE:
Open Command Prompt in WinRE and launch Diskpart: diskpart
list volume
Locate the FAT32 EFI partition (typically 100MB-500MB) -> select it: select volume 2 *(replace with your EFI volume number)*
assign letter=S:
exit
2. Rebuild BCD and EFI Boot Files:
Navigate to the EFI partition structure: cd /d S:\EFI\Microsoft\Boot\
Rename corrupted BCD file: ren BCD BCD.bak
Re-create clean EFI boot files targeting your Windows installation (D:\Windows): bcdboot D:\Windows /s S: /f UEFI
3. Re-scan and Re-add Windows Installations:
Execute: bootrec /rebuildbcd
4. Reboot System (shutdown /r /t 0).
# Prevention & Long-Term Monitoring:
Avoid using third-party bootloader editing tools on UEFI system configurations.
Physical RAM Module / Hardware Memory Bit-Flip Violation
Solution:
Root Cause: Hardware-Level Transistor Bit Flip in Physical Memory
When
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED occurs at completely random boot stages with varying memory addresses, physical RAM hardware failure is the primary cause. Defective memory cells fail to retain charge, resulting in bit flips when the kernel loads system structures into RAM.
# Diagnostic Verification:
1. Download
MemTest86 and flash it to a USB drive using another computer.
2. Boot the affected PC from the MemTest86 USB drive.
3. Allow the test to execute.
4. If red error lines appear during Pass 1, physical DRAM hardware failure is confirmed.
# Step-by-Step Fix:
1. Isolate Defective RAM Module:
Power off PC, disconnect power, and remove all RAM modules except one stick in slot A2.Re-run MemTest86 on individual sticks one by one.2. Replace Defective Memory Stick:
Identify the failing module that produces errors in MemTest86 and replace it under manufacturer warranty.3. Reset BIOS Memory Settings:
Enter BIOS, load Optimized Defaults, and run memory at stock JEDEC speeds to verify stability.# Prevention & Long-Term Monitoring:
Run a full 4-pass MemTest86 validation test whenever assembling new PCs or upgrading memory hardware.
Zero Storage Space on System Drive C: (Disk Space Exhaustion)
Solution:
Root Cause: System Volume Storage Exhaustion & Virtual Memory Allocation Failure
When drive C: reaches 0 bytes of available storage, the Windows kernel cannot allocate memory page files (pagefile.sys), create crash dumps, or expand system registry transaction logs (SYSTEM.LOG). When a system thread requests temporary memory workspace during boot, the allocation request fails instantly, triggering an unhandled system thread exception.
# Diagnostic Verification:
1. Open WinRE Command Prompt.
2. Query free disk space on Windows partition (D:):
dir D:
3. Inspect the bottom summary line showing 0 bytes free.
# Step-by-Step Fix:
1. Purge Temporary Directories via WinRE Command Prompt:
Delete temporary files from user profiles and Windows temp: del /f /s /q D:\Windows\Temp\*.*
del /f /s /q D:\Windows\CbsTemp\*.*
del /f /s /q D:\Users\*\AppData\Local\Temp\*.*
2. Delete Software Distribution Download Cache:
Free up space locked by downloaded Windows updates: rmdir /s /q D:\Windows\SoftwareDistribution\Download
3. Delete Hibernation File (If Emergency Space is Needed):
Remove hiberfil.sys to free gigabytes equivalent to installed RAM size: del /f /a D:\hiberfil.sys
4. Reboot System:
Exit Command Prompt and restart Windows normally.# Prevention & Long-Term Monitoring:
Maintain at least 15–20% free storage space on your primary system drive (C:) to allow smooth operating system pagefile and update expansion.