Fix it now
0x000000F5 is an unrecoverable failure in the Filter Manager, raised because a minifilter broke one of the rules the manager enforces. Parameter 1 says which rule. The driver at fault is whichever minifilter it caught, not fltmgr.sys, so the job is to identify the filter and replace or update it.
fltmc filters
- Read parameter 1 of the stop from the System log event. 0x66 is a missing post-operation callback, 0x67 is an internal object out of space, 0x68, 0x6D and 0x6E are reference counting errors on names and contexts, and 0x6A is a create that could not be cancelled because handles already exist.
- Match every third-party name in the
fltmc filtersoutput to an installed product. Anything you cannot match is a leftover and should come off. - Uninstall the suspect security or backup agent with the vendor’s own removal utility rather than Programs and Features, then reboot.
- Run
fltmc filtersagain and confirm the filter has gone rather than merely gone quiet. - Install a current supported release of the one endpoint product you are keeping. Do not put back the build that crashed.
Data loss prevention agents, encryption products and some backup clients install scanning minifilters too. If you are only counting antivirus, you are undercounting the stack.
If the filter list is now what you intended and the host is stable, stop here. If it is not, the next section covers what the Filter Manager checks and how the three companion codes fit around it.
Why it happens
A minifilter does not talk to the file system directly. It registers with the Filter Manager, declares an altitude that fixes its position in the stack, and supplies pre-operation and post-operation callbacks for the I/O it cares about. The Filter Manager calls those callbacks in altitude order going down and in reverse coming back, and it owns the bookkeeping: which callback data belongs to which request, which file objects are still valid and how many references each context holds.
0x000000F5 is that bookkeeping being violated, and unusually for a bugcheck it tells you exactly which rule was broken. A minifilter that returns FLT_PREOP_SUCCESS_WITH_CALLBACK or FLT_PREOP_SYNCHRONIZE from a pre-operation callback without registering the matching post-operation callback gives you subtype 0x66. A context dereferenced once too often gives 0x6D; a context referenced after it was freed gives 0x6E. A create that could not be cancelled because a handle had already been created for the file gives 0x6A.
That last one is worth holding on to, because it is the same story as 0x000000E8 told from the other side. 0x000000E8 says an invalid file object was passed to IoCancelFileOpen and that the calling driver is at fault; the object should have had a reference count of one. Both are a filter trying to make a file open go away after it has already handed out a handle.
The other two companions describe neighbouring failures in the same layer. 0x00000018 is an object whose reference count is illegal for its current state, which Microsoft attributes to a driver dereferencing an object too many times. 0x00000076 is a driver that failed to release pages it locked for an I/O operation, or tried to unlock pages that were not locked. All of these are the sort of mistake an anti-virus minifilter makes when it is scanning a file at the moment something else deletes, renames or reparses it.
Two products are filtering the same volume
You have this one if fltmc filters shows minifilters from two security vendors, and the stops get worse under file-heavy load.
- Pick the product you are keeping and remove the other with its vendor removal tool.
- Reboot and confirm only one anti-malware filter remains.
- Apply the surviving product’s recommended exclusions for database, mail store and virtual disk paths.
- Watch for a full working day before declaring it fixed; these stops are load dependent.
This includes products you may not think of as anti-virus, such as data loss prevention agents and some backup clients, which also install scanning minifilters.
A stale minifilter is still registered after an uninstall
You have this one if A filter appears in fltmc filters for software that is not in the installed programs list.
- Record the filter name exactly as fltmc reports it.
- Find the matching service under
HKLM\SYSTEM\CurrentControlSet\Servicesand check whether the driver file still exists on disk. - Run the vendor’s cleanup utility if one exists.
- If no tool is available, export the branch, remove the orphaned service key and reboot.
The agent build is older than the Windows build
You have this one if Stops started immediately after a feature or cumulative update, and the endpoint agent has not been updated in a long time.
- Check the vendor’s support statement for the exact Windows build you are running.
- Update the agent to a version listed as supported on that build.
- If the agent version is out of support entirely, replace it rather than pinning Windows back.
- Confirm the new driver version is what loads, using
fltmc filtersand the driver file’s properties.
The filter mishandles one specific file system feature
You have this one if The stop is reproducible: a particular share, folder, reparse point, deduplicated volume or redirector triggers it every time.
- Reproduce it deliberately on a test machine so you have a reliable case for the vendor.
- As a stopgap, exclude that path from real-time scanning and confirm the stop goes away, which proves the filter is the trigger.
- Open a support case with the dump and the reproduction steps. This class of bug needs a driver fix, not configuration.
- If the vendor has no fix, move to a product that handles the feature correctly.
An exclusion that makes a stop disappear is diagnostic evidence, not a permanent design. Track it so it does not quietly become policy.
Full reference
Filter Manager subtypes and what each one tells the vendor
| Parameter 1 | What the minifilter did | What the documentation says to check |
|---|---|---|
| 0x66 | Returned SUCCESS_WITH_CALLBACK or SYNCHRONIZE from a pre-operation callback with no matching post-operation callback | That the driver registers a post-operation callback for this operation |
| 0x67 | An internal object ran out of space and no more could be allocated | Whether something on the machine is leaking non-paged pool |
| 0x68 | A file name information structure was dereferenced too many times | The driver’s name-information reference handling |
| 0x6A | A file open or create could not be cancelled because handles had already been created for the file | That the driver does not take a handle on that file object during its processing of the operation |
| 0x6D | A context structure was dereferenced too many times | Extra calls to FltReleaseContext for the given context |
| 0x6E | A context structure was referenced after being freed | Calls to FltReferenceContext after the context was deleted |
Subtypes 0x6B and 0x6C are internal state errors that the documentation describes as non-recoverable, with no reader-side action. If you have one of those, the dump goes to the vendor and there is nothing to configure in the meantime.
Narrowing it down before you remove anything
| Pattern | Most likely source |
|---|---|
| Reproduces when one particular application opens files | A minifilter mishandling that application’s create or rename pattern |
| Started after the security agent auto-updated | A driver regression in the new agent build |
| Only on machines restored from an old image | A minifilter binary that predates the current Windows build |
| Stop code 0x00000076 at logoff or process exit | Pages locked for scanning and never unlocked before the process ended |
| Stop code 0x000000E8, or 0x000000F5 with parameter 1 of 0x6A | A filter cancelling a create after a handle already exists |
Finding the driver that leaks locked pages
0x00000076 is the one case in this family where Windows will name the driver for you rather than leaving you to read a stack. Microsoft documents a tracking mode for exactly this.
- Under
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management, create or edit theTrackLockedPagesvalue and set it to DWORD 1. - Restart the machine. The system then saves stack traces for locked page operations.
- Wait for the fault to recur. It is then reissued as bug check 0xCB, DRIVER_LEFT_LOCKED_PAGES_IN_PROCESS, with the name of the offending driver displayed on the stop screen.
- Remove the tracking value once you have the name, because it costs memory and performance to keep it on.
Commands for this layer
| Command | Purpose |
|---|---|
fltmc filters |
Lists the loaded minifilters with their altitudes and instance counts |
sc query <service> |
Confirms whether the filter’s driver service is running |
!analyze -v |
Runs the initial bugcheck analysis in the debugger and names the faulting module |
When the filter list is clean and it still stops
- Check the altitude of the surviving filter against the vendor’s documentation. A filter loading at an altitude it was not designed for interacts with the layers around it differently.
- Look at what else touches file objects: file screening, quota, deduplication and search indexing all sit in this path on a file server.
- Read subtype 0x67 literally if you have it. It is a pool exhaustion symptom, so find what is consuming non-paged pool rather than blaming the filter that noticed.
- Collect three dumps before you open a vendor case. One dump gives you a module name; three that agree give you a case.
When a licence is the actual fix
If the filter doing the damage belongs to an agent that is out of support, or to a consumer product that was never meant for servers, replacing it is the fix rather than tuning it. Check fltmc filters first, because if the offending filter is a leftover from software you already removed then deleting it costs nothing, and Windows ships with Microsoft Defender Antivirus, whose minifilter is maintained alongside the operating system. Where you want one vendor’s detection stack across servers and workstations under a single console, so there is no reason to leave a second agent installed, Kaspersky Endpoint Security for Business is one supported route and we can confirm which tier covers your server count and supply the licence.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x000000F5 |
FLTMGR_FILE_SYSTEM: an unrecoverable failure in the Filter Manager, with parameter 1 naming which minifilter rule was broken | Microsoft Learn |
0x00000018 |
REFERENCE_BY_POINTER: an object’s reference count is illegal for its current state, typically a driver dereferencing it too many times | Microsoft Learn |
0x00000076 |
PROCESS_HAS_LOCKED_PAGES: a driver failed to release pages it locked for an I/O operation, or tried to unlock pages that were not locked | Microsoft Learn |
0x000000E8 |
INVALID_CANCEL_OF_FILE_OPEN: an invalid file object was passed to IoCancelFileOpen; the calling driver is at fault | Microsoft Learn |
Confirm the fix worked
- Run
fltmc filtersand confirm only the filters you expect are present. - Confirm no new bugcheck entries appear in the System log over a full working day.
- Reproduce the workload that previously stopped the machine and confirm it completes.
- Confirm the surviving agent reports itself healthy in its own console, so you have not traded a stop for an unprotected machine.
- If you set
TrackLockedPages, confirm it has been removed once the driver was identified.
Questions people ask about this
The dump names fltmgr.sys. Is the Filter Manager broken?
Almost never. It is the component that detected the problem and called the bugcheck, so its name is on the stop. The driver you want is one of the minifilters it was calling, which is why parameter 1 and the fltmc list matter more than the module on the screen.
What does parameter 1 give me that the stop code does not?
The specific rule that was broken, and therefore the specific question to put to the vendor. 0x66 is a missing post-operation callback; 0x6D and 0x6E are context reference counting; 0x6A is cancelling a create after a handle exists. That turns a generic support case into one the vendor can act on.
Can I unload a filter at runtime instead of rebooting?
The Filter Manager supports unloading, but many security drivers refuse it by design as tamper protection, and forcing the issue on a busy production machine can hang I/O. Treat it as a lab technique, not a fix.
Is there a free way out of this?
Usually. Removing a duplicate or abandoned filter costs nothing, and Windows ships with Microsoft Defender Antivirus. Money only comes into it if you want a specific vendor’s detection stack or central management.
Will disabling real-time protection prove the agent is at fault?
Only partly. It reduces the callbacks the filter handles, so a stop that goes away is suggestive, but the driver stays loaded and attached. A clean removal followed by fltmc filters is the test that proves it.
