Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- BugCheck 3B, {c0000005, fffff80003bb0617, fffff88005dae6e0, 0}
- Probably caused by : ntkrnlmp.exe ( nt!ExAllocatePoolWithTag+537 )
- Followup: MachineOwner
- ---------
- 0: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff80003bb0617, Address of the instruction which caused the bugcheck
- Arg3: fffff88005dae6e0, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
- FAULTING_IP:
- nt!ExAllocatePoolWithTag+537
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx
- CONTEXT: fffff88005dae6e0 -- (.cxr 0xfffff88005dae6e0)
- rax=fffef8a0050338a0 rbx=fffffa8004e7a540 rcx=fffff8a004bd78a0
- rdx=0000000000000003 rsi=0000000000000003 rdi=0000000000000001
- rip=fffff80003bb0617 rsp=fffff88005daf0c0 rbp=0000000000001000
- r8=0000000000000001 r9=fffffa8004e7a540 r10=fffffa8004e7a3c8
- r11=0000000000000003 r12=fffffa8004e7a3c0 r13=0000000000000000
- r14=fffffa80068f2b60 r15=000000004b466650
- iopl=0 nv up ei pl zr na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
- nt!ExAllocatePoolWithTag+0x537:
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx ds:002b:fffef8a0`050338a8=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: svchost.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80003bb0617
- STACK_TEXT:
- fffff880`05daf0c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x537
- FOLLOWUP_IP:
- nt!ExAllocatePoolWithTag+537
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx
- SYMBOL_STACK_INDEX: 0
- SYMBOL_NAME: nt!ExAllocatePoolWithTag+537
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd5b
- STACK_COMMAND: .cxr 0xfffff88005dae6e0 ; kb
- FAILURE_BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+537
- BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+537
- Followup: MachineOwner
- ---------
- 0: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff80003bb0617, Address of the instruction which caused the bugcheck
- Arg3: fffff88005dae6e0, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
- FAULTING_IP:
- nt!ExAllocatePoolWithTag+537
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx
- CONTEXT: fffff88005dae6e0 -- (.cxr 0xfffff88005dae6e0)
- rax=fffef8a0050338a0 rbx=fffffa8004e7a540 rcx=fffff8a004bd78a0
- rdx=0000000000000003 rsi=0000000000000003 rdi=0000000000000001
- rip=fffff80003bb0617 rsp=fffff88005daf0c0 rbp=0000000000001000
- r8=0000000000000001 r9=fffffa8004e7a540 r10=fffffa8004e7a3c8
- r11=0000000000000003 r12=fffffa8004e7a3c0 r13=0000000000000000
- r14=fffffa80068f2b60 r15=000000004b466650
- iopl=0 nv up ei pl zr na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
- nt!ExAllocatePoolWithTag+0x537:
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx ds:002b:fffef8a0`050338a8=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: svchost.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80003bb0617
- STACK_TEXT:
- fffff880`05daf0c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x537
- FOLLOWUP_IP:
- nt!ExAllocatePoolWithTag+537
- fffff800`03bb0617 48895808 mov qword ptr [rax+8],rbx
- SYMBOL_STACK_INDEX: 0
- SYMBOL_NAME: nt!ExAllocatePoolWithTag+537
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd5b
- STACK_COMMAND: .cxr 0xfffff88005dae6e0 ; kb
- FAILURE_BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+537
- BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+537
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement