Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
- Copyright (c) Microsoft Corporation. All rights reserved.
- Auto Dump Analyzer by gardenman
- Time to debug file(s): 00 hours and 02 minutes and 24 seconds
- ========================================================================
- =================== Dump File: 072917-35890-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff801`b688e000 PsLoadedModuleList = 0xfffff801`b6bda5e0
- Debug session time: Sat Jul 29 17:59:08.825 2017 (UTC - 4:00)
- System Uptime: 0 days 2:46:03.516
- BugCheck EF, {ffffb10da03dc7c0, 0, 0, 0}
- errfg" bg="errbg">ETW minidump data unavailable
- Probably caused by : ntkrnlmp.exe ( nt!PspCatchCriticalBreak+c9 )
- Followup: MachineOwner
- CRITICAL_PROCESS_DIED (ef)
- A critical system process died
- Arguments:
- Arg1: ffffb10da03dc7c0, Process object or thread object
- Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- ETW minidump data unavailable
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- PROCESS_NAME: svchost.exe
- CRITICAL_PROCESS: svchost.exe
- EXCEPTION_CODE: (NTSTATUS) 0x9dfa77c0 - <Unable to get error code text>
- ERROR_CODE: (NTSTATUS) 0x9dfa77c0 - <Unable to get error code text>
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0xEF
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff801b6f6e071 to fffff801b69fa4c0
- STACK_TEXT:
- ffffc681`e001b098 fffff801`b6f6e071 : 00000000`000000ef ffffb10d`a03dc7c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffffc681`e001b0a0 fffff801`b6ea9c47 : ffffb10d`a03dc7c0 00000000`00000001 ffffb10d`a03dc7c0 fffff801`b68f1059 : nt!PspCatchCriticalBreak+0xc9
- ffffc681`e001b0f0 fffff801`b6d89186 : ffffb10d`00000000 ffffb10d`a03dc7c0 00000000`00000001 ffffb10d`a03dc7c0 : nt!PspTerminateAllThreads+0x1209bb
- ffffc681`e001b160 fffff801`b6d88f47 : ffffffff`ffffffff ffffb10d`a03dc7c0 ffffb10d`a03dc7c0 fffff801`b68f1200 : nt!PspTerminateProcess+0xde
- ffffc681`e001b1a0 fffff801`b6a05413 : ffffb10d`a03dc7c0 ffffb10d`9dfa77c0 ffffc681`e001b290 ffffc681`e001b3e0 : nt!NtTerminateProcess+0xa7
- ffffc681`e001b210 fffff801`b69fd6a0 : fffff801`b68b8f2f ffffc681`e001bb98 ffffc681`e001bb98 ffffc681`e001b3e0 : nt!KiSystemServiceCopyEnd+0x13
- ffffc681`e001b3a8 fffff801`b68b8f2f : ffffc681`e001bb98 ffffc681`e001bb98 ffffc681`e001b3e0 ffffc681`e001bb98 : nt!KiServiceLinkage
- ffffc681`e001b3b0 fffff801`b6a0598e : 00000000`00000000 00000091`00000000 ffffc681`e001bc40 00000000`00000000 : nt!KiDispatchException+0x5ef
- ffffc681`e001ba60 fffff801`b6a03e57 : ffffb10d`9dfa77c0 00007ffb`00000000 00000000`00000000 ffffb10d`00000000 : nt!KiExceptionDispatch+0xce
- ffffc681`e001bc40 00007ffb`d8e79325 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x217
- 00000091`d1601570 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`d8e79325
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: f6b0f7fafbd5253fc3d42ad0a11af14fddabdcf0
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6c21d7479cdfe5c3f7b23f5cd8e9810180c59789
- THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
- FOLLOWUP_IP:
- nt!PspCatchCriticalBreak+c9
- fffff801`b6f6e071 cc int 3
- FAULT_INSTR_CODE: ff8440cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!PspCatchCriticalBreak+c9
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 595f24eb
- IMAGE_VERSION: 10.0.15063.483
- BUCKET_ID_FUNC_OFFSET: c9
- FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_9dfa77c0_nt!PspCatchCriticalBreak
- BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_9dfa77c0_nt!PspCatchCriticalBreak
- PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_9dfa77c0_nt!PspCatchCriticalBreak
- TARGET_TIME: 2017-07-29T21:59:08.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: d80
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_9dfa77c0_nt!pspcatchcriticalbreak
- FAILURE_ID_HASH: {610d89b1-d1c8-ff52-1b4e-48f2f216d436}
- Followup: MachineOwner
- =============================== Drivers ================================
- Image path: peauth.sys
- Image name: peauth.sys
- Timestamp: Sat Dec 9 1989
- Image path: ssudbus.sys
- Image name: ssudbus.sys
- Timestamp: Wed Aug 24 2016
- Image path: MBAMChameleon.sys
- Image name: MBAMChameleon.sys
- Timestamp: Tue Jun 27 2017
- Image path: farflt.sys
- Image name: farflt.sys
- Timestamp: Wed Jun 14 2017
- Image path: mbae64.sys
- Image name: mbae64.sys
- Timestamp: Fri Apr 29 2016
- Image path: mbam.sys
- Image name: mbam.sys
- Timestamp: Wed Jun 7 2017
- Image path: mwac.sys
- Image name: mwac.sys
- Timestamp: Tue Jun 20 2017
- Image path: kdcom.dll
- Image name: kdcom.dll
- Timestamp: ***** Invalid (91688416)
- Image path: mcupdate.dll
- Image name: mcupdate.dll
- Timestamp: Tue Jan 31 1978
- Image path: MBAMSwissArmy.sys
- Image name: MBAMSwissArmy.sys
- Timestamp: Fri Jun 2 2017
- Image path: VBoxUSBMon.sys
- Image name: VBoxUSBMon.sys
- Timestamp: Tue Sep 15 2015
- Image path: MpKsl957b4ea5.sys
- Image name: MpKsl957b4ea5.sys
- Timestamp: Tue May 19 2015
- Image path: atikmpag.sys
- Image name: atikmpag.sys
- Timestamp: Thu Jul 20 2017
- Image path: viahduaa.sys
- Image name: viahduaa.sys
- Timestamp: Tue Aug 18 2015
- Image path: dump_storport.sys
- Image name: dump_storport.sys
- Timestamp: Wed Aug 28 2013
- Image path: drmk.sys
- Image name: drmk.sys
- Timestamp: ***** Invalid (A01C1986)
- Image path: rt640x64.sys
- Image name: rt640x64.sys
- Timestamp: Wed Oct 5 2016
- Image path: ssdevfactory.sys
- Image name: ssdevfactory.sys
- Timestamp: Mon May 8 2017
- Image path: AtihdWT6.sys
- Image name: AtihdWT6.sys
- Timestamp: Sat Mar 25 2017
- Image path: atikmdag.sys
- Image name: atikmdag.sys
- Timestamp: Thu Jul 20 2017
- Unloaded modules:
- fffff801`b6010000 fffff801`b601b000 mshidkmdf.sy
- fffff801`b6000000 fffff801`b600f000 sshid.sys
- fffff801`b6020000 fffff801`b602f000 mouhid.sys
- fffff80b`47f80000 fffff80b`47f9c000 EhStorClass.
- fffff80b`4cb10000 fffff80b`4cb1b000 mshidkmdf.sy
- fffff80b`4f1f0000 fffff80b`4f1ff000 sshid.sys
- fffff80b`4cc80000 fffff80b`4cc8f000 mouhid.sys
- fffff801`b5f40000 fffff801`b5f59000 mwac.sys
- fffff801`b5d50000 fffff801`b5d5d000 mbam.sys
- fffff801`b5d30000 fffff801`b5d49000 mwac.sys
- fffff801`b5d60000 fffff801`b5d7a000 farflt.sys
- fffff80b`49920000 fffff80b`4992f000 mbae64.sys
- fffff80b`49c50000 fffff80b`49c81000 MBAMChameleo
- fffff801`b5db0000 fffff801`b5dd0000 ssudbus.sys
- fffff801`b5e80000 fffff801`b5e91000 modem.sys
- fffff801`b5e40000 fffff801`b5e71000 ssudmdm.sys
- fffff801`b5e30000 fffff801`b5e3d000 WpdUpFltr.sy
- fffff801`b5df0000 fffff801`b5e2d000 WUDFRd.sys
- fffff801`b5dd0000 fffff801`b5ded000 WinUSB.SYS
- fffff80b`4f1d0000 fffff80b`4f1f0000 ssudbus.sys
- fffff80b`49cf0000 fffff80b`49d01000 modem.sys
- fffff80b`49cb0000 fffff80b`49ce1000 ssudmdm.sys
- fffff80b`49ca0000 fffff80b`49cad000 WpdUpFltr.sy
- fffff80b`49460000 fffff80b`4949d000 WUDFRd.sys
- fffff80b`49960000 fffff80b`4997d000 WinUSB.SYS
- fffff80b`4a1c0000 fffff80b`4a1cb000 cldflt.sys
- fffff80b`48da0000 fffff80b`48daf000 dump_storpor
- fffff80b`48560000 fffff80b`48587000 dump_storahc
- fffff80b`48590000 fffff80b`485ad000 dump_dumpfve
- fffff80b`49c50000 fffff80b`49c6d000 WinUSB.SYS
- fffff80b`49c70000 fffff80b`49cad000 WUDFRd.sys
- fffff80b`4cb10000 fffff80b`4cb1a000 amdkmafd.sys
- fffff80b`4f1a0000 fffff80b`4f1aa000 amdkmafd.sys
- fffff80b`49960000 fffff80b`49980000 dam.sys
- fffff80b`48760000 fffff80b`4876f000 WdBoot.sys
- fffff80b`489e0000 fffff80b`489ef000 hwpolicy.sys
- ============================= BIOS INFO ================================
- [SMBIOS Data Tables v2.4]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2829 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor Award Software International, Inc.
- BIOS Version FA
- BIOS Starting Address Segment e000
- BIOS Release Date 04/23/2013
- BIOS ROM Size 400000
- BIOS Characteristics
- 04: - ISA Supported
- 07: - PCI Supported
- 09: - Plug and Play Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 22: - 360KB Floppy Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 30: - CGA/Mono Services Supported
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 02: - AGP Supported
- 04: - LS120-Boot Supported
- 05: - ATAPI ZIP-Boot Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- BIOS Major Revision 255
- BIOS Minor Revision 255
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product Name GA-78LMT-USB3
- Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber
- Family
- [BaseBoard Information (Type 2) - Length 8 - Handle 0002h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product GA-78LMT-USB3
- Version SEx
- [System Enclosure (Type 3) - Length 17 - Handle 0003h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Chassis Type Desktop
- Version
- Bootup State Unknown
- Power Supply State Unknown
- Thermal State Unknown
- Security Status Unknown
- OEM Defined 0
- [Processor Information (Type 4) - Length 35 - Handle 0004h]
- Socket Designation Socket M2
- Processor Type Central Processor
- Processor Family 1dh - AMD Athlon Family
- Processor Manufacturer AMD
- Processor ID a00f1000fffb8b17
- Processor Version AMD Phenom(tm) II X6 1090T Processor
- Processor Voltage 90h - 1.6V
- External Clock 200MHz
- Max Speed 3000MHz
- Current Speed 3200MHz
- Status Enabled Populated
- Processor Upgrade Socket 754
- L1 Cache Handle 000ah
- L2 Cache Handle 000ch
- L3 Cache Handle [Not Present]
- Part Number
- [Memory Controller Information (Type 5) - Length 24 - Handle 0005h]
- Error Detecting Method 06h - 64-bit ECC
- Error Correcting Capability 04h - None
- Supported Interleave 03h - One Way Interleave
- Current Interleave 03h - One Way Interleave
- Maximum Memory Module Size 0ch - 4096MB
- Supported Speeds 001ch - 70ns 60ns 50ns
- Supported Memory Types 0104h - Standard DIMM
- Memory Module Voltage 2.9V
- Number of Memory Slots 4
- Memory Slot Handle 0006h
- Memory Slot Handle 0007h
- Memory Slot Handle 0008h
- Memory Slot Handle 0009h
- Enabled Err Correcting Caps 04h - None
- [Memory Module Information (Type 6) - Length 12 - Handle 0006h]
- Socket Designation A0
- Bank Connections 1fh - 1
- Current Speed 31ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0007h]
- Socket Designation A1
- Bank Connections 2fh - 2
- Current Speed 47ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0008h]
- Socket Designation A2
- Bank Connections 3fh - 3
- Current Speed 63ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 8ch - 4096 [double bank]
- Enabled Size 8ch - 4096 [double bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0009h]
- Socket Designation A3
- Bank Connections 4fh - 4
- Current Speed 79ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Cache Information (Type 7) - Length 19 - Handle 000ah]
- Socket Designation Internal Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000bh]
- Socket Designation Internal Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000ch]
- Socket Designation External Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000dh]
- Socket Designation External Cache
- Cache Configuration 0001h - WT Disabled Int NonSocketed L2
- Maximum Cache Size 0400h - 1024K
- Installed Size 0000h - 0K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Physical Memory Array (Type 16) - Length 15 - Handle 0023h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 16777216KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 27 - Handle 0024h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A0
- Bank Locator Bank0/1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0025h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A1
- Bank Locator Bank2/3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0026h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator A2
- Bank Locator Bank4/5
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0027h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A3
- Bank Locator Bank6/7
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Array Mapped Address (Type 19) - Length 15 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 009fffffh
- Memory Array Handle 0023h
- Partition Width 01
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 0029h]
- Starting Address 00000000h
- Ending Address 001fffffh
- Memory Device Handle 0024h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002ah]
- Starting Address 00200000h
- Ending Address 003fffffh
- Memory Device Handle 0025h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002bh]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0026h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002ch]
- Starting Address 00800000h
- Ending Address 009fffffh
- Memory Device Handle 0027h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- ========================================================================
- =================== Dump File: 072717-33234-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff800`4fc1b000 PsLoadedModuleList = 0xfffff800`4ff675a0
- Debug session time: Thu Jul 27 21:39:03.984 2017 (UTC - 4:00)
- System Uptime: 0 days 0:17:23.673
- BugCheck EF, {ffffc8009574f4c0, 0, 0, 0}
- errfg" bg="errbg">ETW minidump data unavailable
- Probably caused by : ntkrnlmp.exe ( nt!PspCatchCriticalBreak+c9 )
- Followup: MachineOwner
- CRITICAL_PROCESS_DIED (ef)
- A critical system process died
- Arguments:
- Arg1: ffffc8009574f4c0, Process object or thread object
- Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- ETW minidump data unavailable
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.413 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- PROCESS_NAME: svchost.exe
- CRITICAL_PROCESS: svchost.exe
- EXCEPTION_RECORD: ffffdb80b48a6bb0 -- (.exr 0xffffdb80b48a6bb0)
- ExceptionAddress: 000000e434780b80
- ExceptionCode: 00000002
- ExceptionFlags: 00000000
- NumberParameters: 0
- EXCEPTION_CODE: (Win32) 0x2 (2) - The system cannot find the file specified.
- ERROR_CODE: (NTSTATUS) 0x2 - STATUS_WAIT_2
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0xEF
- CURRENT_IRQL: 0
- EXCEPTION_CODE_STR: 2
- LAST_CONTROL_TRANSFER: from fffff800502faf51 to fffff8004fd873f0
- STACK_TEXT:
- ffffdb80`b48a6098 fffff800`502faf51 : 00000000`000000ef ffffc800`9574f4c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffffdb80`b48a60a0 fffff800`50236a6d : ffffc800`9574f4c0 00000000`00000001 ffffc800`9574f4c0 00000000`00000000 : nt!PspCatchCriticalBreak+0xc9
- ffffdb80`b48a60f0 fffff800`501160f6 : ffffc800`00000000 ffffc800`9574f4c0 00000000`00000001 ffffc800`9574f4c0 : nt!PspTerminateAllThreads+0x120871
- ffffdb80`b48a6160 fffff800`50115eb7 : ffffffff`ffffffff ffffc800`9574f4c0 ffffc800`9574f4c0 fffff800`4fc7e200 : nt!PspTerminateProcess+0xde
- ffffdb80`b48a61a0 fffff800`4fd92313 : ffffc800`9574f4c0 ffffc800`95a61080 ffffdb80`b48a6290 ffffdb80`b48a63e0 : nt!NtTerminateProcess+0xa7
- ffffdb80`b48a6210 fffff800`4fd8a5d0 : fffff800`4fc45f2f ffffdb80`b48a6b98 ffffdb80`b48a6b98 ffffdb80`b48a63e0 : nt!KiSystemServiceCopyEnd+0x13
- ffffdb80`b48a63a8 fffff800`4fc45f2f : ffffdb80`b48a6b98 ffffdb80`b48a6b98 ffffdb80`b48a63e0 ffffdb80`b48a6b98 : nt!KiServiceLinkage
- ffffdb80`b48a63b0 fffff800`4fd9288e : ffffdb80`b48a6bb0 000000e4`00000000 ffffdb80`b48a6c00 00000000`00000001 : nt!KiDispatchException+0x5ef
- ffffdb80`b48a6a60 fffff800`4fd90d57 : ffffc800`95a61080 0000023e`973e05e0 00000000`00000000 ffffc800`95da4b20 : nt!KiExceptionDispatch+0xce
- ffffdb80`b48a6c40 00007ffc`a896992e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x217
- 000000e4`34780ae0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`a896992e
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: f6b0f7fafbd5253fc3d42ad0a11af14fddabdcf0
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: efe92f4eb616323a9b7827c3a48553119101f25d
- THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
- FOLLOWUP_IP:
- nt!PspCatchCriticalBreak+c9
- fffff800`502faf51 cc int 3
- FAULT_INSTR_CODE: ff8440cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!PspCatchCriticalBreak+c9
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 59327910
- IMAGE_VERSION: 10.0.15063.413
- BUCKET_ID_FUNC_OFFSET: c9
- FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_95a61080_nt!PspCatchCriticalBreak
- BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_95a61080_nt!PspCatchCriticalBreak
- PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_95a61080_nt!PspCatchCriticalBreak
- TARGET_TIME: 2017-07-28T01:39:03.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 413
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-06-03 04:53:36
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.413
- ANALYSIS_SESSION_ELAPSED_TIME: d80
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_95a61080_nt!pspcatchcriticalbreak
- FAILURE_ID_HASH: {64c8f5f4-4aba-1bcb-f38c-7ef51209d714}
- Followup: MachineOwner
- ========================================================================
- =================== Dump File: 072817-28906-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff801`ca09b000 PsLoadedModuleList = 0xfffff801`ca3e75a0
- Debug session time: Fri Jul 28 18:24:13.748 2017 (UTC - 4:00)
- System Uptime: 0 days 11:05:46.438
- BugCheck EF, {ffffbd0c5703c7c0, 0, 0, 0}
- errfg" bg="errbg">ETW minidump data unavailable
- Probably caused by : ntkrnlmp.exe ( nt!PspCatchCriticalBreak+c9 )
- Followup: MachineOwner
- CRITICAL_PROCESS_DIED (ef)
- A critical system process died
- Arguments:
- Arg1: ffffbd0c5703c7c0, Process object or thread object
- Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- ETW minidump data unavailable
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.413 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- PROCESS_NAME: csrss.exe
- CRITICAL_PROCESS: csrss.exe
- EXCEPTION_RECORD: ffffd300f48b3bb0 -- (.exr 0xffffd300f48b3bb0)
- ExceptionAddress: 00000083a9f00c70
- ExceptionCode: 00000002
- ExceptionFlags: 00000000
- NumberParameters: 0
- EXCEPTION_CODE: (Win32) 0x2 (2) - The system cannot find the file specified.
- ERROR_CODE: (NTSTATUS) 0x2 - STATUS_WAIT_2
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0xEF
- CURRENT_IRQL: 0
- EXCEPTION_CODE_STR: 2
- LAST_CONTROL_TRANSFER: from fffff801ca77af51 to fffff801ca2073f0
- STACK_TEXT:
- ffffd300`f48b3098 fffff801`ca77af51 : 00000000`000000ef ffffbd0c`5703c7c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffffd300`f48b30a0 fffff801`ca6b6a6d : ffffbd0c`5703c7c0 00000000`00000001 ffffbd0c`5703c7c0 fffff801`ca0fe059 : nt!PspCatchCriticalBreak+0xc9
- ffffd300`f48b30f0 fffff801`ca5960f6 : ffffbd0c`00000000 ffffbd0c`5703c7c0 00000000`00000001 ffffbd0c`5703c7c0 : nt!PspTerminateAllThreads+0x120871
- ffffd300`f48b3160 fffff801`ca595eb7 : ffffffff`ffffffff ffffbd0c`5703c7c0 ffffbd0c`5703c7c0 00000000`00000000 : nt!PspTerminateProcess+0xde
- ffffd300`f48b31a0 fffff801`ca212313 : ffffbd0c`5703c7c0 ffffbd0c`589c9080 ffffd300`f48b3290 ffffd300`f48b33e0 : nt!NtTerminateProcess+0xa7
- ffffd300`f48b3210 fffff801`ca20a5d0 : fffff801`ca0c5f2f ffffd300`f48b3b98 ffffd300`f48b3b98 ffffd300`f48b33e0 : nt!KiSystemServiceCopyEnd+0x13
- ffffd300`f48b33a8 fffff801`ca0c5f2f : ffffd300`f48b3b98 ffffd300`f48b3b98 ffffd300`f48b33e0 ffffd300`f48b3b98 : nt!KiServiceLinkage
- ffffd300`f48b33b0 fffff801`ca21288e : ffffd300`f48b3bb0 ffffd300`00000000 ffffd300`f48b3c00 00000000`00000001 : nt!KiDispatchException+0x5ef
- ffffd300`f48b3a60 fffff801`ca210d57 : 00000000`00000000 ffffbd0c`589c9080 00000000`00000000 00000000`00000007 : nt!KiExceptionDispatch+0xce
- ffffd300`f48b3c40 00007ffd`8302992e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x217
- 00000083`a9f00bd0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`8302992e
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: f6b0f7fafbd5253fc3d42ad0a11af14fddabdcf0
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: efe92f4eb616323a9b7827c3a48553119101f25d
- THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
- FOLLOWUP_IP:
- nt!PspCatchCriticalBreak+c9
- fffff801`ca77af51 cc int 3
- FAULT_INSTR_CODE: ff8440cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!PspCatchCriticalBreak+c9
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 59327910
- IMAGE_VERSION: 10.0.15063.413
- BUCKET_ID_FUNC_OFFSET: c9
- FAILURE_BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_589c9080_nt!PspCatchCriticalBreak
- BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_589c9080_nt!PspCatchCriticalBreak
- PRIMARY_PROBLEM_CLASS: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_589c9080_nt!PspCatchCriticalBreak
- TARGET_TIME: 2017-07-28T22:24:13.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 413
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-06-03 04:53:36
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.413
- ANALYSIS_SESSION_ELAPSED_TIME: d9a
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0xef_csrss.exe_bugcheck_critical_process_589c9080_nt!pspcatchcriticalbreak
- FAILURE_ID_HASH: {5476935c-986b-8426-f495-2c28d8bb6dcc}
- Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement