Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.21349.1004 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\Minidump\061221-10984-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff805`43200000 PsLoadedModuleList = 0xfffff805`43e2a230
- Debug session time: Sat Jun 12 23:59:14.557 2021 (UTC - 5:00)
- System Uptime: 0 days 0:09:42.203
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ..............
- Loading User Symbols
- Loading unloaded module list
- ........
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff805`435f6c20 48894c2408 mov qword ptr [rsp+8],rcx ss:ffffd381`d8bbf420=000000000000003b
- 4: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the BugCheck
- Arg2: ffffa91b373bc358, Address of the instruction which caused the BugCheck
- Arg3: ffffd381d8bbfd20, Address of the context record for the exception that caused the BugCheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.mSec
- Value: 4921
- Key : Analysis.DebugAnalysisManager
- Value: Create
- Key : Analysis.Elapsed.mSec
- Value: 33318
- Key : Analysis.Init.CPU.mSec
- Value: 499
- Key : Analysis.Init.Elapsed.mSec
- Value: 26276
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 89
- Key : WER.OS.Branch
- Value: vb_release
- Key : WER.OS.Timestamp
- Value: 2019-12-06T14:06:00Z
- Key : WER.OS.Version
- Value: 10.0.19041.1
- BUGCHECK_CODE: 3b
- BUGCHECK_P1: c0000005
- BUGCHECK_P2: ffffa91b373bc358
- BUGCHECK_P3: ffffd381d8bbfd20
- BUGCHECK_P4: 0
- CONTEXT: ffffd381d8bbfd20 -- (.cxr 0xffffd381d8bbfd20)
- rax=000000007fffafac rbx=ffffa94f86c2f320 rcx=ffffa94f86cd18a0
- rdx=d9ffa94f86cc7ab0 rsi=ffffa94f86c2eb48 rdi=0000000000000200
- rip=ffffa91b373bc358 rsp=ffffd381d8bc0720 rbp=ffffa94f86c2f368
- r8=0000000000000000 r9=000000000000002f r10=ffffa91b3704e0f0
- r11=ffff76fe11400000 r12=0000000000000001 r13=0000000000000001
- r14=ffffa94f86c2f354 r15=ffffa94f86c2f350
- iopl=0 nv up ei pl nz na po nc
- cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00050206
- win32kfull!TimersProc+0x1e8:
- ffffa91b`373bc358 8b8a10040000 mov ecx,dword ptr [rdx+410h] ds:002b:d9ffa94f`86cc7ec0=????????
- Resetting default scope
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXWINLOGON: 1
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: csrss.exe
- STACK_TEXT:
- ffffd381`d8bc0720 ffffa91b`373bbe56 : 00000000`00000010 00000000`0008e23b 00000000`00000001 00000000`00000004 : win32kfull!TimersProc+0x1e8
- ffffd381`d8bc07b0 ffffa91b`37080913 : ffffac0b`453f0080 ffffac0b`453f0080 00000000`00000000 00000000`00000005 : win32kfull!RawInputThread+0x7f6
- ffffd381`d8bc0970 ffffa91b`37393ad0 : ffffac0b`453f0080 00000000`00000000 00000000`00000005 00000000`00000005 : win32kbase!xxxCreateSystemThreads+0xc3
- ffffd381`d8bc0aa0 ffffa91b`37f1474d : ffffac0b`453f0080 ffffac0b`453f0080 00000000`00000000 00000000`00000000 : win32kfull!NtUserCallNoParam+0x70
- ffffd381`d8bc0ad0 fffff805`436085b8 : ffffac0b`00000005 00000000`00000005 000001c7`10804350 00000000`000004b8 : win32k!NtUserCallNoParam+0x15
- ffffd381`d8bc0b00 00007ffb`49cb10e4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 0000007e`e6affa38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`49cb10e4
- SYMBOL_NAME: win32kfull!TimersProc+1e8
- MODULE_NAME: win32kfull
- IMAGE_NAME: win32kfull.sys
- IMAGE_VERSION: 10.0.19041.1055
- STACK_COMMAND: .cxr 0xffffd381d8bbfd20 ; kb
- BUCKET_ID_FUNC_OFFSET: 1e8
- FAILURE_BUCKET_ID: 0x3B_c0000005_win32kfull!TimersProc
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {e19a4cac-ba4d-937b-93bc-07ff9528cd63}
- Followup: MachineOwner
- ---------
- 4: kd> lmvm win32kfull
- Browse full module list
- start end module name
- ffffa91b`372e0000 ffffa91b`37696000 win32kfull # (pdb symbols) C:\ProgramData\Dbg\sym\win32kfull.pdb\53FBCE4396D1F439C8A85D9FB79695FB1\win32kfull.pdb
- Loaded symbol image file: win32kfull.sys
- Mapped memory image file: C:\ProgramData\Dbg\sym\win32kfull.sys\198B748C3b6000\win32kfull.sys
- Image path: \SystemRoot\System32\win32kfull.sys
- Image name: win32kfull.sys
- Browse all global symbols functions data
- Image was built with /Brepro flag.
- Timestamp: 198B748C (This is a reproducible build file hash, not a timestamp)
- CheckSum: 003AE6A4
- ImageSize: 003B6000
- File version: 10.0.19041.1055
- Product version: 10.0.19041.1055
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- Information from resource tables:
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: win32kfull.sys
- OriginalFilename: win32kfull.sys
- ProductVersion: 10.0.19041.1055
- FileVersion: 10.0.19041.1055 (WinBuild.160101.0800)
- FileDescription: Full/Desktop Win32k Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
- Microsoft (R) Windows Debugger Version 10.0.21349.1004 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\Minidump\061221-9796-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff803`81a00000 PsLoadedModuleList = 0xfffff803`8262a230
- Debug session time: Sat Jun 12 23:31:48.953 2021 (UTC - 5:00)
- System Uptime: 0 days 19:17:09.601
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ...............
- Loading User Symbols
- Loading unloaded module list
- .............
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff803`81df6c20 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffe88`00f54a00=000000000000001e
- 11: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- KMODE_EXCEPTION_NOT_HANDLED (1e)
- This is a very common BugCheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Arguments:
- Arg1: ffffffffc0000005, The exception code that was not handled
- Arg2: fffff80381d1652d, The address that the exception occurred at
- Arg3: 0000000000000000, Parameter 0 of the exception
- Arg4: ffffffffffffffff, Parameter 1 of the exception
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.mSec
- Value: 3890
- Key : Analysis.DebugAnalysisManager
- Value: Create
- Key : Analysis.Elapsed.mSec
- Value: 8657
- Key : Analysis.Init.CPU.mSec
- Value: 249
- Key : Analysis.Init.Elapsed.mSec
- Value: 5526
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 75
- Key : WER.OS.Branch
- Value: vb_release
- Key : WER.OS.Timestamp
- Value: 2019-12-06T14:06:00Z
- Key : WER.OS.Version
- Value: 10.0.19041.1
- BUGCHECK_CODE: 1e
- BUGCHECK_P1: ffffffffc0000005
- BUGCHECK_P2: fffff80381d1652d
- BUGCHECK_P3: 0
- BUGCHECK_P4: ffffffffffffffff
- READ_ADDRESS: fffff803826fb390: Unable to get MiVisibleState
- Unable to get NonPagedPoolStart
- Unable to get NonPagedPoolEnd
- Unable to get PagedPoolStart
- Unable to get PagedPoolEnd
- unable to get nt!MmSpecialPagesInUse
- ffffffffffffffff
- EXCEPTION_PARAMETER2: ffffffffffffffff
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXPNP: 1 (!blackboxpnp)
- BLACKBOXWINLOGON: 1
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: svchost.exe
- STACK_TEXT:
- fffffe88`00f549f8 fffff803`81e3b74b : 00000000`0000001e ffffffff`c0000005 fffff803`81d1652d 00000000`00000000 : nt!KeBugCheckEx
- fffffe88`00f54a00 fffff803`81e08cac : fffffe88`00f55300 ffff8a84`006cec00 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x1b579b
- fffffe88`00f550c0 fffff803`81e049e0 : 00000000`00000000 00000000`00000001 fffffe88`00f556a8 fffffe88`00f556b8 : nt!KiExceptionDispatch+0x12c
- fffffe88`00f552a0 fffff803`81d1652d : 00000000`00000000 fffff803`81d24b64 ffff8a84`04c1b001 fffffe88`00f556a0 : nt!KiGeneralProtectionFault+0x320
- fffffe88`00f55430 fffff803`81d15841 : ffff8a83`ffa00340 ffff8a83`ffa02900 ffff8a83`ffa06080 00000000`00000080 : nt!RtlpHpLfhSlotAllocate+0x36d
- fffffe88`00f55580 fffff803`823b31c4 : ffff8a84`00000000 00000000`00000000 00000000`36364d43 fffff803`81ff0bd4 : nt!ExAllocateHeapPool+0x2b1
- fffffe88`00f556c0 fffff803`81fe6edd : 00000000`00000003 fffffe88`00f55810 00000000`00000005 00000000`00000000 : nt!ExAllocatePoolWithTag+0x64
- fffffe88`00f55710 fffff803`81fefc0d : 00000000`00000000 00000000`00000000 ffff8a84`12d3baf0 00000000`00000000 : nt!CmpGetSymbolicLinkTarget+0x20d
- fffffe88`00f55950 fffff803`81fee303 : ffff8a84`0000001c fffffe88`00f55ca0 fffffe88`00f55c58 ffffac89`fb9e4010 : nt!CmpDoParseKey+0xa3d
- fffffe88`00f55bf0 fffff803`81ff23ce : fffff803`81fee001 00000000`00000000 ffffac89`fb9e4010 ffff8a83`00000000 : nt!CmpParseKey+0x2c3
- fffffe88`00f55d90 fffff803`821014aa : ffffac89`fb9e4000 fffffe88`00f55ff8 00000000`00000240 ffffac89`e20c4220 : nt!ObpLookupObjectName+0x3fe
- fffffe88`00f55f60 fffff803`8210128c : 00000000`00000000 00000000`00000000 00000000`00000000 ffffac89`e20c4220 : nt!ObOpenObjectByNameEx+0x1fa
- fffffe88`00f56090 fffff803`82100db1 : fffffe88`00f56580 fffffe88`00f56400 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByName+0x5c
- fffffe88`00f560e0 fffff803`82093f42 : ffffac89`ff4dba60 fffff803`7e7d8b99 ffffac89`ff4dba00 00000000`00000000 : nt!CmOpenKey+0x2c1
- fffffe88`00f56340 fffff803`81e085b8 : 00000000`00000000 ffffac89`ecbb03d0 fffffe88`00f56420 00000000`00000000 : nt!NtOpenKey+0x12
- fffffe88`00f56380 fffff803`81dfaa80 : fffff803`81fc7e47 ffff8a84`04a77df0 fffff803`81c52696 ffffac89`ecc0ee88 : nt!KiSystemServiceCopyEnd+0x28
- fffffe88`00f56518 fffff803`81fc7e47 : ffff8a84`04a77df0 fffff803`81c52696 ffffac89`ecc0ee88 ffff8a84`04a77df0 : nt!KiServiceLinkage
- fffffe88`00f56520 fffff803`82005cf3 : fffffe88`00f56840 00000000`00000000 ffffac89`f54f6040 00000000`00000000 : nt!MiRegQueryDWORD+0xf3
- fffffe88`00f565f0 fffff803`81ffa52f : 00000000`00000000 fffffe88`00f56840 ffff8a84`04b61e60 ffffac89`ecc0ec00 : nt!MiValidateExistingImage+0xe7
- fffffe88`00f566a0 fffff803`81ffb2ed : 00000000`00000000 fffffe88`00f56840 ffffac89`f54f6040 ffffac8a`012048f0 : nt!MiShareExistingControlArea+0xc7
- fffffe88`00f566d0 fffff803`81ffaa64 : ffffac89`ecc0ec80 00000000`00000000 ffffac8a`012048f0 00000000`00000000 : nt!MiCreateImageOrDataSection+0x1ad
- fffffe88`00f567c0 fffff803`81ffa847 : 00000000`01000000 fffffe88`00f56b80 00000000`00000001 00000000`00000010 : nt!MiCreateSection+0xf4
- fffffe88`00f56940 fffff803`81ffa62c : 000000dc`0357f268 00000000`0000000d 00000000`00000000 00000000`00000001 : nt!MiCreateSectionCommon+0x207
- fffffe88`00f56a20 fffff803`81e085b8 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateSection+0x5c
- fffffe88`00f56a90 00007ffe`0800d764 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 000000dc`0357f218 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`0800d764
- SYMBOL_NAME: nt!RtlpHpLfhSlotAllocate+36d
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- IMAGE_VERSION: 10.0.19041.1052
- STACK_COMMAND: .thread ; .cxr ; kb
- BUCKET_ID_FUNC_OFFSET: 36d
- FAILURE_BUCKET_ID: 0x1E_c0000005_R_nt!RtlpHpLfhSlotAllocate
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {5f2edb0e-188e-44d6-b543-6de2bf6feaf3}
- Followup: MachineOwner
- ---------
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
- Microsoft (R) Windows Debugger Version 10.0.21349.1004 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\Minidump\061221-9718-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff800`4b200000 PsLoadedModuleList = 0xfffff800`4be2a230
- Debug session time: Sat Jun 12 23:32:37.148 2021 (UTC - 5:00)
- System Uptime: 0 days 0:00:14.795
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- .........
- Loading User Symbols
- Loading unloaded module list
- .......
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff800`4b5f6c20 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffa87`5724b570=000000000000003b
- 3: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the BugCheck
- Arg2: fffff8004b895d58, Address of the instruction which caused the BugCheck
- Arg3: fffffa875724be70, Address of the context record for the exception that caused the BugCheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.mSec
- Value: 2733
- Key : Analysis.DebugAnalysisManager
- Value: Create
- Key : Analysis.Elapsed.mSec
- Value: 5697
- Key : Analysis.Init.CPU.mSec
- Value: 280
- Key : Analysis.Init.Elapsed.mSec
- Value: 4526
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 75
- Key : WER.OS.Branch
- Value: vb_release
- Key : WER.OS.Timestamp
- Value: 2019-12-06T14:06:00Z
- Key : WER.OS.Version
- Value: 10.0.19041.1
- BUGCHECK_CODE: 3b
- BUGCHECK_P1: c0000005
- BUGCHECK_P2: fffff8004b895d58
- BUGCHECK_P3: fffffa875724be70
- BUGCHECK_P4: 0
- CONTEXT: fffffa875724be70 -- (.cxr 0xfffffa875724be70)
- rax=0000000000000016 rbx=d9ff818c2c446ea0 rcx=ffff818c2dc1cc10
- rdx=d9ff818c2c446ebc rsi=ffffb08c64b223f0 rdi=ffff818c2dc1cc10
- rip=fffff8004b895d58 rsp=fffffa875724c870 rbp=fffff8004be19a00
- r8=fffffa875724c8b0 r9=ffffb08c64b223f0 r10=0000000054777445
- r11=0000000000001001 r12=fffff8004be19a20 r13=0000000000000000
- r14=ffff818c2dc1cc28 r15=fffffa875724ca00
- iopl=0 nv up ei ng nz na pe nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050282
- nt!TraitsCompare+0xc:
- fffff800`4b895d58 663b02 cmp ax,word ptr [rdx] ds:002b:d9ff818c`2c446ebc=????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: GameManagerService.exe
- STACK_TEXT:
- fffffa87`5724c870 fffff800`4b8d85be : fffff800`4be19a40 ffffc0e0`00000000 b08c64b2`00000000 00000000`000000c0 : nt!TraitsCompare+0xc
- fffffa87`5724c8a0 fffff800`4b8d848a : 00000000`00000000 fffffa87`5724cb80 ffffb08c`64b223f0 ffff818c`00000000 : nt!EtwpSetProviderTraitsCommon+0xfe
- fffffa87`5724c960 fffff800`4b8fac63 : ffffb08c`64b223f0 00000000`00000018 00000000`50777445 ffffb08c`64b223f0 : nt!EtwpSetProviderTraitsUm+0x166
- fffffa87`5724c9e0 fffff800`4b6085b8 : 00000000`0000001e 00000000`00000000 00000000`00000018 00000000`004fb978 : nt!NtTraceControl+0x6d3
- fffffa87`5724ca90 00007ffe`a45d0674 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 00000000`0013e4b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`a45d0674
- SYMBOL_NAME: nt!TraitsCompare+c
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- IMAGE_VERSION: 10.0.19041.1052
- STACK_COMMAND: .cxr 0xfffffa875724be70 ; kb
- BUCKET_ID_FUNC_OFFSET: c
- FAILURE_BUCKET_ID: 0x3B_c0000005_nt!TraitsCompare
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {60751898-0d39-6f31-94ec-7f8aa1612e65}
- Followup: MachineOwner
- ---------
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
- Microsoft (R) Windows Debugger Version 10.0.21349.1004 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\Minidump\061221-9468-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff800`42800000 PsLoadedModuleList = 0xfffff800`4342a230
- Debug session time: Sat Jun 12 23:43:00.811 2021 (UTC - 5:00)
- System Uptime: 0 days 0:09:54.459
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ...............
- Loading User Symbols
- Loading unloaded module list
- ........
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff800`42bf6c20 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9c80`4f130160=000000000000001e
- 8: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- KMODE_EXCEPTION_NOT_HANDLED (1e)
- This is a very common BugCheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Arguments:
- Arg1: ffffffffc0000005, The exception code that was not handled
- Arg2: fffff80042b11b56, The address that the exception occurred at
- Arg3: 0000000000000000, Parameter 0 of the exception
- Arg4: ffffffffffffffff, Parameter 1 of the exception
- Debugging Details:
- ------------------
- *** WARNING: Unable to verify checksum for win32k.sys
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.mSec
- Value: 3046
- Key : Analysis.DebugAnalysisManager
- Value: Create
- Key : Analysis.Elapsed.mSec
- Value: 5361
- Key : Analysis.Init.CPU.mSec
- Value: 296
- Key : Analysis.Init.Elapsed.mSec
- Value: 6853
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 81
- Key : WER.OS.Branch
- Value: vb_release
- Key : WER.OS.Timestamp
- Value: 2019-12-06T14:06:00Z
- Key : WER.OS.Version
- Value: 10.0.19041.1
- BUGCHECK_CODE: 1e
- BUGCHECK_P1: ffffffffc0000005
- BUGCHECK_P2: fffff80042b11b56
- BUGCHECK_P3: 0
- BUGCHECK_P4: ffffffffffffffff
- READ_ADDRESS: fffff800434fb390: Unable to get MiVisibleState
- Unable to get NonPagedPoolStart
- Unable to get NonPagedPoolEnd
- Unable to get PagedPoolStart
- Unable to get PagedPoolEnd
- unable to get nt!MmSpecialPagesInUse
- ffffffffffffffff
- EXCEPTION_PARAMETER2: ffffffffffffffff
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXWINLOGON: 1
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: System
- TRAP_FRAME: fffff80381d297a7 -- (.trap 0xfffff80381d297a7)
- Unable to read trap frame at fffff803`81d297a7
- STACK_TEXT:
- ffff9c80`4f130158 fffff800`42cf5b6e : 00000000`0000001e ffffffff`c0000005 fffff800`42b11b56 00000000`00000000 : nt!KeBugCheckEx
- ffff9c80`4f130160 fffff800`42bffae2 : fffff800`42cf5b4c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!HvlpVtlCallExceptionHandler+0x22
- ffff9c80`4f1301a0 fffff800`42a87547 : ffff9c80`4f130710 00000000`00000000 ffff838a`c588bc60 fffff800`42bfa78e : nt!RtlpExecuteHandlerForException+0x12
- ffff9c80`4f1301d0 fffff800`42a86136 : ffff838a`c588b598 ffff9c80`4f130e20 ffff838a`c588b598 c9ff9c80`4f340180 : nt!RtlDispatchException+0x297
- ffff9c80`4f1308f0 fffff800`42bf7ab2 : ffff9a81`bc530210 ffffffff`c0000005 fffff803`81d297a7 fffff803`81d29558 : nt!KiDispatchException+0x186
- ffff9c80`4f130fb0 fffff800`42bf7a80 : fffff800`42c08ca5 fffff800`42ac7520 fffff800`42ac42d0 00000000`0000000c : nt!KxExceptionDispatchOnExceptionStack+0x12
- ffff838a`c588b458 fffff800`42c08ca5 : fffff800`42ac7520 fffff800`42ac42d0 00000000`0000000c ffff9c80`4f284180 : nt!KiExceptionDispatchOnExceptionStackContinue
- ffff838a`c588b460 fffff800`42c049e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x125
- ffff838a`c588b640 fffff800`42b11b56 : 00000000`00400a02 00000000`00000000 00400a02`00000010 000001fe`9817b93e : nt!KiGeneralProtectionFault+0x320
- ffff838a`c588b7d0 fffff800`42b0a996 : ffffc88d`82c7f188 ffff838a`00000000 ffffc88d`82c7f250 00000000`00000000 : nt!KiTryUnwaitThread+0x186
- ffff838a`c588b830 fffff800`42b0a53c : ffffc88d`82c7f180 00000000`00000004 ffff838a`c588bb18 ffffc88d`00000002 : nt!KiTimerWaitTest+0x1e6
- ffff838a`c588b8e0 fffff800`42b2279d : 00000000`00000000 00000000`00000000 00000000`00140001 00000000`000058ac : nt!KiProcessExpiredTimerList+0xdc
- ffff838a`c588b9d0 fffff800`42bfa78e : ffffffff`00000000 ffff9c80`4f110180 ffff9c80`4f11b340 ffffc88d`81a6a080 : nt!KiRetireDpcList+0x5dd
- ffff838a`c588bc60 00000000`00000000 : ffff838a`c588c000 ffff838a`c5886000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x9e
- SYMBOL_NAME: nt!KiTryUnwaitThread+186
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- IMAGE_VERSION: 10.0.19041.1052
- STACK_COMMAND: .thread ; .cxr ; kb
- BUCKET_ID_FUNC_OFFSET: 186
- FAILURE_BUCKET_ID: 0x1E_c0000005_R_nt!KiTryUnwaitThread
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {4abda1ba-718c-fcea-57ff-6e531adb2ce2}
- Followup: MachineOwner
- ---------
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2104.13002.0_neutral__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement