Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.19494.1001 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Users\User\Desktop\minidump\101519-18765-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 18362 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- Machine Name:
- Kernel base = 0xfffff804`2c000000 PsLoadedModuleList = 0xfffff804`2c448210
- Debug session time: Tue Oct 15 17:17:00.869 2019 (UTC + 2:00)
- System Uptime: 0 days 6:57:08.541
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- .............................................
- Loading User Symbols
- Loading unloaded module list
- .........
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff804`2c1c1220 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffa86`036a08d0=0000000000000018
- 1: kd> !analyze
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- REFERENCE_BY_POINTER (18)
- Arguments:
- Arg1: 0000000000000000, Object type of the object whose reference count is being lowered
- Arg2: ffffd1030b0c2080, Object whose reference count is being lowered
- Arg3: 0000000000000006, Reserved
- Arg4: ffffffffffffffff, Reserved
- The reference count of an object is illegal for the current state of the object.
- Each time a driver uses a pointer to an object the driver calls a kernel routine
- to increment the reference count of the object. When the driver is done with the
- pointer the driver calls another kernel routine to decrement the reference count.
- Drivers must match calls to the increment and decrement routines. This bugcheck
- can occur because an object's reference count goes to zero while there are still
- open handles to the object, in which case the fourth parameter indicates the number
- of opened handles. It may also occur when the object's reference count drops below zero
- whether or not there are open handles to the object, and in that case the fourth parameter
- contains the actual value of the pointer references count.
- Debugging Details:
- ------------------
- *** WARNING: Unable to verify checksum for win32k.sys
- BUGCHECK_CODE: 18
- BUGCHECK_P1: 0
- BUGCHECK_P2: ffffd1030b0c2080
- BUGCHECK_P3: 6
- BUGCHECK_P4: ffffffffffffffff
- PROCESS_NAME: System
- SYMBOL_NAME: nt!IopDecrementDeviceObjectRef+1c2834
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- FAILURE_BUCKET_ID: 0x18_nt!IopDecrementDeviceObjectRef
- FAILURE_ID_HASH: {5152315d-027b-14f6-89cb-14807d0ae67b}
- Followup: MachineOwner
- ---------
- 1: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- REFERENCE_BY_POINTER (18)
- Arguments:
- Arg1: 0000000000000000, Object type of the object whose reference count is being lowered
- Arg2: ffffd1030b0c2080, Object whose reference count is being lowered
- Arg3: 0000000000000006, Reserved
- Arg4: ffffffffffffffff, Reserved
- The reference count of an object is illegal for the current state of the object.
- Each time a driver uses a pointer to an object the driver calls a kernel routine
- to increment the reference count of the object. When the driver is done with the
- pointer the driver calls another kernel routine to decrement the reference count.
- Drivers must match calls to the increment and decrement routines. This bugcheck
- can occur because an object's reference count goes to zero while there are still
- open handles to the object, in which case the fourth parameter indicates the number
- of opened handles. It may also occur when the object's reference count drops below zero
- whether or not there are open handles to the object, and in that case the fourth parameter
- contains the actual value of the pointer references count.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.Sec
- Value: 3
- Key : Analysis.DebugAnalysisProvider.CPP
- Value: Create: 8007007e on DESKTOP-QL4QG86
- Key : Analysis.DebugData
- Value: CreateObject
- Key : Analysis.DebugModel
- Value: CreateObject
- Key : Analysis.Elapsed.Sec
- Value: 5
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 70
- Key : Analysis.System
- Value: CreateObject
- BUGCHECK_CODE: 18
- BUGCHECK_P1: 0
- BUGCHECK_P2: ffffd1030b0c2080
- BUGCHECK_P3: 6
- BUGCHECK_P4: ffffffffffffffff
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXPNP: 1 (!blackboxpnp)
- BLACKBOXWINLOGON: 1
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: System
- STACK_TEXT:
- fffffa86`036a08c8 fffff804`2c1f44a4 : 00000000`00000018 00000000`00000000 ffffd103`0b0c2080 00000000`00000006 : nt!KeBugCheckEx
- fffffa86`036a08d0 fffff804`2c5e7362 : ffffd103`0e12dc50 ffffd103`0aa1ddb0 00000000`00000000 ffffd103`0b325030 : nt!IopDecrementDeviceObjectRef+0x1c2834
- fffffa86`036a0920 fffff804`2c5f94c0 : ffffd103`035d0a80 00000000`00000000 ffffd103`035d5e80 ffffd103`0af18788 : nt!IopDeleteFile+0x1b2
- fffffa86`036a09a0 fffff804`2c039084 : 00000000`00000000 00000000`00000000 ffffd103`035d0a80 ffffd103`0e12dc50 : nt!ObpRemoveObjectRoutine+0x80
- fffffa86`036a0a00 fffff804`2c08aa58 : fffffa86`036a0a00 fffffa86`036a0ae8 ffffd103`0af18670 fffffa86`036a0ae8 : nt!ObfDereferenceObject+0xa4
- fffffa86`036a0a40 fffff804`2c08b8f0 : 00000000`00002278 fffffa86`036a0b09 ffffd103`0cf72040 00000000`00000000 : nt!CcDeleteSharedCacheMap+0x18c
- fffffa86`036a0a90 fffff804`2c0bd465 : ffffd103`03474b00 fffff804`00000000 00000000`00002278 fffffa86`030aea90 : nt!CcWriteBehindInternal+0x3a0
- fffffa86`036a0b70 fffff804`2c12a725 : ffffd103`0a957040 00000000`00000080 ffffd103`03496300 00000000`00000000 : nt!ExpWorkerThread+0x105
- fffffa86`036a0c10 fffff804`2c1c886a : ffff9401`8d344180 ffffd103`0a957040 fffff804`2c12a6d0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- fffffa86`036a0c60 00000000`00000000 : fffffa86`036a1000 fffffa86`0369b000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
- SYMBOL_NAME: nt!IopDecrementDeviceObjectRef+1c2834
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- IMAGE_VERSION: 10.0.18362.418
- STACK_COMMAND: .thread ; .cxr ; kb
- BUCKET_ID_FUNC_OFFSET: 1c2834
- FAILURE_BUCKET_ID: 0x18_nt!IopDecrementDeviceObjectRef
- OS_VERSION: 10.0.18362.1
- BUILDLAB_STR: 19h1_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {5152315d-027b-14f6-89cb-14807d0ae67b}
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement