SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff807722277de, Address of the instruction which caused the bugcheck
Arg3: fffff28054644d50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P1.80
BIOS_DATE: 07/31/2013
BASEBOARD_MANUFACTURER: ASRock
BASEBOARD_PRODUCT: 970 Extreme3
BASEBOARD_VERSION:
DUMP_TYPE: 2
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff807722277de
BUGCHECK_P3: fffff28054644d50
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
nt!CmpKeyNodeNeedsAccessBitUpdate+2
fffff807`722277de a0000000a901800000 mov al,byte ptr [00008001A9000000h]
CONTEXT: fffff28054644d50 -- (.cxr 0xfffff28054644d50)
rax=000002a97b721f8c rbx=ffffc8080e61a000 rcx=ffffc8080e61a000
rdx=000002a97b721f8c rsi=0000000000000000 rdi=0000000001090f88
rip=fffff807722277de rsp=fffff28054645748 rbp=fffff28054645850
r8=0000000000000007 r9=ffff85058d3670c0 r10=000002a97b721f88
r11=0000000000000f88 r12=0000000000000000 r13=0000000000000000
r14=ffffc80819ee17a0 r15=000002a97b721f8c
iopl=0 nv up ei pl nz ac pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010212
nt!CmpKeyNodeNeedsAccessBitUpdate+0x2:
fffff807`722277de a0000000a901800000 mov al,byte ptr [00008001A9000000h] ds:002b:00008001`a9000000=??
Resetting default scope
BUGCHECK_STR: 0x3B_c0000005
CPU_COUNT: 6
CPU_MHZ: dac
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 15
CPU_MODEL: 2
CPU_STEPPING: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: Registry
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-7KGVC4E
ANALYSIS_SESSION_TIME: 03-29-2020 16:35:42.0867
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
MISALIGNED_IP:
nt!CmpKeyNodeNeedsAccessBitUpdate+2
fffff807`722277de a0000000a901800000 mov al,byte ptr [00008001A9000000h]
LAST_CONTROL_TRANSFER: from fffff807722255fc to fffff807722277de
STACK_TEXT:
fffff280`54645748 fffff807`722255fc : ffffc808`0e61a000 00000000`01090f88 ffffc808`19ee17a0 ffffc808`0e61a000 : nt!CmpKeyNodeNeedsAccessBitUpdate+0x2
fffff280`54645750 fffff807`722251b5 : 00000006`00000005 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmEnumerateKey+0x1cc
fffff280`54645880 fffff807`71dd2d18 : 00000000`00000c18 00000006`7ee7d608 fffff280`54645aa8 00000000`0003001f : nt!NtEnumerateKey+0x375
fffff280`54645a90 00007ffd`3931c704 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000006`7ee7d248 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`3931c704
THREAD_SHA1_HASH_MOD_FUNC: c0d2392294ede82a7099605a0c6b863c900b5892
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: afb1cdb09ebbeaab974cef0c79ebc000d0d2a101
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!CmpKeyNodeNeedsAccessBitUpdate+2
fffff807`722277de a0000000a901800000 mov al,byte ptr [00008001A9000000h]
FAULT_INSTR_CODE: a0
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKeyNodeNeedsAccessBitUpdate+2
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.592
STACK_COMMAND: .cxr 0xfffff28054644d50 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: IP_MISALIGNED
BUCKET_ID: IP_MISALIGNED
PRIMARY_PROBLEM_CLASS: IP_MISALIGNED
TARGET_TIME: 2020-03-29T13:12:36.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 246d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:ip_misaligned
FAILURE_ID_HASH: {201b0e5d-db2a-63d2-77be-8ce8ff234750}
Followup: MachineOwner
---------
CACHE_MANAGER (34)
See the comment for FAT_FILE_SYSTEM (0x23)
Arguments:
Arg1: 0000000000051359
Arg2: ffff810fed5e9728
Arg3: ffffb4816c1f1930
Arg4: fffff8050cc8ad52
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P1.80
BIOS_DATE: 07/31/2013
BASEBOARD_MANUFACTURER: ASRock
BASEBOARD_PRODUCT: 970 Extreme3
BASEBOARD_VERSION:
DUMP_TYPE: 2
BUGCHECK_P1: 51359
BUGCHECK_P2: ffff810fed5e9728
BUGCHECK_P3: ffffb4816c1f1930
BUGCHECK_P4: fffff8050cc8ad52
EXCEPTION_RECORD: ffff810fed5e9728 -- (.exr 0xffff810fed5e9728)
ExceptionAddress: fffff8050cc8ad52 (nt!CcLazyWriteScan+0x00000000000001f2)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: ffffb4816c1f1930 -- (.cxr 0xffffb4816c1f1930)
rax=ffff8a8aed3924b0 rbx=ffff208aedbccbf0 rcx=0000000011040204
rdx=0000000000010020 rsi=ffff8a8ae665c702 rdi=ffff8a8ae665c5a0
rip=fffff8050cc8ad52 rsp=ffff810fed5e9960 rbp=ffff810fed5e99e9
r8=000000000002625a r9=ffff8a8ae82fbda8 r10=ffff8a8ae84eccf0
r11=ffff810fed5e98f0 r12=00000000fffeffff r13=ffff208aedbccc78
r14=ffff8a8ae665c5e8 r15=0000000000000001
iopl=0 nv up ei ng nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010287
nt!CcLazyWriteScan+0x1f2:
fffff805`0cc8ad52 4c8b4360 mov r8,qword ptr [rbx+60h] ds:002b:ffff208a`edbccc50=????????????????
Resetting default scope
CPU_COUNT: 6
CPU_MHZ: dac
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 15
CPU_MODEL: 2
CPU_STEPPING: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
FOLLOWUP_IP:
nt!CcLazyWriteScan+1f2
fffff805`0cc8ad52 4c8b4360 mov r8,qword ptr [rbx+60h]
FAULTING_IP:
nt!CcLazyWriteScan+1f2
fffff805`0cc8ad52 4c8b4360 mov r8,qword ptr [rbx+60h]
BUGCHECK_STR: 0x34
READ_ADDRESS: fffff8050d1733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
ANALYSIS_SESSION_HOST: DESKTOP-7KGVC4E
ANALYSIS_SESSION_TIME: 03-29-2020 16:35:45.0020
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
BAD_STACK_POINTER: ffffb4816c1f1098
LAST_CONTROL_TRANSFER: from fffff8050cc8c50b to fffff8050cc8ad52
STACK_TEXT:
ffff810f`ed5e9960 fffff805`0cc8c50b : 00000000`00000000 00000000`00000000 ffff8a8a`00000004 fffff805`0d18f200 : nt!CcLazyWriteScan+0x1f2
ffff810f`ed5e9a50 fffff805`0ccbd095 : ffff8a8a`e665f4b0 ffff8a8a`ed41d040 ffff8a8a`e665f4b0 ffff8a8a`e665f4b0 : nt!CcWorkerThread+0x29b
ffff810f`ed5e9b70 fffff805`0cd2a7a5 : ffff8a8a`ed41d040 00000000`00000080 ffff8a8a`e6682040 00000224`acbb3dfe : nt!ExpWorkerThread+0x105
ffff810f`ed5e9c10 fffff805`0cdc8b2a : ffffb481`6c680180 ffff8a8a`ed41d040 fffff805`0cd2a750 00521300`0072006f : nt!PspSystemThreadStartup+0x55
ffff810f`ed5e9c60 00000000`00000000 : ffff810f`ed5ea000 ffff810f`ed5e4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 1352721bfac627672d2ef2913281d157d2d74f2e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6a428ff27b29602c79e7a0c2b69824ccee980407
THREAD_SHA1_HASH_MOD: f08ac56120cad14894587db086f77ce277bfae84
FAULT_INSTR_CODE: 60438b4c
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CcLazyWriteScan+1f2
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4f6eba0
IMAGE_VERSION: 10.0.18362.592
STACK_COMMAND: .cxr 0xffffb4816c1f1930 ; kb
BUCKET_ID_FUNC_OFFSET: 1f2
FAILURE_BUCKET_ID: 0x34_STACKPTR_ERROR_nt!CcLazyWriteScan
BUCKET_ID: 0x34_STACKPTR_ERROR_nt!CcLazyWriteScan
PRIMARY_PROBLEM_CLASS: 0x34_STACKPTR_ERROR_nt!CcLazyWriteScan
TARGET_TIME: 2020-03-28T18:27:49.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 1c07
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x34_stackptr_error_nt!cclazywritescan
FAILURE_ID_HASH: {da713ec5-aaea-923c-870a-08ee97223003}
Followup: MachineOwner
---------
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000008, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ExceptionRecord ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ContextRecord ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P1.80
BIOS_DATE: 07/31/2013
BASEBOARD_MANUFACTURER: ASRock
BASEBOARD_PRODUCT: 970 Extreme3
BASEBOARD_VERSION:
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: 0
BUGCHECK_P3: 8
BUGCHECK_P4: 0
CPU_COUNT: 6
CPU_MHZ: dac
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 15
CPU_MODEL: 2
CPU_STEPPING: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: opera.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-7KGVC4E
ANALYSIS_SESSION_TIME: 03-29-2020 16:35:48.0684
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
EXCEPTION_RECORD: ffffb1d8ec763000 -- (.exr 0xffffb1d8ec763000)
ExceptionAddress: 0000000000000000
ExceptionCode: 55ad3867
ExceptionFlags: 0a000001
NumberParameters: 0
TRAP_FRAME: ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000
LAST_CONTROL_TRANSFER: from fffff80323a2fda7 to fffff803239c14e0
STACK_TEXT:
ffff9a88`56644ee8 fffff803`23a2fda7 : 00000000`0000001e ffffffff`c0000005 00000000`00000000 00000000`00000008 : nt!KeBugCheckEx
ffff9a88`56644ef0 fffff803`239d341d : ffffb1d8`ec763000 ffff9a88`56645780 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x1689d7
ffff9a88`566455a0 fffff803`239cf605 : 00000000`00000000 00000000`00000000 ffff9c80`77680180 00000000`00000000 : nt!KiExceptionDispatch+0x11d
ffff9a88`56645780 00000000`00000000 : 00000000`00000000 ffff9c80`77680180 00000000`00000000 ffff870b`8216d230 : nt!KiPageFault+0x445
THREAD_SHA1_HASH_MOD_FUNC: 2e9ab7e93b3f60731b8608f9c5cc37cdb42d594f
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: ad4e40938d7ce4649a69b0de8cb803599f411381
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!KiDispatchException+1689d7
fffff803`23a2fda7 cc int 3
FAULT_INSTR_CODE: 86f741cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!KiDispatchException+1689d7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4f6eba0
IMAGE_VERSION: 10.0.18362.592
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 1689d7
FAILURE_BUCKET_ID: 0x1E_nt!KiDispatchException
BUCKET_ID: 0x1E_nt!KiDispatchException
PRIMARY_PROBLEM_CLASS: 0x1E_nt!KiDispatchException
TARGET_TIME: 2020-03-28T18:26:42.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 2278
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x1e_nt!kidispatchexception
FAILURE_ID_HASH: {4c003660-11e1-3fb7-2474-3522eb7ee67b}
Followup: MachineOwner
---------
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffdb02290f3140, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P1.80
BIOS_DATE: 07/31/2013
BASEBOARD_MANUFACTURER: ASRock
BASEBOARD_PRODUCT: 970 Extreme3
BASEBOARD_VERSION:
DUMP_TYPE: 2
BUGCHECK_P1: ffffdb02290f3140
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: csrss.exe
CRITICAL_PROCESS: csrss.exe
EXCEPTION_CODE: (Win32) 0x29989080 (697864320) - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0x29989080 - <Unable to get error code text>
CPU_COUNT: 6
CPU_MHZ: dac
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 15
CPU_MODEL: 2
CPU_STEPPING: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-7KGVC4E
ANALYSIS_SESSION_TIME: 03-29-2020 16:35:52.0206
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff80238ccae89 to fffff802385c14e0
STACK_TEXT:
ffff9c0b`9c9d2938 fffff802`38ccae89 : 00000000`000000ef ffffdb02`290f3140 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffff9c0b`9c9d2940 fffff802`38bc75c1 : ffffdb02`290f3140 fffff802`3849c769 ffffdb02`290f3140 fffff802`3849c8c0 : nt!PspCatchCriticalBreak+0x115
ffff9c0b`9c9d29e0 fffff802`38a39fc0 : ffffdb02`00000000 00000000`00000000 ffffdb02`290f3140 ffffdb02`290f3140 : nt!PspTerminateAllThreads+0x175e3d
ffff9c0b`9c9d2a50 fffff802`38a39da9 : ffffffff`ffffffff ffff9c0b`9c9d2b80 ffffdb02`290f3140 ffff9c0b`9c9d2a01 : nt!PspTerminateProcess+0xe0
ffff9c0b`9c9d2a90 fffff802`385d2d18 : ffffdb02`0000026c ffffdb02`29989080 ffffdb02`290f3140 00000000`00000000 : nt!NtTerminateProcess+0xa9
ffff9c0b`9c9d2b00 00007ff8`9665c644 : 00007ff8`93478301 000001da`18646bc0 000001da`18646bd8 ffffffff`ee1e5d00 : nt!KiSystemServiceCopyEnd+0x28
0000005f`f9abcfa8 00007ff8`93478301 : 000001da`18646bc0 000001da`18646bd8 ffffffff`ee1e5d00 00000000`00000368 : 0x00007ff8`9665c644
0000005f`f9abcfb0 000001da`18646bc0 : 000001da`18646bd8 ffffffff`ee1e5d00 00000000`00000368 00000000`ffffffff : 0x00007ff8`93478301
0000005f`f9abcfb8 000001da`18646bd8 : ffffffff`ee1e5d00 00000000`00000368 00000000`ffffffff 00000000`00000001 : 0x000001da`18646bc0
0000005f`f9abcfc0 ffffffff`ee1e5d00 : 00000000`00000368 00000000`ffffffff 00000000`00000001 00000100`00000000 : 0x000001da`18646bd8
0000005f`f9abcfc8 00000000`00000368 : 00000000`ffffffff 00000000`00000001 00000100`00000000 00007ff8`932ecc7a : 0xffffffff`ee1e5d00
0000005f`f9abcfd0 00000000`ffffffff : 00000000`00000001 00000100`00000000 00007ff8`932ecc7a 00007ff8`933720a6 : 0x368
0000005f`f9abcfd8 00000000`00000001 : 00000100`00000000 00007ff8`932ecc7a 00007ff8`933720a6 000001da`18646bc0 : 0xffffffff
0000005f`f9abcfe0 00000100`00000000 : 00007ff8`932ecc7a 00007ff8`933720a6 000001da`18646bc0 00000000`ffffffff : 0x1
0000005f`f9abcfe8 00007ff8`932ecc7a : 00007ff8`933720a6 000001da`18646bc0 00000000`ffffffff 00000000`00000000 : 0x00000100`00000000
0000005f`f9abcff0 00007ff8`933720a6 : 000001da`18646bc0 00000000`ffffffff 00000000`00000000 00000000`00000000 : 0x00007ff8`932ecc7a
0000005f`f9abcff8 000001da`18646bc0 : 00000000`ffffffff 00000000`00000000 00000000`00000000 0000005f`f9abd020 : 0x00007ff8`933720a6
0000005f`f9abd000 00000000`ffffffff : 00000000`00000000 00000000`00000000 0000005f`f9abd020 000064ad`16890f72 : 0x000001da`18646bc0
0000005f`f9abd008 00000000`00000000 : 00000000`00000000 0000005f`f9abd020 000064ad`16890f72 00000000`ffff0101 : 0xffffffff
THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 579718d2ac9cadd09055086e52eaaf605eedcd78
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_IP:
nt!PspCatchCriticalBreak+115
fffff802`38ccae89 cc int 3
FAULT_INSTR_CODE: ed8440cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PspCatchCriticalBreak+115
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4f6eba0
IMAGE_VERSION: 10.0.18362.592
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 115
FAILURE_BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_29989080_nt!PspCatchCriticalBreak
BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_29989080_nt!PspCatchCriticalBreak
PRIMARY_PROBLEM_CLASS: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_29989080_nt!PspCatchCriticalBreak
TARGET_TIME: 2020-03-28T17:36:12.000Z
OSBUILD: 18362
OSSERVICEPACK: 592
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1972-08-22 03:24:00
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 192c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_csrss.exe_bugcheck_critical_process_29989080_nt!pspcatchcriticalbreak
FAILURE_ID_HASH: {c8806b48-3583-0307-1d0f-e1a4a895ffe9}
Followup: MachineOwner
---------