MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8000fac440
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff80003504300
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 080015
BIOS_DATE: 12/03/2015
BASEBOARD_MANUFACTURER: INTEL
BASEBOARD_PRODUCT: INTEL H55
BASEBOARD_VERSION: INTEL
DUMP_TYPE: 2
BUGCHECK_P1: 41790
BUGCHECK_P2: fffffa8000fac440
BUGCHECK_P3: ffff
BUGCHECK_P4: 0
BUGCHECK_STR: 0x1a_41790
CPU_COUNT: 4
CPU_MHZ: d05
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 25
CPU_STEPPING: 2
CPU_MICROCODE: 6,25,2,0 (F,M,S,R) SIG: C'00000000 (cache) 9'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: taskhost.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-BKJR0DQ
ANALYSIS_SESSION_TIME: 03-05-2020 01:12:14.0303
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff800033bedfd to fffff800032faba0
STACK_TEXT:
fffff880`08e629b8 fffff800`033bedfd : 00000000`0000001a 00000000`00041790 fffffa80`00fac440 00000000`0000ffff : nt!KeBugCheckEx
fffff880`08e629c0 fffff800`03295ff4 : fffffa80`00000000 00000000`1b4fffff 00000000`00000000 00000800`00000200 : nt!MiDeleteVirtualAddresses+0x93d
fffff880`08e62b30 fffff800`03308bd3 : ffffffff`ffffffff fffffa80`074c3b50 00000000`004d2400 00000000`00008000 : nt!NtFreeVirtualMemory+0xb34
fffff880`08e62c20 00000000`774e9a6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`02fdf2e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x774e9a6a
THREAD_SHA1_HASH_MOD_FUNC: b47293e23bf0cbc79608a6a39ab32f61232c8fd9
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: cf7c322bca4874ee11d8fbfd48960d70309310f3
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!MiDeleteVirtualAddresses+93d
fffff800`033bedfd cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiDeleteVirtualAddresses+93d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 5c6e1cbd
IMAGE_VERSION: 6.1.7601.24384
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
BUCKET_ID: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
PRIMARY_PROBLEM_CLASS: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
TARGET_TIME: 2020-03-03T23:06:30.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-02-21 06:36:29
BUILDDATESTAMP_STR: 190220-1800
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
ANALYSIS_SESSION_ELAPSED_TIME: 4b1
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x1a_41790_nt!mideletevirtualaddresses+93d
FAILURE_ID_HASH: {f4a94a0f-7c3c-4cbd-b72c-ee4a493af7de}
Followup: MachineOwner
---------
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8000fac440
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff800034af300
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 080015
BIOS_DATE: 12/03/2015
BASEBOARD_MANUFACTURER: INTEL
BASEBOARD_PRODUCT: INTEL H55
BASEBOARD_VERSION: INTEL
DUMP_TYPE: 2
BUGCHECK_P1: 41790
BUGCHECK_P2: fffffa8000fac440
BUGCHECK_P3: ffff
BUGCHECK_P4: 0
BUGCHECK_STR: 0x1a_41790
CPU_COUNT: 4
CPU_MHZ: d05
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 25
CPU_STEPPING: 2
CPU_MICROCODE: 6,25,2,0 (F,M,S,R) SIG: C'00000000 (cache) 9'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: Discord.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-BKJR0DQ
ANALYSIS_SESSION_TIME: 03-05-2020 01:12:12.0093
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff80003369dfd to fffff800032a5ba0
STACK_TEXT:
fffff880`0b7839b8 fffff800`03369dfd : 00000000`0000001a 00000000`00041790 fffffa80`00fac440 00000000`0000ffff : nt!KeBugCheckEx
fffff880`0b7839c0 fffff800`03240ff4 : fffffa80`00000000 00000000`2b7fffff 00000000`00000000 00000800`00000080 : nt!MiDeleteVirtualAddresses+0x93d
fffff880`0b783b30 fffff800`032b3bd3 : ffffffff`ffffffff fffffa80`0a6af510 00000000`0924e5b8 fffffa80`00008000 : nt!NtFreeVirtualMemory+0xb34
fffff880`0b783c20 00000000`77c99a6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0924e588 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77c99a6a
THREAD_SHA1_HASH_MOD_FUNC: b47293e23bf0cbc79608a6a39ab32f61232c8fd9
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: cf7c322bca4874ee11d8fbfd48960d70309310f3
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!MiDeleteVirtualAddresses+93d
fffff800`03369dfd cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiDeleteVirtualAddresses+93d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 5c6e1cbd
IMAGE_VERSION: 6.1.7601.24384
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
BUCKET_ID: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
PRIMARY_PROBLEM_CLASS: X64_0x1a_41790_nt!MiDeleteVirtualAddresses+93d
TARGET_TIME: 2020-03-04T20:49:52.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-02-21 06:36:29
BUILDDATESTAMP_STR: 190220-1800
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
ANALYSIS_SESSION_ELAPSED_TIME: 4b4
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x1a_41790_nt!mideletevirtualaddresses+93d
FAILURE_ID_HASH: {f4a94a0f-7c3c-4cbd-b72c-ee4a493af7de}
Followup: MachineOwner
---------
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800a989548
Arg3: fffff8800a988db0
Arg4: fffff880012bb5e7
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff800034ff300
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 080015
BIOS_DATE: 12/03/2015
BASEBOARD_MANUFACTURER: INTEL
BASEBOARD_PRODUCT: INTEL H55
BASEBOARD_VERSION: INTEL
DUMP_TYPE: 2
BUGCHECK_P1: 1904fb
BUGCHECK_P2: fffff8800a989548
BUGCHECK_P3: fffff8800a988db0
BUGCHECK_P4: fffff880012bb5e7
EXCEPTION_RECORD: fffff8800a989548 -- (.exr 0xfffff8800a989548)
ExceptionAddress: fffff880012bb5e7 (Ntfs!NtfsTeardownStructures+0x0000000000000077)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff8800a988db0 -- (.cxr 0xfffff8800a988db0)
rax=fffff8800a989ab0 rbx=01d5f1b61c74c6df rcx=fffff8800a989ab0
rdx=fffff8a00e60db40 rsi=fffff8800a989cf8 rdi=fffff8800a989ab0
rip=fffff880012bb5e7 rsp=fffff8800a989780 rbp=0000000000000080
r8=0000000000000000 r9=0000000000000001 r10=fffff88001289300
r11=fffff8a0001182a0 r12=fffff8800a989a00 r13=fffffa8007cbe180
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
Ntfs!NtfsTeardownStructures+0x77:
fffff880`012bb5e7 837b1000 cmp dword ptr [rbx+10h],0 ds:002b:01d5f1b6`1c74c6ef=????????
Resetting default scope
CPU_COUNT: 4
CPU_MHZ: d05
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 25
CPU_STEPPING: 2
CPU_MICROCODE: 6,25,2,0 (F,M,S,R) SIG: C'00000000 (cache) 9'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
FOLLOWUP_IP:
Ntfs!NtfsTeardownStructures+77
fffff880`012bb5e7 837b1000 cmp dword ptr [rbx+10h],0
FAULTING_IP:
Ntfs!NtfsTeardownStructures+77
fffff880`012bb5e7 837b1000 cmp dword ptr [rbx+10h],0
BUGCHECK_STR: 0x24
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800034ff100
Unable to get MmSystemRangeStart
GetUlongPtrFromAddress: unable to read from fffff800034ff2f0
GetUlongPtrFromAddress: unable to read from fffff800034ff4a8
GetPointerFromAddress: unable to read from fffff800034ff0d8
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
ANALYSIS_SESSION_HOST: DESKTOP-BKJR0DQ
ANALYSIS_SESSION_TIME: 03-05-2020 01:12:09.0815
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from fffff8800126dd69 to fffff880012bb5e7
STACK_TEXT:
fffff880`0a989780 fffff880`0126dd69 : fffff880`0a989ab0 fffff8a0`0e60db40 00000000`00000001 fffff880`0a989a01 : Ntfs!NtfsTeardownStructures+0x77
fffff880`0a989800 fffff880`0126e620 : fffffa80`07cbe180 fffffa80`07909a70 00000000`00000001 00000000`00000000 : Ntfs!NtfsRepairItem+0xcde
fffff880`0a989ce0 fffff800`035a31a0 : ffffffff`dc3cba00 00000000`00000001 fffff880`02f64180 00000000`00000080 : Ntfs!NtfsProcessRepairQueue+0x1c0
fffff880`0a989d40 fffff800`032fbba6 : fffff880`02f64180 fffffa80`0843f100 fffffa80`06caa170 00000000`00000000 : nt!PspSystemThreadStartup+0x194
fffff880`0a989d80 00000000`00000000 : fffff880`0a98a000 fffff880`0a984000 fffff880`0a989a30 00000000`00000000 : nt!KiStartSystemThread+0x16
THREAD_SHA1_HASH_MOD_FUNC: ff13d8d04fd83409e2705fae2ffaf9c0a711600f
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6576b98fca05766f5857b979bed82f0411b6937b
THREAD_SHA1_HASH_MOD: d550b1eb413cf2794f505a10424198721476b164
FAULT_INSTR_CODE: 107b83
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsTeardownStructures+77
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce792f9
IMAGE_VERSION: 6.1.7601.17514
STACK_COMMAND: .cxr 0xfffff8800a988db0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownStructures+77
BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownStructures+77
PRIMARY_PROBLEM_CLASS: X64_0x24_Ntfs!NtfsTeardownStructures+77
TARGET_TIME: 2020-03-03T23:48:03.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-02-21 06:36:29
BUILDDATESTAMP_STR: 190220-1800
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
ANALYSIS_SESSION_ELAPSED_TIME: 4ed
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x24_ntfs!ntfsteardownstructures+77
FAILURE_ID_HASH: {bacd9162-4f97-b187-f49f-7f5bbd22be9d}
Followup: MachineOwner
---------
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000351363e, Address of the instruction which caused the bugcheck
Arg3: fffff88009329730, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff800034b3300
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 080015
BIOS_DATE: 12/03/2015
BASEBOARD_MANUFACTURER: INTEL
BASEBOARD_PRODUCT: INTEL H55
BASEBOARD_VERSION: INTEL
DUMP_TYPE: 2
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8000351363e
BUGCHECK_P3: fffff88009329730
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0351363e 418b45f4 mov eax,dword ptr [r13-0Ch]
CONTEXT: fffff88009329730 -- (.cxr 0xfffff88009329730)
rax=0000000000000009 rbx=0000000000000000 rcx=000000000000034b
rdx=0000000000000119 rsi=fffff8800932a310 rdi=0000000002687f16
rip=fffff8000351363e rsp=fffff8800932a100 rbp=fffff8a0100b9410
r8=0000000000000008 r9=0000000000000000 r10=000000000000000a
r11=fffff8800932a2b0 r12=fffff8a00b3696f8 r13=f7fff8a001d5f4b8
r14=0000000000000004 r15=0000000000000004
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!CmpKcbCacheLookup+0x1de:
fffff800`0351363e 418b45f4 mov eax,dword ptr [r13-0Ch] ds:002b:f7fff8a0`01d5f4ac=????????
Resetting default scope
BUGCHECK_STR: 0x3B_c0000005
CPU_COUNT: 4
CPU_MHZ: d05
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 25
CPU_STEPPING: 2
CPU_MICROCODE: 6,25,2,0 (F,M,S,R) SIG: C'00000000 (cache) C'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: TrustedInstaller.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-BKJR0DQ
ANALYSIS_SESSION_TIME: 03-05-2020 01:12:07.0757
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000351363e
STACK_TEXT:
fffff880`0932a100 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmpKcbCacheLookup+0x1de
THREAD_SHA1_HASH_MOD_FUNC: 54d81104fabb5fde4db8e833801094376583f6cc
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: f857b03f8571042677125c0cf69ea31c19f9228f
THREAD_SHA1_HASH_MOD: 76cd06466d098060a9eb26e5fd2a25cb1f3fe0a3
FOLLOWUP_IP:
nt!CmpKcbCacheLookup+1de
fffff800`0351363e 418b45f4 mov eax,dword ptr [r13-0Ch]
FAULT_INSTR_CODE: f4458b41
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKcbCacheLookup+1de
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5c6e1cbd
IMAGE_VERSION: 6.1.7601.24384
STACK_COMMAND: .cxr 0xfffff88009329730 ; kb
FAILURE_BUCKET_ID: X64_0x3B_c0000005_nt!CmpKcbCacheLookup+1de
BUCKET_ID: X64_0x3B_c0000005_nt!CmpKcbCacheLookup+1de
PRIMARY_PROBLEM_CLASS: X64_0x3B_c0000005_nt!CmpKcbCacheLookup+1de
TARGET_TIME: 2020-03-03T22:19:24.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-02-21 06:36:29
BUILDDATESTAMP_STR: 190220-1800
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
ANALYSIS_SESSION_ELAPSED_TIME: 4db
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x3b_c0000005_nt!cmpkcbcachelookup+1de
FAILURE_ID_HASH: {ee286f6f-68f8-815c-cfe8-5fbd1b407201}
Followup: MachineOwner
---------
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8800f02a0d4, Address of the instruction which caused the bugcheck
Arg3: fffff88008b89a30, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
GetUlongPtrFromAddress: unable to read from fffff800034e5300
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 080015
BIOS_DATE: 12/03/2015
BASEBOARD_MANUFACTURER: INTEL
BASEBOARD_PRODUCT: INTEL H55
BASEBOARD_VERSION: INTEL
DUMP_TYPE: 2
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8800f02a0d4
BUGCHECK_P3: fffff88008b89a30
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
atikmdag+16a0d4
fffff880`0f02a0d4 488b5108 mov rdx,qword ptr [rcx+8]
CONTEXT: fffff88008b89a30 -- (.cxr 0xfffff88008b89a30)
rax=0000000000000000 rbx=fffff8a016c23220 rcx=0800000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000003
rip=fffff8800f02a0d4 rsp=fffff88008b8a400 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=fffff88002d64e20
r11=fffffa80099d1750 r12=fffff8a016c23168 r13=fffff8a016c23000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
atikmdag+0x16a0d4:
fffff880`0f02a0d4 488b5108 mov rdx,qword ptr [rcx+8] ds:002b:08000000`00000008=????????????????
Resetting default scope
BUGCHECK_STR: 0x3B_c0000005
CPU_COUNT: 4
CPU_MHZ: d05
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 25
CPU_STEPPING: 2
CPU_MICROCODE: 6,25,2,0 (F,M,S,R) SIG: C'00000000 (cache) 9'00000000 (init)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: Spotify.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-BKJR0DQ
ANALYSIS_SESSION_TIME: 03-05-2020 01:12:04.0750
ANALYSIS_VERSION: 10.0.18362.1 amd64fre
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8800f02a0d4
STACK_TEXT:
fffff880`08b8a400 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : atikmdag+0x16a0d4
THREAD_SHA1_HASH_MOD_FUNC: b707fffe94678f64fa20640ed32c4c0e284df15c
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1cc2ae91b1e931294b0703a28d60523a5a679dd2
THREAD_SHA1_HASH_MOD: b707fffe94678f64fa20640ed32c4c0e284df15c
FOLLOWUP_IP:
atikmdag+16a0d4
fffff880`0f02a0d4 488b5108 mov rdx,qword ptr [rcx+8]
FAULT_INSTR_CODE: 8518b48
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: atikmdag+16a0d4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: atikmdag
IMAGE_NAME: atikmdag.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 5d976fcf
STACK_COMMAND: .cxr 0xfffff88008b89a30 ; kb
FAILURE_BUCKET_ID: X64_0x3B_c0000005_atikmdag+16a0d4
BUCKET_ID: X64_0x3B_c0000005_atikmdag+16a0d4
PRIMARY_PROBLEM_CLASS: X64_0x3B_c0000005_atikmdag+16a0d4
TARGET_TIME: 2020-03-03T22:55:05.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-02-21 06:36:29
BUILDDATESTAMP_STR: 190220-1800
BUILDLAB_STR: win7sp1_ldr_escrow
BUILDOSVER_STR: 6.1.7601.24384.amd64fre.win7sp1_ldr_escrow.190220-1800
ANALYSIS_SESSION_ELAPSED_TIME: ab8
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x3b_c0000005_atikmdag+16a0d4
FAILURE_ID_HASH: {37358837-0193-7d67-0dcb-9cd5505403a7}
Followup: MachineOwner
---------