CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffb18133659380, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffb18133659380
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: svchost.exe
CRITICAL_PROCESS: svchost.exe
EXCEPTION_CODE: (NTSTATUS) 0x32fe6080 - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0x32fe6080 - <Unable to get error code text>
CPU_COUNT: 8
CPU_MHZ: e10
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: d
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-04-2020 17:37:14.0027
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8060b4cae89 to fffff8060adc14e0
STACK_TEXT:
ffffe10b`bbe62838 fffff806`0b4cae89 : 00000000`000000ef ffffb181`33659380 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffe10b`bbe62840 fffff806`0b3c75c1 : ffffb181`33659380 fffff806`0ac9c769 ffffb181`33659380 fffff806`0ac9c8c0 : nt!PspCatchCriticalBreak+0x115
ffffe10b`bbe628e0 fffff806`0b239fc0 : ffffb181`00000000 00000000`00000000 ffffb181`33659380 ffffb181`33659380 : nt!PspTerminateAllThreads+0x175e3d
ffffe10b`bbe62950 fffff806`0b239da9 : ffffffff`ffffffff ffffe10b`bbe62a80 ffffb181`33659380 fffff806`0b1c7601 : nt!PspTerminateProcess+0xe0
ffffe10b`bbe62990 fffff806`0add2d15 : ffffb181`00000414 ffffb181`32fe6080 ffffb181`33659380 00000000`00000000 : nt!NtTerminateProcess+0xa9
ffffe10b`bbe62a00 00007ffc`e22dc644 : 00007ffc`e22acef2 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000090`c88ffb08 00007ffc`e22acef2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`e22dc644
00000090`c88ffb10 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`e22acef2
THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1a4815ae145169efb197bcf2f95a4b75c1137497
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_IP:
nt!PspCatchCriticalBreak+115
fffff806`0b4cae89 cc int 3
FAULT_INSTR_CODE: ed8440cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PspCatchCriticalBreak+115
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 12dcb470
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 115
FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_32fe6080_nt!PspCatchCriticalBreak
BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_32fe6080_nt!PspCatchCriticalBreak
PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_32fe6080_nt!PspCatchCriticalBreak
TARGET_TIME: 2019-12-25T05:39:42.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 11f0
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_32fe6080_nt!pspcatchcriticalbreak
FAILURE_ID_HASH: {23bcb86b-96f1-f570-74ca-dc124f6333ce}
Followup: MachineOwner
---------
INTERNAL_POWER_ERROR (a0)
The power policy manager experienced a fatal error.
Arguments:
Arg1: 000000000000010e, The disk subsystem returned corrupt data while reading from the
hibernation file.
Arg2: 000000000000000a
Arg3: 0000000000006129, Incorrect checksum
Arg4: 0000000000006b46, Previous disk read's checksum
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 10.0.18362.535 (WinBuild.160101.0800)
DUMP_FILE_ATTRIBUTES: 0x9
Hiber Crash Dump
Kernel Generated Triage Dump
DUMP_TYPE: 2
BUGCHECK_P1: 10e
BUGCHECK_P2: a
BUGCHECK_P3: 6129
BUGCHECK_P4: 6b46
BUGCHECK_STR: 0xa0_10e
CPU_COUNT: 8
CPU_MHZ: e10
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: d
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
CURRENT_IRQL: f
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-04-2020 17:37:33.0771
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8016f1a6fa6 to fffff8016edc14e0
STACK_TEXT:
ffffbb0d`409bf1e8 fffff801`6f1a6fa6 : 00000000`000000a0 00000000`0000010e 00000000`0000000a 00000000`00006129 : nt!KeBugCheckEx
ffffbb0d`409bf1f0 fffff801`6f1af194 : 00000000`00000001 ffffe784`fac5d7d0 00000003`674b4000 ffffe785`11ae0000 : nt!PopHiberChecksumHiberFileData+0xaa26
ffffbb0d`409bf250 fffff801`6f1aeb66 : 00000001`8ce95000 ffffd78a`fe255a58 ffffbb0d`409bf350 00000000`00000002 : nt!PopRequestRead+0x78
ffffbb0d`409bf2c0 fffff801`6ed638d4 : ffffd78a`fe2558f0 ffffa881`a02f3000 00000003`00000000 fffff801`86588610 : nt!PopDecompressCallback+0x16
ffffbb0d`409bf2f0 fffff801`6ef1810b : ffffe785`11bf165e 00000000`00000029 ffffe785`11bf0000 ffffa881`a02e3000 : nt!RtlpMakeXpressCallback+0x24
ffffbb0d`409bf320 fffff801`6ef17f44 : ffffa881`a02e3000 ffffbb0d`409bf500 00000000`00010000 00007377`84380d34 : nt!RtlDecompressBufferXpressHuffProgress+0x1b3
ffffbb0d`409bf3a0 fffff801`6f1a723b : 00000000`00000001 ffffbb0d`409bf500 00000000`00000000 00000000`00010000 : nt!RtlDecompressBufferProgress+0xac
ffffbb0d`409bf400 fffff801`6f1a64be : 00000001`8cea5000 ffffd78a`fe255a58 00000000`00000001 00000000`00000001 : nt!PopDecompressHiberBlocks+0xab7b
ffffbb0d`409bf620 fffff801`6f19af9e : 00007377`74f681b8 ffffd78a`fe255a58 00000000`00000000 fffff801`6eb5e848 : nt!PopRestoreHiberContext+0xb17e
ffffbb0d`409bf6b0 fffff801`6f19acea : fffff801`6f069f90 ffffbb0d`409bf830 fffff801`6f069f90 ffffe784`fac5d7d0 : nt!PopHandleNextState+0x20e
ffffbb0d`409bf700 fffff801`6f19aa5f : 00000000`00000100 00000000`00989680 ffffe784`fac5d7d0 ffffe784`fac5d7d0 : nt!PopIssueNextState+0x1a
ffffbb0d`409bf730 fffff801`6f19b2ec : 00000000`00000010 00000000`00040282 00000000`00000000 fffff801`6ec93474 : nt!PopInvokeSystemStateHandler+0x35b
ffffbb0d`409bf930 fffff801`6f19f6aa : ffffffff`ffffffff ffffffff`ffffffff 00000000`00000014 00000000`00000000 : nt!PopEndMirroring+0x1ec
ffffbb0d`409bf9f0 fffff801`6f19f3e5 : 00000000`00000000 00000000`00000000 00000022`00000001 00000000`00000001 : nt!MmDuplicateMemory+0x26e
ffffbb0d`409bfa80 fffff801`6ed2a7a5 : ffffe785`046b8000 ffffe785`046b8040 fffff801`6f19f2c0 00000000`000000e0 : nt!PopTransitionToSleep+0x125
ffffbb0d`409bfb10 fffff801`6edc8b2a : ffffa881`9e0b9180 ffffe785`046b8040 fffff801`6ed2a750 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffbb0d`409bfb60 00000000`00000000 : ffffbb0d`409c0000 ffffbb0d`409b9000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: f0ff059cabbd0173ec1c077795d6055d7ec361e1
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 8e40e3bb30e61a850b6cabd164785f85ecf92f2c
THREAD_SHA1_HASH_MOD: aaa5a324bf1bd3082ad2b464ee2ed2f6d50e564c
FOLLOWUP_IP:
nt!PopHiberChecksumHiberFileData+aa26
fffff801`6f1a6fa6 cc int 3
FAULT_INSTR_CODE: 3840cccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PopHiberChecksumHiberFileData+aa26
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 12dcb470
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: aa26
FAILURE_BUCKET_ID: 0xa0_10e_nt!PopHiberChecksumHiberFileData
BUCKET_ID: 0xa0_10e_nt!PopHiberChecksumHiberFileData
PRIMARY_PROBLEM_CLASS: 0xa0_10e_nt!PopHiberChecksumHiberFileData
TARGET_TIME: 2019-12-29T08:45:48.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 160101.0800
BUILDLAB_STR: WinBuild
BUILDOSVER_STR: 10.0.18362.535
ANALYSIS_SESSION_ELAPSED_TIME: aec
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xa0_10e_nt!pophiberchecksumhiberfiledata
FAILURE_ID_HASH: {28ba2091-a476-6f77-2dec-6241bccd4685}
Followup: MachineOwner
---------
CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a00f59081b7661, Reserved
Arg2: b3b71bdf5a9e3332, Reserved
Arg3: ffffc01940153000, Failure type dependent information
Arg4: 000000000000000e, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
8 : Object type
9 : A processor IVT
a : Modification of a system service function
b : A generic session data region
c : Modification of a session function or .pdata
d : Modification of an import table
e : Modification of a session import table
f : Ps Win32 callout modification
10 : Debug switch routine modification
11 : IRP allocator modification
12 : Driver call dispatcher modification
13 : IRP completion dispatcher modification
14 : IRP deallocator modification
15 : A processor control register
16 : Critical floating point control register modification
17 : Local APIC modification
18 : Kernel notification callout modification
19 : Loaded module list modification
1a : Type 3 process list corruption
1b : Type 4 process list corruption
1c : Driver object corruption
1d : Executive callback object modification
1e : Modification of module padding
1f : Modification of a protected process
20 : A generic data region
21 : A page hash mismatch
22 : A session page hash mismatch
23 : Load config directory modification
24 : Inverted function table modification
25 : Session configuration modification
26 : An extended processor control register
27 : Type 1 pool corruption
28 : Type 2 pool corruption
29 : Type 3 pool corruption
2a : Type 4 pool corruption
2b : Modification of a function or .pdata
2c : Image integrity corruption
2d : Processor misconfiguration
2e : Type 5 process list corruption
2f : Process shadow corruption
30 : Retpoline code page corruption
101 : General pool corruption
102 : Modification of win32k.sys
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: a3a00f59081b7661
BUGCHECK_P2: b3b71bdf5a9e3332
BUGCHECK_P3: ffffc01940153000
BUGCHECK_P4: e
PG_MISMATCH: 8000000
FAULTING_IP:
win32kfull!_imp_KeQueryPerformanceCounter+0
ffffc019`40153000 c077cb76 sal byte ptr [rdi-35h],76h
CPU_COUNT: 8
CPU_MHZ: e10
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: d
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x109
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 2
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 01-04-2020 17:37:17.0979
ANALYSIS_VERSION: 10.0.18362.1 x86fre
STACK_TEXT:
ffff8206`54d1ed98 00000000`00000000 : 00000000`00000109 a3a00f59`081b7661 b3b71bdf`5a9e3332 ffffc019`40153000 : nt!KeBugCheckEx
THREAD_SHA1_HASH_MOD_FUNC: 81a83ae0317433a47fcc36991983df3b6e638b71
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6e16edd8c7dd677734fdbcd2397a2e35e9fae964
THREAD_SHA1_HASH_MOD: 76cd06466d098060a9eb26e5fd2a25cb1f3fe0a3
FOLLOWUP_IP:
win32kfull!_imp_KeQueryPerformanceCounter+0
ffffc019`40153000 c077cb76 sal byte ptr [rdi-35h],76h
FAULT_INSTR_CODE: 76cb77c0
SYMBOL_NAME: win32kfull!_imp_KeQueryPerformanceCounter+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32kfull
IMAGE_NAME: win32kfull.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 1be942ef
IMAGE_VERSION: 10.0.18362.535
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 0
FAILURE_BUCKET_ID: 0x109_e_win32kfull!_imp_KeQueryPerformanceCounter
BUCKET_ID: 0x109_e_win32kfull!_imp_KeQueryPerformanceCounter
PRIMARY_PROBLEM_CLASS: 0x109_e_win32kfull!_imp_KeQueryPerformanceCounter
TARGET_TIME: 2020-01-04T07:50:38.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 3294
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x109_e_win32kfull!_imp_kequeryperformancecounter
FAILURE_ID_HASH: {4c58fa6d-3887-2036-bc34-ebd60c0539e4}
Followup: MachineOwner
---------