*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffd70f0a3b8140, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
ETW minidump data unavailable
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffd70f0a3b8140
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: csrss.exe
CRITICAL_PROCESS: csrss.exe
EXCEPTION_CODE: (Win32) 0xacaf080 (181072000) - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0xacaf080 - <Unable to get error code text>
CRITICAL_PROCESS_REPORTGUID: {a295cce6-e274-4493-a9c2-e3d81892c654}
IMAGE_NAME: ntdll.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: ntdll
FAULTING_MODULE: 0000000000000000
CPU_COUNT: c
CPU_MHZ: ed8
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 71
CPU_STEPPING: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-15-2019 10:11:46.0611
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8067cacae89 to fffff8067c3c14e0
STACK_TEXT:
ffffd408`cb6f9938 fffff806`7cacae89 : 00000000`000000ef ffffd70f`0a3b8140 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffd408`cb6f9940 fffff806`7c9c75c1 : ffffd70f`0a3b8140 000000e5`615bf101 ffffd70f`0acaf3a0 ffffd70f`0a3b8420 : nt!PspCatchCriticalBreak+0x115
ffffd408`cb6f99e0 fffff806`7c839fc0 : ffffd70f`00000000 00000000`00000000 ffffd70f`0a3b8140 ffffd70f`0a3b8140 : nt!PspTerminateAllThreads+0x175e3d
ffffd408`cb6f9a50 fffff806`7c839da9 : ffffffff`ffffffff ffffd408`cb6f9b80 ffffd70f`0a3b8140 ffffd408`cb6f9a01 : nt!PspTerminateProcess+0xe0
ffffd408`cb6f9a90 fffff806`7c3d2d18 : ffffd70f`0000031c ffffd70f`0acaf080 ffffd70f`0a3b8140 00000000`00000000 : nt!NtTerminateProcess+0xa9
ffffd408`cb6f9b00 00007ffa`1e93c644 : 00007ffa`1b758301 000001f4`ba280000 00000000`00001000 ffffffff`ee1e5d00 : nt!KiSystemServiceCopyEnd+0x28
000000e5`615be3e8 00007ffa`1b758301 : 000001f4`ba280000 00000000`00001000 ffffffff`ee1e5d00 00000000`00000294 : 0x00007ffa`1e93c644
000000e5`615be3f0 000001f4`ba280000 : 00000000`00001000 ffffffff`ee1e5d00 00000000`00000294 000000e5`615be8c8 : 0x00007ffa`1b758301
000000e5`615be3f8 00000000`00001000 : ffffffff`ee1e5d00 00000000`00000294 000000e5`615be8c8 000001f4`ba280000 : 0x000001f4`ba280000
000000e5`615be400 ffffffff`ee1e5d00 : 00000000`00000294 000000e5`615be8c8 000001f4`ba280000 00000100`01000000 : 0x1000
000000e5`615be408 00000000`00000294 : 000000e5`615be8c8 000001f4`ba280000 00000100`01000000 00000000`00000000 : 0xffffffff`ee1e5d00
000000e5`615be410 000000e5`615be8c8 : 000001f4`ba280000 00000100`01000000 00000000`00000000 00007ffa`1b6257c8 : 0x294
000000e5`615be418 000001f4`ba280000 : 00000100`01000000 00000000`00000000 00007ffa`1b6257c8 00007ffa`1e8f35d0 : 0x000000e5`615be8c8
000000e5`615be420 00000100`01000000 : 00000000`00000000 00007ffa`1b6257c8 00007ffa`1e8f35d0 000001f4`ba170100 : 0x000001f4`ba280000
000000e5`615be428 00000000`00000000 : 00007ffa`1b6257c8 00007ffa`1e8f35d0 000001f4`ba170100 000001f4`ba200000 : 0x00000100`01000000
THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 579718d2ac9cadd09055086e52eaaf605eedcd78
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_NAME: MachineOwner
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_acaf080_ntdll.dll!NtReadVirtualMemory_IMAGE_ntdll.dll
BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_acaf080_ntdll.dll!NtReadVirtualMemory_IMAGE_ntdll.dll
PRIMARY_PROBLEM_CLASS: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_acaf080_ntdll.dll!NtReadVirtualMemory_IMAGE_ntdll.dll
TARGET_TIME: 2019-12-14T23:38:55.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 1abc
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_csrss.exe_bugcheck_critical_process_acaf080_ntdll.dll!ntreadvirtualmemory_image_ntdll.dll
FAILURE_ID_HASH: {c541b907-1931-a461-290f-b11e91698490}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffa989d7baf140, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
ETW minidump data unavailable
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffa989d7baf140
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: csrss.exe
CRITICAL_PROCESS: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xd7ca4080 - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0xd7ca4080 - <Unable to get error code text>
CRITICAL_PROCESS_REPORTGUID: {7bbae2ff-8b22-4901-a80d-ab5158c43b82}
IMAGE_NAME: ntdll.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: ntdll
FAULTING_MODULE: 0000000000000000
CPU_COUNT: c
CPU_MHZ: ed8
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 71
CPU_STEPPING: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-15-2019 10:11:50.0954
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80566acae89 to fffff805663c14e0
STACK_TEXT:
ffff818d`1b2f7938 fffff805`66acae89 : 00000000`000000ef ffffa989`d7baf140 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffff818d`1b2f7940 fffff805`669c75c1 : ffffa989`d7baf140 fffff805`6629c769 ffffa989`d7baf140 fffff805`6629c8c0 : nt!PspCatchCriticalBreak+0x115
ffff818d`1b2f79e0 fffff805`66839fc0 : ffffa989`00000000 00000000`00000000 ffffa989`d7baf140 ffffa989`d7baf140 : nt!PspTerminateAllThreads+0x175e3d
ffff818d`1b2f7a50 fffff805`66839da9 : ffffffff`ffffffff ffff818d`1b2f7b80 ffffa989`d7baf140 ffff818d`1b2f7a01 : nt!PspTerminateProcess+0xe0
ffff818d`1b2f7a90 fffff805`663d2d18 : ffffa989`00000320 ffffa989`d7ca4080 ffffa989`d7baf140 00000000`00000000 : nt!NtTerminateProcess+0xa9
ffff818d`1b2f7b00 00007ffb`44b5c644 : 00007ffb`41978301 00000000`000000ca 000000c9`5a91dec8 ffffffff`ee1e5d00 : nt!KiSystemServiceCopyEnd+0x28
000000c9`5a91dee8 00007ffb`41978301 : 00000000`000000ca 000000c9`5a91dec8 ffffffff`ee1e5d00 00000000`00000940 : 0x00007ffb`44b5c644
000000c9`5a91def0 00000000`000000ca : 000000c9`5a91dec8 ffffffff`ee1e5d00 00000000`00000940 000000c9`5a91e370 : 0x00007ffb`41978301
000000c9`5a91def8 000000c9`5a91dec8 : ffffffff`ee1e5d00 00000000`00000940 000000c9`5a91e370 000000c9`5a91e370 : 0xca
000000c9`5a91df00 ffffffff`ee1e5d00 : 00000000`00000940 000000c9`5a91e370 000000c9`5a91e370 00000100`5a91e370 : 0x000000c9`5a91dec8
000000c9`5a91df08 00000000`00000940 : 000000c9`5a91e370 000000c9`5a91e370 00000100`5a91e370 000002b8`e1478b00 : 0xffffffff`ee1e5d00
000000c9`5a91df10 000000c9`5a91e370 : 000000c9`5a91e370 00000100`5a91e370 000002b8`e1478b00 00000000`00000001 : 0x940
000000c9`5a91df18 000000c9`5a91e370 : 00000100`5a91e370 000002b8`e1478b00 00000000`00000001 00007ffb`417ead5f : 0x000000c9`5a91e370
000000c9`5a91df20 00000100`5a91e370 : 000002b8`e1478b00 00000000`00000001 00007ffb`417ead5f 000002b8`00000000 : 0x000000c9`5a91e370
000000c9`5a91df28 000002b8`e1478b00 : 00000000`00000001 00007ffb`417ead5f 000002b8`00000000 00000000`00000260 : 0x00000100`5a91e370
000000c9`5a91df30 00000000`00000001 : 00007ffb`417ead5f 000002b8`00000000 00000000`00000260 00000000`00000000 : 0x000002b8`e1478b00
000000c9`5a91df38 00007ffb`417ead5f : 000002b8`00000000 00000000`00000260 00000000`00000000 000000c9`5a91df89 : 0x1
000000c9`5a91df40 000002b8`00000000 : 00000000`00000260 00000000`00000000 000000c9`5a91df89 0000a0c5`f714a572 : 0x00007ffb`417ead5f
000000c9`5a91df48 00000000`00000260 : 00000000`00000000 000000c9`5a91df89 0000a0c5`f714a572 0063006d`00000002 : 0x000002b8`00000000
000000c9`5a91df50 00000000`00000000 : 000000c9`5a91df89 0000a0c5`f714a572 0063006d`00000002 00000000`00000000 : 0x260
THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 579718d2ac9cadd09055086e52eaaf605eedcd78
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_NAME: MachineOwner
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_d7ca4080_ntdll.dll!NtWriteVirtualMemory_IMAGE_ntdll.dll
BUCKET_ID: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_d7ca4080_ntdll.dll!NtWriteVirtualMemory_IMAGE_ntdll.dll
PRIMARY_PROBLEM_CLASS: 0xEF_csrss.exe_BUGCHECK_CRITICAL_PROCESS_d7ca4080_ntdll.dll!NtWriteVirtualMemory_IMAGE_ntdll.dll
TARGET_TIME: 2019-12-14T23:36:50.000Z
OSBUILD: 18362
OSSERVICEPACK: 535
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 1980-01-11 18:53:20
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 2860
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_csrss.exe_bugcheck_critical_process_d7ca4080_ntdll.dll!ntwritevirtualmemory_image_ntdll.dll
FAILURE_ID_HASH: {73cae662-2087-0ef7-66c4-aba9a6a86204}
Followup: MachineOwner
---------