CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffff920db87e0280, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 5
Key : Analysis.Elapsed.Sec
Value: 42
Key : Analysis.Memory.CommitPeak.Mb
Value: 70
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 17763.1.amd64fre.rs5_release.180914-1434
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A7 V6.3
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.11
BIOS_DATE: 12/25/2015
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A7 V6.3
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: ffff920db87e0280
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: services.exe
CRITICAL_PROCESS: services.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0c0c080 - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0xc0c0c080 - <Unable to get error code text>
CRITICAL_PROCESS_REPORTGUID: {cd9ae8cb-4240-4a37-8d95-7f77d7a500b7}
IMAGE_NAME: services.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: services
FAULTING_MODULE: 0000000000000000
CPU_COUNT: 8
CPU_MHZ: a20
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 5e
CPU_STEPPING: 3
CPU_MICROCODE: 6,5e,3,0 (F,M,S,R) SIG: C2'00000000 (cache) C2'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXPNP: 1 (!blackboxpnp)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-K01TCKK
ANALYSIS_SESSION_TIME: 05-19-2019 18:23:21.0812
ANALYSIS_VERSION: 10.0.18869.1002 amd64fre
LAST_CONTROL_TRANSFER: from fffff80509f3892d to fffff8050985eef0
STACK_TEXT:
ffffa780`98e77838 fffff805`09f3892d : 00000000`000000ef ffff920d`b87e0280 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffa780`98e77840 fffff805`09e74e19 : 00000000`00000000 fffff805`097da735 ffff920d`b87e0280 fffff805`097da634 : nt!PspCatchCriticalBreak+0xfd
ffffa780`98e778e0 fffff805`09d2f6ec : ffff920d`00000000 00000000`00000000 ffff920d`b87e0280 ffff920d`b87e0558 : nt!PspTerminateAllThreads+0x1468a5
ffffa780`98e77950 fffff805`09d31229 : ffffffff`ffffffff ffffa780`98e77a80 ffff920d`b87e0280 fffff805`09cf2201 : nt!PspTerminateProcess+0xe0
ffffa780`98e77990 fffff805`09870085 : ffff920d`00000374 ffff920d`c0c0c080 ffff920d`b87e0280 000000ab`000ff71c : nt!NtTerminateProcess+0xa9
ffffa780`98e77a00 00007ff8`a951fce4 : 00007ff8`a9590e4b 00007ff8`a95c112c 000000ab`000ff6e0 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000ab`000fd708 00007ff8`a9590e4b : 00007ff8`a95c112c 000000ab`000ff6e0 00000000`00000000 00000000`00000000 : 0x00007ff8`a951fce4
000000ab`000fd710 00007ff8`a95c112c : 000000ab`000ff6e0 00000000`00000000 00000000`00000000 00000000`00000003 : 0x00007ff8`a9590e4b
000000ab`000fd718 000000ab`000ff6e0 : 00000000`00000000 00000000`00000000 00000000`00000003 00007ff8`a952788d : 0x00007ff8`a95c112c
000000ab`000fd720 00000000`00000000 : 00000000`00000000 00000000`00000003 00007ff8`a952788d 00007ff8`a95c112c : 0x000000ab`000ff6e0
THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 79ca02601b1af660df7e84c3214860d8d39a8533
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_NAME: MachineOwner
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0xEF_services.exe_BUGCHECK_CRITICAL_PROCESS_c0c0c080_services.exe!ScOpenService_IMAGE_services.exe
BUCKET_ID: 0xEF_services.exe_BUGCHECK_CRITICAL_PROCESS_c0c0c080_services.exe!ScOpenService_IMAGE_services.exe
PRIMARY_PROBLEM_CLASS: 0xEF_services.exe_BUGCHECK_CRITICAL_PROCESS_c0c0c080_services.exe!ScOpenService_IMAGE_services.exe
TARGET_TIME: 2019-05-18T18:39:53.000Z
OSBUILD: 17763
OSSERVICEPACK: 503
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2021-07-31 18:45:35
BUILDDATESTAMP_STR: 180914-1434
BUILDLAB_STR: rs5_release
BUILDOSVER_STR: 10.0.17763.1.amd64fre.rs5_release.180914-1434
ANALYSIS_SESSION_ELAPSED_TIME: a651
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xef_services.exe_bugcheck_critical_process_c0c0c080_services.exe!scopenservice_image_services.exe
FAILURE_ID_HASH: {dc2bd48a-be6d-71b8-66e3-64026dd24b80}
Followup: MachineOwner
---------
UNEXPECTED_STORE_EXCEPTION (154)
The store component caught an unexpected exception.
Arguments:
Arg1: ffffd501b6a76000, Pointer to the store context or data manager
Arg2: ffffbc0b616066e0, Exception information
Arg3: 0000000000000001, Reserved
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 0
Key : Analysis.Elapsed.Sec
Value: 0
Key : Analysis.Memory.CommitPeak.Mb
Value: 42
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
DUMP_TYPE: 2
BUGCHECK_P1: ffffd501b6a76000
BUGCHECK_P2: ffffbc0b616066e0
BUGCHECK_P3: 1
BUGCHECK_P4: 0
EXCEPTION_RECORD: ffffbc0b61607688 -- (.exr 0xffffbc0b61607688)
ExceptionAddress: fffff800532d43e8
ExceptionCode: c0000420 (Assertion failure)
ExceptionFlags: 00000000
NumberParameters: 0
BUGCHECK_STR: 0x154_0
CONTEXT: ffffbc0b61606ed0 -- (.cxr 0xffffbc0b61606ed0)
rax=00000000c0000225 rbx=ffffd501b6a760e8 rcx=ffffd501c629b000
rdx=000000000000005a rsi=0000000000000000 rdi=ffffd501b6a76050
rip=fffff800532d43e8 rsp=ffffbc0b616078c0 rbp=ffffd501b6a760d0
r8=000000000000102d r9=00000000aeda75ab r10=000000000000000a
r11=000000000000000c r12=ffffd501c83e5dd0 r13=ffffd501b6a76068
r14=0000000000205ac8 r15=ffffd501c897f978
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000282
fffff800`532d43e8 ?? ???
Resetting default scope
CPU_COUNT: 8
CPU_MHZ: a20
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 5e
CPU_STEPPING: 3
CUSTOMER_CRASH_COUNT: 1
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-K01TCKK
ANALYSIS_SESSION_TIME: 05-19-2019 18:20:55.0713
ANALYSIS_VERSION: 10.0.18869.1002 amd64fre
LAST_CONTROL_TRANSFER: from ffffd501b6a760e8 to fffff800532d43e8
STACK_TEXT:
ffffbc0b`61606628 fffff800`533a4ebe : 00000000`00000154 ffffd501`b6a76000 ffffbc0b`616066e0 00000000`00000001 : 0xfffff800`53256ef0
ffffbc0b`61606630 00000000`00000154 : ffffd501`b6a76000 ffffbc0b`616066e0 00000000`00000001 00000000`00000000 : 0xfffff800`533a4ebe
ffffbc0b`61606638 ffffd501`b6a76000 : ffffbc0b`616066e0 00000000`00000001 00000000`00000000 00000000`00000000 : 0x154
ffffbc0b`61606640 ffffbc0b`616066e0 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffffd501`b6a76000
ffffbc0b`61606648 00000000`00000001 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffffbc0b`616066e0
ffffbc0b`61606650 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff800`53432c50 : 0x1
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID: CORRUPT_MODULELIST_0x154_0
DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x154_0
PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST_0x154_0
FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x154_0
TARGET_TIME: 2019-05-18T17:02:54.000Z
OSBUILD: 17763
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
ANALYSIS_SESSION_ELAPSED_TIME: 5c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x154_0
FAILURE_ID_HASH: {82c33c4b-a935-e5a8-0372-673537030b81}
Followup: MachineOwner
---------
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff9ba766f38600, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff804746ca84a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 10
Key : Analysis.Elapsed.Sec
Value: 11
Key : Analysis.Memory.CommitPeak.Mb
Value: 67
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 17763.1.amd64fre.rs5_release.180914-1434
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A7 V6.3
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.11
BIOS_DATE: 12/25/2015
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A7 V6.3
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: ffff9ba766f38600
BUGCHECK_P2: 0
BUGCHECK_P3: fffff804746ca84a
BUGCHECK_P4: 2
READ_ADDRESS: GetUlongFromAddress: unable to read from fffff804745754c0
fffff804745f0390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffff9ba766f38600
FAULTING_IP:
nt!CmpPerformCompleteKcbCacheLookup+15a
fffff804`746ca84a 41395d00 cmp dword ptr [r13],ebx
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: a20
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 5e
CPU_STEPPING: 3
CPU_MICROCODE: 6,5e,3,0 (F,M,S,R) SIG: C2'00000000 (cache) C2'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXPNP: 1 (!blackboxpnp)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: MsMpEng.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-K01TCKK
ANALYSIS_SESSION_TIME: 05-19-2019 18:21:40.0845
ANALYSIS_VERSION: 10.0.18869.1002 amd64fre
TRAP_FRAME: ffffb601cf266df0 -- (.trap 0xffffb601cf266df0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff9b875b241000 rbx=0000000000000000 rcx=000000000000004b
rdx=ffff9b875b241258 rsi=0000000000000000 rdi=0000000000000000
rip=fffff804746ca84a rsp=ffffb601cf266f80 rbp=ffff9b8759924000
r8=ffffb601cf266f88 r9=0000000000000000 r10=7ffffffffffffffc
r11=000000000000fffe r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!CmpPerformCompleteKcbCacheLookup+0x15a:
fffff804`746ca84a 41395d00 cmp dword ptr [r13],ebx ds:00000000`00000000=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff804743059db to fffff804742617e0
STACK_TEXT:
ffffb601`cf266b08 fffff804`743059db : 00000000`00000050 ffff9ba7`66f38600 00000000`00000000 ffffb601`cf266df0 : nt!KeBugCheckEx
ffffb601`cf266b10 fffff804`741763d7 : ffff9b87`56200340 00000000`00000000 00000000`00000000 ffff9ba7`66f38600 : nt!MiSystemFault+0x1303ab
ffffb601`cf266c50 fffff804`7426f283 : 00000000`00000000 ffffb601`cf2671d0 ffffb601`cf2671d0 ffffb601`cf266f20 : nt!MmAccessFault+0x327
ffffb601`cf266df0 fffff804`746ca84a : 00000000`b15f97e0 00000000`00000000 00000000`00000000 ffffb601`cf267210 : nt!KiPageFault+0x343
ffffb601`cf266f80 fffff804`746a8277 : ffff9b87`593cb728 00000000`00000000 00000000`00000003 ffffb601`cf2671d0 : nt!CmpPerformCompleteKcbCacheLookup+0x15a
ffffb601`cf267060 fffff804`746a799a : ffff9b87`0000001c ffffb601`cf267380 ffffb601`cf267350 00000000`00000000 : nt!CmpDoParseKey+0x2a7
ffffb601`cf2672d0 fffff804`746c99c9 : fffff804`746a7730 ffff9b87`00000000 ffffc98f`dd3f1610 ffff9b87`6c555601 : nt!CmpParseKey+0x26a
ffffb601`cf267460 fffff804`746c7fcf : ffffc98f`dd3f1600 ffffb601`cf2676c8 00000000`00000040 ffffc98f`ce715380 : nt!ObpLookupObjectName+0x719
ffffb601`cf267630 fffff804`746c6658 : 00000000`00000001 ffffc98f`ce715380 00000000`00000000 00000000`00000001 : nt!ObOpenObjectByNameEx+0x1df
ffffb601`cf267770 fffff804`746c63af : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmOpenKey+0x298
ffffb601`cf2679c0 fffff804`74272985 : ffffc98f`dbcae080 ffffb601`00000000 ffffc98f`e37b95f0 000001d6`d01c7e70 : nt!NtOpenKeyEx+0xf
ffffb601`cf267a00 00007ffe`94741a94 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000c8`3f87ce58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`94741a94
THREAD_SHA1_HASH_MOD_FUNC: 783b23d65ba42523b90949e8cac08a47fe6ed30f
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 273491e5f5d08f221b6bcb107bdf7d41fe01920e
THREAD_SHA1_HASH_MOD: dc844b1b94baa204d070855e43bbbd27eee98b94
FOLLOWUP_IP:
nt!CmpPerformCompleteKcbCacheLookup+15a
fffff804`746ca84a 41395d00 cmp dword ptr [r13],ebx
FAULT_INSTR_CODE: 5d3941
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!CmpPerformCompleteKcbCacheLookup+15a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.17763.475
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 15a
FAILURE_BUCKET_ID: AV_R_INVALID_nt!CmpPerformCompleteKcbCacheLookup
BUCKET_ID: AV_R_INVALID_nt!CmpPerformCompleteKcbCacheLookup
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!CmpPerformCompleteKcbCacheLookup
TARGET_TIME: 2019-05-16T16:48:39.000Z
OSBUILD: 17763
OSSERVICEPACK: 475
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 180914-1434
BUILDLAB_STR: rs5_release
BUILDOSVER_STR: 10.0.17763.1.amd64fre.rs5_release.180914-1434
ANALYSIS_SESSION_ELAPSED_TIME: 2dfd
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!cmpperformcompletekcbcachelookup
FAILURE_ID_HASH: {5711fa75-3963-d22f-9029-03179928e218}
Followup: MachineOwner
---------