Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

More Info on Driver Writing and Debugging


The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.


Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/


wininit.exe CRITICAL_PROCESS_DIED

Malcolm_McCafferyMalcolm_McCaffery Member - All Emails Posts: 9
Any suggestion for futher analysis of CRITICAL_PROCESS_DIED crash to
help narrow down culprit.

I have access to complete memory dmp and tried to set up Kernel
Debugging session in hyper-V, but despite enabling Kernel Debugging
via Serial Named Pipes with Hyper-V the debugger doesn't connect. The
debugger does connect with bootdebug:on and break into winload.efi,
but when BSOD occurs debugger doesn't break.

This issue occurred on physical machines as well as the virtual.

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffe00080a0c8c0, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a
thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------

DUMP_CLASS: 1
DUMP_QUALIFIER: 402
BUILD_VERSION_STRING: 6.3.9600.18589 (winblue_ltsb.170204-0600)
SYSTEM_MANUFACTURER: Microsoft Corporation
VIRTUAL_MACHINE: HyperV
SYSTEM_PRODUCT_NAME: Virtual Machine
SYSTEM_SKU: None
SYSTEM_VERSION: Hyper-V UEFI Release v2.0
BIOS_VENDOR: Microsoft Corporation
BIOS_VERSION: Hyper-V UEFI Release v2.0
BIOS_DATE: 08/26/2016
BASEBOARD_MANUFACTURER: Microsoft Corporation
BASEBOARD_PRODUCT: Virtual Machine
BASEBOARD_VERSION: Hyper-V UEFI Release v2.0
DUMP_TYPE: 0
BUGCHECK_P1: ffffe00080a0c8c0
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: wininit.exe
CRITICAL_PROCESS: wininit.exe
EXCEPTION_CODE: (NTSTATUS) 0x96026768 - <Unable to get error code text>
ERROR_CODE: (NTSTATUS) 0x96026768 - <Unable to get error code text>
CPU_COUNT: 1
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: FFFFFFFF'00000000 (cache)
FFFFFFFF'00000000 (init)
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0xEF
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-RTTN04O
ANALYSIS_SESSION_TIME: 06-16-2017 07:38:01.0475
ANALYSIS_VERSION: 10.0.15063.137 amd64fre
BAD_STACK_POINTER: ffffd000600d1888
LAST_CONTROL_TRANSFER: from fffff801df68d2e4 to fffff801df1ce2a0
STACK_TEXT:
ffffd000`600d1888 fffff801`df68d2e4 : 00000000`000000ef
ffffe000`80a0c8c0 00000000`00000000 00000000`00000000 :
nt!KeBugCheckEx
ffffd000`600d1890 fffff801`df5a85fa : 00000000`00000001
ffffd000`600d1999 00000000`00000000 00000000`00000000 :
nt!PspCatchCriticalBreak+0xa4
ffffd000`600d18d0 fffff801`df68ce86 : 00000000`00000001
ffffd000`600d1999 00000000`00000001 ffffffff`ffffffff : nt! ??
::NNGAKEGL::`string'+0x6fea
ffffd000`600d1930 fffff801`df1d9ab3 : 00000000`00000008
000000b1`96026768 ffffe000`7f7c1880 000000b1`95eff558 :
nt!NtTerminateProcess+0x2c2
ffffd000`600d1a00 00007ffd`f0d4097a : 00007ffd`f0cc84f0
00009f69`b635d096 00000000`0000000e 000000b1`96291228 :
nt!KiSystemServiceCopyEnd+0x13
000000b1`95eff4f8 00007ffd`f0cc84f0 : 00009f69`b635d096
00000000`0000000e 000000b1`96291228 000000b1`95eff628 :
ntdll!NtTerminateProcess+0xa
000000b1`95eff500 00007ffd`f077516a : 00000000`0000000e
00000000`0000000e 000000b1`96291220 00007ffd`f0d05f67 :
ntdll!RtlExitUserProcess+0x60
000000b1`95eff5f0 00007ffd`eee771d5 : 00000000`0000000e
00000000`00000000 00000000`00000000 00007ffd`00000008 :
KERNEL32!ExitProcessImplementation+0xa
000000b1`95eff620 00007ffd`eee76e6f : 000000b1`96291218
00000000`dae67593 0041002d`0047004c 00340031`00440055 :
msvcrt!_crtExitProcess+0x15
000000b1`95eff650 00007ff7`1cf1ac15 : 000000b1`960226fb
00000000`00000000 00000000`00000000 00000000`00000000 :
msvcrt!doexit+0x15b
000000b1`95eff6c0 00007ffd`f07713d2 : 00007ff7`1cf17bb0
00007ff7`1ca23000 00007ff7`1ca23000 00000000`00000000 :
wininit!__mainCRTStartup+0x1c2
000000b1`95eff780 00007ffd`f0cc54e4 : 00007ffd`f07713b0
00000000`00000000 00000000`00000000 00000000`00000000 :
KERNEL32!BaseThreadInitThunk+0x22
000000b1`95eff7b0 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
ntdll!RtlUserThreadStart+0x34

STACK_COMMAND: kb
THREAD_SHA1_HASH_MOD_FUNC: 78e5e5ee84defa9a712af7c5d7da03a981eef1ca
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6cc35f3c6e145933fd675767150418a268df8cf5
THREAD_SHA1_HASH_MOD: e6e2ca33faf662a181153fef2d904d54f6e10b1e
FOLLOWUP_IP:
ntdll!NtTerminateProcess+a
00007ffd`f0d4097a c3 ret
FAULT_INSTR_CODE: 441f0fc3
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: ntdll!NtTerminateProcess+a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ntdll
IMAGE_NAME: ntdll.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 57ae642e
BUCKET_ID_FUNC_OFFSET: a
FAILURE_BUCKET_ID:
0xEF_wininit.exe_BUGCHECK_CRITICAL_PROCESS_96026768_STACKPTR_ERROR_ntdll!NtTerminateProcess
BUCKET_ID: 0xEF_wininit.exe_BUGCHECK_CRITICAL_PROCESS_96026768_STACKPTR_ERROR_ntdll!NtTerminateProcess
PRIMARY_PROBLEM_CLASS:
0xEF_wininit.exe_BUGCHECK_CRITICAL_PROCESS_96026768_STACKPTR_ERROR_ntdll!NtTerminateProcess
TARGET_TIME: 2017-06-15T15:11:35.000Z
OSBUILD: 9600
OSSERVICEPACK: 18589
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
OSEDITION: Windows 8.1 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2017-02-05 03:43:09
BUILDDATESTAMP_STR: 170204-0600
BUILDLAB_STR: winblue_ltsb
BUILDOSVER_STR: 6.3.9600.18589
ANALYSIS_SESSION_ELAPSED_TIME: a27
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING:
km:0xef_wininit.exe_bugcheck_critical_process_96026768_stackptr_error_ntdll!ntterminateprocess
FAILURE_ID_HASH: {d3ae0218-0799-b67e-a1ce-53a4a39ed9c3}
Followup: MachineOwner
---------
kd> lm
start end module name
00007ff7`1cf10000 00007ff7`1cf38000 wininit (pdb symbols)
c:\symbols\wininit.pdb\5027DD19CB6A4AC3BAFAB94DD613C2922\wininit.pdb
00007ffd`eddc0000 00007ffd`eddcb000 wininitext (deferred)
00007ffd`eddd0000 00007ffd`edde5000 profapi (deferred)
00007ffd`edf50000 00007ffd`ee065000 KERNELBASE (deferred)
00007ffd`ee0c0000 00007ffd`ee0ee000 SspiCli (deferred)
00007ffd`ee360000 00007ffd`ee4a0000 RPCRT4 (deferred)
00007ffd`ee6b0000 00007ffd`ee827000 USER32 (deferred)
00007ffd`eebf0000 00007ffd`eed3f000 GDI32 (deferred)
00007ffd`eee70000 00007ffd`eef1a000 msvcrt (pdb symbols)
c:\symbols\msvcrt.pdb\641F17F578D2431E91F0D267FBD1B0522\msvcrt.pdb
00007ffd`eef20000 00007ffd`ef072000 MSCTF (deferred)
00007ffd`f0770000 00007ffd`f08ae000 KERNEL32 (pdb symbols)
c:\symbols\kernel32.pdb\A49C2B8068D747D5B88373C92E68D42C2\kernel32.pdb
00007ffd`f08b0000 00007ffd`f08e6000 IMM32 (deferred)
00007ffd`f0b90000 00007ffd`f0be9000 sechost (deferred)
00007ffd`f0cb0000 00007ffd`f0e5d000 ntdll (pdb symbols)
c:\symbols\ntdll.pdb\309B7D2A275C49A1917EC6033A73D0ED1\ntdll.pdb
fffff800`98400000 fffff800`98488000 CI (deferred)
fffff800`984b9000 fffff800`98536000 mcupdate_GenuineIntel
(deferred)
fffff800`98536000 fffff800`98544000 werkernel (deferred)
fffff800`98544000 fffff800`985a6000 CLFS (deferred)
fffff800`985a6000 fffff800`985c8000 tm (deferred)
fffff800`985c8000 fffff800`985dd000 PSHED (deferred)
fffff800`985dd000 fffff800`985e7000 BOOTVID (deferred)
fffff800`985e7000 fffff800`985f2000 cmimcext (deferred)
fffff800`98629000 fffff800`98686000 msrpc (deferred)
fffff800`98686000 fffff800`98755000 Wdf01000 (deferred)
fffff800`98755000 fffff800`98766000 WDFLDR (deferred)
fffff800`98766000 fffff800`9877e000 acpiex (deferred)
fffff800`9877e000 fffff800`98789000 WppRecorder (deferred)
fffff800`98789000 fffff800`987f4000 spaceport (deferred)
fffff800`9883f000 fffff800`988c7000 ACPI (deferred)
fffff800`988c7000 fffff800`988d1000 WMILIB (deferred)
fffff800`988d1000 fffff800`9895e000 cng (deferred)
fffff800`98967000 fffff800`98974000 vdrvroot (deferred)
fffff800`98974000 fffff800`98990000 pdc (deferred)
fffff800`98990000 fffff800`989a8000 partmgr (deferred)
fffff800`989a8000 fffff800`989be000 volmgr (deferred)
fffff800`98a00000 fffff800`98a5f000 volmgrx (deferred)
fffff800`98a5f000 fffff800`98a7c000 vmbus (deferred)
fffff800`98a7c000 fffff800`98a93000 vmbkmcl (deferred)
fffff800`98a93000 fffff800`98aa8000 winhv (deferred)
fffff800`98aa8000 fffff800`98ae6000 sdbus (deferred)
fffff800`98ae6000 fffff800`98b01000 mountmgr (deferred)
fffff800`98b01000 fffff800`98b1b000 EhStorClass (deferred)
fffff800`98b1b000 fffff800`98b77000 fltmgr (deferred)
fffff800`98b77000 fffff800`98b8d000 fileinfo (deferred)
fffff800`98b8d000 fffff800`98bb8000 Wof (deferred)
fffff800`98c00000 fffff800`98c79000 UsbHub3 (deferred)
fffff800`98c79000 fffff800`98c84000 Fs_Rec (deferred)
fffff800`98cc0000 fffff800`98e52000 symefasi (deferred)
fffff800`98e52000 fffff800`98f0ee80 mfehidk (deferred)
fffff800`98f0f000 fffff800`98f84000 usbhub (deferred)
fffff800`98f84000 fffff800`98ff4000 USBPORT (deferred)
fffff800`99000000 fffff800`99061000 storport (deferred)
fffff800`99061000 fffff800`99088000 usbccgp (deferred)
fffff800`99088000 fffff800`99094000 USBD (deferred)
fffff800`99094000 fffff800`990ad000 usbehci (deferred)
fffff800`990ad000 fffff800`990bd000 pcw (deferred)
fffff800`990bd000 fffff800`992b5000 Ntfs (deferred)
fffff800`992b5000 fffff800`992d1000 ksecdd (deferred)
fffff800`992d1000 fffff800`993bf000 ReFS (deferred)
fffff800`993bf000 fffff800`993cb000 storvsc (deferred)
fffff800`993cb000 fffff800`993fd000 ucx01000 (deferred)
fffff800`99400000 fffff800`99477000 NETIO (deferred)
fffff800`9949d000 fffff800`995b4000 ndis (deferred)
fffff800`995b4000 fffff800`995e5000 ksecpkg (deferred)
fffff800`99640000 fffff800`998a6000 tcpip (deferred)
fffff800`998a6000 fffff800`99912000 fwpkclnt (deferred)
fffff800`99912000 fffff800`99937000 wfplwfs (deferred)
fffff800`99937000 fffff800`99989a80 mfewfpk (deferred)
fffff800`9998a000 fffff800`999aa000 mup (deferred)
fffff800`999aa000 fffff800`999c6000 disk (deferred)
fffff800`99a00000 fffff800`99a17000 sdstor (deferred)
fffff800`99a17000 fffff800`99a5d000 rdyboost (deferred)
fffff800`99a5d000 fffff800`99a6c000 intelpep (deferred)
fffff800`99a76000 fffff800`99b0b000 fvevol (deferred)
fffff800`99b0b000 fffff800`99b5c000 volsnap (deferred)
fffff800`99b5c000 fffff800`99bb1000 USBXHCI (deferred)
fffff800`99bb1000 fffff800`99bd7000 USBSTOR (deferred)
fffff800`99bd7000 fffff800`99bed000 uaspstor (deferred)
fffff800`99c66000 fffff800`99cba000 CLASSPNP (deferred)
fffff800`99cba000 fffff800`99ccf000 crashdmp (deferred)
fffff800`99d14000 fffff800`99d42000 cdrom (deferred)
fffff800`99d42000 fffff800`99d6e000 ccSetx64 (deferred)
fffff800`99d6e000 fffff800`99d96000 hdlpflt (deferred)
fffff800`99d96000 fffff800`99da2000 hdlpevnt (deferred)
fffff800`99da2000 fffff800`99db8000 hdlpctrl (deferred)
fffff800`9a02b000 fffff800`9a10a000 SRTSP64 (deferred)
fffff800`9a10a000 fffff800`9a11f000 SRTSPX64 (deferred)
fffff800`9a11f000 fffff800`9a163000 Ironx64 (deferred)
fffff800`9a163000 fffff800`9a19b000 SYMEVENT64x86 (deferred)
fffff800`9a200000 fffff800`9a28e000 csc (deferred)
fffff800`9a2f9000 fffff800`9a508000 EX64 (deferred)
fffff800`9a508000 fffff800`9a52b000 ENG64 (deferred)
fffff800`9a52b000 fffff800`9a534000 Null (deferred)
fffff800`9a534000 fffff800`9a53c000 Beep (deferred)
fffff800`9a53c000 fffff800`9a551f00 ctxusbm (deferred)
fffff800`9a552000 fffff800`9a560000 BasicRender (deferred)
fffff800`9a560000 fffff800`9a5ce000 rdbss (deferred)
fffff800`9a600000 fffff800`9a690000 afd (deferred)
fffff800`9a690000 fffff800`9a6ba000 pacer (deferred)
fffff800`9a6ba000 fffff800`9a6cb000 netbios (deferred)
fffff800`9a6e3000 fffff800`9a862000 dxgkrnl (deferred)
fffff800`9a862000 fffff800`9a874000 watchdog (deferred)
fffff800`9a874000 fffff800`9a8d7000 dxgmms1 (deferred)
fffff800`9a8d7000 fffff800`9a8e9000 BasicDisplay (deferred)
fffff800`9a8e9000 fffff800`9a8f0000 rcVidMpt (deferred)
fffff800`9a8f0000 fffff800`9a903000 VIDEOPRT (deferred)
fffff800`9a903000 fffff800`9a917000 Npfs (deferred)
fffff800`9a917000 fffff800`9a923000 Msfs (deferred)
fffff800`9a923000 fffff800`9a943000 tdx (deferred)
fffff800`9a943000 fffff800`9a951000 TDI (deferred)
fffff800`9a951000 fffff800`9a99b000 netbt (deferred)
fffff800`9aa8e000 fffff800`9ab24000 SYMNETS (deferred)
fffff800`9ab24000 fffff800`9ab32000 nsiproxy (deferred)
fffff800`9ab32000 fffff800`9ab3e000 npsvctrig (deferred)
fffff800`9ab3e000 fffff800`9ab4a000 mssmbios (deferred)
fffff800`9ac00000 fffff800`9ac28000 EraserUtilRebootDrv (deferred)
fffff800`9ac28000 fffff800`9ac4f000 dfsc (deferred)
fffff800`9ac4f000 fffff800`9ac5d000 monitor (deferred)
fffff800`9ac69000 fffff800`9ad63000 IDSvia64 (deferred)
fffff800`9ad63000 fffff800`9addf000 eeCtrl64 (deferred)
fffff800`9addf000 fffff800`9adf5000 dump_dumpfve (deferred)
fffff800`9ae00000 fffff800`9ae39000 fastfat (deferred)
fffff800`9ae39000 fffff800`9ae54000 cdfs (deferred)
fffff800`9ae54000 fffff800`9ae60000 dump_diskdump (deferred)
fffff800`9ae60000 fffff800`9ae6c000 dump_storvsc (deferred)
fffff800`9ae79000 fffff800`9b03b000 BHDrvx64 (deferred)
fffff800`9b03b000 fffff800`9b054000 ahcache (deferred)
fffff800`9b054000 fffff800`9b063000 CompositeBus (deferred)
fffff800`9b063000 fffff800`9b06e000 kdnic (deferred)
fffff800`9b06e000 fffff800`9b07f000 umbus (deferred)
fffff800`9b07f000 fffff800`9b09d000 intelppm (deferred)
fffff800`9b09d000 fffff800`9b0a2500 VMBusHID (deferred)
fffff800`9b0a3000 fffff800`9b0c2000 HIDCLASS (deferred)
fffff800`9b0c2000 fffff800`9b0c9f00 HIDPARSE (deferred)
fffff800`9b0ca000 fffff800`9b0d4000 hyperkbd (deferred)
fffff800`9b0d4000 fffff800`9b0e6000 kbdclass (deferred)
fffff800`9b0e6000 fffff800`9b0f3000 hdlpdbk (deferred)
fffff800`9b0f3000 fffff800`9b101000 dmvsc (deferred)
fffff800`9b101000 fffff800`9b10b000 vmgencounter (deferred)
fffff800`9b10b000 fffff800`9b125000 serial (deferred)
fffff800`9b125000 fffff800`9b132000 serenum (deferred)
fffff800`9b132000 fffff800`9b13e000 rcSmCard (deferred)
fffff800`9b13e000 fffff800`9b14a000 SMCLIB (deferred)
fffff800`9b14a000 fffff800`9b15b000 scfilter (deferred)
fffff800`9b15b000 fffff800`9b166000 NdisVirtualBus (deferred)
fffff800`9b166000 fffff800`9b167600 swenum (deferred)
fffff800`9b168000 fffff800`9b1b6000 ks (deferred)
fffff800`9b1b6000 fffff800`9b1c1000 rdpbus (deferred)
fffff800`9b1c1000 fffff800`9b1ce000 mouhid (deferred)
fffff800`9b1ce000 fffff800`9b1de000 mouclass (deferred)
fffff800`9b1de000 fffff800`9b1f5000 dump_vmbkmcl (deferred)
fffff801`de3ba000 fffff801`de3c3000 kd (deferred)
fffff801`df010000 fffff801`df080000 hal (deferred)
fffff801`df080000 fffff801`df80c000 nt (pdb symbols)
c:\symbols\ntkrnlmp.pdb\C1E2C0CCCDAC4F5DB73D0B72F3EECA3F1\ntkrnlmp.pdb
fffff960`00184000 fffff960`00599000 win32k (deferred)
fffff960`007ab000 fffff960`007b4000 TSDDD (deferred)
Unloaded modules:
fffff800`9ab4a000 fffff800`9abc8000 mfefirek.sys
fffff800`9aa00000 fffff800`9aa4b000 mfeavfk.sys
fffff800`99ccf000 fffff800`99cdb000 dump_storport.sys
fffff800`99ce7000 fffff800`99cfe000 dump_vmbkmcl.sys
fffff800`99cdb000 fffff800`99ce7000 dump_storvsc.sys
fffff800`99cfe000 fffff800`99d14000 dump_dumpfve.sys
fffff800`9ac4f000 fffff800`9ac60000 dam.sys
fffff800`9895e000 fffff800`98967000 SymELAM.sys
fffff800`99bed000 fffff800`99bf9000 hwpolicy.sys
00007ffd`eddb0000 00007ffd`eddb4000 kbdus.dll
00007ffd`eddb0000 00007ffd`eddb4000 kbdus.dll
00007ffd`eddb0000 00007ffd`eddb9000 wls0wndh.dll
kd> !process ffffe00080a0c8c0 7
PROCESS ffffe00080a0c8c0
SessionId: 0 Cid: 0234 Peb: 7ff71ca23000 ParentCid: 01d8
DirBase: 20a3a000 ObjectTable: ffffc001dfffff40 HandleCount:
<Data Not Accessible>
Image: wininit.exe
VadRoot ffffe0007f7c2630 Vads 42 Clone 0 Private 194. Modified 42. Locked 0.
DeviceMap ffffc001dea0db20
Token ffffc001e42481e0
ElapsedTime 00:00:00.412
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 85928
QuotaPoolUsage[NonPagedPool] 5360
Working Set Sizes (now,min,max) (917, 50, 345) (3668KB, 200KB, 1380KB)
PeakWorkingSetSize 876
VirtualSize 2097192 Mb
PeakVirtualSize 2097196 Mb
PageFaultCount 1000
MemoryPriority BACKGROUND
BasePriority 13
CommitCharge 246
THREAD ffffe0007f7c1880 Cid 0234.0238 Teb: 00007ff71ca2e000
Win32Thread: fffff901400e3b50 RUNNING on processor 0
Not impersonating
DeviceMap ffffc001dea0db20
Owning Process ffffe00080a0c8c0 Image:
wininit.exe
Attached Process N/A Image: N/A
Wait Start TickCount 316 Ticks: 0
Context Switch Count 268 IdealProcessor: 0
UserTime 00:00:00.015
KernelTime 00:00:00.125
Win32 Start Address wininit!WinMainCRTStartup (0x00007ff71cf17bb0)
Stack Init ffffd000600d1b90 Current ffffd000600d1300
Base ffffd000600d2000 Limit ffffd000600cb000 Call 0000000000000000
Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2
PagePriority 5
Child-SP RetAddr : Args to Child
: Call Site
ffffd000`600d1888 fffff801`df68d2e4 : 00000000`000000ef
ffffe000`80a0c8c0 00000000`00000000 00000000`00000000 :
nt!KeBugCheckEx
ffffd000`600d1890 fffff801`df5a85fa : 00000000`00000001
ffffd000`600d1999 00000000`00000000 00000000`00000000 :
nt!PspCatchCriticalBreak+0xa4
ffffd000`600d18d0 fffff801`df68ce86 : 00000000`00000001
ffffd000`600d1999 00000000`00000001 ffffffff`ffffffff : nt! ??
::NNGAKEGL::`string'+0x6fea
ffffd000`600d1930 fffff801`df1d9ab3 : 00000000`00000008
000000b1`96026768 ffffe000`7f7c1880 000000b1`95eff558 :
nt!NtTerminateProcess+0x2c2
ffffd000`600d1a00 00007ffd`f0d4097a : 00007ffd`f0cc84f0
00009f69`b635d096 00000000`0000000e 000000b1`96291228 :
nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ ffffd000`600d1a00)
000000b1`95eff4f8 00007ffd`f0cc84f0 : 00009f69`b635d096
00000000`0000000e 000000b1`96291228 000000b1`95eff628 :
ntdll!NtTerminateProcess+0xa
000000b1`95eff500 00007ffd`f077516a : 00000000`0000000e
00000000`0000000e 000000b1`96291220 00007ffd`f0d05f67 :
ntdll!RtlExitUserProcess+0x60
000000b1`95eff5f0 00007ffd`eee771d5 : 00000000`0000000e
00000000`00000000 00000000`00000000 00007ffd`00000008 :
KERNEL32!ExitProcessImplementation+0xa
000000b1`95eff620 00007ffd`eee76e6f : 000000b1`96291218
00000000`dae67593 0041002d`0047004c 00340031`00440055 :
msvcrt!_crtExitProcess+0x15
000000b1`95eff650 00007ff7`1cf1ac15 : 000000b1`960226fb
00000000`00000000 00000000`00000000 00000000`00000000 :
msvcrt!doexit+0x15b
000000b1`95eff6c0 00007ffd`f07713d2 : 00007ff7`1cf17bb0
00007ff7`1ca23000 00007ff7`1ca23000 00000000`00000000 :
wininit!__mainCRTStartup+0x1c2
000000b1`95eff780 00007ffd`f0cc54e4 : 00007ffd`f07713b0
00000000`00000000 00000000`00000000 00000000`00000000 :
KERNEL32!BaseThreadInitThunk+0x22
000000b1`95eff7b0 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
ntdll!RtlUserThreadStart+0x34
THREAD ffffe0007f7ec380 Cid 0234.024c Teb: 00007ff71ca2c000
Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffe0007f7dee40 QueueObject
Not impersonating
DeviceMap ffffc001dea0db20
Owning Process ffffe00080a0c8c0 Image:
wininit.exe
Attached Process N/A Image: N/A
Wait Start TickCount 314 Ticks: 2 (0:00:00:00.031)
Context Switch Count 6 IdealProcessor: 0
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address ntdll!TppWorkerThread (0x00007ffdf0ce89b0)
Stack Init ffffd00060487b90 Current ffffd00060487330
Base ffffd00060488000 Limit ffffd00060481000 Call 0000000000000000
Priority 14 BasePriority 13 PriorityDecrement 0 IoPriority 2
PagePriority 5
Child-SP RetAddr : Args to Child
: Call Site
ffffd000`60487370 fffff801`df113f1e : fffff801`df37d180
ffffe000`7f7ec380 ffffd000`fffffffe fffff801`df0af194 :
nt!KiSwapContext+0x76
ffffd000`604874b0 fffff801`df113999 : ffffe000`7f7ec380
fffff801`df1d167d ffffe000`00000000 00000000`02f0c454 :
nt!KiSwapThread+0x14e
ffffd000`60487550 fffff801`df112908 : 00000000`00000000
00000000`00000000 00000000`000000b7 00000000`00000000 :
nt!KiCommitThreadWait+0x129
ffffd000`604875d0 fffff801`df111f6a : ffffe000`7f7dee40
00000000`00000001 00000000`00000001 00000000`00000002 :
nt!KeRemoveQueueEx+0x788
ffffd000`60487650 fffff801`df1115fb : ffffe000`81681bb8
00000000`00000000 ffffe000`7f7ec700 7fffffff`fffffffe :
nt!IoRemoveIoCompletion+0x8a
ffffd000`60487770 fffff801`df1d9ab3 : 00000000`0000002c
000000b1`9602e360 00000000`00000010 000000b1`9619f778 :
nt!NtWaitForWorkViaWorkerFactory+0x30b
ffffd000`60487990 00007ffd`f0d421aa : 00007ffd`f0ce90f6
00007ffd`f0cc9550 00007ffd`f0cc9550 00000000`00000010 :
nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ ffffd000`60487a00)
000000b1`9619f6f8 00007ffd`f0ce90f6 : 00007ffd`f0cc9550
00007ffd`f0cc9550 00000000`00000010 000000b1`9602e6e0 :
ntdll!NtWaitForWorkViaWorkerFactory+0xa
000000b1`9619f700 00007ffd`f07713d2 : 00000000`00000000
00007ffd`f0ce89b0 000000b1`96027650 00000000`00000000 :
ntdll!TppWorkerThread+0x746
000000b1`9619fae0 00007ffd`f0cc54e4 : 00007ffd`f07713b0
00000000`00000000 00000000`00000000 00000000`00000000 :
KERNEL32!BaseThreadInitThunk+0x22
000000b1`9619fb10 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
ntdll!RtlUserThreadStart+0x34
THREAD ffffe0007f7cc080 Cid 0234.0254 Teb: 00007ff71ca2a000
Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffe0007f7dee40 QueueObject
Not impersonating
DeviceMap ffffc001dea0db20
Owning Process ffffe00080a0c8c0 Image:
wininit.exe
Attached Process N/A Image: N/A
Wait Start TickCount 293 Ticks: 23 (0:00:00:00.359)
Context Switch Count 1 IdealProcessor: 0
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address ntdll!TppWorkerThread (0x00007ffdf0ce89b0)
Stack Init ffffd00060507b90 Current ffffd00060507330
Base ffffd00060508000 Limit ffffd00060501000 Call 0000000000000000
Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2
PagePriority 5
Child-SP RetAddr : Args to Child
: Call Site
ffffd000`60507370 fffff801`df113f1e : fffff801`df37d180
ffffe000`7f7cc080 00000000`fffffffe 00000000`00000000 :
nt!KiSwapContext+0x76
ffffd000`605074b0 fffff801`df113999 : ffffe000`7f7cc080
00000000`00000000 00000000`00000000 00000000`00000000 :
nt!KiSwapThread+0x14e
ffffd000`60507550 fffff801`df112908 : 00000000`00000000
00000000`00000000 ffffe000`000000aa 00000000`00000000 :
nt!KiCommitThreadWait+0x129
ffffd000`605075d0 fffff801`df111f6a : ffffe000`7f7dee40
00000000`00000001 00000000`00000001 00000000`00000002 :
nt!KeRemoveQueueEx+0x788
ffffd000`60507650 fffff801`df1115fb : 00000000`00000000
00000000`00000000 00000004`00000001 00000000`00000000 :
nt!IoRemoveIoCompletion+0x8a
ffffd000`60507770 fffff801`df1d9ab3 : 00000000`0000002c
000000b1`96023bb0 ffffe000`00000010 000000b1`9621f6f8 :
nt!NtWaitForWorkViaWorkerFactory+0x30b
ffffd000`60507990 00007ffd`f0d421aa : 00007ffd`f0ce90f6
00007ffd`f0ce89b0 00000000`00000003 000000b1`96027650 :
nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ ffffd000`60507a00)
000000b1`9621f678 00007ffd`f0ce90f6 : 00007ffd`f0ce89b0
00000000`00000003 000000b1`96027650 000000b1`96027650 :
ntdll!NtWaitForWorkViaWorkerFactory+0xa
000000b1`9621f680 00007ffd`f07713d2 : 00000000`00000000
00007ffd`f0ce89b0 000000b1`96027650 00000000`00000000 :
ntdll!TppWorkerThread+0x746
000000b1`9621fa60 00007ffd`f0cc54e4 : 00007ffd`f07713b0
00000000`00000000 00000000`00000000 00000000`00000000 :
KERNEL32!BaseThreadInitThunk+0x22
000000b1`9621fa90 00000000`00000000 : 00000000`00000000
00000000`00000000 00000000`00000000 00000000`00000000 :
ntdll!RtlUserThreadStart+0x34

Thanks
Malcolm.
Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!
Kernel Debugging 30 Mar 2020 OSR Seminar Space
Developing Minifilters 15 Jun 2020 LIVE ONLINE
Writing WDF Drivers 22 June 2020 LIVE ONLINE
Internals & Software Drivers 28 Sept 2020 Dulles, VA