Thank you for your prompt responses. I did use driver verifier before but it didn’t give me any errors. I will perform more test using all the options it provides.
Here is the output of “!analyse - v”
1: kd> !analyze -v
Connected to Windows 10 14393 x64 target at (Thu Dec 1 17:26:27.277 2016 (UTC + 9:00)), ptr64 TRUE
Loading Kernel Symbols
.CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
.CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
…
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
…
…
Loading User Symbols
…CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
Unable to read NT module Base Name string at 0000026128306048 - Win32 error 0n30 ..CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol. Unable to read LDR_DATA_TABLE_ENTRY at 00000261
2830b4a0 - Win32 error 0n30
Loading unloaded module list
…
WARNING: .reload failed, module list may be incomplete
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
Cannot read _LDR_DATA_TABLE_ENTRY at 000002612830b4a0
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn’t have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing “.symopt- 100”. Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ULONG64 ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn’t have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing “.symopt- 100”. Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ULONG64 ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn’t have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing “.symopt- 100”. Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ULONG64 ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn’t have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing “.symopt- 100”. Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ULONG64 ***
*** ***
*************************************************************************
Unable to read NT module Base Name string at 00000261`28306048 - Win32 error 0n30
*** ERROR: Symbol file could not be found. Defaulted to export symbols for combase.dll -
CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
CompressedPageDataReader warning: failed to get _SM_PAGE_KEY symbol.
DUMP_CLASS: 1
DUMP_QUALIFIER: 0
FAULTING_IP:
+0
0033:00007ffa`ec927b73 458b2c8a mov r13d,dword ptr [r10+rcx*4]
EXCEPTION_RECORD: 00000089b1efefb0 – (.exr 0x89b1efefb0)
ExceptionAddress: 00007ffaec927b73
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 00000261ecb81a60
Attempt to read from address 00000261ecb81a60
DEFAULT_BUCKET_ID: STATUS_BREAKPOINT
ERROR_CODE: (NTSTATUS) 0x80000003 - {EXCEPTION} Breakpoint A breakpoint has been reached.
EXCEPTION_CODE: (HRESULT) 0x80000003 (2147483651) - One or more arguments are invalid
EXCEPTION_CODE_STR: 80000003
EXCEPTION_PARAMETER1: 0000000000000000
WATSON_BKT_PROCSTAMP: 578998f1
WATSON_BKT_MODULE: ntdll.dll
WATSON_BKT_MODSTAMP: 578997b2
WATSON_BKT_MODOFFSET: f212a
BUILD_VERSION_STRING: 14393.0.amd64fre.rs1_release.160715-1616
MODLIST_WITH_TSCHKSUM_HASH: 8534755ab65ab751722406aac6c52ec8f40ff0a7
MODLIST_SHA1_HASH: 63ecc2076c006a06958de6d3a0c4d4e824335c08
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
PRODUCT_TYPE: 1
SUITE_MASK: 784
ANALYSIS_SESSION_HOST: DESKTOP-BQ3SG77
ANALYSIS_SESSION_TIME: 12-01-2016 17:27:06.0427
ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
CONTEXT: 00000089b1efeac0 – (.cxr 0x89b1efeac0)
rax=0000000000000000 rbx=00000261286069b8 rcx=00000000301e00f3
rdx=00000000301e00f3 rsi=000002612c402694 rdi=00000089b1eff400
rip=00007ffaec927b73 rsp=00000089b1eff1d0 rbp=00000089b1eff299
r8=000002612c400000 r9=000002612c400000 r10=000002612c401694
r11=0000000000000002 r12=00000089b1eff598 r13=00000089b1eff8e0
r14=00000089b1eff400 r15=0000026128614d30
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010206
0033:00007ffaec927b73 458b2c8a mov r13d,dword ptr [r10+rcx*4] ds:002b:00000261
ecb81a60=???
Resetting default scope
FOLLOWUP_IP:
ntdll!RtlUnhandledExceptionFilter2+34a
0033:00007ffa`f41d212a cc int 3
READ_ADDRESS: 00000261ecb81a60
BUGCHECK_STR: STATUS_BREAKPOINT
THREAD_ATTRIBUTES:
OS_LOCALE: KOR
PROBLEM_CLASSES:
Tid [0x0]
Frame [0x00]
String [STATUS_BREAKPOINT]
Data Bucketing
LAST_CONTROL_TRANSFER: from 0000000000000008 to 00007ffaec927b73
IP_ON_HEAP: 00007ffaec927b73
The fault address in not in any loaded module, please check your build’s rebase
log at \bin\build_logs\timebuild\ntrebase.log for module which may
contain the address if it were loaded.
STACK_TEXT:
00000089b1efe170 00007ffa
f0735e77 : 00000089b1efe350 00007ffa
f41ed402 00007ffaeca0bf80 00000261
283036c8 : ntdll!RtlUnhandledExceptionFilter2+0x34a
00000089b1efe1f0 00007ffa
f418da9b : 00007ffaeca0bf80 00007ffa
f4211b44 0000000000000000 00007ffa
f16aad4b : KERNELBASE!UnhandledExceptionFilter+0x157
00000089b1efe2f0 00007ffa
f4175946 : 00000089b1effbe0 00000089
b1efefb0 00007ffaf3538364 00000089
b1effbe0 : ntdll!RtlUserThreadStart$filt$0+0x38
00000089b1efe320 00007ffa
f418991d : 0000000000000000 00000089
b1efe4c0 00000089b1efeac0 00000000
00000000 : ntdll!C_specific_handler+0x96
00000089b1efe390 00007ffa
f41286d3 : 00007ffaf35d34b0 00000089
b1efeac0 0000000000000000 b1aaa824
a86a7795 : ntdll!RtlpExecuteHandlerForException+0xd
00000089b1efe3c0 00007ffa
f4188a3a : 0000000000000000 00000261
00000060 00000261286069b8 00000000
00000000 : ntdll!RtlDispatchException+0x373
00000089b1efeac0 00007ffa
ec927b73 : 0000000000000008 00000000
00000002 0000000000000ab0 00000261
0002a934 : ntdll!KiUserExceptionDispatch+0x3a
00000089b1eff1d0 00000000
00000008 : 0000000000000002 00000000
00000ab0 000002610002a934 00000000
00000002 : 0x00007ffaec927b73<br>00000089
b1eff1d8 0000000000000002 : 00000000
00000ab0 000002610002a934 00000000
00000002 000002612c400000 : 0x8<br>00000089
b1eff1e0 0000000000000ab0 : 00000261
0002a934 0000000000000002 00000261
2c400000 000002612c400000 : 0x2<br>00000089
b1eff1e8 000002610002a934 : 00000000
00000002 000002612c400000 00000261
2c400000 000002612c402694 : 0xab0<br>00000089
b1eff1f0 0000000000000002 : 00000261
2c400000 000002612c400000 00000261
2c402694 0000000000000000 : 0x00000261
0002a934
00000089b1eff1f8 00000261
2c400000 : 000002612c400000 00000261
2c402694 0000000000000000 00007ffa
ec924552 : 0x2
00000089b1eff200 00000261
2c400000 : 000002612c402694 00000000
00000000 00007ffaec924552 00000000
0000002c : 0x000002612c400000<br>00000089
b1eff208 000002612c402694 : 00000000
00000000 00007ffaec924552 00000000
0000002c 0000000000000008 : 0x00000261
2c400000
00000089b1eff210 00000000
00000000 : 00007ffaec924552 00000000
0000002c 0000000000000008 00000000
00000002 : 0x00000261`2c402694
STACK_COMMAND: kb
THREAD_SHA1_HASH_MOD_FUNC: 540e65e2a9db925b7e789f1200575c3462568bed
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 239f92b65582ef5f9eae60417561a743da4477cf
THREAD_SHA1_HASH_MOD: aff8b0dabc8d844388b1a38dd035d9811d0d5815
FAULT_INSTR_CODE: e8b4dcc
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: ntdll!RtlUnhandledExceptionFilter2+34a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ntdll
IMAGE_NAME: ntdll.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 578997b2
BUCKET_ID_FUNC_OFFSET: 34a
BUCKET_ID: STATUS_BREAKPOINT_ntdll!RtlUnhandledExceptionFilter2
PRIMARY_PROBLEM_CLASS: STATUS_BREAKPOINT_ntdll!RtlUnhandledExceptionFilter2
FAILURE_EXCEPTION_CODE: 80000003
FAILURE_IMAGE_NAME: ntdll.dll
BUCKET_ID_IMAGE_STR: ntdll.dll
FAILURE_MODULE_NAME: ntdll
BUCKET_ID_MODULE_STR: ntdll
FAILURE_FUNCTION_NAME: RtlUnhandledExceptionFilter2
BUCKET_ID_FUNCTION_STR: RtlUnhandledExceptionFilter2
BUCKET_ID_OFFSET: 34a
BUCKET_ID_MODTIMEDATESTAMP: 578997b2
BUCKET_ID_MODCHECKSUM: 1d8dbd
BUCKET_ID_MODVER_STR: 0.0.0.0
BUCKET_ID_PREFIX_STR: STATUS_BREAKPOINT
FAILURE_PROBLEM_CLASS: STATUS_BREAKPOINT
FAILURE_SYMBOL_NAME: ntdll.dll!RtlUnhandledExceptionFilter2
FAILURE_BUCKET_ID: STATUS_BREAKPOINT_80000003_ntdll.dll!RtlUnhandledExceptionFilter2
TARGET_TIME: 2016-12-01T08:24:07.000Z
OSBUILD: 14393
OSSERVICEPACK: 0
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
USER_LCID: 0
OSBUILD_TIMESTAMP: 2016-07-16 11:21:29
BUILDDATESTAMP_STR: 160715-1616
BUILDLAB_STR: rs1_release
BUILDOSVER_STR: 10.0.14393.0.amd64fre.rs1_release.160715-1616
ANALYSIS_SESSION_ELAPSED_TIME: 20ba9
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:status_breakpoint_80000003_ntdll.dll!rtlunhandledexceptionfilter2
FAILURE_ID_HASH: {50ca479e-79a7-fd5a-2eed-5b8f14cbb537}
Followup: MachineOwner
---------