Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\121311-34367-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03c09000 PsLoadedModuleList = 0xfffff800`03e4e670
Debug session time: Tue Dec 13 05:38:37.838 2011 (UTC - 8:00)
System Uptime: 3 days 7:09:28.010
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa8008e54b30, fffffa8008e54e10, fffff80003f898b0}
Probably caused by : csrss.exe
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa8008e54b30, Terminating object
Arg3: fffffa8008e54e10, Process image file name
Arg4: fffff80003f898b0, Explanatory message (ascii)
Debugging Details:
------------------
PROCESS_OBJECT: fffffa8008e54b30
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0xF4_C0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
fffff880`07a970e8 fffff800`040105e2 : 00000000`000000f4 00000000`00000003 fffffa80`08e54b30 fffffa80`08e54e10 : nt!KeBugCheckEx
fffff880`07a970f0 fffff800`03fbd99b : ffffffff`ffffffff fffffa80`08cde060 fffffa80`08e54b30 fffffa80`08e54b30 : nt!PspCatchCriticalBreak+0x92
fffff880`07a97130 fffff800`03f3d448 : ffffffff`ffffffff 00000000`00000001 fffffa80`08e54b30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x176d6
fffff880`07a97180 fffff800`03c84ed3 : fffffa80`08e54b30 fffff800`c0000005 fffffa80`08cde060 00000000`02a308c0 : nt!NtTerminateProcess+0xf4
fffff880`07a97200 fffff800`03c81470 : fffff800`03cd167f fffff880`07a97b78 fffff880`07a978d0 fffff880`07a97c20 : nt!KiSystemServiceCopyEnd+0x13
fffff880`07a97398 fffff800`03cd167f : fffff880`07a97b78 fffff880`07a978d0 fffff880`07a97c20 00000000`02a32100 : nt!KiServiceLinkage
fffff880`07a973a0 fffff800`03c852c2 : fffff880`07a97b78 00000000`00011a44 fffff880`07a97c20 00000000`02a31bd8 : nt! ?? ::FNODOBFM::`string'+0x49874
fffff880`07a97a40 fffff800`03c83e3a : 00000000`00000001 00000000`02a30e78 00000000`00000001 00000000`00011a44 : nt!KiExceptionDispatch+0xc2
fffff880`07a97c20 00000000`776e8e3d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
00000000`02a30e80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776e8e3d
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
Followup: MachineOwner
---------
1: kd> !process fffffa8008e54b30 3
GetPointerFromAddress: unable to read from fffff80003eb8000
PROCESS fffffa8008e54b30
SessionId: none Cid: 01fc Peb: 7fffffdf000 ParentCid: 016c
DirBase: 1d3d9e000 ObjectTable: fffff8a00141a0a0 HandleCount: <Data Not Accessible>
Image: csrss.exe
VadRoot fffffa800a7f7a80 Vads 95 Clone 0 Private 788. Modified 4218. Locked 0.
DeviceMap fffff8a000008bb0
Token fffff8a0014adb40
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 0
QuotaPoolUsage[NonPagedPool] 0
Working Set Sizes (now,min,max) (1622, 50, 345) (6488KB, 200KB, 1380KB)
PeakWorkingSetSize 1622
VirtualSize 49 Mb
PeakVirtualSize 57 Mb
PageFaultCount 5956
MemoryPriority BACKGROUND
BasePriority 13
CommitCharge 1105
*** Error in reading nt!_ETHREAD @ fffffa80091ca060