Microsoft (R) Windows Debugger Version 6.3.9600.16384 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\YUSRA\Downloads\Compressed\ZIABOGA-PC-29_01_2015_130613,63\012915-3276-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18700.amd64fre.win7sp1_gdr.141211-1742
Machine Name:
Kernel base = 0xfffff800`02202000 PsLoadedModuleList = 0xfffff800`02445890
Debug session time: Thu Jan 29 16:26:56.544 2015 (UTC + 6:00)
System Uptime: 0 days 1:10:29.434
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4A, {7798132a, 2, 0, fffff88018107b60}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceExit+245 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a)
Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL.
Arguments:
Arg1: 000000007798132a, Address of system function (system call routine)
Arg2: 0000000000000002, Current IRQL
Arg3: 0000000000000000, 0
Arg4: fffff88018107b60, 0
Debugging Details:
------------------
PROCESS_NAME: vsserv.exe
BUGCHECK_STR: RAISED_IRQL_FAULT
FAULTING_IP:
+641129873909359
00000000`7798132a ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
CURRENT_IRQL: 2
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) x86fre
LAST_CONTROL_TRANSFER: from fffff80002278429 to fffff80002278e80
STACK_TEXT:
fffff880`18107928 fffff800`02278429 : 00000000`0000004a 00000000`7798132a 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`18107930 fffff800`02278360 : 00000000`00000c20 fffff880`18107b60 00000000`00000000 fffff800`02562513 : nt!KiBugCheckDispatch+0x69
fffff880`18107a70 00000000`7798132a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`23fdfcc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7798132a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`02278360 4883ec50 sub rsp,50h
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceExit+245
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 548a6e28
IMAGE_VERSION: 6.1.7601.18700
FAILURE_BUCKET_ID: X64_RAISED_IRQL_FAULT_vsserv.exe_nt!KiSystemServiceExit+245
BUCKET_ID: X64_RAISED_IRQL_FAULT_vsserv.exe_nt!KiSystemServiceExit+245
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_raised_irql_fault_vsserv.exe_nt!kisystemserviceexit+245
FAILURE_ID_HASH: {7e9f2f5a-c8f7-350e-d3b5-490f9ba5e969}
Followup: MachineOwner
---------