Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\jakesnake3037\Windows_NT6_BSOD_jcgriff2\030112-25443-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03018000 PsLoadedModuleList = 0xfffff800`0325d670
Debug session time: Thu Mar 1 15:27:26.865 2012 (UTC - 7:00)
System Uptime: 0 days 7:21:49.036
Loading Kernel Symbols
...............................................................
................................................................
....................................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff80003383415, 0, 1}
Probably caused by : ntkrnlmp.exe ( nt!NtSetInformationProcess+3c8 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80003383415, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000001, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!NtSetInformationProcess+3c8
fffff800`03383415 448d6bf9 lea r13d,[rbx-7]
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000001
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032c7100
0000000000000001
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0x1E_c0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: lsm.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800aba8350 -- (.trap 0xfffff8800aba8350)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffbd7f701a665e rbx=0000000000000000 rcx=ffffffffffffffff
rdx=0000000000000029 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003383415 rsp=fffff8800aba84e0 rbp=fffff8800aba88b0
r8=fffff8800aba8a48 r9=0000000000000028 r10=ffffffffffffffff
r11=00000000002ed74c r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!NtSetInformationProcess+0x3c8:
fffff800`03383415 448d6bf9 lea r13d,[rbx-7]
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030e0588 to fffff80003094c40
STACK_TEXT:
fffff880`0aba7ac8 fffff800`030e0588 : 00000000`0000001e ffffffff`c0000005 fffff800`03383415 00000000`00000000 : nt!KeBugCheckEx
fffff880`0aba7ad0 fffff800`030942c2 : fffff880`0aba82a8 00000000`00000008 fffff880`0aba8350 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4977d
fffff880`0aba8170 fffff800`03092e3a : 00000000`00000000 00000000`00000001 fffffa80`0cff1000 00000000`00000008 : nt!KiExceptionDispatch+0xc2
fffff880`0aba8350 fffff800`03383415 : fffff880`0aba84f8 fffff8a0`0e9a45c0 00000000`72500000 ffffffff`00000014 : nt!KiPageFault+0x23a
fffff880`0aba84e0 fffff800`03093ed3 : 00000000`001fffff 00000000`00000000 fffffa80`0cd82b30 fffff800`001fffff : nt!NtSetInformationProcess+0x3c8
fffff880`0aba8830 fffff800`03090470 : fffff800`03382cce 00000000`00000000 fffff800`0338ea5f fffff8a0`00000000 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0aba89c8 fffff800`03382cce : 00000000`00000000 fffff800`0338ea5f fffff8a0`00000000 fffffa80`0cd19b08 : nt!KiServiceLinkage
fffff880`0aba89d0 fffff800`033812fd : 00000000`00016000 00000000`00080000 00000000`00000000 00000000`00001000 : nt!RtlCreateUserStack+0x122
fffff880`0aba8ac0 fffff800`03380f2e : fffffa80`10aa0060 fffff880`0aba9928 fffffa80`0cd19c00 fffff880`0aba9510 : nt!PspAllocateThread+0x299
fffff880`0aba8ce0 fffff800`03384e35 : 00000000`00000000 00000000`00000000 00000000`00000001 fffff880`0aba9510 : nt!PspCreateThread+0x1d2
fffff880`0aba8f60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateThreadEx+0x25d
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!NtSetInformationProcess+3c8
fffff800`03383415 448d6bf9 lea r13d,[rbx-7]
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!NtSetInformationProcess+3c8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!NtSetInformationProcess+3c8
BUCKET_ID: X64_0x1E_c0000005_nt!NtSetInformationProcess+3c8
Followup: MachineOwner
---------