[list=1]
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\morbias419\Windows_NT6_BSOD_jcgriff2\040212-29484-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17727.amd64fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0xfffff800`03015000 PsLoadedModuleList = 0xfffff800`03259650
Debug session time: Mon Apr 2 18:51:04.890 2012 (UTC - 6:00)
System Uptime: 0 days 0:12:31.466
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 109, {a3a039d89ffe5677, b3b7465ef27b25dd, fffff800033b9ff0, 1}
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a039d89ffe5677, Reserved
Arg2: b3b7465ef27b25dd, Reserved
Arg3: fffff800033b9ff0, Failure type dependent information
Arg4: 0000000000000001, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
Debugging Details:
------------------
BUGCHECK_STR: 0x109
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80003091d40
STACK_TEXT:
fffff880`031c45d8 00000000`00000000 : 00000000`00000109 a3a039d8`9ffe5677 b3b7465e`f27b25dd fffff800`033b9ff0 : nt!KeBugCheckEx
STACK_COMMAND: kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: BAD_STACK
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\morbias419\Windows_NT6_BSOD_jcgriff2\040212-23992-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17727.amd64fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0xfffff800`03065000 PsLoadedModuleList = 0xfffff800`032a9650
Debug session time: Mon Apr 2 18:37:15.312 2012 (UTC - 6:00)
System Uptime: 0 days 1:30:25.498
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800033d739e, fffff88003a74ab0, 0}
Probably caused by : ntkrnlmp.exe ( nt!ObpWaitForMultipleObjects+173 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800033d739e, Address of the instruction which caused the bugcheck
Arg3: fffff88003a74ab0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObpWaitForMultipleObjects+173
fffff800`033d739e 0fb64718 movzx eax,byte ptr [rdi+18h]
CONTEXT: fffff88003a74ab0 -- (.cxr 0xfffff88003a74ab0)
rax=00000000ffefffff rbx=fffff8a00dfc60d0 rcx=0000000000000000
rdx=fffffa80099e3901 rsi=0000000000000006 rdi=0000000000000000
rip=fffff800033d739e rsp=fffff88003a75490 rbp=fffff88003a75ca0
r8=0000000000000010 r9=fffff8a00dfac000 r10=fffffa800a6ae060
r11=fffffffffffffd80 r12=fffff88003a759c8 r13=fffff8a00b69f8f0
r14=0000000000000005 r15=0000000000000007
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ObpWaitForMultipleObjects+0x173:
fffff800`033d739e 0fb64718 movzx eax,byte ptr [rdi+18h] ds:002b:00000000`00000018=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: lotroclient.ex
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800033d739e
STACK_TEXT:
fffff880`03a75490 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpWaitForMultipleObjects+0x173
FOLLOWUP_IP:
nt!ObpWaitForMultipleObjects+173
fffff800`033d739e 0fb64718 movzx eax,byte ptr [rdi+18h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ObpWaitForMultipleObjects+173
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4ec79dd2
STACK_COMMAND: .cxr 0xfffff88003a74ab0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ObpWaitForMultipleObjects+173
BUCKET_ID: X64_0x3B_nt!ObpWaitForMultipleObjects+173
Followup: MachineOwner
---------
[/list]