Kernel base = 0xfffff800`02a08000 PsLoadedModuleList = 0xfffff800`02c45e50
Debug session time: Fri Oct 15 18:17:10.610 2010 (GMT-4)
System Uptime: 0 days 21:25:16.186
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa80061e9060, fffffa80061e9340, fffff80002d835d0}
Probably caused by : csrss.exe
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa80061e9060, Terminating object
Arg3: fffffa80061e9340, Process image file name
Arg4: fffff80002d835d0, Explanatory message (ascii)
Debugging Details:
------------------
PROCESS_OBJECT: fffffa80061e9060
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: csrss.exe
EXCEPTION_RECORD: fffff88002185b78 -- (.exr 0xfffff88002185b78)
ExceptionAddress: 00000000778e592d
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 00000000004d0e58
Attempt to write to address 00000000004d0e58
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 00000000004d0e58
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cb00e0
00000000004d0e58
FOLLOWUP_IP:
+5acb952f01b2d8cc
00000000`778e592d ?? ???
FAULTING_IP:
+5acb952f01b2d8cc
00000000`778e592d ?? ???
FAILED_INSTRUCTION_ADDRESS:
+5acb952f01b2d8cc
00000000`778e592d ?? ???
BUGCHECK_STR: 0xF4_C0000005
STACK_TEXT:
fffff880`021850f8 fffff800`02e04652 : 00000000`000000f4 00000000`00000003 fffffa80`061e9060 fffffa80`061e9340 : nt!KeBugCheckEx
fffff880`02185100 fffff800`02dad3e3 : ffffffff`ffffffff fffffa80`06266b60 fffffa80`061e9060 fffffa80`061e9060 : nt!PspCatchCriticalBreak+0x92
fffff880`02185140 fffff800`02d3580c : ffffffff`ffffffff 00000000`00000001 fffffa80`061e9060 fffff6fb`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17946
fffff880`02185190 fffff800`02a77993 : fffffa80`061e9060 fffff800`c0000005 ffffe7af`d79a86ea fffffa80`06266b60 : nt!NtTerminateProcess+0x20c
fffff880`02185210 fffff800`02a73f30 : fffff800`02ab2dbc fffff880`02185b78 fffff880`021858e0 fffff880`02185c20 : nt!KiSystemServiceCopyEnd+0x13
fffff880`021853a8 fffff800`02ab2dbc : fffff880`02185b78 fffff880`021858e0 fffff880`02185c20 00000000`004d20e0 : nt!KiServiceLinkage
fffff880`021853b0 fffff800`02a77d82 : fffff880`02185b78 00000000`00071288 fffff880`02185c20 00000000`004d1bb8 : nt!KiDispatchException+0x53b
fffff880`02185a40 fffff800`02a768fa : 00000000`00000001 00000000`00071288 00000000`00000001 fffffa80`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`02185c20 00000000`778e592d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
00000000`004d0e60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778e592d
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
Followup: MachineOwner
---------