...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 0, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+454f5 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, An illegal page fault occurred while holding working set synchronization.
Parameter 2 contains the referenced virtual address.
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800d17d700 -- (.trap 0xfffff8800d17d700)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000fffffffff rbx=0000000000000000 rcx=0000000000002b26
rdx=0000000000930975 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000341e93d rsp=fffff8800d17d890 rbp=fffff8800d17db60
r8=fb00000930975847 r9=84000000000003e0 r10=fffff68000015930
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiGetWorkingSetInfoList+0x589:
fffff800`0341e93d 458b0424 mov r8d,dword ptr [r12] ds:00000000`00000000=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003416d32 to fffff8000347dc00
STACK_TEXT:
fffff880`0d17d598 fffff800`03416d32 : 00000000`0000001a 00000000`00041287 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`0d17d5a0 fffff800`0347bd2e : 00000000`00000000 00000000`00000000 fffffa80`01871e00 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x454f5
fffff880`0d17d700 fffff800`0341e93d : 00000000`05008001 00000000`00000000 fffffa80`000000a0 fffff880`00000000 : nt!KiPageFault+0x16e
fffff880`0d17d890 fffff800`03758be8 : 00000000`00000000 00000000`00000001 fffffa80`0e614060 00020bea`00020410 : nt!MiGetWorkingSetInfoList+0x589
fffff880`0d17d980 fffff800`0347ce93 : 00000000`0000019c fffffa80`0f17c640 00000000`00000000 00000000`0118e508 : nt!NtQueryVirtualMemory+0x696
fffff880`0d17da70 00000000`7731154a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0118e4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7731154a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+454f5
fffff800`03416d32 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+454f5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5147d9c6
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+454f5
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+454f5
Followup: MachineOwner
---------