*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 109, {a3a039d896468985, b3b7465ee8c4c747, fffff80000b96bb0, 6}
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Probably caused by : ntoskrnl.exe ( nt_fffff80000b95000+1bb0 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a039d896468985, Reserved
Arg2: b3b7465ee8c4c747, Reserved
Arg3: fffff80000b96bb0, Failure type dependent information
Arg4: 0000000000000006, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
Debugging Details:
------------------
FAULTING_IP:
nt_fffff80000b95000+1bb0
fffff800`00b96bb0 48895c2408 mov qword ptr [rsp+8],rbx
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x109
PROCESS_NAME: System
CURRENT_IRQL: 0
STACK_TEXT:
fffff880`031bd5d8 00000000`00000000 : 00000000`00000109 a3a039d8`96468985 b3b7465e`e8c4c747 fffff800`00b96bb0 : nt!KeBugCheckEx
STACK_COMMAND: kb
FOLLOWUP_IP:
nt_fffff80000b95000+1bb0
fffff800`00b96bb0 48895c2408 mov qword ptr [rsp+8],rbx
SYMBOL_NAME: nt_fffff80000b95000+1bb0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt_fffff80000b95000
IMAGE_NAME: ntoskrnl.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5149a99c
FAILURE_BUCKET_ID: X64_0x109_6_nt_fffff80000b95000+1bb0
BUCKET_ID: X64_0x109_6_nt_fffff80000b95000+1bb0
Followup: MachineOwner
---------
3: kd> lmvm nt_fffff80000b95000
start end module name
fffff800`00b95000 fffff800`00bab000 nt_fffff80000b95000 T (no symbols)
Loaded symbol image file: ntoskrnl.exe
Image path: \SystemRoot\system32\ntoskrnl.exe
Image name: ntoskrnl.exe
Timestamp: Wed Mar 20 17:50:44 2013 (5149A99C)
CheckSum: 0000B8CF
ImageSize: 00016000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4