*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffffa8006958bb0, 0, fffa8000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+487ad )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffffa8006958bb0, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 00000000fffa8000, Parameter 1 of the exception
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff8000350d100
GetUlongFromAddress: unable to read from fffff8000350d1c0
0000000000000000 Nonpaged pool
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
+0
fffffa80`06958bb0 f3a4 rep movs byte ptr [rdi],byte ptr [rsi]
BUGCHECK_STR: 0x1E_c0000005_R
CUSTOMER_CRASH_COUNT: 1
[B]DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: mscorsvw.exe[/B]
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800629a930 -- (.trap 0xfffff8800629a930)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000000000091c rbx=0000000000000000 rcx=000000000000011c
rdx=00000000fffa0288 rsi=0000000000000000 rdi=0000000000000000
rip=fffffa8006958bb0 rsp=fffff8800629aac0 rbp=fffff8800629abc0
r8=0000000000000004 r9=fffffa80097670b0 r10=fffffa8004252840
r11=fffffa80081ae4b0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
fffffa80`06958bb0 f3a4 rep movs byte ptr [rdi],byte ptr [rsi]
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003328a88 to fffff800032ddfc0
STACK_TEXT:
fffff880`0629a0a8 fffff800`03328a88 : 00000000`0000001e ffffffff`c0000005 fffffa80`06958bb0 00000000`00000000 : nt!KeBugCheckEx
fffff880`0629a0b0 fffff800`032dd642 : fffff880`0629a888 fffffa80`0969a680 fffff880`0629a930 00000000`fffa8000 : nt! ?? ::FNODOBFM::`string'+0x487ad
fffff880`0629a750 fffff800`032dc1ba : 00000000`00000000 00000000`fffa8000 fffff880`0629aa00 fffffa80`0969a680 : nt!KiExceptionDispatch+0xc2
fffff880`0629a930 fffffa80`06958bb0 : fffff880`0629abc0 00000000`fffa00e8 fffffa80`0695c250 fffffa80`0695f750 : nt!KiPageFault+0x23a
fffff880`0629aac0 fffff880`0629abc0 : 00000000`fffa00e8 fffffa80`0695c250 fffffa80`0695f750 00000000`00003000 : 0xfffffa80`06958bb0
fffff880`0629aac8 00000000`fffa00e8 : fffffa80`0695c250 fffffa80`0695f750 00000000`00003000 00000000`00000040 : 0xfffff880`0629abc0
fffff880`0629aad0 fffffa80`0695c250 : fffffa80`0695f750 00000000`00003000 00000000`00000040 fffff880`0629ab40 : 0xfffa00e8
fffff880`0629aad8 fffffa80`0695f750 : 00000000`00003000 00000000`00000040 fffff880`0629ab40 00000000`00000002 : 0xfffffa80`0695c250
fffff880`0629aae0 00000000`00003000 : 00000000`00000040 fffff880`0629ab40 00000000`00000002 fffff880`00100000 : 0xfffffa80`0695f750
fffff880`0629aae8 00000000`00000040 : fffff880`0629ab40 00000000`00000002 fffff880`00100000 00000000`00000002 : 0x3000
fffff880`0629aaf0 fffff880`0629ab40 : 00000000`00000002 fffff880`00100000 00000000`00000002 00000000`fffa0000 : 0x40
fffff880`0629aaf8 00000000`00000002 : fffff880`00100000 00000000`00000002 00000000`fffa0000 fffffa80`03aa4a00 : 0xfffff880`0629ab40
fffff880`0629ab00 fffff880`00100000 : 00000000`00000002 00000000`fffa0000 fffffa80`03aa4a00 00000000`00000024 : 0x2
fffff880`0629ab08 00000000`00000002 : 00000000`fffa0000 fffffa80`03aa4a00 00000000`00000024 ffffffff`80000bb4 : 0xfffff880`00100000
fffff880`0629ab10 00000000`fffa0000 : fffffa80`03aa4a00 00000000`00000024 ffffffff`80000bb4 00000000`0000a000 : 0x2
fffff880`0629ab18 fffffa80`03aa4a00 : 00000000`00000024 ffffffff`80000bb4 00000000`0000a000 00000000`00000000 : 0xfffa0000
fffff880`0629ab20 00000000`00000024 : ffffffff`80000bb4 00000000`0000a000 00000000`00000000 00000000`00009000 : 0xfffffa80`03aa4a00
fffff880`0629ab28 ffffffff`80000bb4 : 00000000`0000a000 00000000`00000000 00000000`00009000 00000000`00000030 : 0x24
fffff880`0629ab30 00000000`0000a000 : 00000000`00000000 00000000`00009000 00000000`00000030 00000000`00000000 : 0xffffffff`80000bb4
fffff880`0629ab38 00000000`00000000 : 00000000`00009000 00000000`00000030 00000000`00000000 fffff880`0629ab78 : 0xa000
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+487ad
fffff800`03328a88 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+487ad
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 503f82be
FAILURE_BUCKET_ID: X64_0x1E_c0000005_R_nt!_??_::FNODOBFM::_string_+487ad
BUCKET_ID: X64_0x1E_c0000005_R_nt!_??_::FNODOBFM::_string_+487ad
Followup: MachineOwner
---------