| 1 | Waiting for pipe \\.\pipe\win2k3
|
|---|
| 2 | Waiting to reconnect...
|
|---|
| 3 | Connected to Windows Server 2003 3790 x86 compatible target at (Fri May 22 01:11:46.843 2020 (UTC - 4:00)), ptr64 FALSE
|
|---|
| 4 | Kernel Debugger connection established.
|
|---|
| 5 | Symbol search path is: C:\ac97
|
|---|
| 6 | Executable search path is: C:\ac97\
|
|---|
| 7 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntoskrnl.exe -
|
|---|
| 8 | Windows Server 2003 Kernel Version 3790 UP Free x86 compatible
|
|---|
| 9 | Built by: 3790.srv03_sp2_qfe.150316-2035
|
|---|
| 10 | Machine Name:
|
|---|
| 11 | Kernel base = 0x80800000 PsLoadedModuleList = 0x808aae88
|
|---|
| 12 | System Uptime: not available
|
|---|
| 13 | WARNING: Inaccessible path: 'C:\ac97\driver\objchk_wnet_x86\i386'
|
|---|
| 14 | WARNING: Inaccessible path: 'C:\ac97\driver'
|
|---|
| 15 | IPRT: RTMpPoke => rtMpPokeCpuUsingDpc
|
|---|
| 16 | vgdrvHeartbeatInit: Setting up heartbeat to trigger every 2000 milliseconds
|
|---|
| 17 | vgdrvNtSetupDevice: Device is ready!
|
|---|
| 18 | IPRT: RTMpPoke => rtMpPokeCpuUsingDpc
|
|---|
| 19 | IPRT: RTMpPoke => rtMpPokeCpuUsingDpc
|
|---|
| 20 |
|
|---|
| 21 | *** Fatal System Error: 0x0000007e
|
|---|
| 22 | (0xC0000005,0x89FBB46B,0xF78EE950,0xF78EE64C)
|
|---|
| 23 |
|
|---|
| 24 | Break instruction exception - code 80000003 (first chance)
|
|---|
| 25 |
|
|---|
| 26 | A fatal system error has occurred.
|
|---|
| 27 | Debugger entered on first try; Bugcheck callbacks have not been invoked.
|
|---|
| 28 |
|
|---|
| 29 | A fatal system error has occurred.
|
|---|
| 30 |
|
|---|
| 31 | Connected to Windows Server 2003 3790 x86 compatible target at (Fri May 22 01:11:52.812 2020 (UTC - 4:00)), ptr64 FALSE
|
|---|
| 32 | Loading Kernel Symbols
|
|---|
| 33 | .........................................
|
|---|
| 34 | Loading User Symbols
|
|---|
| 35 |
|
|---|
| 36 | *******************************************************************************
|
|---|
| 37 | * *
|
|---|
| 38 | * Bugcheck Analysis *
|
|---|
| 39 | * *
|
|---|
| 40 | *******************************************************************************
|
|---|
| 41 |
|
|---|
| 42 | Use !analyze -v to get detailed debugging information.
|
|---|
| 43 |
|
|---|
| 44 | BugCheck 7E, {c0000005, 89fbb46b, f78ee950, f78ee64c}
|
|---|
| 45 |
|
|---|
| 46 | *** No owner thread found for resource 808a9960
|
|---|
| 47 | *** No owner thread found for resource 808a9960
|
|---|
| 48 | *** No owner thread found for resource 808a9960
|
|---|
| 49 | Probably caused by : ntoskrnl.exe ( nt!PipProcessDevNodeTree+1a4 )
|
|---|
| 50 |
|
|---|
| 51 | Followup: MachineOwner
|
|---|
| 52 | ---------
|
|---|
| 53 |
|
|---|
| 54 | nt!RtlpBreakWithStatusInstruction:
|
|---|
| 55 | 8081deee cc int 3
|
|---|
| 56 | kd> !analyze -v
|
|---|
| 57 | *******************************************************************************
|
|---|
| 58 | * *
|
|---|
| 59 | * Bugcheck Analysis *
|
|---|
| 60 | * *
|
|---|
| 61 | *******************************************************************************
|
|---|
| 62 |
|
|---|
| 63 | SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
|
|---|
| 64 | This is a very common bugcheck. Usually the exception address pinpoints
|
|---|
| 65 | the driver/function that caused the problem. Always note this address
|
|---|
| 66 | as well as the link date of the driver/image that contains this address.
|
|---|
| 67 | Arguments:
|
|---|
| 68 | Arg1: c0000005, The exception code that was not handled
|
|---|
| 69 | Arg2: 89fbb46b, The address that the exception occurred at
|
|---|
| 70 | Arg3: f78ee950, Exception Record Address
|
|---|
| 71 | Arg4: f78ee64c, Context Record Address
|
|---|
| 72 |
|
|---|
| 73 | Debugging Details:
|
|---|
| 74 | ------------------
|
|---|
| 75 |
|
|---|
| 76 | *** No owner thread found for resource 808a9960
|
|---|
| 77 | *** No owner thread found for resource 808a9960
|
|---|
| 78 | *** No owner thread found for resource 808a9960
|
|---|
| 79 |
|
|---|
| 80 | EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
|
|---|
| 81 |
|
|---|
| 82 | FAULTING_IP:
|
|---|
| 83 | +52302faf009edec0
|
|---|
| 84 | 89fbb46b 8900 mov dword ptr [eax],eax
|
|---|
| 85 |
|
|---|
| 86 | EXCEPTION_RECORD: f78ee950 -- (.exr 0xfffffffff78ee950)
|
|---|
| 87 | ExceptionAddress: 89fbb46b
|
|---|
| 88 | ExceptionCode: c0000005 (Access violation)
|
|---|
| 89 | ExceptionFlags: 00000000
|
|---|
| 90 | NumberParameters: 2
|
|---|
| 91 | Parameter[0]: 00000001
|
|---|
| 92 | Parameter[1]: 00000001
|
|---|
| 93 | Attempt to write to address 00000001
|
|---|
| 94 |
|
|---|
| 95 | CONTEXT: f78ee64c -- (.cxr 0xfffffffff78ee64c)
|
|---|
| 96 | eax=00000001 ebx=000000fb ecx=00000000 edx=00000000 esi=89fc0c80 edi=89eb9d68
|
|---|
| 97 | eip=89fbb46b esp=f78eea18 ebp=e1362b78 iopl=0 nv up ei pl nz na po nc
|
|---|
| 98 | cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
|
|---|
| 99 | 89fbb46b 8900 mov dword ptr [eax],eax ds:0023:00000001=????????
|
|---|
| 100 | Resetting default scope
|
|---|
| 101 |
|
|---|
| 102 | DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
|
|---|
| 103 |
|
|---|
| 104 | PROCESS_NAME: System
|
|---|
| 105 |
|
|---|
| 106 | CURRENT_IRQL: 0
|
|---|
| 107 |
|
|---|
| 108 | ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
|
|---|
| 109 |
|
|---|
| 110 | EXCEPTION_PARAMETER1: 00000001
|
|---|
| 111 |
|
|---|
| 112 | EXCEPTION_PARAMETER2: 00000001
|
|---|
| 113 |
|
|---|
| 114 | WRITE_ADDRESS: 00000001
|
|---|
| 115 |
|
|---|
| 116 | FOLLOWUP_IP:
|
|---|
| 117 | nt!PipProcessDevNodeTree+1a4
|
|---|
| 118 | 808e7aa7 85c0 test eax,eax
|
|---|
| 119 |
|
|---|
| 120 | FAILED_INSTRUCTION_ADDRESS:
|
|---|
| 121 | +52302faf009edec0
|
|---|
| 122 | 89fbb46b 8900 mov dword ptr [eax],eax
|
|---|
| 123 |
|
|---|
| 124 | BUGCHECK_STR: 0x7E
|
|---|
| 125 |
|
|---|
| 126 | LOCK_ADDRESS: 808a99e0 -- (!locks 808a99e0)
|
|---|
| 127 | NTSDEXTS: Unable to resolve ntdll!RtlCriticalSectionList
|
|---|
| 128 | NTSDEXTS: Please check your symbols
|
|---|
| 129 |
|
|---|
| 130 | PNP_TRIAGE:
|
|---|
| 131 | Lock address : 0x808a99e0
|
|---|
| 132 | Thread Count : 1
|
|---|
| 133 | Thread address: 0x89f98020
|
|---|
| 134 | Thread wait : 0x1c4
|
|---|
| 135 |
|
|---|
| 136 | LAST_CONTROL_TRANSFER: from 8087619b to 8081deee
|
|---|
| 137 |
|
|---|
| 138 | STACK_TEXT:
|
|---|
| 139 | WARNING: Frame IP not in any known module. Following frames may be wrong.
|
|---|
| 140 | f78eea14 ba6e000f 00000004 00000001 89e191f0 0x89fbb46b
|
|---|
| 141 | f78eead4 808e7aa7 00000000 02000001 f78eed00 AC97SMPL!PinDataRangesMicStream <PERF> (AC97SMPL+0xa00f)
|
|---|
| 142 | f78eed30 808cf042 89f85cd8 00000001 00000000 nt!PipProcessDevNodeTree+0x1a4
|
|---|
| 143 | f78eed58 8080abb6 00000003 89f98020 808b25fc nt!PiProcessStartSystemDevices+0x3a
|
|---|
| 144 | f78eed80 8082092b 00000000 00000000 89f98020 nt!PipDeviceActionWorker+0x186
|
|---|
| 145 | f78eedac 809079cb 00000000 00000000 00000000 nt!ExpWorkerThread+0xeb
|
|---|
| 146 | f78eeddc 808284bd 8082086e 00000001 00000000 nt!PspSystemThreadStartup+0x2e
|
|---|
| 147 | 00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
|
|---|
| 148 |
|
|---|
| 149 |
|
|---|
| 150 | SYMBOL_STACK_INDEX: 2
|
|---|
| 151 |
|
|---|
| 152 | SYMBOL_NAME: nt!PipProcessDevNodeTree+1a4
|
|---|
| 153 |
|
|---|
| 154 | FOLLOWUP_NAME: MachineOwner
|
|---|
| 155 |
|
|---|
| 156 | MODULE_NAME: nt
|
|---|
| 157 |
|
|---|
| 158 | IMAGE_NAME: ntoskrnl.exe
|
|---|
| 159 |
|
|---|
| 160 | DEBUG_FLR_IMAGE_TIMESTAMP: 5507c485
|
|---|
| 161 |
|
|---|
| 162 | STACK_COMMAND: .cxr 0xfffffffff78ee64c ; kb
|
|---|
| 163 |
|
|---|
| 164 | FAILURE_BUCKET_ID: 0x7E_BAD_IP_nt!PipProcessDevNodeTree+1a4
|
|---|
| 165 |
|
|---|
| 166 | BUCKET_ID: 0x7E_BAD_IP_nt!PipProcessDevNodeTree+1a4
|
|---|
| 167 |
|
|---|
| 168 | Followup: MachineOwner
|
|---|
| 169 | ---------
|
|---|
| 170 |
|
|---|