Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

BSOD .dmp file analyzed with WinDbg. Please help!


  • Please log in to reply
1 reply to this topic

#1 dlee25

dlee25

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:23 AM

Posted 22 July 2016 - 01:00 PM

Microsoft ® Windows Debugger Version 10.0.10586.567 AMD64
Copyright © Microsoft Corporation. All rights reserved.
 
 
Loading Dump File [C:\Users\dlee\Desktop\MEMORY.DMP]
Kernel Summary Dump File: Kernel address space is available, User address space may not be available.
 
 
************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.23418.amd64fre.win7sp1_ldr.160408-2045
Machine Name:
Kernel base = 0xfffff800`02e09000 PsLoadedModuleList = 0xfffff800`0304b730
Debug session time: Thu Jul 21 15:16:01.127 2016 (UTC - 4:00)
System Uptime: 0 days 2:32:17.572
Loading Kernel Symbols
...............................................................
................................................................
...................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffd5018).  Type ".hh dbgerr001" for details
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
 
Use !analyze -v to get detailed debugging information.
 
BugCheck A, {80, 2, 1, fffff80002e823ef}
 
Probably caused by : ntkrnlmp.exe ( nt!KeAcquireInStackQueuedSpinLock+5f )
 
Followup:     MachineOwner
---------
 
1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
 
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000080, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002e823ef, address which referenced memory
 
Debugging Details:
------------------
 
 
DUMP_CLASS: 1
 
DUMP_QUALIFIER: 401
 
BUILD_VERSION_STRING:  7601.23418.amd64fre.win7sp1_ldr.160408-2045
 
SYSTEM_MANUFACTURER:  LENOVO
 
SYSTEM_PRODUCT_NAME:  23594LU
 
SYSTEM_SKU:  LENOVO_MT_2359
 
SYSTEM_VERSION:  ThinkPad T530
 
BIOS_VENDOR:  LENOVO
 
BIOS_VERSION:  G4ET93WW (2.53 )
 
BIOS_DATE:  02/22/2013
 
BASEBOARD_MANUFACTURER:  LENOVO
 
BASEBOARD_PRODUCT:  23594LU
 
BASEBOARD_VERSION:  Win8 Pro DPK TPG
 
DUMP_TYPE:  1
 
BUGCHECK_P1: 80
 
BUGCHECK_P2: 2
 
BUGCHECK_P3: 1
 
BUGCHECK_P4: fffff80002e823ef
 
WRITE_ADDRESS:  0000000000000080 
 
CURRENT_IRQL:  2
 
FAULTING_IP: 
nt!KeAcquireInStackQueuedSpinLock+5f
fffff800`02e823ef 488717          xchg    rdx,qword ptr [rdi]
 
CPU_COUNT: 4
 
CPU_MHZ: a22
 
CPU_VENDOR:  GenuineIntel
 
CPU_FAMILY: 6
 
CPU_MODEL: 3a
 
CPU_STEPPING: 9
 
CPU_MICROCODE: 6,3a,9,0 (F,M,S,R)  SIG: 1B'00000000 (cache) 1B'00000000 (init)
 
DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT
 
BUGCHECK_STR:  0xA
 
PROCESS_NAME:  taskhost.exe
 
ANALYSIS_SESSION_HOST:  ALR90FGS25DLEE
 
ANALYSIS_SESSION_TIME:  07-22-2016 13:55:52.0500
 
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
 
TRAP_FRAME:  fffff8800a221ef0 -- (.trap 0xfffff8800a221ef0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=fffff8800a222100 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002e823ef rsp=fffff8800a222080 rbp=0000000000000000
 r8=fffff8800a222100  r9=00000000ffffffff r10=ffffffffffffffff
r11=fffff8800a222120 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
nt!KeAcquireInStackQueuedSpinLock+0x5f:
fffff800`02e823ef 488717          xchg    rdx,qword ptr [rdi] ds:00000000`00000000=????????????????
Resetting default scope
 
LAST_CONTROL_TRANSFER:  from fffff80002e779a9 to fffff80002e78400
 
STACK_TEXT:  
fffff880`0a221da8 fffff800`02e779a9 : 00000000`0000000a 00000000`00000080 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`0a221db0 fffff800`02e76620 : 00000000`00000000 00000000`00000000 00000000`00040004 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`0a221ef0 fffff800`02e823ef : 00000000`00000000 fffff6fb`7da00000 fffffa80`0676a3c0 fffff680`0012a000 : nt!KiPageFault+0x260
fffff880`0a222080 fffff800`02f394be : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`08712410 : nt!KeAcquireInStackQueuedSpinLock+0x5f
fffff880`0a2220d0 fffff800`02ef746f : ffff0000`00002028 fffff680`0012a000 fffff680`0012a008 000fffff`00000005 : nt!MiReleaseConfirmedPageFileSpace+0x5e
fffff880`0a222150 fffff800`02e65fd2 : 00000000`00000001 00000000`0000cf59 fffffa80`0676a3c0 fffffa80`0676a758 : nt! ?? ::FNODOBFM::`string'+0x3eb16
fffff880`0a2229e0 fffff800`02e77693 : ffffffff`ffffffff 00000000`080bf498 00000000`080bf490 00000000`00004000 : nt!NtFreeVirtualMemory+0x382
fffff880`0a222ae0 00000000`76dfbd1a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`080bf458 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76dfbd1a
 
 
STACK_COMMAND:  kb
 
THREAD_SHA1_HASH_MOD_FUNC:  f543311ec6406f28e4a8eaf85693200c73a0d7ed
 
THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  5ba80191c57cc689f45b6aaf3efee1a87828b193
 
THREAD_SHA1_HASH_MOD:  cb5f414824c2521bcc505eaa03e92fa10922dad8
 
FOLLOWUP_IP: 
nt!KeAcquireInStackQueuedSpinLock+5f
fffff800`02e823ef 488717          xchg    rdx,qword ptr [rdi]
 
FAULT_INSTR_CODE:  48178748
 
SYMBOL_STACK_INDEX:  3
 
SYMBOL_NAME:  nt!KeAcquireInStackQueuedSpinLock+5f
 
FOLLOWUP_NAME:  MachineOwner
 
MODULE_NAME: nt
 
IMAGE_NAME:  ntkrnlmp.exe
 
DEBUG_FLR_IMAGE_TIMESTAMP:  5708972e
 
IMAGE_VERSION:  6.1.7601.23418
 
FAILURE_BUCKET_ID:  X64_0xA_nt!KeAcquireInStackQueuedSpinLock+5f
 
BUCKET_ID:  X64_0xA_nt!KeAcquireInStackQueuedSpinLock+5f
 
PRIMARY_PROBLEM_CLASS:  X64_0xA_nt!KeAcquireInStackQueuedSpinLock+5f
 
TARGET_TIME:  2016-07-21T19:16:01.000Z
 
OSBUILD:  7601
 
OSSERVICEPACK:  1000
 
SERVICEPACK_NUMBER: 0
 
OS_REVISION: 0
 
SUITE_MASK:  272
 
PRODUCT_TYPE:  1
 
OSPLATFORM_TYPE:  x64
 
OSNAME:  Windows 7
 
OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
 
OS_LOCALE:  
 
USER_LCID:  0
 
OSBUILD_TIMESTAMP:  2016-04-09 01:46:22
 
BUILDDATESTAMP_STR:  160408-2045
 
BUILDLAB_STR:  win7sp1_ldr
 
BUILDOSVER_STR:  6.1.7601.23418.amd64fre.win7sp1_ldr.160408-2045
 
ANALYSIS_SESSION_ELAPSED_TIME: 1152
 
ANALYSIS_SOURCE:  KM
 
FAILURE_ID_HASH_STRING:  km:x64_0xa_nt!keacquireinstackqueuedspinlock+5f
 
FAILURE_ID_HASH:  {0c6bb21b-b106-85cc-abdd-146bda985624}
 
Followup:     MachineOwner
---------

Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,893 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:10:23 AM

Posted 22 July 2016 - 02:50 PM

How to receive help diagnosing Blue Screens and Windows crashes - http://www.bleepingcomputer.com/forums/topic176011.html

 

Louis






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users