I analyse a crashdump with the following results.
These output is from bugcheck 3B and 7E:
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800018bc445, Address of the instruction which caused the bugcheck
Arg3: fffff88005707a30, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
...
ADDITIONAL_DEBUG_TEXT:
You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
FAULTING_MODULE: fffff80001850000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 537fbee6
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden.
FAULTING_IP:
nt!ExpInterlockedPopEntrySList+25
fffff800`018bc445 498b08 mov rcx,qword ptr [r8]
CONTEXT: fffff88005707a30 -- (.cxr 0xfffff88005707a30;r)
rax=0000000012820001 rbx=0000000000000000 rcx=fffff8800157e500
rdx=d5d8d8ffcfdedf01 rsi=000000000010d800 rdi=0000000000000000
rip=fffff800018bc445 rsp=fffff88005708410 rbp=fffff8a00aecf2f0
r8=d5d8d8ffcfdedf00 r9=fffff880009c0180 r10=fffff8800157e500
r11=fffffa800d9aabb0 r12=fffff88001554928 r13=fffff8a00896ee50
r14=0000000000000007 r15=fffff88005708590
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExpInterlockedPopEntrySList+0x25:
fffff800`018bc445 498b08 mov rcx,qword ptr [r8] ds:002b:d5d8d8ff`cfdedf00=????????????????
Last set context:
rax=0000000012820001 rbx=0000000000000000 rcx=fffff8800157e500
rdx=d5d8d8ffcfdedf01 rsi=000000000010d800 rdi=0000000000000000
rip=fffff800018bc445 rsp=fffff88005708410 rbp=fffff8a00aecf2f0
r8=d5d8d8ffcfdedf00 r9=fffff880009c0180 r10=fffff8800157e500
r11=fffffa800d9aabb0 r12=fffff88001554928 r13=fffff8a00896ee50
r14=0000000000000007 r15=fffff88005708590
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExpInterlockedPopEntrySList+0x25:
fffff800`018bc445 498b08 mov rcx,qword ptr [r8] ds:002b:d5d8d8ff`cfdedf00=????????????????
Resetting default scope
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x3B
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff880015b6fc8 to fffff800018bc445
STACK_TEXT:
fffff880`05708410 fffff880`015b6fc8 : fffffa80`0d9aabb0 fffff880`05708480 fffffa80`00000005 00000000`00000000 : nt!ExpInterlockedPopEntrySList+0x25
fffff880`05708420 fffff880`015b6f82 : 00000000`00000000 fffff880`01578798 00000000`00000000 00000000`00000000 : symefasi+0x16efc8
fffff880`05708470 fffff880`015b5ab9 : 00000000`00000000 fffff8a0`0896eea0 fffffa80`0cf4a1b0 fffff800`018d53cc : symefasi+0x16ef82
fffff880`057084c0 fffff880`015b5fd6 : 00000000`00000106 fffff880`012c750c 00000000`00000106 fffff8a0`0896eec8 : symefasi+0x16dab9
fffff880`05708560 fffff880`015a8123 : fffff8a0`0896ed40 fffff8a0`0896ed40 fffffa80`0eeb5d90 fffffa80`0a309070 : symefasi+0x16dfd6
fffff880`05708610 fffff880`015adb1b : fffff8a0`0896ed40 00000000`00000000 00000000`00000000 fffff8a0`0896ee48 : symefasi+0x160123
fffff880`05708650 fffff880`015ad39e : 00000000`00000000 fffff880`01578798 00000000`00000000 00000000`00000001 : symefasi+0x165b1b
fffff880`057086d0 fffff880`015aa095 : fffff8a0`0000004b 00000000`00000000 fffff8a0`15c409f0 00000000`000007ff : symefasi+0x16539e
fffff880`05708770 fffff880`0158cc9f : fffffa80`0acdb040 fffffa80`0d917988 00000000`00000000 fffff880`05708b60 : symefasi+0x162095
fffff880`05708890 fffff800`01be2fe7 : fffffa80`0b953b00 fffff880`05708b60 fffffa80`0b953b00 fffffa80`0d917870 : symefasi+0x144c9f
fffff880`057088d0 fffff800`01be3846 : 00000000`054be788 00000000`00001c04 00000000`00000001 00000000`05b9ed1c : nt!NtMapViewOfSection+0x15f7
fffff880`05708a00 fffff800`018c37d3 : 00000000`00000000 fffff880`05708b60 00000000`00000000 fffff800`01bb122b : nt!NtDeviceIoControlFile+0x56
fffff880`05708a70 00000000`74ac2e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeSynchronizeExecution+0x3a23
00000000`054bf038 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x74ac2e09
FOLLOWUP_IP:
symefasi+16efc8
fffff880`015b6fc8 4885c0 test rax,rax
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: symefasi+16efc8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: symefasi
IMAGE_NAME: symefasi.sys
IMAGE_VERSION: 5.0.1.29
STACK_COMMAND: .cxr 0xfffff88005707a30 ; kb
BUCKET_ID: WRONG_SYMBOLS
FAILURE_BUCKET_ID: WRONG_SYMBOLS
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:wrong_symbols
FAILURE_ID_HASH: {70b057e8-2462-896f-28e7-ac72d4d365f8}
Followup: MachineOwner
---------