*******************************************************************************
*
*
*
Bugcheck Analysis
*
*
*
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly
exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 8285d288, Terminating object
Arg3: 8285d3fc, Process image file name
Arg4: 80604450, Explanatory message (ascii)
Debugging Details:
------------------
PROCESS_OBJECT: 8285d288
IMAGE_NAME: klif.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 41f50f6c
MODULE_NAME: klif
FAULTING_MODULE: 00000000
EXCEPTION_RECORD: f1c8f9d8 -- (.exr fffffffff1c8f9d8)
ExceptionAddress: 07041d77
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 07041d77
Attempt to read from address 07041d77
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx"
referenced memory at "0x%08lx". The memory could not be "%s".
BUGCHECK_STR: 0xF4_C0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from 80633eac to 805371aa
STACK_TEXT:
f1c8f4bc 80633eac 000000f4 00000003 8285d288 nt!KeBugCheckEx+0x1b
f1c8f4e0 8060440e 80604450 8285d288 8285d3fc
nt!PspCatchCriticalBreak+0x75
f1c8f510 f3b02a07 8285d4d0 c0000005 f1c8f604
nt!NtTerminateProcess+0x7d
WARNING: Stack unwind information not available. Following frames
may be wrong.
f1c8f584 804e46a7 badb0d00 f1c8f5fc 001e000e klif+0x15a07
f1c8f5f4 8052201c ffffffff c0000005 f1c8f9f4
nt!ZwTerminateProcess+0x11
f1c8f9b0 805083c9 f1c8f9d8 00000000 f1c8fd64
nt!KiDispatchException+0x3a0
f1c8fd34 804e12a8 0378fb48 0378fb64 00000000
nt!KiRaiseException+0x175
f1c8fd50 804dd99f 0378fb48 0378fb64 00000000
nt!NtRaiseException+0x33
f1c8fd50 07041d77 0378fb48 0378fb64 00000000 nt!KiFastCallEntry+0xfc
0378fe2c 00000000 00000000 00000000 00000000 0x7041d77
FOLLOWUP_IP:
klif+15a07
f3b02a07 ?? ???
SYMBOL_STACK_INDEX: 3
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: klif+15a07
STACK_COMMAND: kb
FAILURE_BUCKET_ID: 0xF4_C0000005_klif+15a07
BUCKET_ID: 0xF4_C0000005_klif+15a07
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\MEMORY-KAV.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is:
SRV*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free
x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Tue Jun 7 16:48:45.963 2005 (GMT-7)
System Uptime: 0 days 20:03:59.194
Loading Kernel Symbols
...........................................................................................................................................................
Loading unloaded module list
..................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdc00c). Type ".hh dbgerr001"
for details