*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 8285d288, Terminating object
Arg3: 8285d3fc, Process image file name
Arg4: 80604450, Explanatory message (ascii)

Debugging Details:
------------------


PROCESS_OBJECT:  8285d288

IMAGE_NAME:  klif.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  41f50f6c

MODULE_NAME:  klif

FAULTING_MODULE: 00000000

EXCEPTION_RECORD:  f1c8f9d8 -- (.exr fffffffff1c8f9d8)
ExceptionAddress: 07041d77
  ExceptionCode: c0000005 (Access violation)
 ExceptionFlags: 00000000
NumberParameters: 2
  Parameter[0]: 00000000
  Parameter[1]: 07041d77
Attempt to read from address 07041d77

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

BUGCHECK_STR:  0xF4_C0000005

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  DRIVER_FAULT

PROCESS_NAME:  csrss.exe

LAST_CONTROL_TRANSFER:  from 80633eac to 805371aa

STACK_TEXT:  
f1c8f4bc 80633eac 000000f4 00000003 8285d288 nt!KeBugCheckEx+0x1b
f1c8f4e0 8060440e 80604450 8285d288 8285d3fc nt!PspCatchCriticalBreak+0x75
f1c8f510 f3b02a07 8285d4d0 c0000005 f1c8f604 nt!NtTerminateProcess+0x7d
WARNING: Stack unwind information not available. Following frames may be wrong.
f1c8f584 804e46a7 badb0d00 f1c8f5fc 001e000e klif+0x15a07
f1c8f5f4 8052201c ffffffff c0000005 f1c8f9f4 nt!ZwTerminateProcess+0x11
f1c8f9b0 805083c9 f1c8f9d8 00000000 f1c8fd64 nt!KiDispatchException+0x3a0
f1c8fd34 804e12a8 0378fb48 0378fb64 00000000 nt!KiRaiseException+0x175
f1c8fd50 804dd99f 0378fb48 0378fb64 00000000 nt!NtRaiseException+0x33
f1c8fd50 07041d77 0378fb48 0378fb64 00000000 nt!KiFastCallEntry+0xfc
0378fe2c 00000000 00000000 00000000 00000000 0x7041d77


FOLLOWUP_IP:
klif+15a07
f3b02a07 ??               ???

SYMBOL_STACK_INDEX:  3

FOLLOWUP_NAME:  MachineOwner

SYMBOL_NAME:  klif+15a07

STACK_COMMAND:  kb

FAILURE_BUCKET_ID:  0xF4_C0000005_klif+15a07

BUCKET_ID:  0xF4_C0000005_klif+15a07

Followup: MachineOwner
---------

Microsoft (R) Windows Debugger  Version 6.4.0007.2
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\MEMORY-KAV.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805624a0
Debug session time: Tue Jun  7 16:48:45.963 2005 (GMT-7)
System Uptime: 0 days 20:03:59.194
Loading Kernel Symbols
...........................................................................................................................................................
Loading unloaded module list
..................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdc00c).  Type ".hh dbgerr001" for details