pastebin - collaborative debugging tool
nrubsig.kpaste.net RSS


Crash with Dan's copysup patches
Posted by Anonymous on Sun 20th Sep 2026 11:31
raw | new post

  1.  
  2. Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64
  3. Copyright (c) Microsoft Corporation. All rights reserved.
  4.  
  5.  
  6. Loading Dump File [C:\Windows\MEMORY.DMP]
  7. Kernel Bitmap Dump File: Full address space is available
  8.  
  9. Symbol search path is: srv*
  10. Executable search path is:
  11. Windows 10 Kernel Version 19041 MP (8 procs) Free x64
  12. Product: WinNt, suite: TerminalServer SingleUserTS
  13. Built by: 19041.1.amd64fre.vb_release.191206-1406
  14. Machine Name:
  15. Kernel base = 0xfffff806`38a00000 PsLoadedModuleList = 0xfffff806`3962a420
  16. Debug session time: Sun Sep 20 08:27:11.219 2026 (UTC + 2:00)
  17. System Uptime: 0 days 12:34:37.134
  18. Loading Kernel Symbols
  19. ...............................................................
  20. ................................................................
  21. ................................................................
  22.  
  23. Loading User Symbols
  24.  
  25. Loading unloaded module list
  26. ............
  27. For analysis of this file, run !analyze -v
  28. 2: kd> !analyze -v
  29. *******************************************************************************
  30. *                                                                             *
  31. *                        Bugcheck Analysis                                    *
  32. *                                                                             *
  33. *******************************************************************************
  34.  
  35. PROCESS_HAS_LOCKED_PAGES (76)
  36. Caused by a driver not cleaning up correctly after an I/O.
  37. Arguments:
  38. Arg1: 0000000000000000, Locked memory pages found in process being terminated.
  39. Arg2: ffffae8cadc6b080, Process address.
  40. Arg3: 0000000000000002, Number of locked pages.
  41. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not.
  42.         Issue a !search over all of physical memory for the current process pointer.
  43.         This will yield at least one MDL which points to it.  Then do another !search
  44.         for each MDL found, this will yield the IRP(s) that point to it, revealing
  45.         which driver is leaking the pages.
  46.         Otherwise, set HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory
  47.         Management\TrackLockedPages to a DWORD 1 value and reboot.  Then the system
  48.         will save stack traces so the guilty driver can be easily identified.
  49.         When you enable this flag, if the driver commits the error again you will
  50.         see a different bugcheck - DRIVER_LEFT_LOCKED_PAGES_IN_PROCESS (0xCB) -
  51.         which can identify the offending driver(s).
  52.  
  53. Debugging Details:
  54. ------------------
  55.  
  56.  
  57. KEY_VALUES_STRING: 1
  58.  
  59.     Key  : Analysis.CPU.Sec
  60.     Value: 4
  61.  
  62.     Key  : Analysis.DebugAnalysisProvider.CPP
  63.     Value: Create: 8007007e on WINGRENDEL02
  64.  
  65.     Key  : Analysis.DebugData
  66.     Value: CreateObject
  67.  
  68.     Key  : Analysis.DebugModel
  69.     Value: CreateObject
  70.  
  71.     Key  : Analysis.Elapsed.Sec
  72.     Value: 7
  73.  
  74.     Key  : Analysis.Memory.CommitPeak.Mb
  75.     Value: 68
  76.  
  77.     Key  : Analysis.System
  78.     Value: CreateObject
  79.  
  80.  
  81. BUGCHECK_P1: 0
  82.  
  83. BUGCHECK_P2: ffffae8cadc6b080
  84.  
  85. BUGCHECK_P3: 2
  86.  
  87. BUGCHECK_P4: 0
  88.  
  89. PROCESS_NAME:  install.exe
  90.  
  91. BLACKBOXBSD: 1 (!blackboxbsd)
  92.  
  93.  
  94. BLACKBOXNTFS: 1 (!blackboxntfs)
  95.  
  96.  
  97. BLACKBOXWINLOGON: 1
  98.  
  99. STACK_TEXT:  
  100. ffffc583`16587988 fffff806`392016e9 : 00000000`00000076 00000000`00000000 ffffae8c`adc6b080 00000000`00000002 : nt!KeBugCheckEx
  101. ffffc583`16587990 fffff806`39013c5f : ffffae8c`adc6b080 ffffc583`16587a50 ffffae8c`aff7b040 ffffae8c`adc6b4c8 : nt!MmDeleteProcessAddressSpace+0x1a1545
  102. ffffc583`165879e0 fffff806`3903dbe0 : ffffae8c`adc6b050 ffffae8c`adc6b050 00000000`00000001 ffffae8c`a3ca3220 : nt!PspProcessDelete+0x13f
  103. ffffc583`16587a70 fffff806`39063ff4 : 00000000`00000000 ffffae8c`adc6b050 fffff806`39063df0 ffffae8c`a3c594a0 : nt!ObpRemoveObjectRoutine+0x80
  104. ffffc583`16587ad0 fffff806`38c418f5 : ffffae8c`aff7b040 fffff806`39063df0 ffffae8c`a3c594a0 00000000`00000000 : nt!ObpProcessRemoveObjectQueue+0x204
  105. ffffc583`16587b70 fffff806`38d5d6e5 : ffffae8c`aff7b040 00000000`00000080 ffffae8c`a3c7a040 72202c78`74722000 : nt!ExpWorkerThread+0x105
  106. ffffc583`16587c10 fffff806`38e065c8 : ffffe081`a09e5180 ffffae8c`aff7b040 fffff806`38d5d690 20200a7b`0a293178 : nt!PspSystemThreadStartup+0x55
  107. ffffc583`16587c60 00000000`00000000 : ffffc583`16588000 ffffc583`16582000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
  108.  
  109.  
  110. SYMBOL_NAME:  nt!MmDeleteProcessAddressSpace+1a1545
  111.  
  112. MODULE_NAME: nt
  113.  
  114. STACK_COMMAND:  .thread ; .cxr ; kb
  115.  
  116. IMAGE_NAME:  memory_corruption
  117.  
  118. BUCKET_ID_FUNC_OFFSET:  1a1545
  119.  
  120. FAILURE_BUCKET_ID:  0x76_install.exe_nt!MmDeleteProcessAddressSpace
  121.  
  122. OS_VERSION:  10.0.19041.1
  123.  
  124. BUILDLAB_STR:  vb_release
  125.  
  126. OSPLATFORM_TYPE:  x64
  127.  
  128. OSNAME:  Windows 10
  129.  
  130. FAILURE_ID_HASH:  {af29bd20-22d9-87ee-acec-35605abe09d1}
  131.  
  132. Followup:     MachineOwner
  133. ---------
  134.  
  135. 2: kd> kp
  136.  # Child-SP          RetAddr           Call Site
  137. 00 ffffc583`16587988 fffff806`392016e9 nt!KeBugCheckEx
  138. 01 ffffc583`16587990 fffff806`39013c5f nt!MmDeleteProcessAddressSpace+0x1a1545
  139. 02 ffffc583`165879e0 fffff806`3903dbe0 nt!PspProcessDelete+0x13f
  140. 03 ffffc583`16587a70 fffff806`39063ff4 nt!ObpRemoveObjectRoutine+0x80
  141. 04 ffffc583`16587ad0 fffff806`38c418f5 nt!ObpProcessRemoveObjectQueue+0x204
  142. 05 ffffc583`16587b70 fffff806`38d5d6e5 nt!ExpWorkerThread+0x105
  143. 06 ffffc583`16587c10 fffff806`38e065c8 nt!PspSystemThreadStartup+0x55
  144. 07 ffffc583`16587c60 00000000`00000000 nt!KiStartSystemThread+0x28

Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.

Syntax highlighting:

To highlight particular lines, prefix each line with {%HIGHLIGHT}




All content is user-submitted.
The administrators of this site (kpaste.net) are not responsible for their content.
Abuse reports should be emailed to us at