- Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\MEMORY.DMP]
- Kernel Bitmap Dump File: Full address space is available
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (8 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff806`38a00000 PsLoadedModuleList = 0xfffff806`3962a420
- Debug session time: Sun Sep 20 08:27:11.219 2026 (UTC + 2:00)
- System Uptime: 0 days 12:34:37.134
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- Loading User Symbols
- Loading unloaded module list
- ............
- For analysis of this file, run !analyze -v
- 2: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- PROCESS_HAS_LOCKED_PAGES (76)
- Caused by a driver not cleaning up correctly after an I/O.
- Arguments:
- Arg1: 0000000000000000, Locked memory pages found in process being terminated.
- Arg2: ffffae8cadc6b080, Process address.
- Arg3: 0000000000000002, Number of locked pages.
- Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not.
- Issue a !search over all of physical memory for the current process pointer.
- This will yield at least one MDL which points to it. Then do another !search
- for each MDL found, this will yield the IRP(s) that point to it, revealing
- which driver is leaking the pages.
- Otherwise, set HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory
- Management\TrackLockedPages to a DWORD 1 value and reboot. Then the system
- will save stack traces so the guilty driver can be easily identified.
- When you enable this flag, if the driver commits the error again you will
- see a different bugcheck - DRIVER_LEFT_LOCKED_PAGES_IN_PROCESS (0xCB) -
- which can identify the offending driver(s).
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.Sec
- Value: 4
- Key : Analysis.DebugAnalysisProvider.CPP
- Value: Create: 8007007e on WINGRENDEL02
- Key : Analysis.DebugData
- Value: CreateObject
- Key : Analysis.DebugModel
- Value: CreateObject
- Key : Analysis.Elapsed.Sec
- Value: 7
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 68
- Key : Analysis.System
- Value: CreateObject
- BUGCHECK_P1: 0
- BUGCHECK_P2: ffffae8cadc6b080
- BUGCHECK_P3: 2
- BUGCHECK_P4: 0
- PROCESS_NAME: install.exe
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXWINLOGON: 1
- STACK_TEXT:
- ffffc583`16587988 fffff806`392016e9 : 00000000`00000076 00000000`00000000 ffffae8c`adc6b080 00000000`00000002 : nt!KeBugCheckEx
- ffffc583`16587990 fffff806`39013c5f : ffffae8c`adc6b080 ffffc583`16587a50 ffffae8c`aff7b040 ffffae8c`adc6b4c8 : nt!MmDeleteProcessAddressSpace+0x1a1545
- ffffc583`165879e0 fffff806`3903dbe0 : ffffae8c`adc6b050 ffffae8c`adc6b050 00000000`00000001 ffffae8c`a3ca3220 : nt!PspProcessDelete+0x13f
- ffffc583`16587a70 fffff806`39063ff4 : 00000000`00000000 ffffae8c`adc6b050 fffff806`39063df0 ffffae8c`a3c594a0 : nt!ObpRemoveObjectRoutine+0x80
- ffffc583`16587ad0 fffff806`38c418f5 : ffffae8c`aff7b040 fffff806`39063df0 ffffae8c`a3c594a0 00000000`00000000 : nt!ObpProcessRemoveObjectQueue+0x204
- ffffc583`16587b70 fffff806`38d5d6e5 : ffffae8c`aff7b040 00000000`00000080 ffffae8c`a3c7a040 72202c78`74722000 : nt!ExpWorkerThread+0x105
- ffffc583`16587c10 fffff806`38e065c8 : ffffe081`a09e5180 ffffae8c`aff7b040 fffff806`38d5d690 20200a7b`0a293178 : nt!PspSystemThreadStartup+0x55
- ffffc583`16587c60 00000000`00000000 : ffffc583`16588000 ffffc583`16582000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- SYMBOL_NAME: nt!MmDeleteProcessAddressSpace+1a1545
- MODULE_NAME: nt
- STACK_COMMAND: .thread ; .cxr ; kb
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: 1a1545
- FAILURE_BUCKET_ID: 0x76_install.exe_nt!MmDeleteProcessAddressSpace
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {af29bd20-22d9-87ee-acec-35605abe09d1}
- Followup: MachineOwner
- ---------
- 2: kd> kp
- # Child-SP RetAddr Call Site
- 00 ffffc583`16587988 fffff806`392016e9 nt!KeBugCheckEx
- 01 ffffc583`16587990 fffff806`39013c5f nt!MmDeleteProcessAddressSpace+0x1a1545
- 02 ffffc583`165879e0 fffff806`3903dbe0 nt!PspProcessDelete+0x13f
- 03 ffffc583`16587a70 fffff806`39063ff4 nt!ObpRemoveObjectRoutine+0x80
- 04 ffffc583`16587ad0 fffff806`38c418f5 nt!ObpProcessRemoveObjectQueue+0x204
- 05 ffffc583`16587b70 fffff806`38d5d6e5 nt!ExpWorkerThread+0x105
- 06 ffffc583`16587c10 fffff806`38e065c8 nt!PspSystemThreadStartup+0x55
- 07 ffffc583`16587c60 00000000`00000000 nt!KiStartSystemThread+0x28
Crash with Dan's copysup patches
Posted by Anonymous on Sun 20th Sep 2026 11:31
raw | new post
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.
nrubsig.kpaste.net RSS