************* Symbol Path validation summary ************** Response Time (ms) Location Deferred SRV*C:\Program Files (x86)\Windows Kits\8.1\Debuggers\x64\srcsrv\Symbol*http://msdl.microsoft.com/download/symbols Loading Dump File [C:\Windows\MEMORY.DMP] Kernel Bitmap Dump File: Only kernel address space is available ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred SRV*C:\Program Files (x86)\Windows Kits\8.1\Debuggers\x64\srcsrv\Symbol*http://msdl.microsoft.com/download/symbols Symbol search path is: SRV*C:\Program Files (x86)\Windows Kits\8.1\Debuggers\x64\srcsrv\Symbol*http://msdl.microsoft.com/download/symbols Executable search path is: Windows 8 Kernel Version 9600 MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 9600.17476.amd64fre.winblue_r5.141029-1500 Machine Name: Kernel base = 0xfffff801`31804000 PsLoadedModuleList = 0xfffff801`31add250 Debug session time: Sun Jan 4 15:22:58.090 2015 (UTC + 1:00) System Uptime: 0 days 0:00:05.807 Loading Kernel Symbols ............................................................... ................................................................ ... Loading User Symbols PEB is paged out (Peb.Ldr = 00007ff6`6450c018). Type ".hh dbgerr001" for details Loading unloaded module list ... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1A, {41287, 38, 0, 0} Page 125312 not present in the dump file. Type ".hh dbgerr004" for details Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+143c2 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* MEMORY_MANAGEMENT (1a) # Any other values for parameter 1 must be individually examined. Arguments: Arg1: 0000000000041287, An illegal page fault occurred while holding working set synchronization. Parameter 2 contains the referenced virtual address. Arg2: 0000000000000038 Arg3: 0000000000000000 Arg4: 0000000000000000 Debugging Details: ------------------ Page 125312 not present in the dump file. Type ".hh dbgerr004" for details BUGCHECK_STR: 0x1a_41287 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT PROCESS_NAME: svchost.exe CURRENT_IRQL: 0 ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre TRAP_FRAME: ffffd000235466c0 -- (.trap 0xffffd000235466c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffe0014e3ca8b8 rbx=0000000000000000 rcx=0000000000000000 rdx=00000007ff9c6198 rsi=0000000000000000 rdi=0000000000000000 rip=fffff8013185eda2 rsp=ffffd00023546850 rbp=0000000000000000 r8=00007ff9c6198000 r9=ffffe0014e853900 r10=0000000000000001 r11=0000000000000008 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc nt!MiZeroFault+0xa42: fffff801`3185eda2 f7413800000004 test dword ptr [rcx+38h],4000000h ds:00000000`00000038=???????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80131979372 to fffff80131954aa0 STACK_TEXT: ffffd000`235464f8 fffff801`31979372 : 00000000`0000001a 00000000`00041287 00000000`00000038 00000000`00000000 : nt!KeBugCheckEx ffffd000`23546500 fffff801`3195ed2f : 00000000`00000000 00000000`00000008 00000000`00000000 ffffd000`00000014 : nt! ?? ::FNODOBFM::`string'+0x143c2 ffffd000`235466c0 fffff801`3185eda2 : ffffe001`4923ac01 ffffe001`4dbf0750 00001000`00000004 00000000`00000000 : nt!KiPageFault+0x12f ffffd000`23546850 fffff801`3185bfc7 : 00000000`00000008 00000000`00000000 00000000`00000000 ffffd000`235469f0 : nt!MiZeroFault+0xa42 ffffd000`23546940 fffff801`3195ed2f : 00000000`00000008 000000f1`05ffeb70 ffffe001`4e4d5e01 ffffe001`4e4d5ea0 : nt!MmAccessFault+0x287 ffffd000`23546b00 00007ff9`c6198db8 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x12f 000000f1`0696f850 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`c6198db8 STACK_COMMAND: kb FOLLOWUP_IP: nt! ?? ::FNODOBFM::`string'+143c2 fffff801`31979372 cc int 3 SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+143c2 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 545167e0 IMAGE_VERSION: 6.3.9600.17476 BUCKET_ID_FUNC_OFFSET: 143c2 FAILURE_BUCKET_ID: 0x1a_41287_nt!_??_::FNODOBFM::_string_ BUCKET_ID: 0x1a_41287_nt!_??_::FNODOBFM::_string_ ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0x1a_41287_nt!_??_::fnodobfm::_string_ FAILURE_ID_HASH: {2af18422-d5d5-a2ff-662f-bc5de5db627d} Followup: MachineOwner ---------