Microsoft (R) Windows Debugger Version 6.2.9200.16384 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Waiting for pipe \\.\pipe\com2 Waiting to reconnect... Connected to Windows Vista 6000 x64 target at (Mon May 6 19:38:05.658 2013 (UTC + 1:00)), ptr64 TRUE Kernel Debugger connection established. Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe - Windows Vista Kernel Version 6000 MP (1 procs) Free x64 Built by: 6000.17021.amd64fre.vista_gdr.100218-0019 Machine Name: Kernel base = 0xfffff800`01800000 PsLoadedModuleList = 0xfffff800`0199af70 System Uptime: not available Break instruction exception - code 80000003 (first chance) ******************************************************************************* * * * You are seeing this message because you pressed either * * CTRL+C (if you run console kernel debugger) or, * * CTRL+BREAK (if you run GUI kernel debugger), * * on your debugger machine's keyboard. * * * * THIS IS NOT A BUG OR A SYSTEM CRASH * * * * If you did not intend to break into the debugger, press the "g" key, then * * press the "Enter" key now. This message might immediately reappear. If it * * does, press "g" and "Enter" again. * * * ******************************************************************************* nt!RtlpBreakWithStatusInstruction: fffff800`018472a0 cc int 3 1: kd> kv Child-SP RetAddr : Args to Child : Call Site fffff980`01270998 fffff800`018366eb : 00000000`00000062 fffff980`00a99180 fffff980`012709c0 00000000`00000000 : nt!RtlpBreakWithStatusInstruction fffff980`012709a0 fffff800`01850baf : 00000000`00000001 fffff980`00a99180 fffffa80`027c518f fffff980`01270a70 : nt! ?? ::FNODOBFM::`string'+0x42b6 fffff980`012709f0 fffff800`01ce9af9 : 00000000`00000010 00000000`00000216 fffff980`01270ba0 00000000`00000018 : nt!KiSecondaryClockInterrupt+0x11f (TrapFrame @ fffff980`012709f0) fffff980`01270b80 fffff800`0185aea7 : fffff980`00a99180 fffff800`0194a980 00000000`0003d2e7 00000000`0003d36c : hal!HalpRequestIpiSpecifyVector+0xa9 fffff980`01270bb0 fffff800`0185a8c4 : fffffa80`00000000 fffff980`00a99180 00000000`00000000 00000000`00000000 : nt!KiDeferredReadyThread+0x467 fffff980`01270bf0 fffff800`0185954c : 00000000`007fffff fffffa80`02f82580 fffff980`00b2eed0 00000000`00000000 : nt!KiExitDispatcher+0x74 fffff980`01270c20 fffff980`00b25cc7 : fffff980`00b2eed0 00000bd5`abc2490f fffff980`00b2ee20 fffffa80`02243230 : nt!KeSetEvent+0x2aa fffff980`01270c60 fffff800`01ae1bbb : 00000000`00000bf9 00000000`0008c400 fffffa80`00000000 00000000`00000010 : ecache!EcCacheIoWorker+0x99f fffff980`01270d50 fffff800`018344f6 : fffff980`00a99180 fffffa80`02464bb0 fffff980`00aa2c40 fffffa80`00c7a040 : nt!PspSystemThreadStartup+0x5b fffff980`01270d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16 1: kd> kv Child-SP RetAddr : Args to Child : Call Site fffff980`01270998 fffff800`018366eb : 00000000`00000062 fffff980`00a99180 fffff980`012709c0 00000000`00000000 : nt!RtlpBreakWithStatusInstruction fffff980`012709a0 fffff800`01850baf : 00000000`00000001 fffff980`00a99180 fffffa80`027c518f fffff980`01270a70 : nt! ?? ::FNODOBFM::`string'+0x42b6 fffff980`012709f0 fffff800`01ce9af9 : 00000000`00000010 00000000`00000216 fffff980`01270ba0 00000000`00000018 : nt!KiSecondaryClockInterrupt+0x11f (TrapFrame @ fffff980`012709f0) fffff980`01270b80 fffff800`0185aea7 : fffff980`00a99180 fffff800`0194a980 00000000`0003d2e7 00000000`0003d36c : hal!HalpRequestIpiSpecifyVector+0xa9 fffff980`01270bb0 fffff800`0185a8c4 : fffffa80`00000000 fffff980`00a99180 00000000`00000000 00000000`00000000 : nt!KiDeferredReadyThread+0x467 fffff980`01270bf0 fffff800`0185954c : 00000000`007fffff fffffa80`02f82580 fffff980`00b2eed0 00000000`00000000 : nt!KiExitDispatcher+0x74 fffff980`01270c20 fffff980`00b25cc7 : fffff980`00b2eed0 00000bd5`abc2490f fffff980`00b2ee20 fffffa80`02243230 : nt!KeSetEvent+0x2aa fffff980`01270c60 fffff800`01ae1bbb : 00000000`00000bf9 00000000`0008c400 fffffa80`00000000 00000000`00000010 : ecache!EcCacheIoWorker+0x99f fffff980`01270d50 fffff800`018344f6 : fffff980`00a99180 fffffa80`02464bb0 fffff980`00aa2c40 fffffa80`00c7a040 : nt!PspSystemThreadStartup+0x5b fffff980`01270d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16 1: kd> k Child-SP RetAddr Call Site fffff980`01270998 fffff800`018366eb nt!RtlpBreakWithStatusInstruction fffff980`012709a0 fffff800`01850baf nt! ?? ::FNODOBFM::`string'+0x42b6 fffff980`012709f0 fffff800`01ce9af9 nt!KiSecondaryClockInterrupt+0x11f fffff980`01270b80 fffff800`0185aea7 hal!HalpRequestIpiSpecifyVector+0xa9 fffff980`01270bb0 fffff800`0185a8c4 nt!KiDeferredReadyThread+0x467 fffff980`01270bf0 fffff800`0185954c nt!KiExitDispatcher+0x74 fffff980`01270c20 fffff980`00b25cc7 nt!KeSetEvent+0x2aa fffff980`01270c60 fffff800`01ae1bbb ecache!EcCacheIoWorker+0x99f fffff980`01270d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01270d80 00000000`00000000 nt!KxStartSystemThread+0x16 1: kd> .symfix c:\mss 1: kd> .reload Connected to Windows Vista 6000 x64 target at (Mon May 6 19:39:52.101 2013 (UTC + 1:00)), ptr64 TRUE Loading Kernel Symbols ............................................................... .............................................. Loading User Symbols Loading unloaded module list ...Unable to enumerate user-mode unloaded modules, Win32 error 0n30 1: kd> k Child-SP RetAddr Call Site fffff980`01270998 fffff800`018366eb nt!RtlpBreakWithStatusInstruction fffff980`012709a0 fffff800`01850baf nt! ?? ::FNODOBFM::`string'+0x42b6 fffff980`012709f0 fffff800`01ce9af9 nt!KiSecondaryClockInterrupt+0x11f fffff980`01270b80 fffff800`0185aea7 hal!HalpRequestIpiSpecifyVector+0xa9 fffff980`01270bb0 fffff800`0185a8c4 nt!KiDeferredReadyThread+0x467 fffff980`01270bf0 fffff800`0185954c nt!KiExitDispatcher+0x74 fffff980`01270c20 fffff980`00b25cc7 nt!KeSetEvent+0x2aa fffff980`01270c60 fffff800`01ae1bbb ecache!EcCacheIoWorker+0x99f fffff980`01270d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01270d80 00000000`00000000 nt!KxStartSystemThread+0x16 1: kd> !vm *** Virtual Memory Usage *** Physical Memory: 261872 ( 1047488 Kb) ************ NO PAGING FILE ********************* Available Pages: 159572 ( 638288 Kb) ResAvail Pages: 163988 ( 655952 Kb) Locked IO Pages: 0 ( 0 Kb) Free System PTEs: 268416049 (1073664196 Kb) Modified Pages: 856 ( 3424 Kb) Modified PF Pages: 840 ( 3360 Kb) NonPagedPool Usage: 10736 ( 42944 Kb) NonPagedPool Max: 98304 ( 393216 Kb) PagedPool 0 Usage: 1751 ( 7004 Kb) PagedPool 1 Usage: 524 ( 2096 Kb) PagedPool 2 Usage: 0 ( 0 Kb) PagedPool 3 Usage: 0 ( 0 Kb) PagedPool 4 Usage: 38 ( 152 Kb) PagedPool Usage: 2313 ( 9252 Kb) PagedPool Maximum: 33554432 ( 134217728 Kb) Session Commit: 0 ( 0 Kb) Shared Commit: 387 ( 1548 Kb) Special Pool: 0 ( 0 Kb) Shared Process: 546 ( 2184 Kb) PagedPool Commit: 2313 ( 9252 Kb) Driver Commit: 2076 ( 8304 Kb) Committed pages: 91109 ( 364436 Kb) Commit limit: 250244 ( 1000976 Kb) Total Private: 837 ( 3348 Kb) 0004 System 747 ( 2988 Kb) 0184 smss.exe 90 ( 360 Kb) 1: kd> !process 0 3f **** NT ACTIVE PROCESS DUMP **** PROCESS fffffa8000c74040 SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000 DirBase: 00124000 ObjectTable: fffff88000001fa0 HandleCount: 68. Image: System VadRoot fffffa8001c8dee0 Vads 70 Clone 0 Private 722. Modified 1638. Locked 64. DeviceMap fffff880000075b0 Token fffff880000012c0 ElapsedTime 00:00:16.676 UserTime 00:00:00.000 KernelTime 00:00:00.015 QuotaPoolUsage[PagedPool] 0 QuotaPoolUsage[NonPagedPool] 0 Working Set Sizes (now,min,max) (1068, 0, 0) (4272KB, 0KB, 0KB) PeakWorkingSetSize 2290 VirtualSize 7 Mb PeakVirtualSize 9 Mb PageFaultCount 7854 MemoryPriority BACKGROUND BasePriority 8 CommitCharge 747 PEB NULL... THREAD fffffa8000c74bb0 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (UserRequest) KernelMode Non-Alertable fffffa800223dc10 ProcessObject fffffa8000c74c68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1135 Ticks: 8 (0:00:00:00.124) Context Switch Count 1392 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:03.478 Win32 Start Address nt!Phase1Initialization (0xfffff80001bff0b0) Stack Init fffff98000609db0 Current fffff98000609650 Base fffff9800060a000 Limit fffff98000604000 Call 0 Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00609690 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`006097d0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00609830 fffff800`01a8a79b nt!KeWaitForSingleObject+0x5f5 fffff980`006098b0 fffff800`0184d5f3 nt!NtWaitForSingleObject+0x9b fffff980`00609910 fffff800`0184db00 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`00609910) fffff980`00609aa8 fffff800`01c8f2d5 nt!KiServiceLinkage fffff980`00609ab0 fffff800`01c9c453 nt!StartFirstUserProcess+0x272 fffff980`00609b90 fffff800`01bff0b9 nt!Phase1InitializationDiscard+0x10eb fffff980`00609d20 fffff800`01ae1bbb nt!Phase1Initialization+0x9 fffff980`00609d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00609d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c74700 Cid 0004.000c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (DelayExecution) KernelMode Non-Alertable fffffa8000c747b8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 190 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.109 Win32 Start Address nt!InbvRotateGuiBootDisplay (0xfffff800018fac90) Stack Init fffff9800080edb0 Current fffff9800080eac0 Base fffff9800080f000 Limit fffff98000809000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0080eb00 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0080ec40 fffff800`0185b4a9 nt!KiSwapThread+0x125 fffff980`0080eca0 fffff800`018facab nt!KeDelayExecutionThread+0x339 fffff980`0080ed20 fffff800`01ae1bbb nt!InbvRotateGuiBootDisplay+0x1b fffff980`0080ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0080ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c75bb0 Cid 0004.0010 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff8000197b0a0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!PopIrpWorkerControl (0xfffff800019002a0) Stack Init fffff98000807db0 Current fffff98000807ab0 Base fffff98000808000 Limit fffff98000802000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 2 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00807af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00807c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00807c90 fffff800`019002c2 nt!KeWaitForSingleObject+0x5f5 fffff980`00807d10 fffff800`01ae1bbb nt!PopIrpWorkerControl+0x22 fffff980`00807d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00807d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c76040 Cid 0004.0014 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff8000197b740 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 909 Ticks: 234 (0:00:00:03.650) Context Switch Count 3 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!PopIrpWorker (0xfffff8000180d910) Stack Init fffff98000ab2db0 Current fffff98000ab2a40 Base fffff98000ab3000 Limit fffff98000aad000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 2 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00ab2a80 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00ab2bc0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00ab2c20 fffff800`0180da74 nt!KeWaitForSingleObject+0x5f5 fffff980`00ab2ca0 fffff800`01ae1bbb nt!PopIrpWorker+0x164 fffff980`00ab2d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00ab2d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c76bb0 Cid 0004.0018 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff8000197b740 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 910 Ticks: 233 (0:00:00:03.634) Context Switch Count 4 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!PopIrpWorker (0xfffff8000180d910) Stack Init fffff98000aabdb0 Current fffff98000aaba40 Base fffff98000aac000 Limit fffff98000aa6000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 2 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00aaba80 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00aabbc0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00aabc20 fffff800`0180da74 nt!KeWaitForSingleObject+0x5f5 fffff980`00aabca0 fffff800`01ae1bbb nt!PopIrpWorker+0x164 fffff980`00aabd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00aabd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c76720 Cid 0004.001c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 660 Ticks: 483 (0:00:00:07.534) Context Switch Count 41 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000a15db0 Current fffff98000a15a70 Base fffff98000a16000 Limit fffff98000a10000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Kernel stack not resident. Child-SP RetAddr Call Site fffff980`00a15ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00a15bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00a15c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00a15ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00a15d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00a15d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c7bbb0 Cid 0004.0020 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 660 Ticks: 483 (0:00:00:07.534) Context Switch Count 485 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.327 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000a0edb0 Current fffff98000a0ea70 Base fffff98000a0f000 Limit fffff98000a09000 Call 0 Priority 14 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00a0eab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00a0ebf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00a0ec50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00a0ece0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00a0ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00a0ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c85bb0 Cid 0004.0024 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000a07db0 Current fffff98000a07a70 Base fffff98000a08000 Limit fffff98000a02000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 2 IoPriority 2 PagePriority 5 Kernel stack not resident. Child-SP RetAddr Call Site fffff980`00a07ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00a07bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00a07c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00a07ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00a07d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00a07d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c85720 Cid 0004.0028 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1111 Ticks: 32 (0:00:00:00.499) Context Switch Count 35 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.140 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cffdb0 Current fffff98000cffa70 Base fffff98000d00000 Limit fffff98000cfa000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cffab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cffbf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cffc50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cffce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cffd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cffd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c85290 Cid 0004.002c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cf8db0 Current fffff98000cf8a70 Base fffff98000cf9000 Limit fffff98000cf3000 Call 0 Priority 15 BasePriority 13 PriorityDecrement 2 IoPriority 2 PagePriority 5 Kernel stack not resident. Child-SP RetAddr Call Site fffff980`00cf8ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cf8bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cf8c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cf8ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cf8d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cf8d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c7a040 Cid 0004.0030 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800019689d8 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1137 Ticks: 6 (0:00:00:00.093) Context Switch Count 980 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:02.979 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cf1db0 Current fffff98000cf1a70 Base fffff98000cf2000 Limit fffff98000cec000 Call 0 Priority 15 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cf1ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cf1bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cf1c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cf1ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cf1d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cf1d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c7abb0 Cid 0004.0034 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98004847208 NotificationEvent IRP List: fffffa8001d23470: (0006,03a0) Flags: 00000884 Mdl: 00000000 fffffa800219b510: (0006,03a0) Flags: 00000884 Mdl: 00000000 Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 78 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98004847db0 Current fffff98004846cd0 Base fffff98004848000 Limit fffff98004842000 Call 0 Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`04846d10 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`04846e50 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`04846eb0 fffff980`008482b3 nt!KeWaitForSingleObject+0x5f5 fffff980`04846f30 fffff980`0084560c Ntfs!NtfsNonCachedIo+0x263 fffff980`04847100 fffff980`00847e04 Ntfs!NtfsCommonRead+0x61c fffff980`04847270 fffff980`0043f21a Ntfs!NtfsFsdRead+0x294 fffff980`04847480 fffff980`0043f691 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x20a fffff980`048474f0 fffff800`01877976 fltmgr!FltpDispatch+0xd1 fffff980`04847550 fffff800`01863247 nt!IoPageRead+0x116 fffff980`04847590 fffff800`0185484a nt!MiDispatchFault+0xe50 fffff980`048476e0 fffff800`0184c6d9 nt!MmAccessFault+0x14ae fffff980`048477e0 fffff800`01ac7d67 nt!KiPageFault+0x119 (TrapFrame @ fffff980`048477e0) fffff980`04847970 fffff980`008d52dc nt!CcMapData+0x107 fffff980`04847a20 fffff980`008df943 Ntfs!FindFirstIndexEntry+0x1cc fffff980`04847ac0 fffff980`008f6d1e Ntfs!NtfsFindIndexEntry+0x63 fffff980`04847b40 fffff980`008c9aee Ntfs!NtfsLookupEntry+0xfe fffff980`04847ba0 fffff980`00844edd Ntfs!NtfsCommonCreate+0xf39 fffff980`04847d30 fffff800`01838297 Ntfs!NtfsCommonCreateCallout+0x1d fffff980`04847d60 fffff800`01838255 nt!KxSwitchKernelStackCallout+0x27 (TrapFrame @ fffff980`04847c20) fffff980`00ce9400 fffff800`01837a6e nt!KiSwitchKernelStackContinue fffff980`00ce9420 fffff980`0084342a nt!KeExpandKernelStackAndCalloutEx+0x12e fffff980`00ce94b0 fffff980`008d11e2 Ntfs!NtfsCommonCreateOnNewStack+0x3a fffff980`00ce9510 fffff980`0045d06d Ntfs!NtfsFsdCreate+0x1b2 fffff980`00ce96b0 fffff800`01a90a63 fltmgr! ?? ::NNGAKEGL::`string'+0xaa5 fffff980`00ce9760 fffff800`01a8f411 nt!IopParseDevice+0x883 fffff980`00ce98e0 fffff800`01a9bb01 nt!ObpLookupObjectName+0xa9f fffff980`00ce99f0 fffff800`01abd0d1 nt!ObOpenObjectByName+0x421 fffff980`00ce9ac0 fffff800`01a6031a nt!IopCreateFile+0x93b fffff980`00ce9b60 fffff980`00467d71 nt!IoCreateFileEx+0xfa fffff980`00ce9c00 fffff980`0046a706 fltmgr!FltpNormalizeNameFromCache+0x191 fffff980`00ce9d20 fffff980`0046eb5a fltmgr!FltpExpandShortNames+0x386 fffff980`00ce9d90 fffff980`0046ecde fltmgr!FltpGetNormalizedFileNameWorker+0xbb fffff980`00ce9dc0 fffff980`0046ee2a fltmgr!FltpGetNormalizedFileName+0x1e fffff980`00ce9df0 fffff980`00442ad6 fltmgr!FltpCreateFileNameInformation+0xba fffff980`00ce9e20 fffff980`0044d884 fltmgr!FltpGetFileNameInformation+0x386 fffff980`00ce9e90 fffff980`004332e3 fltmgr!FltGetFileNameInformation+0x174 fffff980`00ce9f20 fffff980`00431c1a fileinfo!FIStreamGetInfo+0x11f fffff980`00ce9fa0 fffff980`00443810 fileinfo!FIPostCreateCallback+0x17a fffff980`00cea020 fffff980`0043f376 fltmgr! ?? ::FNODOBFM::`string'+0xbbe fffff980`00cea0f0 fffff980`0045b28d fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x366 THREAD fffffa8000c7a720 Cid 0004.0038 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800019689d8 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1134 Ticks: 9 (0:00:00:00.140) Context Switch Count 258 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.124 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000ce3db0 Current fffff98000ce3a70 Base fffff98000ce4000 Limit fffff98000cde000 Call 0 Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00ce3ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00ce3bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00ce3c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00ce3ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00ce3d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00ce3d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c79040 Cid 0004.003c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800019689d8 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 282 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.436 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cdcdb0 Current fffff98000cdca70 Base fffff98000cdd000 Limit fffff98000cd7000 Call 0 Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cdcab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cdcbf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cdcc50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cdcce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cdcd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cdcd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c79bb0 Cid 0004.0040 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800019689d8 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 102 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cd5db0 Current fffff98000cd5a70 Base fffff98000cd6000 Limit fffff98000cd0000 Call 0 Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cd5ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cd5bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cd5c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cd5ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cd5d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cd5d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c79720 Cid 0004.0044 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrResource) KernelMode Non-Alertable fffffa8002d6c4f0 Semaphore Limit 0x7fffffff fffffa8000c797d8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 305 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.015 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000ccedb0 Current fffff98000cce3f0 Base fffff98000ccf000 Limit fffff98000cc9000 Call 0 Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cce430 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cce570 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00cce5d0 fffff800`01832bb3 nt!KeWaitForSingleObject+0x5f5 fffff980`00cce650 fffff800`0189010e nt!ExpWaitForResource+0x43 fffff980`00cce6b0 fffff980`0084254b nt!ExAcquireResourceSharedLite+0x1be fffff980`00cce700 fffff980`008c0ab4 Ntfs!NtfsAcquireSharedFcb+0x5b fffff980`00cce750 fffff980`008df223 Ntfs!NtfsCommonQueryInformation+0x164 fffff980`00cce810 fffff980`008c14c4 Ntfs!NtfsFsdDispatchSwitch+0x103 fffff980`00cce890 fffff980`0045d26c Ntfs!NtfsFsdDispatchWait+0x14 fffff980`00ccea70 fffff980`0045dae4 fltmgr!FltpQueryInformationFile+0xfc fffff980`00cceae0 fffff980`004428fb fltmgr!SetStreamListStandardInformationFlags+0x84 fffff980`00cceb50 fffff980`0045c43e fltmgr!FltpGetFileNameInformation+0x1ab fffff980`00ccebc0 fffff980`004338ba fltmgr!FltGetFileNameInformationUnsafe+0x7e fffff980`00ccec30 fffff980`00463ed3 fileinfo!FIStreamQueryWorker+0x9e fffff980`00cceca0 fffff800`01859ca3 fltmgr!FltpProcessGenericWorkItem+0x43 fffff980`00ccece0 fffff800`01ae1bbb nt!ExpWorkerThread+0x12a fffff980`00cced50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cced80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c78040 Cid 0004.0048 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff800019689d8 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 9 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cc7db0 Current fffff98000cc7a70 Base fffff98000cc8000 Limit fffff98000cc2000 Call 0 Priority 15 BasePriority 12 PriorityDecrement 3 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cc7ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cc7bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cc7c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cc7ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cc7d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cc7d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c78bb0 Cid 0004.004c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff80001968a30 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1137 Ticks: 6 (0:00:00:00.093) Context Switch Count 18 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98000cc0db0 Current fffff98000cc0a70 Base fffff98000cc1000 Limit fffff98000cbb000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cc0ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cc0bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00cc0c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`00cc0ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`00cc0d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cc0d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c78720 Cid 0004.0050 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98000cb9d00 NotificationTimer fffff80001968940 SynchronizationEvent fffff80001968920 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1116 Ticks: 27 (0:00:00:00.421) Context Switch Count 30 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThreadBalanceManager (0xfffff80001a939f0) Stack Init fffff98000cb9db0 Current fffff98000cb9a50 Base fffff98000cba000 Limit fffff98000cb4000 Call 0 Priority 15 BasePriority 14 PriorityDecrement 1 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cb9a90 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cb9bd0 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`00cb9c30 fffff800`01a93a78 nt!KeWaitForMultipleObjects+0x703 fffff980`00cb9ca0 fffff800`01ae1bbb nt!ExpWorkerThreadBalanceManager+0x85 fffff980`00cb9d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cb9d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c89040 Cid 0004.0054 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Suspended) KernelMode Non-Alertable fffff8000194dd00 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1051 Ticks: 92 (0:00:00:01.435) Context Switch Count 4 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!KiExecuteDpc (0xfffff8000182d3e0) Stack Init fffff98000cb2db0 Current fffff98000cb2a80 Base fffff98000cb3000 Limit fffff98000cad000 Call 0 Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cb2ac0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cb2c00 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00cb2c60 fffff800`0182d578 nt!KeWaitForSingleObject+0x5f5 fffff980`00cb2ce0 fffff800`01ae1bbb nt!KiExecuteDpc+0x198 fffff980`00cb2d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cb2d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c89bb0 Cid 0004.0058 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Suspended) KernelMode Non-Alertable fffff98000a9c500 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1054 Ticks: 89 (0:00:00:01.388) Context Switch Count 3 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!KiExecuteDpc (0xfffff8000182d3e0) Stack Init fffff98000cabdb0 Current fffff98000caba80 Base fffff98000cac000 Limit fffff98000ca6000 Call 0 Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00cabac0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00cabc00 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00cabc60 fffff800`0182d578 nt!KeWaitForSingleObject+0x5f5 fffff980`00cabce0 fffff800`01ae1bbb nt!KiExecuteDpc+0x198 fffff980`00cabd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cabd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8b040 Cid 0004.005c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrVirtualMemory) UserMode Non-Alertable fffff8000199b920 Semaphore Limit 0x7fffffff fffff8000199b9e0 NotificationEvent fffff8000199bb00 NotificationEvent fffff800019889a0 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!MiDereferenceSegmentThread (0xfffff800018274f0) Stack Init fffff98000ca4db0 Current fffff98000ca4a90 Base fffff98000ca5000 Limit fffff98000c9f000 Call 0 Priority 18 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Kernel stack not resident. Child-SP RetAddr Call Site fffff980`00ca4ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00ca4c10 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`00ca4c70 fffff800`01827577 nt!KeWaitForMultipleObjects+0x703 fffff980`00ca4ce0 fffff800`01ae1bbb nt!MiDereferenceSegmentThread+0x87 fffff980`00ca4d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00ca4d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8bbb0 Cid 0004.0060 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrFreePage) KernelMode Non-Alertable fffff800019865a0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!MiModifiedPageWriter (0xfffff80001911860) Stack Init fffff98000c9ddb0 Current fffff98000c9da90 Base fffff98000c9e000 Limit fffff98000c98000 Call 0 Priority 17 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c9dad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c9dc10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c9dc70 fffff800`019118b9 nt!KeWaitForSingleObject+0x5f5 fffff980`00c9dcf0 fffff800`01ae1bbb nt!MiModifiedPageWriter+0x59 fffff980`00c9dd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c9dd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8c040 Cid 0004.0064 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrFreePage) KernelMode Non-Alertable fffff8000199b0c0 SynchronizationEvent fffff8000199b0d8 SynchronizationEvent fffff8000199b0f0 SynchronizationEvent fffff8000199b108 SynchronizationEvent fffff8000199b120 SynchronizationEvent fffff8000199b138 SynchronizationEvent fffff8000199b150 SynchronizationEvent fffff8000199b168 SynchronizationEvent fffff8000199b180 SynchronizationEvent fffff8000199b198 SynchronizationEvent fffff8000199b1b0 SynchronizationEvent fffff8000199b1c8 SynchronizationEvent fffff8000199b1e0 SynchronizationEvent fffff8000199b1f8 SynchronizationEvent fffff8000199b210 SynchronizationEvent fffff8000199b228 SynchronizationEvent fffff8000199b240 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 71 Ticks: 1072 (0:00:00:16.723) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!MiMappedPageWriter (0xfffff8000181f280) Stack Init fffff98000c96db0 Current fffff98000c96a20 Base fffff98000c97000 Limit fffff98000c91000 Call 0 Priority 17 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c96a60 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c96ba0 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`00c96c00 fffff800`0181f32d nt!KeWaitForMultipleObjects+0x703 fffff980`00c96c70 fffff800`01ae1bbb nt!MiMappedPageWriter+0xad fffff980`00c96d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c96d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8cbb0 Cid 0004.0068 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98000c8fca0 SynchronizationTimer fffff8000199ae20 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1116 Ticks: 27 (0:00:00:00.421) Context Switch Count 17 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!KeBalanceSetManager (0xfffff80001867560) Stack Init fffff98000c8fdb0 Current fffff98000c8f9c0 Base fffff98000c90000 Limit fffff98000c8a000 Call 0 Priority 16 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c8fa00 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c8fb40 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`00c8fba0 fffff800`01867664 nt!KeWaitForMultipleObjects+0x703 fffff980`00c8fc10 fffff800`01ae1bbb nt!KeBalanceSetManager+0x101 fffff980`00c8fd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c8fd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8c720 Cid 0004.006c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff800019c81c0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1133 Ticks: 10 (0:00:00:00.156) Context Switch Count 4 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!KeSwapProcessOrStack (0xfffff800018721b0) Stack Init fffff98000c88db0 Current fffff98000c88ab0 Base fffff98000c89000 Limit fffff98000c83000 Call 0 Priority 23 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c88af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c88c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c88c90 fffff800`018721f4 nt!KeWaitForSingleObject+0x5f5 fffff980`00c88d10 fffff800`01ae1bbb nt!KeSwapProcessOrStack+0x44 fffff980`00c88d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c88d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c71040 Cid 0004.0070 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrFreePage) KernelMode Non-Alertable fffff800019d37e0 SynchronizationEvent fffff800019d37c0 SynchronizationEvent fffff800019d37a0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1105 Ticks: 38 (0:00:00:00.592) Context Switch Count 12 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!CcQueueLazyWriteScanThread (0xfffff800018a30c0) Stack Init fffff98000c61db0 Current fffff98000c61a90 Base fffff98000c62000 Limit fffff98000c5c000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c61ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c61c10 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`00c61c70 fffff800`018a3133 nt!KeWaitForMultipleObjects+0x703 fffff980`00c61ce0 fffff800`01ae1bbb nt!CcQueueLazyWriteScanThread+0x73 fffff980`00c61d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c61d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8d040 Cid 0004.0074 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff800019d1c40 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 85 Ticks: 1058 (0:00:00:16.504) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!FsRtlWorkerThread (0xfffff800018e1f20) Stack Init fffff98000c5adb0 Current fffff98000c5aaa0 Base fffff98000c5b000 Limit fffff98000c55000 Call 0 Priority 16 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c5aae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c5ac20 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00c5ac80 fffff800`018e1f6d nt!KeRemoveQueueEx+0x848 fffff980`00c5ad10 fffff800`01ae1bbb nt!FsRtlWorkerThread+0x4d fffff980`00c5ad50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c5ad80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c8dbb0 Cid 0004.0078 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff800019d1c80 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 74 Ticks: 1069 (0:00:00:16.676) Context Switch Count 2 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!FsRtlWorkerThread (0xfffff800018e1f20) Stack Init fffff98000c53db0 Current fffff98000c53aa0 Base fffff98000c54000 Limit fffff98000c4e000 Call 0 Priority 17 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c53ae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c53c20 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`00c53c80 fffff800`018e1f6d nt!KeRemoveQueueEx+0x848 fffff980`00c53d10 fffff800`01ae1bbb nt!FsRtlWorkerThread+0x4d fffff980`00c53d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c53d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c4ebb0 Cid 0004.0080 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8000c4e1f8 SynchronizationEvent fffffa8000c4ec68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1083 Ticks: 60 (0:00:00:00.936) Context Switch Count 18 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c45db0 Current fffff98000c45a90 Base fffff98000c46000 Limit fffff98000c40000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c45ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c45c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c45c70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c45cf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c45d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c45d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c4f040 Cid 0004.0084 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8000c4e978 SynchronizationEvent fffffa8000c4f0f8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1125 Ticks: 18 (0:00:00:00.280) Context Switch Count 17 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c3edb0 Current fffff98000c3ea90 Base fffff98000c3f000 Limit fffff98000c39000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c3ead0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c3ec10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c3ec70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c3ecf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c3ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c3ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80010ed040 Cid 0004.0088 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80010ac378 SynchronizationEvent fffffa80010ed0f8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1134 Ticks: 9 (0:00:00:00.140) Context Switch Count 18 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c37db0 Current fffff98000c37a90 Base fffff98000c38000 Limit fffff98000c32000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c37ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c37c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c37c70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c37cf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c37d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c37d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80010ed7f0 Cid 0004.008c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80010ede38 SynchronizationEvent fffffa80010ed8a8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1125 Ticks: 18 (0:00:00:00.280) Context Switch Count 17 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c30db0 Current fffff98000c30a90 Base fffff98000c31000 Limit fffff98000c2b000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c30ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c30c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c30c70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c30cf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c30d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c30d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001132bb0 Cid 0004.0090 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80011321f8 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 85 Ticks: 1058 (0:00:00:16.504) Context Switch Count 2 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c29db0 Current fffff98000c29a90 Base fffff98000c2a000 Limit fffff98000c24000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c29ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c29c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c29c70 fffff800`01a8fc44 nt!KeWaitForSingleObject+0x5f5 fffff980`00c29cf0 fffff800`01ae1bbb nt!EtwpLogger+0x84 fffff980`00c29d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c29d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001177040 Cid 0004.0094 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80011329b8 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 85 Ticks: 1058 (0:00:00:16.504) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c22db0 Current fffff98000c22a90 Base fffff98000c23000 Limit fffff98000c1d000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c22ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c22c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c22c70 fffff800`01a8fc44 nt!KeWaitForSingleObject+0x5f5 fffff980`00c22cf0 fffff800`01ae1bbb nt!EtwpLogger+0x84 fffff980`00c22d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c22d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80011777f0 Cid 0004.0098 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001177e38 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 85 Ticks: 1058 (0:00:00:16.504) Context Switch Count 2 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c1bdb0 Current fffff98000c1ba90 Base fffff98000c1c000 Limit fffff98000c16000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c1bad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c1bc10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c1bc70 fffff800`01a8fc44 nt!KeWaitForSingleObject+0x5f5 fffff980`00c1bcf0 fffff800`01ae1bbb nt!EtwpLogger+0x84 fffff980`00c1bd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c1bd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80011b8b20 Cid 0004.009c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80011b81f8 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 889 Ticks: 254 (0:00:00:03.962) Context Switch Count 2 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c14db0 Current fffff98000c14a90 Base fffff98000c15000 Limit fffff98000c0f000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c14ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c14c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c14c70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c14cf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c14d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c14d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80019b9b20 Cid 0004.00a0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa80011b8638 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1067 Ticks: 76 (0:00:00:01.185) Context Switch Count 9 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c0ddb0 Current fffff98000c0da90 Base fffff98000c0e000 Limit fffff98000c08000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c0dad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c0dc10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c0dc70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c0dcf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c0dd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c0dd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80019ca730 Cid 0004.00a4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (DelayExecution) KernelMode Non-Alertable fffffa80019ca7e8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 86 Ticks: 1057 (0:00:00:16.489) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!WdipSemCheckTimeout (0xfffff80001aa5200) Stack Init fffff98000c06db0 Current fffff98000c06ac0 Base fffff98000c07000 Limit fffff98000c01000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c06b00 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c06c40 fffff800`0185b4a9 nt!KiSwapThread+0x125 fffff980`00c06ca0 fffff800`01aa5328 nt!KeDelayExecutionThread+0x339 fffff980`00c06d20 fffff800`01ae1bbb nt!WdipSemCheckTimeout+0x128 fffff980`00c06d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c06d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa80019fe040 Cid 0004.00a8 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff9800024ab00 NotificationEvent fffff9800024aae0 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 940 Ticks: 203 (0:00:00:03.166) Context Switch Count 432 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.624 Win32 Start Address acpi!ACPIWorkerThread (0xfffff98000230964) Stack Init fffff980012f7db0 Current fffff980012f7aa0 Base fffff980012f8000 Limit fffff980012f2000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`012f7ae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`012f7c20 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`012f7c80 fffff980`002309d8 nt!KeWaitForMultipleObjects+0x703 fffff980`012f7cf0 fffff800`01ae1bbb acpi!ACPIWorkerThread+0x74 fffff980`012f7d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`012f7d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8000c4dab0 Cid 0004.00ac Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8000c4bb78 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 746 Ticks: 397 (0:00:00:06.193) Context Switch Count 2 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!EtwpLogger (0xfffff80001a8fbc0) Stack Init fffff98000c4cdb0 Current fffff98000c4ca90 Base fffff98000c4d000 Limit fffff98000c47000 Call 0 Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`00c4cad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`00c4cc10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`00c4cc70 fffff800`01a8fc9d nt!KeWaitForSingleObject+0x5f5 fffff980`00c4ccf0 fffff800`01ae1bbb nt!EtwpLogger+0xdd fffff980`00c4cd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00c4cd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002bfe3a0 Cid 0004.00b0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001b01ac8 SynchronizationEvent fffffa8001b01ab0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 130 Ticks: 1013 (0:00:00:15.802) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address acpi!PciRootBusBiosMethodDispatcherOnResume (0xfffff98000229990) Stack Init fffff980012c6db0 Current fffff980012c6aa0 Base fffff980012c7000 Limit fffff980012c1000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`012c6ae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`012c6c20 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`012c6c80 fffff980`002299e1 nt!KeWaitForMultipleObjects+0x703 fffff980`012c6cf0 fffff800`01ae1bbb acpi!PciRootBusBiosMethodDispatcherOnResume+0x51 fffff980`012c6d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`012c6d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002d30040 Cid 0004.00b4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001b1e058 SynchronizationEvent fffffa8001b1e070 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 131 Ticks: 1012 (0:00:00:15.787) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address pci!ExpressRootComplexPmeEventDispatcher (0xfffff980005db864) Stack Init fffff980012bfdb0 Current fffff980012bfa80 Base fffff980012c0000 Limit fffff980012ba000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`012bfac0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`012bfc00 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`012bfc60 fffff980`005db8bb nt!KeWaitForMultipleObjects+0x703 fffff980`012bfcd0 fffff800`01ae1bbb pci!ExpressRootComplexPmeEventDispatcher+0x57 fffff980`012bfd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`012bfd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001bc9840 Cid 0004.00b8 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Alertable fffff9800058aab8 NotificationEvent fffff9800058aad0 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 239 Ticks: 904 (0:00:00:14.102) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 *** ERROR: Symbol file could not be found. Defaulted to export symbols for vmci.sys - Win32 Start Address vmci (0xfffff9800057a444) Stack Init fffff980012b8db0 Current fffff980012b8aa0 Base fffff980012b9000 Limit fffff980012b3000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`012b8ae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`012b8c20 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`012b8c80 fffff980`0057a4d7 nt!KeWaitForMultipleObjects+0x703 fffff980`012b8cf0 fffff800`01ae1bbb vmci+0x84d7 fffff980`012b8d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`012b8d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001bcebb0 Cid 0004.00bc Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Alertable fffffa8001bcb050 NotificationEvent fffffa8001bcb068 SynchronizationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 239 Ticks: 904 (0:00:00:14.102) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address vmci (0xfffff9800057ec50) Stack Init fffff980012b1db0 Current fffff980012b1a90 Base fffff980012b2000 Limit fffff980012ac000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`012b1ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`012b1c10 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`012b1c70 fffff980`0057ed74 nt!KeWaitForMultipleObjects+0x703 fffff980`012b1ce0 fffff800`01ae1bbb vmci+0xcd74 fffff980`012b1d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`012b1d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001bf7bb0 Cid 0004.00c0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980006a3f00 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1122 Ticks: 21 (0:00:00:00.327) Context Switch Count 10 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address ndis!ndisWorkerThread (0xfffff980007c8eb0) Stack Init fffff9800127edb0 Current fffff9800127ea50 Base fffff9800127f000 Limit fffff98001279000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0127ea90 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0127ebd0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0127ec30 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`0127ecc0 fffff980`007c8ef5 nt!KeRemoveQueue+0x21 fffff980`0127ed00 fffff800`01ae1bbb ndis!ndisWorkerThread+0x45 fffff980`0127ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0127ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c0b450 Cid 0004.00c4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff980006a4920 NotificationEvent fffffa8001c0b508 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 351 Ticks: 792 (0:00:00:12.355) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address ndis!ndisCmWaitThread (0xfffff9800065b590) Stack Init fffff98001277db0 Current fffff98001277ab0 Base fffff98001278000 Limit fffff98001272000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01277af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01277c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01277c90 fffff980`0065b5bc nt!KeWaitForSingleObject+0x5f5 fffff980`01277d10 fffff800`01ae1bbb ndis!ndisCmWaitThread+0x2c fffff980`01277d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01277d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002464bb0 Cid 0004.00c8 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 1 Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1137 Ticks: 6 (0:00:00:00.093) Context Switch Count 2256 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:02.808 Win32 Start Address ecache!EcCacheIoWorker (0xfffff98000b25328) Stack Init fffff98001270db0 Current fffff98001270a00 Base fffff98001271000 Limit fffff9800126b000 Call 0 Priority 26 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01270998 fffff800`018366eb nt!RtlpBreakWithStatusInstruction fffff980`012709a0 fffff800`01850baf nt! ?? ::FNODOBFM::`string'+0x42b6 fffff980`012709f0 fffff800`01ce9af9 nt!KiSecondaryClockInterrupt+0x11f (TrapFrame @ fffff980`012709f0) fffff980`01270b80 fffff800`0185aea7 hal!HalpRequestIpiSpecifyVector+0xa9 fffff980`01270bb0 fffff800`0185a8c4 nt!KiDeferredReadyThread+0x467 fffff980`01270bf0 fffff800`0185954c nt!KiExitDispatcher+0x74 fffff980`01270c20 fffff980`00b25cc7 nt!KeSetEvent+0x2aa fffff980`01270c60 fffff800`01ae1bbb ecache!EcCacheIoWorker+0x99f fffff980`01270d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01270d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c0d450 Cid 0004.00cc Teb: 0000000000000000 Win32Thread: 0000000000000000 STANDBY Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 2821 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.062 Win32 Start Address ecache!EcCacheIoWatchdog (0xfffff98000b24b20) Stack Init fffff98001269db0 Current fffff98001269a50 Base fffff9800126a000 Limit fffff98001264000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01269a90 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01269bd0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01269c30 fffff980`00b24e8d nt!KeWaitForSingleObject+0x5f5 fffff980`01269cb0 fffff800`01ae1bbb ecache!EcCacheIoWatchdog+0x36d fffff980`01269d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01269d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c373a0 Cid 0004.00d0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98000b2f290 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 1928 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.078 Win32 Start Address ecache!EcCacheBootWorker (0xfffff98000b2a144) Stack Init fffff9800124ddb0 Current fffff9800124d9b0 Base fffff9800124e000 Limit fffff98001248000 Call 0 Priority 25 BasePriority 25 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0124d9f0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0124db30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0124db90 fffff980`00b290bd nt!KeWaitForSingleObject+0x5f5 fffff980`0124dc10 fffff980`00b2a356 ecache!EcCacheBootPopulateWorker+0x261 fffff980`0124dca0 fffff800`01ae1bbb ecache!EcCacheBootWorker+0x212 fffff980`0124dd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0124dd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c3f450 Cid 0004.00d4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001c29a60 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 357 Ticks: 786 (0:00:00:12.261) Context Switch Count 2 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address volsnap!VspWorkerThread (0xfffff98000b78158) Stack Init fffff98001246db0 Current fffff98001246ab0 Base fffff98001247000 Limit fffff98001241000 Call 0 Priority 20 BasePriority 8 PriorityDecrement 0 IoPriority 3 PagePriority 5 Child-SP RetAddr Call Site fffff980`01246af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01246c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01246c90 fffff980`00b781ce nt!KeWaitForSingleObject+0x5f5 fffff980`01246d10 fffff800`01ae1bbb volsnap!VspWorkerThread+0x76 fffff980`01246d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01246d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c414e0 Cid 0004.00d8 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001c29a80 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 357 Ticks: 786 (0:00:00:12.261) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address volsnap!VspWorkerThread (0xfffff98000b78158) Stack Init fffff9800123fdb0 Current fffff9800123fab0 Base fffff98001240000 Limit fffff9800123a000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0123faf0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0123fc30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0123fc90 fffff980`00b781ce nt!KeWaitForSingleObject+0x5f5 fffff980`0123fd10 fffff800`01ae1bbb volsnap!VspWorkerThread+0x76 fffff980`0123fd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0123fd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c43710 Cid 0004.00dc Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001c29aa0 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 357 Ticks: 786 (0:00:00:12.261) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address volsnap!VspWorkerThread (0xfffff98000b78158) Stack Init fffff98001238db0 Current fffff98001238ab0 Base fffff98001239000 Limit fffff98001233000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01238af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01238c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01238c90 fffff980`00b781ce nt!KeWaitForSingleObject+0x5f5 fffff980`01238d10 fffff800`01ae1bbb volsnap!VspWorkerThread+0x76 fffff980`01238d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01238d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c43280 Cid 0004.00e0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001c29ac0 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 420 Ticks: 723 (0:00:00:11.278) Context Switch Count 2 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address volsnap!VspWorkerThread (0xfffff98000b78158) Stack Init fffff98001231db0 Current fffff98001231ab0 Base fffff98001232000 Limit fffff9800122c000 Call 0 Priority 20 BasePriority 8 PriorityDecrement 0 IoPriority 3 PagePriority 5 Child-SP RetAddr Call Site fffff980`01231af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01231c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01231c90 fffff980`00b78230 nt!KeWaitForSingleObject+0x5f5 fffff980`01231d10 fffff800`01ae1bbb volsnap!VspWorkerThread+0xd8 fffff980`01231d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01231d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c45bb0 Cid 0004.00e4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001c29ae0 Semaphore Limit 0x7fffffff Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 357 Ticks: 786 (0:00:00:12.261) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address volsnap!VspWorkerThread (0xfffff98000b78158) Stack Init fffff9800122adb0 Current fffff9800122aab0 Base fffff9800122b000 Limit fffff98001225000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0122aaf0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0122ac30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0122ac90 fffff980`00b781ce nt!KeWaitForSingleObject+0x5f5 fffff980`0122ad10 fffff800`01ae1bbb volsnap!VspWorkerThread+0x76 fffff980`0122ad50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0122ad80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c73bb0 Cid 0004.00e8 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98000890790 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1138 Ticks: 5 (0:00:00:00.078) Context Switch Count 17 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address Ntfs!TxfPrivateThreadWorkerRoutine (0xfffff98000849700) Stack Init fffff98001211db0 Current fffff98001211ab0 Base fffff98001212000 Limit fffff9800120c000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01211af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01211c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01211c90 fffff980`0084973f nt!KeWaitForSingleObject+0x5f5 fffff980`01211d10 fffff800`01ae1bbb Ntfs!TxfPrivateThreadWorkerRoutine+0x3f fffff980`01211d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01211d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c934a0 Cid 0004.00ec Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject fffffa8001c93558 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 660 Ticks: 483 (0:00:00:07.534) Context Switch Count 3 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98001429db0 Current fffff98001429a70 Base fffff9800142a000 Limit fffff98001424000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01429ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01429bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`01429c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`01429ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`01429d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01429d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c91bb0 Cid 0004.00f0 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject fffffa8001c91c68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 660 Ticks: 483 (0:00:00:07.534) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98001422db0 Current fffff98001422a70 Base fffff98001423000 Limit fffff9800141d000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Kernel stack not resident. Child-SP RetAddr Call Site fffff980`01422ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01422bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`01422c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`01422ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`01422d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01422d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c91720 Cid 0004.00f4 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject fffffa8001c917d8 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 660 Ticks: 483 (0:00:00:07.534) Context Switch Count 3 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff9800141bdb0 Current fffff9800141ba70 Base fffff9800141c000 Limit fffff98001416000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0141bab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0141bbf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0141bc50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`0141bce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`0141bd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0141bd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c91290 Cid 0004.00f8 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject fffffa8001c91348 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1111 Ticks: 32 (0:00:00:00.499) Context Switch Count 44 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.015 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff98001414db0 Current fffff98001414a70 Base fffff98001415000 Limit fffff9800140f000 Call 0 Priority 13 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01414ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01414bf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`01414c50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`01414ce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`01414d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01414d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001c8bbb0 Cid 0004.00fc Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffff80001968980 QueueObject fffffa8001c8bc68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 77 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!ExpWorkerThread (0xfffff80001859b80) Stack Init fffff9800140ddb0 Current fffff9800140da70 Base fffff9800140e000 Limit fffff98001408000 Call 0 Priority 14 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0140dab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0140dbf0 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0140dc50 fffff800`01859c7d nt!KeRemoveQueueEx+0x848 fffff980`0140dce0 fffff800`01ae1bbb nt!ExpWorkerThread+0x104 fffff980`0140dd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0140dd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001ccb980 Cid 0004.0104 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98003acf628 SynchronizationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 787 Ticks: 356 (0:00:00:05.553) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address dxgkrnl!DpiPdoPollingThread (0xfffff98003b2092c) Stack Init fffff98001430db0 Current fffff98001430a80 Base fffff98001431000 Limit fffff9800142b000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01430ac0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01430c00 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01430c60 fffff980`03b2097d nt!KeWaitForSingleObject+0x5f5 fffff980`01430ce0 fffff800`01ae1bbb dxgkrnl!DpiPdoPollingThread+0x51 fffff980`01430d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01430d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001cb9720 Cid 0004.0108 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98003a9f420 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 787 Ticks: 356 (0:00:00:05.553) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address watchdog!SMgrGdiCalloutThread (0xfffff98003a9b588) Stack Init fffff98001218db0 Current fffff98001218a70 Base fffff98001219000 Limit fffff98001213000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01218ab0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01218bf0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01218c50 fffff980`03a9b5e5 nt!KeWaitForSingleObject+0x5f5 fffff980`01218cd0 fffff800`01ae1bbb watchdog!SMgrGdiCalloutThread+0x5d fffff980`01218d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01218d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001cc3bb0 Cid 0004.010c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001d27cd8 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 787 Ticks: 356 (0:00:00:05.553) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address dxgkrnl!DpiPowerArbiterThread (0xfffff98003b21380) Stack Init fffff98001437db0 Current fffff98001437a90 Base fffff98001438000 Limit fffff98001432000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`01437ad0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`01437c10 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`01437c70 fffff980`03b213cb nt!KeWaitForSingleObject+0x5f5 fffff980`01437cf0 fffff800`01ae1bbb dxgkrnl!DpiPowerArbiterThread+0x4b fffff980`01437d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`01437d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001ca3bb0 Cid 0004.0118 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001cbbf40 NotificationEvent fffffa8001ca3c68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 894 Ticks: 249 (0:00:00:03.884) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address parport!P5FdoThread (0xfffff98003be967c) Stack Init fffff9800121fdb0 Current fffff9800121fa60 Base fffff98001220000 Limit fffff9800121a000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0121faa0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0121fbe0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0121fc40 fffff980`03be96de nt!KeWaitForSingleObject+0x5f5 fffff980`0121fcc0 fffff800`01ae1bbb parport!P5FdoThread+0x62 fffff980`0121fd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0121fd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001d63bb0 Cid 0004.011c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff9800120a9f0 NotificationEvent IRP List: fffffa8001c79260: (0006,03a0) Flags: 00060070 Mdl: 00000000 Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1129 Ticks: 14 (0:00:00:00.218) Context Switch Count 17 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address serenum!SerenumEnumThread (0xfffff9800361b454) Stack Init fffff9800120adb0 Current fffff9800120a730 Base fffff9800120b000 Limit fffff98001205000 Call 0 Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0120a770 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0120a8b0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0120a910 fffff980`036231d8 nt!KeWaitForSingleObject+0x5f5 fffff980`0120a990 fffff980`036223fa serenum!Serenum_ReadSerialPort+0x10c fffff980`0120aa20 fffff980`0362281d serenum!SerenumDoEnumProtocol+0x3b2 fffff980`0120ab20 fffff980`0361b4c1 serenum!Serenum_ReenumerateDevices+0x2b1 fffff980`0120ad20 fffff800`01ae1bbb serenum!SerenumEnumThread+0x6d fffff980`0120ad50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0120ad80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8001e85bb0 Cid 0004.0130 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff98003f805e0 SynchronizationEvent fffff98003f805a0 SynchronizationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 944 Ticks: 199 (0:00:00:03.104) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address raspptp!MainPassiveLevelThread (0xfffff98003f6fe90) Stack Init fffff9800374adb0 Current fffff9800374aaa0 Base fffff9800374b000 Limit fffff98003745000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0374aae0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0374ac20 fffff800`0185a5ef nt!KiSwapThread+0x125 fffff980`0374ac80 fffff980`03f6ff0d nt!KeWaitForMultipleObjects+0x703 fffff980`0374acf0 fffff800`01ae1bbb raspptp!MainPassiveLevelThread+0x7d fffff980`0374ad50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0374ad80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800219dbb0 Cid 0004.0138 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff980030b5180 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1069 Ticks: 74 (0:00:00:01.154) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rasacd!AcdNotificationRequestThread (0xfffff980030b33e4) Stack Init fffff98003751db0 Current fffff98003751ab0 Base fffff98003752000 Limit fffff9800374c000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03751af0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03751c30 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`03751c90 fffff980`030b34ff nt!KeWaitForSingleObject+0x5f5 fffff980`03751d10 fffff800`01ae1bbb rasacd!AcdNotificationRequestThread+0x11b fffff980`03751d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03751d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002205290 Cid 0004.0154 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4b50 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff9800372edb0 Current fffff9800372e9f0 Base fffff9800372f000 Limit fffff98003729000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0372ea30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0372eb70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0372ebd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`0372ec60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`0372eca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`0372ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0372ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002207710 Cid 0004.0158 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4b50 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff980036f6db0 Current fffff980036f69f0 Base fffff980036f7000 Limit fffff980036f1000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`036f6a30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`036f6b70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`036f6bd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`036f6c60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`036f6ca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`036f6d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`036f6d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002207280 Cid 0004.015c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4c68 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff98003720db0 Current fffff980037209f0 Base fffff98003721000 Limit fffff9800371b000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03720a30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03720b70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`03720bd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`03720c60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`03720ca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`03720d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03720d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002209bb0 Cid 0004.0160 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4c68 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff98003727db0 Current fffff980037279f0 Base fffff98003728000 Limit fffff98003722000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03727a30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03727b70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`03727bd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`03727c60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`03727ca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`03727d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03727d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002209720 Cid 0004.0164 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b46f0 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff98003704db0 Current fffff980037049f0 Base fffff98003705000 Limit fffff980036ff000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03704a30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03704b70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`03704bd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`03704c60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`03704ca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`03704d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03704d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002209290 Cid 0004.0168 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4808 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff9800375fdb0 Current fffff9800375f9f0 Base fffff98003760000 Limit fffff9800375a000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0375fa30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0375fb70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0375fbd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`0375fc60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`0375fca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`0375fd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0375fd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800220bbb0 Cid 0004.016c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4920 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff9800162edb0 Current fffff9800162e9f0 Base fffff9800162f000 Limit fffff98001629000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0162ea30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0162eb70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0162ebd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`0162ec60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`0162eca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`0162ed50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0162ed80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800220b720 Cid 0004.0170 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4a38 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff980036fddb0 Current fffff980036fd9f0 Base fffff980036fe000 Limit fffff980036f8000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`036fda30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`036fdb70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`036fdbd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`036fdc60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`036fdca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`036fdd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`036fdd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800220b290 Cid 0004.0174 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrQueue) KernelMode Non-Alertable fffff980048b4a38 QueueObject Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxBootstrapWorkerThreadDispatcher (0xfffff980048d3b60) Stack Init fffff9800370bdb0 Current fffff9800370b9f0 Base fffff9800370c000 Limit fffff98003706000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0370ba30 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0370bb70 fffff800`018685e0 nt!KiSwapThread+0x125 fffff980`0370bbd0 fffff800`01834d51 nt!KeRemoveQueueEx+0x848 fffff980`0370bc60 fffff980`048961f5 nt!KeRemoveQueue+0x21 fffff980`0370bca0 fffff800`01ae1bbb rdbss!RxpWorkerThreadDispatcher+0xc5 fffff980`0370bd50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`0370bd80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800220dbb0 Cid 0004.0178 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffff980048b4cf8 NotificationEvent fffffa800220dc68 NotificationTimer Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1124 Ticks: 19 (0:00:00:00.296) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address rdbss!RxSpinUpRequestsDispatcher (0xfffff9800489c1e0) Stack Init fffff98003712db0 Current fffff98003712a80 Base fffff98003713000 Limit fffff9800370d000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03712ac0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03712c00 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`03712c60 fffff980`0489c2a5 nt!KeWaitForSingleObject+0x5f5 fffff980`03712ce0 fffff800`01ae1bbb rdbss!RxSpinUpRequestsDispatcher+0xc5 fffff980`03712d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03712d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa8002215540 Cid 0004.017c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (UserRequest) KernelMode Non-Alertable fffffa8002217c80 NotificationEvent Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1133 Ticks: 10 (0:00:00:00.156) Context Switch Count 1 IdealProcessor: 1 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address Ntfs!EfsGetSessionKey (0xfffff9800090a320) Stack Init fffff98003735db0 Current fffff98003735870 Base fffff98003736000 Limit fffff98003730000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`037358b0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`037359f0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`03735a50 fffff800`01a8a79b nt!KeWaitForSingleObject+0x5f5 fffff980`03735ad0 fffff800`0184d5f3 nt!NtWaitForSingleObject+0x9b fffff980`03735b30 fffff800`0184db00 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`03735b30) fffff980`03735cc8 fffff980`0090a347 nt!KiServiceLinkage fffff980`03735cd0 fffff800`01ae1bbb Ntfs!EfsGetSessionKey+0x27 fffff980`03735d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03735d80 00000000`00000000 nt!KxStartSystemThread+0x16 THREAD fffffa800221b8a0 Cid 0004.0180 Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (WrLpcReceive) UserMode Non-Alertable fffffa800221bc30 Semaphore Limit 0x1 Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa8000c74040 Image: System Attached Process N/A Image: N/A Wait Start TickCount 1134 Ticks: 9 (0:00:00:00.140) Context Switch Count 1 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address nt!SepRmCommandServerThread (0xfffff80001a72f20) Stack Init fffff98003758db0 Current fffff980037581d0 Base fffff98003759000 Limit fffff98003753000 Call 0 Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`03758210 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`03758350 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`037583b0 fffff800`01ab39d8 nt!KeWaitForSingleObject+0x5f5 fffff980`03758430 fffff800`01a7fbc3 nt!AlpcpReceiveMessagePort+0x298 fffff980`03758490 fffff800`01a754c2 nt!AlpcpReceiveLegacyMessage+0x122 fffff980`03758530 fffff800`01bb5456 nt!NtReplyWaitReceivePortEx+0xc1 fffff980`037585c0 fffff800`0184d5f3 nt!NtListenPort+0x26 fffff980`03758600 fffff800`0184db00 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`03758600) fffff980`03758798 fffff800`01b4428e nt!KiServiceLinkage fffff980`037587a0 fffff800`01a72f4e nt!SepRmCommandServerThreadInit+0x4e fffff980`037588b0 fffff800`01ae1bbb nt!SepRmCommandServerThread+0x2e fffff980`03758d50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`03758d80 00000000`00000000 nt!KxStartSystemThread+0x16 PROCESS fffffa800223dc10 SessionId: none Cid: 0184 Peb: 7fffffdf000 ParentCid: 0004 DirBase: 282f0000 ObjectTable: fffff88000130500 HandleCount: 16. Image: smss.exe VadRoot fffffa8002219680 Vads 10 Clone 0 Private 73. Modified 0. Locked 3. DeviceMap fffff880000075b0 Token fffff8800012f610 ElapsedTime 00:00:00.140 UserTime 00:00:00.000 KernelTime 00:00:00.000 QuotaPoolUsage[PagedPool] 10176 QuotaPoolUsage[NonPagedPool] 864 Working Set Sizes (now,min,max) (211, 50, 345) (844KB, 200KB, 1380KB) PeakWorkingSetSize 211 VirtualSize 4 Mb PeakVirtualSize 4 Mb PageFaultCount 210 MemoryPriority BACKGROUND BasePriority 11 CommitCharge 90 PEB at 000007fffffdf000 InheritedAddressSpace: No ReadImageFileExecOptions: No BeingDebugged: No ImageBaseAddress: 0000000047fa0000 Ldr 00000000770df980 Ldr.Initialized: Yes Ldr.InInitializationOrderModuleList: 00000000002c24c0 . 00000000002c24c0 Ldr.InLoadOrderModuleList: 00000000002c23d0 . 00000000002c24a0 Ldr.InMemoryOrderModuleList: 00000000002c23e0 . 00000000002c24b0 Base TimeStamp Module 47fa0000 4549b4d2 Nov 02 09:05:22 2006 \SystemRoot\System32\smss.exe 76fd0000 4549d372 Nov 02 11:16:02 2006 C:\Windows\system32\ntdll.dll SubSystemData: 0000000000000000 ProcessHeap: 00000000002c0000 ProcessParameters: 00000000002c13a0 CurrentDirectory: 'C:\Windows\' WindowTitle: '< Name not readable >' ImageFile: '\SystemRoot\System32\smss.exe' CommandLine: '\SystemRoot\System32\smss.exe' DllPath: 'C:\Windows\System32' Environment: 00000000002c1310 Path=C:\Windows\System32 SystemDrive=C: SystemRoot=C:\Windows THREAD fffffa8002233bb0 Cid 0184.0188 Teb: 000007fffffdd000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable fffffa8001b1d8e8 NotificationEvent IRP List: fffffa80021472f0: (0006,03a0) Flags: 00060901 Mdl: fffffa80021fb270 Not impersonating DeviceMap fffff880000075b0 Owning Process fffffa800223dc10 Image: smss.exe Attached Process N/A Image: N/A Wait Start TickCount 1142 Ticks: 1 (0:00:00:00.015) Context Switch Count 25 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.062 Win32 Start Address smss!NtProcessStartupW (0x0000000047fafadc) Stack Init fffff9800373cdb0 Current fffff9800373c310 Base fffff9800373d000 Limit fffff98003737000 Call 0 Priority 11 BasePriority 11 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`0373c350 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`0373c490 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`0373c4f0 fffff980`008482b3 nt!KeWaitForSingleObject+0x5f5 fffff980`0373c570 fffff980`0084560c Ntfs!NtfsNonCachedIo+0x263 fffff980`0373c740 fffff980`00847e04 Ntfs!NtfsCommonRead+0x61c fffff980`0373c8b0 fffff980`0043f21a Ntfs!NtfsFsdRead+0x294 fffff980`0373c980 fffff980`0043f691 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x20a fffff980`0373c9f0 fffff800`01abdf8f fltmgr!FltpDispatch+0xd1 fffff980`0373ca50 fffff800`01aa1564 nt!IopSynchronousServiceTail+0x12f fffff980`0373cac0 fffff800`0184d5f3 nt!NtReadFile+0x583 fffff980`0373cbb0 00000000`770202da nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`0373cc20) 00000000`0028d8c8 00000000`47fa59b5 ntdll!ZwReadFile+0xa 00000000`0028d8d0 00000000`47fa4218 smss!SmpCheckForCrashDump+0x145 00000000`0028fa00 00000000`47fa6927 smss!SmpCreatePagingFiles+0x50 00000000`0028fa60 00000000`47fa6359 smss!SmpLoadDataFromRegistry+0x4bf 00000000`0028fb20 00000000`47fad5fe smss!SmpInit+0x1c9 00000000`0028fbd0 00000000`47fafab4 smss!wmain+0x132 00000000`0028fcc0 00000000`76ffb332 smss!NtProcessStartupW_AfterSecurityCookieInitialized+0x2fc 00000000`0028fd50 00000000`00000000 ntdll!RtlUserThreadStart+0x29 1: kd> !irp fffffa80021472f0 Irp is active with 9 stacks 7 is current (= 0xfffffa8002147570) Mdl=fffffa80021fb270: No System Buffer: Thread fffffa8002233bb0: Irp stack trace. cmd flg cl Device File Completion-Context [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 >[ 3, 0] 0 e1 fffffa8001c335b0 00000000 fffff98000b487e4-fffffa8001cbb3d0 Success Error Cancel pending \Driver\Ecache volsnap!VspReadCompletionRoutine Args: 00002000 00000000 06ef3000 00000000 [ 3, 0] 0 e1 fffffa8001c35460 00000000 fffff98000844ab0-fffffa8001b1d8e0 Success Error Cancel pending \Driver\volsnap Ntfs!NtfsMasterIrpSyncCompletionRoutine Args: 00002000 00000000 06ef3000 00000000 [ 3, 0] 0 0 fffffa8001c02030 fffffa8001c655d0 00000000-00000000 \FileSystem\Ntfs Args: 00002000 00000000 00000000 00000000 1: kd> !fileobj fffffa8001c655d0 \pagefile.sys Device Object: 0xfffffa8001c31490 \Driver\volmgr Vpb: 0xfffffa8001c1b630 Access: Read Write Delete SharedRead SharedWrite Flags: 0x4000a Synchronous IO No Intermediate Buffering Handle Created File Object is currently busy and has 0 waiters. FsContext: 0xfffff880008ccc80 FsContext2: 0xfffff880008cce68 CurrentByteOffset: 0 Cache Data: Section Object Pointers: fffffa80022178e0 Shared Cache Map: 00000000 1: kd> g Break instruction exception - code 80000003 (first chance) ******************************************************************************* * * * You are seeing this message because you pressed either * * CTRL+C (if you run console kernel debugger) or, * * CTRL+BREAK (if you run GUI kernel debugger), * * on your debugger machine's keyboard. * * * * THIS IS NOT A BUG OR A SYSTEM CRASH * * * * If you did not intend to break into the debugger, press the "g" key, then * * press the "Enter" key now. This message might immediately reappear. If it * * does, press "g" and "Enter" again. * * * ******************************************************************************* nt!RtlpBreakWithStatusInstruction: fffff800`018472a0 cc int 3 0: kd> !process 0 0 **** NT ACTIVE PROCESS DUMP **** PROCESS fffffa8000c74040 SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000 DirBase: 00124000 ObjectTable: fffff88000001fa0 HandleCount: 496. Image: System PROCESS fffffa800223dc10 SessionId: none Cid: 0184 Peb: 7fffffdf000 ParentCid: 0004 DirBase: 282f0000 ObjectTable: fffff88000130500 HandleCount: 28. Image: smss.exe PROCESS fffffa80022e73c0 SessionId: 0 Cid: 01f0 Peb: 7fffffdb000 ParentCid: 01e4 DirBase: 1fe13000 ObjectTable: fffff880014f2190 HandleCount: 575. Image: csrss.exe PROCESS fffffa800233bc10 SessionId: 0 Cid: 0210 Peb: 7fffffde000 ParentCid: 01e4 DirBase: 1f25a000 ObjectTable: fffff880018607d0 HandleCount: 101. Image: wininit.exe PROCESS fffffa800233f9e0 SessionId: 1 Cid: 0224 Peb: 7fffffdd000 ParentCid: 0218 DirBase: 1ec75000 ObjectTable: fffff88001860760 HandleCount: 234. Image: csrss.exe PROCESS fffffa80023bb3c0 SessionId: 0 Cid: 0254 Peb: 7fffffde000 ParentCid: 0210 DirBase: 1d965000 ObjectTable: fffff880018c1ae0 HandleCount: 258. Image: services.exe PROCESS fffffa80023ad2d0 SessionId: 1 Cid: 026c Peb: 7fffffd7000 ParentCid: 0218 DirBase: 1db3c000 ObjectTable: fffff880018934d0 HandleCount: 126. Image: winlogon.exe PROCESS fffffa80023e98a0 SessionId: 0 Cid: 028c Peb: 7fffffd6000 ParentCid: 0210 DirBase: 1d0d3000 ObjectTable: fffff880018eac20 HandleCount: 584. Image: lsass.exe PROCESS fffffa80023edc10 SessionId: 0 Cid: 0294 Peb: 7fffffd6000 ParentCid: 0210 DirBase: 1d39a000 ObjectTable: fffff880018ebca0 HandleCount: 166. Image: lsm.exe PROCESS fffffa80034b8a40 SessionId: 0 Cid: 031c Peb: 7fffffd7000 ParentCid: 0254 DirBase: 1be0b000 ObjectTable: fffff88001950550 HandleCount: 309. Image: svchost.exe PROCESS fffffa80036f5750 SessionId: 0 Cid: 0354 Peb: 7fffffdd000 ParentCid: 0254 DirBase: 1b725000 ObjectTable: fffff88001a5c060 HandleCount: 298. Image: svchost.exe PROCESS fffffa800371a920 SessionId: 0 Cid: 0378 Peb: 7fffffdf000 ParentCid: 0254 DirBase: 1b97a000 ObjectTable: fffff88001a71360 HandleCount: 334. Image: svchost.exe PROCESS fffffa800376b260 SessionId: 0 Cid: 03e0 Peb: 7fffffd5000 ParentCid: 0254 DirBase: 1abdc000 ObjectTable: fffff88001af25e0 HandleCount: 376. Image: svchost.exe PROCESS fffffa8003702c10 SessionId: 0 Cid: 0110 Peb: 7fffffda000 ParentCid: 0254 DirBase: 19f64000 ObjectTable: fffff88001b7f570 HandleCount: 382. Image: svchost.exe PROCESS fffffa8003a29990 SessionId: 0 Cid: 0144 Peb: 7fffffd4000 ParentCid: 0254 DirBase: 1912a000 ObjectTable: fffff88001b9da50 HandleCount: 706. Image: svchost.exe PROCESS fffffa8003a46c10 SessionId: 0 Cid: 0218 Peb: 7fffffda000 ParentCid: 03e0 DirBase: 18d46000 ObjectTable: fffff88001bb64d0 HandleCount: 117. Image: audiodg.exe PROCESS fffffa8003a59040 SessionId: 0 Cid: 03a0 Peb: 7fffffdf000 ParentCid: 0254 DirBase: 184c5000 ObjectTable: fffff88001af3120 HandleCount: 72. Image: SLsvc.exe PROCESS fffffa8003a5d620 SessionId: 0 Cid: 043c Peb: 7fffffd7000 ParentCid: 0254 DirBase: 17fdb000 ObjectTable: fffff88001bf6ed0 HandleCount: 625. Image: svchost.exe PROCESS fffffa8003aa4750 SessionId: 0 Cid: 04a0 Peb: 7fffffdd000 ParentCid: 0254 DirBase: 167bb000 ObjectTable: fffff88001c62e20 HandleCount: 403. Image: svchost.exe PROCESS fffffa8003b39610 SessionId: 0 Cid: 0588 Peb: 7fffffd4000 ParentCid: 0254 DirBase: 140d2000 ObjectTable: fffff88001ca2950 HandleCount: 341. Image: spoolsv.exe PROCESS fffffa8003b4bb60 SessionId: 0 Cid: 05a0 Peb: 7fffffda000 ParentCid: 0254 DirBase: 13fd8000 ObjectTable: fffff88001d38b40 HandleCount: 296. Image: svchost.exe PROCESS fffffa8003bf12d0 SessionId: 1 Cid: 0684 Peb: 7fffffdc000 ParentCid: 0110 DirBase: 11244000 ObjectTable: fffff88001ab2fa0 HandleCount: 73. Image: dwm.exe PROCESS fffffa8003bfcb30 SessionId: 1 Cid: 06c0 Peb: 7fffffd9000 ParentCid: 0668 DirBase: 10cae000 ObjectTable: fffff88001947a00 HandleCount: 552. Image: explorer.exe PROCESS fffffa8003cd0040 SessionId: 1 Cid: 0770 Peb: 7fffffd4000 ParentCid: 06c0 DirBase: 0dab8000 ObjectTable: fffff88001fc9300 HandleCount: 379. Image: MSASCui.exe PROCESS fffffa8003ccf760 SessionId: 1 Cid: 0778 Peb: 7fffffdb000 ParentCid: 06c0 DirBase: 0cfe1000 ObjectTable: fffff88001ef5fa0 HandleCount: 63. Image: VMwareTray.exe PROCESS fffffa8003f84c10 SessionId: 1 Cid: 078c Peb: 7fffffde000 ParentCid: 06c0 DirBase: 0c750000 ObjectTable: fffff88001ef5f00 HandleCount: 151. Image: vmtoolsd.exe PROCESS fffffa8003d375f0 SessionId: 0 Cid: 0404 Peb: 7fffffdf000 ParentCid: 0254 DirBase: 09253000 ObjectTable: fffff88002042910 HandleCount: 108. Image: svchost.exe PROCESS fffffa8003d59040 SessionId: 0 Cid: 05cc Peb: 7fffffd7000 ParentCid: 0254 DirBase: 08999000 ObjectTable: fffff88001f32230 HandleCount: 42. Image: svchost.exe PROCESS fffffa8003da3040 SessionId: 0 Cid: 03c4 Peb: 7fffffd3000 ParentCid: 0254 DirBase: 0891f000 ObjectTable: fffff8800194b4d0 HandleCount: 686. Image: SearchIndexer.exe PROCESS fffffa8003db1290 SessionId: 0 Cid: 075c Peb: 7fffffde000 ParentCid: 0254 DirBase: 071ef000 ObjectTable: fffff88001e56170 HandleCount: 286. Image: vmtoolsd.exe PROCESS fffffa8003e5eb40 SessionId: 0 Cid: 0844 Peb: 7fffffd3000 ParentCid: 0254 DirBase: 06281000 ObjectTable: fffff880021bc1c0 HandleCount: 132. Image: TPAutoConnSvc.exe PROCESS fffffa8003e14040 SessionId: 1 Cid: 0850 Peb: 7fffffde000 ParentCid: 0144 DirBase: 05bdd000 ObjectTable: fffff880021c2620 HandleCount: 311. Image: taskeng.exe PROCESS fffffa8003e73910 SessionId: 0 Cid: 08a4 Peb: 7fffffd4000 ParentCid: 031c DirBase: 05a0f000 ObjectTable: fffff880022092e0 HandleCount: 152. Image: WmiPrvSE.exe PROCESS fffffa8003e45820 SessionId: 0 Cid: 08ec Peb: 7fffffdc000 ParentCid: 0254 DirBase: 0510a000 ObjectTable: fffff88002242690 HandleCount: 233. Image: dllhost.exe PROCESS fffffa8003da2620 SessionId: 0 Cid: 0914 Peb: 7fffffd6000 ParentCid: 0144 DirBase: 04762000 ObjectTable: fffff880021c2ca0 HandleCount: 133. Image: taskeng.exe PROCESS fffffa8003f09c10 SessionId: 0 Cid: 0974 Peb: 7fffffdc000 ParentCid: 0254 DirBase: 03f52000 ObjectTable: fffff8800222d160 HandleCount: 270. Image: dllhost.exe PROCESS fffffa8003f0e9e0 SessionId: 0 Cid: 0a54 Peb: 7fffffd7000 ParentCid: 0254 DirBase: 024a9000 ObjectTable: fffff880020e1090 HandleCount: 163. Image: msdtc.exe PROCESS fffffa8003f29990 SessionId: 1 Cid: 0a88 Peb: 7fffffd9000 ParentCid: 0844 DirBase: 3d474000 ObjectTable: fffff880024551e0 HandleCount: 107. Image: TPAutoConnect.exe PROCESS fffffa8003f85470 SessionId: 0 Cid: 0b24 Peb: 7fffffd3000 ParentCid: 0254 DirBase: 255b7000 ObjectTable: fffff880020e1c30 HandleCount: 131. Image: VSSVC.exe PROCESS fffffa8003a74bb0 SessionId: 1 Cid: 08e4 Peb: 7fffffdf000 ParentCid: 06c0 DirBase: 21976000 ObjectTable: fffff88002312740 HandleCount: 48. Image: notepad.exe 0: kd> !process fffffa8003a74bb0 3f PROCESS fffffa8003a74bb0 SessionId: 1 Cid: 08e4 Peb: 7fffffdf000 ParentCid: 06c0 DirBase: 21976000 ObjectTable: fffff88002312740 HandleCount: 48. Image: notepad.exe VadRoot fffffa8003fe3b70 Vads 52 Clone 0 Private 273. Modified 0. Locked 0. DeviceMap fffff88001b2add0 Token fffff88002331ab0 ElapsedTime 00:00:09.547 UserTime 00:00:00.000 KernelTime 00:00:00.000 QuotaPoolUsage[PagedPool] 125592 QuotaPoolUsage[NonPagedPool] 4896 Working Set Sizes (now,min,max) (1039, 50, 345) (4156KB, 200KB, 1380KB) PeakWorkingSetSize 1039 VirtualSize 61 Mb PeakVirtualSize 62 Mb PageFaultCount 1049 MemoryPriority BACKGROUND BasePriority 8 CommitCharge 418 PEB at 000007fffffdf000 InheritedAddressSpace: No ReadImageFileExecOptions: No BeingDebugged: No ImageBaseAddress: 00000000ff2c0000 Ldr 00000000770df980 Ldr.Initialized: Yes Ldr.InInitializationOrderModuleList: 00000000002424a0 . 000000000026a380 Ldr.InLoadOrderModuleList: 00000000002423b0 . 000000000026a360 Ldr.InMemoryOrderModuleList: 00000000002423c0 . 000000000026a370 Base TimeStamp Module ff2c0000 4549bb19 Nov 02 09:32:09 2006 C:\Windows\System32\notepad.exe 76fd0000 4549d372 Nov 02 11:16:02 2006 C:\Windows\system32\ntdll.dll 76dc0000 4995251a Feb 13 07:45:30 2009 C:\Windows\system32\kernel32.dll 7feff1d0000 4549d267 Nov 02 11:11:35 2006 C:\Windows\system32\ADVAPI32.dll 7fefd7c0000 49f0690c Apr 23 14:11:40 2009 C:\Windows\system32\RPCRT4.dll 7fefdb90000 48fd6901 Oct 21 06:30:41 2008 C:\Windows\system32\GDI32.dll 76f00000 45d3ee19 Feb 15 05:22:33 2007 C:\Windows\system32\USER32.dll 7fefe030000 4549d2e1 Nov 02 11:13:37 2006 C:\Windows\system32\msvcrt.dll 7fefd730000 4549d32b Nov 02 11:14:51 2006 C:\Windows\system32\COMDLG32.dll 7fefdc00000 4549d31f Nov 02 11:14:39 2006 C:\Windows\system32\SHLWAPI.dll 7fefc040000 4549d32b Nov 02 11:14:51 2006 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_1559f1c6f365a7fa\COMCTL32.dll 7fefe480000 4912ef34 Nov 06 13:20:52 2008 C:\Windows\system32\SHELL32.dll 7fefa8b0000 4549d37c Nov 02 11:16:12 2006 C:\Windows\System32\WINSPOOL.DRV 7fefdc80000 4549d317 Nov 02 11:14:31 2006 C:\Windows\system32\ole32.dll 7fefe230000 4757840f Dec 06 05:09:35 2007 C:\Windows\system32\OLEAUT32.dll 7fefe1e0000 4549d2cb Nov 02 11:13:15 2006 C:\Windows\system32\IMM32.DLL 7fefe310000 4549d2e6 Nov 02 11:13:42 2006 C:\Windows\system32\MSCTF.dll 7fefe420000 4adc79bc Oct 19 15:37:48 2009 C:\Windows\system32\LPK.DLL 7fefdae0000 4549d337 Nov 02 11:15:03 2006 C:\Windows\system32\USP10.dll 7fefc3c0000 4549d33b Nov 02 11:15:07 2006 C:\Windows\System32\UxTheme.dll SubSystemData: 0000000000000000 ProcessHeap: 0000000000240000 ProcessParameters: 0000000000241b40 CurrentDirectory: 'C:\Users\Training\' WindowTitle: 'C:\Users\Training\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk' ImageFile: 'C:\Windows\System32\notepad.exe' CommandLine: '"C:\Windows\System32\notepad.exe" ' DllPath: 'C:\Windows\System32;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem' Environment: 0000000000241310 =::=::\ ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Training\AppData\Roaming CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files COMPUTERNAME=LH-ZH5VMPAL2053 ComSpec=C:\Windows\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Training LOCALAPPDATA=C:\Users\Training\AppData\Local LOGONSERVER=\\LH-ZH5VMPAL2053 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=EM64T Family 6 Model 42 Stepping 7, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=2a07 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) PUBLIC=C:\Users\Public SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\Training\AppData\Local\Temp TMP=C:\Users\Training\AppData\Local\Temp USERDOMAIN=LH-ZH5VMPAL2053 USERNAME=Training USERPROFILE=C:\Users\Training windir=C:\Windows THREAD fffffa8002a86060 Cid 08e4.0904 Teb: 000007fffffdd000 Win32Thread: fffff900c1cd9a60 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003ffe8d0 SynchronizationEvent Not impersonating DeviceMap fffff88001b2add0 Owning Process fffffa8003a74bb0 Image: notepad.exe Attached Process N/A Image: N/A Wait Start TickCount 6789 Ticks: 29 (0:00:00:00.452) Context Switch Count 129 IdealProcessor: 1 LargeStack UserTime 00:00:00.000 KernelTime 00:00:00.015 Win32 Start Address notepad!WinMainCRTStartup (0x00000000ff2cd134) Stack Init fffff98017d1ddb0 Current fffff98017d1d740 Base fffff98017d1e000 Limit fffff98017d15000 Call 0 Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5 *** ERROR: Module load completed but symbols could not be loaded for intelppm.sys Child-SP RetAddr Call Site fffff980`17d1d780 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`17d1d8c0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`17d1d920 fffff960`000c98e8 nt!KeWaitForSingleObject+0x5f5 fffff980`17d1d9a0 fffff960`000c9976 win32k!xxxRealSleepThread+0x278 fffff980`17d1da40 fffff960`000c80de win32k!xxxSleepThread+0x56 fffff980`17d1da70 fffff960`000c81e5 win32k!xxxRealInternalGetMessage+0x72e fffff980`17d1db50 fffff960`000c9a94 win32k!xxxInternalGetMessage+0x35 fffff980`17d1db90 fffff800`0184d5f3 win32k!NtUserGetMessage+0x64 fffff980`17d1dc20 00000000`76f1e6aa nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`17d1dc20) 00000000`001cf938 00000000`76f1e6ea USER32!NtUserGetMessage+0xa 00000000`001cf940 00000000`ff2c6eca USER32!GetMessageW+0x34 00000000`001cf970 00000000`ff2ccf8b notepad!WinMain+0x176 00000000`001cf9f0 00000000`76dfcf1d notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 0: kd> .process /r /p fffffa8003a74bb0 Implicit process is now fffffa80`03a74bb0 .cache forcedecodeuser done Loading User Symbols .................... 0: kd> .thread /r /p fffffa8002a86060 Implicit thread is now fffffa80`02a86060 Implicit process is now fffffa80`03a74bb0 .cache forcedecodeuser done Loading User Symbols .................... 0: kd> kv *** Stack trace for last set context - .thread/.cxr resets it Child-SP RetAddr : Args to Child : Call Site fffff980`17d1d780 fffff800`0185cf55 : 00000000`000001a0 00000000`00000000 00000000`018a0047 fffff960`000c2f43 : nt!KiSwapContext+0x84 fffff980`17d1d8c0 fffff800`0185cc9d : 00000000`00000001 00000000`000001a0 fffff900`c1cd9a60 fffff980`00a99180 : nt!KiSwapThread+0x125 fffff980`17d1d920 fffff960`000c98e8 : 00000000`00000000 fffff900`0000000d fffff900`c0090001 fffff800`01853000 : nt!KeWaitForSingleObject+0x5f5 fffff980`17d1d9a0 fffff960`000c9976 : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`00000000 : win32k!xxxRealSleepThread+0x278 fffff980`17d1da40 fffff960`000c80de : fffff900`c1cd9a60 fffff980`17d1dca0 00000000`00000001 00000000`00000000 : win32k!xxxSleepThread+0x56 fffff980`17d1da70 fffff960`000c81e5 : 00000000`001cf9b0 fffff960`000025ff 00000000`00000000 fffff960`ffffffff : win32k!xxxRealInternalGetMessage+0x72e fffff980`17d1db50 fffff960`000c9a94 : 00000000`00000020 fffff960`000d762d 00000000`001cf9b0 fffff980`17d1dca0 : win32k!xxxInternalGetMessage+0x35 fffff980`17d1db90 fffff800`0184d5f3 : fffffa80`02a86060 00000000`00000001 00000000`00000020 00000000`00000020 : win32k!NtUserGetMessage+0x64 fffff980`17d1dc20 00000000`76f1e6aa : 00000000`76f1e6ea 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`17d1dc20) 00000000`001cf938 00000000`76f1e6ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`ff2c1728 : USER32!NtUserGetMessage+0xa 00000000`001cf940 00000000`ff2c6eca : 00000000`00240048 00000000`0001018f 000007fe`fe313b90 00000000`00000001 : USER32!GetMessageW+0x34 00000000`001cf970 00000000`ff2ccf8b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : notepad!WinMain+0x176 00000000`001cf9f0 00000000`76dfcf1d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d 0: kd> k *** Stack trace for last set context - .thread/.cxr resets it Child-SP RetAddr Call Site fffff980`17d1d780 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`17d1d8c0 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`17d1d920 fffff960`000c98e8 nt!KeWaitForSingleObject+0x5f5 fffff980`17d1d9a0 fffff960`000c9976 win32k!xxxRealSleepThread+0x278 fffff980`17d1da40 fffff960`000c80de win32k!xxxSleepThread+0x56 fffff980`17d1da70 fffff960`000c81e5 win32k!xxxRealInternalGetMessage+0x72e fffff980`17d1db50 fffff960`000c9a94 win32k!xxxInternalGetMessage+0x35 fffff980`17d1db90 fffff800`0184d5f3 win32k!NtUserGetMessage+0x64 fffff980`17d1dc20 00000000`76f1e6aa nt!KiSystemServiceCopyEnd+0x13 00000000`001cf938 00000000`76f1e6ea USER32!NtUserGetMessage+0xa 00000000`001cf940 00000000`ff2c6eca USER32!GetMessageW+0x34 00000000`001cf970 00000000`ff2ccf8b notepad!WinMain+0x176 00000000`001cf9f0 00000000`76dfcf1d notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 0: kd> ba e 1 USER32!GetMessageW 0: kd> bl 0 e 00000000`76f1e6c0 e 1 0001 (0001) USER32!GetMessageW 0: kd> g Breakpoint 0 hit USER32!GetMessageW: 0033:00000000`76f1e6c0 fff3 push rbx 0: kd> k Child-SP RetAddr Call Site 00000000`0610f8a8 000007fe`f4d39e9a USER32!GetMessageW 00000000`0610f8b0 00000000`00000000 0x000007fe`f4d39e9a 0: kd> !process PROCESS fffffa8003bfcb30 SessionId: 1 Cid: 06c0 Peb: 7fffffd9000 ParentCid: 0668 DirBase: 10cae000 ObjectTable: fffff88001947a00 HandleCount: 552. Image: explorer.exe VadRoot fffffa8003c03350 Vads 330 Clone 0 Private 3293. Modified 5822. Locked 0. DeviceMap fffff88001b2add0 Token fffff88001aaf9a0 ElapsedTime 00:30:22.512 UserTime 00:00:00.780 KernelTime 00:00:02.090 QuotaPoolUsage[PagedPool] 331624 QuotaPoolUsage[NonPagedPool] 47312 Working Set Sizes (now,min,max) (8134, 5411, 5927) (32536KB, 21644KB, 23708KB) PeakWorkingSetSize 9497 VirtualSize 187 Mb PeakVirtualSize 191 Mb PageFaultCount 19917 MemoryPriority BACKGROUND BasePriority 8 CommitCharge 6363 THREAD fffffa8003c06bb0 Cid 06c0.06c4 Teb: 000007fffffde000 Win32Thread: fffff900c1c49400 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa800223d480 SynchronizationEvent THREAD fffffa8003c375f0 Cid 06c0.06e0 Teb: 000007fffffdc000 Win32Thread: fffff900c1c248b0 WAIT: (WrQueue) UserMode Non-Alertable fffffa8003c162f0 QueueObject fffffa8003c376a8 NotificationTimer THREAD fffffa8003c39060 Cid 06c0.06e4 Teb: 000007fffffda000 Win32Thread: 0000000000000000 WAIT: (DelayExecution) UserMode Non-Alertable fffffa8003c39118 NotificationTimer THREAD fffffa8003c3a060 Cid 06c0.06e8 Teb: 000007fffffd7000 Win32Thread: fffff900c1c15b40 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003c39790 SynchronizationEvent THREAD fffffa8003c64bb0 Cid 06c0.0728 Teb: 000007fffffd5000 Win32Thread: fffff900c1c51010 WAIT: (UserRequest) UserMode Alertable fffffa8003b1b420 NotificationEvent fffffa8003a27840 NotificationEvent fffffa8003c8b1f0 NotificationEvent fffffa8003c73d90 NotificationEvent fffffa8003b94660 NotificationEvent fffffa8003c8fab0 NotificationEvent fffffa8003c7d3c0 NotificationEvent fffffa8003c6e3b0 NotificationEvent fffffa8003c07560 NotificationEvent fffffa8003c8b6e0 NotificationEvent fffffa8003bf8b50 NotificationEvent fffffa8003c3bec0 NotificationEvent fffffa8003c6d6c0 NotificationEvent fffffa8003766bc0 NotificationEvent fffffa8003c263a0 NotificationEvent fffffa8003c3f4f0 NotificationEvent fffffa8003c3ebd0 SynchronizationEvent THREAD fffffa8003c6f7e0 Cid 06c0.0734 Teb: 000007fffffd3000 Win32Thread: fffff900c1cd6910 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003c6fc70 NotificationEvent fffffa8003c6efe0 SynchronizationEvent THREAD fffffa8003ce1060 Cid 06c0.07a8 Teb: 000007fffffa2000 Win32Thread: fffff900c1c094c0 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003ce6320 SynchronizationEvent THREAD fffffa8003b9abb0 Cid 06c0.07ac Teb: 000007fffffa0000 Win32Thread: 0000000000000000 WAIT: (DelayExecution) UserMode Non-Alertable fffffa8003b9ac68 NotificationTimer THREAD fffffa8003ce4bb0 Cid 06c0.07b8 Teb: 000007fffff9e000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffffa8003cf7040 QueueObject THREAD fffffa8003ce4700 Cid 06c0.07bc Teb: 000007fffff9c000 Win32Thread: fffff900c0702750 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003cf7f00 SynchronizationEvent THREAD fffffa8003d08bb0 Cid 06c0.07c0 Teb: 000007fffff9a000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003ce3aa0 SynchronizationEvent fffffa8003ce3a40 SynchronizationEvent THREAD fffffa8003ce5bb0 Cid 06c0.07fc Teb: 000007fffffa4000 Win32Thread: fffff900c07d4d60 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003766f10 SynchronizationEvent fffffa8003ce7760 SynchronizationEvent THREAD fffffa8003ba2af0 Cid 06c0.0344 Teb: 000007fffff98000 Win32Thread: fffff900c1c39c70 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa800373f3b0 SynchronizationEvent THREAD fffffa8003a1f060 Cid 06c0.0428 Teb: 000007fffff96000 Win32Thread: fffff900c07df610 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003be52a0 SynchronizationEvent fffffa8003763f00 SynchronizationEvent THREAD fffffa8003a07060 Cid 06c0.0310 Teb: 000007fffff94000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Alertable fffffa8003767630 SynchronizationTimer fffffa8003a3f620 NotificationEvent fffffa8003b4ecf0 SynchronizationEvent fffffa8003e4d970 SynchronizationEvent fffffa8003e577c0 SynchronizationEvent fffffa8003b90a60 SynchronizationEvent fffffa8003d5f210 SynchronizationEvent THREAD fffffa8003a37060 Cid 06c0.0454 Teb: 000007fffff92000 Win32Thread: fffff900c1c32640 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003a41ba0 SynchronizationEvent THREAD fffffa8003a52060 Cid 06c0.0484 Teb: 000007fffff90000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Alertable fffffa80036de170 SynchronizationEvent THREAD fffffa8003a5a510 Cid 06c0.0490 Teb: 000007fffff8e000 Win32Thread: fffff900c21b5630 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa80037e36d0 SynchronizationEvent THREAD fffffa8003730060 Cid 06c0.049c Teb: 000007fffff8c000 Win32Thread: fffff900c1cded60 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003759c40 SynchronizationEvent fffffa8003748d60 SynchronizationEvent THREAD fffffa8003ad5060 Cid 06c0.0498 Teb: 000007fffff8a000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable fffffa80036f5390 QueueObject THREAD fffffa8003d77060 Cid 06c0.0550 Teb: 000007fffffae000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffffa8003d80fb8 Semaphore Limit 0x7fffffff fffffa8003d77118 NotificationTimer THREAD fffffa8003e8ebb0 Cid 06c0.08ac Teb: 000007fffffac000 Win32Thread: fffff900c00a5570 WAIT: (WrQueue) UserMode Non-Alertable fffffa8003c162f0 QueueObject fffffa8003e8ec68 NotificationTimer THREAD fffffa8003e83060 Cid 06c0.0944 Teb: 000007fffffaa000 Win32Thread: fffff900c1c21d60 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003dd5d40 SynchronizationEvent THREAD fffffa8003e0e060 Cid 06c0.0948 Teb: 000007fffffa8000 Win32Thread: fffff900c07ecd60 RUNNING on processor 0 THREAD fffffa8003e13060 Cid 06c0.0950 Teb: 000007fffffa6000 Win32Thread: fffff900c1c4d6e0 WAIT: (UserRequest) UserMode Alertable fffffa8003e15c88 NotificationEvent fffffa8003e0a3f0 SynchronizationEvent THREAD fffffa8003e23a60 Cid 06c0.095c Teb: 000007fffff88000 Win32Thread: fffff900c1c244f0 WAIT: (UserRequest) UserMode Alertable fffffa8003e23040 SynchronizationEvent fffffa800224b690 SynchronizationEvent fffffa8003e3d540 SynchronizationEvent THREAD fffffa8003e36060 Cid 06c0.0984 Teb: 000007fffff84000 Win32Thread: 0000000000000000 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003e33210 SynchronizationEvent fffffa8003e36118 NotificationTimer THREAD fffffa8003e3e490 Cid 06c0.099c Teb: 000007fffff82000 Win32Thread: fffff900c1c5d460 WAIT: (UserRequest) UserMode Alertable fffffa8003e259d0 SynchronizationEvent fffffa8003e3e548 NotificationTimer THREAD fffffa8003e63060 Cid 06c0.09bc Teb: 000007fffff7c000 Win32Thread: fffff900c07dfb80 WAIT: (UserRequest) UserMode Non-Alertable fffffa8003e179e0 SynchronizationEvent fffffa8003e60450 SynchronizationEvent THREAD fffffa8003e65060 Cid 06c0.09cc Teb: 000007fffff78000 Win32Thread: fffff900c06df4c0 WAIT: (WrUserRequest) UserMode Non-Alertable fffffa8003e6c4f0 SynchronizationEvent THREAD fffffa8003f42060 Cid 06c0.0b1c Teb: 000007fffff86000 Win32Thread: fffff900c07b1460 WAIT: (WrQueue) UserMode Alertable fffffa8003c71930 QueueObject fffffa8003f42118 NotificationTimer THREAD fffffa8003e40a30 Cid 06c0.0b80 Teb: 000007fffff7e000 Win32Thread: fffff900c07ed7e0 WAIT: (WrQueue) UserMode Alertable fffffa8003c71930 QueueObject fffffa8003e40ae8 NotificationTimer THREAD fffffa8003fdb060 Cid 06c0.0be8 Teb: 000007fffff72000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable fffffa8003c71930 QueueObject fffffa8003fdb118 NotificationTimer THREAD fffffa8003ffea80 Cid 06c0.0bfc Teb: 000007fffff74000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Non-Alertable fffffa8003c162f0 QueueObject fffffa8003ffeb38 NotificationTimer 0: kd> .thread /r /p fffffa8002a86060 Implicit thread is now fffffa80`02a86060 Implicit process is now fffffa80`03a74bb0 .cache forcedecodeuser done Loading User Symbols .................... 0: kd> k *** Stack trace for last set context - .thread/.cxr resets it Child-SP RetAddr Call Site fffff980`17d1d2e0 fffff800`0185a9d5 nt!KiSwapContext+0x84 fffff980`17d1d420 fffff800`0185954c nt!KiExitDispatcher+0x185 fffff980`17d1d450 fffff960`00608395 nt!KeSetEvent+0x2aa fffff980`17d1d490 fffff960`0060880a cdd!CddIssueCommand+0x115 fffff980`17d1d4d0 fffff960`0060928a cdd!vGDIDirtyUpdate+0x132 fffff980`17d1d500 fffff960`0001f357 cdd!DrvBitBlt+0x48e fffff980`17d1d5b0 fffff960`00177cf7 win32k!WatchdogDrvBitBlt+0xc7 fffff980`17d1d640 fffff960`0017bffb win32k!OffBitBlt+0x127 fffff980`17d1d6d0 fffff960`0001ec86 win32k!SpBitBlt+0x35b fffff980`17d1d810 fffff960`0001e87c win32k!GrePatBltLockedDC+0x2e6 fffff980`17d1d8c0 fffff960`0001e554 win32k!GrePolyPatBltInternal+0x2dc fffff980`17d1d9f0 fffff960`00111524 win32k!GrePolyPatBlt+0x74 fffff980`17d1da60 fffff960`00111877 win32k!UT_InvertCaret+0x164 fffff980`17d1daf0 fffff960`00097bc3 win32k!CaretBlinkProc+0x97 fffff980`17d1db30 fffff960`000d7621 win32k!xxxDispatchMessage+0x153 fffff980`17d1dba0 fffff800`0184d5f3 win32k!NtUserDispatchMessage+0x51 fffff980`17d1dc20 00000000`76f1ce9a nt!KiSystemServiceCopyEnd+0x13 00000000`001cf8e8 00000000`76f1ef19 USER32!NtUserDispatchMessage+0xa 00000000`001cf8f0 00000000`ff2c6eb7 USER32!DispatchMessageWorker+0xd9 00000000`001cf970 00000000`ff2ccf8b notepad!WinMain+0x163 00000000`001cf9f0 00000000`76dfcf1d notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 0: kd> g Breakpoint 0 hit USER32!GetMessageW: 0033:00000000`76f1e6c0 fff3 push rbx 1: kd> k Child-SP RetAddr Call Site 00000000`001cf968 00000000`ff2c6eca USER32!GetMessageW 00000000`001cf970 00000000`ff2ccf8b notepad!WinMain+0x176 00000000`001cf9f0 00000000`76dfcf1d notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 1: kd> g Breakpoint 0 hit USER32!GetMessageW: 0033:00000000`76f1e6c0 fff3 push rbx 0: kd> k Child-SP RetAddr Call Site 00000000`0610f8a8 000007fe`f4d39e9a USER32!GetMessageW 00000000`0610f8b0 00000000`00000000 0x000007fe`f4d39e9a 0: kd> ~1s 1: kd> k Child-SP RetAddr Call Site fffff980`174f5960 fffff800`01a8ea7a nt!ObReferenceObjectByHandle+0x1b4 fffff980`174f59e0 fffff800`01a9bb01 nt!ObpLookupObjectName+0xfa fffff980`174f5af0 fffff800`01ab00d6 nt!ObOpenObjectByName+0x421 fffff980`174f5bc0 fffff800`0184d5f3 nt!NtOpenSection+0x66 fffff980`174f5c20 00000000`770205ea nt!KiSystemServiceCopyEnd+0x13 00000000`0012e7d8 00000000`77004fc3 ntdll!ZwOpenSection+0xa 00000000`0012e7e0 00000000`77002fa1 ntdll!LdrpCheckForKnownDll+0x1c3 00000000`0012e8b0 00000000`77002dc3 ntdll!LdrpMapDll+0x17d 00000000`0012ea90 00000000`7700208f ntdll!LdrpLoadDll+0x559 00000000`0012eda0 00000000`76de831e ntdll!LdrLoadDll+0x133 00000000`0012f090 00000000`100063c1 kernel32!LoadLibraryExW+0x12a 00000000`0012f120 00000000`00000000 0x100063c1 1: kd> ~0s Breakpoint 0 hit 0: kd> k Child-SP RetAddr Call Site 00000000`0610f8a8 000007fe`f4d39e9a USER32!GetMessageW 00000000`0610f8b0 00000000`00000000 0x000007fe`f4d39e9a 0: kd> !thread THREAD fffffa8003e0e060 Cid 06c0.0948 Teb: 000007fffffa8000 Win32Thread: fffff900c07ecd60 RUNNING on processor 0 Not impersonating DeviceMap fffff88001b2add0 Owning Process fffffa8003bfcb30 Image: explorer.exe Attached Process N/A Image: N/A Wait Start TickCount 6838 Ticks: 0 Context Switch Count 403 IdealProcessor: 0 LargeStack UserTime 00:00:00.015 KernelTime 00:00:00.046 Win32 Start Address SHLWAPI!WrapperThreadProc (0x000007fefdc14f20) Stack Init fffff98016d54db0 Current fffff98016d54790 Base fffff98016d55000 Limit fffff98016d4d000 Call 0 Priority 10 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr : Args to Child : Call Site 00000000`0610f8a8 000007fe`f4d39e9a : 00000000`00000000 00000000`00000001 000007fe`f4d3cabc 00000000`00000104 : USER32!GetMessageW 00000000`0610f8b0 00000000`00000000 : 00000000`00000001 000007fe`f4d3cabc 00000000`00000104 ffffffff`fffffffe : 0x000007fe`f4d39e9a 0: kd> .thread /r /p fffffa8003e0e060 Implicit thread is now fffffa80`03e0e060 Implicit process is now fffffa80`03bfcb30 .cache forcedecodeuser done Loading User Symbols ................................................................ ............................................................ 0: kd> k *** Stack trace for last set context - .thread/.cxr resets it Child-SP RetAddr Call Site 00000000`0610f8a8 000007fe`f4d39e9a USER32!GetMessageW 00000000`0610f8b0 000007fe`fdc14d48 wpdshserviceobj!CWPDShServiceObj::_SvcObjThreadProc+0x33e 00000000`0610fda0 00000000`76dfcf1d SHLWAPI!WrapperThreadProc+0xfc 00000000`0610fe80 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`0610feb0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 0: kd> bc 0 0: kd> bl 0: kd> g Break instruction exception - code 80000003 (first chance) ******************************************************************************* * * * You are seeing this message because you pressed either * * CTRL+C (if you run console kernel debugger) or, * * CTRL+BREAK (if you run GUI kernel debugger), * * on your debugger machine's keyboard. * * * * THIS IS NOT A BUG OR A SYSTEM CRASH * * * * If you did not intend to break into the debugger, press the "g" key, then * * press the "Enter" key now. This message might immediately reappear. If it * * does, press "g" and "Enter" again. * * * ******************************************************************************* nt!RtlpBreakWithStatusInstruction: fffff800`018472a0 cc int 3 1: kd> !process fffffa8003a74bb0 3f PROCESS fffffa8003a74bb0 SessionId: 1 Cid: 08e4 Peb: 7fffffdf000 ParentCid: 06c0 DirBase: 21976000 ObjectTable: fffff88002312740 HandleCount: 48. Image: notepad.exe VadRoot fffffa8003fe3b70 Vads 54 Clone 0 Private 276. Modified 15. Locked 0. DeviceMap fffff88001b2add0 Token fffff88002331ab0 ElapsedTime 00:00:45.886 UserTime 00:00:00.000 KernelTime 00:00:00.000 QuotaPoolUsage[PagedPool] 125592 QuotaPoolUsage[NonPagedPool] 5088 Working Set Sizes (now,min,max) (1054, 50, 345) (4216KB, 200KB, 1380KB) PeakWorkingSetSize 1054 VirtualSize 62 Mb PeakVirtualSize 62 Mb PageFaultCount 1079 MemoryPriority BACKGROUND BasePriority 8 CommitCharge 427 DebugPort fffffa8003e867b0 PEB at 000007fffffdf000 InheritedAddressSpace: No ReadImageFileExecOptions: No BeingDebugged: Yes ImageBaseAddress: 00000000ff2c0000 Ldr 00000000770df980 Ldr.Initialized: Yes Ldr.InInitializationOrderModuleList: 00000000002424a0 . 000000000026a380 Ldr.InLoadOrderModuleList: 00000000002423b0 . 000000000026a360 Ldr.InMemoryOrderModuleList: 00000000002423c0 . 000000000026a370 Base TimeStamp Module ff2c0000 4549bb19 Nov 02 09:32:09 2006 C:\Windows\System32\notepad.exe 76fd0000 4549d372 Nov 02 11:16:02 2006 C:\Windows\system32\ntdll.dll 76dc0000 4995251a Feb 13 07:45:30 2009 C:\Windows\system32\kernel32.dll 7feff1d0000 4549d267 Nov 02 11:11:35 2006 C:\Windows\system32\ADVAPI32.dll 7fefd7c0000 49f0690c Apr 23 14:11:40 2009 C:\Windows\system32\RPCRT4.dll 7fefdb90000 48fd6901 Oct 21 06:30:41 2008 C:\Windows\system32\GDI32.dll 76f00000 45d3ee19 Feb 15 05:22:33 2007 C:\Windows\system32\USER32.dll 7fefe030000 4549d2e1 Nov 02 11:13:37 2006 C:\Windows\system32\msvcrt.dll 7fefd730000 4549d32b Nov 02 11:14:51 2006 C:\Windows\system32\COMDLG32.dll 7fefdc00000 4549d31f Nov 02 11:14:39 2006 C:\Windows\system32\SHLWAPI.dll 7fefc040000 4549d32b Nov 02 11:14:51 2006 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_1559f1c6f365a7fa\COMCTL32.dll 7fefe480000 4912ef34 Nov 06 13:20:52 2008 C:\Windows\system32\SHELL32.dll 7fefa8b0000 4549d37c Nov 02 11:16:12 2006 C:\Windows\System32\WINSPOOL.DRV 7fefdc80000 4549d317 Nov 02 11:14:31 2006 C:\Windows\system32\ole32.dll 7fefe230000 4757840f Dec 06 05:09:35 2007 C:\Windows\system32\OLEAUT32.dll 7fefe1e0000 4549d2cb Nov 02 11:13:15 2006 C:\Windows\system32\IMM32.DLL 7fefe310000 4549d2e6 Nov 02 11:13:42 2006 C:\Windows\system32\MSCTF.dll 7fefe420000 4adc79bc Oct 19 15:37:48 2009 C:\Windows\system32\LPK.DLL 7fefdae0000 4549d337 Nov 02 11:15:03 2006 C:\Windows\system32\USP10.dll 7fefc3c0000 4549d33b Nov 02 11:15:07 2006 C:\Windows\System32\UxTheme.dll SubSystemData: 0000000000000000 ProcessHeap: 0000000000240000 ProcessParameters: 0000000000241b40 CurrentDirectory: 'C:\Users\Training\' WindowTitle: 'C:\Users\Training\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk' ImageFile: 'C:\Windows\System32\notepad.exe' CommandLine: '"C:\Windows\System32\notepad.exe" ' DllPath: 'C:\Windows\System32;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem' Environment: 0000000000241310 =::=::\ ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Training\AppData\Roaming CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files COMPUTERNAME=LH-ZH5VMPAL2053 ComSpec=C:\Windows\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Training LOCALAPPDATA=C:\Users\Training\AppData\Local LOGONSERVER=\\LH-ZH5VMPAL2053 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=EM64T Family 6 Model 42 Stepping 7, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=2a07 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) PUBLIC=C:\Users\Public SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\Training\AppData\Local\Temp TMP=C:\Users\Training\AppData\Local\Temp USERDOMAIN=LH-ZH5VMPAL2053 USERNAME=Training USERPROFILE=C:\Users\Training windir=C:\Windows THREAD fffffa8002a86060 Cid 08e4.0904 Teb: 000007fffffdd000 Win32Thread: fffff900c1cd9a60 WAIT: (Suspended) KernelMode Non-Alertable SuspendCount 1 FreezeCount 1 fffffa8002a86310 Semaphore Limit 0x2 Not impersonating DeviceMap fffff88001b2add0 Owning Process fffffa8003a74bb0 Image: notepad.exe Attached Process N/A Image: N/A Wait Start TickCount 8408 Ticks: 740 (0:00:00:11.544) Context Switch Count 365 IdealProcessor: 1 LargeStack UserTime 00:00:00.000 KernelTime 00:00:00.140 Win32 Start Address notepad!WinMainCRTStartup (0x00000000ff2cd134) Stack Init fffff98017d1ddb0 Current fffff98017d1d580 Base fffff98017d1e000 Limit fffff98017d15000 Call 0 Priority 10 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`17d1d5c0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`17d1d700 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`17d1d760 fffff800`01831639 nt!KeWaitForSingleObject+0x5f5 fffff980`17d1d7e0 fffff800`01845efe nt!KiSuspendThread+0x29 fffff980`17d1d820 fffff800`0185d227 nt!KiDeliverApc+0x29e fffff980`17d1d8c0 fffff800`0185cc9d nt!KiSwapThread+0x3f7 fffff980`17d1d920 fffff960`000c98e8 nt!KeWaitForSingleObject+0x5f5 fffff980`17d1d9a0 fffff960`000c9976 win32k!xxxRealSleepThread+0x278 fffff980`17d1da40 fffff960`000c80de win32k!xxxSleepThread+0x56 fffff980`17d1da70 fffff960`000c81e5 win32k!xxxRealInternalGetMessage+0x72e fffff980`17d1db50 fffff960`000c9a94 win32k!xxxInternalGetMessage+0x35 fffff980`17d1db90 fffff800`0184d5f3 win32k!NtUserGetMessage+0x64 fffff980`17d1dc20 00000000`76f1e6aa nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff980`17d1dc20) 00000000`001cf938 00000000`76f1e6ea USER32!NtUserGetMessage+0xa 00000000`001cf940 00000000`ff2c6eca USER32!GetMessageW+0x34 00000000`001cf970 00000000`ff2ccf8b notepad!WinMain+0x176 00000000`001cf9f0 00000000`76dfcf1d notepad!IsTextUTF8+0x24f 00000000`001cfab0 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`001cfae0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d THREAD fffffa8002cd14d0 Cid 08e4.011c Teb: 000007fffffdb000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable SuspendCount 1 fffff9801512d130 SynchronizationEvent Not impersonating DeviceMap fffff88001b2add0 Owning Process fffffa8003a74bb0 Image: notepad.exe Attached Process N/A Image: N/A Wait Start TickCount 8408 Ticks: 740 (0:00:00:11.544) Context Switch Count 9 IdealProcessor: 0 UserTime 00:00:00.000 KernelTime 00:00:00.000 Win32 Start Address ntdll!DbgUiRemoteBreakin (0x00000000770b33b0) Stack Init fffff9801512ddb0 Current fffff9801512ce90 Base fffff9801512e000 Limit fffff98015128000 Call 0 Priority 10 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5 Child-SP RetAddr Call Site fffff980`1512ced0 fffff800`0185cf55 nt!KiSwapContext+0x84 fffff980`1512d010 fffff800`0185cc9d nt!KiSwapThread+0x125 fffff980`1512d070 fffff800`01b43278 nt!KeWaitForSingleObject+0x5f5 fffff980`1512d0f0 fffff800`01b43ecc nt!DbgkpQueueMessage+0x2a8 fffff980`1512d2c0 fffff800`01afd9be nt!DbgkpSendApiMessage+0x5c fffff980`1512d300 fffff800`01832305 nt! ?? ::NNGAKEGL::`string'+0x23eef fffff980`1512d440 fffff800`0184d9ae nt!KiDispatchException+0x1f5 fffff980`1512da40 fffff800`0184bc77 nt!KiExceptionDispatch+0xae fffff980`1512dc20 00000000`7701fdf1 nt!KiBreakpointTrap+0xb7 (TrapFrame @ fffff980`1512dc20) 00000000`01f5fc58 00000000`770b33e8 ntdll!DbgBreakPoint+0x1 00000000`01f5fc60 00000000`76dfcf1d ntdll!DbgUiRemoteBreakin+0x38 00000000`01f5fc90 00000000`7701c6e1 kernel32!BaseThreadInitThunk+0xd 00000000`01f5fcc0 00000000`00000000 ntdll!RtlUserThreadStart+0x1d 1: kd> ba e 1 nt!KiExceptionDispatch 1: kd> bl 0 e fffff800`0184d900 e 1 0001 (0001) nt!KiExceptionDispatch 1: kd> g *** Fatal System Error: 0x0000007f (0x0000000000000008,0x0000000080050031,0x00000000000006F8,0xFFFFF8000184B754) Break instruction exception - code 80000003 (first chance) A fatal system error has occurred. Debugger entered on first try; Bugcheck callbacks have not been invoked. A fatal system error has occurred. Connected to Windows Vista 6000 x64 target at (Mon May 6 19:52:37.869 2013 (UTC + 1:00)), ptr64 TRUE Loading Kernel Symbols ............................................................... ................................................................ .......... Loading User Symbols Loading unloaded module list ...Unable to enumerate user-mode unloaded modules, Win32 error 0n30 ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 7F, {8, 80050031, 6f8, fffff8000184b754} Probably caused by : ntkrnlmp.exe ( nt!KiDoubleFaultAbort+b8 ) Followup: MachineOwner --------- nt!RtlpBreakWithStatusInstruction: fffff800`018472a0 cc int 3 1: kd> k Child-SP RetAddr Call Site fffff980`00a9e288 fffff800`018e54c2 nt!RtlpBreakWithStatusInstruction fffff980`00a9e290 fffff800`018e778e nt!KiBugCheckDebugBreak+0x12 fffff980`00a9e2f0 fffff800`0184dc54 nt!KeBugCheck2+0x5ee fffff980`00a9e930 fffff800`0184d8f3 nt!KeBugCheckEx+0x104 fffff980`00a9e970 fffff800`0184c138 nt!KiBugCheckDispatch+0x73 fffff980`00a9eab0 fffff800`0184b754 nt!KiDoubleFaultAbort+0xb8 fffff980`00cc8f80 fffff800`0184d900 nt!KiDebugTrapOrFault+0x14 fffff980`00cc9118 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9120 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc92b8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc92c0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9458 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9460 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc95f8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9600 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9798 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc97a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9938 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9940 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9ad8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9ae0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9c78 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9c80 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9e18 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9e20 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cc9fb8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cc9fc0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca158 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca160 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca2f8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca300 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca498 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca4a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca638 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca640 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca7d8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca7e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cca978 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cca980 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccab18 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccab20 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccacb8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccacc0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccae58 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccae60 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccaff8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb000 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb198 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb1a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb338 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb340 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb4d8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb4e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb678 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb680 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb818 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb820 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccb9b8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccb9c0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccbb58 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccbb60 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccbcf8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccbd00 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccbe98 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccbea0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc038 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc040 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc1d8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc1e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc378 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc380 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc518 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc520 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc6b8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc6c0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc858 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccc860 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccc9f8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccca00 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cccb98 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cccba0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cccd38 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cccd40 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccced8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cccee0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd078 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd080 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd218 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd220 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd3b8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd3c0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd558 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd560 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd6f8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd700 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccd898 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccd8a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccda38 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccda40 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccdbd8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccdbe0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccdd78 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccdd80 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccdf18 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00ccdf20 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce0b8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce0c0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce258 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce260 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce3f8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce400 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce598 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce5a0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce738 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce740 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00cce8d8 fffff800`0184b871 nt!KiExceptionDispatch fffff980`00cce8e0 fffff800`0184d900 nt!KiDebugTrapOrFault+0x131 fffff980`00ccea78 fffff800`0184bec3 nt!KiExceptionDispatch fffff980`00ccea80 fffff980`12e6910b nt!KiInvalidOpcodeFault+0xc3 *** ERROR: Symbol file could not be found. Defaulted to export symbols for spsys.sys - fffff980`00ccec10 fffff980`12e69415 spsys!SPVersion+0x237db fffff980`00ccec50 fffff980`12e74e6c spsys!SPVersion+0x23ae5 fffff980`00ccec90 fffff800`01859ca3 spsys!SPVersion+0x2f53c fffff980`00ccece0 fffff800`01ae1bbb nt!ExpWorkerThread+0x12a fffff980`00cced50 fffff800`018344f6 nt!PspSystemThreadStartup+0x5b fffff980`00cced80 00000000`00000000 nt!KxStartSystemThread+0x16