*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffffb18fc56090c0, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3311
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 7631
Key : Analysis.Init.CPU.mSec
Value: 765
Key : Analysis.Init.Elapsed.mSec
Value: 20952
Key : Analysis.Memory.CommitPeak.Mb
Value: 75
Key : CriticalProcessDied.ExceptionCode
Value: c78830c0
Key : CriticalProcessDied.ImageName
Value: services.exe
Key : CriticalProcessDied.ImageOffset
Value: 6048c
Key : CriticalProcessDied.ImageSize
Value: b0000
Key : CriticalProcessDied.ImageTimestamp
Value: a9fb6bc9
Key : CriticalProcessDied.Process
Value: services.exe
Key : CriticalProcessDied.Symbol
Value: services.exe!?QueueRecoveryAction@CWin32ServiceRecord@@QEAAXW4SERVICE_FAILURE_REASON@@@Z
Key : CriticalProcessDied.WERReportId
Value: 3c829606-6f77-4e74-b78c-93cba9a9faa0
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: ef
BUGCHECK_P1: ffffb18fc56090c0
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: services.exe
CRITICAL_PROCESS: services.exe
ERROR_CODE: (NTSTATUS) 0xc78830c0 - <Unable to get error code text>
CRITICAL_PROCESS_REPORTGUID: {3c829606-6f77-4e74-b78c-93cba9a9faa0}
IMAGE_NAME: services.exe
MODULE_NAME: services
FAULTING_MODULE: 0000000000000000
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
STACK_TEXT:
ffffc48e`be0aa8f8 fffff801`30907c22 : 00000000`000000ef ffffb18f`c56090c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffc48e`be0aa900 fffff801`3080ea17 : 00000000`00000000 fffff801`302fd7cd 00000000`00000002 fffff801`302fcde7 : nt!PspCatchCriticalBreak+0x10e
ffffc48e`be0aa9a0 fffff801`306b3dd4 : ffffb18f`00000000 00000000`00000000 ffffb18f`c56090c0 ffffb18f`c56094f8 : nt!PspTerminateAllThreads+0x15b37b
ffffc48e`be0aaa10 fffff801`306b40fc : ffffb18f`c56090c0 00000000`00000000 00000000`0074fc6c fffff801`30600daa : nt!PspTerminateProcess+0xe0
ffffc48e`be0aaa50 fffff801`30408ab5 : ffffb18f`c56090c0 ffffb18f`c78830c0 ffffc48e`be0aab40 ffffb18f`c56090c0 : nt!NtTerminateProcess+0x9c
ffffc48e`be0aaac0 00007fff`44c6d2f4 : 00007fff`44ce2b53 00007fff`44d16708 00000000`0074fc30 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0074ea28 00007fff`44ce2b53 : 00007fff`44d16708 00000000`0074fc30 00000000`00000000 00007fff`44bd0000 : 0x00007fff`44c6d2f4
00000000`0074ea30 00007fff`44d16708 : 00000000`0074fc30 00000000`00000000 00007fff`44bd0000 00000000`00000004 : 0x00007fff`44ce2b53
00000000`0074ea38 00000000`0074fc30 : 00000000`00000000 00007fff`44bd0000 00000000`00000004 00007fff`44c752ed : 0x00007fff`44d16708
00000000`0074ea40 00000000`00000000 : 00007fff`44bd0000 00000000`00000004 00007fff`44c752ed 00007fff`44d16708 : 0x74fc30
STACK_COMMAND: .thread ; .cxr ; kb
FAILURE_BUCKET_ID: 0xEF_services.exe_BUGCHECK_CRITICAL_PROCESS_c78830c0_services.exe!?QueueRecoveryAction@CWin32Service Record@@QEAAXW4SERVICE_FAILURE_REASON@@@Z_IMAGE_services.exe
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {cdc43f7a-324c-a135-e1eb-356fbea90c0c}
Followup: MachineOwner
---------
4: kd> !process
PROCESS ffffb18fc56090c0
SessionId: 0 Cid: 03a8 Peb: 00343000 ParentCid: 0360
DirBase: 3c28d8000 ObjectTable: ffff8c0bf9b58b80 HandleCount: <Data Not Accessible>
Image: services.exe
VadRoot ffffb18fc306c8a0 Vads 117 Clone 0 Private 1249. Modified 308. Locked 2.
DeviceMap ffff8c0bf50361e0
Token ffff8c0bf9b9b770
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 155752
QuotaPoolUsage[NonPagedPool] 19408
Working Set Sizes (now,min,max) (2715, 50, 345) (10860KB, 200KB, 1380KB)
PeakWorkingSetSize 2647
VirtualSize 4189 Mb
PeakVirtualSize 4205 Mb
PageFaultCount 3861
MemoryPriority BACKGROUND
BasePriority 9
CommitCharge 1617
*** Error in reading nt!_ETHREAD @ ffffb18fc556a0c0