Stuck - Please help - Windows 7 x64 debugging RRS feed

  • Question

  • I have a handful of computers that keep crashing, the debugging is all the same except the app changes excel, word, and outlook. I need help determining the issue and finding a resolution.


    Symbol search path is: C:\websymbols
    Executable search path is: 
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7601.18113.amd64fre.win7sp1_gdr.130318-1533
    Machine Name:
    Kernel base = 0xfffff800`02c4b000 PsLoadedModuleList = 0xfffff800`02e8e670
    Debug session time: Thu Oct 17 09:39:39.382 2013 (UTC - 7:00)
    System Uptime: 0 days 1:23:02.726
    Loading Kernel Symbols
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 00000000`7efdf018).  Type ".hh dbgerr001" for details
    Loading unloaded module list
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *

    Use !analyze -v to get detailed debugging information.

    BugCheck F4, {3, fffffa800b061b30, fffffa800b061e10, fffff80002fc7350}

    Probably caused by : csrss.exe

    Followup: MachineOwner

    1: kd> !analyze -v
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *

    A process or thread crucial to system operation has unexpectedly exited or been
    Several processes and threads are necessary for the operation of the
    system; when they are terminated (for any reason), the system can no
    longer function.
    Arg1: 0000000000000003, Process
    Arg2: fffffa800b061b30, Terminating object
    Arg3: fffffa800b061e10, Process image file name
    Arg4: fffff80002fc7350, Explanatory message (ascii)

    Debugging Details:


    PROCESS_OBJECT: fffffa800b061b30

    IMAGE_NAME:  csrss.exe


    MODULE_NAME: csrss

    FAULTING_MODULE: 0000000000000000 





    LAST_CONTROL_TRANSFER:  from fffff8000304ed22 to fffff80002cc0c00

    fffff880`0628a9c8 fffff800`0304ed22 : 00000000`000000f4 00000000`00000003 fffffa80`0b061b30 fffffa80`0b061e10 : nt!KeBugCheckEx
    fffff880`0628a9d0 fffff800`02ffb08b : ffffffff`ffffffff fffffa80`0a5c6b50 fffffa80`0b061b30 fffffa80`07297b30 : nt!PspCatchCriticalBreak+0x92
    fffff880`0628aa10 fffff800`02f7b144 : ffffffff`ffffffff 00000000`00000001 fffffa80`0b061b30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17486
    fffff880`0628aa60 fffff800`02cbfe93 : fffffa80`0b061b30 00000000`00000000 fffffa80`0a5c6b50 fffffa80`0b061b30 : nt!NtTerminateProcess+0xf4
    fffff880`0628aae0 00000000`76d715da : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`06cde7a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76d715da


    FOLLOWUP_NAME:  MachineOwner


    BUCKET_ID:  X64_0xF4_EXCEL.EXE_IMAGE_csrss.exe

    Followup: MachineOwner

    1: kd> !process fffffa800b061b30 3
    PROCESS fffffa800b061b30
        SessionId: 1  Cid: 02b0    Peb: 7fffffd9000  ParentCid: 02a4
        DirBase: 1cade4000  ObjectTable: fffff8a000d814b0  HandleCount: 799.
        Image: csrss.exe
        VadRoot fffffa800a5c36b0 Vads 167 Clone 0 Private 719. Modified 37305. Locked 13076.
        DeviceMap fffff8a000008e00
        Token                             fffff8a000cac060
        ElapsedTime                       01:22:48.577
        UserTime                          00:00:00.000
        KernelTime                        00:00:00.031
        QuotaPoolUsage[PagedPool]         343632
        QuotaPoolUsage[NonPagedPool]      25712
        Working Set Sizes (now,min,max)  (16100, 50, 345) (64400KB, 200KB, 1380KB)
        PeakWorkingSetSize                19413
        VirtualSize                       138 Mb
        PeakVirtualSize                   281 Mb
        PageFaultCount                    66394
        MemoryPriority                    BACKGROUND
        BasePriority                      13
        CommitCharge                      1145

            THREAD fffffa800b0ba3d0  Cid 02b0.02cc  Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable
                fffffa800b0ec2d0  SynchronizationEvent

            THREAD fffffa800b108b50  Cid 02b0.02d0  Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable
                fffffa800b0f7c10  SynchronizationEvent
                fffffa800b0e5810  SynchronizationEvent
                fffffa800b0ec1e0  SynchronizationEvent
                fffffa800b0e4770  SynchronizationEvent

            THREAD fffffa800b0b31d0  Cid 02b0.02d4  Teb: 000007fffffdc000 Win32Thread: fffff900c22f4c20 WAIT: (WrLpcReply) UserMode Non-Alertable
                fffffa800b0b3598  Semaphore Limit 0x1

            THREAD fffffa800bb8c060  Cid 02b0.02d8  Teb: 000007fffffda000 Win32Thread: fffff900c22f2c20 WAIT: (UserRequest) UserMode Alertable
                fffffa800b0de500  SynchronizationEvent
                fffffa800b0ddc60  SynchronizationEvent
                fffffa800b0de580  SynchronizationEvent
                fffffa800b0e1540  SynchronizationEvent

            THREAD fffffa800bb98b50  Cid 02b0.02dc  Teb: 000007fffffd7000 Win32Thread: fffff900c00fa420 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa800bb98f18  Semaphore Limit 0x1

            THREAD fffffa800bb92b50  Cid 02b0.02e0  Teb: 000007fffffd5000 Win32Thread: 0000000000000000 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa800bb92f18  Semaphore Limit 0x1

            THREAD fffffa800b066b50  Cid 02b0.02ec  Teb: 000007fffffde000 Win32Thread: fffff900c22f6c20 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa800b066f18  Semaphore Limit 0x1

            THREAD fffffa800b0cc060  Cid 02b0.02f8  Teb: 000007fffffd3000 Win32Thread: fffff900c01c9010 WAIT: (WrUserRequest) KernelMode Alertable
                fffffa800a262a90  SynchronizationEvent
                fffffa800b0b3aa0  NotificationTimer
                fffffa800b0d2fc0  SynchronizationTimer
                fffffa80066dcc80  SynchronizationEvent

            THREAD fffffa800a261530  Cid 02b0.02fc  Teb: 000007fffffae000 Win32Thread: fffff900c01c9c00 WAIT: (WrUserRequest) UserMode Non-Alertable
                fffffa800b0d6980  SynchronizationEvent
                fffffa8007654f60  SynchronizationEvent

            THREAD fffffa800bf447e0  Cid 02b0.05ec  Teb: 000007fffffac000 Win32Thread: fffff900c1d716e0 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa800bf44ba8  Semaphore Limit 0x1

            THREAD fffffa8006b0db50  Cid 02b0.08e8  Teb: 000007fffffaa000 Win32Thread: fffff900c01638f0 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa8006b0df18  Semaphore Limit 0x1

            THREAD fffffa8007153920  Cid 02b0.0758  Teb: 000007fffffa8000 Win32Thread: fffff900c1fa6c20 WAIT: (WrLpcReceive) UserMode Non-Alertable
                fffffa8007153ce8  Semaphore Limit 0x1

            THREAD fffffa8006edcb50  Cid 02b0.12c4  Teb: 000007fffffa6000 Win32Thread: fffff900c20e8c20 WAIT: (WrUserRequest) UserMode Non-Alertable
                fffffa800bdf53f0  SynchronizationEvent

    1: kd> lmvm csrss
    start             end                 module name

    Tuesday, October 22, 2013 12:54 AM


All replies

  • post some details about your hardware. Do you use Crucial M4 SSDs? They have a firmware bug which cause of 0xF4 bugchecks.

    If you have such a SSD, make a firmware update

    "A programmer is just a tool which converts caffeine into code"

    • Marked as answer by 暁北 Wednesday, November 6, 2013 3:13 AM
    Tuesday, October 22, 2013 5:28 AM
  • It actually does have a hybrid SSD - ill try the firmware update on them and see if that helps, the hardware is listed below.

    Computer Model             OptiPlex 7010

    BIOS Vendor      Dell Inc.

    BIOS Version      DELL - 1072009

    BIOS Date            3/25/2013

    Window Version              Microsoft Windows 7 Professional


    Manufacture     Intel(R) Core(TM) i5-3570 CPU @ 3.40GHz

    Clock Speed       3.4Ghz

    L2 Cache Size     1024


    Available Memory           72.26 %

    Page File Size     8,110.5MB

    Available Page File           100.00 %

    Virtual Memory                16,219.1MB

    Available Virtual Memory             85.13 %

    ChannelA-DIMM1           4,096.0MB

    ChannelB-DIMM1            4,096.0MB

     Network Card


    Type      Description

    DVD/CD-ROM Drives      HL-DT-ST DVD+-RW GT80N

    Disk Drives          ST500LM000-1EJ162

    Display Adapters              Intel(R) HD Graphics

    IDE ATA/ATAPI Controllers          Intel(R) 7 Series/C216 Chipset Family SATA AHCI Controller

    Keyboards,Mice and Other Pointing Devices       USB Input Device (Logitech Download Assistant)

    USB Input Device

    HID-compliant mouse

    Monitors             Generic PnP Monitor

    Sound Devices  Realtek High Definition Audio

    Intel(R) Display Audio

    USB Controllers                Intel(R) USB 3.0 eXtensible Host Controller

    Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E26

    Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E2D

    Tuesday, October 22, 2013 4:34 PM
    • Marked as answer by 暁北 Wednesday, November 6, 2013 3:13 AM
    Wednesday, November 6, 2013 3:12 AM