Share via

CriticalProcessDied.Process help

Anonymous
2024-03-13T01:39:39+00:00

help ı get this problem

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true

   EnableRedirectToV8JsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.125 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 41

Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\MrSwat\AppData\Local\Temp\Rar$DRa3400.35916.rartemp\031324-20421-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 19041 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff803`27e00000 PsLoadedModuleList = 0xfffff803`28a2a750
Debug session time: Wed Mar 13 04:12:39.478 2024 (UTC + 3:00)
System Uptime: 0 days 9:02:49.101
Loading Kernel Symbols
...............................................................
................................................................
.....................................................
Loading User Symbols
..Unable to read LDR_DATA_TABLE_ENTRY at 00000237`eb604190 - Win32 error 0n30

Loading unloaded module list
............
WARNING: .reload failed, module list may be incomplete
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff803`281fd3a0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffb00e`f23a9d90=00000000000000ef
1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_PROCESS_DIED (ef)
        A critical system process died
Arguments:
Arg1: ffffb1080c157280, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000, The process object that initiated the termination.
Arg4: 0000000000000000

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 3593

    Key  : Analysis.Elapsed.mSec
    Value: 17627

    Key  : Analysis.IO.Other.Mb
    Value: 20

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 22

    Key  : Analysis.Init.CPU.mSec
    Value: 608

    Key  : Analysis.Init.Elapsed.mSec
    Value: 72824

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 97

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xef

    Key  : Bugcheck.Code.TargetModel
    Value: 0xef

    Key  : CriticalProcessDied.ExceptionCode
    Value: 15ee3080

    Key  : CriticalProcessDied.Process
    Value: svchost.exe

    Key  : Failure.Bucket
    Value: 0xEF_svchost.exe_DcomLaunch_BUGCHECK_CRITICAL_PROCESS_15ee3080_ntdll!RtlDispatchException

    Key  : Failure.Hash
    Value: {25febdc8-aa78-1e19-4777-2cd2fe555b9f}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1

BUGCHECK_CODE:  ef

BUGCHECK_P1: ffffb1080c157280

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

FILE_IN_CAB:  031324-20421-01.dmp

PROCESS_NAME:  svchost.exe

CRITICAL_PROCESS:  svchost.exe

EXCEPTION_RECORD:  0000000000001000 -- (.exr 0x1000)
Cannot read Exception record @ 0000000000001000

ERROR_CODE: (NTSTATUS) 0x15ee3080 - <Unable to get error code text>

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

TRAP_FRAME:  ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000

STACK_TEXT:  
ffffb00e`f23a9d88 fffff803`2870c3c2     : 00000000`000000ef ffffb108`0c157280 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffb00e`f23a9d90 fffff803`28617efb     : 00000000`00000001 fffff803`280b8b31 00000000`00000002 fffff803`280b8a5b : nt!PspCatchCriticalBreak+0x10e
ffffb00e`f23a9e30 fffff803`28481f70     : ffffb108`00000000 00000000`00000000 ffffb108`0c157280 ffffb108`0c1576b8 : nt!PspTerminateAllThreads+0x17614f
ffffb00e`f23a9ea0 fffff803`28481d6c     : ffffb108`0c157280 00000000`00000001 ffffffff`ffffffff 00000000`00000000 : nt!PspTerminateProcess+0xe0
ffffb00e`f23a9ee0 fffff803`28210f38     : ffffb108`0c157280 ffffb108`15ee3080 ffffb00e`f23a9fd0 fffff803`28531162 : nt!NtTerminateProcess+0x9c
ffffb00e`f23a9f50 fffff803`28202080     : fffff803`2827a4f5 ffffb00e`f23aaa58 ffffb00e`f23aaa58 ffffffff`ffffffff : nt!KiSystemServiceCopyEnd+0x28
ffffb00e`f23aa0e8 fffff803`2827a4f5     : ffffb00e`f23aaa58 ffffb00e`f23aaa58 ffffffff`ffffffff 00007ffa`e3fcae94 : nt!KiServiceLinkage
ffffb00e`f23aa0f0 fffff803`282118ec     : 00000000`00001000 ffffb00e`f23aab00 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x141265
ffffb00e`f23aa920 fffff803`2820d23d     : 00007ffa`e3f03d69 ffffb108`0c14fce0 ffffb00e`f23aab80 00000000`000032e4 : nt!KiExceptionDispatch+0x12c
ffffb00e`f23aab00 00007ffa`e88c12b5     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x43d
000000bf`5cd80fb0 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlDispatchException+0x45

SYMBOL_NAME:  ntdll!RtlDispatchException+45

MODULE_NAME: ntdll

IMAGE_NAME:  ntdll.dll

IMAGE_VERSION:  10.0.19041.1006

STACK_COMMAND:  .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET:  45

FAILURE_BUCKET_ID:  0xEF_svchost.exe_DcomLaunch_BUGCHECK_CRITICAL_PROCESS_15ee3080_ntdll!RtlDispatchException

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {25febdc8-aa78-1e19-4777-2cd2fe555b9f}

Followup:     MachineOwner
---------

NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'
Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Sakiko 39,240 Reputation points Independent Advisor
    2024-03-14T04:29:14+00:00

    I'm sorry, I don't quite understand what you mean.

    Can you repeat it?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-03-13T19:15:52+00:00

    The information you have provided indicates a problem with the system kernel, usually caused by a driver, which we need to verify further. Please first create a restore point for your system, then please refer to this article: https://learn.microsoft.com/en-us/windows-hardw... to validate the driver. In the third step select "Automatically select all drivers installed on this computer", wait for a couple of new blue screens and then collect 2-3 copies of the dump file and share the new dump file with me.
    If the computer has any automatic overclocking features enabled (including XMP, PBO, etc.) or manual overclocking, please restore the defaults first.

    Driver verification puts heavy pressure on the drivers in your system to troubleshoot drivers that are in poor condition or misbehaving. It is normal for your computer to run slowly after driver validation is turned on. The computer will also crash more frequently and generate dump files during this process.
    If your system fails to boot after driver verification is turned on, restore the state via a restore point.

    hello insta closing my computer ı do that driver verifier and closeing ı cant do anything

    Was this answer helpful?

    0 comments No comments
  3. Sakiko 39,240 Reputation points Independent Advisor
    2024-03-13T08:06:38+00:00

    The information you have provided indicates a problem with the system kernel, usually caused by a driver, which we need to verify further. Please first create a restore point for your system, then please refer to this article: https://learn.microsoft.com/en-us/windows-hardw... to validate the driver. In the third step select "Automatically select all drivers installed on this computer", wait for a couple of new blue screens and then collect 2-3 copies of the dump file and share the new dump file with me.

    If the computer has any automatic overclocking features enabled (including XMP, PBO, etc.) or manual overclocking, please restore the defaults first.

    Driver verification puts heavy pressure on the drivers in your system to troubleshoot drivers that are in poor condition or misbehaving. It is normal for your computer to run slowly after driver validation is turned on. The computer will also crash more frequently and generate dump files during this process.

    If your system fails to boot after driver verification is turned on, restore the state via a restore point.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-03-13T06:17:55+00:00

    Hello, I'm here to help.

    I may need you to provide the dump file to help you analyze the failure. Please see if there is a. DMP file in your system directory "C:\Windows\Minidump". If there is, please upload it to a cloud drive such as OneDrive, Dropbox, Google Drive and share the link here, I will help you analyze it.

    Disclaimer: The dump file may contain some information about you, such as system environment, software used, etc. This is a public community and can be viewed by anyone, so please remove the share as soon as possible after I answer. Please do not provide the file named "MEORY.DMP", which contains almost all information about your system at runtime.

    https://drive.google.com/file/d/14z-848WI0dOl-naMsGnZ-6aW4mYtAdfA/view?usp=drive_link

    Was this answer helpful?

    0 comments No comments
  5. Sakiko 39,240 Reputation points Independent Advisor
    2024-03-13T04:43:11+00:00

    Hello, I'm here to help.

    I may need you to provide the dump file to help you analyze the failure. Please see if there is a. DMP file in your system directory "C:\Windows\Minidump". If there is, please upload it to a cloud drive such as OneDrive, Dropbox, Google Drive and share the link here, I will help you analyze it.

    Disclaimer: The dump file may contain some information about you, such as system environment, software used, etc. This is a public community and can be viewed by anyone, so please remove the share as soon as possible after I answer. Please do not provide the file named "MEORY.DMP", which contains almost all information about your system at runtime.

    Was this answer helpful?

    0 comments No comments