The computer has rebooted from a bugcheck. The bugcheck was: 0x00000027 (0x00000000fcb0027c, 0xffffa58e37d017a8, 0xffffa58e37d013e0, 0x0000000000000000).
A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 5076302f-1f7e-4832-a700-0aad33689189.
Microsoft (R) Windows Debugger Version 10.0.25200.1003 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
RDR_FILE_SYSTEM (27)
If you see RxExceptionFilter on the stack then the 2nd and 3rd parameters are the
exception record and context record. Do a .cxr on the 3rd parameter and then kb to
obtain a more informative stack trace.
The high 16 bits of the first parameter is the RDBSS BugCheck code, which is defined
as follows:
RDBSS_BUG_CHECK_CACHESUP = 0xca550000,
RDBSS_BUG_CHECK_CLEANUP = 0xc1ee0000,
RDBSS_BUG_CHECK_CLOSE = 0xc10e0000,
RDBSS_BUG_CHECK_NTEXCEPT = 0xbaad0000,
Arguments:
Arg1: 00000000fcb0027c
Arg2: ffffa58e37d017a8
Arg3: ffffa58e37d013e0
Arg4: 0000000000000000
Debugging Details:
Page 3900 not present in the dump file. Type ".hh dbgerr004" for details
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2812
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 3206
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 1999
Key : Analysis.Init.Elapsed.mSec
Value: 14293
Key : Analysis.Memory.CommitPeak.Mb
Value: 94
Key : Bugcheck.Code.DumpHeader
Value: 0x27
Key : Bugcheck.Code.KiBugCheckData
Value: 0x27
Key : Bugcheck.Code.Register
Value: 0x27
Key : WER.OS.Branch
Value: rs1\_release\_inmarket
Key : WER.OS.Timestamp
Value: 2016-11-02T01:00:00Z
Key : WER.OS.Version
Value: 10.0.14393.447
FILE_IN_CAB: MEMORY.DMP
BUGCHECK_CODE: 27
BUGCHECK_P1: fcb0027c
BUGCHECK_P2: ffffa58e37d017a8
BUGCHECK_P3: ffffa58e37d013e0
BUGCHECK_P4: 0
EXCEPTION_RECORD: ffffa58e37d017a8 -- (.exr 0xffffa58e37d017a8)
ExceptionAddress: ffffa58e37d017b8
ExceptionCode: 0130ec30
ExceptionFlags: 00000001
NumberParameters: 936384440
Parameter[0]: ffffa58e37d016b0
Parameter[1]: ffffa58e37d013e0
Parameter[2]: ffffb58bf42009d0
Parameter[3]: ffffb58b9c4da460
Parameter[4]: ffffb58b26f57130
Parameter[5]: 0000000006400200
Parameter[6]: 0000000000000000
Parameter[7]: 0000000000000000
Parameter[8]: 0000000000000000
Parameter[9]: ffffa58e37d01768
Parameter[10]: ffffa58e37d01768
Parameter[11]: ffffa58e37d01820
Parameter[12]: ffffa58e37d01820
Parameter[13]: 0000000001000000
Parameter[14]: 0000000000000000
CONTEXT: ffffa58e37d013e0 -- (.cxr 0xffffa58e37d013e0)
rax=0000000000000000 rbx=0000000000400800 rcx=0000000000000000
rdx=c040000000000003 rsi=0000000000000000 rdi=0000000000000001
rip=ffffa58e37d01738 rsp=ffffffffffffffff rbp=ffffffffffffffff
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=1c1ce15c00000000
iopl=2 vip vif nv dn di ng nz na po nc
cs=1418 ss=37d0 ds=37d0 es=a58e fs=ffff gs=1418 efl=ffffa58e
1418:1738 ?? ???
Resetting default scope
PROCESS_NAME: explorer.exe
ERROR_CODE: (NTSTATUS) 0x130ec30 - <Unable to get error code text>
EXCEPTION_CODE_STR: 130ec30
EXCEPTION_PARAMETER1: ffffa58e37d016b0
EXCEPTION_PARAMETER2: ffffa58e37d013e0
EXCEPTION_PARAMETER3: ffffb58bf42009d0
EXCEPTION_PARAMETER4: 0
EXCEPTION_STR: 0x130ec30
UNALIGNED_STACK_POINTER: ffffffffffffffff
STACK_TEXT:
ffffc680bb66e2c8 fffff80fbfb3fd19 : 0000000000000027 00000000fcb0027c ffffa58e37d017a8 ffffa58e37d013e0 : nt!KeBugCheckEx
ffffc680bb66e2d0 fffff80fbfb733b6 : ffffa58e00000000 0000000000000000 ffffb58b22112001 ffffb58b22112010 : rdbss! ?? ::FNODOBFM::string'+0x1f09 ffffc680bb66e420 fffff80fbfb3299b : ffffb58b22112010 ffffa58e37d013e0 ffffa58e37d017a8 00000000009a6000 : rdbss!RxCommonClose+0x126 ffffc680bb66e4c0 fffff80fbfb6e626 : 0000000000000000 ffffb58bf42009d0 ffffb58b2434e060 fffff803b05456be : rdbss!RxFsdCommonDispatch+0x55b ffffc680bb66e640 fffff80fc0ad1203 : ffffb58b20e32040 ffffb58b23712260 ffffb58b1c8bb680 fffff80fbe00485b : rdbss!RxFsdDispatch+0x86 ffffc680bb66e690 fffff80fbf12dc8c : ffffb58b22342090 ffffb58b22342090 0000000000000000 ffffb58bc91708b8 : rdpdr!DrPeekDispatch+0x203 ffffc680bb66e710 fffff80fbf12c64c : ffffa58e26ad68a0 ffffb58bf42009d0 ffffb58bc9170710 ffffb58b22342090 : mup!MupStateMachine+0x1dc ffffc680bb66e780 fffff80fbe003172 : ffffb58b1cc04ad0 0000000000000000 ffffb58b30ce45b0 0000000000000001 : mup!MupClose+0x8c ffffc680bb66e7e0 fffff803b091486d : ffffb58bf42009d0 0000000000000001 ffffb58bc9170710 ffffb58b1cc04ad0 : FLTMGR!FltpDispatch+0xe2 ffffc680bb66e840 fffff803b090fce8 : ffffb58bf42009a0 0000000000000000 ffffb58b1bd9b080 0000000000000000 : nt!IopDeleteFile+0x12d ffffc680bb66e8c0 fffff803b056ed56 : 0000000000000000 0000000000000000 ffffb58bf42009a0 ffffb58bf42009d0 : nt!ObpRemoveObjectRoutine+0x78 ffffc680bb66e920 fffff803b095998b : 0000000000000000 ffffb58bf4200900 ffffb58bf42009a0 ffffb58bf42009b0 : nt!ObfDereferenceObjectWithTag+0xc6 ffffc680bb66e960 fffff803b09218db : 0000000000000000 0000000000000000 00007ffa496cfcc0 00007ffa496cfca0 : nt!ObCloseHandleTableEntry+0x28b ffffc680bb66eaa0 fffff803b05dd193 : ffffb58b2260a080 0000000000000000 0000000000000000 00007ffa4a241390 : nt!NtClose+0xcb ffffc680bb66eb00 00007ffa4cc75044 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x13 0000000005a2f8a8 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffa4cc75044
SYMBOL_NAME: rdbss! ?? ::FNODOBFM::`string'+1f09
MODULE_NAME: rdbss
IMAGE_NAME: rdbss.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 1f09
FAILURE_BUCKET_ID: 0x27_rdbss!_??_::FNODOBFM::_string_
OS_VERSION: 10.0.14393.447
BUILDLAB_STR: rs1_release_inmarket
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {739462db-bb60-7004-0eb3-bb18b98df0d6}
Followup: MachineOwner