Skip to content

Instantly share code, notes, and snippets.

@chenshaoju
Created November 19, 2018 07:20
Show Gist options
  • Save chenshaoju/e1853e7f61827ee7bcfc6caae9f56090 to your computer and use it in GitHub Desktop.
Save chenshaoju/e1853e7f61827ee7bcfc6caae9f56090 to your computer and use it in GitHub Desktop.
Windows 10 1809 BSOD Dump Analysis (2)
Microsoft (R) Windows Debugger Version 10.0.17134.12 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\ShareFiles\111918-10078-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred SRV*D:\symbols\*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*D:\symbols\*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 10 Kernel Version 17763 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Machine Name:
Kernel base = 0xfffff804`0c4a8000 PsLoadedModuleList = 0xfffff804`0c8c7990
Debug session time: Mon Nov 19 12:13:03.802 2018 (UTC + 8:00)
System Uptime: 0 days 13:55:01.337
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 9F, {4, 12c, ffffd10b73b8d040, fffff98295237a40}
Implicit thread is now ffffd10b`73b8d040
Probably caused by : ntkrnlmp.exe ( nt!PnpBugcheckPowerTimeout+8a )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000004, The power transition timed out waiting to synchronize with the Pnp
subsystem.
Arg2: 000000000000012c, Timeout in seconds.
Arg3: ffffd10b73b8d040, The thread currently holding on to the Pnp lock.
Arg4: fffff98295237a40, nt!TRIAGE_9F_PNP on Win7 and higher
Debugging Details:
------------------
Implicit thread is now ffffd10b`73b8d040
KEY_VALUES_STRING: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 10.0.17763.134 (WinBuild.160101.0800)
SYSTEM_MANUFACTURER: Dell Inc.
SYSTEM_PRODUCT_NAME: Inspiron 11-3162
SYSTEM_SKU: 0725
SYSTEM_VERSION: 2.4.0
BIOS_VENDOR: Dell Inc.
BIOS_VERSION: 2.4.0
BIOS_DATE: 01/31/2018
BASEBOARD_MANUFACTURER: Dell Inc.
BASEBOARD_PRODUCT: 0FCNP5
BASEBOARD_VERSION: A00
DUMP_TYPE: 2
DUMP_FILE_ATTRIBUTES: 0xc
Insufficient Dumpfile Size
Kernel Generated Triage Dump
BUGCHECK_P1: 4
BUGCHECK_P2: 12c
BUGCHECK_P3: ffffd10b73b8d040
BUGCHECK_P4: fffff98295237a40
DRVPOWERSTATE_SUBCODE: 4
FAULTING_THREAD: 73b8d040
CPU_COUNT: 4
CPU_MHZ: 640
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 4c
CPU_STEPPING: 3
CPU_MICROCODE: 6,4c,3,0 (F,M,S,R) SIG: 367'00000000 (cache) 367'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXPNP: 1 (!blackboxpnp)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x9F
PROCESS_NAME: System
CURRENT_IRQL: 2
ANALYSIS_SESSION_HOST: SHAOJU-1756
ANALYSIS_SESSION_TIME: 11-19-2018 13:04:56.0879
ANALYSIS_VERSION: 10.0.17134.12 amd64fre
LAST_CONTROL_TRANSFER: from fffff8040c72fd4e to fffff8040c659040
STACK_TEXT:
fffff982`95237a08 fffff804`0c72fd4e : 00000000`0000009f 00000000`00000004 00000000`0000012c ffffd10b`73b8d040 : nt!KeBugCheckEx
fffff982`95237a10 fffff804`0c9a73c6 : 00000000`00000002 ffff9d00`38db7100 00000000`00000001 00000000`00000019 : nt!PnpBugcheckPowerTimeout+0x8a
fffff982`95237a70 fffff804`0c50b729 : fffff982`9639c660 00000000`000000ff fffff982`95237c58 00000000`00000008 : nt!PopBuildDeviceNotifyListWatchdog+0x16
fffff982`95237aa0 fffff804`0c50a6e7 : 00000000`00000018 00000000`00989680 ffff9d00`38db7100 00000000`00000019 : nt!KiProcessExpiredTimerList+0x159
fffff982`95237b90 fffff804`0c65ca5a : 00000000`00000000 ffff9d00`38da7180 00000000`00000000 ffff9d00`38db7100 : nt!KiRetireDpcList+0x4a7
fffff982`95237da0 00000000`00000000 : fffff982`95238000 fffff982`95232000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: .thread 0xffffd10b73b8d040 ; kb
THREAD_SHA1_HASH_MOD_FUNC: 0efaf37e6601d7f65db9dbe50a219f0403a414f7
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 12d850c4ea804313b7c46e2f9fbbe8962c331702
THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
FOLLOWUP_IP:
nt!PnpBugcheckPowerTimeout+8a
fffff804`0c72fd4e cc int 3
FAULT_INSTR_CODE: cccccccc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PnpBugcheckPowerTimeout+8a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 3eeaaca9
IMAGE_VERSION: 10.0.17763.134
BUCKET_ID_FUNC_OFFSET: 8a
FAILURE_BUCKET_ID: 0x9F_4_nt!PnpBugcheckPowerTimeout
BUCKET_ID: 0x9F_4_nt!PnpBugcheckPowerTimeout
PRIMARY_PROBLEM_CLASS: 0x9F_4_nt!PnpBugcheckPowerTimeout
TARGET_TIME: 2018-11-19T04:13:03.000Z
OSBUILD: 17763
OSSERVICEPACK: 134
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2003-06-14 13:03:37
BUILDDATESTAMP_STR: 160101.0800
BUILDLAB_STR: WinBuild
BUILDOSVER_STR: 10.0.17763.134
ANALYSIS_SESSION_ELAPSED_TIME: 992
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x9f_4_nt!pnpbugcheckpowertimeout
FAILURE_ID_HASH: {626456dc-f029-5ddb-d8eb-a53e0f3ffebc}
Followup: MachineOwner
---------
2: kd> lmvm nt
Browse full module list
start end module name
fffff804`0c4a8000 fffff804`0ce99000 nt (pdb symbols) d:\symbols\ntkrnlmp.pdb\BCE32FB88EC22A4E1D5562A338E477271\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: d:\symbols\ntoskrnl.exe\3EEAACA99f1000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 3EEAACA9 (This is a reproducible build file hash, not a timestamp)
CheckSum: 00949FEC
ImageSize: 009F1000
File version: 10.0.17763.134
Product version: 10.0.17763.134
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.17763.134
FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment