Help narrowing cause BSOD

cblodgett

New member
Joined
Jan 13, 2017
Posts
1
I am new at this and not sure how to interpret. Symptoms are sporadic BSODs. Drivers are up to date as far as I can tell. Please assist if possible!

System info -

Dell Latitude E5470

Intel Core i5-6300U CPU @ 2.40GHz 2.40 GHz

8GB memory

64-Bit

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: SRV*c:\symbols*Symbol information
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.23418.amd64fre.win7sp1_ldr.160408-2045
Machine Name:
Kernel base = 0xfffff800`03210000 PsLoadedModuleList = 0xfffff800`03452730
Debug session time: Fri Jan 13 06:25:57.376 2017 (UTC - 6:00)
System Uptime: 0 days 0:03:37.671
Loading Kernel Symbols
...............................................................
................................................................
..................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffdf018). Type ".hh dbgerr001" for details
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4A, {77afbbaa, 2, 0, fffff8800b60db60}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceExit+245 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a)
Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL.
Arguments:
Arg1: 0000000077afbbaa, Address of system function (system call routine)
Arg2: 0000000000000002, Current IRQL
Arg3: 0000000000000000, 0
Arg4: fffff8800b60db60, 0
Debugging Details:
------------------

PROCESS_NAME: EPSecurityServ
BUGCHECK_STR: RAISED_IRQL_FAULT
FAULTING_IP:
+3362366635653635
00000000`77afbbaa ?? ???
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff8000327e9a9 to fffff8000327f400
STACK_TEXT:
fffff880`0b60d928 fffff800`0327e9a9 : 00000000`0000004a 00000000`77afbbaa 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0b60d930 fffff800`0327e8e0 : 00000000`00001474 fffff880`0b60db60 00000000`00000000 fffff800`0356a98b : nt!KiBugCheckDispatch+0x69
fffff880`0b60da70 00000000`77afbbaa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`2c76fad8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77afbbaa

STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`0327e8e0 4883ec50 sub rsp,50h
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceExit+245
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5708972e
FAILURE_BUCKET_ID: X64_RAISED_IRQL_FAULT_EPSecurityServ_nt!KiSystemServiceExit+245
BUCKET_ID: X64_RAISED_IRQL_FAULT_EPSecurityServ_nt!KiSystemServiceExit+245
Followup: MachineOwner

Thanks!
 
Hi & welcome

we'd love to have the memory.dmp as well- or at least me. :smile9:

what about to bann your Bitdefender for a while, seems he did the trick: EPSecurityServ
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top