UNEXPECTED_KERNEL_MODE_TRAP (7f)
This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault). The first number in the
bugcheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
use .trap on that value
Else
.trap on the appropriate frame will show where the trap was taken
(on x86, this will be the ebp that goes with the procedure KiTrap)
Endif
kb will then show the corrected stack.
Arguments:
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: 0000000080050031
Arg3: 00000000000406f8
Arg4: fffff800033b7fac
Debugging Details:
------------------
BUGCHECK_STR: 0x7f_8
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff800032c39a9 to fffff800032c4400
STACK_TEXT:
fffff880`02eabd68 fffff800`032c39a9 : 00000000`0000007f 00000000`00000008 00000000`80050031 00000000`000406f8 : nt!KeBugCheckEx
fffff880`02eabd70 fffff800`032c1e72 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
[COLOR="#FF0000"]fffff880`02eabeb0 fffff800`033b7fac : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0xb2[/COLOR]
fffff880`02ec8000 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!EtwWriteEx+0xc
STACK_COMMAND: kb
FOLLOWUP_IP: nt!KiDoubleFaultAbort+b2 fffff800`032c1e72 90 nop
SYMBOL_STACK_INDEX: 2
[COLOR="#FF0000"]SYMBOL_NAME: nt!KiDoubleFaultAbort+b2[/COLOR]
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 57f7b833
IMAGE_VERSION: 6.1.7601.23569
FAILURE_BUCKET_ID: X64_0x7f_8_nt!KiDoubleFaultAbort+b2
BUCKET_ID: X64_0x7f_8_nt!KiDoubleFaultAbort+b2
ANALYSIS_SOURCE: KM
[COLOR="#FF0000"]FAILURE_ID_HASH_STRING: km:x64_0x7f_8_nt!kidoublefaultabort+b2[/COLOR]
FAILURE_ID_HASH: {0367acc4-9bb4-ab69-5701-46a2011718e9}
[COLOR="#008000"]Es ist also ein Doppelfehler aufgetreten, der natürlich zum Bluescreen führte.[/COLOR]
Followup: MachineOwner
---------
5: kd> !sysinfo machineid
[COLOR="#FF0000"]sysinfo: could not find necessary interfaces.[/COLOR]
sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
5: kd> !sysinfo smbios
[COLOR="#FF0000"]sysinfo: could not find necessary interfaces.[/COLOR]
sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
[COLOR="#008000"]Hier wollte ich einige Systeminfos abrufen. Leider sind keine gespeichert.
Das sind nur zwei Beispiele. Man kann noch mehr Infos abrufen, keine führt hier zu Ergebnissen.[/COLOR]
.....
[COLOR="#008000"]Auch der aktive Thread enthält keine verwertbaren Informationen[/COLOR]
5: kd> !thread
GetPointerFromAddress: unable to read from fffff80003500000
THREAD fffff88002eb0040 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 5
Not impersonating
GetUlongFromAddress: unable to read from fffff8000343ec18
Owning Process fffff80003451180 Image: <Unknown>
Attached Process fffffa8006a20040 Image: System
fffff78000000000: Unable to get shared data
Wait Start TickCount 0
Context Switch Count 1510 IdealProcessor: 5
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address nt!KiIdleLoop (0xfffff800032bc0b0)
Stack Init fffff88002ecdc70 Current fffff88002ecdc00
Base fffff88002ece000 Limit fffff88002ec8000 Call 0
Priority 16 BasePriority 0 UnusualBoost 0 ForegroundBoost 0 IoPriority 0 PagePriority 0
Child-SP RetAddr : Args to Child : Call Site
fffff880`02eabd68 fffff800`032c39a9 : 00000000`0000007f 00000000`00000008 00000000`80050031 00000000`000406f8 : nt!KeBugCheckEx
fffff880`02eabd70 fffff800`032c1e72 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`02eabeb0 fffff800`033b7fac : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0xb2 (TrapFrame @ fffff880`02eabeb0)
fffff880`02ec8000 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!EtwWriteEx+0xc
....
[COLOR="#008000"]Als letztes wollte ich noch den Speicher des Thread einsehen. Auch dort ist nichts Verwertbares.[/COLOR]