0: kd> !process fffffa8005ea9b10
GetPointerFromAddress: unable to read from fffff80003509000
PROCESS fffffa8005ea9b10
SessionId: none Cid: 0434 Peb: 7fffffd8000 ParentCid: 01f8
DirBase: 5217b000 ObjectTable: fffff8a0016804e0 HandleCount: <Data Not Accessible>
Image: services.exe
VadRoot fffffa8005f176e0 Vads 189 Clone 0 Private 1787. Modified 77. Locked 10.
DeviceMap fffff8a000008aa0
Token fffff8a00168ac40
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 71424
QuotaPoolUsage[NonPagedPool] 37152
Working Set Sizes (now,min,max) (2915, 50, 345) (11660KB, 200KB, 1380KB)
PeakWorkingSetSize 3951
VirtualSize 68 Mb
PeakVirtualSize 68 Mb
PageFaultCount 4523
MemoryPriority BACKGROUND
BasePriority 9
CommitCharge 2465
THREAD fffffa8005f63060 Cid 0434.0438 Teb: 000007fffffde000 Win32Thread: fffff900c01e38d0 RUNNING on processor 0
Impersonation token: fffff8a003e00c40 (Level Impersonation)
GetUlongFromAddress: unable to read from fffff80003447c18
Owning Process fffffa8005ea9b10 Image: services.exe
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 4476
Context Switch Count 960 IdealProcessor: 0 LargeStack
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x00000000ff1e331c
Stack Init fffff88002460c70 Current fffff88002460010
Base fffff88002461000 Limit fffff88002457000 Call 0000000000000000
Priority 7 BasePriority 7 PriorityDecrement 0 IoPriority 2 PagePriority 3
Child-SP RetAddr Call Site
fffff880`024602b8 fffff800`036076fa nt!KeBugCheckEx
fffff880`024602c0 fffff800`035643b5 nt! ?? ::NNGAKEGL::`string'+0x977a
fffff880`02460320 fffff800`035641ac nt!HvMarkDirty+0x176
fffff880`02460380 fffff800`0360a759 nt!HvMarkCellDirty+0x150
fffff880`024603d0 fffff800`03529d02 nt! ?? ::NNGAKEGL::`string'+0xeeb4
fffff880`02460410 fffff800`03529aa4 nt!CmpMarkKeyValuesDirty+0x182
fffff880`024604b0 fffff800`035291aa nt!CmpFreeKeyValues+0x24
fffff880`024604e0 fffff800`03528ed8 nt!CmpSyncKeyValues+0x7a
fffff880`024605c0 fffff800`0352aa7e nt!CmpCopySyncTree2+0x2a8
fffff880`02460670 fffff800`0352a997 nt!CmpCopySyncTree+0x6e
fffff880`024606c0 fffff800`0352a566 nt!CmpSaveBootControlSet+0x307
fffff880`024608a0 fffff800`032cb6d3 nt!NtInitializeRegistry+0xc6
fffff880`024608f0 fffff800`032c7c90 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`024608f0)
fffff880`02460a88 fffff800`0352a50f nt!KiServiceLinkage
fffff880`02460a90 fffff800`032cb6d3 nt!NtInitializeRegistry+0x6f
fffff880`02460ae0 00000000`775acada nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`02460ae0)
00000000`0020fa68 00000000`00000000 0x775acada
*** Error in reading nt!_ETHREAD @ fffffa8005fce060