Добрый день. Сегодня случайно обнаружил, что моя система падает в BSOD при попытке использования ETW (Event Tracing for Windows), если в пути к логу имеются точки повторного разбора, указывающие в никуда. У меня нет опыта разбора ошибок в ядре, но очень интересно узнать, почему происходит это исключение – поэтому решил спросить здесь. Также интересно, воспроизводима ли ситуацию на других конфигурациях. Система: Windows Vista x64 SP1. Шаги для воспроизведения ситуации: 1. Запустить perfmon и создать новый 'Data Collector Set' в 'Startup Event Trace Sessions': 2. Выбрать 'Create Manually' в появившемся окне [img]. 3. Выбрать провайдера и выставить свойства в действительное значение (я выбирал 'Microsoft-Windows-Winlogon') [img]. 4. Создать точку повтороного разбора (reparse point), указывающую в несуществующую директорию. 5. Выбрать в качестве директории для хранения логов созданную точку разбора: 6. Завершить создание 'Data Collector Set' [img]. 7. Перезагрузиться. 8. Запустить perfmon и остановить созданную ранее сессию: 9. BSOD: 0x7E – SYSTEM_THREAD_EXCEPTION_NOT_HANDLED [img]. Возможно, кто-нибудь сможет воспроизвести ситуацию? Или есть какая-нибудь информация по этой ситуации? Буду благодарен за любые факты или предположения.
вот вывод !analyze -v: Код (Text): Loading Dump File [d:\bsod_reparse.dmp] Kernel Complete Dump File: Full address space is available Symbol search path is: srv*d:\symbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x64 Product: Server, suite: Enterprise TerminalServer SingleUserTS Built by: 6001.18145.amd64fre.vistasp1_gdr.080917-1612 Machine Name: Kernel base = 0xfffff800`01c63000 PsLoadedModuleList = 0xfffff800`01e28db0 Debug session time: Wed Sep 16 16:12:35.046 2009 (GMT+4) System Uptime: 0 days 0:04:00.765 Loading Kernel Symbols ............................................................... ................................................................ ............................. Loading User Symbols Loading unloaded module list ..... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 7E, {ffffffffc0000005, fffff80001f459be, fffffa6001ecad88, fffffa6001eca760} Probably caused by : ntkrnlmp.exe ( nt!ObpCaptureObjectCreateInformation+8e ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffff80001f459be, The address that the exception occurred at Arg3: fffffa6001ecad88, Exception Record Address Arg4: fffffa6001eca760, Context Record Address Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. FAULTING_IP: nt!ObpCaptureObjectCreateInformation+8e fffff800`01f459be 0fb601 movzx eax,byte ptr [rcx] EXCEPTION_RECORD: fffffa6001ecad88 -- (.exr 0xfffffa6001ecad88) ExceptionAddress: fffff80001f459be (nt!ObpCaptureObjectCreateInformation+0x000000000000008e) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: 000007ffffff0000 Attempt to read from address 000007ffffff0000 CONTEXT: fffffa6001eca760 -- (.cxr 0xfffffa6001eca760) rax=000007ffffff0000 rbx=fffffa80062520b0 rcx=000007ffffff0000 rdx=0000000000000001 rsi=fffffa6001ecb0b0 rdi=0000000000000000 rip=fffff80001f459be rsp=fffffa6001ecafc0 rbp=fffffa6001ecbb68 r8=0000000000000001 r9=fffffa6001ecbb68 r10=0000000000000000 r11=fffffa6001ecb418 r12=fffffa80062520b0 r13=0000000000000000 r14=0000000000000001 r15=0000000000000001 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!ObpCaptureObjectCreateInformation+0x8e: fffff800`01f459be 0fb601 movzx eax,byte ptr [rcx] ds:002b:000007ff`ffff0000=?? Resetting default scope DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT PROCESS_NAME: System CURRENT_IRQL: 0 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. EXCEPTION_PARAMETER1: 0000000000000000 EXCEPTION_PARAMETER2: 000007ffffff0000 READ_ADDRESS: 000007ffffff0000 FOLLOWUP_IP: nt!ObpCaptureObjectCreateInformation+8e fffff800`01f459be 0fb601 movzx eax,byte ptr [rcx] BUGCHECK_STR: 0x7E LAST_CONTROL_TRANSFER: from fffff80001f3b6f5 to fffff80001f459be STACK_TEXT: fffffa60`01ecafc0 fffff800`01f3b6f5 : fffffa80`06252010 fffffa80`018bd1d0 fffffa80`05719bc0 fffffa60`032d90d5 : nt!ObpCaptureObjectCreateInformation+0x8e fffffa60`01ecb030 fffff800`02003edb : fffffa60`01ecb3d0 00000000`0012019f fffffa80`061cd201 fffffa60`0101cc40 : nt!ObOpenObjectByName+0xa5 fffffa60`01ecb100 fffff800`020046b3 : 00000000`00000000 00000000`00000015 00000000`00000000 00000000`00000000 : nt!IopFastQueryNetworkAttributes+0x15b fffffa60`01ecb370 fffff800`01f7e0ee : 00000000`00000104 00000000`00000005 fffffa80`06204740 fffffa80`4346744e : nt!IopQueryNetworkAttributes+0x53 fffffa60`01ecb420 fffff800`01f37a59 : fffffa80`01d7ecc0 00000000`00000000 fffffa80`06217010 ffffffff`00000001 : nt! ?? ::NNGAKEGL::`string'+0x23e93 fffffa60`01ecb5c0 fffff800`01f3b944 : 00000000`00000000 fffffa80`01864200 00000000`00000640 00000000`00000000 : nt!ObpLookupObjectName+0x5eb fffffa60`01ecb6d0 fffff800`01f47ee0 : 00000000`0012019f fffffa60`01ecbb68 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByName+0x2f4 fffffa60`01ecb7a0 fffff800`01f48a0c : fffffa60`01ecbb40 00000000`0012019f 00000000`00000000 fffffa60`01ecbc08 : nt!IopCreateFile+0x290 fffffa60`01ecb840 fffff800`01cb7df3 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateFile+0x78 fffffa60`01ecb8d0 fffff800`01cb8300 : fffff800`01ec8106 00000000`00000000 00000000`00000000 fffffa60`01ecbb98 : nt!KiSystemServiceCopyEnd+0x13 fffffa60`01ecbad8 fffff800`01ec8106 : 00000000`00000000 00000000`00000000 fffffa60`01ecbb98 00000000`00000000 : nt!KiServiceLinkage fffffa60`01ecbae0 fffff800`01eb68d0 : 00000000`c000003a fffffa60`01ecbcf0 fffffa60`01ecbcf0 00000000`00000001 : nt!EtwpCreateDirectoryFile+0xf6 fffffa60`01ecbbc0 fffff800`01ec6506 : fffffa80`0195e701 fffffa80`00000018 00000000`00000000 00000000`00000001 : nt! ?? ::NNGAKEGL::`string'+0x315ca fffffa60`01ecbc40 fffff800`01f95e6c : fffffa80`0195e700 fffffa80`0195e710 00000000`00000000 00000000`00000000 : nt!EtwpCreateLogFile+0xc6 fffffa60`01ecbcf0 fffff800`01edaff3 : 00000000`00000000 fffffa80`0195e2b0 00000000`00000080 fffffa80`0195e710 : nt! ?? ::NNGAKEGL::`string'+0x4300c fffffa60`01ecbd50 fffff800`01cf2546 : fffff800`01dd7680 fffffa80`0195e2b0 fffffa80`01885bb0 00000000`00000001 : nt!PspSystemThreadStartup+0x57 fffffa60`01ecbd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16 SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: nt!ObpCaptureObjectCreateInformation+8e FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6001eca760 ; kb FAILURE_BUCKET_ID: X64_0x7E_nt!ObpCaptureObjectCreateInformation+8e BUCKET_ID: X64_0x7E_nt!ObpCaptureObjectCreateInformation+8e Followup: MachineOwner --------- stacktrace: Код (Text): 0: kd> .cxr 0xfffffa6001eca760 rax=000007ffffff0000 rbx=fffffa80062520b0 rcx=000007ffffff0000 rdx=0000000000000001 rsi=fffffa6001ecb0b0 rdi=0000000000000000 rip=fffff80001f459be rsp=fffffa6001ecafc0 rbp=fffffa6001ecbb68 r8=0000000000000001 r9=fffffa6001ecbb68 r10=0000000000000000 r11=fffffa6001ecb418 r12=fffffa80062520b0 r13=0000000000000000 r14=0000000000000001 r15=0000000000000001 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!ObpCaptureObjectCreateInformation+0x8e: fffff800`01f459be 0fb601 movzx eax,byte ptr [rcx] ds:002b:000007ff`ffff0000=?? 0: kd> .prefer_dml DML versions of commands on by default 0: kd> kn 200 # Child-SP RetAddr Call Site 00 fffffa60`01ecafc0 fffff800`01f3b6f5 nt!ObpCaptureObjectCreateInformation+0x8e 01 fffffa60`01ecb030 fffff800`02003edb nt!ObOpenObjectByName+0xa5 02 fffffa60`01ecb100 fffff800`020046b3 nt!IopFastQueryNetworkAttributes+0x15b 03 fffffa60`01ecb370 fffff800`01f7e0ee nt!IopQueryNetworkAttributes+0x53 04 fffffa60`01ecb420 fffff800`01f37a59 nt! ?? ::NNGAKEGL::`string'+0x23e93 05 fffffa60`01ecb5c0 fffff800`01f3b944 nt!ObpLookupObjectName+0x5eb 06 fffffa60`01ecb6d0 fffff800`01f47ee0 nt!ObOpenObjectByName+0x2f4 07 fffffa60`01ecb7a0 fffff800`01f48a0c nt!IopCreateFile+0x290 08 fffffa60`01ecb840 fffff800`01cb7df3 nt!NtCreateFile+0x78 09 fffffa60`01ecb8d0 fffff800`01cb8300 nt!KiSystemServiceCopyEnd+0x13 0a fffffa60`01ecbad8 fffff800`01ec8106 nt!KiServiceLinkage 0b fffffa60`01ecbae0 fffff800`01eb68d0 nt!EtwpCreateDirectoryFile+0xf6 0c fffffa60`01ecbbc0 fffff800`01ec6506 nt! ?? ::NNGAKEGL::`string'+0x315ca 0d fffffa60`01ecbc40 fffff800`01f95e6c nt!EtwpCreateLogFile+0xc6 0e fffffa60`01ecbcf0 fffff800`01edaff3 nt! ?? ::NNGAKEGL::`string'+0x4300c 0f fffffa60`01ecbd50 fffff800`01cf2546 nt!PspSystemThreadStartup+0x57 10 fffffa60`01ecbd80 00000000`00000000 nt!KxStartSystemThread+0x16 частичный disassembly верхней функции: Код (Text): 0: kd> u nt!ObpCaptureObjectCreateInformation nt!ObpCaptureObjectCreateInformation+0x8e+1 nt!ObpCaptureObjectCreateInformation: fffff800`01f45930 48895c2408 mov qword ptr [rsp+8],rbx fffff800`01f45935 4889742410 mov qword ptr [rsp+10h],rsi fffff800`01f4593a 57 push rdi fffff800`01f4593b 4154 push r12 fffff800`01f4593d 4155 push r13 fffff800`01f4593f 4156 push r14 fffff800`01f45941 4157 push r15 fffff800`01f45943 4883ec40 sub rsp,40h fffff800`01f45947 440fb6f2 movzx r14d,dl fffff800`01f4594b 4c8bd1 mov r10,rcx fffff800`01f4594e 33c0 xor eax,eax fffff800`01f45950 488b9c2498000000 mov rbx,qword ptr [rsp+98h] fffff800`01f45958 488903 mov qword ptr [rbx],rax fffff800`01f4595b 48894308 mov qword ptr [rbx+8],rax fffff800`01f4595f 48894310 mov qword ptr [rbx+10h],rax fffff800`01f45963 48894318 mov qword ptr [rbx+18h],rax fffff800`01f45967 48894320 mov qword ptr [rbx+20h],rax fffff800`01f4596b 48894328 mov qword ptr [rbx+28h],rax fffff800`01f4596f 48894330 mov qword ptr [rbx+30h],rax fffff800`01f45973 48894338 mov qword ptr [rbx+38h],rax fffff800`01f45977 48894340 mov qword ptr [rbx+40h],rax fffff800`01f4597b 488bb42490000000 mov rsi,qword ptr [rsp+90h] fffff800`01f45983 48894608 mov qword ptr [rsi+8],rax fffff800`01f45987 668906 mov word ptr [rsi],ax fffff800`01f4598a 66894602 mov word ptr [rsi+2],ax fffff800`01f4598e 4d85c9 test r9,r9 fffff800`01f45991 0f84d8010000 je nt!ObpCaptureObjectCreateInformation+0x23e (fffff800`01f45b6f) fffff800`01f45997 33ff xor edi,edi fffff800`01f45999 897c2430 mov dword ptr [rsp+30h],edi fffff800`01f4599d 84d2 test dl,dl fffff800`01f4599f 7424 je nt!ObpCaptureObjectCreateInformation+0x95 (fffff800`01f459c5) fffff800`01f459a1 498bc9 mov rcx,r9 fffff800`01f459a4 41f6c107 test r9b,7 fffff800`01f459a8 0f8548010000 jne nt!ObpCaptureObjectCreateInformation+0x1c6 (fffff800`01f45af6) fffff800`01f459ae 488b054b66f4ff mov rax,qword ptr [nt!MmUserProbeAddress (fffff800`01e8c000)] fffff800`01f459b5 4c3bc8 cmp r9,rax fffff800`01f459b8 0f833e010000 jae nt!ObpCaptureObjectCreateInformation+0x1cb (fffff800`01f45afc) fffff800`01f459be 0fb601 movzx eax,byte ptr [rcx] 0: kd> r rax, rcx, dl, r9 Last set context: rax=000007ffffff0000 rcx=000007ffffff0000 dl=1 r9=fffffa6001ecbb68 0: kd> u fffff800`01f45afc L4 nt!ObpCaptureObjectCreateInformation+0x1cb: fffff800`01f45afc 488bc8 mov rcx,rax fffff800`01f45aff e9bafeffff jmp nt!ObpCaptureObjectCreateInformation+0x8e (fffff800`01f459be) fffff800`01f45b04 bf0d0000c0 mov edi,0C000000Dh fffff800`01f45b09 897c2430 mov dword ptr [rsp+30h],edi полный стек: Код (Text): 0: kd> dps @rsp @@(@$thread->Tcb.StackBase) fffffa60`01ecafc0 ffff0180`ffff6c4a fffffa60`01ecafc8 00000000`00000149 fffffa60`01ecafd0 00000000`00001010 fffffa60`01ecafd8 fffffa80`00000000 fffffa60`01ecafe0 00000000`00000003 fffffa60`01ecafe8 00000000`00000000 fffffa60`01ecaff0 fffffa80`00000000 fffffa60`01ecaff8 00000000`00000000 fffffa60`01ecb000 00000000`00000001 fffffa60`01ecb008 00000000`00000001 fffffa60`01ecb010 00000000`00000000 fffffa60`01ecb018 fffffa80`062520b0 fffffa60`01ecb020 00000000`00000000 fffffa60`01ecb028 fffff800`01f3b6f5 nt!ObOpenObjectByName+0xa5 fffffa60`01ecb030 fffffa80`06252010 fffffa60`01ecb038 fffffa80`018bd1d0 fffffa60`01ecb040 fffffa80`05719bc0 fffffa60`01ecb048 fffffa60`032d90d5 SandBox64+0x540d5 fffffa60`01ecb050 fffffa60`01ecb0b0 fffffa60`01ecb058 fffffa80`062520b0 fffffa60`01ecb060 00000000`00000001 fffffa60`01ecb068 fffff800`4e584253 fffffa60`01ecb070 fffffa60`54005800 fffffa60`01ecb078 fffffa60`032862e3 SandBox64+0x12e3 fffffa60`01ecb080 fffffa80`05ab4b50 fffffa60`01ecb088 fffffa60`01ecb0b1 fffffa60`01ecb090 00000000`00000000 fffffa60`01ecb098 fffffa60`01ecb300 fffffa60`01ecb0a0 00000000`00000000 fffffa60`01ecb0a8 fffffa80`02c99220 fffffa60`01ecb0b0 00000000`00000000 fffffa60`01ecb0b8 00000000`00000000 fffffa60`01ecb0c0 00000000`00000001 fffffa60`01ecb0c8 fffff880`0dcf4870 fffffa60`01ecb0d0 00000000`00000000 fffffa60`01ecb0d8 00000000`00200021 fffffa60`01ecb0e0 fffffa60`01ecb3c0 fffffa60`01ecb0e8 fffffa60`01ecbb68 fffffa60`01ecb0f0 fffffa60`01ecb3d0 fffffa60`01ecb0f8 fffff800`02003edb nt!IopFastQueryNetworkAttributes+0x15b fffffa60`01ecb100 fffffa60`01ecb3d0 fffffa60`01ecb108 00000000`0012019f fffffa60`01ecb110 fffffa80`061cd201 fffffa60`01ecb118 fffffa60`0101cc40 Ntfs!NtfsExtendedCompleteRequest+0x110 fffffa60`01ecb120 fffffa80`0012019f fffffa60`01ecb128 fffffa60`01ecb150 fffffa60`01ecb130 fffffa60`01ecb140 fffffa60`01ecb138 fffffa80`057198b0 fffffa60`01ecb140 00000000`00000000 fffffa60`01ecb148 fffffa80`057198b0 fffffa60`01ecb150 00000000`00b80008 fffffa60`01ecb158 00000000`00000000 fffffa60`01ecb160 00000000`00000000 fffffa60`01ecb168 00000000`00000000 fffffa60`01ecb170 00000000`00000000 fffffa60`01ecb178 00000000`00000000 fffffa60`01ecb180 fffffa60`01ecbb68 fffffa60`01ecb188 00000000`00000000 fffffa60`01ecb190 00070000`00200021 fffffa60`01ecb198 00000000`00000000 fffffa60`01ecb1a0 00000021`00000000 fffffa60`01ecb1a8 00000000`00000001 fffffa60`01ecb1b0 00000000`00000000 fffffa60`01ecb1b8 fffffa60`01ecb3d0 fffffa60`01ecb1c0 00000000`00000000 fffffa60`01ecb1c8 00000000`00000000 fffffa60`01ecb1d0 00000000`01000100 fffffa60`01ecb1d8 fffffa60`01ecb210 fffffa60`01ecb1e0 00000000`00000020 fffffa60`01ecb1e8 00000000`00000000 fffffa60`01ecb1f0 00000000`00000000 fffffa60`01ecb1f8 00000000`00000000 fffffa60`01ecb200 00000000`00000000 fffffa60`01ecb208 fffff800`01d96f1c nt!ExFreePoolWithTag+0x35c fffffa60`01ecb210 00000000`ffffbfff fffffa60`01ecb218 fffffa60`00ce4cf1 fltmgr!DeleteNameCacheNodes+0x141 fffffa60`01ecb220 00000000`00000000 fffffa60`01ecb228 fffff800`01fa9fbc nt!IopSymlinkInitializeSymlinkInfo+0xac fffffa60`01ecb230 fffff880`0e385358 fffffa60`01ecb238 fffffa80`057198b0 fffffa60`01ecb240 00000000`00000032 fffffa60`01ecb248 00000000`00000000 fffffa60`01ecb250 00000000`00000000 fffffa60`01ecb258 fffff800`0200a841 nt!IopSymlinkRememberJunction+0x191 fffffa60`01ecb260 fffff880`0e385358 fffffa60`01ecb268 fffffa80`05a23f20 fffffa60`01ecb270 00000000`00000000 fffffa60`01ecb278 fffff880`0e385358 fffffa60`01ecb280 fffff880`0fb60000 fffffa60`01ecb288 00000000`00000000 fffffa60`01ecb290 00000000`00000000 fffffa60`01ecb298 fffff880`0fb60000 fffffa60`01ecb2a0 fffff880`0fb60000 fffffa60`01ecb2a8 00000000`00000000 fffffa60`01ecb2b0 00000000`00000018 fffffa60`01ecb2b8 fffff880`0e385358 fffffa60`01ecb2c0 fffffa80`058d4ac0 fffffa60`01ecb2c8 fffffa80`058d4ac0 fffffa60`01ecb2d0 fffff880`0fb6b470 fffffa60`01ecb2d8 fffffa80`057198b0 fffffa60`01ecb2e0 00000000`00000032 fffffa60`01ecb2e8 fffffa80`058d4ac0 fffffa60`01ecb2f0 00000000`00000034 fffffa60`01ecb2f8 fffff800`0200ae3d nt!IopGraftName+0x5cd fffffa60`01ecb300 fffffa80`05a23f20 fffffa60`01ecb308 fffff880`0e385358 fffffa60`01ecb310 00000000`00000030 fffffa60`01ecb318 fffffa80`0000077d fffffa60`01ecb320 ffff62b6`783da197 fffffa60`01ecb328 fffff800`01f147bf nt!FsRtlInsertExtraCreateParameter+0x1f fffffa60`01ecb330 fffffa80`01da5ae0 fffffa60`01ecb338 00000000`00000000 fffffa60`01ecb340 fffffa80`05a23f20 fffffa60`01ecb348 fffffa80`06217010 fffffa60`01ecb350 00000000`00000104 fffffa60`01ecb358 fffffa80`06204740 fffffa60`01ecb360 00000000`00000640 fffffa60`01ecb368 fffff800`020046b3 nt!IopQueryNetworkAttributes+0x53 fffffa60`01ecb370 00000000`00000000 fffffa60`01ecb378 00000000`00000015 fffffa60`01ecb380 00000000`00000000 fffffa60`01ecb388 00000000`00000000 fffffa60`01ecb390 fffffa60`01ecb3c0 fffffa60`01ecb398 fffffa60`01ecb3d0 fffffa60`01ecb3a0 fffffa80`05719801 fffffa60`01ecb3a8 00000000`00000001 fffffa60`01ecb3b0 fffff880`0dcf4870 fffffa60`01ecb3b8 fffffa80`05a23f20 fffffa60`01ecb3c0 fffffa80`05719800 fffffa60`01ecb3c8 fffffa80`058d4ac0 fffffa60`01ecb3d0 fffffa80`058d4b10 fffffa60`01ecb3d8 fffff800`01cc93b8 nt!IopFreeIrp+0xb8 fffffa60`01ecb3e0 fffffa80`01da5ae0 fffffa60`01ecb3e8 00000000`00000000 fffffa60`01ecb3f0 fffffa80`05a23f20 fffffa60`01ecb3f8 fffffa80`058d4ac0 fffffa60`01ecb400 fffffa80`06204740 fffffa60`01ecb408 00000000`00000640 fffffa60`01ecb410 00000000`00000015 fffffa60`01ecb418 fffff800`01f7e0ee nt! ?? ::NNGAKEGL::`string'+0x23e93 fffffa60`01ecb420 00000000`00000104 fffffa60`01ecb428 00000000`00000005 fffffa60`01ecb430 fffffa80`06204740 fffffa60`01ecb438 fffffa80`4346744e fffffa60`01ecb440 fffffa60`01ecb4d8 fffffa60`01ecb448 fffffa80`06204740 fffffa60`01ecb450 00000000`00000000 fffffa60`01ecb458 00000000`0012019f fffffa60`01ecb460 00000000`00000000 fffffa60`01ecb468 00000000`00000000 fffffa60`01ecb470 00000000`00000000 fffffa60`01ecb478 fffffa80`01d7ecc0 fffffa60`01ecb480 00000000`00000000 fffffa60`01ecb488 00000000`0012019f fffffa60`01ecb490 fffffa80`01da5ae0 fffffa60`01ecb498 00000000`00000000 fffffa60`01ecb4a0 00000000`00000000 fffffa60`01ecb4a8 fffffa80`01d7fd90 fffffa60`01ecb4b0 fffffa80`0195e2b0 fffffa60`01ecb4b8 fffffa80`05a23f20 fffffa60`01ecb4c0 00000000`00000000 fffffa60`01ecb4c8 00000000`00000000 fffffa60`01ecb4d0 00000000`00000000 fffffa60`01ecb4d8 fffff880`0e385358 fffffa60`01ecb4e0 fffff880`0dcf4870 fffffa60`01ecb4e8 00000000`00000000 fffffa60`01ecb4f0 00000000`00000000 fffffa60`01ecb4f8 00000000`00000000 fffffa60`01ecb500 00000000`00000104 fffffa60`01ecb508 00000000`a0000003 fffffa60`01ecb510 fffffa80`0195e2b0 fffffa60`01ecb518 00000000`00000000 fffffa60`01ecb520 00000000`00000000 fffffa60`01ecb528 00000000`00000000 fffffa60`01ecb530 fffffa80`06204740 fffffa60`01ecb538 00000000`0000001e fffffa60`01ecb540 fffffa80`062170f8 fffffa60`01ecb548 00000000`00000000 fffffa60`01ecb550 fffff880`000132f0 fffffa60`01ecb558 fffff800`01f433e2 nt!ObpLookupDirectoryEntry+0x422 fffffa60`01ecb560 00000000`00000000 fffffa60`01ecb568 fffffa80`06217010 fffffa60`01ecb570 00000021`0012019f fffffa60`01ecb578 00000000`00000000 fffffa60`01ecb580 fffffa80`06204740 fffffa60`01ecb588 fffff880`00005060 fffffa60`01ecb590 fffffa80`062170f8 fffffa60`01ecb598 fffffa60`01ecb750 fffffa60`01ecb5a0 fffffa80`01d7ec90 fffffa60`01ecb5a8 fffff800`01f3d7a0 nt!IopParseDevice fffffa60`01ecb5b0 fffffa80`01d7ec70 fffffa60`01ecb5b8 fffff800`01f37a59 nt!ObpLookupObjectName+0x5eb fffffa60`01ecb5c0 fffffa80`01d7ecc0 fffffa60`01ecb5c8 00000000`00000000 fffffa60`01ecb5d0 fffffa80`06217010 fffffa60`01ecb5d8 ffffffff`00000001 fffffa60`01ecb5e0 00000000`00000640 fffffa60`01ecb5e8 fffffa60`01ecb750 fffffa60`01ecb5f0 fffffa60`01ecb640 fffffa60`01ecb5f8 fffffa80`06204740 fffffa60`01ecb600 00000000`00000000 fffffa60`01ecb608 fffffa60`01ecb618 fffffa60`01ecb610 00000104`00000000 fffffa60`01ecb618 00000000`00000000 fffffa60`01ecb620 00000000`00000000 fffffa60`01ecb628 fffff880`0000003e fffffa60`01ecb630 00000000`00000000 fffffa60`01ecb638 00000000`00000000 fffffa60`01ecb640 00000000`00f8000c fffffa60`01ecb648 fffff880`0f9543be fffffa60`01ecb650 00000000`00000000 fffffa60`01ecb658 00000000`00000000 fffffa60`01ecb660 fffff880`00005060 fffffa60`01ecb668 fffffa60`01ecb750 fffffa60`01ecb670 00000000`00f8001e fffffa60`01ecb678 fffff880`0f9543a0 fffffa60`01ecb680 00000000`00000000 fffffa60`01ecb688 00000000`00000000 fffffa60`01ecb690 00000000`00000001 fffffa60`01ecb698 00000000`00000000 fffffa60`01ecb6a0 fffffa80`062170b0 fffffa60`01ecb6a8 fffffa80`06217010 fffffa60`01ecb6b0 fffffa80`062170f8 fffffa60`01ecb6b8 fffff880`00003380 fffffa60`01ecb6c0 fffffa80`06217010 fffffa60`01ecb6c8 fffff800`01f3b944 nt!ObOpenObjectByName+0x2f4 fffffa60`01ecb6d0 00000000`00000000 fffffa60`01ecb6d8 fffffa80`01864200 fffffa60`01ecb6e0 00000000`00000640 fffffa60`01ecb6e8 00000000`00000000 fffffa60`01ecb6f0 fffffa60`01ecb700 fffffa60`01ecb6f8 fffffa80`06204740 fffffa60`01ecb700 00000000`00000000 fffffa60`01ecb708 00000000`00000000 fffffa60`01ecb710 fffffa80`06217010 fffffa60`01ecb718 fffffa80`06217001 fffffa60`01ecb720 fffffa60`01ecb730 fffffa60`01ecb728 00000000`00000000 fffffa60`01ecb730 00000000`00000000 fffffa60`01ecb738 fffffa80`0195e2b0 fffffa60`01ecb740 fffffa80`0195e6b8 fffffa60`01ecb748 00000000`00000000 fffffa60`01ecb750 00000000`00f8003a fffffa60`01ecb758 fffff880`0f954390 fffffa60`01ecb760 00000000`0012019f fffffa60`01ecb768 00000000`00000000 fffffa60`01ecb770 00000000`00000000 fffffa60`01ecb778 fffffa80`06204740 fffffa60`01ecb780 00000000`00000021 fffffa60`01ecb788 fffffa60`01ecb9c0 fffffa60`01ecb790 00000000`00000003 fffffa60`01ecb798 fffff800`01f47ee0 nt!IopCreateFile+0x290 fffffa60`01ecb7a0 00000000`0012019f fffffa60`01ecb7a8 fffffa60`01ecbb68 fffffa60`01ecb7b0 00000000`00000000 fffffa60`01ecb7b8 00000000`00000000 fffffa60`01ecb7c0 00000000`0012019f fffffa60`01ecb7c8 fffffa80`06204740 fffffa60`01ecb7d0 fffffa60`01ecb7f0 fffffa60`01ecb7d8 00000000`00000000 fffffa60`01ecb7e0 00000000`00000000 fffffa60`01ecb7e8 fffffa80`06204740 fffffa60`01ecb7f0 00000000`00000000 fffffa60`01ecb7f8 00000000`00000000 fffffa60`01ecb800 00000000`00000000 fffffa60`01ecb808 fffffa60`01ecbd00 fffffa60`01ecb810 00000000`00000001 fffffa60`01ecb818 00000000`00000000 fffffa60`01ecb820 fffffa60`01ecb8e8 fffffa60`01ecb828 fffffa60`01ecbaf8 fffffa60`01ecb830 fffffa80`0195e2b0 fffffa60`01ecb838 fffff800`01f48a0c nt!NtCreateFile+0x78 fffffa60`01ecb840 fffffa60`01ecbb40 fffffa60`01ecb848 00000000`0012019f fffffa60`01ecb850 00000000`00000000 fffffa60`01ecb858 fffffa60`01ecbc08 fffffa60`01ecb860 00000000`00000000 fffffa60`01ecb868 00000000`00000080 fffffa60`01ecb870 00000000`00000005 fffffa60`01ecb878 00000000`00000003 fffffa60`01ecb880 00000000`00000021 fffffa60`01ecb888 00000000`00000000 fffffa60`01ecb890 00000000`00000000 fffffa60`01ecb898 00000000`00000000 fffffa60`01ecb8a0 00000000`00000000 fffffa60`01ecb8a8 00000000`00000000 fffffa60`01ecb8b0 00000000`00000020 fffffa60`01ecb8b8 00000000`00000000 fffffa60`01ecb8c0 00000000`00000000 fffffa60`01ecb8c8 fffff800`01cb7df3 nt!KiSystemServiceCopyEnd+0x13 fffffa60`01ecb8d0 00000000`00000000 fffffa60`01ecb8d8 00000000`00000000 fffffa60`01ecb8e0 00000000`00000000 fffffa60`01ecb8e8 00000000`00000000 fffffa60`01ecb8f0 00000000`00000000 fffffa60`01ecb8f8 fffff800`00000080 fffffa60`01ecb900 fffffa80`00000005 fffffa60`01ecb908 00000000`00000003 fffffa60`01ecb910 00000000`00000021 fffffa60`01ecb918 00000000`00000000 fffffa60`01ecb920 fffff880`00000000 fffffa60`01ecb928 00000000`00000000 fffffa60`01ecb930 00000000`00000000 fffffa60`01ecb938 00000000`00000000 fffffa60`01ecb940 00000000`00000000 fffffa60`01ecb948 00000000`00000000 fffffa60`01ecb950 00000000`00000000 fffffa60`01ecb958 00000000`00000000 fffffa60`01ecb960 00000000`00000000 fffffa60`01ecb968 00000000`00000000 fffffa60`01ecb970 00000000`00000000 fffffa60`01ecb978 00000000`00000000 fffffa60`01ecb980 00000000`00000000 fffffa60`01ecb988 00000000`00000000 fffffa60`01ecb990 00000000`00000000 fffffa60`01ecb998 00000000`00000000 fffffa60`01ecb9a0 00000000`00000000 fffffa60`01ecb9a8 00000000`00000000 fffffa60`01ecb9b0 00000000`00000000 fffffa60`01ecb9b8 00000000`00000000 fffffa60`01ecb9c0 00000000`00000000 fffffa60`01ecb9c8 00000000`00000000 fffffa60`01ecb9d0 00000000`00000000 fffffa60`01ecb9d8 00000000`00000000 fffffa60`01ecb9e0 00000000`00000000 fffffa60`01ecb9e8 00000000`00000000 fffffa60`01ecb9f0 00000000`00000000 fffffa60`01ecb9f8 00000000`00000000 fffffa60`01ecba00 00000000`00000000 fffffa60`01ecba08 00000000`00000000 fffffa60`01ecba10 ffff62b6`783da537 fffffa60`01ecba18 00000000`00000000 fffffa60`01ecba20 00000000`00000000 fffffa60`01ecba28 fffffa60`01ecbd00 fffffa60`01ecba30 00000000`00000001 fffffa60`01ecba38 00000000`00000001 fffffa60`01ecba40 00000000`00000000 fffffa60`01ecba48 fffffa60`01ecbc00 fffffa60`01ecba50 fffff880`0ec2f970 fffffa60`01ecba58 fffff800`01c9f8ee nt!vsnwprintf_l+0xd2 fffffa60`01ecba60 00000000`00000000 fffffa60`01ecba68 00000000`00000000 fffffa60`01ecba70 fffff880`0ec2f970 fffffa60`01ecba78 00000000`00000000 fffffa60`01ecba80 00000000`c000003a fffffa60`01ecba88 00000000`00000000 fffffa60`01ecba90 fffff880`0ec2f901 fffffa60`01ecba98 fffffa60`01ecbc00 fffffa60`01ecbaa0 fffff880`0ec2f970 fffffa60`01ecbaa8 fffff800`01cb8300 nt!KiServiceLinkage fffffa60`01ecbab0 00000000`00000010 fffffa60`01ecbab8 00000000`00000082 fffffa60`01ecbac0 fffffa60`01ecbad8 fffffa60`01ecbac8 fffff800`01c9f921 nt!vsnwprintf+0x11 fffffa60`01ecbad0 00000000`00000022 fffffa60`01ecbad8 fffff800`01ec8106 nt!EtwpCreateDirectoryFile+0xf6 fffffa60`01ecbae0 00000000`00000000 fffffa60`01ecbae8 00000000`00000000 fffffa60`01ecbaf0 fffffa60`01ecbb98 fffffa60`01ecbaf8 00000000`00000000 fffffa60`01ecbb00 00000000`00000000 fffffa60`01ecbb08 fffff800`00000080 fffffa60`01ecbb10 fffffa80`00000005 fffffa60`01ecbb18 00000000`00000003 fffffa60`01ecbb20 00000000`00000021 fffffa60`01ecbb28 00000000`00000000 fffffa60`01ecbb30 fffff880`00000000 fffffa60`01ecbb38 fffff800`01ca0f7e nt!RtlStringCbPrintfW+0x3a fffffa60`01ecbb40 00000000`00000000 fffffa60`01ecbb48 00000000`002a0028 fffffa60`01ecbb50 fffff880`0ec2f970 fffffa60`01ecbb58 fffffa60`01ecbd00 fffffa60`01ecbb60 fffffa60`01ecbb98 fffffa60`01ecbb68 fffffa60`00000030 fffffa60`01ecbb70 00000000`00000000 fffffa60`01ecbb78 fffffa60`01ecbb48 fffffa60`01ecbb80 00000000`00000640 fffffa60`01ecbb88 00000000`00000000 fffffa60`01ecbb90 00000000`00000000 fffffa60`01ecbb98 fffff800`01f56af0 nt! ?? ::NNGAKEGL::`string' fffffa60`01ecbba0 00000000`00000001 fffffa60`01ecbba8 fffff880`0ec2f998 fffffa60`01ecbbb0 fffff880`0ec2f970 fffffa60`01ecbbb8 fffff800`01eb68d0 nt! ?? ::NNGAKEGL::`string'+0x315ca fffffa60`01ecbbc0 00000000`c000003a fffffa60`01ecbbc8 fffffa60`01ecbcf0 fffffa60`01ecbbd0 fffffa60`01ecbcf0 fffffa60`01ecbbd8 00000000`00000001 fffffa60`01ecbbe0 00000000`00000000 fffffa60`01ecbbe8 fffffa60`01ecbc08 fffffa60`01ecbbf0 00000000`00000000 fffffa60`01ecbbf8 fffff800`01f0db5d nt!SeImpersonateClientEx+0x35 fffffa60`01ecbc00 fffff880`0ec2f970 fffffa60`01ecbc08 00000000`00000000 fffffa60`01ecbc10 00000000`00000000 fffffa60`01ecbc18 00000000`00000001 fffffa60`01ecbc20 00000000`00000001 fffffa60`01ecbc28 00000000`00000000 fffffa60`01ecbc30 fffffa80`0195e710 fffffa60`01ecbc38 fffff800`01ec6506 nt!EtwpCreateLogFile+0xc6 fffffa60`01ecbc40 fffffa80`0195e701 fffffa60`01ecbc48 fffffa80`00000018 fffffa60`01ecbc50 00000000`00000000 fffffa60`01ecbc58 00000000`00000001 fffffa60`01ecbc60 00000000`00000000 fffffa60`01ecbc68 00000000`3f490901 fffffa60`01ecbc70 00000000`002e002c fffffa60`01ecbc78 fffff880`001fab80 fffffa60`01ecbc80 00000000`00000001 fffffa60`01ecbc88 fffff800`01c918c0 nt!EtwpEnqueueFreeBuffer+0x2c fffffa60`01ecbc90 0006fa80`06169850 fffffa60`01ecbc98 fffffa80`0195e710 fffffa60`01ecbca0 00560000`00000000 fffffa60`01ecbca8 0005fa80`061bd400 fffffa60`01ecbcb0 fffffa80`0195e710 fffffa60`01ecbcb8 fffff800`01c7b148 nt!EtwpAllocateFreeBuffers+0xac fffffa60`01ecbcc0 fffffa80`01864110 fffffa60`01ecbcc8 00000000`00000000 fffffa60`01ecbcd0 00000000`00000000 fffffa60`01ecbcd8 00000000`00000001 fffffa60`01ecbce0 00000000`00000001 fffffa60`01ecbce8 fffff800`01f95e6c nt! ?? ::NNGAKEGL::`string'+0x4300c fffffa60`01ecbcf0 fffffa80`0195e700 fffffa60`01ecbcf8 fffffa80`0195e710 fffffa60`01ecbd00 00000000`00000000 fffffa60`01ecbd08 00000000`00000000 fffffa60`01ecbd10 00000000`00000000 fffffa60`01ecbd18 00000000`00000000 fffffa60`01ecbd20 fffff800`0420f070 fffffa60`01ecbd28 fffffa80`01864110 fffffa60`01ecbd30 00000000`00000000 fffffa60`01ecbd38 fffff800`01f206e8 nt!EtwpLogger fffffa60`01ecbd40 fffffa80`01864110 fffffa60`01ecbd48 fffff800`01edaff3 nt!PspSystemThreadStartup+0x57 fffffa60`01ecbd50 00000000`00000000 fffffa60`01ecbd58 fffffa80`0195e2b0 fffffa60`01ecbd60 00000000`00000080 fffffa60`01ecbd68 fffffa80`0195e710 fffffa60`01ecbd70 00000000`00000000 fffffa60`01ecbd78 fffff800`01cf2546 nt!KxStartSystemThread+0x16 fffffa60`01ecbd80 fffff800`01dd7680 nt!KiInitialPCR+0x180 fffffa60`01ecbd88 fffffa80`0195e2b0 fffffa60`01ecbd90 fffffa80`01885bb0 fffffa60`01ecbd98 00000000`00000001 fffffa60`01ecbda0 00000000`00000000 fffffa60`01ecbda8 00000000`00000000 fffffa60`01ecbdb0 00000000`00000000 fffffa60`01ecbdb8 00000000`00000000 fffffa60`01ecbdc0 00000000`00000000 fffffa60`01ecbdc8 00000000`00000000 fffffa60`01ecbdd0 00000000`00000000 fffffa60`01ecbdd8 00000000`00000000 fffffa60`01ecbde0 00000000`00000000 fffffa60`01ecbde8 00000000`00000000 fffffa60`01ecbdf0 00000000`00000000 fffffa60`01ecbdf8 00000000`00000000 fffffa60`01ecbe00 00000000`00000000 fffffa60`01ecbe08 00000000`00000000 fffffa60`01ecbe10 00000000`00000000 fffffa60`01ecbe18 00000000`00000000 fffffa60`01ecbe20 00000000`00000000 fffffa60`01ecbe28 00000000`00000000 fffffa60`01ecbe30 00000000`00000000 fffffa60`01ecbe38 00000000`00000000 fffffa60`01ecbe40 00000000`00000000 fffffa60`01ecbe48 00000000`00000000 fffffa60`01ecbe50 00000000`00000000 fffffa60`01ecbe58 00000000`00000000 fffffa60`01ecbe60 00000000`00000000 fffffa60`01ecbe68 00000000`00000000 fffffa60`01ecbe70 00000000`00000000 fffffa60`01ecbe78 00000000`00000000 fffffa60`01ecbe80 00000000`00000000 fffffa60`01ecbe88 00000000`00000000 fffffa60`01ecbe90 00000000`00000000 fffffa60`01ecbe98 00000000`00000000 fffffa60`01ecbea0 00000000`00000000 fffffa60`01ecbea8 00000000`00000000 fffffa60`01ecbeb0 00000000`00000000 fffffa60`01ecbeb8 00000000`00000000 fffffa60`01ecbec0 00000000`00000000 fffffa60`01ecbec8 00000000`00000000 fffffa60`01ecbed0 00000000`00000000 fffffa60`01ecbed8 00000000`00000000 fffffa60`01ecbee0 00000000`00000000 fffffa60`01ecbee8 00000000`00000000 fffffa60`01ecbef0 00000000`00000000 fffffa60`01ecbef8 00000000`00000000 fffffa60`01ecbf00 00000000`00000000 fffffa60`01ecbf08 00000000`00000000 fffffa60`01ecbf10 00000000`00000000 fffffa60`01ecbf18 00000000`00000000 fffffa60`01ecbf20 00000000`00000000 fffffa60`01ecbf28 00000000`00000000 fffffa60`01ecbf30 00000000`00000000 fffffa60`01ecbf38 00000000`00000000 fffffa60`01ecbf40 00000000`00000000 fffffa60`01ecbf48 00000000`00000000 fffffa60`01ecbf50 00000000`00000000 fffffa60`01ecbf58 00000000`00000000 fffffa60`01ecbf60 00000000`00000000 fffffa60`01ecbf68 00000000`00000000 fffffa60`01ecbf70 00000000`00000000 fffffa60`01ecbf78 00000000`00000000 fffffa60`01ecbf80 00000000`00000000 fffffa60`01ecbf88 00000000`00000000 fffffa60`01ecbf90 00000000`00000000 fffffa60`01ecbf98 00000000`00000000 fffffa60`01ecbfa0 00000000`00000000 fffffa60`01ecbfa8 00000000`00000000 fffffa60`01ecbfb0 fffffa60`01ecc000 fffffa60`01ecbfb8 fffffa60`01ec6000 fffffa60`01ecbfc0 fffffa60`01ecba70 fffffa60`01ecbfc8 00000000`00000000 fffffa60`01ecbfd0 fffffa60`01ec6000 fffffa60`01ecbfd8 00000000`00000000 fffffa60`01ecbfe0 00000000`00000000 fffffa60`01ecbfe8 00000000`00000000 fffffa60`01ecbff0 00000000`00000000 fffffa60`01ecbff8 00000000`00000000 fffffa60`01ecc000 ????????`???????? Clerk Event Tracing for Windows – это не сторонний софт, а системный механизм. является частью ядра.
Clerk, спасибо за участие =) простите – не так вас понял сначала. но ядро реальное – никаких виртуальных машин, честно-честно =) пока что попытался понять, почему в stacktrace местами какая-то ерунда – и, похоже, это следствие какой-то оптимизации. попробовал привести stacktrace к более приемлемому виду такой последовательностью команд: Код (Text): 0: kd> kn 100 # Child-SP RetAddr Call Site 00 fffffa60`01ecafc0 fffff800`01f3b6f5 nt!ObpCaptureObjectCreateInformation+0x8e <- exception! 01 fffffa60`01ecb030 fffff800`02003edb nt!ObOpenObjectByName+0xa5 02 fffffa60`01ecb100 fffff800`020046b3 nt!IopFastQueryNetworkAttributes+0x15b 03 fffffa60`01ecb370 fffff800`01f7e0ee nt!IopQueryNetworkAttributes+0x53 04 fffffa60`01ecb420 fffff800`01f37a59 nt! ?? ::NNGAKEGL::`string'+0x23e93 05 fffffa60`01ecb5c0 fffff800`01f3b944 nt!ObpLookupObjectName+0x5eb 06 fffffa60`01ecb6d0 fffff800`01f47ee0 nt!ObOpenObjectByName+0x2f4 07 fffffa60`01ecb7a0 fffff800`01f48a0c nt!IopCreateFile+0x290 08 fffffa60`01ecb840 fffff800`01cb7df3 nt!NtCreateFile+0x78 09 fffffa60`01ecb8d0 fffff800`01cb8300 nt!KiSystemServiceCopyEnd+0x13 0a fffffa60`01ecbad8 fffff800`01ec8106 nt!KiServiceLinkage 0b fffffa60`01ecbae0 fffff800`01eb68d0 nt!EtwpCreateDirectoryFile+0xf6 0c fffffa60`01ecbbc0 fffff800`01ec6506 nt! ?? ::NNGAKEGL::`string'+0x315ca 0d fffffa60`01ecbc40 fffff800`01f95e6c nt!EtwpCreateLogFile+0xc6 0e fffffa60`01ecbcf0 fffff800`01edaff3 nt! ?? ::NNGAKEGL::`string'+0x4300c 0f fffffa60`01ecbd50 fffff800`01cf2546 nt!PspSystemThreadStartup+0x57 10 fffffa60`01ecbd80 00000000`00000000 nt!KxStartSystemThread+0x16 0: kd> .frame /c 5 05 fffffa60`01ecb5c0 fffff800`01f3b944 nt!ObpLookupObjectName+0x5eb rax=000007ffffff0000 rbx=fffffa8001d7ec70 rcx=000007ffffff0000 rdx=0000000000000001 rsi=fffff80001f3d7a0 rdi=fffffa8001d7ec90 rip=fffff80001f37a59 rsp=fffffa6001ecb5c0 rbp=0000000000000640 r8=0000000000000001 r9=fffffa6001ecbb68 r10=0000000000000000 r11=fffffa6001ecb418 r12=fffffa6001ecb750 r13=fffffa80062170f8 r14=fffff88000005060 r15=fffffa8006204740 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!ObpLookupObjectName+0x5eb: fffff800`01f37a59 488d4f30 lea rcx,[rdi+30h] 0: kd> ub @rip L2 nt!ObpLookupObjectName+0x5e5: fffff800`01f37a53 896c2420 mov dword ptr [rsp+20h],ebp fffff800`01f37a57 ffd6 call rsi 0: kd> ln @rsi Browse module Set bu breakpoint (fffff800`01f3d7a0) nt!IopParseDevice | (fffff800`01f3ec20) nt!FsRtlAreNamesEqual Exact matches: nt!IopParseDevice = <no type information> 0: kd> .frame /c 0d 0d fffffa60`01ecbc40 fffff800`01f95e6c nt!EtwpCreateLogFile+0xc6 rax=000007ffffff0000 rbx=fffffa800195e701 rcx=000007ffffff0000 rdx=0000000000000001 rsi=0000000000000001 rdi=fffffa800195e710 rip=fffff80001ec6506 rsp=fffffa6001ecbc40 rbp=0000000000000000 r8=0000000000000001 r9=fffffa6001ecbb68 r10=0000000000000000 r11=fffffa6001ecb418 r12=0000000000000001 r13=0000000000000000 r14=0000000000000001 r15=0000000000000000 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!EtwpCreateLogFile+0xc6: fffff800`01ec6506 413af6 cmp sil,r14b 0: kd> ub @rip L2 nt!EtwpCreateLogFile+0xbc: fffff800`01ec64fc 44886c2420 mov byte ptr [rsp+20h],r13b fffff800`01ec6501 e8ca000000 call nt!EtwpDelayCreate (fffff800`01ec65d0) 0: kd> .frame /c 0f 0f fffffa60`01ecbd50 fffff800`01cf2546 nt!PspSystemThreadStartup+0x57 rax=000007ffffff0000 rbx=fffffa800195e2b0 rcx=000007ffffff0000 rdx=0000000000000001 rsi=fffffa800195e710 rdi=fffffa8001864110 rip=fffff80001edaff3 rsp=fffffa6001ecbd50 rbp=0000000000000080 r8=0000000000000001 r9=fffffa6001ecbb68 r10=0000000000000000 r11=fffffa6001ecb418 r12=fffff80001f206e8 r13=0000000000000000 r14=fffffa8001864110 r15=fffff8000420f070 iopl=0 nv up ei ng nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282 nt!PspSystemThreadStartup+0x57: fffff800`01edaff3 eb0e jmp nt!PspSystemThreadStartup+0x64 (fffff800`01edb003) 0: kd> ub @rip L2 nt!PspSystemThreadStartup+0x51: fffff800`01edafed 488bce mov rcx,rsi fffff800`01edaff0 41ffd4 call r12 0: kd> ln @r12 Browse module Set bu breakpoint (fffff800`01f206e8) nt!EtwpLogger | (fffff800`01ec5154) nt!CmpSyncKeyValues Exact matches: nt!EtwpLogger = <no type information> таким образом, stacktrace принимает следующий вид: Код (Text): # Child-SP RetAddr Call Site 00 fffffa60`01ecafc0 fffff800`01f3b6f5 nt!ObpCaptureObjectCreateInformation+0x8e 01 fffffa60`01ecb030 fffff800`02003edb nt!ObOpenObjectByName+0xa5 02 fffffa60`01ecb100 fffff800`020046b3 nt!IopFastQueryNetworkAttributes+0x15b 03 fffffa60`01ecb370 fffff800`01f7e0ee nt!IopQueryNetworkAttributes+0x53 04 fffffa60`01ecb420 fffff800`01f37a59 nt!IopParseDevice+xxxx 05 fffffa60`01ecb5c0 fffff800`01f3b944 nt!ObpLookupObjectName+0x5eb 06 fffffa60`01ecb6d0 fffff800`01f47ee0 nt!ObOpenObjectByName+0x2f4 07 fffffa60`01ecb7a0 fffff800`01f48a0c nt!IopCreateFile+0x290 08 fffffa60`01ecb840 fffff800`01cb7df3 nt!NtCreateFile+0x78 09 fffffa60`01ecb8d0 fffff800`01cb8300 nt!KiSystemServiceCopyEnd+0x13 0a fffffa60`01ecbad8 fffff800`01ec8106 nt!KiServiceLinkage 0b fffffa60`01ecbae0 fffff800`01eb68d0 nt!EtwpCreateDirectoryFile+0xf6 0c fffffa60`01ecbbc0 fffff800`01ec6506 nt!EtwpDelayCreate+xxxx 0d fffffa60`01ecbc40 fffff800`01f95e6c nt!EtwpCreateLogFile+0xc6 0e fffffa60`01ecbcf0 fffff800`01edaff3 nt!EtwpLogger+xxxx 0f fffffa60`01ecbd50 fffff800`01cf2546 nt!PspSystemThreadStartup+0x57 10 fffffa60`01ecbd80 00000000`00000000 nt!KxStartSystemThread+0x16 вот только пока не получается увидеть истинную причину исключения – где что-то пошло не так?