*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C000021A, {ffffc00117dd59c0, 0, 0, 0}
----- ETW minidump data unavailable-----
Probably caused by : ntkrnlmp.exe ( nt! ?? ::OKHAJAOM::`string'+b69 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffc00117dd59c0, String that identifies the problem.
Arg2: 0000000000000000, Error Code.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
----- ETW minidump data unavailable-----
ERROR_CODE: (NTSTATUS) 0xc000021a - {Onherstelbare systeemfout} Het systeemproces %hs is onverwacht afgebroken met de status: 0x%08x (0x%08x 0x%08x). Het systeem is afgesloten.
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Onherstelbare systeemfout} Het systeemproces %hs is onverwacht afgebroken met de status: 0x%08x (0x%08x 0x%08x). Het systeem is afgesloten.
EXCEPTION_PARAMETER1: ffffc00117dd59c0
EXCEPTION_PARAMETER2: 0000000000000000
EXCEPTION_PARAMETER3: 0000000000000000
EXCEPTION_PARAMETER4: 0
ADDITIONAL_DEBUG_TEXT: Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly
BUGCHECK_STR: 0xc000021a_RPC_Terminated
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: services.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
LAST_CONTROL_TRANSFER: from fffff802a4384779 to fffff802a415afa0
STACK_TEXT:
ffffd001`65f88658 fffff802`a4384779 : 00000000`0000004c 00000000`c000021a ffffd001`689863f8 ffffe000`e96b4c50 : nt!KeBugCheckEx
ffffd001`65f88660 fffff802`a437c909 : ffffe000`e8de3c00 ffffd001`65f887a0 00000000`00000000 00000000`00000002 : nt!PopGracefulShutdown+0x2c9
ffffd001`65f886a0 fffff802`a41667b3 : fffff802`a41482bc fffff802`a4144774 00000000`00000000 ffffe000`e8de3880 : nt! ?? ::OKHAJAOM::`string'+0xb69
ffffd001`65f88840 fffff802`a415ec00 : fffff802`a45967e1 00000000`00000001 ffffd001`65f88a58 00000000`c0000004 : nt!KiSystemServiceCopyEnd+0x13
ffffd001`65f889d8 fffff802`a45967e1 : 00000000`00000001 ffffd001`65f88a58 00000000`c0000004 ffffd001`65b8a180 : nt!KiServiceLinkage
ffffd001`65f889e0 fffff802`a44cc853 : 00000000`00000000 00000000`00000000 ffffd001`65b8a180 ffffe000`e8de39c0 : nt! ?? ::NNGAKEGL::`string'+0x65101
ffffd001`65f88aa0 fffff802`a404efee : fffff802`a404ef34 00000000`00000000 00000000`00000002 ffffe000`e8de3880 : nt!PopPolicyWorkerAction+0x63
ffffd001`65f88b10 fffff802`a405aadb : fffff802`00000002 ffffd001`65f88bd0 00000000`80000000 fffff802`a42e04b0 : nt!PopPolicyWorkerThread+0xba
ffffd001`65f88b50 fffff802`a40d6794 : ffffe000`e8348880 ffffe000`e8de3880 ffffe000`e8de3880 ffffe000`e8258040 : nt!ExpWorkerThread+0x293
ffffd001`65f88c00 fffff802`a41615c6 : ffffd001`65b0e180 ffffe000`e8de3880 ffffe000`e8348880 c67e4bc6`54bab469 : nt!PspSystemThreadStartup+0x58
ffffd001`65f88c60 00000000`00000000 : ffffd001`65f89000 ffffd001`65f83000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::OKHAJAOM::`string'+b69
fffff802`a437c909 cc int 3
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt! ?? ::OKHAJAOM::`string'+b69
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5318053f
IMAGE_VERSION: 6.3.9600.17041
BUCKET_ID_FUNC_OFFSET: b69
FAILURE_BUCKET_ID: 0xc000021a_RPC_Terminated_nt!_??_::OKHAJAOM::_string_
BUCKET_ID: 0xc000021a_RPC_Terminated_nt!_??_::OKHAJAOM::_string_
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xc000021a_rpc_terminated_nt!_??_::okhajaom::_string_
FAILURE_ID_HASH: {eaac3022-4065-944e-ed60-c9bf280cfe1e}
Followup: MachineOwner
---------