[list=1]
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\robzibob\Windows_NT6_BSOD_jcgriff2\012012-26582-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02264000 PsLoadedModuleList = 0xfffff800`024a9670
Debug session time: Fri Jan 20 13:28:29.268 2012 (UTC - 7:00)
System Uptime: 0 days 0:00:18.768
Loading Kernel Symbols
...............................................................
.................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C000021A, {fffff8a00013b2a0, c0000189, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt!ExpSystemErrorHandler2+5e1 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: fffff8a00013b2a0, String that identifies the problem.
Arg2: 00000000c0000189, Error Code.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
ERROR_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_PARAMETER1: fffff8a00013b2a0
EXCEPTION_PARAMETER2: 00000000c0000189
EXCEPTION_PARAMETER3: 0000000000000000
EXCEPTION_PARAMETER4: 0
ADDITIONAL_DEBUG_TEXT: Session Manager Initialization
BUGCHECK_STR: 0xc000021a_smss.exe_c0000189
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: smss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff8000273d63e to fffff800022e0c40
STACK_TEXT:
fffff880`009b74e8 fffff800`0273d63e : 00000000`0000004c 00000000`c000021a fffff880`009b7608 fffffa80`058cf820 : nt!KeBugCheckEx
fffff880`009b74f0 fffff800`0252a2c1 : fffffa80`05965886 fffff880`009b7ca0 00000000`00000100 fffffa80`05aec150 : nt!PoShutdownBugCheck+0xae
fffff880`009b7570 fffff800`0232d74d : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`0018f801 : nt!ExpSystemErrorHandler2+0x5e1
fffff880`009b77a0 fffff800`027102a1 : 00000000`c000021a 00000000`00000004 00000000`00000001 fffff880`009b7b58 : nt!ExpSystemErrorHandler+0xdd
fffff880`009b77e0 fffff800`02712023 : 00000000`c000021a fffffa80`00000004 fffff8a0`00000001 fffff880`009b7b58 : nt!ExpRaiseHardError+0xe1
fffff880`009b7b10 fffff800`022dfed3 : fffffa80`052acb60 00000000`00000001 00000000`0018f838 fffff800`025d84f4 : nt!NtRaiseHardError+0x1a1
fffff880`009b7bb0 00000000`7757264a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0018f818 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7757264a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExpSystemErrorHandler2+5e1
fffff800`0252a2c1 cc int 3
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!ExpSystemErrorHandler2+5e1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0xc000021a_smss.exe_c0000189_nt!ExpSystemErrorHandler2+5e1
BUCKET_ID: X64_0xc000021a_smss.exe_c0000189_nt!ExpSystemErrorHandler2+5e1
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\robzibob\Windows_NT6_BSOD_jcgriff2\012012-26504-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e14000 PsLoadedModuleList = 0xfffff800`03059670
Debug session time: Fri Jan 20 13:16:28.026 2012 (UTC - 7:00)
System Uptime: 0 days 0:07:44.056
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {32, d, 0, fffff800034104ca}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000032, memory referenced
Arg2: 000000000000000d, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800034104ca, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030c3100
0000000000000032
CURRENT_IRQL: d
FAULTING_IP:
hal!HalpSendFlatIpi+5b
fffff800`034104ca 0fb60c08 movzx ecx,byte ptr [rax+rcx]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: System
TRAP_FRAME: fffff80000b9c8d0 -- (.trap 0xfffff80000b9c8d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000032
rdx=0000000000000832 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800034104ca rsp=fffff80000b9ca60 rbp=fffff800034269b0
r8=0004000000000000 r9=fffbffffffffffff r10=0000000000000018
r11=fffff80000b9cb00 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl nz na po nc
hal!HalpSendFlatIpi+0x5b:
fffff800`034104ca 0fb60c08 movzx ecx,byte ptr [rax+rcx] ds:cf7b:00000000`00000032=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e901e9 to fffff80002e90c40
STACK_TEXT:
fffff800`00b9c788 fffff800`02e901e9 : 00000000`0000000a 00000000`00000032 00000000`0000000d 00000000`00000000 : nt!KeBugCheckEx
fffff800`00b9c790 fffff800`02e8ee60 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000064 : nt!KiBugCheckDispatch+0x69
fffff800`00b9c8d0 fffff800`034104ca : 00000005`00000000 00000001`00000000 00000000`0000718e fffff800`02e9b497 : nt!KiPageFault+0x260
fffff800`00b9ca60 fffff800`0341057e : fffff780`00000320 00000000`000008d1 00000000`00000000 fffff780`00000320 : hal!HalpSendFlatIpi+0x5b
fffff800`00b9ca90 fffff800`02e9b39a : 00000000`00000000 fffff800`03006e80 00000000`00000000 00000000`00000000 : hal!HalpRequestIpiSpecifyVector+0x6d
fffff800`00b9cac0 fffff800`03407895 : fffff800`0342d460 fffff800`00b9cc70 fffff800`0342d460 00000000`00000000 : nt!KeUpdateSystemTime+0x27a
fffff800`00b9cbc0 fffff800`02e8d173 : fffff800`03006e80 fffff800`00b9cc70 fffff800`030098c0 00000000`00000004 : hal!HalpHpetClockInterrupt+0x8d
fffff800`00b9cbf0 fffff800`02e88942 : fffff800`03006e80 fffff800`00000001 00000000`00000001 fffff800`00000000 : nt!KiInterruptDispatchNoLock+0x163
fffff800`00b9cd80 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cd40 00000000`00000000 : nt!KiIdleLoop+0x32
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiPageFault+260
fffff800`02e8ee60 440f20c0 mov rax,cr8
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiPageFault+260
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0xA_nt!KiPageFault+260
BUCKET_ID: X64_0xA_nt!KiPageFault+260
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\robzibob\Windows_NT6_BSOD_jcgriff2\011912-25927-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e4a000 PsLoadedModuleList = 0xfffff800`0308f670
Debug session time: Wed Jan 18 15:07:11.462 2012 (UTC - 7:00)
System Uptime: 0 days 0:04:13.492
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff880010e3c11, fffff8800906fba0, 0}
Probably caused by : fltmgr.sys ( fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff880010e3c11, Address of the instruction which caused the bugcheck
Arg3: fffff8800906fba0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291
fffff880`010e3c11 c3 ret
CONTEXT: fffff8800906fba0 -- (.cxr 0xfffff8800906fba0)
rax=0000000000000000 rbx=fffffa8003fccc60 rcx=0000000000000000
rdx=0000000000000000 rsi=fffffa8004c39010 rdi=fffffa8004acd890
rip=fffff880010e3c11 rsp=fffff88009070588 rbp=0000000000000000
r8=0000000000000000 r9=00000000000003e0 r10=fffff80002e4a000
r11=fffff88009070560 r12=fffffa8003df2070 r13=fffffa8003df2070
r14=fffffa8003fccfb8 r15=fffffa8004acd890
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x291:
fffff880`010e3c11 c3 ret
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: SearchIndexer.
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff880010e3c11
STACK_TEXT:
fffff880`09070588 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x291
FOLLOWUP_IP:
fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291
fffff880`010e3c11 c3 ret
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fltmgr
IMAGE_NAME: fltmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7929c
STACK_COMMAND: .cxr 0xfffff8800906fba0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291
BUCKET_ID: X64_0x3B_fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+291
Followup: MachineOwner
---------
[/list]