[list=1]
Loading Dump File [D:\Kingston\BSODDmpFiles\pschand\Windows_NT6_BSOD_jcgriff2\030112-34023-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03058000 PsLoadedModuleList = 0xfffff800`0329d670
Debug session time: Thu Mar 1 18:44:06.696 2012 (UTC - 7:00)
System Uptime: 0 days 2:01:42.413
Loading Kernel Symbols
...............................................................
................................................................
................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {80000003, fffff800030ccad8, fffff88009b36850, 0}
Probably caused by : ntkrnlmp.exe ( nt!DebugPrompt+18 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 0000000080000003, Exception code that caused the bugcheck
Arg2: fffff800030ccad8, Address of the instruction which caused the bugcheck
Arg3: fffff88009b36850, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (HRESULT) 0x80000003 (2147483651) - One or more arguments are invalid
FAULTING_IP:
nt!DebugPrompt+18
fffff800`030ccad8 c3 ret
CONTEXT: fffff88009b36850 -- (.cxr 0xfffff88009b36850)
rax=0000000000000002 rbx=fffff880011a37a0 rcx=fffff880011c6070
rdx=fffff88009b3001f rsi=00000000000001e7 rdi=fffff880011c6090
rip=fffff800030ccad7 rsp=fffff88009b37238 rbp=fffffa80060222e0
r8=fffff88009b372b0 r9=fffff880011c0002 r10=0000000000000000
r11=fffff88009b37288 r12=0000000000000001 r13=0000000000000000
r14=fffffa8006022200 r15=0000000000000032
iopl=0 nv up ei pl nz ac pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00200212
nt!DebugPrompt+0x17:
fffff800`030ccad7 cc int 3
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
BUGCHECK_STR: 0x3B
PROCESS_NAME: iexplore.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800030ccad7
STACK_TEXT:
fffff880`09b37238 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!DebugPrompt+0x17
FOLLOWUP_IP:
nt!DebugPrompt+18
fffff800`030ccad8 c3 ret
SYMBOL_NAME: nt!DebugPrompt+18
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff88009b36850 ; kb
FAILURE_BUCKET_ID: X64_0x3B_VRF_nt!DebugPrompt+18
BUCKET_ID: X64_0x3B_VRF_nt!DebugPrompt+18
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\pschand\Windows_NT6_BSOD_jcgriff2\022912-26754-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03002000 PsLoadedModuleList = 0xfffff800`03247670
Debug session time: Wed Feb 29 20:11:30.633 2012 (UTC - 7:00)
System Uptime: 4 days 0:53:57.022
Loading Kernel Symbols
...............................................................
................................................................
..................................................
Loading User Symbols
Loading unloaded module list
................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffffffffffffd0, 1, fffff80003088a4c, 0}
Could not read faulting driver name
Probably caused by : win32k.sys ( win32k!xxxCreateDesktopEx+8e2 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffffffffffffd0, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff80003088a4c, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b1100
ffffffffffffffd0
FAULTING_IP:
nt!ObfDereferenceObject+2c
fffff800`03088a4c f0480fc11f lock xadd qword ptr [rdi],rbx
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: winlogon.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff880086882b0 -- (.trap 0xfffff880086882b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff900c06447e0 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003088a4c rsp=fffff88008688440 rbp=fffff88008391ca0
r8=fffffa800635f388 r9=0000000000000000 r10=fffffffffffffffe
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!ObfDereferenceObject+0x2c:
fffff800`03088a4c f0480fc11f lock xadd qword ptr [rdi],rbx ds:00000000`00000000=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000302a9fc to fffff8000307ec40
STACK_TEXT:
fffff880`08688148 fffff800`0302a9fc : 00000000`00000050 ffffffff`ffffffd0 00000000`00000001 fffff880`086882b0 : nt!KeBugCheckEx
fffff880`08688150 fffff800`0307cd6e : 00000000`00000001 ffffffff`ffffffd0 00000000`00000000 ffffffff`ffffffff : nt! ?? ::FNODOBFM::`string'+0x4611f
fffff880`086882b0 fffff800`03088a4c : fffffa80`079e1090 00000000`00000000 fffff900`c06447e0 00000000`00000001 : nt!KiPageFault+0x16e
fffff880`08688440 fffff960`0018945a : fffff880`08391ca0 00000000`00000000 fffffa80`03f7b090 fffffa80`046b0c68 : nt!ObfDereferenceObject+0x2c
fffff880`086884a0 fffff960`001a3593 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : win32k!xxxCreateDesktopEx+0x8e2
fffff880`08688640 fffff960`001a1a6a : 00000000`00000000 fffff880`08391ca0 fffff900`c06447e0 00000000`00000000 : win32k!xxxResolveDesktop+0xa47
fffff880`086889f0 fffff960`001cddcf : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`0635f300 : win32k!xxxCreateThreadInfo+0x64e
fffff880`08688b60 fffff960`001a5000 : fffff900`c06447e0 fffffa80`08270b60 fffffa80`08270b60 fffffa80`0635f300 : win32k!UserThreadCallout+0xcf
fffff880`08688b90 fffff800`03322265 : fffffa80`08270b60 fffffa80`0635f300 fffff6fc`40041c58 fffff6fc`40041c88 : win32k!W32pThreadCallout+0x78
fffff880`08688bc0 fffff800`030764fa : fffffa80`08270b60 00000000`00000001 00000000`00000020 00000000`00000000 : nt!PsConvertToGuiThread+0xe9
fffff880`08688bf0 fffff800`0307e09f : 00000000`00000104 00000000`00000001 00000000`7fffffff 000007fe`faa50000 : nt!KiConvertToGuiThread+0xa
fffff880`08688c20 00000000`77894e2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x1c4
00000000`00b7f798 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77894e2a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!xxxCreateDesktopEx+8e2
fffff960`0018945a 49895d38 mov qword ptr [r13+38h],rbx
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: win32k!xxxCreateDesktopEx+8e2
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4f10ff24
FAILURE_BUCKET_ID: X64_0x50_win32k!xxxCreateDesktopEx+8e2
BUCKET_ID: X64_0x50_win32k!xxxCreateDesktopEx+8e2
Followup: MachineOwner
---------
[/list]