Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-28423-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x83047000 PsLoadedModuleList = 0x8318f810
Debug session time: Sat Dec 18 08:34:11.803 2010 (UTC - 5:00)
System Uptime: 0 days 0:03:04.473
Loading Kernel Symbols
...............................................................
................................................................
......................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c000001d, 822b9653, 90563788, 0}
Probably caused by : memory_corruption
Followup: memory_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c000001d, The exception code that was not handled
Arg2: 822b9653, The address that the exception occurred at
Arg3: 90563788, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {
FAULTING_IP:
win32k!SFMLOGICALSURFACE::GetRedirectionInfo+97
822b9653 c6 ???
TRAP_FRAME: 90563788 -- (.trap 0xffffffff90563788)
ErrCode = 00000000
eax=ec050bd6 ebx=fdb52488 ecx=00000000 edx=90563884 esi=00000000 edi=90563828
eip=822b9653 esp=905637fc ebp=90563800 iopl=0 ov up ei pl nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010a02
win32k!SFMLOGICALSURFACE::GetRedirectionInfo+0x97:
822b9653 c6 ???
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 822df389 to 822b9653
FAILED_INSTRUCTION_ADDRESS:
win32k!SFMLOGICALSURFACE::GetRedirectionInfo+97
822b9653 c6 ???
STACK_TEXT:
90563800 822df389 90563884 90563898 90563890 win32k!SFMLOGICALSURFACE::GetRedirectionInfo+0x97
905638c8 82370d79 ffb8a008 00000000 b40f0b9a win32k!GreUpdateSprite+0x470
9056394c 82269d61 ffb7a6b8 00000767 0000017e win32k!EngpMovePointer+0x2b1
90563974 8226d61c ffb8a008 00000767 0000017e win32k!vMovePointer+0x81
905639b4 8233d827 00b46008 00000767 0000017e win32k!GreMovePointer+0x20f
905639f4 8230cabc 00000767 0000017e 00000000 win32k!xxxMoveEventAbsolute+0x17f
90563a2c 8230c93d 00000000 882d8640 90563a84 win32k!ProcessMouseInput+0x16f
90563a3c 830ef027 ffa45d28 ffa45d50 00000000 win32k!InputApc+0x4e
90563a84 830b5b0d 00000000 00000000 00000000 nt!KiDeliverApc+0x17f
90563ac8 830b4423 887c7d18 88811618 88811714 nt!KiSwapThread+0x24e
90563af0 830b06ef 88811618 888116d8 00000000 nt!KiCommitThreadWait+0x1df
90563c68 822bdc1c 00000002 882a85f0 00000001 nt!KeWaitForMultipleObjects+0x535
90563cc0 82228fff 00000001 882a85f0 82232838 win32k!xxxMsgWaitForMultipleObjects+0xe9
90563d04 82228590 882a85f0 00000001 8243eaa0 win32k!xxxDesktopThread+0x1b6
90563d18 822ec440 00000004 025ffedc 90563d34 win32k!xxxCreateSystemThreads+0x54
90563d28 8308a44a 00000004 025fff1c 777964f4 win32k!NtUserCallNoParam+0x1b
90563d28 777964f4 00000004 025fff1c 777964f4 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
025fff1c 00000000 00000000 00000000 00000000 0x777964f4
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -db !win32k
234 errors : !win32k (822b9040-822b9ff8)
822b9040 *00 83 7d e0 0c 75 55 c7 *00 fc 02 00 00 00 8b 4d ..}..uU........M
822b9050 *00 a1 b0 fb 43 82 3b c8 *00 04 8b 00 eb 02 8b 01 ....C.;.........
822b9060 *00 45 bc 89 55 fc eb 36 *00 c0 40 c3 8b 65 e8 eb [email protected]..
822b9070 *00 8b 45 ec 8b 00 ff 30 *00 f8 ca 14 00 c3 eb ec ..E....0........
...
822b90c0 *00 08 01 00 00 50 89 88 *00 00 00 00 e8 1b 1a 02 .....P..........
822b90d0 00 33 c0 40 5d c2 08 00 *00 90 90 90 90 8b ff 55 .3.@]..........U
822b90e0 *00 ec ff 75 08 ff 35 58 *00 43 82 e8 bb ff ff ff ...u..5X.C......
822b90f0 *00 c2 04 00 90 90 90 90 *00 8b 51 0c 8b 41 08 56 ..........Q..A.V
...
822b9140 *00 bc 00 00 00 ff 00 83 *00 01 75 22 33 c0 3b 05 ..........u"3.;.
822b9150 *00 d8 43 82 1b c0 83 e0 *00 50 6a 00 6a f8 ff b7 ..C......Pj.j...
822b9160 *00 00 00 00 68 03 80 00 00 e8 4e 5d 04 00 5f 5e ....h.....N].._^
822b9170 *00 90 90 90 90 90 8b ff *00 8b ec 83 ec 2c 56 8b .............,V.
...
822b91c0 *00 1b c0 25 ff ff c0 7f *00 01 00 3f 80 5e c9 c2 ...%.......?.^..
822b91d0 *00 00 90 90 90 90 90 8b *00 55 8b ec a1 04 f4 43 .........U.....C
822b91e0 *00 56 ff 30 e8 77 3d 03 00 a1 04 f4 43 82 8b 70 .V.0.w=.....C..p
822b91f0 *00 eb 2e 8b 46 20 a9 00 *00 40 04 75 22 83 7e 08 ....F [email protected]".~.
...
822b9240 *00 56 57 8b f1 56 33 db *00 b7 30 02 00 8b 55 0c .VW..V3...0...U.
822b9250 *00 46 14 8d 8a b0 00 00 00 8b 79 04 89 08 89 78 .F........y....x
822b9260 *00 89 07 89 41 04 ff 82 *00 00 00 00 83 4e 54 0c ....A........NT.
822b9270 *00 46 54 39 5e 10 74 24 *00 06 6a 01 50 ff 75 08 .FT9^.t$..j.P.u.
...
822b92c0 *00 c7 0f 86 86 00 00 00 *00 d2 d1 fe ff 89 45 08 ..............E.
822b92d0 *00 c0 74 19 6a 05 6a 00 *00 76 68 50 e8 db ea ff ..t.j.j..vhP....
822b92e0 *00 85 c0 75 0b ff 75 08 *00 e8 02 04 00 89 7d 08 ...u..u.......}.
822b92f0 *00 7d 0c 00 74 5b 57 ff *00 d4 f3 43 82 56 e8 70 .}..t[W....C.V.p
...
822b9340 *00 ff 76 68 e8 8c 02 04 00 89 7e 68 eb 03 89 45 ..vh......~h...E
822b9350 *00 8b 45 08 5f 5e 5d c2 *00 00 90 90 90 90 90 8b ..E._^].........
822b9360 *00 55 8b ec 56 8b 75 08 *00 68 08 01 00 00 56 e8 .U..V.u..h....V.
822b9370 *00 93 02 00 a1 58 ea 43 *00 8b 80 bc 00 00 00 3b .....X.C.......;
...
822b93c0 *00 85 00 00 00 56 e8 29 *00 02 00 5f 5e 5d c2 08 .....V.)..._^]..
822b93d0 00 90 90 90 90 90 8b ff *00 8b ec 83 ec 14 56 8b ..............V.
822b93e0 *00 10 8d 46 ff 57 83 f8 *00 77 0d 8b 0d fc d1 43 ...F.W...w.....C
822b93f0 *00 8b b4 81 d0 09 00 00 *00 45 0c 8b 08 8b 50 04 .........E....P.
...
822b9440 *00 33 f6 56 ff 75 08 e8 *00 a6 03 00 85 c0 0f 84 .3.V.u..........
822b9450 *00 00 00 00 ff 75 08 8d *00 08 e8 be 4c 03 00 8b .....u......L...
822b9460 *00 08 85 c0 0f 84 a2 00 00 00 f7 40 48 00 08 00 ...........@H...
822b9470 00 0f 84 8b 00 00 00 83 *00 10 50 8d 4d f8 e8 e5 ..........P.M...
...
822b94c0 *00 b0 48 01 00 00 8b 4d *00 81 c1 94 00 00 00 e8 ..H....M........
822b94d0 *00 5a 02 00 85 f6 74 1c *00 4d 08 6a 00 8d 45 08 .Z....t..M.j..E.
822b94e0 *00 e8 a5 38 02 00 8b 4d *00 6a 00 8d 45 08 50 e8 ...8...M.j..E.P.
822b94f0 *00 3f 02 00 33 f6 8d 4d *00 46 e8 3d 3e 02 00 8b .?..3..M.F.=>...
...
822b9540 *00 8b 40 18 51 52 56 50 *00 75 18 8d 45 f4 ff 75 [email protected]
822b9550 *00 ff 75 10 ff 75 0c 50 *00 cd 7d 02 00 8d 4d f4 ..u..u.P..}...M.
822b9560 *00 f0 e8 cf 7c 02 00 eb *00 6a 06 e8 a3 59 ff ff ....|....j...Y..
822b9570 *00 c6 5e c9 c2 14 00 90 *00 90 90 90 8b ff 55 8b ..^...........U.
...
822b95c0 *00 8b 41 2c 56 33 f6 3b *00 74 6c 50 e8 9b 2e 02 ..A,V3.;.tlP....
822b95d0 00 8b 48 20 8b 55 0c 89 *00 8b 48 24 8b 55 10 89 ..H .U....H$.U..
822b95e0 *00 33 c9 41 84 48 4c 74 *00 8b 4d 08 c7 01 02 00 .3.A.HLt..M.....
822b95f0 00 00 8b 4d 14 3b ce 74 *00 8b 90 30 01 00 00 89 ...M.;.t...0....
...
822b9640 *00 8b 45 10 89 30 8b 45 *00 3b c6 74 02 89 30 8b ..E..0.E.;.t..0.
822b9650 *00 18 3b c6 74 05 89 70 *00 89 30 5e 5d c2 14 00 ..;.t..p..0^]...
WARNING: !chkimg output was truncated to 50 lines. Invoke !chkimg without '-lo [num_lines]' to view entire output.
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: STRIDE
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_STRIDE
BUCKET_ID: MEMORY_CORRUPTION_STRIDE
Followup: memory_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-22339-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x8304d000 PsLoadedModuleList = 0x83195810
Debug session time: Sat Dec 18 09:19:38.280 2010 (UTC - 5:00)
System Uptime: 0 days 0:10:39.560
Loading Kernel Symbols
...............................................................
................................................................
.......................................
Loading User Symbols
Loading unloaded module list
....
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00003452, The subtype of the bugcheck.
Arg2: 6d44b000
Arg3: c0808c80
Arg4: bf512024
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_3452
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 830f20a8 to 830ed5bc
STACK_TEXT:
a26e3c14 830f20a8 8ea8f120 8ea8f120 00000000 nt!MiDeleteAddressesInWorkingSet+0x389
a26e3c40 83295dae 91be75a2 8a7ca6b0 c0000005 nt!MmCleanProcessAddressSpace+0x8c
a26e3cb4 832ca1e1 00000000 9fa257c8 00000001 nt!PspExitThread+0x683
a26e3ccc 830f5133 9fa257c8 a26e3cf8 a26e3d04 nt!PsExitSpecialApc+0x22
a26e3d1c 83090504 00000001 00000000 a26e3d34 nt!KiDeliverApc+0x28b
a26e3d1c 773e6400 00000001 00000000 a26e3d34 nt!KiServiceExit+0x64
WARNING: Frame IP not in any known module. Following frames may be wrong.
075ffa20 00000000 00000000 00000000 00000000 0x773e6400
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiDeleteAddressesInWorkingSet+389
830ed5bc cc int 3
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiDeleteAddressesInWorkingSet+389
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c3fac
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x1a_3452_VRF_nt!MiDeleteAddressesInWorkingSet+389
BUCKET_ID: 0x1a_3452_VRF_nt!MiDeleteAddressesInWorkingSet+389
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-21964-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x83051000 PsLoadedModuleList = 0x83199810
Debug session time: Sat Dec 18 09:26:30.890 2010 (UTC - 5:00)
System Uptime: 0 days 0:02:31.575
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols
Loading unloaded module list
....
Unable to load image \SystemRoot\system32\DRIVERS\atikmdag.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 8deff95f, 9d8ab704, 0}
*** WARNING: Unable to verify timestamp for atikmpag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmpag.sys
*** WARNING: Unable to verify timestamp for dxgkrnl.sys
*** ERROR: Module load completed but symbols could not be loaded for dxgkrnl.sys
Probably caused by : atikmdag.sys ( atikmdag+2c295f )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8deff95f, The address that the exception occurred at
Arg3: 9d8ab704, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
atikmdag+2c295f
8deff95f 8b4508 mov eax,dword ptr [ebp+8]
TRAP_FRAME: 9d8ab704 -- (.trap 0xffffffff9d8ab704)
ErrCode = 00000000
eax=00000000 ebx=00000001 ecx=9ddbef68 edx=00000001 esi=9d8ab87c edi=9dc34d80
eip=8deff95f esp=9d8ab778 ebp=9d8ab778 iopl=0 nv up ei ng nz ac pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010296
atikmdag+0x2c295f:
8deff95f 8b4508 mov eax,dword ptr [ebp+8] ss:0010:9d8ab780=00000015
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
BUGCHECK_STR: 0x8E
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 8deef129 to 8deff95f
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
9d8ab778 8deef129 00000015 9d8ab7a8 8defac64 atikmdag+0x2c295f
9d8ab784 8defac64 00000000 9d8ab87c 8c308fc8 atikmdag+0x2b2129
9d8ab7a8 8dc4af3e 9d8ab87c 9d8ab7d4 8d154b6d atikmdag+0x2bdc64
9d8ab7b4 8d154b6d 8c308fc8 9d8ab87c 81fef000 atikmdag+0xdf3e
9d8ab7d4 8e2f296a 8c308fc8 9d8ab87c 9d8ab8a0 atikmpag+0x4b6d
9d8ab7fc 8e2ef11b 9d8ab87c 867d6e30 9c5bfa38 dxgkrnl+0x2296a
9d8aba04 8e2ee505 9fc08bf8 9d8abcdc 9d8abcb8 dxgkrnl+0x1f11b
9d8abd18 98c5023e 00000010 867d6e30 9d8abd34 dxgkrnl+0x1e505
9d8abd28 8309444a 01d6ee18 01d6f0a8 772164f4 win32k!NtGdiDdDDIPresent+0x19
9d8abd28 772164f4 01d6ee18 01d6f0a8 772164f4 nt!KiFastCallEntry+0x12a
01d6f0a8 00000000 00000000 00000000 00000000 0x772164f4
STACK_COMMAND: kb
FOLLOWUP_IP:
atikmdag+2c295f
8deff95f 8b4508 mov eax,dword ptr [ebp+8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: atikmdag+2c295f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: atikmdag
IMAGE_NAME: atikmdag.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc78dcd
FAILURE_BUCKET_ID: 0x8E_VRF_atikmdag+2c295f
BUCKET_ID: 0x8E_VRF_atikmdag+2c295f
Followup: MachineOwner
---------