Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121310-16520-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c57000 PsLoadedModuleList = 0xfffff800`02e94e50
Debug session time: Mon Dec 13 13:09:51.294 2010 (UTC - 5:00)
System Uptime: 0 days 2:13:42.684
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {ffffda8005237ff0, 2, 1, fffff80002ccb7b4}
Probably caused by : win32k.sys ( win32k!SetWakeBit+f8 )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffda8005237ff0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002ccb7b4, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eff0e0
ffffda8005237ff0
CURRENT_IRQL: 2
FAULTING_IP:
nt!KeSetEvent+124
fffff800`02ccb7b4 48894108 mov qword ptr [rcx+8],rax
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: csrss.exe
TRAP_FRAME: fffff880039e4870 -- (.trap 0xfffff880039e4870)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8005237fe8 rbx=0000000000000000 rcx=ffffda8005237fe8
rdx=fffffa8001bde458 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ccb7b4 rsp=fffff880039e4a00 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=ffffffffffffffef
r11=0000000000021114 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
nt!KeSetEvent+0x124:
fffff800`02ccb7b4 48894108 mov qword ptr [rcx+8],rax ds:ffffda80`05237ff0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cc6ca9 to fffff80002cc7740
STACK_TEXT:
fffff880`039e4728 fffff800`02cc6ca9 : 00000000`0000000a ffffda80`05237ff0 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`039e4730 fffff800`02cc5920 : 00000000`00000004 fffffa80`05237fe0 fffffa80`046f13a0 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`039e4870 fffff800`02ccb7b4 : 00000000`40df0088 00000000`00000000 00000000`00010001 00000000`00000000 : nt!KiPageFault+0x260
fffff880`039e4a00 fffff960`0019b578 : 00000000`00000000 fffff960`00000002 00000000`00000000 ffffda80`05237fe8 : nt!KeSetEvent+0x124
fffff880`039e4a70 fffff960`00192f33 : fffff900`c00cc280 00000000`00000001 00000000`00000004 fffff800`02cd31e3 : win32k!SetWakeBit+0xf8
fffff880`039e4aa0 fffff960`00193954 : 00000000`00000000 fffff960`003afa90 00000000`00000004 00000000`00000001 : win32k!TimersProc+0x157
fffff880`039e4af0 fffff960`00124708 : fffffa80`0000007b 00000000`0000000f fffff880`00000001 ffffffff`8000031c : win32k!RawInputThread+0x9b4
fffff880`039e4bc0 fffff960`001a429a : fffffa80`00000002 fffff880`02139f40 00000000`00000020 00000000`00000000 : win32k!xxxCreateSystemThreads+0x58
fffff880`039e4bf0 fffff800`02cc6993 : fffffa80`046f12e0 00000000`00000004 000007ff`fffd3000 00000000`00000000 : win32k!NtUserCallNoParam+0x36
fffff880`039e4c20 000007fe`fd333d3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`01bbf9c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd333d3a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!SetWakeBit+f8
fffff960`0019b578 488b5c2430 mov rbx,qword ptr [rsp+30h]
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: win32k!SetWakeBit+f8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
FAILURE_BUCKET_ID: X64_0xA_win32k!SetWakeBit+f8
BUCKET_ID: X64_0xA_win32k!SetWakeBit+f8
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121510-16052-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c0b000 PsLoadedModuleList = 0xfffff800`02e48e50
Debug session time: Wed Dec 15 14:12:35.040 2010 (UTC - 5:00)
System Uptime: 0 days 3:20:52.068
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {ffffda800542652c, 2, 0, fffff880016079eb}
Probably caused by : NETIO.SYS ( NETIO!KfdClassify+76e )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: ffffda800542652c, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff880016079eb, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb30e0
ffffda800542652c
CURRENT_IRQL: 2
FAULTING_IP:
NETIO!KfdClassify+76e
fffff880`016079eb 458b422c mov r8d,dword ptr [r10+2Ch]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff88003361ab0 -- (.trap 0xfffff88003361ab0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=fffff88003361d98
rdx=fffffa8001b14cd8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880016079eb rsp=fffff88003361c40 rbp=fffff880033621b0
r8=0000000000000000 r9=0000000000000001 r10=ffffda8005426500
r11=fffffa8001b14cb0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
NETIO!KfdClassify+0x76e:
fffff880`016079eb 458b422c mov r8d,dword ptr [r10+2Ch] ds:0001:ffffda80`0542652c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c7aca9 to fffff80002c7b740
STACK_TEXT:
fffff880`03361968 fffff800`02c7aca9 : 00000000`0000000a ffffda80`0542652c 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`03361970 fffff800`02c79920 : 00000000`00000000 fffff880`03361d98 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`03361ab0 fffff880`016079eb : 00000000`00000000 fffff880`033621b0 fffff880`03362070 fffff880`03362070 : nt!KiPageFault+0x260
fffff880`03361c40 fffff880`0163fa84 : fffff880`033623f8 fffff880`03362120 fffffa80`00000001 fffff880`03362020 : NETIO!KfdClassify+0x76e
fffff880`03361fb0 fffff880`0163fef8 : fffffa80`0219d2c0 00000000`00000014 00000000`00000000 00000000`00000000 : NETIO!StreamClassify+0x104
fffff880`033620d0 fffff880`016402a9 : fffffa80`0219d200 fffffa80`02898960 fffffa80`01eeb000 fffff880`010398a2 : NETIO!StreamCommonInspect+0x228
fffff880`033623b0 fffff880`01908af8 : fffffa80`0219d2c0 fffff880`03362700 fffffa80`01eeb030 fffffa80`02727fa0 : NETIO!WfpStreamInspectReceive+0xf9
fffff880`03362430 fffff880`01933131 : fffffa80`023006f0 fffff880`03362760 00000000`0000002a fffff880`03362760 : tcpip!InetInspectReceive+0x48
fffff880`03362470 fffff880`018bb830 : 00000000`81cc1f3d fffffa80`023006f0 fffffa80`01eeb030 fffffa80`01eeb030 : tcpip!TcpInspectReceive+0x71
fffff880`033624c0 fffff880`01878e95 : 00000000`00000014 fffff880`00000000 fffffa80`04a5b6c0 fffffa80`0219d2c0 : tcpip! ?? ::FNODOBFM::`string'+0x3cab5
fffff880`03362680 fffff880`0187d86a : fffffa80`028aef00 00000000`00000000 fffffa80`0271c448 00000000`00000000 : tcpip!TcpTcbReceive+0x1f5
fffff880`03362830 fffff880`0187d3b7 : fffffa80`031effd0 fffffa80`04a5b6c0 00000000`00000000 fffff880`01860700 : tcpip!TcpMatchReceive+0x1fa
fffff880`03362980 fffff880`0185f6c7 : fffffa80`04a5d8d7 fffffa80`028bd9d7 fffffa80`028ad8d7 00000000`00000000 : tcpip!TcpPreValidatedReceive+0x177
fffff880`03362a30 fffff880`0185f799 : fffff880`03362bb0 fffff880`0196d9a0 fffff880`03362bc0 00000000`00000001 : tcpip!IppDeliverListToProtocol+0x97
fffff880`03362af0 fffff880`0185fc90 : 00000000`00000000 fffff800`02c82992 00000000`00000000 fffff880`03362bb0 : tcpip!IppProcessDeliverList+0x59
fffff880`03362b60 fffff880`018367c2 : fffffa80`018dfb60 fffff880`00c4077d 00000000`00000000 fffffa80`026fe040 : tcpip!IppReceiveHeaderBatch+0x231
fffff880`03362c40 fffff800`02f77c43 : fffffa80`026fe040 fffff800`02e205f8 fffffa80`018dfb60 fffffa80`027539e0 : tcpip!IppLoopbackTransmit+0x72
fffff880`03362c80 fffff800`02c88961 : fffff800`02e20500 fffff800`02f77c20 fffffa80`018dfb60 fffff800`02e205f8 : nt!IopProcessWorkItem+0x23
fffff880`03362cb0 fffff800`02f1fc06 : 00000000`00000000 fffffa80`018dfb60 00000000`00000080 fffffa80`018aa890 : nt!ExpWorkerThread+0x111
fffff880`03362d40 fffff800`02c59c26 : fffff880`0328e180 fffffa80`018dfb60 fffff880`03299040 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`03362d80 00000000`00000000 : fffff880`03363000 fffff880`0335d000 fffff880`033629f0 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!KfdClassify+76e
fffff880`016079eb 458b422c mov r8d,dword ptr [r10+2Ch]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: NETIO!KfdClassify+76e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETIO
IMAGE_NAME: NETIO.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc18a
FAILURE_BUCKET_ID: X64_0xD1_NETIO!KfdClassify+76e
BUCKET_ID: X64_0xD1_NETIO!KfdClassify+76e
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-15475-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c66000 PsLoadedModuleList = 0xfffff800`02ea3e50
Debug session time: Sat Dec 18 12:56:26.580 2010 (UTC - 5:00)
System Uptime: 0 days 2:25:17.969
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {ffffda8003398290, 2, 0, fffff80002ce31dc}
Probably caused by : win32k.sys ( win32k!TimersProc+197 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: ffffda8003398290, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002ce31dc, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f0e0e0
ffffda8003398290
CURRENT_IRQL: 2
FAULTING_IP:
nt!KiInsertTimerTable+1cc
fffff800`02ce31dc 4c3b78f8 cmp r15,qword ptr [rax-8]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: csrss.exe
TRAP_FRAME: fffff8800212c7e0 -- (.trap 0xfffff8800212c7e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffda8003398298 rbx=0000000000000000 rcx=fffffa800339c298
rdx=fffffa8003396298 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ce31dc rsp=fffff8800212c970 rbp=fffffa8003396298
r8=ffffffffffffffff r9=0000000000000013 r10=fffff80002e50e80
r11=fffff8800212c900 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!KiInsertTimerTable+0x1cc:
fffff800`02ce31dc 4c3b78f8 cmp r15,qword ptr [rax-8] ds:dc40:ffffda80`03398290=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cd5ca9 to fffff80002cd6740
STACK_TEXT:
fffff880`0212c698 fffff800`02cd5ca9 : 00000000`0000000a ffffda80`03398290 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0212c6a0 fffff800`02cd4920 : fffff800`02ce2b25 fffffa80`0464b160 fffff880`03163180 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`0212c7e0 fffff800`02ce31dc : 00000000`00200202 fffff800`02cdb1fa fffff880`031d3180 fffffa80`05749060 : nt!KiPageFault+0x260
fffff880`0212c970 fffff800`02ce2de0 : ffffffff`ffbf9ba0 fffff800`02e50e80 fffffa80`0464b160 00000000`00000000 : nt!KiInsertTimerTable+0x1cc
fffff880`0212c9d0 fffff800`02ce2ce4 : fffff900`c013dc40 ffffffff`ffbf9ba0 00000000`00000000 fffff960`00000002 : nt!KiSetTimerEx+0xf0
fffff880`0212ca60 fffff960`000f2eb3 : fffff900`c013dc40 00000000`00000001 00000000`00000004 fffff800`02ce21e3 : nt!KeSetTimer+0x14
fffff880`0212caa0 fffff960`000f3894 : 00000000`00000000 fffff960`00310a90 00000000`00000004 00000000`00000001 : win32k!TimersProc+0x197
fffff880`0212caf0 fffff960`00084528 : fffffa80`0000007b 00000000`0000000f fffff880`00000001 00000000`00000000 : win32k!RawInputThread+0x9b4
fffff880`0212cbc0 fffff960`0010409a : fffffa80`00000002 fffff880`02111f40 00000000`00000020 00000000`00000000 : win32k!xxxCreateSystemThreads+0x58
fffff880`0212cbf0 fffff800`02cd5993 : fffffa80`04658990 00000000`00000004 000007ff`fffae000 00000000`00000000 : win32k!NtUserCallNoParam+0x36
fffff880`0212cc20 000007fe`fda83d3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0033f9c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fda83d3a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!TimersProc+197
fffff960`000f2eb3 488b5c2450 mov rbx,qword ptr [rsp+50h]
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: win32k!TimersProc+197
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4cbe5d3e
FAILURE_BUCKET_ID: X64_0xA_win32k!TimersProc+197
BUCKET_ID: X64_0xA_win32k!TimersProc+197
Followup: MachineOwner
---------