*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 124, {0, fffffa8005172028, b2000040, 800}
Unable to load image Unknown_Module_00000000`00144042, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00144042
*** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_00000000`00144042
Unknown module 'Unknown_Module_00000000_00144042' found on stack, using vad to reload module.
!vad_reload -1 0x144042
Unable to read KTHREAD address fffffa800876abd0
Failed to get new vadroot
Unable to load image PSHED.dll, Win32 error 0n2
*** WARNING: Unable to verify timestamp for PSHED.dll
*** ERROR: Module load completed but symbols could not be loaded for PSHED.dll
---------
Kernel base = 0xfffff800`02a02000 PsLoadedModuleList = 0xfffff800`02c3fe50
Debug session time: Wed Sep 8 19:49:46.295 2010 (GMT-4)
System Uptime: 0 days 0:52:19.153
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960001264b4, fffff8800992a140, 0}
Unable to load image \SystemRoot\System32\win32k.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : win32k.sys ( win32k+c64b4 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960001264b4, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff8800992a140, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k+c64b4
fffff960`001264b4 f30f7f808c010000 movdqu xmmword ptr [rax+18Ch],xmm0
CONTEXT: fffff8800992a140 -- (.cxr 0xfffff8800992a140)
rax=000000000101020d rbx=fffff900c00bf010 rcx=0000000000000000
rdx=fffff900c1e8d380 rsi=fffff900c06bb010 rdi=fffffa8005aff9a0
rip=fffff960001264b4 rsp=fffff8800992ab10 rbp=fffff8800992aca0
r8=0000000000000002 r9=fffff900c06bb210 r10=fffff900c0200000
r11=fffff900c06bb084 r12=0000000000000001 r13=0000000000000000
r14=fffff900c2a55010 r15=0000000000000001
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
win32k+0xc64b4:
fffff960`001264b4 f30f7f808c010000 movdqu xmmword ptr [rax+18Ch],xmm0 ds:002b:00000000`01010399=????????????????????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: winamp.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff960001264b4
STACK_TEXT:
fffff880`0992ab10 00000000`00000000 : 00000001`00000001 fffff900`c00bf010 fffff960`000da9e1 00000000`00000000 : win32k+0xc64b4
FOLLOWUP_IP:
win32k+c64b4
fffff960`001264b4 f30f7f808c010000 movdqu xmmword ptr [rax+18Ch],xmm0
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k+c64b4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c4840
STACK_COMMAND: .cxr 0xfffff8800992a140 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k+c64b4
BUCKET_ID: X64_0x3B_win32k+c64b4
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02c4b000 PsLoadedModuleList = 0xfffff800`02e88e50
Debug session time: Thu Sep 9 10:20:53.337 2010 (GMT-4)
System Uptime: 0 days 1:48:36.194
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {0, 0, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiKernelCalloutExceptionHandler+e )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 0000000000000000, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (Win32) 0 (0) - The operation completed successfully.
FAULTING_IP:
+5cab952f01eadf7c
00000000`00000000 ?? ???
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: System
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff80000ba2558 -- (.exr 0xfffff80000ba2558)
ExceptionAddress: fffff80002cc02d6 (nt!KiDeferredReadyThread+0x00000000000003f6)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff80000ba2600 -- (.trap 0xfffff80000ba2600)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000000000000f rbx=0000000000000000 rcx=fffffa8005b61b60
rdx=ffffffffffffffff rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002cc02d6 rsp=fffff80000ba2790 rbp=0000000000000000
r8=0000000000000008 r9=0000000000000008 r10=fffff80002c4b000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KiDeferredReadyThread+0x3f6:
fffff800`02cc02d6 a12003000080f7ffff mov eax,dword ptr [FFFFF78000000320h] ds:fffff780`00000320=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cb346e to fffff80002cbb710
STACK_TEXT:
fffff800`00ba1648 fffff800`02cb346e : 00000000`00000000 00000000`00000000 fffff800`00ba1dc0 fffff800`02ce8668 : nt!KeBugCheck
fffff800`00ba1650 fffff800`02ce140d : fffff800`02ec9b7c fffff800`02e03e84 fffff800`02c4b000 fffff800`00ba2558 : nt!KiKernelCalloutExceptionHandler+0xe
fffff800`00ba1680 fffff800`02ce8a90 : fffff800`02e0aa40 fffff800`00ba16f8 fffff800`00ba2558 fffff800`02c4b000 : nt!RtlpExecuteHandlerForException+0xd
fffff800`00ba16b0 fffff800`02cf59ef : fffff800`00ba2558 fffff800`00ba1dc0 fffff800`00000000 fffffa80`06f5b6d0 : nt!RtlDispatchException+0x410
fffff800`00ba1d90 fffff800`02cbad82 : fffff800`00ba2558 fffff800`02e35e80 fffff800`00ba2600 fffff800`02e35e80 : nt!KiDispatchException+0x16f
fffff800`00ba2420 fffff800`02cb968a : fffff800`00ba2700 00000000`00000001 fffffa80`070063b0 fffff880`0487fc07 : nt!KiExceptionDispatch+0xc2
fffff800`00ba2600 fffff800`02cc02d6 : fffffa80`06be1da8 fffffa80`063833b0 00000000`00000000 fffffa80`06be1da0 : nt!KiGeneralProtectionFault+0x10a
fffff800`00ba2790 fffff800`02cc6e67 : fffffa80`06be1da0 fffffa80`08ad5ce0 fffffa80`08ad5ce0 00000000`00000000 : nt!KiDeferredReadyThread+0x3f6
fffff800`00ba2810 fffff800`02cc74be : 0000000f`2bf46e5e fffff800`00ba2e88 00000000`00065fa6 fffff800`02e39748 : nt!KiProcessExpiredTimerList+0x157
fffff800`00ba2e60 fffff800`02cc6cb7 : fffff800`02e35ec1 fffffa80`00065fa6 fffffa80`058f12b0 00000000`000000a6 : nt!KiTimerExpiration+0x1be
fffff800`00ba2f00 fffff800`02cc1865 : 00000000`00000000 fffffa80`05b61b60 00000000`00000000 fffff880`0147bd80 : nt!KiRetireDpcList+0x277
fffff800`00ba2fb0 fffff800`02cc167c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxRetireDpcList+0x5
fffff880`079068c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiKernelCalloutExceptionHandler+e
fffff800`02cb346e 90 nop
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e
BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e
Followup: MachineOwner
---------