PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff900c24835c0, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff9600036c69d, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030b00e0
GetUlongFromAddress: unable to read from fffff800030b0198
fffff900c24835c0
FAULTING_IP:
win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+2d
fffff960`0036c69d 488b4f20 mov rcx,qword ptr [rdi+20h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
TRAP_FRAME: fffff8800ba93920 -- (.trap 0xfffff8800ba93920)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000011 rbx=0000000000000000 rcx=fffff900c00f7280
rdx=000000000a12168f rsi=0000000000000000 rdi=0000000000000000
rip=fffff9600036c69d rsp=fffff8800ba93ab0 rbp=0000000000000001
r8=0000000000000000 r9=0000000000000410 r10=fffff80002e08000
r11=0000000000000020 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+0x2d:
fffff960`0036c69d 488b4f20 mov rcx,qword ptr [rdi+20h] ds:00000000`00000020=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002ef91e4 to fffff80002e79f00
STACK_TEXT:
fffff880`0ba937b8 fffff800`02ef91e4 : 00000000`00000050 fffff900`c24835c0 00000000`00000000 fffff880`0ba93920 : nt!KeBugCheckEx
fffff880`0ba937c0 fffff800`02e77fee : 00000000`00000000 fffff900`c00f7280 fffffa80`35616c00 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x42907
fffff880`0ba93920 fffff960`0036c69d : 00000000`00000000 00000000`0a12168f 00000000`0a12168f 00000000`00000001 : nt!KiPageFault+0x16e
fffff880`0ba93ab0 fffff960`0036bbae : fffff900`c00f7280 00000000`00000000 0000168f`624d4653 00000000`0000001d : win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+0x2d
fffff880`0ba93ae0 fffff960`0036cab3 : 00000000`00000000 00000000`0a12168f fffff900`c00f7280 00000000`0ada574c : win32k!SFMLOGICALSURFACE::DeInitialize+0x4e
fffff880`0ba93b20 fffff960`002c95ff : 00000000`00000000 fffff900`c00bf010 fffff900`c00f7280 00000000`00000020 : win32k!bhLSurfDestroyLogicalSurfaceObject+0x4b
fffff880`0ba93b60 fffff960`002ea908 : 00000000`00000001 00000000`00000001 fffff880`0ba93ca0 00000000`00000000 : win32k!GreSfmCloseCompositorRef+0x10f
fffff880`0ba93ba0 fffff800`02e79153 : fffffa80`088f8b60 fffff880`0ba93ca0 00000000`000000f0 fffffa80`088f75e0 : win32k!NtGdiHLSurfSetInformation+0x1a8
fffff880`0ba93c20 000007fe`fe404efa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`037af1c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x000007fe`fe404efa
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+2d
fffff960`0036c69d 488b4f20 mov rcx,qword ptr [rdi+20h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+2d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: [COLOR=red]win32k.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc5e0
IMAGE_VERSION: 6.1.7600.16385
FAILURE_BUCKET_ID: X64_0x50_win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+2d
BUCKET_ID: X64_0x50_win32k!SFMLOGICALSURFACE::OwnsSurfaceCleanup+2d
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x50_win32k!sfmlogicalsurface::ownssurfacecleanup+2d
FAILURE_ID_HASH: {422c0597-aeb5-515f-65d6-15149510f84c}
Followup: MachineOwner