.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {300100000009, 2, 1, fffff80002cd6266}
Probably caused by : win32k.sys ( win32k!TimersProc+197 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000300100000009, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002cd6266, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002efa100
0000300100000009
CURRENT_IRQL: 2
FAULTING_IP:
nt!KiInsertTimerTable+c6
fffff800`02cd6266 4c894008 mov qword ptr [rax+8],r8
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: csrss.exe
TRAP_FRAME: fffff880023127e0 -- (.trap 0xfffff880023127e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000300100000001 rbx=0000000000000000 rcx=0000000000019283
rdx=fffff80002e64f90 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002cd6266 rsp=fffff88002312970 rbp=fffffa8005235538
r8=fffffa8007830cb0 r9=000000000000006b r10=fffff80002e3de80
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!KiInsertTimerTable+0xc6:
fffff800`02cd6266 4c894008 mov qword ptr [rax+8],r8 ds:00003001`00000009=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cca769 to fffff80002ccb1c0
STACK_TEXT:
fffff880`02312698 fffff800`02cca769 : 00000000`0000000a 00003001`00000009 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`023126a0 fffff800`02cc93e0 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`07830c90 : nt!KiBugCheckDispatch+0x69
fffff880`023127e0 fffff800`02cd6266 : 00000000`00000202 fffff800`02cd081a fffff880`009e7180 fffffa80`08821510 : nt!KiPageFault+0x260
fffff880`02312970 fffff800`02cd5fa0 : ffffffff`fffca4a0 fffff800`02e3de80 fffffa80`07830c90 00000000`00000000 : nt!KiInsertTimerTable+0xc6
fffff880`023129d0 fffff800`02cd5ea4 : fffff900`c064ddf0 ffffffff`fffca4a0 00000000`00000000 fffff960`00000002 : nt!KiSetTimerEx+0xf0
fffff880`02312a60 fffff960`00144b77 : 00000000`00000000 00000000`00000001 00000000`00000004 fffff800`02cd4033 : nt!KeSetTimer+0x14
fffff880`02312aa0 fffff960`0014554b : 00000000`00000000 fffff960`00365f10 00000000`00000004 00000000`00000001 : win32k!TimersProc+0x197
fffff880`02312af0 fffff960`000d5098 : fffffa80`0000007b 00000000`0000000f fffff880`00000001 ffffffff`800002e4 : win32k!RawInputThread+0x9ab
fffff880`02312bc0 fffff960`00155d9a : fffffa80`00000002 fffff880`01fe5f40 00000000`00000020 00000000`00000000 : win32k!xxxCreateSystemThreads+0x58
fffff880`02312bf0 fffff800`02cca453 : fffffa80`078b6980 00000000`00000004 000007ff`fffae000 00000000`00000000 : win32k!NtUserCallNoParam+0x36
fffff880`02312c20 000007fe`fd761eea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`002ef798 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd761eea
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!TimersProc+197
fffff960`00144b77 488b5c2450 mov rbx,qword ptr [rsp+50h]
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: win32k!TimersProc+197
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 5006fd0d
FAILURE_BUCKET_ID: X64_0xA_win32k!TimersProc+197
BUCKET_ID: X64_0xA_win32k!TimersProc+197
Followup: MachineOwner
---------
0: kd> .trap 0xfffff880023127e0
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000300100000001 rbx=0000000000000000 rcx=0000000000019283
rdx=fffff80002e64f90 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002cd6266 rsp=fffff88002312970 rbp=fffffa8005235538
r8=fffffa8007830cb0 r9=000000000000006b r10=fffff80002e3de80
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!KiInsertTimerTable+0xc6:
fffff800`02cd6266 4c894008 mov qword ptr [rax+8],r8 ds:00003001`00000009=????????????????
0: kd> kv
*** Stack trace for last set context - .thread/.cxr resets it
Child-SP RetAddr : Args to Child : Call Site
fffff880`02312970 fffff800`02cd5fa0 : ffffffff`fffca4a0 fffff800`02e3de80 fffffa80`07830c90 00000000`00000000 : nt!KiInsertTimerTable+0xc6
fffff880`023129d0 fffff800`02cd5ea4 : fffff900`c064ddf0 ffffffff`fffca4a0 00000000`00000000 fffff960`00000002 : nt!KiSetTimerEx+0xf0
fffff880`02312a60 fffff960`00144b77 : 00000000`00000000 00000000`00000001 00000000`00000004 fffff800`02cd4033 : nt!KeSetTimer+0x14
fffff880`02312aa0 fffff960`0014554b : 00000000`00000000 fffff960`00365f10 00000000`00000004 00000000`00000001 : win32k!TimersProc+0x197
fffff880`02312af0 fffff960`000d5098 : fffffa80`0000007b 00000000`0000000f fffff880`00000001 ffffffff`800002e4 : win32k!RawInputThread+0x9ab
fffff880`02312bc0 fffff960`00155d9a : fffffa80`00000002 fffff880`01fe5f40 00000000`00000020 00000000`00000000 : win32k!xxxCreateSystemThreads+0x58
fffff880`02312bf0 fffff800`02cca453 : fffffa80`078b6980 00000000`00000004 000007ff`fffae000 00000000`00000000 : win32k!NtUserCallNoParam+0x36
fffff880`02312c20 000007fe`fd761eea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`02312c20)
00000000`002ef798 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd761eea
0: kd> .trap fffff880`02312c20
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=000007fefd763734
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=000007fefd761eea rsp=00000000002ef798 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
0033:000007fe`fd761eea ?? ???
0: kd> kv
*** Stack trace for last set context - .thread/.cxr resets it
Child-SP RetAddr : Args to Child : Call Site
00000000`002ef798 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd761eea