*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff9600026c9ed, fffff8800c8c8100, 0}
Probably caused by : win32k.sys ( win32k!MulAssociateSharedSurface+15 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff9600026c9ed, Address of the instruction which caused the bugcheck
Arg3: fffff8800c8c8100, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'ksaud' and 'ksaud.sys' overlap
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!MulAssociateSharedSurface+15
fffff960`0026c9ed 4c8b98300d0000 mov r11,qword ptr [rax+0D30h]
CONTEXT: fffff8800c8c8100 -- (.cxr 0xfffff8800c8c8100;r)
rax=0000000000000000 rbx=fffff900c38c2350 rcx=fffffa8008213b00
rdx=00000000c0003840 rsi=fffff900c51e2028 rdi=fffff900c38c23e8
rip=fffff9600026c9ed rsp=fffff8800c8c8ae0 rbp=ffffffffb1122195
r8=ffffffffb1122195 r9=0000001b000000a0 r10=0000000000000000
r11=fffff8800c8c8b08 r12=fffff900c0134010 r13=00000000c0003840
r14=0000000006cbd2e0 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!MulAssociateSharedSurface+0x15:
fffff960`0026c9ed 4c8b98300d0000 mov r11,qword ptr [rax+0D30h] ds:002b:00000000`00000d30=????????????????
Last set context:
rax=0000000000000000 rbx=fffff900c38c2350 rcx=fffffa8008213b00
rdx=00000000c0003840 rsi=fffff900c51e2028 rdi=fffff900c38c23e8
rip=fffff9600026c9ed rsp=fffff8800c8c8ae0 rbp=ffffffffb1122195
r8=ffffffffb1122195 r9=0000001b000000a0 r10=0000000000000000
r11=fffff8800c8c8b08 r12=fffff900c0134010 r13=00000000c0003840
r14=0000000006cbd2e0 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
win32k!MulAssociateSharedSurface+0x15:
fffff960`0026c9ed 4c8b98300d0000 mov r11,qword ptr [rax+0D30h] ds:002b:00000000`00000d30=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
LAST_CONTROL_TRANSFER: from fffff960002177bd to fffff9600026c9ed
STACK_TEXT:
fffff880`0c8c8ae0 fffff960`002177bd : 00000000`00000000 ffffffff`b1122195 00000000`021ff730 fffff8a0`0076d000 : win32k!MulAssociateSharedSurface+0x15
fffff880`0c8c8b10 fffff960`0023a969 : 00000000`00000001 fffff880`0c8c8c60 00000000`021ff730 00000000`0000a18b : win32k!GreSetRedirectionSurfaceSignaling+0x125
fffff880`0c8c8b60 fffff800`02287153 : fffffa80`09f22060 fffffa80`09492060 00000000`0031100b fffffa80`09492060 : win32k!NtGdiHLSurfSetInformation+0x209
fffff880`0c8c8be0 000007fe`fe1a4efa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`021ff668 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x000007fe`fe1a4efa
FOLLOWUP_IP:
win32k!MulAssociateSharedSurface+15
fffff960`0026c9ed 4c8b98300d0000 mov r11,qword ptr [rax+0D30h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!MulAssociateSharedSurface+15
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc5e0
IMAGE_VERSION: 6.1.7600.16385
STACK_COMMAND: .cxr 0xfffff8800c8c8100 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!MulAssociateSharedSurface+15
BUCKET_ID: X64_0x3B_win32k!MulAssociateSharedSurface+15
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x3b_win32k!mulassociatesharedsurface+15
FAILURE_ID_HASH: {08b97eea-ad52-6762-8e6c-277f3c48177d}
Followup: MachineOwner
---------