Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03005000 PsLoadedModuleList = 0xfffff800`03242e50
Debug session time: Sat Nov 27 14:32:49.101 2010 (GMT-5)
System Uptime: 0 days 0:01:00.911
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 6, {0, 0, 0, 0}
Probably caused by : win32k.sys ( win32k!PDEVOBJ::QueryFontData+97 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
INVALID_PROCESS_DETACH_ATTEMPT (6)
Arguments:
Arg1: 0000000000000000
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x6
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff800030ceb5b to fffff80003075710
STACK_TEXT:
fffff880`094274b8 fffff800`030ceb5b : fffff900`c0172cb8 fffff960`0011c5e9 00000000`00000068 00000000`ffffffff : nt!KeBugCheck
fffff880`094274c0 fffff960`000f0b77 : fffff960`0011c53c fffff900`c0172ca0 00000000`00000001 fffff800`00000000 : nt! ?? ::FNODOBFM::`string'+0xdf5f
fffff880`09427530 fffff960`000f0c83 : fffff900`c0172ca0 fffff900`c379d330 00000000`00000062 fffff880`09427730 : win32k!PDEVOBJ::QueryFontData+0x97
fffff880`094275c0 fffff960`000eda28 : fffff900`c0081000 fffff880`094277b0 00000000`00000040 fffff800`0308121b : win32k!xInsertMetricsRFONTOBJ+0xe3
fffff880`09427680 fffff960`0011a43a : 00000000`00000003 00000000`00000080 00000000`00000020 00000000`00000020 : win32k!RFONTOBJ::bGetGlyphMetrics+0x178
fffff880`09427700 fffff960`0011a190 : 00000000`7efdb001 fffff900`c020e388 fffff900`c2edf010 fffff960`00194682 : win32k!GreGetCharABCWidthsW+0x22a
fffff880`09427b20 fffff800`03074993 : 00000000`0c01097b 00000000`00000040 fffff900`00000040 00000000`00000000 : win32k!NtGdiGetCharABCWidthsW+0x1b0
fffff880`09427bb0 00000000`73801c7a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`000ddc98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73801c7a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!PDEVOBJ::QueryFontData+97
fffff960`000f0b77 4c8d9c2480000000 lea r11,[rsp+80h]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: win32k!PDEVOBJ::QueryFontData+97
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
FAILURE_BUCKET_ID: X64_0x6_win32k!PDEVOBJ::QueryFontData+97
BUCKET_ID: X64_0x6_win32k!PDEVOBJ::QueryFontData+97
Followup: MachineOwner
---------
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03014000 PsLoadedModuleList = 0xfffff800`03251e50
Debug session time: Sat Nov 27 15:35:27.092 2010 (GMT-5)
System Uptime: 0 days 0:58:10.902
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {fffff88004f91cc0, 69b0000035900101, fffff80000b9c910, a}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+409b4 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff88004f91cc0, Virtual address for the attempted write.
Arg2: 69b0000035900101, PTE contents.
Arg3: fffff80000b9c910, (reserved)
Arg4: 000000000000000a, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: System
CURRENT_IRQL: 8
TRAP_FRAME: fffff80000b9c910 -- (.trap 0xfffff80000b9c910)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000d00 rbx=0000000000000000 rcx=fffff88004f91cc0
rdx=000000000000ab0a rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003091c9e rsp=fffff80000b9caa8 rbp=fffff80000b9cb80
r8=000000000000ab08 r9=00000000ffffff00 r10=00000000ffffffff
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!KeReleaseSpinLockFromDpcLevel+0xe:
fffff800`03091c9e f048832100 lock and qword ptr [rcx],0 ds:dc00:fffff880`04f91cc0=c88303750af88341
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003103448 to fffff80003084740
STACK_TEXT:
fffff800`00b9c7a8 fffff800`03103448 : 00000000`000000be fffff880`04f91cc0 69b00000`35900101 fffff800`00b9c910 : nt!KeBugCheckEx
fffff800`00b9c7b0 fffff800`0308282e : 00000000`00000000 fffffa80`03fc9cc8 fffffa80`00000000 fffffa80`063f8000 : nt! ?? ::FNODOBFM::`string'+0x409b4
fffff800`00b9c910 fffff800`03091c9e : fffff800`03080347 fffffa80`03fc9cc8 fffffa80`03fc9cc0 fffffa80`03fc9cc0 : nt!KiPageFault+0x16e
fffff800`00b9caa8 fffff800`03080347 : fffffa80`03fc9cc8 fffffa80`03fc9cc0 fffffa80`03fc9cc0 fffff800`035fa895 : nt!KeReleaseSpinLockFromDpcLevel+0xe
fffff800`00b9cab0 fffff800`03080118 : 00000000`00000000 fffff800`00b9cb80 00000000`00000001 fffffa80`057cdc50 : nt!KiScanInterruptObjectList+0x77
fffff800`00b9cb00 fffff880`018147f2 : fffff800`0309224a 00000000`0039027f fffffa80`057f1598 fffff800`0320cc40 : nt!KiChainedDispatch+0x128
fffff800`00b9cc98 fffff800`0309224a : 00000000`0039027f fffffa80`057f1598 fffff800`0320cc40 00000000`00000001 : amdppm!C1Halt+0x2
fffff800`00b9cca0 fffff800`0308cebc : fffff800`031fee80 fffff800`00000000 00000000`00000000 fffff880`01412c50 : nt!PoIdle+0x53a
fffff800`00b9cd80 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cd40 00000000`00000000 : nt!KiIdleLoop+0x2c
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+409b4
fffff800`03103448 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+409b4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0xBE_nt!_??_::FNODOBFM::_string_+409b4
BUCKET_ID: X64_0xBE_nt!_??_::FNODOBFM::_string_+409b4
Followup: MachineOwner
---------
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03014000 PsLoadedModuleList = 0xfffff800`03251e50
Debug session time: Sat Nov 27 15:35:27.092 2010 (GMT-5)
System Uptime: 0 days 0:58:10.902
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {fffff88004f91cc0, 69b0000035900101, fffff80000b9c910, a}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+409b4 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff88004f91cc0, Virtual address for the attempted write.
Arg2: 69b0000035900101, PTE contents.
Arg3: fffff80000b9c910, (reserved)
Arg4: 000000000000000a, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: System
CURRENT_IRQL: 8
TRAP_FRAME: fffff80000b9c910 -- (.trap 0xfffff80000b9c910)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000d00 rbx=0000000000000000 rcx=fffff88004f91cc0
rdx=000000000000ab0a rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003091c9e rsp=fffff80000b9caa8 rbp=fffff80000b9cb80
r8=000000000000ab08 r9=00000000ffffff00 r10=00000000ffffffff
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!KeReleaseSpinLockFromDpcLevel+0xe:
fffff800`03091c9e f048832100 lock and qword ptr [rcx],0 ds:dc00:fffff880`04f91cc0=c88303750af88341
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003103448 to fffff80003084740
STACK_TEXT:
fffff800`00b9c7a8 fffff800`03103448 : 00000000`000000be fffff880`04f91cc0 69b00000`35900101 fffff800`00b9c910 : nt!KeBugCheckEx
fffff800`00b9c7b0 fffff800`0308282e : 00000000`00000000 fffffa80`03fc9cc8 fffffa80`00000000 fffffa80`063f8000 : nt! ?? ::FNODOBFM::`string'+0x409b4
fffff800`00b9c910 fffff800`03091c9e : fffff800`03080347 fffffa80`03fc9cc8 fffffa80`03fc9cc0 fffffa80`03fc9cc0 : nt!KiPageFault+0x16e
fffff800`00b9caa8 fffff800`03080347 : fffffa80`03fc9cc8 fffffa80`03fc9cc0 fffffa80`03fc9cc0 fffff800`035fa895 : nt!KeReleaseSpinLockFromDpcLevel+0xe
fffff800`00b9cab0 fffff800`03080118 : 00000000`00000000 fffff800`00b9cb80 00000000`00000001 fffffa80`057cdc50 : nt!KiScanInterruptObjectList+0x77
fffff800`00b9cb00 fffff880`018147f2 : fffff800`0309224a 00000000`0039027f fffffa80`057f1598 fffff800`0320cc40 : nt!KiChainedDispatch+0x128
fffff800`00b9cc98 fffff800`0309224a : 00000000`0039027f fffffa80`057f1598 fffff800`0320cc40 00000000`00000001 : amdppm!C1Halt+0x2
fffff800`00b9cca0 fffff800`0308cebc : fffff800`031fee80 fffff800`00000000 00000000`00000000 fffff880`01412c50 : nt!PoIdle+0x53a
fffff800`00b9cd80 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cd40 00000000`00000000 : nt!KiIdleLoop+0x2c
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+409b4
fffff800`03103448 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+409b4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0xBE_nt!_??_::FNODOBFM::_string_+409b4
BUCKET_ID: X64_0xBE_nt!_??_::FNODOBFM::_string_+409b4
Followup: MachineOwner
---------