1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Dump Data

Discussion in 'Windows 7' started by TheBola, 2011/05/19.

  1. 2011/05/19
    TheBola

    TheBola Inactive Thread Starter

    Joined:
    2011/05/19
    Messages:
    4
    Likes Received:
    0
    Hey all, I read the Dump Data collection tool and instructions and got the Mother of all dumps!

    I build my computer about 6/7 months ago but recently I've been getting completely random desktop windows manager crashes. Then last night my Pc was idle so the screens turned of but when I moved my mouse to bring them back up, it displayed my desktop then flickered and went to The Blue screen of death! I'm trying to get to the bottom of the problem (mainly the issue with DWM randomly crashing), could you help me out?


    Opened log file 'c:debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Windows\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    WARNING: Whitespace at end of path element
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/...ls*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\Windows;C:\Windows\system32;C:\Windows\system32\drivers
    Windows 7 Kernel Version 7600 MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
    Machine Name:
    Kernel base = 0xfffff800`02a06000 PsLoadedModuleList = 0xfffff800`02c43e50
    Debug session time: Thu May 19 02:21:46.125 2011 (UTC - 4:00)
    System Uptime: 0 days 4:23:05.295
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ............................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 00000000`7efdf018). Type ".hh dbgerr001" for details
    Loading unloaded module list
    ......

    3: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff96000179dad, Address of the instruction which caused the bugcheck
    Arg3: fffff8800805ef00, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.

    Debugging Details:
    ------------------

    Page 12c7dc not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d47b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de8a not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de0b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e191 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c231 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3b2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2b4 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bfb5 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bfbf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c851 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2e8 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d469 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d6eb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfec not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d46d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2ef not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d670 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cef1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2f2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d373 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d274 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d0f5 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d4f6 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d477 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d278 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d379 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d17a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d3fb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d67c not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d6fd not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e109 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e08d not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df8e not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de13 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc94 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11d815 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd96 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df97 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd18 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e119 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e11d not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df1e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b621 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b4a5 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c7d9 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c6da not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cd65 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d268 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2ea not present in the dump file. Type ".hh dbgerr004" for details
    Page 11d981 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc87 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df88 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e089 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd8a not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd0b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df0c not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e10f not present in the dump file. Type ".hh dbgerr004" for details
    Page 11d795 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd16 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b627 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12baae not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c1b4 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3b7 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c0b9 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2bb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2bc not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3bd not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bebf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c140 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc3 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d044 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12ce45 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c1c6 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c4cc not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c34d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c54e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2cf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2d0 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c751 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c8d2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c759 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c85b not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c7dd not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c7de not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3df not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d167 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d26a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d5eb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12ceec not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d1ef not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d570 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cdf1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d377 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d1f8 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d279 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d0fa not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc8b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de97 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc18 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e019 not present in the dump file. Type ".hh dbgerr004" for details

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

    FAULTING_IP:
    win32k!HMFreeObject+59
    fffff960`00179dad 488b8058010000 mov rax,qword ptr [rax+158h]

    CONTEXT: fffff8800805ef00 -- (.cxr 0xfffff8800805ef00)
    .cxr 0xfffff8800805ef00
    rax=ffdff900c3b91370 rbx=fffff900c0407aa0 rcx=fffff960003571bc
    rdx=fffff900c0c00b90 rsi=fffff900c0c67540 rdi=fffff900c0c67540
    rip=fffff96000179dad rsp=fffff8800805f8e0 rbp=fffff900c0c67539
    r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
    r11=fffff8800805f910 r12=fffff900c0c4d4c0 r13=0000000000000001
    r14=000000000008e4f0 r15=0000000073fe2450
    iopl=0 nv up ei pl nz na pe nc
    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
    win32k!HMFreeObject+0x59:
    fffff960`00179dad 488b8058010000 mov rax,qword ptr [rax+158h] ds:002b:ffdff900`c3b914c8=????????????????
    .cxr
    Resetting default scope

    DEFAULT_BUCKET_ID: CODE_CORRUPTION

    BUGCHECK_STR: 0x3B

    PROCESS_NAME: iTunes.exe

    CURRENT_IRQL: 0

    LAST_CONTROL_TRANSFER: from fffff9600017f572 to fffff96000179dad

    STACK_TEXT:
    fffff880`0805f8e0 fffff960`0017f572 : fffffa80`05d33dc0 fffff900`c0c67598 00000000`00000000 fffff900`c0c67540 : win32k!HMFreeObject+0x59
    fffff880`0805f920 fffff960`0017fd40 : 00000000`00000000 fffff900`c0c67540 fffff900`c3b91370 fffffa80`0603f090 : win32k!xxxFreeWindow+0x1332
    fffff880`0805fa20 fffff960`0017ffcd : 00000000`00000000 fffff900`c0c67540 fffff900`c0c00b90 fffff900`c0c63fa0 : win32k!xxxDestroyWindow+0x6e0
    fffff880`0805fad0 fffff960`0017fa55 : fffff900`c0c63fa0 fffff900`c0c63fa0 00000000`00000000 00000000`00000000 : win32k!xxxDW_DestroyOwnedWindows+0x9d
    fffff880`0805fb10 fffff960`00180583 : 00000000`00000000 00000000`00000000 fffff880`0805fca0 fffffa80`05e04d8c : win32k!xxxDestroyWindow+0x3f5
    fffff880`0805fbc0 fffff880`018201ae : 00000000`000104e6 fffff880`0805fca0 fffff960`00180548 00000000`77c3f992 : win32k!NtUserDestroyWindow+0x3b
    fffff880`0805fbf0 fffff800`02a77153 : 00000000`76161e83 fffff960`00180548 00000000`7efdb000 00000000`00000020 : aswSnx+0x201ae
    fffff880`0805fc20 00000000`73fe2dd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`0008e478 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73fe2dd9


    CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
    !chkimg -lo 50 -d !win32k
    fffff960000d6e3d-fffff960000d6e44 8 bytes - win32k!ESTROBJ::bOpaqueArea+401

    [ 90 90 90 90 90 90 90 90:48 02 82 01 80 f8 ff ff ]
    fffff960000eae30-fffff960000eae35 6 bytes - win32k!NtUserSwitchDesktop (+0x13ff3)

    [ 48 89 5c 24 08 57:ff 25 76 c1 1b 00 ]
    fffff96000124c70-fffff96000124c75 6 bytes - win32k!NtGdiOpenDCW (+0x39e40)

    [ 48 8b c4 48 89 58:ff 25 6d 59 06 00 ]
    fffff9600012e09c-fffff9600012e0a1 6 bytes - win32k!NtUserSetWindowsHookEx (+0x942c)

    [ 48 89 5c 24 18 48:ff 25 55 f3 05 00 ]
    fffff96000136548-fffff9600013654d 6 bytes - win32k!NtGdiDeleteObjectApp (+0x84ac)

    [ 48 89 5c 24 08 57:ff 25 0e c5 01 00 ]
    fffff96000143e38-fffff96000143e3f 8 bytes - win32k!NtUserThunkedMenuItemInfo+1b8 (+0xd8f0)

    [ 90 90 90 90 90 90 90 90:e0 00 82 01 80 f8 ff ff ]
    fffff9600014c2c4-fffff9600014c2cb 8 bytes - win32k!CalcForegroundInsertAfter+144 (+0x848c)

    [ 90 90 90 90 90 90 90 90:28 04 82 01 80 f8 ff ff ]
    fffff96000152a5c-fffff96000152a63 8 bytes - win32k!NtUserfnNCDESTROY+2c (+0x6798)

    [ 90 90 90 90 90 90 90 90:28 14 82 01 80 f8 ff ff ]
    fffff960001669ec-fffff960001669f3 8 bytes - win32k!GreCreateDisplayDC+3b8 (+0x13f90)

    [ 90 90 90 90 90 90 90 90:9c 06 82 01 80 f8 ff ff ]
    fffff96000169794-fffff96000169799 6 bytes - win32k!NtUserSystemParametersInfo (+0x2da8)

    [ 44 89 4c 24 20 4c:ff 25 dd 43 02 00 ]
    fffff96000180549-fffff9600018054d 5 bytes - win32k!NtUserDestroyWindow+1 (+0x16db5)

    [ f3 48 83 ec 20:25 45 5f 00 00 ]
    fffff96000182bff-fffff96000182c02 4 bytes - win32k!W32pServiceTable+fff (+0x26b6)

    [ ff c0 2c 2c:00 00 00 00 ]
    fffff96000182c04-fffff96000182c0a 7 bytes - win32k!W32pServiceTable+1004 (+0x05)

    [ 60 f9 ff ff f4 27 2c:00 00 00 00 00 00 00 ]
    fffff96000182c0c-fffff96000182c22 23 bytes - win32k!W32pServiceTable+100c (+0x08)

    [ 60 f9 ff ff c8 83 2b 00:00 00 00 00 00 00 00 01 ]
    fffff96000182c24-fffff96000182c26 3 bytes - win32k!W32pServiceTable+1024 (+0x18)

    [ 60 f9 ff:00 00 00 ]
    fffff96000185f3c-fffff96000185f41 6 bytes - win32k!NtUserOpenDesktop (+0x3318)

    [ 48 89 5c 24 08 48:ff 25 82 63 fc ff ]
    fffff96000186493-fffff9600018649a 8 bytes - win32k!NtUserDragObject+153 (+0x557)

    [ 90 90 90 90 90 90 90 90:80 01 82 01 80 f8 ff ff ]
    fffff96000186946-fffff9600018694d 8 bytes - win32k!NtUserRealInternalGetMessage+c6 (+0x4b3)

    [ 90 90 90 90 90 90 90 90:00 02 82 01 80 f8 ff ff ]
    fffff96000188158-fffff9600018815d 6 bytes - win32k!NtUserSetWinEventHook (+0x1812)

    [ 48 89 5c 24 08 48:ff 25 71 04 0b 00 ]
    fffff96000189220-fffff96000189225 6 bytes - win32k!NtUserGetClipboardData (+0x10c8)

    [ 48 89 5c 24 08 48:ff 25 dd 93 11 00 ]
    fffff96000189e90-fffff96000189e95 6 bytes - win32k!NtUserCallHwndParamLock (+0xc70)

    [ 48 89 5c 24 08 48:ff 25 a2 9f fb ff ]
    fffff9600018a5e3-fffff9600018a5ea 8 bytes - win32k!NtUserPaintMonitor+17b (+0x753)

    [ 90 90 90 90 90 90 90 90:8c 13 82 01 80 f8 ff ff ]
    fffff9600018aee7-fffff9600018aeee 8 bytes - win32k!NtUserGetPriorityClipboardFormat+af (+0x904)

    [ 90 90 90 90 90 90 90 90:fc 07 82 01 80 f8 ff ff ]
    fffff9600018bad0-fffff9600018bad7 8 bytes - win32k!NtUserSetActiveWindow+98 (+0xbe9)

    [ 90 90 90 90 90 90 90 90:84 1b 82 01 80 f8 ff ff ]
    fffff9600018bc50-fffff9600018bc55 6 bytes - win32k!NtUserSetClipboardViewer (+0x180)

    [ 48 89 5c 24 08 57:ff 25 8f 46 00 00 ]
    fffff9600018c094-fffff9600018c099 6 bytes - win32k!NtUserSetSysColors (+0x444)

    [ 48 8b c4 48 89 58:ff 25 41 e3 11 00 ]
    fffff9600018d3f7-fffff9600018d3fe 8 bytes - win32k!NtUserGetDCEx+167 (+0x1363)

    [ 90 90 90 90 90 90 90 90:58 ff 81 01 80 f8 ff ff ]
    fffff9600018db77-fffff9600018db7e 8 bytes - win32k!NtUserSetWindowRgnEx+1cb (+0x780)

    [ 90 90 90 90 90 90 90 90:c0 ff 81 01 80 f8 ff ff ]
    fffff9600018f320-fffff9600018f325 6 bytes - win32k!NtUserBuildNameList (+0x17a9)

    [ 48 89 5c 24 08 48:ff 25 c6 76 fd ff ]
    fffff9600018f840-fffff9600018f845 6 bytes - win32k!NtUserSendInput (+0x520)

    [ 48 8b c4 48 89 58:ff 25 f7 75 f4 ff ]
    fffff9600018f9ac-fffff9600018f9b1 6 bytes - win32k!NtUserBlockInput (+0x16c)

    [ 48 89 5c 24 08 48:ff 25 94 6f ff ff ]
    fffff960001902e5-fffff960001902ec 8 bytes - win32k!NtUserGetInputLocaleInfo+11d (+0x939)

    [ 90 90 90 90 90 90 90 90:f4 02 82 01 80 f8 ff ff ]
    fffff9600019037c-fffff96000190383 8 bytes - win32k!NtUserMapVirtualKeyEx+8c (+0x97)

    [ 90 90 90 90 90 90 90 90:74 1e 82 01 80 f8 ff ff ]
    Page 12c7dc not present in the dump file. Type ".hh dbgerr004" for details
    fffff960001904eb-fffff960001904f2 8 bytes - win32k!NtUserGetProp+7b (+0x16f)

    [ 90 90 90 90 90 90 90 90:2c 18 82 01 80 f8 ff ff ]
    fffff960001950b1-fffff960001950b8 8 bytes - win32k!NtUserNotifyIMEStatus+a5 (+0x4bc6)

    [ 90 90 90 90 90 90 90 90:c8 19 82 01 80 f8 ff ff ]
    Page 12d47b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de8a not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de0b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e191 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c231 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3b2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2b4 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bfb5 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bfbf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c851 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2e8 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d469 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d6eb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfec not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d46d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2ef not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d670 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cef1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2f2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d373 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d274 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d0f5 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d4f6 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d477 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d278 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d379 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d17a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d3fb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d67c not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d6fd not present in the dump file. Type ".hh dbgerr004" for details
    fffff96000196880-fffff96000196885 6 bytes - win32k!NtUserRegisterRawInputDevices (+0x17cf)

    [ 48 89 5c 24 10 56:ff 25 61 46 ff ff ]
    fffff960002385cf-fffff960002385d6 8 bytes - win32k!NtGdiD3dValidateTextureStageState+b (+0xa1d4f)

    [ 90 90 90 90 90 90 90 90:08 fe 81 01 80 f8 ff ff ]
    Page 11e109 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e08d not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df8e not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de13 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc94 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11d815 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd96 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df97 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd18 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e119 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e11d not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df1e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b621 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b4a5 not present in the dump file. Type ".hh dbgerr004" for details
    fffff9600023cb08-fffff9600023cb0d 6 bytes - win32k!NtGdiAlphaBlend (+0x4539)

    [ 4c 8b dc 45 89 4b:ff 25 6e 38 f5 ff ]
    Page 12c7d9 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c6da not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cd65 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d268 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d2ea not present in the dump file. Type ".hh dbgerr004" for details
    fffff9600028f964-fffff9600028f969 6 bytes - win32k!NtGdiPlgBlt (+0x52e5c)

    [ 48 8b c4 44 89 48:ff 25 66 c1 ef ff ]
    fffff960002a2603-fffff960002a260a 8 bytes - win32k!XLATE::pfnXlateBetweenBitfields+5f (+0x12c9f)

    [ 90 90 90 90 90 90 90 90:3c 03 82 01 80 f8 ff ff ]
    fffff960002a2d00-fffff960002a2d05 6 bytes - win32k!NtGdiBitBltInternal (+0x6fd)

    [ 48 8b c4 48 89 58:ff 25 65 a7 00 00 ]
    fffff960002a626f-fffff960002a6276 8 bytes - win32k!CaptureDriverInfo2W+317 (+0x356f)

    [ 90 90 90 90 90 90 90 90:f8 1c 82 01 80 f8 ff ff ]
    fffff960002a6fad-fffff960002a6fb3 7 bytes - win32k!NtGdiSetMetaRgn+59 (+0xd3e)

    [ 90 90 90 90 90 90 90:06 82 01 80 f8 ff ff ]
    fffff960002a7228-fffff960002a722d 6 bytes - win32k!NtGdiMaskBlt (+0x27b)

    [ 48 83 ec 78 8b 84:ff 25 83 de ee ff ]
    fffff960002a8140-fffff960002a8145 6 bytes - win32k!NtGdiStretchBlt (+0xf18)

    [ 48 83 ec 78 83 64:ff 25 a5 83 ee ff ]
    fffff960002a9f94-fffff960002a9f9b 8 bytes - win32k!NtGdiTransformPoints+158 (+0x1e54)

    [ 90 90 90 90 90 90 90 90:d8 14 82 01 80 f8 ff ff ]
    fffff960002aa3db-fffff960002aa3e2 8 bytes - win32k!NtGdiGetFontUnicodeRanges+ab (+0x447)

    [ 90 90 90 90 90 90 90 90:68 00 82 01 80 f8 ff ff ]
    fffff960002ad46b-fffff960002ad472 8 bytes - win32k!GreLineTo+857 (+0x3090)

    [ 90 90 90 90 90 90 90 90:1c 15 82 01 80 f8 ff ff ]
    Page 11d981 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc87 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df88 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e089 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd8a not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd0b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11df0c not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e10f not present in the dump file. Type ".hh dbgerr004" for details
    Page 11d795 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dd16 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12b627 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12baae not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c1b4 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3b7 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c0b9 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2bb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2bc not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3bd not present in the dump file. Type ".hh dbgerr004" for details
    Page 12bebf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c140 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cfc3 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d044 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12ce45 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c1c6 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c4cc not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c34d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c54e not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2cf not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c2d0 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c751 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c8d2 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c759 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c85b not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c7dd not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c7de not present in the dump file. Type ".hh dbgerr004" for details
    Page 12c3df not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d167 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d26a not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d5eb not present in the dump file. Type ".hh dbgerr004" for details
    Page 12ceec not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d36d not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d1ef not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d570 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12cdf1 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d377 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d1f8 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d279 not present in the dump file. Type ".hh dbgerr004" for details
    Page 12d0fa not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc8b not present in the dump file. Type ".hh dbgerr004" for details
    Page 11de97 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11dc18 not present in the dump file. Type ".hh dbgerr004" for details
    Page 11e019 not present in the dump file. Type ".hh dbgerr004" for details
    fffff960002b7954-fffff960002b7959 6 bytes - win32k!NtGdiGetPixel (+0xa4e9)

    [ 48 8b c4 48 89 58:ff 25 3a 26 ff ff ]
    351 errors : !win32k (fffff960000d6e3d-fffff960002b7959)

    MODULE_NAME: memory_corruption

    IMAGE_NAME: memory_corruption

    FOLLOWUP_NAME: memory_corruption

    DEBUG_FLR_IMAGE_TIMESTAMP: 0

    MEMORY_CORRUPTOR: LARGE

    STACK_COMMAND: .cxr 0xfffff8800805ef00 ; kb

    FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

    BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE

    Followup: memory_corruption
    ---------

    rax=fffff8800805e740 rbx=fffff80002bc61e8 rcx=000000000000003b
    rdx=00000000c0000005 rsi=fffff80002a06000 rdi=0000000000000000
    rip=fffff80002a77f00 rsp=fffff8800805e638 rbp=0000000000000000
    r8=fffff96000179dad r9=fffff8800805ef00 r10=0000000000000000
    r11=fffff8800805e838 r12=fffff80002a77153 r13=fffff80002c84354
    r14=fffff80002a76d40 r15=0000000000000000
    iopl=0 nv up ei ng nz na pe nc
    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000282
    nt!KeBugCheckEx:
    fffff800`02a77f00 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffff880`0805e640=000000000000003b
    Child-SP RetAddr : Args to Child : Call Site
    fffff880`0805e638 fffff800`02a77469 : 00000000`0000003b 00000000`c0000005 fffff960`00179dad fffff880`0805ef00 : nt!KeBugCheckEx
    fffff880`0805e640 fffff800`02a76dbc : 00000000`00000000 fffff800`02a8ec78 fffffa80`05c8ba00 fffffa80`0642f760 : nt!KiBugCheckDispatch+0x69
    fffff880`0805e780 fffff800`02a9dbed : fffff880`01888c54 fffff880`0185d730 fffff880`01800000 fffff880`0805f6a8 : nt!KiSystemServiceHandler+0x7c
    fffff880`0805e7c0 fffff800`02aa5250 : fffff800`02bc61e8 fffff880`0805e838 fffff880`0805f6a8 fffff800`02a06000 : nt!RtlpExecuteHandlerForException+0xd
    fffff880`0805e7f0 fffff800`02ab21b5 : fffff880`0805f6a8 fffff880`0805ef00 fffff880`00000000 fffff900`c0c67540 : nt!RtlDispatchException+0x410
    fffff880`0805eed0 fffff800`02a77542 : fffff880`0805f6a8 fffff900`c0407aa0 fffff880`0805f750 fffff900`c0c67540 : nt!KiDispatchException+0x135
    fffff880`0805f570 fffff800`02a75e4a : 00000000`00000003 fffff900`c0c00208 00000000`00000000 fffff8a0`0966a360 : nt!KiExceptionDispatch+0xc2
    fffff880`0805f750 fffff960`00179dad : 00000000`00000000 00000000`00000000 00000000`00000000 0001051c`40000013 : nt!KiGeneralProtectionFault+0x10a (TrapFrame @ fffff880`0805f750)
    fffff880`0805f8e0 fffff960`0017f572 : fffffa80`05d33dc0 fffff900`c0c67598 00000000`00000000 fffff900`c0c67540 : win32k!HMFreeObject+0x59
    fffff880`0805f920 fffff960`0017fd40 : 00000000`00000000 fffff900`c0c67540 fffff900`c3b91370 fffffa80`0603f090 : win32k!xxxFreeWindow+0x1332
    fffff880`0805fa20 fffff960`0017ffcd : 00000000`00000000 fffff900`c0c67540 fffff900`c0c00b90 fffff900`c0c63fa0 : win32k!xxxDestroyWindow+0x6e0
    fffff880`0805fad0 fffff960`0017fa55 : fffff900`c0c63fa0 fffff900`c0c63fa0 00000000`00000000 00000000`00000000 : win32k!xxxDW_DestroyOwnedWindows+0x9d
    fffff880`0805fb10 fffff960`00180583 : 00000000`00000000 00000000`00000000 fffff880`0805fca0 fffffa80`05e04d8c : win32k!xxxDestroyWindow+0x3f5
    fffff880`0805fbc0 fffff880`018201ae : 00000000`000104e6 fffff880`0805fca0 fffff960`00180548 00000000`77c3f992 : win32k!NtUserDestroyWindow+0x3b
    fffff880`0805fbf0 fffff800`02a77153 : 00000000`76161e83 fffff960`00180548 00000000`7efdb000 00000000`00000020 : aswSnx+0x201ae
    fffff880`0805fc20 00000000`73fe2dd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`0805fc20)
    00000000`0008e478 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73fe2dd9
    start end module name
    fffff800`00bbf000 fffff800`00bc9000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
    fffff800`02a06000 fffff800`02fe3000 nt ntkrnlmp.exe Mon Jul 13 19:40:48 2009 (4A5BC600)
    fffff800`02fe3000 fffff800`0302c000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
    fffff880`00c00000 fffff880`00c5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
    fffff880`00c5c000 fffff880`00c86000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
    fffff880`00c88000 fffff880`00ccc000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
    fffff880`00ccc000 fffff880`00ce0000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
    fffff880`00ce0000 fffff880`00d3e000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00d3e000 fffff880`00dfe000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
    fffff880`00e00000 fffff880`00e33000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`00e33000 fffff880`00e40000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
    fffff880`00e40000 fffff880`00e55000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00e55000 fffff880`00e6a000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00e6a000 fffff880`00e71000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
    fffff880`00e71000 fffff880`00e81000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`00e81000 fffff880`00e9b000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00e9b000 fffff880`00ea4000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00ea4000 fffff880`00eaf000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
    fffff880`00eba000 fffff880`00f5e000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
    fffff880`00f5e000 fffff880`00f6d000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00f6d000 fffff880`00fc4000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
    fffff880`00fc4000 fffff880`00fcd000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`00fcd000 fffff880`00fd7000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
    fffff880`01000000 fffff880`0104c000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
    fffff880`0104c000 fffff880`01086000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
    fffff880`0108b000 fffff880`010d7000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
    fffff880`010d7000 fffff880`010eb000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
    fffff880`010eb000 fffff880`01149000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
    fffff880`01149000 fffff880`011bc000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
    fffff880`011bc000 fffff880`011f6000 fvevol fvevol.sys Mon Jul 13 19:22:15 2009 (4A5BC1A7)
    fffff880`01205000 fffff880`013a8000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
    fffff880`013a8000 fffff880`013c2000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
    fffff880`013c2000 fffff880`013d3000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
    fffff880`013d3000 fffff880`013dd000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
    fffff880`013dd000 fffff880`013f3000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01400000 fffff880`01460000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
    fffff880`01460000 fffff880`0148b000 ksecpkg ksecpkg.sys Mon Jul 13 19:50:34 2009 (4A5BC84A)
    fffff880`0148b000 fffff880`0149b000 vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
    fffff880`0149b000 fffff880`014a3000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
    fffff880`014a3000 fffff880`014b5000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
    fffff880`014b5000 fffff880`014be000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
    fffff880`014c0000 fffff880`015b2000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`015b2000 fffff880`015fc000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
    fffff880`01602000 fffff880`017ff000 tcpip tcpip.sys Mon Jul 13 19:25:34 2009 (4A5BC26E)
    fffff880`01800000 fffff880`01898000 aswSnx aswSnx.SYS Tue May 10 08:04:06 2011 (4DC929B6)
    fffff880`01898000 fffff880`018a1000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
    fffff880`018a1000 fffff880`018a8000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
    fffff880`018a8000 fffff880`018b6000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
    fffff880`018b6000 fffff880`018db000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
    fffff880`018db000 fffff880`018eb000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
    fffff880`018eb000 fffff880`018f4000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`018fc000 fffff880`0192c000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`01962000 fffff880`0198c000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`0198c000 fffff880`01995000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`01995000 fffff880`0199e000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
    fffff880`0199e000 fffff880`019a9000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`019a9000 fffff880`019ba000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`019ba000 fffff880`019d8000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
    fffff880`019d8000 fffff880`019e5000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
    fffff880`019e5000 fffff880`019f5000 aswTdi aswTdi.SYS Tue May 10 08:02:40 2011 (4DC92960)
    fffff880`03a00000 fffff880`03a51000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
    fffff880`03a51000 fffff880`03a5d000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
    fffff880`03a5d000 fffff880`03a68000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
    fffff880`03a68000 fffff880`03a77000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
    fffff880`03a84000 fffff880`03b0e000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`03b0e000 fffff880`03b18000 aswRdr aswRdr.SYS Tue May 10 07:59:58 2011 (4DC928BE)
    fffff880`03b18000 fffff880`03b5d000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
    fffff880`03b5d000 fffff880`03b66000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`03b66000 fffff880`03b8c000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
    fffff880`03b8c000 fffff880`03ba2000 vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
    fffff880`03ba2000 fffff880`03bb1000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`03bb1000 fffff880`03bce000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
    fffff880`03bce000 fffff880`03be9000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
    fffff880`03be9000 fffff880`03bfd000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
    fffff880`03c00000 fffff880`03c36000 fastfat fastfat.SYS Mon Jul 13 19:23:28 2009 (4A5BC1F0)
    fffff880`03c36000 fffff880`03cdc000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
    fffff880`03cde000 fffff880`03d18000 aswMonFlt aswMonFlt.sys Tue May 10 07:59:47 2011 (4DC928B3)
    fffff880`03d18000 fffff880`03d21000 aswFsBlk aswFsBlk.SYS Tue May 10 07:59:36 2011 (4DC928A8)
    fffff880`03d21000 fffff880`03d42000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
    fffff880`03d42000 fffff880`03d57000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`03d57000 fffff880`03daa000 nwifi nwifi.sys Mon Jul 13 20:07:23 2009 (4A5BCC3B)
    fffff880`03daa000 fffff880`03dbd000 ndisuio ndisuio.sys Mon Jul 13 20:09:25 2009 (4A5BCCB5)
    fffff880`03dbd000 fffff880`03dd5000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`04000000 fffff880`04026000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
    fffff880`04026000 fffff880`0403c000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    fffff880`0403c000 fffff880`04092000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`04092000 fffff880`040d0000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
    fffff880`040e9000 fffff880`0416c000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
    fffff880`0416c000 fffff880`0418a000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
    fffff880`0418a000 fffff880`0419b000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
    fffff880`0419b000 fffff880`041e8000 aswSP aswSP.SYS Tue May 10 08:04:06 2011 (4DC929B6)
    fffff880`04400000 fffff880`04416000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
    fffff880`04416000 fffff880`0443a000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`0443a000 fffff880`04446000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
    fffff880`04446000 fffff880`04475000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`04475000 fffff880`04490000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
    fffff880`04490000 fffff880`044b1000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
    fffff880`044b1000 fffff880`044cb000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
    fffff880`044cb000 fffff880`044d6000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
    fffff880`044d6000 fffff880`044e5000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`044e5000 fffff880`044f4000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`044f4000 fffff880`044f5480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
    fffff880`044f8000 fffff880`04597000 netr28x netr28x.sys Wed Feb 25 22:02:09 2009 (49A60631)
    fffff880`04597000 fffff880`045a4000 vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
    fffff880`045a4000 fffff880`045ac000 ASACPI ASACPI.sys Wed Jul 15 23:31:29 2009 (4A5E9F11)
    fffff880`045ac000 fffff880`045b8000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`045b8000 fffff880`045d5000 parport parport.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
    fffff880`045d5000 fffff880`045e2000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
    fffff880`045e2000 fffff880`045f2000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`045f2000 fffff880`045ff000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff880`04800000 fffff880`04846000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
    fffff880`04846000 fffff880`0486a000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
    fffff880`0486a000 fffff880`0487b000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`0487b000 fffff880`04889000 kbdhid kbdhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff880`04889000 fffff880`048ac000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
    fffff880`048ac000 fffff880`04ed1000 atikmdag atikmdag.sys Wed Nov 11 00:25:32 2009 (4AFA4ACC)
    fffff880`04ed1000 fffff880`04fc5000 dxgkrnl dxgkrnl.sys Mon Jul 13 19:38:56 2009 (4A5BC590)
    fffff880`04fc5000 fffff880`04ff7000 Rt64win7 Rt64win7.sys Thu Feb 26 04:04:13 2009 (49A65B0D)
    fffff880`05003000 fffff880`05046000 ks ks.sys Mon Jul 13 20:00:31 2009 (4A5BCA9F)
    fffff880`05046000 fffff880`05058000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
    fffff880`05058000 fffff880`050b2000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
    fffff880`050b2000 fffff880`050c7000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
    fffff880`050c7000 fffff880`050e8000 AtiHdmi AtiHdmi.sys Wed Sep 30 09:54:46 2009 (4AC36326)
    fffff880`050e8000 fffff880`05125000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`05125000 fffff880`05147000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
    fffff880`05147000 fffff880`0514c200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
    fffff880`0514d000 fffff880`0515b000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
    fffff880`0515b000 fffff880`05178000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
    fffff880`05178000 fffff880`05185000 nx6000 nx6000.sys Thu Dec 02 17:23:39 2010 (4CF81C6B)
    fffff880`05185000 fffff880`051b2100 usbvideo usbvideo.sys Mon Jul 13 20:07:00 2009 (4A5BCC24)
    fffff880`051b3000 fffff880`051cdc00 usbaudio usbaudio.sys Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`051ce000 fffff880`051dc000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
    fffff880`051dc000 fffff880`051f5000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
    fffff880`051f5000 fffff880`051fd080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
    fffff880`05e02000 fffff880`05f9c000 viahduaa viahduaa.sys Mon Aug 17 07:20:43 2009 (4A893D0B)
    fffff880`05f9c000 fffff880`05faa000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
    fffff880`05faa000 fffff880`05fb6000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`05fb6000 fffff880`05fbf000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`05fbf000 fffff880`05fd2000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    fffff880`05fd2000 fffff880`05fde000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
    fffff880`05ff9000 fffff880`05ffaf00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
    fffff880`07000000 fffff880`0702d000 srvnet srvnet.sys Mon Jul 13 19:24:58 2009 (4A5BC24A)
    fffff880`0702d000 fffff880`0703f000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
    fffff880`07051000 fffff880`07119000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
    fffff880`07119000 fffff880`07137000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
    fffff880`07137000 fffff880`0714f000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
    fffff880`0714f000 fffff880`0717b000 mrxsmb mrxsmb.sys Mon Jul 13 19:23:59 2009 (4A5BC20F)
    fffff880`0717b000 fffff880`071c8000 mrxsmb10 mrxsmb10.sys Mon Jul 13 19:24:08 2009 (4A5BC218)
    fffff880`071c8000 fffff880`071eb000 mrxsmb20 mrxsmb20.sys Mon Jul 13 19:24:05 2009 (4A5BC215)
    fffff880`071eb000 fffff880`071f6000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
    fffff880`074bc000 fffff880`07525000 srv2 srv2.sys Mon Jul 13 19:25:02 2009 (4A5BC24E)
    fffff880`07525000 fffff880`075bd000 srv srv.sys Mon Jul 13 19:25:11 2009 (4A5BC257)
    fffff960`000b0000 fffff960`003bf000 win32k win32k.sys Mon Jul 13 19:40:16 2009 (4A5BC5E0)
    fffff960`004a0000 fffff960`004aa000 TSDDD TSDDD.dll Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff960`006b0000 fffff960`006d7000 cdd cdd.dll Mon Jul 13 21:25:40 2009 (4A5BDE94)
    fffff960`00920000 fffff960`00981000 ATMFD ATMFD.DLL Mon Jul 13 19:38:13 2009 (4A5BC565)

    Unloaded modules:
    fffff880`075bd000 fffff880`075ee000 WUDFRd.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00031000
    fffff880`05fde000 fffff880`05ff9000 USBSTOR.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0001B000
    fffff880`0192c000 fffff880`0193a000 crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000E000
    fffff880`0193a000 fffff880`01946000 dump_ataport.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 0000C000
    fffff880`01946000 fffff880`0194f000 dump_atapi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00009000
    fffff880`0194f000 fffff880`01962000 dump_dumpfve.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    ImageSize: 00013000
    Closing open log file c:debuglog.txt
     
  2. 2011/05/19
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :
    I would suspect a hardware problem - memory or hard drive. I suggest you check them both out.

    Start with the memory - W7 has an inbuilt memory checker .....

    Windows 7 - Memory Diagnostics Tool

    However please note ....
    The only satisfactory way of testing RAM is to test the installed RAM in various configurations. If you have a single module swap it around the slots. If you have a pair of modules run each one singly, swapping between slots; then run them in pairs swapping between pairs of slots. If you have 2 sets of matched modules do not get them mixed up.

    Test your hard drive using the drive manufacturer's disk diagnostic software - DOS version from a bootable CD .....

    Disk Diagnostic Software ....

    ExcelStore

    Hitachi/IBM

    Samsung

    Seagate, Maxtor, Quantum

    Western Digital

    Toshiba
     

  3. to hide this advert.

  4. 2011/05/19
    TheBola

    TheBola Inactive Thread Starter

    Joined:
    2011/05/19
    Messages:
    4
    Likes Received:
    0
    Thanks for the help but I tired both the harddrive and the ram test and they both came up with no problems or error what so ever, I put my ram card in another slot and hopefully nothing will ever happen again!
     
  5. 2011/05/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You posted only one BSOD log, which may be simply misleading, but this particular one indicates RAM issue:
    Download BlueScreenView (in Zip file)
    No installation required.
    Unzip downloaded file and double click on BlueScreenView.exe file to run the program.
    When scanning is done, go Edit>Select All.
    Go File>Save Selected Items, and save the report as BSOD.txt.
    Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.
     
  6. 2011/05/19
    TheBola

    TheBola Inactive Thread Starter

    Joined:
    2011/05/19
    Messages:
    4
    Likes Received:
    0
    Thanks, I ran the program and heres what I got.
    What does it mean?
    ==================================================
    Dump File : 051911-13416-01.dmp
    Crash Time : 5/19/2011 2:23:06 AM
    Bug Check String : SYSTEM_SERVICE_EXCEPTION
    Bug Check Code : 0x0000003b
    Parameter 1 : 00000000`c0000005
    Parameter 2 : fffff960`00179dad
    Parameter 3 : fffff880`0805ef00
    Parameter 4 : 00000000`00000000
    Caused By Driver : win32k.sys
    Caused By Address : win32k.sys+c9dad
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : x64
    Computer Name :
    Full Path : C:\Windows\Minidump\051911-13416-01.dmp
    Processors Count : 4
    Major Version : 15
    Minor Version : 7600
    Dump File Size : 275,520
    ==================================================
     
  7. 2011/05/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    SYSTEM_SERVICE_EXCEPTION (0x0000003b) is usually software related, but...
    Did the BSOD happen just once?
    If so, nothing definitive can be said.
     
  8. 2011/05/20
    TheBola

    TheBola Inactive Thread Starter

    Joined:
    2011/05/19
    Messages:
    4
    Likes Received:
    0
    Yes it did, but the main problem I'm having is random desktop windows manager crashing. On a side note, my warcraft 3 randomly gets a fatal error and crashing.

    Some how they're probably all connected
     
  9. 2011/05/21
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Are you overclocking? Check your Event Log for details about the WDM crashing.
     
    Arie,
    #8

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.