Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\050211-25677-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c66000 PsLoadedModuleList = 0xfffff800`02ea3e50
Debug session time: Mon May 2 04:48:05.876 2011 (UTC - 4:00)
System Uptime: 0 days 4:53:27.002
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8000d50d50, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339d6 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8000d50d50
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: services.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d4a26e to fffff80002cd7f00
STACK_TEXT:
fffff880`07677668 fffff800`02d4a26e : 00000000`0000001a 00000000`00041790 fffffa80`00d50d50 00000000`0000ffff : nt!KeBugCheckEx
fffff880`07677670 fffff800`02d19c4a : 00000000`00000000 00000000`0117ffff fffffa80`00000000 fffffa80`06908630 : nt! ?? ::FNODOBFM::`string'+0x339d6
fffff880`07677830 fffff800`02cd7153 : ffffffff`ffffffff fffff880`07677b08 fffff880`07677b00 fffff8a0`00008000 : nt!NtFreeVirtualMemory+0x5ca
fffff880`07677920 fffff800`02cd36f0 : fffff800`02fba853 fffffa80`06c40990 fffffa80`0676b900 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
fffff880`07677ab8 fffff800`02fba853 : fffffa80`06c40990 fffffa80`0676b900 00000000`00000000 fffffa80`0676b900 : nt!KiServiceLinkage
fffff880`07677ac0 fffff800`02fbe2a1 : 00000000`00000000 00000000`00000000 000007ff`fffd5000 00000000`00000000 : nt!PspExitThread+0x523
fffff880`07677b90 fffff800`02fbe4dd : fffffa80`06c40990 00000000`00000000 fffffa80`06c40990 00000000`01469840 : nt!PspTerminateThreadByPointer+0x4d
fffff880`07677be0 fffff800`02cd7153 : fffffa80`06c40990 fffff880`07677ca0 00000000`77934270 fffffa80`049adcc0 : nt!NtTerminateThread+0x45
fffff880`07677c20 00000000`778803ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0117f4a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x778803ea
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+339d6
fffff800`02d4a26e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+339d6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\050811-24164-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e1c000 PsLoadedModuleList = 0xfffff800`03061e90
Debug session time: Sun May 8 16:24:10.437 2011 (UTC - 4:00)
System Uptime: 1 days 17:30:33.650
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960001a55c3, fffff8800b9e8000, 0}
Probably caused by : win32k.sys ( win32k!SURFACE::bDeleteSurface+117 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960001a55c3, Address of the instruction which caused the bugcheck
Arg3: fffff8800b9e8000, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!SURFACE::bDeleteSurface+117
fffff960`001a55c3 40846b38 test byte ptr [rbx+38h],bpl
CONTEXT: fffff8800b9e8000 -- (.cxr 0xfffff8800b9e8000)
rax=fffff8800b9e8aa0 rbx=0000002000000020 rcx=fffff8800b9e8ac0
rdx=00000080b658a760 rsi=fffff900c1f73008 rdi=0000000000000000
rip=fffff960001a55c3 rsp=fffff8800b9e89e0 rbp=0000000000000001
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff8800b9e8aa0 r12=fffff900c1f741b8 r13=0000000000000000
r14=0000000000000000 r15=000000004e050c48
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010203
win32k!SURFACE::bDeleteSurface+0x117:
fffff960`001a55c3 40846b38 test byte ptr [rbx+38h],bpl ds:002b:00000020`00000058=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960001a5bc4 to fffff960001a55c3
STACK_TEXT:
fffff880`0b9e89e0 fffff960`001a5bc4 : fffff900`c1dcd8a0 fffff900`00000000 fffff900`c1f73008 00000000`00000000 : win32k!SURFACE::bDeleteSurface+0x117
fffff880`0b9e8b30 fffff960`001a5b65 : fffff900`c1dcd8a0 fffff900`c1f73008 00000000`00000000 ffffffff`f0ec02cf : win32k!bDeleteSurface+0x34
fffff880`0b9e8b60 fffff960`001dcf74 : 00000000`00110676 00000000`00110676 00000000`00000000 00000000`00000020 : win32k!GreDeleteObject+0x6d
fffff880`0b9e8b90 fffff960`001acc3b : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`000002b1 : win32k!CleanupCursorObject+0xbc
fffff880`0b9e8bc0 fffff960`00157c00 : fffff880`0b9e8ca0 00000000`00000001 fffff900`c1e952a0 00000000`00000000 : win32k!DestroyCursor+0x53
fffff880`0b9e8bf0 fffff800`02e9b8d3 : fffffa80`0756b060 00000000`00000001 00000000`00000020 00000000`13010fdf : win32k!NtUserDestroyCursor+0x84
fffff880`0b9e8c20 00000000`7790ceea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0578f688 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7790ceea
FOLLOWUP_IP:
win32k!SURFACE::bDeleteSurface+117
fffff960`001a55c3 40846b38 test byte ptr [rbx+38h],bpl
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!SURFACE::bDeleteSurface+117
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d6f104c
STACK_COMMAND: .cxr 0xfffff8800b9e8000 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!SURFACE::bDeleteSurface+117
BUCKET_ID: X64_0x3B_win32k!SURFACE::bDeleteSurface+117
Followup: MachineOwner
---------