Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\FUBAR-RC1-Desktop\Downloads\Minidump9\Mini052709-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18226.x86fre.vistasp1_gdr.090302-1506
Machine Name:
Kernel base = 0x81a07000 PsLoadedModuleList = 0x81b1ec70
Debug session time: Wed May 27 10:44:39.711 2009 (GMT-4)
System Uptime: 0 days 0:11:39.454
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 94b8317f, 8d42fc68, 0}
Probably caused by : win32k.sys ( win32k!TimersProc+80 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 94b8317f, The address that the exception occurred at
Arg3: 8d42fc68, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!TimersProc+80
94b8317f 0fba762803 btr dword ptr [esi+28h],3
TRAP_FRAME: 8d42fc68 -- (.trap 0xffffffff8d42fc68)
ErrCode = 00000003
eax=00000000 ebx=00000000 ecx=00005c68 edx=00005c68 esi=0067a8c8 edi=0067a8d4
eip=94b8317f esp=8d42fcdc ebp=8d42fcf8 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!TimersProc+0x80:
94b8317f 0fba762803 btr dword ptr [esi+28h],3 ds:0023:0067a8f0=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 94abe847 to 94b8317f
STACK_TEXT:
8d42fcf8 94abe847 00000004 017bfe78 94b81fd7 win32k!TimersProc+0x80
8d42fd34 94abee1e 00000004 00000002 97a5c450 win32k!RawInputThread+0x615
8d42fd48 94b81ff2 00000004 017bfe78 8d42fd64 win32k!xxxCreateSystemThreads+0x4a
8d42fd58 81a5ea1a 00000004 017bfeb8 76e79a94 win32k!NtUserCallNoParam+0x1b
8d42fd58 76e79a94 00000004 017bfeb8 76e79a94 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
017bfeb8 00000000 00000000 00000000 00000000 0x76e79a94
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!TimersProc+80
94b8317f 0fba762803 btr dword ptr [esi+28h],3
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!TimersProc+80
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 498f9e9d
FAILURE_BUCKET_ID: 0x8E_win32k!TimersProc+80
BUCKET_ID: 0x8E_win32k!TimersProc+80
Followup: MachineOwner
---------
1: kd> !thread
GetPointerFromAddress: unable to read from 81b3e86c
THREAD 88204c58 Cid 026c.0300 Teb: 7ffd9000 Win32Thread: ffaaacb8 RUNNING on processor 1
IRP List:
Unable to read nt!_IRP @ 84ced008
Not impersonating
GetUlongFromAddress: unable to read from 81b16394
Owning Process 87c755d8 Image: csrss.exe
Attached Process N/A Image: N/A
ffdf0000: Unable to get shared data
Wait Start TickCount 44765
Context Switch Count 173766
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x75579a30
Stack Init 8d430000 Current 8d42f678 Base 8d430000 Limit 8d42d000 Call 0
Priority 15 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5
ChildEBP RetAddr Args to Child
8d42fcf8 94abe847 00000004 017bfe78 94b81fd7 win32k!TimersProc+0x80 (FPO: [0,4,4])
8d42fd34 94abee1e 00000004 00000002 97a5c450 win32k!RawInputThread+0x615 (FPO: [1,10,0])
8d42fd48 94b81ff2 00000004 017bfe78 8d42fd64 win32k!xxxCreateSystemThreads+0x4a (FPO: [0,2,0])
8d42fd58 81a5ea1a 00000004 017bfeb8 76e79a94 win32k!NtUserCallNoParam+0x1b (FPO: [1,0,0])
8d42fd58 76e79a94 00000004 017bfeb8 76e79a94 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ 8d42fd64)
WARNING: Frame IP not in any known module. Following frames may be wrong.
017bfeb8 00000000 00000000 00000000 00000000 0x76e79a94