******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff80002b70e0b, fffff880021760d0, 0} Probably caused by : ntkrnlmp.exe ( nt!AlpcAddHandleTableEntry+3b ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff80002b70e0b, Address of the instruction which caused the bugcheck Arg3: fffff880021760d0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden. FAULTING_IP: nt!AlpcAddHandleTableEntry+3b fffff800`02b70e0b 483919 cmp qword ptr [rcx],rbx CONTEXT: fffff880021760d0 -- (.cxr 0xfffff880021760d0) rax=0000000000000001 rbx=0000000000000000 rcx=ffff78a0011d4010 rdx=0000000000000010 rsi=fffff8a0011cb348 rdi=fffff8a0017efd30 rip=fffff80002b70e0b rsp=fffff88002176aa0 rbp=0000000000000000 r8=0000000000000578 r9=0000000000000110 r10=fffff80002813000 r11=fffff88002176aa0 r12=fffff8a0017efd10 r13=fffff88002176b30 r14=0000000000000000 r15=fffff8a0010af060 iopl=0 nv up ei pl nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202 nt!AlpcAddHandleTableEntry+0x3b: fffff800`02b70e0b 483919 cmp qword ptr [rcx],rbx ds:002b:ffff78a0`011d4010=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: svchost.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff80002b70c77 to fffff80002b70e0b STACK_TEXT: fffff880`02176aa0 fffff800`02b70c77 : 00000000`00000000 ffffffff`ffffffff fffffa80`055aa730 fffffa80`055aa730 : nt!AlpcAddHandleTableEntry+0x3b fffff880`02176ae0 fffff800`02b1f8ed : 00000000`00baf630 fffff8a0`00000001 fffff880`02176bc8 fffff880`02176c38 : nt!AlpcpCreateSecurityContext+0x193 fffff880`02176b80 fffff800`02882993 : fffffa80`055b0440 00000000`00000001 fffff880`02176bf8 00000000`00000001 : nt!NtAlpcCreateSecurityContext+0x130 fffff880`02176c20 00000000`77b604ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`00baf498 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77b604ea FOLLOWUP_IP: nt!AlpcAddHandleTableEntry+3b fffff800`02b70e0b 483919 cmp qword ptr [rcx],rbx SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: nt!AlpcAddHandleTableEntry+3b FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9 STACK_COMMAND: .cxr 0xfffff880021760d0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!AlpcAddHandleTableEntry+3b BUCKET_ID: X64_0x3B_nt!AlpcAddHandleTableEntry+3b Followup: MachineOwner --------- ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck F4, {3, fffffa800527cb30, fffffa800527ce10, fffff80002d7d5d0} Probably caused by : csrss.exe Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* CRITICAL_OBJECT_TERMINATION (f4) A process or thread crucial to system operation has unexpectedly exited or been terminated. Several processes and threads are necessary for the operation of the system; when they are terminated (for any reason), the system can no longer function. Arguments: Arg1: 0000000000000003, Process Arg2: fffffa800527cb30, Terminating object Arg3: fffffa800527ce10, Process image file name Arg4: fffff80002d7d5d0, Explanatory message (ascii) Debugging Details: ------------------ PROCESS_OBJECT: fffffa800527cb30 IMAGE_NAME: csrss.exe DEBUG_FLR_IMAGE_TIMESTAMP: 0 MODULE_NAME: csrss FAULTING_MODULE: 0000000000000000 PROCESS_NAME: csrss.exe EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden. BUGCHECK_STR: 0xF4_C0000005 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT CURRENT_IRQL: 0 STACK_TEXT: fffff880`07c73b08 fffff800`02dfe652 : 00000000`000000f4 00000000`00000003 fffffa80`0527cb30 fffffa80`0527ce10 : nt!KeBugCheckEx fffff880`07c73b10 fffff800`02da73e3 : ffffffff`ffffffff fffffa80`05e17060 fffffa80`0527cb30 fffffa80`0527cb30 : nt!PspCatchCriticalBreak+0x92 fffff880`07c73b50 fffff800`02d2f80c : ffffffff`ffffffff 00000000`00000001 fffffa80`0527cb30 00000000`00000008 : nt! ?? ::NNGAKEGL::`string'+0x17946 fffff880`07c73ba0 fffff800`02a71993 : fffffa80`0527cb30 fffff880`c0000005 00000000`030afb80 fffffa80`05e17060 : nt!NtTerminateProcess+0x20c fffff880`07c73c20 00000000`77b8001a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`030adb08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77b8001a STACK_COMMAND: kb FOLLOWUP_NAME: MachineOwner FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe Followup: MachineOwner --------- ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff960000cd3db, fffff88005811d70, 0} Probably caused by : win32k.sys ( win32k!GreCombineRgn+197 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff960000cd3db, Address of the instruction which caused the bugcheck Arg3: fffff88005811d70, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden. FAULTING_IP: win32k!GreCombineRgn+197 fffff960`000cd3db 396e54 cmp dword ptr [rsi+54h],ebp CONTEXT: fffff88005811d70 -- (.cxr 0xfffff88005811d70) rax=fffff880058127b0 rbx=0000000000000000 rcx=fffff880058127b0 rdx=fffff880058127e0 rsi=0000000000000001 rdi=0000000000000001 rip=fffff960000cd3db rsp=fffff88005812748 rbp=0000000000000001 r8=fffff880058127f8 r9=0000000000000001 r10=fffff900c00c9490 r11=0000000000000001 r12=0000000001040050 r13=0000000001040041 r14=0000000000000001 r15=fffff900c0600b90 iopl=0 nv up ei pl nz na pe nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202 win32k!GreCombineRgn+0x197: fffff960`000cd3db 396e54 cmp dword ptr [rsi+54h],ebp ds:002b:00000000`00000055=???????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: explorer.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from 0000000001040050 to fffff960000cd3db STACK_TEXT: fffff880`05812748 00000000`01040050 : fffff960`001c68b5 fffff900`c1d566c0 fffff880`05812948 fffff900`c0693190 : win32k!GreCombineRgn+0x197 fffff880`05812848 fffff960`001c68b5 : fffff900`c1d566c0 fffff880`05812948 fffff900`c0693190 00000000`00000001 : 0x1040050 fffff880`05812850 fffff960`0014a222 : fffff900`c200b3a0 00000000`00000000 00000000`00000005 fffff900`c0693190 : win32k!RestoreSpb+0x75 fffff880`058128e0 fffff960`00149216 : fffff960`00390120 00000000`00000000 fffff960`00000001 fffff800`00000000 : win32k!zzzBltValidBits+0x816 fffff880`058129e0 fffff960`00148fe6 : fffff900`00000001 fffff900`c0693190 00000000`00000008 ffffd0a7`00000000 : win32k!xxxEndDeferWindowPosEx+0x1ee fffff880`05812aa0 fffff960`0018746d : 00000000`00000000 00000000`00000000 fffff880`00000000 fffffa80`00000000 : win32k!xxxSetWindowPos+0x156 fffff880`05812b20 fffff800`02a7f993 : fffffa80`058a9060 fffff880`05812ca0 00000000`0296e9d8 fffff880`05812bc8 : win32k!NtUserSetWindowPos+0x1e5 fffff880`05812bb0 00000000`77006c7a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0296e9b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77006c7a FOLLOWUP_IP: win32k!GreCombineRgn+197 fffff960`000cd3db 396e54 cmp dword ptr [rsi+54h],ebp SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: win32k!GreCombineRgn+197 FOLLOWUP_NAME: MachineOwner MODULE_NAME: win32k IMAGE_NAME: win32k.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c STACK_COMMAND: .cxr 0xfffff88005811d70 ; kb FAILURE_BUCKET_ID: X64_0x3B_win32k!GreCombineRgn+197 BUCKET_ID: X64_0x3B_win32k!GreCombineRgn+197 Followup: MachineOwner --------- ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff9600012e94b, fffff880084db110, 0} Probably caused by : win32k.sys ( win32k!DestroyCacheDC+bb ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff9600012e94b, Address of the instruction which caused the bugcheck Arg3: fffff880084db110, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Die Anweisung in 0x%08lx verweist auf Speicher 0x%08lx. Der Vorgang %s konnte nicht im Speicher durchgef hrt werden. FAULTING_IP: win32k!DestroyCacheDC+bb fffff960`0012e94b 4885c9 test rcx,rcx CONTEXT: fffff880084db110 -- (.cxr 0xfffff880084db110) rax=fffff900c5f824c0 rbx=fffff900c0743b90 rcx=0000000000000000 rdx=ffffffff900101b6 rsi=0000000000000000 rdi=fffff900c0581e90 rip=fffff9600012e94b rsp=fffff880084dbae0 rbp=0000000000000000 r8=0000000000000003 r9=fffff9600035baa8 r10=0000000000000000 r11=fffff900c1e3c010 r12=0000000000000000 r13=0000000000000000 r14=0000000000000001 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246 win32k!DestroyCacheDC+0xbb: fffff960`0012e94b 4885c9 test rcx,rcx Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: VDeck.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff9600016f349 to fffff9600012e94b STACK_TEXT: fffff880`084dbae0 fffff960`0016f349 : fffff900`c0743b90 00000000`00000000 fffff900`c0581e90 fffffa80`063d0060 : win32k!DestroyCacheDC+0xbb fffff880`084dbb30 fffff960`000d4490 : ffffffff`900101b6 ffffffff`900101b6 00000000`00000000 00000000`00000000 : win32k!ReleaseCacheDC+0x8d fffff880`084dbb70 fffff960`00177728 : fffff880`084dbbc0 00000000`00000000 fffff900`00000000 00000000`00000000 : win32k!UserReleaseDC+0x20 fffff880`084dbba0 fffff960`00136730 : ffffffff`900101b6 fffff880`084dbca0 00000000`00000000 00000000`00000020 : win32k!bDeleteDCInternal+0x98 fffff880`084dbbf0 fffff800`02a79993 : fffffa80`063d0060 00000000`00000000 00000000`00000020 00000000`00000000 : win32k!NtGdiDeleteObjectApp+0x120 fffff880`084dbc20 000007fe`fe14118a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`088cf4b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fe14118a FOLLOWUP_IP: win32k!DestroyCacheDC+bb fffff960`0012e94b 4885c9 test rcx,rcx SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: win32k!DestroyCacheDC+bb FOLLOWUP_NAME: MachineOwner MODULE_NAME: win32k IMAGE_NAME: win32k.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c STACK_COMMAND: .cxr 0xfffff880084db110 ; kb FAILURE_BUCKET_ID: X64_0x3B_win32k!DestroyCacheDC+bb BUCKET_ID: X64_0x3B_win32k!DestroyCacheDC+bb Followup: MachineOwner ---------