PEB is paged out (Peb.Ldr = 7ffdb00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffdb00c). Type ".hh dbgerr001" for details
MODULE_NAME: win32k
FAULTING_MODULE: 82433000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 48d1b9ef
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!EngCopyBits+b06
9579e868 833800 cmp dword ptr [eax],0
TRAP_FRAME: b3f9dbd0 -- (.trap 0xffffffffb3f9dbd0)
ErrCode = 00000000
eax=00000000 ebx=fae18a38 ecx=b3f9dc18 edx=000aec81 esi=b3f9dc5c edi=b3f9dc6c
eip=9579e868 esp=b3f9dc44 ebp=b3f9dd10 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!EngCopyBits+0xb06:
9579e868 833800 cmp dword ptr [eax],0 ds:0023:00000000=????????
Resetting default scope
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
BUGCHECK_STR: 0x8E
LAST_CONTROL_TRANSFER: from 82469590 to 825000e3
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
b3f9d790 82469590 0000008e c0000005 9579e868 nt!KeBugCheckEx+0x1e
b3f9db60 8248b5da b3f9db7c 00000000 b3f9dbd0 nt!ExfReleasePushLockShared+0xaa4
b3f9dbe0 95793586 000aec80 00000000 fa853008 nt!Kei386EoiHelper+0x1d2
b3f9dd10 8248aa1a f9c03008 ffa8e8b8 fa4a6748 win32k!EngStrokePath+0x2858
b3f9dd44 776b9a94 badb0d00 0012c608 00000000 nt!ZwQueryLicenseValue+0xbd2
b3f9dd48 badb0d00 0012c608 00000000 00000000 0x776b9a94
b3f9dd4c 0012c608 00000000 00000000 00000000 0xbadb0d00
b3f9dd50 00000000 00000000 00000000 00000000 0x12c608
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!EngCopyBits+b06
9579e868 833800 cmp dword ptr [eax],0
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!EngCopyBits+b06
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: win32k.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
1: kd> lmvm nt
start end module name
82433000 827ec000 nt (export symbols) ntkrpamp.exe
Loaded symbol image file: ntkrpamp.exe
Image path: ntkrpamp.exe
Image name: ntkrpamp.exe
Timestamp: Thu Sep 18 04:07:54 2008 (48D1B7FA)
CheckSum: 00379F5D
ImageSize: 003B9000
File version: 6.0.6001.18145
Product version: 6.0.6001.18145
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrpamp.exe
OriginalFilename: ntkrpamp.exe
ProductVersion: 6.0.6001.18145
FileVersion: 6.0.6001.18145 (vistasp1_gdr.080917-1612)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
1: kd> .trap 0xffffffffb3f9dbd0
ErrCode = 00000000
eax=00000000 ebx=fae18a38 ecx=b3f9dc18 edx=000aec81 esi=b3f9dc5c edi=b3f9dc6c
eip=9579e868 esp=b3f9dc44 ebp=b3f9dd10 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!EngCopyBits+0xb06:
9579e868 833800 cmp dword ptr [eax],0 ds:0023:00000000=????????
Partager