in de systemroot map (c/windows)
was ook een minidump.DMP file
daar kreeg ik de volgende LOG uit
****************************************************************************************************
Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18226.amd64fre.vistasp1_gdr.090302-1506
Machine Name:
Kernel base = 0xfffff800`0285d000 PsLoadedModuleList = 0xfffff800`02a22db0
Debug session time: Sun May 24 22:44:09.011 2009 (GMT+2)
System Uptime: 0 days 0:27:03.928
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrnlmp.exe -
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`7efdf018). Type ".hh dbgerr001" for details
Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffffffffffff8b, 1, fffff960001ba6ed, 0}
Page bc782 not present in the dump file. Type ".hh dbgerr004" for details
*** ERROR: Symbol file could not be found. Defaulted to export symbols for win32k.sys -
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Page 1737cb not present in the dump file. Type ".hh dbgerr004" for details
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Page 1737cb not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Probably caused by : win32k.sys ( win32k!W32pArgumentTable+5db1 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffffffffffff8b, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff960001ba6ed, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Page 1737cb not present in the dump file. Type ".hh dbgerr004" for details
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Page 1737cb not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
Page 15ffb5 not present in the dump file. Type ".hh dbgerr004" for details
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.
MODULE_NAME: win32k
FAULTING_MODULE: fffff8000285d000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 498fa36b
WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
ffffffffffffff8b
FAULTING_IP:
win32k!W32pArgumentTable+5db1
fffff960`001ba6ed ff488b dec dword ptr [rax-75h]
MM_INTERNAL_CODE: 0
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800028c0671 to fffff800028b1650
STACK_TEXT:
fffffa60`0c838918 fffff800`028c0671 : 00000000`00000050 ffffffff`ffffff8b 00000000`00000001 fffffa60`0c838a10 : nt!KeBugCheckEx
fffffa60`0c838920 fffff800`028b01d9 : 00000000`00000001 fffffa80`06adbbb0 00000000`74a43300 00000000`0026e1b0 : nt!ExReleaseResourceLite+0x1391
fffffa60`0c838a10 fffff960`001ba6ed : 00000000`0026e1b0 fffffa60`0c838ca0 00000000`00000000 fffff800`028bf172 : nt!ZwUnloadKeyEx+0x11b9
fffffa60`0c838ba0 00000000`0026e1b0 : fffffa60`0c838ca0 00000000`00000000 fffff800`028bf172 fffffa60`0c838bc8 : win32k!W32pArgumentTable+0x5db1
fffffa60`0c838ba8 fffffa60`0c838ca0 : 00000000`00000000 fffff800`028bf172 fffffa60`0c838bc8 fffffa60`0c838ca0 : 0x26e1b0
fffffa60`0c838bb0 00000000`00000000 : fffff800`028bf172 fffffa60`0c838bc8 fffffa60`0c838ca0 00000000`00000001 : 0xfffffa60`0c838ca0
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!W32pArgumentTable+5db1
fffff960`001ba6ed ff488b dec dword ptr [rax-75h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: win32k!W32pArgumentTable+5db1
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: win32k.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------