Okay so I've been doing a clean install of Vista x64 for about a week and have been getting many random blue screens of deaths yesterday I did another clean install and only had about 4 drivers or so installed and I got a BSOD but no dump file was created for some reason so I kept installing more drivers and it work for about 4 hours till it crahsed again this time it gave me a dump file so here are the results...
Microsoft (R) Windows Debugger Version 6.9.0003.113 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\Mini060408-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*Symbol information
Executable search path is:
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6000.16584.amd64fre.vista_gdr.071023-1545
Kernel base = 0xfffff800`01c00000 PsLoadedModuleList = 0xfffff800`01d9af70
Debug session time: Wed Jun 4 20:18:02.665 2008 (GMT-4)
System Uptime: 0 days 1:43:47.735
Loading Kernel Symbols
.............................................................................................................................................................
Loading User Symbols
Loading unloaded module list
...................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960000b218b, fffff9801338d220, 0}
Probably caused by : win32k.sys ( win32k!hGetFreeHandle+1b )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000b218b, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff9801338d220, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
CONTEXT: fffff9801338d220 -- (.cxr 0xfffff9801338d220)
rax=0000000000000d60 rbx=fffff9801338db30 rcx=fffffa8008b5cc07
rdx=fffff900c0200000 rsi=0000000000000000 rdi=0000000000000644
rip=fffff960000b218b rsp=fffff9801338da88 rbp=fffff900c1c92c00
r8=fffe000000002820 r9=0000000000000d60 r10=fffffa8008b5cc00
r11=fffffa80090ef9e0 r12=0000000000000002 r13=0000000000000007
r14=0000000000000007 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
win32k!hGetFreeHandle+0x1b:
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8] ds:002b:ffeff900`c0214100=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960000b4d21 to fffff960000b218b
STACK_TEXT:
fffff980`1338da88 fffff960`000b4d21 : fffff980`1338db30 fffff980`1338db30 00000000`0000006a 00000000`00000007 : win32k!hGetFreeHandle+0x1b
fffff980`1338da90 fffff960`00187c5a : fffff980`1338db30 00000000`0000006a 00000000`000000ae 00000000`00000001 : win32k!HmgAlloc+0xb1
fffff980`1338dad0 fffff960`00184120 : 00000000`00000001 fffff960`0008ddb4 fffff980`1338dbc0 00000000`00000d60 : win32k!PATHMEMOBJ::PATHMEMOBJ+0x1a
fffff980`1338db00 fffff800`01c4d733 : fffffa80`090ef9e0 fffff980`1338dca0 00000000`023ff598 fffff980`1338dbc8 : win32k!NtGdiCreateRoundRectRgn+0x30
fffff980`1338dbb0 000007fe`fd4f66ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`023ff578 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd4f66ea
FOLLOWUP_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!hGetFreeHandle+1b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47c78af2
STACK_COMMAND: .cxr 0xfffff9801338d220 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000b218b, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff9801338d220, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
CONTEXT: fffff9801338d220 -- (.cxr 0xfffff9801338d220)
rax=0000000000000d60 rbx=fffff9801338db30 rcx=fffffa8008b5cc07
rdx=fffff900c0200000 rsi=0000000000000000 rdi=0000000000000644
rip=fffff960000b218b rsp=fffff9801338da88 rbp=fffff900c1c92c00
r8=fffe000000002820 r9=0000000000000d60 r10=fffffa8008b5cc00
r11=fffffa80090ef9e0 r12=0000000000000002 r13=0000000000000007
r14=0000000000000007 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
win32k!hGetFreeHandle+0x1b:
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8] ds:002b:ffeff900`c0214100=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960000b4d21 to fffff960000b218b
STACK_TEXT:
fffff980`1338da88 fffff960`000b4d21 : fffff980`1338db30 fffff980`1338db30 00000000`0000006a 00000000`00000007 : win32k!hGetFreeHandle+0x1b
fffff980`1338da90 fffff960`00187c5a : fffff980`1338db30 00000000`0000006a 00000000`000000ae 00000000`00000001 : win32k!HmgAlloc+0xb1
fffff980`1338dad0 fffff960`00184120 : 00000000`00000001 fffff960`0008ddb4 fffff980`1338dbc0 00000000`00000d60 : win32k!PATHMEMOBJ::PATHMEMOBJ+0x1a
fffff980`1338db00 fffff800`01c4d733 : fffffa80`090ef9e0 fffff980`1338dca0 00000000`023ff598 fffff980`1338dbc8 : win32k!NtGdiCreateRoundRectRgn+0x30
fffff980`1338dbb0 000007fe`fd4f66ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`023ff578 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd4f66ea
FOLLOWUP_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!hGetFreeHandle+1b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47c78af2
STACK_COMMAND: .cxr 0xfffff9801338d220 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
Followup: MachineOwner
---------
any help? I've never debugged before I have a feeling its a driver though I'm not sure which one everything I installed was for x64 bit so there shouldn't be a problem thanks in advance
Microsoft (R) Windows Debugger Version 6.9.0003.113 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\Mini060408-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*Symbol information
Executable search path is:
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6000.16584.amd64fre.vista_gdr.071023-1545
Kernel base = 0xfffff800`01c00000 PsLoadedModuleList = 0xfffff800`01d9af70
Debug session time: Wed Jun 4 20:18:02.665 2008 (GMT-4)
System Uptime: 0 days 1:43:47.735
Loading Kernel Symbols
.............................................................................................................................................................
Loading User Symbols
Loading unloaded module list
...................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960000b218b, fffff9801338d220, 0}
Probably caused by : win32k.sys ( win32k!hGetFreeHandle+1b )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000b218b, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff9801338d220, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
CONTEXT: fffff9801338d220 -- (.cxr 0xfffff9801338d220)
rax=0000000000000d60 rbx=fffff9801338db30 rcx=fffffa8008b5cc07
rdx=fffff900c0200000 rsi=0000000000000000 rdi=0000000000000644
rip=fffff960000b218b rsp=fffff9801338da88 rbp=fffff900c1c92c00
r8=fffe000000002820 r9=0000000000000d60 r10=fffffa8008b5cc00
r11=fffffa80090ef9e0 r12=0000000000000002 r13=0000000000000007
r14=0000000000000007 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
win32k!hGetFreeHandle+0x1b:
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8] ds:002b:ffeff900`c0214100=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960000b4d21 to fffff960000b218b
STACK_TEXT:
fffff980`1338da88 fffff960`000b4d21 : fffff980`1338db30 fffff980`1338db30 00000000`0000006a 00000000`00000007 : win32k!hGetFreeHandle+0x1b
fffff980`1338da90 fffff960`00187c5a : fffff980`1338db30 00000000`0000006a 00000000`000000ae 00000000`00000001 : win32k!HmgAlloc+0xb1
fffff980`1338dad0 fffff960`00184120 : 00000000`00000001 fffff960`0008ddb4 fffff980`1338dbc0 00000000`00000d60 : win32k!PATHMEMOBJ::PATHMEMOBJ+0x1a
fffff980`1338db00 fffff800`01c4d733 : fffffa80`090ef9e0 fffff980`1338dca0 00000000`023ff598 fffff980`1338dbc8 : win32k!NtGdiCreateRoundRectRgn+0x30
fffff980`1338dbb0 000007fe`fd4f66ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`023ff578 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd4f66ea
FOLLOWUP_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!hGetFreeHandle+1b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47c78af2
STACK_COMMAND: .cxr 0xfffff9801338d220 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960000b218b, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff9801338d220, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
CONTEXT: fffff9801338d220 -- (.cxr 0xfffff9801338d220)
rax=0000000000000d60 rbx=fffff9801338db30 rcx=fffffa8008b5cc07
rdx=fffff900c0200000 rsi=0000000000000000 rdi=0000000000000644
rip=fffff960000b218b rsp=fffff9801338da88 rbp=fffff900c1c92c00
r8=fffe000000002820 r9=0000000000000d60 r10=fffffa8008b5cc00
r11=fffffa80090ef9e0 r12=0000000000000002 r13=0000000000000007
r14=0000000000000007 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
win32k!hGetFreeHandle+0x1b:
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8] ds:002b:ffeff900`c0214100=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960000b4d21 to fffff960000b218b
STACK_TEXT:
fffff980`1338da88 fffff960`000b4d21 : fffff980`1338db30 fffff980`1338db30 00000000`0000006a 00000000`00000007 : win32k!hGetFreeHandle+0x1b
fffff980`1338da90 fffff960`00187c5a : fffff980`1338db30 00000000`0000006a 00000000`000000ae 00000000`00000001 : win32k!HmgAlloc+0xb1
fffff980`1338dad0 fffff960`00184120 : 00000000`00000001 fffff960`0008ddb4 fffff980`1338dbc0 00000000`00000d60 : win32k!PATHMEMOBJ::PATHMEMOBJ+0x1a
fffff980`1338db00 fffff800`01c4d733 : fffffa80`090ef9e0 fffff980`1338dca0 00000000`023ff598 fffff980`1338dbc8 : win32k!NtGdiCreateRoundRectRgn+0x30
fffff980`1338dbb0 000007fe`fd4f66ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`023ff578 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd4f66ea
FOLLOWUP_IP:
win32k!hGetFreeHandle+1b
fffff960`000b218b 4a8b04c2 mov rax,qword ptr [rdx+r8*8]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!hGetFreeHandle+1b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47c78af2
STACK_COMMAND: .cxr 0xfffff9801338d220 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
BUCKET_ID: X64_0x3B_win32k!hGetFreeHandle+1b
Followup: MachineOwner
---------
any help? I've never debugged before I have a feeling its a driver though I'm not sure which one everything I installed was for x64 bit so there shouldn't be a problem thanks in advance