Jag tror att jag fick igång WinDbg ok. Här är resultatet jag fick fram:
Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini071109-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Program\Debugging Tools for Windows (x86)*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 2600.xpsp_sp3_gdr.090206-1234
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Jul 11 23:58:11.796 2009 (GMT+2)
System Uptime: 0 days 1:24:43.487
Loading Kernel Symbols
...............................................................
................................................................
Loading User Symbols
Loading unloaded module list
.................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, bf80232f, a959ba38, 0}
Probably caused by : win32k.sys ( win32k!AllocQEntry+3f )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: bf80232f, The address that the exception occurred at
Arg3: a959ba38, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instruktionen p "0x%08lx" refererade till minnet p "0x%08lx". Det gick inte att utf ra en minnes tg rd. F ljande fel returnerades: The memory could not be "%s".
FAULTING_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
TRAP_FRAME: a959ba38 -- (.trap 0xffffffffa959ba38)
ErrCode = 00000003
eax=00000000 ebx=e36e1f40 ecx=0000000c edx=10000000 esi=e36e1f40 edi=10000000
eip=bf80232f esp=a959baac ebp=a959bab4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!AllocQEntry+0x3f:
bf80232f f3ab rep stos dword ptr es:[edi]
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf808167 to bf80232f
STACK_TEXT:
a959bab4 bf808167 e36e1f40 e3d1a638 bbe9b050 win32k!AllocQEntry+0x3f
a959badc bf887514 00000000 00000218 0000000a win32k!_PostMessage+0x15b
a959bbac bf88721a bbe606e8 00000218 0000000a win32k!xxxSendBSMtoDesktop+0x321
a959bbec bf859b38 00000000 00000218 0000000a win32k!xxxSendMessageBSM+0x7c
a959bd2c bf85979b 893c38f0 0053fda8 00000000 win32k!xxxUserPowerEventCalloutWorker+0x15f
a959bd48 bf80112d a959bd64 0053fda8 a959bd64 win32k!xxxUserPowerCalloutWorker+0x34
a959bd58 8054162c 0000001a 0053fff4 7c90e514 win32k!NtUserCallNoParam+0x1b
a959bd58 7c90e514 0000001a 0053fff4 7c90e514 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0053fff4 00000000 00000000 00000000 00000000 0x7c90e514
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!AllocQEntry+3f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49e87572
FAILURE_BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: bf80232f, The address that the exception occurred at
Arg3: a959ba38, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instruktionen p "0x%08lx" refererade till minnet p "0x%08lx". Det gick inte att utf ra en minnes tg rd. F ljande fel returnerades: The memory could not be "%s".
FAULTING_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
TRAP_FRAME: a959ba38 -- (.trap 0xffffffffa959ba38)
ErrCode = 00000003
eax=00000000 ebx=e36e1f40 ecx=0000000c edx=10000000 esi=e36e1f40 edi=10000000
eip=bf80232f esp=a959baac ebp=a959bab4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!AllocQEntry+0x3f:
bf80232f f3ab rep stos dword ptr es:[edi]
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf808167 to bf80232f
STACK_TEXT:
a959bab4 bf808167 e36e1f40 e3d1a638 bbe9b050 win32k!AllocQEntry+0x3f
a959badc bf887514 00000000 00000218 0000000a win32k!_PostMessage+0x15b
a959bbac bf88721a bbe606e8 00000218 0000000a win32k!xxxSendBSMtoDesktop+0x321
a959bbec bf859b38 00000000 00000218 0000000a win32k!xxxSendMessageBSM+0x7c
a959bd2c bf85979b 893c38f0 0053fda8 00000000 win32k!xxxUserPowerEventCalloutWorker+0x15f
a959bd48 bf80112d a959bd64 0053fda8 a959bd64 win32k!xxxUserPowerCalloutWorker+0x34
a959bd58 8054162c 0000001a 0053fff4 7c90e514 win32k!NtUserCallNoParam+0x1b
a959bd58 7c90e514 0000001a 0053fff4 7c90e514 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0053fff4 00000000 00000000 00000000 00000000 0x7c90e514
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!AllocQEntry+3f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49e87572
FAILURE_BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: bf80232f, The address that the exception occurred at
Arg3: a959ba38, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instruktionen p "0x%08lx" refererade till minnet p "0x%08lx". Det gick inte att utf ra en minnes tg rd. F ljande fel returnerades: The memory could not be "%s".
FAULTING_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
TRAP_FRAME: a959ba38 -- (.trap 0xffffffffa959ba38)
ErrCode = 00000003
eax=00000000 ebx=e36e1f40 ecx=0000000c edx=10000000 esi=e36e1f40 edi=10000000
eip=bf80232f esp=a959baac ebp=a959bab4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!AllocQEntry+0x3f:
bf80232f f3ab rep stos dword ptr es:[edi]
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf808167 to bf80232f
STACK_TEXT:
a959bab4 bf808167 e36e1f40 e3d1a638 bbe9b050 win32k!AllocQEntry+0x3f
a959badc bf887514 00000000 00000218 0000000a win32k!_PostMessage+0x15b
a959bbac bf88721a bbe606e8 00000218 0000000a win32k!xxxSendBSMtoDesktop+0x321
a959bbec bf859b38 00000000 00000218 0000000a win32k!xxxSendMessageBSM+0x7c
a959bd2c bf85979b 893c38f0 0053fda8 00000000 win32k!xxxUserPowerEventCalloutWorker+0x15f
a959bd48 bf80112d a959bd64 0053fda8 a959bd64 win32k!xxxUserPowerCalloutWorker+0x34
a959bd58 8054162c 0000001a 0053fff4 7c90e514 win32k!NtUserCallNoParam+0x1b
a959bd58 7c90e514 0000001a 0053fff4 7c90e514 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0053fff4 00000000 00000000 00000000 00000000 0x7c90e514
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!AllocQEntry+3f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49e87572
FAILURE_BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: bf80232f, The address that the exception occurred at
Arg3: a959ba38, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instruktionen p "0x%08lx" refererade till minnet p "0x%08lx". Det gick inte att utf ra en minnes tg rd. F ljande fel returnerades: The memory could not be "%s".
FAULTING_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
TRAP_FRAME: a959ba38 -- (.trap 0xffffffffa959ba38)
ErrCode = 00000003
eax=00000000 ebx=e36e1f40 ecx=0000000c edx=10000000 esi=e36e1f40 edi=10000000
eip=bf80232f esp=a959baac ebp=a959bab4 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
win32k!AllocQEntry+0x3f:
bf80232f f3ab rep stos dword ptr es:[edi]
Resetting default scope
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: csrss.exe
LAST_CONTROL_TRANSFER: from bf808167 to bf80232f
STACK_TEXT:
a959bab4 bf808167 e36e1f40 e3d1a638 bbe9b050 win32k!AllocQEntry+0x3f
a959badc bf887514 00000000 00000218 0000000a win32k!_PostMessage+0x15b
a959bbac bf88721a bbe606e8 00000218 0000000a win32k!xxxSendBSMtoDesktop+0x321
a959bbec bf859b38 00000000 00000218 0000000a win32k!xxxSendMessageBSM+0x7c
a959bd2c bf85979b 893c38f0 0053fda8 00000000 win32k!xxxUserPowerEventCalloutWorker+0x15f
a959bd48 bf80112d a959bd64 0053fda8 a959bd64 win32k!xxxUserPowerCalloutWorker+0x34
a959bd58 8054162c 0000001a 0053fff4 7c90e514 win32k!NtUserCallNoParam+0x1b
a959bd58 7c90e514 0000001a 0053fff4 7c90e514 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0053fff4 00000000 00000000 00000000 00000000 0x7c90e514
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!AllocQEntry+3f
bf80232f f3ab rep stos dword ptr es:[edi]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!AllocQEntry+3f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49e87572
FAILURE_BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
BUCKET_ID: 0x8E_win32k!AllocQEntry+3f
Followup: MachineOwner
---------
Av det kan jag utläsa att win32k utgör problemet? Men vad gör win32k och vad kan problemet bero på?
Mycket tacksam för ytterligare feedback på informationen.
Vänligen / Magnus