Microsoft (R) Windows Debugger Version 6.8.0004.0 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Windows\MEMORY.DMP] Kernel Complete Dump File: Full address space is available Symbol search path is: SRV*[+] [D:\symbols]*http://msdl.microsoft.com/download/symbols Executable search path is: Windows Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Built by: 6001.18145.x86fre.vistasp1_gdr.080917-1612 Kernel base = 0x82434000 PsLoadedModuleList = 0x8254bc70 Debug session time: Thu Feb 19 05:26:38.960 2009 (GMT-8) System Uptime: 2 days 16:55:01.238 Loading Kernel Symbols ..................................................................................................................................................................... Loading User Symbols ......................Unable to read NT module Base Name string at 0020d04c - NTSTATUS 0xC0000147 .....Unable to read NT module Base Name string at 0021b0c0 - NTSTATUS 0xC0000147 .Unable to read NT module Base Name string at 0021b160 - NTSTATUS 0xC0000147 .Unable to read NT module Base Name string at 0021b1b0 - NTSTATUS 0xC0000147 ...Unable to read NT module Base Name string at 0021b250 - NTSTATUS 0xC0000147 .....Unable to read NT module Base Name string at 0021b2a0 - NTSTATUS 0xC0000147 ................ Loading unloaded module list ..................... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 8E, {c000001d, 99ff65fc, 9dd073c0, 0} *** ERROR: Module load completed but symbols could not be loaded for LCDMedia.exe ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: kernel32!pNlsUserInfo *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: kernel32!pNlsUserInfo *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k!bLines+53f ) Followup: MachineOwner --------- 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Some common problems are exception code 0x80000003. This means a hard coded breakpoint or assertion was hit, but this system was booted /NODEBUG. This is not supposed to happen as developers should never have hardcoded breakpoints in retail code, but ... If this happens, make sure a debugger gets connected, and the system is booted /DEBUG. This will let us see why this breakpoint is happening. Arguments: Arg1: c000001d, The exception code that was not handled Arg2: 99ff65fc, The address that the exception occurred at Arg3: 9dd073c0, Trap Frame Arg4: 00000000 Debugging Details: ------------------ ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: kernel32!pNlsUserInfo *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: kernel32!pNlsUserInfo *** *** *** ************************************************************************* EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction. FAULTING_IP: win32k!bLines+53f 99ff65fc 40 inc eax TRAP_FRAME: 9dd073c0 -- (.trap 0xffffffff9dd073c0) ErrCode = 00000000 eax=00000038 ebx=9dd0772c ecx=00000002 edx=001d0000 esi=9d567458 edi=00000000 eip=99ff65fc esp=9dd07434 ebp=9dd07664 iopl=0 nv up ei pl nz na po nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202 win32k!bLines+0x53f: 99ff65fc 40 inc eax Resetting default scope DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x8E PROCESS_NAME: LCDMedia.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from 8246a590 to 825010e3 FAILED_INSTRUCTION_ADDRESS: win32k!bLines+53f 99ff65fc 40 inc eax STACK_TEXT: 9dd06f80 8246a590 0000008e c000001d 99ff65fc nt!KeBugCheckEx+0x1e 9dd07350 8248c5da 9dd0736c 00000000 9dd073c0 nt!KiDispatchException+0x1a9 9dd073b8 8248c576 9dd07664 99ff65fc badb0d00 nt!CommonDispatchException+0x4a 9dd073c0 99ff65fc badb0d00 001d0000 9dd07654 nt!Kei386EoiHelper+0x16e 9dd07664 99ff6ec2 9a0c0e68 00008480 9dd07c14 win32k!bLines+0x53f 9dd07874 99fc0e14 fe208cb8 9dd07ad0 9dd07930 win32k!bStrokeCosmetic+0x443 9dd078a0 99fc0d1e fe208cc8 9dd07ad0 9dd07930 win32k!EngStrokePath+0xe6 9dd078f8 99fbfb04 00000500 9dd07a1c fe208cb8 win32k!EPATHOBJ::bSimpleStroke+0x1fc 9dd07a28 9a017173 00000d0d fe061070 9dd07a74 win32k!EPATHOBJ::bStrokeAndOrFill+0x469 9dd07cf4 9a0173fd 05010bfe 00000039 00000002 win32k!GreLineTo+0x68b 9dd07d50 8248ba1a 05010bfe 00000039 00000002 win32k!NtGdiLineTo+0x64 9dd07d50 77669a94 05010bfe 00000039 00000002 nt!KiFastCallEntry+0x12a 0012fa14 7649efd2 7649efba 05010bfe 00000039 ntdll!KiFastSystemCallRet 0012fa18 7649efba 05010bfe 00000039 00000002 GDI32!NtGdiLineTo+0xc 0012fa38 00410b91 05010bfe 00000039 00000002 GDI32!LineTo+0x92 WARNING: Stack unwind information not available. Following frames may be wrong. 0012fa70 0040f283 4266895e 020f7730 020f7770 LCDMedia+0x10b91 0012fa9c 0040faa5 020ffcc4 00000000 020f4d6c LCDMedia+0xf283 00000000 00000000 00000000 00000000 00000000 LCDMedia+0xfaa5 STACK_COMMAND: kb FOLLOWUP_IP: win32k!bLines+53f 99ff65fc 40 inc eax SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: win32k!bLines+53f FOLLOWUP_NAME: MachineOwner MODULE_NAME: win32k IMAGE_NAME: win32k.sys DEBUG_FLR_IMAGE_TIMESTAMP: 48d1b9ef FAILURE_BUCKET_ID: 0x8E_BAD_IP_win32k!bLines+53f BUCKET_ID: 0x8E_BAD_IP_win32k!bLines+53f Followup: MachineOwner --------- 1: kd> lmvm win32k start end module name 99ef0000 9a0f2000 win32k (pdb symbols) C:\Program Files\Debugging Tools for Windows\sym\win32k.pdb\230B5B2DCF9F4D36AEC89C0F41FE0EAA2\win32k.pdb Loaded symbol image file: win32k.sys Image path: \SystemRoot\System32\win32k.sys Image name: win32k.sys Timestamp: Wed Sep 17 19:16:15 2008 (48D1B9EF) CheckSum: 001F7B79 ImageSize: 00202000 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0