Çözüldü Intel i5 6200U mavi ekran hatası

Bu konu çözüldü olarak işaretlenmiştir. Çözülmediğini düşünüyorsanız konuyu rapor edebilirsiniz.
Durum
Mesaj gönderimine kapalı.

MFO10

Kilopat
Katılım
21 Temmuz 2016
Mesajlar
450
Çözümler
1
Daha fazla  
Cinsiyet
Erkek
Belli aralıklarla mavi ekran hatası alıyorum. Hata kodunu ve sistemimi de paylaşıyorum.

Windows 8.1 Pro.
Intel i5 6200U 2.30 GHz.
8 GB RAM.
NVIDIA 940M.
ASUS X555UB laptop.

 
Çözüm
Bellekte arıza tespit edilmiş. Dilersen Windows'un bellek test aracını da kullanabilirsin ama Memtest sorun var diyorsa sorun vardır. Belleklerini değiştirmende fayda var gibi.

Bellek sorunları bazen ısınma kaynaklı da olabilir ama Memtest esnasında sistem çok sıcak olmaz genelde. Ben bu yüzden bellek arızası diyorum Memtest gibi.

Bellekleri değiş, sonucu paylaş. Öncesinde ek test ede yapabilirsin dediğim gibi.
-Belleklerinizi test edin (Memtest86+ ile).
-Eksik veya eski sürücüleri güncelleyin.
-DDU ile sürücüleri silip temiz kurulum yapın.
-Eksik dosyalar için CMD'yi yönetici çalıştırıp sfc/scannow yapın.
-Genellikle belleklerde sorun var (ntoskrnl.exe)
-Sistemi malwarabytes ile taratın zararlı yazılımlar eksik dosya sorununa yol açabilir.
 
Isınma sorunları var evet ama normal zamanlarda bile kendi kendine kapandığı oluyor. Ve bazen şu konuda da belirttiğim gibi CPU kendi kendine 90-100 seviyesine çıkıyor.
Driver'ların doğruluğunu nasıl kontrol edebilirim?
 
Isınma sorunları var evet ama normal zamanlarda bile kendi kendine kapandığı oluyor. Ve bazen şu konuda da belirttiğim gibi CPU kendi kendine 90-100 seviyesine çıkıyor.
Driver'ların doğruluğunu nasıl kontrol edebilirim?

Malwarabytes ile taratın eğer anormal bir ısınma varsa Bitcoin mining virüsü olabilir.
 
Dosyalarını analiz ettim. Sorunun bellek kaynaklı olduğunu düşünüyorum. Memtest ile test eder misin?


Memtest sonucunu paylaşırsan sevinirim.

Kod:
DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000004, The power transition timed out waiting to synchronize with the Pnp
    subsystem.
Arg2: 000000000000012c, Timeout in seconds.
Arg3: ffffe000a9480800, The thread currently holding on to the Pnp lock.
Arg4: ffffd001d859ccd0, nt!TRIAGE_9F_PNP on Win7 and higher

Debugging Details:
------------------

Implicit thread is now ffffe000`a9480800
*** WARNING: Unable to verify timestamp for IntcAudioBus.sys
*** WARNING: Unable to verify timestamp for win32k.sys

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 5

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 7

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 63

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  9f

BUGCHECK_P1: 4

BUGCHECK_P2: 12c

BUGCHECK_P3: ffffe000a9480800

BUGCHECK_P4: ffffd001d859ccd0

DRVPOWERSTATE_SUBCODE:  4

IMAGE_NAME:  IntcAudioBus.sys

MODULE_NAME: IntcAudioBus

FAULTING_MODULE: fffff8014e28c000 IntcAudioBus

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd000`24f48090 fffff802`32aabb6e : ffffd001`d85e6180 ffffe000`a9480800 00000000`fffffffe 00000000`fffffffe : nt!KiSwapContext+0x76
ffffd000`24f481d0 fffff802`32aab5e9 : 00000000`00000000 ffffe000`a998f7b0 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x14e
ffffd000`24f48270 fffff802`32a5c4a3 : 00000000`00000000 00000000`00000000 ffffd000`24f48390 fffff802`32b63757 : nt!KiCommitThreadWait+0x129
ffffd000`24f482f0 fffff802`32bbf6f9 : ffffe000`a75840c0 fffff802`00000000 00000000`00000000 fffff802`00000000 : nt!KeWaitForSingleObject+0x373
ffffd000`24f48380 fffff802`3300877f : ffffe000`a7584010 ffffe000`a6afd060 ffffe000`a6afd060 ffffe000`a758aa50 : nt! ?? ::FNODOBFM::`string'+0x55e39
ffffd000`24f483c0 fffff802`32f95642 : ffffe000`a758aa50 ffffe000`a8bb88c8 ffffe000`a6afd060 ffffe000`a8bb88c8 : nt!PopFxUnregisterDevice+0xc3
ffffd000`24f48400 fffff802`33008666 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff801`4e36d010 : nt! ?? ::NNGAKEGL::`string'+0x695b2
ffffd000`24f48440 fffff801`4e3813ba : 00000000`ffffffff fffff801`4e38134c 00000000`00000010 00000000`00010246 : nt!PoFxUnregisterDevice+0x1e
ffffd000`24f48470 fffff801`4e37e05b : ffffe000`a6afd1b0 ffffe000`a8bb88c8 ffffe000`a8bb8690 00000000`00010246 : portcls!PnpStopDevice+0x6e
ffffd000`24f484b0 fffff801`4e37232c : ffffe000`a6afd060 ffffe000`a8bb8690 ffffe000`a6afd060 fffff801`4eb17048 : portcls!DispatchPnp+0x958b
ffffd000`24f48500 fffff801`4eb063ef : ffffe000`a6afd060 fffff802`32a5c6c6 ffffe000`a758db80 fffff802`32e7ef2d : portcls!PcDispatchIrp+0x32c
ffffd000`24f48570 ffffe000`a6afd060 : fffff802`32a5c6c6 ffffe000`a758db80 fffff802`32e7ef2d ffffe000`a758db80 : IntcDAud+0xc3ef
ffffd000`24f48578 fffff802`32a5c6c6 : ffffe000`a758db80 fffff802`32e7ef2d ffffe000`a758db80 fffff801`4e3b485f : 0xffffe000`a6afd060
ffffd000`24f48580 ffffd000`24f486b0 : ffffd000`00000000 ffffe000`a8bb8690 ffffd000`24f48602 ffffe000`a758aa50 : nt!KeWaitForSingleObject+0x596
ffffd000`24f48610 ffffd000`00000000 : ffffe000`a8bb8690 ffffd000`24f48602 ffffe000`a758aa50 00000000`c00000bb : 0xffffd000`24f486b0
ffffd000`24f48618 ffffe000`a8bb8690 : ffffd000`24f48602 ffffe000`a758aa50 00000000`c00000bb 00000000`00000000 : 0xffffd000`00000000
ffffd000`24f48620 ffffd000`24f48602 : ffffe000`a758aa50 00000000`c00000bb 00000000`00000000 00000000`00060001 : 0xffffe000`a8bb8690
ffffd000`24f48628 ffffe000`a758aa50 : 00000000`c00000bb 00000000`00000000 00000000`00060001 ffffd000`24f48648 : 0xffffd000`24f48602
ffffd000`24f48630 00000000`c00000bb : 00000000`00000000 00000000`00060001 ffffd000`24f48648 ffffd000`24f48648 : 0xffffe000`a758aa50
ffffd000`24f48638 00000000`00000000 : 00000000`00060001 ffffd000`24f48648 ffffd000`24f48648 ffffe000`a758db80 : 0xc00000bb


STACK_COMMAND:  .thread ; .cxr ; kb

FAILURE_BUCKET_ID:  0x9F_4_IntcDAud_IMAGE_IntcAudioBus.sys

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {4451066e-73a1-ced1-9f81-49d5b56ed94f}

Followup:     MachineOwner
---------

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8001825c922, Address of the instruction which caused the bugcheck
Arg3: ffffd000206286c0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  3b

BUGCHECK_P1: c0000005

BUGCHECK_P2: fffff8001825c922

BUGCHECK_P3: ffffd000206286c0

BUGCHECK_P4: 0

CONTEXT:  ffffd000206286c0 -- (.cxr 0xffffd000206286c0)
rax=00000000000000ff rbx=0000000000000000 rcx=ffffe00088df2118
rdx=0000000000000000 rsi=a0ffffc0011c55d0 rdi=0000000082caee0d
rip=fffff8001825c922 rsp=ffffd000206290f0 rbp=ffffd00020629198
 r8=0000000000000000  r9=ffffc00112c2005c r10=ffffc00112c2005c
r11=0000000000000000 r12=ffffc00111a6b401 r13=0000000000003670
r14=ffffc0010b816000 r15=a0ffffc0011c55c8
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010282
nt!CmpGetNameControlBlock+0x152:
fffff800`1825c922 3b3e            cmp     edi,dword ptr [rsi] ds:002b:a0ffffc0`011c55d0=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  launcher.exe

STACK_TEXT: 
ffffd000`206290f0 fffff800`1825c28f : 00000000`678f9301 00000000`00000026 ffffc001`e38392ae a0ffffc0`011c55c8 : nt!CmpGetNameControlBlock+0x152
ffffd000`20629170 fffff800`18246e4b : ffffc001`0c7f2000 ffffd000`01e8d300 ffffc001`15348304 ffffc001`0e6c1258 : nt!CmpCreateKeyControlBlock+0x3cf
ffffd000`20629200 fffff800`1843b954 : ffffc001`00000000 00000000`01e8d300 ffffd000`206298d0 ffffe000`88e21b10 : nt!CmpDoOpen+0x6ab
ffffd000`206292e0 fffff800`18324b9e : 00000000`00000000 00000000`00000000 ffffe000`00020000 ffffd000`20629691 : nt!CmpParseKey+0x10d4
ffffd000`206295a0 fffff800`18243f73 : 00000000`00000204 ffffd000`20629758 ffffc001`00000040 ffffe000`845a5f20 : nt!ObpLookupObjectName+0x7be
ffffd000`206296e0 fffff800`18243b94 : 00000000`00000001 000000c2`fdc6c498 000000c2`fdc6c430 00000000`00020019 : nt!ObOpenObjectByName+0x1e3
ffffd000`20629810 fffff800`182438e3 : ffff9bcb`e346f84a 00000000`0000017e 00007fff`e06c5740 00007fff`e06a11f0 : nt!CmOpenKey+0x2a4
ffffd000`206299c0 fffff800`17fdfbb3 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000000 : nt!NtOpenKeyEx+0xf
ffffd000`20629a00 00007fff`e26d173a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
000000c2`fdc6c3d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`e26d173a


SYMBOL_NAME:  nt!CmpGetNameControlBlock+152

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .cxr 0xffffd000206286c0 ; kb

BUCKET_ID_FUNC_OFFSET:  152

FAILURE_BUCKET_ID:  0x3B_c0000005_nt!CmpGetNameControlBlock

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {8a5e360a-e831-e203-6a33-02da6bab5e29}

Followup:     MachineOwner
---------

DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
Arg2: ffffe00100b6ca90, Physical Device Object of the stack
Arg3: ffffd001579fb860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack
Arg4: ffffe00100b81790, The blocked IRP

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for IntcAudioBus.sys

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 3

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 63

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  9f

BUGCHECK_P1: 3

BUGCHECK_P2: ffffe00100b6ca90

BUGCHECK_P3: ffffd001579fb860

BUGCHECK_P4: ffffe00100b81790

DRVPOWERSTATE_SUBCODE:  3

DRIVER_OBJECT: ffffe001002f4640

IMAGE_NAME:  IntcAudioBus.sys

MODULE_NAME: IntcAudioBus

FAULTING_MODULE: fffff801ebabd000 IntcAudioBus

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd001`579fb828 fffff801`e5c1d2f2 : 00000000`0000009f 00000000`00000003 ffffe001`00b6ca90 ffffd001`579fb860 : nt!KeBugCheckEx
ffffd001`579fb830 fffff801`e5c1d212 : ffffe001`00b81338 00000000`00000008 ffffd001`579fb958 fffff801`e5a54f45 : nt!PopIrpWatchdogBugcheck+0xde
ffffd001`579fb890 fffff801`e5a563c8 : 00000000`00000000 ffffd001`579fb9e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32
ffffd001`579fb8e0 fffff801`e5b6beea : ffffd001`579e6180 ffffd001`579e6180 ffffd001`579f22c0 ffffe001`00dd4880 : nt!KiRetireDpcList+0x4f8
ffffd001`579fbb60 00000000`00000000 : ffffd001`579fc000 ffffd001`579f5000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND:  .thread ; .cxr ; kb

FAILURE_BUCKET_ID:  0x9F_3_IMAGE_IntcAudioBus.sys

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {5eb67757-a85c-4361-5751-171332ac0b2a}

Followup:     MachineOwner
---------

3: kd> lmvm IntcAudioBus
Browse full module list
start             end                 module name
fffff801`ebabd000 fffff801`ebae4000   IntcAudioBus T (no symbols)           
    Loaded symbol image file: IntcAudioBus.sys
    Image path: \SystemRoot\System32\drivers\IntcAudioBus.sys
    Image name: IntcAudioBus.sys
    Browse all global symbols  functions  data
    Timestamp:        Thu Mar  5 14:20:16 2015 (54F83BF0)
    CheckSum:         0002AF30
    ImageSize:        00027000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Information from resource tables:
    
    DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
Arg2: ffffe001e41a6060, Physical Device Object of the stack
Arg3: ffffd00064794860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack
Arg4: ffffe001e88cdbd0, The blocked IRP

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 7

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 64

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  9f

BUGCHECK_P1: 3

BUGCHECK_P2: ffffe001e41a6060

BUGCHECK_P3: ffffd00064794860

BUGCHECK_P4: ffffe001e88cdbd0

DRVPOWERSTATE_SUBCODE:  3

DRIVER_OBJECT: ffffe001e41be060

IMAGE_NAME:  pci.sys

MODULE_NAME: pci

FAULTING_MODULE: fffff80038697000 pci

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd000`64794828 fffff803`8a8832f2 : 00000000`0000009f 00000000`00000003 ffffe001`e41a6060 ffffd000`64794860 : nt!KeBugCheckEx
ffffd000`64794830 fffff803`8a883212 : ffffe001`e3b9a660 ffffe001`e83bd880 ffffe001`e3b9a600 fffff803`8a6baf45 : nt!PopIrpWatchdogBugcheck+0xde
ffffd000`64794890 fffff803`8a6bc3c8 : 00000000`00000000 ffffd000`647949e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32
ffffd000`647948e0 fffff803`8a7d1eea : ffffd000`687ec180 ffffd000`687ec180 ffffd000`687f82c0 ffffe001`e7a2a880 : nt!KiRetireDpcList+0x4f8
ffffd000`64794b60 00000000`00000000 : ffffd000`64795000 ffffd000`6478e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


IMAGE_VERSION:  6.3.9600.17238

STACK_COMMAND:  .thread ; .cxr ; kb

FAILURE_BUCKET_ID:  0x9F_3_IMAGE_pci.sys

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {a89ab2d1-2459-89ee-9990-558bbc68ffab}

Followup:     MachineOwner
---------

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa8003dd7540
Arg3: fffffa8003b3a570
Arg4: 0000000000000201

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  1a

BUGCHECK_P1: 8886

BUGCHECK_P2: fffffa8003dd7540

BUGCHECK_P3: fffffa8003b3a570

BUGCHECK_P4: 201

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  svchost.exe

STACK_TEXT: 
ffffd000`27316518 fffff801`cd7eb517 : 00000000`0000001a 00000000`00008886 fffffa80`03dd7540 fffffa80`03b3a570 : nt!KeBugCheckEx
ffffd000`27316520 fffff801`cd736cff : ffffe000`00000001 00000000`00000000 00000000`00000000 00000000`00000005 : nt! ?? ::FNODOBFM::`string'+0xec57
ffffd000`273165b0 fffff801`cd736a8c : fffffa80`03dd7540 00000000`00000000 00000000`00000002 fffff801`cda63ad7 : nt!MiRelinkStandbyPage+0x23
ffffd000`273165e0 fffff801`cda427f0 : 00000000`00000001 ffffd000`27316a80 ffffe000`d2ca2000 00000000`00000000 : nt!MmSetPfnListPriorities+0xfc
ffffd000`27316640 fffff801`cda27a59 : fffffa80`05d9e3a0 00000000`00000001 ffffd000`27316740 ffffe000`d2ca2000 : nt!PfpPfnPrioRequest+0x220
ffffd000`273166c0 fffff801`cda271d0 : 00000000`4e2fb150 00000000`00000000 00000000`00000000 fffff680`61675a01 : nt!PfSetSuperfetchInformation+0x105
ffffd000`273167a0 fffff801`cd7d7bb3 : ffffe000`d12f1080 00000000`0000003f 000000c2`4e754801 00000000`00000001 : nt!NtSetSystemInformation+0x1dc
ffffd000`27316a00 00007ffd`81061f2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
000000c2`4e2faf48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`81061f2a


SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+ec57

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  ec57

FAILURE_BUCKET_ID:  0x1a_8886_nt!_??_::FNODOBFM::_string_

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {c57d09b3-1175-ffc6-e486-373f0712eef1}

Followup:     MachineOwner
---------
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffc001b7585e60, String that identifies the problem.
Arg2: 0000000000000000, Error Code.
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------

ETW minidump data unavailable

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 3

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 3

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

ERROR_CODE: (NTSTATUS) 0xc000021a - { nemli Sistem Hatas }  %hs sistem i lemi, 0x

EXCEPTION_CODE_STR:  c000021a

EXCEPTION_PARAMETER1:  ffffc001b7585e60

EXCEPTION_PARAMETER2:  0000000000000000

EXCEPTION_PARAMETER3:  0000000000000000

EXCEPTION_PARAMETER4: 0

BUGCHECK_CODE:  c000021a

BUGCHECK_P1: ffffc001b7585e60

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

PROCESS_NAME:  services.exe

ADDITIONAL_DEBUG_TEXT:  Uzaktan Yordam Çaðrýsý (RPC) hizmeti beklenmedik biçimde sonlandýrýldýðýndan, Windows þimdi yeniden baþlatýlmalýdýr

TAG_NOT_DEFINED_1004c: 
This is a STATUS_SYSTEM_PROCESS_TERMINATED bugcheck.
It signals that the system is rebooting due to a critical service termination.
The bugcheck is not very useful for debugging. To investigate the root cause
find the related svchost.exe crashes that happened on the same machine
around the time of this dump.

IMAGE_NAME:  ntkrnlmp.exe

MODULE_NAME: nt

CUSTOMER_CRASH_COUNT:  1

STACK_TEXT: 
ffffd001`6703c5b8 fffff802`dc58d98d : 00000000`0000004c 00000000`c000021a ffffd001`681ff2f8 ffffe000`e119b900 : nt!KeBugCheckEx
ffffd001`6703c5c0 fffff802`dc5874ea : ffffe000`e1a02b00 ffffd001`6703c6d9 00000000`00000000 00000000`00000002 : nt!PopGracefulShutdown+0x2c9
ffffd001`6703c600 fffff802`dc362bb3 : ffffe000`e1a02880 fffff802`dc33fc00 00000000`c0000004 fffff802`dc244400 : nt! ?? ::OKHAJAOM::`string'+0x269a
ffffd001`6703c740 fffff802`dc35b020 : fffff802`dc7963b1 00000000`00000001 ffffd001`6703c958 00000000`c0000004 : nt!KiSystemServiceCopyEnd+0x13
ffffd001`6703c8d8 fffff802`dc7963b1 : 00000000`00000001 ffffd001`6703c958 00000000`c0000004 ffffd001`6abec180 : nt!KiServiceLinkage
ffffd001`6703c8e0 fffff802`dc6d0ca7 : 00000000`00000000 00000000`00000000 ffffd001`6abec180 ffffe000`e1a029c0 : nt! ?? ::NNGAKEGL::`string'+0x6c321
ffffd001`6703c9a0 fffff802`dc2ea91a : fffff802`dc2ea860 00000000`00000000 00000000`00000002 00000000`00000000 : nt!PopPolicyWorkerAction+0x63
ffffd001`6703ca10 fffff802`dc247d6f : fffff802`00000002 ffffe000`e1a02880 fffff802`dc4c3080 fffff801`79513d90 : nt!PopPolicyWorkerThread+0xba
ffffd001`6703ca50 fffff802`dc239f34 : ffffc001`b636ed88 ffffe000`e1a02880 00000000`00000080 ffffe000`e1a02880 : nt!ExpWorkerThread+0x69f
ffffd001`6703cb00 fffff802`dc35d9c6 : ffffd001`6ab60180 ffffe000`e1a02880 ffffe000`e20f0080 fffff801`7957a6ef : nt!PspSystemThreadStartup+0x58
ffffd001`6703cb60 00000000`00000000 : ffffd001`6703d000 ffffd001`67036000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16


SYMBOL_NAME:  nt! ?? ::OKHAJAOM::`string'+269a

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  269a

FAILURE_BUCKET_ID:  0xc000021a_rpcss.dll_Critical_Service_Terminated_nt!_??_::OKHAJAOM::_string_

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {985ba5ee-c7fd-3ab7-c026-2d066fd15a29}

Followup:     MachineOwner
---------


This is a STATUS_SYSTEM_PROCESS_TERMINATED bugcheck.
It signals that the system is rebooting due to a critical service termination.
The bugcheck is not very useful for debugging. To investigate the root cause
find the related svchost.exe crashes that happened on the same machine
around the time of this dump.

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000010, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff801deee2510, address which referenced memory

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  a

BUGCHECK_P1: 10

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff801deee2510

WRITE_ADDRESS: fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock
GetUlongPtrFromAddress: unable to read from fffff801df1e6298
GetUlongPtrFromAddress: unable to read from fffff801df1e6520
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock
 0000000000000010

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  Origin.exe

TRAP_FRAME:  ffffd00207027330 -- (.trap 0xffffd00207027330)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000fffffffff rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801deee2510 rsp=ffffd002070274c0 rbp=fffff801df1de6c0
 r8=0000000000000000  r9=0000000000000000 r10=fffffa8001102590
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
nt!MiReplenishPageSlist+0x170:
fffff801`deee2510 f0410fba681000  lock bts dword ptr [r8+10h],0 ds:00000000`00000010=????????
Resetting default scope

STACK_TEXT: 
ffffd002`070271e8 fffff801`defe3ee9 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd002`070271f0 fffff801`defe273a : 00000000`00000001 00000000`00000005 ffffd002`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffd002`07027330 fffff801`deee2510 : ffff085f`d40c2a9a 00000000`00000000 00000000`00000001 00000000`00000002 : nt!KiPageFault+0x23a
ffffd002`070274c0 fffff801`deee0639 : fffff801`df1de6c0 00000000`00000033 00000000`00000000 fffffa80`0064dd90 : nt!MiReplenishPageSlist+0x170
ffffd002`07027540 fffff801`deedf699 : 00000000`00000002 00000000`000000c2 ffffffff`fffffffe 00000000`000004c8 : nt!MiRemoveAnyPage+0x2d9
ffffd002`07027610 fffff801`deedf2df : 00000000`00000033 00000000`00000000 00000000`000000c2 00000000`00000001 : nt!MiGetFreeOrZeroPage+0x249
ffffd002`070276b0 fffff801`deede283 : 00000400`00000000 00000000`00000002 00000000`00000001 ffffd002`07027780 : nt!MiGetPage+0x6f
ffffd002`07027720 fffff801`deed9af0 : 00000000`00000001 00000000`03f09000 ffffd002`07027a00 fffff680`0001f848 : nt!MiResolveDemandZeroFault+0x193
ffffd002`07027840 fffff801`defe262f : 00000000`00000001 00000000`00078000 ffffc001`a19bf001 ffffc001`a19bf000 : nt!MmAccessFault+0x4e0
ffffd002`07027a00 00000000`7412de7e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x12f
00000000`00d0afb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7412de7e


SYMBOL_NAME:  nt!MiReplenishPageSlist+170

MODULE_NAME: nt

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .thread ; .cxr ; kb

IMAGE_NAME:  memory_corruption

BUCKET_ID_FUNC_OFFSET:  170

FAILURE_BUCKET_ID:  AV_nt!MiReplenishPageSlist

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {e1780c1b-c7ae-f629-f6fa-ba2f8fe42756}

Followup:     MachineOwner
---------

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000025,
Arg2: 0000000000000001
Arg3: 0000000000000001
Arg4: ffffe0015dec1290

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 61

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  19

BUGCHECK_P1: 25

BUGCHECK_P2: 1

BUGCHECK_P3: 1

BUGCHECK_P4: ffffe0015dec1290

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd000`9830f708 fffff800`64126077 : 00000000`00000019 00000000`00000025 00000000`00000001 00000000`00000001 : nt!KeBugCheckEx
ffffd000`9830f710 fffff801`b087d5bb : 00000000`00000001 ffffe001`5d372000 ffffe001`5d372000 00000000`00000035 : nt!ExDeferredFreePool+0x807
ffffd000`9830f800 fffff801`b087c914 : ffffe001`5d70c2a0 ffffe001`5d70c2a0 ffffd000`9830f990 ffffe001`5d70c2a0 : dxgmms1!VidSchiSwitchContextWithCheck+0x2db
ffffd000`9830f890 fffff801`b08b2fb8 : ffffe001`5ff5f000 ffffe001`5ff5f000 ffffe001`5d70c2a0 ffffe001`00000000 : dxgmms1!VidSchiScheduleCommandToRun+0x304
ffffd000`9830fa50 fffff801`b08b2f7d : ffffe001`5ff5f000 ffffe001`00000000 00000000`00000080 ffffe001`60305500 : dxgmms1!VidSchiRun_PriorityTable+0x38
ffffd000`9830fac0 fffff800`63eb7f34 : ffffd000`9aff82c0 ffffe001`60305500 ffffd000`9830fb90 fffff800`63fd877d : dxgmms1!VidSchiWorkerThread+0x8d
ffffd000`9830fb00 fffff800`63fdb9c6 : ffffd000`9afec180 ffffe001`60305500 ffffd000`9aff82c0 fffff800`63f2c4e0 : nt!PspSystemThreadStartup+0x58
ffffd000`9830fb60 00000000`00000000 : ffffd000`98310000 ffffd000`98309000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16


SYMBOL_NAME:  nt!ExDeferredFreePool+807

IMAGE_NAME:  Pool_Corruption

IMAGE_VERSION:  6.3.9600.18505

MODULE_NAME: Pool_Corruption

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  807

FAILURE_BUCKET_ID:  0x19_25_nt!ExDeferredFreePool

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {680ab642-66fb-4ff9-27f7-315ec4127c9b}

Followup:     Pool_corruption
---------

1: kd> lmvm Pool_Corruption
Browse full module list
start             end                 module name

DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
Arg2: ffffe0009cb77c40, Physical Device Object of the stack
Arg3: ffffd001b94ab860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack
Arg4: ffffe0009c2893e0, The blocked IRP

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for IntcAudioBus.sys

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 8

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 63

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  9f

BUGCHECK_P1: 3

BUGCHECK_P2: ffffe0009cb77c40

BUGCHECK_P3: ffffd001b94ab860

BUGCHECK_P4: ffffe0009c2893e0

DRVPOWERSTATE_SUBCODE:  3

DRIVER_OBJECT: ffffe0009c19c820

IMAGE_NAME:  IntcAudioBus.sys

MODULE_NAME: IntcAudioBus

FAULTING_MODULE: fffff8002a906000 IntcAudioBus

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd001`b94ab828 fffff800`ffe812f2 : 00000000`0000009f 00000000`00000003 ffffe000`9cb77c40 ffffd001`b94ab860 : nt!KeBugCheckEx
ffffd001`b94ab830 fffff800`ffe81212 : ffffe000`9cbdd338 00000000`00000008 ffffd001`b94ab958 fffff800`ffcb8f45 : nt!PopIrpWatchdogBugcheck+0xde
ffffd001`b94ab890 fffff800`ffcba3c8 : 00000000`00000000 ffffd001`b94ab9e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32
ffffd001`b94ab8e0 fffff800`ffdcfeea : ffffd001`b9481180 ffffd001`b9481180 ffffd001`b948d2c0 ffffe000`9c0a1040 : nt!KiRetireDpcList+0x4f8
ffffd001`b94abb60 00000000`00000000 : ffffd001`b94ac000 ffffd001`b94a5000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND:  .thread ; .cxr ; kb

FAILURE_BUCKET_ID:  0x9F_3_IMAGE_IntcAudioBus.sys

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {5eb67757-a85c-4361-5751-171332ac0b2a}

Followup:     MachineOwner
---------

3: kd> lmvm IntcAudioBus
Browse full module list
start             end                 module name
fffff800`2a906000 fffff800`2a92d000   IntcAudioBus T (no symbols)           
    Loaded symbol image file: IntcAudioBus.sys
    Image path: \SystemRoot\System32\drivers\IntcAudioBus.sys
    Image name: IntcAudioBus.sys
    Browse all global symbols  functions  data
    Timestamp:        Thu Mar  5 14:20:16 2015 (54F83BF0)
    CheckSum:         0002AF30
    ImageSize:        00027000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Information from resource tables:
DPC_WATCHDOG_VIOLATION (133)
The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL
or above.
Arguments:
Arg1: 0000000000000000, A single DPC or ISR exceeded its time allotment. The offending
    component can usually be identified with a stack trace.
Arg2: 0000000000000501, The DPC time count (in ticks).
Arg3: 0000000000000500, The DPC time allotment (in ticks).
Arg4: 0000000000000000, cast to nt!DPC_WATCHDOG_GLOBAL_TRIAGE_BLOCK, which contains
    additional information regarding this single DPC timeout

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 63

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  133

BUGCHECK_P1: 0

BUGCHECK_P2: 501

BUGCHECK_P3: 500

BUGCHECK_P4: 0

DPC_TIMEOUT_TYPE:  SINGLE_DPC_TIMEOUT_EXCEEDED

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd001`55fa3c88 fffff801`4f1750dc : 00000000`00000133 00000000`00000000 00000000`00000501 00000000`00000500 : nt!KeBugCheckEx
ffffd001`55fa3c90 fffff801`4f05b1f7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x1681c
ffffd001`55fa3d20 fffff801`4f79467f : 00000000`000000ff fffff801`4f03beb4 ffffe000`6c6003b0 00000000`0000b801 : nt!KeClockInterruptNotify+0x787
ffffd001`55fa3f40 fffff801`4f0d9db3 : ffffe000`6c600300 00000000`00000008 ffffe000`7088c280 00000000`000000ff : hal!HalpTimerClockInterrupt+0x4f
ffffd001`55fa3f70 fffff801`4f14f82a : ffffe000`6c600300 ffffe000`7088c010 ffffe000`7088c288 ffffe000`7088c0b8 : nt!KiCallInterruptServiceRoutine+0xa3
ffffd001`55fa3fb0 fffff801`4f14fc0f : 00000000`00000000 00000000`000000ff ffffe000`7088c288 ffffe000`6f7dc900 : nt!KiInterruptSubDispatchNoLockNoEtw+0xea
ffffd001`55f94710 fffff801`58b4bcaf : ffffd001`55f94a02 ffffe000`6cf4daf0 ffffe000`6d08a7b8 ffffe000`7088c2c0 : nt!KiInterruptDispatchLBControl+0x11f
ffffd001`55f948a0 fffff801`4f03c3c8 : ffffd001`55f94a20 00000000`07981c04 ffffd001`55f949e0 ffffd001`59fec180 : usb8023x!CancelSendsTimerDpc+0x57
ffffd001`55f948e0 fffff801`4f151eea : ffffd001`59fec180 ffffd001`59fec180 ffffd001`59ff82c0 ffffe000`6ebb3340 : nt!KiRetireDpcList+0x4f8
ffffd001`55f94b60 00000000`00000000 : ffffd001`55f95000 ffffd001`55f8e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


SYMBOL_NAME:  usb8023x!CancelSendsTimerDpc+57

MODULE_NAME: usb8023x

IMAGE_NAME:  usb8023x.sys

IMAGE_VERSION:  6.3.9600.16384

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  57

FAILURE_BUCKET_ID:  0x133_DPC_usb8023x!CancelSendsTimerDpc

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {246f7e65-0458-b0d9-ce75-f02203155395}

Followup:     MachineOwner
---------

2: kd> lmvm usb8023x
Browse full module list
start             end                 module name
fffff801`58b49000 fffff801`58b54000   usb8023x   (pdb symbols)          C:\ProgramData\Dbg\sym\usb8023x.pdb\29F6FDE964F84B8EAEAC34E2081CCEBC1\usb8023x.pdb
    Loaded symbol image file: usb8023x.sys
    Mapped memory image file: C:\ProgramData\Dbg\sym\usb8023x.sys\5215F829b000\usb8023x.sys
    Image path: \SystemRoot\system32\DRIVERS\usb8023x.sys
    Image name: usb8023x.sys
    Browse all global symbols  functions  data
    Timestamp:        Thu Aug 22 14:38:17 2013 (5215F829)
    CheckSum:         0000E78E
    ImageSize:        0000B000
    File version:     6.3.9600.16384
    Product version:  6.3.9600.16384
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        2.0 Dll
    File date:        00000000.00000000
    Translations:     0409.04b0
    Information from resource tables:
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     usb8023.sys
        OriginalFilename: usb8023.sys
        ProductVersion:   6.3.9600.16384
        FileVersion:      6.3.9600.16384 (winblue_rtm.130821-1623)
        FileDescription:  Remote NDIS USB Driver
        LegalCopyright:   © Microsoft Corporation. All rights reserved.
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffd00025d9f6e0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffd00025d9f638, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  139

BUGCHECK_P1: 3

BUGCHECK_P2: ffffd00025d9f6e0

BUGCHECK_P3: ffffd00025d9f638

BUGCHECK_P4: 0

TRAP_FRAME:  ffffd00025d9f6e0 -- (.trap 0xffffd00025d9f6e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe000f3c64018 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffe000f3c64118 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801e14f687c rsp=ffffd00025d9f878 rbp=ffffe000f3c64001
 r8=ffffe000f3c64118  r9=7fffe000f6a32b88 r10=0000000000000003
r11=7ffffffffffffffc r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz ac po nc
nt!KiInsertQueueApc+0x68:
fffff801`e14f687c cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  ffffd00025d9f638 -- (.exr 0xffffd00025d9f638)
ExceptionAddress: fffff801e14f687c (nt!KiInsertQueueApc+0x0000000000000068)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  opera.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y   n tabanl  bir arabelle in ta t   n  alg lad . Bu ta ma, k t  niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000003

EXCEPTION_STR:  0xc0000409

STACK_TEXT: 
ffffd000`25d9f3b8 fffff801`e15cdee9 : 00000000`00000139 00000000`00000003 ffffd000`25d9f6e0 ffffd000`25d9f638 : nt!KeBugCheckEx
ffffd000`25d9f3c0 fffff801`e15ce210 : 00000000`00000000 00000000`00000000 00000000`00000000 0158814a`81458101 : nt!KiBugCheckDispatch+0x69
ffffd000`25d9f500 fffff801`e15cd434 : ffffe000`f406c530 ffffd000`25d9f758 ffffed18`5cd13361 ffffe000`ef9a4f20 : nt!KiFastFailDispatch+0xd0
ffffd000`25d9f6e0 fffff801`e14f687c : fffff801`e14a5aad ffffe000`f0c34880 ffffe000`f0c34801 ffffe000`f6a32b88 : nt!KiRaiseSecurityCheckFailure+0xf4
ffffd000`25d9f878 fffff801`e14a5aad : ffffe000`f0c34880 ffffe000`f0c34801 ffffe000`f6a32b88 fffff801`e1822d56 : nt!KiInsertQueueApc+0x68
ffffd000`25d9f880 fffff801`e1822ffa : ffffe000`f3c64080 ffffe000`f3c64080 00000000`00000000 00000000`00000000 : nt!KeRequestTerminationThread+0x75
ffffd000`25d9f8c0 fffff801`e1822ab4 : 00000000`f6a328c8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!PspTerminateThreadByPointer+0x6a
ffffd000`25d9f8f0 fffff801`e1822891 : ffffe000`f642c880 ffffe000`f19dad80 ffffe000`f6a328c0 ffffe000`f6a328c0 : nt!PspTerminateAllThreads+0xf0
ffffd000`25d9f950 fffff801`e182261e : ffffffff`ffffffff ffffe000`f00991c0 ffffe000`f6a328c0 ffffe000`f19da880 : nt!PspTerminateProcess+0xe5
ffffd000`25d9f990 fffff801`e15cdbb3 : ffffe000`f6a328c0 ffffe000`f19da880 ffffd000`25d9fa80 00000000`00000000 : nt!NtTerminateProcess+0x9e
ffffd000`25d9fa00 00007ff9`a8f7097a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000082`e88cf6a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`a8f7097a


SYMBOL_NAME:  nt!KiFastFailDispatch+d0

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  d0

FAILURE_BUCKET_ID:  0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {3aede96a-54dd-40d6-d4cb-2a161a843851}

Followup:     MachineOwner
---------
VIDEO_MEMORY_MANAGEMENT_INTERNAL (10e)
The video memory manager encountered a condition that it can't recover from. By crashing,
the video memory manager is attempting to get enough information into the minidump such that
somebody can pinpoint what lead to this condition.
Arguments:
Arg1: 000000000000001f, The subtype of the bugcheck:
Arg2: ffffc00142fdd010
Arg3: 0000000000000000
Arg4: 000000000029f0fc

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 63

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  10e

BUGCHECK_P1: 1f

BUGCHECK_P2: ffffc00142fdd010

BUGCHECK_P3: 0

BUGCHECK_P4: 29f0fc

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT: 
ffffd000`dc105438 fffff800`d1de39ca : 00000000`0000010e 00000000`0000001f ffffc001`42fdd010 00000000`00000000 : nt!KeBugCheckEx
ffffd000`dc105440 fffff800`d108d46b : ffffe000`c65c8900 00000000`0029f0fc ffffc001`3cd59e48 ffffd000`dc105580 : watchdog!WdLogEvent5_WdCriticalError+0xce
ffffd000`dc105480 fffff800`d106d711 : 00000000`00000002 00000000`00000002 00000000`00000000 ffffe000`c7ab1508 : dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+0x1b2cb
ffffd000`dc105700 fffff800`d10831d2 : ffffe000`c8772a50 ffffe000`00000000 ffffe000`00000000 ffffe000`00000001 : dxgmms1!VidSchiSubmitRenderCommand+0x1f1
ffffd000`dc105a50 fffff800`d1082f7d : ffffe000`c7ab1000 ffffe000`00000000 00000000`00000080 ffffe000`c7a7b080 : dxgmms1!VidSchiRun_PriorityTable+0x252
ffffd000`dc105ac0 fffff800`974a5f34 : ffffd000`de1f82c0 ffffe000`c7a7b080 ffffd000`dc105b90 fffff800`975c677d : dxgmms1!VidSchiWorkerThread+0x8d
ffffd000`dc105b00 fffff800`975c99c6 : ffffd000`de1ec180 ffffe000`c7a7b080 ffffd000`de1f82c0 00000000`0000000f : nt!PspSystemThreadStartup+0x58
ffffd000`dc105b60 00000000`00000000 : ffffd000`dc106000 ffffd000`dc0ff000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16


SYMBOL_NAME:  dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+1b2cb

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

IMAGE_VERSION:  6.3.9600.17415

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  1b2cb

FAILURE_BUCKET_ID:  0x10e_1f_dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {e59c19db-fe47-a4eb-496d-1dc2434ca82a}

Followup:     MachineOwner
---------

REFERENCE_BY_POINTER (18)
Arguments:
Arg1: ffffe0016e16d930, Object type of the object whose reference count is being lowered
Arg2: ffffe001719049d0, Object whose reference count is being lowered
Arg3: 0000000000000001, Reserved
Arg4: 0000000000000001, Reserved
    The reference count of an object is illegal for the current state of the object.
    Each time a driver uses a pointer to an object the driver calls a kernel routine
    to increment the reference count of the object. When the driver is done with the
    pointer the driver calls another kernel routine to decrement the reference count.
    Drivers must match calls to the increment and decrement routines. This bugcheck
    can occur because an object's reference count goes to zero while there are still
    open handles to the object, in which case the fourth parameter indicates the number
    of opened handles. It may also occur when the object's reference count drops below zero
    whether or not there are open handles to the object, and in that case the fourth parameter
    contains the actual value of the pointer references count.

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 60

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  18

BUGCHECK_P1: ffffe0016e16d930

BUGCHECK_P2: ffffe001719049d0

BUGCHECK_P3: 1

BUGCHECK_P4: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  uTorrent.exe

STACK_TEXT: 
ffffd000`204871d8 fffff800`e73ebe58 : 00000000`00000018 ffffe001`6e16d930 ffffe001`719049d0 00000000`00000001 : nt!KeBugCheckEx
ffffd000`204871e0 fffff800`e7644112 : ffffd000`20487530 fffff800`e7561140 ffffe001`6eacd110 fffff800`00000006 : nt! ?? ::FNODOBFM::`string'+0x12598
ffffd000`20487220 fffff800`e76de112 : ffffe001`6f07e000 00000000`0225f148 ffffd000`204879a8 00000000`00000000 : nt!ObWaitForMultipleObjects+0x2d2
ffffd000`20487730 fffff800`e73d4bb3 : 00000000`00000001 ffffd000`20487a00 ffffd000`204879c0 00000000`00000000 : nt!NtWaitForMultipleObjects32+0xda
ffffd000`20487990 00000000`771c2352 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0225f128 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771c2352


SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+12598

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  12598

FAILURE_BUCKET_ID:  0x18_CORRUPT_REF_COUNT_nt!_??_::FNODOBFM::_string_

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {f79c57ae-b68f-40b5-de2a-a8ffc9173143}

Followup:     MachineOwner
---------
NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 000000b500190645
Arg2: ffffd00021ac6d48
Arg3: ffffd00021ac6550
Arg4: fffff8012be5946b

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 69

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  24

BUGCHECK_P1: b500190645

BUGCHECK_P2: ffffd00021ac6d48

BUGCHECK_P3: ffffd00021ac6550

BUGCHECK_P4: fffff8012be5946b

EXCEPTION_RECORD:  ffffd00021ac6d48 -- (.exr 0xffffd00021ac6d48)
ExceptionAddress: fffff8012be5946b (nt!ExpReleaseResourceForThreadLite+0x000000000000005b)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  ffffd00021ac6550 -- (.cxr 0xffffd00021ac6550)
rax=0000000000000000 rbx=00020000000115cd rcx=000200000001162d
rdx=ffffd00021ac6fd0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8012be5946b rsp=ffffd00021ac6f80 rbp=ffffd00021ac7080
 r8=0000000000000000  r9=7fffe000f5711428 r10=ffffe000f5711428
r11=7ffffffffffffffc r12=0000000000000727 r13=ffffe000f5711180
r14=0000000000000000 r15=ffffe000f60ed880
iopl=0         nv up di pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010046
nt!ExpReleaseResourceForThreadLite+0x5b:
fffff801`2be5946b 488711          xchg    rdx,qword ptr [rcx] ds:002b:00020000`0001162d=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  svchost.exe

READ_ADDRESS: fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock
GetUlongPtrFromAddress: unable to read from fffff8012c171298
GetUlongPtrFromAddress: unable to read from fffff8012c171520
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock
 ffffffffffffffff

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek  u olamaz %s.

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

EXCEPTION_STR:  0xc0000005

STACK_TEXT: 
ffffd000`21ac6f80 fffff801`c5502e6b : ffffb000`00000000 fffff801`c5612231 ffffe000`f6f2f702 fffff801`2befd1cf : nt!ExpReleaseResourceForThreadLite+0x5b
ffffd000`21ac70c0 fffff801`c5612652 : ffffc000`47b43010 ffffd000`21ac7501 ffffe000`f5b7aa00 ffffe000`f5711180 : Ntfs!NtfsReleaseFcb+0x4b
ffffd000`21ac7100 fffff801`c5624e87 : 00000000`00000000 00000000`00000000 ffffd000`21ac7500 ffffc000`48ddb580 : Ntfs!NtfsReleaseAllFiles+0xc2
ffffd000`21ac7150 fffff801`c5623591 : ffffe000`f7023060 ffffe000`f7085010 ffffe000`f5b7ab38 fffff801`c5208f5d : Ntfs!NtfsDefragFileInternal+0x1771
ffffd000`21ac73d0 fffff801`c5642294 : ffffe000`00000000 ffffe000`f613fb00 ffffc000`550d64b0 ffffe000`f5711180 : Ntfs!NtfsDefragFile+0x3cd
ffffd000`21ac7480 fffff801`c55dc074 : 00000000`00000000 ffffd000`21ac7500 00000000`00000001 ffffd000`21ac7500 : Ntfs!NtfsUserFsRequest+0x66b8c
ffffd000`21ac74c0 fffff801`c5398b1e : ffffe000`f8e378c0 00000000`00000000 00000000`00000000 ffffe000`f6d73d28 : Ntfs!NtfsFsdFileSystemControl+0x2e0
ffffd000`21ac7610 fffff801`c53c1831 : ffffd000`21ac76d0 ffffe000`f7118040 ffffe000`f6d73d28 ffffe000`f6d73940 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2ce
ffffd000`21ac76b0 fffff801`2c2b0e03 : 00000000`00000002 ffffd000`21ac7791 ffffe000`f7937580 ffffe000`f6a588c0 : fltmgr!FltpFsControl+0x111
ffffd000`21ac7710 fffff801`2c2b1d36 : ffffe000`f7937505 ffffd000`21ac7a80 ffffe000`f613faa0 ffffe000`f7937580 : nt!IopSynchronousServiceTail+0x32b
ffffd000`21ac77e0 fffff801`2c1c357a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0xd86
ffffd000`21ac7920 fffff801`2bf6ebb3 : fffff6fb`7dbed000 fffff6fb`7da00ee8 00000000`00000000 fffff680`3ba80a78 : nt!NtFsControlFile+0x56
ffffd000`21ac7990 00007ffa`6c600a4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000077`4e3bdb48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`6c600a4a


SYMBOL_NAME:  nt!ExpReleaseResourceForThreadLite+5b

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  6.3.9600.18505

STACK_COMMAND:  .cxr 0xffffd00021ac6550 ; kb

BUCKET_ID_FUNC_OFFSET:  5b

FAILURE_BUCKET_ID:  0x24_nt!ExpReleaseResourceForThreadLite

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {cb3bd0d5-89de-2805-a9a3-92a97f2785fc}

Followup:     MachineOwner
---------

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000025,
Arg2: 0000000000000001
Arg3: 0000000000000001
Arg4: fffff90143c29520

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.Sec
    Value: 2

    Key  : Analysis.DebugAnalysisProvider.CPP
    Value: Create: 8007007e on DESKTOP-G25IS1E

    Key  : Analysis.DebugData
    Value: CreateObject

    Key  : Analysis.DebugModel
    Value: CreateObject

    Key  : Analysis.Elapsed.Sec
    Value: 2

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 76

    Key  : Analysis.System
    Value: CreateObject


ADDITIONAL_XML: 1

BUGCHECK_CODE:  19

BUGCHECK_P1: 25

BUGCHECK_P2: 1

BUGCHECK_P3: 1

BUGCHECK_P4: fffff90143c29520

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  explorer.exe

STACK_TEXT: 
ffffd001`4ac3f2b8 fffff802`04528077 : 00000000`00000019 00000000`00000025 00000000`00000001 00000000`00000001 : nt!KeBugCheckEx
ffffd001`4ac3f2c0 fffff960`00445af8 : 00000000`00000000 ffffd001`4ac3f4f0 00000000`00000000 fffff960`0000000f : nt!ExDeferredFreePool+0x807
ffffd001`4ac3f3b0 fffff960`0035c851 : ffffe001`a9312e90 00000000`00000000 00000000`00000001 00000000`00000001 : win32k!NSInstrumentation::PlatformFreeToPagedLookasideList+0x28
ffffd001`4ac3f3e0 fffff960`001ccd5c : 00000000`00001778 fffff901`40908010 00000000`00000000 00000000`0101085f : win32k!Win32FreeToPagedLookasideList+0x5d
ffffd001`4ac3f410 fffff960`001ccd9f : 00000000`00000000 00000000`00000000 0000001f`4ac3f4f0 00000000`00000000 : win32k!REGION::vDeleteREGION+0x1c
ffffd001`4ac3f440 fffff960`00173015 : fffff901`40083d00 00000000`0101085f 00000000`00000000 00000000`00000000 : win32k!DC::vReleaseVis+0x2f
ffffd001`4ac3f470 fffff960`001770fd : ffffd001`4ac3f4f0 00000000`00000000 00000000`00000001 00000000`00000000 : win32k!bDeleteDCInternalWorker+0x155
ffffd001`4ac3f4d0 fffff960`00169158 : fffff901`4021c8e8 00000000`00001778 fffff901`40908010 00000000`00000001 : win32k!bDeleteDCInternal+0x8d
ffffd001`4ac3f530 fffff960`0016d390 : 00000000`00000001 00000000`00000001 00000000`00001778 fffff901`408abc90 : win32k!vCleanupDCs+0xa8
ffffd001`4ac3f570 fffff960`00168551 : 00000000`00001778 ffffe001`a84ff800 ffffd001`4ac3f760 fffff901`408abc90 : win32k!NtGdiCloseProcess+0x54
ffffd001`4ac3f5a0 fffff960`00167dcb : fffff901`408abc90 ffffe001`a84ff8c0 00000000`00000000 fffff801`c8909300 : win32k!GdiProcessCallout+0x1c5
ffffd001`4ac3f620 fffff802`0467fc8e : ffffd001`4ac3f760 ffffd001`4ac3f700 00000000`00000000 00060030`00010002 : win32k!W32pProcessCallout+0x53
ffffd001`4ac3f650 fffff802`0467eebc : ffffe001`a97d2090 00000000`00000000 00000000`00000000 ffffe001`a84ffb88 : nt!PsInvokeWin32Callout+0x42
ffffd001`4ac3f690 fffff802`04715b58 : 00000000`40010004 ffffe001`a6b84880 ffffd001`4ac3fa00 ffffe001`a6b84928 : nt!PspExitThread+0x518
ffffd001`4ac3f7a0 fffff802`04326eba : 00000000`00000000 00000000`00000000 00000000`00000000 fffff802`042c4704 : nt!KiSchedulerApcTerminate+0x18
ffffd001`4ac3f7d0 fffff802`043dc2c0 : 00000000`00000002 ffffd001`4ac3f850 fffff802`0446ad20 00000000`00000000 : nt!KiDeliverApc+0x2fa
ffffd001`4ac3f850 fffff802`043e2c5a : ffffe001`a6b84880 00000000`0ec792a8 ffffd001`4ac3f9a8 fffff680`000763c8 : nt!KiInitiateUserApc+0x70
ffffd001`4ac3f990 00007fff`dd2d0c6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
00000000`0ec79288 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`dd2d0c6a


SYMBOL_NAME:  nt!ExDeferredFreePool+807

IMAGE_NAME:  Pool_Corruption

IMAGE_VERSION:  6.3.9600.18505

MODULE_NAME: Pool_Corruption

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  807

FAILURE_BUCKET_ID:  0x19_25_nt!ExDeferredFreePool

OS_VERSION:  8.1.9600.18505

BUILDLAB_STR:  winblue_ltsb

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {680ab642-66fb-4ff9-27f7-315ec4127c9b}

Followup:     Pool_corruption
---------
 
Dosyalarını analiz ettim. Sorunun bellek kaynaklı olduğunu düşünüyorum. Memtest ile test eder misin?


Memtest sonucunu paylaşırsan sevinirim.

Kod:
DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000004, The power transition timed out waiting to synchronize with the Pnp.
subsystem.
Arg2: 000000000000012c, Timeout in seconds.
Arg3: ffffe000a9480800, The thread currently holding on to the Pnp lock.
Arg4: ffffd001d859ccd0, nt!TRIAGE_9F_PNP on Win7 and higher.

Debugging Details:
------------------

Implicit thread is now ffffe000`a9480800.
*** WARNING: Unable to verify timestamp for IntcAudioBus.sys.
*** WARNING: Unable to verify timestamp for win32k.sys.

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 5.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 7.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 63.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 9f.

BUGCHECK_P1: 4.

BUGCHECK_P2: 12c.

BUGCHECK_P3: ffffe000a9480800.

BUGCHECK_P4: ffffd001d859ccd0.

DRVPOWERSTATE_SUBCODE: 4.

IMAGE_NAME: IntcAudioBus.sys.

MODULE_NAME: IntcAudioBus.

FAULTING_MODULE: fffff8014e28c000 IntcAudioBus.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd000`24f48090 fffff802`32aabb6e : ffffd001`d85e6180 ffffe000`a9480800 00000000`fffffffe 00000000`fffffffe : nt!KiSwapContext+0x76.
ffffd000`24f481d0 fffff802`32aab5e9 : 00000000`00000000 ffffe000`a998f7b0 00000000`00000000 00000000`00000000 : nt!KiSwapThread+0x14e.
ffffd000`24f48270 fffff802`32a5c4a3 : 00000000`00000000 00000000`00000000 ffffd000`24f48390 fffff802`32b63757 : nt!KiCommitThreadWait+0x129.
ffffd000`24f482f0 fffff802`32bbf6f9 : ffffe000`a75840c0 fffff802`00000000 00000000`00000000 fffff802`00000000 : nt!KeWaitForSingleObject+0x373.
ffffd000`24f48380 fffff802`3300877f : ffffe000`a7584010 ffffe000`a6afd060 ffffe000`a6afd060 ffffe000`a758aa50 : nt! ?? ::FNODOBFM::`string'+0x55e39.
ffffd000`24f483c0 fffff802`32f95642 : ffffe000`a758aa50 ffffe000`a8bb88c8 ffffe000`a6afd060 ffffe000`a8bb88c8 : nt!PopFxUnregisterDevice+0xc3.
ffffd000`24f48400 fffff802`33008666 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff801`4e36d010 : nt! ?? ::NNGAKEGL::`string'+0x695b2.
ffffd000`24f48440 fffff801`4e3813ba : 00000000`ffffffff fffff801`4e38134c 00000000`00000010 00000000`00010246 : nt!PoFxUnregisterDevice+0x1e.
ffffd000`24f48470 fffff801`4e37e05b : ffffe000`a6afd1b0 ffffe000`a8bb88c8 ffffe000`a8bb8690 00000000`00010246 : portcls!PnpStopDevice+0x6e.
ffffd000`24f484b0 fffff801`4e37232c : ffffe000`a6afd060 ffffe000`a8bb8690 ffffe000`a6afd060 fffff801`4eb17048 : portcls!DispatchPnp+0x958b.
ffffd000`24f48500 fffff801`4eb063ef : ffffe000`a6afd060 fffff802`32a5c6c6 ffffe000`a758db80 fffff802`32e7ef2d : portcls!PcDispatchIrp+0x32c.
ffffd000`24f48570 ffffe000`a6afd060 : fffff802`32a5c6c6 ffffe000`a758db80 fffff802`32e7ef2d ffffe000`a758db80 : IntcDAud+0xc3ef.
ffffd000`24f48578 fffff802`32a5c6c6 : ffffe000`a758db80 fffff802`32e7ef2d ffffe000`a758db80 fffff801`4e3b485f : 0xffffe000`a6afd060.
ffffd000`24f48580 ffffd000`24f486b0 : ffffd000`00000000 ffffe000`a8bb8690 ffffd000`24f48602 ffffe000`a758aa50 : nt!KeWaitForSingleObject+0x596.
ffffd000`24f48610 ffffd000`00000000 : ffffe000`a8bb8690 ffffd000`24f48602 ffffe000`a758aa50 00000000`c00000bb : 0xffffd000`24f486b0.
ffffd000`24f48618 ffffe000`a8bb8690 : ffffd000`24f48602 ffffe000`a758aa50 00000000`c00000bb 00000000`00000000 : 0xffffd000`00000000.
ffffd000`24f48620 ffffd000`24f48602 : ffffe000`a758aa50 00000000`c00000bb 00000000`00000000 00000000`00060001 : 0xffffe000`a8bb8690.
ffffd000`24f48628 ffffe000`a758aa50 : 00000000`c00000bb 00000000`00000000 00000000`00060001 ffffd000`24f48648 : 0xffffd000`24f48602.
ffffd000`24f48630 00000000`c00000bb : 00000000`00000000 00000000`00060001 ffffd000`24f48648 ffffd000`24f48648 : 0xffffe000`a758aa50.
ffffd000`24f48638 00000000`00000000 : 00000000`00060001 ffffd000`24f48648 ffffd000`24f48648 ffffe000`a758db80 : 0xc00000bb.

STACK_COMMAND: .thread ; .cxr ; kb.

FAILURE_BUCKET_ID: 0x9F_4_IntcDAud_IMAGE_IntcAudioBus.sys.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {4451066e-73a1-ced1-9f81-49d5b56ed94f}

Followup: MachineOwner.
---------

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck.
Arg2: fffff8001825c922, Address of the instruction which caused the bugcheck.
Arg3: ffffd000206286c0, Address of the context record for the exception that caused the bugcheck.
Arg4: 0000000000000000, zero.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 3b.

BUGCHECK_P1: c0000005.

BUGCHECK_P2: fffff8001825c922.

BUGCHECK_P3: ffffd000206286c0.

BUGCHECK_P4: 0.

CONTEXT: ffffd000206286c0 -- (.cxr 0xffffd000206286c0)
rax=00000000000000ff rbx=0000000000000000 rcx=ffffe00088df2118.
rdx=0000000000000000 rsi=a0ffffc0011c55d0 rdi=0000000082caee0d.
rip=fffff8001825c922 rsp=ffffd000206290f0 rbp=ffffd00020629198.
r8=0000000000000000 r9=ffffc00112c2005c r10=ffffc00112c2005c.
r11=0000000000000000 r12=ffffc00111a6b401 r13=0000000000003670.
r14=ffffc0010b816000 r15=a0ffffc0011c55c8.
iopl=0 nv up ei ng nz na pe nc.
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282.
nt!CmpGetNameControlBlock+0x152:
fffff800`1825c922 3b3e cmp edi,dword ptr [rsi] ds:002b:a0ffffc0`011c55d0=????????
Resetting default scope.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: launcher.exe.

STACK_TEXT:
ffffd000`206290f0 fffff800`1825c28f : 00000000`678f9301 00000000`00000026 ffffc001`e38392ae a0ffffc0`011c55c8 : nt!CmpGetNameControlBlock+0x152.
ffffd000`20629170 fffff800`18246e4b : ffffc001`0c7f2000 ffffd000`01e8d300 ffffc001`15348304 ffffc001`0e6c1258 : nt!CmpCreateKeyControlBlock+0x3cf.
ffffd000`20629200 fffff800`1843b954 : ffffc001`00000000 00000000`01e8d300 ffffd000`206298d0 ffffe000`88e21b10 : nt!CmpDoOpen+0x6ab.
ffffd000`206292e0 fffff800`18324b9e : 00000000`00000000 00000000`00000000 ffffe000`00020000 ffffd000`20629691 : nt!CmpParseKey+0x10d4.
ffffd000`206295a0 fffff800`18243f73 : 00000000`00000204 ffffd000`20629758 ffffc001`00000040 ffffe000`845a5f20 : nt!ObpLookupObjectName+0x7be.
ffffd000`206296e0 fffff800`18243b94 : 00000000`00000001 000000c2`fdc6c498 000000c2`fdc6c430 00000000`00020019 : nt!ObOpenObjectByName+0x1e3.
ffffd000`20629810 fffff800`182438e3 : ffff9bcb`e346f84a 00000000`0000017e 00007fff`e06c5740 00007fff`e06a11f0 : nt!CmOpenKey+0x2a4.
ffffd000`206299c0 fffff800`17fdfbb3 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000000 : nt!NtOpenKeyEx+0xf.
ffffd000`20629a00 00007fff`e26d173a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13.
000000c2`fdc6c3d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`e26d173a.

SYMBOL_NAME: nt!CmpGetNameControlBlock+152.

MODULE_NAME: nt.

IMAGE_NAME: ntkrnlmp.exe.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .cxr 0xffffd000206286c0 ; kb.

BUCKET_ID_FUNC_OFFSET: 152.

FAILURE_BUCKET_ID: 0x3B_c0000005_nt!CmpGetNameControlBlock.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {8a5e360a-e831-e203-6a33-02da6bab5e29}

Followup: MachineOwner.
---------

DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time.
Arg2: ffffe00100b6ca90, Physical Device Object of the stack.
Arg3: ffffd001579fb860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack.
Arg4: ffffe00100b81790, The blocked IRP.

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for IntcAudioBus.sys.

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 3.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 63.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 9f.

BUGCHECK_P1: 3.

BUGCHECK_P2: ffffe00100b6ca90.

BUGCHECK_P3: ffffd001579fb860.

BUGCHECK_P4: ffffe00100b81790.

DRVPOWERSTATE_SUBCODE: 3.

DRIVER_OBJECT: ffffe001002f4640.

IMAGE_NAME: IntcAudioBus.sys.

MODULE_NAME: IntcAudioBus.

FAULTING_MODULE: fffff801ebabd000 IntcAudioBus.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd001`579fb828 fffff801`e5c1d2f2 : 00000000`0000009f 00000000`00000003 ffffe001`00b6ca90 ffffd001`579fb860 : nt!KeBugCheckEx.
ffffd001`579fb830 fffff801`e5c1d212 : ffffe001`00b81338 00000000`00000008 ffffd001`579fb958 fffff801`e5a54f45 : nt!PopIrpWatchdogBugcheck+0xde.
ffffd001`579fb890 fffff801`e5a563c8 : 00000000`00000000 ffffd001`579fb9e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32.
ffffd001`579fb8e0 fffff801`e5b6beea : ffffd001`579e6180 ffffd001`579e6180 ffffd001`579f22c0 ffffe001`00dd4880 : nt!KiRetireDpcList+0x4f8.
ffffd001`579fbb60 00000000`00000000 : ffffd001`579fc000 ffffd001`579f5000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a.

STACK_COMMAND: .thread ; .cxr ; kb.

FAILURE_BUCKET_ID: 0x9F_3_IMAGE_IntcAudioBus.sys.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {5eb67757-a85c-4361-5751-171332ac0b2a}

Followup: MachineOwner.
---------

3: kd> lmvm IntcAudioBus.
Browse full module list.
start end module name.
fffff801`ebabd000 fffff801`ebae4000 IntcAudioBus T (no symbols)
Loaded symbol image file: IntcAudioBus.sys.
Image path: \SystemRoot\System32\drivers\IntcAudioBus.sys.
Image name: IntcAudioBus.sys.
Browse all global symbols functions data.
Timestamp: Thu Mar 5 14:20:16 2015 (54F83BF0)
CheckSum: 0002AF30.
ImageSize: 00027000.
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4.
Information from resource tables:

DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time.
Arg2: ffffe001e41a6060, Physical Device Object of the stack.
Arg3: ffffd00064794860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack.
Arg4: ffffe001e88cdbd0, The blocked IRP.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 7.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 64.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 9f.

BUGCHECK_P1: 3.

BUGCHECK_P2: ffffe001e41a6060.

BUGCHECK_P3: ffffd00064794860.

BUGCHECK_P4: ffffe001e88cdbd0.

DRVPOWERSTATE_SUBCODE: 3.

DRIVER_OBJECT: ffffe001e41be060.

IMAGE_NAME: pci.sys.

MODULE_NAME: pci.

FAULTING_MODULE: fffff80038697000 pci.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd000`64794828 fffff803`8a8832f2 : 00000000`0000009f 00000000`00000003 ffffe001`e41a6060 ffffd000`64794860 : nt!KeBugCheckEx.
ffffd000`64794830 fffff803`8a883212 : ffffe001`e3b9a660 ffffe001`e83bd880 ffffe001`e3b9a600 fffff803`8a6baf45 : nt!PopIrpWatchdogBugcheck+0xde.
ffffd000`64794890 fffff803`8a6bc3c8 : 00000000`00000000 ffffd000`647949e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32.
ffffd000`647948e0 fffff803`8a7d1eea : ffffd000`687ec180 ffffd000`687ec180 ffffd000`687f82c0 ffffe001`e7a2a880 : nt!KiRetireDpcList+0x4f8.
ffffd000`64794b60 00000000`00000000 : ffffd000`64795000 ffffd000`6478e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a.

IMAGE_VERSION: 6.3.9600.17238.

STACK_COMMAND: .thread ; .cxr ; kb.

FAILURE_BUCKET_ID: 0x9F_3_IMAGE_pci.sys.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {a89ab2d1-2459-89ee-9990-558bbc68ffab}

Followup: MachineOwner.
---------

MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa8003dd7540.
Arg3: fffffa8003b3a570.
Arg4: 0000000000000201.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 1a.

BUGCHECK_P1: 8886.

BUGCHECK_P2: fffffa8003dd7540.

BUGCHECK_P3: fffffa8003b3a570.

BUGCHECK_P4: 201.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: svchost.exe.

STACK_TEXT:
ffffd000`27316518 fffff801`cd7eb517 : 00000000`0000001a 00000000`00008886 fffffa80`03dd7540 fffffa80`03b3a570 : nt!KeBugCheckEx.
ffffd000`27316520 fffff801`cd736cff : ffffe000`00000001 00000000`00000000 00000000`00000000 00000000`00000005 : nt! ?? ::FNODOBFM::`string'+0xec57.
ffffd000`273165b0 fffff801`cd736a8c : fffffa80`03dd7540 00000000`00000000 00000000`00000002 fffff801`cda63ad7 : nt!MiRelinkStandbyPage+0x23.
ffffd000`273165e0 fffff801`cda427f0 : 00000000`00000001 ffffd000`27316a80 ffffe000`d2ca2000 00000000`00000000 : nt!MmSetPfnListPriorities+0xfc.
ffffd000`27316640 fffff801`cda27a59 : fffffa80`05d9e3a0 00000000`00000001 ffffd000`27316740 ffffe000`d2ca2000 : nt!PfpPfnPrioRequest+0x220.
ffffd000`273166c0 fffff801`cda271d0 : 00000000`4e2fb150 00000000`00000000 00000000`00000000 fffff680`61675a01 : nt!PfSetSuperfetchInformation+0x105.
ffffd000`273167a0 fffff801`cd7d7bb3 : ffffe000`d12f1080 00000000`0000003f 000000c2`4e754801 00000000`00000001 : nt!NtSetSystemInformation+0x1dc.
ffffd000`27316a00 00007ffd`81061f2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13.
000000c2`4e2faf48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`81061f2a.

SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+ec57.

MODULE_NAME: nt.

IMAGE_NAME: ntkrnlmp.exe.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: ec57.

FAILURE_BUCKET_ID: 0x1a_8886_nt!_??_::FNODOBFM::_string_.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {c57d09b3-1175-ffc6-e486-373f0712eef1}

Followup: MachineOwner.
---------
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffc001b7585e60, String that identifies the problem.
Arg2: 0000000000000000, Error Code.
Arg3: 0000000000000000.
Arg4: 0000000000000000.

Debugging Details:
------------------

ETW minidump data unavailable.

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 3.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 3.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

ERROR_CODE: (NTSTATUS) 0xc000021a - { nemli Sistem Hatas } %hs sistem i lemi, 0x.

EXCEPTION_CODE_STR: c000021a.

EXCEPTION_PARAMETER1: ffffc001b7585e60.

EXCEPTION_PARAMETER2: 0000000000000000.

EXCEPTION_PARAMETER3: 0000000000000000.

EXCEPTION_PARAMETER4: 0.

BUGCHECK_CODE: c000021a.

BUGCHECK_P1: ffffc001b7585e60.

BUGCHECK_P2: 0.

BUGCHECK_P3: 0.

BUGCHECK_P4: 0.

PROCESS_NAME: services.exe.

ADDITIONAL_DEBUG_TEXT: Uzaktan Yordam Çaðrýsý (RPC) hizmeti beklenmedik biçimde sonlandýrýldýðýndan, Windows þimdi yeniden baþlatýlmalýdýr.

TAG_NOT_DEFINED_1004c:
This is a STATUS_SYSTEM_PROCESS_TERMINATED bugcheck.
It signals that the system is rebooting due to a critical service termination.
The bugcheck is not very useful for debugging. To investigate the root cause.
find the related svchost.exe crashes that happened on the same machine.
around the time of this dump.

IMAGE_NAME: ntkrnlmp.exe.

MODULE_NAME: nt.

CUSTOMER_CRASH_COUNT: 1.

STACK_TEXT:
ffffd001`6703c5b8 fffff802`dc58d98d : 00000000`0000004c 00000000`c000021a ffffd001`681ff2f8 ffffe000`e119b900 : nt!KeBugCheckEx.
ffffd001`6703c5c0 fffff802`dc5874ea : ffffe000`e1a02b00 ffffd001`6703c6d9 00000000`00000000 00000000`00000002 : nt!PopGracefulShutdown+0x2c9.
ffffd001`6703c600 fffff802`dc362bb3 : ffffe000`e1a02880 fffff802`dc33fc00 00000000`c0000004 fffff802`dc244400 : nt! ?? ::OKHAJAOM::`string'+0x269a.
ffffd001`6703c740 fffff802`dc35b020 : fffff802`dc7963b1 00000000`00000001 ffffd001`6703c958 00000000`c0000004 : nt!KiSystemServiceCopyEnd+0x13.
ffffd001`6703c8d8 fffff802`dc7963b1 : 00000000`00000001 ffffd001`6703c958 00000000`c0000004 ffffd001`6abec180 : nt!KiServiceLinkage.
ffffd001`6703c8e0 fffff802`dc6d0ca7 : 00000000`00000000 00000000`00000000 ffffd001`6abec180 ffffe000`e1a029c0 : nt! ?? ::NNGAKEGL::`string'+0x6c321.
ffffd001`6703c9a0 fffff802`dc2ea91a : fffff802`dc2ea860 00000000`00000000 00000000`00000002 00000000`00000000 : nt!PopPolicyWorkerAction+0x63.
ffffd001`6703ca10 fffff802`dc247d6f : fffff802`00000002 ffffe000`e1a02880 fffff802`dc4c3080 fffff801`79513d90 : nt!PopPolicyWorkerThread+0xba.
ffffd001`6703ca50 fffff802`dc239f34 : ffffc001`b636ed88 ffffe000`e1a02880 00000000`00000080 ffffe000`e1a02880 : nt!ExpWorkerThread+0x69f.
ffffd001`6703cb00 fffff802`dc35d9c6 : ffffd001`6ab60180 ffffe000`e1a02880 ffffe000`e20f0080 fffff801`7957a6ef : nt!PspSystemThreadStartup+0x58.
ffffd001`6703cb60 00000000`00000000 : ffffd001`6703d000 ffffd001`67036000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16.

SYMBOL_NAME: nt! ?? ::OKHAJAOM::`string'+269a.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 269a.

FAILURE_BUCKET_ID: 0xc000021a_rpcss.dll_Critical_Service_Terminated_nt!_??_::OKHAJAOM::_string_.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {985ba5ee-c7fd-3ab7-c026-2d066fd15a29}

Followup: MachineOwner.
---------

This is a STATUS_SYSTEM_PROCESS_TERMINATED bugcheck.
It signals that the system is rebooting due to a critical service termination.
The bugcheck is not very useful for debugging. To investigate the root cause.
find the related svchost.exe crashes that happened on the same machine.
around the time of this dump.

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an.
interrupt request level (IRQL) that is too high. This is usually.
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000010, memory referenced.
Arg2: 0000000000000002, IRQL.
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation.
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff801deee2510, address which referenced memory.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: a.

BUGCHECK_P1: 10.

BUGCHECK_P2: 2.

BUGCHECK_P3: 1.

BUGCHECK_P4: fffff801deee2510.

WRITE_ADDRESS: fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock.
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock.
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock.
GetUlongPtrFromAddress: unable to read from fffff801df1e6298.
GetUlongPtrFromAddress: unable to read from fffff801df1e6520.
fffff801df12ae60: Unable to get Flags value from nt!KdVersionBlock.
0000000000000010.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: Origin.exe.

TRAP_FRAME: ffffd00207027330 -- (.trap 0xffffd00207027330)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000fffffffff rbx=0000000000000000 rcx=0000000000000000.
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000.
rip=fffff801deee2510 rsp=ffffd002070274c0 rbp=fffff801df1de6c0.
r8=0000000000000000 r9=0000000000000000 r10=fffffa8001102590.
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000.
r14=0000000000000000 r15=0000000000000000.
iopl=0 nv up ei pl nz na pe nc.
nt!MiReplenishPageSlist+0x170:
fffff801`deee2510 f0410fba681000 lock bts dword ptr [r8+10h],0 ds:00000000`00000010=????????
Resetting default scope.

STACK_TEXT:
ffffd002`070271e8 fffff801`defe3ee9 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx.
ffffd002`070271f0 fffff801`defe273a : 00000000`00000001 00000000`00000005 ffffd002`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69.
ffffd002`07027330 fffff801`deee2510 : ffff085f`d40c2a9a 00000000`00000000 00000000`00000001 00000000`00000002 : nt!KiPageFault+0x23a.
ffffd002`070274c0 fffff801`deee0639 : fffff801`df1de6c0 00000000`00000033 00000000`00000000 fffffa80`0064dd90 : nt!MiReplenishPageSlist+0x170.
ffffd002`07027540 fffff801`deedf699 : 00000000`00000002 00000000`000000c2 ffffffff`fffffffe 00000000`000004c8 : nt!MiRemoveAnyPage+0x2d9.
ffffd002`07027610 fffff801`deedf2df : 00000000`00000033 00000000`00000000 00000000`000000c2 00000000`00000001 : nt!MiGetFreeOrZeroPage+0x249.
ffffd002`070276b0 fffff801`deede283 : 00000400`00000000 00000000`00000002 00000000`00000001 ffffd002`07027780 : nt!MiGetPage+0x6f.
ffffd002`07027720 fffff801`deed9af0 : 00000000`00000001 00000000`03f09000 ffffd002`07027a00 fffff680`0001f848 : nt!MiResolveDemandZeroFault+0x193.
ffffd002`07027840 fffff801`defe262f : 00000000`00000001 00000000`00078000 ffffc001`a19bf001 ffffc001`a19bf000 : nt!MmAccessFault+0x4e0.
ffffd002`07027a00 00000000`7412de7e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x12f.
00000000`00d0afb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7412de7e.

SYMBOL_NAME: nt!MiReplenishPageSlist+170.

MODULE_NAME: nt.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .thread ; .cxr ; kb.

IMAGE_NAME: memory_corruption.

BUCKET_ID_FUNC_OFFSET: 170.

FAILURE_BUCKET_ID: AV_nt!MiReplenishPageSlist.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {e1780c1b-c7ae-f629-f6fa-ba2f8fe42756}

Followup: MachineOwner.
---------

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of.
the problem, and then special pool applied to the suspect tags or the driver.
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000025,
Arg2: 0000000000000001.
Arg3: 0000000000000001.
Arg4: ffffe0015dec1290.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 61.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 19.

BUGCHECK_P1: 25.

BUGCHECK_P2: 1.

BUGCHECK_P3: 1.

BUGCHECK_P4: ffffe0015dec1290.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd000`9830f708 fffff800`64126077 : 00000000`00000019 00000000`00000025 00000000`00000001 00000000`00000001 : nt!KeBugCheckEx.
ffffd000`9830f710 fffff801`b087d5bb : 00000000`00000001 ffffe001`5d372000 ffffe001`5d372000 00000000`00000035 : nt!ExDeferredFreePool+0x807.
ffffd000`9830f800 fffff801`b087c914 : ffffe001`5d70c2a0 ffffe001`5d70c2a0 ffffd000`9830f990 ffffe001`5d70c2a0 : dxgmms1!VidSchiSwitchContextWithCheck+0x2db.
ffffd000`9830f890 fffff801`b08b2fb8 : ffffe001`5ff5f000 ffffe001`5ff5f000 ffffe001`5d70c2a0 ffffe001`00000000 : dxgmms1!VidSchiScheduleCommandToRun+0x304.
ffffd000`9830fa50 fffff801`b08b2f7d : ffffe001`5ff5f000 ffffe001`00000000 00000000`00000080 ffffe001`60305500 : dxgmms1!VidSchiRun_PriorityTable+0x38.
ffffd000`9830fac0 fffff800`63eb7f34 : ffffd000`9aff82c0 ffffe001`60305500 ffffd000`9830fb90 fffff800`63fd877d : dxgmms1!VidSchiWorkerThread+0x8d.
ffffd000`9830fb00 fffff800`63fdb9c6 : ffffd000`9afec180 ffffe001`60305500 ffffd000`9aff82c0 fffff800`63f2c4e0 : nt!PspSystemThreadStartup+0x58.
ffffd000`9830fb60 00000000`00000000 : ffffd000`98310000 ffffd000`98309000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16.

SYMBOL_NAME: nt!ExDeferredFreePool+807.

IMAGE_NAME: Pool_Corruption.

IMAGE_VERSION: 6.3.9600.18505.

MODULE_NAME: Pool_Corruption.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 807.

FAILURE_BUCKET_ID: 0x19_25_nt!ExDeferredFreePool.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {680ab642-66fb-4ff9-27f7-315ec4127c9b}

Followup: Pool_corruption.
---------

1: kd> lmvm Pool_Corruption.
Browse full module list.
start end module name.

DRIVER_POWER_STATE_FAILURE (9f)
A driver has failed to complete a power IRP within a specific time.
Arguments:
Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time.
Arg2: ffffe0009cb77c40, Physical Device Object of the stack.
Arg3: ffffd001b94ab860, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack.
Arg4: ffffe0009c2893e0, The blocked IRP.

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for IntcAudioBus.sys.

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 8.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 63.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 9f.

BUGCHECK_P1: 3.

BUGCHECK_P2: ffffe0009cb77c40.

BUGCHECK_P3: ffffd001b94ab860.

BUGCHECK_P4: ffffe0009c2893e0.

DRVPOWERSTATE_SUBCODE: 3.

DRIVER_OBJECT: ffffe0009c19c820.

IMAGE_NAME: IntcAudioBus.sys.

MODULE_NAME: IntcAudioBus.

FAULTING_MODULE: fffff8002a906000 IntcAudioBus.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd001`b94ab828 fffff800`ffe812f2 : 00000000`0000009f 00000000`00000003 ffffe000`9cb77c40 ffffd001`b94ab860 : nt!KeBugCheckEx.
ffffd001`b94ab830 fffff800`ffe81212 : ffffe000`9cbdd338 00000000`00000008 ffffd001`b94ab958 fffff800`ffcb8f45 : nt!PopIrpWatchdogBugcheck+0xde.
ffffd001`b94ab890 fffff800`ffcba3c8 : 00000000`00000000 ffffd001`b94ab9e0 00000000`00000001 00000000`00000001 : nt!PopIrpWatchdog+0x32.
ffffd001`b94ab8e0 fffff800`ffdcfeea : ffffd001`b9481180 ffffd001`b9481180 ffffd001`b948d2c0 ffffe000`9c0a1040 : nt!KiRetireDpcList+0x4f8.
ffffd001`b94abb60 00000000`00000000 : ffffd001`b94ac000 ffffd001`b94a5000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a.

STACK_COMMAND: .thread ; .cxr ; kb.

FAILURE_BUCKET_ID: 0x9F_3_IMAGE_IntcAudioBus.sys.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {5eb67757-a85c-4361-5751-171332ac0b2a}

Followup: MachineOwner.
---------

3: kd> lmvm IntcAudioBus.
Browse full module list.
start end module name.
fffff800`2a906000 fffff800`2a92d000 IntcAudioBus T (no symbols)
Loaded symbol image file: IntcAudioBus.sys.
Image path: \SystemRoot\System32\drivers\IntcAudioBus.sys.
Image name: IntcAudioBus.sys.
Browse all global symbols functions data.
Timestamp: Thu Mar 5 14:20:16 2015 (54F83BF0)
CheckSum: 0002AF30.
ImageSize: 00027000.
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4.
Information from resource tables:
DPC_WATCHDOG_VIOLATION (133)
The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL.
or above.
Arguments:
Arg1: 0000000000000000, A single DPC or ISR exceeded its time allotment. The offending.
component can usually be identified with a stack trace.
Arg2: 0000000000000501, The DPC time count (in ticks).
Arg3: 0000000000000500, The DPC time allotment (in ticks).
Arg4: 0000000000000000, cast to nt!DPC_WATCHDOG_GLOBAL_TRIAGE_BLOCK, which contains.
additional information regarding this single DPC timeout.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 63.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 133.

BUGCHECK_P1: 0.

BUGCHECK_P2: 501.

BUGCHECK_P3: 500.

BUGCHECK_P4: 0.

DPC_TIMEOUT_TYPE: SINGLE_DPC_TIMEOUT_EXCEEDED.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd001`55fa3c88 fffff801`4f1750dc : 00000000`00000133 00000000`00000000 00000000`00000501 00000000`00000500 : nt!KeBugCheckEx.
ffffd001`55fa3c90 fffff801`4f05b1f7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x1681c.
ffffd001`55fa3d20 fffff801`4f79467f : 00000000`000000ff fffff801`4f03beb4 ffffe000`6c6003b0 00000000`0000b801 : nt!KeClockInterruptNotify+0x787.
ffffd001`55fa3f40 fffff801`4f0d9db3 : ffffe000`6c600300 00000000`00000008 ffffe000`7088c280 00000000`000000ff : hal!HalpTimerClockInterrupt+0x4f.
ffffd001`55fa3f70 fffff801`4f14f82a : ffffe000`6c600300 ffffe000`7088c010 ffffe000`7088c288 ffffe000`7088c0b8 : nt!KiCallInterruptServiceRoutine+0xa3.
ffffd001`55fa3fb0 fffff801`4f14fc0f : 00000000`00000000 00000000`000000ff ffffe000`7088c288 ffffe000`6f7dc900 : nt!KiInterruptSubDispatchNoLockNoEtw+0xea.
ffffd001`55f94710 fffff801`58b4bcaf : ffffd001`55f94a02 ffffe000`6cf4daf0 ffffe000`6d08a7b8 ffffe000`7088c2c0 : nt!KiInterruptDispatchLBControl+0x11f.
ffffd001`55f948a0 fffff801`4f03c3c8 : ffffd001`55f94a20 00000000`07981c04 ffffd001`55f949e0 ffffd001`59fec180 : usb8023x!CancelSendsTimerDpc+0x57.
ffffd001`55f948e0 fffff801`4f151eea : ffffd001`59fec180 ffffd001`59fec180 ffffd001`59ff82c0 ffffe000`6ebb3340 : nt!KiRetireDpcList+0x4f8.
ffffd001`55f94b60 00000000`00000000 : ffffd001`55f95000 ffffd001`55f8e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a.

SYMBOL_NAME: usb8023x!CancelSendsTimerDpc+57.

MODULE_NAME: usb8023x.

IMAGE_NAME: usb8023x.sys.

IMAGE_VERSION: 6.3.9600.16384.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 57.

FAILURE_BUCKET_ID: 0x133_DPC_usb8023x!CancelSendsTimerDpc.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {246f7e65-0458-b0d9-ce75-f02203155395}

Followup: MachineOwner.
---------

2: kd> lmvm usb8023x.
Browse full module list.
start end module name.
fffff801`58b49000 fffff801`58b54000 usb8023x (pdb symbols) C:\ProgramData\Dbg\sym\usb8023x.pdb\29F6FDE964F84B8EAEAC34E2081CCEBC1\usb8023x.pdb.
Loaded symbol image file: usb8023x.sys.
Mapped memory image file: C:\ProgramData\Dbg\sym\usb8023x.sys\5215F829b000\usb8023x.sys.
Image path: \SystemRoot\system32\DRIVERS\usb8023x.sys.
Image name: usb8023x.sys.
Browse all global symbols functions data.
Timestamp: Thu Aug 22 14:38:17 2013 (5215F829)
CheckSum: 0000E78E.
ImageSize: 0000B000.
File version: 6.3.9600.16384.
Product version: 6.3.9600.16384.
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32.
File type: 2.0 Dll.
File date: 00000000.00000000.
Translations: 0409.04b0.
Information from resource tables:
CompanyName: Microsoft Corporation.
ProductName: Microsoft® Windows® Operating System.
InternalName: usb8023.sys.
OriginalFilename: usb8023.sys.
ProductVersion: 6.3.9600.16384.
FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
FileDescription: Remote NDIS USB Driver.
LegalCopyright: © Microsoft Corporation. All rights reserved.
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption.
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffffd00025d9f6e0, Address of the trap frame for the exception that caused the bugcheck.
Arg3: ffffd00025d9f638, Address of the exception record for the exception that caused the bugcheck.
Arg4: 0000000000000000, Reserved.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 139.

BUGCHECK_P1: 3.

BUGCHECK_P2: ffffd00025d9f6e0.

BUGCHECK_P3: ffffd00025d9f638.

BUGCHECK_P4: 0.

TRAP_FRAME: ffffd00025d9f6e0 -- (.trap 0xffffd00025d9f6e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe000f3c64018 rbx=0000000000000000 rcx=0000000000000003.
rdx=ffffe000f3c64118 rsi=0000000000000000 rdi=0000000000000000.
rip=fffff801e14f687c rsp=ffffd00025d9f878 rbp=ffffe000f3c64001.
r8=ffffe000f3c64118 r9=7fffe000f6a32b88 r10=0000000000000003.
r11=7ffffffffffffffc r12=0000000000000000 r13=0000000000000000.
r14=0000000000000000 r15=0000000000000000.
iopl=0 nv up ei pl nz ac po nc.
nt!KiInsertQueueApc+0x68:
fffff801`e14f687c cd29 int 29h.
Resetting default scope.

EXCEPTION_RECORD: ffffd00025d9f638 -- (.exr 0xffffd00025d9f638)
ExceptionAddress: fffff801e14f687c (nt!KiInsertQueueApc+0x0000000000000068)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001.
NumberParameters: 1.
Parameter[0]: 0000000000000003.
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: opera.exe.

ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.

EXCEPTION_CODE_STR: c0000409.

EXCEPTION_PARAMETER1: 0000000000000003.

EXCEPTION_STR: 0xc0000409.

STACK_TEXT:
ffffd000`25d9f3b8 fffff801`e15cdee9 : 00000000`00000139 00000000`00000003 ffffd000`25d9f6e0 ffffd000`25d9f638 : nt!KeBugCheckEx.
ffffd000`25d9f3c0 fffff801`e15ce210 : 00000000`00000000 00000000`00000000 00000000`00000000 0158814a`81458101 : nt!KiBugCheckDispatch+0x69.
ffffd000`25d9f500 fffff801`e15cd434 : ffffe000`f406c530 ffffd000`25d9f758 ffffed18`5cd13361 ffffe000`ef9a4f20 : nt!KiFastFailDispatch+0xd0.
ffffd000`25d9f6e0 fffff801`e14f687c : fffff801`e14a5aad ffffe000`f0c34880 ffffe000`f0c34801 ffffe000`f6a32b88 : nt!KiRaiseSecurityCheckFailure+0xf4.
ffffd000`25d9f878 fffff801`e14a5aad : ffffe000`f0c34880 ffffe000`f0c34801 ffffe000`f6a32b88 fffff801`e1822d56 : nt!KiInsertQueueApc+0x68.
ffffd000`25d9f880 fffff801`e1822ffa : ffffe000`f3c64080 ffffe000`f3c64080 00000000`00000000 00000000`00000000 : nt!KeRequestTerminationThread+0x75.
ffffd000`25d9f8c0 fffff801`e1822ab4 : 00000000`f6a328c8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!PspTerminateThreadByPointer+0x6a.
ffffd000`25d9f8f0 fffff801`e1822891 : ffffe000`f642c880 ffffe000`f19dad80 ffffe000`f6a328c0 ffffe000`f6a328c0 : nt!PspTerminateAllThreads+0xf0.
ffffd000`25d9f950 fffff801`e182261e : ffffffff`ffffffff ffffe000`f00991c0 ffffe000`f6a328c0 ffffe000`f19da880 : nt!PspTerminateProcess+0xe5.
ffffd000`25d9f990 fffff801`e15cdbb3 : ffffe000`f6a328c0 ffffe000`f19da880 ffffd000`25d9fa80 00000000`00000000 : nt!NtTerminateProcess+0x9e.
ffffd000`25d9fa00 00007ff9`a8f7097a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13.
00000082`e88cf6a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`a8f7097a.

SYMBOL_NAME: nt!KiFastFailDispatch+d0.

MODULE_NAME: nt.

IMAGE_NAME: ntkrnlmp.exe.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: d0.

FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {3aede96a-54dd-40d6-d4cb-2a161a843851}

Followup: MachineOwner.
---------
VIDEO_MEMORY_MANAGEMENT_INTERNAL (10e)
The video memory manager encountered a condition that it can't recover from. By crashing,
the video memory manager is attempting to get enough information into the minidump such that.
somebody can pinpoint what lead to this condition.
Arguments:
Arg1: 000000000000001f, The subtype of the bugcheck:
Arg2: ffffc00142fdd010.
Arg3: 0000000000000000.
Arg4: 000000000029f0fc.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 63.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 10e.

BUGCHECK_P1: 1f.

BUGCHECK_P2: ffffc00142fdd010.

BUGCHECK_P3: 0.

BUGCHECK_P4: 29f0fc.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: System.

STACK_TEXT:
ffffd000`dc105438 fffff800`d1de39ca : 00000000`0000010e 00000000`0000001f ffffc001`42fdd010 00000000`00000000 : nt!KeBugCheckEx.
ffffd000`dc105440 fffff800`d108d46b : ffffe000`c65c8900 00000000`0029f0fc ffffc001`3cd59e48 ffffd000`dc105580 : watchdog!WdLogEvent5_WdCriticalError+0xce.
ffffd000`dc105480 fffff800`d106d711 : 00000000`00000002 00000000`00000002 00000000`00000000 ffffe000`c7ab1508 : dxgmms1!VIDMM_GLOBAL::prepareDmaBuffer+0x1b2cb.
ffffd000`dc105700 fffff800`d10831d2 : ffffe000`c8772a50 ffffe000`00000000 ffffe000`00000000 ffffe000`00000001 : dxgmms1!VidSchiSubmitRenderCommand+0x1f1.
ffffd000`dc105a50 fffff800`d1082f7d : ffffe000`c7ab1000 ffffe000`00000000 00000000`00000080 ffffe000`c7a7b080 : dxgmms1!VidSchiRun_PriorityTable+0x252.
ffffd000`dc105ac0 fffff800`974a5f34 : ffffd000`de1f82c0 ffffe000`c7a7b080 ffffd000`dc105b90 fffff800`975c677d : dxgmms1!VidSchiWorkerThread+0x8d.
ffffd000`dc105b00 fffff800`975c99c6 : ffffd000`de1ec180 ffffe000`c7a7b080 ffffd000`de1f82c0 00000000`0000000f : nt!PspSystemThreadStartup+0x58.
ffffd000`dc105b60 00000000`00000000 : ffffd000`dc106000 ffffd000`dc0ff000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16.

SYMBOL_NAME: dxgmms1!VIDMM_GLOBAL::prepareDmaBuffer+1b2cb.

MODULE_NAME: dxgmms1.

IMAGE_NAME: dxgmms1.sys.

IMAGE_VERSION: 6.3.9600.17415.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 1b2cb.

FAILURE_BUCKET_ID: 0x10e_1f_dxgmms1!VIDMM_GLOBAL::prepareDmaBuffer.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {e59c19db-fe47-a4eb-496d-1dc2434ca82a}

Followup: MachineOwner.
---------

REFERENCE_BY_POINTER (18)
Arguments:
Arg1: ffffe0016e16d930, Object type of the object whose reference count is being lowered.
Arg2: ffffe001719049d0, Object whose reference count is being lowered.
Arg3: 0000000000000001, Reserved.
Arg4: 0000000000000001, Reserved.
The reference count of an object is illegal for the current state of the object.
Each time a driver uses a pointer to an object the driver calls a kernel routine.
to increment the reference count of the object. When the driver is done with the.
pointer the driver calls another kernel routine to decrement the reference count.
Drivers must match calls to the increment and decrement routines. This bugcheck.
can occur because an object's reference count goes to zero while there are still.
open handles to the object, in which case the fourth parameter indicates the number.
of opened handles. It may also occur when the object's reference count drops below zero.
whether or not there are open handles to the object, and in that case the fourth parameter.
contains the actual value of the pointer references count.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 60.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 18.

BUGCHECK_P1: ffffe0016e16d930.

BUGCHECK_P2: ffffe001719049d0.

BUGCHECK_P3: 1.

BUGCHECK_P4: 1.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: uTorrent.exe.

STACK_TEXT:
ffffd000`204871d8 fffff800`e73ebe58 : 00000000`00000018 ffffe001`6e16d930 ffffe001`719049d0 00000000`00000001 : nt!KeBugCheckEx.
ffffd000`204871e0 fffff800`e7644112 : ffffd000`20487530 fffff800`e7561140 ffffe001`6eacd110 fffff800`00000006 : nt! ?? ::FNODOBFM::`string'+0x12598.
ffffd000`20487220 fffff800`e76de112 : ffffe001`6f07e000 00000000`0225f148 ffffd000`204879a8 00000000`00000000 : nt!ObWaitForMultipleObjects+0x2d2.
ffffd000`20487730 fffff800`e73d4bb3 : 00000000`00000001 ffffd000`20487a00 ffffd000`204879c0 00000000`00000000 : nt!NtWaitForMultipleObjects32+0xda.
ffffd000`20487990 00000000`771c2352 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13.
00000000`0225f128 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771c2352.

SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+12598.

MODULE_NAME: nt.

IMAGE_NAME: ntkrnlmp.exe.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 12598.

FAILURE_BUCKET_ID: 0x18_CORRUPT_REF_COUNT_nt!_??_::FNODOBFM::_string_.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {f79c57ae-b68f-40b5-de2a-a8ffc9173143}

Followup: MachineOwner.
---------
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd.
parameters are the exception record and context record. Do a .cxr.
on the 3rd parameter and then kb to obtain a more informative stack.
trace.
Arguments:
Arg1: 000000b500190645.
Arg2: ffffd00021ac6d48.
Arg3: ffffd00021ac6550.
Arg4: fffff8012be5946b.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : AV.Fault.
Value: Read.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 69.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 24.

BUGCHECK_P1: b500190645.

BUGCHECK_P2: ffffd00021ac6d48.

BUGCHECK_P3: ffffd00021ac6550.

BUGCHECK_P4: fffff8012be5946b.

EXCEPTION_RECORD: ffffd00021ac6d48 -- (.exr 0xffffd00021ac6d48)
ExceptionAddress: fffff8012be5946b (nt!ExpReleaseResourceForThreadLite+0x000000000000005b)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000.
NumberParameters: 2.
Parameter[0]: 0000000000000000.
Parameter[1]: ffffffffffffffff.
Attempt to read from address ffffffffffffffff.

CONTEXT: ffffd00021ac6550 -- (.cxr 0xffffd00021ac6550)
rax=0000000000000000 rbx=00020000000115cd rcx=000200000001162d.
rdx=ffffd00021ac6fd0 rsi=0000000000000000 rdi=0000000000000000.
rip=fffff8012be5946b rsp=ffffd00021ac6f80 rbp=ffffd00021ac7080.
r8=0000000000000000 r9=7fffe000f5711428 r10=ffffe000f5711428.
r11=7ffffffffffffffc r12=0000000000000727 r13=ffffe000f5711180.
r14=0000000000000000 r15=ffffe000f60ed880.
iopl=0 nv up di pl zr na po nc.
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010046.
nt!ExpReleaseResourceForThreadLite+0x5b:
fffff801`2be5946b 488711 xchg rdx,qword ptr [rcx] ds:002b:00020000`0001162d=????????????????
Resetting default scope.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: svchost.exe.

READ_ADDRESS: fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock.
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock.
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock.
GetUlongPtrFromAddress: unable to read from fffff8012c171298.
GetUlongPtrFromAddress: unable to read from fffff8012c171520.
fffff8012c0b5e60: Unable to get Flags value from nt!KdVersionBlock.
ffffffffffffffff.

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.

EXCEPTION_CODE_STR: c0000005.

EXCEPTION_PARAMETER1: 0000000000000000.

EXCEPTION_PARAMETER2: ffffffffffffffff.

EXCEPTION_STR: 0xc0000005.

STACK_TEXT:
ffffd000`21ac6f80 fffff801`c5502e6b : ffffb000`00000000 fffff801`c5612231 ffffe000`f6f2f702 fffff801`2befd1cf : nt!ExpReleaseResourceForThreadLite+0x5b.
ffffd000`21ac70c0 fffff801`c5612652 : ffffc000`47b43010 ffffd000`21ac7501 ffffe000`f5b7aa00 ffffe000`f5711180 : Ntfs!NtfsReleaseFcb+0x4b.
ffffd000`21ac7100 fffff801`c5624e87 : 00000000`00000000 00000000`00000000 ffffd000`21ac7500 ffffc000`48ddb580 : Ntfs!NtfsReleaseAllFiles+0xc2.
ffffd000`21ac7150 fffff801`c5623591 : ffffe000`f7023060 ffffe000`f7085010 ffffe000`f5b7ab38 fffff801`c5208f5d : Ntfs!NtfsDefragFileInternal+0x1771.
ffffd000`21ac73d0 fffff801`c5642294 : ffffe000`00000000 ffffe000`f613fb00 ffffc000`550d64b0 ffffe000`f5711180 : Ntfs!NtfsDefragFile+0x3cd.
ffffd000`21ac7480 fffff801`c55dc074 : 00000000`00000000 ffffd000`21ac7500 00000000`00000001 ffffd000`21ac7500 : Ntfs!NtfsUserFsRequest+0x66b8c.
ffffd000`21ac74c0 fffff801`c5398b1e : ffffe000`f8e378c0 00000000`00000000 00000000`00000000 ffffe000`f6d73d28 : Ntfs!NtfsFsdFileSystemControl+0x2e0.
ffffd000`21ac7610 fffff801`c53c1831 : ffffd000`21ac76d0 ffffe000`f7118040 ffffe000`f6d73d28 ffffe000`f6d73940 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2ce.
ffffd000`21ac76b0 fffff801`2c2b0e03 : 00000000`00000002 ffffd000`21ac7791 ffffe000`f7937580 ffffe000`f6a588c0 : fltmgr!FltpFsControl+0x111.
ffffd000`21ac7710 fffff801`2c2b1d36 : ffffe000`f7937505 ffffd000`21ac7a80 ffffe000`f613faa0 ffffe000`f7937580 : nt!IopSynchronousServiceTail+0x32b.
ffffd000`21ac77e0 fffff801`2c1c357a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0xd86.
ffffd000`21ac7920 fffff801`2bf6ebb3 : fffff6fb`7dbed000 fffff6fb`7da00ee8 00000000`00000000 fffff680`3ba80a78 : nt!NtFsControlFile+0x56.
ffffd000`21ac7990 00007ffa`6c600a4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13.
00000077`4e3bdb48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`6c600a4a.

SYMBOL_NAME: nt!ExpReleaseResourceForThreadLite+5b.

MODULE_NAME: nt.

IMAGE_NAME: ntkrnlmp.exe.

IMAGE_VERSION: 6.3.9600.18505.

STACK_COMMAND: .cxr 0xffffd00021ac6550 ; kb.

BUCKET_ID_FUNC_OFFSET: 5b.

FAILURE_BUCKET_ID: 0x24_nt!ExpReleaseResourceForThreadLite.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {cb3bd0d5-89de-2805-a9a3-92a97f2785fc}

Followup: MachineOwner.
---------

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of.
the problem, and then special pool applied to the suspect tags or the driver.
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000025,
Arg2: 0000000000000001.
Arg3: 0000000000000001.
Arg4: fffff90143c29520.

Debugging Details:
------------------

KEY_VALUES_STRING: 1.

Key : Analysis.CPU.Sec.
Value: 2.

Key : Analysis.DebugAnalysisProvider.CPP.
Value: Create: 8007007e on DESKTOP-G25IS1E.

Key : Analysis.DebugData.
Value: CreateObject.

Key : Analysis.DebugModel.
Value: CreateObject.

Key : Analysis.Elapsed.Sec.
Value: 2.

Key : Analysis.Memory.CommitPeak.Mb.
Value: 76.

Key : Analysis.System.
Value: CreateObject.

ADDITIONAL_XML: 1.

BUGCHECK_CODE: 19.

BUGCHECK_P1: 25.

BUGCHECK_P2: 1.

BUGCHECK_P3: 1.

BUGCHECK_P4: fffff90143c29520.

CUSTOMER_CRASH_COUNT: 1.

PROCESS_NAME: explorer.exe.

STACK_TEXT:
ffffd001`4ac3f2b8 fffff802`04528077 : 00000000`00000019 00000000`00000025 00000000`00000001 00000000`00000001 : nt!KeBugCheckEx.
ffffd001`4ac3f2c0 fffff960`00445af8 : 00000000`00000000 ffffd001`4ac3f4f0 00000000`00000000 fffff960`0000000f : nt!ExDeferredFreePool+0x807.
ffffd001`4ac3f3b0 fffff960`0035c851 : ffffe001`a9312e90 00000000`00000000 00000000`00000001 00000000`00000001 : win32k!NSInstrumentation::platformFreeToPagedLookasideList+0x28.
ffffd001`4ac3f3e0 fffff960`001ccd5c : 00000000`00001778 fffff901`40908010 00000000`00000000 00000000`0101085f : win32k!Win32FreeToPagedLookasideList+0x5d.
ffffd001`4ac3f410 fffff960`001ccd9f : 00000000`00000000 00000000`00000000 0000001f`4ac3f4f0 00000000`00000000 : win32k!REGION::vDeleteREGION+0x1c.
ffffd001`4ac3f440 fffff960`00173015 : fffff901`40083d00 00000000`0101085f 00000000`00000000 00000000`00000000 : win32k!DC::vReleaseVis+0x2f.
ffffd001`4ac3f470 fffff960`001770fd : ffffd001`4ac3f4f0 00000000`00000000 00000000`00000001 00000000`00000000 : win32k!bDeleteDCInternalWorker+0x155.
ffffd001`4ac3f4d0 fffff960`00169158 : fffff901`4021c8e8 00000000`00001778 fffff901`40908010 00000000`00000001 : win32k!bDeleteDCInternal+0x8d.
ffffd001`4ac3f530 fffff960`0016d390 : 00000000`00000001 00000000`00000001 00000000`00001778 fffff901`408abc90 : win32k!vCleanupDCs+0xa8.
ffffd001`4ac3f570 fffff960`00168551 : 00000000`00001778 ffffe001`a84ff800 ffffd001`4ac3f760 fffff901`408abc90 : win32k!NtGdiCloseProcess+0x54.
ffffd001`4ac3f5a0 fffff960`00167dcb : fffff901`408abc90 ffffe001`a84ff8c0 00000000`00000000 fffff801`c8909300 : win32k!GdiProcessCallout+0x1c5.
ffffd001`4ac3f620 fffff802`0467fc8e : ffffd001`4ac3f760 ffffd001`4ac3f700 00000000`00000000 00060030`00010002 : win32k!W32pProcessCallout+0x53.
ffffd001`4ac3f650 fffff802`0467eebc : ffffe001`a97d2090 00000000`00000000 00000000`00000000 ffffe001`a84ffb88 : nt!PsInvokeWin32Callout+0x42.
ffffd001`4ac3f690 fffff802`04715b58 : 00000000`40010004 ffffe001`a6b84880 ffffd001`4ac3fa00 ffffe001`a6b84928 : nt!PspExitThread+0x518.
ffffd001`4ac3f7a0 fffff802`04326eba : 00000000`00000000 00000000`00000000 00000000`00000000 fffff802`042c4704 : nt!KiSchedulerApcTerminate+0x18.
ffffd001`4ac3f7d0 fffff802`043dc2c0 : 00000000`00000002 ffffd001`4ac3f850 fffff802`0446ad20 00000000`00000000 : nt!KiDeliverApc+0x2fa.
ffffd001`4ac3f850 fffff802`043e2c5a : ffffe001`a6b84880 00000000`0ec792a8 ffffd001`4ac3f9a8 fffff680`000763c8 : nt!KiInitiateUserApc+0x70.
ffffd001`4ac3f990 00007fff`dd2d0c6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f.
00000000`0ec79288 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`dd2d0c6a.

SYMBOL_NAME: nt!ExDeferredFreePool+807.

IMAGE_NAME: Pool_Corruption.

IMAGE_VERSION: 6.3.9600.18505.

MODULE_NAME: Pool_Corruption.

STACK_COMMAND: .thread ; .cxr ; kb.

BUCKET_ID_FUNC_OFFSET: 807.

FAILURE_BUCKET_ID: 0x19_25_nt!ExDeferredFreePool.

OS_VERSION: 8.1.9600.18505.

BUILDLAB_STR: winblue_ltsb.

OSPLATFORM_TYPE: x64.

OSNAME: Windows 8.1.

FAILURE_ID_HASH: {680ab642-66fb-4ff9-27f7-315ec4127c9b}

Followup: Pool_corruption.
---------

Hocam peki watchdog.sys ve win32k.exe ne anlama geliyor? (Blue screen view ile incelendi)
 
Kesin bir şey diyemem. Mavi ekran hatalarında her sorun illa rapordakiyle ilgili değil. Mesela bu konuda Intel ses sürücüsünde sorun var gözükmekte ama sorunun Intel ses sürücüsü ile bir ilgisi yok bence. Az önce bir video kaydı yaptım analiz için. Konu sahibi dönüş yaparsa güzel bir video çıkacak.
 
Kesin bir şey diyemem. Mavi ekran hatalarında her sorun illa rapordakiyle ilgili değil. Mesela bu konuda Intel ses sürücüsünde sorun var gözükmekte ama sorunun Intel ses sürücüsü ile bir ilgisi yok bence. Az önce bir video kaydı yaptım analiz için. Konu sahibi dönüş yaparsa güzel bir video çıkacak.

Sanırım rehber yapılacak öyle mi? Eğer yapılırsa çok iyi olur birçok kişi istiyordu.
 
Durum
Mesaj gönderimine kapalı.

Yeni konular

Geri
Yukarı