Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff960001e1d01, Address of the instruction which caused the bugcheck
- Arg3: fffff8800301ad30, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
- FAULTING_IP:
- win32k!xxxSendBSMtoDesktop+a1
- fffff960`001e1d01 488b4e60 mov rcx,qword ptr [rsi+60h]
- CONTEXT: fffff8800301ad30 -- (.cxr 0xfffff8800301ad30)
- rax=fffff90100798830 rbx=0000000000000000 rcx=0000000000000001
- rdx=000000000000031e rsi=0000000000000000 rdi=000000000000031e
- rip=fffff960001e1d01 rsp=fffff8800301b730 rbp=fffff8800301b819
- r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
- r11=fffff8800301b8f8 r12=0000000000000000 r13=0000000000000001
- r14=0000000000000000 r15=fffff8800301b930
- iopl=0 nv up ei pl nz na pe nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
- win32k!xxxSendBSMtoDesktop+0xa1:
- fffff960`001e1d01 488b4e60 mov rcx,qword ptr [rsi+60h] ds:002b:00000000`00000060=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: powershell.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff960001dea0e to fffff960001e1d01
- STACK_TEXT:
- fffff880`0301b730 fffff960`001dea0e : 00000000`00000000 fffffa80`00d11eb0 fffff880`0301b8f0 fffff901`000bb070 : win32k!xxxSendBSMtoDesktop+0xa1
- fffff880`0301b870 fffff960`0032250f : fffff901`00400000 fffffa80`02eb8590 fffffa80`0292be40 00000000`00000000 : win32k!xxxSendMessageBSM+0x12a
- fffff880`0301b900 fffff960`00399ae2 : fffff901`000bb010 fffff901`00000000 fffff901`04036350 fffffa80`00d11a90 : win32k!BroadcastCompositionChange+0x43
- fffff880`0301b970 fffff960`0043e79a : fffffa80`02eb8590 fffff880`0301bcc0 fffffa80`0292be40 fffffa80`01f649a0 : win32k!zzzDecomposeDesktop+0x122
- fffff880`0301b9d0 fffff960`001dcd7f : 00000000`00000000 00000000`00000000 00000097`200dd870 00000000`00000000 : win32k!xxxCreateDesktopEx+0x2298fa
- fffff880`0301bb70 fffff802`f7889053 : fffffa80`0110d240 00000097`200dd858 fffff880`0301bbe8 00000000`00000000 : win32k!NtUserCreateDesktopEx+0xc3
- fffff880`0301bbd0 000007fa`ab021e4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000097`200dd838 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x000007fa`ab021e4a
- FOLLOWUP_IP:
- win32k!xxxSendBSMtoDesktop+a1
- fffff960`001e1d01 488b4e60 mov rcx,qword ptr [rsi+60h]
- SYMBOL_STACK_INDEX: 0
- SYMBOL_NAME: win32k!xxxSendBSMtoDesktop+a1
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: win32k
- IMAGE_NAME: win32k.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 5010aae5
- STACK_COMMAND: .cxr 0xfffff8800301ad30 ; kb
- BUCKET_ID_FUNC_OFFSET: a1
- FAILURE_BUCKET_ID: 0x3B_win32k!xxxSendBSMtoDesktop
- BUCKET_ID: 0x3B_win32k!xxxSendBSMtoDesktop
- Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement