locked
windows 7 64 bits ultimate blue screen RRS feed

  • Question

  • Hi:

     

    Just 3 days ago  I installed my new win7 ultimate 64 bits and yesterday and today it's made a blue screen and restart (just one time occurs yesteraday and one time today)

    The error in the blue screen is:

    SYSTEM_SERVICE_EXCEPTION

    0x0000003b

    caused by drive: win32k.sys

    caused by address: win32k.sys+cadd9

    the windebug show:

    1: kd> !analyze -v

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    SYSTEM_SERVICE_EXCEPTION (3b)

    An exception happened while executing a system service routine.

    Arguments:

    Arg1: 00000000c0000005, Exception code that caused the bugcheck

    Arg2: fffff960001badd9, Address of the instruction which caused the bugcheck

    Arg3: fffff880061da1c0, Address of the context record for the exception that caused the bugcheck

    Arg4: 0000000000000000, zero.

    Debugging Details:

    ------------------

     

    OVERLAPPED_MODULE: Address regions for 'USBSTOR' and 'spsys.sys' overlap

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

    FAULTING_IP:

    win32k!ValidateHwnd+89

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h]

    CONTEXT: fffff880061da1c0 -- (.cxr 0xfffff880061da1c0)

    rax=fff7f900c06ffc30 rbx=fffff900c04081f0 rcx=00000000000b056a

    rdx=fffffa8003cf1280 rsi=00000000000b056a rdi=fffff900c083dfe0

    rip=fffff960001badd9 rsp=fffff880061dab90 rbp=0000000000000000

    r8=fffff900c065ec30 r9=0000000000000000 r10=fffff960001c0b00

    r11=fff7f900c06ffc30 r12=0000000000000000 r13=0000000000000000

    r14=0000000003944c20 r15=0000000002169d50

    iopl=0 nv up ei pl nz na po nc

    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206

    win32k!ValidateHwnd+0x89:

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h] ds:002b:fff7f900`c06ffda8=????????????????

    Resetting default scope

    DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

    BUGCHECK_STR: 0x3B

    PROCESS_NAME: ts3client_win6

    CURRENT_IRQL: 0

    LAST_CONTROL_TRANSFER: from fffff960001c0b72 to fffff960001badd9

    STACK_TEXT:

    fffff880`061dab90 fffff960`001c0b72 : 00000000`00000000 00000000`000b056a 00000980`00000000 0000007f`fffffff8 : win32k!ValidateHwnd+0x89

    fffff880`061dabc0 fffff800`0288b993 : fffffa80`04411060 fffff880`061daca0 00000000`00000401 00000000`00000020 : win32k!NtUserPostMessage+0x72

    fffff880`061dac20 00000000`772d92ca : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13

    00000000`0380f6c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x772d92ca

     

    FOLLOWUP_IP:

    win32k!ValidateHwnd+89

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: win32k!ValidateHwnd+89

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c

    STACK_COMMAND: .cxr 0xfffff880061da1c0 ; kb

    FAILURE_BUCKET_ID: X64_0x3B_win32k!ValidateHwnd+89

    BUCKET_ID: X64_0x3B_win32k!ValidateHwnd+89

    Followup: MachineOwner

    ---------

    what can be the problem ? (today it occurs when I used teamspeak 3, and I see this process in the dump of the windebug, also I see "

    OVERLAPPED_MODULE: Address regions for 'USBSTOR' and 'spsys.sys' overlap" and I have an external USB hard disk...

     

    can be any of them be the cause of the problem ? (just to clarify, yesterday the USB HD was connected but teamspeak3 NO)

     

    T.I.A.

    Ernesto

     

     

     

     

    Thursday, November 18, 2010 11:05 PM

Answers

  • Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION

    This indicates that an exception happened while executing a routine that transitions from non-privileged code to privileged code.

    http://msdn.microsoft.com/en-us/library/ff558949%28VS.85%29.aspx

    Cause

    This error has been linked to excessive paged pool usage and may occur due to user-mode graphics drivers crossing over and passing bad data to the kernel code.



    update the graphic card driver and check your RAM for errors, because you get access violations:

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    • Marked as answer by Leo Huang Wednesday, November 24, 2010 9:16 AM
    Friday, November 19, 2010 12:41 PM

All replies

  • Hi:

     

    Just 3 days ago  I installed my new win7 ultimate 64 bits and yesterday and today it's made a blue screen and restart (just one time occurs yesteraday and one time today)

    The error in the blue screen is:

    SYSTEM_SERVICE_EXCEPTION

    0x0000003b

    caused by drive: win32k.sys

    caused by address: win32k.sys+cadd9

    the windebug show:

    1: kd> !analyze -v

    *******************************************************************************

    * *

    * Bugcheck Analysis *

    * *

    *******************************************************************************

    SYSTEM_SERVICE_EXCEPTION (3b)

    An exception happened while executing a system service routine.

    Arguments:

    Arg1: 00000000c0000005, Exception code that caused the bugcheck

    Arg2: fffff960001badd9, Address of the instruction which caused the bugcheck

    Arg3: fffff880061da1c0, Address of the context record for the exception that caused the bugcheck

    Arg4: 0000000000000000, zero.

    Debugging Details:

    ------------------

     

    OVERLAPPED_MODULE: Address regions for 'USBSTOR' and 'spsys.sys' overlap

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

    FAULTING_IP:

    win32k!ValidateHwnd+89

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h]

    CONTEXT: fffff880061da1c0 -- (.cxr 0xfffff880061da1c0)

    rax=fff7f900c06ffc30 rbx=fffff900c04081f0 rcx=00000000000b056a

    rdx=fffffa8003cf1280 rsi=00000000000b056a rdi=fffff900c083dfe0

    rip=fffff960001badd9 rsp=fffff880061dab90 rbp=0000000000000000

    r8=fffff900c065ec30 r9=0000000000000000 r10=fffff960001c0b00

    r11=fff7f900c06ffc30 r12=0000000000000000 r13=0000000000000000

    r14=0000000003944c20 r15=0000000002169d50

    iopl=0 nv up ei pl nz na po nc

    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206

    win32k!ValidateHwnd+0x89:

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h] ds:002b:fff7f900`c06ffda8=????????????????

    Resetting default scope

    DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

    BUGCHECK_STR: 0x3B

    PROCESS_NAME: ts3client_win6

    CURRENT_IRQL: 0

    LAST_CONTROL_TRANSFER: from fffff960001c0b72 to fffff960001badd9

    STACK_TEXT:

    fffff880`061dab90 fffff960`001c0b72 : 00000000`00000000 00000000`000b056a 00000980`00000000 0000007f`fffffff8 : win32k!ValidateHwnd+0x89

    fffff880`061dabc0 fffff800`0288b993 : fffffa80`04411060 fffff880`061daca0 00000000`00000401 00000000`00000020 : win32k!NtUserPostMessage+0x72

    fffff880`061dac20 00000000`772d92ca : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13

    00000000`0380f6c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x772d92ca

     

    FOLLOWUP_IP:

    win32k!ValidateHwnd+89

    fffff960`001badd9 483b9078010000 cmp rdx,qword ptr [rax+178h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: win32k!ValidateHwnd+89

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: win32k

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c

    STACK_COMMAND: .cxr 0xfffff880061da1c0 ; kb

    FAILURE_BUCKET_ID: X64_0x3B_win32k!ValidateHwnd+89

    BUCKET_ID: X64_0x3B_win32k!ValidateHwnd+89

    Followup: MachineOwner

    ---------

    what can be the problem ? (today it occurs when I used teamspeak 3, and I see this process in the dump of the windebug, also I see "

    OVERLAPPED_MODULE: Address regions for 'USBSTOR' and 'spsys.sys' overlap" and I have an external USB hard disk...

     

    can be any of them be the cause of the problem ? (just to clarify, yesterday the USB HD was connected but teamspeak3 NO)

     

    T.I.A.

    Ernesto

     

     

     

     


    Also, yesterday dump crash was:

     

    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff8000285df97, Address of the instruction which caused the bugcheck
    Arg3: fffff88008388f10, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.

    Debugging Details:
    ------------------


    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

    FAULTING_IP:
    nt!KiDeliverApc+a7
    fffff800`0285df97 498b4a30        mov     rcx,qword ptr [r10+30h]

    CONTEXT:  fffff88008388f10 -- (.cxr 0xfffff88008388f10)
    rax=0000000000000002 rbx=fffffa8004b333a0 rcx=0000000000000001
    rdx=fffff800028889b4 rsi=fffffa8004b333f0 rdi=0000000000000102
    rip=fffff8000285df97 rsp=fffff880083898e0 rbp=fffff88008389960
     r8=fff7fa8004b333f0  r9=0000000000000000 r10=fff7fa8004b333e0
    r11=0000000000000000 r12=0000000000000001 r13=0000000000000000
    r14=fffffa80046b05e0 r15=fffff88008389c20
    iopl=0         nv up ei ng nz na po cy
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010287
    nt!KiDeliverApc+0xa7:
    fffff800`0285df97 498b4a30        mov     rcx,qword ptr [r10+30h] ds:002b:fff7fa80`04b33410=????????????????
    Resetting default scope

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    BUGCHECK_STR:  0x3B

    PROCESS_NAME:  fsx.exe

    CURRENT_IRQL:  2

    LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff8000285df97

    STACK_TEXT: 
    fffff880`083898e0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDeliverApc+0xa7


    FOLLOWUP_IP:
    nt!KiDeliverApc+a7
    fffff800`0285df97 498b4a30        mov     rcx,qword ptr [r10+30h]

    SYMBOL_STACK_INDEX:  0

    SYMBOL_NAME:  nt!KiDeliverApc+a7

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME:  ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9

    STACK_COMMAND:  .cxr 0xfffff88008388f10 ; kb

    FAILURE_BUCKET_ID:  X64_0x3B_nt!KiDeliverApc+a7

    BUCKET_ID:  X64_0x3B_nt!KiDeliverApc+a7

    Followup: MachineOwner
    ---------

     

    Thursday, November 18, 2010 11:13 PM
  • Bug Check 0x3B: SYSTEM_SERVICE_EXCEPTION

    This indicates that an exception happened while executing a routine that transitions from non-privileged code to privileged code.

    http://msdn.microsoft.com/en-us/library/ff558949%28VS.85%29.aspx

    Cause

    This error has been linked to excessive paged pool usage and may occur due to user-mode graphics drivers crossing over and passing bad data to the kernel code.



    update the graphic card driver and check your RAM for errors, because you get access violations:

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.


    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/
    • Marked as answer by Leo Huang Wednesday, November 24, 2010 9:16 AM
    Friday, November 19, 2010 12:41 PM