We are seeing lot of blue screen issues in our enterprise desktops. Most of them are pointing to eitherntkrnlmp.exe orcsrss.exe processes. Can someone help us in this?
Our corporate policy prohibits us to upload the dump files. So find below a part of Windows DebuggerBugcheck Analysis:
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000005005, The subtype of the bugcheck.
Arg2: fffff70001080000
Arg3: 00000000000004c1
Arg4: 00000000000004c2
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_5005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: DF_p.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800030f2d2b to fffff80003092b80
STACK_TEXT:
fffff880`0a07b8f8 fffff800`030f2d2b : 00000000`0000001a 00000000`00005005 fffff700`01080000 00000000`000004c1 : nt!KeBugCheckEx
fffff880`0a07b900 fffff800`030afa17 : 80000000`8e196025 00000000`00000020 fffff700`01080000 fffff800`0333cda6 : nt! ?? ::FNODOBFM::`string'+0x1fff5
fffff880`0a07b970 fffff800`0309f179 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff8a0`00000000 : nt!MiDispatchFault+0x6e7
fffff880`0a07ba80 fffff800`03090cae : 00000000`00000000 00000000`02c428c8 00000000`7efdb001 00000000`02c428c8 : nt!MmAccessFault+0x359
fffff880`0a07bbe0 00000000`7797f50f : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`0140efd4 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7797f50f
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+1fff5
fffff800`030f2d2b cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+1fff5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 51fb06cd
FAILURE_BUCKET_ID: X64_0x1a_5005_nt!_??_::FNODOBFM::_string_+1fff5
BUCKET_ID: X64_0x1a_5005_nt!_??_::FNODOBFM::_string_+1fff5
Followup: MachineOwner
---------
Any help in this is greatly appreciated.
Thanks,
Vijay