<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ask the Core Team : Disaster Recovery</title><link>http://blogs.technet.com/askcore/archive/tags/Disaster+Recovery/default.aspx</link><description>Tags: Disaster Recovery</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Windows Vista Boots to a Black Screen with only the Mouse Cursor</title><link>http://blogs.technet.com/askcore/archive/2009/01/07/windows-vista-boots-to-a-black-screen-with-only-the-mouse-cursor.aspx</link><pubDate>Wed, 07 Jan 2009 22:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3177587</guid><dc:creator>tomac</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askcore/comments/3177587.aspx</comments><wfw:commentRss>http://blogs.technet.com/askcore/commentrss.aspx?PostID=3177587</wfw:commentRss><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;&lt;U&gt;Problem&lt;/U&gt;&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Upon startup, Windows Vista Boots to a Black Screen with only the Mouse Cursor &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;&lt;U&gt;Resolution&lt;/U&gt;&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;This is most likely due to the Remote Procedure Call service (rpcss) running under the LocalSystem account rather than NT Authority\NetworkService account. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;To resolve the issue, follow this procedure on the problem machine: &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; On the affected machine, boot using the Vista Media (i.e. the Vista install DVD or any Vista Media that is bootable will work) and Select “Next” &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_2.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_2.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=365 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb.png" width=496 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; Then in the bottom left you will see “&lt;STRONG&gt;Repair your Computer&lt;/STRONG&gt;”&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_4.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_4.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=378 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_1.png" width=505 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; Select &lt;STRONG&gt;Next&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_6.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_6.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=323 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_2.png" width=420 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp; Then Select &lt;STRONG&gt;Command Prompt&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_10.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_10.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=303 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_4.png" width=400 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_4.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp; At the command prompt, launch &lt;STRONG&gt;regedit.exe&lt;/STRONG&gt; and load the SYSTEM hive, following the next steps below.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_12.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_12.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=276 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_5.png" width=547 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_5.png"&gt;&lt;/A&gt; &lt;FONT face=Arial size=2&gt;&lt;BR&gt;a)&amp;nbsp;&amp;nbsp;&amp;nbsp; Select&amp;nbsp; &lt;STRONG&gt;HKEY_LOCAL_MACHINE&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_14.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_14.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=255 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_6.png" width=368 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_6.png"&gt;&lt;/A&gt; &lt;FONT face=Arial size=2&gt;&lt;BR&gt;b)&amp;nbsp;&amp;nbsp;&amp;nbsp; On the &lt;STRONG&gt;File&lt;/STRONG&gt; menu, select &lt;STRONG&gt;Load Hive&lt;/STRONG&gt;. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_16.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_16.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=164 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_7.png" width=327 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_7.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;BR&gt;c)&amp;nbsp;&amp;nbsp;&amp;nbsp; Browse to %WINDIR%\System32\Config Folder (typically C:\Windows\\System32\Config) and select “&lt;STRONG&gt;SYSTEM&lt;/STRONG&gt;”&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_18.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_18.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=177 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_8.png" width=254 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_8.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_20.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_20.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=118 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_9.png" width=368 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_9.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;d)&amp;nbsp;&amp;nbsp;&amp;nbsp; Select &lt;STRONG&gt;Open&lt;/STRONG&gt;. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;e)&amp;nbsp;&amp;nbsp;&amp;nbsp; In the &lt;STRONG&gt;Load Hive&lt;/STRONG&gt; dialog box, type in “&lt;STRONG&gt;MySYSTEM&lt;/STRONG&gt;” box for the registry hive that you want to edit. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_22.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_22.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=131 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_10.png" width=440 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_10.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp; After the hive is loaded, modify the following key value per the instructions below: &lt;BR&gt;You will need to know what ControlSet the machine is currently running on, this can be determined by going to &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;HKEY_LOCAL_MACHINE\MySYSTEM\Select &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;and find the “Current” value in the Right hand side. (Example: Current value is 1 then the ControlSet will be ControlSet001)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_24.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_24.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=308 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_11.png" width=484 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_11.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp; Navigate to the following key: &lt;BR&gt;Key:&amp;nbsp; &lt;STRONG&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00&lt;FONT color=#ff0000&gt;X&lt;/FONT&gt;\Services\RpcSs&lt;/STRONG&gt; (&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;X&lt;/FONT&gt;&lt;/STRONG&gt; is the Number from the Current Key from above)&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Arial size=2&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Double click the value: &lt;BR&gt;&lt;/STRONG&gt;Value Name:&amp;nbsp; ObjectName&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Change the value: &lt;BR&gt;&lt;/STRONG&gt;Old Value:&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;LocalSystem &lt;BR&gt;&lt;/STRONG&gt;New Value:&amp;nbsp; &lt;STRONG&gt;NT AUTHORITY\NetworkService&lt;/STRONG&gt; &lt;/P&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_26.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_26.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=358 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_12.png" width=501 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_12.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_28.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_28.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=131 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_13.png" width=303 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_13.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp; Unload the SYSTEM hive by selecting the key “&lt;STRONG&gt;MySYSTEM&lt;/STRONG&gt;” and then select File -&amp;gt; Unload Hive… menu item.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_30.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_30.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=161 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_14.png" width=244 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_14.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_32.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_32.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=266 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_15.png" width=292 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_15.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;9.&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit regedit.exe &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;10.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;Restart &lt;/STRONG&gt;the system normally &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_34.png" mce_href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_34.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=291 alt=image src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_16.png" width=384 border=0 mce_src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/WindowsVistaBootstoaBlackScreenwithonlyt_B8B8/image_thumb_16.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;* If you do not have the Vista Boot CD, you can download Microsoft Diagnostics and Recovery Toolset from this link: &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=5D600369-0554-4595-8AB4-C34B2860E087&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=5D600369-0554-4595-8AB4-C34B2860E087&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=1&gt;http://www.microsoft.com/downloads/details.aspx?familyid=5D600369-0554-4595-8AB4-C34B2860E087&amp;amp;displaylang=en&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We are still investigating root cause of this issue.&amp;nbsp; At this time, a 3rd party remote access program is suspected.&lt;/P&gt;
&lt;P&gt;Author: &lt;BR&gt;&lt;STRONG&gt;Tanner Slayton&lt;/STRONG&gt; &lt;BR&gt;Senior Support Engineer &lt;BR&gt;Microsoft Corporation&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class=wlWriterSmartContent id=scid:0767317B-992E-4b12-91E0-4F059A8CECA8:dd79b24d-9e83-47a2-a7f2-61bd10f529a8 style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"&gt;Technorati Tags: &lt;A href="http://technorati.com/tags/black%20screen" rel=tag mce_href="http://technorati.com/tags/black%20screen"&gt;black screen&lt;/A&gt;,&lt;A href="http://technorati.com/tags/Vista" rel=tag mce_href="http://technorati.com/tags/Vista"&gt;Vista&lt;/A&gt;,&lt;A href="http://technorati.com/tags/repair" rel=tag mce_href="http://technorati.com/tags/repair"&gt;repair&lt;/A&gt;,&lt;A href="http://technorati.com/tags/recovery" rel=tag mce_href="http://technorati.com/tags/recovery"&gt;recovery&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3177587" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askcore/archive/tags/Disaster+Recovery/default.aspx">Disaster Recovery</category><category domain="http://blogs.technet.com/askcore/archive/tags/Windows+Vista/default.aspx">Windows Vista</category></item><item><title>How to Debug Kernel Mode Blue Screen Crashes (for beginners)</title><link>http://blogs.technet.com/askcore/archive/2008/11/01/how-to-debug-kernel-mode-blue-screen-crashes-for-beginners.aspx</link><pubDate>Sat, 01 Nov 2008 03:47:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145531</guid><dc:creator>tomac</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/askcore/comments/3145531.aspx</comments><wfw:commentRss>http://blogs.technet.com/askcore/commentrss.aspx?PostID=3145531</wfw:commentRss><description>&lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;Perhaps the largest call generator for the Core Team is for us to determine cause of a hard system crash that generates a Blue Screen and memory dump file.&amp;#160; Commonly called a &amp;quot;Blue Screen of Death (BSOD).&amp;quot;&amp;#160; The vast majority of these memory dumps could be analyzed by Administrators in just a few minutes using the latest debugging tools.&amp;#160; These tools do most of the work for you, once they're set up.&amp;#160; Kernel mode debugging is a pretty specialized skill, with experienced debuggers throwing around lots of imponderable terms.&amp;#160; But it's really pretty simple and I'll point out the gaffe's you'll want to avoid as a beginner. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" size="3"&gt;&lt;font color="#000080"&gt;Keep in mind that the following is very basic (Debugging for Dummies, if you will).&amp;#160; If you're already familiar with &lt;u&gt;!analyze&lt;/u&gt;&amp;#160; and how to get there, this article is not for you.&amp;#160; Consider instead our sister website, NTDebugging&lt;/font&gt; (&lt;/font&gt;&lt;a href="http://blogs.msdn.com/ntdebugging/)"&gt;&lt;font face="Arial" size="3"&gt;http://blogs.msdn.com/ntdebugging/)&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial" size="3"&gt;. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;Here's some terminology you should know before carrying on:&lt;/font&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;u&gt;Blue screen&lt;/u&gt;       &lt;br /&gt;When the system encounters a hardware problem, data inconsistency, or similar error, it may display a blue screen containing information that can be used to determine the cause of the error. This information includes the STOP code and whether a crash dump file was created. It may also include a list of loaded drivers and a stack trace. &lt;/p&gt;    &lt;p&gt;&lt;u&gt;Crash dump file&lt;/u&gt;       &lt;br /&gt;You can configure the system to write information to a crash dump file on your hard disk whenever a STOP code is generated. The file (memory.dmp) contains information the debugger can use to analyze the error. This file can be as big as the physical memory contained in the computer.&amp;#160; By default, it's located in the Windows folder, and you CAN call them &amp;quot;memory dumps&amp;quot; without fear of offending anyone. &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;u&gt;Debugger &lt;/u&gt;      &lt;br /&gt;A program designed to help detect, locate, and correct errors in another program. It allows the user to step through the execution of the process and its threads, monitoring memory, variables, and other elements of process and thread context. &lt;/p&gt;    &lt;p&gt;&lt;u&gt;Kernel mode&lt;/u&gt;       &lt;br /&gt;The processor mode in which system services and device drivers run. All interfaces and CPU instructions are available, and all memory is accessible. &lt;/p&gt;    &lt;p&gt;&lt;u&gt;Minidump file        &lt;br /&gt;&lt;/u&gt;A minidump is a smaller version of a complete, or kernel memory dump.&amp;#160; Usually Microsoft will want a kernel memory dump.&amp;#160; But the debugger will analyze a mini-dump and quite possibly give information needed to resolve.&amp;#160; If it's all you have, then debug it, rather than waiting for the machine to crash again.&amp;#160; Open the file in the debugger (see below) just as opening memory.dmp in the demonstration. &lt;/p&gt;    &lt;p&gt;&lt;u&gt;STOP code&lt;/u&gt;       &lt;br /&gt;The error code that identifies the error that stopped the system kernel from continuing to run.&amp;#160; It is the first set of hexadecimal values displayed on the blue screen.&amp;#160; At a minimum, frontline Admins should be required to note this code, and the four other codes displayed in parenthesis, and any drivers identified on the screen.&amp;#160; Often, this is all you really need! &lt;/p&gt;    &lt;p&gt;&lt;u&gt;Symbol files        &lt;br /&gt;&lt;/u&gt;All system applications, drivers, and DLLs are built such that their debugging information resides in separate files known as symbol files. Therefore, the system is smaller and faster, yet it can still be debugged if the symbol files are available.&amp;#160;&amp;#160; You don't need the Symbol files to debug - the debugger will automatically access the ones it needs from Microsoft's public site. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;First, let's install the Debugger and Symbols.&amp;#160; You can debug a 64 bit dump on a 32 bit system, and you can debug a 32 bit dump on an x64 machine.&amp;#160; If you have an x64 machine then, you only need the x64 version to analyze any version of memory.dmp.&amp;#160; Many engineers prefer to use just the 32 bit version, since you'll still see the information necessary to determine cause. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080"&gt;&lt;font face="Arial" size="3"&gt;The sites below identify the system requirements, etc. you'll need for the debugger to work.&amp;#160; For our purposes, we'll assume you have an actual memory dump (memory.dmp) file.&amp;#160; If you don't the rest is not going to be much fun.&amp;#160; You can access a memory dump over the network to a machine that's recently crashed.&amp;#160; Most times though, it will make more sense to copy the dump file to your Debugging machine.&amp;#160; Oh, and if you're wondering, you don't need a separate &amp;quot;Debugging machine&amp;quot; - the debugger doesn't use much memory and evil code from a memory dump can't sneak on to your machine and devour your movies and music.&lt;/font&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;For 32 bit, x86 debugging&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx#a"&gt;http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx#a&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;For 64 bit debugging &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#"&gt;http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" size="3"&gt;&lt;font color="#000080"&gt;In this article I'll be using x64, but the examples will still apply to a 32 bit system.&amp;#160; You'll need to download the debugger and install it - accept the defaults.&lt;/font&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="315" alt="image" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_thumb.png" width="477" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_4.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="352" alt="image" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_thumb_1.png" width="451" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;By default, everything you need (for now) is installed here. &lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Arial" size="3"&gt;C:\Program Files\Debugging Tools for Windows (x64) &lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;Note there's a help file (debugger.chm) that will be very useful as you advance your debugging skills.&amp;#160; You start the debugger from /Start /Debugging Tools for Windows /WinDbg.&amp;#160; This brings up the GUI mode of the Windows Debugger.&amp;#160; There's also a command version that can be&amp;#160; started using kd.exe.&amp;#160; Unless you work at a driver developer, the GUI version is fine.&amp;#160; If you do work at a driver developer, never open the GUI mode unless you're ready for sneers behind your back. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;The debugger opens to a big red window with nothing in it.&amp;#160; Assuming you have a memory.dmp file to be analyzed in your X:\crashes folder, you'll want to go to /File /Open Crash Dump and browse there. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_6.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="487" alt="image" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_thumb_2.png" width="637" border="0" /&gt;&lt;/a&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;When you so open the memory.dmp, another window will be launched and you'll see output similar to below.&amp;#160; Note the errors about Symbol files.&lt;/font&gt;&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Loading Dump File [X:\Crashes\MEMORY.DMP]       &lt;br /&gt;Kernel Summary Dump File: Only kernel address space is available &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Symbol search path is:       &lt;br /&gt;Executable search path is:         &lt;br /&gt;*** ERROR: &lt;font color="#ff0000"&gt;Symbol file could not be found&lt;/font&gt;.&amp;#160; Defaulted to export symbols for ntkrnlmp.exe -         &lt;br /&gt;Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (8 procs) Free x64        &lt;br /&gt;Product: Server, suite: TerminalServer SingleUserTS        &lt;br /&gt;Built by: 3790.srv03_sp2_gdr.080813-1204        &lt;br /&gt;Kernel base = 0xfffff800`01000000 PsLoadedModuleList = 0xfffff800`011d4140        &lt;br /&gt;Debug session time: Thu Oct 23 08:53:46.973 2008 (GMT-5)        &lt;br /&gt;System Uptime: 6 days 9:45:10.361        &lt;br /&gt;*** &lt;font color="#ff0000"&gt;ERROR: Symbol file could not be found.&lt;/font&gt;&amp;#160; Defaulted to export symbols for ntkrnlmp.exe -         &lt;br /&gt;Loading Kernel Symbols        &lt;br /&gt;..............................................................................................................................        &lt;br /&gt;Loading User Symbols        &lt;br /&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details        &lt;br /&gt;Loading unloaded module list        &lt;br /&gt;............................................        &lt;br /&gt;*******************************************************************************        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Bugcheck Analysis&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;******************************************************************************* &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Use &lt;font color="#0000ff"&gt;&lt;u&gt;!analyze -v&lt;/u&gt;&lt;/font&gt; to get detailed debugging information. &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;BugCheck D1, {0, c, 0, 0} &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;*** &lt;font color="#ff0000"&gt;ERROR: Module load completed but symbols could not be loaded for mssmbios.sys&lt;/font&gt;        &lt;br /&gt;***** &lt;font color="#ff0000"&gt;Kernel symbols are WRONG. Please fix symbols to do analysis. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;*************************************************************************       &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; &lt;font color="#ff0000"&gt;Your debugger is not using the correct symbols&lt;/font&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; In order for this command to work properly, your symbol path&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; must point to .pdb files that have full type information.&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; Certain .pdb files (such as the public OS symbols) do not&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; contain the required information.&amp;#160; Contact the group that&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; provided you with these symbols if you need this command to&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; work.&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160; Type referenced: nt!_KPRCB&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;***&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ***        &lt;br /&gt;*************************************************************************        &lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for CLASSPNP.SYS&lt;/font&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;Obviously, we have a Symbols problem!&amp;#160; More importantly, this is our first experience of the debugger telling us what to do (or giving good hints).&amp;#160; You'll want to watch for these clues as you progress in debugging.&amp;#160; If you've heard people muttering about symbols and not being able to find the right ones, fear not!&amp;#160; Go to the window at the bottom of the page and type !symfix. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_8.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="50" alt="image" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_thumb_3.png" width="207" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;font size="3"&gt;&lt;font face="Arial"&gt;&lt;font color="#000080"&gt;Most of the commands you'll use start with an exclamation point.&amp;#160; But don't call it that!&amp;#160; What you just typed is called &amp;quot;bang symfix.&amp;quot;&amp;#160; And what it does is connects the debugger to Microsoft's public symbols library on the internet.&lt;/font&gt;&amp;#160; &lt;/font&gt;&lt;/font&gt;&lt;a href="http://msdl.microsoft.com/download/symbols"&gt;&lt;font face="Arial" size="3"&gt;http://msdl.microsoft.com/download/symbols&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial" size="3"&gt;&amp;#160; &lt;font color="#000080"&gt;Note this isn't an ordinary web page, you can't access it through a browser.&amp;#160; At this point, you'll need to save your workspace (give it a name in /File /Save Workspace).&amp;#160; Close WinDbg and reopen it, your workspace, and your memory dump file. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" size="3"&gt;&lt;font color="#000080"&gt;This time, information will fly by and voila, you're debugging!&amp;#160; What you'll see in the debugger window will vary by the kind of Stop Code being debugged.&amp;#160; In this example, we're looking at a Stop 0x000000D1 (known to those in the know as a &amp;quot;Stop D1&amp;quot; - zeroes are ignored).&amp;#160; You should see something like the following.&amp;#160; If you get errors, or Symbols errors, for now, ignore them.&lt;/font&gt; &lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Microsoft (R) Windows Debugger Version 6.10.0002.229 AMD64       &lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved. &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Loading Dump File [X:\crashes\MEMORY.DMP]       &lt;br /&gt;Kernel Summary Dump File: Only kernel address space is available &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Symbol search path is: &lt;/font&gt;&lt;a href="http://msdl.microsoft.com/download/symbols"&gt;&lt;font face="Lucida Console" size="2"&gt;http://msdl.microsoft.com/download/symbols&lt;/font&gt;&lt;/a&gt;      &lt;br /&gt;&lt;font face="Lucida Console" size="2"&gt;Executable search path is: srv*       &lt;br /&gt;Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (8 procs) Free x64        &lt;br /&gt;Product: Server, suite: TerminalServer SingleUserTS        &lt;br /&gt;Built by: 3790.srv03_sp2_gdr.080813-1204        &lt;br /&gt;Machine Name:        &lt;br /&gt;Kernel base = 0xfffff800`01000000 PsLoadedModuleList = 0xfffff800`011d4140        &lt;br /&gt;Debug session time: Thu Oct 23 08:53:46.973 2008 (GMT-5)        &lt;br /&gt;System Uptime: 6 days 9:45:10.361        &lt;br /&gt;Loading Kernel Symbols        &lt;br /&gt;...............................................................        &lt;br /&gt;...............................................................        &lt;br /&gt;Loading User Symbols        &lt;br /&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details        &lt;br /&gt;Loading unloaded module list        &lt;br /&gt;............................................        &lt;br /&gt;*******************************************************************************        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Bugcheck Analysis&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;******************************************************************************* &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Use &lt;font color="#0000ff"&gt;&lt;u&gt;!analyze -v&lt;/u&gt;&lt;/font&gt; to get detailed debugging information. &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;BugCheck D1, {0, c, 0, 0} &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Debugger CompCtrlDb Connection::Open failed 80004005       &lt;br /&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details        &lt;br /&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details        &lt;br /&gt;Probably caused by : HpCISSs2.sys &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Followup: wintriag       &lt;br /&gt;--------- &lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;At this point the debugger might give us a clue to what likely caused the problem, with the statement (which may not be present in your analysis),&lt;/font&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;font color="#ff0000"&gt;&lt;font face="Lucida Console" size="2"&gt;Probably caused by :&lt;/font&gt;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;Then the problem file will be identified.&amp;#160;&amp;#160; Nearly all bugchecks are caused by an incorrect driver (most manufacturers are pretty good about fixing flaws in their drivers).&amp;#160; You can fix this (again in most cases) by just obtaining the latest version of that driver (and related installation software) from the vendor. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;If the debugger doesn't give this clue, or you're suspicious it's incorrect, the debugger tells you what to do..&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;font face="Lucida Console" size="2"&gt;Use &lt;u&gt;&lt;font color="#0000ff"&gt;!analyze -v&lt;/font&gt;&lt;/u&gt; to get detailed debugging information.&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;&lt;font face="Arial" color="#000080" size="3"&gt;In fact, you don't even have to type, just click on the &lt;font face="Lucida Console" color="#0000ff" size="2"&gt;!analyze -v&lt;/font&gt; with your mouse, and you're off and running again.&amp;#160; The debugger gives even more detailed information and a message of what to do next...&lt;/font&gt;&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;7: kd&amp;gt; !analyze -v       &lt;br /&gt;*******************************************************************************        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Bugcheck Analysis&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *        &lt;br /&gt;******************************************************************************* &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)       &lt;br /&gt;An attempt was made to access a pageable (or completely invalid) address at an        &lt;br /&gt;interrupt request level (IRQL) that is too high.&amp;#160; This is usually        &lt;br /&gt;caused by drivers using improper addresses.        &lt;br /&gt;If kernel debugger is available get stack backtrace.        &lt;br /&gt;Arguments:        &lt;br /&gt;Arg1: 0000000000000000, memory referenced        &lt;br /&gt;Arg2: 000000000000000c, IRQL        &lt;br /&gt;Arg3: 0000000000000000, value 0 = read operation, 1 = write operation        &lt;br /&gt;Arg4: 0000000000000000, address which referenced memory &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Debugging Details:       &lt;br /&gt;------------------ &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details       &lt;br /&gt;PEB is paged out (Peb.Ldr = 000007ff`fffde018).&amp;#160; Type &amp;quot;.hh dbgerr001&amp;quot; for details &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;READ_ADDRESS:&amp;#160; 0000000000000000 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;CURRENT_IRQL:&amp;#160; c &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;FAULTING_IP:        &lt;br /&gt;+0        &lt;br /&gt;00000000`00000000 ??&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ??? &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;PROCESS_NAME:&amp;#160; vssrvc.exe &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;DEFAULT_BUCKET_ID:&amp;#160; DRIVER_FAULT &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;BUGCHECK_STR:&amp;#160; 0xD1 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;TRAP_FRAME:&amp;#160; fffffadf238fc110 -- (.trap 0xfffffadf238fc110)       &lt;br /&gt;NOTE: The trap frame does not contain all registers.        &lt;br /&gt;Some register values may be zeroed or incorrect.        &lt;br /&gt;rax=00000000fff92000 rbx=0000000000000000 rcx=00000000c0000102        &lt;br /&gt;rdx=00000000000007ff rsi=0000000000000000 rdi=fffff80001031095        &lt;br /&gt;rip=0000000000000000 rsp=fffffadf238fc2a0 rbp=0000000000000007        &lt;br /&gt; r8=0004969a8262692a&amp;#160; r9=fffff800011b73e8 r10=0000000000000000        &lt;br /&gt;r11=fffffadf29aed450 r12=0000000000000000 r13=0000000000000000        &lt;br /&gt;r14=0000000000000000 r15=0000000000000000        &lt;br /&gt;iopl=0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; nv up ei ng nz na pe nc        &lt;br /&gt;00000000`00000000 ??&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ???        &lt;br /&gt;Resetting default scope &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;LAST_CONTROL_TRANSFER:&amp;#160; from fffff8000102e5b4 to fffff8000102e890 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;FAILED_INSTRUCTION_ADDRESS:        &lt;br /&gt;+0        &lt;br /&gt;00000000`00000000 ??&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ??? &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;STACK_TEXT:&amp;#160; &lt;br /&gt;fffffadf`238fbf88 fffff800`0102e5b4 : 00000000`0000000a 00000000`00000000 00000000`0000000c 00000000`00000000 : nt!KeBugCheckEx [d:\nt\base\ntos\ke\amd64\procstat.asm @ 170]        &lt;br /&gt;fffffadf`238fbf90 fffff800`0102d547 : fffffadf`35519260 00000000`00008000 00000000`00000100 fffffadf`292ca8cf : nt!KiBugCheckDispatch+0x74 [d:\nt\base\ntos\ke\amd64\trap.asm @ 2122]        &lt;br /&gt;fffffadf`238fc110 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x207 [d:\nt\base\ntos\ke\amd64\trap.asm @ 1006] &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;STACK_COMMAND:&amp;#160; kb &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;MODULE_NAME: &lt;u&gt;&lt;font color="#0000ff"&gt;HpCISSs2 &lt;/font&gt;&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;IMAGE_NAME:&amp;#160; HpCISSs2.sys &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:&amp;#160; 4600a3fe &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;POOL_CORRUPTOR:&amp;#160; HpCISSs2 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;FOLLOWUP_NAME:&amp;#160; wintriag &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;FAILURE_BUCKET_ID:&amp;#160; X64_POOL_CORRUPTION_HpCISSs2 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;BUCKET_ID:&amp;#160; X64_POOL_CORRUPTION_HpCISSs2 &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;OCA_CRASHES:&amp;#160; 854 (in last 90 days) &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;Followup: wintriag       &lt;br /&gt;--------- &lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;The Debugger again tells you what to do (just click on&lt;/font&gt;&amp;#160; &lt;font face="Lucida Console" color="#0000ff" size="2"&gt;&lt;u&gt;HpCISSs2&lt;/u&gt;&lt;/font&gt;&amp;#160;&amp;#160; &lt;font size="3"&gt;&lt;font face="Arial" color="#000080"&gt;to get details on the driver you should update&amp;#160; and the timestamp (highlighted below).&lt;/font&gt;&lt;/font&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Lucida Console" size="2"&gt;7: kd&amp;gt; lmvm HpCISSs2       &lt;br /&gt;start&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; end&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; module name        &lt;br /&gt;fffffadf`296f3000 fffffadf`29705000&amp;#160;&amp;#160; HpCISSs2&amp;#160;&amp;#160; (deferred)&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; Image path: HpCISSs2.sys        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; Image name: &lt;font color="#ff0000"&gt;HpCISSs2.sys&lt;/font&gt;        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; Timestamp:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;font color="#ff0000"&gt;Tue Mar 20 22:18:22 2007&lt;/font&gt; (4600A3FE)        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; CheckSum:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 00015F1F        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; ImageSize:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 00012000        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; Translations:&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0000.04b0 0000.04e4 0409.04b0 0409.04e4&lt;/font&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="arial" color="#000080" size="3"&gt;To confirm, you should contact the manufacturer of this driver to see if they have any reported issues, and whether there's a replacement.&amp;#160; You can also search the Microsoft Knowledge Base, and one of the hits will be:&lt;/font&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;You receive a Stop error message after you install update 932755 or 941276      &lt;br /&gt;on an HP ProLiant server that is running Storport in Windows Server 2003      &lt;br /&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;940015"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;940015&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="aria" color="#000080" size="3"&gt;The article explains exactly what you'll need to do to resolve the bugcheck problem.&amp;#160; It won't always be that easy, but usually a little intelligent searching on the internet (using the bugcheck code and the driver) will lead you to a resolution.&amp;#160; If it doesn't please open a case with us to confirm or identify root cause. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="aria" color="#000080" size="3"&gt;If you're ready to venture out on your own, hit the helpfile and navigate to the Bug Check Code Reference.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_10.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="481" alt="image" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/HowtoDebugKernelModeBlueScreenCrashesfor_10CCD/image_thumb_4.png" width="471" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;font&gt;Here, you'll find information you need to begin debugging the Code referenced.&amp;#160; For example, if you're analyzing a Stop A, you'll want to check out the advice in the help window to the right of the marker above. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="aria" color="#000080" size="3"&gt;Further study:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;on TechNet&amp;#160;&amp;#160; &lt;/font&gt;&lt;a title="http://msdn.microsoft.com/en-us/library/cc267861.aspx" href="http://msdn.microsoft.com/en-us/library/cc267861.aspx"&gt;http://msdn.microsoft.com/en-us/library/cc267861.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="arial" color="#000080" size="3"&gt;OSR Online&lt;/font&gt;&amp;#160;&amp;#160; &lt;a title="http://www.osronline.com/index.cfm" href="http://www.osronline.com/index.cfm"&gt;http://www.osronline.com/index.cfm&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:c99e21e7-54c3-469d-996f-6b6ffdec7d24" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/bugcheck" rel="tag"&gt;bugcheck&lt;/a&gt;,&lt;a href="http://technorati.com/tags/memory%20dump" rel="tag"&gt;memory dump&lt;/a&gt;,&lt;a href="http://technorati.com/tags/debugger" rel="tag"&gt;debugger&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Disaster%20Recovery" rel="tag"&gt;Disaster Recovery&lt;/a&gt;&lt;/div&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="aria" color="#000080" size="3"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3145531" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askcore/archive/tags/Disaster+Recovery/default.aspx">Disaster Recovery</category></item></channel></rss>