<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8410376900868672224</id><updated>2012-02-15T22:56:39.079-08:00</updated><title type='text'>Month of Vista Bugs</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://movb.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-366251259470359995</id><published>2009-10-22T04:30:00.000-07:00</published><updated>2009-10-22T04:30:10.172-07:00</updated><title type='text'>This is the end</title><content type='html'>With the official launch of Windows Seven today, I guess it makes no sense to update this blog anymore.&lt;br /&gt;&lt;br /&gt;Vista has been a neverending source of &lt;a href="http://cybernetnews.com/cybernotes-microsoft-windows-vista-comics-jokes-and-humor/"&gt;pain and jokes&lt;/a&gt;. So long, goodbye, and hail to Windows Seven !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-366251259470359995?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/366251259470359995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=366251259470359995' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/366251259470359995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/366251259470359995'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2009/10/this-is-end.html' title='This is the end'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-6866080920063048239</id><published>2009-01-13T06:07:00.000-08:00</published><updated>2009-01-13T12:31:32.837-08:00</updated><title type='text'>MOVB-20 A must read</title><content type='html'>&lt;a href="http://www.motler.com/2008/11/02/upgrading-from-vista-to-xp/"&gt;Upgrading from Vista to XP&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;What else ? ;)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-6866080920063048239?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/6866080920063048239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=6866080920063048239' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/6866080920063048239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/6866080920063048239'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2009/01/movb-20-must-read.html' title='MOVB-20 A must read'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-1827989743784645815</id><published>2008-12-19T08:33:00.000-08:00</published><updated>2008-12-19T09:51:47.588-08:00</updated><title type='text'>Windows Defender: application failed to initialize: 0x80070006</title><content type='html'>I have been experiencing the following error on Windows Vista64 startup for 7 monthes:&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/0x80070006.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 457px; height: 169px;" src="http://newsoft.dyndns.org/movb/0x80070006.png" alt="Application failed to initialize: 0x80070006. The handle is invalid." border="0" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;div style="text-align: center;"&gt;Application failed to initialize: 0x80070006. The handle is invalid.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I could live without Windows Defender and &lt;a href="http://windowshelp.microsoft.com/Windows/en-us/help/b15d099f-68f5-4512-8bd2-68dd0dc9875e1033.mspx"&gt;SpyNet&lt;/a&gt;. But today, I took time to debug.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The most obvious thing to do is to query the Microsoft &lt;a href="http://support.microsoft.com/"&gt;knowledge base&lt;/a&gt;. And it worked ! Quoting &lt;a href="http://support.microsoft.com/?kbid=935511"&gt;KB935511&lt;/a&gt;:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Method 1: Use System Restore to restore Windows Vista&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Method 2: Reinstall Windows Vista&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;Ok ... maybe I'll try something else.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then I thought that interesting logs could appear in PerfMon, because Windows Defender implements &lt;a href="http://msdn.microsoft.com/en-us/library/ms793164.aspx"&gt;WPP software tracing&lt;/a&gt;. I managed to find the right Event Trace Provider (&lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;Microsoft-Windows-Windows Defender&lt;/span&gt;), create a Data Collector ... but nothing was eventually logged. Therefore I gave up this option.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then I had a look at the &lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;C:\Program Files\Windows Defender\MpCmdRun.exe&lt;/span&gt; command-line utility.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: courier new;"&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;----------------------------------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;Windows Defender Command Line Utility (c) 2006 Microsoft Corporation&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;Use this tool to automate and troubleshoot Windows Defender&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;Usage:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;mpcmdrun.exe [command] [-options]&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;Command Description&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -? [h]                          Displays all available options for this tool&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -Scan [-ScanType]               Scans for malicious software&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -SignatureUpdate                Checks for new definition updates&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -Trace [-Grouping] [-Level]     Starts diagnostic tracing&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -GetFiles                       Collects support information&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -RemoveDefinitions [-All]       Restores the installed signature definitions&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;                                   to a previous backup copy or to the original&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;                                   default set of signatures&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;   -GetSWE                         Exports information about software installed&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;                                   on your computer&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: courier new;"&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;----------------------------------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I tried &lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;-GetFiles&lt;/span&gt;, went through all log files but ... found nothing interesting either.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Looks like it is time to get out with &lt;a href="http://hex-rays.com/"&gt;IDA Pro Debugger&lt;/a&gt; ... Fortunately, remote Vista64 debugging is available through the &lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;win64_remotex64.exe&lt;/span&gt; stub ! Of course this is not for the faint of heart :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/IDA64.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 672px; height: 420px;" src="http://newsoft.dyndns.org/movb/IDA64.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Fortunately, the error is pretty easy to figure out: Windows Defender cannot acquire a handle on the &lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;WinDefend&lt;/span&gt; service ... because this service does not exist!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Why on earth was the &lt;span style="font-family: courier new;font-size:85%;" class="Apple-style-span" &gt;WinDefend&lt;/span&gt; service removed from my computer ? I guess I'll never know. But for the time being, it is enough to export the following registry key from another Vista computer, and to import it back again:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: courier new;"&gt;&lt;span class="Apple-style-span"  style="font-size:85%;"&gt;HKLM\SYSTEM\CurrentControlSet\Services\WinDefend&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Case solved !&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-1827989743784645815?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/1827989743784645815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=1827989743784645815' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/1827989743784645815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/1827989743784645815'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/12/windows-defender-application-failed-to.html' title='Windows Defender: application failed to initialize: 0x80070006'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-3006807041362112758</id><published>2008-05-21T13:36:00.000-07:00</published><updated>2008-05-21T13:55:19.438-07:00</updated><title type='text'>MOVB-19 Vista, 1 year later ...</title><content type='html'>Microsoft Vista has been available for IT professionals as soon as 30th, November 2006. But it has been launched to the public on 31st, January 2007 (if I remember well).&lt;br /&gt;&lt;br /&gt;Consequently, there has been some press activity about Vista first anniversary.&lt;br /&gt;&lt;br /&gt;Microsoft point of view is that "&lt;a href="http://msdn.microsoft.com/en-us/windowsvista/cc188969.aspx?tapm=A80S01G05"&gt;the press and critics have lauded Windows Vista for its beautiful graphics and increased usability&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;Here is my personal press review, though:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.pcworld.com/article/id,140583-page,5-c,techindustrytrends/article.html"&gt;The 15 Biggest Tech Disappointments of 2007&lt;/a&gt; (Vista is #1)&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.techrepublic.com.com/hiner/?p=571&amp;amp;tag=nl.e124"&gt;The 10 biggest technology belly flops of 2007&lt;/a&gt; (Vista ranks #2 only :)&lt;/li&gt;&lt;li&gt;&lt;a href="http://seattlepi.nwsource.com/business/349265_msftvista30.html"&gt;Vista at one year: Progress and pain&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Did SP1 change something? More (&lt;a href="http://blogs.technet.com/markrussinovich/archive/2008/02/04/2826167.aspx"&gt;file copy is now as fast as on Windows XP&lt;/a&gt;) or less (&lt;a href="http://www.crn.com/software/207500472"&gt;a key audio driver is not compatible with Vista SP1&lt;/a&gt;) ...&lt;br /&gt;&lt;br /&gt;So in the end :&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Most people &lt;a href="http://www.savexp.com/"&gt;stick to Windows XP&lt;/a&gt; for now.&lt;/li&gt;&lt;li&gt;90% of IT professionals &lt;a href="http://it.slashdot.org/article.pl?sid=07/11/19/1341253"&gt;do not want Vista&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Gartner: &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9076698"&gt;Windows is collapsing&lt;/a&gt;.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Fortunately, Microsoft has a &lt;a href="http://www.techcrunch.com/2008/04/16/microsoft-does-some-amazing-things-this-isnt-one-of-them/"&gt;refreshing video&lt;/a&gt; for motivating depressed salesmen :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-3006807041362112758?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/3006807041362112758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=3006807041362112758' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3006807041362112758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3006807041362112758'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/05/movb-19-vista-1-year-later.html' title='MOVB-19 Vista, 1 year later ...'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2821370078152594283</id><published>2008-04-04T12:01:00.000-07:00</published><updated>2008-04-04T14:01:21.567-07:00</updated><title type='text'>MOVB-18 I am not alone</title><content type='html'>Truth is out there: I have the less stable hardware configuration for running Windows Vista.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/vistacrash.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/vistacrash.jpg" alt="" border="0" /&gt;&lt;/a&gt;Read the full story on &lt;a href="http://arstechnica.com/news.ars/post/20080325-vista-capable-lawsuit-paints-picture-of-buggy-nvidia-drivers.html"&gt;ArsTechnica&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2821370078152594283?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2821370078152594283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2821370078152594283' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2821370078152594283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2821370078152594283'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/04/movb-18-i-am-not-alone.html' title='MOVB-18 I am not alone'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-3884257438474759655</id><published>2008-03-20T12:48:00.000-07:00</published><updated>2008-03-20T12:51:12.528-07:00</updated><title type='text'>MOVB-17 Got to love this one</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Stop error message when you start a Windows Vista-based computer: "0xC1F5"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;(Knowledge base article &lt;/span&gt;&lt;a style="font-style: italic;" href="http://support.microsoft.com/?kbid=946084"&gt;946084&lt;/a&gt;&lt;span style="font-style: italic;"&gt;, accessed on March 20th, 2008)&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;[...]&lt;br /&gt;WORKAROUND&lt;br /&gt;&lt;br /&gt;If you have only one disk installed, and if you have access to Windows XP or Windows 2000 installation media, restart the computer by using the Windows XP or Windows 2000 installation media. Next, format the offending disk, and then reinstall Windows Vista.&lt;br /&gt;[...]&lt;/blockquote&gt;&lt;br /&gt;Hu ho, looks pretty bad :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-3884257438474759655?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/3884257438474759655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=3884257438474759655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3884257438474759655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3884257438474759655'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/03/movb-17-got-to-love-this-one.html' title='MOVB-17 Got to love this one'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-335334862671555238</id><published>2008-03-16T13:22:00.000-07:00</published><updated>2008-03-16T13:24:31.557-07:00</updated><title type='text'>MOVB-16 Vista SP1: first bug</title><content type='html'>Yet another kernel bug triggered by FireFox.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;0: kd&gt; !analyze -v&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                        Bugcheck Analysis                                    *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IRQL_NOT_LESS_OR_EQUAL (a)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;An attempt was made to access a pageable (or completely invalid) address at an&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; interrupt request level (IRQL) that is too high.  This is usually&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; caused by drivers using improper addresses.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;If a kernel debugger is available get the stack backtrace.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arguments:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg1: c0075000, memory referenced&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg2: 00000000, IRQL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg3: 00000000, bitfield :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    bit 0 : value 0 = read operation, 1 = write operation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg4: 81eabf99, address which referenced memory&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Debugging Details:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;READ_ADDRESS: GetPointerFromAddress: unable to read from 81f53868&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Unable to read MiSystemVaType memory at 81f33420&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; c0075000 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CURRENT_IRQL:  0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAULTING_IP: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nt!MiAgeWorkingSet+1a2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;81eabf99 8b1e            mov     ebx,dword ptr [esi]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CUSTOMER_CRASH_COUNT:  1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUGCHECK_STR:  0xA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PROCESS_NAME:  firefox.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;TRAP_FRAME:  86f8fa54 -- (.trap 0xffffffff86f8fa54)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ErrCode = 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;eax=c0802d18 ebx=00a3a000 ecx=00002408 edx=00a39000 esi=c0075000 edi=c080bd38&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;eip=81eabf99 esp=86f8fac8 ebp=86f8fc44 iopl=0         nv up ei ng nz na pe cy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010287&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nt!MiAgeWorkingSet+0x1a2:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;81eabf99 8b1e            mov     ebx,dword ptr [esi]  ds:0023:c0075000=????????&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Resetting default scope&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LAST_CONTROL_TRANSFER:  from 81eabf99 to 81e76d84&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_TEXT:  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fa54 81eabf99 badb0d00 00a39000 81f099a9 nt!KiTrap0E+0x2ac&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fc44 81eab9af 8521bf60 00000003 86f8fc80 nt!MiAgeWorkingSet+0x1a2&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fc98 81eab3e4 00000002 86f8fcb4 00000001 nt!MiProcessWorkingSets+0x1ff&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fcd8 81e57612 00000000 8356e020 00000000 nt!MmWorkingSetManager+0x199&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fd7c 81ff1a1c 00000000 aea14805 00000000 nt!KeBalanceSetManager+0x12a&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;86f8fdc0 81e4aa3e 81e574e8 00000000 00000000 nt!PspSystemThreadStartup+0x9d&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_COMMAND:  kb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_IP: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nt!MiAgeWorkingSet+1a2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;81eabf99 8b1e            mov     ebx,dword ptr [esi]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_STACK_INDEX:  1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_NAME:  nt!MiAgeWorkingSet+1a2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MODULE_NAME: nt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  47918b12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IMAGE_NAME:  memory_corruption&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAILURE_BUCKET_ID:  0xA_nt!MiAgeWorkingSet+1a2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUCKET_ID:  0xA_nt!MiAgeWorkingSet+1a2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Followup: MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-335334862671555238?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/335334862671555238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=335334862671555238' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/335334862671555238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/335334862671555238'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/03/movb-16-vista-sp1-first-bug.html' title='MOVB-16 Vista SP1: first bug'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-8389584837166878912</id><published>2008-02-03T00:00:00.000-08:00</published><updated>2008-02-18T01:39:44.448-08:00</updated><title type='text'>MOVB-15 "I cannot auto-terminate"</title><content type='html'>Yet another kernel bug delivered by FireFox+YouTube combination.&lt;br /&gt;&lt;br /&gt;NtTerminateProcess() failed with the infamous IRQL_NOT_LESS_OR_EQUAL. It seems that MiDeleteAddressesInWorkingSet() tried to access data without any probe or exception handling. Did Vista kernel passed WHQL?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;0: kd&gt; !analyze -v&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                        Bugcheck Analysis                                    *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IRQL_NOT_LESS_OR_EQUAL (a)&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;An attempt was made to access a pageable (or completely invalid) address at an&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; interrupt request level (IRQL) that is too high.  This is usually &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;caused by drivers using improper addresses. &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;If a kernel debugger is available get the stack backtrace.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arguments:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arg1: c0053000, memory referenced&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arg2: 00000000, IRQL&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arg3: 00000000, bitfield :&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;    bit 0 : value 0 = read operation, 1 = write operation&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arg4: 8201985f, address which referenced memory&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Debugging Details:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;------------------&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Missing image name, possible paged-out or corrupt data.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Unable to read KLDR_DATA_TABLE_ENTRY at 00000000 - NTSTATUS 0xC0000147&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;WARNING: .reload failed, module list may be incomplete&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Missing image name, possible paged-out or corrupt data.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Unable to read KLDR_DATA_TABLE_ENTRY at 00000000 - NTSTATUS 0xC0000147&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;WARNING: .reload failed, module list may be incomplete&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;READ_ADDRESS:  c0053000&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CURRENT_IRQL:  0&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAULTING_IP:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nt!MiDeleteAddressesInWorkingSet+141&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;8201985f 8b0e            mov     ecx,dword ptr [esi]&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUGCHECK_STR:  0xA&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;TRAP_FRAME:  af78f79c -- (.trap 0xffffffffaf78f79c)&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;ErrCode = 00000000&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;eax=0a600201 ebx=84ded3a8 ecx=c080f514 edx=c080a50c esi=c0053000 edi=c0801000&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;eip=8201985f esp=af78f810 ebp=af78fc6c iopl=0         nv up ei ng nz na pe cy&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010287&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;nt!MiDeleteAddressesInWorkingSet+0x141:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;8201985f 8b0e            mov     ecx,dword ptr [esi]  ds:0023:c0053000=????????&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Resetting default scope&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LAST_CONTROL_TRANSFER:  from 8201985f to 8208fd84&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_TEXT:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:courier new;"&gt;af78f79c 8201985f badb0d00 c080a50c 85382cb5 nt!KiTrap0E+0x2ac&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fc6c 82019cc7 84ded1d8 84ded1d8 84ded1d8 nt!MiDeleteAddressesInWorkingSet+0x141&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fc9c 8221bd12 84ded1d8 af784644 84daf818 nt!MmCleanProcessAddressSpace+0x14f&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fd04 8221ad7a 00000000 00000000 84daf5b8 nt!PspExitThread+0x64a&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fd24 8221b265 84daf5b8 00000000 00000001 nt!PspTerminateThreadByPointer+0x5b&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fd54 8208caaa ffffffff 00000000 0012fea4 nt!NtTerminateProcess+0x1e0&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;af78fd54 77b20f34 ffffffff 00000000 0012fea4 nt!KiFastCallEntry+0x12a&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;0012fea4 00000000 00000000 00000000 00000000 0x77b20f34&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_IP:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;nt!MiDeleteAddressesInWorkingSet+141&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;8201985f 8b0e            mov     ecx,dword ptr [esi]&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_STACK_INDEX:  1&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_NAME:  nt!MiDeleteAddressesInWorkingSet+141&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MODULE_NAME: nt&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  471ea39c&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAILURE_BUCKET_ID:  0xA_nt!MiDeleteAddressesInWorkingSet+141&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUCKET_ID:  0xA_nt!MiDeleteAddressesInWorkingSet+141&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-8389584837166878912?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/8389584837166878912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=8389584837166878912' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/8389584837166878912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/8389584837166878912'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/02/movb-15-i-cannot-auto-terminate.html' title='MOVB-15 &quot;I cannot auto-terminate&quot;'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2911406465798245656</id><published>2008-02-02T00:00:00.000-08:00</published><updated>2008-02-04T10:26:40.776-08:00</updated><title type='text'>MOVB-14 DirectX BSoD</title><content type='html'>I have been lucky on this one.&lt;br /&gt;&lt;br /&gt;My daughter was watching videos on YouTube, so I could not deliver MOVB of the day. And then Vista died with a &lt;a href="http://msdn2.microsoft.com/en-us/library/ms796067.aspx"&gt;DirectX&lt;/a&gt; BSoD ... Enjoy !&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;0: kd&gt; !analyze -v&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                        Bugcheck Analysis                                    *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MEMORY_MANAGEMENT (1a)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    # Any other values for parameter 1 must be individually examined.&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Arguments:&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Arg1: 00000403, The subtype of the bugcheck.&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Arg2: c004e000&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Arg3: 000002f5&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Arg4: 00000000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Debugging Details:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUGCHECK_STR:  0x1a_403&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CUSTOMER_CRASH_COUNT:  1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PROCESS_NAME:  firefox.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CURRENT_IRQL:  2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BAD_PAGES_DETECTED: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LAST_CONTROL_TRANSFER:  from 82040566 to 8204099b&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;STACK_TEXT:  &lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c778a0 82040566 c004e000 84c194f0 91f19768 nt!MiDeletePte+0x360&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c779d4 820bf1bd 099c0000 09ebffff a9c7c12c nt!MiDeleteVirtualAddresses+0x8a1&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77a6c 8208caaa ffffffff 9073ccd0 9073cce4 nt!NtFreeVirtualMemory+0x655&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77a6c 8207e83d ffffffff 9073ccd0 9073cce4 nt!KiFastCallEntry+0x12a&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77af4 89461123 ffffffff 9073ccd0 9073cce4 nt!ZwFreeVirtualMemory+0x11&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77b1c 894621fb 9073ccc8 9246a008 850082d8 dxgkrnl!VIDMM_PROCESS_HEAP::Free+0x75&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77b50 89461b26 0006d258 00000001 00000000 dxgkrnl!VIDMM_GLOBAL::CloseLocalAllocation+0xd9&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77b90 89462b73 00000000 00000000 92548008 dxgkrnl!VIDMM_GLOBAL::CloseOneAllocation+0xe6&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77bb0 8946a49c af095c60 00000000 92548008 dxgkrnl!VIDMM_GLOBAL::CloseAllocation+0x37&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77c1c 89471394 b03d8e00 00000001 906d6268 dxgkrnl!DXGDEVICE::DestroyAllocations+0x176&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77c40 8946a96d b03d8e00 a94e3804 00000000 dxgkrnl!DXGDEVICE::DestroyResource+0x4b&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77c94 89463d14 a9c77cf0 00000001 a94e39c8 dxgkrnl!DXGDEVICE::DestroyAllocation+0x97&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77d58 8208caaa 099bfcfc 099bfd0c 76e80f34 dxgkrnl!DxgkDestroyAllocation+0x538&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;a9c77d58 76e80f34 099bfcfc 099bfd0c 76e80f34 nt!KiFastCallEntry+0x12a&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;099bfd0c 00000000 00000000 00000000 00000000 0x76e80f34&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_COMMAND:  kb&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_NAME:  PAGE_NOT_ZERO_VISTA&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MODULE_NAME: Unknown_Module&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IMAGE_NAME:  Unknown_Image&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUCKET_ID:  PAGE_NOT_ZERO_VISTA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Followup: MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; *** Memory manager detected 1 instance(s) of page corruption, target is likely to have memory corruption.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2911406465798245656?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2911406465798245656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2911406465798245656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2911406465798245656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2911406465798245656'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/02/movb-14-directx-bsod.html' title='MOVB-14 DirectX BSoD'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-3297626614139788046</id><published>2008-02-01T00:00:00.000-08:00</published><updated>2008-02-01T13:18:53.556-08:00</updated><title type='text'>MOVB-13 Minor annoyances</title><content type='html'>When importing pictures from a digital camera, &lt;a href="http://blogs.msdn.com/pix/archive/2006/11/07/importing-photos-with-windows-vista.aspx"&gt;you cannot selected pictures individually&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;When doing anything that requires elevation from a network share (e.g. installing software), you  have to re-enter network credentials after elevation (this is logical because of UAC design, yet annoying if you have a super-secure password :).&lt;br /&gt;&lt;br /&gt;When creating a new folder in a "privileged" location, you have to go through UAC twice: once for creating the "new folder" directory, once for renaming it. Depending on the scenario, the number of UAC prompts can be as high as 4. Hopefully, &lt;a href="http://technet2.microsoft.com/WindowsVista/en/library/005f921e-f706-401e-abb5-eec42ea0a03e1033.mspx?mfr=true"&gt;"SP1 reduces the number of UAC (User Account Control) prompts from 4 to 1 when creating or renaming a folder at a protected location"&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You cannot drag and drop files anywhere (like on the desktop) from a network share. You are restricted to a subset of folders, such as "Documents".&lt;br /&gt;&lt;br /&gt;You cannot drag and drop inside a CMD anymore. This is &lt;a href="http://www.petri.co.il/missing_drag_and_drop_vista_command_prompt.htm"&gt;"by design"&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Windows Vista users cannot easily access files on a Windows XP partition in a dual-boot configuration. Default XP users are admins, and most files are accessible by the "Administrators" group only. Vista users are not admins, and Explorer cannot be elevated.&lt;br /&gt;&lt;br /&gt;".HLP" files are not supported anymore.&lt;br /&gt;&lt;br /&gt;HyperTerminal is not bundled anymore. There is no easy way to access the serial port on Windows Vista.&lt;br /&gt;&lt;br /&gt;Telnet (and many other commands) are not available by default. You have to "re-enable" them from the Control Panel.&lt;br /&gt;&lt;br /&gt;Other interesting annoyances (FireWire drives, etc.) can be found &lt;a href="http://www.nynaeve.net/?p=109"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-3297626614139788046?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/3297626614139788046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=3297626614139788046' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3297626614139788046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3297626614139788046'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/02/movb-13-minor-annoyances.html' title='MOVB-13 Minor annoyances'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2186659101577813053</id><published>2008-01-31T00:00:00.000-08:00</published><updated>2008-02-01T13:17:08.153-08:00</updated><title type='text'>MOVB-12 Application compatibility</title><content type='html'>When trying to install third party software under Vista, you can run into the following trouble:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Software would like to disable UAC entirely.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sample application: &lt;a href="http://neosmart.net/dl.php?id=1"&gt;EasyBCD&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Software needs to be added to DEP exemption list, because it's somehow protected ("packed").&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;... and the error message will puzzle most (if not all) end-users :)&lt;br /&gt;&lt;br /&gt;Sample application: &lt;a href="http://www.auctionsentry.com/"&gt;AuctionSentry&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Software needs a compatibility pack from Microsoft&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I guess compatibility packs rely on the &lt;a href="http://www.alex-ionescu.com/?p=39"&gt;Shim Engine&lt;/a&gt;, but I have never dug too deep in those mechanisms. Let's say that it is a database of big hacks to get crappy applications working :)&lt;br /&gt;&lt;br /&gt;Sample : &lt;a href="http://support.microsoft.com/kb/932246"&gt;March 2007 Windows Vista Application Compatibility Update&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;You wait 3 monthes for an upgrade&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sample : &lt;a href="http://docs.info.apple.com/article.html?artnum=305042"&gt;iTunes&lt;/a&gt; [*], &lt;a href="http://msdn2.microsoft.com/en-us/vstudio/aa948853.aspx"&gt;Microsoft Visual Studio 2005&lt;/a&gt; [**]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;[*] It seems also that iTunes will never be Vista64-compatible.&lt;br /&gt;[**] Visual Studio 2005 still needs to be "elevated" to run properly on Vista.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;You wait 3 monthes, but the upgrade is not free&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sample : some &lt;a href="http://www.adobe.com/support/products/pdfs/adobe_products_and_windows_vista.pdf"&gt;Adobe&lt;/a&gt; products&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Oh yeah, I almost forgot. The software can play nice on 1st try! ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2186659101577813053?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2186659101577813053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2186659101577813053' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2186659101577813053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2186659101577813053'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/01/movb-12-application-compatibility.html' title='MOVB-12 Application compatibility'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-7372048830937847555</id><published>2008-01-30T00:00:00.000-08:00</published><updated>2008-01-31T09:12:35.029-08:00</updated><title type='text'>MOVB-11 Vista logging</title><content type='html'>A nice finding about Windows Vista logging:&lt;br /&gt;&lt;a href="http://www.heysoft.de/Frames/Vista_Remarks1_en.htm"&gt;http://www.heysoft.de/Frames/Vista_Remarks1_en.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In short, most event log files are not properly referenced in the registry. Under &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;HKLM\System\CCS\Services\EventLog\*\&lt;/span&gt;&lt;/span&gt;, the "File" entry has a ".elf" suffix, whereas Vista file format is ".evtx".&lt;br /&gt;&lt;br /&gt;Consequently, most remote log reading tools (like Windows XP's Event Viewer, but most log collection tools could be affected) are unable to access Vista event logs.&lt;br /&gt;&lt;br /&gt;This has been confirmed on my up-to-date Vista 64 system.&lt;br /&gt;&lt;br /&gt;The conclusion from this guy is: "&lt;span style="font-style: italic;"&gt;I must admit that I do now better understand all those people why say that they never install a Windows operating system in a     production environment before its first Service Pack is out.&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;Fortunately, SP1 is due for Q1 2008 :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-7372048830937847555?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/7372048830937847555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=7372048830937847555' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/7372048830937847555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/7372048830937847555'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/01/movb-11-vista-logging.html' title='MOVB-11 Vista logging'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-8384689575697301871</id><published>2008-01-29T00:49:00.000-08:00</published><updated>2008-01-29T02:20:22.749-08:00</updated><title type='text'>MOVB-10 Bug or security flaw?</title><content type='html'>[ &lt;span style="font-style: italic;"&gt;MOVB is back on track ... time to finish up, before Vista SP1 being out!&lt;/span&gt; ]&lt;br /&gt;&lt;br /&gt;An interesting bug from Microsoft Knowledge Base &lt;a href="http://support.microsoft.com/?kbid=945438"&gt;945438&lt;/a&gt;:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Consider the following scenario:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;On a computer that is running Windows Vista, you use Microsoft Office PowerPoint 2007 to record audio, or you use another application to record audio.&lt;/li&gt;&lt;li&gt;The application calls the &lt;span style="font-weight: bold;"&gt;acmFormatChoose&lt;/span&gt; function to display a dialog box so that you can select the waveform-audio format.&lt;/li&gt;&lt;/ul&gt;In this scenario, the application crashes.&lt;/blockquote&gt;What is more interesting is the logic behind this bug:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;The &lt;span style="font-weight: bold;"&gt;acmFormatChoose&lt;/span&gt; function tries to free a pointer that was not allocated.&lt;/blockquote&gt;Bug or security flaw? Given Vista heap protections, this one might be hard to exploit, even locally. But who dares to say &lt;a href="http://archives.neohapsis.com/archives/dailydave/2008-q1/0018.html"&gt;impossible&lt;/a&gt;, when it comes to bug exploitation?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-8384689575697301871?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/8384689575697301871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=8384689575697301871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/8384689575697301871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/8384689575697301871'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2008/01/movb-10-bug-or-security-flaw.html' title='MOVB-10 Bug or security flaw?'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-9182036949333222566</id><published>2007-11-09T12:00:00.000-08:00</published><updated>2007-11-12T01:48:47.871-08:00</updated><title type='text'>MOVB-09 Mobile devices support</title><content type='html'>So I plugged my Windows Mobile 2005 &lt;a href="http://www.europe.htc.com/products/htcp3600.html"&gt;HTC&lt;/a&gt; SmartPhone on Vista64 ...&lt;br /&gt;&lt;br /&gt;"Out of the box" software has multiple issues, such as:&lt;br /&gt;- It does not allow access to the phone internal storage (as explained in &lt;a href="http://support.microsoft.com/kb/931621"&gt;Q931621&lt;/a&gt;) ;&lt;br /&gt;- Windows Media Device Center (WMDC) shall be updated to &lt;a href="http://www.microsoft.com/windowsmobile/devicecenter.mspx"&gt;version 6.1&lt;/a&gt;, otherwise you will experience various other issues.&lt;br /&gt;&lt;br /&gt;Yet there is this nasty "feature" of Vista itself: you cannot import individual pictures from a camera. "All or none" is your only choice.&lt;br /&gt;&lt;br /&gt;Last but not least, if you set the default browser to a 3rd party application (namely FireFox), WMDC will raise an "Unhandled Exception" error when opening external links.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/wmdc.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/wmdc.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-9182036949333222566?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/9182036949333222566/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=9182036949333222566' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/9182036949333222566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/9182036949333222566'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-09-mobile-devices-support.html' title='MOVB-09 Mobile devices support'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-4350933891980327921</id><published>2007-11-08T12:00:00.000-08:00</published><updated>2007-11-08T11:04:19.451-08:00</updated><title type='text'>MOVB-08 Does UAC serve any purpose?</title><content type='html'>&lt;span style="font-style: italic;"&gt;User Account Control&lt;/span&gt; (aka UAC) is a Vista security feature[*] that has been previously experimented by other operating systems (namely Mac OS X and Linux).&lt;br /&gt;&lt;span style="font-size:78%;"&gt;[*] Well, not for &lt;a href="http://blogs.technet.com/markrussinovich/archive/2007/02/12/638372.aspx"&gt;Mark Russinovitch&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The idea is to have non-admin users by default, and to prompt them in case of an application requiring "elevated" rights.&lt;br /&gt;&lt;br /&gt;So far so good, but since users have had admin rights since the beginning of Windows saga, such a change has a huge impact on the &lt;span style="font-style: italic;"&gt;user experience&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;My bet is, a great bunch of domestic users have (or will have) UAC turned off because of:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Software invites users to disable UAC entirely (or disables UAC silently)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sample software: &lt;a href="http://www.totalidea.com/content/tweakvi/tweakvi-index.php"&gt;TweakVI&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/UAC-off.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/UAC-off.png" alt="" border="0" /&gt;&lt;/a&gt;You'd better be sure, because there is a second prompt.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/UAC-off-again.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/UAC-off-again.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;User disables UAC entirely by himself&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It is as easy as downloading &lt;a href="http://www.tweak-uac.com/"&gt;TweakUAC&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;According to this completely non-scientific poll (seens on &lt;a href="http://4sysops.com/"&gt;4sysops.com&lt;/a&gt;), that is exactly what is happening now:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/uac-poll.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/uac-poll.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Not to mention OEMs that may be tempted to disable UAC&lt;/span&gt;&lt;br /&gt;... in order to lower support costs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-4350933891980327921?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/4350933891980327921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=4350933891980327921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/4350933891980327921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/4350933891980327921'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-08-does-uac-serve-any-purpose.html' title='MOVB-08 Does UAC serve any purpose?'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-3300297513045794425</id><published>2007-11-07T12:00:00.000-08:00</published><updated>2007-11-07T05:28:34.397-08:00</updated><title type='text'>MOVB-07 Drivers, drivers, drivers!</title><content type='html'>When looking for drivers under Vista, you can run into the following trouble:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;You will never get the driver, because your hardware is unsupported&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here is a sample error message:&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;span style="font-style: italic;"&gt;Windows Vista does not support SNAPSCAN e20.&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;This problem was caused by a compatibility issue between Windows Vista and SNAPSCAN e20.&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;AGFA-Gevaert NV, the company that manufactured SNAPSCAN e20, has informed Microsoft that they do not expect to offer updates to fix this problem.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;You are trying to use a "generic" piece of hardware&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;In most cases, &lt;a href="http://www.cs.auckland.ac.nz/%7Epgut001/pubs/vista_cost.html"&gt;you loose&lt;/a&gt;! For instance, when trying to plug a generic USB mouse, here is what you get:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/mouse.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/mouse.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;You are looking for a video driver&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://channel9.msdn.com/ShowPost.aspx?PostID=236023"&gt;According to Microsoft&lt;/a&gt;, drivers are accountable for most Blue Screens of Death. So they decided to move as many drivers as possible in userland, especially video drivers. This is called &lt;span style="font-style: italic;"&gt;User Mode Driver Framework&lt;/span&gt; (aka UMDF).&lt;br /&gt;&lt;br /&gt;The result: most video cards that are older than, let's say 2 years, will never have Vista drivers (since manufacturers do not see clear value in porting drivers to UMDF).&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;You are running Vista64&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Oh my! This is alpha-testing!&lt;br /&gt;&lt;br /&gt;For instance, here are two crash dumps that are related to my NVidia Quadro FX 3400 Vista64 driver. Most driver code is userland-based, but there is still a kernelland recovery thread. And if the userland driver does not recover fast enough, the system will ... BSoD!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;0: kd&gt; !analyze -v&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                        Bugcheck Analysis                                    *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*                                                                             *&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VIDEO_TDR_FAILURE (116)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Attempt to reset the display driver and recover from timeout failed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arguments:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg1: fffffa8003c8c630, Optional pointer to internal TDR recovery context (TDR_RECOVERY_CONTEXT).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg2: fffff9800404e0f0, The pointer into responsible device driver module (e.g. owner tag).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg3: ffffffffc00000b5, Optional error code (NTSTATUS) of the last failed operation.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg4: 000000000000000a, Optional internal context dependent data.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Debugging Details:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAULTING_IP: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nvlddmkm+60f0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`0404e0f0 4883ec28        sub     rsp,28h&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEFAULT_BUCKET_ID:  GRAPHICS_DRIVER_TDR_FAULT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUGCHECK_STR:  0x116&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PROCESS_NAME:  System&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CURRENT_IRQL:  0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_TEXT:  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370a08 fffff980`0477c01c : 00000000`00000116 fffffa80`03c8c630 fffff980`0404e0f0 ffffffff`c00000b5 : nt!KeBugCheckEx&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370a10 fffff980`0477bf1f : fffff980`0404e0f0 fffffa80`03c8c630 fffffa80`05da0820 fffffa80`0320b730 : dxgkrnl!TdrBugcheckOnTimeout+0xec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370a50 fffff980`04738c48 : fffff980`ffffe464 00000000`c00000b5 00000000`00000000 fffffa80`0320b730 : dxgkrnl!TdrIsRecoveryRequired+0x1c3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370a90 fffff980`047f5993 : 00000000`00000000 00000000`00000002 00000000`ffffffff 00000000`00000002 : dxgkrnl!VidSchiReportHwHang+0x2f4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370b40 fffff980`047f4591 : fffffa80`0320b730 00000000`00000000 00000000`01ff8f6c 00000000`00000000 : dxgkrnl!VidSchiCheckHwProgress+0x7b&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370b70 fffff980`0473ccd8 : ffffffff`ff676980 00000000`00000000 00000000`00000000 00000000`00000000 : dxgkrnl!VidSchiWaitForSchedulerEvents+0x199&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370bf0 fffff980`047f43b1 : 00000000`00000000 fffffa80`031fe710 00000000`00000080 fffffa80`0320b730 : dxgkrnl!VidSchiScheduleCommandToRun+0x398&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370d10 fffff800`01ae199b : fffffa80`053b4060 fffff800`018388f7 fffff980`0121f900 00000000`00000001 : dxgkrnl!VidSchiWorkerThread+0x95&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370d50 fffff800`01834b86 : fffff980`00c85180 fffffa80`053b4060 fffff980`00c8ec40 fffff980`00a75290 : nt!PspSystemThreadStartup+0x5b&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`05370d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_COMMAND:  .bugcheck ; kb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_IP: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nvlddmkm+60f0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fffff980`0404e0f0 4883ec28        sub     rsp,28h&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_NAME:  nvlddmkm+60f0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MODULE_NAME: nvlddmkm&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IMAGE_NAME:  nvlddmkm.sys&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4578ef88&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAILURE_BUCKET_ID:  X64_0x116_IMAGE_nvlddmkm.sys&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUCKET_ID:  X64_0x116_IMAGE_nvlddmkm.sys&lt;br /&gt;&lt;br /&gt;&lt;hr width="50%"&gt;&lt;br /&gt;0: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;VIDEO_TDR_FAILURE (116)&lt;br /&gt;Attempt to reset the display driver and recover from timeout failed.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: fffffa80034834e0, Optional pointer to internal TDR recovery context (TDR_RECOVERY_CONTEXT).&lt;br /&gt;Arg2: fffff980046d5800, The pointer into responsible device driver module (e.g. owner tag).&lt;br /&gt;Arg3: 0000000000000000, Optional error code (NTSTATUS) of the last failed operation.&lt;br /&gt;Arg4: 0000000000000002, Optional internal context dependent data.&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;FAULTING_IP:&lt;br /&gt;nvlddmkm+8800&lt;br /&gt;fffff980`046d5800 4885c9          test    rcx,rcx&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  GRAPHICS_DRIVER_TDR_FAULT&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0x116&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  System&lt;br /&gt;&lt;br /&gt;CURRENT_IRQL:  0&lt;br /&gt;&lt;br /&gt;STACK_TEXT:&lt;br /&gt;&lt;span style="font-size:78%;"&gt;fffff980`05ef9a08 fffff980`0517c2c4 : 00000000`00000116 fffffa80`034834e0 fffff980`046d5800 00000000`00000000 : nt!KeBugCheckEx&lt;br /&gt;fffff980`05ef9a10 fffff980`0517c0f7 : fffff980`046d5800 fffffa80`034834e0 fffffa80`06252d90 fffffa80`03733730 : dxgkrnl!TdrBugcheckOnTimeout+0xec&lt;br /&gt;fffff980`05ef9a50 fffff980`05137c1b : fffff980`ffffe464 00000000`00000000 00000000`00000000 fffffa80`03733730 : dxgkrnl!TdrIsRecoveryRequired+0x16f&lt;br /&gt;fffff980`05ef9a90 fffff980`051f5f83 : 00000000`00000000 00000000`00000002 00000000`ffffffff 00000000`00000002 : dxgkrnl!VidSchiReportHwHang+0x2f7&lt;br /&gt;fffff980`05ef9b40 fffff980`051f4b85 : fffffa80`03733730 00000000`00000000 00000000`0000f375 00000000`00000000 : dxgkrnl!VidSchiCheckHwProgress+0x7b&lt;br /&gt;fffff980`05ef9b70 fffff980`0513bc90 : ffffffff`ff676980 00000000`00000000 00000000`00000000 00000000`00000000 : dxgkrnl!VidSchiWaitForSchedulerEvents+0x199&lt;br /&gt;fffff980`05ef9bf0 fffff980`051f49a5 : 00000000`00000000 fffffa80`0372d430 00000000`00000080 fffffa80`03733730 : dxgkrnl!VidSchiScheduleCommandToRun+0x398&lt;br /&gt;fffff980`05ef9d10 fffff800`01ee222b : fffffa80`03737a70 fffff800`01c38257 fffff980`014e0900 00000000`00000001 : dxgkrnl!VidSchiWorkerThread+0x95&lt;br /&gt;fffff980`05ef9d50 fffff800`01c344f6 : fffff980`00c4e180 fffffa80`03737a70 fffffa80`0359db60 fffffa80`03733c90 : nt!PspSystemThreadStartup+0x5b&lt;br /&gt;fffff980`05ef9d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  .bugcheck ; kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nvlddmkm+8800&lt;br /&gt;fffff980`046d5800 4885c9          test    rcx,rcx&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nvlddmkm+8800&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nvlddmkm&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  nvlddmkm.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  46c63a34&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  X64_0x116_IMAGE_nvlddmkm.sys&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  X64_0x116_IMAGE_nvlddmkm.sys&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-3300297513045794425?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/3300297513045794425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=3300297513045794425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3300297513045794425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3300297513045794425'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/06/movb-07-drivers-drivers-drivers.html' title='MOVB-07 Drivers, drivers, drivers!'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-544613965302857182</id><published>2007-11-07T04:44:00.000-08:00</published><updated>2007-11-07T05:02:12.856-08:00</updated><title type='text'>BONUS-02 ... and counting</title><content type='html'>After a few monthes of "standard" use, here are my stats:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/160problems.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/160problems.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;On June, 30th 2007 Microsoft &lt;a href="http://www.xbitlabs.com/news/other/display/20070726224717.html"&gt;claims&lt;/a&gt; 60 millions Vista licences. Estimating a (low) average of 100 "problems" per user, it means that Microsoft has a database of at least 6 billions bug reports.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://showusyourwow.msn.com/"&gt;Wow&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-544613965302857182?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/544613965302857182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=544613965302857182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/544613965302857182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/544613965302857182'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/bonus-02-and-counting.html' title='BONUS-02 ... and counting'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-7390808208098276885</id><published>2007-11-06T12:00:00.000-08:00</published><updated>2007-11-06T14:59:05.539-08:00</updated><title type='text'>MOVB-06 Internationalization weirdness</title><content type='html'>When using the English language pack, CACLS.EXE&lt;span style="font-size:100%;"&gt;[*]&lt;/span&gt; command performs as expected.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;[*] This command has been taken as an example, I am pretty sure you could find others.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;When using the French language pack, CACLS.EXE &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;usage()&lt;/span&gt;&lt;/span&gt; output is truncated:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/cacls-level1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/cacls-level1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Everything seems ok in &lt;span style="font-size:85%;"&gt;C:\Windows\System32\fr-FR\CACLS.EXE.MUI&lt;/span&gt; resource file. Since only 3 APIs are called by &lt;span style="font-size:85%;"&gt;usage()&lt;/span&gt;, guessing the one to blame is left as an exercise to the reader:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;FormatMessageW()&lt;/li&gt;&lt;li&gt;WideCharToMultiByte()&lt;/li&gt;&lt;li&gt;fprintf()&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;A revival of the &lt;a href="http://en.wikipedia.org/wiki/Notepad"&gt;NOTEPAD&lt;/a&gt; bug?&lt;br /&gt;&lt;br /&gt;PS. On my home system, here is stranger behavior indeed:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/cacls-level2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/cacls-level2.png" alt="" border="0" /&gt;&lt;/a&gt;Oh my, how could I dare to stop (seemingly) "useless" services?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-7390808208098276885?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/7390808208098276885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=7390808208098276885' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/7390808208098276885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/7390808208098276885'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-06-internationalization-weirdness.html' title='MOVB-06 Internationalization weirdness'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2811805929223523253</id><published>2007-11-05T12:00:00.000-08:00</published><updated>2007-11-05T04:02:12.233-08:00</updated><title type='text'>MOVB-05 Not all Vista applications are IPv6-aware</title><content type='html'>If you have native IPv6 connectivity on your network, Windows Meeting Space will fail to run with the following error:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/ipv6.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/ipv6.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The stack trace is the following (on Vista 64):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   0  Id: 132c.d0c Suspend: 1 Teb: 000007ff`fffdd000 Unfrozen&lt;br /&gt;Child-SP          RetAddr           Call Site&lt;br /&gt;00000000`001db188 00000000`7706ed73 ntdll!NtWaitForMultipleObjects+0xa&lt;br /&gt;00000000`001db190 00000000`76f7e96d kernel32!WaitForMultipleObjectsEx+0x10b&lt;br /&gt;00000000`001db2a0 000007fe`fc551ab6 USER32!RealMsgWaitForMultipleObjectsEx+0x129&lt;br /&gt;00000000`001db340 000007fe`fc55371f DUser!CoreSC::Wait+0x62&lt;br /&gt;00000000`001db390 000007fe`fc553696 DUser!CoreSC::WaitMessage+0x6f&lt;br /&gt;00000000`001db3d0 00000000`76f6bd1a DUser!MphWaitMessageEx+0x36&lt;br /&gt;00000000`001db400 00000000`771c2016 USER32!_ClientWaitMessageExMPH+0x1a&lt;br /&gt;00000000`001db450 00000000`76f7df2a ntdll!KiUserCallbackDispatcherContinue&lt;br /&gt;00000000`001db4b8 00000000`76f673e9 USER32!ZwUserWaitMessage+0xa&lt;br /&gt;00000000`001db4c0 00000000`76f6760a USER32!DialogBox2+0x261&lt;br /&gt;00000000`001db540 00000000`76f674c6 USER32!InternalDialogBox+0x134&lt;br /&gt;00000000`001db5a0 00000000`76f67918 USER32!DialogBoxIndirectParamAorW+0x58&lt;br /&gt;00000000`001db5e0 000007fe`fc34f262 USER32!DialogBoxIndirectParamW+0x18&lt;br /&gt;00000000`001db620 000007fe`fc2930ca COMCTL32!SHFusionDialogBoxIndirectParam+0x56&lt;br /&gt;00000000`001db670 00000000`ffce84ab COMCTL32!CTaskDialog::Show+0x156&lt;br /&gt;00000000`001db6e0 00000000`ffce86de WinCollab!ReportMessageForLH+0x178&lt;br /&gt;00000000`001db7b0 00000000`ffce87a1 WinCollab!ReportMessage+0x1dd&lt;br /&gt;00000000`001ddf70 00000000`ffce887a WinCollab!ReportErrorCommon+0x9f&lt;br /&gt;00000000`001ddfd0 00000000`ffcf43ba WinCollab!ReportError+0x67&lt;br /&gt;00000000`001de000 00000000`ffcf125d WinCollab!CStartMeetingMain::CallCallbackOnGroupConnected+0x11c&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2811805929223523253?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2811805929223523253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2811805929223523253' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2811805929223523253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2811805929223523253'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/06/movb-05-not-all-vista-applications-are.html' title='MOVB-05 Not all Vista applications are IPv6-aware'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-5447862083154431771</id><published>2007-11-04T12:00:00.000-08:00</published><updated>2007-11-04T03:32:06.647-08:00</updated><title type='text'>MOVB-04 BSoD in PCMCIA driver</title><content type='html'>Microsoft cannot be blamed for this one, but I still find it "fun".&lt;br /&gt;&lt;br /&gt;Vista "Gold" has a (known) integer overflow in Texas Instruments Cardbus driver. It means that PCMCIA is not useable under Vista on our official, corporate laptop (HP &lt;a href="http://h20000.www2.hp.com/bizsupport/TechSupport/DriverDownload.jsp?prodNameId=447355&amp;amp;lang=en&amp;amp;cc=us&amp;amp;taskId=135&amp;amp;prodTypeId=321957&amp;amp;prodSeriesId=447354"&gt;nc4200&lt;/a&gt;) - FYI, we bought a few thousands of this one.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;object height="335" width="425"&gt;&lt;param name="movie" value="http://www.dailymotion.com/swf/5e03qjlzAqOe0gw8H"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.dailymotion.com/swf/5e03qjlzAqOe0gw8H" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="335" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;Video: &lt;b&gt;&lt;a href="http://www.dailymotion.com/video/x2cdnf_je-me-revele-avec-vista_fun"&gt;Unleashing Vista&lt;/a&gt;&lt;/b&gt;&lt;i&gt;&lt;a href="http://www.dailymotion.com/nikoleim"&gt;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-5447862083154431771?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/5447862083154431771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=5447862083154431771' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5447862083154431771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5447862083154431771'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-04-bsod-in-pcmcia-driver.html' title='MOVB-04 BSoD in PCMCIA driver'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-3913786614040221865</id><published>2007-11-03T12:03:00.000-07:00</published><updated>2007-11-03T12:09:25.285-07:00</updated><title type='text'>BONUS-01 Who's to blame?</title><content type='html'>Sorry for being late today, here is a small bonus.&lt;br /&gt;(This has not been edited - this is a real screenshot)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://newsoft.dyndns.org/movb/vista.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/vista.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-3913786614040221865?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/3913786614040221865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=3913786614040221865' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3913786614040221865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/3913786614040221865'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/bonus-01-whos-to-blame.html' title='BONUS-01 Who&apos;s to blame?'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-5260700109138587893</id><published>2007-11-03T12:00:00.000-07:00</published><updated>2007-11-07T05:38:21.948-08:00</updated><title type='text'>MOVB-03 BSoD in WIN32K.SYS</title><content type='html'>What about this nice one ?&lt;br /&gt;Userland context is WerFault.exe&lt;br /&gt;(WER = Windows Error Reporting)&lt;br /&gt;&lt;br /&gt;PS. I promise, there won't be only BSoD during MOVB ;)&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Bugcheck Analysis&lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;*******************************************************************************&lt;/span&gt;  &lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;This is a very common bugcheck.  Usually the exception address pinpoints&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;the driver/function that caused the problem.  Always note this address&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;as well as the link date of the driver/image that contains this address.&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Some common problems are exception code 0x80000003.  This means a hard&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;coded breakpoint or assertion was hit, but this system was booted&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;/NODEBUG.  This is not supposed to happen as developers should never have&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;hardcoded breakpoints in retail code, but ...&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;If this happens, make sure a debugger gets connected, and the&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;system is booted /DEBUG.  This will let us see why this breakpoint is&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;happening.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arguments:&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg1: c0000005, The exception code that was not handled&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg2: 8c2c5881, The address that the exception occurred at&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg3: b30b3c04, Trap Frame&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg4: 00000000&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Debugging Details:&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;------------------&lt;/span&gt;&lt;span style="font-size:85%;"&gt;  &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;EXCEPTION_CODE: (NTSTATUS) 0xc0000005&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FAULTING_IP: &lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;win32k+c5881&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;8c2c5881 8b402c          mov     eax,dword ptr [eax+2Ch]&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;TRAP_FRAME:  b30b3c04 -- (.trap 0xffffffffb30b3c04)&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;ErrCode = 00000000&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;eax=00000000 ebx=000000c0 ecx=ffa6e8e0 edx=00000000 esi=00000000 edi=00000000&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;eip=8c2c5881 esp=b30b3c78 ebp=b30b3c88 iopl=0         nv up ei pl nz na po nc&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010202&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;win32k+0xc5881:&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;8c2c5881 8b402c          mov     eax,dword ptr [eax+2Ch] ds:0023:0000002c=????????&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;Resetting default scope&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CUSTOMER_CRASH_COUNT:  1&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;BUGCHECK_STR:  0x8E&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;PROCESS_NAME:  WerFault.exe&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CURRENT_IRQL:  0&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;LAST_CONTROL_TRANSFER:  from 8c2cdf9c to 8c2c5881&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;STACK_TEXT:&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;b30b3c88 8c2cdf9c 00000000 00000000 00000010 win32k!HMAllocObject+0x27&lt;br /&gt;b30b3cac 8c2b4fd6 00000000 00000000 000088b8 win32k!InternalSetTimer+0x86&lt;br /&gt;b30b3cc8 8c2a68a2 00000000 000088b8 8c286d62 win32k!SetRITTimer+0x22&lt;br /&gt;b30b3ce0 8c2bc1fe ffabce50 ffabce50 ffabce50 win32k!SetAppStarting+0x3d&lt;br /&gt;b30b3d00 8c2bc00e 00000000 ffabce50 8445d410 win32k!xxxInitProcessInfo+0xaa&lt;br /&gt;b30b3d24 8c2bbfa7 ffabce50 00000001 8445d410 win32k!xxxUserProcessCallout+0x1f&lt;br /&gt;b30b3d40 81e19337 83851438 00000001 81d31b10 win32k!W32pProcessCallout+0x43&lt;br /&gt;b30b3d4c 81d31b10 8445d410 81c8c62e 000010e4 nt!PsConvertToGuiThread+0x47&lt;br /&gt;b30b3d64 77640f34 badb0d00 0019ee54 00000000 nt!KeServiceDescriptorTable+0x10&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;b30b3d68 badb0d00 0019ee54 00000000 00000000 0x77640f34&lt;br /&gt;b30b3d6c 0019ee54 00000000 00000000 00000000 0xbadb0d00&lt;br /&gt;b30b3d70 00000000 00000000 00000000 00000000 0x19ee54&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;STACK_COMMAND:  kb&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FOLLOWUP_IP: &lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;win32k+c5881&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;8c2c5881 8b402c          mov     eax,dword ptr [eax+2Ch]&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;SYMBOL_STACK_INDEX:  0&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;MODULE_NAME: win32k&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;IMAGE_NAME:  win32k.sys&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;DEBUG_FLR_IMAGE_TIMESTAMP:  45d3cc1d&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;SYMBOL_NAME:  win32k+c5881&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FAILURE_BUCKET_ID:  0x8E_win32k+c5881&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;BUCKET_ID:  0x8E_win32k+c5881&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-5260700109138587893?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/5260700109138587893/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=5260700109138587893' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5260700109138587893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5260700109138587893'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-03-bsod-in-win32ksys.html' title='MOVB-03 BSoD in WIN32K.SYS'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2574809449918709586</id><published>2007-11-02T12:00:00.000-07:00</published><updated>2007-11-02T02:56:33.773-07:00</updated><title type='text'>MOVB-02 Another BSoD in NTFS.SYS</title><content type='html'>Yet another bug in NTFS.SYS driver (same platform, same configuration).&lt;br /&gt;&lt;br /&gt;This one has been triggered in background by the defragmentation process (DfrgNtfs.exe).&lt;br /&gt;&lt;br /&gt;PS. Don't worry, I am not going to publish crashdumps during one full month. Funny bugs are coming out. Stay tuned!&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Bugcheck Analysis &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;*******************************************************************************&lt;/span&gt;  &lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;NTFS_FILE_SYSTEM (24)&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;If you see NtfsExceptionFilter on the stack then the 2nd and 3rd&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;    parameters are the exception record and context record. Do a .cxr&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;    on the 3rd parameter and then kb to obtain a more informative stack&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;    trace.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arguments:&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg1: 001904ab&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg2: a2a468e0&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg3: a2a465dc&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Arg4: 8519b53b&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Debugging Details:&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;EXCEPTION_RECORD:  a2a468e0 -- (.exr 0xffffffffa2a468e0)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;ExceptionAddress: 8519b53b (Ntfs!NtfsCreateScb+0x0000004c)&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;ExceptionCode: c0000005 (Access violation)&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;ExceptionFlags: 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NumberParameters: 2&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;Parameter[0]: 00000000&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;Parameter[1]: 30000010&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Attempt to read from address 30000010&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CONTEXT:  a2a465dc -- (.cxr 0xffffffffa2a465dc)&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;eax=30000000 ebx=c5ef080d ecx=c5ef0855 edx=00000000 esi=c5efd008 edi=00000000&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;eip=8519b53b esp=a2a469a8 ebp=a2a46a08 iopl=0         nv up ei pl nz na pe nc&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010206&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Ntfs!NtfsCreateScb+0x4c:&lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;8519b53b f6401006        test    byte ptr [eax+10h],6 ds:0023:30000010=??&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Resetting default scope&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CUSTOMER_CRASH_COUNT:  1&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;PROCESS_NAME:  DfrgNtfs.exe&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CURRENT_IRQL:  1&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;ERROR_CODE: (NTSTATUS) 0xc0000005&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;READ_ADDRESS: GetPointerFromAddress: unable to read from 81d315ac&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Unable to read MiSystemVaType memory at 81d11780&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt; 30000010&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;BUGCHECK_STR:  0x24&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;LAST_CONTROL_TRANSFER:  from 851a64b8 to 8519b53b&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;br /&gt;STACK_TEXT:&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46a08 851a64b8 84911400 c5efd008 00000080 Ntfs!NtfsCreateScb+0x4c&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46a40 851a5b15 84911400 84653520 846536d4 Ntfs!NtfsBreakBatchOplock+0x7e&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46a74 851a3cee 84911400 84653520 00000000 Ntfs!NtfsOpenExistingAttr+0x6a&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46b5c 8518554e 84911400 84653520 00000000 Ntfs!NtfsOpenAttributeInExistingFile+0x79b&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46c10 8519c637 84911400 84653520 00000000 Ntfs!NtfsOpenFcbById+0x590&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46cec 851126b6 84911400 84653520 aa7b3964 Ntfs!NtfsCommonCreate+0x601&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46d2c 81c80278 aa7b38fc 00000000 ffffffff Ntfs!NtfsCommonCreateCallout+0x20&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;a2a46d2c 81c80371 aa7b38fc 00000000 ffffffff nt!KiSwapKernelStackAndExit+0x118&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;span style="font-size:78%;"&gt;aa7b3894 00000000 00000000 00000000 00000000 nt!KiSwitchKernelStackAndCallout+0x31&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FOLLOWUP_IP: &lt;/span&gt; &lt;span style=";font-family:courier new;font-size:85%;"  &gt;Ntfs!NtfsCreateScb+4c&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;8519b53b f6401006        test    byte ptr [eax+10h],6&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;SYMBOL_STACK_INDEX:  0&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;SYMBOL_NAME:  Ntfs!NtfsCreateScb+4c&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;MODULE_NAME: Ntfs&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;IMAGE_NAME:  Ntfs.sys&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4549aceb&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;STACK_COMMAND:  .cxr 0xffffffffa2a465dc ; kb&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;FAILURE_BUCKET_ID:  0x24_Ntfs!NtfsCreateScb+4c&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;BUCKET_ID:  0x24_Ntfs!NtfsCreateScb+4c&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2574809449918709586?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2574809449918709586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2574809449918709586' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2574809449918709586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2574809449918709586'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-02-another-bsod-in-ntfssys.html' title='MOVB-02 Another BSoD in NTFS.SYS'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-955217901025848294</id><published>2007-11-01T02:29:00.000-07:00</published><updated>2007-11-01T02:30:27.385-07:00</updated><title type='text'>MOVB-01 BSoD in NTFS.SYS</title><content type='html'>&lt;span style="font-size:100%;"&gt;So, this is day one of MOVB.&lt;br /&gt;&lt;br /&gt;Contrary to other Monthes of Bugs, this one will not focus on "security" bugs (do not expect 30 remotely anonymously exploitable bugs ;). My favoraite bugs are "stupid" bugs/features, or blatant QA failures.&lt;br /&gt;&lt;br /&gt;First BSOD was caught on a fresh install of Vista32 Ultimate, running on Intel Core Duo processor. Faulting driver was NTFS.SYS - luckily I did not loose any data.&lt;br /&gt;&lt;br /&gt;It might be time to get your &lt;a href="http://projects.info-pull.com/mokb/"&gt;NTFS fuzzers&lt;/a&gt; back on track ;)&lt;br /&gt;&lt;br /&gt;PS. Bug has been reported to Microsoft using built-in WER.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PPS. I am willing to answer questions. However, I cannot forward the full memory dump: it holds personal information.&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;1: kd&gt; !analyze -v *******************************************************************************&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Bugcheck Analysis&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;*******************************************************************************&lt;/span&gt;  &lt;span style="font-family:courier new;"&gt;NTFS_FILE_SYSTEM (24)&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;If you see NtfsExceptionFilter on the stack then the 2nd and 3rd&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;    parameters are the exception record and context record. Do a .cxr&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;    on the 3rd parameter and then kb to obtain a more informative stack&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;    trace.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arguments:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg1: 001904ab&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg2: 85ac09e4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Arg3: 85ac06e0&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Arg4: 81c5e86c&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Debugging Details&lt;br /&gt;&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EXCEPTION_RECORD:  85ac09e4 -- (.exr 0xffffffff85ac09e4)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ExceptionAddress: 81c5e86c (nt!RtlSubtreePredecessor+0x00000015)&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;ExceptionCode: c0000005 (Access violation)&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;ExceptionFlags: 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;NumberParameters: 2&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Parameter[0]: 00000000&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Parameter[1]: 3f3f3f47&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Attempt to read from address 3f3f3f47&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;CONTEXT:  85ac06e0 -- (.cxr 0xffffffff85ac06e0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;eax=3f3f3f3f ebx=00000000 ecx=3f3f3f3f edx=00000000 esi=a6e36ca8 edi=00010000&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;eip=81c5e86c esp=85ac0aac ebp=85ac0aac iopl=0         nv up ei pl nz na pe nc&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010206&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;nt!RtlSubtreePredecessor+0x15:&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;81c5e86c 8b4808          mov     ecx,dword ptr [eax+8] ds:0023:3f3f3f47=????????&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Resetting default scope&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CUSTOMER_CRASH_COUNT:  1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PROCESS_NAME:  System&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;CURRENT_IRQL:  0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ERROR_CODE: (NTSTATUS) 0xc0000005&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;READ_ADDRESS: GetPointerFromAddress: unable to read from 81d315ac&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Unable to read MiSystemVaType memory at 81d11780&lt;/span&gt; &lt;span style="font-family:courier new;"&gt; 3f3f3f47 &lt;/span&gt;  &lt;span style="font-family:courier new;"&gt;BUGCHECK_STR:  0x24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LAST_CONTROL_TRANSFER:  from 81c5e7c7 to 81c5e86c&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;STACK_TEXT:&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0aac 81c5e7c7 a6e36ca8 8a265cfc a6e36ca8 nt!RtlSubtreePredecessor+0x15&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0ac4 806629e1 a6e36ca8 00010000 a6e36ca8 nt!RtlDeleteNoSplay+0x20&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0ad8 80662cbe a6e36ca8 8a265cec 8487e2f8 fltmgr!TreeUnlinkNoBalance+0x13&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0af0 80674fb6 8a265cfc ffffffff ffffffff fltmgr!TreeUnlinkMulti+0x22&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0b10 8067509f 8a265cb8 00008000 ffffffff fltmgr!DeleteNameCacheNodes+0x84&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0b2c 806783d1 8487e008 8a265cb8 8a265cf8 fltmgr!FltpFreeNameCacheList+0x17&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0b48 806785d6 8a265cb8 8a265cbc ac3e1d08 fltmgr!CleanupStreamListCtrl+0x37&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0b5c 81d7cd18 8a265cbc 85acb0d4 81ce7b69 fltmgr!DeleteStreamListCtrlCallback+0x5a&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0b94 8517cd79 ac3e1d08 00000000 ac3e1d08 nt!FsRtlTeardownPerStreamContexts+0xd4&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0bb0 8518f1ad 00000705 ac3e1c18 ac3e1c40 Ntfs!NtfsDeleteScb+0x1f2&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0bc8 85109c9b 83bbec90 ac3e1d08 00000000 Ntfs!NtfsRemoveScb+0xc2&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0be4 8519bed4 83bbec90 ac3e1c18 00000000 Ntfs!NtfsPrepareFcbForRemoval+0x59&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0c28 851113be 83bbec90 ac3e1d08 00000000 Ntfs!NtfsTeardownStructures+0x62&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0c50 85197fe1 83bbec90 ac3e1d08 00000000 Ntfs!NtfsDecrementCloseCounts+0xad&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0cb0 8517d126 83bbec90 ac3e1d08 ac3e1c18 Ntfs!NtfsCommonClose+0x4d9&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0d44 81c78e18 00000000 00000000 82f64828 Ntfs!NtfsFspClose+0x117&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0d7c 81e254a8 00000000 85acb680 00000000 nt!ExpWorkerThread+0xfd&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;85ac0dc0 81c9145e 81c78d1b 00000000 00000000 nt!PspSystemThreadStartup+0x9d&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"&gt;00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_IP: &lt;/span&gt; &lt;span style="font-family:courier new;"&gt;Ntfs!NtfsDeleteScb+1f2&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;8517cd79 8b06            mov     eax,dword ptr [esi]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_STACK_INDEX:  9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SYMBOL_NAME:  Ntfs!NtfsDeleteScb+1f2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FOLLOWUP_NAME:  MachineOwner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MODULE_NAME: Ntfs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IMAGE_NAME:  Ntfs.sys&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4549aceb&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;STACK_COMMAND:  .cxr 0xffffffff85ac06e0 ; kb&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FAILURE_BUCKET_ID:  0x24_Ntfs!NtfsDeleteScb+1f2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BUCKET_ID:  0x24_Ntfs!NtfsDeleteScb+1f2&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-955217901025848294?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/955217901025848294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=955217901025848294' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/955217901025848294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/955217901025848294'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/11/movb-01-bsod-in-ntfssys.html' title='MOVB-01 BSoD in NTFS.SYS'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-5723107228760475019</id><published>2007-10-27T12:55:00.000-07:00</published><updated>2007-10-27T13:08:50.077-07:00</updated><title type='text'>MOVB démarre le 1er novembre</title><content type='html'>Il parait que novembre est un bon mois ...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.lemoisdetouslesexploits.com/"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://newsoft.dyndns.org/movb/exploit.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Alors rendez-vous le 1er novembre pour découvrir "&lt;a href="http://www.microsoft.com/windows/products/windowsvista/100reasons.mspx"&gt;30 reasons you'll be speechless&lt;/a&gt;".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-5723107228760475019?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/5723107228760475019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=5723107228760475019' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5723107228760475019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/5723107228760475019'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/10/movb-dmarre-le-1er-novembre.html' title='MOVB démarre le 1er novembre'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8410376900868672224.post-2947272007721095473</id><published>2007-03-10T01:04:00.000-08:00</published><updated>2007-03-10T01:09:33.258-08:00</updated><title type='text'>Bienvenue sur MOVB !</title><content type='html'>Comme son nom ne l'indique pas, le but de ce projet n'est pas de publier un bug par jour pendant un mois - ce serait trop lourd pour un homme seul, père de famille qui plus est :)&lt;br /&gt;&lt;br /&gt;Ayant commencé depuis quelques temps à utiliser Vista 32 bits Ultimate et Vista 64 bits Ultimate, il me semblait important de garder trace de tous les bugs que je rencontre chaque jour ... ou que je lis ailleurs sur Internet.&lt;br /&gt;&lt;br /&gt;Surtout n'hésitez pas à contribuer, de manière anonyme ou avec les &lt;span style="font-style: italic;"&gt;full credits&lt;/span&gt; !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8410376900868672224-2947272007721095473?l=movb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://movb.blogspot.com/feeds/2947272007721095473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8410376900868672224&amp;postID=2947272007721095473' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2947272007721095473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8410376900868672224/posts/default/2947272007721095473'/><link rel='alternate' type='text/html' href='http://movb.blogspot.com/2007/03/bienvenue-sur-movb.html' title='Bienvenue sur MOVB !'/><author><name>newsoft</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://newsoft.dyndns.org/blog.jpg'/></author><thr:total>1</thr:total></entry></feed>
