Microsoft (R) Windows Debugger Version 6.11.0001.404 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini032413-02.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: http://msdl.microsoft.com/download/symbols Executable search path is: Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 2600.xpsp_sp3_gdr.130107-0416 Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b2c0 Debug session time: Sun Mar 24 12:43:59.984 2013 (GMT+1) System Uptime: 0 days 0:07:50.584 Loading Kernel Symbols ............................................................... ............................................. Loading User Symbols Loading unloaded module list ........... ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck C000021A, {e1e43e88, c0000005, 0, 0} unable to get nt!KiCurrentEtwBufferOffset unable to get nt!KiCurrentEtwBufferBase Probably caused by : ntoskrnl.exe ( nt!KiFastCallEntry+f8 ) Followup: MachineOwner --------- kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* WINLOGON_FATAL_ERROR (c000021a) The Winlogon process terminated unexpectedly. Arguments: Arg1: e1e43e88, String that identifies the problem. Arg2: c0000005, Error Code. Arg3: 00000000 Arg4: 00000000 Debugging Details: ------------------ unable to get nt!KiCurrentEtwBufferOffset unable to get nt!KiCurrentEtwBufferBase ERROR_CODE: (NTSTATUS) 0xc000021a - {Z va EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Z va EXCEPTION_PARAMETER1: e1e43e88 EXCEPTION_PARAMETER2: c0000005 EXCEPTION_PARAMETER3: 00000000 EXCEPTION_PARAMETER4: 0 ADDITIONAL_DEBUG_TEXT: Windows Logon Process BUGCHECK_STR: 0xc000021a_c0000005 CUSTOMER_CRASH_COUNT: 2 DEFAULT_BUCKET_ID: DRIVER_FAULT PROCESS_NAME: smss.exe LAST_CONTROL_TRANSFER: from 8062b66b to 805338ce STACK_TEXT: ba7bf934 8062b66b 0000004c c000021a ba7bf9b0 nt!KeBugCheckEx+0x1b ba7bf970 8066caa1 00000001 0000004c c000021a nt!PoShutdownBugCheck+0x5c ba7bfb28 80648cc6 c000021a 00000004 00000001 nt!ExpSystemErrorHandler+0x511 ba7bfcd4 8064910d c000021a 00000004 00000001 nt!ExpRaiseHardError+0x9a ba7bfd44 804de7ec c000021a 00000004 00000001 nt!NtRaiseHardError+0x16b ba7bfd44 7c90e514 c000021a 00000004 00000001 nt!KiFastCallEntry+0xf8 WARNING: Frame IP not in any known module. Following frames may be wrong. 0015ff1c 00000000 00000000 00000000 00000000 0x7c90e514 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiFastCallEntry+f8 804de7ec 8be5 mov esp,ebp SYMBOL_STACK_INDEX: 5 SYMBOL_NAME: nt!KiFastCallEntry+f8 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntoskrnl.exe DEBUG_FLR_IMAGE_TIMESTAMP: 50ea21c6 FAILURE_BUCKET_ID: 0xc000021a_c0000005_nt!KiFastCallEntry+f8 BUCKET_ID: 0xc000021a_c0000005_nt!KiFastCallEntry+f8 Followup: MachineOwner ---------