Hi,
112216-46437-01.dmp
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000096, Exception code that caused the bugcheck
Arg2: fffff80319b6789e, Address of the instruction which caused the bugcheck
Arg3: ffffab8117e31d00, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
privileged escalation
Mem problem
pretty rare this failure
FAULTING_IP:
nt!SwapContext+2be
fffff803`19b6789e 0f30 wrmsr
112216-40937-01.dmp
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Arguments:
Arg1: 8000c148c4b88bbc, Actual security check cookie from the stack
Arg2: 0000c148c4b88bbc, Expected security check cookie
Arg3: ffff3eb73b477443, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
BUGCHECK_STR: 0xF7_ONE_BIT
a nice one too
112216-32390-01.dmp
Probably caused by :
memory_corruption
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff8010bebdd7d - nt!MiDeleteSystemPagableVm+5fd
[ f6:fd ]
fffff8010bebdd98 - nt!MiDeleteSystemPagableVm+618 (+0x1b)
[ f6:fd ]
fffff8010bebe331 - nt!MiDeleteValidSystemPage+251 (+0x599)
[ f6:fd ]
fffff8010bebe34d-fffff8010bebe34e 2 bytes - nt!MiDeleteValidSystemPage+26d (+0x1c)
[ 80 fa:00 eb ]
fffff8010beec602-fffff8010beec604 3 bytes - nt!MiPfnShareCountIsZero+192 (+0x2e2b5)
[ 40 fb f6:c0 fe fd ]
fffff8010beec627 - nt!MiPfnShareCountIsZero+1b7 (+0x25)
[ f6:fd ]
fffff8010beec646-fffff8010beec647 2 bytes - nt!MiPfnShareCountIsZero+1d6 (+0x1f)
[ a0 7d:60 ff ]
fffff8010bf17e6d-fffff8010bf17e6e 2 bytes - nt!MiPurgeZeroList+6d (+0x2b827)
[ 80 fa:00 eb ]
fffff8010c056387-fffff8010c056389 3 bytes - nt!ExFreePoolWithTag+387
[ 40 fb f6:c0 fe fd ]
16 errors : !nt (fffff8010bebdd7d-fffff8010c056389)
.
so a memory test is a good option, checking the harddisk as well.
Memtest86+ - Advanced Memory Diagnostic Tool