It looks like wininit.exe or csrss.exe is crashing, so the machine blue screens?
It said VISTA_DRIVER_FAULT but I didn’t see it fingering any particular driver.
Crash #1:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Chris\Downloads\tmp5\MEMORY-lastweek.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: srv*c:\users\chris\downloads\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17944.amd64fre.win7sp1_gdr.120830-0333
Machine Name:
Kernel base = 0xfffff80002e5c000 PsLoadedModuleList = 0xfffff800
030a0670
Debug session time: Fri Oct 19 09:57:43.224 2012 (UTC - 5:00)
System Uptime: 2 days 14:11:46.036
Loading Kernel Symbols
…
…
…
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffd8018). Type “.hh dbgerr001” for details
Loading unloaded module list
…
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa800eabdb30, fffffa800eabde10, fffff800031da460}
Probably caused by : wininit.exe
Followup: MachineOwner
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa800eabdb30, Terminating object
Arg3: fffffa800eabde10, Process image file name
Arg4: fffff800031da460, Explanatory message (ascii)
Debugging Details:
PROCESS_OBJECT: fffffa800eabdb30
IMAGE_NAME: wininit.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: wininit
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: wininit.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
BUGCHECK_STR: 0xF4_IOERR
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
fffff8800904d9c8 fffff800
03262822 : 00000000000000f4 00000000
00000003 fffffa800eabdb30 fffffa80
0eabde10 : nt!KeBugCheckEx
fffff8800904d9d0 fffff800
0320ee0b : ffffffffffffffff fffffa80
0ea91060 fffffa800eabdb30 fffffa80
0eabdb30 : nt!PspCatchCriticalBreak+0x92
fffff8800904da10 fffff800
0318df04 : ffffffffffffffff 00000000
00000001 fffffa800eabdb30 0000007f
00000008 : nt! ?? ::NNGAKEGL::string'+0x176e6 fffff880
0904da60 fffff80002eda253 : fffffa80
0eabdb30 00000000c0000006 fffffa80
0ea91060 0000000000000026 : nt!NtTerminateProcess+0xf4 fffff880
0904dae0 0000000077c215da : 00000000
00000000 0000000000000000 00000000
00000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x13 00000000
00def968 0000000000000000 : 00000000
00000000 0000000000000000 00000000
00000000 00000000`00000000 : 0x77c215da
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_IOERR_IMAGE_wininit.exe
BUCKET_ID: X64_0xF4_IOERR_IMAGE_wininit.exe
Followup: MachineOwner
Crash #2:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Chris\Downloads\tmp5\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: srv*c:\users\chris\downloads\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17944.amd64fre.win7sp1_gdr.120830-0333
Machine Name:
Kernel base = 0xfffff80002e63000 PsLoadedModuleList = 0xfffff800
030a7670
Debug session time: Mon Oct 22 09:57:19.383 2012 (UTC - 5:00)
System Uptime: 2 days 23:59:17.195
Loading Kernel Symbols
…
…
…
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffdb018). Type “.hh dbgerr001” for details
Loading unloaded module list
…
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa800fd2b150, fffffa800fd2b430, fffff800031e1460}
Probably caused by : csrss.exe
Followup: MachineOwner
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa800fd2b150, Terminating object
Arg3: fffffa800fd2b430, Process image file name
Arg4: fffff800031e1460, Explanatory message (ascii)
Debugging Details:
PROCESS_OBJECT: fffffa800fd2b150
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000006 - The instruction at 0x%p referenced memory at 0x%p. The required data was not placed into memory because of an I/O error status of 0x%x.
BUGCHECK_STR: 0xF4_IOERR
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
fffff8800a5e3e38 fffff800
03269822 : 00000000000000f4 00000000
00000003 fffffa800fd2b150 fffffa80
0fd2b430 : nt!KeBugCheckEx
fffff8800a5e3e40 fffff800
03215e0b : ffffffffffffffff fffffa80
0fc5a060 fffffa800fd2b150 fffffa80
0fd2b150 : nt!PspCatchCriticalBreak+0x92
fffff8800a5e3e80 fffff800
03194f04 : ffffffffffffffff 00000000
00000001 fffffa800fd2b150 00000000
00000008 : nt! ?? ::NNGAKEGL::string'+0x176e6 fffff880
0a5e3ed0 fffff80002ee1253 : fffffa80
0fd2b150 fffff800c0000006 fffffa80
0fc5a060 00000000009a0dc0 : nt!NtTerminateProcess+0xf4 fffff880
0a5e3f50 fffff80002edd810 : fffff800
02f2cb7f fffff8800a5e4a38 fffff880
0a5e4790 fffff8800a5e4ae0 : nt!KiSystemServiceCopyEnd+0x13 fffff880
0a5e40e8 fffff80002f2cb7f : fffff880
0a5e4a38 fffff8800a5e4790 fffff880
0a5e4ae0 0000000077425a44 : nt!KiServiceLinkage fffff880
0a5e40f0 fffff80002ee1642 : fffff880
0a5e4a38 00000000009e0000 fffff880
0a5e4ae0 0000000077431670 : nt! ?? ::FNODOBFM::
string’+0x488a4
fffff8800a5e4900 fffff800
02ee01ba : 0000000000000000 00000000
77425a47 fffffa800fd2b101 00000000
009e0000 : nt!KiExceptionDispatch+0xc2
fffff8800a5e4ae0 00000000
777c8f36 : 0000000000000000 00000000
00000000 0000000000000000 00000000
00000000 : nt!KiPageFault+0x23a
00000000009a14e0 00000000
00000000 : 0000000000000000 00000000
00000000 0000000000000000 00000000
00000000 : 0x777c8f36
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_IOERR_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_IOERR_IMAGE_csrss.exe