вот дамп:


Компьютер был перезагружен после критической ошибки. Код ошибки: 0x00000050 (0xffffffe8, 0x00000001, 0x828bdcfe, 0x00000000). Дамп памяти сохранен в: C:\Windows\MEMORY.DMP. Код отчета: 052512-20264-01.





C:\>kdfe.cmd MEMORY.DMP -v


Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: srv*C:\symbols*http://msdl.microsoft.com/download/symbols

Executable search path is: srv*C:\symbols*http://msdl.microsoft.com/download/sym
bols
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17790.x86fre.win7sp1_gdr.120305-1505
Machine Name:
Kernel base = 0x82845000 PsLoadedModuleList = 0x8298e4d0
Debug session time: Fri May 25 17:51:33.068 2012 (GMT+4)
System Uptime: 0 days 0:00:16.957
Loading Kernel Symbols
.................................................. .............
.................................................. ...........
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffde00c). Type ".hh dbgerr001" for details
Loading unloaded module list
....
0: kd> kd: Reading initial command '!analyze -v; q'
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffffe8, memory referenced.
Arg2: 00000001, value 0 = read operation, 1 = write operation.
Arg3: 828bdcfe, If non-zero, the instruction address which referenced the bad memory address.
Arg4: 00000000, (reserved)

Debugging Details:
------------------

Page 1dd44 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 7ffde00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffde00c). Type ".hh dbgerr001" for details

WRITE_ADDRESS: ffffffe8

FAULTING_IP:
nt!ObfDereferenceObjectWithTag+27
828bdcfe f00fc118 lock xadd dword ptr [eax],ebx

MM_INTERNAL_CODE: 0

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: winlogon.exe

CURRENT_IRQL: 0

TRAP_FRAME: 8c2f57d4 -- (.trap 0xffffffff8c2f57d4)
ErrCode = 00000002
eax=ffffffe8 ebx=ffffffff ecx=00000000 edx=746c6644 esi=ffffffe8 edi=00000000
eip=828bdcfe esp=8c2f5848 ebp=8c2f58ec iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
nt!ObfDereferenceObjectWithTag+0x27:
828bdcfe f00fc118 lock xadd dword ptr [eax],ebx ds:0023:ffffffe8=ИИИИ

Resetting default scope

LAST_CONTROL_TRANSFER: from 828863f8 to 828d340f

STACK_TEXT:
8c2f57bc 828863f8 00000001 ffffffe8 00000000 nt!MmAccessFault+0x106
8c2f57bc 828bdcfe 00000001 ffffffe8 00000000 nt!KiTrap0E+0xdc
8c2f5850 828bdcd0 00000000 955dc124 195bef91 nt!ObfDereferenceObjectWithTag+0x27

8c2f5858 955dc124 195bef91 00000000 00130018 nt!ObfDereferenceObject+0xd
8c2f58ec 9561ca29 863323c8 000000b4 00000000 win32k!xxxCreateDesktopEx+0x51b
8c2f5c00 956135cd ffffffff 8c2f5c98 8c2f5cb0 win32k!xxxResolveDesktop+0x921
8c2f5cdc 9560bf5e 00000000 86332030 0000114e win32k!xxxCreateThreadInfo+0x4e2
8c2f5cf4 9560c085 86332030 00000000 0000114e win32k!UserThreadCallout+0x9d
8c2f5d10 82abcffe 86332030 00000000 829aeb10 win32k!W32pThreadCallout+0x3a
8c2f5d24 82882ece 0000114e 0011fbc8 0011fc08 nt!PsConvertToGuiThread+0x5e
8c2f5d34 76ea7094 badb0d00 0011fbc8 00000000 nt!KiBBTUnexpectedRange+0xc
WARNING: Frame IP not in any known module. Following frames may be wrong.
8c2f5d38 badb0d00 0011fbc8 00000000 00000000 0x76ea7094
8c2f5d3c 0011fbc8 00000000 00000000 00000000 0xbadb0d00
8c2f5d40 00000000 00000000 00000000 00000000 0x11fbc8


STACK_COMMAND: kb

FOLLOWUP_IP:
win32k!xxxCreateDesktopEx+51b
955dc124 897e1c mov dword ptr [esi+1Ch],edi

SYMBOL_STACK_INDEX: 4

SYMBOL_NAME: win32k!xxxCreateDesktopEx+51b

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: win32k

IMAGE_NAME: win32k.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4f2b5a5e

FAILURE_BUCKET_ID: 0x50_win32k!xxxCreateDesktopEx+51b

BUCKET_ID: 0x50_win32k!xxxCreateDesktopEx+51b

Followup: MachineOwner
---------

quit:
Для продолжения нажмите любую клавишу . . .

C:\>


развернул новую систему, к сети подключена небыла, поставил касперского и дала такой результат.............. причина была в нем, больше грешит не на что.