Here is what I got from Windbg.exe for both crashs.. I couldn't quite follow how to get the data from using minicrash_stackwalk (but I can try that today if this isn't sufficient)
(Below are both Exception analysis's each followed by the Callstacks.)
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
FAULTING_IP:
nw+bbd7b4
01bed7b4 8a1a mov bl,byte ptr [edx]
EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 01bed7b4 (nw+0x00bbd7b4)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 2b52de47
Attempt to read from address 2b52de47
CONTEXT: 00000000 -- (.cxr 0x0;r)
eax=00000000 ebx=00000000 ecx=0044ecfc edx=2b52de47 esi=00000118 edi=00000000
eip=779df8d1 esp=0044e590 ebp=0044e5fc iopl=0 nv up ei pl zr na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00200246
ntdll!ZwWaitForSingleObject+0x15:
779df8d1 83c404 add esp,4
DEFAULT_BUCKET_ID: INVALID_POINTER_READ
PROCESS_NAME: nw.exe
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 2b52de47
READ_ADDRESS: 2b52de47
FOLLOWUP_IP:
nw+bbd7b4
01bed7b4 8a1a mov bl,byte ptr [edx]
NTGLOBALFLAG: 0
APP: nw.exe
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) x86fre
FAULTING_THREAD: 0000066c
PRIMARY_PROBLEM_CLASS: INVALID_POINTER_READ
BUGCHECK_STR: APPLICATION_FAULT_INVALID_POINTER_READ
LAST_CONTROL_TRANSFER: from 01ae394f to 01bed7b4
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
0044ece4 01ae394f 0f4c64a1 000031ff 0f406380 nw+0xbbd7b4
0044ed3c 01ae4ef7 0044ee60 0f406380 0f4c64a0 nw+0xab394f
0044ed50 01bca5fe 00000082 00000320 0044ee60 nw+0xab4ef7
0044edf8 01bcd538 00467c40 004aba74 004aba50 nw+0xb9a5fe
0044ee80 01bcdbca 004f7e80 0046c638 0044ef2c nw+0xb9d538
0044eea8 01bdd2d6 0046b008 01b3e87f 004f7e80 nw+0xb9dbca
0044eec4 01b513e2 0044ef2c 004b2800 0046b008 nw+0xbad2d6
0044ef04 01b51b2a 00000001 0044ef2c 0046b008 nw+0xb213e2
0044f018 01b51c28 00000001 00000001 02ff450c nw+0xb21b2a
0044f038 01b36924 00000000 02ff450c 00000000 nw+0xb21c28
0044f058 01b8c555 0046b000 0044f088 0044f084 nw+0xb06924
0044f068 2740a2d6 00000000 0044f088 0046b000 nw+0xb5c555
0044f084 2741d839 27f08091 3c5c3189 3c5b920d 0x2740a2d6
0044f098 0f4aeaf7 00000000 27dffde5 0f4aea01 0x2741d839
0044f0b4 0f42d7bb 00000000 27d34495 2e131c65 0xf4aeaf7
0044f0e4 27410941 0007b6b4 00000002 24c45ab5 0xf42d7bb
0044f108 0f42d203 00000002 24c45ab5 3587c7fd 0x27410941
0044f14c 0f427cf8 0cbfe471 35816099 0cbf1d2d 0xf42d203
0044f170 27410941 0cbfe481 0cbf1d6d 0cbf1339 0xf427cf8
0044f198 2746924c 1e208081 27dfae61 358160b1 0x27410941
0044f1b4 27429725 358a1e29 24c44f45 00000002 0x2746924c
0044f1d8 0f477a99 0cbfe49d 24c44f45 24c3d589 0x27429725
0044f1fc 27410941 24c44f45 00000002 24c44c1d 0xf477a99
0044f214 2742971e 358a1e29 24c44f45 00000002 0x27410941
0044f238 0f478f27 0cbfe4b1 24c44f45 24c44c1d 0x2742971e
0044f254 0f478ccc 0cbfe4c5 37a2c2d5 24c3d695 0xf478f27
0044f270 0f478a6f 0cbfe4c5 24c44f45 24c44f61 0xf478ccc
0044f294 27410941 24c44f61 00000002 24c3ac1d 0xf478a6f
0044f2ac 0f478939 358a1e29 24c44f61 24c43b5d 0x27410941
0044f2c4 274267f9 37a2c2d5 24c43b5d 27426761 0xf478939
0044f2e0 2741784a 00000000 00000000 274177a1 0x274267f9
0044f31c 01b36c28 0f4788c0 24c43b5d 37a2c2d5 0x2741784a
0044f35c 01b37805 0044f3e0 0046b198 00458008 nw+0xb06c28
0044f394 01ad7621 0044f3e0 00458008 00458004 nw+0xb07805
0044f3e8 01599dde 0044f414 00458004 00000000 nw+0xaa7621
0044f41c 0137984d 0044f4cc 00458008 394b4068 nw+0x569dde
0044f454 01379d8d 0044f4cc 394b4068 00458008 nw+0x34984d
0044f47c 015d62e4 0044f4cc 00458008 00458004 nw+0x349d8d
0044f4d8 015d645a 00451240 394b4068 0848a0e0 nw+0x5a62e4
0044f4ec 01896d6c 394b4068 00544520 0848a0e0 nw+0x5a645a
0044f51c 01a3483f 00475418 0044fa20 e978d4fe nw+0x866d6c
0044f53c 01a34898 0134b923 083d01f0 0044fa20 nw+0xa0483f
0044f564 0134b3ed 00000000 0044f6b8 0133f714 nw+0xa04898
0044f570 0133f714 083d7f20 0044fa20 004b4180 nw+0x31b3ed
0044f6b8 0134126a 0044f718 0045fd90 00000001 nw+0x30f714
0044f754 01365851 00000010 0044fa20 00000000 nw+0x31126a
0044f8b8 013403df 0044fa20 0044f990 00000000 nw+0x335851
0044f980 01362b33 0044fdd8 0133ebe6 0044fa20 nw+0x3103df
0044f9ac 02945174 00000008 02de9b60 0076cd58 nw+0x332b33
0044fc28 01e88f8a 0044fdd8 00462cf0 0045db40 nw+0x1915174
0044fd04 01e8916d 0044fde4 0044fdd8 0044fe48 nw+0xe58f8a
0044fe20 01e889a0 00000000 00000000 0044fe70 nw+0xe5916d
0044fe30 01031554 01030000 0044fe68 0044fe48 nw+0xe589a0
0044fe70 024ab093 01030000 00000000 00732148 nw+0x1554
0044ff00 7700336a fffde000 0044ff4c 779f9f72 nw+0x147b093
0044ff0c 779f9f72 fffde000 77c81c0f 00000000 kernel32!BaseThreadInitThunk+0xe
0044ff4c 779f9f45 024ab0e6 fffde000 00000000 ntdll!__RtlUserThreadStart+0x70
0044ff64 00000000 024ab0e6 fffde000 00000000 ntdll!_RtlUserThreadStart+0x1b
STACK_COMMAND: ~0s; .ecxr ; kb
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nw+bbd7b4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nw
IMAGE_NAME: nw.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 52703519
FAILURE_BUCKET_ID: INVALID_POINTER_READ_c0000005_nw.exe!Unknown
BUCKET_ID: APPLICATION_FAULT_INVALID_POINTER_READ_nw+bbd7b4
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:invalid_pointer_read_c0000005_nw.exe!unknown
FAILURE_ID_HASH: {102af0d7-aa97-56e0-ea3a-9d43e34f6540}
Followup: MachineOwner
And here is the stacktrace for this crash
# Args to Child
00 00000118 00000000 00000000 ntdll!ZwWaitForSingleObject+0x15 (FPO: [3,0,0])
01 00000118 ffffffff 00000000 KERNELBASE!WaitForSingleObjectEx+0x98 (FPO: [Non-Fpo])
02 00000118 ffffffff 00000000 kernel32!WaitForSingleObjectExImplementation+0x75 (FPO: [Non-Fpo])
03 00000118 ffffffff 0044e718 kernel32!WaitForSingleObject+0x12 (FPO: [Non-Fpo])
04 0044e718 00000000 0136f540 nw+0x33ed0b
05 0044e718 7dc098a3 00000000 nw+0x33f58f
06 0044e718 77a373dc 00000000 kernel32!UnhandledExceptionFilter+0x127 (FPO: [Non-Fpo])
07 00000000 0044ff4c 779ec550 ntdll!__RtlUserThreadStart+0x62 (FPO: [SEH])
08 00000000 00000000 00000000 ntdll!_EH4_CallFilterFunc+0x12 (FPO: [Uses EBP] [0,0,4])
09 fffffffe 0044ff3c 0044e868 ntdll!_except_handler4+0x8e (FPO: [Non-Fpo])
0a 0044e818 0044ff3c 0044e868 ntdll!ExecuteHandler2+0x26 (FPO: [Uses EBP] [5,3,1])
0b 0044e818 0044ff3c 0044e868 ntdll!ExecuteHandler+0x24 (FPO: [5,0,3])
0c 0044e818 0044e868 0044e818 ntdll!RtlDispatchException+0x127 (FPO: [Non-Fpo])
0d 0044e818 0044e868 0044e818 ntdll!KiUserExceptionDispatcher+0xf (FPO: [2,0,0]) (CONTEXT @ 0044e868)
0e 0f4c64a1 000031ff 0f406380 nw+0xbbd7b4
0f 0044ee60 0f406380 0f4c64a0 nw+0xab394f
10 00000082 00000320 0044ee60 nw+0xab4ef7
11 00467c40 004aba74 004aba50 nw+0xb9a5fe
12 004f7e80 0046c638 0044ef2c nw+0xb9d538
13 0046b008 01b3e87f 004f7e80 nw+0xb9dbca
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
FAULTING_IP:
nw+5a61fa
014161fa 8b4674 mov eax,dword ptr [esi+74h]
EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 014161fa (nw+0x005a61fa)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000075
Attempt to read from address 00000075
CONTEXT: 00000000 -- (.cxr 0x0;r)
eax=00000000 ebx=00000000 ecx=00000001 edx=02c26508 esi=00000118 edi=00000000
eip=7734f8d1 esp=0045e9d0 ebp=0045ea3c iopl=0 nv up ei pl zr na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000246
ntdll!ZwWaitForSingleObject+0x15:
7734f8d1 83c404 add esp,4
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_READ
PROCESS_NAME: nw.exe
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00000075
READ_ADDRESS: 00000075
FOLLOWUP_IP:
nw+5a61fa
014161fa 8b4674 mov eax,dword ptr [esi+74h]
NTGLOBALFLAG: 0
APP: nw.exe
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) x86fre
FAULTING_THREAD: 00001b18
PRIMARY_PROBLEM_CLASS: NULL_CLASS_PTR_READ
BUGCHECK_STR: APPLICATION_FAULT_NULL_CLASS_PTR_READ
LAST_CONTROL_TRANSFER: from 0141645a to 014161fa
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
0045f148 0141645a 04c51240 228a4f08 04c5fd9c nw+0x5a61fa
0045f15c 016d6d6c 228a4f08 04d44500 04c5fd9c nw+0x5a645a
0045f18c 0187483f 04c74418 0045f690 eb851eb8 nw+0x866d6c
0045f1ac 01874898 0118b923 06d5d270 0045f690 nw+0xa0483f
0045f1d4 0118b3ed 00000000 0045f328 0117f714 nw+0xa04898
0045f1e0 0117f714 06d5d230 0045f690 04c5d400 nw+0x31b3ed
0045f328 0118126a 0045f388 04c5fd90 00000001 nw+0x30f714
0045f3c4 011a5851 00000010 0045f690 00000000 nw+0x31126a
0045f528 011803df 0045f690 0045f600 00000000 nw+0x335851
0045f5f0 011a2b33 0045fa48 0117ebe6 0045f690 nw+0x3103df
0045f61c 02785174 00000008 02c29b60 0059cee0 nw+0x332b33
0045f898 01cc8f8a 0045fa48 04c62cf0 04c5db40 nw+0x1915174
0045f974 01cc916d 0045fa54 0045fa48 0045fab8 nw+0xe58f8a
0045fa90 01cc89a0 00000000 00000000 0045fae0 nw+0xe5916d
0045faa0 00e71554 00e70000 0045fad8 0045fab8 nw+0xe589a0
0045fae0 022eb093 00e70000 00000000 00562148 nw+0x1554
0045fb70 7680336a fffde000 0045fbbc 77369f72 nw+0x147b093
0045fb7c 77369f72 fffde000 777a5bb3 00000000 kernel32!BaseThreadInitThunk+0xe
0045fbbc 77369f45 022eb0e6 fffde000 00000000 ntdll!__RtlUserThreadStart+0x70
0045fbd4 00000000 022eb0e6 fffde000 00000000 ntdll!_RtlUserThreadStart+0x1b
STACK_COMMAND: ~0s; .ecxr ; kb
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nw+5a61fa
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nw
IMAGE_NAME: nw.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 52703519
FAILURE_BUCKET_ID: NULL_CLASS_PTR_READ_c0000005_nw.exe!Unknown
BUCKET_ID: APPLICATION_FAULT_NULL_CLASS_PTR_READ_nw+5a61fa
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:null_class_ptr_read_c0000005_nw.exe!unknown
FAILURE_ID_HASH: {bf8c7acd-2060-0946-dd7e-8d1334386b86}
Followup: MachineOwner
---------
And here is the stacktrace for this crash
ChildEBP RetAddr
0045e9d0 750b149d ntdll!ZwWaitForSingleObject+0x15 (FPO: [3,0,0])
0045ea3c 76801194 KERNELBASE!WaitForSingleObjectEx+0x98 (FPO: [Non-Fpo])
0045ea54 76801148 kernel32!WaitForSingleObjectExImplementation+0x75 (FPO: [Non-Fpo])
0045ea68 011aed0b kernel32!WaitForSingleObject+0x12 (FPO: [Non-Fpo])
0045ea84 011af58f nw+0x33ed0b
0045eaa0 7683fffb nw+0x33f58f
0045eb28 773a74ff kernel32!UnhandledExceptionFilter+0x127 (FPO: [Non-Fpo])
0045eb30 773a73dc ntdll!__RtlUserThreadStart+0x62 (FPO: [SEH])
0045eb44 773a7281 ntdll!_EH4_CallFilterFunc+0x12 (FPO: [Uses EBP] [0,0,4])
0045eb6c 7738b499 ntdll!_except_handler4+0x8e (FPO: [Non-Fpo])
0045eb90 7738b46b ntdll!ExecuteHandler2+0x26 (FPO: [Uses EBP] [5,3,1])
0045ebb4 7738b40e ntdll!ExecuteHandler+0x24 (FPO: [5,0,3])
0045ec40 77340133 ntdll!RtlDispatchException+0x127 (FPO: [Non-Fpo])
0045ec40 014161fa ntdll!KiUserExceptionDispatcher+0xf (FPO: [2,0,0]) (CONTEXT @ 0045eca8)
0045f148 0141645a nw+0x5a61fa
0045f15c 016d6d6c nw+0x5a645a
0045f18c 0187483f nw+0x866d6c
0045f1ac 01874898 nw+0xa0483f
0045f1d4 0118b3ed nw+0xa04898
0045f1e0 0117f714 nw+0x31b3ed
Thanks
Josh