I have a cross-post over on TechNet trying to figure this out...BSOD in DWM with Intel Haswell HD4600
The OS is Windows 7 Ultimate sp1 and all relevant updates are applied. I updated all drivers and utilities for the motherboard from the manufacturers web site. After I went out to Intel's web site and ran their driver auto-verification utility and verified that both the audio and video drivers were up to date. These drivers were equalivalent to the ones you posted. After doing all this yesterday, I reproduced this problem for a third time with driver verifier turned on for almost everything, the analyze -v from the dump is below and these are posted online at
https://onedrive.live.com/?cid=989EBBE8B022D186&id=989EBBE8B022D186%21126
---------------------------
DRIVER_PAGE_FAULT_IN_FREED_SPECIAL_POOL (d5)
Memory was referenced after it was freed.
This cannot be protected by try-except.
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff900d1ccccf8, memory referenced
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation
Arg3: fffff96000289d84, if non-zero, the address which referenced memory.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Page 1d71f7 not present in the dump file. Type ".hh dbgerr004" for details
READ_ADDRESS: fffff900d1ccccf8 Special pool
FAULTING_IP:
win32k!GreTransferSpriteStateToDwmState+198
fffff960`00289d84 8b4020 mov eax,dword ptr [rax+20h]
MM_INTERNAL_CODE: 0
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 52f4357b
MODULE_NAME: win32k
FAULTING_MODULE: fffff960000b0000 win32k
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD5
PROCESS_NAME: dwm.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre
TRAP_FRAME: fffff8800b581740 -- (.trap 0xfffff8800b581740)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff900d1ccccd8 rbx=0000000000000000 rcx=0000000000000098
rdx=0000000000000007 rsi=0000000000000000 rdi=0000000000000000
rip=fffff96000289d84 rsp=fffff8800b5818d0 rbp=0000000000000001
r8=000000000000006b r9=fffff9600039e1fc r10=fffff8800b581ae0
r11=fffff8800b5818b0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
win32k!GreTransferSpriteStateToDwmState+0x198:
fffff960`00289d84 8b4020 mov eax,dword ptr [rax+20h] ds:fffff900`d1ccccf8=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003101bf0 to fffff80003083bc0
STACK_TEXT:
fffff880`0b5815d8 fffff800`03101bf0 : 00000000`00000050 fffff900`d1ccccf8 00000000`00000000 fffff880`0b581740 : nt!KeBugCheckEx
fffff880`0b5815e0 fffff800`03081cee : 00000000`00000000 fffff900`d1ccccf8 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4518f
fffff880`0b581740 fffff960`00289d84 : 00000000`00000000 00000000`00000001 fffff900`d84aefe0 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`0b5818d0 fffff960`00204d0e : fffff880`00000001 fffff800`00000001 00000000`00000014 00000000`0000009e : win32k!GreTransferSpriteStateToDwmState+0x198
fffff880`0b5819e0 fffff960`00205743 : 00000000`00000000 fffff880`0b581b60 00000000`c0000001 fffff880`0b581b60 : win32k!zzzComposeDesktop+0x52
fffff880`0b581a80 fffff960`00199083 : 00000000`00000000 00000000`ff69a3b0 fffff880`0b580000 00000000`00000018 : win32k!zzzDwmStartRedirection+0xbf
fffff880`0b581ab0 fffff800`03082e53 : fffffa80`0811fb50 fffff880`0b581b60 fffffa80`08c2bd70 00000000`00000000 : win32k!NtUserDwmStartRedirection+0x6b
fffff880`0b581ae0 00000000`76cc5f7a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0226f758 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76cc5f7a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!GreTransferSpriteStateToDwmState+198
fffff960`00289d84 8b4020 mov eax,dword ptr [rax+20h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: win32k!GreTransferSpriteStateToDwmState+198
FOLLOWUP_NAME: MachineOwner
IMAGE_VERSION: 6.1.7601.18388
FAILURE_BUCKET_ID: X64_0xD5_VRF_win32k!GreTransferSpriteStateToDwmState+198
BUCKET_ID: X64_0xD5_VRF_win32k!GreTransferSpriteStateToDwmState+198
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xd5_vrf_win32k!gretransferspritestatetodwmstate+198
FAILURE_ID_HASH: {c3a8d87a-3ab8-71bb-6ec8-ff490f7fee0c}