Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c0c000 PsLoadedModuleList = 0xfffff800`02e49e50
Debug session time: Sun Oct 24 11:57:16.212 2010 (GMT-4)
System Uptime: 0 days 0:47:09.148
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff901c2fcd05d, 0, fffff960000f5e1f, 5}
Could not read faulting driver name
Probably caused by : win32k.sys ( win32k!draw_clrt_nf_ntb_o_to_temp_start+7b )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff901c2fcd05d, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff960000f5e1f, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb40e0
fffff901c2fcd05d
FAULTING_IP:
win32k!draw_clrt_nf_ntb_o_to_temp_start+7b
fffff960`000f5e1f 41803b00 cmp byte ptr [r11],0
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: firefox.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff880098f8350 -- (.trap 0xfffff880098f8350)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000095 rbx=0000000000000000 rcx=00000000ffffff64
rdx=0000000000000015 rsi=0000000000000000 rdi=0000000000000000
rip=fffff960000f5e1f rsp=fffff880098f84e8 rbp=0000000000000007
r8=fffff900c22368d0 r9=fffff900c2fcd0cc r10=fffff960000f5da4
r11=fffff901c2fcd05d r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
win32k!draw_clrt_nf_ntb_o_to_temp_start+0x7b:
fffff960`000f5e1f 41803b00 cmp byte ptr [r11],0 ds:8190:fffff901`c2fcd05d=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cfb8c1 to fffff80002c7c740
STACK_TEXT:
fffff880`098f81e8 fffff800`02cfb8c1 : 00000000`00000050 fffff901`c2fcd05d 00000000`00000000 fffff880`098f8350 : nt!KeBugCheckEx
fffff880`098f81f0 fffff800`02c7a82e : 00000000`00000000 fffff900`c0148394 fffff8a0`034d6c00 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x40e8b
fffff880`098f8350 fffff960`000f5e1f : fffff900`c289a000 00000000`0000009c 00000000`00000090 00000000`00000015 : nt!KiPageFault+0x16e
fffff880`098f84e8 fffff960`0012aa58 : fffff900`c00bf010 fffff880`098f8ec0 fffff900`c2fcd0cc 00000000`00000090 : win32k!draw_clrt_nf_ntb_o_to_temp_start+0x7b
fffff880`098f8520 fffff960`00104e68 : 00000000`00000000 fffff900`c2fcd030 fffff900`c01482f0 00000000`00000090 : win32k!vExpandAndCopyText+0x268
fffff880`098f88b0 fffff960`00103a49 : fffff900`00000015 fffff880`00000028 fffff900`c1c48010 fffff880`098f8e00 : win32k!EngTextOut+0xe28
fffff880`098f8c40 fffff960`002d3682 : fffff900`c2921738 fffff880`00000093 fffff880`0000000c 00000000`01011513 : win32k!GreExtTextOutWLocked+0x1d29
fffff880`098f9060 fffff960`0014cecf : 00000000`757b6e30 fffff960`0014af80 fffff880`00000000 fffff900`00ffffff : win32k!GreBatchTextOut+0x26a
fffff880`098f9100 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!NtGdiFlushUserBatch+0x377
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!draw_clrt_nf_ntb_o_to_temp_start+7b
fffff960`000f5e1f 41803b00 cmp byte ptr [r11],0
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: win32k!draw_clrt_nf_ntb_o_to_temp_start+7b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
FAILURE_BUCKET_ID: X64_0x50_win32k!draw_clrt_nf_ntb_o_to_temp_start+7b
BUCKET_ID: X64_0x50_win32k!draw_clrt_nf_ntb_o_to_temp_start+7b
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02c0a000 PsLoadedModuleList = 0xfffff800`02e47e50
Debug session time: Sun Oct 24 08:22:59.958 2010 (GMT-4)
System Uptime: 0 days 0:47:45.893
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff8800988ee78, fffff8800988e6e0, fffff80002f8c19b}
Probably caused by : Ntfs.sys ( Ntfs! ?? ::FNODOBFM::`string'+2cc9 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800988ee78
Arg3: fffff8800988e6e0
Arg4: fffff80002f8c19b
Debugging Details:
------------------
EXCEPTION_RECORD: fffff8800988ee78 -- (.exr 0xfffff8800988ee78)
ExceptionAddress: fffff80002f8c19b (nt!CcPinRead+0x000000000000005f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000028
Attempt to read from address 0000000000000028
CONTEXT: fffff8800988e6e0 -- (.cxr 0xfffff8800988e6e0)
rax=fffffa8006c83b60 rbx=fffff8a00db91c70 rcx=0000000000000000
rdx=fffff8800988f1b0 rsi=fffffa80087195e0 rdi=fffffa80087195e0
rip=fffff80002f8c19b rsp=fffff8800988f0b0 rbp=fffff8800988f820
r8=0000000000000ffa r9=0000000000000001 r10=0000000000000ffa
r11=fffff8800988f158 r12=0000000000000ffa r13=0000000000000000
r14=fffff8800988f1b0 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!CcPinRead+0x5f:
fffff800`02f8c19b 488b4128 mov rax,qword ptr [rcx+28h] ds:002b:00000000`00000028=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: avgchsva.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000028
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb20e0
0000000000000028
FOLLOWUP_IP:
Ntfs! ?? ::FNODOBFM::`string'+2cc9
fffff880`0126f3d8 cc int 3
FAULTING_IP:
nt!CcPinRead+5f
fffff800`02f8c19b 488b4128 mov rax,qword ptr [rcx+28h]
BUGCHECK_STR: 0x24
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002f8c19b
STACK_TEXT:
fffff880`0988de78 fffff880`0126f3d8 : 00000000`00000024 00000000`001904fb fffff880`0988ee78 fffff880`0988e6e0 : nt!KeBugCheckEx
fffff880`0988de80 fffff880`01267951 : fffff880`0129b1b4 fffff880`0988f820 fffff880`0988f7f0 fffff880`01290010 : Ntfs! ?? ::FNODOBFM::`string'+0x2cc9
fffff880`0988dec0 fffff800`02ca8d1c : 00000000`00680000 00000000`00000000 00000000`00017551 ffffffff`c0000102 : Ntfs! ?? ::FNODOBFM::`string'+0x1446
fffff880`0988df00 fffff880`01267775 : fffff880`0129b1bc fffff880`0988f7f0 fffff880`0988ee78 fffff880`0988f7f0 : nt!_C_specific_handler+0x8c
fffff880`0988df70 fffff800`02ca040d : fffff880`0129b1a8 00000000`00000000 fffff880`0124e000 00000000`00000000 : Ntfs!_GSHandlerCheck_SEH+0x75
fffff880`0988dfa0 fffff800`02ca7a90 : fffff880`0129b1a8 fffff880`0988e018 fffff880`0988ee78 fffff880`0124e000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`0988dfd0 fffff800`02cb49ef : fffff880`0988ee78 fffff880`0988e6e0 fffff880`00000000 fffffa80`087195e0 : nt!RtlDispatchException+0x410
fffff880`0988e6b0 fffff800`02c79d82 : fffff880`0988ee78 fffff8a0`0db91c70 fffff880`0988ef20 fffffa80`087195e0 : nt!KiDispatchException+0x16f
fffff880`0988ed40 fffff800`02c788fa : 00000000`00000000 fffff8a0`0db91c70 fffff880`0988f500 fffff8a0`0db91b40 : nt!KiExceptionDispatch+0xc2
fffff880`0988ef20 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x23a
STACK_COMMAND: kb
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs! ?? ::FNODOBFM::`string'+2cc9
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
FAILURE_BUCKET_ID: X64_0x24_Ntfs!_??_::FNODOBFM::_string_+2cc9
BUCKET_ID: X64_0x24_Ntfs!_??_::FNODOBFM::_string_+2cc9
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02c05000 PsLoadedModuleList = 0xfffff800`02e42e50
Debug session time: Sun Oct 24 07:31:04.918 2010 (GMT-4)
System Uptime: 0 days 5:52:44.215
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41289, 7fefc53c001, 731, 7f6fc53c005}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a49 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041289, The subtype of the bugcheck.
Arg2: 000007fefc53c001
Arg3: 0000000000000731
Arg4: 000007f6fc53c005
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41289
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002cca379 to fffff80002c75740
STACK_TEXT:
fffff880`0aa8b7e8 fffff800`02cca379 : 00000000`0000001a 00000000`00041289 000007fe`fc53c001 00000000`00000731 : nt!KeBugCheckEx
fffff880`0aa8b7f0 fffff800`02ce8cc3 : fffffa80`05d88f50 73100001`f2da7025 000007fe`fc537000 66600001`f45b0025 : nt! ?? ::FNODOBFM::`string'+0x4a49
fffff880`0aa8b830 fffff800`02ca8df9 : 00000000`00000000 000007fe`fc586fff fffffa80`00000000 fffff800`02c84b7c : nt! ?? ::FNODOBFM::`string'+0x3360b
fffff880`0aa8b9f0 fffff800`02f8e1d0 : fffffa80`09725350 0007ffff`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0aa8bb10 fffff800`02f8e5db : 00000000`00000000 000007fe`fc530000 fffffa80`00000001 fffffa80`0969c5b0 : nt!MiUnmapViewOfSection+0x1b0
fffff880`0aa8bbd0 fffff800`02c74993 : fffffa80`097db320 fffff880`0aa8bca0 fffffa80`0a1cab30 00000000`0030df02 : nt!NtUnmapViewOfSection+0x5f
fffff880`0aa8bc20 00000000`771ffffa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0012c1f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771ffffa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4a49
fffff800`02cca379 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4a49
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41289_nt!_??_::FNODOBFM::_string_+4a49
BUCKET_ID: X64_0x1a_41289_nt!_??_::FNODOBFM::_string_+4a49
Followup: MachineOwner
---------