Win 7 x64 Crashing on idle

Page 1 of 2 12 LastLast

  1. Posts : 8
    Windows 7 Ultimate 64
       #1

    Win 7 x64 Crashing on idle


    Hello,
    I have expereienced crashing on idle for a while now (@1yr.) with no time to investigate. After first building the system, I had ongoing and frequent BSOD preceded by hairline colored strips. I narrowed that down to my ATI Radeon 5850($300 wasted) which I replaced with my old nVidia GeForce 7800GTX. This stopped the pinstripe crashes but not the crashing on idle. No BSOD, just black screen--restart. Power options are set to never sleep or hibernate.

    I built the machine.
    Win 7 x64 original install/purchased
    MSI 790FX-Gd70
    AMD Phenom II x4 965
    nVidia 7800GTX
    8G DDR3 Corsair RAM
    sys 1 yr old.
    OS 1 yr.

    I have been trying to narrow down with startup drivers, etc. but with no luck.
    I hope I have posted this correctly.
    Thank you for any advice you can offer.
    Don
      My Computer


  2. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #2

    Hi, istr8or. Welcome to the forum. Sorry you are having problems. You have a lot of dump files. I am looking at your five most recent ones. Three of those dumps point to NTFS.sys, your file system.

    I suggest you run Check Disk to check your hard drive.
    Run CHKDSK /R /F from an elevated (Run as adminstrator) Command Prompt. Please do this for each hard drive on your system.
    When it tells you it can't do it right now - and asks you if you'd like to do it at the next reboot - answer Y (for Yes) and press Enter. Then reboot and let the test run. It may take a while for it to run, but keep an occasional eye on it to see if it generates any errors. See "CHKDSK LogFile" below in order to check the results of the test.

    Elevated Command Prompt:
    Go to Start and type in "cmd.exe" (without the quotes)
    At the top of the Search Box, right click on Cmd.exe and select "Run as administrator"

    CHKDSK LogFile:
    Go to Start and type in "eventvwr.msc" (without the quotes) and press Enter
    Expand the Windows logs heading, then select the Application log file entry.
    Double click on the Source column header.
    Scroll down the list until you find the Chkdsk entry (wininit for Windows 7) (winlogon for XP).


    Copy/paste the results into your next post.


    Error code 24 (3X), NTFS_FILE_SYSTEM. Usual causes: Disk corruption, insufficient physical memory, Device driver, Indexing, Resident antivirus, backup, defrag programs, Disk/Drive failing/failure.

    Error code 19, BAD_POOL_HEADER. Usual causes: Device driver.

    Error code 1A, MEMORY_MANAGEMENT. Usual causes: Device driver, memory, kernel.
    Code:
    Windows 7 Kernel Version 7600 MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
    Machine Name:
    Kernel base = 0xfffff800`03251000 PsLoadedModuleList = 0xfffff800`0348ee50
    Debug session time: Sat Oct 30 10:29:47.534 2010 (GMT-4)
    System Uptime: 0 days 1:29:18.250
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...................................................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 24, {1904fb, fffff8800863c218, fffff8800863ba80, fffff88001221454}
    
    Unable to load image mozy.sys, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for mozy.sys
    *** ERROR: Module load completed but symbols could not be loaded for mozy.sys
    Unable to load image eamon.sys, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for eamon.sys
    *** ERROR: Module load completed but symbols could not be loaded for eamon.sys
    Probably caused by : Ntfs.sys ( Ntfs!NtfsReleaseFcb+54 )
    
    Followup: MachineOwner
    ---------
    
    3: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    NTFS_FILE_SYSTEM (24)
        If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
        parameters are the exception record and context record. Do a .cxr
        on the 3rd parameter and then kb to obtain a more informative stack
        trace.
    Arguments:
    Arg1: 00000000001904fb
    Arg2: fffff8800863c218
    Arg3: fffff8800863ba80
    Arg4: fffff88001221454
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_RECORD:  fffff8800863c218 -- (.exr 0xfffff8800863c218)
    ExceptionAddress: fffff88001221454 (Ntfs!NtfsReleaseFcb+0x0000000000000054)
       ExceptionCode: c0000005 (Access violation)
      ExceptionFlags: 00000000
    NumberParameters: 2
       Parameter[0]: 0000000000000001
       Parameter[1]: 0000000015000008
    Attempt to write to address 0000000015000008
    
    CONTEXT:  fffff8800863ba80 -- (.cxr 0xfffff8800863ba80)
    rax=fffff8a0125a1050 rbx=fffff8a015ed5010 rcx=fffffa800b876450
    rdx=0000000015000000 rsi=fffffa800832f180 rdi=0000000000000000
    rip=fffff88001221454 rsp=fffff8800863c450 rbp=fffffa800b876450
     r8=fffff8a015dd25c0  r9=fffff8a015dd25e0 r10=fffff8800863c4b0
    r11=fffffa8007fa2090 r12=fffffa800b876450 r13=fffffa8008330bd0
    r14=0000000000000000 r15=fffffa800832f180
    iopl=0         nv up ei pl zr na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
    Ntfs!NtfsReleaseFcb+0x54:
    fffff880`01221454 48894208        mov     qword ptr [rdx+8],rax ds:002b:00000000`15000008=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    PROCESS_NAME:  svchost.exe
    
    CURRENT_IRQL:  0
    
    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    EXCEPTION_PARAMETER1:  0000000000000001
    
    EXCEPTION_PARAMETER2:  0000000015000008
    
    WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800034f90e0
     0000000015000008 
    
    FOLLOWUP_IP: 
    Ntfs!NtfsReleaseFcb+54
    fffff880`01221454 48894208        mov     qword ptr [rdx+8],rax
    
    FAULTING_IP: 
    Ntfs!NtfsReleaseFcb+54
    fffff880`01221454 48894208        mov     qword ptr [rdx+8],rax
    
    BUGCHECK_STR:  0x24
    
    LAST_CONTROL_TRANSFER:  from fffff880012effcb to fffff88001221454
    
    STACK_TEXT:  
    fffff880`0863c450 fffff880`012effcb : fffff8a0`15ed5b40 fffffa80`0832f180 00000000`00000000 fffffa80`0b876450 : Ntfs!NtfsReleaseFcb+0x54
    fffff880`0863c490 fffff880`0134e07d : 00000000`00000001 fffffa80`0ac3f093 fffff880`0863c880 fffffa80`0ac3f093 : Ntfs!NtfsReleaseAllFiles+0x8b
    fffff880`0863c4e0 fffff880`0134edfe : fffffa80`0b876450 fffffa80`0ac3f010 fffffa80`08330bd0 fffffa80`0a8d8750 : Ntfs!NtfsDefragFileInternal+0x12e7
    fffff880`0863c6b0 fffff880`0130e702 : fffff880`00000000 fffffa80`0b7a8300 fffffa80`0832f180 fffffa80`08330bd0 : Ntfs!NtfsDefragFile+0x43e
    fffff880`0863c750 fffff880`012c72ed : fffffa80`0b876450 00000000`00000000 fffff880`0863c880 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x1cc89
    fffff880`0863c790 fffff880`010e223f : fffff880`0863c8e0 fffffa80`0ac3f010 fffff880`0863c801 fffffa80`0b876450 : Ntfs!NtfsFsdFileSystemControl+0x13d
    fffff880`0863c830 fffff880`0110191e : fffffa80`08350ce0 00000000`00000000 fffffa80`08350c00 fffffa80`0ac3f010 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
    fffff880`0863c8c0 fffff880`019c5695 : fffffa80`0ac3f000 fffffa80`20206f49 00000000`00000064 fffff800`035b27c5 : fltmgr!FltpFsControl+0xee
    fffff880`0863c920 fffffa80`0ac3f000 : fffffa80`20206f49 00000000`00000064 fffff800`035b27c5 fffff880`0863c940 : mozy+0x4695
    fffff880`0863c928 fffffa80`20206f49 : 00000000`00000064 fffff800`035b27c5 fffff880`0863c940 fffff880`0863c940 : 0xfffffa80`0ac3f000
    fffff880`0863c930 00000000`00000064 : fffff800`035b27c5 fffff880`0863c940 fffff880`0863c940 fffffa80`0b7a82d0 : 0xfffffa80`20206f49
    fffff880`0863c938 fffff800`035b27c5 : fffff880`0863c940 fffff880`0863c940 fffffa80`0b7a82d0 00000000`00100080 : 0x64
    fffff880`0863c940 fffff880`0863cca0 : fffffa80`09a70490 fffffa80`0847e2c0 fffffa80`0ac3f010 fffff880`024839d1 : nt!SeCreateAccessStateEx+0xa5
    fffff880`0863c990 fffffa80`09a70490 : fffffa80`0847e2c0 fffffa80`0ac3f010 fffff880`024839d1 00000000`00000000 : 0xfffff880`0863cca0
    fffff880`0863c998 fffffa80`0847e2c0 : fffffa80`0ac3f010 fffff880`024839d1 00000000`00000000 fffff800`032e259c : 0xfffffa80`09a70490
    fffff880`0863c9a0 fffffa80`0ac3f010 : fffff880`024839d1 00000000`00000000 fffff800`032e259c ffffffff`ffffffff : 0xfffffa80`0847e2c0
    fffff880`0863c9a8 fffff880`024839d1 : 00000000`00000000 fffff800`032e259c ffffffff`ffffffff 00000000`00000000 : 0xfffffa80`0ac3f010
    fffff880`0863c9b0 00000000`00000000 : fffff800`032e259c ffffffff`ffffffff 00000000`00000000 fffffa80`0b92a470 : eamon+0x69d1
    
    
    SYMBOL_STACK_INDEX:  0
    
    SYMBOL_NAME:  Ntfs!NtfsReleaseFcb+54
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: Ntfs
    
    IMAGE_NAME:  Ntfs.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc14f
    
    STACK_COMMAND:  .cxr 0xfffff8800863ba80 ; kb
    
    FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsReleaseFcb+54
    
    BUCKET_ID:  X64_0x24_Ntfs!NtfsReleaseFcb+54
    
    Followup: MachineOwner
    ---------
    
    3: kd> lmtsmn
    start             end                 module name
    fffff880`03f4f000 fffff880`03f8d000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
    fffff880`00f09000 fffff880`00f60000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
    fffff880`03bd7000 fffff880`03bef000   adfs     adfs.SYS     Mon Nov 03 11:48:14 2008 (490F2B4E)
    fffff880`02c97000 fffff880`02d21000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`0457a000 fffff880`04590000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
    fffff880`03f08000 fffff880`03f1d000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    fffff880`00e33000 fffff880`00e3e000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
    fffff880`06b77000 fffff880`06b82000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
    fffff880`00e2a000 fffff880`00e33000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00c00000 fffff880`00c2a000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
    fffff880`01959000 fffff880`01961000   AtiPcie  AtiPcie.sys  Tue May 05 11:00:22 2009 (4A005486)
    fffff960`00940000 fffff960`009a1000   ATMFD    ATMFD.DLL    Thu May 27 00:11:31 2010 (4BFDF0F3)
    fffff880`00fd1000 fffff880`00fdd000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
    fffff880`042c5000 fffff880`0456d000   bcmwl664 bcmwl664.sys Tue Jul 07 20:45:04 2009 (4A53EC10)
    fffff880`019e0000 fffff880`019e7000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
    fffff880`03ed1000 fffff880`03ee2000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
    fffff880`03ae6000 fffff880`03b04000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
    fffff960`006c0000 fffff960`006e7000   cdd      cdd.dll      Wed May 19 15:48:26 2010 (4BF4408A)
    fffff880`03b1c000 fffff880`03b39000   cdfs     cdfs.sys     Mon Jul 13 19:19:46 2009 (4A5BC112)
    fffff880`01997000 fffff880`019c1000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00cd6000 fffff880`00d96000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
    fffff880`01929000 fffff880`01959000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00c78000 fffff880`00cd6000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01000000 fffff880`01073000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
    fffff880`05c00000 fffff880`05c2b000   COMMONFX COMMONFX.SYS Thu Mar 18 08:19:04 2010 (4BA21A38)
    fffff880`00fc8000 fffff880`00fd1000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`04852000 fffff880`04862000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`03bef000 fffff880`03bf7000   cpuz132_x64 cpuz132_x64.sys Thu Mar 26 19:17:23 2009 (49CC0D03)
    fffff880`065dc000 fffff880`065ea000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
    fffff880`03e30000 fffff880`03eb3000   csc      csc.sys      Mon Jul 13 19:24:26 2009 (4A5BC22A)
    fffff880`05000000 fffff880`050ae000   ctac32k  ctac32k.sys  Thu Mar 18 08:20:26 2010 (4BA21A8A)
    fffff880`0486e000 fffff880`0493fd80   ctaud2k  ctaud2k.sys  Thu Mar 18 08:18:42 2010 (4BA21A22)
    fffff880`05e41000 fffff880`05ef1000   CTAUDFX  CTAUDFX.SYS  Thu Mar 18 08:19:07 2010 (4BA21A3B)
    fffff880`04800000 fffff880`0483b000   ctoss2k  ctoss2k.sys  Thu Mar 18 08:17:56 2010 (4BA219F4)
    fffff880`0483b000 fffff880`04843000   ctprxy2k ctprxy2k.sys Thu Mar 18 08:18:45 2010 (4BA21A25)
    fffff880`05ef1000 fffff880`05f9c000   CTSBLFX  CTSBLFX.SYS  Thu Mar 18 08:19:13 2010 (4BA21A41)
    fffff880`0518f000 fffff880`051d9000   ctsfm2k  ctsfm2k.sys  Thu Mar 18 08:17:48 2010 (4BA219EC)
    fffff880`03eb3000 fffff880`03ed1000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
    fffff880`02c7c000 fffff880`02c8b000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
    fffff880`01913000 fffff880`01929000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`0497d000 fffff880`0499f000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
    fffff880`065f6000 fffff880`065ff000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`065ea000 fffff880`065f6000   dump_ataport dump_ataport.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`05f9c000 fffff880`05faf000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    fffff880`065d0000 fffff880`065dc000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
    fffff880`14a98000 fffff880`14b8c000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
    fffff880`14b8c000 fffff880`14bd2000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
    fffff880`0247d000 fffff880`0254f000   eamon    eamon.sys    Mon Nov 16 02:51:14 2009 (4B010472)
    fffff880`01800000 fffff880`01823000   ehdrv    ehdrv.sys    Mon Nov 16 02:51:48 2009 (4B010494)
    fffff880`0513d000 fffff880`0518f000   emupia2k emupia2k.sys Thu Mar 18 08:17:45 2010 (4BA219E9)
    fffff880`04291000 fffff880`042b1000   epfwwfpr epfwwfpr.sys Mon Nov 16 02:46:31 2009 (4B010357)
    fffff880`0242b000 fffff880`02461000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
    fffff880`0112b000 fffff880`0113f000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
    fffff880`010df000 fffff880`0112b000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
    fffff880`013da000 fffff880`013e4000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
    fffff880`018d9000 fffff880`01913000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
    fffff880`01400000 fffff880`0144a000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
    fffff880`14bee000 fffff880`14bfb000   GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
    fffff880`05c2d000 fffff880`05de6000   ha10kx2k ha10kx2k.sys Thu Mar 18 08:17:59 2010 (4BA219F7)
    fffff800`03208000 fffff800`03251000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
    fffff880`03e00000 fffff880`03e24000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
    fffff880`05fcc000 fffff880`05fd7000   HidBatt  HidBatt.sys  Mon Jul 13 19:31:06 2009 (4A5BC3BA)
    fffff880`049e2000 fffff880`049fb000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
    fffff880`04865000 fffff880`0486d080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
    fffff880`06400000 fffff880`0640e000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
    fffff880`03a1e000 fffff880`03ae6000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
    fffff880`01469000 fffff880`01472000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
    fffff880`04261000 fffff880`04270000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`05fea000 fffff880`05ff8000   kbdhid   kbdhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff800`00ba6000 fffff800`00bb0000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
    fffff880`0499f000 fffff880`049e2000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
    fffff880`013af000 fffff880`013c9000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
    fffff880`015c8000 fffff880`015f3000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
    fffff880`04843000 fffff880`04848200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
    fffff880`05fd7000 fffff880`05fea000   LHidFilt LHidFilt.Sys Wed Jun 17 12:49:39 2009 (4A391EA3)
    fffff880`0258b000 fffff880`025a0000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`05e00000 fffff880`05e14000   LMouFilt LMouFilt.Sys Wed Jun 17 12:49:43 2009 (4A391EA7)
    fffff880`051d9000 fffff880`051fc000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
    fffff880`00c57000 fffff880`00c64000   mcupdate mcupdate.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
    fffff880`05e14000 fffff880`05e22000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
    fffff880`04270000 fffff880`0427f000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`05113000 fffff880`05120000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff880`00e10000 fffff880`00e2a000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`019c1000 fffff880`019d7000   mozy     mozy.sys     Thu Dec 31 22:20:07 2009 (4B3D69E7)
    fffff880`03b04000 fffff880`03b1c000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
    fffff880`03b39000 fffff880`03b66000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
    fffff880`03b66000 fffff880`03bb4000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
    fffff880`03bb4000 fffff880`03bd7000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
    fffff880`01881000 fffff880`0188c000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00f69000 fffff880`00f73000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
    fffff880`0114b000 fffff880`011a9000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
    fffff880`02c71000 fffff880`02c7c000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
    fffff880`013e4000 fffff880`013f6000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
    fffff880`01476000 fffff880`01568000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`045b4000 fffff880`045c0000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
    fffff880`02400000 fffff880`02413000   ndisuio  ndisuio.sys  Mon Jul 13 20:09:25 2009 (4A5BCCB5)
    fffff880`045c0000 fffff880`045ef000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`05128000 fffff880`0513d000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
    fffff880`02dab000 fffff880`02dba000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`02d21000 fffff880`02d66000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
    fffff880`01568000 fffff880`015c8000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
    fffff880`0188c000 fffff880`0189d000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`02c65000 fffff880`02c71000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
    fffff800`03251000 fffff800`0382d000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
    fffff880`0120c000 fffff880`013af000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
    fffff880`019d7000 fffff880`019e0000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
    fffff880`14a96000 fffff880`14a97180   nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
    fffff880`13e04000 fffff880`14a95e00   nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
    fffff880`025a0000 fffff880`025f3000   nwifi    nwifi.sys    Mon Jul 13 20:07:23 2009 (4A5BCC3B)
    fffff880`02d6f000 fffff880`02d95000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
    fffff880`00fb3000 fffff880`00fc8000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00f73000 fffff880`00fa6000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`00ff2000 fffff880`00ff9000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
    fffff880`00e00000 fffff880`00e10000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`013c9000 fffff880`013da000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
    fffff880`06629000 fffff880`066cf000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
    fffff880`04940000 fffff880`0497d000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`00c64000 fffff880`00c78000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
    fffff880`0113f000 fffff880`0114ae00   PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253)
    fffff880`04590000 fffff880`045b4000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`04200000 fffff880`0421b000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
    fffff880`0421b000 fffff880`0423c000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
    fffff880`0423c000 fffff880`04256000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
    fffff880`02c14000 fffff880`02c65000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
    fffff880`04256000 fffff880`04261000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
    fffff880`01866000 fffff880`0186f000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`0186f000 fffff880`01878000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`01878000 fffff880`01881000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
    fffff880`011a9000 fffff880`011e3000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
    fffff880`02413000 fffff880`0242b000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`03f1d000 fffff880`03f4f000   Rt64win7 Rt64win7.sys Thu Feb 26 04:04:13 2009 (49A65B0D)
    fffff880`06412000 fffff880`065cfa00   RTKVHD64 RTKVHD64.sys Mon Jul 20 06:52:29 2009 (4A644C6D)
    fffff880`010bf000 fffff880`010dc000   sbp2port sbp2port.sys Mon Jul 13 19:19:53 2009 (4A5BC119)
    fffff880`066cf000 fffff880`066da000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
    fffff880`03e24000 fffff880`03e30000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`02dba000 fffff880`02dd7000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
    fffff880`01462000 fffff880`01469000   speedfan speedfan.sys Sun Sep 24 09:26:48 2006 (45168798)
    fffff880`0145a000 fffff880`01462000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
    fffff880`06a3f000 fffff880`06ad5000   srv      srv.sys      Thu Aug 26 23:38:00 2010 (4C773318)
    fffff880`06719000 fffff880`06780000   srv2     srv2.sys     Thu Aug 26 23:37:46 2010 (4C77330A)
    fffff880`066da000 fffff880`06707000   srvnet   srvnet.sys   Thu Aug 26 23:37:24 2010 (4C7732F4)
    fffff880`049fb000 fffff880`049fc480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
    fffff880`01602000 fffff880`017ff000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
    fffff880`06707000 fffff880`06719000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
    fffff880`018bb000 fffff880`018c8000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
    fffff880`0189d000 fffff880`018bb000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
    fffff880`02c00000 fffff880`02c14000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
    fffff960`00590000 fffff960`0059a000   TSDDD    TSDDD.dll    Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`03ee2000 fffff880`03f08000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
    fffff880`0427f000 fffff880`04291000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
    fffff880`05faf000 fffff880`05fcc000   usbccgp  usbccgp.sys  Mon Jul 13 20:06:45 2009 (4A5BCC15)
    fffff880`0640e000 fffff880`0640ff00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
    fffff880`14bdd000 fffff880`14bee000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`050b9000 fffff880`05113000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
    fffff880`14bd2000 fffff880`14bdd000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`03f8d000 fffff880`03fe3000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`02570000 fffff880`0258b000   USBSTOR  USBSTOR.SYS  Mon Jul 13 20:06:34 2009 (4A5BCC0A)
    fffff880`00fa6000 fffff880`00fb3000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
    fffff880`01823000 fffff880`01831000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
    fffff880`01831000 fffff880`01856000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
    fffff880`0144a000 fffff880`0145a000   vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
    fffff880`00fdd000 fffff880`00ff2000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00d96000 fffff880`00df2000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
    fffff880`01073000 fffff880`010bf000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
    fffff880`0456d000 fffff880`0457a000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
    fffff880`02d95000 fffff880`02dab000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
    fffff880`05e22000 fffff880`05e2b000   wacmoumonitor wacmoumonitor.sys Fri Jan 22 20:33:34 2010 (4B5A51EE)
    fffff880`05120000 fffff880`05128000   wacommousefilter wacommousefilter.sys Fri Feb 16 13:12:17 2007 (45D5F401)
    fffff880`04862000 fffff880`04864a00   wacomvhid wacomvhid.sys Mon Sep 21 19:29:14 2009 (4AB80C4A)
    fffff880`02dd7000 fffff880`02df2000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
    fffff880`01856000 fffff880`01866000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
    fffff880`00e56000 fffff880`00efa000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
    fffff880`00efa000 fffff880`00f09000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`02d66000 fffff880`02d6f000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff960`000e0000 fffff960`003ef000   win32k   win32k.sys   Tue Aug 31 22:58:04 2010 (4C7DC13C)
    fffff880`04849000 fffff880`04852000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`00f60000 fffff880`00f69000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`0254f000 fffff880`02570000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)
    fffff880`06ad5000 fffff880`06b06000   WUDFRd   WUDFRd.sys   Mon Jul 13 20:06:06 2009 (4A5BCBEE)
    
    Unloaded modules:
    fffff880`06b06000 fffff880`06b77000   spsys.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`01961000 fffff880`0196f000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`0196f000 fffff880`0197b000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`0197b000 fffff880`01984000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`01984000 fffff880`01997000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 19, {20, fffff8a00d4a7b50, fffff8a00d4a8680, 5b36f80}
    
    GetPointerFromAddress: unable to read from fffff800035050e0
    GetUlongFromAddress: unable to read from fffff800034731b0
    Probably caused by : ntkrnlmp.exe ( nt!SepTokenDeleteMethod+6b )
    
    Followup: MachineOwner
    ---------
    
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    BAD_POOL_HEADER (19)
    The pool is already corrupt at the time of the current request.
    This may or may not be due to the caller.
    The internal pool links must be walked to figure out a possible cause of
    the problem, and then special pool applied to the suspect tags or the driver
    verifier to a suspect driver.
    Arguments:
    Arg1: 0000000000000020, a pool block header size is corrupt.
    Arg2: fffff8a00d4a7b50, The pool entry we were looking for within the page.
    Arg3: fffff8a00d4a8680, The next pool entry.
    Arg4: 0000000005b36f80, (reserved)
    
    Debugging Details:
    ------------------
    
    GetUlongFromAddress: unable to read from fffff800034731b0
    
    BUGCHECK_STR:  0x19_20
    
    POOL_ADDRESS:  fffff8a00d4a7b50 
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    PROCESS_NAME:  svchost.exe
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from fffff800034006d3 to fffff800032cd740
    
    STACK_TEXT:  
    fffff880`06d8e9f8 fffff800`034006d3 : 00000000`00000019 00000000`00000020 fffff8a0`0d4a7b50 fffff8a0`0d4a8680 : nt!KeBugCheckEx
    fffff880`06d8ea00 fffff800`0359534b : fffff8a0`0e315500 fffff800`035c99dd 00000000`74416553 fffffa80`09b3db30 : nt!ExDeferredFreePool+0x12c4
    fffff880`06d8eab0 fffff800`032d28b4 : 00000000`00000000 00000000`00000000 fffffa80`09b3db30 fffffa80`069abd90 : nt!SepTokenDeleteMethod+0x6b
    fffff880`06d8eae0 fffff800`035e3514 : fffffa80`09b3db30 00000000`00000000 fffffa80`08fd7370 00000000`00000000 : nt!ObfDereferenceObject+0xd4
    fffff880`06d8eb40 fffff800`035e3414 : 00000000`00000980 fffffa80`09b3db30 fffff8a0`0298a490 00000000`00000980 : nt!ObpCloseHandleTableEntry+0xc4
    fffff880`06d8ebd0 fffff800`032cc993 : fffffa80`08fd7370 fffff880`06d8eca0 00000000`00000000 00000000`00000000 : nt!ObpCloseHandle+0x94
    fffff880`06d8ec20 00000000`7794fe4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`013de558 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7794fe4a
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt!SepTokenDeleteMethod+6b
    fffff800`0359534b 488b8fa8000000  mov     rcx,qword ptr [rdi+0A8h]
    
    SYMBOL_STACK_INDEX:  2
    
    SYMBOL_NAME:  nt!SepTokenDeleteMethod+6b
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9
    
    FAILURE_BUCKET_ID:  X64_0x19_20_nt!SepTokenDeleteMethod+6b
    
    BUCKET_ID:  X64_0x19_20_nt!SepTokenDeleteMethod+6b
    
    Followup: MachineOwner
    ---------
    
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 1A, {8886, fffffa80049a15d0, fffffa80049a4090, 407}
    
    Unable to load image ATMFD.DLL, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for ATMFD.DLL
    *** ERROR: Module load completed but symbols could not be loaded for ATMFD.DLL
    Probably caused by : ATMFD.DLL ( ATMFD+3efbb )
    
    Followup: MachineOwner
    ---------
    
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    MEMORY_MANAGEMENT (1a)
        # Any other values for parameter 1 must be individually examined.
    Arguments:
    Arg1: 0000000000008886, The subtype of the bugcheck.
    Arg2: fffffa80049a15d0
    Arg3: fffffa80049a4090
    Arg4: 0000000000000407
    
    Debugging Details:
    ------------------
    
    
    BUGCHECK_STR:  0x1a_8886
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    PROCESS_NAME:  csrss.exe
    
    CURRENT_IRQL:  2
    
    TRAP_FRAME:  fffff880079717a0 -- (.trap 0xfffff880079717a0)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=4928000008500000 rbx=0000000000000000 rcx=fffff900c0926850
    rdx=000006ff438b97a8 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff960008cefbb rsp=fffff88007971938 rbp=0000000000000001
     r8=0000000000035550  r9=00000000000007c2 r10=0950000009500000
    r11=fffff900c0917020 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei ng nz na po nc
    ATMFD+0x3efbb:
    fffff960`008cefbb ??              ???
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff800032ac8c8 to fffff8000328b740
    
    STACK_TEXT:  
    fffff880`07971368 fffff800`032ac8c8 : 00000000`0000001a 00000000`00008886 fffffa80`049a15d0 fffffa80`049a4090 : nt!KeBugCheckEx
    fffff880`07971370 fffff800`032bd587 : 81700001`88a20025 00000001`00000000 fffff6fc`88a20025 fffff8a0`0545a078 : nt!MiUnlinkPageFromLockedList+0x298
    fffff880`07971400 fffff800`032b1dc9 : 00000000`00000000 00000001`88b1f8c0 00000000`00000000 fffffa80`096a78b8 : nt!MiResolveTransitionFault+0x167
    fffff880`07971490 fffff800`032a75be : 00000000`00000000 00000000`041dfff8 fffff680`00020ef8 fffffa80`096a78b8 : nt!MiResolveProtoPteFault+0x419
    fffff880`07971530 fffff800`032a5743 : ffffffff`ffffff00 00000000`041dfff8 00000000`00000000 fffff800`00000000 : nt!MiDispatchFault+0x1de
    fffff880`07971640 fffff800`0328982e : 00000000`00000000 00000000`00035550 00000000`00000000 fffff800`032a57c0 : nt!MmAccessFault+0x343
    fffff880`079717a0 fffff960`008cefbb : fffff960`00894c3f 00000000`70616d63 fffff900`c0ddf798 00000000`ffffffff : nt!KiPageFault+0x16e
    fffff880`07971938 fffff960`00894c3f : 00000000`70616d63 fffff900`c0ddf798 00000000`ffffffff fffff960`001288e8 : ATMFD+0x3efbb
    fffff880`07971940 00000000`70616d63 : fffff900`c0ddf798 00000000`ffffffff fffff960`001288e8 ffffffff`00035550 : ATMFD+0x4c3f
    fffff880`07971948 fffff900`c0ddf798 : 00000000`ffffffff fffff960`001288e8 ffffffff`00035550 00000000`041d07c8 : 0x70616d63
    fffff880`07971950 00000000`ffffffff : fffff960`001288e8 ffffffff`00035550 00000000`041d07c8 00000000`70616d63 : 0xfffff900`c0ddf798
    fffff880`07971958 fffff960`001288e8 : ffffffff`00035550 00000000`041d07c8 00000000`70616d63 00000000`00000000 : 0xffffffff
    fffff880`07971960 fffff960`000fa923 : fffff900`c30a7680 00000000`70616d63 00000000`00000000 fffff900`c0917020 : win32k!RFONTOBJ::bInit+0x40
    fffff880`07971a80 fffff960`000fa7eb : fffff900`c0917020 fffff880`07971ca0 00000000`70616d63 fffff960`0013623f : win32k!ulGetFontData2+0xf3
    fffff880`07971af0 fffff960`000fa701 : 00000000`ffffffff 00000000`ffffffff 00000000`00000001 fffff880`07971b70 : win32k!ulGetFontData+0x7f
    fffff880`07971b40 fffff800`0328a993 : 00000000`01010936 fffffa80`06fa2b60 00000000`0022e0a8 00000000`0022e080 : win32k!NtGdiGetFontData+0x8d
    fffff880`07971bb0 00000000`73e3093a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`0022e088 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x73e3093a
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    ATMFD+3efbb
    fffff960`008cefbb ??              ???
    
    SYMBOL_STACK_INDEX:  7
    
    SYMBOL_NAME:  ATMFD+3efbb
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: ATMFD
    
    IMAGE_NAME:  ATMFD.DLL
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4bfdf0f3
    
    FAILURE_BUCKET_ID:  X64_0x1a_8886_ATMFD+3efbb
    
    BUCKET_ID:  X64_0x1a_8886_ATMFD+3efbb
    
    Followup: MachineOwner
    ---------
    I find some outdated drivers loaded on your system. Older drivers can cause memory corruption and BSOD's. Note that drivers are mentions in all three of the causes above. the drivers in red font are really obsolete. Update these drivers.
    adfs.SYS Mon Nov 03 11:48:14 2008 - Adobe File System Driver http://www.adobe.com.

    AtiPcie.sys Tue May 05 11:00:22 2009 - ATI PCIE Driver for ATI PCIE chipsetGlobal Provider of Innovative Graphics, Processors and Media Solutions | AMD

    bcmwl664.sys Tue Jul 07 20:45:04 2009 - Broadcom Wireless Win64bit. Broadcom.com - Downloads & Support

    LHidFilt.Sys Wed Jun 17 12:49:39 2009 - Logitech SetPoint HID Filter Driver Downloads

    LMouFilt.Sys Wed Jun 17 12:49:43 2009 - Logitech Mouse Filter driverDownloads

    PxHlpa64.sys Tue Jun 23 19:16:35 2009 - Sonic CD/DVD driver (used by many different CD/DVD programs) pxHelp20.sys programs
    Go to C:\Windows\System32\drivers and rename PxHlpa64.sys to PxHlpa64.BAK
    This will break your CD/DVD program, but can easily be renamed after we've finished.

    Rt64win7.sys Thu Feb 26 04:04:13 2009 - Rt64win7.sys - Latest PCIe GBE (GigaBit Ethernet) drivers here: Realtek

    wacommousefilter.sys Fri Feb 16 13:12:17 2007 - Wacom(tablet) Mouse Filter Wacom Hardware Drivers
    How to find drivers -
    - I have listed links to most of the drivers in the code box below. Please use the links there to see what info I've found about those drivers.
    - search Google for the name of the driver
    - compare the Google results with what's installed on your system to figure out which device/program it belongs to
    - visit the web site of the manufacturer of the hardware/program to get the latest drivers (DON'T use Windows Update or the Update driver function of Device Manager).
    - if there are difficulties in locating them, post back with questions and someone will try and help you locate the appropriate program.


    - - The most common drivers are listed on this page: Driver Reference
    - - Driver manufacturer links are on this page: Drivers and Downloads
    Update the above drivers, reboot, and let's see how your system runs. If you get another crash, upload the dump and we will go from there.
    Last edited by CarlTR6; 30 Oct 2010 at 14:47.
      My Computer


  3. Posts : 8
    Windows 7 Ultimate 64
    Thread Starter
       #3

    Carl,
    Wow. Thank you for your response and the time it took to make it. Much appreciation.
    I am working on finding the drivers. Not much luck on the adobe, and I have both CS4 and CS5 Master collections installed. I will continue to try.

    Thank you again. I am pasting the wininit below.
    Don

    The chkdsk results:
    Log Name: Application
    Source: Microsoft-Windows-Wininit
    Date: 10/31/2010 6:46:40 AM
    Event ID: 1001
    Task Category: None
    Level: Information
    Keywords: Classic
    User: N/A
    Computer: Win764
    Description:

    Checking file system on C:
    The type of the file system is NTFS.

    One of your disks needs to be checked for consistency. You
    may cancel the disk check, but it is strongly recommended
    that you continue.
    Windows will now check the disk.
    CHKDSK is verifying files (stage 1 of 3)...
    532480 file records processed.
    File verification completed.
    579 large file records processed.
    0 bad file records processed.
    2 EA records processed.
    44 reparse records processed.
    CHKDSK is verifying indexes (stage 2 of 3)...
    648458 index entries processed.
    Index verification completed.
    CHKDSK is scanning unindexed files for reconnect to their original directory.
    1 unindexed files scanned.
    CHKDSK is recovering remaining unindexed files.
    1 unindexed files recovered.
    CHKDSK is verifying security descriptors (stage 3 of 3)...
    532480 file SDs/SIDs processed.
    Cleaning up 159 unused index entries from index $SII of file 0x9.
    Cleaning up 159 unused index entries from index $SDH of file 0x9.
    Cleaning up 159 unused security descriptors.
    Security descriptor verification completed.
    57990 data files processed.
    CHKDSK is verifying Usn Journal...
    33912800 USN bytes processed.
    Usn Journal verification completed.
    Correcting errors in the master file table's (MFT) BITMAP attribute.
    CHKDSK discovered free space marked as allocated in the volume bitmap.
    Windows has made corrections to the file system.
    502629375 KB total disk space.
    179578276 KB in 446018 files.
    232452 KB in 57992 indexes.
    0 KB in bad sectors.
    649411 KB in use by the system.
    65536 KB occupied by the log file.
    322169236 KB available on disk.
    4096 bytes in each allocation unit.
    125657343 total allocation units on disk.
    80542309 allocation units available on disk.
    Internal Info:
    00 20 08 00 d0 b0 07 00 0b f2 0d 00 00 00 00 00 . ..............
    9d 06 00 00 2c 00 00 00 00 00 00 00 00 00 00 00 ....,...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    Windows has finished checking your disk.
    Please wait while your computer restarts.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" EventSourceName="Wininit" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-10-31T13:46:40.000000000Z" />
    <EventRecordID>37135</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>Win764</Computer>
    <Security />
    </System>
    <EventData>
    <Data>
    Checking file system on C:
    The type of the file system is NTFS.

    One of your disks needs to be checked for consistency. You
    may cancel the disk check, but it is strongly recommended
    that you continue.
    Windows will now check the disk.
    CHKDSK is verifying files (stage 1 of 3)...
    532480 file records processed.
    File verification completed.
    579 large file records processed.
    0 bad file records processed.
    2 EA records processed.
    44 reparse records processed.
    CHKDSK is verifying indexes (stage 2 of 3)...
    648458 index entries processed.
    Index verification completed.
    CHKDSK is scanning unindexed files for reconnect to their original directory.
    1 unindexed files scanned.
    CHKDSK is recovering remaining unindexed files.
    1 unindexed files recovered.
    CHKDSK is verifying security descriptors (stage 3 of 3)...
    532480 file SDs/SIDs processed.
    Cleaning up 159 unused index entries from index $SII of file 0x9.
    Cleaning up 159 unused index entries from index $SDH of file 0x9.
    Cleaning up 159 unused security descriptors.
    Security descriptor verification completed.
    57990 data files processed.
    CHKDSK is verifying Usn Journal...
    33912800 USN bytes processed.
    Usn Journal verification completed.
    Correcting errors in the master file table's (MFT) BITMAP attribute.
    CHKDSK discovered free space marked as allocated in the volume bitmap.
    Windows has made corrections to the file system.
    502629375 KB total disk space.
    179578276 KB in 446018 files.
    232452 KB in 57992 indexes.
    0 KB in bad sectors.
    649411 KB in use by the system.
    65536 KB occupied by the log file.
    322169236 KB available on disk.
    4096 bytes in each allocation unit.
    125657343 total allocation units on disk.
    80542309 allocation units available on disk.
    Internal Info:
    00 20 08 00 d0 b0 07 00 0b f2 0d 00 00 00 00 00 . ..............
    9d 06 00 00 2c 00 00 00 00 00 00 00 00 00 00 00 ....,...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    Windows has finished checking your disk.
    Please wait while your computer restarts.
    </Data>
    </EventData>
    </Event>
      My Computer


  4. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #4

    You are very welcome. The good news is that your hard drive has no bad sectors. Your file system (NTFS file system) had some errors; but they all seem to be corrected. It might be a good idea to run Check Disk now and then as routine maintenance. If you ever start seeinga lot of bad sectors, you will know your hard drive is starting to fail. A few bad sectors, even on a brand new hard drive, is not unusual.

    Have you tried to find the adfs.sys driver on the Adobe site? Here are a couple of links:

    Adobe - Latest Product Updates

    Adobe - Support

    If you can't find an update or find what Adobe program it goes to, skip it for now. We can see if it causes trouble later.
      My Computer


  5. Posts : 8
    Windows 7 Ultimate 64
    Thread Starter
       #5

    Crashing continues


    Hello Carl:

    Happy New Year!
    I got a chance to do a clean install. Slowly adding software, but the BSOD continues. Now is is happening more while working, but also on idle. I cannot pin-point a culprit.
    I ran a new dump file collection that I will post here.

    I have never had issues with computers like this one.
    I built the machine.
    Win 7 x64 original install/purchased
    MSI 790FX-Gd70
    AMD Phenom II x4 965
    nVidia 7800GTX
    8G DDR3 Corsair RAM
    sys 1 yr old.
    OS 1 yr.

    Any help is appreciated.
    Cheers!
    Thank you.
    Don
      My Computer


  6. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #6

    Hi Don, unfortunately you uploaded the .exe file instead of the files it generated. The dump files are not included either; only the perfmon report was included.

    I cannot tell from your perfmon report what version of Eset you have installed. I recommend that you completely uninstall it using this removal tool: Tool. I recommend that until you know your system is stable that you do not install any third party antivirus, firewall, or security program with the exception of Malwarebytes. Install Microsoft Security Essentials and make sure Windows Firewall is turned on. Eset is known to cause BSOD's on some Win 7 systems. You don't anything that is a potential cause of conflicts until you get your system stable.
      My Computer


  7. Posts : 8
    Windows 7 Ultimate 64
    Thread Starter
       #7

    Sorry Carl. Here is another try


    Sorry for that. Thanks for the advice. I will remove eset. Here is another zip file of the dumps.

    Thank you for your help!

    Happy New Year!
    Don
      My Computer


  8. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #8

    Happy New Year, Don. And you are welcome for the help. Thanks for uploading the files.

    I looked at your three most recent dumps. Your dumps show Eset is still loading. This version of Eset generally runs well with Win 7. However, I recommend uninstalling it while you are troubleshooting. I find two out of date drivers loaded on your system. Outdated drivers can and do cause conflicts, memory corruption, and crashes. Your dumps indicate memory corruption. Update these drivers. Either or both could be creating conflicts.
    bcmwl664.sys Thu Mar 26 21:06:57 2009 - Broadcom 802.11g Network Adapter - Dell Wireless 1390 WLAN Mini-Card. Broadcom.com - Downloads & Support.

    Rt64win7.sys Thu Feb 26 04:04:13 2009 - Realtek 8101E/8168/8169 Network Driver Interface Specification 6.20 64-bit Driver. Latest PCIe GBE (GigaBit Ethernet) drivers here: Realtek.
    Update thes drivers, reboot, and see if your system is more stable. Post back and let us know. If you get another BSOD, upload the dump and we will go from there.
    Code:
    Windows 7 Kernel Version 7600 MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
    Machine Name:
    Kernel base = 0xfffff800`02c51000 PsLoadedModuleList = 0xfffff800`02e8ee50
    Debug session time: Wed Dec 29 12:20:52.993 2010 (GMT-5)
    System Uptime: 0 days 1:45:13.710
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ............................
    Loading User Symbols
    Loading unloaded module list
    ....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 50, {fffffa801ba154e0, 0, fffff8800415fd42, 2}
    
    
    Could not read faulting driver name
    Probably caused by : dxgmms1.sys ( dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76 )
    
    Followup: MachineOwner
    ---------
    
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except,
    it must be protected by a Probe.  Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: fffffa801ba154e0, memory referenced.
    Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
    Arg3: fffff8800415fd42, If non-zero, the instruction address which referenced the bad memory
        address.
    Arg4: 0000000000000002, (reserved)
    
    Debugging Details:
    ------------------
    
    
    Could not read faulting driver name
    
    READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef90e0
     fffffa801ba154e0 
    
    FAULTING_IP: 
    dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76
    fffff880`0415fd42 488b01          mov     rax,qword ptr [rcx]
    
    MM_INTERNAL_CODE:  2
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x50
    
    PROCESS_NAME:  System
    
    CURRENT_IRQL:  0
    
    TRAP_FRAME:  fffff880009cf750 -- (.trap 0xfffff880009cf750)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=fffff8a00a24fca0 rbx=0000000000000000 rcx=fffffa801ba154e0
    rdx=fffffa80072fc660 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff8800415fd42 rsp=fffff880009cf8e0 rbp=fffffa80075502f0
     r8=fffffa8006ba1d00  r9=0000000000000000 r10=0000000000000000
    r11=0000000000000024 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei ng nz na pe nc
    dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+0x76:
    fffff880`0415fd42 488b01          mov     rax,qword ptr [rcx] ds:5680:fffffa80`1ba154e0=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002d408f2 to fffff80002cc1740
    
    STACK_TEXT:  
    fffff880`009cf5e8 fffff800`02d408f2 : 00000000`00000050 fffffa80`1ba154e0 00000000`00000000 fffff880`009cf750 : nt!KeBugCheckEx
    fffff880`009cf5f0 fffff800`02cbf82e : 00000000`00000000 fffff8a0`09cd1780 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x40ec0
    fffff880`009cf750 fffff880`0415fd42 : 00000000`ffffd978 00000000`0000000f fffffa80`09562000 fffffa80`09563410 : nt!KiPageFault+0x16e
    fffff880`009cf8e0 fffff880`0415ced3 : 00000000`00000000 fffffa80`06b0c0f8 00000000`00000005 00000000`00000000 : dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+0x76
    fffff880`009cf910 fffff880`0417765d : 00000000`00000000 fffff8a0`0b90f950 fffffa80`00000000 fffffa80`06ba1dd0 : dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+0x43f
    fffff880`009cfae0 fffff880`04177398 : fffff800`00b96080 fffff880`04176d00 fffffa80`00000000 fffffa80`00000000 : dxgmms1!VidSchiSubmitRenderCommand+0x241
    fffff880`009cfcd0 fffff880`04176e96 : 00000000`00000000 fffffa80`095a5d50 00000000`00000080 fffffa80`06a14010 : dxgmms1!VidSchiSubmitQueueCommand+0x50
    fffff880`009cfd00 fffff800`02f65c06 : 00000000`12445a30 fffffa80`06a15680 fffffa80`06a0b040 fffffa80`06a15680 : dxgmms1!VidSchiWorkerThread+0xd6
    fffff880`009cfd40 fffff800`02c9fc26 : fffff800`02e3be80 fffffa80`06a15680 fffff800`02e49c40 fffff880`0123c534 : nt!PspSystemThreadStartup+0x5a
    fffff880`009cfd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76
    fffff880`0415fd42 488b01          mov     rax,qword ptr [rcx]
    
    SYMBOL_STACK_INDEX:  3
    
    SYMBOL_NAME:  dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: dxgmms1
    
    IMAGE_NAME:  dxgmms1.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc578
    
    FAILURE_BUCKET_ID:  X64_0x50_dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76
    
    BUCKET_ID:  X64_0x50_dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForPreparation+76
    
    Followup: MachineOwner
    ---------
    
    Debug session time: Thu Dec 30 14:46:20.835 2010 (GMT-5)
    System Uptime: 0 days 0:22:22.552
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ............................
    Loading User Symbols
    Loading unloaded module list
    ....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 50, {ffffffffffffffff, 8, ffffffffffffffff, 0}
    
    
    Could not read faulting driver name
    Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+42837 )
    
    Followup: MachineOwner
    ---------
    
    1: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced.  This cannot be protected by try-except,
    it must be protected by a Probe.  Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: ffffffffffffffff, memory referenced.
    Arg2: 0000000000000008, value 0 = read operation, 1 = write operation.
    Arg3: ffffffffffffffff, If non-zero, the instruction address which referenced the bad memory
        address.
    Arg4: 0000000000000000, (reserved)
    
    Debugging Details:
    ------------------
    
    
    Could not read faulting driver name
    
    WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030b70e0
     ffffffffffffffff 
    
    FAULTING_IP: 
    +55bc952f01b0dc88
    ffffffff`ffffffff ??              ???
    
    MM_INTERNAL_CODE:  0
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x50
    
    PROCESS_NAME:  MemeoBackup.ex
    
    CURRENT_IRQL:  0
    
    TRAP_FRAME:  fffff8800a7e1960 -- (.trap 0xfffff8800a7e1960)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8006b921c0
    rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
    rip=ffffffffffffffff rsp=fffff8800a7e1af0 rbp=fffff8800a7e1ca0
     r8=0000000000000000  r9=fffff880009e9180 r10=fffffa8006a3fe00
    r11=fffffa8006a8a010 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei ng nz na po nc
    ffffffff`ffffffff ??              ???
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002efff14 to fffff80002e7f740
    
    STACK_TEXT:  
    fffff880`0a7e17f8 fffff800`02efff14 : 00000000`00000050 ffffffff`ffffffff 00000000`00000008 fffff880`0a7e1960 : nt!KeBugCheckEx
    fffff880`0a7e1800 fffff800`02e7d82e : 00000000`00000008 fffffa80`06b921c0 fffffa80`06a8a000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x42837
    fffff880`0a7e1960 ffffffff`ffffffff : fffff800`02e848b4 fffff800`0313a9af fffff880`00000001 fffff880`0a7e1b68 : nt!KiPageFault+0x16e
    fffff880`0a7e1af0 fffff800`02e848b4 : fffff800`0313a9af fffff880`00000001 fffff880`0a7e1b68 fffff880`0a7e1b60 : 0xffffffff`ffffffff
    fffff880`0a7e1af8 ffffffff`f70f2e80 : fffffa80`06b921c0 fffffa80`06a8a0b8 00000000`7333773a 00000000`02c56ad8 : nt!ObfDereferenceObject+0xd4
    fffff880`0a7e1b58 fffffa80`06b921c0 : fffffa80`06a8a0b8 00000000`7333773a 00000000`02c56ad8 00000000`00000000 : 0xffffffff`f70f2e80
    fffff880`0a7e1b60 fffffa80`06a8a0b8 : 00000000`7333773a 00000000`02c56ad8 00000000`00000000 00000000`0000002a : 0xfffffa80`06b921c0
    fffff880`0a7e1b68 00000000`7333773a : 00000000`02c56ad8 00000000`00000000 00000000`0000002a 00000000`7ef95000 : 0xfffffa80`06a8a0b8
    fffff880`0a7e1b70 00000000`02c56ad8 : 00000000`00000000 00000000`0000002a 00000000`7ef95000 00000000`06c9ef50 : 0x7333773a
    fffff880`0a7e1b78 00000000`00000000 : 00000000`0000002a 00000000`7ef95000 00000000`06c9ef50 00000000`06c9fd20 : 0x2c56ad8
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt! ?? ::FNODOBFM::`string'+42837
    fffff800`02efff14 cc              int     3
    
    SYMBOL_STACK_INDEX:  1
    
    SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+42837
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9
    
    FAILURE_BUCKET_ID:  X64_0x50_nt!_??_::FNODOBFM::_string_+42837
    
    BUCKET_ID:  X64_0x50_nt!_??_::FNODOBFM::_string_+42837
    
    Followup: MachineOwner
    ---------
    
    Debug session time: Thu Dec 30 11:57:50.403 2010 (GMT-5)
    System Uptime: 0 days 3:32:11.120
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ............................
    Loading User Symbols
    Loading unloaded module list
    ....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 3B, {c0000005, fffff80002f85b1f, fffff88006c8fcb0, 0}
    
    Probably caused by : memory_corruption ( nt!MiIdentifyPfn+26f )
    
    Followup: MachineOwner
    ---------
    
    2: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff80002f85b1f, Address of the exception record for the exception that caused the bugcheck
    Arg3: fffff88006c8fcb0, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    
    Debugging Details:
    ------------------
    
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    FAULTING_IP: 
    nt!MiIdentifyPfn+26f
    fffff800`02f85b1f f0410fba6e481f  lock bts dword ptr [r14+48h],1Fh
    
    CONTEXT:  fffff88006c8fcb0 -- (.cxr 0xfffff88006c8fcb0)
    rax=0000000000000001 rbx=02000000000c4f0a rcx=0000000000000020
    rdx=00000000001e130d rsi=0000000000000000 rdi=fffffa8006e1f7c0
    rip=fffff80002f85b1f rsp=fffff88006c90680 rbp=fffffa8006cc0050
     r8=00000000001e130e  r9=0000000000000001 r10=0000000000000042
    r11=0000058000000000 r12=fffff88002f64180 r13=0000000000000000
    r14=004d005c00730065 r15=0000000000000000
    iopl=0         nv up ei pl nz na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
    nt!MiIdentifyPfn+0x26f:
    fffff800`02f85b1f f0410fba6e481f  lock bts dword ptr [r14+48h],1Fh ds:002b:004d005c`007300ad=????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0x3B
    
    PROCESS_NAME:  svchost.exe
    
    CURRENT_IRQL:  2
    
    LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff80002f85b1f
    
    STACK_TEXT:  
    fffff880`06c90680 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiIdentifyPfn+0x26f
    
    
    FOLLOWUP_IP: 
    nt!MiIdentifyPfn+26f
    fffff800`02f85b1f f0410fba6e481f  lock bts dword ptr [r14+48h],1Fh
    
    SYMBOL_STACK_INDEX:  0
    
    SYMBOL_NAME:  nt!MiIdentifyPfn+26f
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9
    
    STACK_COMMAND:  .cxr 0xfffff88006c8fcb0 ; kb
    
    IMAGE_NAME:  memory_corruption
    
    FAILURE_BUCKET_ID:  X64_0x3B_nt!MiIdentifyPfn+26f
    
    BUCKET_ID:  X64_0x3B_nt!MiIdentifyPfn+26f
    
    Followup: MachineOwner
    ---------
    
    2: kd> lmtsmn
    start             end                 module name
    fffff880`04000000 fffff880`0403e000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
    fffff880`00efc000 fffff880`00f53000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
    fffff880`02c4f000 fffff880`02cd9000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`04400000 fffff880`04416000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
    fffff880`03e26000 fffff880`03e3b000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    fffff880`00ec0000 fffff880`00ecb000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
    fffff880`00e8d000 fffff880`00e96000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00e96000 fffff880`00ec0000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
    fffff880`04805000 fffff880`04ffa000   atikmdag atikmdag.sys Tue Oct 26 22:29:53 2010 (4CC78EA1)
    fffff880`03e3b000 fffff880`03e86000   atikmpag atikmpag.sys Tue Oct 26 22:14:23 2010 (4CC78AFF)
    fffff960`00830000 fffff960`00891000   ATMFD    ATMFD.DLL    Tue Oct 19 23:05:45 2010 (4CBE5C89)
    fffff880`00fc4000 fffff880`00fd0000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
    fffff880`04489000 fffff880`045cd000   bcmwl664 bcmwl664.sys Thu Mar 26 21:06:57 2009 (49CC26B1)
    fffff880`01950000 fffff880`01957000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
    fffff880`03fe3000 fffff880`03ff4000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
    fffff880`063b0000 fffff880`063ce000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
    fffff960`00720000 fffff960`00747000   cdd      cdd.dll      unavailable (00000000)
    fffff880`01907000 fffff880`01931000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00c00000 fffff880`00cc0000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
    fffff880`018a1000 fffff880`018d1000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00cf4000 fffff880`00d52000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01000000 fffff880`01073000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
    fffff880`00fbb000 fffff880`00fc4000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`045e3000 fffff880`045f3000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`051e7000 fffff880`051f5000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
    fffff880`03f42000 fffff880`03fc5000   csc      csc.sys      Mon Jul 13 19:24:26 2009 (4A5BC22A)
    fffff880`03fc5000 fffff880`03fe3000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
    fffff880`03f33000 fffff880`03f42000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
    fffff880`0188b000 fffff880`018a1000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`051bf000 fffff880`051e1000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
    fffff880`0500c000 fffff880`05015000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`05000000 fffff880`0500c000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`05015000 fffff880`05028000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    fffff880`05028000 fffff880`05034000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
    fffff880`04070000 fffff880`04164000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
    fffff880`04164000 fffff880`041aa000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
    fffff880`038d2000 fffff880`039a9000   eamonm   eamonm.sys   Wed Jul 14 04:13:43 2010 (4C3D71B7)
    fffff880`01957000 fffff880`0197c000   ehdrv    ehdrv.sys    Wed Jul 14 04:14:21 2010 (4C3D71DD)
    fffff880`0387e000 fffff880`0389f000   epfwwfpr epfwwfpr.sys Wed Jul 14 04:10:34 2010 (4C3D70FA)
    fffff880`0629e000 fffff880`062d4000   fastfat  fastfat.SYS  Mon Jul 13 19:23:28 2009 (4A5BC1F0)
    fffff880`0112d000 fffff880`01141000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
    fffff880`010e1000 fffff880`0112d000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
    fffff880`013d6000 fffff880`013e0000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
    fffff880`01851000 fffff880`0188b000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
    fffff880`01073000 fffff880`010bd000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
    fffff800`02e1a000 fffff800`02e63000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
    fffff880`041aa000 fffff880`041ce000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
    fffff880`05126000 fffff880`05182000   HdAudio  HdAudio.sys  Mon Jul 13 20:06:59 2009 (4A5BCC23)
    fffff880`051f5000 fffff880`05200000   HidBatt  HidBatt.sys  Mon Jul 13 19:31:06 2009 (4A5BC3BA)
    fffff880`0182b000 fffff880`01844000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
    fffff880`05050000 fffff880`05058080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
    fffff880`05042000 fffff880`05050000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
    fffff880`062e8000 fffff880`063b0000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
    fffff880`014b5000 fffff880`014be000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
    fffff880`02c1a000 fffff880`02c29000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`02c38000 fffff880`02c46000   kbdhid   kbdhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff800`00b9a000 fffff800`00ba4000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
    fffff880`05062000 fffff880`050a5000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
    fffff880`013ab000 fffff880`013c5000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
    fffff880`01460000 fffff880`0148b000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
    fffff880`051e1000 fffff880`051e6200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
    fffff880`039ca000 fffff880`039df000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`010bd000 fffff880`010e0000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
    fffff880`00cd3000 fffff880`00ce0000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
    fffff880`05034000 fffff880`05042000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
    fffff880`02c29000 fffff880`02c38000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`018ee000 fffff880`018fb000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff880`00e73000 fffff880`00e8d000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`01931000 fffff880`01947000   mozy     mozy.sys     Mon Nov 08 17:38:55 2010 (4CD87BFF)
    fffff880`063ce000 fffff880`063e6000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
    fffff880`06200000 fffff880`0622d000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
    fffff880`0622d000 fffff880`0627b000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
    fffff880`0627b000 fffff880`0629e000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
    fffff880`019da000 fffff880`019e5000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00f5c000 fffff880`00f66000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
    fffff880`0114d000 fffff880`011ab000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
    fffff880`03f28000 fffff880`03f33000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
    fffff880`014a3000 fffff880`014b5000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
    fffff880`014d2000 fffff880`015c4000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`045f3000 fffff880`045ff000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
    fffff880`03853000 fffff880`03866000   ndisuio  ndisuio.sys  Mon Jul 13 20:09:25 2009 (4A5BCCB5)
    fffff880`03e86000 fffff880`03eb5000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`05111000 fffff880`05126000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
    fffff880`02d63000 fffff880`02d72000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`02cd9000 fffff880`02d1e000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
    fffff880`01400000 fffff880`01460000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
    fffff880`019e5000 fffff880`019f6000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`03f1c000 fffff880`03f28000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
    fffff800`02e63000 fffff800`0343f000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
    fffff880`01208000 fffff880`013ab000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
    fffff880`01947000 fffff880`01950000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
    fffff880`03800000 fffff880`03853000   nwifi    nwifi.sys    Mon Jul 13 20:07:23 2009 (4A5BCC3B)
    fffff880`02d27000 fffff880`02d4d000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
    fffff880`00fa6000 fffff880`00fbb000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00f66000 fffff880`00f99000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`00e5c000 fffff880`00e63000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
    fffff880`00e63000 fffff880`00e73000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`013c5000 fffff880`013d6000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
    fffff880`06e80000 fffff880`06f26000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
    fffff880`05182000 fffff880`051bf000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`00ce0000 fffff880`00cf4000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
    fffff880`01141000 fffff880`0114ce00   PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253)
    fffff880`04049000 fffff880`0406d000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`02dbe000 fffff880`02dd9000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
    fffff880`02dd9000 fffff880`02dfa000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
    fffff880`02c00000 fffff880`02c1a000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
    fffff880`03ecb000 fffff880`03f1c000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
    fffff880`03eb5000 fffff880`03ec0000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
    fffff880`019bf000 fffff880`019c8000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`019c8000 fffff880`019d1000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`019d1000 fffff880`019da000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
    fffff880`015c4000 fffff880`015fe000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
    fffff880`03866000 fffff880`0387e000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`041ce000 fffff880`04200000   Rt64win7 Rt64win7.sys Thu Feb 26 04:04:13 2009 (49A65B0D)
    fffff880`06f26000 fffff880`06f31000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
    fffff880`0447d000 fffff880`04489000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`02d72000 fffff880`02d8f000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
    fffff880`0149b000 fffff880`014a3000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
    fffff880`07ae8000 fffff880`07b59000   spsys    spsys.sys    Mon May 11 13:20:58 2009 (4A085E7A)
    fffff880`07a52000 fffff880`07ae8000   srv      srv.sys      Thu Aug 26 23:38:00 2010 (4C773318)
    fffff880`06f70000 fffff880`06fd7000   srv2     srv2.sys     Thu Aug 26 23:37:46 2010 (4C77330A)
    fffff880`06f31000 fffff880`06f5e000   srvnet   srvnet.sys   Thu Aug 26 23:37:24 2010 (4C7732F4)
    fffff880`0406d000 fffff880`0406e480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
    fffff880`01602000 fffff880`017ff000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
    fffff880`06f5e000 fffff880`06f70000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
    fffff880`0181e000 fffff880`0182b000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
    fffff880`01800000 fffff880`0181e000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
    fffff880`02daa000 fffff880`02dbe000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
    fffff960`005c0000 fffff960`005ca000   TSDDD    TSDDD.dll    Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`03e00000 fffff880`03e26000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
    fffff880`050a5000 fffff880`050b7000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
    fffff880`018d1000 fffff880`018ee000   usbccgp  usbccgp.sys  Mon Jul 13 20:06:45 2009 (4A5BCC15)
    fffff880`05059000 fffff880`0505af00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
    fffff880`0446c000 fffff880`0447d000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`050b7000 fffff880`05111000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
    fffff880`0403e000 fffff880`04049000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`04416000 fffff880`0446c000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`013e0000 fffff880`013fb000   USBSTOR  USBSTOR.SYS  Mon Jul 13 20:06:34 2009 (4A5BCC0A)
    fffff880`00f99000 fffff880`00fa6000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
    fffff880`0197c000 fffff880`0198a000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
    fffff880`0198a000 fffff880`019af000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
    fffff880`0148b000 fffff880`0149b000   vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
    fffff880`00fd0000 fffff880`00fe5000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00e00000 fffff880`00e5c000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
    fffff880`011ab000 fffff880`011f7000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
    fffff880`045cd000 fffff880`045da000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
    fffff880`02d4d000 fffff880`02d63000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
    fffff880`02d8f000 fffff880`02daa000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
    fffff880`019af000 fffff880`019bf000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
    fffff880`00d52000 fffff880`00df6000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
    fffff880`00cc0000 fffff880`00ccf000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`02d1e000 fffff880`02d27000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff960`000c0000 fffff960`003d0000   win32k   win32k.sys   Tue Oct 19 23:08:46 2010 (4CBE5D3E)
    fffff880`045da000 fffff880`045e3000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`00f53000 fffff880`00f5c000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`039a9000 fffff880`039ca000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)
    
    Unloaded modules:
    fffff880`018d1000 fffff880`018df000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`018df000 fffff880`018eb000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`018eb000 fffff880`018f4000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`018f4000 fffff880`01907000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
      My Computer


  9. Posts : 8
    Windows 7 Ultimate 64
    Thread Starter
       #9

    Saga contines...


    Hello Carl,
    I'm back and still lost. I removed Eset, I removed Mozy, I removed my Broadcom card and updated everything I could update. One problem is I must keep on working on my machine and have just been dealing with the crashes.

    About to give up. Throw in the towel.
    I'll attach the dump file.

    Any suggestions are greatly appreciated.
    Thanks,
    Don

    My latest checkdsk:
    The type of the file system is NTFS.


    One of your disks needs to be checked for consistency. You
    may cancel the disk check, but it is strongly recommended
    that you continue.
    Windows will now check the disk.

    CHKDSK is verifying files (stage 1 of 3)...
    211968 file records processed. File verification completed.
    356 large file records processed. 0 bad file records processed. 2 EA records processed. 44 reparse records processed. CHKDSK is verifying indexes (stage 2 of 3)...
    280468 index entries processed. Index verification completed.
    0 unindexed files scanned. 0 unindexed files recovered. CHKDSK is verifying security descriptors (stage 3 of 3)...
    211968 file SDs/SIDs processed. Cleaning up 364 unused index entries from index $SII of file 0x9.
    Cleaning up 364 unused index entries from index $SDH of file 0x9.
    Cleaning up 364 unused security descriptors.
    Security descriptor verification completed.
    34251 data files processed. CHKDSK is verifying Usn Journal...
    33889408 USN bytes processed. Usn Journal verification completed.
    Windows has checked the file system and found no problems.

    502629375 KB total disk space.
    63919304 KB in 176936 files.
    95612 KB in 34252 indexes.
    0 KB in bad sectors.
    327155 KB in use by the system.
    65536 KB occupied by the log file.
    438287304 KB available on disk.

    4096 bytes in each allocation unit.
    125657343 total allocation units on disk.
    109571826 allocation units available on disk.

    Internal Info:
    00 3c 03 00 ff 38 03 00 d6 f9 05 00 00 00 00 00 .<...8..........
    30 01 00 00 2c 00 00 00 00 00 00 00 00 00 00 00 0...,...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

    Windows has finished checking your disk.
    Please wait while your computer restarts.
      My Computer


  10. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #10

    Don, your had drive looks fine. Check Disk made a few repairs to the file system and you have no bad sectors. I looked at your four most recent dumps; each has a different error code. The usually indicates a hardware/hardware related problem. All for dumps indicate memory corruption. By the way, your latest dump show that Eset is still loading. Did you run the removal tool: Tool.

    I suggest that you rest your RAM with Memtest. Follow the instructions in this tutorial:
    RAM - Test with Memtest86+. Run Memtest from a cold boot after your computer has been off for an hour or two. Let it run for a minimum of seven passes. This will take 6-8 hours. If you see any errors, you can stop Memtest. Post back with your results.

    If you get no errors with Memtest, enable Driver Verifier. Carefully follow the instructions in this tutorial: Driver Verifier - Enable and Disable. Use your computer normally while Verifier is running. Upload any and all Driver Verifier enabled dump files.
    Code:
    Windows 7 Kernel Version 7600 MP (4 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
    Machine Name:
    Kernel base = 0xfffff800`02e0b000 PsLoadedModuleList = 0xfffff800`03048e50
    Debug session time: Sun Jan  9 08:43:27.275 2011 (GMT-5)
    System Uptime: 0 days 0:17:45.993
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..............................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck D1, {1, 2, 0, fffff88001683e79}
    
    *** WARNING: Unable to verify timestamp for win32k.sys
    *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
    Probably caused by : memory_corruption
    
    Followup: memory_corruption
    ---------
    
    2: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: 0000000000000001, memory referenced
    Arg2: 0000000000000002, IRQL
    Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
    Arg4: fffff88001683e79, address which referenced memory
    
    Debugging Details:
    ------------------
    
    
    READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030b30e0
     0000000000000001 
    
    CURRENT_IRQL:  2
    
    FAULTING_IP: 
    tcpip!TcpMppQuerySynDropRate+121
    fffff880`01683e79 488b00          mov     rax,qword ptr [rax]
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  CODE_CORRUPTION
    
    BUGCHECK_STR:  0xD1
    
    PROCESS_NAME:  System
    
    TRAP_FRAME:  fffff8800318b710 -- (.trap 0xfffff8800318b710)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=0000000000000001 rbx=0000000000000000 rcx=fffffa8006a4ede0
    rdx=fffffa8007839fe0 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff88001683e79 rsp=fffff8800318b8a0 rbp=fffffa800789b190
     r8=fffff8800318b928  r9=000000000001a096 r10=fffff88006593920
    r11=000000038e2674bd r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei pl nz na pe nc
    tcpip!TcpMppQuerySynDropRate+0x121:
    fffff880`01683e79 488b00          mov     rax,qword ptr [rax] ds:1010:00000000`00000001=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002e7aca9 to fffff80002e7b740
    
    STACK_TEXT:  
    fffff880`0318b5c8 fffff800`02e7aca9 : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
    fffff880`0318b5d0 fffff800`02e79920 : fffff880`0318b701 00000000`00000001 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
    fffff880`0318b710 fffff880`01683e79 : fffffa80`079fa000 fffff880`01673459 fffffa80`092caa78 00000002`7b61a0bd : nt!KiPageFault+0x260
    fffff880`0318b8a0 fffff880`0170b6b9 : fffffa80`07839fd0 fffffa80`0789b190 fffffa80`078c49e0 fffffa80`0789b190 : tcpip!TcpMppQuerySynDropRate+0x121
    fffff880`0318b8f0 fffff880`0167b277 : fffffa80`078c49e0 fffffa80`00000000 fffffa80`079fa000 fffff880`0165e77a : tcpip!TcpEnterReceiveDpc+0xc9
    fffff880`0318b920 fffff880`0165d6c7 : fffffa80`079fa000 fffffa80`0789b190 fffffa80`078c49e0 00000000`00000000 : tcpip!TcpPreValidatedReceive+0x37
    fffff880`0318b9d0 fffff880`0165d799 : fffff880`0318bb50 fffff880`0176b9a0 fffff880`0318bb60 00000000`00009e0c : tcpip!IppDeliverListToProtocol+0x97
    fffff880`0318ba90 fffff880`0165dc90 : fffffa80`073bf290 fffffa80`0a9dc300 00000000`00000011 fffff880`0318bb50 : tcpip!IppProcessDeliverList+0x59
    fffff880`0318bb00 fffff880`0165cb21 : 00000000`00000000 fffffa80`079fa000 fffff880`0176b9a0 00000000`098d9901 : tcpip!IppReceiveHeaderBatch+0x231
    fffff880`0318bbe0 fffff880`0165b592 : fffffa80`098c48a0 00000000`00000000 fffffa80`098d9901 00000000`00000001 : tcpip!IpFlcReceivePackets+0x651
    fffff880`0318bde0 fffff880`01674e5a : fffffa80`098d9920 fffff880`0318bf10 fffffa80`098d9920 00000000`00000000 : tcpip!FlpReceiveNonPreValidatedNetBufferListChain+0x2b2
    fffff880`0318bec0 fffff800`02e8ae5a : fffffa80`073bf290 fffff880`03187000 00000000`00004800 00000000`00000000 : tcpip!FlReceiveNetBufferListChainCalloutRoutine+0xda
    fffff880`0318bf10 fffff880`01674882 : fffff880`01674d80 fffff880`0318c020 00000000`00000002 00000000`00000000 : nt!KeExpandKernelStackAndCalloutEx+0xda
    fffff880`0318bff0 fffff880`015280eb : fffffa80`098d6010 00000000`00000000 fffffa80`086f21a0 fffffa80`086f21a0 : tcpip!FlReceiveNetBufferListChain+0xb2
    fffff880`0318c060 fffff880`014f1fc6 : fffff8a0`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ndis!ndisMIndicateNetBufferListsToOpen+0xdb
    fffff880`0318c0d0 fffff880`01474a24 : fffffa80`086f21a0 00000000`00000002 00000000`00000001 fffffa80`073bf290 : ndis!ndisMDispatchReceiveNetBufferLists+0x1d6
    fffff880`0318c550 fffff880`014749e9 : 00000000`00000000 00000000`00000000 fffffa80`098e7680 00000000`00000001 : ndis!ndisMTopReceiveNetBufferLists+0x24
    fffff880`0318c590 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ndis!ndisFilterIndicateReceiveNetBufferLists+0x29
    
    
    STACK_COMMAND:  kb
    
    CHKIMG_EXTENSION: !chkimg -lo 50 -db !tcpip
    7 errors : !tcpip (fffff88001683e43-fffff88001683e7b)
    fffff88001683e40  8b  c8  41 *00  07  4c  8d  05  14  68  10  00  48  8b  c1  48 ..A..L...h..H..H
    fffff88001683e50  23  c6  48 *00  c0  41  8b  44  c0  08  41 *00  06  3b  d1  75 #.H..A.D..A..;.u
    fffff88001683e60  d2  41  0f *00  06  48  8b  6c  24  58  44 *00  eb  0f  95  c3 .A...H.l$XD.....
    fffff88001683e70  66  89  47 *00  83  27  fe  23  de  48  8b *00  24  60  09  1f f.G..'.#.H..$`..
    
    MODULE_NAME: memory_corruption
    
    IMAGE_NAME:  memory_corruption
    
    FOLLOWUP_NAME:  memory_corruption
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
    
    MEMORY_CORRUPTOR:  STRIDE
    
    FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_STRIDE
    
    BUCKET_ID:  X64_MEMORY_CORRUPTION_STRIDE
    
    Followup: memory_corruption
    ---------
    
    Debug session time: Mon Jan 10 09:27:27.768 2011 (GMT-5)
    System Uptime: 0 days 1:12:47.484
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ................................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 1A, {41284, fffff98006e50001, 51e0, fffff780c0000000}
    
    Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a83 )
    
    Followup: MachineOwner
    ---------
    
    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    MEMORY_MANAGEMENT (1a)
        # Any other values for parameter 1 must be individually examined.
    Arguments:
    Arg1: 0000000000041284, A PTE or the working set list is corrupt.
    Arg2: fffff98006e50001
    Arg3: 00000000000051e0
    Arg4: fffff780c0000000
    
    Debugging Details:
    ------------------
    
    
    BUGCHECK_STR:  0x1a_41284
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    PROCESS_NAME:  MemeoBackup.ex
    
    CURRENT_IRQL:  0
    
    LAST_CONTROL_TRANSFER:  from fffff80002f2d3b3 to fffff80002ed8740
    
    STACK_TEXT:  
    fffff880`0aaad268 fffff800`02f2d3b3 : 00000000`0000001a 00000000`00041284 fffff980`06e50001 00000000`000051e0 : nt!KeBugCheckEx
    fffff880`0aaad270 fffff800`02e7c157 : 00000000`000051e0 fffff880`0aaad3c0 fffffa80`00a018e0 fffff880`0aaad3b8 : nt! ?? ::FNODOBFM::`string'+0x4a83
    fffff880`0aaad2b0 fffff800`031ef1b5 : fffff980`06e50000 fffff8a0`03638b90 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x2be88
    fffff880`0aaad590 fffff800`02ef1567 : 00000000`8e300000 fffffa80`069f27b0 00000000`00000000 00000000`8e400000 : nt!CcUnmapVacb+0x5d
    fffff880`0aaad5d0 fffff800`02ef73b5 : fffff980`00000001 00000000`8dc00000 fffffa80`06ca0e10 00000000`00000001 : nt!CcUnmapVacbArray+0x1b7
    fffff880`0aaad660 fffff800`031f5922 : 00000000`8dc00000 00000000`8e400000 fffff880`0aaad730 fffff880`0aaad7c0 : nt!CcGetVirtualAddress+0x2c5
    fffff880`0aaad6f0 fffff880`012c9c48 : fffff880`00000000 00000000`00000005 fffffa80`08745e60 fffffa80`00001001 : nt!CcCopyRead+0x132
    fffff880`0aaad7b0 fffff880`010480c8 : fffffa80`0743e320 fffffa80`08745df8 fffffa80`0743e370 fffffa80`0743e301 : Ntfs!NtfsCopyReadA+0x1a8
    fffff880`0aaad980 fffff880`0104bc2a : fffff880`0aaada50 00000000`0a7a2203 00000000`0a7a2200 fffffa80`0743e300 : fltmgr!FltpPerformFastIoCall+0x88
    fffff880`0aaad9e0 fffff880`010695f0 : fffffa80`0743e320 00000000`00000000 fffff880`0aaadb40 00000000`00001000 : fltmgr!FltpPassThroughFastIo+0xda
    fffff880`0aaada20 fffff800`031f6289 : fffffa80`0743e320 fffffa80`00000001 fffffa80`06a19c90 fffffa80`0743e320 : fltmgr!FltpFastIoRead+0x1d0
    fffff880`0aaadac0 fffff800`02ed7993 : 00000000`741d2450 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x417
    fffff880`0aaadbb0 00000000`741d2dd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`0703ee88 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x741d2dd9
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    nt! ?? ::FNODOBFM::`string'+4a83
    fffff800`02f2d3b3 cc              int     3
    
    SYMBOL_STACK_INDEX:  1
    
    SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+4a83
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9
    
    FAILURE_BUCKET_ID:  X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
    
    BUCKET_ID:  X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
    
    Followup: MachineOwner
    ---------
    
    Debug session time: Tue Jan 11 14:12:41.528 2011 (GMT-5)
    System Uptime: 0 days 5:57:22.245
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    .............................
    Loading User Symbols
    Loading unloaded module list
    .....
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck A, {5e44a, 2, 1, fffff80002eee182}
    
    Probably caused by : win32k.sys ( win32k!FreeObject+58 )
    
    Followup: MachineOwner
    ---------
    
    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: 000000000005e44a, memory referenced
    Arg2: 0000000000000002, IRQL
    Arg3: 0000000000000001, bitfield :
        bit 0 : value 0 = read operation, 1 = write operation
        bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
    Arg4: fffff80002eee182, address which referenced memory
    
    Debugging Details:
    ------------------
    
    
    WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff8000310d0e0
     000000000005e44a 
    
    CURRENT_IRQL:  2
    
    FAULTING_IP: 
    nt!MiInsertPageInFreeOrZeroedList+352
    fffff800`02eee182 48894108        mov     qword ptr [rcx+8],rax
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    BUGCHECK_STR:  0xA
    
    PROCESS_NAME:  firefox.exe
    
    TRAP_FRAME:  fffff88008cffa40 -- (.trap 0xfffff88008cffa40)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=fffff680000e480a rbx=0000000000000000 rcx=000000000005e442
    rdx=fffffa8000a0bc68 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff80002eee182 rsp=fffff88008cffbd0 rbp=fffff88008cffc40
     r8=fffff8000304fe80  r9=0000000000000000 r10=fffff8000310f840
    r11=0000058000000000 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up ei pl nz na pe nc
    nt!MiInsertPageInFreeOrZeroedList+0x352:
    fffff800`02eee182 48894108        mov     qword ptr [rcx+8],rax ds:00000000`0005e44a=????????????????
    Resetting default scope
    
    LAST_CONTROL_TRANSFER:  from fffff80002ed4ca9 to fffff80002ed5740
    
    STACK_TEXT:  
    fffff880`08cff8f8 fffff800`02ed4ca9 : 00000000`0000000a 00000000`0005e44a 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
    fffff880`08cff900 fffff800`02ed3920 : 00000000`00000000 00000000`0005e442 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
    fffff880`08cffa40 fffff800`02eee182 : fffff6fb`7e403150 00000000`35122109 00000000`00000000 00000001`00000001 : nt!KiPageFault+0x260
    fffff880`08cffbd0 fffff800`02ecb414 : 00000000`00000000 ffffffff`ffffffff 00000000`00000000 fffff960`001f6c2f : nt!MiInsertPageInFreeOrZeroedList+0x352
    fffff880`08cffcd0 fffff800`02ecad49 : 00000000`00000000 00000000`00000173 fffff900`00000000 00000000`00000000 : nt!MiDeleteSystemPagableVm+0x254
    fffff880`08cffe30 fffff800`0300634f : 00000000`00000000 00000000`00000000 00000000`00000000 fffff880`02853000 : nt!MiFreePagedPoolPages+0x129
    fffff880`08cfff80 fffff800`0300a87c : 00000000`00000000 fffff880`08d00150 fffff880`08d000c0 00000000`00000001 : nt!MiFreePoolPages+0x343
    fffff880`08d00090 fffff960`00134db8 : fffff900`c5400228 fffff880`08d001e0 00000000`35316847 00000000`00000001 : nt!ExFreePoolWithTag+0x7cc
    fffff880`08d00140 fffff960`00135592 : 00000000`00000000 fffff900`c5400000 00000000`00000000 fffff900`c5400228 : win32k!FreeObject+0x58
    fffff880`08d00170 fffff960`00135720 : fffff900`00000000 00000000`00000000 fffff900`c5400000 00000000`00000000 : win32k!SURFACE::bDeleteSurface+0x58a
    fffff880`08d002c0 fffff960`0013c46a : fffff900`c08404f0 fffff900`c5400000 00000000`00000000 00000000`00000000 : win32k!bDeleteSurface+0x34
    fffff880`08d002f0 fffff960`00137a4f : 00000000`23101e52 00000000`00000000 00000000`00000001 fffff900`00000000 : win32k!bDeleteBrush+0x282
    fffff880`08d003a0 fffff960`000ea931 : fffff900`c3b39630 00000000`01900010 00000000`01900010 fffff900`c0000340 : win32k!GreDCSelectBrush+0xc3
    fffff880`08d00410 fffff800`02ed4993 : 00000000`75f66ed8 fffff880`08d00520 00000000`00010000 00000000`77a3f905 : win32k!GreSaveDC+0x75
    fffff880`08d004a0 00000000`731b2dd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`000cd328 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x731b2dd9
    
    
    STACK_COMMAND:  kb
    
    FOLLOWUP_IP: 
    win32k!FreeObject+58
    fffff960`00134db8 488b5c2430      mov     rbx,qword ptr [rsp+30h]
    
    SYMBOL_STACK_INDEX:  8
    
    SYMBOL_NAME:  win32k!FreeObject+58
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: win32k
    
    IMAGE_NAME:  win32k.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4cbe5d3e
    
    FAILURE_BUCKET_ID:  X64_0xA_win32k!FreeObject+58
    
    BUCKET_ID:  X64_0xA_win32k!FreeObject+58
    
    Followup: MachineOwner
    ---------
    
    Debug session time: Tue Jan 11 16:20:49.396 2011 (GMT-5)
    System Uptime: 0 days 1:54:45.112
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    .............................
    Loading User Symbols
    Loading unloaded module list
    ......
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 24, {1904fb, fffff88008cc3308, fffff88008cc2b70, fffff8800121b454}
    
    Probably caused by : Ntfs.sys ( Ntfs!NtfsReleaseFcb+54 )
    
    Followup: MachineOwner
    ---------
    
    2: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    NTFS_FILE_SYSTEM (24)
        If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
        parameters are the exception record and context record. Do a .cxr
        on the 3rd parameter and then kb to obtain a more informative stack
        trace.
    Arguments:
    Arg1: 00000000001904fb
    Arg2: fffff88008cc3308
    Arg3: fffff88008cc2b70
    Arg4: fffff8800121b454
    
    Debugging Details:
    ------------------
    
    
    OVERLAPPED_MODULE: Address regions for 'arusb_win7x' and 'arusb_lhx.sy' overlap
    
    EXCEPTION_RECORD:  fffff88008cc3308 -- (.exr 0xfffff88008cc3308)
    ExceptionAddress: fffff8800121b454 (Ntfs!NtfsReleaseFcb+0x0000000000000054)
       ExceptionCode: c0000005 (Access violation)
      ExceptionFlags: 00000000
    NumberParameters: 2
       Parameter[0]: 0000000000000001
       Parameter[1]: 000000000c000008
    Attempt to write to address 000000000c000008
    
    CONTEXT:  fffff88008cc2b70 -- (.cxr 0xfffff88008cc2b70)
    rax=fffff8a00cb28050 rbx=fffff8a00caee010 rcx=fffffa8006e08e40
    rdx=000000000c000000 rsi=fffffa8008394180 rdi=0000000000000000
    rip=fffff8800121b454 rsp=fffff88008cc3540 rbp=fffffa8006e08e40
     r8=fffff8a00ca3d8a0  r9=fffff8a00ca3d8c0 r10=fffff88008cc35a0
    r11=fffffa8007ae9290 r12=fffffa8006e08e40 r13=fffffa80083bddc0
    r14=0000000000000000 r15=fffffa8008394180
    iopl=0         nv up ei pl zr na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
    Ntfs!NtfsReleaseFcb+0x54:
    fffff880`0121b454 48894208        mov     qword ptr [rdx+8],rax ds:002b:00000000`0c000008=????????????????
    Resetting default scope
    
    CUSTOMER_CRASH_COUNT:  1
    
    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT
    
    PROCESS_NAME:  svchost.exe
    
    CURRENT_IRQL:  0
    
    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    
    EXCEPTION_PARAMETER1:  0000000000000001
    
    EXCEPTION_PARAMETER2:  000000000c000008
    
    WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030f60e0
     000000000c000008 
    
    FOLLOWUP_IP: 
    Ntfs!NtfsReleaseFcb+54
    fffff880`0121b454 48894208        mov     qword ptr [rdx+8],rax
    
    FAULTING_IP: 
    Ntfs!NtfsReleaseFcb+54
    fffff880`0121b454 48894208        mov     qword ptr [rdx+8],rax
    
    BUGCHECK_STR:  0x24
    
    LAST_CONTROL_TRANSFER:  from fffff880012e9fcb to fffff8800121b454
    
    STACK_TEXT:  
    fffff880`08cc3540 fffff880`012e9fcb : fffff8a0`0c83ca90 fffffa80`08394180 00000000`00000000 fffffa80`06e08e40 : Ntfs!NtfsReleaseFcb+0x54
    fffff880`08cc3580 fffff880`0134807d : 00000000`00000001 fffffa80`0c400393 fffff880`08cc3960 fffffa80`0c400393 : Ntfs!NtfsReleaseAllFiles+0x8b
    fffff880`08cc35d0 fffff880`01348dfe : fffffa80`06e08e40 fffffa80`0c4003e0 fffffa80`083bddc0 fffffa80`09172730 : Ntfs!NtfsDefragFileInternal+0x12e7
    fffff880`08cc37a0 fffff880`01308702 : fffff880`00000000 fffffa80`0c7223e0 fffffa80`08394180 fffffa80`083bddc0 : Ntfs!NtfsDefragFile+0x43e
    fffff880`08cc3840 fffff880`012c12ed : fffffa80`06e08e40 00000000`00000000 fffff880`08cc3960 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x1cc89
    fffff880`08cc3880 fffff880`00e0323f : fffff880`08cc39d0 fffffa80`0c4003e0 fffff880`08cc3901 fffffa80`06e08e40 : Ntfs!NtfsFsdFileSystemControl+0x13d
    fffff880`08cc3920 fffff880`00e2291e : fffffa80`083af040 fffffa80`0a29af20 fffffa80`083af000 fffffa80`0c4003e0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
    fffff880`08cc39b0 fffff800`031d9707 : fffffa80`0a29af20 fffff880`08cc3ca0 fffffa80`0c4007c8 fffffa80`0c4003e0 : fltmgr!FltpFsControl+0xee
    fffff880`08cc3a10 fffff800`031a2b1a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
    fffff880`08cc3b40 fffff800`02ebd993 : fffffa80`0abfeb30 00000000`00000001 fffffa80`06e2cb60 fffff800`031d4414 : nt!NtFsControlFile+0x56
    fffff880`08cc3bb0 00000000`771000ea : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
    00000000`013ee5e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771000ea
    
    
    SYMBOL_STACK_INDEX:  0
    
    SYMBOL_NAME:  Ntfs!NtfsReleaseFcb+54
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: Ntfs
    
    IMAGE_NAME:  Ntfs.sys
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc14f
    
    STACK_COMMAND:  .cxr 0xfffff88008cc2b70 ; kb
    
    FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsReleaseFcb+54
    
    BUCKET_ID:  X64_0x24_Ntfs!NtfsReleaseFcb+54
    
    Followup: MachineOwner
    ---------
    
    2: kd> lmtsmn
    start             end                 module name
    fffff880`03ef7000 fffff880`03f35000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
    fffff880`00e4c000 fffff880`00ea3000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
    fffff880`02a00000 fffff880`02a8a000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`03fb4000 fffff880`03fca000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
    fffff880`03e96000 fffff880`03eab000   amdppm   amdppm.sys   Mon Jul 13 19:19:25 2009 (4A5BC0FD)
    fffff880`00ff5000 fffff880`01000000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
    fffff880`0a800000 fffff880`0a90a000   arusb_win7x arusb_win7x.sys Thu Nov 26 03:55:17 2009 (4B0E4275)
    fffff880`0a917000 fffff880`0a922000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
    fffff880`00fc2000 fffff880`00fcb000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00fcb000 fffff880`00ff5000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
    fffff880`0433f000 fffff880`0435f000   AtihdW76 AtihdW76.sys Wed Nov 17 07:02:04 2010 (4CE3C43C)
    fffff880`04625000 fffff880`04e36000   atikmdag atikmdag.sys Thu Nov 25 21:46:44 2010 (4CEF1F94)
    fffff880`03eab000 fffff880`03ef7000   atikmpag atikmpag.sys Thu Nov 25 21:16:47 2010 (4CEF188F)
    fffff960`00860000 fffff960`008c1000   ATMFD    ATMFD.DLL    Tue Oct 19 23:05:45 2010 (4CBE5C89)
    fffff880`00f14000 fffff880`00f20000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
    fffff880`02b01000 fffff880`02b08000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
    fffff880`03c1e000 fffff880`03c2f000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
    fffff880`039c3000 fffff880`039e1000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
    fffff960`00770000 fffff960`00797000   cdd      cdd.dll      unavailable (00000000)
    fffff880`08558000 fffff880`08575000   cdfs     cdfs.sys     Mon Jul 13 19:19:46 2009 (4A5BC112)
    fffff880`02a9d000 fffff880`02ac7000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`00c9c000 fffff880`00d5c000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
    fffff880`01074000 fffff880`010a4000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00c3e000 fffff880`00c9c000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`01125000 fffff880`01198000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
    fffff880`00f0b000 fffff880`00f14000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`03fa4000 fffff880`03fb4000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`043c4000 fffff880`043d2000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
    fffff880`03d6c000 fffff880`03def000   csc      csc.sys      Mon Jul 13 19:24:26 2009 (4A5BC22A)
    fffff880`03c00000 fffff880`03c1e000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
    fffff880`03d5d000 fffff880`03d6c000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
    fffff880`013de000 fffff880`013f4000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`0439c000 fffff880`043be000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
    fffff880`043de000 fffff880`043e7000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`043d2000 fffff880`043de000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`043e7000 fffff880`043fa000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
    fffff880`0425c000 fffff880`04268000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
    fffff880`04e36000 fffff880`04f2a000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
    fffff880`04f2a000 fffff880`04f70000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
    fffff880`03838000 fffff880`0390f000   eamonm   eamonm.sys   Wed Jul 14 04:13:43 2010 (4C3D71B7)
    fffff880`010a7000 fffff880`010bb000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
    fffff880`00e00000 fffff880`00e4c000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
    fffff880`013d4000 fffff880`013de000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
    fffff880`0103a000 fffff880`01074000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
    fffff880`0148b000 fffff880`014d5000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
    fffff880`03f8b000 fffff880`03f98000   GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
    fffff800`02e05000 fffff800`02e4e000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
    fffff880`04f70000 fffff880`04f94000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
    fffff880`04200000 fffff880`0425c000   HdAudio  HdAudio.sys  Mon Jul 13 20:06:59 2009 (4A5BCC23)
    fffff880`03733000 fffff880`0373e000   HidBatt  HidBatt.sys  Mon Jul 13 19:31:06 2009 (4A5BC3BA)
    fffff880`036f6000 fffff880`0370f000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
    fffff880`0370f000 fffff880`03717080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
    fffff880`036e8000 fffff880`036f6000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
    fffff880`03600000 fffff880`036c8000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
    fffff880`014d5000 fffff880`014de000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
    fffff880`03def000 fffff880`03dfe000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`03718000 fffff880`03726000   kbdhid   kbdhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff800`00bd5000 fffff800`00bdf000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
    fffff880`0427b000 fffff880`042be000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
    fffff880`013a9000 fffff880`013c3000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
    fffff880`01460000 fffff880`0148b000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
    fffff880`043be000 fffff880`043c3200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
    fffff880`03930000 fffff880`03945000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`0374c000 fffff880`0376f000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
    fffff880`00c1d000 fffff880`00c2a000   mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
    fffff880`0373e000 fffff880`0374c000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
    fffff880`0426a000 fffff880`04279000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
    fffff880`03726000 fffff880`03733000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
    fffff880`00fa8000 fffff880`00fc2000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`02ac7000 fffff880`02af8000   MpFilter MpFilter.sys Tue Sep 14 20:19:28 2010 (4C901110)
    fffff880`037e0000 fffff880`037f0000   MpNWMon  MpNWMon.sys  Tue Sep 14 20:19:30 2010 (4C901112)
    fffff880`039e1000 fffff880`039f9000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
    fffff880`03800000 fffff880`0382d000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
    fffff880`0376f000 fffff880`037bd000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
    fffff880`037bd000 fffff880`037e0000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
    fffff880`02b66000 fffff880`02b71000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
    fffff880`00eac000 fffff880`00eb6000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
    fffff880`010c7000 fffff880`01125000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
    fffff880`03d52000 fffff880`03d5d000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
    fffff880`015e9000 fffff880`015fb000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
    fffff880`014df000 fffff880`015d1000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
    fffff880`03fee000 fffff880`03ffa000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
    fffff880`03998000 fffff880`039ab000   ndisuio  ndisuio.sys  Mon Jul 13 20:09:25 2009 (4A5BCCB5)
    fffff880`03e00000 fffff880`03e2f000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`0432a000 fffff880`0433f000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
    fffff880`03c9a000 fffff880`03ca9000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff880`02bad000 fffff880`02bf2000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
    fffff880`01400000 fffff880`01460000   NETIO    NETIO.SYS    Thu Apr 08 22:43:59 2010 (4BBE946F)
    fffff880`08543000 fffff880`08558000   NisDrvWFP NisDrvWFP.sys Tue Sep 14 20:20:25 2010 (4C901149)
    fffff880`02b71000 fffff880`02b82000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`03d46000 fffff880`03d52000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
    fffff800`02e4e000 fffff800`0342a000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
    fffff880`01206000 fffff880`013a9000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
    fffff880`02af8000 fffff880`02b01000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
    fffff880`03945000 fffff880`03998000   nwifi    nwifi.sys    Mon Jul 13 20:07:23 2009 (4A5BCC3B)
    fffff880`03c5e000 fffff880`03c84000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
    fffff880`00ef6000 fffff880`00f0b000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
    fffff880`00eb6000 fffff880`00ee9000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`00f91000 fffff880`00f98000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
    fffff880`00f98000 fffff880`00fa8000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
    fffff880`013c3000 fffff880`013d4000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
    fffff880`080fb000 fffff880`081a1000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
    fffff880`0435f000 fffff880`0439c000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
    fffff880`00c2a000 fffff880`00c3e000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
    fffff880`010bb000 fffff880`010c6e00   PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253)
    fffff880`03fca000 fffff880`03fee000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
    fffff880`03e2f000 fffff880`03e4a000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
    fffff880`03e4a000 fffff880`03e6b000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
    fffff880`03e6b000 fffff880`03e85000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
    fffff880`03cf5000 fffff880`03d46000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
    fffff880`03e85000 fffff880`03e90000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
    fffff880`02b4b000 fffff880`02b54000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`02b54000 fffff880`02b5d000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`02b5d000 fffff880`02b66000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
    fffff880`01000000 fffff880`0103a000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
    fffff880`039ab000 fffff880`039c3000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
    fffff880`04f94000 fffff880`04ffa000   Rt64win7 Rt64win7.sys Tue Nov 30 01:01:28 2010 (4CF49338)
    fffff880`081a1000 fffff880`081ac000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
    fffff880`03f98000 fffff880`03fa4000   serenum  serenum.sys  Mon Jul 13 20:00:33 2009 (4A5BCAA1)
    fffff880`03ca9000 fffff880`03cc6000   serial   serial.sys   Mon Jul 13 20:00:40 2009 (4A5BCAA8)
    fffff880`015e1000 fffff880`015e9000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
    fffff880`084ad000 fffff880`08543000   srv      srv.sys      Thu Aug 26 23:38:00 2010 (4C773318)
    fffff880`08000000 fffff880`08067000   srv2     srv2.sys     Thu Aug 26 23:37:46 2010 (4C77330A)
    fffff880`081ac000 fffff880`081d9000   srvnet   srvnet.sys   Thu Aug 26 23:37:24 2010 (4C7732F4)
    fffff880`04279000 fffff880`0427a480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
    fffff880`01603000 fffff880`01800000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
    fffff880`081d9000 fffff880`081eb000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
    fffff880`02ba0000 fffff880`02bad000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
    fffff880`02b82000 fffff880`02ba0000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
    fffff880`03ce1000 fffff880`03cf5000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
    fffff960`00480000 fffff960`0048a000   TSDDD    TSDDD.dll    Mon Jul 13 20:16:34 2009 (4A5BCE62)
    fffff880`03c2f000 fffff880`03c55000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
    fffff880`042be000 fffff880`042d0000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
    fffff880`036c9000 fffff880`036e6000   usbccgp  usbccgp.sys  Mon Jul 13 20:06:45 2009 (4A5BCC15)
    fffff880`036e6000 fffff880`036e7f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
    fffff880`0460b000 fffff880`0461c000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`042d0000 fffff880`0432a000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
    fffff880`04600000 fffff880`0460b000   usbohci  usbohci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
    fffff880`03f35000 fffff880`03f8b000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
    fffff880`00ee9000 fffff880`00ef6000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
    fffff880`02b08000 fffff880`02b16000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
    fffff880`02b16000 fffff880`02b3b000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
    fffff880`015d1000 fffff880`015e1000   vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
    fffff880`00f20000 fffff880`00f35000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
    fffff880`00f35000 fffff880`00f91000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
    fffff880`01198000 fffff880`011e4000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
    fffff880`0a90a000 fffff880`0a917000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
    fffff880`03c84000 fffff880`03c9a000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
    fffff880`03cc6000 fffff880`03ce1000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
    fffff880`02b3b000 fffff880`02b4b000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
    fffff880`00d5c000 fffff880`00e00000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
    fffff880`00c00000 fffff880`00c0f000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
    fffff880`02bf2000 fffff880`02bfb000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
    fffff960`00050000 fffff960`00360000   win32k   win32k.sys   Tue Oct 19 23:08:46 2010 (4CBE5D3E)
    fffff880`0461c000 fffff880`04625000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
    fffff880`00ea3000 fffff880`00eac000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
    fffff880`0390f000 fffff880`03930000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)
    
    Unloaded modules:
    fffff880`0a865000 fffff880`0a917000   arusb_lhx.sy
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`08575000 fffff880`085e6000   spsys.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`011e4000 fffff880`011f2000   crashdmp.sys
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`013f4000 fffff880`01400000   dump_ataport
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`011f2000 fffff880`011fb000   dump_atapi.s
        Timestamp: unavailable (00000000)
        Checksum:  00000000
    fffff880`02a8a000 fffff880`02a9d000   dump_dumpfve
        Timestamp: unavailable (00000000)
        Checksum:  00000000
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:33.
Find Us