Code:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0301f000 PsLoadedModuleList = 0xfffff800`0325ce50
Debug session time: Tue Jan 18 15:32:23.401 2011 (GMT-5)
System Uptime: 0 days 0:10:20.806
Loading Kernel Symbols
...............................................................
................................................................
..........................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff8000301f005, 1, 0}
Probably caused by : memory_corruption ( nt!MmIsSessionAddress <PERF> (nt+0x5)+0 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000301f005, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MmIsSessionAddress <PERF> (nt+0x5)+0
fffff800`0301f005 0000 add byte ptr [rax],al
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800032c70e0
0000000000000000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: cfp.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff880093919e8 -- (.exr 0xfffff880093919e8)
ExceptionAddress: fffff8000301f005 (nt!MmIsSessionAddress <PERF> (nt+0x5))
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
TRAP_FRAME: fffff88009391a90 -- (.trap 0xfffff88009391a90)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=000000000202da30
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000301f005 rsp=fffff88009391c20 rbp=fffff88009391ca0
r8=fffffa8007fa0060 r9=0000000000000020 r10=fffff8000308e993
r11=fffff88009391c10 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!MmIsSessionAddress <PERF> (nt+0x5):
fffff800`0301f005 0000 add byte ptr [rax],al ds:0001:00000000`00000000=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030c9a39 to fffff8000308f740
STACK_TEXT:
fffff880`09391218 fffff800`030c9a39 : 00000000`0000001e ffffffff`c0000005 fffff800`0301f005 00000000`00000001 : nt!KeBugCheckEx
fffff880`09391220 fffff800`0308ed82 : fffff880`093919e8 fffffa80`07fa0060 fffff880`09391a90 fffff800`0301f000 : nt!KiDispatchException+0x1b9
fffff880`093918b0 fffff800`0308d8fa : 00000000`00000001 fffffa80`07fa0060 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`09391a90 fffff800`0301f005 : fffffa80`07fa0060 00000000`00000002 00000000`00000020 fffffa80`00000000 : nt!KiPageFault+0x23a
fffff880`09391c20 fffffa80`07fa0060 : 00000000`00000002 00000000`00000020 fffffa80`00000000 00000000`00000000 : nt!MmIsSessionAddress <PERF> (nt+0x5)
fffff880`09391c28 00000000`00000002 : 00000000`00000020 fffffa80`00000000 00000000`00000000 00001fa0`02080000 : 0xfffffa80`07fa0060
fffff880`09391c30 00000000`00000020 : fffffa80`00000000 00000000`00000000 00001fa0`02080000 00000000`0206d600 : 0x2
fffff880`09391c38 fffffa80`00000000 : 00000000`00000000 00001fa0`02080000 00000000`0206d600 00000000`0202da30 : 0x20
fffff880`09391c40 00000000`00000000 : 00001fa0`02080000 00000000`0206d600 00000000`0202da30 00000000`00000001 : 0xfffffa80`00000000
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MmIsSessionAddress <PERF> (nt+0x5)+0
fffff800`0301f005 0000 add byte ptr [rax],al
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MmIsSessionAddress <PERF> (nt+0x5)+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!MmIsSessionAddress__PERF__(nt+0x5)+0
BUCKET_ID: X64_0x1E_nt!MmIsSessionAddress__PERF__(nt+0x5)+0
Followup: MachineOwner
---------
Debug session time: Fri Jan 21 14:29:25.190 2011 (GMT-5)
System Uptime: 0 days 3:00:28.969
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000096, fffff8000309cf98, fffff880086640d0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KeInsertQueueApc+2c )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000096, Exception code that caused the bugcheck
Arg2: fffff8000309cf98, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff880086640d0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'ENG64' and 'ENG64.SYS' overlap
EXCEPTION_CODE: (NTSTATUS) 0xc0000096 - {EXCEPTION} Privileged instruction.
FAULTING_IP:
nt!KeInsertQueueApc+2c
fffff800`0309cf98 440f20c5 mov rbp,cr8
CONTEXT: fffff880086640d0 -- (.cxr 0xfffff880086640d0)
rax=000000006c4ff025 rbx=fffffa80079a5b60 rcx=fffffa8003f60cd0
rdx=0000000002b5f890 rsi=fffff800031f0e80 rdi=fffffa8003f60cd0
rip=fffff8000309cf98 rsp=fffff88008664aa0 rbp=fffffffe2a527b60
r8=0000000000000000 r9=0000000000000000 r10=fffff88002f63c40
r11=0000000000000010 r12=000000006c4ff025 r13=0000000000000000
r14=0000000002b5f890 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!KeInsertQueueApc+0x2c:
fffff800`0309cf98 440f20c5 mov rbp,cr8
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: ccsvchst.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800033a9264 to fffff8000309cf98
STACK_TEXT:
fffff880`08664aa0 fffff800`033a9264 : fffffa80`03f60cd0 fffffffe`2a527b60 fffff800`031f0e80 00000000`00000001 : nt!KeInsertQueueApc+0x2c
fffff880`08664b00 fffff800`033a92b8 : fffffa80`079c15b0 fffff880`08664ca0 00000000`030be1a8 00000000`00000000 : nt!NtQueueApcThreadEx+0x108
fffff880`08664b70 fffff800`030bc993 : fffff880`08664ca0 fffffa80`079c13f0 00000000`00000000 0000007f`ffffff01 : nt!NtQueueApcThread+0x20
fffff880`08664bb0 00000000`776901aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`030be188 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776901aa
FOLLOWUP_IP:
nt!KeInsertQueueApc+2c
fffff800`0309cf98 440f20c5 mov rbp,cr8
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!KeInsertQueueApc+2c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff880086640d0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!KeInsertQueueApc+2c
BUCKET_ID: X64_0x3B_nt!KeInsertQueueApc+2c
Followup: MachineOwner
---------
Debug session time: Sat Jan 22 05:11:00.386 2011 (GMT-5)
System Uptime: 0 days 0:26:58.791
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000096, fffff8000309cf98, fffff88003b00ec0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KeInsertQueueApc+2c )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000096, Exception code that caused the bugcheck
Arg2: fffff8000309cf98, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88003b00ec0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000096 - {EXCEPTION} Privileged instruction.
FAULTING_IP:
nt!KeInsertQueueApc+2c
fffff800`0309cf98 440f20c5 mov rbp,cr8
CONTEXT: fffff88003b00ec0 -- (.cxr 0xfffff88003b00ec0)
rax=fffff8000348a5a0 rbx=fffffa8006e55060 rcx=fffffa800417a088
rdx=fffffa8004283f20 rsi=0000000000000000 rdi=fffffa800417a088
rip=fffff8000309cf98 rsp=fffff88003b01890 rbp=00000000a000000c
r8=0000000000000000 r9=0000000000000002 r10=fffff80003238820
r11=fffff88003b019c8 r12=00000000a0000003 r13=0000000000000000
r14=fffffa8004283f20 r15=0000000000000002
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!KeInsertQueueApc+0x2c:
fffff800`0309cf98 440f20c5 mov rbp,cr8
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000309cf98
STACK_TEXT:
fffff880`03b01890 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeInsertQueueApc+0x2c
FOLLOWUP_IP:
nt!KeInsertQueueApc+2c
fffff800`0309cf98 440f20c5 mov rbp,cr8
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!KeInsertQueueApc+2c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88003b00ec0 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!KeInsertQueueApc+2c
BUCKET_ID: X64_0x3B_nt!KeInsertQueueApc+2c
Followup: MachineOwner
---------
Debug session time: Tue Feb 1 15:17:49.228 2011 (GMT-5)
System Uptime: 0 days 3:18:56.007
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {10c, 2, 0, fffff88006fbee24}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000000010c, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88006fbee24, address which referenced memory
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'ENG64' and 'ENG64.SYS' overlap
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b70e0
000000000000010c
CURRENT_IRQL: 2
FAULTING_IP:
USBSTOR!UsbQueueInsert+ac
fffff880`06fbee24 f6412c20 test byte ptr [rcx+2Ch],20h
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff80000b9c140 -- (.trap 0xfffff80000b9c140)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=00000000000000e0
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88006fbee24 rsp=fffff80000b9c2d0 rbp=fffffa80070d3000
r8=fffff80000b9c2f0 r9=0000000000000001 r10=fffff8000300f000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
USBSTOR!UsbQueueInsert+0xac:
fffff880`06fbee24 f6412c20 test byte ptr [rcx+2Ch],20h ds:00000000`0000010c=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000307eca9 to fffff8000307f740
STACK_TEXT:
fffff800`00b9bff8 fffff800`0307eca9 : 00000000`0000000a 00000000`0000010c 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00b9c000 fffff800`0307d920 : 00000000`00000000 fffffa80`04764010 fffffa80`04d407b0 0000057f`f9ec4bd8 : nt!KiBugCheckDispatch+0x69
fffff800`00b9c140 fffff880`06fbee24 : 00000000`00000000 fffffa80`04764010 fffffa80`070d3320 fffff880`14077907 : nt!KiPageFault+0x260
fffff800`00b9c2d0 fffff880`06fba4f5 : 00000000`00000000 fffffa80`070d3060 fffffa80`070d3000 fffffa80`070d31b0 : USBSTOR!UsbQueueInsert+0xac
fffff800`00b9c330 fffff880`0193d0c9 : fffffa80`04ae5580 fffffa80`04ae5580 00000000`00000000 fffffa80`03af58e0 : USBSTOR!USBSTOR_Scsi+0x2e1
fffff800`00b9c390 fffff880`0193d609 : fffffa80`04586500 fffffa80`03af58e0 fffffa80`03af5790 00000000`00000002 : CLASSPNP!ClasspSendMediaStateIrp+0x329
fffff800`00b9c3f0 fffff880`01932698 : 00000000`00000002 fffff880`0657bfc1 00000000`00000000 fffffa80`08aa15b8 : CLASSPNP!ClassCheckMediaState+0x59
fffff800`00b9c420 fffff800`0306a5bf : 00000000`00000000 00000000`00000002 00000000`00000001 fffffa80`069fb278 : CLASSPNP! ?? ::FNODOBFM::`string'+0x42c8
fffff800`00b9c460 fffff800`0308b29e : 00000000`00000002 fffff800`00b9c6d8 00000000`00000000 00000000`00000000 : nt!IopTimerDispatch+0x132
fffff800`00b9c570 fffff800`0308add6 : fffffa80`07442c68 fffffa80`07442c68 00000000`00000000 00000000`00000000 : nt!KiProcessTimerDpcTable+0x66
fffff800`00b9c5e0 fffff800`0308b4be : 0000001b`ca6a3cb2 fffff800`00b9cc58 00000000`000bacc3 fffff800`031fdae8 : nt!KiProcessExpiredTimerList+0xc6
fffff800`00b9cc30 fffff800`0308acb7 : 00000008`b97858cd 00000008`000bacc3 00000008`b97858bc 00000000`000000c3 : nt!KiTimerExpiration+0x1be
fffff800`00b9ccd0 fffff800`03087eea : fffff800`031f9e80 fffff800`03207c40 00000000`00000000 fffff880`00fd24c0 : nt!KiRetireDpcList+0x277
fffff800`00b9cd80 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cd40 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !USBSTOR
fffff88006fbee19 - USBSTOR!UsbQueueInsert+a1
[ 8b:8a ]
1 error : !USBSTOR (fffff88006fbee19)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BIT
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------
0: kd> lmtsmn
start end module name
fffff880`06c00000 fffff880`06c2b000 000 000.fcl Fri Sep 26 09:11:22 2008 (48DCDF7A)
fffff880`14b76000 fffff880`14bb4000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00e00000 fffff880`00e57000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02c00000 fffff880`02c8a000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`14bd0000 fffff880`14be6000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`04316000 fffff880`0432b000 amdppm amdppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00c44000 fffff880`00c4f000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`08de5000 fffff880`08dec000 AODDriver AODDriver.sys Mon Oct 13 00:38:55 2008 (48F2D0DF)
fffff880`08dec000 fffff880`08df7000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00eeb000 fffff880`00ef4000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00c1a000 fffff880`00c44000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`01809000 fffff880`01810000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04203000 fffff880`042f0000 BHDrvx64 BHDrvx64.sys Mon Nov 15 18:11:35 2010 (4CE1BE27)
fffff880`0409c000 fffff880`040ad000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`0657a000 fffff880`06598000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff880`04000000 fffff880`0409c000 ccHPx64 ccHPx64.sys Fri Feb 05 16:05:45 2010 (4B6C8829)
fffff960`00650000 fffff960`00677000 cdd cdd.dll unavailable (00000000)
fffff880`05747000 fffff880`05764000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`0198d000 fffff880`019b7000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00ce0000 fffff880`00da0000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01927000 fffff880`01957000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00c82000 fffff880`00ce0000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`019b7000 fffff880`019f9000 cmdguard cmdguard.sys Wed Jan 05 12:10:43 2011 (4D24A613)
fffff880`02da1000 fffff880`02dad000 cmdhlp cmdhlp.sys Wed Jan 05 12:09:59 2011 (4D24A5E7)
fffff880`0105e000 fffff880`010d1000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`14bc0000 fffff880`14bd0000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`05764000 fffff880`05772000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`04158000 fffff880`04176000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`04149000 fffff880`04158000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01911000 fffff880`01927000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0571f000 fffff880`05741000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`05ff7000 fffff880`06000000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05772000 fffff880`0577e000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`0577e000 fffff880`05791000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05feb000 fffff880`05ff7000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`04495000 fffff880`04589000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04589000 fffff880`045cf000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`040ae000 fffff880`04124000 eeCtrl64 eeCtrl64.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`08dba000 fffff880`08dda000 ENG64 ENG64.SYS Mon Dec 13 20:47:30 2010 (4D06CCB2)
fffff880`04124000 fffff880`04149000 EraserUtilRebootDrv EraserUtilRebootDrv.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`08c00000 fffff880`08dba000 EX64 EX64.SYS Mon Dec 13 20:55:48 2010 (4D06CEA4)
fffff880`045f3000 fffff880`04600000 fdc fdc.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`01120000 fffff880`01134000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`010d4000 fffff880`01120000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`013f1000 fffff880`013fb000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`018d7000 fffff880`01911000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0148b000 fffff880`014d5000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff880`06f92000 fffff880`06f9b000 gdrv gdrv.sys Thu Mar 12 23:22:29 2009 (49B9D175)
fffff880`08ddb000 fffff880`08de5000 GVTDrv64 GVTDrv64.sys Tue Sep 05 03:10:02 2006 (44FD22CA)
fffff800`035eb000 fffff800`03634000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`045cf000 fffff880`045f3000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`05686000 fffff880`056e2000 HdAudio HdAudio.sys Mon Jul 13 20:06:59 2009 (4A5BCC23)
fffff880`057bc000 fffff880`057d5000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`057d5000 fffff880`057dd080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`057ae000 fffff880`057bc000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`064b2000 fffff880`0657a000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`018ce000 fffff880`018d7000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`03e00000 fffff880`03e7b000 IDSvia64 IDSvia64.sys Fri Nov 05 17:13:11 2010 (4CD47367)
fffff880`02cb0000 fffff880`02cc8000 inspect inspect.sys Wed Jan 05 12:09:49 2011 (4D24A5DD)
fffff880`03f1d000 fffff880`03f44000 Ironx64 Ironx64.SYS Tue Apr 27 20:48:23 2010 (4BD785D7)
fffff880`00fad000 fffff880`00fcd000 jraid jraid.sys Wed Oct 07 07:26:03 2009 (4ACC7ACB)
fffff880`13e7a000 fffff880`13e89000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`057de000 fffff880`057ec000 kbdhid kbdhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff800`00baf000 fffff800`00bb9000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`043a1000 fffff880`043e4000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`013c6000 fffff880`013e0000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01460000 fffff880`0148b000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`05741000 fffff880`05746200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`041d0000 fffff880`041e3000 LHidFilt LHidFilt.Sys Wed Jun 17 12:49:39 2009 (4A391EA3)
fffff880`03fe1000 fffff880`03ff6000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`03e7b000 fffff880`03e8f000 LMouFilt LMouFilt.Sys Wed Jun 17 12:49:43 2009 (4A391EA7)
fffff880`03e8f000 fffff880`03eb2000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`05600000 fffff880`05610000 LUsbFilt LUsbFilt.Sys Wed Jun 17 12:49:46 2009 (4A391EAA)
fffff880`04176000 fffff880`041ba000 MarvinBus64 MarvinBus64.sys Fri Sep 23 17:17:03 2005 (433470CF)
fffff880`04364000 fffff880`043a0880 mcdbus mcdbus.sys Tue Feb 24 05:34:07 2009 (49A3CD1F)
fffff880`00c61000 fffff880`00c6e000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`057ec000 fffff880`057fa000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`04355000 fffff880`04364000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`041e3000 fffff880`041f0000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00c00000 fffff880`00c1a000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`06598000 fffff880`065b0000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`065b0000 fffff880`065dd000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`06400000 fffff880`0644e000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0644e000 fffff880`06471000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`01212000 fffff880`0121d000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e60000 fffff880`00e6a000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01000000 fffff880`0105e000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`03fb5000 fffff880`03fc0000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`018bc000 fffff880`018ce000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`014ff000 fffff880`015f1000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`13e24000 fffff880`13e30000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`13e30000 fffff880`13e5f000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`05671000 fffff880`05686000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`011ee000 fffff880`011fd000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02dad000 fffff880`02df2000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01400000 fffff880`01460000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`011dd000 fffff880`011ee000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03fa9000 fffff880`03fb5000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`0300f000 fffff800`035eb000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01223000 fffff880`013c6000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`01800000 fffff880`01809000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`041ba000 fffff880`041d0000 nusb3hub nusb3hub.sys Fri Sep 25 09:58:23 2009 (4ABCCC7F)
fffff880`04400000 fffff880`04430000 nusb3xhc nusb3xhc.sys Fri Sep 25 09:58:31 2009 (4ABCCC87)
fffff880`14b1e000 fffff880`14b1f180 nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
fffff880`13e8c000 fffff880`14b1de00 nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
fffff880`02c8a000 fffff880`02cb0000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00eaa000 fffff880`00ebf000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00e6a000 fffff880`00e9d000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00ed4000 fffff880`00edb000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00edb000 fffff880`00eeb000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`013e0000 fffff880`013f1000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`06ce7000 fffff880`06d8d000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`056e2000 fffff880`0571f000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c6e000 fffff880`00c82000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`13e00000 fffff880`13e24000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`13e5f000 fffff880`13e7a000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`04334000 fffff880`04355000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`14be6000 fffff880`14c00000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03f58000 fffff880`03fa9000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`015f1000 fffff880`015fa000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01200000 fffff880`01209000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01209000 fffff880`01212000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01882000 fffff880`018bc000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`03eb2000 fffff880`03eca000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04432000 fffff880`04471000 Rt64win7 Rt64win7.sys Thu Aug 20 12:05:06 2009 (4A8D7432)
fffff880`05e00000 fffff880`05fea080 RTKVHD64 RTKVHD64.sys Wed Oct 21 10:27:48 2009 (4ADF1A64)
fffff880`00fcd000 fffff880`00ffc000 SCSIPORT SCSIPORT.SYS Mon Jul 13 20:01:04 2009 (4A5BCAC0)
fffff880`06d8d000 fffff880`06d98000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`14bb4000 fffff880`14bc0000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03ed1000 fffff880`03eee000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`0187a000 fffff880`01882000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`06e00000 fffff880`06e86000 SRTSP64 SRTSP64.SYS Wed Feb 24 18:59:29 2010 (4B85BD61)
fffff880`03f44000 fffff880`03f58000 SRTSPX64 SRTSPX64.SYS Wed Feb 24 18:59:48 2010 (4B85BD74)
fffff880`06efc000 fffff880`06f92000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`06c2b000 fffff880`06c92000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`06d98000 fffff880`06dc5000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`0448d000 fffff880`0448e480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01134000 fffff880`011a2000 SYMDS64 SYMDS64.SYS Mon Aug 17 19:35:30 2009 (4A89E942)
fffff880`011a2000 fffff880`011dd000 SYMEFA64 SYMEFA64.SYS Wed Apr 21 17:47:39 2010 (4BCF727B)
fffff880`02d6b000 fffff880`02da1000 SYMEVENT64x86 SYMEVENT64x86.SYS Thu Aug 13 18:28:21 2009 (4A849385)
fffff880`02cf5000 fffff880`02d6b000 SYMTDIV SYMTDIV.SYS Tue May 04 00:38:27 2010 (4BDFA4C3)
fffff880`01601000 fffff880`017fe000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`06dc5000 fffff880`06dd7000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02ce8000 fffff880`02cf5000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02cca000 fffff880`02ce8000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`03f09000 fffff880`03f1d000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00560000 fffff960`0056a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`042f0000 fffff880`04316000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`043e4000 fffff880`043f6000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`05791000 fffff880`057ae000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
fffff880`04430000 fffff880`04431f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`0447c000 fffff880`0448d000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`05617000 fffff880`05671000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`04471000 fffff880`0447c000 usbohci usbohci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`14b20000 fffff880`14b76000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`06fac000 fffff880`06fb8000 usbprint usbprint.sys Mon Jul 13 20:38:18 2009 (4A5BD37A)
fffff880`06f9b000 fffff880`06fac000 usbscan usbscan.sys Mon Jul 13 20:35:32 2009 (4A5BD2D4)
fffff880`06fb8000 fffff880`06fd3000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`00e9d000 fffff880`00eaa000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01810000 fffff880`0181e000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`014d5000 fffff880`014fa000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00ebf000 fffff880`00ed4000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00da0000 fffff880`00dfc000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`0182e000 fffff880`0187a000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`03eee000 fffff880`03f09000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`0181e000 fffff880`0182e000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00efa000 fffff880`00f9e000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f9e000 fffff880`00fad000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02df2000 fffff880`02dfb000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000a0000 fffff960`003b0000 win32k win32k.sys unavailable (00000000)
fffff880`0432b000 fffff880`04334000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00e57000 fffff880`00e60000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`03fc0000 fffff880`03fe1000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`06e86000 fffff880`06eb7000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
Unloaded modules:
fffff880`08dbb000 fffff880`08ddb000 ENG64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`08c01000 fffff880`08dbb000 EX64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`06e86000 fffff880`06ef7000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01957000 fffff880`01965000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01965000 fffff880`01971000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01971000 fffff880`0197a000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0197a000 fffff880`0198d000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000