[list=1]
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\111011-22869-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c0e000 PsLoadedModuleList = 0xfffff800`02e53670
Debug session time: Thu Nov 10 02:15:35.378 2011 (UTC - 7:00)
System Uptime: 2 days 21:03:13.580
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, fffffa800d40c4c0, fffffa800d40c950, 94492492}
GetPointerFromAddress: unable to read from fffff80002ebd100
GetUlongFromAddress: unable to read from fffff80002e2ba18
Probably caused by : ntkrnlmp.exe ( nt!FsRtlTeardownPerStreamContexts+e2 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000020, a pool block header size is corrupt.
Arg2: fffffa800d40c4c0, The pool entry we were looking for within the page.
Arg3: fffffa800d40c950, The next pool entry.
Arg4: 0000000094492492, (reserved)
Debugging Details:
------------------
GetUlongFromAddress: unable to read from fffff80002e2ba18
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: fffffa800d40c4c0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002db8cae to fffff80002c8ac40
STACK_TEXT:
fffff880`021850b8 fffff800`02db8cae : 00000000`00000019 00000000`00000020 fffffa80`0d40c4c0 fffffa80`0d40c950 : nt!KeBugCheckEx
fffff880`021850c0 fffff800`02f4390e : 00000000`00000705 00003450`13ed96df fffff8a0`53924924 fffff880`01239f49 : nt!ExDeferredFreePool+0x12da
fffff880`02185170 fffff880`012bcbac : fffff8a0`04f04890 fffffa80`09ab3040 fffff880`02185248 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`021851c0 fffff880`012c1cc1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`02185200 fffff880`0123a85c : fffff8a0`04f04790 fffff8a0`04f04890 00000000`00000000 00000000`000004d0 : Ntfs!NtfsRemoveScb+0x61
fffff880`02185240 fffff880`012bf64c : fffff8a0`04f04760 00000000`00000001 fffff880`02185372 fffffa80`0a318370 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`02185270 fffff880`012410e2 : fffffa80`0a318370 fffffa80`0a318370 fffff8a0`04f04760 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`021852f0 fffff880`012cf193 : fffffa80`0a318370 00000000`00000001 fffff8a0`04f04760 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`02185330 fffff880`012be357 : fffffa80`0a318370 fffff8a0`04f04890 fffff8a0`04f04760 fffffa80`0cedc180 : Ntfs!NtfsCommonClose+0x353
fffff880`02185400 fffff880`012ad291 : fffffa80`0cedc180 00000000`01000100 fffff8a0`0000ea01 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`021854d0 fffff880`013829fa : fffff880`021857d0 fffffa80`0cedc180 fffff880`02185701 fffff880`013a3100 : Ntfs!NtfsFlushVolume+0x75
fffff880`02185600 fffff880`013a6bc7 : fffff880`021857d0 fffffa80`0cedc180 fffffa80`0cedc180 fffffa80`0cedc180 : Ntfs!NtfsCheckpointVolumeUntilDone+0x4a
fffff880`02185680 fffff880`012f927b : fffff880`021857d0 fffffa80`0cedc180 fffffa80`0e9b8010 fffffa80`0cedc188 : Ntfs!NtfsShutdownVolume+0xa7
fffff880`02185700 fffff880`013aefc5 : fffff880`021857d0 00000000`00000000 fffff880`013a8ae0 00000000`00000000 : Ntfs!NtfsForEachVcb+0x167
fffff880`021857a0 fffff880`0119f6af : fffffa80`0c0ce4b0 fffff800`02e2b260 fffff800`02e8a990 fffffa80`0e9b8010 : Ntfs!NtfsFsdShutdown+0x145
fffff880`021859d0 fffff800`02ed542c : fffffa80`0c0cebd0 fffff800`02e35620 00000000`00000001 00000000`00000000 : fltmgr!FltpDispatch+0x9f
fffff880`02185a30 fffff800`02ed55c2 : 00000000`00000001 00000000`00000001 fffff800`02e2b260 00000000`00000000 : nt!IopShutdownBaseFileSystems+0xac
fffff880`02185ab0 fffff800`02ed6286 : fffff800`02ed60a0 fffff800`02e2b260 00000000`00000001 00000000`00000001 : nt!IoShutdownSystem+0x122
fffff880`02185b30 fffff800`02c95001 : fffff800`02ed60a0 fffff800`02e2b201 fffff800`02e8c800 00000000`00000004 : nt!PopGracefulShutdown+0x1e6
fffff880`02185b70 fffff800`02f25fee : 00000000`00000000 fffffa80`09ab3040 00000000`00000080 fffffa80`099eb040 : nt!ExpWorkerThread+0x111
fffff880`02185c00 fffff800`02c7c5e6 : fffff880`03381180 fffffa80`09ab3040 fffff880`0338bfc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`02185c40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!FsRtlTeardownPerStreamContexts+e2
fffff800`02f4390e 448a5e07 mov r11b,byte ptr [rsi+7]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!FsRtlTeardownPerStreamContexts+e2
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x19_20_nt!FsRtlTeardownPerStreamContexts+e2
BUCKET_ID: X64_0x19_20_nt!FsRtlTeardownPerStreamContexts+e2
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\120811-10108-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c60000 PsLoadedModuleList = 0xfffff800`02ea5670
Debug session time: Thu Dec 8 06:31:56.256 2011 (UTC - 7:00)
System Uptime: 0 days 10:11:45.458
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
.
Unable to load image \SystemRoot\system32\drivers\RTDVHD64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for RTDVHD64.sys
*** ERROR: Module load completed but symbols could not be loaded for RTDVHD64.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff88005f4d8a9, fffff8800476a748, fffff88004769fa0}
Probably caused by : RTDVHD64.sys ( RTDVHD64+1458a9 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88005f4d8a9, The address that the exception occurred at
Arg3: fffff8800476a748, Exception Record Address
Arg4: fffff88004769fa0, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
RTDVHD64+1458a9
fffff880`05f4d8a9 ff5060 call qword ptr [rax+60h]
EXCEPTION_RECORD: fffff8800476a748 -- (.exr 0xfffff8800476a748)
ExceptionAddress: fffff88005f4d8a9 (RTDVHD64+0x00000000001458a9)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88004769fa0 -- (.cxr 0xfffff88004769fa0)
rax=9c74979a72959a72 rbx=fffffa800d074530 rcx=fffffa800d06e4c0
rdx=fffffa800d09b4d0 rsi=fffffa800d1fd000 rdi=fffffa800d1fd000
rip=fffff88005f4d8a9 rsp=fffff8800476a980 rbp=0000000000000000
r8=fffff88005ebfef8 r9=fffff80002e52e80 r10=0000000000000009
r11=fffffa800d0a4580 r12=0000000000000000 r13=0000000000000001
r14=0000000000000004 r15=0000000000000001
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
RTDVHD64+0x1458a9:
fffff880`05f4d8a9 ff5060 call qword ptr [rax+60h] ds:002b:9c74979a`72959ad2=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f0f100
ffffffffffffffff
FOLLOWUP_IP:
RTDVHD64+1458a9
fffff880`05f4d8a9 ff5060 call qword ptr [rax+60h]
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from 8000000000000000 to fffff88005f4d8a9
STACK_TEXT:
fffff880`0476a980 80000000`00000000 : 00000000`00000000 fffffa80`0d083500 fffff880`05e0ade8 00000000`00000009 : RTDVHD64+0x1458a9
fffff880`0476a988 00000000`00000000 : fffffa80`0d083500 fffff880`05e0ade8 00000000`00000009 fffffa80`0d0a49c0 : 0x80000000`00000000
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: RTDVHD64+1458a9
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: RTDVHD64
IMAGE_NAME: RTDVHD64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c8eefa2
STACK_COMMAND: .cxr 0xfffff88004769fa0 ; kb
FAILURE_BUCKET_ID: X64_0x7E_RTDVHD64+1458a9
BUCKET_ID: X64_0x7E_RTDVHD64+1458a9
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\121211-11824-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c00000 PsLoadedModuleList = 0xfffff800`02e45670
Debug session time: Mon Dec 12 11:34:23.987 2011 (UTC - 7:00)
System Uptime: 2 days 23:46:51.189
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002c3bf80, fffff8800d18cb40, 0}
Probably caused by : ntkrnlmp.exe ( nt!WmipDoFindRegEntryByProviderId+10 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c3bf80, Address of the instruction which caused the bugcheck
Arg3: fffff8800d18cb40, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c3bf80 394830 cmp dword ptr [rax+30h],ecx
CONTEXT: fffff8800d18cb40 -- (.cxr 0xfffff8800d18cb40)
rax=ff847fb083ff1a9b rbx=0000000000000044 rcx=0000000000000044
rdx=fffff80002dee460 rsi=0000000000000000 rdi=fffff8800d18d6d0
rip=fffff80002c3bf80 rsp=fffff8800d18d528 rbp=fffffa800f80e010
r8=fffff78000000008 r9=0000000000000000 r10=0000000000000000
r11=fffff880033f3180 r12=0000000000000001 r13=0000000000000001
r14=fffff8a012112d78 r15=fffff8800d18d6e8
iopl=0 nv up ei ng nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010283
nt!WmipDoFindRegEntryByProviderId+0x10:
fffff800`02c3bf80 394830 cmp dword ptr [rax+30h],ecx ds:002b:ff847fb0`83ff1acb=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: WmiPrvSE.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c3bf80
STACK_TEXT:
fffff880`0d18d528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!WmipDoFindRegEntryByProviderId+0x10
FOLLOWUP_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c3bf80 394830 cmp dword ptr [rax+30h],ecx
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!WmipDoFindRegEntryByProviderId+10
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff8800d18cb40 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\121311-10389-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c64000 PsLoadedModuleList = 0xfffff800`02ea9670
Debug session time: Tue Dec 13 09:39:57.874 2011 (UTC - 7:00)
System Uptime: 0 days 22:04:11.702
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002c9ff80, fffff88009c93b40, 0}
Probably caused by : ntkrnlmp.exe ( nt!WmipDoFindRegEntryByProviderId+10 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c9ff80, Address of the instruction which caused the bugcheck
Arg3: fffff88009c93b40, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c9ff80 394830 cmp dword ptr [rax+30h],ecx
CONTEXT: fffff88009c93b40 -- (.cxr 0xfffff88009c93b40)
rax=24a0000000000000 rbx=0000000000000042 rcx=0000000000000042
rdx=fffff80002e52460 rsi=0000000000000000 rdi=fffff88009c946d0
rip=fffff80002c9ff80 rsp=fffff88009c94528 rbp=fffffa800e91bbe0
r8=fffff78000000008 r9=0000000000000000 r10=0000000000000000
r11=fffff88003181180 r12=0000000000000001 r13=0000000000000001
r14=fffff8a00fb99a70 r15=fffff88009c946e8
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010207
nt!WmipDoFindRegEntryByProviderId+0x10:
fffff800`02c9ff80 394830 cmp dword ptr [rax+30h],ecx ds:002b:24a00000`00000030=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: WmiPrvSE.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c9ff80
STACK_TEXT:
fffff880`09c94528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!WmipDoFindRegEntryByProviderId+0x10
FOLLOWUP_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c9ff80 394830 cmp dword ptr [rax+30h],ecx
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!WmipDoFindRegEntryByProviderId+10
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff88009c93b40 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\121511-11840-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c1d000 PsLoadedModuleList = 0xfffff800`02e62670
Debug session time: Thu Dec 15 15:36:40.020 2011 (UTC - 7:00)
System Uptime: 1 days 18:47:24.222
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002c58f80, fffff8800a682b40, 0}
Probably caused by : ntkrnlmp.exe ( nt!WmipDoFindRegEntryByProviderId+10 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002c58f80, Address of the instruction which caused the bugcheck
Arg3: fffff8800a682b40, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c58f80 394830 cmp dword ptr [rax+30h],ecx
CONTEXT: fffff8800a682b40 -- (.cxr 0xfffff8800a682b40)
rax=8888888800000000 rbx=0000000000000043 rcx=0000000000000043
rdx=fffff80002e0b460 rsi=0000000000000000 rdi=fffff8800a6836d0
rip=fffff80002c58f80 rsp=fffff8800a683528 rbp=fffffa800ffc7780
r8=fffff78000000008 r9=0000000000000000 r10=0000000000000000
r11=fffff80002e0fe80 r12=0000000000000001 r13=0000000000000001
r14=fffff8800a683650 r15=fffff8800a6836e8
iopl=0 nv up ei ng nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010287
nt!WmipDoFindRegEntryByProviderId+0x10:
fffff800`02c58f80 394830 cmp dword ptr [rax+30h],ecx ds:002b:88888888`00000030=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: WmiPrvSE.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002c58f80
STACK_TEXT:
fffff880`0a683528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!WmipDoFindRegEntryByProviderId+0x10
FOLLOWUP_IP:
nt!WmipDoFindRegEntryByProviderId+10
fffff800`02c58f80 394830 cmp dword ptr [rax+30h],ecx
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!WmipDoFindRegEntryByProviderId+10
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
STACK_COMMAND: .cxr 0xfffff8800a682b40 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
BUCKET_ID: X64_0x3B_nt!WmipDoFindRegEntryByProviderId+10
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\122111-15865-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c50000 PsLoadedModuleList = 0xfffff800`02e95670
Debug session time: Wed Dec 21 11:50:51.210 2011 (UTC - 7:00)
System Uptime: 0 days 1:49:57.038
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {21, fffffa800cffb000, 24a0, c0c0c0c0c0}
Unable to load image \SystemRoot\system32\DRIVERS\agnfilt.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for agnfilt.sys
*** ERROR: Module load completed but symbols could not be loaded for agnfilt.sys
Probably caused by : agnfilt.sys ( agnfilt+1b08 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000021, the data following the pool block being freed is corrupt. Typically this means the consumer (call stack ) has overrun the block.
Arg2: fffffa800cffb000, The pool pointer being freed.
Arg3: 00000000000024a0, The number of bytes allocated for the pool block.
Arg4: 000000c0c0c0c0c0, The corrupted value found following the pool block.
Debugging Details:
------------------
BUGCHECK_STR: 0x19_21
POOL_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eff100
fffffa800cffb000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: msiexec.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002dfa9b2 to fffff80002cccc40
STACK_TEXT:
fffff880`0a8c6598 fffff800`02dfa9b2 : 00000000`00000019 00000000`00000021 fffffa80`0cffb000 00000000`000024a0 : nt!KeBugCheckEx
fffff880`0a8c65a0 fffff880`01480b08 : 00000000`00000001 fffff880`01727110 fffffa80`66747441 fffffa80`00000000 : nt!ExDeferredFreePool+0xfaa
fffff880`0a8c6650 00000000`00000001 : fffff880`01727110 fffffa80`66747441 fffffa80`00000000 fffffa80`09c50e70 : agnfilt+0x1b08
fffff880`0a8c6658 fffff880`01727110 : fffffa80`66747441 fffffa80`00000000 fffffa80`09c50e70 fffff880`01714526 : 0x1
fffff880`0a8c6660 fffffa80`66747441 : fffffa80`00000000 fffffa80`09c50e70 fffff880`01714526 00000000`00000001 : ndis!WPP_GLOBAL_Control
fffff880`0a8c6668 fffffa80`00000000 : fffffa80`09c50e70 fffff880`01714526 00000000`00000001 fffffa80`0cb041a0 : 0xfffffa80`66747441
fffff880`0a8c6670 fffffa80`09c50e70 : fffff880`01714526 00000000`00000001 fffffa80`0cb041a0 fffffa80`09c50e00 : 0xfffffa80`00000000
fffff880`0a8c6678 fffff880`01714526 : 00000000`00000001 fffffa80`0cb041a0 fffffa80`09c50e00 00000000`00000000 : 0xfffffa80`09c50e70
fffff880`0a8c6680 fffff880`0177d1c3 : fffffa80`0cde4860 fffffa80`0c3e7700 fffffa80`0cde4800 fffffa80`0cb04100 : ndis!ndisDetachFilter+0x436
fffff880`0a8c6760 fffff880`0177190f : fffffa80`0c3e7700 00000000`00000000 fffff8a0`00004e01 fffffa80`0c5d2670 : ndis!ndisHandleFilterDetachNotification+0x1f3
fffff880`0a8c67f0 fffff880`0176399f : 00000000`c0000023 fffffa80`0c3e7700 00000000`000000f9 fffffa80`0c3e7700 : ndis! ?? ::LNCPHCLB::`string'+0x660c
fffff880`0a8c6830 fffff880`01763c91 : fffffa80`0ccaf750 fffffa80`0ccaf750 fffffa80`0c0f9e40 00000000`00000000 : ndis!ndisHandlePnPRequest+0x11f
fffff880`0a8c68a0 fffff800`02fe7a97 : fffffa80`0c45d070 fffff880`0a8c6b60 fffff880`0a8c6b60 fffffa80`0c45d070 : ndis!ndisDispatchRequest+0x111
fffff880`0a8c68d0 fffff800`02fe82f6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
fffff880`0a8c6a00 fffff800`02ccbed3 : fffffa80`09ebc4b0 fffff880`0a8c6b60 fffffa80`09ebc4b0 fffff800`02fc44f4 : nt!NtDeviceIoControlFile+0x56
fffff880`0a8c6a70 00000000`7735138a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0290ed28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7735138a
STACK_COMMAND: kb
FOLLOWUP_IP:
agnfilt+1b08
fffff880`01480b08 ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: agnfilt+1b08
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: agnfilt
IMAGE_NAME: agnfilt.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c602418
FAILURE_BUCKET_ID: X64_0x19_21_agnfilt+1b08
BUCKET_ID: X64_0x19_21_agnfilt+1b08
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\122211-11949-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c0e000 PsLoadedModuleList = 0xfffff800`02e53670
Debug session time: Thu Dec 22 08:05:05.718 2011 (UTC - 7:00)
System Uptime: 0 days 19:17:33.920
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff80002c0f530, fffff880021a8118, fffff880021a7970}
Probably caused by : WSDPrint.sys ( WSDPrint!WSDPrintDispatchPnp+eb )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002c0f530, The address that the exception occurred at
Arg3: fffff880021a8118, Exception Record Address
Arg4: fffff880021a7970, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!WmipDoFindRegEntryByDevice+10
fffff800`02c0f530 48394810 cmp qword ptr [rax+10h],rcx
EXCEPTION_RECORD: fffff880021a8118 -- (.exr 0xfffff880021a8118)
ExceptionAddress: fffff80002c0f530 (nt!WmipDoFindRegEntryByDevice+0x0000000000000010)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000010
Attempt to read from address 0000000000000010
CONTEXT: fffff880021a7970 -- (.cxr 0xfffff880021a7970)
rax=0000000000000000 rbx=fffffa8009d9c6a0 rcx=fffffa8009d9c6a0
rdx=fffff80002dfc460 rsi=0000000000000000 rdi=fffffa8009d9c6a0
rip=fffff80002c0f530 rsp=fffff880021a8358 rbp=fffffa8009d9c6a0
r8=fffff78000000008 r9=0000000000000000 r10=0000000000000000
r11=fffff8800330f180 r12=0000000000000000 r13=0000000000000000
r14=fffff880078c9150 r15=fffff88000f160f0
iopl=0 nv up ei pl nz na po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010207
nt!WmipDoFindRegEntryByDevice+0x10:
fffff800`02c0f530 48394810 cmp qword ptr [rax+10h],rcx ds:002b:00000000`00000010=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000010
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ebd100
0000000000000010
FOLLOWUP_IP:
WSDPrint!WSDPrintDispatchPnp+eb
fffff880`078cd27b 488bcf mov rcx,rdi
BUGCHECK_STR: 0x7E
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
LAST_CONTROL_TRANSFER: from fffff8000301863d to fffff80002c0f530
STACK_TEXT:
fffff880`021a8358 fffff800`0301863d : fffffa80`09dc0400 0000057f`f623fb00 fffff880`0330f180 00000000`00000000 : nt!WmipDoFindRegEntryByDevice+0x10
fffff880`021a8360 fffff800`030af658 : 00000000`75626d75 00000000`00000000 fffff880`021a8410 fffff880`00ec64e5 : nt!WmipFindRegEntryByDevice+0x1d
fffff880`021a8390 fffff800`030b536e : fffffa80`09dd68a0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!WmipDeregisterDevice+0x28
fffff880`021a83c0 fffff880`00ee5bc4 : fffffa80`09dd68a0 00000000`00000100 00000000`0000012b fffffa80`09d9c901 : nt!IoWMIRegistrationControl+0xde
fffff880`021a83f0 fffff880`00f082d6 : 00000000`00000008 fffffa80`09d9c980 00000000`00000008 fffff880`021a84f8 : Wdf01000!FxWmiIrpHandler::Deregister+0xf0
fffff880`021a8450 fffff880`00f08854 : fffffa80`09d9c980 00000000`0000012b 00000000`0000012b 00000000`00000000 : Wdf01000!FxPkgPnp::PnpCleanupForRemove+0x2a
fffff880`021a8490 fffff880`00f07841 : 00000000`0000012b 00000000`0000012a 00000000`0000012a 00000000`00000000 : Wdf01000!FxPkgPnp::PnpEventFailed+0x10
fffff880`021a84c0 fffff880`00f074fe : fffffa80`09d9c980 fffff880`021a85f0 00000000`00001000 fffff880`00f167f0 : Wdf01000!FxPkgPnp::PnpEnterNewState+0x1a5
fffff880`021a8530 fffff880`00f07201 : 00000000`00000000 00000000`00000400 fffffa80`09d9c980 fffffa80`09d9c980 : Wdf01000!FxPkgPnp::PnpProcessEventInner+0x122
fffff880`021a85a0 fffff880`00efc35a : 00000000`00000000 fffffa80`09da2850 00000000`00000001 fffffa80`09d9c980 : Wdf01000!FxPkgPnp::PnpProcessEvent+0x1b1
fffff880`021a8630 fffff880`00efddd6 : fffffa80`0cd56b17 00000000`00000000 00000000`00000000 fffffa80`09d9c980 : Wdf01000!FxPkgPdo::_PnpSurpriseRemoval+0x6a
fffff880`021a8660 fffff880`00ecd245 : fffffa80`0f75bc60 fffffa80`0f75bc60 fffffa80`09d9c6a0 fffffa80`0f75bf28 : Wdf01000!FxPkgPnp::Dispatch+0x1b2
fffff880`021a86d0 fffff880`00ecd14b : 00000000`00000001 fffffa80`0f75bc60 00000000`00000001 fffffa80`09d9c6a0 : Wdf01000!FxDevice::Dispatch+0xa9
fffff880`021a8700 fffff880`078cd27b : fffffa80`0f75bc60 00000000`00000001 fffffa80`09dc0040 fffff880`021a8af8 : Wdf01000!FxDevice::DispatchWithLock+0x93
fffff880`021a8740 fffff800`02ef5af9 : fffffa80`09dc0040 00000000`c00000bb fffff880`021a8848 fffffa80`0f75bc60 : WSDPrint!WSDPrintDispatchPnp+0xeb
fffff880`021a8790 fffff800`03073f71 : fffffa80`09d9c6a0 00000000`00000000 fffffa80`09de5a10 00000000`00000000 : nt!IopSynchronousCall+0xc5
fffff880`021a8800 fffff800`0306e968 : fffff8a0`0ff4eef0 fffffa80`09d9c6a0 00000000`0000030a 00000000`00000308 : nt!IopRemoveDevice+0x101
fffff880`021a88c0 fffff800`03073ab7 : fffffa80`09de5a10 00000000`00000000 00000000`00000003 fffff880`021a8b78 : nt!PnpSurpriseRemoveLockedDeviceNode+0x128
fffff880`021a8900 fffff800`03073bd0 : 00000000`00000000 fffff8a0`0fd54e00 fffff8a0`0ff4eef0 fffff880`021a8a58 : nt!PnpDeleteLockedDeviceNode+0x37
fffff880`021a8930 fffff800`031044cf : 00000000`00000002 00000000`00000000 fffffa80`09dcfd90 00000000`00000000 : nt!PnpDeleteLockedDeviceNodes+0xa0
fffff880`021a89a0 fffff800`0310508c : fffff880`021a8b78 fffffa80`0fa13500 fffffa80`09a9d600 fffffa80`00000000 : nt!PnpProcessQueryRemoveAndEject+0x6cf
fffff880`021a8ae0 fffff800`02fee34e : 00000000`00000000 fffffa80`0fa13580 fffff8a0`0a090680 00000000`00000000 : nt!PnpProcessTargetDeviceEvent+0x4c
fffff880`021a8b10 fffff800`02c95001 : fffff800`02ef4998 fffff8a0`0fd54e10 fffff800`02e2b2b8 fffff800`02e2b2b8 : nt! ?? ::NNGAKEGL::`string'+0x5b3cb
fffff880`021a8b70 fffff800`02f25fee : 00000000`00000000 fffffa80`09a9d680 00000000`00000080 fffffa80`099dc040 : nt!ExpWorkerThread+0x111
fffff880`021a8c00 fffff800`02c7c5e6 : fffff880`03381180 fffffa80`09a9d680 fffff880`0338bfc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`021a8c40 00000000`00000000 : fffff880`021a9000 fffff880`021a3000 fffff880`021a85e0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: e
SYMBOL_NAME: WSDPrint!WSDPrintDispatchPnp+eb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: WSDPrint
IMAGE_NAME: WSDPrint.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bd3b8
STACK_COMMAND: .cxr 0xfffff880021a7970 ; kb
FAILURE_BUCKET_ID: X64_0x7E_WSDPrint!WSDPrintDispatchPnp+eb
BUCKET_ID: X64_0x7E_WSDPrint!WSDPrintDispatchPnp+eb
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\122211-10826-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c1e000 PsLoadedModuleList = 0xfffff800`02e63670
Debug session time: Thu Dec 22 21:29:32.568 2011 (UTC - 7:00)
System Uptime: 0 days 13:23:05.770
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {21, fffffa800cff2000, 24a0, d3ccced1ccccdcd6}
Unable to load image \SystemRoot\system32\DRIVERS\agnfilt.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for agnfilt.sys
*** ERROR: Module load completed but symbols could not be loaded for agnfilt.sys
Probably caused by : agnfilt.sys ( agnfilt+1b08 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000021, the data following the pool block being freed is corrupt. Typically this means the consumer (call stack ) has overrun the block.
Arg2: fffffa800cff2000, The pool pointer being freed.
Arg3: 00000000000024a0, The number of bytes allocated for the pool block.
Arg4: d3ccced1ccccdcd6, The corrupted value found following the pool block.
Debugging Details:
------------------
BUGCHECK_STR: 0x19_21
POOL_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ecd100
fffffa800cff2000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: msiexec.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002dc89b2 to fffff80002c9ac40
STACK_TEXT:
fffff880`08eee598 fffff800`02dc89b2 : 00000000`00000019 00000000`00000021 fffffa80`0cff2000 00000000`000024a0 : nt!KeBugCheckEx
fffff880`08eee5a0 fffff880`00dc3b08 : 00000000`00000001 fffff880`016ae110 fffffa80`66747441 fffffa80`00000000 : nt!ExDeferredFreePool+0xfaa
fffff880`08eee650 00000000`00000001 : fffff880`016ae110 fffffa80`66747441 fffffa80`00000000 fffffa80`0a6826b0 : agnfilt+0x1b08
fffff880`08eee658 fffff880`016ae110 : fffffa80`66747441 fffffa80`00000000 fffffa80`0a6826b0 fffff880`0169b526 : 0x1
fffff880`08eee660 fffffa80`66747441 : fffffa80`00000000 fffffa80`0a6826b0 fffff880`0169b526 00000000`00000001 : ndis!WPP_GLOBAL_Control
fffff880`08eee668 fffffa80`00000000 : fffffa80`0a6826b0 fffff880`0169b526 00000000`00000001 fffffa80`0cb111a0 : 0xfffffa80`66747441
fffff880`08eee670 fffffa80`0a6826b0 : fffff880`0169b526 00000000`00000001 fffffa80`0cb111a0 fffffa80`0a682600 : 0xfffffa80`00000000
fffff880`08eee678 fffff880`0169b526 : 00000000`00000001 fffffa80`0cb111a0 fffffa80`0a682600 00000000`00000000 : 0xfffffa80`0a6826b0
fffff880`08eee680 fffff880`017041c3 : fffffa80`0cde6520 fffffa80`0d2bc700 fffffa80`0cde6500 fffffa80`0cb11100 : ndis!ndisDetachFilter+0x436
fffff880`08eee760 fffff880`016f890f : fffffa80`0d2bc780 00000000`00000000 fffff8a0`00004e01 fffffa80`0c62c010 : ndis!ndisHandleFilterDetachNotification+0x1f3
fffff880`08eee7f0 fffff880`016ea99f : 00000000`c0000023 fffffa80`0d2bc780 00000000`000000f9 fffffa80`0d2bc780 : ndis! ?? ::LNCPHCLB::`string'+0x660c
fffff880`08eee830 fffff880`016eac91 : fffffa80`0ed09ad0 fffffa80`0ed09ad0 fffffa80`0c113df0 00000000`00000000 : ndis!ndisHandlePnPRequest+0x11f
fffff880`08eee8a0 fffff800`02fb5a97 : fffffa80`09da7720 fffff880`08eeeb60 fffff880`08eeeb60 fffffa80`09da7720 : ndis!ndisDispatchRequest+0x111
fffff880`08eee8d0 fffff800`02fb62f6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
fffff880`08eeea00 fffff800`02c99ed3 : fffffa80`0e55f060 fffff880`08eeeb60 fffffa80`0e55f060 fffff800`02f924f4 : nt!NtDeviceIoControlFile+0x56
fffff880`08eeea70 00000000`76e7138a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`02a5f048 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76e7138a
STACK_COMMAND: kb
FOLLOWUP_IP:
agnfilt+1b08
fffff880`00dc3b08 ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: agnfilt+1b08
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: agnfilt
IMAGE_NAME: agnfilt.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c602418
FAILURE_BUCKET_ID: X64_0x19_21_agnfilt+1b08
BUCKET_ID: X64_0x19_21_agnfilt+1b08
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\122611-13665-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c17000 PsLoadedModuleList = 0xfffff800`02e5c670
Debug session time: Mon Dec 26 10:01:26.895 2011 (UTC - 7:00)
System Uptime: 3 days 2:01:42.723
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffadb6db6dc78, 0, fffff88005e1e5ac, 5}
Unable to load image \SystemRoot\system32\drivers\RTDVHD64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for RTDVHD64.sys
*** ERROR: Module load completed but symbols could not be loaded for RTDVHD64.sys
Could not read faulting driver name
Probably caused by : RTDVHD64.sys ( RTDVHD64+d5ac )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffadb6db6dc78, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff88005e1e5ac, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec6100
fffffadb6db6dc78
FAULTING_IP:
RTDVHD64+d5ac
fffff880`05e1e5ac 8a910b010000 mov dl,byte ptr [rcx+10Bh]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff880045a8830 -- (.trap 0xfffff880045a8830)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000003 rbx=0000000000000000 rcx=fffffadb6db6db6d
rdx=fffffa800d1724e0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88005e1e5ac rsp=fffff880045a89c8 rbp=0000000000000000
r8=fffff88005ec8ef8 r9=fffffadb6db6db6d r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
RTDVHD64+0xd5ac:
fffff880`05e1e5ac 8a910b010000 mov dl,byte ptr [rcx+10Bh] ds:0010:fffffadb`6db6dc78=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c3e3bf to fffff80002c93c40
STACK_TEXT:
fffff880`045a86c8 fffff800`02c3e3bf : 00000000`00000050 fffffadb`6db6dc78 00000000`00000000 fffff880`045a8830 : nt!KeBugCheckEx
fffff880`045a86d0 fffff800`02c91d6e : 00000000`00000000 fffffadb`6db6dc78 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x44791
fffff880`045a8830 fffff880`05e1e5ac : fffff880`05e1e5f8 00000000`00000009 fffffa80`0d1484f0 fffffa80`0d2b4000 : nt!KiPageFault+0x16e
fffff880`045a89c8 fffff880`05e1e5f8 : 00000000`00000009 fffffa80`0d1484f0 fffffa80`0d2b4000 00000000`00000000 : RTDVHD64+0xd5ac
fffff880`045a89d0 00000000`00000009 : fffffa80`0d1484f0 fffffa80`0d2b4000 00000000`00000000 00000000`00000005 : RTDVHD64+0xd5f8
fffff880`045a89d8 fffffa80`0d1484f0 : fffffa80`0d2b4000 00000000`00000000 00000000`00000005 fffff880`05ec903f : 0x9
fffff880`045a89e0 fffffa80`0d2b4000 : 00000000`00000000 00000000`00000005 fffff880`05ec903f fffff800`02c9e845 : 0xfffffa80`0d1484f0
fffff880`045a89e8 00000000`00000000 : 00000000`00000005 fffff880`05ec903f fffff800`02c9e845 fffff880`0330f180 : 0xfffffa80`0d2b4000
STACK_COMMAND: kb
FOLLOWUP_IP:
RTDVHD64+d5ac
fffff880`05e1e5ac 8a910b010000 mov dl,byte ptr [rcx+10Bh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: RTDVHD64+d5ac
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: RTDVHD64
IMAGE_NAME: RTDVHD64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c8eefa2
FAILURE_BUCKET_ID: X64_0x50_RTDVHD64+d5ac
BUCKET_ID: X64_0x50_RTDVHD64+d5ac
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\kingbear\First 5\DUNELAND-PC-BSOD\Windows_NT6_BSOD_jcgriff2\122811-12948-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02c51000 PsLoadedModuleList = 0xfffff800`02e96670
Debug session time: Wed Dec 28 09:01:40.176 2011 (UTC - 7:00)
System Uptime: 1 days 22:58:51.003
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
.................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {0, 0, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiKernelCalloutExceptionHandler+e )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 0000000000000000, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (Win32) 0 (0) - The operation completed successfully.
FAULTING_IP:
+3532343234656437
00000000`00000000 ?? ???
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
ERROR_CODE: (NTSTATUS) 0 - STATUS_WAIT_0
BUGCHECK_STR: 0x1E_0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff80000b9c0e8 -- (.exr 0xfffff80000b9c0e8)
ExceptionAddress: fffff80002cdd2dc (nt!IopTimerDispatch+0x000000000000012f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff80000b9c190 -- (.trap 0xfffff80000b9c190)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff80000b9c2e0 rbx=0000000000000000 rcx=73f83b44f78b4d00
rdx=0000958e0fc73b41 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002cdd2dc rsp=fffff80000b9c320 rbp=0000000000000000
r8=00000000646d5800 r9=0000000000000000 r10=07fffaecdaec27ff
r11=fffff80000b9c2f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!IopTimerDispatch+0x12f:
fffff800`02cdd2dc ff5710 call qword ptr [rdi+10h] ds:34c8:00000000`00000010=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cc55fe to fffff80002ccdc10
STACK_TEXT:
fffff800`00b9b1c8 fffff800`02cc55fe : 00000000`00000000 fffff800`02cf99f0 fffff800`02ed7908 fffff800`02cdd2dc : nt!KeBugCheck
fffff800`00b9b1d0 fffff800`02cf94fd : fffff800`02ed771c fffff800`02e14c30 fffff800`02c51000 fffff800`00b9c0e8 : nt!KiKernelCalloutExceptionHandler+0xe
fffff800`00b9b200 fffff800`02cf82d5 : fffff800`02e180fc fffff800`00b9b278 fffff800`00b9c0e8 fffff800`02c51000 : nt!RtlpExecuteHandlerForException+0xd
fffff800`00b9b230 fffff800`02d09361 : fffff800`00b9c0e8 fffff800`00b9b940 fffff800`00000000 fffffa80`0d0143ac : nt!RtlDispatchException+0x415
fffff800`00b9b910 fffff800`02ccd2c2 : fffff800`00b9c0e8 00000000`00000000 fffff800`00b9c190 00000000`00000001 : nt!KiDispatchException+0x135
fffff800`00b9bfb0 fffff800`02ccbbca : 0000000e`00000028 fffff880`03037bb4 fffff880`03037bb4 00000000`0007c0c8 : nt!KiExceptionDispatch+0xc2
fffff800`00b9c190 fffff800`02cdd2dc : 00000000`00000000 00000000`00000000 00000000`00000001 fffffa80`0d0084c8 : nt!KiGeneralProtectionFault+0x10a
fffff800`00b9c320 fffff800`02cd95fc : 00000000`00000002 fffff800`00b9c538 00000000`00000004 00000000`00000007 : nt!IopTimerDispatch+0x12f
fffff800`00b9c430 fffff800`02cd9496 : fffffa80`0f82ac60 fffffa80`0f82ac60 00000000`00000000 00000000`00000000 : nt!KiProcessTimerDpcTable+0x6c
fffff800`00b9c4a0 fffff800`02cd937e : 00000189`c9ef1b54 fffff800`00b9cb18 00000000`00a56e3d fffff800`02e46a28 : nt!KiProcessExpiredTimerList+0xc6
fffff800`00b9caf0 fffff800`02cd9167 : 00000082`7443a8d1 00000082`00a56e3d 00000082`7443a83a 00000000`0000003d : nt!KiTimerExpiration+0x1be
fffff800`00b9cb90 fffff800`02cc596a : fffff800`02e43e80 fffff800`02e51cc0 00000000`00000002 fffff880`00000000 : nt!KiRetireDpcList+0x277
fffff800`00b9cc40 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cc00 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiKernelCalloutExceptionHandler+e
fffff800`02cc55fe 90 nop
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1E_0_nt!KiKernelCalloutExceptionHandler+e
BUCKET_ID: X64_0x1E_0_nt!KiKernelCalloutExceptionHandler+e
Followup: MachineOwner
---------
[/list]