Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c02000 PsLoadedModuleList = 0xfffff800`02e3fe50
Debug session time: Wed Feb 2 16:19:11.240 2011 (GMT-5)
System Uptime: 0 days 1:42:14.130
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
..........................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa8c00f50a90, 0, fffff80002ca33fa, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiDeleteVirtualAddresses+481 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa8c00f50a90, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002ca33fa, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eaa0e0
fffffa8c00f50a90
FAULTING_IP:
nt!MiDeleteVirtualAddresses+481
fffff800`02ca33fa 448b2b mov r13d,dword ptr [rbx]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88008d4bde0 -- (.trap 0xfffff88008d4bde0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000040051ae3 rbx=0000000000000000 rcx=0000058000000000
rdx=000000000000014e rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ca33fa rsp=fffff88008d4bf70 rbp=000000000b350000
r8=0000000000000001 r9=fffffa80053e0330 r10=0000000fffffffff
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!MiDeleteVirtualAddresses+0x481:
fffff800`02ca33fa 448b2b mov r13d,dword ptr [rbx] ds:00000000`00000000=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cf18c1 to fffff80002c72740
STACK_TEXT:
fffff880`08d4bc78 fffff800`02cf18c1 : 00000000`00000050 fffffa8c`00f50a90 00000000`00000000 fffff880`08d4bde0 : nt!KeBugCheckEx
fffff880`08d4bc80 fffff800`02c7082e : 00000000`00000000 fffffa8c`00f50a90 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x40e8b
fffff880`08d4bde0 fffff800`02ca33fa : 00000000`00000000 fffff680`00058ff8 fffffa80`053e0330 00000000`00000050 : nt!KiPageFault+0x16e
fffff880`08d4bf70 fffff800`02cb40da : 00000000`00000000 00000000`0b847fff fffffa80`00000000 fffffa80`053e0330 : nt!MiDeleteVirtualAddresses+0x481
fffff880`08d4c130 fffff800`02c71993 : ffffffff`ffffffff 00000000`0010e900 00000000`0010e8c8 00000000`00008000 : nt!NtFreeVirtualMemory+0x5ca
fffff880`08d4c220 00000000`77d8ff3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0010e838 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77d8ff3a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiDeleteVirtualAddresses+481
fffff800`02ca33fa 448b2b mov r13d,dword ptr [rbx]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiDeleteVirtualAddresses+481
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiDeleteVirtualAddresses+481
BUCKET_ID: X64_0x50_nt!MiDeleteVirtualAddresses+481
Followup: MachineOwner
---------
Debug session time: Wed Feb 2 14:36:28.982 2011 (GMT-5)
System Uptime: 0 days 0:48:10.872
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff88001324c7c, 2, 8, fffff88001324c7c}
Probably caused by : Ntfs.sys ( Ntfs! ?? ::NNGAKEGL::`string'+2ad0 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff88001324c7c, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffff88001324c7c, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002efa0e0
fffff88001324c7c
CURRENT_IRQL: 2
FAULTING_IP:
Ntfs! ?? ::NNGAKEGL::`string'+2ad0
fffff880`01324c7c 55 push rbp
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: Wow.exe
TRAP_FRAME: fffff880053d9ff0 -- (.trap 0xfffff880053d9ff0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff88001324c7c rbx=0000000000000000 rcx=fffff880053da1c0
rdx=fffff880053db770 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001324c7c rsp=fffff880053da188 rbp=fffff880053da2c0
r8=fffff880053da940 r9=fffff880053da2c0 r10=fffff880053db940
r11=fffff880053da1f8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
Ntfs! ?? ::NNGAKEGL::`string'+0x2ad0:
fffff880`01324c7c 55 push rbp
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cc1ca9 to fffff80002cc2740
FAILED_INSTRUCTION_ADDRESS:
Ntfs! ?? ::NNGAKEGL::`string'+2ad0
fffff880`01324c7c 55 push rbp
STACK_TEXT:
fffff880`053d9ea8 fffff800`02cc1ca9 : 00000000`0000000a fffff880`01324c7c 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff880`053d9eb0 fffff800`02cc0920 : 23d0052e`00000000 fffff880`01284544 052e23d0`052e0000 00000001`052e23d0 : nt!KiBugCheckDispatch+0x69
fffff880`053d9ff0 fffff880`01324c7c : fffff800`02cf0d1c 00000000`00000000 23d0052e`23d0052e 00020000`0001052e : nt!KiPageFault+0x260
fffff880`053da188 fffff800`02cf0d1c : 00000000`00000000 23d0052e`23d0052e 00020000`0001052e 65280015`ae580000 : Ntfs! ?? ::NNGAKEGL::`string'+0x2ad0
fffff880`053da190 fffff800`02ce840d : fffff880`01284538 fffff880`053db770 00000000`00000000 fffff880`01233000 : nt!_C_specific_handler+0x8c
fffff880`053da200 fffff800`02cefa90 : fffff880`01284538 fffff880`053da278 fffff880`053db0d8 fffff880`01233000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`053da230 fffff800`02cfc9ef : fffff880`053db0d8 fffff880`053da940 fffff880`00000000 00000000`00000004 : nt!RtlDispatchException+0x410
fffff880`053da910 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x16f
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs! ?? ::NNGAKEGL::`string'+2ad0
fffff880`01324c7c 55 push rbp
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs! ?? ::NNGAKEGL::`string'+2ad0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!_??_::NNGAKEGL::_string_+2ad0
BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_Ntfs!_??_::NNGAKEGL::_string_+2ad0
Followup: MachineOwner
---------