[list=1]
[*]
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\BFHunter\Windows_NT6_BSOD_jcgriff2\032112-18439-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02e1b000 PsLoadedModuleList = 0xfffff800`03058e50
Debug session time: Wed Mar 21 17:28:00.255 2012 (UTC - 6:00)
System Uptime: 0 days 0:04:33.893
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {fffff87ff09a9c98, 2, 0, fffff80002ed4099}
Probably caused by : memory_corruption ( nt!MmZeroPageThread+5e4 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff87ff09a9c98, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002ed4099, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030c30e0
fffff87ff09a9c98
CURRENT_IRQL: 2
FAULTING_IP:
nt!MmZeroPageThread+5e4
fffff800`02ed4099 0fb6842488000000 movzx eax,byte ptr [rsp+88h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: System
TRAP_FRAME: fffff880009a9a80 -- (.trap 0xfffff880009a9a80)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8004fe06f0 rbx=0000000000000000 rcx=fffff880009a9c68
rdx=fffffa8000000008 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ed4099 rsp=fffff880009a9c10 rbp=00000000000000ff
r8=0000000000000000 r9=0000000000000000 r10=fffffa8006a82e10
r11=fffff880009a9c08 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!MmZeroPageThread+0x5e4:
fffff800`02ed4099 0fb6842488000000 movzx eax,byte ptr [rsp+88h] ss:0018:fffff880`009a9c98=00
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e8c469 to fffff80002e8cf00
STACK_TEXT:
fffff880`009a9938 fffff800`02e8c469 : 00000000`0000000a fffff87f`f09a9c98 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`009a9940 fffff800`02e8b0e0 : fffffa80`04fdffd0 00000000`001a9600 fffffa80`04fdffd0 00000000`00000001 : nt!KiBugCheckDispatch+0x69
fffff880`009a9a80 fffff800`02ed4099 : 00000000`000000ff 00000000`00000026 00000000`00000026 00000000`00000000 : nt!KiPageFault+0x260
fffff880`009a9c10 fffff800`03130166 : fffffa80`06ba5040 00000000`00000080 fffffa80`06b2c9e0 fffff800`02e6b479 : nt!MmZeroPageThread+0x5e4
fffff880`009a9d40 fffff800`02e6b486 : fffff800`03005e80 fffffa80`06ba5040 fffff800`03013c40 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`009a9d80 00000000`00000000 : fffff880`009aa000 fffff880`009a4000 fffff880`009a99b0 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MmZeroPageThread+5e4
fffff800`02ed4099 0fb6842488000000 movzx eax,byte ptr [rsp+88h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MmZeroPageThread+5e4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0xA_nt!MmZeroPageThread+5e4
BUCKET_ID: X64_0xA_nt!MmZeroPageThread+5e4
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\BFHunter\Windows_NT6_BSOD_jcgriff2\032012-20326-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02e07000 PsLoadedModuleList = 0xfffff800`03044e50
Debug session time: Tue Mar 20 23:10:43.138 2012 (UTC - 6:00)
System Uptime: 0 days 0:19:23.777
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
Loading unloaded module list
................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff880062562e8, fffff88006255b40, fffff8800130ea6c}
Probably caused by : hardware ( Ntfs!NtfsWriteLog+49c )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff880062562e8
Arg3: fffff88006255b40
Arg4: fffff8800130ea6c
Debugging Details:
------------------
EXCEPTION_RECORD: fffff880062562e8 -- (.exr 0xfffff880062562e8)
ExceptionAddress: fffff8800130ea6c (Ntfs!NtfsWriteLog+0x000000000000049c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 00000000ffffff8a
Attempt to write to address 00000000ffffff8a
CONTEXT: fffff88006255b40 -- (.cxr 0xfffff88006255b40)
rax=00000000ffffffff rbx=0000000000000000 rcx=fffffa800925e010
rdx=fffffa8007216b60 rsi=fffff880062566b0 rdi=fffffa8007c55028
rip=fffff8800130ea6c rsp=fffff88006256520 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000000 r10=0000001800000028
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000702 r15=fffffa800851f690
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
Ntfs!NtfsWriteLog+0x49c:
fffff880`0130ea6c 10488b adc byte ptr [rax-75h],cl ds:002b:00000000`ffffff8a=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: msiexec.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 00000000ffffff8a
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030af0e0
00000000ffffff8a
FOLLOWUP_IP:
Ntfs!NtfsWriteLog+49c
fffff880`0130ea6c 10488b adc byte ptr [rax-75h],cl
FAULTING_IP:
Ntfs!NtfsWriteLog+49c
fffff880`0130ea6c 10488b adc byte ptr [rax-75h],cl
BUGCHECK_STR: 0x24
MISALIGNED_IP:
Ntfs!NtfsWriteLog+49c
fffff880`0130ea6c 10488b adc byte ptr [rax-75h],cl
LAST_CONTROL_TRANSFER: from fffff880012fa4f6 to fffff8800130ea6c
STACK_TEXT:
fffff880`06256520 fffff880`012fa4f6 : 00000000`00000000 fffffa80`0925e010 00000000`00000000 fffff880`062567b0 : Ntfs!NtfsWriteLog+0x49c
fffff880`06256770 fffff880`01268f51 : fffffa80`0851f690 00000000`00000000 fffffa80`0925e010 fffffa80`0851f690 : Ntfs!NtfsCommitCurrentTransaction+0x126
fffff880`06256800 fffff880`012f2dfa : fffff8a0`077092d0 fffffa80`07c68180 00000000`00000000 fffff880`0102d100 : Ntfs!NtfsExtendedCompleteRequestInternal+0x131
fffff880`06256840 fffff880`01261e0c : fffffa80`0925e010 fffffa80`0851f690 fffff880`06256901 fffff880`06256900 : Ntfs!NtfsCommonSetInformation+0xef1
fffff880`06256920 fffff880`0102723f : fffff880`06256a50 fffffa80`0851f690 fffffa80`0925e010 fffff880`06256948 : Ntfs!NtfsFsdSetInformation+0x11c
fffff880`062569a0 fffff880`010256df : fffffa80`07c63de0 fffffa80`0851f690 fffffa80`07c63d00 fffffa80`0851f690 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`06256a30 fffff800`03159142 : 00000000`00000008 fffff880`06256ca0 fffffa80`0851f690 00000000`00000000 : fltmgr!FltpDispatch+0xcf
fffff880`06256a90 fffff800`02e78153 : 00000000`00000344 fffffa80`07216b60 00000000`0084f458 ffffffff`00000008 : nt!NtSetInformationFile+0x5ae
fffff880`06256bb0 00000000`7707012a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0084f438 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7707012a
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsWriteLog+49c
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .cxr 0xfffff88006255b40 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED_Ntfs.sys
BUCKET_ID: X64_IP_MISALIGNED_Ntfs.sys
Followup: MachineOwner
---------
[/list]