Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: BSOD

03 Oct 2010   #1
dapyeatt

Windows 7 home x64
 
 
BSOD

I'm clueless, crashes intermittently, don't know why


My System SpecsSystem Spec
.
03 Oct 2010   #2
CarlTR6

Windows 7 Ultimate 32 bit
 
 

I will take a look and be right back. That is a lot of dumps!

I didn't have to look very far. The first dump I looked at directly blamed a driver, sptd.sys.
Quote:
Please remove any CD virtualization programs such as Daemon Tools and Alcohol 120%. They use a driver, found in your dmp, sptd.sys, that is notorious for causing BSODs. Use this SPTD uninstaller when you're done: DuplexSecure - Downloads. Select uninstall; do not select reinstall.
I will look further at more dumps; but in the meantime get rid of sptd and reboot.

Ilooked your four dumps from the today; I will look at more later.

Quote:
Stop error code D1, DRIVER_IRQL_NOT_LESS_OR_EQUAL, usually caused by a device driver.

Stop error code 3B, SYSTEM_SERVICE_EXCEPTION. Usual causes are System service, Device driver, graphics driver, ?memory

Stop error code 1E (2X), KMODE_EXCEPTION_NOT_HANDLED. Usual causes are Device driver, hardware, System service, compatibility, Remote control programs, memory, BIOS
Code:
Kernel base = 0xfffff800`02c0e000 PsLoadedModuleList = 0xfffff800`02e4be50
Debug session time: Sun Oct  3 16:25:39.423 2010 (GMT-4)
System Uptime: 0 days 0:32:14.739
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {1, 2, 8, 1}

Unable to load image \SystemRoot\System32\Drivers\sptd.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for sptd.sys
*** ERROR: Module load completed but symbols could not be loaded for sptd.sys
Probably caused by : mouhid.sys ( mouhid!MouHid_StartRead+d1 )

Followup: MachineOwner
---------

7: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000001, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: 0000000000000001, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb60e0
 0000000000000001 

CURRENT_IRQL:  2

FAULTING_IP: 
+53f2952f01b1df54
00000000`00000001 ??              ???

PROCESS_NAME:  System

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xD1

TRAP_FRAME:  fffff88003392530 -- (.trap 0xfffff88003392530)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000001 rbx=0000000000000000 rcx=fffffa800cef2810
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=0000000000000001 rsp=fffff880033926c8 rbp=fffffa800cea4940
 r8=fffff88005824e19  r9=0000000000000000 r10=000000000000001c
r11=fffffa800ad488a0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
00000000`00000001 ??              ???
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002c7dca9 to fffff80002c7e740

FAILED_INSTRUCTION_ADDRESS: 
+53f2952f01b1df54
00000000`00000001 ??              ???

STACK_TEXT:  
fffff880`033923e8 fffff800`02c7dca9 : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff880`033923f0 fffff800`02c7c920 : fffff880`0336a180 00000000`00000000 00000000`00000000 00000000`00000002 : nt!KiBugCheckDispatch+0x69
fffff880`03392530 00000000`00000001 : fffff880`05824e19 00000000`00000000 fffffa80`0ce892e0 fffffa80`0ce892e0 : nt!KiPageFault+0x260
fffff880`033926c8 fffff880`05824e19 : 00000000`00000000 fffffa80`0ce892e0 fffffa80`0ce892e0 fffffa80`0cee15c0 : 0x1
fffff880`033926d0 fffff880`05824cd1 : 00000000`00000000 00000000`ffffffff fffffa80`0ce892e0 fffffa80`0cee15c0 : mouhid!MouHid_StartRead+0xd1
fffff880`03392720 fffff800`02c80d26 : fffffa80`0cea4bc3 fffff880`00000000 fffffa80`00000001 00000000`00000000 : mouhid!MouHid_ReadComplete+0x6f5
fffff880`033927a0 fffff880`05804acc : fffffa80`0ade0d10 fffffa80`0ade0d06 fffffa80`0ceafc00 00000000`00000000 : nt!IopfCompleteRequest+0x3a6
fffff880`03392880 fffff880`05804d35 : fffffa80`0ce71d02 fffffa80`0ce71dd0 fffffa80`0ceafcb0 00000000`00000004 : HIDCLASS!HidpDistributeInterruptReport+0x130
fffff880`03392910 fffff800`02c80d26 : fffffa80`0ced24d3 00000000`00000000 fffffa80`0ceafb01 fffffa80`0ced22e0 : HIDCLASS!HidpInterruptReadComplete+0x235
fffff880`033929a0 fffff880`100135d9 : fffffa80`0be29050 fffffa80`0d953200 00000000`00000000 00000000`00000000 : nt!IopfCompleteRequest+0x3a6
fffff880`03392a80 fffff880`10013ab7 : fffffa80`0a984002 fffffa80`0ced22e0 00000000`ffffffff fffffa80`0be29ea8 : USBPORT!USBPORT_Core_iCompleteDoneTransfer+0xa15
fffff880`03392b60 fffff880`1001164f : fffffa80`0be29ea8 fffffa80`0be291a0 fffffa80`0be2a040 00000000`00000000 : USBPORT!USBPORT_Core_iIrpCsqCompleteDoneTransfer+0x3a7
fffff880`03392bc0 fffff880`10002f89 : fffffa80`0be29050 00000000`00000000 fffffa80`0be19702 fffffa80`0be29ea8 : USBPORT!USBPORT_Core_UsbIocDpc_Worker+0xf3
fffff880`03392c00 fffff880`0107c4ce : fffffa80`0be19000 fffffa80`0be29ea8 fffffa80`0be19750 fffffa80`0be29ec0 : USBPORT!USBPORT_Xdpc_Worker+0x1d9
fffff880`03392c30 fffffa80`0be19000 : fffffa80`0be29ea8 fffffa80`0be19750 fffffa80`0be29ec0 fffff880`0336a180 : sptd+0x424ce
fffff880`03392c38 fffffa80`0be29ea8 : fffffa80`0be19750 fffffa80`0be29ec0 fffff880`0336a180 00000000`00000000 : 0xfffffa80`0be19000
fffff880`03392c40 fffffa80`0be19750 : fffffa80`0be29ec0 fffff880`0336a180 00000000`00000000 fffff880`0336f040 : 0xfffffa80`0be29ea8
fffff880`03392c48 fffffa80`0be29ec0 : fffff880`0336a180 00000000`00000000 fffff880`0336f040 00000000`00000022 : 0xfffffa80`0be19750
fffff880`03392c50 fffff880`0336a180 : 00000000`00000000 fffff880`0336f040 00000000`00000022 00000000`00000000 : 0xfffffa80`0be29ec0
fffff880`03392c58 00000000`00000000 : fffff880`0336f040 00000000`00000022 00000000`00000000 00000000`00000000 : 0xfffff880`0336a180


STACK_COMMAND:  kb

FOLLOWUP_IP: 
mouhid!MouHid_StartRead+d1
fffff880`05824e19 488d8f98000000  lea     rcx,[rdi+98h]

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  mouhid!MouHid_StartRead+d1

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: mouhid

IMAGE_NAME:  mouhid.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bca94

FAILURE_BUCKET_ID:  X64_0xD1_CODE_AV_BAD_IP_mouhid!MouHid_StartRead+d1

BUCKET_ID:  X64_0xD1_CODE_AV_BAD_IP_mouhid!MouHid_StartRead+d1

Followup: MachineOwner
---------

7: kd> lmtsmn
start             end                 module name
fffff880`046eb000 fffff880`04729000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`0475e000 fffff880`047a3000   a1xly67r a1xly67r.SYS Tue Jul 14 17:12:55 2009 (4A5CF4D7)
fffff880`01198000 fffff880`011ef000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02e8f000 fffff880`02f19000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`047bc000 fffff880`047d2000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`01364000 fffff880`0136f000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`04729000 fffff880`04731000   ASACPI   ASACPI.sys   Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`03e65000 fffff880`03e6b000   AsIO     AsIO.sys     Thu Apr 22 07:18:03 2010 (4BD0306B)
fffff880`03e5f000 fffff880`03e65000   AsUpIO   AsUpIO.sys   Sun Jul 05 22:21:38 2009 (4A515FB2)
fffff880`05852000 fffff880`0585b000   aswFsBlk aswFsBlk.SYS Mon Jun 28 16:32:34 2010 (4C2906E2)
fffff880`04f06000 fffff880`04f20000   aswMonFlt aswMonFlt.sys Mon Jun 28 16:32:58 2010 (4C2906FA)
fffff880`02f19000 fffff880`02f23000   aswRdr   aswRdr.SYS   Mon Jun 28 16:33:15 2010 (4C29070B)
fffff880`03e3c000 fffff880`03e5f000   aswSP    aswSP.SYS    Mon Jun 28 16:37:34 2010 (4C29080E)
fffff880`01400000 fffff880`01410000   aswTdi   aswTdi.SYS   Mon Jun 28 16:37:54 2010 (4C290822)
fffff880`06a96000 fffff880`06aa1000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00e1a000 fffff880`00e23000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e23000 fffff880`00e4d000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`01b78000 fffff880`01b7f000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`02e77000 fffff880`02e88000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`0658e000 fffff880`065ac000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`00780000 fffff960`007a7000   cdd      cdd.dll      unavailable (00000000)
fffff880`05b00000 fffff880`05b1d000   cdfs     cdfs.sys     Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`01aa7000 fffff880`01ad1000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00c00000 fffff880`00cc0000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01b30000 fffff880`01b60000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00d2d000 fffff880`00d8b000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00d8b000 fffff880`00dfe000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`047ac000 fffff880`047bc000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`05b1d000 fffff880`05b2b000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`013cf000 fffff880`013ed000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`02e68000 fffff880`02e77000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01b1a000 fffff880`01b30000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`05acc000 fffff880`05aee000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`05b2b000 fffff880`05b35000   dump_diskdump dump_diskdump.sys Mon Jul 13 20:01:00 2009 (4A5BCABC)
fffff880`05bc1000 fffff880`05bd4000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05b35000 fffff880`05bc1000   dump_mv91xx dump_mv91xx.sys Fri Dec 25 01:45:39 2009 (4B345F93)
fffff880`01a8c000 fffff880`01a94000   dump_mvxxmm dump_mvxxmm.sys Fri Dec 25 01:45:15 2009 (4B345F7B)
fffff880`05af4000 fffff880`05b00000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`03ed9000 fffff880`03fcd000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`10d19000 fffff880`10d5f000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`10d5f000 fffff880`10da9000   e1y62x64 e1y62x64.sys Tue Oct 20 17:06:09 2009 (4ADE2641)
fffff880`013bb000 fffff880`013cf000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`0136f000 fffff880`013bb000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`015e7000 fffff880`015f1000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`01ae0000 fffff880`01b1a000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0162b000 fffff880`01675000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`031ea000 fffff800`03233000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`10db6000 fffff880`10dda000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`05800000 fffff880`05819000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`05819000 fffff880`05821080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`05be2000 fffff880`05bf0000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`064c6000 fffff880`0658e000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`017ec000 fffff880`017f5000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`04731000 fffff880`0474f000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`03e91000 fffff880`03ea7000   intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00fda000 fffff880`00ffa000   jraid    jraid.sys    Thu Oct 29 04:14:20 2009 (4AE94EDC)
fffff880`0474f000 fffff880`0475e000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00bbf000 fffff800`00bc9000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`046a2000 fffff880`046e5000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`015bc000 fffff880`015d6000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01600000 fffff880`0162b000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`05aee000 fffff880`05af3200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`04f41000 fffff880`04f56000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0582f000 fffff880`05852000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00cd5000 fffff880`00d19000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`05bd4000 fffff880`05be2000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`04691000 fffff880`046a0000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`05822000 fffff880`0582f000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00e00000 fffff880`00e1a000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`065ac000 fffff880`065c4000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`065c4000 fffff880`065f1000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`06400000 fffff880`0644e000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0644e000 fffff880`06471000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`01bdd000 fffff880`01be8000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`011ef000 fffff880`011f9000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01200000 fffff880`0125e000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`02e5d000 fffff880`02e68000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`017da000 fffff880`017ec000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`012d0000 fffff880`0135c000   mv91xx   mv91xx.sys   Fri Dec 25 01:45:39 2009 (4B345F93)
fffff880`0135c000 fffff880`01364000   mvxxmm   mvxxmm.sys   Fri Dec 25 01:45:15 2009 (4B345F7B)
fffff880`01688000 fffff880`0177a000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04600000 fffff880`0460c000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`04fa9000 fffff880`04fbc000   ndisuio  ndisuio.sys  Mon Jul 13 20:09:25 2009 (4A5BCCB5)
fffff880`0460c000 fffff880`0463b000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04ef1000 fffff880`04f06000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02fad000 fffff880`02fbc000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02f23000 fffff880`02f68000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0177a000 fffff880`017da000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`01be8000 fffff880`01bf9000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02e51000 fffff880`02e5d000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02c0e000 fffff800`031ea000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01419000 fffff880`015bc000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`01ad1000 fffff880`01ada000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`10067000 fffff880`1007f000   nusb3hub nusb3hub.sys Thu Jan 21 22:22:18 2010 (4B5919EA)
fffff880`03ea7000 fffff880`03ed7000   nusb3xhc nusb3xhc.sys Thu Jan 21 22:22:21 2010 (4B5919ED)
fffff880`10d17000 fffff880`10d18180   nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
fffff880`10085000 fffff880`10d16e00   nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
fffff880`04f56000 fffff880`04fa9000   nwifi    nwifi.sys    Mon Jul 13 20:07:23 2009 (4A5BCC3B)
fffff880`02f71000 fffff880`02f97000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`0100d000 fffff880`01022000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f3b000 fffff880`00f6e000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`011f9000 fffff880`01200000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00fca000 fffff880`00fda000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`015d6000 fffff880`015e7000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`06aa8000 fffff880`06b4e000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`05a8f000 fffff880`05acc000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00d19000 fffff880`00d2d000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`047d2000 fffff880`047f6000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`0463b000 fffff880`04656000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`04656000 fffff880`04677000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`04677000 fffff880`04691000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02e00000 fffff880`02e51000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`01bc2000 fffff880`01bcb000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01bcb000 fffff880`01bd4000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01bd4000 fffff880`01bdd000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`00e4d000 fffff880`00e87000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`04fbc000 fffff880`04fd4000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`05868000 fffff880`05a8e300   RTKVHD64 RTKVHD64.sys Fri Jan 29 01:48:35 2010 (4B6284C3)
fffff880`01675000 fffff880`0167f000   scmndisp scmndisp.sys Wed Jan 17 02:48:03 2007 (45ADD4B3)
fffff880`01169000 fffff880`01198000   SCSIPORT SCSIPORT.SYS Mon Jul 13 20:01:04 2009 (4A5BCAC0)
fffff880`06b4e000 fffff880`06b59000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`0167f000 fffff880`01687000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0103a000 fffff880`01160000   sptd     sptd.sys     Sun Oct 11 16:55:14 2009 (4AD24632)
fffff880`06a00000 fffff880`06a96000   srv      srv.sys      Mon Jun 21 23:21:11 2010 (4C202C27)
fffff880`06b98000 fffff880`06c00000   srv2     srv2.sys     Mon Jun 21 23:20:47 2010 (4C202C0F)
fffff880`06b59000 fffff880`06b86000   srvnet   srvnet.sys   Mon Jun 21 23:20:32 2010 (4C202C00)
fffff880`046a0000 fffff880`046a1480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01803000 fffff880`01a00000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`06b86000 fffff880`06b98000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`015f1000 fffff880`015fe000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`012aa000 fffff880`012c8000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02fd7000 fffff880`02feb000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00430000 fffff960`0043a000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`03e6b000 fffff880`03e91000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`10dda000 fffff880`10dec000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`03ed7000 fffff880`03ed8f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`10056000 fffff880`10067000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04e97000 fffff880`04ef1000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`10000000 fffff880`10056000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`10da9000 fffff880`10db6000   usbuhci  usbuhci.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`01000000 fffff880`0100d000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01b7f000 fffff880`01b8d000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`01b8d000 fffff880`01bb2000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`01022000 fffff880`01037000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00f6e000 fffff880`00fca000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`0125e000 fffff880`012aa000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02f97000 fffff880`02fad000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`02fbc000 fffff880`02fd7000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`01bb2000 fffff880`01bc2000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e88000 fffff880`00f2c000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f2c000 fffff880`00f3b000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02f68000 fffff880`02f71000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00070000 fffff960`0037f000   win32k   win32k.sys   unavailable (00000000)
fffff880`047a3000 fffff880`047ac000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`01160000 fffff880`01169000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`04f20000 fffff880`04f41000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)

Unloaded modules:
fffff880`04e00000 fffff880`04e71000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`01b60000 fffff880`01b6e000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`01b6e000 fffff880`01b78000   dump_scsipor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`01a00000 fffff880`01a8c000   dump_mv91xx.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`01a94000 fffff880`01aa7000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
-----

Kernel base = 0xfffff800`02c12000 PsLoadedModuleList = 0xfffff800`02e4fe50
Debug session time: Sun Oct  3 18:36:25.866 2010 (GMT-4)
System Uptime: 0 days 0:00:33.990
Loading Kernel Symbols
...............................................................
................................................................
..........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, 0, fffff88004858960, 0}

Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceHandler+7c )

Followup: MachineOwner
---------

6: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: 0000000000000000, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88004858960, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
+0
00000000`00000000 ??              ???

CONTEXT:  fffff88004858960 -- (.cxr 0xfffff88004858960)
rax=fffff8a002b3f1d0 rbx=0000000000000000 rcx=000000000000ffff
rdx=fffff88004859840 rsi=0000000000000000 rdi=000000000000007b
rip=0000000000000000 rsp=fffff88004859330 rbp=0000000000000000
 r8=fffff88004859370  r9=000000000000007b r10=0000000000000000
r11=0000000000000000 r12=fffff88004859840 r13=0000000000000000
r14=ffffffffffffffff r15=fffff88004859908
iopl=0         nv up ei pl nz ac pe cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010213
00000000`00000000 ??              ???
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0x3B

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

LAST_CONTROL_TRANSFER:  from 0000000000000000 to 0000000000000000

STACK_TEXT:  
fffff880`04858098 fffff800`02c81ca9 : 00000000`0000003b 00000000`c0000005 00000000`00000000 fffff880`04858960 : nt!KeBugCheckEx
fffff880`048580a0 fffff800`02c815fc : fffff800`02dd0b64 fffff800`02ccf8bb 00290065`00700079 fffff800`02e0eb40 : nt!KiBugCheckDispatch+0x69
fffff880`048581e0 fffff800`02ca840d : fffff800`02ea1f94 fffff800`02ddcaf4 fffff800`02c12000 fffff880`048590f8 : nt!KiSystemServiceHandler+0x7c
fffff880`04858220 fffff800`02cafa90 : fffff800`02dd21a0 fffff880`04858298 fffff880`048590f8 fffff800`02c12000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`04858250 fffff800`02cbc9ef : fffff880`048590f8 fffff880`04858960 fffff880`00000000 00000000`0000007b : nt!RtlDispatchException+0x410
fffff880`04858930 fffff800`02c81d82 : fffff880`048590f8 00000000`00000000 fffff880`048591a0 00000000`00000000 : nt!KiDispatchException+0x16f
fffff880`04858fc0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!KiSystemServiceHandler+7c
fffff800`02c815fc b801000000      mov     eax,1

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!KiSystemServiceHandler+7c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  4c1c44a9

FAILURE_BUCKET_ID:  X64_0x3B_nt!KiSystemServiceHandler+7c

BUCKET_ID:  X64_0x3B_nt!KiSystemServiceHandler+7c

Followup: MachineOwner
---------

Kernel base = 0xfffff800`02c0c000 PsLoadedModuleList = 0xfffff800`02e49e50
Debug session time: Sun Oct  3 18:35:04.145 2010 (GMT-4)
System Uptime: 0 days 0:07:37.269
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1E, {ffffffffc0000005, fffff80002ca1737, 0, ffffffffffffffff}

Probably caused by : memory_corruption

Followup: memory_corruption
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002ca1737, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP: 
nt!FsRtlEmptyFreePoolList+17
fffff800`02ca1737 488b10          mov     rdx,qword ptr [rax]

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb40e0
 ffffffffffffffff 

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  CODE_CORRUPTION

BUGCHECK_STR:  0x1E

PROCESS_NAME:  iexplore.exe

CURRENT_IRQL:  0

EXCEPTION_RECORD:  fffff880076fdae8 -- (.exr 0xfffff880076fdae8)
ExceptionAddress: fffff80002ca1737 (nt!FsRtlEmptyFreePoolList+0x0000000000000017)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

TRAP_FRAME:  fffff880076fdb90 -- (.trap 0xfffff880076fdb90)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=07cdb77c00000000 rbx=0000000000000000 rcx=fffff880076fdd78
rdx=0000001ffaa4a284 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ca1737 rsp=fffff880076fdd28 rbp=fffffa800d3a17f0
 r8=0000000000000000  r9=0000000000000000 r10=fffff980083c2800
r11=0000000000000050 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz ac po nc
nt!FsRtlEmptyFreePoolList+0x17:
fffff800`02ca1737 488b10          mov     rdx,qword ptr [rax] ds:7a30:07cdb77c`00000000=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002cb6a39 to fffff80002c7c740

STACK_TEXT:  
fffff880`076fd318 fffff800`02cb6a39 : 00000000`0000001e ffffffff`c0000005 fffff800`02ca1737 00000000`00000000 : nt!KeBugCheckEx
fffff880`076fd320 fffff800`02c7bd82 : fffff880`076fdae8 00000000`076fdd78 fffff880`076fdb90 fffff880`076fdf00 : nt!KiDispatchException+0x1b9
fffff880`076fd9b0 fffff800`02c7a68a : fffffa80`00000004 fffff8a0`0b2d05a0 fffff8a0`0b1e792c 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`076fdb90 fffff800`02ca1737 : fffffa80`0d3a17f0 fffff880`076fdfe0 00000000`00000001 fffffa80`0b6f6238 : nt!KiGeneralProtectionFault+0x10a
fffff880`076fdd28 fffffa80`00000243 : fffffa80`0b6f6238 fffffa80`0d3a17f0 00000000`000007ff fffffa80`0a8b7a01 : nt!FsRtlEmptyFreePoolList+0x17
fffff880`076fdd58 fffffa80`0b6f6238 : fffffa80`0d3a17f0 00000000`000007ff fffffa80`0a8b7a01 fffff880`076fdd78 : 0xfffffa80`00000243
fffff880`076fdd60 fffffa80`0d3a17f0 : 00000000`000007ff fffffa80`0a8b7a01 fffff880`076fdd78 fffff880`076fdd78 : 0xfffffa80`0b6f6238
fffff880`076fdd68 00000000`000007ff : fffffa80`0a8b7a01 fffff880`076fdd78 fffff880`076fdd78 fffff8a0`0adf1140 : 0xfffffa80`0d3a17f0
fffff880`076fdd70 fffffa80`0a8b7a01 : fffff880`076fdd78 fffff880`076fdd78 fffff8a0`0adf1140 fffffa80`0b6f5180 : 0x7ff
fffff880`076fdd78 fffff880`076fdd78 : fffff880`076fdd78 fffff8a0`0adf1140 fffffa80`0b6f5180 fffff8a0`0adf1140 : 0xfffffa80`0a8b7a01
fffff880`076fdd80 fffff880`076fdd78 : fffff8a0`0adf1140 fffffa80`0b6f5180 fffff8a0`0adf1140 00000000`00000001 : 0xfffff880`076fdd78
fffff880`076fdd88 fffff8a0`0adf1140 : fffffa80`0b6f5180 fffff8a0`0adf1140 00000000`00000001 fffff880`076fe4b0 : 0xfffff880`076fdd78
fffff880`076fdd90 fffffa80`0b6f5180 : fffff8a0`0adf1140 00000000`00000001 fffff880`076fe4b0 00000000`00000000 : 0xfffff8a0`0adf1140
fffff880`076fdd98 fffff8a0`0adf1140 : 00000000`00000001 fffff880`076fe4b0 00000000`00000000 fffff880`01517280 : 0xfffffa80`0b6f5180
fffff880`076fdda0 00000000`00000001 : fffff880`076fe4b0 00000000`00000000 fffff880`01517280 fffffa80`0b6f6238 : 0xfffff8a0`0adf1140
fffff880`076fdda8 fffff880`076fe4b0 : 00000000`00000000 fffff880`01517280 fffffa80`0b6f6238 fffffa80`0a8b7a00 : 0x1
fffff880`076fddb0 00000000`00000000 : fffff880`01517280 fffffa80`0b6f6238 fffffa80`0a8b7a00 fffffa80`0c90b920 : 0xfffff880`076fe4b0


STACK_COMMAND:  kb

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
    fffff80002ca1726 - nt!FsRtlEmptyFreePoolList+6
    [ 48:58 ]
1 error : !nt (fffff80002ca1726)

MODULE_NAME: memory_corruption

IMAGE_NAME:  memory_corruption

FOLLOWUP_NAME:  memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MEMORY_CORRUPTOR:  ONE_BIT

FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT

BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT

Followup: memory_corruption
---------
The last three dumps do not tell us specific causes; but they indicate memeory corruption. I find one really obsolete driver on your system. Out of date drivers can and do cause memory corruption and crashes.

scmndisp.sys Wed Jan 17 02:48:03 2007
- Netgear Neutral Wireless Solution, Support Home Page. Try to update this driver. If you cannot, you may have to unstall the Netgear hardware and upgrade to one that is Windows 7 compatible.

After you uninstall sptd.sys and update the nNetgeargear driver, reboot and let's see how your systems runs. If you get another BSOD, upload it and we will go from there. If your system runs smoothly, please update us and let us know.
My System SpecsSystem Spec
03 Oct 2010   #3
dapyeatt

Windows 7 home x64
 
 
WOW

I will update if everything goes well. I really appreciate your help!!!
My System SpecsSystem Spec
.

03 Oct 2010   #4
dapyeatt

Windows 7 home x64
 
 

Just crashed. How do you read the dump files? We were just coping files.
My System SpecsSystem Spec
03 Oct 2010   #5
CarlTR6

Windows 7 Ultimate 32 bit
 
 

We use a program called WinDbg to read the dumps.

Both of these dumps are error code 24, NTFS_FILE_SYSTEM. Usually caused by Disk corruption, insufficient physical memory, Device driver, Indexing, Resident antivirus, backup, defrag programs, Disk/Drive failing/failure.

The dumps do not point to a specific cause except that that Ntfs.sys failed and memory corruption. Since Ntfs.sys is a Windows core system driver, it is not likely the real cause. So we look at the usual causes. SPTD.sys is gone; but you still have that obsolete device driver, scmndisp.sys, on your system. Your antivirus is Avast and Avast should not be the cause; it generally runs well with Win 7.

Let's check your hard drive with Check Disk.
Quote:
Run CHKDSK /R /F from an elevated (Run as adminstrator) Command Prompt. Please do this for each hard drive on your system.
When it tells you it can't do it right now - and asks you if you'd like to do it at the next reboot - answer Y (for Yes) and press Enter. Then reboot and let the test run. It may take a while for it to run, but keep an occasional eye on it to see if it generates any errors. See "CHKDSK LogFile" below in order to check the results of the test.

Elevated Command Prompt:
Go to Start and type in "cmd.exe" (without the quotes)
At the top of the Search Box, right click on Cmd.exe and select "Run as administrator"

CHKDSK LogFile:
Go to Start and type in "eventvwr.msc" (without the quotes) and press Enter
Expand the Windows logs heading, then select the Application log file entry.
Double click on the Source column header.
Scroll down the list until you find the Chkdsk entry (wininit for Windows 7) (winlogon for XP).

Copy/paste the results into your next post.

Try to update
scmndisp.sys so that we can eliminate that driver as the cause.

Code:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Owner\AppData\Local\Temp\Temp1_Windows_NT6_BSOD_jcgriff2 (2).zip\Windows_NT6_BSOD_jcgriff2\100310-22604-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*Symbol information
Executable search path is: 
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c11000 PsLoadedModuleList = 0xfffff800`02e4ee50
Debug session time: Sun Oct  3 20:19:25.374 2010 (GMT-4)
System Uptime: 0 days 0:09:58.372
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 24, {1904fb, fffff8800827c6b8, fffff8800827bf20, fffff80002c528c3}

Probably caused by : Ntfs.sys ( Ntfs!NtfsDeleteFcb+179 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800827c6b8
Arg3: fffff8800827bf20
Arg4: fffff80002c528c3

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff8800827c6b8 -- (.exr 0xfffff8800827c6b8)
ExceptionAddress: fffff80002c528c3 (nt!DeleteNodeFromTree+0x00000000000000b3)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff8800827bf20 -- (.cxr 0xfffff8800827bf20)
rax=ffeff8a00c4904c0 rbx=fffff8a00beebe30 rcx=0000000000000000
rdx=00000000000000ff rsi=fffff8a00c8d74e0 rdi=fffff8a00c8bc780
rip=fffff80002c528c3 rsp=fffff8800827c8f0 rbp=fffffa800afac640
 r8=0000000000047aac  r9=0000ffffffffffff r10=fffff88001261880
r11=fffffa800dbba810 r12=0000000000000001 r13=fffffa800afac180
r14=fffff8800827c9ff r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
nt!DeleteNodeFromTree+0xb3:
fffff800`02c528c3 48397010        cmp     qword ptr [rax+10h],rsi ds:002b:ffeff8a0`0c4904d0=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  System

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb90e0
 ffffffffffffffff 

FOLLOWUP_IP: 
Ntfs!NtfsDeleteFcb+179
fffff880`0129af69 4c8b1b          mov     r11,qword ptr [rbx]

FAULTING_IP: 
nt!DeleteNodeFromTree+b3
fffff800`02c528c3 48397010        cmp     qword ptr [rax+10h],rsi

BUGCHECK_STR:  0x24

LAST_CONTROL_TRANSFER:  from fffff80002c529e9 to fffff80002c528c3

STACK_TEXT:  
fffff880`0827c8f0 fffff800`02c529e9 : fffffa80`0afac640 fffff800`02e265a0 fffffa80`0dbba810 fffffa80`0afac180 : nt!DeleteNodeFromTree+0xb3
fffff880`0827c930 fffff880`0129af69 : fffff880`0827c9f0 fffff800`02e265a0 fffff8a0`0c8bc780 fffffa80`0cf776b0 : nt!RtlDeleteElementGenericTableAvl+0x39
fffff880`0827c960 fffff880`0120df6a : fffff800`02e265a0 fffff880`0827cb01 fffff880`0827c9e1 fffff8a0`0c86d910 : Ntfs!NtfsDeleteFcb+0x179
fffff880`0827c9c0 fffff880`012982cc : fffffa80`0cf776b0 fffffa80`0afac180 fffff8a0`0c86d910 fffff8a0`0c86dca8 : Ntfs!NtfsTeardownFromLcb+0x1ea
fffff880`0827ca50 fffff880`01216882 : fffffa80`0cf776b0 fffffa80`0cf776b0 fffff8a0`0c86d910 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`0827cad0 fffff880`012af813 : fffffa80`0cf776b0 fffff800`02e265a0 fffff8a0`0c86d910 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`0827cb10 fffff880`0128938f : fffffa80`0cf776b0 fffff8a0`0c86da40 fffff8a0`0c86d910 fffffa80`0afac180 : Ntfs!NtfsCommonClose+0x353
fffff880`0827cbe0 fffff800`02c8e961 : 00000000`00000000 fffff880`01289200 fffffa80`0d3e9b01 fffffa80`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`0827ccb0 fffff800`02f25c06 : 00000000`03a7ce7a fffffa80`0d3e9b60 00000000`00000080 fffffa80`09d42b30 : nt!ExpWorkerThread+0x111
fffff880`0827cd40 fffff800`02c5fc26 : fffff800`02dfbe80 fffffa80`0d3e9b60 fffffa80`09d72b60 fffff880`01213534 : nt!PspSystemThreadStartup+0x5a
fffff880`0827cd80 00000000`00000000 : fffff880`0827d000 fffff880`08277000 fffff880`0827c9f0 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  Ntfs!NtfsDeleteFcb+179

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc14f

STACK_COMMAND:  .cxr 0xfffff8800827bf20 ; kb

FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsDeleteFcb+179

BUCKET_ID:  X64_0x24_Ntfs!NtfsDeleteFcb+179

Followup: MachineOwner
---------

0: kd> lmtsmn
start             end                 module name
fffff880`10b9c000 fffff880`10bda000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f4b000 fffff880`00fa2000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`04209000 fffff880`04293000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`0fe00000 fffff880`0fe16000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`01157000 fffff880`01162000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`04424000 fffff880`0442c000   ASACPI   ASACPI.sys   Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`04200000 fffff880`04206000   AsIO     AsIO.sys     Thu Apr 22 07:18:03 2010 (4BD0306B)
fffff880`043fa000 fffff880`04400000   AsUpIO   AsUpIO.sys   Sun Jul 05 22:21:38 2009 (4A515FB2)
fffff880`059e5000 fffff880`059ee000   aswFsBlk aswFsBlk.SYS Mon Jun 28 16:32:34 2010 (4C2906E2)
fffff880`059cb000 fffff880`059e5000   aswMonFlt aswMonFlt.sys Mon Jun 28 16:32:58 2010 (4C2906FA)
fffff880`04293000 fffff880`0429d000   aswRdr   aswRdr.SYS   Mon Jun 28 16:33:15 2010 (4C29070B)
fffff880`02c68000 fffff880`02c8b000   aswSP    aswSP.SYS    Mon Jun 28 16:37:34 2010 (4C29080E)
fffff880`02c47000 fffff880`02c57000   aswTdi   aswTdi.SYS   Mon Jun 28 16:37:54 2010 (4C290822)
fffff880`07800000 fffff880`0780b000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`01090000 fffff880`01099000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01099000 fffff880`010c3000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`02d9b000 fffff880`02da2000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`02c57000 fffff880`02c68000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`073b6000 fffff880`073d4000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`006a0000 fffff960`006c7000   cdd      cdd.dll      unavailable (00000000)
fffff880`02d68000 fffff880`02d92000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00d1a000 fffff880`00dda000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01450000 fffff880`01480000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00cbc000 fffff880`00d1a000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`014e5000 fffff880`01558000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`10be9000 fffff880`10bf9000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`058a6000 fffff880`058b4000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`043dc000 fffff880`043fa000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`043cd000 fffff880`043dc000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`0143a000 fffff880`01450000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`05872000 fffff880`05894000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`058b4000 fffff880`058be000   dump_diskdump dump_diskdump.sys Mon Jul 13 20:01:00 2009 (4A5BCABC)
fffff880`0594a000 fffff880`0595d000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`058be000 fffff880`0594a000   dump_mv91xx dump_mv91xx.sys Fri Dec 25 01:45:39 2009 (4B345F93)
fffff880`02d4d000 fffff880`02d55000   dump_mvxxmm dump_mvxxmm.sys Fri Dec 25 01:45:15 2009 (4B345F7B)
fffff880`0589a000 fffff880`058a6000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`04455000 fffff880`04549000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04549000 fffff880`0458f000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`0458f000 fffff880`045d9000   e1y62x64 e1y62x64.sys Tue Oct 20 17:06:09 2009 (4ADE2641)
fffff880`011ae000 fffff880`011c2000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`01162000 fffff880`011ae000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`01569000 fffff880`01573000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`01400000 fffff880`0143a000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0179c000 fffff880`017e6000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`031ed000 fffff800`03236000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04400000 fffff880`04424000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`05979000 fffff880`05992000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`05992000 fffff880`0599a080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`0596b000 fffff880`05979000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`072ee000 fffff880`073b6000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`01612000 fffff880`0161b000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`0442c000 fffff880`0444a000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01498000 fffff880`014ae000   intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00c00000 fffff880`00c20000   jraid    jraid.sys    Thu Oct 29 04:14:20 2009 (4AE94EDC)
fffff880`10bda000 fffff880`10be9000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00bae000 fffff800`00bb8000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`04cb5000 fffff880`04cf8000   ks       ks.sys       Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`013a8000 fffff880`013c2000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01771000 fffff880`0179c000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`05894000 fffff880`05899200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`04db2000 fffff880`04dc7000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`059a8000 fffff880`059cb000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c64000 fffff880`00ca8000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`0595d000 fffff880`0596b000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`02cb1000 fffff880`02cc0000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`0599b000 fffff880`059a8000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`01076000 fffff880`01090000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`073d4000 fffff880`073ec000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`07200000 fffff880`0722d000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`0722d000 fffff880`0727b000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0727b000 fffff880`0729e000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`02c00000 fffff880`02c0b000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00fab000 fffff880`00fb5000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01000000 fffff880`0105e000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`043c2000 fffff880`043cd000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`01600000 fffff880`01612000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`010c3000 fffff880`0114f000   mv91xx   mv91xx.sys   Fri Dec 25 01:45:39 2009 (4B345F93)
fffff880`0114f000 fffff880`01157000   mvxxmm   mvxxmm.sys   Fri Dec 25 01:45:15 2009 (4B345F7B)
fffff880`0161f000 fffff880`01711000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`0fe3a000 fffff880`0fe46000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`04c53000 fffff880`04c66000   ndisuio  ndisuio.sys  Mon Jul 13 20:09:25 2009 (4A5BCCB5)
fffff880`0fe46000 fffff880`0fe75000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04d7c000 fffff880`04d91000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`04327000 fffff880`04336000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`0429d000 fffff880`042e2000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01711000 fffff880`01771000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`02c0b000 fffff880`02c1c000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`043b6000 fffff880`043c2000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02c11000 fffff800`031ed000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01205000 fffff880`013a8000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`02d92000 fffff880`02d9b000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`04d0a000 fffff880`04d22000   nusb3hub nusb3hub.sys Thu Jan 21 22:22:18 2010 (4B5919EA)
fffff880`014ae000 fffff880`014de000   nusb3xhc nusb3xhc.sys Thu Jan 21 22:22:21 2010 (4B5919ED)
fffff880`10b44000 fffff880`10b45180   nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
fffff880`0feb2000 fffff880`10b43e00   nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
fffff880`04c00000 fffff880`04c53000   nwifi    nwifi.sys    Mon Jul 13 20:07:23 2009 (4A5BCC3B)
fffff880`042eb000 fffff880`04311000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00e00000 fffff880`00e15000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00fc2000 fffff880`00ff5000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e86000 fffff880`00e8d000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00dda000 fffff880`00dea000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01558000 fffff880`01569000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0780b000 fffff880`078b1000   peauth   peauth.sys   Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`05835000 fffff880`05872000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00ca8000 fffff880`00cbc000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`0fe16000 fffff880`0fe3a000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`0fe75000 fffff880`0fe90000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`0fe90000 fffff880`0feb1000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`013c2000 fffff880`013dc000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`04365000 fffff880`043b6000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`02de5000 fffff880`02dee000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02dee000 fffff880`02df7000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02df7000 fffff880`02e00000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`015bf000 fffff880`015f9000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`04c66000 fffff880`04c7e000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0560e000 fffff880`05834300   RTKVHD64 RTKVHD64.sys Fri Jan 29 01:48:35 2010 (4B6284C3)
fffff880`017e6000 fffff880`017f0000   scmndisp scmndisp.sys Wed Jan 17 02:48:03 2007 (45ADD4B3)
fffff880`00c20000 fffff880`00c4f000   SCSIPORT SCSIPORT.SYS Mon Jul 13 20:01:04 2009 (4A5BCAC0)
fffff880`078b1000 fffff880`078bc000   secdrv   secdrv.SYS   Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`017f0000 fffff880`017f8000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`07963000 fffff880`079f9000   srv      srv.sys      Mon Jun 21 23:21:11 2010 (4C202C27)
fffff880`078fb000 fffff880`07963000   srv2     srv2.sys     Mon Jun 21 23:20:47 2010 (4C202C0F)
fffff880`078bc000 fffff880`078e9000   srvnet   srvnet.sys   Mon Jun 21 23:20:32 2010 (4C202C00)
fffff880`04453000 fffff880`04454480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01801000 fffff880`019fe000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`078e9000 fffff880`078fb000   tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02c3a000 fffff880`02c47000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02c1c000 fffff880`02c3a000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`04351000 fffff880`04365000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`005c0000 fffff960`005ca000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`02c8b000 fffff880`02cb1000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04cf8000 fffff880`04d0a000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`04206000 fffff880`04207f00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`045e6000 fffff880`045f7000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04d22000 fffff880`04d7c000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`10b46000 fffff880`10b9c000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`045d9000 fffff880`045e6000   usbuhci  usbuhci.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00fb5000 fffff880`00fc2000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`02da2000 fffff880`02db0000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`02db0000 fffff880`02dd5000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00e15000 fffff880`00e2a000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e2a000 fffff880`00e86000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01573000 fffff880`015bf000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`04311000 fffff880`04327000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`04336000 fffff880`04351000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`02dd5000 fffff880`02de5000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e98000 fffff880`00f3c000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f3c000 fffff880`00f4b000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`042e2000 fffff880`042eb000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000d0000 fffff960`003df000   win32k   win32k.sys   unavailable (00000000)
fffff880`0444a000 fffff880`04453000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00fa2000 fffff880`00fab000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`04d91000 fffff880`04db2000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)

Unloaded modules:
fffff880`02cc0000 fffff880`02d31000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`01480000 fffff880`0148e000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`0148e000 fffff880`01498000   dump_scsipor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`02cc1000 fffff880`02d4d000   dump_mv91xx.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
fffff880`02d55000 fffff880`02d68000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
---


Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Owner\AppData\Local\Temp\Temp1_Windows_NT6_BSOD_jcgriff2 (2).zip\Windows_NT6_BSOD_jcgriff2\100310-19983-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*Symbol information
Executable search path is: 
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c19000 PsLoadedModuleList = 0xfffff800`02e56e50
Debug session time: Sun Oct  3 19:43:53.480 2010 (GMT-4)
System Uptime: 0 days 0:38:07.604
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 24, {1904fb, fffff88008303938, fffff880083031a0, fffff880014ba5a9}

Probably caused by : Ntfs.sys ( Ntfs!NtfsCheckExistingFile+f9 )

Followup: MachineOwner
---------

4: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88008303938
Arg3: fffff880083031a0
Arg4: fffff880014ba5a9

Debugging Details:
------------------


EXCEPTION_RECORD:  fffff88008303938 -- (.exr 0xfffff88008303938)
ExceptionAddress: fffff880014ba5a9 (Ntfs!NtfsCheckExistingFile+0x00000000000000f9)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff880083031a0 -- (.cxr 0xfffff880083031a0)
rax=fffff8a033e9a040 rbx=ffeff8a033e99fe0 rcx=00000000000000a0
rdx=fffffa801304c9c0 rsi=0000000000000000 rdi=fffff8a033e9a010
rip=fffff880014ba5a9 rsp=fffff88008303b70 rbp=0000000000000000
 r8=0000000000000001  r9=0000000000000000 r10=fffff8a02f0f7060
r11=fffffa801304c9c0 r12=fffffa8014c76e40 r13=fffffa800de8f010
r14=fffff880083043c0 r15=fffffa8014d8cc10
iopl=0         nv up ei ng nz na pe cy
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010283
Ntfs!NtfsCheckExistingFile+0xf9:
fffff880`014ba5a9 8b8bac000000    mov     ecx,dword ptr [rbx+0ACh] ds:002b:ffeff8a0`33e9a08c=????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  TortoiseProc.e

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec10e0
 ffffffffffffffff 

FOLLOWUP_IP: 
Ntfs!NtfsCheckExistingFile+f9
fffff880`014ba5a9 8b8bac000000    mov     ecx,dword ptr [rbx+0ACh]

FAULTING_IP: 
Ntfs!NtfsCheckExistingFile+f9
fffff880`014ba5a9 8b8bac000000    mov     ecx,dword ptr [rbx+0ACh]

BUGCHECK_STR:  0x24

LAST_CONTROL_TRANSFER:  from fffff880014bad73 to fffff880014ba5a9

STACK_TEXT:  
fffff880`08303b70 fffff880`014bad73 : fffff880`083043c0 fffff8a0`33e9a010 00000000`00000002 00000000`00001001 : Ntfs!NtfsCheckExistingFile+0xf9
fffff880`08303c00 fffff880`014b76ef : fffff880`083043c0 fffffa80`0a8e4080 00000000`00000005 fffff800`00000042 : Ntfs!NtfsOpenExistingAttr+0x73
fffff880`08303cc0 fffff880`014b7eff : fffffa80`14c76e40 fffffa80`14d8c900 fffff8a0`33e9a450 fffff880`00000042 : Ntfs!NtfsOpenAttributeInExistingFile+0x50f
fffff880`08303e50 fffff880`014c8e76 : fffffa80`14c76e40 fffffa80`14d8c900 fffff8a0`33e9a450 fffffa80`15949c01 : Ntfs!NtfsOpenExistingPrefixFcb+0x1ef
fffff880`08303f40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsFindStartingNode+0x5e6


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  Ntfs!NtfsCheckExistingFile+f9

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME:  Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc14f

STACK_COMMAND:  .cxr 0xfffff880083031a0 ; kb

FAILURE_BUCKET_ID:  X64_0x24_Ntfs!NtfsCheckExistingFile+f9

BUCKET_ID:  X64_0x24_Ntfs!NtfsCheckExistingFile+f9

Followup: MachineOwner
---------
My System SpecsSystem Spec
04 Oct 2010   #6
dapyeatt

Windows 7 home x64
 
 

It was one of my memory sticks. I think... It checked out on the windows 7 memtest so I ruled that out. But I took it out and now it works with out crashing. Also, I had this memory in another box and it worked fine for 6 months.

The other thing that gets me is the memory put back in my old box still works fine. Could it be my MB?
My System SpecsSystem Spec
04 Oct 2010   #7
CarlTR6

Windows 7 Ultimate 32 bit
 
 

Yes, it could be a bad memory slot on the mother board. I do not have a lot of confidence in Windows built in memory test. Most of us here recommend Memtest86 which runs outside of Windows. I was going to suggest Memtest if all came out well with Check Disk, which I still recommend that you run.

Here is a tutorial on Memtest written by Jonathan King:
RAM - Test with Memtest86+.

Put all of your RAM in and run Memtest for at least seven passes or until you see errors. This will take about six or seven hours. If you get errors, pull all of your RAM except one stick and repeat the the test. Do this with each stick. If all sticks pass individually, take a good stick and test each RAM slot. If all the slots pass, it may be a RAM compatibility problem.

I know this is time consuming; but there is not short cut. Post back with your results.
My System SpecsSystem Spec
04 Oct 2010   #8
dapyeatt

Windows 7 home x64
 
 

Okay I ran the chkdsk... Is this stuff I want to post?

Checking file system on C: The type of the file system is NTFS. One of your disks needs to be checked for consistency. You may cancel the disk check, but it is strongly recommended that you continue. Windows will now check the disk. CHKDSK is verifying files (stage 1 of 3)... 284416 file records processed. File verification completed. 125 large file records processed. 0 bad file records processed. 0 EA records processed. 60 reparse records processed. CHKDSK is verifying indexes (stage 2 of 3)... 387278 index entries processed. Index verification completed. 0 unindexed files scanned. 0 unindexed files recovered. CHKDSK is verifying security descriptors (stage 3 of 3)... 284416 file SDs/SIDs processed. Cleaning up 357 unused index entries from index $SII of file 0x9. Cleaning up 357 unused index entries from index $SDH of file 0x9. Cleaning up 357 unused security descriptors. Security descriptor verification completed. 51432 data files processed. CHKDSK is verifying Usn Journal... 35899144 USN bytes processed. Usn Journal verification completed. CHKDSK discovered free space marked as allocated in the master file table (MFT) bitmap. CHKDSK discovered free space marked as allocated in the volume bitmap. Windows has made corrections to the file system. 585956351 KB total disk space. 80396180 KB in 232587 files. 129248 KB in 51433 indexes. 0 KB in bad sectors. 403883 KB in use by the system. 65536 KB occupied by the log file. 505027040 KB available on disk. 4096 bytes in each allocation unit. 146489087 total allocation units on disk. 126256760 allocation units available on disk. Internal Info: 00 57 04 00 80 55 04 00 d2 f3 07 00 00 00 00 00 .W...U.......... df 01 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 ....<........... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ Windows has finished checking your disk. Please wait while your computer restarts.
My System SpecsSystem Spec
04 Oct 2010   #9
CarlTR6

Windows 7 Ultimate 32 bit
 
 

What this means is that Check Disk found your drive to be OK; but it cleaned up some loose ends. That is good news. Now on to Memtest.
My System SpecsSystem Spec
05 Oct 2010   #10
dapyeatt

Windows 7 home x64
 
 

Apparently the memory is good. According to the test it is anyway. Right now the memory is laying on my desk because whatever machine I put it in starts locking up. Sort of frustrating. But at least nobody is getting the BOSD at the moment. So problem solved. Oh, and I did update that net-gear wireless driver. I don't think it was the problem, but at least we know for sure. I want to thank you for all your help, and I hope one day to return the favor by helping someone else who has as much trouble as I did. Thanks again!!!!
My System SpecsSystem Spec
Reply

 BSOD




Thread Tools



Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 14:49.
Twitter Facebook Google+ Seven Forums iOS App Seven Forums Android App