Code:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02a08000 PsLoadedModuleList = 0xfffff800`02c45e50
Debug session time: Sat Oct 23 16:55:37.837 2010 (GMT-4)
System Uptime: 0 days 0:00:22.429
Loading Kernel Symbols
.................................................Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
Unable to add module at 00000000`00000000
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41284, fffff680003a3001, 1418, fffff70001080000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a83 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: fffff680003a3001
Arg3: 0000000000001418
Arg4: fffff70001080000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002acd3b3 to fffff80002a78740
STACK_TEXT:
fffff880`08a12698 fffff800`02acd3b3 : 00000000`0000001a 00000000`00041284 fffff680`003a3001 00000000`00001418 : nt!KeBugCheckEx
fffff880`08a126a0 fffff800`02aab379 : fffffa80`04bf5cf8 00000000`00000000 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4a83
fffff880`08a126e0 fffff800`02aab60a : fffffa80`0166d1c0 fffffa80`04bf5960 00000000`00000000 fffff680`003a3ff8 : nt!MiTerminateWsle+0x29
fffff880`08a12720 fffff800`02aa98e5 : fffffa80`04bf5960 55555555`55555555 00000000`00000000 fffff800`02a26aa3 : nt!MiDeletePageTableHierarchy+0xca
fffff880`08a12830 fffff800`02aabdf9 : 00000000`00000000 00000000`74c4dfff fffffa80`00000000 00000000`00000000 : nt!MiDeleteVirtualAddresses+0x96c
fffff880`08a129f0 fffff800`02d911d0 : fffffa80`05691480 0007ffff`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`08a12b10 fffff800`02d915db : 00000980`00000000 00000000`747b0000 fffffa80`00000001 fffffa80`056b0720 : nt!MiUnmapViewOfSection+0x1b0
fffff880`08a12bd0 fffff800`02a77993 : 00000000`00000001 00000000`003f3610 fffffa80`04bf5960 00000000`003477b0 : nt!NtUnmapViewOfSection+0x5f
fffff880`08a12c20 00000000`76f7fffa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0579eed8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f7fffa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4a83
fffff800`02acd3b3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4a83
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02a14000 PsLoadedModuleList = 0xfffff800`02c51e50
Debug session time: Wed Oct 6 00:24:14.909 2010 (GMT-4)
System Uptime: 2 days 17:02:41.502
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
..................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {63de, 2, 0, fffff80002a911dc}
Probably caused by : win32k.sys ( win32k!NtUserCallOneParam+29 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000000000063de, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002a911dc, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cbc0e0
00000000000063de
CURRENT_IRQL: 2
FAULTING_IP:
nt!KiInsertTimerTable+1cc
fffff800`02a911dc 4c3b78f8 cmp r15,qword ptr [rax-8]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: dwm.exe
TRAP_FRAME: fffff8800732c7c0 -- (.trap 0xfffff8800732c7c0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000000063e6 rbx=0000000000000000 rcx=fffffa8006837c40
rdx=fffffa8003a6a250 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002a911dc rsp=fffff8800732c950 rbp=fffffa8005ef7390
r8=ffffffffffffffff r9=00000000000000f0 r10=fffff880009ec180
r11=fffff880009ec100 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!KiInsertTimerTable+0x1cc:
fffff800`02a911dc 4c3b78f8 cmp r15,qword ptr [rax-8] ds:00000000`000063de=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002a83ca9 to fffff80002a84740
STACK_TEXT:
fffff880`0732c678 fffff800`02a83ca9 : 00000000`0000000a 00000000`000063de 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0732c680 fffff800`02a82920 : 00000000`00000140 fffffa80`05492480 fffff800`02bfee80 fffffa80`07b0d750 : nt!KiBugCheckDispatch+0x69
fffff880`0732c7c0 fffff800`02a911dc : 00000000`00000000 fffff800`02d80bf2 0000000a`00000002 fffff880`02f63180 : nt!KiPageFault+0x260
fffff880`0732c950 fffff800`02a8baf2 : fffffa80`054923c0 fffffa80`054923c0 00000000`00000000 00000000`00000001 : nt!KiInsertTimerTable+0x1cc
fffff880`0732c9b0 fffff800`02a8dcff : 00000000`00000010 fffff800`02c01080 00000000`000000f0 fffff800`02a891fa : nt!KiCommitThreadWait+0x332
fffff880`0732ca40 fffff800`02a4d242 : fffffa80`04d1fd00 00000000`0000001b 00000000`0405fe00 fffff880`009ec100 : nt!KeWaitForSingleObject+0x19f
fffff880`0732cae0 fffff800`02a8c5ac : ffffffff`ffb3b4c0 fffffa80`04dfd820 fffffa80`04d1fd30 fffff800`00000000 : nt!ExpWaitForResource+0xae
fffff880`0732cb50 fffff800`02a901e3 : 00000000`00000000 fffffa80`054923c0 fffff880`0732cca0 fffffa80`053f1168 : nt!ExAcquireResourceExclusiveLite+0x14f
fffff880`0732cbc0 fffff960`001a3d95 : fffffa80`054923c0 00000000`00000000 00000000`00000001 00000000`00000001 : nt!ExEnterPriorityRegionAndAcquireResourceExclusive+0x23
fffff880`0732cbf0 fffff800`02a83993 : fffffa80`054923c0 fffff880`0732cca0 00000000`00000000 00000000`00000001 : win32k!NtUserCallOneParam+0x29
fffff880`0732cc20 00000000`7745d33a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0405fcd8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7745d33a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!NtUserCallOneParam+29
fffff960`001a3d95 c605ec8f200001 mov byte ptr [win32k!gbValidateHandleForIL (fffff960`003acd88)],1
SYMBOL_STACK_INDEX: 9
SYMBOL_NAME: win32k!NtUserCallOneParam+29
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c483f
FAILURE_BUCKET_ID: X64_0xA_win32k!NtUserCallOneParam+29
BUCKET_ID: X64_0xA_win32k!NtUserCallOneParam+29
Followup: MachineOwner
---------
1: kd> lmtsmn
start end module name
fffff880`04077000 fffff880`040b5000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`010d0000 fffff880`01127000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02c64000 fffff880`02cee000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`041e7000 fffff880`041fd000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`03e00000 fffff880`03e15000 amdppm amdppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`01068000 fffff880`01073000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`041c6000 fffff880`041ce000 ASACPI ASACPI.sys Sun Mar 27 22:30:36 2005 (42476C4C)
fffff880`03b3d000 fffff880`03b46000 aswFsBlk aswFsBlk.SYS Tue Sep 07 10:47:09 2010 (4C86506D)
fffff880`03b03000 fffff880`03b3d000 aswMonFlt aswMonFlt.sys Tue Sep 07 10:47:32 2010 (4C865084)
fffff880`02cee000 fffff880`02cf8000 aswRdr aswRdr.SYS Tue Sep 07 10:47:47 2010 (4C865093)
fffff880`03fa6000 fffff880`03fc9000 aswSP aswSP.SYS Tue Sep 07 10:52:07 2010 (4C865197)
fffff880`02c54000 fffff880`02c64000 aswTdi aswTdi.SYS Tue Sep 07 10:52:27 2010 (4C8651AB)
fffff880`0102a000 fffff880`01033000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01033000 fffff880`0105d000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`04584000 fffff880`045a7000 AtiHdmi AtiHdmi.sys Thu May 06 05:20:39 2010 (4BE289E7)
fffff880`048cc000 fffff880`04fa8000 atikmdag atikmdag.sys Thu May 27 12:47:58 2010 (4BFEA23E)
fffff880`03e15000 fffff880`03e5b000 atikmpag atikmpag.sys Thu May 27 12:25:36 2010 (4BFE9D00)
fffff880`04fa8000 fffff880`04fed000 aywpwzl9 aywpwzl9.SYS Tue Jul 14 17:12:55 2009 (4A5CF4D7)
fffff880`01628000 fffff880`0162f000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`03f95000 fffff880`03fa6000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`03bca000 fffff880`03be8000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`006e0000 fffff960`00707000 cdd cdd.dll unavailable (00000000)
fffff880`06e31000 fffff880`06e4e000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`00e00000 fffff880`00e2a000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00c93000 fffff880`00d53000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01200000 fffff880`01230000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00c35000 fffff880`00c93000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`014f8000 fffff880`0156b000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`041d7000 fffff880`041e7000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`05be9000 fffff880`05bf7000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`03ef4000 fffff880`03f77000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`03f77000 fffff880`03f95000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`03ee5000 fffff880`03ef4000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`0144c000 fffff880`01462000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`04400000 fffff880`04422000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`05a00000 fffff880`05a0c000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05a17000 fffff880`05a2a000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05a0c000 fffff880`05a17000 dump_msahci dump_msahci.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`04428000 fffff880`04434000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`040d2000 fffff880`041c6000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04000000 fffff880`04046000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`03b94000 fffff880`03bca000 fastfat fastfat.SYS Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`00fab000 fffff880`00fbf000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`01073000 fffff880`010bf000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`0157c000 fffff880`01586000 Fs_Rec Fs_Rec.sys unavailable (00000000)
fffff880`00fbf000 fffff880`00ff9000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`017ac000 fffff880`017f6000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff880`0406a000 fffff880`04077000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
fffff800`02ff0000 fffff800`03039000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04046000 fffff880`0406a000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`06e4e000 fffff880`06e67000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`0444f000 fffff880`04457080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`06e1d000 fffff880`06e2b000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`03a00000 fffff880`03ac8000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`0161f000 fffff880`01628000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`044a0000 fffff880`044af000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06e67000 fffff880`06e75000 kbdhid kbdhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff800`00bc9000 fffff800`00bd3000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`044c0000 fffff880`04503000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`014de000 fffff880`014f8000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01781000 fffff880`017ac000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`04422000 fffff880`04427200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`06ee1000 fffff880`06ee4d80 LGBusEnum LGBusEnum.sys Mon Nov 23 20:36:48 2009 (4B0B38B0)
fffff880`06e82000 fffff880`06e84480 LGVirHid LGVirHid.sys Mon Nov 23 20:36:48 2009 (4B0B38B0)
fffff880`03b67000 fffff880`03b7c000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`03ae0000 fffff880`03b03000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c14000 fffff880`00c21000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`045e4000 fffff880`045f2000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`044af000 fffff880`044be000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06e75000 fffff880`06e82000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`01010000 fffff880`0102a000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`03be8000 fffff880`03c00000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`06012000 fffff880`0603f000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`0603f000 fffff880`0608d000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0608d000 fffff880`060b0000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`0105d000 fffff880`01068000 msahci msahci.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`02c0d000 fffff880`02c18000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01127000 fffff880`01131000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01480000 fffff880`014de000 msrpc msrpc.sys unavailable (00000000)
fffff880`03eda000 fffff880`03ee5000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`0143a000 fffff880`0144c000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`0162f000 fffff880`01721000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04fed000 fffff880`04ff9000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`03e7f000 fffff880`03eae000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`0456f000 fffff880`04584000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02d6c000 fffff880`02d7b000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02cf8000 fffff880`02d3d000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01721000 fffff880`01781000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`02c18000 fffff880`02c29000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02c00000 fffff880`02c0c000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02a14000 fffff800`02ff0000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01238000 fffff880`013db000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`017f6000 fffff880`017ff000 Null Null.SYS unavailable (00000000)
fffff880`02d46000 fffff880`02d6c000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`01171000 fffff880`01186000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`0113e000 fffff880`01171000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`011f7000 fffff880`011fe000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`01000000 fffff880`01010000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`0156b000 fffff880`0157c000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`060b0000 fffff880`06156000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`045a7000 fffff880`045e4000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c21000 fffff880`00c35000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`03e5b000 fffff880`03e7f000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`03eae000 fffff880`03ec9000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`0445a000 fffff880`0447b000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`0447b000 fffff880`04495000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02daa000 fffff880`02dfb000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`04495000 fffff880`044a0000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`00e2a000 fffff880`00e33000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`00e33000 fffff880`00e3c000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`00e3c000 fffff880`00e45000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01400000 fffff880`0143a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`03b7c000 fffff880`03b94000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`00f7c000 fffff880`00fab000 SCSIPORT SCSIPORT.SYS Mon Jul 13 20:01:04 2009 (4A5BCAC0)
fffff880`06156000 fffff880`06161000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`01618000 fffff880`0161f000 speedfan speedfan.sys Sun Sep 24 09:26:48 2006 (45168798)
fffff880`01610000 fffff880`01618000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`08474000 fffff880`084e5000 spsys spsys.sys Mon May 11 13:20:58 2009 (4A085E7A)
fffff880`00e4d000 fffff880`00f73000 sptd sptd.sys Sun Oct 11 16:55:14 2009 (4AD24632)
fffff880`06f5b000 fffff880`06ff1000 srv srv.sys Mon Jun 21 23:21:11 2010 (4C202C27)
fffff880`06ef3000 fffff880`06f5b000 srv2 srv2.sys Mon Jun 21 23:20:47 2010 (4C202C0F)
fffff880`06161000 fffff880`0618e000 srvnet srvnet.sys Mon Jun 21 23:20:32 2010 (4C202C00)
fffff880`044be000 fffff880`044bf480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01803000 fffff880`01a00000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`0618e000 fffff880`061a0000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02c47000 fffff880`02c54000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02c29000 fffff880`02c47000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02d96000 fffff880`02daa000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00550000 fffff960`0055a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`03fc9000 fffff880`03fef000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04503000 fffff880`04515000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`06e00000 fffff880`06e1d000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
fffff880`05bf7000 fffff880`05bf8f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`040c0000 fffff880`040d1000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04515000 fffff880`0456f000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`040b5000 fffff880`040c0000 usbohci usbohci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04865000 fffff880`048bb000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`04434000 fffff880`0444f000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`01131000 fffff880`0113e000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`015f0000 fffff880`015fe000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`05a2a000 fffff880`05bdb000 viahduaa viahduaa.sys Tue Mar 02 06:30:18 2010 (4B8CF6CA)
fffff880`013db000 fffff880`01400000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`05bdb000 fffff880`05be9000 VMfilt64 VMfilt64.sys Thu Jul 30 23:40:32 2009 (4A7267B0)
fffff880`01600000 fffff880`01610000 vmstorfl vmstorfl.sys unavailable (00000000)
fffff880`01186000 fffff880`0119b000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0119b000 fffff880`011f7000 volmgrx volmgrx.sys unavailable (00000000)
fffff880`01586000 fffff880`015d2000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02d7b000 fffff880`02d96000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`010bf000 fffff880`010cf000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00d53000 fffff880`00df7000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00c00000 fffff880`00c0f000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02d3d000 fffff880`02d46000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000d0000 fffff960`003df000 win32k win32k.sys Sat Jun 19 00:31:59 2010 (4C1C483F)
fffff880`041ce000 fffff880`041d7000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f73000 fffff880`00f7c000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`03b46000 fffff880`03b67000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`06eb0000 fffff880`06ee1000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
fffff880`04800000 fffff880`04865000 yk62x64 yk62x64.sys Mon Feb 15 10:46:41 2010 (4B796C61)
Unloaded modules:
fffff880`0850f000 fffff880`0851b000 hiber_pciide
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0851b000 fffff880`08526000 hiber_msahci
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`08526000 fffff880`08539000 hiber_dumpfv
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`084e5000 fffff880`084f1000 hiber_pciide
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`084f1000 fffff880`084fc000 hiber_msahci
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`084fc000 fffff880`0850f000 hiber_dumpfv
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`015d2000 fffff880`015eb000 HIDCLASS.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`045f2000 fffff880`04600000 hidusb.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01462000 fffff880`0147f000 usbccgp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`03ec9000 fffff880`03ed6000 mouhid.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`048bb000 fffff880`048c9000 kbdhid.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`06e7f000 fffff880`06eb0000 WUDFRd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`06e4e000 fffff880`06e7f000 WUDFRd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`06e00000 fffff880`06e31000 WUDFRd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01462000 fffff880`01470000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01470000 fffff880`0147c000 dump_pciidex
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`015d2000 fffff880`015dd000 dump_msahci.
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`015dd000 fffff880`015f0000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
Kernel base = 0xfffff800`02a13000 PsLoadedModuleList = 0xfffff800`02c50e50
Debug session time: Thu Sep 30 09:13:05.338 2010 (GMT-4)
System Uptime: 0 days 12:01:32.790
Loading Kernel Symbols
.................................................Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
Unable to add module at 00000000`00000000
Loading User Symbols
Loading unloaded module list
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
....Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
..Missing image name, possible paged-out or corrupt data.
Missing image name, possible paged-out or corrupt data.
.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88006dc1448, fffff88006dc0cb0, fffff880012338a0}
Probably caused by : ntkrnlmp.exe ( nt!PoIdle+53a )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88006dc1448
Arg3: fffff88006dc0cb0
Arg4: fffff880012338a0
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88006dc1448 -- (.exr 0xfffff88006dc1448)
Cannot read Exception record @ fffff88006dc1448
CONTEXT: fffff88006dc0cb0 -- (.cxr 0xfffff88006dc0cb0)
Unable to read context, Win32 error 0n30
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x24
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002a9124a to fffff88003fd07f2
STACK_TEXT:
fffff800`00b9cc98 fffff800`02a9124a : 00000000`003a75f9 fffffa80`04747578 fffff800`02c0bc40 00000000`00000001 : 0xfffff880`03fd07f2
fffff800`00b9cca0 fffff800`02a8bebc : fffff800`02bfde80 fffff800`00000000 00000000`00000000 fffffa80`046870f0 : nt!PoIdle+0x53a
fffff800`00b9cd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c
FOLLOWUP_IP:
nt!PoIdle+53a
fffff800`02a9124a 0fba25f61318000f bt dword ptr [<Unloaded_Unknown_Module_00000000`00000000>+0x1813f6 (00000000`001813f6)],0Fh
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PoIdle+53a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88006dc0cb0 ; kb
FAILURE_BUCKET_ID: X64_0x24_nt!PoIdle+53a
BUCKET_ID: X64_0x24_nt!PoIdle+53a
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02818000 PsLoadedModuleList = 0xfffff800`02a55e50
Debug session time: Sun Sep 19 13:33:20.238 2010 (GMT-4)
System Uptime: 0 days 0:16:46.756
Loading Kernel Symbols
.................................................Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
Unable to add module at 00000000`00000000
Loading User Symbols
Missing image name, possible paged-out or corrupt data.
Loading unloaded module list
..Missing image name, possible paged-out or corrupt data.
..Missing image name, possible paged-out or corrupt data.
..Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
.Missing image name, possible paged-out or corrupt data.
Missing image name, possible paged-out or corrupt data.
Missing image name, possible paged-out or corrupt data.
.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {0, 0, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt!KiKernelCalloutExceptionHandler+e )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 0000000000000000, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (Win32) 0 (0) - The operation completed successfully.
FAULTING_IP:
Unknown_Module_00000000`00000000>+0
00000000`00000000 ?? ???
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: System
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff80003d11328 -- (.exr 0xfffff80003d11328)
ExceptionAddress: fffff8000288cfc4 (nt!KiDeferredReadyThread+0x00000000000000e4)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00ffffffffffffff
Parameter[1]: ff00000000000000
Attempt to execute non-executable address ff00000000000000
TRAP_FRAME: fffff80003d113d0 -- (.trap 0xfffff80003d113d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000061 rbx=0000000000000000 rcx=000000000000000f
rdx=000000000000000f rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000288cfc4 rsp=fffff80003d11560 rbp=00fffa8003e3c060
r8=000000000000000f r9=0000000000000003 r10=fffff80002818000
r11=fffff80003d115b0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!KiDeferredReadyThread+0xe4:
fffff800`0288cfc4 80bd1e04000002 cmp byte ptr <Unloaded_Unknown_Module_00000000`00000000>+0x41e (00000000`0000041e)[rbp],2 ss:0018:00fffa80`03e3c47e=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000288046e to fffff80002888710
STACK_TEXT:
fffff800`03d10418 fffff800`0288046e : 00000000`00000000 fffff880`018637d5 fffff800`03d10b90 fffff800`028b5668 : nt!KeBugCheck
fffff800`03d10420 fffff800`028ae40d : fffff800`02a96b7c fffff800`029d0e84 fffff800`02818000 fffff800`03d11328 : nt!KiKernelCalloutExceptionHandler+0xe
fffff800`03d10450 fffff800`028b5a90 : fffff800`029d7b14 fffff800`03d104c8 fffff800`03d11328 fffff800`02818000 : nt!RtlpExecuteHandlerForException+0xd
fffff800`03d10480 fffff800`028c29ef : fffff800`03d11328 fffff800`03d10b90 fffff800`00000000 fffffa80`03d7c620 : nt!RtlDispatchException+0x410
fffff800`03d10b60 fffff800`02887d82 : fffff800`03d11328 fffffa80`03d7c704 fffff800`03d113d0 00000000`00000000 : nt!KiDispatchException+0x16f
fffff800`03d111f0 fffff800`02886552 : 00000000`00000002 00000000`00000001 00000000`00000000 00000000`00000001 : nt!KiExceptionDispatch+0xc2
fffff800`03d113d0 fffff800`0288cfc4 : fffff880`02fd3180 fffffa80`03d7c620 fffff800`03d11600 00000000`00000000 : nt!KiStackFault+0x112
fffff800`03d11560 fffff800`02893e67 : fffffa80`05446c20 fffffa80`03d7c728 fffffa80`03d7c728 00000000`00000000 : nt!KiDeferredReadyThread+0xe4
fffff800`03d115e0 fffff800`028944be : 00000002`5812e089 fffff800`03d11c58 00000000`0000fc17 fffff800`02a05568 : nt!KiProcessExpiredTimerList+0x157
fffff800`03d11c30 fffff800`02893cb7 : 00000000`e601b1c2 00000000`0000fc17 00000000`e601b1b2 00000000`00000017 : nt!KiTimerExpiration+0x1be
fffff800`03d11cd0 fffff800`02890eea : fffff800`02a02e80 fffff800`02a10c40 00000000`00000000 fffff880`04f0b588 : nt!KiRetireDpcList+0x277
fffff800`03d11d80 00000000`00000000 : fffff800`03d12000 fffff800`03d0c000 fffff800`03d11d40 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiKernelCalloutExceptionHandler+e
fffff800`0288046e 90 nop
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!KiKernelCalloutExceptionHandler+e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e
BUCKET_ID: X64_0x1E_nt!KiKernelCalloutExceptionHandler+e
Followup: MachineOwner
---------