Hi Rowan; welcome to the forums. If you can, run what part of that tool that will run and upload the files. Thsi will give us some system information that dumps don't tell us.
Error code 24, NTFS_FILE_SYSTEM.
Usual causes: Disk corruption, insufficient physical memory, Device driver, Indexing, Resident antivirus, backup, defrag programs, Disk/Drive failing/failure.
Error code 19, BAD_POOL_HEADER.
Usual causes: Device driver
Error code 1E, KMODE_EXCEPTION_NOT_HANDLED.
Usual causes: Device driver, hardware, System service, compatibility, Remote control programs, memory, BIOS.
Error code 3B, SYSTEM_SERVICE_EXCEPTION.
Usual causes: System service, Device driver, graphics driver, ?memory.
The dumps indicate a hardware/hardware related problem. I recommend that you uninstall Avira. Avira is known to cause crashes on some Win 7 systems. Note antivirus is mentioned in the usual causes above.
You have two outdated drivers loading on your system. One is an XP driver. Older drivers can cause memory corruption and BSOD's. Update the following drivers.
000.fcl Fri Sep 26 09:11:22 2008 - CyberLink FCL Driver
http://www.gocyberlink.com. Update the driver or the software.
DB3G.sys Mon Nov 07 01:33:11 2005 - Diamondback USB Optical Mouse Driver
Razer Diamondback Driver v6.02. If you cannot update this driver, you need to upgrade your mouse to one that is certified Win 7 compatible.
Uninstall Avira and take care of the above drivers. Reboot your system and let's see how it runs. If you get another BSOD, upload the dump and we will take the next steps.
How to find drivers -
- I have listed links to most of the drivers in the code box above. Please use the links there to see what info I've found about those drivers.
- search Google for the name of the driver
- compare the Google results with what's installed on your system to figure out which device/program it belongs to
- visit the web site of the manufacturer of the hardware/program to get the latest drivers (DON'T use Windows Update or the Update driver function of Device Manager).
- if there are difficulties in locating them, post back with questions and someone will try and help you locate the appropriate program.
- - The most common drivers are listed on this page: Driver Reference
- - Driver manufacturer links are on this page: Drivers and Downloads
Code:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03057000 PsLoadedModuleList = 0xfffff800`03294e50
Debug session time: Sat Oct 30 16:38:01.495 2010 (GMT-4)
System Uptime: 0 days 0:00:57.274
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff8800703c418, fffff8800703bc80, fffff8000351397a}
Probably caused by : fileinfo.sys ( fileinfo!FIStreamLog+89 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff8800703c418
Arg3: fffff8800703bc80
Arg4: fffff8000351397a
Debugging Details:
------------------
EXCEPTION_RECORD: fffff8800703c418 -- (.exr 0xfffff8800703c418)
ExceptionAddress: fffff8000351397a (nt!PfpRpFileKeyUpdate+0x000000000000025a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff8800703bc80 -- (.cxr 0xfffff8800703bc80)
rax=fffff8a002871000 rbx=fffff8a003132270 rcx=bffff8a00175f980
rdx=fffff8a002873948 rsi=fffff80003268c00 rdi=ffffffffffffffff
rip=fffff8000351397a rsp=fffff8800703c650 rbp=0000000000000000
r8=0000000000000800 r9=fffff8a008a246e0 r10=ffffffffffffffff
r11=fffff8a008a246e0 r12=fffff80003268c88 r13=0000000000000000
r14=fffff80003268c30 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!PfpRpFileKeyUpdate+0x25a:
fffff800`0351397a 488b4108 mov rax,qword ptr [rcx+8] ds:002b:bffff8a0`0175f988=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032ff0e0
ffffffffffffffff
FOLLOWUP_IP:
fileinfo!FIStreamLog+89
fffff880`00c8a55d 4c8b1534c5ffff mov r10,qword ptr [fileinfo!FIGlobals+0x798 (fffff880`00c86a98)]
FAULTING_IP:
nt!PfpRpFileKeyUpdate+25a
fffff800`0351397a 488b4108 mov rax,qword ptr [rcx+8]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff800031e8559 to fffff8000351397a
STACK_TEXT:
fffff880`0703c650 fffff800`031e8559 : fffff880`0703c860 00000000`00000000 00000000`00000000 fffff8a0`08a246e0 : nt!PfpRpFileKeyUpdate+0x25a
fffff880`0703c6e0 fffff880`00c8a55d : 00000000`00000000 00000000`00000000 fffff880`0703c860 00000000`c000007f : nt!PfFileInfoNotify+0x549
fffff880`0703c770 fffff880`00c8a746 : fffff8a0`03132d90 fffff8a0`03132d90 00000000`00000000 00000000`00000000 : fileinfo!FIStreamLog+0x89
fffff880`0703c840 fffff880`00c4365e : fffffa80`0a491df8 00000000`00000000 ffffffff`ffffffff fffffa80`086bc130 : fileinfo!FIStreamCleanup+0x96
fffff880`0703c890 fffff880`00c5f22d : fffff8a0`03132d48 fffff880`00c35000 00000000`00000000 00000000`00000040 : fltmgr!DoFreeContext+0x7e
fffff880`0703c8c0 fffff880`00c5abc1 : fffffa80`07ac4010 00000000`00000130 fffff8a0`08a246e0 fffff8a0`08a246e0 : fltmgr! ?? ::NNGAKEGL::`string'+0x1196
fffff880`0703c8f0 fffff880`00c5ab7b : fffffa80`07ac4010 fffff8a0`08a24948 fffffa80`07ac4010 fffff800`0326c5a0 : fltmgr!CleanupStreamListCtrl+0x21
fffff880`0703c920 fffff800`033b6896 : 00000000`00000001 fffff880`010b90b8 fffff880`0703c9f0 00000000`00000000 : fltmgr!DeleteStreamListCtrlCallback+0x6b
fffff880`0703c950 fffff880`010b8bcc : fffff8a0`08a246e0 fffffa80`09ee1b60 fffff880`0703ca28 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`0703c9a0 fffff880`010b88d5 : fffff800`01010000 00000000`00000000 fffff800`0326c500 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`0703c9e0 fffff880`0102bcb4 : fffff8a0`08a245e0 fffff8a0`08a246e0 fffff800`0326c500 fffff880`0703cb52 : Ntfs!NtfsRemoveScb+0x61
fffff880`0703ca20 fffff880`010b62dc : fffff8a0`08a245b0 fffff800`0326c5a0 fffff880`0703cb52 fffffa80`0951dcf0 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`0703ca50 fffff880`01034882 : fffffa80`0951dcf0 fffffa80`0951dcf0 fffff8a0`08a245b0 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`0703cad0 fffff880`010cd813 : fffffa80`0951dcf0 fffff800`0326c5a0 fffff8a0`08a245b0 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`0703cb10 fffff880`010a738f : fffffa80`0951dcf0 fffff8a0`08a246e0 fffff8a0`08a245b0 fffffa80`07bcf180 : Ntfs!NtfsCommonClose+0x353
fffff880`0703cbe0 fffff800`030d4961 : 00000000`00000000 fffff880`010a7200 fffff800`032ce101 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`0703ccb0 fffff800`0336bc06 : 00000000`064c3b13 fffffa80`09ee1b60 00000000`00000080 fffffa80`069abb30 : nt!ExpWorkerThread+0x111
fffff880`0703cd40 fffff800`030a5c26 : fffff800`03241e80 fffffa80`09ee1b60 fffffa80`09ea6060 fffff880`01034a90 : nt!PspSystemThreadStartup+0x5a
fffff880`0703cd80 00000000`00000000 : fffff880`0703d000 fffff880`07037000 fffff880`0703c9f0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: fileinfo!FIStreamLog+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc481
STACK_COMMAND: .cxr 0xfffff8800703bc80 ; kb
FAILURE_BUCKET_ID: X64_0x24_fileinfo!FIStreamLog+89
BUCKET_ID: X64_0x24_fileinfo!FIStreamLog+89
Followup: MachineOwner
---------
1: kd> lmtsmn
start end module name
fffff880`0671d000 fffff880`06748000 000 000.fcl Fri Sep 26 09:11:22 2008 (48DCDF7A)
fffff880`03e43000 fffff880`03e81000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f48000 fffff880`00f9f000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02b32000 fffff880`02bbc000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`03eed000 fffff880`03f03000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`03dda000 fffff880`03def000 amdppm amdppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00c2a000 fffff880`00c35000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`03c7a000 fffff880`03c82000 ASACPI ASACPI.sys Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`00ff2000 fffff880`00ffb000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00c00000 fffff880`00c2a000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff960`00800000 fffff960`00861000 ATMFD ATMFD.DLL unavailable (00000000)
fffff880`05bad000 fffff880`05bca000 avgntflt avgntflt.sys Thu Feb 11 10:12:02 2010 (4B741E42)
fffff880`03d92000 fffff880`03db4000 avipbb avipbb.sys Mon Feb 22 05:08:50 2010 (4B8257B2)
fffff880`02a86000 fffff880`02a8d000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`03d81000 fffff880`03d92000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`05d36000 fffff880`05d54000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`007a0000 fffff960`007c7000 cdd cdd.dll unavailable (00000000)
fffff880`0586a000 fffff880`05887000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`02a49000 fffff880`02a73000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00d14000 fffff880`00dd4000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`013c7000 fffff880`013f7000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`02a73000 fffff880`02a7d000 CLBStor CLBStor.SYS Wed Oct 07 02:42:27 2009 (4ACC3853)
fffff880`05800000 fffff880`0586a000 CLBUDF CLBUDF.SYS Wed Oct 07 02:42:23 2009 (4ACC384F)
fffff880`00cb6000 fffff880`00d14000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`012a3000 fffff880`01316000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`03edd000 fffff880`03eed000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`05aaf000 fffff880`05abd000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`05b5c000 fffff880`05b61280 DB3G DB3G.sys Mon Nov 07 01:33:11 2005 (436EF527)
fffff880`03d63000 fffff880`03d81000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`03d54000 fffff880`03d63000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`015e8000 fffff880`015fe000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0476d000 fffff880`0478f000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`05ac9000 fffff880`05ad2000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05abd000 fffff880`05ac9000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`05ad2000 fffff880`05ae5000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05ae5000 fffff880`05af1000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`148f9000 fffff880`149ed000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`13c00000 fffff880`13c46000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`00c81000 fffff880`00c95000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00c35000 fffff880`00c81000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`01327000 fffff880`01331000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`011c6000 fffff880`01200000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`01331000 fffff880`0137b000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`0300e000 fffff800`03057000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`03c00000 fffff880`03c24000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`05b1e000 fffff880`05b37000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`05b37000 fffff880`05b3f080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`05b10000 fffff880`05b1e000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`05c6e000 fffff880`05d36000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`015df000 fffff880`015e8000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`03fb8000 fffff880`03fc7000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`05b40000 fffff880`05b4e000 kbdhid kbdhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff800`00b9d000 fffff800`00ba7000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`03e00000 fffff880`03e43000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`01289000 fffff880`012a3000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`0159a000 fffff880`015c5000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`0478f000 fffff880`04794200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`05beb000 fffff880`05c00000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`05b8a000 fffff880`05bad000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c95000 fffff880`00ca2000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`05b4e000 fffff880`05b5c000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`03fc7000 fffff880`03fd6000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`05b62000 fffff880`05b6f000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00de4000 fffff880`00dfe000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`05d54000 fffff880`05d6c000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`05d6c000 fffff880`05d99000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`05d99000 fffff880`05de7000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`05c00000 fffff880`05c23000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`02aeb000 fffff880`02af6000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00fa8000 fffff880`00fb2000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`0122b000 fffff880`01289000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`03d49000 fffff880`03d54000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015cd000 fffff880`015df000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01448000 fffff880`0153a000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`03f27000 fffff880`03f33000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`03f33000 fffff880`03f62000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`046f8000 fffff880`0470d000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02beb000 fffff880`02bfa000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02a00000 fffff880`02a45000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0153a000 fffff880`0159a000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`02af6000 fffff880`02b07000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03d3d000 fffff880`03d49000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`03057000 fffff800`03633000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01023000 fffff880`011c6000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`02a7d000 fffff880`02a86000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`148f7000 fffff880`148f8180 nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
fffff880`0470d000 fffff880`04730000 nvhda64v nvhda64v.sys Mon Jun 21 18:07:25 2010 (4C1FE29D)
fffff880`13c65000 fffff880`148f6e00 nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
fffff880`02bc5000 fffff880`02beb000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00e00000 fffff880`00e15000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00fb2000 fffff880`00fe5000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e86000 fffff880`00e8d000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00dd4000 fffff880`00de4000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01316000 fffff880`01327000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0662d000 fffff880`066d3000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`04730000 fffff880`0476d000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00ca2000 fffff880`00cb6000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`03f03000 fffff880`03f27000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`03f62000 fffff880`03f7d000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`03f7d000 fffff880`03f9e000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`03f9e000 fffff880`03fb8000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03cec000 fffff880`03d3d000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`02ad0000 fffff880`02ad9000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02ad9000 fffff880`02ae2000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02ae2000 fffff880`02aeb000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01400000 fffff880`0143a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`04600000 fffff880`04618000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`03e81000 fffff880`03ed4000 Rt64win7 Rt64win7.sys Sun May 30 23:46:43 2010 (4C033123)
fffff880`05888000 fffff880`05aae300 RTKVHD64 RTKVHD64.sys Fri Jan 29 01:48:35 2010 (4B6284C3)
fffff880`066d3000 fffff880`066de000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`149ed000 fffff880`149f9000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`01000000 fffff880`0101d000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`015c5000 fffff880`015cd000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`06c89000 fffff880`06d1f000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`06748000 fffff880`067af000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`066de000 fffff880`0670b000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`03fd6000 fffff880`03fd7480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01600000 fffff880`017fd000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`0670b000 fffff880`0671d000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02b25000 fffff880`02b32000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02b07000 fffff880`02b25000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`03cd8000 fffff880`03cec000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00540000 fffff960`0054a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`03db4000 fffff880`03dda000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04795000 fffff880`047e9000 udfs udfs.sys Mon Jul 13 19:23:37 2009 (4A5BC1F9)
fffff880`03fd8000 fffff880`03fea000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`05af1000 fffff880`05b0e000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
fffff880`05b0e000 fffff880`05b0ff00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`13c51000 fffff880`13c62000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0469e000 fffff880`046f8000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`13c46000 fffff880`13c51000 usbohci usbohci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`03c24000 fffff880`03c7a000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`05b6f000 fffff880`05b8a000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`00fe5000 fffff880`00ff2000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`02a8d000 fffff880`02a9b000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`02a9b000 fffff880`02ac0000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00e15000 fffff880`00e2a000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e2a000 fffff880`00e86000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`0137b000 fffff880`013c7000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`03cbd000 fffff880`03cd8000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`02ac0000 fffff880`02ad0000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e95000 fffff880`00f39000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f39000 fffff880`00f48000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02bbc000 fffff880`02bc5000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00090000 fffff960`0039f000 win32k win32k.sys unavailable (00000000)
fffff880`03ed4000 fffff880`03edd000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f9f000 fffff880`00fa8000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`05bca000 fffff880`05beb000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`06d1f000 fffff880`06d50000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
Unloaded modules:
fffff880`0143a000 fffff880`01448000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01200000 fffff880`0120c000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0120c000 fffff880`01215000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01215000 fffff880`01228000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {3, fffffa800699cc10, fffffa800699cc10, bffffa800699cc10}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+a56 )
Followup: Pool_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffffa800699cc10, the pool entry being checked.
Arg3: fffffa800699cc10, the read back flink freelist value (should be the same as 2).
Arg4: bffffa800699cc10, the read back blink freelist value (should be the same as 2).
Debugging Details:
------------------
BUGCHECK_STR: 0x19_3
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800031bed6f to fffff8000308b740
STACK_TEXT:
fffff880`0a614858 fffff800`031bed6f : 00000000`00000019 00000000`00000003 fffffa80`0699cc10 fffffa80`0699cc10 : nt!KeBugCheckEx
fffff880`0a614860 fffff800`03384754 : fffffa80`00000004 fffffa80`069a6f30 00000000`00000000 00000000`00000000 : nt!ExDeferredFreePool+0xa56
fffff880`0a614950 fffff800`033875bb : 00000000`00000000 fffffa80`06a45100 00000000`00000070 fffff880`0a6149e8 : nt!ObpAllocateObject+0xc4
fffff880`0a6149b0 fffff800`0335fb54 : fffff880`0a614b60 00000000`00000002 fffff8a0`03668290 fffff8a0`014c4060 : nt!ObCreateObject+0xdb
fffff880`0a614a20 fffff800`03360c95 : 00000000`0026e730 fffff8a0`00fdeab0 fffff8a0`014c4060 00000000`00000001 : nt!SepDuplicateToken+0xf4
fffff880`0a614ac0 fffff800`03360d21 : fffffa80`0a452190 00000000`00000008 000aab47`00000100 00000000`0016dac0 : nt!NtOpenThreadTokenEx+0x405
fffff880`0a614be0 fffff800`0308a993 : fffffa80`0a452190 00000000`0016dac0 00000000`0026e940 fffffa80`098da070 : nt!NtOpenThreadToken+0x11
fffff880`0a614c20 00000000`77a2ff9a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0026e648 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a2ff9a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+a56
fffff800`031bed6f cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExDeferredFreePool+a56
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
Followup: Pool_corruption
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff800031faf8c, 0, ffffffffffffffff}
Unable to load image \SystemRoot\system32\DRIVERS\avgntflt.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for avgntflt.sys
*** ERROR: Module load completed but symbols could not be loaded for avgntflt.sys
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+100 )
Followup: Pool_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800031faf8c, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExDeferredFreePool+100
fffff800`031faf8c 4c8b02 mov r8,qword ptr [rdx]
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032ff0e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff8800377e5e8 -- (.exr 0xfffff8800377e5e8)
ExceptionAddress: fffff800031faf8c (nt!ExDeferredFreePool+0x0000000000000100)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff8800377e690 -- (.trap 0xfffff8800377e690)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a008d5d1b0 rbx=0000000000000000 rcx=fffffa80069994c0
rdx=bffff8a008d42c00 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800031faf8c rsp=fffff8800377e820 rbp=0000000000000000
r8=bffff8a008d42c00 r9=0000000000000000 r10=fffff8a008d613e0
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExDeferredFreePool+0x100:
fffff800`031faf8c 4c8b02 mov r8,qword ptr [rdx] ds:2060:bffff8a0`08d42c00=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003101a39 to fffff800030c7740
STACK_TEXT:
fffff880`0377de18 fffff800`03101a39 : 00000000`0000001e ffffffff`c0000005 fffff800`031faf8c 00000000`00000000 : nt!KeBugCheckEx
fffff880`0377de20 fffff800`030c6d82 : fffff880`0377e5e8 00000000`00000001 fffff880`0377e690 00000000`00000000 : nt!KiDispatchException+0x1b9
fffff880`0377e4b0 fffff800`030c568a : fffffa80`656c6946 fffffa80`06a17f30 00000000`00000000 fffff800`033dd196 : nt!KiExceptionDispatch+0xc2
fffff880`0377e690 fffff800`031faf8c : 00000000`00000000 fffffa80`0a031af0 fffffa80`083e6320 fffff880`01088a64 : nt!KiGeneralProtectionFault+0x10a
fffff880`0377e820 fffff800`031fc4c1 : fffff880`0377e8d0 fffff8a0`08d7a690 00000000`00000000 00000000`00000001 : nt!ExDeferredFreePool+0x100
fffff880`0377e8b0 fffff880`010881c0 : 00000000`00000000 00000000`00000037 fffffa80`6e664d46 00000000`000007ff : nt!ExFreePoolWithTag+0x411
fffff880`0377e960 fffff880`01089361 : 00000000`00000052 00000000`00000068 00000000`00000038 00000000`00000000 : fltmgr!FltpExpandShortNames+0x2f0
fffff880`0377e9c0 fffff880`0108913e : fffffa80`083e6320 fffffa80`09540000 00000000`00000000 00000000`00000001 : fltmgr!FltpGetNormalizedFileNameWorker+0xc1
fffff880`0377ea00 fffff880`0106a54b : fffffa80`07bc9010 fffffa80`06cef170 fffffa80`0782b000 fffff880`03780000 : fltmgr!FltpCreateFileNameInformation+0xee
fffff880`0377ea60 fffff880`01075ad4 : fffffa80`06a88000 fffffa80`06cef170 fffffa80`095474c0 fffff8a0`08c9c618 : fltmgr!FltpGetFileNameInformation+0x26b
fffff880`0377eae0 fffff880`05bd3ea6 : fffffa80`083e6320 00000000`00000108 00000000`00000000 fffff880`0377ec78 : fltmgr!FltGetFileNameInformation+0x184
fffff880`0377eb70 fffffa80`083e6320 : 00000000`00000108 00000000`00000000 fffff880`0377ec78 00000000`01000160 : avgntflt+0x14ea6
fffff880`0377eb78 00000000`00000108 : 00000000`00000000 fffff880`0377ec78 00000000`01000160 fffff880`010b7c06 : 0xfffffa80`083e6320
fffff880`0377eb80 00000000`00000000 : fffff880`0377ec78 00000000`01000160 fffff880`010b7c06 00000000`00000000 : 0x108
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+100
fffff800`031faf8c 4c8b02 mov r8,qword ptr [rdx]
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!ExDeferredFreePool+100
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!ExDeferredFreePool+100
BUCKET_ID: X64_0x1E_nt!ExDeferredFreePool+100
Followup: Pool_corruption
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff8000336a74d, fffff88008785770, 0}
Probably caused by : ntkrnlmp.exe ( nt!CmpKcbCacheLookup+1dd )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8000336a74d, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88008785770, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!CmpKcbCacheLookup+1dd
fffff800`0336a74d 418b45f4 mov eax,dword ptr [r13-0Ch]
CONTEXT: fffff88008785770 -- (.cxr 0xfffff88008785770)
rax=000000000000000b rbx=0000000000000000 rcx=00000000000004da
rdx=000000000000019e rsi=fffff8a0019f4608 rdi=fffff880087862c0
rip=fffff8000336a74d rsp=fffff88008786140 rbp=fffff8a0019f4010
r8=000000000000000c r9=0000000000000000 r10=0000000000000002
r11=fffff880087862c0 r12=fffff8a00c5f9258 r13=bffff8a00c5eb140
r14=0000000000000000 r15=fffff8a00c5fc6f8
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!CmpKcbCacheLookup+0x1dd:
fffff800`0336a74d 418b45f4 mov eax,dword ptr [r13-0Ch] ds:002b:bffff8a0`0c5eb134=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: Blizzard Downl
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8000336a74d
STACK_TEXT:
fffff880`08786140 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmpKcbCacheLookup+0x1dd
FOLLOWUP_IP:
nt!CmpKcbCacheLookup+1dd
fffff800`0336a74d 418b45f4 mov eax,dword ptr [r13-0Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpKcbCacheLookup+1dd
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88008785770 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1dd
BUCKET_ID: X64_0x3B_nt!CmpKcbCacheLookup+1dd
Followup: MachineOwner
---------