Code:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c62000 PsLoadedModuleList = 0xfffff800`02e9fe50
Debug session time: Wed Dec 8 07:11:40.500 2010 (GMT-5)
System Uptime: 0 days 19:50:21.546
Loading Kernel Symbols
...............................................................
................................................................
............................................
Loading User Symbols
Loading unloaded module list
............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {fffffac00cc2d03b, 2, 0, fffff80002cdde13}
Probably caused by : ntkrnlmp.exe ( nt!KiProcessExpiredTimerList+103 )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffac00cc2d03b, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002cdde13, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f0a0e0
fffffac00cc2d03b
CURRENT_IRQL: 2
FAULTING_IP:
nt!KiProcessExpiredTimerList+103
fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: System
TRAP_FRAME: fffff880009da450 -- (.trap 0xfffff880009da450)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=000000000cc89403
rdx=fffffa800cc2d3a0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002cdde13 rsp=fffff880009da5e0 rbp=fffffac00cc2d010
r8=0000000000000013 r9=0000000000000000 r10=0000000000000063
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!KiProcessExpiredTimerList+0x103:
fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh] ds:00000000`0000002b=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cd1ca9 to fffff80002cd2740
STACK_TEXT:
fffff880`009da308 fffff800`02cd1ca9 : 00000000`0000000a fffffac0`0cc2d03b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`009da310 fffff800`02cd0920 : 00000000`00000008 fffffac0`0cc2d010 fffffa80`0b32d5b0 00000000`006cfc00 : nt!KiBugCheckDispatch+0x69
fffff880`009da450 fffff800`02cdde13 : fffffa80`0cc4a060 fffffa80`0e800c68 fffffa80`0e800c68 00000000`00000000 : nt!KiPageFault+0x260
fffff880`009da5e0 fffff800`02cde4be : 000000a6`4a8f2ece fffff880`009dac58 00000000`0045bf63 fffff880`009b51e8 : nt!KiProcessExpiredTimerList+0x103
fffff880`009dac30 fffff800`02cddcb7 : 0000002f`bec484c1 0000002f`0045bf63 0000002f`bec484fe 00000000`00000063 : nt!KiTimerExpiration+0x1be
fffff880`009dacd0 fffff800`02cdaeea : fffff880`009b2180 fffff880`009bd0c0 00000000`00000000 fffff880`0165cc50 : nt!KiRetireDpcList+0x277
fffff880`009dad80 00000000`00000000 : fffff880`009db000 fffff880`009d5000 fffff880`009dad40 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiProcessExpiredTimerList+103
fffff800`02cdde13 0fb6432b movzx eax,byte ptr [rbx+2Bh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!KiProcessExpiredTimerList+103
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+103
BUCKET_ID: X64_0xA_nt!KiProcessExpiredTimerList+103
Followup: MachineOwner
---------
4: kd> lmtsmn
start end module name
fffff880`04a57000 fffff880`04a95000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f19000 fffff880`00f70000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02f32000 fffff880`02fbc000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`047db000 fffff880`047f1000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`011a3000 fffff880`011ae000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`07e20000 fffff880`07e2b000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`01170000 fffff880`01179000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01179000 fffff880`011a3000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff960`008e0000 fffff960`00941000 ATMFD ATMFD.DLL unavailable (00000000)
fffff880`01b45000 fffff880`01b4c000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04ab0000 fffff880`04b9d000 BHDrvx64 BHDrvx64.sys Mon Nov 15 18:11:35 2010 (4CE1BE27)
fffff880`047ba000 fffff880`047cb000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`02bbf000 fffff880`02bdd000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff880`0471e000 fffff880`047ba000 ccHPx64 ccHPx64.sys Fri Feb 05 16:05:45 2010 (4B6C8829)
fffff960`006a0000 fffff960`006c7000 cdd cdd.dll unavailable (00000000)
fffff880`07b76000 fffff880`07b93000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`01b12000 fffff880`01b3c000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00cf3000 fffff880`00db3000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01aac000 fffff880`01adc000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00c95000 fffff880`00cf3000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0135c000 fffff880`013cf000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`047cb000 fffff880`047db000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`074c9000 fffff880`074d7000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`0467d000 fffff880`04700000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`04700000 fffff880`0471e000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`043a4000 fffff880`043b3000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01a96000 fffff880`01aac000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`07437000 fffff880`0745f000 Dot4 Dot4.sys Mon Jul 13 20:00:16 2009 (4A5BCA90)
fffff880`0745f000 fffff880`07469000 Dot4Prt Dot4Prt.sys Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`07427000 fffff880`07437000 dot4usb dot4usb.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`0776a000 fffff880`0778c000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`074e3000 fffff880`074ec000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`074d7000 fffff880`074e3000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`051b8000 fffff880`051cb000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`07469000 fffff880`07475000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`04ca1000 fffff880`04d95000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04d95000 fffff880`04ddb000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`04309000 fffff880`0437f000 eeCtrl64 eeCtrl64.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`07e00000 fffff880`07e20000 ENG64 ENG64.SYS Wed Sep 15 06:25:35 2010 (4C909F1F)
fffff880`0437f000 fffff880`043a4000 EraserUtilRebootDrv EraserUtilRebootDrv.sys Fri May 21 17:44:45 2010 (4BF6FECD)
fffff880`07e2b000 fffff880`07fe9000 EX64 EX64.SYS Wed Sep 15 06:33:41 2010 (4C90A105)
fffff880`07b93000 fffff880`07bc9000 fastfat fastfat.SYS Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`04de8000 fffff880`04df5000 fdc fdc.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`012a3000 fffff880`012b7000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`05198000 fffff880`051a3000 flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`011ae000 fffff880`011fa000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`015d5000 fffff880`015df000 Fs_Rec Fs_Rec.sys unavailable (00000000)
fffff880`01a5c000 fffff880`01a96000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`01600000 fffff880`0164a000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff880`04c8b000 fffff880`04c98000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
fffff800`02c19000 fffff800`02c62000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04c67000 fffff880`04c8b000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`077bf000 fffff880`077d8000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`077d8000 fffff880`077e0080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`077b1000 fffff880`077bf000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`02af7000 fffff880`02bbf000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`017f4000 fffff880`017fd000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`04bd9000 fffff880`04bf7000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01052000 fffff880`01170000 iaStorV iaStorV.sys Wed Apr 08 12:57:17 2009 (49DCD76D)
fffff880`05600000 fffff880`0567b000 IDSvia64 IDSvia64.sys Fri Nov 05 17:13:11 2010 (4CD47367)
fffff880`04bc3000 fffff880`04bd9000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`01a00000 fffff880`01a27000 Ironx64 Ironx64.SYS Tue Apr 27 20:48:23 2010 (4BD785D7)
fffff880`04a95000 fffff880`04aa4000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00bb7000 fffff800`00bc1000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`050e9000 fffff880`0512c000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`015aa000 fffff880`015c4000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`017ad000 fffff880`017d8000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`0778c000 fffff880`07791200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`05021000 fffff880`05036000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`051d9000 fffff880`051fc000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c3d000 fffff880`00c81000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`051cb000 fffff880`051d9000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`05800000 fffff880`0580f000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`00db3000 fffff880`00dcd000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02bdd000 fffff880`02bf5000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`02a00000 fffff880`02a2d000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`02a2d000 fffff880`02a7b000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`02a7b000 fffff880`02a9e000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`01baa000 fffff880`01bb5000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f79000 fffff880`00f83000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`012fe000 fffff880`0135c000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`04283000 fffff880`0428e000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015df000 fffff880`015f1000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`0165b000 fffff880`0174d000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04aa4000 fffff880`04ab0000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`04624000 fffff880`04653000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`051a3000 fffff880`051b8000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02fbc000 fffff880`02fcb000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02e00000 fffff880`02e45000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0174d000 fffff880`017ad000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`01bb5000 fffff880`01bc6000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`04277000 fffff880`04283000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02c62000 fffff800`0323e000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01407000 fffff880`015aa000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`01b3c000 fffff880`01b45000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`063f3000 fffff880`063f4180 nvBridge nvBridge.kmd Tue Jul 27 00:54:49 2010 (4C4E6699)
fffff880`05811000 fffff880`063f2980 nvlddmkm nvlddmkm.sys Tue Jul 27 00:54:50 2010 (4C4E669A)
fffff880`02e4e000 fffff880`02e74000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00fc3000 fffff880`00fd8000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f83000 fffff880`00fb6000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e5c000 fffff880`00e63000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00fed000 fffff880`00ffd000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`015c4000 fffff880`015d5000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0567d000 fffff880`05723000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`0772d000 fffff880`0776a000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c81000 fffff880`00c95000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`012f2000 fffff880`012fde00 PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253)
fffff880`04600000 fffff880`04624000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04653000 fffff880`0466e000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`043b3000 fffff880`043d4000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`043d4000 fffff880`043ee000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`04226000 fffff880`04277000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`063f5000 fffff880`06400000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`01b8f000 fffff880`01b98000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01b98000 fffff880`01ba1000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01ba1000 fffff880`01baa000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`00c00000 fffff880`00c3a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`05036000 fffff880`0504e000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04a00000 fffff880`04a57000 Rt64win7 Rt64win7.sys Mon Mar 22 05:57:14 2010 (4BA73EFA)
fffff880`074ee000 fffff880`0772c580 RTKVHD64 RTKVHD64.sys Fri Apr 30 05:05:58 2010 (4BDA9D76)
fffff880`017e9000 fffff880`017f4000 Sahdad64 Sahdad64.sys Mon Oct 27 23:56:11 2008 (49068D5B)
fffff880`017e0000 fffff880`017e9000 Saibad64 Saibad64.sys Mon Oct 27 23:56:15 2008 (49068D5F)
fffff880`01a3b000 fffff880`01a45000 SaibVdAd64 SaibVdAd64.sys Mon Oct 27 23:56:20 2008 (49068D64)
fffff880`05723000 fffff880`0572e000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`017d8000 fffff880`017e0000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`07a4e000 fffff880`07ad4000 SRTSP64 SRTSP64.SYS Wed Feb 24 18:59:29 2010 (4B85BD61)
fffff880`01a27000 fffff880`01a3b000 SRTSPX64 SRTSPX64.SYS Wed Feb 24 18:59:48 2010 (4B85BD74)
fffff880`0504e000 fffff880`050e4000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`05788000 fffff880`057ef000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`0572e000 fffff880`0575b000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`04dfe000 fffff880`04dff480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01235000 fffff880`012a3000 SYMDS64 SYMDS64.SYS Mon Aug 17 19:35:30 2009 (4A89E942)
fffff880`012b7000 fffff880`012f2000 SYMEFA64 SYMEFA64.SYS Wed Apr 21 17:47:39 2010 (4BCF727B)
fffff880`02efc000 fffff880`02f32000 SYMEVENT64x86 SYMEVENT64x86.SYS Thu Aug 13 18:28:21 2009 (4A849385)
fffff880`02e74000 fffff880`02e86000 SymIMv SymIMv.sys Fri Apr 30 22:12:21 2010 (4BDB8E05)
fffff880`02e86000 fffff880`02efc000 SYMTDIV SYMTDIV.SYS Tue May 04 00:38:27 2010 (4BDFA4C3)
fffff880`01803000 fffff880`01a00000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`0575b000 fffff880`0576d000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`01be4000 fffff880`01bf1000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`01bc6000 fffff880`01be4000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02fe6000 fffff880`02ffa000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`005e0000 fffff960`005ea000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`04b9d000 fffff880`04bc3000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`07475000 fffff880`074c9000 udfs udfs.sys Mon Jul 13 19:23:37 2009 (4A5BC1F9)
fffff880`0512c000 fffff880`0513e000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`07400000 fffff880`0741ac00 usbaudio usbaudio.sys Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`07792000 fffff880`077af000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
fffff880`077af000 fffff880`077b0f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`04c56000 fffff880`04c67000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0513e000 fffff880`05198000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`04c00000 fffff880`04c56000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`0741b000 fffff880`07427000 usbprint usbprint.sys Mon Jul 13 20:38:18 2009 (4A5BD37A)
fffff880`077e1000 fffff880`077fc000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`04ddb000 fffff880`04de8000 usbuhci usbuhci.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00fb6000 fffff880`00fc3000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01b4c000 fffff880`01b5a000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`01b5a000 fffff880`01b7f000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`0164a000 fffff880`0165a000 vmstorfl vmstorfl.sys unavailable (00000000)
fffff880`00fd8000 fffff880`00fed000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e00000 fffff880`00e5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01000000 fffff880`0104c000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02fcb000 fffff880`02fe6000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`01b7f000 fffff880`01b8f000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e66000 fffff880`00f0a000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f0a000 fffff880`00f19000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02e45000 fffff880`02e4e000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`0576d000 fffff880`05787200 WibuKey64 WibuKey64.sys Wed Nov 22 07:09:49 2006 (45643E0D)
fffff960`000b0000 fffff960`003bf000 win32k win32k.sys unavailable (00000000)
fffff880`04df5000 fffff880`04dfe000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f70000 fffff880`00f79000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`05000000 fffff880`05021000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`07ad4000 fffff880`07b05000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
Unloaded modules:
fffff880`07e00000 fffff880`07e20000 ENG64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07e2b000 fffff880`07fe9000 EX64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0428e000 fffff880`04309000 IDSvia64.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07e00000 fffff880`07e20000 ENG64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07e2b000 fffff880`07fe9000 EX64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07e00000 fffff880`07e20000 ENG64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07e2e000 fffff880`07fec000 EX64.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`07b05000 fffff880`07b76000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01adc000 fffff880`01aea000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01aea000 fffff880`01af6000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01af6000 fffff880`01aff000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01aff000 fffff880`01b12000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
Debug session time: Thu Dec 2 05:03:18.072 2010 (GMT-5)
System Uptime: 1 days 13:50:38.228
Loading Kernel Symbols
...............................................................
................................................................
.............................................
Loading User Symbols
Loading unloaded module list
.................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff900c542eb18, 0, fffff96000143188, 0}
Could not read faulting driver name
Probably caused by : win32k.sys ( win32k!GreGetClipBox+140 )
Followup: MachineOwner
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff900c542eb18, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff96000143188, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eaa0e0
fffff900c542eb18
FAULTING_IP:
win32k!GreGetClipBox+140
fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: sidebar.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88008465150 -- (.trap 0xfffff88008465150)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000001 rbx=0000000000000000 rcx=fffff900c502e9e0
rdx=fffff88008465300 rsi=0000000000000000 rdi=0000000000000000
rip=fffff96000143188 rsp=fffff880084652e0 rbp=0000000000000001
r8=0000000000000402 r9=0000000000000082 r10=0000000000000000
r11=0000000000000059 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
win32k!GreGetClipBox+0x140:
fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h] ds:0001:fffff900`c502eb18=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cf2f14 to fffff80002c72740
STACK_TEXT:
fffff880`08464fe8 fffff800`02cf2f14 : 00000000`00000050 fffff900`c542eb18 00000000`00000000 fffff880`08465150 : nt!KeBugCheckEx
fffff880`08464ff0 fffff800`02c7082e : 00000000`00000000 fffff880`0846543c fffff900`c4b9de00 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x42837
fffff880`08465150 fffff960`00143188 : fffff900`c00e5010 fffff880`0846543c 00000000`00000001 ffffffff`99042a2a : nt!KiPageFault+0x16e
fffff880`084652e0 fffff960`0011579f : fffff900`c06198e0 fffff880`08465520 ffffffff`99042a2a 00000000`24042d7a : win32k!GreGetClipBox+0x140
fffff880`08465370 fffff960`001ad310 : 00000000`00000000 fffff880`08465520 00000000`00000000 00000000`0300f2e0 : win32k!xxxBeginPaint+0x1af
fffff880`084653d0 fffff800`02c71993 : fffffa80`0e8b8b60 00000000`00000000 fffffa80`0e8b8b60 fffffa80`0e8b8b01 : win32k!NtUserBeginPaint+0x8c
fffff880`084654a0 00000000`7758b3aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0300ede8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7758b3aa
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!GreGetClipBox+140
fffff960`00143188 8b8138010000 mov eax,dword ptr [rcx+138h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: win32k!GreGetClipBox+140
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
FAILURE_BUCKET_ID: X64_0x50_win32k!GreGetClipBox+140
BUCKET_ID: X64_0x50_win32k!GreGetClipBox+140
Followup: MachineOwner
---------
Debug session time: Tue Nov 30 15:11:33.300 2010 (GMT-5)
System Uptime: 1 days 3:05:42.347
Unable to load image Unknown_Module_4dd5333b`c7e94772, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_4dd5333b`c7e94772
*** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_4dd5333b`c7e94772
Debugger can not determine kernel base address
Loading Kernel Symbols
.
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 18, {fffffa8009760570, fffffa800a4b18f0, 1, 4000000000}
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
REFERENCE_BY_POINTER (18)
Arguments:
Arg1: fffffa8009760570, Object type of the object whose reference count is being lowered
Arg2: fffffa800a4b18f0, Object whose reference count is being lowered
Arg3: 0000000000000001, Reserved
Arg4: 0000004000000000, Reserved
The reference count of an object is illegal for the current state of the object.
Each time a driver uses a pointer to an object the driver calls a kernel routine
to increment the reference count of the object. When the driver is done with the
pointer the driver calls another kernel routine to decrement the reference count.
Drivers must match calls to the increment and decrement routines. This bugcheck
can occur because an object's reference count goes to zero while there are still
open handles to the object, in which case the fourth parameter indicates the number
of opened handles. It may also occur when the object’s reference count drops below zero
whether or not there are open handles to the object, and in that case the fourth parameter
contains the actual value of the pointer references count.
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x18
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002c7f24a to fffff880044039c2
STACK_TEXT:
fffff800`041c7c98 fffff800`02c7f24a : 00000000`002bcf70 fffffa80`0c675dd8 fffff800`02df9c40 00000000`00000001 : 0xfffff880`044039c2
fffff800`041c7ca0 00000000`002bcf70 : fffffa80`0c675dd8 fffff800`02df9c40 00000000`00000001 fffff800`02debe80 : 0xfffff800`02c7f24a
fffff800`041c7ca8 fffffa80`0c675dd8 : fffff800`02df9c40 00000000`00000001 fffff800`02debe80 fffff800`02c7ccb7 : 0x2bcf70
fffff800`041c7cb0 fffff800`02df9c40 : 00000000`00000001 fffff800`02debe80 fffff800`02c7ccb7 00000041`336f76b8 : 0xfffffa80`0c675dd8
fffff800`041c7cb8 00000000`00000001 : fffff800`02debe80 fffff800`02c7ccb7 00000041`336f76b8 00000041`336f6fe9 : 0xfffff800`02df9c40
fffff800`041c7cc0 fffff800`02debe80 : fffff800`02c7ccb7 00000041`336f76b8 00000041`336f6fe9 00000041`336f76b8 : 0x1
fffff800`041c7cc8 fffff800`02c7ccb7 : 00000041`336f76b8 00000041`336f6fe9 00000041`336f76b8 00000000`00000095 : 0xfffff800`02debe80
fffff800`041c7cd0 00000041`336f76b8 : 00000041`336f6fe9 00000041`336f76b8 00000000`00000095 fffffa80`0c675d40 : 0xfffff800`02c7ccb7
fffff800`041c7cd8 00000041`336f6fe9 : 00000041`336f76b8 00000000`00000095 fffffa80`0c675d40 400000c2`400000c1 : 0x41`336f76b8
fffff800`041c7ce0 00000041`336f76b8 : 00000000`00000095 fffffa80`0c675d40 400000c2`400000c1 0000000b`400000c3 : 0x41`336f6fe9
fffff800`041c7ce8 00000000`00000095 : fffffa80`0c675d40 400000c2`400000c1 0000000b`400000c3 0000003d`0c72f543 : 0x41`336f76b8
fffff800`041c7cf0 fffffa80`0c675d40 : 400000c2`400000c1 0000000b`400000c3 0000003d`0c72f543 fffff800`041c1080 : 0x95
fffff800`041c7cf8 400000c2`400000c1 : 0000000b`400000c3 0000003d`0c72f543 fffff800`041c1080 fffffa80`0973f890 : 0xfffffa80`0c675d40
fffff800`041c7d00 0000000b`400000c3 : 0000003d`0c72f543 fffff800`041c1080 fffffa80`0973f890 00000000`00000000 : 0x400000c2`400000c1
fffff800`041c7d08 0000003d`0c72f543 : fffff800`041c1080 fffffa80`0973f890 00000000`00000000 000104cd`07083b40 : 0xb`400000c3
fffff800`041c7d10 fffff800`041c1080 : fffffa80`0973f890 00000000`00000000 000104cd`07083b40 000104cd`07083ff0 : 0x3d`0c72f543
fffff800`041c7d18 fffffa80`0973f890 : 00000000`00000000 000104cd`07083b40 000104cd`07083ff0 fffff800`02c779a2 : 0xfffff800`041c1080
fffff800`041c7d20 00000000`00000000 : 000104cd`07083b40 000104cd`07083ff0 fffff800`02c779a2 fffff800`041c1080 : 0xfffffa80`0973f890
STACK_COMMAND: kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: CORRUPT_MODULELIST
Followup: MachineOwner
---------
Debug session time: Fri Nov 26 10:14:15.009 2010 (GMT-5)
System Uptime: 0 days 2:26:58.181
Loading Kernel Symbols
...............................................................
................................................................
.............................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff960001a000b, fffff880026b5010, 0}
Probably caused by : win32k.sys ( win32k!zzzSetDesktop+187 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960001a000b, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff880026b5010, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
win32k!zzzSetDesktop+187
fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h]
CONTEXT: fffff880026b5010 -- (.cxr 0xfffff880026b5010)
rax=0000000000000389 rbx=fffff900c00f5c30 rcx=fffffa800c45a400
rdx=fffff900c0aed270 rsi=0000000000000000 rdi=0000000000000000
rip=fffff960001a000b rsp=fffff880026b59e0 rbp=0000000000000000
r8=0000000000000000 r9=00000000ffffffff r10=0000000000002407
r11=fffff900c00f5c30 r12=fffff900c0c14a50 r13=0000000000000000
r14=0000000000000001 r15=fffffa800c45a400
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
win32k!zzzSetDesktop+0x187:
fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h] ds:002b:fffff900`c00f5e98=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff960001612bd to fffff960001a000b
STACK_TEXT:
fffff880`026b59e0 fffff960`001612bd : fffff900`c00f5c30 00000000`00000000 fffffa80`0cc93b80 fffff800`000025ff : win32k!zzzSetDesktop+0x187
fffff880`026b5ac0 fffff960`00161448 : fffff880`026b5bf8 fffffa80`0b7d6b60 fffff880`026b5bf0 00000000`00000003 : win32k!xxxSetThreadDesktop+0x1ad
fffff880`026b5b10 fffff960`00160fe1 : 00000000`00000000 fffff880`026b5bf0 00000000`00000000 fffff800`02c7d1e3 : win32k!xxxRestoreCsrssThreadDesktop+0x64
fffff880`026b5b80 fffff960`00160e8d : 00000000`00000018 fffff880`026b5ca0 00000000`00000018 00000000`01f2f508 : win32k!xxxSetInformationThread+0xf9
fffff880`026b5bd0 fffff800`02c70993 : fffffa80`0b7d6b60 00000000`00000000 00000000`00000020 00000000`00000000 : win32k!NtUserSetInformationThread+0xbd
fffff880`026b5c20 000007fe`fd131c2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`01f2f4b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`fd131c2a
FOLLOWUP_IP:
win32k!zzzSetDesktop+187
fffff960`001a000b 488b8368020000 mov rax,qword ptr [rbx+268h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: win32k!zzzSetDesktop+187
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
STACK_COMMAND: .cxr 0xfffff880026b5010 ; kb
FAILURE_BUCKET_ID: X64_0x3B_win32k!zzzSetDesktop+187
BUCKET_ID: X64_0x3B_win32k!zzzSetDesktop+187
Followup: MachineOwner
---------