Disable the driver verifier and update these drivers:
HECIx64.sys Thu Sep 17 15:54:16 2009
Intel(R) Management Engine Interface
RtNdPt60.sys Sun Jul 19 22:27:32 2009
Realtek NDIS Protocol Driver
RTKVHD64.sys Fri Mar 26 06:30:50 2010
Realtek Audio
If the crashes reoccur, disable Apple Mobile Device USB:
usbaapl64.sys Wed Mar 31 23:20:15 2010
Crash Dumps:
Code:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-47970-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c4f000 PsLoadedModuleList = 0xfffff800`02e8ce50
Debug session time: Fri Dec 17 23:34:00.930 2010 (UTC - 5:00)
System Uptime: 0 days 3:36:19.381
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C1, {fffff98017de2f50, fffff98017de2030, af40b0, 32}
Probably caused by : memory_corruption ( nt!MiCheckSpecialPoolSlop+83 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SPECIAL_POOL_DETECTED_MEMORY_CORRUPTION (c1)
Special pool has detected memory corruption. Typically the current thread's
stack backtrace will reveal the guilty party.
Arguments:
Arg1: fffff98017de2f50, address trying to free
Arg2: fffff98017de2030, address where one bit is corrupted
Arg3: 0000000000af40b0, (reserved)
Arg4: 0000000000000032, caller is freeing an address where nearby bytes within the same page have a single bit error
Debugging Details:
------------------
BUGCHECK_STR: 0xC1_32
SPECIAL_POOL_CORRUPTION_TYPE: 32
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d4f5f3 to fffff80002cbf740
STACK_TEXT:
fffff880`089fa638 fffff800`02d4f5f3 : 00000000`000000c1 fffff980`17de2f50 fffff980`17de2030 00000000`00af40b0 : nt!KeBugCheckEx
fffff880`089fa640 fffff800`02dc6693 : 00000000`00000003 fffff980`17de2f58 00000000`00000293 fffff800`03152dfe : nt!MiCheckSpecialPoolSlop+0x83
fffff880`089fa680 fffff800`02df2356 : 00000000`000003ed 00000000`6c734d46 00000000`00300a00 fffff980`17de2f50 : nt!MmFreeSpecialPool+0x1d3
fffff880`089fa7b0 fffff800`0316392b : fffff880`0111c5c0 00000000`00000130 fffff980`7e584bc0 fffff980`7e584bc0 : nt!ExDeferredFreePool+0xf13
fffff880`089fa860 fffff880`01106633 : fffff980`0a52e800 00000000`00000000 fffff980`0a52e800 00000000`00000018 : nt!VerifierExFreePool+0x1b
fffff880`089fa890 fffff800`02fae896 : 00000000`00000001 00000000`00000130 00000000`00000010 fffff800`02fae7b4 : fltmgr! ?? ::FNODOBFM::`string'+0x429
fffff880`089fa8c0 fffff880`012c1bcc : fffff980`7e584bc0 fffffa80`07690040 fffff880`089fa998 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`089fa910 fffff880`012c18d5 : 00000000`00000000 00000000`00000000 fffff800`02e64500 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`089fa950 fffff880`01234cb4 : fffff980`7e584ac0 fffff980`7e584bc0 fffff800`02e64500 00000000`00010246 : Ntfs!NtfsRemoveScb+0x61
fffff880`089fa990 fffff880`01235037 : fffff980`7e584a90 fffff800`02e645a0 fffff880`089fab01 fffff980`9a910e40 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`089fa9c0 fffff880`012bf2cc : fffff980`9a910e40 fffffa80`05954180 fffff980`88c62a90 fffff980`88c62ed0 : Ntfs!NtfsTeardownFromLcb+0x2b7
fffff880`089faa50 fffff880`0123d882 : fffff980`9a910e40 fffff980`9a910e40 fffff980`88c62a90 fffff800`02e64500 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`089faad0 fffff880`012d6813 : fffff980`9a910e40 fffff980`88c62a90 fffff980`88c62a90 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`089fab10 fffff880`012b038f : fffff980`9a910e40 fffff980`88c62bc0 fffff980`88c62a90 fffffa80`05954180 : Ntfs!NtfsCommonClose+0x353
fffff880`089fabe0 fffff800`02ccc961 : 00000000`00000000 fffff880`012b0200 fffffa80`07690001 fffff800`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`089facb0 fffff800`02f63c06 : 00000000`00000010 fffffa80`07690040 00000000`00000080 fffffa80`035050b0 : nt!ExpWorkerThread+0x111
fffff880`089fad40 fffff800`02c9dc26 : fffff880`009e8180 fffffa80`07690040 fffffa80`0766cb60 fffff880`0123a534 : nt!PspSystemThreadStartup+0x5a
fffff880`089fad80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCheckSpecialPoolSlop+83
fffff800`02d4f5f3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiCheckSpecialPoolSlop+83
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0xC1_32_VRF_nt!MiCheckSpecialPoolSlop+83
BUCKET_ID: X64_0xC1_32_VRF_nt!MiCheckSpecialPoolSlop+83
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121610-37596-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c07000 PsLoadedModuleList = 0xfffff800`02e44e50
Debug session time: Thu Dec 16 02:10:39.487 2010 (UTC - 5:00)
System Uptime: 0 days 23:37:54.923
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C1, {fffff980aba0efb0, fffff980aba0eab0, 9d4058, 23}
Probably caused by : fileinfo.sys ( fileinfo!FIStreamCleanup+b3 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SPECIAL_POOL_DETECTED_MEMORY_CORRUPTION (c1)
Special pool has detected memory corruption. Typically the current thread's
stack backtrace will reveal the guilty party.
Arguments:
Arg1: fffff980aba0efb0, address trying to free
Arg2: fffff980aba0eab0, address where bits are corrupted
Arg3: 00000000009d4058, (reserved)
Arg4: 0000000000000023, caller is freeing an address where nearby bytes within the same page have been corrupted
Debugging Details:
------------------
BUGCHECK_STR: 0xC1_23
SPECIAL_POOL_CORRUPTION_TYPE: 23
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d0760a to fffff80002c77740
STACK_TEXT:
fffff880`07798538 fffff800`02d0760a : 00000000`000000c1 fffff980`aba0efb0 fffff980`aba0eab0 00000000`009d4058 : nt!KeBugCheckEx
fffff880`07798540 fffff800`02d7e693 : fffff980`00000003 fffff980`aba5ef58 00000000`00000293 fffff800`0310adfe : nt!MiCheckSpecialPoolSlop+0x9a
fffff880`07798580 fffff800`02daa356 : fffff800`02c07000 00000000`6a764d46 00000000`000d84e0 fffff980`aba0efb0 : nt!MmFreeSpecialPool+0x1d3
fffff880`077986b0 fffff800`0311b92b : fffff980`01996f40 fffffa80`034d8a88 00000000`00000000 fffff800`0310f58b : nt!ExDeferredFreePool+0xf13
fffff880`07798760 fffff880`01035633 : fffffa80`034d8a78 00000000`00000004 00000000`00000001 00000000`00000000 : nt!VerifierExFreePool+0x1b
fffff880`07798790 fffff880`0106e054 : fffff980`018b8be0 fffff980`018b8be0 00000000`00000004 00000000`00000001 : fltmgr! ?? ::FNODOBFM::`string'+0x429
fffff880`077987c0 fffff880`0106bf14 : fffff980`3f4cce80 fffff980`3f4cce80 00000000`00000000 00000000`00000000 : fltmgr!FltpvUnlinkResourceFromFilter+0x164
fffff880`07798810 fffff880`01083763 : fffff980`ab4b007f fffff980`ab4b8fb0 00000000`00000000 00000000`00000000 : fltmgr!FltvReleaseFileNameInformation+0x24
fffff880`07798840 fffff880`0103c65e : 00000000`00000000 fffff880`01058116 00000000`00000010 00000000`00010282 : fileinfo!FIStreamCleanup+0xb3
fffff880`07798890 fffff880`0105822d : fffff980`ab4b8f68 fffff880`0102e000 00000000`00000000 00000000`00000018 : fltmgr!DoFreeContext+0x7e
fffff880`077988c0 fffff880`01053bc1 : fffff980`02a3e800 00000000`00000130 fffff980`3d8fac70 fffff980`3d8fac70 : fltmgr! ?? ::NNGAKEGL::`string'+0x1196
fffff880`077988f0 fffff880`01053b7b : fffff980`02a3e800 fffff980`3d8faed8 fffff980`02a3e800 00000000`00000018 : fltmgr!CleanupStreamListCtrl+0x21
fffff880`07798920 fffff800`02f66896 : 00000000`00000001 fffff800`02c6090f 00000000`00000705 fffff800`02caa33f : fltmgr!DeleteStreamListCtrlCallback+0x6b
fffff880`07798950 fffff880`012afbcc : fffff980`3d8fac70 fffffa80`06a4f120 fffff880`07798a28 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`077989a0 fffff880`012af8d5 : fffff980`abaf2eb8 00000000`00000000 fffff800`02e1c500 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`077989e0 fffff880`01222cb4 : fffff980`3d8fab70 fffff980`3d8fac70 fffff800`02e1c500 00000000`00000003 : Ntfs!NtfsRemoveScb+0x61
fffff880`07798a20 fffff880`012ad2dc : fffff980`3d8fab40 fffff800`02e1c5a0 fffff880`07798b52 fffff980`07ea6e40 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`07798a50 fffff880`0122b882 : fffff980`07ea6e40 fffff980`07ea6e40 fffff980`3d8fab40 fffff800`02e1c500 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`07798ad0 fffff880`012c4813 : fffff980`07ea6e40 fffff980`3d8fab40 fffff980`3d8fab40 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`07798b10 fffff880`0129e38f : fffff980`07ea6e40 fffff980`3d8fac70 fffff980`3d8fab40 fffffa80`05253180 : Ntfs!NtfsCommonClose+0x353
fffff880`07798be0 fffff800`02c84961 : 00000000`00000000 fffff800`02f73c00 fffffa80`06a4f101 fffffa80`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`07798cb0 fffff800`02f1bc06 : 00000000`00000010 fffffa80`06a4f120 00000000`00000080 fffffa80`035050b0 : nt!ExpWorkerThread+0x111
fffff880`07798d40 fffff800`02c55c26 : fffff800`02df1e80 fffffa80`06a4f120 fffffa80`0522e040 5f5f5f5f`5f5f5f5f : nt!PspSystemThreadStartup+0x5a
fffff880`07798d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
fileinfo!FIStreamCleanup+b3
fffff880`01083763 f08305c1bbffffff lock add dword ptr [fileinfo!FIGlobals+0x2c (fffff880`0107f32c)],0FFFFFFFFh
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: fileinfo!FIStreamCleanup+b3
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc481
FAILURE_BUCKET_ID: X64_0xC1_23_VRF_fileinfo!FIStreamCleanup+b3
BUCKET_ID: X64_0xC1_23_VRF_fileinfo!FIStreamCleanup+b3
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121610-46722-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c01000 PsLoadedModuleList = 0xfffff800`02e3ee50
Debug session time: Thu Dec 16 06:54:44.438 2010 (UTC - 5:00)
System Uptime: 0 days 4:42:35.874
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C1, {fffff900cadaaf20, fffff900cadaa010, 9ba0d8, 23}
Probably caused by : win32k.sys ( win32k!FreeObject+40 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SPECIAL_POOL_DETECTED_MEMORY_CORRUPTION (c1)
Special pool has detected memory corruption. Typically the current thread's
stack backtrace will reveal the guilty party.
Arguments:
Arg1: fffff900cadaaf20, address trying to free
Arg2: fffff900cadaa010, address where bits are corrupted
Arg3: 00000000009ba0d8, (reserved)
Arg4: 0000000000000023, caller is freeing an address where nearby bytes within the same page have been corrupted
Debugging Details:
------------------
BUGCHECK_STR: 0xC1_23
SPECIAL_POOL_CORRUPTION_TYPE: 23
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: FlashDevelop.e
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d0160a to fffff80002c71740
STACK_TEXT:
fffff880`083ed0f8 fffff800`02d0160a : 00000000`000000c1 fffff900`cadaaf20 fffff900`cadaa010 00000000`009ba0d8 : nt!KeBugCheckEx
fffff880`083ed100 fffff800`02d78693 : 00000000`00000003 fffff900`c8b88f70 00000000`00000293 fffff800`03104dfe : nt!MiCheckSpecialPoolSlop+0x9a
fffff880`083ed140 fffff800`02da4390 : 00000000`000000e0 00000000`34616c47 00000000`00035a18 fffff900`cadaaf20 : nt!MmFreeSpecialPool+0x1d3
fffff880`083ed270 fffff960`00184e3c : fffff980`0e95af80 fffff880`083ed3a0 fffff880`083ed454 00000000`3f011304 : nt!ExDeferredFreePool+0xf4d
fffff880`083ed320 fffff960`00290f07 : fffff900`cadaaf20 fffff880`083ed370 fffff880`083ed410 00000000`3f011304 : win32k!FreeObject+0x40
fffff880`083ed350 fffff960`0029207e : 00000000`00000004 fffff900`ca756f20 fffff900`c8b88fe0 fffff900`ca9a0fc8 : win32k!vSpUpdateDirtyRgn+0x4fb
fffff880`083ed3f0 fffff960`00292d04 : fffff900`c38c2280 00000000`00010574 00000000`230f1301 00000000`00000000 : win32k!GreUpdateSprite+0x706
fffff880`083ed590 fffff960`00147e8b : fffff880`083ed990 00000000`00000000 0000042a`0000065e fffff900`c38c2280 : win32k!GreUpdateSpriteDevLockEnd+0x444
fffff880`083ed840 fffff960`002b40b0 : 00000000`00000000 fffff900`ca6d2ce8 00000000`00000000 fffff900`c8bb6fa0 : win32k!DEVLOCKBLTOBJ::~DEVLOCKBLTOBJ+0x4b
fffff880`083ed870 fffff960`001e68ba : 00000000`3f011304 00000000`0185000f 00000000`00000000 00000000`3f011304 : win32k!NtGdiBitBltInternal+0xdd8
fffff880`083eda50 fffff960`001e6c92 : fffff880`083edbd8 00000000`00000113 00000000`00000000 00000000`0027eb40 : win32k!UT_InvertCaret+0xea
fffff880`083edae0 fffff960`001565ba : fffff880`083edbd8 00000000`0000ffff 00000000`0027fd20 00000000`73471aa0 : win32k!CaretBlinkProc+0x9a
fffff880`083edb20 fffff960`001997a6 : 00000000`0027e1d0 fffff880`083edca0 00000000`0000ffff 00000000`00000001 : win32k!xxxDispatchMessage+0x16e
fffff880`083edba0 fffff800`02c70993 : fffffa80`067e7060 00000000`7efdb000 00000000`00000020 00000000`7efdb000 : win32k!NtUserDispatchMessage+0x66
fffff880`083edc20 00000000`734aff2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0027e158 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x734aff2a
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!FreeObject+40
fffff960`00184e3c eb16 jmp win32k!FreeObject+0x58 (fffff960`00184e54)
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: win32k!FreeObject+40
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c7dc13c
FAILURE_BUCKET_ID: X64_0xC1_23_VRF_win32k!FreeObject+40
BUCKET_ID: X64_0xC1_23_VRF_win32k!FreeObject+40
Followup: MachineOwner
---------
Drivers:
Code:
start end module name
fffff880`04089000 fffff880`040c7000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f72000 fffff880`00fc9000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`03ebf000 fffff880`03f49000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`040d7000 fffff880`040ed000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`00c2a000 fffff880`00c35000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`041af000 fffff880`041b7000 AppleCharger AppleCharger.sys Mon Apr 26 23:54:05 2010 (4BD65FDD)
fffff880`04671000 fffff880`0467c000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00df5000 fffff880`00dfe000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00c00000 fffff880`00c2a000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff960`00890000 fffff960`008f1000 ATMFD ATMFD.DLL unavailable (00000000)
fffff880`019f0000 fffff880`019f7000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`0419e000 fffff880`041af000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`03959000 fffff880`03977000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`00690000 fffff960`006b7000 cdd cdd.dll unavailable (00000000)
fffff880`01990000 fffff880`019ba000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00d1b000 fffff880`00ddb000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`0192a000 fffff880`0195a000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00cbd000 fffff880`00d1b000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01000000 fffff880`01073000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`040c7000 fffff880`040d7000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`06d62000 fffff880`06d70000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`040fd000 fffff880`04180000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`04180000 fffff880`0419e000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`03e97000 fffff880`03ea6000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01914000 fffff880`0192a000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`06c80000 fffff880`06ca2000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`06d7c000 fffff880`06d85000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06d70000 fffff880`06d7c000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06d85000 fffff880`06d98000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`06d2d000 fffff880`06d39000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`052e9000 fffff880`053dd000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04800000 fffff880`04846000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`0111d000 fffff880`01131000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`010d1000 fffff880`0111d000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`013cf000 fffff880`013d9000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`018da000 fffff880`01914000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0148b000 fffff880`014d5000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff880`053ee000 fffff880`053fb000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
fffff800`031dd000 fffff800`03226000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04000000 fffff880`04024000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`04846000 fffff880`04857000 HECIx64 HECIx64.sys Thu Sep 17 15:54:16 2009 (4AB293E8)
fffff880`06d09000 fffff880`06d22000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`06d22000 fffff880`06d2a080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`06cfb000 fffff880`06d09000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`03891000 fffff880`03959000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`013d9000 fffff880`013e2000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`048c8000 fffff880`052e89a0 igdkmd64 igdkmd64.sys Sat Oct 16 01:28:37 2010 (4CB93805)
fffff880`06ca8000 fffff880`06cfb000 IntcDAud IntcDAud.sys Tue Aug 31 09:07:05 2010 (4C7CFE79)
fffff880`041dd000 fffff880`041f3000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`044d5000 fffff880`044e4000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06d46000 fffff880`06d54000 kbdhid kbdhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff800`00bb5000 fffff800`00bbf000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`044f5000 fffff880`04538000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`013a4000 fffff880`013be000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01460000 fffff880`0148b000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`06ca2000 fffff880`06ca7200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`06ddc000 fffff880`06df1000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`06d98000 fffff880`06dbb000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c65000 fffff880`00ca9000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`06d54000 fffff880`06d62000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`044e4000 fffff880`044f3000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06d39000 fffff880`06d46000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00ddb000 fffff880`00df5000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`019ba000 fffff880`019e7000 MpFilter MpFilter.sys Sat Mar 20 01:58:08 2010 (4BA463F0)
fffff880`03871000 fffff880`03881000 MpNWMon MpNWMon.sys Sat Mar 20 01:58:00 2010 (4BA463E8)
fffff880`03977000 fffff880`0398f000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`0398f000 fffff880`039bc000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`03800000 fffff880`0384e000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0384e000 fffff880`03871000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`0185e000 fffff880`01869000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00fd2000 fffff880`00fdc000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`0113d000 fffff880`0119b000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`03e8c000 fffff880`03e97000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015e7000 fffff880`015f9000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`014f5000 fffff880`015e7000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`040ed000 fffff880`040f9000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`00c35000 fffff880`00c64000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`045a4000 fffff880`045b9000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`03fcc000 fffff880`03fdb000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`03f49000 fffff880`03f8e000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01400000 fffff880`01460000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`03fbd000 fffff880`03fcc000 nm3 nm3.sys Wed Jun 09 20:05:51 2010 (4C102C5F)
fffff880`01869000 fffff880`0187a000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03e80000 fffff880`03e8c000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02c01000 fffff800`031dd000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01201000 fffff880`013a4000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`019e7000 fffff880`019f0000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`03f97000 fffff880`03fbd000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00e33000 fffff880`00e48000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00e00000 fffff880`00e33000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00fe9000 fffff880`00ff0000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00ff0000 fffff880`01000000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`013be000 fffff880`013cf000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`04400000 fffff880`044a6000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`06c43000 fffff880`06c80000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00ca9000 fffff880`00cbd000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`01131000 fffff880`0113ce00 PxHlpa64 PxHlpa64.sys Tue Jun 23 19:16:35 2009 (4A416253)
fffff880`018a5000 fffff880`018c9000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`013e2000 fffff880`013fd000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`011d5000 fffff880`011f6000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`044b0000 fffff880`044ca000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03e2f000 fffff880`03e80000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`044ca000 fffff880`044d5000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`01843000 fffff880`0184c000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`0184c000 fffff880`01855000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01855000 fffff880`0185e000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`0119b000 fffff880`011d5000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`045b9000 fffff880`045d1000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04024000 fffff880`04089000 Rt64win7 Rt64win7.sys Mon Oct 25 05:33:07 2010 (4CC54ED3)
fffff880`06a11000 fffff880`06c42c00 RTKVHD64 RTKVHD64.sys Fri Mar 26 06:30:50 2010 (4BAC8CDA)
fffff880`06df1000 fffff880`06dfd000 RtNdPt60 RtNdPt60.sys Sun Jul 19 22:27:32 2009 (4A63D614)
fffff880`03881000 fffff880`0388c000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`048ba000 fffff880`048c6000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03fdb000 fffff880`03ff8000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`014e5000 fffff880`014ed000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0472d000 fffff880`047c3000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`046c6000 fffff880`0472d000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`039bc000 fffff880`039e9000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`044f3000 fffff880`044f4480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01602000 fffff880`017ff000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`039e9000 fffff880`039fb000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`01898000 fffff880`018a5000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`0187a000 fffff880`01898000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`03e1b000 fffff880`03e2f000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00500000 fffff960`0050a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`041b7000 fffff880`041dd000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04538000 fffff880`0454a000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`046b5000 fffff880`046c6000 usbaapl64 usbaapl64.sys Wed Mar 31 23:20:15 2010 (4BB410EF)
fffff880`06d2b000 fffff880`06d2cf00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`053dd000 fffff880`053ee000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`0454a000 fffff880`045a4000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`04864000 fffff880`048ba000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`04857000 fffff880`04864000 usbuhci usbuhci.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00fdc000 fffff880`00fe9000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01800000 fffff880`0180e000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`0180e000 fffff880`01833000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`014d5000 fffff880`014e5000 vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
fffff880`00e48000 fffff880`00e5d000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e5d000 fffff880`00eb9000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01073000 fffff880`010bf000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`03e00000 fffff880`03e1b000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`01833000 fffff880`01843000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00ebf000 fffff880`00f63000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f63000 fffff880`00f72000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`03f8e000 fffff880`03f97000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000c0000 fffff960`003cf000 win32k win32k.sys Tue Aug 31 22:58:04 2010 (4C7DC13C)
fffff880`047c3000 fffff880`047d4000 WinUsb WinUsb.sys Mon Jul 13 20:06:28 2009 (4A5BCC04)
fffff880`00fc9000 fffff880`00fd2000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`06dbb000 fffff880`06ddc000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`04600000 fffff880`04631000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
Unloaded modules:
fffff880`046a4000 fffff880`046b5000 usbaapl64.sy
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00011000
fffff880`0467c000 fffff880`04688000 hiber_atapor
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`04688000 fffff880`04691000 hiber_atapi.
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`04691000 fffff880`046a4000 hiber_dumpfv
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000
fffff880`04600000 fffff880`04671000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00071000
fffff880`0195a000 fffff880`01968000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`01968000 fffff880`01974000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`01974000 fffff880`0197d000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`0197d000 fffff880`01990000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000