[list=1]
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\NassiC\Windows_NT6_BSOD_jcgriff2\011012-16317-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e03000 PsLoadedModuleList = 0xfffff800`03048670
Debug session time: Mon Jan 9 18:41:43.063 2012 (UTC - 7:00)
System Uptime: 0 days 0:09:16.249
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4E, {2, a3d60, 12ffff, 1}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+11718 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000002, A list entry was corrupt
Arg2: 00000000000a3d60, entry in list being removed
Arg3: 000000000012ffff, highest physical page number
Arg4: 0000000000000001, reference count of entry being removed
Debugging Details:
------------------
BUGCHECK_STR: 0x4E_2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002e14488 to fffff80002e7fc40
STACK_TEXT:
fffff880`0318c6c8 fffff800`02e14488 : 00000000`0000004e 00000000`00000002 00000000`000a3d60 00000000`0012ffff : nt!KeBugCheckEx
fffff880`0318c6d0 fffff800`02ec378b : fffff8a0`0c5da900 00000000`0006455f 00000000`0c5da900 fffff8a0`0c5da900 : nt! ?? ::FNODOBFM::`string'+0x11718
fffff880`0318c760 fffff800`02ec2188 : fffff8a0`0c5da800 fffff8a0`0c5db000 fffffa80`04111f90 fffffa80`04111f90 : nt!MiFlushSectionInternal+0x6bb
fffff880`0318c990 fffff800`02ec1669 : 00000000`00008b4a fffff880`0318cc58 00000000`00100000 fffffa80`043a2760 : nt!MmFlushSection+0xa4
fffff880`0318ca50 fffff800`02ec4f76 : fffffa80`040b0558 00000000`00000001 fffffa80`00000001 fffffa80`00100000 : nt!CcFlushCache+0x5e9
fffff880`0318cb50 fffff800`02ec5938 : fffff880`00000000 fffff880`0318cc58 fffffa80`03fb0c10 fffff880`042db734 : nt!CcWriteBehind+0x1c6
fffff880`0318cc00 fffff800`02e8a001 : fffffa80`03a48530 fffff800`03176901 fffff800`030818c0 00000000`00000002 : nt!CcWorkerThread+0x1c8
fffff880`0318ccb0 fffff800`0311afee : 00000000`00000000 fffffa80`03adb040 00000000`00000080 fffffa80`039ed040 : nt!ExpWorkerThread+0x111
fffff880`0318cd40 fffff800`02e715e6 : fffff880`02f63180 fffffa80`03adb040 fffff880`02f6dfc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0318cd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+11718
fffff800`02e14488 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+11718
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x4E_2_nt!_??_::FNODOBFM::_string_+11718
BUCKET_ID: X64_0x4E_2_nt!_??_::FNODOBFM::_string_+11718
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\NassiC\Windows_NT6_BSOD_jcgriff2\011012-16879-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e4d000 PsLoadedModuleList = 0xfffff800`03092670
Debug session time: Mon Jan 9 18:44:25.092 2012 (UTC - 7:00)
System Uptime: 0 days 0:01:38.653
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88008317758, fffff88008316fb0, fffff80002edc19a}
Probably caused by : Ntfs.sys ( Ntfs!NtfsTeardownFromLcb+fb )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88008317758
Arg3: fffff88008316fb0
Arg4: fffff80002edc19a
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88008317758 -- (.exr 0xfffff88008317758)
ExceptionAddress: fffff80002edc19a (nt!ExAcquireFastMutex+0x000000000000001a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 000000006bd59921
Attempt to write to address 000000006bd59921
CONTEXT: fffff88008316fb0 -- (.cxr 0xfffff88008316fb0)
rax=0000000000000001 rbx=000000006bd59921 rcx=000000006bd59921
rdx=0000000000000001 rsi=fffff88008317b01 rdi=0000000000000000
rip=fffff80002edc19a rsp=fffff88008317990 rbp=fffff8000306a260
r8=fffff8a007526480 r9=fffff8a0075268c0 r10=fffff880010ab5c0
r11=fffffa8003ca3510 r12=fffff8a007526480 r13=fffff8a001d07bc0
r14=fffff8a007526800 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExAcquireFastMutex+0x1a:
fffff800`02edc19a f00fba3100 lock btr dword ptr [rcx],0 ds:002b:00000000`6bd59921=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 1
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 000000006bd59921
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030fc100
000000006bd59921
FOLLOWUP_IP:
Ntfs!NtfsTeardownFromLcb+fb
fffff880`0123988b 83bfc000000000 cmp dword ptr [rdi+0C0h],0
FAULTING_IP:
nt!ExAcquireFastMutex+1a
fffff800`02edc19a f00fba3100 lock btr dword ptr [rcx],0
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff8800123988b to fffff80002edc19a
STACK_TEXT:
fffff880`08317990 fffff880`0123988b : fffff8a0`07526480 fffffa80`03bc5c30 fffff8a0`075265b0 fffff880`012c1cc1 : nt!ExAcquireFastMutex+0x1a
fffff880`083179c0 fffff880`012bf63c : fffffa80`03bc5c30 fffffa80`04a39180 fffff8a0`07526480 fffff8a0`075268c0 : Ntfs!NtfsTeardownFromLcb+0xfb
fffff880`08317a50 fffff880`012410e2 : fffffa80`03bc5c30 fffffa80`03bc5c30 fffff8a0`07526480 fffff880`08317c00 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`08317ad0 fffff880`012cf193 : fffffa80`03bc5c30 fffff800`0306a260 fffff8a0`4946744e 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`08317b10 fffff880`012be357 : fffffa80`03bc5c30 fffff8a0`075265b0 fffff8a0`07526480 fffffa80`04a39180 : Ntfs!NtfsCommonClose+0x353
fffff880`08317be0 fffff800`02ed4001 : 00000000`00000000 fffff800`031c0900 fffffa80`061c6001 00000000`00000003 : Ntfs!NtfsFspClose+0x15f
fffff880`08317cb0 fffff800`03164fee : 00000000`271f90ca fffffa80`061c6040 00000000`00000080 fffffa80`039ed040 : nt!ExpWorkerThread+0x111
fffff880`08317d40 fffff800`02ebb5e6 : fffff880`02fd4180 fffffa80`061c6040 fffffa80`0603f060 fffff880`01240a20 : nt!PspSystemThreadStartup+0x5a
fffff880`08317d80 00000000`00000000 : fffff880`08318000 fffff880`08312000 fffff880`083179e0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs!NtfsTeardownFromLcb+fb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79997b
STACK_COMMAND: .cxr 0xfffff88008316fb0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownFromLcb+fb
BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownFromLcb+fb
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\NassiC\Windows_NT6_BSOD_jcgriff2\011012-18142-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e57000 PsLoadedModuleList = 0xfffff800`0309c670
Debug session time: Mon Jan 9 18:00:54.873 2012 (UTC - 7:00)
System Uptime: 0 days 4:17:05.434
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff880074be288, fffff880074bdae0, fffff880012294d3}
Probably caused by : Ntfs.sys ( Ntfs!NtfsCommonRead+1ca7 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff880074be288
Arg3: fffff880074bdae0
Arg4: fffff880012294d3
Debugging Details:
------------------
EXCEPTION_RECORD: fffff880074be288 -- (.exr 0xfffff880074be288)
ExceptionAddress: fffff880012294d3 (Ntfs!NtfsCommonRead+0x0000000000001ca7)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff880074bdae0 -- (.cxr 0xfffff880074bdae0)
rax=00fffa80048b6ec0 rbx=fffff8a0034c7790 rcx=fffff880074be5f8
rdx=fffffa8004a3e180 rsi=fffff8a0034c7980 rdi=fffff8a0034c7660
rip=fffff880012294d3 rsp=fffff880074be4c0 rbp=fffff880074be7f0
r8=0000000000000000 r9=0000000000671c00 r10=fffffa8004789c00
r11=fffff880074be698 r12=0000000000060001 r13=0000000000000001
r14=fffff880074be708 r15=fffff880074be690
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00010246
Ntfs!NtfsCommonRead+0x1ca7:
fffff880`012294d3 ff4008 inc dword ptr [rax+8] ds:002b:00fffa80`048b6ec8=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: League of Lege
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003106100
ffffffffffffffff
FOLLOWUP_IP:
Ntfs!NtfsCommonRead+1ca7
fffff880`012294d3 ff4008 inc dword ptr [rax+8]
FAULTING_IP:
Ntfs!NtfsCommonRead+1ca7
fffff880`012294d3 ff4008 inc dword ptr [rax+8]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff88001229a68 to fffff880012294d3
STACK_TEXT:
fffff880`074be4c0 fffff880`01229a68 : fffff880`074be690 fffffa80`04789860 fffff880`074be701 fffffa80`03e3bb01 : Ntfs!NtfsCommonRead+0x1ca7
fffff880`074be660 fffff880`01142bcf : fffffa80`04789c00 fffffa80`04789860 fffffa80`03e3bb00 00000000`00000000 : Ntfs!NtfsFsdRead+0x1b8
fffff880`074be870 fffff880`011416df : fffffa80`048b8ca0 fffffa80`03ed7301 fffffa80`048b8c00 fffffa80`04789860 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`074be900 fffff800`02efbbc5 : fffffa80`04789880 fffffa80`03d9f7d0 fffffa80`03d21640 00000000`00a7355c : fltmgr!FltpDispatch+0xcf
fffff880`074be960 fffff800`02efb699 : 00000000`00000001 00000000`00000001 fffffa80`03d21580 fffffa80`03d21580 : nt!IoPageRead+0x255
fffff880`074be9f0 fffff800`02ee202a : 00000000`00000000 00000000`00000000 ffffffff`ffffffff 00000000`00000000 : nt!MiIssueHardFault+0x255
fffff880`074beac0 fffff800`02ed1d6e : 00000000`00000000 00000000`00a7355c fffffa80`03997a01 00000000`005006d4 : nt!MmAccessFault+0x146a
fffff880`074bec20 00000000`77aa6882 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`0018e8b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77aa6882
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsCommonRead+1ca7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79997b
STACK_COMMAND: .cxr 0xfffff880074bdae0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsCommonRead+1ca7
BUCKET_ID: X64_0x24_Ntfs!NtfsCommonRead+1ca7
Followup: MachineOwner
---------
[/list]