Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\New folder (3)\031210-16879-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a09000 PsLoadedModuleList = 0xfffff800`02c46e50
Debug session time: Fri Mar 12 01:21:48.446 2010 (GMT-5)
System Uptime: 0 days 1:20:37.506
Loading Kernel Symbols
...............................................................
................................................................
................................................................
......
Loading User Symbols
Loading unloaded module list
.....................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, fffffa800130fd80, fffffa80013107d0, 4a56510}
GetPointerFromAddress: unable to read from fffff80002cb10e0
GetUlongFromAddress: unable to read from fffff80002c1f1b0
Probably caused by : ntkrnlmp.exe ( nt!CcWriteBehind+5bc )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000020, a pool block header size is corrupt.
Arg2: fffffa800130fd80, The pool entry we were looking for within the page.
Arg3: fffffa80013107d0, The next pool entry.
Arg4: 0000000004a56510, (reserved)
Debugging Details:
------------------
GetUlongFromAddress: unable to read from fffff80002c1f1b0
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: fffffa800130fd80
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002bac6d3 to fffff80002a7af00
STACK_TEXT:
fffff880`0c812a98 fffff800`02bac6d3 : 00000000`00000019 00000000`00000020 fffffa80`0130fd80 fffffa80`013107d0 : nt!KeBugCheckEx
fffff880`0c812aa0 fffff800`02a6e55c : fffff800`02cb3800 00000000`00000000 fffffa80`63536343 fffff800`00000000 : nt!ExFreePool+0xda4
fffff880`0c812b50 fffff800`02a6ed60 : fffff880`041bcd00 fffff880`0c812c58 00000000`00000000 fffff880`00000000 : nt!CcWriteBehind+0x5bc
fffff880`0c812c00 fffff800`02a88161 : fffffa80`03c38930 fffff800`02d74504 fffff800`02c80140 fffffa80`00000002 : nt!CcWorkerThread+0x1c8
fffff880`0c812cb0 fffff800`02d1e166 : fffff880`0bbe9400 fffffa80`08998880 00000000`00000080 fffffa80`03babb30 : nt!ExpWorkerThread+0x111
fffff880`0c812d40 fffff800`02a59486 : fffff880`009ea180 fffffa80`08998880 fffffa80`061b7b60 fffff880`01424bf0 : nt!PspSystemThreadStartup+0x5a
fffff880`0c812d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!CcWriteBehind+5bc
fffff800`02a6e55c 4c8b9c24b8000000 mov r11,qword ptr [rsp+0B8h]
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!CcWriteBehind+5bc
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x19_20_nt!CcWriteBehind+5bc
BUCKET_ID: X64_0x19_20_nt!CcWriteBehind+5bc
Followup: MachineOwner
---------