Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\021410-23337-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a11000 PsLoadedModuleList = 0xfffff800`02c4ee50
Debug session time: Sat Feb 13 19:00:41.428 2010 (GMT-5)
System Uptime: 0 days 0:02:00.129
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff8a042c4b440, 0, fffff80002bb4f8c, 5}
Could not read faulting driver name
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+100 )
Followup: Pool_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8a042c4b440, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002bb4f8c, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cb90e0
fffff8a042c4b440
FAULTING_IP:
nt!ExDeferredFreePool+100
fffff800`02bb4f8c 4c8b02 mov r8,qword ptr [rdx]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88006877810 -- (.trap 0xfffff88006877810)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a002c58000 rbx=0000000000000000 rcx=fffffa8003c5fc50
rdx=fffff8a042c4b440 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002bb4f8c rsp=fffff880068779a0 rbp=0000000000000002
r8=fffff8a042c4b440 r9=0000000000000000 r10=fffff8a002c588b0
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExDeferredFreePool+0x100:
fffff800`02bb4f8c 4c8b02 mov r8,qword ptr [rdx] ds:fffff8a0`42c4b440=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002b00b91 to fffff80002a82f00
STACK_TEXT:
fffff880`068776a8 fffff800`02b00b91 : 00000000`00000050 fffff8a0`42c4b440 00000000`00000000 fffff880`06877810 : nt!KeBugCheckEx
fffff880`068776b0 fffff800`02a80fee : 00000000`00000000 00000000`00000003 fffff8a0`00e7f800 fffff8a0`02c46060 : nt! ?? ::FNODOBFM::`string'+0x40f5b
fffff880`06877810 fffff800`02bb4f8c : 00000000`00000001 fffff800`02d51c6f fffff880`06877ca0 00000000`011fea8c : nt!KiPageFault+0x16e
fffff880`068779a0 fffff800`02bb64c1 : 00000000`00000001 fffff8a0`02c46000 fffffa80`061f7620 fffff8a0`02c46000 : nt!ExDeferredFreePool+0x100
fffff880`06877a30 fffff800`02a880bc : fffff8a0`02c46030 00000000`00000000 fffffa80`656b6f54 fffffa80`03c69f30 : nt!ExFreePoolWithTag+0x411
fffff880`06877ae0 fffff800`02d96194 : fffffa80`0647b060 00000000`00000000 fffffa80`061f7620 00000000`00000000 : nt!ObfDereferenceObject+0xdc
fffff880`06877b40 fffff800`02d96094 : 00000000`00000590 fffffa80`0647b060 fffff8a0`00d2fe20 00000000`00000590 : nt!ObpCloseHandleTableEntry+0xc4
fffff880`06877bd0 fffff800`02a82153 : fffffa80`061f7620 fffff880`06877ca0 00000000`011fec90 00000000`011fec90 : nt!ObpCloseHandle+0x94
fffff880`06877c20 00000000`77b4ffaa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`011feb38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77b4ffaa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+100
fffff800`02bb4f8c 4c8b02 mov r8,qword ptr [rdx]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExDeferredFreePool+100
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x50_nt!ExDeferredFreePool+100
BUCKET_ID: X64_0x50_nt!ExDeferredFreePool+100
Followup: Pool_corruption
---------